#!/bin/bash
# Ladill jailed shell for the hosting browser terminal. Confines a hosting
# account to /home/jail with ONLY its own home visible: a private mount namespace
# plus a per-session tmpfs /home that contains just this user's directory (so
# 'ls /home' shows their own folder and never other tenants).
# Usage: ladill-jailsh <username> [relpath]
set -euo pipefail
JAIL=/home/jail
U=${1:-}
REL=${2:-/public_html}
[ -n "$U" ] || { echo 'usage: ladill-jailsh <user> [relpath]'; exit 2; }
UID_=$(id -u "$U" 2>/dev/null || true)
GID_=$(id -g "$U" 2>/dev/null || true)
[ -n "$UID_" ] && [ "$UID_" -ge 1000 ] || { echo 'refusing: not a hosting user'; exit 1; }
HOMEDIR=/home/$U
[ -d "$HOMEDIR" ] || { echo 'no home directory'; exit 1; }
case "$REL" in *..*) REL=/public_html;; esac
# re-exec into a private mount namespace so all mounts are per-session
if [ -z "${LADILL_JAIL_NS:-}" ]; then
  exec env LADILL_JAIL_NS=1 unshare --mount --propagation private -- "$0" "$U" "$REL"
fi
# Fresh, listable /home holding ONLY this user's directory (no tenant leak).
mount -t tmpfs -o mode=0755,nosuid,nodev tmpfs "$JAIL/home"
mkdir -p "$JAIL/home/$U"
mount --bind "$HOMEDIR" "$JAIL/home/$U"
export HOME="/home/$U" USER="$U" LOGNAME="$U" SHELL=/bin/bash PATH=/usr/bin:/bin
export TERM="${TERM:-xterm-256color}"
exec /usr/sbin/chroot --userspec="$UID_:$GID_" "$JAIL" /bin/bash -l -c "cd '/home/$U$REL' 2>/dev/null || cd ~; exec /bin/bash -l"
