# Copyright (c) 2002-2003,2006 Ryan Murray <rmurray@debian.org>
# Copyright (c) 2004-2005 Joey Schulze <joey@infodrom.org>
# Copyright (c) 2008 Peter Palfrader <peter@palfrader.org>
-# Copyright (©) 2008 Stephen Gran <sgran@debian.org>
+# Copyright (c) 2008 Stephen Gran <sgran@debian.org>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
fi
tempdir=''
+tempfile=''
+tempfile2=''
cleanup ()
{
rm -f lock
rm -rf $tempdir
+ rm -f $tempfile
+ rm -f $tempfile2
}
PATH=/sbin:/usr/sbin:/bin:/usr/bin
HOST=`hostname -f`
SYNCHOST=`ud-config synchost`;
LOCALSYNCON=`ud-config localsyncon`;
+EMAILAPPEND=`ud-config emailappend`;
cd /tmp/
cd /var/lib/misc || cd /var/state/glibc/ || cd /var/db/
lockfile -r 1 -l 3600 lock
;;
esac
-rsync ${verbose} -e 'ssh -i /etc/ssh/ssh_host_rsa_key -o PreferredAuthentications=publickey' -rp "${udhost}/var/cache/userdir-ldap/hosts/$HOST" .
+tempfile=$(mktemp)
+tempfile2=$(mktemp)
+
+if [ -e /var/lib/misc/thishost/dns-sshfp ]; then
+ cp /var/lib/misc/thishost/dns-sshfp $tempfile
+fi
+
+if [ -e /var/lib/misc/thishost/dns-zone ]; then
+ cp /var/lib/misc/thishost/dns-zone $tempfile2
+fi
+
+rsync ${verbose} --delete-after -e 'ssh -i /etc/ssh/ssh_host_rsa_key -o PreferredAuthentications=publickey' -rp "${udhost}/var/cache/userdir-ldap/hosts/$HOST" .
makedb "$HOST/passwd.tdb" -o passwd.db.t
if [ -s "$HOST/shadow.tdb" ]
makedb "$HOST/group.tdb" -o group.db.t
mv -f passwd.db.t passwd.db
mv -f group.db.t group.db
-for a in $HOST/ssh-rsa-shadow $HOST/ssh_known_hosts; do
- ln -sf $a .
-done
-ln -sf `pwd -P`/ssh-rsa-shadow /etc/ssh
+if [ -e "$HOST/ssh-rsa-shadow" ]; then
+ ln -sf $HOST/ssh-rsa-shadow .
+ ln -sf `pwd -P`/ssh-rsa-shadow /etc/ssh
+else
+ rm -f ssh-rsa-shadow /etc/ssh/ssh-rsa-shadow
+fi
+ln -sf $HOST/ssh_known_hosts .
ln -sf `pwd -P`/ssh_known_hosts /etc/ssh
if [ -e ${HOST}/ssh-keys.tar.gz ]; then
- export TMPDIR='/tmp/'
+ export TMPDIR='/tmp/'
tempdir=$(mktemp -d)
- old=$(pwd -P)
- cd $tempdir && tar -xvf ${old}/${HOST}/ssh-keys.tar.gz
- cd old
- mkdir userkeys 2> /dev/null || true
+ tar -C "$tempdir" -xf ${HOST}/ssh-keys.tar.gz
+ mkdir -p userkeys
chmod 755 $tempdir
- rsync -av --delete-after $tempdir/ userkeys/
+ rsync -a --delete-after $tempdir/ userkeys/
fi
+CHROOTS=""
if [ -x /usr/bin/dchroot ]; then
CHROOTS=`dchroot --listpaths`
+elif [ -x /usr/bin/dchroot-dsa ]; then
+ CHROOTS=$(dchroot-dsa -i | grep Location | awk '{print $2}')
+fi
+if [ -n "$CHROOTS" ]; then
for c in $CHROOTS; do
+ if [ "$c" = "/" ] || [ "$c" = "" ]; then
+ echo "$0 WTF: \$c is '' or '/' here." 2>&1
+ exit 1
+ fi
if [ -x "$c/usr/bin/makedb" ]
then
-
- test ! -d "$c/var/lib/misc/$HOST" || mkdir -p "$c/var/lib/misc/$HOST"
-
- rsync -a ${verbose} $HOST/group.tdb $HOST/passwd.tdb $HOST/ssh* "$c/var/lib/misc/$HOST"
-
- test ! -f "$c/var/lib/misc/$HOST/shadow.tdb" || rm -f "$c/var/lib/misc/$HOST/shadow.tdb"
- test ! -f "$c/var/lib/misc/shadow.db" || rm -f "$c/var/lib/misc/shadow.db"
-
+ mkdir -p "$c/var/lib/misc/$HOST"
+
+ # remove extra stuff from earlier times and so
+ find "$c/var/lib/misc/$HOST" -mindepth 1 \
+ ! -name group.tdb -a \
+ ! -name passwd.tdb -a \
+ ! -name ssh_known_hosts \
+ -print0 | xargs --no-run-if-empty -0 rm -f
+ rsync -a ${verbose} $HOST/group.tdb $HOST/passwd.tdb $HOST/ssh_known_hosts "$c/var/lib/misc/$HOST"
+
+ # clean up from the times we supposedly did shadow stuff in chroots
+ rm -f "$c/var/lib/misc/shadow.db"
+
+ # from failed makedb runs earlier.
+ rm -f "$c/var/lib/misc/passwd.db.t" \
+ "$c/var/lib/misc/group.db.t"
+ # build passwd information
chroot "$c" makedb "/var/lib/misc/$HOST/passwd.tdb" -o /var/lib/misc/passwd.db.t
chroot "$c" makedb "/var/lib/misc/$HOST/group.tdb" -o /var/lib/misc/group.db.t
mv -f "$c/var/lib/misc/passwd.db.t" "$c/var/lib/misc/passwd.db"
mv -f "$c/var/lib/misc/group.db.t" "$c/var/lib/misc/group.db"
+
ln -sf "$HOST/ssh_known_hosts" "$c/var/lib/misc/"
- ln -sf ../../var/lib/misc/ssh_known_hosts "$c/etc/ssh"
+ if [ -d "$c/etc/ssh" ]; then
+ ln -sf ../../var/lib/misc/ssh_known_hosts "$c/etc/ssh"
+ elif [ -L "$c/etc/ssh" ] && [ "`readlink \"$c/etc/ssh\"`" = "../../var/lib/misc/ssh_known_hosts" ]; then
+ # clean up past mistakes
+ rm -f "$c/etc/ssh"
+ fi
fi
done
fi
fi
fi
if [ -d "/etc/postfix" -a -f "$HOST/forward-alias" ]; then
- sed -e 's/:/@debian.org/' $HOST/forward-alias > /etc/postfix/debian
+ sed -e "s/:/@$EMAILAPPEND/" $HOST/forward-alias > /etc/postfix/debian
/usr/sbin/postmap hash:/etc/postfix/debian < /etc/postfix/debian || true
fi
+
+rndc_reload=0
+if [ -e /var/lib/misc/thishost/dns-sshfp ]; then
+ if ! cmp -s /var/lib/misc/thishost/dns-sshfp $tempfile; then
+ /git/HOOKS/write_zonefile debian.org
+ rndc_reload=1
+ fi
+fi
+
+if [ -e /var/lib/misc/thishost/dns-zone ]; then
+ if ! cmp -s /var/lib/misc/thishost/dns-zone $tempfile2; then
+ /git/HOOKS/write_zonefile debian.net
+ rndc_reload=1
+ fi
+fi
+
+if [ "${rndc_reload}" -gt 0 ]; then
+ rndc reload
+fi