X-Git-Url: https://git.adam-barratt.org.uk/?p=mirror%2Fuserdir-ldap.git;a=blobdiff_plain;f=ud-replicate;h=53867e76bac12de3797288fd01070f25b5330481;hp=80846fb29d0a604db38fa030e2eb5a5f3c17694b;hb=HEAD;hpb=f46e6c6a323d5fa70ef5c913f08df3b506f20de6 diff --git a/ud-replicate b/ud-replicate index 80846fb..53867e7 100755 --- a/ud-replicate +++ b/ud-replicate @@ -1,8 +1,10 @@ -#! /bin/sh +#! /bin/bash -# Copyright (c) 1999-2001 Jason Gunthorpe -# Copyright (c) 2002-2003 Ryan Murray -# Copyright (c) 2004 Joey Schulze +# Copyright (c) 1999-2001 Jason Gunthorpe +# Copyright (c) 2002-2003,2006 Ryan Murray +# Copyright (c) 2004-2005 Joey Schulze +# Copyright (c) 2008,2011 Peter Palfrader +# Copyright (c) 2008 Stephen Gran # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by @@ -21,62 +23,141 @@ set -e # Without effect on the commandline -if [ -z "$PS1" -o "$TERM" = "dumb" ] +if [ -z "$TERM" -o "$TERM" = "dumb" ] then exec > /dev/null 2>&1 + sleep $(( $RANDOM % 120 )) else verbose=-v fi +tempdir='' +tempfile='' +tempfile2='' + +cleanup () +{ + rm -rf $tempdir + rm -f $tempfile + rm -f $tempfile2 +} + +PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin +export PATH HOST=`hostname -f` -cd /tmp/ -cd /var/lib/misc || cd /var/state/glibc/ || cd /var/db/ -lockfile -r 1 -l 3600 lock -trap "rm -f lock" exit +SYNCHOST=`ud-config synchost`; +LOCALSYNCON=`ud-config localsyncon`; +EMAILAPPEND=`ud-config emailappend`; +cd /var/lib/misc +exec 200< "." +if ! flock -w 60 -e 200; then + log "Cannot acquire lock on `pwd`" + exit 1 +fi + +trap cleanup exit case $HOST in -*samosa*) +$LOCALSYNCON) udhost= ;; *) - udhost="sshdist@samosa:" + udhost="sshdist@$SYNCHOST:" ;; esac -rsync ${verbose} -e ssh -rp "${udhost}/var/cache/userdir-ldap/hosts/$HOST" . +tempfile=$(mktemp) +tempfile2=$(mktemp) + +if [ -e /var/lib/misc/thishost/dns-sshfp ]; then + cp /var/lib/misc/thishost/dns-sshfp $tempfile +fi + +if [ -e /var/lib/misc/thishost/dns-zone ]; then + cp /var/lib/misc/thishost/dns-zone $tempfile2 +fi + +rsync ${verbose} --delete-after --times -e 'ssh -i /etc/ssh/ssh_host_rsa_key -o ControlPath=/var/run/.ud-replicate.ssh.socket -o ControlMaster=auto -o ControlPersist=2h -o BatchMode=yes' -rp "${udhost}/var/cache/userdir-ldap/hosts/$HOST" . +rm -f __db.passwd.db.t makedb "$HOST/passwd.tdb" -o passwd.db.t -(umask 027 && makedb "$HOST/shadow.tdb" -o shadow.db.t) -chown root.shadow shadow.db.t; chmod 0640 shadow.db.t +if [ -s "$HOST/shadow.tdb" ] +then + rm -f __db.shadow.db.t + (umask 027 && makedb "$HOST/shadow.tdb" -o shadow.db.t) + chown root.shadow shadow.db.t + chmod 0640 shadow.db.t + mv -f shadow.db.t shadow.db +fi +rm -f __db.group.db.t makedb "$HOST/group.tdb" -o group.db.t mv -f passwd.db.t passwd.db -mv -f shadow.db.t shadow.db mv -f group.db.t group.db -ln -sf "$HOST/ssh-rsa-shadow" . -ln -sf "$HOST/ssh_known_hosts" . - -#if [ -x /usr/bin/dchroot ]; then -# CHROOTS=`dchroot --listpaths` -# for c in $CHROOTS; do -# if [ -e "$c/var/lib/misc/$HOST" ]; then -# chroot "$c" makedb "/var/lib/misc/$HOST/passwd.tdb" -o /var/lib/misc/passwd.db.t -# (umask 027 && chroot "$c" makedb "/var/lib/misc/$HOST/shadow.tdb" -o /var/lib/misc/shadow.db.t) -# chown root.shadow "$c/var/lib/misc/shadow.db.t" -# chmod 0640 "$c/var/lib/misc/shadow.db.t" -# chroot "$c" makedb "/var/lib/misc/$HOST/group.tdb" -o /var/lib/misc/group.db.t -# mv -f "$c/var/lib/misc/passwd.db.t" "$c/var/lib/misc/passwd.db" -# mv -f "$c/var/lib/misc/shadow.db.t" "$c/var/lib/misc/shadow.db" -# mv -f "$c/var/lib/misc/group.db.t" "$c/var/lib/misc/group.db" -# fi -# done -#fi - -if [ -d "/etc/exim" -a -e "$HOST/bsmtp" ]; then - if perl -e 'exit !((stat "/etc/exim/bsmtp")[9] < time()-3600)'; then - cp "$HOST/bsmtp" /etc/exim/bsmtp +if [ -e "$HOST/ssh-rsa-shadow" ]; then + ln -sf $HOST/ssh-rsa-shadow . + ln -sf `pwd -P`/ssh-rsa-shadow /etc/ssh +else + rm -f ssh-rsa-shadow /etc/ssh/ssh-rsa-shadow +fi +ln -sf $HOST/ssh_known_hosts . +ln -sf `pwd -P`/ssh_known_hosts /etc/ssh + +if [ -e ${HOST}/ssh-keys.tar.gz ]; then + export TMPDIR='/tmp/' + tempdir=$(mktemp -d) + tar -C "$tempdir" -xf ${HOST}/ssh-keys.tar.gz + mkdir -p userkeys + chmod 755 $tempdir + rsync -a --delete-after $tempdir/ userkeys/ +fi + +if [ -e ${HOST}/web-passwords ]; then + chown root:www-data ${HOST}/web-passwords + chmod 0640 ${HOST}/web-passwords +fi + +if [ -d "/etc/exim4" -a -e "$HOST/bsmtp" ]; then + if perl -e 'exit !((stat "/etc/exim4/bsmtp")[9] < time()-3600)'; then + cp "$HOST/bsmtp" /etc/exim4/bsmtp fi fi if [ -d "/etc/postfix" -a -f "$HOST/forward-alias" ]; then - sed -e 's/:/@debian.org/' $HOST/forward-alias > /etc/postfix/debian + sed -e "s/:/@$EMAILAPPEND/" $HOST/forward-alias > /etc/postfix/debian /usr/sbin/postmap hash:/etc/postfix/debian < /etc/postfix/debian || true fi + +rebuild_zones=0 +if [ -e /var/lib/misc/thishost/dns-sshfp ]; then + if ! cmp -s /var/lib/misc/thishost/dns-sshfp "$tempfile"; then + rebuild_zones=1 + fi +fi + +if [ -e /var/lib/misc/thishost/dns-zone ]; then + if ! cmp -s /var/lib/misc/thishost/dns-zone "$tempfile2"; then + rebuild_zones=1 + fi +fi + +if [ "${rebuild_zones}" -gt 0 ]; then + sudo -u dnsadm /srv/dns.debian.org/bin/update +fi + +if [ -d "/etc/freeradius" -a -e "$HOST/rtc-passwords" ]; then + if ! cmp -s "$HOST/rtc-passwords" /var/local/rtc-passwords.freerad; then + install -o freerad -g freerad -m 400 "$HOST/rtc-passwords" /var/local/rtc-passwords.freerad + service freeradius reload + fi +fi +if [ -d "/etc/reTurn" -a -e "$HOST/rtc-passwords" ]; then + if ! cmp -s "$HOST/rtc-passwords" /var/local/rtc-passwords.return; then + install -o return -g return -m 400 "$HOST/rtc-passwords" /var/local/rtc-passwords.return + service resiprocate-turn-server reload + fi +fi +if [ -d "/etc/prosody" -a -e "$HOST/rtc-passwords" ]; then + if ! cmp -s "$HOST/rtc-passwords" /var/local/rtc-passwords.prosody; then + install -o prosody -g prosody -m 400 "$HOST/rtc-passwords" /var/local/rtc-passwords.prosody + service prosody reload + fi +fi