summaryrefslogtreecommitdiff
path: root/src/opt
diff options
context:
space:
mode:
authorJohn Estabrook <jestabro@vyos.io>2025-06-03 09:10:43 -0500
committerGitHub <noreply@github.com>2025-06-03 09:10:43 -0500
commita26d3fcd3cb76d6cd56081c3eed6aad56a91563a (patch)
tree2d978a4bf03b7d11d200d1b2940d8cfd7fb1ef45 /src/opt
parentc32b30f1e8f560bff935c48a7b4d1993b3a622a5 (diff)
parent6b562aae240927c14f629b9307583013bc3a9008 (diff)
downloadvyos-1x-a26d3fcd3cb76d6cd56081c3eed6aad56a91563a.tar.gz
vyos-1x-a26d3fcd3cb76d6cd56081c3eed6aad56a91563a.zip
Merge pull request #4512 from dmbaturin/T7459-no-direct-sudo-in-op-mode
op-mode: T7459: eliminate direct use of sudo in op mode commands
Diffstat (limited to 'src/opt')
-rw-r--r--src/opt/vyatta/share/vyatta-op/functions/interpreter/vyatta-op-run17
1 files changed, 14 insertions, 3 deletions
diff --git a/src/opt/vyatta/share/vyatta-op/functions/interpreter/vyatta-op-run b/src/opt/vyatta/share/vyatta-op/functions/interpreter/vyatta-op-run
index f0479ae88..6bc77b61d 100644
--- a/src/opt/vyatta/share/vyatta-op/functions/interpreter/vyatta-op-run
+++ b/src/opt/vyatta/share/vyatta-op/functions/interpreter/vyatta-op-run
@@ -222,10 +222,21 @@ _vyatta_op_run ()
local cmd_regex="^(LESSOPEN=|less|pager|tail|(sudo )?$file_cmd).*"
if [ -n "$run_cmd" ]; then
eval $restore_shopts
- if [[ -t 1 && "${args[1]}" == "show" && ! $run_cmd =~ $cmd_regex ]] ; then
- eval "($run_cmd) | ${VYATTA_PAGER:-cat}"
- else
+ if [[ "${args[1]}" == "configure" ]]; then
+ # The "configure" command modifies the shell environment
+ # and must run in the current shell.
+ eval "$run_cmd"
+ elif [[ "${args[1]} ${args[2]}" =~ ^set[[:space:]]+(builtin|terminal) ]]; then
+ # Some commands like "set terminal width"
+ # only affect the user shell
+ # (so they don't need special privileges)
+ # and must be executed directly in the current shell
+ # to be able to do their job.
eval "$run_cmd"
+ elif [[ -t 1 && "${args[1]}" == "show" && ! $run_cmd =~ $cmd_regex ]] ; then
+ eval "(sudo $run_cmd) | ${VYATTA_PAGER:-cat}"
+ else
+ eval "sudo $run_cmd"
fi
else
echo -ne "\n Incomplete command: ${args[@]}\n\n" >&2