Finit had no way to answer the question every service manager gets
asked: what is running, and change it. D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.
So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET. It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top. Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.
Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Relocate process-wide global variables from legacy parser that ended up
there because it used to be conf.c, but which is now now frozen at the
4.x feature set. Each variable is moved to their respective "owner".
Give cgroup_current[] and cgroup_settings_current[] named bounds. Their
extern declarations were unsized, so sizeof() on them stopped compiling
once the definitions moved to another translation unit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In containerized or virtualized environments, standard mount point
directories may not exist at boot. Ensure they are created before
attempting to mount.
Finit has support for "Please press Enter to activate this console."
which means there's no getty yet running. However, when profiling
systems with Finit, and embedded systems in general, a common metric
is the time from power-on to getty has started.
This commit makes sure to rename the process so that BusyBox pidof is
capable of detecting that "getty" has started. This is mostly for the
bootchart2 project's bootchartd, the native BusyBox bootchartd does not
have this issue.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When running Finit under boothcartd (bootchart2 project) the PATH is
lost due to a bug. This was a wakeup, so set critical variables in
main() early, before calling fs_init().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These variables really belong in conf.c. Relocate and move external
decls. from finit.h -> conf.h to simplify linking of other programs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This refactor should have been done years ago when we first introduced
the big state machine. The old functions service_runvel() and the oddly
named service_reload_dynamic() are actually state machine control fns,
so let relocate them.
Also in this commit, remove the global variable 'sm' and rename a few of
the critical functions to better names.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.
this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.
for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console. For embedded
systems, which is the primary target for Finit, this is what you want
to see.
Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console. A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Inspired by Alpine Linux, add /dev/mqueue if missing. We should check
the /proc/filesystems first, but this is quicker.
The sticky bit ensures only the owner of files in /dev/shm can delete or
rename files. This is also what Alpine Linux use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change expands the readiness notification system in Finit with the
native 'pid' style, which will remain the default readiness in Finit 4.x
For systems that want to transition to Finit 5.x early, a global option
to set 'readiness none' in /etc/finit.conf, has been added. This change
the service default notification mode to 'notify:none', which can also
be set by Finit 4.x ('readiness pid') for select services.
Fixes#386.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.
Additionally, by default `runparts` now runs entirely in the background
without any progress. To enable progress, an optional argument has been
added to the runparts command line.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
As pointed out in #366, the configure options --enable-fastboot and
--enable-fsckfix should just alter the default values of the two fsck
command line options.
This commit simplifies the code and makes it possible to override using
the command line regardless of the two build options.
Finally, add the two command line options to doc/cmdline.md
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The code refactored in this commit has long been an eyesore. The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.
Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.
Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls. To
ensure they run at the same point in time two things have been done:
1. A new <int/bootstrap> condition has been added which triggers
runparts, which now is a regular task created by conf_init()
2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
transition from runlevel S to any other runlevel.
Fixes#356
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff. If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.
This change is quite invasive. It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When this code was moved from finit.c we rely on WDT_DEVNODE to be
defined in config.h, which is controlled by configure. Meaning, before
the relocation, Finit did not honor the configure settings.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
All services registered in the system rely on conf_init() having been
set up properly, e.g., global_rlimit. Having conf_init() be responsible
also for registering static services is only logical, and also helps us
clean up main() a bit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of the revert in c9fe9afa, we restore HOOK_BASFFS_UP to its
proper place at the end of fs_mount_all(). For this to not cause any
regressions we add a new hook, HOOK_SVC_PLUGIN, and update all plugins
that call service_register() to run at the new hook.
This will cause regressions for external 3rd party plugins that rely on
HOOK_BASEFS_UP to be called at its previous postion. Nevertheless, this
is the proper fix to the problem.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This reverts commit 5b41c6e since it causes regressions in plugins
adding services to the system. The proper fix for early bootmisc
is to add a new hook, which will be added in subsequent commits.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slightly different take on issue #334 making it optional, possible to
enable per system.
reboot-delay <0-60> # default: 0 (disabled)
When enabled (non-zero), runs after filesystems have been unmounted,
the root filesystems has been remounted read-only, and sync(2) has
been called, twice.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
At this hook point the bootmisc.so plugin runs and creates all relevant
system directories. Much of the rest of system bootstrap relies on this
so it should be called together with the other FS hooks as soon as all
the filesystems have been mounted.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
All hook scripts are called with at least one environment variable set,
FINIT_HOOK_NAME, useful when reusing the same hook script for multiple
hook points. It is set to the string name, also used by the path, e.g.,
hook/net/up.
For all hook points from hook/sys/shutdown and later, FINIT_SHUTDOWN is
also set, to one of: halt, poweroff, reboot.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For all other run_parts() use-cases we just give the script control over
stdout/stderr to prevent clobbering ANSI color escape codes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This reverts commit 03c08d3970 due to it
breaking handling of bootstrap tasks, causing endless boot loop.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.
For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added. It in turn can be used by factory.conf
as follows to override /etc/finit.d:
rcsd /etc/factory.d
Manually verified in myLinux
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Always better to have at least one sulogin available, if the system
provided sulogin isn't available we fall back to the built-in one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This delays the start of the .conf monitor and service initialization
slightly to allow the event loop to run earlier to process any events
from the initial setup.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This seemed odd at first, but it turns out we seem to have adjusted the
time scale for the bootstrap worker, so we were off by ... a factor 10.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>