The service_fork() function blocks all signals for the new process, it
is up to the callee to call sig_unblock() before calling exec().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add explicit argument separator before username to ensure correct
parsing of the login command regardless of username format. This
follows best practices for command execution and prevents unexpected
behavior when processing special characters in usernames.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a service is stopped, but does not respond to the default SIGTERM,
a fallback kicks in after 3 seconds (default) to send SIGKILL. Since
91a9c83 (v3.2-rc2) this has however not worked since the signal was
only sent to the process group.
It is the job of service_monitor(), when it reaps the process leader,
to forward the signal to the process group.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Don't try to source an optional env:file if it is missing. Otherwise
execution of pre/post/ready/cleanup script will fail.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Initiating a shutdown/reboot from `initctl` should not cause `initctl`
to be killed in do_shutdown().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a user sets up a TTY without a device, triggering the tty->notty
code path, the tty->dev will be NULL and tty_parse_args() still return
OK result.
Found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When using Finit with an external getty that supports alternative login
program argument, the tty_parse_args() function did not check if a getty
command had already been registered:
tty [12345] /sbin/agetty -L -l /bin/login console noclear
This caused Finit to try /bin/login as the getty program.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change introduces two new states for the big Finit state machine:
runlevel-clean and reload-clean. Here Finit now waits for any post or
cleanup script to finish before returning OK to the initctl command.
Additionally, the service state machine has been updated to ensure a
run/task/sysv/service calls any post or cleanup script before they are
removed. A new 'dead' state for svc_t is introduced which any removed
svc_t ends up in now instead of becing collected from 'halted' state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add cleanup:script support, runs at service removal
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some subsystems call iwatch_add() without first calling iwatch_del() on
the same path. E.g., cgroup_config().
Issue #417 but unclear atm. if this is the root cause.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A long running pre/post/ready script must be killed properly, not by
targeting its process group. Process group cleanup is handled by the
service_monitor() when reaping the script's PID.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check exit status of `pre:` scripts, on failure drive service/sysv to
`crashed` state. The exit code of `post:` scripts remain ignored for
now.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Syntax:
[pre|post|ready]:[0-3600,]/path/to/script
Description:
Before this patch all pre/post/ready scripts used the global kill
delay as timeout. After this patch it is possible to disable the
timeout as well as set a timeout >60, which is max kill delay.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Follow-up to 465bc17, which addressed unintended restart of siblings.
This patch fixes a problem where template instantiated services are not
properly reloaded/restarted when marked as "dirty" with `initctl touch`.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.
this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.
for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
Consider the case where container@.conf is an available template. When
creating a container@foo.conf it will share the same base .conf as an
existing container@bar.conf, but we do not expect to restart bar just
because foo is instantiated.
Up until this change, all template siblings were considered "dirty" if a
new one was created or updated. Skipping realpath() for all files that
have a '@' works around the problem.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some boot loaders, like GRUB, leave background color artifacts from
their boot menu. This patch resets the foreground and background
color attributes, and then clears the screen, without clearing the
scrollback buffer.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch changes a behavior that's been default since Finit 4.0,
introduced in 4d05bf9 with 4.0-rc2.
If service B depends on A and A needs to be reloaded, then B may be
affected. If A is declared as NOHUP <!>, then A will be stopped and
restarted, during which time the condition it provides is removed,
and B will also be stopped.
However, and as of this patch, if A is declared supporting HUP, then the
condition A provides will only go into flux, during which time B will be
SIGSTOPed instead of needing to be reloaded.
Fix#415
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When dealing with "L+" and "R", the function call 'nftw' should not
follow symbolic links, otherwise, it would also delete the targets
which is wrong.
For instance, if there is already a symbolic link:
```
/path/to/the/link -> /path/to/some/folder
```
if we set the following in a tmpfile conf:
```
L+ /path/to/the/link - - - - /path/to/the/target
```
the result would be /path/to/some/folder also get deleted, which it
should not.
it could be even worse, when the symbolic link already is pointing to:
/path/to/the/target, the whole /path/to/the/target would be deleted on
next system boot.
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console. For embedded
systems, which is the primary target for Finit, this is what you want
to see.
Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console. A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Systems that have the following tty setup and multiple consoles listed
in /sys/class/tty/console/active misbehave:
tty [12345789] @console 0 xterm noclear passenv
Only the first listed console is started properly, the remaining ones
were registered using the wrong :ID and no arguments to getty.
This patch fixes the parsing and re-use of the base paramenters for
all consoles listed in the active file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>