1
# IVLE - Informatics Virtual Learning Environment
2
# Copyright (C) 2007-2008 The University of Melbourne
4
# This program is free software; you can redistribute it and/or modify
5
# it under the terms of the GNU General Public License as published by
6
# the Free Software Foundation; either version 2 of the License, or
7
# (at your option) any later version.
9
# This program is distributed in the hope that it will be useful,
10
# but WITHOUT ANY WARRANTY; without even the implied warranty of
11
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12
# GNU General Public License for more details.
14
# You should have received a copy of the GNU General Public License
15
# along with this program; if not, write to the Free Software
16
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
18
# Module: setup/config
19
# Author: Matt Giuca, Refactored by David Coles
23
# Configures IVLE with machine-specific details, most notably, various paths.
24
# Either prompts the administrator for these details or accepts them as
26
# Creates lib/conf/conf.py and trampoline/conf.h.
33
from setup.setuputil import query_user
36
"""A configuration option; one of the things written to conf.py."""
37
def __init__(self, option_name, default, prompt, comment):
38
"""Creates a configuration option.
39
option_name: Name of the variable in conf.py. Also name of the
40
command-line argument to setup.py conf.
41
default: Default value for this variable.
42
prompt: (Short) string presented during the interactive prompt in
44
comment: (Long) comment string stored in conf.py. Each line of this
45
string should begin with a '#'.
47
self.option_name = option_name
48
self.default = default
50
self.comment = comment
52
# Configuration options, defaults and descriptions
54
config_options.append(ConfigOption("root_dir", "/",
55
"""Root directory where IVLE is located (in URL space):""",
57
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
59
# eg. "/" or "/ivle"."""))
60
config_options.append(ConfigOption("ivle_install_dir", "/opt/ivle",
61
'Root directory where IVLE will be installed (on the local file '
64
# In the local file system, where IVLE is actually installed.
65
# This directory should contain the "www" and "bin" directories."""))
66
config_options.append(ConfigOption("jail_base", "/home/informatics/jails",
67
"""Location of jail mountpoints
68
============================
69
Root directory where the user jails will be mounted, and the non-user
70
components of the jails will be stored (on the local file system):""",
72
# In the local file system, where the student/user jails will be mounted.
73
# Only a single copy of the jail's system components will be stored here -
74
# all user jails will be virtually mounted here."""))
75
config_options.append(ConfigOption("jail_system", "/home/informatics/jails/__base__",
76
"""Location of system jail components
77
==================================
78
Directory where the template system jail will be stored.""",
80
# In the local file system, where the template system jail will be stored."""))
81
config_options.append(ConfigOption("jail_src_base", "/home/informatics/jailssrc",
82
"""Location of user jail components
83
================================
84
Root directory where the user components of the jails will be stored (on the
85
local file system):""",
87
# In the local file system, where are the student/user file spaces located.
88
# The user jails are expected to be located immediately in subdirectories of
89
# this location. Note that no complete jails reside here - only user
91
config_options.append(ConfigOption("subjects_base",
92
"/home/informatics/subjects",
93
"""Root directory where the subject directories (containing worksheets
94
and other per-subject files) are stored (on the local file system):""",
96
# In the local file system, where are the per-subject file spaces located.
97
# The individual subject directories are expected to be located immediately
98
# in subdirectories of this location."""))
99
config_options.append(ConfigOption("exercises_base",
100
"/home/informatics/exercises",
101
"""Root directory where the exercise directories (containing
102
subject-independent exercise sheets) are stored (on the local file
105
# In the local file system, where are the subject-independent exercise sheet
106
# file spaces located."""))
107
config_options.append(ConfigOption("tos_path",
108
"/home/informatics/tos.html",
109
"""Location where the Terms of Service document is stored (on the local
112
# In the local file system, where is the Terms of Service document located."""))
113
config_options.append(ConfigOption("motd_path",
114
"/home/informatics/motd.html",
115
"""Location where the Message of the Day document is stored (on the local
118
# In the local file system, where is the Message of the Day document
119
# located. This is an HTML file (just the body fragment), which will
120
# be displayed on the login page. It is optional."""))
121
config_options.append(ConfigOption("public_host", "public.localhost",
122
"""Hostname which will cause the server to go into "public mode",
123
providing login-free access to student's published work:""",
125
# The server goes into "public mode" if the browser sends a request with this
126
# host. This is for security reasons - we only serve public student files on a
127
# separate domain to the main IVLE site.
128
# Public mode does not use cookies, and serves only public content.
129
# Private mode (normal mode) requires login, and only serves files relevant to
130
# the logged-in user."""))
131
config_options.append(ConfigOption("allowed_uids", "33",
132
"""UID of the web server process which will run IVLE.
133
Only this user may execute the trampoline. May specify multiple users as
134
a comma-separated list.
137
# The User-ID of the web server process which will run IVLE, and any other
138
# users who are allowed to run the trampoline. This is stores as a string of
139
# comma-separated integers, simply because it is not used within Python, only
140
# used by the setup program to write to conf.h (see setup.py config)."""))
141
config_options.append(ConfigOption("db_host", "localhost",
142
"""PostgreSQL Database config
143
==========================
144
Hostname of the DB server:""",
146
### PostgreSQL Database config ###
147
# Database server hostname"""))
148
config_options.append(ConfigOption("db_port", "5432",
149
"""Port of the DB server:""",
151
# Database server port"""))
152
config_options.append(ConfigOption("db_dbname", "ivle",
153
"""Database name:""",
156
config_options.append(ConfigOption("db_forumdbname", "ivle_forum",
157
"""Forum Database name:""",
159
# Forum Database name"""))
160
config_options.append(ConfigOption("db_user", "postgres",
161
"""Username for DB server login:""",
163
# Database username"""))
164
config_options.append(ConfigOption("db_password", "",
165
"""Password for DB server login:
166
(Caution: This password is stored in plaintext in lib/conf/conf.py)""",
168
# Database password"""))
169
config_options.append(ConfigOption("auth_modules", "ldap_auth",
170
"""Authentication config
171
=====================
172
Comma-separated list of authentication modules. Only "ldap" is available
175
# Comma-separated list of authentication modules.
176
# These refer to importable Python modules in the www/auth directory.
177
# Modules "ldap" and "guest" are available in the source tree, but
178
# other modules may be plugged in to auth against organisation-specific
179
# auth backends."""))
180
config_options.append(ConfigOption("ldap_url", "ldaps://www.example.com",
181
"""(LDAP options are only relevant if "ldap" is included in the list of
183
URL for LDAP authentication server:""",
185
# URL for LDAP authentication server"""))
186
config_options.append(ConfigOption("ldap_format_string",
187
"uid=%s,ou=users,o=example",
188
"""Format string for LDAP auth request:
189
(Must contain a single "%s" for the user's login name)""",
191
# Format string for LDAP auth request
192
# (Must contain a single "%s" for the user's login name)"""))
193
config_options.append(ConfigOption("svn_addr", "http://svn.localhost/",
196
The base url for accessing subversion repositories:""",
198
# The base url for accessing subversion repositories."""))
199
config_options.append(ConfigOption("svn_conf", "/opt/ivle/svn/svn.conf",
200
"""The location of the subversion configuration file used by apache
201
to host the user repositories:""",
203
# The location of the subversion configuration file used by
204
# apache to host the user repositories."""))
205
config_options.append(ConfigOption("svn_repo_path", "/home/informatics/repositories",
206
"""The root directory for the subversion repositories:""",
208
# The root directory for the subversion repositories."""))
209
config_options.append(ConfigOption("svn_auth_ivle", "/opt/ivle/svn/ivle.auth",
210
"""The location of the password file used to authenticate users
211
of the subversion repository from the ivle server:""",
213
# The location of the password file used to authenticate users
214
# of the subversion repository from the ivle server."""))
215
config_options.append(ConfigOption("svn_auth_local", "/opt/ivle/svn/local.auth",
216
"""The location of the password file used to authenticate local users
217
of the subversion repository:""",
219
# The location of the password file used to authenticate local users
220
# of the subversion repository."""))
221
config_options.append(ConfigOption("usrmgt_host", "localhost",
222
"""User Management Server config
223
============================
224
The hostname where the usrmgt-server runs:""",
226
# The hostname where the usrmgt-server runs."""))
227
config_options.append(ConfigOption("usrmgt_port", "2178",
228
"""The port where the usrmgt-server runs:""",
230
# The port where the usrmgt-server runs."""))
231
config_options.append(ConfigOption("usrmgt_magic", "",
232
"""The password for the usrmgt-server:""",
234
# The password for the usrmgt-server."""))
237
usage = """usage: %prog build [options]
239
Compiles all files and sets up a jail template in the source directory.
240
-O is recommended to cause compilation to be optimised.
242
Compiles (GCC) trampoline/trampoline.c to trampoline/trampoline.
243
Creates jail with system and student packages installed from MIRROR.
244
Copies console/ to a location within the jail.
245
Copies OS programs and files to corresponding locations within the jail
246
(eg. python and Python libs, ld.so, etc).
247
Generates .pyc or .pyo files for all the IVLE .py files."""
250
parser = optparse.OptionParser(usage)
251
(options, args) = parser.parse_args(args)
253
# Call the real function
256
def __configure(args):
257
global db_port, usrmgt_port
259
# Try importing existing conf, but if we can't just set up defaults
260
# The reason for this is that these settings are used by other phases
261
# of setup besides conf, so we need to know them.
262
# Also this allows you to hit Return to accept the existing value.
264
confmodule = __import__("lib/conf/conf")
265
for opt in config_options:
267
globals()[opt.option_name] = \
268
confmodule.__dict__[opt.option_name]
270
globals()[opt.option_name] = opt.default
272
# Just set reasonable defaults
273
for opt in config_options:
274
globals()[opt.option_name] = opt.default
276
# Set up some variables
279
# the files that will be created/overwritten
280
conffile = os.path.join(cwd, "lib/conf/conf.py")
281
jailconffile = os.path.join(cwd, "lib/conf/jailconf.py")
282
conf_hfile = os.path.join(cwd, "trampoline/conf.h")
283
phpBBconffile = os.path.join(cwd, "www/php/phpBB3/config.php")
284
usrmgtserver_initdfile = os.path.join(cwd, "doc/setup/usrmgt-server.init")
286
# Get command-line arguments to avoid asking questions.
289
for opt in config_options:
290
optnames.append(opt.option_name + "=")
291
(opts, args) = getopt.gnu_getopt(args, "", optnames)
294
print >>sys.stderr, "Invalid arguments:", string.join(args, ' ')
298
# Interactive mode. Prompt the user for all the values.
300
print """This tool will create the following files:
306
prompting you for details about your configuration. The file will be
307
overwritten if it already exists. It will *not* install or deploy IVLE.
309
Please hit Ctrl+C now if you do not wish to do this.
310
""" % (conffile, jailconffile, conf_hfile, phpBBconffile, usrmgtserver_initdfile)
312
# Get information from the administrator
313
# If EOF is encountered at any time during the questioning, just exit
316
for opt in config_options:
317
globals()[opt.option_name] = \
318
query_user(globals()[opt.option_name], opt.prompt)
321
# Non-interactive mode. Parse the options.
322
for opt in config_options:
323
if '--' + opt.option_name in opts:
324
globals()[opt.option_name] = opts['--' + opt.option_name]
326
# Error handling on input values
328
allowed_uids_list = map(int, allowed_uids.split(','))
330
print >>sys.stderr, (
331
"Invalid UID list (%s).\n"
332
"Must be a comma-separated list of integers." % allowed_uids)
335
db_port = int(db_port)
336
if db_port < 0 or db_port >= 65536: raise ValueError()
338
print >>sys.stderr, (
339
"Invalid DB port (%s).\n"
340
"Must be an integer between 0 and 65535." % repr(db_port))
343
usrmgt_port = int(usrmgt_port)
344
if usrmgt_port < 0 or usrmgt_port >= 65536: raise ValueError()
346
print >>sys.stderr, (
347
"Invalid user management port (%s).\n"
348
"Must be an integer between 0 and 65535." % repr(usrmgt_port))
351
# Generate the forum secret
352
forum_secret = hashlib.md5(uuid.uuid4().bytes).hexdigest()
354
# Write lib/conf/conf.py
357
conf = open(conffile, "w")
359
conf.write("""# IVLE Configuration File
361
# Miscellaneous application settings
364
for opt in config_options:
365
conf.write('%s\n%s = %s\n' % (opt.comment, opt.option_name,
366
repr(globals()[opt.option_name])))
368
# Add the forum secret to the config file (regenerated each config)
369
conf.write('forum_secret = "%s"\n' % (forum_secret))
372
except IOError, (errno, strerror):
373
print "IO error(%s): %s" % (errno, strerror)
376
print "Successfully wrote lib/conf/conf.py"
378
# Write conf/jailconf.py
381
conf = open(jailconffile, "w")
383
# In the "in-jail" version of conf, we don't need MOST of the details
384
# (it would be a security risk to have them here).
385
# So we just write root_dir, and jail_base is "/".
386
# (jail_base being "/" means "jail-relative" paths are relative to "/"
387
# when inside the jail.)
388
conf.write("""# IVLE Configuration File
390
# Miscellaneous application settings
391
# (User jail version)
394
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
396
# eg. "/" or "/ivle".
399
# In the local file system, where are the student/user file spaces located.
400
# The user jails are expected to be located immediately in subdirectories of
404
# The hostname for serving publicly accessible pages
406
""" % (repr(root_dir),repr(public_host)))
409
except IOError, (errno, strerror):
410
print "IO error(%s): %s" % (errno, strerror)
413
print "Successfully wrote lib/conf/jailconf.py"
415
# Write trampoline/conf.h
418
conf = open(conf_hfile, "w")
420
conf.write("""/* IVLE Configuration File
422
* Administrator settings required by trampoline.
423
* Note: trampoline will have to be rebuilt in order for changes to this file
427
#define IVLE_AUFS_JAILS
429
/* In the local file system, where are the jails located.
430
* The trampoline does not allow the creation of a jail anywhere besides
431
* jail_base or a subdirectory of jail_base.
433
static const char* jail_base = "%s";
434
static const char* jail_src_base = "%s";
435
static const char* jail_system = "%s";
437
/* Which user IDs are allowed to run the trampoline.
438
* This list should be limited to the web server user.
439
* (Note that root is an implicit member of this list).
441
static const int allowed_uids[] = { %s };
442
""" % (repr(jail_base)[1:-1], repr(jail_src_base)[1:-1],
443
repr(jail_system)[1:-1], repr(allowed_uids_list)[1:-1]))
444
# Note: The above uses PYTHON reprs, not C reprs
445
# However they should be the same with the exception of the outer
446
# characters, which are stripped off and replaced
449
except IOError, (errno, strerror):
450
print "IO error(%s): %s" % (errno, strerror)
453
print "Successfully wrote trampoline/conf.h"
455
# Write www/php/phpBB3/config.php
458
conf = open(phpBBconffile, "w")
461
if db_host == 'localhost':
462
forumdb_host = '127.0.0.1'
464
forumdb_host = db_host
467
// phpBB 3.0.x auto-generated configuration file
468
// Do not change anything in this file!
470
$dbhost = '""" + forumdb_host + """';
471
$dbport = '""" + str(db_port) + """';
472
$dbname = '""" + db_forumdbname + """';
473
$dbuser = '""" + db_user + """';
474
$dbpasswd = '""" + db_password + """';
476
$table_prefix = 'phpbb_';
478
$load_extensions = '';
479
@define('PHPBB_INSTALLED', true);
480
// @define('DEBUG', true);
481
//@define('DEBUG_EXTRA', true);
483
$forum_secret = '""" + forum_secret +"""';
487
except IOError, (errno, strerror):
488
print "IO error(%s): %s" % (errno, strerror)
491
print "Successfully wrote www/php/phpBB3/config.php"
493
# Write lib/conf/usrmgt-server.init
496
conf = open(usrmgtserver_initdfile, "w")
498
conf.write( '''#! /bin/sh
500
# Works for Ubuntu. Check before using on other distributions
503
# Provides: usrmgt-server
504
# Required-Start: $syslog $networking $urandom
505
# Required-Stop: $syslog
506
# Default-Start: 2 3 4 5
508
# Short-Description: IVLE user management server
509
# Description: Daemon connecting to the IVLE user management database.
512
PATH=/sbin:/bin:/usr/sbin:/usr/bin
513
DESC="IVLE user management server"
515
DAEMON=/opt/ivle/scripts/$NAME
516
DAEMON_ARGS="''' + str(usrmgt_port) + ''' ''' + usrmgt_magic + '''"
517
PIDFILE=/var/run/$NAME.pid
518
SCRIPTNAME=/etc/init.d/usrmgt-server
520
# Exit if the daemon does not exist
521
test -f $DAEMON || exit 0
523
# Load the VERBOSE setting and other rcS variables
524
[ -f /etc/default/rcS ] && . /etc/default/rcS
526
# Define LSB log_* functions.
527
# Depend on lsb-base (>= 3.0-6) to ensure that this file is present.
528
. /lib/lsb/init-functions
531
# Function that starts the daemon/service
536
# 0 if daemon has been started
537
# 1 if daemon was already running
538
# 2 if daemon could not be started
539
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON --test > /dev/null \
541
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON -- \
544
# Add code here, if necessary, that waits for the process to be ready
545
# to handle requests from services started subsequently which depend
546
# on this one. As a last resort, sleep for some time.
550
# Function that stops the daemon/service
555
# 0 if daemon has been stopped
556
# 1 if daemon was already stopped
557
# 2 if daemon could not be stopped
558
# other if a failure occurred
559
start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
561
[ "$RETVAL" = 2 ] && return 2
562
# Wait for children to finish too if this is a daemon that forks
563
# and if the daemon is only ever run from this initscript.
564
# If the above conditions are not satisfied then add some other code
565
# that waits for the process to drop all resources that could be
566
# needed by services started subsequently. A last resort is to
567
# sleep for some time.
568
start-stop-daemon --stop --quiet --oknodo --retry=0/30/KILL/5 --exec $DAEMON
569
[ "$?" = 2 ] && return 2
570
# Many daemons don't delete their pidfiles when they exit.
576
# Function that sends a SIGHUP to the daemon/service
580
# If the daemon can reload its configuration without
581
# restarting (for example, when it is sent a SIGHUP),
582
# then implement that here.
584
start-stop-daemon --stop --signal 1 --quiet --pidfile $PIDFILE --name $NAME
590
[ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
593
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
594
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
598
[ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
601
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
602
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
605
#reload|force-reload)
607
# If do_reload() is not implemented then leave this commented out
608
# and leave 'force-reload' as an alias for 'restart'.
610
#log_daemon_msg "Reloading $DESC" "$NAME"
614
restart|force-reload)
616
# If the "reload" option is implemented then remove the
617
# 'force-reload' alias
619
log_daemon_msg "Restarting $DESC" "$NAME"
626
1) log_end_msg 1 ;; # Old process is still running
627
*) log_end_msg 1 ;; # Failed to start
637
#echo "Usage: $SCRIPTNAME {start|stop|restart|reload|force-reload}" >&2
638
echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload}" >&2
647
except IOError, (errno, strerror):
648
print "IO error(%s): %s" % (errno, strerror)
651
# fix permissions as the file contains the database password
653
os.chmod('doc/setup/usrmgt-server.init', 0600)
654
except OSError, (errno, strerror):
655
print "WARNING: Couldn't chmod doc/setup/usrmgt-server.init:"
656
print "OS error(%s): %s" % (errno, strerror)
658
print "Successfully wrote lib/conf/usrmgt-server.init"
661
print "You may modify the configuration at any time by editing"
666
print usrmgtserver_initdfile