X-Git-Url: https://iankelling.org/git/?a=blobdiff_plain;f=fai%2Fconfig%2Fscripts%2FGRUB_PC%2F11-ian;h=e27e394e8ac3509032d1ab194fc8c35812ebee92;hb=d0b6a8cd4608fdffcf733f9180744819d8889be0;hp=24a10ae6f476dfba44a332f0c22f8aaac76cdd1a;hpb=146686eb0d97bab588a5912e1994835001e5b459;p=automated-distro-installer diff --git a/fai/config/scripts/GRUB_PC/11-ian b/fai/config/scripts/GRUB_PC/11-ian index 24a10ae..e27e394 100755 --- a/fai/config/scripts/GRUB_PC/11-ian +++ b/fai/config/scripts/GRUB_PC/11-ian @@ -1,14 +1,84 @@ #!/bin/bash -x set -eE -o pipefail -trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?"' ERR +trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR -$ROOTCMD adduser --disabled-password --gecos ian ian -$ROOTCMD usermod -p "$ROOTPW" ian +if [[ $EUID != 0 ]]; then + echo "$0: error: expected to be root." + exit 1 +fi -/var/lib/fai/config/distro-install-common/end +if ! type -t fcopy &>/dev/null; then + sudo apt-get -y install fai-client +fi -fcopy -r -m 1000,1000,700 -i /home/ian/.ssh +dir=/q/root/shadow +fai_shadow=$FAI/distro-install-common/shadow +if [[ ! -e $dir && -e $fai_shadow ]]; then + mkdir -p $dir + mount -o bind $fai_shadow $dir +fi +$FAI/distro-install-common/end + +if ifclass STABLE || ifclass LINODESTABLE; then + fcopy -M /etc/apt/preferences +fi + +if ifclass DEBIAN; then + fcopy -M /etc/apt/preferences.d/unstable +fi +fcopy -riM /etc/apt/sources.list.d +$ROOTCMD apt-get update + + + +# note: +# fcopy -i = ignore nonmatching class error, always return 0. + +# for lj, this will be empty and fail +fcopy -riM /home/ian/.ssh + +rm -f $FAI_ROOT/etc/apt/sources.list + +chroot $FAI_ROOT bash <<'EOF' +set -eE -o pipefail +mkdir -p /home/ian/.ssh +f=/root/.ssh/authorized_keys +if [[ -e $f ]]; then + cp $f /home/ian/.ssh +fi +chown -R 1000:1000 /home/ian/.ssh +chmod -R u=Xrw,og= /home/ian/.ssh +rm -rf /root/.ssh +cp -rL /home/ian/.ssh /root +chown -R root:root /root/.ssh +chmod 700 /root/.ssh + + +# default jessie groups + kvm, systemd-journal, adm +usermod -aG adm,cdrom,floppy,sudo,audio,dip,video,plugdev,netdev ian + +if getent group systemd-journal >/dev/null; then + usermod -aG systemd-journal ian + # makes the journal be saved to disk. + mkdir -p /var/log/journal + chmod 755 /var/log/journal +fi +# https://askubuntu.com/questions/33416/how-do-i-disable-the-boot-splash-screen-and-only-show-kernel-and-boot-text-inst +# it suggests not having plymouth-theme-ubuntu-text, but +# making it not installed then kills plymouth, then makes +# the system not boot. +sed -ri 's/(^ *GRUB_CMDLINE_LINUX.*)quiet splash/\1/' /etc/default/grub +# on xenial, no grub is displayed at all. fix that. +# found just by noticing this in the config file, and a +# warning about it in error.log +sed -i '/^ *GRUB_HIDDEN_TIMEOUT/d' /etc/default/grub +update-grub2 +EOF + + +# reading through the groups that ian is in but traci isn't, +for g in plugdev audio video cdrom; do + $ROOTCMD usermod -a -G $g traci +done -# the defaults in wheezy -$ROOTCMD usermod -aG cdrom,floppy,sudo,audio,dip,video,plugdev,netdev ian