Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel. As a result, the recv() buffer can be reduced
down to 4k again.
Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling. If we get ENOBUFS in resync, we
are screwed anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.
This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used. We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop. Plan is to refactor this mess in a later commit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly. Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.
When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:
1. deassert all net/ conditions
2. open a new (temporary) netlink socket
3. send RTM_GETLINK and re-assert all interfaces using nl_link()
4. send RTM_GETROUTE and re-assert all routes with nl_route()
Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves. This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.
The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down. When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name. This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c
https://code.woboq.org/linux/linux/net/core/dev.c.html#1020
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check if ifname contains double periods, this should *not* be a valid
name, though eth0.10 is, et0..10 is not. Should protect better against
directory traversal attacks.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check for spaces and slashes in interface name to prevent path based
attacks. Found by Coverity Scan.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
An interface may come up with IFF_RUNNING already set, but we would
only detect IFF_UP. This patch simplfies the code a lot by pivoting
the qualifier from using ifi_change to ifi_flags, which is the actual
current status of an interface.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We never get any NEWLINK message for lo since it as an interface exists
very early. So we add this workaround when lo comes up so services can
depend on exists for lo as well as for other interfaces.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
When building a static Finit the plugins do not get a unique name
automatically from the file. This led to only the first plugin being
loaded, since its name was 'unknown' it was registered as such and all
other plugins conflicted, since 'unknown' was already ... known and
loaded.
This patch gives all plugins a default name, __FILE__, making it
possible to use all of them when building a static Finit.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit adds support for event based services to Finit. Along with
the previously added support for multiple instances of the same process,
the feature scope for Finit v2.0 has been reached!
As of now a service can be declared in /etc/finit.conf or /etc/finit.d/
like this:
service :1 [2345] <!IFUP:eth0,GW> /sbin/dropbear -R -F -p 22 -- SSH daemon
Here the first instance `:1` of dropbear is declared to run in runlevels
2-5, but only if eth0 `IFUP:eth0` is up and a gateway `GW` is set. When
the configuration changes, a new gateway is set, or somehow a new `IFUP`
event for eth0 is received, then dropbear is not SIGHUP'ed, but instead
stop-started `<!>`. The latter trick applies to all services, even
those that do not define any events.
Currently inetd services are not supported for event based starting, but
it could easily be added. Likely scenario is to deny incoming requests
on, e.g., eth0 if there is no gateway.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>