This commit introduces a bare-bones replacement for libsystemd:
- Build .so file and add --with-libsystemd to configure
- Add capabilities support to test/src/serv.c
- Update tests to account for a Finit built w/o libsystemd support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In 42ef3d3c, for v4.4-rc1, support for setting a custom RTC restore date
was introduced. Unfortunately the configure script was wrong and caused
config.h to contain
#define RTC_TIMESTAMP_CUSTOM "$rtc_date"
instead of
#define RTC_TIMESTAMP_CUSTOM "2023-04-10 14:35:42"
Furthermore, the error handling for strptime() was wrong, so the restore
date was always reverted to the default.
This patch fixes both issues and extends the DATE of --with-rtc-date to
also include seconds.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch introduces a new configure option --with-rtc-file=FILE. When
enabled the RTC plugin detects missing RTC device and falls back to save
and restore system time from a file instead. When --with-rtc-file is
used without an argument the default file is /var/lib/misc/rtc, but the
feature itself is disabled by default.
The usefulness of this feature may not be obvious at first, but some
systems are equipped with an RTC that resets to a random date at power
on. This can be really bad in the case the date is far in the future,
because an NTP sync would then cause time skips backwards, which shows
up in logs and causes a whole lot of pain in alarm systems.
The solution is to disable the RTC driver or device tree node, and when
Finit starts up, the RTC plugin detects a the device node and instead
restores time from the last save game. Meaning time will always only
move forwards.
NOTE: when Finit is built --with-rtc-file we always save to disk, but
only restore from the "save game" if restoring from RTC fails.
If the system has no RTC we always restore from disk.
As an added bonus, this change also makes sure to periodically
sync also the RTC with the system clock. Useful for systems
that do not run an NTP client.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console. For embedded
systems, which is the primary target for Finit, this is what you want
to see.
Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console. A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This fixes an annying buglet that creeped in just before the v4.5 release
causing none of the internal services to be registered properly:
conf_save_service():Failed creating ${localstatedir}/run/finit/system/dbus.conf: No such file or directory
plugin_run_hook():Calling modules-load hook n:o 5 (arg: 0x55c4c8133621) ...
load():Scanning /etc/modules-load.d for config files ...
cond_set_oneshot():hook/svc/plugin
cond_set_oneshot_noupdate():hook/svc/plugin => /run/finit/cond/hook/svc/plugin
cond_update():hook/svc/plugin
parse_conf():*** Parsing /etc/finit.conf
conf_save_service():Failed creating ${localstatedir}/run/finit/system/runparts.conf: No such file or directory
The fix, like most, is simple when you find it. We must expand $runstatedir
before creating the #define in config.h
For convenience, here's the patch for the generated configure script:
&<---------------------------[cut here]---------------------------
--- a/configure 2023-11-05 23:39:51.907334321 +0100
+++ b/configure 2023-11-05 23:39:58.339299795 +0100
@@ -15352,7 +15352,15 @@
printf "%s\n" "#define FINIT_EXECPATH_ \"$pkglibexecdir\"" >>confdefs.h
-printf "%s\n" "#define FINIT_RUNPATH_ \"$runstatedir/finit/system\"" >>confdefs.h
+ finit_runpath="$runstatedir/finit/system"
+ finit_runpath=`(
+ test "x$prefix" = xNONE && prefix="$ac_default_prefix"
+ test "x$exec_prefix" = xNONE && exec_prefix="${prefix}"
+ eval echo \""$finit_runpath"\"
+ )`
+
+
+printf "%s\n" "#define FINIT_RUNPATH_ \"$finit_runpath\"" >>confdefs.h
&<---------------------------[cut here]---------------------------
Ensure you include the three empty lines for context at the end!
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We cannot rely on the auto-detection of Bash completion dir during 'make
distcheck' because autotools does not use DESTDIR, only --prefix for the
install check, and pkg-config returns a system path.
Also, show detected path in configure summary for debug.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The updated 10-hotplug.conf now ensures modules are loaded, so we no
longer need the modprobe.so plugin to be enabled by default.
Also, update the hotplug "plugin" description, it is kept entirely
for backwards compatibility reasons after the plugin was converted
to 10-hotplug.conf.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit replaces the `mdev -s` call to populate the device tree with
the "new" `mdev -df` daemon mode, introduced in BusyBox 1.31.0, 2019.
In daemon mode mdev listens to kernel uevents, replacing the hotplug use
of mdev. After creating the netlink socket, 'mdev -df' performs the same
initial scan as 'mdev -s' did.
To perform device (re)discovery, module loading and setup, including any
firmware loading, a coldplug operation is typically required. This is
done by the new /libexec/finit/coldplug script, by Alexander Zangerl.
Unlike 'mdevadm settle', mdev does not offer any mechanism to detect when
the discovery operation is done: on slower systems the triggering side,
the coldplug script, often completes quite a bit earlier than mdev's
uevent processing. I.e., depending on <run/coldplug/success> is not an
indicator of all devices having been (re)discovered and fully set up.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This adds a new function conf_save_service() replacing service_register() for
plugins and bundled services like watchdogd, keventd, runparts, etc.
The benefits to this change are several:
- Plugin/Bundled services no longer risk starting before udev or other
critical services/task have started
- Definitions can be overridden by an administrator (see docs)
- Increases visibility (user: where are all these services coming from?)
Previously the origin (file the service was loaded from) was NULL.
- Adds another level of extensibility to Finit
The most notable change is that dbus is no longer started before udevd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
No more changes are expected after -rc3. Will be used for testing in
Infix and br2-ext-finit before the final v4.5 GA.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.
it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slowly migrating away from hard-coded services in plugins. This way
it's possible for the user to both inspect and override as needed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>