robbiew | 3f9a880 | 2001-10-12 20:39:17 +0000 | [diff] [blame] | 1 | #!/bin/sh |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 2 | # |
robbiew | 599ddd7 | 2001-11-28 21:31:41 +0000 | [diff] [blame] | 3 | # Copyright (c) International Business Machines Corp., 2001 |
| 4 | # |
| 5 | # This program is free software; you can redistribute it and/or modify |
| 6 | # it under the terms of the GNU General Public License as published by |
| 7 | # the Free Software Foundation; either version 2 of the License, or |
| 8 | # (at your option) any later version. |
| 9 | # |
| 10 | # This program is distributed in the hope that it will be useful, |
| 11 | # but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 12 | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See |
| 13 | # the GNU General Public License for more details. |
| 14 | # |
| 15 | # You should have received a copy of the GNU General Public License |
| 16 | # along with this program; if not, write to the Free Software |
Wanlong Gao | 4548c6c | 2012-10-19 18:03:36 +0800 | [diff] [blame] | 17 | # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 18 | # |
robbiew | 599ddd7 | 2001-11-28 21:31:41 +0000 | [diff] [blame] | 19 | # FILE : IDcheck.sh |
| 20 | # DESCRIPTION : checks for req'd users/groups and will create them if requested. |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 21 | # HISTORY : see the cvs log |
| 22 | # |
robbiew | 599ddd7 | 2001-11-28 21:31:41 +0000 | [diff] [blame] | 23 | |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 24 | # Prompt user if ids/groups should be created |
robbiew | c0f37e6 | 2001-11-27 19:14:19 +0000 | [diff] [blame] | 25 | echo "Checking for required user/group ids" |
| 26 | echo "" |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 27 | |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 28 | # Check ids and create if needed. |
| 29 | NO_NOBODY_ID=1 |
| 30 | NO_BIN_ID=1 |
| 31 | NO_DAEMON_ID=1 |
| 32 | NO_NOBODY_GRP=1 |
| 33 | NO_BIN_GRP=1 |
| 34 | NO_DAEMON_GRP=1 |
| 35 | NO_USERS_GRP=1 |
| 36 | NO_SYS_GRP=1 |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 37 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 38 | group="$DESTDIR/etc/group" |
| 39 | passwd="$DESTDIR/etc/passwd" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 40 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 41 | # find entry. |
| 42 | fe() { |
yaberauneya | 0c66cf8 | 2009-11-12 11:56:05 +0000 | [diff] [blame] | 43 | ID=$1 |
| 44 | FILE=$2 |
yaberauneya | 3ab801e | 2009-07-10 23:01:27 +0000 | [diff] [blame] | 45 | [ -e "$FILE" ] || return $? |
yaberauneya | 0c66cf8 | 2009-11-12 11:56:05 +0000 | [diff] [blame] | 46 | grep -q "^$ID:" "$FILE" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 47 | } |
| 48 | |
| 49 | prompt_for_create() { |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 50 | if [ -z "$CREATE_ENTRIES" ] ; then |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 51 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 52 | if [ $NO_NOBODY_ID -ne 0 -o $NO_BIN_ID -ne 0 -o $NO_DAEMON_ID -ne 0 -o $NO_NOBODY_GRP -ne 0 -o $NO_BIN_GRP -ne 0 -o $NO_DAEMON_GRP -ne 0 -o $NO_USERS_GRP -ne 0 -o $NO_SYS_GRP -ne 0 ] ; then |
subrata_modak | 4ede9d0 | 2008-09-29 18:12:16 +0000 | [diff] [blame] | 53 | echo -n "If any required user ids and/or groups are missing, would you like these created? [y/N]" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 54 | read ans |
| 55 | case "$ans" in |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 56 | [Yy]*) CREATE_ENTRIES=1 ;; |
yaberauneya | 0c66cf8 | 2009-11-12 11:56:05 +0000 | [diff] [blame] | 57 | *) CREATE_ENTRIES=0 ;; |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 58 | esac |
| 59 | else |
| 60 | CREATE_ENTRIES=0 |
| 61 | fi |
| 62 | |
| 63 | fi |
| 64 | } |
| 65 | |
subrata_modak | 694c3f0 | 2008-08-29 18:03:48 +0000 | [diff] [blame] | 66 | if [ -z ${EUID} ] ; then |
| 67 | EUID=$(id -u) |
| 68 | fi |
| 69 | |
yaberauneya | 3ab801e | 2009-07-10 23:01:27 +0000 | [diff] [blame] | 70 | for i in "$passwd" "$group"; do |
| 71 | if [ -e "$i" -a ! -r "$i" ] ; then |
| 72 | echo "$i not readable by uid $EUID" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 73 | exit 1 |
yaberauneya | 3ab801e | 2009-07-10 23:01:27 +0000 | [diff] [blame] | 74 | fi |
| 75 | done |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 76 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 77 | fe bin "$passwd"; NO_BIN_ID=$? |
| 78 | fe daemon "$passwd"; NO_DAEMON_ID=$? |
| 79 | fe nobody "$passwd"; NO_NOBODY_ID=$? |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 80 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 81 | fe bin "$group"; NO_BIN_GRP=$? |
| 82 | fe daemon "$group"; NO_DAEMON_GRP=$? |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 83 | fe nobody "$group" || fe nogroup "$group"; NO_NOBODY_GRP=$? |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 84 | fe sys "$group"; NO_SYS_GRP=$? |
| 85 | fe users "$group"; NO_USERS_GRP=$? |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 86 | |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 87 | prompt_for_create |
| 88 | |
| 89 | debug_vals() { |
| 90 | |
| 91 | echo "Missing the following group / user entries:" |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 92 | echo "Group file: $group" |
| 93 | echo "Password file: $passwd" |
| 94 | echo "nobody: $NO_NOBODY_ID" |
| 95 | echo "bin: $NO_BIN_ID" |
| 96 | echo "daemon: $NO_DAEMON_ID" |
| 97 | echo "nobody[/nogroup] grp: $NO_NOBODY_GRP" |
| 98 | echo "bin grp: $NO_BIN_GRP" |
| 99 | echo "daemon grp: $NO_DAEMON_GRP" |
| 100 | echo "sys grp: $NO_SYS_GRP" |
| 101 | echo "users grp: $NO_USERS_GRP" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 102 | echo "" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 103 | |
| 104 | } |
| 105 | |
| 106 | #debug_vals |
| 107 | |
| 108 | if [ $CREATE_ENTRIES -ne 0 ] ; then |
yaberauneya | 3ab801e | 2009-07-10 23:01:27 +0000 | [diff] [blame] | 109 | if ! touch "$group" "$passwd" 2>/dev/null; then |
| 110 | echo "Failed to touch $group or $passwd" |
| 111 | exit 1 |
| 112 | fi |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 113 | fi |
| 114 | |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 115 | make_user_group() { |
| 116 | local name=$1 id=$2 no_id=$3 no_grp=$4 |
| 117 | |
| 118 | if [ $no_id -eq 0 -a $no_grp -eq 0 ] ; then |
| 119 | echo "'$name' user id and group found." |
| 120 | elif [ $CREATE_ENTRIES -ne 0 ] ; then |
| 121 | echo "Creating entries for $name" |
| 122 | |
| 123 | # Avoid chicken and egg issue with id(1) call |
| 124 | # made above and below. |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 125 | if ! fe "$name" "$passwd" && [ $no_id -ne 0 ] ; then |
| 126 | echo "${name}:x:${id}:${id}:${name}::" >> "$passwd" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 127 | fi |
| 128 | if [ $no_grp -ne 0 ] ; then |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 129 | echo "${name}:x:$(id -u ${name}):" >> "$group" |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 130 | fi |
| 131 | fi |
| 132 | } |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 133 | make_user_group nobody 65534 $NO_NOBODY_ID $NO_NOBODY_GRP |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 134 | make_user_group bin 1 $NO_BIN_ID $NO_BIN_GRP |
| 135 | make_user_group daemon 2 $NO_DAEMON_ID $NO_DAEMON_GRP |
| 136 | |
| 137 | if [ $NO_USERS_GRP -eq 0 ] ; then |
| 138 | echo "Users group found." |
| 139 | elif [ $CREATE_ENTRIES -ne 0 ] ; then |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 140 | echo 'users:x:100:' >> "$group" |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 141 | fi |
| 142 | |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 143 | if [ $NO_SYS_GRP -eq 0 ] ; then |
| 144 | echo "Sys group found." |
| 145 | elif [ $CREATE_ENTRIES -ne 0 ] ; then |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 146 | echo 'sys:x:3:' >> "$group" |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 147 | fi |
| 148 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 149 | MISSING_ENTRY=0 |
| 150 | |
| 151 | # For entries that exist in both $group and $passwd. |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 152 | for i in bin daemon; do |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 153 | for file in "$group" "$passwd"; do |
| 154 | if ! fe "$i" "$file"; then |
| 155 | MISSING_ENTRY=1 |
| 156 | break |
| 157 | fi |
| 158 | done |
| 159 | if [ $MISSING_ENTRY -ne 0 ]; then |
| 160 | break |
| 161 | fi |
| 162 | done |
| 163 | |
Garrett Cooper | 9116567 | 2010-03-07 14:32:56 -0800 | [diff] [blame] | 164 | # nobody is a standard group on all distros, apart from debian based ones; |
| 165 | # let's account for the fact that they use the nogroup group instead. |
| 166 | if ! fe "nobody" "$passwd" || ! (fe "nogroup" "$group" || fe "nobody" "$group") |
| 167 | then |
| 168 | MISSING_ENTRY=1 |
| 169 | fi |
| 170 | |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 171 | # For entries that only exist in $group. |
| 172 | for i in users sys; do |
yaberauneya | 0c66cf8 | 2009-11-12 11:56:05 +0000 | [diff] [blame] | 173 | if ! fe "$i" "$group" ; then |
subrata_modak | d9f329e | 2009-07-07 14:30:27 +0000 | [diff] [blame] | 174 | MISSING_ENTRY=1 |
| 175 | fi |
| 176 | done |
| 177 | |
| 178 | if [ $MISSING_ENTRY -eq 0 ] ; then |
| 179 | echo "Required users/groups exist." |
| 180 | exit 0 |
robbiew | 06e3bdf | 2003-04-08 15:23:33 +0000 | [diff] [blame] | 181 | fi |
| 182 | |
vapier | 4fdf37f | 2008-04-28 01:36:44 +0000 | [diff] [blame] | 183 | echo "" |
robbiew | d23f724 | 2001-11-21 17:33:40 +0000 | [diff] [blame] | 184 | echo "*****************************************" |
| 185 | echo "* Required users/groups do NOT exist!!! *" |
| 186 | echo "* *" |
| 187 | echo "* Some kernel/syscall tests will FAIL! *" |
| 188 | echo "*****************************************" |
| 189 | exit 1 |