/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to Makefile

Merge new wireless network hook.  Fix bridge network hook to use
hardware addresses instead of interface names.  Implement and document
new "CONNECT" environment variable for network hooks.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
WARN=-O -Wall -Wformat=2 -Winit-self -Wmissing-include-dirs \
2
2
        -Wswitch-default -Wswitch-enum -Wunused-parameter \
3
 
        -Wstrict-aliasing=2 -Wextra -Wfloat-equal -Wundef -Wshadow \
 
3
        -Wstrict-aliasing=1 -Wextra -Wfloat-equal -Wundef -Wshadow \
4
4
        -Wunsafe-loop-optimizations -Wpointer-arith \
5
5
        -Wbad-function-cast -Wcast-qual -Wcast-align -Wwrite-strings \
6
6
        -Wconversion -Wstrict-prototypes -Wold-style-definition \
7
 
        -Wpacked -Wnested-externs -Wunreachable-code -Winline \
8
 
        -Wvolatile-register-var
9
 
DEBUG=-ggdb3
 
7
        -Wpacked -Wnested-externs -Winline -Wvolatile-register-var
 
8
#       -Wunreachable-code
 
9
#DEBUG=-ggdb3
10
10
# For info about _FORTIFY_SOURCE, see
11
 
# <http://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>
12
 
FORTIFY=-D_FORTIFY_SOURCE=2 # -fstack-protector-all
 
11
# <http://www.kernel.org/doc/man-pages/online/pages/man7/feature_test_macros.7.html>
 
12
# and <http://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>.
 
13
FORTIFY=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIC
 
14
LINK_FORTIFY_LD=-z relro -z now
 
15
LINK_FORTIFY=
 
16
 
 
17
# If BROKEN_PIE is set, do not build with -pie
 
18
ifndef BROKEN_PIE
 
19
FORTIFY += -fPIE
 
20
LINK_FORTIFY += -pie
 
21
endif
13
22
#COVERAGE=--coverage
14
23
OPTIMIZE=-Os
15
24
LANGUAGE=-std=gnu99
16
 
# PREFIX=/usr/local
 
25
htmldir=man
 
26
version=1.4.1
 
27
SED=sed
 
28
 
 
29
USER=$(firstword $(subst :, ,$(shell getent passwd _mandos || getent passwd nobody || echo 65534)))
 
30
GROUP=$(firstword $(subst :, ,$(shell getent group _mandos || getent group nobody || echo 65534)))
 
31
 
 
32
## Use these settings for a traditional /usr/local install
 
33
# PREFIX=$(DESTDIR)/usr/local
 
34
# CONFDIR=$(DESTDIR)/etc/mandos
 
35
# KEYDIR=$(DESTDIR)/etc/mandos/keys
 
36
# MANDIR=$(PREFIX)/man
 
37
# INITRAMFSTOOLS=$(DESTDIR)/etc/initramfs-tools
 
38
# STATEDIR=$(DESTDIR)/var/lib/mandos
 
39
##
 
40
 
 
41
## These settings are for a package-type install
17
42
PREFIX=$(DESTDIR)/usr
18
 
# CONFDIR=/usr/local/lib/mandos
19
43
CONFDIR=$(DESTDIR)/etc/mandos
20
 
# MANDIR=/usr/local/man
21
 
MANDIR=$(DESTDIR)/usr/share/man
 
44
KEYDIR=$(DESTDIR)/etc/keys/mandos
 
45
MANDIR=$(PREFIX)/share/man
 
46
INITRAMFSTOOLS=$(DESTDIR)/usr/share/initramfs-tools
 
47
STATEDIR=$(DESTDIR)/var/lib/mandos
 
48
##
22
49
 
23
 
GNUTLS_CFLAGS=$(shell libgnutls-config --cflags)
24
 
GNUTLS_LIBS=$(shell libgnutls-config --libs)
 
50
GNUTLS_CFLAGS=$(shell pkg-config --cflags-only-I gnutls)
 
51
GNUTLS_LIBS=$(shell pkg-config --libs gnutls)
25
52
AVAHI_CFLAGS=$(shell pkg-config --cflags-only-I avahi-core)
26
53
AVAHI_LIBS=$(shell pkg-config --libs avahi-core)
27
 
GPGME_CFLAGS=$(shell gpgme-config --cflags)
28
 
GPGME_LIBS=$(shell gpgme-config --libs)
 
54
GPGME_CFLAGS=$(shell gpgme-config --cflags; getconf LFS_CFLAGS)
 
55
GPGME_LIBS=$(shell gpgme-config --libs; getconf LFS_LIBS; \
 
56
        getconf LFS_LDFLAGS)
29
57
 
30
58
# Do not change these two
31
59
CFLAGS=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
32
 
        $(LANGUAGE) $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(GPGME_CFLAGS)
33
 
LDFLAGS=$(COVERAGE)
 
60
        $(LANGUAGE) $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(GPGME_CFLAGS) \
 
61
        -DVERSION='"$(version)"'
 
62
LDFLAGS=-Xlinker --as-needed $(COVERAGE) $(LINK_FORTIFY) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
34
63
 
35
 
# Commands to format a DocBook refentry document into a manual page
36
 
DOCBOOKTOMAN=cd $(dir $^); xsltproc --nonet --xinclude \
 
64
# Commands to format a DocBook <refentry> document into a manual page
 
65
DOCBOOKTOMAN=$(strip cd $(dir $<); xsltproc --nonet --xinclude \
37
66
        --param man.charmap.use.subset          0 \
38
67
        --param make.year.ranges                1 \
39
68
        --param make.single.year.ranges         1 \
41
70
        --param man.authors.section.enabled     0 \
42
71
         /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
43
72
        $(notdir $<); \
44
 
        $(MANPOST) $(notdir $@)
45
 
# DocBook-to-man post-processing to fix a \n escape bug
46
 
MANPOST=sed --in-place --expression='s,\\\\en,\\en,g;s,\\n,\\en,g'
47
 
 
48
 
PLUGINS=plugins.d/password-prompt plugins.d/password-request
49
 
PROGS=plugin-runner $(PLUGINS)
50
 
DOCS=mandos.8 plugin-runner.8mandos mandos-keygen.8 \
51
 
        plugins.d/password-request.8mandos \
52
 
        plugins.d/password-prompt.8mandos mandos.conf.5 \
53
 
        mandos-clients.conf.5
54
 
 
55
 
objects=$(addsuffix .o,$(PROGS))
56
 
 
57
 
all: $(PROGS)
 
73
        $(MANPOST) $(notdir $@);\
 
74
        LANG=en_US.UTF-8 MANWIDTH=80 man --warnings --encoding=UTF-8 \
 
75
        --local-file $(notdir $@) >/dev/null)
 
76
# DocBook-to-man post-processing to fix a '\n' escape bug
 
77
MANPOST=$(SED) --in-place --expression='s,\\\\en,\\en,g;s,\\n,\\en,g'
 
78
 
 
79
DOCBOOKTOHTML=$(strip xsltproc --nonet --xinclude \
 
80
        --param make.year.ranges                1 \
 
81
        --param make.single.year.ranges         1 \
 
82
        --param man.output.quietly              1 \
 
83
        --param man.authors.section.enabled     0 \
 
84
        --param citerefentry.link               1 \
 
85
        --output $@ \
 
86
        /usr/share/xml/docbook/stylesheet/nwalsh/xhtml/docbook.xsl \
 
87
        $<; $(HTMLPOST) $@)
 
88
# Fix citerefentry links
 
89
HTMLPOST=$(SED) --in-place \
 
90
        --expression='s/\(<a class="citerefentry" href="\)\("><span class="citerefentry"><span class="refentrytitle">\)\([^<]*\)\(<\/span>(\)\([^)]*\)\()<\/span><\/a>\)/\1\3.\5\2\3\4\5\6/g'
 
91
 
 
92
PLUGINS=plugins.d/password-prompt plugins.d/mandos-client \
 
93
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo \
 
94
        plugins.d/plymouth
 
95
CPROGS=plugin-runner $(PLUGINS)
 
96
PROGS=mandos mandos-keygen mandos-ctl mandos-monitor $(CPROGS)
 
97
DOCS=mandos.8 mandos-keygen.8 mandos-monitor.8 mandos-ctl.8 \
 
98
        mandos.conf.5 mandos-clients.conf.5 plugin-runner.8mandos \
 
99
        plugins.d/mandos-client.8mandos \
 
100
        plugins.d/password-prompt.8mandos plugins.d/usplash.8mandos \
 
101
        plugins.d/splashy.8mandos plugins.d/askpass-fifo.8mandos \
 
102
        plugins.d/plymouth.8mandos intro.8mandos
 
103
 
 
104
htmldocs=$(addsuffix .xhtml,$(DOCS))
 
105
 
 
106
objects=$(addsuffix .o,$(CPROGS))
 
107
 
 
108
all: $(PROGS) mandos.lsm
58
109
 
59
110
doc: $(DOCS)
60
111
 
61
 
%.5: %.xml
62
 
        $(DOCBOOKTOMAN)
63
 
 
64
 
%.8: %.xml
65
 
        $(DOCBOOKTOMAN)
66
 
 
67
 
%.8mandos: %.xml
68
 
        $(DOCBOOKTOMAN)
69
 
 
70
 
mandos.8: mandos.xml mandos-options.xml
71
 
        $(DOCBOOKTOMAN)
72
 
 
73
 
mandos.conf.5: mandos.conf.xml mandos-options.xml
74
 
        $(DOCBOOKTOMAN)
75
 
 
76
 
plugins.d/password-request: plugins.d/password-request.o
77
 
        $(LINK.o) $(GNUTLS_LIBS) $(AVAHI_LIBS) $(GPGME_LIBS) \
78
 
                $(COMMON) $^ $(LOADLIBES) $(LDLIBS) -o $@
79
 
 
80
 
.PHONY : all doc clean distclean run-client run-server install \
 
112
html: $(htmldocs)
 
113
 
 
114
%.5: %.xml common.ent legalnotice.xml
 
115
        $(DOCBOOKTOMAN)
 
116
%.5.xhtml: %.xml common.ent legalnotice.xml
 
117
        $(DOCBOOKTOHTML)
 
118
 
 
119
%.8: %.xml common.ent legalnotice.xml
 
120
        $(DOCBOOKTOMAN)
 
121
%.8.xhtml: %.xml common.ent legalnotice.xml
 
122
        $(DOCBOOKTOHTML)
 
123
 
 
124
%.8mandos: %.xml common.ent legalnotice.xml
 
125
        $(DOCBOOKTOMAN)
 
126
%.8mandos.xhtml: %.xml common.ent legalnotice.xml
 
127
        $(DOCBOOKTOHTML)
 
128
 
 
129
intro.8mandos: intro.xml common.ent legalnotice.xml
 
130
        $(DOCBOOKTOMAN)
 
131
intro.8mandos.xhtml: intro.xml common.ent legalnotice.xml
 
132
        $(DOCBOOKTOHTML)
 
133
 
 
134
mandos.8: mandos.xml common.ent mandos-options.xml overview.xml \
 
135
                legalnotice.xml
 
136
        $(DOCBOOKTOMAN)
 
137
mandos.8.xhtml: mandos.xml common.ent mandos-options.xml \
 
138
                overview.xml legalnotice.xml
 
139
        $(DOCBOOKTOHTML)
 
140
 
 
141
mandos-keygen.8: mandos-keygen.xml common.ent overview.xml \
 
142
                legalnotice.xml
 
143
        $(DOCBOOKTOMAN)
 
144
mandos-keygen.8.xhtml: mandos-keygen.xml common.ent overview.xml \
 
145
                 legalnotice.xml
 
146
        $(DOCBOOKTOHTML)
 
147
 
 
148
mandos-monitor.8: mandos-monitor.xml common.ent overview.xml \
 
149
                legalnotice.xml
 
150
        $(DOCBOOKTOMAN)
 
151
mandos-monitor.8.xhtml: mandos-monitor.xml common.ent overview.xml \
 
152
                 legalnotice.xml
 
153
        $(DOCBOOKTOHTML)
 
154
 
 
155
mandos-ctl.8: mandos-ctl.xml common.ent overview.xml \
 
156
                legalnotice.xml
 
157
        $(DOCBOOKTOMAN)
 
158
mandos-ctl.8.xhtml: mandos-ctl.xml common.ent overview.xml \
 
159
                 legalnotice.xml
 
160
        $(DOCBOOKTOHTML)
 
161
 
 
162
mandos.conf.5: mandos.conf.xml common.ent mandos-options.xml \
 
163
                legalnotice.xml
 
164
        $(DOCBOOKTOMAN)
 
165
mandos.conf.5.xhtml: mandos.conf.xml common.ent mandos-options.xml \
 
166
                legalnotice.xml
 
167
        $(DOCBOOKTOHTML)
 
168
 
 
169
plugin-runner.8mandos: plugin-runner.xml common.ent overview.xml \
 
170
                legalnotice.xml
 
171
        $(DOCBOOKTOMAN)
 
172
plugin-runner.8mandos.xhtml: plugin-runner.xml common.ent \
 
173
                overview.xml legalnotice.xml
 
174
        $(DOCBOOKTOHTML)
 
175
 
 
176
plugins.d/mandos-client.8mandos: plugins.d/mandos-client.xml \
 
177
                                        common.ent \
 
178
                                        mandos-options.xml \
 
179
                                        overview.xml legalnotice.xml
 
180
        $(DOCBOOKTOMAN)
 
181
plugins.d/mandos-client.8mandos.xhtml: plugins.d/mandos-client.xml \
 
182
                                        common.ent \
 
183
                                        mandos-options.xml \
 
184
                                        overview.xml legalnotice.xml
 
185
        $(DOCBOOKTOHTML)
 
186
 
 
187
# Update all these files with version number $(version)
 
188
common.ent: Makefile
 
189
        $(strip $(SED) --in-place \
 
190
                --expression='s/^\(<!ENTITY version "\)[^"]*">$$/\1$(version)">/' \
 
191
                $@)
 
192
 
 
193
mandos: Makefile
 
194
        $(strip $(SED) --in-place \
 
195
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
 
196
                $@)
 
197
 
 
198
mandos-keygen: Makefile
 
199
        $(strip $(SED) --in-place \
 
200
                --expression='s/^\(VERSION="\)[^"]*"$$/\1$(version)"/' \
 
201
                $@)
 
202
 
 
203
mandos-ctl: Makefile
 
204
        $(strip $(SED) --in-place \
 
205
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
 
206
                $@)
 
207
 
 
208
mandos-monitor: Makefile
 
209
        $(strip $(SED) --in-place \
 
210
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
 
211
                $@)
 
212
 
 
213
mandos.lsm: Makefile
 
214
        $(strip $(SED) --in-place \
 
215
                --expression='s/^\(Version:\).*/\1\t$(version)/' \
 
216
                $@)
 
217
        $(strip $(SED) --in-place \
 
218
                --expression='s/^\(Entered-date:\).*/\1\t$(shell date --rfc-3339=date --reference=Makefile)/' \
 
219
                $@)
 
220
        $(strip $(SED) --in-place \
 
221
                --expression='s/\(mandos_\)[0-9.]\+\(\.orig\.tar\.gz\)/\1$(version)\2/' \
 
222
                $@)
 
223
 
 
224
plugins.d/mandos-client: plugins.d/mandos-client.c
 
225
        $(LINK.c) $^ -lrt $(GNUTLS_LIBS) $(AVAHI_LIBS) $(strip\
 
226
                ) $(GPGME_LIBS) $(LOADLIBES) $(LDLIBS) -o $@
 
227
 
 
228
.PHONY : all doc html clean distclean run-client run-server install \
81
229
        install-server install-client uninstall uninstall-server \
82
230
        uninstall-client purge purge-server purge-client
83
231
 
84
232
clean:
85
 
        -rm --force $(PROGS) $(objects) $(DOCS) core
 
233
        -rm --force $(CPROGS) $(objects) $(htmldocs) $(DOCS) core
86
234
 
87
235
distclean: clean
88
236
mostlyclean: clean
89
237
maintainer-clean: clean
90
 
        -rm --force --recursive keydir
 
238
        -rm --force --recursive keydir confdir statedir
91
239
 
92
 
check:
 
240
check:  all
93
241
        ./mandos --check
94
242
 
95
 
run-client: all
96
 
        -mkdir keydir
97
 
        -./mandos-keygen --dir keydir
 
243
# Run the client with a local config and key
 
244
run-client: all keydir/seckey.txt keydir/pubkey.txt
 
245
        @echo "###################################################################"
 
246
        @echo "# The following error messages are harmless and can be safely     #"
 
247
        @echo "# ignored.  The messages are caused by not running as root, but   #"
 
248
        @echo "# you should NOT run \"make run-client\" as root unless you also    #"
 
249
        @echo "# unpacked and compiled Mandos as root, which is NOT recommended. #"
 
250
        @echo "# From plugin-runner: setuid: Operation not permitted             #"
 
251
        @echo "# From askpass-fifo:  mkfifo: Permission denied                   #"
 
252
        @echo "# From mandos-client: setuid: Operation not permitted             #"
 
253
        @echo "#                     seteuid: Operation not permitted            #"
 
254
        @echo "#                     klogctl: Operation not permitted            #"
 
255
        @echo "###################################################################"
98
256
        ./plugin-runner --plugin-dir=plugins.d \
99
 
                --options-for=password-request:--keydir=keydir
100
 
 
101
 
run-server:
102
 
        ./mandos --debug --configdir=.
103
 
 
104
 
install: install-server install-client
 
257
                --config-file=plugin-runner.conf \
 
258
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt,--network-hook-dir=network-hooks.d \
 
259
                $(CLIENTARGS)
 
260
 
 
261
# Used by run-client
 
262
keydir/seckey.txt keydir/pubkey.txt: mandos-keygen
 
263
        install --directory keydir
 
264
        ./mandos-keygen --dir keydir --force
 
265
 
 
266
# Run the server with a local config
 
267
run-server: confdir/mandos.conf confdir/clients.conf
 
268
        ./mandos --debug --no-dbus --configdir=confdir \
 
269
                --statedir=statedir $(SERVERARGS)
 
270
 
 
271
# Used by run-server
 
272
confdir/mandos.conf: mandos.conf
 
273
        install --directory confdir
 
274
        install --mode=u=rw,go=r $^ $@
 
275
confdir/clients.conf: clients.conf keydir/seckey.txt
 
276
        install --directory confdir
 
277
        install --mode=u=rw $< $@
 
278
# Add a client password
 
279
        ./mandos-keygen --dir keydir --password >> $@
 
280
statedir:
 
281
        install --directory statedir
 
282
 
 
283
install: install-server install-client-nokey
 
284
 
 
285
install-html: html
 
286
        install --directory $(htmldir)
 
287
        install --mode=u=rw,go=r --target-directory=$(htmldir) \
 
288
                $(htmldocs)
105
289
 
106
290
install-server: doc
107
 
        install --directory --parents $(CONFDIR) $(MANDIR)/man5 \
108
 
                $(MANDIR)/man8
109
 
        install --mode=0755 mandos $(PREFIX)/sbin/mandos
110
 
        install --mode=0644 --target-directory=$(CONFDIR) mandos.conf
111
 
        install --mode=0640 --target-directory=$(CONFDIR) \
 
291
        install --directory $(CONFDIR)
 
292
        install --directory --mode=u=rwx --owner=$(USER) \
 
293
                --group=$(GROUP) $(STATEDIR)
 
294
        install --mode=u=rwx,go=rx mandos $(PREFIX)/sbin/mandos
 
295
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
 
296
                mandos-ctl
 
297
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
 
298
                mandos-monitor
 
299
        install --mode=u=rw,go=r --target-directory=$(CONFDIR) \
 
300
                mandos.conf
 
301
        install --mode=u=rw --target-directory=$(CONFDIR) \
112
302
                clients.conf
 
303
        install --mode=u=rw,go=r dbus-mandos.conf \
 
304
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
 
305
        install --mode=u=rwx,go=rx init.d-mandos \
 
306
                $(DESTDIR)/etc/init.d/mandos
 
307
        install --mode=u=rw,go=r default-mandos \
 
308
                $(DESTDIR)/etc/default/mandos
 
309
        if [ -z $(DESTDIR) ]; then \
 
310
                update-rc.d mandos defaults 25 15;\
 
311
        fi
113
312
        gzip --best --to-stdout mandos.8 \
114
313
                > $(MANDIR)/man8/mandos.8.gz
 
314
        gzip --best --to-stdout mandos-monitor.8 \
 
315
                > $(MANDIR)/man8/mandos-monitor.8.gz
 
316
        gzip --best --to-stdout mandos-ctl.8 \
 
317
                > $(MANDIR)/man8/mandos-ctl.8.gz
115
318
        gzip --best --to-stdout mandos.conf.5 \
116
319
                > $(MANDIR)/man5/mandos.conf.5.gz
117
320
        gzip --best --to-stdout mandos-clients.conf.5 \
118
321
                > $(MANDIR)/man5/mandos-clients.conf.5.gz
119
322
 
120
 
install-client: all doc /usr/share/initramfs-tools/hooks/.
121
 
        install --directory --parents $(PREFIX)/lib/mandos \
122
 
                $(CONFDIR) $(MANDIR)/man8
123
 
        install --directory --mode=0700 $(PREFIX)/lib/mandos/plugins.d
124
 
        chmod u=rwx,g=,o= $(PREFIX)/lib/mandos/plugins.d
125
 
        install --mode=0755 --target-directory=$(PREFIX)/lib/mandos \
126
 
                plugin-runner
127
 
        install --mode=0755 --target-directory=$(PREFIX)/sbin \
 
323
install-client-nokey: all doc
 
324
        install --directory $(PREFIX)/lib/mandos $(CONFDIR)
 
325
        install --directory --mode=u=rwx $(KEYDIR) \
 
326
                $(PREFIX)/lib/mandos/plugins.d
 
327
        if [ "$(CONFDIR)" != "$(PREFIX)/lib/mandos" ]; then \
 
328
                install --mode=u=rwx \
 
329
                        --directory "$(CONFDIR)/plugins.d"; \
 
330
        fi
 
331
        install --mode=u=rwx,go=rx --directory \
 
332
                "$(CONFDIR)/network-hooks.d"
 
333
        install --mode=u=rwx,go=rx \
 
334
                --target-directory=$(PREFIX)/lib/mandos plugin-runner
 
335
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
128
336
                mandos-keygen
129
 
        install --mode=0755 \
 
337
        install --mode=u=rwx,go=rx \
130
338
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
131
339
                plugins.d/password-prompt
132
 
        install --mode=4755 \
133
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
134
 
                plugins.d/password-request
 
340
        install --mode=u=rwxs,go=rx \
 
341
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
342
                plugins.d/mandos-client
 
343
        install --mode=u=rwxs,go=rx \
 
344
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
345
                plugins.d/usplash
 
346
        install --mode=u=rwxs,go=rx \
 
347
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
348
                plugins.d/splashy
 
349
        install --mode=u=rwxs,go=rx \
 
350
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
351
                plugins.d/askpass-fifo
 
352
        install --mode=u=rwxs,go=rx \
 
353
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
354
                plugins.d/plymouth
135
355
        install initramfs-tools-hook \
136
 
                /usr/share/initramfs-tools/hooks/mandos
137
 
        install initramfs-tools-hook-conf \
138
 
                /usr/share/initramfs-tools/conf-hooks.d/mandos
 
356
                $(INITRAMFSTOOLS)/hooks/mandos
 
357
        install --mode=u=rw,go=r initramfs-tools-hook-conf \
 
358
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos
139
359
        install initramfs-tools-script \
140
 
                /usr/share/initramfs-tools/scripts/local-top/mandos
 
360
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos
 
361
        install --mode=u=rw,go=r plugin-runner.conf $(CONFDIR)
141
362
        gzip --best --to-stdout mandos-keygen.8 \
142
363
                > $(MANDIR)/man8/mandos-keygen.8.gz
143
364
        gzip --best --to-stdout plugin-runner.8mandos \
144
365
                > $(MANDIR)/man8/plugin-runner.8mandos.gz
 
366
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
 
367
                > $(MANDIR)/man8/mandos-client.8mandos.gz
145
368
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
146
369
                > $(MANDIR)/man8/password-prompt.8mandos.gz
147
 
        gzip --best --to-stdout plugins.d/password-request.8mandos \
148
 
                > $(MANDIR)/man8/password-request.8mandos.gz
149
 
        -$(PREFIX)/sbin/mandos-keygen
 
370
        gzip --best --to-stdout plugins.d/usplash.8mandos \
 
371
                > $(MANDIR)/man8/usplash.8mandos.gz
 
372
        gzip --best --to-stdout plugins.d/splashy.8mandos \
 
373
                > $(MANDIR)/man8/splashy.8mandos.gz
 
374
        gzip --best --to-stdout plugins.d/askpass-fifo.8mandos \
 
375
                > $(MANDIR)/man8/askpass-fifo.8mandos.gz
 
376
        gzip --best --to-stdout plugins.d/plymouth.8mandos \
 
377
                > $(MANDIR)/man8/plymouth.8mandos.gz
 
378
 
 
379
install-client: install-client-nokey
 
380
# Post-installation stuff
 
381
        -$(PREFIX)/sbin/mandos-keygen --dir "$(KEYDIR)"
150
382
        update-initramfs -k all -u
 
383
        echo "Now run mandos-keygen --password --dir $(KEYDIR)"
151
384
 
152
385
uninstall: uninstall-server uninstall-client
153
386
 
154
 
uninstall-server: $(PREFIX)/sbin/mandos
 
387
uninstall-server:
155
388
        -rm --force $(PREFIX)/sbin/mandos \
 
389
                $(PREFIX)/sbin/mandos-ctl \
 
390
                $(PREFIX)/sbin/mandos-monitor \
156
391
                $(MANDIR)/man8/mandos.8.gz \
 
392
                $(MANDIR)/man8/mandos-monitor.8.gz \
 
393
                $(MANDIR)/man8/mandos-ctl.8.gz \
157
394
                $(MANDIR)/man5/mandos.conf.5.gz \
158
395
                $(MANDIR)/man5/mandos-clients.conf.5.gz
 
396
        update-rc.d -f mandos remove
159
397
        -rmdir $(CONFDIR)
160
398
 
161
399
uninstall-client:
162
400
# Refuse to uninstall client if /etc/crypttab is explicitly configured
163
401
# to use it.
164
402
        ! grep --regexp='^ *[^ #].*keyscript=[^,=]*/mandos/' \
165
 
                /etc/crypttab
 
403
                $(DESTDIR)/etc/crypttab
166
404
        -rm --force $(PREFIX)/sbin/mandos-keygen \
167
405
                $(PREFIX)/lib/mandos/plugin-runner \
168
406
                $(PREFIX)/lib/mandos/plugins.d/password-prompt \
169
 
                $(PREFIX)/lib/mandos/plugins.d/password-request \
170
 
                /usr/share/initramfs-tools/hooks/mandos \
171
 
                /usr/share/initramfs-tools/conf-hooks.d/mandos \
 
407
                $(PREFIX)/lib/mandos/plugins.d/mandos-client \
 
408
                $(PREFIX)/lib/mandos/plugins.d/usplash \
 
409
                $(PREFIX)/lib/mandos/plugins.d/splashy \
 
410
                $(PREFIX)/lib/mandos/plugins.d/askpass-fifo \
 
411
                $(PREFIX)/lib/mandos/plugins.d/plymouth \
 
412
                $(INITRAMFSTOOLS)/hooks/mandos \
 
413
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos \
 
414
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos \
 
415
                $(MANDIR)/man8/mandos-keygen.8.gz \
172
416
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
173
 
                $(MANDIR)/man8/mandos-keygen.8.gz \
 
417
                $(MANDIR)/man8/mandos-client.8mandos.gz
174
418
                $(MANDIR)/man8/password-prompt.8mandos.gz \
175
 
                $(MANDIR)/man8/password-request.8mandos.gz
 
419
                $(MANDIR)/man8/usplash.8mandos.gz \
 
420
                $(MANDIR)/man8/splashy.8mandos.gz \
 
421
                $(MANDIR)/man8/askpass-fifo.8mandos.gz \
 
422
                $(MANDIR)/man8/plymouth.8mandos.gz \
176
423
        -rmdir $(PREFIX)/lib/mandos/plugins.d $(CONFDIR)/plugins.d \
177
 
                 $(PREFIX)/lib/mandos $(CONFDIR)
 
424
                 $(PREFIX)/lib/mandos $(CONFDIR) $(KEYDIR)
178
425
        update-initramfs -k all -u
179
426
 
180
427
purge: purge-server purge-client
181
428
 
182
429
purge-server: uninstall-server
183
 
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf
 
430
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf \
 
431
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
 
432
                $(DESTDIR)/etc/default/mandos \
 
433
                $(DESTDIR)/etc/init.d/mandos \
 
434
                $(DESTDIR)/var/run/mandos.pid
184
435
        -rmdir $(CONFDIR)
185
436
 
186
437
purge-client: uninstall-client
187
 
        -rm --force $(CONFDIR)/seckey.txt $(CONFDIR)/pubkey.txt
188
 
        -rmdir $(CONFDIR) $(CONFDIR)/plugins.d
 
438
        -shred --remove $(KEYDIR)/seckey.txt
 
439
        -rm --force $(CONFDIR)/plugin-runner.conf \
 
440
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt
 
441
        -rmdir $(KEYDIR) $(CONFDIR)/plugins.d $(CONFDIR)