mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
A process started by the service control manager has no standard handles, and writes to its absent stdout report success, so everything the daemon logged in service mode was lost. So were config-load failures, the service's own error report and panic messages, which all went to stderr. In service mode the daemon now logs to C:\ProgramData\fips\fips.log. The file is rolled at 10 MiB with four old files kept, so it takes at most about 50 MiB. A roll that fails, for example because another process holds the file, keeps writing to the current file and is not retried until another 10 MiB have been written. Config-load failures, the service error and panic messages go to the same file. A foreground run still logs to the console, and --install-service names the log file. The writer is built in rather than taken from a crate, so it is tested on every platform and adds no dependency. The Windows ZIP's README and the fips reference now say where the service log goes, and install-service.ps1 prints the log path.
137 lines
3.8 KiB
PowerShell
137 lines
3.8 KiB
PowerShell
# Build a Windows ZIP package for FIPS.
|
|
#
|
|
# Usage: powershell -File packaging/windows/build-zip.ps1 [-Version <version>] [-NoBuild]
|
|
# Output: deploy/fips-<version>-windows-x86_64.zip
|
|
#
|
|
# Prerequisites: Rust toolchain installed
|
|
|
|
param(
|
|
[string]$Version = "",
|
|
[switch]$NoBuild
|
|
)
|
|
|
|
$ErrorActionPreference = "Stop"
|
|
|
|
$ScriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
|
|
$PackagingDir = Split-Path -Parent $ScriptDir
|
|
$ProjectRoot = Split-Path -Parent $PackagingDir
|
|
|
|
# Derive version from Cargo.toml if not provided
|
|
if (-not $Version) {
|
|
$cargoToml = Get-Content "$ProjectRoot\Cargo.toml" -Raw
|
|
if ($cargoToml -match 'version\s*=\s*"([^"]+)"') {
|
|
$Version = $Matches[1]
|
|
} else {
|
|
Write-Error "Could not determine version from Cargo.toml"
|
|
exit 1
|
|
}
|
|
}
|
|
|
|
$Arch = "x86_64"
|
|
$PkgName = "fips-$Version-windows-$Arch"
|
|
$DeployDir = "$ProjectRoot\deploy"
|
|
$StagingDir = "$env:TEMP\fips-staging-$([guid]::NewGuid().ToString('N'))"
|
|
$BinaryDir = "$ProjectRoot\target\release"
|
|
|
|
Write-Host "Building FIPS v$Version for Windows $Arch..."
|
|
|
|
# Build release binaries
|
|
if (-not $NoBuild) {
|
|
Push-Location $ProjectRoot
|
|
cargo build --release
|
|
if ($LASTEXITCODE -ne 0) {
|
|
Write-Error "cargo build failed"
|
|
exit 1
|
|
}
|
|
Pop-Location
|
|
}
|
|
|
|
# Verify binaries exist
|
|
$Binaries = @("fips.exe", "fipsctl.exe", "fipstop.exe")
|
|
foreach ($bin in $Binaries) {
|
|
if (-not (Test-Path "$BinaryDir\$bin")) {
|
|
Write-Error "Missing binary: $BinaryDir\$bin"
|
|
exit 1
|
|
}
|
|
}
|
|
|
|
# Create staging directory
|
|
New-Item -ItemType Directory -Force -Path $StagingDir | Out-Null
|
|
|
|
# Copy binaries
|
|
foreach ($bin in $Binaries) {
|
|
Copy-Item "$BinaryDir\$bin" "$StagingDir\$bin"
|
|
}
|
|
|
|
# Copy config
|
|
Copy-Item "$PackagingDir\common\fips.yaml" "$StagingDir\fips.yaml"
|
|
Copy-Item "$PackagingDir\common\hosts" "$StagingDir\hosts"
|
|
|
|
# Copy helper scripts
|
|
Copy-Item "$ScriptDir\install-service.ps1" "$StagingDir\install-service.ps1"
|
|
Copy-Item "$ScriptDir\uninstall-service.ps1" "$StagingDir\uninstall-service.ps1"
|
|
|
|
# Create README
|
|
@"
|
|
FIPS v$Version for Windows
|
|
==========================
|
|
|
|
Quick Start (foreground mode):
|
|
.\fips.exe -c fips.yaml
|
|
|
|
Windows Service:
|
|
# Install (requires Administrator)
|
|
powershell -File install-service.ps1
|
|
|
|
# Manage
|
|
sc start fips
|
|
sc stop fips
|
|
|
|
# Uninstall
|
|
powershell -File uninstall-service.ps1
|
|
|
|
TUN Support:
|
|
Download wintun.dll from https://www.wintun.net/ and place it
|
|
in the same directory as fips.exe. Running the daemon requires
|
|
Administrator privileges for TUN creation.
|
|
|
|
Control Socket:
|
|
The control socket uses TCP on localhost:21210.
|
|
fipsctl and fipstop connect to this port automatically.
|
|
|
|
Configuration:
|
|
The service reads C:\ProgramData\fips\fips.yaml, where
|
|
install-service.ps1 puts it, and keeps fips.key, hosts,
|
|
peers.allow and peers.deny beside it. Edit fips.yaml there
|
|
before starting the service.
|
|
|
|
A foreground run takes -c <file>, or reads
|
|
C:\ProgramData\fips\fips.yaml and then, as per-user overrides
|
|
the service does not read, %APPDATA%\fips\fips.yaml,
|
|
%USERPROFILE%\.fips.yaml and .\fips.yaml. The key file sits
|
|
beside the last config loaded.
|
|
|
|
fipsctl keygen writes to C:\ProgramData\fips by default and
|
|
needs an elevated prompt.
|
|
|
|
Logs:
|
|
The service logs to C:\ProgramData\fips\fips.log, rolled at
|
|
10 MiB with four old files kept. A foreground run logs to the
|
|
console.
|
|
"@ | Out-File -FilePath "$StagingDir\README.txt" -Encoding UTF8
|
|
|
|
# Create ZIP
|
|
New-Item -ItemType Directory -Force -Path $DeployDir | Out-Null
|
|
$ZipPath = "$DeployDir\$PkgName.zip"
|
|
if (Test-Path $ZipPath) { Remove-Item $ZipPath }
|
|
Compress-Archive -Path "$StagingDir\*" -DestinationPath $ZipPath
|
|
|
|
# Cleanup
|
|
Remove-Item -Recurse -Force $StagingDir
|
|
|
|
Write-Host ""
|
|
Write-Host "Package built: deploy\$PkgName.zip"
|
|
Write-Host " Size: $([math]::Round((Get-Item $ZipPath).Length / 1MB, 2)) MB"
|
|
Write-Host ""
|
|
Write-Host "Extract and run: .\fips.exe -c fips.yaml"
|