From efb22b47dbafff233e0a2d332d019270297be8b5 Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Sun, 12 Aug 2018 21:19:38 +0200 Subject: services: cgit: Disable repo booleans having a global counterpart. Otherwise the global counterpart is never taken into account. * doc/guix.texi (Version Control Services): Update accordingly. * gnu/services/cgit.scm (repo-boolean?, serialize-repo-boolean): Use the DEFINE-MAYBE macro to allow for the 'disabled value. (repository-cgit-configuration)[enable-commit-graph?, enable-log-filecount?, enable-log-linecount?, enable-remote-branches?, enable-subject-links?, enable-html-serving?]: Change default value to 'disabled. --- gnu/services/cgit.scm | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) (limited to 'gnu/services') diff --git a/gnu/services/cgit.scm b/gnu/services/cgit.scm index 3289d37333..a84a2dadb2 100644 --- a/gnu/services/cgit.scm +++ b/gnu/services/cgit.scm @@ -149,6 +149,7 @@ (define (serialize-repo-integer field-name val) (define (serialize-repo-boolean field-name val) (serialize-repo-integer field-name (if val 1 0))) +(define-maybe repo-boolean) (define repo-list? list?) @@ -239,27 +240,27 @@ (define-configuration repository-cgit-configuration (repo-file-object "") "Override the default @code{email-filter}.") (enable-commit-graph? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "A flag which can be used to disable the global setting @code{enable-commit-graph?}.") (enable-log-filecount? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "A flag which can be used to disable the global setting @code{enable-log-filecount?}.") (enable-log-linecount? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "A flag which can be used to disable the global setting @code{enable-log-linecount?}.") (enable-remote-branches? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "Flag which, when set to @code{#t}, will make cgit display remote branches in the summary and refs views.") (enable-subject-links? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "A flag which can be used to override the global setting @code{enable-subject-links?}.") (enable-html-serving? - (repo-boolean #f) + (maybe-repo-boolean 'disabled) "A flag which can be used to override the global setting @code{enable-html-serving?}.") (hide? -- cgit v1.2.3 From 2ded865665850d9f257ee62a995658c1381a8f4a Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Mon, 13 Aug 2018 17:36:05 +0200 Subject: services: prosody: Use 'invoke' rather than 'system*'. * gnu/services/messaging.scm (prosody-shepherd-service): Replace SYSTEM* with INVOKE. --- gnu/services/messaging.scm | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'gnu/services') diff --git a/gnu/services/messaging.scm b/gnu/services/messaging.scm index 4b7e724a78..6d3a5803c2 100644 --- a/gnu/services/messaging.scm +++ b/gnu/services/messaging.scm @@ -634,7 +634,7 @@ (define (prosody-shepherd-service config) (prosodyctl-bin (file-append prosody "/bin/prosodyctl")) (prosodyctl-action (lambda args #~(lambda _ - (zero? (system* #$prosodyctl-bin #$@args)))))) + (invoke #$prosodyctl-bin #$@args))))) (list (shepherd-service (documentation "Run the Prosody XMPP server") (provision '(prosody xmpp-daemon)) -- cgit v1.2.3 From fdbca05d78d091bfc075e54c9fb90125262eadf0 Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Mon, 13 Aug 2018 17:35:24 +0200 Subject: services: prosody: Get the Shepherd to respawn Prosody. * gnu/services/messaging.scm (prosody-shepherd-service): Return the PID when the action is "start". --- gnu/services/messaging.scm | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'gnu/services') diff --git a/gnu/services/messaging.scm b/gnu/services/messaging.scm index 6d3a5803c2..1108006411 100644 --- a/gnu/services/messaging.scm +++ b/gnu/services/messaging.scm @@ -632,13 +632,20 @@ (define (prosody-shepherd-service config) (opaque-prosody-configuration-prosody config) (prosody-configuration-prosody config))) (prosodyctl-bin (file-append prosody "/bin/prosodyctl")) + (pid-file (prosody-configuration-pidfile config)) (prosodyctl-action (lambda args #~(lambda _ - (invoke #$prosodyctl-bin #$@args))))) + (invoke #$prosodyctl-bin #$@args) + (match '#$args + (("start") + (call-with-input-file #$pid-file read)) + (_ #t)))))) (list (shepherd-service (documentation "Run the Prosody XMPP server") (provision '(prosody xmpp-daemon)) (requirement '(networking syslogd user-processes)) + (modules `((ice-9 match) + ,@%default-modules)) (start (prosodyctl-action "start")) (stop (prosodyctl-action "stop")))))) -- cgit v1.2.3 From ef2dda8edb2b78cf6a2ffcdac138421b2553aec8 Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Mon, 13 Aug 2018 20:37:09 +0200 Subject: services: postgresql: Get the Shepherd to respawn PostgreSQL. * gnu/services/databases.scm (postgresql-shepherd-service): Change 'start' to return the PID. --- gnu/services/databases.scm | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'gnu/services') diff --git a/gnu/services/databases.scm b/gnu/services/databases.scm index 8ae248ebe4..aff78a0566 100644 --- a/gnu/services/databases.scm +++ b/gnu/services/databases.scm @@ -221,13 +221,20 @@ (define postgresql-shepherd-service (setuid (passwd:uid user)) (execl pg_ctl pg_ctl "-D" #$data-directory "-o" options mode))))))) + (pid-file (in-vicinity data-directory "postmaster.pid")) (action (lambda args #~(lambda _ - (invoke #$pg_ctl-wrapper #$@args))))) + (invoke #$pg_ctl-wrapper #$@args) + (match '#$args + (("start") + (call-with-input-file #$pid-file read)) + (_ #t)))))) (list (shepherd-service (provision '(postgres)) (documentation "Run the PostgreSQL daemon.") (requirement '(user-processes loopback syslogd)) + (modules `((ice-9 match) + ,@%default-modules)) (start (action "start")) (stop (action "stop")))))))) -- cgit v1.2.3 From 4ae0607dd88cfb36a56fa27d0e04f6e6228058e8 Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Mon, 13 Aug 2018 21:02:39 +0200 Subject: services: nginx: Use 'invoke' rather than 'system*'. * gnu/services/web.scm (nginx-shepherd-service): Replace SYSTEM* with INVOKE. --- gnu/services/web.scm | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) (limited to 'gnu/services') diff --git a/gnu/services/web.scm b/gnu/services/web.scm index 9a58eff5ef..97976509b6 100644 --- a/gnu/services/web.scm +++ b/gnu/services/web.scm @@ -5,7 +5,7 @@ ;;; Copyright © 2016, 2017, 2018 Julien Lepiller ;;; Copyright © 2017 Christopher Baines ;;; Copyright © 2017 nee -;;; Copyright © 2017 Clément Lassieur +;;; Copyright © 2017, 2018 Clément Lassieur ;;; Copyright © 2018 Pierre-Antoine Rouby ;;; ;;; This file is part of GNU Guix. @@ -602,11 +602,10 @@ (define (nginx-shepherd-service config) (nginx-action (lambda args #~(lambda _ - (zero? - (system* #$nginx-binary "-c" - #$(or file - (default-nginx-config config)) - #$@args)))))) + (invoke #$nginx-binary "-c" + #$(or file + (default-nginx-config config)) + #$@args))))) ;; TODO: Add 'reload' action. (list (shepherd-service -- cgit v1.2.3 From de30205ba0f63eb987097a9f47b6e4fd38cd9044 Mon Sep 17 00:00:00 2001 From: Arun Isaac Date: Thu, 2 Aug 2018 05:32:56 +0530 Subject: gnu: services: Add pcscd service. * gnu/services/security-token.scm: New file. * gnu/tests/security-token.scm: New file. * gnu/local.mk (GNU_SYSTEM_MODULES): Register new files. * doc/guix.texi (Miscellaneous Services): Document the service. --- doc/guix.texi | 31 +++++++++++++++ gnu/local.mk | 2 + gnu/services/security-token.scm | 84 +++++++++++++++++++++++++++++++++++++++++ gnu/tests/security-token.scm | 71 ++++++++++++++++++++++++++++++++++ 4 files changed, 188 insertions(+) create mode 100644 gnu/services/security-token.scm create mode 100644 gnu/tests/security-token.scm (limited to 'gnu/services') diff --git a/doc/guix.texi b/doc/guix.texi index bcb368ce3f..dddf8c89c6 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -20331,6 +20331,37 @@ An association list specifies kernel parameters and their values. @end table @end deftp +@cindex pcscd +@subsubheading PC/SC Smart Card Daemon Service + +The @code{(gnu services security-token)} module provides the following service +to run @command{pcscd}, the PC/SC Smart Card Daemon. @command{pcscd} is the +daemon program for pcsc-lite and the MuscleCard framework. It is a resource +manager that coordinates communications with smart card readers, smart cards +and cryptographic tokens that are connected to the system. + +@defvr {Scheme Variable} pcscd-service-type +Service type for the @command{pcscd} service. Its value must be a +@code{pcscd-configuration} object. To run pcscd in the default +configuration, instantiate it as: + +@example +(service pcscd-service-type) +@end example +@end defvr + +@deftp {Data Type} pcscd-configuration +The data type representing the configuration of @command{pcscd}. + +@table @asis +@item @code{pcsc-lite} (default: @code{pcsc-lite}) +The pcsc-lite package that provides pcscd. +@item @code{usb-drivers} (default: @code{(list ccid)}) +List of packages that provide USB drivers to pcscd. Drivers are expected to be +under @file{pcsc/drivers} in the store directory of the package. +@end table +@end deftp + @cindex lirc @subsubheading Lirc Service diff --git a/gnu/local.mk b/gnu/local.mk index e14657c2d1..e3ca237d87 100644 --- a/gnu/local.mk +++ b/gnu/local.mk @@ -486,6 +486,7 @@ GNU_SYSTEM_MODULES = \ %D%/services/monitoring.scm \ %D%/services/networking.scm \ %D%/services/nfs.scm \ + %D%/services/security-token.scm \ %D%/services/shepherd.scm \ %D%/services/sound.scm \ %D%/services/herd.scm \ @@ -540,6 +541,7 @@ GNU_SYSTEM_MODULES = \ %D%/tests/messaging.scm \ %D%/tests/networking.scm \ %D%/tests/rsync.scm \ + %D%/tests/security-token.scm \ %D%/tests/ssh.scm \ %D%/tests/version-control.scm \ %D%/tests/virtualization.scm \ diff --git a/gnu/services/security-token.scm b/gnu/services/security-token.scm new file mode 100644 index 0000000000..7e7ea54a50 --- /dev/null +++ b/gnu/services/security-token.scm @@ -0,0 +1,84 @@ +;;; GNU Guix --- Functional package management for GNU +;;; Copyright © 2018 Arun Isaac +;;; +;;; This file is part of GNU Guix. +;;; +;;; GNU Guix is free software; you can redistribute it and/or modify it +;;; under the terms of the GNU General Public License as published by +;;; the Free Software Foundation; either version 3 of the License, or (at +;;; your option) any later version. +;;; +;;; GNU Guix is distributed in the hope that it will be useful, but +;;; WITHOUT ANY WARRANTY; without even the implied warranty of +;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +;;; GNU General Public License for more details. +;;; +;;; You should have received a copy of the GNU General Public License +;;; along with GNU Guix. If not, see . + +(define-module (gnu services security-token) + #:use-module (gnu services) + #:use-module (gnu services shepherd) + #:use-module (gnu packages admin) + #:use-module (gnu packages security-token) + #:use-module (gnu system shadow) + #:use-module (guix gexp) + #:use-module (guix modules) + #:use-module (guix records) + #:use-module (ice-9 match) + #:use-module (srfi srfi-26) + #:export (pcscd-configuration + pcscd-configuration? + pcscd-configuration-pcsc-lite + pcscd-configuration-usb-drivers + pcscd-service-type)) + +;;; +;;; PC/SC Smart Card Daemon +;;; + +(define-record-type* + pcscd-configuration make-pcscd-configuration pcscd-configuration? + (pcsc-lite pcscd-configuration-pcsc-lite + (default pcsc-lite)) + (usb-drivers pcscd-configuration-usb-drivers + (default (list ccid)))) + +(define pcscd-shepherd-service + (match-lambda + (($ pcsc-lite) + (with-imported-modules (source-module-closure + '((gnu build shepherd))) + (shepherd-service + (documentation "PC/SC Smart Card Daemon") + (provision '(pcscd)) + (requirement '(syslogd)) + (modules '((gnu build shepherd))) + (start #~(lambda _ + (invoke #$(file-append pcsc-lite "/sbin/pcscd")) + (call-with-input-file "/var/run/pcscd/pcscd.pid" read))) + (stop #~(make-kill-destructor))))))) + +(define pcscd-activation + (match-lambda + (($ pcsc-lite usb-drivers) + #~(begin + (use-modules (guix build utils)) + (mkdir-p "/var/lib") + (symlink #$(directory-union + "pcsc" + (map (cut file-append <> "/pcsc") + usb-drivers)) + "/var/lib/pcsc"))))) + +(define pcscd-service-type + (service-type + (name 'pcscd) + (description + "Run @command{pcscd}, the PC/SC smart card daemon.") + (extensions + (list (service-extension shepherd-root-service-type + (compose list pcscd-shepherd-service)) + (service-extension activation-service-type + pcscd-activation))) + (default-value (pcscd-configuration)))) diff --git a/gnu/tests/security-token.scm b/gnu/tests/security-token.scm new file mode 100644 index 0000000000..1169a4b9fd --- /dev/null +++ b/gnu/tests/security-token.scm @@ -0,0 +1,71 @@ +;;; GNU Guix --- Functional package management for GNU +;;; Copyright © 2018 Arun Isaac +;;; +;;; This file is part of GNU Guix. +;;; +;;; GNU Guix is free software; you can redistribute it and/or modify it +;;; under the terms of the GNU General Public License as published by +;;; the Free Software Foundation; either version 3 of the License, or (at +;;; your option) any later version. +;;; +;;; GNU Guix is distributed in the hope that it will be useful, but +;;; WITHOUT ANY WARRANTY; without even the implied warranty of +;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +;;; GNU General Public License for more details. +;;; +;;; You should have received a copy of the GNU General Public License +;;; along with GNU Guix. If not, see . + +(define-module (gnu tests security-token) + #:use-module (gnu tests) + #:use-module (gnu system vm) + #:use-module (gnu services) + #:use-module (gnu services security-token) + #:use-module (guix gexp) + #:export (%test-pcscd)) + +(define %pcscd-os + (simple-operating-system + (service pcscd-service-type))) + +(define* (run-pcscd-test) + "Run tests of 'pcscd-service-type'." + (define os + (marionette-operating-system + %pcscd-os + #:imported-modules '((gnu services herd)) + #:requirements '(pcscd))) + + (define test + (with-imported-modules '((gnu build marionette)) + #~(begin + (use-modules (srfi srfi-64) + (gnu build marionette)) + (define marionette + (make-marionette (list #$(virtual-machine os)))) + + (mkdir #$output) + (chdir #$output) + + (test-begin "pcscd") + + (test-assert "pcscd is alive" + (marionette-eval + '(begin + (use-modules (gnu services herd)) + (live-service-running + (find (lambda (live) + (memq 'pcscd (live-service-provision live))) + (current-services)))) + marionette)) + + (test-end) + (exit (= (test-runner-fail-count (test-runner-current)) 0))))) + + (gexp->derivation "pcscd" test)) + +(define %test-pcscd + (system-test + (name "pcscd") + (description "Test a running pcscd daemon.") + (value (run-pcscd-test)))) -- cgit v1.2.3 From 8d4805ba2934e492524512aac8a95662f2cf97c7 Mon Sep 17 00:00:00 2001 From: Clément Lassieur Date: Thu, 16 Aug 2018 19:07:33 +0200 Subject: services: cuirass: Put data in /var/lib to avoid removal at boot. Fixes . * gnu/services/cuirass.scm ()[database]: Change default from /var/run/cuirass/cuirass.db to /var/lib/cuirass/cuirass.db. (cuirass-account): Change home directory from /var/run/ to /var/lib/. --- gnu/services/cuirass.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'gnu/services') diff --git a/gnu/services/cuirass.scm b/gnu/services/cuirass.scm index 9c62080629..496b2d06c8 100644 --- a/gnu/services/cuirass.scm +++ b/gnu/services/cuirass.scm @@ -61,7 +61,7 @@ (define-record-type* (interval cuirass-configuration-interval ;integer (seconds) (default 60)) (database cuirass-configuration-database ;string (file-name) - (default "/var/run/cuirass/cuirass.db")) + (default "/var/lib/cuirass/cuirass.db")) (port cuirass-configuration-port ;integer (port) (default 8081)) (host cuirass-configuration-host ;string @@ -131,7 +131,7 @@ (define (cuirass-account config) (group cuirass-group) (system? #t) (comment "Cuirass privilege separation user") - (home-directory (string-append "/var/run/" cuirass-user)) + (home-directory (string-append "/var/lib/" cuirass-user)) (shell #~(string-append #$shadow "/sbin/nologin")))))) (define (cuirass-activation config) -- cgit v1.2.3 From 6fb6ac6857df31c55a640eead2a5f79edd7dab14 Mon Sep 17 00:00:00 2001 From: Chris Marusich Date: Mon, 20 Aug 2018 00:16:06 -0700 Subject: gnu: services: Fix pcscd activation bug. Fixes: . * gnu/services/security-token.scm (pcscd-activation): Idempotently create the /var/lib/pcsc symlink so that it does not fail when it already exists. --- gnu/services/security-token.scm | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) (limited to 'gnu/services') diff --git a/gnu/services/security-token.scm b/gnu/services/security-token.scm index 7e7ea54a50..354549b33c 100644 --- a/gnu/services/security-token.scm +++ b/gnu/services/security-token.scm @@ -20,6 +20,7 @@ (define-module (gnu services security-token) #:use-module (gnu services) #:use-module (gnu services shepherd) #:use-module (gnu packages admin) + #:use-module (gnu packages base) #:use-module (gnu packages security-token) #:use-module (gnu system shadow) #:use-module (guix gexp) @@ -62,14 +63,22 @@ (define pcscd-shepherd-service (define pcscd-activation (match-lambda (($ pcsc-lite usb-drivers) - #~(begin - (use-modules (guix build utils)) - (mkdir-p "/var/lib") - (symlink #$(directory-union - "pcsc" - (map (cut file-append <> "/pcsc") - usb-drivers)) - "/var/lib/pcsc"))))) + (with-imported-modules (source-module-closure + '((guix build utils))) + #~(begin + (use-modules (guix build utils)) + ;; XXX: We can't use (guix utils) because it requires a + ;; dynamically-linked Guile, hence the duplicate switch-symlinks. + (define (switch-symlinks link target) + (let ((pivot (string-append link ".new"))) + (symlink target pivot) + (rename-file pivot link))) + (mkdir-p "/var/lib") + (switch-symlinks "/var/lib/pcsc" + #$(directory-union + "pcsc" + (map (cut file-append <> "/pcsc") + usb-drivers)))))))) (define pcscd-service-type (service-type -- cgit v1.2.3