/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to Makefile

  • Committer: Björn Påhlsson
  • Date: 2008-07-20 02:52:20 UTC
  • Revision ID: belorn@braxen-20080720025220-r5u0388uy9iu23h6
Added following support:
Pluginbased client handler
rewritten Mandos client
       Avahi instead of udp server discovery
       openpgp encrypted key support
Passprompt stand alone application for direct console input
Added logging for Mandos server

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
WARN=-O -Wall -Wformat=2 -Winit-self -Wmissing-include-dirs \
2
 
        -Wswitch-default -Wswitch-enum -Wunused-parameter \
3
 
        -Wstrict-aliasing=1 -Wextra -Wfloat-equal -Wundef -Wshadow \
4
 
        -Wunsafe-loop-optimizations -Wpointer-arith \
5
 
        -Wbad-function-cast -Wcast-qual -Wcast-align -Wwrite-strings \
6
 
        -Wconversion -Wstrict-prototypes -Wold-style-definition \
7
 
        -Wpacked -Wnested-externs -Winline -Wvolatile-register-var
8
 
#       -Wunreachable-code 
9
 
#DEBUG=-ggdb3
10
 
# For info about _FORTIFY_SOURCE, see
11
 
# <http://www.kernel.org/doc/man-pages/online/pages/man7/feature_test_macros.7.html>
12
 
# and <http://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>.
13
 
FORTIFY=-D_FORTIFY_SOURCE=2 -fstack-protector-all -fPIC
14
 
LINK_FORTIFY_LD=-z relro -z now
15
 
LINK_FORTIFY=
16
 
 
17
 
# If BROKEN_PIE is set, do not build with -pie
18
 
ifndef BROKEN_PIE
19
 
FORTIFY += -fPIE
20
 
LINK_FORTIFY_LD += -fPIE
21
 
LINK_FORTIFY += -pie
22
 
endif
23
 
#COVERAGE=--coverage
24
 
OPTIMIZE=-Os
25
 
LANGUAGE=-std=gnu99
26
 
htmldir=man
27
 
version=1.0.14
28
 
SED=sed
29
 
 
30
 
## Use these settings for a traditional /usr/local install
31
 
# PREFIX=$(DESTDIR)/usr/local
32
 
# CONFDIR=$(DESTDIR)/etc/mandos
33
 
# KEYDIR=$(DESTDIR)/etc/mandos/keys
34
 
# MANDIR=$(PREFIX)/man
35
 
# INITRAMFSTOOLS=$(DESTDIR)/etc/initramfs-tools
36
 
##
37
 
 
38
 
## These settings are for a package-type install
39
 
PREFIX=$(DESTDIR)/usr
40
 
CONFDIR=$(DESTDIR)/etc/mandos
41
 
KEYDIR=$(DESTDIR)/etc/keys/mandos
42
 
MANDIR=$(PREFIX)/share/man
43
 
INITRAMFSTOOLS=$(DESTDIR)/usr/share/initramfs-tools
44
 
##
45
 
 
46
 
GNUTLS_CFLAGS=$(shell pkg-config --cflags-only-I gnutls)
47
 
GNUTLS_LIBS=$(shell pkg-config --libs gnutls)
48
 
AVAHI_CFLAGS=$(shell pkg-config --cflags-only-I avahi-core)
49
 
AVAHI_LIBS=$(shell pkg-config --libs avahi-core)
50
 
GPGME_CFLAGS=$(shell gpgme-config --cflags; getconf LFS_CFLAGS)
51
 
GPGME_LIBS=$(shell gpgme-config --libs; getconf LFS_LIBS; \
52
 
        getconf LFS_LDFLAGS)
53
 
 
54
 
# Do not change these two
55
 
CFLAGS=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
56
 
        $(LANGUAGE) $(GNUTLS_CFLAGS) $(AVAHI_CFLAGS) $(GPGME_CFLAGS) \
57
 
        -DVERSION='"$(version)"'
58
 
LDFLAGS=$(COVERAGE) $(LINK_FORTIFY) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
59
 
 
60
 
# Commands to format a DocBook <refentry> document into a manual page
61
 
DOCBOOKTOMAN=$(strip cd $(dir $<); xsltproc --nonet --xinclude \
62
 
        --param man.charmap.use.subset          0 \
63
 
        --param make.year.ranges                1 \
64
 
        --param make.single.year.ranges         1 \
65
 
        --param man.output.quietly              1 \
66
 
        --param man.authors.section.enabled     0 \
67
 
         /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
68
 
        $(notdir $<); \
69
 
        $(MANPOST) $(notdir $@))
70
 
# DocBook-to-man post-processing to fix a '\n' escape bug
71
 
MANPOST=$(SED) --in-place --expression='s,\\\\en,\\en,g;s,\\n,\\en,g'
72
 
 
73
 
DOCBOOKTOHTML=$(strip xsltproc --nonet --xinclude \
74
 
        --param make.year.ranges                1 \
75
 
        --param make.single.year.ranges         1 \
76
 
        --param man.output.quietly              1 \
77
 
        --param man.authors.section.enabled     0 \
78
 
        --param citerefentry.link               1 \
79
 
        --output $@ \
80
 
        /usr/share/xml/docbook/stylesheet/nwalsh/xhtml/docbook.xsl \
81
 
        $<; $(HTMLPOST) $@)
82
 
# Fix citerefentry links
83
 
HTMLPOST=$(SED) --in-place \
84
 
        --expression='s/\(<a class="citerefentry" href="\)\("><span class="citerefentry"><span class="refentrytitle">\)\([^<]*\)\(<\/span>(\)\([^)]*\)\()<\/span><\/a>\)/\1\3.\5\2\3\4\5\6/g'
85
 
 
86
 
PLUGINS=plugins.d/password-prompt plugins.d/mandos-client \
87
 
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo
88
 
CPROGS=plugin-runner $(PLUGINS)
89
 
PROGS=mandos mandos-keygen mandos-ctl $(CPROGS)
90
 
DOCS=mandos.8 plugin-runner.8mandos mandos-keygen.8 \
91
 
        plugins.d/mandos-client.8mandos \
92
 
        plugins.d/password-prompt.8mandos mandos.conf.5 \
93
 
        plugins.d/usplash.8mandos plugins.d/splashy.8mandos \
94
 
        plugins.d/askpass-fifo.8mandos mandos-clients.conf.5
95
 
 
96
 
htmldocs=$(addsuffix .xhtml,$(DOCS))
97
 
 
98
 
objects=$(addsuffix .o,$(CPROGS))
99
 
 
100
 
all: $(PROGS) mandos.lsm
101
 
 
102
 
doc: $(DOCS)
103
 
 
104
 
html: $(htmldocs)
105
 
 
106
 
%.5: %.xml common.ent legalnotice.xml
107
 
        $(DOCBOOKTOMAN)
108
 
%.5.xhtml: %.xml common.ent legalnotice.xml
109
 
        $(DOCBOOKTOHTML)
110
 
 
111
 
%.8: %.xml common.ent legalnotice.xml
112
 
        $(DOCBOOKTOMAN)
113
 
%.8.xhtml: %.xml common.ent legalnotice.xml
114
 
        $(DOCBOOKTOHTML)
115
 
 
116
 
%.8mandos: %.xml common.ent legalnotice.xml
117
 
        $(DOCBOOKTOMAN)
118
 
%.8mandos.xhtml: %.xml common.ent legalnotice.xml
119
 
        $(DOCBOOKTOHTML)
120
 
 
121
 
mandos.8: mandos.xml common.ent mandos-options.xml overview.xml \
122
 
                legalnotice.xml
123
 
        $(DOCBOOKTOMAN)
124
 
mandos.8.xhtml: mandos.xml common.ent mandos-options.xml \
125
 
                overview.xml legalnotice.xml
126
 
        $(DOCBOOKTOHTML)
127
 
 
128
 
mandos-keygen.8: mandos-keygen.xml common.ent overview.xml \
129
 
                legalnotice.xml
130
 
        $(DOCBOOKTOMAN)
131
 
mandos-keygen.8.xhtml: mandos-keygen.xml common.ent overview.xml \
132
 
                 legalnotice.xml
133
 
        $(DOCBOOKTOHTML)
134
 
 
135
 
mandos.conf.5: mandos.conf.xml common.ent mandos-options.xml \
136
 
                legalnotice.xml
137
 
        $(DOCBOOKTOMAN)
138
 
mandos.conf.5.xhtml: mandos.conf.xml common.ent mandos-options.xml \
139
 
                legalnotice.xml
140
 
        $(DOCBOOKTOHTML)
141
 
 
142
 
plugin-runner.8mandos: plugin-runner.xml common.ent overview.xml \
143
 
                legalnotice.xml
144
 
        $(DOCBOOKTOMAN)
145
 
plugin-runner.8mandos.xhtml: plugin-runner.xml common.ent \
146
 
                overview.xml legalnotice.xml
147
 
        $(DOCBOOKTOHTML)
148
 
 
149
 
plugins.d/mandos-client.8mandos: plugins.d/mandos-client.xml \
150
 
                                        common.ent \
151
 
                                        mandos-options.xml \
152
 
                                        overview.xml legalnotice.xml
153
 
        $(DOCBOOKTOMAN)
154
 
plugins.d/mandos-client.8mandos.xhtml: plugins.d/mandos-client.xml \
155
 
                                        common.ent \
156
 
                                        mandos-options.xml \
157
 
                                        overview.xml legalnotice.xml
158
 
        $(DOCBOOKTOHTML)
159
 
 
160
 
# Update all these files with version number $(version)
161
 
common.ent: Makefile
162
 
        $(strip $(SED) --in-place \
163
 
                --expression='s/^\(<!ENTITY version "\)[^"]*">$$/\1$(version)">/' \
164
 
                $@)
165
 
 
166
 
mandos: Makefile
167
 
        $(strip $(SED) --in-place \
168
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
169
 
                $@)
170
 
 
171
 
mandos-keygen: Makefile
172
 
        $(strip $(SED) --in-place \
173
 
                --expression='s/^\(VERSION="\)[^"]*"$$/\1$(version)"/' \
174
 
                $@)
175
 
 
176
 
mandos-ctl: Makefile
177
 
        $(strip $(SED) --in-place \
178
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
179
 
                $@)
180
 
 
181
 
mandos.lsm: Makefile
182
 
        $(strip $(SED) --in-place \
183
 
                --expression='s/^\(Version:\).*/\1\t$(version)/' \
184
 
                $@)
185
 
        $(strip $(SED) --in-place \
186
 
                --expression='s/^\(Entered-date:\).*/\1\t$(shell date --rfc-3339=date --reference=Makefile)/' \
187
 
                $@)
188
 
        $(strip $(SED) --in-place \
189
 
                --expression='s/\(mandos_\)[0-9.]\+\(\.orig\.tar\.gz\)/\1$(version)\2/' \
190
 
                $@)
191
 
 
192
 
plugins.d/mandos-client: plugins.d/mandos-client.c
193
 
        $(LINK.c) $(GNUTLS_LIBS) $(AVAHI_LIBS) $(GPGME_LIBS) $(strip\
194
 
                ) $(COMMON) $^ $(LOADLIBES) $(LDLIBS) -o $@
195
 
 
196
 
.PHONY : all doc html clean distclean run-client run-server install \
197
 
        install-server install-client uninstall uninstall-server \
198
 
        uninstall-client purge purge-server purge-client
 
1
CFLAGS="-Wall -std=gnu99"
 
2
LDFLAGS=-lgnutls
 
3
 
 
4
all: plugbasedclient
199
5
 
200
6
clean:
201
 
        -rm --force $(CPROGS) $(objects) $(htmldocs) $(DOCS) core
202
 
 
203
 
distclean: clean
204
 
mostlyclean: clean
205
 
maintainer-clean: clean
206
 
        -rm --force --recursive keydir confdir
207
 
 
208
 
check:  all
209
 
        ./mandos --check
210
 
 
211
 
# Run the client with a local config and key
212
 
run-client: all keydir/seckey.txt keydir/pubkey.txt
213
 
        ./plugin-runner --plugin-dir=plugins.d \
214
 
                --config-file=plugin-runner.conf \
215
 
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt \
216
 
                $(CLIENTARGS)
217
 
 
218
 
# Used by run-client
219
 
keydir/seckey.txt keydir/pubkey.txt: mandos-keygen
220
 
        install --directory keydir
221
 
        ./mandos-keygen --dir keydir --force
222
 
 
223
 
# Run the server with a local config
224
 
run-server: confdir/mandos.conf confdir/clients.conf
225
 
        ./mandos --debug --no-dbus --configdir=confdir $(SERVERARGS)
226
 
 
227
 
# Used by run-server
228
 
confdir/mandos.conf: mandos.conf
229
 
        install --directory confdir
230
 
        install --mode=u=rw,go=r $^ $@
231
 
confdir/clients.conf: clients.conf keydir/seckey.txt
232
 
        install --directory confdir
233
 
        install --mode=u=rw $< $@
234
 
# Add a client password
235
 
        ./mandos-keygen --dir keydir --password >> $@
236
 
 
237
 
install: install-server install-client-nokey
238
 
 
239
 
install-html: html
240
 
        install --directory $(htmldir)
241
 
        install --mode=u=rw,go=r --target-directory=$(htmldir) \
242
 
                $(htmldocs)
243
 
 
244
 
install-server: doc
245
 
        install --directory $(CONFDIR)
246
 
        install --mode=u=rwx,go=rx mandos $(PREFIX)/sbin/mandos
247
 
        install --mode=u=rw,go=r --target-directory=$(CONFDIR) \
248
 
                mandos.conf
249
 
        install --mode=u=rw --target-directory=$(CONFDIR) \
250
 
                clients.conf
251
 
        install --mode=u=rwx,go=rx init.d-mandos \
252
 
                $(DESTDIR)/etc/init.d/mandos
253
 
        install --mode=u=rw,go=r default-mandos \
254
 
                $(DESTDIR)/etc/default/mandos
255
 
        if [ -z $(DESTDIR) ]; then \
256
 
                update-rc.d mandos defaults 25 15;\
257
 
        fi
258
 
        gzip --best --to-stdout mandos.8 \
259
 
                > $(MANDIR)/man8/mandos.8.gz
260
 
        gzip --best --to-stdout mandos.conf.5 \
261
 
                > $(MANDIR)/man5/mandos.conf.5.gz
262
 
        gzip --best --to-stdout mandos-clients.conf.5 \
263
 
                > $(MANDIR)/man5/mandos-clients.conf.5.gz
264
 
 
265
 
install-client-nokey: all doc
266
 
        install --directory $(PREFIX)/lib/mandos $(CONFDIR)
267
 
        install --directory --mode=u=rwx $(KEYDIR) \
268
 
                $(PREFIX)/lib/mandos/plugins.d
269
 
        if [ "$(CONFDIR)" != "$(PREFIX)/lib/mandos" ]; then \
270
 
                install --mode=u=rwx \
271
 
                        --directory "$(CONFDIR)/plugins.d"; \
272
 
        fi
273
 
        install --mode=u=rwx,go=rx \
274
 
                --target-directory=$(PREFIX)/lib/mandos plugin-runner
275
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
276
 
                mandos-keygen
277
 
        install --mode=u=rwx,go=rx \
278
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
279
 
                plugins.d/password-prompt
280
 
        install --mode=u=rwxs,go=rx \
281
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
282
 
                plugins.d/mandos-client
283
 
        install --mode=u=rwxs,go=rx \
284
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
285
 
                plugins.d/usplash
286
 
        install --mode=u=rwxs,go=rx \
287
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
288
 
                plugins.d/splashy
289
 
        install --mode=u=rwxs,go=rx \
290
 
                --target-directory=$(PREFIX)/lib/mandos/plugins.d \
291
 
                plugins.d/askpass-fifo
292
 
        install initramfs-tools-hook \
293
 
                $(INITRAMFSTOOLS)/hooks/mandos
294
 
        install --mode=u=rw,go=r initramfs-tools-hook-conf \
295
 
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos
296
 
        install initramfs-tools-script \
297
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos
298
 
        install --mode=u=rw,go=r plugin-runner.conf $(CONFDIR)
299
 
        gzip --best --to-stdout mandos-keygen.8 \
300
 
                > $(MANDIR)/man8/mandos-keygen.8.gz
301
 
        gzip --best --to-stdout plugin-runner.8mandos \
302
 
                > $(MANDIR)/man8/plugin-runner.8mandos.gz
303
 
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
304
 
                > $(MANDIR)/man8/password-prompt.8mandos.gz
305
 
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
306
 
                > $(MANDIR)/man8/mandos-client.8mandos.gz
307
 
        gzip --best --to-stdout plugins.d/usplash.8mandos \
308
 
                > $(MANDIR)/man8/usplash.8mandos.gz
309
 
        gzip --best --to-stdout plugins.d/splashy.8mandos \
310
 
                > $(MANDIR)/man8/splashy.8mandos.gz
311
 
        gzip --best --to-stdout plugins.d/askpass-fifo.8mandos \
312
 
                > $(MANDIR)/man8/askpass-fifo.8mandos.gz
313
 
 
314
 
install-client: install-client-nokey
315
 
# Post-installation stuff
316
 
        -$(PREFIX)/sbin/mandos-keygen --dir "$(KEYDIR)"
317
 
        update-initramfs -k all -u
318
 
        echo "Now run mandos-keygen --password --dir $(KEYDIR)"
319
 
 
320
 
uninstall: uninstall-server uninstall-client
321
 
 
322
 
uninstall-server:
323
 
        -rm --force $(PREFIX)/sbin/mandos \
324
 
                $(MANDIR)/man8/mandos.8.gz \
325
 
                $(MANDIR)/man5/mandos.conf.5.gz \
326
 
                $(MANDIR)/man5/mandos-clients.conf.5.gz
327
 
        update-rc.d -f mandos remove
328
 
        -rmdir $(CONFDIR)
329
 
 
330
 
uninstall-client:
331
 
# Refuse to uninstall client if /etc/crypttab is explicitly configured
332
 
# to use it.
333
 
        ! grep --regexp='^ *[^ #].*keyscript=[^,=]*/mandos/' \
334
 
                $(DESTDIR)/etc/crypttab
335
 
        -rm --force $(PREFIX)/sbin/mandos-keygen \
336
 
                $(PREFIX)/lib/mandos/plugin-runner \
337
 
                $(PREFIX)/lib/mandos/plugins.d/password-prompt \
338
 
                $(PREFIX)/lib/mandos/plugins.d/mandos-client \
339
 
                $(PREFIX)/lib/mandos/plugins.d/usplash \
340
 
                $(PREFIX)/lib/mandos/plugins.d/splashy \
341
 
                $(PREFIX)/lib/mandos/plugins.d/askpass-fifo \
342
 
                $(INITRAMFSTOOLS)/hooks/mandos \
343
 
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos \
344
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos \
345
 
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
346
 
                $(MANDIR)/man8/mandos-keygen.8.gz \
347
 
                $(MANDIR)/man8/password-prompt.8mandos.gz \
348
 
                $(MANDIR)/man8/usplash.8mandos.gz \
349
 
                $(MANDIR)/man8/splashy.8mandos.gz \
350
 
                $(MANDIR)/man8/askpass-fifo.8mandos.gz \
351
 
                $(MANDIR)/man8/mandos-client.8mandos.gz
352
 
        -rmdir $(PREFIX)/lib/mandos/plugins.d $(CONFDIR)/plugins.d \
353
 
                 $(PREFIX)/lib/mandos $(CONFDIR) $(KEYDIR)
354
 
        update-initramfs -k all -u
355
 
 
356
 
purge: purge-server purge-client
357
 
 
358
 
purge-server: uninstall-server
359
 
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf \
360
 
                $(DESTDIR)/etc/default/mandos \
361
 
                $(DESTDIR)/etc/init.d/mandos \
362
 
                $(DESTDIR)/var/run/mandos.pid
363
 
        -rmdir $(CONFDIR)
364
 
 
365
 
purge-client: uninstall-client
366
 
        -shred --remove $(KEYDIR)/seckey.txt
367
 
        -rm --force $(CONFDIR)/plugin-runner.conf \
368
 
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt
369
 
        -rmdir $(KEYDIR) $(CONFDIR)/plugins.d $(CONFDIR)
 
7
        rm -f plugbasedclient
 
8
 
 
9
client_debug: client
 
10
        mv -f client client.tmp
 
11
        $(MAKE) client CXXFLAGS="$(CXXFLAGS) -DDEBUG -DCERT_ROOT=\\\"./\\\""
 
12
        mv client client_debug
 
13
        mv client.tmp client