hcoop-backup: More permissions twiddling.
[clinton/scripts.git] / hcoop-backup
1 #!/bin/bash -e
2
3 #
4 # it is dangerous to remove the "-e" above; please don't do that.
5 #
6
7 #
8 # run this script as root, on deleuze
9 #
10
11 PATH=$PATH:/bin:/usr/bin:/sbin:/usr/sbin
12 #COMPRESS_EXT=.bz2
13 #COMPRESS_PROG=bzip2
14 COMPRESS_EXT=.gz
15 COMPRESS_PROG=gzip
16 KEYFILE=/etc/backup-encryption-key
17 BACKUPTMP=/var/backups/hcoop-backup
18 CURDATE=$(date -u +%Y.%m.%d)
19
20 MOVE_OVER=$(dirname $0)/rsync.net-move-over
21
22 IFS=$'\n'
23
24 # Initialize storage area
25 RSYNCDIR=/vicepa/hcoop-backups/files
26 rm -fr $RSYNCDIR
27 mkdir -p $RSYNCDIR/$CURDATE
28 chmod og=rx,u=rwx $RSYNCDIR
29 chmod og= $RSYNCDIR/$CURDATE
30
31 # Initialize backup staging area
32 mkdir -p $BACKUPTMP
33 cd $BACKUPTMP
34
35 groups
36 echo "I am in: $(pwd)"
37 echo
38
39 echo "Building package lists..."
40 dpkg-query -W -f='${Package}\n' > packages
41 (cd /; find / /usr/ /usr/local/ /var/ -xdev) | sort | uniq > allfiles
42 dpkg-query -W -f='${Package}\n' | xargs dpkg -L | sort | uniq > debfiles
43 dpkg-query -W -f='${Conffiles}\n' | grep / | cut -b2- | \
44 sed 's_ .*__' | sort | uniq > conffiles
45
46 diff allfiles debfiles | grep '^<' | cut -b 3- | \
47 grep -v ^/var/cache | \
48 grep -v ^/var/tmp | \
49 grep -v ^/var/lib/dpkg | \
50 grep -v ^/var/backups | \
51 grep -v ^/var/lib/changetrack | \
52 grep -v ^/var/local/lib/spamd | \
53 grep -v ^/var/run | \
54 grep -v ^/var/lock | \
55 grep -v ^/var/lib/ucf | \
56 grep -v ^/vicepa | \
57 grep -v ^/home | \
58 grep -v ^/tmp | \
59 grep -v '^/afs$' | \
60 grep -v '^/$' | \
61 grep -v '^/usr/$' | \
62 grep -v ^/usr/src | \
63 grep -v '^/usr/.*\.pyc' | \
64 grep -v '^/usr/.*\.elc' | \
65 grep -v '^/usr/bin/perldoc\.stub$' | \
66 grep -v '^/usr/bin/.*\.notslocate$' | \
67 grep -v '^/usr/lib/courier/.*\.rand$' | \
68 grep -v '^/usr/lib/gconv/gconv-modules\.cache$' | \
69 grep -v '^/usr/lib/graphviz/config$' | \
70 grep -v '^/usr/lib/locale/locale-archive$' | \
71 grep -v '^/usr/share/info/dir$' | \
72 grep -v '^/usr/share/info/dir\.old$' | \
73 grep -v '^/usr/share/emacs21/site-lisp/' | \
74 grep -v '^/usr/share/emacs22/site-lisp/' | \
75 grep -v '^/usr/share/snmp/mibs/\.index$' | \
76 grep -v '^/usr/share/vim/addons/doc/tags$' \
77 > backupfiles
78
79 cat conffiles >> backupfiles
80
81 cat backupfiles | \
82 grep -v ^/home | \
83 grep -v ^/usr/local | \
84 grep -v ^/var/spool | \
85 grep -v ^/var/log | \
86 grep -v ^/usr/lib/python2.4/ | \
87 grep -v ^/var/lib/python-support | \
88 grep -v ^/usr/share/jed/lib | \
89 grep -v ^/usr/share/man | \
90 grep -v ^/usr/share/perl5/IkiWiki/Plugin | \
91 grep -v ^/media | \
92 grep -v ^/vmlinuz | \
93 grep -v ^/vmlinuz.old | \
94 grep -v '^/sbin/[a-z\-]*\.modutils$' | \
95 grep -v ^/opt | \
96 grep -v ^/boot/ | \
97 grep -v ^/dev/ | \
98 grep -v ^/etc/ | \
99 grep -v ^/root/ | \
100 grep -v ^/var/ | \
101 grep -v ^/lib/modules/ | \
102 grep -v ^/var/domtool/ | \
103 grep -v ^/var/lib/mysql/ | \
104 grep -v ^/var/lib/postgres/ | \
105 grep -v ^/var/lib/postgresql/ | \
106 xargs -I{} -d\\n -- bash -c "test -L '{}' || echo '{}'" > complain
107
108 F=hcoop.backup.tar$COMPRESS_EXT.aescrypt
109 tar clpf - --ignore-failed-read --no-recursion -C / -T backupfiles | \
110 $COMPRESS_PROG | \
111 ccrypt -k $KEYFILE -e | \
112 $MOVE_OVER $CURDATE $F
113
114 # Acquire lock before messing with spamd
115 COUNT=0
116 LOCK=/var/local/lib/spamd/.lock
117 while test -f $LOCK; do
118 sleep 2m
119 COUNT=$(expr $COUNT + 1)
120 if test $COUNT -eq 10; then
121 # Enough waiting. Kill the process.
122 P=$(cat $LOCK) || :
123 test -n "$P" && kill $P || :
124 rm -f $LOCK
125 break
126 fi
127 done
128 touch $LOCK
129
130 F=common.spamd.tar$COMPRESS_EXT.aescrypt
131 tar clpf - --ignore-failed-read -C / /var/local/lib/spamd | \
132 $COMPRESS_PROG | \
133 ccrypt -k $KEYFILE -e > $F
134 rm -f $LOCK
135 < $F $MOVE_OVER $CURDATE $F
136 rm -f $F
137
138 vos listvol deleuze | \
139 tail -n +2 | \
140 head -n -3 | \
141 cut -b1-34 | \
142 grep -v "\.backup .*$" | \
143 grep -v "\.readonly .*$" | \
144 sed 's_^ .*__' | \
145 sed 's_ .*$__' | \
146 grep '[A-Za-z]' \
147 > volumes
148
149 cat volumes | \
150 grep -v not-backed-up | \
151 xargs -I{} -d\\n -- \
152 bash -e -c \
153 "F={}.dump$COMPRESS_EXT.aescrypt ;
154 vos dump -id {} -localauth -clone |
155 $COMPRESS_PROG | ccrypt -k $KEYFILE -e |
156 $MOVE_OVER $CURDATE \$F" || :
157
158 echo "Backing up databases ..."
159 F=databases.tar$COMPRESS_EXT.aescrypt
160 tar -C /var/backups/databases/ -cf - . | \
161 $COMPRESS_PROG | \
162 ccrypt -k $KEYFILE -e | \
163 $MOVE_OVER $CURDATE $F
164
165 # Update file permissions so that rsync.net can access the backups
166 chmod -R go=,u-w $RSYNCDIR/$CURDATE
167 chmod u+w $RSYNCDIR/$CURDATE
168 chown -R rsync $RSYNCDIR/$CURDATE
169
170 # Complain to admins if there are unknown files
171 grep '[a-z/]' complain && \
172 mail -a 'From: The Backup Program <backups@deleuze.hcoop.net>' \
173 -s "automated message: annoying files found on deleuze (please do something about them)" admins@hcoop.net \
174 < complain \
175 || :
176
177 echo "Done."