diff options
| author | Simon Rettberg | 2013-11-28 13:58:53 +0100 |
|---|---|---|
| committer | Simon Rettberg | 2013-11-28 13:58:53 +0100 |
| commit | 1a572e8064db374a1a8188f74e5d674e46eb34d5 (patch) | |
| tree | 319fd32bd5a8db6967cf4728c48ac65f9d1ffbed | |
| parent | [vmchooser] Consistent slxlog event ids (diff) | |
| parent | [pam] slxlog for global pam script (diff) | |
| download | tm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.tar.gz tm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.tar.xz tm-scripts-1a572e8064db374a1a8188f74e5d674e46eb34d5.zip | |
Merge branch 'master' of dnbd3:openslx-ng/tm-scripts
| -rwxr-xr-x | remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open | 31 | ||||
| -rw-r--r-- | server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent | 33 |
2 files changed, 33 insertions, 31 deletions
diff --git a/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open b/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open index 13f0cd3b..a46a6784 100755 --- a/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open +++ b/remote/modules/pam/data/opt/openslx/scripts/pam_script_ses_open @@ -3,8 +3,6 @@ # Needed as pam_script clears PATH export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/openslx/usr/sbin:/opt/openslx/usr/bin:/opt/openslx/sbin:/opt/openslx/bin" -echo "[${PAM_TYPE}] Opening session for ${PAM_USER}" - PERSISTENT_MOUNT_SCRIPT="/opt/openslx/scripts/pam_script_mount_persistent" TEMP_HOME_DIR="/home/${PAM_USER}" @@ -15,20 +13,17 @@ slxlog "session-open" "$PAM_USER logged in on $PAM_TTY" [ "x${PAM_USER}" == "xroot" ] && exit 0 # check if we already mounted the home directory -if mount | grep -q "$TEMP_HOME_DIR"; then - echo "[${PAM_TYPE}] Home directory of '${PAM_USER}' is already mounted." - exit 0 -fi +mount | grep -q "$TEMP_HOME_DIR" && exit 0 # no home, lets create it mkdir -p "${TEMP_HOME_DIR}" || \ - { echo "Could not create '${TEMP_HOME_DIR}'."; exit 1; } + { slxlog "pam-global-mktemphome" "Could not create '${TEMP_HOME_DIR}'."; exit 1; } chown -R "${PAM_USER}" "${TEMP_HOME_DIR}" || \ - { echo "Could not chown '${TEMP_HOME_DIR}' to ${PAM_USER}."; exit 1; } + { slxlog "pam-global-chtemphome" "Could not chown '${TEMP_HOME_DIR}' to ${PAM_USER}."; exit 1; } # now make it a tmpfs mount -t tmpfs -o size=100m tmpfs "${TEMP_HOME_DIR}" || \ - { echo "Could not make a tmpfs on ${TEMP_HOME_DIR}"; exit 1; } + { slxlog "pam-global-tmpfstemphome" "Could not make a tmpfs on ${TEMP_HOME_DIR}"; exit 1; } # create a WARNING.txt for the user cat > "${TEMP_HOME_DIR}/WARNING.txt" << EOF @@ -38,11 +33,23 @@ Your real home is under /home/<user>/PERSISTENT. Please save your files there. EOF +# create the PERSISTENT directory +mkdir -p "${PERSISTENT_HOME_DIR}" || \ + { slxlog "pam-global-mkpersistent" "Could not create '${PERSISTENT_HOME_DIR}'."; exit 1; } + +# always warn the user that his files won't be saved persistently +cat > "${PERSISTENT_HOME_DIR}/WARNING.txt" << EOF +Your home directory contents is unavailable. +DO NOT SAVE ANYTHING HERE AS ALL WILL BE LOST UPON REBOOT! +EOF + +chown -R "${PAM_USER}" "${PERSISTENT_HOME_DIR}" || \ + { slxlog "pam-global-chpersistent " "Could not chown '${PERSISTENT_HOME_DIR}' to '${PAM_USER}'."; exit 1; } + # now lets see if we have a persistent directory [ ! -e "${PERSISTENT_MOUNT_SCRIPT}" ] && exit 0 - . "${PERSISTENT_MOUNT_SCRIPT}" || \ - { echo "Could not source ${PERSISTENT_MOUNT_SCRIPT}."; exit 1; } + { slxlog "pam-global-sourcepersistent" "Could not source ${PERSISTENT_MOUNT_SCRIPT}."; exit 1; } # TODO: Symlinks mkdirs for certain programs etc. - +exit 0 diff --git a/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent b/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent index b5b23327..65634716 100644 --- a/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent +++ b/server/modules/pam-freiburg/opt/openslx/scripts/pam_script_mount_persistent @@ -13,45 +13,40 @@ PERSISTENT_HOME_DIR="${TEMP_HOME_DIR}/PERSISTENT" # These have a gid > 1000 if [ $(id -g ${PAM_USER}) -ge 1000 ]; then - # create the PERSISTENT directory - mkdir -p "${PERSISTENT_HOME_DIR}" || \ - { echo "Could not create '${PERSISTENT_HOME_DIR}'."; exit 1; } - chown -R "${PAM_USER}" "${PERSISTENT_HOME_DIR}" || \ - { echo "Could not chown '${PERSISTENT_HOME_DIR}' to '${PAM_USER}'."; exit 1; } - # generate keytab sslconnect npserv.ruf.uni-freiburg.de:3 > /etc/krb5.keytab || \ - { echo "Could not get /etc/kr5b.keytab from npserver.ruf.uni-freiburg.de"; exit 1; } + { slxlog "pam-freiburg-sslconnect" "Could not get /etc/kr5b.keytab from npserver.ruf.uni-freiburg.de"; exit 1; } chmod 600 /etc/krb5.keytab || \ - { echo "Could not run 'chmod 600 /etc/kr5b.keytab'"; exit 1; } + { slxlog "pam-freiburg-keytab" "Could not run 'chmod 600 /etc/kr5b.keytab'"; exit 1; } # determine fileserver and share for home directories ldapsearch -x -LLL uid="${PAM_USER}" homeDirectory rufFileserver > "/tmp/ldapsearch.${PAM_USER}" || \ - { echo "Could not search LDAP server for 'homeDirectory' and 'rufFileserver' parameters."; exit 1; } + { slxlog "pam-freiburg-ldapquery" "Could not query LDAP server for 'homeDirectory' and 'rufFileserver' parameters of user '${PAM_USER}'."; exit 1; } FILESERVER=$(cat /tmp/ldapsearch.${PAM_USER} | grep rufFileserver | cut -d" " -f2) VOLUME=$(cat /tmp/ldapsearch.${PAM_USER} | grep homeDirectory | cut -d" " -f2) - [ -z "${FILESERVER}" ] && echo "[${PAM_TYPE}] Could not determine fileserver for home directories. Aborting mount for ${PAM_USER}." && exit 1 - [ -z "${VOLUME}" ] && echo "[${PAM_TYPE}] Could not determine volume to mount. Aborting mount for ${PAM_USER}." && exit 1 + [ -z "${FILESERVER}" ] && slxlog "pam-freiburg-ldapfs" "LDAP server did not provide 'rufFileserver'. Aborting mount for ${PAM_USER}." && exit 1 + [ -z "${VOLUME}" ] && slxlog "pam-freiburg-ldapvolume" "LDAP server did not provide 'homeDirectory'. Aborting mount for ${PAM_USER}." && exit 1 # now we can mount the home directory! + MOUNT_OPTS="-t nfs4 -o rw,nosuid,nodev,nolock,intr,hard,sloppy,sec=krb5p" + SIGNAL=$(mktemp) - rm -f -- "$SIGNAL" - (mount -t nfs4 -o rw,nosuid,nodev,nolock,intr,hard,sloppy,sec=krb5p "$FILESERVER:$VOLUME" "${PERSISTENT_HOME_DIR}" || touch "$SIGNAL") & + rm -f -- "${SIGNAL}" + (mount "${MOUNT_OPTS}" "${FILESERVER}:${VOLUME}" "${PERSISTENT_HOME_DIR}" || touch "${SIGNAL}") & MOUNT_PID=$! for COUNTER in 1 2 4 4; do - kill -0 "$MOUNT_PID" 2>/dev/null || break - sleep "$COUNTER" + kill -0 "${MOUNT_PID}" 2>/dev/null || break + sleep "${COUNTER}" done - if [ -e "$SIGNAL" ] || kill -9 "$MOUNT_PID" 2>/dev/null; then - echo "Your home directory contents is unavailable. DO NOT SAVE ANYTHING HERE AS ALL WILL BE LOST UPON REBOOT!" > "${PERSISTENT_HOME_DIR}/WARNING.txt" - rm -f -- "$SIGNAL" + if [ -e "${SIGNAL}" ] || kill -9 "${MOUNT_PID}" 2>/dev/null; then + slxlog "pam-freiburg" "Mount of '${FILESERVER}:${VOLUME}' to '${PERSISTENT_HOME_DIR}' failed. (Args: ${MOUNT_OPTS})" + rm -f -- "${SIGNAL}" else - echo "Mounting of $FILESERVER:$VOLUME on ${PERSISTENT_HOME_DIR} succeeded." exit 0 fi fi |
