aboutsummaryrefslogtreecommitdiffstats
path: root/packaging/build/build-node.sh
blob: b9d542c9238dde85bfc53f52870a6a0826ae53d8 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
#!/usr/bin/env bash
# Build the meshbay-node package: node-specific files on top of meshbay-common.
#
# Expects build-common.sh to have run first (shared venv exists in staging).
#
# Usage: ./build-node.sh [staging-dir]
set -euo pipefail

REPO="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
STAGING="${1:-/tmp/meshbay-build}"
COMMON_ROOT="$STAGING/meshbay-common-root"
ROOT="$STAGING/meshbay-node-root"

VENV="$COMMON_ROOT/opt/meshbay-common/venv"
PYVER=$(basename "$VENV"/lib/python3.*)
SITE="$VENV/lib/$PYVER/site-packages"

VERSION=$(python3 -c "
import tomllib, pathlib
p = pathlib.Path('$REPO/packages/meshbay-node/pyproject.toml')
print(tomllib.loads(p.read_text())['project']['version'])
")
echo "==> meshbay-node $VERSION"

[ -d "$VENV" ] || { echo "!! shared venv not found — run build-common.sh first" >&2; exit 1; }

rm -rf "$ROOT"
mkdir -p "$ROOT"

# --- Node code in the shared venv (owned by meshbay-node package) ---------
# MOVE (not copy) from the common staging tree — same rationale as build-hub.sh.
NODE_ROOT="$ROOT/opt/meshbay-common/venv/lib/$PYVER/site-packages"
mkdir -p "$NODE_ROOT"
mv "$SITE/meshbay_node" "$NODE_ROOT/"
mv "$SITE"/meshbay_node-*.dist-info "$NODE_ROOT/"

# Entry point
mkdir -p "$ROOT/opt/meshbay-common/venv/bin"
mv "$VENV/bin/meshbay-node" "$ROOT/opt/meshbay-common/venv/bin/"

# Symlink in PATH
mkdir -p "$ROOT/usr/bin"
ln -sf /opt/meshbay-common/venv/bin/meshbay-node "$ROOT/usr/bin/meshbay-node"

# --- Node-specific assets -------------------------------------------------
mkdir -p "$ROOT/opt/meshbay-node/share"

# default.env: the shared TMDB token, copied as is from QE/default.env (never
# versioned), one line: MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... The daemon reads it
# beneath <config>/node.env and the operator's own token, so it is only the
# fallback. 0644: a per-user node must read it, and it is the same token in
# every copy of the package. No token, no build: an empty one goes unnoticed.
DEFAULT_ENV="$REPO/QE/default.env"
if [ "$(head -c 30 "$DEFAULT_ENV" 2>/dev/null)" != "MESHBAY_TMDB_DEFAULT_TOKEN=eyJ" ]; then
    echo "!! $DEFAULT_ENV missing, or not starting with MESHBAY_TMDB_DEFAULT_TOKEN=eyJ... (no BOM)" >&2
    exit 1
fi
install -m 644 "$DEFAULT_ENV" "$ROOT/opt/meshbay-node/share/default.env"
echo "    default.env copied from QE/"

# --- Systemd units --------------------------------------------------------
mkdir -p "$ROOT/usr/lib/systemd/system"
mkdir -p "$ROOT/usr/lib/systemd/user"
cp "$REPO/packaging/systemd/meshbay-node.service" \
   "$ROOT/usr/lib/systemd/system/meshbay-node@.service"
cp "$REPO/packaging/systemd/meshbay-node-user.service" \
   "$ROOT/usr/lib/systemd/user/meshbay-node.service"

# --- Firewall profiles --------------------------------------------------------
# The node's admin surface is a loopback API (127.0.0.1, token-gated) and is
# never firewall-exposed. Its *peer* traffic is: WebRTC binds an ephemeral UDP
# port per connection, and a peer that publishes an unroutable address — every
# browser does, as an mDNS .local name aioice cannot resolve — can only be
# reached if it calls the node. A node refusing unsolicited inbound UDP is
# therefore unreachable from browsers on its own LAN. Both profiles are passive:
# packaged, not activated, and meant to be scoped to a LAN zone/source.
mkdir -p "$ROOT/etc/ufw/applications.d"
cp "$REPO/packaging/firewall/ufw/meshbay" \
   "$ROOT/etc/ufw/applications.d/"

mkdir -p "$ROOT/usr/lib/firewalld/services"
cp "$REPO/packaging/firewall/firewalld/meshbay-node.xml" \
   "$ROOT/usr/lib/firewalld/services/"

echo "==> meshbay-node staging ready at $ROOT"