+s mkdir -p /nocow/user
+s chown $USER:$USER /nocow/user
+pi anki
+
+
+####### begin transmission
+
+# adapted from /var/lib/dpkg/info/transmission-daemon.postinst
+# 450 seems likely to be unused. we need to specify one or else
+# it won't be stable across installs.
+if ! getent passwd debian-transmission > /dev/null; then
+ s groupadd -g 450 debian-transmission
+ s adduser --quiet \
+ --gid 450 \
+ --uid 450 \
+ --system \
+ --no-create-home \
+ --disabled-password \
+ --home /var/lib/transmission-daemon \
+ debian-transmission
+fi
+# We want group writable stuff from transmission.
+# However, after setting this, I learn that transmission sets it's
+# own umask based on it's settings file. Well, no harm leaving this
+# so it's set right from the beginning.
+s chfn debian-transmission -o umask=0002
+
+# note i had to do this, which is persistent:
+# cd /i/k
+# s chgrp debian-transmission torrents partial-torrents
+
+# syslog says things like
+# 'Failed to set receive buffer: requested 4194304, got 425984'
+# google suggets giving it even more than that
+tu /etc/sysctl.conf<<'EOF'
+net.core.rmem_max = 67108864
+net.core.wmem_max = 16777216
+EOF
+s sysctl -p
+
+# some reason it doesn\'t seem to start automatically anyways
+pi-nostart transmission-daemon
+# be extra sure its not started
+ser disable transmission-daemon
+ser stop transmission-daemon
+
+# the folder was moved here after an install around 02/2017.
+# it contains runtime data,
+# plus a simple symlink to the config file which it\'s
+# not worth separating out.
+# between comps, the uid can change
+f=/i/transmission-daemon
+s lnf -T $f /var/lib/transmission-daemon/.config/transmission-daemon
+if [[ -e $f ]]; then
+ s chown -R debian-transmission:debian-transmission $f
+fi
+for f in /i/k/partial-torrents /i/k/torrents; do
+ if [[ -e $f ]]; then
+ s chown -R debian-transmission:user2 $f
+ fi
+done
+s chown -R debian-transmission:debian-transmission /var/lib/transmission-daemon
+#
+# config file documented here, and it\'s the same config
+# for daemon vs client, so it\'s documented in the gui.
+# https://trac.transmissionbt.com/wiki/EditConfigFiles#Options
+#
+# I originaly setup rpc-whitelist, but after using
+# routing to a network namespace, it doesn\'t see the
+# real source address, so it\'s disabled.
+#
+# Changed the cache-size to 256 mb, reduces disk use.
+# It is a read & write cache.
+#
+s ruby <<'EOF'
+require 'json'
+p = '/etc/transmission-daemon/settings.json'
+File.write(p, JSON.pretty_generate(JSON.parse(File.read(p)).merge({
+'rpc-whitelist-enabled' => false,
+'rpc-authentication-required' => false,
+'incomplete-dir' => '/i/k/partial-torrents',
+'incomplete-dir-enabled' => true,
+'download-dir' => '/i/k/torrents',
+"speed-limit-up" => 800,
+"speed-limit-up-enabled" => true,
+"peer-port" => 61486,
+"cache-size-mb" => 256,
+"ratio-limit" => 5.0,
+"ratio-limit-enabled" => true,
+})) + "\n")
+EOF
+####### end transmission
+
+
+
+# trisquel 8 = openvpn, debian stretch = openvpn-client
+vpn_ser=openvpn-client
+if [[ ! -e /lib/systemd/system/openvpn-client@.service ]]; then
+ vpn_ser=openvpn
+fi
+
+sd /etc/systemd/system/transmission-daemon-nn.service <<EOF
+[Unit]
+Description=Transmission BitTorrent Daemon netns
+After=network.target
+Requires=${vpn_ser}-nn@client.service
+After=${vpn_ser}-nn@client.service
+JoinsNamespaceOf=${vpn_ser}-nn@client.service
+
+[Service]
+#User=debian-transmission
+# notify type doesn't work with sudo
+#Type=notify
+ExecStart=/usr/bin/nsenter --mount=/root/mount_namespaces/client sudo -u debian-transmission /usr/bin/transmission-daemon -f --log-error
+ExecReload=/bin/kill -s HUP \$MAINPID
+PrivateNetwork=true
+Nice=19
+
+[Install]
+WantedBy=multi-user.target
+EOF
+ser daemon-reload
+
+if [[ $HOSTNAME == frodo ]]; then
+ m sgo transmission-daemon-nn
+fi
+
+
+######### begin transmission client setup ######
+
+if [[ -e /p/transmission-rpc-pass ]]; then
+ # arch had a default config,
+ # debian had nothing until you start it.
+ # With a little trial an error, here is a minimal config
+ # taken from the generated one, plus changes that the
+ # settings ui does, without a bunch of ui crap settings.
+ #
+ # only settings I set were
+ # hostname
+ # auto-connect
+ # password
+
+ # the password is randomly generated on first run, i copied it out
+ # so it could be used by other hosts.
+ s ruby <<'EOF'
+require 'json'
+p = '/etc/transmission-daemon/settings.json'
+s = JSON.parse(File.read(p))
+s["rpc-password"] = File.read("/p/transmission-rpc-pass").chomp
+# default is 0022 (18 in decimal)
+s["umask"] = 2
+File.write p, JSON.pretty_generate(s)
+EOF
+
+ rpc_pass=$(</p/transmission-rpc-pass)
+ for f in /home/*; do
+ u=${f##*/}
+ uid=$(id -u $u 2>/dev/null) || continue
+ if [[ ! $uid -ge 1000 ]]; then
+ continue
+ fi
+ d=$f/.config/transmission-remote-gtk
+ s -u $u mkdir -p $d
+ s -u $u dd of=$d/config.json <<EOF
+{
+ "profiles" : [
+ {
+ "profile-name" : "Default",
+ "hostname" : "transmission.b8.nz",
+ "rpc-url-path" : "/transmission/rpc",
+ "username" : "",
+ "password" : "$rpc_pass",
+ "auto-connect" : true,
+ "ssl" : false,
+ "timeout" : 40,
+ "retries" : 3,
+ "update-active-only" : false,
+ "activeonly-fullsync-enabled" : false,
+ "activeonly-fullsync-every" : 2,
+ "update-interval" : 3,
+ "min-update-interval" : 3,
+ "session-update-interval" : 60,
+ "exec-commands" : [
+ ],
+ "destinations" : [
+ ]
+ }
+ ],
+ "profile-id" : 0,
+ "add-options-dialog" : false
+}
+EOF
+ done
+fi
+######### end transmission client setup ######
+
+
+### printer setup
+pi cups hplip
+s gpasswd -a $USER lpadmin # based on ubuntu wiki
+# goto http://127.0.0.1:631
+# administration tab, add new printer button.
+# In debian, I could use hte recommended driver,
+# in arch, I had to pick out the 6L driver.
+
+
+# allow user to run vms, from debian handbook
+for x in iank user2; do s usermod -a -G libvirt,kvm $x; done
+# bridge networking as user fails. google lead here, but it doesn\'t work:
+# oh well, I give up.
+# http://wiki.qemu.org/Features-Done/HelperNetworking
+# s mkdir /etc/qemu
+# f=/etc/qemu/bridge.conf
+# sd $f <<'EOF'
+# allow br0
+# EOF
+# #s chown root:qemu $f # debian has somethig like qemu-libvirt. equivalent?
+# s chmod 640 $f
+
+# general known for debian/ubuntu, not for fedora
+
+m /a/bin/buildscripts/go
+m /a/bin/buildscripts/rust
+m /a/bin/buildscripts/misc
+
+pi-nostart virtinst virt-manager
+
+
+
+pi --no-install-recommends kdeconnect
+### kdeconnect for gnome. started in /a/bin/distro-setup/desktop-20-autostart.sh
+### but gnome + xmonad not working in flidas, so i disabled it
+# pi libgtk-3-dev python3-requests-oauthlib valac cmake python-nautilus libappindicator3-dev
+# cd /a/opt/indicator-kdeconnect
+# mkdir -p build
+# cd build
+# cmake .. -DCMAKE_INSTALL_PREFIX=/usr
+# make
+# sudo make install
+# # we can start it manually with /usr/lib/x86_64-linux-gnu/libexec/kdeconnectd
+# # it seems, according to
+# # /etc/xdg/autostart/kdeconnectd.desktop
+# # I'm not seeing the icon, but the clipboard replication is working
+
+
+### model 01 arduino support ###
+# https://github.com/keyboardio/Kaleidoscope/wiki/Install-Arduino-support-on-Linux
+# also built latest arduino in /a/opt/Arduino, (just cd build; ant build; ant run )
+# set arduino var in bashrc,
+# have system config file setup too.
+s adduser $USER dialout
+
+# this is for the mail command too. update-alternatives is kind of misleading
+# since at least it's main commands pretend mail does not exist.
+# bsd's mail got pulled in on some dumb dependency, i dunno how.
+s update-alternatives --set mailx /usr/bin/mail.mailutils
+