]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/rootfiles/core/184/update.sh
CU184-update.sh: Add drop hostile in & out logging entries
[people/pmueller/ipfire-2.x.git] / config / rootfiles / core / 184 / update.sh
CommitLineData
ffe528be
MT
1#!/bin/bash
2############################################################################
3# #
4# This file is part of the IPFire Firewall. #
5# #
6# IPFire is free software; you can redistribute it and/or modify #
7# it under the terms of the GNU General Public License as published by #
8# the Free Software Foundation; either version 3 of the License, or #
9# (at your option) any later version. #
10# #
11# IPFire is distributed in the hope that it will be useful, #
12# but WITHOUT ANY WARRANTY; without even the implied warranty of #
13# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
14# GNU General Public License for more details. #
15# #
16# You should have received a copy of the GNU General Public License #
17# along with IPFire; if not, write to the Free Software #
18# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA #
19# #
20# Copyright (C) 2023 IPFire-Team <info@ipfire.org>. #
21# #
22############################################################################
23#
24. /opt/pakfire/lib/functions.sh
25/usr/local/bin/backupctrl exclude >/dev/null 2>&1
26
27core=184
28
29# Remove old core updates from pakfire cache to save space...
30for (( i=1; i<=$core; i++ )); do
31 rm -f /var/cache/pakfire/core-upgrade-*-$i.ipfire
32done
33
34# Stop services
8e111d6f 35/etc/init.d/squid stop
0742f6ed 36/etc/init.d/vnstat stop
ffe528be
MT
37
38# Extract files
39extract_files
40
fb7d1372
MT
41# Remove dropped elfutils addon
42rm -vf \
43 /opt/pakfire/db/installed/meta-elfutils \
44 /opt/pakfire/db/meta/meta-elfutils \
7d0f4866
MT
45 /opt/pakfire/db/rootfiles/elfutils \
46 /usr/bin/eu-addr2line \
47 /usr/bin/eu-ar \
48 /usr/bin/eu-elfclassify \
49 /usr/bin/eu-elfcmp \
50 /usr/bin/eu-elfcompress \
51 /usr/bin/eu-elflint \
52 /usr/bin/eu-findtextrel \
53 /usr/bin/eu-make-debug-archive \
54 /usr/bin/eu-nm \
55 /usr/bin/eu-objdump \
56 /usr/bin/eu-ranlib \
57 /usr/bin/eu-readelf \
58 /usr/bin/eu-size \
59 /usr/bin/eu-srcfiles \
60 /usr/bin/eu-stack \
61 /usr/bin/eu-strings \
62 /usr/bin/eu-strip \
63 /usr/bin/eu-unstrip
fb7d1372 64
ffe528be
MT
65# Remove files
66
67# update linker config
68ldconfig
69
70# Update Language cache
71/usr/local/bin/update-lang-cache
72
73# Filesytem cleanup
74/usr/local/bin/filesystem-cleanup
75
06a6788e
AF
76# fix module compression of rtl8812au
77xz -d /lib/modules/6.6.15-ipfire/extra/wlan/8812au.ko.xz
78xz --check=crc32 --lzma2=dict=512KiB /lib/modules/6.6.15-ipfire/extra/wlan/8812au.ko
79
ffe528be
MT
80# Apply local configuration to sshd_config
81/usr/local/bin/sshctrl
82
68c3cfd0
AB
83# Add the drop hostile in and out logging options
84# into the optionsfw settings file and apply to firewall
85sed -i '$ a\LOGDROPHOSTILEIN=on' /var/ipfire/optionsfw/settings
86sed -i '$ a\LOGDROPHOSTILEOUT=on' /var/ipfire/optionsfw/settings
87/usr/local/bin/firewallctrl
88
ffe528be 89# Start services
2240d083 90telinit u
0742f6ed 91/etc/init.d/vnstat start
08c20b84 92/etc/init.d/collectd restart
bce42f80 93/etc/init.d/suricata restart
f3d7ce3b 94/etc/init.d/unbound restart
8e111d6f
MT
95if [ -f /var/ipfire/proxy/enable ]; then
96 /etc/init.d/squid start
97fi
98
ffe528be 99# This update needs a reboot...
2240d083 100touch /var/run/need_reboot
ffe528be
MT
101
102# Finish
103/etc/init.d/fireinfo start
104sendprofile
105
106# Update grub config to display new core version
107if [ -e /boot/grub/grub.cfg ]; then
108 grub-mkconfig -o /boot/grub/grub.cfg
109fi
110
111sync
112
113# Don't report the exitcode last command
114exit 0