Merge pull request #76 from JRGTH/master
Added support for: - HardenedBSD new link structure - basic mirror support - console user validation
This commit is contained in:
@@ -442,6 +442,10 @@ NAME_VERIFY=$(echo "${RELEASE}" | grep -iwE '^([1-9]{2,2})\.[0-9](-RELEASE|-RC[1
|
|||||||
if [ -n "${NAME_VERIFY}" ]; then
|
if [ -n "${NAME_VERIFY}" ]; then
|
||||||
RELEASE="${NAME_VERIFY}"
|
RELEASE="${NAME_VERIFY}"
|
||||||
UPSTREAM_URL="http://ftp.freebsd.org/pub/FreeBSD/releases/${HW_MACHINE}/${HW_MACHINE_ARCH}/${RELEASE}"
|
UPSTREAM_URL="http://ftp.freebsd.org/pub/FreeBSD/releases/${HW_MACHINE}/${HW_MACHINE_ARCH}/${RELEASE}"
|
||||||
|
if ! fetch -qo /dev/null "${UPSTREAM_URL}/MANIFEST" 2>/dev/null; then
|
||||||
|
## try an alternate url
|
||||||
|
UPSTREAM_URL="ftp://ftp.freebsd.org/pub/FreeBSD/releases/${HW_MACHINE}/${HW_MACHINE_ARCH}/${RELEASE}"
|
||||||
|
fi
|
||||||
bootstrap_directories
|
bootstrap_directories
|
||||||
bootstrap_release
|
bootstrap_release
|
||||||
else
|
else
|
||||||
@@ -460,6 +464,24 @@ else
|
|||||||
usage
|
usage
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
*-stable-build-*|*-STABLE-BUILD-*)
|
||||||
|
## check for HardenedBSD(for current changes)
|
||||||
|
NAME_VERIFY=$(echo "${RELEASE}" | grep -iwE '([0-9]{1,2})(-stable-build|-STABLE-BUILD)-([0-9]{1,2})$' | sed 's/BUILD/build/g' | sed 's/STABLE/stable/g')
|
||||||
|
NAME_RELEASE=$(echo ${NAME_VERIFY} | sed 's/-build-[0-9]\{1,2\}//g')
|
||||||
|
NAME_BUILD=$(echo ${NAME_VERIFY} | sed 's/[0-9]\{1,2\}-stable-//g')
|
||||||
|
if [ -n "${NAME_VERIFY}" ]; then
|
||||||
|
RELEASE="${NAME_VERIFY}"
|
||||||
|
UPSTREAM_URL="http://installer.hardenedbsd.org/pub/hardenedbsd/${NAME_RELEASE}/${HW_MACHINE}/${HW_MACHINE_ARCH}/${NAME_BUILD}"
|
||||||
|
if ! fetch -qo /dev/null "${UPSTREAM_URL}/MANIFEST" 2>/dev/null; then
|
||||||
|
## try an alternate url
|
||||||
|
UPSTREAM_URL="http://ci-01.nyi.hardenedbsd.org/pub/hardenedbsd/${NAME_RELEASE}/${HW_MACHINE}/${HW_MACHINE_ARCH}/${NAME_BUILD}"
|
||||||
|
fi
|
||||||
|
bootstrap_directories
|
||||||
|
bootstrap_release
|
||||||
|
else
|
||||||
|
usage
|
||||||
|
fi
|
||||||
|
;;
|
||||||
http?://github.com/*/*|http?://gitlab.com/*/*)
|
http?://github.com/*/*|http?://gitlab.com/*/*)
|
||||||
BASTILLE_TEMPLATE_URL=${1}
|
BASTILLE_TEMPLATE_URL=${1}
|
||||||
BASTILLE_TEMPLATE_USER=$(echo "${1}" | awk -F / '{ print $4 }')
|
BASTILLE_TEMPLATE_USER=$(echo "${1}" | awk -F / '{ print $4 }')
|
||||||
|
|||||||
@@ -57,10 +57,27 @@ if [ "${TARGET}" != 'ALL' ]; then
|
|||||||
JAILS=$(jls name | grep -w "${TARGET}")
|
JAILS=$(jls name | grep -w "${TARGET}")
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
validate_user() {
|
||||||
|
if jexec -l ${_jail} id "${USER}" >/dev/null 2>&1; then
|
||||||
|
USER_SHELL="$(jexec -l ${_jail} getent passwd "${USER}" | cut -d: -f7)"
|
||||||
|
if [ -n "${USER_SHELL}" ]; then
|
||||||
|
if jexec -l ${_jail} grep -qwF "${USER_SHELL}" /etc/shells; then
|
||||||
|
jexec -l ${_jail} /usr/bin/login -f "${USER}"
|
||||||
|
else
|
||||||
|
echo "Invalid shell for user ${USER}"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "User ${USER} has no shell"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "Unknown user ${USER}"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
for _jail in ${JAILS}; do
|
for _jail in ${JAILS}; do
|
||||||
echo -e "${COLOR_GREEN}[${_jail}]:${COLOR_RESET}"
|
echo -e "${COLOR_GREEN}[${_jail}]:${COLOR_RESET}"
|
||||||
if [ ! -z "${USER}" ]; then
|
if [ ! -z "${USER}" ]; then
|
||||||
jexec -l ${_jail} /usr/bin/login -f "${USER}"
|
validate_user
|
||||||
else
|
else
|
||||||
jexec -l ${_jail} /usr/bin/login -f root
|
jexec -l ${_jail} /usr/bin/login -f root
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -333,6 +333,15 @@ fi
|
|||||||
*-stable-LAST|*-STABLE-last|*-stable-last|*-STABLE-LAST)
|
*-stable-LAST|*-STABLE-last|*-stable-last|*-STABLE-LAST)
|
||||||
## check for HardenedBSD releases name
|
## check for HardenedBSD releases name
|
||||||
NAME_VERIFY=$(echo "${RELEASE}" | grep -iwE '^([1-9]{2,2})(-stable-LAST|-STABLE-last|-stable-last|-STABLE-LAST)$' | sed 's/STABLE/stable/g' | sed 's/last/LAST/g')
|
NAME_VERIFY=$(echo "${RELEASE}" | grep -iwE '^([1-9]{2,2})(-stable-LAST|-STABLE-last|-stable-last|-STABLE-LAST)$' | sed 's/STABLE/stable/g' | sed 's/last/LAST/g')
|
||||||
|
if [ -n "${NAME_VERIFY}" ]; then
|
||||||
|
RELEASE="${NAME_VERIFY}"
|
||||||
|
else
|
||||||
|
usage
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
*-stable-build-*|*-STABLE-BUILD-*)
|
||||||
|
## check for HardenedBSD(for current changes)
|
||||||
|
NAME_VERIFY=$(echo "${RELEASE}" | grep -iwE '([0-9]{1,2})(-stable-build|-STABLE-BUILD)-([0-9]{1,2})$' | sed 's/BUILD/build/g' | sed 's/STABLE/stable/g')
|
||||||
if [ -n "${NAME_VERIFY}" ]; then
|
if [ -n "${NAME_VERIFY}" ]; then
|
||||||
RELEASE="${NAME_VERIFY}"
|
RELEASE="${NAME_VERIFY}"
|
||||||
else
|
else
|
||||||
|
|||||||
@@ -146,7 +146,6 @@ case "${NAME}" in
|
|||||||
usage
|
usage
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
|
||||||
*-stable-LAST|*-STABLE-last|*-stable-last|*-STABLE-LAST)
|
*-stable-LAST|*-STABLE-last|*-stable-last|*-STABLE-LAST)
|
||||||
## check for HardenedBSD releases name
|
## check for HardenedBSD releases name
|
||||||
NAME_VERIFY=$(echo "${NAME}" | grep -iwE '^([1-9]{2,2})(-stable-LAST|-STABLE-last|-stable-last|-STABLE-LAST)$' | sed 's/STABLE/stable/g' | sed 's/last/LAST/g')
|
NAME_VERIFY=$(echo "${NAME}" | grep -iwE '^([1-9]{2,2})(-stable-LAST|-STABLE-last|-stable-last|-STABLE-LAST)$' | sed 's/STABLE/stable/g' | sed 's/last/LAST/g')
|
||||||
@@ -157,8 +156,17 @@ case "${NAME}" in
|
|||||||
usage
|
usage
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
*-stable-build-*|*-STABLE-BUILD-*)
|
||||||
|
## check for HardenedBSD(for current changes)
|
||||||
|
NAME_VERIFY=$(echo "${NAME}" | grep -iwE '([0-9]{1,2})(-stable-build|-STABLE-BUILD)-([0-9]{1,2})$' | sed 's/BUILD/build/g' | sed 's/STABLE/stable/g')
|
||||||
|
if [ -n "${NAME_VERIFY}" ]; then
|
||||||
|
NAME="${NAME_VERIFY}"
|
||||||
|
destroy_rel
|
||||||
|
else
|
||||||
|
usage
|
||||||
|
fi
|
||||||
|
;;
|
||||||
*)
|
*)
|
||||||
|
|
||||||
## just destroy a jail
|
## just destroy a jail
|
||||||
destroy_jail
|
destroy_jail
|
||||||
;;
|
;;
|
||||||
|
|||||||
Reference in New Issue
Block a user