#!/usr/bin/env bash # Required on every host: tool availability does not enable packet capture. set -euo pipefail [[ $# == 0 ]] || { echo 'usage: install-diagnostics.sh (no environment switches)' >&2; exit 2; } [[ $EUID == 0 ]] || { echo 'diagnostic package installation requires root' >&2; exit 1; } for command in apt-get awk; do command -v "$command" >/dev/null || { echo "required installer command missing: $command" >&2; exit 1; } done # Noninteractive package defaults do not add users to the wireshark group or # grant capture capabilities. Existing operator capture permissions are retained. export DEBIAN_FRONTEND=noninteractive apt-get update apt-get install -y --no-install-recommends tcpdump tshark for command in tcpdump tshark; do command -v "$command" >/dev/null || { echo "installed diagnostic command missing: $command" >&2; exit 1; } done tcpdump_version=$(tcpdump --version) tshark_version=$(tshark --version) printf '%s\n%s\n' "${tcpdump_version%%$'\n'*}" "${tshark_version%%$'\n'*}" protocols=$(tshark -G protocols) if ! awk -F '\t' '$3 == "sip" {sip=1} $3 == "rtp" {rtp=1} END {exit !(sip && rtp)}' <<< "$protocols"; then echo 'installed tshark lacks SIP/RTP dissectors' >&2 exit 1 fi printf 'tcpdump and tshark installed; SIP/RTP decoders verified; capture remains opt-in\n'