Commit Graph
898 Commits
Author SHA1 Message Date
Joachim Wiberg 221ab20898 tty: add basic security, call sulogin in rescue mode (notty)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:27:26 +02:00
Joachim Wiberg 96534789db Minor, rename LOGIT_PATH -> _PATH_LOGIT for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:26:52 +02:00
Joachim Wiberg 799e992542 tty: minor, rename local variables for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:58 +02:00
Joachim Wiberg 6dced29b49 Add another constraint for the built-in watchdog, device exists
- Check if watchdogd *and* `WDT_DEVNODE` exists before registering the
   built-in watchdogd at boot
 - Update bootstrap.md with this additional constraint
 - Update config.md with references to bootstrap and the new constraint

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:57 +02:00
Joachim Wiberg 985df20519 cgroup: don't warn on cgroup.events EINVAL for top-level groups
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 07:42:31 +02:00
Joachim Wiberg 25c5014d3c Also check env: file for changes to detect svc->args_dirty
This patch fixes an issue where services that support SIGHUP are not
properly stop/started on changes to their command line arguments.

A change to a service's env: file, e.g. /etc/default/foo for service
foo, must also be counted as a change to the foo args.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-23 17:12:59 +02:00
Joachim Wiberg b8b7b53d96 External plugins require exporting cgroup.h, svc.h needs it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-20 01:48:03 +02:00
Joachim Wiberg 7707c4b8e6 initctl: only show key capture in debug mode
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 15:56:39 +02:00
Joachim Wiberg c85551a42e watchdog: wait for WDT reset only if watchdogd is running
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 14:41:48 +02:00
Joachim Wiberg 06e456384c watchdog: Enable --with-watchdog[=DEV] and improve log messages
This patch changes the configure option to enable the built-in watchdog
from --enable-watchdog to --with-watchdog[=DEV].  This is the convention
for features that take arguments.

Also, improve log messages to aid debugging when finit-watchdogd does
not start properly.  This means flushing logs to syslogd with closelog()

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 13:41:31 +02:00
Joachim Wiberg 38f7d24a80 tty: clean up developer debug messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg dd437bf0a5 Follow-up to 18ab7d3: restore start of built-in watchdogd
This patch restores the start of the built-in/bundled watchdogd.  It is
tracked in the `wdog` variable and handled as an exception at shutdown.

This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external.  External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg 7f76202865 Simplify, drop --enable-fallback-shell from configure script
Recommend using `notty` option in tty stanza instead.  See the updated
docs for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 23:13:19 +02:00
Joachim Wiberg edc6eb1747 initctl: fix too small destination buffer (unlikely)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:24:49 +02:00
Joachim Wiberg be5ec94fdf Fix GCC warnings for unhandled return value
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:24:32 +02:00
Joachim Wiberg 23a13fe1b6 initctl: add hidden command line option -d,--debug
For developer use only.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:23:58 +02:00
Joachim Wiberg ba858743e5 Fix #129: add pre:script and post:script action support
This patch updates the service state machine with two new states: SETUP
and CLEANUP.  If an executable pre:/path/to/script is defined for a
service, it is called every time the task goes to READY state.  If an
executable post:/path/to/script is defined for a service, it is called
when the task goes to HALTED state.

Each of these two scripts default to a three (3) second execution time
before they are SIGKILLed.  This can be adjusted with the `kill:SEC`
option for the service.  There are no execution guarantees, nor are
there any way of detecting if the script was killed before completion or
not -- except for running Finit in debug mode and inspecting the result
printed by system_monitor().

Note: the post:script MUST be idempotent since transitions between READY
      and HALTED can take place any number of times before a task goes
      to its RUNNING state.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 11:33:38 +02:00
Joachim Wiberg 9fd860ef3c initctl: cgroup and status commands should show mem.min numeric
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 10:37:38 +02:00
Joachim Wiberg 46ccdc3820 Fix ordering issue, pid is unset for kill(-pid, SIGKILL) op
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 09:52:48 +02:00
Joachim Wiberg 242fe54afd initctl: standardize on code=signal for signaled/killed cause
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 09:51:53 +02:00
Joachim Wiberg df5d296cd9 initctl: fix too small buffer for extended status
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 09:51:33 +02:00
Joachim Wiberg f641eef8f7 Adjust command length for built-in getty
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 06:08:14 +02:00
Joachim Wiberg f17b5b3cd3 init: move bug report+homepage from -h to -v
Also, detect progname to improve usage text slightly.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 05:52:36 +02:00
Joachim Wiberg d945f4960b initctl: move bug report+homepage from help to version
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 05:51:45 +02:00
Joachim Wiberg 6a5a6ac62f Fix tty command line recomposition for initctl -v
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 05:50:49 +02:00
Joachim Wiberg 7bb649f11a tty: don't block SIGHUP, needed to exit getty gracefully
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:57:37 +02:00
Joachim Wiberg 85ada0ac99 initctl: minor, add linefeed at end of top session
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:47:22 +02:00
Joachim Wiberg 0ac0e5c7d3 plugins: create /var/run/finit/cond/pid directory
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:34:29 +02:00
Joachim Wiberg 7f272768e4 Log error if reconf cannot be written
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:31:56 +02:00
Jacques de Laval 7b74c9900f Revert "Only track built-in watchdogd, not external ones"
This reverts commit 9eb8e8dd99.
2021-04-15 11:34:07 +02:00
Joachim Wiberg 6d380082eb ttinit: check retun value from tcgetattr(), only restore if OK
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 10:11:06 +02:00
Joachim Wiberg eaeddc36c2 Restore tty plugin after tty refactor
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 09:02:28 +02:00
Joachim Wiberg 4f40b65f0c svc_find_by_tty(): fix finder fn, check svc->dev, not name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 08:46:21 +02:00
Joachim Wiberg f958aa504e cond_set_path(): minor, improve debug, 'new' -> 'next'
- Avoid using reserved C++ keyword 'new'
 - Rename new -> next
 - Rename old -> prev
 - Add debug for value being set to cond path

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 08:44:03 +02:00
Joachim Wiberg 3d1b95aa7a tty: export tty_exists() to rest of finit (for plugins)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 08:43:32 +02:00
Joachim Wiberg 4bb67bc06f Restore @console handling and support for external getty
- Drop vhangup(), how did things ever work *with* this in?!
 - setsid() + TIOCSCTTY are best buds, see notty code
 - Allow storing any non-NULL string as tty->dev, expand in service_register()
 - Reorder parse_cmdline_args(), we need to expand @console to current dev
 - Fix tty arg parser, swapparoo for external getty
 - Refactor tty_atcon(), iterated over by service_register()
 - New arg format, need to translate for old run_getty2()

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 23:41:22 +02:00
Joachim Wiberg 0929c93caf Misc. cleanup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 23:41:02 +02:00
Joachim Wiberg c0368d2b16 Refactor fallback shell handling, run as regular service
This patch re-enables the fallback shell handling after the big TTY
refactor.  We do this by allowing the fallback shell to run as a
regular service.

Note: this also adds the "hidden" support for 'notty' option for
      tty configurations stanzas.  This is just to pick up from
      where the kernel left us, reusing stdin + stdout.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 85a212ef93 service_monitor(): cancel any pending SIGKILL timers
As soon as we collect a PID we should cancel any outstanding timer
actions.   Because we may very soon svc_del() it ...

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 12c3cb3dc0 service_stop(): improve debug, show rc of kill(), and it's args.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 16710e7ab5 Fix possible NULL pointer deref.
Some C-lib, like GLIBC, convert NULL to <nil> when printing %p,
which we shouldn't rely on since others just bite the dust.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg b652aaf0cb Rename nologin shell: finit-sh -> finitsh, as fallback shell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg d60baa2b80 initctl: logically dead code, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 15:59:13 +02:00
Joachim Wiberg a50bc331db Fix possible string truncation, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 15:56:44 +02:00
Joachim Wiberg eff4453de9 initctl: add missing comma in signames[], found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 15:54:11 +02:00
Joachim Wiberg c9e1c2f80f initctl: show exit status/signaled like systemctl
- Show if exited/signaled
 - Show status code and the std /NAME
 - Show signal value and the std /NAME

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 11:51:29 +02:00
Joachim Wiberg 93039e40cc initctl: usability improvements to ls/edit family of commands
- List /etc/finit.conf
 - Allow edit of /etc/finit.conf, using finit/finit.conf or NULL
 - Add helpful question to edit /etc/finit.conf if no edit arg.
 - Show available files if delete has no arg, like disable

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 08:56:26 +02:00
Joachim Wiberg 015a52a20d sample.conf: update with cgroup help and examples
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 19:52:12 +02:00
Joachim Wiberg 3c4eca60b7 initctl: fix restart of run/tasks, stuck in DONE state
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 19:51:03 +02:00