Subpackage minimal set of daemons into -minimal

For the users directly interacting with pluto through whack, such as
Submariner, pulling in the entire systemd dependencies upon installing
libreswan occupies unnecessary amount of disk space. This splits the
minimal portion of the package without systemd into a -minimal
subpackage.

Resolves: RHEL-5299
Signed-off-by: Daiki Ueno <dueno@redhat.com>
Co-authored-by: Stephen Kitt <skitt@redhat.com>
This commit is contained in:
Daiki Ueno 2025-11-28 14:31:09 +09:00
parent 53f869e6fc
commit 2351834a72

View File

@ -11,6 +11,7 @@
MANDIR=%{_mandir} \\\
PREFIX=%{_prefix} \\\
INITSYSTEM=systemd \\\
SBINDIR=%{_sbindir} \\\
SHELL_BINARY=%{_bindir}/sh \\\
USE_DNSSEC=true \\\
USE_LABELED_IPSEC=true \\\
@ -78,15 +79,12 @@ BuildRequires: ElectricFence
Requires: iproute >= 2.6.8
Requires: nss >= %{nss_version}
Requires: nss-softokn
Requires: nss-tools
Requires: unbound-libs >= %{unbound_version}
Requires: logrotate
# for pidof
Requires: procps-ng
Requires(post): bash
Requires(post): coreutils
Requires: %{name}-minimal%{?_isa} = %{version}-%{release}
Obsoletes: %{name} < 5.3-5
Requires(post): systemd
Requires(preun): systemd
Requires(postun): systemd
@ -107,6 +105,26 @@ Libreswan also supports IKEv2 (RFC7296) and Secure Labeling
Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04
%package minimal
Summary: Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec (minimal version)
Requires(post): bash
Requires(post): coreutils
Requires: nss-tools
Requires: unbound-libs >= %{unbound_version}
Obsoletes: %{name} < 5.3-5
%description minimal
Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is
the Internet Protocol Security and uses strong cryptography to provide
both authentication and encryption services. These services allow you
to build secure tunnels through untrusted networks. Everything passing
through the untrusted net is encrypted by the ipsec gateway machine and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network or VPN.
This package contains the minimal set of daemons and userland tools
for setting up Libreswan.
%prep
%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}'
%setup -q -n libreswan-%{version}%{?prever}
@ -189,6 +207,8 @@ certutil -N -d sql:$tmpdir --empty-password
%post
%systemd_post ipsec.service
%post minimal
%sysctl_apply 50-libreswan.conf
%preun
@ -200,6 +220,10 @@ certutil -N -d sql:$tmpdir --empty-password
%files
%doc CHANGES COPYING CREDITS README* LICENSE
%doc docs/*.* docs/examples
%attr(0644,root,root) %{_unitdir}/ipsec.service
%doc %{_mandir}/*/*
%files minimal
%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ipsec.conf
%attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ipsec.secrets
%attr(0700,root,root) %dir %{_sysconfdir}/ipsec.d
@ -210,12 +234,10 @@ certutil -N -d sql:$tmpdir --empty-password
%attr(0700,root,root) %dir %{_sharedstatedir}/ipsec
%attr(0700,root,root) %dir %{_sharedstatedir}/ipsec/nss
%attr(0644,root,root) %{_tmpfilesdir}/libreswan.conf
%attr(0644,root,root) %{_unitdir}/ipsec.service
%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/pam.d/pluto
%config(noreplace) %{_sysconfdir}/logrotate.d/libreswan
%{_sbindir}/ipsec
%{_libexecdir}/ipsec
%doc %{_mandir}/*/*
%changelog
%autochangelog