kuksa-val: split client certificates into a separate package
[AGL/meta-agl-demo.git] / recipes-connectivity / kuksa-val / kuksa-val_git.bb
1 SUMMARY = "KUKSA.val, the KUKSA Vehicle Abstraction Layer"
2 DESCRIPTION = "KUKSA.val provides a COVESA VSS data model describing data in a vehicle."
3 HOMEPAGE = "https://github.com/eclipse/kuksa.val"
4 BUGTRACKER = "https://github.com/eclipse/kuksa.val/issues"
5
6 LICENSE = "EPL-2.0 & BSL-1.0 & MIT"
7 LIC_FILES_CHKSUM = "file://LICENSE;md5=d9fc0efef5228704e7f5b37f27192723 \
8                     file://3rd-party-libs/jsoncons/LICENSE;md5=6ee7f7ed2001e4cde4679fdb8926f820 \
9                     file://3rd-party-libs/turtle/LICENSE_1_0.txt;md5=e4224ccaecb14d942c71d31bef20d78c \
10                     file://3rd-party-libs/jwt-cpp/LICENSE;md5=8325a5ce4414c65ffdda392e0d96a9ff"
11
12 DEPENDS = "boost openssl mosquitto protobuf-native grpc-native grpc"
13
14 require kuksa-val.inc
15
16 SRC_URI += "file://kuksa-val.service \
17             file://0001-Make-Boost-requirements-more-liberal.patch \
18             file://0002-Fix-gRPC-configuration-for-OE-cross-compiling.patch \
19             file://0003-Make-install-locations-configurable.patch \
20             file://0004-Disable-default-fetch-and-build-of-googletest.patch \
21 "
22
23 inherit cmake pkgconfig systemd useradd
24
25 SYSTEMD_SERVICE:${PN} = "kuksa-val.service"
26
27 USERADD_PACKAGES = "${PN}"
28 USERADDEXTENSION = "useradd-staticids"
29 GROUPADD_PARAM:${PN} = "-g 900 kuksa ;"
30 USERADD_PARAM:${PN} = "--system -g 900 -u 900 -o -d / --shell /bin/nologin kuksa ;"
31
32 # Configure file locations more along the lines of FHS instead of kuksa.val's
33 # default locations.
34 EXTRA_OECMAKE = " \
35     -DKUKSA_INSTALL_BINDIR=${bindir} \
36     -DKUKSA_INSTALL_CERTDIR=${sysconfdir}/kuksa-val \
37     -DKUKSA_INSTALL_DATADIR=${datadir}/kuksa-val \
38     -DKUKSA_INSTALL_CONFIGDIR=${sysconfdir}/kuksa-val \
39 "
40
41 do_install:append() {
42     # Lower the logging level used in the installed config.ini from the upstream
43     # default of "ALL", which spams the logs.
44     sed -i 's/^log-level = .*/log-level = WARNING/' ${D}/${sysconfdir}/kuksa-val/config.ini
45
46     if ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'true', 'false', d)}; then
47         install -d ${D}${systemd_system_unitdir}
48         install -m 0644 ${WORKDIR}/kuksa-val.service ${D}${systemd_system_unitdir}
49     fi
50
51     # Restrict server certificate access
52     # NOTE: The client certificates are left alone here for client
53     #       development convenience for now, but this will need to
54     #       be revisited.
55     chmod 640 ${D}${sysconfdir}/kuksa-val/Server.key
56     chgrp 900 ${D}${sysconfdir}/kuksa-val/Server.key
57     chmod 640 ${D}${sysconfdir}/kuksa-val/Server.pem
58     chgrp 900 ${D}${sysconfdir}/kuksa-val/Server.pem
59 }
60
61 # Put client certificates into their own package so we can avoid
62 # duplicates of them for e.g. cluster clients.  Longer term this
63 # will need to be revisited.
64 PACKAGE_BEFORE_PN += "${PN}-client-certificates"
65
66 FILES:${PN}-client-certificates = " \
67     ${sysconfdir}/kuksa-val/Client.key \
68     ${sysconfdir}/kuksa-val/Client.pem \
69     ${sysconfdir}/kuksa-val/CA.pem \
70 "
71
72 FILES:${PN} += "${systemd_system_unitdir} ${datadir}"
73
74 RDEPENDS:${PN} += "${PN}-client-certificates"