#!/bin/sh # aldermon-setup.sh - one-shot privileged setup for aldermon (run once as # root; idempotent, re-running overwrites installed files): # # 1. RAPL watts: energy_uj is 0400 root-only. Installs a udev rule + RUN # helper chgrp'ing it 0440 to group `adm` so the TUI reads watts # unprivileged. # 2. VID: opening /dev/cpu/N/msr must pass TWO gates: the DAC file-mode # check (node is 0600 root:root — CAP_SYS_RAWIO does NOT override DAC), # then msr_open()'s capable(CAP_SYS_RAWIO). So: udev puts the nodes at # 0440 group `adm` (gate 1), and cap_sys_rawio+ep goes on the minimal # read-only helper aldermon-msr (gate 2, reads only 0x198). Neither # alone works; the app itself never holds the capability. # # doas ./aldermon-setup.sh (from the source tree) # doas /usr/share/aldermon/aldermon-setup.sh (after make install) set -eu PREFIX=${PREFIX:-/usr/local} MSRBIN=$PREFIX/bin/aldermon-msr HELPER=$PREFIX/sbin/aldermon-powercap-chmod RULE=/etc/udev/rules.d/60-aldermon-powercap.rules # Helper: relax energy_uj to 0440, group adm, on every powercap dir. cat > "$HELPER" <<'EOF' #!/bin/sh for d in /sys/class/powercap/intel-rapl*; do [ -e "$d/energy_uj" ] && chgrp adm "$d/energy_uj" && chmod 0440 "$d/energy_uj" done exit 0 EOF chmod 0755 "$HELPER" # RUN+= (not MODE=/GROUP=) - powercap has no devnode, so udev's standard # MODE/GROUP assignment doesn't apply; we chmod in-process instead. cat > "$RULE" < "$MSRRULE" <<'EOF' KERNEL=="msr[0-9]*", SUBSYSTEM=="msr", MODE="0440", GROUP="adm" EOF udevadm control --reload-rules udevadm trigger --subsystem-match=msr # VID gate 2: hand the capability to the helper only. Fail loudly if it's # missing — without the cap the helper is inert and the TUI shows "VID n/a". if [ -x "$MSRBIN" ]; then setcap cap_sys_rawio+ep "$MSRBIN" echo " setcap cap_sys_rawio+ep $MSRBIN" else echo "aldermon-setup: $MSRBIN not found - run 'doas make install' first," >&2 echo " or use aldermon --vid under root." >&2 exit 1 fi echo "Installed:" echo " $HELPER" echo " $RULE" echo " $MSRRULE" echo "Add yourself to adm if not already: doas usermod -aG adm \$USER"