mirror of
https://github.com/certbot/certbot.git
synced 2026-08-01 19:02:52 +02:00
Move sudo to the top
(So that people who want to audit can see it quickly)
This commit is contained in:
committed by
Erik Rose
parent
5aa9fe9e7f
commit
8a3bbf97e0
@@ -15,6 +15,42 @@ VENV_PATH=${VENV_PATH:-"$XDG_DATA_HOME/$VENV_NAME"}
|
|||||||
VENV_BIN=${VENV_PATH}/bin
|
VENV_BIN=${VENV_PATH}/bin
|
||||||
LE_AUTO_VERSION="{{ LE_AUTO_VERSION }}"
|
LE_AUTO_VERSION="{{ LE_AUTO_VERSION }}"
|
||||||
|
|
||||||
|
# letsencrypt-auto needs root access to bootstrap OS dependencies, and
|
||||||
|
# letsencrypt itself needs root access for almost all modes of operation
|
||||||
|
# The "normal" case is that sudo is used for the steps that need root, but
|
||||||
|
# this script *can* be run as root (not recommended), or fall back to using
|
||||||
|
# `su`
|
||||||
|
if test "`id -u`" -ne "0" ; then
|
||||||
|
if command -v sudo 1>/dev/null 2>&1; then
|
||||||
|
SUDO=sudo
|
||||||
|
else
|
||||||
|
echo \"sudo\" is not available, will use \"su\" for installation steps...
|
||||||
|
# Because the parameters in `su -c` has to be a string,
|
||||||
|
# we need properly escape it
|
||||||
|
su_sudo() {
|
||||||
|
args=""
|
||||||
|
# This `while` loop iterates over all parameters given to this function.
|
||||||
|
# For each parameter, all `'` will be replace by `'"'"'`, and the escaped string
|
||||||
|
# will be wrapped in a pair of `'`, then appended to `$args` string
|
||||||
|
# For example, `echo "It's only 1\$\!"` will be escaped to:
|
||||||
|
# 'echo' 'It'"'"'s only 1$!'
|
||||||
|
# │ │└┼┘│
|
||||||
|
# │ │ │ └── `'s only 1$!'` the literal string
|
||||||
|
# │ │ └── `\"'\"` is a single quote (as a string)
|
||||||
|
# │ └── `'It'`, to be concatenated with the strings following it
|
||||||
|
# └── `echo` wrapped in a pair of `'`, it's totally fine for the shell command itself
|
||||||
|
while [ $# -ne 0 ]; do
|
||||||
|
args="$args'$(printf "%s" "$1" | sed -e "s/'/'\"'\"'/g")' "
|
||||||
|
shift
|
||||||
|
done
|
||||||
|
su root -c "$args"
|
||||||
|
}
|
||||||
|
SUDO=su_sudo
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
SUDO=
|
||||||
|
fi
|
||||||
|
|
||||||
ExperimentalBootstrap() {
|
ExperimentalBootstrap() {
|
||||||
# Arguments: Platform name, bootstrap function name
|
# Arguments: Platform name, bootstrap function name
|
||||||
if [ "$DEBUG" = 1 ]; then
|
if [ "$DEBUG" = 1 ]; then
|
||||||
@@ -120,42 +156,6 @@ for arg in "$@" ; do
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
# letsencrypt-auto needs root access to bootstrap OS dependencies, and
|
|
||||||
# letsencrypt itself needs root access for almost all modes of operation
|
|
||||||
# The "normal" case is that sudo is used for the steps that need root, but
|
|
||||||
# this script *can* be run as root (not recommended), or fall back to using
|
|
||||||
# `su`
|
|
||||||
if test "`id -u`" -ne "0" ; then
|
|
||||||
if command -v sudo 1>/dev/null 2>&1; then
|
|
||||||
SUDO=sudo
|
|
||||||
else
|
|
||||||
echo \"sudo\" is not available, will use \"su\" for installation steps...
|
|
||||||
# Because the parameters in `su -c` has to be a string,
|
|
||||||
# we need properly escape it
|
|
||||||
su_sudo() {
|
|
||||||
args=""
|
|
||||||
# This `while` loop iterates over all parameters given to this function.
|
|
||||||
# For each parameter, all `'` will be replace by `'"'"'`, and the escaped string
|
|
||||||
# will be wrapped in a pair of `'`, then appended to `$args` string
|
|
||||||
# For example, `echo "It's only 1\$\!"` will be escaped to:
|
|
||||||
# 'echo' 'It'"'"'s only 1$!'
|
|
||||||
# │ │└┼┘│
|
|
||||||
# │ │ │ └── `'s only 1$!'` the literal string
|
|
||||||
# │ │ └── `\"'\"` is a single quote (as a string)
|
|
||||||
# │ └── `'It'`, to be concatenated with the strings following it
|
|
||||||
# └── `echo` wrapped in a pair of `'`, it's totally fine for the shell command itself
|
|
||||||
while [ $# -ne 0 ]; do
|
|
||||||
args="$args'$(printf "%s" "$1" | sed -e "s/'/'\"'\"'/g")' "
|
|
||||||
shift
|
|
||||||
done
|
|
||||||
su root -c "$args"
|
|
||||||
}
|
|
||||||
SUDO=su_sudo
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
SUDO=
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "$1" = "--no-self-upgrade" ]; then
|
if [ "$1" = "--no-self-upgrade" ]; then
|
||||||
# Phase 2: Create venv, install LE, and run.
|
# Phase 2: Create venv, install LE, and run.
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user