From a66f61fcdb403fa557332ffdb4b09c8c4b1352d8 Mon Sep 17 00:00:00 2001 From: Peter Leese Date: Wed, 29 Jul 2026 07:39:37 +0100 Subject: [PATCH] net-misc/kea: Remove unused kea-ctrl-agent In addition to removal of kea-ctrl-agent conf and init, tidy up some comments, use lowercase for variables and other minor corrections. Bug: https://bugs.gentoo.org/979728 Signed-off-by: Peter Leese Part-of: https://codeberg.org/gentoo/gentoo/pulls/1567 Merges: https://codeberg.org/gentoo/gentoo/pulls/1567 Signed-off-by: Sam James --- net-misc/kea/files/kea-confd-r4 | 7 + net-misc/kea/files/kea-initd-r5 | 78 +++++++ net-misc/kea/kea-3.2.0-r1.ebuild | 335 +++++++++++++++++++++++++++++++ net-misc/kea/kea-9999.ebuild | 87 +++----- 4 files changed, 450 insertions(+), 57 deletions(-) create mode 100644 net-misc/kea/files/kea-confd-r4 create mode 100644 net-misc/kea/files/kea-initd-r5 create mode 100644 net-misc/kea/kea-3.2.0-r1.ebuild diff --git a/net-misc/kea/files/kea-confd-r4 b/net-misc/kea/files/kea-confd-r4 new file mode 100644 index 0000000000000..a39610acadc78 --- /dev/null +++ b/net-misc/kea/files/kea-confd-r4 @@ -0,0 +1,7 @@ +# KEA_SVC must be defined here! +# Available values: dhcp4 dhcp6 dhcp-ddns +KEA_SVC="@KEA_SVC@" + +#KEA_USER=dhcp +#KEA_GROUP=dhcp +#KEA_CONFIG=/etc/kea/kea-@KEA_SVC@.conf diff --git a/net-misc/kea/files/kea-initd-r5 b/net-misc/kea/files/kea-initd-r5 new file mode 100644 index 0000000000000..0208b21d46783 --- /dev/null +++ b/net-misc/kea/files/kea-initd-r5 @@ -0,0 +1,78 @@ +#!/sbin/openrc-run +# Copyright 2025-2026 Gentoo Authors +# Distributed under the terms of the GNU General Public License v2 + +: ${KEA_USER:=dhcp} +: ${KEA_GROUP:=dhcp} +: ${KEA_CONFIG:=/etc/kea/${RC_SVCNAME}.conf} + +description="kea ${KEA_SVC} services" +command="/usr/sbin/kea-${KEA_SVC}" +command_args="-c ${KEA_CONFIG}" +command_user="${KEA_USER}:${KEA_GROUP}" +pidfile="/run/kea/$(basename ${KEA_CONFIG%.*}).kea-${KEA_SVC}.pid" +required_files="${KEA_CONFIG}" +start_stop_daemon_args="--background" + +extra_commands="check_kea_svc checkconfig" +extra_started_commands="reload" + +check_kea_svc() { + if [ "${RC_SVCNAME}" = "kea" ]; then + eerror "You are not supposed to run this script directly." + eerror "Create a symlink for the kea service you want to run." + eerror "Symlinks should have been created during installation." + return 1 + fi + + case "${KEA_SVC}" in + dhcp4) + capabilities="^cap_net_bind_service,^cap_net_raw" + ;; + dhcp6|dhcp-ddns) + capabilities="^cap_net_bind_service" + ;; + *) + eerror "KEA_SVC is undefined or invalid!" + eerror "It should be defined in /etc/conf.d/${RC_SVCNAME}" + return 1 + ;; + esac +} + +checkconfig() { + ${command} -t ${KEA_CONFIG} 1>/dev/null || return 1 +} + +reload() { + checkconfig || return 1 + ebegin "Reloading ${RC_SVCNAME}" + start-stop-daemon --signal HUP --pidfile ${pidfile} + eend $? +} + +start_pre() { + check_kea_svc || return 1 + + if [ $(stat -c "%U:%G" ${KEA_CONFIG}) != "root:${KEA_GROUP}" ] ; then + eerror "${KEA_CONFIG} config file is not owned by root:${KEA_GROUP}" + eerror "you should reset the ownership:" + eerror "chown root:${KEA_GROUP} ${KEA_CONFIG}" + return 1 + fi + + if [ "${RC_CMD}" != "restart" ]; then + checkconfig || return 1 + fi +} + +start_post() { + # Kea creates the pidfile only after it has started successfully. + ewaitfile "${STARTUP_TIMEOUT:-1}" "${pidfile}" +} + +stop_pre() { + if [ "${RC_CMD}" = "restart" ]; then + checkconfig || return 1 + fi +} diff --git a/net-misc/kea/kea-3.2.0-r1.ebuild b/net-misc/kea/kea-3.2.0-r1.ebuild new file mode 100644 index 0000000000000..668ce8005c279 --- /dev/null +++ b/net-misc/kea/kea-3.2.0-r1.ebuild @@ -0,0 +1,335 @@ +# Copyright 1999-2026 Gentoo Authors +# Distributed under the terms of the GNU General Public License v2 + +EAPI=8 + +PYTHON_COMPAT=( python3_{11..15} ) +VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/isc.asc +inherit eapi9-ver flag-o-matic meson python-r1 systemd tmpfiles +inherit toolchain-funcs verify-sig + +DESCRIPTION="High-performance production grade DHCPv4 & DHCPv6 server" +HOMEPAGE="https://www.isc.org/kea/" + +if [[ ${PV} == 9999 ]]; then + inherit git-r3 + EGIT_REPO_URI="https://gitlab.isc.org/isc-projects/kea.git" +else + SRC_URI=" + https://downloads.isc.org/isc/kea/${PV}/${P}.tar.xz + !doc? ( https://codeberg.org/peter1010/kea-manpages/archive/kea-manpages-${PV}.tar.gz ) + verify-sig? ( https://downloads.isc.org/isc/kea/${PV}/${P}.tar.xz.asc ) + " + KEYWORDS="~amd64 ~arm ~arm64 ~x86" +fi + +LICENSE="MPL-2.0" +SLOT="0" +IUSE="debug doc kerberos mysql +openssl postgres selinux shell test" + +REQUIRED_USE="shell? ( ${PYTHON_REQUIRED_USE} )" +RESTRICT="!test? ( test )" + +COMMON_DEPEND=" + >=dev-libs/boost-1.66:= + dev-libs/log4cplus:= + kerberos? ( virtual/krb5 ) + mysql? ( + app-arch/zstd:= + dev-db/mysql-connector-c:= + dev-libs/openssl:= + virtual/zlib:= + ) + !openssl? ( dev-libs/botan:3=[boost] ) + openssl? ( dev-libs/openssl:0= ) + postgres? ( dev-db/postgresql:* ) + shell? ( ${PYTHON_DEPS} ) +" +DEPEND="${COMMON_DEPEND} + test? ( dev-cpp/gtest ) +" +RDEPEND="${COMMON_DEPEND} + acct-group/dhcp + acct-user/dhcp + selinux? ( sec-policy/selinux-dhcp ) +" +BDEPEND=" + ${PYTHON_DEPS} + >=dev-build/meson-1.8 + virtual/pkgconfig + doc? ( + $(python_gen_any_dep ' + dev-python/sphinx[${PYTHON_USEDEP}] + dev-python/sphinx-rtd-theme[${PYTHON_USEDEP}] + ') + ) + verify-sig? ( sec-keys/openpgp-keys-isc ) +" + +python_check_deps() { + use doc || return 0 + python_has_version "dev-python/sphinx[${PYTHON_USEDEP}]" \ + "dev-python/sphinx-rtd-theme[${PYTHON_USEDEP}]" +} + +pkg_setup() { + [[ ${MERGE_TYPE} != binary ]] && python_setup +} + +src_unpack() { + if [[ ${PV} == 9999 ]]; then + git-r3_src_unpack + return + fi + + if use verify-sig; then + verify-sig_verify_detached "${DISTDIR}"/${P}.tar.xz{,.asc} + fi + + default +} + +src_prepare() { + default + + # Fix up all doc paths, whether or not we are installing full set of docs + sed -e "s:'doc/kea':'doc/${PF}':" \ + -i meson.build || die + sed -e "s:'share/doc/kea':'share/doc/${PF}':" \ + -i doc/meson.build || die + sed -e "s:'doc/kea':'doc/${PF}':" \ + -i doc/sphinx/meson.build || die + sed -e "s:share/doc/kea/:share/doc/${PF}/:" \ + -i doc/sphinx/arm/install.rst || die + sed -e "s:share/doc/kea/examples:share/doc/${PF}/examples:" \ + -i doc/sphinx/arm/config.rst || die + + # set shebang before meson whether or not we are installing the shell + sed -e 's:^#!@PYTHON@:#!/usr/bin/env python3:' \ + -i src/bin/shell/kea-shell.in || die + + # Don't allow meson to install shell, we shall do that if required + sed -e 's:install\: true:install\: false:' \ + -i src/bin/shell/meson.build || die + + # do not create /run + sed -e '/^install_emptydir(RUNSTATEDIR/d' \ + -i meson.build || die +} + +src_configure() { + # https://bugs.gentoo.org/861617 + # https://gitlab.isc.org/isc-projects/kea/-/issues/3946 + # + # Upstream does not support LTO + filter-lto + + if use !openssl; then + append-cxxflags -std=c++20 + fi + + # Note: https://gitlab.isc.org/isc-projects/kea/-/issues/4171 suggests patching meson.build to set umask, + # instead here we pass install-umask as an argument to do the same thing, i.e. control permissions on + # installed files. + local emesonargs=( + --localstatedir="${EPREFIX}/var" + -Drunstatedir="${EPREFIX}/run" + $(meson_feature kerberos krb5) + -Dnetconf=disabled + -Dcrypto=$(usex openssl openssl botan) + $(meson_feature mysql) + $(meson_feature postgres postgresql) + $(meson_feature test tests) + --install-umask=0o023 + ) + if use debug; then + emesonargs+=( + --debug + ) + fi + meson_src_configure +} + +src_compile() { + meson_src_compile + + use doc && meson_src_compile doc +} + +src_test() { + # Get list of all test suites into an associative array + # the meson test --list returns either "kea / test_suite", "kea:shell-tests / test_suite" or + # "kea:python-tests / test_suite" + # Note: In meson >= 1.10 the format has changed to + # the meson test --list returns either "kea:test_suite", "shell-tests - kea:test_suite" or + # "python-tests - kea:test_suite" + # + # Discard the shell tests as we can't run shell tests in sandbox + + pushd "${BUILD_DIR}" || die + + local -A test_suites + local -a words + while IFS="/: " read -ra words ; do + if [[ "${words[0]}" != "shell-tests" ]] && [[ "${words[2]}" != "shell-tests" ]]; then + test_suites["${words[-1]}"]=1 + fi + done < <(meson test --list || die) + popd || die + + # Some other tests will fail for interface access restrictions, we have to remove the test suites those tests + # belong to + local -a skip_tests=( + dhcp-radius-tests + kea-log-buffer_logger_test.sh + kea-log-console_test.sh + dhcp-lease-query-tests + kea-dhcp6-tests + kea-dhcp4-tests + kea-dhcp-tests + ) + + # skip shell tests that require a running instance of MySQL + if use mysql; then + skip_tests+=( + kea-mysql-tests + dhcp-mysql-lib-tests + dhcp-forensic-log-libload-tests + ) + fi + + # skip shell tests that require a running instance of PgSQL + if use postgres; then + skip_tests+=( + kea-pgsql-tests + dhcp-pgsql-lib-tests + dhcp-forensic-log-libload-tests + ) + fi + + if use kerberos; then + skip_tests+=( + ddns-gss-tsig-tests + ) + fi + + if [[ $(tc-get-ptr-size) -eq 4 ]]; then + # see https://bugs.gentoo.org/958171 for reason for skipping these tests + skip_tests+=( + kea-util-tests + kea-dhcpsrv-tests + dhcp-ha-lib-tests + kea-d2-tests + ) + fi + + local name + for name in ${skip_tests[@]}; do + unset -v 'test_suites[${name}]' + done + + meson_src_test "${!test_suites[@]}" +} + +install_shell() { + local orig_build_dir=$1 + python_domodule "${orig_build_dir}"/src/bin/shell/*.py + python_doscript "${orig_build_dir}"/src/bin/shell/kea-shell + + # fix path to import kea modules + sed -e "/^sys.path.append/s|(.*)|('$(python_get_sitedir)/${PN}')|" \ + -i "${ED}"/usr/lib/python-exec/${EPYTHON}/kea-shell || die +} + +src_install() { + meson_install + + # Remove unused database files + if use !mysql; then + rm -r "${ED}"/usr/share/kea/scripts/mysql || die + fi + if use !postgres; then + rm -r "${ED}"/usr/share/kea/scripts/pgsql || die + fi + + # No easy way to control how meson_install sets permissions in meson < 1.9 + # So make sure permissions are same as in previous versions of kea + # To avoid any differences between an update vers first time install + fperms -R 0755 /usr/sbin + fperms -R 0755 /usr/bin + fperms -R 0755 /usr/$(get_libdir) + + if use shell; then + python_moduleinto ${PN} + python_foreach_impl install_shell "${BUILD_DIR}" + fi + + # We don't use keactrl.conf so move to reduce confusion + mv "${ED}"/etc/${PN}/keactrl.conf "${ED}"/usr/share/doc/${PF}/examples/keactrl.conf || die + + fowners -R root:dhcp /etc/${PN} + + # A side effect of using install_umask 023 in meson setup is setting config files to be world readable + # lets not do that + fperms -R 0750 /etc/${PN} + chmod 0640 "${ED}"/etc/${PN}/*.conf || die + + # Install a conf per service and a linked init script per service + newinitd "${FILESDIR}"/${PN}-initd-r5 ${PN} + local svc + for svc in dhcp4 dhcp6 dhcp-ddns; do + newconfd "${FILESDIR}"/${PN}-confd-r4 kea-${svc} + sed -e "s:@KEA_SVC@:${svc}:g" \ + -i "${ED}"/etc/conf.d/kea-${svc} || die + dosym kea "${EPREFIX}"/etc/init.d/kea-${svc} + done + + if use !doc; then + doman "${WORKDIR}"/kea-manpages/man/* + fi + + systemd_newunit "${FILESDIR}"/${PN}-dhcp-ddns.service-r2 ${PN}-dhcp-ddns.service + systemd_newunit "${FILESDIR}"/${PN}-dhcp4.service-r2 ${PN}-dhcp4.service + systemd_newunit "${FILESDIR}"/${PN}-dhcp6.service-r2 ${PN}-dhcp6.service + + newtmpfiles "${FILESDIR}"/${PN}.tmpfiles.conf ${PN}.conf + + keepdir /var/lib/${PN} /var/log/${PN} + fowners -R dhcp:dhcp /var/lib/${PN} /var/log/${PN} + fperms 750 /var/lib/${PN} /var/log/${PN} +} + +pkg_postinst() { + tmpfiles_process ${PN}.conf + + if ver_replacing -lt 2.6; then + ewarn "Several changes have been made for daemons:" + ewarn " To comply with common practices for this package," + ewarn " config paths by default has been changed as below:" + ewarn " /etc/kea/kea-dhcp4.conf" + ewarn " /etc/kea/kea-dhcp6.conf" + ewarn " /etc/kea/kea-dhcp-ddns.conf" + ewarn + ewarn " Daemons are launched by default with the unprivileged user 'dhcp'" + ewarn + ewarn "Please check your configuration!" + fi + + if ver_replacing -lt 3.0; then + ewarn "Make sure that ${EPREFIX}/var/lib/kea and all the files in it are owned by dhcp:" + ewarn "chown -R dhcp:dhcp ${EPREFIX}/var/lib/kea" + ewarn + ewarn "If using openrc;" + ewarn " There are now separate conf.d scripts and associated init.d per daemon!" + ewarn " Each Daemon needs to be launched separately, i.e. the daemons are" + ewarn " kea-dhcp4" + ewarn " kea-dhcp6" + ewarn " kea-dhcp-ddns" + ewarn "Please adjust your service startups appropriately" + fi + + if ! has_version net-misc/kea; then + elog "See examples of config files in:" + elog " ${EROOT}/usr/share/doc/${PF}/examples" + fi +} diff --git a/net-misc/kea/kea-9999.ebuild b/net-misc/kea/kea-9999.ebuild index fd85ad53e8941..28eeef19389d2 100644 --- a/net-misc/kea/kea-9999.ebuild +++ b/net-misc/kea/kea-9999.ebuild @@ -5,7 +5,7 @@ EAPI=8 PYTHON_COMPAT=( python3_{11..15} ) VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/isc.asc -inherit eapi9-ver flag-o-matic meson python-r1 systemd tmpfiles +inherit flag-o-matic meson python-r1 systemd tmpfiles inherit toolchain-funcs verify-sig DESCRIPTION="High-performance production grade DHCPv4 & DHCPv6 server" @@ -66,7 +66,7 @@ BDEPEND=" " python_check_deps() { - use doc || return 0; + use doc || return 0 python_has_version "dev-python/sphinx[${PYTHON_USEDEP}]" \ "dev-python/sphinx-rtd-theme[${PYTHON_USEDEP}]" } @@ -76,7 +76,7 @@ pkg_setup() { } src_unpack() { - if [[ ${PV} == 9999 ]] ; then + if [[ ${PV} == 9999 ]]; then git-r3_src_unpack return fi @@ -112,7 +112,7 @@ src_prepare() { -i src/bin/shell/meson.build || die # do not create /run - sed -e '/^install_emptydir(RUNSTATEDIR)$/d' \ + sed -e '/^install_emptydir(RUNSTATEDIR/d' \ -i meson.build || die } @@ -120,7 +120,7 @@ src_configure() { # https://bugs.gentoo.org/861617 # https://gitlab.isc.org/isc-projects/kea/-/issues/3946 # - # Kea Devs say no to LTO + # Upstream does not support LTO filter-lto if use !openssl; then @@ -152,8 +152,6 @@ src_configure() { src_compile() { meson_src_compile - # Note: If you want man pages doc use has to be set. This may change - # in the future and be like 2.6.3 where man pages were part of the release tarball use doc && meson_src_compile doc } @@ -168,18 +166,19 @@ src_test() { # Discard the shell tests as we can't run shell tests in sandbox pushd "${BUILD_DIR}" || die - local -A TEST_SUITES - while IFS="/: " read -a words ; do + local -A test_suites + local -a words + while IFS="/: " read -ra words ; do if [[ "${words[0]}" != "shell-tests" ]] && [[ "${words[2]}" != "shell-tests" ]]; then - TEST_SUITES["${words[-1]}"]=1 + test_suites["${words[-1]}"]=1 fi done < <(meson test --list || die) - popd + popd || die # Some other tests will fail for interface access restrictions, we have to remove the test suites those tests # belong to - local SKIP_TESTS=( + local -a skip_tests=( dhcp-radius-tests kea-log-buffer_logger_test.sh kea-log-console_test.sh @@ -191,31 +190,31 @@ src_test() { # skip shell tests that require a running instance of MySQL if use mysql; then - SKIP_TESTS+=( + skip_tests+=( kea-mysql-tests dhcp-mysql-lib-tests - dhcp-forensic-log-libloadtests + dhcp-forensic-log-libload-tests ) fi # skip shell tests that require a running instance of PgSQL if use postgres; then - SKIP_TESTS+=( + skip_tests+=( kea-pgsql-tests dhcp-pgsql-lib-tests - dhcp-forensic-log-libloadtests + dhcp-forensic-log-libload-tests ) fi if use kerberos; then - SKIP_TESTS+=( + skip_tests+=( ddns-gss-tsig-tests ) fi if [[ $(tc-get-ptr-size) -eq 4 ]]; then # see https://bugs.gentoo.org/958171 for reason for skipping these tests - SKIP_TESTS+=( + skip_tests+=( kea-util-tests kea-dhcpsrv-tests dhcp-ha-lib-tests @@ -223,16 +222,18 @@ src_test() { ) fi - for SKIP in ${SKIP_TESTS[@]}; do - unset TEST_SUITES["${SKIP}"] + local name + for name in ${skip_tests[@]}; do + unset -v 'test_suites[${name}]' done - meson_src_test ${!TEST_SUITES[@]} + meson_src_test "${!test_suites[@]}" } install_shell() { - python_domodule ${ORIG_BUILD_DIR}/src/bin/shell/*.py - python_doscript ${ORIG_BUILD_DIR}/src/bin/shell/kea-shell + local orig_build_dir=$1 + python_domodule "${orig_build_dir}"/src/bin/shell/*.py + python_doscript "${orig_build_dir}"/src/bin/shell/kea-shell # fix path to import kea modules sed -e "/^sys.path.append/s|(.*)|('$(python_get_sitedir)/${PN}')|" \ @@ -242,7 +243,7 @@ install_shell() { src_install() { meson_install - # Tidy up + # Remove build metadata and unused database files rm -r "${ED}"/usr/share/kea/meson-info || die if use !mysql; then rm -r "${ED}"/usr/share/kea/scripts/mysql || die @@ -260,7 +261,7 @@ src_install() { if use shell; then python_moduleinto ${PN} - ORIG_BUILD_DIR=${BUILD_DIR} python_foreach_impl install_shell + python_foreach_impl install_shell "${BUILD_DIR}" fi # We don't use keactrl.conf so move to reduce confusion @@ -274,16 +275,16 @@ src_install() { chmod 0640 "${ED}"/etc/${PN}/*.conf || die # Install a conf per service and a linked init script per service - newinitd "${FILESDIR}"/${PN}-initd-r4 ${PN} + newinitd "${FILESDIR}"/${PN}-initd-r5 ${PN} + local svc - for svc in dhcp4 dhcp6 dhcp-ddns ctrl-agent; do - newconfd "${FILESDIR}"/${PN}-confd-r3 kea-${svc} + for svc in dhcp4 dhcp6 dhcp-ddns; do + newconfd "${FILESDIR}"/${PN}-confd-r4 kea-${svc} sed -e "s:@KEA_SVC@:${svc}:g" \ -i "${ED}"/etc/conf.d/kea-${svc} || die dosym kea "${EPREFIX}"/etc/init.d/kea-${svc} done - systemd_newunit "${FILESDIR}"/${PN}-ctrl-agent.service-r2 ${PN}-ctrl-agent.service systemd_newunit "${FILESDIR}"/${PN}-dhcp-ddns.service-r2 ${PN}-dhcp-ddns.service systemd_newunit "${FILESDIR}"/${PN}-dhcp4.service-r2 ${PN}-dhcp4.service systemd_newunit "${FILESDIR}"/${PN}-dhcp6.service-r2 ${PN}-dhcp6.service @@ -298,34 +299,6 @@ src_install() { pkg_postinst() { tmpfiles_process ${PN}.conf - if ver_replacing -lt 2.6; then - ewarn "Several changes have been made for daemons:" - ewarn " To comply with common practices for this package," - ewarn " config paths by default has been changed as below:" - ewarn " /etc/kea/kea-dhcp4.conf" - ewarn " /etc/kea/kea-dhcp6.conf" - ewarn " /etc/kea/kea-dhcp-ddns.conf" - ewarn " /etc/kea/kea-ctrl-agent.conf" - ewarn - ewarn " Daemons are launched by default with the unprivileged user 'dhcp'" - ewarn - ewarn "Please check your configuration!" - fi - - if ver_replacing -lt 3.0; then - ewarn "Make sure that ${EPREFIX}/var/lib/kea and all the files in it are owned by dhcp:" - ewarn "chown -R dhcp:dhcp ${EPREFIX}/var/lib/kea" - ewarn - ewarn "If using openrc;" - ewarn " There are now separate conf.d scripts and associated init.d per daemon!" - ewarn " Each Daemon needs to be launched separately, i.e. the daemons are" - ewarn " kea-dhcp4" - ewarn " kea-dhcp6" - ewarn " kea-dhcp-ddns" - ewarn " kea-ctrl" - ewarn "Please adjust your service startups appropriately" - fi - if ! has_version net-misc/kea; then elog "See examples of config files in:" elog " ${EROOT}/usr/share/doc/${PF}/examples"