Annotation of src/etc/daily, Revision 1.42
1.1 deraadt 1: #!/bin/sh -
2: #
1.42 ! pvalchev 3: # $OpenBSD: daily,v 1.41 2002/12/07 20:16:19 millert Exp $
1.17 millert 4: # From: @(#)daily 8.2 (Berkeley) 1/25/94
1.1 deraadt 5: #
1.17 millert 6: PATH=/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin
7: bak=/var/backups
1.1 deraadt 8:
1.21 deraadt 9: if [ -f /etc/daily.local ]; then
1.2 david 10: echo ""
11: echo "Running daily.local:"
12: . /etc/daily.local
13: fi
14:
1.16 millert 15: TMP=`mktemp /tmp/_daily.XXXXXX` || exit 1
1.42 ! pvalchev 16: OUT=`mktemp /tmp/_security.XXXXXX` || {
! 17: rm -f ${TMP}
! 18: exit 1
! 19: }
1.16 millert 20:
1.33 marc 21: trap 'rm -f $TMP $OUT' 0 1 15
1.14 millert 22:
1.1 deraadt 23: echo ""
1.17 millert 24: echo "Removing scratch and junk files:"
1.32 aaron 25: if [ -d /tmp -a ! -L /tmp ]; then
1.17 millert 26: cd /tmp && {
1.37 espie 27: find -x . \( -path './ssh-*' -o -path './.X11-unix' \) -prune -o \
1.31 millert 28: -type f -atime +3 -execdir rm -f -- {} \;
1.28 deraadt 29: find -x . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.17 millert 30: >/dev/null 2>&1; }
31: fi
1.1 deraadt 32:
1.32 aaron 33: if [ -d /var/tmp -a ! -L /var/tmp ]; then
1.17 millert 34: cd /var/tmp && {
1.37 espie 35: find -x . \( -path './ssh-*' -o -path './.X11-unix' \) -prune -o \
1.31 millert 36: ! -type d -atime +7 -execdir rm -f -- {} \;
1.28 deraadt 37: find -x . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.17 millert 38: >/dev/null 2>&1; }
39: fi
1.1 deraadt 40:
1.3 deraadt 41: # Additional junk directory cleanup would go like this:
1.32 aaron 42: #if [ -d /scratch -a ! -L /scratch ]; then
1.3 deraadt 43: # cd /scratch && {
1.17 millert 44: # find . ! -name . -atime +1 -execdir rm -f -- {} \;
45: # find . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.3 deraadt 46: # >/dev/null 2>&1; }
47: #fi
1.1 deraadt 48:
1.32 aaron 49: if [ -d /var/preserve -a ! -L /var/preserve ]; then
1.17 millert 50: cd /var/preserve && {
51: find . ! -name . -mtime +7 -execdir rm -f -- {} \; ; }
52: fi
53:
1.32 aaron 54: if [ -d /var/rwho -a ! -L /var/rwho ] ; then
1.17 millert 55: cd /var/rwho && {
56: find . ! -name . -mtime +7 -execdir rm -f -- {} \; ; }
57: fi
1.1 deraadt 58:
1.24 deraadt 59: #find / \( ! -fstype local -o -fstype rdonly -o -fstype fdesc \
60: # -o -fstype kernfs -o -fstype procfs \) -a -prune -o \
61: # -name 'lost+found' -a -prune -o \
62: # -name '*.core' -a -print -o \
63: # \( -name '[#,]*' -o -name '.#*' -o -name a.out \
64: # -o -name '*.CKP' -o -name '.emacs_[0-9]*' \) \
65: # -a -atime +3 -a -execdir rm -f -- {} \; -a -print > $TMP
1.1 deraadt 66:
1.14 millert 67: if egrep -q '\.core$' $TMP; then
1.17 millert 68: echo ""
69: echo "Possible core dumps:"
70: egrep '\.core$' $TMP
71: fi
72:
73: if egrep -qv '\.core$' $TMP; then
74: echo ""
75: echo "Deleted files:"
76: egrep -v '\.core$' $TMP
1.14 millert 77: fi
1.1 deraadt 78:
1.26 downsj 79: if [ -d /var/msgs -a ! -L /var/msgs ]; then
80: msgs -c
81: fi
1.1 deraadt 82:
1.17 millert 83: if [ -s /etc/news.expire ]; then
1.1 deraadt 84: /etc/news.expire
85: fi
86:
87: if [ -f /var/account/acct ]; then
1.17 millert 88: echo ""
89: echo "Purging accounting records:"
90: mv /var/account/acct.2 /var/account/acct.3
91: mv /var/account/acct.1 /var/account/acct.2
92: mv /var/account/acct.0 /var/account/acct.1
93: cp /var/account/acct /var/account/acct.0
94: sa -sq
95: fi
96:
97: # If ROOTBACKUP is set to 1 in the environment, and
98: # if filesystem named /altroot is type ffs, on /dev/* and mounted "xx",
99: # use it as a backup root filesystem to be updated daily.
100: [ "X$ROOTBACKUP" = X1 ] && {
101: rootdev=`awk '$2 == "/" && $1 ~ /^\/dev\// && $3 == "ffs" && \
1.29 todd 102: $4 ~ /rw/ \
1.17 millert 103: { print substr($1, 6) }' < /etc/fstab`
104: rootbak=`awk '$2 == "/altroot" && $1 ~ /^\/dev\// && $3 == "ffs" && \
1.29 todd 105: $4 ~ /xx/ \
1.17 millert 106: { print substr($1, 6) }' < /etc/fstab`
107: [ X$rootdev != X -a X$rootbak != X ] && {
108: sync
109: echo ""
110: echo "Backing up root filesystem:"
111: echo "copying /dev/r$rootdev to /dev/r$rootbak"
112: dd if=/dev/r$rootdev of=/dev/r$rootbak bs=16b seek=1 skip=1 \
1.22 mickey 113: conv=noerror
1.17 millert 114: fsck -y /dev/r$rootbak
115: }
116: }
1.1 deraadt 117:
118: # Rotation of mail log now handled automatically by cron and 'newsyslog'
119:
120: echo ""
121: echo "Checking subsystem status:"
122: echo ""
123: echo "disks:"
1.40 danh 124: df -kl
1.1 deraadt 125: echo ""
126: dump W
127: echo ""
128:
1.15 millert 129: mailq > $TMP
1.34 angelos 130: if ! grep -q "^/var/spool/mqueue is empty$" $TMP; then
1.15 millert 131: echo ""
132: echo "mail:"
133: cat $TMP
1.1 deraadt 134: fi
135:
136: echo ""
137: echo "network:"
1.35 niklas 138: netstat -ivn
1.1 deraadt 139: echo ""
1.14 millert 140:
1.15 millert 141: t=/var/rwho/*
142: if [ "$t" != '/var/rwho/*' ]; then
1.17 millert 143: echo ""
1.14 millert 144: ruptime
1.38 millert 145: fi
146:
147: echo ""
148: if [ -d /var/yp/binding -a ! -d /var/yp/`domainname` -o "X$CALENDAR" = X0 ]
149: then
150: if [ "X$CALENDAR" = X0 ]; then
151: echo "Not running calendar, (disabled)."
152: else
153: echo "Not running calendar, (yp client)."
154: fi
155: else
156: echo "Running calendar in the background."
157: calendar -a &
1.14 millert 158: fi
1.1 deraadt 159:
1.17 millert 160: # If CHECKFILESYSTEMS is set to 1 in the environment, run fsck
161: # with the no-write flag.
162: [ "X$CHECKFILESYSTEMS" = X1 ] && {
163: echo ""
164: echo "Checking filesystems:"
165: fsck -n | grep -v '^\*\* Phase'
166: }
1.1 deraadt 167:
168: if [ -f /etc/Distfile ]; then
1.17 millert 169: echo ""
1.1 deraadt 170: echo "Running rdist:"
1.17 millert 171: if [ -d /var/log/rdist ]; then
1.19 deraadt 172: logf=`date +%Y.%b.%e`
1.17 millert 173: rdist -f /etc/Distfile 2>&1 | tee /var/log/rdist/$logf
174: else
1.39 deraadt 175: rdist -f /etc/Distfile
1.17 millert 176: fi
1.1 deraadt 177: fi
178:
1.33 marc 179: sh /etc/security 2>&1 > $OUT
180: if [ -s $OUT ]; then
1.41 millert 181: mail -s "`hostname` daily insecurity output" root < $OUT
1.33 marc 182: fi