better trash; no favicon
This commit is contained in:
@@ -15,6 +15,13 @@ RUN apt-get update \
|
||||
tini \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Rootless Podman maps 65,536 IDs. Keep this disposable DC's internal idmap
|
||||
# inside that namespace; production AD domains must use their normal range.
|
||||
RUN sed -i \
|
||||
-e 's/lowerBound: 3000000/lowerBound: 10000/' \
|
||||
-e 's/upperBound: 4000000/upperBound: 60000/' \
|
||||
/usr/share/samba/setup/idmap_init.ldif
|
||||
|
||||
COPY dev/ad-entrypoint.sh /usr/local/bin/preview-ad-entrypoint
|
||||
COPY dev/preview-client.sh /usr/local/bin/preview-client
|
||||
COPY dev/seed-files.sh /usr/local/bin/preview-seed-files
|
||||
|
||||
+20
-2
@@ -21,14 +21,32 @@ done
|
||||
|
||||
if [[ ! -s /var/lib/samba/private/sam.ldb ]]; then
|
||||
log "Provisioning disposable ${AD_REALM} domain"
|
||||
rm -f /etc/samba/smb.conf
|
||||
netbios_name=${HOSTNAME%%.*}
|
||||
netbios_name=${netbios_name^^}
|
||||
mkdir -p /var/lib/samba/state
|
||||
cat > /etc/samba/smb.conf <<EOF
|
||||
[global]
|
||||
netbios name = ${netbios_name}
|
||||
realm = ${AD_REALM}
|
||||
workgroup = ${AD_DOMAIN}
|
||||
server role = active directory domain controller
|
||||
xattr_tdb:file = /var/lib/samba/state/xattr.tdb
|
||||
|
||||
[sysvol]
|
||||
path = /var/lib/samba/sysvol
|
||||
read only = no
|
||||
|
||||
[netlogon]
|
||||
path = /var/lib/samba/sysvol/${AD_DNS_DOMAIN}/scripts
|
||||
read only = no
|
||||
EOF
|
||||
samba-tool domain provision \
|
||||
--server-role=dc \
|
||||
--use-rfc2307 \
|
||||
--dns-backend=SAMBA_INTERNAL \
|
||||
--realm="$AD_REALM" \
|
||||
--domain="$AD_DOMAIN" \
|
||||
--adminpass="$AD_ADMIN_PASSWORD"
|
||||
samba-tool ntacl sysvolcheck
|
||||
fi
|
||||
|
||||
ln -sf /var/lib/samba/private/krb5.conf /etc/krb5.conf
|
||||
|
||||
+56
-4
@@ -324,7 +324,7 @@ def main() -> int:
|
||||
"-U",
|
||||
f"{WORKGROUP}\\alice%{USER_PASSWORD}",
|
||||
"-c",
|
||||
"cd .trash; ls",
|
||||
"cd .trash",
|
||||
check_result=False,
|
||||
)
|
||||
check(
|
||||
@@ -332,6 +332,48 @@ def main() -> int:
|
||||
"ordinary SMB user can browse the admin-managed trash repository",
|
||||
)
|
||||
|
||||
announce("temporary and document-lock files bypass the recycle repository")
|
||||
transient_delete = engine_run(
|
||||
"exec",
|
||||
CLIENT_CONTAINER,
|
||||
"smbclient",
|
||||
f"//files.{DNS_DOMAIN}/Data",
|
||||
"-m",
|
||||
"SMB3",
|
||||
"-U",
|
||||
f"{WORKGROUP}\\alice%{USER_PASSWORD}",
|
||||
"-c",
|
||||
(
|
||||
"cd Finance; cd Reports; "
|
||||
"put /tmp/live-note.txt 713A292F.tmp; del 713A292F.tmp; "
|
||||
'put /tmp/live-note.txt "~$RG Eingang 2026.xlsx"; '
|
||||
'del "~$RG Eingang 2026.xlsx"'
|
||||
),
|
||||
check_result=False,
|
||||
)
|
||||
check(
|
||||
transient_delete.returncode == 0,
|
||||
"temporary/document-lock deletion over SMB failed: "
|
||||
+ (transient_delete.stderr.strip() or transient_delete.stdout.strip()),
|
||||
)
|
||||
transient_absent = engine_run(
|
||||
"exec",
|
||||
FILES_CONTAINER,
|
||||
"sh",
|
||||
"-ec",
|
||||
(
|
||||
"test ! -e '/data/groups/data/Finance/Reports/713A292F.tmp'; "
|
||||
"test ! -e '/data/groups/data/Finance/Reports/~$RG Eingang 2026.xlsx'; "
|
||||
"test -z \"$(find /data/groups/data/.trash -type f "
|
||||
"\\( -iname '*.tmp' -o -name '~$*' \\) -print -quit)\""
|
||||
),
|
||||
check_result=False,
|
||||
)
|
||||
check(
|
||||
transient_absent.returncode == 0,
|
||||
"temporary or document-lock file was retained in the trash repository",
|
||||
)
|
||||
|
||||
announce("real Samba recycle, admin download, and conflict-safe restore")
|
||||
trash_response = eventually(
|
||||
"deleted SMB file in the seven-day trash",
|
||||
@@ -486,9 +528,19 @@ def main() -> int:
|
||||
)
|
||||
check(
|
||||
{
|
||||
"audit_events_time",
|
||||
"audit_events_user_time",
|
||||
"audit_events_action_time",
|
||||
"audit_events_main_time",
|
||||
"audit_events_main_action_time",
|
||||
"audit_events_main_success_time",
|
||||
"audit_events_main_user_time",
|
||||
"audit_events_main_account_time",
|
||||
"audit_events_main_share_time",
|
||||
"audit_events_main_result_time",
|
||||
"audit_events_fslogix_time",
|
||||
"audit_events_fslogix_action_time",
|
||||
"audit_events_fslogix_success_time",
|
||||
"audit_events_fslogix_user_time",
|
||||
"audit_events_fslogix_account_time",
|
||||
"audit_events_fslogix_result_time",
|
||||
}.issubset(indexes),
|
||||
f"audit indexes are incomplete: {sorted(indexes)}",
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user