In an upside world, much like the Finit test cases, the root may be
relocated. This make /var/run relative to /var, instead of /. Which
hopefully is safer and covers more use-cases.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for optional logging of output from all run()
commands. For run_interactive() we've opted to log instead of just
redirect, meaning output on error is till on console but also in log.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch allows disabling (enabled by default) the modprobe and tty
plugins. They are not particularly useful in container use-cases.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With the introduction of GLIBC v2.34, all 32-bit devices running Linux
get the option of having a 64-bit time_t to survice the UNIX 2038
apocalypse.
Support for 64-bit time_t was added to libuev in v2.4.0. The build
flags for linking against libuev are defined in the library's .pc
files, which basically gives you -D_TIME_BITS=64 for your CPPFLAGS.
However, it turns out the $(uev_CFLAGS) from pkg-config were only used
when building the main finit binary -- not for the plugins, causing
some really wacky behavior as a result. All plugins and Finit itself
had some very different opinions on what `struct plugin` looked like,
including offsets and size. This led to all I/O plugins initializing
their sockets at the wrong offset -- little-endian 32-bit targets set
the HOOK_SHUTDOWN callback hook to address 0x1 -- which the reboot
code then tried to execute, of course leading to a segfault.
This is quite possibly the root cause of issue #216
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch prevents bogus error messages from Finit for when
directories or symlinks already exist.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Clearing of the svc->pidfile was introduced in e1b87d70 for a
restriction that has now been removed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
initctl cannot link with helpers.c, so let's relocate these helper
functions to util.c instead. Need them to probe for cgroup support.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch switches from "cp /var/lib/misc/random-seed /dev/urandom"
to use the kernel RNDADDENTROPY ioctl, which actually increments the
entropy count.
Also, the amount of random data saved at reboot is increased from the
fairly low 512 to 32768 bytes.
All in all, this should greatly improve the stability of most systems
during, or close to, bootstrap. In particular embedded systems with
limited or no HWRNG.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from
lite/*.h -> libite/*.h
This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config. This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Both DBUS user and pidfile is configurable in DBUS compilation, by
passing "--with-dbus-user=" and "--with-system-pid-file=", let's avoid
hard-coding them here, use macros instead.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
- Fix bug when calling sys_update_conds() when dir already exists
and we're not being called from the scandir() handler. I.e.,
every time but the first for each new condition sub-family
- Drop sys conditions that don't affect any svc_t. This may seem
counterintuitive, and we should probably not use oneshot conds,
but if we leave these conds asserted they may cause inadvertent
trigger if a finit.conf is loaded which ha this sys cond. E.g.,
if ctrlaltdel is asserted and we enable a task in finit.conf and
call `initctl reload`, the task would start immediately, even
though ctrl-alt-del may have been pressed a week ago
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some systems may want to handle RTC and /dev/urandom by themselves, or
not at all as in the case of containers where the host does all this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch is a refactor of the prototype sys condition plugin. It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition. The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them. This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup. This is a workaround to ensure they are assigned one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel. As a result, the recv() buffer can be reduced
down to 4k again.
Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling. If we get ENOBUFS in resync, we
are screwed anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.
This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used. We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop. Plan is to refactor this mess in a later commit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly. Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.
When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:
1. deassert all net/ conditions
2. open a new (temporary) netlink socket
3. send RTM_GETLINK and re-assert all interfaces using nl_link()
4. send RTM_GETROUTE and re-assert all routes with nl_route()
Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves. This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.
The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down. When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name. This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c
https://code.woboq.org/linux/linux/net/core/dev.c.html#1020
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.
Essentially, only services in rescue.conf should run in rescue mode.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
If we get a notification and the service dies immediately, and also
removes its pid file, we need to take corrective action.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Before this patch bootclean() ran first in setup() which caused to to
remove the entire /var/run/finit directory, and other files as well,
created earlier. Only possible fix is to split clean and setup in
two and make sure to call clean as soon as we've mounted everything.
Note: this introduces a new behavior, and anyone hooking into the
same point to do good-stuff(tm) may be affected by this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Initial refactor of the tty implementation to use the service/run/task
general backend. This enables all the features of services also for
ttys, except logging because it makes no sense.
Work in progress:
- plugins/tty.c does not work anymore, could possibly be removed in
favor of usinga (a new) condition instead (if-tty-exists)
- fallback tty does not work anymore, should we remove it, or can we
handle it as an optional built-in with (a new) condition?
- @console does not work anymore, needs to generate N cloned services
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Since the introduction of the iwatch framework we can now safely free
the memory allocated by realpath() and prevent leaks in a more elegant
way than before.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The bootmisc plugin creates lots of required system directories which
udev, and possibly also mdev, need to operate. E.g., a system which
has an empty tmpfs for /var need to populate that before we run.
The plugin loader handled this dependency implicitly before, loading all
plugins in alphabetical order. We should not rely on that for proper
operation.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This plugin should be able to start much earlier than on network UP,
it uses a UNIX domain socket to communicate so loopback should not be
needed.
Also, Finit supports runvels up to 9 (0 and 6 are special), so allow
dbus to run in all these runlevels. It is up to the user/OS to set
any policy for what runlevels to use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>