Arch Loop项目中如何无交互创建用户并设置密码?
Hey there! I feel your pain—repeating the Arch install process multiple times a day is such a drain, so automating it makes total sense. Let's figure out why your password setup trick is failing for TTY logins, and fix it with a reliable, non-interactive method.
Why Your Original Approach Isn't Working
The echo -e 'password\npassword\n' | passwd method can flake out in chroot environments because:
- Some versions of
passwdenforce TTY input checks (even when wrapped inbash -c), which can silently fail to set the password correctly. - The
-eflag forechomight behave differently in the chroot's shell environment, leading to malformed input that doesn't match what you expect.
You were on the right track with pre-encrypting passwords—this is the most reliable way to avoid interactive prompts entirely.
The Proper Non-Interactive Solution
We'll use crypt-format password hashes (which is what /etc/shadow stores) to set passwords directly, no passwd command hoops required. Here's how to implement it:
1. Safely Collect User Passwords
First, read passwords securely without echoing them to the terminal:
# Read non-root user details read -r -p "Enter non-root username: " USERNAME read -r -s -p "Enter $USERNAME password: " USER_PASSWORD echo read -r -s -p "Confirm $USERNAME password: " USER_PASSWORD_CONFIRM echo if [ "$USER_PASSWORD" != "$USER_PASSWORD_CONFIRM" ]; then echo "Error: Passwords don't match!" exit 1 fi # Read root password read -r -s -p "Enter root password: " ROOT_PASSWORD echo read -r -s -p "Confirm root password: " ROOT_PASSWORD_CONFIRM echo if [ "$ROOT_PASSWORD" != "$ROOT_PASSWORD_CONFIRM" ]; then echo "Error: Root passwords don't match!" exit 1 fi
2. Generate Encrypted Password Hashes
Use openssl (pre-installed on Arch install media) to generate SHA-512 hashes with random salts—this is secure and compliant with Arch's shadow file standards:
USER_ENCRYPTED=$(openssl passwd -6 "$USER_PASSWORD") ROOT_ENCRYPTED=$(openssl passwd -6 "$ROOT_PASSWORD")
The -6 flag specifies SHA-512, which is the default for Arch Linux.
3. Set Passwords in Chroot
Now apply these hashes directly to the user accounts:
# Create non-root user with pre-hashed password arch-chroot /mnt useradd -m -g users -G wheel -s /usr/bin/bash -p "$USER_ENCRYPTED" "$USERNAME" # Set root password using chpasswd (handles shadow file updates cleanly) arch-chroot /mnt bash -c "echo root:$ROOT_ENCRYPTED | chpasswd -e"
- The
-pflag foruseraddaccepts the pre-encrypted hash directly. chpasswd -etells the command we're passing encrypted hashes instead of plaintext.
4. Optional: Configure Sudo Access
If you haven't already, make sure the wheel group can use sudo:
arch-chroot /mnt sed -i 's/^# %wheel ALL=(ALL:ALL) ALL/%wheel ALL=(ALL:ALL) ALL/' /etc/sudoers
Why This Works
This method bypasses the interactive passwd command entirely, writing directly to the /etc/shadow file through trusted tools. It avoids TTY checks, shell inconsistencies, and ensures your passwords are stored securely with proper hashing.
内容的提问来源于stack exchange,提问作者Vasanth Srivatsa

