summaryrefslogtreecommitdiff
path: root/src/Propellor/Property/Sbuild.hs
diff options
context:
space:
mode:
authorSean Whitton2016-06-11 20:41:39 +0900
committerSean Whitton2016-06-12 13:19:14 +0900
commit83b19b06f27a36c5ae0af7982663f08ae721e073 (patch)
tree5408708dd40fa823352b590f9383efe8ea7d45fb /src/Propellor/Property/Sbuild.hs
parent942a65ab9f9847897abbd2c8515f349465c33843 (diff)
Sbuild.keypairInsecurelyGenerated
Diffstat (limited to 'src/Propellor/Property/Sbuild.hs')
-rw-r--r--src/Propellor/Property/Sbuild.hs17
1 files changed, 16 insertions, 1 deletions
diff --git a/src/Propellor/Property/Sbuild.hs b/src/Propellor/Property/Sbuild.hs
index 2647e69e..fbc0642a 100644
--- a/src/Propellor/Property/Sbuild.hs
+++ b/src/Propellor/Property/Sbuild.hs
@@ -66,6 +66,7 @@ module Propellor.Property.Sbuild (
-- blockNetwork,
installed,
keypairGenerated,
+ keypairInsecurelyGenerated,
shareAptCache,
usableBy,
) where
@@ -320,7 +321,21 @@ keypairGenerated = check (not <$> doesFileExist secKeyFile) $ go
go = tightenTargets $
cmdProperty "sbuild-update" ["--keygen"]
`assume` MadeChange
- secKeyFile = "/var/lib/sbuild/apt-keys/sbuild-key.sec"
+
+secKeyFile :: FilePath
+secKeyFile = "/var/lib/sbuild/apt-keys/sbuild-key.sec"
+
+-- | Generate the apt keys needed by sbuild using a low-quality source of
+-- randomness
+--
+-- Useful on throwaway build VMs.
+keypairInsecurelyGenerated :: Property DebianLike
+keypairInsecurelyGenerated = check (not <$> doesFileExist secKeyFile) $ go
+ `requires` Apt.installed ["rng-tools"]
+ where
+ go :: Property DebianLike
+ go = (cmdProperty "rngd" ["-r", "/dev/urandom"] `assume` MadeChange)
+ `before` keypairGenerated
-- another script from wiki.d.o/sbuild
ccachePrepared :: Property DebianLike