Files
fips/packaging/macos/build-pkg.sh
T
Arjen 98786e527a feat(logging): let the daemon own and rotate its log file
The macOS package accumulated a single unbounded log file — 717 MB on a
node running at debug level. Nothing rotated it, and nothing could.

fips logs to stdout and leaves capture to the supervisor, which is right
where the platform rotates that stream: journald does, and so does syslog
under procd. launchd does not. It redirects stdout to a plain file and
appends to it forever, and the usual rename-and-signal rotators cannot
help, because launchd holds the descriptor and passes it as fd 1 — the
daemon has no way to reopen a file rotated out from under it, and
signalling it achieves nothing. Rotation therefore has to happen in the
process that writes, which means the daemon has to own the file.

`node.log_file` names it, and is unset by default so every platform whose
supervisor already rotates keeps logging to stdout exactly as before —
setting it there would only duplicate what journald and syslog hold.
`node.log_rotation` (hourly/daily/never, default daily) and
`node.log_max_files` (default 7) govern the roll. Both parse leniently in
the same way as `node.log_level`: a typo falls back to the default rather
than refusing to boot, and the resolved values are logged at startup.

Rotation is by period rather than by size, so `node.log_level` is what
actually governs volume — debug costs roughly an order of magnitude more
per day than info. Retention bounds the rest.

Writes go through a non-blocking appender, so a slow or full disk cannot
stall the tick loop behind a log write. The worker guard is held for the
lifetime of the daemon; dropping it would silently discard every line
logged afterward.

The live file carries the date the current period opened, since that is
how the appender names a rolled file. Splitting the configured path on its
extension rather than suffixing the whole name keeps `.log` on the end, so
`/var/log/fips/fips.log` is written as `fips.2026-08-31.log`. That does
mean the current file no longer has a fixed name; the packaged config
carries the `tail` incantation for it.

Opening the log is fatal on failure, matching how this binary treats an
unusable config. A daemon that silently dropped its logging because a
directory was unwritable would present as exactly the disappearing-logs
problem this exists to fix.

macOS packaging is the only one that turns this on. The plist stops
redirecting stdout and stderr, which would otherwise reintroduce the
unbounded file alongside the rotated one; the cost is that a failure
before logging initialises, and a panic, now go nowhere rather than to
fips.log. The setting is inserted after the `node:` key rather than
appended to the shared config, which ends at a top-level `peers:` key —
an appended block would land under the wrong mapping, and a second
top-level `node:` would collide with the first.
2026-08-31 09:36:50 +01:00

241 lines
7.8 KiB
Bash
Executable File

#!/usr/bin/env bash
# Build a macOS .pkg installer for FIPS.
#
# Usage: ./packaging/macos/build-pkg.sh [--version <version>] [--no-build]
# Output: deploy/fips-<version>-macos-<arch>.pkg
#
# Prerequisites: Xcode command-line tools (pkgbuild is included)
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PACKAGING_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)"
PROJECT_ROOT="$(cd "${PACKAGING_DIR}/.." && pwd)"
usage() {
cat <<'EOF'
Usage: packaging/macos/build-pkg.sh [options]
Options:
--version <version> Override package version
--target <triple> Rust target triple (e.g. x86_64-apple-darwin)
--no-build Package existing binaries without running cargo build
-h, --help Show this help
EOF
}
VERSION_OVERRIDE=""
TARGET_TRIPLE=""
NO_BUILD=0
while [[ $# -gt 0 ]]; do
case "$1" in
--version)
VERSION_OVERRIDE="${2:?missing value for --version}"
shift 2
;;
--target)
TARGET_TRIPLE="${2:?missing value for --target}"
shift 2
;;
--no-build)
NO_BUILD=1
shift
;;
-h|--help)
usage
exit 0
;;
*)
echo "Unknown option: $1" >&2
usage >&2
exit 1
;;
esac
done
VERSION="${VERSION_OVERRIDE:-$(grep '^version' "${PROJECT_ROOT}/Cargo.toml" | head -1 | sed 's/.*"\(.*\)"/\1/')}"
# Derive the package architecture from the build target, not the build
# host. When cross-compiling (for example building the x86_64 package on
# an Apple-silicon machine) `uname -m` reports the host architecture and
# would mislabel the package; the Rust target triple is authoritative.
if [[ -n "${TARGET_TRIPLE}" ]]; then
case "${TARGET_TRIPLE}" in
aarch64-*) ARCH="arm64" ;;
x86_64-*) ARCH="x86_64" ;;
*)
echo "Unsupported target triple: ${TARGET_TRIPLE}" >&2
exit 1
;;
esac
else
ARCH="$(uname -m)"
fi
PKG_NAME="fips-${VERSION}-macos-${ARCH}"
DEPLOY_DIR="${PROJECT_ROOT}/deploy"
STAGING_DIR="$(mktemp -d)"
SCRIPTS_DIR="$(mktemp -d)"
trap 'rm -rf "${STAGING_DIR}" "${SCRIPTS_DIR}"' EXIT
if [[ -n "${TARGET_TRIPLE}" ]]; then
BINARY_DIR="${PROJECT_ROOT}/target/${TARGET_TRIPLE}/release"
else
BINARY_DIR="${PROJECT_ROOT}/target/release"
fi
echo "Building FIPS v${VERSION} for macOS ${ARCH}..."
# Build release binaries
if [[ "${NO_BUILD}" -eq 0 ]]; then
cargo_args=(build --release --manifest-path="${PROJECT_ROOT}/Cargo.toml")
[[ -n "${TARGET_TRIPLE}" ]] && cargo_args+=(--target "${TARGET_TRIPLE}")
cargo "${cargo_args[@]}"
fi
# Verify binaries exist
for bin in fips fipsctl fipstop; do
if [[ ! -f "${BINARY_DIR}/${bin}" ]]; then
echo "Missing binary: ${BINARY_DIR}/${bin}" >&2
exit 1
fi
done
# Stage the payload (mirrors installed filesystem layout)
mkdir -p "${STAGING_DIR}/usr/local/bin"
mkdir -p "${STAGING_DIR}/usr/local/etc/fips"
mkdir -p "${STAGING_DIR}/usr/local/var/log/fips"
mkdir -p "${STAGING_DIR}/Library/LaunchDaemons"
mkdir -p "${STAGING_DIR}/etc/resolver"
# Binaries
for bin in fips fipsctl fipstop; do
cp "${BINARY_DIR}/${bin}" "${STAGING_DIR}/usr/local/bin/"
strip "${STAGING_DIR}/usr/local/bin/${bin}"
done
# Config (marked as conf file via postinstall logic — won't overwrite on upgrade)
cp "${PACKAGING_DIR}/common/fips.yaml" "${STAGING_DIR}/usr/local/etc/fips/fips.yaml.default"
# Turn on file logging, which is a macOS-only default. Everywhere else the
# daemon logs to stdout and the platform rotates it (journald, syslog);
# launchd has no rotation at all, so the daemon has to own the file itself.
# Set here rather than in packaging/common/fips.yaml, which is shared with
# the platforms that must keep logging to stdout.
#
# Inserted directly after the `node:` line rather than appended: the shared
# config ends at a top-level `peers:` key, so an appended block would land
# under the wrong mapping, and a second top-level `node:` would collide with
# the first.
LOG_SETTINGS=' # Log rotation. launchd does not rotate what it captures, so the\
# daemon owns this file and rolls it. The live file carries the date the\
# period opened -- with the settings below, fips.<YYYY-MM-DD>.log -- and\
# the oldest is deleted once log_max_files exist. Follow the current one\
# with: tail -f "$(ls -t /usr/local/var/log/fips/fips.*.log | head -1)"\
log_file: /usr/local/var/log/fips/fips.log\
log_rotation: daily\
log_max_files: 7'
CONF_DEFAULT="${STAGING_DIR}/usr/local/etc/fips/fips.yaml.default"
if ! grep -q '^node:' "${CONF_DEFAULT}"; then
echo "packaging/common/fips.yaml has no top-level 'node:' key to insert log settings under" >&2
exit 1
fi
awk -v settings="${LOG_SETTINGS}" '
{ print }
!done && /^node:$/ { print settings; done = 1 }
' "${CONF_DEFAULT}" > "${CONF_DEFAULT}.tmp"
mv "${CONF_DEFAULT}.tmp" "${CONF_DEFAULT}"
cp "${PACKAGING_DIR}/common/hosts" "${STAGING_DIR}/usr/local/etc/fips/hosts.default"
# LaunchDaemon plist
cp "${SCRIPT_DIR}/com.fips.daemon.plist" "${STAGING_DIR}/Library/LaunchDaemons/"
# DNS resolver. Must match the daemon's dns.bind_addr (defaults to ::1).
cat > "${STAGING_DIR}/etc/resolver/fips" <<EOF
nameserver ::1
port 5354
EOF
# Create postinstall script
cat > "${SCRIPTS_DIR}/postinstall" <<'POSTINSTALL'
#!/bin/sh
set -e
LOG="/var/log/fips-install.log"
log() { echo "$(date '+%Y-%m-%d %H:%M:%S') $*" | tee -a "$LOG"; logger -t fips-install "$*"; }
log "postinstall started"
CONFDIR="/usr/local/etc/fips"
# Install default config only if none exists (preserve on upgrade)
if [ ! -f "$CONFDIR/fips.yaml" ]; then
cp "$CONFDIR/fips.yaml.default" "$CONFDIR/fips.yaml"
chmod 600 "$CONFDIR/fips.yaml"
log "installed default config"
fi
if [ ! -f "$CONFDIR/hosts" ]; then
cp "$CONFDIR/hosts.default" "$CONFDIR/hosts"
fi
# Flush DNS cache so macOS picks up the new /etc/resolver/fips file
dscacheutil -flushcache
killall -HUP mDNSResponder 2>/dev/null || true
log "flushed DNS cache"
# Create fips group if it doesn't exist
if ! dscl . -read /Groups/fips > /dev/null 2>&1; then
dscl . -create /Groups/fips RecordName fips
dscl . -create /Groups/fips PrimaryGroupID 999
log "created group fips"
fi
# stat /dev/console gives the user logged into the GUI session —
# logname/SUDO_USER are not set in pkg postinstall context
REAL_USER="$(stat -f '%Su' /dev/console 2>/dev/null || true)"
log "console user: ${REAL_USER:-unknown}"
if [ -n "$REAL_USER" ] && [ "$REAL_USER" != "root" ]; then
if ! dscl . -read /Groups/fips GroupMembership 2>/dev/null | grep -qw "$REAL_USER"; then
dscl . -append /Groups/fips GroupMembership "$REAL_USER"
log "added $REAL_USER to group fips"
else
log "$REAL_USER already in group fips"
fi
fi
# Load the launchd service
launchctl bootout system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
launchctl bootstrap system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
log "launchd service loaded"
log "postinstall complete"
exit 0
POSTINSTALL
chmod +x "${SCRIPTS_DIR}/postinstall"
# Create preinstall script (stop service before upgrade)
cat > "${SCRIPTS_DIR}/preinstall" <<'PREINSTALL'
#!/bin/sh
# Stop service before upgrade
launchctl bootout system /Library/LaunchDaemons/com.fips.daemon.plist 2>/dev/null || true
exit 0
PREINSTALL
chmod +x "${SCRIPTS_DIR}/preinstall"
# Build the .pkg
mkdir -p "${DEPLOY_DIR}"
pkgbuild \
--root "${STAGING_DIR}" \
--scripts "${SCRIPTS_DIR}" \
--identifier com.fips.pkg \
--version "${VERSION}" \
--ownership recommended \
"${DEPLOY_DIR}/${PKG_NAME}.pkg"
echo ""
echo "Package built: deploy/${PKG_NAME}.pkg"
ls -lh "${DEPLOY_DIR}/${PKG_NAME}.pkg"
echo ""
echo "Install with: sudo installer -pkg deploy/${PKG_NAME}.pkg -target /"
echo "Remove with: sudo packaging/macos/uninstall.sh"