X-Git-Url: https://iankelling.org/git/?p=distro-setup;a=blobdiff_plain;f=distro-end;h=317852291a0d21fb83764c2d7225f0c5a0f5dd66;hp=2c638206b74f85476ce892899b7c0b49e377019c;hb=79b274fcd8bfa556133ab13270e84b40aebe8468;hpb=f2f92addec853ee989c3bb30ebf69fc49a649062 diff --git a/distro-end b/distro-end index 2c63820..3178522 100755 --- a/distro-end +++ b/distro-end @@ -1,384 +1,1194 @@ #!/bin/bash -l -# Copyright (C) 2016 Ian Kelling +# Copyright (C) 2019 Ian Kelling +# SPDX-License-Identifier: AGPL-3.0-or-later -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at +### setup +source /a/bin/errhandle/err +src="$(readlink -f -- "${BASH_SOURCE[0]}")"; src=${src%/*} # directory of this file -# http://www.apache.org/licenses/LICENSE-2.0 - -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. +if [[ $EUID == 0 ]]; then + echo "$0: error: run as regular user" >&2 + exit 1 +fi -errcatch +_errcatch_cleanup() { + echo 1 >~/.local/distro-end +} -set -x +# shellcheck source=./pkgs +source $src/pkgs exec &> >(sudo tee -a /var/log/distro-end) echo "$0: $(date): starting now)" - -src="${BASH_SOURCE%/*}" - +# see example of usage to understand. end_msg() { - = local y - IFS= read -r -d '' y ||: - end_msg_var+="$y" + local y + IFS= read -r -d '' y ||: + end_msg_var+="$y" } - -spa() { # simple package add - simple_packages+=($@) +end() { + e "$end_msg_var" + echo 0 >~/.local/distro-end + if $pending_reboot; then + echo "$0: pending reboot and then finished. doing it now." + s reboot now + else + echo "$0: $(date): ending now)" + fi + exit 0 } - +pre="${0##*/}:" +s() { + printf "s %s\n" "$*" + SUDOD="$PWD" sudo -i "$@"; +} +sd() { + s dd of="$1" 2>/dev/null +} +m() { printf "$pre %s\n" "$*"; "$@"; } +e() { printf "$pre %s\n" "$*"; } +err() { echo "[$(date +'%Y-%m-%d %H:%M:%S%z')]: $0: $*" >&2; } distro=$(distro-name) - +codename=$(debian-codename) +codename_compat=$(debian-codename-compat) pending_reboot=false - +sed="sed --follow-symlinks" # template case $distro in esac +#### initial packages pup +if isdeb; then + pi aptitude +fi -simple_packages=( - htop - mailutils - nmon - ruby - ruby-rest-client - tree - vim -) +# avoid prompts +s debconf-set-selections < +# AllowOverride None +# AuthType basic +# AuthName "Authentication Required" +# # setup one time, with root:www-data, 640 +# AuthUserFile "/etc/prometheus-htpasswd" +# Require valid-user +# +# EOF +# fi + + +######### begin flidas pinned packages ###### +case $(debian-codename) in + # needed for debootstrap scripts for fai since fai requires debian + flidas) + curl http://archive.ubuntu.com/ubuntu/project/ubuntu-archive-keyring.gpg | s apt-key add - + sd /etc/apt/preferences.d/flidas-xenial </dev/null </dev/null; then + s apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 + sd /etc/apt/preferences.d/flidas-bionic <$t <$t <$t < + Options +FollowSymLinks +Multiviews +Indexes + AllowOverride None + AuthType basic + AuthName "Authentication Required" + # setup one time, with root:www-data, 640 + AuthUserFile "/etc/caldav-htpasswd" + Require valid-user + +EOF + # nginx version of above would be: + # auth_basic "Not currently available"; + # auth_basic_user_file /etc/nginx/caldav/htpasswd; + + + + ###### begin znc setup ##### + pi znc + + # https://wiki.znc.in/FAQ seems to imply that znc doesn\'t need restart after cert change. + # to get into the web interface, + # then use non-main browser or else it doebsn't allow it based on ocsp stapling from my main site. + # https://iankelling.org:12533/ + sudo -i <<'EOF' +export RENEWED_LINEAGE=/etc/letsencrypt/live/iankelling.org +/a/bin/distro-setup/certbot-renew-hook +EOF + + # znc config generated by doing + # znc --makeconf + # selected port is also used in erc config + # comma separated channel list worked. + # while figuring things out, running znc -D for debug in foreground. + # to exit and save config: + # /msg *status shutdown + # configed auth on freenode by following + # https://wiki.znc.in/Sasl: + # /msg *sasl RequireAuth yes + # /msg *sasl Mechanism PLAIN + # /msg *sasl Set ident_name password + # created the system service after, and had to do + # mv /home/iank/.znc/* /var/lib/znc + # sed -i 's,/home/iank/.znc/,/var/lib/znc,' /var/lib/znc/config/znc.conf + # and made a copy of the config files into /p/c + # /msg *status LoadMod --type=global log -sanitize + # todo: in config file AllowWeb = true should be false. better security if that is off unless we need it. + # /msg *status LoadMod --type=network perform + # /msg *perform add PRIVMSG ChanServ :invite #fsf-office + # /msg *perform add JOIN #fsf-office + # + # i set Buffer = 500 + # also ran /znc LoadMod clearbufferonmsg + # it would be nice if erc supported erc query buffers by doing + # /msg *status clearbuffer /dev/null <<'EOF' +[Unit] +Description=ZNC, an advanced IRC bouncer +After=network-online.target + +[Service] +ExecStart=/usr/bin/znc -f --datadir=/var/lib/znc +User=znc + +[Install] +WantedBy=multi-user.target +EOF + ser daemon-reload + # avoid restarting if possible, reconnecting to irc is annoying. + if [[ $(ser is-active znc) != active ]]; then + m sgo znc + fi + ###### stop znc setup ##### + + end + ;; esac +###### end website setup ########### end section including li/lj ############### +#### desktop stuff +case $codename_compat in + xenial) + # mate-indicator-applet and beyond are msc things I noticed diffing a + # standard install with mine. + pi xorg lightdm mate-desktop-environment mate-desktop-environment-extras mate-indicator-applet anacron + ;; + stretch) + pi task-mate-desktop + ;; + buster) + # mate doesnt have wayland support yet + pi task-gnome-desktop + ;; +esac + + + + +# TODO: some of the X programs can be removed from pall when using wayland + +# depends gcc is a way to install suggests. this is apparently the only +# way to install suggests even if the main package is already +# installed. reinstall doesn't work, uninstalling can cause removing +# dependent packages. +pi ${pall[@]} $(apt-cache search ruby[.0-9]+-doc| awk '{print $1}') $(apt-cache depends gcc|grep -i suggests:| awk '{print $2}') $($src/distro-pkgs) + + +m sgo fsf-vpn-dns-cleanup + + +# website is dead june 14 2019. back in october, but meh +s rm -fv /etc/apt/sources.list.d/iridium-browser.list +# case $distro in +# debian) +# pi chromium ;; +# trisquel|ubuntu) +# wget -qO - https://downloads.iridiumbrowser.de/ubuntu/iridium-release-sign-01.pub|sudo apt-key add - +# t=$(mktemp) +# cat >$t < /dev/null; then + s groupadd -g 450 debian-transmission + s adduser --quiet \ + --gid 450 \ + --uid 450 \ + --system \ + --no-create-home \ + --disabled-password \ + --home /var/lib/transmission-daemon \ + debian-transmission +fi +# We want group writable stuff from transmission. +# However, after setting this, I learn that transmission sets it's +# own umask based on it's settings file. Well, no harm leaving this +# so it's set right from the beginning. +s chfn debian-transmission -o umask=0002 + +# note i had to do this, which is persistent: +# cd /i/k +# s chgrp debian-transmission torrents partial-torrents + +# syslog says things like +# 'Failed to set receive buffer: requested 4194304, got 425984' +# google suggets giving it even more than that +tu /etc/sysctl.conf<<'EOF' net.core.rmem_max = 67108864 net.core.wmem_max = 16777216 EOF - s sysctl -p - - # some reason it doesn't seem to start automatically anyways - pi-nostart transmission-daemon - # config file documented here, and it's the same config - # for daemon vs client, so it's documented in the gui. - # https://trac.transmissionbt.com/wiki/EditConfigFiles#Options - s ruby <<'EOF' +s sysctl -p + +# some reason it doesn\'t seem to start automatically anyways +pi-nostart transmission-daemon +# be extra sure its not started +ser disable transmission-daemon +ser stop transmission-daemon + +# the folder was moved here after an install around 02/2017. +# it contains runtime data, +# plus a simple symlink to the config file which it\'s +# not worth separating out. +# between comps, the uid can change +f=/i/transmission-daemon +s lnf -T $f /var/lib/transmission-daemon/.config/transmission-daemon +if [[ -e $f ]]; then + s chown -R debian-transmission:debian-transmission $f +fi +for f in /i/k/partial-torrents /i/k/torrents; do + if [[ -e $f ]]; then + s chown -R debian-transmission:user2 $f + fi +done +s chown -R debian-transmission:debian-transmission /var/lib/transmission-daemon +# +# config file documented here, and it\'s the same config +# for daemon vs client, so it\'s documented in the gui. +# https://trac.transmissionbt.com/wiki/EditConfigFiles#Options +# +# I originaly setup rpc-whitelist, but after using +# routing to a network namespace, it doesn\'t see the +# real source address, so it\'s disabled. +# +# Changed the cache-size to 256 mb, reduces disk use. +# It is a read & write cache. +# +s ruby <<'EOF' require 'json' p = '/etc/transmission-daemon/settings.json' File.write(p, JSON.pretty_generate(JSON.parse(File.read(p)).merge({ -'rpc-whitelist' => '127.0.0.1,192.168.1.*', +'rpc-whitelist-enabled' => false, 'rpc-authentication-required' => false, 'incomplete-dir' => '/i/k/partial-torrents', +'incomplete-dir-enabled' => true, 'download-dir' => '/i/k/torrents', -"speed-limit-up" => 700, +"speed-limit-up" => 800, "speed-limit-up-enabled" => true, -"ratio-limit" => 1.4000, +"peer-port" => 61486, +"cache-size-mb" => 256, +"ratio-limit" => 5.0, "ratio-limit-enabled" => true, })) + "\n") EOF - sgo transmission-daemon - ;; - arch) - # todo, setup it's config file & daemon - pi transmission-cli - ;; - esac +####### end transmission + + + +# trisquel 8 = openvpn, debian stretch = openvpn-client +vpn_ser=openvpn-client +if [[ ! -e /lib/systemd/system/openvpn-client@.service ]]; then + vpn_ser=openvpn fi -# adapted from /var/lib/dpkg/info/transmission-daemon.postinst -if ! getent passwd debian-transmission > /dev/null; then - case $distro in - arch) - s useradd \ - --system \ - --create-home \ - --home-dir /var/lib/transmission-daemon \ - --shell /bin/false \ - debian-transmission - ;; - *) - s adduser --quiet \ - --system \ - --group \ - --no-create-home \ - --disabled-password \ - --home /var/lib/transmission-daemon \ - debian-transmission - ;; - esac +sd /etc/systemd/system/transmission-daemon-nn.service </dev/null) || continue + if [[ ! $uid -ge 1000 ]]; then + continue + fi + d=$f/.config/transmission-remote-gtk s -u $u mkdir -p $d - s -u $u dd of=$d/config.json <<'EOF' + s -u $u dd of=$d/config.json </dev/null; then - s apt-get -fy install - else - exit 1 - fi - ;; -esac -;; -arch) - pi google-chrome - ;; -esac -;; -esac - -# printer -case $distro in - arch) - pi cups ghostscript gsfonts # from arch wiki cups page - pi hplip # from google - s gpasswd -a $USER sys # from arch wiki - sgo org.cups.cupsd.service - # goto http://127.0.0.1:631 - # administration tab, add new printer button. - # In debian, I could use hte recommended driver, - # in arch, I had to pick out the 6L driver. - ;; - debian|ubuntu) - spa hplip - ;; - # other distros unknown -esac - - -case $distro in - ubuntu|debian) pi --no-install-recommends mairix notmuch ;; - fedora|arch) spa mairix notmuch ;; -esac -case $distro in - arch) spa nfs-utils ;; - ubuntu|debian) spa nfs-client ;; -esac -case $distro in - ubuntu|debian) spa par2 ;; - arch|fedora) spa par2cmdline ;; -esac - -# needed for my tex resume -case $distro in - ubuntu|debian) spa texlive-full ;; - arch) spa texlive-most ;; - # fedora unknown -esac - -case $distro in - ubuntu) - # flash, unrar, codecs, ms fonts. - # This has a manual prompt. - spa ubuntu-restricted-extras - ;; - fedora) - pi yum-utils - # rpm fusion recommended codecs - s su -c "yum localinstall -y --nogpgcheck http://download1.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm http://download1.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm" - pi gstreamer-plugins-ugly gstreamer-plugins-bad gstreamer-ffmpeg\ - xine-lib-extras-freeworld - ;; -esac - -case $distro in - # optional dep for firefox for h.264 video - arch) spa gst-libav ;; - # other distros, probably come by default -esac - -case $distro in - fedora|ubuntu|debian) spa gnupg-agent ;; - arch) : ;; -esac - - -case $distro in - fedora) spa pinentry-gtk ;; - *) : ;; # comes default or with other packages -esac - -case $distro in - arch) spa firefox pulseaudio;; - *) : ;; # comes default or with other packages -esac + done +fi +######### end transmission client setup ###### -case $distro in - arch) spa ttf-dejavu;; - debian|ubuntu) spa fonts-dejavu ;; - # others unknown -esac +### printer setup +pi cups hplip +s gpasswd -a $USER lpadmin # based on ubuntu wiki +# goto http://127.0.0.1:631 +# administration tab, add new printer button. +# In debian, I could use hte recommended driver, +# in arch, I had to pick out the 6L driver. -case $distro in - arch) spa xorg-xev;; - debian|ubuntu) spa x11-utils ;; - # others unknown -esac - -case $distro in - arch) pi virt-install;;& - debian|ubuntu) pi virtinst ;;& - *) pi virt-manager ;; # creates the libvirt group in debian at least - # others unknown -esac # allow user to run vms, from debian handbook -for x in ian traci; do s usermod -a -G libvirt,kvm $x; done -# bridge networking as user fails. google lead here, but it doesn't work: +for x in iank user2; do s usermod -a -G libvirt,kvm $x; done +# bridge networking as user fails. google lead here, but it doesn\'t work: # oh well, I give up. # http://wiki.qemu.org/Features-Done/HelperNetworking # s mkdir /etc/qemu # f=/etc/qemu/bridge.conf -# s dd of=$f <<'EOF' +# sd $f <<'EOF' # allow br0 # EOF # #s chown root:qemu $f # debian has somethig like qemu-libvirt. equivalent? # s chmod 640 $f - -case $distro in - arch) spa cdrkit;; - debian|ubuntu) spa genisoimage;; - # others unknown -esac - -case $distro in - arch) spa spice-gtk3 ;; - debian|ubuntu) spa spice-client-gtk;; - # others unknown -esac - # general known for debian/ubuntu, not for fedora -case $distro in - arch) - # cdrkit for cloud-init isos - # dnsmasq & ebtables for nat networking in libvirt - # qemu for qemu-img, bind-tools for dig - # dmidecode just because syslog complains - pi unzip xorg-xmodmap dmidecode ebtables\ - bridge-utils dnsmasq qemu bind-tools - # otherwise we get error about accessing kvm module. - # seems like there might be a better way, but google was a bit vague. - s sed -ri --follow-symlinks '/^ *user *=/d' /etc/libvirt/qemu.conf - echo 'user = "root"' | s tee -a /etc/libvirt/qemu.conf - # https://bbs.archlinux.org/viewtopic.php?id=206206 - # # this should prolly go in the wiki - sgo virtlogd.socket - # guessing this is not needed - #sgo virtlogd.service - sgo libvirtd - - ;; -esac -case $distro in - arch) pi virtviewer ;; - *) : ;; # other distros have it as a dependency afaik. -esac +m /a/bin/buildscripts/go +m /a/bin/buildscripts/rust +m /a/bin/buildscripts/misc +pi-nostart virtinst virt-manager -case $distro in - fedora) cabal install shellcheck ;; - *) spa shellcheck ;; - # unknown for older ubuntu -esac +pi --no-install-recommends kdeconnect +### kdeconnect for gnome. started in /a/bin/distro-setup/desktop-20-autostart.sh +### but gnome + xmonad not working in flidas, so i disabled it +# pi libgtk-3-dev python3-requests-oauthlib valac cmake python-nautilus libappindicator3-dev +# cd /a/opt/indicator-kdeconnect +# mkdir -p build +# cd build +# cmake .. -DCMAKE_INSTALL_PREFIX=/usr +# make +# sudo make install +# # we can start it manually with /usr/lib/x86_64-linux-gnu/libexec/kdeconnectd +# # it seems, according to +# # /etc/xdg/autostart/kdeconnectd.desktop +# # I'm not seeing the icon, but the clipboard replication is working -case $distro in - arch|debian|ubuntu) spa pumpa ;; - # others unknown. do have a buildscript: - # /a/bin/buildscripts/pumpa ;; -esac +### model 01 arduino support ### +# https://github.com/keyboardio/Kaleidoscope/wiki/Install-Arduino-support-on-Linux +# also built latest arduino in /a/opt/Arduino, (just cd build; ant build; ant run ) +# set arduino var in bashrc, +# have system config file setup too. +s adduser $USER dialout -case $distro in - debian|ubuntu) spa android-tools-adb/unstable ;; - arch) spa android-tools ;; - # other distros unknown -esac - -case $distro in - debian) - if [[ `debian-archive` == testing ]]; then - # has no unstable dependencies - spa bitcoin-qt/unstable - fi - ;; - # other distros unknown -esac - - -# proprietary flash. going without for now -# case $distro in -# debian) -# pi flashplugin-nonfree -# esac - - - -case $distro in - fedora) - cd $(mktemp -d) - wget http://tamacom.com/global/global-6.3.2.tar.gz - ex global* - cd global-6.3.2 - # based on https://github.com/leoliu/ggtags - ./configure --with-exuberant-ctags=/usr/bin/ctags - make - s make install - s pip install pygments - ;; - *) - pi global - ;;& - arch) - pi python2-pygments - ;; - debian|ubuntu) - pi python-pygments - ;; -esac - - -case $distro in - debian) - pi task-cinnamon-desktop - # in settings, change scrolling to two-finger, - # because the default edge scroll doesn\'t work. - pu transmission-gtk - ;; - # others unknown -esac - -case $distro in - arch) spa apg ;; - - # already in debian jessie -esac - - - - -# note this failed running at the beginning of this file, -# because no systemd user instance was running. -# Doing systemd --user resulted in -# Trying to run as user instance, but $XDG_RUNTIME_DIR is not set - -if isdebian-testing; then - # as of 7/2016, has no unstable deps, and is not in testing anymore. - pi synergy/unstable -else - pi synergy -fi - -case $distro in - # ubuntu unknown. probably the same as debian, just check if the - # init scripts come with the package. - debian) - # copied from arch, but moved to etc - s dd of=/etc/systemd/user/synergys.service <<'EOF' -[Unit] -Description=Synergy Server Daemon -After=network.target - -[Service] -User=%i -ExecStart=/usr/bin/synergys --no-daemon --config /etc/synergy.conf -Restart=on-failure - -[Install] -WantedBy=multi-user.target -EOF - s dd of=/etc/systemd/user/synergys.socket <<'EOF' -[Unit] -Conflicts=synergys@.service - -[Socket] -ListenStream=24800 -Accept=false - -[Install] -WantedBy=sockets.target -EOF - systemctl --user daemon-reload - ;;& - *) - # taken from arch wiki. - s dd of=/etc/systemd/system/synergyc@.service <<'EOF' -[Unit] -Description=Synergy Client -After=network.target - -[Service] -User=%i -ExecStart=/usr/bin/synergyc --no-daemon frodo -Restart=on-failure -# per man systemd.unit, StartLimitInterval, by default we -# restart more than 5 times in 10 seconds. -# And this param defaults too 200 miliseconds. -RestartSec=3s - -[Install] -WantedBy=multi-user.target -EOF - s systemctl daemon-reload - case $HOSTNAME in - x2|treetowl) - ser enable synergyc@ian - ser start synergyc@ian ||: # X might not be running yet - ;; - frodo) - systemctl --user start synergys ||: - systemctl --user enable synergys - ;; - esac - ;; -esac - +# this is for the mail command too. update-alternatives is kind of misleading +# since at least it's main commands pretend mail does not exist. +# bsd's mail got pulled in on some dumb dependency, i dunno how. +s update-alternatives --set mailx /usr/bin/mail.mailutils ######### end misc packages ######### -# packages I once used before and liked, but don't want installed now for +# packages I once used before and liked, but don\'t want installed now for # various reasons: # python-sqlite is used for offlineimap # lxappearance python-sqlite dolphin paman dconf-editor @@ -781,7 +1298,7 @@ pi smartmontools # short test daily 2-3am, extended tests Saturdays between 3-4am: sched="-s (S/../.././02|L/../../6/03)" s sed -i --follow-symlinks "s#^[[:space:]]*DEVICESCAN.*#\ -DEVICESCAN -a -o on -S on -n standby,q $sched\ +DEVICESCAN -a -o on -S on -n standby,q $sched \ -m ian@iankelling.org -M exec /usr/local/bin/smart-notify#" /etc/smartd.conf # in the default configuration of at least ubuntu 14.04, resolvconf is @@ -800,316 +1317,128 @@ DEVICESCAN -a -o on -S on -n standby,q $sched\ ########### misc stuff - -if ! sudo test -e /etc/openvpn/client.key; then - /a/bin/vpn-setup/vpn-mk-client-cert +# make networkmanager use resolvconf instead of its own dnsmasq which +# conflicts with the normal dnsmasq package. +f=/etc/NetworkManager/NetworkManager.conf +m=$(md5sum $f) +s sed -ri '/ *\[main\]/,/^ *\[[^]]+\]/{/^\s*dns[[:space:]=]/d}' $f +if [[ $m != $(md5sum $f) ]]; then + srestart NetworkManager fi +# make my /etc/fonts/conf.d/ get used. +# I have a new sans-serif font there because the default one +# displays l and I as the same char, grrrrr. +s fc-cache -case $distro in - debian|ubuntu) - case `debian-archive` in - stable) - s dd of=/etc/apt/preferences.d/unison-gtk <<'EOF' -Explanation: Allow unison-gtk to be upgraded -Package: unison-gtk -Pin: release a=unstable -Pin-Priority: 500 -EOF - # dont think using testing is needed since I figured out how to - # deal with mismatching unison compilers, but I dont - # see any reason to revert it, since it only installs - # a single package which is primarily a single binary - ;; - esac - pi unison/testing - pi unison-gtk/testing # after to make it the default unison - ;; - arch) - pi unison gtk2 - ;; -esac +m /a/bin/distro-setup/mymimes -case $distro in - arch) - # default is alsa, doesn\'t work with with pianobar - s dd of=/etc/libao.conf <<'EOF' -default_driver=pulse -EOF - ;; -esac - -# not using it atm, and for jessie, it depends on a higher version of btrfs-tools -# case $distro in -# arch|debian|ubuntu) pi btrbk ;; -# # others unknown -# esac - -if [[ $HOSTNAME == treetowl ]] && [[ `debian-archive` != testing ]]; then - # fail2 ban is broken, with a workaround, per - # https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770171 - # ill wait a while to see if it gets fixed - pi fail2ban - sgo fail2ban -fi +m sgo dynamicipupdate +# stop autopoping windows when i plug in an android phone. +# dbus-launch makes this work within an ssh connection, otherwise you get this message, +# with still 0 exit code. +# dconf-WARNING **: failed to commit changes to dconf: Cannot autolaunch D-Bus without X11 $DISPLAY +m dbus-launch gsettings set org.gnome.desktop.media-handling automount-open false -case $distro in - debian|ubuntu) s gpasswd -a ian adm ;; #needed for reading logs -esac - -# tor -case $distro in - # based on - # https://www.torproject.org/docs/rpms.html.en - # https://www.torproject.org/docs/debian.html.en - # todo: figure out if the running service needs to be restarted upon updates - - - # todo on fedora: setup non-dev packages - fedora) - s dd of=/etc/yum.repos.d/torproject.repo <<'EOF' -[tor] -name=Tor experimental repo -enabled=1 -baseurl=http://deb.torproject.org/torproject.org/rpm/tor-testing/fc/20/$basearch/ -gpgcheck=1 -gpgkey=http://deb.torproject.org/torproject.org/rpm/RPM-GPG-KEY-torproject.org.asc - -[tor-source] -name=Tor experimental source repo -enabled=1 -autorefresh=0 -baseurl=http://deb.torproject.org/torproject.org/rpm/tor-testing/fc/20/SRPMS -gpgcheck=1 -gpgkey=http://deb.torproject.org/torproject.org/rpm/RPM-GPG-KEY-torproject.org.asc +# on grub upgrade, we get prompts unless we do this +devs=() +for dev in $(s btrfs fil show /boot | sed -nr 's#.*path\s+(\S+)$#\1#p'); do + devs+=("$(devbyid $dev),") +done +devs[-1]=${devs[-1]%,} # jonied by commas +s debconf-set-selections </dev/null; then +# cd $(mktemp -d) +# wget https://git.savannah.gnu.org/cgit/guix.git/plain/etc/guix-install.sh +# # added some stuff to envonment.sh for profile based on +# # manual instructions +# # wget https://sv.gnu.org/people/viewgpg.php?user_id=15145 -qO - | gpg --import - +# # echo is to get past prompt +# yes | sudo -E HOME=$HOME bash guix-install.sh || [[ $? == 141 ]] +# guix install glibc-utf8-locales +# guix package --install guile +# fi -case $distro in - debian|ubuntu) - pi libosinfo-bin; - ;; -esac -# distro may not know about win 10 yet. -variant=win7 -if ! virt-install --os-variant list &>/dev/null; then # we are using a newer virt-install - for v in 10 8.1 8; do - if osinfo-query os | gr "^\s*win${v/./\\.}\s" &>/dev/null; then - variant=win$v - break - fi - done -fi -if ! s virsh list --all --name | grep -xF win10 &>/dev/null; then - - # created account with - # win10vmian@outlook.com, and easy to remember password - # win 10 virtio, makes disk way way way faster - # wget https://fedorapeople.org/groups/virt/virtio-win/direct-downloads/latest-virtio/virtio-win.iso - # https://wiki.archlinux.org/index.php/QEMU#Change_Existing_Windows_VM_to_use_virtio - # for installing virtio after initial install instead of with initial iso: - # qemu-img create -f qcow2 fake.qcow2 1G - # --disk=/a/images/virtio-win.iso,device=cdrom \ - # --disk=/a/images/fake.qcow2,bus=virtio - # Also, - # went to device manager, saw 2 pci devices with yellow !, - # did search for drivers, pick cdrom location, done. - # - # from http://www.tenforums.com/tutorials/4189-fast-startup-turn-off-windows-10-a.html. - # google said there was a control panel option for it, but - # that turned out to be a lie. - # Put this in a .bat file and run as administrator to turn off - # hyberboot which fucks things up. - # REG ADD "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power" /V HiberbootEnabled /T REG_dWORD /D 0 /F - # power settings, turn off display: never - # run "control userpasswords2", turn on automatic login. - # note: when changing devices, I just undefine, the create the vm again. - - s virt-install --noautoconsole --graphics spice,listen=0.0.0.0 \ - --disk=/a/images/win10.qcow2,bus=virtio --vcpus 2 -r 4096 -w bridge=br0 \ - -n win10 --import --os-variant $variant --cpu host-model-only - - s virsh destroy win10 - - # this one hasn\'t had the virtio fix done yet. - s virt-install --noautoconsole --graphics spice,listen=0.0.0.0 \ - --disk=/a/images/win7.qcow2 --vcpus 2 -r 4096 -w bridge=br0 \ - -n win7 --import --os-variant win7 --cpu host-model-only - s virsh destroy win7 - # had a problem with --cpu host, so trying out - # --cpu host-model-only +pi tor +m /a/bin/buildscripts/tor-browser -fi +# nfs server +pi-nostart nfs-kernel-server +# networkmanager has this nasty behavior on flidas: if the machine +# crashes with dnsmasq running, on subsequent boot, it adds an entry to +# resolvconf for 127.0.0.1 in some stupid attempt to restore +# nameservers. +# This can be manually fixed by stoping dnsmasq, +# then based on whats in /run/dnsmasq/, i see we can run +# s resolvconf -d NetworkManager +# oh ya, and stoping NetworkManager leaves this crap behind without cleaning it up. +ser stop NetworkManager +ser disable NetworkManager -pi samba -# note samba re-reads it's config every 1 minute -case $distro in - arch) s cp /etc/samba/smb.conf.default /etc/samba/smb.conf ;; -esac -# add 2 lines after workgroup option -s sed -ri --follow-symlinks '/^\s*encrypt passwords\s*=/d' /etc/samba/smb.conf -s sed -ri --follow-symlinks '/^\s*map to guest\s*=/d' /etc/samba/smb.conf -s sed -i --follow-symlinks 's/\(\s*workgroup\s*=\).*/\1 WORKGROUP\n\tencrypt passwords = yes\n\tmap to guest = bad password/' /etc/samba/smb.conf -# remove default homes section. not sharing that. -s sed -ri --follow-symlinks '/^\s*\[homes\]/,/\s*\[/d' /etc/samba/smb.conf - -if ! grep -xF '[public]' /etc/samba/smb.conf &>/dev/null; then - s tee -a /etc/samba/smb.conf <<'EOF' -[public] - guest ok = yes - read only = no - path = /kfrodo +if [[ $HOSTNAME == frodo ]]; then + # nohide = export filesystems mounted deeper than the export point + # fsid=0 makes this export the "root" export + # not documented in the man page, but this means + # 1. it can be mounted with a shorthand of server:/ + # 2. exports that are subdirectories of this one will automatically be mounted + tu /etc/exports <<'EOF' +/k 10.0.0.0/24(rw,fsid=0,nohide,no_root_squash,async,no_subtree_check,insecure) EOF -fi - -case $distro in - debian|ubuntu) -# systemd claims it generates units from /etc/init.d, but it clearly doesn't -# in debian. I have no idea how they are related. fuck debian right now. It's -# not documented. samba has a systemd init file linked to /dev/null. -# There's this https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769714 which -# claims samba's sub-services will be started automatically by systemd... it -# didn't on install, wonder if it will on boot. It clued me in how to start -# it manually though. Nothing in /usr/share/doc/samba, debian admin guide -# says nothing about any of this. (this is in debian testing as of 4/2016). - -s /etc/init.d/samba start -;; - arch) - sgo samba - ;; -esac - -tu /etc/hosts <<< "127.0.1.1 $(hostname).lan $(hostname)" - - - -rootdev=$(mount | sed -rn 's#^(\S+) on / .*#\1#p') -s mkdir /mnt/root -tu /etc/fstab <<< "$rootdev /mnt/root btrfs noatime,subvolid=0 0 0" -mountpoint /mnt/root || s mount /mnt/root -idev=$(mount | sed -rn 's#^(\S+) on /i .*#\1#p') -if [[ $idev != $rootdev ]]; then - s mkdir /mnt/iroot - tu /etc/fstab <<< "$idev /mnt/iroot btrfs noatime,subvolid=0 0 0" - mountpoint /mnt/iroot || s mount /mnt/iroot + s exportfs -rav fi -######### begin stuff belonging at the end ########## -# Apps we want to override others for default file handler: -# simplest way in debian is to just install them last. -simple_packages+=( - mpv -) -case $distro in - ubuntu|debian) - spa spacefm-gtk3 ;; - arch) - spa spacefm ;; -esac +# if I was going to create a persistent vm, i might do it like this: +# variant=something # from: virt-install --os-variant list +# s virt-install --noautoconsole --graphics spice,listen=0.0.0.0 \ + # --disk=/a/images/some_name.qcow2,bus=virtio --vcpus 2 -r 4096 -w bridge=br0 \ + # -n some_name --import --os-variant $variant --cpu host-model-only -pi "${simple_packages[@]}" +######### begin stuff belonging at the end ########## -if $pending_reboot; then - echo "$0: pending reboot and then finished. doing it now." - s reboot now -else - echo "$0: $(date): ending now)" -fi +end