mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
check-pfsense-pkg.sh reads the package from the outside and drives the boot script against a stub. Nothing installed the package or ran the real daemon under daemon(8) on a kernel of the target's major, so a post-install that leaves fips.yaml world-readable, a daemon that dies at TUN setup, a supervisor that keeps writing into a rotated log inode, or a pre-deinstall that lets pkg delete remove the binary under a running process would all have passed. Add testing/pfsense-install-smoke.sh: pkg add, the seeded configs and their modes, the fips group, fips.sh start, status, fipsctl answering on the control socket, the DNS responder answering on 127.0.0.1:5354, a forced newsyslog rotation on the shipped entry with the daemon(8) supervisor's open log following to the new /var/log/fips.log inode, re-entrant start (what rc.start_packages does on every WAN address change) exiting 0 without a second daemon, restart with a new pid, stop, and pkg delete stopping a running daemon and taking the files and the unmodified configs back out. The pfsense CI job runs it after the checker, in the same 15.1 VM, and shellchecks it on the runner first. It is written to run on pfSense too, as the first thing to run against a new package there; its header says what a plain-FreeBSD pass does not cover. Split out of #159 at the maintainer's request, so it can land on the existing FreeBSD 15.1 job whatever happens with the FreeBSD 16 builder.