scripts/install.sh — one command for both halves

`bun setup` runs it. Machine setup first, then officer setup, stopping if the
first does not finish rather than running the second against a machine that is
not ready.

They stay two scripts because they answer two different questions and are worth
running apart — a machine you already trust needs only the second, one you are
rebuilding needs only the first. --machine-only and --officer-only say so
directly, and both halves remain runnable by path.

Privileges are checked here, before anything is done, because the two systems
want opposite things: Linux needs root for apt, systemd, useradd, netplan and ufw
and for creating directories owned by the service account; macOS must NOT be
root, since Homebrew refuses to run as one. Each script already enforces its own
rule, so this is only about failing early instead of halfway.

officer-setup.sh gained the same OS-aware check. It required root unconditionally,
which on macOS would have failed immediately after machine-setup — which must run
as the user — and for no reason: there the account running it IS the owner, so
there is nothing to chown and nothing to drop privileges to.

Arguments are parsed before privileges, so --help works without sudo and an
unknown option is rejected before anybody is asked for a password. It did not,
first time round.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-13 02:49:44 +00:00
co-authored by Claude Opus 5
parent b5aa2e0387
commit 3cca07187e
3 changed files with 115 additions and 2 deletions
+11 -1
View File
@@ -66,7 +66,17 @@ echo -e "${BOLD}╔════════════════════
echo -e "${BOLD}║ Officer Setup ║${NC}"
echo -e "${BOLD}╚══════════════════════════════════════════════════╝${NC}"
if [[ "$EUID" -ne 0 ]]; then
# root on Linux, NOT root on macOS — the same split machine-setup makes, for the
# same reason. On Linux this creates directories owned by another account and
# drops privileges with `sudo -u`. On macOS the account running the script IS the
# owner, so there is nothing to chown and nothing to drop to — and Homebrew, which
# machine-setup ran just before this, refuses to run as root at all.
OFFICER_OS="$(uname -s)"
if [[ "$OFFICER_OS" == "Darwin" ]]; then
if [[ "$EUID" -eq 0 ]]; then
fail "Do not run this with sudo on macOS — run it as yourself."
fi
elif [[ "$EUID" -ne 0 ]]; then
fail "Please run as root: sudo ./officer-setup.sh"
fi