From 8f0cb9482f4d4051c6542099acf60eafb82ee5f9 Mon Sep 17 00:00:00 2001 From: An-Cheng Huang Date: Thu, 29 Nov 2007 18:21:57 -0800 Subject: * add completion for "pipe". * don't use eval for "show". --- etc/bash_completion.d/20vyatta-cfg | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) (limited to 'etc') diff --git a/etc/bash_completion.d/20vyatta-cfg b/etc/bash_completion.d/20vyatta-cfg index fe64f40..ee640f9 100644 --- a/etc/bash_completion.d/20vyatta-cfg +++ b/etc/bash_completion.d/20vyatta-cfg @@ -54,8 +54,8 @@ show () args[${#args[@]}]="$arg" fi done - eval "${vyatta_sbindir}/vyatta-output-config.pl ${show_all}\ - \${VYATTA_EDIT_LEVEL//\// } ${args[@]}" + ${vyatta_sbindir}/vyatta-output-config.pl ${show_all} \ + ${VYATTA_EDIT_LEVEL//\// } ${args[@]} } save () @@ -705,6 +705,20 @@ vyatta_config_complete () end_space=1 (( num_comp -= 1 )) fi + + # handle pipe + if [ "${COMP_WORDS[$num_comp]}" == "|" ]; then + declare -a hitems=( "more" \ + ) + declare -a hstrs=( \ + "Paginate the output" \ + ) + generate_help_text hitems hstrs + vyatta_completions=( "${hitems[@]}" ) + vyatta_do_complete + return + fi + (( last_idx = num_comp - 1 )) comp_words=( ${COMP_WORDS[@]:1:$num_comp} ) -- cgit v1.2.3 From 70b6ff3777bb913909bbb214adc24cbd27b61847 Mon Sep 17 00:00:00 2001 From: An-Cheng Huang Date: Fri, 30 Nov 2007 17:24:58 -0800 Subject: use the default pager set in op mode for config mode "show" output. --- etc/bash_completion.d/20vyatta-cfg | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'etc') diff --git a/etc/bash_completion.d/20vyatta-cfg b/etc/bash_completion.d/20vyatta-cfg index ee640f9..dc05cf1 100644 --- a/etc/bash_completion.d/20vyatta-cfg +++ b/etc/bash_completion.d/20vyatta-cfg @@ -55,7 +55,8 @@ show () fi done ${vyatta_sbindir}/vyatta-output-config.pl ${show_all} \ - ${VYATTA_EDIT_LEVEL//\// } ${args[@]} + ${VYATTA_EDIT_LEVEL//\// } ${args[@]} \ + | eval "${VYATTA_PAGER:-cat}" } save () -- cgit v1.2.3 From 04a54264cfc1041eb9ae238ccafab7f0e4be4a75 Mon Sep 17 00:00:00 2001 From: An-Cheng Huang Date: Fri, 7 Dec 2007 18:19:48 -0800 Subject: add policy mechanism for user management: per-level policies control default restricted mode and allowed op/cfg/pipe commands. --- Makefile.am | 6 ++++++ etc/default/vyatta-cfg | 40 +++++++++++++++++++++++++++++++++++ etc/shell/level/admin/restricted-mode | 1 + etc/shell/level/users/allowed-cfg | 0 etc/shell/level/users/allowed-op | 3 +++ etc/shell/level/users/allowed-pipe | 10 +++++++++ etc/shell/level/users/restricted-mode | 1 + 7 files changed, 61 insertions(+) create mode 100644 etc/default/vyatta-cfg create mode 100644 etc/shell/level/admin/restricted-mode create mode 100644 etc/shell/level/users/allowed-cfg create mode 100644 etc/shell/level/users/allowed-op create mode 100644 etc/shell/level/users/allowed-pipe create mode 100644 etc/shell/level/users/restricted-mode (limited to 'etc') diff --git a/Makefile.am b/Makefile.am index c757ac1..733526f 100644 --- a/Makefile.am +++ b/Makefile.am @@ -2,6 +2,8 @@ cfgdir = $(datadir)/vyatta-cfg/templates share_perl5dir = /opt/vyatta/share/perl5 completiondir = /etc/bash_completion.d initddir = /etc/init.d +defaultdir = /etc/default +etc_shell_leveldir = $(sysconfdir)/shell/level AM_CFLAGS = -I src -Wall AM_YFLAGS = -d --name-prefix=yy_`basename $* .y`_ @@ -43,9 +45,13 @@ share_perl5_DATA += scripts/VyattaConfigLoad.pm share_perl5_DATA += scripts/VyattaMisc.pm share_perl5_DATA += scripts/VyattaTypeChecker.pm +default_DATA = etc/default/vyatta-cfg + cpiop = find . ! -regex '\(.*~\|.*\.bak\|.*\.swp\|.*\#.*\#\)' -print0 | \ cpio -0pd install-exec-hook: mkdir -p $(DESTDIR)$(cfgdir) cd templates; $(cpiop) $(DESTDIR)$(cfgdir) + mkdir -p $(DESTDIR)$(etc_shell_leveldir) + cd etc/shell/level; $(cpiop) $(DESTDIR)$(etc_shell_leveldir) diff --git a/etc/default/vyatta-cfg b/etc/default/vyatta-cfg new file mode 100644 index 0000000..d369e0f --- /dev/null +++ b/etc/default/vyatta-cfg @@ -0,0 +1,40 @@ +# Vyatta shell environment variables for config mode +# should be sourced from /etc/default/vyatta + +export VYATTA_ACTIVE_CONFIGURATION_DIR=${vyatta_configdir}/active +export VYATTA_CHANGES_ONLY_DIR=${vyatta_configdir}/tmp/changes_only_$$ +export VYATTA_TEMP_CONFIG_DIR=${vyatta_configdir}/tmp/new_config_$$ +export VYATTA_CONFIG_TMP=${vyatta_configdir}/tmp/tmp_$$ +export VYATTA_CONFIG_TEMPLATE=$vyatta_cfg_templates +export VYATTA_EDIT_LEVEL=/ +export VYATTA_TEMPLATE_LEVEL=/ +export VYATTA_TAG_NAME=node.tag +export VYATTA_MOD_NAME=.modified + +# don't set level if already set +if [ -n "$VYATTA_USER_LEVEL_DIR" ]; then + return +fi +{ +is_admin=0 +is_users=0 +VYATTA_LEVEL_GROUP_ADMIN=vyattacfg +VYATTA_LEVEL_GROUP_USERS=quaggavty +local -a groups=( $(id -Gn) ) +for g in "${groups[@]}"; do + if [ "$g" == "$VYATTA_LEVEL_GROUP_ADMIN" ]; then + is_admin=1 + fi + if [ "$g" == "$VYATTA_LEVEL_GROUP_USERS" ]; then + is_users=1 + fi +done +# check level from high to low +if [ $is_admin == 1 ]; then + declare -x -r VYATTA_USER_LEVEL_DIR=${vyatta_sysconfdir}/shell/level/admin +else + # no need to check is_users since there are only 2 levels for now + declare -x -r VYATTA_USER_LEVEL_DIR=${vyatta_sysconfdir}/shell/level/users +fi +} 2>/dev/null || : + diff --git a/etc/shell/level/admin/restricted-mode b/etc/shell/level/admin/restricted-mode new file mode 100644 index 0000000..53752db --- /dev/null +++ b/etc/shell/level/admin/restricted-mode @@ -0,0 +1 @@ +output diff --git a/etc/shell/level/users/allowed-cfg b/etc/shell/level/users/allowed-cfg new file mode 100644 index 0000000..e69de29 diff --git a/etc/shell/level/users/allowed-op b/etc/shell/level/users/allowed-op new file mode 100644 index 0000000..a2ad52d --- /dev/null +++ b/etc/shell/level/users/allowed-op @@ -0,0 +1,3 @@ +show +terminal +exit diff --git a/etc/shell/level/users/allowed-pipe b/etc/shell/level/users/allowed-pipe new file mode 100644 index 0000000..3204ef3 --- /dev/null +++ b/etc/shell/level/users/allowed-pipe @@ -0,0 +1,10 @@ +more +1 +no-more +1 +count +1 +match +2 +no-match +2 diff --git a/etc/shell/level/users/restricted-mode b/etc/shell/level/users/restricted-mode new file mode 100644 index 0000000..2877147 --- /dev/null +++ b/etc/shell/level/users/restricted-mode @@ -0,0 +1 @@ +full -- cgit v1.2.3