Commit Graph
2378 Commits
Author SHA1 Message Date
Joachim Wiberg 11a3318c02 Properly set status 'missing' for missing binaries and/or env files
When we try to start a service/run/task we call whichp() to see if the
binary exists, either tha absolute path given in the .conf file, or in
the $PATH we run with.  If binary, or the env: file, doesn't exist we
now set svc_missing() state.

On `initctl reload` we unblock the service to be able to check again.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 2711b27971 plugins: pidfile: tricky zebra doesn't close its pid file
This patch fixes a few really hard problems wrt PID files:

 1. Listening for IN_CREATE events means we get notified immediately by
    the kernel when someone calls open()/fopen() on a PID file.  Reading
    the contents returns 0, thank you atoi() ... so we drop IN_CREATE
    and instead look for IN_CLOSE_WRITE, there fixed it!  Not quite ...

 2. Some programs, like Zebra, and other Quagga/Frr daemons, don't
    close() their PID files after creation.  Instead they ftruncate()
    and keep them open, and locked.  Presumably to get a mechanism to
    detect already running instances -- messes life up a bit for the
    rest of us though.  So we need to read files after IN_MODIFY too.

 3. We also want to track IN_DELETE so we can deassert conditions when
    services exit gracefully and clean up their PID files

The rest fo the commit is debug instrumentation changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 05ac9c18c9 Update changelog, new inictcl cond set|clear commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 1a7092f545 doc: update with new 'initctl cond set|clear foo' commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 8000d361b3 initctl: restore 'cond [set|clr] foo' for user-defined conditions
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user.  That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.

This patch restores the behavior, albeit in a very reduced and simple
format.  All conditions set with this command are constrained to the
'usr/...' namespace.  No subdirectories are allowed.  The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:

    initctl cond set foo:2

creates a static/oneshot condition in /run/finit/cond/usr/foo:2

These conditions are static and are fully handled by the user.  The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.

This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory.  When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.

For instance, the following service is not started by default at boot:

    service <usr/foo> myservice -- MyService

However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.

Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions.  This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg e3c8febe3b Refactor; common nomenclature, ordering, possib. security fix
- Use _PATH_foo for all condition paths, *with* trailing /
- Read condition file first, may not exist, in which case we save time
- Change from libte makepath() to mkpath(), this changes from hard-coded
  0777 perms on all cond dirs to 0755 -- possible security fix

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 32ca117949 initctl: refactor command line parser, use concept from mroutectl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg b966d031c8 initctl: enable plain mode for ls and utmp commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-09 21:30:11 +01:00
Joachim Wiberg 905c2678a3 Fix path to fallback console and handle leading /dev from cmdline
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-08 09:33:16 +01:00
Joachim Wiberg 7d429bdbb1 initctl: restore -p,--plain output for headings and ps listing
This is the same output style as used in the mroutectl and pimctl tools.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 23:30:13 +01:00
Joachim Wiberg ccfea59cb3 Bump version for Finit v4.0-rc2 release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
4.0-rc2
2021-03-07 18:50:50 +01:00
Joachim Wiberg 7b315364ca Update initctl help text, and output, relocate screenshot
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 15:38:23 +01:00
Joachim Wiberg e9e28ece1c Add Finit4 + Alpine screenshot
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 15:28:32 +01:00
Joachim Wiberg c1f9b4e1f6 Use .svg for Travis-CI status badge
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 15:17:26 +01:00
Joachim Wiberg 6ebb23e0f0 Travis-CI: Minor, adjust configure line for Coverity
- Drop commented-out sudo:true
- Drop unnecessary configure option

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 15:16:26 +01:00
Joachim Wiberg 026c229005 Revert "Travis-CI: disable clang and unit tests for Coverity Scan run"
This reverts commit c71bafd495.
2021-03-07 15:14:47 +01:00
Joachim Wiberg 4d05bf9359 Mark affected services as dirty if their rdeps are dirty
Provided a configuration that looks like this:

ospfd.conf:
    service [2345] <!pid/zebra> log ospfd -A 127.0.0.1 -u root -g root -- OSPF daemon

zebra.conf:
    service [2345] <!> log zebra -A 127.0.0.1 -u root -g root -- Zebra Routing daemon

If zebra.conf is changed, we restart it when `initctl reload` is issued.

This change ensures that ospfd is also restarted, because ospfd depends
on zebra, we must restart it too.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 14:52:19 +01:00
Joachim Wiberg 289247dab9 plugins: netlink: slightly stricter ifname validation
Check if ifname contains double periods, this should *not* be a valid
name, though eth0.10 is, et0..10 is not.  Should protect better against
directory traversal attacks.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 13:25:40 +01:00
Joachim Wiberg e44dfde54e plugins: tty: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 35b200d3a9 Validate inotify event against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 5badf4d376 plugins: pidfile: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:48:42 +01:00
Joachim Wiberg 24f274c126 plugins: netlink: validate interface name
Check for spaces and slashes in interface name to prevent path based
attacks.  Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:23:24 +01:00
Joachim Wiberg 1abd43384b plugins: netlink: minor refactor, collapse for-loop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:20:59 +01:00
Joachim Wiberg 70a1acc210 Highly unlikekly, but chdir() needs to be checked
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:40:25 +01:00
Joachim Wiberg 6af0446490 plugins: netlink: fix untrusted loop bound, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:28:39 +01:00
Joachim Wiberg ecaf111a4b plugins: tty: possible out-of-bounds read in inotify_event parser
This is a major refactor to use the same construct as in the pidfile.so
plugin to parse kernel inotify events for when TTYs are added removed
from the system.

Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:58:55 +01:00
Joachim Wiberg 32ec25b070 Check return value from remove(), found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:34:23 +01:00
Joachim Wiberg 305ad302f2 Refactor, reduce code duplication
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:28:54 +01:00
Joachim Wiberg d6390244ad Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 790a316607 Log rotate: improved handling of return values from syscalls
- Align the two implementations in logit.c and utmp-api.c
 - Use libite APIs to handle common constructs
 - If gzip fails, don't remove rotated-to file
 - Don't try gzip if rename fails
 - Issues found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 77aa941e84 Mounting devtmpfs may fail if already mounted
Ignore EBUSY errors, the kernel has the ability to automount /dev as
soon as the rootfs has been mounted.  This may be added to procfs and
sysfs later, so we make this a general change in fs_init().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:48:02 +01:00
Joachim Wiberg e0a65f67c9 Minor, staticify, reduce includes and allow debug to kmsg
The loglevel setting should control all logging, regardless of
where we target it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-06 23:55:54 +01:00
Joachim Wiberg 3ed291789c Fix GCC warnings with _FORTIFY_SOURCE=2
- Decleare some return values with (void)fn(), for cases where
  we don't care (dropping table headers), or best effor
- Check return value from fgets() and chdir() in some cases that
  are valid, i.e., continuing execution is pointless

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 12:36:48 +01:00
Joachim Wiberg 774a24cdd8 Allow building with -D_FORTIFY_SOURCE[=1,2]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 11:17:59 +01:00
Joachim Wiberg 6011f91f22 Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 11:16:37 +01:00
Joachim Wiberg 07a364e570 initctl: fix use of possibly unterminated string, found by Coverity
No point in using rq.data, which could have been modified, instead use
the input argument to the function in the error message.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:51:25 +01:00
Joachim Wiberg 5b9d99011b Fix long-standing bug in reset of rlimits between reconf
While skimming through the results of the latest Coverity Scan, I
discovered that that the reset logic of global rlimits was broken.
This it seems to have been since its first introduction in Finit.

We fix this by reading initial rlimits at bootstrap, then for each
reconf, including the first, we seed global rlimits with the initial
ones -- thus resetting between each reconf.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:44:01 +01:00
Joachim Wiberg f4f773b4c7 Initialize fallback svc_t in client comms, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:35:12 +01:00
Joachim Wiberg 9d949c4186 Fix possible NULL ptr deref in cmdline option parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:21:58 +01:00
Joachim Wiberg 1434561a46 initctl: fix cut-and-paste error in new 'show' command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:17:52 +01:00
Joachim Wiberg cf3d3f6f8e Properly check return value from mount(2) and display error message
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:15:46 +01:00
Joachim Wiberg 621da582c2 Fix obvious bug in ismnt() found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:10:45 +01:00
Joachim Wiberg 9167d9255d Work around weird finding from Coverity Scan
The utmp_set() function allows id==NULL, so default the line to NULL and
avoid parsing empty lines.  Which is better code anyway.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 09:59:58 +01:00
Joachim Wiberg c71bafd495 Travis-CI: disable clang and unit tests for Coverity Scan run
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 08:25:32 +01:00
Joachim Wiberg b3b7a33252 initctl: developer mode, hidden command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 08:22:38 +01:00
Joachim Wiberg d1efc60c84 initctl: add show command to cat foo.conf, default finit.conf
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 08:06:01 +01:00
Joachim Wiberg 9a24dfd98d initctl: refactor command composition for status command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 00:13:01 +01:00
Joachim Wiberg 0e3fe5e3bf initctl: fix too long args list to status command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 00:06:36 +01:00
Joachim Wiberg 224f42c344 cgreaper.sh: drop log message when cleaning up
Mostly used during development, doesn't really provide any value to the
user at normal runtime.  Leave it commented out though so user can do
debug themselves if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:57:48 +01:00
Joachim Wiberg e60eb94810 initctl: complete rewrite of cgroup dumper in 'ps' command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:49:42 +01:00