103
103
os.rename(ivle.conf.svn_conf + ".new", ivle.conf.svn_conf)
104
104
chown_to_webserver(ivle.conf.svn_conf)
106
def rebuild_svn_group_config(store):
106
def rebuild_svn_group_config():
107
107
"""Build the complete SVN configuration file for groups
110
groups = conn.get_all('project_group',
111
['groupid', 'groupnm', 'projectsetid'])
109
112
f = open(ivle.conf.svn_group_conf + ".new", "w")
110
113
f.write("# IVLE SVN Group Repositories Configuration\n")
111
114
f.write("# Auto-generated on %s\n" % time.asctime())
113
for group in store.find(ProjectGroup):
114
offering = group.project_set.offering
115
reponame = "_".join([offering.subject.short_name,
116
offering.semester.year,
117
offering.semester.semester,
117
projectsetid = g['projectsetid']
118
offeringinfo = conn.get_offering_info(projectsetid)
119
subj_short_name = offeringinfo['subj_short_name']
120
year = offeringinfo['year']
121
semester = offeringinfo['semester']
122
reponame = "_".join([subj_short_name, year, semester, g['groupnm']])
119
123
f.write("[%s:/]\n"%reponame)
120
for user in group.members:
121
f.write("%s = rw\n" % user.login)
124
users = conn.get_projectgroup_members(g['groupid'])
126
f.write("%s = rw\n"%u['login'])
124
129
os.rename(ivle.conf.svn_group_conf + ".new", ivle.conf.svn_group_conf)
125
130
chown_to_webserver(ivle.conf.svn_group_conf)
127
def make_svn_auth(store, login, throw_on_error=True):
132
def make_svn_auth(login, throw_on_error=True):
128
133
"""Setup svn authentication for the given user.
129
Uses the given DB store object. Does not commit to the db.
134
FIXME: create local.auth entry
131
136
passwd = md5.new(uuid.uuid4().bytes).digest().encode('hex')
132
137
if os.path.exists(ivle.conf.svn_auth_ivle):
178
182
return (to_add, to_remove)
181
def make_jail(user, force=True):
185
def make_jail(username, uid, force=True, svn_pass=None):
182
186
"""Creates a new user's jail space, in the jail directory as configured in
190
194
Chowns the user's directory within the jail to the given UID.
196
Note: This takes separate username and uid arguments. The UID need not
197
*necessarily* correspond to a Unix username at all, if all you are
198
planning to do is setuid to it. This allows the caller the freedom of
199
deciding the binding between username and uid, if any.
192
201
force: If false, exception if jail already exists for this user.
193
202
If true (default), overwrites it, but preserves home directory.
204
svn_pass: If provided this will be a string, the randomly-generated
205
Subversion password for this user (if you happen to already have it).
206
If not provided, it will be read from the database.
195
208
# MUST run as root or some of this may fail
196
209
if os.getuid() != 0:
203
216
elif not os.path.isdir(tempdir):
204
217
os.unlink(tempdir)
205
218
os.mkdir(tempdir)
206
userdir = os.path.join(ivle.conf.jail_src_base, user.login)
219
userdir = os.path.join(ivle.conf.jail_src_base, username)
207
220
homedir = os.path.join(userdir, 'home')
208
userhomedir = os.path.join(homedir, user.login) # Return value
221
userhomedir = os.path.join(homedir, username) # Return value
210
223
if os.path.exists(userdir):
226
239
shutil.move(homebackup, homedir)
227
240
# Change the ownership of all the files to the right unixid
228
241
logging.debug("chown %s's home directory files to uid %d"
229
%(user.login, user.unixid))
230
os.chown(userhomedir, user.unixid, user.unixid)
243
os.chown(userhomedir, uid, uid)
231
244
for root, dirs, files in os.walk(userhomedir):
232
245
for fsobj in dirs + files:
233
os.chown(os.path.join(root, fsobj), user.unixid, user.unixid)
246
os.chown(os.path.join(root, fsobj), uid, uid)
235
248
# No user jail exists
236
249
# Set up the user's home directory
237
250
os.makedirs(userhomedir)
238
251
# Chown (and set the GID to the same as the UID).
239
os.chown(userhomedir, user.unixid, user.unixid)
252
os.chown(userhomedir, uid, uid)
240
253
# Chmod to rwxr-xr-x (755)
241
254
os.chmod(userhomedir, 0755)
243
make_conf_py(user.login, userdir, ivle.conf.jail_system, user.svn_pass)
244
make_etc_passwd(user.login, userdir, ivle.conf.jail_system, user.unixid)
256
# There are 2 special files which need to be generated specific to this
257
# user: ${python_site_packages}/lib/conf/conf.py and /etc/passwd.
258
# "__" username "__" users are exempt (special)
259
if not (username.startswith("__") and username.endswith("__")):
260
make_conf_py(username, userdir, ivle.conf.jail_system, svn_pass)
261
make_etc_passwd(username, userdir, ivle.conf.jail_system, uid)
246
263
return userhomedir
248
def make_conf_py(username, user_jail_dir, staging_dir, svn_pass):
265
def make_conf_py(username, user_jail_dir, staging_dir, svn_pass=None):
250
267
Creates (overwriting any existing file, and creating directories) a
251
268
file ${python_site_packages}/ivle/conf/conf.py in a given user's jail.
262
279
ivle.conf.python_site_packages[1:], "ivle/conf/conf.py")
263
280
os.makedirs(os.path.dirname(conf_path))
282
# If svn_pass isn't supplied, grab it from the DB
284
dbconn = ivle.db.DB()
285
svn_pass = dbconn.get_user(username).svn_pass
265
288
# Read the contents of the template conf file
267
290
template_conf_file = open(template_conf_path, "r")
304
327
% (username, unixid, unixid, username))
305
328
passwd_file.close()
330
def make_user_db(throw_on_error = True, **kwargs):
331
"""Creates a user's entry in the database, filling in all the fields.
332
All arguments must be keyword args. They are the fields in the table.
333
However, instead of supplying a "passhash", you must supply a
334
"password" argument, which will be hashed internally.
335
Also do not supply a state. All users are created in the "no_agreement"
337
Also pulls the user's subjects using the configured subject pulldown
338
module, and adds enrolments to the DB.
339
Throws an exception if the user already exists.
341
dbconn = ivle.db.DB()
342
dbconn.create_user(**kwargs)
345
if kwargs['password']:
346
if os.path.exists(ivle.conf.svn_auth_local):
350
res = os.system("htpasswd -%smb %s %s %s" % (create,
351
ivle.conf.svn_auth_local,
354
if res != 0 and throw_on_error:
355
raise Exception("Unable to create local-auth for %s" % kwargs['login'])
357
# Make sure the file is owned by the web server
359
chown_to_webserver(ivle.conf.svn_auth_local)
361
# Pulldown subjects and add enrolments
362
ivle.pulldown_subj.enrol_user(kwargs['login'])
307
364
def mount_jail(login):
308
365
# This is where we'll mount to...
309
366
destdir = os.path.join(ivle.conf.jail_base, login)