When Finit receives SIGHUP or a reload command all services listed in
/etc/finit.d/*.conf are first stopped and then started again. I.e.,
removed/changed services are stopped and then new/changed services are
started again. In between we call HOOK_SVC_RECONF. It should always be
called, even though no services were removed/changed/added. This to
allow plugins connected to that hook may need to run as intended.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit. When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances. For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix side effect with run stanza children not being collected if finit is
not run in verbose mode. Regression introduced in release cycle.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Replace `remove()` with our own `erase()` which checks the return value
and warns on actual real failure.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The new iterators `svc_inetd_iterator()` and `svc_dynamic_iterator()`
used unsafe constructs that could cause them, at least the latter, to
dereference a `NULL` pointer.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We must check the return value from `accept()`, it may fail. Also, we
should probably retry the syscall in some cases ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When receiving a start/stop/reload/restart request from initctl we must
make sure to validate and NUL terminate the job ID. The `read()` API
does not NUL terminate strings for us and we cannot rely on `initctl` or
any other external API user to do so for us.
This patch improves error and boundary checking.
- Use memcpy() + hard termination instead.
- Fix use of strchr() on possibly non-NUL terminated string.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch changes the syntax for custom inetd services and adds support
for deny filters. The new syntax is:
inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>
This means the second column now defines what@from and the third to/what
process. For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin. Here follows a few examples:
inetd time/udp wait [2345] internal -- UNIX rdate service
inetd time/tcp nowait [2345] internal -- UNIX rdate service
inetd 3737/tcp nowait [2345] internal.time -- UNIX rdate service
inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 2323/tcp@eth1,eth2,eth0 nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 222/tcp@eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
inetd ssh/tcp@*,!eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`. The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`. The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.
NOTE: This patch breaks syntax compatibility with Finit v1.12!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
- Reduce size of `helpers.c`, for linking against new `initctl` tool,
by moving out functions to `pid.c` and `exec.c`
- Add `AF_UNIX` API to Finit, to complement old `/dev/initctl` FIFO
- Let old FIFO API be used by init/telinit: `init <q | 1-9>`
- Move all advanced initctl code from `client.c` to `initctl.c`, yes
its a bit confusing to call the *new* tool the same as the old FIFO
but this is more in line with what, e.g Upstart does.
- Move all advanced server side code from `plugins/initctl.c` to `api.c`
- Update TODO with upcoming inetd syntax change and dynamic events.
- Temporarily fix display of inetd services from `initctl status -v`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch further extends the capabilities of the client with the
ability to control the running state of services:
finit <stop|start|reload|restart> JOB
Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch. A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier. See the output of `finit status` for the JOB id.
Also, with the introduction of multiple instances we broke support for
multiple related inetd services. This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Turns out that #ID syntax for multiple instances, introduced in cb07556,
was very cumbersome to reference from the shell command line in the new
Finit client. This patch changes the syntax from #ID to :ID, which also
means that listing services/jobs in the shell will look like JOB:ID.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>