1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
1 |
# IVLE - Informatics Virtual Learning Environment
|
2 |
# Copyright (C) 2007-2008 The University of Melbourne
|
|
3 |
#
|
|
4 |
# This program is free software; you can redistribute it and/or modify
|
|
5 |
# it under the terms of the GNU General Public License as published by
|
|
6 |
# the Free Software Foundation; either version 2 of the License, or
|
|
7 |
# (at your option) any later version.
|
|
8 |
#
|
|
9 |
# This program is distributed in the hope that it will be useful,
|
|
10 |
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
11 |
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
12 |
# GNU General Public License for more details.
|
|
13 |
#
|
|
14 |
# You should have received a copy of the GNU General Public License
|
|
15 |
# along with this program; if not, write to the Free Software
|
|
16 |
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
17 |
||
18 |
# Module: MakeUser
|
|
19 |
# Author: Matt Giuca
|
|
20 |
# Date: 1/2/2008
|
|
21 |
||
22 |
# Allows creation of users. This sets up the following:
|
|
23 |
# * User's jail and home directory within the jail.
|
|
24 |
# * Subversion repository (TODO)
|
|
25 |
# * Check out Subversion workspace into jail (TODO)
|
|
26 |
# * Database details for user
|
|
27 |
# * Unix user account
|
|
28 |
||
29 |
# TODO: Sanitize login name and other fields.
|
|
30 |
# Users must not be called "temp" or "template".
|
|
31 |
||
32 |
# TODO: When creating a new home directory, chown it to its owner
|
|
33 |
||
34 |
# TODO: In chown_to_webserver:
|
|
35 |
# Do not call os.system("chown www-data") - use Python lib
|
|
36 |
# and use the web server uid given in conf. (Several places).
|
|
37 |
||
38 |
import md5 |
|
39 |
import os |
|
40 |
import stat |
|
41 |
import shutil |
|
42 |
import time |
|
43 |
import uuid |
|
44 |
import warnings |
|
45 |
import filecmp |
|
46 |
import logging |
|
47 |
import ivle.conf |
|
48 |
import ivle.db |
|
49 |
import ivle.pulldown_subj |
|
50 |
||
51 |
def chown_to_webserver(filename): |
|
52 |
"""
|
|
53 |
Chowns a file so the web server user owns it.
|
|
54 |
(This is useful in setting up Subversion conf files).
|
|
55 |
Assumes root.
|
|
56 |
"""
|
|
57 |
try: |
|
58 |
os.system("chown -R www-data:www-data %s" % filename) |
|
59 |
except: |
|
60 |
pass
|
|
61 |
||
62 |
def make_svn_repo(path, throw_on_error=True): |
|
63 |
"""Create a Subversion repository at the given path.
|
|
64 |
"""
|
|
65 |
try: |
|
66 |
res = os.system("svnadmin create '%s'" % path) |
|
67 |
if res != 0 and throw_on_error: |
|
68 |
raise Exception("Cannot create repository: %s" % path) |
|
69 |
except Exception, exc: |
|
70 |
print repr(exc) |
|
71 |
if throw_on_error: |
|
72 |
raise
|
|
73 |
||
74 |
chown_to_webserver(path) |
|
75 |
||
76 |
def rebuild_svn_config(): |
|
77 |
"""Build the complete SVN configuration file.
|
|
78 |
"""
|
|
79 |
conn = ivle.db.DB() |
|
80 |
users = conn.get_users() |
|
81 |
groups = {} |
|
82 |
for u in users: |
|
83 |
role = str(u.role) |
|
84 |
if role not in groups: |
|
85 |
groups[role] = [] |
|
86 |
groups[role].append(u.login) |
|
87 |
f = open(ivle.conf.svn_conf + ".new", "w") |
|
88 |
f.write("# IVLE SVN Repositories Configuration\n") |
|
89 |
f.write("# Auto-generated on %s\n" % time.asctime()) |
|
90 |
f.write("\n") |
|
91 |
f.write("[groups]\n") |
|
92 |
for (g,ls) in groups.iteritems(): |
|
93 |
f.write("%s = %s\n" % (g, ",".join(ls))) |
|
94 |
f.write("\n") |
|
95 |
for u in users: |
|
96 |
f.write("[%s:/]\n" % u.login) |
|
97 |
f.write("%s = rw\n" % u.login) |
|
98 |
#f.write("@tutor = r\n")
|
|
99 |
#f.write("@lecturer = rw\n")
|
|
100 |
#f.write("@admin = rw\n")
|
|
101 |
f.write("\n") |
|
102 |
f.close() |
|
103 |
os.rename(ivle.conf.svn_conf + ".new", ivle.conf.svn_conf) |
|
104 |
chown_to_webserver(ivle.conf.svn_conf) |
|
105 |
||
106 |
def rebuild_svn_group_config(): |
|
107 |
"""Build the complete SVN configuration file for groups
|
|
108 |
"""
|
|
109 |
conn = ivle.db.DB() |
|
110 |
groups = conn.get_all('project_group', |
|
111 |
['groupid', 'groupnm', 'projectsetid']) |
|
112 |
f = open(ivle.conf.svn_group_conf + ".new", "w") |
|
113 |
f.write("# IVLE SVN Group Repositories Configuration\n") |
|
114 |
f.write("# Auto-generated on %s\n" % time.asctime()) |
|
115 |
f.write("\n") |
|
116 |
for g in groups: |
|
117 |
projectsetid = g['projectsetid'] |
|
118 |
offeringinfo = conn.get_offering_info(projectsetid) |
|
119 |
subj_short_name = offeringinfo['subj_short_name'] |
|
120 |
year = offeringinfo['year'] |
|
121 |
semester = offeringinfo['semester'] |
|
122 |
reponame = "_".join([subj_short_name, year, semester, g['groupnm']]) |
|
123 |
f.write("[%s:/]\n"%reponame) |
|
124 |
users = conn.get_projectgroup_members(g['groupid']) |
|
125 |
for u in users: |
|
126 |
f.write("%s = rw\n"%u['login']) |
|
127 |
f.write("\n") |
|
128 |
f.close() |
|
129 |
os.rename(ivle.conf.svn_group_conf + ".new", ivle.conf.svn_group_conf) |
|
130 |
chown_to_webserver(ivle.conf.svn_group_conf) |
|
131 |
||
132 |
def make_svn_auth(login, throw_on_error=True): |
|
133 |
"""Setup svn authentication for the given user.
|
|
134 |
FIXME: create local.auth entry
|
|
135 |
"""
|
|
136 |
passwd = md5.new(uuid.uuid4().bytes).digest().encode('hex') |
|
137 |
if os.path.exists(ivle.conf.svn_auth_ivle): |
|
138 |
create = "" |
|
139 |
else: |
|
140 |
create = "c" |
|
141 |
||
142 |
ivle.db.DB().update_user(login, svn_pass=passwd) |
|
143 |
||
144 |
res = os.system("htpasswd -%smb %s %s %s" % (create, |
|
145 |
ivle.conf.svn_auth_ivle, |
|
146 |
login, passwd)) |
|
147 |
if res != 0 and throw_on_error: |
|
148 |
raise Exception("Unable to create ivle-auth for %s" % login) |
|
149 |
||
150 |
# Make sure the file is owned by the web server
|
|
151 |
if create == "c": |
|
152 |
chown_to_webserver(ivle.conf.svn_auth_ivle) |
|
153 |
||
154 |
return passwd |
|
155 |
||
156 |
def generate_manifest(basedir, targetdir, parent=''): |
|
157 |
""" From a basedir and a targetdir work out which files are missing or out
|
|
158 |
of date and need to be added/updated and which files are redundant and need
|
|
159 |
to be removed.
|
|
160 |
|
|
161 |
parent: This is used for the recursive call to track the relative paths
|
|
162 |
that we have decended.
|
|
163 |
"""
|
|
164 |
||
165 |
cmp = filecmp.dircmp(basedir, targetdir) |
|
166 |
||
167 |
# Add all new files and files that have changed
|
|
168 |
to_add = [os.path.join(parent,x) for x in (cmp.left_only + cmp.diff_files)] |
|
169 |
||
170 |
# Remove files that are redundant
|
|
171 |
to_remove = [os.path.join(parent,x) for x in cmp.right_only] |
|
172 |
||
173 |
# Recurse
|
|
174 |
for d in cmp.common_dirs: |
|
175 |
newbasedir = os.path.join(basedir, d) |
|
176 |
newtargetdir = os.path.join(targetdir, d) |
|
177 |
newparent = os.path.join(parent, d) |
|
178 |
(sadd,sremove) = generate_manifest(newbasedir, newtargetdir, newparent) |
|
179 |
to_add += sadd |
|
180 |
to_remove += sremove |
|
181 |
||
182 |
return (to_add, to_remove) |
|
183 |
||
184 |
||
185 |
def make_jail(username, uid, force=True, svn_pass=None): |
|
186 |
"""Creates a new user's jail space, in the jail directory as configured in
|
|
187 |
conf.py.
|
|
188 |
||
189 |
This only creates things within /home - everything else is expected to be
|
|
190 |
part of another UnionFS branch.
|
|
191 |
||
192 |
Returns the path to the user's home directory.
|
|
193 |
||
194 |
Chowns the user's directory within the jail to the given UID.
|
|
195 |
||
196 |
Note: This takes separate username and uid arguments. The UID need not
|
|
197 |
*necessarily* correspond to a Unix username at all, if all you are
|
|
198 |
planning to do is setuid to it. This allows the caller the freedom of
|
|
199 |
deciding the binding between username and uid, if any.
|
|
200 |
||
201 |
force: If false, exception if jail already exists for this user.
|
|
202 |
If true (default), overwrites it, but preserves home directory.
|
|
203 |
||
204 |
svn_pass: If provided this will be a string, the randomly-generated
|
|
205 |
Subversion password for this user (if you happen to already have it).
|
|
206 |
If not provided, it will be read from the database.
|
|
207 |
"""
|
|
208 |
# MUST run as root or some of this may fail
|
|
209 |
if os.getuid() != 0: |
|
210 |
raise Exception("Must run make_jail as root") |
|
211 |
||
212 |
# tempdir is for putting backup homes in
|
|
213 |
tempdir = os.path.join(ivle.conf.jail_base, '__temp__') |
|
214 |
if not os.path.exists(tempdir): |
|
215 |
os.makedirs(tempdir) |
|
216 |
elif not os.path.isdir(tempdir): |
|
217 |
os.unlink(tempdir) |
|
218 |
os.mkdir(tempdir) |
|
219 |
userdir = os.path.join(ivle.conf.jail_src_base, username) |
|
220 |
homedir = os.path.join(userdir, 'home') |
|
221 |
userhomedir = os.path.join(homedir, username) # Return value |
|
222 |
||
223 |
if os.path.exists(userdir): |
|
224 |
if not force: |
|
225 |
raise Exception("User's jail already exists") |
|
226 |
# User jail already exists. Blow it away but preserve their home
|
|
227 |
# directory. It should be all that is there anyway, but you never
|
|
228 |
# know!
|
|
229 |
# Ignore warnings about the use of tmpnam
|
|
230 |
warnings.simplefilter('ignore') |
|
231 |
homebackup = os.tempnam(tempdir) |
|
232 |
warnings.resetwarnings() |
|
233 |
# Note: shutil.move does not behave like "mv" - it does not put a file
|
|
234 |
# into a directory if it already exists, just fails. Therefore it is
|
|
235 |
# not susceptible to tmpnam symlink attack.
|
|
236 |
shutil.move(homedir, homebackup) |
|
237 |
shutil.rmtree(userdir) |
|
238 |
os.makedirs(homedir) |
|
239 |
shutil.move(homebackup, homedir) |
|
240 |
# Change the ownership of all the files to the right unixid
|
|
241 |
logging.debug("chown %s's home directory files to uid %d" |
|
242 |
%(username, uid)) |
|
243 |
os.chown(userhomedir, uid, uid) |
|
244 |
for root, dirs, files in os.walk(userhomedir): |
|
245 |
for fsobj in dirs + files: |
|
246 |
os.chown(os.path.join(root, fsobj), uid, uid) |
|
247 |
else: |
|
248 |
# No user jail exists
|
|
249 |
# Set up the user's home directory
|
|
250 |
os.makedirs(userhomedir) |
|
251 |
# Chown (and set the GID to the same as the UID).
|
|
252 |
os.chown(userhomedir, uid, uid) |
|
253 |
# Chmod to rwxr-xr-x (755)
|
|
254 |
os.chmod(userhomedir, 0755) |
|
255 |
||
256 |
# There are 2 special files which need to be generated specific to this
|
|
257 |
# user: ${python_site_packages}/lib/conf/conf.py and /etc/passwd.
|
|
258 |
# "__" username "__" users are exempt (special)
|
|
259 |
if not (username.startswith("__") and username.endswith("__")): |
|
260 |
make_conf_py(username, userdir, ivle.conf.jail_system, svn_pass) |
|
261 |
make_etc_passwd(username, userdir, ivle.conf.jail_system, uid) |
|
262 |
||
263 |
return userhomedir |
|
264 |
||
265 |
def make_conf_py(username, user_jail_dir, staging_dir, svn_pass=None): |
|
266 |
"""
|
|
267 |
Creates (overwriting any existing file, and creating directories) a
|
|
268 |
file ${python_site_packages}/ivle/conf/conf.py in a given user's jail.
|
|
269 |
username: Username.
|
|
270 |
user_jail_dir: User's jail dir, ie. ivle.conf.jail_base + username
|
|
271 |
staging_dir: The dir with the staging copy of the jail. (With the
|
|
272 |
template conf.py file).
|
|
273 |
svn_pass: As with make_jail. User's SVN password, but if not supplied,
|
|
274 |
will look up in the DB.
|
|
275 |
"""
|
|
276 |
template_conf_path = os.path.join(staging_dir, |
|
277 |
ivle.conf.python_site_packages[1:], "ivle/conf/conf.py") |
|
278 |
conf_path = os.path.join(user_jail_dir, |
|
279 |
ivle.conf.python_site_packages[1:], "ivle/conf/conf.py") |
|
280 |
os.makedirs(os.path.dirname(conf_path)) |
|
281 |
||
282 |
# If svn_pass isn't supplied, grab it from the DB
|
|
283 |
if svn_pass is None: |
|
284 |
dbconn = ivle.db.DB() |
|
285 |
svn_pass = dbconn.get_user(username).svn_pass |
|
286 |
dbconn.close() |
|
287 |
||
288 |
# Read the contents of the template conf file
|
|
289 |
try: |
|
290 |
template_conf_file = open(template_conf_path, "r") |
|
291 |
template_conf_data = template_conf_file.read() |
|
292 |
template_conf_file.close() |
|
293 |
except: |
|
294 |
# Couldn't open template conf.py for some reason
|
|
295 |
# Just treat it as empty file
|
|
296 |
template_conf_data = ("# Warning: Problem building config script.\n" |
|
297 |
"# Could not find template conf.py file.\n") |
|
298 |
||
299 |
conf_file = open(conf_path, "w") |
|
300 |
conf_file.write(template_conf_data) |
|
301 |
conf_file.write("\n# The login name for the owner of the jail\n") |
|
302 |
conf_file.write("login = %s\n" % repr(username)) |
|
303 |
conf_file.write("\n") |
|
304 |
conf_file.write("# The subversion-only password for the owner of " |
|
305 |
"the jail\n") |
|
306 |
conf_file.write("svn_pass = %s\n" % repr(svn_pass)) |
|
307 |
conf_file.close() |
|
308 |
||
309 |
# Make this file world-readable
|
|
310 |
# (chmod 644 conf_path)
|
|
311 |
os.chmod(conf_path, stat.S_IRUSR | stat.S_IWUSR | stat.S_IRGRP |
|
312 |
| stat.S_IROTH) |
|
313 |
||
314 |
def make_etc_passwd(username, user_jail_dir, template_dir, unixid): |
|
315 |
"""
|
|
316 |
Creates /etc/passwd in the given user's jail. This will be identical to
|
|
317 |
that in the template jail, except for the added entry for this user.
|
|
318 |
"""
|
|
319 |
template_passwd_path = os.path.join(template_dir, "etc/passwd") |
|
320 |
passwd_path = os.path.join(user_jail_dir, "etc/passwd") |
|
321 |
passwd_dir = os.path.dirname(passwd_path) |
|
322 |
if not os.path.exists(passwd_dir): |
|
323 |
os.makedirs(passwd_dir) |
|
324 |
shutil.copy(template_passwd_path, passwd_path) |
|
325 |
passwd_file = open(passwd_path, 'a') |
|
326 |
passwd_file.write('%s:x:%d:%d::/home/%s:/bin/bash' |
|
327 |
% (username, unixid, unixid, username)) |
|
328 |
passwd_file.close() |
|
329 |
||
330 |
def make_user_db(throw_on_error = True, **kwargs): |
|
331 |
"""Creates a user's entry in the database, filling in all the fields.
|
|
332 |
All arguments must be keyword args. They are the fields in the table.
|
|
333 |
However, instead of supplying a "passhash", you must supply a
|
|
334 |
"password" argument, which will be hashed internally.
|
|
335 |
Also do not supply a state. All users are created in the "no_agreement"
|
|
336 |
state.
|
|
337 |
Also pulls the user's subjects using the configured subject pulldown
|
|
338 |
module, and adds enrolments to the DB.
|
|
339 |
Throws an exception if the user already exists.
|
|
340 |
"""
|
|
341 |
dbconn = ivle.db.DB() |
|
342 |
dbconn.create_user(**kwargs) |
|
343 |
dbconn.close() |
|
344 |
||
345 |
if kwargs['password']: |
|
346 |
if os.path.exists(ivle.conf.svn_auth_local): |
|
347 |
create = "" |
|
348 |
else: |
|
349 |
create = "c" |
|
350 |
res = os.system("htpasswd -%smb %s %s %s" % (create, |
|
351 |
ivle.conf.svn_auth_local, |
|
352 |
kwargs['login'], |
|
353 |
kwargs['password'])) |
|
354 |
if res != 0 and throw_on_error: |
|
355 |
raise Exception("Unable to create local-auth for %s" % kwargs['login']) |
|
356 |
||
357 |
# Make sure the file is owned by the web server
|
|
358 |
if create == "c": |
|
359 |
chown_to_webserver(ivle.conf.svn_auth_local) |
|
360 |
||
361 |
# Pulldown subjects and add enrolments
|
|
362 |
ivle.pulldown_subj.enrol_user(kwargs['login']) |
|
363 |
||
364 |
def mount_jail(login): |
|
365 |
# This is where we'll mount to...
|
|
366 |
destdir = os.path.join(ivle.conf.jail_base, login) |
|
367 |
# ... and this is where we'll get the user bits.
|
|
368 |
srcdir = os.path.join(ivle.conf.jail_src_base, login) |
|
369 |
try: |
|
370 |
if not os.path.exists(destdir): |
|
371 |
os.mkdir(destdir) |
|
372 |
if os.system('/bin/mount -t aufs -o dirs=%s:%s=ro none %s' |
|
373 |
% (srcdir, ivle.conf.jail_system, destdir)) == 0: |
|
374 |
logging.info("mounted user %s's jail." % login) |
|
375 |
else: |
|
376 |
logging.error("failed to mount user %s's jail!" % login) |
|
377 |
except Exception, message: |
|
378 |
logging.warning(str(message)) |