Add Dangerous Pi MVP implementation - complete backend and system integration
This commit adds the complete Dangerous Pi web management interface with all MVP features implemented and tested locally. ## New Features ### Backend (Python + FastAPI) - Complete FastAPI backend with async support - 40+ API endpoints (Health, PM3, WiFi, Updates, UPS, BLE, Plugins) - 6 managers: Session, WiFi, Update, UPS, BLE, Plugin - SQLite database with sessions, config, history, crash reports - Server-Sent Events (SSE) for real-time notifications - Mock PM3 worker for development without hardware ### WiFi Manager - Interface detection (USB vs built-in) - Network scanning with signal strength - Mode switching (AP/Client/Dual/Auto/Off) - Network connection with password support - Hidden SSID and saved networks support - Static IP and DHCP configuration - 10 WiFi API endpoints ### Update Manager - GitHub releases API integration - Automatic periodic update checks - Semantic version comparison - Update download with progress tracking - SHA256 checksum verification - Automatic installation with backup and rollback - PM3 client rebuild after updates - 6 Update API endpoints ### UPS Manager - I2C battery monitoring (MAX17040-compatible) - Battery percentage, voltage, current tracking - Power source detection (AC/Battery) - Safe shutdown triggers at configurable thresholds - Event callbacks for battery warnings - SSE and BLE notification integration - 3 UPS API endpoints ### BLE Manager - Bluetooth Low Energy notification support - Auto-detects BLE capability - Multiple notification types (updates, battery, shutdown, etc.) - BLE advertising management - Device connection tracking - 4 BLE API endpoints ### Plugin Framework - Dynamic plugin loading/unloading - Plugin lifecycle management (load, enable, disable, unload) - Hook system for extensibility - JSON-based metadata - Example "Hello World" plugin included - 7 Plugin API endpoints ### Frontend (Remix.js + React) - Cyberpunk-themed responsive UI - Dashboard with system status - PM3 command interface with history - Settings page with WiFi and Update management - Command logs viewer - Theme toggle (Dark/Light/Auto) - Server-side rendering (SSR) - Mobile-first responsive design ### System Integration - Systemd service with security hardening - Automated install/uninstall scripts - Environment configuration template - Hardware access groups (i2c, bluetooth, gpio, dialout) - Pi-gen stage 04 integration for OS image building - Port conflict resolution with ttyd-bash - I2C interface auto-enable for UPS HAT ### Testing - test_backend.py - Backend API tests - test_ups.py - UPS manager tests - test_ble.py - BLE manager tests - test_plugins.py - Plugin manager tests - All tests passing locally ### Documentation - 12 comprehensive documentation files - claude.md - AI development guide - WIFI_MANAGER.md - WiFi management guide - UPDATE_MANAGER.md - Update system guide - PORT_CONFLICT.md - Port conflict resolution guide - MVP_COMPLETE.md - MVP implementation summary - PROJECT_STATUS.md - Project status and roadmap - systemd/README.md - Service management docs - pi-gen integration documentation ## Technical Details - ~5,000+ lines of backend code - 11 Python dependencies (smbus2 added for UPS) - FastAPI with async/await throughout - Type hints and docstrings on all functions - RESTful API design with SSE for notifications - Security hardening (non-root, protected dirs, resource limits) ## Next Steps - Deploy to Raspberry Pi Zero 2 W hardware - Test with real Proxmark3 device - Test UPS HAT integration - Test BLE on Pi hardware - Build custom OS image with pi-gen - Performance optimization for Pi Zero 2 W 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
235
systemd/README.md
Normal file
235
systemd/README.md
Normal file
@@ -0,0 +1,235 @@
|
||||
# Dangerous Pi Systemd Service
|
||||
|
||||
This directory contains systemd service files and installation scripts for running Dangerous Pi as a system service.
|
||||
|
||||
## Files
|
||||
|
||||
- `dangerous-pi.service` - Main systemd service unit file
|
||||
- `dangerous-pi.env.example` - Environment configuration template
|
||||
- `install-service.sh` - Installation script
|
||||
- `uninstall-service.sh` - Uninstallation script
|
||||
|
||||
## Installation
|
||||
|
||||
### Automated Installation
|
||||
|
||||
Run the installation script as root:
|
||||
|
||||
```bash
|
||||
cd /path/to/dangerous-pi/systemd
|
||||
sudo ./install-service.sh
|
||||
```
|
||||
|
||||
This will:
|
||||
1. Copy the service file to `/etc/systemd/system/`
|
||||
2. Create the environment configuration file at `/opt/dangerous-pi/.env`
|
||||
3. Create data and logs directories
|
||||
4. Add the `pi` user to required hardware access groups
|
||||
5. Enable the service to start on boot
|
||||
|
||||
### Manual Installation
|
||||
|
||||
If you prefer to install manually:
|
||||
|
||||
```bash
|
||||
# Copy service file
|
||||
sudo cp dangerous-pi.service /etc/systemd/system/
|
||||
|
||||
# Copy environment template
|
||||
sudo cp dangerous-pi.env.example /opt/dangerous-pi/.env
|
||||
|
||||
# Create directories
|
||||
sudo mkdir -p /opt/dangerous-pi/data /opt/dangerous-pi/logs
|
||||
sudo chown -R pi:pi /opt/dangerous-pi/data /opt/dangerous-pi/logs
|
||||
|
||||
# Add pi user to groups
|
||||
sudo usermod -a -G i2c,bluetooth,gpio,dialout pi
|
||||
|
||||
# Reload systemd and enable service
|
||||
sudo systemctl daemon-reload
|
||||
sudo systemctl enable dangerous-pi
|
||||
```
|
||||
|
||||
## Configuration
|
||||
|
||||
Edit the environment file to customize your installation:
|
||||
|
||||
```bash
|
||||
sudo nano /opt/dangerous-pi/.env
|
||||
```
|
||||
|
||||
Available configuration options:
|
||||
- `PM3_DEVICE` - Proxmark3 device path (default: `/dev/ttyACM0`)
|
||||
- `PM3_TIMEOUT` - PM3 command timeout in seconds
|
||||
- `SESSION_TIMEOUT` - User session timeout in seconds
|
||||
- `HOST` - Server bind address (default: `0.0.0.0`)
|
||||
- `PORT` - Server port (default: `8000`)
|
||||
- `GITHUB_REPO` - GitHub repository for updates
|
||||
- `UPS_I2C_ADDRESS` - I2C address for UPS HAT
|
||||
- `BLE_ENABLED` - Enable/disable BLE notifications
|
||||
- `AUTH_ENABLED` - Enable/disable authentication
|
||||
- See `dangerous-pi.env.example` for all options
|
||||
|
||||
## Service Management
|
||||
|
||||
### Start the service
|
||||
|
||||
```bash
|
||||
sudo systemctl start dangerous-pi
|
||||
```
|
||||
|
||||
### Stop the service
|
||||
|
||||
```bash
|
||||
sudo systemctl stop dangerous-pi
|
||||
```
|
||||
|
||||
### Restart the service
|
||||
|
||||
```bash
|
||||
sudo systemctl restart dangerous-pi
|
||||
```
|
||||
|
||||
### Check service status
|
||||
|
||||
```bash
|
||||
sudo systemctl status dangerous-pi
|
||||
```
|
||||
|
||||
### View service logs
|
||||
|
||||
```bash
|
||||
# View recent logs
|
||||
sudo journalctl -u dangerous-pi
|
||||
|
||||
# Follow logs in real-time
|
||||
sudo journalctl -u dangerous-pi -f
|
||||
|
||||
# View logs since boot
|
||||
sudo journalctl -u dangerous-pi -b
|
||||
```
|
||||
|
||||
### Enable service (start on boot)
|
||||
|
||||
```bash
|
||||
sudo systemctl enable dangerous-pi
|
||||
```
|
||||
|
||||
### Disable service (don't start on boot)
|
||||
|
||||
```bash
|
||||
sudo systemctl disable dangerous-pi
|
||||
```
|
||||
|
||||
## Uninstallation
|
||||
|
||||
Run the uninstallation script as root:
|
||||
|
||||
```bash
|
||||
cd /path/to/dangerous-pi/systemd
|
||||
sudo ./uninstall-service.sh
|
||||
```
|
||||
|
||||
This will:
|
||||
1. Stop the service if running
|
||||
2. Disable the service
|
||||
3. Remove the service unit file
|
||||
4. Reload systemd daemon
|
||||
|
||||
Note: Application files in `/opt/dangerous-pi` are NOT removed automatically.
|
||||
|
||||
## Security Features
|
||||
|
||||
The service includes security hardening:
|
||||
- Runs as non-root user (`pi`)
|
||||
- Private `/tmp` directory
|
||||
- Protected system directories
|
||||
- Read-only application directory (except for `data` and `logs`)
|
||||
- Resource limits (memory, CPU, file descriptors)
|
||||
- No new privileges allowed
|
||||
|
||||
## Hardware Access
|
||||
|
||||
The service is configured to access the following hardware:
|
||||
- I2C devices (for UPS HAT) via `i2c` group
|
||||
- Bluetooth (for BLE notifications) via `bluetooth` group
|
||||
- GPIO pins via `gpio` group
|
||||
- Serial devices (for Proxmark3) via `dialout` group
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Service fails to start
|
||||
|
||||
Check the logs for errors:
|
||||
```bash
|
||||
sudo journalctl -u dangerous-pi -n 50
|
||||
```
|
||||
|
||||
### Permission denied errors
|
||||
|
||||
Ensure the `pi` user is in the required groups:
|
||||
```bash
|
||||
groups pi
|
||||
```
|
||||
|
||||
Should include: `i2c`, `bluetooth`, `gpio`, `dialout`
|
||||
|
||||
### Port already in use
|
||||
|
||||
The default port (8000) conflicts with ttyd-bash from pi-pm3. See the main README for resolution options.
|
||||
|
||||
### Can't access Proxmark3
|
||||
|
||||
Ensure the PM3 device path is correct in `/opt/dangerous-pi/.env`:
|
||||
```bash
|
||||
PM3_DEVICE=/dev/ttyACM0
|
||||
```
|
||||
|
||||
Check that the device exists:
|
||||
```bash
|
||||
ls -l /dev/ttyACM*
|
||||
```
|
||||
|
||||
## Advanced Configuration
|
||||
|
||||
### Custom Installation Directory
|
||||
|
||||
To use a different installation directory, edit the service file before installation:
|
||||
|
||||
```bash
|
||||
WorkingDirectory=/your/custom/path
|
||||
ReadWritePaths=/your/custom/path/data /your/custom/path/logs
|
||||
```
|
||||
|
||||
### Different User/Group
|
||||
|
||||
To run as a different user, edit the service file:
|
||||
|
||||
```bash
|
||||
User=your-user
|
||||
Group=your-group
|
||||
```
|
||||
|
||||
Don't forget to add the user to required hardware groups.
|
||||
|
||||
### Resource Limits
|
||||
|
||||
Adjust resource limits in the service file:
|
||||
|
||||
```bash
|
||||
MemoryMax=1G # Maximum memory
|
||||
CPUQuota=100% # CPU usage limit
|
||||
LimitNOFILE=131072 # Max open files
|
||||
```
|
||||
|
||||
## Integration with pi-pm3
|
||||
|
||||
When running alongside the existing pi-pm3 setup:
|
||||
|
||||
1. **Port Conflict**: Port 8000 is used by ttyd-bash. Options:
|
||||
- Change Dangerous Pi port in `.env`: `PORT=8001`
|
||||
- Disable ttyd-bash: `sudo systemctl disable ttyd-bash`
|
||||
|
||||
2. **RaspAP Compatibility**: Dangerous Pi WiFi manager can coexist with RaspAP or replace it.
|
||||
|
||||
3. **PM3 Access**: Only one service should access PM3 at a time. Disable ttyd-pm3 if using Dangerous Pi's PM3 interface.
|
||||
34
systemd/dangerous-pi.env.example
Normal file
34
systemd/dangerous-pi.env.example
Normal file
@@ -0,0 +1,34 @@
|
||||
# Dangerous Pi Environment Configuration
|
||||
# Copy this file to /opt/dangerous-pi/.env and customize as needed
|
||||
|
||||
# PM3 Configuration
|
||||
PM3_DEVICE=/dev/ttyACM0
|
||||
PM3_TIMEOUT=30
|
||||
|
||||
# Session Configuration
|
||||
SESSION_TIMEOUT=300
|
||||
|
||||
# Server Configuration
|
||||
HOST=0.0.0.0
|
||||
PORT=8000
|
||||
VERSION=1.0.0
|
||||
|
||||
# Update Configuration
|
||||
GITHUB_REPO=yourusername/dangerous-pi
|
||||
UPDATE_CHECK_INTERVAL=3600
|
||||
|
||||
# Wi-Fi Configuration
|
||||
WLAN_INTERFACE=wlan0
|
||||
USB_WLAN_INTERFACE=wlan1
|
||||
|
||||
# UPS Configuration
|
||||
UPS_I2C_ADDRESS=0x36
|
||||
UPS_CHECK_INTERVAL=60
|
||||
|
||||
# BLE Configuration
|
||||
BLE_ENABLED=true
|
||||
BLE_DEVICE_NAME=DangerousPi
|
||||
|
||||
# Security
|
||||
AUTH_ENABLED=false
|
||||
HTTPS_ENABLED=false
|
||||
50
systemd/dangerous-pi.service
Normal file
50
systemd/dangerous-pi.service
Normal file
@@ -0,0 +1,50 @@
|
||||
[Unit]
|
||||
Description=Dangerous Pi Backend Service
|
||||
Documentation=https://github.com/yourusername/dangerous-pi
|
||||
After=network.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=pi
|
||||
Group=pi
|
||||
WorkingDirectory=/opt/dangerous-pi
|
||||
Environment="PATH=/usr/local/bin:/usr/bin:/bin"
|
||||
Environment="PYTHONUNBUFFERED=1"
|
||||
EnvironmentFile=-/opt/dangerous-pi/.env
|
||||
|
||||
# Main service command
|
||||
ExecStart=/usr/bin/python3 -m uvicorn app.backend.main:app \
|
||||
--host 0.0.0.0 \
|
||||
--port 8000 \
|
||||
--log-level info
|
||||
|
||||
# Restart policy
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
StartLimitBurst=5
|
||||
StartLimitInterval=60
|
||||
|
||||
# Resource limits
|
||||
LimitNOFILE=65536
|
||||
MemoryMax=512M
|
||||
CPUQuota=80%
|
||||
|
||||
# Security hardening
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
ReadWritePaths=/opt/dangerous-pi/data /opt/dangerous-pi/logs
|
||||
ReadOnlyPaths=/opt/dangerous-pi
|
||||
|
||||
# Allow I2C and Bluetooth access
|
||||
SupplementaryGroups=i2c bluetooth gpio dialout
|
||||
|
||||
# Graceful shutdown
|
||||
TimeoutStopSec=30
|
||||
KillMode=mixed
|
||||
KillSignal=SIGTERM
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
67
systemd/install-service.sh
Executable file
67
systemd/install-service.sh
Executable file
@@ -0,0 +1,67 @@
|
||||
#!/bin/bash
|
||||
# Installation script for Dangerous Pi systemd service
|
||||
|
||||
set -e
|
||||
|
||||
echo "Installing Dangerous Pi systemd service..."
|
||||
|
||||
# Check if running as root
|
||||
if [ "$EUID" -ne 0 ]; then
|
||||
echo "Error: This script must be run as root (use sudo)"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Variables
|
||||
SERVICE_NAME="dangerous-pi"
|
||||
SERVICE_FILE="dangerous-pi.service"
|
||||
INSTALL_DIR="/opt/dangerous-pi"
|
||||
SYSTEMD_DIR="/etc/systemd/system"
|
||||
|
||||
# Create installation directory if it doesn't exist
|
||||
if [ ! -d "$INSTALL_DIR" ]; then
|
||||
echo "Creating installation directory: $INSTALL_DIR"
|
||||
mkdir -p "$INSTALL_DIR"
|
||||
fi
|
||||
|
||||
# Copy service file to systemd directory
|
||||
echo "Installing systemd service unit..."
|
||||
cp "$(dirname "$0")/$SERVICE_FILE" "$SYSTEMD_DIR/"
|
||||
chmod 644 "$SYSTEMD_DIR/$SERVICE_FILE"
|
||||
|
||||
# Create .env file if it doesn't exist
|
||||
if [ ! -f "$INSTALL_DIR/.env" ]; then
|
||||
echo "Creating environment configuration file..."
|
||||
cp "$(dirname "$0")/dangerous-pi.env.example" "$INSTALL_DIR/.env"
|
||||
chown pi:pi "$INSTALL_DIR/.env"
|
||||
chmod 600 "$INSTALL_DIR/.env"
|
||||
echo "NOTE: Please edit $INSTALL_DIR/.env to configure your installation"
|
||||
fi
|
||||
|
||||
# Create data and logs directories
|
||||
echo "Creating data and logs directories..."
|
||||
mkdir -p "$INSTALL_DIR/data"
|
||||
mkdir -p "$INSTALL_DIR/logs"
|
||||
chown -R pi:pi "$INSTALL_DIR/data" "$INSTALL_DIR/logs"
|
||||
chmod 755 "$INSTALL_DIR/data" "$INSTALL_DIR/logs"
|
||||
|
||||
# Add pi user to required groups for hardware access
|
||||
echo "Adding pi user to hardware access groups..."
|
||||
usermod -a -G i2c,bluetooth,gpio,dialout pi || true
|
||||
|
||||
# Reload systemd daemon
|
||||
echo "Reloading systemd daemon..."
|
||||
systemctl daemon-reload
|
||||
|
||||
# Enable service to start on boot
|
||||
echo "Enabling $SERVICE_NAME service..."
|
||||
systemctl enable "$SERVICE_NAME.service"
|
||||
|
||||
echo ""
|
||||
echo "✅ Installation complete!"
|
||||
echo ""
|
||||
echo "Next steps:"
|
||||
echo " 1. Edit configuration: sudo nano $INSTALL_DIR/.env"
|
||||
echo " 2. Start the service: sudo systemctl start $SERVICE_NAME"
|
||||
echo " 3. Check status: sudo systemctl status $SERVICE_NAME"
|
||||
echo " 4. View logs: sudo journalctl -u $SERVICE_NAME -f"
|
||||
echo ""
|
||||
47
systemd/uninstall-service.sh
Executable file
47
systemd/uninstall-service.sh
Executable file
@@ -0,0 +1,47 @@
|
||||
#!/bin/bash
|
||||
# Uninstallation script for Dangerous Pi systemd service
|
||||
|
||||
set -e
|
||||
|
||||
echo "Uninstalling Dangerous Pi systemd service..."
|
||||
|
||||
# Check if running as root
|
||||
if [ "$EUID" -ne 0 ]; then
|
||||
echo "Error: This script must be run as root (use sudo)"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Variables
|
||||
SERVICE_NAME="dangerous-pi"
|
||||
SERVICE_FILE="dangerous-pi.service"
|
||||
SYSTEMD_DIR="/etc/systemd/system"
|
||||
|
||||
# Stop the service if running
|
||||
if systemctl is-active --quiet "$SERVICE_NAME"; then
|
||||
echo "Stopping $SERVICE_NAME service..."
|
||||
systemctl stop "$SERVICE_NAME"
|
||||
fi
|
||||
|
||||
# Disable the service
|
||||
if systemctl is-enabled --quiet "$SERVICE_NAME" 2>/dev/null; then
|
||||
echo "Disabling $SERVICE_NAME service..."
|
||||
systemctl disable "$SERVICE_NAME"
|
||||
fi
|
||||
|
||||
# Remove service file
|
||||
if [ -f "$SYSTEMD_DIR/$SERVICE_FILE" ]; then
|
||||
echo "Removing service unit file..."
|
||||
rm "$SYSTEMD_DIR/$SERVICE_FILE"
|
||||
fi
|
||||
|
||||
# Reload systemd daemon
|
||||
echo "Reloading systemd daemon..."
|
||||
systemctl daemon-reload
|
||||
systemctl reset-failed || true
|
||||
|
||||
echo ""
|
||||
echo "✅ Uninstallation complete!"
|
||||
echo ""
|
||||
echo "Note: Application files in /opt/dangerous-pi were NOT removed."
|
||||
echo "To remove them manually: sudo rm -rf /opt/dangerous-pi"
|
||||
echo ""
|
||||
Reference in New Issue
Block a user