mirror of
https://github.com/troglobit/finit.git
synced 2026-10-04 06:44:12 +07:00
Fix #342: prevent certain commands at bootstrap and shutdown
Over the years there have been multiple cases of invalid and/or unsafe uses of signals and initctl commands at bootstrap and shutdown. These cases cannot be safely supported. This commit locks down finit a bit to avoid the most common cases. If you run into this, please open a new discussion at GitHub and we'll talk about it. Maybe I've been overzealous or you have another use-case that warrants opening up some or parts of the API. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
@@ -365,6 +365,25 @@ static void api_cb(uev_t *w, void *arg, int events)
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
switch (rq.cmd) {
|
||||||
|
case INIT_CMD_RUNLVL:
|
||||||
|
case INIT_CMD_RELOAD:
|
||||||
|
case INIT_CMD_START_SVC:
|
||||||
|
case INIT_CMD_RESTART_SVC:
|
||||||
|
case INIT_CMD_STOP_SVC:
|
||||||
|
case INIT_CMD_RELOAD_SVC:
|
||||||
|
case INIT_CMD_REBOOT:
|
||||||
|
case INIT_CMD_HALT:
|
||||||
|
case INIT_CMD_POWEROFF:
|
||||||
|
case INIT_CMD_SUSPEND:
|
||||||
|
if (runlevel == 0 || runlevel == 6) {
|
||||||
|
warnx("Unsupported command in runlevel S and 6.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
default:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
switch (rq.cmd) {
|
switch (rq.cmd) {
|
||||||
case INIT_CMD_RUNLVL:
|
case INIT_CMD_RUNLVL:
|
||||||
switch (rq.runlevel) {
|
switch (rq.runlevel) {
|
||||||
|
|||||||
@@ -431,6 +431,11 @@ static void sighup_cb(uev_t *w, void *arg, int events)
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (runlevel == 0 || runlevel == 6) {
|
||||||
|
warnx("SIGHUP ignored in runlevel S and 6.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
/* Restart initctl API domain socket, similar to systemd/SysV init */
|
/* Restart initctl API domain socket, similar to systemd/SysV init */
|
||||||
api_exit();
|
api_exit();
|
||||||
api_init(w->ctx);
|
api_init(w->ctx);
|
||||||
@@ -482,6 +487,11 @@ static void sigusr1_cb(uev_t *w, void *arg, int events)
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (runlevel == 0 || runlevel == 6) {
|
||||||
|
warnx("SIGUSR1 ignored in runlevel S and 6.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
/* Restart initctl API domain socket, similar to systemd/SysV init */
|
/* Restart initctl API domain socket, similar to systemd/SysV init */
|
||||||
api_exit();
|
api_exit();
|
||||||
api_init(w->ctx);
|
api_init(w->ctx);
|
||||||
@@ -498,6 +508,11 @@ static void sigusr2_cb(uev_t *w, void *arg, int events)
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (runlevel == 0 || runlevel == 6) {
|
||||||
|
warnx("SIGUSR2 ignored in runlevel S and 6.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
halt = SHUT_OFF;
|
halt = SHUT_OFF;
|
||||||
service_runlevel(0);
|
service_runlevel(0);
|
||||||
}
|
}
|
||||||
@@ -513,6 +528,11 @@ static void sigterm_cb(uev_t *w, void *arg, int events)
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (runlevel == 0 || runlevel == 6) {
|
||||||
|
warnx("SIGTERM ignored in runlevel S and 6.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
halt = SHUT_REBOOT;
|
halt = SHUT_REBOOT;
|
||||||
service_runlevel(6);
|
service_runlevel(6);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user