Add option to the installer for uid/gid starting numbers.

This also adds a new option to the template system. If you include
eval(string) in a file that goes through the templater then the
string in the eval will be evaluated by the Python interpreter. This is
used so one can do $UIDSTART+1. If any errors occur during the evaluation
the original string is is returned, eval() and all so it is up to the
developer to make sure the evaluation passes.

The default value for uid and gid is now a random value between
1,000,000 and (2^31 - 1,000,000)
This commit is contained in:
Rob Crittenden
2009-08-27 14:15:26 -04:00
parent cab5525076
commit 559c76f761
6 changed files with 37 additions and 11 deletions
+5 -5
View File
@@ -69,8 +69,8 @@ uid: admin
krbPrincipalName: admin@$REALM
cn: Administrator
sn: Administrator
uidNumber: 999
gidNumber: 1001
uidNumber: $UIDSTART
gidNumber: $GIDSTART
homeDirectory: /home/admin
loginShell: /bin/bash
gecos: Administrator
@@ -107,7 +107,7 @@ objectClass: groupofnames
objectClass: posixgroup
cn: admins
description: Account administrators group
gidNumber: 1001
gidNumber: $GIDSTART
member: uid=admin,cn=users,cn=accounts,$SUFFIX
nsAccountLock: False
@@ -118,7 +118,7 @@ objectClass: groupofnames
objectClass: nestedgroup
objectClass: ipausergroup
objectClass: posixgroup
gidNumber: 1002
gidNumber: eval($GIDSTART+1)
description: Default group for all users
cn: ipausers
@@ -127,7 +127,7 @@ changetype: add
objectClass: top
objectClass: groupofnames
objectClass: posixgroup
gidNumber: 1003
gidNumber: eval($GIDSTART+2)
description: Limited admins who can edit other users
cn: editors
+2 -2
View File
@@ -6,7 +6,7 @@ objectclass: top
objectclass: extensibleObject
cn: Posix Accounts
dnaType: uidNumber
dnaNextValue: 1100
dnaNextValue: eval($UIDSTART+1)
dnaInterval: 1
dnaMaxValue: 1000000000
dnaMagicRegen: 999
@@ -21,7 +21,7 @@ objectclass: top
objectclass: extensibleObject
cn: Posix Groups
dnaType: gidNumber
dnaNextValue: 1100
dnaNextValue: eval($GIDSTART+3)
dnaInterval: 1
dnaMaxValue: 1000000000
dnaMagicRegen: 999
+10 -1
View File
@@ -36,6 +36,7 @@ import shutil
import glob
import traceback
from optparse import OptionParser
import random
from ipaserver.install import dsinstance
from ipaserver.install import krbinstance
@@ -54,7 +55,11 @@ from ipalib import util
pw_name = None
# Used to determine the the highest possible uid/gid
MAXINT_32BIT = 2147483648
def parse_options():
namespace = random.randint(1000000, (MAXINT_32BIT - 1000000))
parser = OptionParser(version=version.VERSION)
parser.add_option("-u", "--user", dest="ds_user",
help="ds user")
@@ -97,6 +102,10 @@ def parse_options():
default=False,
help="Do not use DNS for hostname lookup during installation")
parser.add_option("--uidstart", dest="uidstart", default=namespace, type=int,
help="The starting uid value (default random)")
parser.add_option("--gidstart", dest="gidstart", default=namespace, type=int,
help="The starting gid value (default random)")
options, args = parser.parse_args()
if options.uninstall:
@@ -537,7 +546,7 @@ def main():
finally:
os.remove(pw_name)
else:
ds.create_instance(ds_user, realm_name, host_name, domain_name, dm_password, self_signed_ca=not options.ca)
ds.create_instance(ds_user, realm_name, host_name, domain_name, dm_password, self_signed_ca=not options.ca, uidstart=options.uidstart, gidstart=options.gidstart)
# Create a kerberos instance
krb = krbinstance.KrbInstance(fstore)
+6
View File
@@ -75,6 +75,12 @@ The password of the Directory Server PKCS#12 file
\fB\-\-http_pin\fR=\fIHTTP_PIN\fR
The password of the Apache Server PKCS#12 file
.PP
\fB\-\-uidstart\fR=\fIUIDSTART\fR
The starting user id number (default random)
.PP
\fB\-\-gidstart\fR=\fIGIDSTART\fR
The starting group id number (default random)
.PP
.SH "EXIT STATUS"
0 if the installation was successful