Commit Graph
441 Commits
Author SHA1 Message Date
Joachim Nilsson b644f6f635 plugins/initctl.c: Minor debug updates.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 11:47:14 +01:00
Joachim Nilsson 510d15195c plugins.c:generic_io_cb() -- Stop watcher before running callback
Stop event watcher before running callback, the plugin may manipulate
the descriptor and cause the kernel into a EPOLLHUP frenzy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 11:46:32 +01:00
Joachim Nilsson 7ad4bce487 Upgrade to libuEv v1.1.0 for error handling fixes.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 11:02:01 +01:00
Joachim Nilsson 703b7537cf Refactor inetd support to add support for switching runlevels.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-01 02:35:30 +01:00
Joachim Nilsson 9cb6c88f34 Spellchecks, cleanup and simplify intro.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-27 10:02:08 +01:00
Joachim Nilsson 97068223ff CHANGELOG: Add user-friendly info on the 1.12 release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-27 00:14:49 +01:00
Joachim Nilsson 1de5777f7e README: Update with new inetd support.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-27 00:14:14 +01:00
Joachim Nilsson aff11d83d8 tty.c: Let fallback shells be consoles, improved job control etc.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 18:57:17 +01:00
Joachim Nilsson 335f09726f conf.c: Slight update in TTY fallback behavior.
If no tty is configured in finit.conf, only use FALLBACK_SHELL (usually
/bin/sh on UNIX) when no console is configured either.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 18:57:10 +01:00
Joachim Nilsson 12c470667f Only restart daemons when getting SIGCONT after SIGSTOP
Fix `restart_any_lost_procs()`, called when finit recovers from being
stopped for a while.  This function should not restart task/run/inetd
services when called -- must check for type `SVC_CMD_SERVICE` when
iterating over all registered `svc_t`, just like a regular lost pid.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:55:15 +01:00
Joachim Nilsson 71ac8bb802 Set hostname early, so boostrap processes, e.g., syslog can use it.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:47:55 +01:00
Joachim Nilsson fc9758da8e Fix Coverity CID #87811 Double close
Fix double close of TCP socket introduced in GIT ded4b39,
replaced with closing all open stdio descriptors, which
shouldn't really be needed.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:39:30 +01:00
Joachim Nilsson 216701ce3c Attempt to fix Coverity CID #87810 Dereference null return value
Fixes, or rather works around the Coverity warning of possible NULL
pointer dereference.  (Not an error.)

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:34:38 +01:00
Joachim Nilsson 5d5075954e TODO: Add some ideas on pmon to watchdog chapter.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:14:29 +01:00
Joachim Nilsson ded4b3926e Refactor inetd support, now with support for custom ports and iface filtering
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth1:22/tcp  nowait [2345] /usr/sbin/sshd -i

In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively.  Attempting to connect
from any other interface is denied.  Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.

If eth0 is your upstream interface you may want to avoid using the
default port.  To run ssh on port 222, and all others on port 22:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i

This actually adds a deny rule for eth0 on ssh/tcp, implicitly.  You can
even list the services in the reverse order with the same result:

    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i

There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 01:37:11 +01:00
Joachim Nilsson 365932510f Update dreamworld.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-25 10:13:44 +01:00
Joachim Nilsson 888128e56b README: Slight cleanup to make it more readable w/o Markdown.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-25 10:13:12 +01:00
Joachim Nilsson 2adec264af Replace atoi() with atonum() --> better error handling.
Friends don't let friends use atoi().

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-25 10:12:15 +01:00
Joachim Nilsson ccdab464c3 Fix Coverity CID 87570: Unchecked return value from setsockopt()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 23:10:30 +01:00
Joachim Nilsson a7353678a3 Actually fix Coverity CID 56281: dlopen() resource leak
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:59:32 +01:00
Joachim Nilsson ad8ae4af91 Fix Coverity CID CID 56281: Resource leak (RESOURCE_LEAK)
Initial support for unloading plugins.  Currently we only save dlopen()
handle.  The plugin_unregister() function itself is never called atm.
This should at the very least make Coverity happy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:39:54 +01:00
Joachim Nilsson dd7f0ce090 Fix Coverity CID 87571: Uninitialized scalar variable (UNINIT)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:18:02 +01:00
Joachim Nilsson 8c955836dd Load plugins before finit.conf is parsed, needed by internal inetd services
This patch is slightly sub-optimal, since it will causes us to load all
availble plugins, not just those referenced by finit.conf.  However, in
the short term perspective we need to reference internal inted services
provided by plugins from finit.conf, so the dependency order is clear.

In the midterm perspective we want to add support for SIGHUP to reload
finit.conf, but not plugins.  So again, this is an OK patch.

One fix would be to allow loading of all plugins, parse finit.conf and
then unload all unused plugins before continuing.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:04:36 +01:00
Joachim Nilsson 183022ebe4 Initial support for RFC 868 (rdate), internal inetd service.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:04:31 +01:00
Joachim Nilsson 33be077f92 TODO: Remember to support non-getty logins.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 16:53:00 +01:00
Joachim Nilsson 6a137fa73c TODO: Update with info on internal inetd services, like time, echo etc.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 15:17:00 +01:00
Joachim Nilsson 25c85dfc88 Add markdown hinting for Emacs.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:27:16 +01:00
Joachim Nilsson 58cc96115c Initial support for figuring out inbound interface for inetd connections
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.

The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:26:54 +01:00
Joachim Nilsson b4b63d3722 Trap segfaults caused by service callbacks in separate process context
This patch traps segfaults caused by 3rd party service callbacks in a
separate process context.  Effectively preventing a single programming
mistake from taking down the entire system.  Previously it was up to the
callback coder to write error free code so that PID 1 did not crash.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:21:03 +01:00
Joachim Nilsson d6efe85a57 Silence launch of inetd services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:57:21 +01:00
Joachim Nilsson 51b27e8372 Revert "Use vfork() instead of fork() before exec()"
This reverts commit 074686b520.  Which
turned out to not work so well after all.  For instance, launching TTYs
in a background process completely blocked inetd services from even
starting up listening sockets ... proper fork seems to work fine though.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:45:09 +01:00
Joachim Nilsson cac612c485 Remember to fix these ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:43:33 +01:00
Joachim Nilsson a5b9f566b3 Initial support for inetd/on-demand services \o/
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:43:15 +01:00
Joachim Nilsson 0d098616e8 Whitespace changes only
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-01 17:28:36 +01:00
Joachim Nilsson 63722a20ac Allow mixed case configuration commands in finit.conf
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-01 17:27:18 +01:00
Joachim Nilsson 6f6ab6bc33 Minor whitespace fixes
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-29 12:34:30 +01:00
Joachim Nilsson 7f0a85c106 Updated inetd syntax and add possible bug, needs investigating.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-29 12:33:35 +01:00
Joachim Nilsson 46ddf4bcc6 Commence new -dev phase.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 23:56:52 +01:00
Joachim Nilsson f5ab075f9d Upgrade libuEv to v1.0.4
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 23:54:53 +01:00
Joachim Nilsson 9b361864fa Fix make dist target for v1.11 release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
1.11
2015-01-24 16:16:13 +01:00
Joachim Nilsson 41b0dc41a6 Update ChangeLog for v1.11 release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 16:13:46 +01:00
Joachim Nilsson cab339c857 Simplify build example.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 16:07:55 +01:00
Joachim Nilsson dcb42602c9 Cleanup README for release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 16:04:54 +01:00
Joachim Nilsson 9e446557b4 Change Coverity Scan branch to use 'dev' instead of master.
We don't want to run out of scan tokens for every README update.  This
also means the introduction of a new workflow.  All new development must
be staged to the dev branch before being merged to master.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-24 15:29:16 +01:00
Joachim Nilsson a3d76c58a4 Expand on how plugins can interact with system bootstrap.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-21 19:34:01 +01:00
Joachim Nilsson e0e0581d10 Trim slogan ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-21 13:29:35 +01:00
Joachim Nilsson ef75d5ec31 Cleanup Introduction and add Bootstrap section.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-21 13:25:24 +01:00
Joachim Nilsson dfeabd8bae Improve inetd syntax proposal
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-21 13:15:16 +01:00
Joachim Nilsson 7aa687bad9 Reindent to more 'pure' Markdown and remove fixed event lib TODO.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-19 21:24:06 +01:00
Joachim Nilsson c2ea2c1193 Reindent to more 'pure' Markdown.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-19 21:12:14 +01:00