qubes-sysinit.sh 3.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697
  1. #!/bin/sh
  2. # List of services enabled by default (in case of absence of qubesdb entry)
  3. DEFAULT_ENABLED_NETVM="network-manager qubes-network qubes-update-check qubes-updates-proxy"
  4. DEFAULT_ENABLED_PROXYVM="meminfo-writer qubes-network qubes-firewall qubes-netwatcher qubes-update-check"
  5. DEFAULT_ENABLED_APPVM="meminfo-writer cups qubes-update-check"
  6. DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_APPVM updates-proxy-setup"
  7. DEFAULT_ENABLED="meminfo-writer"
  8. QDB_READ=qubesdb-read
  9. QDB_LS=qubesdb-multiread
  10. read_service() {
  11. $QDB_READ /qubes-service/$1 2> /dev/null
  12. }
  13. systemd_pkg_version=`systemctl --version|head -n 1`
  14. if ! dmesg | grep -q "$systemd_pkg_version running in system mode."; then
  15. # Ensure we're running right version of systemd (the one started by initrd may be different)
  16. systemctl daemon-reexec
  17. fi
  18. # Wait for evtchn initialization
  19. while [ ! -e /proc/xen/xenbus ]; do
  20. sleep 0.1
  21. done
  22. mkdir -p /var/run/qubes
  23. mkdir -p /var/run/qubes-service
  24. mkdir -p /var/run/xen-hotplug
  25. # Set permissions to /proc/xen/xenbus, so normal user can use qubesdb-read
  26. chmod 666 /proc/xen/xenbus
  27. # Set permissions to /proc/xen/privcmd, so a user in qubes group can access
  28. chmod 660 /proc/xen/privcmd
  29. chgrp qubes /proc/xen/privcmd
  30. [ -e /proc/u2mfn ] || modprobe u2mfn
  31. # Set permissions to files needed to listen at vchan
  32. chmod 666 /proc/u2mfn
  33. # Set default services depending on VM type
  34. TYPE=`$QDB_READ /qubes-vm-type 2> /dev/null`
  35. [ "$TYPE" = "AppVM" ] && DEFAULT_ENABLED=$DEFAULT_ENABLED_APPVM
  36. [ "$TYPE" = "NetVM" ] && DEFAULT_ENABLED=$DEFAULT_ENABLED_NETVM
  37. [ "$TYPE" = "ProxyVM" ] && DEFAULT_ENABLED=$DEFAULT_ENABLED_PROXYVM
  38. [ "$TYPE" = "TemplateVM" ] && DEFAULT_ENABLED=$DEFAULT_ENABLED_TEMPLATEVM
  39. # Enable default services
  40. for srv in $DEFAULT_ENABLED; do
  41. touch /var/run/qubes-service/$srv
  42. done
  43. # Enable services
  44. for srv in `$QDB_LS /qubes-service/ 2>/dev/null |grep ' = 1'|cut -f 1 -d ' '`; do
  45. touch /var/run/qubes-service/$srv
  46. done
  47. # Disable services
  48. for srv in `$QDB_LS /qubes-service/ 2>/dev/null |grep ' = 0'|cut -f 1 -d ' '`; do
  49. rm -f /var/run/qubes-service/$srv
  50. done
  51. # Set the hostname
  52. name=`$QDB_READ /name`
  53. if [ -n "$name" ]; then
  54. hostname $name
  55. if [ -e /etc/debian_version ]; then
  56. ipv4_localhost_re="127\.0\.1\.1"
  57. else
  58. ipv4_localhost_re="127\.0\.0\.1"
  59. fi
  60. sed -i "s/^\($ipv4_localhost_re\(\s.*\)*\s\).*$/\1${name}/" /etc/hosts
  61. sed -i "s/^\(::1\(\s.*\)*\s\).*$/\1${name}/" /etc/hosts
  62. fi
  63. timezone=`$QDB_READ /qubes-timezone 2> /dev/null`
  64. if [ -n "$timezone" ]; then
  65. cp -p /usr/share/zoneinfo/$timezone /etc/localtime
  66. if [ -e /etc/debian_version ]; then
  67. echo "$timezone" > /etc/timezone
  68. else
  69. echo "# Clock configuration autogenerated based on Qubes dom0 settings" > /etc/sysconfig/clock
  70. echo "ZONE=\"$timezone\"" >> /etc/sysconfig/clock
  71. fi
  72. fi
  73. # Prepare environment for other services
  74. echo > /var/run/qubes-service-environment
  75. debug_mode=`$QDB_READ /qubes-debug-mode 2> /dev/null`
  76. if [ -n "$debug_mode" -a "$debug_mode" -gt 0 ]; then
  77. echo "GUI_OPTS=-vv" >> /var/run/qubes-service-environment
  78. fi
  79. exit 0