diff --git a/flake.nix b/flake.nix index 0d2ad46..ea7a0be 100644 --- a/flake.nix +++ b/flake.nix @@ -90,38 +90,68 @@ cat > "$out" <<'SH' #!/bin/sh set -euf - : "''${TMPDIR:=/tmp}" - EXTRACT_DIR="$(mktemp -d "''${TMPDIR%/}/nxbdl.XXXXXX")" - cleanup() { [ -n "''${KEEP_BUNDLE:-}" ] || rm -rf "$EXTRACT_DIR"; } + umask 077 + + # harden env + unset LD_PRELOAD LD_LIBRARY_PATH LD_AUDIT LD_DEBUG LD_PROFILE LD_USE_LOAD_BIAS LD_ORIGIN_PATH LD_ASSUME_KERNEL + + : "${TMPDIR:=/tmp}" + EXTRACT_DIR="$(mktemp -d "${TMPDIR%/}/nxbdl.XXXXXX")" + cleanup() { [ -n "${KEEP_BUNDLE:-}" ] || rm -rf "$EXTRACT_DIR"; } trap cleanup EXIT INT TERM - + ARCHIVE_LINE=$(awk '/^__ARCHIVE_BELOW__/ {print NR+1; exit 0}' "$0") - tail -n +"$ARCHIVE_LINE" "$0" | tar -xzf - -C "$EXTRACT_DIR" - - BUNDLE_PWD="''${BUNDLE_PWD:-$PWD}" - + # portable vs tail -n +N + sed -n "${ARCHIVE_LINE},\$p" "$0" | tar -xzf - -C "$EXTRACT_DIR" + + BUNDLE_PWD="${BUNDLE_PWD:-$PWD}" + cd "$EXTRACT_DIR" APP_REL='__APP_REL__' PROOT_REL='__PROOT_REL__' - - if [ -n "''${BUNDLE_PROOT:-}" ] && command -v "''${BUNDLE_PROOT}" >/dev/null 2>&1; then - PROOT_BIN="''${BUNDLE_PROOT}" + + # choose proot: env -> host -> bundled + if [ -n "${BUNDLE_PROOT:-}" ] && command -v "${BUNDLE_PROOT}" >/dev/null 2>&1; then + PROOT_BIN="${BUNDLE_PROOT}" elif command -v proot >/dev/null 2>&1; then PROOT_BIN="$(command -v proot)" else - PROOT_BIN="$EXTRACT_DIR''${PROOT_REL}" + PROOT_BIN="$EXTRACT_DIR${PROOT_REL}" fi - - if [ "''${BUNDLE_FORCE_BUNDLED_PROOT:-0}" = 1 ]; then - PROOT_BIN="$EXTRACT_DIR''${PROOT_REL}" + [ "${BUNDLE_FORCE_BUNDLED_PROOT:-0}" = 1 ] && PROOT_BIN="$EXTRACT_DIR${PROOT_REL}" + + # sanity + [ -x "$PROOT_BIN" ] || { echo "proot not found/executable: $PROOT_BIN" >&2; exit 127; } + [ -x "$EXTRACT_DIR${APP_REL}" ] || { echo "app not found/executable: $EXTRACT_DIR${APP_REL}" >&2; exit 127; } + + # DNS for Android/termux (no /etc/resolv.conf in root) + mkdir -p "$EXTRACT_DIR/etc" + cat > "$EXTRACT_DIR/etc/resolv.conf" <<'EOF' + nameserver 9.9.9.9 + nameserver 8.8.8.8 + nameserver 1.1.1.1 + nameserver 1.0.0.1 + EOF + + # run proot (no exec so trap can clean). Set BUNDLE_EXEC=1 to exec instead. + if [ "${BUNDLE_EXEC:-0}" = 1 ]; then + exec "${PROOT_BIN}" \ + -R / \ + -b "$EXTRACT_DIR/nix:/nix" \ + -b "$EXTRACT_DIR/etc/resolv.conf:/etc/resolv.conf" \ + -b /dev -b /proc -b /sys \ + -w "$BUNDLE_PWD" \ + "$EXTRACT_DIR${APP_REL}" "$@" + else + "${PROOT_BIN}" \ + -R / \ + -b "$EXTRACT_DIR/nix:/nix" \ + -b "$EXTRACT_DIR/etc/resolv.conf:/etc/resolv.conf" \ + -b /dev -b /proc -b /sys \ + -w "$BUNDLE_PWD" \ + "$EXTRACT_DIR${APP_REL}" "$@" fi - - exec "''${PROOT_BIN}" \ - -b "$EXTRACT_DIR/nix:/nix" \ - -R / \ - -w "$BUNDLE_PWD" \ - "$EXTRACT_DIR''${APP_REL}" "$@" - + __ARCHIVE_BELOW__ SH