This patch is a refactor of the prototype sys condition plugin. It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition. The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them. This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The top-level cgroup init is a leaf group and should be treated as such,
even for user setup tasks/services.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup. This is a workaround to ensure they are assigned one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This fixes a long-standanding issue with finit not controlling the
reboot when the user presses ctrl-alt-delete (PC systems).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch does several things related to /run and system reliability.
- Mount /run with MAX 10% of usable RAM
- Create and mount /run/lock as a separate tmpfs with max 5 MiB
As a spin-off, this patch also fixes permisions on /run/lock to 0777
so regular users can create lock files.
Note: none of this code runs if /run is mounted alread in /etc/fstab
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel. As a result, the recv() buffer can be reduced
down to 4k again.
Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling. If we get ENOBUFS in resync, we
are screwed anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.
This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used. We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop. Plan is to refactor this mess in a later commit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly. Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.
When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:
1. deassert all net/ conditions
2. open a new (temporary) netlink socket
3. send RTM_GETLINK and re-assert all interfaces using nl_link()
4. send RTM_GETROUTE and re-assert all routes with nl_route()
Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves. This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.
The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down. When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch restores parts of 4febd28, but in a more orderly fashion, in
order to get a standard Debian system to boot properly with X and tools.
The patch adds fs_finalize() which checks if /dev/sh/, /dev/pts, /run,
and /tmp have been mounted properly from /etc/fstab. If not, then the
function makes sure to mount tmfps (or devpts) file systems as expected
by most modern systems.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch changes the behavior of SIGUSR1. Previously USR1 could be
used to halt a running Finit system, similar to BusyBox init. However,
compatibility with sysvinit and systemd has been deemed more important.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name. This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c
https://code.woboq.org/linux/linux/net/core/dev.c.html#1020
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
sulogin should return OK (exit code 0) when the user presses Ctrl-D,
regardless of the prompt shown. Otherwise Finit may look for another
sulogin to run straight after this one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>