Annotation of src/etc/daily, Revision 1.48
1.1 deraadt 1: #!/bin/sh -
2: #
1.48 ! millert 3: # $OpenBSD: daily,v 1.47 2004/11/15 18:10:48 nick Exp $
1.17 millert 4: # From: @(#)daily 8.2 (Berkeley) 1/25/94
1.1 deraadt 5: #
1.17 millert 6: PATH=/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin
7: bak=/var/backups
1.47 nick 8:
9: sysctl -n kern.version
1.1 deraadt 10:
1.21 deraadt 11: if [ -f /etc/daily.local ]; then
1.2 david 12: echo ""
13: echo "Running daily.local:"
14: . /etc/daily.local
15: fi
16:
1.45 avsm 17: TMP=`mktemp /tmp/_daily.XXXXXXXXXX` || exit 1
18: OUT=`mktemp /tmp/_security.XXXXXXXXXX` || {
1.42 pvalchev 19: rm -f ${TMP}
20: exit 1
21: }
1.16 millert 22:
1.33 marc 23: trap 'rm -f $TMP $OUT' 0 1 15
1.14 millert 24:
1.1 deraadt 25: echo ""
1.17 millert 26: echo "Removing scratch and junk files:"
1.32 aaron 27: if [ -d /tmp -a ! -L /tmp ]; then
1.17 millert 28: cd /tmp && {
1.37 espie 29: find -x . \( -path './ssh-*' -o -path './.X11-unix' \) -prune -o \
1.31 millert 30: -type f -atime +3 -execdir rm -f -- {} \;
1.28 deraadt 31: find -x . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.17 millert 32: >/dev/null 2>&1; }
33: fi
1.1 deraadt 34:
1.32 aaron 35: if [ -d /var/tmp -a ! -L /var/tmp ]; then
1.17 millert 36: cd /var/tmp && {
1.37 espie 37: find -x . \( -path './ssh-*' -o -path './.X11-unix' \) -prune -o \
1.31 millert 38: ! -type d -atime +7 -execdir rm -f -- {} \;
1.28 deraadt 39: find -x . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.17 millert 40: >/dev/null 2>&1; }
41: fi
1.1 deraadt 42:
1.3 deraadt 43: # Additional junk directory cleanup would go like this:
1.32 aaron 44: #if [ -d /scratch -a ! -L /scratch ]; then
1.3 deraadt 45: # cd /scratch && {
1.17 millert 46: # find . ! -name . -atime +1 -execdir rm -f -- {} \;
47: # find . ! -name . -type d -mtime +1 -execdir rmdir -- {} \; \
1.3 deraadt 48: # >/dev/null 2>&1; }
49: #fi
1.17 millert 50:
1.32 aaron 51: if [ -d /var/rwho -a ! -L /var/rwho ] ; then
1.17 millert 52: cd /var/rwho && {
53: find . ! -name . -mtime +7 -execdir rm -f -- {} \; ; }
54: fi
1.1 deraadt 55:
1.24 deraadt 56: #find / \( ! -fstype local -o -fstype rdonly -o -fstype fdesc \
57: # -o -fstype kernfs -o -fstype procfs \) -a -prune -o \
58: # -name 'lost+found' -a -prune -o \
59: # -name '*.core' -a -print -o \
60: # \( -name '[#,]*' -o -name '.#*' -o -name a.out \
61: # -o -name '*.CKP' -o -name '.emacs_[0-9]*' \) \
62: # -a -atime +3 -a -execdir rm -f -- {} \; -a -print > $TMP
1.1 deraadt 63:
1.14 millert 64: if egrep -q '\.core$' $TMP; then
1.17 millert 65: echo ""
66: echo "Possible core dumps:"
67: egrep '\.core$' $TMP
68: fi
69:
70: if egrep -qv '\.core$' $TMP; then
71: echo ""
72: echo "Deleted files:"
73: egrep -v '\.core$' $TMP
1.14 millert 74: fi
1.1 deraadt 75:
1.26 downsj 76: if [ -d /var/msgs -a ! -L /var/msgs ]; then
77: msgs -c
1.1 deraadt 78: fi
79:
80: if [ -f /var/account/acct ]; then
1.17 millert 81: echo ""
82: echo "Purging accounting records:"
1.44 mickey 83: mv -f /var/account/acct.2 /var/account/acct.3
84: mv -f /var/account/acct.1 /var/account/acct.2
85: mv -f /var/account/acct.0 /var/account/acct.1
86: cp -f /var/account/acct /var/account/acct.0
1.17 millert 87: sa -sq
88: fi
89:
90: # If ROOTBACKUP is set to 1 in the environment, and
91: # if filesystem named /altroot is type ffs, on /dev/* and mounted "xx",
92: # use it as a backup root filesystem to be updated daily.
93: [ "X$ROOTBACKUP" = X1 ] && {
1.48 ! millert 94: rootdev=`df -n / | awk '/^\/dev\// { print substr($1, 6) }'`
1.17 millert 95: rootbak=`awk '$2 == "/altroot" && $1 ~ /^\/dev\// && $3 == "ffs" && \
1.29 todd 96: $4 ~ /xx/ \
1.17 millert 97: { print substr($1, 6) }' < /etc/fstab`
1.48 ! millert 98: [ X$rootdev != X -a X$rootbak != X -a X$rootdev != X$rootbak ] && {
1.17 millert 99: sync
100: echo ""
101: echo "Backing up root filesystem:"
102: echo "copying /dev/r$rootdev to /dev/r$rootbak"
103: dd if=/dev/r$rootdev of=/dev/r$rootbak bs=16b seek=1 skip=1 \
1.22 mickey 104: conv=noerror
1.17 millert 105: fsck -y /dev/r$rootbak
106: }
107: }
1.1 deraadt 108:
109: # Rotation of mail log now handled automatically by cron and 'newsyslog'
110:
111: echo ""
112: echo "Checking subsystem status:"
113: echo ""
114: echo "disks:"
1.40 danh 115: df -kl
1.1 deraadt 116: echo ""
117: dump W
118: echo ""
119:
1.15 millert 120: mailq > $TMP
1.34 angelos 121: if ! grep -q "^/var/spool/mqueue is empty$" $TMP; then
1.15 millert 122: echo ""
123: echo "mail:"
124: cat $TMP
1.1 deraadt 125: fi
126:
127: echo ""
128: echo "network:"
1.35 niklas 129: netstat -ivn
1.1 deraadt 130: echo ""
1.14 millert 131:
1.15 millert 132: t=/var/rwho/*
133: if [ "$t" != '/var/rwho/*' ]; then
1.17 millert 134: echo ""
1.14 millert 135: ruptime
1.38 millert 136: fi
137:
138: echo ""
139: if [ -d /var/yp/binding -a ! -d /var/yp/`domainname` -o "X$CALENDAR" = X0 ]
140: then
141: if [ "X$CALENDAR" = X0 ]; then
142: echo "Not running calendar, (disabled)."
143: else
144: echo "Not running calendar, (yp client)."
145: fi
146: else
147: echo "Running calendar in the background."
148: calendar -a &
1.14 millert 149: fi
1.1 deraadt 150:
1.17 millert 151: # If CHECKFILESYSTEMS is set to 1 in the environment, run fsck
152: # with the no-write flag.
153: [ "X$CHECKFILESYSTEMS" = X1 ] && {
154: echo ""
155: echo "Checking filesystems:"
156: fsck -n | grep -v '^\*\* Phase'
157: }
1.1 deraadt 158:
159: if [ -f /etc/Distfile ]; then
1.17 millert 160: echo ""
1.1 deraadt 161: echo "Running rdist:"
1.17 millert 162: if [ -d /var/log/rdist ]; then
1.19 deraadt 163: logf=`date +%Y.%b.%e`
1.17 millert 164: rdist -f /etc/Distfile 2>&1 | tee /var/log/rdist/$logf
165: else
1.39 deraadt 166: rdist -f /etc/Distfile
1.17 millert 167: fi
1.1 deraadt 168: fi
169:
1.33 marc 170: sh /etc/security 2>&1 > $OUT
171: if [ -s $OUT ]; then
1.41 millert 172: mail -s "`hostname` daily insecurity output" root < $OUT
1.33 marc 173: fi