mirror of
https://github.com/stornic56/debianito-post-install.git
synced 2026-09-15 06:32:37 +00:00
Security hardening & DRY refactoring
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation. - Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos(). - Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration. - Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs. - Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u. - Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable. - Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e. - Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment. - Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules. - Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing. - Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes. - Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries. - Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures. - Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version. - Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus. - Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM. - Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion. - Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp. - Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh. - Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list. - Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates. - update docs and added quickstart guide
This commit is contained in:
+46
-10
@@ -130,7 +130,14 @@ _install_xfce_custom() {
|
||||
local cleaned
|
||||
cleaned=$(echo "$choices" | tr -d '"')
|
||||
[ -z "$cleaned" ] && return
|
||||
_run_cmd "XFCE Custom" "sudo apt install -y $cleaned" \
|
||||
|
||||
# BH-004: Convert to array to avoid word splitting and injection.
|
||||
local -a xfce_pkgs=()
|
||||
while IFS= read -r _pkg; do
|
||||
[ -n "$_pkg" ] && xfce_pkgs+=("$_pkg")
|
||||
done < <(echo "$cleaned" | tr ' ' '\n')
|
||||
|
||||
_run_cmd "XFCE Custom" "sudo apt install -y ${xfce_pkgs[*]}" \
|
||||
"Installing selected XFCE packages..."
|
||||
_xfce_polkit_rules
|
||||
}
|
||||
@@ -161,7 +168,13 @@ EOF
|
||||
if ! getent group backlight >/dev/null 2>&1; then
|
||||
sudo groupadd --system backlight || true
|
||||
fi
|
||||
local de_user="${SUDO_USER:-$USER}"
|
||||
# SECURITY: Validate that the target user is a real login user, not root.
|
||||
# If SUDO_USER is empty (script run directly as root), fall back to the
|
||||
# first non-system user from /etc/passwd, never to root.
|
||||
local de_user="${SUDO_USER:-}"
|
||||
if [ -z "$de_user" ] || [ "$de_user" = "root" ]; then
|
||||
de_user=$(awk -F: '$3>=1000 && $3<65534 {print $1}' /etc/passwd | head -1)
|
||||
fi
|
||||
if [ -n "$de_user" ] && ! id -nG "$de_user" 2>/dev/null | grep -qw backlight; then
|
||||
sudo usermod -aG backlight "$de_user" || true
|
||||
fi
|
||||
@@ -219,7 +232,13 @@ lightdm_config_menu() {
|
||||
fi
|
||||
local cleaned
|
||||
cleaned=$(echo "$choices" | tr -d '"')
|
||||
for item in $cleaned; do
|
||||
# SECURITY: Convert to array to avoid word splitting and command injection.
|
||||
local -a lm_items=()
|
||||
while IFS= read -r _item; do
|
||||
[ -n "$_item" ] && lm_items+=("$_item")
|
||||
done < <(echo "$cleaned" | tr ' ' '\n')
|
||||
|
||||
for item in "${lm_items[@]}"; do
|
||||
case $item in
|
||||
install_lightdm)
|
||||
if ! is_installed lightdm || ! is_installed lightdm-gtk-greeter-settings; then
|
||||
@@ -241,7 +260,10 @@ greeter-hide-users=false" | sudo tee "$conf" >/dev/null; then
|
||||
;;
|
||||
enable_autologin)
|
||||
local dm_conf="/etc/lightdm/lightdm.conf"
|
||||
local lightdm_user="${SUDO_USER:-$USER}"
|
||||
local lightdm_user="${SUDO_USER:-}"
|
||||
if [ -z "$lightdm_user" ] || [ "$lightdm_user" = "root" ]; then
|
||||
lightdm_user=$(awk -F: '$3>=1000 && $3<65534 {print $1}' /etc/passwd | head -1)
|
||||
fi
|
||||
sudo sed -i 's/^#[[:space:]]*autologin-user[[:space:]=].*/autologin-user='"$lightdm_user"'/' "$dm_conf"
|
||||
sudo sed -i 's/^#[[:space:]]*autologin-user-timeout[[:space:]=].*/autologin-user-timeout=0/' "$dm_conf"
|
||||
echo -e "${GREEN}Autologin enabled for user: ${lightdm_user}${NC}"
|
||||
@@ -338,7 +360,14 @@ configure_gdm3() {
|
||||
|
||||
local cleaned
|
||||
cleaned=$(echo "$choice" | tr -d '"')
|
||||
for item in $cleaned; do
|
||||
|
||||
# SECURITY: Convert to array to avoid word splitting and command injection.
|
||||
local -a gdm_items=()
|
||||
while IFS= read -r _item; do
|
||||
[ -n "$_item" ] && gdm_items+=("$_item")
|
||||
done < <(echo "$cleaned" | tr ' ' '\n')
|
||||
|
||||
for item in "${gdm_items[@]}"; do
|
||||
case $item in
|
||||
install)
|
||||
echo "gdm3 shared/default-x-display-manager select gdm3" | sudo debconf-set-selections
|
||||
@@ -358,12 +387,16 @@ configure_gdm3() {
|
||||
autologin)
|
||||
local daemon_conf="/etc/gdm3/daemon.conf"
|
||||
local username
|
||||
username=$(whiptail --title "GDM3 Autologin" \
|
||||
--inputbox "Enter username to autologin (leave empty to DISABLE autologin):" \
|
||||
10 60 "" 3>&1 1>&2 2>&3 || true)
|
||||
username=$(_inputbox "GDM3 Autologin" \
|
||||
"Enter username to autologin (leave empty to DISABLE autologin):" 10 60)
|
||||
if [ -n "$username" ]; then
|
||||
if ! [[ "$username" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
|
||||
_msg_red "GDM3 Autologin" "Invalid username: ${username}"
|
||||
continue
|
||||
fi
|
||||
[ -f "$daemon_conf" ] || sudo touch "$daemon_conf"
|
||||
sudo sed -i 's/^# *AutomaticLoginEnable[[:space:]=].*/AutomaticLoginEnable=true/' "$daemon_conf"
|
||||
sudo sed -i 's/^# *AutomaticLogin[[:space:]=].*/AutomaticLogin='"$username"'/' "$daemon_conf"
|
||||
sudo sed -i "s|^# *AutomaticLogin[[:space:]=].*|AutomaticLogin=${username}|" "$daemon_conf"
|
||||
echo -e "${GREEN}Autologin enabled for user: ${username}${NC}"
|
||||
else
|
||||
sudo sed -i 's/^AutomaticLoginEnable[[:space:]=].*/# AutomaticLoginEnable=false/' "$daemon_conf"
|
||||
@@ -408,7 +441,10 @@ configure_sddm() {
|
||||
;;
|
||||
2)
|
||||
local sddm_session=""
|
||||
local sddm_user="${SUDO_USER:-$USER}"
|
||||
local sddm_user="${SUDO_USER:-}"
|
||||
if [ -z "$sddm_user" ] || [ "$sddm_user" = "root" ]; then
|
||||
sddm_user=$(awk -F: '$3>=1000 && $3<65534 {print $1}' /etc/passwd | head -1)
|
||||
fi
|
||||
if [ -f /usr/share/wayland-sessions/plasmawayland.desktop ]; then
|
||||
sddm_session="plasmawayland"
|
||||
elif [ -f /usr/share/wayland-sessions/lxqt-wayland.desktop ]; then
|
||||
|
||||
Reference in New Issue
Block a user