Skip to content

Commit a721f1d

Browse files
committed
tinc: Provide SMF and user support.
Submitted by Antonio Huete in TritonDataCenter#108. Bump PKGREVISION.
1 parent 989fd0b commit a721f1d

8 files changed

Lines changed: 231 additions & 3 deletions

File tree

‎net/tinc/MESSAGE.smf‎

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
===========================================================================
2+
$NetBSD: MESSAGE.smf,v 1.1 2018/09/30 15:55:25 jperkin Exp $
3+
4+
This package supports multiple SMF instances.
5+
6+
By default a 'default' instance is created and a example tinc.conf
7+
config file is put in place in the 'default' network directory.
8+
No keys will be generated automatically, the user is expected to do so.
9+
10+
Configure using the SMF properties: user, chroot, memlock
11+
12+
'user' is the user to setuid to after initialization.
13+
'chroot' will chroot the server process to the directory where the
14+
network config is located.
15+
'memlock' locks tinc into the main memory.
16+
17+
For more information about these options check tincd(8) manpage.
18+
19+
Add a example service instance:
20+
21+
svccfg -s tinc add mynetwork
22+
svccfg -s tinc:mynetwork addpg tinc application
23+
svccfg -s tinc:mynetwork setprop tinc/user = astring: tincuser
24+
svccfg -s tinc:mynetwork setprop tinc/chroot = boolean: true
25+
svccfg -s tinc:mynetwork setprop tinc/memlock = boolean: true
26+
27+
===========================================================================

‎net/tinc/Makefile‎

Lines changed: 43 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
1-
# $NetBSD: Makefile,v 1.27 2017/09/08 13:53:25 jperkin Exp $
1+
# $NetBSD: Makefile,v 1.28 2018/09/30 15:55:25 jperkin Exp $
22

33
DISTNAME= tinc-1.0.32
4+
PKGREVISION= 1
45
CATEGORIES= net
56
MASTER_SITES= http://www.tinc-vpn.org/packages/
67

@@ -9,14 +10,54 @@ HOMEPAGE= http://www.tinc-vpn.org/
910
COMMENT= Virtual Private Network (VPN) daemon
1011
LICENSE= gnu-gpl-v2
1112

13+
BUILD_DEFS+= VARBASE
14+
1215
INFO_FILES= yes
1316
USE_TOOLS+= msgfmt
1417
GNU_CONFIGURE= yes
1518

1619
SUBST_CLASSES+= mdoc
1720
SUBST_FILES.mdoc= doc/tinc.conf.5.in
1821
SUBST_SED.mdoc+= -e '/^$$/d'
19-
SUBST_STAGE.mdoc= pre-patch
22+
SUBST_STAGE.mdoc= pre-configure
23+
24+
EGDIR= ${PREFIX}/share/examples/tinc
25+
TINC_USER?= tinc
26+
TINC_GROUP?= tinc
27+
28+
PKG_GROUPS_VARS+= TINC_GROUP
29+
PKG_USERS_VARS+= TINC_USER
30+
31+
PKG_GROUPS= ${TINC_GROUP}
32+
PKG_USERS= ${TINC_USER}:${TINC_GROUP}
33+
PKG_SHELL.${TINC_USER}= ${SH}
34+
35+
OWN_DIRS+= ${VARBASE}/log/tinc
36+
MAKE_DIRS+= ${PKG_SYSCONFDIR}/default
37+
38+
INSTALLATION_DIRS= share/examples/tinc
39+
40+
PKG_SYSCONFSUBDIR= tinc
41+
42+
CONF_FILES_PERMS+= ${EGDIR}/tinc.conf ${PKG_SYSCONFDIR}/default/tinc.conf \
43+
${REAL_ROOT_USER} ${REAL_ROOT_GROUP} 644
44+
CONF_FILES_PERMS+= ${EGDIR}/tinc-up ${PKG_SYSCONFDIR}/default/tinc-up \
45+
${REAL_ROOT_USER} ${REAL_ROOT_GROUP} 755
46+
CONF_FILES_PERMS+= ${EGDIR}/tinc-down ${PKG_SYSCONFDIR}/default/tinc-down \
47+
${REAL_ROOT_USER} ${REAL_ROOT_GROUP} 755
48+
49+
.include "../../mk/bsd.prefs.mk"
50+
51+
.if ${INIT_SYSTEM} == "smf"
52+
SMF_METHODS= tinc
53+
MESSAGE_SRC+= MESSAGE.smf
54+
MESSAGE_SUBST+= PKG_SYSCONFDIR=${PKG_SYSCONFDIR:Q}
55+
.endif
56+
57+
post-install:
58+
${INSTALL_DATA} ${FILESDIR}/tinc.conf ${DESTDIR}${EGDIR}
59+
${INSTALL_DATA} ${FILESDIR}/tinc-up ${DESTDIR}${EGDIR}
60+
${INSTALL_DATA} ${FILESDIR}/tinc-down ${DESTDIR}${EGDIR}
2061

2162
.include "../../archivers/lzo/buildlink3.mk"
2263
.include "../../converters/libiconv/buildlink3.mk"

‎net/tinc/PLIST‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
1-
@comment $NetBSD: PLIST,v 1.4 2010/05/01 16:56:40 tonnerre Exp $
1+
@comment $NetBSD: PLIST,v 1.5 2018/09/30 15:55:25 jperkin Exp $
22
info/tinc.info
33
man/man5/tinc.conf.5
44
man/man8/tincd.8
55
sbin/tincd
6+
share/examples/tinc/tinc-down
7+
share/examples/tinc/tinc-up
8+
share/examples/tinc/tinc.conf

‎net/tinc/files/smf/manifest.xml‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
<?xml version='1.0'?>
2+
<!DOCTYPE service_bundle SYSTEM '/usr/share/lib/xml/dtd/service_bundle.dtd.1'>
3+
<service_bundle type='manifest' name='export'>
4+
<service name='@SMF_PREFIX@/@SMF_NAME@' type='service' version='1'>
5+
<create_default_instance enabled='false'/>
6+
<dependency name='network' grouping='require_all' restart_on='refresh' type='service'>
7+
<service_fmri value='svc:/milestone/network:default'/>
8+
</dependency>
9+
<dependency name='filesystem' grouping='require_all' restart_on='refresh' type='service'>
10+
<service_fmri value='svc:/system/filesystem/local'/>
11+
</dependency>
12+
<exec_method type='method' name='start' exec='@PREFIX@/@SMF_METHOD_FILE.tinc@ start' timeout_seconds='60'/>
13+
<exec_method type='method' name='stop' exec='@PREFIX@/@SMF_METHOD_FILE.tinc@ stop' timeout_seconds='60'/>
14+
<property_group name='application' type='application'></property_group>
15+
<property_group name='startd' type='framework'>
16+
<propval name='duration' type='astring' value='contract'/>
17+
<propval name='ignore_error' type='astring' value='core,signal'/>
18+
</property_group>
19+
<template>
20+
<common_name>
21+
<loctext xml:lang='C'>Virtual Private Network (VPN) daemon</loctext>
22+
</common_name>
23+
<documentation>
24+
<manpage title='tincd' section='8' manpath='@PREFIX@/@PKGMANDIR@'/>
25+
</documentation>
26+
</template>
27+
</service>
28+
</service_bundle>

‎net/tinc/files/smf/tinc.sh‎

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
#!@SMF_METHOD_SHELL@
2+
#
3+
# Init script for tinc (SMF)
4+
#
5+
6+
. /lib/svc/share/smf_include.sh
7+
8+
getproparg() {
9+
svcprop -p $1 $SMF_FMRI 2>/dev/null
10+
}
11+
12+
METHOD=$1
13+
INSTANCE=$(echo $SMF_FMRI | sed s_.*:__)
14+
INSTANCE=${INSTANCE:=default}
15+
16+
LOGDIR="@VARBASE@/log/tinc"
17+
LOGFILE="${LOGDIR}/tinc.${INSTANCE}.log"
18+
PIDFILE="@VARBASE@/run/tinc.${INSTANCE}.pid"
19+
_USER=$(getproparg tinc/user)
20+
_CHROOT=$(getproparg tinc/chroot)
21+
_MEMLOCK=$(getproparg tinc/memlock)
22+
23+
USER=${_USER:=tinc}
24+
25+
TINC_FLAGS=""
26+
27+
# Check if there is a configuration directory for this instance
28+
if [ ! -d @PKG_SYSCONFDIR@/${INSTANCE} ]; then
29+
echo "$0: No configuration directory found"
30+
exit $SMF_EXIT_ERR_CONFIG
31+
fi
32+
33+
# Chroot tinc into its config directory
34+
if [ "${_CHROOT}" == "true" ]; then
35+
TINC_FLAGS="${TINC_FLAGS} -R"
36+
fi
37+
38+
# Lock tinc memory to avoid going into swap
39+
if [ "${_MEMLOCK}" == "true" ]; then
40+
TINC_FLAGS="${TINC_FLAGS} -L"
41+
fi
42+
43+
case ${METHOD} in
44+
start)
45+
@PREFIX@/sbin/tincd -n ${INSTANCE} -U ${USER} ${TINC_FLAGS} --logfile=${LOGFILE} --pidfile=${PIDFILE}
46+
;;
47+
stop)
48+
@PREFIX@/sbin/tincd -n ${INSTANCE} -k --pidfile=${PIDFILE}
49+
;;
50+
esac
51+
52+
exit ${SMF_EXIT_OK}

‎net/tinc/files/tinc-down‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
#!/bin/sh
2+
3+
ifconfig $INTERFACE down
4+
ifconfig $INTERFACE unplumb

‎net/tinc/files/tinc-up‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
#!/bin/sh
2+
3+
ifconfig $INTERFACE plumb
4+
ifconfig $INTERFACE 192.168.100.1 netmask 255.255.255.0 up
5+
6+
# Add the routes needed
7+
# route add -net 192.168.4.0/24 172.16.12.10 -interface

‎net/tinc/files/tinc.conf‎

Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
# $NetBSD: tinc.conf,v 1.1 2018/09/30 15:55:25 jperkin Exp $
2+
#
3+
# tinc-vpn example configuration file. Please do NOT rely solely in the
4+
# information of this template, the information tinc.conf(5) manpage might
5+
# be more current.
6+
#
7+
# -------------------------------------------------------------------------------
8+
# Name = name [required]
9+
# This is the name which identifies this tinc daemon. It must be unique
10+
# for the virtual private network this daemon will connect to.
11+
# We're using 'default' to match the instance name of the SMF service which
12+
# is created by default.
13+
# -------------------------------------------------------------------------------
14+
Name = default
15+
#
16+
#
17+
# -------------------------------------------------------------------------------
18+
# Mode = router | switch | hub (router)
19+
# This option selects the way packets are routed to other daemons.
20+
#
21+
# router In this mode Subnet variables in the host configuration files will
22+
# be used to form a routing table. Only unicast packets of routable
23+
# protocols (IPv4 and IPv6) are supported in this mode.
24+
#
25+
# This is the default mode, and unless you really know you need
26+
# another mode, don't change it.
27+
#
28+
# switch In this mode the MAC addresses of the packets on the VPN will be
29+
# used to dynamically create a routing table just like an Ethernet
30+
# switch does. Unicast, multicast and broadcast packets of every
31+
# protocol that runs over Ethernet are supported in this mode at the
32+
# cost of frequent broadcast ARP requests and routing table updates.
33+
#
34+
# This mode is primarily useful if you want to bridge Ethernet
35+
# segments.
36+
#
37+
# hub This mode is almost the same as the switch mode, but instead every
38+
# packet will be broadcast to the other daemons while no routing
39+
# table is managed.
40+
# -------------------------------------------------------------------------------
41+
# Mode = router
42+
#
43+
#
44+
# -------------------------------------------------------------------------------
45+
# ConnectTo = name
46+
# Specifies which other tinc daemon to connect to on startup. Multiple
47+
# ConnectTo variables may be specified, in which case outgoing connections
48+
# to each specified tinc daemon are made. The names should be known to this
49+
# tinc daemon (i.e., there should be a host configuration file for the name
50+
# on the ConnectTo line).
51+
#
52+
# If you don't specify a host with ConnectTo, tinc won't try to connect to
53+
# other daemons at all, and will instead just listen for incoming
54+
# connections.
55+
# -------------------------------------------------------------------------------
56+
# ConnectTo = vpn1
57+
#
58+
#
59+
# -------------------------------------------------------------------------------
60+
# DeviceType = type (platform dependent)
61+
# The type of the virtual network device. Tinc will normally automatically
62+
# select the right type of tun/tap interface, and this option should not be
63+
# used. However, this option can be used to select one of the special
64+
# interface types, if support for them is compiled in.
65+
# -------------------------------------------------------------------------------
66+
# DeviceType = tap

0 commit comments

Comments
 (0)