Commit Graph
1478 Commits
Author SHA1 Message Date
Joachim Wiberg 0a8f3a6250 Fix #425: flush .conf file events before reload and runlevel change
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-13 07:06:13 +01:00
Joachim Wiberg 70c4e7d774 iwatch: ensure adding a new watcher is idempotent
Some subsystems call iwatch_add() without first calling iwatch_del() on
the same path.  E.g., cgroup_config().

Issue #417 but unclear atm. if this is the root cause.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-13 05:53:24 +01:00
Joachim Wiberg 4b06e1a49f Silence overly verbose debug messages in cond_set/clear/update
These functions call other functions that log more detailed information.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:35 +01:00
Joachim Wiberg 6b9aa21509 Minor cleanup, code (style) and comments
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:35 +01:00
Joachim Wiberg 990307fbc9 Fix kill() on timeout of pre:/post:/ready:scripts
A long running pre/post/ready script must be killed properly, not by
targeting its process group.  Process group cleanup is handled by the
service_monitor() when reaping the script's PID.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:34 +01:00
Joachim Wiberg 9d8a9b7fba Check for pre:- and post:scripts in $PATH
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:34 +01:00
Joachim Wiberg 23d034f521 Prevent main process from starting if pre: script fails
Check exit status of `pre:` scripts, on failure drive service/sysv to
`crashed` state.  The exit code of `post:` scripts remain ignored for
now.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 09:39:40 +01:00
Joachim Wiberg 8560103a24 Add individual timeout support for pre/post/ready scripts
Syntax:
    [pre|post|ready]:[0-3600,]/path/to/script

Description:
    Before this patch all pre/post/ready scripts used the global kill
    delay as timeout.  After this patch it is possible to disable the
    timeout as well as set a timeout >60, which is max kill delay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-10 10:43:37 +01:00
Joachim Wiberg 7a75e34808 Fix initctl touch of template services
Follow-up to 465bc17, which addressed unintended restart of siblings.
This patch fixes a problem where template instantiated services are not
properly reloaded/restarted when marked as "dirty" with `initctl touch`.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-10 10:43:37 +01:00
Aaron Andersen 048302f06a add systemd-nspawn to the list of container types 2025-02-02 08:58:36 -05:00
az 3cfe0a33b8 fstab with UUID/LABEL: nofail handling for fsck
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.

this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.

for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
2024-12-20 09:09:24 +10:00
Joachim Wiberg 465bc17ca4 Fix unintended restart of template siblings
Consider the case where container@.conf is an available template.  When
creating a container@foo.conf it will share the same base .conf as an
existing container@bar.conf, but we do not expect to restart bar just
because foo is instantiated.

Up until this change, all template siblings were considered "dirty" if a
new one was created or updated.  Skipping realpath() for all files that
have a '@' works around the problem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-11-28 11:13:44 +01:00
Joachim Wiberg 119e66a7e9 Reset color attributes and clear screen when starting up
Some boot loaders, like GRUB, leave background color artifacts from
their boot menu.  This patch resets the foreground and background
color attributes, and then clears the screen, without clearing the
scrollback buffer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-28 10:58:04 +01:00
Joachim Wiberg 46ffa81f5c Only mark rdeps dirty if main service is nohup
This patch changes a behavior that's been default since Finit 4.0,
introduced in 4d05bf9 with 4.0-rc2.

If service B depends on A and A needs to be reloaded, then B may be
affected.  If A is declared as NOHUP <!>, then A will be stopped and
restarted, during which time the condition it provides is removed,
and B will also be stopped.

However, and as of this patch, if A is declared supporting HUP, then the
condition A provides will only go into flux, during which time B will be
SIGSTOPed instead of needing to be reloaded.

Fix #415

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-17 14:33:30 +02:00
Joachim Wiberg 56e558c960 initctl: add support for showing template@foo.conf
Fixes #411

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-13 19:40:21 +02:00
Joachim Wiberg dfaf351da1 Fix #414: zebra immediately restarts if manually stopped
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-13 19:40:21 +02:00
Ming Liu 3e3e9aadf5 tmpfiles.c: prevent nftw follow symbolic links
When dealing with "L+" and "R", the function call 'nftw' should not
follow symbolic links, otherwise, it would also delete the targets
which is wrong.

For instance, if there is already a symbolic link:
```
/path/to/the/link -> /path/to/some/folder
```

if we set the following in a tmpfile conf:

```
L+ /path/to/the/link -    -    -     - /path/to/the/target
```

the result would be /path/to/some/folder also get deleted, which it
should not.

it could be even worse, when the symbolic link already is pointing to:
/path/to/the/target, the whole /path/to/the/target would be deleted on
next system boot.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2024-08-24 13:29:10 +02:00
Mathias Thore a0685219cf Avoid remounting already mounted /run and /tmp directories
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
2024-08-05 14:33:43 +02:00
Joachim Wiberg 13b107b7b1 Fix #407: extend initctl poll timeout
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-22 09:23:14 +02:00
Joachim Wiberg ab62b5282b runparts: add -b (batch) mode for syslog output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-19 09:20:03 +02:00
Ming 9a0dea6aef configure.ac: make cgroup2 configurable (#406) 2024-05-11 14:06:01 +02:00
Joachim Wiberg 8251f1a422 Fix derefernce before NULL check
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:40:05 +02:00
Joachim Wiberg 612f5a9385 Allow building Finit --without-rc-local support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:25:53 +02:00
Joachim Wiberg 4a2381eb6f Fix #404: possible undefined behavior --without-fstab
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:22:57 +02:00
Joachim Wiberg 0cae7d44dd Follow-up to 6a89e60, len may be used unitialized
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-28 14:21:22 +02:00
Joachim Wiberg 340cae4afd Change default behavior, allow kernel logs to console
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console.  For embedded
systems, which is the primary target for Finit, this is what you want
to see.

Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console.  A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-24 12:46:59 +02:00
Joachim Wiberg 6a89e60fc8 Fix #405: parsing >1 active consoles in tty @console setups
Systems that have the following tty setup and multiple consoles listed
in /sys/class/tty/console/active misbehave:

    tty [12345789] @console 0 xterm noclear passenv

Only the first listed console is started properly, the remaining ones
were registered using the wrong :ID and no arguments to getty.

This patch fixes the parsing and re-use of the base paramenters for
all consoles listed in the active file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-24 11:33:35 +02:00
Joachim Wiberg deada0fa89 initctl: refactor to use new suffix() function
Reduce code duplication and use suffix() function to check and append a
suffix to a path.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 08:10:35 +02:00
Joachim Wiberg 7b501f255b initctl: touch does not support template services
Fixes #403

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 07:47:23 +02:00
Joachim Wiberg 052136cb99 initctl: touch does not respect -n switch
Fixes #402

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-02 16:07:01 +02:00
Joachim Wiberg c32b5a749a Refactor popen()/pclose() logic in ifupdown calls
Currently no code checks the return code of ifupdown at runlevel
changes, but for future reference this code has been refactored
to match the changes made in cbdb949 to fix issue #400.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-30 12:38:50 +01:00
Joachim Wiberg 7701718d7b Fix #400: resolve exit code from pclose() by calling WEXITSTATUS()
This problem affects all calls to run_interactive() that check the
return value of the command.  Causing HOOK_MOUNT_ERROR to *not* run
on mount failure, and sulogin() to *not* be started on fsck error.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-30 12:38:50 +01:00
Joachim Wiberg b49f55ab3d tmpfiles.d: ignore x/X command, no cleanup at runtime with Finit
Silence log warnings for command x/X (ignore clean for path), because
Finit does not do tmpfiles cleaning at runtime.

x /tmp/podman-run-*
x /tmp/containers-user-*
x /tmp/run-*/libpod
D! /var/lib/containers/storage/tmp 0700 root root
D! /run/podman 0700 root root
D! /var/lib/cni/networks

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 12:06:39 +01:00
Joachim Wiberg 146bf55122 Fix #398: display unsupported initctl command (number) in log
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-11 16:01:30 +01:00
Joachim Wiberg c1ed373398 Fix #397: drop ttinit() for PID 1
After reports from the field, see issue #397, of lockups at reboot,
we've decided to drop this code from PID 1.  It was added before the 4.x
series, when the current progress output was introduced.  For the older
style progress it served a purpose since the placement of [OK]/[FAIL]
was on the right hand side.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-11 15:46:38 +01:00
Joachim Wiberg c221823654 shutdown: use cond_clear_noupdate() to prevent nested service_stop()
When the system shuts down, or user changes runlevels, we don't have to
call cond_clear_update(), because this can lead to nested service_stop()
calls, which in turn lead to out of sync progress updates:

[ .. ] Stopping Foo
[ OK ] Stopping Bar
[ OK ]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-03 17:31:37 +01:00
Joachim Wiberg cd060e8af3 getty: trigger /etc/issue compat mode for Alpine Linux
The /etc/issue file on Alpine Linux says "Kernel \r on an \m (\l)", so
\r needs to return the uts release rather than os-release VERSION.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 21:18:58 +01:00
Joachim Wiberg 59152b557c keventd: remove runlevels 0 and 6
The responsibility of the kernel event daemon is to relay kernel events
to Finit.  At shutdown and reboot it is too late for more events and the
daemon should just shut down with other services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 15:18:52 +01:00
Joachim Wiberg d5d9cd5645 tmpfiles: fix error message and ignore unremovable dirs (EBUSY)
Fix copy-paste of error message from cond-w.c

A read-only root filesystem may have /var/lock, while we want to remove
it and add a symlink to ../run/lock.  Ignore errors from this since we
cannot do anything about it.  It is up to the user to fix their skeleton
or use an overlay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 13:56:31 +01:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Joachim Wiberg 337ee003bb Mount /dev/mqueue if missing and set sticky bit to /dev/shm
Inspired by Alpine Linux, add /dev/mqueue if missing.  We should check
the /proc/filesystems first, but this is quicker.

The sticky bit ensures only the owner of files in /dev/shm can delete or
rename files.  This is also what Alpine Linux use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 23:50:30 +01:00
Joachim Wiberg 791df0c986 Refactor, ensure basenm() returns a const char pointer of its arg.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 23:46:17 +01:00
Joachim Wiberg d66455496a Fix #392: ensure 'ready' condition is cleared on pidfile removal
A service with notify:pid is 'ready' when the pidfile has been created,
the converse also holds true -- when a pidfile is removed the service is
no longer 'ready'.

The state transition for the service has probably already been done, in
svc_set_state(), clearing all <service/foo/*> conditions when the PID
was collected.  The pidfile event may arrive later, so for completeness
we make sure the 'ready' condition is not recreated at least.

Problem introduced in 912a281 with the original supoport for service
readiness notification.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 12:25:41 +01:00
Joachim Wiberg 6cc587068b Log service identifier, not process name, in debug message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 11:59:46 +01:00
Stargirl-chan cbea83b369 Simplified function comment and follow coding style 2023-12-29 13:37:08 +01:00
Stargirl-chan 42cd8d284b Implement custom basename function (basenm)
There exist two possible basename functions, a xpg compliant one in libgen.h
and a GLIBC exclusive one declared in string.h, that was previously also declared by musl libc.
Both implementations are expecting different parameter types (`const char *` for GLIBC and `char *` for xpg)

With the removal of the basename function from string.h in musl libc, we could only rely on the xpg implementation.

Unfortunately, the xpg implementation of basename does modify the contents of whatever you put in it,
even though that there really is no need for it.

This is an issue in some cases, where we might want to get the basename of a read-only variable, e.g. a `const char *`,
as trying to modify something read-only is undefined behavior.

So in order to keep things consistent for us, we implement our own version of basename called `basenm`,
that does not modify the passed argument.
2023-12-29 10:44:40 +01:00
Stargirl-chan 72ebc92622 Fix compilation on musl by using posix basename 2023-12-28 03:41:00 +01:00
Ryan Rorison efc0592961 Fix log child exiting with debug disabled 2023-12-18 21:00:45 -08:00
Joachim Wiberg ed88469276 Actually silence the log message, missing hunk for previous change
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-10 17:32:19 +01:00
Joachim Wiberg cbf96a1de0 Silence 'not available' log messages for nowarn run/task/service
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-10 16:42:29 +01:00