Files
fips/packaging/systemd/uninstall.sh
T
Johnathan Corgan c99e6d3908 Remove every DNS routing file on purge and uninstall, and restart the resolver that used it
When the package was purged, or the tarball uninstalled, while fips-dns
was not running, fips-dns-teardown never ran and the DNS routing that
fips-dns-setup wrote stayed behind. The cleanup in postrm purge and in
uninstall.sh was meant to catch that case but removed the dns-delegate
file from the wrong directory (dns-delegate/ instead of dns-delegate.d/),
never removed the systemd-resolved global drop-in, and restarted no
resolver. systemd-resolved kept sending .fips queries to [::1]:5354,
where nothing listens any more, so .fips lookups timed out.

Both scripts now remove all four files fips-dns-setup can write, and
restart systemd-resolved, reload dnsmasq or reload NetworkManager when
they removed that resolver's file and it is running. A failed restart
prints a warning and does not fail the removal.

A packaging test pins both scripts to the paths fips-dns-setup and
fips-dns-teardown use, and the deb-install scenario now purges the
package with the routing file in place and fips-dns stopped, checking
the file is gone and systemd-resolved restarted. The CI comment on the
arm64 leg is corrected to say that leg now runs that purge.
No suite runs uninstall.sh, and the test's doc comment says so.
2026-09-24 22:44:42 +00:00

122 lines
3.8 KiB
Bash
Executable File

#!/usr/bin/env bash
# FIPS Uninstall Script
#
# Removes the FIPS daemon, service, and optionally configuration.
#
# Usage: sudo ./uninstall.sh [--purge]
# --purge Also remove /etc/fips/ and the fips system group
set -euo pipefail
PURGE=false
if [ "${1:-}" = "--purge" ]; then
PURGE=true
fi
if [ "$(id -u)" -ne 0 ]; then
echo "Error: This script must be run as root (use sudo)." >&2
exit 1
fi
# --- Stop and disable services ---
# Stop dependents (firewall, gateway, dns) before the daemon to avoid
# noisy "fips0 disappeared" cascades during the teardown.
for unit in fips-gateway.service fips-firewall.service fips-dns.service fips.service; do
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
echo "Stopping ${unit}..."
systemctl stop "${unit}"
fi
if systemctl is-enabled --quiet "${unit}" 2>/dev/null; then
systemctl disable "${unit}"
fi
done
# --- Remove systemd units ---
rm -f /etc/systemd/system/fips.service
rm -f /etc/systemd/system/fips-dns.service
rm -f /etc/systemd/system/fips-gateway.service
rm -f /etc/systemd/system/fips-firewall.service
rm -rf /usr/lib/fips/
systemctl daemon-reload
echo "systemd units and DNS scripts removed."
# --- Remove DNS routing ---
# fips-dns-setup may have written one of these, and stopping fips-dns.service
# above runs fips-dns-teardown only when the unit was active. The paths match
# packaging/common/fips-dns-teardown.
restart_resolved=false
if [ -f /etc/systemd/dns-delegate.d/fips.dns-delegate ]; then
rm -f /etc/systemd/dns-delegate.d/fips.dns-delegate
echo "Removed /etc/systemd/dns-delegate.d/fips.dns-delegate."
restart_resolved=true
fi
if [ -f /etc/systemd/resolved.conf.d/fips.conf ]; then
rm -f /etc/systemd/resolved.conf.d/fips.conf
echo "Removed /etc/systemd/resolved.conf.d/fips.conf."
restart_resolved=true
fi
# Only pre-v0.3.0 development builds wrote this path, and systemd never read it.
rm -f /etc/systemd/dns-delegate/fips.dns-delegate
if $restart_resolved && systemctl is-active --quiet systemd-resolved.service 2>/dev/null; then
if systemctl restart systemd-resolved; then
echo "systemd-resolved restarted."
else
echo "Warning: could not restart systemd-resolved; restart it to drop the .fips route." >&2
fi
fi
if [ -f /etc/dnsmasq.d/fips.conf ]; then
rm -f /etc/dnsmasq.d/fips.conf
echo "Removed /etc/dnsmasq.d/fips.conf."
if systemctl is-active --quiet dnsmasq.service 2>/dev/null; then
if systemctl reload dnsmasq; then
echo "dnsmasq reloaded."
else
echo "Warning: could not reload dnsmasq; reload it to drop the .fips route." >&2
fi
fi
fi
if [ -f /etc/NetworkManager/dnsmasq.d/fips.conf ]; then
rm -f /etc/NetworkManager/dnsmasq.d/fips.conf
echo "Removed /etc/NetworkManager/dnsmasq.d/fips.conf."
if systemctl is-active --quiet NetworkManager.service 2>/dev/null \
&& command -v nmcli >/dev/null 2>&1; then
if nmcli general reload; then
echo "NetworkManager reloaded."
else
echo "Warning: could not reload NetworkManager; reload it to drop the .fips route." >&2
fi
fi
fi
# --- Remove tmpfiles.d entry ---
rm -f /etc/tmpfiles.d/fips.conf
# --- Remove binaries ---
rm -f /usr/local/bin/fips /usr/local/bin/fipsctl /usr/local/bin/fipstop /usr/local/bin/fips-gateway
echo "Binaries removed."
# --- Optionally remove configuration and group ---
if $PURGE; then
echo "Purging /etc/fips/ (including identity key files)..."
rm -rf /etc/fips/
if getent group fips &>/dev/null; then
groupdel fips
echo "System group 'fips' removed."
fi
echo "Configuration and group removed."
else
echo "Configuration and identity preserved at /etc/fips/"
echo " Use --purge to remove everything (including key files and group)."
fi
echo ""
echo "Uninstall complete."