Read

Module 5 · Users, groups and permissions

Creating users and groups: adduser, addgroup

Create accounts and groups with BusyBox's adduser and addgroup, understand what each one writes, and remove them again cleanly.

What you will learn

  • Create a user with `adduser -D` and a group with `addgroup`.
  • Choose the primary group, home and shell at creation time.
  • Add an existing user to a group when the tools do not help, and delete users and groups.

Two small tools instead of five

On a full distribution you would meet useradd, usermod, groupadd, chsh and perhaps a friendlier adduser wrapper. BusyBox collapses all that into adduser and addgroup, plus deluser and delgroup to undo them. They do the honest work: append a line to /etc/passwd, /etc/shadow and /etc/group, create the home directory and copy /etc/skel into it if it exists.

By default adduser asks for a password interactively, twice. For scripted or quick work use -D: the account is created with no password and its shadow field set to !, which means *locked* until somebody runs passwd for it (next lesson). Other useful options: -G grp to pick the primary group, -h DIR for a non-standard home, -s SHELL to choose the shell, -H to skip the home directory and -S for a system account with a low UID. adduser --help lists them.

~% mkdir -p /home
~% adduser -D alice
~% grep alice /etc/passwd /etc/group /etc/shadow
/etc/passwd:alice:x:1000:1000:Linux User,,,:/home/alice:/bin/sh
/etc/group:alice:x:1000:
/etc/shadow:alice:!:20730:0:99999:7:::
~% ls -ld /home/alice
drwxr-sr-x    2 alice    alice            0 Oct  4 18:53 /home/alice
~% addgroup devs
~% adduser -D -G devs carol
~% id carol
uid=1001(carol) gid=1001(devs) groups=1001(devs)

Three things to notice. adduser also created a group called alice with the same number, the "user private group" convention. UIDs are handed out from 1000 upwards, GIDs likewise. And the mkdir -p /home line is not decoration: this lab image boots without a /home directory, so without it adduser prints /home/alice: No such file or directory, still creates the account, but leaves it homeless.

Adding an existing user to a group

Here is the gap in this BusyBox build: addgroup USER GROUP, the usual way to give an existing user a supplementary group, is not compiled in (addgroup --help shows no such form, and trying it fails). You have two options. If the user does not exist yet, create it with -G as above. If it does, remember that /etc/group is only text: append the name to the members field of the group's line, with vi or with sed. The members list is comma-separated, so the first member goes straight after the last colon and later ones need a comma.

~% sed -i '/^devs:/s/$/alice/' /etc/group
~% grep '^devs:' /etc/group
devs:x:1001:alice
~% id -nG alice
alice devs

Removing

deluser bob removes bob from /etc/passwd, /etc/shadow and from any group members lists, and drops his private group. It leaves /home/bob in place, now owned by a bare number because the name is gone; deluser --remove-home bob deletes it too. delgroup devs removes a group. Order matters a little: delete the user before his private group, or delgroup will have nothing to do.

Commands in this lesson

CommandWhat it does
adduser -D aliceCreate user alice with no password (locked).
adduser -D -G devs carolCreate carol with devs as primary group.
adduser -D -s /bin/false -H svcService account: no shell, no home.
addgroup devsCreate group devs.
sed -i '/^devs:/s/$/alice/' /etc/groupAdd alice as first member of devs (no addgroup USER GROUP here).
deluser --remove-home bobDelete bob and his home directory.
delgroup devsDelete group devs.

Quiz

  1. What does `-D` do in `adduser -D bob`?

    • Creates bob as a daemon account
    • Skips the password prompt, leaving the account locked
    • Deletes bob
  2. Which option sets the primary group at creation time?

    • `-g`
    • `-G`
    • `-S`
  3. How do you give an existing user a supplementary group in this BusyBox build?

    • `usermod -aG devs alice`
    • `addgroup alice devs`
    • Edit the members field of the group's line in /etc/group
  4. After `deluser bob`, what happens to /home/bob?

    • It is deleted automatically
    • It stays, owned by a numeric UID, unless you used `--remove-home`
    • It is moved to /root

Practice

  1. Create a user called `bob` without setting a password.

  2. Create a group called `devs`.

  3. The group `devs` exists. Create a user `carol`, with no password, whose *primary* group is `devs`.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.