From 054baed13424aee24c420e0955dfac7cebba6f33 Mon Sep 17 00:00:00 2001 From: Joachim Nilsson Date: Tue, 15 Aug 2017 08:09:19 +0200 Subject: [PATCH 1/2] Reap zombie processes in emergency shell mode, issue #76 The emergency shell is just a Finit debug mode. This patch adresses a concern from GitHub issue #76, with zombie processes in this mode. Emergency shell could be further improved, e.g. informing the real Finit process of each collected child (zombie) to be restarted if needed. Signed-off-by: Joachim Nilsson --- src/finit.c | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/src/finit.c b/src/finit.c index 84582dd9..a0a49cc4 100644 --- a/src/finit.c +++ b/src/finit.c @@ -202,6 +202,14 @@ done: /* * If everything goes south we can use this to give the operator an * emergency shell to debug the problem -- Finit should not crash! + * + * Note: Only use this for debugging a new Finit setup, don't use + * this in production since it gives a root shell to anyone + * if Finit crashes. + * + * This emergency shell steps in to prevent "Aieee, PID 1 crashed" + * messages from the kernel, which usually results in a reboot, so + * that the operator instead can debug the problem. */ static void emergency_shell(void) { @@ -210,7 +218,15 @@ static void emergency_shell(void) pid = fork(); if (pid) { - waitpid(pid, NULL, 0); + while (1) { + pid_t id; + + /* Reap 'em (prevents Zombies) */ + id = waitpid(-1, NULL, WNOHANG); + if (id == pid) + break; + } + fprintf(stderr, "\n=> Embarrassingly, Finit has crashed. Check /dev/kmsg for details.\n"); fprintf(stderr, "=> To debug, add '--debug' to the kernel command line.\n\n"); From 299962118ab9d0b8095872464e07e3b324446a45 Mon Sep 17 00:00:00 2001 From: Joachim Nilsson Date: Fri, 18 Aug 2017 17:32:00 +0200 Subject: [PATCH 2/2] Update debug section with info on rescue shell, issue #76 --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index 9a699ae5..70371c4f 100644 --- a/README.md +++ b/README.md @@ -421,6 +421,14 @@ Finit is configured with this option, Finit will try to start a bare `/bin/sh` on the boot console. Remember, this is only for debugging and would leave your production system potentially wide open. +There is also a rescue shell available, in case Finit crashes and the +kernel usually reboots: `configure --enable-emergency-shell`. However, +the behavior of Finit is severely limited when this is enabled, so use +it only for debugging start up issues when Finit crashes. + +**NOTE:** Both of these configure options *should not* be enabled for +production systems since they can potentially give a user root access. + Origin & References -------------------