Move all writable data used by security-manager and appfw to /var
[AGL/meta-agl.git] / meta-app-framework / recipes-core / af-main / af-main_1.0.bb
1 require af-main_${PV}.inc 
2
3 # NOTE: using libcap-native and setcap in install doesn't work
4 # NOTE: there is no SYSTEMD_USER_SERVICE_...
5 # NOTE: maybe setting afm_name to agl-framework is cleaner but has implications
6 # NOTE: there is a hack of security for using groups and dbus (to be checked)
7 # NOTE: using ZIP programs creates directories with mode 777 (very bad)
8
9 inherit cmake pkgconfig useradd systemd
10 BBCLASSEXTEND = "native"
11
12 SECTION = "base"
13
14 DEPENDS = "openssl libxml2 xmlsec1 systemd libzip json-c security-manager libcap-native af-binder"
15 DEPENDS_class-native = "openssl libxml2 xmlsec1 libzip"
16
17 afm_name    = "afm"
18 afm_confdir = "${sysconfdir}/${afm_name}"
19 afm_datadir = "/var/lib/${afm_name}"
20 afm_init_datadir = "${datadir}/${afm_name}"
21 afb_binding_dir = "${libdir}/afb"
22
23 EXTRA_OECMAKE_class-native  = "\
24         -DUSE_LIBZIP=1 \
25         -DUSE_SIMULATION=1 \
26         -DUSE_SDK=1 \
27         -Dafm_name=${afm_name} \
28         -Dafm_confdir=${afm_confdir} \
29         -Dafm_datadir=${afm_datadir} \
30 "
31
32 EXTRA_OECMAKE = "\
33         -DUSE_LIBZIP=1 \
34         -DUSE_SIMULATION=0 \
35         -DUSE_SDK=0 \
36         -Dafm_name=${afm_name} \
37         -Dafm_confdir=${afm_confdir} \
38         -Dafm_datadir=${afm_datadir} \
39         -DUNITDIR_USER=${systemd_user_unitdir} \
40         -DUNITDIR_SYSTEM=${systemd_system_unitdir} \
41 "
42
43 USERADD_PACKAGES = "${PN}"
44 USERADD_PARAM_${PN} = "-g ${afm_name} -d ${afm_datadir} -r ${afm_name}"
45 GROUPADD_PARAM_${PN} = "-r ${afm_name}"
46
47 SYSTEMD_SERVICE_${PN} = "afm-system-daemon.service"
48 SYSTEMD_AUTO_ENABLE = "enable"
49
50 SRC_URI_append = "file://init-afm-dirs.sh \
51                   ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'file://init-afm-dirs.service', '', d)}"
52
53 FILES_${PN} += "\
54         ${bindir}/init-afm-dirs.sh \
55         ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${systemd_user_unitdir}/afm-user-daemon.service ${systemd_unitdir}/system/init-afm-dirs.service', '', d)} \
56 "
57
58 RDEPENDS_${PN}_append_smack = " smack-userspace"
59 DEPENDS_append_smack = " smack-userspace-native"
60
61 # short hacks here
62 SRC_URI += "\
63         file://Hack-to-allow-the-debugging.patch \
64         file://add-qt-wayland-shell-integration.patch \
65 "
66
67 do_install_append() {
68     install -d ${D}${bindir}
69     install -m 0755 ${WORKDIR}/init-afm-dirs.sh ${D}${bindir}
70     if ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'true', 'false', d)}; then
71         mkdir -p ${D}${sysconfdir}/systemd/user/default.target.wants
72         mkdir -p ${D}${sysconfdir}/systemd/system/default.target.wants
73         ln -sf ${systemd_user_unitdir}/afm-user-daemon.service ${D}${sysconfdir}/systemd/user/default.target.wants
74         install -p -D ${WORKDIR}/init-afm-dirs.service ${D}${systemd_unitdir}/system/init-afm-dirs.service
75         ln -sf ${systemd_unitdir}/system/init-afm-dirs.service ${D}${sysconfdir}/systemd/system/default.target.wants
76     fi
77 }
78
79 do_install_append_smack () {
80     install -d ${D}/${sysconfdir}/smack/accesses.d
81     cat > ${D}/${sysconfdir}/smack/accesses.d/default-access-domains-no-user <<EOF
82 System User::App-Shared rwxat
83 System User::Home       rwxat
84 EOF
85     chmod 0644 ${D}/${sysconfdir}/smack/accesses.d/default-access-domains-no-user
86     install -d ${D}/${sysconfdir}/skel/app-data
87     chsmack -a 'User::Home' -t -D ${D}/${sysconfdir}/skel
88     chsmack -a 'User::App-Shared' -D ${D}/${sysconfdir}/skel/app-data
89 }
90
91 pkg_postinst_${PN}() {
92     mkdir -p $D${afm_init_datadir}/applications $D${afm_init_datadir}/icons
93     setcap cap_mac_override,cap_dac_override=ep $D${bindir}/afm-system-daemon
94     setcap cap_mac_override,cap_mac_admin,cap_setgid=ep $D${bindir}/afm-user-daemon
95 }
96
97 pkg_postinst_${PN}_smack() {
98     mkdir -p $D${afm_init_datadir}/applications $D${afm_init_datadir}/icons
99     chown ${afm_name}:${afm_name} $D${afm_init_datadir} $D${afm_init_datadir}/applications $D${afm_init_datadir}/icons
100     chsmack -a 'System::Shared' -t $D${afm_init_datadir} $D${afm_init_datadir}/applications $D${afm_init_datadir}/icons
101     setcap cap_mac_override,cap_dac_override=ep $D${bindir}/afm-system-daemon
102     setcap cap_mac_override,cap_mac_admin,cap_setgid=ep $D${bindir}/afm-user-daemon
103 }
104
105 PACKAGES =+ "${PN}-binding ${PN}-binding-dbg"
106 FILES_${PN}-binding = " ${afb_binding_dir}/afm-main-binding.so "
107 FILES_${PN}-binding-dbg = " ${afb_binding_dir}/.debug/afm-main-binding.so "
108
109 PACKAGES =+ "${PN}-tools ${PN}-tools-dbg"
110 FILES_${PN}-tools = "${bindir}/wgtpkg-*"
111 FILES_${PN}-tools-dbg = "${bindir}/.debug/wgtpkg-*"
112