This patch adds protection against a common inetd attack vector wherein
the reply port to UDP inetd services is forged to an internal inetd
service port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch replaces the old 'initctl emit <EV>' idea with a more
full blown condition generator:
initctl cond <set|clear|flux> <COND>
This aligns better with terminology used elsewhere in the new Finit
service state machine and dependency handling already documented.
The 'flux' sub-command is mostly intended for simulation/test of
Finit itself and should perhaps not be documented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This is a first effort at cleaning up and consolidating all information
about the new service state machine and how conditions control this
state machine.
Also, clarified and added sections for all documents regarding how
services and conditions relate.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Prune standard configure flags and focus on the most important, whatever
they may be. Mention --disable-inetd and describe how --enable-static
works.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Now that we have a proper GNU configure script there is no such thing as
lightweight, and the respected environment variables are listed at the
end of `./configure --help`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Add support for changing the initial hard and soft resource limits for
finit and any processes it launches.
See /etc/finit.conf section in README.md for more information.
Patrick Stewart added the optional `log` keyword to service, run, task
and inetd stanzas in 889bce1. It redirects stdout/stderr to syslog
using the logger tool. This addition to the README is mainly just a
place holder so it's not forgotten before the upcoming README refactor.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for the runtime `HOOK_SVC_LOST` and the (very
noisy) *example* plugin `lost.so`.
Customer request.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for declaring *why* a service is being stopped
or reloaded. This is later used when all stopped services have been
collected by the `service_monitor()` to issue start or postponed SIGHUP.
As an added benefit we can now also see why a service is not running.
If it has been paused by a user, halted when moving to another runlevel,
waiting for a condition (event), or similar.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The event API, including Netlink events to services, looks OK now
to build the remaining two features on:
- Netlink plugin for GW and IFUP IFDN events
- Generic event support for services
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This part of the README must be completely overhauled before the
release, so much of the contents is basically just TODO or design
ideas atm.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch changes the syntax for custom inetd services and adds support
for deny filters. The new syntax is:
inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>
This means the second column now defines what@from and the third to/what
process. For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin. Here follows a few examples:
inetd time/udp wait [2345] internal -- UNIX rdate service
inetd time/tcp nowait [2345] internal -- UNIX rdate service
inetd 3737/tcp nowait [2345] internal.time -- UNIX rdate service
inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 2323/tcp@eth1,eth2,eth0 nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 222/tcp@eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
inetd ssh/tcp@*,!eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`. The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`. The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.
NOTE: This patch breaks syntax compatibility with Finit v1.12!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>