galeb

Једноставна статичка дистрибуција заснована на musl-у
Дневник | Датотеке | Референце | ПРОЧИТАЈМЕ | ЛИЦЕНЦА

чување 381767be2a9c2bf308ed80a5b45c4aeb31bf4fd3
родитељ 3359a3f4b2bdaadce336e8024e3e019b66d40ab8
Аутор: Страхиња Радић <contact@strahinja.org>
Датум:   Mon, 18 Jul 2022 21:57:56 +0200

Add curl, metalog; improve svc scripts

Signed-off-by: Страхиња Радић <contact@strahinja.org>

Diffstat:
M02-chroot.sh | 3++-
M03-packages.sh | 366++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----
M04-finale.sh | 5+++++
MBUGS | 3++-
MFAQ | 9+++++----
MTODO | 5+++--
Afil/ca-certificates-bmlfs/certdata2pem.c | 143+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Afil/ca-certificates-bmlfs/remove-expired-certs.sh | 51+++++++++++++++++++++++++++++++++++++++++++++++++++
Mfil/rc.d/rc.conf | 5+++--
Mfil/rc.d/rc.init | 23+++++++++++++++++++----
Mfil/rc.d/rc.shutdown | 10+++++-----
Mfil/rc.d/rc.svc | 2+-
Mfil/svc.d/avail/crond | 21---------------------
Mfil/svc.d/avail/hwclock | 13+++++++------
Mlib/perms.tsv | 8++++++--
Mlib/pkgs.tsv | 10+++++++++-
Msrc/umountall.c | 12+++++++++---
измењених датотека: 17, додавања: 615(+), брисања: 74(-)

diff --git a/02-chroot.sh b/02-chroot.sh @@ -128,7 +128,8 @@ cp_or_fail ${WD}/${FLD}/rc.d/rc.init ${GR}/bin/rc.init cp_or_fail ${WD}/${FLD}/rc.d/rc.shutdown ${GR}/bin/rc.shutdown cp_or_fail ${WD}/${FLD}/rc.d/rc.svc ${GR}/bin/rc.svc cp_or_fail ${WD}/${FLD}/rc.d/rc.local ${GR}/etc/rc.local -cp_or_fail -r ${WD}/${FLD}/svc.d/* ${GR}/bin/svc.d/ +check_dir ${GR}/src/svc.d +cp_or_fail -r ${WD}/${FLD}/svc.d/* ${GR}/src/svc.d/ msg warn "Next run 03-packages.sh" diff --git a/03-packages.sh b/03-packages.sh @@ -79,6 +79,7 @@ input:x:24: cron:x:33: mail:x:34: nogroup:x:99: +metalog:x:983: wheel:x:998: users:x:999: ! @@ -87,9 +88,6 @@ for log in btmp lastlog faillog wtmp do :>/var/log/${log} done -chgrp utmp /var/log/lastlog -chgrp 664 /var/log/lastlog -chgrp 600 /var/log/btmp begin_substep linux-5.17.13 "Linux headers" if [ -e /include/linux/stddef.h ]; then @@ -1897,6 +1895,41 @@ mkpk_install() fi end_substep +begin_substep autoconf-archive-2022.02.11 +if [ -x /share/aclocal/ax_zoneinfo.m4 ]; then + msg info "%s exists, skipping %s" /share/aclocal/ax_zoneinfo.m4 ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + extract_pkg ${G_SRC} ${pkg} ${pkg}.tar.xz + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -pipe' + LDFLAGS= + DESTDIR=/build + export CFLAGS LDFLAGS DESTDIR + + ./configure --prefix=/sucks + + make install +} +! + mkpk ${pkg} + remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + begin_substep musl-fts-1.2.7 if [ -x /lib/libfts.so.0.0.0 ]; then msg info "%s exists, skipping %s" /lib/libfts.so.0.0.0 ${pkg} @@ -2302,9 +2335,9 @@ mkpk_install() autoreconf -vif - ./configure --prefix=/ \ - --sysconfdir=/etc \ - --mandir=/share/man \ + ./configure --prefix=/ \\ + --sysconfdir=/etc \\ + --mandir=/share/man \\ --localstatedir=/var make ${JN} || exit 1 @@ -2318,6 +2351,126 @@ mkpk_install() fi end_substep +begin_substep ca-certificates-20211016 +if [ -e /bin/ca-certificates ]; then + msg info "%s exists, skipping %s" /bin/ca-certificates ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / + mkdir -p /etc/ssl/certs + update-ca-certificates +else + extract_pkg ${G_SRC} work ${pkg}.tar.xz ${pkg} + ( + cd_or_fail ${G_SRC}/${pkg} + + cp_or_fail ${G_FIL}/ca-certificates-bmlfs/certdata2pem.c \ + ${G_SRC}/${pkg} + cp_or_fail ${G_FIL}/ca-certificates-bmlfs/\ +remove-expired-certs.sh ${G_SRC}/${pkg}/mozilla/ + chmod +x ${G_SRC}/${pkg}/mozilla/remove-expired-certs.sh + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + DESTDIR=/build + export DESTDIR + + cc \${CFLAGS} -o mozilla/certdata2pem certdata2pem.c + + /${TLD}/bin/sed -i -e 's,python3 certdata2pem.py,./certdata2pem,g' \\ + mozilla/Makefile + /${TLD}/bin/sed -i -e 's,\(.*\)\(certdata2pem.*\),\1\2\n\1./'\ +'remove-expired-certs.sh,' mozilla/Makefile + + mkdir -p ../build + ln -sf . ../build/usr + mkdir -p ../build/bin + ln -sf bin ../build/usr/sbin + mkdir -p ../build/usr/share/ca-certificates/mozilla + mkdir -p ../build/etc/ssl/certs + mkdir -p ../build/share/man/man8 + + make ${JN} || exit 1 + make install + + /${TLD}/bin/install -Dm644 -v sbin/update-ca-certificates.8 \\ + ../build/share/man/man8/update-ca-certificates.8 + /${TLD}/bin/mv -v ../build/share/ca-certificates/mozilla/* \\ + ../build/share/ca-certificates/ + cd /build/share/ca-certificates + /${TLD}/bin/find . -name '*.crt' | sort | cut -b3- > \\ + /build/etc/ca-certificates.conf + /${TLD}/bin/sed -i -e 's,openssl rehash,openssl certhash,g' \\ + /build/bin/update-ca-certificates + + /${TLD}/bin/ln -sv /etc/ssl/certs/ca-certificates.crt \\ + /build/etc/ssl/certs.pem +} +! + mkpk ${pkg} + remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + mkdir -p /etc/ssl/certs + update-ca-certificates + ) || exit 1 +fi +end_substep + +begin_substep curl-7.84.0 +if [ -e /bin/curl ]; then + msg info "%s exists, skipping %s" /bin/curl ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + extract_pkg ${G_SRC} ${pkg} ${pkg}.tar.xz + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -pipe' + CFLAGS+=' -D_FORTIFY_SOURCE=2 -I/include' + CPPFLAGS='-D_FORTIFY_SOURCE=2' + LDFLAGS='' + DESTDIR=/build + export CFLAGS LDFLAGS DESTDIR + + + autoreconf -vif || exit 1 + + ac_cv_sizeof_off_t=8 \\ + ./configure --prefix=/sucks \\ + --enable-threaded-resolver \\ + --with-ca-path=/etc/ssl/certs \\ + --enable-ipv6 \\ + --enable-unix-sockets \\ + --with-pic \\ + --with-openssl \\ + --disable-static \\ + --without-libssh2 || exit 1 + + make ${JN} || exit 1 + make install-strip +} +! + mkpk ${pkg} + #remove_dir ${G_SRC}/${pkg} + #unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + begin_substep Python-3.9.9 if [ -x /sucks/bin/python3 ]; then msg info "%s exists, skipping %s" /sucks/bin/python3 ${pkg} @@ -2484,7 +2637,7 @@ mkpk_install() autoreconf -vif || exit 1 - sed -i '1i#include <langinfo.h>' proc/escape.c + /${TLD}/bin/sed -i '1i#include <langinfo.h>' proc/escape.c ac_cv_func_malloc_0_nonnull=yes \ ac_cv_func_realloc_0_nonnull=yes \ @@ -2499,18 +2652,23 @@ mkpk_install() make ${JN} || exit 1 make DESTDIR=\${DESTDIR} install - mkdir -pv /build/sucks/bin - ln -sv bin /build/sucks/sbin - find /build/bin -type f -cnewer /timestamp | \\ - xargs -I{} mv -v {} /build/sucks/bin/ - find /build/sbin -type f -cnewer /timestamp | \\ - xargs -I{} mv -v {} /build/sucks/sbin/ + mkdir -p /build/sucks/bin + ln -s bin /build/sucks/sbin + /${TLD}/bin/find /build/bin -type f -cnewer /timestamp | \\ + xargs -I{} mv {} /build/sucks/bin/ + /${TLD}/bin/find /build/sbin -type f -cnewer /timestamp | \\ + xargs -I{} mv {} /build/sucks/sbin/ + + # Fix sucky install scripts + mv /build/bin/* /build/sucks/bin/ + mv /build/sbin/* /build/sucks/sbin/ + rm -fr /build/bin /build/sbin # Overlap with ubase for duplicate in free pidof ps pwdx sysctl uptime watch do - rm -fv /build/sucks/bin/\${duplicate} - rm -fv /build/sucks/share/man/man1/\${duplicate}.1 + rm -f /build/sucks/bin/\${duplicate} + rm -f /build/sucks/share/man/man1/\${duplicate}.1 done } ! @@ -2544,13 +2702,14 @@ mkpk_install() export CFLAGS LDFLAGS DESTDIR - sed -i -e 's/^HOSTCC =.*/HOSTCC = gcc -Wall/' \\ + /${TLD}/bin/sed -i -e 's/^HOSTCC =.*/HOSTCC = gcc -Wall/' \\ -e 's/^CFLAGS =/#&/' \\ -e "s/^#CFLAGS =\\$/CFLAGS = \${CFLAGS}&/" \\ -e 's/^#\( YACC = yacc.*\)/\1/' \\ -e 's/^\(YACC = bison.*\)/# \1/' \\ makefile + make clean make ${JN} || exit 1 install -dm 755 /build/bin @@ -3095,22 +3254,26 @@ mkpk_name() mkpk_install() { - CFLAGS='-Os -pipe -static --static -fcommon' - LDFLAGS='-static --static -fcommon -s' + CFLAGS='-Os -pipe' + LDFLAGS='-s' DESTDIR=/build TAR=/tools/bin/tar export CFLAGS LDFLAGS DESTDIR TAR - ./configure --prefix=/ \\ + ./configure --prefix=/sucks \\ + --with-curl \\ + --with-openssl \\ + --with-libpcre2 \\ --with-gitconfig=/etc/gitconfig || exit 1 + make ${JN} || exit 1 make DESTDIR=\${DESTDIR} perllibdir=/lib/perl5/5.32/site_perl \\ TAR=\${TAR} install } ! mkpk ${pkg} - remove_dir ${G_SRC}/${pkg} - unpack_pkg ${pkg} / + #remove_dir ${G_SRC}/${pkg} + #unpack_pkg ${pkg} / ) || exit 1 fi end_substep @@ -3305,6 +3468,134 @@ mkpk_install() fi end_substep +begin_substep pcre-8.45 +if [ -x /sucks/lib/libpcre.so ]; then + msg info "%s exists, skipping %s" /sucks/lib/libpcre.so ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + extract_pkg ${G_SRC} ${pkg} ${pkg}.tar.bz2 + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -pipe' + LDFLAGS='' + DESTDIR=/build + export CFLAGS LDFLAGS DESTDIR + + ./configure --prefix=/sucks \\ + --docdir=/sucks/share/doc/${pkg} \\ + --enable-unicode-properties \\ + --enable-pcre16 \\ + --enable-pcre32 \\ + --enable-pcregrep-libz \\ + --enable-pcregrep-libbz2 \\ + --enable-pcretest-libreadline \\ + --disable-static \\ + --enable-jit + + make ${JN} || exit 1 + make install +} +! + mkpk ${pkg} + remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + +begin_substep pcre2-10.39 +if [ -x /sucks/lib/libpcre2.so ]; then + msg info "%s exists, skipping %s" /sucks/lib/libpcre2.so ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + extract_pkg ${G_SRC} ${pkg} ${pkg}.tar.bz2 + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -pipe' + LDFLAGS='' + DESTDIR=/build + export CFLAGS LDFLAGS DESTDIR + + ./configure --prefix=/sucks \\ + --docdir=/sucks/share/doc/${pkg} \\ + --enable-unicode \\ + --enable-pcre2-16 \\ + --enable-pcre2-32 \\ + --enable-pcre2grep-libz \\ + --enable-pcre2grep-libbz2 \\ + --enable-pcre2test-libreadline \\ + --disable-static \\ + --enable-jit + + make ${JN} || exit 1 + make install +} +! + mkpk ${pkg} + remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + +begin_substep metalog-20220214 +if [ -x /bin/metalog ]; then + msg info "%s exists, skipping %s" /bin/metalog ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + extract_pkg ${G_SRC} metalog-${pkg} ${pkg}.tar.gz ${pkg} + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -pipe' + LDFLAGS='' + DESTDIR=/build + export CFLAGS LDFLAGS DESTDIR + + ./autogen.sh + + ./configure --prefix=/sucks || exit 1 + + make ${JN} || exit 1 + make install-strip +} +! + mkpk ${pkg} + remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + begin_substep reflex-20210808 if [ -x /bin/reflex ]; then msg info "%s exists, skipping %s" /bin/reflex ${pkg} @@ -3413,6 +3704,39 @@ mkpk_install() fi end_substep +begin_substep usleep-20220718 +if [ -x /bin/usleep ]; then + msg info "%s exists, skipping %s" /bin/usleep ${pkg} +elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then + unpack_pkg ${pkg} / +else + ( + cd_or_fail ${G_SRC}/${pkg} + + cat <<! >MKPK +mkpk_name() +{ + printf "%s" "${pkg}" +} + +mkpk_install() +{ + CFLAGS='-Os -static --static -fcommon' + LDFLAGS='-static --static -fcommon' + PREFIX=/build/bin + export CFLAGS LDFLAGS DESTDIR + + make ${JN} || exit 1 + make install +} +! + mkpk ${pkg} + #remove_dir ${G_SRC}/${pkg} + unpack_pkg ${pkg} / + ) || exit 1 +fi +end_substep + # Unfortunately, gives "Out of memory - too many lines in file" # https://github.com/n-t-roff/heirloom-ex-vi/issues/3 # begin_substep vi-050325 diff --git a/04-finale.sh b/04-finale.sh @@ -232,6 +232,7 @@ elif [ -e ${G_SPKG}/${pkg}.tar.xz ]; then else ( cd_or_fail ${G_SRC}/${pkg} + cp_or_fail -r ${GR}/src/svc.d/* ${GR}/bin/svc.d/ cat <<! >MKPK mkpk_name() @@ -245,6 +246,10 @@ mkpk_install() cp -r svc.d ../build/bin/ mkdir -p ../build/share/doc/${pkg} cp README.md ../build/share/doc/${pkg}/ + mkdir -p ../build/bin/svc.d/avail + cp -r /svc.d/avail/* ../build/bin/svc.d/avail/ + mkdir -p ../build/bin/svc.d/default + cp -r /svc.d/default/* ../build/bin/svc.d/default/ } ! mkpk ${pkg} diff --git a/BUGS b/BUGS @@ -1,7 +1,8 @@ Known bugs/Errata ================= -* Packages having dynamic binaries in /bin (only until a workaround): +* Packages having dynamic binaries in /bin instead of having them in /sucks/bin + only until a fix): - LibreSSL - mandoc See lib/impostors for a current report when building (needs table(1)). diff --git a/FAQ b/FAQ @@ -9,10 +9,11 @@ A: [gɑ:leb]. Q: Is this Linux? GNU/Linux? Something else? A: Kernel = Linux. libc = musl-libc. coreutils = suckless core. Init system - = suckless init. The rest are GNU or other utilities which weren't covered - by the above. Thus, "suckless/musl/Linux", or "musl/Linux". It is not wrong - to throw GNU in the name as well, but this system is definitely different - than something like Debian, Fedora or Ubuntu. + = suckless init. Process supervisor = suckless svc, with modifications by + me.The rest are GNU or other utilities which weren't covered by the above. + Thus, "suckless/musl/Linux", or "musl/Linux". It is not wrong to throw GNU in + the name as well, but this system is definitely different than something like + Debian, Fedora or Ubuntu. Q: How do I install this thing? A: By reading files in this repository and typing commands. diff --git a/TODO b/TODO @@ -12,7 +12,7 @@ TODO [x] shutdown as regular user (remount / ro) [~] Add packages - [ ] Add curl (needed for git?) - needed + [x] Add curl (needed for git?) - needed [ ] git://git.suckless.org/utmp [ ] git://r-36.net/nldev [ ] git://r-36.net/nlmon @@ -20,7 +20,8 @@ TODO [ ] fsck.vfat [ ] Add ssh(d) [ ] Add sup - [~] Add git + [x] Add ~syslog-ng~ metalog + [x] Add git [~] Add table, text-utils [x] Add sdhcp [x] Test sdhcp diff --git a/fil/ca-certificates-bmlfs/certdata2pem.c b/fil/ca-certificates-bmlfs/certdata2pem.c @@ -0,0 +1,142 @@ +/* Copyright (C) 2013, Felix Janda <felix.janda@posteo.de> + +Permission to use, copy, modify, and/or distribute this software for +any purpose with or without fee is hereby granted, provided that the +above copyright notice and this permission notice appear in all copies. + +SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR +ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN +ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF +OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +*/ + +#include <stdio.h> +#include <stdlib.h> +#include <string.h> +#include <err.h> + +void xwrite(FILE *f, void *p, size_t size) +{ + if (fwrite(p, 1, size, f) != size) err(1, 0); +} + +int main(void) +{ + FILE *f; + char cert[4096], ecert[4096*4/3 + 100]; + char *line = 0, *tmp, *filename, *label, *pcert = 0; + ssize_t len; + size_t size, certsize; + int trust; + char **blacklist = 0, **node; + + filename = "./blacklist.txt"; + if (!(f = fopen(filename, "r"))) err(1, "%s", filename); + while ((len = getline(&line, &size, f)) != -1) { + if ((line[0] != '#') && (len > 1)) { + if (!(node = malloc(sizeof(void*) + len))) err(1, 0); + *node = (char*)blacklist; + memcpy(node + 1, line, len); + blacklist = node; + } + } + fclose(f); + + filename = "./certdata.txt"; + if (!(f = fopen(filename, "r"))) err(1, "%s", filename); + while ((len = getline(&line, &size, f)) != -1) { + tmp = line; + if (line[0] == '#') continue; + if (pcert) { + if (!strcmp(line, "END\n")) { + char *base64 = "ABCDEFGHIJKLMNOPQRSTUVWXYZ" + "abcdefghijklmnopqrstuvwxyz0123456789+/"; + size_t i, j, k, val; + + for (i = 0, val = 0, tmp = ecert; i < (size_t)(pcert - cert); i++) { + val = (val << 8) + (unsigned char)cert[i]; + if (i % 3 == 2) { + for (j = 0; j < 4; j++, val >>= 6) tmp[3 - j] = base64[val & 0x3f]; + tmp += 4; + } + if (i && !(i % 48)) { + *tmp = '\n'; + tmp++; + } + } + if (k = i % 3) { + tmp[2] = '='; + tmp[3] = '='; + val <<= 6 - 2*k; + for (j = 0; j < k + 1; j++, val >>= 6) tmp[k - j] = base64[val & 0x3f]; + tmp += 4; + } + certsize = tmp - ecert; + pcert = 0; + } else while (sscanf(tmp, "\\%hho", pcert) == 1) pcert++, tmp += 4; + } else if (!memcmp(line, "CKA_LABEL UTF8 ", 15)) { + + char *p2, *tmp2; + len -= 15; + if (!(label = malloc(len))) err(1, 0); + memcpy(label, line + 15, len); + trust = 0; + for (node = blacklist; node; node = (char**)*node) + if (!strcmp(label, (char*)(node + 1))) trust = 4; + if (!(p2 = malloc(len + 2))) err(1, 0); + for (tmp = label + 1, tmp2 = p2; *tmp != '"'; tmp++, tmp2++) { + switch (*tmp) { + case '\\': + if (sscanf(tmp, "\\x%hhx", tmp2)!=1) errx(1, "Bad triple: %s\n", tmp); + tmp += 3; + break; + case '/': + case ' ': + *tmp2 = '_'; + break; + case '(': + case ')': + *tmp2 = '='; + break; + default: + *tmp2 = *tmp; + } + } + strcpy(tmp2, ".crt"); + free(label); + label = p2; + } else if (!strcmp(line, "CKA_VALUE MULTILINE_OCTAL\n")) pcert = cert; + else if (!memcmp(line, "CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_", 39)) { + tmp += 39; + if (!strcmp(tmp, "TRUSTED_DELEGATOR\n")) trust |= 1; + else if (!strcmp(tmp, "NOT_TRUSTED\n")) trust |= 2; + } else if (!memcmp(line, + "CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_", 44)) { + tmp += 44; + if (!strcmp(tmp, "TRUSTED_DELEGATOR\n")) trust |= 1; + else if (!strcmp(tmp, "NOT_TRUSTED\n")) trust |= 2; + if (!trust) printf("Ignoring %s\n", label); + if (trust == 1) { + FILE *out; + if (!(out = fopen(label, "w"))) err(1, "%s", label); + xwrite(out, "-----BEGIN CERTIFICATE-----\n", 28); + xwrite(out, ecert, certsize); + xwrite(out, "\n-----END CERTIFICATE-----\n", 27); + fclose(out); + } + } + } + fclose(f); + + while (blacklist) { + node = (char**)*blacklist; + free(blacklist); + blacklist = node; + } + free(line); + free(label); + return 0; +} +\ No newline at end of file diff --git a/fil/ca-certificates-bmlfs/remove-expired-certs.sh b/fil/ca-certificates-bmlfs/remove-expired-certs.sh @@ -0,0 +1,51 @@ +#!/bin/sh +# Begin remove-expired-certs.sh +# +# Version 20120211 + +# Make sure the date is parsed correctly on all systems +mydate() +{ + local y=$( echo $1 | cut -d" " -f4 ) + local M=$( echo $1 | cut -d" " -f1 ) + local d=$( echo $1 | cut -d" " -f2 ) + local m + + [ -z "${d}" ] && d="0" + [ "${d}" -lt 10 ] && d="0${d}" + + case $M in + Jan) m="01";; + Feb) m="02";; + Mar) m="03";; + Apr) m="04";; + May) m="05";; + Jun) m="06";; + Jul) m="07";; + Aug) m="08";; + Sep) m="09";; + Oct) m="10";; + Nov) m="11";; + Dec) m="12";; + esac + + certdate="${y}${m}${d}" +} + +DIR="$1" +[ -z "$DIR" ] && DIR=$(pwd) + +today=$(date +%Y%m%d) + +find ${DIR} -type f -a -iname "*.crt" -printf "%p\n" | while read cert; do + notafter=$(/usr/bin/openssl x509 -enddate -in "${cert}" -noout) + date=$( echo ${notafter} | sed 's/^notAfter=//' ) + mydate "$date" + + if [ ${certdate} -lt ${today} ]; then + echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" + echo "EXPIRED CERTIFICATE FOUND $certdate: \"$(basename ${cert})\"" + echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" + rm -f "${cert}" + fi +done diff --git a/fil/rc.d/rc.conf b/fil/rc.d/rc.conf @@ -1,5 +1,6 @@ -HOSTNAME=galeb +FONT=LatArCyrHeb-16 INTERFACE=eth0 +KILLDELAY=3 HARDWARECLOCK=UTC +HOSTNAME=galeb TIMEZONE=Europe/Belgrade -FONT=LatArCyrHeb-16 diff --git a/fil/rc.d/rc.init b/fil/rc.d/rc.init @@ -58,16 +58,28 @@ mount -a ln -sf /proc/mounts /etc/mtab -msg info "Setting font" -setfont ${FONT} +msg info "Starting metalog" +/sucks/bin/metalog -B -g metalog -msg info "Setting hostname" -hostname ${HOSTNAME} +if [ -n "${FONT}" ]; then + msg info "Setting font" + setfont ${FONT} +fi + +if [ -n "${HOSTNAME}" ]; then + msg info "Setting hostname" + hostname ${HOSTNAME} +fi msg info "Bringing up lo interface" ip addr add 127.0.0.1/8 dev lo broadcast + scope host ip link set lo up +if [ -n "${INTERFACE}" ]; then + msg info "Bringing up %s" ${INTERFACE} + ip link set "${INTERFACE}" up +fi + msg info "Setting random seed" if [ -f /etc/random-seed ]; then cat /etc/random-seed >/dev/urandom @@ -87,14 +99,17 @@ fi if [ -x /bin/rc.modules ]; then msg info "Starting /bin/rc.modules" + /bin/rc.modules fi if [ -x /bin/rc.svc ]; then msg info "Starting /bin/rc.svc" + /bin/rc.svc fi if [ -x /bin/rc.local ]; then msg info "Starting /bin/rc.local" + /bin/rc.local fi :>/var/run/utmp diff --git a/fil/rc.d/rc.shutdown b/fil/rc.d/rc.shutdown @@ -47,20 +47,20 @@ dd if=/dev/urandom of=/etc/random-seed count=1 bs=512 2>/dev/null svc -k +KILLDELAY=${KILLDELAY:-3} + msg info "Sending processes the TERM signal..." killall5 -s TERM -sleep 3 +msg info "Waiting %ss" "${KILLDELAY}" +sleep "${KILLDELAY}" msg info "Sending processes the KILL signal..." killall5 -s KILL -msg info "whoami=" -whoami - msg info "Remounting / as read-only" remountroot msg info "Unmounting filesystems" -umountall +umountall -q sync; sync; sync sleep 3 wait diff --git a/fil/rc.d/rc.svc b/fil/rc.d/rc.svc @@ -11,7 +11,7 @@ svc -c for service in $(find /bin/svc.d/run -type l) do msg serv "Starting %s\t\t\t" ${service##*/} - service start ${service##*/} >/dev/null 2>&1 + svc -s "${service##*/}" >/dev/null 2>&1 case $? in 0) printf "${green}( ${white}OK${norm} ${green})${norm}\n";; 1) printf "${green}(RNNG)${norm}\n";; diff --git a/fil/svc.d/avail/crond b/fil/svc.d/avail/crond @@ -1,21 +0,0 @@ -#!/bin/sh - -. /bin/svc.d/default/crond - -PID=$(pidof -o %PPID /bin/crond) - -case $1 in - -s) if [ -z "${PID}" ]; then - /bin/crond ${PARAMS} || exit 2 - else - exit 1 - fi;; - -k) kill ${PID} >/dev/null 2>&1 - sleep 1 - if [ -n "${PID}" ]; then - kill -9 ${PID} >/dev/null 2>&1 || exit 2 - else - exit 2 - fi;; - *) exit 2;; -esac diff --git a/fil/svc.d/avail/hwclock b/fil/svc.d/avail/hwclock @@ -9,8 +9,10 @@ if [ -n "${TIMEZONE}" ]; then fi case $1 in - -s) hwclock -s ${PARAMS} >/dev/null 2>&1;; - -k) hwclock -w ${PARAMS} >/dev/null 2>&1;; - *) echo "usage: $0 -s|-k" - exit 1 -esac -\ No newline at end of file + -e) ;; # one-shot + -s) hwclock -s ${PARAMS} >/dev/null 2>&1 || exit 2;; + -k) hwclock -w ${PARAMS} >/dev/null 2>&1 || exit 2;; + -r) exit 1;; + *) echo "usage: $0 -s|-k" >&2 + exit 2 +esac diff --git a/lib/perms.tsv b/lib/perms.tsv @@ -5,6 +5,10 @@ Path Mode Owner Group /bin/crond 4700 root root /bin/crontab 4750 root cron /bin/halt 4550 root wheel +/var/log 775 root metalog +/var/log/lastlog 664 root utmp +/var/log/btmp 600 root utmp +/var/log/btmp 664 root utmp /var/spool/cron 0755 root root /var/spool/cron/cronstamps 0755 root root /var/spool/cron/crontabs 0755 root root @@ -12,5 +16,5 @@ Path Mode Owner Group /bin/rc.init 555 root root /bin/rc.shutdown 4555 root wheel /bin/rc.svc 555 root root -/bin/remountroot 4755 root wheel -/bin/umountall 4755 root wheel +/bin/remountroot 4750 root wheel +/bin/umountall 4750 root wheel diff --git a/lib/pkgs.tsv b/lib/pkgs.tsv @@ -1,6 +1,8 @@ URL Directory/Tarball MD5 Sum git+https://git.adelielinux.org/adelie/musl-locales.git musl-locales-20220708 git+https://git.sr.ht/~strahinja/reflow reflow-20220716 +git+https://git.sr.ht/~strahinja/svc svc-20220717 +git+https://github.com/cpeuvrel/usleep-aur usleep-20220718 git+https://github.com/mirbsd/mksh mksh-20220709 git+https://github.com/onetrueawk/awk awk-20220709 git://git.2f30.org/sdhcp sdhcp-20220716 @@ -9,12 +11,13 @@ git://git.suckless.org/sbase sbase-20220709 git://git.suckless.org/sinit sinit-20220713 git://git.suckless.org/smdev smdev-20220715 git://git.suckless.org/ubase ubase-20220709 -git+https://git.sr.ht/~strahinja/svc svc-20220717 +git://oldgit.suckless.org/sup sup-20220718 git://repo.or.cz/tinycc.git tinycc-20220708 http://www.jimpryor.net/linux/releases/dcron-4.5.tar.gz 078833f3281f96944fc30392b1888326 https://astron.com/pub/file/file-5.41.tar.gz 18233bb0a0089dfdc7dfbc93b96f231b https://cmake.org/files/v3.23/cmake-3.23.2.tar.gz ab3c9ed9578cdb496a252c6733989d78 https://cpan.metacpan.org/authors/id/T/TO/TODDR/XML-Parser-2.46.tar.gz 80bb18a8e6240fcf7ec2f7b57601c170 +https://curl.se/download/curl-7.84.0.tar.xz 6ce66afa416bb11b8f39cc9e059afd5b https://dev.alpinelinux.org/archive/posixtz/posixtz-0.5.tar.xz 80f8ae1df19dd28e1c8b192c6ea7b836 https://dev.gentoo.org/~xen0n/distfiles/pax-utils-1.3.4.tar.xz b9cdbc70fdd4e377dcf17eeff28c5ade https://dist.libuv.org/dist/v1.44.1/libuv-v1.44.1.tar.gz libuv-1.44.1.tar.gz c09e81ebac8c4cdb9ef3adada0257350 @@ -24,6 +27,7 @@ https://download.savannah.gnu.org/releases/attr/attr-2.5.1.tar.gz ac1c5a7a084f0 https://downloads.sourceforge.net/project/e2fsprogs/e2fsprogs/v1.46.5/e2fsprogs-1.46.5.tar.gz 3da91854c960ad8a819b48b2a404eb43 https://ftp.barfooze.de/pub/sabotage/tarballs/gettext-tiny-0.3.2.tar.xz 9ddf4d35636fa3beacd3627cc02723ff https://ftp.barfooze.de/pub/sabotage/tarballs/netbsd-curses-0.3.2.tar.xz bff9cfda41ae25ea84bd8da6c674dcb7 +https://ftp.debian.org/debian/pool/main/c/ca-certificates/ca-certificates_20211016.tar.xz ca-certificates-20211016.tar.xz 5cce77de047611c4b9384d4ce52d9204 https://ftp.gnu.org/gnu/autoconf/autoconf-2.71.tar.xz 12cfa1687ffa2606337efe1a64416106 https://ftp.gnu.org/gnu/automake/automake-1.16.4.tar.xz 86e8e682bd74e6390a016c4d9c11267c https://ftp.gnu.org/gnu/bash/bash-5.1.tar.gz bb91a17fd6c9032c26d0b2b78b50aff5 @@ -52,14 +56,17 @@ https://ftp.gnu.org/gnu/sed/sed-4.8.tar.xz 6d906edfdb3202304059233f51f9a71d https://ftp.gnu.org/gnu/tar/tar-1.34.tar.xz 9a08d29a9ac4727130b5708347c0f5cf https://ftp.gnu.org/gnu/texinfo/texinfo-6.8.tar.xz a91b404e30561a5df803e6eb3a53be71 https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.4.2.tar.gz 18aa728e7947a30af3bb04243e4482aa +https://ftpmirror.gnu.org/autoconf-archive/autoconf-archive-2022.02.11.tar.xz d140e95be64f0aa7369f82e3caae4730 https://gcc.gnu.org/pub/gcc/snapshots/11-20220101/gcc-11-20220101.tar.xz 2d984314c9ad01d941358bcf3ec6b29e https://git.sr.ht/~strahinja/sled/archive/v0.10.8.tar.gz sled-0.10.8.tar.gz 2a12c7eb0e6cb4f671299acb76753986 https://git.sr.ht/~strahinja/table/archive/v0.6.2.tar.gz table-0.6.2.tar.gz d77b956284878bb68c07d96e7efbc161 https://github.com/Mic92/iana-etc/releases/download/20210611/iana-etc-20210611.tar.gz f2854be57fe281e3ffc7364984467d2f +https://github.com/PhilipHazel/pcre2/releases/download/pcre2-10.39/pcre2-10.39.tar.bz2 4a765b1419c2e7a01263c3260abca87a https://github.com/arsv/perl-cross/releases/download/1.4/perl-cross-1.4.tar.gz 73c246c20766d027c3dc9f606418c22c https://github.com/ericonr/argp-standalone/archive/refs/tags/1.4.1.tar.gz argp-standalone-1.4.1.tar.gz 7f391d52161e7fe8e8d3df4f850bc7ee https://github.com/facebook/zstd/releases/download/v1.5.0/zstd-1.5.0.tar.gz a6eb7fb1f2c21fa80030a47993853e92 https://github.com/gavinhoward/bc/releases/download/5.0.0/bc-5.0.0.tar.xz 8345bb81c576ddfc8c27e0842370603c +https://github.com/hvisage/metalog/archive/refs/tags/metalog-20220214.tar.gz fdc00a7b41dbb7f18375352e4e3a37d5 https://github.com/libcheck/check/releases/download/0.15.2/check-0.15.2.tar.gz 50fcafcecde5a380415b12e9c574e0b2 https://github.com/libffi/libffi/releases/download/v3.4.2/libffi-3.4.2.tar.gz 294b921e6cf9ab0fbaea4b639f8fdbe8 https://github.com/martanne/vis/releases/download/v0.7/vis-0.7.tar.gz a45ba03d1fa4785ee5693f9619f22e85 @@ -84,6 +91,7 @@ https://mirrors.edge.kernel.org/pub/linux/docs/man-pages/man-pages-5.13.tar.xz https://mirrors.edge.kernel.org/pub/software/scm/git/git-2.37.1.tar.xz 8201241ee1eca83a9f72f4505350f6bc https://musl.libc.org/releases/musl-1.2.3.tar.gz a507ae4f7f20bcfe566d8eb65c1af73e https://prdownloads.sourceforge.net/expat/expat-2.4.8.tar.xz 0584a7318a4c007f7ec94778799d72fe +https://sourceforge.net/projects/pcre/files/pcre/8.45/pcre-8.45.tar.bz2 4452288e6a0eefb2ab11d36010a1eebb https://sourceforge.net/projects/procps-ng/files/Production/procps-ng-3.3.17.tar.xz d60613e88c2f442ebd462b5a75313d56 https://sourceforge.net/projects/psmisc/files/psmisc/psmisc-23.4.tar.xz 8114cd4489b95308efe2509c3a406bbf https://sourceforge.net/projects/tcl/files/Tcl/8.6.12/tcl8.6.12-src.tar.gz 87ea890821d2221f2ab5157bc5eb885f diff --git a/src/umountall.c b/src/umountall.c @@ -4,16 +4,22 @@ #define MAXBUF 4096 +static int quiet = 0; + int -main() +main(int argc, char** argv) { FILE* mounts = NULL; char line[MAXBUF]; char* eol = NULL; + if (*argv[1] && !strcmp(argv[1], "-q")) + quiet = 1; + if (!(mounts = fopen("/proc/self/mounts", "r"))) { - perror("umountall"); + if (!quiet) + perror("umountall"); return 1; } @@ -23,7 +29,7 @@ main() if (eol) *eol = 0; strtok(line, " "); - if (umount(strtok(NULL, " "))) + if (umount(strtok(NULL, " ")) && !quiet) perror("umountall"); }