mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
The maintainer scripts handled fips, fips-dns and fips-firewall but never fips-gateway. An upgrade stopped the daemon, which the gateway requires, and never brought the gateway back, so an operator who had enabled it lost it until the next reboot. Removing or purging the package left the gateway's enablement symlink behind, pointing at a unit file that no longer exists. prerm now stops the gateway before the daemon on upgrade, and stops and disables it first on remove and purge. On upgrade postinst restarts it, bounded at 90 seconds because its start waits for the daemon's interface, only when it is enabled and the daemon came up. A gateway that was running but never enabled stays stopped, and nothing enables it. A gateway that does not come back is reported with its status but does not fail the upgrade: it is an opt-in addition to a daemon that is running, and only a daemon that does not start fails the install. The upgrade scenario's opted-in host now enables and runs the gateway, and after the upgrade requires the daemon and the gateway to run new processes of the installed binaries, then purges the package and requires no gateway enablement to remain. Its other host runs the gateway without enabling it and requires it to be stopped and still disabled after the upgrade, then enables a gateway that cannot start and requires apt to succeed, report it and leave the daemon running. The upgrade and purge are bounded at 300 seconds, above the package's own worst case, and the install scenario's gateway config step is shared with it.
33 lines
1.1 KiB
Bash
Executable File
33 lines
1.1 KiB
Bash
Executable File
#!/bin/sh
|
|
# FIPS pre-removal script for Debian/Ubuntu
|
|
set -e
|
|
|
|
case "$1" in
|
|
remove|purge)
|
|
if [ -d /run/systemd/system ]; then
|
|
# The gateway requires the daemon, so it goes first.
|
|
systemctl stop fips-gateway.service 2>/dev/null || true
|
|
systemctl disable fips-gateway.service 2>/dev/null || true
|
|
systemctl stop fips-dns.service 2>/dev/null || true
|
|
systemctl disable fips-dns.service 2>/dev/null || true
|
|
systemctl stop fips.service 2>/dev/null || true
|
|
systemctl disable fips.service 2>/dev/null || true
|
|
systemctl stop fips-firewall.service 2>/dev/null || true
|
|
systemctl disable fips-firewall.service 2>/dev/null || true
|
|
systemctl daemon-reload
|
|
fi
|
|
;;
|
|
upgrade)
|
|
# Stop services before upgrade; postinst will restart them
|
|
if [ -d /run/systemd/system ]; then
|
|
systemctl stop fips-gateway.service 2>/dev/null || true
|
|
systemctl stop fips-dns.service 2>/dev/null || true
|
|
systemctl stop fips.service 2>/dev/null || true
|
|
fi
|
|
;;
|
|
esac
|
|
|
|
#DEBHELPER#
|
|
|
|
exit 0
|