Files
pi-pm3/systemd

Dangerous Pi Systemd Service

This directory contains systemd service files and installation scripts for running Dangerous Pi as a system service.

Files

  • dangerous-pi.service - Main systemd service unit file
  • dangerous-pi.env.example - Environment configuration template
  • install-service.sh - Installation script
  • uninstall-service.sh - Uninstallation script

Installation

Automated Installation

Run the installation script as root:

cd /path/to/dangerous-pi/systemd
sudo ./install-service.sh

This will:

  1. Copy the service file to /etc/systemd/system/
  2. Create the environment configuration file at /opt/dangerous-pi/.env
  3. Create data and logs directories
  4. Add the pi user to required hardware access groups
  5. Enable the service to start on boot

Manual Installation

If you prefer to install manually:

# Copy service file
sudo cp dangerous-pi.service /etc/systemd/system/

# Copy environment template
sudo cp dangerous-pi.env.example /opt/dangerous-pi/.env

# Create directories
sudo mkdir -p /opt/dangerous-pi/data /opt/dangerous-pi/logs
sudo chown -R pi:pi /opt/dangerous-pi/data /opt/dangerous-pi/logs

# Add pi user to groups
sudo usermod -a -G i2c,bluetooth,gpio,dialout pi

# Reload systemd and enable service
sudo systemctl daemon-reload
sudo systemctl enable dangerous-pi

Configuration

Edit the environment file to customize your installation:

sudo nano /opt/dangerous-pi/.env

Available configuration options:

  • PM3_DEVICE - Proxmark3 device path (default: /dev/ttyACM0)
  • PM3_TIMEOUT - PM3 command timeout in seconds
  • SESSION_TIMEOUT - User session timeout in seconds
  • HOST - Server bind address (default: 0.0.0.0)
  • PORT - Server port (default: 8000)
  • GITHUB_REPO - GitHub repository for updates
  • UPS_I2C_ADDRESS - I2C address for UPS HAT
  • BLE_ENABLED - Enable/disable BLE notifications
  • AUTH_ENABLED - Enable/disable authentication
  • See dangerous-pi.env.example for all options

Service Management

Start the service

sudo systemctl start dangerous-pi

Stop the service

sudo systemctl stop dangerous-pi

Restart the service

sudo systemctl restart dangerous-pi

Check service status

sudo systemctl status dangerous-pi

View service logs

# View recent logs
sudo journalctl -u dangerous-pi

# Follow logs in real-time
sudo journalctl -u dangerous-pi -f

# View logs since boot
sudo journalctl -u dangerous-pi -b

Enable service (start on boot)

sudo systemctl enable dangerous-pi

Disable service (don't start on boot)

sudo systemctl disable dangerous-pi

Uninstallation

Run the uninstallation script as root:

cd /path/to/dangerous-pi/systemd
sudo ./uninstall-service.sh

This will:

  1. Stop the service if running
  2. Disable the service
  3. Remove the service unit file
  4. Reload systemd daemon

Note: Application files in /opt/dangerous-pi are NOT removed automatically.

Security Features

The service includes security hardening:

  • Runs as non-root user (pi)
  • Private /tmp directory
  • Protected system directories
  • Read-only application directory (except for data and logs)
  • Resource limits (memory, CPU, file descriptors)
  • No new privileges allowed

Hardware Access

The service is configured to access the following hardware:

  • I2C devices (for UPS HAT) via i2c group
  • Bluetooth (for BLE notifications) via bluetooth group
  • GPIO pins via gpio group
  • Serial devices (for Proxmark3) via dialout group

Troubleshooting

Service fails to start

Check the logs for errors:

sudo journalctl -u dangerous-pi -n 50

Permission denied errors

Ensure the pi user is in the required groups:

groups pi

Should include: i2c, bluetooth, gpio, dialout

Port already in use

The default port (8000) conflicts with ttyd-bash from pi-pm3. See the main README for resolution options.

Can't access Proxmark3

Ensure the PM3 device path is correct in /opt/dangerous-pi/.env:

PM3_DEVICE=/dev/ttyACM0

Check that the device exists:

ls -l /dev/ttyACM*

Advanced Configuration

Custom Installation Directory

To use a different installation directory, edit the service file before installation:

WorkingDirectory=/your/custom/path
ReadWritePaths=/your/custom/path/data /your/custom/path/logs

Different User/Group

To run as a different user, edit the service file:

User=your-user
Group=your-group

Don't forget to add the user to required hardware groups.

Resource Limits

Adjust resource limits in the service file:

MemoryMax=1G           # Maximum memory
CPUQuota=100%          # CPU usage limit
LimitNOFILE=131072     # Max open files

Integration with pi-pm3

When running alongside the existing pi-pm3 setup:

  1. Port Conflict: Port 8000 is used by ttyd-bash. Options:

    • Change Dangerous Pi port in .env: PORT=8001
    • Disable ttyd-bash: sudo systemctl disable ttyd-bash
  2. RaspAP Compatibility: Dangerous Pi WiFi manager can coexist with RaspAP or replace it.

  3. PM3 Access: Only one service should access PM3 at a time. Disable ttyd-pm3 if using Dangerous Pi's PM3 interface.