blob: 29d0963064884c3fdb4f00933d895ae0ccc69400 [file] [log] [blame]
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +00001#!/bin/sh
2#
Tim Rice29bdd2c2002-03-11 20:55:53 -08003# Fake Root Solaris/SVR4/SVR5 Build System - Prototype
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +00004#
5# The following code has been provide under Public Domain License. I really
6# don't care what you use it for. Just as long as you don't complain to me
7# nor my employer if you break it. - Ben Lindstrom (mouring@eviladmin.org)
Damien Millera8e06ce2003-11-21 23:48:55 +11008#
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +00009umask 022
Tim Rice29bdd2c2002-03-11 20:55:53 -080010#
11# Options for building the package
12# You can create a config.local with your customized options
13#
Tim Rice88177242002-07-08 19:02:10 -070014# uncommenting TEST_DIR and using
15# configure --prefix=/var/tmp --with-privsep-path=/var/tmp/empty
Damien Millera8e06ce2003-11-21 23:48:55 +110016# and
Tim Rice29bdd2c2002-03-11 20:55:53 -080017# PKGNAME=tOpenSSH should allow testing a package without interfering
Tim Ricef1a10012002-07-19 11:57:57 -070018# with a real OpenSSH package on a system. This is not needed on systems
19# that support the -R option to pkgadd.
Tim Rice29bdd2c2002-03-11 20:55:53 -080020#TEST_DIR=/var/tmp # leave commented out for production build
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000021PKGNAME=OpenSSH
Tim Rice29bdd2c2002-03-11 20:55:53 -080022SYSVINIT_NAME=opensshd
23MAKE=${MAKE:="make"}
Tim Ricef1a10012002-07-19 11:57:57 -070024SSHDUID=67 # Default privsep uid
25SSHDGID=67 # Default privsep gid
Tim Ricec9001282004-01-22 16:10:03 -080026# uncomment these next three as needed
Tim Rice29bdd2c2002-03-11 20:55:53 -080027#PERMIT_ROOT_LOGIN=no
28#X11_FORWARDING=yes
Tim Ricec9001282004-01-22 16:10:03 -080029#USR_LOCAL_IS_SYMLINK=yes
Tim Rice29bdd2c2002-03-11 20:55:53 -080030# list of system directories we do NOT want to change owner/group/perms
31# when installing our package
32SYSTEM_DIR="/etc \
33/etc/init.d \
34/etc/rcS.d \
35/etc/rc0.d \
36/etc/rc1.d \
37/etc/rc2.d \
Tim Rice3a423462002-03-17 14:05:24 -080038/etc/opt \
Tim Rice29bdd2c2002-03-11 20:55:53 -080039/opt \
40/opt/bin \
41/usr \
42/usr/bin \
43/usr/lib \
44/usr/sbin \
45/usr/share \
46/usr/share/man \
47/usr/share/man/man1 \
48/usr/share/man/man8 \
49/usr/local \
50/usr/local/bin \
51/usr/local/etc \
52/usr/local/libexec \
53/usr/local/man \
54/usr/local/man/man1 \
55/usr/local/man/man8 \
56/usr/local/sbin \
57/usr/local/share \
58/var \
Tim Rice3a423462002-03-17 14:05:24 -080059/var/opt \
Tim Rice29bdd2c2002-03-11 20:55:53 -080060/var/run \
61/var/tmp \
62/tmp"
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000063
Tim Ricef1a10012002-07-19 11:57:57 -070064# We may need to build as root so we make sure PATH is set up
Tim Rice29bdd2c2002-03-11 20:55:53 -080065# only set the path if it's not set already
66[ -d /usr/local/bin ] && {
67 echo $PATH | grep ":/usr/local/bin" > /dev/null 2>&1
68 [ $? -ne 0 ] && PATH=$PATH:/usr/local/bin
69}
70[ -d /usr/ccs/bin ] && {
71 echo $PATH | grep ":/usr/ccs/bin" > /dev/null 2>&1
72 [ $? -ne 0 ] && PATH=$PATH:/usr/ccs/bin
73}
74export PATH
75#
76
77[ -f Makefile ] || {
78 echo "Please run this script from your build directory"
79 exit 1
80}
81
82# we will look for config.local to override the above options
83[ -s ./config.local ] && . ./config.local
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000084
Damien Millera8e06ce2003-11-21 23:48:55 +110085## Start by faking root install
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000086echo "Faking root install..."
87START=`pwd`
Tim Rice29bdd2c2002-03-11 20:55:53 -080088OPENSSHD_IN=`dirname $0`/opensshd.in
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000089FAKE_ROOT=$START/package
Tim Rice29bdd2c2002-03-11 20:55:53 -080090[ -d $FAKE_ROOT ] && rm -fr $FAKE_ROOT
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000091mkdir $FAKE_ROOT
Tim Rice29bdd2c2002-03-11 20:55:53 -080092${MAKE} install-nokeys DESTDIR=$FAKE_ROOT
93if [ $? -gt 0 ]
94then
95 echo "Fake root install failed, stopping."
96 exit 1
97fi
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +000098
99## Fill in some details, like prefix and sysconfdir
Tim Rice29bdd2c2002-03-11 20:55:53 -0800100for confvar in prefix exec_prefix bindir sbindir libexecdir datadir mandir sysconfdir piddir
101do
Damien Millera8e06ce2003-11-21 23:48:55 +1100102 eval $confvar=`grep "^$confvar=" Makefile | cut -d = -f 2`
Tim Rice29bdd2c2002-03-11 20:55:53 -0800103done
104
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000105
106## Collect value of privsep user
107for confvar in SSH_PRIVSEP_USER
108do
Damien Millera8e06ce2003-11-21 23:48:55 +1100109 eval $confvar=`awk '/#define[ \t]'$confvar'/{print $3}' config.h`
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000110done
111
112## Set privsep defaults if not defined
113if [ -z "$SSH_PRIVSEP_USER" ]
114then
Damien Millera8e06ce2003-11-21 23:48:55 +1100115 SSH_PRIVSEP_USER=sshd
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000116fi
117
Tim Rice29bdd2c2002-03-11 20:55:53 -0800118## Extract common info requires for the 'info' part of the package.
119VERSION=`./ssh -V 2>&1 | sed -e 's/,.*//'`
120
121UNAME_S=`uname -s`
122case ${UNAME_S} in
123 SunOS) UNAME_S=Solaris
124 ARCH=`uname -p`
125 RCS_D=yes
126 DEF_MSG="(default: n)"
127 ;;
Tim Rice88177242002-07-08 19:02:10 -0700128 *) ARCH=`uname -m`
129 DEF_MSG="\n" ;;
Tim Rice29bdd2c2002-03-11 20:55:53 -0800130esac
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000131
132## Setup our run level stuff while we are at it.
Tim Rice29bdd2c2002-03-11 20:55:53 -0800133mkdir -p $FAKE_ROOT${TEST_DIR}/etc/init.d
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000134
135## setup our initscript correctly
Tim Rice29bdd2c2002-03-11 20:55:53 -0800136sed -e "s#%%configDir%%#${sysconfdir}#g" \
137 -e "s#%%openSSHDir%%#$prefix#g" \
138 -e "s#%%pidDir%%#${piddir}#g" \
139 ${OPENSSHD_IN} > $FAKE_ROOT${TEST_DIR}/etc/init.d/${SYSVINIT_NAME}
140chmod 744 $FAKE_ROOT${TEST_DIR}/etc/init.d/${SYSVINIT_NAME}
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000141
Tim Rice29bdd2c2002-03-11 20:55:53 -0800142[ "${PERMIT_ROOT_LOGIN}" = no ] && \
143 perl -p -i -e "s/#PermitRootLogin yes/PermitRootLogin no/" \
144 $FAKE_ROOT/${sysconfdir}/sshd_config
145[ "${X11_FORWARDING}" = yes ] && \
146 perl -p -i -e "s/#X11Forwarding no/X11Forwarding yes/" \
147 $FAKE_ROOT/${sysconfdir}/sshd_config
148# fix PrintMotd
149perl -p -i -e "s/#PrintMotd yes/PrintMotd no/" \
150 $FAKE_ROOT/${sysconfdir}/sshd_config
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000151
Tim Rice29bdd2c2002-03-11 20:55:53 -0800152# We don't want to overwrite config files on multiple installs
153mv $FAKE_ROOT/${sysconfdir}/ssh_config $FAKE_ROOT/${sysconfdir}/ssh_config.default
154mv $FAKE_ROOT/${sysconfdir}/sshd_config $FAKE_ROOT/${sysconfdir}/sshd_config.default
155[ -f $FAKE_ROOT/${sysconfdir}/ssh_prng_cmds ] && \
156mv $FAKE_ROOT/${sysconfdir}/ssh_prng_cmds $FAKE_ROOT/${sysconfdir}/ssh_prng_cmds.default
157
158cd $FAKE_ROOT
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000159
160## Ok, this is outright wrong, but it will work. I'm tired of pkgmk
161## whining.
162for i in *; do
163 PROTO_ARGS="$PROTO_ARGS $i=/$i";
164done
165
166## Build info file
167echo "Building pkginfo file..."
168cat > pkginfo << _EOF
169PKG=$PKGNAME
Tim Rice29bdd2c2002-03-11 20:55:53 -0800170NAME="OpenSSH Portable for ${UNAME_S}"
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000171DESC="Secure Shell remote access utility; replaces telnet and rlogin/rsh."
172VENDOR="OpenSSH Portable Team - http://www.openssh.com/portable.html"
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000173ARCH=$ARCH
174VERSION=$VERSION
Tim Rice29bdd2c2002-03-11 20:55:53 -0800175CATEGORY="Security,application"
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000176BASEDIR=/
Tim Rice29bdd2c2002-03-11 20:55:53 -0800177CLASSES="none"
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000178_EOF
179
Tim Rice29bdd2c2002-03-11 20:55:53 -0800180## Build preinstall file
181echo "Building preinstall file..."
182cat > preinstall << _EOF
183#! /sbin/sh
184#
185[ "\${PRE_INS_STOP}" = "yes" ] && ${TEST_DIR}/etc/init.d/${SYSVINIT_NAME} stop
186exit 0
187_EOF
188
189## Build postinstall file
190echo "Building postinstall file..."
191cat > postinstall << _EOF
192#! /sbin/sh
193#
Tim Rice88177242002-07-08 19:02:10 -0700194[ -f \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_config ] || \\
195 cp -p \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_config.default \\
196 \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_config
197[ -f \${PKG_INSTALL_ROOT}${sysconfdir}/sshd_config ] || \\
198 cp -p \${PKG_INSTALL_ROOT}${sysconfdir}/sshd_config.default \\
199 \${PKG_INSTALL_ROOT}${sysconfdir}/sshd_config
200[ -f \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_prng_cmds.default ] && {
201 [ -f \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_prng_cmds ] || \\
202 cp -p \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_prng_cmds.default \\
203 \${PKG_INSTALL_ROOT}${sysconfdir}/ssh_prng_cmds
Tim Rice29bdd2c2002-03-11 20:55:53 -0800204}
205
206# make rc?.d dirs only if we are doing a test install
207[ -n "${TEST_DIR}" ] && {
208 [ "$RCS_D" = yes ] && mkdir -p ${TEST_DIR}/etc/rcS.d
209 mkdir -p ${TEST_DIR}/etc/rc0.d
210 mkdir -p ${TEST_DIR}/etc/rc1.d
211 mkdir -p ${TEST_DIR}/etc/rc2.d
212}
213
214if [ "\${USE_SYM_LINKS}" = yes ]
215then
216 [ "$RCS_D" = yes ] && \
Tim Rice88177242002-07-08 19:02:10 -0700217installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rcS.d/K30${SYSVINIT_NAME}=../init.d/${SYSVINIT_NAME} s
218 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc0.d/K30${SYSVINIT_NAME}=../init.d/${SYSVINIT_NAME} s
219 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc1.d/K30${SYSVINIT_NAME}=../init.d/${SYSVINIT_NAME} s
220 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc2.d/S98${SYSVINIT_NAME}=../init.d/${SYSVINIT_NAME} s
Tim Rice29bdd2c2002-03-11 20:55:53 -0800221else
222 [ "$RCS_D" = yes ] && \
Tim Rice88177242002-07-08 19:02:10 -0700223installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rcS.d/K30${SYSVINIT_NAME}=$TEST_DIR/etc/init.d/${SYSVINIT_NAME} l
224 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc0.d/K30${SYSVINIT_NAME}=$TEST_DIR/etc/init.d/${SYSVINIT_NAME} l
225 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc1.d/K30${SYSVINIT_NAME}=$TEST_DIR/etc/init.d/${SYSVINIT_NAME} l
226 installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR/etc/rc2.d/S98${SYSVINIT_NAME}=$TEST_DIR/etc/init.d/${SYSVINIT_NAME} l
Tim Rice29bdd2c2002-03-11 20:55:53 -0800227fi
228
Tim Rice3a423462002-03-17 14:05:24 -0800229# If piddir doesn't exist we add it. (Ie. --with-pid-dir=/var/opt/ssh)
Tim Rice88177242002-07-08 19:02:10 -0700230[ -d $piddir ] || installf ${PKGNAME} \${PKG_INSTALL_ROOT}$TEST_DIR$piddir d 755 root sys
Tim Rice3a423462002-03-17 14:05:24 -0800231
Tim Rice29bdd2c2002-03-11 20:55:53 -0800232installf -f ${PKGNAME}
233
Tim Ricef1a10012002-07-19 11:57:57 -0700234# Use chroot to handle PKG_INSTALL_ROOT
235if [ ! -z "\${PKG_INSTALL_ROOT}" ]
236then
237 chroot="chroot \${PKG_INSTALL_ROOT}"
238fi
239# If this is a test build, we will skip the groupadd/useradd/passwd commands
240if [ ! -z "${TEST_DIR}" ]
241then
242 chroot=echo
243fi
244
245if egrep '^[ \t]*UsePrivilegeSeparation[ \t]+no' \${PKG_INSTALL_ROOT}/$sysconfdir/sshd_config >/dev/null
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000246then
Damien Millera8e06ce2003-11-21 23:48:55 +1100247 echo "UsePrivilegeSeparation disabled in config, not creating PrivSep user"
248 echo "or group."
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000249else
Damien Millera8e06ce2003-11-21 23:48:55 +1100250 echo "UsePrivilegeSeparation enabled in config (or defaulting to on)."
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000251
Damien Millera8e06ce2003-11-21 23:48:55 +1100252 # create group if required
253 if cut -f1 -d: \${PKG_INSTALL_ROOT}/etc/group | egrep '^'$SSH_PRIVSEP_USER'\$' >/dev/null
254 then
255 echo "PrivSep group $SSH_PRIVSEP_USER already exists."
256 else
Tim Ricef1a10012002-07-19 11:57:57 -0700257 # Use gid of 67 if possible
258 if cut -f3 -d: \${PKG_INSTALL_ROOT}/etc/group | egrep '^'$SSHDGID'\$' >/dev/null
259 then
260 :
261 else
262 sshdgid="-g $SSHDGID"
263 fi
Damien Millera8e06ce2003-11-21 23:48:55 +1100264 echo "Creating PrivSep group $SSH_PRIVSEP_USER."
265 \$chroot /usr/sbin/groupadd \$sshdgid $SSH_PRIVSEP_USER
266 fi
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000267
Damien Millera8e06ce2003-11-21 23:48:55 +1100268 # Create user if required
269 if cut -f1 -d: \${PKG_INSTALL_ROOT}/etc/passwd | egrep '^'$SSH_PRIVSEP_USER'\$' >/dev/null
270 then
271 echo "PrivSep user $SSH_PRIVSEP_USER already exists."
272 else
Tim Ricef1a10012002-07-19 11:57:57 -0700273 # Use uid of 67 if possible
274 if cut -f3 -d: \${PKG_INSTALL_ROOT}/etc/passwd | egrep '^'$SSHDGID'\$' >/dev/null
275 then
276 :
277 else
278 sshduid="-u $SSHDUID"
279 fi
Damien Millera8e06ce2003-11-21 23:48:55 +1100280 echo "Creating PrivSep user $SSH_PRIVSEP_USER."
Tim Ricef1a10012002-07-19 11:57:57 -0700281 \$chroot /usr/sbin/useradd -c 'SSHD PrivSep User' -s /bin/false -g $SSH_PRIVSEP_USER \$sshduid $SSH_PRIVSEP_USER
282 \$chroot /usr/bin/passwd -l $SSH_PRIVSEP_USER
Damien Millera8e06ce2003-11-21 23:48:55 +1100283 fi
Ben Lindstrom104c3fe2002-07-15 18:49:20 +0000284fi
285
Tim Rice29bdd2c2002-03-11 20:55:53 -0800286[ "\${POST_INS_START}" = "yes" ] && ${TEST_DIR}/etc/init.d/${SYSVINIT_NAME} start
287exit 0
288_EOF
289
290## Build preremove file
291echo "Building preremove file..."
292cat > preremove << _EOF
293#! /sbin/sh
294#
295${TEST_DIR}/etc/init.d/${SYSVINIT_NAME} stop
296exit 0
297_EOF
298
299## Build request file
300echo "Building request file..."
301cat > request << _EOF
302trap 'exit 3' 15
303USE_SYM_LINKS=no
304PRE_INS_STOP=no
305POST_INS_START=no
306# Use symbolic links?
307ans=\`ckyorn -d n \
308-p "Do you want symbolic links for the start/stop scripts? ${DEF_MSG}"\` || exit \$?
309case \$ans in
310 [y,Y]*) USE_SYM_LINKS=yes ;;
311esac
312
313# determine if should restart the daemon
314if [ -s ${piddir}/sshd.pid -a -f ${TEST_DIR}/etc/init.d/${SYSVINIT_NAME} ]
315then
316 ans=\`ckyorn -d n \
317-p "Should the running sshd daemon be restarted? ${DEF_MSG}"\` || exit \$?
318 case \$ans in
319 [y,Y]*) PRE_INS_STOP=yes
320 POST_INS_START=yes
321 ;;
322 esac
323
324else
325
326# determine if we should start sshd
327 ans=\`ckyorn -d n \
328-p "Start the sshd daemon after installing this package? ${DEF_MSG}"\` || exit \$?
329 case \$ans in
330 [y,Y]*) POST_INS_START=yes ;;
331 esac
332fi
333
334# make parameters available to installation service,
335# and so to any other packaging scripts
336cat >\$1 <<!
337USE_SYM_LINKS='\$USE_SYM_LINKS'
338PRE_INS_STOP='\$PRE_INS_STOP'
339POST_INS_START='\$POST_INS_START'
340!
341exit 0
342
343_EOF
344
345## Build space file
346echo "Building space file..."
347cat > space << _EOF
348# extra space required by start/stop links added by installf in postinstall
349$TEST_DIR/etc/rc0.d/K30${SYSVINIT_NAME} 0 1
350$TEST_DIR/etc/rc1.d/K30${SYSVINIT_NAME} 0 1
351$TEST_DIR/etc/rc2.d/S98${SYSVINIT_NAME} 0 1
352_EOF
353[ "$RCS_D" = yes ] && \
354echo "$TEST_DIR/etc/rcS.d/K30${SYSVINIT_NAME} 0 1" >> space
355
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000356## Next Build our prototype
357echo "Building prototype file..."
Tim Rice29bdd2c2002-03-11 20:55:53 -0800358cat >mk-proto.awk << _EOF
359 BEGIN { print "i pkginfo"; print "i preinstall"; \\
360 print "i postinstall"; print "i preremove"; \\
361 print "i request"; print "i space"; \\
Damien Millera8e06ce2003-11-21 23:48:55 +1100362 split("$SYSTEM_DIR",sys_files); }
Tim Rice29bdd2c2002-03-11 20:55:53 -0800363 {
364 for (dir in sys_files) { if ( \$3 != sys_files[dir] )
Damien Millera8e06ce2003-11-21 23:48:55 +1100365 { \$5="root"; \$6="sys"; }
366 else
367 { \$4="?"; \$5="?"; \$6="?"; break;}
Tim Rice29bdd2c2002-03-11 20:55:53 -0800368 } }
369 { print; }
370_EOF
371find . | egrep -v "prototype|pkginfo|mk-proto.awk" | sort | \
372 pkgproto $PROTO_ARGS | nawk -f mk-proto.awk > prototype
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000373
Tim Ricec9001282004-01-22 16:10:03 -0800374# /usr/local is a symlink on some systems
375[ "${USR_LOCAL_IS_SYMLINK}" = yes ] && {
376 grep -v "^d none /usr/local ? ? ?$" prototype > prototype.new
377 mv prototype.new prototype
378}
379
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000380## Step back a directory and now build the package.
381echo "Building package.."
382cd ..
Tim Rice29bdd2c2002-03-11 20:55:53 -0800383pkgmk -d ${FAKE_ROOT} -f $FAKE_ROOT/prototype -o
384echo | pkgtrans -os ${FAKE_ROOT} ${START}/$PKGNAME-$UNAME_S-$ARCH-$VERSION.pkg
Ben Lindstrom8b5ba1c2001-10-12 20:30:52 +0000385rm -rf $FAKE_ROOT
Tim Rice29bdd2c2002-03-11 20:55:53 -0800386