X-Git-Url: https://iankelling.org/git/?a=blobdiff_plain;f=distro-end;h=d63d315d3da01c6a275bd2d68dda08ee0fed1e8b;hb=165008e5b82c81ebff1061c8f8294c3bc6e9dced;hp=87a54e3af75a4bd81230f907fd3f61924b60f267;hpb=4d0dc703ef2e62cd16ea84f27456f6f50f74baa3;p=distro-setup diff --git a/distro-end b/distro-end index 87a54e3..d63d315 100755 --- a/distro-end +++ b/distro-end @@ -1,6 +1,7 @@ -#!/bin/bash -l +#!/bin/bash # Copyright (C) 2019 Ian Kelling # SPDX-License-Identifier: AGPL-3.0-or-later +if [[ -s ~/.bashrc ]];then . ~/.bashrc;fi ### setup source /a/bin/errhandle/err @@ -11,7 +12,7 @@ if [[ $EUID == 0 ]]; then exit 1 fi -_errcatch_cleanup() { +errcatch-cleanup() { echo 1 >~/.local/distro-end } @@ -31,19 +32,19 @@ end() { echo 0 >~/.local/distro-end if $pending_reboot; then echo "$0: pending reboot and then finished. doing it now." - s reboot now + sudo reboot now else echo "$0: $(date): ending now)" fi exit 0 } pre="${0##*/}:" -s() { - printf "s %s\n" "$*" - SUDOD="$PWD" sudo -i "$@"; +sudo() { + printf "$pre %s\n" "$*" + SUDOD="$PWD" command sudo "$@"; } sd() { - s dd of="$1" 2>/dev/null + sudo dd of="$1" 2>/dev/null } m() { printf "$pre %s\n" "$*"; "$@"; } e() { printf "$pre %s\n" "$*"; } @@ -53,9 +54,9 @@ codename=$(debian-codename) codename_compat=$(debian-codename-compat) pending_reboot=false sed="sed --follow-symlinks" -# template -case $distro in -esac +## template: +# case $distro in +# esac #### initial packages pup @@ -64,7 +65,7 @@ if isdeb; then fi # avoid prompts -s debconf-set-selections </dev/null; then - s apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 + sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 sd /etc/apt/preferences.d/flidas-bionic <$t </dev/null <<'EOF' -[Unit] -Description=ZNC, an advanced IRC bouncer -After=network-online.target - -[Service] -ExecStart=/usr/bin/znc -f --datadir=/var/lib/znc -User=znc - -[Install] -WantedBy=multi-user.target -EOF - ser daemon-reload - # avoid restarting if possible, reconnecting to irc is annoying. - if [[ $(ser is-active znc) != active ]]; then - m sgo znc + if ! getent passwd znc > /dev/null; then + sudo useradd --create-home -d /var/lib/znc --system --shell /sbin/nologin --comment "Account to run ZNC daemon" --user-group znc + fi + sudo chmod 700 /var/lib/znc + sudo chown -R znc:znc /var/lib/znc + # Avoid restarting if possible, reconnecting to irc is annoying. + # The unit file was made active with conflink. + # Note, avoid using ser here because we wrap sudo to prints the command first. + if [[ $(systemctl is-active znc) != active ]]; then + sgo znc fi ###### stop znc setup ##### @@ -607,11 +617,11 @@ esac pi ${pall[@]} $(apt-cache search ruby[.0-9]+-doc| awk '{print $1}') $(apt-cache depends gcc|grep -i suggests:| awk '{print $2}') $($src/distro-pkgs) -m sgo fsf-vpn-dns-cleanup +sgo fsf-vpn-dns-cleanup # website is dead june 14 2019. back in october, but meh -s rm -fv /etc/apt/sources.list.d/iridium-browser.list +sudo rm -fv /etc/apt/sources.list.d/iridium-browser.list # case $distro in # debian) # pi chromium ;; @@ -655,12 +665,12 @@ s rm -fv /etc/apt/sources.list.d/iridium-browser.list # key already exists, so this won't generate one, just the configs. m vpn-server-setup -rds -s tee -a /etc/openvpn/server/server.conf <<'EOF' +sudo tee -a /etc/openvpn/server/server.conf <<'EOF' push "dhcp-option DNS 10.0.0.1" push "route 10.0.0.0 255.255.0.0" client-connect /a/bin/distro-setup/vpn-client-connect EOF -s sed -i --follow-symlinks 's/10.8./10.9./g;s/^\s*port\s.*/port 1196/' /etc/openvpn/server/server.conf +sudo sed -i --follow-symlinks 's/10.8./10.9./g;s/^\s*port\s.*/port 1196/' /etc/openvpn/server/server.conf if [[ $HOSTNAME == tp ]]; then if [[ -e /lib/systemd/system/openvpn-server@.service ]]; then @@ -668,7 +678,7 @@ if [[ $HOSTNAME == tp ]]; then else vpn_service=openvpn@server fi - m sgo $vpn_service + sgo $vpn_service fi ### end vpn server setup @@ -702,7 +712,7 @@ OnUnitInactiveSec=300 [Install] WantedBy=timers.target EOF -s systemctl daemon-reload +sudo systemctl daemon-reload ######### begin pump.io periodic backup ############# @@ -728,7 +738,7 @@ OnCalendar=hourly WantedBy=timers.target EOF ser daemon-reload - m sgo pumpbackup.timer + sgo pumpbackup.timer fi ######### end pump.io periodic backup ############# @@ -755,7 +765,7 @@ OnCalendar=hourly [Install] WantedBy=timers.target EOF - s systemctl daemon-reload + sudo systemctl daemon-reload sgo ircbackup.timer fi @@ -801,7 +811,7 @@ if [[ $HOSTNAME == frodo ]]; then pi syncthing m lnf -T /w/syncthing /home/iank/.config/syncthing ser daemon-reload # syncthing likely not properly packaged - m sgo syncthing@iank # runs as iank + sgo syncthing@iank # runs as iank # these things persist in ~/.config/syncthing, which I save in # /w/syncthing (not in /p, because syncthing should continue to @@ -886,7 +896,7 @@ fi pi libswitch-perl libdigest-md5-file-perl libgnupg-interface-perl t=$(mktemp) m wget -O $t http://mirror.fsf.org/fsfsys-trisquel/fsfsys-trisquel/pool/main/s/spd-perl/spd-perl_0.2-1_amd64.deb -s dpkg -i $t +sudo dpkg -i $t m rm $t # this guesses at the appropriate directory, adjust if needed perldir=(/usr/lib/x86_64-linux-gnu/perl/5.*) @@ -894,7 +904,7 @@ m sudo ln -sf ../../../perl/5.18.2/SPD/ ${perldir[0]} # newer distro had gpg2 as default, older one, flidas, need to make it that way gpgpath=$(which gpg2) if [[ $x ]]; then - s mkdir -p /usr/local/spdhackfix + sudo mkdir -p /usr/local/spdhackfix s lnf -T $gpgpath /usr/local/spdhackfix/gpg fi ### end spd install @@ -977,16 +987,16 @@ preserve-environment=true users=$USER,user2 EOF if [[ -e $d/bin ]]; then - s chroot $d apt-get update - s chroot $d apt-get -y dist-upgrade --purge --auto-remove - cd; s schroot -c $n -- apt-get install --allow-unauthenticated -y ${apps[@]} + sudo chroot $d apt-get update + sudo chroot $d apt-get -y dist-upgrade --purge --auto-remove + cd; sudo schroot -c $n -- apt-get install --allow-unauthenticated -y ${apps[@]} else - s mkdir -p $d + sudo mkdir -p $d - s debootstrap $n $d $repo - cd; s schroot -c $n -- apt-get install --allow-unauthenticated -y ${apps[@]} + sudo debootstrap $n $d $repo + cd; sudo schroot -c $n -- apt-get install --allow-unauthenticated -y ${apps[@]} fi - s cp -P {,$d}/etc/localtime + sudo cp -P {,$d}/etc/localtime } sd /etc/systemd/system/schrootupdate.service <<'EOF' [Unit] @@ -1008,7 +1018,7 @@ OnCalendar=*-*-* 04:20:00 WantedBy=timers.target EOF ser daemon-reload -m sgo schrootupdate.timer +sgo schrootupdate.timer @@ -1022,32 +1032,41 @@ case $distro in ;; esac -s mkdir -p /nocow/user -s chown $USER:$USER /nocow/user +sudo mkdir -p /nocow/user +sudo chown $USER:$USER /nocow/user pi anki ####### begin transmission +case $HOSTNAME in + frodo) + tdir=/i/k + ;; + *) + tdir=/nocow/user + ;; +esac + # adapted from /var/lib/dpkg/info/transmission-daemon.postinst # 450 seems likely to be unused. we need to specify one or else # it won't be stable across installs. if ! getent passwd debian-transmission > /dev/null; then - s groupadd -g 450 debian-transmission - s adduser --quiet \ - --gid 450 \ - --uid 450 \ - --system \ - --no-create-home \ - --disabled-password \ - --home /var/lib/transmission-daemon \ - debian-transmission + sudo groupadd -g 450 debian-transmission + sudo adduser --quiet \ + --gid 450 \ + --uid 450 \ + --system \ + --no-create-home \ + --disabled-password \ + --home /var/lib/transmission-daemon \ + debian-transmission fi # We want group writable stuff from transmission. # However, after setting this, I learn that transmission sets it's # own umask based on it's settings file. Well, no harm leaving this # so it's set right from the beginning. -s chfn debian-transmission -o umask=0002 +sudo chfn debian-transmission -o umask=0002 # note i had to do this, which is persistent: # cd /i/k @@ -1060,7 +1079,7 @@ tu /etc/sysctl.conf<<'EOF' net.core.rmem_max = 67108864 net.core.wmem_max = 16777216 EOF -s sysctl -p +sudo sysctl -p # some reason it doesn\'t seem to start automatically anyways pi-nostart transmission-daemon @@ -1073,17 +1092,17 @@ ser stop transmission-daemon # plus a simple symlink to the config file which it\'s # not worth separating out. # between comps, the uid can change -f=/i/transmission-daemon +f=$tdir/transmission-daemon +mkdir -p $f s lnf -T $f /var/lib/transmission-daemon/.config/transmission-daemon -if [[ -e $f ]]; then - s chown -R debian-transmission:debian-transmission $f -fi -for f in /i/k/partial-torrents /i/k/torrents; do +s lnf -T /etc/transmission-daemon/settings.json $f/settings.json +sudo chown -R debian-transmission:debian-transmission $f +for f in $tdir/partial-torrents $tdir/torrents; do if [[ -e $f ]]; then - s chown -R debian-transmission:user2 $f + sudo chown -R debian-transmission:user2 $f fi done -s chown -R debian-transmission:debian-transmission /var/lib/transmission-daemon +sudo chown -R debian-transmission:debian-transmission /var/lib/transmission-daemon # # config file documented here, and it\'s the same config # for daemon vs client, so it\'s documented in the gui. @@ -1095,16 +1114,15 @@ s chown -R debian-transmission:debian-transmission /var/lib/transmission-daemon # # Changed the cache-size to 256 mb, reduces disk use. # It is a read & write cache. -# -s ruby <<'EOF' +sudo ruby < false, 'rpc-authentication-required' => false, -'incomplete-dir' => '/i/k/partial-torrents', +'incomplete-dir' => '$tdir/partial-torrents', 'incomplete-dir-enabled' => true, -'download-dir' => '/i/k/torrents', +'download-dir' => '$tdir/torrents', "speed-limit-up" => 800, "speed-limit-up-enabled" => true, "peer-port" => 61486, @@ -1146,7 +1164,7 @@ EOF ser daemon-reload if [[ $HOSTNAME == frodo ]]; then - m sgo transmission-daemon-nn + sgo transmission-daemon-nn fi @@ -1166,7 +1184,7 @@ if [[ -e /p/transmission-rpc-pass ]]; then # the password is randomly generated on first run, i copied it out # so it could be used by other hosts. - s ruby <<'EOF' + sudo ruby <<'EOF' require 'json' p = '/etc/transmission-daemon/settings.json' s = JSON.parse(File.read(p)) @@ -1184,13 +1202,14 @@ EOF continue fi d=$f/.config/transmission-remote-gtk - s -u $u mkdir -p $d - s -u $u dd of=$d/config.json <