Finit speaks D-Bus itself now and claims org.finit on the system bus
when it finds one, but nothing in a default build ever brings that bus
up. The plugin that does was opt-in, so the built-in support sat idle
unless the integrator knew to ask for both halves.
Defaulting it on is only reasonable if the result stays the admin's to
change, and a service registered from C through conf_save_service() is
not: it lands in the run path where it cannot be overridden or emptied
out. So the daemon moves to 20-dbus.conf and its directories to
tmpfiles.d/dbus.conf, the same way hotplug and every other daemon we
ship them for. The plugin keeps only what has to look at the running
system, the stale pidfile and the machine UUID.
Those directories are no longer chowned to messagebus. tmpfiles.d
skips a line whose user does not exist rather than falling back, so
the plugin's messagebus/dbus/root ladder has no equivalent there, and
dbus-daemon binds its socket before dropping privileges anyway.
The plugin already bows out where there is no dbus-daemon installed,
so systems that never wanted a bus are unaffected, and
--disable-dbus-plugin is there for those that have one and would still
rather init left it alone.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The runparts directory and the dbus pidfile and daemon paths are
embedded in double-quoted values of the generated block files. A
literal quote in either ends the value early and libconfuse rejects
the whole file, and a backslash is read as an escape sequence,
silently mangling the path. The legacy one-liners had no quoting, so
neither failure existed before the block conversion.
conf_escape() doubles backslashes and escapes quotes; verified by
round-tripping hostile paths through cfg_parse_buf().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Finit's own generated services -- watchdogd, keventd, runparts, and
the dbus plugin -- still went through conf_save_service() as legacy
one-liners, so `initctl show keventd` taught the old format on a
system otherwise converted to the new one.
conf_save_service() now takes the block title and a printf-style body
and writes the file itself:
# Generated by finit:conf_save_service()
service keventd {
description = "Finit kernel event daemon"
runlevel = "S12345789"
notify = "none"
cgroup init {}
command = "/libexec/finit/keventd"
}
vfprintf() into the file also removes the fixed-size staging buffers
in the callers, where a long dbus pidfile path could truncate inside
a quoted string and take the whole generated file with it.
Semantics preserved: watch-only pid:! maps to pidfile without
pidfile-create, the watchdog keeps its watchdog:finit identity, and
log:console becomes log { file = "/dev/console" }.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Prevent name clash with upcoming refactor and any confusion with
src/plugin.c functions with the same name.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change expands the readiness notification system in Finit with the
native 'pid' style, which will remain the default readiness in Finit 4.x
For systems that want to transition to Finit 5.x early, a global option
to set 'readiness none' in /etc/finit.conf, has been added. This change
the service default notification mode to 'notify:none', which can also
be set by Finit 4.x ('readiness pid') for select services.
Fixes#386.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This adds a new function conf_save_service() replacing service_register() for
plugins and bundled services like watchdogd, keventd, runparts, etc.
The benefits to this change are several:
- Plugin/Bundled services no longer risk starting before udev or other
critical services/task have started
- Definitions can be overridden by an administrator (see docs)
- Increases visibility (user: where are all these services coming from?)
Previously the origin (file the service was loaded from) was NULL.
- Adds another level of extensibility to Finit
The most notable change is that dbus is no longer started before udevd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some services (openresolv) tries to talk to it very early, so lets get
dbus up and running as soon as possible.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of the revert in c9fe9afa, we restore HOOK_BASFFS_UP to its
proper place at the end of fs_mount_all(). For this to not cause any
regressions we add a new hook, HOOK_SVC_PLUGIN, and update all plugins
that call service_register() to run at the new hook.
This will cause regressions for external 3rd party plugins that rely on
HOOK_BASEFS_UP to be called at its previous postion. Nevertheless, this
is the proper fix to the problem.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Not all Linux systems are based on Debian, and even if they are inspired
by Debian (Buildroot), they do not necessarily use the same defaults.
This patch probes the current system for:
- dbus user and group
- dbus PID file
If the user/group cannot be found we fall back to "root", if the PID
file cannot be determined we ignore PID file readiness.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Prefix plugin defines with DBUS_ to allow overriding at build-time
- Create missing directories for modern d-bus
Signed-off-by: Andy Savage <andy@savage.hk>
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from
lite/*.h -> libite/*.h
This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config. This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Both DBUS user and pidfile is configurable in DBUS compilation, by
passing "--with-dbus-user=" and "--with-system-pid-file=", let's avoid
hard-coding them here, use macros instead.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup. This is a workaround to ensure they are assigned one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.
Essentially, only services in rescue.conf should run in rescue mode.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This plugin should be able to start much earlier than on network UP,
it uses a UNIX domain socket to communicate so loopback should not be
needed.
Also, Finit supports runvels up to 9 (0 and 6 are special), so allow
dbus to run in all these runlevels. It is up to the user/OS to set
any policy for what runlevels to use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This reverts commit df89cc79b9. Not all
distros (Debian, Alpine) have a dbus-daemon that supports --syslog-only
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch extends the existing rlimit implementation to support setting
limits per service, run/task, inetd, and tty.
Use rlimit in /etc/finit.conf to change the global setting, which is
then inherited to each /etc/finit.d/*.conf. For each .conf file the
rlimit is reinitialized to the global finit.conf settings.
Also, add `unlimited` keyword, to replace the now deprecated `infinity`
keyword. The latter is however kept, for compatibility with previous
releases, for the foreseeable future.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch changes how the D-Bus plugin starts dbus-daemon, from being
started in the background to letting Finit start and monitor it.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Still TODO, replace `run_interactive()` start of dbus-daemon with a
proper service. Possibly only service_register() is needed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Libraries and system headers should be included with <> instead of "".
This makes a great difference for the automatic dependency tracking.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When building a static Finit the plugins do not get a unique name
automatically from the file. This led to only the first plugin being
loaded, since its name was 'unknown' it was registered as such and all
other plugins conflicted, since 'unknown' was already ... known and
loaded.
This patch gives all plugins a default name, __FILE__, making it
possible to use all of them when building a static Finit.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>