With the new practise of keeping record of process pid files, we no
longer need to log/update when reading back the same PID we already
have on file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Services that create their own PID files usually don't declare one with
Finit. This patch adds support to track those PID files anywayt at
runtime for the purpose of identifying match svc_t when a PID file is
removed, i.e. when a service exits.
- On IN_CREATE the pidfile.so plugin saves the pid file name in svc_t
- On ON_DELETE the pidfile.so plugin finds svc_t based on pid file
Quicker tracking and less dead code, win-win.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes a few really hard problems wrt PID files:
1. Listening for IN_CREATE events means we get notified immediately by
the kernel when someone calls open()/fopen() on a PID file. Reading
the contents returns 0, thank you atoi() ... so we drop IN_CREATE
and instead look for IN_CLOSE_WRITE, there fixed it! Not quite ...
2. Some programs, like Zebra, and other Quagga/Frr daemons, don't
close() their PID files after creation. Instead they ftruncate()
and keep them open, and locked. Presumably to get a mechanism to
detect already running instances -- messes life up a bit for the
rest of us though. So we need to read files after IN_MODIFY too.
3. We also want to track IN_DELETE so we can deassert conditions when
services exit gracefully and clean up their PID files
The rest fo the commit is debug instrumentation changes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user. That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.
This patch restores the behavior, albeit in a very reduced and simple
format. All conditions set with this command are constrained to the
'usr/...' namespace. No subdirectories are allowed. The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:
initctl cond set foo:2
creates a static/oneshot condition in /run/finit/cond/usr/foo:2
These conditions are static and are fully handled by the user. The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.
This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory. When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.
For instance, the following service is not started by default at boot:
service <usr/foo> myservice -- MyService
However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.
Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions. This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fix ev->len validation; must check against sz read(), not total buffer
size. Also, fix off-by-one in comparison.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With the redesign from <svc/path/to/pidfile> to <pid/name:id> in d1fac6f
we moved to matching svc_t only against their PID, which could pop up in
any *.pid or */pid in /var/run. This patch drops the (hopefully) last
remnants of the old <svc/> legacy.
To ensure we don't try reading the PID value from socket files, like
/var/run/initctl, we add simple fnmatch() of the inotified file. Two
calls to fnmatch(), for portability reasons, not every system has GNU
libc extensions like FNM_EXTMATCH.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch removes the built-in inetd support from Finit. We recommend
using an external inetd instead, e.g. xinetd.
If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it. We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.
So long for now, old friend.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation. Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.
However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit. To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.
Connecting the dots between these wasn't obvious.
This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser. Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The recently updated pidfile plugin now also watches the subdirectories
in /var/run, but for that to work it must witness the creation of these
subdirectories. The bootmisc plugin creates several, e.g., /run/quagga/
in which PID files like zebra.pid are created.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,
- /var/run/teamd/a1.pid -- For aggregate A1
- /var/run/dbus/pid
- /var/run/lxc/foo.pid -- For container foo
This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).
To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax. This pid file name
is also used to create the condition this service asserts using the
following formula:
svc/ + <dirname of service> + <subdir and file without .pid>
E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'
The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory. It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid. Matching files follow the teamd
case. The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'
One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo. The service stanza:
service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo
This command has no leading path so the condition is composed entirely
from the PID file location:
svc/ + '' + lxc/foo => svc/lxc/foo
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We can now rely on service_step() to continue stepping run/taks/services
until no more state transitions are made.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Reassert condition when an unchanged/unmodified process goes from
WAITING state to RUNNING. I.e. it had a condition that went to flux
during `initctl reload`, which drove it to WAITING and was then sent
SIGSTOP during reconf.
Also, on condition update, loop through all services until no more state
changes are observed. This allows long dependency chains of services to
resolve and actually go back to RUNNING state as intended whenever any
condition changes at runtime.
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The pidfile plugin just listens to changes in files in /run or /var/run,
so when trying to locate an svc_t from a file change we need to compare
using the proper prefix path.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
A service may now have a custom PID file, possibly because it doesn't
really create one itself. This needs to be taken into account also in
the pidfile plugin.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch implements support for calling run/task jobs on the built-in
`HOOK_*` points in Finit. To map each HOOK point to a condition a new
classification was made, as shown in plugin.h and in the example below.
task <hook/mount/root> /sbin/attachubi.sh # run in parallel with other tasks/services
run <hook/net/up> /sbin/dosomething.sh # run in sequence with other commands
Please note, only rudimentary tested.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When performing an `initctl reload` with one (unchanged) service
depending on, e.g. `net/iface/lo`, its condition will not be set
to ON by the pidfile plugin unless the netlink plugin hook runs
first.
Example:
service <net/iface/lo> /sbin/dropbear ...
Which provides the <svc/sbin/dropbear> condition, will not be
set by pidfile.so during `initctl reload` because dropbear is
still SIGSTP:ed waiting for <net/iface/lo>.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
In GCC 7 the -Wall infers the new -Wformat-truncation which finds
problems with string truncation in functions like snprintf().
This patch fixes a problem in condition parsing for very long
PID filenames which might be truncated in internal buffers
causing a mismatch in Finit condition tracking.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If a service depend on the service last in the list the application
will be kept in flux state forever.
Signed-off-by: Mattias Walström <mattias.walstrom@westermo.se>