X-Git-Url: https://iankelling.org/git/?a=blobdiff_plain;f=rootsshsync;h=4767c7d54b76f7dd44d1077498cfd923968ce07d;hb=HEAD;hp=b4335dbcbbccfdb9164e44b4762dffcbba089268;hpb=7d9ec600a5ed9f88b85e02a27ee017b85721a6ac;p=distro-setup diff --git a/rootsshsync b/rootsshsync index b4335db..5395c44 100755 --- a/rootsshsync +++ b/rootsshsync @@ -1,5 +1,12 @@ #!/bin/bash -# Copyright (C) 2016 Ian Kelling +# I, Ian Kelling, follow the GNU license recommendations at +# https://www.gnu.org/licenses/license-recommendations.en.html. They +# recommend that small programs, < 300 lines, be licensed under the +# Apache License 2.0. This file contains or is part of one or more small +# programs. If a small program grows beyond 300 lines, I plan to switch +# its license to GPL. + +# Copyright 2024 Ian Kelling # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -13,6 +20,7 @@ # See the License for the specific language governing permissions and # limitations under the License. + set -eE -o pipefail trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR @@ -37,9 +45,11 @@ fi find $user_ssh_dir -xtype l -exec rm '{}' \; # -t times, so it won't rewrite the file every time, # -L resolve links -rsync --exclude=/h --exclude=/h.pub --exclude /config --exclude /confighome -rtL --delete $user_ssh_dir/ /root/.ssh +rsync --exclude=/h --exclude=/h.pub \ + --exclude=/hrsa --exclude=/hrsa.pub \ + --exclude /config --exclude /confighome -rtL --delete $user_ssh_dir/ /root/.ssh if [[ -e /q/root/h ]]; then - cp -a /q/root/h{,.pub} /root/.ssh + cp -a /q/root/{h,hrsa}{,.pub} /root/.ssh fi if [[ -e $user_ssh_dir/config ]]; then @@ -57,8 +67,10 @@ if [[ -e $user_ssh_dir/config ]]; then fi chown -R root:root /root/.ssh -# notably: installs hssh -/a/exe/install-my-scripts +# --update, -u skip files that are newer on the receiver +# I often push out a new hssh +rsync -tpu --chmod=755 --chown=root:root /a/bin/fai/fai/config/files/usr/local/bin/hssh/IANK /usr/local/bin/hssh + if [[ -e /a/opt/btrbk/ssh_filter_btrbk.sh ]]; then install /a/opt/btrbk/ssh_filter_btrbk.sh /usr/local/bin fi @@ -67,14 +79,21 @@ if [[ -e /etc/systemd/system/ssh-agent-root.service ]]; then systemctl enable --now ssh-agent-root fi -d=/etc/initramfs-tools -if [[ -e $d ]] && ! diff -q /root/.ssh/authorized_keys $d/root/.ssh/authorized_keys &>/dev/null; then - mkdir -p $d/root/.ssh /etc/dropbear-initramfs - chmod 700 $d/root $d/root/.ssh - cp -p /root/.ssh/authorized_keys $d/root/.ssh/authorized_keys - cp -p /root/.ssh/authorized_keys /etc/dropbear-initramfs - if [[ -e /root/.ssh/authorized_keys2 ]]; then - cat /root/.ssh/authorized_keys2 >>/etc/dropbear-initramfs - fi + +# note: i previously had $auth_dir/root/.ssh/authorized_keys +# but /usr/share/doc/dropbear-initramfs/README.initramfs +# says differently. not sure what is up. + +auth_dir=/etc/dropbear/initramfs/ +candidate=$(apt-cache policy dropbear-initramfs | awk '$1 == "Candidate:" { print $2 }' | head -n1 ||:) +if [[ $candidate ]] && dpkg --compare-versions "$candidate" lt 2020.81-4; then + auth_dir=/etc/dropbear-initramfs +fi +auth_file=$auth_dir/authorized_keys +mkdir -p $auth_dir +if [[ ! -e $auth_file ]] || ! diff -q /root/.ssh/authorized_keys $auth_file; then + cp -p /root/.ssh/authorized_keys $auth_file update-initramfs -u -k all fi + +rsync -tpur /p/c/subdir_files/.dsh /root