#!/bin/bash installDebianUbuntu() { if [[ "$OS_TYPE" == "Ubuntu" || "$OS_TYPE" == "Debian" ]]; then # OS package management needs real root. A root install runs apt directly # (and bootstraps sudo itself on a bare box); the hardened de-sudo manager # is deliberately NOT granted `sudo apt` — the LP_SYSTEM sudoers allowlist # scopes systemctl/ufw/sysctl/loginctl/service, never apt. So at manager # runtime skip cleanly instead of logging apt permission failures (exit # 100) on every preinstall pass; OS/security updates are a host / # install-time concern there. `priv` is the privilege prefix: empty when # we're already root, "sudo" only where sudo-apt is actually permitted. local priv="" if [[ $EUID -ne 0 ]]; then if sudo -n apt-get --version >/dev/null 2>&1; then priv="sudo" else isNotice "OS package updates need root and aren't permitted for the manager — skipping (handled at install time / by the host)." return 0 fi fi if checkIfOSUpdateShouldRun; then isNotice "Installing System Updates... this may take a while." if [[ "$OS_TYPE" == "Debian" ]]; then export DEBIAN_FRONTEND="noninteractive" fi local result; result=$(DEBIAN_FRONTEND=noninteractive APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=1 $priv apt-get update -qq 2>&1 && DEBIAN_FRONTEND=noninteractive APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=1 $priv apt-get install sudo -yqq 2>&1 && $priv apt-get autoclean 2>&1) checkSuccess "Updating System Operating system." local result; result=$(DEBIAN_FRONTEND=noninteractive APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=1 $priv apt-get update -qq 2>&1) checkSuccess "Running application update" # 7-Zip changed package name: Debian 13 and Ubuntu 24.04+ ship `7zip`, older # releases ship `p7zip-full`. Resolve against the freshly-updated package # lists rather than relying on a `p7zip*` glob — that only still matches on # new releases because `7zip` happens to declare `Provides: p7zip`. # Match on a real package stanza, not just apt-cache's exit status — it # returns 0 with empty output for virtual/provided-only names. local sevenzip="p7zip-full" if apt-cache show 7zip 2>/dev/null | grep -q .; then sevenzip="7zip" fi installed_apps="apt-get install curl dialog pv wget git zip htop sqlite3 sshpass rsync acl apache2-utils inotify-tools jq $sevenzip" local result; result=$(DEBIAN_FRONTEND=noninteractive APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=1 $priv $installed_apps -yqq 2>&1) checkSuccess "Installing system applications" else isNotice "System Updates already ran within the last ${CFG_UPDATER_CHECK} minutes, skipping..." fi $priv mkdir -p "$(dirname "$sysctl")" $priv touch $sysctl fi }