2012-01-02 05:30:09 +01:00
|
|
|
#!/bin/sh
|
|
|
|
#
|
|
|
|
# Script to install Shoreline Firewall Core Modules
|
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# (c) 2000-2011,2014 - Tom Eastep (teastep@shorewall.net)
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Shorewall documentation is available at http://shorewall.net
|
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# This program is part of Shorewall.
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by the
|
|
|
|
# Free Software Foundation, either version 2 of the license or, at your
|
|
|
|
# option, any later version.
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, see <http://www.gnu.org/licenses/>.
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
|
|
|
|
VERSION=xxx #The Build script inserts the actual version
|
|
|
|
|
|
|
|
usage() # $1 = exit status
|
|
|
|
{
|
|
|
|
ME=$(basename $0)
|
2012-03-25 16:49:52 +02:00
|
|
|
echo "usage: $ME [ <configuration-file> ] "
|
2012-01-02 05:30:09 +01:00
|
|
|
echo " $ME -v"
|
|
|
|
echo " $ME -h"
|
|
|
|
exit $1
|
|
|
|
}
|
|
|
|
|
2012-04-24 23:52:57 +02:00
|
|
|
fatal_error()
|
2012-03-24 21:05:39 +01:00
|
|
|
{
|
|
|
|
echo " ERROR: $@" >&2
|
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
|
2012-01-02 05:30:09 +01:00
|
|
|
split() {
|
|
|
|
local ifs
|
|
|
|
ifs=$IFS
|
|
|
|
IFS=:
|
|
|
|
set -- $1
|
|
|
|
echo $*
|
|
|
|
IFS=$ifs
|
|
|
|
}
|
|
|
|
|
|
|
|
qt()
|
|
|
|
{
|
|
|
|
"$@" >/dev/null 2>&1
|
|
|
|
}
|
|
|
|
|
|
|
|
mywhich() {
|
|
|
|
local dir
|
|
|
|
|
|
|
|
for dir in $(split $PATH); do
|
|
|
|
if [ -x $dir/$1 ]; then
|
|
|
|
echo $dir/$1
|
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
return 2
|
|
|
|
}
|
|
|
|
|
|
|
|
run_install()
|
|
|
|
{
|
|
|
|
if ! install $*; then
|
|
|
|
echo
|
|
|
|
echo "ERROR: Failed to install $*" >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
cant_autostart()
|
|
|
|
{
|
|
|
|
echo
|
|
|
|
echo "WARNING: Unable to configure shorewall to start automatically at boot" >&2
|
|
|
|
}
|
|
|
|
|
|
|
|
delete_file() # $1 = file to delete
|
|
|
|
{
|
|
|
|
rm -f $1
|
|
|
|
}
|
|
|
|
|
|
|
|
install_file() # $1 = source $2 = target $3 = mode
|
|
|
|
{
|
|
|
|
run_install $T $OWNERSHIP -m $3 $1 ${2}
|
|
|
|
}
|
|
|
|
|
2012-04-24 23:52:57 +02:00
|
|
|
require()
|
2012-03-24 21:05:39 +01:00
|
|
|
{
|
|
|
|
eval [ -n "\$$1" ] || fatal_error "Required option $1 not set"
|
|
|
|
}
|
2012-02-23 19:07:02 +01:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
cd "$(dirname $0)"
|
2012-02-23 19:07:02 +01:00
|
|
|
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Parse the run line
|
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
finished=0
|
|
|
|
|
|
|
|
while [ $finished -eq 0 ]; do
|
|
|
|
option=$1
|
|
|
|
|
|
|
|
case "$option" in
|
|
|
|
-*)
|
|
|
|
option=${option#-}
|
|
|
|
|
|
|
|
while [ -n "$option" ]; do
|
|
|
|
case $option in
|
|
|
|
h)
|
|
|
|
usage 0
|
|
|
|
;;
|
|
|
|
v)
|
|
|
|
echo "Shorewall Firewall Installer Version $VERSION"
|
|
|
|
exit 0
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
usage 1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
|
|
|
shift
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
finished=1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
# Read the RC file
|
|
|
|
#
|
|
|
|
if [ $# -eq 0 ]; then
|
2012-04-01 02:40:18 +02:00
|
|
|
if [ -f ./shorewallrc ]; then
|
|
|
|
. ./shorewallrc
|
2012-04-01 19:47:24 +02:00
|
|
|
file=./shorewallrc
|
|
|
|
elif [ -f ~/.shorewallrc ]; then
|
2012-04-01 02:40:18 +02:00
|
|
|
. ~/.shorewallrc || exit 1
|
|
|
|
file=~/.shorewallrc
|
2012-03-30 21:02:25 +02:00
|
|
|
elif [ -f /usr/share/shorewall/shorewallrc ]; then
|
|
|
|
. /usr/share/shorewall/shorewallrc
|
2012-03-31 00:22:06 +02:00
|
|
|
file=/usr/share/shorewall/shorewallrc
|
2012-03-30 21:02:25 +02:00
|
|
|
else
|
|
|
|
fatal_error "No configuration file specified and /usr/share/shorewall/shorewallrc not found"
|
2012-03-24 21:05:39 +01:00
|
|
|
fi
|
|
|
|
elif [ $# -eq 1 ]; then
|
|
|
|
file=$1
|
|
|
|
case $file in
|
|
|
|
/*|.*)
|
|
|
|
;;
|
|
|
|
*)
|
2012-03-27 23:33:49 +02:00
|
|
|
file=./$file || exit 1
|
2012-03-24 21:05:39 +01:00
|
|
|
;;
|
|
|
|
esac
|
2012-01-02 05:30:09 +01:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
. $file
|
|
|
|
else
|
|
|
|
usage 1
|
|
|
|
fi
|
2012-01-02 05:30:09 +01:00
|
|
|
|
2012-09-15 17:09:37 +02:00
|
|
|
update=0
|
|
|
|
|
2012-09-02 23:36:11 +02:00
|
|
|
if [ -z "${VARLIB}" ]; then
|
|
|
|
VARLIB=${VARDIR}
|
2012-09-14 17:20:54 +02:00
|
|
|
VARDIR="${VARLIB}/${PRODUCT}"
|
2012-09-15 17:09:37 +02:00
|
|
|
update=1
|
2012-09-03 00:51:35 +02:00
|
|
|
elif [ -z "${VARDIR}" ]; then
|
2012-09-14 17:20:54 +02:00
|
|
|
VARDIR="${VARLIB}/${PRODUCT}"
|
2012-09-15 17:09:37 +02:00
|
|
|
update=2
|
2012-09-02 23:36:11 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
for var in SHAREDIR LIBEXECDIR PERLLIBDIR CONFDIR SBINDIR VARLIB VARDIR; do
|
2012-03-24 21:05:39 +01:00
|
|
|
require $var
|
|
|
|
done
|
2012-01-02 05:30:09 +01:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
[ "${INITFILE}" != 'none/' ] && require INITSOURCE && require INITDIR
|
|
|
|
|
|
|
|
T="-T"
|
2012-01-02 05:30:09 +01:00
|
|
|
|
|
|
|
INSTALLD='-D'
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ -z "$BUILD" ]; then
|
2012-02-18 17:19:39 +01:00
|
|
|
case $(uname) in
|
2014-07-09 19:48:03 +02:00
|
|
|
cygwin*|CYGWIN*)
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=cygwin
|
2012-02-18 17:19:39 +01:00
|
|
|
;;
|
|
|
|
Darwin)
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=apple
|
2012-02-18 17:19:39 +01:00
|
|
|
;;
|
|
|
|
*)
|
2013-08-09 02:44:40 +02:00
|
|
|
if [ -f /etc/os-release ]; then
|
|
|
|
eval $(cat /etc/os-release | grep ^ID)
|
|
|
|
|
|
|
|
case $ID in
|
2014-09-23 12:18:58 +02:00
|
|
|
fedora|rhel|centos|foobar)
|
2013-08-09 02:44:40 +02:00
|
|
|
BUILD=redhat
|
|
|
|
;;
|
|
|
|
debian)
|
|
|
|
BUILD=debian
|
|
|
|
;;
|
2013-09-17 17:22:52 +02:00
|
|
|
gentoo)
|
|
|
|
BUILD=gentoo
|
|
|
|
;;
|
2013-08-09 02:44:40 +02:00
|
|
|
opensuse)
|
|
|
|
BUILD=suse
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
BUILD="$ID"
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
elif [ -f /etc/debian_version ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=debian
|
2013-09-17 17:22:52 +02:00
|
|
|
elif [ -f /etc/gentoo-release ]; then
|
|
|
|
BUILD=gentoo
|
2012-02-18 17:19:39 +01:00
|
|
|
elif [ -f /etc/redhat-release ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=redhat
|
2012-02-18 17:19:39 +01:00
|
|
|
elif [ -f /etc/slackware-version ] ; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=slackware
|
2012-02-18 17:19:39 +01:00
|
|
|
elif [ -f /etc/SuSE-release ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=suse
|
2012-02-18 17:19:39 +01:00
|
|
|
elif [ -f /etc/arch-release ] ; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=archlinux
|
2012-02-18 17:19:39 +01:00
|
|
|
else
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=linux
|
2012-02-18 17:19:39 +01:00
|
|
|
fi
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
fi
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
case $BUILD in
|
|
|
|
cygwin*)
|
2012-01-02 05:30:09 +01:00
|
|
|
if [ -z "$DESTDIR" ]; then
|
|
|
|
DEST=
|
|
|
|
INIT=
|
|
|
|
fi
|
|
|
|
|
|
|
|
OWNER=$(id -un)
|
|
|
|
GROUP=$(id -gn)
|
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
apple)
|
2012-01-02 05:30:09 +01:00
|
|
|
if [ -z "$DESTDIR" ]; then
|
|
|
|
DEST=
|
|
|
|
INIT=
|
2012-02-18 17:19:39 +01:00
|
|
|
SPARSE=Yes
|
2012-01-02 05:30:09 +01:00
|
|
|
fi
|
|
|
|
|
|
|
|
[ -z "$OWNER" ] && OWNER=root
|
|
|
|
[ -z "$GROUP" ] && GROUP=wheel
|
|
|
|
INSTALLD=
|
|
|
|
T=
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
[ -z "$OWNER" ] && OWNER=root
|
|
|
|
[ -z "$GROUP" ] && GROUP=root
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
OWNERSHIP="-o $OWNER -g $GROUP"
|
|
|
|
|
|
|
|
#
|
|
|
|
# Determine where to install the firewall script
|
|
|
|
#
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
[ -n "$HOST" ] || HOST=$BUILD
|
2012-02-18 17:19:39 +01:00
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
case "$HOST" in
|
|
|
|
cygwin)
|
2012-02-18 17:19:39 +01:00
|
|
|
echo "Installing Cygwin-specific configuration..."
|
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
apple)
|
2012-02-18 17:19:39 +01:00
|
|
|
echo "Installing Mac-specific configuration...";
|
|
|
|
;;
|
2013-09-17 17:22:52 +02:00
|
|
|
debian|gentoo|redhat|slackware|archlinux|linux|suse)
|
2012-02-18 17:19:39 +01:00
|
|
|
;;
|
|
|
|
*)
|
2012-02-22 22:32:10 +01:00
|
|
|
echo "ERROR: Unknown HOST \"$HOST\"" >&2
|
2012-02-18 17:19:39 +01:00
|
|
|
exit 1;
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
2012-03-25 16:49:52 +02:00
|
|
|
if [ -z "$file" ]; then
|
|
|
|
if $HOST = linux; then
|
|
|
|
file=shorewallrc.default
|
|
|
|
else
|
2012-03-31 00:22:06 +02:00
|
|
|
file=shorewallrc.${HOST}
|
2012-03-25 16:49:52 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
echo "You have not specified a configuration file and ~/.shorewallrc does not exist" >&2
|
|
|
|
echo "Shorewall-core $VERSION has determined that the $file configuration is appropriate for your system" >&2
|
|
|
|
echo "Please review the settings in that file. If you wish to change them, make a copy and modify the copy" >&2
|
|
|
|
echo "Then re-run install.sh passing either $file or the name of your modified copy" >&2
|
|
|
|
echo "" >&2
|
|
|
|
echo "Example:" >&2
|
|
|
|
echo "" >&2
|
|
|
|
echo " ./install.sh $file" &>2
|
|
|
|
fi
|
|
|
|
|
2012-01-02 05:30:09 +01:00
|
|
|
if [ -n "$DESTDIR" ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ $BUILD != cygwin ]; then
|
2012-01-02 05:30:09 +01:00
|
|
|
if [ `id -u` != 0 ] ; then
|
|
|
|
echo "Not setting file owner/group permissions, not running as root."
|
|
|
|
OWNERSHIP=""
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
echo "Installing Shorewall Core Version $VERSION"
|
|
|
|
|
|
|
|
#
|
2012-04-01 17:16:07 +02:00
|
|
|
# Create directories
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
mkdir -p ${DESTDIR}${LIBEXECDIR}/shorewall
|
|
|
|
chmod 755 ${DESTDIR}${LIBEXECDIR}/shorewall
|
2012-02-21 01:11:28 +01:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
mkdir -p ${DESTDIR}${SHAREDIR}/shorewall
|
|
|
|
chmod 755 ${DESTDIR}${SHAREDIR}/shorewall
|
2012-04-01 17:16:07 +02:00
|
|
|
|
|
|
|
mkdir -p ${DESTDIR}${CONFDIR}
|
|
|
|
chmod 755 ${DESTDIR}${CONFDIR}
|
|
|
|
|
|
|
|
if [ -n "${SYSCONFDIR}" ]; then
|
|
|
|
mkdir -p ${DESTDIR}${SYSCONFDIR}
|
|
|
|
chmod 755 ${DESTDIR}${SYSCONFDIR}
|
|
|
|
fi
|
|
|
|
|
2014-10-13 20:56:26 +02:00
|
|
|
if [ -z "${SERVICEDIR}" ]; then
|
|
|
|
SERVICEDIR="$SYSTEMD"
|
2014-10-08 01:46:16 +02:00
|
|
|
fi
|
|
|
|
|
2014-10-13 20:56:26 +02:00
|
|
|
if [ -n "${SERVICEDIR}" ]; then
|
|
|
|
mkdir -p ${DESTDIR}${SERVICEDIR}
|
|
|
|
chmod 755 ${DESTDIR}${SERVICEDIR}
|
2012-04-01 17:16:07 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
mkdir -p ${DESTDIR}${SBINDIR}
|
|
|
|
chmod 755 ${DESTDIR}${SBINDIR}
|
|
|
|
|
|
|
|
mkdir -p ${DESTDIR}${MANDIR}
|
|
|
|
chmod 755 ${DESTDIR}${MANDIR}
|
|
|
|
|
2012-04-28 01:15:04 +02:00
|
|
|
if [ -n "${INITFILE}" ]; then
|
|
|
|
mkdir -p ${DESTDIR}${INITDIR}
|
|
|
|
chmod 755 ${DESTDIR}${INITDIR}
|
|
|
|
|
|
|
|
if [ -n "$AUXINITSOURCE" -a -f "$AUXINITSOURCE" ]; then
|
|
|
|
install_file $AUXINITSOURCE ${DESTDIR}${INITDIR}/$AUXINITFILE 0544
|
|
|
|
[ "${SHAREDIR}" = /usr/share ] || eval sed -i \'s\|/usr/share/\|${SHAREDIR}/\|\' ${DESTDIR}${INITDIR}/$AUXINITFILE
|
2013-09-09 17:11:45 +02:00
|
|
|
echo "SysV init script $AUXINITSOURCE installed in ${DESTDIR}${INITDIR}/$AUXINITFILE"
|
2012-04-28 01:15:04 +02:00
|
|
|
fi
|
|
|
|
fi
|
2012-04-01 17:16:07 +02:00
|
|
|
#
|
|
|
|
# Note: ${VARDIR} is created at run-time since it has always been
|
|
|
|
# a relocatable directory on a per-product basis
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Install wait4ifup
|
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
install_file wait4ifup ${DESTDIR}${LIBEXECDIR}/shorewall/wait4ifup 0755
|
2012-01-02 05:30:09 +01:00
|
|
|
|
|
|
|
echo
|
2012-03-24 21:05:39 +01:00
|
|
|
echo "wait4ifup installed in ${DESTDIR}${LIBEXECDIR}/shorewall/wait4ifup"
|
2012-01-02 05:30:09 +01:00
|
|
|
|
|
|
|
#
|
|
|
|
# Install the libraries
|
|
|
|
#
|
|
|
|
for f in lib.* ; do
|
2012-03-24 21:05:39 +01:00
|
|
|
install_file $f ${DESTDIR}${SHAREDIR}/shorewall/$f 0644
|
|
|
|
echo "Library ${f#*.} file installed as ${DESTDIR}${SHAREDIR}/shorewall/$f"
|
2012-01-02 05:30:09 +01:00
|
|
|
done
|
2012-02-13 21:57:07 +01:00
|
|
|
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Symbolically link 'functions' to lib.base
|
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
ln -sf lib.base ${DESTDIR}${SHAREDIR}/shorewall/functions
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Create the version file
|
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
echo "$VERSION" > ${DESTDIR}${SHAREDIR}/shorewall/coreversion
|
|
|
|
chmod 644 ${DESTDIR}${SHAREDIR}/shorewall/coreversion
|
|
|
|
|
2012-09-15 17:09:37 +02:00
|
|
|
if [ -z "${DESTDIR}" ]; then
|
|
|
|
if [ $update -ne 0 ]; then
|
|
|
|
echo "Updating $file - original saved in $file.bak"
|
|
|
|
|
|
|
|
cp $file $file.bak
|
|
|
|
|
|
|
|
echo '#' >> $file
|
|
|
|
echo "# Updated by Shorewall-core $VERSION -" `date` >> $file
|
|
|
|
echo '#' >> $file
|
|
|
|
|
|
|
|
[ $update -eq 1 ] && sed -i 's/VARDIR/VARLIB/' $file
|
|
|
|
|
|
|
|
echo 'VARDIR=${VARLIB}/${PRODUCT}' >> $file
|
|
|
|
fi
|
|
|
|
fi
|
2012-03-24 21:05:39 +01:00
|
|
|
|
2012-09-15 17:09:37 +02:00
|
|
|
[ $file != "${DESTDIR}${SHAREDIR}/shorewall/shorewallrc" ] && cp $file ${DESTDIR}${SHAREDIR}/shorewall/shorewallrc
|
2012-03-30 21:02:25 +02:00
|
|
|
|
2013-10-09 23:06:41 +02:00
|
|
|
|
|
|
|
[ -z "${DESTDIR}" ] && [ ! -f ~/.shorewallrc ] && cp ${SHAREDIR}/shorewall/shorewallrc ~/.shorewallrc
|
|
|
|
|
2012-03-30 21:02:25 +02:00
|
|
|
if [ ${SHAREDIR} != /usr/share ]; then
|
|
|
|
for f in lib.*; do
|
|
|
|
if [ $BUILD != apple ]; then
|
2012-04-01 19:47:24 +02:00
|
|
|
eval sed -i \'s\|/usr/share/\|${SHAREDIR}/\|\' ${DESTDIR}/${SHAREDIR}/shorewall/$f
|
2012-03-30 21:02:25 +02:00
|
|
|
else
|
2012-04-01 19:47:24 +02:00
|
|
|
eval sed -i \'\' -e \'s\|/usr/share/\|${SHAREDIR}/\|\' ${DESTDIR}/${SHAREDIR}/shorewall/$f
|
2012-03-30 21:02:25 +02:00
|
|
|
fi
|
|
|
|
done
|
2012-03-24 21:05:39 +01:00
|
|
|
fi
|
2012-01-02 05:30:09 +01:00
|
|
|
#
|
|
|
|
# Report Success
|
|
|
|
#
|
|
|
|
echo "Shorewall Core Version $VERSION Installed"
|