85 lines
3.8 KiB
Bash
Executable File
85 lines
3.8 KiB
Bash
Executable File
#!/bin/bash
|
|
# qfix.sh — repair dom0 qrexec policy + signer handler. Run as root in dom0:
|
|
# sudo bash qfix.sh
|
|
# Fixes (with backups saved to ~/qfix-backup-<ts>/):
|
|
# 1. Removes invalid old-format file /etc/qubes-rpc/policy/qubes.SignerRpc
|
|
# (its "* * * allow" content breaks ALL qrexec policy loading)
|
|
# 2. Rewrites /etc/qubes/policy.d/45-signer.policy with direct targets
|
|
# 3. Sets the signer-signer tag on nostr_signer (optional, for tag rules)
|
|
# 4. Creates /etc/qubes-rpc/qubes.SignerRpc handler inside nostr_signer
|
|
# (modeled on the existing qubes.NsignerRpc handler)
|
|
# 5. Verifies policy loads cleanly
|
|
|
|
set -u
|
|
TS=$(date +%Y%m%d-%H%M%S)
|
|
BK=~/qfix-backup-$TS
|
|
mkdir -p "$BK"
|
|
|
|
ok() { printf '\033[1;32m[OK]\033[0m %s\n' "$*"; }
|
|
info(){ printf '\033[1;34m[..]\033[0m %s\n' "$*"; }
|
|
err() { printf '\033[1;31m[ERR]\033[0m %s\n' "$*"; }
|
|
|
|
[[ $EUID -eq 0 ]] || { err "Run as root: sudo bash qfix.sh"; exit 1; }
|
|
|
|
# ── 1. Remove the invalid old-format policy file ─────────────────────
|
|
if [[ -f /etc/qubes-rpc/policy/qubes.SignerRpc ]]; then
|
|
cp /etc/qubes-rpc/policy/qubes.SignerRpc "$BK/" 2>/dev/null
|
|
rm -f /etc/qubes-rpc/policy/qubes.SignerRpc
|
|
ok "removed invalid /etc/qubes-rpc/policy/qubes.SignerRpc (backed up)"
|
|
else
|
|
ok "no invalid old-format file present"
|
|
fi
|
|
|
|
# ── 2. Rewrite 45-signer.policy with direct target rules ─────────────
|
|
SIGNER_POLICY=/etc/qubes/policy.d/45-signer.policy
|
|
if [[ -f "$SIGNER_POLICY" ]]; then
|
|
cp "$SIGNER_POLICY" "$BK/45-signer.policy"
|
|
fi
|
|
cat > "$SIGNER_POLICY" <<'EOF'
|
|
# Qubes OS qrexec policy for signer (qubes.SignerRpc)
|
|
# Direct rules: caller -> nostr_signer
|
|
qubes.SignerRpc * ai nostr_signer allow
|
|
qubes.SignerRpc * nostr nostr_signer allow
|
|
qubes.SignerRpc * @anyvm @anyvm ask default_target=nostr_signer
|
|
EOF
|
|
chown root:root "$SIGNER_POLICY"
|
|
chmod 0644 "$SIGNER_POLICY"
|
|
ok "rewrote $SIGNER_POLICY"
|
|
|
|
# ── 3. Tag nostr_signer (enables @tag:signer-signer rules if ever used) ──
|
|
qvm-tags nostr_signer add signer-signer 2>/dev/null \
|
|
&& ok "tagged nostr_signer with signer-signer" \
|
|
|| info "tag set skipped (non-fatal)"
|
|
|
|
# ── 4. Create the qrexec handler inside nostr_signer ─────────────────
|
|
info "inspecting existing handlers in nostr_signer..."
|
|
qvm-run -p nostr_signer 'cat /etc/qubes-rpc/qubes.NsignerRpc 2>/dev/null' || true
|
|
|
|
# Detect signer binary location in the target qube
|
|
BIN=$(qvm-run -p nostr_signer \
|
|
'for b in $HOME/.local/bin/signer /usr/local/bin/signer; do [ -x "$b" ] && echo "$b" && break; done' 2>/dev/null | tr -d '\r')
|
|
[[ -n "$BIN" ]] || { err "signer binary not found in nostr_signer (run install_signer.sh there first)"; BIN="/home/user/.local/bin/signer"; }
|
|
info "signer binary in nostr_signer: $BIN"
|
|
|
|
qvm-run -u root -p nostr_signer "printf '#!/bin/sh\nexec $BIN bridge\n' > /etc/qubes-rpc/qubes.SignerRpc && chmod 0755 /etc/qubes-rpc/qubes.SignerRpc" \
|
|
&& ok "created /etc/qubes-rpc/qubes.SignerRpc in nostr_signer" \
|
|
|| err "handler creation failed (create manually)"
|
|
|
|
# Show what we created
|
|
qvm-run -p nostr_signer 'ls -la /etc/qubes-rpc/qubes.SignerRpc; cat /etc/qubes-rpc/qubes.SignerRpc' || true
|
|
|
|
# ── 5. Verify policy loads cleanly ───────────────────────────────────
|
|
info "verifying policy syntax..."
|
|
if qrexec-policy-graph --include-ask >/dev/null 2>"$BK/policy-graph.err"; then
|
|
ok "policy loads cleanly (no syntax errors)"
|
|
else
|
|
err "policy still has errors:"
|
|
cat "$BK/policy-graph.err"
|
|
fi
|
|
|
|
echo
|
|
ok "repair complete. Backups in $BK"
|
|
echo "Now test from the ai qube:"
|
|
echo " signer-client --qrexec nostr_signer:qubes.SignerRpc --role main --path \"m/44'/1237'/0'/0/0\" get-public-key"
|
|
echo "Clipboard (dom0 -> ai) should also work again: Ctrl+Shift+C in dom0, Ctrl+Shift+V in ai"
|