-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·185 lines (159 loc) · 5.94 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·185 lines (159 loc) · 5.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
#!/usr/bin/env bash
# screenguard system installer
#
# Usage: sudo ./install.sh
#
# Effects:
# /opt/screenguard/venv self-contained Python venv with package
# /opt/screenguard/install.sh copy of this script (for reference)
# /opt/screenguard/uninstall.sh copy of uninstaller (used by `screenguard uninstall`)
# /opt/screenguard/scripts/ copy of helper scripts
# /usr/local/bin/screenguard wrapper that execs the venv entry point
# /usr/local/sbin/screenguard-trigger fast PAM trigger
# /usr/local/share/man/man1/screenguard.1.gz man page
# /etc/screenguard/ empty config dir (root:root 0700)
# /var/lib/screenguard/ empty data dir (root:root 0700)
# /etc/pam.d/common-auth patched with hook + sentinel block
# /etc/pam.d/common-auth.screenguard.bak backup of original common-auth
set -euo pipefail
# ------------------------------------------------------------------ paths --
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PREFIX="/opt/screenguard"
VENV="${PREFIX}/venv"
BIN="/usr/local/bin/screenguard"
TRIGGER="/usr/local/sbin/screenguard-trigger"
MAN_DIR="/usr/local/share/man/man1"
MAN_PAGE="${MAN_DIR}/screenguard.1.gz"
CFG_DIR="/etc/screenguard"
DATA_DIR="/var/lib/screenguard"
LOG_FILE="/var/log/screenguard-trigger.log"
PAM_FILE="/etc/pam.d/common-auth"
PAM_BACKUP="/etc/pam.d/common-auth.screenguard.bak"
# ------------------------------------------------------------------ helpers
log() { printf '[install] %s\n' "$*"; }
warn() { printf '[install] WARN: %s\n' "$*" >&2; }
die() { printf '[install] ERROR: %s\n' "$*" >&2; exit 1; }
require_root() {
if [[ ${EUID:-$(id -u)} -ne 0 ]]; then
die "run as root: sudo $0"
fi
}
# ------------------------------------------------------------------ steps --
PYTHON=""
detect_python() {
# Pick the first python3.X interpreter that can actually create a venv
# (i.e. has 'ensurepip' available — that's the part python3-venv ships).
for py in python3.13 python3.12 python3.11 python3; do
if command -v "$py" >/dev/null 2>&1 \
&& "$py" -c 'import ensurepip' >/dev/null 2>&1; then
PYTHON="$py"
log "Using $PYTHON ($("$py" --version 2>&1)) for the venv"
return 0
fi
done
return 1
}
apt_deps() {
# Only required runtime tools. python3-venv is handled via detect_python:
# we use whichever python3.X is already venv-capable on this box, rather
# than apt-installing python3.13-venv (which may not exist on all releases).
local missing=()
for pkg in ffmpeg v4l-utils; do
if ! dpkg -s "$pkg" >/dev/null 2>&1; then
missing+=("$pkg")
fi
done
if (( ${#missing[@]} )); then
log "Installing apt deps: ${missing[*]}"
# Tolerate apt-get update failures from broken third-party repos —
# we only care that the packages we need are reachable.
DEBIAN_FRONTEND=noninteractive apt-get update -y || \
warn "apt-get update returned non-zero (broken third-party repo?); continuing"
DEBIAN_FRONTEND=noninteractive apt-get install -y "${missing[@]}"
else
log "ffmpeg, v4l-utils already present"
fi
if ! detect_python; then
die "no python3.X with working venv found.
Tried: python3.13, python3.12, python3.11, python3
Install one with venv support, e.g.:
sudo apt-get install python3.13-venv # (or python3-venv)"
fi
}
make_dirs() {
install -d -m 0755 "$PREFIX"
install -d -m 0755 "$PREFIX/scripts"
install -d -m 0700 "$CFG_DIR"
install -d -m 0700 "$DATA_DIR"
install -d -m 0700 "$DATA_DIR/captures"
install -d -m 0755 "$MAN_DIR"
: > "$LOG_FILE"
chmod 0640 "$LOG_FILE"
}
build_venv() {
if [[ ! -d "$VENV" ]]; then
log "Creating venv at $VENV with $PYTHON"
"$PYTHON" -m venv "$VENV"
fi
log "Upgrading pip in venv"
"$VENV/bin/pip" install --quiet --upgrade pip
log "Installing screenguard package into venv (from $SCRIPT_DIR)"
"$VENV/bin/pip" install --quiet "$SCRIPT_DIR"
}
install_wrappers() {
log "Installing $BIN wrapper"
cat > "$BIN" <<EOF
#!/bin/sh
exec "${VENV}/bin/screenguard" "\$@"
EOF
chmod 0755 "$BIN"
log "Installing $TRIGGER"
install -m 0755 "$SCRIPT_DIR/scripts/screenguard-trigger" "$TRIGGER"
log "Copying helper scripts and uninstaller into $PREFIX"
install -m 0755 "$SCRIPT_DIR/scripts/pam-patch.py" "$PREFIX/scripts/pam-patch.py"
install -m 0755 "$SCRIPT_DIR/install.sh" "$PREFIX/install.sh"
install -m 0755 "$SCRIPT_DIR/uninstall.sh" "$PREFIX/uninstall.sh"
}
install_man_page() {
log "Installing man page → $MAN_PAGE"
gzip -9 -c "$SCRIPT_DIR/man/screenguard.1" > "$MAN_PAGE"
chmod 0644 "$MAN_PAGE"
if command -v mandb >/dev/null 2>&1; then
mandb -q || true
fi
}
patch_pam() {
log "Patching $PAM_FILE"
"$VENV/bin/python" "$PREFIX/scripts/pam-patch.py" install \
--path "$PAM_FILE" \
--backup "$PAM_BACKUP"
}
print_next_steps() {
cat <<EOF
screenguard installed.
Next steps:
1. sudo screenguard configure # set bot token, chat id, devices
2. sudo screenguard test # capture + post a test message
3. man screenguard # full docs
PAM hook is live in $PAM_FILE. To verify it works:
- Open a new terminal
- Run \`sudo -k\` to clear the sudo timestamp, then type a wrong password to \`sudo true\`
- Watch the bot chat — a photo bundle should arrive within a few seconds
To remove everything:
sudo screenguard uninstall # keeps /etc/screenguard and /var/lib/screenguard
sudo screenguard uninstall --purge # also removes config and captures
EOF
}
# ------------------------------------------------------------------ main ---
main() {
require_root
log "screenguard install starting (source: $SCRIPT_DIR)"
apt_deps
make_dirs
build_venv
install_wrappers
install_man_page
patch_pam
print_next_steps
}
main "$@"