From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:45491) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1flXFc-0000Dl-AN for guix-patches@gnu.org; Fri, 03 Aug 2018 06:24:06 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1flXFa-0004OU-CB for guix-patches@gnu.org; Fri, 03 Aug 2018 06:24:04 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:34522) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1flXFa-0004OH-4q for guix-patches@gnu.org; Fri, 03 Aug 2018 06:24:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1flXFZ-00033G-SI for guix-patches@gnu.org; Fri, 03 Aug 2018 06:24:01 -0400 Subject: [bug#32358] Add pcscd service Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:45389) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1flXEr-0000Au-QA for guix-patches@gnu.org; Fri, 03 Aug 2018 06:23:19 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1flXEq-0002f8-00 for guix-patches@gnu.org; Fri, 03 Aug 2018 06:23:17 -0400 Received: from [2001:19f0:5:274f:351:616f:fec3:2694] (port=54938 helo=vultr.systemreboot.net) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1flXEp-0002Sd-Dk for guix-patches@gnu.org; Fri, 03 Aug 2018 06:23:15 -0400 Received: from [192.168.2.1] (helo=steel) by systemreboot.net with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.91) (envelope-from ) id 1flXEi-0001pu-RW for guix-patches@gnu.org; Fri, 03 Aug 2018 15:53:10 +0530 From: Arun Isaac Date: Fri, 03 Aug 2018 15:53:02 +0530 Message-ID: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="=-=-=" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: 32358@debbugs.gnu.org --=-=-= Content-Type: text/plain This patchset adds pcscd service. It is required for gpg to detect and use security tokens such as the Nitrokey and the Gnuk. --=-=-= Content-Type: text/x-patch; charset=utf-8 Content-Disposition: inline; filename=0001-gnu-pcsc-lite-Link-to-USB-drivers-from-ccid.patch Content-Transfer-Encoding: quoted-printable >From 3fe4571e27afcecd5cfb72059ece22969fd6f72a Mon Sep 17 00:00:00 2001 From: Arun Isaac Date: Thu, 2 Aug 2018 05:24:37 +0530 Subject: [PATCH 1/2] gnu: pcsc-lite: Link to USB drivers from ccid. * gnu/packages/security-token.scm (pcsc-lite-bootstrap): New variable. (ccid)[inputs]: Remove pcsc-lite. [native-inputs]: Add pcsc-lite-bootstrap. (pcsc-lite)[inputs]: Add ccid. [arguments]: Set --enable-usbdropdir configure flag, linking to USB drivers from ccid. --- gnu/packages/security-token.scm | 27 +++++++++++++++++++++------ 1 file changed, 21 insertions(+), 6 deletions(-) diff --git a/gnu/packages/security-token.scm b/gnu/packages/security-token.= scm index 7fdcaaf1e..424f4626e 100644 --- a/gnu/packages/security-token.scm +++ b/gnu/packages/security-token.scm @@ -7,6 +7,7 @@ ;;; Copyright =C2=A9 2017, 2018 Tobias Geerinckx-Rice ;;; Copyright =C2=A9 2017 Ricardo Wurmus ;;; Copyright =C2=A9 2018 Chris Marusich +;;; Copyright =C2=A9 2018 Arun Isaac ;;; ;;; This file is part of GNU Guix. ;;; @@ -29,6 +30,7 @@ #:use-module (guix packages) #:use-module (guix download) #:use-module (guix git-download) + #:use-module (guix utils) #:use-module (guix build-system gnu) #:use-module (guix build-system glib-or-gtk) #:use-module (gnu packages autotools) @@ -75,11 +77,11 @@ (("/bin/echo") (which "echo"))) #t))))) (native-inputs - `(("perl" ,perl) + `(("pcsc-lite-bootstrap" ,pcsc-lite-bootstrap) ; only required for he= aders + ("perl" ,perl) ("pkg-config" ,pkg-config))) (inputs - `(("libusb" ,libusb) - ("pcsc-lite" ,pcsc-lite))) + `(("libusb" ,libusb))) (home-page "https://ccid.apdu.fr/") (synopsis "PC/SC driver for USB smart card devices") (description @@ -169,13 +171,16 @@ the low-level development kit for the Yubico YubiKey = authentication device.") "1jc9ws5ra6v3plwraqixin0w0wfxj64drahrbkyrrwzghqjjc9ss")))) (build-system gnu-build-system) (arguments - `(#:configure-flags '("--enable-usbdropdir=3D/var/lib/pcsc/drivers" - "--disable-libsystemd"))) + `(#:configure-flags + (list (string-append "--enable-usbdropdir=3D" + (assoc-ref %build-inputs "ccid") "/pcsc/driver= s") + "--disable-libsystemd"))) (native-inputs `(("perl" ,perl) ; for pod2man ("pkg-config" ,pkg-config))) (inputs - `(("libudev" ,eudev))) + `(("ccid" ,ccid) + ("libudev" ,eudev))) (home-page "https://pcsclite.apdu.fr/") (synopsis "Middleware to access a smart card using PC/SC") (description @@ -186,6 +191,16 @@ from a client application and provide access to the de= sired reader.") license:isc ; src/strlcat.c src/strlcp= y.c license:gpl3+)))) ; src/spy/* =20 +(define pcsc-lite-bootstrap + (package + (inherit pcsc-lite) + (name "pcsc-lite-bootstrap") + (inputs + `(("libudev" ,eudev))) + (arguments + (substitute-keyword-arguments (package-arguments pcsc-lite) + ((#:configure-flags _) '(list "--disable-libsystemd")))))) + (define-public ykclient (package (name "ykclient") --=20 2.18.0 --=-=-= Content-Type: text/x-patch; charset=utf-8 Content-Disposition: inline; filename=0002-gnu-services-Add-pcscd-service.patch Content-Transfer-Encoding: quoted-printable >From d565f247fc34680bf39c2618ea0ff05c229c2b54 Mon Sep 17 00:00:00 2001 From: Arun Isaac Date: Thu, 2 Aug 2018 05:32:56 +0530 Subject: [PATCH 2/2] gnu: services: Add pcscd service. * gnu/services/security-token.scm: New file. * gnu/local.mk (GNU_SYSTEM_MODULES): Add it. * doc/guix.texi (Miscellaneous Services): Document the service. --- doc/guix.texi | 28 +++++++++++++++ gnu/local.mk | 1 + gnu/services/security-token.scm | 63 +++++++++++++++++++++++++++++++++ 3 files changed, 92 insertions(+) create mode 100644 gnu/services/security-token.scm diff --git a/doc/guix.texi b/doc/guix.texi index 080b091b3..7e5212a66 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -20326,6 +20326,34 @@ An association list specifies kernel parameters an= d their values. @end table @end deftp =20 +@cindex pcscd +@subsubheading PC/SC Smart Card Daemon Service + +The @code{(gnu services security-token)} module provides the following ser= vice +to run @command{pcscd}, the PC/SC Smart Card Daemon. @command{pcscd} is t= he +daemon program for pcsc-lite and the MuscleCard framework. It is a resource +manager that coordinates communications with smart card readers, smart car= ds +and cryptographic tokens that are connected to the system. + +@defvr {Scheme Variable} pcscd-service-type +Service type for the @command{pcscd} service. Its value must be a +@code{pcscd-configuration} object. To run pcscd in the default +configuration, instantiate it as: + +@example +(service pcscd-service-type) +@end example +@end defvr + +@deftp {Data Type} pcscd-configuration +The data type representing the configuration of @command{pcscd}. + +@table @asis +@item @code{pcsc-lite} (default: @code{pcsc-lite}) +The pcsc-lite package that provides pcscd. +@end table +@end deftp + @cindex lirc @subsubheading Lirc Service =20 diff --git a/gnu/local.mk b/gnu/local.mk index d1f9a193b..c637f0954 100644 --- a/gnu/local.mk +++ b/gnu/local.mk @@ -485,6 +485,7 @@ GNU_SYSTEM_MODULES =3D \ %D%/services/monitoring.scm \ %D%/services/networking.scm \ %D%/services/nfs.scm \ + %D%/services/security-token.scm \ %D%/services/shepherd.scm \ %D%/services/sound.scm \ %D%/services/herd.scm \ diff --git a/gnu/services/security-token.scm b/gnu/services/security-token.= scm new file mode 100644 index 000000000..888c92fb1 --- /dev/null +++ b/gnu/services/security-token.scm @@ -0,0 +1,63 @@ +;;; GNU Guix --- Functional package management for GNU +;;; Copyright =C2=A9 2018 Arun Isaac +;;; +;;; This file is part of GNU Guix. +;;; +;;; GNU Guix is free software; you can redistribute it and/or modify it +;;; under the terms of the GNU General Public License as published by +;;; the Free Software Foundation; either version 3 of the License, or (at +;;; your option) any later version. +;;; +;;; GNU Guix is distributed in the hope that it will be useful, but +;;; WITHOUT ANY WARRANTY; without even the implied warranty of +;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +;;; GNU General Public License for more details. +;;; +;;; You should have received a copy of the GNU General Public License +;;; along with GNU Guix. If not, see . + +(define-module (gnu services security-token) + #:use-module (gnu services) + #:use-module (gnu services shepherd) + #:use-module (gnu packages admin) + #:use-module (gnu packages security-token) + #:use-module (gnu system shadow) + #:use-module (guix gexp) + #:use-module (guix modules) + #:use-module (guix records) + #:use-module (ice-9 match) + #:export (pcscd-configuration + pcscd-configuration? + pcscd-service-type)) + +;;; +;;; PC/SC Smart Card Daemon +;;; + +(define-record-type* + pcscd-configuration make-pcscd-configuration pcscd-configuration? + (pcsc-lite pcscd-configuration-package + (default pcsc-lite))) + +(define pcscd-shepherd-service + (match-lambda + (($ pcsc-lite) + (with-imported-modules (source-module-closure + '((gnu build shepherd))) + (shepherd-service + (documentation "PC/SC Smart Card Daemon") + (provision '(pcscd)) + (modules '((gnu build shepherd))) + (start #~(make-forkexec-constructor + (list #$(file-append pcsc-lite "/sbin/pcscd") "-f"))) + (stop #~(make-kill-destructor))))))) + +(define pcscd-service-type + (service-type + (name 'pcscd) + (description + "Run @command{pcscd}, the PC/SC smart card daemon.") + (extensions + (list (service-extension shepherd-root-service-type + (compose list pcscd-shepherd-service)))) + (default-value (pcscd-configuration)))) --=20 2.18.0 --=-=-=--