Compare commits
82 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3fdca86988 | ||
|
|
19d001a3d2 | ||
|
|
a87333fa2e | ||
|
|
a192cc0244 | ||
|
|
61bb1ddb16 | ||
|
|
4e92b4d4d3 | ||
|
|
1183e1fae1 | ||
|
|
e9e47118fd | ||
| 57003fcd33 | |||
|
|
1ce2df7c19 | ||
|
|
2d054054d6 | ||
|
|
2791b45cb0 | ||
|
|
b1b78cba9f | ||
|
|
56be75c641 | ||
|
|
c96f805990 |
||
|
|
3e8facaf86 | ||
| 58c8325db1 | |||
|
|
6f26ec9057 | ||
|
|
c53f29e0f2 | ||
|
|
cbd04012d9 | ||
|
|
1efe6840e8 | ||
|
|
d039cd1126 | ||
| 6cd4261cfc | |||
|
|
af58233d58 | ||
|
|
ad4bb86a1d | ||
|
|
333ba8c787 | ||
|
|
fa27fb3ef0 | ||
|
|
07951ec3fc | ||
|
|
d582efc717 | ||
|
|
59859d45af | ||
|
|
b7bfdb9d73 | ||
|
|
9e3440354e | ||
|
|
492bfbdc86 | ||
|
|
2386b7c722 | ||
|
|
575aba85b7 | ||
|
|
165251f091 | ||
|
|
11b009e37c | ||
|
|
cf35130420 | ||
|
|
63004d1702 | ||
|
|
620e84db8e | ||
|
|
8b25de519c | ||
|
|
8335f46295 | ||
|
|
82eddd5b4d | ||
|
|
8be953dc1f | ||
|
|
49f479d3ff | ||
|
|
5ae7170961 | ||
|
|
7b9af589de | ||
|
|
d038b39414 | ||
|
|
23ddc9f8a3 | ||
|
|
c789a7586f | ||
|
|
eced601a88 | ||
|
|
49f62e47db | ||
|
|
ee9dff33c4 | ||
|
|
f1cc4e9d32 | ||
|
|
41152253b1 | ||
|
|
84f1870618 | ||
|
|
7de7f60c17 | ||
|
|
188e1584f7 | ||
|
|
c92212b826 | ||
|
|
e4eaa39d98 | ||
|
|
0ed034f7e8 | ||
|
|
05d81c0613 | ||
|
|
f48798436d | ||
|
|
7888d11c91 | ||
|
|
19197c2db5 | ||
|
|
10720bbfa3 | ||
|
|
66e1c3bfce | ||
|
|
06f78f0c08 | ||
|
|
78135a135a | ||
|
|
ba9603988b | ||
|
|
8c191cf66a | ||
|
|
c7a1500930 | ||
|
|
b84edf6c34 | ||
|
|
3e022482d1 | ||
|
|
3354bbb91e | ||
|
|
811e1c67fe | ||
|
|
e476844265 | ||
|
|
ad2263a160 | ||
|
|
6a4c285fa7 | ||
|
|
cd9fff6d3d | ||
|
|
e2ea81b149 | ||
|
|
99c943080a |
16 changed files with 1 additions and 1631 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -1 +0,0 @@
|
|||
xinetd-2.3.14.tar.gz
|
||||
1
dead.package
Normal file
1
dead.package
Normal file
|
|
@ -0,0 +1 @@
|
|||
Orphaned for 6+ weeks
|
||||
1
sources
1
sources
|
|
@ -1 +0,0 @@
|
|||
567382d7972613090215c6c54f9b82d9 xinetd-2.3.14.tar.gz
|
||||
|
|
@ -1,22 +0,0 @@
|
|||
--- xinetd/Makefile.in.pie 2003-06-07 09:47:24.000000000 -0700
|
||||
+++ xinetd/Makefile.in 2003-10-28 10:59:55.000000000 -0800
|
||||
@@ -119,7 +119,7 @@
|
||||
$(CC) $(CFLAGS) $(DEBUG) $(SRCDIR)/itox.c -o $@ $(LDFLAGS) $(LIBS)
|
||||
|
||||
xinetd: $(OBJS)
|
||||
- $(CC) $(CFLAGS) $(DEBUG) -o $@ $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
|
||||
+ $(CC) $(CFLAGS) $(DEBUG) -o $@ -PIE $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
|
||||
|
||||
clean:
|
||||
rm -f $(OBJS) $(NAME) core itox
|
||||
--- Makefile.in.pie 2003-10-28 10:54:39.000000000 -0800
|
||||
+++ Makefile.in 2003-10-28 10:54:39.000000000 -0800
|
||||
@@ -14,7 +14,7 @@
|
||||
|
||||
LIBS = -lsio -lstr -lmisc -lxlog -lportable -lpset @LIBS@
|
||||
|
||||
-CFLAGS += @CFLAGS@
|
||||
+CFLAGS += @CFLAGS@ -fPIE
|
||||
DCFLAGS = -Wall -Wredundant-decls -W -Wfloat-equal -Wundef -Wcast-qual -Wwrite-strings -Wconversion -Wmissing-noreturn -Wmissing-format-attribute -Wshadow -Wpointer-arith -g
|
||||
|
||||
|
||||
|
|
@ -1,22 +0,0 @@
|
|||
--- xinetd/Makefile.in.pie 2003-06-07 09:47:24.000000000 -0700
|
||||
+++ xinetd/Makefile.in 2003-10-28 10:59:55.000000000 -0800
|
||||
@@ -119,7 +119,7 @@
|
||||
$(CC) $(CFLAGS) $(DEBUG) $(SRCDIR)/itox.c -o $@ $(LDFLAGS) $(LIBS)
|
||||
|
||||
xinetd: $(OBJS)
|
||||
- $(CC) $(CFLAGS) $(DEBUG) -o $@ $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
|
||||
+ $(CC) $(CFLAGS) $(DEBUG) -o $@ -pie $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
|
||||
|
||||
clean:
|
||||
rm -f $(OBJS) $(NAME) core itox
|
||||
--- Makefile.in.pie 2003-10-28 10:54:39.000000000 -0800
|
||||
+++ Makefile.in 2003-10-28 10:54:39.000000000 -0800
|
||||
@@ -14,7 +14,7 @@
|
||||
|
||||
LIBS = -lsio -lstr -lmisc -lxlog -lportable -lpset @LIBS@
|
||||
|
||||
-CFLAGS += @CFLAGS@
|
||||
+CFLAGS += @CFLAGS@ -fpie
|
||||
DCFLAGS = -Wall -Wredundant-decls -W -Wfloat-equal -Wundef -Wcast-qual -Wwrite-strings -Wconversion -Wmissing-noreturn -Wmissing-format-attribute -Wshadow -Wpointer-arith -g
|
||||
|
||||
|
||||
|
|
@ -1,34 +0,0 @@
|
|||
--- xinetd-2.3.12/xinetd/service.c.tcp_rpc 2003-06-27 21:05:06.000000000 -0400
|
||||
+++ xinetd-2.3.12/xinetd/service.c 2004-01-29 23:09:29.000000000 -0500
|
||||
@@ -181,6 +181,9 @@
|
||||
else
|
||||
memset( &tsin, 0, sizeof(tsin));
|
||||
|
||||
+ if ( SC_PROTOVAL ( scp ) == IPPROTO_TCP ) {
|
||||
+ M_SET ( scp->sc_xflags, SF_NOLIBWRAP );
|
||||
+ }
|
||||
if( SC_IPV4( scp ) ) {
|
||||
tsin.sa_in.sin_family = AF_INET ;
|
||||
sin_len = sizeof(struct sockaddr_in);
|
||||
--- xinetd-2.3.12/xinetd/xinetd.conf.man.tcp_rpc 2004-01-30 12:38:59.000000000 -0500
|
||||
+++ xinetd-2.3.12/xinetd/xinetd.conf.man 2004-01-30 12:43:50.000000000 -0500
|
||||
@@ -123,6 +123,8 @@
|
||||
to the service. This may be needed in order to use libwrap functionality
|
||||
not available to long-running processes such as xinetd; in this case,
|
||||
the tcpd program can be called explicitly (see also the NAMEINARGS flag).
|
||||
+For RPC services using TCP transport, this flag is automatically turned on,
|
||||
+because xinetd cannot get remote host address information for the rpc port.
|
||||
.TP
|
||||
.B SENSOR
|
||||
This replaces the service with a sensor that detects accesses to the
|
||||
@@ -1215,6 +1217,10 @@
|
||||
access control on the address of the remote host is not performed when
|
||||
\fIwait\fP is \fIyes\fP and \fIsocket_type\fP is \fIstream\fP.
|
||||
.LP
|
||||
+The NOLIBWRAP flag is automatically turned on for RPC services whose
|
||||
+\fIsocket_type\fP is \fIstream\fP because xinetd cannot determine the
|
||||
+address of the remote host.
|
||||
+.LP
|
||||
If the
|
||||
.B INTERCEPT
|
||||
flag is not used,
|
||||
|
|
@ -1,29 +0,0 @@
|
|||
--- xinetd-2.3.14/xinetd/service.c.old 2007-05-16 15:33:41.000000000 +0200
|
||||
+++ xinetd-2.3.14/xinetd/service.c 2007-05-16 15:29:53.000000000 +0200
|
||||
@@ -335,6 +335,15 @@
|
||||
|
||||
if ( SVC_FD(sp) == -1 )
|
||||
{
|
||||
+ if (SC_BIND_ADDR(scp) == NULL && SC_IPV6( scp ))
|
||||
+ {
|
||||
+ /* there was no bind address configured and IPv6 fails. Try IPv4 */
|
||||
+ msg( LOG_NOTICE, func, "IPv6 socket creation failed for service %s, trying IPv4", SC_ID( scp ) ) ;
|
||||
+ M_CLEAR(SC_XFLAGS(scp), SF_IPV6);
|
||||
+ M_SET(SC_XFLAGS(scp), SF_IPV4);
|
||||
+ return svc_activate(sp);
|
||||
+ }
|
||||
+
|
||||
msg( LOG_ERR, func,
|
||||
"socket creation failed (%m). service = %s", SC_ID( scp ) ) ;
|
||||
return( FAILED ) ;
|
||||
--- xinetd-2.3.14/xinetd/confparse.c.old 2007-05-16 15:33:26.000000000 +0200
|
||||
+++ xinetd-2.3.14/xinetd/confparse.c 2007-05-16 15:15:22.000000000 +0200
|
||||
@@ -245,7 +245,7 @@
|
||||
M_SET(SC_XFLAGS(scp), SF_IPV6);
|
||||
}
|
||||
else
|
||||
- M_SET(SC_XFLAGS(scp), SF_IPV4);
|
||||
+ M_SET(SC_XFLAGS(scp), SF_IPV6); /*try bind IPv6 by default*/
|
||||
}
|
||||
|
||||
if (SC_ORIG_BIND_ADDR(scp))
|
||||
|
|
@ -1,110 +0,0 @@
|
|||
diff -rup xinetd-2.3.14-orig/xinetd/child.c xinetd-2.3.14/xinetd/child.c
|
||||
--- xinetd-2.3.14-orig/xinetd/child.c 2006-11-28 14:03:07.000000000 -0500
|
||||
+++ xinetd-2.3.14/xinetd/child.c 2006-11-29 17:04:19.000000000 -0500
|
||||
@@ -33,6 +33,8 @@
|
||||
#endif
|
||||
#ifdef LABELED_NET
|
||||
#include <selinux/selinux.h>
|
||||
+#include <selinux/flask.h>
|
||||
+#include <selinux/context.h>
|
||||
#endif
|
||||
|
||||
#include "str.h"
|
||||
@@ -49,7 +51,7 @@
|
||||
|
||||
/* Local declarations */
|
||||
#ifdef LABELED_NET
|
||||
-static int set_context_from_socket( int fd );
|
||||
+static int set_context_from_socket( const struct service_config *scp, int fd );
|
||||
#endif
|
||||
|
||||
|
||||
@@ -158,7 +160,7 @@ void exec_server( const struct server *s
|
||||
#ifdef LABELED_NET
|
||||
if (SC_LABELED_NET(scp))
|
||||
{
|
||||
- if (set_context_from_socket( descriptor ) < 0) {
|
||||
+ if (set_context_from_socket( scp, descriptor ) < 0) {
|
||||
msg( LOG_ERR, func,
|
||||
"Changing process context failed for %s", SC_ID( scp )) ;
|
||||
_exit( 1 ) ;
|
||||
@@ -485,16 +487,11 @@ void child_exit(void)
|
||||
}
|
||||
|
||||
#ifdef LABELED_NET
|
||||
-static int set_context_from_socket( int fd )
|
||||
+static int set_context( security_context_t cntx )
|
||||
{
|
||||
- const char *func = "set_context_from_socket" ;
|
||||
- security_context_t peer_context;
|
||||
+ const char *func = "set_context" ;
|
||||
|
||||
- if (getpeercon(fd, &peer_context) < 0)
|
||||
- return -1;
|
||||
-
|
||||
- int retval = setexeccon(peer_context);
|
||||
- freecon( peer_context );
|
||||
+ int retval = setexeccon(cntx);
|
||||
|
||||
if (debug.on)
|
||||
{
|
||||
@@ -513,4 +510,59 @@ static int set_context_from_socket( int
|
||||
|
||||
return retval;
|
||||
}
|
||||
+
|
||||
+static int set_context_from_socket( const struct service_config *scp, int fd )
|
||||
+{
|
||||
+ security_context_t curr_context = NULL;
|
||||
+ security_context_t peer_context = NULL;
|
||||
+ security_context_t exec_context = NULL;
|
||||
+ context_t bcon = NULL;
|
||||
+ context_t pcon = NULL;
|
||||
+ security_context_t new_context = NULL;
|
||||
+ security_context_t new_exec_context = NULL;
|
||||
+ int retval = -1;
|
||||
+ const char *exepath = NULL;
|
||||
+
|
||||
+ if (getcon(&curr_context) < 0)
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (getpeercon(fd, &peer_context) < 0)
|
||||
+ goto fail;
|
||||
+
|
||||
+ exepath = SC_SERVER( scp );
|
||||
+ if (getfilecon(exepath, &exec_context) < 0)
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!(bcon = context_new(curr_context)))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!(pcon = context_new(peer_context)))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!context_range_get(pcon))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (context_range_set(bcon, context_range_get(pcon)))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!(new_context = context_str(bcon)))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (security_compute_create(new_context, exec_context, SECCLASS_PROCESS,
|
||||
+ &new_exec_context) < 0)
|
||||
+ goto fail;
|
||||
+
|
||||
+ retval = set_context(new_exec_context);
|
||||
+
|
||||
+ freecon(new_exec_context);
|
||||
+
|
||||
+ fail:
|
||||
+ context_free(pcon);
|
||||
+ context_free(bcon);
|
||||
+ freecon(exec_context);
|
||||
+ freecon(peer_context);
|
||||
+ freecon(curr_context);
|
||||
+
|
||||
+ return retval;
|
||||
+}
|
||||
#endif
|
||||
|
|
@ -1,42 +0,0 @@
|
|||
448069: xinetd: socket bind: Invalid argument (errno = 22) when using USERID on ipv6
|
||||
|
||||
Use right size of addresses in bind() call. Also use getpeername addresses when
|
||||
connecting to ident service to prevent address family mismatch between socket(),
|
||||
bind() and connect() calls.
|
||||
|
||||
Author: Jan Safranek <jsafrane@redhat.com>
|
||||
Reviewed-By: Adam Tkac <atkac@redhat.com>
|
||||
|
||||
diff -up xinetd-2.3.14/xinetd/ident.c.orig xinetd-2.3.14/xinetd/ident.c
|
||||
--- xinetd-2.3.14/xinetd/ident.c.orig 2008-05-29 16:30:19.000000000 +0200
|
||||
+++ xinetd-2.3.14/xinetd/ident.c 2008-05-29 16:29:57.000000000 +0200
|
||||
@@ -97,7 +98,13 @@ idresult_e log_remote_user( const struct
|
||||
}
|
||||
|
||||
CLEAR( sin_contact );
|
||||
- sin_remote = *CONN_XADDRESS( SERVER_CONNECTION( serp ) ) ;
|
||||
+
|
||||
+ sin_len = sizeof( sin_remote );
|
||||
+ if ( getpeername( SERVER_FD( serp ), &sin_remote.sa, &sin_len ) == -1 )
|
||||
+ {
|
||||
+ msg( LOG_ERR, func, "(%d) getpeername: %m", getpid() ) ;
|
||||
+ return( IDR_ERROR ) ;
|
||||
+ }
|
||||
sin_contact = sin_remote;
|
||||
memcpy( &sin_bind, &sin_local, sizeof(sin_bind) ) ;
|
||||
local_port = 0;
|
||||
@@ -121,7 +128,13 @@ idresult_e log_remote_user( const struct
|
||||
msg( LOG_ERR, func, "socket creation: %m" ) ;
|
||||
return( IDR_ERROR ) ;
|
||||
}
|
||||
- if ( bind(sd, &sin_bind.sa, sizeof(sin_bind.sa)) == -1 )
|
||||
+
|
||||
+ if ( sin_bind.sa.sa_family == AF_INET )
|
||||
+ sin_len = sizeof( sin_bind.sa_in ) ;
|
||||
+ else
|
||||
+ sin_len = sizeof( sin_bind.sa_in6 ) ;
|
||||
+
|
||||
+ if ( bind(sd, &sin_bind.sa, sin_len) == -1 )
|
||||
{
|
||||
msg( LOG_ERR, func, "socket bind: %m" ) ;
|
||||
(void) Sclose( sd ) ;
|
||||
|
|
@ -1,227 +0,0 @@
|
|||
diff -urp xinetd-2.3.14.orig/config.h.in xinetd-2.3.14/config.h.in
|
||||
--- xinetd-2.3.14.orig/config.h.in 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/config.h.in 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -112,6 +112,7 @@
|
||||
/* Options */
|
||||
#undef HAVE_LIBWRAP
|
||||
#undef LIBWRAP
|
||||
+#undef LABELED_NET
|
||||
|
||||
#undef HAVE_LOADAVG
|
||||
|
||||
diff -urp xinetd-2.3.14.orig/configure.in xinetd-2.3.14/configure.in
|
||||
--- xinetd-2.3.14.orig/configure.in 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/configure.in 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -289,6 +289,34 @@ AC_ARG_WITH(libwrap,
|
||||
AC_MSG_RESULT(no)
|
||||
)
|
||||
|
||||
+AC_MSG_CHECKING(whether to use labeled-networking)
|
||||
+AC_ARG_WITH(labeled-networking,
|
||||
+[ --with-labeled-networking[=PATH] Compile in labeled networking support.],
|
||||
+[ case "$withval" in
|
||||
+ no)
|
||||
+ AC_MSG_RESULT(no)
|
||||
+ ;;
|
||||
+ yes)
|
||||
+ AC_MSG_RESULT(yes)
|
||||
+ AC_CHECK_LIB(selinux, setexeccon, [
|
||||
+ AC_DEFINE(LABELED_NET)
|
||||
+ LABELLIBS="-lselinux" ])
|
||||
+ LIBS="$LABELLIBS $LIBS"
|
||||
+ ;;
|
||||
+ *)
|
||||
+ AC_MSG_RESULT(yes)
|
||||
+ AC_DEFINE(LABELED_NET)
|
||||
+ if test -d "$withval"; then
|
||||
+ LABELLIBS="-L$withval -lselinux"
|
||||
+ else
|
||||
+ LABELLIBS="$withval"
|
||||
+ fi
|
||||
+ LIBS="$LABELLIBS $LIBS"
|
||||
+ ;;
|
||||
+ esac ],
|
||||
+ AC_MSG_RESULT(no)
|
||||
+)
|
||||
+
|
||||
AC_FUNC_MMAP
|
||||
|
||||
AC_CHECK_FUNCS(isatty)
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/child.c xinetd-2.3.14/xinetd/child.c
|
||||
--- xinetd-2.3.14.orig/xinetd/child.c 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/child.c 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -31,6 +31,9 @@
|
||||
#ifdef HAVE_NETDB_H
|
||||
#include <netdb.h>
|
||||
#endif
|
||||
+#ifdef LABELED_NET
|
||||
+#include <selinux/selinux.h>
|
||||
+#endif
|
||||
|
||||
#include "str.h"
|
||||
#include "child.h"
|
||||
@@ -44,6 +47,12 @@
|
||||
#include "options.h"
|
||||
#include "redirect.h"
|
||||
|
||||
+/* Local declarations */
|
||||
+#ifdef LABELED_NET
|
||||
+static int set_context_from_socket( int fd );
|
||||
+#endif
|
||||
+
|
||||
+
|
||||
/*
|
||||
* This function is running in the new process
|
||||
*/
|
||||
@@ -143,6 +152,20 @@ void exec_server( const struct server *s
|
||||
}
|
||||
#endif
|
||||
|
||||
+ /*
|
||||
+ Set the context if the option was given
|
||||
+ */
|
||||
+#ifdef LABELED_NET
|
||||
+ if (SC_LABELED_NET(scp))
|
||||
+ {
|
||||
+ if (set_context_from_socket( descriptor ) < 0) {
|
||||
+ msg( LOG_ERR, func,
|
||||
+ "Changing process context failed for %s", SC_ID( scp )) ;
|
||||
+ _exit( 1 ) ;
|
||||
+ }
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
(void) Sclose( descriptor ) ;
|
||||
|
||||
#ifndef solaris
|
||||
@@ -461,3 +484,33 @@ void child_exit(void)
|
||||
}
|
||||
}
|
||||
|
||||
+#ifdef LABELED_NET
|
||||
+static int set_context_from_socket( int fd )
|
||||
+{
|
||||
+ const char *func = "set_context_from_socket" ;
|
||||
+ security_context_t peer_context;
|
||||
+
|
||||
+ if (getpeercon(fd, &peer_context) < 0)
|
||||
+ return -1;
|
||||
+
|
||||
+ int retval = setexeccon(peer_context);
|
||||
+ freecon( peer_context );
|
||||
+
|
||||
+ if (debug.on)
|
||||
+ {
|
||||
+ security_context_t current_exec_context;
|
||||
+ if ( getexeccon( ¤t_exec_context ) == 0 ) {
|
||||
+
|
||||
+ msg( LOG_DEBUG, func,
|
||||
+ "current security exec context now: %s",
|
||||
+ current_exec_context ? current_exec_context : "unknown" );
|
||||
+
|
||||
+ freecon( current_exec_context );
|
||||
+ }
|
||||
+ else
|
||||
+ msg( LOG_DEBUG, func, "Error calling getexeccon: %m" );
|
||||
+ }
|
||||
+
|
||||
+ return retval;
|
||||
+}
|
||||
+#endif
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/confparse.c xinetd-2.3.14/xinetd/confparse.c
|
||||
--- xinetd-2.3.14.orig/xinetd/confparse.c 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/confparse.c 2006-09-20 17:16:35.000000000 -0400
|
||||
@@ -697,6 +697,35 @@ static status_e check_entry( struct serv
|
||||
return( FAILED ) ;
|
||||
}
|
||||
|
||||
+#ifdef LABELED_NET
|
||||
+ if (SC_LABELED_NET(scp)) {
|
||||
+ if ( SC_IS_INTERNAL( scp ) ) {
|
||||
+ msg( LOG_ERR, func,
|
||||
+ "Internal services cannot support labeled networking: %s",
|
||||
+ SC_ID(scp) ) ;
|
||||
+ return( FAILED ) ;
|
||||
+ }
|
||||
+ if ( SC_SOCKET_TYPE(scp) != SOCK_STREAM ) {
|
||||
+ msg( LOG_ERR, func,
|
||||
+ "Non-stream socket types cannot support labeled networking: %s",
|
||||
+ SC_ID(scp) ) ;
|
||||
+ return( FAILED ) ;
|
||||
+ }
|
||||
+ if ( SC_WAITS( scp ) ) {
|
||||
+ msg( LOG_ERR, func,
|
||||
+ "Tcp wait services cannot support labeled networking: %s",
|
||||
+ SC_ID(scp) ) ;
|
||||
+ return( FAILED ) ;
|
||||
+ }
|
||||
+ if ( SC_REDIR_ADDR( scp ) != NULL) {
|
||||
+ msg( LOG_ERR, func,
|
||||
+ "Redirected services cannot support labeled networking: %s",
|
||||
+ SC_ID(scp) ) ;
|
||||
+ return( FAILED ) ;
|
||||
+ }
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
if ( SC_IS_MUXCLIENT( scp ) )
|
||||
{
|
||||
if ( !SC_IS_UNLISTED( scp ) )
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/main.c xinetd-2.3.14/xinetd/main.c
|
||||
--- xinetd-2.3.14.orig/xinetd/main.c 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/main.c 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -80,7 +80,10 @@ int main( int argc, char *argv[] )
|
||||
#ifdef HAVE_DNSREGISTRATION
|
||||
"rendezvous "
|
||||
#endif
|
||||
-#if !defined(LIBWRAP) && !defined(HAVE_LOADAVG) && !defined(HAVE_MDNS) && !defined(HAVE_HOWL) && !defined(HAVE_DNSREGISTRATION)
|
||||
+#ifdef LABELED_NET
|
||||
+ "labeled-networking "
|
||||
+#endif
|
||||
+#if !defined(LIBWRAP) && !defined(HAVE_LOADAVG) && !defined(HAVE_MDNS) && !defined(HAVE_HOWL) && !defined(HAVE_DNSREGISTRATION) && !defined(LABELED_NET)
|
||||
"no "
|
||||
#endif
|
||||
"options compiled in."
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/nvlists.c xinetd-2.3.14/xinetd/nvlists.c
|
||||
--- xinetd-2.3.14.orig/xinetd/nvlists.c 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/nvlists.c 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -47,6 +47,7 @@ const struct name_value service_flags[]
|
||||
{ "SENSOR", SF_SENSOR },
|
||||
{ "IPv4", SF_IPV4 },
|
||||
{ "IPv6", SF_IPV6 },
|
||||
+ { "LABELED", SF_LABELED },
|
||||
{ CHAR_NULL, 0 }
|
||||
} ;
|
||||
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/sconf.h xinetd-2.3.14/xinetd/sconf.h
|
||||
--- xinetd-2.3.14.orig/xinetd/sconf.h 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/sconf.h 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -58,6 +58,7 @@
|
||||
#define SF_SENSOR 9
|
||||
#define SF_IPV4 10
|
||||
#define SF_IPV6 11
|
||||
+#define SF_LABELED 12
|
||||
|
||||
/*
|
||||
* Values for log options
|
||||
@@ -239,6 +240,7 @@ struct service_config
|
||||
#define SC_SENSOR( scp ) M_IS_SET( (scp)->sc_xflags, SF_SENSOR )
|
||||
#define SC_IPV4( scp ) M_IS_SET( (scp)->sc_xflags, SF_IPV4 )
|
||||
#define SC_IPV6( scp ) M_IS_SET( (scp)->sc_xflags, SF_IPV6 )
|
||||
+#define SC_LABELED_NET( scp ) M_IS_SET( (scp)->sc_xflags, SF_LABELED )
|
||||
|
||||
#define SC_IS_RPC( scp ) ( M_IS_SET( (scp)->sc_type, ST_RPC ) )
|
||||
#define SC_IS_INTERNAL( scp ) ( M_IS_SET( (scp)->sc_type, ST_INTERNAL ) )
|
||||
diff -urp xinetd-2.3.14.orig/xinetd/xinetd.conf.man xinetd-2.3.14/xinetd/xinetd.conf.man
|
||||
--- xinetd-2.3.14.orig/xinetd/xinetd.conf.man 2006-06-16 13:20:01.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/xinetd.conf.man 2006-09-20 17:12:00.000000000 -0400
|
||||
@@ -145,6 +145,9 @@ Sets the service to be an IPv4 service (
|
||||
.B IPv6
|
||||
Sets the service to be an IPv6 service (AF_INET6), if IPv6 is available on the system.
|
||||
.TP
|
||||
+.B LABELED
|
||||
+The LABELED flag will tell xinetd to change the child processes SE Linux context to match that of the incoming connection as it starts the service. This only works for external tcp non-waiting servers and is an error if applied to an internal, udp, or tcp-wait server.
|
||||
+.TP
|
||||
.B REUSE
|
||||
The REUSE flag is deprecated. All services now implicitly use the REUSE flag.
|
||||
.RE
|
||||
|
|
@ -1,16 +0,0 @@
|
|||
117746: xinetd.log man page in wrong section
|
||||
|
||||
Put xinetd.log to the right man section.
|
||||
|
||||
diff -up xinetd-2.3.13/Makefile.in.orig xinetd-2.3.13/Makefile.in
|
||||
--- xinetd-2.3.13/Makefile.in.orig 2007-12-06 10:58:32.000000000 +0100
|
||||
+++ xinetd-2.3.13/Makefile.in 2008-01-15 13:39:38.000000000 +0100
|
||||
@@ -80,7 +80,7 @@ install: build
|
||||
$(INSTALL_CMD) -m 755 xinetd/itox $(DAEMONDIR)
|
||||
$(INSTALL_CMD) -m 755 $(SRCDIR)/xinetd/xconv.pl $(DAEMONDIR)
|
||||
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.conf.man $(MANDIR)/man5/xinetd.conf.5
|
||||
- $(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.log.man $(MANDIR)/man8/xinetd.log.8
|
||||
+ $(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.log.man $(MANDIR)/man5/xinetd.log.5
|
||||
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.man $(MANDIR)/man8/xinetd.8
|
||||
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/itox.8 $(MANDIR)/man8/itox.8
|
||||
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xconv.pl.8 $(MANDIR)/man8/xconv.pl.8
|
||||
|
|
@ -1,77 +0,0 @@
|
|||
Generate debuginfo package with all include files readable.
|
||||
|
||||
The support libraries would install their header files with 640 permissions,
|
||||
which is not what we want.
|
||||
|
||||
diff -up xinetd-2.3.14/libs/src/misc/Makefile.in.orig xinetd-2.3.14/libs/src/misc/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/misc/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/misc/Makefile.in 2008-09-18 10:18:59.000000000 +0200
|
||||
@@ -49,7 +49,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
diff -up xinetd-2.3.14/libs/src/portable/Makefile.in.orig xinetd-2.3.14/libs/src/portable/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/portable/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/portable/Makefile.in 2008-09-18 10:19:09.000000000 +0200
|
||||
@@ -44,7 +44,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
diff -up xinetd-2.3.14/libs/src/pset/Makefile.in.orig xinetd-2.3.14/libs/src/pset/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/pset/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/pset/Makefile.in 2008-09-18 10:19:17.000000000 +0200
|
||||
@@ -41,7 +41,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
diff -up xinetd-2.3.14/libs/src/sio/Makefile.in.orig xinetd-2.3.14/libs/src/sio/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/sio/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/sio/Makefile.in 2008-09-18 10:19:25.000000000 +0200
|
||||
@@ -40,7 +40,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
diff -up xinetd-2.3.14/libs/src/str/Makefile.in.orig xinetd-2.3.14/libs/src/str/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/str/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/str/Makefile.in 2008-09-18 10:19:33.000000000 +0200
|
||||
@@ -51,7 +51,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
diff -up xinetd-2.3.14/libs/src/xlog/Makefile.in.orig xinetd-2.3.14/libs/src/xlog/Makefile.in
|
||||
--- xinetd-2.3.14/libs/src/xlog/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
|
||||
+++ xinetd-2.3.14/libs/src/xlog/Makefile.in 2008-09-18 10:19:41.000000000 +0200
|
||||
@@ -46,7 +46,7 @@ CC_FLAGS = $(DEBUG)
|
||||
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
-FMODE = -m 640 # used by install
|
||||
+FMODE = -m 644 # used by install
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
LIBNAME = lib$(NAME).a
|
||||
|
|
@ -1,660 +0,0 @@
|
|||
--- xinetd-2.3.14/libs/src/sio/impl.h.ssize_t 2006-10-27 12:33:29.000000000 -0400
|
||||
+++ xinetd-2.3.14/libs/src/sio/impl.h 2006-10-27 12:40:21.000000000 -0400
|
||||
@@ -142,9 +142,9 @@
|
||||
* Internal functions that are visible
|
||||
*/
|
||||
int __sio_writef( __sio_od_t *odp, int fd ) ;
|
||||
-int __sio_extend_buffer( __sio_id_t *idp, int fd, int b_left ) ;
|
||||
+ssize_t __sio_extend_buffer( __sio_id_t *idp, int fd, ssize_t b_left ) ;
|
||||
int __sio_init( __sio_descriptor_t *dp, int fd, enum __sio_stream stream_type );
|
||||
-int __sio_more( __sio_id_t *idp, int fd ) ;
|
||||
+ssize_t __sio_more( __sio_id_t *idp, int fd ) ;
|
||||
sio_status_e __sio_switch( __sio_id_t *idp, int fd ) ;
|
||||
|
||||
|
||||
--- xinetd-2.3.14/libs/src/sio/siosup.c.ssize_t 2003-09-06 10:41:59.000000000 -0400
|
||||
+++ xinetd-2.3.14/libs/src/sio/siosup.c 2006-10-27 12:40:23.000000000 -0400
|
||||
@@ -599,9 +599,9 @@
|
||||
* If it does not return SIO_ERR, it sets start, nextb, end
|
||||
* If it returns SIO_ERR, it does not change anything
|
||||
*/
|
||||
-static int __sio_readf( __sio_id_t *idp, int fd )
|
||||
+static ssize_t __sio_readf( __sio_id_t *idp, int fd )
|
||||
{
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
|
||||
/*
|
||||
* First check for a tied fd and flush the stream if necessary
|
||||
@@ -634,7 +634,7 @@
|
||||
{
|
||||
if ( __sio_switch( idp, fd ) == FAILURE )
|
||||
return( SIO_ERR ) ;
|
||||
- cc = -1 ;
|
||||
+ cc = (ssize_t)-1 ;
|
||||
}
|
||||
}
|
||||
else
|
||||
@@ -680,7 +680,7 @@
|
||||
for ( ;; )
|
||||
{
|
||||
cc = read( fd, idp->buf, (int) idp->buffer_size ) ;
|
||||
- if ( cc == -1 )
|
||||
+ if ( cc == (ssize_t)-1 )
|
||||
if ( errno == EINTR )
|
||||
continue ;
|
||||
else
|
||||
@@ -705,9 +705,9 @@
|
||||
* auxiliary buffer)
|
||||
* Also, if successful, idp->nextb is set to idp->buf, idp->end is modified.
|
||||
*/
|
||||
-int __sio_extend_buffer( __sio_id_t *idp, int fd, int b_left )
|
||||
+ssize_t __sio_extend_buffer( __sio_id_t *idp, int fd, ssize_t b_left )
|
||||
{
|
||||
- int b_read ;
|
||||
+ ssize_t b_read ;
|
||||
|
||||
/*
|
||||
* copy to auxiliary buffer
|
||||
@@ -733,10 +733,10 @@
|
||||
*
|
||||
* Return value: the number of bytes read.
|
||||
*/
|
||||
-int __sio_more( __sio_id_t *idp, int fd )
|
||||
+ssize_t __sio_more( __sio_id_t *idp, int fd )
|
||||
{
|
||||
int b_left = &idp->buf[ idp->buffer_size ] - idp->end ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
|
||||
if ( b_left <= 0 )
|
||||
return( 0 ) ;
|
||||
--- xinetd-2.3.14/libs/src/sio/sprint.c.ssize_t 2006-10-27 13:14:49.000000000 -0400
|
||||
+++ xinetd-2.3.14/libs/src/sio/sprint.c 2006-10-27 13:14:51.000000000 -0400
|
||||
@@ -18,7 +18,7 @@
|
||||
typedef unsigned long long u_wide_int ;
|
||||
typedef int bool_int ;
|
||||
|
||||
-static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, int *len );
|
||||
+static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, size_t *len );
|
||||
|
||||
#define S_NULL_LEN 6
|
||||
static char S_NULL[S_NULL_LEN+1] = "(null)";
|
||||
@@ -69,7 +69,7 @@
|
||||
} \
|
||||
if ( __SIO_MUST_FLUSH( *odp, c ) && fd >= 0 ) \
|
||||
{ \
|
||||
- int b_in_buffer = sp - odp->start ; \
|
||||
+ ssize_t b_in_buffer = sp - odp->start ; \
|
||||
\
|
||||
odp->nextb = sp ; \
|
||||
if ( __sio_writef( odp, fd ) != b_in_buffer ) \
|
||||
@@ -122,11 +122,11 @@
|
||||
* - all floating point arguments are passed as doubles
|
||||
*/
|
||||
/* VARARGS2 */
|
||||
-int Sprint( int fd, const char *fmt, ...)
|
||||
+ssize_t Sprint( int fd, const char *fmt, ...)
|
||||
{
|
||||
__sio_descriptor_t *dp ;
|
||||
__sio_od_t *odp ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
va_list ap ;
|
||||
|
||||
if( sio_setup( fd, &dp, __SIO_OUTPUT_STREAM ) == SIO_ERR )
|
||||
@@ -143,7 +143,7 @@
|
||||
/*
|
||||
* This is the equivalent of vfprintf for SIO
|
||||
*/
|
||||
-int Sprintv( int fd, const char *fmt, va_list ap)
|
||||
+ssize_t Sprintv( int fd, const char *fmt, va_list ap)
|
||||
{
|
||||
__sio_descriptor_t *dp ;
|
||||
__sio_od_t *odp ;
|
||||
@@ -162,7 +162,7 @@
|
||||
* in buf).
|
||||
*/
|
||||
static char *conv_fp( char format, double num, boolean_e add_dp,
|
||||
- int precision, bool_int *is_negative, char buf[], int *len )
|
||||
+ size_t precision, bool_int *is_negative, char buf[], size_t *len )
|
||||
/* always add decimal point if YES */
|
||||
{
|
||||
char *s = buf ;
|
||||
@@ -220,7 +220,7 @@
|
||||
if ( format != 'f' )
|
||||
{
|
||||
char temp[ EXPONENT_LENGTH ] ; /* for exponent conversion */
|
||||
- int t_len ;
|
||||
+ size_t t_len ;
|
||||
bool_int exponent_is_negative ;
|
||||
|
||||
*s++ = format ; /* either e or E */
|
||||
@@ -261,7 +261,7 @@
|
||||
* which is a pointer to the END of the buffer + 1 (i.e. if the buffer
|
||||
* is declared as buf[ 100 ], buf_end should be &buf[ 100 ])
|
||||
*/
|
||||
-static char *conv_p2( u_wide_int num, int nbits, char format, char *buf_end, int *len )
|
||||
+static char *conv_p2( u_wide_int num, int nbits, char format, char *buf_end, size_t *len )
|
||||
{
|
||||
int mask = ( 1 << nbits ) - 1 ;
|
||||
char *p = buf_end ;
|
||||
@@ -292,7 +292,7 @@
|
||||
* which is a pointer to the END of the buffer + 1 (i.e. if the buffer
|
||||
* is declared as buf[ 100 ], buf_end should be &buf[ 100 ])
|
||||
*/
|
||||
-static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, int *len )
|
||||
+static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, size_t *len )
|
||||
{
|
||||
char *p = buf_end ;
|
||||
u_wide_int magnitude ;
|
||||
@@ -346,19 +346,19 @@
|
||||
* Do format conversion placing the output in odp.
|
||||
* Note: we do not support %n for security reasons.
|
||||
*/
|
||||
-int __sio_converter( __sio_od_t *odp, int fd, const char *fmt, va_list ap )
|
||||
+ssize_t __sio_converter( __sio_od_t *odp, int fd, const char *fmt, va_list ap )
|
||||
{
|
||||
char *sp = NULL;
|
||||
char *bep = NULL;
|
||||
- int cc = 0 ;
|
||||
- int i ;
|
||||
+ ssize_t cc = 0 ;
|
||||
+ size_t i ;
|
||||
|
||||
char *s = NULL;
|
||||
char *q = NULL;
|
||||
- int s_len ;
|
||||
+ size_t s_len ;
|
||||
|
||||
int min_width = 0 ;
|
||||
- int precision = 0 ;
|
||||
+ size_t precision = 0 ;
|
||||
enum { LEFT, RIGHT } adjust ;
|
||||
char pad_char ;
|
||||
char prefix_char ;
|
||||
--- xinetd-2.3.14/libs/src/sio/sio.c.ssize_t 2006-10-27 12:35:12.000000000 -0400
|
||||
+++ xinetd-2.3.14/libs/src/sio/sio.c 2006-10-27 13:28:09.000000000 -0400
|
||||
@@ -28,17 +28,17 @@
|
||||
/*
|
||||
* Stream write call: arguments same as those of write(2)
|
||||
*/
|
||||
-int Swrite( int fd, const char *addr, unsigned int nbytes )
|
||||
+ssize_t Swrite( int fd, const char *addr, size_t nbytes )
|
||||
{
|
||||
__sio_descriptor_t *dp ;
|
||||
__sio_od_t *odp ;
|
||||
- unsigned int b_transferred ;
|
||||
- unsigned int b_avail ;
|
||||
- int total_b_transferred ;
|
||||
- int b_written ;
|
||||
- int b_in_buffer ;
|
||||
+ size_t b_transferred ;
|
||||
+ size_t b_avail ;
|
||||
+ ssize_t total_b_transferred ;
|
||||
+ ssize_t b_written ;
|
||||
+ ssize_t b_in_buffer ;
|
||||
|
||||
- if ( nbytes > INT_MAX )
|
||||
+ if ( nbytes > SSIZE_MAX )
|
||||
return( SIO_ERR );
|
||||
if( sio_setup( fd, &dp, __SIO_OUTPUT_STREAM ) == SIO_ERR )
|
||||
return( SIO_ERR );
|
||||
@@ -62,7 +62,7 @@
|
||||
b_in_buffer = odp->buf_end - odp->start ;
|
||||
b_written = __sio_writef( odp, fd ) ;
|
||||
if ( b_written != b_in_buffer )
|
||||
- return( (b_written >= (int)nbytes) ? (int)nbytes : b_written ) ;
|
||||
+ return( (b_written >= (ssize_t)nbytes) ? (ssize_t)nbytes : b_written ) ;
|
||||
|
||||
total_b_transferred = b_transferred ;
|
||||
addr += b_transferred ;
|
||||
@@ -83,7 +83,7 @@
|
||||
* the buffer is full
|
||||
*/
|
||||
b_written = __sio_writef( odp, fd ) ;
|
||||
- if ( b_written != (int)odp->buffer_size )
|
||||
+ if ( b_written != (ssize_t)odp->buffer_size )
|
||||
{
|
||||
if ( b_written != SIO_ERR )
|
||||
{
|
||||
@@ -157,8 +157,8 @@
|
||||
__sio_id_t *idp ;
|
||||
char *cp ;
|
||||
char *line_start ;
|
||||
- int b_left ;
|
||||
- int extension ;
|
||||
+ ssize_t b_left ;
|
||||
+ ssize_t extension ;
|
||||
|
||||
if( sio_setup( fd, &dp, __SIO_INPUT_STREAM ) == SIO_ERR )
|
||||
return( NULL );
|
||||
@@ -361,7 +361,7 @@
|
||||
|
||||
#ifndef sio_memscan
|
||||
|
||||
-static char *sio_memscan( const char *from, int how_many, char ch )
|
||||
+static char *sio_memscan( const char *from, size_t how_many, char ch )
|
||||
{
|
||||
char *p ;
|
||||
char *last = from + how_many ;
|
||||
@@ -377,7 +377,7 @@
|
||||
|
||||
#ifdef NEED_MEMCOPY
|
||||
|
||||
-void __sio_memcopy( const char *from, char *to, int nbytes )
|
||||
+void __sio_memcopy( const char *from, char *to, size_t nbytes )
|
||||
{
|
||||
while ( nbytes-- )
|
||||
*to++ = *from++ ;
|
||||
--- xinetd-2.3.14/xinetd/udpint.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/udpint.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -226,7 +226,7 @@
|
||||
{
|
||||
char *p ;
|
||||
int left ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
const char *func = "send_data" ;
|
||||
|
||||
for ( p = buf, left = len ; left > 0 ; left -= cc, p+= cc )
|
||||
@@ -236,7 +236,7 @@
|
||||
else
|
||||
cc = sendto( sd, p, left, 0, SA( addr ), sizeof( *addr ) ) ;
|
||||
|
||||
- if ( cc == -1 ) {
|
||||
+ if ( cc == (ssize_t)-1 ) {
|
||||
if ( errno == EINTR )
|
||||
{
|
||||
cc = 0 ;
|
||||
@@ -264,12 +264,12 @@
|
||||
|
||||
for ( ;; )
|
||||
{
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
|
||||
from_len = sizeof( pp->from ) ;
|
||||
cc = recvfrom( INT_REMOTE( ip ), pp->data, pp->size,
|
||||
0, SA( &pp->from ), &from_len ) ;
|
||||
- if ( cc == -1 )
|
||||
+ if ( cc == (ssize_t)-1 )
|
||||
{
|
||||
if ( errno != EINTR )
|
||||
{
|
||||
@@ -306,14 +306,14 @@
|
||||
static status_e udp_local_to_remote( channel_s *chp )
|
||||
{
|
||||
char buf[ MAX_DATAGRAM_SIZE ] ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
const char *func = "udp_local_to_remote" ;
|
||||
|
||||
for ( ;; )
|
||||
{
|
||||
cc = recv( chp->ch_local_socket, buf, sizeof( buf ), 0 ) ;
|
||||
|
||||
- if ( cc == -1 )
|
||||
+ if ( cc == (ssize_t)-1 )
|
||||
{
|
||||
if ( errno != EINTR )
|
||||
{
|
||||
--- xinetd-2.3.14/xinetd/service.c.ssize_t 2006-10-27 12:17:10.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/service.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -610,7 +610,7 @@
|
||||
/* print the banner regardless of access control */
|
||||
if ( SC_BANNER(scp) != NULL ) {
|
||||
char tmpbuf[TMPSIZE];
|
||||
- int retval;
|
||||
+ ssize_t retval;
|
||||
int bannerfd = open(SC_BANNER(scp), O_RDONLY);
|
||||
|
||||
if( bannerfd < 0 ) {
|
||||
@@ -620,7 +620,7 @@
|
||||
}
|
||||
|
||||
while( (retval = read(bannerfd, tmpbuf, sizeof(tmpbuf))) ) {
|
||||
- if (retval == -1)
|
||||
+ if (retval == (ssize_t)-1)
|
||||
{
|
||||
if (errno == EINTR)
|
||||
continue;
|
||||
--- xinetd-2.3.14/xinetd/signals.c.ssize_t 2003-12-23 10:30:10.000000000 -0500
|
||||
+++ xinetd-2.3.14/xinetd/signals.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -402,7 +402,7 @@
|
||||
*/
|
||||
static void my_handler( int sig )
|
||||
{
|
||||
- int ret_val;
|
||||
+ ssize_t ret_val;
|
||||
int saved_errno = errno;
|
||||
#if NSIG < 256
|
||||
unsigned char sig_byte;
|
||||
@@ -412,13 +412,13 @@
|
||||
do
|
||||
{
|
||||
ret_val = write(signals_pending[1], &sig_byte, 1);
|
||||
- } while (ret_val == -1 && errno == EINTR);
|
||||
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
|
||||
#else
|
||||
if (signals_pending[1] < 0) return;
|
||||
do
|
||||
{
|
||||
ret_val = write(signals_pending[1], &sig, sizeof(int));
|
||||
- } while (ret_val == -1 && errno == EINTR);
|
||||
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
|
||||
#endif
|
||||
errno = saved_errno;
|
||||
}
|
||||
@@ -470,12 +470,12 @@
|
||||
#endif
|
||||
|
||||
while( --i >= 0 ) {
|
||||
- int ret_val;
|
||||
+ ssize_t ret_val;
|
||||
do
|
||||
{
|
||||
ret_val = read(signals_pending[0], &sig, sizeof(sig));
|
||||
- } while (ret_val == -1 && errno == EINTR);
|
||||
- if (ret_val != sizeof(sig) ) {
|
||||
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
|
||||
+ if (ret_val != (ssize_t)sizeof(sig) ) {
|
||||
msg(LOG_ERR, func, "Error retrieving pending signal: %m");
|
||||
return;
|
||||
}
|
||||
--- xinetd-2.3.14/xinetd/connection.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/connection.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -96,13 +96,15 @@
|
||||
if ( SVC_SOCKET_TYPE( sp ) == SOCK_DGRAM )
|
||||
{
|
||||
char t_ch ;
|
||||
+ ssize_t val;
|
||||
|
||||
/*
|
||||
* This trick is done to get the remote address.
|
||||
* select(2) guaranteed that we won't block on the recvfrom
|
||||
*/
|
||||
- if ( recvfrom( SVC_FD( sp ), &t_ch, 1, MSG_PEEK,
|
||||
- &cp->co_remote_address.sa, &sin_len ) == -1 )
|
||||
+ val = recvfrom( SVC_FD( sp ), &t_ch, 1, MSG_PEEK,
|
||||
+ &cp->co_remote_address.sa, &sin_len );
|
||||
+ if ( val == (ssize_t)-1 )
|
||||
{
|
||||
msg( LOG_ERR, func, "service %s, recvfrom: %m", SVC_ID( sp ) ) ;
|
||||
return( FAILED ) ;
|
||||
--- xinetd-2.3.14/xinetd/util.c.ssize_t 2005-10-05 17:45:41.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/util.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -198,7 +198,8 @@
|
||||
*/
|
||||
status_e write_buf( int fd, const char *buf, int len )
|
||||
{
|
||||
- int cc, i ;
|
||||
+ int i ;
|
||||
+ ssize_t cc;
|
||||
|
||||
for ( i = 0 ; len > 0 ; i += cc, len -= cc )
|
||||
{
|
||||
@@ -234,7 +235,7 @@
|
||||
void drain( int sd )
|
||||
{
|
||||
char buf[ 256 ] ; /* This size is arbitrarily chosen */
|
||||
- int ret ;
|
||||
+ ssize_t ret ;
|
||||
int old_val ;
|
||||
|
||||
/* Put in non-blocking mode so we don't hang. */
|
||||
--- xinetd-2.3.14/xinetd/redirect.c.ssize_t 2003-08-06 02:12:10.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/redirect.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -58,7 +58,8 @@
|
||||
struct service *sp = SERVER_SERVICE( serp );
|
||||
struct service_config *scp = SVC_CONF( sp );
|
||||
int RedirDescrip = SERVER_FD( serp );
|
||||
- int maxfd, num_read, num_wrote=0, ret=0;
|
||||
+ int maxfd;
|
||||
+ ssize_t num_read, num_wrote=0, ret=0;
|
||||
unsigned int sin_len = 0;
|
||||
unsigned long bytes_in = 0, bytes_out = 0;
|
||||
int no_to_nagle = 1;
|
||||
@@ -156,7 +157,7 @@
|
||||
do {
|
||||
num_read = read(RedirDescrip,
|
||||
buff, sizeof(buff));
|
||||
- if (num_read == -1 && errno == EINTR)
|
||||
+ if (num_read == (ssize_t)-1 && errno == EINTR)
|
||||
continue;
|
||||
if (num_read <= 0)
|
||||
goto REDIROUT;
|
||||
--- xinetd-2.3.14/xinetd/tcpint.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/tcpint.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -273,7 +273,7 @@
|
||||
static stream_status_e tcp_local_to_remote( channel_s *chp )
|
||||
{
|
||||
char buf[ DATAGRAM_SIZE ] ;
|
||||
- int rcc, wcc ;
|
||||
+ ssize_t rcc, wcc ;
|
||||
char *p ;
|
||||
int left ;
|
||||
const char *func = "tcp_local_to_remote" ;
|
||||
@@ -283,7 +283,7 @@
|
||||
rcc = recv( chp->ch_local_socket, buf, sizeof( buf ), 0 ) ;
|
||||
if ( rcc == 0 )
|
||||
return( S_SERVER_ERR ) ;
|
||||
- else if ( rcc == -1 )
|
||||
+ else if ( rcc == (ssize_t)-1 )
|
||||
{
|
||||
if ( errno != EINTR )
|
||||
{
|
||||
@@ -300,7 +300,7 @@
|
||||
wcc = send( chp->ch_remote_socket, p, left, 0 ) ;
|
||||
if ( wcc == 0 )
|
||||
return( S_CLIENT_ERR ) ;
|
||||
- else if ( wcc == -1 )
|
||||
+ else if ( wcc == (ssize_t)-1 )
|
||||
{
|
||||
if ( errno == EINTR )
|
||||
wcc = 0 ;
|
||||
@@ -326,7 +326,7 @@
|
||||
static stream_status_e tcp_remote_to_local( channel_s *chp )
|
||||
{
|
||||
char buf[ DATAGRAM_SIZE ] ;
|
||||
- int rcc, wcc ;
|
||||
+ ssize_t rcc, wcc ;
|
||||
int left ;
|
||||
char *p ;
|
||||
const char *func = "tcp_remote_to_local" ;
|
||||
@@ -336,7 +336,7 @@
|
||||
rcc = recv( chp->ch_remote_socket, buf, sizeof( buf ), 0 ) ;
|
||||
if ( rcc == 0 )
|
||||
return( S_CLIENT_ERR ) ;
|
||||
- else if ( rcc == -1 )
|
||||
+ else if ( rcc == (ssize_t)-1 )
|
||||
{
|
||||
if ( errno != EINTR )
|
||||
{
|
||||
@@ -353,7 +353,7 @@
|
||||
wcc = send( chp->ch_local_socket, p, left, 0 ) ;
|
||||
if ( wcc == 0 ) {
|
||||
return( S_SERVER_ERR ) ;
|
||||
- } else if ( wcc == -1 ) {
|
||||
+ } else if ( wcc == (ssize_t)-1 ) {
|
||||
if ( errno == EINTR ) {
|
||||
rcc = 0 ;
|
||||
} else {
|
||||
--- xinetd-2.3.14/xinetd/builtins.c.ssize_t 2005-10-06 11:38:04.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/builtins.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -129,7 +129,7 @@
|
||||
static void stream_echo( const struct server *serp )
|
||||
{
|
||||
char buf[ BUFFER_SIZE ] ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
int descriptor = SERVER_FD( serp ) ;
|
||||
struct service *svc = SERVER_SERVICE( serp ) ;;
|
||||
|
||||
@@ -149,7 +149,7 @@
|
||||
cc = read( descriptor, buf, sizeof( buf ) ) ;
|
||||
if ( cc == 0 )
|
||||
break ;
|
||||
- if ( cc == -1 ) {
|
||||
+ if ( cc == (ssize_t)-1 ) {
|
||||
if ( errno == EINTR )
|
||||
continue ;
|
||||
else
|
||||
@@ -167,7 +167,7 @@
|
||||
{
|
||||
char buf[ DATAGRAM_SIZE ] ;
|
||||
union xsockaddr lsin;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
socklen_t sin_len = 0;
|
||||
int descriptor = SERVER_FD( serp ) ;
|
||||
const char *func = "dgram_echo";
|
||||
@@ -178,15 +178,15 @@
|
||||
sin_len = sizeof( struct sockaddr_in6 );
|
||||
|
||||
cc = recvfrom( descriptor, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) ;
|
||||
- if ( cc != -1 ) {
|
||||
- (void) sendto( descriptor, buf, cc, 0, SA( &lsin ), sizeof( lsin ) ) ;
|
||||
+ if ( cc != (ssize_t)-1 ) {
|
||||
+ (void) sendto( descriptor, buf, (size_t)cc, 0, SA( &lsin ), sizeof( lsin ) ) ;
|
||||
}
|
||||
}
|
||||
|
||||
static void stream_discard( const struct server *serp )
|
||||
{
|
||||
char buf[ BUFFER_SIZE ] ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
int descriptor = SERVER_FD( serp ) ;
|
||||
struct service *svc = SERVER_SERVICE( serp ) ;;
|
||||
|
||||
@@ -204,7 +204,7 @@
|
||||
for ( ;; )
|
||||
{
|
||||
cc = read( descriptor, buf, sizeof( buf ) ) ;
|
||||
- if ( (cc == 0) || ((cc == -1) && (errno != EINTR)) )
|
||||
+ if ( (cc == 0) || ((cc == (ssize_t)-1) && (errno != EINTR)) )
|
||||
break ;
|
||||
}
|
||||
if( SVC_WAITS( svc ) ) /* Service forks, so close it */
|
||||
@@ -293,14 +293,16 @@
|
||||
unsigned int buflen = sizeof( time_buf ) ;
|
||||
int descriptor = SERVER_FD( serp ) ;
|
||||
const char *func = "dgram_daytime";
|
||||
+ ssize_t val;
|
||||
|
||||
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in );
|
||||
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in6 );
|
||||
|
||||
- if ( recvfrom( descriptor, time_buf, sizeof( time_buf ), 0,
|
||||
- SA( &lsin ), &sin_len ) == -1 )
|
||||
+ val = recvfrom( descriptor, time_buf, sizeof( time_buf ), 0,
|
||||
+ SA( &lsin ), &sin_len );
|
||||
+ if ( val == (ssize_t)-1 )
|
||||
return ;
|
||||
|
||||
daytime_protocol( time_buf, &buflen ) ;
|
||||
@@ -359,13 +361,15 @@
|
||||
socklen_t sin_len = 0 ;
|
||||
int fd = SERVER_FD( serp ) ;
|
||||
const char *func = "dgram_daytime";
|
||||
+ ssize_t val;
|
||||
|
||||
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in );
|
||||
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in6 );
|
||||
|
||||
- if ( recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) == -1 )
|
||||
+ val = recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len );
|
||||
+ if ( val == (ssize_t)-1 )
|
||||
return ;
|
||||
|
||||
time_protocol( time_buf ) ;
|
||||
@@ -465,13 +469,15 @@
|
||||
int fd = SERVER_FD( serp ) ;
|
||||
unsigned int left = sizeof( buf ) ;
|
||||
const char *func = "dgram_chargen";
|
||||
+ ssize_t val;
|
||||
|
||||
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in );
|
||||
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
|
||||
sin_len = sizeof( struct sockaddr_in6 );
|
||||
|
||||
- if ( recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) == -1 )
|
||||
+ val = recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len );
|
||||
+ if ( val == (ssize_t)-1 )
|
||||
return ;
|
||||
|
||||
#if BUFFER_SIZE < LINE_LENGTH+2
|
||||
--- xinetd-2.3.14/xinetd/ident.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
|
||||
+++ xinetd-2.3.14/xinetd/ident.c 2006-10-27 12:17:10.000000000 -0400
|
||||
@@ -267,7 +267,7 @@
|
||||
static char *get_line( int sd, char *buf, unsigned bufsize )
|
||||
{
|
||||
int size ;
|
||||
- int cc ;
|
||||
+ ssize_t cc ;
|
||||
char *p ;
|
||||
char *s ;
|
||||
const char *func = "get_line" ;
|
||||
@@ -275,7 +275,7 @@
|
||||
for ( p = buf, size = bufsize ; size > 0 ; p += cc, size -= cc )
|
||||
{
|
||||
cc = read( sd, p, size ) ;
|
||||
- if ( cc == -1 ) {
|
||||
+ if ( cc == (ssize_t)-1 ) {
|
||||
if ( errno == EINTR )
|
||||
{
|
||||
cc = 0 ;
|
||||
--- xinetd-2.3.14/libs/src/sio/sio.h.ssize_t 2003-06-10 09:15:44.000000000 -0400
|
||||
+++ xinetd-2.3.14/libs/src/sio/sio.h 2006-10-27 15:47:37.000000000 -0400
|
||||
@@ -12,6 +12,8 @@
|
||||
#define __SIO_H
|
||||
|
||||
#include <errno.h>
|
||||
+#include <string.h>
|
||||
+#include <unistd.h>
|
||||
#include <stdarg.h>
|
||||
|
||||
/*
|
||||
@@ -56,7 +58,7 @@
|
||||
* buffer is right below buf and is of the same size.
|
||||
*/
|
||||
char *buf ;
|
||||
- unsigned buffer_size ;
|
||||
+ size_t buffer_size ;
|
||||
|
||||
char *start ; /* start of valid buffer contents */
|
||||
char *end ; /* end of valid buffer contents + 1 */
|
||||
@@ -163,15 +165,15 @@
|
||||
/*
|
||||
* The Write functions
|
||||
*/
|
||||
-int Swrite ( int fd, const char *buf, unsigned int nbytes );
|
||||
-int Sprint ( int fd, const char *format, ... )
|
||||
+ssize_t Swrite ( int fd, const char *buf, size_t );
|
||||
+ssize_t Sprint ( int fd, const char *format, ... )
|
||||
#ifdef __GNUC__
|
||||
__attribute__ ((format (printf, 2, 3)));
|
||||
#else
|
||||
;
|
||||
#endif
|
||||
int Sputchar( int fd, char c );
|
||||
-int Sprintv ( int fd, const char *format, va_list ap )
|
||||
+ssize_t Sprintv ( int fd, const char *format, va_list ap )
|
||||
#ifdef __GNUC__
|
||||
__attribute__ ((format (printf, 2, 0)));
|
||||
#else
|
||||
@@ -186,7 +188,7 @@
|
||||
int Sclose ( int fd ) ;
|
||||
int Sbuftype ( int fd, int type ) ;
|
||||
int Smorefds ( int ) ;
|
||||
-int __sio_converter( __sio_od_t *, int , const char *, va_list );
|
||||
+ssize_t __sio_converter( __sio_od_t *, int , const char *, va_list );
|
||||
int sio_setup(int fd, __sio_descriptor_t **dp, unsigned int type );
|
||||
|
||||
#ifdef __GNUC__
|
||||
150
xinetd.init
150
xinetd.init
|
|
@ -1,150 +0,0 @@
|
|||
#!/bin/bash
|
||||
#
|
||||
# xinetd This starts and stops xinetd.
|
||||
#
|
||||
# chkconfig: 345 56 50
|
||||
# description: xinetd is a powerful replacement for inetd. \
|
||||
# xinetd has access control mechanisms, extensive \
|
||||
# logging capabilities, the ability to make services \
|
||||
# available based on time, and can place \
|
||||
# limits on the number of servers that can be started, \
|
||||
# among other things.
|
||||
#
|
||||
# processname: /usr/sbin/xinetd
|
||||
# config: /etc/sysconfig/network
|
||||
# config: /etc/xinetd.conf
|
||||
# pidfile: /var/run/xinetd.pid
|
||||
|
||||
|
||||
### BEGIN INIT INFO
|
||||
# Provides:
|
||||
# Required-Start: $network
|
||||
# Required-Stop:
|
||||
# Should-Start:
|
||||
# Should-Stop:
|
||||
# Default-Start: 3 4 5
|
||||
# Default-Stop: 0 1 2 6
|
||||
# Short-Description: start and stop xinetd
|
||||
# Description: xinetd is a powerful replacement for inetd. \
|
||||
# xinetd has access control mechanisms, extensive \
|
||||
# logging capabilities, the ability to make services \
|
||||
# available based on time, and can place \
|
||||
# limits on the number of servers that can be started, \
|
||||
# among other things.
|
||||
### END INIT INFO
|
||||
|
||||
PATH=/sbin:/bin:/usr/bin:/usr/sbin
|
||||
|
||||
# Source function library.
|
||||
. /etc/init.d/functions
|
||||
|
||||
# Get config.
|
||||
test -f /etc/sysconfig/network && . /etc/sysconfig/network
|
||||
|
||||
# More config
|
||||
|
||||
test -f /etc/sysconfig/xinetd && . /etc/sysconfig/xinetd
|
||||
|
||||
RETVAL=0
|
||||
|
||||
prog="xinetd"
|
||||
|
||||
start(){
|
||||
[ -f /usr/sbin/xinetd ] || exit 5
|
||||
[ -f /etc/xinetd.conf ] || exit 6
|
||||
|
||||
echo -n $"Starting $prog: "
|
||||
|
||||
# Localization for xinetd is controlled in /etc/synconfig/xinetd
|
||||
if [ -z "$XINETD_LANG" -o "$XINETD_LANG" = "none" -o "$XINETD_LANG" = "NONE" ]; then
|
||||
unset LANG LC_TIME LC_ALL LC_MESSAGES LC_NUMERIC LC_MONETARY LC_COLLATE
|
||||
else
|
||||
LANG="$XINETD_LANG"
|
||||
LC_TIME="$XINETD_LANG"
|
||||
LC_ALL="$XINETD_LANG"
|
||||
LC_MESSAGES="$XINETD_LANG"
|
||||
LC_NUMERIC="$XINETD_LANG"
|
||||
LC_MONETARY="$XINETD_LANG"
|
||||
LC_COLLATE="$XINETD_LANG"
|
||||
export LANG LC_TIME LC_ALL LC_MESSAGES LC_NUMERIC LC_MONETARY LC_COLLATE
|
||||
fi
|
||||
unset HOME MAIL USER USERNAME
|
||||
daemon $prog -stayalive -pidfile /var/run/xinetd.pid "$EXTRAOPTIONS"
|
||||
RETVAL=$?
|
||||
echo
|
||||
[ $RETVAL -eq 0 ] && touch /var/lock/subsys/xinetd
|
||||
return $RETVAL
|
||||
}
|
||||
|
||||
stop(){
|
||||
[ -f /usr/sbin/xinetd ] || exit 5
|
||||
[ -f /etc/xinetd.conf ] || exit 6
|
||||
|
||||
echo -n $"Stopping $prog: "
|
||||
killproc -p /var/run/xinetd.pid $prog
|
||||
RETVAL=$?
|
||||
echo
|
||||
[ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/xinetd
|
||||
return $RETVAL
|
||||
|
||||
}
|
||||
|
||||
reload(){
|
||||
[ -f /usr/sbin/xinetd ] || exit 5
|
||||
[ -f /etc/xinetd.conf ] || exit 6
|
||||
|
||||
echo -n $"Reloading configuration: "
|
||||
killproc $prog -HUP
|
||||
RETVAL=$?
|
||||
echo
|
||||
return $RETVAL
|
||||
}
|
||||
|
||||
restart(){
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
condrestart(){
|
||||
if [ -e /var/lock/subsys/xinetd ] ; then
|
||||
restart
|
||||
RETVAL=$?
|
||||
return $RETVAL
|
||||
fi
|
||||
RETVAL=0
|
||||
return $RETVAL
|
||||
}
|
||||
|
||||
|
||||
# See how we were called.
|
||||
case "$1" in
|
||||
start)
|
||||
start
|
||||
RETVAL=$?
|
||||
;;
|
||||
stop)
|
||||
stop
|
||||
RETVAL=$?
|
||||
;;
|
||||
status)
|
||||
status $prog
|
||||
RETVAL=$?
|
||||
;;
|
||||
restart)
|
||||
restart
|
||||
RETVAL=$?
|
||||
;;
|
||||
reload|force-reload)
|
||||
reload
|
||||
RETVAL=$?
|
||||
;;
|
||||
condrestart|try-restart)
|
||||
condrestart
|
||||
RETVAL=$?
|
||||
;;
|
||||
*)
|
||||
echo $"Usage: $0 {start|stop|status|restart|condrestart|reload}"
|
||||
RETVAL=2
|
||||
esac
|
||||
|
||||
exit $RETVAL
|
||||
230
xinetd.spec
230
xinetd.spec
|
|
@ -1,230 +0,0 @@
|
|||
Summary: A secure replacement for inetd
|
||||
Name: xinetd
|
||||
Version: 2.3.14
|
||||
Release: 22%{?dist}
|
||||
License: xinetd
|
||||
Group: System Environment/Daemons
|
||||
Epoch: 2
|
||||
URL: http://www.xinetd.org
|
||||
Source: http://www.xinetd.org/xinetd-%{version}.tar.gz
|
||||
Source1: xinetd.init
|
||||
Source3: xinetd.sysconf
|
||||
Patch0: xinetd-2.3.11-pie.patch
|
||||
Patch1: xinetd-2.3.12-tcp_rpc.patch
|
||||
Patch2: xinetd-2.3.14-label.patch
|
||||
Patch3: xinetd-2.3.14-contextconf.patch
|
||||
Patch4: xinetd-2.3.14-bind-ipv6.patch
|
||||
Patch5: xinetd-2.3.14-ssize_t.patch
|
||||
Patch6: xinetd-2.3.14-man-section.patch
|
||||
Patch7: xinetd-2.3.11-PIE.patch
|
||||
Patch8: xinetd-2.3.14-ident-bind.patch
|
||||
Patch9: xinetd-2.3.14-readable-debuginfo.patch
|
||||
|
||||
BuildRequires: autoconf, automake
|
||||
BuildRequires: libselinux-devel >= 1.30
|
||||
Requires: /sbin/chkconfig /etc/init.d /sbin/service
|
||||
%{!?tcp_wrappers:BuildRequires: tcp_wrappers-devel}
|
||||
Requires: filesystem >= 2.0.1, initscripts, setup, fileutils
|
||||
Provides: inetd
|
||||
BuildRoot: %{_tmppath}/%{name}-%{version}-root
|
||||
|
||||
%description
|
||||
Xinetd is a secure replacement for inetd, the Internet services
|
||||
daemon. Xinetd provides access control for all services based on the
|
||||
address of the remote host and/or on time of access and can prevent
|
||||
denial-of-access attacks. Xinetd provides extensive logging, has no
|
||||
limit on the number of server arguments, and lets you bind specific
|
||||
services to specific IP addresses on your host machine. Each service
|
||||
has its own specific configuration file for Xinetd; the files are
|
||||
located in the /etc/xinetd.d directory.
|
||||
|
||||
%prep
|
||||
%setup -q
|
||||
|
||||
# SPARC/SPARC64 needs -fPIE/-PIE
|
||||
# This really should be detected by configure.
|
||||
%ifarch sparcv9 sparc64
|
||||
%patch7 -p0 -b .PIE
|
||||
%else
|
||||
%patch0 -p0 -b .pie
|
||||
%endif
|
||||
%patch1 -p1 -b .tcp_rpc
|
||||
%patch2 -p1 -b .lspp
|
||||
%patch3 -p1 -b .confcntx
|
||||
%patch4 -p1 -b .bind
|
||||
%patch5 -p1 -b .ssize_t
|
||||
%patch6 -p1 -b .man-section
|
||||
%patch8 -p1 -b .ident-bind
|
||||
%patch9 -p1 -b .readable-debuginfo
|
||||
|
||||
aclocal
|
||||
autoconf
|
||||
|
||||
%build
|
||||
%configure --with-loadavg --with-inet6 %{!?tcp_wrappers:--with-libwrap} --with-labeled-networking
|
||||
make
|
||||
|
||||
%install
|
||||
rm -rf $RPM_BUILD_ROOT
|
||||
mkdir -p $RPM_BUILD_ROOT/etc/rc.d/init.d
|
||||
mkdir -p $RPM_BUILD_ROOT/etc/xinetd.d/
|
||||
# Remove unneeded service
|
||||
rm -f contrib/xinetd.d/ftp-sensor
|
||||
%makeinstall DAEMONDIR=$RPM_BUILD_ROOT/usr/sbin MANDIR=$RPM_BUILD_ROOT/%{_mandir}
|
||||
install -m 644 contrib/xinetd.conf $RPM_BUILD_ROOT/etc
|
||||
install -m 644 contrib/xinetd.d/* $RPM_BUILD_ROOT/etc/xinetd.d
|
||||
install -m 755 %SOURCE1 $RPM_BUILD_ROOT/etc/rc.d/init.d/xinetd
|
||||
|
||||
rm -f $RPM_BUILD_ROOT/%{_mandir}/man8/itox*
|
||||
rm -f $RPM_BUILD_ROOT/usr/sbin/itox
|
||||
rm -f $RPM_BUILD_ROOT/%{_mandir}/man8/xconv.pl*
|
||||
rm -f $RPM_BUILD_ROOT/usr/sbin/xconv.pl
|
||||
|
||||
mkdir -p $RPM_BUILD_ROOT/etc/sysconfig
|
||||
install -m 644 %SOURCE3 $RPM_BUILD_ROOT/etc/sysconfig/xinetd
|
||||
|
||||
%clean
|
||||
rm -rf $RPM_BUILD_ROOT
|
||||
|
||||
%post
|
||||
if [ $1 = 1 ]; then
|
||||
/sbin/chkconfig --add xinetd
|
||||
fi
|
||||
|
||||
%preun
|
||||
if [ $1 = 0 ]; then
|
||||
/sbin/service xinetd stop > /dev/null 2>&1
|
||||
/sbin/chkconfig --del xinetd
|
||||
fi
|
||||
|
||||
%postun
|
||||
if [ $1 -ge 1 ]; then
|
||||
/sbin/service xinetd condrestart >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
|
||||
%files
|
||||
%defattr(-,root,root)
|
||||
%doc INSTALL CHANGELOG COPYRIGHT README xinetd/sample.conf contrib/empty.conf
|
||||
|
||||
%config(noreplace) /etc/xinetd.conf
|
||||
%config(noreplace) /etc/sysconfig/xinetd
|
||||
/etc/rc.d/init.d/xinetd
|
||||
%config(noreplace) /etc/xinetd.d/*
|
||||
/usr/sbin/xinetd
|
||||
%{_mandir}/*/*
|
||||
|
||||
%changelog
|
||||
* Thu Feb 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2:2.3.14-22
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
|
||||
|
||||
* Thu Sep 18 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-21
|
||||
- fix glitches found during package review (#226560)
|
||||
- make all files in .debuginfo package readable by everyone
|
||||
|
||||
* Wed Jul 16 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-20
|
||||
- fix wrong bind() call (#448069)
|
||||
|
||||
* Thu May 29 2008 Tom "spot" Callaway <tcallawa@redhat.com> - 2:2.3.14-19
|
||||
- fix sparc fPIE issues
|
||||
|
||||
* Thu Jan 31 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-18
|
||||
- fixed LABEL flag (#430929)
|
||||
|
||||
* Wed Jan 30 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-17
|
||||
- fixing init scripts (#430816)
|
||||
|
||||
* Mon Jan 28 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-16
|
||||
- xinetd.log man page is in the right section now (#428812)
|
||||
|
||||
* Thu Sep 6 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-15
|
||||
- initscript made LSB compliant (#247099)
|
||||
|
||||
* Thu Sep 6 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-14
|
||||
- removed inetdconvert script, nobody is using inetd
|
||||
|
||||
* Wed Aug 22 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-13
|
||||
- updated license field
|
||||
|
||||
* Wed May 16 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-12
|
||||
- bind IPv6 socket by default and switch to IPv4 on error
|
||||
(bz#195265)
|
||||
- service xinetd status returns actual status (bz#232887)
|
||||
- use ssize_t instead of int (bz#211776)
|
||||
|
||||
* Mon Dec 4 2006 Thomas Woerner <twoerner@redhat.com> - 2:2.3.14-11
|
||||
- tcp_wrappers has a new devel and libs sub package, therefore changing build
|
||||
requirement for tcp_wrappers to tcp_wrappers-devel
|
||||
|
||||
* Fri Dec 01 2006 James Antill <james.antill@redhat.com> - 2:2.3.14-9
|
||||
- Fix getpeercon() for LABELED networking MLS environments
|
||||
- Resolves: rhbz#209379
|
||||
|
||||
* Sun Oct 01 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.14-8
|
||||
- rebuilt for unwind info generation, broken in gcc-4.1.1-21
|
||||
|
||||
* Wed Sep 20 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-7
|
||||
- Revised labeled networking patch to not allow redirection
|
||||
|
||||
* Tue Aug 29 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-6
|
||||
- Revised labeled networking patch again
|
||||
|
||||
* Thu Aug 24 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-5
|
||||
- Revised labeled networking patch
|
||||
|
||||
* Wed Aug 23 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-4
|
||||
- Added labeled networking patch
|
||||
|
||||
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.14-3.1
|
||||
- rebuild
|
||||
|
||||
* Fri Jun 16 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-3
|
||||
- Rework spec file & use xinetd's sevice config files
|
||||
|
||||
* Fri Mar 24 2006 Jay Fenlason <fenlason@redhat.com> 2:2.3.14-2
|
||||
- Upgrade to new upstream version. This obsoletes the -libwrap,
|
||||
-rpc, -banner, -bug140084 and -gcc4 patches.
|
||||
|
||||
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.13-6.2.1
|
||||
- bump again for double-long bug on ppc(64)
|
||||
|
||||
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.13-6.2
|
||||
- rebuilt for new gcc4.1 snapshot and glibc changes
|
||||
|
||||
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Thu Feb 17 2005 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-6
|
||||
- include new patch to allow gcc4 to compile xinetd.
|
||||
|
||||
* Sat Jan 8 2005 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-4
|
||||
- Added patch committed to upstream CVS to fix bz#140084
|
||||
(error logging accidentally using one of [012] as the syslog
|
||||
descriptor)
|
||||
|
||||
* Fri Jun 18 2004 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-3
|
||||
- Add patch to fix #126242: banner's don't work
|
||||
|
||||
* Thu Jun 17 2004 Jay Fenlason <fenlason@redhat.com>
|
||||
- Remove the configuration for the no-longer-present "services" service.
|
||||
Closes #126169
|
||||
|
||||
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Fri May 14 2004 Jay Fenlason <fenlason@redhat.com>
|
||||
- Add patch to allow multiple rpc services to cooexist as long as they're
|
||||
different program numbers or different versions.
|
||||
|
||||
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Thu Jan 29 2004 Jay Fenlason <fenlason@redhat.com> 2.3.13-1
|
||||
- Upgrade to new upstream version, which obsoletes most patches.
|
||||
- Add new tcp_rpc patch, to turn on the nolibwrap flag on tcp rpc services,
|
||||
since libwrap cannot be used on them.
|
||||
|
||||
* Sun Dec 28 2003 Florian La Roche <Florian.LaRoche@redhat.de>
|
||||
- use new technology to filter python dep for inetdconvert instead
|
||||
of changing the -x bit on file permissions
|
||||
|
||||
|
|
@ -1,10 +0,0 @@
|
|||
# Add extra options here
|
||||
EXTRAOPTIONS=""
|
||||
#
|
||||
# This is the locale information that xinetd uses. It is passed to every
|
||||
# server that xinetd starts. It is set to en_US to maintain compatability
|
||||
# with previous Red Hat Linux releases.
|
||||
#
|
||||
# To remove all locale information from xinetd's environment, set
|
||||
# XINETD_LANG to the empty string or the string "none".
|
||||
XINETD_LANG="en_US"
|
||||
Loading…
Add table
Add a link
Reference in a new issue