JFIF$        dd7 

Viewing File: /usr/bin/clsupergid_process

#!/opt/cloudlinux/venv/bin/python3 -bb
# -*- coding: utf-8 -*-

#
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2021 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENCE.TXT

# pylint: disable=no-absolute-import

import sys
import os
import grp
import pwd
import subprocess

from clcommon.sysctl import SysCtlConf, SYSCTL_CL_CONF_FILE
from cl_proc_hidepid import remount_proc, get_gid_from_mounts

from clcommon.lib.cledition import lve_supported_or_exit


def _is_group_present_by_id(gid: int):
    """
    Checks if group present in system
    :param gid: Gid to check
    :return: True/False - present/absent
    """
    try:
        grp.getgrgid(gid)
    except KeyError:
        return False
    return True


def polkitd_process(gids_to_add_list: list):
    """
    Add polkitd user to groups
    :param gids_to_add_list: List of gids to add user
    """
    polkitd_username = "polkitd"
    try:
        pwd.getpwnam(polkitd_username)
    except KeyError:
        return
    # Determine group names list to add user
    group_names_to_add = []
    for gid in gids_to_add_list:
        try:
            _grp = grp.getgrgid(gid)
            if polkitd_username not in _grp.gr_mem:
                group_names_to_add.append(_grp.gr_name)
        except KeyError:
            pass
    if group_names_to_add:
        print("INFO: adding user '%s' to group(s)" % polkitd_username, group_names_to_add)
        # usermod -a -G group1,group2 username
        cmd = '/usr/sbin/usermod -a -G ' + ','.join(group_names_to_add) + ' ' + polkitd_username
        subprocess.run(cmd, shell=True, executable='/bin/bash')


@lve_supported_or_exit
def main():
    print("INFO: Checking fs.proc_super_gid group...")
    sysctl = SysCtlConf(config_file=SYSCTL_CL_CONF_FILE)
    sgid_key = 'fs.proc_super_gid'
    proc_super_gid = 0
    try:
        # sysctl.get may return empty string in some cases like cldeploy
        # when CL kernel is not loaded yet and proc has no such param
        proc_super_gid = int(sysctl.get(sgid_key))
    except ValueError:
        pass

    if proc_super_gid == 0 or (proc_super_gid != 0 and not _is_group_present_by_id(proc_super_gid)):
        print("INFO: clsupergid group absent, creating ...")
        sgid_name = 'clsupergid'
        subprocess.run('/usr/sbin/groupadd -f ' + sgid_name, shell=True, executable='/bin/bash')
        proc_super_gid = grp.getgrnam(sgid_name).gr_gid
        sysctl.set(sgid_key, proc_super_gid)
        print("INFO: clsupergid group created, gid is", proc_super_gid)
    else:
        print("INFO: fs.proc_super_gid group already present (gid is {}).".format(proc_super_gid))
    remount_proc()

    gids_to_add_list = [proc_super_gid]
    gid_from_mounts = get_gid_from_mounts()
    if gid_from_mounts != proc_super_gid and _is_group_present_by_id(gid_from_mounts):
        gids_to_add_list.append(gid_from_mounts)
    polkitd_process(gids_to_add_list)
    sys.exit(0)


if __name__ == "__main__":
    main()
Back to Directory  nL+D550H?Mx ,D"v]qv;6*Zqn)ZP0!1 A "#a$2Qr D8 a Ri[f\mIykIw0cuFcRı?lO7к_f˓[C$殷WF<_W ԣsKcëIzyQy/_LKℂ;C",pFA:/]=H  ~,ls/9ć:[=/#f;)x{ٛEQ )~ =𘙲r*2~ a _V=' kumFD}KYYC)({ *g&f`툪ry`=^cJ.I](*`wq1dđ#̩͑0;H]u搂@:~וKL Nsh}OIR*8:2 !lDJVo(3=M(zȰ+i*NAr6KnSl)!JJӁ* %݉?|D}d5:eP0R;{$X'xF@.ÊB {,WJuQɲRI;9QE琯62fT.DUJ;*cP A\ILNj!J۱+O\͔]ޒS߼Jȧc%ANolՎprULZԛerE2=XDXgVQeӓk yP7U*omQIs,K`)6\G3t?pgjrmۛجwluGtfh9uyP0D;Uڽ"OXlif$)&|ML0Zrm1[HXPlPR0'G=i2N+0e2]]9VTPO׮7h(F*癈'=QVZDF,d߬~TX G[`le69CR(!S2!P <0x<!1AQ "Raq02Br#SCTb ?Ζ"]mH5WR7k.ۛ!}Q~+yԏz|@T20S~Kek *zFf^2X*(@8r?CIuI|֓>^ExLgNUY+{.RѪ τV׸YTD I62'8Y27'\TP.6d&˦@Vqi|8-OΕ]ʔ U=TL8=;6c| !qfF3aů&~$l}'NWUs$Uk^SV:U# 6w++s&r+nڐ{@29 gL u"TÙM=6(^"7r}=6YݾlCuhquympǦ GjhsǜNlɻ}o7#S6aw4!OSrD57%|?x>L |/nD6?/8w#[)L7+6〼T ATg!%5MmZ/c-{1_Je"|^$'O&ޱմTrb$w)R$& N1EtdU3Uȉ1pM"N*(DNyd96.(jQ)X 5cQɎMyW?Q*!R>6=7)Xj5`J]e8%t!+'!1Q5 !1 AQaqё#2"0BRb?Gt^## .llQT $v,,m㵜5ubV =sY+@d{N! dnO<.-B;_wJt6;QJd.Qc%p{ 1,sNDdFHI0ГoXшe黅XۢF:)[FGXƹ/w_cMeD,ʡcc.WDtA$j@:) -# u c1<@ۗ9F)KJ-hpP]_x[qBlbpʖw q"LFGdƶ*s+ډ_Zc"?%t[IP 6J]#=ɺVvvCGsGh1 >)6|ey?Lӣm,4GWUi`]uJVoVDG< SB6ϏQ@ TiUlyOU0kfV~~}SZ@*WUUi##; s/[=!7}"WN]'(L! ~y5g9T̅JkbM' +s:S +B)v@Mj e Cf jE 0Y\QnzG1д~Wo{T9?`Rmyhsy3!HAD]mc1~2LSu7xT;j$`}4->L#vzŏILS ֭T{rjGKC;bpU=-`BsK.SFw4Mq]ZdHS0)tLg