first commit

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-24 20:36:08 +02:00
commit 8612b38bee
10 changed files with 3109 additions and 0 deletions

54
install.sh Normal file
View File

@@ -0,0 +1,54 @@
#!/usr/bin/env bash
# Build + install the AVNI control-center, and set up access delegation.
# - binary -> /usr/local/bin/avni (real file, so granted non-root users can exec it)
# - firewall helper -> /usr/local/bin/avni-firewall.sh (used by the blacklist/whitelist engine)
# - 'avni' Unix group = who may use the tool (root always can)
# - sudoers drop-in lets 'avni' members auto-elevate (the binary re-execs via sudo)
#
# Run from anywhere — the script locates its own directory, so the repo can be cloned
# to any path. Re-run after every code change to redeploy. Usage: sudo bash install.sh
set -euo pipefail
SRC="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
BIN=/usr/local/bin/avni
FWBIN=/usr/local/bin/avni-firewall.sh
if [ "$(id -u)" -ne 0 ]; then echo "!! run as root: sudo bash install.sh"; exit 1; fi
# locate cargo (rustup install lives under the invoking user's home even under sudo)
CARGO="$(command -v cargo || true)"
[ -z "$CARGO" ] && [ -x "$HOME/.cargo/bin/cargo" ] && CARGO="$HOME/.cargo/bin/cargo"
[ -z "$CARGO" ] && [ -n "${SUDO_USER:-}" ] && [ -x "/home/$SUDO_USER/.cargo/bin/cargo" ] && CARGO="/home/$SUDO_USER/.cargo/bin/cargo"
if [ -z "$CARGO" ]; then echo "!! cargo not found — install Rust via https://rustup.rs"; exit 1; fi
echo "==> building (release)"
( cd "$SRC" && "$CARGO" build --release >/dev/null )
echo "==> 'avni' access group"
groupadd -f avni
echo "==> sudoers drop-in (auto-elevation for granted users)"
cat > /etc/sudoers.d/avni <<'EOF'
# AVNI control-center — members of the 'avni' group may run the tool as root.
# They are already admins (sudo); granting 'avni' just makes `avni` launch seamlessly.
%avni ALL=(root) NOPASSWD: /usr/local/bin/avni
EOF
chmod 440 /etc/sudoers.d/avni
if ! visudo -cf /etc/sudoers.d/avni >/dev/null; then
echo "!! sudoers validation failed — removing drop-in"; rm -f /etc/sudoers.d/avni; exit 1
fi
echo "==> installing firewall helper -> $FWBIN"
install -o root -g root -m 0755 "$SRC/avni-firewall.sh" "$FWBIN"
echo "==> installing binary -> $BIN"
rm -f "$BIN"
install -o root -g root -m 0755 "$SRC/target/release/avni" "$BIN"
# optional: pure-Python fallback
if [ -f "$SRC/avni.py" ]; then
install -o root -g root -m 0755 "$SRC/avni.py" /usr/local/bin/avni-py
fi
echo "OK. root + 'avni' group members can run: avni"
echo "Current avni-group members: $(getent group avni | cut -d: -f4)"