mirror of
https://github.com/stornic56/debianito-post-install.git
synced 2026-09-15 06:32:37 +00:00
54257d5a8a
- Fixed command injection in desktop_display.sh by converting word-splitting loops to safe array-based iteration for LightDM/GDM3 configuration and XFCE package installation. - Added symlink detection guard before repository file operations in repos.sh to prevent TOCTOU attacks during restore_previous_repos(). - Hardened SUDO_USER resolution with awk validation against /etc/passwd to prevent root fallback and ensure real login users are targeted for sudoers configuration. - Implemented algorithm (lz4/zstd) and size validation before ZRAM configuration writes in zram.sh to reject invalid inputs. - Protected grep MemTotal read from /proc/meminfo with 2>/dev/null and default assignment under set -u. - Added || true guards around apt-cache madison pipelines in firmware.sh, kernel.sh, gpu.sh, and utils.sh to prevent pipefail aborts when backports unavailable. - Wrapped whiptail installation in if/else blocks to allow offline error messages instead of script termination under set -e. - Fixed grep -c output duplication in swap.sh with proper || true pattern and default variable assignment. - Replaced unquoted $cleaned loops with array conversion using while read for secure package iteration across gaming, desktop_display, firmware, and kernel modules. - Anchored sed regex patterns to space-delimited "main" components to prevent mirror URL corruption in sources.list editing. - Escaped % characters in _msg() function before passing to whiptail to prevent printf format interpretation crashes. - Consolidated package version helpers into canonical wrappers: _get_pkg_version, _get_installed_version, _get_backports_version for consistent apt/dpkg queries. - Created _install_if_missing() and _install_pkg() with proper error handling that respects set -e while providing user feedback on installation failures. - Removed 6 dead code functions (~51 lines): check_system_time, sync_system_time, get_cpu_summary, get_ram_summary, pkg_versions, get_backports_kernel_version. - Added detect_displayserver and detect_audio_server to refresh_system_state() for complete state refresh when returning from menus. - Enhanced _on_interrupt() trap handler to kill lingering apt/dpkg child processes and clean /tmp/debianito.* temporary files on Ctrl+C or TERM. - Improved restore_previous_repos() with manifest-based backup verification (.backed_up_* markers) to prevent destructive repository file deletion. - Added mktemp usage for secure temporary deb file downloads in nvidia.sh, heroic.sh, and tools.sh to eliminate TOCTOU vulnerabilities in /tmp. - Fixed Bluetooth USB dongle misclassification as WiFi devices by excluding "bluetooth" strings from USB_WIFI_DEVS detection in firmware.sh. - Properly utilized the need array for selective package installation in internet.sh instead of hardcoding full package list. - Corrected fwupdmgr duplicate execution and grep false positives in system.sh with strict pattern matching for available updates. - update docs and added quickstart guide
167 lines
5.7 KiB
Bash
167 lines
5.7 KiB
Bash
#!/usr/bin/env bash
|
|
# sudo_config.sh — User Privileges & Feedback submenu
|
|
# License GPL v3
|
|
|
|
# Resolve the invoking user once. USER may be unset in minimal
|
|
# environments (SSH sessions, cron), which would abort under set -u.
|
|
TARGET_USER="${SUDO_USER:-${USER:-$(id -un)}}"
|
|
|
|
config_sudo() {
|
|
echo -e "${YELLOW}User Privileges & Feedback${NC}"
|
|
|
|
while true; do
|
|
local choice
|
|
choice=$(_menu "User Privileges & Feedback" \
|
|
"Select an option:" $TUI_ALTO $TUI_ANCHO 6 \
|
|
"1" "Sudo Group Membership" \
|
|
"2" "Passwordless Sudo (maintenance commands)" \
|
|
"3" "Repair Home Directory Ownership" \
|
|
"4" "Sudo Password Feedback (asterisks)" \
|
|
"5" "Back to main menu")
|
|
|
|
[ -z "$choice" ] && return
|
|
clear
|
|
|
|
case "$choice" in
|
|
1) _check_sudo_group ;;
|
|
2) _configure_nopasswd ;;
|
|
3) _repair_home_ownership ;;
|
|
4) _toggle_pwfeedback ;;
|
|
5) return ;;
|
|
esac
|
|
done
|
|
}
|
|
|
|
# ── Option 1: Sudo Group Membership ──
|
|
_check_sudo_group() {
|
|
if groups "$TARGET_USER" | grep -qE '\bsudo\b'; then
|
|
_msg "Sudo Group" "User '$TARGET_USER' is already in the sudo group."
|
|
else
|
|
if _confirm "Sudo Group" \
|
|
"User '$TARGET_USER' is NOT in the sudo group.\n\nAdd to sudo group?"; then
|
|
if sudo usermod -aG sudo "$TARGET_USER"; then
|
|
_msg "Sudo Group" \
|
|
"User added to sudo group.\n\nLog out and back in for\ngroup changes to take effect." 10 60
|
|
else
|
|
_msg "Sudo Group" "Failed to add user to sudo group." 7 60
|
|
return 1
|
|
fi
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# ── Option 2: Passwordless Sudo (NOPASSWD) ──
|
|
_configure_nopasswd() {
|
|
# sudo silently ignores /etc/sudoers.d/ files whose name contains
|
|
# '.' or '~' (package manager / editor backup guards).
|
|
local safe_user="${TARGET_USER//./_}"
|
|
local nopasswd_file="/etc/sudoers.d/${safe_user}-nopasswd"
|
|
|
|
if [ -f "$nopasswd_file" ]; then
|
|
if _confirm "NOPASSWD" \
|
|
"Passwordless sudo is already configured.\n\nRemove it to restore password prompts?"; then
|
|
sudo rm -f "$nopasswd_file"
|
|
echo -e "${GREEN}Passwordless sudo removed.${NC}"
|
|
fi
|
|
return
|
|
fi
|
|
|
|
if _confirm "NOPASSWD" \
|
|
"Configure passwordless sudo for maintenance commands?\n\n\
|
|
- apt / apt-get (package management)\n\
|
|
- systemctl (service management)\n\
|
|
- shutdown / reboot / halt (power commands)\n\n\
|
|
Useful for automation but reduces security." 14 70; then
|
|
local choices
|
|
choices=$(_checklist "NOPASSWD Commands" \
|
|
"Select commands to allow without password:" 12 60 3 \
|
|
"apt" "APT package management" ON \
|
|
"systemctl" "Systemd service management" ON \
|
|
"power" "Shutdown, reboot, halt" ON)
|
|
clear
|
|
|
|
[ -z "$choices" ] && {
|
|
echo "No commands selected."
|
|
return
|
|
}
|
|
local cleaned
|
|
cleaned=$(echo "$choices" | tr -d '"')
|
|
|
|
local content=""
|
|
for cmd in $cleaned; do
|
|
case $cmd in
|
|
apt)
|
|
content+="${TARGET_USER} ALL=(root) NOPASSWD: /usr/bin/apt, /usr/bin/apt-get, /bin/apt, /bin/apt-get\n"
|
|
;;
|
|
systemctl)
|
|
content+="${TARGET_USER} ALL=(root) NOPASSWD: /usr/bin/systemctl, /bin/systemctl\n"
|
|
;;
|
|
power)
|
|
content+="${TARGET_USER} ALL=(root) NOPASSWD: /usr/sbin/shutdown, /sbin/shutdown, /usr/sbin/reboot, /sbin/reboot, /usr/sbin/halt, /sbin/halt\n"
|
|
;;
|
|
esac
|
|
done
|
|
|
|
local content_str
|
|
content_str=$(echo -e "$content")
|
|
if _validate_sudoers "$content_str" "$nopasswd_file"; then
|
|
echo -e "${GREEN}Passwordless sudo configured for selected commands.${NC}"
|
|
else
|
|
return 1
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# ── Option 3: Repair Home Directory Ownership ──
|
|
_repair_home_ownership() {
|
|
local home
|
|
home=$(getent passwd "$TARGET_USER" | cut -d: -f6)
|
|
|
|
if [ ! -d "$home" ]; then
|
|
_msg "Home Directory" "Home directory '$home' does not exist." 8 60
|
|
return 1
|
|
fi
|
|
|
|
local uid uid_owner
|
|
uid=$(id -u "$TARGET_USER" 2>/dev/null)
|
|
uid_owner=$(stat -c '%u' "$home" 2>/dev/null || echo "0")
|
|
|
|
if [ "$uid_owner" != "$uid" ]; then
|
|
local expected_user
|
|
expected_user=$(id -nu "$uid_owner" 2>/dev/null || echo "UID $uid_owner")
|
|
if _confirm "Home Permissions" \
|
|
"Home directory '$home' is owned by\n'$expected_user' (expected: '$TARGET_USER').\n\nRepair ownership?" 12 65; then
|
|
if sudo chown -R "$TARGET_USER:$TARGET_USER" "$home"; then
|
|
echo -e "${GREEN}Home directory ownership repaired.${NC}"
|
|
else
|
|
echo -e "${RED}Failed to repair home directory ownership.${NC}"
|
|
return 1
|
|
fi
|
|
fi
|
|
else
|
|
_msg "Home Permissions" "Home directory ownership is correct\n(owner: $TARGET_USER)." 8 60
|
|
fi
|
|
}
|
|
|
|
# ── Option 4: Sudo Password Feedback (pwfeedback) ──
|
|
_toggle_pwfeedback() {
|
|
local fb_file="/etc/sudoers.d/pwfeedback"
|
|
|
|
if [ -f "$fb_file" ]; then
|
|
if _confirm "Password Feedback" \
|
|
"Asterisks are currently ENABLED when typing sudo password.\n\nDisable them?"; then
|
|
sudo rm -f "$fb_file"
|
|
echo -e "${GREEN}Password feedback disabled.${NC}"
|
|
fi
|
|
else
|
|
if _confirm "Password Feedback" \
|
|
"Show asterisks when typing the sudo password?"; then
|
|
if _validate_sudoers 'Defaults pwfeedback' "$fb_file"; then
|
|
echo -e "${GREEN}Password feedback enabled.${NC}"
|
|
else
|
|
return 1
|
|
fi
|
|
fi
|
|
fi
|
|
}
|