Repository navigation
Conversation
For running as the invoking user and following the session's PipeWire or PulseAudio. It keeps the seccomp half of the system unit's hardening, which is what an unprivileged manager can apply.
The script now works piped into bash, with prompts read from the terminal and the body wrapped so a truncated download runs nothing. It offers to install missing runtime libraries and a --user-service mode. --yes with no --output on an unconfigured host still enables without starting.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
scripts/get_started_linux.shnow goes all the way to a running player: it asks for a name and an output device, writes them to the config and starts the service. It works as acurl | bashone-liner, and there is an uninstaller to match. The README opens with the quick start.What changed
nameandoutput, writes them and starts the service.--nameand--outputanswer up front. A key the config already sets is never asked for or replaced, so re-running on a configured host is still an upgrade with one confirmation./dev/ttywhen the script arrives on stdin. The body is a function called from a final{ main "$@"; }, so a truncated download is a syntax error.--helpno longer reads$0.install/cp; the lines it sets are printed again just before the copy.lddon an unprivileged copy of the binary runs before anything is installed. Missing libraries map toapt-get/dnf/pacmanpackages and the install command joins the plan. An unmapped library, no known package manager, or a too-old glibc stops with the reason and nothing installed.--user-service. Runs as the invoking user undersystemctl --user, with linger,audiomembership and~/.config/sendspin-cli/config. On a fresh interactive run the script asks which mode; the hardened system unit stays the default. Choosing one mode disables the other.lib/systemd/user/sendspin-cli.service. It keeps the seccomp half of the hardening block. For a release that predates it (every release so far), the script writes a marked equivalent to~/.config/systemd/user/and removes it on the first upgrade that ships one.scripts/uninstall_linux.sh. Removes the service in either mode and the payload; keeps config, state and the account unless--purgeor a yes at its prompt.BUILD-INFO.txtcover the new unit.Compatibility
Nothing breaks for users of the binary: no flag, config key, control-socket, state-store or exit-code change.
Visible but not breaking:
--yesruns behave as before: system service, and with no--outputand none configured, enabled but not started with the device list printed. One addition:--yesnow also installs missing runtime packages, shown in the plan, where the old script died on the loader error.usr/local/lib/systemd/user/sendspin-cli.service. Nothing enables it unless asked.What was run
In a privileged rootless podman container running systemd (Fedora 44), as an unprivileged sudo user, with
SENDSPIN_CLI_TARBALLbuilt from this branch and prompts answered on a pty:bash: name and output asked, config written, unmodified hardened unitactiveassendspin-cli.--yesalone on a fresh host: enabled, not started, device list and next steps.--yes --name … --output null: fully unattended, running, a name with&,\and|written verbatim.--yes: refuses, nothing installed. Declining the plan: nothing installed.active, linger on, config in~/.config,sendspin-cli statusworks with no sudo or flags, system unit not running.--yesre-run keeps the mode it finds.sudo: fallback unit written and owned by the user; upgrade to a payload with the unit removes it.With the real v0.3.0 release downloaded and checksummed, in plain containers (no systemd, root):
libasound2t64 libavahi-compat-libdnssd1 libpipewire-0.3-0t64 libportaudio2 libpulse0, installed, binary loads.dnf) and Arch (pacman): packages installed, binary loads.GLIBC_2.38.Also:
bashas truncated input: none reachesmain.systemd-run --useron a Fedora 44 desktop with PipeWire: the player starts, stays up, and-lenumerates the PipeWire default.shellcheck scripts/*.sh,scripts/smoke_test.sh, andctest(518/520; the two failures are this checkout's path exceeding the Unix socket address limit, and pass from a short directory).Not run: playback of a real stream through the user service (no server in the test setup), a real Raspberry Pi, and a real
curlof the script frommain, which only exists after merge.Closes #71