1
# IVLE - Informatics Virtual Learning Environment
2
# Copyright (C) 2007-2008 The University of Melbourne
4
# This program is free software; you can redistribute it and/or modify
5
# it under the terms of the GNU General Public License as published by
6
# the Free Software Foundation; either version 2 of the License, or
7
# (at your option) any later version.
9
# This program is distributed in the hope that it will be useful,
10
# but WITHOUT ANY WARRANTY; without even the implied warranty of
11
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12
# GNU General Public License for more details.
14
# You should have received a copy of the GNU General Public License
15
# along with this program; if not, write to the Free Software
16
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
18
# Module: setup/config
19
# Author: Matt Giuca, Refactored by David Coles
23
# Configures IVLE with machine-specific details, most notably, various paths.
24
# Either prompts the administrator for these details or accepts them as
26
# Creates lib/conf/conf.py and trampoline/conf.h.
34
from setup.setuputil import query_user
37
"""A configuration option; one of the things written to conf.py."""
38
def __init__(self, option_name, default, prompt, comment):
39
"""Creates a configuration option.
40
option_name: Name of the variable in conf.py. Also name of the
41
command-line argument to setup.py conf.
42
default: Default value for this variable.
43
prompt: (Short) string presented during the interactive prompt in
45
comment: (Long) comment string stored in conf.py. Each line of this
46
string should begin with a '#'.
48
self.option_name = option_name
49
self.default = default
51
self.comment = comment
53
# Configuration options, defaults and descriptions
55
config_options.append(ConfigOption("root_dir", "/",
56
"""Root directory where IVLE is located (in URL space):""",
58
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
60
# eg. "/" or "/ivle"."""))
61
config_options.append(ConfigOption("ivle_install_dir", "/opt/ivle",
62
'Root directory where IVLE will be installed (on the local file '
65
# In the local file system, where IVLE is actually installed.
66
# This directory should contain the "www" and "bin" directories."""))
67
config_options.append(ConfigOption("jail_base", "/home/informatics/jails",
68
"""Location of jail mountpoints
69
============================
70
Root directory where the user jails will be mounted, and the non-user
71
components of the jails will be stored (on the local file system):""",
73
# In the local file system, where the student/user jails will be mounted.
74
# Only a single copy of the jail's system components will be stored here -
75
# all user jails will be virtually mounted here."""))
76
config_options.append(ConfigOption("jail_system", "/home/informatics/jails/__base__",
77
"""Location of system jail components
78
==================================
79
Directory where the template system jail will be stored.""",
81
# In the local file system, where the template system jail will be stored."""))
82
config_options.append(ConfigOption("jail_src_base", "/home/informatics/jailssrc",
83
"""Location of user jail components
84
================================
85
Root directory where the user components of the jails will be stored (on the
86
local file system):""",
88
# In the local file system, where are the student/user file spaces located.
89
# The user jails are expected to be located immediately in subdirectories of
90
# this location. Note that no complete jails reside here - only user
92
config_options.append(ConfigOption("subjects_base",
93
"/home/informatics/subjects",
94
"""Root directory where the subject directories (containing worksheets
95
and other per-subject files) are stored (on the local file system):""",
97
# In the local file system, where are the per-subject file spaces located.
98
# The individual subject directories are expected to be located immediately
99
# in subdirectories of this location."""))
100
config_options.append(ConfigOption("exercises_base",
101
"/home/informatics/exercises",
102
"""Root directory where the exercise directories (containing
103
subject-independent exercise sheets) are stored (on the local file
106
# In the local file system, where are the subject-independent exercise sheet
107
# file spaces located."""))
108
config_options.append(ConfigOption("tos_path",
109
"/home/informatics/tos.html",
110
"""Location where the Terms of Service document is stored (on the local
113
# In the local file system, where is the Terms of Service document located."""))
114
config_options.append(ConfigOption("motd_path",
115
"/home/informatics/motd.html",
116
"""Location where the Message of the Day document is stored (on the local
119
# In the local file system, where is the Message of the Day document
120
# located. This is an HTML file (just the body fragment), which will
121
# be displayed on the login page. It is optional."""))
122
config_options.append(ConfigOption("log_path",
123
"/home/informatics/logs",
124
"""Directory where IVLE log files are stored (on the local
125
file system). Note - this must be writable by the user the IVLE server
126
process runs as (usually www-data).:""",
128
# In the local file system, where IVLE error logs should be located."""))
129
config_options.append(ConfigOption("public_host", "public.localhost",
130
"""Hostname which will cause the server to go into "public mode",
131
providing login-free access to student's published work:""",
133
# The server goes into "public mode" if the browser sends a request with this
134
# host. This is for security reasons - we only serve public student files on a
135
# separate domain to the main IVLE site.
136
# Public mode does not use cookies, and serves only public content.
137
# Private mode (normal mode) requires login, and only serves files relevant to
138
# the logged-in user."""))
139
config_options.append(ConfigOption("allowed_uids", "33",
140
"""UID of the web server process which will run IVLE.
141
Only this user may execute the trampoline. May specify multiple users as
142
a comma-separated list.
145
# The User-ID of the web server process which will run IVLE, and any other
146
# users who are allowed to run the trampoline. This is stores as a string of
147
# comma-separated integers, simply because it is not used within Python, only
148
# used by the setup program to write to conf.h (see setup.py config)."""))
149
config_options.append(ConfigOption("db_host", "localhost",
150
"""PostgreSQL Database config
151
==========================
152
Hostname of the DB server:""",
154
### PostgreSQL Database config ###
155
# Database server hostname"""))
156
config_options.append(ConfigOption("db_port", "5432",
157
"""Port of the DB server:""",
159
# Database server port"""))
160
config_options.append(ConfigOption("db_dbname", "ivle",
161
"""Database name:""",
164
config_options.append(ConfigOption("db_forumdbname", "ivle_forum",
165
"""Forum Database name:""",
167
# Forum Database name"""))
168
config_options.append(ConfigOption("db_user", "postgres",
169
"""Username for DB server login:""",
171
# Database username"""))
172
config_options.append(ConfigOption("db_password", "",
173
"""Password for DB server login:
174
(Caution: This password is stored in plaintext in lib/conf/conf.py)""",
176
# Database password"""))
177
config_options.append(ConfigOption("auth_modules", "ldap_auth",
178
"""Authentication config
179
=====================
180
Comma-separated list of authentication modules. Only "ldap" is available
183
# Comma-separated list of authentication modules.
184
# These refer to importable Python modules in the www/auth directory.
185
# Modules "ldap" and "guest" are available in the source tree, but
186
# other modules may be plugged in to auth against organisation-specific
187
# auth backends."""))
188
config_options.append(ConfigOption("ldap_url", "ldaps://www.example.com",
189
"""(LDAP options are only relevant if "ldap" is included in the list of
191
URL for LDAP authentication server:""",
193
# URL for LDAP authentication server"""))
194
config_options.append(ConfigOption("ldap_format_string",
195
"uid=%s,ou=users,o=example",
196
"""Format string for LDAP auth request:
197
(Must contain a single "%s" for the user's login name)""",
199
# Format string for LDAP auth request
200
# (Must contain a single "%s" for the user's login name)"""))
201
config_options.append(ConfigOption("subject_pulldown_modules", "",
202
"""Comma-separated list of subject pulldown modules.
203
Add proprietary modules to automatically enrol students in subjects.""",
205
# Comma-separated list of subject pulldown modules.
206
# These refer to importable Python modules in the lib/pulldown_subj directory.
207
# Only "dummy_subj" is available in the source tree (an example), but
208
# other modules may be plugged in to pulldown against organisation-specific
209
# pulldown backends."""))
210
config_options.append(ConfigOption("svn_addr", "http://svn.localhost/",
213
The base url for accessing subversion repositories:""",
215
# The base url for accessing subversion repositories."""))
216
config_options.append(ConfigOption("svn_conf", "/opt/ivle/svn/svn.conf",
217
"""The location of the subversion configuration file used by apache
218
to host the user repositories:""",
220
# The location of the subversion configuration file used by
221
# apache to host the user repositories."""))
222
config_options.append(ConfigOption("svn_group_conf",
223
"/opt/ivle/svn/svn-group.conf",
224
"""The location of the subversion configuration file used by apache
225
to host group repositories:""",
227
# The location of the subversion configuration file used by
228
# apache to host the user repositories."""))
229
config_options.append(ConfigOption("svn_repo_path", "/home/informatics/repositories",
230
"""The root directory for the subversion repositories:""",
232
# The root directory for the subversion repositories."""))
233
config_options.append(ConfigOption("svn_auth_ivle", "/opt/ivle/svn/ivle.auth",
234
"""The location of the password file used to authenticate users
235
of the subversion repository from the ivle server:""",
237
# The location of the password file used to authenticate users
238
# of the subversion repository from the ivle server."""))
239
config_options.append(ConfigOption("svn_auth_local", "/opt/ivle/svn/local.auth",
240
"""The location of the password file used to authenticate local users
241
of the subversion repository:""",
243
# The location of the password file used to authenticate local users
244
# of the subversion repository."""))
245
config_options.append(ConfigOption("usrmgt_host", "localhost",
246
"""User Management Server config
247
============================
248
The hostname where the usrmgt-server runs:""",
250
# The hostname where the usrmgt-server runs."""))
251
config_options.append(ConfigOption("usrmgt_port", "2178",
252
"""The port where the usrmgt-server runs:""",
254
# The port where the usrmgt-server runs."""))
255
config_options.append(ConfigOption("usrmgt_magic", "",
256
"""The password for the usrmgt-server:""",
258
# The password for the usrmgt-server."""))
261
usage = """usage: %prog build [options]
263
Compiles all files and sets up a jail template in the source directory.
264
-O is recommended to cause compilation to be optimised.
266
Compiles (GCC) trampoline/trampoline.c to trampoline/trampoline.
267
Creates jail with system and student packages installed from MIRROR.
268
Copies console/ to a location within the jail.
269
Copies OS programs and files to corresponding locations within the jail
270
(eg. python and Python libs, ld.so, etc).
271
Generates .pyc or .pyo files for all the IVLE .py files."""
274
parser = optparse.OptionParser(usage)
275
(options, args) = parser.parse_args(args)
277
# Call the real function
280
def __configure(args):
281
global db_port, usrmgt_port
283
# Try importing existing conf, but if we can't just set up defaults
284
# The reason for this is that these settings are used by other phases
285
# of setup besides conf, so we need to know them.
286
# Also this allows you to hit Return to accept the existing value.
288
confmodule = __import__("lib/conf/conf")
289
for opt in config_options:
291
globals()[opt.option_name] = \
292
confmodule.__dict__[opt.option_name]
294
globals()[opt.option_name] = opt.default
296
# Just set reasonable defaults
297
for opt in config_options:
298
globals()[opt.option_name] = opt.default
300
# Set up some variables
303
# the files that will be created/overwritten
304
conffile = os.path.join(cwd, "lib/conf/conf.py")
305
jailconffile = os.path.join(cwd, "lib/conf/jailconf.py")
306
conf_hfile = os.path.join(cwd, "trampoline/conf.h")
307
phpBBconffile = os.path.join(cwd, "www/php/phpBB3/config.php")
308
usrmgtserver_initdfile = os.path.join(cwd, "doc/setup/usrmgt-server.init")
310
# Get command-line arguments to avoid asking questions.
313
for opt in config_options:
314
optnames.append(opt.option_name + "=")
315
(opts, args) = getopt.gnu_getopt(args, "", optnames)
318
print >>sys.stderr, "Invalid arguments:", string.join(args, ' ')
322
# Interactive mode. Prompt the user for all the values.
324
print """This tool will create the following files:
330
prompting you for details about your configuration. The file will be
331
overwritten if it already exists. It will *not* install or deploy IVLE.
333
Please hit Ctrl+C now if you do not wish to do this.
334
""" % (conffile, jailconffile, conf_hfile, phpBBconffile, usrmgtserver_initdfile)
336
# Get information from the administrator
337
# If EOF is encountered at any time during the questioning, just exit
340
for opt in config_options:
341
globals()[opt.option_name] = \
342
query_user(globals()[opt.option_name], opt.prompt)
345
# Non-interactive mode. Parse the options.
346
for opt in config_options:
347
if '--' + opt.option_name in opts:
348
globals()[opt.option_name] = opts['--' + opt.option_name]
350
# Error handling on input values
352
allowed_uids_list = map(int, allowed_uids.split(','))
354
print >>sys.stderr, (
355
"Invalid UID list (%s).\n"
356
"Must be a comma-separated list of integers." % allowed_uids)
359
db_port = int(db_port)
360
if db_port < 0 or db_port >= 65536: raise ValueError()
362
print >>sys.stderr, (
363
"Invalid DB port (%s).\n"
364
"Must be an integer between 0 and 65535." % repr(db_port))
367
usrmgt_port = int(usrmgt_port)
368
if usrmgt_port < 0 or usrmgt_port >= 65536: raise ValueError()
370
print >>sys.stderr, (
371
"Invalid user management port (%s).\n"
372
"Must be an integer between 0 and 65535." % repr(usrmgt_port))
375
# Generate the forum secret
376
forum_secret = hashlib.md5(uuid.uuid4().bytes).hexdigest()
378
# Write lib/conf/conf.py
381
conf = open(conffile, "w")
383
conf.write("""# IVLE Configuration File
385
# Miscellaneous application settings
388
for opt in config_options:
389
conf.write('%s\n%s = %s\n' % (opt.comment, opt.option_name,
390
repr(globals()[opt.option_name])))
392
# Add the forum secret to the config file (regenerated each config)
393
conf.write('forum_secret = "%s"\n' % (forum_secret))
396
except IOError, (errno, strerror):
397
print "IO error(%s): %s" % (errno, strerror)
400
print "Successfully wrote lib/conf/conf.py"
402
# Write conf/jailconf.py
405
conf = open(jailconffile, "w")
407
# In the "in-jail" version of conf, we don't need MOST of the details
408
# (it would be a security risk to have them here).
409
# So we just write root_dir, and jail_base is "/".
410
# (jail_base being "/" means "jail-relative" paths are relative to "/"
411
# when inside the jail.)
412
conf.write("""# IVLE Configuration File
414
# Miscellaneous application settings
415
# (User jail version)
418
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
420
# eg. "/" or "/ivle".
423
# In the local file system, where are the student/user file spaces located.
424
# The user jails are expected to be located immediately in subdirectories of
428
# The hostname for serving publicly accessible pages
431
# The URL under which the Subversion repositories are located.
433
""" % (repr(root_dir),repr(public_host),repr(svn_addr)))
436
except IOError, (errno, strerror):
437
print "IO error(%s): %s" % (errno, strerror)
440
print "Successfully wrote lib/conf/jailconf.py"
442
# Write trampoline/conf.h
445
conf = open(conf_hfile, "w")
447
conf.write("""/* IVLE Configuration File
449
* Administrator settings required by trampoline.
450
* Note: trampoline will have to be rebuilt in order for changes to this file
454
#define IVLE_AUFS_JAILS
456
/* In the local file system, where are the jails located.
457
* The trampoline does not allow the creation of a jail anywhere besides
458
* jail_base or a subdirectory of jail_base.
460
static const char* jail_base = "%s";
461
static const char* jail_src_base = "%s";
462
static const char* jail_system = "%s";
464
/* Which user IDs are allowed to run the trampoline.
465
* This list should be limited to the web server user.
466
* (Note that root is an implicit member of this list).
468
static const int allowed_uids[] = { %s };
469
""" % (repr(jail_base)[1:-1], repr(jail_src_base)[1:-1],
470
repr(jail_system)[1:-1], repr(allowed_uids_list)[1:-1]))
471
# Note: The above uses PYTHON reprs, not C reprs
472
# However they should be the same with the exception of the outer
473
# characters, which are stripped off and replaced
476
except IOError, (errno, strerror):
477
print "IO error(%s): %s" % (errno, strerror)
480
print "Successfully wrote trampoline/conf.h"
482
# Write www/php/phpBB3/config.php
485
conf = open(phpBBconffile, "w")
488
if db_host == 'localhost':
489
forumdb_host = '127.0.0.1'
491
forumdb_host = db_host
494
// phpBB 3.0.x auto-generated configuration file
495
// Do not change anything in this file!
497
$dbhost = '""" + forumdb_host + """';
498
$dbport = '""" + str(db_port) + """';
499
$dbname = '""" + db_forumdbname + """';
500
$dbuser = '""" + db_user + """';
501
$dbpasswd = '""" + db_password + """';
503
$table_prefix = 'phpbb_';
505
$load_extensions = '';
506
@define('PHPBB_INSTALLED', true);
507
// @define('DEBUG', true);
508
//@define('DEBUG_EXTRA', true);
510
$forum_secret = '""" + forum_secret +"""';
514
except IOError, (errno, strerror):
515
print "IO error(%s): %s" % (errno, strerror)
518
print "Successfully wrote www/php/phpBB3/config.php"
520
# Write lib/conf/usrmgt-server.init
523
conf = open(usrmgtserver_initdfile, "w")
525
conf.write( '''#! /bin/sh
527
# Works for Ubuntu. Check before using on other distributions
530
# Provides: usrmgt-server
531
# Required-Start: $syslog $networking $urandom
532
# Required-Stop: $syslog
533
# Default-Start: 2 3 4 5
535
# Short-Description: IVLE user management server
536
# Description: Daemon connecting to the IVLE user management database.
539
PATH=/sbin:/bin:/usr/sbin:/usr/bin
540
DESC="IVLE user management server"
542
DAEMON=/opt/ivle/scripts/$NAME
543
PIDFILE=/var/run/$NAME.pid
544
SCRIPTNAME=/etc/init.d/usrmgt-server
546
# Exit if the daemon does not exist
547
test -f $DAEMON || exit 0
549
# Load the VERBOSE setting and other rcS variables
550
[ -f /etc/default/rcS ] && . /etc/default/rcS
552
# Define LSB log_* functions.
553
# Depend on lsb-base (>= 3.0-6) to ensure that this file is present.
554
. /lib/lsb/init-functions
557
# Function that starts the daemon/service
562
# 0 if daemon has been started
563
# 1 if daemon was already running
564
# 2 if daemon could not be started
565
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON --test > /dev/null \
567
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON \
569
# Add code here, if necessary, that waits for the process to be ready
570
# to handle requests from services started subsequently which depend
571
# on this one. As a last resort, sleep for some time.
575
# Function that stops the daemon/service
580
# 0 if daemon has been stopped
581
# 1 if daemon was already stopped
582
# 2 if daemon could not be stopped
583
# other if a failure occurred
584
start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
586
[ "$RETVAL" = 2 ] && return 2
587
# Wait for children to finish too if this is a daemon that forks
588
# and if the daemon is only ever run from this initscript.
589
# If the above conditions are not satisfied then add some other code
590
# that waits for the process to drop all resources that could be
591
# needed by services started subsequently. A last resort is to
592
# sleep for some time.
593
start-stop-daemon --stop --quiet --oknodo --retry=0/30/KILL/5 --exec $DAEMON
594
[ "$?" = 2 ] && return 2
595
# Many daemons don't delete their pidfiles when they exit.
601
# Function that sends a SIGHUP to the daemon/service
605
# If the daemon can reload its configuration without
606
# restarting (for example, when it is sent a SIGHUP),
607
# then implement that here.
609
start-stop-daemon --stop --signal 1 --quiet --pidfile $PIDFILE --name $NAME
615
[ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
618
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
619
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
623
[ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
626
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
627
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
630
#reload|force-reload)
632
# If do_reload() is not implemented then leave this commented out
633
# and leave 'force-reload' as an alias for 'restart'.
635
#log_daemon_msg "Reloading $DESC" "$NAME"
639
restart|force-reload)
641
# If the "reload" option is implemented then remove the
642
# 'force-reload' alias
644
log_daemon_msg "Restarting $DESC" "$NAME"
651
1) log_end_msg 1 ;; # Old process is still running
652
*) log_end_msg 1 ;; # Failed to start
662
#echo "Usage: $SCRIPTNAME {start|stop|restart|reload|force-reload}" >&2
663
echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload}" >&2
672
except IOError, (errno, strerror):
673
print "IO error(%s): %s" % (errno, strerror)
676
# fix permissions as the file contains the database password
678
os.chmod('doc/setup/usrmgt-server.init', 0600)
679
except OSError, (errno, strerror):
680
print "WARNING: Couldn't chmod doc/setup/usrmgt-server.init:"
681
print "OS error(%s): %s" % (errno, strerror)
683
print "Successfully wrote lib/conf/usrmgt-server.init"
686
print "You may modify the configuration at any time by editing"
691
print usrmgtserver_initdfile