From c41016ef3212c9ada79ce9ecf970766b2ae0c473 Mon Sep 17 00:00:00 2001 From: Tobias Waldekranz Date: Fri, 19 Feb 2016 12:50:24 +0100 Subject: [PATCH 1/2] Only default to SIGHUP support on daemons When parsing a service configuration, only default to SIGHUP support if the service is a daemon. inetd services must be stop/started on change. --- conf.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/conf.c b/conf.c index 66831c5b..e8f66476 100644 --- a/conf.c +++ b/conf.c @@ -125,7 +125,8 @@ void conf_parse_cond(svc_t *svc, char *cond) } /* By default we assume UNIX daemons support SIGHUP */ - svc->sighup = 1; + if (svc_is_daemon(svc)) + svc->sighup = 1; if (!cond) return; From 2555fe8e96a8424c05f56ebedd7801323730262e Mon Sep 17 00:00:00 2001 From: Tobias Waldekranz Date: Fri, 19 Feb 2016 12:53:39 +0100 Subject: [PATCH 2/2] inetd: Flush existing filters on reload Flush any existing filter rules when a configuration file is updated. Otherwise filters are simply appended to the old configuration which can cause finit to accept connections on interfaces that are blocked in the new configuration. --- inetd.c | 12 ++++++++++++ inetd.h | 1 + service.c | 2 ++ 3 files changed, 15 insertions(+) diff --git a/inetd.c b/inetd.c index a48272da..52671aca 100644 --- a/inetd.c +++ b/inetd.c @@ -351,6 +351,18 @@ inetd_filter_t *inetd_filter_match(inetd_t *inetd, char *ifname) return NULL; } +int inetd_flush(inetd_t *inetd) +{ + inetd_filter_t *filter, *next; + + TAILQ_FOREACH_SAFE(filter, &inetd->filters, link, next) { + TAILQ_REMOVE(&inetd->filters, filter, link); + free(filter); + } + + return 0; +} + /* Poor man's tcpwrappers filtering */ int inetd_allow(inetd_t *inetd, char *ifname) { diff --git a/inetd.h b/inetd.h index 83073cfd..1fdf1edd 100644 --- a/inetd.h +++ b/inetd.h @@ -64,6 +64,7 @@ int inetd_del (inetd_t *inetd); int inetd_match (inetd_t *inetd, char *service, char *proto); int inetd_filter_str (inetd_t *inetd, char *str, size_t len); +int inetd_flush (inetd_t *inetd); int inetd_allow (inetd_t *inetd, char *ifname); int inetd_deny (inetd_t *inetd, char *ifname); int inetd_is_allowed (inetd_t *inetd, char *ifname); diff --git a/service.c b/service.c index 4454cfc3..36482a77 100644 --- a/service.c +++ b/service.c @@ -671,6 +671,8 @@ int service_register(int type, char *line, time_t mtime, char *username) } inetd_setup: + inetd_flush(&svc->inetd); + if (!ifaces) { _d("No specific iface listed for %s, allowing ANY.", service); inetd_allow(&svc->inetd, NULL);