blob: fab27f1ee25902368eca66c57b6309288baccdd7 [file] [log] [blame]
Brad Bishop19323692019-04-05 15:28:33 -04001SUMMARY = "Dynamic firewall daemon with a D-Bus interface"
2HOMEPAGE = "https://firewalld.org/"
3BUGTRACKER = "https://github.com/firewalld/firewalld/issues"
Brad Bishop779d0ac2019-09-27 08:23:48 -04004UPSTREAM_CHECK_URI = "https://github.com/firewalld/firewalld/releases"
Brad Bishop19323692019-04-05 15:28:33 -04005LICENSE = "GPLv2+"
6LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
7
Brad Bishop26bdd442019-08-16 17:08:17 -04008SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/v${PV}/${BP}.tar.gz \
Brad Bishop26bdd442019-08-16 17:08:17 -04009 file://firewalld.init \
Brad Bishop19323692019-04-05 15:28:33 -040010"
Brad Bishop4fe7a132019-10-07 09:34:48 -040011SRC_URI[md5sum] = "32c16df3f6cc859d0df627baf5ee8401"
12SRC_URI[sha256sum] = "88bc63a011209ac046fb5d7bfc73ddcc0bc616ddf3013bbb6bf1a421cb497f76"
Brad Bishop19323692019-04-05 15:28:33 -040013
14# glib-2.0-native is needed for GSETTINGS_RULES autoconf macro from gsettings.m4
Brad Bishop4fe7a132019-10-07 09:34:48 -040015DEPENDS = "intltool-native glib-2.0-native libxslt-native docbook-xsl-stylesheets-native"
Brad Bishop19323692019-04-05 15:28:33 -040016
17inherit gettext autotools bash-completion python3native gsettings systemd update-rc.d
18
19PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'systemd', d)}"
Brad Bishop4fe7a132019-10-07 09:34:48 -040020PACKAGECONFIG[systemd] = "--with-systemd-unitdir=${systemd_system_unitdir},--disable-systemd"
21
22PACKAGES += "${PN}-zsh-completion"
Brad Bishop19323692019-04-05 15:28:33 -040023
24# iptables, ip6tables, ebtables, and ipset *should* be unnecessary
25# when the nftables backend is available, because nftables supersedes all of them.
26# However we still need iptables and ip6tables to be available otherwise any
27# application relying on "direct passthrough" rules (such as docker) will break.
28# /etc/sysconfig/firewalld is a Red Hat-ism, only referenced by
29# the Red Hat-specific init script which we aren't using, so we disable that.
30EXTRA_OECONF = "\
31 --with-nft=${sbindir}/nft \
32 --without-ipset \
33 --with-iptables=${sbindir}/iptables \
34 --with-iptables-restore=${sbindir}/iptables-restore \
35 --with-ip6tables=${sbindir}/ip6tables \
36 --with-ip6tables-restore=${sbindir}/ip6tables-restore \
37 --without-ebtables \
38 --without-ebtables-restore \
39 --disable-sysconfig \
Brad Bishop4fe7a132019-10-07 09:34:48 -040040 --with-xml-catalog=${STAGING_ETCDIR_NATIVE}/xml/catalog \
Brad Bishop19323692019-04-05 15:28:33 -040041"
42
43INITSCRIPT_NAME = "firewalld"
Brad Bishop4fe7a132019-10-07 09:34:48 -040044SYSTEMD_SERVICE_${PN} = "firewalld.service"
Brad Bishop19323692019-04-05 15:28:33 -040045
46do_install_append() {
47 if ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'true', 'false', d)}; then
48 :
49 else
50 # firewalld ships an init script but it contains Red Hat-isms, replace it with our own
51 rm -rf ${D}${sysconfdir}/rc.d/
52 install -d ${D}${sysconfdir}/init.d
53 install -m0755 ${WORKDIR}/firewalld.init ${D}${sysconfdir}/init.d/firewalld
54 fi
55
56 # We ran ./configure with PYTHON pointed at the binary inside $STAGING_BINDIR_NATIVE
57 # so now we need to fix up any references to point at the proper path in the image.
58 # This hack is also in distutils.bbclass, but firewalld doesn't use distutils/setuptools.
59 if [ ${PN} != "${BPN}-native" ]; then
60 sed -i -e s:${STAGING_BINDIR_NATIVE}/python3-native/python3:${bindir}/python3:g \
61 ${D}${bindir}/* ${D}${sbindir}/* ${D}${sysconfdir}/firewalld/*.xml
62 fi
63 sed -i -e s:${STAGING_BINDIR_NATIVE}:${bindir}:g \
64 ${D}${bindir}/* ${D}${sbindir}/* ${D}${sysconfdir}/firewalld/*.xml
65}
66
67FILES_${PN} += "\
68 ${PYTHON_SITEPACKAGES_DIR}/firewall \
Brad Bishop4fe7a132019-10-07 09:34:48 -040069 ${datadir}/dbus-1 \
Brad Bishop19323692019-04-05 15:28:33 -040070 ${datadir}/polkit-1 \
71 ${datadir}/metainfo \
72"
Brad Bishop4fe7a132019-10-07 09:34:48 -040073FILES_${PN}-zsh-completion = "${datadir}/zsh/site-functions"
Brad Bishop19323692019-04-05 15:28:33 -040074
75RDEPENDS_${PN} = "\
76 nftables \
77 iptables \
78 python3-core \
79 python3-io \
80 python3-fcntl \
81 python3-shell \
82 python3-syslog \
83 python3-xml \
84 python3-dbus \
85 python3-slip-dbus \
86 python3-decorator \
87 python3-pygobject \
88"