X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=scripts%2Fvuseradd;h=8023aa66043944a935dc8753906470d1ccccc89f;hb=61374297e8ff43ae7d704fbd20999d52eff6d23f;hp=f779ffc1d81ed76c09c913bc75012a95d753a87c;hpb=5dd1ea431149f8ef74242b68a22f940fea05c0e4;p=util-vserver.git diff --git a/scripts/vuseradd b/scripts/vuseradd index f779ffc..8023aa6 100755 --- a/scripts/vuseradd +++ b/scripts/vuseradd @@ -4,10 +4,10 @@ # # Copyright (c) 2004 The Trustees of Princeton University (Trustees). # -# $Id: vuseradd,v 1.11 2004/10/12 21:27:05 mlhuang Exp $ +# $Id: vuseradd,v 1.23 2005/08/21 21:41:03 mlhuang Exp $ # -: ${UTIL_VSERVER_VARS:=$(dirname $0)/util-vserver-vars} +: ${UTIL_VSERVER_VARS:=/usr/lib/util-vserver/util-vserver-vars} test -e "$UTIL_VSERVER_VARS" || { echo "Can not find util-vserver installation; aborting..." exit 1 @@ -21,79 +21,80 @@ usage() } [ -z "$1" ] && usage +[ "$1" == "--static" ] && { STATIC=yes; shift; } NAME=$1 # add slices group if not already present groupadd slices 2>/dev/null || : # add user -useradd -g slices -s /bin/vsh $NAME +[ -z "$STATIC" ] && useradd -g slices -s /bin/vsh $NAME -# automount keys -if [ -d "/var/pl_sshd/keys/$NAME" ]; then - # (eval expands ~) - eval rm -rf ~$NAME/.ssh - eval ln -nsf /var/pl_sshd/keys/$NAME ~$NAME/.ssh -fi +# openssh-server 3.8 and above refuse login for "locked" accounts +for file in /etc/passwd /etc/shadow ; do + [ -f $file ] && sed -i -e "s/$NAME:\!\!:\(.*\)/$NAME:*:\1/" $file +done -USERID=$(awk -F: "\$1 == \"$NAME\" { print \$3 }" < /etc/passwd) -GROUPID=$(awk -F: "\$1 == \"slices\" { print \$3 }" < /etc/group) +USERID=`id -u $NAME` +GROUPID=`id -g $NAME` +GROUPNAME=`id -gn $NAME` # create vserver configuration file -if [ ! -f /etc/vservers/$NAME.conf ] ; then +if [ ! -f $__CONFDIR/$NAME.conf ] ; then sed \ -e "s/.*S_CONTEXT=.*/S_CONTEXT=$USERID/" \ -e "s/.*ONBOOT=.*/ONBOOT=yes/" \ - < $PKGLIBDIR/sample.conf \ - > /etc/vservers/$NAME.conf + < $__PKGLIBDIR/defaults/sample.conf \ + > $__CONFDIR/$NAME.conf fi -if [ ! -d "$VROOTDIR/$NAME" ] ; then +if [ ! -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then # check the cache shopt -s nullglob - for i in "$VROOTDIR/.vcache/"* ; do - [ -d "$i" ] && mv "$i" "$VROOTDIR/$NAME" && break + for i in "$__DEFAULT_VSERVERDIR/.vcache/"* ; do + [ -d "$i" ] && mv "$i" "$__DEFAULT_VSERVERDIR/$NAME" && break done # build vserver - if [ ! -d "$VROOTDIR/$NAME" ] ; then - # build image in .vtmp - TMP=$(mktemp -d "$VROOTDIR/.vtmp/$NAME.XXXXXX") - "$PKGLIBDIR/vbuild" "$VROOTDIR/vserver-reference" "$TMP" + if [ ! -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then + # build in temporary directory + TMP=$(mktemp -d "$__DEFAULT_VSERVERDIR/.$NAME.XXXXXX") + "$__PKGLIBDIR/vbuild" "$__DEFAULT_VSERVERDIR/vserver-reference" "$TMP" RETVAL=$? - # move it to .vcache when complete - if [ $RETVAL -ne 0 ] || \ - [ $(du -s "$TMP" | awk "{ print \$1 }") -lt \ - $(du -s "$VROOTDIR/vserver-reference" | awk "{ print \$1 }") ] ; then - echo "Error $RETVAL building $VROOTDIR/$NAME" - chattr -R -i "$TMP" - rm -rf "$TMP" + # move it to its permanent location when complete + if [ $RETVAL -ne 0 ] ; then + echo "Error $RETVAL building $__DEFAULT_VSERVERDIR/$NAME" + rm -rf "$TMP" $__CONFDIR/$NAME.conf $__PKGSTATEDIR/$NAME.ctx + userdel -r $NAME exit $RETVAL else - mv "$TMP" "$VROOTDIR/$NAME" + # sanity check + vnewsize=$(du -s "$TMP" | awk "{ print \$1 }") + vrefsize=$(du -s "$__DEFAULT_VSERVERDIR/vserver-reference" | awk "{ print \$1 }") + if [ $vnewsize -lt $vrefsize ] ; then + echo "WARNING: Unexpected for 'du -s $__DEFAULT_VSERVERDIR/$NAME'=$vnewsize to be less than 'du -s $__DEFAULT_VSERVERDIR/vserver-reference'=$vrefsize" + fi + + mv "$TMP" "$__DEFAULT_VSERVERDIR/$NAME" fi fi fi -if [ -d "$VROOTDIR/$NAME" ] ; then +if [ -d "$__DEFAULT_VSERVERDIR/$NAME" ] ; then # fix permissions - chmod 755 "$VROOTDIR/$NAME" + chmod 755 "$__DEFAULT_VSERVERDIR/$NAME" # add user in vserver - vserver $NAME suexec root groupadd -g $GROUPID slices - vserver $NAME suexec root useradd -u $USERID -g $GROUPID -p '' $NAME + $_VSERVER_LEGACY $NAME suexec root sh -c \ + "groupadd -g $GROUPID $GROUPNAME ; useradd -u $USERID -g $GROUPID -p '' $NAME" # add an unrestricted entry to /etc/sudoers file - if [ -f "$VROOTDIR/$NAME/etc/sudoers" ] && \ - ! grep -q "^$NAME" "$VROOTDIR/$NAME/etc/sudoers" ; then - echo "$NAME ALL=(ALL) ALL" >> "$VROOTDIR/$NAME/etc/sudoers" + if [ -f "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" ] && \ + ! grep -q "^$NAME" "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" ; then + echo "$NAME ALL=(ALL) ALL" >> "$__DEFAULT_VSERVERDIR/$NAME/etc/sudoers" fi fi # turn resource management on for vserver $NAME -[ -x /usr/sbin/vs2ckrm ] && /usr/sbin/vs2ckrm on $NAME -[ -x /usr/sbin/cpulimit ] && /usr/sbin/cpulimit on $NAME -[ -x /usr/sbin/tasklimit ] && /usr/sbin/tasklimit on $NAME -[ -x /usr/sbin/iolimit ] && /usr/sbin/iolimit on $NAME -[ -x /usr/sbin/memlimit ] && /usr/sbin/memlimit on $NAME -[ -x /usr/sbin/bwlimit ] && /usr/sbin/bwlimit on $NAME -[ -x /usr/sbin/disklimit ] && /usr/sbin/disklimit on $NAME +chkconfig resman && service resman start $NAME +# XXX - resman doesn't print a trailing newline +echo