aboutsummaryrefslogtreecommitdiffstats
path: root/init-sh
diff options
context:
space:
mode:
authorYoann Vandoorselaere <yoann@mandriva.com>2000-03-22 17:39:12 +0000
committerYoann Vandoorselaere <yoann@mandriva.com>2000-03-22 17:39:12 +0000
commit80a65450bd92bd7d24c8e5087856053bbacfe9d9 (patch)
tree5e8858584f8e33a80645e9284b7616741d142fbf /init-sh
parentee50375647abff0b29c25673938835cbac434eb7 (diff)
downloadmsec-80a65450bd92bd7d24c8e5087856053bbacfe9d9.tar
msec-80a65450bd92bd7d24c8e5087856053bbacfe9d9.tar.gz
msec-80a65450bd92bd7d24c8e5087856053bbacfe9d9.tar.bz2
msec-80a65450bd92bd7d24c8e5087856053bbacfe9d9.tar.xz
msec-80a65450bd92bd7d24c8e5087856053bbacfe9d9.zip
*** empty log message ***
Diffstat (limited to 'init-sh')
-rwxr-xr-xinit-sh/custom.sh156
-rwxr-xr-xinit-sh/level5.sh18
-rw-r--r--init-sh/lib.sh6
3 files changed, 171 insertions, 9 deletions
diff --git a/init-sh/custom.sh b/init-sh/custom.sh
index 253d9d9..3018f75 100755
--- a/init-sh/custom.sh
+++ b/init-sh/custom.sh
@@ -1,10 +1,23 @@
#!/bin/bash
+
#
# Security level implementation...
# Writen by Vandoorselaere Yoann <yoann@mandrakesoft.com>
#
+###
+clear
+echo "This script allows you to customize the security on your system."
+echo "If you feel at all you don't know what you're doing abort now!!!"
+# can't use ctrl-c, we trap all signal.
+echo -n "continue [yes/no] : "
+read answer;
+
+if [[ ${answer} != yes ]]; then
+ exit 1
+fi
+
if [[ -f /usr/share/msec/lib.sh ]]; then
. /usr/share/msec/lib.sh
else
@@ -17,13 +30,7 @@ clear
WRITE_CRON="false"
###
-echo "Do you want all system events to be logged on tty12 ?"
-WaitAnswer; clear
-if [[ ${answer} == yes ]]; then
- AddRules "*.* /dev/tty12" /etc/syslog.conf
-fi
-###
echo "Do you want to only allow ctrl-alt-del if root is logged locally ?"
echo "( or if an user present in /etc/shutdown.allow is logged locally )"
WaitAnswer; clear
@@ -186,7 +193,8 @@ LiloUpdate;
/sbin/lilo >& /dev/null
###
-echo "Do you want to disable your running server ( except important one )"
+clear
+echo "Do you want to disable your running server ( except those specified in /etc/security/msec/server.4 )"
echo "This is only valuable for server installed with rpm."
WaitAnswer; clear
if [[ ${answer} == yes ]]; then
@@ -229,7 +237,7 @@ echo "paranoid ( 077 ) = user = rwx, group = , other ="
answer="nothing"
while [[ "${answer}" != "easy" && "${answer}" != "normal" && "${answer}" != "restricted" && "${answer}" != "paranoid" ]]; do
echo -n "easy/normal/restricted/paranoid : "
- read answer
+ read answer
done
case "${answer}" in
"easy")
@@ -247,6 +255,129 @@ case "${answer}" in
esac
###
+
+echo "Do you want easy, normal, restricted, or paranoid permission ?"
+answer="nothing"
+while [[ "${answer}" != "easy" && "${answer}" != "normal" && "${answer}" != "restricted" && "${answer}" != "paranoid" ]]; do
+ echo -n "easy/normal/restricted/paranoid : "
+ read answer
+done
+case "${answer}" in
+ "easy")
+ /usr/share/msec/file_perm.sh /etc/security/msec/perm.2
+ ;;
+ "normal")
+ /usr/share/msec/file_perm.sh /etc/security/msec/perm.3
+ ;;
+ "restricted")
+ /usr/share/msec/file_perm.sh /etc/security/msec/perm.4
+ ;;
+ "paranoid")
+ /usr/share/msec/file_perm.sh /etc/security/msec/perm.5
+ ;;
+esac
+
+#Logging
+clear
+echo "Would you like set to up additional logging ?"
+echo "Logging will still go to its respected places in /var/log as well."
+WaitAnswer; clear
+if [[ ${answer} == yes ]]; then
+ echo "Would you like all system events to be logged on a specific tty ?"
+ echo "please answer by \"no\" or the tty number."
+ echo -n "no/ttynumber :"
+ read answer
+ if [[ ${answer} != no && ${anwer} != yes ]]; then
+ AddRules "*.* /dev/tty${answer}" /etc/syslog.conf
+ fi
+
+ echo
+ echo "Would you like for auth and warnings to a specific tty ?"
+ echo "please answer by \"no\" or the tty number."
+ echo -n "no/ttynumber :"
+ read answer
+ if [[ ${answer} != no && ${anwer} != yes ]]; then
+ AddRules "authpriv.* /dev/tty${answer}" /etc/syslog.conf
+ fi
+
+ echo
+ echo "Would you like kernel logging to go on a specific tty ?"
+ echo "please answer by \"no\" or the tty number."
+ echo -n "no/ttynumber :"
+ read answer
+ if [[ ${answer} != no && ${anwer} != yes ]]; then
+ AddRules "kern.* /dev/tty${answer}" /etc/syslog.conf
+ fi
+
+ echo
+ echo "Would you like mail logging to a specific tty ?"
+ echo "This is only useful if you're running a mail server."
+ echo "please answer by \"no\" or the tty number."
+ echo -n "no/ttynumber :"
+ read answer
+ if [[ ${answer} != no && ${anwer} != yes ]]; then
+ AddRules "mail.* /dev/tty${answer}" /etc/syslog.conf
+ fi
+
+ /etc/rc.d/init.d/syslog restart >& /dev/null
+fi
+
+clear
+
+###
+clear
+echo "We can setup your system to log who does what commands and when..."
+echo "May we set up proccess accounting ?"
+echo "The log file (/var/log/security/psacct.log) will get filled up VERY quickly..."
+echo "You need the psacct package."
+WaitAnswer;
+
+if [[ ${answer} == yes ]]; then
+ AddRules "touch /var/log/security/pacct.log" /etc/rc.d/rc.local
+ AddRules "/sbin/accton /var/log/security/pacct.log" /etc/rc.d/rc.local
+ AddRules "/var/log/security/pacct.log {" /etc/logrotate.conf
+ AddRules " postrotate" /etc/logrotate.conf
+ AddRules " /sbin/accton /var/log/security/pacct.log" /etc/logrotate.conf
+ AddRules " }" /etc/logrotate.conf
+ touch /var/log/security/pacct.log
+ chown root.root /var/log/security/pacct.log
+ chmod 600 /var/log/security/pacct.log
+ /sbin/accton /var/log/security/pacct.log
+fi
+
+### Pam
+clear
+
+dfsize=40000
+echo "We help prevent certain types of DoS attacks through the use of PAM(Pluggable Authentication Modules.)"
+echo "By setting a limit on how big user files may get and how many processes a user may run."
+
+echo "Would you like to set up some PAM configuration ?"
+WaitAnswer; clear
+if [[ ${answer} == yes ]]; then
+ AddRules "# Limit user processes" /etc/security/limits.conf
+ AddRules "* soft nproc 100" /etc/security/limits.conf
+ AddRules "* hard nproc 150" /etc/security/limits.conf
+
+ echo "Would you like to set a maximum file size a user is allowed ?"
+ WaitAnswer; clear
+ if [[ ${answer} == yes ]]; then
+ echo "What shall be the maximum file size(default is $(dfsize))"
+ echo -n "Size : "
+ read fsize
+ if [[ -z ${fsize} ]]; then
+ AddRules "# limits size of any one of users' files" /etc/security/limits.conf
+ AddRules "* hard $dfsize" /etc/security/limits.conf
+ else
+ AddRules "# limits size of any one of users' files" /etc/security/limits.conf
+ AddRules "* hard $fsize" /etc/security/limits.conf
+ fi
+ fi
+fi
+
+
+
+###
echo "Do you want a "." in your PATH variable ?"
echo "This permit you to not use ./progname & to just type progname"
echo "However this is a *high* security risk."
@@ -273,3 +404,12 @@ AddRules "export PATH SECURE_LEVEL" /etc/profile
+
+
+
+
+
+
+
+
+
diff --git a/init-sh/level5.sh b/init-sh/level5.sh
index 0e458b7..0d9b58c 100755
--- a/init-sh/level5.sh
+++ b/init-sh/level5.sh
@@ -70,7 +70,23 @@ AddRules "0 0 * * * root /usr/share/msec/security.sh" /etc/crontab
###################################################
-# Wanna a password ?
+# setup BSD accounting.
+
+echo "Setting up BSD process accounting..."
+if [[ -f /sbin/accton ]]; then
+ AddRules "touch /var/log/security/pacct.log" /etc/rc.d/rc.local
+ AddRules "/sbin/accton /var/log/security/pacct.log" /etc/rc.d/rc.local
+ AddRules "/var/log/security/pacct.log {" /etc/logrotate.conf
+ AddRules " postrotate" /etc/logrotate.conf
+ AddRules " /sbin/accton /var/log/security/pacct.log" /etc/logrotate.conf
+ AddRules " }" /etc/logrotate.conf
+ touch /var/log/security/pacct.log
+ chown root.root /var/log/security/pacct.log
+ chmod 600 /var/log/security/pacct.log
+ /sbin/accton /var/log/security/pacct.log
+fi
+
+# Wanna password ?
LiloUpdate;
echo -n "Running lilo to record new config : "
diff --git a/init-sh/lib.sh b/init-sh/lib.sh
index 7f55c7c..7b395a7 100644
--- a/init-sh/lib.sh
+++ b/init-sh/lib.sh
@@ -181,6 +181,8 @@ CleanRules /etc/security/msec/security.conf
CommentUserRules /etc/security/msec/security.conf
CleanRules /etc/profile
CleanRules /etc/lilo.conf
+CleanRules /etc/logrotate.conf
+CleanRules /etc/rc.d/rc.local
CleanRules /etc/rc.d/rc.firewall
CleanRules /etc/crontab
CleanRules /etc/X11/xdm/Xsession
@@ -192,9 +194,13 @@ echo "Setting spoofing protection : "
AddRules "echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter" /etc/rc.d/rc.firewall
# default group which must exist on the system
+# groupadd already check for their existance...
groupadd nogroup >& /dev/null
groupadd audio >& /dev/null
groupadd xgrp >& /dev/null
+groupadd ntools >& /dev/null
+groupadd ctools >& /dev/null
+
usermod -G xgrp xfs
/usr/share/msec/grpuser.sh --clean
477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118
package install::pkgs; # $Id: pkgs.pm 267288 2010-04-02 14:49:40Z pterjan $

use strict;
use feature 'state';

BEGIN {
    # needed before "use URPM"
    mkdir '/etc/rpm';
    symlink "/tmp/stage2/etc/rpm/$_", "/etc/rpm/$_" foreach 'macros.d';
}

use URPM;
use URPM::Resolve;
use URPM::Signature;
use urpm;
use urpm::args;
use urpm::main_loop;
use urpm::select;
use common;
use install::any;
use install::media qw(getFile_ getAndSaveFile_ packageMedium);
use run_program;
use detect_devices;
use log;
use fs;
use fs::any;
use fs::loopback;
use c;

#- lower bound on the left ( aka 90 means [90-100[ )
our %compssListDesc = (
   5 => N_("must have"),
   4 => N_("important"),
   3 => N_("very nice"),
   2 => N_("nice"),
   1 => N_("maybe"),
);

#- TODO BEFORE TODO
#- size and correction size functions for packages.
my $B = 1.20873;
my $C = 4.98663; #- does not take hdlist's into account as getAvailableSpace will do it.
sub correctSize { $B * $_[0] + $C }
sub invCorrectSize { ($_[0] - $C) / $B }

sub selectedSize {
    my ($packages) = @_;
    my $size = 0;
    my %skip;
    #- take care of packages selected...
    foreach (@{$packages->{depslist}}) {
	if ($_->flag_selected) {
	    $size += $_->size;
	    #- if a package is obsoleted with the same name it should
	    #- have been selected, so a selected new package obsoletes
	    #- all the old package.
	    exists $skip{$_->name} and next; $skip{$_->name} = undef;
	    $size -= $packages->{sizes}{$_->name};
	}
    }
    #- but remove size of package being obsoleted or removed.
    foreach (keys %{$packages->{state}{rejected}}) {
	my ($name) = /(.*)-[^\-]*-[^\-]*$/ or next;
	exists $skip{$name} and next; $skip{$name} = undef;
	$size -= $packages->{sizes}{$name};
    }
    $size;
}

sub size2time {
    my ($x, $max) = @_;
    my $A = 7e-07;
    my $limit = min($max * 3 / 4, 9e8);
    if ($x < $limit) {
	$A * $x;
    } else { 
	$x -= $limit;
	my $B = 6e-16;
	my $C = 15e-07;
	$B * $x ** 2 + $C * $x + $A * $limit;
    }
}

# Based on Rpmdrake::pkg::extract_header():
sub get_pkg_info {
    my ($p) = @_;

    my $urpm = $::o->{packages};
    my $name = $p->fullname;

    my $medium = URPM::pkg2media($urpm->{media}, $p);
    my ($local_source, %xml_info_pkgs, $description);
    my $dir = urpm::file_from_local_url($medium->{url});
    $local_source = "$dir/" . $p->filename if $dir;

    if (-s $local_source) {
	log::l("getting information from $dir...");
	$p->update_header($local_source) and $description = $p->description;
	log::l("Warning, could not extract header for $name from $medium!") if !$description;
    }
    if (!$description) {
	my $_w = $::o->wait_message(undef, N("Getting package information from XML meta-data..."));
	if (my $xml_info_file = eval { urpm::media::any_xml_info($urpm, $medium, 'info', undef, urpm::download::sync_logger) }) {
	    require urpm::xml_info;
	    require urpm::xml_info_pkg;
	    log::l("getting information from $xml_info_file");
	    my %nodes = eval { urpm::xml_info::get_nodes('info', $xml_info_file, [ $name ]) };
	    goto header_non_available if $@;
	    put_in_hash($xml_info_pkgs{$name} ||= {}, $nodes{$name});
	} else {
	    $urpm->{info}(N("No xml info for medium \"%s\", only partial result for package %s", $medium->{name}, $name));
	}
    }

    if (!$description && $xml_info_pkgs{$name}) {
	$description = $xml_info_pkgs{$name}{description};
    }
  header_non_available:
    $description || N("No description");
}

sub packagesProviding {
    my ($packages, $name) = @_;
    grep { $_->is_arch_compat } URPM::packages_providing($packages, $name);
}

#- search package with given name and compatible with current architecture.
#- take the best one found (most up-to-date).
sub packageByName {
    my ($packages, $name) = @_;

    my @l =  grep { $_->name eq $name } packagesProviding($packages, $name);

    my $best;
    foreach (@l) {
	if ($best && $best != $_) {
	    if ($best->fullname eq $_->fullname) {
		$best = $_ if $_->flag_installed;
	    } else {
	        $_->compare_pkg($best) > 0 and $best = $_;
            }
	} else {
	    $best = $_;
	}
    }
    $best or log::l("unknown package `$name'");
    $best;
}

sub _is_kernelServer_needed() {
    # forbid selecting kernel-server if not having PAE since PAE support is mandatory for kernel-server:
    return if !detect_devices::has_cpu_flag('pae');
    arch() =~ /i.86/ && detect_devices::dmi_detect_memory() > 3.8 * 1024 || detect_devices::isServer();
}

sub _bestKernel_extensions {
    my ($o_match_all_hardware) = @_;

    $::o->{kernel_extension} ? $::o->{kernel_extension} :
    $o_match_all_hardware ? (arch() =~ /i.86/ ? '-desktop586' : '-desktop') :
      detect_devices::is_i586() ? '-desktop586' :
      _is_kernelServer_needed() ? '-server' :
      '-desktop';
}

sub bestKernelPackage {
    my ($packages, $o_match_all_hardware) = @_;

    my @preferred_exts = _bestKernel_extensions($o_match_all_hardware);
    my @kernels = grep { $_ } map { packageByName($packages, "kernel$_-latest") } @preferred_exts;

    if (!@kernels) {
        #- fallback on most generic kernel if the suitable one is not available
        #- (only kernel-desktop586-latest is available on Dual ISO for i586)
        my @fallback_exts = _bestKernel_extensions('force');
        @kernels = grep { $_ } map { packageByName($packages, "kernel$_-latest") } @fallback_exts;
    }

    log::l("bestKernelPackage (" . join(':', @preferred_exts) . "): " . join(' ', map { $_->name } @kernels) . (@kernels > 1 ? ' (choosing the first)' : ''));

    $kernels[0];
}

sub packagesToInstall {
    my ($packages) = @_;
    my @packages;
    foreach (@{$packages->{media}}) {
	!$_->{ignore} or next;
	log::l("examining packagesToInstall of medium $_->{name}");
	push @packages, grep { $_->flag_selected } install::media::packagesOfMedium($packages, $_);
    }
    log::l("found " . scalar(@packages) . " packages to install: " . formatList(5, map { $_->fullname } @packages));
    @packages;
}

sub _packageRequest {
    my ($packages, $pkg) = @_;

    #- check if the same or better version is installed,
    #- do not select in such case.
    $pkg && ($pkg->flag_upgrade || !$pkg->flag_installed) or return;

    #- check for medium selection, if the medium has not been
    #- selected, the package cannot be selected.
    my $medium = packageMedium($packages, $pkg);
    $medium && !$medium->{ignore} or return;

    +{ $pkg->id => 1 };
}

sub packageCallbackChoices {
    my ($urpm, $_db, $_state, $choices, $virtual_pkg_name, $prefered) = @_;
  
    if ($prefered && @$prefered) {
	@$prefered;
    } elsif (my @l = _packageCallbackChoices_($urpm, $choices, $virtual_pkg_name)) {
	@l;
    } else {
	log::l("packageCallbackChoices: default choice ('" . $choices->[0]->name . "') from " . join(",", map { $_->name } @$choices) . " for $virtual_pkg_name");
	$choices->[0];
    }
}

sub _packageCallbackChoices_ {
    my ($urpm, $choices, $virtual_pkg_name) = @_;

    my ($prefer, $_other) = urpm::select::get_preferred($urpm, $choices, $::o->{preferred_packages});
    if (@$prefer) {
	@$prefer;
    } elsif ($virtual_pkg_name eq 'kernel') {
	my $re = join('|', map { "kernel\Q$_-2" } _bestKernel_extensions());
	my @l = grep { $_->name =~ $re } @$choices;
	log::l("packageCallbackChoices: kernel chosen ", join(",", map { $_->name } @l), " in ", join(",", map { $_->name } @$choices));
	@l;
    } elsif ($choices->[0]->name =~ /^kernel-(.*source-|.*-devel-)/) {
	my @l = grep {
	    if ($_->name =~ /^kernel-.*source-stripped-(.*)/) {
		my $version = quotemeta($1);
		find {
		    $_->name =~ /-$version$/ && ($_->flag_installed || $_->flag_selected);
		} $urpm->packages_providing('kernel');
	    } elsif ($_->name =~ /(kernel-.*)-devel-(.*)/) {
		my $kernel = "$1-$2";
		my $p = packageByName($urpm, $kernel);
		$p && ($p->flag_installed || $p->flag_selected);
	    } elsif ($_->name =~ /^kernel-.*source-/) {
		#- hopefully we don't have a media with kernel-source but not kernel-source-stripped nor kernel-.*-devel
		0;
	    } else {
		log::l("unknown kernel-source package " . $_->fullname);
		0;
	    }
	} @$choices;

	log::l("packageCallbackChoices: kernel source chosen ", join(",", map { $_->name } @l), " in ", join(",", map { $_->name } @$choices));

	@l;
    } else {
	();
    }
}

sub skip_packages {
    my ($packages, $skipped_packages) = @_;
    $packages->compute_flags($skipped_packages, skip => 1);
}

sub select_by_package_names {
    my ($packages, $names, $b_base) = @_;

    my @l;
    foreach (@$names) {
	my $p = packageByName($packages, $_) or next;
	push @l, selectPackage($packages, $p, $b_base);
    }
    @l;
}

sub select_by_package_names_or_die {
    my ($packages, $names, $b_base) = @_;

    foreach (@$names) {
	my $p = packageByName($packages, $_) or die "package $_ not found";
	!$p->flag_installed && !$p->flag_selected or next;
	my ($_pkgs, $error) = _selectPackage_with_error($packages, $p, $b_base);
	$error and die N("Some packages requested by %s cannot be installed:\n%s", $_, $error);
    }
}

my @suggested_package_ids;
sub _resolve_requested_and_check {
    my ($packages, $state, $requested) = @_;

    my @l = $packages->resolve_requested($packages->{rpmdb}, $state, $requested,
					 callback_choices => \&packageCallbackChoices, no_suggests => $::o->{no_suggests});

    #- keep track of suggested packages so that theys could be unselected if the "no suggests" option is choosen later:
    if (!is_empty_hash_ref($state->{selected})) {
        my @new_ids = map { $packages->{depslist}[$_]->id } grep { $state->{selected}{$_}{suggested} } keys $state->{selected};
        @suggested_package_ids = uniq(@suggested_package_ids, @new_ids);
    }

    my $error;
    if (find { !exists $state->{selected}{$_} } keys %$requested) {
	my @rejected = urpm::select::unselected_packages($state);
	$error = urpm::select::translate_why_unselected($packages, $state, @rejected);
	log::l("ERROR: selection failed: $error");
    }

    \@l, $error;
}

sub selectPackage {
    my ($packages, $pkg, $b_base) = @_;
    my ($pkgs, $_error) = _selectPackage_with_error($packages, $pkg, $b_base);
    @$pkgs;
}

sub _selectPackage_with_error {
    my ($packages, $pkg, $b_base) = @_;

    my $state = $packages->{state} ||= {};

    $packages->{rpmdb} ||= rpmDbOpen();

    my ($pkgs, $error) = _resolve_requested_and_check($packages, $state, _packageRequest($packages, $pkg) || {});

    if ($b_base) {
	$_->set_flag_base foreach @$pkgs;
    }
    ($pkgs, $error);
}

sub unselectPackage {
    my ($packages, $pkg) = @_;

    #- base packages are not unselectable,
    #- and already unselected package are no more unselectable.
    $pkg->flag_base and return;
    $pkg->flag_selected or return;

    my $state = $packages->{state} ||= {};
    log::l("removing selection on package " . $pkg->fullname);
    my @l = $packages->disable_selected($packages->{rpmdb}, $state, $pkg);
    log::l("   removed selection on package " . $pkg->fullname . "gives " . join(',', map { scalar $_->fullname } @l));
}

sub unselectAllPackages {
    my ($packages) = @_;
    my %keep_selected;
    log::l("unselecting all packages...");
    foreach (@{$packages->{depslist}}) {
	my $to_select = $_->flag_base || $_->flag_installed && $_->flag_selected;
	# unselect suggested packages if minimal install:
	if ($::o->{no_suggests} && member($_->id, @suggested_package_ids)) {
	    log::l("unselecting suggested package " . $_->name);
	    undef $to_select;
	}
	if ($to_select) {
	    #- keep track of packages that should be kept selected.
	    $keep_selected{$_->id} = $_;
	} else {
	    #- deselect all packages except base or packages that need to be upgraded.
	    $_->set_flag_required(0);
	    $_->set_flag_requested(0);
	}
    }
    #- clean state, in order to start with a brand new set...
    $packages->{state} = {};
    _resolve_requested_and_check($packages, $packages->{state}, \%keep_selected);
}


my (@errors, $push_errors);
sub start_pushing_error() {
    $push_errors = 1;
    undef @errors;
}

sub popup_errors() {
    if (@errors) {
	$::o->ask_warn(undef, N("An error occurred:") . "\n\n" . join("\n", @errors));
    }
    undef $push_errors;
}

sub empty_packages {
    my ($o_keep_unrequested_dependencies) = @_;
    my $packages = urpm->new;
    urpm::get_global_options($packages);
    urpm::set_files($packages, '/mnt');

    #- add additional fields used by DrakX.
    $packages->{media} = [];

    urpm::args::set_debug($packages) if $::o->{debug_urpmi};
    $packages->{log} = \&log::l;
    $packages->{info} = \&log::l;
    $packages->{fatal} = sub {
        log::l("urpmi error: $_[1] ($_[0])\n" . common::backtrace());
        $::o->ask_warn(undef, N("A fatal error occurred: %s.", "$_[1] ($_[0])"));
    };
    $packages->{error} = sub {
        log::l("urpmi error: $_[0]");
	if ($push_errors) {
	    push @errors, @_;
	    return;
	}
        $::o->ask_warn(undef, N("An error occurred:") . "\n\n" . $_[0]);
    };
    $packages->{root} = $::prefix;
    $packages->{prefer_vendor_list} = '/etc/urpmi/prefer.vendor.list';
    $packages->{keep_unrequested_dependencies} =
      defined($o_keep_unrequested_dependencies) ? $o_keep_unrequested_dependencies : 1;
    $urpm::args::options{force_transactions} = 1;
    $urpm::args::options{justdb} = $::o->{justdb};
    urpm::set_tune_rpm($packages, $::o->{'tune-rpm'}) if $::o->{'tune-rpm'};
    $::force = 1;
    $packages->{options}{ignoresize} = 1;
    # prevent priority upgrade (redundant for now as $urpm->{root} implies disabling it:
    $packages->{options}{'priority-upgrade'} = undef;
    # log $trans->add() faillure; FIXME: should we override *urpm::msg::sys_log?
    $packages->{debug} = $packages->{debug_URPM} = \&log::l;
    $packages->{options}{'curl-options'} = $::o->{curl_options} if $::o->{curl_options};

    $packages;
}

sub readCompssUsers {
    my ($file) = @_;

    my $f = common::open_file($file) or log::l("cannot find $file: $!"), return;
    my ($compssUsers, $gtk_display_compssUsers) = eval join('', <$f>);
    if ($@) {
	log::l("ERROR: bad $file: $@");
    } else {
	log::l("compssUsers.pl got: ", join(', ', map { qq("$_->{path}|$_->{label}") } @$compssUsers));
    }
    ($compssUsers, $gtk_display_compssUsers);
}

sub saveCompssUsers {
    my ($packages, $compssUsers) = @_;
    my $flat;
    foreach (@$compssUsers) {
	my %fl = map { ("CAT_$_" => 1) } @{$_->{flags}};
	$flat .= "$_->{label} [icon=xxx] [path=$_->{path}]\n";
	foreach my $p (@{$packages->{depslist}}) {
	    my @flags = $p->rflags;
	    if ($p->rate && any { any { !/^!/ && $fl{$_} } split('\|\|') } @flags) {
		$flat .= sprintf "\t%d %s\n", $p->rate, $p->name;
	    }
	}
    }
    my $urpmidir = install::media::urpmidir();
    output "$urpmidir/compssUsers.flat", $flat;
}

sub setSelectedFromCompssList {
    my ($packages, $rpmsrate_flags_chosen, $min_level, $max_size) = @_;
    $rpmsrate_flags_chosen->{TRUE} = 1; #- ensure TRUE is set
    my $nb = selectedSize($packages);

    my %pkgs;
    foreach my $p (@{$packages->{depslist}}) {
	my @flags = $p->rflags;
	next if
	  !$p->rate || $p->rate < $min_level || 
	  any { !any { /^!(.*)/ ? !$rpmsrate_flags_chosen->{$1} : $rpmsrate_flags_chosen->{$_} } split('\|\|') } @flags;	
	$pkgs{$p->rate} ||= {};
	$pkgs{$p->rate}{$p->id} = 1 if _packageRequest($packages, $p);
    }
    my %pkgswanted;
    foreach my $level (sort { $b <=> $a } keys %pkgs) {
	#- determine the packages that will be selected
	#- the packages are not selected.
	my $state = $packages->{state} ||= {};
	foreach my $p (keys %{$pkgs{$level}}) {
	    $pkgswanted{$p} = 1;
	}
	my ($l, $_error) = _resolve_requested_and_check($packages, $state, \%pkgswanted);
    
	#- this enable an incremental total size.
	my $old_nb = $nb;
	foreach (@$l) {
	    $nb += $_->size;
	}
	if ($max_size && $nb > $max_size) {
	    log::l("disabling selected packages because too big for level $level: $nb > $max_size");
	    $nb = $old_nb;
	    $min_level = $level;
	    $packages->disable_selected($packages->{rpmdb}, $state, @$l);
	    last;
	}
    }
    my @flags = map_each { if_($::b, $::a) } %$rpmsrate_flags_chosen;
    log::l("setSelectedFromCompssList: reached size ", int($nb / 1024/1024), "MB, up to indice $min_level (less than ", formatXiB($max_size), ") for flags ", join(' ', sort @flags));
    log::l("setSelectedFromCompssList: ", join(" ", sort map { $_->name } grep { $_->flag_selected } @{$packages->{depslist}}));
    $min_level;
}

#- useful to know the size it would take for a given min_level/max_size
#- just save the selected packages, call setSelectedFromCompssList, and restore the selected packages
sub saveSelected {
    my ($packages) = @_;
    my $state = delete $packages->{state};
    my @l = @{$packages->{depslist} || []};
    my @flags = map { ($_->flag_requested && 1) + ($_->flag_required && 2) + ($_->flag_upgrade && 4) } @l;
    [ $packages, $state, \@l, \@flags ];
}
sub restoreSelected {
    my ($packages, $state, $l, $flags) = @{$_[0]};
    $packages->{state} = $state;
    mapn { my ($pkg, $flag) = @_;
	   $pkg->set_flag_requested($flag & 1);
	   $pkg->set_flag_required($flag & 2);
	   $pkg->set_flag_upgrade($flag & 4);
         } $l, $flags;
}

sub _inside {
    my ($l1, $l2) = @_;
    my $i = 0;
    return if @$l1 > @$l2;
    foreach (@$l1) {
        my $c;
        while ($c = $l2->[$i++] cmp $_) {
            return if $c == 1 || $i > @$l2;
        }
    }
    1;
}

sub _or_ify {
    my ($first, @other) = @_;
    my @l = split('\|\|', $first);
    foreach (@other) {
        @l = map {
            my $n = $_;
            map { "$_&&$n" } @l;
        } split('\|\|');
    }
    @l;
}
sub _or_clean {
    my ($flags) = @_;
    my @l = split("\t", $flags);
    @l = map { [ sort split('&&') ] } @l;
    my @r;
  B: while (@l) {
        my $e = shift @l;
        foreach (@r, @l) {
            _inside($_, $e) and next B;
        }
        push @r, $e;
    }
    join("\t", map { join('&&', @$_) } @r);
}


sub computeGroupSize {
    my ($packages, $min_level) = @_;
    my (%group, %memo);

    my %or_ify_cache;
    my $or_ify_cached = sub {
	$or_ify_cache{$_[0]} ||= join("\t", _or_ify(split("\t", $_[0])));
    };

    log::l("install::pkgs::computeGroupSize");
    my $time = time();

    my %pkgs_with_same_rflags;
    foreach (@{$packages->{depslist}}) {
	next if !$_->rate || $_->rate < $min_level || $_->flag_available;
	my $flags = join("\t", $_->rflags);
	next if $flags eq 'FALSE';
	push @{$pkgs_with_same_rflags{$flags}}, $_;
    }

    foreach my $raw_flags (keys %pkgs_with_same_rflags) {
	my $flags = $or_ify_cached->($raw_flags);
	my @pkgs = @{$pkgs_with_same_rflags{$raw_flags}};
  
	#- determine the packages that will be selected when selecting $p.
	#- make a fast selection (but potentially erroneous).
	#- installed and upgrade flags must have been computed (see compute_installed_flags).
	my %newSelection;