Browse Source

Fixing tripwire policy

Bob Mottram 7 years ago
parent
commit
b432410716
1 changed files with 3 additions and 37 deletions
  1. 3
    37
      src/freedombone-base-tripwire

+ 3
- 37
src/freedombone-base-tripwire View File

@@ -120,43 +120,9 @@ function install_tripwire {
120 120
     if ! grep -q '!/etc/share/tt-rss/lock' /etc/tripwire/twpol.txt; then
121 121
         sed -i '\|/etc\t\t->.*|a\    !/etc/share/tt-rss/lock ;' /etc/tripwire/twpol.txt
122 122
     fi
123
-    # Ignore additional install files
124
-    if ! grep -q '!/usr/local/bin/freedombone' /etc/tripwire/twpol.txt; then
125
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/freedombone* ;' /etc/tripwire/twpol.txt
126
-    fi
127
-    if ! grep -q '!=/usr/local/bin' /etc/tripwire/twpol.txt; then
128
-        sed -i '\|/usr/local/sbin.*|a\    !=/usr/local/bin ;' /etc/tripwire/twpol.txt
129
-    fi
130
-    if ! grep -q '!/usr/local/bin/addremove' /etc/tripwire/twpol.txt; then
131
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/addremove ;' /etc/tripwire/twpol.txt
132
-    fi
133
-    if ! grep -q '!/usr/local/bin/backup' /etc/tripwire/twpol.txt; then
134
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/backup ;' /etc/tripwire/twpol.txt
135
-    fi
136
-    if ! grep -q '!/usr/local/bin/backup2friends' /etc/tripwire/twpol.txt; then
137
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/backup2friends ;' /etc/tripwire/twpol.txt
138
-    fi
139
-    if ! grep -q '!/usr/local/bin/batman' /etc/tripwire/twpol.txt; then
140
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/batman ;' /etc/tripwire/twpol.txt
141
-    fi
142
-    if ! grep -q '!/usr/local/bin/control' /etc/tripwire/twpol.txt; then
143
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/control ;' /etc/tripwire/twpol.txt
144
-    fi
145
-    if ! grep -q '!/usr/local/bin/controluser' /etc/tripwire/twpol.txt; then
146
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/controluser ;' /etc/tripwire/twpol.txt
147
-    fi
148
-    if ! grep -q '!/usr/local/bin/cronic' /etc/tripwire/twpol.txt; then
149
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/cronic ;' /etc/tripwire/twpol.txt
150
-    fi
151
-    if ! grep -q '!/usr/local/bin/meshavahi' /etc/tripwire/twpol.txt; then
152
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/meshavahi ;' /etc/tripwire/twpol.txt
153
-    fi
154
-    if ! grep -q '!/usr/local/bin/restore' /etc/tripwire/twpol.txt; then
155
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/restore ;' /etc/tripwire/twpol.txt
156
-    fi
157
-    if ! grep -q '!/usr/local/bin/restorefromfriend' /etc/tripwire/twpol.txt; then
158
-        sed -i '\|/usr/local/sbin.*|a\    !/usr/local/bin/restorefromfriend ;' /etc/tripwire/twpol.txt
159
-    fi
123
+    # Not much is in /usr/local/bin other than project commands and avoiding it removes
124
+    # problems with updates. This is a tradeoff, but not by much.
125
+    sed -i '/\/usr\/local\/bin/d' /etc/tripwire/twpol.txt
160 126
 
161 127
     # Avoid logging the changed database
162 128
     sed -i 's|$(TWETC)/tw.pol.*||g' /etc/tripwire/twpol.txt