1
# IVLE - Informatics Virtual Learning Environment
2
# Copyright (C) 2007-2008 The University of Melbourne
4
# This program is free software; you can redistribute it and/or modify
5
# it under the terms of the GNU General Public License as published by
6
# the Free Software Foundation; either version 2 of the License, or
7
# (at your option) any later version.
9
# This program is distributed in the hope that it will be useful,
10
# but WITHOUT ANY WARRANTY; without even the implied warranty of
11
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12
# GNU General Public License for more details.
14
# You should have received a copy of the GNU General Public License
15
# along with this program; if not, write to the Free Software
16
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
18
# Module: setup/config
19
# Author: Matt Giuca, Refactored by David Coles
23
# Configures IVLE with machine-specific details, most notably, various paths.
24
# Either prompts the administrator for these details or accepts them as
26
# Creates lib/conf/conf.py and trampoline/conf.h.
34
from setup.setuputil import query_user
37
"""A configuration option; one of the things written to conf.py."""
38
def __init__(self, option_name, default, prompt, comment):
39
"""Creates a configuration option.
40
option_name: Name of the variable in conf.py. Also name of the
41
command-line argument to setup.py conf.
42
default: Default value for this variable.
43
prompt: (Short) string presented during the interactive prompt in
45
comment: (Long) comment string stored in conf.py. Each line of this
46
string should begin with a '#'.
48
self.option_name = option_name
49
self.default = default
51
self.comment = comment
53
# Configuration options, defaults and descriptions
55
config_options.append(ConfigOption("root_dir", "/",
56
"""Root directory where IVLE is located (in URL space):""",
58
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
60
# eg. "/" or "/ivle"."""))
61
config_options.append(ConfigOption("ivle_install_dir", "/opt/ivle",
62
'Root directory where IVLE will be installed (on the local file '
65
# In the local file system, where IVLE is actually installed.
66
# This directory should contain the "www" and "bin" directories."""))
67
config_options.append(ConfigOption("jail_base", "/home/informatics/jails",
68
"""Location of jail mountpoints
69
============================
70
Root directory where the user jails will be mounted, and the non-user
71
components of the jails will be stored (on the local file system):""",
73
# In the local file system, where the student/user jails will be mounted.
74
# Only a single copy of the jail's system components will be stored here -
75
# all user jails will be virtually mounted here."""))
76
config_options.append(ConfigOption("jail_system", "/home/informatics/jails/__base__",
77
"""Location of system jail components
78
==================================
79
Directory where the template system jail will be stored.""",
81
# In the local file system, where the template system jail will be stored."""))
82
config_options.append(ConfigOption("jail_src_base", "/home/informatics/jailssrc",
83
"""Location of user jail components
84
================================
85
Root directory where the user components of the jails will be stored (on the
86
local file system):""",
88
# In the local file system, where are the student/user file spaces located.
89
# The user jails are expected to be located immediately in subdirectories of
90
# this location. Note that no complete jails reside here - only user
92
config_options.append(ConfigOption("subjects_base",
93
"/home/informatics/subjects",
94
"""Root directory where the subject directories (containing worksheets
95
and other per-subject files) are stored (on the local file system):""",
97
# In the local file system, where are the per-subject file spaces located.
98
# The individual subject directories are expected to be located immediately
99
# in subdirectories of this location."""))
100
config_options.append(ConfigOption("exercises_base",
101
"/home/informatics/exercises",
102
"""Root directory where the exercise directories (containing
103
subject-independent exercise sheets) are stored (on the local file
106
# In the local file system, where are the subject-independent exercise sheet
107
# file spaces located."""))
108
config_options.append(ConfigOption("tos_path",
109
"/home/informatics/tos.html",
110
"""Location where the Terms of Service document is stored (on the local
113
# In the local file system, where is the Terms of Service document located."""))
114
config_options.append(ConfigOption("motd_path",
115
"/home/informatics/motd.html",
116
"""Location where the Message of the Day document is stored (on the local
119
# In the local file system, where is the Message of the Day document
120
# located. This is an HTML file (just the body fragment), which will
121
# be displayed on the login page. It is optional."""))
122
config_options.append(ConfigOption("public_host", "public.localhost",
123
"""Hostname which will cause the server to go into "public mode",
124
providing login-free access to student's published work:""",
126
# The server goes into "public mode" if the browser sends a request with this
127
# host. This is for security reasons - we only serve public student files on a
128
# separate domain to the main IVLE site.
129
# Public mode does not use cookies, and serves only public content.
130
# Private mode (normal mode) requires login, and only serves files relevant to
131
# the logged-in user."""))
132
config_options.append(ConfigOption("allowed_uids", "33",
133
"""UID of the web server process which will run IVLE.
134
Only this user may execute the trampoline. May specify multiple users as
135
a comma-separated list.
138
# The User-ID of the web server process which will run IVLE, and any other
139
# users who are allowed to run the trampoline. This is stores as a string of
140
# comma-separated integers, simply because it is not used within Python, only
141
# used by the setup program to write to conf.h (see setup.py config)."""))
142
config_options.append(ConfigOption("db_host", "localhost",
143
"""PostgreSQL Database config
144
==========================
145
Hostname of the DB server:""",
147
### PostgreSQL Database config ###
148
# Database server hostname"""))
149
config_options.append(ConfigOption("db_port", "5432",
150
"""Port of the DB server:""",
152
# Database server port"""))
153
config_options.append(ConfigOption("db_dbname", "ivle",
154
"""Database name:""",
157
config_options.append(ConfigOption("db_forumdbname", "ivle_forum",
158
"""Forum Database name:""",
160
# Forum Database name"""))
161
config_options.append(ConfigOption("db_user", "postgres",
162
"""Username for DB server login:""",
164
# Database username"""))
165
config_options.append(ConfigOption("db_password", "",
166
"""Password for DB server login:
167
(Caution: This password is stored in plaintext in lib/conf/conf.py)""",
169
# Database password"""))
170
config_options.append(ConfigOption("auth_modules", "ldap_auth",
171
"""Authentication config
172
=====================
173
Comma-separated list of authentication modules. Only "ldap" is available
176
# Comma-separated list of authentication modules.
177
# These refer to importable Python modules in the www/auth directory.
178
# Modules "ldap" and "guest" are available in the source tree, but
179
# other modules may be plugged in to auth against organisation-specific
180
# auth backends."""))
181
config_options.append(ConfigOption("ldap_url", "ldaps://www.example.com",
182
"""(LDAP options are only relevant if "ldap" is included in the list of
184
URL for LDAP authentication server:""",
186
# URL for LDAP authentication server"""))
187
config_options.append(ConfigOption("ldap_format_string",
188
"uid=%s,ou=users,o=example",
189
"""Format string for LDAP auth request:
190
(Must contain a single "%s" for the user's login name)""",
192
# Format string for LDAP auth request
193
# (Must contain a single "%s" for the user's login name)"""))
194
config_options.append(ConfigOption("subject_pulldown_modules", "",
195
"""Comma-separated list of subject pulldown modules.
196
Add proprietary modules to automatically enrol students in subjects.""",
198
# Comma-separated list of subject pulldown modules.
199
# These refer to importable Python modules in the lib/pulldown_subj directory.
200
# Only "dummy_subj" is available in the source tree (an example), but
201
# other modules may be plugged in to pulldown against organisation-specific
202
# pulldown backends."""))
203
config_options.append(ConfigOption("svn_addr", "http://svn.localhost/",
206
The base url for accessing subversion repositories:""",
208
# The base url for accessing subversion repositories."""))
209
config_options.append(ConfigOption("svn_conf", "/opt/ivle/svn/svn.conf",
210
"""The location of the subversion configuration file used by apache
211
to host the user repositories:""",
213
# The location of the subversion configuration file used by
214
# apache to host the user repositories."""))
215
config_options.append(ConfigOption("svn_repo_path", "/home/informatics/repositories",
216
"""The root directory for the subversion repositories:""",
218
# The root directory for the subversion repositories."""))
219
config_options.append(ConfigOption("svn_auth_ivle", "/opt/ivle/svn/ivle.auth",
220
"""The location of the password file used to authenticate users
221
of the subversion repository from the ivle server:""",
223
# The location of the password file used to authenticate users
224
# of the subversion repository from the ivle server."""))
225
config_options.append(ConfigOption("svn_auth_local", "/opt/ivle/svn/local.auth",
226
"""The location of the password file used to authenticate local users
227
of the subversion repository:""",
229
# The location of the password file used to authenticate local users
230
# of the subversion repository."""))
231
config_options.append(ConfigOption("usrmgt_host", "localhost",
232
"""User Management Server config
233
============================
234
The hostname where the usrmgt-server runs:""",
236
# The hostname where the usrmgt-server runs."""))
237
config_options.append(ConfigOption("usrmgt_port", "2178",
238
"""The port where the usrmgt-server runs:""",
240
# The port where the usrmgt-server runs."""))
241
config_options.append(ConfigOption("usrmgt_magic", "",
242
"""The password for the usrmgt-server:""",
244
# The password for the usrmgt-server."""))
247
usage = """usage: %prog build [options]
249
Compiles all files and sets up a jail template in the source directory.
250
-O is recommended to cause compilation to be optimised.
252
Compiles (GCC) trampoline/trampoline.c to trampoline/trampoline.
253
Creates jail with system and student packages installed from MIRROR.
254
Copies console/ to a location within the jail.
255
Copies OS programs and files to corresponding locations within the jail
256
(eg. python and Python libs, ld.so, etc).
257
Generates .pyc or .pyo files for all the IVLE .py files."""
260
parser = optparse.OptionParser(usage)
261
(options, args) = parser.parse_args(args)
263
# Call the real function
266
def __configure(args):
267
global db_port, usrmgt_port
269
# Try importing existing conf, but if we can't just set up defaults
270
# The reason for this is that these settings are used by other phases
271
# of setup besides conf, so we need to know them.
272
# Also this allows you to hit Return to accept the existing value.
274
confmodule = __import__("lib/conf/conf")
275
for opt in config_options:
277
globals()[opt.option_name] = \
278
confmodule.__dict__[opt.option_name]
280
globals()[opt.option_name] = opt.default
282
# Just set reasonable defaults
283
for opt in config_options:
284
globals()[opt.option_name] = opt.default
286
# Set up some variables
289
# the files that will be created/overwritten
290
conffile = os.path.join(cwd, "lib/conf/conf.py")
291
jailconffile = os.path.join(cwd, "lib/conf/jailconf.py")
292
conf_hfile = os.path.join(cwd, "trampoline/conf.h")
293
phpBBconffile = os.path.join(cwd, "www/php/phpBB3/config.php")
294
usrmgtserver_initdfile = os.path.join(cwd, "doc/setup/usrmgt-server.init")
296
# Get command-line arguments to avoid asking questions.
299
for opt in config_options:
300
optnames.append(opt.option_name + "=")
301
(opts, args) = getopt.gnu_getopt(args, "", optnames)
304
print >>sys.stderr, "Invalid arguments:", string.join(args, ' ')
308
# Interactive mode. Prompt the user for all the values.
310
print """This tool will create the following files:
316
prompting you for details about your configuration. The file will be
317
overwritten if it already exists. It will *not* install or deploy IVLE.
319
Please hit Ctrl+C now if you do not wish to do this.
320
""" % (conffile, jailconffile, conf_hfile, phpBBconffile, usrmgtserver_initdfile)
322
# Get information from the administrator
323
# If EOF is encountered at any time during the questioning, just exit
326
for opt in config_options:
327
globals()[opt.option_name] = \
328
query_user(globals()[opt.option_name], opt.prompt)
331
# Non-interactive mode. Parse the options.
332
for opt in config_options:
333
if '--' + opt.option_name in opts:
334
globals()[opt.option_name] = opts['--' + opt.option_name]
336
# Error handling on input values
338
allowed_uids_list = map(int, allowed_uids.split(','))
340
print >>sys.stderr, (
341
"Invalid UID list (%s).\n"
342
"Must be a comma-separated list of integers." % allowed_uids)
345
db_port = int(db_port)
346
if db_port < 0 or db_port >= 65536: raise ValueError()
348
print >>sys.stderr, (
349
"Invalid DB port (%s).\n"
350
"Must be an integer between 0 and 65535." % repr(db_port))
353
usrmgt_port = int(usrmgt_port)
354
if usrmgt_port < 0 or usrmgt_port >= 65536: raise ValueError()
356
print >>sys.stderr, (
357
"Invalid user management port (%s).\n"
358
"Must be an integer between 0 and 65535." % repr(usrmgt_port))
361
# Generate the forum secret
362
forum_secret = hashlib.md5(uuid.uuid4().bytes).hexdigest()
364
# Write lib/conf/conf.py
367
conf = open(conffile, "w")
369
conf.write("""# IVLE Configuration File
371
# Miscellaneous application settings
374
for opt in config_options:
375
conf.write('%s\n%s = %s\n' % (opt.comment, opt.option_name,
376
repr(globals()[opt.option_name])))
378
# Add the forum secret to the config file (regenerated each config)
379
conf.write('forum_secret = "%s"\n' % (forum_secret))
382
except IOError, (errno, strerror):
383
print "IO error(%s): %s" % (errno, strerror)
386
print "Successfully wrote lib/conf/conf.py"
388
# Write conf/jailconf.py
391
conf = open(jailconffile, "w")
393
# In the "in-jail" version of conf, we don't need MOST of the details
394
# (it would be a security risk to have them here).
395
# So we just write root_dir, and jail_base is "/".
396
# (jail_base being "/" means "jail-relative" paths are relative to "/"
397
# when inside the jail.)
398
conf.write("""# IVLE Configuration File
400
# Miscellaneous application settings
401
# (User jail version)
404
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
406
# eg. "/" or "/ivle".
409
# In the local file system, where are the student/user file spaces located.
410
# The user jails are expected to be located immediately in subdirectories of
414
# The hostname for serving publicly accessible pages
416
""" % (repr(root_dir),repr(public_host)))
419
except IOError, (errno, strerror):
420
print "IO error(%s): %s" % (errno, strerror)
423
print "Successfully wrote lib/conf/jailconf.py"
425
# Write trampoline/conf.h
428
conf = open(conf_hfile, "w")
430
conf.write("""/* IVLE Configuration File
432
* Administrator settings required by trampoline.
433
* Note: trampoline will have to be rebuilt in order for changes to this file
437
#define IVLE_AUFS_JAILS
439
/* In the local file system, where are the jails located.
440
* The trampoline does not allow the creation of a jail anywhere besides
441
* jail_base or a subdirectory of jail_base.
443
static const char* jail_base = "%s";
444
static const char* jail_src_base = "%s";
445
static const char* jail_system = "%s";
447
/* Which user IDs are allowed to run the trampoline.
448
* This list should be limited to the web server user.
449
* (Note that root is an implicit member of this list).
451
static const int allowed_uids[] = { %s };
452
""" % (repr(jail_base)[1:-1], repr(jail_src_base)[1:-1],
453
repr(jail_system)[1:-1], repr(allowed_uids_list)[1:-1]))
454
# Note: The above uses PYTHON reprs, not C reprs
455
# However they should be the same with the exception of the outer
456
# characters, which are stripped off and replaced
459
except IOError, (errno, strerror):
460
print "IO error(%s): %s" % (errno, strerror)
463
print "Successfully wrote trampoline/conf.h"
465
# Write www/php/phpBB3/config.php
468
conf = open(phpBBconffile, "w")
471
if db_host == 'localhost':
472
forumdb_host = '127.0.0.1'
474
forumdb_host = db_host
477
// phpBB 3.0.x auto-generated configuration file
478
// Do not change anything in this file!
480
$dbhost = '""" + forumdb_host + """';
481
$dbport = '""" + str(db_port) + """';
482
$dbname = '""" + db_forumdbname + """';
483
$dbuser = '""" + db_user + """';
484
$dbpasswd = '""" + db_password + """';
486
$table_prefix = 'phpbb_';
488
$load_extensions = '';
489
@define('PHPBB_INSTALLED', true);
490
// @define('DEBUG', true);
491
//@define('DEBUG_EXTRA', true);
493
$forum_secret = '""" + forum_secret +"""';
497
except IOError, (errno, strerror):
498
print "IO error(%s): %s" % (errno, strerror)
501
print "Successfully wrote www/php/phpBB3/config.php"
503
# Write lib/conf/usrmgt-server.init
506
conf = open(usrmgtserver_initdfile, "w")
508
conf.write( '''#! /bin/sh
510
# Works for Ubuntu. Check before using on other distributions
513
# Provides: usrmgt-server
514
# Required-Start: $syslog $networking $urandom
515
# Required-Stop: $syslog
516
# Default-Start: 2 3 4 5
518
# Short-Description: IVLE user management server
519
# Description: Daemon connecting to the IVLE user management database.
522
PATH=/sbin:/bin:/usr/sbin:/usr/bin
523
DESC="IVLE user management server"
525
DAEMON=/opt/ivle/scripts/$NAME
526
DAEMON_ARGS="''' + str(usrmgt_port) + ''' ''' + usrmgt_magic + '''"
527
PIDFILE=/var/run/$NAME.pid
528
SCRIPTNAME=/etc/init.d/usrmgt-server
530
# Exit if the daemon does not exist
531
test -f $DAEMON || exit 0
533
# Load the VERBOSE setting and other rcS variables
534
[ -f /etc/default/rcS ] && . /etc/default/rcS
536
# Define LSB log_* functions.
537
# Depend on lsb-base (>= 3.0-6) to ensure that this file is present.
538
. /lib/lsb/init-functions
541
# Function that starts the daemon/service
546
# 0 if daemon has been started
547
# 1 if daemon was already running
548
# 2 if daemon could not be started
549
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON --test > /dev/null \
551
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON -- \
554
# Add code here, if necessary, that waits for the process to be ready
555
# to handle requests from services started subsequently which depend
556
# on this one. As a last resort, sleep for some time.
560
# Function that stops the daemon/service
565
# 0 if daemon has been stopped
566
# 1 if daemon was already stopped
567
# 2 if daemon could not be stopped
568
# other if a failure occurred
569
start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
571
[ "$RETVAL" = 2 ] && return 2
572
# Wait for children to finish too if this is a daemon that forks
573
# and if the daemon is only ever run from this initscript.
574
# If the above conditions are not satisfied then add some other code
575
# that waits for the process to drop all resources that could be
576
# needed by services started subsequently. A last resort is to
577
# sleep for some time.
578
start-stop-daemon --stop --quiet --oknodo --retry=0/30/KILL/5 --exec $DAEMON
579
[ "$?" = 2 ] && return 2
580
# Many daemons don't delete their pidfiles when they exit.
586
# Function that sends a SIGHUP to the daemon/service
590
# If the daemon can reload its configuration without
591
# restarting (for example, when it is sent a SIGHUP),
592
# then implement that here.
594
start-stop-daemon --stop --signal 1 --quiet --pidfile $PIDFILE --name $NAME
600
[ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
603
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
604
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
608
[ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
611
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
612
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
615
#reload|force-reload)
617
# If do_reload() is not implemented then leave this commented out
618
# and leave 'force-reload' as an alias for 'restart'.
620
#log_daemon_msg "Reloading $DESC" "$NAME"
624
restart|force-reload)
626
# If the "reload" option is implemented then remove the
627
# 'force-reload' alias
629
log_daemon_msg "Restarting $DESC" "$NAME"
636
1) log_end_msg 1 ;; # Old process is still running
637
*) log_end_msg 1 ;; # Failed to start
647
#echo "Usage: $SCRIPTNAME {start|stop|restart|reload|force-reload}" >&2
648
echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload}" >&2
657
except IOError, (errno, strerror):
658
print "IO error(%s): %s" % (errno, strerror)
661
# fix permissions as the file contains the database password
663
os.chmod('doc/setup/usrmgt-server.init', 0600)
664
except OSError, (errno, strerror):
665
print "WARNING: Couldn't chmod doc/setup/usrmgt-server.init:"
666
print "OS error(%s): %s" % (errno, strerror)
668
print "Successfully wrote lib/conf/usrmgt-server.init"
671
print "You may modify the configuration at any time by editing"
676
print usrmgtserver_initdfile