Files
debianito-post-install/modules/bluetooth.sh
T
stornic56 54257d5a8a Security hardening & DRY refactoring
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation.
- Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos().
- Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration.
- Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs.
- Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u.
- Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable.
- Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e.
- Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment.
- Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules.
- Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing.
- Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes.
- Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries.
- Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures.
- Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version.
- Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus.
- Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM.
- Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion.
- Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp.
- Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh.
- Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list.
- Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates.
- update docs and added quickstart guide
2026-09-14 20:31:48 -05:00

93 lines
3.7 KiB
Bash

#!/usr/bin/env bash
# modules/bluetooth.sh
# Requires: modules/utils.sh (globals + helpers), modules/firmware.sh (PCI_BT_DEVS, USB_BT_DEVS, USB_WIFI_DEVS)
_install_bluetooth_stack() {
local has_bt=false
[ ${#PCI_BT_DEVS[@]} -gt 0 ] && has_bt=true
[ ${#USB_BT_DEVS[@]} -gt 0 ] && has_bt=true
if ! $has_bt; then
for dev in "${USB_WIFI_DEVS[@]}"; do
if echo "$dev" | grep -qi 'bluetooth'; then
has_bt=true; break
fi
done
fi
if ! $has_bt; then
echo " → No Bluetooth hardware detected, skipping."
return
fi
local stack_failed=false
if is_installed bluez; then
echo " → Bluetooth stack already installed."
service_enable_only=true
fi
if [ ! ${service_enable_only:-false} = true ]; then
local bt_pkgs=()
! is_installed bluez && bt_pkgs+=(bluez)
! is_installed bluez-tools && bt_pkgs+=(bluez-tools)
! is_installed bluez-obexd && bt_pkgs+=(bluez-obexd)
if [ ${#bt_pkgs[@]} -gt 0 ]; then
if ! _run_cmd "Bluetooth" "sudo DEBIAN_FRONTEND=noninteractive apt install -y ${bt_pkgs[*]}" "Installing Bluetooth stack..."; then
_msg_red "Bluetooth" "Failed to install the Bluetooth stack."
stack_failed=true
fi
fi
fi
if command -v rfkill &>/dev/null; then
if rfkill list bluetooth 2>/dev/null | grep -q "Soft blocked: yes"; then
echo " → Unblocking Bluetooth (rfkill)..."
sudo rfkill unblock bluetooth
fi
fi
case "${DESKTOP_ENV:-other}" in
kde)
if ! is_installed bluedevil; then
if ! _run_cmd "Bluetooth" "sudo DEBIAN_FRONTEND=noninteractive apt install -y bluedevil" "Installing bluedevil..."; then
_msg_red "Bluetooth" "Failed to install bluedevil."
fi
fi
if [ "${AUDIO_SERVER:-}" = "pipewire" ]; then
if ! is_installed pipewire-pulse; then
if ! _run_cmd "Bluetooth" "sudo DEBIAN_FRONTEND=noninteractive apt install -y pipewire-pulse" "Installing pipewire-pulse..."; then
_msg_red "Bluetooth" "Failed to install pipewire-pulse."
fi
fi
if ! is_installed wireplumber; then
if ! _run_cmd "Bluetooth" "sudo DEBIAN_FRONTEND=noninteractive apt install -y wireplumber" "Installing wireplumber..."; then
_msg_red "Bluetooth" "Failed to install wireplumber."
fi
fi
fi
;;
gnome)
echo " → GNOME Bluetooth support already in gnome-control-center."
;;
xfce|other)
if ! is_installed blueman; then
if ! _run_cmd "Bluetooth" "sudo DEBIAN_FRONTEND=noninteractive apt install -y blueman" "Installing blueman..."; then
_msg_red "Bluetooth" "Failed to install blueman."
fi
fi
;;
esac
if ! systemctl is-enabled bluetooth &>/dev/null 2>&1; then
sudo systemctl enable bluetooth 2>/dev/null || true
fi
if ! systemctl is-active bluetooth &>/dev/null 2>&1; then
sudo systemctl start bluetooth 2>/dev/null || true
fi
if $stack_failed; then
_msg_red "Bluetooth Setup" "Bluetooth setup finished with errors.\n\nThe stack may be incomplete.\nA session restart or reboot is\nrecommended to load the desktop\napplets and tray icons." 10 60
else
_msg "Bluetooth Setup" "Bluetooth stack installed.\n\nA session restart or reboot is\nrecommended to load the desktop\napplets and tray icons." 10 60
fi
}