ReferenceEvery page

panel-installd(8)

panel installer

Name

panel-installd — panel installer

Synopsis

panel-installd [-v] [-f file]

Description

panel-installd installs and removes the Debian packages of the panel's modules, and upgrades the panel itself, for panel-brokerd(8). It exists because the broker is confined with Landlock, and whatever a confined process starts is confined with it: a package's maintainer scripts write anywhere, and an upgrade replaces the programs root runs. panel-installd runs as root and is not confined.

It is started by panel-masterd(8) only when the broker connects to its socket, and exits once a minute passes with nothing to do. It refuses to start any other way.

It does a fixed set of jobs and builds every command line itself: finishing what dpkg(1) left half-done; opening an uploaded bundle; running apt-get(8) to update, install, remove or purge named packages; staging, applying, confirming, discarding, rolling back and reverting an upgrade; setting up, updating and removing an app from the catalogue, and moving its folders or its own data to another disk, and removing the old copy a move kept; and formatting, mounting and ejecting a disk for the NAS module, making a folder on one ready to share, making a btrfs disk a mirror with a second, replacing a mirror's missing disk, taking a disk out of a mirror, and tending the disks: the monthly checks' timers, mounting a mirror from the disk left when the other is missing, and taking up again work a restart cut short. A package name must look like one, and nothing a caller sends becomes an option to apt. What the broker asked of a disk or an app is checked again here, against the machine as it is when the job runs: the disk the machine runs from is never formatted or mounted, a disk is not ejected while an app keeps anything on it or a mirror's copy runs, a disk of a mounted btrfs is never erased, a mirror is never mounted from the disk it was not last used from alone unless a person said to, and only an old copy on the list a move wrote is removed. An upgrade is not staged, applied or rolled back on a disk that cannot be written to: a file is made and removed first in each place it writes, and refused there, nothing is changed. Uploads are read from the fixed spool in upgrade_dir.

It answers only root, and only the process panel-masterd(8) says is the broker it started. Anything else is refused and logged.

The options are as follows:

-f file
Read configuration from file.
-v
Print the version and exit.

Environment

For tests only; each logs a warning when set. The environment rather than panel.conf(5), which the confined broker may write.

PANEL_TEST_APPS_UNIT_DIR, PANEL_TEST_APPS_DIR, PANEL_TEST_APPS_PODMAN, PANEL_TEST_APPS_SYSTEMCTL, PANEL_TEST_APPS_ACCOUNT
Where apps' units and data go, the podman and systemctl run, and an existing account every app runs as.
PANEL_TEST_NAS_ROOT, PANEL_TEST_NAS_UNITS, PANEL_TEST_NAS_MOUNTS, PANEL_TEST_NAS_SYSTEMCTL, PANEL_TEST_NAS_SHARE_ACCOUNT
A directory with the sys, proc, run and dev the disks are read from; where mount units are written; where disks are mounted; the systemctl run; and an existing account a shared folder is made for, rather than panel-nas.

Files

/var/run/panel/installer.sock
/var/cache/panel/modules
/usr/sbin/policy-rc.d
/etc/systemd/system/panel-*.service
/etc/systemd/system/srv-*.mount
/etc/systemd/system/panel-scrub@.service
/etc/systemd/system/panel-scrub@.timer
/run/udev/rules.d/65-panel-mirror-*.rules
/var/db/panel/nas/mirrors/*.json
/var/db/panel/nas/scrub/*.txt
/etc/systemd/system/wsdd2.service.d/panel.conf
/var/lib/panel/apps/old-copies.json
/var/lib/panel/apps/data-at.json

See also

panel.conf(5), panel-brokerd(8), panel-masterd(8)