Files
fips/packaging/Makefile
Gustavo Lima ChavesandJohnathan Corgan 17ca52e694 Package FIPS for RPM-based distributions
Add an RPM package for Fedora and RHEL. `make -C packaging rpm` builds it
from packaging/rpm/fips.spec, and the release workflow attaches it beside
the .deb and the systemd tarball.

- The package is named `fips-mesh`, because Fedora already ships an
  unrelated `fips` (a FITS image viewer) that owns /usr/bin/fips. The spec
  declares `Conflicts: fips`.
- It installs the same files, units and fips group as the .deb. fips.service
  and fips-dns.service are enabled but not started on install;
  fips-firewall and fips-gateway stay opt-in.
- An upgrade queues `systemctl --no-block try-restart` of fips, fips-dns and
  fips-gateway, and reloads fips-firewall rather than restarting it.
- The binaries come from the pinned build image via build-deb-container.sh,
  so the RPM passes the same glibc floor and dependency checks as the .deb.
  rpmbuild runs in FIPS_RPM_BUILD_IMAGE, AlmaLinux 9 pinned by digest.
- The glibc floor is now 2.34 project-wide, the lowest supported RPM
  distribution (RHEL 9). testing/check-rpm-floor.sh fails a package that
  requires a newer glibc. RHEL 8 and openSUSE are not supported.
- Erase removes the DNS drop-ins fips-dns-setup wrote and restarts or
  reloads the resolver whose file it removed, as the Debian postrm does.
  /etc/fips is kept, since rpm has no purge.
- Dev builds are versioned 0.6.0-0.dev.git<date>.<sha>.

Tested on Fedora 44 and in AlmaLinux 9 containers with systemd: the package
requires GLIBC_2.34 and passes the floor check; install leaves both units
enabled and inactive; upgrade returns immediately and the daemon restarts
on the new binary; erase removes the units and DNS files and keeps
/etc/fips; host-built binaries (GLIBC_2.39) fail the floor check; dnf
refuses to install alongside the FITS viewer. The erase branch's resolver
restart and reload were exercised in AlmaLinux 9 with systemctl stubbed.

No install-test suite covers the RPM yet; it is only built.
2026-09-26 15:58:19 +00:00

93 lines
3.7 KiB
Makefile

# FIPS Packaging Makefile
#
# Builds release packages for supported target platforms.
# All outputs are placed in deploy/ at the project root.
#
# Usage:
# make deb Build a Debian/Ubuntu .deb package in the pinned container
# make deb-host Build a .deb with the host toolchain (see below)
# make rpm Build an .rpm in the pinned container
# make rpm-host Build an .rpm with the host toolchain (see below)
# make tarball Build a systemd install tarball
# make ipk Build an OpenWrt .ipk package (opkg, OpenWrt 24.x and earlier)
# make apk Build an OpenWrt .apk package (apk-tools, mandatory on OpenWrt 25+)
# make aur Build fips-git AUR package and validate with namcap
# make pkg Build a macOS .pkg installer
# make freebsd Build a FreeBSD .pkg package (on FreeBSD; use gmake)
# make pfsense Build a pfSense .pkg package (on FreeBSD; use gmake)
# make zip Build a Windows .zip package
# make all Build deb and tarball (default)
# make clean Remove deploy/ directory
SHELL := /bin/bash
PACKAGING_DIR := $(dir $(abspath $(lastword $(MAKEFILE_LIST))))
PROJECT_ROOT := $(abspath $(PACKAGING_DIR)/..)
.PHONY: all deb deb-host rpm rpm-host tarball ipk apk aur pkg freebsd pfsense zip clean
all: deb tarball
# `deb` builds in the pinned container so the package carries the declared glibc
# floor and can install on every supported distribution. It also checks that
# floor before it hands the package back.
deb:
@bash $(PACKAGING_DIR)/debian/build-deb-container.sh
# `deb-host` builds with whatever toolchain and C library the host has. It is
# for iterating locally and NOT for anything anyone else installs: on a modern
# host it produces a package that installs cleanly and then cannot start on
# Debian 12 or Ubuntu 22.04, which is the defect that made the container build
# necessary. Nothing checks its floor, deliberately, so the check stays
# attached to the artifact that ships.
deb-host:
@bash $(PACKAGING_DIR)/debian/build-deb.sh
# `rpm` compiles nothing on the host either: it builds the binaries in the same
# pinned container the .deb uses, packages those, and then checks the glibc
# requirement rpm derived for the finished package against the declared floor.
# So the RPM carries the same objects as the .deb and the tarball, and a
# package built above the floor fails here rather than at a user's `dnf
# install` -- which is what `deb` gets from its container and its Depends
# check.
rpm:
@bash $(PACKAGING_DIR)/rpm/build-rpm-container.sh
# `rpm-host` packages whatever the host toolchain built, and like `deb-host` it
# is for local iteration and NOT for anything anyone else installs. Nothing
# checks its floor, deliberately, so the check stays attached to the artifact
# that ships. Its failure is at least loud: rpm derives the requirement from
# the binaries, so a package built on a host above the floor is refused by dnf
# on an older system rather than installed and unable to start.
rpm-host:
@bash $(PACKAGING_DIR)/rpm/build-rpm.sh
tarball:
@bash $(PACKAGING_DIR)/systemd/build-tarball.sh
ipk:
@bash $(PACKAGING_DIR)/openwrt-ipk/build-ipk.sh
apk:
@bash $(PACKAGING_DIR)/openwrt-apk/build-apk.sh
aur:
@bash $(PACKAGING_DIR)/aur/build-aur.sh
pkg:
@bash $(PACKAGING_DIR)/macos/build-pkg.sh
freebsd:
@sh $(PACKAGING_DIR)/freebsd/build-pkg.sh
# pfSense is FreeBSD underneath but boots, resolves and is upgraded
# differently enough that the FreeBSD package does not work there; see
# packaging/pfsense/README.md for the three divergences.
pfsense:
@sh $(PACKAGING_DIR)/pfsense/build-pkg.sh
zip:
@powershell -File $(PACKAGING_DIR)/windows/build-zip.ps1
clean:
rm -rf $(PROJECT_ROOT)/deploy