Files
ladill-hosting/deployment/setup-terminal-jail.sh
T
isaaccladandClaude Opus 4.8 75ba450938
Deploy Ladill Hosting / deploy (push) Successful in 45s
Terminal: show the live full working-directory path in the toolbar
The toolbar showed a static ~/public_html. The jailed shell now reports its cwd
via OSC 7 each prompt (jail rcfile keeps the user's prompt + emits it); xterm
captures it and the toolbar shows the full path (/home/<user>/...), updating as
the user cd's. Launcher/rcfile committed in deployment/ for reproducibility.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 07:53:48 +00:00

40 lines
1.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Provision the jailkit chroot used by the control-panel browser terminal so the
# customer shell is confined to its own home (cannot see /var/www, other tenants,
# /etc, or secrets). Idempotent; run as root on each hosting node.
set -Eeuo pipefail
JAIL=/home/jail
echo "==> Installing jailkit"
export DEBIAN_FRONTEND=noninteractive
command -v jk_init >/dev/null 2>&1 || apt-get install -y jailkit
echo "==> Building jail tree at $JAIL"
jk_init -j "$JAIL" uidbasics netbasics basicshell interactiveshell extendedshell editors netutils terminfo || true
jk_cp -j "$JAIL" /usr/bin/id /usr/bin/whoami /usr/bin/find /usr/bin/grep /usr/bin/less \
/usr/bin/head /usr/bin/tail /usr/bin/du /usr/bin/df /usr/bin/wc /usr/bin/clear /usr/bin/sed /usr/bin/awk || true
# Terminal definitions (xterm*) for a usable TTY.
mkdir -p "$JAIL/usr/share/terminfo"
cp -rn /usr/share/terminfo/x "$JAIL/usr/share/terminfo/" 2>/dev/null || true
# Non-listable jail /home (each session bind-mounts only its own home here).
install -d -o root -g root -m 711 "$JAIL/home"
install -d -m 1777 "$JAIL/tmp"
# NOTE: do NOT sync hosting users into the shared jail passwd — that would let
# any customer enumerate every tenant. ladill-jailsh injects a per-session
# passwd/group (root + the current user only) inside each session's namespace.
echo "==> Installing the interactive rc (keeps user prompt + reports cwd via OSC 7)"
install -o root -g root -m 644 "$(dirname "$0")/ladill-jail-bashrc" "$JAIL/etc/ladill-jail-bashrc"
echo "==> Installing the jailed-shell launcher + scoped sudoers"
install -o root -g root -m 755 "$(dirname "$0")/ladill-jailsh" /usr/local/sbin/ladill-jailsh
echo 'www-data ALL=(root) NOPASSWD: /usr/local/sbin/ladill-jailsh *' > /etc/sudoers.d/ladill-jailsh
chmod 440 /etc/sudoers.d/ladill-jailsh
visudo -cf /etc/sudoers.d/ladill-jailsh
echo "==> Done. Customer terminals now run jailed in $JAIL."