mirror of
https://github.com/apache/nuttx.git
synced 2026-08-01 20:28:58 +00:00
!build: add build-time password generation with mkpasswd tool.
Introduce mkpasswd, a pure-C host tool for generating encrypted password
files at build time using TEA encryption. This enables secure,
credential-free firmware images while allowing build-time password
configuration.
Changes:
* Add mkpasswd.c host tool for TEA-based password hashing and encryption
* Integrate mkpasswd into Make build system (tools/Makefile.host)
* Add CMake support for mkpasswd compilation and ROMFS passwd generation
* Add CONFIG_BOARD_ETC_ROMFS_PASSWD_* configuration options to Kconfig
* Implement credential exclusion from defconfig to prevent password leaking
* Update savedefconfig.cmake to strip sensitive credentials
* Fix mkdir() portability for Windows Native builds (CONFIG_WINDOWS_NATIVE)
* Change default username from "admin" to "root" (POSIX convention)
* Improve build-failure error message with full menuconfig navigation path
BREAKING CHANGE: Boards enabling CONFIG_BOARD_ETC_ROMFS_PASSWD_ENABLE
must set CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD to a non-empty string
of at least 8 characters. The build now fails with an explicit error if
this config is left empty. To fix: run 'make menuconfig' and navigate to:
Board Selection --->
Auto-generate /etc/passwd at build time --->
Admin password
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
This commit is contained in:
parent
ea161e4fa9
commit
ab6b1fd6f9
9 changed files with 813 additions and 8 deletions
|
|
@ -282,6 +282,75 @@ function(process_all_directory_romfs)
|
|||
list(PREPEND RCSRCS ${board_rcsrcs} ${dyn_rcsrcs})
|
||||
list(PREPEND RCRAWS ${board_rcraws} ${dyn_rcraws})
|
||||
|
||||
# Auto-generate /etc/passwd at build time if configured
|
||||
if(CONFIG_BOARD_ETC_ROMFS_PASSWD_ENABLE)
|
||||
if("${CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD}" STREQUAL "")
|
||||
message(
|
||||
FATAL_ERROR
|
||||
"CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD must be set when "
|
||||
"BOARD_ETC_ROMFS_PASSWD_ENABLE is enabled. Run 'make menuconfig' "
|
||||
"to set a password.")
|
||||
endif()
|
||||
|
||||
# Determine host executable suffix (.exe on Windows, empty elsewhere)
|
||||
if(CMAKE_HOST_WIN32)
|
||||
set(HOST_EXE_SUFFIX .exe)
|
||||
else()
|
||||
set(HOST_EXE_SUFFIX "")
|
||||
endif()
|
||||
|
||||
# Locate a host C compiler to build the mkpasswd tool
|
||||
find_program(HOST_CC NAMES cc gcc clang REQUIRED)
|
||||
|
||||
# Build mkpasswd.c as a host binary in the CMake build directory and keep
|
||||
# the source tree clean.
|
||||
set(MKPASSWD_SRC ${NUTTX_DIR}/tools/mkpasswd.c)
|
||||
set(MKPASSWD_BIN ${CMAKE_BINARY_DIR}/tools/mkpasswd${HOST_EXE_SUFFIX})
|
||||
|
||||
if(NOT TARGET build_host_mkpasswd)
|
||||
add_custom_command(
|
||||
OUTPUT ${MKPASSWD_BIN}
|
||||
COMMAND ${CMAKE_COMMAND} -E make_directory ${CMAKE_BINARY_DIR}/tools
|
||||
COMMAND ${HOST_CC} -o ${MKPASSWD_BIN} ${MKPASSWD_SRC}
|
||||
DEPENDS ${MKPASSWD_SRC}
|
||||
COMMENT "Building host tool: mkpasswd")
|
||||
add_custom_target(build_host_mkpasswd DEPENDS ${MKPASSWD_BIN})
|
||||
endif()
|
||||
|
||||
# Pass TEA key overrides when the user has changed them from defaults
|
||||
set(MKPASSWD_KEY_ARGS "")
|
||||
if(CONFIG_FSUTILS_PASSWD_KEY1)
|
||||
list(APPEND MKPASSWD_KEY_ARGS --key1 ${CONFIG_FSUTILS_PASSWD_KEY1})
|
||||
endif()
|
||||
if(CONFIG_FSUTILS_PASSWD_KEY2)
|
||||
list(APPEND MKPASSWD_KEY_ARGS --key2 ${CONFIG_FSUTILS_PASSWD_KEY2})
|
||||
endif()
|
||||
if(CONFIG_FSUTILS_PASSWD_KEY3)
|
||||
list(APPEND MKPASSWD_KEY_ARGS --key3 ${CONFIG_FSUTILS_PASSWD_KEY3})
|
||||
endif()
|
||||
if(CONFIG_FSUTILS_PASSWD_KEY4)
|
||||
list(APPEND MKPASSWD_KEY_ARGS --key4 ${CONFIG_FSUTILS_PASSWD_KEY4})
|
||||
endif()
|
||||
|
||||
set(GENPASSWD_OUTPUT ${CMAKE_CURRENT_BINARY_DIR}/etc/passwd)
|
||||
add_custom_command(
|
||||
OUTPUT ${GENPASSWD_OUTPUT}
|
||||
COMMAND ${CMAKE_COMMAND} -E make_directory ${CMAKE_CURRENT_BINARY_DIR}/etc
|
||||
COMMAND
|
||||
${MKPASSWD_BIN} --user "${CONFIG_BOARD_ETC_ROMFS_PASSWD_USER}"
|
||||
--password "${CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD}" --uid
|
||||
${CONFIG_BOARD_ETC_ROMFS_PASSWD_UID} --gid
|
||||
${CONFIG_BOARD_ETC_ROMFS_PASSWD_GID} --home
|
||||
"${CONFIG_BOARD_ETC_ROMFS_PASSWD_HOME}" ${MKPASSWD_KEY_ARGS} -o
|
||||
${GENPASSWD_OUTPUT}
|
||||
DEPENDS ${MKPASSWD_BIN} ${NUTTX_DIR}/.config
|
||||
COMMENT "Generating /etc/passwd from Kconfig values")
|
||||
add_custom_target(generate_passwd DEPENDS ${GENPASSWD_OUTPUT})
|
||||
add_dependencies(generate_passwd build_host_mkpasswd)
|
||||
list(APPEND RCRAWS ${GENPASSWD_OUTPUT})
|
||||
list(APPEND dyn_deps generate_passwd)
|
||||
endif()
|
||||
|
||||
# init dynamic dependencies
|
||||
|
||||
get_property(
|
||||
|
|
|
|||
|
|
@ -27,10 +27,14 @@ set(TARGET_FILE ${CMAKE_ARGV4})
|
|||
|
||||
file(STRINGS ${SOURCE_FILE} ConfigContents)
|
||||
encode_brackets(ConfigContents)
|
||||
set(PASSWD_AUTOGEN_ENABLED FALSE)
|
||||
|
||||
foreach(NameAndValue ${ConfigContents})
|
||||
decode_brackets(NameAndValue)
|
||||
encode_semicolon(NameAndValue)
|
||||
if("${NameAndValue}" MATCHES "^CONFIG_BOARD_ETC_ROMFS_PASSWD_ENABLE=y$")
|
||||
set(PASSWD_AUTOGEN_ENABLED TRUE)
|
||||
endif()
|
||||
if("${NameAndValue}" MATCHES "CONFIG_ARCH="
|
||||
OR "${NameAndValue}" MATCHES "^CONFIG_ARCH_CHIP_"
|
||||
OR "${NameAndValue}" MATCHES "CONFIG_ARCH_CHIP="
|
||||
|
|
@ -72,9 +76,20 @@ list(SORT LINES)
|
|||
foreach(LINE IN LISTS LINES)
|
||||
decode_brackets(LINE)
|
||||
decode_semicolon(LINE)
|
||||
file(APPEND ${OUTPUT_FILE} "${LINE}\n")
|
||||
if(NOT "${LINE}" MATCHES "^CONFIG_FSUTILS_PASSWD_KEY[0-9]"
|
||||
AND NOT "${LINE}" MATCHES "^CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD=")
|
||||
file(APPEND ${OUTPUT_FILE} "${LINE}\n")
|
||||
endif()
|
||||
endforeach()
|
||||
|
||||
if(PASSWD_AUTOGEN_ENABLED)
|
||||
message(
|
||||
WARNING
|
||||
"CONFIG_BOARD_ETC_ROMFS_PASSWD_PASSWORD and CONFIG_FSUTILS_PASSWD_KEY1-4 "
|
||||
"were intentionally excluded from defconfig by savedefconfig. Add them "
|
||||
"manually in local defconfig if needed.")
|
||||
endif()
|
||||
|
||||
# Converts the newline style for the output file.
|
||||
configure_file(${OUTPUT_FILE} ${OUTPUT_FILE} @ONLY NEWLINE_STYLE LF)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue