commit 83d44903ab650470bcf1bd706753426a22a77c4f
parent faeb889812e7a92ac50db695dd2a18aaa71e13cb
Author: Iván Ávalos <avalos@disroot.org>
Date: Fri, 2 Oct 2026 12:05:12 +0200
debian: ship only the sync-httpd2 units and fix build deps
Diffstat:
11 files changed, 55 insertions(+), 51 deletions(-)
diff --git a/debian/README-packaging.md b/debian/README-packaging.md
@@ -0,0 +1,50 @@
+This file contains some notes about packaging.
+
+## Systemd Units
+
+The main units are sync-httpd2.service and sync-httpd2.socket.
+
+The socket unit listens on `/run/sync/httpd/sync-httpd2.sock`, owned by the
+`sync-httpd` system user with group `www-data` and mode 0660, so that the
+Web server (Apache or Nginx) can connect to the backend through the socket.
+
+The service unit runs `/usr/bin/sync-httpd2 -c /etc/sync/sync.conf`.
+The service is socket-activated: enable (or start) the socket and the
+service will be pulled in on the first connection. The service is
+restarted on exit (unless it exits with status 9, which is used to
+indicate a configuration error).
+
+The database connection is configured through
+`/etc/sync/secrets/sync-db.secret.conf`, referenced from
+`/etc/sync/sync.conf` via `@inline-secret@`. The file is root-owned with
+mode 640 (set via dpkg-statoverride) so the `sync-httpd` user can read it
+while other users cannot. Use `sync-dbconfig` to create the database
+and prepare the configuration:
+
+ # sync-dbconfig -c /etc/sync/sync.conf
+
+## libmicrohttpd2
+
+sync-httpd2 is built against GNU libmicrohttpd 2.x (the MHD2 API), which
+Debian does not (yet) package. The CI containers build it from source
+(see contrib/ci/Containerfile, pinned to a revision of
+git.gnunet.org/libmicrohttpd2), so there is deliberately no
+`libmicrohttpd2-dev` in Build-Depends. The resulting binary needs the
+libmicrohttpd2 shared library at runtime (`libgnutls30` is declared
+because MHD2 links GnuTLS); make sure the target system provides it.
+
+## Web Server Integration
+
+The package installs ready-made configuration fragments for both Apache
+and Nginx that proxy the `/sync/` path to the Unix socket (see
+`/etc/apache2/sites-available/sync.conf` and
+`/etc/nginx/sites-available/sync`). Only one of the two should be
+enabled, adjust them to your site, and terminate TLS in the Web server.
+
+## Database
+
+The PostgreSQL database is created with `sync-dbinit` (run via
+`sync-dbconfig`). The SQL schema files are installed under
+`/usr/share/sync/sql/`. Note that the schema version is tracked in the
+`versioning.sql` file; do not run `sync-dbinit` from a different version
+of the package than the one installed.
diff --git a/debian/control b/debian/control
@@ -9,6 +9,9 @@ Build-Depends:
libgnunet-dev (>=0.27.0),
libtalerexchange-dev (>= 1.5.0),
libtalermerchant-dev (>= 1.5.0),
+ libjansson-dev (>= 2.13),
+ libgcrypt20-dev (>=1.8),
+ libcurl4-gnutls-dev (>=7.35.0) | libcurl4-openssl-dev (>=7.35.0),
libpq-dev (>=15.0),
pkg-config,
po-debconf,
diff --git a/debian/etc/apache2/sites-available/sync.conf b/debian/etc/apache2/sites-available/sync.conf
@@ -7,5 +7,5 @@
-->
<Location "/sync/">
-ProxyPass "unix:/run/sync/httpd/sync-http.sock|http://example.com/"
+ProxyPass "unix:/run/sync/httpd/sync-httpd2.sock|http://example.com/"
</Location>
diff --git a/debian/etc/nginx/sites-available/sync b/debian/etc/nginx/sites-available/sync
@@ -5,7 +5,7 @@ server {
# server_name example.com
location /sync/ {
- proxy_pass http://unix:/run/sync/httpd/sync-http.sock;
+ proxy_pass http://unix:/run/sync/httpd/sync-httpd2.sock;
proxy_redirect off;
proxy_set_header Host $host;
#proxy_set_header X-Forwarded-Host "example.com";
diff --git a/debian/rules b/debian/rules
@@ -29,7 +29,6 @@ override_dh_auto_clean:
dh_auto_clean
override_dh_installsystemd:
- dh_installsystemd -psync-httpd --name=sync-httpd --no-start --no-enable
dh_installsystemd -psync-httpd --name=sync-httpd2 --no-start --no-enable
# final invocation to generate daemon reload
dh_installsystemd
diff --git a/debian/sync-httpd.postinst b/debian/sync-httpd.postinst
@@ -7,15 +7,12 @@ if [ -d /run/systemd/system ]; then
fi
if [ "$1" = "remove" ]; then
if [ -x "/usr/bin/deb-systemd-helper" ]; then
- deb-systemd-helper mask 'sync-httpd.service' >/dev/null || true
deb-systemd-helper mask 'sync-httpd2.service' >/dev/null || true
fi
fi
if [ "$1" = "purge" ]; then
if [ -x "/usr/bin/deb-systemd-helper" ]; then
- deb-systemd-helper purge 'sync-httpd.service' >/dev/null || true
- deb-systemd-helper unmask 'sync-httpd.service' >/dev/null || true
deb-systemd-helper purge 'sync-httpd2.service' >/dev/null || true
deb-systemd-helper unmask 'sync-httpd2.service' >/dev/null || true
fi
diff --git a/debian/sync-httpd.prerm b/debian/sync-httpd.prerm
@@ -3,7 +3,6 @@
set -e
if [ -d /run/systemd/system ] && [ "$1" = remove ]; then
- deb-systemd-invoke stop 'sync-httpd.service' >/dev/null || true
deb-systemd-invoke stop 'sync-httpd2.service' >/dev/null || true
fi
diff --git a/debian/sync-httpd.service b/debian/sync-httpd.service
@@ -1,31 +0,0 @@
-[Unit]
-Description=Sync backup backend
-After=postgresql.service network.target
-Requires=sync-httpd.socket
-
-[Service]
-User=sync-httpd
-Type=simple
-Restart=always
-RestartMode=direct
-RestartSec=1s
-RestartPreventExitStatus=9
-
-# Disable the service if more than 5 restarts are encountered within 5s.
-# These are usually the systemd defaults, but can be overwritten, thus we set
-# them here explicitly, as the exchange code assumes StartLimitInterval
-# to be >=5s.
-StartLimitBurst=5
-StartLimitInterval=5s
-
-RuntimeMaxSec=3600s
-ExecStart=/usr/bin/sync-httpd -c /etc/sync/sync.conf -L INFO
-
-StandardOutput=journal
-StandardError=journal
-PrivateTmp=yes
-PrivateDevices=yes
-ProtectSystem=full
-
-[Install]
-WantedBy=multi-user.target
diff --git a/debian/sync-httpd.socket b/debian/sync-httpd.socket
@@ -1,13 +0,0 @@
-[Unit]
-Description=Sync Socket
-
-[Socket]
-ListenStream=/run/sync/httpd/sync-http.sock
-Accept=no
-Service=sync-httpd.service
-SocketUser=sync-httpd
-SocketGroup=www-data
-SocketMode=0660
-
-[Install]
-WantedBy=sockets.target
diff --git a/debian/sync-httpd2.service b/debian/sync-httpd.sync-httpd2.service
diff --git a/debian/sync-httpd2.socket b/debian/sync-httpd.sync-httpd2.socket