/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to Makefile

  • Committer: Teddy Hogeborn
  • Date: 2019-08-05 21:14:05 UTC
  • Revision ID: teddy@recompile.se-20190805211405-9m6hecekaihpttz9
Override lintian warnings about upgrading from old versions

There are some really things which are imperative that we fix in case
someone were to upgrade from a really old version.  We want to keep
these fixes in the postinst maintainer scripts, even though lintian
complains about such old upgrades not being supported by Debian in
general.  We prefer the code being there, for the sake of the users.

* debian/mandos-client.lintian-overrides
  (maintainer-script-supports-ancient-package-version): New.
  debian/mandos.lintian-overrides
  (maintainer-script-supports-ancient-package-version): - '' -

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
WARN=-O -Wall -Wformat=2 -Winit-self -Wmissing-include-dirs \
2
 
        -Wswitch-default -Wswitch-enum -Wunused-parameter \
3
 
        -Wstrict-aliasing=2 -Wextra -Wfloat-equal -Wundef -Wshadow \
 
1
WARN:=-O -Wall -Wextra -Wdouble-promotion -Wformat=2 -Winit-self \
 
2
        -Wmissing-include-dirs -Wswitch-default -Wswitch-enum \
 
3
        -Wunused -Wuninitialized -Wstrict-overflow=5 \
 
4
        -Wsuggest-attribute=pure -Wsuggest-attribute=const \
 
5
        -Wsuggest-attribute=noreturn -Wfloat-equal -Wundef -Wshadow \
4
6
        -Wunsafe-loop-optimizations -Wpointer-arith \
5
7
        -Wbad-function-cast -Wcast-qual -Wcast-align -Wwrite-strings \
6
 
        -Wconversion -Wstrict-prototypes -Wold-style-definition \
7
 
        -Wpacked -Wnested-externs -Winline -Wvolatile-register-var
8
 
#       -Wunreachable-code 
9
 
#DEBUG=-ggdb3
10
 
# For info about _FORTIFY_SOURCE, see
11
 
# <http://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>
12
 
FORTIFY=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIC -fPIE
13
 
LINK_FORTIFY_LD=-z relro -fPIE
14
 
LINK_FORTIFY=-pie
 
8
        -Wconversion -Wlogical-op -Waggregate-return \
 
9
        -Wstrict-prototypes -Wold-style-definition \
 
10
        -Wmissing-format-attribute -Wnormalized=nfc -Wpacked \
 
11
        -Wredundant-decls -Wnested-externs -Winline -Wvla \
 
12
        -Wvolatile-register-var -Woverlength-strings
 
13
 
 
14
#DEBUG:=-ggdb3 -fsanitize=address $(SANITIZE)
 
15
## Check which sanitizing options can be used
 
16
#SANITIZE:=$(foreach option,$(ALL_SANITIZE_OPTIONS),$(shell \
 
17
#       echo 'int main(){}' | $(CC) --language=c $(option) \
 
18
#       /dev/stdin -o /dev/null >/dev/null 2>&1 && echo $(option)))
 
19
# <https://developerblog.redhat.com/2014/10/16/gcc-undefined-behavior-sanitizer-ubsan/>
 
20
ALL_SANITIZE_OPTIONS:=-fsanitize=leak -fsanitize=undefined \
 
21
        -fsanitize=shift -fsanitize=integer-divide-by-zero \
 
22
        -fsanitize=unreachable -fsanitize=vla-bound -fsanitize=null \
 
23
        -fsanitize=return -fsanitize=signed-integer-overflow \
 
24
        -fsanitize=bounds -fsanitize=alignment \
 
25
        -fsanitize=object-size -fsanitize=float-divide-by-zero \
 
26
        -fsanitize=float-cast-overflow -fsanitize=nonnull-attribute \
 
27
        -fsanitize=returns-nonnull-attribute -fsanitize=bool \
 
28
        -fsanitize=enum -fsanitize-address-use-after-scope
 
29
 
 
30
# For info about _FORTIFY_SOURCE, see feature_test_macros(7)
 
31
# and <https://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>.
 
32
FORTIFY:=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIC
 
33
LINK_FORTIFY_LD:=-z relro -z now
 
34
LINK_FORTIFY:=
 
35
 
 
36
# If BROKEN_PIE is set, do not build with -pie
 
37
ifndef BROKEN_PIE
 
38
FORTIFY += -fPIE
 
39
LINK_FORTIFY += -pie
 
40
endif
15
41
#COVERAGE=--coverage
16
 
OPTIMIZE=-Os
17
 
LANGUAGE=-std=gnu99
18
 
htmldir=man
19
 
version=1.0.5
20
 
SED=sed
 
42
OPTIMIZE:=-Os -fno-strict-aliasing
 
43
LANGUAGE:=-std=gnu11
 
44
FEATURES:=-D_FILE_OFFSET_BITS=64
 
45
htmldir:=man
 
46
version:=1.8.6
 
47
SED:=sed
 
48
PKG_CONFIG?=pkg-config
 
49
 
 
50
USER:=$(firstword $(subst :, ,$(shell getent passwd _mandos \
 
51
        || getent passwd nobody || echo 65534)))
 
52
GROUP:=$(firstword $(subst :, ,$(shell getent group _mandos \
 
53
        || getent group nogroup || echo 65534)))
 
54
 
 
55
LINUXVERSION:=$(shell uname --kernel-release)
21
56
 
22
57
## Use these settings for a traditional /usr/local install
23
 
# PREFIX=$(DESTDIR)/usr/local
24
 
# CONFDIR=$(DESTDIR)/etc/mandos
25
 
# KEYDIR=$(DESTDIR)/etc/mandos/keys
26
 
# MANDIR=$(PREFIX)/man
27
 
# INITRAMFSTOOLS=$(DESTDIR)/etc/initramfs-tools
 
58
# PREFIX:=$(DESTDIR)/usr/local
 
59
# CONFDIR:=$(DESTDIR)/etc/mandos
 
60
# KEYDIR:=$(DESTDIR)/etc/mandos/keys
 
61
# MANDIR:=$(PREFIX)/man
 
62
# INITRAMFSTOOLS:=$(DESTDIR)/etc/initramfs-tools
 
63
# DRACUTMODULE:=$(DESTDIR)/usr/lib/dracut/modules.d/90mandos
 
64
# STATEDIR:=$(DESTDIR)/var/lib/mandos
 
65
# LIBDIR:=$(PREFIX)/lib
28
66
##
29
67
 
30
68
## These settings are for a package-type install
31
 
PREFIX=$(DESTDIR)/usr
32
 
CONFDIR=$(DESTDIR)/etc/mandos
33
 
KEYDIR=$(DESTDIR)/etc/keys/mandos
34
 
MANDIR=$(PREFIX)/share/man
35
 
INITRAMFSTOOLS=$(DESTDIR)/usr/share/initramfs-tools
 
69
PREFIX:=$(DESTDIR)/usr
 
70
CONFDIR:=$(DESTDIR)/etc/mandos
 
71
KEYDIR:=$(DESTDIR)/etc/keys/mandos
 
72
MANDIR:=$(PREFIX)/share/man
 
73
INITRAMFSTOOLS:=$(DESTDIR)/usr/share/initramfs-tools
 
74
DRACUTMODULE:=$(DESTDIR)/usr/lib/dracut/modules.d/90mandos
 
75
STATEDIR:=$(DESTDIR)/var/lib/mandos
 
76
LIBDIR:=$(shell \
 
77
        for d in \
 
78
        "/usr/lib/`dpkg-architecture \
 
79
                        -qDEB_HOST_MULTIARCH 2>/dev/null`" \
 
80
        "`rpm --eval='%{_libdir}' 2>/dev/null`" /usr/lib; do \
 
81
                if [ -d "$$d" -a "$$d" = "$${d%/}" ]; then \
 
82
                        echo "$(DESTDIR)$$d"; \
 
83
                        break; \
 
84
                fi; \
 
85
        done)
36
86
##
37
87
 
38
 
GNUTLS_CFLAGS=$(shell libgnutls-config --cflags)
39
 
GNUTLS_LIBS=$(shell libgnutls-config --libs)
40
 
AVAHI_CFLAGS=$(shell pkg-config --cflags-only-I avahi-core)
41
 
AVAHI_LIBS=$(shell pkg-config --libs avahi-core)
42
 
GPGME_CFLAGS=$(shell gpgme-config --cflags)
43
 
GPGME_LIBS=$(shell gpgme-config --libs)
 
88
SYSTEMD:=$(DESTDIR)$(shell $(PKG_CONFIG) systemd \
 
89
                        --variable=systemdsystemunitdir)
 
90
TMPFILES:=$(DESTDIR)$(shell $(PKG_CONFIG) systemd \
 
91
                        --variable=tmpfilesdir)
 
92
 
 
93
GNUTLS_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I gnutls)
 
94
GNUTLS_LIBS:=$(shell $(PKG_CONFIG) --libs gnutls)
 
95
AVAHI_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I avahi-core)
 
96
AVAHI_LIBS:=$(shell $(PKG_CONFIG) --libs avahi-core)
 
97
GPGME_CFLAGS:=$(shell gpgme-config --cflags; getconf LFS_CFLAGS)
 
98
GPGME_LIBS:=$(shell gpgme-config --libs; getconf LFS_LIBS; \
 
99
        getconf LFS_LDFLAGS)
 
100
LIBNL3_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I libnl-route-3.0)
 
101
LIBNL3_LIBS:=$(shell $(PKG_CONFIG) --libs libnl-route-3.0)
 
102
GLIB_CFLAGS:=$(shell $(PKG_CONFIG) --cflags glib-2.0)
 
103
GLIB_LIBS:=$(shell $(PKG_CONFIG) --libs glib-2.0)
44
104
 
45
105
# Do not change these two
46
 
CFLAGS=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
47
 
        $(LANGUAGE) $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(GPGME_CFLAGS) \
48
 
        -DVERSION='"$(version)"'
49
 
LDFLAGS=$(COVERAGE) $(LINK_FORTIFY) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
 
106
CFLAGS+=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
 
107
        $(LANGUAGE) $(FEATURES) -DVERSION='"$(version)"'
 
108
LDFLAGS+=-Xlinker --as-needed $(COVERAGE) $(LINK_FORTIFY) $(strip \
 
109
        ) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
50
110
 
51
111
# Commands to format a DocBook <refentry> document into a manual page
52
 
DOCBOOKTOMAN=cd $(dir $<); xsltproc --nonet --xinclude \
 
112
DOCBOOKTOMAN=$(strip cd $(dir $<); xsltproc --nonet --xinclude \
53
113
        --param man.charmap.use.subset          0 \
54
114
        --param make.year.ranges                1 \
55
115
        --param make.single.year.ranges         1 \
56
116
        --param man.output.quietly              1 \
57
117
        --param man.authors.section.enabled     0 \
58
 
         /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
 
118
        /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
59
119
        $(notdir $<); \
60
 
        $(MANPOST) $(notdir $@)
61
 
# DocBook-to-man post-processing to fix a '\n' escape bug
62
 
MANPOST=$(SED) --in-place --expression='s,\\\\en,\\en,g;s,\\n,\\en,g'
 
120
        if locale --all 2>/dev/null | grep --regexp='^en_US\.utf8$$' \
 
121
        && command -v man >/dev/null; then LANG=en_US.UTF-8 \
 
122
        MANWIDTH=80 man --warnings --encoding=UTF-8 --local-file \
 
123
        $(notdir $@); fi >/dev/null)
63
124
 
64
 
DOCBOOKTOHTML=xsltproc --nonet --xinclude \
 
125
DOCBOOKTOHTML=$(strip xsltproc --nonet --xinclude \
65
126
        --param make.year.ranges                1 \
66
127
        --param make.single.year.ranges         1 \
67
128
        --param man.output.quietly              1 \
69
130
        --param citerefentry.link               1 \
70
131
        --output $@ \
71
132
        /usr/share/xml/docbook/stylesheet/nwalsh/xhtml/docbook.xsl \
72
 
        $<; $(HTMLPOST) $@
 
133
        $<; $(HTMLPOST) $@)
73
134
# Fix citerefentry links
74
 
HTMLPOST=$(SED) --in-place \
 
135
HTMLPOST:=$(SED) --in-place \
75
136
        --expression='s/\(<a class="citerefentry" href="\)\("><span class="citerefentry"><span class="refentrytitle">\)\([^<]*\)\(<\/span>(\)\([^)]*\)\()<\/span><\/a>\)/\1\3.\5\2\3\4\5\6/g'
76
137
 
77
 
PLUGINS=plugins.d/password-prompt plugins.d/mandos-client \
78
 
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo
79
 
CPROGS=plugin-runner $(PLUGINS)
80
 
PROGS=mandos mandos-keygen mandos-ctl $(CPROGS)
81
 
DOCS=mandos.8 plugin-runner.8mandos mandos-keygen.8 \
 
138
PLUGINS:=plugins.d/password-prompt plugins.d/mandos-client \
 
139
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo \
 
140
        plugins.d/plymouth
 
141
PLUGIN_HELPERS:=plugin-helpers/mandos-client-iprouteadddel
 
142
CPROGS:=plugin-runner dracut-module/password-agent $(PLUGINS) \
 
143
        $(PLUGIN_HELPERS)
 
144
PROGS:=mandos mandos-keygen mandos-ctl mandos-monitor $(CPROGS)
 
145
DOCS:=mandos.8 mandos-keygen.8 mandos-monitor.8 mandos-ctl.8 \
 
146
        mandos.conf.5 mandos-clients.conf.5 plugin-runner.8mandos \
 
147
        dracut-module/password-agent.8mandos \
82
148
        plugins.d/mandos-client.8mandos \
83
 
        plugins.d/password-prompt.8mandos mandos.conf.5 \
84
 
        plugins.d/usplash.8mandos plugins.d/splashy.8mandos \
85
 
        plugins.d/askpass-fifo.8mandos mandos-clients.conf.5
86
 
 
87
 
htmldocs=$(addsuffix .xhtml,$(DOCS))
88
 
 
89
 
objects=$(addsuffix .o,$(CPROGS))
 
149
        plugins.d/password-prompt.8mandos plugins.d/usplash.8mandos \
 
150
        plugins.d/splashy.8mandos plugins.d/askpass-fifo.8mandos \
 
151
        plugins.d/plymouth.8mandos intro.8mandos
 
152
 
 
153
htmldocs:=$(addsuffix .xhtml,$(DOCS))
 
154
 
 
155
objects:=$(addsuffix .o,$(CPROGS))
90
156
 
91
157
all: $(PROGS) mandos.lsm
92
158
 
109
175
%.8mandos.xhtml: %.xml common.ent legalnotice.xml
110
176
        $(DOCBOOKTOHTML)
111
177
 
 
178
intro.8mandos: intro.xml common.ent legalnotice.xml
 
179
        $(DOCBOOKTOMAN)
 
180
intro.8mandos.xhtml: intro.xml common.ent legalnotice.xml
 
181
        $(DOCBOOKTOHTML)
 
182
 
112
183
mandos.8: mandos.xml common.ent mandos-options.xml overview.xml \
113
184
                legalnotice.xml
114
185
        $(DOCBOOKTOMAN)
123
194
                 legalnotice.xml
124
195
        $(DOCBOOKTOHTML)
125
196
 
 
197
mandos-monitor.8: mandos-monitor.xml common.ent overview.xml \
 
198
                legalnotice.xml
 
199
        $(DOCBOOKTOMAN)
 
200
mandos-monitor.8.xhtml: mandos-monitor.xml common.ent overview.xml \
 
201
                 legalnotice.xml
 
202
        $(DOCBOOKTOHTML)
 
203
 
 
204
mandos-ctl.8: mandos-ctl.xml common.ent overview.xml \
 
205
                legalnotice.xml
 
206
        $(DOCBOOKTOMAN)
 
207
mandos-ctl.8.xhtml: mandos-ctl.xml common.ent overview.xml \
 
208
                 legalnotice.xml
 
209
        $(DOCBOOKTOHTML)
 
210
 
126
211
mandos.conf.5: mandos.conf.xml common.ent mandos-options.xml \
127
212
                legalnotice.xml
128
213
        $(DOCBOOKTOMAN)
137
222
                overview.xml legalnotice.xml
138
223
        $(DOCBOOKTOHTML)
139
224
 
 
225
dracut-module/password-agent.8mandos: \
 
226
                dracut-module/password-agent.xml common.ent \
 
227
                overview.xml legalnotice.xml
 
228
        $(DOCBOOKTOMAN)
 
229
dracut-module/password-agent.8mandos.xhtml: \
 
230
                dracut-module/password-agent.xml common.ent \
 
231
                overview.xml legalnotice.xml
 
232
        $(DOCBOOKTOHTML)
 
233
 
140
234
plugins.d/mandos-client.8mandos: plugins.d/mandos-client.xml \
141
235
                                        common.ent \
142
236
                                        mandos-options.xml \
150
244
 
151
245
# Update all these files with version number $(version)
152
246
common.ent: Makefile
153
 
        $(SED) --in-place \
154
 
                --expression='s/^\(<ENTITY VERSION "\)[^"]*">$$/\1$(version)"/' \
155
 
                $@
 
247
        $(strip $(SED) --in-place \
 
248
                --expression='s/^\(<!ENTITY version "\)[^"]*">$$/\1$(version)">/' \
 
249
                $@)
156
250
 
157
251
mandos: Makefile
158
 
        $(SED) --in-place \
 
252
        $(strip $(SED) --in-place \
159
253
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
160
 
                $@
 
254
                $@)
161
255
 
162
256
mandos-keygen: Makefile
163
 
        $(SED) --in-place \
 
257
        $(strip $(SED) --in-place \
164
258
                --expression='s/^\(VERSION="\)[^"]*"$$/\1$(version)"/' \
165
 
                $@
 
259
                $@)
166
260
 
167
261
mandos-ctl: Makefile
168
 
        $(SED) --in-place \
169
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
170
 
                $@
 
262
        $(strip $(SED) --in-place \
 
263
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
 
264
                $@)
 
265
 
 
266
mandos-monitor: Makefile
 
267
        $(strip $(SED) --in-place \
 
268
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
 
269
                $@)
171
270
 
172
271
mandos.lsm: Makefile
173
 
        $(SED) --in-place \
 
272
        $(strip $(SED) --in-place \
174
273
                --expression='s/^\(Version:\).*/\1\t$(version)/' \
175
 
                $@
176
 
        $(SED) --in-place \
 
274
                $@)
 
275
        $(strip $(SED) --in-place \
177
276
                --expression='s/^\(Entered-date:\).*/\1\t$(shell date --rfc-3339=date --reference=Makefile)/' \
178
 
                $@
179
 
        $(SED) --in-place \
 
277
                $@)
 
278
        $(strip $(SED) --in-place \
180
279
                --expression='s/\(mandos_\)[0-9.]\+\(\.orig\.tar\.gz\)/\1$(version)\2/' \
181
 
                $@
182
 
 
183
 
plugins.d/mandos-client: plugins.d/mandos-client.o
184
 
        $(LINK.o) $(GNUTLS_LIBS) $(AVAHI_LIBS) $(GPGME_LIBS) \
185
 
                $(COMMON) $^ $(LOADLIBES) $(LDLIBS) -o $@
186
 
 
187
 
.PHONY : all doc html clean distclean run-client run-server install \
188
 
        install-server install-client uninstall uninstall-server \
189
 
        uninstall-client purge purge-server purge-client
 
280
                $@)
 
281
 
 
282
# Need to add the GnuTLS, Avahi and GPGME libraries
 
283
plugins.d/mandos-client: plugins.d/mandos-client.c
 
284
        $(LINK.c) $^ $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(strip\
 
285
                ) $(GPGME_CFLAGS) $(GNUTLS_LIBS) $(strip\
 
286
                ) $(AVAHI_LIBS) $(GPGME_LIBS) $(LOADLIBES) $(strip\
 
287
                ) $(LDLIBS) -o $@
 
288
 
 
289
# Need to add the libnl-route library
 
290
plugin-helpers/mandos-client-iprouteadddel: plugin-helpers/mandos-client-iprouteadddel.c
 
291
        $(LINK.c) $(LIBNL3_CFLAGS) $^ $(LIBNL3_LIBS) $(strip\
 
292
                ) $(LOADLIBES) $(LDLIBS) -o $@
 
293
 
 
294
# Need to add the GLib and pthread libraries
 
295
dracut-module/password-agent: dracut-module/password-agent.c
 
296
        $(LINK.c) $(GLIB_CFLAGS) $^ $(GLIB_LIBS) -lpthread $(strip\
 
297
                ) $(LOADLIBES) $(LDLIBS) -o $@
 
298
 
 
299
.PHONY : all doc html clean distclean mostlyclean maintainer-clean \
 
300
        check run-client run-server install install-html \
 
301
        install-server install-client-nokey install-client uninstall \
 
302
        uninstall-server uninstall-client purge purge-server \
 
303
        purge-client
190
304
 
191
305
clean:
192
306
        -rm --force $(CPROGS) $(objects) $(htmldocs) $(DOCS) core
194
308
distclean: clean
195
309
mostlyclean: clean
196
310
maintainer-clean: clean
197
 
        -rm --force --recursive keydir confdir
 
311
        -rm --force --recursive keydir confdir statedir
198
312
 
199
 
check:  all
 
313
check: all
200
314
        ./mandos --check
 
315
        ./mandos-ctl --check
 
316
        ./mandos-keygen --version
 
317
        ./plugin-runner --version
 
318
        ./plugin-helpers/mandos-client-iprouteadddel --version
 
319
        ./dracut-module/password-agent --test
201
320
 
202
321
# Run the client with a local config and key
203
 
run-client: all keydir/seckey.txt keydir/pubkey.txt
 
322
run-client: all keydir/seckey.txt keydir/pubkey.txt \
 
323
                        keydir/tls-privkey.pem keydir/tls-pubkey.pem
 
324
        @echo '######################################################'
 
325
        @echo '# The following error messages are harmless and can  #'
 
326
        @echo '#  be safely ignored:                                #'
 
327
        @echo '## From plugin-runner:                               #'
 
328
        @echo '# setgid: Operation not permitted                    #'
 
329
        @echo '# setuid: Operation not permitted                    #'
 
330
        @echo '## From askpass-fifo:                                #'
 
331
        @echo '# mkfifo: Permission denied                          #'
 
332
        @echo '## From mandos-client:                               #'
 
333
        @echo '# Failed to raise privileges: Operation not permi... #'
 
334
        @echo '# Warning: network hook "*" exited with status *     #'
 
335
        @echo '# ioctl SIOCSIFFLAGS +IFF_UP: Operation not permi... #'
 
336
        @echo '# Failed to bring up interface "*": Operation not... #'
 
337
        @echo '#                                                    #'
 
338
        @echo '# (The messages are caused by not running as root,   #'
 
339
        @echo '# but you should NOT run "make run-client" as root   #'
 
340
        @echo '# unless you also unpacked and compiled Mandos as    #'
 
341
        @echo '# root, which is also NOT recommended.)              #'
 
342
        @echo '######################################################'
 
343
# We set GNOME_KEYRING_CONTROL to block pam_gnome_keyring
204
344
        ./plugin-runner --plugin-dir=plugins.d \
 
345
                --plugin-helper-dir=plugin-helpers \
205
346
                --config-file=plugin-runner.conf \
206
 
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt \
 
347
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt,--tls-privkey=keydir/tls-privkey.pem,--tls-pubkey=keydir/tls-pubkey.pem,--network-hook-dir=network-hooks.d \
 
348
                --env-for=mandos-client:GNOME_KEYRING_CONTROL= \
207
349
                $(CLIENTARGS)
208
350
 
209
351
# Used by run-client
210
 
keydir/seckey.txt keydir/pubkey.txt: mandos-keygen
 
352
keydir/seckey.txt keydir/pubkey.txt keydir/tls-privkey.pem keydir/tls-pubkey.pem: mandos-keygen
211
353
        install --directory keydir
212
354
        ./mandos-keygen --dir keydir --force
213
355
 
214
356
# Run the server with a local config
215
 
run-server: confdir/mandos.conf confdir/clients.conf
216
 
        ./mandos --debug --no-dbus --configdir=confdir $(SERVERARGS)
 
357
run-server: confdir/mandos.conf confdir/clients.conf statedir
 
358
        ./mandos --debug --no-dbus --configdir=confdir \
 
359
                --statedir=statedir $(SERVERARGS)
217
360
 
218
361
# Used by run-server
219
362
confdir/mandos.conf: mandos.conf
220
363
        install --directory confdir
221
364
        install --mode=u=rw,go=r $^ $@
222
 
confdir/clients.conf: clients.conf keydir/seckey.txt
 
365
confdir/clients.conf: clients.conf keydir/seckey.txt keydir/tls-pubkey.pem
223
366
        install --directory confdir
224
367
        install --mode=u=rw $< $@
225
368
# Add a client password
226
 
        ./mandos-keygen --dir keydir --password >> $@
 
369
        ./mandos-keygen --dir keydir --password --no-ssh >> $@
 
370
statedir:
 
371
        install --directory statedir
227
372
 
228
373
install: install-server install-client-nokey
229
374
 
234
379
 
235
380
install-server: doc
236
381
        install --directory $(CONFDIR)
 
382
        if install --directory --mode=u=rwx --owner=$(USER) \
 
383
                --group=$(GROUP) $(STATEDIR); then \
 
384
                :; \
 
385
        elif install --directory --mode=u=rwx $(STATEDIR); then \
 
386
                chown -- $(USER):$(GROUP) $(STATEDIR) || :; \
 
387
        fi
 
388
        if [ "$(TMPFILES)" != "$(DESTDIR)" \
 
389
                        -a -d "$(TMPFILES)" ]; then \
 
390
                install --mode=u=rw,go=r tmpfiles.d-mandos.conf \
 
391
                        $(TMPFILES)/mandos.conf; \
 
392
        fi
237
393
        install --mode=u=rwx,go=rx mandos $(PREFIX)/sbin/mandos
 
394
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
 
395
                mandos-ctl
 
396
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
 
397
                mandos-monitor
238
398
        install --mode=u=rw,go=r --target-directory=$(CONFDIR) \
239
399
                mandos.conf
240
400
        install --mode=u=rw --target-directory=$(CONFDIR) \
241
401
                clients.conf
 
402
        install --mode=u=rw,go=r dbus-mandos.conf \
 
403
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
242
404
        install --mode=u=rwx,go=rx init.d-mandos \
243
405
                $(DESTDIR)/etc/init.d/mandos
 
406
        if [ "$(SYSTEMD)" != "$(DESTDIR)" -a -d "$(SYSTEMD)" ]; then \
 
407
                install --mode=u=rw,go=r mandos.service $(SYSTEMD); \
 
408
        fi
244
409
        install --mode=u=rw,go=r default-mandos \
245
410
                $(DESTDIR)/etc/default/mandos
246
411
        if [ -z $(DESTDIR) ]; then \
248
413
        fi
249
414
        gzip --best --to-stdout mandos.8 \
250
415
                > $(MANDIR)/man8/mandos.8.gz
 
416
        gzip --best --to-stdout mandos-monitor.8 \
 
417
                > $(MANDIR)/man8/mandos-monitor.8.gz
 
418
        gzip --best --to-stdout mandos-ctl.8 \
 
419
                > $(MANDIR)/man8/mandos-ctl.8.gz
251
420
        gzip --best --to-stdout mandos.conf.5 \
252
421
                > $(MANDIR)/man5/mandos.conf.5.gz
253
422
        gzip --best --to-stdout mandos-clients.conf.5 \
254
423
                > $(MANDIR)/man5/mandos-clients.conf.5.gz
 
424
        gzip --best --to-stdout intro.8mandos \
 
425
                > $(MANDIR)/man8/intro.8mandos.gz
255
426
 
256
427
install-client-nokey: all doc
257
 
        install --directory $(PREFIX)/lib/mandos $(CONFDIR)
 
428
        install --directory $(LIBDIR)/mandos $(CONFDIR)
258
429
        install --directory --mode=u=rwx $(KEYDIR) \
259
 
                $(PREFIX)/lib/mandos/plugins.d
260
 
        if [ "$(CONFDIR)" != "$(PREFIX)/lib/mandos" ]; then \
 
430
                $(LIBDIR)/mandos/plugins.d \
 
431
                $(LIBDIR)/mandos/plugin-helpers
 
432
        if [ "$(CONFDIR)" != "$(LIBDIR)/mandos" ]; then \
261
433
                install --mode=u=rwx \
262
 
                        --directory "$(CONFDIR)/plugins.d"; \
 
434
                        --directory "$(CONFDIR)/plugins.d" \
 
435
                        "$(CONFDIR)/plugin-helpers"; \
263
436
        fi
264
 
        install --mode=u=rwx,go=rx \
265
 
                --target-directory=$(PREFIX)/lib/mandos plugin-runner
 
437
        install --mode=u=rwx,go=rx --directory \
 
438
                "$(CONFDIR)/network-hooks.d"
 
439
        install --mode=u=rwx,go=rx \
 
440
                --target-directory=$(LIBDIR)/mandos plugin-runner
 
441
        install --mode=u=rwx,go=rx \
 
442
                --target-directory=$(LIBDIR)/mandos \
 
443
                mandos-to-cryptroot-unlock
266
444
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
267
445
                mandos-keygen
268
446
        install --mode=u=rwx,go=rx \
269
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
447
                --target-directory=$(LIBDIR)/mandos/plugins.d \
270
448
                plugins.d/password-prompt
271
449
        install --mode=u=rwxs,go=rx \
272
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
450
                --target-directory=$(LIBDIR)/mandos/plugins.d \
273
451
                plugins.d/mandos-client
274
452
        install --mode=u=rwxs,go=rx \
275
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
453
                --target-directory=$(LIBDIR)/mandos/plugins.d \
276
454
                plugins.d/usplash
277
455
        install --mode=u=rwxs,go=rx \
278
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
456
                --target-directory=$(LIBDIR)/mandos/plugins.d \
279
457
                plugins.d/splashy
280
458
        install --mode=u=rwxs,go=rx \
281
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
 
459
                --target-directory=$(LIBDIR)/mandos/plugins.d \
282
460
                plugins.d/askpass-fifo
 
461
        install --mode=u=rwxs,go=rx \
 
462
                --target-directory=$(LIBDIR)/mandos/plugins.d \
 
463
                plugins.d/plymouth
 
464
        install --mode=u=rwx,go=rx \
 
465
                --target-directory=$(LIBDIR)/mandos/plugin-helpers \
 
466
                plugin-helpers/mandos-client-iprouteadddel
283
467
        install initramfs-tools-hook \
284
468
                $(INITRAMFSTOOLS)/hooks/mandos
285
 
        install --mode=u=rw,go=r initramfs-tools-hook-conf \
286
 
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos
 
469
        install --mode=u=rw,go=r initramfs-tools-conf \
 
470
                $(INITRAMFSTOOLS)/conf.d/mandos-conf
 
471
        install --mode=u=rw,go=r initramfs-tools-conf-hook \
 
472
                $(INITRAMFSTOOLS)/conf-hooks.d/zz-mandos
287
473
        install initramfs-tools-script \
288
 
                $(INITRAMFSTOOLS)/scripts/local-top/mandos
 
474
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos
 
475
        install initramfs-tools-script-stop \
 
476
                $(INITRAMFSTOOLS)/scripts/local-premount/mandos
 
477
        install --directory $(DRACUTMODULE)
 
478
        install --mode=u=rw,go=r --target-directory=$(DRACUTMODULE) \
 
479
                dracut-module/ask-password-mandos.path \
 
480
                dracut-module/ask-password-mandos.service
 
481
        install --mode=u=rwxs,go=rx \
 
482
                --target-directory=$(DRACUTMODULE) \
 
483
                dracut-module/module-setup.sh \
 
484
                dracut-module/cmdline-mandos.sh \
 
485
                dracut-module/password-agent
289
486
        install --mode=u=rw,go=r plugin-runner.conf $(CONFDIR)
290
487
        gzip --best --to-stdout mandos-keygen.8 \
291
488
                > $(MANDIR)/man8/mandos-keygen.8.gz
292
489
        gzip --best --to-stdout plugin-runner.8mandos \
293
490
                > $(MANDIR)/man8/plugin-runner.8mandos.gz
 
491
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
 
492
                > $(MANDIR)/man8/mandos-client.8mandos.gz
294
493
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
295
494
                > $(MANDIR)/man8/password-prompt.8mandos.gz
296
 
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
297
 
                > $(MANDIR)/man8/mandos-client.8mandos.gz
298
495
        gzip --best --to-stdout plugins.d/usplash.8mandos \
299
496
                > $(MANDIR)/man8/usplash.8mandos.gz
300
497
        gzip --best --to-stdout plugins.d/splashy.8mandos \
301
498
                > $(MANDIR)/man8/splashy.8mandos.gz
302
499
        gzip --best --to-stdout plugins.d/askpass-fifo.8mandos \
303
500
                > $(MANDIR)/man8/askpass-fifo.8mandos.gz
 
501
        gzip --best --to-stdout plugins.d/plymouth.8mandos \
 
502
                > $(MANDIR)/man8/plymouth.8mandos.gz
 
503
        gzip --best --to-stdout dracut-module/password-agent.8mandos \
 
504
                > $(MANDIR)/man8/password-agent.8mandos.gz
304
505
 
305
506
install-client: install-client-nokey
306
507
# Post-installation stuff
307
508
        -$(PREFIX)/sbin/mandos-keygen --dir "$(KEYDIR)"
308
 
        update-initramfs -k all -u
 
509
        if command -v update-initramfs >/dev/null; then \
 
510
            update-initramfs -k all -u; \
 
511
        elif command -v dracut >/dev/null; then \
 
512
            for initrd in $(DESTDIR)/boot/initr*-$(LINUXVERSION); do \
 
513
                if [ -w "$$initrd" ]; then \
 
514
                    chmod go-r "$$initrd"; \
 
515
                    dracut --force "$$initrd"; \
 
516
                fi; \
 
517
            done; \
 
518
        fi
309
519
        echo "Now run mandos-keygen --password --dir $(KEYDIR)"
310
520
 
311
521
uninstall: uninstall-server uninstall-client
312
522
 
313
523
uninstall-server:
314
524
        -rm --force $(PREFIX)/sbin/mandos \
 
525
                $(PREFIX)/sbin/mandos-ctl \
 
526
                $(PREFIX)/sbin/mandos-monitor \
315
527
                $(MANDIR)/man8/mandos.8.gz \
 
528
                $(MANDIR)/man8/mandos-monitor.8.gz \
 
529
                $(MANDIR)/man8/mandos-ctl.8.gz \
316
530
                $(MANDIR)/man5/mandos.conf.5.gz \
317
531
                $(MANDIR)/man5/mandos-clients.conf.5.gz
318
532
        update-rc.d -f mandos remove
324
538
        ! grep --regexp='^ *[^ #].*keyscript=[^,=]*/mandos/' \
325
539
                $(DESTDIR)/etc/crypttab
326
540
        -rm --force $(PREFIX)/sbin/mandos-keygen \
327
 
                $(PREFIX)/lib/mandos/plugin-runner \
328
 
                $(PREFIX)/lib/mandos/plugins.d/password-prompt \
329
 
                $(PREFIX)/lib/mandos/plugins.d/mandos-client \
330
 
                $(PREFIX)/lib/mandos/plugins.d/usplash \
331
 
                $(PREFIX)/lib/mandos/plugins.d/splashy \
332
 
                $(PREFIX)/lib/mandos/plugins.d/askpass-fifo \
 
541
                $(LIBDIR)/mandos/plugin-runner \
 
542
                $(LIBDIR)/mandos/plugins.d/password-prompt \
 
543
                $(LIBDIR)/mandos/plugins.d/mandos-client \
 
544
                $(LIBDIR)/mandos/plugins.d/usplash \
 
545
                $(LIBDIR)/mandos/plugins.d/splashy \
 
546
                $(LIBDIR)/mandos/plugins.d/askpass-fifo \
 
547
                $(LIBDIR)/mandos/plugins.d/plymouth \
333
548
                $(INITRAMFSTOOLS)/hooks/mandos \
334
549
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos \
335
 
                $(INITRAMFSTOOLS)/scripts/local-top/mandos \
 
550
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos \
 
551
                $(INITRAMFSTOOLS)/scripts/local-premount/mandos \
 
552
                $(DRACUTMODULE)/ask-password-mandos.path \
 
553
                $(DRACUTMODULE)/ask-password-mandos.service \
 
554
                $(DRACUTMODULE)/module-setup.sh \
 
555
                $(DRACUTMODULE)/cmdline-mandos.sh \
 
556
                $(DRACUTMODULE)/password-agent \
 
557
                $(MANDIR)/man8/mandos-keygen.8.gz \
336
558
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
337
 
                $(MANDIR)/man8/mandos-keygen.8.gz \
 
559
                $(MANDIR)/man8/mandos-client.8mandos.gz
338
560
                $(MANDIR)/man8/password-prompt.8mandos.gz \
339
561
                $(MANDIR)/man8/usplash.8mandos.gz \
340
562
                $(MANDIR)/man8/splashy.8mandos.gz \
341
563
                $(MANDIR)/man8/askpass-fifo.8mandos.gz \
342
 
                $(MANDIR)/man8/mandos-client.8mandos.gz
343
 
        -rmdir $(PREFIX)/lib/mandos/plugins.d $(CONFDIR)/plugins.d \
344
 
                 $(PREFIX)/lib/mandos $(CONFDIR) $(KEYDIR)
345
 
        update-initramfs -k all -u
 
564
                $(MANDIR)/man8/plymouth.8mandos.gz \
 
565
                $(MANDIR)/man8/password-agent.8mandos.gz \
 
566
        -rmdir $(LIBDIR)/mandos/plugins.d $(CONFDIR)/plugins.d \
 
567
                 $(LIBDIR)/mandos $(CONFDIR) $(KEYDIR) $(DRACUTMODULE)
 
568
        if command -v update-initramfs >/dev/null; then \
 
569
            update-initramfs -k all -u; \
 
570
        elif command -v dracut >/dev/null; then \
 
571
            for initrd in $(DESTDIR)/boot/initr*-$(LINUXVERSION); do \
 
572
                test -w "$$initrd" && dracut --force "$$initrd"; \
 
573
            done; \
 
574
        fi
346
575
 
347
576
purge: purge-server purge-client
348
577
 
349
578
purge-server: uninstall-server
350
579
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf \
 
580
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
351
581
                $(DESTDIR)/etc/default/mandos \
352
582
                $(DESTDIR)/etc/init.d/mandos \
 
583
                $(SYSTEMD)/mandos.service \
 
584
                $(DESTDIR)/run/mandos.pid \
353
585
                $(DESTDIR)/var/run/mandos.pid
354
586
        -rmdir $(CONFDIR)
355
587
 
356
588
purge-client: uninstall-client
357
 
        -shred --remove $(KEYDIR)/seckey.txt
 
589
        -shred --remove $(KEYDIR)/seckey.txt $(KEYDIR)/tls-privkey.pem
358
590
        -rm --force $(CONFDIR)/plugin-runner.conf \
359
 
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt
 
591
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt \
 
592
                $(KEYDIR)/tls-pubkey.txt $(KEYDIR)/tls-privkey.txt
360
593
        -rmdir $(KEYDIR) $(CONFDIR)/plugins.d $(CONFDIR)