Aaron Andersen points out in the #492 discussion that the *Directory
settings carry more contract than create-and-chown: per-directory
modes, specific ownership rules, and cleanup toggles. Without them
config-dir was chowned to the service user, which systemd never does,
an existing directory with drifted ownership was left wrong, and the
runtime directory could not survive a restart.
Now matching systemd.exec(5), and where the man page is vague, the
code in setup_exec_directory():
- each directory takes a matching -mode key, octal with the leading
zero, default 0755. The mode of the named directory is locked
down again on every start, also when it already exists
- config-dir is created but never chowned
- the contents of an existing directory are left alone as long as
the owner is right; on drift everything under it is chowned back
- runtime-dir-preserve = no | restart | yes maps
RuntimeDirectoryPreserve=. A service still qualified to run when
the runtime directory would be removed is restarting, not
stopping, which is what svc_enabled() answers
The dir mechanics move to mksubsysd(), taking resolved ids, with
mksubsys() reduced to a name-resolving wrapper for the dbus plugin.
The child resolves uid/gid once for both directory setup and
privilege drop.
The symlink form, RuntimeDirectory=foo:bar, is not adopted.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
rmrf() is needed outside tmpfiles.c. The move also deduplicates the
nftw callback: the contents-only removal used by tmpfiles 'D' entries
is now rmcontents(), sharing the callback with rmrf().
mksubsys() did nothing at all when the user could not be resolved, no
directory and no message, and callers had no way to tell. Now the
directory is always created, ownership is best effort, and an unknown
user is warned about.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Three private ones had grown: fnread() in util.c, flen() behind
pid_cmdline()/pid_cgroup() in cgutil.c, and conf_read_template() in
conf.c. Two of them were also wrong in ways the others were not.
fnread() formatted the path into a char[256] and stat()ed it before
opening, so a longer path was silently truncated and then read from
whichever file the truncation happened to name, and the size could
change between the look and the read. flen() existed because neither
of those approaches works on procfs at all, where stat() reports zero
and the only way to learn the size is to read to EOF.
Add fslurp() to util.[ch], which every tool already links. It opens
first and sizes the fd it holds, treats st_size as a hint, and reads
until EOF, so procfs and regular files take the same path. Paths are
formatted by libite's vfopenf(), which allocates to fit. Callers that
need the byte count, /proc/PID/cmdline embeds NUL, ask for it.
fnread() keeps its signature and becomes a bounded copy out of the
result, so its one caller is unaffected.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The file helpers.c should strictly only be used for misc. helper
functions to the main Finit daemon. The functions moved in this
commit are generic enough to be used by any deamon or programs,
and for that we have util.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
There exist two possible basename functions, a xpg compliant one in libgen.h
and a GLIBC exclusive one declared in string.h, that was previously also declared by musl libc.
Both implementations are expecting different parameter types (`const char *` for GLIBC and `char *` for xpg)
With the removal of the basename function from string.h in musl libc, we could only rely on the xpg implementation.
Unfortunately, the xpg implementation of basename does modify the contents of whatever you put in it,
even though that there really is no need for it.
This is an issue in some cases, where we might want to get the basename of a read-only variable, e.g. a `const char *`,
as trying to modify something read-only is undefined behavior.
So in order to keep things consistent for us, we implement our own version of basename called `basenm`,
that does not modify the passed argument.
Unfortunately we cannot use realpath(3) here since the the PID files
usually do not yet exist at this point.
Add and modify my ugly de_dotdot() from Merecat httpd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of unconditionally waiting 2 seconds for processes to die,
check continuously for remaining processes, and break the loop when
none remain.
Turn PID 1 to a RT process with highest priority 99 during shutdown,
this ensures it would not be preempted by other RT processes.
Signed-off-by: Robert Andersson <robert.m.andersson@atlascopco.com>
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
initctl cannot link with helpers.c, so let's relocate these helper
functions to util.c instead. Need them to probe for cgroup support.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from
lite/*.h -> libite/*.h
This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config. This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch moves the built-in getty out of Finit into /libexec/finit/,
reducing the size of the Finit binary and simplifying the code.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Show if exited/signaled
- Show status code and the std /NAME
- Show signal value and the std /NAME
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
More often than not, the file to write to in sysfs changes rather than
the value. This patch changes echo() into a fnwrite(), flipping what
is vsnprintf()'ed, and adds a stupid str() function that converts any
value (float/int/double/uint64_t) to a static string buffer.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Refactor screen_init()
- use native impl. of TTY probing from pimd project
- check if TIOCWINSZ works
- check if we're running in watch(1), for initctl
- check if ANSI goto(999,999) escape seq. works (invasive)
- fallback to 80x24
- Drop screen_exit()
- Rename screen_init() to get_width(), for now, matching pimd
- Relocate call in main() to banner(), first fn to write to TTY
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>