qubes-sysinit.sh 2.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576
  1. #!/bin/bash
  2. # Source Qubes library.
  3. # shellcheck source=init/functions
  4. . /usr/lib/qubes/init/functions
  5. # List of services enabled by default (in case of absence of qubesdb entry)
  6. DEFAULT_ENABLED_NETVM="network-manager qubes-network qubes-update-check qubes-updates-proxy meminfo-writer qubes-firewall"
  7. DEFAULT_ENABLED_PROXYVM="qubes-network qubes-firewall qubes-update-check meminfo-writer"
  8. DEFAULT_ENABLED_APPVM="cups qubes-update-check meminfo-writer"
  9. DEFAULT_ENABLED_TEMPLATEVM="$DEFAULT_ENABLED_APPVM updates-proxy-setup"
  10. DEFAULT_ENABLED="meminfo-writer"
  11. if systemd_version_changed ; then
  12. # Ensure we're running right version of systemd (the one started by initrd may be different)
  13. systemctl daemon-reexec
  14. fi
  15. # Wait for xenbus initialization
  16. while [ ! -e /dev/xen/xenbus ] && [ -e /proc/xen/xenbus ]; do
  17. sleep 0.1
  18. done
  19. mkdir -p /var/run/qubes
  20. chgrp qubes /var/run/qubes
  21. chmod 0775 /var/run/qubes
  22. mkdir -p /var/run/qubes-service
  23. mkdir -p /var/run/xen-hotplug
  24. # Set permissions to /proc/xen/xenbus, so normal user can talk to xenstore, to
  25. # open vchan connection. Note that new code uses /dev/xen/xenbus (which have
  26. # permissions set by udev), so this probably can go away soon
  27. chmod 666 /proc/xen/xenbus
  28. # Set permissions to /proc/xen/privcmd, so a user in qubes group can access
  29. chmod 660 /proc/xen/privcmd
  30. chgrp qubes /proc/xen/privcmd
  31. [ -e /proc/u2mfn ] || modprobe u2mfn
  32. # Set permissions to files needed by gui-agent
  33. chmod 666 /proc/u2mfn
  34. # Set default services depending on VM type
  35. is_appvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_APPVM && touch /var/run/qubes/this-is-appvm
  36. is_netvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_NETVM && touch /var/run/qubes/this-is-netvm
  37. is_proxyvm && DEFAULT_ENABLED=$DEFAULT_ENABLED_PROXYVM && touch /var/run/qubes/this-is-proxyvm
  38. is_templatevm && DEFAULT_ENABLED=$DEFAULT_ENABLED_TEMPLATEVM && touch /var/run/qubes/this-is-templatevm
  39. # Enable default services
  40. for srv in $DEFAULT_ENABLED; do
  41. touch "/var/run/qubes-service/$srv"
  42. done
  43. # Enable services
  44. for srv in $(qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 1'|cut -f 1 -d ' '); do
  45. touch "/var/run/qubes-service/$srv"
  46. done
  47. # Disable services
  48. for srv in $(qubesdb-multiread /qubes-service/ 2>/dev/null |grep ' = 0'|cut -f 1 -d ' '); do
  49. rm -f "/var/run/qubes-service/$srv"
  50. done
  51. # Prepare environment for other services
  52. echo > /var/run/qubes-service-environment
  53. gui_opts="-d $(qubesdb-read /qubes-gui-domain-xid || echo 0)"
  54. debug_mode=$(qubesdb-read /qubes-debug-mode 2> /dev/null)
  55. if [ -n "$debug_mode" ] && [ "$debug_mode" -gt 0 ]; then
  56. gui_opts="$gui_opts -vv"
  57. fi
  58. echo "GUI_OPTS=$gui_opts" >> /var/run/qubes-service-environment
  59. exit 0