Files
Johnathan Corgan c99e6d3908 Remove every DNS routing file on purge and uninstall, and restart the resolver that used it
When the package was purged, or the tarball uninstalled, while fips-dns
was not running, fips-dns-teardown never ran and the DNS routing that
fips-dns-setup wrote stayed behind. The cleanup in postrm purge and in
uninstall.sh was meant to catch that case but removed the dns-delegate
file from the wrong directory (dns-delegate/ instead of dns-delegate.d/),
never removed the systemd-resolved global drop-in, and restarted no
resolver. systemd-resolved kept sending .fips queries to [::1]:5354,
where nothing listens any more, so .fips lookups timed out.

Both scripts now remove all four files fips-dns-setup can write, and
restart systemd-resolved, reload dnsmasq or reload NetworkManager when
they removed that resolver's file and it is running. A failed restart
prints a warning and does not fail the removal.

A packaging test pins both scripts to the paths fips-dns-setup and
fips-dns-teardown use, and the deb-install scenario now purges the
package with the routing file in place and fips-dns stopped, checking
the file is gone and systemd-resolved restarted. The CI comment on the
arm64 leg is corrected to say that leg now runs that purge.
No suite runs uninstall.sh, and the test's doc comment says so.
2026-09-24 22:44:42 +00:00

66 lines
2.5 KiB
Bash
Executable File

#!/bin/sh
# FIPS post-removal script for Debian/Ubuntu
set -e
case "$1" in
purge)
# Remove configuration and identity keys
rm -rf /etc/fips/
# Remove tmpfiles.d entry
rm -f /usr/lib/tmpfiles.d/fips.conf
# Remove runtime directory
rm -rf /run/fips/
# Remove the DNS routing fips-dns-setup may have written, in case
# fips-dns-teardown did not run (prerm's stop runs it only when
# fips-dns.service was active), and make the resolver drop it. The
# paths match packaging/common/fips-dns-teardown, which dpkg has
# already removed, so it cannot be called from here.
restart_resolved=0
if [ -f /etc/systemd/dns-delegate.d/fips.dns-delegate ]; then
rm -f /etc/systemd/dns-delegate.d/fips.dns-delegate
restart_resolved=1
fi
if [ -f /etc/systemd/resolved.conf.d/fips.conf ]; then
rm -f /etc/systemd/resolved.conf.d/fips.conf
restart_resolved=1
fi
# Only pre-v0.3.0 development builds wrote this path, and systemd
# never read it.
rm -f /etc/systemd/dns-delegate/fips.dns-delegate
if [ "$restart_resolved" = 1 ] && [ -d /run/systemd/system ] \
&& systemctl is-active --quiet systemd-resolved.service; then
systemctl restart systemd-resolved \
|| echo "fips: warning: could not restart systemd-resolved; restart it to drop the .fips route"
fi
if [ -f /etc/dnsmasq.d/fips.conf ]; then
rm -f /etc/dnsmasq.d/fips.conf
if [ -d /run/systemd/system ] \
&& systemctl is-active --quiet dnsmasq.service; then
systemctl reload dnsmasq \
|| echo "fips: warning: could not reload dnsmasq; reload it to drop the .fips route"
fi
fi
if [ -f /etc/NetworkManager/dnsmasq.d/fips.conf ]; then
rm -f /etc/NetworkManager/dnsmasq.d/fips.conf
if [ -d /run/systemd/system ] \
&& systemctl is-active --quiet NetworkManager.service \
&& command -v nmcli >/dev/null 2>&1; then
nmcli general reload \
|| echo "fips: warning: could not reload NetworkManager; reload it to drop the .fips route"
fi
fi
# Remove fips system group
if getent group fips >/dev/null 2>&1; then
groupdel fips 2>/dev/null || true
fi
;;
esac
#DEBHELPER#
exit 0