dotfiles/.local/bin/chroot-gen

58 lines
1.6 KiB
Plaintext
Raw Normal View History

2023-12-14 08:27:07 +00:00
#!/bin/bash
# Adapted from LinuxConfig.org
# GNU GPL v3.0+
CMDS="mkdir touch mv rm ls grep cat vim"
USER=$1
2023-12-14 08:50:20 +00:00
CMDS=($CMDS) # convert to array
2023-12-14 09:06:15 +00:00
# Create user if not exist
2023-12-14 08:27:07 +00:00
if ! id "$USER" 2&>/dev/null; then
echo 'INFO: User not found'
echo 'Creating...'
useradd -m $USER
2023-12-14 09:06:15 +00:00
echo "Password for $USER:"
passwd $USER
2023-12-14 08:27:07 +00:00
fi
2023-12-14 09:06:15 +00:00
CHROOT=$(eval echo ~$USER)
2023-12-14 09:31:31 +00:00
# ChrootDirectory requires these permissions
chown root:root $CHROOT
chmod 745 $CHROOT
2023-12-14 09:15:12 +00:00
printf "Match User $USER\n ChrootDirectory $CHROOT" > /etc/ssh/sshd_config.d/70-$USER.conf
2023-12-14 09:06:15 +00:00
2023-12-14 08:27:07 +00:00
# cp in all commands and dependencies
for cmd in "${CMDS[@]}"; do
for dep in $( ldd $(which $cmd) | grep -v dynamic | cut -d " " -f 3 | sed 's/://' | sort | uniq ); do
cp --parents $dep $CHROOT
done
cp --parents $(which $cmd) $CHROOT
done
# cp user and group into chroot
2023-12-14 09:03:46 +00:00
mkdir -p $CHROOT/etc/
2023-12-14 08:27:07 +00:00
cat /etc/passwd | grep $USER > $CHROOT/etc/passwd
cat /etc/group | grep $USER > $CHROOT/etc/group
2023-12-14 09:27:11 +00:00
mkdir -p $CHROOT$CHROOT # make new home dir
2023-12-14 08:27:07 +00:00
SHELL=$(cat /etc/passwd | grep $USER | tr ":" "\n" | tail -n 1)
if [ ! -f $CHROOT$SHELL ]; then
echo "WARN: You didn't add the shell specified in /etc/passwd for $USER: ($SHELL)"
fi
# ARCH amd64
if [ -f /lib64/ld-linux-x86-64.so.2 ]; then
cp --parents /lib64/ld-linux-x86-64.so.2 /$CHROOT
fi
# ARCH i386
if [ -f /lib/ld-linux.so.2 ]; then
cp --parents /lib/ld-linux.so.2 /$CHROOT
fi
2023-12-14 09:32:30 +00:00
systemctl restart sshd
2023-12-14 08:27:07 +00:00
echo "NOTE: If you are using a shell that is NOT /bin/bash, you need to tell"
echo " chroot that by using: chroot $CHROOT {other shell path}"
echo ""
echo "Chroot jail is ready. To access it execute: chroot $CHROOT"