summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html')
-rw-r--r--zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html183
1 files changed, 183 insertions, 0 deletions
diff --git a/zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html b/zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html
new file mode 100644
index 000000000..689946658
--- /dev/null
+++ b/zarb-ml/mageia-sysadm/attachments/20101123/0c4827d6/attachment-0001.html
@@ -0,0 +1,183 @@
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
+"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
+<html xmlns="http://www.w3.org/1999/xhtml">
+<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
+<title>[408] - split the module in 2 part, and add class to allow to more easyly</title>
+</head>
+<body>
+
+<style type="text/css"><!--
+#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
+#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
+#msg dt:after { content:':';}
+#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; }
+#msg dl a { font-weight: bold}
+#msg dl a:link { color:#fc3; }
+#msg dl a:active { color:#ff0; }
+#msg dl a:visited { color:#cc6; }
+h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
+#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
+#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
+#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
+#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
+#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
+#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
+#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
+#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
+#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
+#logmsg pre { background: #eee; padding: 1em; }
+#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
+#logmsg dl { margin: 0; }
+#logmsg dt { font-weight: bold; }
+#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
+#logmsg dd:before { content:'\00bb';}
+#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
+#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
+#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
+#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
+#logmsg table th.Corner { text-align: left; }
+#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
+#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
+#patch { width: 100%; }
+--></style>
+<div id="msg">
+<dl class="meta">
+<dt>Revision</dt> <dd>408</dd>
+<dt>Author</dt> <dd>misc</dd>
+<dt>Date</dt> <dd>2010-11-23 02:11:10 +0100 (Tue, 23 Nov 2010)</dd>
+</dl>
+
+<h3>Log Message</h3>
+<pre>- split the module in 2 part, and add class to allow to more easyly
+combine the autorized shell</pre>
+
+<h3>Modified Paths</h3>
+<ul>
+<li><a href="#puppetmodulesrestrictshellmanifestsinitpp">puppet/modules/restrictshell/manifests/init.pp</a></li>
+<li><a href="#puppetmodulesrestrictshelltemplatesmembershconfpl">puppet/modules/restrictshell/templates/membersh-conf.pl</a></li>
+</ul>
+
+</div>
+<div id="patch"><pre>
+<a id="puppetmodulesrestrictshellmanifestsinitpp">Modified: puppet/modules/restrictshell/manifests/init.pp</a>
+===================================================================
+--- puppet/modules/restrictshell/manifests/init.pp 2010-11-23 01:11:08 UTC (rev 407)
++++ puppet/modules/restrictshell/manifests/init.pp 2010-11-23 01:11:10 UTC (rev 408)
+@@ -1,5 +1,12 @@
+ class restrictshell {
+ class shell {
++ file {&quot;/etc/membersh-conf.d&quot;:
++ ensure =&gt; directory,
++ owner =&gt; root,
++ group =&gt; root,
++ mode =&gt; 755,
++ }
++
+ file { '/usr/local/bin/sv_membersh.pl':
+ ensure =&gt; present,
+ owner =&gt; root,
+@@ -7,16 +14,7 @@
+ mode =&gt; 755,
+ content =&gt; template(&quot;restrictshell/sv_membersh.pl&quot;),
+ }
+- }
+
+- class base {
+- include shell
+- $allow_svn = &quot;0&quot;
+- $allow_git = &quot;0&quot;
+- $allow_rsync = &quot;0&quot;
+- $allow_pkgsubmit = &quot;0&quot;
+-
+- $ldap_pwfile = &quot;/etc/ldap.secret&quot;
+ file { '/etc/membersh-conf.pl':
+ ensure =&gt; present,
+ owner =&gt; root,
+@@ -24,6 +22,9 @@
+ mode =&gt; 755,
+ content =&gt; template(&quot;restrictshell/membersh-conf.pl&quot;),
+ }
++ }
++
++ class ssh_keys_from_ldap {
+
+ package { 'python-ldap':
+ ensure =&gt; installed,
+@@ -37,6 +38,7 @@
+ mode =&gt; 755,
+ }
+
++ $ldap_pwfile = &quot;/etc/ldap.secret&quot;
+ file { '/usr/local/bin/ldap-sshkey2file.py':
+ ensure =&gt; present,
+ owner =&gt; root,
+@@ -47,9 +49,32 @@
+ }
+ }
+
+- class allow_svn_git_pkgsubmit inherits base {
+- $allow_svn = &quot;1&quot;
+- $allow_git = &quot;1&quot;
+- $allow_pkgsubmit = &quot;1&quot;
++ define allow {
++ include shell
++ file { &quot;/etc/membersh-conf.d/allow_$name.pl&quot;:
++ ensure =&gt; &quot;present&quot;,
++ owner =&gt; root,
++ group =&gt; root,
++ mode =&gt; 755,
++ content =&gt; &quot;\$use_$name = 1;\n&quot;,
++ }
+ }
++
++ # yes, we could directly use the allow, but this is
++ # a nicer syntax
++ class allow_git {
++ allow{ &quot;git&quot;: }
++ }
++
++ class allow_rsync {
++ allow{ &quot;rsync&quot;: }
++ }
++
++ class allow_pkgsubmit {
++ allow{ &quot;pkgsubmit&quot;: }
++ }
++
++ class allow_svn {
++ allow{ &quot;svn&quot;: }
++ }
+ }
+
+<a id="puppetmodulesrestrictshelltemplatesmembershconfpl">Modified: puppet/modules/restrictshell/templates/membersh-conf.pl</a>
+===================================================================
+--- puppet/modules/restrictshell/templates/membersh-conf.pl 2010-11-23 01:11:08 UTC (rev 407)
++++ puppet/modules/restrictshell/templates/membersh-conf.pl 2010-11-23 01:11:10 UTC (rev 408)
+@@ -1,16 +1,18 @@
+-$use_svn = &quot;&lt;%= allow_svn %&gt;&quot;;
++
++
+ $bin_svn = &quot;/usr/bin/svnserve&quot;;
+ $regexp_svn = &quot;^svnserve -t\$&quot;;
+ #@prepend_args_svn = ( '-r', '/svn' );
+ @prepend_args_svn = ();
+
+-$use_git = &quot;&lt;%= allow_git %&gt;&quot;;
+ $bin_git = &quot;/usr/bin/git-shell&quot;;
+
+-$use_rsync = &quot;&lt;%= allow_rsync %&gt;&quot;;
+ $bin_rsync = &quot;/usr/bin/rsync&quot;;
+ $regexp_rsync = &quot;^rsync --server&quot;;
+ $regexp_dir_rsync = &quot;^/.*&quot;;
+
+-$use_pkgsubmit = &quot;&lt;%= allow_pkgsubmit %&gt;&quot;;
+
++foreach my $f (glob(&quot;/etc/membersh-conf.d/allow_*pl&quot;)) {
++ do($f)
++}
++1;
+
+</pre></div>
+
+</body>
+</html> \ No newline at end of file