From e251d09d1fe6948eae248610a2a4c7ba178250af Mon Sep 17 00:00:00 2001 From: ali Date: Thu, 25 Jun 2026 08:12:43 +0300 Subject: [PATCH] working alpha version --- mini-pc/etc/nginx/sites-available/talia-sd | 4 + mini-pc/etc/systemd/system/talia-wait.service | 10 ++ mini-pc/readme | 13 ++ mini-pc/root/scripts/scan.sh | 33 ++++ mini-pc/root/scripts/wait.sh | 26 +++ .../systemd/system/talia-serial-wait.service | 11 ++ .../etc/systemd/system/talia-wait.service | 10 ++ raspberry-pi/etc/vsftpd.conf | 156 ++++++++++++++++++ raspberry-pi/readme | 20 +++ raspberry-pi/root/scripts/expose_usb.sh | 35 ++++ raspberry-pi/root/scripts/serial-wait.sh | 18 ++ raspberry-pi/root/scripts/wait.sh | 45 +++++ 12 files changed, 381 insertions(+) create mode 100644 mini-pc/etc/nginx/sites-available/talia-sd create mode 100644 mini-pc/etc/systemd/system/talia-wait.service create mode 100644 mini-pc/readme create mode 100755 mini-pc/root/scripts/scan.sh create mode 100755 mini-pc/root/scripts/wait.sh create mode 100644 raspberry-pi/etc/systemd/system/talia-serial-wait.service create mode 100644 raspberry-pi/etc/systemd/system/talia-wait.service create mode 100644 raspberry-pi/etc/vsftpd.conf create mode 100644 raspberry-pi/readme create mode 100755 raspberry-pi/root/scripts/expose_usb.sh create mode 100755 raspberry-pi/root/scripts/serial-wait.sh create mode 100755 raspberry-pi/root/scripts/wait.sh diff --git a/mini-pc/etc/nginx/sites-available/talia-sd b/mini-pc/etc/nginx/sites-available/talia-sd new file mode 100644 index 0000000..046e557 --- /dev/null +++ b/mini-pc/etc/nginx/sites-available/talia-sd @@ -0,0 +1,4 @@ +server { +autoindex on; +root /var/www/talia; +} diff --git a/mini-pc/etc/systemd/system/talia-wait.service b/mini-pc/etc/systemd/system/talia-wait.service new file mode 100644 index 0000000..a0e5ee8 --- /dev/null +++ b/mini-pc/etc/systemd/system/talia-wait.service @@ -0,0 +1,10 @@ +[Unit] +Description=Talia SD Wait Service + +[Service] +ExecStart=/root/scripts/wait.sh +Restart=on-failure +RestartSec=60 + +[Install] +WantedBy=multi-user.target diff --git a/mini-pc/readme b/mini-pc/readme new file mode 100644 index 0000000..3568e1c --- /dev/null +++ b/mini-pc/readme @@ -0,0 +1,13 @@ +# mini pc +# debian 13 trixie + +# packages +# libclamunrar require non-free +apt-get install clamav libclamunrar nginx + +# create app dirs +mkdir -p /mnt/usb_share /var/www/talia /var/local/talia + +# enable service +systemctl enable talia-wait.service +systemctl start talia-wait.service diff --git a/mini-pc/root/scripts/scan.sh b/mini-pc/root/scripts/scan.sh new file mode 100755 index 0000000..af276cf --- /dev/null +++ b/mini-pc/root/scripts/scan.sh @@ -0,0 +1,33 @@ +#!/bin/bash + +LOCAL_DIR="/var/local/talia/" +WEB_DIR="/var/www/talia/" + +cd $LOCAL_DIR +# hash control +if hashinfo=$(md5sum --check talia-md5sum.txt | egrep 'FAILED$') +then + file_list=$(echo "$hashinfo" | rev | cut -d ":" -f 2- | rev) + for i in $(echo "$file_list") + do + sed -i "s|.*"$i"$|Hash Mismatch "$i"|" talia-md5sum.txt + rm $LOCAL_DIR/"$i" + done +fi + +# av scan +if ! scaninfo=$(clamscan --no-summary --infected --recursive "$LOCAL_DIR") +then + file_list=$(echo "$scaninfo" | cut -d '/' -f 5- | rev | cut -d ':' -f2 | rev) + for i in $(echo "$file_list") + do + sed -i "s|.*"$i"$|Virus Detected "$i"|" talia-md5sum.txt + rm $LOCAL_DIR/"$i" + done +fi + +# mv files to web dir +scan_date=$(date "+%Y%m%d_%H%M%S") +mv $LOCAL_DIR $WEB_DIR/$scan_date +mkdir $LOCAL_DIR +chown -R www-data:www-data $WEB_DIR/$scan_date diff --git a/mini-pc/root/scripts/wait.sh b/mini-pc/root/scripts/wait.sh new file mode 100755 index 0000000..8de3613 --- /dev/null +++ b/mini-pc/root/scripts/wait.sh @@ -0,0 +1,26 @@ +#!/bin/bash + +SERIAL_PORT="/dev/ttyACM0" +USB_MOUNT="/mnt/usb_share/" +LOCAL_DIR="/var/local/talia/" + +while sleep 3 +do + # device is ready + USB_DEV=$(lsblk -ndo PATH,SERIAL | grep "TALIA003512M" | cut -d " " -f 1) + if [ -e "$USB_DEV" ] && [ -c "$SERIAL_PORT" ] + then + mkdir -p "$USB_MOUNT" + mount "$USB_DEV" "$USB_MOUNT" + rsync -a "$USB_MOUNT"talia-sd/ "$LOCAL_DIR" + umount "$USB_MOUNT" + stty -F "$SERIAL_PORT" raw + # send done and wait for disconnect + while [ -e "$USB_DEV" ] && [ -c "$SERIAL_PORT" ] + do + echo "DONE" > "$SERIAL_PORT" + sleep 3 + done + /root/scripts/scan.sh + fi +done diff --git a/raspberry-pi/etc/systemd/system/talia-serial-wait.service b/raspberry-pi/etc/systemd/system/talia-serial-wait.service new file mode 100644 index 0000000..79c143a --- /dev/null +++ b/raspberry-pi/etc/systemd/system/talia-serial-wait.service @@ -0,0 +1,11 @@ +[Unit] +Description=Talia SD Serial Wait Service + +[Service] +Type=exec +ExecStart=/root/scripts/serial-wait.sh +Restart=on-failure +RestartSec=5 + +[Install] +WantedBy=multi-user.target diff --git a/raspberry-pi/etc/systemd/system/talia-wait.service b/raspberry-pi/etc/systemd/system/talia-wait.service new file mode 100644 index 0000000..a0e5ee8 --- /dev/null +++ b/raspberry-pi/etc/systemd/system/talia-wait.service @@ -0,0 +1,10 @@ +[Unit] +Description=Talia SD Wait Service + +[Service] +ExecStart=/root/scripts/wait.sh +Restart=on-failure +RestartSec=60 + +[Install] +WantedBy=multi-user.target diff --git a/raspberry-pi/etc/vsftpd.conf b/raspberry-pi/etc/vsftpd.conf new file mode 100644 index 0000000..008e712 --- /dev/null +++ b/raspberry-pi/etc/vsftpd.conf @@ -0,0 +1,156 @@ +# Example config file /etc/vsftpd.conf +# +# The default compiled in settings are fairly paranoid. This sample file +# loosens things up a bit, to make the ftp daemon more usable. +# Please see vsftpd.conf.5 for all compiled in defaults. +# +# READ THIS: This example file is NOT an exhaustive list of vsftpd options. +# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's +# capabilities. +# +# +# Run standalone? vsftpd can run either from an inetd or as a standalone +# daemon started from an initscript. +listen=NO +# +# This directive enables listening on IPv6 sockets. By default, listening +# on the IPv6 "any" address (::) will accept connections from both IPv6 +# and IPv4 clients. It is not necessary to listen on *both* IPv4 and IPv6 +# sockets. If you want that (perhaps because you want to listen on specific +# addresses) then you must run two copies of vsftpd with two configuration +# files. +listen_ipv6=YES +# +# Allow anonymous FTP? (Disabled by default). +anonymous_enable=NO +# +# Uncomment this to allow local users to log in. +local_enable=YES +# +# Uncomment this to enable any form of FTP write command. +# talia +write_enable=YES +# +# Default umask for local users is 077. You may wish to change this to 022, +# if your users expect that (022 is used by most other ftpd's) +#local_umask=022 +# +# Uncomment this to allow the anonymous FTP user to upload files. This only +# has an effect if the above global write enable is activated. Also, you will +# obviously need to create a directory writable by the FTP user. +#anon_upload_enable=YES +# +# Uncomment this if you want the anonymous FTP user to be able to create +# new directories. +#anon_mkdir_write_enable=YES +# +# Activate directory messages - messages given to remote users when they +# go into a certain directory. +dirmessage_enable=YES +# +# If enabled, vsftpd will display directory listings with the time +# in your local time zone. The default is to display GMT. The +# times returned by the MDTM FTP command are also affected by this +# option. +use_localtime=YES +# +# Activate logging of uploads/downloads. +xferlog_enable=YES +# +# Make sure PORT transfer connections originate from port 20 (ftp-data). +connect_from_port_20=YES +# +# If you want, you can arrange for uploaded anonymous files to be owned by +# a different user. Note! Using "root" for uploaded files is not +# recommended! +#chown_uploads=YES +#chown_username=whoever +# +# You may override where the log file goes if you like. The default is shown +# below. +#xferlog_file=/var/log/vsftpd.log +# +# If you want, you can have your log file in standard ftpd xferlog format. +# Note that the default log file location is /var/log/xferlog in this case. +#xferlog_std_format=YES +# +# You may change the default value for timing out an idle session. +#idle_session_timeout=600 +# +# You may change the default value for timing out a data connection. +#data_connection_timeout=120 +# +# It is recommended that you define on your system a unique user which the +# ftp server can use as a totally isolated and unprivileged user. +#nopriv_user=ftpsecure +# +# Enable this and the server will recognise asynchronous ABOR requests. Not +# recommended for security (the code is non-trivial). Not enabling it, +# however, may confuse older FTP clients. +#async_abor_enable=YES +# +# By default the server will pretend to allow ASCII mode but in fact ignore +# the request. Turn on the below options to have the server actually do ASCII +# mangling on files when in ASCII mode. +# Beware that on some FTP servers, ASCII support allows a denial of service +# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd +# predicted this attack and has always been safe, reporting the size of the +# raw file. +# ASCII mangling is a horrible feature of the protocol. +#ascii_upload_enable=YES +#ascii_download_enable=YES +# +# You may fully customise the login banner string: +#ftpd_banner=Welcome to blah FTP service. +# +# You may specify a file of disallowed anonymous e-mail addresses. Apparently +# useful for combatting certain DoS attacks. +#deny_email_enable=YES +# (default follows) +#banned_email_file=/etc/vsftpd.banned_emails +# +# You may restrict local users to their home directories. See the FAQ for +# the possible risks in this before using chroot_local_user or +# chroot_list_enable below. +#chroot_local_user=YES +# +# You may specify an explicit list of local users to chroot() to their home +# directory. If chroot_local_user is YES, then this list becomes a list of +# users to NOT chroot(). +# (Warning! chroot'ing can be very dangerous. If using chroot, make sure that +# the user does not have write access to the top level directory within the +# chroot) +#chroot_local_user=YES +#chroot_list_enable=YES +# (default follows) +#chroot_list_file=/etc/vsftpd.chroot_list +# +# You may activate the "-R" option to the builtin ls. This is disabled by +# default to avoid remote users being able to cause excessive I/O on large +# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume +# the presence of the "-R" option, so there is a strong case for enabling it. +#ls_recurse_enable=YES +# +# Customization +# +# Some of vsftpd's settings don't fit the filesystem layout by +# default. +# +# This option should be the name of a directory which is empty. Also, the +# directory should not be writable by the ftp user. This directory is used +# as a secure chroot() jail at times vsftpd does not require filesystem +# access. +secure_chroot_dir=/var/run/vsftpd/empty +# +# This string is the name of the PAM service vsftpd will use. +pam_service_name=vsftpd +# +# This option specifies the location of the RSA certificate to use for SSL +# encrypted connections. +rsa_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem +rsa_private_key_file=/etc/ssl/private/ssl-cert-snakeoil.key +ssl_enable=NO + +# +# Uncomment this to indicate that vsftpd use a utf8 filesystem. +#utf8_filesystem=YES diff --git a/raspberry-pi/readme b/raspberry-pi/readme new file mode 100644 index 0000000..bc9de9a --- /dev/null +++ b/raspberry-pi/readme @@ -0,0 +1,20 @@ +# install raspberry-pi os +# debian 13 trixie +# https://www.raspberrypi.com/documentation/computers/getting-started.html#imager-install + +# pi as usb storage +echo '# Enable USB OTG +dtoverlay=dwc2' >> /boot/firmware/config.txt +echo 'dwc2 +g_mass_storage' > /etc/modules-load.d/talia.conf + +dd if=/dev/zero of=/usb_share.img bs=1M count=8192 +mkfs.ext4 /usb_share.img +mkdir /mnt/usb_share + +# packages +apt install vsftpd inotify-tools + +# enable service +systemctl enable talia-wait.service +systemctl start talia-wait.service diff --git a/raspberry-pi/root/scripts/expose_usb.sh b/raspberry-pi/root/scripts/expose_usb.sh new file mode 100755 index 0000000..377d9df --- /dev/null +++ b/raspberry-pi/root/scripts/expose_usb.sh @@ -0,0 +1,35 @@ +#!/bin/bash +modprobe libcomposite +cd /sys/kernel/config/usb_gadget/ +mkdir -p g1 && cd g1 + +# Standard USB descriptors +echo 0x1d6b > idVendor +echo 0x0104 > idProduct +echo 0x0100 > bcdDevice +echo 0x0200 > bcdUSB + +mkdir -p strings/0x409 +echo "TALIA003512M" > strings/0x409/serialnumber +echo "Debian" > strings/0x409/manufacturer +echo "EmulatedDrive" > strings/0x409/product + +mkdir -p configs/c.1/strings/0x409 +echo "Storage and Serial" > configs/c.1/strings/0x409/configuration +echo 500 > configs/c.1/MaxPower + +mkdir -p functions/mass_storage.usb0 +echo 1 > functions/mass_storage.usb0/stall +echo 1 > functions/mass_storage.usb0/lun.0/removable +# CRITICAL: Forces target PC to treat it as Read-Only +echo 1 > functions/mass_storage.usb0/lun.0/ro + +echo /usb_share.img > functions/mass_storage.usb0/lun.0/file +ln -sf functions/mass_storage.usb0 configs/c.1/ + +# Serial connection +mkdir -p functions/acm.usb0 +ln -sf functions/acm.usb0 configs/c.1/ + +# Bind to the physical controller to make it appear on the reading PC +echo $(ls /sys/class/udc/) > UDC diff --git a/raspberry-pi/root/scripts/serial-wait.sh b/raspberry-pi/root/scripts/serial-wait.sh new file mode 100755 index 0000000..7a88e3d --- /dev/null +++ b/raspberry-pi/root/scripts/serial-wait.sh @@ -0,0 +1,18 @@ +#!/bin/bash + +SERIAL_PORT="/dev/ttyGS0" +stty -F "$SERIAL_PORT" raw + +while true +do + if read -r line < "$SERIAL_PORT" + then + # wait for done message + if [ "$line" = "DONE" ] + then + echo "" > /sys/kernel/config/usb_gadget/g1/UDC + exit + fi + fi + sleep 0.5 +done diff --git a/raspberry-pi/root/scripts/wait.sh b/raspberry-pi/root/scripts/wait.sh new file mode 100755 index 0000000..0f93b26 --- /dev/null +++ b/raspberry-pi/root/scripts/wait.sh @@ -0,0 +1,45 @@ +#!/bin/bash + +SERIAL_PORT="/dev/ttyGS0" +USB_FILE="/usb_share.img" +USB_MOUNT="/mnt/usb_share/" +LOCAL_DIR="/var/local/talia/" +FTP_DIR="/home/birikim/out/" + +while sleep 3 +do + if [ -z "$(cat /sys/kernel/config/usb_gadget/g1/UDC)" ] && \ + [ -n "$(ls -A $FTP_DIR)" ] + then + mount $USB_FILE $USB_MOUNT + rm -rf $USB_MOUNT/talia-sd + mkdir $USB_MOUNT/talia-sd + + # wait writes to be completed + while inotifywait -t 60 -r -e close_write -e moved_to "$FTP_DIR" + do + true + done + + # lock dir and mv files to USB storage + chown -R root:root $FTP_DIR + cd $FTP_DIR + for i in $(ls -A $FTP_DIR) + do + mv "$i" $USB_MOUNT/talia-sd/ + done + chown -R birikim:birikim $FTP_DIR + cd $USB_MOUNT/talia-sd/ + # md5sum + find -type f -exec md5sum {} \; > /tmp/talia-md5sum.txt + sed -i "s/.\///" /tmp/talia-md5sum.txt + cd /tmp + mv talia-md5sum.txt $USB_MOUNT/talia-sd/ + umount $USB_MOUNT + + # expose USB storage + /root/scripts/expose_usb.sh + # wait serial + systemctl start talia-serial-wait.service + fi +done