These two new hooks run when SIGHUP is received and when changing
system runlevel. The hooks are called when all services have been
stopped, just before starting up new/modified services. Making it
the perfect hook for reconfiguring the system/hardware before new
services or modified services are started up again.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When receiving SIGCHLD we must reap *all* children. We only receive one
signal, but multiple processes may have exited.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for starting and supervising multiple
services (run, task, or service) using an extra #ID number.
service #1 [2345] /sbin/httpd -f -h /http -p 80 -- Web server
service #2 [2345] /sbin/httpd -f -h /http -p 8080 -- Old web server
Also included in this patch is a fix for endless respawn of faulty
services. For instance, a buggy daemon that crashes repeatedly will now
be stopped after 10 respawns.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for adding and removing services from Finit at
runtime. Configuration file stanzas for service, run and task may now
be written to files in /etc/finit.d/*.conf, using the exact same syntax
as before in /etc/finit.conf. When a file is added, removed or modified
the user may simply SIGHUP Finit (PID 1) to activate the changes.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When a user changes runlevel, or wants to reload the config, we want the
command to return only when the operation has completed. For instance,
rolling in a new system configuration in runlevel 1 requires that we are
sure we've actually entered that runlevel before rolling it in.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for a configure script and with it
support for disabling inetd support. See the output from
./configure --help
* Add configure script
* Sprinkle #ifdef fairy dust on svc.c when inetd support is disabled
* Use GCC built-in autodep calculator (-MMD -MP)
* Fix name space issue with include files, use relative paths
* Disable username/group name to uid/gid functions in static builds
* Bug out (error) if a user tries to build the bootmisc plugin static
Possibly fixes GitHub issue #5 and issue #6.
NOTE: The static build has not received any testing at all!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adresses issue #5. However, there still remains a few issues
to work around before Finit can be built completely standalone.
$ make clean all STATIC=1
LINK finit
helpers.o: In function `getgroup':
helpers.c:(.text+0x10a7): warning: Using 'getgrnam' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
helpers.o: In function `getuser':
helpers.c:(.text+0x108e): warning: Using 'getpwnam' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
inetd.o: In function `getent':
inetd.c:(.text+0x127): warning: Using 'getprotobyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
inetd.c:(.text+0xce): warning: Using 'getservbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
The problem is the NSS plugins and similar issues that prevent static
linking when using the above functions. See issue #5 for more on this.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Without this patch binding to sockets when restarting them fails. This
was found when quickly changing between runlevels where a service runs,
not runs, then back to a runlevel where is shall run.
Also, refactor previous setsockopt() call to use new common macro.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
There seems to have been a regression from earlier when this worked.
I'm sure it worked ... or am I? This patch makes the whole thing look
a lot more sane, so I wonder ... might have worked in my unit tests on
x86, but not when I cross-compile to ARM.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When changing runlevels netstat still listed closed sockets as being
open and listening. With this patch all sockets are properly shut down
before we close them.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
With O_CLOEXEC we prevent forked+exec'ed children from accessing the
initctl fifo via that socket.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Stop event watcher before running callback, the plugin may manipulate
the descriptor and cause the kernel into a EPOLLHUP frenzy.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If no tty is configured in finit.conf, only use FALLBACK_SHELL (usually
/bin/sh on UNIX) when no console is configured either.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix `restart_any_lost_procs()`, called when finit recovers from being
stopped for a while. This function should not restart task/run/inetd
services when called -- must check for type `SVC_CMD_SERVICE` when
iterating over all registered `svc_t`, just like a regular lost pid.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix double close of TCP socket introduced in GIT ded4b39,
replaced with closing all open stdio descriptors, which
shouldn't really be needed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fixes, or rather works around the Coverity warning of possible NULL
pointer dereference. (Not an error.)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth1:22/tcp nowait [2345] /usr/sbin/sshd -i
In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively. Attempting to connect
from any other interface is denied. Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.
If eth0 is your upstream interface you may want to avoid using the
default port. To run ssh on port 222, and all others on port 22:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
This actually adds a deny rule for eth0 on ssh/tcp, implicitly. You can
even list the services in the reverse order with the same result:
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>