]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/rootfiles/core/44/update.sh
Updater: add keyexchange=ikev1 to ipsec.conf.
[people/pmueller/ipfire-2.x.git] / config / rootfiles / core / 44 / update.sh
CommitLineData
228455b3
AF
1#!/bin/bash
2############################################################################
3# #
4# This file is part of the IPFire Firewall. #
5# #
6# IPFire is free software; you can redistribute it and/or modify #
7# it under the terms of the GNU General Public License as published by #
8# the Free Software Foundation; either version 3 of the License, or #
9# (at your option) any later version. #
10# #
11# IPFire is distributed in the hope that it will be useful, #
12# but WITHOUT ANY WARRANTY; without even the implied warranty of #
13# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
14# GNU General Public License for more details. #
15# #
16# You should have received a copy of the GNU General Public License #
17# along with IPFire; if not, write to the Free Software #
18# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA #
19# #
20# Copyright (C) 2010 IPFire-Team <info@ipfire.org>. #
21# #
22############################################################################
23#
24. /opt/pakfire/lib/functions.sh
25/usr/local/bin/backupctrl exclude >/dev/null 2>&1
c1db5636 26#
16739e91 27KVER="2.6.32.27"
c1db5636
AF
28MOUNT=`grep "kernel" /boot/grub/grub.conf | tail -n 1`
29# Nur den letzten Parameter verwenden
30echo $MOUNT > /dev/null
31MOUNT=$_
32if [ ! $MOUNT == "rw" ]; then
33 MOUNT="ro"
34fi
35
228455b3
AF
36
37#
c1db5636
AF
38# check if we the backup file already exist
39if [ -e /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 ]; then
40 echo Moving backup to backup-old ...
41 mv -f /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 \
42 /var/ipfire/backup/core-upgrade_$KVER-old.tar.bz2
43fi
44echo First we made a backup of all files that was inside of the
45echo update archive. This may take a while ...
46# Add some files that are not in the package to backup
47echo lib/modules >> /opt/pakfire/tmp/ROOTFILES
48echo boot >> /opt/pakfire/tmp/ROOTFILES
49echo etc/mkinitcpio.conf >> /opt/pakfire/tmp/ROOTFILES
50echo etc/mkinitcpio.conf.org >> /opt/pakfire/tmp/ROOTFILES
51echo etc/mkinitcpio.d >> /opt/pakfire/tmp/ROOTFILES
52echo lib/initcpio >> /opt/pakfire/tmp/ROOTFILES
53echo sbin/mkinitcpio >> /opt/pakfire/tmp/ROOTFILES
54echo usr/bin/iw >> /opt/pakfire/tmp/ROOTFILES
1fdae966
AF
55echo etc/snort >> /opt/pakfire/tmp/ROOTFILES
56echo usr/lib/snort_* >> /opt/pakfire/tmp/ROOTFILES
57echo usr/lib/squid >> /opt/pakfire/tmp/ROOTFILES
228455b3 58
c1db5636
AF
59# Backup the files
60tar cjvf /var/ipfire/backup/core-upgrade_$KVER.tar.bz2 \
61 -C / -T /opt/pakfire/tmp/ROOTFILES --exclude='#*' > /dev/null 2>&1
62
63echo
64echo Update Kernel to $KVER ...
65# Remove old kernel, configs, initrd, modules ...
66#
67rm -rf /boot/System.map-*
68rm -rf /boot/config-*
69rm -rf /boot/ipfirerd-*
70rm -rf /boot/vmlinuz-*
71rm -rf /lib/modules/*-ipfire
72# Remove mkinitcpio
73rm -rf /etc/mkinitcpio.*
74rm -rf /lib/initcpio
75rm -rf /sbin/mkinitcpio
76# Remove old iw (new is in usr/sbin)
77rm -rf /usr/bin/iw
78#
79# Backup grub.conf
80#
81cp -vf /boot/grub/grub.conf /boot/grub/grub.conf.org
1fdae966
AF
82
83#
84# Stop services to save memory
85#
86/etc/init.d/snort stop
87/etc/init.d/squid stop
c599b6df
AF
88/etc/init.d/ipsec stop
89
1fdae966
AF
90#
91#
92# Remove old snort...
93rm -rf /etc/snort
94rm -rf /usr/lib/snort_*
95# Remove old squid...
96rm -rf /usr/lib/squid
c1db5636
AF
97#
98# Unpack the updated files
228455b3 99#
c1db5636
AF
100echo
101echo Unpack the updated files ...
102#
103tar xvf /opt/pakfire/tmp/files --preserve --numeric-owner -C / \
104 --no-overwrite-dir
105
e959976b
MT
106# Remove old pakfire cronjob.
107rm -f /etc/fcron.daily/pakfire-update
108
c1db5636
AF
109# Convert /etc/fstab entries to UUID ...
110#
111echo Convert fstab entries to UUID ...
112ROOT=`mount | grep " / " | cut -d" " -f1`
113BOOT=`mount | grep " /boot " | cut -d" " -f1`
114VAR=`mount | grep " /var " | cut -d" " -f1`
115SWAP=`grep "/dev/" /proc/swaps | cut -d" " -f1`
228455b3 116#
228455b3 117
c1db5636
AF
118if [ ! -z $ROOT ]; then
119 ROOTUUID=`blkid -c /dev/null -sUUID $ROOT | cut -d'"' -f2`
120 if [ ! -z $ROOTUUID ]; then
121 sed -i "s|^$ROOT|UUID=$ROOTUUID|g" /etc/fstab
122 #else
123 #to do add uuid to rootfs
124 fi
125 else
126 echo "ERROR! / not found!!!"
127fi
128
129if [ ! -z $BOOT ]; then
130 BOOTUUID=`blkid -c /dev/null -sUUID $BOOT | cut -d'"' -f2`
131 if [ ! -z $BOOTUUID ]; then
132 sed -i "s|^$BOOT|UUID=$BOOTUUID|g" /etc/fstab
133 #else
134 #to do add uuid to bootfs
135 fi
136 else
137 echo "WARNING! /boot not found!!!"
138fi
139
140if [ ! -z $VAR ]; then
141 VARUUID=`blkid -c /dev/null -sUUID $VAR | cut -d'"' -f2`
142 if [ ! -z $VARUUID ]; then
143 sed -i "s|^$VAR|UUID=$VARUUID|g" /etc/fstab
144 #else
145 #to do add uuid to varfs
146 fi
147 else
148 echo "WARNING! /var not found!!!"
149fi
150
151if [ ! -z $SWAP ]; then
152 SWAPUUID=`blkid -c /dev/null -sUUID $SWAP | cut -d'"' -f2`
153 if [ ! -z $SWAPUUID ]; then
154 sed -i "s|^$SWAP|UUID=$SWAPUUID|g" /etc/fstab
155 else
156 # Reformat swap to add a UUID
157 swapoff -a
158 mkswap $SWAP
159 swapon -a
160 SWAPUUID=`blkid -c /dev/null -sUUID $SWAP | cut -d'"' -f2`
161 if [ ! -z $SWAPUUID ]; then
162 sed -i "s|^$SWAP|UUID=$SWAPUUID|g" /etc/fstab
163 fi
164 fi
165 else
166 echo "WARNING! swap not found!!!"
167fi
168
c599b6df
AF
169#new strongswan need keyexchange=ikev1 because this is not default anymore
170mv /var/ipfire/vpn/ipsec.conf /var/ipfire/vpn/ipsec.conf.org
171grep -v "keyexchange=ikev1" /var/ipfire/vpn/ipsec.conf.org > /var/ipfire/vpn/ipsec.conf
172sed -i "s|^conn [A-Za-z].*$|&\n\tkeyexchange=ikev1|g" /var/ipfire/vpn/ipsec.conf
173
c1db5636
AF
174#
175# Start services
228455b3 176#
c1db5636
AF
177/etc/init.d/squid start
178/etc/init.d/snort start
c599b6df 179/etc/init.d/ipsec start
228455b3 180
b03cd0fb
AF
181
182# Add pakfire and fireinfo cronjobs...
183grep -v "# fireinfo" /var/spool/cron/root.orig |
184grep -v "/usr/bin/sendprofile" |
185grep -v "# pakfire" |
186grep -v "/usr/local/bin/pakfire" > /var/tmp/root.tmp
187echo "" >> /var/tmp/root.tmp
188echo "# fireinfo" >> /var/tmp/root.tmp
189echo "%nightly,random * 23-4 /usr/bin/sendprofile >/dev/null 2>&1" >> /var/tmp/root.tmp
190echo "" >> /var/tmp/root.tmp
191echo "# pakfire" >> /var/tmp/root.tmp
192echo "%nightly,random * 23-4 /usr/local/bin/pakfire update >/dev/null 2>&1" >> /var/tmp/root.tmp
193fcrontab /var/tmp/root.tmp
194
c1db5636
AF
195#
196# Modify grub.conf
197#
198echo
199echo Update grub configuration ...
200if [ ! -z $ROOTUUID ]; then
201 sed -i "s|ROOT|UUID=$ROOTUUID|g" /boot/grub/grub.conf
202else
203 sed -i "s|ROOT|$ROOT|g" /boot/grub/grub.conf
204fi
205sed -i "s|KVER|$KVER|g" /boot/grub/grub.conf
206sed -i "s|MOUNT|$MOUNT|g" /boot/grub/grub.conf
228455b3 207
c1db5636
AF
208if [ "$(grep "^serial" /boot/grub/grub.conf.org)" == "" ]; then
209 echo "grub use default console ..."
210else
211 echo "grub use serial console ..."
212 sed -i -e "s|splashimage|#splashimage|g" /boot/grub/grub.conf
213 sed -i -e "s|#serial|serial|g" /boot/grub/grub.conf
214 sed -i -e "s|#terminal|terminal|g" /boot/grub/grub.conf
215 sed -i -e "s| panic=10 | console=ttyS0,38400n8 panic=10 |g" /boot/grub/grub.conf
216fi
217#
218# Change /dev/hd? to /dev/sda
219#
220if [ "${ROOT:0:7}" == "/dev/hd" ];then
221 sed -i -e "s|${ROOT:0:8}|/dev/sda|g" /boot/grub/grub.conf
222 sed -i -e "s|${ROOT:0:8}|/dev/sda|g" /etc/fstab
223fi
224#
225# ReInstall grub
226#
227grub-install --no-floppy ${ROOT::`expr length $ROOT`-1} --recheck
228#
229# Rebuild Language
230#
231perl -e "require '/var/ipfire/lang.pl'; &Lang::BuildCacheLang"
232#
233# Delete old lm-sensor modullist to force search at next boot
228455b3 234#
c1db5636
AF
235rm -rf /etc/sysconfig/lm_sensors
236/usr/bin/logger -p syslog.emerg -t kernel "Upgrade finished. If you use a customized grub.cfg"
237/usr/bin/logger -p syslog.emerg -t kernel "Check it before reboot !!!"
238/usr/bin/logger -p syslog.emerg -t kernel " *** Please reboot... *** "
f8e4f32b 239touch /var/run/need_reboot