secubox-deb/scripts/fix-namespace-errors.sh
CyberMind-FR cf7ea44c78 fix(kiosk): Skip X11 config on bare metal, disable service sandboxing
- X11 setup now exits early for bare metal (VM_TYPE=none) without
  creating config files - Intel/AMD/NVIDIA auto-detect perfectly
- Remove static fallback 10-modesetting.conf that caused conflicts
- Sanitize GPU_INFO in config comments to remove special chars
- Disable PrivateTmp and ProtectSystem for haproxy, metrics, threats
  services - causes Python symlink namespace errors on some kernels
- Add fix-namespace-errors.sh script for quick fixes on running systems

Fixes: X11 "no screens found" on Intel HD Graphics 630
Fixes: "Failed to set up mount namespacing" for Python services

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-15 09:52:20 +02:00

74 lines
2.5 KiB
Bash
Executable File

#!/bin/bash
# ══════════════════════════════════════════════════════════════════
# fix-namespace-errors.sh — Disable sandboxing that causes Python errors
# Run this on real hardware when services fail with:
# "Failed to set up mount namespacing: /run/systemd/unit-root/usr/bin/python3"
# ══════════════════════════════════════════════════════════════════
set -euo pipefail
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m'
log() { echo -e "${GREEN}[fix]${NC} $*"; }
warn() { echo -e "${YELLOW}[warn]${NC} $*"; }
err() { echo -e "${RED}[error]${NC} $*" >&2; }
if [[ $EUID -ne 0 ]]; then
err "This script must be run as root"
exit 1
fi
log "Scanning for SecuBox services with sandboxing..."
# Find all secubox services with PrivateTmp or ProtectSystem
SERVICES=$(systemctl list-unit-files 'secubox-*.service' --no-legend | awk '{print $1}')
FIXED=0
for SERVICE in $SERVICES; do
# Get the service file path
SERVICE_FILE=$(systemctl show -p FragmentPath "$SERVICE" --value 2>/dev/null || true)
[[ -z "$SERVICE_FILE" ]] && continue
[[ ! -f "$SERVICE_FILE" ]] && continue
# Check if it has sandboxing options
if grep -qE '^(PrivateTmp|ProtectSystem)=' "$SERVICE_FILE" 2>/dev/null; then
# Create override directory
OVERRIDE_DIR="/etc/systemd/system/${SERVICE}.d"
mkdir -p "$OVERRIDE_DIR"
# Create override file
cat > "$OVERRIDE_DIR/no-sandbox.conf" <<'EOF'
# Override to disable sandboxing that causes namespace errors with Python
[Service]
PrivateTmp=false
ProtectSystem=false
EOF
log "Created override for: $SERVICE"
((FIXED++))
fi
done
if [[ $FIXED -gt 0 ]]; then
log "Fixed $FIXED services"
log "Reloading systemd..."
systemctl daemon-reload
log "Restarting failed services..."
systemctl reset-failed 'secubox-*' 2>/dev/null || true
# Restart specifically known problematic services
for svc in secubox-haproxy secubox-metrics secubox-threats; do
if systemctl is-enabled "$svc" &>/dev/null; then
log "Restarting $svc..."
systemctl restart "$svc" 2>/dev/null || warn "$svc failed to start"
fi
done
log "Done! Check status with: systemctl status 'secubox-*'"
else
log "No services needed fixing"
fi