Files
fips/packaging/debian
Johnathan Corgan c99e6d3908 Remove every DNS routing file on purge and uninstall, and restart the resolver that used it
When the package was purged, or the tarball uninstalled, while fips-dns
was not running, fips-dns-teardown never ran and the DNS routing that
fips-dns-setup wrote stayed behind. The cleanup in postrm purge and in
uninstall.sh was meant to catch that case but removed the dns-delegate
file from the wrong directory (dns-delegate/ instead of dns-delegate.d/),
never removed the systemd-resolved global drop-in, and restarted no
resolver. systemd-resolved kept sending .fips queries to [::1]:5354,
where nothing listens any more, so .fips lookups timed out.

Both scripts now remove all four files fips-dns-setup can write, and
restart systemd-resolved, reload dnsmasq or reload NetworkManager when
they removed that resolver's file and it is running. A failed restart
prints a warning and does not fail the removal.

A packaging test pins both scripts to the paths fips-dns-setup and
fips-dns-teardown use, and the deb-install scenario now purges the
package with the routing file in place and fips-dns stopped, checking
the file is gone and systemd-resolved restarted. The CI comment on the
arm64 leg is corrected to say that leg now runs that purge.
No suite runs uninstall.sh, and the test's doc comment says so.
2026-09-24 22:44:42 +00:00
..