Files
finit/initctl.c
T
Joachim Nilsson 03573b41ca Add support for a deny filter syntax to inetd services
This patch changes the syntax for custom inetd services and adds support
for deny filters.  The new syntax is:

    inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>

This means the second column now defines what@from and the third to/what
process.  For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin.  Here follows a few examples:

    inetd time/udp                    wait [2345] internal                -- UNIX rdate service
    inetd time/tcp                  nowait [2345] internal                -- UNIX rdate service
    inetd 3737/tcp                  nowait [2345] internal.time           -- UNIX rdate service
    inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 2323/tcp@eth1,eth2,eth0   nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 222/tcp@eth0              nowait [2345] /sbin/dropbear -i -R -F -- SSH service
    inetd ssh/tcp@*,!eth0           nowait [2345] /sbin/dropbear -i -R -F -- SSH service

Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`.  The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`.  The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.

NOTE: This patch breaks syntax compatibility with Finit v1.12!

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 14:15:39 +02:00

265 lines
6.4 KiB
C

/* New client tool, complements old /dev/initctl API and telinit tool
*
* Copyright (c) 2015 Joachim Nilsson <troglobit@gmail.com>
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in
* all copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
* THE SOFTWARE.
*/
#include <ctype.h>
#include <getopt.h>
#include <stdio.h>
#include <sys/socket.h>
#include <sys/un.h>
#include "finit.h"
#include "helpers.h"
#include "service.h"
#include "libite/lite.h"
typedef struct {
char *cmd;
int (*cb)(char *arg);
} command_t;
int debug = 0;
int verbose = 0;
static int do_send(struct init_request *rq, ssize_t len)
{
int sd, result = 255;
struct sockaddr_un sun = {
.sun_family = AF_UNIX,
.sun_path = INIT_SOCKET,
};
sd = socket(AF_UNIX, SOCK_STREAM, 0);
if (-1 == sd)
return -1;
if (connect(sd, (struct sockaddr*)&sun, sizeof(sun)) == -1)
goto error;
if (write(sd, rq, len) != len)
goto error;
if (read(sd, rq, len) != len)
goto error;
result = 0;
goto exit;
error:
perror("Failed communicating with finit");
exit:
close(sd);
return result;
}
static int toggle_debug(char *UNUSED(arg))
{
struct init_request rq = {
.magic = INIT_MAGIC,
.cmd = INIT_CMD_DEBUG,
};
return do_send(&rq, sizeof(rq));
}
static int set_runlevel(char *arg)
{
struct init_request rq = {
.magic = INIT_MAGIC,
.cmd = INIT_CMD_RUNLVL,
.runlevel = (int)arg[0],
};
return do_send(&rq, sizeof(rq));
}
static int do_svc(int cmd, char *jobid)
{
struct init_request rq = {
.magic = INIT_MAGIC,
.cmd = cmd,
};
if (!jobid) {
if (cmd == INIT_CMD_RELOAD_SVC) {
rq.cmd = INIT_CMD_RELOAD;
goto exit;
}
return 1;
}
strlcpy(rq.data, jobid, sizeof(rq.data));
exit:
return do_send(&rq, sizeof(rq));
}
static int do_start (char *arg) { return do_svc(INIT_CMD_START_SVC, arg); }
static int do_stop (char *arg) { return do_svc(INIT_CMD_STOP_SVC, arg); }
static int do_reload (char *arg) { return do_svc(INIT_CMD_RELOAD_SVC, arg); }
static int do_restart(char *arg) { return do_svc(INIT_CMD_RESTART_SVC, arg); }
static int show_version(char *UNUSED(arg))
{
puts("v" VERSION);
return 0;
}
/* In verbose mode we skip the header and each service description.
* This in favor of having all info on one line so a machine can more
* easily parse it. */
static int show_status(char *UNUSED(arg))
{
svc_t *svc;
if (!verbose) {
printf("# Status PID Runlevels Service Description\n");
printf("====================================================================================\n");
}
for (svc = svc_iterator(1); svc; svc = svc_iterator(0)) {
int inetd = svc_is_inetd(svc);
char jobid[10];
if (svc_is_unique(svc))
snprintf(jobid, sizeof(jobid), "%d", svc->job);
else
snprintf(jobid, sizeof(jobid), "%d:%d", svc->job, svc->id);
if (verbose) {
int internal = !strcmp("internal", svc->cmd);
char *info, args[80] = "";
struct init_request rq = {
.magic = INIT_MAGIC,
.cmd = INIT_CMD_QUERY_INETD,
};
printf("%-6s %7s %-6d %-9s ", jobid, svc_status(svc), svc->pid, runlevel_string(svc->runlevels));
if (inetd) {
snprintf(rq.data, sizeof(rq.data), "%s", jobid);
if (do_send(&rq, sizeof(rq))) {
snprintf(args, sizeof(args), "Unknown inetd");
info = args;
} else {
info = rq.data;
if (!internal) {
char *ptr = strchr(info, ' ');
if (ptr)
info = ptr + 1;
}
}
printf("%s %s\n", svc->cmd, info);
} else {
int i;
for (i = 1; i < MAX_NUM_SVC_ARGS; i++) {
strlcat(args, svc->args[i], sizeof(args));
strlcat(args, " ", sizeof(args));
}
printf("%s %s\n", svc->cmd, args);
}
} else {
printf("%-6s %7s %-6d %-9s %-20s %s\n", jobid, svc_status(svc), svc->pid,
runlevel_string(svc->runlevels), svc->cmd, svc->desc);
}
}
return 0;
}
static int usage(int rc)
{
fprintf(stderr, "Usage: %s [OPTIONS] <COMMAND>\n\n"
"Options:\n"
" -v, --verbose Verbose output\n"
" -h, --help This help text\n\n"
"Commands:\n"
" debug Toggle Finit debug\n"
" reload Reload *.conf in /etc/finit.d/\n"
" runlevel <0-9> Change runlevel: 0 halt, 6 reboot\n"
" status Show status of services\n"
" start <JOB#> Start stopped service\n"
" stop <JOB#> Stop running service\n"
" restart <JOB#> Restart (stop/start) running service\n"
" reload <JOB#> Reload (SIGHUP) running service\n"
" version Show Finit version\n\n", __progname);
return rc;
}
int main(int argc, char *argv[])
{
int c;
command_t command[] = {
{ "debug", toggle_debug },
{ "reload", do_reload },
{ "runlevel", set_runlevel },
{ "status", show_status },
{ "start", do_start },
{ "stop", do_stop },
{ "restart", do_restart },
{ "version", show_version },
{ NULL, NULL }
};
struct option long_options[] = {
{"help", 0, NULL, 'h'},
{"verbose", 0, NULL, 'v'},
{NULL, 0, NULL, 0}
};
verbose = 0;
while ((c = getopt_long(argc, argv, "h?v", long_options, NULL)) != EOF) {
switch(c) {
case 'h':
case '?':
return usage(0);
case 'v':
verbose = 1;
break;
}
}
if (optind < argc) {
char *cmd = argv[optind++];
char *arg = optind < argc ? argv[optind] : NULL;
for (c = 0; command[c].cmd; c++) {
if (!strcmp(command[c].cmd, cmd))
return command[c].cb(arg);
}
}
return usage(1);
}
/**
* Local Variables:
* version-control: t
* indent-tabs-mode: t
* c-file-style: "linux"
* End:
*/