mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
The macOS package accumulated a single unbounded log file, 717 MB on a node running at debug level. launchd redirects stdout to a plain file, appends to it forever, and holds the descriptor itself, so the daemon has no way to reopen a file rotated out from under it and a rename-and-signal rotator cannot help. Rotation has to happen in the process that writes, so the daemon has to own the file. master already carries a size-rolling, unbuffered writer for the Windows service (utils::logfile). Use it on every platform: the live file keeps its name so `tail -F` follows it, rolls touch only <name>.N, and the disk taken is bounded by size rather than by how loud a day was. - `node.log_file` names the file. Unset by default, so platforms whose supervisor already rotates stdout (journald, syslog) are unchanged. - `--log-file` overrides it and is opened before the config loads, so a config error is recorded too. The macOS plist passes it, because an upgrade keeps the existing fips.yaml. - `node.log_max_size_mb` (default 10) and `node.log_max_files` (default 4, clamped to 1..=100) set the limits, for the Windows service log as well. A roll renames every kept file with the log locked, hence the cap; lowering the count removes the excess on the next roll. All three keys skip serializing when unset, like `drain_timeout_secs`. Writes stay synchronous and unbuffered, as stdout under launchd was, so the line logged before a process::exit is on disk when the process ends. Errors raised before logging is up, and panics, go to the log file, and to stderr only when no log is open or stderr is a terminal: launchd restarts a failing daemon every ten seconds, and the stderr file it appends to (now fips.stderr.log rather than the log itself) is never rolled. The daemon writes the log as root and recreates it on every roll, so on Unix it refuses to open the log through a symlink, and the macOS postinstall makes /usr/local/var/log/fips root-owned in case it predates the package. An upgraded node's old unbounded fips.log rolls to fips.log.1 on the first write and ages out with the rest. The launchd behaviour itself is not covered by the Docker harness; the writer, limits and flag precedence are unit-tested.
221 lines
6.7 KiB
Bash
Executable File
221 lines
6.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Build a macOS .pkg installer for FIPS.
|
|
#
|
|
# Usage: ./packaging/macos/build-pkg.sh [--version <version>] [--no-build]
|
|
# Output: deploy/fips-<version>-macos-<arch>.pkg
|
|
#
|
|
# Prerequisites: Xcode command-line tools (pkgbuild is included)
|
|
|
|
set -euo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
PACKAGING_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)"
|
|
PROJECT_ROOT="$(cd "${PACKAGING_DIR}/.." && pwd)"
|
|
|
|
usage() {
|
|
cat <<'EOF'
|
|
Usage: packaging/macos/build-pkg.sh [options]
|
|
|
|
Options:
|
|
--version <version> Override package version
|
|
--target <triple> Rust target triple (e.g. x86_64-apple-darwin)
|
|
--no-build Package existing binaries without running cargo build
|
|
-h, --help Show this help
|
|
EOF
|
|
}
|
|
|
|
VERSION_OVERRIDE=""
|
|
TARGET_TRIPLE=""
|
|
NO_BUILD=0
|
|
|
|
while [[ $# -gt 0 ]]; do
|
|
case "$1" in
|
|
--version)
|
|
VERSION_OVERRIDE="${2:?missing value for --version}"
|
|
shift 2
|
|
;;
|
|
--target)
|
|
TARGET_TRIPLE="${2:?missing value for --target}"
|
|
shift 2
|
|
;;
|
|
--no-build)
|
|
NO_BUILD=1
|
|
shift
|
|
;;
|
|
-h|--help)
|
|
usage
|
|
exit 0
|
|
;;
|
|
*)
|
|
echo "Unknown option: $1" >&2
|
|
usage >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
done
|
|
|
|
VERSION="${VERSION_OVERRIDE:-$(grep '^version' "${PROJECT_ROOT}/Cargo.toml" | head -1 | sed 's/.*"\(.*\)"/\1/')}"
|
|
|
|
# Derive the package architecture from the build target, not the build
|
|
# host. When cross-compiling (for example building the x86_64 package on
|
|
# an Apple-silicon machine) `uname -m` reports the host architecture and
|
|
# would mislabel the package; the Rust target triple is authoritative.
|
|
if [[ -n "${TARGET_TRIPLE}" ]]; then
|
|
case "${TARGET_TRIPLE}" in
|
|
aarch64-*) ARCH="arm64" ;;
|
|
x86_64-*) ARCH="x86_64" ;;
|
|
*)
|
|
echo "Unsupported target triple: ${TARGET_TRIPLE}" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
else
|
|
ARCH="$(uname -m)"
|
|
fi
|
|
PKG_NAME="fips-${VERSION}-macos-${ARCH}"
|
|
DEPLOY_DIR="${PROJECT_ROOT}/deploy"
|
|
STAGING_DIR="$(mktemp -d)"
|
|
SCRIPTS_DIR="$(mktemp -d)"
|
|
trap 'rm -rf "${STAGING_DIR}" "${SCRIPTS_DIR}"' EXIT
|
|
|
|
if [[ -n "${TARGET_TRIPLE}" ]]; then
|
|
BINARY_DIR="${PROJECT_ROOT}/target/${TARGET_TRIPLE}/release"
|
|
else
|
|
BINARY_DIR="${PROJECT_ROOT}/target/release"
|
|
fi
|
|
|
|
echo "Building FIPS v${VERSION} for macOS ${ARCH}..."
|
|
|
|
# Build release binaries
|
|
if [[ "${NO_BUILD}" -eq 0 ]]; then
|
|
cargo_args=(build --release --manifest-path="${PROJECT_ROOT}/Cargo.toml")
|
|
[[ -n "${TARGET_TRIPLE}" ]] && cargo_args+=(--target "${TARGET_TRIPLE}")
|
|
cargo "${cargo_args[@]}"
|
|
fi
|
|
|
|
# Verify binaries exist
|
|
for bin in fips fipsctl fipstop; do
|
|
if [[ ! -f "${BINARY_DIR}/${bin}" ]]; then
|
|
echo "Missing binary: ${BINARY_DIR}/${bin}" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
# Stage the payload (mirrors installed filesystem layout)
|
|
mkdir -p "${STAGING_DIR}/usr/local/bin"
|
|
mkdir -p "${STAGING_DIR}/usr/local/etc/fips"
|
|
mkdir -p "${STAGING_DIR}/usr/local/var/log/fips"
|
|
mkdir -p "${STAGING_DIR}/Library/LaunchDaemons"
|
|
mkdir -p "${STAGING_DIR}/etc/resolver"
|
|
|
|
# Binaries
|
|
for bin in fips fipsctl fipstop; do
|
|
cp "${BINARY_DIR}/${bin}" "${STAGING_DIR}/usr/local/bin/"
|
|
strip "${STAGING_DIR}/usr/local/bin/${bin}"
|
|
done
|
|
|
|
# Config (marked as conf file via postinstall logic — won't overwrite on upgrade)
|
|
cp "${PACKAGING_DIR}/common/fips.yaml" "${STAGING_DIR}/usr/local/etc/fips/fips.yaml.default"
|
|
cp "${PACKAGING_DIR}/common/hosts" "${STAGING_DIR}/usr/local/etc/fips/hosts.default"
|
|
|
|
# LaunchDaemon plist
|
|
cp "${SCRIPT_DIR}/com.fips.daemon.plist" "${STAGING_DIR}/Library/LaunchDaemons/"
|
|
|
|
# DNS resolver. Must match the daemon's dns.bind_addr (defaults to ::1).
|
|
cat > "${STAGING_DIR}/etc/resolver/fips" <<EOF
|
|
nameserver ::1
|
|
port 5354
|
|
EOF
|
|
|
|
# Create postinstall script
|
|
cat > "${SCRIPTS_DIR}/postinstall" <<'POSTINSTALL'
|
|
#!/bin/sh
|
|
set -e
|
|
|
|
LOG="/var/log/fips-install.log"
|
|
log() { echo "$(date '+%Y-%m-%d %H:%M:%S') $*" | tee -a "$LOG"; logger -t fips-install "$*"; }
|
|
|
|
log "postinstall started"
|
|
|
|
CONFDIR="/usr/local/etc/fips"
|
|
|
|
# Install default config only if none exists (preserve on upgrade)
|
|
if [ ! -f "$CONFDIR/fips.yaml" ]; then
|
|
cp "$CONFDIR/fips.yaml.default" "$CONFDIR/fips.yaml"
|
|
chmod 600 "$CONFDIR/fips.yaml"
|
|
log "installed default config"
|
|
fi
|
|
if [ ! -f "$CONFDIR/hosts" ]; then
|
|
cp "$CONFDIR/hosts.default" "$CONFDIR/hosts"
|
|
fi
|
|
|
|
# The daemon writes its log here as root. A directory that predates the
|
|
# package keeps its owner, and one another user can write to would let them
|
|
# swap the log for a link elsewhere; the daemon refuses to follow one, but a
|
|
# root-owned directory keeps the log from being tampered with at all.
|
|
LOGDIR="/usr/local/var/log/fips"
|
|
mkdir -p "$LOGDIR"
|
|
chown root:wheel "$LOGDIR"
|
|
chmod 755 "$LOGDIR"
|
|
|
|
# Flush DNS cache so macOS picks up the new /etc/resolver/fips file
|
|
dscacheutil -flushcache
|
|
killall -HUP mDNSResponder 2>/dev/null || true
|
|
log "flushed DNS cache"
|
|
|
|
# Create fips group if it doesn't exist
|
|
if ! dscl . -read /Groups/fips > /dev/null 2>&1; then
|
|
dscl . -create /Groups/fips RecordName fips
|
|
dscl . -create /Groups/fips PrimaryGroupID 999
|
|
log "created group fips"
|
|
fi
|
|
|
|
# stat /dev/console gives the user logged into the GUI session —
|
|
# logname/SUDO_USER are not set in pkg postinstall context
|
|
REAL_USER="$(stat -f '%Su' /dev/console 2>/dev/null || true)"
|
|
log "console user: ${REAL_USER:-unknown}"
|
|
if [ -n "$REAL_USER" ] && [ "$REAL_USER" != "root" ]; then
|
|
if ! dscl . -read /Groups/fips GroupMembership 2>/dev/null | grep -qw "$REAL_USER"; then
|
|
dscl . -append /Groups/fips GroupMembership "$REAL_USER"
|
|
log "added $REAL_USER to group fips"
|
|
else
|
|
log "$REAL_USER already in group fips"
|
|
fi
|
|
fi
|
|
|
|
# Load the launchd service
|
|
launchctl bootout system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
|
|
launchctl bootstrap system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
|
|
log "launchd service loaded"
|
|
|
|
log "postinstall complete"
|
|
exit 0
|
|
POSTINSTALL
|
|
chmod +x "${SCRIPTS_DIR}/postinstall"
|
|
|
|
# Create preinstall script (stop service before upgrade)
|
|
cat > "${SCRIPTS_DIR}/preinstall" <<'PREINSTALL'
|
|
#!/bin/sh
|
|
# Stop service before upgrade
|
|
launchctl bootout system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
|
|
exit 0
|
|
PREINSTALL
|
|
chmod +x "${SCRIPTS_DIR}/preinstall"
|
|
|
|
# Build the .pkg
|
|
mkdir -p "${DEPLOY_DIR}"
|
|
pkgbuild \
|
|
--root "${STAGING_DIR}" \
|
|
--scripts "${SCRIPTS_DIR}" \
|
|
--identifier com.fips.pkg \
|
|
--version "${VERSION}" \
|
|
--ownership recommended \
|
|
"${DEPLOY_DIR}/${PKG_NAME}.pkg"
|
|
|
|
echo ""
|
|
echo "Package built: deploy/${PKG_NAME}.pkg"
|
|
ls -lh "${DEPLOY_DIR}/${PKG_NAME}.pkg"
|
|
echo ""
|
|
echo "Install with: sudo installer -pkg deploy/${PKG_NAME}.pkg -target /"
|
|
echo "Remove with: sudo packaging/macos/uninstall.sh"
|