Commit Graph
530 Commits
Author SHA1 Message Date
Joachim Nilsson 70af5d7f8d Refactor: Move HAVE_DBUS and CONSOLE to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 36c59e77b4 Fix broken SYSROOT and add it to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 57b167f9aa Refactor: Move root fs remount setting to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 155ae15390 Refactor: Move random seed config to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 06a1a3c839 Refactor: Move default runlevel to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 42f3d4dc79 Refactor: Move DEFUSER and DEFHOST to configure script
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 8e12dba8d9 Refactor: Move conf.c declarations from finit.h --> conf.h
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 589a7ea8a5 Always run HOOK_SVC_RECONF on SIGHUP/reload
When Finit receives SIGHUP or a reload command all services listed in
/etc/finit.d/*.conf are first stopped and then started again.  I.e.,
removed/changed services are stopped and then new/changed services are
started again.  In between we call HOOK_SVC_RECONF.  It should always be
called, even though no services were removed/changed/added.  This to
allow plugins connected to that hook may need to run as intended.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson e5732f24d3 Followup to tempfile(): template must be writable.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 3d0e58ebcd Followup to tempfile(): paranoid umask as well ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 22:25:33 +02:00
Joachim Nilsson 162b394726 Replace insecure tmpfile() with mkstemp() based local tempfile()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 21:54:24 +02:00
Joachim Nilsson c6a9fa3b98 initctl: Order inetd filters same as in .conf file.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 19:06:07 +02:00
Joachim Nilsson e04c73bab8 initctl: Add UDP/TCP to presentation of inetd services in verbose mode.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 18:55:05 +02:00
Joachim Nilsson ac0edc9b37 initctl: Fix broken presentation of inetd services in verbose mode.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 18:54:29 +02:00
Joachim Nilsson 59731988fd initctl: Add support for showing current runlevel
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 18:30:01 +02:00
Joachim Nilsson d0da3b8b98 Followup to 'initctl with process name as well as JOBID'
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 17:56:41 +02:00
Joachim Nilsson be074abce8 Followup libite submodule, use https not git proto.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 16:29:16 +02:00
Joachim Nilsson 577622c945 Add support for calling initctl with process name as well as JOBID
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit.  When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances.  For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 15:54:47 +02:00
Joachim Nilsson 5d2172eac8 Upgrade to libuev -dev.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-18 08:44:41 +02:00
Joachim Nilsson 276cda9a4d Install -dev files for both libite and libuev, needed for external plugins.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-18 08:44:15 +02:00
Joachim Nilsson bafdf0007f Helper macros moved to libite/lite.h
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-18 02:26:53 +02:00
Joachim Nilsson 064e94e030 Add/readd libite, now as a separate submodule.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-18 02:26:47 +02:00
Joachim Nilsson c00ac21fe2 Remove libite and chomp() in preparing for ... libite.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-18 01:11:22 +02:00
Joachim Nilsson 164fe12685 Update ChangeLog
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 14:27:34 +02:00
Joachim Nilsson e7dad9a770 Add inetd.h to distributed headers, needed for external plugins.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 14:07:35 +02:00
Joachim Nilsson 02e5c868ba Makefile: Declare dependencies better, for parallel builds
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 14:07:30 +02:00
Joachim Nilsson 66f472bb05 service_start(): Make sure to collect the run child.
Fix side effect with run stanza children not being collected if finit is
not run in verbose mode.  Regression introduced in release cycle.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 7b894fcf52 Prune and relocate #include files.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 0de4fb0cbf inetd: Fix naming of built-in service on custom port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 231539cd7d Move all custom banner() handling to configure script.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 195f17ae08 TODO: Markdown syntax fixes.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 54ace1a6cf README: Further updates and corrections to inetd syntax.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 1f19b50846 Fix Coverty CID #96208: Unchecked return value from library.
Replace `remove()` with our own `erase()` which checks the return value
and warns on actual real failure.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:17 +02:00
Joachim Nilsson 6c58a7d774 Fix Coverty CID #96209: Dereference NULL return value.
The new iterators `svc_inetd_iterator()` and `svc_dynamic_iterator()`
used unsafe constructs that could cause them, at least the latter, to
dereference a `NULL` pointer.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:06 +02:00
Joachim Nilsson dbcece81ea Fix Coverty CID #96210: Argument cannot be negative.
We must check the return value from `accept()`, it may fail.  Also, we
should probably retry the syscall in some cases ...

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:06 +02:00
Joachim Nilsson 70f4d99922 Fix Coverty CID #96211: String not NUL terminated.
When receiving a start/stop/reload/restart request from initctl we must
make sure to validate and NUL terminate the job ID.  The `read()` API
does not NUL terminate strings for us and we cannot rely on `initctl` or
any other external API user to do so for us.

This patch improves error and boundary checking.

- Use memcpy() + hard termination instead.
- Fix use of strchr() on possibly non-NUL terminated string.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:35:10 +02:00
Joachim Nilsson ee6d524bc8 Update ChangeLog and README for release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 22:43:03 +02:00
Joachim Nilsson d9055c3965 Fix build/install --with-plugins='a b' -- only build/install a and b
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 16:55:17 +02:00
Joachim Nilsson 03573b41ca Add support for a deny filter syntax to inetd services
This patch changes the syntax for custom inetd services and adds support
for deny filters.  The new syntax is:

    inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>

This means the second column now defines what@from and the third to/what
process.  For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin.  Here follows a few examples:

    inetd time/udp                    wait [2345] internal                -- UNIX rdate service
    inetd time/tcp                  nowait [2345] internal                -- UNIX rdate service
    inetd 3737/tcp                  nowait [2345] internal.time           -- UNIX rdate service
    inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 2323/tcp@eth1,eth2,eth0   nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 222/tcp@eth0              nowait [2345] /sbin/dropbear -i -R -F -- SSH service
    inetd ssh/tcp@*,!eth0           nowait [2345] /sbin/dropbear -i -R -F -- SSH service

Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`.  The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`.  The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.

NOTE: This patch breaks syntax compatibility with Finit v1.12!

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 14:15:39 +02:00
Joachim Nilsson b0c759e518 Add missing file api.c
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 14:06:55 +02:00
Joachim Nilsson 1a1f24721f Refactor: introduce telinit and a new initctl tool w/ API
- Reduce size of `helpers.c`, for linking against new `initctl` tool,
  by moving out functions to `pid.c` and `exec.c`
- Add `AF_UNIX` API to Finit, to complement old `/dev/initctl` FIFO
- Let old FIFO API be used by init/telinit: `init <q | 1-9>`
- Move all advanced initctl code from `client.c` to `initctl.c`, yes
  its a bit confusing to call the *new* tool the same as the old FIFO
  but this is more in line with what, e.g Upstart does.
- Move all advanced server side code from `plugins/initctl.c` to `api.c`
- Update TODO with upcoming inetd syntax change and dynamic events.
- Temporarily fix display of inetd services from `initctl status -v`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-13 12:26:16 +02:00
Joachim Nilsson 66edb42e06 Upgrade to libuev v1.2.0
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-09 14:57:41 +02:00
Joachim Nilsson 4e904142cb configure: Reverse kernel-quiet, enable --> disable, enabled by default.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 18:08:08 +02:00
Joachim Nilsson 7b5d56df98 TODO: Document proposal for dynamic event framework
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 18:07:40 +02:00
Joachim Nilsson 1d58f4abbe initctl: New symlink to finit binary, document functions in README.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 18:06:55 +02:00
Joachim Nilsson 24e1d284ad Add support for finit <stop|start|reload|restart> JOB
This patch further extends the capabilities of the client with the
ability to control the running state of services:

    finit <stop|start|reload|restart> JOB

Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch.  A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier.  See the output of `finit status` for the JOB id.

Also, with the introduction of multiple instances we broke support for
multiple related inetd services.  This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 08:32:49 +02:00
Joachim Nilsson 720324b256 Change syntax for multiple instances: #ID --> :ID
Turns out that #ID syntax for multiple instances, introduced in cb07556,
was very cumbersome to reference from the shell command line in the new
Finit client.  This patch changes the syntax from #ID to :ID, which also
means that listing services/jobs in the shell will look like JOB:ID.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 01:07:41 +02:00
Joachim Nilsson 534979e6c7 inetd_match(): Fix bug in matcher, make sure to also compare protocol!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 00:54:54 +02:00
Joachim Nilsson 6a27ad8997 Improve output from 'finit status'
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 16:26:11 +02:00
Joachim Nilsson 6d3972cca8 Add --enable-kernel-quiet to configure, delayed quiet after initial boot.
... with the additional twist that the kernel command line option
'quiet' also gets to play.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 16:20:23 +02:00