Without this patch binding to sockets when restarting them fails. This
was found when quickly changing between runlevels where a service runs,
not runs, then back to a runlevel where is shall run.
Also, refactor previous setsockopt() call to use new common macro.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
There seems to have been a regression from earlier when this worked.
I'm sure it worked ... or am I? This patch makes the whole thing look
a lot more sane, so I wonder ... might have worked in my unit tests on
x86, but not when I cross-compile to ARM.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When changing runlevels netstat still listed closed sockets as being
open and listening. With this patch all sockets are properly shut down
before we close them.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth1:22/tcp nowait [2345] /usr/sbin/sshd -i
In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively. Attempting to connect
from any other interface is denied. Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.
If eth0 is your upstream interface you may want to avoid using the
default port. To run ssh on port 222, and all others on port 22:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
This actually adds a deny rule for eth0 on ssh/tcp, implicitly. You can
even list the services in the reverse order with the same result:
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.
The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>