Commit Graph
91 Commits
Author SHA1 Message Date
Joachim Wiberg b53c7e6879 dbus: mirror legacy runlevel edge cases in Manager1.SetRunlevel
The bus method called sm_runlevel() unconditionally.  In runlevel 0
and 6 that aborts an in-flight shutdown, which INIT_CMD_RUNLVL
refuses with a warning, and during bootstrap it switches immediately
where the legacy path defers via cfglevel to the end of runlevel S.

Port both.  A bad runlevel argument still returns InvalidArgs, where
the legacy protocol acks silently: a typed interface rejects garbage.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 22:03:37 +02:00
Joachim Wiberg 0a269f3298 libink: a brokerless D-Bus implementation for Finit
Finit had no way to answer the question every service manager gets
asked: what is running, and change it.  D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.

So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET.  It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top.  Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.

Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:14 +02:00
Joachim Wiberg 22fbb408eb conf: route service conditions through one owner primitive
A service's condition was computed with mkcond() at each of the six
sites that assert or clear it, and svc_find_by_cond() reimplemented
the reverse lookup a seventh time.  maybe_clear_cond() had its own
scan for another service supplying the same condition.

svc_cond_owner() answers who owns a condition, svc_cond_nth() walks
the conditions a service owns, and svc_cond_set()/svc_cond_clear()
apply to all of them.  svc_find_by_cond() becomes a wrapper, and
maybe_clear_cond() keeps its rule per condition rather than for the
one it used to compute.

The provides[] storage lands here unused, since svc_cond_nth() reads
num_provides.  Nothing sets it yet, so a service still owns exactly
its own pid/<ident> and there is no functional change.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-05 17:57:57 +02:00
Joachim Wiberg d77f0127b4 Don't disrupt dependents on reload of SIGHUP-capable service
This fixes a real bug where `initctl reload syslogd` unconditionally
clears syslogd's pid condition, causing all dependent services (dbus,
dnsmasq, etc.) to be stopped even though syslogd handles SIGHUP
gracefully and its PID/pidfile persist.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-22 20:36:35 +01:00
Joachim Wiberg f0914f6d32 Fix 'initctl reload NAME' not updating conditions for dependents
When reloading a specific service with 'initctl reload foo', the
pid/foo and service/foo/ready conditions were never cleared, so
dependent services were not notified of the reload.

Clear the service's pid condition and, for pid/none notify types,
the ready condition before reloading.  The conditions are then
reasserted by the pidfile inotify handler when the service touches
its PID file after processing SIGHUP.

For s6/systemd services the ready condition is left intact since
their readiness notification may not re-trigger on SIGHUP.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-10 15:59:49 +01:00
Aaron Andersen 8e7d1b7bb5 Refactor: drop do_ prefix from iterate_proc() and switch_root()
The do_ prefix is conventionally reserved for local helper functions.
Move switch_root() declaration to private.h alongside iterate_proc()
and remove the now-empty initramfs.h header.
2026-01-02 18:13:00 -05:00
Aaron Andersen 373738f3d1 Implement switch_root functionality allowing Finit to serve as the init
in an initramfs, then transition to the real root filesystem.  Useful
for systems requiring early boot tasks like LUKS unlock, LVM activation,
or network boot before mounting the real root.

Adds INIT_CMD_SWITCH_ROOT API command, `initctl switch-root` subcommand,
and HOOK_SWITCH_ROOT plugin hook point.  The implementation gracefully
stops services, moves virtual filesystems (/dev, /proc, /sys, /run) to
the new root, deletes initramfs contents to free memory, then execs the
new init as PID 1.

See GitHub Discussion #292 for background.
2026-01-01 19:10:24 -05:00
Joachim Wiberg 21f40fb95e Allow more initctl commands in runlevels S/0/6
Relax the constraints introduced in a39ee0b, for issue #342, a bit on
when start/stop/restart/reload service can be called.  Also, allow
'initctl reload', but ignore it when the system is in runlevels S/0/6.

This makes it possible to start manual:yes type services at botostrap,
for example, which has been a common feature request.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:12 +01:00
Joachim Wiberg 8377f0e736 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 14:34:16 +02:00
Joachim Wiberg 1b9e69414e Refactor state machine control functions
This refactor should have been done years ago when we first introduced
the big state machine.  The old functions service_runvel() and the oddly
named service_reload_dynamic() are actually state machine control fns,
so let relocate them.

Also in this commit, remove the global variable 'sm' and rename a few of
the critical functions to better names.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:13:56 +02:00
Joachim Wiberg 76f8a18816 Fix #440: refactor systemd and s6 readiness notifcation
This patch fixes issue #440 which details how systemd readiness
notification has been broken since its inception in Finit.

In addition to now providing a proper abstract socket, the refactor
also drops the reliance on the Finit client API to fetch a socket.
Now an s6 descriptor is the write end of a pipe() and the systemd
socket is instead created before forking off the service.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:36:58 +02:00
Joachim Wiberg 91f7a75bee api: ensure socket is non-blocking
Also, remember to refactor the client socket handling to prevent
blocking PID 1.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:36:57 +02:00
Joachim Wiberg ffd00f646c Declare unused parameters
When building with global CFLAGS=-Wunused-parameter the output from the
build looks terrible.  This commit explicitly declares unused variables
to prevent triggering -Wunused-parameter

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 14:29:52 +02:00
Joachim Wiberg 75fa868a4b Fix various typos found by codepsell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 16:46:28 +01:00
Joachim Wiberg abac31682d Handle UEV_ERROR properly in all libuev callbacks
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 02:34:31 +01:00
Joachim Wiberg 146bf55122 Fix #398: display unsupported initctl command (number) in log
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-11 16:01:30 +01:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Joachim Wiberg 2e73563eea Fix #369: allow runlevel change using initctl during bootstrap
This change opens up the runlevel change API from bootstrap.  The twist
is that the change is only queued, i.e., the call `initctl runlevel 9`
during bootstrap only changes the configured runlevel to go to after
bootstrap has completed.

Effectively, this change allows overriding the `runlevel` directive in
/etc/finit.conf without having to change the file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 15:11:33 +02:00
Joachim Wiberg 51befb492c Allow conflicting services to start when conflict is resolved
These changes add a new svc_block_t type: SVC_BLOCK_CONFLICT so a user
can more clearly see why a run/task/service has not been started by
Finit.  The reason for the block is by default logged, which can be
escaped by using the `nowarn` flag.

Also, when the conflict is resolved, allow the service to start.

With these changes, the system/hotplug.conf should work better and
cause less questions about "strange" log messages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-15 16:23:40 +02:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg e00fda5dc3 Fix #352: separate runlevel S from runlevel 0
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff.  If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.

This change is quite invasive.  It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-22 15:11:27 +02:00
Joachim Wiberg 3bb2eb2a8d Fix potential socket leak at bootstrap and shutdown
This is a follow-up to a39ee0b, found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-04 11:44:48 +01:00
Joachim Wiberg e9515971ea Refactor, move registration of static services to conf_init()
All services registered in the system rely on conf_init() having been
set up properly, e.g., global_rlimit.  Having conf_init() be responsible
also for registering static services is only logical, and also helps us
clean up main() a bit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg a39ee0b44d Fix #342: prevent certain commands at bootstrap and shutdown
Over the years there have been multiple cases of invalid and/or unsafe
uses of signals and initctl commands at bootstrap and shutdown.  These
cases cannot be safely supported.  This commit locks down finit a bit
to avoid the most common cases.

If you run into this, please open a new discussion at GitHub and we'll
talk about it.  Maybe I've been overzealous or you have another use-case
that warrants opening up some or parts of the API.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-10 17:18:50 +01:00
Joachim Wiberg 1ef9a9f128 Cancel pending restart timer on initctl stop/start/restart/reload
When a service crashes Finit launches a restart timer that periodically
will try restart the service.  If a user calls `initctl stop foo` finit
must cancel this timer callback, otherwise we may end up with a weird
state where Finit thinkgs the service is running, but pid: 0, i.e., not
started.

Note: this fix has been expanded upon from the proof of concept
      submitted by Jack Newman.

Bug #313

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-11 16:34:50 +01:00
Joachim Wiberg 912a281ee2 Fix #299: add support for service readiness notification
This patch adds service readiness notification to support daemons
employing systemd and s6 notification.  Complementing the native
Finit readiness support using PID files that exist already.

The two have slightly different ways of implementing readiness:

 - https://www.freedesktop.org/software/systemd/man/sd_notify.html
 - https://skarnet.org/software/s6/notifywhenup.html

Finit now provides both a NOTIFY_SOCKET environemnt variable, for
systemd, and a way to start s6 daemons with a descriptor argument.

For details on the syntax, see the `service` documentation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 20:06:26 +02:00
Joachim Wiberg d22dea74e3 Finalize refactor to new log macros, following-up to 37e3be9
This possible also mitigates the issue tracked in #307.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-09 12:52:40 +02:00
Joachim Wiberg e589c5b269 Refactor, create svc_find_by_cond() from api.c callback
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-18 14:00:02 +02:00
Joachim Wiberg a61a8015d7 initctl: new command, list installed plugins
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-15 11:00:39 +02:00
Joachim Wiberg 6c874895dc Fix #295: add reboot/shutdown/poweroff timeout -t SEC to initctl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-12 15:06:54 +02:00
Joachim Wiberg f50b5a4ac6 Fix #285: initctl restart should start crashed service
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-12 22:24:27 +02:00
Joachim Wiberg ccb84ced2e Fix #280: allow calling initctl restart foo from within foo
Move the stop+start from initctl to the state machine by allowing
stopped tasks to restart once it has been collected.  This should
prevent finit from blocking, allowing it to handle other requests
while waiting for the service's PID to be collected.

Effectively, this will allow a service to call initctl to restart
itself, as reported in issue #280.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-30 06:54:27 +02:00
Joachim Wiberg d3c6351ed8 Fix nasty service matcher bug
In some conditions, typically when the same command is used for multiple
services, e.g. the modules-load plugin, the svc_find() function returned
an existing "similar" entry instead of NULL, causing loss of config.

When creating, and searching for, a run/task/service we must follow the
new name:id paradigm to the letter.  Always create based on name:id and
always search for matching name:id.  The name may be derived from the
command, but they cannot be used interchangably.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-06 07:57:08 +02:00
Joachim Wiberg 181d9556a1 Drop config.h include from helpers.h, exported header file
Drop the config.h include from helpers.h after a report from a colleague
trying to build an external plugin from the latest GIT sources.

Instead, make sure config.h is included, and properly commented, in all
.c files that have configure #ifdefs and other deps.  Also, move more
ot the includes from helpers.h to their respective .c file instead to
reduce the amount of headers an external plugin pulls in.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-05 14:48:30 +02:00
Joachim Wiberg 108bbf56dd Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:35:49 +02:00
Joachim Wiberg 54dd726d16 Follow-up to bd9bb92, missing API change
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-17 00:01:10 +02:00
Joachim Wiberg bd9bb92ca0 Replace reboot(RB_SW_SUSPEND) w/ internal /sys/power/state API
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-16 23:59:32 +02:00
Joachim Wiberg 49bd63994c Minor refactor
- Check all pointers
  - Declaratons always at top of func/scope
  - Use established variable nomenclature
  - Skip useless if() stmt

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-25 07:15:03 +01:00
Joachim Wiberg 85b29d9407 Minor whitespace and comment cleanup
- Comments preferably at beginning of func/sect
  - Reorder code slightly, add whitespace for readability
  - Drop useless comment

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-25 07:15:03 +01:00
Jörgen Sigvardsson 4121113688 Added implementation for the new command INIT_CMD_SIGNAL.
The implementation looks up the named service by using
`svc_parse_jobstr`. The callbacks for `svc_parse_jobstr` has been
augmented to accept a user data parameter. For this use case,
a carrier for the actual signal was needed. The address of the
signal parameter is taken and passed on as a `void *`. The
callback then simply deferences it as an int - the signal number.
2022-02-15 12:29:40 +01:00
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
Joachim Wiberg 980152fd53 Add support for non-root users to use initctl, e.g. group wheel
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-11-30 11:44:22 +01:00
Joachim Wiberg 522a06f864 Merge pull request #181 from yangfl/typo
Fix typo
2021-06-25 07:43:08 +02:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg 2a71f35005 Reduce log level of watchdog handover, this is not an error condition
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg dd437bf0a5 Follow-up to 18ab7d3: restore start of built-in watchdogd
This patch restores the start of the built-in/bundled watchdogd.  It is
tracked in the `wdog` variable and handled as an exception at shutdown.

This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external.  External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Jacques de Laval 7b74c9900f Revert "Only track built-in watchdogd, not external ones"
This reverts commit 9eb8e8dd99.
2021-04-15 11:34:07 +02:00
Joachim Wiberg 3c4eca60b7 initctl: fix restart of run/tasks, stuck in DONE state
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 19:51:03 +02:00
Joachim Wiberg c0716d7f63 Minor optimization, drop expensive memset() ops
No need to zero out whole buffer for strlcat(), or other string check
ops.  Also drop a few completely useless memset() calls.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:41 +02:00
Joachim Wiberg 90f7ff1c23 initctl: new command 'reload NAME:ID' and new semantics for restart
This patch corrects a logical glitch, or design flaw, in initctl.  The
'restart FOO' command did not stop+start FOO only send SIGHUP (provided
FOO supports SIGHUP).  Hence, a new command 'reload FOO' is introduced,
which does exactly that, and 'restart FOO' now stops and restarts FOO.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-04 12:35:35 +02:00