mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
Add an RPM package for Fedora and RHEL. `make -C packaging rpm` builds it from packaging/rpm/fips.spec, and the release workflow attaches it beside the .deb and the systemd tarball. - The package is named `fips-mesh`, because Fedora already ships an unrelated `fips` (a FITS image viewer) that owns /usr/bin/fips. The spec declares `Conflicts: fips`. - It installs the same files, units and fips group as the .deb. fips.service and fips-dns.service are enabled but not started on install; fips-firewall and fips-gateway stay opt-in. - An upgrade queues `systemctl --no-block try-restart` of fips, fips-dns and fips-gateway, and reloads fips-firewall rather than restarting it. - The binaries come from the pinned build image via build-deb-container.sh, so the RPM passes the same glibc floor and dependency checks as the .deb. rpmbuild runs in FIPS_RPM_BUILD_IMAGE, AlmaLinux 9 pinned by digest. - The glibc floor is now 2.34 project-wide, the lowest supported RPM distribution (RHEL 9). testing/check-rpm-floor.sh fails a package that requires a newer glibc. RHEL 8 and openSUSE are not supported. - Erase removes the DNS drop-ins fips-dns-setup wrote and restarts or reloads the resolver whose file it removed, as the Debian postrm does. /etc/fips is kept, since rpm has no purge. - Dev builds are versioned 0.6.0-0.dev.git<date>.<sha>. Tested on Fedora 44 and in AlmaLinux 9 containers with systemd: the package requires GLIBC_2.34 and passes the floor check; install leaves both units enabled and inactive; upgrade returns immediately and the daemon restarts on the new binary; erase removes the units and DNS files and keeps /etc/fips; host-built binaries (GLIBC_2.39) fail the floor check; dnf refuses to install alongside the FITS viewer. The erase branch's resolver restart and reload were exercised in AlmaLinux 9 with systemctl stubbed. No install-test suite covers the RPM yet; it is only built.
93 lines
3.7 KiB
Makefile
93 lines
3.7 KiB
Makefile
# FIPS Packaging Makefile
|
|
#
|
|
# Builds release packages for supported target platforms.
|
|
# All outputs are placed in deploy/ at the project root.
|
|
#
|
|
# Usage:
|
|
# make deb Build a Debian/Ubuntu .deb package in the pinned container
|
|
# make deb-host Build a .deb with the host toolchain (see below)
|
|
# make rpm Build an .rpm in the pinned container
|
|
# make rpm-host Build an .rpm with the host toolchain (see below)
|
|
# make tarball Build a systemd install tarball
|
|
# make ipk Build an OpenWrt .ipk package (opkg, OpenWrt 24.x and earlier)
|
|
# make apk Build an OpenWrt .apk package (apk-tools, mandatory on OpenWrt 25+)
|
|
# make aur Build fips-git AUR package and validate with namcap
|
|
# make pkg Build a macOS .pkg installer
|
|
# make freebsd Build a FreeBSD .pkg package (on FreeBSD; use gmake)
|
|
# make pfsense Build a pfSense .pkg package (on FreeBSD; use gmake)
|
|
# make zip Build a Windows .zip package
|
|
# make all Build deb and tarball (default)
|
|
# make clean Remove deploy/ directory
|
|
|
|
SHELL := /bin/bash
|
|
PACKAGING_DIR := $(dir $(abspath $(lastword $(MAKEFILE_LIST))))
|
|
PROJECT_ROOT := $(abspath $(PACKAGING_DIR)/..)
|
|
|
|
.PHONY: all deb deb-host rpm rpm-host tarball ipk apk aur pkg freebsd pfsense zip clean
|
|
|
|
all: deb tarball
|
|
|
|
# `deb` builds in the pinned container so the package carries the declared glibc
|
|
# floor and can install on every supported distribution. It also checks that
|
|
# floor before it hands the package back.
|
|
deb:
|
|
@bash $(PACKAGING_DIR)/debian/build-deb-container.sh
|
|
|
|
# `deb-host` builds with whatever toolchain and C library the host has. It is
|
|
# for iterating locally and NOT for anything anyone else installs: on a modern
|
|
# host it produces a package that installs cleanly and then cannot start on
|
|
# Debian 12 or Ubuntu 22.04, which is the defect that made the container build
|
|
# necessary. Nothing checks its floor, deliberately, so the check stays
|
|
# attached to the artifact that ships.
|
|
deb-host:
|
|
@bash $(PACKAGING_DIR)/debian/build-deb.sh
|
|
|
|
# `rpm` compiles nothing on the host either: it builds the binaries in the same
|
|
# pinned container the .deb uses, packages those, and then checks the glibc
|
|
# requirement rpm derived for the finished package against the declared floor.
|
|
# So the RPM carries the same objects as the .deb and the tarball, and a
|
|
# package built above the floor fails here rather than at a user's `dnf
|
|
# install` -- which is what `deb` gets from its container and its Depends
|
|
# check.
|
|
rpm:
|
|
@bash $(PACKAGING_DIR)/rpm/build-rpm-container.sh
|
|
|
|
# `rpm-host` packages whatever the host toolchain built, and like `deb-host` it
|
|
# is for local iteration and NOT for anything anyone else installs. Nothing
|
|
# checks its floor, deliberately, so the check stays attached to the artifact
|
|
# that ships. Its failure is at least loud: rpm derives the requirement from
|
|
# the binaries, so a package built on a host above the floor is refused by dnf
|
|
# on an older system rather than installed and unable to start.
|
|
rpm-host:
|
|
@bash $(PACKAGING_DIR)/rpm/build-rpm.sh
|
|
|
|
tarball:
|
|
@bash $(PACKAGING_DIR)/systemd/build-tarball.sh
|
|
|
|
ipk:
|
|
@bash $(PACKAGING_DIR)/openwrt-ipk/build-ipk.sh
|
|
|
|
apk:
|
|
@bash $(PACKAGING_DIR)/openwrt-apk/build-apk.sh
|
|
|
|
aur:
|
|
@bash $(PACKAGING_DIR)/aur/build-aur.sh
|
|
|
|
pkg:
|
|
@bash $(PACKAGING_DIR)/macos/build-pkg.sh
|
|
|
|
freebsd:
|
|
@sh $(PACKAGING_DIR)/freebsd/build-pkg.sh
|
|
|
|
# pfSense is FreeBSD underneath but boots, resolves and is upgraded
|
|
# differently enough that the FreeBSD package does not work there; see
|
|
# packaging/pfsense/README.md for the three divergences.
|
|
pfsense:
|
|
@sh $(PACKAGING_DIR)/pfsense/build-pkg.sh
|
|
|
|
zip:
|
|
@powershell -File $(PACKAGING_DIR)/windows/build-zip.ps1
|
|
|
|
clean:
|
|
rm -rf $(PROJECT_ROOT)/deploy
|