[debian-edu-commits] [Git][debian-edu/debian-edu-config][personal/sunweaver/x2go-kdeplasma-sessions] 10 commits: share/debian-edu-config/tools/run-at-firstboot: Add an environment check to...
Mike Gabriel (@sunweaver)
gitlab at salsa.debian.org
Mon Sep 21 08:11:02 BST 2026
Mike Gabriel pushed to branch personal/sunweaver/x2go-kdeplasma-sessions at Debian Edu / debian-edu-config
Commits:
c2ba0299 by Serhii Horichenko at 2026-09-04T19:26:12+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an environment check to avoid starting the image creation on an LTSP-client (Closes: #1092123).
- - - - -
8b5765b6 by Serhii Horichenko at 2026-09-04T19:40:06+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an ability to create a Diskless Workstation chroot and separate the creation of an image on an LTSP-server without the Main-Server role (Closes: #1092123).
- - - - -
1b3d05e6 by Mike Gabriel at 2026-09-04T21:24:53+00:00
sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).
- - - - -
18d340a3 by Mike Gabriel at 2026-09-04T21:26:05+00:00
share/debian-edu-config/tools/kerberos-kdc-init: Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes: #1052962).
- - - - -
a3082be9 by Mike Gabriel at 2026-09-04T21:26:19+00:00
Stop using killer script in Debian Edu. (Closes: #703710).
- - - - -
b03fe98b by Mike Gabriel at 2026-09-04T21:26:55+00:00
cf3/cf.ldapclient: Ensure empty file /etc/netgroup exists. (Closes: #1146398).
- - - - -
476a3853 by Mike Gabriel at 2026-09-04T21:27:14+00:00
exim4/exim-ldap-{server,client}-v4.conf: Write logs to syslog. (Closes: #1051836).
- - - - -
a6cd1123 by Mike Gabriel at 2026-09-04T21:27:45+00:00
run-at-firstboot: Initialize first user's mailbox only when logging into Main-Server
- - - - -
bd9d8250 by Mike Gabriel at 2026-09-04T23:38:51+02:00
release as 2.13.2
Signed-off-by: Mike Gabriel <mike.gabriel at das-netzwerkteam.de>
- - - - -
7f855d62 by Mike Gabriel at 2026-09-21T09:10:35+02:00
sbin/debian-edu-ltsp-install: Support KDE in X2Go sessions again. The fix for #955128 has landed in X2Go Server a while back.
- - - - -
11 changed files:
- Makefile
- cf3/cf.ldapclient
- cf3/cf.workarounds
- debian/changelog
- etc/exim4/exim-ldap-client-v4.conf
- etc/exim4/exim-ldap-server-v4.conf
- sbin/debian-edu-ltsp-install
- − share/debian-edu-config/killer.cron
- share/debian-edu-config/tools/kerberos-kdc-init
- share/debian-edu-config/tools/run-at-firstboot
- share/debian-edu-config/tools/setup-roaming
Changes:
=====================================
Makefile
=====================================
@@ -289,7 +289,6 @@ install: install-testsuite
set -e ; for f in \
share/debian-edu-config/d-i/finish-install \
share/debian-edu-config/d-i/pre-pkgsel \
- share/debian-edu-config/killer.cron \
share/debian-edu-config/tools/passwd \
share/debian-edu-config/tools/clean-up-host-keytabs \
share/debian-edu-config/tools/create-debian-edu-certs \
=====================================
cf3/cf.ldapclient
=====================================
@@ -41,6 +41,10 @@ files:
"/etc/nsswitch.conf"
edit_line => nsswitch_conf;
+
+ debian.installation::
+ "/etc/netgroup" create => "true";
+
}
bundle edit_line nsswitch_conf
=====================================
cf3/cf.workarounds
=====================================
@@ -15,13 +15,4 @@ files:
"$(gosa_file)"
create => "true";
-
- debian.ltspserver.installation::
-
- "/etc/cron.hourly/killer"
- delete => tidy;
-
- "/etc/cron.hourly/killer"
- copy_from => local_cp("/usr/share/debian-edu-config/killer.cron"),
- perms => mog("755","root","root");
}
=====================================
debian/changelog
=====================================
@@ -1,3 +1,29 @@
+debian-edu-config (2.13.2) unstable; urgency=medium
+
+ [ Serhii Horichenko ]
+ * share/debian-edu-config/tools/run-at-firstboot:
+ - Add an environment check to avoid starting the image creation on
+ an LTSP-client (Closes: #1092123).
+ - Add an ability to create a Diskless Workstation chroot and separate
+ the creation of an image on an LTSP-server without the Main-Server
+ role (Closes: #1092123).
+
+ [ Mike Gabriel ]
+ * sbin/debian-edu-ltsp-install:
+ - When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).
+ * share/debian-edu-config/tools/kerberos-kdc-init:
+ - Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes:
+ #1052962).
+ * Stop using killer script in Debian Edu. (Closes: #703710).
+ * cf3/cf.ldapclient:
+ - Ensure empty file /etc/netgroup exists. (Closes: #1146398).
+ * exim4/exim-ldap-{server,client}-v4.conf:
+ - Write logs to syslog. (Closes: #1051836).
+ * run-at-firstboot:
+ - Initialize first user's mailbox only when logging into Main-Server.
+
+ -- Mike Gabriel <sunweaver at debian.org> Fri, 04 Sep 2026 23:35:24 +0200
+
debian-edu-config (2.13.1) unstable; urgency=medium
[ Daniel Teichmann ]
=====================================
etc/exim4/exim-ldap-client-v4.conf
=====================================
@@ -17,6 +17,9 @@ LOCALHOST = 127.0.0.1/8
# constant warning messages in the log file
keep_environment =
+# Send log messages to syslog
+log_file_path = syslog
+
# These options specify the Access Control Lists (ACLs) that
# are used for incoming SMTP messages - after the RCPT and DATA
# commands, respectively.
=====================================
etc/exim4/exim-ldap-server-v4.conf
=====================================
@@ -17,6 +17,9 @@
# from 'check_local_user' directive instead.
# -- Wolfgang Schweer <wschweer at arcor.de>, 2020-06-27.
+# Send log messages to syslog
+log_file_path = syslog
+
##
keep_environment = KRB5_KTNAME : PWD : ^LDAP
tls_advertise_hosts = *
=====================================
sbin/debian-edu-ltsp-install
=====================================
@@ -28,10 +28,8 @@ select_desktop () {
# support
if [ -x /usr/bin/startxfce4 ]; then # from xfce4-session
echo XFCE
- # FIXME x2goclient and x2goserver (x2goruncommand) in Debian only support
- # startkde which does not exist any more (#955128)
- #elif [ -x /usr/bin/startplasma-x11 ]; then # from plasma-workspace
- # echo KDE
+ elif [ -x /usr/bin/startplasma-x11 ]; then # from plasma-workspace
+ echo KDE
elif [ -x /usr/bin/gnome-session ]; then # from gnome-session-bin
echo GNOME
elif [ -x /usr/bin/mate-session ]; then # from mate-session
@@ -607,11 +605,15 @@ EOF
rm -f /etc/resolv.conf
echo "nameserver $dns_server" > /etc/resolv.conf
echo "search intern" >> /etc/resolv.conf
+ # Temporary workaround needed to turn DLW images into machines of profile type 'Workstation'
+ sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"Workstation\"/g"
# Create SqashFS image.
ltsp image /,,/boot,subdir=boot,,/usr,subdir=usr,,/var,subdir=var
# Revert resolver workaround from above.
rm -f /etc/resolv.conf
ln -s /run/resolvconf/resolv.conf /etc/resolv.conf
+ # Revert temporary change to PROFILE in /etc/debian-edu/config
+ sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"${PROFILE}\"/g"
# next modification avoids ltsp command error if lot of images are available.
ALL_IMAGES=1 ltsp kernel
ltsp initrd
@@ -675,7 +677,7 @@ EOF
chroot /srv/ltsp/dlw apt-get install -y -qq apt-utils ltsp
# Turn system into a Debian Edu workstation.
- chroot /srv/ltsp/dlw sh -c "DESKTOP=$desktop /sbin/debian-edu-bless"
+ chroot /srv/ltsp/dlw sh -c "PROFILE=Workstation DESKTOP=$desktop /sbin/debian-edu-bless"
mkdir -p /srv/ltsp/dlw/skole
chmod 755 /srv/ltsp/dlw/skole
rm -f /srv/ltsp/dlw/etc/resolv.conf
=====================================
share/debian-edu-config/killer.cron deleted
=====================================
@@ -1,3 +0,0 @@
-#!/bin/sh
-
-if [ "$(ps aux | grep sshd: | grep @notty)" = "" ] && [ -x /usr/sbin/killer ] ; then /usr/sbin/killer; fi
=====================================
share/debian-edu-config/tools/kerberos-kdc-init
=====================================
@@ -173,7 +173,6 @@ mit_kerberos_kdc() {
kdc_ports = 750,88
max_life = 10h 0m 0s
max_renewable_life = 7d 0h 0m 0s
- master_key_type = des3-hmac-sha1
default_principal_flags = +preauth
}
EOF
=====================================
share/debian-edu-config/tools/run-at-firstboot
=====================================
@@ -26,6 +26,14 @@ at_exit() {
error "script $0 terminated unexpectedly."
}
disable_exception() { trap - INT TERM EXIT; }
+is_ltsp_client() {
+ if grep -q "initrd=ltsp.img" < /proc/cmdline; then
+ return 0
+ else
+ return 1
+ fi
+}
+
trap at_exit INT TERM EXIT
info "Executing run-at-firstboot script."
@@ -62,9 +70,23 @@ fi
# information from some daemons isn't available during installation. It's done
# for a combined server but not for a separate LTSP server because the image
# needs to include the krb5.keytab file which isn't available at this time.
-if echo "$PROFILE" | grep -Eq 'Main-Server.*LTSP-Server' && \
- [ ! -f /srv/ltsp/images/$ltspimg ] ; then
- /usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+if ! is_ltsp_client; then
+ # If this runs on a combi server (Main-Server + LTSP-Server), create
+ # Diskless Workstation chroot from scratch as clean environment.
+ if echo "$PROFILE" | grep -Eq 'Main-Server' && \
+ echo "$PROFILE" | grep -Eq 'LTSP-Server'; then
+ if [ ! -d /srv/ltsp/dlw ]; then
+ /usr/sbin/debian-edu-ltsp-install --dlw yes
+ fi
+ # else if this runs on a pure LTSP-Server (no Main-Server role), then
+ # let's use the file system of the LTSP-Server and generate the LTSP
+ # image directly from it (faster!).
+ elif echo "$PROFILE" | grep -Eqv 'Main-Server' && \
+ echo "$PROFILE" | grep -Eq 'LTSP-Server'; then
+ if [ ! -f /srv/ltsp/images/$ltspimg ] ; then
+ /usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+ fi
+ fi
fi
# Update PXE setup on LTSP servers with proxy values set in environment
@@ -100,10 +122,11 @@ fi
# Send mail to the first user to avoid the Dovecot permission pitfall
# also in this special case. It doesn't seem to work during installation,
# because Exim4 needs to grab information from LDAP which fails at that time.
-FIRSTUSER=$(grep -1 first-user-name /var/cache/debconf/config.dat | grep Value | cut -d' ' -f2)
+if echo "$PROFILE" | grep -q Main-Server ; then
+ FIRSTUSER=$(grep -1 first-user-name /var/cache/debconf/config.dat | grep Value | cut -d' ' -f2)
-if [ ! -d /var/mail/"$FIRSTUSER" ] ; then
- cat << EOF | /usr/lib/sendmail $FIRSTUSER
+ if [ ! -d /var/mail/"$FIRSTUSER" ] ; then
+ cat << EOF | /usr/lib/sendmail $FIRSTUSER
Subject: Welcome to the mail-system
Hello $FIRSTUSER,
@@ -113,7 +136,8 @@ welcome to the mail-system.
(Sent from the Debian Edu first boot script.)
EOF
- logger -t exim-create-environment -p notice Sent mail to first-user.
+ logger -t exim-create-environment -p notice Sent mail to first-user.
+ fi
fi
# Create first user's Samba account. The smbpasswd command fails inside d-i
=====================================
share/debian-edu-config/tools/setup-roaming
=====================================
@@ -27,10 +27,6 @@ apt-get purge -y libpam-krb5
# Avoid double caching, as sssd is already caching
apt-get purge -y nscd
-# Roaming workstations are typically single user machines, so do not
-# throw out the user if he is idle.
-apt-get purge -y killer
-
# try to configure sssd dynamically, fall back to default setup if
# generation fail
# sssd refuses to read the sssd.conf file unless it is 0600 root:root
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/b39e10a76de68a0a02ac4e22fe8079079b9d711a...7f855d629f686410fd66dc6d93572cf36cfa46a6
--
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/b39e10a76de68a0a02ac4e22fe8079079b9d711a...7f855d629f686410fd66dc6d93572cf36cfa46a6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260921/d7280223/attachment-0001.htm>
More information about the debian-edu-commits
mailing list