mirror of
https://github.com/stornic56/debianito-post-install.git
synced 2026-09-15 06:32:37 +00:00
54257d5a8a
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation. - Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos(). - Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration. - Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs. - Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u. - Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable. - Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e. - Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment. - Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules. - Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing. - Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes. - Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries. - Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures. - Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version. - Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus. - Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM. - Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion. - Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp. - Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh. - Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list. - Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates. - update docs and added quickstart guide
127 lines
4.3 KiB
Bash
127 lines
4.3 KiB
Bash
#!/usr/bin/env bash
|
|
# AMD and Intel GPU firmware + tools
|
|
|
|
install_amd_firmware() {
|
|
local fw_info
|
|
fw_info=$(pkg_versions firmware-amd-graphics)
|
|
if _confirm "AMD Firmware" "Install AMD GPU firmware?\n\n${fw_info}"; then
|
|
if ! _run_cmd "AMD" "sudo apt install -y firmware-amd-graphics" "Installing AMD GPU firmware..."; then
|
|
_msg_red "AMD Firmware" "Failed to install AMD GPU firmware."
|
|
fi
|
|
fi
|
|
}
|
|
|
|
offer_amd_tools() {
|
|
local amd_tools=("radeontop")
|
|
|
|
local pkgs
|
|
if [ "$DEBIAN_VERSION" = "11" ]; then
|
|
pkgs=$(pkg_versions "${amd_tools[@]}" vainfo)
|
|
else
|
|
pkgs=$(pkg_versions "${amd_tools[@]}" nvtop vainfo)
|
|
fi
|
|
|
|
if ! _confirm "AMD Tools" "Install AMD monitoring tools?\n\n${pkgs}"; then
|
|
echo "Skipping AMD tools."
|
|
return
|
|
fi
|
|
|
|
local tools_failed=false
|
|
if [ "$DEBIAN_VERSION" = "11" ]; then
|
|
if ! _run_cmd "AMD Tools" "sudo apt install -y ${amd_tools[*]} vainfo" "Installing AMD tools..."; then
|
|
_msg_red "AMD Tools" "Failed to install AMD monitoring tools."
|
|
tools_failed=true
|
|
fi
|
|
else
|
|
if ! _run_cmd "AMD Tools" "sudo apt install -y ${amd_tools[*]} nvtop vainfo" "Installing AMD tools..."; then
|
|
_msg_red "AMD Tools" "Failed to install AMD monitoring tools."
|
|
tools_failed=true
|
|
fi
|
|
fi
|
|
if command -v vainfo &>/dev/null; then
|
|
vainfo
|
|
_pause "vainfo output shown above."
|
|
else
|
|
echo -e "${YELLOW}vainfo not available, skipping report.${NC}"
|
|
fi
|
|
|
|
if $tools_failed; then
|
|
echo -e "${RED}AMD tools installation failed.${NC}"
|
|
else
|
|
echo -e "${GREEN}AMD tools installed.${NC}"
|
|
fi
|
|
}
|
|
|
|
install_intel_firmware() {
|
|
local gen
|
|
gen=$(get_intel_generation)
|
|
local va_driver
|
|
if [ "$gen" = "gen7-" ]; then
|
|
va_driver="i965-va-driver-shaders"
|
|
else
|
|
va_driver="intel-media-va-driver-non-free"
|
|
fi
|
|
|
|
local fw_info
|
|
fw_info=$(pkg_versions firmware-intel-graphics "$va_driver")
|
|
if _confirm "Intel Firmware" "Install Intel GPU firmware?\n\n${fw_info}"; then
|
|
if ! _run_cmd "Intel" "sudo apt install -y firmware-intel-graphics $va_driver" "Installing Intel GPU firmware..."; then
|
|
_msg_red "Intel Firmware" "Failed to install Intel GPU firmware."
|
|
fi
|
|
fi
|
|
}
|
|
|
|
offer_intel_tools() {
|
|
local driver_info=""
|
|
local has_xe=false
|
|
local has_i915=false
|
|
local pkg_list=()
|
|
local pkg_info=""
|
|
|
|
[ -d "/sys/bus/pci/drivers/xe" ] && has_xe=true
|
|
[ -d "/sys/bus/pci/drivers/i915" ] && has_i915=true
|
|
|
|
if [ "$DEBIAN_VERSION" = "11" ]; then
|
|
if $has_xe; then
|
|
echo "Intel Xe GPU detected. No monitoring tools available on Bullseye."
|
|
return
|
|
elif $has_i915; then
|
|
driver_info="Classic Intel GPU detected (i915 driver)."
|
|
pkg_list=("intel-gpu-tools")
|
|
else
|
|
echo "Intel GPU driver not identified. No monitoring tools available on Bullseye."
|
|
return
|
|
fi
|
|
elif $has_xe; then
|
|
driver_info="Modern Intel GPU detected (Xe driver).\nintel-gpu-tools is NOT compatible with Xe.\nOnly nvtop will be offered."
|
|
pkg_list=("nvtop")
|
|
elif $has_i915; then
|
|
driver_info="Classic Intel GPU detected (i915 driver).\nintel-gpu-tools is compatible and will be offered."
|
|
pkg_list=("intel-gpu-tools" "nvtop")
|
|
else
|
|
driver_info="Intel GPU driver not identified.\nOffering nvtop as a safe default."
|
|
pkg_list=("nvtop")
|
|
fi
|
|
|
|
pkg_info=$(pkg_versions "${pkg_list[@]}" vainfo)
|
|
|
|
if _confirm "Intel Tools" "Intel GPU monitoring tools\n\n${driver_info}\n\nPackages:\n${pkg_info}"; then
|
|
local intel_failed=false
|
|
if ! _run_cmd "Intel Tools" "sudo apt install -y ${pkg_list[*]} vainfo" "Installing Intel monitoring tools..."; then
|
|
_msg_red "Intel Tools" "Failed to install Intel monitoring tools."
|
|
intel_failed=true
|
|
fi
|
|
if command -v vainfo &>/dev/null; then
|
|
vainfo
|
|
_pause "vainfo output shown above."
|
|
else
|
|
echo -e "${YELLOW}vainfo not available, skipping report.${NC}"
|
|
fi
|
|
if $intel_failed; then
|
|
echo -e "${RED}Intel monitoring tools installation failed.${NC}"
|
|
fi
|
|
else
|
|
echo "Skipping Intel monitoring tools."
|
|
fi
|
|
}
|