#!/bin/sh # =========================================================================== # get-hwid.sh - print this server's GhostShield HWID, and nothing else. # =========================================================================== # # curl -sL https://bastioncyber.online/get-hwid.sh | sudo bash # # WHAT IT DOES, IN FULL: it reads two files and prints one line. It writes # nothing, installs nothing, contacts nothing. Anyone about to pipe a stranger's # script into a root shell is right to read it first, and the whole point of # this file is that reading it takes ten seconds. # # WHY IT EXISTS: the HWID is the one value a prospect cannot guess, and until # now the only way to see it was to download the 55 MB package, prepare the # kernel and let the installer pause at its prompt. That is a long walk to # reach a form field. This is the same walk in one line. # # THE DERIVATION IS NOT A CONVENIENCE COPY - IT IS THE PRODUCT'S OWN. It must # match `gs_hwid` in license_common.sh and `hwid_local()` in the ghostshield # CLI, character for character. If the three ever diverge, the portal issues a # token for an HWID the installer will not recognise, and the failure lands on # the worst possible person: the customer who already paid, holding a valid # token that the install refuses as `hwid_mismatch`. # # machine-id, trimmed of all whitespace, lower-cased. # /etc/machine-id first; /var/lib/dbus/machine-id if that file is absent. # # `sh` and not `bash`: it has to run on a minimal container image too, and # nothing below is a bashism. # # `sudo` in the published one-liner is belt and braces: /etc/machine-id is # normally world-readable, so this works unprivileged - but a hardened host may # have tightened it, and an unprivileged failure at this step reads to the # visitor like the product is broken. set -eu hwid=$( { cat /etc/machine-id 2>/dev/null || cat /var/lib/dbus/machine-id 2>/dev/null || true; } \ | tr -d '[:space:]' | tr 'A-Z' 'a-z' ) # The empty case is REAL and it is not an error in the script: a container built # from a golden image with the file zeroed has no stable identity yet, and a # licence bound to nothing would be a licence bound to every clone of it. The # host fixes it with `systemd-machine-id-setup`, and it must be said on stderr # so a pipe into a form field never captures the sentence as if it were an HWID. if [ -z "$hwid" ]; then echo "get-hwid: this host has no machine-id yet." >&2 echo "get-hwid: run 'sudo systemd-machine-id-setup' and try again." >&2 exit 1 fi # ONLY the HWID on stdout. Nothing else is printed here, on purpose: this output # is meant to be piped, copied and pasted into a web form, and a friendly # "Your HWID is:" prefix would be pasted along with it and rejected by RE_HWID. printf '%s\n' "$hwid"