summaryrefslogtreecommitdiff
path: root/utilities/ovs-openflowd.c
diff options
context:
space:
mode:
authorBen Pfaff <blp@nicira.com>2009-12-21 17:02:17 -0800
committerBen Pfaff <blp@nicira.com>2010-01-04 10:09:27 -0800
commit2280e7223cc5d014fe60ad3be45b8e4d9d401997 (patch)
tree1ebc58c48fec201f1b2e52fb3c6354296e7b10f6 /utilities/ovs-openflowd.c
parent0b1fae1b73c4c6cfc84edafc6845a17257191e42 (diff)
downloadopenvswitch-2280e7223cc5d014fe60ad3be45b8e4d9d401997.tar.gz
ofproto: Drop remote command execution feature.
At one point Nicira had deployment plans for which adding a remote command execution feature to the OpenFlow stack made a lot of sense. We no longer have those plans, as far as I know, and leaving the feature in seems like a huge potential security hole. So this commit blows away the entire feature.
Diffstat (limited to 'utilities/ovs-openflowd.c')
-rw-r--r--utilities/ovs-openflowd.c30
1 files changed, 1 insertions, 29 deletions
diff --git a/utilities/ovs-openflowd.c b/utilities/ovs-openflowd.c
index ba97faf6f..0b0580df8 100644
--- a/utilities/ovs-openflowd.c
+++ b/utilities/ovs-openflowd.c
@@ -94,10 +94,6 @@ struct ofsettings {
/* Spanning tree protocol. */
bool enable_stp;
- /* Remote command execution. */
- char *command_acl; /* Command white/blacklist, as shell globs. */
- char *command_dir; /* Directory that contains commands. */
-
/* Management. */
uint64_t mgmt_id; /* Management ID. */
@@ -206,11 +202,6 @@ main(int argc, char *argv[])
if (error) {
ovs_fatal(error, "failed to configure STP");
}
- error = ofproto_set_remote_execution(ofproto, s.command_acl,
- s.command_dir);
- if (error) {
- ovs_fatal(error, "failed to configure remote command execution");
- }
if (!s.discovery) {
error = ofproto_set_controller(ofproto, s.controller_name);
if (error) {
@@ -265,8 +256,6 @@ parse_options(int argc, char *argv[], struct ofsettings *s)
OPT_NO_STP,
OPT_OUT_OF_BAND,
OPT_IN_BAND,
- OPT_COMMAND_ACL,
- OPT_COMMAND_DIR,
OPT_NETFLOW,
OPT_MGMT_ID,
OPT_PORTS,
@@ -295,8 +284,6 @@ parse_options(int argc, char *argv[], struct ofsettings *s)
{"no-stp", no_argument, 0, OPT_NO_STP},
{"out-of-band", no_argument, 0, OPT_OUT_OF_BAND},
{"in-band", no_argument, 0, OPT_IN_BAND},
- {"command-acl", required_argument, 0, OPT_COMMAND_ACL},
- {"command-dir", required_argument, 0, OPT_COMMAND_DIR},
{"netflow", required_argument, 0, OPT_NETFLOW},
{"mgmt-id", required_argument, 0, OPT_MGMT_ID},
{"ports", required_argument, 0, OPT_PORTS},
@@ -332,8 +319,6 @@ parse_options(int argc, char *argv[], struct ofsettings *s)
s->accept_controller_re = NULL;
s->enable_stp = false;
s->in_band = true;
- s->command_acl = "";
- s->command_dir = NULL;
svec_init(&s->netflow);
s->mgmt_id = 0;
svec_init(&s->ports);
@@ -449,16 +434,6 @@ parse_options(int argc, char *argv[], struct ofsettings *s)
s->in_band = true;
break;
- case OPT_COMMAND_ACL:
- s->command_acl = (s->command_acl[0]
- ? xasprintf("%s,%s", s->command_acl, optarg)
- : optarg);
- break;
-
- case OPT_COMMAND_DIR:
- s->command_dir = optarg;
- break;
-
case OPT_NETFLOW:
svec_add(&s->netflow, optarg);
break;
@@ -584,10 +559,7 @@ usage(void)
" --netflow=HOST:PORT configure NetFlow output target\n"
"\nRate-limiting of \"packet-in\" messages to the controller:\n"
" --rate-limit[=PACKETS] max rate, in packets/s (default: 1000)\n"
- " --burst-limit=BURST limit on packet credit for idle time\n"
- "\nRemote command execution options:\n"
- " --command-acl=[!]GLOB[,[!]GLOB...] set allowed/denied commands\n"
- " --command-dir=DIR set command dir (default: %s/commands)\n",
+ " --burst-limit=BURST limit on packet credit for idle time\n",
ovs_pkgdatadir);
daemon_usage();
vlog_usage();