/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to TODO

  • Committer: Teddy Hogeborn
  • Date: 2008-07-29 03:35:39 UTC
  • Revision ID: teddy@fukt.bsnet.se-20080729033539-08zecoj3jwlkpjhw
* server.conf: New file.

* mandos-clients.conf: Renamed to clients.conf.

* Makefile (FORTIFY): New.
  (CFLAGS): Include $(FORTIFY).

* plugins.d/mandosclient.c (main): New "if_index" variable.  Bug fix:
                                   check if interface exists.  New
                                   "--connect" option.

* server.py (serviceInterface): Removed; replaced by
                                "AvahiService.interface".  All users
                                changed.
  (AvahiError, AvahiServiceError, AvahiGroupError): New exception
                                                    classes.
  (AvahiService): New class.
  (serviceName): Removed; replaced by "AvahiService.name".  All users
                 changed.
  (serviceType): Removed; replaced by "AvahiService.type".  All users
                 changed.
  (servicePort): Removed; replaced by "AvahiService.port".  All users
                 changed.
  (serviceTXT): Removed; replaced by "AvahiService.TXT".  All users
                changed.
  (domain): Removed; replaced by "AvahiService.domain".  All users
            changed.
  (host): Removed; replaced by "AvahiService.host".  All users
          changed.
  (rename_count): Removed; replaced by "AvahiService.rename_count" and
                 "AvahiService.max_renames".  All users changed.
  (Client.__init__): If no secret or secfile, raise TypeError instead
                     of RuntimeError.
  (Client.last_seen): Renamed to "Client.last_checked_ok".  All users
                      changed.
  (Client.stop, Client.stop_checker): Use "getattr" with default value
                                      instead of "hasattr".
  (Client.still_valid): Removed "now" argument.
  (Client.handle): Separate the "no client found" and "client invalid"
                   cases for clearer code.
  (IPv6_TCPServer.__init__): "options" argument replaced by
                             "settings".  All callers changed.
  (IPv6_TCPServer.options): Replaced by "IPv6_TCPServer.settings".
                            All users changed.
  (IPv6_TCPServer.server_bind): Use getattr instead of hasattr.
  (add_service): Removed; replaced by "AvahiService.add".  All callers
                 changed.
  (remove_service): Removed; replaced by "AvahiService.remove".  All
                    callers changed.
  (entry_group_state_changed): On entry group collision, call the new
                               AvahiService.rename method.  Raise
                               AvahiGroupError on group error.
  (if_nametoindex): Use ctypes.utils.find_library to locate the C
                    library.  Cache the result.  Loop on EINTR.
  (daemon): Use os.path.devnull to locate "/dev/null".
  (killme): Removed.  All callers changed to do "sys.exit()" instead,
            except where stated otherwise.
  (main): Removed "exitstatus".  Removed all default values from all
          non-bool options.  New option "--configdir".  New variables
          "server_defaults" and "server_settings", read from
          "%(configdir)s/server.conf".  Let any supplied command line
          options override server settings.   Variable "defaults"
          renamed to "client_defaults", which is read from
          "clients.conf" instead of "mandos-clients.conf".  New global
          AvahiService object "service" replaces old global variables.
          Catch AvahiError and exit with error if caught.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
-*- org -*-
2
 
 
3
 
* plugin-runner
4
 
** TODO Man page  for plugin-runner.conf.5
5
 
   link to plugin-runner.8
6
 
 
7
 
* mandos-client
8
 
** TODO [#B] Temporarily lower kernel log level
9
 
   for less printouts during sucessfull boot.
10
 
** TODO IPv4 support
11
 
** TODO use strsep instead of strtok?
12
 
 
13
 
* DONE password-prompt
14
 
 
15
 
* mandos (server)
16
 
** TODO [#B] Log level                          :bugs:
17
 
** TODO /etc/mandos/clients.d/*.conf
18
 
   Watch this directory and add/remove/update clients?
19
 
** TODO config for TXT record
20
 
** TODO [#B] Run-time communication with server :bugs:
21
 
   Probably using D-Bus
22
 
   See also [[*Mandos-tools]]
23
 
** TODO Implement --foreground                  :bugs:
24
 
   [[info:standards:Option%20Table][Table of Long Options]]
25
 
** TODO Implement --socket
26
 
   [[info:standards:Option%20Table][Table of Long Options]]
27
 
** TODO Date+time on console log messages       :bugs:
28
 
   Is this the default?
29
 
** TODO delete hook when clients fall out by timeout
30
 
 
31
 
* Mandos-tools/utilities
32
 
  All of this probably using D-Bus
33
 
** TODO List clients
34
 
** TODO Disable client
35
 
** TODO Enable client
36
 
** TODO Reset timer
37
 
 
38
 
* Man pages
39
 
** TODO Use xinclude for all common sections
40
 
   Like authors, etc.
41
 
 
42
 
 
43
 
* Installer
44
 
** Client-side
45
 
*** TODO Update initrd.img after installation
46
 
    This seems to use some kind of "trigger" system
47
 
    [[file:/usr/share/doc/dpkg/triggers.txt.gz]]
48
 
    dpkg-trigger(1), deb-triggers(5)
49
 
*** mandos-keygen
50
 
**** TODO [#A] Ask for password twice for confirmation
51
 
**** TODO "--passfile" option
52
 
     Using the "secfile" option instead of "secret"
53
 
**** TODO [#B] "--test" option
54
 
     For testing decryption before rebooting.
55
 
** Server-side
56
 
*** TODO [#A] Create mandos user and group for server
57
 
 
58
 
 
59
 
* [#A] Package
60
 
** /usr/share/initramfs-tools/hooks/mandos
61
 
*** TODO Do not install in initrd.img if configured not to.
62
 
    Use "/etc/initramfs-tools/conf.d/mandos"?  Definitely a debconf
63
 
    question.
64
 
** TODO /etc/bash_completion.d/mandos
65
 
   From XML sources directly?
66
 
** TODO unperish
67
 
** DONE bzr-builddeb
68
 
** TODO mandos user/group creation
69
 
** TODO Key creation in postinst
70
 
 
71
 
* TODO Web site
72
 
** DONE http://www.fukt.bsnet.se/mandos
73
 
   Redirects to the wiki page
74
 
** TODO http://wiki.fukt.bsnet.se/wiki/Mandos
75
 
 
76
 
* Mailing list
77
 
** DONE mandos-dev
78
 
*** TODO http://gmane.org/subscribe.php
79
 
 
80
 
* TODO Announce project on Usenet
81
 
  [[news:comp.os.linux.announce]]
82
 
 
83
 
 
84
 
#+STARTUP: showall
 
1
[Mandos client]
 
2
configuration for OpenPGP key dir
 
3
header files/symbols tally
 
4
check exit codes of all system calls
 
5
IPv4 support
 
6
protocol version header
 
7
use strsep instead of strtok?
 
8
 
 
9
[Pluginbasedclient]
 
10
disable certain plugins
 
11
header files/symbols tally
 
12
check exit codes of all system calls
 
13
change uid to nobody:nogroup
 
14
        other drop privs stuff?
 
15
pass things in environment, like device name, etc
 
16
        Does cryptsetup already do this?
 
17
Configurable plugin dir
 
18
use strsep instead of strtok?
 
19
 
 
20
[Server]
 
21
config for:
 
22
        TXT record
 
23
protocol version header
 
24
Run-time communication with server
 
25
        probably using D-Bus
 
26
 
 
27
[Mandos-tools/utilities]
 
28
        List clients
 
29
        Enable client
 
30
        Disable client
 
31
 
 
32
[Installer]
 
33
...