/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to Makefile

  • Committer: Teddy Hogeborn
  • Date: 2008-07-20 06:33:48 UTC
  • Revision ID: teddy@fukt.bsnet.se-20080720063348-jscgy5p0itrgvlo8
* mandos-clients.conf ([foo]): Uncommented.
  ([foo]/secret): New.
  ([foo]/secfile): Commented out.
  ([foo]/checker): Changed to "fping -q -- %%(fqdn)s".
  ([foo]/timeout): New.

* server.py: New modeline for Python and Emacs.  Set a logging format.
  (Client.__init__): Bug fix: Choose either the value from the options
                     object or pass the argument through string_to_delta
                     for both "timeout" and "interval".
  (Client.checker_callback): Bug fix: Do not log spurious "Checker for
                             <foo> failed" messages.
  (Client.start_checker): Moved "Starting checker" log message down to
                          just before actually starting the subprocess.
                          Do not redirect the subprocesses' stdout to a
                          pipe.
  (peer_certificate, fingerprint): Added docstrings.
  (entry_group_state_changed): Call "killme()" instead of
                               "main_loop.quit()".
  (daemon, killme): New functions.
  (exitstatus, main_loop_started): New global variables.
  (__main__): Removed the "--cert", "--key", "--ca", and "--crl"
              options.  Removed the sleep command from the default
              checker.  Add a console logger in debug mode.  Call
              "killme()" instead of "main_loop.quit()" when there are no
              more clients.  Call "daemon()" if not in debug mode.
              Register "cleanup()" to run at exit.  Ignore some
              signals.  Catch DBusException to detect another running
              server and exit cleanly.  Exit with "exitstatus".
  (cleanup): New function.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
WARN:=-O -Wall -Wextra -Wdouble-promotion -Wformat=2 -Winit-self \
2
 
        -Wmissing-include-dirs -Wswitch-default -Wswitch-enum \
3
 
        -Wunused -Wuninitialized -Wstrict-overflow=5 \
4
 
        -Wsuggest-attribute=pure -Wsuggest-attribute=const \
5
 
        -Wsuggest-attribute=noreturn -Wfloat-equal -Wundef -Wshadow \
6
 
        -Wunsafe-loop-optimizations -Wpointer-arith \
7
 
        -Wbad-function-cast -Wcast-qual -Wcast-align -Wwrite-strings \
8
 
        -Wconversion -Wlogical-op -Waggregate-return \
9
 
        -Wstrict-prototypes -Wold-style-definition \
10
 
        -Wmissing-format-attribute -Wnormalized=nfc -Wpacked \
11
 
        -Wredundant-decls -Wnested-externs -Winline -Wvla \
12
 
        -Wvolatile-register-var -Woverlength-strings
13
 
 
14
 
#DEBUG:=-ggdb3 -fsanitize=address $(SANITIZE)
15
 
## Check which sanitizing options can be used
16
 
#SANITIZE:=$(foreach option,$(ALL_SANITIZE_OPTIONS),$(shell \
17
 
#       echo 'int main(){}' | $(CC) --language=c $(option) \
18
 
#       /dev/stdin -o /dev/null >/dev/null 2>&1 && echo $(option)))
19
 
# <https://developerblog.redhat.com/2014/10/16/gcc-undefined-behavior-sanitizer-ubsan/>
20
 
ALL_SANITIZE_OPTIONS:=-fsanitize=leak -fsanitize=undefined \
21
 
        -fsanitize=shift -fsanitize=integer-divide-by-zero \
22
 
        -fsanitize=unreachable -fsanitize=vla-bound -fsanitize=null \
23
 
        -fsanitize=return -fsanitize=signed-integer-overflow \
24
 
        -fsanitize=bounds -fsanitize=alignment \
25
 
        -fsanitize=object-size -fsanitize=float-divide-by-zero \
26
 
        -fsanitize=float-cast-overflow -fsanitize=nonnull-attribute \
27
 
        -fsanitize=returns-nonnull-attribute -fsanitize=bool \
28
 
        -fsanitize=enum -fsanitize-address-use-after-scope
29
 
 
30
 
# For info about _FORTIFY_SOURCE, see feature_test_macros(7)
31
 
# and <https://gcc.gnu.org/ml/gcc-patches/2004-09/msg02055.html>.
32
 
FORTIFY:=-D_FORTIFY_SOURCE=3 -fstack-protector-all -fPIC
33
 
LINK_FORTIFY_LD:=-z relro -z now
34
 
LINK_FORTIFY:=
35
 
 
36
 
# If BROKEN_PIE is set, do not build with -pie
37
 
ifndef BROKEN_PIE
38
 
FORTIFY += -fPIE
39
 
LINK_FORTIFY += -pie
40
 
endif
41
 
#COVERAGE=--coverage
42
 
OPTIMIZE:=-Os -fno-strict-aliasing
43
 
LANGUAGE:=-std=gnu11
44
 
FEATURES:=-D_FILE_OFFSET_BITS=64
45
 
htmldir:=man
46
 
version:=1.8.15
47
 
SED:=sed
48
 
PKG_CONFIG?=pkg-config
49
 
 
50
 
USER:=$(firstword $(subst :, ,$(shell getent passwd _mandos \
51
 
        || getent passwd nobody || echo 65534)))
52
 
GROUP:=$(firstword $(subst :, ,$(shell getent group _mandos \
53
 
        || getent group nogroup || echo 65534)))
54
 
 
55
 
LINUXVERSION:=$(shell uname --kernel-release)
56
 
 
57
 
## Use these settings for a traditional /usr/local install
58
 
# PREFIX:=$(DESTDIR)/usr/local
59
 
# CONFDIR:=$(DESTDIR)/etc/mandos
60
 
# KEYDIR:=$(DESTDIR)/etc/mandos/keys
61
 
# MANDIR:=$(PREFIX)/man
62
 
# INITRAMFSTOOLS:=$(DESTDIR)/etc/initramfs-tools
63
 
# DRACUTMODULE:=$(DESTDIR)/usr/lib/dracut/modules.d/90mandos
64
 
# STATEDIR:=$(DESTDIR)/var/lib/mandos
65
 
# LIBDIR:=$(PREFIX)/lib
66
 
##
67
 
 
68
 
## These settings are for a package-type install
69
 
PREFIX:=$(DESTDIR)/usr
70
 
CONFDIR:=$(DESTDIR)/etc/mandos
71
 
KEYDIR:=$(DESTDIR)/etc/keys/mandos
72
 
MANDIR:=$(PREFIX)/share/man
73
 
INITRAMFSTOOLS:=$(DESTDIR)/usr/share/initramfs-tools
74
 
DRACUTMODULE:=$(DESTDIR)/usr/lib/dracut/modules.d/90mandos
75
 
STATEDIR:=$(DESTDIR)/var/lib/mandos
76
 
LIBDIR:=$(shell \
77
 
        for d in \
78
 
        "/usr/lib/`dpkg-architecture \
79
 
                        -qDEB_HOST_MULTIARCH 2>/dev/null`" \
80
 
        "`rpm --eval='%{_libdir}' 2>/dev/null`" /usr/lib; do \
81
 
                if [ -d "$$d" -a "$$d" = "$${d%/}" ]; then \
82
 
                        echo "$(DESTDIR)$$d"; \
83
 
                        break; \
84
 
                fi; \
85
 
        done)
86
 
##
87
 
 
88
 
SYSTEMD:=$(DESTDIR)$(shell $(PKG_CONFIG) systemd \
89
 
                        --variable=systemdsystemunitdir)
90
 
TMPFILES:=$(DESTDIR)$(shell $(PKG_CONFIG) systemd \
91
 
                        --variable=tmpfilesdir)
92
 
SYSUSERS:=$(DESTDIR)$(shell $(PKG_CONFIG) systemd \
93
 
                        --variable=sysusersdir)
94
 
 
95
 
GNUTLS_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I gnutls)
96
 
GNUTLS_LIBS:=$(shell $(PKG_CONFIG) --libs gnutls)
97
 
AVAHI_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I avahi-core)
98
 
AVAHI_LIBS:=$(shell $(PKG_CONFIG) --libs avahi-core)
99
 
GPGME_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I gpgme 2>/dev/null \
100
 
        || gpgme-config --cflags; getconf LFS_CFLAGS)
101
 
GPGME_LIBS:=$(shell $(PKG_CONFIG) --libs gpgme 2>/dev/null \
102
 
        || gpgme-config --libs; getconf LFS_LIBS; \
103
 
        getconf LFS_LDFLAGS)
104
 
LIBNL3_CFLAGS:=$(shell $(PKG_CONFIG) --cflags-only-I libnl-route-3.0)
105
 
LIBNL3_LIBS:=$(shell $(PKG_CONFIG) --libs libnl-route-3.0)
106
 
GLIB_CFLAGS:=$(shell $(PKG_CONFIG) --cflags glib-2.0)
107
 
GLIB_LIBS:=$(shell $(PKG_CONFIG) --libs glib-2.0)
108
 
 
109
 
# Do not change these two
110
 
CFLAGS+=$(WARN) $(DEBUG) $(FORTIFY) $(COVERAGE) $(OPTIMIZE) \
111
 
        $(LANGUAGE) $(FEATURES) -DVERSION='"$(version)"'
112
 
LDFLAGS+=-Xlinker --as-needed $(COVERAGE) $(LINK_FORTIFY) $(strip \
113
 
        ) $(foreach flag,$(LINK_FORTIFY_LD),-Xlinker $(flag))
114
 
 
115
 
# Commands to format a DocBook <refentry> document into a manual page
116
 
DOCBOOKTOMAN=$(strip cd $(dir $<); xsltproc --nonet --xinclude \
117
 
        --param man.charmap.use.subset          0 \
118
 
        --param make.year.ranges                1 \
119
 
        --param make.single.year.ranges         1 \
120
 
        --param man.output.quietly              1 \
121
 
        --param man.authors.section.enabled     0 \
122
 
        /usr/share/xml/docbook/stylesheet/nwalsh/manpages/docbook.xsl \
123
 
        $(notdir $<); \
124
 
        if locale --all 2>/dev/null | grep --regexp='^en_US\.utf8$$' \
125
 
        && command -v man >/dev/null; then LANG=en_US.UTF-8 \
126
 
        MANWIDTH=80 man --warnings --encoding=UTF-8 --local-file \
127
 
        $(notdir $@); fi >/dev/null)
128
 
 
129
 
DOCBOOKTOHTML=$(strip xsltproc --nonet --xinclude \
130
 
        --param make.year.ranges                1 \
131
 
        --param make.single.year.ranges         1 \
132
 
        --param man.output.quietly              1 \
133
 
        --param man.authors.section.enabled     0 \
134
 
        --param citerefentry.link               1 \
135
 
        --output $@ \
136
 
        /usr/share/xml/docbook/stylesheet/nwalsh/xhtml/docbook.xsl \
137
 
        $<; $(HTMLPOST) $@)
138
 
# Fix citerefentry links
139
 
HTMLPOST:=$(SED) --in-place \
140
 
        --expression='s/\(<a class="citerefentry" href="\)\("><span class="citerefentry"><span class="refentrytitle">\)\([^<]*\)\(<\/span>(\)\([^)]*\)\()<\/span><\/a>\)/\1\3.\5\2\3\4\5\6/g'
141
 
 
142
 
PLUGINS:=plugins.d/password-prompt plugins.d/mandos-client \
143
 
        plugins.d/usplash plugins.d/splashy plugins.d/askpass-fifo \
144
 
        plugins.d/plymouth
145
 
PLUGIN_HELPERS:=plugin-helpers/mandos-client-iprouteadddel
146
 
CPROGS:=plugin-runner dracut-module/password-agent $(PLUGINS) \
147
 
        $(PLUGIN_HELPERS)
148
 
PROGS:=mandos mandos-keygen mandos-ctl mandos-monitor $(CPROGS)
149
 
DOCS:=mandos.8 mandos-keygen.8 mandos-monitor.8 mandos-ctl.8 \
150
 
        mandos.conf.5 mandos-clients.conf.5 plugin-runner.8mandos \
151
 
        dracut-module/password-agent.8mandos \
152
 
        plugins.d/mandos-client.8mandos \
153
 
        plugins.d/password-prompt.8mandos plugins.d/usplash.8mandos \
154
 
        plugins.d/splashy.8mandos plugins.d/askpass-fifo.8mandos \
155
 
        plugins.d/plymouth.8mandos intro.8mandos
156
 
 
157
 
htmldocs:=$(addsuffix .xhtml,$(DOCS))
158
 
 
159
 
objects:=$(addsuffix .o,$(CPROGS))
160
 
 
161
 
.PHONY: all
162
 
all: $(PROGS) mandos.lsm
163
 
 
164
 
.PHONY: doc
165
 
doc: $(DOCS)
166
 
 
167
 
.PHONY: html
168
 
html: $(htmldocs)
169
 
 
170
 
%.5: %.xml common.ent legalnotice.xml
171
 
        $(DOCBOOKTOMAN)
172
 
%.5.xhtml: %.xml common.ent legalnotice.xml
173
 
        $(DOCBOOKTOHTML)
174
 
 
175
 
%.8: %.xml common.ent legalnotice.xml
176
 
        $(DOCBOOKTOMAN)
177
 
%.8.xhtml: %.xml common.ent legalnotice.xml
178
 
        $(DOCBOOKTOHTML)
179
 
 
180
 
%.8mandos: %.xml common.ent legalnotice.xml
181
 
        $(DOCBOOKTOMAN)
182
 
%.8mandos.xhtml: %.xml common.ent legalnotice.xml
183
 
        $(DOCBOOKTOHTML)
184
 
 
185
 
intro.8mandos: intro.xml common.ent legalnotice.xml
186
 
        $(DOCBOOKTOMAN)
187
 
intro.8mandos.xhtml: intro.xml common.ent legalnotice.xml
188
 
        $(DOCBOOKTOHTML)
189
 
 
190
 
mandos.8: mandos.xml common.ent mandos-options.xml overview.xml \
191
 
                legalnotice.xml
192
 
        $(DOCBOOKTOMAN)
193
 
mandos.8.xhtml: mandos.xml common.ent mandos-options.xml \
194
 
                overview.xml legalnotice.xml
195
 
        $(DOCBOOKTOHTML)
196
 
 
197
 
mandos-keygen.8: mandos-keygen.xml common.ent overview.xml \
198
 
                legalnotice.xml
199
 
        $(DOCBOOKTOMAN)
200
 
mandos-keygen.8.xhtml: mandos-keygen.xml common.ent overview.xml \
201
 
                 legalnotice.xml
202
 
        $(DOCBOOKTOHTML)
203
 
 
204
 
mandos-monitor.8: mandos-monitor.xml common.ent overview.xml \
205
 
                legalnotice.xml
206
 
        $(DOCBOOKTOMAN)
207
 
mandos-monitor.8.xhtml: mandos-monitor.xml common.ent overview.xml \
208
 
                 legalnotice.xml
209
 
        $(DOCBOOKTOHTML)
210
 
 
211
 
mandos-ctl.8: mandos-ctl.xml common.ent overview.xml \
212
 
                legalnotice.xml
213
 
        $(DOCBOOKTOMAN)
214
 
mandos-ctl.8.xhtml: mandos-ctl.xml common.ent overview.xml \
215
 
                 legalnotice.xml
216
 
        $(DOCBOOKTOHTML)
217
 
 
218
 
mandos.conf.5: mandos.conf.xml common.ent mandos-options.xml \
219
 
                legalnotice.xml
220
 
        $(DOCBOOKTOMAN)
221
 
mandos.conf.5.xhtml: mandos.conf.xml common.ent mandos-options.xml \
222
 
                legalnotice.xml
223
 
        $(DOCBOOKTOHTML)
224
 
 
225
 
plugin-runner.8mandos: plugin-runner.xml common.ent overview.xml \
226
 
                legalnotice.xml
227
 
        $(DOCBOOKTOMAN)
228
 
plugin-runner.8mandos.xhtml: plugin-runner.xml common.ent \
229
 
                overview.xml legalnotice.xml
230
 
        $(DOCBOOKTOHTML)
231
 
 
232
 
dracut-module/password-agent.8mandos: \
233
 
                dracut-module/password-agent.xml common.ent \
234
 
                overview.xml legalnotice.xml
235
 
        $(DOCBOOKTOMAN)
236
 
dracut-module/password-agent.8mandos.xhtml: \
237
 
                dracut-module/password-agent.xml common.ent \
238
 
                overview.xml legalnotice.xml
239
 
        $(DOCBOOKTOHTML)
240
 
 
241
 
plugins.d/mandos-client.8mandos: plugins.d/mandos-client.xml \
242
 
                                        common.ent \
243
 
                                        mandos-options.xml \
244
 
                                        overview.xml legalnotice.xml
245
 
        $(DOCBOOKTOMAN)
246
 
plugins.d/mandos-client.8mandos.xhtml: plugins.d/mandos-client.xml \
247
 
                                        common.ent \
248
 
                                        mandos-options.xml \
249
 
                                        overview.xml legalnotice.xml
250
 
        $(DOCBOOKTOHTML)
251
 
 
252
 
# Update all these files with version number $(version)
253
 
common.ent: Makefile
254
 
        $(strip $(SED) --in-place \
255
 
                --expression='s/^\(<!ENTITY version "\)[^"]*">$$/\1$(version)">/' \
256
 
                $@)
257
 
 
258
 
mandos: Makefile
259
 
        $(strip $(SED) --in-place \
260
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
261
 
                $@)
262
 
 
263
 
mandos-keygen: Makefile
264
 
        $(strip $(SED) --in-place \
265
 
                --expression='s/^\(VERSION="\)[^"]*"$$/\1$(version)"/' \
266
 
                $@)
267
 
 
268
 
mandos-ctl: Makefile
269
 
        $(strip $(SED) --in-place \
270
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
271
 
                $@)
272
 
 
273
 
mandos-monitor: Makefile
274
 
        $(strip $(SED) --in-place \
275
 
                --expression='s/^\(version = "\)[^"]*"$$/\1$(version)"/' \
276
 
                $@)
277
 
 
278
 
mandos.lsm: Makefile
279
 
        $(strip $(SED) --in-place \
280
 
                --expression='s/^\(Version:\).*/\1\t$(version)/' \
281
 
                $@)
282
 
        $(strip $(SED) --in-place \
283
 
                --expression='s/^\(Entered-date:\).*/\1\t$(shell date --rfc-3339=date --reference=Makefile)/' \
284
 
                $@)
285
 
        $(strip $(SED) --in-place \
286
 
                --expression='s/\(mandos_\)[0-9.]\+\(\.orig\.tar\.gz\)/\1$(version)\2/' \
287
 
                $@)
288
 
 
289
 
# Need to add the GnuTLS, Avahi and GPGME libraries
290
 
plugins.d/mandos-client: CFLAGS += $(GNUTLS_CFLAGS) $(strip \
291
 
        ) $(AVAHI_CFLAGS) $(GPGME_CFLAGS)
292
 
plugins.d/mandos-client: LDLIBS += $(GNUTLS_LIBS) $(strip \
293
 
        ) $(AVAHI_LIBS) $(GPGME_LIBS)
294
 
 
295
 
# Need to add the libnl-route library
296
 
plugin-helpers/mandos-client-iprouteadddel: CFLAGS += $(LIBNL3_CFLAGS)
297
 
plugin-helpers/mandos-client-iprouteadddel: LDLIBS += $(LIBNL3_LIBS)
298
 
 
299
 
# Need to add the GLib and pthread libraries
300
 
dracut-module/password-agent: CFLAGS += $(GLIB_CFLAGS)
301
 
# Note: -lpthread is unnecessary with the GNU C library 2.34 or later
302
 
dracut-module/password-agent: LDLIBS += $(GLIB_LIBS) -lpthread
303
 
 
304
 
.PHONY: clean
 
1
CFLAGS=-Wall -g -std=gnu99
 
2
LDFLAGS=-lgnutls
 
3
 
 
4
all: plugbasedclient
 
5
 
305
6
clean:
306
 
        -rm --force $(CPROGS) $(objects) $(htmldocs) $(DOCS) core
307
 
 
308
 
.PHONY: distclean
309
 
distclean: clean
310
 
.PHONY: mostlyclean
311
 
mostlyclean: clean
312
 
.PHONY: maintainer-clean
313
 
maintainer-clean: clean
314
 
        -rm --force --recursive keydir confdir statedir
315
 
 
316
 
.PHONY: check
317
 
check: all
318
 
        ./mandos --check
319
 
        ./mandos-ctl --check
320
 
        ./mandos-keygen --version
321
 
        ./plugin-runner --version
322
 
        ./plugin-helpers/mandos-client-iprouteadddel --version
323
 
        ./dracut-module/password-agent --test
324
 
 
325
 
# Run the client with a local config and key
326
 
.PHONY: run-client
327
 
run-client: all keydir/seckey.txt keydir/pubkey.txt \
328
 
                        keydir/tls-privkey.pem keydir/tls-pubkey.pem
329
 
        @echo '######################################################'
330
 
        @echo '# The following error messages are harmless and can  #'
331
 
        @echo '#  be safely ignored:                                #'
332
 
        @echo '## From plugin-runner:                               #'
333
 
        @echo '# setgid: Operation not permitted                    #'
334
 
        @echo '# setuid: Operation not permitted                    #'
335
 
        @echo '## From askpass-fifo:                                #'
336
 
        @echo '# mkfifo: Permission denied                          #'
337
 
        @echo '## From mandos-client:                               #'
338
 
        @echo '# Failed to raise privileges: Operation not permi... #'
339
 
        @echo '# Warning: network hook "*" exited with status *     #'
340
 
        @echo '# ioctl SIOCSIFFLAGS +IFF_UP: Operation not permi... #'
341
 
        @echo '# Failed to bring up interface "*": Operation not... #'
342
 
        @echo '#                                                    #'
343
 
        @echo '# (The messages are caused by not running as root,   #'
344
 
        @echo '# but you should NOT run "make run-client" as root   #'
345
 
        @echo '# unless you also unpacked and compiled Mandos as    #'
346
 
        @echo '# root, which is also NOT recommended.)              #'
347
 
        @echo '######################################################'
348
 
# We set GNOME_KEYRING_CONTROL to block pam_gnome_keyring
349
 
        ./plugin-runner --plugin-dir=plugins.d \
350
 
                --plugin-helper-dir=plugin-helpers \
351
 
                --config-file=plugin-runner.conf \
352
 
                --options-for=mandos-client:--seckey=keydir/seckey.txt,--pubkey=keydir/pubkey.txt,--tls-privkey=keydir/tls-privkey.pem,--tls-pubkey=keydir/tls-pubkey.pem,--network-hook-dir=network-hooks.d \
353
 
                --env-for=mandos-client:GNOME_KEYRING_CONTROL= \
354
 
                $(CLIENTARGS)
355
 
 
356
 
# Used by run-client
357
 
keydir/seckey.txt keydir/pubkey.txt keydir/tls-privkey.pem keydir/tls-pubkey.pem: mandos-keygen
358
 
        install --directory keydir
359
 
        ./mandos-keygen --dir keydir --force
360
 
        if ! [ -e keydir/tls-privkey.pem ]; then \
361
 
                install --mode=u=rw /dev/null keydir/tls-privkey.pem; \
362
 
        fi
363
 
        if ! [ -e keydir/tls-pubkey.pem ]; then \
364
 
                install --mode=u=rw /dev/null keydir/tls-pubkey.pem; \
365
 
        fi
366
 
 
367
 
# Run the server with a local config
368
 
.PHONY: run-server
369
 
run-server: confdir/mandos.conf confdir/clients.conf statedir
370
 
        ./mandos --debug --no-dbus --configdir=confdir \
371
 
                --statedir=statedir $(SERVERARGS)
372
 
 
373
 
# Used by run-server
374
 
confdir/mandos.conf: mandos.conf
375
 
        install --directory confdir
376
 
        install --mode=u=rw,go=r $^ $@
377
 
confdir/clients.conf: clients.conf keydir/seckey.txt keydir/tls-pubkey.pem
378
 
        install --directory confdir
379
 
        install --mode=u=rw $< $@
380
 
# Add a client password
381
 
        ./mandos-keygen --dir keydir --password --no-ssh >> $@
382
 
statedir:
383
 
        install --directory statedir
384
 
 
385
 
.PHONY: install
386
 
install: install-server install-client-nokey
387
 
 
388
 
.PHONY: install-html
389
 
install-html: html
390
 
        install --directory $(htmldir)
391
 
        install --mode=u=rw,go=r --target-directory=$(htmldir) \
392
 
                $(htmldocs)
393
 
 
394
 
.PHONY: install-server
395
 
install-server: doc
396
 
        install --directory $(CONFDIR)
397
 
        if install --directory --mode=u=rwx --owner=$(USER) \
398
 
                --group=$(GROUP) $(STATEDIR); then \
399
 
                :; \
400
 
        elif install --directory --mode=u=rwx $(STATEDIR); then \
401
 
                chown -- $(USER):$(GROUP) $(STATEDIR) || :; \
402
 
        fi
403
 
        if [ "$(TMPFILES)" != "$(DESTDIR)" \
404
 
                        -a -d "$(TMPFILES)" ]; then \
405
 
                install --mode=u=rw,go=r tmpfiles.d-mandos.conf \
406
 
                        $(TMPFILES)/mandos.conf; \
407
 
        fi
408
 
        if [ "$(SYSUSERS)" != "$(DESTDIR)" \
409
 
                        -a -d "$(SYSUSERS)" ]; then \
410
 
                install --mode=u=rw,go=r sysusers.d-mandos.conf \
411
 
                        $(SYSUSERS)/mandos.conf; \
412
 
        fi
413
 
        install --mode=u=rwx,go=rx mandos $(PREFIX)/sbin/mandos
414
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
415
 
                mandos-ctl
416
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
417
 
                mandos-monitor
418
 
        install --mode=u=rw,go=r --target-directory=$(CONFDIR) \
419
 
                mandos.conf
420
 
        install --mode=u=rw --target-directory=$(CONFDIR) \
421
 
                clients.conf
422
 
        install --mode=u=rw,go=r dbus-mandos.conf \
423
 
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
424
 
        install --mode=u=rwx,go=rx init.d-mandos \
425
 
                $(DESTDIR)/etc/init.d/mandos
426
 
        if [ "$(SYSTEMD)" != "$(DESTDIR)" -a -d "$(SYSTEMD)" ]; then \
427
 
                install --mode=u=rw,go=r mandos.service $(SYSTEMD); \
428
 
        fi
429
 
        install --mode=u=rw,go=r default-mandos \
430
 
                $(DESTDIR)/etc/default/mandos
431
 
        if [ -z $(DESTDIR) ]; then \
432
 
                update-rc.d mandos defaults 25 15;\
433
 
        fi
434
 
        gzip --best --to-stdout mandos.8 \
435
 
                > $(MANDIR)/man8/mandos.8.gz
436
 
        gzip --best --to-stdout mandos-monitor.8 \
437
 
                > $(MANDIR)/man8/mandos-monitor.8.gz
438
 
        gzip --best --to-stdout mandos-ctl.8 \
439
 
                > $(MANDIR)/man8/mandos-ctl.8.gz
440
 
        gzip --best --to-stdout mandos.conf.5 \
441
 
                > $(MANDIR)/man5/mandos.conf.5.gz
442
 
        gzip --best --to-stdout mandos-clients.conf.5 \
443
 
                > $(MANDIR)/man5/mandos-clients.conf.5.gz
444
 
        gzip --best --to-stdout intro.8mandos \
445
 
                > $(MANDIR)/man8/intro.8mandos.gz
446
 
 
447
 
.PHONY: install-client-nokey
448
 
install-client-nokey: all doc
449
 
        install --directory $(LIBDIR)/mandos $(CONFDIR)
450
 
        install --directory --mode=u=rwx $(KEYDIR) \
451
 
                $(LIBDIR)/mandos/plugins.d \
452
 
                $(LIBDIR)/mandos/plugin-helpers
453
 
        if [ "$(SYSUSERS)" != "$(DESTDIR)" \
454
 
                        -a -d "$(SYSUSERS)" ]; then \
455
 
                install --mode=u=rw,go=r sysusers.d-mandos.conf \
456
 
                        $(SYSUSERS)/mandos-client.conf; \
457
 
        fi
458
 
        if [ "$(CONFDIR)" != "$(LIBDIR)/mandos" ]; then \
459
 
                install --mode=u=rwx \
460
 
                        --directory "$(CONFDIR)/plugins.d" \
461
 
                        "$(CONFDIR)/plugin-helpers"; \
462
 
        fi
463
 
        install --mode=u=rwx,go=rx --directory \
464
 
                "$(CONFDIR)/network-hooks.d"
465
 
        install --mode=u=rwx,go=rx \
466
 
                --target-directory=$(LIBDIR)/mandos plugin-runner
467
 
        install --mode=u=rwx,go=rx \
468
 
                --target-directory=$(LIBDIR)/mandos \
469
 
                mandos-to-cryptroot-unlock
470
 
        install --mode=u=rwx,go=rx --target-directory=$(PREFIX)/sbin \
471
 
                mandos-keygen
472
 
        install --mode=u=rwx,go=rx \
473
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
474
 
                plugins.d/password-prompt
475
 
        install --mode=u=rwxs,go=rx \
476
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
477
 
                plugins.d/mandos-client
478
 
        install --mode=u=rwxs,go=rx \
479
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
480
 
                plugins.d/usplash
481
 
        install --mode=u=rwxs,go=rx \
482
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
483
 
                plugins.d/splashy
484
 
        install --mode=u=rwxs,go=rx \
485
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
486
 
                plugins.d/askpass-fifo
487
 
        install --mode=u=rwxs,go=rx \
488
 
                --target-directory=$(LIBDIR)/mandos/plugins.d \
489
 
                plugins.d/plymouth
490
 
        install --mode=u=rwx,go=rx \
491
 
                --target-directory=$(LIBDIR)/mandos/plugin-helpers \
492
 
                plugin-helpers/mandos-client-iprouteadddel
493
 
        install initramfs-tools-hook \
494
 
                $(INITRAMFSTOOLS)/hooks/mandos
495
 
        install --mode=u=rw,go=r initramfs-tools-conf \
496
 
                $(INITRAMFSTOOLS)/conf.d/mandos-conf
497
 
        install --mode=u=rw,go=r initramfs-tools-conf-hook \
498
 
                $(INITRAMFSTOOLS)/conf-hooks.d/zz-mandos
499
 
        install initramfs-tools-script \
500
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos
501
 
        install initramfs-tools-script-stop \
502
 
                $(INITRAMFSTOOLS)/scripts/local-premount/mandos
503
 
        install --directory $(DRACUTMODULE)
504
 
        install --mode=u=rw,go=r --target-directory=$(DRACUTMODULE) \
505
 
                dracut-module/ask-password-mandos.path \
506
 
                dracut-module/ask-password-mandos.service
507
 
        install --mode=u=rwxs,go=rx \
508
 
                --target-directory=$(DRACUTMODULE) \
509
 
                dracut-module/module-setup.sh \
510
 
                dracut-module/cmdline-mandos.sh \
511
 
                dracut-module/password-agent
512
 
        install --mode=u=rw,go=r plugin-runner.conf $(CONFDIR)
513
 
        gzip --best --to-stdout mandos-keygen.8 \
514
 
                > $(MANDIR)/man8/mandos-keygen.8.gz
515
 
        gzip --best --to-stdout plugin-runner.8mandos \
516
 
                > $(MANDIR)/man8/plugin-runner.8mandos.gz
517
 
        gzip --best --to-stdout plugins.d/mandos-client.8mandos \
518
 
                > $(MANDIR)/man8/mandos-client.8mandos.gz
519
 
        gzip --best --to-stdout plugins.d/password-prompt.8mandos \
520
 
                > $(MANDIR)/man8/password-prompt.8mandos.gz
521
 
        gzip --best --to-stdout plugins.d/usplash.8mandos \
522
 
                > $(MANDIR)/man8/usplash.8mandos.gz
523
 
        gzip --best --to-stdout plugins.d/splashy.8mandos \
524
 
                > $(MANDIR)/man8/splashy.8mandos.gz
525
 
        gzip --best --to-stdout plugins.d/askpass-fifo.8mandos \
526
 
                > $(MANDIR)/man8/askpass-fifo.8mandos.gz
527
 
        gzip --best --to-stdout plugins.d/plymouth.8mandos \
528
 
                > $(MANDIR)/man8/plymouth.8mandos.gz
529
 
        gzip --best --to-stdout dracut-module/password-agent.8mandos \
530
 
                > $(MANDIR)/man8/password-agent.8mandos.gz
531
 
 
532
 
.PHONY: install-client
533
 
install-client: install-client-nokey
534
 
# Post-installation stuff
535
 
        -$(PREFIX)/sbin/mandos-keygen --dir "$(KEYDIR)"
536
 
        if command -v update-initramfs >/dev/null; then \
537
 
            update-initramfs -k all -u; \
538
 
        elif command -v dracut >/dev/null; then \
539
 
            for initrd in $(DESTDIR)/boot/initr*-$(LINUXVERSION); do \
540
 
                if [ -w "$$initrd" ]; then \
541
 
                    chmod go-r "$$initrd"; \
542
 
                    dracut --force "$$initrd"; \
543
 
                fi; \
544
 
            done; \
545
 
        fi
546
 
        echo "Now run mandos-keygen --password --dir $(KEYDIR)"
547
 
 
548
 
.PHONY: uninstall
549
 
uninstall: uninstall-server uninstall-client
550
 
 
551
 
.PHONY: uninstall-server
552
 
uninstall-server:
553
 
        -rm --force $(PREFIX)/sbin/mandos \
554
 
                $(PREFIX)/sbin/mandos-ctl \
555
 
                $(PREFIX)/sbin/mandos-monitor \
556
 
                $(MANDIR)/man8/mandos.8.gz \
557
 
                $(MANDIR)/man8/mandos-monitor.8.gz \
558
 
                $(MANDIR)/man8/mandos-ctl.8.gz \
559
 
                $(MANDIR)/man5/mandos.conf.5.gz \
560
 
                $(MANDIR)/man5/mandos-clients.conf.5.gz
561
 
        update-rc.d -f mandos remove
562
 
        -rmdir $(CONFDIR)
563
 
 
564
 
.PHONY: uninstall-client
565
 
uninstall-client:
566
 
# Refuse to uninstall client if /etc/crypttab is explicitly configured
567
 
# to use it.
568
 
        ! grep --regexp='^ *[^ #].*keyscript=[^,=]*/mandos/' \
569
 
                $(DESTDIR)/etc/crypttab
570
 
        -rm --force $(PREFIX)/sbin/mandos-keygen \
571
 
                $(LIBDIR)/mandos/plugin-runner \
572
 
                $(LIBDIR)/mandos/plugins.d/password-prompt \
573
 
                $(LIBDIR)/mandos/plugins.d/mandos-client \
574
 
                $(LIBDIR)/mandos/plugins.d/usplash \
575
 
                $(LIBDIR)/mandos/plugins.d/splashy \
576
 
                $(LIBDIR)/mandos/plugins.d/askpass-fifo \
577
 
                $(LIBDIR)/mandos/plugins.d/plymouth \
578
 
                $(INITRAMFSTOOLS)/hooks/mandos \
579
 
                $(INITRAMFSTOOLS)/conf-hooks.d/mandos \
580
 
                $(INITRAMFSTOOLS)/scripts/init-premount/mandos \
581
 
                $(INITRAMFSTOOLS)/scripts/local-premount/mandos \
582
 
                $(DRACUTMODULE)/ask-password-mandos.path \
583
 
                $(DRACUTMODULE)/ask-password-mandos.service \
584
 
                $(DRACUTMODULE)/module-setup.sh \
585
 
                $(DRACUTMODULE)/cmdline-mandos.sh \
586
 
                $(DRACUTMODULE)/password-agent \
587
 
                $(MANDIR)/man8/mandos-keygen.8.gz \
588
 
                $(MANDIR)/man8/plugin-runner.8mandos.gz \
589
 
                $(MANDIR)/man8/mandos-client.8mandos.gz
590
 
                $(MANDIR)/man8/password-prompt.8mandos.gz \
591
 
                $(MANDIR)/man8/usplash.8mandos.gz \
592
 
                $(MANDIR)/man8/splashy.8mandos.gz \
593
 
                $(MANDIR)/man8/askpass-fifo.8mandos.gz \
594
 
                $(MANDIR)/man8/plymouth.8mandos.gz \
595
 
                $(MANDIR)/man8/password-agent.8mandos.gz \
596
 
        -rmdir $(LIBDIR)/mandos/plugins.d $(CONFDIR)/plugins.d \
597
 
                 $(LIBDIR)/mandos $(CONFDIR) $(KEYDIR) $(DRACUTMODULE)
598
 
        if command -v update-initramfs >/dev/null; then \
599
 
            update-initramfs -k all -u; \
600
 
        elif command -v dracut >/dev/null; then \
601
 
            for initrd in $(DESTDIR)/boot/initr*-$(LINUXVERSION); do \
602
 
                test -w "$$initrd" && dracut --force "$$initrd"; \
603
 
            done; \
604
 
        fi
605
 
 
606
 
.PHONY: purge
607
 
purge: purge-server purge-client
608
 
 
609
 
.PHONY: purge-server
610
 
purge-server: uninstall-server
611
 
        -rm --force $(CONFDIR)/mandos.conf $(CONFDIR)/clients.conf \
612
 
                $(DESTDIR)/etc/dbus-1/system.d/mandos.conf
613
 
                $(DESTDIR)/etc/default/mandos \
614
 
                $(DESTDIR)/etc/init.d/mandos \
615
 
                $(SYSTEMD)/mandos.service \
616
 
                $(DESTDIR)/run/mandos.pid \
617
 
                $(DESTDIR)/var/run/mandos.pid
618
 
        -rmdir $(CONFDIR)
619
 
 
620
 
.PHONY: purge-client
621
 
purge-client: uninstall-client
622
 
        -shred --remove $(KEYDIR)/seckey.txt $(KEYDIR)/tls-privkey.pem
623
 
        -rm --force $(CONFDIR)/plugin-runner.conf \
624
 
                $(KEYDIR)/pubkey.txt $(KEYDIR)/seckey.txt \
625
 
                $(KEYDIR)/tls-pubkey.txt $(KEYDIR)/tls-privkey.txt
626
 
        -rmdir $(KEYDIR) $(CONFDIR)/plugins.d $(CONFDIR)
 
7
        rm -f plugbasedclient