[debian-edu-commits] [Git][debian-edu/debian-edu-config][personal/sunweaver/etc-netgroup] 6 commits: share/debian-edu-config/tools/run-at-firstboot: Add an environment check to...

Mike Gabriel (@sunweaver) gitlab at salsa.debian.org
Fri Sep 4 22:26:59 BST 2026



Mike Gabriel pushed to branch personal/sunweaver/etc-netgroup at Debian Edu / debian-edu-config


Commits:
c2ba0299 by Serhii Horichenko at 2026-09-04T19:26:12+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an environment check to avoid starting the image creation on an LTSP-client (Closes: #1092123).

- - - - -
8b5765b6 by Serhii Horichenko at 2026-09-04T19:40:06+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an ability to create a Diskless Workstation chroot and separate the creation of an image on an LTSP-server without the Main-Server role (Closes: #1092123).

- - - - -
1b3d05e6 by Mike Gabriel at 2026-09-04T21:24:53+00:00
sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).

- - - - -
18d340a3 by Mike Gabriel at 2026-09-04T21:26:05+00:00
share/debian-edu-config/tools/kerberos-kdc-init: Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes: #1052962).

- - - - -
a3082be9 by Mike Gabriel at 2026-09-04T21:26:19+00:00
Stop using killer script in Debian Edu. (Closes: #703710).

- - - - -
b03fe98b by Mike Gabriel at 2026-09-04T21:26:55+00:00
cf3/cf.ldapclient: Ensure empty file /etc/netgroup exists. (Closes: #1146398).

- - - - -


8 changed files:

- Makefile
- cf3/cf.ldapclient
- cf3/cf.workarounds
- sbin/debian-edu-ltsp-install
- − share/debian-edu-config/killer.cron
- share/debian-edu-config/tools/kerberos-kdc-init
- share/debian-edu-config/tools/run-at-firstboot
- share/debian-edu-config/tools/setup-roaming


Changes:

=====================================
Makefile
=====================================
@@ -289,7 +289,6 @@ install: install-testsuite
 	set -e ; for f in \
 		share/debian-edu-config/d-i/finish-install \
 		share/debian-edu-config/d-i/pre-pkgsel \
-		share/debian-edu-config/killer.cron \
 		share/debian-edu-config/tools/passwd \
 		share/debian-edu-config/tools/clean-up-host-keytabs \
 		share/debian-edu-config/tools/create-debian-edu-certs \


=====================================
cf3/cf.ldapclient
=====================================
@@ -41,6 +41,10 @@ files:
 
     "/etc/nsswitch.conf"
       edit_line => nsswitch_conf;
+
+  debian.installation::
+      "/etc/netgroup" create => "true";
+
 }
 
 bundle edit_line nsswitch_conf


=====================================
cf3/cf.workarounds
=====================================
@@ -15,13 +15,4 @@ files:
 
     "$(gosa_file)"
       create => "true";
-
-  debian.ltspserver.installation::
-
-    "/etc/cron.hourly/killer"
-      delete => tidy;
-
-    "/etc/cron.hourly/killer"
-      copy_from => local_cp("/usr/share/debian-edu-config/killer.cron"),
-      perms => mog("755","root","root");
 }


=====================================
sbin/debian-edu-ltsp-install
=====================================
@@ -607,11 +607,15 @@ EOF
 	rm -f /etc/resolv.conf
 	echo "nameserver $dns_server" > /etc/resolv.conf
 	echo "search intern" >> /etc/resolv.conf
+	# Temporary workaround needed to turn DLW images into machines of profile type 'Workstation'
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"Workstation\"/g"
 	# Create SqashFS image.
 	ltsp image /,,/boot,subdir=boot,,/usr,subdir=usr,,/var,subdir=var
 	# Revert resolver workaround from above.
 	rm -f /etc/resolv.conf
 	ln -s /run/resolvconf/resolv.conf /etc/resolv.conf
+	# Revert temporary change to PROFILE in /etc/debian-edu/config
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"${PROFILE}\"/g"
 	# next modification avoids ltsp command error if lot of images are available.
 	ALL_IMAGES=1 ltsp kernel
 	ltsp initrd
@@ -675,7 +679,7 @@ EOF
 	chroot /srv/ltsp/dlw apt-get install -y -qq apt-utils ltsp
 
 	# Turn system into a Debian Edu workstation.
-	chroot /srv/ltsp/dlw sh -c "DESKTOP=$desktop /sbin/debian-edu-bless"
+	chroot /srv/ltsp/dlw sh -c "PROFILE=Workstation DESKTOP=$desktop /sbin/debian-edu-bless"
 	mkdir -p /srv/ltsp/dlw/skole
 	chmod 755 /srv/ltsp/dlw/skole
 	rm -f /srv/ltsp/dlw/etc/resolv.conf


=====================================
share/debian-edu-config/killer.cron deleted
=====================================
@@ -1,3 +0,0 @@
-#!/bin/sh
-
-if [ "$(ps aux | grep sshd: | grep @notty)" = "" ] && [ -x /usr/sbin/killer ] ; then /usr/sbin/killer; fi


=====================================
share/debian-edu-config/tools/kerberos-kdc-init
=====================================
@@ -173,7 +173,6 @@ mit_kerberos_kdc() {
         kdc_ports = 750,88
         max_life = 10h 0m 0s
         max_renewable_life = 7d 0h 0m 0s
-        master_key_type = des3-hmac-sha1
         default_principal_flags = +preauth
     }
 EOF


=====================================
share/debian-edu-config/tools/run-at-firstboot
=====================================
@@ -26,6 +26,14 @@ at_exit() {
 	error "script $0 terminated unexpectedly."
 }
 disable_exception() { trap - INT TERM EXIT; }
+is_ltsp_client() {
+        if grep -q "initrd=ltsp.img" < /proc/cmdline; then
+                return 0
+        else
+                return 1
+        fi
+}
+
 trap at_exit INT TERM EXIT
 
 info "Executing run-at-firstboot script."
@@ -62,9 +70,23 @@ fi
 # information from some daemons isn't available during installation. It's done
 # for a combined server but not for a separate LTSP server because the image
 # needs to include the krb5.keytab file which isn't available at this time.
-if echo "$PROFILE" | grep -Eq 'Main-Server.*LTSP-Server' && \
-	[ ! -f /srv/ltsp/images/$ltspimg ] ; then
-	/usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+if ! is_ltsp_client; then
+	# If this runs on a combi server (Main-Server + LTSP-Server), create
+	# Diskless Workstation chroot from scratch as clean environment.
+	if echo "$PROFILE" | grep -Eq 'Main-Server' && \
+		echo "$PROFILE" | grep -Eq 'LTSP-Server'; then
+			if [ ! -d /srv/ltsp/dlw ]; then
+				/usr/sbin/debian-edu-ltsp-install --dlw yes
+			fi
+	# else if this runs on a pure LTSP-Server (no Main-Server role), then
+	# let's use the file system of the LTSP-Server and generate the LTSP
+	# image directly from it (faster!).
+	elif echo "$PROFILE" | grep -Eqv 'Main-Server' && \
+		echo "$PROFILE" | grep -Eq  'LTSP-Server'; then
+			if [ ! -f /srv/ltsp/images/$ltspimg ] ; then
+					/usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+			fi
+	fi
 fi
 
 # Update PXE setup on LTSP servers with proxy values set in environment


=====================================
share/debian-edu-config/tools/setup-roaming
=====================================
@@ -27,10 +27,6 @@ apt-get purge -y libpam-krb5
 # Avoid double caching, as sssd is already caching
 apt-get purge -y nscd
 
-# Roaming workstations are typically single user machines, so do not
-# throw out the user if he is idle.
-apt-get purge -y killer
-
 # try to configure sssd dynamically, fall back to default setup if
 # generation fail
 # sssd refuses to read the sssd.conf file unless it is 0600 root:root



View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/9b3c2d77cda816c95b6f183cc94e1db7fee5de98...b03fe98bbd949fd2772f3664d0b7e35ca2d266d7

-- 
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/9b3c2d77cda816c95b6f183cc94e1db7fee5de98...b03fe98bbd949fd2772f3664d0b7e35ca2d266d7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260904/6eca764f/attachment-0001.htm>


More information about the debian-edu-commits mailing list