mirror of
https://github.com/stornic56/debianito-post-install.git
synced 2026-09-15 06:32:37 +00:00
54257d5a8a
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation. - Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos(). - Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration. - Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs. - Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u. - Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable. - Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e. - Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment. - Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules. - Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing. - Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes. - Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries. - Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures. - Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version. - Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus. - Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM. - Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion. - Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp. - Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh. - Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list. - Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates. - update docs and added quickstart guide
80 lines
3.3 KiB
Bash
80 lines
3.3 KiB
Bash
#!/usr/bin/env bash
|
|
# kernel.sh — Submenu for kernel variants: Stable, RT, Cloud, Backports
|
|
|
|
show_kernel_menu() {
|
|
while true; do
|
|
local items=("stable" "Install linux-image-amd64")
|
|
[ "$DEBIAN_VERSION" = "13" ] && items+=("backports" "Install from backports")
|
|
items+=("rt" "Install linux-image-rt-amd64 (Preempt-RT)")
|
|
items+=("cloud" "Install linux-image-cloud-amd64")
|
|
items+=("back" "Return to main menu")
|
|
|
|
local choice
|
|
choice=$(_menu "Kernel Installation" "Select kernel variant:" \
|
|
16 65 5 "${items[@]}")
|
|
[ -z "$choice" ] && break
|
|
clear
|
|
|
|
case "$choice" in
|
|
stable) _install_kernel_package "linux-image-amd64" "Stable" "" ;;
|
|
rt) _install_kernel_package "linux-image-rt-amd64" "RT" "" ;;
|
|
cloud) _install_kernel_package "linux-image-cloud-amd64" "Cloud" "" ;;
|
|
backports)
|
|
if [ "$(is_backports_enabled)" != "true" ]; then
|
|
_msg "Kernel" "Backports repository is not enabled.\n\nUse option 3 (Configure repositories) to enable backports\nbefore installing the backports kernel."
|
|
else
|
|
_install_kernel_package "linux-image-amd64" "Backports" \
|
|
"-t ${DEBIAN_CODENAME}-backports"
|
|
fi
|
|
;;
|
|
back) break ;;
|
|
esac
|
|
done
|
|
}
|
|
|
|
_install_kernel_package() {
|
|
local pkg_base="$1"
|
|
local flavor="$2"
|
|
local bpo_flag="$3"
|
|
|
|
if ! apt-cache show "$pkg_base" >/dev/null 2>&1; then
|
|
_msg "Kernel" "Kernel not available for your current version of Debian.\n\nPackage: ${pkg_base}" 10 60
|
|
return
|
|
fi
|
|
|
|
if [ "$flavor" = "Backports" ] && [ "$GPU_TYPE" = "nvidia" ]; then
|
|
if ! _confirm "Kernel" "WARNING: Backports kernel changes the kernel version.\nYour NVIDIA driver will need recompilation (DKMS).\n\nProceed?"; then
|
|
echo "Skipping."
|
|
return
|
|
fi
|
|
fi
|
|
if [ "$flavor" = "RT" ] && [ "$GPU_TYPE" = "nvidia" ]; then
|
|
_msg "Kernel — RT" "Note: Ensure your NVIDIA driver supports the RT (Preempt-RT) kernel.\nSome proprietary drivers may not work correctly." 10 60
|
|
fi
|
|
|
|
local headers_pkg="${pkg_base/linux-image-/linux-headers-}"
|
|
local ver headers_ver
|
|
if [ -n "$bpo_flag" ]; then
|
|
ver=$(apt-cache madison "$pkg_base" 2>/dev/null | grep "${DEBIAN_CODENAME}-backports" | awk '{print $3}' | head -1 || true)
|
|
headers_ver=$(apt-cache madison "$headers_pkg" 2>/dev/null | grep "${DEBIAN_CODENAME}-backports" | awk '{print $3}' | head -1 || true)
|
|
else
|
|
ver=$(apt-cache show "$pkg_base" 2>/dev/null | sed -n 's/^Version: //p' | grep -v '~bpo' | head -1)
|
|
headers_ver=$(apt-cache show "$headers_pkg" 2>/dev/null | sed -n 's/^Version: //p' | grep -v '~bpo' | head -1)
|
|
fi
|
|
[ -n "$ver" ] && ver=" ($ver)"
|
|
[ -n "$headers_ver" ] && headers_ver=" ($headers_ver)"
|
|
local summary="Install ${flavor} kernel?\n Image: ${pkg_base}${ver}\n Headers: ${headers_pkg}${headers_ver}"
|
|
[ -n "$bpo_flag" ] && summary+="\n From: ${DEBIAN_CODENAME^}-backports"
|
|
|
|
if ! _confirm "Kernel — ${flavor}" "$summary"; then
|
|
echo "Skipping."
|
|
return
|
|
fi
|
|
|
|
_run_cmd "Kernel" "sudo apt install -y ${bpo_flag} ${pkg_base} ${headers_pkg}" \
|
|
"Installing ${flavor} kernel + headers..."
|
|
|
|
echo -e "${GREEN}${flavor} kernel installed. Reboot to use it.${NC}"
|
|
_pause
|
|
}
|