Files
debianito-post-install/modules/gaming.sh
T
stornic56 54257d5a8a Security hardening & DRY refactoring
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation.
- Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos().
- Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration.
- Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs.
- Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u.
- Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable.
- Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e.
- Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment.
- Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules.
- Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing.
- Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes.
- Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries.
- Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures.
- Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version.
- Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus.
- Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM.
- Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion.
- Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp.
- Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh.
- Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list.
- Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates.
- update docs and added quickstart guide
2026-09-14 20:31:48 -05:00

166 lines
5.8 KiB
Bash

#!/usr/bin/env bash
# Gaming dispatcher — sources submodules and provides install_gaming()
_GAMING_DIR="${MODULES_DIR}/gaming"
source "${_GAMING_DIR}/_helpers.sh"
source "${_GAMING_DIR}/steam.sh"
source "${_GAMING_DIR}/heroic.sh"
source "${_GAMING_DIR}/tools.sh"
# Check if 'contrib' component is enabled; offer to add if missing
ensure_contrib_repo() {
local contrib_found=false
if [ -f /etc/apt/sources.list ]; then
if grep -Eq '^[^#]*\bcontrib\b' /etc/apt/sources.list 2>/dev/null; then
contrib_found=true
fi
fi
if ! $contrib_found && [ -d /etc/apt/sources.list.d ]; then
if grep -qr 'Components:.*\bcontrib\b' /etc/apt/sources.list.d/*.sources 2>/dev/null; then
contrib_found=true
fi
fi
if $contrib_found; then
return 0
fi
if ! _confirm "contrib Repository" "Component 'contrib' is required for Steam.\n\nAdd 'contrib' to your APT repositories?"; then
echo -e "${YELLOW}contrib repository not enabled. Steam installation may fail.${NC}"
return 1
fi
# No active sources at all → bootstrap a complete configuration
if ! has_active_deb_sources; then
backup_current_repos
if ! bootstrap_repositories "main contrib"; then
return 1
fi
else
if [ -f /etc/apt/sources.list ]; then
sudo cp /etc/apt/sources.list "/etc/apt/sources.list.backup.$(date +%Y%m%d_%H%M%S)"
# Anchor to the space-delimited "main" component so mirror URLs
# containing "main" (e.g. https://main.example.com) are untouched.
sudo sed -i -E '/^deb / { /\bcontrib\b/! s/ main([[:space:]]|$)/ main contrib\1/ }' /etc/apt/sources.list
fi
if [ -d /etc/apt/sources.list.d ]; then
for f in /etc/apt/sources.list.d/*.sources; do
[ -f "$f" ] || continue
sudo sed -i '/^Components:/ { /contrib/! s/$/ contrib/ }' "$f"
done
fi
fi
# Verify the component was actually added before reporting success
local contrib_ok=false
[ -f /etc/apt/sources.list ] && grep -Eq '^[^#]*\bcontrib\b' /etc/apt/sources.list 2>/dev/null && contrib_ok=true
[ -d /etc/apt/sources.list.d ] && grep -qr 'Components:.*\bcontrib\b' /etc/apt/sources.list.d/*.sources 2>/dev/null && contrib_ok=true
[ -d /etc/apt/sources.list.d ] && grep -qrE '^[^#]*\bcontrib\b' /etc/apt/sources.list.d/*.list 2>/dev/null && contrib_ok=true
if ! $contrib_ok; then
echo -e "${RED}Failed to enable contrib repository. Check your APT sources.${NC}"
return 1
fi
_ensure_apt_updated
echo -e "${GREEN}contrib repository enabled.${NC}"
return 0
}
install_gaming() {
echo -e "${YELLOW}Gaming setup...${NC}"
# 1. Single checklist with ALL options (including i386 toggle)
local choices
choices=$(_checklist "Gaming Setup" \
"Check [*] the packages you want installed/updated on your system.\n" $TUI_ALTO $TUI_ANCHO $TUI_ALTO_LISTA \
"i386" "Enable 32-bit (i386) architecture" ON \
"steam" "Steam (requires 32-bit support)" ON \
"mangohud" "Performance overlay (Vulkan/OpenGL)" ON \
"gamemode" "Game performance optimization" OFF \
"goverlay" "MangoHud config GUI" ON \
"heroic" "Heroic Launcher (Epic/GOG)" OFF \
"java" "Minecraft Java Runtime" OFF \
"openrgb" "OpenRGB (RGB lighting control)" OFF \
"lutris" "Lutris + Wine (requires 32-bit support)" OFF \
"retroarch" "RetroArch Emulator Frontend" OFF)
if [ -z "$choices" ]; then
echo "No gaming packages selected."
_pause
return
fi
local cleaned
cleaned=$(echo "$choices" | tr -d '"')
# 2. Determine if 32-bit is needed (steam, lutris, or explicit i386 toggle)
local need_32bit=false
local -a install_pkgs=()
while IFS= read -r _pkg; do
[ -n "$_pkg" ] && install_pkgs+=("$_pkg")
done < <(echo "$cleaned" | tr ' ' '\n')
for p in "${install_pkgs[@]}"; do
case "$p" in steam | lutris) need_32bit=true ;; esac
done
echo "$cleaned" | grep -qw i386 && need_32bit=true
# Strip pseudo-entry "i386" from the install list
local -a install_list=()
while IFS= read -r _pkg; do
[ "$_pkg" = "i386" ] && continue
[ -n "$_pkg" ] && install_list+=("$_pkg")
done < <(echo "$cleaned" | tr ' ' '\n')
# 3. Enable i386 architecture if needed
if $need_32bit && ! dpkg --print-foreign-architectures 2>/dev/null | grep -q i386; then
echo -e "${YELLOW}Enabling i386 architecture (required by selection)...${NC}"
sudo dpkg --add-architecture i386
_ensure_apt_updated
fi
# 4. Install 32-bit graphics drivers only if 32-bit is needed
if $need_32bit; then
echo "Installing 32-bit graphics drivers..."
if [ "$GPU_TYPE" = "nvidia" ]; then
_install_nvidia_32bit
else
_install_mesa_32bit
fi
fi
# 5. Install selected packages
for pkg in "${install_list[@]}"; do
case $pkg in
steam)
if ensure_contrib_repo; then
install_steam
else
echo -e "${YELLOW}Skipping Steam installation (contrib repository not enabled).${NC}"
fi
;;
heroic) install_heroic ;;
java) install_minecraft_java ;;
mangohud) install_mangohud ;;
gamemode) install_gamemode ;;
goverlay) install_goverlay ;;
openrgb)
if [ "$DEBIAN_VERSION" = "11" ]; then
echo "OpenRGB requires Debian 12+."
continue
fi
install_openrgb
;;
lutris) install_lutris ;;
retroarch) install_retroarch ;;
*) _run_install "$pkg" ;;
esac
done
echo -e "${GREEN}Gaming setup complete.${NC}"
_pause
}