X-Git-Url: http://git.madism.org/?a=blobdiff_plain;f=main-postlicyd.c;h=ff5097fae14fb785db1961063529ece6a63df9e5;hb=e19b9956a229a2197ec33175f1da59629192c3aa;hp=4cf059b327dcbcc8bff638675b9564a40bae9446;hpb=4c619131857a40cf59a472fc55257bae4ded12d7;p=apps%2Fpfixtools.git diff --git a/main-postlicyd.c b/main-postlicyd.c index 4cf059b..ff5097f 100644 --- a/main-postlicyd.c +++ b/main-postlicyd.c @@ -41,6 +41,9 @@ #include "tokens.h" #define DAEMON_NAME "postlicyd" +#define DEFAULT_PORT 10000 +#define RUNAS_USER "nobody" +#define RUNAS_GROUP "nogroup" enum smtp_state { SMTP_UNKNOWN, @@ -229,6 +232,7 @@ static int main_initialize(void) signal(SIGPIPE, SIG_IGN); signal(SIGINT, &common_sighandler); signal(SIGTERM, &common_sighandler); + signal(SIGHUP, &common_sighandler); signal(SIGSEGV, &common_sighandler); syslog(LOG_INFO, "Starting..."); return 0; @@ -247,7 +251,9 @@ void usage(void) fputs("usage: "DAEMON_NAME" [options] config\n" "\n" "Options:\n" + " -l port to listen to\n" " -p file to write our pid to\n" + " -f stay in foreground\n" , stderr); } @@ -255,14 +261,26 @@ void usage(void) int main(int argc, char *argv[]) { + struct sockaddr_in addr = { + .sin_family = AF_INET, + .sin_addr = { htonl(INADDR_LOOPBACK) }, + }; const char *pidfile = NULL; + bool daemonize = true; + int port = DEFAULT_PORT; int sock = -1; - for (int c = 0; (c = getopt(argc, argv, "h" "p:")) >= 0; ) { + for (int c = 0; (c = getopt(argc, argv, "hf" "l:p:")) >= 0; ) { switch (c) { case 'p': pidfile = optarg; break; + case 'l': + port = atoi(optarg); + break; + case 'f': + daemonize = false; + break; default: usage(); return EXIT_FAILURE; @@ -279,13 +297,23 @@ int main(int argc, char *argv[]) return EXIT_FAILURE; } - if (daemon_detach() < 0) { + if (drop_privileges(RUNAS_USER, RUNAS_GROUP) < 0) { + syslog(LOG_CRIT, "unable to drop privileges"); + return EXIT_FAILURE; + } + + if (daemonize && daemon_detach() < 0) { syslog(LOG_CRIT, "unable to fork"); return EXIT_FAILURE; } pidfile_refresh(); + addr.sin_port = htons(port); + sock = tcp_listen((struct sockaddr *)&addr, sizeof(addr)); + if (sock < 0) + return EXIT_FAILURE; + while (!sigint) { int fd = accept(sock, NULL, 0); if (fd < 0) {