* add support for systemd, OpenRC, SysVinit, and Dinit * add automatic init-system detection through CMake * make libsystemd optional for non-systemd builds * add native service definitions for all supported init systems * add Gentoo ebuild and Alpine APKBUILD packaging support * publish the official BastionGuard source repository * update the README with supported distributions, init systems, repository information, and build documentation
142 lines
4 KiB
Text
Executable file
142 lines
4 KiB
Text
Executable file
#!/sbin/openrc-run
|
|
# Generic OpenRC dispatcher installed under each BastionGuard service name.
|
|
|
|
name="${RC_SVCNAME:-$(basename "$0")}"
|
|
description="BastionGuard service: ${name}"
|
|
pidfile="/run/${name}.pid"
|
|
logdir=/var/log/BastionGuard
|
|
|
|
extra_commands="reload"
|
|
|
|
is_oneshot() {
|
|
case "$name" in
|
|
BastionGuard-phishing-updater|bastionguard-sanesecurity) return 0 ;;
|
|
*) return 1 ;;
|
|
esac
|
|
}
|
|
|
|
depend() {
|
|
need localmount
|
|
use net dbus dnsmasq
|
|
after bootmisc dbus udev
|
|
}
|
|
|
|
start_pre() {
|
|
checkpath --directory --mode 0755 "$logdir"
|
|
checkpath --directory --mode 0755 /run
|
|
}
|
|
|
|
start_bg() {
|
|
daemon=$1
|
|
shift
|
|
start-stop-daemon --start --quiet --background --make-pidfile \
|
|
--pidfile "$pidfile" --startas "$daemon" -- "$@"
|
|
}
|
|
|
|
start_supervised() {
|
|
policy=$1
|
|
delay=$2
|
|
workdir=$3
|
|
daemon=$4
|
|
shift 4
|
|
start_bg /usr/libexec/bastionguard/bastionguard-supervise \
|
|
--restart "$policy" --delay "$delay" --chdir "$workdir" \
|
|
--log "$logdir/$name.log" -- \
|
|
"$daemon" "$@"
|
|
}
|
|
|
|
start() {
|
|
ebegin "Starting ${name}"
|
|
case "$name" in
|
|
BastionGuard-phishing-scanner)
|
|
start_supervised on-failure 5 /usr/share/BastionGuard \
|
|
/usr/bin/BastionGuard-daemon \
|
|
--http-port=81 --https-port=444 \
|
|
--bind-address=127.0.0.2 \
|
|
--page-warning=/usr/share/BastionGuard/data/blocking/block.html
|
|
;;
|
|
BastionGuard-phishing-updater)
|
|
/usr/share/BastionGuard/data/scripts/BastionGuard-phishing-updater.sh
|
|
;;
|
|
BastionGuard-phishing-updater-timer)
|
|
start_supervised on-failure 5 / \
|
|
/usr/libexec/bastionguard/bastionguard-periodic \
|
|
--delay 600 --interval 7200 -- \
|
|
/usr/share/BastionGuard/data/scripts/BastionGuard-phishing-updater.sh
|
|
;;
|
|
BastionGuard-ransomware-realtime)
|
|
start_supervised on-failure 5 / \
|
|
/usr/bin/BastionGuard-ransomware-realtime
|
|
;;
|
|
bastionguard-sanesecurity)
|
|
/usr/libexec/bastionguard/bastionguard-sanesecurity-update
|
|
;;
|
|
bastionguard-sanesecurity-timer)
|
|
start_supervised on-failure 5 / \
|
|
/usr/libexec/bastionguard/bastionguard-periodic \
|
|
--delay 300 --interval 7200 -- \
|
|
/usr/libexec/bastionguard/bastionguard-sanesecurity-update
|
|
;;
|
|
BastionGuard-usbd)
|
|
start_supervised on-failure 5 / \
|
|
/usr/bin/BastionGuard-usbd
|
|
;;
|
|
bsc-daemon)
|
|
start_supervised on-failure 5 / \
|
|
/usr/sbin/bsc-daemon \
|
|
--rules-path /etc/bastionguard-secure-connectiond/rules \
|
|
--ui-socket unix:///tmp/bsd-daemon.sock
|
|
;;
|
|
clamav-clamonacc)
|
|
start_supervised on-failure 5 / /usr/sbin/clamonacc \
|
|
-F --fdpass \
|
|
--log=/var/log/clamav/clamonacc.log \
|
|
--move=/root/quarantine
|
|
;;
|
|
*)
|
|
eerror "Unknown BastionGuard OpenRC service: ${name}"
|
|
eend 1
|
|
return 1
|
|
;;
|
|
esac
|
|
eend $?
|
|
}
|
|
|
|
stop() {
|
|
if is_oneshot; then
|
|
return 0
|
|
fi
|
|
ebegin "Stopping ${name}"
|
|
start-stop-daemon --stop --quiet --retry TERM/10/KILL/5 --pidfile "$pidfile"
|
|
rc=$?
|
|
rm -f "$pidfile"
|
|
eend "$rc"
|
|
}
|
|
|
|
status() {
|
|
if is_oneshot; then
|
|
return 3
|
|
fi
|
|
start-stop-daemon --stop --test --quiet --pidfile "$pidfile"
|
|
}
|
|
|
|
reload() {
|
|
ebegin "Reloading ${name}"
|
|
case "$name" in
|
|
BastionGuard-phishing-scanner)
|
|
/usr/libexec/bastionguard/bastionguard-service --system reload dnsmasq.service
|
|
;;
|
|
bsc-daemon)
|
|
ewarn "bsc-daemon does not support reload; use restart"
|
|
return 3
|
|
;;
|
|
*)
|
|
if [ -r "$pidfile" ]; then
|
|
kill -HUP "$(cat "$pidfile")" 2>/dev/null
|
|
else
|
|
return 3
|
|
fi
|
|
;;
|
|
esac
|
|
eend $?
|
|
}
|