101
101
# Needed by python
102
102
'/usr/bin/python%s' % PYTHON_VERSION,
103
# Needed by fileservice
104
'/lib/libcom_err.so.2',
105
'/lib/libcrypt.so.1',
106
'/lib/libkeyutils.so.1',
107
'/lib/libresolv.so.2',
110
'/usr/lib/libapr-1.so.0',
111
'/usr/lib/libaprutil-1.so.0',
112
'/usr/lib/libdb-4.4.so',
113
'/usr/lib/libexpat.so.1',
114
'/usr/lib/libgcrypt.so.11',
115
'/usr/lib/libgnutls.so.13',
116
'/usr/lib/libgpg-error.so.0',
117
'/usr/lib/libgssapi_krb5.so.2',
118
'/usr/lib/libk5crypto.so.3',
119
'/usr/lib/libkrb5.so.3',
120
'/usr/lib/libkrb5support.so.0',
121
'/usr/lib/liblber.so.2',
122
'/usr/lib/libldap_r.so.2',
123
'/usr/lib/libneon.so.26',
124
'/usr/lib/libpq.so.5',
125
'/usr/lib/libsasl2.so.2',
126
'/usr/lib/libsqlite3.so.0',
127
'/usr/lib/libsvn_client-1.so.1',
128
'/usr/lib/libsvn_delta-1.so.1',
129
'/usr/lib/libsvn_diff-1.so.1',
130
'/usr/lib/libsvn_fs-1.so.1',
131
'/usr/lib/libsvn_fs_base-1.so.1',
132
'/usr/lib/libsvn_fs_fs-1.so.1',
133
'/usr/lib/libsvn_ra-1.so.1',
134
'/usr/lib/libsvn_ra_dav-1.so.1',
135
'/usr/lib/libsvn_ra_local-1.so.1',
136
'/usr/lib/libsvn_ra_svn-1.so.1',
137
'/usr/lib/libsvn_repos-1.so.1',
138
'/usr/lib/libsvn_subr-1.so.1',
139
'/usr/lib/libsvn_wc-1.so.1',
140
'/usr/lib/libtasn1.so.3',
141
'/usr/lib/libxml2.so.2',
103
142
# Needed by matplotlib
104
143
'/usr/lib/i686/cmov/libssl.so.0.9.8',
105
144
'/usr/lib/i686/cmov/libcrypto.so.0.9.8',
133
181
'/etc/ld.so.conf.d': 'jail/etc/ld.so.conf.d',
185
"""A configuration option; one of the things written to conf.py."""
186
def __init__(self, option_name, default, prompt, comment):
187
"""Creates a configuration option.
188
option_name: Name of the variable in conf.py. Also name of the
189
command-line argument to setup.py conf.
190
default: Default value for this variable.
191
prompt: (Short) string presented during the interactive prompt in
193
comment: (Long) comment string stored in conf.py. Each line of this
194
string should begin with a '#'.
196
self.option_name = option_name
197
self.default = default
199
self.comment = comment
201
# Configuration options, defaults and descriptions
203
config_options.append(ConfigOption("root_dir", "/",
204
"""Root directory where IVLE is located (in URL space):""",
206
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
208
# eg. "/" or "/ivle"."""))
209
config_options.append(ConfigOption("ivle_install_dir", "/opt/ivle",
210
'Root directory where IVLE will be installed (on the local file '
213
# In the local file system, where IVLE is actually installed.
214
# This directory should contain the "www" and "bin" directories."""))
215
config_options.append(ConfigOption("jail_base", "/home/informatics/jails",
216
"""Location of Directories
217
=======================
218
Root directory where the jails (containing user files) are stored
219
(on the local file system):""",
221
# In the local file system, where are the student/user file spaces located.
222
# The user jails are expected to be located immediately in subdirectories of
223
# this location."""))
224
config_options.append(ConfigOption("subjects_base",
225
"/home/informatics/subjects",
226
"""Root directory where the subject directories (containing worksheets
227
and other per-subject files) are stored (on the local file system):""",
229
# In the local file system, where are the per-subject file spaces located.
230
# The individual subject directories are expected to be located immediately
231
# in subdirectories of this location."""))
232
config_options.append(ConfigOption("exercises_base",
233
"/home/informatics/exercises",
234
"""Root directory where the exercise directories (containing
235
subject-independent exercise sheets) are stored (on the local file
238
# In the local file system, where are the subject-independent exercise sheet
239
# file spaces located."""))
240
config_options.append(ConfigOption("public_host", "public.localhost",
241
"""Hostname which will cause the server to go into "public mode",
242
providing login-free access to student's published work:""",
244
# The server goes into "public mode" if the browser sends a request with this
245
# host. This is for security reasons - we only serve public student files on a
246
# separate domain to the main IVLE site.
247
# Public mode does not use cookies, and serves only public content.
248
# Private mode (normal mode) requires login, and only serves files relevant to
249
# the logged-in user."""))
250
config_options.append(ConfigOption("allowed_uids", "33",
251
"""UID of the web server process which will run IVLE.
252
Only this user may execute the trampoline. May specify multiple users as
253
a comma-separated list.
256
# The User-ID of the web server process which will run IVLE, and any other
257
# users who are allowed to run the trampoline. This is stores as a string of
258
# comma-separated integers, simply because it is not used within Python, only
259
# used by the setup program to write to conf.h (see setup.py config)."""))
260
config_options.append(ConfigOption("db_host", "localhost",
261
"""PostgreSQL Database config
262
==========================
263
Hostname of the DB server:""",
265
### PostgreSQL Database config ###
266
# Database server hostname"""))
267
config_options.append(ConfigOption("db_port", "5432",
268
"""Port of the DB server:""",
270
# Database server port"""))
271
config_options.append(ConfigOption("db_dbname", "ivle",
272
"""Database name:""",
275
config_options.append(ConfigOption("db_user", "postgres",
276
"""Username for DB server login:""",
278
# Database username"""))
279
config_options.append(ConfigOption("db_password", "",
280
"""Password for DB server login:
281
(Caution: This password is stored in plaintext in lib/conf/conf.py)""",
283
# Database password"""))
284
config_options.append(ConfigOption("auth_modules", "ldap_auth",
285
"""Authentication config
286
=====================
287
Comma-separated list of authentication modules. Only "ldap" is available
290
# Comma-separated list of authentication modules.
291
# These refer to importable Python modules in the www/auth directory.
292
# Modules "ldap" and "guest" are available in the source tree, but
293
# other modules may be plugged in to auth against organisation-specific
294
# auth backends."""))
295
config_options.append(ConfigOption("ldap_url", "ldaps://www.example.com",
296
"""(LDAP options are only relevant if "ldap" is included in the list of
298
URL for LDAP authentication server:""",
300
# URL for LDAP authentication server"""))
301
config_options.append(ConfigOption("ldap_format_string",
302
"uid=%s,ou=users,o=example",
303
"""Format string for LDAP auth request:
304
(Must contain a single "%s" for the user's login name)""",
306
# Format string for LDAP auth request
307
# (Must contain a single "%s" for the user's login name)"""))
308
config_options.append(ConfigOption("svn_addr", "http://svn.localhost/",
311
The base url for accessing subversion repositories:""",
313
# The base url for accessing subversion repositories."""))
314
config_options.append(ConfigOption("svn_conf", "/opt/ivle/svn/svn.conf",
315
"""The location of the subversion configuration file used by apache
316
to host the user repositories:""",
318
# The location of the subversion configuration file used by
319
# apache to host the user repositories."""))
320
config_options.append(ConfigOption("svn_repo_path", "/home/informatics/repositories",
321
"""The root directory for the subversion repositories:""",
323
# The root directory for the subversion repositories."""))
324
config_options.append(ConfigOption("svn_auth_ivle", "/opt/ivle/svn/ivle.auth",
325
"""The location of the password file used to authenticate users
326
of the subversion repository from the ivle server:""",
328
# The location of the password file used to authenticate users
329
# of the subversion repository from the ivle server."""))
330
config_options.append(ConfigOption("svn_auth_local", "/opt/ivle/svn/local.auth",
331
"""The location of the password file used to authenticate local users
332
of the subversion repository:""",
334
# The location of the password file used to authenticate local users
335
# of the subversion repository."""))
336
config_options.append(ConfigOption("usrmgt_host", "localhost",
337
"""User Management Server config
338
============================
339
The hostname where the usrmgt-server runs:""",
341
# The hostname where the usrmgt-server runs."""))
342
config_options.append(ConfigOption("usrmgt_port", "2178",
343
"""The port where the usrmgt-server runs:""",
345
# The port where the usrmgt-server runs."""))
346
config_options.append(ConfigOption("usrmgt_magic", "",
347
"""The password for the usrmgt-server:""",
349
# The password for the usrmgt-server."""))
136
351
# Try importing existing conf, but if we can't just set up defaults
137
352
# The reason for this is that these settings are used by other phases
138
353
# of setup besides conf, so we need to know them.
139
354
# Also this allows you to hit Return to accept the existing value.
141
confmodule = __import__("www/conf/conf")
143
root_dir = confmodule.root_dir
147
ivle_install_dir = confmodule.ivle_install_dir
149
ivle_install_dir = "/opt/ivle"
151
public_host = confmodule.public_host
153
public_host = "public.localhost"
155
jail_base = confmodule.jail_base
157
jail_base = "/home/informatics/jails"
159
subjects_base = confmodule.subjects_base
161
subjects_base = "/home/informatics/subjects"
356
confmodule = __import__("lib/conf/conf")
357
for opt in config_options:
359
globals()[opt.option_name] = confmodule.__dict__[opt.option_name]
361
globals()[opt.option_name] = opt.default
162
362
except ImportError:
163
363
# Just set reasonable defaults
165
ivle_install_dir = "/opt/ivle"
166
public_host = "public.localhost"
167
jail_base = "/home/informatics/jails"
168
subjects_base = "/home/informatics/subjects"
364
for opt in config_options:
365
globals()[opt.option_name] = opt.default
172
367
# Try importing install_list, but don't fail if we can't, because listmake can
173
368
# function without it.
432
638
print """This tool will create the following files:
435
642
prompting you for details about your configuration. The file will be
436
643
overwritten if it already exists. It will *not* install or deploy IVLE.
438
645
Please hit Ctrl+C now if you do not wish to do this.
439
""" % (conffile, conf_hfile)
646
""" % (conffile, jailconffile, conf_hfile)
441
648
# Get information from the administrator
442
649
# If EOF is encountered at any time during the questioning, just exit
445
root_dir = query_user(root_dir,
446
"""Root directory where IVLE is located (in URL space):""")
447
ivle_install_dir = query_user(ivle_install_dir,
448
'Root directory where IVLE will be installed (on the local file '
450
jail_base = query_user(jail_base,
451
"""Root directory where the jails (containing user files) are stored
452
(on the local file system):""")
453
subjects_base = query_user(subjects_base,
454
"""Root directory where the subject directories (containing worksheets
455
and other per-subject files) are stored (on the local file system):""")
456
public_host = query_user(public_host,
457
"""Hostname which will cause the server to go into "public mode",
458
providing login-free access to student's published work:""")
459
allowed_uids = query_user(allowed_uids,
460
"""UID of the web server process which will run IVLE.
461
Only this user may execute the trampoline. May specify multiple users as
462
a comma-separated list.
652
for opt in config_options:
653
globals()[opt.option_name] = \
654
query_user(globals()[opt.option_name], opt.prompt)
466
656
opts = dict(opts)
467
657
# Non-interactive mode. Parse the options.
468
if '--root_dir' in opts:
469
root_dir = opts['--root_dir']
470
if '--ivle_install_dir' in opts:
471
ivle_install_dir = opts['--ivle_install_dir']
472
if '--jail_base' in opts:
473
jail_base = opts['--jail_base']
474
if '--subjects_base' in opts:
475
jail_base = opts['--subjects_base']
476
if '--public_host' in opts:
477
public_host = opts['--public_host']
478
if '--allowed_uids' in opts:
479
allowed_uids = opts['--allowed_uids']
658
for opt in config_options:
659
if '--' + opt.option_name in opts:
660
globals()[opt.option_name] = opts['--' + opt.option_name]
481
662
# Error handling on input values
483
allowed_uids = map(int, allowed_uids.split(','))
664
allowed_uids_list = map(int, allowed_uids.split(','))
484
665
except ValueError:
485
666
print >>sys.stderr, (
486
667
"Invalid UID list (%s).\n"
487
668
"Must be a comma-separated list of integers." % allowed_uids)
671
db_port = int(db_port)
672
if db_port < 0 or db_port >= 65536: raise ValueError()
674
print >>sys.stderr, (
675
"Invalid DB port (%s).\n"
676
"Must be an integer between 0 and 65535." % repr(db_port))
679
usrmgt_port = int(usrmgt_port)
680
if usrmgt_port < 0 or usrmgt_port >= 65536: raise ValueError()
682
print >>sys.stderr, (
683
"Invalid user management port (%s).\n"
684
"Must be an integer between 0 and 65535." % repr(usrmgt_port))
490
# Write www/conf/conf.py
687
# Write lib/conf/conf.py
493
690
conf = open(conffile, "w")
497
694
# Miscellaneous application settings
697
for opt in config_options:
698
conf.write('%s\n%s = %s\n' % (opt.comment, opt.option_name,
699
repr(globals()[opt.option_name])))
702
except IOError, (errno, strerror):
703
print "IO error(%s): %s" % (errno, strerror)
706
print "Successfully wrote lib/conf/conf.py"
708
# Write conf/jailconf.py
711
conf = open(jailconffile, "w")
713
# In the "in-jail" version of conf, we don't need MOST of the details
714
# (it would be a security risk to have them here).
715
# So we just write root_dir, and jail_base is "/".
716
# (jail_base being "/" means "jail-relative" paths are relative to "/"
717
# when inside the jail.)
718
conf.write("""# IVLE Configuration File
720
# Miscellaneous application settings
721
# (User jail version)
500
724
# In URL space, where in the site is IVLE located. (All URLs will be prefixed
502
726
# eg. "/" or "/ivle".
505
# In the local file system, where IVLE is actually installed.
506
# This directory should contain the "www" and "bin" directories.
507
ivle_install_dir = "%s"
509
# The server goes into "public mode" if the browser sends a request with this
510
# host. This is for security reasons - we only serve public student files on a
511
# separate domain to the main IVLE site.
512
# Public mode does not use cookies, and serves only public content.
513
# Private mode (normal mode) requires login, and only serves files relevant to
514
# the logged-in user.
517
729
# In the local file system, where are the student/user file spaces located.
518
730
# The user jails are expected to be located immediately in subdirectories of
522
# In the local file system, where are the per-subject file spaces located.
523
# The individual subject directories are expected to be located immediately
524
# in subdirectories of this location.
526
""" % (root_dir, ivle_install_dir, public_host, jail_base, subjects_base))
734
# The hostname for serving publicly accessible pages
736
""" % (repr(root_dir),repr(public_host)))
529
739
except IOError, (errno, strerror):
530
740
print "IO error(%s): %s" % (errno, strerror)
533
print "Successfully wrote www/conf/conf.py"
743
print "Successfully wrote lib/conf/jailconf.py"
535
745
# Write trampoline/conf.h
590
806
action_mkdir('jail/home', dry)
591
807
action_mkdir('jail/tmp', dry)
809
# Chmod the tmp directory to world writable
810
action_chmod_w('jail/tmp', dry)
593
812
# Copy all console and operating system files into the jail
594
action_copylist(install_list.list_console, 'jail/opt/ivle', dry)
813
action_copylist(install_list.list_scripts, 'jail/opt/ivle', dry)
595
814
copy_os_files_jail(dry)
596
815
# Chmod the python console
597
action_chmod_x('jail/opt/ivle/console/python-console', dry)
816
action_chmod_x('jail/opt/ivle/scripts/python-console', dry)
817
action_chmod_x('jail/opt/ivle/scripts/fileservice', dry)
819
# Also copy the IVLE lib directory into the jail
820
# This is necessary for running certain scripts
821
action_copylist(install_list.list_lib, 'jail/opt/ivle', dry)
822
# IMPORTANT: The file jail/opt/ivle/lib/conf/conf.py contains details
823
# which could compromise security if left in the jail (such as the DB
825
# The "safe" version is in jailconf.py. Delete conf.py and replace it with
827
action_copyfile('lib/conf/jailconf.py',
828
'jail/opt/ivle/lib/conf/conf.py', dry)
600
830
# Compile .py files into .pyc or .pyo files
601
831
compileall.compile_dir('www', quiet=True)
602
compileall.compile_dir('console', quiet=True)
832
compileall.compile_dir('lib', quiet=True)
833
compileall.compile_dir('scripts', quiet=True)
834
compileall.compile_dir('jail/opt/ivle/lib', quiet=True)
836
# Set up ivle.pth inside the jail
837
# Need to set /opt/ivle/lib to be on the import path
839
"jail/usr/lib/python%s/site-packages/ivle.pth" % PYTHON_VERSION
840
f = open(ivle_pth, 'w')
841
f.write('/opt/ivle/lib\n')