mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
commissioning: the layer, the acceptance tests, the harness rule, the docs, and the bench drills
meta-forgefirm: the forgefirm-users init replays the account at boot; sshd refuses root and empty passwords and runs only while the panel turns it on; the release image keeps an empty root password for the console; the console banner; avahi announces forgefirm.local; https in libmicrohttpd and ulfius; the panel on 80 and 443; the license bundle on the rootfs; release.sh checks the root policy on the built rootfs. forgetest: the commission suites (commission, commission_dark, commission_sheet: 23 cases); the runner turns cloud mode on with the typed phrase for a test that declares it; the baseline's motor_lock is 0; the log-export test checks the bundle for the camera key; the record helpers write bytes as given and join the daemon's paths as POSIX. The stream harness gains rule 24: a hold verdict is held again after a resume. Bench drills: lens_travel.py and lens_stop_accel.py. Docs: BRINGUP carries the present state; CAMPAIGN-LOG carries the dated record.
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
# ForgeFIRM avahi-daemon configuration (avahi-daemon.conf(5)).
|
||||
# The machine answers forgefirm.local on the WiFi link (and on eth0 when
|
||||
# the machine has one), over IPv4 and IPv6. It publishes its addresses
|
||||
# and the services in /etc/avahi/services, nothing else: no workstation
|
||||
# record, no host information, no wide-area lookups, no reflector.
|
||||
|
||||
[server]
|
||||
host-name=forgefirm
|
||||
use-ipv4=yes
|
||||
use-ipv6=yes
|
||||
allow-interfaces=wlan0,eth0
|
||||
ratelimit-interval-usec=1000000
|
||||
ratelimit-burst=1000
|
||||
|
||||
[wide-area]
|
||||
enable-wide-area=no
|
||||
|
||||
[publish]
|
||||
publish-hinfo=no
|
||||
publish-workstation=no
|
||||
publish-addresses=yes
|
||||
publish-domain=yes
|
||||
|
||||
[reflector]
|
||||
enable-reflector=no
|
||||
|
||||
[rlimits]
|
||||
rlimit-core=0
|
||||
rlimit-data=8388608
|
||||
rlimit-fsize=0
|
||||
rlimit-nofile=768
|
||||
rlimit-stack=8388608
|
||||
rlimit-nproc=3
|
||||
@@ -0,0 +1,21 @@
|
||||
<?xml version="1.0" standalone='no'?>
|
||||
<!DOCTYPE service-group SYSTEM "avahi-service.dtd">
|
||||
|
||||
<!-- ForgeFIRM control panel: HTTPS on 443 and HTTP on 80, served by
|
||||
forgectrl. %h is the host name (avahi.service(5)). -->
|
||||
|
||||
<service-group>
|
||||
|
||||
<name replace-wildcards="yes">ForgeFIRM on %h</name>
|
||||
|
||||
<service>
|
||||
<type>_https._tcp</type>
|
||||
<port>443</port>
|
||||
</service>
|
||||
|
||||
<service>
|
||||
<type>_http._tcp</type>
|
||||
<port>80</port>
|
||||
</service>
|
||||
|
||||
</service-group>
|
||||
@@ -0,0 +1,17 @@
|
||||
FILESEXTRAPATHS:prepend := "${THISDIR}/${BPN}:"
|
||||
|
||||
# mDNS for the control panel: the machine answers forgefirm.local and
|
||||
# advertises the panel on HTTPS 443 and HTTP 80. Only avahi-daemon is
|
||||
# installed (forgefirm-image.bb); the build options that keep it to the
|
||||
# daemon are in conf/distro/forgefirm.conf. The daemon reads the service
|
||||
# file itself: no D-Bus is involved.
|
||||
SRC_URI += " \
|
||||
file://avahi-daemon.conf \
|
||||
file://forgefirm.service \
|
||||
"
|
||||
|
||||
do_install:append() {
|
||||
install -m 0644 ${WORKDIR}/avahi-daemon.conf ${D}${sysconfdir}/avahi/avahi-daemon.conf
|
||||
install -d ${D}${sysconfdir}/avahi/services
|
||||
install -m 0644 ${WORKDIR}/forgefirm.service ${D}${sysconfdir}/avahi/services/forgefirm.service
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
# ForgeFIRM SSH policy, set in the installed files so the release image
|
||||
# carries it as built:
|
||||
# PermitRootLogin no root logs in at the serial console only
|
||||
# PermitEmptyPasswords no an account without a password cannot log in
|
||||
# PasswordAuthentication yes operator accounts log in with a password
|
||||
# The dev image's debug-tweaks turns PermitRootLogin and
|
||||
# PermitEmptyPasswords back to yes at rootfs time (ssh_allow_root_login
|
||||
# and ssh_allow_empty_password in rootfs-postcommands.bbclass match the
|
||||
# active lines too), so the bench keeps root over SSH.
|
||||
#
|
||||
# The init script starts sshd only when the control panel has turned it
|
||||
# on (/run/forgefirm/ssh-enabled, tmpfs, gone at reboot) or on the dev
|
||||
# image (/etc/forgefirm-dev). The guard sits in check_for_no_start, which
|
||||
# start, reload and restart call; stop is never gated.
|
||||
|
||||
do_install:append() {
|
||||
for config in sshd_config sshd_config_readonly; do
|
||||
f=${D}${sysconfdir}/ssh/$config
|
||||
[ -e "$f" ] || continue
|
||||
sed -i \
|
||||
-e 's/^[#[:space:]]*PermitRootLogin .*/PermitRootLogin no/' \
|
||||
-e 's/^[#[:space:]]*PermitEmptyPasswords .*/PermitEmptyPasswords no/' \
|
||||
-e 's/^[#[:space:]]*PasswordAuthentication .*/PasswordAuthentication yes/' \
|
||||
"$f"
|
||||
grep -q '^PermitRootLogin no$' "$f" \
|
||||
&& grep -q '^PermitEmptyPasswords no$' "$f" \
|
||||
&& grep -q '^PasswordAuthentication yes$' "$f" \
|
||||
|| bbfatal "$config: the ForgeFIRM policy lines did not land"
|
||||
done
|
||||
|
||||
init=${D}${sysconfdir}/init.d/sshd
|
||||
sed -i '/^check_for_no_start() {$/a\
|
||||
[ -e /run/forgefirm/ssh-enabled ] || [ -e /etc/forgefirm-dev ] || {\
|
||||
echo "sshd: not enabled (turn it on from the ForgeFIRM control panel)"\
|
||||
exit 0\
|
||||
}' "$init"
|
||||
grep -q 'forgefirm/ssh-enabled' "$init" \
|
||||
|| bbfatal "init.d/sshd: the check_for_no_start anchor was not found"
|
||||
}
|
||||
Reference in New Issue
Block a user