mirror of
https://github.com/troglobit/finit.git
synced 2026-10-01 05:22:48 +07:00
inetd: Flush existing filters on reload
Flush any existing filter rules when a configuration file is updated. Otherwise filters are simply appended to the old configuration which can cause finit to accept connections on interfaces that are blocked in the new configuration.
This commit is contained in:
@@ -351,6 +351,18 @@ inetd_filter_t *inetd_filter_match(inetd_t *inetd, char *ifname)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
int inetd_flush(inetd_t *inetd)
|
||||
{
|
||||
inetd_filter_t *filter, *next;
|
||||
|
||||
TAILQ_FOREACH_SAFE(filter, &inetd->filters, link, next) {
|
||||
TAILQ_REMOVE(&inetd->filters, filter, link);
|
||||
free(filter);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Poor man's tcpwrappers filtering */
|
||||
int inetd_allow(inetd_t *inetd, char *ifname)
|
||||
{
|
||||
|
||||
@@ -64,6 +64,7 @@ int inetd_del (inetd_t *inetd);
|
||||
int inetd_match (inetd_t *inetd, char *service, char *proto);
|
||||
int inetd_filter_str (inetd_t *inetd, char *str, size_t len);
|
||||
|
||||
int inetd_flush (inetd_t *inetd);
|
||||
int inetd_allow (inetd_t *inetd, char *ifname);
|
||||
int inetd_deny (inetd_t *inetd, char *ifname);
|
||||
int inetd_is_allowed (inetd_t *inetd, char *ifname);
|
||||
|
||||
Reference in New Issue
Block a user