[ECOS] any existing code about a prompt password for entering redboot ?
Andrew Lunn
andrew@lunn.ch
Fri Mar 31 12:51:00 GMT 2006
On Fri, Mar 31, 2006 at 01:28:27PM +0200, Rainer Arndt wrote:
> Hi Thierry
>
> I'm starting to work on the same feature. I suggest the following:
>
> Define a new CDL option. Make the new code dependent on the CDL option.
> The right point to start is main.c from redboot package. Define a new
> redboot command (see RedBoot_cmd macro) which should handle the password
> verification and set a flag if the right password is found.
>
> Then look at the code after the parse() function call. Allow command handler
> calls (cmd->func)() only if the password flag was set valid from the
> passwort command or if the current cmd even is the password command
> (cmd->str).
>
> You can use a fixed password defined in a CDL option or use redboot config
> entries to store individual passwords.
>
> This is a simple solution, but it fulfill my requirements.
> Any comments from the specialists?
So there seems to be more interest than i expect. So here is my code
from a long time ago.
You will need to work on the CDL. I had some local modifications to
make this work and i no longer have the code. It could be in the email
archive.
See the thread
http://sourceware.org/ml/ecos-patches/2002-11/msg00019.html
If i remeber correctly Bart suggested doing it a different way, but
i've not found that discuss thread yet.
Andrew
-------------- next part --------------
A non-text attachment was scrubbed...
Name: passwd.c
Type: text/x-csrc
Size: 7919 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/ecos-discuss/attachments/20060331/54e5e045/attachment.bin>
-------------- next part --------------
? cdl/redboot.cdl.safe
? src/passwd.c
Index: cdl/redboot.cdl
===================================================================
RCS file: /cvs/ecos/ecos/packages/redboot/current/cdl/redboot.cdl,v
retrieving revision 1.49
diff -u -r1.49 redboot.cdl
--- cdl/redboot.cdl 20 May 2003 18:43:51 -0000 1.49
+++ cdl/redboot.cdl 31 Mar 2006 11:18:20 -0000
@@ -199,6 +199,75 @@
# Implemented within the platform HAL
}
+ cdl_component CYGBLD_BUILD_REDBOOT_WITH_PASSWORD {
+ display "Prompt for a password to unlock the CLI"
+ flavor bool
+ requires { CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_FIXED !=
+ CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_FLASH }
+ default_value 0
+
+ compile -library=libextras.a passwd.c
+
+ cdl_option CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_ROT13 {
+ display "Obfusticate the password with ROT13"
+ flavor bool
+ active_if CYGPKG_ENCRYPT_ROT13
+ default_value 1
+ }
+
+ cdl_option CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_FLASH {
+ display "Store the password in flash"
+ flavor bool
+ active_if CYGSEM_REDBOOT_FLASH_CONFIG
+ default_value CYGSEM_REDBOOT_FLASH_CONFIG
+ }
+ cdl_component CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_FIXED {
+ display "Use a fixed value for the password"
+ flavor bool
+ default_value !CYGSEM_REDBOOT_FLASH_CONFIG
+
+ cdl_option CYGDAT_REDBOOT_PASSWD {
+ display "Password for RedBoot"
+ no_define
+ flavor data
+ default_value {"\"0penSezerU\""}
+
+ define_proc {
+proc rot13 { line } {
+ set string1 "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz"
+ set string2 "NOPQRSTUVWXYZABCDEFGHIJKLMnopqrstuvwxyzabcdefghijklm"
+ set newline ""
+ for { set num 0 } {$num < [string length $line]} {incr num 1} {
+ set char [string index $line $num]
+ set idx [string first $char $string1]
+ if {$idx >= 0} {
+ append newline [string index $string2 $idx]
+ } else {
+ append newline $char
+ }
+ }
+ return $newline
+}
+
+if {{} == [info commands get_value]} {
+ puts stderr "Your version of libcdl is too old to support configurations"
+ puts stderr "which include a fixed reboot password. Please either "
+ puts stderr "upgrade/recompile your configuration tool, or disable option"
+ puts stderr "CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_FIXED."
+ exit 1
+} else {
+ if { 1 == [is_active CYGBLD_BUILD_REDBOOT_WITH_PASSWORD_ROT13 ] } {
+ set password [rot13 [get_value CYGDAT_REDBOOT_PASSWD ]]
+ } else {
+ set password [get_value CYGDAT_REDBOOT_PASSWD ]
+ }
+ puts $::cdl_header "#define CYGDAT_REDBOOT_PASSWD $password"
+}
+ }
+ }
+ }
+ }
+
no_define
description "This option enables the building of the Redboot ELF image.
The image may require further relocation or symbol
Index: include/redboot.h
===================================================================
RCS file: /cvs/ecos/ecos/packages/redboot/current/include/redboot.h,v
retrieving revision 1.27
diff -u -r1.27 redboot.h
--- include/redboot.h 24 Aug 2002 11:34:50 -0000 1.27
+++ include/redboot.h 31 Mar 2006 11:18:20 -0000
@@ -137,6 +137,7 @@
// Result codes from 'gets()'
#define _GETS_TIMEOUT -1
#define _GETS_CTRLC -2
+#define _GETS_PASSWD -3
#define _GETS_GDB 0
#define _GETS_OK 1
@@ -150,6 +151,11 @@
#endif
externC void expand_aliases(char *line, int len);
+#ifdef CYGBLD_BUILD_REDBOOT_WITH_PASSWORD
+externC void get_password(char *line, const int size, const int timeout);
+#endif
+
+
//
// Stream I/O support
//
Index: src/flash.c
===================================================================
RCS file: /cvs/ecos/ecos/packages/redboot/current/src/flash.c,v
retrieving revision 1.46
diff -u -r1.46 flash.c
--- src/flash.c 14 May 2003 20:12:54 -0000 1.46
+++ src/flash.c 31 Mar 2006 11:18:21 -0000
@@ -2163,3 +2163,6 @@
#endif // CYGSEM_REDBOOT_FLASH_CONFIG
// EOF flash.c
+
+
+
Index: src/io.c
===================================================================
RCS file: /cvs/ecos/ecos/packages/redboot/current/src/io.c,v
retrieving revision 1.30
diff -u -r1.30 io.c
--- src/io.c 20 May 2003 18:43:52 -0000 1.30
+++ src/io.c 31 Mar 2006 11:18:21 -0000
@@ -337,6 +337,9 @@
int _index = _cl_index; // Last saved line
char *xp;
#endif
+#ifdef CYGBLD_BUILD_REDBOOT_WITH_PASSWORD
+ static bool passwd_time = true;
+#endif
// Display current buffer data
while (*eol) {
@@ -350,6 +353,12 @@
do_idle(false);
else
#endif
+#ifdef CYGBLD_BUILD_REDBOOT_WITH_PASSWORD
+ if (passwd_time) {
+ passwd_time = false;
+ return _GETS_PASSWD;
+ }
+#endif
if ((timeout > 0) && (eol == buf)) {
#define MIN_TIMEOUT 50
_timeout = timeout > MIN_TIMEOUT ? MIN_TIMEOUT : timeout;
Index: src/main.c
===================================================================
RCS file: /cvs/ecos/ecos/packages/redboot/current/src/main.c,v
retrieving revision 1.45
diff -u -r1.45 main.c
--- src/main.c 6 May 2003 21:00:21 -0000 1.45
+++ src/main.c 31 Mar 2006 11:18:21 -0000
@@ -311,6 +311,14 @@
if (res == _GETS_TIMEOUT) {
// No input arrived
} else {
+#ifdef CYGBLD_BUILD_REDBOOT_WITH_PASSWORD
+ if (res == _GETS_PASSWD) {
+ get_password(line, sizeof(line),
+ CYGNUM_REDBOOT_CLI_IDLE_TIMEOUT);
+ prompt = true;
+ continue;
+ }
+#endif
#ifdef CYGDBG_HAL_DEBUG_GDB_INCLUDE_STUBS
if (res == _GETS_GDB) {
int dbgchan;
-------------- next part --------------
--
Before posting, please read the FAQ: http://ecos.sourceware.org/fom/ecos
and search the list archive: http://ecos.sourceware.org/ml/ecos-discuss
More information about the Ecos-discuss
mailing list