sync

Backup service to store encrypted wallet databases (experimental)
Log | Files | Refs | Submodules | README | LICENSE

commit 83d44903ab650470bcf1bd706753426a22a77c4f
parent faeb889812e7a92ac50db695dd2a18aaa71e13cb
Author: Iván Ávalos <avalos@disroot.org>
Date:   Fri,  2 Oct 2026 12:05:12 +0200

debian: ship only the sync-httpd2 units and fix build deps

Diffstat:
Adebian/README-packaging.md | 50++++++++++++++++++++++++++++++++++++++++++++++++++
Mdebian/control | 3+++
Mdebian/etc/apache2/sites-available/sync.conf | 2+-
Mdebian/etc/nginx/sites-available/sync | 2+-
Mdebian/rules | 1-
Mdebian/sync-httpd.postinst | 3---
Mdebian/sync-httpd.prerm | 1-
Ddebian/sync-httpd.service | 31-------------------------------
Ddebian/sync-httpd.socket | 13-------------
Rdebian/sync-httpd2.service -> debian/sync-httpd.sync-httpd2.service | 0
Rdebian/sync-httpd2.socket -> debian/sync-httpd.sync-httpd2.socket | 0
11 files changed, 55 insertions(+), 51 deletions(-)

diff --git a/debian/README-packaging.md b/debian/README-packaging.md @@ -0,0 +1,50 @@ +This file contains some notes about packaging. + +## Systemd Units + +The main units are sync-httpd2.service and sync-httpd2.socket. + +The socket unit listens on `/run/sync/httpd/sync-httpd2.sock`, owned by the +`sync-httpd` system user with group `www-data` and mode 0660, so that the +Web server (Apache or Nginx) can connect to the backend through the socket. + +The service unit runs `/usr/bin/sync-httpd2 -c /etc/sync/sync.conf`. +The service is socket-activated: enable (or start) the socket and the +service will be pulled in on the first connection. The service is +restarted on exit (unless it exits with status 9, which is used to +indicate a configuration error). + +The database connection is configured through +`/etc/sync/secrets/sync-db.secret.conf`, referenced from +`/etc/sync/sync.conf` via `@inline-secret@`. The file is root-owned with +mode 640 (set via dpkg-statoverride) so the `sync-httpd` user can read it +while other users cannot. Use `sync-dbconfig` to create the database +and prepare the configuration: + + # sync-dbconfig -c /etc/sync/sync.conf + +## libmicrohttpd2 + +sync-httpd2 is built against GNU libmicrohttpd 2.x (the MHD2 API), which +Debian does not (yet) package. The CI containers build it from source +(see contrib/ci/Containerfile, pinned to a revision of +git.gnunet.org/libmicrohttpd2), so there is deliberately no +`libmicrohttpd2-dev` in Build-Depends. The resulting binary needs the +libmicrohttpd2 shared library at runtime (`libgnutls30` is declared +because MHD2 links GnuTLS); make sure the target system provides it. + +## Web Server Integration + +The package installs ready-made configuration fragments for both Apache +and Nginx that proxy the `/sync/` path to the Unix socket (see +`/etc/apache2/sites-available/sync.conf` and +`/etc/nginx/sites-available/sync`). Only one of the two should be +enabled, adjust them to your site, and terminate TLS in the Web server. + +## Database + +The PostgreSQL database is created with `sync-dbinit` (run via +`sync-dbconfig`). The SQL schema files are installed under +`/usr/share/sync/sql/`. Note that the schema version is tracked in the +`versioning.sql` file; do not run `sync-dbinit` from a different version +of the package than the one installed. diff --git a/debian/control b/debian/control @@ -9,6 +9,9 @@ Build-Depends: libgnunet-dev (>=0.27.0), libtalerexchange-dev (>= 1.5.0), libtalermerchant-dev (>= 1.5.0), + libjansson-dev (>= 2.13), + libgcrypt20-dev (>=1.8), + libcurl4-gnutls-dev (>=7.35.0) | libcurl4-openssl-dev (>=7.35.0), libpq-dev (>=15.0), pkg-config, po-debconf, diff --git a/debian/etc/apache2/sites-available/sync.conf b/debian/etc/apache2/sites-available/sync.conf @@ -7,5 +7,5 @@ --> <Location "/sync/"> -ProxyPass "unix:/run/sync/httpd/sync-http.sock|http://example.com/" +ProxyPass "unix:/run/sync/httpd/sync-httpd2.sock|http://example.com/" </Location> diff --git a/debian/etc/nginx/sites-available/sync b/debian/etc/nginx/sites-available/sync @@ -5,7 +5,7 @@ server { # server_name example.com location /sync/ { - proxy_pass http://unix:/run/sync/httpd/sync-http.sock; + proxy_pass http://unix:/run/sync/httpd/sync-httpd2.sock; proxy_redirect off; proxy_set_header Host $host; #proxy_set_header X-Forwarded-Host "example.com"; diff --git a/debian/rules b/debian/rules @@ -29,7 +29,6 @@ override_dh_auto_clean: dh_auto_clean override_dh_installsystemd: - dh_installsystemd -psync-httpd --name=sync-httpd --no-start --no-enable dh_installsystemd -psync-httpd --name=sync-httpd2 --no-start --no-enable # final invocation to generate daemon reload dh_installsystemd diff --git a/debian/sync-httpd.postinst b/debian/sync-httpd.postinst @@ -7,15 +7,12 @@ if [ -d /run/systemd/system ]; then fi if [ "$1" = "remove" ]; then if [ -x "/usr/bin/deb-systemd-helper" ]; then - deb-systemd-helper mask 'sync-httpd.service' >/dev/null || true deb-systemd-helper mask 'sync-httpd2.service' >/dev/null || true fi fi if [ "$1" = "purge" ]; then if [ -x "/usr/bin/deb-systemd-helper" ]; then - deb-systemd-helper purge 'sync-httpd.service' >/dev/null || true - deb-systemd-helper unmask 'sync-httpd.service' >/dev/null || true deb-systemd-helper purge 'sync-httpd2.service' >/dev/null || true deb-systemd-helper unmask 'sync-httpd2.service' >/dev/null || true fi diff --git a/debian/sync-httpd.prerm b/debian/sync-httpd.prerm @@ -3,7 +3,6 @@ set -e if [ -d /run/systemd/system ] && [ "$1" = remove ]; then - deb-systemd-invoke stop 'sync-httpd.service' >/dev/null || true deb-systemd-invoke stop 'sync-httpd2.service' >/dev/null || true fi diff --git a/debian/sync-httpd.service b/debian/sync-httpd.service @@ -1,31 +0,0 @@ -[Unit] -Description=Sync backup backend -After=postgresql.service network.target -Requires=sync-httpd.socket - -[Service] -User=sync-httpd -Type=simple -Restart=always -RestartMode=direct -RestartSec=1s -RestartPreventExitStatus=9 - -# Disable the service if more than 5 restarts are encountered within 5s. -# These are usually the systemd defaults, but can be overwritten, thus we set -# them here explicitly, as the exchange code assumes StartLimitInterval -# to be >=5s. -StartLimitBurst=5 -StartLimitInterval=5s - -RuntimeMaxSec=3600s -ExecStart=/usr/bin/sync-httpd -c /etc/sync/sync.conf -L INFO - -StandardOutput=journal -StandardError=journal -PrivateTmp=yes -PrivateDevices=yes -ProtectSystem=full - -[Install] -WantedBy=multi-user.target diff --git a/debian/sync-httpd.socket b/debian/sync-httpd.socket @@ -1,13 +0,0 @@ -[Unit] -Description=Sync Socket - -[Socket] -ListenStream=/run/sync/httpd/sync-http.sock -Accept=no -Service=sync-httpd.service -SocketUser=sync-httpd -SocketGroup=www-data -SocketMode=0660 - -[Install] -WantedBy=sockets.target diff --git a/debian/sync-httpd2.service b/debian/sync-httpd.sync-httpd2.service diff --git a/debian/sync-httpd2.socket b/debian/sync-httpd.sync-httpd2.socket