freedombone-image-mesh 45KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065
  1. #!/bin/bash
  2. #
  3. # .---. . .
  4. # | | |
  5. # |--- .--. .-. .-. .-.| .-. .--.--. |.-. .-. .--. .-.
  6. # | | (.-' (.-' ( | ( )| | | | )( )| | (.-'
  7. # ' ' --' --' -' - -' ' ' -' -' -' ' - --'
  8. #
  9. # Freedom in the Cloud
  10. #
  11. # This command is run on initial install in order to set up a mesh router
  12. #
  13. # License
  14. # =======
  15. #
  16. # This program is free software: you can redistribute it and/or modify
  17. # it under the terms of the GNU Affero General Public License as published by
  18. # the Free Software Foundation, either version 3 of the License, or
  19. # (at your option) any later version.
  20. #
  21. # This program is distributed in the hope that it will be useful,
  22. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  23. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  24. # GNU Affero General Public License for more details.
  25. #
  26. # You should have received a copy of the GNU Affero General Public License
  27. # along with this program. If not, see <http://www.gnu.org/licenses/>.
  28. PROJECT_NAME='freedombone'
  29. export TEXTDOMAIN=${PROJECT_NAME}-image-mesh
  30. export TEXTDOMAINDIR="/usr/share/locale"
  31. # The browser application to use
  32. BROWSER=midori
  33. BROWSER_OPTIONS='-p'
  34. MY_USERNAME='fbone'
  35. PEER_ID=
  36. INSTALL_DIR=/root/build
  37. INSTALL_LOG=/var/log/${PROJECT_NAME}.log
  38. DEFAULT_USERNAME=fbone
  39. TOX_NODES=
  40. #TOX_NODES=(
  41. # '192.254.75.102,2607:5600:284::2,33445,951C88B7E75C867418ACDB5D273821372BB5BD652740BCDF623A4FA293E75D2F,Tox RELENG,US'
  42. # '144.76.60.215,2a01:4f8:191:64d6::1,33445,04119E835DF3E78BACF0F84235B300546AF8B936F035185E2A8E9E0A67C8924F,sonOfRa,DE'
  43. #)
  44. MESH_INSTALL_DIR=/var/lib
  45. MESH_INSTALL_COMPLETED=/root/.mesh_setup_completed
  46. MESH_INSTALL_SETUP=/root/.initial_mesh_setup
  47. MESH_AMNESIC=/root/.amnesic
  48. FIRST_BOOT=/home/$MY_USERNAME/.first_boot
  49. # Tomb containing logs
  50. TOMB_LOG_SIZE_MB=10
  51. # tmp directory
  52. TOMB_TMP_SIZE_MB=10
  53. # size of the tomb used to store qtox settings
  54. TOMB_TOX_SIZE_MB=10
  55. # Tomb containing tox bootstrap
  56. TOMB_TOX_BOOTSTRAP_SIZE_MB=10
  57. MESH_INSTALL_DIR=/var/lib
  58. IPFS_PORT=4001
  59. CURRENT_BLOG_INDEX=/home/$MY_USERNAME/.blog-index
  60. OPENVPN_SERVER_NAME="server"
  61. OPENVPN_KEY_FILENAME='client.ovpn'
  62. VPN_COUNTRY_CODE="US"
  63. VPN_AREA="Apparent Free Speech Zone"
  64. VPN_LOCATION="Freedomville"
  65. VPN_ORGANISATION="Freedombone"
  66. VPN_UNIT="Freedombone Unit"
  67. STUNNEL_PORT=3439
  68. VPN_TLS_PORT=553
  69. VPN_MESH_TLS_PORT=653
  70. SCUTTLEBOT_PORT=8010
  71. CRYPTPAD_PORT=9003
  72. CRYPTPAD_DIR=/etc/cryptpad
  73. function enable_cryptpad {
  74. if [ ! -d $CRYPTPAD_DIR ]; then
  75. return
  76. fi
  77. # Set up the web server
  78. ln -s /etc/nginx/sites-available/cryptpad /etc/nginx/sites-enabled/cryptpad
  79. rm /etc/nginx/sites-enabled/default
  80. if [ ! -d $CRYPTPAD_DIR/customize/api ]; then
  81. mkdir -p $CRYPTPAD_DIR/customize/api
  82. fi
  83. wget 127.0.0.1:$CRYPTPAD_PORT/api/config -O $CRYPTPAD_DIR/customize/api/config
  84. if [ ! -f $CRYPTPAD_DIR/customize/api/config ]; then
  85. echo $'Unable to wget api/config'
  86. exit 89252
  87. fi
  88. chown -R cryptpad:cryptpad $CRYPTPAD_DIR
  89. }
  90. # Debian stretch has a problem where the formerly predictable wlan0 and eth0
  91. # device names get assigned random names. This is a hacky workaround.
  92. # Also adding net.ifnames=0 to kernel options on bootloader may work.
  93. function enable_predictable_device_names {
  94. ln -s /dev/null /etc/udev/rules.d/80-net-setup-link.rules
  95. update-initramfs -u
  96. }
  97. function create_avahi_mesh_service {
  98. service_name=$1
  99. service_type=$2
  100. service_protocol=$3
  101. service_port=$4
  102. service_description="$5"
  103. if [ ! -d /etc/avahi ]; then
  104. echo $'create_avahi_mesh_service: avahi was not installed'
  105. exit 52925
  106. fi
  107. echo '<?xml version="1.0" standalone="no"?><!--*-nxml-*-->' > /etc/avahi/services/${service_name}.service
  108. echo '<!DOCTYPE service-group SYSTEM "avahi-service.dtd">' >> /etc/avahi/services/${service_name}.service
  109. echo '<service-group>' >> /etc/avahi/services/${service_name}.service
  110. echo " <name replace-wildcards=\"yes\">%h ${service_type}</name>" >> /etc/avahi/services/${service_name}.service
  111. echo ' <service>' >> /etc/avahi/services/${service_name}.service
  112. echo " <type>_${service_type}._${service_protocol}</type>" >> /etc/avahi/services/${service_name}.service
  113. echo " <port>${service_port}</port>" >> /etc/avahi/services/${service_name}.service
  114. echo " <txt-record>$service_description</txt-record>" >> /etc/avahi/services/${service_name}.service
  115. echo ' </service>' >> /etc/avahi/services/${service_name}.service
  116. echo '</service-group>' >> /etc/avahi/services/${service_name}.service
  117. }
  118. function create_ram_disk {
  119. ramdisk_size_mb=$1
  120. if [ ! -d /mnt/ramdisk ]; then
  121. mkdir -p /mnt/ramdisk
  122. fi
  123. if ! grep -q "ramdisk" /etc/fstab; then
  124. mount -t tmpfs -o size=${ramdisk_size_mb}m tmpfs /mnt/ramdisk
  125. echo "tmpfs /mnt/ramdisk tmpfs nodev,nosuid,noexec,nodiratime,size=${ramdisk_size_mb}M 0 0" >> /etc/fstab
  126. echo $"${ramdisk_size_mb}M ramdisk created for /tmp" >> $INSTALL_LOG
  127. fi
  128. }
  129. function make_root_read_only {
  130. if [ ! -d /home/$MY_USERNAME/Desktop ]; then
  131. if ! grep -q 'ro,subvol=@' /etc/fstab; then
  132. sed -i 's|subvol=@|ro,subvol=@|g' /etc/fstab
  133. echo $'Root filesystem set to read only' >> $INSTALL_LOG
  134. fi
  135. fi
  136. }
  137. function tmp_ram_disk {
  138. ramdisk_size_mb=$1
  139. if [ ! -d /tmp ]; then
  140. mkdir -p /tmp
  141. fi
  142. if ! grep -q '/tmp' /etc/fstab; then
  143. mount -t tmpfs -o size=${ramdisk_size_mb}m tmpfs /tmp
  144. echo "tmpfs /tmp tmpfs nodev,nosuid,noexec,nodiratime,size=${ramdisk_size_mb}M 0 0" >> /etc/fstab
  145. fi
  146. }
  147. function set_hostname {
  148. DEFAULT_DOMAIN_NAME="$1"
  149. echo "$DEFAULT_DOMAIN_NAME" > /etc/hostname
  150. echo "$DEFAULT_DOMAIN_NAME" > /etc/mailname
  151. hostname $DEFAULT_DOMAIN_NAME
  152. if grep -q "127.0.1.1" /etc/hosts; then
  153. sed -i "s/127.0.1.1.*/127.0.1.1 $DEFAULT_DOMAIN_NAME/g" /etc/hosts
  154. else
  155. echo "127.0.1.1 $DEFAULT_DOMAIN_NAME" >> /etc/hosts
  156. fi
  157. }
  158. function change_avahi_name {
  159. decarray=( 1 2 3 4 5 6 7 8 9 0 )
  160. PEER_ID=${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}${decarray[$RANDOM%10]}
  161. sed -i "s|#host-name=.*|host-name=P$PEER_ID|g" /etc/avahi/avahi-daemon.conf
  162. sed -i "s|host-name=.*|host-name=P$PEER_ID|g" /etc/avahi/avahi-daemon.conf
  163. set_hostname P$PEER_ID
  164. systemctl restart avahi-daemon
  165. echo "New avahi name for this peer is P$PEER_ID"
  166. echo $"avahi name changed to P${PEER_ID}.local" >> $INSTALL_LOG
  167. }
  168. function configure_toxcore {
  169. echo $'Configuring toxcore' >> $INSTALL_LOG
  170. TOXIC_FILE=$(cat /usr/share/${PROJECT_NAME}/apps/${PROJECT_NAME}-app-tox | grep "TOXIC_FILE=" | head -n 1 | awk -F '=' '{print $2}')
  171. if [ -f $MESH_AMNESIC ]; then
  172. # change to the amnesic mount
  173. sed -i 's|/var/lib/tox-bootstrapd|/media/tox-bootstrapd|g' /etc/tox-bootstrapd.conf
  174. systemctl stop tox-bootstrapd.service
  175. sed -i 's|WorkingDirectory=.*|WorkingDirectory=/media/tox-bootstrapd|g' /etc/systemd/system/tox-bootstrapd.service
  176. systemctl daemon-reload
  177. userdel -r tox-bootstrapd
  178. useradd --home-dir /media/tox-bootstrapd --create-home --system --shell /sbin/nologin --comment "Account to run Tox's DHT bootstrap daemon" --user-group tox-bootstrapd
  179. chmod 700 /media/tox-bootstrapd
  180. fi
  181. echo $'Enabling toxcore daemon' >> $INSTALL_LOG
  182. chmod +x /etc/systemd/system/tox-bootstrapd.service
  183. systemctl enable tox-bootstrapd.service
  184. echo $'Regenerating Tox bootstrap node keys' >> $INSTALL_LOG
  185. systemctl stop tox-bootstrapd.service
  186. if [ -f /var/lib/tox-bootstrapd/keys ]; then
  187. rm /var/lib/tox-bootstrapd/keys
  188. fi
  189. systemctl start tox-bootstrapd.service
  190. # sleep for a while so that the tox keys can be generated
  191. sleep 30
  192. TOX_BOOTSTRAP_ID_FILE=/var/lib/tox-bootstrapd/pubkey.txt
  193. if [ -f $MESH_AMNESIC ]; then
  194. TOX_BOOTSTRAP_ID_FILE=/media/tox-bootstrapd/pubkey.txt
  195. fi
  196. TOX_PUBLIC_KEY=$(cat /var/log/syslog | grep tox | grep "Public Key" | awk -F ' ' '{print $8}' | tail -1)
  197. if [ ${#TOX_PUBLIC_KEY} -lt 30 ]; then
  198. echo $'WARNING: Could not obtain the tox node public key' >> $INSTALL_LOG
  199. exit 46362
  200. fi
  201. # save the public key for later reference
  202. echo "$TOX_PUBLIC_KEY" > $TOX_BOOTSTRAP_ID_FILE
  203. echo $'Configured toxcore' >> $INSTALL_LOG
  204. }
  205. function create_tox_user {
  206. # remove any existing user
  207. if [ -f /home/${MY_USERNAME}/.config/tox/data.tox ]; then
  208. rm -f /home/${MY_USERNAME}/.config/tox/data*
  209. fi
  210. if [ -d /home/${MY_USERNAME}/.config/tox/avatars ]; then
  211. rm -rf /home/${MY_USERNAME}/.config/tox/avatars
  212. fi
  213. if [ ! -f /home/${MY_USERNAME}/.first_boot ]; then
  214. touch /home/${MY_USERNAME}/.first_boot
  215. fi
  216. if [ ! -d /home/$MY_USERNAME/Desktop ]; then
  217. return
  218. fi
  219. toxid -u $MY_USERNAME -n data
  220. chown -R ${MY_USERNAME}:${MY_USERNAME} /home/${MY_USERNAME}/.config/tox
  221. chmod +x /home/$MY_USERNAME/Desktop/*.desktop
  222. chown ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/Desktop/*
  223. echo $'Created Tox user' >> $INSTALL_LOG
  224. }
  225. function show_desktop_icons {
  226. if [ ! -d /home/$MY_USERNAME/Desktop ]; then
  227. return
  228. fi
  229. echo '#!/bin/bash' > /home/$MY_USERNAME/.showhelp
  230. echo "pkill $BROWSER" >> /home/$MY_USERNAME/.showhelp
  231. echo "$BROWSER $BROWSER_OPTIONS /home/$MY_USERNAME/help/mesh.html" >> /home/$MY_USERNAME/.showhelp
  232. chmod +x /home/$MY_USERNAME/.showhelp
  233. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/.showhelp
  234. echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/help.desktop
  235. echo 'Version=1.0' >> /home/$MY_USERNAME/Desktop/help.desktop
  236. echo 'Name=Help' >> /home/$MY_USERNAME/Desktop/help.desktop
  237. echo "Name[el]=Βοήθεια" >> /home/$MY_USERNAME/Desktop/help.desktop
  238. echo "Name[ar]=مساعدة" >> /home/$MY_USERNAME/Desktop/help.desktop
  239. echo "Name[ca]=Ajuda" >> /home/$MY_USERNAME/Desktop/help.desktop
  240. echo "Name[hi]=मदद" >> /home/$MY_USERNAME/Desktop/help.desktop
  241. echo "Name[fr]=Aidez-moi" >> /home/$MY_USERNAME/Desktop/help.desktop
  242. echo "Name[de]=Hilfe" >> /home/$MY_USERNAME/Desktop/help.desktop
  243. echo "Name[es]=Ayuda" >> /home/$MY_USERNAME/Desktop/help.desktop
  244. echo "Name[it]=Aiuto" >> /home/$MY_USERNAME/Desktop/help.desktop
  245. echo "Name[ru]=Помогите" >> /home/$MY_USERNAME/Desktop/help.desktop
  246. echo "Name[zh]=帮帮我" >> /home/$MY_USERNAME/Desktop/help.desktop
  247. echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/help.desktop
  248. echo 'Comment=Show help' >> /home/$MY_USERNAME/Desktop/help.desktop
  249. echo "Comment[el]=Εμφάνιση βοήθειας" >> /home/$MY_USERNAME/Desktop/help.desktop
  250. echo "Comment[ar]=عرض المساعدة" >> /home/$MY_USERNAME/Desktop/help.desktop
  251. echo "Comment[ca]=Mostra ajuda" >> /home/$MY_USERNAME/Desktop/help.desktop
  252. echo "Comment[hi]=मदद दिखायें" >> /home/$MY_USERNAME/Desktop/help.desktop
  253. echo "Comment[fr]=Afficher l'aide" >> /home/$MY_USERNAME/Desktop/help.desktop
  254. echo "Comment[de]=Zeig Hilfe" >> /home/$MY_USERNAME/Desktop/help.desktop
  255. echo "Comment[es]=Mostrar ayuda" >> /home/$MY_USERNAME/Desktop/help.desktop
  256. echo "Comment[it]=Mostra aiuto" >> /home/$MY_USERNAME/Desktop/help.desktop
  257. echo "Comment[ru]=Показать справку" >> /home/$MY_USERNAME/Desktop/help.desktop
  258. echo "Comment[zh]=显示帮助" >> /home/$MY_USERNAME/Desktop/help.desktop
  259. echo "Exec=bash -c /home/$MY_USERNAME/.showhelp" >> /home/$MY_USERNAME/Desktop/help.desktop
  260. echo "Icon=/usr/share/${PROJECT_NAME}/avatars/icon_help.png" >> /home/$MY_USERNAME/Desktop/help.desktop
  261. echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/help.desktop
  262. echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/help.desktop
  263. echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/wifi.desktop
  264. echo 'Version=1.0' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  265. echo 'Name=Wifi' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  266. echo "Name[el]=Wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  267. echo "Name[ar]=واي فاي" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  268. echo "Name[ca]=Wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  269. echo "Name[hi]=वाई - फाई" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  270. echo "Name[fr]=Wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  271. echo "Name[de]=W-lan" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  272. echo "Name[es]=Wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  273. echo "Name[it]=Wi-Fi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  274. echo "Name[ru]=вай-фай" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  275. echo "Name[zh]=无线上网" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  276. echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  277. echo 'Comment=Check wifi status' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  278. echo "Comment[el]=Ελέγξτε την κατάσταση wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  279. echo "Comment[ar]=التحقق من حالة واي فاي" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  280. echo "Comment[ca]=Comprova l'estat de wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  281. echo "Comment[hi]=वाईफ़ाई स्थिति की जांच करें" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  282. echo "Comment[fr]=Vérifier l'état du wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  283. echo "Comment[de]=WLAN-Status überprüfen" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  284. echo "Comment[es]=Verificar el estado del wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  285. echo "Comment[it]=Controllare lo stato wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  286. echo "Comment[ru]=Проверить статус wifi" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  287. echo "Comment[zh]=检查wifi状态" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  288. echo 'Exec=mate-terminal --full-screen -e "sudo batman monitor"' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  289. echo "Icon=/usr/share/${PROJECT_NAME}/avatars/icon_wifi.png" >> /home/$MY_USERNAME/Desktop/wifi.desktop
  290. echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  291. echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/wifi.desktop
  292. echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/restart.desktop
  293. echo 'Version=1.0' >> /home/$MY_USERNAME/Desktop/restart.desktop
  294. echo 'Name=Network Restart' >> /home/$MY_USERNAME/Desktop/restart.desktop
  295. echo "Name[el]=Δικτυακή επανεκκίνηση" >> /home/$MY_USERNAME/Desktop/restart.desktop
  296. echo "Name[ar]=إعادة تشغيل الشبكة" >> /home/$MY_USERNAME/Desktop/restart.desktop
  297. echo "Name[ca]=Reinicia la xarxa" >> /home/$MY_USERNAME/Desktop/restart.desktop
  298. echo "Name[hi]=नेटवर्क पुनरारंभ करें" >> /home/$MY_USERNAME/Desktop/restart.desktop
  299. echo "Name[fr]=Redémarrage du réseau" >> /home/$MY_USERNAME/Desktop/restart.desktop
  300. echo "Name[de]=Netzwerk Neustart" >> /home/$MY_USERNAME/Desktop/restart.desktop
  301. echo "Name[es]=Reinicio de red" >> /home/$MY_USERNAME/Desktop/restart.desktop
  302. echo "Name[it]=Riavvia rete" >> /home/$MY_USERNAME/Desktop/restart.desktop
  303. echo "Name[ru]=Перезапуск сети" >> /home/$MY_USERNAME/Desktop/restart.desktop
  304. echo "Name[zh]=网络重新启动" >> /home/$MY_USERNAME/Desktop/restart.desktop
  305. echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/restart.desktop
  306. echo 'Comment=Restart the mesh network daemon' >> /home/$MY_USERNAME/Desktop/restart.desktop
  307. echo "Comment[el]=Κάντε επανεκκίνηση του δαίμονα του δικτύου ματιών" >> /home/$MY_USERNAME/Desktop/restart.desktop
  308. echo "Comment[ar]=إعادة تشغيل شبكة شبكة الخفي" >> /home/$MY_USERNAME/Desktop/restart.desktop
  309. echo "Comment[ca]=Reinicia el dimoni de la xarxa de malla" >> /home/$MY_USERNAME/Desktop/restart.desktop
  310. echo "Comment[hi]=जाल नेटवर्क डेमॉन को पुनरारंभ करें" >> /home/$MY_USERNAME/Desktop/restart.desktop
  311. echo "Comment[fr]=Redémarrez le démon réseau maillé" >> /home/$MY_USERNAME/Desktop/restart.desktop
  312. echo "Comment[de]=Starten Sie den Mesh-Netzwerk-Daemon neu." >> /home/$MY_USERNAME/Desktop/restart.desktop
  313. echo "Comment[es]=Reinicie el daemon de red de malla" >> /home/$MY_USERNAME/Desktop/restart.desktop
  314. echo "Comment[it]=Riavviare il daemon della rete mesh" >> /home/$MY_USERNAME/Desktop/restart.desktop
  315. echo "Comment[ru]=Перезапустить демон сетчатой сети" >> /home/$MY_USERNAME/Desktop/restart.desktop
  316. echo "Comment[zh]=重新启动网状网络守护程序" >> /home/$MY_USERNAME/Desktop/restart.desktop
  317. echo 'Exec=mate-terminal -e "sudo batman restart 2> /dev/null"' >> /home/$MY_USERNAME/Desktop/restart.desktop
  318. echo "Icon=/usr/share/${PROJECT_NAME}/avatars/icon_restart_network.png" >> /home/$MY_USERNAME/Desktop/restart.desktop
  319. echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/restart.desktop
  320. echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/restart.desktop
  321. echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/new_identity.desktop
  322. echo 'Version=1.0' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  323. echo 'Name=New Identity' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  324. echo "Name[el]=Νέα ταυτότητα" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  325. echo "Name[ar]=هوية جديدة" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  326. echo "Name[ca]=Nova identitat" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  327. echo "Name[hi]=नई पहचान" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  328. echo "Name[fr]=Nouvelle identité" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  329. echo "Name[de]=Neue Identität" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  330. echo "Name[es]=Nueva identidad" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  331. echo "Name[it]=Nuova Identità" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  332. echo "Name[ru]=Новая идентификация" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  333. echo "Name[zh]=新身份" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  334. echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  335. echo 'Comment=Create a new identity' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  336. echo "Comment[el]=Δημιουργήστε μια νέα ταυτότητα" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  337. echo "Comment[ar]=إنشاء هوية جديدة" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  338. echo "Comment[ca]=Crea una nova identitat" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  339. echo "Comment[hi]=एक नई पहचान बनाएँ" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  340. echo "Comment[fr]=Créer une nouvelle identité" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  341. echo "Comment[de]=Erstellen Sie eine neue Identität" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  342. echo "Comment[es]=Crea una nueva identidad" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  343. echo "Comment[it]=Crea una nuova identità" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  344. echo "Comment[ru]=Создайте новое удостоверение личности" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  345. echo "Comment[zh]=创建一个新的身份" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  346. echo "Exec=mate-terminal --full-screen -e ${PROJECT_NAME}-mesh-reset" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  347. echo "Icon=/usr/share/${PROJECT_NAME}/avatars/icon_new_identity.png" >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  348. echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  349. echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/new_identity.desktop
  350. echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/social.desktop
  351. echo 'Name=Social' >> /home/$MY_USERNAME/Desktop/social.desktop
  352. echo 'Name[el]=Κοινωνικός' >> /home/$MY_USERNAME/Desktop/social.desktop
  353. echo 'Name[ar]=اجتماعي' >> /home/$MY_USERNAME/Desktop/social.desktop
  354. echo 'Name[ca]=Social' >> /home/$MY_USERNAME/Desktop/social.desktop
  355. echo 'Name[hi]=सामाजिक' >> /home/$MY_USERNAME/Desktop/social.desktop
  356. echo 'Name[fr]=Social' >> /home/$MY_USERNAME/Desktop/social.desktop
  357. echo 'Name[de]=Soziale' >> /home/$MY_USERNAME/Desktop/social.desktop
  358. echo 'Name[es]=Social' >> /home/$MY_USERNAME/Desktop/social.desktop
  359. echo 'Name[it]=Sociale' >> /home/$MY_USERNAME/Desktop/social.desktop
  360. echo 'Name[ru]=Социальное' >> /home/$MY_USERNAME/Desktop/social.desktop
  361. echo 'Name[zh]=社会' >> /home/$MY_USERNAME/Desktop/social.desktop
  362. echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/social.desktop
  363. echo "Comment=A decentralized messaging and sharing app built on top of Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  364. echo "Comment[el]=Μια αποκεντρωμένη εφαρμογή ανταλλαγής μηνυμάτων και κοινής χρήσης που είναι ενσωματωμένη στην κορυφή του Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  365. echo "Comment[ar]=والرسائل اللامركزية وتبادل التطبيق بنيت على رأس سكوتليبوت الآمنة (سب)" >> /home/$MY_USERNAME/Desktop/social.desktop
  366. echo "Comment[ca]=Una aplicació de missatgeria i distribució descentralitzada integrada a Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  367. echo "Comment[hi]=सिक्योर स्कूटलबट (एसएसबी) के शीर्ष पर निर्मित एक विकेन्द्रीकृत संदेश और साझाकरण ऐप" >> /home/$MY_USERNAME/Desktop/social.desktop
  368. echo "Comment[fr]=Une application de messagerie et de partage décentralisée basée sur Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  369. echo "Comment[de]=Eine dezentralisierte Messaging- und Sharing-App, die auf Secure Scuttlebutt basiert" >> /home/$MY_USERNAME/Desktop/social.desktop
  370. echo "Comment[es]=Una aplicación de mensajería y uso compartido descentralizada construida sobre Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  371. echo "Comment[it]=Un'applicazione decentralizzata di messaggistica e condivisione costruita sulla base di Secure Shuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  372. echo "Comment[ru]=Децентрализованное приложение для обмена сообщениями и совместного использования, построенное на основе Secure Scuttlebutt" >> /home/$MY_USERNAME/Desktop/social.desktop
  373. echo "Comment[zh]=安全Scuttlebutt之上构建的分散式消息和共享应用程序" >> /home/$MY_USERNAME/Desktop/social.desktop
  374. echo 'Exec=bash /usr/bin/start_patchwork' >> /home/$MY_USERNAME/Desktop/social.desktop
  375. echo "Icon=/usr/share/$PROJECT_NAME/avatars/icon_social.png" >> /home/$MY_USERNAME/Desktop/social.desktop
  376. echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/social.desktop
  377. echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/social.desktop
  378. #echo '[Desktop Entry]' > /home/$MY_USERNAME/Desktop/audio.desktop
  379. #echo 'Name=Audio/Music' >> /home/$MY_USERNAME/Desktop/audio.desktop
  380. #echo 'Type=Application' >> /home/$MY_USERNAME/Desktop/audio.desktop
  381. #echo 'Comment=Audio publishing and streaming' >> /home/$MY_USERNAME/Desktop/audio.desktop
  382. #echo 'Exec=bash /usr/bin/start_ferment' >> /home/$MY_USERNAME/Desktop/audio.desktop
  383. #echo "Icon=/etc/patchwork/icon_ferment.png" >> /home/$MY_USERNAME/Desktop/audio.desktop
  384. #echo 'Terminal=false' >> /home/$MY_USERNAME/Desktop/audio.desktop
  385. #echo 'Categories=Application;' >> /home/$MY_USERNAME/Desktop/audio.desktop
  386. # set permissions
  387. chmod +x /home/$MY_USERNAME/Desktop/*.desktop
  388. chown ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/Desktop/*
  389. chown ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/.config
  390. chown -R ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/.config/tox
  391. chown -R ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/.config/autostart
  392. chown ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/*.sh
  393. # link to Tahoe-LAFS Magic folder
  394. #ln -s /home/${MY_USERNAME}/Desktop/${TAHOELAFS_SHARED_DIR} /home/${MY_USERNAME}/${TAHOELAFS_SHARED_DIR}
  395. # restart caja
  396. killall caja
  397. killall mate-panel
  398. }
  399. function enable_batman_daemon {
  400. systemctl enable batman
  401. systemctl daemon-reload
  402. }
  403. function mesh_amnesic {
  404. if [ ! -f $MESH_AMNESIC ]; then
  405. return
  406. fi
  407. echo '#!/bin/bash' > /usr/bin/amnesic
  408. echo '' >> /usr/bin/amnesic
  409. echo 'MY_USERNAME=$1' >> /usr/bin/amnesic
  410. echo 'tomb slam all' >> /usr/bin/amnesic
  411. echo "if [ -f /home/${MY_USERNAME}/.bash_history ]; then" >> /usr/bin/amnesic
  412. echo " shred -zu /home/${MY_USERNAME}/.bash_history" >> /usr/bin/amnesic
  413. echo 'fi' >> /usr/bin/amnesic
  414. echo "if [ -f /home/${MY_USERNAME}/.xsession-errors ]; then" >> /usr/bin/amnesic
  415. echo " shred -zu /home/${MY_USERNAME}/.xsession-errors" >> /usr/bin/amnesic
  416. echo 'fi' >> /usr/bin/amnesic
  417. echo '' >> /usr/bin/amnesic
  418. echo 'exit 0' >> /usr/bin/amnesic
  419. chmod +x /usr/bin/amnesic
  420. if [ ! -f /etc/systemd/system/amnesic.service ]; then
  421. echo '[Unit]' > /etc/systemd/system/amnesic.service
  422. echo 'Description=Amnesic Mesh' >> /etc/systemd/system/amnesic.service
  423. echo '' >> /etc/systemd/system/amnesic.service
  424. echo '[Service]' >> /etc/systemd/system/amnesic.service
  425. echo 'User=root' >> /etc/systemd/system/amnesic.service
  426. echo 'Group=root' >> /etc/systemd/system/amnesic.service
  427. echo 'Type=oneshot' >> /etc/systemd/system/amnesic.service
  428. echo 'RemainAfterExit=true' >> /etc/systemd/system/amnesic.service
  429. echo 'ExecStart=/bin/true' >> /etc/systemd/system/amnesic.service
  430. echo "ExecStop=/usr/bin/amnesic $MY_USERNAME" >> /etc/systemd/system/amnesic.service
  431. echo '' >> /etc/systemd/system/amnesic.service
  432. echo '[Install]' >> /etc/systemd/system/amnesic.service
  433. echo 'WantedBy=multi-user.target' >> /etc/systemd/system/amnesic.service
  434. chmod +x /etc/systemd/system/amnesic.service
  435. systemctl daemon-reload
  436. fi
  437. systemctl enable amnesic
  438. systemctl start amnesic
  439. }
  440. function mesh_restart_daemons {
  441. systemctl restart avahi-daemon
  442. systemctl restart tox-bootstrapd
  443. echo $'Daemons restarted' >> $INSTALL_LOG
  444. }
  445. function create_tomb {
  446. tomb_name=$1
  447. tomb_size=$2
  448. if [ -f /tmp/${tomb_name}.tomb ]; then
  449. tomb slam /tmp/${tomb_name}.tomb
  450. fi
  451. # make a temporary password
  452. tomb dig -s ${tomb_size} /tmp/${tomb_name}.tomb
  453. if [ ! -f /tmp/${tomb_name}.tomb ]; then
  454. echo "WARNING: ${tomb_name} tomb did not install properly" >> /var/log/${PROJECT_NAME}.log
  455. tomb >> /var/log/${PROJECT_NAME}.log
  456. fi
  457. TOMB_TEMP_PASSWORD=$(openssl rand -base64 64 | tr -dc A-Za-z0-9 | head -c 30)
  458. tomb forge /mnt/ramdisk/${tomb_name}.tomb.key --tomb-pwd "${TOMB_TEMP_PASSWORD}" --unsafe
  459. tomb lock /tmp/${tomb_name}.tomb -k /mnt/ramdisk/${tomb_name}.tomb.key --tomb-pwd "${TOMB_TEMP_PASSWORD}" --unsafe
  460. tomb open /tmp/${tomb_name}.tomb -k /mnt/ramdisk/${tomb_name}.tomb.key --tomb-pwd "${TOMB_TEMP_PASSWORD}" --unsafe
  461. # stop stuff from popping up
  462. pkill caja
  463. # clear the temporary password
  464. TOMB_TEMP_PASSWORD=
  465. }
  466. function setup_amnesic_data {
  467. if [ ! -f $MESH_AMNESIC ]; then
  468. return
  469. fi
  470. if [ ! -d /mnt/ramdisk ]; then
  471. return
  472. fi
  473. # clear crypttab
  474. if [ -f /etc/crypttab ]; then
  475. shred -zu /etc/crypttab
  476. touch /etc/crypttab
  477. fi
  478. tomb_name=log
  479. create_tomb ${tomb_name} $TOMB_LOG_SIZE_MB
  480. if [ -d /media/${tomb_name} ]; then
  481. if [ -d /var/log ]; then
  482. if [ ! -d /var/log_base ]; then
  483. mv /var/log /var/log_base
  484. fi
  485. fi
  486. ln -s /media/${tomb_name} /var/log
  487. if [ -d /var/log_base ]; then
  488. cp -rp /var/log_base/* /media/${tomb_name}
  489. fi
  490. echo "${tomb_name} tomb created" >> $INSTALL_LOG
  491. else
  492. echo "WARNING: ${tomb_name} tomb not found" >> $INSTALL_LOG
  493. fi
  494. tomb_name=tox-bootstrapd
  495. if [ -f /etc/systemd/system/${tomb_name}.service ]; then
  496. systemctl stop ${tomb_name}
  497. fi
  498. create_tomb ${tomb_name} $TOMB_TOX_BOOTSTRAP_SIZE_MB
  499. if [ -d /media/${tomb_name} ]; then
  500. if [ -d /var/lib/tox-bootstrapd ]; then
  501. if [ ! -d /var/lib/tox-bootstrapd_base ]; then
  502. mv /var/lib/tox-bootstrapd /var/lib/tox-bootstrapd_base
  503. fi
  504. fi
  505. if [ -d /var/lib/tox-bootstrapd ]; then
  506. shred -zu /var/lib/tox-bootstrapd/*
  507. rm -rf /var/lib/tox-bootstrapd
  508. fi
  509. ln -s /media/${tomb_name} /var/lib/tox-bootstrapd
  510. if [ -d /var/lib/tox-bootstrapd_base ]; then
  511. cp -rp /var/lib/tox-bootstrapd_base/* /media/${tomb_name}
  512. fi
  513. echo "${tomb_name} tomb created" >> $INSTALL_LOG
  514. else
  515. echo "WARNING: ${tomb_name} tomb not found" >> $INSTALL_LOG
  516. fi
  517. tomb_name=tox
  518. create_tomb ${tomb_name} $TOMB_TOX_SIZE_MB
  519. if [ -d /media/${tomb_name} ]; then
  520. if [ ! -d /home/${MY_USERNAME}/.config ]; then
  521. mkdir -p /home/${MY_USERNAME}/.config
  522. chown ${MY_USERNAME}:${MY_USERNAME} /home/${MY_USERNAME}/.config
  523. fi
  524. if [ -d /home/${MY_USERNAME}/.config/${tomb_name} ]; then
  525. rm -rf /home/${MY_USERNAME}/.config/${tomb_name}
  526. fi
  527. ln -s /media/${tomb_name} /home/${MY_USERNAME}/.config/${tomb_name}
  528. chown -R ${MY_USERNAME}:${MY_USERNAME} /home/${MY_USERNAME}/.config/${tomb_name}
  529. chown -R ${MY_USERNAME}:${MY_USERNAME} /media/${tomb_name}
  530. echo "${tomb_name} tomb created" >> $INSTALL_LOG
  531. else
  532. echo "WARNING: ${tomb_name} tomb not found" >> $INSTALL_LOG
  533. fi
  534. }
  535. function setup_ipfs {
  536. IPFS_PATH=/usr/bin
  537. IPFS_KEY_LENGTH=2048
  538. IPFS_COMMAND=$IPFS_PATH/ipfs
  539. IPFS_PUBLIC=/home/$MY_USERNAME/.ipfs-public
  540. su -c "systemctl --user enable ipfs" - $MY_USERNAME
  541. if [ -f $CURRENT_BLOG_INDEX ]; then
  542. shred -zu $CURRENT_BLOG_INDEX
  543. fi
  544. if [ -d /home/$MY_USERNAME/Public ]; then
  545. rm /home/$MY_USERNAME/Desktop/Public
  546. rm -rf /home/$MY_USERNAME/Public
  547. fi
  548. if [ -d /home/$MY_USERNAME/CreateBlog/content/images ]; then
  549. shred -zu /home/$MY_USERNAME/CreateBlog/content/images/*
  550. fi
  551. if [ -d /home/$MY_USERNAME/CreateBlog/content ]; then
  552. shred -zu /home/$MY_USERNAME/CreateBlog/content/*
  553. if grep -q "THEME=" /home/$MY_USERNAME/CreateBlog/pelicanconf.py; then
  554. sed -i "s|THEME=.*|THEME='themes/nice-blog'|g" /home/$MY_USERNAME/CreateBlog/pelicanconf.py
  555. else
  556. echo "THEME='themes/nice-blog'" >> /home/$MY_USERNAME/CreateBlog/pelicanconf.py
  557. fi
  558. fi
  559. if [ -d /home/$MY_USERNAME/.ipfs ]; then
  560. shred -zu /home/$MY_USERNAME/.ipfs/config
  561. rm -rf /home/$MY_USERNAME/.ipfs
  562. su -c "systemctl --user restart ipfs" - $MY_USERNAME
  563. else
  564. su -c "systemctl --user start ipfs" - $MY_USERNAME
  565. fi
  566. if [ -f /home/$MY_USERNAME/.blog-index ]; then
  567. shred -zu /home/$MY_USERNAME/.blog-index
  568. fi
  569. if [ -f /home/$MY_USERNAME/.blog-theme-index ]; then
  570. shred -zu /home/$MY_USERNAME/.blog-theme-index
  571. fi
  572. if [ -f /home/$MY_USERNAME/.ipfs-id ]; then
  573. shred -zu /home/$MY_USERNAME/.ipfs-id
  574. fi
  575. if [ -f /home/$MY_USERNAME/.ipfs-public ]; then
  576. shred -zu /home/$MY_USERNAME/.ipfs-public
  577. fi
  578. su -c "$IPFS_COMMAND init -b $IPFS_KEY_LENGTH" - $MY_USERNAME
  579. if [ ! -d /home/$MY_USERNAME/.ipfs ]; then
  580. echo "IPFS could not be initialised for user $MY_USERNAME" >> $INSTALL_LOG
  581. return
  582. fi
  583. MY_IPFS_ID=/home/$MY_USERNAME/.ipfs-id
  584. su -c "echo \$($IPFS_COMMAND id | grep '\"ID\":' | awk -F '\"' '{print \$4}') > $MY_IPFS_ID" - $MY_USERNAME
  585. if [ ! -f $MY_IPFS_ID ]; then
  586. echo 'No IPFS identity was created' >> $INSTALL_LOG
  587. return
  588. fi
  589. IPFS_PEER_ID=$(cat $MY_IPFS_ID)
  590. if [ ${#IPFS_PEER_ID} -lt 10 ]; then
  591. echo 'Invalid IPFS peer ID' >> $INSTALL_LOG
  592. echo "$IPFS_PEER_ID" >> $INSTALL_LOG
  593. return
  594. fi
  595. # make a public directory
  596. TOX_ID='none'
  597. if [ -d /home/$MY_USERNAME/Desktop ]; then
  598. if [ ! -d /home/$MY_USERNAME/Public ]; then
  599. mkdir /home/$MY_USERNAME/Public
  600. echo $'Files within this directory will be publicly visible on the network' > /home/$MY_USERNAME/Public/README.txt
  601. chown -R $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/Public
  602. ln -s /home/$MY_USERNAME/Public /home/$MY_USERNAME/Desktop/Public
  603. su -c "echo \$($IPFS_COMMAND add -rq /home/$MY_USERNAME/Public | tail -n 1) > $IPFS_PUBLIC" - $MY_USERNAME
  604. if [ ! -f $IPFS_PUBLIC ]; then
  605. echo $'Unable to create public IPFS directory' >> $INSTALL_LOG
  606. exit 368225
  607. fi
  608. fi
  609. TOX_ID=$(su -c 'toxid' - $MY_USERNAME)
  610. fi
  611. create_avahi_mesh_service "ipfs_id" "ipfs_id" "udp" "$IPFS_PORT" "${IPFS_PEER_ID}:${TOX_ID}"
  612. echo "IPFS installed with ID ${IPFS_PEER_ID}" >> $INSTALL_LOG
  613. }
  614. function setup_tahoelafs {
  615. reconfigure_tahoelafs
  616. TAHOELAFS_CONFIG=/home/${MY_USERNAME}/.tahoe/tahoe.cfg
  617. if [ ! -f ${TAHOELAFS_CONFIG} ]; then
  618. exit 673923
  619. fi
  620. echo $'Configured Tahoe-LAFS' >> $INSTALL_LOG
  621. }
  622. function create_user_vpn_key {
  623. username=$1
  624. if [ ! -d /home/$username ]; then
  625. return
  626. fi
  627. echo $"Creating VPN key for $username" >> /var/log/${PROJECT_NAME}.log
  628. cd /etc/openvpn/easy-rsa
  629. if [ -f /etc/openvpn/easy-rsa/keys/$username.crt ]; then
  630. rm /etc/openvpn/easy-rsa/keys/$username.crt
  631. fi
  632. if [ -f /etc/openvpn/easy-rsa/keys/$username.key ]; then
  633. rm /etc/openvpn/easy-rsa/keys/$username.key
  634. fi
  635. if [ -f /etc/openvpn/easy-rsa/keys/$username.csr ]; then
  636. rm /etc/openvpn/easy-rsa/keys/$username.csr
  637. fi
  638. sed -i 's| --interact||g' build-key
  639. ./build-key "$username"
  640. if [ ! -f /etc/openvpn/easy-rsa/keys/$username.crt ]; then
  641. echo $'VPN user cert not generated' >> /var/log/${PROJECT_NAME}.log
  642. exit 783528
  643. fi
  644. user_cert=$(cat /etc/openvpn/easy-rsa/keys/$username.crt)
  645. if [ ${#user_cert} -lt 10 ]; then
  646. cat /etc/openvpn/easy-rsa/keys/$username.crt
  647. echo $'User cert generation failed' >> /var/log/${PROJECT_NAME}.log
  648. exit 634659
  649. fi
  650. if [ ! -f /etc/openvpn/easy-rsa/keys/$username.key ]; then
  651. echo $'VPN user key not generated'
  652. exit 682523
  653. fi
  654. user_key=$(cat /etc/openvpn/easy-rsa/keys/$username.key)
  655. if [ ${#user_key} -lt 10 ]; then
  656. cat /etc/openvpn/easy-rsa/keys/$username.key
  657. echo $'User key generation failed'
  658. exit 285838
  659. fi
  660. user_vpn_cert_file=/home/$username/$OPENVPN_KEY_FILENAME
  661. echo 'client' > $user_vpn_cert_file
  662. echo 'dev tun' >> $user_vpn_cert_file
  663. echo 'proto tcp' >> $user_vpn_cert_file
  664. echo "remote localhost $STUNNEL_PORT" >> $user_vpn_cert_file
  665. echo "route $DEFAULT_DOMAIN_NAME 255.255.255.255 net_gateway" >> $user_vpn_cert_file
  666. echo 'resolv-retry infinite' >> $user_vpn_cert_file
  667. echo 'nobind' >> $user_vpn_cert_file
  668. echo 'tun-mtu 1500' >> $user_vpn_cert_file
  669. echo 'tun-mtu-extra 32' >> $user_vpn_cert_file
  670. echo 'mssfix 1450' >> $user_vpn_cert_file
  671. echo 'persist-key' >> $user_vpn_cert_file
  672. echo 'persist-tun' >> $user_vpn_cert_file
  673. echo 'auth-nocache' >> $user_vpn_cert_file
  674. echo 'remote-cert-tls server' >> $user_vpn_cert_file
  675. echo 'comp-lzo' >> $user_vpn_cert_file
  676. echo 'verb 3' >> $user_vpn_cert_file
  677. echo '' >> $user_vpn_cert_file
  678. echo '<ca>' >> $user_vpn_cert_file
  679. cat /etc/openvpn/ca.crt >> $user_vpn_cert_file
  680. echo '</ca>' >> $user_vpn_cert_file
  681. echo '<cert>' >> $user_vpn_cert_file
  682. cat /etc/openvpn/easy-rsa/keys/$username.crt >> $user_vpn_cert_file
  683. echo '</cert>' >> $user_vpn_cert_file
  684. echo '<key>' >> $user_vpn_cert_file
  685. cat /etc/openvpn/easy-rsa/keys/$username.key >> $user_vpn_cert_file
  686. echo '</key>' >> $user_vpn_cert_file
  687. chown $username:$username $user_vpn_cert_file
  688. # keep a backup
  689. cp $user_vpn_cert_file /etc/openvpn/easy-rsa/keys/$username.ovpn
  690. #rm /etc/openvpn/easy-rsa/keys/$username.crt
  691. #rm /etc/openvpn/easy-rsa/keys/$username.csr
  692. shred -zu /etc/openvpn/easy-rsa/keys/$username.key
  693. echo $"VPN key created at $user_vpn_cert_file" >> /var/log/${PROJECT_NAME}.log
  694. }
  695. function vpn_generate_keys {
  696. # generate host keys
  697. if [ ! -f /etc/openvpn/dh2048.pem ]; then
  698. ${PROJECT_NAME}-dhparam -o /etc/openvpn/dh2048.pem
  699. fi
  700. if [ ! -f /etc/openvpn/dh2048.pem ]; then
  701. echo $'vpn dhparams were not generated' >> /var/log/${PROJECT_NAME}.log
  702. exit 73724523
  703. fi
  704. cp /etc/openvpn/dh2048.pem /etc/openvpn/easy-rsa/keys/dh2048.pem
  705. cd /etc/openvpn/easy-rsa
  706. . ./vars
  707. ./clean-all
  708. vpn_openssl_version='1.0.0'
  709. if [ ! -f openssl-${vpn_openssl_version}.cnf ]; then
  710. echo $"openssl-${vpn_openssl_version}.cnf was not found" >> /var/log/${PROJECT_NAME}.log
  711. exit 7392353
  712. fi
  713. cp openssl-${vpn_openssl_version}.cnf openssl.cnf
  714. if [ -f /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.crt ]; then
  715. rm /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.crt
  716. fi
  717. if [ -f /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.key ]; then
  718. rm /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.key
  719. fi
  720. if [ -f /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.csr ]; then
  721. rm /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.csr
  722. fi
  723. sed -i 's| --interact||g' build-key-server
  724. sed -i 's| --interact||g' build-ca
  725. ./build-ca
  726. ./build-key-server ${OPENVPN_SERVER_NAME}
  727. if [ ! -f /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.crt ]; then
  728. echo $'OpenVPN crt not found' >> /var/log/${PROJECT_NAME}.log
  729. exit 7823352
  730. fi
  731. server_cert=$(cat /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.crt)
  732. if [ ${#server_cert} -lt 10 ]; then
  733. cat /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.crt
  734. echo $'Server cert generation failed' >> /var/log/${PROJECT_NAME}.log
  735. exit 3284682
  736. fi
  737. if [ ! -f /etc/openvpn/easy-rsa/keys/${OPENVPN_SERVER_NAME}.key ]; then
  738. echo $'OpenVPN key not found' >> /var/log/${PROJECT_NAME}.log
  739. exit 6839436
  740. fi
  741. if [ ! -f /etc/openvpn/easy-rsa/keys/ca.key ]; then
  742. echo $'OpenVPN ca not found' >> /var/log/${PROJECT_NAME}.log
  743. exit 7935203
  744. fi
  745. cp /etc/openvpn/easy-rsa/keys/{$OPENVPN_SERVER_NAME.crt,$OPENVPN_SERVER_NAME.key,ca.crt} /etc/openvpn
  746. create_user_vpn_key ${MY_USERNAME}
  747. }
  748. function generate_stunnel_keys {
  749. echo "Creating stunnel keys" >> /var/log/${PROJECT_NAME}.log
  750. openssl req -x509 -nodes -days 3650 -sha256 \
  751. -subj "/O=$VPN_ORGANISATION/OU=$VPN_UNIT/C=$VPN_COUNTRY_CODE/ST=$VPN_AREA/L=$VPN_LOCATION/CN=$HOSTNAME" \
  752. -newkey rsa:2048 -keyout /etc/stunnel/key.pem \
  753. -out /etc/stunnel/cert.pem
  754. if [ ! -f /etc/stunnel/key.pem ]; then
  755. echo $'stunnel key not created' >> /var/log/${PROJECT_NAME}.log
  756. exit 793530
  757. fi
  758. if [ ! -f /etc/stunnel/cert.pem ]; then
  759. echo $'stunnel cert not created' >> /var/log/${PROJECT_NAME}.log
  760. exit 204587
  761. fi
  762. chmod 400 /etc/stunnel/key.pem
  763. chmod 640 /etc/stunnel/cert.pem
  764. cat /etc/stunnel/key.pem /etc/stunnel/cert.pem >> /etc/stunnel/stunnel.pem
  765. chmod 640 /etc/stunnel/stunnel.pem
  766. openssl pkcs12 -export -out /etc/stunnel/stunnel.p12 -inkey /etc/stunnel/key.pem -in /etc/stunnel/cert.pem -passout pass:
  767. if [ ! -f /etc/stunnel/stunnel.p12 ]; then
  768. echo $'stunnel pkcs12 not created' >> /var/log/${PROJECT_NAME}.log
  769. exit 639353
  770. fi
  771. chmod 640 /etc/stunnel/stunnel.p12
  772. cp /etc/stunnel/stunnel.pem /home/$MY_USERNAME/stunnel.pem
  773. cp /etc/stunnel/stunnel.p12 /home/$MY_USERNAME/stunnel.p12
  774. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/stunnel*
  775. echo "stunnel keys created" >> /var/log/${PROJECT_NAME}.log
  776. }
  777. function mesh_setup_vpn {
  778. vpn_generate_keys
  779. cp /etc/stunnel/stunnel-client.conf /home/$MY_USERNAME/stunnel-client.conf
  780. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/stunnel*
  781. generate_stunnel_keys
  782. sed -i 's|tun-mtu .*|tun-mtu 1532|g' /home/$MY_USERNAME/client.ovpn
  783. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/client.ovpn
  784. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/stunnel*
  785. # create an archive of the vpn client files
  786. cd /home/$MY_USERNAME
  787. tar -czvf vpn.tar.gz stunnel* client.ovpn
  788. chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/vpn.tar.gz
  789. systemctl restart openvpn
  790. }
  791. function initialise_scuttlebot_pub {
  792. chown -R scuttlebot:scuttlebot /etc/scuttlebot
  793. systemctl enable scuttlebot.service
  794. systemctl daemon-reload
  795. systemctl start scuttlebot.service
  796. sleep 3
  797. if [ ! -d /etc/scuttlebot/.ssb ]; then
  798. echo $'Scuttlebot config not generated' >> /var/log/${PROJECT_NAME}.log
  799. exit 73528
  800. fi
  801. echo '{' > /etc/scuttlebot/.ssb/config
  802. echo " \"host\": \"${HOSTNAME}\"," >> /etc/scuttlebot/.ssb/config
  803. echo " \"port\": ${SCUTTLEBOT_PORT}," >> /etc/scuttlebot/.ssb/config
  804. echo ' "allowPrivate": true,' >> /etc/scuttlebot/.ssb/config
  805. echo ' "timeout": 30000,' >> /etc/scuttlebot/.ssb/config
  806. echo ' "pub": true,' >> /etc/scuttlebot/.ssb/config
  807. echo ' "local": true,' >> /etc/scuttlebot/.ssb/config
  808. echo ' "friends": {' >> /etc/scuttlebot/.ssb/config
  809. echo ' "dunbar": 150,' >> /etc/scuttlebot/.ssb/config
  810. echo ' "hops": 3' >> /etc/scuttlebot/.ssb/config
  811. echo ' },' >> /etc/scuttlebot/.ssb/config
  812. echo ' "gossip": {' >> /etc/scuttlebot/.ssb/config
  813. echo ' "connections": 2' >> /etc/scuttlebot/.ssb/config
  814. echo ' },' >> /etc/scuttlebot/.ssb/config
  815. echo ' "master": [],' >> /etc/scuttlebot/.ssb/config
  816. echo ' "logging": {' >> /etc/scuttlebot/.ssb/config
  817. echo ' "level": "error"' >> /etc/scuttlebot/.ssb/config
  818. echo ' }' >> /etc/scuttlebot/.ssb/config
  819. echo '}' >> /etc/scuttlebot/.ssb/config
  820. chown scuttlebot:scuttlebot /etc/scuttlebot/.ssb/config
  821. systemctl restart scuttlebot.service
  822. }
  823. # whether to reset the identity
  824. set_new_identity=
  825. if [ $2 ]; then
  826. if [[ "$2" == $"new"* ]]; then
  827. if [ ! -f $MESH_INSTALL_SETUP ]; then
  828. touch $MESH_INSTALL_SETUP
  829. fi
  830. set_new_identity=1
  831. fi
  832. if [[ "$2" == $"amnesic"* ]]; then
  833. if [ ! -f $MESH_AMNESIC ]; then
  834. touch $MESH_AMNESIC
  835. fi
  836. if [ ! -f $MESH_INSTALL_SETUP ]; then
  837. touch $MESH_INSTALL_SETUP
  838. fi
  839. set_new_identity=1
  840. fi
  841. fi
  842. if [ -f $MESH_INSTALL_SETUP ]; then
  843. if [ $1 ]; then
  844. MY_USERNAME=$1
  845. fi
  846. if [ ! $set_new_identity ]; then
  847. # sleep in order to allow other daemons to start up
  848. sleep 5
  849. fi
  850. # clear the install log
  851. if [ -f $INSTALL_LOG ]; then
  852. rm $INSTALL_LOG
  853. fi
  854. # Remove SSB/Patchwork files
  855. if [ -d /home/$MY_USERNAME/.ssb ]; then
  856. rm -rf /home/$MY_USERNAME/.ssb
  857. fi
  858. # Remove vpn host keys
  859. if [ -d /etc/openvpn/easy-rsa/keys ]; then
  860. rm -rf /etc/openvpn/easy-rsa/keys/*
  861. fi
  862. # Remove any existing vpn client keys
  863. if [ -f /home/$MY_USERNAME/vpn.tar.gz ]; then
  864. rm /home/$MY_USERNAME/vpn.tar.gz
  865. fi
  866. if [ -f /home/$USERNAME/stunnel.pem ]; then
  867. rm /home/$USERNAME/stunnel.pem
  868. fi
  869. if [ -f /home/$USERNAME/stunnel.p12 ]; then
  870. rm /home/$USERNAME/stunnel.p12
  871. fi
  872. # Remove cryptpad datastore
  873. if [ -d $CRYPTPAD_DIR/datastore ]; then
  874. rm -rf $CRYPTPAD_DIR/datastore
  875. fi
  876. echo $'Beginning mesh node setup' >> $INSTALL_LOG
  877. if [ -d /home/$MY_USERNAME/.config ]; then
  878. chown ${MY_USERNAME}:${MY_USERNAME} /home/$MY_USERNAME/.config
  879. fi
  880. #tomb slam all
  881. tmp_ram_disk 100
  882. enable_predictable_device_names
  883. enable_batman_daemon
  884. #create_ram_disk 1
  885. #setup_amnesic_data
  886. change_avahi_name
  887. if [ -d $CRYPTPAD_DIR ]; then
  888. systemctl start cryptpad
  889. fi
  890. configure_toxcore
  891. create_tox_user
  892. #setup_tahoelafs
  893. mesh_setup_vpn
  894. initialise_scuttlebot_pub
  895. setup_ipfs
  896. enable_cryptpad
  897. mesh_amnesic
  898. make_root_read_only
  899. if [ ! -f $MESH_AMNESIC ]; then
  900. rm $MESH_INSTALL_SETUP
  901. systemctl disable mesh-setup.service
  902. fi
  903. show_desktop_icons
  904. mesh_restart_daemons
  905. if [ ! -f $MESH_INSTALL_COMPLETED ]; then
  906. echo $'Mesh node setup complete' >> $INSTALL_LOG
  907. touch $MESH_INSTALL_COMPLETED
  908. if [ -d /home/$MY_USERNAME/Desktop ]; then
  909. touch $FIRST_BOOT
  910. chown ${MY_USERNAME}:${MY_USERNAME} $FIRST_BOOT
  911. fi
  912. # set the desktop background
  913. if [ -d /home/$MY_USERNAME/Desktop ]; then
  914. MESH_DESKTOP_BACKGROUND_IMAGE=/usr/local/share/${PROJECT_NAME}_mesh_background.png
  915. cp $MESH_DESKTOP_BACKGROUND_IMAGE /usr/share/images/desktop-base/${PROJECT_NAME}_mesh_background.png
  916. rm /usr/share/images/desktop-base/desktop-background
  917. ln -s /usr/share/images/desktop-base/${PROJECT_NAME}_mesh_background.png /usr/share/images/desktop-base/desktop-background
  918. fi
  919. if [ -f /etc/default/grub ]; then
  920. update-grub
  921. fi
  922. systemctl reboot -i
  923. fi
  924. fi
  925. exit 0