Openembedded Core Discussions
 help / color / mirror / Atom feed
* [PATCH 1/2] shadow-native: Add --root option in groupmems
@ 2013-06-26  2:54 mikhail_durnev
  2013-06-26  2:54 ` [PATCH 2/2] useradd.bbclass: Add members to a group mikhail_durnev
  0 siblings, 1 reply; 2+ messages in thread
From: mikhail_durnev @ 2013-06-26  2:54 UTC (permalink / raw)
  To: openembedded-core

From: Mikhail Durnev <mikhail_durnev@mentor.com>

    Patch add_root_cmd_groupmems.patch that we apply to shadow-native
    allows program groupmems from the shadow utility package to chroot()
    so it can be used to modify etc/passwd and etc/group if they are
    located in a sysroot.

    The --root option in groupmems is needed for class useradd.

Signed-off-by: Mikhail Durnev <mikhail_durnev@mentor.com>
---
 .../shadow/files/add_root_cmd_groupmems.patch      |   75 ++++++++++++++++++++
 .../shadow/shadow-native_4.1.4.3.bb                |    1 +
 2 files changed, 76 insertions(+)
 create mode 100644 meta/recipes-extended/shadow/files/add_root_cmd_groupmems.patch

diff --git a/meta/recipes-extended/shadow/files/add_root_cmd_groupmems.patch b/meta/recipes-extended/shadow/files/add_root_cmd_groupmems.patch
new file mode 100644
index 0000000..4044496
--- /dev/null
+++ b/meta/recipes-extended/shadow/files/add_root_cmd_groupmems.patch
@@ -0,0 +1,75 @@
+Add a --root command option to groupmems utility.
+
+This option allows the utility to be chrooted when run under pseudo.
+
+Signed-off-by: Mikhail Durnev <mikhail_durnev@mentor.com>
+
+diff -Naur old/src/groupmems.c new/src/groupmems.c
+--- old/src/groupmems.c	2011-02-13 11:58:16.000000000 -0600
++++ new/src/groupmems.c	2013-05-30 04:45:38.000000000 -0500
+@@ -60,6 +60,7 @@
+ #define EXIT_MEMBER_EXISTS	7	/* member of group already exists */
+ #define EXIT_INVALID_USER	8	/* specified user does not exist */
+ #define EXIT_INVALID_GROUP	9	/* specified group does not exist */
++#define EXIT_BAD_ARG		10	/* invalid argument to option */
+
+ /*
+  * Global variables
+@@ -79,6 +80,7 @@
+ static bool is_shadowgrp;
+ static bool sgr_locked = false;
+ #endif
++static const char *newroot = "";
+
+ /* local function prototypes */
+ static char *whoami (void);
+@@ -368,6 +370,7 @@
+	                "Options:\n"
+	                "  -g, --group groupname         change groupname instead of the user's group\n"
+	                "                                (root only)\n"
++	                "  -R, --root CHROOT_DIR         directory to chroot into\n"
+	                "\n"
+	                "Actions:\n"
+	                "  -a, --add username            add username to the members of the group\n"
+@@ -391,10 +394,11 @@
+		{"group", required_argument, NULL, 'g'},
+		{"list", no_argument, NULL, 'l'},
+		{"purge", no_argument, NULL, 'p'},
++		{"root", required_argument, NULL, 'R'},
+		{NULL, 0, NULL, '\0'}
+	};
+
+-	while ((arg = getopt_long (argc, argv, "a:d:g:lp", long_options,
++	while ((arg = getopt_long (argc, argv, "a:d:g:lpR:", long_options,
+	                           &option_index)) != EOF) {
+		switch (arg) {
+		case 'a':
+@@ -416,6 +420,28 @@
+			purge = true;
+			++exclusive;
+			break;
++		case 'R':
++			if ('/' != optarg[0]) {
++				fprintf (stderr,
++					 _("%s: invalid chroot path '%s'\n"),
++					Prog, optarg);
++				exit (EXIT_BAD_ARG);
++			}
++			newroot = optarg;
++
++			if (access (newroot, F_OK) != 0) {
++				fprintf(stderr,
++					_("%s: chroot directory %s does not exist\n"),
++					Prog, newroot);
++				exit (EXIT_BAD_ARG);
++			}
++			if ( chroot(newroot) != 0 ) {
++				fprintf(stderr,
++					_("%s: unable to chroot to directory %s\n"),
++					Prog, newroot);
++				exit (EXIT_BAD_ARG);
++			}
++			break;
+		default:
+			usage ();
+		}
diff --git a/meta/recipes-extended/shadow/shadow-native_4.1.4.3.bb b/meta/recipes-extended/shadow/shadow-native_4.1.4.3.bb
index 2c4edbe..1ed5d4e 100644
--- a/meta/recipes-extended/shadow/shadow-native_4.1.4.3.bb
+++ b/meta/recipes-extended/shadow/shadow-native_4.1.4.3.bb
@@ -17,6 +17,7 @@ SRC_URI = "http://pkg-shadow.alioth.debian.org/releases/${BPN}-${PV}.tar.bz2 \
            file://disable-syslog.patch \
            file://useradd.patch \
            file://shadow_fix_for_automake-1.12.patch \
+           file://add_root_cmd_groupmems.patch \
            "
 
 SRC_URI[md5sum] = "b8608d8294ac88974f27b20f991c0e79"
-- 
1.7.9.5



^ permalink raw reply related	[flat|nested] 2+ messages in thread

* [PATCH 2/2] useradd.bbclass: Add members to a group
  2013-06-26  2:54 [PATCH 1/2] shadow-native: Add --root option in groupmems mikhail_durnev
@ 2013-06-26  2:54 ` mikhail_durnev
  0 siblings, 0 replies; 2+ messages in thread
From: mikhail_durnev @ 2013-06-26  2:54 UTC (permalink / raw)
  To: openembedded-core

From: Mikhail Durnev <mikhail_durnev@mentor.com>

useradd.bbclass supports adding new users and new groups. But it does not
support adding existing users to existing groups.

There is a need of adding users to some groups (e.g. audio). The class was
extended to call groupmems utility with arguments passed via GROUPMEMS_PARAM.

Signed-off-by: Mikhail Durnev <mikhail_durnev@mentor.com>
---
 meta/classes/useradd.bbclass |   68 ++++++++++++++++++++++++++++++++++++++----
 1 file changed, 63 insertions(+), 5 deletions(-)

diff --git a/meta/classes/useradd.bbclass b/meta/classes/useradd.bbclass
index e50c889..3fe011d 100644
--- a/meta/classes/useradd.bbclass
+++ b/meta/classes/useradd.bbclass
@@ -24,13 +24,15 @@ if test "x$D" != "x"; then
 	OPT="--root $D"
 
 	# Add groups and users defined for all recipe packages
-	GROUPADD_PARAM="${@get_all_cmd_params(d, 'group')}"
-	USERADD_PARAM="${@get_all_cmd_params(d, 'user')}"
+	GROUPADD_PARAM="${@get_all_cmd_params(d, 'groupadd')}"
+	USERADD_PARAM="${@get_all_cmd_params(d, 'useradd')}"
+	GROUPMEMS_PARAM="${@get_all_cmd_params(d, 'groupmems')}"
 else
 	# Installing onto a target
 	# Add groups and users defined only for this package
 	GROUPADD_PARAM="${GROUPADD_PARAM}"
 	USERADD_PARAM="${USERADD_PARAM}"
+	GROUPMEMS_PARAM="${GROUPMEMS_PARAM}"
 fi
 
 # Perform group additions first, since user additions may depend
@@ -114,6 +116,62 @@ if test "x$USERADD_PARAM" != "x"; then
 		remaining=`echo "$remaining" | cut -d ';' -f 2-`
 	done
 fi
+
+if test "x$GROUPMEMS_PARAM" != "x"; then
+	echo "Running groupmems commands..."
+	# groupmems fails if /etc/gshadow does not exist
+	if [ -f $SYSROOT${sysconfdir}/gshadow ]; then
+		gshadow="yes"
+	else
+		gshadow="no"
+		touch $SYSROOT${sysconfdir}/gshadow
+	fi
+	# Invoke multiple instances of groupmems for parameter lists
+	# separated by ';'
+	opts=`echo "$GROUPMEMS_PARAM" | cut -d ';' -f 1`
+	remaining=`echo "$GROUPMEMS_PARAM" | cut -d ';' -f 2-`
+	while test "x$opts" != "x"; do
+		groupname=`echo "$opts" | awk '{ for (i = 1; i < NF; i++) if ($i == "-g" || $i == "--group") print $(i+1) }'`
+		username=`echo "$opts" | awk '{ for (i = 1; i < NF; i++) if ($i == "-a" || $i == "--add") print $(i+1) }'`
+		echo "$groupname $username"
+		mem_exists=`grep "^$groupname:[^:]*:[^:]*:\([^,]*,\)*$username\(,[^,]*\)*" $SYSROOT/etc/group || true`
+		if test "x$mem_exists" = "x"; then
+			count=1
+			while true; do
+				eval $PSEUDO groupmems $OPT $opts || true
+				mem_exists=`grep "^$groupname:[^:]*:[^:]*:\([^,]*,\)*$username\(,[^,]*\)*" $SYSROOT/etc/group || true`
+				if test "x$mem_exists" = "x"; then
+					# File locking issues can require us to retry the command
+					echo "WARNING: groupmems command did not succeed. Retrying..."
+					sleep 1
+				else
+					break
+				fi
+				count=`expr $count + 1`
+				if test $count = 11; then
+					echo "ERROR: tried running groupmems command 10 times without success, giving up"
+					if test "x$gshadow" = "xno"; then
+						rm -f $SYSROOT${sysconfdir}/gshadow
+						rm -f $SYSROOT${sysconfdir}/gshadow-
+					fi
+					exit 1
+				fi
+			done
+		else
+			echo "Note: group $groupname already contains $username, not re-adding it"
+		fi
+
+		if test "x$opts" = "x$remaining"; then
+			break
+		fi
+		opts=`echo "$remaining" | cut -d ';' -f 1`
+		remaining=`echo "$remaining" | cut -d ';' -f 2-`
+	done
+	if test "x$gshadow" = "xno"; then
+		rm -f $SYSROOT${sysconfdir}/gshadow
+		rm -f $SYSROOT${sysconfdir}/gshadow-
+	fi
+fi
 }
 
 useradd_sysroot () {
@@ -160,8 +218,8 @@ def update_useradd_after_parse(d):
         raise bb.build.FuncFailed("%s inherits useradd but doesn't set USERADD_PACKAGES" % d.getVar('FILE'))
 
     for pkg in useradd_packages.split():
-        if not d.getVar('USERADD_PARAM_%s' % pkg, True) and not d.getVar('GROUPADD_PARAM_%s' % pkg, True):
-            raise bb.build.FuncFailed("%s inherits useradd but doesn't set USERADD_PARAM or GROUPADD_PARAM for package %s" % (d.getVar('FILE'), pkg))
+        if not d.getVar('USERADD_PARAM_%s' % pkg, True) and not d.getVar('GROUPADD_PARAM_%s' % pkg, True) and not d.getVar('GROUPMEMS_PARAM_%s' % pkg, True):
+            raise bb.build.FuncFailed("%s inherits useradd but doesn't set USERADD_PARAM, GROUPADD_PARAM or GROUPMEMS_PARAM for package %s" % (d.getVar('FILE'), pkg))
 
 python __anonymous() {
     update_useradd_after_parse(d)
@@ -172,7 +230,7 @@ python __anonymous() {
 def get_all_cmd_params(d, cmd_type):
     import string
     
-    param_type = cmd_type.upper() + "ADD_PARAM_%s"
+    param_type = cmd_type.upper() + "_PARAM_%s"
     params = []
 
     useradd_packages = d.getVar('USERADD_PACKAGES', True) or ""
-- 
1.7.9.5



^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-06-26  2:55 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-06-26  2:54 [PATCH 1/2] shadow-native: Add --root option in groupmems mikhail_durnev
2013-06-26  2:54 ` [PATCH 2/2] useradd.bbclass: Add members to a group mikhail_durnev

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox