freedombone-app-turtl 24KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734
  1. #!/bin/bash
  2. # _____ _ _
  3. # | __|___ ___ ___ _| |___ _____| |_ ___ ___ ___
  4. # | __| _| -_| -_| . | . | | . | . | | -_|
  5. # |__| |_| |___|___|___|___|_|_|_|___|___|_|_|___|
  6. #
  7. # Freedom in the Cloud
  8. #
  9. # turtl app
  10. #
  11. # http://portallinux.es/instalacion-servidor-turtl-debian-8
  12. # http://framacloud.org/cultiver-son-jardin/installation-de-turtl/
  13. #
  14. # License
  15. # =======
  16. #
  17. # Copyright (C) 2016-2018 Bob Mottram <bob@freedombone.net>
  18. #
  19. # This program is free software: you can redistribute it and/or modify
  20. # it under the terms of the GNU Affero General Public License as published by
  21. # the Free Software Foundation, either version 3 of the License, or
  22. # (at your option) any later version.
  23. #
  24. # This program is distributed in the hope that it will be useful,
  25. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  26. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  27. # GNU Affero General Public License for more details.
  28. #
  29. # You should have received a copy of the GNU Affero General Public License
  30. # along with this program. If not, see <http://www.gnu.org/licenses/>.
  31. VARIANTS="full full-vim writer"
  32. IN_DEFAULT_INSTALL=0
  33. SHOW_ON_ABOUT=1
  34. TURTL_DOMAIN_NAME=
  35. TURTL_CODE=
  36. TURTL_ONION_PORT=8107
  37. TURTL_PORT=8181
  38. TURTL_REPO="https://github.com/turtl/api.git"
  39. TURTL_COMMIT='53e00a5583f52de8f86ef380fe11c176b5738dcf'
  40. TURTL_ADMIN_PASSWORD=
  41. TURTL_STORAGE_LIMIT_MB=100
  42. TURTL_BASE_DIR=/etc/turtl
  43. # part of a hack to enable/disable signups
  44. TURTL_SIGNUP_STRING='Signup a new user'
  45. turtl_users_file=$TURTL_BASE_DIR/api/controllers/users.lisp
  46. turtl_variables=(ONION_ONLY
  47. DEFAULT_DOMAIN_NAME
  48. TURTL_DOMAIN_NAME
  49. TURTL_CODE
  50. TURTL_STORAGE_LIMIT_MB
  51. DDNS_PROVIDER
  52. MY_EMAIL_ADDRESS
  53. MY_USERNAME)
  54. function logging_on_turtl {
  55. echo -n ''
  56. }
  57. function logging_off_turtl {
  58. echo -n ''
  59. }
  60. function change_password_turtl {
  61. echo -n ''
  62. # change_username="$1"
  63. # new_user_password="$2"
  64. }
  65. function remove_user_turtl {
  66. echo -n ''
  67. # remove_username="$1"
  68. }
  69. function add_user_turtl {
  70. # new_username="$1"
  71. # new_user_password="$2"
  72. echo '0'
  73. }
  74. function install_interactive_turtl {
  75. if [ ! "$ONION_ONLY" ]; then
  76. ONION_ONLY='no'
  77. fi
  78. if [[ $ONION_ONLY != "no" ]]; then
  79. TURTL_DOMAIN_NAME='notes.local'
  80. write_config_param "TURTL_DOMAIN_NAME" "$TURTL_DOMAIN_NAME"
  81. else
  82. function_check interactive_site_details
  83. interactive_site_details "turtl" "TURTL_DOMAIN_NAME" "TURTL_CODE"
  84. fi
  85. APP_INSTALLED=1
  86. }
  87. function turtl_disable_registrations {
  88. if grep -q "$TURTL_SIGNUP_STRING" $turtl_users_file; then
  89. if [ -f $turtl_users_file ]; then
  90. cp $turtl_users_file $TURTL_BASE_DIR/.users.lisp
  91. sed -i '/(route (:post "\/users") (req res)/,/(send-json res user))))/{//!d}' $turtl_users_file
  92. sed -i 's|(send-json res user))))|())|g' $turtl_users_file
  93. chown -R turtl:turtl $TURTL_BASE_DIR
  94. systemctl restart turtl
  95. fi
  96. fi
  97. }
  98. function turtl_enable_registrations {
  99. if ! grep -q "$TURTL_SIGNUP_STRING" $turtl_users_file; then
  100. if [ -f $TURTL_BASE_DIR/.users.lisp ]; then
  101. cp $TURTL_BASE_DIR/.users.lisp $turtl_users_file
  102. rm $TURTL_BASE_DIR/.users.lisp
  103. chown -R turtl:turtl $TURTL_BASE_DIR
  104. systemctl restart turtl
  105. fi
  106. fi
  107. }
  108. function configure_interactive_turtl_signups {
  109. # This implements a hack which removes or adds the function needed
  110. # to sign up new users. It should eventually be removed once that
  111. # capability exists within the api
  112. dialog --title $"Allow new turtl signups" \
  113. --backtitle $"Freedombone Control Panel" \
  114. --defaultno \
  115. --yesno $"\\nAllow registration of new users?" 10 60
  116. sel=$?
  117. case $sel in
  118. 0)
  119. turtl_enable_registrations
  120. dialog --title $"Allow new turtl signups" \
  121. --msgbox $"New turtl user registrations are now allowed" 6 60
  122. return;;
  123. 1)
  124. turtl_disable_registrations
  125. dialog --title $"Disable new turtl signups" \
  126. --msgbox $"New turtl user registrations are now disabled" 6 60
  127. return;;
  128. 255) return;;
  129. esac
  130. }
  131. function configure_interactive_turtl_storage {
  132. data=$(mktemp 2>/dev/null)
  133. dialog --title $"Change storage limit" \
  134. --backtitle $"Freedombone Control Panel" \
  135. --inputbox $"Enter a storage limit in megabytes." 8 75 "$TURTL_STORAGE_LIMIT_MB" 2>"$data"
  136. sel=$?
  137. case $sel in
  138. 0)
  139. STORAGE=$(<"$data")
  140. if [ ${#STORAGE} -gt 0 ]; then
  141. TURTL_STORAGE_LIMIT_MB=$STORAGE
  142. sed -i "s|defparameter *default-storage-limit*.*|defparameter *default-storage-limit* ${TURTL_STORAGE_LIMIT_MB})|g" $TURTL_BASE_DIR/api/config/config.lisp
  143. systemctl restart turtl
  144. dialog --title $"Change storage limit" \
  145. --msgbox $"Storage limit changed to ${TURTL_STORAGE_LIMIT_MB}M" 6 50
  146. fi
  147. ;;
  148. esac
  149. rm -f "$data"
  150. }
  151. function configure_interactive_turtl {
  152. data=$(mktemp 2>/dev/null)
  153. dialog --backtitle $"Freedombone Control Panel" \
  154. --title $"turtl app settings" \
  155. --radiolist $"Choose an operation:" 12 70 3 \
  156. 1 $"Enable/disable new user registrations" off \
  157. 2 $"Change storage limit" off \
  158. 3 $"Exit" on 2> "$data"
  159. sel=$?
  160. case $sel in
  161. 1) rm -f "$data"
  162. exit 1;;
  163. 255) rm -f "$data"
  164. exit 1;;
  165. esac
  166. case $(cat "$data") in
  167. 1) configure_interactive_turtl_signups;;
  168. 2) configure_interactive_turtl_storage;;
  169. 3) rm -f "$data"
  170. return;;
  171. esac
  172. rm -f "$data"
  173. }
  174. function reconfigure_turtl {
  175. if [ -d $TURTL_BASE_DIR/data ]; then
  176. rm -rf $TURTL_BASE_DIR/data/*
  177. fi
  178. }
  179. function upgrade_turtl {
  180. CURR_TURTL_COMMIT=$(get_completion_param "turtl commit")
  181. if [[ "$CURR_TURTL_COMMIT" == "$TURTL_COMMIT" ]]; then
  182. return
  183. fi
  184. read_config_param "TURTL_DOMAIN_NAME"
  185. function_check set_repo_commit
  186. set_repo_commit $TURTL_BASE_DIR/api "turtl commit" "$TURTL_COMMIT" $TURTL_REPO
  187. # this is used as a crude way of disabling signups and so
  188. # should be superceded in future
  189. if [ -f $TURTL_BASE_DIR/.users.lisp ]; then
  190. turtl_disable_registrations
  191. fi
  192. systemctl restart turtl
  193. nginx_dissite $TURTL_DOMAIN_NAME
  194. chown -R turtl:turtl $TURTL_BASE_DIR
  195. nginx_ensite $TURTL_DOMAIN_NAME
  196. }
  197. function backup_local_turtl {
  198. read_config_param "TURTL_DOMAIN_NAME"
  199. source_directory=$TURTL_BASE_DIR
  200. if [ -d $source_directory ]; then
  201. dest_directory=turtl
  202. function_check suspend_site
  203. suspend_site ${TURTL_DOMAIN_NAME}
  204. function_check backup_directory_to_usb
  205. backup_directory_to_usb $source_directory $dest_directory
  206. function_check restart_site
  207. restart_site
  208. fi
  209. source_directory=/var/lib/rethinkdb
  210. if [ -d $source_directory ]; then
  211. dest_directory=rethinkdb
  212. function_check suspend_site
  213. suspend_site ${TURTL_DOMAIN_NAME}
  214. function_check backup_directory_to_usb
  215. backup_directory_to_usb $source_directory $dest_directory
  216. function_check restart_site
  217. restart_site
  218. fi
  219. }
  220. function restore_local_turtl {
  221. read_config_param "TURTL_DOMAIN_NAME"
  222. if [ $TURTL_DOMAIN_NAME ]; then
  223. temp_restore_dir=/root/tempturtl
  224. restore_directory_from_usb $temp_restore_dir turtl
  225. if [ -d ${temp_restore_dir}/etc/turtl ]; then
  226. cp -r ${temp_restore_dir}/etc/turtl/* /etc/turtl/
  227. else
  228. cp -r ${temp_restore_dir}/* /etc/turtl/
  229. fi
  230. # shellcheck disable=SC2181
  231. if [ ! "$?" = "0" ]; then
  232. set_user_permissions
  233. backup_unmount_drive
  234. exit 36723
  235. fi
  236. rm -rf ${temp_restore_dir}
  237. chown -R turtl:turtl $TURTL_BASE_DIR
  238. temp_restore_dir=/root/temprethinkdb
  239. restore_directory_from_usb $temp_restore_dir rethinkdb
  240. if [ -d ${temp_restore_dir}/var/lib/rethinkdb ]; then
  241. cp -r ${temp_restore_dir}/var/lib/rethinkdb/* /var/lib/rethinkdb/
  242. else
  243. cp -r ${temp_restore_dir}/* /var/lib/rethinkdb/
  244. fi
  245. # shellcheck disable=SC2181
  246. if [ ! "$?" = "0" ]; then
  247. set_user_permissions
  248. backup_unmount_drive
  249. exit 378324
  250. fi
  251. rm -rf ${temp_restore_dir}
  252. fi
  253. }
  254. function backup_remote_turtl {
  255. read_config_param "TURTL_DOMAIN_NAME"
  256. if [ $TURTL_DOMAIN_NAME ]; then
  257. temp_backup_dir=$TURTL_BASE_DIR
  258. if [ -d $temp_backup_dir ]; then
  259. echo $"Backing up turtl"
  260. backup_directory_to_friend $temp_backup_dir turtl
  261. echo $"Backup of turtl complete"
  262. else
  263. echo $"turtl domain specified but not found in $temp_backup_dir"
  264. exit 68725
  265. fi
  266. temp_backup_dir=/var/lib/rethinkdb
  267. if [ -d $temp_backup_dir ]; then
  268. echo $"Backing up rethinkdb"
  269. backup_directory_to_friend $temp_backup_dir rethinkdb
  270. echo $"Backup of rethinkdb complete"
  271. fi
  272. fi
  273. }
  274. function restore_remote_turtl {
  275. read_config_param "TURTL_DOMAIN_NAME"
  276. if [ $TURTL_DOMAIN_NAME ]; then
  277. temp_restore_dir=/root/tempturtl
  278. mkdir $temp_restore_dir
  279. function_check restore_directory_from_friend
  280. restore_directory_from_friend $temp_restore_dir turtl
  281. if [ -d ${temp_restore_dir}/etc/turtl ]; then
  282. cp -r ${temp_restore_dir}/etc/turtl/* /etc/turtl/
  283. else
  284. cp -r ${temp_restore_dir}/* /etc/turtl/
  285. fi
  286. # shellcheck disable=SC2181
  287. if [ ! "$?" = "0" ]; then
  288. if [ -d /etc/turtl_previous ]; then
  289. mv /etc/turtl_previous $TURTL_BASE_DIR
  290. fi
  291. set_user_permissions
  292. exit 37823
  293. fi
  294. rm -rf ${temp_restore_dir}
  295. temp_restore_dir=/root/temprethinkdb
  296. mkdir $temp_restore_dir
  297. function_check restore_directory_from_friend
  298. restore_directory_from_friend $temp_restore_dir rethinkdb
  299. if [ -d ${temp_restore_dir}/var/lib/rethinkdb ]; then
  300. cp -r ${temp_restore_dir}/var/lib/rethinkdb/* /var/lib/rethinkdb/
  301. else
  302. cp -r ${temp_restore_dir}/* /var/lib/rethinkdb/
  303. fi
  304. # shellcheck disable=SC2181
  305. if [ ! "$?" = "0" ]; then
  306. set_user_permissions
  307. exit 26783
  308. fi
  309. rm -rf ${temp_restore_dir}
  310. fi
  311. }
  312. function remove_turtl {
  313. if [ ! -d $TURTL_BASE_DIR ]; then
  314. return
  315. fi
  316. systemctl stop turtl
  317. systemctl disable turtl
  318. rm /etc/systemd/system/turtl.service
  319. systemctl daemon-reload
  320. remove_rethinkdb
  321. remove_app turtl
  322. remove_completion_param install_turtl
  323. sed -i '/turtl/d' "$COMPLETION_FILE"
  324. nginx_dissite $TURTL_DOMAIN_NAME
  325. if [ -f /etc/nginx/sites-available/$TURTL_DOMAIN_NAME ]; then
  326. rm /etc/nginx/sites-available/$TURTL_DOMAIN_NAME
  327. fi
  328. remove_certs $TURTL_DOMAIN_NAME
  329. function_check remove_onion_service
  330. remove_onion_service turtl ${TURTL_ONION_PORT}
  331. function_check remove_ddns_domain
  332. remove_ddns_domain $TURTL_DOMAIN_NAME
  333. rm -rf /etc/rethinkdb
  334. rm -rf /var/lib/rethinkdb
  335. rm -rf $TURTL_BASE_DIR
  336. groupdel -f turtl
  337. userdel -r turtl
  338. }
  339. function turtl_setup {
  340. PIDFILE=${PIDFILE:-nil}
  341. BINDADDR=${BINDADDR:-0.0.0.0}
  342. BINDPORT=${BINDPORT:-8181}
  343. PROD_ERR_HANDLING=${PROD_ERR_HANDLING:-t}
  344. if [[ $ONION_ONLY == 'no' ]]; then
  345. FQDN=${FQDN:-$TURTL_DOMAIN_NAME}
  346. SITE_URL=${SITE_URL:-https://$TURTL_DOMAIN_NAME}
  347. else
  348. FQDN=${FQDN:-$TURTL_ONION_HOSTNAME}
  349. SITE_URL=${SITE_URL:-http://$TURTL_ONION_HOSTNAME}
  350. fi
  351. ADMIN_EMAIL=${ADMIN_EMAIL:-$MY_EMAIL_ADDRESS}
  352. EMAIL_FROM=${EMAIL_FROM:-noreply@$DEFAULT_DOMAIN_NAME}
  353. SMTP_USER=${SMTP_USER:-}
  354. SMTP_PASS=${SMTP_PASS:-}
  355. DISPLAY_ERRORS=${DISPLAY_ERRORS:-t}
  356. DEFAULT_STORAGE_LIMIT=${DEFAULT_STORAGE_LIMIT:-100}
  357. STORAGE_INVITE_CREDIT=${STORAGE_INVITE_CREDIT:-25}
  358. if [[ $ONION_ONLY == 'no' ]]; then
  359. LOCAL_UPLOAD_URL=${LOCAL_UPLOAD_URL:-https://$TURTL_DOMAIN_NAME}
  360. else
  361. LOCAL_UPLOAD_URL=${LOCAL_UPLOAD_URL:-http://$TURTL_ONION_HOSTNAME}
  362. fi
  363. LOCAL_UPLOAD_PATH=${LOCAL_UPLOAD_PATH:-"$TURTL_BASE_DIR/data"}
  364. AWS_S3_TOKEN=${AWS_S3_TOKEN:-(:token ''
  365. :secret ''
  366. :bucket ''
  367. :endpoint 'https://s3.amazonaws.com')}
  368. # generates the config-file
  369. cat << __ENDCONFIG__ > $TURTL_BASE_DIR/api/config/config.lisp
  370. (in-package :turtl)
  371. (defparameter *root* (asdf:system-relative-pathname :turtl #P""))
  372. (defparameter *pid-file* "${PIDFILE}")
  373. (defvar *server-bind* "${BINDADDR}")
  374. (defvar *server-port* ${BINDPORT})
  375. (defvar *db-name* "turtl")
  376. (defvar *db-host* "127.0.0.1")
  377. (defvar *db-port* 28015)
  378. (defvar *production-error-handling* ${PROD_ERR_HANDLING})
  379. (defvar *enable-hsts-header* nil)
  380. (defvar *site-url* "${SITE_URL}")
  381. (defvar *api-path* "")
  382. (defvar *admin-email* "${ADMIN_EMAIL}")
  383. (defvar *email-from* "${EMAIL_FROM}")
  384. (defvar *email-user* "${SMTP_USER}")
  385. (defvar *email-pass* "${SMTP_PASS}")
  386. (defvar *display-errors* ${DISPLAY_ERRORS})
  387. (defparameter *default-storage-limit* ${DEFAULT_STORAGE_LIMIT})
  388. (defparameter *storage-invite-credit* ${STORAGE_INVITE_CREDIT})
  389. (vom:config :turtl :info)
  390. (defvar *local-upload* "${LOCAL_UPLOAD_PATH}")
  391. (defvar *local-upload-url* "${LOCAL_UPLOAD_URL}")
  392. (defvar *amazon-s3* "${AWS_S3_TOKEN}")
  393. __ENDCONFIG__
  394. cat $TURTL_BASE_DIR/api/config/config.footer >> $TURTL_BASE_DIR/api/config/config.lisp
  395. # start the turtl server
  396. systemctl restart rethinkdb
  397. if [ ! -f $TURTL_BASE_DIR/quicklisp/setup.lisp ]; then
  398. echo $"$TURTL_BASE_DIR/quicklisp/setup.lisp was not found"
  399. exit 6238234
  400. fi
  401. { echo '[Unit]';
  402. echo 'Description=Note taking service';
  403. echo 'Documentation=http://turtl.it';
  404. echo 'Requires=network.target';
  405. echo 'Requires=rethinkdb.service';
  406. echo 'After=network.target';
  407. echo 'After=rethinkdb.service';
  408. echo '';
  409. echo '[Service]';
  410. echo 'Type=simple';
  411. echo 'User=turtl';
  412. echo "WorkingDirectory=$TURTL_BASE_DIR/api/"; } > /etc/systemd/system/turtl.service
  413. if [[ "$check_architecture" == *"64"* && "$check_architecture" != *"arm"* ]]; then
  414. echo "ExecStart=$TURTL_BASE_DIR/ccl/lx86cl64 -l $TURTL_BASE_DIR/quicklisp/setup.lisp -l launch.lisp" >> /etc/systemd/system/turtl.service
  415. else
  416. if [[ "$check_architecture" != *"arm"* ]]; then
  417. echo "ExecStart=$TURTL_BASE_DIR/ccl/lx86cl -l $TURTL_BASE_DIR/quicklisp/setup.lisp -l launch.lisp" >> /etc/systemd/system/turtl.service
  418. else
  419. echo "ExecStart=$TURTL_BASE_DIR/ccl/armcl -l $TURTL_BASE_DIR/quicklisp/setup.lisp -l launch.lisp" >> /etc/systemd/system/turtl.service
  420. fi
  421. fi
  422. { echo '';
  423. echo '[Install]';
  424. echo 'WantedBy=multi-user.target'; } >> /etc/systemd/system/turtl.service
  425. chmod +x /etc/systemd/system/turtl.service
  426. chown -R turtl:turtl $TURTL_BASE_DIR
  427. systemctl enable turtl
  428. systemctl daemon-reload
  429. systemctl start turtl
  430. }
  431. function install_turtl_api {
  432. # https://github.com/ArthurGarnier/turtl-docker
  433. apt-get -yq install wget libterm-readline-perl-perl gcc libuv1-dev
  434. if [ ! -d $TURTL_BASE_DIR ]; then
  435. mkdir -p $TURTL_BASE_DIR
  436. fi
  437. cd "$TURTL_BASE_DIR" || exit 745726542
  438. mkdir cd $TURTL_BASE_DIR/data
  439. check_architecture=$(uname -a)
  440. # Install ccl
  441. if [[ "$check_architecture" != *"arm"* ]]; then
  442. wget -P $TURTL_BASE_DIR/ ftp://ftp.clozure.com/pub/release/1.11/ccl-1.11-linuxx86.tar.gz
  443. mkdir -p $TURTL_BASE_DIR/ccl
  444. tar xvzf $TURTL_BASE_DIR/ccl-1.11-linuxx86.tar.gz -C $TURTL_BASE_DIR/ccl --strip-components=1
  445. else
  446. wget -P $TURTL_BASE_DIR/ ftp://ftp.clozure.com/pub/release/1.11/ccl-1.11-linuxarm.tar.gz
  447. mkdir -p $TURTL_BASE_DIR/ccl
  448. tar xvzf $TURTL_BASE_DIR/ccl-1.11-linuxarm.tar.gz -C $TURTL_BASE_DIR/ccl --strip-components=1
  449. fi
  450. # install quicklisp
  451. cat << __ENDCONFIG__ > $TURTL_BASE_DIR/quicklisp_install
  452. (load (compile-file "asdf.lisp"))
  453. (load (compile-file "quicklisp.lisp"))
  454. (quicklisp-quickstart:install)
  455. (ql:system-apropos "vecto")
  456. (ql:quickload "alexandria")
  457. (ql:quickload "babel")
  458. (ql:quickload "blackbird")
  459. (ql:quickload "bordeaux-threads")
  460. (ql:quickload "cffi")
  461. (ql:quickload "chipz")
  462. (ql:quickload "chunga")
  463. (ql:quickload "cl-annot")
  464. (ql:quickload "cl-async")
  465. (ql:quickload "cl-async-future")
  466. (ql:quickload "cl-base64")
  467. (ql:quickload "cl-fad")
  468. (ql:quickload "cl-libuv")
  469. (ql:quickload "cl-mongo-id")
  470. (ql:quickload "cl-ppcre")
  471. (ql:quickload "cl-rethinkdb")
  472. (ql:quickload "cl-smtp")
  473. (ql:quickload "cl+ssl")
  474. (ql:quickload "cl-syntax")
  475. (ql:quickload "cl-utilities")
  476. (ql:quickload "cl-vectors")
  477. (ql:quickload "do-urlencode")
  478. (ql:quickload "drakma")
  479. (ql:quickload "drakma-async")
  480. (ql:quickload "event-glue")
  481. (ql:quickload "fast-http")
  482. (ql:quickload "fast-io")
  483. (ql:quickload "flexi-streams")
  484. (ql:quickload "ironclad")
  485. (ql:quickload "jonathan")
  486. (ql:quickload "local-time")
  487. (ql:quickload "md5")
  488. (ql:quickload "named-readtables")
  489. (ql:quickload "nibbles")
  490. (ql:quickload "proc-parse")
  491. (ql:quickload "puri")
  492. (ql:quickload "quri")
  493. (ql:quickload "salza2")
  494. (ql:quickload "secure-random")
  495. (ql:quickload "smart-buffer")
  496. (ql:quickload "split-sequence")
  497. (ql:quickload "static-vectors")
  498. (ql:quickload "trivial-backtrace")
  499. (ql:quickload "trivial-features")
  500. (ql:quickload "trivial-garbage")
  501. (ql:quickload "trivial-gray-streams")
  502. (ql:quickload "trivial-types")
  503. (ql:quickload "usocket")
  504. (ql:quickload "vecto")
  505. (ql:quickload "vom")
  506. (ql:quickload "wookie")
  507. (ql:quickload "xmls")
  508. (ql:quickload "xsubseq")
  509. (ql:quickload "yason")
  510. (ql:quickload "zpb-ttf")
  511. (ql:quickload "zpng")
  512. (ql:add-to-init-file)
  513. (ccl::quit)
  514. __ENDCONFIG__
  515. if [ ! -f asdf.lisp ]; then
  516. wget https://common-lisp.net/project/asdf/asdf.lisp
  517. fi
  518. if [ ! -f quicklisp.lisp ]; then
  519. wget https://beta.quicklisp.org/quicklisp.lisp
  520. fi
  521. if [ -d $TURTL_BASE_DIR ]; then
  522. chown -R turtl:turtl $TURTL_BASE_DIR
  523. fi
  524. adduser --disabled-login --home=$TURTL_BASE_DIR --gecos 'turtl' turtl
  525. if [ ! -d $TURTL_BASE_DIR ]; then
  526. echo $"$TURTL_BASE_DIR directory not created"
  527. exit 263493
  528. fi
  529. groupadd turtl
  530. chown -R turtl:turtl $TURTL_BASE_DIR
  531. if [[ "$check_architecture" != *"arm"* ]]; then
  532. if [[ "$check_architecture" == *"64"* ]]; then
  533. su -c "cat $TURTL_BASE_DIR/quicklisp_install | $TURTL_BASE_DIR/ccl/lx86cl64" - turtl
  534. else
  535. su -c "cat $TURTL_BASE_DIR/quicklisp_install | $TURTL_BASE_DIR/ccl/lx86cl" - turtl
  536. fi
  537. else
  538. su -c "cat $TURTL_BASE_DIR/quicklisp_install | $TURTL_BASE_DIR/ccl/larmcl" - turtl
  539. fi
  540. rm $TURTL_BASE_DIR/quicklisp_install
  541. install_rethinkdb
  542. echo "http-port=8091" > /etc/rethinkdb/instances.d/turtl.conf
  543. chown -R rethinkdb:rethinkdb /var/lib/rethinkdb
  544. # install turtl API
  545. cd "$TURTL_BASE_DIR/" || exit 6428462
  546. if [ -d /repos/turtl ]; then
  547. mkdir $TURTL_BASE_DIR/api
  548. cp -r -p /repos/turtl/. $TURTL_BASE_DIR/api
  549. cd "$TURTL_BASE_DIR/api" || exit 57141845
  550. git pull
  551. else
  552. git clone $TURTL_REPO $TURTL_BASE_DIR/api
  553. fi
  554. cd "$TURTL_BASE_DIR/api" || exit 35814614
  555. git checkout $TURTL_COMMIT -b $TURTL_COMMIT
  556. set_completion_param "turtl commit" "$TURTL_COMMIT"
  557. cd "$TURTL_BASE_DIR/quicklisp/local-projects" || exit 43618941415
  558. git clone git://github.com/orthecreedence/cl-hash-util
  559. if [[ "$check_architecture" != *"arm"* ]]; then
  560. if [[ "$check_architecture" == *"64"* ]]; then
  561. su -c "cat '(ccl:quit)' | $TURTL_BASE_DIR/ccl/lx86cl64 -l $TURTL_BASE_DIR/quicklisp/setup.lisp" - turtl
  562. else
  563. su -c "cat '(ccl:quit)' | $TURTL_BASE_DIR/ccl/lx86cl -l $TURTL_BASE_DIR/quicklisp/setup.lisp" - turtl
  564. fi
  565. else
  566. su -c "cat '(ccl:quit)' | $TURTL_BASE_DIR/ccl/larmcl -l $TURTL_BASE_DIR/quicklisp/setup.lisp" - turtl
  567. fi
  568. # config
  569. { echo '(defvar *enabled-cors-resources* "resource://turtl-at-lyonbros-dot-com"';
  570. echo ' "When set, will enable CORS for resource:// origins if they match the given';
  571. echo ' string. Entries should be comma separated (this string is passed verbatim in';
  572. echo ' the Access-Control-Allow-Origin header).")';
  573. echo '(defparameter *public-actions*';
  574. echo " \`((:post . ,(concatenate 'string *api-path* \"/users\"))";
  575. echo " (:post . ,(concatenate 'string *api-path* \"/log/error\"))";
  576. echo ' (:post . "/cla/sign")';
  577. echo ' (:get . "/ping")';
  578. echo ' (:get . "/admin")';
  579. echo " (:get . ,(cl-ppcre:create-scanner (concatenate 'string *api-path* \"/invites/codes/([0-9a-f-]+)\"))))";
  580. echo " \"A list of public resources/actions that do not require authentication.\")";
  581. echo "(defvar *analytics* '(:enabled t";
  582. echo ' :db "analytics"))'; } > "$TURTL_BASE_DIR/api/config/config.footer"
  583. cp $TURTL_BASE_DIR/asdf.lisp $TURTL_BASE_DIR/api
  584. echo '(load (compile-file "asdf.lisp"))' > $TURTL_BASE_DIR/api/launch.lisp
  585. echo "(pushnew \"./\" asdf:*central-registry* :test #'equal)" >> $TURTL_BASE_DIR/api/launch.lisp
  586. echo '(load "start")' >> $TURTL_BASE_DIR/api/launch.lisp
  587. TURTL_ONION_HOSTNAME=$(add_onion_service turtl 80 ${TURTL_ONION_PORT})
  588. turtl_setup
  589. }
  590. function install_turtl_nginx {
  591. turtl_nginx_site=/etc/nginx/sites-available/$TURTL_DOMAIN_NAME
  592. if [[ $ONION_ONLY == "no" ]]; then
  593. function_check nginx_http_redirect
  594. nginx_http_redirect $TURTL_DOMAIN_NAME
  595. { echo 'server {';
  596. echo ' listen 443 ssl;';
  597. echo ' #listen [::]:443 ssl;';
  598. echo " server_name ${TURTL_DOMAIN_NAME};";
  599. echo '';
  600. echo ' # Security'; } >> "$turtl_nginx_site"
  601. function_check nginx_ssl
  602. nginx_ssl $TURTL_DOMAIN_NAME
  603. function_check nginx_security_options
  604. nginx_security_options $TURTL_DOMAIN_NAME
  605. { echo ' add_header Strict-Transport-Security max-age=15768000;';
  606. echo '';
  607. echo ' # Logs';
  608. echo ' access_log /dev/null;';
  609. echo ' error_log /dev/null;';
  610. echo '';
  611. echo ' location / {'; } >> "$turtl_nginx_site"
  612. function_check nginx_limits
  613. nginx_limits $TURTL_DOMAIN_NAME '15m'
  614. { echo " proxy_pass http://localhost:${TURTL_PORT}/;";
  615. echo " proxy_set_header Host \$host;";
  616. echo ' proxy_buffering off;';
  617. echo ' }';
  618. echo '}'; } >> "$turtl_nginx_site"
  619. else
  620. echo -n '' > $turtl_nginx_site
  621. fi
  622. { echo 'server {';
  623. echo " listen 127.0.0.1:${TURTL_ONION_PORT};";
  624. echo " server_name ${TURTL_ONION_HOSTNAME};";
  625. echo ''; } >> $turtl_nginx_site
  626. function_check nginx_security_options
  627. nginx_security_options $TURTL_DOMAIN_NAME
  628. { echo '';
  629. echo ' # Logs';
  630. echo ' access_log /dev/null;';
  631. echo ' error_log /dev/null;';
  632. echo '';
  633. echo ' location / {'; } >> $turtl_nginx_site
  634. function_check nginx_limits
  635. nginx_limits $TURTL_DOMAIN_NAME '15m'
  636. { echo " proxy_pass http://localhost:${TURTL_PORT}/;";
  637. echo " proxy_set_header Host \$host;";
  638. echo ' proxy_buffering off;';
  639. echo ' }';
  640. echo '}'; } >> $turtl_nginx_site
  641. function_check add_ddns_domain
  642. add_ddns_domain $TURTL_DOMAIN_NAME
  643. set_completion_param "turtl domain" "$TURTL_DOMAIN_NAME"
  644. function_check create_site_certificate
  645. create_site_certificate $TURTL_DOMAIN_NAME 'yes'
  646. function_check nginx_ensite
  647. nginx_ensite $TURTL_DOMAIN_NAME
  648. systemctl restart nginx
  649. }
  650. function install_turtl {
  651. install_turtl_api
  652. install_turtl_nginx
  653. APP_INSTALLED=1
  654. }