The rc.d script and Apache config hard-coded the /usr/local paths the
FreeBSD/OpenBSD distro target uses, so any build with other paths got
files pointing at the wrong place.
Make the rc.d script a template filled with CMAKE_INSTALL_FULL_BINDIR and
PERL_EXECUTABLE, generated into misc/ when building on OpenBSD. Drop the
OpenBSD Apache config: misc/apache.conf is already generated from the
configured web, cgi and cache paths.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
misc/ has a systemd unit and an init.d script, so on macOS nothing
restarts ZoneMinder after a reboot. This is the launchd counterpart,
generated next to zoneminder.service with the same substitutions.
Mapping the unit across needed three decisions worth recording.
zmpkg.pl forks zmdc.pl and returns, which systemd calls Type=forking.
launchd has no such notion and by default kills everything left in a
job's process group once the job exits - which would be all of
ZoneMinder, immediately. AbandonProcessGroup=true disables exactly that.
So the job starts ZoneMinder rather than supervising it, and zmdc.pl and
zmwatch.pl go on restarting the daemons themselves as they always have.
There is no equivalent of ExecStop, so unloading the job does not stop
ZoneMinder. The comment in the file says so and gives the stop-then-
unload order rather than leaving people to find out.
There is no equivalent of After= or Requires= either. launchd only
orders jobs it manages, and a Homebrew MariaDB is not one, so ZoneMinder
can start before the database is listening. zmdc.pl retries, and the
comment points at zmdc.log for when it matters.
Generated but not installed, matching how zoneminder.service is treated:
/Library/LaunchDaemons is read at boot, so putting a job there is the
installer's decision and not the build's.
Verified with plutil -lint and plutil -p on the generated file, and every
key checked against launchd.plist(5). Not loaded here - that needs an
installed ZoneMinder to start.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B5KL9Xbi7K5aGsauLtd8tG
Now that the daemons reliably land in this unit rather than inheriting the web
server's namespace, the unit is worth hardening. Add the protections that do
not interfere with capture: ProtectSystem=full, ProtectClock,
ProtectControlGroups, ProtectHostname, ProtectKernelLogs, ProtectKernelModules,
ProtectKernelTunables, LockPersonality, RestrictRealtime and RestrictSUIDSGID.
Set the options that would break us explicitly rather than leaving them to a
default a distribution might override, since each fails in a way that is not
visible from the web ui:
PrivateDevices and PrivateTmp, because zmc publishes frames in /dev/shm for a
zms that runs under the web server, and zmaudit.pl cleans up the swap images
zms writes under /var/tmp.
ProcSubset and ProtectProc, because zmstats reads /proc/stat, /proc/meminfo
and /proc/loadavg, and zmpkg.pl reads /proc/self/cgroup to decide whether
systemd started it.
Record why NoNewPrivileges, ProtectHome and MemoryDenyWriteExecute are absent,
and warn that the mount namespace these options create hides filesystems
mounted after ZoneMinder starts.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019URmtYqza6Rzi6F7cmabSm
Merge MAC vendor database from zm_utils into ZoneMinder. Adds entries for
Reolink, Dahua, Hanwha, Buffalo, Google, Sagemcom, and many additional
HikVision/Ubiquiti/Grandstream MACs. Sorted by vendor type for readability.
Removes duplicates from zm_utils source. Preserves ZM-only Uniview and
TP-Link entries. Keeps IC Realtime Dahua control mapping that zm_utils lost.
Updates Vivotek with ePTZ control and normalizes D-Link type name.
34 -> 73 entries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add probeUniview() that queries the camera's LAPI for device model,
name, resolution, and codec. Uses RTSP main stream URL format
rtsp://ip:554/media/video1 and LAPI snapshot endpoint for thumbnails.
Includes OUI alias probeZhejiangUniviewTechnologiesCoLtd for IEEE
vendor name matching. Adds all 4 registered Uniview MAC OUI prefixes
(48ea63, 6cf17e, 88263f, c47905) to MacVendors.json.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Indent with 2 spaces
Also remove expressions form closing tags. They have been made optional a while ago since they make reading rather more difficult.
RPM packaging calls the freedesktop tool "desktop-file-install", which fails with:
```
error: key "Categories" is present in group "Desktop Entry", but the type is "Link" while this key is only valid for type "Application"
```
@connortechnology This fails the build so I'm removing the categories. Let me know if you've got any other ideas.