2014-10-29 09:11:07 +01:00
|
|
|
---
|
|
|
|
src/Makefile | 2 +-
|
|
|
|
src/daemon.h | 4 ++--
|
|
|
|
src/macros.pesign | 2 +-
|
|
|
|
src/pesign.sysvinit | 14 +++++++-------
|
|
|
|
src/tmpfiles.conf | 2 +-
|
|
|
|
5 files changed, 12 insertions(+), 12 deletions(-)
|
|
|
|
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/Makefile
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/Makefile
|
|
|
|
+++ pesign-0.112/src/Makefile
|
|
|
|
@@ -68,7 +68,7 @@ install_sysvinit: pesign.sysvinit
|
2014-04-16 09:27:13 +02:00
|
|
|
install :
|
|
|
|
$(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/
|
2016-04-26 16:58:40 +02:00
|
|
|
$(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/
|
2014-04-16 09:27:13 +02:00
|
|
|
- $(INSTALL) -d -m 770 $(INSTALLROOT)/var/run/pesign/
|
|
|
|
+ $(INSTALL) -d -m 770 $(INSTALLROOT)/run/pesign/
|
2015-12-01 10:03:35 +01:00
|
|
|
$(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir)
|
|
|
|
$(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir)
|
|
|
|
$(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir)
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/daemon.h
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/daemon.h
|
|
|
|
+++ pesign-0.112/src/daemon.h
|
2014-10-29 09:11:07 +01:00
|
|
|
@@ -49,7 +49,7 @@ typedef enum {
|
2014-04-16 09:27:13 +02:00
|
|
|
} pesignd_cmd;
|
|
|
|
|
2014-10-29 09:11:07 +01:00
|
|
|
#define PESIGND_VERSION 0x2a9edaf0
|
2014-04-16 09:27:13 +02:00
|
|
|
-#define SOCKPATH "/var/run/pesign/socket"
|
|
|
|
-#define PIDFILE "/var/run/pesign.pid"
|
|
|
|
+#define SOCKPATH "/run/pesign/socket"
|
|
|
|
+#define PIDFILE "/run/pesign.pid"
|
|
|
|
|
|
|
|
#endif /* DAEMON_H */
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/macros.pesign
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/macros.pesign
|
|
|
|
+++ pesign-0.112/src/macros.pesign
|
|
|
|
@@ -40,7 +40,7 @@
|
2014-04-16 09:27:13 +02:00
|
|
|
%{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\
|
|
|
|
--certdir ${nss} -c signer %{-o} \
|
|
|
|
rm -rf ${sattrs} ${sattrs}.sig ${nss} \
|
|
|
|
- elif [ -S /var/run/pesign/socket ]; then \
|
|
|
|
+ elif [ -S /run/pesign/socket ]; then \
|
|
|
|
%{_pesign_client} -t "OpenSC Card (Fedora Signer)" \\\
|
|
|
|
-c "/CN=Fedora Secure Boot Signer" \\\
|
|
|
|
%{-i} %{-o} %{-e} %{-s} %{-C} \
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/tmpfiles.conf
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/tmpfiles.conf
|
|
|
|
+++ pesign-0.112/src/tmpfiles.conf
|
2015-12-01 10:03:35 +01:00
|
|
|
@@ -1 +1 @@
|
|
|
|
-D /var/run/pesign 0770 pesign pesign -
|
|
|
|
+D /run/pesign 0770 pesign pesign -
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/pesign.sysvinit.in
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/pesign.sysvinit.in
|
|
|
|
+++ pesign-0.112/src/pesign.sysvinit.in
|
2014-04-16 09:27:13 +02:00
|
|
|
@@ -4,7 +4,7 @@
|
|
|
|
#
|
|
|
|
# chkconfig: - 50 50
|
|
|
|
# processname: /usr/bin/pesign
|
|
|
|
-# pidfile: /var/run/pesign.pid
|
|
|
|
+# pidfile: /run/pesign.pid
|
|
|
|
### BEGIN INIT INFO
|
|
|
|
# Provides: pesign
|
|
|
|
# Should-Start: $remote_fs
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/pesign.service.in
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/pesign.service.in
|
|
|
|
+++ pesign-0.112/src/pesign.service.in
|
2015-12-01 10:03:35 +01:00
|
|
|
@@ -4,7 +4,7 @@ Description=Pesign signing daemon
|
|
|
|
[Service]
|
|
|
|
PrivateTmp=true
|
|
|
|
Type=forking
|
|
|
|
-PIDFile=/var/run/pesign.pid
|
|
|
|
+PIDFile=/run/pesign.pid
|
|
|
|
ExecStart=/usr/bin/pesign --daemonize
|
|
|
|
ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize-users
|
|
|
|
ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize-groups
|
2016-04-26 16:58:40 +02:00
|
|
|
Index: pesign-0.112/src/pesign-authorize-groups
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/pesign-authorize-groups
|
|
|
|
+++ pesign-0.112/src/pesign-authorize-groups
|
|
|
|
@@ -12,10 +12,10 @@ set -e
|
2014-04-16 09:27:13 +02:00
|
|
|
|
2016-04-26 16:58:40 +02:00
|
|
|
if [ -r /etc/pesign/groups ]; then
|
2015-12-01 10:03:35 +01:00
|
|
|
for group in $(cat /etc/pesign/groups); do
|
2016-04-26 16:58:40 +02:00
|
|
|
- if [ -d /var/run/pesign ]; then
|
|
|
|
- setfacl -m g:${group}:rx /var/run/pesign
|
|
|
|
- if [ -e /var/run/pesign/socket ]; then
|
|
|
|
- setfacl -m g:${group}:rw /var/run/pesign/socket
|
|
|
|
+ if [ -d /run/pesign ]; then
|
|
|
|
+ setfacl -m g:${group}:rx /run/pesign
|
|
|
|
+ if [ -e /run/pesign/socket ]; then
|
|
|
|
+ setfacl -m g:${group}:rw /run/pesign/socket
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
for x in /etc/pki/pesign* ; do
|
|
|
|
Index: pesign-0.112/src/pesign-authorize-users
|
2015-12-01 10:03:35 +01:00
|
|
|
===================================================================
|
2016-04-26 16:58:40 +02:00
|
|
|
--- pesign-0.112.orig/src/pesign-authorize-users
|
|
|
|
+++ pesign-0.112/src/pesign-authorize-users
|
|
|
|
@@ -12,10 +12,10 @@ set -e
|
2014-04-16 09:27:13 +02:00
|
|
|
|
2016-04-26 16:58:40 +02:00
|
|
|
if [ -r /etc/pesign/users ]; then
|
2015-12-01 10:03:35 +01:00
|
|
|
for username in $(cat /etc/pesign/users); do
|
2016-04-26 16:58:40 +02:00
|
|
|
- if [ -d /var/run/pesign ]; then
|
|
|
|
- setfacl -m g:${username}:rx /var/run/pesign
|
|
|
|
- if [ -e /var/run/pesign/socket ]; then
|
|
|
|
- setfacl -m g:${username}:rw /var/run/pesign/socket
|
|
|
|
+ if [ -d /run/pesign ]; then
|
|
|
|
+ setfacl -m g:${username}:rx /run/pesign
|
|
|
|
+ if [ -e /run/pesign/socket ]; then
|
|
|
|
+ setfacl -m g:${username}:rw /run/pesign/socket
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
for x in /etc/pki/pesign* ; do
|