Files
fips/packaging/debian/postrm
T
Johnathan Corgan faeac11ca8 Remove the .fips DNS routing on package remove, not only on purge
Removing the .deb while fips-dns was not running left the resolver's
.fips routing file in place. prerm stops fips-dns, but systemd runs its
teardown only for an active unit, and postrm cleaned up the routing only
on purge. After an apt remove the resolver kept sending .fips queries to
[::1]:5354, where nothing listens once the daemon is gone, so .fips
lookups timed out until the file was deleted by hand.

postrm now runs the DNS cleanup on both remove and purge. A purge of an
installed package runs remove and then purge; the second pass finds no
file and restarts nothing. A purge of a package already removed runs
only the purge pass, which still cleans up. Configuration, keys and the
fips group are still removed only on purge.

The deb-install check now removes the package with the routing planted
and fips-dns stopped, then plants the routing again and purges from
config-files state, so each postrm branch is exercised on its own. The
packaging text test reads the remove|purge branch.
2026-10-06 00:25:59 +00:00

74 lines
2.8 KiB
Bash
Executable File

#!/bin/sh
# FIPS post-removal script for Debian/Ubuntu
set -e
case "$1" in
remove|purge)
# Remove the DNS routing fips-dns-setup may have written, in case
# fips-dns-teardown did not run (prerm's stop runs it only when
# fips-dns.service was active), and make the resolver drop it. This
# runs on remove as well as purge: a removed package leaves nothing
# listening behind the routing, and purging a package already removed
# runs only postrm purge. On a purge of an installed package the
# purge pass finds nothing left and restarts nothing. The paths match
# packaging/common/fips-dns-teardown, which dpkg has already removed,
# so it cannot be called from here.
restart_resolved=0
if [ -f /etc/systemd/dns-delegate.d/fips.dns-delegate ]; then
rm -f /etc/systemd/dns-delegate.d/fips.dns-delegate
restart_resolved=1
fi
if [ -f /etc/systemd/resolved.conf.d/fips.conf ]; then
rm -f /etc/systemd/resolved.conf.d/fips.conf
restart_resolved=1
fi
# Only pre-v0.3.0 development builds wrote this path, and systemd
# never read it.
rm -f /etc/systemd/dns-delegate/fips.dns-delegate
if [ "$restart_resolved" = 1 ] && [ -d /run/systemd/system ] \
&& systemctl is-active --quiet systemd-resolved.service; then
systemctl restart systemd-resolved \
|| echo "fips: warning: could not restart systemd-resolved; restart it to drop the .fips route"
fi
if [ -f /etc/dnsmasq.d/fips.conf ]; then
rm -f /etc/dnsmasq.d/fips.conf
if [ -d /run/systemd/system ] \
&& systemctl is-active --quiet dnsmasq.service; then
systemctl reload dnsmasq \
|| echo "fips: warning: could not reload dnsmasq; reload it to drop the .fips route"
fi
fi
if [ -f /etc/NetworkManager/dnsmasq.d/fips.conf ]; then
rm -f /etc/NetworkManager/dnsmasq.d/fips.conf
if [ -d /run/systemd/system ] \
&& systemctl is-active --quiet NetworkManager.service \
&& command -v nmcli >/dev/null 2>&1; then
nmcli general reload \
|| echo "fips: warning: could not reload NetworkManager; reload it to drop the .fips route"
fi
fi
;;
esac
case "$1" in
purge)
# Remove configuration and identity keys
rm -rf /etc/fips/
# Remove tmpfiles.d entry
rm -f /usr/lib/tmpfiles.d/fips.conf
# Remove runtime directory
rm -rf /run/fips/
# Remove fips system group
if getent group fips >/dev/null 2>&1; then
groupdel fips 2>/dev/null || true
fi
;;
esac
#DEBHELPER#
exit 0