summaryrefslogtreecommitdiffstats
path: root/scripts/xds-server-start.sh
blob: 13a426874fd66bccbd5c65f6649b57b28c528636 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
#!/bin/bash

# Configurable variables
[ -z "$BINDIR" ] && BINDIR=/usr/local/bin
[ -z "$XDS_CONFFILE" ] && XDS_CONFFILE=$HOME/.xds/config.json
[ -z "$XDS_SHAREDIR" ] && XDS_SHAREDIR=$HOME/.xds/share
[ -z "$ST_CONFDIR" ] && ST_CONFDIR=$HOME/.xds/syncthing-config
[ -z "$XDS_WWWDIR" ] && XDS_WWWDIR=webapp/dist
[ -z "$LOGLEVEL" ] && LOGLEVEL=info
[ -z "$LOGDIR" ] && LOGDIR=/tmp/xds-server/logs
[ -z "$PORT_GUI" ] && PORT_GUI=8384
[ -z "$API_KEY" ] && API_KEY="1234abcezam"
[ -z "$UPDATE_XDS_TARBALL" ] && UPDATE_XDS_TARBALL=0

[[ -f $BINDIR/xds-server ]] || { echo "Cannot find xds-server in BINDIR !"; exit 1; }

# Create config.json file when needed
if [ ! -f "${XDS_CONFFILE}" ]; then
    mv ${XDS_CONFFILE} ${XDS_CONFFILE}.old
    [ ! -f "$XDS_WWWDIR/index.html" ] && XDS_WWWDIR=$BINDIR/www-xds-server
    [ ! -f "$XDS_WWWDIR/index.html" ] && XDS_WWWDIR=/var/www/xds-server
    [ ! -f "$XDS_WWWDIR/index.html" ] && { echo "Cannot determine XDS-server webapp directory."; exit 1; }
    cat <<EOF > ${XDS_CONFFILE}
{
    "webAppDir": "${XDS_WWWDIR}",
    "shareRootDir": "${XDS_SHAREDIR}",
    "logsDir": "${LOGDIR}",
    "sdkRootDir": "/xdt/sdk",
    "syncthing": {
        "binDir": "${BINDIR}",
        "home": "${ST_CONFDIR}",
        "gui-address": "http://localhost:${PORT_GUI}",
        "gui-apikey": "${API_KEY}"
    }
}
EOF
fi

echo "### Configuration in config.json: "
cat ${XDS_CONFFILE}
echo ""

mkdir -p ${LOGDIR}
LOG_XDS=${LOGDIR}/xds-server.log

# Download xds-agent tarball
if [ "${UPDATE_XDS_TARBALL}" = 1 ]; then
    SCRIPT_GET_XDS_TARBALL=$BINDIR/xds-utils/get-xds-agent.sh
    if [ ! -f ${SCRIPT_GET_XDS_TARBALL} ]; then
        SCRIPT_GET_XDS_TARBALL=$(dirname $0)/xds-utils/get-xds-agent.sh
    fi
    if [ -f ${SCRIPT_GET_XDS_TARBALL} ]; then
        TARBALLDIR=${XDS_WWWDIR}/assets/xds-agent-tarballs
        [ ! -d "$TARBALLDIR" ] && TARBALLDIR=$BINDIR/www-xds-server/assets/xds-agent-tarballs
        [ ! -d "$TARBALLDIR" ] && TARBALLDIR=$(grep webAppDir ~/.xds/config.json|cut -d '"' -f 4)/assets/xds-agent-tarballs
        if [ -d "$TARBALLDIR" ]; then
            DEST_DIR=$TARBALLDIR $SCRIPT_GET_XDS_TARBALL
        else
            echo "WARNING: cannot download / update xds-agent tarballs (DESTDIR error)"
        fi
    else
        echo "WARNING: cannot download / update xds-agent tarballs"
    fi
fi


echo "### Start XDS server"
echo "nohup $BINDIR/xds-server --config $XDS_CONFFILE -log $LOGLEVEL > $LOG_XDS 2>&1"
if [ "$1" != "-dryrun" ]; then
    nohup $BINDIR/xds-server --config $XDS_CONFFILE -log $LOGLEVEL > $LOG_XDS 2>&1 &
    pid_xds=$(jobs -p)
    echo "pid=${pid_xds}"
fi
lication will receive an identifier. That identifier must have the following feature: - it must be unique to identify the application and its revisions - it should be short enough to be used with efficiency by security components of the system - it can not be stolen by malicious applications that would like to spoof the application identity - it can be sold to other company The framework provide a facility to create an asymetric key that will serve all the above purposes (it currently doesn't). Using its favorite environment, the developer produces applications for the target. Depending on its constraints either economic, technical or human, the developer chooses the language and the environment for developing the applications. This step needs to test and to debug the application on a target or on a simulator of the target. In both cases, the code should be lively inspected and changed, as well as the permissions and the security aspects. The framework will provide facilities for debugging (it currently doesn't). #### Packaging applications Currently the framework expects widgets packaged as specified by [Packaged Web Apps](http://www.w3.org/TR/widgets). When the application is ready, the developer creates a package for it. The creation of the package is made of few steps: - isolate the strict necessarily files and structure it to be children of only one root directory - sign the application with the developer key - sign the application with its application key - pack the application using zip The framework will provide facilities to package applications. Parts of the job can be done with tools provided by afm-main: - ***wgtpkg-sign*** is used to add signatures at root of the package - ***wgtpkg-pack*** is used to create the package file (with wgt extension). Currently, the ***config.xml*** file must be edited by hand. See below [Writing the config.xml](#writing-config). #### Distributing applications Normally a store will distribute the application. It will be the normal process. The distributor adds a signature to the distributed application. The added signature can allow more or less permission to applications. For example, a critical application nested in the system should have high level permissions allowing it to do things that should normally not be done (changing system configuration for example). To allow such application, the distributor must sign it using its secret private key that will unlock the requested level of permissions. Currently, the framework allows to make these steps manually using ***unzip***, ***wgtpkg-sign*** and ***wgtpkg-pack*** utilities. Applications of the store will then be available for browsing and searching over HTTP/Internet. #### Installing applications The framework will provide an API for downloading and installing an application from stores (it currently doesn't). The current version of afm allows to install widgets from local files (either pre-installed or downloaded). To install a widget, you can use either the program ***wgtpkg-installer*** while being the framework user. TO BE CONTINUED #### Launching application TO BE CONTINUED ## Writing the config.xml <a id="writing-config"/> TO BE CONTINUED For permissions: ***urn:agl:perm:...*** For plugins: ***urn:agl:plugin:...*** ## Cryptography The widgets are currently signed and checked using the library [XMLSec](https://www.aleksey.com/xmlsec). The current state isn't providing our keys. Will be done soon. TO BE CONTINUED ## Extension to the packaging specifications The widgets are specified in that W3C recommendation: [Packaged Web Apps](http://www.w3.org/TR/widgets). This model was initially designed for HTML applications. But it is well suited for other kind of applications. It relies on this specification that is the master piece of interest and the most useful part: [XML Digital Signatures for Widgets](http://www.w3.org/TR/widgets-digsig). An other specification exist that isn't either mature nor suited for managing privileges: [Web App Manifest](http://www.w3.org/TR/appmanifest). However, it may become of actuallity in some future. The main idea is to use the file ***config.xml*** as a switch for several constants. The current specifications for ***config.xml*** are allowing to describe either HTML5, QML and native applications. Using *feature*, it is also possible to define uses of libraries. For more advanced uses like: - incremental updates - multiple application packages - system updates The file ***config.xml*** may: - either, contain a root different that *widget* - or, not exist, being replaced with something else. ## Comparison with Tizen framework This package is providing few less behaviour than the following Tizen packages: - platform/appfw/app-installers - platform/core/security/cert-svc - platform/core/appfw/ail - platform/core/appfw/aul-1 - platform/core/appfw/libslp-db-util - platform/core/appfw/pkgmgr-info - platform/core/appfw/slp-pkgmgr ## Links - [Packaged Web Apps](http://www.w3.org/TR/widgets) - [XML Digital Signatures for Widgets](http://www.w3.org/TR/widgets-digsig) - [libxml2](http://xmlsoft.org/html/index.html) - [OpenSSL](https://www.openssl.org) - [XMLSec](https://www.aleksey.com/xmlsec) - [JSON-c](https://github.com/json-c/json-c) - [D-Bus](http://www.freedesktop.org/wiki/Software/dbus) - [libzip](http://www.nih.at/libzip) - [CMake](https://cmake.org) - [Security-Manager](https://wiki.tizen.org/wiki/Security/Tizen_3.X_Security_Manager) - [Web App Manifest](http://www.w3.org/TR/appmanifest)