123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899 |
- #!/bin/bash
- # Source Qubes library.
- # shellcheck source=init/functions
- . /usr/lib/qubes/init/functions
- # List of services enabled by default (in case of absence of qubesdb entry)
- DEFAULT_ENABLED_NETVM="network-manager qubes-network qubes-update-check qubes-updates-proxy"
- DEFAULT_ENABLED_PROXYVM="qubes-network qubes-firewall qubes-update-check"
- DEFAULT_ENABLED_APPVM="cups qubes-update-check"
- DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_APPVM updates-proxy-setup"
- DEFAULT_ENABLED=""
- # devices emulated by qemu, first list of vendor IDs then list of device IDs:
- qemu_devices="0x8086
- 0x8086
- 0x8086
- 0x8086
- 0x8086
- 0x5853
- 0x1013
- 0x1237
- 0x7000
- 0x7010
- 0x7020
- 0x7113
- 0x0001
- 0x00b8
- "
- if [ -z "$(ls /sys/bus/pci/devices/)" ] || \
- [ "$(cat /sys/bus/pci/devices/*/{vendor,device})" != "$qemu_devices" ]; then
- # do not enable meminfo-writer (so qmemman for this domain) when any real PCI
- # device is present
- DEFAULT_ENABLED="$DEFAULT_ENABLED meminfo-writer"
- DEFAULT_ENABLED_APPVM="$DEFAULT_ENABLED_APPVM meminfo-writer"
- DEFAULT_ENABLED_PROXYVM="$DEFAULT_ENABLED_PROXYVM meminfo-writer"
- DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_TEMPLATEVM meminfo-writer"
- fi
- if systemd_version_changed ; then
- # Ensure we're running right version of systemd (the one started by initrd may be different)
- systemctl daemon-reexec
- fi
- # Wait for xenbus initialization
- while [ ! -e /dev/xen/xenbus ] && [ -e /proc/xen/xenbus ]; do
- sleep 0.1
- done
- mkdir -p /var/run/qubes
- chgrp qubes /var/run/qubes
- chmod 0775 /var/run/qubes
- mkdir -p /var/run/qubes-service
- mkdir -p /var/run/xen-hotplug
- # Set permissions to /proc/xen/xenbus, so normal user can talk to xenstore, to
- # open vchan connection. Note that new code uses /dev/xen/xenbus (which have
- # permissions set by udev), so this probably can go away soon
- chmod 666 /proc/xen/xenbus
- # Set permissions to /proc/xen/privcmd, so a user in qubes group can access
- chmod 660 /proc/xen/privcmd
- chgrp qubes /proc/xen/privcmd
- [ -e /proc/u2mfn ] || modprobe u2mfn
- # Set permissions to files needed by gui-agent
- chmod 666 /proc/u2mfn
- # Set default services depending on VM type
- is_appvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_APPVM && touch /var/run/qubes/this-is-appvm
- is_netvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_NETVM && touch /var/run/qubes/this-is-netvm
- is_proxyvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_PROXYVM && touch /var/run/qubes/this-is-proxyvm
- is_templatevm && DEFAULT_ENABLED=$DEFAULT_ENABLED_TEMPLATEVM && touch /var/run/qubes/this-is-templatevm
- # Enable default services
- for srv in $DEFAULT_ENABLED; do
- touch "/var/run/qubes-service/$srv"
- done
- # Enable services
- for srv in $(qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 1'|cut -f 1 -d ' '); do
- touch "/var/run/qubes-service/$srv"
- done
- # Disable services
- for srv in $(qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 0'|cut -f 1 -d ' '); do
- rm -f "/var/run/qubes-service/$srv"
- done
- # Prepare environment for other services
- echo > /var/run/qubes-service-environment
- debug_mode=$(qubesdb-read /qubes-debug-mode 2> /dev/null)
- if [ -n "$debug_mode" ] && [ "$debug_mode" -gt 0 ]; then
- echo "GUI_OPTS=-vv" >> /var/run/qubes-service-environment
- fi
- exit 0
|