From 2788e4fa981566e34fa40938705cd7f595f05e74 Mon Sep 17 00:00:00 2001 From: Andrew Lubawy Date: Mon, 17 Jun 2024 11:56:58 -0700 Subject: [PATCH] Use `sysadminctl` instead of `dscl` Co-authored-by: Michael Hoang --- modules/users/default.nix | 23 +++++++++++----------- tests/users-groups.nix | 40 ++++++++++++++++++++------------------- 2 files changed, 32 insertions(+), 31 deletions(-) diff --git a/modules/users/default.nix b/modules/users/default.nix index cd0986d8..ead996c3 100644 --- a/modules/users/default.nix +++ b/modules/users/default.nix @@ -147,28 +147,28 @@ in ${concatMapStringsSep "\n" (v: '' ${optionalString cfg.forceRecreate '' - u=$(dscl . -read '/Users/${v.name}' UniqueID 2> /dev/null) || true - u=''${u#UniqueID: } + u=$(id -u '${v.name}' 2> /dev/null) || true if [[ "$u" -eq ${toString v.uid} ]]; then echo "deleting user ${v.name}..." >&2 - dscl . -delete '/Users/${v.name}' 2> /dev/null + sysadminctl -deleteUser '${v.name}' 2> /dev/null else echo "warning: existing user '${v.name}' has unexpected uid $u, skipping..." >&2 fi ''} - u=$(dscl . -read '/Users/${v.name}' UniqueID 2> /dev/null) || true - u=''${u#UniqueID: } + u=$(id -u '${v.name}' 2> /dev/null) || true if [[ -n "$u" && "$u" -ne "${toString v.uid}" ]]; then echo "warning: existing user '${v.name}' has unexpected uid $u, skipping..." >&2 else if [ -z "$u" ]; then echo "creating user ${v.name}..." >&2 - dscl . -create '/Users/${v.name}' UniqueID ${toString v.uid} - dscl . -create '/Users/${v.name}' PrimaryGroupID ${toString v.gid} + sysadminctl -addUser '${v.name}' \ + -UID ${toString v.uid} \ + -GID ${toString v.gid} \ + -fullName '${v.description}' \ + -home '${v.home}' \ + -shell ${lib.escapeShellArg (shellPath v.shell)} dscl . -create '/Users/${v.name}' IsHidden ${if v.isHidden then "1" else "0"} - dscl . -create '/Users/${v.name}' RealName '${v.description}' - dscl . -create '/Users/${v.name}' NFSHomeDirectory '${v.home}' ${optionalString v.createHome "createhomedir -cu '${v.name}'"} fi # Always set the shell path, in case it was updated @@ -177,12 +177,11 @@ in '') createdUsers} ${concatMapStringsSep "\n" (name: '' - u=$(dscl . -read '/Users/${name}' UniqueID 2> /dev/null) || true - u=''${u#UniqueID: } + u=$(id -u '${name}' 2> /dev/null) || true if [ -n "$u" ]; then if [ "$u" -gt 501 ]; then echo "deleting user ${name}..." >&2 - dscl . -delete '/Users/${name}' 2> /dev/null + sysadminctl -deleteUser '${name}' 2> /dev/null else echo "warning: existing user '${name}' has unexpected uid $u, skipping..." >&2 fi diff --git a/tests/users-groups.nix b/tests/users-groups.nix index feaaf2bd..b619f9b4 100644 --- a/tests/users-groups.nix +++ b/tests/users-groups.nix @@ -22,13 +22,15 @@ users.users."unknown.user".uid = 42002; test = '' - echo "checking group creation in /activate" >&2 + set -v + + # checking group creation in /activate grep "dscl . -create '/Groups/foo' PrimaryGroupID 42000" ${config.out}/activate grep "dscl . -create '/Groups/foo' RealName 'Foo group'" ${config.out}/activate grep "dscl . -create '/Groups/created.group' PrimaryGroupID 42001" ${config.out}/activate grep -qv "dscl . -delete '/Groups/created.group'" ${config.out}/activate - echo "checking group deletion in /activate" >&2 + # checking group deletion in /activate grep "dscl . -delete '/Groups/deleted.group'" ${config.out}/activate grep -qv "dscl . -create '/Groups/deleted.group'" ${config.out}/activate @@ -36,28 +38,28 @@ grep "dscl . -create '/Groups/foo' GroupMembership 'admin' 'foo'" ${config.out}/activate grep "dscl . -create '/Groups/created.group' GroupMembership" ${config.out}/activate - echo "checking unknown group in /activate" >&2 + # checking unknown group in /activate grep -qv "dscl . -create '/Groups/unknown.group'" ${config.out}/activate grep -qv "dscl . -delete '/Groups/unknown.group'" ${config.out}/activate - echo "checking user creation in /activate" >&2 - grep "dscl . -create '/Users/foo' UniqueID 42000" ${config.out}/activate - grep "dscl . -create '/Users/foo' PrimaryGroupID 42000" ${config.out}/activate - grep "dscl . -create '/Users/foo' IsHidden 0" ${config.out}/activate - grep "dscl . -create '/Users/foo' RealName 'Foo user'" ${config.out}/activate - grep "dscl . -create '/Users/foo' NFSHomeDirectory '/Users/foo'" ${config.out}/activate - grep "dscl . -create '/Users/foo' UserShell ${lib.escapeShellArg "/run/current-system/sw/bin/bash"}" ${config.out}/activate - grep "dscl . -create '/Users/created.user' UniqueID 42001" ${config.out}/activate - grep "dscl . -create '/Users/created.user' UserShell ${lib.escapeShellArg "/sbin/nologin"}" ${config.out}/activate + # checking user creation in /activate + grep -zoP "sysadminctl -addUser 'foo' (.|\n)* -UID 42000 (.|\n)* -GID 42000 (.|\n)* -fullName 'Foo user' (.|\n)* -home '/Users/foo' (.|\n)* -shell ${lib.escapeShellArg "/run/current-system/sw/bin/bash"}" ${config.out}/activate grep "createhomedir -cu 'foo'" ${config.out}/activate - grep -qv "dscl . -delete '/Groups/created.user'" ${config.out}/activate + grep -zoP "sysadminctl -addUser 'created.user' (.|\n)* -UID 42001 (.|\n)* -shell ${lib.escapeShellArg "/sbin/nologin"}" ${config.out}/activate + grep -qv "sysadminctl -deleteUser 'created.user'" ${config.out}/activate + grep -qv "sysadminctl -deleteUser 'created.user'" ${config.out}/activate - echo "checking user deletion in /activate" >&2 - grep "dscl . -delete '/Users/deleted.user'" ${config.out}/activate - grep -qv "dscl . -create '/Users/deleted.user'" ${config.out}/activate + # checking user properties always get updated in /activate + grep "dscl . -create '/Users/foo' UserShell ${lib.escapeShellArg "/run/current-system/sw/bin/bash"}" ${config.out}/activate - echo "checking unknown user in /activate" >&2 - grep -qv "dscl . -create '/Users/unknown.user'" ${config.out}/activate - grep -qv "dscl . -delete '/Users/unknown.user'" ${config.out}/activate + # checking user deletion in /activate + grep "sysadminctl -deleteUser 'deleted.user'" ${config.out}/activate + grep -qv "sysadminctl -addUser 'deleted.user'" ${config.out}/activate + + # checking unknown user in /activate + grep -qv "sysadminctl -addUser 'unknown.user'" ${config.out}/activate + grep -qv "sysadminctl -deleteUser 'unknown.user'" ${config.out}/activate + + set +v ''; }