From 721a7d359012ea8830cea270cb9b9cd8e49bb95f Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Sat, 26 Sep 2026 11:05:08 +0200 Subject: [PATCH 1/2] askline: use bash, BusyBox ash has no read -e or -i With /bin/sh now BusyBox ash, askline fails before prompting: askline: read: line 13: illegal option -e This breaks the CLI edit command on string settings, datetime -e, and editing the boot order. Prefilling the line with the current value needs read -e -i, which only bash has. Signed-off-by: Joachim Wiberg --- board/common/rootfs/usr/bin/askline | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/board/common/rootfs/usr/bin/askline b/board/common/rootfs/usr/bin/askline index 7420b0d74..ec27c6d94 100755 --- a/board/common/rootfs/usr/bin/askline +++ b/board/common/rootfs/usr/bin/askline @@ -1,10 +1,9 @@ -#!/bin/sh +#!/bin/bash # Prompt for a single-line value, prefilled with the current one. # # askline LABEL FILE # # FILE holds the current value on entry and the new value on exit. -# shellcheck disable=SC3045 LABEL=$1 FILE=$2 From fa99387191dd12283f1ef61ca5ff222487002ce1 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Sat, 26 Sep 2026 11:05:12 +0200 Subject: [PATCH 2/2] askpass: abort on Ctrl-D, report errors on stderr The result of read was never checked, so Ctrl-D at the first prompt did not abort. askpass asked for the retype and only then failed with "Empty Passphrase, try again." The mismatch and empty errors went to stdout, which is where the encoded secret goes when no OUTPUT file is given. Signed-off-by: Joachim Wiberg --- board/common/rootfs/usr/bin/askpass | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/board/common/rootfs/usr/bin/askpass b/board/common/rootfs/usr/bin/askpass index 7c47f1d21..562bad0a1 100755 --- a/board/common/rootfs/usr/bin/askpass +++ b/board/common/rootfs/usr/bin/askpass @@ -20,18 +20,18 @@ if [ "$1" = "-b" ]; then fi OUTPUT=$1 -read -r -s -p "$LABEL: " secret +read -r -s -p "$LABEL: " secret || exit 1 >&2 echo -read -r -s -p "Retype $LABEL: " secret_again +read -r -s -p "Retype $LABEL: " secret_again || exit 1 >&2 echo if [ "$secret" != "$secret_again" ]; then - echo "${LABEL}s do not match, try again." + >&2 echo "${LABEL}s do not match, try again." exit 1 fi if [ -z "$secret" ]; then - echo "Empty $LABEL, try again." + >&2 echo "Empty $LABEL, try again." exit 1 fi