agama/rust/install.sh
Ladislav Slezák 8ff52c8717
Use inst.remote=0 for disabling the remote access to Agama (#3336)
## Problem

- Using the new `inst.listen_on` boot option to disable remote access to
the server looks inconsistent (for disabling the SSH access you can use
the `systemd.mask=sshd.service` boot option)
- Simplify the implementation, limiting access to some interface or IP
address was not requested
- Related to https://github.com/agama-project/agama/pull/3269

## Solution

- Use systemd services to implement disabling the remote access
- ~~Implement new `agama-web-server-local` and `agama-web-server-remote`
services~~
- ~~By default the remote service is enabled, but the user can disable
it and enable the local service instead using the
`systemd.mask=agama-web-server-remote.service
systemd.wants=agama-web-server-local.service` boot parameters.~~
- Support new `inst.remote=0` boot option

## Testing

- Tested manually

## Notes

I tried several approaches but either they did not work or were a bit
hacky:

1. First a wanted to be the both local and remote services enabled by
default. Because of conflicts only one of them should be running at a
time. I used `Before` and `After` so the remote service starts first and
the conflict should block the local service from running. Disabling the
remote service allows running the local service automatically.
The problem was that there is probably some race condition and sometimes
the local service was actually running instead of the remote by default.
I tried several changes but nothing helped.
2. Then I added code to the local service to explicitly check whether
the remote service is disabled or not (using `ExecCondition` attribute).
But that feels a bit hacky and it is a hidden magic.
3. Then I realized that the same way how you can disable a service at
boot using `systemd.mask` option you can also enable a disabled service
using the `systemd.wants` parameter. So instead of enabling both
services enable only the default remote one. The users then can
explicitly disable the remote service and enable the local one using the
`systemd.mask=agama-web-server-remote.service
systemd.wants=agama-web-server-local.service` boot options. But that
turned out to be quite complicated.
4. So let's implement simple `inst.remote=0` boot option which disables
the remotes access to the Agama installer. The SSH service can be
disabled using the standard `systemd.mask=sshd.service` option.
2026-04-13 17:10:54 +02:00

77 lines
3.2 KiB
Bash
Executable file

#!/bin/bash
set -eu
# After building this part of Agama, install it so that it is ready for run time
# This is used by agama.spec and testing-in-container.sh
# The caller (RPM .spec) is expected to set these environment variables:
# NAME=%{name}
# SRCDIR=.
# DESTDIR=%{buildroot}
# bindir=%{_bindir}
# datadir=%{_datadir}
# pamvendordir=%{_pam_vendordir}
# unitdir=%{_unitdir}
# libexecdir=%{_libexecdir}
# mandir=%{_mandir}
# pamvendordir=%{_pam_vendordir}
: ${RUST_TARGET:=release}
if [ "${1-}" = --system ]; then
SRCDIR=.
DESTDIR=""
NAME=agama
RUST_TARGET=debug
bindir=/usr/bin
datadir=/usr/share
mandir=/usr/share/man
libexecdir=/usr/lib
unitdir=/usr/lib/systemd/system
pamvendordir=/etc/pam.d
fi
# install regular file, with mode 644 (not an executable with mode 755)
install6() {
install -m 0644 "$@"
}
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-autoinstall"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-proxy-setup"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-web-server"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-journal"
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-zypp-journal"
install6 -D -p "${SRCDIR}"/share/agama.pam "${DESTDIR}${pamvendordir}"/agama
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/dasd.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/iscsi.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/profile.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/software.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/zfcp.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.model.schema.json
install6 -D -t "${DESTDIR}${datadir}"/agama/jsonnet "${SRCDIR}"/share/agama.libsonnet
install -D -t "${DESTDIR}${libexecdir}" "${SRCDIR}"/share/agama-scripts.sh
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-autoinstall.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-proxy-setup.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-scripts.service
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-web-server.service
# create the licenses directory
install -d -m 0755 "${DESTDIR}${datadir}"/agama/eula
# install manpages
install6 -D -t "${DESTDIR}${mandir}"/man1 "${SRCDIR}"/out/man/*
# install shell completion scripts
install6 -D "${SRCDIR}"/out/shell/"${NAME}".bash "${DESTDIR}${datadir}/bash-completion/completions/${NAME}"
install6 -D -t "${DESTDIR}${datadir}"/zsh/site-functions "${SRCDIR}"/out/shell/_"${NAME}"
install6 -D -t "${DESTDIR}${datadir}"/fish/vendor_completions.d "${SRCDIR}"/out/shell/"${NAME}".fish
# install OpenAPI specification
install6 -D -t "${DESTDIR}${datadir}"/agama/openapi "${SRCDIR}"/out/openapi/*
# install translations
make -C "${SRCDIR}/po" install DESTDIR="${DESTDIR}" datadir="${datadir}"