X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=scripts%2Fvuseradd;h=2be0ac9775b3cce7994f4f07e5082c0eaa0e0138;hb=49f2c3e784129bd7055258e42d66377083161e18;hp=7c59e736718064748230839b47721a9324b72914;hpb=6fc1eb0a961d6ea174c33f875aa6e75672889ef2;p=util-vserver.git diff --git a/scripts/vuseradd b/scripts/vuseradd index 7c59e73..2be0ac9 100755 --- a/scripts/vuseradd +++ b/scripts/vuseradd @@ -4,7 +4,7 @@ # # Copyright (c) 2004 The Trustees of Princeton University (Trustees). # -# $Id: vuseradd,v 1.1 2004/07/30 16:46:41 mlh-pl_kernel Exp $ +# $Id: vuseradd,v 1.21 2005/04/26 21:23:28 mlhuang Exp $ # : ${UTIL_VSERVER_VARS:=$(dirname $0)/util-vserver-vars} @@ -21,25 +21,28 @@ usage() } [ -z "$1" ] && usage +[ "$1" == "--static" ] && { STATIC=yes; shift; } NAME=$1 -# add user -useradd -s /bin/vsh $NAME +# add slices group if not already present +groupadd slices 2>/dev/null || : -# change shell (in case user already exists) -usermod -s /bin/vsh $NAME +# add user +[ -z "$STATIC" ] && useradd -g slices -s /bin/vsh $NAME -# automount keys (eval expands ~) -eval rm -rf ~$NAME/.ssh -eval ln -sf /var/pl_sshd/keys/$NAME ~$NAME/.ssh +# openssh-server 3.8 and above refuse login for "locked" accounts +sed -i -e "s/$NAME:\!\!:\(.*\)/$NAME:*:\1/" /etc/shadow -USERID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) -GROUPID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) +USERID=`id -u $NAME` +GROUPID=`id -g $NAME` +GROUPNAME=`id -gn $NAME` # create vserver configuration file if [ ! -f /etc/vservers/$NAME.conf ] ; then - sed -e "s/#S_CONTEXT=/S_CONTEXT=$USERID/" \ - < /etc/vservers/vserver-reference.conf \ + sed \ + -e "s/.*S_CONTEXT=.*/S_CONTEXT=$USERID/" \ + -e "s/.*ONBOOT=.*/ONBOOT=yes/" \ + < $PKGLIBDIR/sample.conf \ > /etc/vservers/$NAME.conf fi @@ -54,13 +57,42 @@ if [ ! -d "$VROOTDIR/$NAME" ] ; then # build image in .vtmp TMP=$(mktemp -d "$VROOTDIR/.vtmp/$NAME.XXXXXX") "$PKGLIBDIR/vbuild" "$VROOTDIR/vserver-reference" "$TMP" + RETVAL=$? # move it to .vcache when complete - mv "$TMP" "$VROOTDIR/$NAME" + if [ $RETVAL -ne 0 ] ; then + echo "Error $RETVAL building $VROOTDIR/$NAME" + rm -rf "$TMP" /etc/vservers/$NAME.conf /var/run/vservers/$NAME.ctx + userdel -r $NAME + exit $RETVAL + else + # sanity check + vnewsize=$(du -s "$TMP" | awk "{ print \$1 }") + vrefsize=$(du -s "$VROOTDIR/vserver-reference" | awk "{ print \$1 }") + if [ $vnewsize -lt $vrefsize ] ; then + echo "WARNING: Unexpected for 'du -s $VROOTDIR/$NAME'=$vnewsize to be less than 'du -s $VROOTDIR/vserver-reference'=$vrefsize" + fi + + mv "$TMP" "$VROOTDIR/$NAME" + fi fi +fi + +if [ -d "$VROOTDIR/$NAME" ] ; then # fix permissions chmod 755 "$VROOTDIR/$NAME" + + # add user in vserver + vserver $NAME suexec root groupadd -g $GROUPID $GROUPNAME + vserver $NAME suexec root useradd -u $USERID -g $GROUPID -p '' $NAME + + # add an unrestricted entry to /etc/sudoers file + if [ -f "$VROOTDIR/$NAME/etc/sudoers" ] && \ + ! grep -q "^$NAME" "$VROOTDIR/$NAME/etc/sudoers" ; then + echo "$NAME ALL=(ALL) ALL" >> "$VROOTDIR/$NAME/etc/sudoers" + fi fi -# add user in vserver -vserver $NAME suexec root groupadd -g $GROUPID $NAME -vserver $NAME suexec root useradd -u $USERID -g $GROUPID -p '' $NAME +# turn resource management on for vserver $NAME +service resman start $NAME +# XXX - resman doesn't print a trailing newline +echo