inetd: Flush existing filters on reload

Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
This commit is contained in:
Tobias Waldekranz
2016-02-19 12:53:39 +01:00
parent c41016ef32
commit 2555fe8e96
3 changed files with 15 additions and 0 deletions
+12
View File
@@ -351,6 +351,18 @@ inetd_filter_t *inetd_filter_match(inetd_t *inetd, char *ifname)
return NULL;
}
int inetd_flush(inetd_t *inetd)
{
inetd_filter_t *filter, *next;
TAILQ_FOREACH_SAFE(filter, &inetd->filters, link, next) {
TAILQ_REMOVE(&inetd->filters, filter, link);
free(filter);
}
return 0;
}
/* Poor man's tcpwrappers filtering */
int inetd_allow(inetd_t *inetd, char *ifname)
{
+1
View File
@@ -64,6 +64,7 @@ int inetd_del (inetd_t *inetd);
int inetd_match (inetd_t *inetd, char *service, char *proto);
int inetd_filter_str (inetd_t *inetd, char *str, size_t len);
int inetd_flush (inetd_t *inetd);
int inetd_allow (inetd_t *inetd, char *ifname);
int inetd_deny (inetd_t *inetd, char *ifname);
int inetd_is_allowed (inetd_t *inetd, char *ifname);
+2
View File
@@ -671,6 +671,8 @@ int service_register(int type, char *line, time_t mtime, char *username)
}
inetd_setup:
inetd_flush(&svc->inetd);
if (!ifaces) {
_d("No specific iface listed for %s, allowing ANY.", service);
inetd_allow(&svc->inetd, NULL);