better trash; no favicon

This commit is contained in:
Ludwig Lehnert
2026-08-19 10:07:25 +00:00
parent 1c4e07c713
commit d618957b68
14 changed files with 263 additions and 54 deletions
+7
View File
@@ -15,6 +15,13 @@ RUN apt-get update \
tini \
&& rm -rf /var/lib/apt/lists/*
# Rootless Podman maps 65,536 IDs. Keep this disposable DC's internal idmap
# inside that namespace; production AD domains must use their normal range.
RUN sed -i \
-e 's/lowerBound: 3000000/lowerBound: 10000/' \
-e 's/upperBound: 4000000/upperBound: 60000/' \
/usr/share/samba/setup/idmap_init.ldif
COPY dev/ad-entrypoint.sh /usr/local/bin/preview-ad-entrypoint
COPY dev/preview-client.sh /usr/local/bin/preview-client
COPY dev/seed-files.sh /usr/local/bin/preview-seed-files
+20 -2
View File
@@ -21,14 +21,32 @@ done
if [[ ! -s /var/lib/samba/private/sam.ldb ]]; then
log "Provisioning disposable ${AD_REALM} domain"
rm -f /etc/samba/smb.conf
netbios_name=${HOSTNAME%%.*}
netbios_name=${netbios_name^^}
mkdir -p /var/lib/samba/state
cat > /etc/samba/smb.conf <<EOF
[global]
netbios name = ${netbios_name}
realm = ${AD_REALM}
workgroup = ${AD_DOMAIN}
server role = active directory domain controller
xattr_tdb:file = /var/lib/samba/state/xattr.tdb
[sysvol]
path = /var/lib/samba/sysvol
read only = no
[netlogon]
path = /var/lib/samba/sysvol/${AD_DNS_DOMAIN}/scripts
read only = no
EOF
samba-tool domain provision \
--server-role=dc \
--use-rfc2307 \
--dns-backend=SAMBA_INTERNAL \
--realm="$AD_REALM" \
--domain="$AD_DOMAIN" \
--adminpass="$AD_ADMIN_PASSWORD"
samba-tool ntacl sysvolcheck
fi
ln -sf /var/lib/samba/private/krb5.conf /etc/krb5.conf
+56 -4
View File
@@ -324,7 +324,7 @@ def main() -> int:
"-U",
f"{WORKGROUP}\\alice%{USER_PASSWORD}",
"-c",
"cd .trash; ls",
"cd .trash",
check_result=False,
)
check(
@@ -332,6 +332,48 @@ def main() -> int:
"ordinary SMB user can browse the admin-managed trash repository",
)
announce("temporary and document-lock files bypass the recycle repository")
transient_delete = engine_run(
"exec",
CLIENT_CONTAINER,
"smbclient",
f"//files.{DNS_DOMAIN}/Data",
"-m",
"SMB3",
"-U",
f"{WORKGROUP}\\alice%{USER_PASSWORD}",
"-c",
(
"cd Finance; cd Reports; "
"put /tmp/live-note.txt 713A292F.tmp; del 713A292F.tmp; "
'put /tmp/live-note.txt "~$RG Eingang 2026.xlsx"; '
'del "~$RG Eingang 2026.xlsx"'
),
check_result=False,
)
check(
transient_delete.returncode == 0,
"temporary/document-lock deletion over SMB failed: "
+ (transient_delete.stderr.strip() or transient_delete.stdout.strip()),
)
transient_absent = engine_run(
"exec",
FILES_CONTAINER,
"sh",
"-ec",
(
"test ! -e '/data/groups/data/Finance/Reports/713A292F.tmp'; "
"test ! -e '/data/groups/data/Finance/Reports/~$RG Eingang 2026.xlsx'; "
"test -z \"$(find /data/groups/data/.trash -type f "
"\\( -iname '*.tmp' -o -name '~$*' \\) -print -quit)\""
),
check_result=False,
)
check(
transient_absent.returncode == 0,
"temporary or document-lock file was retained in the trash repository",
)
announce("real Samba recycle, admin download, and conflict-safe restore")
trash_response = eventually(
"deleted SMB file in the seven-day trash",
@@ -486,9 +528,19 @@ def main() -> int:
)
check(
{
"audit_events_time",
"audit_events_user_time",
"audit_events_action_time",
"audit_events_main_time",
"audit_events_main_action_time",
"audit_events_main_success_time",
"audit_events_main_user_time",
"audit_events_main_account_time",
"audit_events_main_share_time",
"audit_events_main_result_time",
"audit_events_fslogix_time",
"audit_events_fslogix_action_time",
"audit_events_fslogix_success_time",
"audit_events_fslogix_user_time",
"audit_events_fslogix_account_time",
"audit_events_fslogix_result_time",
}.issubset(indexes),
f"audit indexes are incomplete: {sorted(indexes)}",
)