Stop event watcher before running callback, the plugin may manipulate
the descriptor and cause the kernel into a EPOLLHUP frenzy.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If no tty is configured in finit.conf, only use FALLBACK_SHELL (usually
/bin/sh on UNIX) when no console is configured either.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix `restart_any_lost_procs()`, called when finit recovers from being
stopped for a while. This function should not restart task/run/inetd
services when called -- must check for type `SVC_CMD_SERVICE` when
iterating over all registered `svc_t`, just like a regular lost pid.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix double close of TCP socket introduced in GIT ded4b39,
replaced with closing all open stdio descriptors, which
shouldn't really be needed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fixes, or rather works around the Coverity warning of possible NULL
pointer dereference. (Not an error.)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth1:22/tcp nowait [2345] /usr/sbin/sshd -i
In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively. Attempting to connect
from any other interface is denied. Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.
If eth0 is your upstream interface you may want to avoid using the
default port. To run ssh on port 222, and all others on port 22:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
This actually adds a deny rule for eth0 on ssh/tcp, implicitly. You can
even list the services in the reverse order with the same result:
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Initial support for unloading plugins. Currently we only save dlopen()
handle. The plugin_unregister() function itself is never called atm.
This should at the very least make Coverity happy.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch is slightly sub-optimal, since it will causes us to load all
availble plugins, not just those referenced by finit.conf. However, in
the short term perspective we need to reference internal inted services
provided by plugins from finit.conf, so the dependency order is clear.
In the midterm perspective we want to add support for SIGHUP to reload
finit.conf, but not plugins. So again, this is an OK patch.
One fix would be to allow loading of all plugins, parse finit.conf and
then unload all unused plugins before continuing.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.
The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch traps segfaults caused by 3rd party service callbacks in a
separate process context. Effectively preventing a single programming
mistake from taking down the entire system. Previously it was up to the
callback coder to write error free code so that PID 1 did not crash.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This reverts commit 074686b520. Which
turned out to not work so well after all. For instance, launching TTYs
in a background process completely blocked inetd services from even
starting up listening sockets ... proper fork seems to work fine though.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We don't want to run out of scan tokens for every README update. This
also means the introduction of a new workflow. All new development must
be staged to the dev branch before being merged to master.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>