7
** [[https://www.freedesktop.org/software/polkit/docs/latest/polkit-apps.html][Writing polkit applications]]
10
** TODO A ~--server~ option which only adds to the server list.
11
(Unlike ~--connect~, which implicitly disables ZeroConf.)
12
** TODO [#B] Use [[man:capabilities][capabilities]] instead of [[info:libc#Setting%20User%20ID][seteuid()]].
13
[[https://forums.grsecurity.net/viewtopic.php?f=7&t=2522]]
14
** TODO [#B] Use ~getaddrinfo(hints=AI_NUMERICHOST)~ instead of ~inet_pton()~
15
** TODO [#C] Make ~start_mandos_communication()~ take ~struct server~.
16
** TODO [#C] ~--interfaces=regex,eth*,noregex~ [[man:bridge-utils-interfaces][bridge-utils-interfaces(5)]]
17
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
20
** TODO [#B] use [[info:libc#Scanning%20Directory%20Content][scandir(3)]] instead of [[info:libc#Reading/Closing%20Directory][readdir(3)]]
21
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
23
* usplash (Deprecated)
24
** TODO [#B] Make it work again
25
** TODO [#B] use [[info:libc#Scanning%20Directory%20Content][scandir(3)]] instead of [[info:libc#Reading/Closing%20Directory][readdir(3)]]
26
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
29
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
32
** TODO [#B] lock stdin (with [[info:libc#File%20Locks][flock()]]?)
33
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
36
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
41
** TODO handle printing for errors for plugins
42
*** Hook up stderr of plugins, buffer them, and prepend "Mandos Plugin [plugin name]"
43
** TODO [#C] use same file name rules as [[man:run-parts][run-parts(8)]]
44
** kernel command line option for debug info
45
** TODO [#A] Restart plugins which exit with ~EX_TEMPFAIL~
48
** TODO [#B] ~--notify-command~
49
This would allow the mandos.service to use
50
~--notify-command="systemd-notify --pid --ready"~
51
** TODO [#B] python-systemd
52
*** import systemd.daemon; systemd.daemon.notify()
53
** TODO [#B] Log level :BUGS:
54
*** TODO /etc/mandos/clients.d/*.conf
55
Watch this directory and add/remove/update clients?
56
** TODO [#C] config for TXT record
57
** TODO Log level dbus option
58
SetLogLevel D-Bus call
59
** TODO [#C] DBusServiceObjectUsingSuper
60
** TODO [#B] Global enable/disable flag
61
** TODO [#B] By-client countdown on number of secrets given
62
** D-Bus Client method NeedsPassword(50) - Timeout, default disapprove
63
+ SetPass("gazonk", True) -> Approval, persistent
64
+ Approve(False) -> Close client connection immediately
65
** TODO [#C] python-parsedatetime
66
** TODO Separate logging logic to own object
67
** TODO [#B] Limit ~approval_delay~ to max GnuTLS/TLS timeout value
68
** TODO [#B] break the wait on ~approval_delay~ if connection dies
69
** TODO Generate ~Client.runtime_expansions~ from client options + extra
70
** TODO Allow %%(checker)s as a runtime expansion
71
** TODO D-Bus AddClient() method on server object
72
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods. :2:
73
** TODO Save state periodically to recover better from hard shutdowns
74
** TODO CheckerCompleted method, deprecate CheckedOK
75
** TODO [[https://standards.freedesktop.org/secret-service/][Secret Service]] API?
76
** TODO Remove D-Bus interfaces with old domain name :2:
77
** TODO Remove old ~string_to_delta~ format :2:
78
** TODO http://0pointer.de/blog/projects/stateless.html
79
*** File in /usr/lib/sysusers.d to create user+group "~_mandos~"
80
** TODO Error handling on error parsing config files
81
** TODO init.d script error handling
82
** TODO D-Bus server properties; address, port, interface, etc. :2:
85
** TODO Remove old string_to_delta format :2:
87
* TODO mandos-dispatch
88
Listens for specified D-Bus signals and spawns shell commands with
92
** TODO ~--servicename~ :BUGS:
93
** TODO help should be toggleable
94
** Urwid client data displayer
95
Better view of client data in the listing
97
** Print a nice "We are sorry" message, save stack trace to log.
100
** TODO "~--secfile~" option
101
Using the "secfile" option instead of "secret"
102
** TODO [#B] "~--test~" option
103
For testing decryption before rebooting.
106
** /usr/share/initramfs-tools/hooks/mandos
107
*** TODO [#C] use same file name rules as [[man:run-parts][run-parts(8)]]
108
*** TODO [#C] Do not install in initrd.img if configured not to.
109
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
110
** TODO [#C] ~$(pkg-config --variable=completionsdir bash-completion)~
111
From XML sources directly?
114
** TODO Locate which package moves the other bin/sh when busybox is deactivated
115
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox
117
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]]
7
** [#A] check exit codes of all system calls
8
** [#B] header files/symbols tally
10
** use strsep instead of strtok?
11
** Do not depend on GPG key rings on disk
12
This would mean creating new GPG key rings with GPGME by importing
13
the key files from scratch every time we start the program.
20
** [#A] check exit codes of all system calls
21
** [#B] header files/symbols tally
22
** use strsep instead of strtok?
23
** use config file in addition to arguments
24
** pass things in environment, like device name, etc
28
** [#A] write PID file
29
** [#A] /etc/init.d/mandos-server
30
** Better comments in config files
32
** /etc/mandos/clients.d/*.conf
33
Watch this directory and add/remove/update clients?
34
** config for TXT record
35
** Run-time communication with server
38
* Mandos-tools/utilities
39
All of this probably using D-Bus
45
** Change initrd.img file to not be publically readable
46
** Create GPG key ring files in initrd
120
49
#+STARTUP: showall