]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/rootfiles/core/44/update.sh
updater: fix ipsec start if it is disabled.
[people/pmueller/ipfire-2.x.git] / config / rootfiles / core / 44 / update.sh
CommitLineData
228455b3
AF
1#!/bin/bash
2############################################################################
3# #
4# This file is part of the IPFire Firewall. #
5# #
6# IPFire is free software; you can redistribute it and/or modify #
7# it under the terms of the GNU General Public License as published by #
8# the Free Software Foundation; either version 3 of the License, or #
9# (at your option) any later version. #
10# #
11# IPFire is distributed in the hope that it will be useful, #
12# but WITHOUT ANY WARRANTY; without even the implied warranty of #
13# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
14# GNU General Public License for more details. #
15# #
16# You should have received a copy of the GNU General Public License #
17# along with IPFire; if not, write to the Free Software #
18# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA #
19# #
20# Copyright (C) 2010 IPFire-Team <info@ipfire.org>. #
21# #
22############################################################################
23#
24. /opt/pakfire/lib/functions.sh
25/usr/local/bin/backupctrl exclude >/dev/null 2>&1
c1db5636 26#
16739e91 27KVER="2.6.32.27"
c1db5636
AF
28MOUNT=`grep "kernel" /boot/grub/grub.conf | tail -n 1`
29# Nur den letzten Parameter verwenden
30echo $MOUNT > /dev/null
31MOUNT=$_
32if [ ! $MOUNT == "rw" ]; then
33 MOUNT="ro"
34fi
35
228455b3
AF
36
37#
c1db5636
AF
38# check if we the backup file already exist
39if [ -e /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 ]; then
40 echo Moving backup to backup-old ...
41 mv -f /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 \
42 /var/ipfire/backup/core-upgrade_$KVER-old.tar.bz2
43fi
44echo First we made a backup of all files that was inside of the
45echo update archive. This may take a while ...
46# Add some files that are not in the package to backup
47echo lib/modules >> /opt/pakfire/tmp/ROOTFILES
48echo boot >> /opt/pakfire/tmp/ROOTFILES
49echo etc/mkinitcpio.conf >> /opt/pakfire/tmp/ROOTFILES
50echo etc/mkinitcpio.conf.org >> /opt/pakfire/tmp/ROOTFILES
51echo etc/mkinitcpio.d >> /opt/pakfire/tmp/ROOTFILES
52echo lib/initcpio >> /opt/pakfire/tmp/ROOTFILES
53echo sbin/mkinitcpio >> /opt/pakfire/tmp/ROOTFILES
54echo usr/bin/iw >> /opt/pakfire/tmp/ROOTFILES
1fdae966
AF
55echo etc/snort >> /opt/pakfire/tmp/ROOTFILES
56echo usr/lib/snort_* >> /opt/pakfire/tmp/ROOTFILES
57echo usr/lib/squid >> /opt/pakfire/tmp/ROOTFILES
228455b3 58
c1db5636
AF
59# Backup the files
60tar cjvf /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 \
61 -C / -T /opt/pakfire/tmp/ROOTFILES --exclude='#*' > /dev/null 2>&1
62
63echo
64echo Update Kernel to $KVER ...
65# Remove old kernel, configs, initrd, modules ...
66#
67rm -rf /boot/System.map-*
68rm -rf /boot/config-*
69rm -rf /boot/ipfirerd-*
70rm -rf /boot/vmlinuz-*
71rm -rf /lib/modules/*-ipfire
72# Remove mkinitcpio
73rm -rf /etc/mkinitcpio.*
74rm -rf /lib/initcpio
75rm -rf /sbin/mkinitcpio
76# Remove old iw (new is in usr/sbin)
77rm -rf /usr/bin/iw
78#
79# Backup grub.conf
80#
81cp -vf /boot/grub/grub.conf /boot/grub/grub.conf.org
1fdae966
AF
82
83#
84# Stop services to save memory
85#
86/etc/init.d/snort stop
87/etc/init.d/squid stop
c599b6df
AF
88/etc/init.d/ipsec stop
89
1fdae966
AF
90#
91#
92# Remove old snort...
93rm -rf /etc/snort
94rm -rf /usr/lib/snort_*
95# Remove old squid...
96rm -rf /usr/lib/squid
c1db5636
AF
97#
98# Unpack the updated files
228455b3 99#
c1db5636
AF
100echo
101echo Unpack the updated files ...
102#
103tar xvf /opt/pakfire/tmp/files --preserve --numeric-owner -C / \
104 --no-overwrite-dir
105
e959976b
MT
106# Remove old pakfire cronjob.
107rm -f /etc/fcron.daily/pakfire-update
108
c1db5636
AF
109# Convert /etc/fstab entries to UUID ...
110#
111echo Convert fstab entries to UUID ...
112ROOT=`mount | grep " / " | cut -d" " -f1`
113BOOT=`mount | grep " /boot " | cut -d" " -f1`
114VAR=`mount | grep " /var " | cut -d" " -f1`
115SWAP=`grep "/dev/" /proc/swaps | cut -d" " -f1`
228455b3 116#
228455b3 117
c1db5636
AF
118if [ ! -z $ROOT ]; then
119 ROOTUUID=`blkid -c /dev/null -sUUID $ROOT | cut -d'"' -f2`
120 if [ ! -z $ROOTUUID ]; then
121 sed -i "s|^$ROOT|UUID=$ROOTUUID|g" /etc/fstab
122 #else
123 #to do add uuid to rootfs
124 fi
125 else
126 echo "ERROR! / not found!!!"
127fi
128
129if [ ! -z $BOOT ]; then
130 BOOTUUID=`blkid -c /dev/null -sUUID $BOOT | cut -d'"' -f2`
131 if [ ! -z $BOOTUUID ]; then
132 sed -i "s|^$BOOT|UUID=$BOOTUUID|g" /etc/fstab
133 #else
134 #to do add uuid to bootfs
135 fi
136 else
137 echo "WARNING! /boot not found!!!"
138fi
139
140if [ ! -z $VAR ]; then
141 VARUUID=`blkid -c /dev/null -sUUID $VAR | cut -d'"' -f2`
142 if [ ! -z $VARUUID ]; then
143 sed -i "s|^$VAR|UUID=$VARUUID|g" /etc/fstab
144 #else
145 #to do add uuid to varfs
146 fi
147 else
148 echo "WARNING! /var not found!!!"
149fi
150
151if [ ! -z $SWAP ]; then
152 SWAPUUID=`blkid -c /dev/null -sUUID $SWAP | cut -d'"' -f2`
153 if [ ! -z $SWAPUUID ]; then
154 sed -i "s|^$SWAP|UUID=$SWAPUUID|g" /etc/fstab
155 else
156 # Reformat swap to add a UUID
157 swapoff -a
158 mkswap $SWAP
159 swapon -a
160 SWAPUUID=`blkid -c /dev/null -sUUID $SWAP | cut -d'"' -f2`
161 if [ ! -z $SWAPUUID ]; then
162 sed -i "s|^$SWAP|UUID=$SWAPUUID|g" /etc/fstab
163 fi
164 fi
165 else
166 echo "WARNING! swap not found!!!"
167fi
168
c599b6df
AF
169#new strongswan need keyexchange=ikev1 because this is not default anymore
170mv /var/ipfire/vpn/ipsec.conf /var/ipfire/vpn/ipsec.conf.org
171grep -v "keyexchange=ikev1" /var/ipfire/vpn/ipsec.conf.org > /var/ipfire/vpn/ipsec.conf
172sed -i "s|^conn [A-Za-z].*$|&\n\tkeyexchange=ikev1|g" /var/ipfire/vpn/ipsec.conf
2120ed47 173chown nobody:nobody /var/ipfire/vpn/ipsec.conf
c599b6df 174
d7aea5bd
AF
175#new squid has some changed options. Build a basic config to be able start squid.
176mv /var/ipfire/proxy/squid.conf /var/ipfire/proxy/squid.conf.org
177grep -v "header_access " /var/ipfire/proxy/squid.conf.org | \
178grep -v "error_directory " | \
e07587fc 179grep -v "cache_dir null" | \
d7aea5bd
AF
180grep -v "reply_body_max_size 0" > /var/ipfire/proxy/squid.conf
181echo >> /var/ipfire/proxy/squid.conf
182echo error_directory /etc/squid/errors >> /var/ipfire/proxy/squid.conf
2120ed47 183chown nobody:nobody /var/ipfire/proxy/squid.conf
d7aea5bd 184
455a698f
AF
185#Convert extrahd entries to UUID
186cp -f /var/ipfire/extrahd/devices /var/ipfire/extrahd/devices.org
187while read entry
188do
189 device=`echo $entry | cut -f1 -d";"`
190 uuid=`blkid -c /dev/null -s UUID -o value /dev/$device`
191 if [ ! -z $uuid ]; then
192 sed -i -e "s|$device|UUID=$uuid|g" /var/ipfire/extrahd/devices
193 sed -i -e "s|/dev/$device|UUID=$uuid|g" /var/ipfire/extrahd/fstab
194 sed -i -e "s|/dev/$device|UUID=$uuid|g" /etc/fstab
195 fi
196done < /var/ipfire/extrahd/devices.org
197
c1db5636
AF
198#
199# Start services
228455b3 200#
c1db5636
AF
201/etc/init.d/squid start
202/etc/init.d/snort start
bf22df04
AF
203if [ `grep "ENABLED=on" /var/ipfire/vpn/settings` ]; then
204 /etc/init.d/ipsec start
205fi
b03cd0fb
AF
206
207# Add pakfire and fireinfo cronjobs...
208grep -v "# fireinfo" /var/spool/cron/root.orig |
209grep -v "/usr/bin/sendprofile" |
210grep -v "# pakfire" |
211grep -v "/usr/local/bin/pakfire" > /var/tmp/root.tmp
212echo "" >> /var/tmp/root.tmp
213echo "# fireinfo" >> /var/tmp/root.tmp
214echo "%nightly,random * 23-4 /usr/bin/sendprofile >/dev/null 2>&1" >> /var/tmp/root.tmp
215echo "" >> /var/tmp/root.tmp
216echo "# pakfire" >> /var/tmp/root.tmp
217echo "%nightly,random * 23-4 /usr/local/bin/pakfire update >/dev/null 2>&1" >> /var/tmp/root.tmp
218fcrontab /var/tmp/root.tmp
219
c1db5636
AF
220#
221# Modify grub.conf
222#
223echo
224echo Update grub configuration ...
225if [ ! -z $ROOTUUID ]; then
226 sed -i "s|ROOT|UUID=$ROOTUUID|g" /boot/grub/grub.conf
227else
228 sed -i "s|ROOT|$ROOT|g" /boot/grub/grub.conf
229fi
230sed -i "s|KVER|$KVER|g" /boot/grub/grub.conf
231sed -i "s|MOUNT|$MOUNT|g" /boot/grub/grub.conf
228455b3 232
c1db5636
AF
233if [ "$(grep "^serial" /boot/grub/grub.conf.org)" == "" ]; then
234 echo "grub use default console ..."
235else
236 echo "grub use serial console ..."
237 sed -i -e "s|splashimage|#splashimage|g" /boot/grub/grub.conf
238 sed -i -e "s|#serial|serial|g" /boot/grub/grub.conf
239 sed -i -e "s|#terminal|terminal|g" /boot/grub/grub.conf
240 sed -i -e "s| panic=10 | console=ttyS0,38400n8 panic=10 |g" /boot/grub/grub.conf
241fi
242#
243# Change /dev/hd? to /dev/sda
244#
245if [ "${ROOT:0:7}" == "/dev/hd" ];then
246 sed -i -e "s|${ROOT:0:8}|/dev/sda|g" /boot/grub/grub.conf
247 sed -i -e "s|${ROOT:0:8}|/dev/sda|g" /etc/fstab
248fi
249#
250# ReInstall grub
251#
252grub-install --no-floppy ${ROOT::`expr length $ROOT`-1} --recheck
253#
254# Rebuild Language
255#
256perl -e "require '/var/ipfire/lang.pl'; &Lang::BuildCacheLang"
257#
258# Delete old lm-sensor modullist to force search at next boot
228455b3 259#
c1db5636 260rm -rf /etc/sysconfig/lm_sensors
d85fb69b
AF
261#
262# Change version of Pakfire.conf
263#
264OLDVERSION=`grep "version = " /opt/pakfire/etc/pakfire.conf | cut -d'"' -f2`
265NEWVERSION="2.9"
266sed -i "s|$OLDVERSION|$NEWVERSION|g" /opt/pakfire/etc/pakfire.conf
267#
268# After pakfire has ended run it again and update the lists and do upgrade
269#
270echo '#!/bin/bash' > /tmp/pak_update
271echo 'while [ "$(ps -A | grep " update.sh")" != "" ]; do' >> /tmp/pak_update
272echo ' sleep 1' >> /tmp/pak_update
273echo 'done' >> /tmp/pak_update
274echo 'while [ "$(ps -A | grep " pakfire")" != "" ]; do' >> /tmp/pak_update
275echo ' sleep 1' >> /tmp/pak_update
276echo 'done' >> /tmp/pak_update
277echo '/opt/pakfire/pakfire update -y --force' >> /tmp/pak_update
278echo '/opt/pakfire/pakfire upgrade -y' >> /tmp/pak_update
279echo '/opt/pakfire/pakfire upgrade -y' >> /tmp/pak_update
280echo '/opt/pakfire/pakfire upgrade -y' >> /tmp/pak_update
281echo '/usr/bin/logger -p syslog.emerg -t core-upgrade-44 "Upgrade finished. If you use a customized grub.cfg"' >> /tmp/pak_update
282echo '/usr/bin/logger -p syslog.emerg -t core-upgrade-44 "Check it before reboot !!!"' >> /tmp/pak_update
283echo '/usr/bin/logger -p syslog.emerg -t core-upgrade-44 " *** Please reboot... *** "' >> /tmp/pak_update
284echo 'touch /var/run/need_reboot ' >> /tmp/pak_update
285#
286chmod +x /tmp/pak_update
287/tmp/pak_update &
288echo
289echo Please wait until pakfire has ended...
290echo