Module 5 · Users, groups and permissions
Creating users and groups: adduser, addgroup
Create accounts and groups with BusyBox's adduser and addgroup, understand what each one writes, and remove them again cleanly.
What you will learn
- Create a user with `adduser -D` and a group with `addgroup`.
- Choose the primary group, home and shell at creation time.
- Add an existing user to a group when the tools do not help, and delete users and groups.
Two small tools instead of five
On a full distribution you would meet useradd, usermod, groupadd, chsh and perhaps a friendlier adduser wrapper. BusyBox collapses all that into adduser and addgroup, plus deluser and delgroup to undo them. They do the honest work: append a line to /etc/passwd, /etc/shadow and /etc/group, create the home directory and copy /etc/skel into it if it exists.
By default adduser asks for a password interactively, twice. For scripted or quick work use -D: the account is created with no password and its shadow field set to !, which means *locked* until somebody runs passwd for it (next lesson). Other useful options: -G grp to pick the primary group, -h DIR for a non-standard home, -s SHELL to choose the shell, -H to skip the home directory and -S for a system account with a low UID. adduser --help lists them.
~% mkdir -p /home
~% adduser -D alice
~% grep alice /etc/passwd /etc/group /etc/shadow
/etc/passwd:alice:x:1000:1000:Linux User,,,:/home/alice:/bin/sh
/etc/group:alice:x:1000:
/etc/shadow:alice:!:20730:0:99999:7:::
~% ls -ld /home/alice
drwxr-sr-x 2 alice alice 0 Oct 4 18:53 /home/alice
~% addgroup devs
~% adduser -D -G devs carol
~% id carol
uid=1001(carol) gid=1001(devs) groups=1001(devs)
Three things to notice. adduser also created a group called alice with the same number, the "user private group" convention. UIDs are handed out from 1000 upwards, GIDs likewise. And the mkdir -p /home line is not decoration: this lab image boots without a /home directory, so without it adduser prints /home/alice: No such file or directory, still creates the account, but leaves it homeless.
Adding an existing user to a group
Here is the gap in this BusyBox build: addgroup USER GROUP, the usual way to give an existing user a supplementary group, is not compiled in (addgroup --help shows no such form, and trying it fails). You have two options. If the user does not exist yet, create it with -G as above. If it does, remember that /etc/group is only text: append the name to the members field of the group's line, with vi or with sed. The members list is comma-separated, so the first member goes straight after the last colon and later ones need a comma.
~% sed -i '/^devs:/s/$/alice/' /etc/group
~% grep '^devs:' /etc/group
devs:x:1001:alice
~% id -nG alice
alice devs
Removing
deluser bob removes bob from /etc/passwd, /etc/shadow and from any group members lists, and drops his private group. It leaves /home/bob in place, now owned by a bare number because the name is gone; deluser --remove-home bob deletes it too. delgroup devs removes a group. Order matters a little: delete the user before his private group, or delgroup will have nothing to do.
Commands in this lesson
| Command | What it does |
|---|---|
adduser -D alice | Create user alice with no password (locked). |
adduser -D -G devs carol | Create carol with devs as primary group. |
adduser -D -s /bin/false -H svc | Service account: no shell, no home. |
addgroup devs | Create group devs. |
sed -i '/^devs:/s/$/alice/' /etc/group | Add alice as first member of devs (no addgroup USER GROUP here). |
deluser --remove-home bob | Delete bob and his home directory. |
delgroup devs | Delete group devs. |
Quiz
What does `-D` do in `adduser -D bob`?
- Creates bob as a daemon account
- Skips the password prompt, leaving the account locked
- Deletes bob
Which option sets the primary group at creation time?
- `-g`
- `-G`
- `-S`
How do you give an existing user a supplementary group in this BusyBox build?
- `usermod -aG devs alice`
- `addgroup alice devs`
- Edit the members field of the group's line in /etc/group
After `deluser bob`, what happens to /home/bob?
- It is deleted automatically
- It stays, owned by a numeric UID, unless you used `--remove-home`
- It is moved to /root
Practice
Create a user called `bob` without setting a password.
Create a group called `devs`.
The group `devs` exists. Create a user `carol`, with no password, whose *primary* group is `devs`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.