freedombone-image 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508
  1. #!/bin/bash
  2. #
  3. # .---. . .
  4. # | | |
  5. # |--- .--. .-. .-. .-.| .-. .--.--. |.-. .-. .--. .-.
  6. # | | (.-' (.-' ( | ( )| | | | )( )| | (.-'
  7. # ' ' --' --' -' - -' ' ' -' -' -' ' - --'
  8. #
  9. # Freedom in the Cloud
  10. #
  11. # Creates a debian image using vmdebootstrap
  12. #
  13. # To shut down after error: fuser -mvk /tmp/tmpdir/build
  14. #
  15. # License
  16. # =======
  17. #
  18. # Copyright (C) 2015-2016 Bob Mottram <bob@robotics.uk.to>
  19. #
  20. # This program is free software: you can redistribute it and/or modify
  21. # it under the terms of the GNU Affero General Public License as published by
  22. # the Free Software Foundation, either version 3 of the License, or
  23. # (at your option) any later version.
  24. #
  25. # This program is distributed in the hope that it will be useful,
  26. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  27. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  28. # GNU Affero General Public License for more details.
  29. #
  30. # You should have received a copy of the GNU Affero General Public License
  31. # along with this program. If not, see <http://www.gnu.org/licenses/>.
  32. PROJECT_NAME='freedombone'
  33. export TEXTDOMAIN=${PROJECT_NAME}-image
  34. export TEXTDOMAINDIR="/usr/share/locale"
  35. PROJECT_REPO="https://github.com/bashrc/${PROJECT_NAME}"
  36. # recommended RAM for virtual machines
  37. VM_MEMORY='1G'
  38. VARIANT='full'
  39. # fixed username and password when the --generic option is used
  40. GENERIC_IMAGE_USERNAME='fbone'
  41. GENERIC_IMAGE_PASSWORD='freedombone'
  42. IMAGE_TYPE='beaglebone'
  43. CURR_DIR=$(pwd)
  44. CURR_USER=$(echo $USER)
  45. TEMPBUILD_DIR=~/.tmp_${PROJECT_NAME}_build
  46. VMDEBOOTSTRAP_REPO=git://git.liw.fi/vmdebootstrap
  47. VMDEBOOTSTRAP_VERSION=0.8
  48. MAKEFILE=${PROJECT_NAME}-image-makefile
  49. IMAGE_SIZE=7.8G
  50. IMAGE_SIZE_SPECIFIED=
  51. IMAGE_NAME='full'
  52. USERNAME=$(echo $USER)
  53. PASSWORD=
  54. # IP address of the router (gateway)
  55. ROUTER_IP_ADDRESS="192.168.1.254"
  56. # The fixed IP address of the Beaglebone Black (or other SBC) on your local network
  57. BOX_IP_ADDRESS="192.168.1.55"
  58. # DNS
  59. NAMESERVER1='213.73.91.35'
  60. NAMESERVER2='85.214.20.141'
  61. # An optional freedombone configuration file
  62. CONFIG_FILENAME=
  63. DEFAULT_DOMAIN_NAME="${PROJECT_NAME}.local"
  64. # Minimum number of characters in a password
  65. MINIMUM_PASSWORD_LENGTH=$(cat /usr/share/${PROJECT_NAME}/utils/${PROJECT_NAME}-utils-passwords | grep 'MINIMUM_PASSWORD_LENGTH=' | head -n 1 | awk -F '=' '{print $2}')
  66. # Optional ssh public key to allow
  67. SSH_PUBKEY="no"
  68. # interactive mode
  69. INTERACTIVE="no"
  70. # Whether this is a generic image for mass redistribution on the interwebs
  71. GENERIC_IMAGE="yes"
  72. # Whether to reduce the number of decisions during interactive install
  73. MINIMAL_INSTALL="yes"
  74. # default SSH port
  75. SSH_PORT=2222
  76. # Whether sites are accessible only within a Tor browser
  77. ONION_ONLY="no"
  78. # Where to fetch packages
  79. #MIRROR='http://httpredir.debian.org/debian'
  80. MIRROR='http://ftp.de.debian.org/debian'
  81. # Whether to only install debian but nothing else
  82. DEBIAN_INSTALL_ONLY='no'
  83. # wifi settings
  84. WIFI_INTERFACE='wlan0'
  85. WIFI_SSID=
  86. WIFI_TYPE='wpa2-psk'
  87. WIFI_PASSPHRASE=
  88. WIFI_HOTSPOT='no'
  89. WIFI_NETWORKS_FILE=~/${PROJECT_NAME}-wifi.cfg
  90. # Whether to install non-free wifi drivers for the mesh client
  91. INSECURE='no'
  92. # for mesh installs whether to delete all data and generate
  93. # a new identity at every shutdown/boot
  94. AMNESIC='no'
  95. mesh_router_setup_script() {
  96. # create a setup script for a mesh router
  97. mesh_script_filename=$1
  98. echo "MY_USERNAME=${USERNAME}" > $mesh_script_filename
  99. echo "DEFAULT_DOMAIN_NAME=${USERNAME}" >> $mesh_script_filename
  100. echo 'SYSTEM_TYPE=mesh' >> $mesh_script_filename
  101. echo 'INSTALLING_ON_BBB=no' >> $mesh_script_filename
  102. echo 'USB_DRIVE=/dev/sda1' >> $mesh_script_filename
  103. echo 'DDNS_PROVIDER=' >> $mesh_script_filename
  104. echo 'DDNS_USERNAME=' >> $mesh_script_filename
  105. echo 'DDNS_PASSWORD=' >> $mesh_script_filename
  106. echo 'DEFAULT_LANGUAGE=en_GB.UTF-8' >> $mesh_script_filename
  107. echo 'MY_EMAIL_ADDRESS=' >> $mesh_script_filename
  108. echo 'ENABLE_CJDNS=no' >> $mesh_script_filename
  109. echo 'ENABLE_BATMAN=yes' >> $mesh_script_filename
  110. echo 'ENABLE_BABEL=no' >> $mesh_script_filename
  111. echo 'DEBIAN_REPO=' >> $mesh_script_filename
  112. echo 'NAMESERVER1=' >> $mesh_script_filename
  113. echo 'NAMESERVER2=' >> $mesh_script_filename
  114. echo 'BATMAN_CELLID=any' >> $mesh_script_filename
  115. echo 'WIFI_CHANNEL=9' >> $mesh_script_filename
  116. }
  117. while [[ $# > 1 ]]
  118. do
  119. key="$1"
  120. case $key in
  121. -h|--help)
  122. show_help
  123. ;;
  124. -c|--config)
  125. shift
  126. CONFIG_FILENAME="$1"
  127. if [ ! -f $CONFIG_FILENAME ]; then
  128. echo $"Config file $CONFIG_FILENAME not found"
  129. exit 3
  130. fi
  131. DEFAULT_DOMAIN_NAME=$(cat $CONFIG_FILENAME | grep 'DEFAULT_DOMAIN_NAME' | awk -F '=' '{print $2}')
  132. ;;
  133. -t|--target|--board)
  134. shift
  135. IMAGE_TYPE="$1"
  136. ;;
  137. -u|--user|--username)
  138. shift
  139. USERNAME="$1"
  140. ;;
  141. -p|--password)
  142. shift
  143. PASSWORD="$1"
  144. if [ ${#PASSWORD} -lt $MINIMUM_PASSWORD_LENGTH ]; then
  145. echo $"Your password chould contain at least ${MINIMUM_PASSWORD_LENGTH} characters"
  146. exit 3628
  147. fi
  148. ;;
  149. --sshkey|--sshpubkey|--pubkey)
  150. shift
  151. SSH_PUBKEY="$1"
  152. ;;
  153. -s|--size)
  154. shift
  155. IMAGE_SIZE="$1"
  156. IMAGE_SIZE_SPECIFIED=1
  157. ;;
  158. # Box static IP address on the LAN
  159. --ip)
  160. shift
  161. BOX_IP_ADDRESS="$1"
  162. ;;
  163. # Router IP address on the LAN
  164. --iprouter)
  165. shift
  166. ROUTER_IP_ADDRESS="$1"
  167. ;;
  168. # nameserver 1
  169. --ns1|--nameserver1)
  170. shift
  171. NAMESERVER1="$1"
  172. ;;
  173. # nameserver 2
  174. --ns2|--nameserver2)
  175. shift
  176. NAMESERVER2="$1"
  177. ;;
  178. -i|--interactive)
  179. shift
  180. INTERACTIVE="$1"
  181. ;;
  182. -g|--generic)
  183. shift
  184. GENERIC_IMAGE="$1"
  185. ;;
  186. --minimal)
  187. shift
  188. MINIMAL_INSTALL="$1"
  189. ;;
  190. --ssh|--sshport)
  191. shift
  192. SSH_PORT="$1"
  193. ;;
  194. -v|--variant)
  195. shift
  196. VARIANT="$1"
  197. ;;
  198. -o|--onion)
  199. shift
  200. ONION_ONLY="$1"
  201. ;;
  202. -a|--amnesic)
  203. shift
  204. AMNESIC="$1"
  205. ;;
  206. -r|--repo|--repository)
  207. shift
  208. PROJECT_REPO="$1"
  209. ;;
  210. -m|--mirror)
  211. shift
  212. MIRROR="$1"
  213. ;;
  214. --debianonly|--basic|--minimal)
  215. shift
  216. DEBIAN_INSTALL_ONLY="$1"
  217. ;;
  218. --interface|--if)
  219. shift
  220. WIFI_INTERFACE="$1"
  221. ;;
  222. --ssid|--essid)
  223. shift
  224. WIFI_SSID="$1"
  225. ;;
  226. --wifitype)
  227. shift
  228. WIFI_TYPE="$1"
  229. ;;
  230. --wifipass|--passphrase)
  231. shift
  232. WIFI_PASSPHRASE="$1"
  233. ;;
  234. --hotspot)
  235. shift
  236. if [[ $"$1" == $'yes' || $"$1" == $'y' ]]; then
  237. WIFI_HOTSPOT='yes'
  238. fi
  239. ;;
  240. --networks)
  241. shift
  242. WIFI_NETWORKS_FILE="$1"
  243. ;;
  244. --insecure)
  245. shift
  246. INSECURE="$1"
  247. ;;
  248. *)
  249. # unknown option
  250. ;;
  251. esac
  252. shift
  253. done
  254. if [[ $INTERACTIVE == "yes" || $INTERACTIVE == "y" || $INTERACTIVE == "Yes" ]]; then
  255. ${PROJECT_NAME}-config --minimal "$MINIMAL_INSTALL"
  256. if [ -f freedombone.cfg ]; then
  257. CONFIG_FILENAME=freedombone.cfg
  258. DEFAULT_DOMAIN_NAME=$(cat $CONFIG_FILENAME | grep 'DEFAULT_DOMAIN_NAME' | awk -F '=' '{print $2}')
  259. fi
  260. fi
  261. if [[ $GENERIC_IMAGE == "yes" ]]; then
  262. USERNAME=$GENERIC_IMAGE_USERNAME
  263. PASSWORD=$GENERIC_IMAGE_PASSWORD
  264. fi
  265. if [ ! $PASSWORD ]; then
  266. # generate a random password
  267. PASSWORD="$(openssl rand -base64 30 | cut -c1-${MINIMUM_PASSWORD_LENGTH})"
  268. fi
  269. # Move any existing images into a build subdirectory
  270. image_types=( xz img sig vdi qcow2 )
  271. for im in "${image_types[@]}"
  272. do
  273. no_of_files=$(ls -afq ${CURR_DIR}/${PROJECT_NAME}*.${im} | wc -l)
  274. if (( no_of_files > 0 )); then
  275. if [ ! -d ${CURR_DIR}/build ]; then
  276. mkdir ${CURR_DIR}/build
  277. fi
  278. mv -f ${CURR_DIR}/${PROJECT_NAME}*.${im} ${CURR_DIR}/build
  279. fi
  280. done
  281. # Delete anything which didn't move
  282. for im in "${image_types[@]}"
  283. do
  284. no_of_files=$(ls -afq ${CURR_DIR}/${PROJECT_NAME}*.${im} | wc -l)
  285. if (( no_of_files > 0 )); then
  286. rm -f ${CURR_DIR}/${PROJECT_NAME}*.${im}
  287. fi
  288. done
  289. # Remove any existing login credentials file
  290. if [ -f ${CURR_DIR}/${PROJECT_NAME}_login_credentials.txt ]; then
  291. rm ${CURR_DIR}/${PROJECT_NAME}_login_credentials.txt
  292. fi
  293. if [ -d $TEMPBUILD_DIR ]; then
  294. rm -rf $TEMPBUILD_DIR
  295. fi
  296. mkdir -p $TEMPBUILD_DIR
  297. if [ -f /usr/local/bin/$MAKEFILE ]; then
  298. cp /usr/local/bin/$MAKEFILE $TEMPBUILD_DIR/Makefile
  299. else
  300. cp /usr/bin/$MAKEFILE $TEMPBUILD_DIR/Makefile
  301. fi
  302. cp -r /etc/${PROJECT_NAME}/* $TEMPBUILD_DIR
  303. rm -rf $TEMPBUILD_DIR/vendor
  304. chown -R $CURR_USER:$CURR_USER $TEMPBUILD_DIR
  305. cd $TEMPBUILD_DIR
  306. if [[ $MINIMAL_INSTALL == "yes" ]]; then
  307. IMAGE_NAME=$'min'
  308. fi
  309. if [[ $ONION_ONLY != "no" ]]; then
  310. IMAGE_NAME=$'onion'
  311. fi
  312. if [[ $VARIANT == 'mesh' ]]; then
  313. IMAGE_NAME=$'mesh'
  314. # typically not much disk space is needed for a mesh node
  315. if [ ! $IMAGE_SIZE_SPECIFIED ]; then
  316. IMAGE_SIZE=3G
  317. fi
  318. fi
  319. if [[ $VARIANT == 'meshclient' || $VARIANT == 'meshusb' ]]; then
  320. IMAGE_NAME=$'meshclient'
  321. if [[ $INSECURE != 'no' ]]; then
  322. IMAGE_NAME=$'meshclient-insecure'
  323. fi
  324. if [ ! $IMAGE_SIZE_SPECIFIED ]; then
  325. IMAGE_SIZE=7.8G
  326. fi
  327. fi
  328. if [[ $VARIANT == 'usb' ]]; then
  329. IMAGE_NAME=$'usb'
  330. fi
  331. # append amnesic to the image name if needed
  332. if [[ $AMNESIC != 'no' ]]; then
  333. IMAGE_NAME="${IMAGE_NAME}-amnesic"
  334. fi
  335. cd $TEMPBUILD_DIR
  336. make $IMAGE_TYPE \
  337. MYUSERNAME="$USERNAME" \
  338. MYPASSWORD="$PASSWORD" \
  339. ROUTER_IP_ADDRESS="$ROUTER_IP_ADDRESS" \
  340. BOX_IP_ADDRESS="$BOX_IP_ADDRESS" \
  341. NAMESERVER1="$NAMESERVER1" \
  342. NAMESERVER2="$NAMESERVER2" \
  343. PROJECT_NAME="$PROJECT_NAME" \
  344. CONFIG_FILENAME="$CONFIG_FILENAME" \
  345. IMAGE_SIZE="$IMAGE_SIZE" \
  346. SSH_PUBKEY="$SSH_PUBKEY" \
  347. GENERIC_IMAGE="$GENERIC_IMAGE" \
  348. MINIMAL_INSTALL="$MINIMAL_INSTALL" \
  349. SSH_PORT="$SSH_PORT" \
  350. ONION_ONLY="$ONION_ONLY" \
  351. IMAGE_NAME="$IMAGE_NAME" \
  352. PROJECT_REPO="$PROJECT_REPO" \
  353. MIRROR="$MIRROR" \
  354. BUILD_MIRROR="$MIRROR" \
  355. DEBIAN_INSTALL_ONLY="$DEBIAN_INSTALL_ONLY" \
  356. WIFI_INTERFACE="$WIFI_INTERFACE" \
  357. WIFI_SSID="$WIFI_SSID" \
  358. WIFI_TYPE="$WIFI_TYPE" \
  359. WIFI_PASSPHRASE="$WIFI_PASSPHRASE" \
  360. WIFI_HOTSPOT="$WIFI_HOTSPOT" \
  361. WIFI_NETWORKS_FILE="$WIFI_NETWORKS_FILE" \
  362. VARIANT="$VARIANT" \
  363. MINIMUM_PASSWORD_LENGTH="$MINIMUM_PASSWORD_LENGTH" \
  364. INSECURE="$INSECURE" \
  365. AMNESIC="$AMNESIC"
  366. if [ ! "$?" = "0" ]; then
  367. echo $'Build failed'
  368. rm -rf $TEMPBUILD_DIR
  369. exit 1
  370. fi
  371. EXPECTED_EXTENSION='xz'
  372. if [[ $IMAGE_TYPE == "qemu"* ]]; then
  373. EXPECTED_EXTENSION='qcow2'
  374. fi
  375. if [[ $IMAGE_TYPE == "virtualbox"* ]]; then
  376. EXPECTED_EXTENSION='vdi'
  377. fi
  378. shopt -s nullglob
  379. imgfiles=(build/${PROJECT_NAME}*.${EXPECTED_EXTENSION})
  380. if [ ${#imgfiles[@]} -eq 0 ]; then
  381. echo $'Image was not created'
  382. rm -rf $TEMPBUILD_DIR
  383. exit 2
  384. fi
  385. # Move images from temporary directory to the current directory
  386. for im in "${image_types[@]}"
  387. do
  388. no_of_files=$(ls -afq build/${PROJECT_NAME}*.${im} | wc -l)
  389. if (( no_of_files > 0 )); then
  390. mv build/${PROJECT_NAME}*.${im} ${CURR_DIR}/
  391. sudo chown ${CURR_USER}:${CURR_USER} ${CURR_DIR}/*.${im}
  392. fi
  393. done
  394. # Remove the temporary directory
  395. rm -rf ${TEMPBUILD_DIR}
  396. cd ${CURR_DIR}
  397. clear
  398. if [[ $VARIANT != 'meshclient' && $VARIANT != 'meshusb' && $VARIANT != 'mesh' ]]; then
  399. echo $"
  400. Image was created.
  401. You will be able to log into it with:
  402. "
  403. if [[ $IMAGE_TYPE != "virtualbox"* && $IMAGE_TYPE != "qemu"* ]]; then
  404. echo $" ssh $USERNAME@$DEFAULT_DOMAIN_NAME -p $SSH_PORT
  405. Password: $PASSWORD
  406. "
  407. else
  408. if [[ $IMAGE_TYPE != "qemu"* ]]; then
  409. echo $" Username: $USERNAME
  410. Password: $PASSWORD
  411. "
  412. else
  413. if [[ $IMAGE_TYPE != "qemu-x86_64"* && $IMAGE_TYPE != "qemu-amd64"* ]]; then
  414. echo "qemu-system-i386 -m ${VM_MEMORY} $(ls ${PROJECT_NAME}*.qcow2)"
  415. else
  416. echo "qemu-system-x86_64 -m ${VM_MEMORY} $(ls ${PROJECT_NAME}*.qcow2)"
  417. fi
  418. echo $"
  419. Username: $USERNAME
  420. Password: $PASSWORD
  421. "
  422. fi
  423. fi
  424. else
  425. echo $"
  426. Image was created.
  427. "
  428. fi
  429. ls -lh ${PROJECT_NAME}*.img ${PROJECT_NAME}*.sig ${PROJECT_NAME}*.xz ${PROJECT_NAME}*.vdi ${PROJECT_NAME}*.qcow2
  430. # Remove the mesh script after use
  431. if [[ $VARIANT == "mesh"* ]]; then
  432. rm -f $CONFIG_FILENAME
  433. fi
  434. # record the default login credentials for later use
  435. echo $"Username: $USERNAME
  436. Password: $PASSWORD" > ${CURR_DIR}/${PROJECT_NAME}_login_credentials.txt
  437. chmod 600 ${CURR_DIR}/${PROJECT_NAME}_login_credentials.txt
  438. if [[ $IMAGE_TYPE != "virtualbox"* && $IMAGE_TYPE != "qemu"* ]]; then
  439. echo ''
  440. if [[ $VARIANT != 'meshclient' && $VARIANT != 'meshusb' ]]; then
  441. echo $'You can copy the image to a microSD card with:'
  442. else
  443. echo $'You can copy the image to a USB drive with:'
  444. fi
  445. echo ''
  446. echo " unxz -k ${PROJECT_NAME}*.img.xz"
  447. echo " sudo dd bs=1M if=${PROJECT_NAME}*.img of=/dev/sdX conv=fdatasync"
  448. echo ''
  449. fi
  450. exit 0