/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to Makefile

First version of a somewhat complete D-Bus server interface.  Also
change user/group name to "_mandos".

* debian/mandos.postinst: Rename old "mandos" user and group to
                          "_mandos"; create "_mandos" user and group
                          if none exist.
* debian/mandos-client.postinst: - '' -

* initramfs-tools-hook: Try "_mandos" before "mandos" as user and
                        group name.

* mandos (_datetime_to_dbus_struct): New; was previously local.
  (Client.started): Renamed to "last_started".  All users changed.
  (Client.started): New; boolean.
  (Client.dbus_object_path): New.
  (Client.check_command): Renamed to "checker_command".  All users
                          changed.
  (Client.__init__): Set and use "self.dbus_object_path".  Set
                     "self.started".
  (Client.start): Update "self.started".  Emit "self.PropertyChanged"
                  signals for both "started" and "last_started".
  (Client.stop): Update "self.started".  Emit "self.PropertyChanged"
                 signal for "started".
  (Client.checker_callback): Take additional "command" argument.  All
                             callers changed. Emit
                             "self.PropertyChanged" signal.
  (Client.bump_timeout): Emit "self.PropertyChanged" signal for
                         "last_checked_ok".
  (Client.start_checker): Emit "self.PropertyChanged" signal for
                          "checker_running".
  (Client.stop_checker): Emit "self.PropertyChanged" signal for
                         "checker_running".
  (Client.still_valid): Bug fix: use "getattr(self, started, False)"
                        instead of "self.started" in case this client
                        object is so new that the "started" attribute
                        has not been created yet.
  (Client.IntervalChanged, Client.CheckerIsRunning, Client.GetChecker,
  Client.GetCreated, Client.GetFingerprint, Client.GetHost,
  Client.GetInterval, Client.GetName, Client.GetStarted,
  Client.GetTimeout, Client.StateChanged, Client.TimeoutChanged):
  Removed; all callers changed.
  (Client.CheckerCompleted): Add "condition" and "command" arguments.
                             All callers changed.
  (Client.GetAllProperties, Client.PropertyChanged): New.
  (Client.StillValid): Renamed to "IsStillValid".
  (Client.StartChecker): Changed to its own function to avoid the
                         return value from "Client.start_checker()".
  (Client.Stop): Changed to its own function to avoid the return value
                 from "Client.stop()".
  (main): Try "_mandos" before "mandos" as user and group name.
          Removed inner function "remove_from_clients".  New inner
          class "MandosServer".

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
WARN:=-O -Wall -Wextra -Wdouble-promotion -Wformat=2 -Winit-self \
2
 
        -Wmissing-include-dirs -Wswitch-default -Wswitch-enum \
3
 
        -Wunused -Wuninitialized -Wstrict-overflow=5 \
4
 
        -Wsuggest-attribute=pure -Wsuggest-attribute=const \
5
 
        -Wsuggest-attribute=noreturn -Wfloat-equal -Wundef -Wshadow \
 
1
WARN=-O -Wall -Wformat=2 -Winit-self -Wmissing-include-dirs \
 
2
        -Wswitch-default -Wswitch-enum -Wunused-parameter \
 
3
        -Wstrict-aliasing=2 -Wextra -Wfloat-equal -Wundef -Wshadow \
6
4
        -Wunsafe-loop-optimizations -Wpointer-arith \
7
5
        -Wbad-function-cast -Wcast-qual -Wcast-align -Wwrite-strings \
8
 
        -Wconversion -Wlogical-op -Waggregate-return \
9
 
        -Wstrict-prototypes -Wold-style-definition \
10
 
        -Wmissing-format-attribute -Wnormalized=nfc -Wpacked \
11
 
        -Wredundant-decls -Wnested-externs -Winline -Wvla \
12
 
        -Wvolatile-register-var -Woverlength-strings
13
 
 
14
 
#DEBUG:=-ggdb3 -fsanitize=address $(SANITIZE)
15
 
## Check which sanitizing options can be used
16
 
#SANITIZE:=$(foreach option,$(ALL_SANITIZE_OPTIONS),$(shell \
17
 
#       echo 'int main(){}' | $(CC) --language=c $(option) \
18
 
#       /dev/stdin -o /dev/null >/dev/null 2>&1 && echo $(option)))
19
 
# <https://developerblog.redhat.com/2014/10/16/gcc-undefined-behavior-sanitizer-ubsan/>
20
 
ALL_SANITIZE_OPTIONS:=-fsanitize=leak -fsanitize=undefined \
21
 
        -fsanitize=shift -fsanitize=integer-divide-by-zero \
22
 
        -fsanitize=unreachable -fsanitize=vla-bound -fsanitize=null \
23
 
        -fsanitize=return -fsanitize=signed-integer-overflow \
24
 
        -fsanitize=bounds -fsanitize=alignment \
25
 
        -fsanitize=object-size -fsanitize=float-divide-by-zero \
26
 
        -fsanitize=float-cast-overflow -fsanitize=nonnull-attribute \
27
 
        -fsanitize=returns-nonnull-attribute -fsanitize=bool \
28
 
        -fsanitize=enum -fsanitize-address-use-after-scope
29
 
 
30
 
# For info about _FORTIFY_SOURCE, see feature_test_macros(7)
31
 
# and <https://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>.
32
 
FORTIFY:=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIC
33
 
LINK_FORTIFY_LD:=-z relro -z now
34
 
LINK_FORTIFY:=
35
 
 
36
 
# If BROKEN_PIE is set, do not build with -pie
37
 
ifndef BROKEN_PIE
38
 
FORTIFY += -fPIE
39
 
LINK_FORTIFY += -pie
40
 
endif
 
6
        -Wconversion -Wstrict-prototypes -Wold-style-definition \
 
7
        -Wpacked -Wnested-externs -Winline -Wvolatile-register-var
 
8
#       -Wunreachable-code 
 
9
#DEBUG=-ggdb3
 
10
# For info about _FORTIFY_SOURCE, see
 
11
# <http://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>
 
12
FORTIFY=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIE -pie
 
13
LINK_FORTIFY=-z relro -pie
41
14
#COVERAGE=--coverage
42
 
OPTIMIZE:=-Os -fno-strict-aliasing
43
 
LANGUAGE:=-std=gnu11
44
 
htmldir:=man
45
 
version:=1.8.4
46
 
SED:=sed
47
 
 
48
 
USER:=$(firstword $(subst :, ,$(shell getent passwd _mandos \
49
 
        || getent passwd nobody || echo 65534)))
50
 
GROUP:=$(firstword $(subst :, ,$(shell getent group _mandos \
51
 
        || getent group nogroup || echo 65534)))
 
15
OPTIMIZE=-Os
 
16
LANGUAGE=-std=gnu99
 
17
htmldir=man
 
18
version=1.0.2
 
19
SED=sed
52
20
 
53
21
## Use these settings for a traditional /usr/local install
54
 
# PREFIX:=$(DESTDIR)/usr/local
55
 
# CONFDIR:=$(DESTDIR)/etc/mandos
56
 
# KEYDIR:=$(DESTDIR)/etc/mandos/keys
57
 
# MANDIR:=$(PREFIX)/man
58
 
# INITRAMFSTOOLS:=$(DESTDIR)/etc/initramfs-tools
59
 
# STATEDIR:=$(DESTDIR)/var/lib/mandos
60
 
# LIBDIR:=$(PREFIX)/lib
 
22
# PREFIX=$(DESTDIR)/usr/local
 
23
# CONFDIR=$(DESTDIR)/etc/mandos
 
24
# KEYDIR=$(DESTDIR)/etc/mandos/keys
 
25
# MANDIR=$(PREFIX)/man
 
26
# INITRAMFSTOOLS=$(DESTDIR)/etc/initramfs-tools
61
27
##
62
28
 
63
29
## These settings are for a package-type install
64
 
PREFIX:=$(DESTDIR)/usr
65
 
CONFDIR:=$(DESTDIR)/etc/mandos
66
 
KEYDIR:=$(DESTDIR)/etc/keys/mandos
67
 
MANDIR:=$(PREFIX)/share/man
68
 
INITRAMFSTOOLS:=$(DESTDIR)/usr/share/initramfs-tools
69
 
STATEDIR:=$(DESTDIR)/var/lib/mandos
70
 
LIBDIR:=$(shell \
71
 
        for d in \
72
 
        "/usr/lib/`dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null`" \
73
 
        "`rpm --eval='%{_libdir}' 2>/dev/null`" /usr/lib; do \
74
 
                if [ -d "$$d" -a "$$d" = "$${d%/}" ]; then \
75
 
                        echo "$(DESTDIR)$$d"; \
76
 
                        break; \
77
 
                fi; \
78
 
        done)
 
30
PREFIX=$(DESTDIR)/usr
 
31
CONFDIR=$(DESTDIR)/etc/mandos
 
32
KEYDIR=$(DESTDIR)/etc/keys/mandos
 
33
MANDIR=$(PREFIX)/share/man
 
34
INITRAMFSTOOLS=$(DESTDIR)/usr/share/initramfs-tools
79
35
##
80
36
 
81
 
SYSTEMD:=$(DESTDIR)$(shell pkg-config systemd --variable=systemdsystemunitdir)
82
 
TMPFILES:=$(DESTDIR)$(shell pkg-config systemd --variable=tmpfilesdir)
83
 
 
84
 
GNUTLS_CFLAGS:=$(shell pkg-config --cflags-only-I gnutls)
85
 
GNUTLS_LIBS:=$(shell pkg-config --libs gnutls)
86
 
AVAHI_CFLAGS:=$(shell pkg-config --cflags-only-I avahi-core)
87
 
AVAHI_LIBS:=$(shell pkg-config --libs avahi-core)
88
 
GPGME_CFLAGS:=$(shell gpgme-config --cflags; getconf LFS_CFLAGS)
89
 
GPGME_LIBS:=$(shell gpgme-config --libs; getconf LFS_LIBS; \
90
 
        getconf LFS_LDFLAGS)
91
 
LIBNL3_CFLAGS:=$(shell pkg-config --cflags-only-I libnl-route-3.0)
92
 
LIBNL3_LIBS:=$(shell pkg-config --libs libnl-route-3.0)
 
37
GNUTLS_CFLAGS=$(shell libgnutls-config --cflags)
 
38
GNUTLS_LIBS=$(shell libgnutls-config --libs)
 
39
AVAHI_CFLAGS=$(shell pkg-config --cflags-only-I avahi-core)
 
40
AVAHI_LIBS=$(shell pkg-config --libs avahi-core)
 
41
GPGME_CFLAGS=$(shell gpgme-config --cflags)
 
42
GPGME_LIBS=$(shell gpgme-config --libs)
93
43
 
94
44
# Do not change these two
95
 
CFLAGS+=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) \
96
 
        $(OPTIMIZE) $(LANGUAGE) -DVERSION='"$(version)"'
97
 
LDFLAGS+=-Xlinker --as-needed $(COVERAGE) $(LINK_FORTIFY) $(strip \
98
 
        ) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
 
45
CFLAGS=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
 
46
        $(LANGUAGE) $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(GPGME_CFLAGS) \
 
47
        -DVERSION='"$(version)"'
 
48
LDFLAGS=$(COVERAGE) $(LINK_FORTIFY)
99
49
 
100
50
# Commands to format a DocBook <refentry> document into a manual page
101
 
DOCBOOKTOMAN=$(strip cd $(dir $<); xsltproc --nonet --xinclude \
 
51
DOCBOOKTOMAN=cd $(dir $<); xsltproc --nonet --xinclude \
102
52
        --param man.charmap.use.subset          0 \
103
53
        --param make.year.ranges                1 \
104
54
        --param make.single.year.ranges         1 \
105
55
        --param man.output.quietly              1 \
106
56
        --param man.authors.section.enabled     0 \
107
 
        /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
 
57
         /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
108
58
        $(notdir $<); \
109
 
        if locale --all 2>/dev/null | grep --regexp='^en_US\.utf8$$' \
110
 
        && type man 2>/dev/null; then LANG=en_US.UTF-8 MANWIDTH=80 \
111
 
        man --warnings --encoding=UTF-8 --local-file $(notdir $@); \
112
 
        fi >/dev/null)
 
59
        $(MANPOST) $(notdir $@)
 
60
# DocBook-to-man post-processing to fix a '\n' escape bug
 
61
MANPOST=$(SED) --in-place --expression='s,\\\\en,\\en,g;s,\\n,\\en,g'
113
62
 
114
 
DOCBOOKTOHTML=$(strip xsltproc --nonet --xinclude \
 
63
DOCBOOKTOHTML=xsltproc --nonet --xinclude \
115
64
        --param make.year.ranges                1 \
116
65
        --param make.single.year.ranges         1 \
117
66
        --param man.output.quietly              1 \
119
68
        --param citerefentry.link               1 \
120
69
        --output $@ \
121
70
        /usr/share/xml/docbook/stylesheet/nwalsh/xhtml/docbook.xsl \
122
 
        $<; $(HTMLPOST) $@)
 
71
        $<; $(HTMLPOST) $@
123
72
# Fix citerefentry links
124
 
HTMLPOST:=$(SED) --in-place \
 
73
HTMLPOST=$(SED) --in-place \
125
74
        --expression='s/\(<a class="citerefentry" href="\)\("><span class="citerefentry"><span class="refentrytitle">\)\([^<]*\)\(<\/span>(\)\([^)]*\)\()<\/span><\/a>\)/\1\3.\5\2\3\4\5\6/g'
126
75
 
127
 
PLUGINS:=plugins.d/password-prompt plugins.d/mandos-client \
128
 
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo \
129
 
        plugins.d/plymouth
130
 
PLUGIN_HELPERS:=plugin-helpers/mandos-client-iprouteadddel
131
 
CPROGS:=plugin-runner $(PLUGINS) $(PLUGIN_HELPERS)
132
 
PROGS:=mandos mandos-keygen mandos-ctl mandos-monitor $(CPROGS)
133
 
DOCS:=mandos.8 mandos-keygen.8 mandos-monitor.8 mandos-ctl.8 \
134
 
        mandos.conf.5 mandos-clients.conf.5 plugin-runner.8mandos \
 
76
PLUGINS=plugins.d/password-prompt plugins.d/mandos-client \
 
77
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo
 
78
CPROGS=plugin-runner $(PLUGINS)
 
79
PROGS=mandos mandos-keygen $(CPROGS)
 
80
DOCS=mandos.8 plugin-runner.8mandos mandos-keygen.8 \
135
81
        plugins.d/mandos-client.8mandos \
136
 
        plugins.d/password-prompt.8mandos plugins.d/usplash.8mandos \
137
 
        plugins.d/splashy.8mandos plugins.d/askpass-fifo.8mandos \
138
 
        plugins.d/plymouth.8mandos intro.8mandos
139
 
 
140
 
htmldocs:=$(addsuffix .xhtml,$(DOCS))
141
 
 
142
 
objects:=$(addsuffix .o,$(CPROGS))
 
82
        plugins.d/password-prompt.8mandos mandos.conf.5 \
 
83
        plugins.d/usplash.8mandos plugins.d/splashy.8mandos \
 
84
        plugins.d/askpass-fifo.8mandos mandos-clients.conf.5
 
85
 
 
86
htmldocs=$(addsuffix .xhtml,$(DOCS))
 
87
 
 
88
objects=$(addsuffix .o,$(CPROGS))
143
89
 
144
90
all: $(PROGS) mandos.lsm
145
91
 
162
108
%.8mandos.xhtml: %.xml common.ent legalnotice.xml
163
109
        $(DOCBOOKTOHTML)
164
110
 
165
 
intro.8mandos: intro.xml common.ent legalnotice.xml
166
 
        $(DOCBOOKTOMAN)
167
 
intro.8mandos.xhtml: intro.xml common.ent legalnotice.xml
168
 
        $(DOCBOOKTOHTML)
169
 
 
170
111
mandos.8: mandos.xml common.ent mandos-options.xml overview.xml \
171
112
                legalnotice.xml
172
113
        $(DOCBOOKTOMAN)
181
122
                 legalnotice.xml
182
123
        $(DOCBOOKTOHTML)
183
124
 
184
 
mandos-monitor.8: mandos-monitor.xml common.ent overview.xml \
185
 
                legalnotice.xml
186
 
        $(DOCBOOKTOMAN)
187
 
mandos-monitor.8.xhtml: mandos-monitor.xml common.ent overview.xml \
188
 
                 legalnotice.xml
189
 
        $(DOCBOOKTOHTML)
190
 
 
191
 
mandos-ctl.8: mandos-ctl.xml common.ent overview.xml \
192
 
                legalnotice.xml
193
 
        $(DOCBOOKTOMAN)
194
 
mandos-ctl.8.xhtml: mandos-ctl.xml common.ent overview.xml \
195
 
                 legalnotice.xml
196
 
        $(DOCBOOKTOHTML)
197
 
 
198
125
mandos.conf.5: mandos.conf.xml common.ent mandos-options.xml \
199
126
                legalnotice.xml
200
127
        $(DOCBOOKTOMAN)
222
149
 
223
150
# Update all these files with version number $(version)
224
151
common.ent: Makefile
225
 
        $(strip $(SED) --in-place \
226
 
                --expression='s/^\(<!ENTITY version "\)[^"]*">$$/\1$(version)">/' \
227
 
                $@)
 
152
        $(SED) --in-place \
 
153
                --expression='s/^\(<ENTITY VERSION "\)[^"]*">$$/\1$(version)"/' \
 
154
                $@
228
155
 
229
156
mandos: Makefile
230
 
        $(strip $(SED) --in-place \
 
157
        $(SED) --in-place \
231
158
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
232
 
                $@)
 
159
                $@
233
160
 
234
161
mandos-keygen: Makefile
235
 
        $(strip $(SED) --in-place \
 
162
        $(SED) --in-place \
236
163
                --expression='s/^\(VERSION="\)[^"]*"$$/\1$(version)"/' \
237
 
                $@)
238
 
 
239
 
mandos-ctl: Makefile
240
 
        $(strip $(SED) --in-place \
241
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
242
 
                $@)
243
 
 
244
 
mandos-monitor: Makefile
245
 
        $(strip $(SED) --in-place \
246
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
247
 
                $@)
 
164
                $@
248
165
 
249
166
mandos.lsm: Makefile
250
 
        $(strip $(SED) --in-place \
 
167
        $(SED) --in-place \
251
168
                --expression='s/^\(Version:\).*/\1\t$(version)/' \
252
 
                $@)
253
 
        $(strip $(SED) --in-place \
 
169
                $@
 
170
        $(SED) --in-place \
254
171
                --expression='s/^\(Entered-date:\).*/\1\t$(shell date --rfc-3339=date --reference=Makefile)/' \
255
 
                $@)
256
 
        $(strip $(SED) --in-place \
257
 
                --expression='s/\(mandos_\)[0-9.]\+\(\.orig\.tar\.gz\)/\1$(version)\2/' \
258
 
                $@)
259
 
 
260
 
# Need to add the GnuTLS, Avahi and GPGME libraries
261
 
plugins.d/mandos-client: plugins.d/mandos-client.c
262
 
        $(LINK.c) $^ $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(strip\
263
 
                ) $(GPGME_CFLAGS) $(GNUTLS_LIBS) $(strip\
264
 
                ) $(AVAHI_LIBS) $(GPGME_LIBS) $(LOADLIBES) $(strip\
265
 
                ) $(LDLIBS) -o $@
266
 
 
267
 
plugin-helpers/mandos-client-iprouteadddel: plugin-helpers/mandos-client-iprouteadddel.c
268
 
        $(LINK.c) $(LIBNL3_CFLAGS) $^ $(LIBNL3_LIBS) $(strip\
269
 
                ) $(LOADLIBES) $(LDLIBS) -o $@
270
 
 
271
 
.PHONY : all doc html clean distclean mostlyclean maintainer-clean \
272
 
        check run-client run-server install install-html \
273
 
        install-server install-client-nokey install-client uninstall \
274
 
        uninstall-server uninstall-client purge purge-server \
275
 
        purge-client
 
172
                $@
 
173
 
 
174
plugins.d/mandos-client: plugins.d/mandos-client.o
 
175
        $(LINK.o) $(GNUTLS_LIBS) $(AVAHI_LIBS) $(GPGME_LIBS) \
 
176
                $(COMMON) $^ $(LOADLIBES) $(LDLIBS) -o $@
 
177
 
 
178
.PHONY : all doc html clean distclean run-client run-server install \
 
179
        install-server install-client uninstall uninstall-server \
 
180
        uninstall-client purge purge-server purge-client
276
181
 
277
182
clean:
278
183
        -rm --force $(CPROGS) $(objects) $(htmldocs) $(DOCS) core
280
185
distclean: clean
281
186
mostlyclean: clean
282
187
maintainer-clean: clean
283
 
        -rm --force --recursive keydir confdir statedir
 
188
        -rm --force --recursive keydir confdir
284
189
 
285
 
check: all
 
190
check:  all
286
191
        ./mandos --check
287
 
        ./mandos-ctl --check
288
 
        ./mandos-keygen --version
289
 
        ./plugin-runner --version
290
 
        ./plugin-helpers/mandos-client-iprouteadddel --version
291
192
 
292
193
# Run the client with a local config and key
293
 
run-client: all keydir/seckey.txt keydir/pubkey.txt keydir/tls-privkey.pem keydir/tls-pubkey.pem
294
 
        @echo "###################################################################"
295
 
        @echo "# The following error messages are harmless and can be safely     #"
296
 
        @echo "# ignored:                                                        #"
297
 
        @echo "# From plugin-runner: setgid: Operation not permitted             #"
298
 
        @echo "#                     setuid: Operation not permitted             #"
299
 
        @echo "# From askpass-fifo:  mkfifo: Permission denied                   #"
300
 
        @echo "# From mandos-client:                                             #"
301
 
        @echo "#             Failed to raise privileges: Operation not permitted #"
302
 
        @echo "#             Warning: network hook \"*\" exited with status *      #"
303
 
        @echo "#                                                                 #"
304
 
        @echo "# (The messages are caused by not running as root, but you should #"
305
 
        @echo "# NOT run \"make run-client\" as root unless you also unpacked and  #"
306
 
        @echo "# compiled Mandos as root, which is also NOT recommended.)        #"
307
 
        @echo "###################################################################"
308
 
# We set GNOME_KEYRING_CONTROL to block pam_gnome_keyring
 
194
run-client: all keydir/seckey.txt keydir/pubkey.txt
309
195
        ./plugin-runner --plugin-dir=plugins.d \
310
 
                --plugin-helper-dir=plugin-helpers \
311
196
                --config-file=plugin-runner.conf \
312
 
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt,--tls-privkey=keydir/tls-privkey.pem,--tls-pubkey=keydir/tls-pubkey.pem,--network-hook-dir=network-hooks.d \
313
 
                --env-for=mandos-client:GNOME_KEYRING_CONTROL= \
314
 
                $(CLIENTARGS)
 
197
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt
315
198
 
316
199
# Used by run-client
317
 
keydir/seckey.txt keydir/pubkey.txt keydir/tls-privkey.pem keydir/tls-pubkey.pem: mandos-keygen
 
200
keydir/seckey.txt keydir/pubkey.txt: mandos-keygen
318
201
        install --directory keydir
319
202
        ./mandos-keygen --dir keydir --force
320
203
 
321
204
# Run the server with a local config
322
 
run-server: confdir/mandos.conf confdir/clients.conf statedir
323
 
        ./mandos --debug --no-dbus --configdir=confdir \
324
 
                --statedir=statedir $(SERVERARGS)
 
205
run-server: confdir/mandos.conf confdir/clients.conf
 
206
        ./mandos --debug --configdir=confdir
325
207
 
326
208
# Used by run-server
327
209
confdir/mandos.conf: mandos.conf
328
210
        install --directory confdir
329
211
        install --mode=u=rw,go=r $^ $@
330
 
confdir/clients.conf: clients.conf keydir/seckey.txt keydir/tls-pubkey.pem
 
212
confdir/clients.conf: clients.conf keydir/seckey.txt
331
213
        install --directory confdir
332
214
        install --mode=u=rw $< $@
333
215
# Add a client password
334
 
        ./mandos-keygen --dir keydir --password --no-ssh >> $@
335
 
statedir:
336
 
        install --directory statedir
 
216
        ./mandos-keygen --dir keydir --password >> $@
337
217
 
338
218
install: install-server install-client-nokey
339
219
 
344
224
 
345
225
install-server: doc
346
226
        install --directory $(CONFDIR)
347
 
        if install --directory --mode=u=rwx --owner=$(USER) \
348
 
                --group=$(GROUP) $(STATEDIR); then \
349
 
                :; \
350
 
        elif install --directory --mode=u=rwx $(STATEDIR); then \
351
 
                chown -- $(USER):$(GROUP) $(STATEDIR) || :; \
352
 
        fi
353
 
        if [ "$(TMPFILES)" != "$(DESTDIR)" -a -d "$(TMPFILES)" ]; then \
354
 
                install --mode=u=rw,go=r tmpfiles.d-mandos.conf \
355
 
                        $(TMPFILES)/mandos.conf; \
356
 
        fi
357
227
        install --mode=u=rwx,go=rx mandos $(PREFIX)/sbin/mandos
358
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
359
 
                mandos-ctl
360
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
361
 
                mandos-monitor
362
228
        install --mode=u=rw,go=r --target-directory=$(CONFDIR) \
363
229
                mandos.conf
364
230
        install --mode=u=rw --target-directory=$(CONFDIR) \
365
231
                clients.conf
366
 
        install --mode=u=rw,go=r dbus-mandos.conf \
367
 
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
368
232
        install --mode=u=rwx,go=rx init.d-mandos \
369
233
                $(DESTDIR)/etc/init.d/mandos
370
 
        if [ "$(SYSTEMD)" != "$(DESTDIR)" -a -d "$(SYSTEMD)" ]; then \
371
 
                install --mode=u=rw,go=r mandos.service $(SYSTEMD); \
372
 
        fi
373
234
        install --mode=u=rw,go=r default-mandos \
374
235
                $(DESTDIR)/etc/default/mandos
375
236
        if [ -z $(DESTDIR) ]; then \
377
238
        fi
378
239
        gzip --best --to-stdout mandos.8 \
379
240
                > $(MANDIR)/man8/mandos.8.gz
380
 
        gzip --best --to-stdout mandos-monitor.8 \
381
 
                > $(MANDIR)/man8/mandos-monitor.8.gz
382
 
        gzip --best --to-stdout mandos-ctl.8 \
383
 
                > $(MANDIR)/man8/mandos-ctl.8.gz
384
241
        gzip --best --to-stdout mandos.conf.5 \
385
242
                > $(MANDIR)/man5/mandos.conf.5.gz
386
243
        gzip --best --to-stdout mandos-clients.conf.5 \
387
244
                > $(MANDIR)/man5/mandos-clients.conf.5.gz
388
 
        gzip --best --to-stdout intro.8mandos \
389
 
                > $(MANDIR)/man8/intro.8mandos.gz
390
245
 
391
246
install-client-nokey: all doc
392
 
        install --directory $(LIBDIR)/mandos $(CONFDIR)
 
247
        install --directory $(PREFIX)/lib/mandos $(CONFDIR)
393
248
        install --directory --mode=u=rwx $(KEYDIR) \
394
 
                $(LIBDIR)/mandos/plugins.d \
395
 
                $(LIBDIR)/mandos/plugin-helpers
396
 
        if [ "$(CONFDIR)" != "$(LIBDIR)/mandos" ]; then \
 
249
                $(PREFIX)/lib/mandos/plugins.d
 
250
        if [ "$(CONFDIR)" != "$(PREFIX)/lib/mandos" ]; then \
397
251
                install --mode=u=rwx \
398
 
                        --directory "$(CONFDIR)/plugins.d" \
399
 
                        "$(CONFDIR)/plugin-helpers"; \
 
252
                        --directory "$(CONFDIR)/plugins.d"; \
400
253
        fi
401
 
        install --mode=u=rwx,go=rx --directory \
402
 
                "$(CONFDIR)/network-hooks.d"
403
 
        install --mode=u=rwx,go=rx \
404
 
                --target-directory=$(LIBDIR)/mandos plugin-runner
405
 
        install --mode=u=rwx,go=rx \
406
 
                --target-directory=$(LIBDIR)/mandos mandos-to-cryptroot-unlock
 
254
        install --mode=u=rwx,go=rx \
 
255
                --target-directory=$(PREFIX)/lib/mandos plugin-runner
407
256
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
408
257
                mandos-keygen
409
258
        install --mode=u=rwx,go=rx \
410
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
259
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
411
260
                plugins.d/password-prompt
412
261
        install --mode=u=rwxs,go=rx \
413
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
262
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
414
263
                plugins.d/mandos-client
415
264
        install --mode=u=rwxs,go=rx \
416
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
265
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
417
266
                plugins.d/usplash
418
267
        install --mode=u=rwxs,go=rx \
419
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
268
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
420
269
                plugins.d/splashy
421
270
        install --mode=u=rwxs,go=rx \
422
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
271
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
423
272
                plugins.d/askpass-fifo
424
 
        install --mode=u=rwxs,go=rx \
425
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
426
 
                plugins.d/plymouth
427
 
        install --mode=u=rwx,go=rx \
428
 
                --target-directory=$(LIBDIR)/mandos/plugin-helpers \
429
 
                plugin-helpers/mandos-client-iprouteadddel
430
273
        install initramfs-tools-hook \
431
274
                $(INITRAMFSTOOLS)/hooks/mandos
432
 
        install --mode=u=rw,go=r initramfs-tools-conf \
433
 
                $(INITRAMFSTOOLS)/conf.d/mandos-conf
434
 
        install --mode=u=rw,go=r initramfs-tools-conf-hook \
435
 
                $(INITRAMFSTOOLS)/conf-hooks.d/zz-mandos
 
275
        install --mode=u=rw,go=r initramfs-tools-hook-conf \
 
276
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos
436
277
        install initramfs-tools-script \
437
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos
438
 
        install initramfs-tools-script-stop \
439
 
                $(INITRAMFSTOOLS)/scripts/local-premount/mandos
 
278
                $(INITRAMFSTOOLS)/scripts/local-top/mandos
440
279
        install --mode=u=rw,go=r plugin-runner.conf $(CONFDIR)
441
280
        gzip --best --to-stdout mandos-keygen.8 \
442
281
                > $(MANDIR)/man8/mandos-keygen.8.gz
443
282
        gzip --best --to-stdout plugin-runner.8mandos \
444
283
                > $(MANDIR)/man8/plugin-runner.8mandos.gz
 
284
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
 
285
                > $(MANDIR)/man8/password-prompt.8mandos.gz
445
286
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
446
287
                > $(MANDIR)/man8/mandos-client.8mandos.gz
447
 
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
448
 
                > $(MANDIR)/man8/password-prompt.8mandos.gz
449
288
        gzip --best --to-stdout plugins.d/usplash.8mandos \
450
289
                > $(MANDIR)/man8/usplash.8mandos.gz
451
290
        gzip --best --to-stdout plugins.d/splashy.8mandos \
452
291
                > $(MANDIR)/man8/splashy.8mandos.gz
453
292
        gzip --best --to-stdout plugins.d/askpass-fifo.8mandos \
454
293
                > $(MANDIR)/man8/askpass-fifo.8mandos.gz
455
 
        gzip --best --to-stdout plugins.d/plymouth.8mandos \
456
 
                > $(MANDIR)/man8/plymouth.8mandos.gz
457
294
 
458
295
install-client: install-client-nokey
459
296
# Post-installation stuff
465
302
 
466
303
uninstall-server:
467
304
        -rm --force $(PREFIX)/sbin/mandos \
468
 
                $(PREFIX)/sbin/mandos-ctl \
469
 
                $(PREFIX)/sbin/mandos-monitor \
470
305
                $(MANDIR)/man8/mandos.8.gz \
471
 
                $(MANDIR)/man8/mandos-monitor.8.gz \
472
 
                $(MANDIR)/man8/mandos-ctl.8.gz \
473
306
                $(MANDIR)/man5/mandos.conf.5.gz \
474
307
                $(MANDIR)/man5/mandos-clients.conf.5.gz
475
308
        update-rc.d -f mandos remove
481
314
        ! grep --regexp='^ *[^ #].*keyscript=[^,=]*/mandos/' \
482
315
                $(DESTDIR)/etc/crypttab
483
316
        -rm --force $(PREFIX)/sbin/mandos-keygen \
484
 
                $(LIBDIR)/mandos/plugin-runner \
485
 
                $(LIBDIR)/mandos/plugins.d/password-prompt \
486
 
                $(LIBDIR)/mandos/plugins.d/mandos-client \
487
 
                $(LIBDIR)/mandos/plugins.d/usplash \
488
 
                $(LIBDIR)/mandos/plugins.d/splashy \
489
 
                $(LIBDIR)/mandos/plugins.d/askpass-fifo \
490
 
                $(LIBDIR)/mandos/plugins.d/plymouth \
 
317
                $(PREFIX)/lib/mandos/plugin-runner \
 
318
                $(PREFIX)/lib/mandos/plugins.d/password-prompt \
 
319
                $(PREFIX)/lib/mandos/plugins.d/mandos-client \
 
320
                $(PREFIX)/lib/mandos/plugins.d/usplash \
 
321
                $(PREFIX)/lib/mandos/plugins.d/splashy \
 
322
                $(PREFIX)/lib/mandos/plugins.d/askpass-fifo \
491
323
                $(INITRAMFSTOOLS)/hooks/mandos \
492
324
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos \
493
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos \
 
325
                $(INITRAMFSTOOLS)/scripts/local-top/mandos \
 
326
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
494
327
                $(MANDIR)/man8/mandos-keygen.8.gz \
495
 
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
496
 
                $(MANDIR)/man8/mandos-client.8mandos.gz
497
328
                $(MANDIR)/man8/password-prompt.8mandos.gz \
498
329
                $(MANDIR)/man8/usplash.8mandos.gz \
499
330
                $(MANDIR)/man8/splashy.8mandos.gz \
500
331
                $(MANDIR)/man8/askpass-fifo.8mandos.gz \
501
 
                $(MANDIR)/man8/plymouth.8mandos.gz \
502
 
        -rmdir $(LIBDIR)/mandos/plugins.d $(CONFDIR)/plugins.d \
503
 
                 $(LIBDIR)/mandos $(CONFDIR) $(KEYDIR)
 
332
                $(MANDIR)/man8/mandos-client.8mandos.gz
 
333
        -rmdir $(PREFIX)/lib/mandos/plugins.d $(CONFDIR)/plugins.d \
 
334
                 $(PREFIX)/lib/mandos $(CONFDIR) $(KEYDIR)
504
335
        update-initramfs -k all -u
505
336
 
506
337
purge: purge-server purge-client
507
338
 
508
339
purge-server: uninstall-server
509
340
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf \
510
 
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
511
341
                $(DESTDIR)/etc/default/mandos \
512
342
                $(DESTDIR)/etc/init.d/mandos \
513
 
                $(SYSTEMD)/mandos.service \
514
 
                $(DESTDIR)/run/mandos.pid \
515
343
                $(DESTDIR)/var/run/mandos.pid
516
344
        -rmdir $(CONFDIR)
517
345
 
518
346
purge-client: uninstall-client
519
 
        -shred --remove $(KEYDIR)/seckey.txt $(KEYDIR)/tls-privkey.pem
 
347
        -shred --remove $(KEYDIR)/seckey.txt
520
348
        -rm --force $(CONFDIR)/plugin-runner.conf \
521
 
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt \
522
 
                $(KEYDIR)/tls-pubkey.txt $(KEYDIR)/tls-privkey.txt
 
349
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt
523
350
        -rmdir $(KEYDIR) $(CONFDIR)/plugins.d $(CONFDIR)