-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathMakefile
More file actions
128 lines (111 loc) · 4.61 KB
/
Copy pathMakefile
File metadata and controls
128 lines (111 loc) · 4.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
.PHONY: help build build-server run start check-deps setup-certs setup-certs-session install clean test test-race test-e2e
help:
@echo "Keylime MCP"
@echo ""
@echo "Setup:"
@echo " make install - Full setup (check deps, env, certs, build)"
@echo " make check-deps - Verify dependencies (Go, setfacl, systemctl, sudo, certs)"
@echo " make setup-certs - Grant read access to Keylime certs, persists across reboots (requires sudo)"
@echo " make setup-certs-session - Same but only for current session (does not survive reboot)"
@echo ""
@echo "Build & Run:"
@echo " make build-server - Build MCP server binary"
@echo " make build - Build everything (server + client)"
@echo " make run - Build and run"
@echo " make start - Run pre-built binary (no compilation)"
@echo ""
@echo "Tests:"
@echo " make test - Run unit tests"
@echo " make test-race - Run unit tests with race detector"
@echo " make test-e2e - Submit e2e tests to Testing Farm (requires testing-farm + credentials)"
.env:
@if [ ! -f .env ]; then \
cp .env.example .env; \
echo "Created .env from .env.example"; \
fi
build-server:
go build -o bin/server cmd/server/main.go
build: build-server
go build -o bin/client cmd/client/main.go
run: .env build
cd bin/ && ./client
start:
cd bin/ && ./client
KEYLIME_CERT_DIR := /var/lib/keylime/cv_ca
CERT_FILES := cacert.crt client-cert.crt client-private.pem
EFFECTIVE_USER := $(or $(SUDO_USER),$(USER))
EFFECTIVE_UID := $(shell id -u $(EFFECTIVE_USER))
SYSTEMD_SERVICE := /etc/systemd/system/keylime-mcp-certs.service
TMPFILES_CONF := /etc/tmpfiles.d/keylime-mcp.conf
setup-certs: setup-certs-session
@echo "Installing systemd service for reboot persistence..."
@printf '%s\n' \
"[Unit]" \
"Description=Grant certificate access for Keylime MCP" \
"After=systemd-tmpfiles-setup.service nss-user-lookup.target" \
"[Service]" \
"Type=oneshot" \
"RemainAfterExit=yes" \
"ExecStart=/usr/bin/setfacl -m u:$(EFFECTIVE_UID):rx /var/lib/keylime" \
"ExecStart=/usr/bin/setfacl -m u:$(EFFECTIVE_UID):rx $(KEYLIME_CERT_DIR)" \
$(foreach f,$(CERT_FILES),"ExecStart=/usr/bin/setfacl -m u:$(EFFECTIVE_UID):r $(KEYLIME_CERT_DIR)/$(f)") \
"[Install]" \
"WantedBy=multi-user.target" \
| sudo tee $(SYSTEMD_SERVICE) > /dev/null
@printf '%s\n' \
"a+ /var/lib/keylime - - - - u:$(EFFECTIVE_UID):rx" \
"a+ $(KEYLIME_CERT_DIR) - - - - u:$(EFFECTIVE_UID):rx" \
$(foreach f,$(CERT_FILES),"a+ $(KEYLIME_CERT_DIR)/$(f) - - - - u:$(EFFECTIVE_UID):r") \
| sudo tee $(TMPFILES_CONF) > /dev/null
@sudo systemctl daemon-reload
@sudo systemctl enable keylime-mcp-certs.service
@echo "Done. Certificate access granted and will persist across reboots."
setup-certs-session:
@echo "Granting read access to Keylime certificates for user '$(EFFECTIVE_USER)'..."
@sudo setfacl -m u:$(EFFECTIVE_USER):rx /var/lib/keylime
@sudo setfacl -m u:$(EFFECTIVE_USER):rx $(KEYLIME_CERT_DIR)
@for f in $(CERT_FILES); do \
sudo setfacl -m u:$(EFFECTIVE_USER):r "$(KEYLIME_CERT_DIR)/$$f"; \
done
@echo "Done. Certificate access granted (will not persist across reboots)."
check-deps:
@echo "Checking dependencies..."
@command -v go >/dev/null 2>&1 || { echo "Go not found. Install: https://go.dev/dl/"; exit 1; }
@echo " Go: $$(go version)"
@command -v setfacl >/dev/null 2>&1 || { echo "setfacl not found. Install: sudo dnf install acl"; exit 1; }
@command -v systemctl >/dev/null 2>&1 || { echo "systemctl not found. systemd is required."; exit 1; }
@command -v sudo >/dev/null 2>&1 || { echo "sudo not found. Install: sudo dnf install sudo"; exit 1; }
@echo " Tools: OK (setfacl, systemctl, sudo)"
@for f in $(CERT_FILES); do \
if [ ! -r "$(KEYLIME_CERT_DIR)/$$f" ]; then \
echo " Certificate not readable: $(KEYLIME_CERT_DIR)/$$f"; \
echo " Run 'make setup-certs' to fix."; \
exit 1; \
fi; \
done
@echo " Certs: OK"
@echo "All dependencies satisfied."
install: setup-certs check-deps .env build
@echo "Installation complete. Run 'make run' or 'make start'."
clean:
rm -rf bin/*
@if [ -f $(SYSTEMD_SERVICE) ]; then \
sudo systemctl disable keylime-mcp-certs.service 2>/dev/null; \
sudo rm -f $(SYSTEMD_SERVICE); \
sudo systemctl daemon-reload; \
echo "Removed keylime-mcp-certs.service"; \
fi
@if [ -f $(TMPFILES_CONF) ]; then \
sudo rm -f $(TMPFILES_CONF); \
echo "Removed $(TMPFILES_CONF)"; \
fi
# Tests
test:
go test ./internal/... ./cmd/... -count=1
test-race:
go test ./internal/... ./cmd/... -race -count=1
test-e2e:
testing-farm request \
--compose Fedora-Rawhide \
--plan 'e2e/plans/keylime-mcp-main' \
--arch x86_64,aarch64,ppc64le,s390x