mirror of
https://github.com/bin456789/reinstall.git
synced 2026-10-11 17:59:50 +08:00
core: 支持 linux 设置普通账号
This commit is contained in:
+117
-31
@@ -24,13 +24,9 @@ d-i mirror/country string manual
|
||||
# d-i mirror/http/hostname string deb.debian.org
|
||||
|
||||
# B.4.5. 帐号设置
|
||||
d-i passwd/make-user boolean false
|
||||
# 注意如果用 ssh key 后面还要删除密码
|
||||
# d-i passwd/root-password password ''
|
||||
# d-i passwd/root-password-again password ''
|
||||
# d-i passwd/root-password-crypted password ''
|
||||
# kali 需要下面这行,否则会提示输入用户名
|
||||
d-i passwd/root-login boolean true
|
||||
# kali 需要设置这行,否则会提示输入用户名
|
||||
# 因为 kali installer initrd 内置了一个 preseed.cfg,设置了 passwd/root-login false
|
||||
# d-i passwd/root-login boolean true
|
||||
|
||||
# B.4.6. 时钟与时区设置
|
||||
d-i time/zone string Asia/Shanghai
|
||||
@@ -121,6 +117,19 @@ d-i grub-installer/force-efi-extra-removable boolean true
|
||||
|
||||
# debian 11+ 才有 websocketd
|
||||
|
||||
# debian 9 sshd_config 不支持 Include
|
||||
|
||||
# di 环境下 /etc/passwd 设置了 root 的家目录是 /,不是常见的 /root
|
||||
# 我们不修改它,防止出问题
|
||||
|
||||
# di 环境下 锁定用户将无法登录 ssh
|
||||
|
||||
# passwd/root-password-crypted 是 ! 开头时会提示输入密码
|
||||
# 因此这个值设成 *
|
||||
# https://salsa.debian.org/installer-team/user-setup/-/blob/1.109/user-setup-ask?ref_type=tags#L35
|
||||
|
||||
# screen 需要设置 +s 权限,否则普通用户无法 attach 到 root 的 screen 会话
|
||||
|
||||
# 有 /cdrom/simple-cdd 才安装 simple-cdd-profiles
|
||||
# 不然安装时 control 脚本会报错:
|
||||
# Loading simple-cdd-profiles failed for unknown reasons
|
||||
@@ -133,6 +142,9 @@ d-i grub-installer/force-efi-extra-removable boolean true
|
||||
# 此时还没有配置源,anna-install 会在配置完源后再安装
|
||||
d-i preseed/early_command string true; \
|
||||
for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \
|
||||
username=${username:-root}; \
|
||||
ssh_port=${ssh_port:-22}; \
|
||||
web_port=${web_port:-80}; \
|
||||
|
||||
di(){ \
|
||||
echo "d-i $*" >/tmp/selections.cfg; \
|
||||
@@ -150,6 +162,11 @@ d-i preseed/early_command string true; \
|
||||
cp -f /etc/screenrc.bak /etc/screenrc; \
|
||||
}; \
|
||||
|
||||
chmod +s /usr/bin/screen; \
|
||||
|
||||
screen -x root/ -X multiuser on; \
|
||||
screen -x root/ -X acladd "$username"; \
|
||||
|
||||
if [ "$hold" = 1 ]; then \
|
||||
di auto-install/enable boolean false; \
|
||||
di debconf/priority select low; \
|
||||
@@ -160,7 +177,9 @@ d-i preseed/early_command string true; \
|
||||
echo 'Option 1. View logs:'; \
|
||||
echo ' tail -fn+1 /var/log/syslog'; \
|
||||
echo 'Option 2. Attach to the installer:'; \
|
||||
echo ' TERM=screen screen -xp1'; \
|
||||
echo ' TERM=screen screen -x root/ -p 1'; \
|
||||
echo 'Option 3. Attach to the root shell if you are not root:'; \
|
||||
echo ' TERM=screen screen -x root/ -p 2'; \
|
||||
} >>/etc/motd; \
|
||||
mem=$(grep ^MemTotal: /proc/meminfo | { read -r _ y _; echo "$((y / 1024))"; }); \
|
||||
if command -v websocketd && [ "$mem" -ge 400 ]; then \
|
||||
@@ -170,10 +189,7 @@ d-i preseed/early_command string true; \
|
||||
fi; \
|
||||
sleep 5; \
|
||||
done; \
|
||||
if [ -z "$web_port" ]; then \
|
||||
web_port=80; \
|
||||
fi; \
|
||||
run_as_service_with_screen websocketd --port 80 --loglevel=fatal --staticdir=/tmp \
|
||||
run_as_service_with_screen websocketd --port "$web_port" --loglevel=fatal --staticdir=/tmp \
|
||||
sh -c "tail -fn+0 /var/log/syslog | tr '\r' '\n' | grep -Fiv -e password -e token" ; \
|
||||
fi; \
|
||||
fi; \
|
||||
@@ -182,25 +198,64 @@ d-i preseed/early_command string true; \
|
||||
di finish-install/reboot_in_progress note; \
|
||||
fi; \
|
||||
|
||||
if [ -s /configs/ssh_keys ]; then \
|
||||
di passwd/root-password-crypted password "''"; \
|
||||
mkdir -p /home; \
|
||||
chmod 755 /home; \
|
||||
|
||||
if [ "$username" = "root" ]; then \
|
||||
uid=0; \
|
||||
scope=root; \
|
||||
user_home=/; \
|
||||
di passwd/root-login boolean true; \
|
||||
di passwd/make-user boolean false; \
|
||||
else \
|
||||
di passwd/root-password-crypted password "$(cat /configs/password-linux-sha512)"; \
|
||||
uid=1000; \
|
||||
scope=user; \
|
||||
user_home=/home/$username; \
|
||||
di passwd/root-login boolean false; \
|
||||
di passwd/make-user boolean true; \
|
||||
di passwd/user-fullname string "$username"; \
|
||||
di passwd/username string "$username"; \
|
||||
fi; \
|
||||
|
||||
mkdir -p /etc/ssh; \
|
||||
true >/etc/ssh/sshd_config; \
|
||||
if [ -s /configs/ssh_keys ]; then \
|
||||
(umask 077; mkdir -p /.ssh; cat /configs/ssh_keys >/.ssh/authorized_keys); \
|
||||
password_hash_for_initrd=''; \
|
||||
password_hash_for_preseed='*'; \
|
||||
else \
|
||||
echo "PermitRootLogin yes" >>/etc/ssh/sshd_config; \
|
||||
password_hash_for_initrd=$(cat /configs/password-linux-sha512); \
|
||||
password_hash_for_preseed=$(cat /configs/password-linux-sha512); \
|
||||
fi; \
|
||||
if [ -n "$ssh_port" ] && ! [ "$ssh_port" = 22 ]; then \
|
||||
echo "Port $ssh_port" >>/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
grep -qs ^root: /etc/shadow || echo "root:$(cat /configs/password-linux-sha512):1:0:99999:7:::" >>/etc/shadow; \
|
||||
|
||||
di passwd/$scope-password-crypted password "$password_hash_for_preseed"; \
|
||||
|
||||
grep -qs ^$username: /etc/passwd || echo "$username:*:$uid:$uid:$username:$user_home:/bin/sh" >>/etc/passwd; \
|
||||
grep -qs ^$username: /etc/group || echo "$username:*:$uid:" >>/etc/group; \
|
||||
grep -qs ^$username: /etc/shadow || echo "$username:$password_hash_for_initrd:1:0:99999:7:::" >>/etc/shadow; \
|
||||
grep -qs ^nogroup: /etc/group || echo "nogroup:*:65534:" >>/etc/group; \
|
||||
grep -qs ^sshd: /etc/passwd || echo "sshd:*:100:65534::/run/sshd:/bin/false" >>/etc/passwd; \
|
||||
|
||||
mkdir -p /etc/ssh/; \
|
||||
true >/etc/ssh/sshd_config; \
|
||||
|
||||
if [ -s /configs/ssh_keys ]; then \
|
||||
( \
|
||||
umask 077; \
|
||||
mkdir -p "$user_home/.ssh"; \
|
||||
cat /configs/ssh_keys >"$user_home/.ssh/authorized_keys"; \
|
||||
); \
|
||||
chown "$username:$username" "$user_home"; \
|
||||
chown "$username:$username" "$user_home/.ssh"; \
|
||||
chown "$username:$username" "$user_home/.ssh/authorized_keys"; \
|
||||
echo "PasswordAuthentication no" >>/etc/ssh/sshd_config; \
|
||||
else \
|
||||
if [ "$username" = root ]; then \
|
||||
echo "PermitRootLogin yes" >>/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
fi; \
|
||||
|
||||
if ! [ "$ssh_port" = 22 ]; then \
|
||||
echo "Port $ssh_port" >>/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
|
||||
mkdir -p /run/sshd; \
|
||||
chmod 0755 /run/sshd; \
|
||||
ssh-keygen -A; \
|
||||
@@ -230,7 +285,11 @@ d-i preseed/early_command string true; \
|
||||
# efi 分区大小未改变时,不会被格式化,因此需要手动删除旧系统的 efi 文件
|
||||
# os-prober 卡太久,因此跳过
|
||||
d-i partman/early_command string true; \
|
||||
eval "$(grep -o 'extra_confhome=[^ ]*' /proc/cmdline | sed 's/^extra_//')"; \
|
||||
for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \
|
||||
username=${username:-root}; \
|
||||
ssh_port=${ssh_port:-22}; \
|
||||
web_port=${web_port:-80}; \
|
||||
|
||||
|
||||
postinst=/var/lib/dpkg/info/bootstrap-base.postinst; \
|
||||
cp $postinst $postinst.orig; \
|
||||
@@ -276,6 +335,9 @@ d-i partman/early_command string true; \
|
||||
# debian 9 tar 不支持 --strip-components
|
||||
d-i preseed/late_command string true; \
|
||||
for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \
|
||||
username=${username:-root}; \
|
||||
ssh_port=${ssh_port:-22}; \
|
||||
web_port=${web_port:-80}; \
|
||||
|
||||
if [ "$elts" = 1 ]; then sed -i "s|deb\.freexian\.com/extended-lts|$deb_mirror|" /target/etc/apt/sources.list; fi; \
|
||||
|
||||
@@ -283,19 +345,43 @@ d-i preseed/late_command string true; \
|
||||
|
||||
in-target systemctl enable ssh; \
|
||||
|
||||
if [ -s /configs/ssh_keys ]; then \
|
||||
(umask 077; mkdir -p /target/root/.ssh; cat /configs/ssh_keys >/target/root/.ssh/authorized_keys); \
|
||||
in-target passwd -d root; \
|
||||
if [ "$username" = root ]; then \
|
||||
user_home=/root; \
|
||||
else \
|
||||
echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \
|
||||
echo "PermitRootLogin yes" >>/target/etc/ssh/sshd_config; \
|
||||
user_home=/home/$username; \
|
||||
fi; \
|
||||
|
||||
if [ -n "$ssh_port" ] && ! [ "$ssh_port" = 22 ]; then \
|
||||
echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-change-ssh-port.conf || \
|
||||
if [ -s /configs/ssh_keys ]; then \
|
||||
( \
|
||||
umask 077; \
|
||||
mkdir -p "/target/$user_home/.ssh"; \
|
||||
cat /configs/ssh_keys >"/target/$user_home/.ssh/authorized_keys"; \
|
||||
); \
|
||||
in-target passwd -d -l "$username"; \
|
||||
in-target chown "$username:$username" "$user_home"; \
|
||||
in-target chown "$username:$username" "$user_home/.ssh"; \
|
||||
in-target chown "$username:$username" "$user_home/.ssh/authorized_keys"; \
|
||||
|
||||
echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \
|
||||
echo "PasswordAuthentication no" >>/target/etc/ssh/sshd_config; \
|
||||
|
||||
else \
|
||||
if [ "$username" = root ]; then \
|
||||
echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \
|
||||
echo "PermitRootLogin yes" >>/target/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
fi; \
|
||||
|
||||
if ! [ "$ssh_port" = 22 ]; then \
|
||||
echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-port.conf || \
|
||||
echo "Port $ssh_port" >>/target/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
|
||||
if ! [ "$username" = root ]; then \
|
||||
printf '%s\n' "$username ALL=(ALL) NOPASSWD:ALL" >"/target/etc/sudoers.d/99-$username"; \
|
||||
chmod 0440 "/target/etc/sudoers.d/99-$username"; \
|
||||
fi; \
|
||||
|
||||
if ls /configs/frpc.* >/dev/null 2>&1; then \
|
||||
mkdir -p /target/usr/local/bin; \
|
||||
mkdir -p /target/usr/local/etc/frpc; \
|
||||
|
||||
Reference in New Issue
Block a user