-#!/bin/bash -l
+#!/bin/bash
# Copyright (C) 2016 Ian Kelling
#
# Licensed under the Apache License, Version 2.0 (the "License");
# limitations under the License.
# for setting up a new machine
-# usage: $0 [-r] HOSTNAME
+# usage: $0 [-r] [HOSTNAME]
+# HOSTNAME changes the machine's hostname
# tips:
# run any sudo command first so your pass is cached
# set the scrollback to unlimited in case something goes wrong
+# send to registrar, glue records:
+# for iankelling.org:
+
+# ns1.iankelling.org 72.14.176.105
+# ns1.iankelling.org 2600:3c00::f03c:91ff:fe6d:baf8
+# ns2.iankelling.org 172.105.84.95
+# ns2.iankelling.org 2a01:7e01::f03c:91ff:feb5:baec
+
+# for zroe.org:
+
+# ns1.zroe.org 72.14.176.105
+# ns1.zroe.org 2600:3c00::f03c:91ff:fe6d:baf8
+# ns2.zroe.org 172.105.84.95
+# ns2.zroe.org 2a01:7e01::f03c:91ff:feb5:baec
+#
+
+
+
####### begin setup environment #######
### make ssh interactive shell run better. for when running line interactively line by line
-sudo bash -c 'source /a/c/.bashrc && source /a/exe/ssh-emacs-setup'
-
+sudo bash -c '/a/exe/ssh-emacs-setup'
+if [[ -s ~/.bashrc ]];then . ~/.bashrc;fi
##### setup error handling
interactive=true # set this to false to force set -x
[[ $- == *i* ]] || interactive=false
fi
source /a/bin/errhandle/err
+errcatch-cleanup() {
+ echo 1 >~/.local/distro-begin
+}
+
+source /a/bin/distro-functions/src/package-manager-abstractions
+
### setup logging
exec &> >(sudo tee -a /var/log/distro-begin)
echo "$0: $(date): starting now)"
### arg parsing
recompile=false
+emacs=true
while [[ $1 == -* ]]; do
case $1 in
-r) recompile=true; shift ;;
+ -e) emacs=false; shift ;;
esac
done
if [[ $1 ]]; then
set +x
source /a/bin/distro-functions/src/identify-distros
$interactive || set -x
-for f in iank-dev htpc kd x2 x3 frodo tp li lj demohost kw fz; do
+for f in kd x2 x3 frodo tp li l2 demohost kw; do
eval "$f() { [[ $HOSTNAME == $f ]]; }"
done
codename=$(debian-codename)
-has_wayland() { [[ $codename == buster ]]; }
-has_x() { [[ $codename != buster ]]; }
+has_wayland() { has_monitor && [[ $codename == buster ]]; }
+has_x() { has_monitor && [[ $codename != buster ]]; }
has_monitor() { ! linode ; }
-linode() { lj || li; }
+linode() { l2 || li; }
+# linode actually has btrfs now, but we dont do anything with it.
has_btrfs() { ! linode; }
-home_network() { ! linode; }
-encrypted() { has_p; }
+home_network() { ! linode && ! kw; }
+has_p() { ! linode; }
+encrypted() { true; }
shopt -s extglob
-export GLOBIGNORE=*/.:*/..
+export GLOBIGNORE="*/.:*/.."
umask 022
PATH="/a/exe:$PATH"
sed="sed --follow-symlinks"
sudo dd of=/etc/systemd/system/keyscripton.service <<'EOF'
[Unit]
Description=Turn on automatic decryption of drives on boot
+# This is triggered by reboot and when keyscriptoff stops.
+
# tried using graphical.target, but it made my display manager restart before rebooting.
# generally, I don't think targets order shutdown like they do startup.
# So, I did systemd-analyze plot > something.svg, and picked a reliably started
WantedBy=keyscriptoff.service
EOF
sudo systemctl daemon-reload # needed if the file was already there
- sudo systemctl stop keyscripton.service
- # sudo systemctl start keyscripton.service
sudo systemctl enable keyscripton.service
sudo dd of=/etc/systemd/system/keyscriptoff.service <<'EOF'
sudo systemctl enable keyscriptoff.service
sudo systemctl start keyscriptoff.service
+ pi rsync
+
# from /usr/share/doc/dropbear-initramfs/README.initramfs.gz
+ tmp=$(mktemp)
while read -r m _; do /sbin/modinfo -F filename "$m"; done </proc/modules | \
- sed -nr "s@^/lib/modules/`uname -r`/kernel/drivers/net(/.*)?/([^/]+)\.ko\$@\2@p" \
- | sudo dd of=/etc/initramfs-tools/modules
- sudo apt-get -y install initramfs-tools-core
+ sed -nr "s@^/lib/modules/$(uname -r)/kernel/drivers/net(/.*)?/([^/]+)\.ko\$@\2@p" \
+ | sudo dd of=$tmp
+ if ! diff -q /etc/initramfs-tools/modules $tmp &>/dev/null; then
+ sudo dd if=$tmp of=/etc/initramfs-tools/modules
+ sudo /usr/sbin/update-initramfs -u -k all
+ fi
# initram auth keys get setup with rootsshsync
+ $script_dir/rootsshsync
# then for remote unlock, ssh and do this once per crypt disk:
# echo -n PASS >/lib/cryptsetup/passfifo
+ # or for buster+
+ # cryptroot-unlock
+
fi
##### end setup encryption scripts ######
# todo, it would be nice to cut down on some of the output
-##### fedora prereq/fundamental settings
-if isfedora; then
- # comment out line disallowing calling sudo in scripts
- sudo $sed -i 's/^Defaults *requiretty/#\0 # ian commented/' /etc/sudoers
- # turn on magic sysrq commands
- echo 1 > sudo dd of=/proc/sys/kernel/sysrq
- echo "kernel.sysrq = 1" > /etc/sysctl.d/90-sysrq.conf
- # selinux is not user friendly. Like, you enable samba, but you haven't run the magic selinux commands so it doesn't work
- # and you have no idea why.
- sudo $sed -i 's/^\(SELINUX=\).*/\1disabled/' /etc/selinux/config
- selinuxenabled && sudo setenforce 0
-fi
-
#### rerun my fai-time scripts
# already ran for pxe installs, but used for vps & updates
esac
###### setup hostname
-sudo $sed -i '/^127\.0\.1\.1/d' /etc/hosts
-echo "127.0.1.1 $HOSTNAME.b8.nz $HOSTNAME" | sudo tee -a /etc/hosts
+if [[ $HOSTNAME != $(cat /etc/hostname) ]]; then
+ echo $HOSTNAME > /etc/hostname
+ hostname -F /etc/hostname
+fi
+sudo sed -i --follow-symlinks -f - /etc/hosts <<EOF
+\$a 127.0.1.1 $HOSTNAME.b8.nz $HOSTNAME
+/^127\.0\.1\.1/d
+EOF
##### exit first stage if running as root
#### setup bash for root
-for x in /a/c/{.bashrc,brc,.bash_profile,.profile,.inputrc,path_add_function}; do
+for x in /a/c/{.bashrc,brc,brc2,.bash_profile,.profile,.inputrc,path_add_function}; do
sudo -i <<EOF
PATH="/a/exe:$PATH"
lnf $x /root
done
###### do conflink
-# li needs the bind group before conflink
-if [[ $HOSTNAME == li ]]; then
- getent group bind &>/dev/null || sudo groupadd -r bind
+# linode needs bind group before conflink
+if linode; then
+ pi-nostart bind9
fi
# this needs to be before installing pacserve so we have gpg conf.
conflink
set +x
err-allow
source /etc/profile.d/environment.sh
+export BRC=t
+# shellcheck source=./.bashrc
source ~/.bashrc
err-catch
$interactive || set -x
#### setup passwordless sudo
-tu /etc/sudoers <<EOF
-$USER ALL=(ALL) NOPASSWD: ALL
-Defaults env_keep += SUDOD
+
+# always_set_home
# makes ubuntu be like debian
# https://unix.stackexchange.com/a/91572
-Defaults always_set_home
-# default setting is to have minimum umask of 0022
+
+# umask: default setting is to have minimum umask of 0022
# This lets us have user-specific umasks which are more permissive.
# I did this for transmission and set it's umask gecos on install,
# see there for more info.
+
+tu /etc/sudoers <<EOF
+$USER ALL=(ALL) NOPASSWD: ALL
+Defaults env_keep += SUDOD
+Defaults always_set_home
Defaults !umask
EOF
###### p1 packages install ######
-if isarch; then
- # requirement for trash-cli.
- # background: strange error if just installing trash-cli: "pyalpm requires python",
- # so I see that it requires python2, and installing that manually fixes it.
- # I didn\'t see this on earlier installation, main thing which changed was
- # pacserve, so not sure if it\'s related.
- pi python2
-fi
pi ${p1[@]}
sudo rmmod evbug ||: # might not be loaded yet
file=/etc/modprobe.d/evbug.conf
line="blacklist evbug"
- if ! grep -xFq "$line" $file; then
+ if [[ $(cat $file) != $line ]]; then
sudo dd of=$file 2>/dev/null <<<"$line"
sudo depmod -a
sudo update-initramfs -u
###### link files
# convenient to just do all file linking in one place
-s lnf -T /a/bin /b
-s lnf -T /nocow/t /t
+sudo /a/exe/lnf -T /a/bin /b
+sudo /a/exe/lnf -T /nocow/t /t
if has_p; then
lnf -T /p/News ~/News
fi
-s lnf /q/root/.editor-backups /q/root/.undo-tree-history \
+sudo /a/exe/lnf /q/root/.editor-backups /q/root/.undo-tree-history \
/a/opt /a/c/.emacs.d $HOME/mw_vars /k/backup /root
-pi rsync # needed for rootsshsync
-/a/bin/ds/install-my-scripts # needed for rootsshsync
-rootsshsync
-s lnf /a/c/.vim /a/c/.vimrc /a/c/.gvimrc /root
-if has_p; then
- # for dovecot
- lnf -T /i/k/mboxes ~/mail
-fi
-
-
-
-##### install xinput
-if has_x; then
- case $(distro-name) in
- trisquel|ubuntu|debian)
- pi xinput
- ;;
- fedora)
- pi xinput_calibrator
- ;;
- arch)
- pi xorg-xinput
- ;;
- esac
+/a/bin/ds/install-my-scripts # needed for rootsshsync cronjob
+sudo /a/exe/lnf /a/c/.vim /a/c/.vimrc /a/c/.gvimrc /root
- #### install redshift
- case $(distro-name) in
- trisquel|ubuntu|debian)
- # recommends gets us geoclue (for darkening automatically at night i assume),
- # which recommends modemmanager, which is annoying to fix for the model01 keyboard.
- pi --no-install-recommends gtk-redshift
- ;;&
- fedora)
- pi redshift-gtk
- ;;&
- arch)
- pi redshift
- ;;&
- esac
-fi
-if has_wayland; then
- pi sway xwayland
- # originally used xkbcomp, documented in input-setup.sh, this doesnt
- # work under wayland, but its still useful for creating the config,
- # then modifying the system files.
- s sed -i.orig '/key *<KPMU> *{/,/}/s/KP_Multiply/underscore/g' /usr/share/X11/xkb/symbols/keypad
-fi
arch)
# pkgfile is like apt-cache
pi pkgfile
- s pkgfile --update
- ;;
-esac
-
-#### fedora specific packages
-case $(distro-name) in
- fedora)
- # todo, this could probably come later
- p -y groupinstall development-tools c-development books admin-tools
- pi man-pages
+ sudo pkgfile --update
;;
- # other distros unknown
esac
#### enable trim
sudo $sed -ri 's/( *issue_discards\b).*/\1 = 1/' /etc/lvm/lvm.conf
if encrypted; then
# flidas or so, these units arent built-in
- if isdeb && ! systemctl list-unit-files | grep -xF fstrim.timer &>/dev/null ; then
+ if isdeb && ! systemctl list-unit-files | grep ^fstrim.timer &>/dev/null ; then
sudo cp /usr/share/doc/util-linux/examples/fstrim.{service,timer} /etc/systemd/system
fi
# does weekly trim
##### make extra dirs
dirs=(/mnt/{1,2,3,4,5,6,7,8,9} /nocow/t)
-s mkdir -p "${dirs[@]}"
-s chown $USER:$USER "${dirs[@]}"
+sudo mkdir -p "${dirs[@]}"
+sudo chown $USER:$USER "${dirs[@]}"
###### setup /i
-tu /etc/fstab <<'EOF'
+if home_network; then
+ tu /etc/fstab <<'EOF'
/i/w /w none bind,noauto 0 0
/i/k /k none bind,noauto 0 0
EOF
-if ! mountpoint /kr; then
- s mkdir -p /kr
- s chown $USER:user2 /kr
-fi
-if home_network; then
+ if ! mountpoint /kr; then
+ sudo mkdir -p /kr
+ sudo chown $USER:user2 /kr
+ fi
if [[ $HOSTNAME == frodo ]]; then
tu /etc/fstab <<'EOF'
/k /kr none bind,noauto 0 0
frodo:/k /kr nfs noauto 0 0
EOF
fi
-fi
-s mkdir -p /q /i/{w,k}
-for dir in /{i,w,k}; do
- if mountpoint $dir; then continue; fi # already mounted
- s mkdir -p $dir
- s chown $USER:$USER $dir
-done
-# not needed for all hosts, but rather just keep it uniform
-s mkdir -p /mnt/iroot
-# debian auto mounting of multi-disk encrypted btrfs is busted. It is
-# in jessie, and in stretch as of 11/26/2016 I have 4 disks in cryptab,
-# based on 3 of those, it creates .device units for /dev/mapper/dev...
-# then waits endlessly for them on bootup, after the /dev/mapper disks
-# have already been created and exist. todo: create a simple repro
-# for this in a vm and report it upstream.
-if has_btrfs || home_network; then
+ sudo mkdir -p /q /i/{w,k}
+ for dir in /{i,w,k}; do
+ if mountpoint $dir; then continue; fi # already mounted
+ sudo mkdir -p $dir
+ sudo chown $USER:$USER $dir
+ done
+ # not needed for all hosts, but rather just keep it uniform
+ sudo mkdir -p /mnt/iroot
+ # debian auto mounting of multi-disk encrypted btrfs is busted. It is
+ # in jessie, and in stretch as of 11/26/2016 I have 4 disks in cryptab,
+ # based on 3 of those, it creates .device units for /dev/mapper/dev...
+ # then waits endlessly for them on bootup, after the /dev/mapper disks
+ # have already been created and exist. todo: create a simple repro
+ # for this in a vm and report it upstream.
pi nfs-common
- s dd of=/root/imount <<'EOF'
+ sudo dd of=/root/imount <<'EOF'
#!/bin/bash
[[ $EUID == 0 ]] || exec sudo -E "${BASH_SOURCE[0]}" "$@"
set -eE -o pipefail
fi
done
EOF
- s chmod +x /root/imount
-
- s dd of=/etc/systemd/system/imount.service <<EOF
+ sudo chmod +x /root/imount
+ sudo dd of=/etc/systemd/system/imount.service <<EOF
[Unit]
Description=Mount /i and related mountpoints
Before=syncthing@$USER.service
sudo systemctl enable imount.service
sudo systemctl start imount.service
fi
+###### end setup /i
##### setup /nocow.
# a nocow dir that is common to multiple distros installed on the same system
if ! mountpoint $dir; then
subvol=/mnt/root/nocow
if [[ ! -e $subvol ]]; then
- s btrfs subvolume create $subvol
- s chown root:1000 $subvol
- s chattr +C $subvol
+ sudo btrfs subvolume create $subvol
+ sudo chown root:1000 $subvol
+ sudo chattr +C $subvol
fi
first_root_crypt=$(awk '$2 == "/" {print $1}' /etc/mtab)
tu /etc/fstab <<EOF
$first_root_crypt /nocow btrfs noatime,subvol=nocow 0 0
EOF
- s mkdir -p $dir
- s chown $USER:$USER $dir
- s mount $dir
+ sudo mkdir -p $dir
+ sudo chown $USER:$USER $dir
+ sudo mount $dir
fi
else
sudo mkdir -p $dir
#### ubuntu nicety
if isubuntu; then
# disable crash report annoying dialogs.
- s dd of=/etc/default/apport <<<'enabled=0'
+ sudo dd of=/etc/default/apport <<<'enabled=0'
fi
-##### install emacs
-if isarch; then
- # emacs git build was broken last time i checked,
- x=$(mktemp -d)
- pushd $x
- aurex emacs-git
- makepkg -si --noconfirm
- popd
- rm -rf $x
- pi hunspell hunspell-en
-else
- if $recompile; then
- /a/bin/buildscripts/emacs
- else
- /a/bin/buildscripts/emacs --no-r || /a/bin/buildscripts/emacs
- fi
-fi
##### install laptop hardware packages
if tp || x2 || x3; then
esac
fi
-
-##### install x stuff
-if has_monitor; then
- pi ${p2[@]}
- if has_x; then
- pi i3
- if isarch; then
- # xorg-xmessage for displaying error messages.
- # optional dependency in arch, standard elsewhere.
- pi xorg-server xorg-xmessage xorg-xsetroot xorg-xinit
- fi
+if has_x; then
+ ###### install X
+ pi i3
+ if isarch; then
+ # xorg-xmessage for displaying error messages.
+ # optional dependency in arch, standard elsewhere.
+ pi xorg-server xorg-xmessage xorg-xsetroot xorg-xinit
fi
-fi
+ ##### install xinput
+ case $(distro-name) in
+ trisquel|ubuntu|debian)
+ pi xinput
+ ;;
+ arch)
+ pi xorg-xinput
+ ;;
+ esac
+
+ #### install redshift
+ case $(distro-name) in
+ trisquel|ubuntu|debian)
+ # recommends gets us geoclue (for darkening automatically at night i assume),
+ # which recommends modemmanager, which is annoying to fix for the model01 keyboard.
+ pi --no-install-recommends gtk-redshift
+ ;;&
+ arch)
+ pi redshift
+ ;;&
+ esac
-##### setup X autostart
-if has_x; then
+ ##### setup X autostart
if isarch; then
# https://wiki.archlinux.org/index.php/Xinitrc
for homedir in /home/*; do
cp /etc/X11/xinit/xinitrc $homedir/.xinitrc
+ # shellcheck disable=SC2016
$sed -ri '/^ *twm\b/,$d' $homedir/.xinitrc
tee -a $homedir/.xinitrc <<'EOF'
/a/bin/desktop-20-autostart.sh
else
# todo, figure this out for arch if we ever try out gnome.
# install for multiple display managers in case we use one
- if isdeb; then
- dir=/etc/gdm3
- elif isfedora; then
- # fedora didn\'t have the 3.
- dir=/etc/gdm
- fi
- s mkdir -p $dir/PostLogin
- s command cp /a/bin/distro-setup/desktop-20-autostart.sh $dir/PostLogin/Default
- s mkdir /etc/lightdm/lightdm.conf.d
- s dd of=/etc/lightdm/lightdm.conf.d/12-iank.conf <<'EOF'
+ dir=/etc/gdm3
+ sudo mkdir -p $dir/PostLogin
+ sudo cp /a/bin/distro-setup/desktop-20-autostart.sh $dir/PostLogin/Default
+ sudo mkdir -p /etc/lightdm/lightdm.conf.d
+ sudo dd of=/etc/lightdm/lightdm.conf.d/12-iank.conf <<'EOF'
[SeatDefaults]
session-setup-script=/a/bin/distro-setup/desktop-20-autostart.sh
EOF
fi
+
+fi
+
+### install and configure wayland
+if has_wayland; then
+ pi sway xwayland
+ # originally used xkbcomp, documented in input-setup.sh, this doesnt
+ # work under wayland, but its still useful for creating the config,
+ # then modifying the system files.
+ sudo sed -i.orig '/key *<KPMU> *{/,/}/s/KP_Multiply/underscore/g' /usr/share/X11/xkb/symbols/keypad
+fi
+
+##### basic graphical packages
+if has_monitor; then
+ pi konsole suckless-tools
fi
-#### refix interactive ssh terminal
-# the first pup command can kill off our /etc/ mod, so rerun this
-/a/exe/ssh-emacs-setup
+##### install emacs
+if $emacs; then
+ if isarch; then
+ # emacs git build was broken last time i checked,
+ x=$(mktemp -d)
+ pushd $x
+ aurex emacs-git
+ makepkg -si --noconfirm
+ popd
+ rm -rf $x
+ pi hunspell hunspell-en
+ else
+ if $recompile; then
+ /a/bin/buildscripts/emacs
+ else
+ /a/bin/buildscripts/emacs --no-r
+ fi
+ fi
+ # the first pup command can kill off our /etc/ mod, so rerun this
+ /a/exe/ssh-emacs-setup
+fi
+echo 0 >~/.local/distro-begin
echo "$0: $(date): ending now"
exit 0