#!/usr/bin/env bash # ============================================================================= # 00-preflight — assert the box is what we think it is before changing it. # # This stage NEVER modifies anything. It only reports. Its job is to catch # "the BIOS update reset your settings" before you spend an hour wondering # why Plex will not transcode. # ============================================================================= set -uo pipefail RC=0 note() { printf ' %-34s %s\n' "$1" "$2"; } bad() { printf ' \033[1;31m%-34s %s\033[0m\n' "$1" "$2"; RC=1; } warn() { printf ' \033[1;33m%-34s %s\033[0m\n' "$1" "$2"; } echo "--- identity ---" note "hostname" "$(hostname)" note "kernel" "$(uname -r)" note "ip" "$(hostname -I | tr -s ' ')" echo "--- firmware ---" if [ -d /sys/firmware/efi ]; then note "boot mode" "UEFI"; else bad "boot mode" "LEGACY/BIOS — expected UEFI"; fi # Secure Boot must stay OFF. A BIOS update commonly restores defaults, and the # ASUS default for this board turns Secure Boot back on. With it on, the DKMS # NVIDIA module will not load and there is no keyboard attached to enroll a MOK. if command -v mokutil >/dev/null 2>&1; then SB="$(mokutil --sb-state 2>/dev/null || echo unknown)" case "$SB" in *disabled*) note "secure boot" "disabled (correct)" ;; *enabled*) bad "secure boot" "ENABLED — NVIDIA DKMS will not load. Disable it in BIOS." ;; *) warn "secure boot" "$SB" ;; esac else warn "secure boot" "mokutil not installed; check BIOS manually" fi echo "--- disks ---" # Disk 0 must be the system disk. Disk 1 must still be NTFS and untouched. SYS_SERIAL="$(lsblk -dno SERIAL "$(findmnt -no SOURCE / | sed -E 's/p?[0-9]+$//')" 2>/dev/null | tr -d ' ')" if [ "$SYS_SERIAL" = "1808AE802176" ]; then note "root disk serial" "1808AE802176 (correct)" else bad "root disk serial" "${SYS_SERIAL:-unknown} — expected 1808AE802176" fi DATA_DEV="$(lsblk -dno NAME,SERIAL | awk '$2=="WD-WCC7K3JAEDR3"{print $1}')" if [ -n "$DATA_DEV" ]; then FSTYPES="$(lsblk -no FSTYPE "/dev/$DATA_DEV" | tr -s '\n' ' ')" note "data disk (D:)" "/dev/$DATA_DEV present, fstypes: ${FSTYPES:-none}" if echo "$FSTYPES" | grep -q ntfs; then note "data disk state" "still NTFS — correct, leave it until after soak" else warn "data disk state" "no NTFS found — has it already been converted?" fi if findmnt -rno TARGET -S "/dev/${DATA_DEV}1" >/dev/null 2>&1; then warn "data disk mounted" "D: is mounted; it should not be during the soak" fi else bad "data disk (D:)" "WD-WCC7K3JAEDR3 NOT FOUND" fi echo "--- gpu ---" if lspci -nn | grep -qi 'VGA.*Intel'; then note "iGPU (UHD 630)" "present" else bad "iGPU (UHD 630)" "NOT enumerated — set BIOS: Advanced > System Agent (SA) Configuration > Graphics Configuration > iGPU Multi-Monitor = Enabled" fi if lspci -nn | grep -qi 'NVIDIA'; then note "GTX 1070" "$(lspci -nn | grep -i nvidia | head -1 | cut -c1-70)" else warn "GTX 1070" "not seen on PCI bus" fi if [ -e /dev/dri/renderD128 ]; then note "/dev/dri/renderD128" "present" note "render group gid" "$(stat -c '%g (%G)' /dev/dri/renderD128)" else warn "/dev/dri/renderD128" "missing — Quick Sync unavailable until iGPU is enabled in BIOS" fi echo "--- runtime ---" if command -v docker >/dev/null 2>&1 && docker info >/dev/null 2>&1; then note "docker" "$(docker --version | cut -d, -f1)" else bad "docker" "not running" fi note "media uid/gid" "$(id -u media 2>/dev/null || echo '?'):$(getent group media | cut -d: -f3 2>/dev/null || echo '?')" note "swap" "$(free -h | awk '/Swap:/{print $2}')" echo [ $RC -eq 0 ] && echo " preflight clean" || echo " preflight found problems above" # Preflight never blocks the rest of the bootstrap — it reports. exit 0