summaryrefslogtreecommitdiff
path: root/frontends/etc/rc.d
diff options
context:
space:
mode:
authorPaul Buetow <paul@buetow.org>2026-07-10 09:24:56 +0300
committerPaul Buetow <paul@buetow.org>2026-07-10 09:24:56 +0300
commit2f5b1fa3df0b49c5453aee19520e9a090794d044 (patch)
tree8c188e9bf1eaecb1c112a71bf4f4d9fb59776c0e /frontends/etc/rc.d
parent03779322f5d8f1130ec1352ee9f0d2de69881b3b (diff)
packages+frontends: dtail packaging follow-ups (vs0 review items)
- dtail-freebsd.json.tpl: move HostKeyFile from volatile /var/run/dserver/cache to persistent /var/db/dserver/ssh_host_key — FreeBSD's cleanvar purges /var/run at boot, so the host key was regenerated on every reboot (mirrors the NetBSD/OpenBSD templates) - dserver-freebsd.tpl rc.d: start_precmd now creates /var/db/dserver (0700, dserver-owned) and re-runs dserver-update-key-cache.sh on every start, so the volatile key cache repopulates right after a reboot or restart instead of waiting for the daily periodic job - packages/Makefile: .SHELLFLAGS gains -o pipefail — the "git archive | ssh ... tar" pipeline could mask a git archive failure as long as tar succeeded on the truncated stream (the only recipe-level pipeline; $(shell ...) calls are unaffected) - packages/Makefile: OS-suffixed /tmp staging names for the OpenBSD and NetBSD dtail tgz (dtail-openbsd-*/dtail-netbsd-*) — a dash-less version would have made both targets stage to the same /tmp/dtail-<version>.tgz locally and on f0; the final repo copy keeps the canonical dtail-<version>.tgz name - dserver-update-key-cache.sh.tpl (OpenBSD): port the NetBSD hardening — quote all variable expansions, derive the user via basename suffix stripping instead of cut -d. -f1 (dotted usernames broke), fix the obsolete-cachefile echo that used single quotes and never interpolated $cachefile, add a header comment documenting the rc_pre and /etc/daily.local call sites - dserver.tpl (OpenBSD rc.d): replace 'rc_cmd $1 &' with rc_bg=YES and a plain rc_cmd "$1" — the daemon needs backgrounding because it does not daemonize, but backgrounding the whole rc framework made rc_pre failures and the start result invisible to rcctl; rc_bg is rc.subr's supported way to background only the daemon - dserver-update-key-cache-freebsd.sh.tpl: header now documents the new rc.d start_precmd call site Deployed: FreeBSD pkg republished, f0/f1/f2 upgraded with host key migrated to /var/db/dserver first (sha256 verified identical); f3 unreachable, still on the old package. OpenBSD pkg republished, fishfinger reinstalled + restarted, host key unchanged, dcat verified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Diffstat (limited to 'frontends/etc/rc.d')
-rw-r--r--frontends/etc/rc.d/dserver-freebsd.tpl9
-rwxr-xr-xfrontends/etc/rc.d/dserver.tpl6
2 files changed, 14 insertions, 1 deletions
diff --git a/frontends/etc/rc.d/dserver-freebsd.tpl b/frontends/etc/rc.d/dserver-freebsd.tpl
index 6110c0c..04380cb 100644
--- a/frontends/etc/rc.d/dserver-freebsd.tpl
+++ b/frontends/etc/rc.d/dserver-freebsd.tpl
@@ -21,9 +21,18 @@ start_precmd="dserver_precmd"
dserver_precmd()
{
+ # /var/run is volatile on FreeBSD (cleanvar purges it at boot) — recreate
+ # the runtime dirs and repopulate the SSH key cache on every service
+ # start (a daily periodic job keeps it fresh afterwards). The SSH host
+ # key lives in persistent /var/db/dserver so it survives reboots (a
+ # regenerated host key would break clients' known_hosts).
install -d -o dserver -m 0755 /var/log/dserver
install -d -o dserver -m 0755 /var/run/dserver
install -d -o dserver -m 0755 /var/run/dserver/cache
+ install -d -o dserver -m 0700 /var/db/dserver
+ if [ -x /usr/local/bin/dserver-update-key-cache.sh ]; then
+ /usr/local/bin/dserver-update-key-cache.sh
+ fi
}
load_rc_config $name
diff --git a/frontends/etc/rc.d/dserver.tpl b/frontends/etc/rc.d/dserver.tpl
index 305b0ce..76e79a5 100755
--- a/frontends/etc/rc.d/dserver.tpl
+++ b/frontends/etc/rc.d/dserver.tpl
@@ -7,6 +7,10 @@ daemon_user="_dserver"
. /etc/rc.d/rc.subr
rc_reload=NO
+# dserver does not daemonize itself — let rc.subr start it in the background
+# (rc_bg) instead of backgrounding the whole rc_cmd invocation, which would
+# hide rc_pre failures and the start result from rcctl.
+rc_bg=YES
rc_pre() {
# /var/run is wiped by /etc/rc at boot — recreate the runtime dirs and
@@ -26,4 +30,4 @@ rc_pre() {
fi
}
-rc_cmd $1 &
+rc_cmd "$1"