#!/usr/bin/env bash # Runs once, on the first boot after an install from the ISO. Runs setup.sh as the # desktop user, then takes back the passwordless sudo the installer granted for it. # Log: /var/log/main-desktop-firstboot.log (and the journal). set -uo pipefail LOG=/var/log/main-desktop-firstboot.log SUDOERS=/etc/sudoers.d/99-main-desktop-firstboot STAMP=/var/lib/main-desktop-firstboot.done # Whatever the installer called the account it made — uid 1000 is the desktop user. USER_NAME=$(id -nu 1000 2>/dev/null || true) cleanup() { rm -f "$SUDOERS" # never leave passwordless sudo lying around, pass or fail systemctl disable main-desktop-firstboot.service >/dev/null 2>&1 || true : > "$STAMP" } trap cleanup EXIT exec > >(tee -a "$LOG") 2>&1 echo "=== main-desktop first boot: $(date -Is) ===" if [[ -z $USER_NAME ]]; then echo "no uid 1000 user found — run /opt/main-desktop/scripts/setup.sh by hand" exit 1 fi echo "running setup.sh as $USER_NAME" if runuser -u "$USER_NAME" -- env HOME="/home/$USER_NAME" UNATTENDED=1 \ bash /opt/main-desktop/scripts/setup.sh; then echo "=== setup.sh finished $(date -Is) ===" echo "Log out and back in to pick up the docker and kvm groups." else echo "=== setup.sh FAILED (see above) $(date -Is) ===" echo "Fix whatever it complained about, then re-run it by hand (it's safe to re-run):" echo " /opt/main-desktop/scripts/setup.sh" fi