From 10d49641065928ecfd65635a351943b7b3fb9180 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Thu, 11 Feb 2021 21:50:17 +0100 Subject: [PATCH] Remove last traces of inetd support Signed-off-by: Joachim Wiberg --- .travis.yml | 4 +- README.md | 47 ++------------- contrib/alpine/build.sh | 4 +- contrib/debian/build.sh | 16 +++-- contrib/finit.conf | 6 -- contrib/void/build.sh | 4 +- doc/Makefile.am | 2 +- doc/TODO.md | 3 - doc/build.md | 5 -- doc/config.md | 38 ++---------- doc/inetd.md | 125 ---------------------------------------- doc/plugins.md | 13 +---- src/finit.c | 2 +- src/finit.h | 2 +- src/plugin.h | 9 +-- src/tty.c | 2 +- 16 files changed, 26 insertions(+), 256 deletions(-) delete mode 100644 doc/inetd.md diff --git a/.travis.yml b/.travis.yml index f5ebe163..74c98092 100644 --- a/.travis.yml +++ b/.travis.yml @@ -45,10 +45,10 @@ install: # Custom build script for the time being, no "make test" yet script: - ./autogen.sh - - ./configure --prefix=/tmp --disable-inetd --enable-static + - ./configure --prefix=/tmp --enable-static - make clean - make V=1 -j5 - - ./configure --prefix=/tmp --enable-inetd-echo-plugin --enable-inetd-time-plugin --enable-x11-common-plugin --enable-inetd-chargen-plugin --enable-fallback-shell --enable-watchdog --enable-logit + - ./configure --prefix=/tmp --enable-x11-common-plugin --enable-fallback-shell --enable-watchdog --enable-logit - cat config.log - make clean - make V=1 -j5 diff --git a/README.md b/README.md index d205bb38..b8b3ded3 100644 --- a/README.md +++ b/README.md @@ -6,7 +6,6 @@ * [Bootstrap](doc/bootstrap.md#bootstrap) * [Runlevels](#runlevels) * [Syntax](doc/config.md#syntax) - * [Inetd](doc/inetd.md#inetd) * [Runparts & /etc/rc.local](#runparts--etcrclocal) * [Hooks, Callbacks & Plugins](doc/plugins.md#hooks-callbacks--plugins) * [Rebooting & Halting](#rebooting--halting) @@ -81,17 +80,6 @@ service :2 [2345] /sbin/merecat -n -p 8080 /var/www -- Old web server #task [S] /etc/init.d/acpid start -- Starting ACPI Daemon #task [S] /etc/init.d/kbd start -- Preparing console -# Inetd services to start on demand, with alternate ports and filtering -inetd ftp/tcp nowait [2345] /sbin/in.ftpd -- FTP daemon -inetd tftp/udp wait [2345] /sbin/in.tftpd -- TFTP daemon -inetd time/udp wait [2345] internal -- UNIX rdate service -inetd time/tcp nowait [2345] internal -- UNIX rdate service -inetd 3737/tcp nowait [2345] internal.time -- UNIX rdate service -inetd telnet/tcp nowait [2345] /sbin/telnetd -i -F -- Telnet daemon -inetd 2323/tcp nowait [2345] /sbin/telnetd -i -F -- Telnet daemon -inetd 222/tcp@eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service -inetd ssh/tcp@*,!eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service - # Run start scripts from this directory # runparts /etc/start.d @@ -108,10 +96,9 @@ tty [12345] /dev/ttyUSB0 noclear tty [12345] @console noclear nologin ``` -The `service` stanza, as well as `task`, `run`, `inetd` and others are -described in full in [doc/config.md](doc/config.md). Here's a quick -overview of some of the most common components needed to start a UNIX -daemon: +The `service` stanza, as well as `task`, `run` and others are described +in full in [doc/config.md](doc/config.md). Here's a quick overview of +some of the most common components needed to start a UNIX daemon: ``` service [LVLS] /path/to/daemon ARGS -- Some text @@ -169,26 +156,6 @@ Features Start, monitor and restart services should they fail. -**Inetd** - -Finit comes with a built-in [inetd server](doc/inetd.md). No need to -maintain a separate config file for services that you want to start on -demand. - -All inetd services started can be filtered per port and inbound -interface, reducing the need for a full blown firewall. - -Built-in optional inetd services: - -- echo [RFC862][] -- chargen [RFC864][] -- daytime [RFC867][] -- discard [RFC863][] -- time (rdate) [RFC868][] - -For more information, see [doc/inetd.md](doc/inetd.md). - - **Getty** Finit supports external getty but also comes with a limited built-in @@ -220,7 +187,7 @@ see [doc/config.md](doc/config.md#syntax). Support for SysV init-style [runlevels][5] is available, in the same minimal style as everything else in Finit. The `[2345]` syntax can be -applied to service, task, run, inetd, and TTY stanzas. +applied to service, task, run, and TTY stanzas. Reserved runlevels are 0 and 6, halt and reboot, respectively just like SysV init. Runlevel 1 can be configured freely, but is recommended to @@ -250,9 +217,6 @@ Capabilities: Hook into the boot at predefined points to extend Finit - **I/O** Listen to external events and control Finit behavior/services -- **Inetd** - Extend Finit with internal inetd services, for an example, see - `plugins/time.c` Extensions and functionality not purely related to what an `/sbin/init` needs to start a system are available as a set of plugins that either @@ -488,9 +452,6 @@ or `/bin/sh`, if no TTYs are configured in `/etc/finit.conf`. For a fully operational system `/var`, `/run` and `/tmp` must be set up properly in `/etc/fstab` -- which is iterated over at boot. -The built-in Inetd requires `/etc/services` and `/etc/protocols` to work -with port names rather than numbers. - Origin & References ------------------- diff --git a/contrib/alpine/build.sh b/contrib/alpine/build.sh index 5a7ec886..ce8c317b 100755 --- a/contrib/alpine/build.sh +++ b/contrib/alpine/build.sh @@ -18,9 +18,7 @@ PKG_CONFIG_LIBDIR=/usr/lib/pkgconfig:/usr/local/lib/pkgconfig ./configure \ --sysconfdir=/etc --localstatedir=/var \ --enable-progress \ --enable-dbus-plugin --enable-x11-common-plugin \ - --enable-alsa-utils-plugin --enable-inetd-echo-plugin \ - --enable-inetd-chargen-plugin --enable-inetd-daytime-plugin \ - --enable-inetd-discard-plugin --enable-inetd-time-plugin \ + --enable-alsa-utils-plugin \ --with-heading="Alpine Linux 3.13" --with-hostname=alpine echo diff --git a/contrib/debian/build.sh b/contrib/debian/build.sh index 6ac4a7a2..15a5c6e8 100755 --- a/contrib/debian/build.sh +++ b/contrib/debian/build.sh @@ -21,15 +21,13 @@ echo # The plugins are optional, but you may need D-Bus and X11 if you want # to run X-Window, the other configure flags are however required. -./configure \ - --prefix=/usr --exec-prefix= \ - --sysconfdir=/etc --localstatedir=/var \ - --enable-progress \ - --enable-dbus-plugin --enable-x11-common-plugin \ - --enable-alsa-utils-plugin --enable-inetd-echo-plugin \ - --enable-inetd-chargen-plugin --enable-inetd-daytime-plugin \ - --enable-inetd-discard-plugin --enable-inetd-time-plugin \ - --with-random-seed=/var/lib/urandom/random-seed \ +./configure \ + --prefix=/usr --exec-prefix= \ + --sysconfdir=/etc --localstatedir=/var \ + --enable-progress \ + --enable-dbus-plugin --enable-x11-common-plugin \ + --enable-alsa-utils-plugin \ + --with-random-seed=/var/lib/urandom/random-seed \ --with-heading="Debian GNU/Linux" --with-hostname="stretch" if [ $? -ne 0 ]; then diff --git a/contrib/finit.conf b/contrib/finit.conf index a8facfa5..87f699d7 100644 --- a/contrib/finit.conf +++ b/contrib/finit.conf @@ -47,12 +47,6 @@ service [2345] log:/var/log/ntpd.log /sbin/ntpd -n -l -I et # Run start scripts from this directory # runparts /etc/start.d -# Inetd services -inetd time/udp wait [2345] internal -- UNIX rdate service -inetd time/tcp nowait [2345] internal -- UNIX rdate service -inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i -- SSH service -inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i -- SSH service - # For multiple instances of the same service, add :ID somewhere between # the service/run/task keyword and the command. service :1 [2345] /sbin/httpd -f -h /http -p 80 -- Web server diff --git a/contrib/void/build.sh b/contrib/void/build.sh index 9d427858..2a427318 100755 --- a/contrib/void/build.sh +++ b/contrib/void/build.sh @@ -18,9 +18,7 @@ PKG_CONFIG_LIBDIR=/usr/lib/pkgconfig:/usr/local/lib/pkgconfig ./configure \ --sysconfdir=/etc --localstatedir=/var \ --enable-progress \ --enable-dbus-plugin --enable-x11-common-plugin \ - --enable-alsa-utils-plugin --enable-inetd-echo-plugin \ - --enable-inetd-chargen-plugin --enable-inetd-daytime-plugin \ - --enable-inetd-discard-plugin --enable-inetd-time-plugin \ + --enable-alsa-utils-plugin \ --with-heading="Void Linux" --with-hostname=void echo diff --git a/doc/Makefile.am b/doc/Makefile.am index 27e732d8..1219ab01 100644 --- a/doc/Makefile.am +++ b/doc/Makefile.am @@ -1,4 +1,4 @@ docsdir := @docdir@/doc -docs_DATA = config.md conditions.md distro.md inetd.md plugins.md \ +docs_DATA = config.md conditions.md distro.md plugins.md \ service.md signals.md svc-machine.png cmdline.md EXTRA_DIST = $(docs_DATA) diff --git a/doc/TODO.md b/doc/TODO.md index 8c66bb1f..d55b81e6 100644 --- a/doc/TODO.md +++ b/doc/TODO.md @@ -12,9 +12,6 @@ value in the project turned out to be: Near Future ----------- -* Remove native inetd support. Relocate to a stand-alone application, - possibly even outside of the Finit project. Will greatly simplify - the remaining bits ... * ... when inetd support has been removed, we can refactor the .conf parser, parse user input in a separate process, move process monitor to separate process (same as parser?), and possibly even ... diff --git a/doc/build.md b/doc/build.md index 20a0113f..d38f8ace 100644 --- a/doc/build.md +++ b/doc/build.md @@ -49,8 +49,6 @@ Below are a few of the main switches to configure: * `--localstatedir=..`: follows `--prefix`, you likely want `/var` -* `--disable-inetd`: Disable the built-in inetd server. - * `--enable-static`: Build Finit statically. The plugins will be built-ins (.o files) and all external libraries, except the C library will be linked statically. @@ -81,9 +79,6 @@ Then configure, build and install: ```shell $ ./configure --prefix=/usr --exec-prefix= \ --sysconfdir=/etc --localstatedir=/var \ - --enable-inetd-echo-plugin \ - --enable-inetd-chargen-plugin --enable-inetd-daytime-plugin \ - --enable-inetd-discard-plugin --enable-inetd-time-plugin \ --with-heading="Alpine Linux 3.13" --with-hostname=alpine $ make . diff --git a/doc/config.md b/doc/config.md index cf721428..3c1c4d10 100644 --- a/doc/config.md +++ b/doc/config.md @@ -247,33 +247,6 @@ Syntax use the option `kill:SEC`, e.g., `kill:10` to wait 10 seconds before sending `SIGKILL`. -* `inetd service/proto[@iflist] [LVLS] /path/to/daemon args` - Launch a daemon when a client initiates a connection on an Internet - port. Available services are listed in the UNIX `/etc/services` file. - Finit can filter access to from a list of interfaces, `@iflist`, per - inetd service as well as listen to custom ports. - -```shell - inetd ftp/tcp nowait @root /usr/sbin/uftpd -i -f - inetd tftp/udp wait @root /usr/sbin/uftpd -i -t -``` - - The following example listens to port 2323 for telnet connections and - only allows clients connecting from `eth0`: - -```shell - inetd 2323/tcp@eth0 nowait [2345] /sbin/telnetd -i -F -``` - - The interface list, `@iflist`, is of the format `@iface,!iface,iface`, - where a single `!` means to deny access. Notice how interfaces are - comma separated with no spaces. - - The `inetd` directive can also have ` -- Optional Description`, only - Finit does not output this text on the console when launching inetd - services. Instead this text is sent to syslog and also shown by the - `initctl` tool. More on inetd below. - * `runparts ` Call [run-parts(8)][] on `DIR` to run start scripts. All executable files, or scripts, in the directory are called, in alphabetic order. @@ -376,8 +349,8 @@ be installed since system requirements differ too much. Try out the Debian 6.0 example `/usr/share/doc/finit/finit.conf` configuration that is capable of service monitoring SSH, sysklogd, gdm and getty! -Every `run`, `task`, `service`, or `inetd` can also list the privileges -the `/path/to/cmd` should be executed with. Simply prefix the path with +Every `run`, `task`, or `service` can also list the privileges the +`/path/to/cmd` should be executed with. Simply prefix the path with `[@USR[:GRP]]` like this: ```shell @@ -396,9 +369,9 @@ multiple web servers, add `:ID` somewhere between the `run`, `task`, Without the `:ID` to the service the latter will overwrite the former and only the old web server would be started and supervised. -The `run`, `task`, `service`, or `inetd` stanzas also allow the keyword -`log` to redirect `stderr` and `stdout` of the application to a file or -syslog using the native `logit` tool. The full syntax is: +The `run`, `task`, and `service` stanzas also allow the keyword `log` to +redirect `stderr` and `stdout` of the application to a file or syslog +using the native `logit` tool. The full syntax is: log:/path/to/file log:prio:facility.level,tag:ident @@ -455,7 +428,6 @@ the following: - `service` - `task` - `run` -- `inetd` - `rlimit` - `tty` diff --git a/doc/inetd.md b/doc/inetd.md deleted file mode 100644 index 8c9aafaf..00000000 --- a/doc/inetd.md +++ /dev/null @@ -1,125 +0,0 @@ -Internet Super Server -===================== - -Inetd ------ - -A built-in *Internet Super Server* support was added in Finit v1.12 and -v1.13, along with an internal `time` inetd service, RFC 868 (rdate). -The latter is supplied as a plugin to illustrate how simple it is to -extend finit with more internal inetd services. Today more built-in -services are available. - -> Please note, not all UNIX daemons are prepared to run as inetd services. -> In the example below `sshd` also need the command line argument `-i`. - -The inetd support in finit is quite advanced. Not only does it launch -services on demand, it can do so on custom ports and also filter inbound -traffic using a poor man's [TCP wrappers][]. The syntax is very similar -to the traditional `/etc/inetd.conf`, yet keeping with the style of -Finit: - -```shell - # Launch SSH on demand, in runlevels 2-5 as root - inetd ssh/tcp nowait [2345] @root:root /usr/sbin/sshd -i -``` - -A more advanced example is listed below, please note the *incompatible -syntax change* that was made between Finit v1.12 and v1.13 to support -deny filters: - -```shell - # Start sshd if inbound connection on eth0, port 222, or - # inbound on eth1, port 22. Ignore on other interfaces. - inetd 222/tcp@eth0 nowait [2345] /usr/sbin/sshd -i - inetd ssh/tcp@eth1,eth1 nowait [2345] /usr/sbin/sshd -i -``` - -If `eth0` is your Internet interface you may want to avoid using the -default port. To run ssh on port 222, and all others on port 22: - -```shell - inetd 222/tcp@eth0 nowait [2345] /usr/sbin/sshd -i - inetd ssh/tcp@*,!eth0 nowait [2345] /usr/sbin/sshd -i -``` - -Compared to Finit v1.12 you must *explicitly deny* access from `eth0`! - -To protect against looping attacks, the inetd server will refuse UDP -service if the reply port corresponds to any internal service. Similar -to how the FreeBSD inetd operates. - - -**Internal Services** - -Like the original `inetd`, Finit has a few standard services built-in. -They are realized as plugins to provide a simple means of testing the -inetd functionality stand-alone. But this also provides both a useful -network testing/availability, as well as a rudimentary time server for -`rdate` clients. - -- echo -- chargen -- daytime -- discard -- time - -For security reasons they are all disabled by default and have to be -enabled with both the `configure` script and a special `inetd` stanza in -the `finit.conf` or `finit.d/*.conf` like this: - -```shell - inetd echo/udp wait [2345] internal - inetd echo/tcp nowait [2345] internal - inetd chargen/udp wait [2345] internal - inetd chargen/tcp nowait [2345] internal - inetd daytime/udp wait [2345] internal - inetd daytime/tcp nowait [2345] internal - inetd discard/udp wait [2345] internal - inetd discard/tcp nowait [2345] internal - inetd time/udp wait [2345] internal - inetd time/tcp nowait [2345] internal -``` - -Then call `rdate` from a remote machine (or use localhost): - -```shell - rdate -p - rdate -up -``` - -Or `echoping` to reach the echo service: - -```shell - echoping -v - echoping -uv -``` - -Or `echoping -d` to reach the discard service: - -```shell - echoping -dv - echoping -duv -``` - -Or `echoping -c` to reach the chargen service: - -```shell - echoping -cv - echoping -cuv -``` - -If you use `time/udp` you must use the standard rdate implementation and -then call it with `rdate -up` to connect using UDP. Without the `-p` -argument rdate will try to set the system clock. Please note that rdate -has been deprecated by the NTP protocol and this plugin should only be -used for testing or environments where NTP for some reason is blocked. -Also, remember the UNIX year 2038 bug, or in the case of RFC 868 (and -some NTP implementations), year 2036! - -**Note:** There is currently no verification that the same port is used - more than once. So a standard `inetd http/tcp` service will clash - with an ssh entry for the same port `inetd 80/tcp` … - - -[TCP Wrappers]: https://en.wikipedia.org/wiki/TCP_Wrapper diff --git a/doc/plugins.md b/doc/plugins.md index 43073200..e5aed731 100644 --- a/doc/plugins.md +++ b/doc/plugins.md @@ -8,7 +8,7 @@ Hooks & Plugins * [Shutdown Hooks](#shutdown-hooks) Finit can be extended to add general functionality in the form of I/O -monitors, built-in inetd services, or hook plugins. +monitors, or hook plugins. The following sections detail existing plugins and hook points. For more information, see the plugins listed below. @@ -34,14 +34,6 @@ For your convenience a set of *optional* plugins are available: * *dbus.so*: Setup and start system message bus, D-Bus, at boot. _Optional plugin._ -* *echo.so*: RFC 862 plugin. Start as inetd service, like time below. - -* *chargen.so*: RFC 864 plugin. Start as inetd service, like time below. - -* *daytime.so*: RFC 867 plugin. Start as inetd service, like time below. - -* *discard.so*: RFC 863 plugin. Start as inetd service, like time below. - * *hotplug.so*: Setup and start either udev or mdev hotplug daemon, if available. @@ -57,9 +49,6 @@ For your convenience a set of *optional* plugins are available: * *resolvconf.so*: Setup necessary files for `resolvconf` at startup. _Optional plugin._ -* *time.so*: RFC 868 (rdate) plugin. Start as inetd service. Useful - for testing inetd filtering — BusyBox has an rdate (TCP) client. - * *tty.so*: Watches `/dev`, using inotify, for new device nodes (TTY's) to start/stop getty consoles on them on demand. Useful when plugging in a usb2serial converter to login to your embedded device. diff --git a/src/finit.c b/src/finit.c index 3c9c6c4a..424f3149 100644 --- a/src/finit.c +++ b/src/finit.c @@ -295,7 +295,7 @@ static void finalize(void) _d("Clean up all bootstrap-only tasks/services ..."); svc_prune_bootstrap(); - /* All services/tasks/inetd/etc. in configure runlevel have started */ + /* All services/tasks/etc. in configure runlevel have started */ _d("Running svc up hooks ..."); plugin_run_hooks(HOOK_SVC_UP); service_step_all(SVC_TYPE_ANY); diff --git a/src/finit.h b/src/finit.h index a29c2920..6745f17d 100644 --- a/src/finit.h +++ b/src/finit.h @@ -69,7 +69,7 @@ #define INIT_CMD_STOP_SVC 11 #define INIT_CMD_RELOAD_SVC 12 /* SIGHUP service */ #define INIT_CMD_RESTART_SVC 13 /* STOP + START service */ -#define INIT_CMD_QUERY_INETD 14 +#define INIT_CMD_UNUSED2 14 /* Unused, was INIT_CMD_QUERY_INETD */ #define INIT_CMD_UNUSED1 15 /* Unused, was INIT_CMD_EMIT */ #define INIT_CMD_GET_RUNLEVEL 16 #define INIT_CMD_WDOG_HELLO 128 /* Watchdog register and hello */ diff --git a/src/plugin.h b/src/plugin.h index 46cc8197..0727aa17 100644 --- a/src/plugin.h +++ b/src/plugin.h @@ -120,8 +120,7 @@ typedef struct plugin { /* Event loop handler, used internally by Finit */ uev_t watcher; - /* Plugin name, defaults to basename of plugin path if unset. - * NOTE: Must match cmd for services or inetd plugins! */ + /* Plugin name, defaults to basename of plugin path if unset. */ char *name; /* List of hook callbacks. */ @@ -137,12 +136,6 @@ typedef struct plugin { void (*cb)(void *arg, int fd, int events); } io; - /* Inetd Plugin, stdio used as client socket. - * @type argument will be either SOCK_DGRAM or SOCK_STREAM */ - struct { - int (*cmd)(int type); - } inetd; - char *depends[PLUGIN_DEP_MAX]; /* List of other .name's this depends on. */ } plugin_t; diff --git a/src/tty.c b/src/tty.c index fa5f18bf..d8f914d6 100644 --- a/src/tty.c +++ b/src/tty.c @@ -99,7 +99,7 @@ void tty_sweep(void) /** * tty_register - Register a getty on a device * @line: Configuration, text after initial "tty" - * @rlimit: Limits for this service/task/run/inetd, may be global limits + * @rlimit: Limits for this service/run/task, may be global limits * @file: The file name TTY was loaded from * * A Finit tty line can use the internal getty implementation or an