Commit Graph
38 Commits
Author SHA1 Message Date
Joachim Nilsson a1e6febc4f Merge pull request #28 from westermo/wmo/2.4
Westermo fixes for services changing type at runtime

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-26 09:38:41 +02:00
Joachim Nilsson 448a9e1198 Stop inetd watcher and close socket when inetd service is removed
This patch fixes a problem with lingering inet sockets when inetd
services are removed.  When removing an inetd service we must stop
the watcher and close the socket.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-26 09:27:30 +02:00
Joachim Nilsson 4b0f78c1b5 Merge pull request #27 from westermo/wmo/2.4
Westermo fixes for UDP inetd services and more

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:06:43 +02:00
Joachim Nilsson 5ea3cc0090 Reduce max backlog in listen(): 20 --> 10
Both the original MIT Athena inetd and the GNU inetutils inetd only keep
a backlog of 10 connections in listen() for TCP sockets.  This patch
adjusts the Finit hard coded default accordingly.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:01:10 +02:00
Joachim Nilsson 7f5f8ba09d Minor grammar: "Connection" --> "connection"
When starting an inetd service in verbose mode we print a progress
message to the console appended with "Connection".  This patch simply
changes that to append with "connection" in lower case.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:01:10 +02:00
Joachim Nilsson efd265c9c8 Fix "broken pipe" problem for UDP inetd services
This patch fixes several issues related to the problem of launching
UDP inetd services:

- Make sure to disable O_NONBLOCK on the socket before passing it to
  the inetd service, that's what is expected.  This goes for both UDP
  and TCP (accepted) connections -- there is no guarantee even for TCP
  sockets that they do *not* inherit the parent socket's flags.
- Mark the UDP inetd parent's SVC as busy and stop its watcher before
  starting the child task to service the connection.  The watcher must
  be stopped or multiple child tasks may be spawned!
- Only copy the most relevant parts to the UDP task.  In particular
  must *not* copy the libuEv watcher data to the task!
- With the child task done and the parent inetd service unblocked we
  must restore O_NONBLOCK to the socket before restarting the watcher

When a UDP inetd service connection is handled we create a child task
to service the request, meanwhile we block the parent service.  There
was a problem with blocking the parent since we called inetd_stop(),
which both did a shutdown() and close() of the socket ... this patch
introduces separate handling of blocked (busy) inetd services in the
inetd_stop() function and also make sure to handle restarting the
parent watcher in inetd_start() when the child task is done.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:01:10 +02:00
Joachim Nilsson 7e91cb4afc Minor log message improvements
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:01:10 +02:00
Patrick Stewart 0ba8df5c2d Change stdin member of svc to stdin_fd
'stdin' is a macro in stdio.h, so it shouldn't be used as a member name. GLIBC happens to have "#define stdin stdin", but other libcs don't.
2016-04-13 22:09:05 +01:00
Joachim Nilsson 2e2d87ee78 Update include path for libuEv and libite
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-09 20:33:07 +02:00
Joachim Nilsson 8bcc34ce91 Remove Emacs version-control handling
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-03-21 15:41:51 +01:00
Joachim Nilsson 0704947c33 Merge pull request #20 from westermo/wmo/2.4
inetd reload fixes

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-02-19 15:11:20 +01:00
Tobias Waldekranz 2555fe8e96 inetd: Flush existing filters on reload
Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
2016-02-19 12:53:39 +01:00
Joachim Nilsson 6c91c4ec12 Fix unused variable warning
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-02-05 21:09:31 +01:00
Tobias Waldekranz 6ece4b8fa3 inetd: Re-integrate the inetd subsystem into the new service model
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
2016-01-15 10:07:15 +01:00
Joachim Nilsson 924bf041bc On reload/restart we must wait for services to stop first
This patch adds support for declaring *why* a service is being stopped
or reloaded.  This is later used when all stopped services have been
collected by the `service_monitor()` to issue start or postponed SIGHUP.

As an added benefit we can now also see why a service is not running.
If it has been paused by a user, halted when moving to another runlevel,
waiting for a condition (event), or similar.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-11-22 10:11:27 +01:00
Joachim Nilsson 369fcf2100 Issue #14: Improved support for static Finit builds
- Upgrade libite (LITE) for new UNIX file parser API to improve static
  builds of Finit.
- Re-enable bootmisc plugin for static builds by adding built-in support
  for reading GID from /etc/group.
- Allow inetd support for static builds by adding built-in support for
  reading service and protocol from /etc/services and /etc/protocols.
- Do not try to install/uninstall any plugins for static builds.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-10-26 00:56:50 +01:00
Joachim Nilsson d6490df9a3 inetd.c: Improve error detection in inet port conversion.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-07-10 19:10:28 +02:00
Joachim Nilsson 8b8ddc43b5 Refactor: Further API cleanup -- hide svc_t internals.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-29 01:50:21 +02:00
Joachim Nilsson c6a9fa3b98 initctl: Order inetd filters same as in .conf file.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 19:06:07 +02:00
Joachim Nilsson e04c73bab8 initctl: Add UDP/TCP to presentation of inetd services in verbose mode.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 18:55:05 +02:00
Joachim Nilsson 0de4fb0cbf inetd: Fix naming of built-in service on custom port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 03573b41ca Add support for a deny filter syntax to inetd services
This patch changes the syntax for custom inetd services and adds support
for deny filters.  The new syntax is:

    inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>

This means the second column now defines what@from and the third to/what
process.  For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin.  Here follows a few examples:

    inetd time/udp                    wait [2345] internal                -- UNIX rdate service
    inetd time/tcp                  nowait [2345] internal                -- UNIX rdate service
    inetd 3737/tcp                  nowait [2345] internal.time           -- UNIX rdate service
    inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 2323/tcp@eth1,eth2,eth0   nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 222/tcp@eth0              nowait [2345] /sbin/dropbear -i -R -F -- SSH service
    inetd ssh/tcp@*,!eth0           nowait [2345] /sbin/dropbear -i -R -F -- SSH service

Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`.  The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`.  The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.

NOTE: This patch breaks syntax compatibility with Finit v1.12!

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 14:15:39 +02:00
Joachim Nilsson 1a1f24721f Refactor: introduce telinit and a new initctl tool w/ API
- Reduce size of `helpers.c`, for linking against new `initctl` tool,
  by moving out functions to `pid.c` and `exec.c`
- Add `AF_UNIX` API to Finit, to complement old `/dev/initctl` FIFO
- Let old FIFO API be used by init/telinit: `init <q | 1-9>`
- Move all advanced initctl code from `client.c` to `initctl.c`, yes
  its a bit confusing to call the *new* tool the same as the old FIFO
  but this is more in line with what, e.g Upstart does.
- Move all advanced server side code from `plugins/initctl.c` to `api.c`
- Update TODO with upcoming inetd syntax change and dynamic events.
- Temporarily fix display of inetd services from `initctl status -v`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-13 12:26:16 +02:00
Joachim Nilsson 66edb42e06 Upgrade to libuev v1.2.0
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-09 14:57:41 +02:00
Joachim Nilsson 534979e6c7 inetd_match(): Fix bug in matcher, make sure to also compare protocol!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 00:54:54 +02:00
Joachim Nilsson 97a48ec5fb Refactor: move advanced service methods from svc.c --> service.c
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 03:23:46 +02:00
Joachim Nilsson 687f52b0b5 Add support for adding/removing services from /etc/finit.d at runtime.
This patch adds support for adding and removing services from Finit at
runtime.  Configuration file stanzas for service, run and task may now
be written to files in /etc/finit.d/*.conf, using the exact same syntax
as before in /etc/finit.conf.  When a file is added, removed or modified
the user may simply SIGHUP Finit (PID 1) to activate the changes.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-05-31 01:55:39 +02:00
Joachim Nilsson daa299721d inetd.c: Check for SO_REUSEPORT capability in system first.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 15:54:13 +01:00
Joachim Nilsson 5ddd5c15a5 inetd.c:spawn_socket() - Set socket options for reusing address and port
Without this patch binding to sockets when restarting them fails.  This
was found when quickly changing between runlevels where a service runs,
not runs, then back to a runlevel where is shall run.

Also, refactor previous setsockopt() call to use new common macro.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 15:21:43 +01:00
Joachim Nilsson 957586db09 inetd.c:inetd_dgram_peek() - Fix reading inbound UDP interface.
There seems to have been a regression from earlier when this worked.
I'm sure it worked ... or am I?  This patch makes the whole thing look
a lot more sane, so I wonder ... might have worked in my unit tests on
x86, but not when I cross-compile to ARM.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 15:15:03 +01:00
Joachim Nilsson e0c8a7df66 inetd.c: Shutdown sockets properly before closing them.
When changing runlevels netstat still listed closed sockets as being
open and listening.  With this patch all sockets are properly shut down
before we close them.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 14:45:21 +01:00
Joachim Nilsson 872d0d24e7 inetd.c: Only ever allow respawn if correct runlevel.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 11:48:16 +01:00
Joachim Nilsson 703b7537cf Refactor inetd support to add support for switching runlevels.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-01 02:35:30 +01:00
Joachim Nilsson ded4b3926e Refactor inetd support, now with support for custom ports and iface filtering
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth1:22/tcp  nowait [2345] /usr/sbin/sshd -i

In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively.  Attempting to connect
from any other interface is denied.  Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.

If eth0 is your upstream interface you may want to avoid using the
default port.  To run ssh on port 222, and all others on port 22:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i

This actually adds a deny rule for eth0 on ssh/tcp, implicitly.  You can
even list the services in the reverse order with the same result:

    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i

There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 01:37:11 +01:00
Joachim Nilsson ccdab464c3 Fix Coverity CID 87570: Unchecked return value from setsockopt()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 23:10:30 +01:00
Joachim Nilsson dd7f0ce090 Fix Coverity CID 87571: Uninitialized scalar variable (UNINIT)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:18:02 +01:00
Joachim Nilsson 58cc96115c Initial support for figuring out inbound interface for inetd connections
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.

The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:26:54 +01:00
Joachim Nilsson a5b9f566b3 Initial support for inetd/on-demand services \o/
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:43:15 +01:00