mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
Removing the .deb while fips-dns was not running left the resolver's .fips routing file in place. prerm stops fips-dns, but systemd runs its teardown only for an active unit, and postrm cleaned up the routing only on purge. After an apt remove the resolver kept sending .fips queries to [::1]:5354, where nothing listens once the daemon is gone, so .fips lookups timed out until the file was deleted by hand. postrm now runs the DNS cleanup on both remove and purge. A purge of an installed package runs remove and then purge; the second pass finds no file and restarts nothing. A purge of a package already removed runs only the purge pass, which still cleans up. Configuration, keys and the fips group are still removed only on purge. The deb-install check now removes the package with the routing planted and fips-dns stopped, then plants the routing again and purges from config-files state, so each postrm branch is exercised on its own. The packaging text test reads the remove|purge branch.
74 lines
2.8 KiB
Bash
Executable File
74 lines
2.8 KiB
Bash
Executable File
#!/bin/sh
|
|
# FIPS post-removal script for Debian/Ubuntu
|
|
set -e
|
|
|
|
case "$1" in
|
|
remove|purge)
|
|
# Remove the DNS routing fips-dns-setup may have written, in case
|
|
# fips-dns-teardown did not run (prerm's stop runs it only when
|
|
# fips-dns.service was active), and make the resolver drop it. This
|
|
# runs on remove as well as purge: a removed package leaves nothing
|
|
# listening behind the routing, and purging a package already removed
|
|
# runs only postrm purge. On a purge of an installed package the
|
|
# purge pass finds nothing left and restarts nothing. The paths match
|
|
# packaging/common/fips-dns-teardown, which dpkg has already removed,
|
|
# so it cannot be called from here.
|
|
restart_resolved=0
|
|
if [ -f /etc/systemd/dns-delegate.d/fips.dns-delegate ]; then
|
|
rm -f /etc/systemd/dns-delegate.d/fips.dns-delegate
|
|
restart_resolved=1
|
|
fi
|
|
if [ -f /etc/systemd/resolved.conf.d/fips.conf ]; then
|
|
rm -f /etc/systemd/resolved.conf.d/fips.conf
|
|
restart_resolved=1
|
|
fi
|
|
# Only pre-v0.3.0 development builds wrote this path, and systemd
|
|
# never read it.
|
|
rm -f /etc/systemd/dns-delegate/fips.dns-delegate
|
|
if [ "$restart_resolved" = 1 ] && [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet systemd-resolved.service; then
|
|
systemctl restart systemd-resolved \
|
|
|| echo "fips: warning: could not restart systemd-resolved; restart it to drop the .fips route"
|
|
fi
|
|
if [ -f /etc/dnsmasq.d/fips.conf ]; then
|
|
rm -f /etc/dnsmasq.d/fips.conf
|
|
if [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet dnsmasq.service; then
|
|
systemctl reload dnsmasq \
|
|
|| echo "fips: warning: could not reload dnsmasq; reload it to drop the .fips route"
|
|
fi
|
|
fi
|
|
if [ -f /etc/NetworkManager/dnsmasq.d/fips.conf ]; then
|
|
rm -f /etc/NetworkManager/dnsmasq.d/fips.conf
|
|
if [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet NetworkManager.service \
|
|
&& command -v nmcli >/dev/null 2>&1; then
|
|
nmcli general reload \
|
|
|| echo "fips: warning: could not reload NetworkManager; reload it to drop the .fips route"
|
|
fi
|
|
fi
|
|
;;
|
|
esac
|
|
|
|
case "$1" in
|
|
purge)
|
|
# Remove configuration and identity keys
|
|
rm -rf /etc/fips/
|
|
|
|
# Remove tmpfiles.d entry
|
|
rm -f /usr/lib/tmpfiles.d/fips.conf
|
|
|
|
# Remove runtime directory
|
|
rm -rf /run/fips/
|
|
|
|
# Remove fips system group
|
|
if getent group fips >/dev/null 2>&1; then
|
|
groupdel fips 2>/dev/null || true
|
|
fi
|
|
;;
|
|
esac
|
|
|
|
#DEBHELPER#
|
|
|
|
exit 0
|