X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=scripts%2Fvuseradd;h=2be0ac9775b3cce7994f4f07e5082c0eaa0e0138;hb=49f2c3e784129bd7055258e42d66377083161e18;hp=177466aaf92b4e99787d495bbed2fd8b04ea2a37;hpb=ea93fb4bd90c6fd1073dd2c7c2bd05b0b1a843dd;p=util-vserver.git diff --git a/scripts/vuseradd b/scripts/vuseradd index 177466a..2be0ac9 100755 --- a/scripts/vuseradd +++ b/scripts/vuseradd @@ -4,7 +4,7 @@ # # Copyright (c) 2004 The Trustees of Princeton University (Trustees). # -# $Id: vuseradd,v 1.17 2004/11/17 19:35:47 mef Exp $ +# $Id: vuseradd,v 1.21 2005/04/26 21:23:28 mlhuang Exp $ # : ${UTIL_VSERVER_VARS:=$(dirname $0)/util-vserver-vars} @@ -21,16 +21,21 @@ usage() } [ -z "$1" ] && usage +[ "$1" == "--static" ] && { STATIC=yes; shift; } NAME=$1 # add slices group if not already present groupadd slices 2>/dev/null || : # add user -useradd -g slices -s /bin/vsh $NAME +[ -z "$STATIC" ] && useradd -g slices -s /bin/vsh $NAME -USERID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) -GROUPID=$(awk -F: "\$1 == \"slices\" { print \$3 }" < /etc/group) +# openssh-server 3.8 and above refuse login for "locked" accounts +sed -i -e "s/$NAME:\!\!:\(.*\)/$NAME:*:\1/" /etc/shadow + +USERID=`id -u $NAME` +GROUPID=`id -g $NAME` +GROUPNAME=`id -gn $NAME` # create vserver configuration file if [ ! -f /etc/vservers/$NAME.conf ] ; then @@ -56,9 +61,8 @@ if [ ! -d "$VROOTDIR/$NAME" ] ; then # move it to .vcache when complete if [ $RETVAL -ne 0 ] ; then echo "Error $RETVAL building $VROOTDIR/$NAME" - chattr -R -i "$TMP" - rm -rf "$TMP" - userdel $NAME + rm -rf "$TMP" /etc/vservers/$NAME.conf /var/run/vservers/$NAME.ctx + userdel -r $NAME exit $RETVAL else # sanity check @@ -78,7 +82,7 @@ if [ -d "$VROOTDIR/$NAME" ] ; then chmod 755 "$VROOTDIR/$NAME" # add user in vserver - vserver $NAME suexec root groupadd -g $GROUPID slices + vserver $NAME suexec root groupadd -g $GROUPID $GROUPNAME vserver $NAME suexec root useradd -u $USERID -g $GROUPID -p '' $NAME # add an unrestricted entry to /etc/sudoers file @@ -90,3 +94,5 @@ fi # turn resource management on for vserver $NAME service resman start $NAME +# XXX - resman doesn't print a trailing newline +echo