summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSimon Rettberg2013-11-28 13:58:53 +0100
committerSimon Rettberg2013-11-28 13:58:53 +0100
commit1a572e8064db374a1a8188f74e5d674e46eb34d5 (patch)
tree319fd32bd5a8db6967cf4728c48ac65f9d1ffbed
parent[vmchooser] Consistent slxlog event ids (diff)
parent[pam] slxlog for global pam script (diff)
downloadtm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.tar.gz
tm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.tar.xz
tm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.zip
Merge branch 'master' of dnbd3:openslx-ng/tm-scripts
-rwxr-xr-xremote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open31
-rw-r--r--server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent33
2 files changed, 33 insertions, 31 deletions
diff --git a/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open b/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open
index 13f0cd3b..a46a6784 100755
--- a/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open
+++ b/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open
@@ -3,8 +3,6 @@
# Needed as pam_script clears PATH
export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/openslx/usr/sbin:/opt/openslx/usr/bin:/opt/openslx/sbin:/opt/openslx/bin"
-echo "[${PAM_TYPE}] Opening session for ${PAM_USER}"
-
PERSISTENT_MOUNT_SCRIPT="/opt/openslx/scripts/pam_script_mount_persistent"
TEMP_HOME_DIR="/home/${PAM_USER}"
@@ -15,20 +13,17 @@ slxlog "session-open" "$PAM_USER logged in on $PAM_TTY"
[ "x${PAM_USER}" == "xroot" ] && exit 0
# check if we already mounted the home directory
-if mount | grep -q "$TEMP_HOME_DIR"; then
- echo "[${PAM_TYPE}] Home directory of '${PAM_USER}' is already mounted."
- exit 0
-fi
+mount | grep -q "$TEMP_HOME_DIR" && exit 0
# no home, lets create it
mkdir -p "${TEMP_HOME_DIR}" || \
- { echo "Could not create '${TEMP_HOME_DIR}'."; exit 1; }
+ { slxlog "pam-global-mktemphome" "Could not create '${TEMP_HOME_DIR}'."; exit 1; }
chown -R "${PAM_USER}" "${TEMP_HOME_DIR}" || \
- { echo "Could not chown '${TEMP_HOME_DIR}' to ${PAM_USER}."; exit 1; }
+ { slxlog "pam-global-chtemphome" "Could not chown '${TEMP_HOME_DIR}' to ${PAM_USER}."; exit 1; }
# now make it a tmpfs
mount -t tmpfs -o size=100m tmpfs "${TEMP_HOME_DIR}" || \
- { echo "Could not make a tmpfs on ${TEMP_HOME_DIR}"; exit 1; }
+ { slxlog "pam-global-tmpfstemphome" "Could not make a tmpfs on ${TEMP_HOME_DIR}"; exit 1; }
# create a WARNING.txt for the user
cat > "${TEMP_HOME_DIR}/WARNING.txt" << EOF
@@ -38,11 +33,23 @@ Your real home is under /home/<user>/PERSISTENT.
Please save your files there.
EOF
+# create the PERSISTENT directory
+mkdir -p "${PERSISTENT_HOME_DIR}" || \
+ { slxlog "pam-global-mkpersistent" "Could not create '${PERSISTENT_HOME_DIR}'."; exit 1; }
+
+# always warn the user that his files won't be saved persistently
+cat > "${PERSISTENT_HOME_DIR}/WARNING.txt" << EOF
+Your home directory contents is unavailable.
+DO NOT SAVE ANYTHING HERE AS ALL WILL BE LOST UPON REBOOT!
+EOF
+
+chown -R "${PAM_USER}" "${PERSISTENT_HOME_DIR}" || \
+ { slxlog "pam-global-chpersistent " "Could not chown '${PERSISTENT_HOME_DIR}' to '${PAM_USER}'."; exit 1; }
+
# now lets see if we have a persistent directory
[ ! -e "${PERSISTENT_MOUNT_SCRIPT}" ] && exit 0
-
. "${PERSISTENT_MOUNT_SCRIPT}" || \
- { echo "Could not source ${PERSISTENT_MOUNT_SCRIPT}."; exit 1; }
+ { slxlog "pam-global-sourcepersistent" "Could not source ${PERSISTENT_MOUNT_SCRIPT}."; exit 1; }
# TODO: Symlinks mkdirs for certain programs etc.
-
+exit 0
diff --git a/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent b/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent
index b5b23327..65634716 100644
--- a/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent
+++ b/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent
@@ -13,45 +13,40 @@ PERSISTENT_HOME_DIR="${TEMP_HOME_DIR}/PERSISTENT"
# These have a gid > 1000
if [ $(id -g ${PAM_USER}) -ge 1000 ]; then
- # create the PERSISTENT directory
- mkdir -p "${PERSISTENT_HOME_DIR}" || \
- { echo "Could not create '${PERSISTENT_HOME_DIR}'."; exit 1; }
- chown -R "${PAM_USER}" "${PERSISTENT_HOME_DIR}" || \
- { echo "Could not chown '${PERSISTENT_HOME_DIR}' to '${PAM_USER}'."; exit 1; }
-
# generate keytab
sslconnect npserv.ruf.uni-freiburg.de:3 > /etc/krb5.keytab || \
- { echo "Could not get /etc/kr5b.keytab from npserver.ruf.uni-freiburg.de"; exit 1; }
+ { slxlog "pam-freiburg-sslconnect" "Could not get /etc/kr5b.keytab from npserver.ruf.uni-freiburg.de"; exit 1; }
chmod 600 /etc/krb5.keytab || \
- { echo "Could not run 'chmod 600 /etc/kr5b.keytab'"; exit 1; }
+ { slxlog "pam-freiburg-keytab" "Could not run 'chmod 600 /etc/kr5b.keytab'"; exit 1; }
# determine fileserver and share for home directories
ldapsearch -x -LLL uid="${PAM_USER}" homeDirectory rufFileserver > "/tmp/ldapsearch.${PAM_USER}" || \
- { echo "Could not search LDAP server for 'homeDirectory' and 'rufFileserver' parameters."; exit 1; }
+ { slxlog "pam-freiburg-ldapquery" "Could not query LDAP server for 'homeDirectory' and 'rufFileserver' parameters of user '${PAM_USER}'."; exit 1; }
FILESERVER=$(cat /tmp/ldapsearch.${PAM_USER} | grep rufFileserver | cut -d" " -f2)
VOLUME=$(cat /tmp/ldapsearch.${PAM_USER} | grep homeDirectory | cut -d" " -f2)
- [ -z "${FILESERVER}" ] && echo "[${PAM_TYPE}] Could not determine fileserver for home directories. Aborting mount for ${PAM_USER}." && exit 1
- [ -z "${VOLUME}" ] && echo "[${PAM_TYPE}] Could not determine volume to mount. Aborting mount for ${PAM_USER}." && exit 1
+ [ -z "${FILESERVER}" ] && slxlog "pam-freiburg-ldapfs" "LDAP server did not provide 'rufFileserver'. Aborting mount for ${PAM_USER}." && exit 1
+ [ -z "${VOLUME}" ] && slxlog "pam-freiburg-ldapvolume" "LDAP server did not provide 'homeDirectory'. Aborting mount for ${PAM_USER}." && exit 1
# now we can mount the home directory!
+ MOUNT_OPTS="-t nfs4 -o rw,nosuid,nodev,nolock,intr,hard,sloppy,sec=krb5p"
+
SIGNAL=$(mktemp)
- rm -f -- "$SIGNAL"
- (mount -t nfs4 -o rw,nosuid,nodev,nolock,intr,hard,sloppy,sec=krb5p "$FILESERVER:$VOLUME" "${PERSISTENT_HOME_DIR}" || touch "$SIGNAL") &
+ rm -f -- "${SIGNAL}"
+ (mount "${MOUNT_OPTS}" "${FILESERVER}:${VOLUME}" "${PERSISTENT_HOME_DIR}" || touch "${SIGNAL}") &
MOUNT_PID=$!
for COUNTER in 1 2 4 4; do
- kill -0 "$MOUNT_PID" 2>/dev/null || break
- sleep "$COUNTER"
+ kill -0 "${MOUNT_PID}" 2>/dev/null || break
+ sleep "${COUNTER}"
done
- if [ -e "$SIGNAL" ] || kill -9 "$MOUNT_PID" 2>/dev/null; then
- echo "Your home directory contents is unavailable. DO NOT SAVE ANYTHING HERE AS ALL WILL BE LOST UPON REBOOT!" > "${PERSISTENT_HOME_DIR}/WARNING.txt"
- rm -f -- "$SIGNAL"
+ if [ -e "${SIGNAL}" ] || kill -9 "${MOUNT_PID}" 2>/dev/null; then
+ slxlog "pam-freiburg" "Mount of '${FILESERVER}:${VOLUME}' to '${PERSISTENT_HOME_DIR}' failed. (Args: ${MOUNT_OPTS})"
+ rm -f -- "${SIGNAL}"
else
- echo "Mounting of $FILESERVER:$VOLUME on ${PERSISTENT_HOME_DIR} succeeded."
exit 0
fi
fi