mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
packaging: bring systemd tarball to feature parity with .deb / AUR
The generic systemd install tarball is the catch-all install path
for systemd Linux distros that don't have a per-format package
(Fedora, RHEL/CentOS, openSUSE, Alpine, etc.). It had drifted
behind the .deb and AUR packages and was missing fips-gateway, the
mesh-interface firewall baseline, and the multi-backend DNS helper
in the shipped tarball. Bring it to parity:
- New `packaging/systemd/fips-gateway.service` (clone of the .deb
unit; ExecStart pointed at `/usr/local/bin/fips-gateway`). Not
enabled at install time; operator opt-in.
- New `packaging/systemd/fips-firewall.service` (clone of the .deb
unit; nft path unchanged at `/usr/sbin/nft`). Not enabled at
install time; operator opt-in.
- `build-tarball.sh` now bundles the `fips-gateway` binary, the two
new units, the `fips.nft` baseline conffile, and the
`fips-dns-setup` / `fips-dns-teardown` multi-backend helpers from
`packaging/common/`.
- `install.sh` now installs `fips-gateway` to `/usr/local/bin/`,
installs both new units to `/etc/systemd/system/` (without
enabling them), preserves `/etc/fips/fips.nft` on upgrade like
`fips.yaml`, and creates the `/etc/fips/fips.d/` operator drop-in
directory. Post-install messaging mentions both opt-in services.
- `uninstall.sh` stops and disables the optional services in
dependency order (firewall, gateway, dns, daemon), removes the
new unit files, and removes the gateway binary. `--purge` already
handles `/etc/fips/` removal which covers `fips.nft` and
`fips.d/`.
- `README.install.md` documents all of the above: expanded
"What Gets Installed" table, new sections covering the firewall
baseline and the LAN gateway, refreshed DNS section reflecting
the multi-backend setup helper (systemd dns-delegate /
systemd-resolved drop-in / per-link resolvectl / dnsmasq /
NetworkManager-dnsmasq), and updated Service Management.
Also fixes a latent packaging bug: `install.sh` previously
referenced `${SCRIPT_DIR}/../common/fips-dns-setup`, a path that
exists only in the source-repo layout and not in the extracted
tarball. The script now resolves the helper from the staging
directory first (the tarball case), falling back to the source-repo
relative path. Bug latent since the multi-backend DNS helpers
landed.
CHANGELOG `[Unreleased]` documents the parity bump under Changed
and the path-resolution fix under Fixed.
Closes the longest-standing parity gap for non-Debian / non-Arch
systemd Linux distros installing from the release-distribution
tarball.
This commit is contained in:
@@ -388,9 +388,33 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
bind by setting `dns.listen: "[::]:53"` explicitly. The new
|
||||
default binds IPv6 loopback only — forwarders that reach the
|
||||
gateway over IPv4 loopback need an explicit IPv4 listen address.
|
||||
- Generic systemd install tarball brought to feature parity with
|
||||
the `.deb` and AUR packages. The tarball now ships the
|
||||
`fips-gateway` binary with its (operator-opt-in)
|
||||
`fips-gateway.service`, a `fips-firewall.service` unit with the
|
||||
`/etc/fips/fips.nft` mesh-interface nftables baseline (also
|
||||
opt-in), an `/etc/fips/fips.d/` operator drop-in directory for
|
||||
per-service nft rules, and the multi-backend `fips-dns-setup` /
|
||||
`fips-dns-teardown` helpers. `install.sh` and `uninstall.sh`
|
||||
handle the new units and conffile (preserve-on-upgrade for
|
||||
`fips.nft`, like `fips.yaml`). `README.install.md` documents
|
||||
the gateway, firewall, and DNS-routing services. Closes the
|
||||
longest-standing parity gap for non-Debian / non-Arch systemd
|
||||
Linux distros (Fedora, RHEL/CentOS, openSUSE, etc.) installing
|
||||
from the release-distribution tarball.
|
||||
|
||||
### Fixed
|
||||
|
||||
- Generic systemd install tarball: `install.sh` now correctly
|
||||
resolves the `fips-dns-setup` and `fips-dns-teardown` helpers
|
||||
from the tarball staging directory. Previously the script
|
||||
referenced them at `${SCRIPT_DIR}/../common/`, a path that
|
||||
exists only in the source-repo layout, not in the extracted
|
||||
tarball. Bug latent since the multi-backend DNS helpers
|
||||
landed in `7260ad2`; only manifested when operators ran
|
||||
`install.sh` from an extracted tarball rather than from a
|
||||
source checkout.
|
||||
|
||||
- Adopted NAT-traversed UDP transports inherit the primary listener's
|
||||
MTU and buffer config. `Node::adopt_established_traversal`
|
||||
constructed the adopted UDP transport with `UdpConfig::default()`
|
||||
|
||||
Reference in New Issue
Block a user