mirror of
https://github.com/stornic56/debianito-post-install.git
synced 2026-09-15 06:32:37 +00:00
Security hardening & DRY refactoring
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation. - Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos(). - Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration. - Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs. - Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u. - Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable. - Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e. - Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment. - Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules. - Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing. - Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes. - Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries. - Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures. - Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version. - Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus. - Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM. - Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion. - Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp. - Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh. - Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list. - Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates. - update docs and added quickstart guide
This commit is contained in:
@@ -87,6 +87,18 @@ The submenu offers the next categories:
|
||||
|
||||
---
|
||||
|
||||
## Quick Start Guide
|
||||
|
||||
For a streamlined post-installation setup (~15-20 minutes), refer to the [Quick Start Visual Guide](/docs/quickstart.md). It provides:
|
||||
|
||||
- Step-by-step recommended order for running Debianito options (Steps 1–13)
|
||||
- What each option does and when to enable it
|
||||
- Screenshots of key dialogs (whiptail menus, confirmations, hardware detection)
|
||||
- Troubleshooting tips for common issues (WiFi after firmware install, NVIDIA + Wayland, GRUB boot menu hidden, etc.)
|
||||
|
||||
**Tip:** If you're unsure where to start, follow Steps 1–5 from the Quick Start guide. They cover the essentials: system info, permissions, repositories, firmware, and graphics drivers.
|
||||
|
||||
---
|
||||
## File Structure
|
||||
|
||||
| Directory/File | Description |
|
||||
@@ -110,7 +122,7 @@ The submenu offers the next categories:
|
||||
│ ├── gaming.md
|
||||
│ ├── gpu.md
|
||||
│ ├── kernel.md
|
||||
│ ├── QUICKSTART.md
|
||||
│ ├── quickstart.md
|
||||
│ ├── repos_config.md
|
||||
│ ├── retroarch.md
|
||||
│ ├── swap.md
|
||||
@@ -119,8 +131,25 @@ The submenu offers the next categories:
|
||||
│ ├── user_priv_feed.md
|
||||
│ └── zram.md
|
||||
├── media
|
||||
│ └── gift
|
||||
│ └── script.gif
|
||||
│ ├── gift
|
||||
│ │ └── script.gif
|
||||
│ └── screenshots
|
||||
│ ├── 01-system-info.png
|
||||
│ ├── 02b-pwfeedback.png
|
||||
│ ├── 02-user-privileges.png
|
||||
│ ├── 03-system-prefs.png
|
||||
│ ├── 04b-backports.png
|
||||
│ ├── 04-repos.png
|
||||
│ ├── 05-firmware-plan.png
|
||||
│ ├── 06-gpu-choice.png
|
||||
│ ├── 07-kernel.png
|
||||
│ ├── 08-gaming.png
|
||||
│ ├── 09b-zram-status.png
|
||||
│ ├── 09-zram-algo.png
|
||||
│ ├── 10b-swap-status.png
|
||||
│ ├── 10-swap.png
|
||||
│ ├── 11b-essential-pack.png
|
||||
│ └── 11-programs.gif
|
||||
├── modules
|
||||
│ ├── bluetooth.sh
|
||||
│ ├── bullseye
|
||||
|
||||
Reference in New Issue
Block a user