On Fri, Sep 18, 2015 at 1:09 PM, Ansis Atteka <aatt...@nicira.com> wrote:
> On Mon, Sep 14, 2015 at 3:54 PM, Andy Zhou <az...@nicira.com> wrote:
>> ovs-dev.py "run" command now accepts the "--user" option for runing
>> all ovs daemons as "user". The argument can be speicfied in
>> "user[:group]" format.
>>
>> '-u' is an short hand option that, if ovs-dev.py is lauch as a non-root
> s/an/a
> s/lauch/launched
>> user, the current user and group will be used as if they are supplied
> s/the/then
>> by the --user option.
>>
>> "./ovs-dev.py run -u" can now launch ovsdb-server and ovs-vswitchd as
>> current user and group.
>>
>> Signed-off-by: Andy Zhou <az...@nicira.com>
>> ---
>>  utilities/ovs-dev.py | 30 +++++++++++++++++++++++-------
>>  1 file changed, 23 insertions(+), 7 deletions(-)
>>
>> diff --git a/utilities/ovs-dev.py b/utilities/ovs-dev.py
>> index 9376020..45fa38b 100755
>> --- a/utilities/ovs-dev.py
>> +++ b/utilities/ovs-dev.py
>> @@ -55,9 +55,16 @@ def uname():
>>      return _sh("uname", "-r", capture=True)[0].strip()
>>
>>
>> -def sudo():
>> +def sudo(run_as_me):
>>      if os.geteuid() != 0:
>> -        _sh(" ".join(["sudo"] + sys.argv), check=True)
>> +        opt = []
>> +        if (run_as_me):
>> +            user = subprocess.check_output(["id", "-un"]).strip()
>> +            group = subprocess.check_output(["id", "-gn"]).strip()
>> +            opt=["--user", user + ":" + group]
> spacing around =
>> +            sys.argv.remove("-u")
> Do you need to remove("-u")  because -u flag is intended solely
> consumed by ovs-dev?
No. We are switching to root (via sudo). Not removing -u will cause
ROOT to be used as the new user, rather than the current user.
>> +
>> +        _sh(" ".join(["sudo"] + sys.argv + opt), check=True)
>>          sys.exit(0)
>>
>>  def conf():
>> @@ -191,7 +198,7 @@ commands.append(tag)
>>
>>
>>  def kill():
>> -    sudo()
>> +    sudo(False)
>>      for proc in ["ovs-vswitchd", "ovsdb-server"]:
>>          if os.path.exists("%s/run/openvswitch/%s.pid" % (RUNDIR, proc)):
>>              _sh("ovs-appctl", "-t", proc, "exit", check=False)
>> @@ -201,7 +208,7 @@ commands.append(kill)
>>
>>
>>  def reset():
>> -    sudo()
>> +    sudo(False)
>>      kill()
>>      if os.path.exists(RUNDIR):
>>          shutil.rmtree(RUNDIR)
>> @@ -210,7 +217,7 @@ def reset():
>>  commands.append(reset)
>>
>>  def run():
>> -    sudo()
>> +    sudo(options.as_me)
>>      kill()
>>      for d in ["log", "run"]:
>>          d = "%s/%s" % (RUNDIR, d)
>> @@ -231,6 +238,11 @@ def run():
>>
>>      opts = ["--pidfile", "--log-file"]
>>
>> +    _sh("chown", options.user, "-R", RUNDIR);
>> +
>> +    if (options.user != "root:root"):
>> +        opts = ["--user", options.user] + opts
>> +
>>      _sh(*(["ovsdb-server",
>>             "--remote=punix:%s/run/db.sock" % RUNDIR,
>>             "--remote=db:Open_vSwitch,Open_vSwitch,manager_options",
>> @@ -274,7 +286,7 @@ def modinst():
>>          print "Missing modules directory.  Is this a Linux system?"
>>          sys.exit(1)
>>
>> -    sudo()
>> +    sudo(False)
>>      try:
>>          _sh("rmmod", "openvswitch")
>>      except subprocess.CalledProcessError, e:
>> @@ -315,7 +327,7 @@ Basic Configuration:
>>
>>      # First install the basic requirements needed to build Open vSwitch.
>>      sudo apt-get install git build-essential libtool autoconf pkg-config \\
>> -            libssl-dev gdb linux-headers-`uname -r`
>> +            libssl-dev gdb libcap-ng linux-headers-`uname -r`
>>
>>      # Next clone the Open vSwitch source.
>>      git clone https://github.com/openvswitch/ovs.git %(ovs)s
>> @@ -414,6 +426,10 @@ def main():
>>                       help="run ovs-vswitchd with dpdk subopts (ended by 
>> --)")
>>      group.add_option("--clang", dest="clang", action="store_true",
>>                       help="Use binaries built by clang")
>> +    group.add_option("--user", dest="user", action="store", default="root",
>> +                     help="run all daemons as a non root user")
>> +    group.add_option("-u", dest="as_me", action="store_true",
>> +                     help="set --user to the current user")
> Are -u and --user flags conflicting with each other if both are set at
> the same time? I mean does -u supersedes --user even if it was set?
Good point. I should add check to not allow both to be specified at
the same time.
>
>>
>>      parser.add_option_group(group)
>>
>> --
>> 1.9.1
>>
>> _______________________________________________
>> dev mailing list
>> dev@openvswitch.org
>> http://openvswitch.org/mailman/listinfo/dev
_______________________________________________
dev mailing list
dev@openvswitch.org
http://openvswitch.org/mailman/listinfo/dev

Reply via email to