Implement supplementary group support for services, allowing them to
access resources owned by multiple groups. Uses the @user:group,sup1,sup2
syntax to explicitly specify supplementary groups, in addition to now
reading group membership from /etc/group.
Cgroups v2 limits are hierarchical - a process is constrained by the
most restrictive limit in its ancestor chain, not just its immediate
cgroup. This patch updates cg_conf() to walk up the hierarchy and
report effective limits by comparing values at each level.
This fixes incorrect "max" (unlimited) reporting in 'initctl --json
status', 'initctl cgroup', and 'initctl top' when child cgroups have
no explicit limits but parents do.
For memory.max and cpu.max: take minimum (most restrictive)
For memory.min: take maximum (most protection)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Comment-out code that makes the cursor "jump" around at boot before
displaying: Please press Enter to activate this console.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes an issue where the mouse scroll wheel and Shift+PgUp/PgDn
sometimes would not work properly after login.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Drop clear screen to fix flickering in 'initctl top' output. Also, make
sure to not garble the display if the the terminal is too small.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This should not be needed, but for some reason we don't get events when
early processes exit, so we end up with lingering cgroups.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The container monitor that podman forks off when starting a container
instance creates subgroups in the cgroup v2 hieararchy that we want to
reuse. This patch adds cgroup_move_svc() which we call from the pidfile
plugins to relocate the conmon process.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit activates the use of clone3() for service_fork(), to allow
Linux to create the new process directly in the correct cgroup instead
of later moving it there -- much cheaper and less error prone.
To facilitate this a few new helper cgroup functions have been added and
two new configuration directives introduced: delegate and name:leafname.
The delegate option is for running, e.g., container runtimes that want
to create their own cgroup v2 structur, and the name:leafname allows a
user to change the name of the subgroup under user/system/init.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The PTY approach caused isatty() to return true for services using
the log directive, triggering programs like fprintd (using glib) to
emit ANSI escape codes and other TTY-specific formatting in syslog.
Using a standard pipe ensures isatty() correctly returns false, so
programs produce plain text output suitable for logging.
For services that require line-buffered output, users can wrap the
command with `stdbuf -oL` as documented in doc/config/logging.md.
Fixes#455
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When setting up a new system with Finit it is very common to make small
logical mistakes that cause "hangs" at boot. This is when Finit waits
for 180 sec. for run/tasks to complete before moving to the configured
runlevel. This patch adds console input monitoring during bootstrap
wait that allows users to press Ctrl-C to skip waiting and proceed to
the configured runlevel.
When Ctrl-C is detected, all incomplete run/task/services are logged
to syslog for later troubleshooting after login.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Relax the constraints introduced in a39ee0b, for issue #342, a bit on
when start/stop/restart/reload service can be called. Also, allow
'initctl reload', but ignore it when the system is in runlevels S/0/6.
This makes it possible to start manual:yes type services at botostrap,
for example, which has been a common feature request.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add missing memory information to JSON output in json_status_one().
The memory field shows cgroup memory usage in bytes when cgroup
support is available and the service has a valid PID, matching
the behavior of the text status output.
Signed-off-by: Richard Alpe <richard@bit42.se>
Implement Linux capability support for services, allowing them to run
with minimal required privileges instead of running as root. This uses
the modern IAB (Inheritable, Ambient, Bounding) API from libcap.
Allow service IDs up to 64 characters to support SHA-256 hashes,
UUIDs, and other long unique identifiers. This increases memory
usage by ~98 bytes per service instance, which is negligible for
typical deployments.
The IDENT column width in initctl output adapts dynamically based
on actual ID lengths in use, so short IDs remain unaffected.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Both service and sysv stanzas support a cleanup:script (since v4.10), with an
optional timeout. These timers must be stopped when collecting a PID for an
svc_t, or when unregistering an svc_t, otherwise the timer callback will be
continuously called, reporting "spurious problem", and cause 100% CPU usage.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes an ordering issue where the configuration generation is
stepped before all old/disabled services had been stopped. Finit should
ensure disabled services are stopped before entering the next generation.
If the genation is stepped first, all conditions are put in "flux" state,
so, e.g, a podman container running as a sysv service may lock-up until
it is killed by Finit. Found in the Infix OS project.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Also, added benefit, we don't get compiler warnings for ignoring the
return value of system(), which we don't care about in this case.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>