Commit Graph
289 Commits
Author SHA1 Message Date
Joachim Wiberg 85058b54a8 plugins: bootmisc: use relative symlink for /var/run
In an upside world, much like the Finit test cases, the root may be
relocated.  This make /var/run relative to /var, instead of /.  Which
hopefully is safer and covers more use-cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-05 17:46:43 +02:00
Joachim Wiberg f9f52a46a6 Debug sys plugin
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-05 07:27:22 +02:00
Joachim Wiberg 6fa3aa41df run(): add support for logging/redirect
This patch adds support for optional logging of output from all run()
commands.  For run_interactive() we've opted to log instead of just
redirect, meaning output on error is till on console but also in log.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-03-01 20:46:01 +01:00
Joachim Wiberg 1b5b37c06b plugin: allow modprobe and tty plugins to be disabled
This patch allows disabling (enabled by default) the modprobe and tty
plugins.  They are not particularly useful in container use-cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-13 22:45:47 +01:00
Joachim Wiberg cb934ca39f Fix issue with "reboot doesn't work on 32-bit targets"
With the introduction of GLIBC v2.34, all 32-bit devices running Linux
get the option of having a 64-bit time_t to survice the UNIX 2038
apocalypse.

Support for 64-bit time_t was added to libuev in v2.4.0.  The build
flags for linking against libuev are defined in the library's .pc
files, which basically gives you -D_TIME_BITS=64 for your CPPFLAGS.

However, it turns out the $(uev_CFLAGS) from pkg-config were only used
when building the main finit binary -- not for the plugins, causing
some really wacky behavior as a result.  All plugins and Finit itself
had some very different opinions on what `struct plugin` looked like,
including offsets and size.  This led to all I/O plugins initializing
their sockets at the wrong offset -- little-endian 32-bit targets set
the HOOK_SHUTDOWN callback hook to address 0x1 -- which the reboot
code then tried to execute, of course leading to a segfault.

This is quite possibly the root cause of issue #216

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-27 18:50:46 +01:00
Joachim Wiberg cb62349054 plugins/bootmisc: only ignore EEXIST errors in ln()
This patch prevents bogus error messages from Finit for when
directories or symlinks already exist.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-27 18:45:00 +01:00
Joachim Wiberg ea4821fd18 plugins/urandom: fix resource leak, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-16 04:56:34 +01:00
Joachim Wiberg b4c7ae9c8c plugins/bootmisc: check return value from symlink() log on error
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-11 17:20:22 +01:00
Joachim Wiberg 9a5bb46f78 Fix #212: service PID file lost after initctl reload
Clearing of the svc->pidfile was introduced in e1b87d70 for a
restriction that has now been removed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-11 15:54:53 +01:00
Joachim Wiberg d331b72dfd Relocate ismnt() and fismnt() to util.c, for sharing with initctl
initctl cannot link with helpers.c, so let's relocate these helper
functions to util.c instead.  Need them to probe for cgroup support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-10 20:26:37 +01:00
Joachim Wiberg 615cd5aac3 plugins/urandom: use RNDADDENTROPY ioctl to seed kernel rng
This patch switches from "cp /var/lib/misc/random-seed /dev/urandom"
to use the kernel RNDADDENTROPY ioctl, which actually increments the
entropy count.

Also, the amount of random data saved at reboot is increased from the
fairly low 512 to 32768 bytes.

All in all, this should greatly improve the stability of most systems
during, or close to, bootstrap.  In particular embedded systems with
limited or no HWRNG.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-02 01:04:07 +01:00
Joachim Wiberg cd383167f9 plugins/rtc: instead of bailing, reset invalid RTC to kernel default
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-01 22:51:45 +01:00
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
Joachim Wiberg d994420d4d plugins: minor coding style cleanup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-11-10 10:18:02 +01:00
Ming Liu d718a27abf dbus: dont hard-code daemon user/pidfile
Both DBUS user and pidfile is configurable in DBUS compilation, by
passing "--with-dbus-user=" and "--with-system-pid-file=", let's avoid
hard-coding them here, use macros instead.

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-09-21 10:48:25 +02:00
Ming Liu ae8e205343 Fix a memleak.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-08-29 14:02:04 +02:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg e2ef6e9c34 plugins: sys: drop conditions not affecting any svc_t
- Fix bug when calling sys_update_conds() when dir already exists
  and we're not being called from the scandir() handler.  I.e.,
  every time but the first for each new condition sub-family

- Drop sys conditions that don't affect any svc_t.  This may seem
  counterintuitive, and we should probably not use oneshot conds,
  but if we leave these conds asserted they may cause inadvertent
  trigger if a finit.conf is loaded which ha this sys cond.  E.g.,
  if ctrlaltdel is asserted and we enable a task in finit.conf and
  call `initctl reload`, the task would start immediately, even
  though ctrl-alt-del may have been pressed a week ago

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-06 00:34:11 +02:00
Joachim Wiberg 1c941fdfbb plugins: add support for disabling RTC and urandom plugins
Some systems may want to handle RTC and /dev/urandom by themselves, or
not at all as in the case of containers where the host does all this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 11:43:58 +02:00
Joachim Wiberg 0ba67a72f8 plugins: add missing x11-common plugin to static libplug.la
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 11:43:26 +02:00
Joachim Wiberg 2641256254 plugins: sys: no need to compose path, name is already absolute path
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 13:58:30 +02:00
Joachim Wiberg 93a027ca23 plugins: netlink: fix gcc signed vs unsigned comparsion warning
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-27 11:18:06 +02:00
Joachim Wiberg c251304146 Refactor sys condition plugin into a standalone keventd
This patch is a refactor of the prototype sys condition plugin.  It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition.  The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them.  This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:31:08 +02:00
Joachim Wiberg b04dc4d457 Ensure services in plugins and from finit.c belong to a cgroup
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup.  This is a workaround to ensure they are assigned one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:27:59 +02:00
Joachim Wiberg 2018c82ea1 plugins: sys: watch uevent to prevent feedback loop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-13 21:20:08 +02:00
Joachim Wiberg c27f3603e6 plugins: sys: use counting semaphores to handle >1 AC supply
- Track number of ac and ac online
 - Use systemd logic to assert sys/pwr/ac also when no supply

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-13 08:45:49 +02:00
Joachim Wiberg 6f82b806ad plugins: new sys condition event monitor (wip)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-11 07:02:49 +02:00
Joachim Wiberg 21ebbb942f plugins: bootmisc: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 988ecd95e3 plugins: bootmisc: only create /run/lock if missing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg cbc7b8c3c7 plugins: bootmisc: add S02sudo setup for Debian systems
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 424db825a3 plugins: netlink: error handling fixes
Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 17:02:09 +02:00
Joachim Wiberg b9cc4cd629 Revert "plugins: fix #173, increase size of netlink socket receive buffer"
This reverts commit add55cfc2a.
2021-05-07 16:50:04 +02:00
Joachim Wiberg 243b8f025b plugins: netlink: refactor and reduce recv() buffer
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel.  As a result, the recv() buffer can be reduced
down to 4k again.

Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling.  If we get ENOBUFS in resync, we
are screwed anyway.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 16:42:42 +02:00
Joachim Wiberg 6c60b67588 plugins: netlink: fix resync request size alignment with kernel
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.

This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used.  We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop.  Plan is to refactor this mess in a later commit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 15:20:25 +02:00
Joachim Wiberg 910bb13711 plugins: netlink: redesign to handle ENOBUFS with kernel resync
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly.  Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.

When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:

  1. deassert all net/ conditions
  2. open a new (temporary) netlink socket
  3. send RTM_GETLINK  and re-assert all interfaces using nl_link()
  4. send RTM_GETROUTE and re-assert all routes with nl_route()

Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves.  This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.

The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 13:06:47 +02:00
Joachim Wiberg add55cfc2a plugins: fix #173, increase size of netlink socket receive buffer
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-04 13:19:54 +02:00
Joachim Wiberg ea8c46cd30 Fix #170: check for loss of default route when interfaces go down
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down.  When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-03 15:18:25 +02:00
Joachim Wiberg 3872077ff1 plugins: netlink: stricter interface name validation
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name.  This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c

 https://code.woboq.org/linux/linux/net/core/dev.c.html#1020

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-29 17:19:19 +02:00
Joachim Wiberg 26128dd788 plugins: skip plugin in rescue mode
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.

Essentially, only services in rescue.conf should run in rescue mode.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 19:46:43 +02:00
Joachim Wiberg d82d119729 plugins: handle corner case when PID file doesn't exist
If we get a notification and the service dies immediately, and also
removes its pid file, we need to take corrective action.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 09:45:57 +02:00
Joachim Wiberg be343a3b34 plugins: call bootmisc:bootclean() in HOOK_MOUNT_POST
Before this patch bootclean() ran first in setup() which caused to to
remove the entire /var/run/finit directory, and other files as well,
created earlier.  Only possible fix is to split clean and setup in
two and make sure to call clean as soon as we've mounted everything.

Note: this introduces a new behavior, and anyone hooking into the
      same point to do good-stuff(tm) may be affected by this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:34:48 +02:00
Joachim Wiberg 0ac0e5c7d3 plugins: create /var/run/finit/cond/pid directory
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:34:29 +02:00
Joachim Wiberg eaeddc36c2 Restore tty plugin after tty refactor
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 09:02:28 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 9e6e653c57 plugins: pidfile: fix subtle memory leak
Since the introduction of the iwatch framework we can now safely free
the memory allocated by realpath() and prevent leaks in a more elegant
way than before.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-29 23:20:00 +02:00
Joachim Wiberg d4bbebeb93 plugins: hotplug: ensure we always call setup() *after* bootmisc
The bootmisc plugin creates lots of required system directories which
udev, and possibly also mdev, need to operate.  E.g., a system which
has an empty tmpfs for /var need to populate that before we run.

The plugin loader handled this dependency implicitly before, loading all
plugins in alphabetical order.  We should not rely on that for proper
operation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-24 13:16:12 +01:00
Joachim Wiberg 1a22b4f0aa plugins: dbus: allow in all runlevels and start already in 'S'
This plugin should be able to start much earlier than on network UP,
it uses a UNIX domain socket to communicate so loopback should not be
needed.

Also, Finit supports runvels up to 9 (0 and 6 are special), so allow
dbus to run in all these runlevels.  It is up to the user/OS to set
any policy for what runlevels to use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-24 13:13:35 +01:00
Joachim Wiberg 959c9fe5aa plugins: restore previous umask() after plugin ops
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:04:29 +01:00
Joachim Wiberg 31cae6a56d plugins: dbus: simplify, use mksubsys(), run as messagebus user
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00
Joachim Wiberg 1fd45c6f2e plugins: bootmisc: refactor, use mksubys() and simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00