cancel a sudo askpass request

Viewed 182

I'm trying to use kdialog with sudo in a bash script, by exporting SUDO_ASKPASS to a script that has the line

kdialog --password "enter password: " 

and using sudo -A. This works well, except that if I click cancel in the dialogue, sudo ignores that, and retries the password entry after a delay. The one-line script exits with kdialog's exit status, which is non-zero if cancel is clicked.

Is there any way to persuade sudo to give up, as one can with the text interface by typing control-C?

Edit - eventually I worked out what was going on. If you click cancel, kdialog outputs a newline. Sudo --askpass interprets this as a blank password, and starts its wrong password processing. The askpass script must not emit that newline if cancel is clicked. A way to do this is

pe=$(kdialog --password 'enter password: ') && echo "$pe"
1 Answers

For this, after few tries, I now use the following workaround for the SUDO_ASKPASS script:

#!/bin/bash

kdialog --password 'Enter password: ' || kill -9 "${PPID}"

If the user chooses to cancel, then the calling process (the sudo command) is killed.

To mitigate the risk of killing your own process by error if you call the script directly from the command line, you can harden it:

#!/bin/bash

kdialog --password 'Enter password: ' || [ ! -z ${DIE_ON_CANCEL+x} ] && kill -9 "${PPID}"

Then, if you want to kill the process on cancel, the DIE_ON_CANCEL variable must be defined explicitly like this:

SUDO_ASKPASS='<your script>' DIE_ON_CANCEL=true sudo --askpass <your command here>

I don't like to use kill, but I don't see any other solution. Somebody has a better idea?

Related