X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=scripts%2Fvuseradd;h=23118bc81ce66d52b1bd34fb5a810799aa3b4ae3;hb=645ea33ea11c95013764e0eb7d955731315c22b5;hp=6e72bf5ea9de0614f439a3bffbb28bb86cb6abec;hpb=baf8d1ace0dec2a77e01b5cad29c9972c2e7e779;p=util-vserver.git diff --git a/scripts/vuseradd b/scripts/vuseradd index 6e72bf5..23118bc 100755 --- a/scripts/vuseradd +++ b/scripts/vuseradd @@ -2,68 +2,126 @@ # # useradd(8) wrapper for vservers # -# Copyright (c) 2004 The Trustees of Princeton University (Trustees). +# Mark Huang +# Copyright (C) 2004-2006 The Trustees of Princeton University # -# $Id: vuseradd,v 1.2 2004/08/19 22:30:30 mlh-pl_kernel Exp $ +# $Id: vuseradd,v 1.25 2005/11/08 00:22:59 smuir Exp $ # -: ${UTIL_VSERVER_VARS:=$(dirname $0)/util-vserver-vars} +: ${UTIL_VSERVER_VARS:=/usr/lib/util-vserver/util-vserver-vars} test -e "$UTIL_VSERVER_VARS" || { echo "Can not find util-vserver installation; aborting..." exit 1 } . "$UTIL_VSERVER_VARS" +shopt -s nullglob + +# Defaults +TYPE="default" + usage() { - echo "usage: $0 name" + TYPES= + pushd "$__DEFAULT_VSERVERDIR/.vref" >/dev/null + for ref in * ; do + if [ -z "$TYPES" ] ; then + TYPES=$ref + else + TYPES="$TYPES, $ref" + fi + done + popd >/dev/null + + echo "Usage: vuseradd [OPTION]... [NAME]" + echo " -t Reference image type ($TYPES)" exit 1 } +# Get options +while getopts "t:" opt ; do + case $opt in + t) + TYPE="$OPTARG" + ;; + *) + usage + ;; + esac +done +shift $(($OPTIND - 1)) + +# Get slice name [ -z "$1" ] && usage NAME=$1 -# bail on errors -set -e +# Add slices group to /etc/group if not already present +groupadd slices 2>/dev/null || : + +# Add slice name to /etc/passwd +useradd -g slices -s /bin/vsh $NAME + +# openssh-server 3.8 and above refuse login for "locked" accounts +for file in /etc/passwd /etc/shadow ; do + [ -f $file ] && sed -i -e "s/$NAME:\!\!:\(.*\)/$NAME:*:\1/" $file +done -# add user -useradd -s /bin/vsh $NAME +USERID=`id -u $NAME` +GROUPID=`id -g $NAME` +GROUPNAME=`id -gn $NAME` -# change shell (in case user already exists) -usermod -s /bin/vsh $NAME +# Create /etc/vservers configuration file +if [ ! -f $__CONFDIR/$NAME.conf ] ; then + sed \ + -e "s/.*S_CONTEXT=.*/S_CONTEXT=$USERID/" \ + -e "s/.*ONBOOT=.*/ONBOOT=yes/" \ + < $__PKGLIBDIR/defaults/sample.conf \ + > $__CONFDIR/$NAME.conf +fi + +if [ ! -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then + # Check the cache + if [ "$TYPE" = "default" ] ; then + for i in "$__DEFAULT_VSERVERDIR/.vcache/"* ; do + [ -d "$i" ] && mv "$i" "$__DEFAULT_VSERVERDIR/$NAME" && break + done + fi -# automount keys (eval expands ~) -eval rm -rf ~$NAME/.ssh -eval ln -nsf /var/pl_sshd/keys/$NAME ~$NAME/.ssh + # Build slice from reference image + if [ ! -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then + REF="$__DEFAULT_VSERVERDIR/.vref/$TYPE" -USERID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) -GROUPID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) + # Build in temporary directory + mkdir -p "$__DEFAULT_VSERVERDIR/.vtmp" + TMP=$(mktemp -d "$__DEFAULT_VSERVERDIR/.vtmp/$NAME.XXXXXX") + "$__PKGLIBDIR/vbuild" "$REF" "$TMP" + RETVAL=$? -# create vserver configuration file -if [ ! -f /etc/vservers/$NAME.conf ] ; then - sed -e "s/#S_CONTEXT=/S_CONTEXT=$USERID/" \ - < /etc/vservers/vserver-reference.conf \ - > /etc/vservers/$NAME.conf + # Move it to its permanent location when complete + if [ $RETVAL -eq 0 ] ; then + mv "$TMP" "$__DEFAULT_VSERVERDIR/$NAME" + else + echo "Error $RETVAL building $__DEFAULT_VSERVERDIR/$NAME" + rm -rf "$TMP" $__CONFDIR/$NAME.conf $__PKGSTATEDIR/$NAME.ctx + userdel -r $NAME + exit $RETVAL + fi + fi fi -if [ ! -d "$VROOTDIR/$NAME" ] ; then - # check the cache - shopt -s nullglob - for i in "$VROOTDIR/.vcache/"* ; do - [ -d "$i" ] && mv "$i" "$VROOTDIR/$NAME" && break - done - # build vserver - if [ ! -d "$VROOTDIR/$NAME" ] ; then - # build image in .vtmp - TMP=$(mktemp -d "$VROOTDIR/.vtmp/$NAME.XXXXXX") - "$PKGLIBDIR/vbuild" "$VROOTDIR/vserver-reference" "$TMP" - # move it to .vcache when complete - mv "$TMP" "$VROOTDIR/$NAME" +if [ -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then + # Fix permissions + chmod 755 "$__DEFAULT_VSERVERDIR/$NAME" + + # Add user in vserver + $_VSERVER_LEGACY $NAME suexec root sh -c \ + "groupadd -g $GROUPID $GROUPNAME ; useradd -u $USERID -g $GROUPID -p '' $NAME" + + # Add an unrestricted entry to /etc/sudoers file + if [ -f "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" ] && \ + ! grep -q "^$NAME" "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" ; then + echo "$NAME ALL=(ALL) ALL" >> "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" fi - # fix permissions - chmod 755 "$VROOTDIR/$NAME" fi -# add user in vserver -vserver $NAME suexec root groupadd -g $GROUPID $NAME -vserver $NAME suexec root useradd -u $USERID -g $GROUPID -p '' $NAME +exit 0