We cannot clear the svc_t memory because other applications may have
connected to the same shared memory. An application may be inspecting
the current list of services (initctl) and pulling the rug from under
them could cause some really unpredicatble results.
This reverts commit 06d1e90bac.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.
As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
Stopped services are now (again) listed as "stopped" and halted
services, due to a runlevel change, are listed as "halted". Several
users complained that this change was just not intuitive. I agreee.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Leverage new svc_t states in initctl status/show output. Also, ensure
different svc_t types have correct start state.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit. When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances. For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The new iterators `svc_inetd_iterator()` and `svc_dynamic_iterator()`
used unsafe constructs that could cause them, at least the latter, to
dereference a `NULL` pointer.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
- Reduce size of `helpers.c`, for linking against new `initctl` tool,
by moving out functions to `pid.c` and `exec.c`
- Add `AF_UNIX` API to Finit, to complement old `/dev/initctl` FIFO
- Let old FIFO API be used by init/telinit: `init <q | 1-9>`
- Move all advanced initctl code from `client.c` to `initctl.c`, yes
its a bit confusing to call the *new* tool the same as the old FIFO
but this is more in line with what, e.g Upstart does.
- Move all advanced server side code from `plugins/initctl.c` to `api.c`
- Update TODO with upcoming inetd syntax change and dynamic events.
- Temporarily fix display of inetd services from `initctl status -v`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch further extends the capabilities of the client with the
ability to control the running state of services:
finit <stop|start|reload|restart> JOB
Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch. A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier. See the output of `finit status` for the JOB id.
Also, with the introduction of multiple instances we broke support for
multiple related inetd services. This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
These two new hooks run when SIGHUP is received and when changing
system runlevel. The hooks are called when all services have been
stopped, just before starting up new/modified services. Making it
the perfect hook for reconfiguring the system/hardware before new
services or modified services are started up again.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for starting and supervising multiple
services (run, task, or service) using an extra #ID number.
service #1 [2345] /sbin/httpd -f -h /http -p 80 -- Web server
service #2 [2345] /sbin/httpd -f -h /http -p 8080 -- Old web server
Also included in this patch is a fix for endless respawn of faulty
services. For instance, a buggy daemon that crashes repeatedly will now
be stopped after 10 respawns.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for adding and removing services from Finit at
runtime. Configuration file stanzas for service, run and task may now
be written to files in /etc/finit.d/*.conf, using the exact same syntax
as before in /etc/finit.conf. When a file is added, removed or modified
the user may simply SIGHUP Finit (PID 1) to activate the changes.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for a configure script and with it
support for disabling inetd support. See the output from
./configure --help
* Add configure script
* Sprinkle #ifdef fairy dust on svc.c when inetd support is disabled
* Use GCC built-in autodep calculator (-MMD -MP)
* Fix name space issue with include files, use relative paths
* Disable username/group name to uid/gid functions in static builds
* Bug out (error) if a user tries to build the bootmisc plugin static
Possibly fixes GitHub issue #5 and issue #6.
NOTE: The static build has not received any testing at all!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix `restart_any_lost_procs()`, called when finit recovers from being
stopped for a while. This function should not restart task/run/inetd
services when called -- must check for type `SVC_CMD_SERVICE` when
iterating over all registered `svc_t`, just like a regular lost pid.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix double close of TCP socket introduced in GIT ded4b39,
replaced with closing all open stdio descriptors, which
shouldn't really be needed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fixes, or rather works around the Coverity warning of possible NULL
pointer dereference. (Not an error.)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth1:22/tcp nowait [2345] /usr/sbin/sshd -i
In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively. Attempting to connect
from any other interface is denied. Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.
If eth0 is your upstream interface you may want to avoid using the
default port. To run ssh on port 222, and all others on port 22:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
This actually adds a deny rule for eth0 on ssh/tcp, implicitly. You can
even list the services in the reverse order with the same result:
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch is slightly sub-optimal, since it will causes us to load all
availble plugins, not just those referenced by finit.conf. However, in
the short term perspective we need to reference internal inted services
provided by plugins from finit.conf, so the dependency order is clear.
In the midterm perspective we want to add support for SIGHUP to reload
finit.conf, but not plugins. So again, this is an OK patch.
One fix would be to allow loading of all plugins, parse finit.conf and
then unload all unused plugins before continuing.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.
The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch traps segfaults caused by 3rd party service callbacks in a
separate process context. Effectively preventing a single programming
mistake from taking down the entire system. Previously it was up to the
callback coder to write error free code so that PID 1 did not crash.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This reverts commit 074686b520. Which
turned out to not work so well after all. For instance, launching TTYs
in a background process completely blocked inetd services from even
starting up listening sockets ... proper fork seems to work fine though.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>