1 | #!/bin/sh |
---|
2 | # |
---|
3 | # snapshot-run PROGRAM [ARGS] |
---|
4 | # Create an Athena login snapshot, run PROGRAM within it, and clean up |
---|
5 | # the snapshot. |
---|
6 | # |
---|
7 | # This script is run as the user who is logging in, usually as a wrapper |
---|
8 | # around their Xsession or shell. You probably want to run reactivate |
---|
9 | # immediately afterwards, as root. |
---|
10 | |
---|
11 | set -e |
---|
12 | cd / |
---|
13 | |
---|
14 | addgroups="sudo admin lpadmin adm fuse cdrom floppy audio video plugdev scanner dialout lp" |
---|
15 | daemons="$(/usr/sbin/policy-rc.d --daemons)" |
---|
16 | |
---|
17 | # Setup |
---|
18 | |
---|
19 | session=$(schroot -c login -b) |
---|
20 | sch() { schroot -r -c "$session" -- "$@"; } # Run in the chroot |
---|
21 | schq() { schroot -q -r -c "$session" -- "$@"; } # Run in the chroot quietly |
---|
22 | schr() { schroot -r -c "$session" -u root -- "$@"; } # Run in the chroot as root |
---|
23 | |
---|
24 | for group in $addgroups; do |
---|
25 | schr env NSS_NONLOCAL_IGNORE=ignore getent group "$group" >/dev/null 2>&1 && schr adduser "$USER" "$group" |
---|
26 | done |
---|
27 | |
---|
28 | schr sed -i "/su-error/d" "/etc/pam.d/su.debathena" |
---|
29 | |
---|
30 | schr touch /ClusterLogin |
---|
31 | |
---|
32 | for daemon in $daemons; do |
---|
33 | schr invoke-rc.d "$daemon" start || [ $? = 100 ] |
---|
34 | done |
---|
35 | |
---|
36 | schr rm /etc/debian_chroot |
---|
37 | |
---|
38 | # Deter people from thinking they can use /home as persistant storage |
---|
39 | # by punting it |
---|
40 | schr rm -rf /home |
---|
41 | |
---|
42 | # Fix up mtab so that df and friends work correctly |
---|
43 | schr sed -i "s| /var/lib/schroot/mount/${session}/| /|" /etc/mtab |
---|
44 | |
---|
45 | # Run the session |
---|
46 | # |
---|
47 | # We wrap the target command in sudo because it runs initgroups(3) |
---|
48 | # /after/ being chrooted, which puts users back in the groups we |
---|
49 | # added them to |
---|
50 | |
---|
51 | # Workaround for stupidity, see #928 for details |
---|
52 | # Remove this once we're running pam-afs-session 2.4 |
---|
53 | # Run this inside the "set -e" block so it'll fail if necessary |
---|
54 | echo "KRB5CCNAME=$KRB5CCNAME" >| /tmp/ticketenv |
---|
55 | |
---|
56 | set +e |
---|
57 | |
---|
58 | echo "$USER ALL=(ALL) ALL" | schr sh -c "cat >> /etc/sudoers" |
---|
59 | |
---|
60 | cd |
---|
61 | schroot -c "$session" -r -p -- sudo -E -u "$USER" -- "$@" |
---|
62 | cd / |
---|
63 | |
---|
64 | # Teardown |
---|
65 | |
---|
66 | # Remove file from above. |
---|
67 | # (This also gets nuked in reactivate, but be paranoid) |
---|
68 | rm -f /tmp/ticketenv |
---|
69 | |
---|
70 | for daemon in $daemons; do |
---|
71 | schr invoke-rc.d "$daemon" stop || [ $? = 100 ] |
---|
72 | done |
---|
73 | |
---|
74 | schroot -c "$session" -e |
---|