-#!/bin/bash -l
+#!/bin/bash
# Copyright (C) 2016 Ian Kelling
#
# Licensed under the Apache License, Version 2.0 (the "License");
# set the scrollback to unlimited in case something goes wrong
+# send to registrar, glue records:
+# for iankelling.org:
+
+# ns1.iankelling.org 72.14.176.105
+# ns1.iankelling.org 2600:3c00::f03c:91ff:fe6d:baf8
+# ns2.iankelling.org 172.105.84.95
+# ns2.iankelling.org 2a01:7e01::f03c:91ff:feb5:baec
+
+# for zroe.org:
+
+# ns1.zroe.org 72.14.176.105
+# ns1.zroe.org 2600:3c00::f03c:91ff:fe6d:baf8
+# ns2.zroe.org 172.105.84.95
+# ns2.zroe.org 2a01:7e01::f03c:91ff:feb5:baec
+#
+
+
+
####### begin setup environment #######
### make ssh interactive shell run better. for when running line interactively line by line
-sudo bash -c 'source /a/c/.bashrc && source /a/exe/ssh-emacs-setup'
-
+sudo bash -c '/a/exe/ssh-emacs-setup'
##### setup error handling
interactive=true # set this to false to force set -x
set -x
fi
source /a/bin/errhandle/err
+
+err-cleanup() {
+ echo 1 >~/.local/distro-begin
+}
+
source /a/bin/distro-functions/src/package-manager-abstractions
### setup logging
-exec &> >(sudo tee -a /var/log/distro-begin)
echo "$0: $(date): starting now)"
set +x
source /a/bin/distro-functions/src/identify-distros
$interactive || set -x
-for f in kd x2 x3 frodo tp li lj demohost kw; do
+for f in kd x2 x3 frodo tp li l2 demohost kw; do
eval "$f() { [[ $HOSTNAME == $f ]]; }"
done
codename=$(debian-codename)
has_wayland() { has_monitor && [[ $codename == buster ]]; }
has_x() { has_monitor && [[ $codename != buster ]]; }
has_monitor() { ! linode ; }
-linode() { lj || li; }
+linode() { l2 || li; }
# linode actually has btrfs now, but we dont do anything with it.
has_btrfs() { ! linode; }
home_network() { ! linode && ! kw; }
# but it happened too late in the shutdown process.
sudo dd of=/etc/systemd/system/keyscripton.service <<'EOF'
[Unit]
-Description=Turn on automatic decryption of drives on boot
+Description=keyscripton
+# This is triggered by reboot and when keyscriptoff stops.
+
# tried using graphical.target, but it made my display manager restart before rebooting.
# generally, I don't think targets order shutdown like they do startup.
# So, I did systemd-analyze plot > something.svg, and picked a reliably started
WantedBy=keyscriptoff.service
EOF
sudo systemctl daemon-reload # needed if the file was already there
- sudo systemctl stop keyscripton.service
- # sudo systemctl start keyscripton.service
sudo systemctl enable keyscripton.service
sudo dd of=/etc/systemd/system/keyscriptoff.service <<'EOF'
[Unit]
-Description=Turn off automatic decryption of drives on boot
+Description=keyscriptoff
[Service]
Type=oneshot
pi rsync
- # from /usr/share/doc/dropbear-initramfs/README.initramfs.gz
- tmp=$(mktemp)
- while read -r m _; do /sbin/modinfo -F filename "$m"; done </proc/modules | \
- sed -nr "s@^/lib/modules/$(uname -r)/kernel/drivers/net(/.*)?/([^/]+)\.ko\$@\2@p" \
- | sudo dd of=$tmp
- if ! diff -q /etc/initramfs-tools/modules $tmp &>/dev/null; then
- sudo dd if=$tmp of=/etc/initramfs-tools/modules
- sudo /usr/sbin update-initramfs -u -k all
+ ## /usr/share/doc/dropbear-initramfs/README.initramfs.gz
+ ## claims we need to do this. but it works fine without it.
+ # tmp=$(mktemp)
+ # while read -r m _; do /sbin/modinfo -F filename "$m"; done </proc/modules | \
+ # sed -nr "s@^/lib/modules/$(uname -r)/kernel/drivers/net(/.*)?/([^/]+)\.ko\$@\2@p" \
+ # | sudo dd of=$tmp
+ # if ! diff -q /etc/initramfs-tools/modules $tmp &>/dev/null; then
+ # sudo dd if=$tmp of=/etc/initramfs-tools/modules
+ # sudo /usr/sbin/update-initramfs -u -k all
+ # fi
+ #
+ ## if we were creating an intall for a different machine needing different modules, we could include them all like this:
+ ## find /lib/modules/*/kernel/drivers/net /lib/modules/*/kernel/net -type f -name '*.ko' -printf "%f\n" | sed 's/.ko$//' | sort -u >/etc/initramfs-tools/modules
+
+ # this is here to cleanup the leftover from the comments above. remove it eventually.
+ if [[ -s /etc/initramfs-tools/modules ]]; then
+ sudo truncate -s0 /etc/initramfs-tools/modules
+ sudo /usr/sbin/update-initramfs -u -k all
fi
+
# initram auth keys get setup with rootsshsync
$script_dir/rootsshsync
# then for remote unlock, ssh and do this once per crypt disk:
echo $HOSTNAME > /etc/hostname
hostname -F /etc/hostname
fi
-sudo $sed -i '/^127\.0\.1\.1/d' /etc/hosts
-echo "127.0.1.1 $HOSTNAME.b8.nz $HOSTNAME" | sudo tee -a /etc/hosts
+# office vpn dhcp adds to /etc/resolv.conf search office.fsf.org which
+# makes that be #1 priority, which makes dnsmasq resolve that for
+# unqualified hosts first, which means we skip the hosts file. Ya, its
+# kinda dumb, but it is what it is. There is a dnsmasq config option to
+# override it too, but this seems simpler.
+sudo sed -i --follow-symlinks -f - /etc/hosts <<EOF
+\$a 127.0.1.1 $HOSTNAME.b8.nz $HOSTNAME.office.fsf.org $HOSTNAME
+/^127\.0\.1\.1/d
+EOF
##### exit first stage if running as root
#### setup bash for root
-for x in /a/c/{.bashrc,brc,.bash_profile,.profile,.inputrc,path_add_function}; do
+for x in /a/c/{.bashrc,brc,brc2,.bash_profile,.profile,.inputrc,path_add_function}; do
sudo -i <<EOF
PATH="/a/exe:$PATH"
lnf $x /root
done
###### do conflink
-# li needs the bind group before conflink
-if [[ $HOSTNAME == li ]]; then
- getent group bind &>/dev/null || sudo groupadd -r bind
+# linode needs bind group before conflink
+if linode; then
+ pi-nostart bind9
fi
# this needs to be before installing pacserve so we have gpg conf.
conflink
set +x
err-allow
source /etc/profile.d/environment.sh
+export BRC=t
# shellcheck source=./.bashrc
source ~/.bashrc
err-catch
######## fix evbug bug ######
-case $distro in
- trisquel|ubuntu)
- # noticed in flidas.
+case $(debian-codename-compat) in
+ xenial)
+ # noticed in flidas. dunno if it affects any others
#https://bugs.launchpad.net/ubuntu/+source/module-init-tools/+bug/240553
#https://wiki.debian.org/KernelModuleBlacklisting
#common advice when searching is to use /etc/modprobe.d/blacklist.conf,
sudo rmmod evbug ||: # might not be loaded yet
file=/etc/modprobe.d/evbug.conf
line="blacklist evbug"
- if ! grep -xFq "$line" $file; then
+ if [[ $(cat $file) != $line ]]; then
sudo dd of=$file 2>/dev/null <<<"$line"
sudo depmod -a
sudo update-initramfs -u
###### link files
# convenient to just do all file linking in one place
-s /a/exe/lnf -T /a/bin /b
-s /a/exe/lnf -T /nocow/t /t
+sudo /a/exe/lnf -T /a/bin /b
+sudo /a/exe/lnf -T /nocow/t /t
if has_p; then
lnf -T /p/News ~/News
fi
-s /a/exe/lnf /q/root/.editor-backups /q/root/.undo-tree-history \
- /a/opt /a/c/.emacs.d $HOME/mw_vars /k/backup /root
+sudo /a/exe/lnf /q/root/.editor-backups /q/root/.undo-tree-history \
+ /a/opt /a/c/.emacs.d $HOME/mw_vars /k/backup /root
/a/bin/ds/install-my-scripts # needed for rootsshsync cronjob
-s /a/exe/lnf /a/c/.vim /a/c/.vimrc /a/c/.gvimrc /root
+sudo /a/exe/lnf /a/c/.vim /a/c/.vimrc /a/c/.gvimrc /root
arch)
# pkgfile is like apt-cache
pi pkgfile
- s pkgfile --update
+ sudo pkgfile --update
;;
esac
##### make extra dirs
dirs=(/mnt/{1,2,3,4,5,6,7,8,9} /nocow/t)
-s mkdir -p "${dirs[@]}"
-s chown $USER:$USER "${dirs[@]}"
+sudo mkdir -p "${dirs[@]}"
+sudo chown $USER:$USER "${dirs[@]}"
###### setup /i
if home_network; then
/i/k /k none bind,noauto 0 0
EOF
if ! mountpoint /kr; then
- s mkdir -p /kr
- s chown $USER:user2 /kr
+ sudo mkdir -p /kr
+ sudo chown $USER:user2 /kr
fi
if [[ $HOSTNAME == frodo ]]; then
tu /etc/fstab <<'EOF'
frodo:/k /kr nfs noauto 0 0
EOF
fi
- s mkdir -p /q /i/{w,k}
+ sudo mkdir -p /q /i/{w,k}
for dir in /{i,w,k}; do
if mountpoint $dir; then continue; fi # already mounted
- s mkdir -p $dir
- s chown $USER:$USER $dir
+ sudo mkdir -p $dir
+ sudo chown $USER:$USER $dir
done
# not needed for all hosts, but rather just keep it uniform
- s mkdir -p /mnt/iroot
+ sudo mkdir -p /mnt/iroot
# debian auto mounting of multi-disk encrypted btrfs is busted. It is
# in jessie, and in stretch as of 11/26/2016 I have 4 disks in cryptab,
# based on 3 of those, it creates .device units for /dev/mapper/dev...
# have already been created and exist. todo: create a simple repro
# for this in a vm and report it upstream.
pi nfs-common
- s dd of=/root/imount <<'EOF'
+ sudo dd of=/root/imount <<'EOF'
#!/bin/bash
[[ $EUID == 0 ]] || exec sudo -E "${BASH_SOURCE[0]}" "$@"
set -eE -o pipefail
fi
done
EOF
- s chmod +x /root/imount
- s dd of=/etc/systemd/system/imount.service <<EOF
+ sudo chmod +x /root/imount
+ sudo dd of=/etc/systemd/system/imount.service <<EOF
[Unit]
Description=Mount /i and related mountpoints
Before=syncthing@$USER.service
if ! mountpoint $dir; then
subvol=/mnt/root/nocow
if [[ ! -e $subvol ]]; then
- s btrfs subvolume create $subvol
- s chown root:1000 $subvol
- s chattr +C $subvol
+ sudo btrfs subvolume create $subvol
+ sudo chown root:1000 $subvol
+ sudo chattr +C $subvol
fi
first_root_crypt=$(awk '$2 == "/" {print $1}' /etc/mtab)
tu /etc/fstab <<EOF
$first_root_crypt /nocow btrfs noatime,subvol=nocow 0 0
EOF
- s mkdir -p $dir
- s chown $USER:$USER $dir
- s mount $dir
+ sudo mkdir -p $dir
+ sudo chown $USER:$USER $dir
+ sudo mount $dir
fi
else
sudo mkdir -p $dir
#### ubuntu nicety
if isubuntu; then
# disable crash report annoying dialogs.
- s dd of=/etc/default/apport <<<'enabled=0'
+ sudo dd of=/etc/default/apport <<<'enabled=0'
fi
esac
fi
-if has_x; then
+if has_monitor; then
+
+ # sway not packaged for t9, not bothering to build it yet since
+ # i3 doesnt seem to tear and stutter on video anymore.
+ if [[ $codename == buster ]]; then
+ pi sway xwayland
+ fi
+
+
###### install X
pi i3
- if isarch; then
- # xorg-xmessage for displaying error messages.
- # optional dependency in arch, standard elsewhere.
- pi xorg-server xorg-xmessage xorg-xsetroot xorg-xinit
- fi
##### install xinput
case $(distro-name) in
trisquel|ubuntu|debian)
pi xinput
;;
- arch)
- pi xorg-xinput
- ;;
esac
- #### install redshift
- case $(distro-name) in
- trisquel|ubuntu|debian)
- # recommends gets us geoclue (for darkening automatically at night i assume),
- # which recommends modemmanager, which is annoying to fix for the model01 keyboard.
- pi --no-install-recommends gtk-redshift
- ;;&
- arch)
- pi redshift
- ;;&
- esac
+ # recommends gets us geoclue (for darkening automatically at night i assume),
+ # which recommends modemmanager, which is annoying to fix for the model01 keyboard.
+ pi --no-install-recommends gtk-redshift
##### setup X autostart
- if isarch; then
- # https://wiki.archlinux.org/index.php/Xinitrc
- for homedir in /home/*; do
- cp /etc/X11/xinit/xinitrc $homedir/.xinitrc
- # shellcheck disable=SC2016
- $sed -ri '/^ *twm\b/,$d' $homedir/.xinitrc
- tee -a $homedir/.xinitrc <<'EOF'
-/a/bin/desktop-20-autostart.sh
-xsetroot -cursor_name left_ptr
-exec xmonad
-EOF
- done
- else
- # todo, figure this out for arch if we ever try out gnome.
- # install for multiple display managers in case we use one
- dir=/etc/gdm3
- s mkdir -p $dir/PostLogin
- s command cp /a/bin/distro-setup/desktop-20-autostart.sh $dir/PostLogin/Default
- s mkdir /etc/lightdm/lightdm.conf.d
- s dd of=/etc/lightdm/lightdm.conf.d/12-iank.conf <<'EOF'
+ # todo, figure this out for arch if we ever try out gnome.
+ # install for multiple display managers in case we use one
+ dir=/etc/gdm3
+ sudo mkdir -p $dir/PostLogin
+ sudo cp /a/bin/distro-setup/desktop-20-autostart.sh $dir/PostLogin/Default
+ sudo mkdir -p /etc/lightdm/lightdm.conf.d
+ sudo dd of=/etc/lightdm/lightdm.conf.d/12-iank.conf <<'EOF'
[SeatDefaults]
session-setup-script=/a/bin/distro-setup/desktop-20-autostart.sh
EOF
- fi
-fi
-### install and configure wayland
-if has_wayland; then
- pi sway xwayland
# originally used xkbcomp, documented in input-setup.sh, this doesnt
# work under wayland, but its still useful for creating the config,
# then modifying the system files.
- s sed -i.orig '/key *<KPMU> *{/,/}/s/KP_Multiply/underscore/g' /usr/share/X11/xkb/symbols/keypad
-fi
+ sudo sed -i.orig '/key *<KPMU> *{/,/}/s/KP_Multiply/underscore/g' /usr/share/X11/xkb/symbols/keypad
-##### basic graphical packages
-if has_monitor; then
+ ##### basic graphical packages
pi konsole suckless-tools
fi
+
##### install emacs
if $emacs; then
if isarch; then
/a/exe/ssh-emacs-setup
fi
+
+echo 0 >~/.local/distro-begin
echo "$0: $(date): ending now"
+echo "exiting with status 0"
exit 0