diff --git a/configuration/system-configuration.sh b/configuration/system-configuration.sh index fa2e7def257..0020053edf7 100644 --- a/configuration/system-configuration.sh +++ b/configuration/system-configuration.sh @@ -26,6 +26,7 @@ if test -n "$grubDevice"; then $grub/sbin/grub-install "$grubDevice" --no-floppy --recheck fi fi +sync EOF chmod +x $out/bin/switch-to-configuration diff --git a/helpers/accounts.sh b/helpers/accounts.sh new file mode 100644 index 00000000000..1e189c56e7f --- /dev/null +++ b/helpers/accounts.sh @@ -0,0 +1,20 @@ +userExists() { + local name="$1" + if id -u "$name" > /dev/null 2>&1; then + return 0 # true + else + return 1 # false + fi +} + + +createUser() { + local name="$1" + local password="$2" + local uid="$3" + local gid="$4" + local gecos="$5" + local homedir="$6" + local shell="$7" + echo "$name:$password:$uid:$gid:$gecos:$homedir:$shell" >> /etc/passwd +} diff --git a/upstart-jobs/sshd.nix b/upstart-jobs/sshd.nix index 466c7616f55..3f210467277 100644 --- a/upstart-jobs/sshd.nix +++ b/upstart-jobs/sshd.nix @@ -10,6 +10,8 @@ start on network-interfaces/started stop on network-interfaces/stop start script + source ${../helpers/accounts.sh} + mkdir -m 0555 -p /var/empty mkdir -m 0755 -p /etc/ssh @@ -20,8 +22,8 @@ start script ${openssh}/bin/ssh-keygen -t dsa -b 1024 -f /etc/ssh/ssh_host_dsa_key -N '' fi - if ! grep -q '^sshd:' /etc/passwd; then - echo 'sshd:x:74:74:SSH privilege separation user:/var/empty:/noshell' >> /etc/passwd + if ! userExists sshd; then + createUser sshd x 74 74 'SSH privilege separation user' /var/empty /noshell fi end script