Repository navigation
Expand file tree
/
Copy pathreplace-sudo.sh
More file actions
executable file
·142 lines (121 loc) · 3.68 KB
/
Copy pathreplace-sudo.sh
File metadata and controls
executable file
·142 lines (121 loc) · 3.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
#!/bin/sh
#
# Copyright waiver for <https://github.com/Kinderfeld/replace-sudo>
#
# I dedicate any and all copyright interest in this software to the
# public domain. I make this dedication for the benefit of the public at
# large and to the detriment of my heirs and successors. I intend this
# dedication to be an overt act of relinquishment in perpetuity of all
# present and future rights to this software under copyright law.
#
# To the best of my knowledge and belief, my contributions are either
# originally authored by me or are derived from prior works which I have
# verified are also in the public domain and are not subject to claims
# of copyright by other parties.
#
# To the best of my knowledge and belief, no individual, business,
# organization, government, or other entity has any copyright interest
# in my contributions, and I affirm that I will not make contributions
# that are otherwise encumbered.
#
# Use the C locale for deterministic command output and parsing.
#
LANG="C"
LC_ALL="C"
sudo_to_ignore()
{
printf "[<==] Adding 'sudo' to ignored packages...\n"
mkdir -p /etc/xbps.d
if [ ! -e /etc/xbps.d/ignore.conf ] || \
! grep -q "^ignorepkg=sudo" /etc/xbps.d/ignore.conf
then
echo "ignorepkg=sudo" >> /etc/xbps.d/ignore.conf
fi
}
remove_sudo()
{
printf "[<==] Removing 'sudo'...\n"
case "$1" in
"alpine") apk del sudo ;;
"arch") pacman -R sudo ;;
"debian") apt remove sudo ;;
"freebsd") pkg remove sudo ;;
"netbsd") pkgin remove sudo ;;
"openbsd") pkg_delete sudo ;;
"void") sudo_to_ignore && xbps-remove sudo ;;
*)
printf "[!] Unsupported OS: '%s'.\n" "$1"
exit 1 ;;
esac
}
install_doas()
{
printf "[<==] Installing 'doas'...\n"
case "$1" in
"alpine") apk add doas ;;
"arch") pacman -S doas ;;
"debian") apt install doas ;;
"freebsd") pkg install doas ;;
"netbsd") pkgin install doas ;;
"openbsd") pkg_add doas ;;
"void") xbps-install -S opendoas ;;
*)
printf "[!] Unsupported OS: '%s'.\n" "$1"
exit 1 ;;
esac
}
configure_doas()
{
printf "[<==] Configuring 'doas'...\n"
config="permit persist :wheel as root"
case "$1" in
"freebsd") echo "$config" > /usr/local/etc/doas.conf ;;
"netbsd") echo "$config" > /usr/pkg/etc/doas.conf ;;
esac
echo "$config" > /etc/doas.conf
ln -sf "$(command -v doas)" /usr/bin/sudo
}
configure_mdo()
{
printf "[<==] Configuring 'mdo'...\n"
config="uid=1001>uid=0,gid=*,+gid=*"
kldload mac_do
sysctl security.mac.do.enabled
sysctl security.mac.do.rules="$config"
echo 'mac_do_load="YES"' >> /boot/loader.conf
}
root_check()
{
if [ "$(id -u)" -ne "0" ]
then
printf "[!] This script must be run with root privileges.\n" >&2
exit 1
fi
}
main()
{
root_check
printf "[*] Starting 'sudo' replacement...\n"
printf "[==>] Enter your OS family "
printf "[Debian, Arch, Alpine, Void, FreeBSD, OpenBSD, NetBSD]: "
read -r os
os="$(printf "%s" "$os" | tr '[:upper:]' '[:lower:]')"
if [ "$os" = "freebsd" ]
then
printf "[==>] FreeBSD supports 'mdo' via mac_do."
printf "Use it instead of 'doas'? [y/N]: "
read -r choice
case "$choice" in
[Yy]|[Yy][Ee][Ss])
remove_sudo "$os"
configure_mdo
printf "[*] Success! 'mdo' has been configured.\n"
exit 0 ;;
esac
fi
remove_sudo "$os"
install_doas "$os"
configure_doas "$os"
printf "[*] Success! 'doas' has been configured.\n"
}
main