mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The FreeBSD package wrote the daemon's output to /var/log/fips.log and never rotated it, so the log grew without bound. Ship a newsyslog entry in /usr/local/etc/newsyslog.conf.d, which the stock newsyslog.conf includes: five bzip2-compressed generations of 1000 KB, mode 600 to match the file daemon(8) creates. An entry alone would not work, because daemon(8) keeps the -o file open and reopens it on SIGHUP only when started with -H, and only the supervisor handles that signal. The rc script now starts daemon(8) with -H and records the supervisor's pid in /var/run/fips/daemon.pid, which is the pid file the entry signals. The child pidfile that rc.subr uses for stop and status is unchanged. Add a lib test that checks the rc script, the newsyslog entry and the package staging agree on the log path, the signalled pid file and the installed location. The FreeBSD package smoke install now also confirms the stock newsyslog configuration picks up the shipped entry, starts the daemon, forces a rotation of its log, and checks that daemon(8) closes the rotated file and holds the new one open. This exercises the SIGHUP reopen that the static check of the packaging files cannot.
51 lines
1.7 KiB
Bash
Executable File
51 lines
1.7 KiB
Bash
Executable File
#!/bin/sh
|
|
|
|
# PROVIDE: fips
|
|
# REQUIRE: NETWORKING FILESYSTEMS
|
|
# KEYWORD: shutdown
|
|
|
|
# rc.conf knobs:
|
|
# fips_enable (bool): Set YES to run the FIPS daemon. Default NO.
|
|
# fips_config (path): Config file. Default /usr/local/etc/fips/fips.yaml.
|
|
# fips_flags (str): Extra arguments passed to the fips daemon.
|
|
# fips_logfile (path): Daemon stdout/stderr log. Default /var/log/fips.log;
|
|
# rotated by newsyslog only at the default path.
|
|
|
|
. /etc/rc.subr
|
|
|
|
name="fips"
|
|
rcvar="fips_enable"
|
|
desc="FIPS mesh networking daemon"
|
|
|
|
load_rc_config $name
|
|
|
|
: ${fips_enable:="NO"}
|
|
: ${fips_config:="/usr/local/etc/fips/fips.yaml"}
|
|
: ${fips_logfile:="/var/log/fips.log"}
|
|
|
|
runtime_dir="/var/run/fips"
|
|
pidfile="${runtime_dir}/fips.pid"
|
|
# daemon(8) records its own pid here (-P) so newsyslog can signal it after
|
|
# rotating the log: with -H the supervisor reopens its output on SIGHUP.
|
|
supervisor_pidfile="${runtime_dir}/daemon.pid"
|
|
procname="/usr/local/bin/fips"
|
|
command="/usr/sbin/daemon"
|
|
command_args="-H -p ${pidfile} -P ${supervisor_pidfile} -t fips -o ${fips_logfile} ${procname} --config ${fips_config} ${fips_flags}"
|
|
start_precmd="fips_precmd"
|
|
|
|
# The daemon resolves its control socket to /var/run/fips when the
|
|
# directory exists, so it must be there before the daemon starts.
|
|
# root:fips 0750 (matching the Debian tmpfiles entry) lets members of
|
|
# the fips group use fipsctl/fipstop without root; the group is created
|
|
# by the package post-install. Fall back to 0755 for source builds
|
|
# where the group does not exist.
|
|
fips_precmd() {
|
|
if pw groupshow fips >/dev/null 2>&1; then
|
|
install -d -m 0750 -o root -g fips "$runtime_dir"
|
|
else
|
|
install -d -m 0755 "$runtime_dir"
|
|
fi
|
|
}
|
|
|
|
run_rc_command "$1"
|