make distcheck fails in install:
/usr/bin/install: cannot create regular file '/etc/dbus-1/system.d/org.finit.conf': Permission denied
The policy was installed to $sysconfdir/dbus-1/system.d. distcheck only
overrides the prefix, so the file escaped its sandbox and aimed for the
real /etc.
Install it where dbus looks for package owned policy, leaving
/etc/dbus-1/system.d to the admin. The test bus config reads it
relative to itself.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Two races, both around the post:script Finit runs when it gives up on a
service.
Finit marks the service crashed before it forks post:script, so the file
the test greps for lands a moment later. Waiting for the state is not
enough.
slay then takes the PID from initctl status, and service_post_script()
sets svc->pid to the script's PID, so once Finit has given up the PID
reported for the service is the post:script. Killing that takes out the
script instead of the service and the file never arrives at all. The
guard for this was already there, with a comment describing it, but
inside the loop that waits for a PID to appear, so it only covered the
case where there was none. A PID that was already there went straight
to kill -9. Hence the gcc leg killing once more at lap 13, after Finit
had stopped restarting, where clang stopped at 12.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Once it gives up it forks the post:script and reports that PID as the
service's, so a slay still waiting for the service to come back killed
the script instead, and crashing.sh lost the /tmp/post it checks for.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The other dbus-*.sh tests drive libink's own client, so the wire format
was only ever checked against the implementation that wrote it, and the
broker path had no coverage at all. Every bug found in it so far was
found by hand on a target.
Let the dbus plugin bring up a real dbus-daemon, wait for Finit to
claim org.finit, then talk to Finit with dbus-send, which shares no
code with us. The privileged call is the interesting one: it can only
be answered by parking the call and asking the broker who sent it.
The bus reads the policy Finit installs, so a malformed org.finit.conf
fails here rather than on a target.
Tests no longer build --with-libsystemd. Our replacement carries the
real soname but only the sd_notify() symbols, so in the test root it
shadowed the libsystemd the host's libdbus-1 wants and dbus-daemon
died on a missing sd_is_socket. Nothing under test needs the shared
library: serv is the only consumer and it compiles sd-daemon.c
straight in, which it now does regardless of the flag so notify.sh
keeps testing notify:systemd either way.
Staged from the host by lib/sysroot.mk like any other binary, and
skipped when the host has neither program.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it. Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.
Ask the bus driver instead. libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else. Nothing blocks:
blocking in PID 1 is why libuEv exists. That needs calls libink can
make on a connection it already has, so it gained those too.
Answers are cached, since a bus never reuses a unique name while it
runs. Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does. A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.
Privilege is no longer uid 0 alone. The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot. Both gates now say the same thing.
Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Verify that 'initctl reload foo' properly triggers dependent
services by checking that bar gets a new PID after the reload.
Also change the second test case from service/foo/running to
service/foo/ready which is the actual condition set by pidfile.so.
Fix a race in slay where the target process could exit between
the PID lookup and kill -9, causing spurious test failures in
tight kill loops (e.g., start-kill-service.sh).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Finit now requires being able to query at least for the root user and
group before starting any services.
Also, add support for using libraries installed in /usr/local
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
New test adds /bin/fail.sh to verify that a failing pre:script (that
also takes too long to run) is detected: exit code and timeout.
Ensure existing test pass full path to /sbin/fail.sh script.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.
Additionally, by default `runparts` now runs entirely in the background
without any progress. To enable progress, an optional argument has been
added to the runparts command line.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Multiple parallel tests writing to the same /var leads to quite
unexpected results. Let's start fresh in each test instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Running tests in massive parallel causes failing startk-kill-service.sh.
This in turn was caused by the shared test tool 'slay' that cached its
"oldpid" file to a shared area of the rootfs (tenv-root). It must use a
test instance-specific ramdisk.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Follow-up to abcb3ce, calling the service ready:script when readiness
has been signaled to or detected by Finit.
Issue #300
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This was a tough nut to crack. Spent 3-4 calendar weeks (getting blurry
now) to try and figure it all out. In the end, the following changes
were necessary:
- Ensure setup-root.sh is guaranteed to run before any of the tests
- Give all tests their unique /etc, /tmp, and /run inside the chroot.
Turns out tmpfs+overlayfs can be used unprivileged inside an unshare
- A static BusyBox binary with support for mount helpers so we can
do the mkdir magic in skel/etc/fstab for the /etc overlay
The last item turned out to be a bit of a roller coaster ride of its
own. First of all, the original binary we used was from the upstream
BusyBox project[1]. I was sure it couldn't be that hard to enable the
CONFIG_FEATURE_MOUNT_HELPERS ... oh boy was I wrong. To make long and
tedious story short; two new projects on GitHub were created for this
task: 1) troglobit/misc[2] to house a mirror of https://musl.cc
toolchains and 2) troglobit/busybox-builder[3] to download, patch, and
build the thing using a .config from the myLinux[4] project. Patching
this .config was necessary, however, since musl libc is strict POSIX
and does not have any of the BSD extensions, e.g. REG_STARTEND that is
in GLIBC regex(3).
[1]: https://busybox.net/downloads/binaries/1.31.0-defconfig-multiarch-musl/
[2]: https://github.com/troglobit/misc/releases/tag/11-20211120
[3]: https://github.com/troglobit/busybox-builder/releases/tag/1_35_0
[4]: https://github.com/troglobit/myLinux
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of having to create files, and copying them in place for each
test, we move all static test files to a skeleton rootfs. This makes
it a lot easier to get an overview of how things and how they work.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>