Files
fips/packaging/openwrt-ipk/scripts/postinst
T
Johnathan Corgan 9462d5d125 Restart fips and the gateway when an apk upgrade replaces them
apk-tools v3 runs only the incoming package's pre-upgrade and post-upgrade
scripts on an upgrade, and the .apk registered neither. An upgrade replaced
the binaries and init scripts on disk but left procd running the old fips
and fips-gateway processes until a reboot or a manual restart.

The .apk now registers pre-upgrade and post-upgrade as thin wrappers around
the same prerm and postinst bodies the .ipk ships. One header line gives each
body the opkg upgrade contract it already handles: pre-upgrade rewrites apk's
"<new> <old>" arguments to "upgrade <new>", so prerm stops both services
without disabling them and leaves its marker, and post-upgrade exports
PKG_UPGRADE=1, as OpenWrt's own package-pack.mk does, so postinst starts fips
and starts the gateway only if it was enabled. Registering post-upgrade alone
would not have been enough: procd ignores a start of a running instance whose
command line is unchanged, so the services have to be stopped first.

testing/openwrt/package-test.sh runs the real build-apk.sh on the host
against a stub apk and checks the registered phases, the #! lines, that the
install and removal scripts are the shipped bodies, and, by executing each
wrapper's header with apk's argv and environment, that the upgrade pair hands
the bodies the right arguments. The ash harness runs it first and then runs
the captured scripts in three new apk scenarios, and the packaging workflow's
apk structural check now requires all four scripts in the adbdump.

An upgrade onto a package built this way was run on OpenWrt 25.12.2 with its
apk-tools 3.0.5: apk ran both pre-upgrade and post-upgrade, and both came from
the incoming package.

The adbdump key format the workflow check matches, each script as a
"<phase>:" key under scripts:, was read from the apk-tools v3.0.5 source
(src/serialize_yaml.c), the tag the packaging workflow builds from source.
It matches the dump that source-built 3.0.5 printed for this change in the
packaging workflow, where all four scripts appeared under scripts: and
passed the check on both architectures. OpenWrt's own apk-tools 3.0.5 is
built without mkpkg, and on a router adbdump cannot read the installed
database and info has no --scripts, so which scripts an installed package
registered cannot be read back on a device. The check covers the built
package only.
2026-09-26 20:41:13 +00:00

50 lines
1.8 KiB
Bash
Executable File

#!/bin/sh
# Maintainer script run after the FIPS package is unpacked.
#
# Installed as the .ipk CONTROL/postinst and registered as the .apk
# post-install script, and as the .apk post-upgrade script with PKG_UPGRADE=1
# exported ahead of this body, so one body serves both packagers.
#
# The fips daemon is enabled and started on every install. The gateway is not:
# the package ships that service disabled, and the README and the deployment
# tutorial tell the operator to enable it deliberately.
#
# Upgrades are the awkward case, because opkg runs the OLD package's prerm
# before any script from the new one:
#
# marker present the old package was one of these, its prerm left
# enablement alone, and the gateway only needs starting
# again if it was enabled;
# no marker the old package's prerm disabled the gateway on its way
# out, so its former state is unrecoverable; the gateway is
# re-enabled, which also re-enables one an operator had
# disabled by hand.
#
# Under apk, a fresh install runs this as post-install and the gateway stays
# off. An upgrade runs it as post-upgrade, after the .apk pre-upgrade script
# (the prerm body) has stopped the services and left the marker.
UPGRADE_MARKER=/tmp/fips-prerm-upgrade
# Run first-boot UCI setup (the script deletes itself when done).
if [ -x /etc/uci-defaults/90-fips-setup ]; then
/etc/uci-defaults/90-fips-setup && rm -f /etc/uci-defaults/90-fips-setup
fi
/etc/init.d/fips enable
/etc/init.d/fips start
if [ "${PKG_UPGRADE:-0}" = "1" ]; then
if [ -e "$UPGRADE_MARKER" ]; then
rm -f "$UPGRADE_MARKER"
else
/etc/init.d/fips-gateway enable
fi
if /etc/init.d/fips-gateway enabled 2>/dev/null; then
/etc/init.d/fips-gateway start
fi
fi
exit 0