Commit Graph
1501 Commits
Author SHA1 Message Date
Joachim Wiberg ac4b9c2f93 Unblock signals for pre/post/ready/cleanup scripts
The service_fork() function blocks all signals for the new process, it
is up to the callee to call sig_unblock() before calling exec().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-27 19:10:56 +01:00
Joachim Wiberg 6528628b5c getty: improve argument handling when launching login
Add explicit argument separator before username to ensure correct
parsing of the login command regardless of username format.  This
follows best practices for command execution and prevents unexpected
behavior when processing special characters in usernames.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-18 13:18:10 +01:00
Joachim Wiberg 33e378a345 Fix #432: allow services in 'setup' to be stopped
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-18 07:21:44 +01:00
Joachim Wiberg b695b46a9d Revert last part of 91a9c83, fallback SIGKILL when stopping services
When a service is stopped, but does not respond to the default SIGTERM,
a fallback kicks in after 3 seconds (default) to send SIGKILL.  Since
91a9c83 (v3.2-rc2) this has however not worked since the signal was
only sent to the process group.

It is the job of service_monitor(), when it reaps the process leader,
to forward the signal to the process group.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-18 07:18:16 +01:00
Joachim Wiberg 0e61ed727f Add helper function, svc_is_stopped() when stopped by user
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-18 07:17:37 +01:00
Joachim Wiberg e9d60a6c04 Minor, coding style
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-18 07:17:23 +01:00
Joachim Wiberg 8ed2751ae1 Fix pre/post/ready/cleanup script execution if env:file is missing
Don't try to source an optional env:file if it is missing.  Otherwise
execution of pre/post/ready/cleanup script will fail.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 18:39:05 +01:00
Joachim Wiberg 7fec66dc09 Simplify, svc_checkenv() already checks if optional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 18:38:31 +01:00
Joachim Wiberg 75fa868a4b Fix various typos found by codepsell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 16:46:28 +01:00
Joachim Wiberg 1691ebb292 logit(): RFC3164 conformance for /dev/kmsg fallback
RFC3164 section 5.3 states; "a colon and a space character usually
follow the TAG".  This is also the reference format in the kernel:
https://www.kernel.org/doc/Documentation/ABI/testing/dev-kmsg

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-03 03:39:55 +01:00
Joachim Wiberg 9210f2851e Skip killing initctl on shutdown/reboot
Initiating a shutdown/reboot from `initctl` should not cause `initctl`
to be killed in do_shutdown().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-25 08:37:27 +01:00
Joachim Wiberg 9a357b7aab Fix possible NULL pointer dereference
When a user sets up a TTY without a device, triggering the tty->notty
code path, the tty->dev will be NULL and tty_parse_args() still return
OK result.

Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 10:30:16 +01:00
Joachim Wiberg 1f2c1d2109 Minor, staticify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:46:43 +01:00
Joachim Wiberg f328d24d01 Fix possible overflow in return value
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:29:56 +01:00
Joachim Wiberg 211293a83d Fix possible overflow in return value
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:28:26 +01:00
Joachim Wiberg 446f5bc8b8 Fix possible memory leak in sourcing of environment file
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:26:54 +01:00
Joachim Wiberg 0c6f748f2c Fix invalid pointer use in log message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:23:22 +01:00
Joachim Wiberg a677b94ad9 Minor, coding style fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:05:55 +01:00
Joachim Wiberg 6552cda605 Fix #427: make sure first found binary is used as external getty
When using Finit with an external getty that supports alternative login
program argument, the tty_parse_args() function did not check if a getty
command had already been registered:

    tty [12345] /sbin/agetty -L -l /bin/login console noclear

This caused Finit to try /bin/login as the getty program.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:02:00 +01:00
Joachim Wiberg 3add682be3 Wait for post:script and cleanup:script before returning OK
This change introduces two new states for the big Finit state machine:
runlevel-clean and reload-clean.  Here Finit now waits for any post or
cleanup script to finish before returning OK to the initctl command.

Additionally, the service state machine has been updated to ensure a
run/task/sysv/service calls any post or cleanup script before they are
removed.  A new 'dead' state for svc_t is introduced which any removed
svc_t ends up in now instead of becing collected from 'halted' state.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>

Add cleanup:script support, runs at service removal

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 02:36:34 +01:00
Joachim Wiberg abac31682d Handle UEV_ERROR properly in all libuev callbacks
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 02:34:31 +01:00
Joachim Wiberg cfe915e6d5 Reclassify sysv, more like service than run/task
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 02:34:30 +01:00
Joachim Wiberg cf201a43df Add cleanup:script support, runs at service removal
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-17 05:16:28 +01:00
Joachim Wiberg 0a8f3a6250 Fix #425: flush .conf file events before reload and runlevel change
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-13 07:06:13 +01:00
Joachim Wiberg 70c4e7d774 iwatch: ensure adding a new watcher is idempotent
Some subsystems call iwatch_add() without first calling iwatch_del() on
the same path.  E.g., cgroup_config().

Issue #417 but unclear atm. if this is the root cause.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-13 05:53:24 +01:00
Joachim Wiberg 4b06e1a49f Silence overly verbose debug messages in cond_set/clear/update
These functions call other functions that log more detailed information.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:35 +01:00
Joachim Wiberg 6b9aa21509 Minor cleanup, code (style) and comments
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:35 +01:00
Joachim Wiberg 990307fbc9 Fix kill() on timeout of pre:/post:/ready:scripts
A long running pre/post/ready script must be killed properly, not by
targeting its process group.  Process group cleanup is handled by the
service_monitor() when reaping the script's PID.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:34 +01:00
Joachim Wiberg 9d8a9b7fba Check for pre:- and post:scripts in $PATH
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:34 +01:00
Joachim Wiberg 23d034f521 Prevent main process from starting if pre: script fails
Check exit status of `pre:` scripts, on failure drive service/sysv to
`crashed` state.  The exit code of `post:` scripts remain ignored for
now.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 09:39:40 +01:00
Joachim Wiberg 8560103a24 Add individual timeout support for pre/post/ready scripts
Syntax:
    [pre|post|ready]:[0-3600,]/path/to/script

Description:
    Before this patch all pre/post/ready scripts used the global kill
    delay as timeout.  After this patch it is possible to disable the
    timeout as well as set a timeout >60, which is max kill delay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-10 10:43:37 +01:00
Joachim Wiberg 7a75e34808 Fix initctl touch of template services
Follow-up to 465bc17, which addressed unintended restart of siblings.
This patch fixes a problem where template instantiated services are not
properly reloaded/restarted when marked as "dirty" with `initctl touch`.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-10 10:43:37 +01:00
Aaron Andersen 048302f06a add systemd-nspawn to the list of container types 2025-02-02 08:58:36 -05:00
az 3cfe0a33b8 fstab with UUID/LABEL: nofail handling for fsck
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.

this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.

for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
2024-12-20 09:09:24 +10:00
Joachim Wiberg 465bc17ca4 Fix unintended restart of template siblings
Consider the case where container@.conf is an available template.  When
creating a container@foo.conf it will share the same base .conf as an
existing container@bar.conf, but we do not expect to restart bar just
because foo is instantiated.

Up until this change, all template siblings were considered "dirty" if a
new one was created or updated.  Skipping realpath() for all files that
have a '@' works around the problem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-11-28 11:13:44 +01:00
Joachim Wiberg 119e66a7e9 Reset color attributes and clear screen when starting up
Some boot loaders, like GRUB, leave background color artifacts from
their boot menu.  This patch resets the foreground and background
color attributes, and then clears the screen, without clearing the
scrollback buffer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-28 10:58:04 +01:00
Joachim Wiberg 46ffa81f5c Only mark rdeps dirty if main service is nohup
This patch changes a behavior that's been default since Finit 4.0,
introduced in 4d05bf9 with 4.0-rc2.

If service B depends on A and A needs to be reloaded, then B may be
affected.  If A is declared as NOHUP <!>, then A will be stopped and
restarted, during which time the condition it provides is removed,
and B will also be stopped.

However, and as of this patch, if A is declared supporting HUP, then the
condition A provides will only go into flux, during which time B will be
SIGSTOPed instead of needing to be reloaded.

Fix #415

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-17 14:33:30 +02:00
Joachim Wiberg 56e558c960 initctl: add support for showing template@foo.conf
Fixes #411

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-13 19:40:21 +02:00
Joachim Wiberg dfaf351da1 Fix #414: zebra immediately restarts if manually stopped
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-13 19:40:21 +02:00
Ming Liu 3e3e9aadf5 tmpfiles.c: prevent nftw follow symbolic links
When dealing with "L+" and "R", the function call 'nftw' should not
follow symbolic links, otherwise, it would also delete the targets
which is wrong.

For instance, if there is already a symbolic link:
```
/path/to/the/link -> /path/to/some/folder
```

if we set the following in a tmpfile conf:

```
L+ /path/to/the/link -    -    -     - /path/to/the/target
```

the result would be /path/to/some/folder also get deleted, which it
should not.

it could be even worse, when the symbolic link already is pointing to:
/path/to/the/target, the whole /path/to/the/target would be deleted on
next system boot.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2024-08-24 13:29:10 +02:00
Mathias Thore a0685219cf Avoid remounting already mounted /run and /tmp directories
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
2024-08-05 14:33:43 +02:00
Joachim Wiberg 13b107b7b1 Fix #407: extend initctl poll timeout
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-22 09:23:14 +02:00
Joachim Wiberg ab62b5282b runparts: add -b (batch) mode for syslog output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-19 09:20:03 +02:00
Ming 9a0dea6aef configure.ac: make cgroup2 configurable (#406) 2024-05-11 14:06:01 +02:00
Joachim Wiberg 8251f1a422 Fix derefernce before NULL check
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:40:05 +02:00
Joachim Wiberg 612f5a9385 Allow building Finit --without-rc-local support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:25:53 +02:00
Joachim Wiberg 4a2381eb6f Fix #404: possible undefined behavior --without-fstab
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:22:57 +02:00
Joachim Wiberg 0cae7d44dd Follow-up to 6a89e60, len may be used unitialized
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:21:22 +02:00
Joachim Wiberg 340cae4afd Change default behavior, allow kernel logs to console
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console.  For embedded
systems, which is the primary target for Finit, this is what you want
to see.

Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console.  A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-24 12:46:59 +02:00
Joachim Wiberg 6a89e60fc8 Fix #405: parsing >1 active consoles in tty @console setups
Systems that have the following tty setup and multiple consoles listed
in /sys/class/tty/console/active misbehave:

    tty [12345789] @console 0 xterm noclear passenv

Only the first listed console is started properly, the remaining ones
were registered using the wrong :ID and no arguments to getty.

This patch fixes the parsing and re-use of the base paramenters for
all consoles listed in the active file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-24 11:33:35 +02:00