4
** General: [[https://www.atlassian.com/git/workflows][Git Workflows]], [[http://gitimmersion.com/][Git Immersion]], [[https://news.ycombinator.com/item?id=7036628][Simple git workflow is simple]] [[https://news.ycombinator.com/item?id=9661349][On undoing, fixing, or removing commits in git]]
5
** Intro: [[http://www.eyrie.org/~eagle/notes/debian/git.html#combine][Using Git for Debian Packaging]]
6
** Use: [[https://honk.sigxcpu.org/piki/projects/git-buildpackage/][git-buildpackage]]
9
Using bzr-fastimport: [[http://www.fusonic.net/en/blog/2013/03/26/migrating-from-bazaar-to-git/][Migrating from Bazaar to Git]]
10
** Unresolved: [[http://jameswestby.net/bzr/builddeb/user_manual/split.html][bzr builddeb split mode]]
11
Maybe: [[http://honk.sigxcpu.org/projects/git-buildpackage/manual-html/gbp.import.html#GBP.IMPORT.UPSTREAM.GIT.NOTARBALL][git-buildpackage - No upstream tarballs]]
12
[[http://www.python.org/dev/peps/pep-0374/][PEP 374 - Choosing a distributed VCS for the Python project]]
13
[[http://www.emacswiki.org/emacs/GitForEmacsDevs][Git For Emacs Devs]]
15
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]]
23
** TODO [#A] --dh-params=FILE
24
** TODO [#B] Use capabilities instead of seteuid().
25
https://forums.grsecurity.net/viewtopic.php?f=7&t=2522
26
** TODO [#B] Use getaddrinfo(hints=AI_NUMERICHOST) instead of inet_pton()
27
** TODO [#C] Make start_mandos_communication() take "struct server".
28
** TODO [#C] --interfaces=regex,eth*,noregex (bridge-utils-interfaces(5))
29
** TODO [#C] Remove code for GNU libc < 2.15
32
** TODO [#B] use scandir(3) instead of readdir(3)
34
* usplash (Deprecated)
35
** TODO [#A] Make it work again
36
** TODO [#B] use scandir(3) instead of readdir(3)
41
** TODO [#B] lock stdin (with flock()?)
6
** [#B] Temporarily lower kernel log level
7
for less printouts during sucessfull boot.
9
** use strsep instead of strtok?
10
** Do not depend on GnuPG key rings on disk
11
This would mean creating new GnuPG key rings with GPGME by
12
importing the key files from scratch on every program start.
13
** Keydir move: /etc/mandos -> /etc/keys/mandos
14
Must create in preinst if not pre-depending on cryptsetup
48
** TODO handle printing for errors for plugins
49
*** Hook up stderr of plugins, buffer them, and prepend "Mandos Plugin [plugin name]"
50
** TODO [#C] use same file name rules as run-parts(8)
51
** kernel command line option for debug info
52
** TODO [#C] Remove code for GNU libc < 2.15
19
** [#A] /etc/init.d/mandos-server :teddy:
20
** [#B] Log level :bugs:
21
** /etc/mandos/clients.d/*.conf
22
Watch this directory and add/remove/update clients?
23
** config for TXT record
24
** [#B] Run-time communication with server :bugs:
26
See also [[*Mandos-tools]]
27
** Implement --foreground :bugs:
28
[[info:standards:Option%20Table][Table of Long Options]]
30
[[info:standards:Option%20Table][Table of Long Options]]
31
** Date+time on console log messages :bugs:
33
** delete hook when clients fall out by timeout
35
* Mandos-tools/utilities
36
All of this probably using D-Bus
43
** Use xinclude for common sections
49
*** Update initrd.img after installation
50
This seems to use some kind of "trigger" system
51
[[file:/usr/share/doc/dpkg/triggers.txt.gz]]
52
dpkg-trigger(1), deb-triggers(5)
54
**** "--passfile" option
55
Using the "secfile" option instead of "secret"
56
**** [#A] "--test" option
57
For testing decryption before rebooting.
59
*** [#A] Create mandos user and group for server
60
*** [#A] Create /var/run/mandos directory with perm and ownership
61
*** [#A] install rc.d script and do update-rc.d
62
between config files and man pages
55
** TODO [#B] Work around Avahi issue
56
Avahi does not announce link-local addresses if any global
57
addresses exist: http://lists.freedesktop.org/archives/avahi/2010-March/001863.html
58
** TODO [#B] --notify-command
59
This would allow the mandos.service to use
60
--notify-command="systemd-notify --pid READY=1"
61
** TODO [#B] Log level :BUGS:
62
*** TODO /etc/mandos/clients.d/*.conf
63
Watch this directory and add/remove/update clients?
64
** TODO [#C] config for TXT record
65
** TODO Log level dbus option
66
SetLogLevel D-Bus call
67
** TODO [#C] DBusServiceObjectUsingSuper
68
** TODO [#B] Global enable/disable flag
69
** TODO [#B] By-client countdown on number of secrets given
70
** D-Bus Client method NeedsPassword(50) - Timeout, default disapprove
71
+ SetPass(u"gazonk", True) -> Approval, persistent
72
+ Approve(False) -> Close client connection immediately
73
** TODO [#C] python-parsedatetime
74
** TODO Separate logging logic to own object
75
** TODO [#A] Limit approval_delay to max gnutls/tls timeout value
76
** TODO [#B] break the wait on approval_delay if connection dies
77
** TODO Generate Client.runtime_expansions from client options + extra
78
** TODO Allow %%(checker)s as a runtime expansion
79
** TODO Use python-tlslite?
80
** TODO D-Bus AddClient() method on server object
81
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods. :2:
82
** TODO Support [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-objectmanager][org.freedesktop.DBus.ObjectManager]] interface on server object :2:
83
Deprecate methods GetAllClients(), GetAllClientsWithProperties()
84
and signals ClientAdded and ClientRemoved.
85
** TODO Save state periodically to recover better from hard shutdowns
86
** TODO CheckerCompleted method, deprecate CheckedOK
87
** TODO Secret Service API?
88
http://standards.freedesktop.org/secret-service/
89
** TODO Remove D-Bus interfaces with old domain name :2:
90
** TODO Remove old string_to_delta format :2:
91
** TODO http://0pointer.de/blog/projects/stateless.html
92
*** tmpfiles snippet to create /var/lib/mandos with right user+perms
93
*** File in /usr/lib/sysusers.d to create user+group "_mandos"
94
** TODO Error handling on error parsing config files
95
** TODO init.d script error handling
96
** TODO D-Bus server properties; address, port, interface, etc. :2:
97
** TODO [#C] In Python 3.3, use shlex.quote() instead of re.escape()
98
** TODO [#A] USe systemd Type=dbus
101
** Add mandos contact info in manual pages
104
*** Handle "no D-Bus server" and/or "no Mandos server found" better
105
*** [#B] --dump option
106
** TODO Remove old string_to_delta format :2:
108
* TODO mandos-dispatch
109
Listens for specified D-Bus signals and spawns shell commands with
113
** TODO help should be toggleable
114
** Urwid client data displayer
115
Better view of client data in the listing
117
** Print a nice "We are sorry" message, save stack trace to log.
118
** Rename module "gobject" to "GObject".
121
** TODO "--secfile" option
122
Using the "secfile" option instead of "secret"
123
** TODO [#B] "--test" option
124
For testing decryption before rebooting.
66
127
** /usr/share/initramfs-tools/hooks/mandos
67
*** Do not install in initrd.img if configured not to.
68
Use "/etc/initramfs-tools/conf.d/mandos"? Definitely a debconf
70
** /etc/bash_completion.d/mandos
128
*** TODO [#C] use same file name rules as run-parts(8)
129
*** TODO [#C] Do not install in initrd.img if configured not to.
130
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
131
** TODO [#C] $(pkg-config --variable=completionsdir bash-completion)
71
132
From XML sources directly?
81
* Announce project on news
82
[[news:comp.os.linux.announce]]
135
** TODO Locate which package moves the other bin/sh when busybox is deactivated
136
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox
85
139
#+STARTUP: showall