52 lines
3.5 KiB
Bash
Executable file
52 lines
3.5 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Bakes the relay URL, key, token and downloads base into copies of the clients and zips them. The files in the repo keep
|
|
# their placeholders; the zip is the secret-bearing artefact and goes to the PC by hand (USB stick, AirDrop), NEVER
|
|
# through the downloads host (review round 4, X23: the hosted zip put both relay secrets one dl token away).
|
|
#
|
|
# make-clients.sh [--machine NAME] [outdir-for-zip]
|
|
#
|
|
# --machine NAME also puts that machine's secret (~/.config/igneum/relay-machines/NAME, from `node tools/relay.mjs
|
|
# secret NAME`) into the zip as machine-secret.txt, which is what lets the agent there run signed tasks and lets its
|
|
# results carry its name (X23, X27). Without --machine the zip can read, post notes and files, and nothing runs.
|
|
# Reads ~/.config/igneum/relay-url (optional), relay-key, relay-token, dl-token (for RELAY_DL_BASE; X26: the base is a
|
|
# value the agent holds, never text in a task body).
|
|
set -euo pipefail
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
CFG="$HOME/.config/igneum"
|
|
MACHINE=""; OUT="$HOME/Desktop"
|
|
while [ $# -gt 0 ]; do
|
|
case "$1" in --machine) MACHINE="$2"; shift 2 ;; --*) echo "unknown flag $1" >&2; exit 2 ;; *) OUT="$1"; shift ;; esac
|
|
done
|
|
URL="$(cat "$CFG/relay-url" 2>/dev/null | tr -d '\n' || true)"; URL="${URL:-https://relay.igneum.network}"
|
|
KEY="$(tr -d '\n' < "$CFG/relay-key")"; TOKEN="$(tr -d '\n' < "$CFG/relay-token")"
|
|
DL="$(tr -d '[:space:]' < "$CFG/dl-token" 2>/dev/null || true)"
|
|
DL_BASE="https://dl.igneum.network/dl/${DL:-MISSING-DL-TOKEN}"
|
|
SECRET=""
|
|
if [ -n "$MACHINE" ]; then
|
|
SF="$CFG/relay-machines/$MACHINE"
|
|
[ -f "$SF" ] || { echo "no $SF: node tools/relay.mjs secret $MACHINE first" >&2; exit 1; }
|
|
SECRET="$(tr -d '[:space:]' < "$SF")"
|
|
[ ${#SECRET} = 64 ] || { echo "$SF is not a 64-hex secret" >&2; exit 1; }
|
|
fi
|
|
mkdir -p "$OUT"
|
|
NAME="igneum-relay-clients${MACHINE:+-$MACHINE}"
|
|
STAGE="$(mktemp -d)/$NAME"; mkdir -p "$STAGE"; umask 077
|
|
for f in send.bat send.ps1 send.sh igneum-agent.bat igneum-agent.ps1 igneum-agent-service.ps1 install-agent.ps1 IgneumRelayService.xml agent.sh CLAUDE-PC.md; do
|
|
sed -e "s#__RELAY_URL__#$URL#g" -e "s#__RELAY_KEY__#$KEY#g" -e "s#__RELAY_TOKEN__#$TOKEN#g" -e "s#__DL_BASE__#$DL_BASE#g" "$HERE/$f" > "$STAGE/$f"
|
|
done
|
|
[ -n "$SECRET" ] && printf '%s\n' "$SECRET" > "$STAGE/machine-secret.txt"
|
|
# Windows reads CRLF batch files most reliably; PowerShell is fine either way
|
|
for f in send.bat igneum-agent.bat; do perl -pi -e 's/\r?\n/\r\n/' "$STAGE/$f"; done
|
|
chmod +x "$STAGE/send.sh" "$STAGE/agent.sh"
|
|
# the two optional phrases are built first: an apostrophe inside ${MACHINE:+...} in a heredoc is "no closing }" to bash 3.2
|
|
FOR="${MACHINE:+ for $MACHINE}"
|
|
OWN=""; [ -n "$MACHINE" ] && OWN=" and this machine's own secret (machine-secret.txt)"
|
|
cat > "$STAGE/README.txt" <<TXT
|
|
Igneum relay clients$FOR. Unzip anywhere. send.bat "<text>" | send.bat <file> | send.bat inbox | send.bat result "<text>" | send.bat get <id>
|
|
install-agent.ps1 (right-click, Run with PowerShell; no administrator needed): registers the agent as the per-user logon task IgneumRelayService, restarted on failure, so it outlives the app and comes back after a reboot. igneum-agent.bat: the hand-started form, double-click once, leave open. CLAUDE-PC.md: paste into the Claude Code session on this PC.
|
|
These files contain the relay secret$OWN. Keep them off shared drives and off the downloads host.
|
|
TXT
|
|
rm -f "$OUT/$NAME.zip"
|
|
(cd "$(dirname "$STAGE")" && zip -qr "$OUT/$NAME.zip" "$NAME")
|
|
echo "staged: $STAGE"
|
|
echo "zip: $OUT/$NAME.zip ($(du -h "$OUT/$NAME.zip" | cut -f1)); carry it to the PC by hand, never through the downloads host"
|