mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
When the package was purged, or the tarball uninstalled, while fips-dns was not running, fips-dns-teardown never ran and the DNS routing that fips-dns-setup wrote stayed behind. The cleanup in postrm purge and in uninstall.sh was meant to catch that case but removed the dns-delegate file from the wrong directory (dns-delegate/ instead of dns-delegate.d/), never removed the systemd-resolved global drop-in, and restarted no resolver. systemd-resolved kept sending .fips queries to [::1]:5354, where nothing listens any more, so .fips lookups timed out. Both scripts now remove all four files fips-dns-setup can write, and restart systemd-resolved, reload dnsmasq or reload NetworkManager when they removed that resolver's file and it is running. A failed restart prints a warning and does not fail the removal. A packaging test pins both scripts to the paths fips-dns-setup and fips-dns-teardown use, and the deb-install scenario now purges the package with the routing file in place and fips-dns stopped, checking the file is gone and systemd-resolved restarted. The CI comment on the arm64 leg is corrected to say that leg now runs that purge. No suite runs uninstall.sh, and the test's doc comment says so.
66 lines
2.5 KiB
Bash
Executable File
66 lines
2.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# FIPS post-removal script for Debian/Ubuntu
|
|
set -e
|
|
|
|
case "$1" in
|
|
purge)
|
|
# Remove configuration and identity keys
|
|
rm -rf /etc/fips/
|
|
|
|
# Remove tmpfiles.d entry
|
|
rm -f /usr/lib/tmpfiles.d/fips.conf
|
|
|
|
# Remove runtime directory
|
|
rm -rf /run/fips/
|
|
|
|
# Remove the DNS routing fips-dns-setup may have written, in case
|
|
# fips-dns-teardown did not run (prerm's stop runs it only when
|
|
# fips-dns.service was active), and make the resolver drop it. The
|
|
# paths match packaging/common/fips-dns-teardown, which dpkg has
|
|
# already removed, so it cannot be called from here.
|
|
restart_resolved=0
|
|
if [ -f /etc/systemd/dns-delegate.d/fips.dns-delegate ]; then
|
|
rm -f /etc/systemd/dns-delegate.d/fips.dns-delegate
|
|
restart_resolved=1
|
|
fi
|
|
if [ -f /etc/systemd/resolved.conf.d/fips.conf ]; then
|
|
rm -f /etc/systemd/resolved.conf.d/fips.conf
|
|
restart_resolved=1
|
|
fi
|
|
# Only pre-v0.3.0 development builds wrote this path, and systemd
|
|
# never read it.
|
|
rm -f /etc/systemd/dns-delegate/fips.dns-delegate
|
|
if [ "$restart_resolved" = 1 ] && [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet systemd-resolved.service; then
|
|
systemctl restart systemd-resolved \
|
|
|| echo "fips: warning: could not restart systemd-resolved; restart it to drop the .fips route"
|
|
fi
|
|
if [ -f /etc/dnsmasq.d/fips.conf ]; then
|
|
rm -f /etc/dnsmasq.d/fips.conf
|
|
if [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet dnsmasq.service; then
|
|
systemctl reload dnsmasq \
|
|
|| echo "fips: warning: could not reload dnsmasq; reload it to drop the .fips route"
|
|
fi
|
|
fi
|
|
if [ -f /etc/NetworkManager/dnsmasq.d/fips.conf ]; then
|
|
rm -f /etc/NetworkManager/dnsmasq.d/fips.conf
|
|
if [ -d /run/systemd/system ] \
|
|
&& systemctl is-active --quiet NetworkManager.service \
|
|
&& command -v nmcli >/dev/null 2>&1; then
|
|
nmcli general reload \
|
|
|| echo "fips: warning: could not reload NetworkManager; reload it to drop the .fips route"
|
|
fi
|
|
fi
|
|
|
|
# Remove fips system group
|
|
if getent group fips >/dev/null 2>&1; then
|
|
groupdel fips 2>/dev/null || true
|
|
fi
|
|
;;
|
|
esac
|
|
|
|
#DEBHELPER#
|
|
|
|
exit 0
|