agama/rust/install.sh
Ladislav Slezák 078af95a65
Optionally disable remote access (#3269)
## Problem

- https://jira.suse.com/browse/AGM-153
- For security reasons it should be possible to disable remote access to
the Agama web server. A server which is not reachable cannot be hacked.
😃

## Solution

- Add a new `inst.listen_on` boot option, the possible values:
- `inst.listen_on=all` - listen on all network interfaces (allow local
and remote access). This is the default behavior used even without the
`inst.listen_on` option, added just for completeness.
- `inst.listen_on=localhost` - listen only on loop back (localhost)
device. This disables remote access, Agama can be accessed only locally.
- `inst.listen_on=<ip>` - listen on the specified IP address. Both IPv4
and IPv6 addresses are supported. It is possible to use multiple IP
addresses separated by comma. Addresses not found in the system are
ignored.
- `inst.listen_on=<interface>` - listen on the specified network
interface. Multiple interfaces can be separated by comma. Not found
interfaces are ignored.

Agama always listens on the local loop back interface even when
specifying a specific network interface or IP address for listening. The
reason is to avoid reporting connection errors by the Firefox started in
the Live ISO.

## Details

- The `--address2` CLI option has been removed, instead it is possible
to specify `--address` option multiple times.
- The PR includes the @mvidner's patch
https://github.com/agama-project/agama/pull/3111 - fallback to an IPv4
address when listening to IPv6 address fails (when IPv6 is disabled with
the `ipv6.disable=1` boot option)
- Added the `agama-web-server.sh` wrapper script started from the
systemd service. It evaluates the boot parameters and builds the address
parameters for the Agama server.

## Notes

- The other network services like SSH can be disabled using the standard
`systemd.mask` boot option. For example to disable the SSH service use
this boot option: `systemd.mask=sshd.service`. (I'll document this as
well...)

## Testing

- Tested manually in all scenarios: with disabled remote access,
listening on the specified IPv6 (including link local address) or IPv4
address, listening on specified interface, listening on multiple
interfaces
- Tested Martin's patch with the `ipv6.disable=1` boot option, Agama
properly listens on the IPv4 addresses in that case.

---------

Co-authored-by: Martin Vidner <mvidner@suse.com>
2026-03-12 14:12:15 +01:00

76 lines
3.1 KiB
Bash
Executable file

#!/bin/bash
set -eu
# After building this part of Agama, install it so that it is ready for run time
# This is used by agama.spec and testing-in-container.sh
# The caller (RPM .spec) is expected to set these environment variables:
# NAME=%{name}
# SRCDIR=.
# DESTDIR=%{buildroot}
# bindir=%{_bindir}
# datadir=%{_datadir}
# pamvendordir=%{_pam_vendordir}
# unitdir=%{_unitdir}
# libexecdir=%{_libexecdir}
# mandir=%{_mandir}
# pamvendordir=%{_pam_vendordir}
: ${RUST_TARGET:=release}
if [ "${1-}" = --system ]; then
SRCDIR=.
DESTDIR=""
NAME=agama
RUST_TARGET=debug
bindir=/usr/bin
datadir=/usr/share
mandir=/usr/share/man
libexecdir=/usr/lib
unitdir=/usr/lib/systemd/system
pamvendordir=/etc/pam.d
fi
# install regular file, with mode 644 (not an executable with mode 755)
install6() {
install -m 0644 "$@"
}
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-autoinstall"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-proxy-setup"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-web-server"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-web-server.sh"
install6 -D -p "${SRCDIR}"/share/agama.pam "${DESTDIR}${pamvendordir}"/agama
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/dasd.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/iscsi.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/profile.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/software.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/zfcp.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.model.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/jsonnet "${SRCDIR}"/share/agama.libsonnet
install -D -t "${DESTDIR}${libexecdir}" "${SRCDIR}"/share/agama-scripts.sh
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-autoinstall.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-proxy-setup.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-scripts.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-web-server.service
# create the licenses directory
install -d -m 0755 "${DESTDIR}${datadir}"/agama/eula
# install manpages
install6 -D -t "${DESTDIR}${mandir}"/man1 "${SRCDIR}"/out/man/*
# install shell completion scripts
install6 -D "${SRCDIR}"/out/shell/"${NAME}".bash "${DESTDIR}${datadir}/bash-completion/completions/${NAME}"
install6 -D -t "${DESTDIR}${datadir}"/zsh/site-functions "${SRCDIR}"/out/shell/_"${NAME}"
install6 -D -t "${DESTDIR}${datadir}"/fish/vendor_completions.d "${SRCDIR}"/out/shell/"${NAME}".fish
# install OpenAPI specification
install6 -D -t "${DESTDIR}${datadir}"/agama/openapi "${SRCDIR}"/out/openapi/*
# install translations
make -C "${SRCDIR}/po" install DESTDIR="${DESTDIR}" datadir="${datadir}"