qubes-sysinit.sh 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081
  1. #!/bin/bash
  2. # Source Qubes library.
  3. . /usr/lib/qubes/init/functions
  4. # List of services enabled by default (in case of absence of qubesdb entry)
  5. DEFAULT_ENABLED_NETVM="network-manager qubes-network qubes-update-check qubes-updates-proxy"
  6. DEFAULT_ENABLED_PROXYVM="qubes-network qubes-firewall qubes-update-check"
  7. DEFAULT_ENABLED_APPVM="cups qubes-update-check"
  8. DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_APPVM updates-proxy-setup"
  9. DEFAULT_ENABLED=""
  10. if [ -z "`ls /sys/bus/pci/devices/`" ]; then
  11. # do not enable meminfo-writer (so qmemman for this domain) when any PCI
  12. # device is present
  13. DEFAULT_ENABLED="$DEFAULT_ENABLED meminfo-writer"
  14. DEFAULT_ENABLED_APPVM="$DEFAULT_ENABLED_APPVM meminfo-writer"
  15. DEFAULT_ENABLED_PROXYVM="$DEFAULT_ENABLED_PROXYVM meminfo-writer"
  16. DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_TEMPLATEVM meminfo-writer"
  17. fi
  18. if systemd_version_changed ; then
  19. # Ensure we're running right version of systemd (the one started by initrd may be different)
  20. systemctl daemon-reexec
  21. fi
  22. # Wait for xenbus initialization
  23. while [ ! -e /dev/xen/xenbus -a ! -e /proc/xen/xenbus ]; do
  24. sleep 0.1
  25. done
  26. mkdir -p /var/run/qubes
  27. chgrp qubes /var/run/qubes
  28. chmod 0775 /var/run/qubes
  29. mkdir -p /var/run/qubes-service
  30. mkdir -p /var/run/xen-hotplug
  31. # Set permissions to /proc/xen/xenbus, so normal user can talk to xenstore, to
  32. # open vchan connection. Note that new code uses /dev/xen/xenbus (which have
  33. # permissions set by udev), so this probably can go away soon
  34. chmod 666 /proc/xen/xenbus
  35. # Set permissions to /proc/xen/privcmd, so a user in qubes group can access
  36. chmod 660 /proc/xen/privcmd
  37. chgrp qubes /proc/xen/privcmd
  38. [ -e /proc/u2mfn ] || modprobe u2mfn
  39. # Set permissions to files needed by gui-agent
  40. chmod 666 /proc/u2mfn
  41. # Set default services depending on VM type
  42. is_appvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_APPVM && touch /var/run/qubes/this-is-appvm
  43. is_netvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_NETVM && touch /var/run/qubes/this-is-netvm
  44. is_proxyvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_PROXYVM && touch /var/run/qubes/this-is-proxyvm
  45. is_templatevm && DEFAULT_ENABLED=$DEFAULT_ENABLED_TEMPLATEVM && touch /var/run/qubes/this-is-templatevm
  46. # Enable default services
  47. for srv in $DEFAULT_ENABLED; do
  48. touch /var/run/qubes-service/$srv
  49. done
  50. # Enable services
  51. for srv in `qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 1'|cut -f 1 -d ' '`; do
  52. touch /var/run/qubes-service/$srv
  53. done
  54. # Disable services
  55. for srv in `qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 0'|cut -f 1 -d ' '`; do
  56. rm -f /var/run/qubes-service/$srv
  57. done
  58. # Prepare environment for other services
  59. echo > /var/run/qubes-service-environment
  60. debug_mode=`qubesdb-read /qubes-debug-mode 2> /dev/null`
  61. if [ -n "$debug_mode" -a "$debug_mode" -gt 0 ]; then
  62. echo "GUI_OPTS=-vv" >> /var/run/qubes-service-environment
  63. fi
  64. exit 0