This patch adds support for the runtime `HOOK_SVC_LOST` and the (very
noisy) *example* plugin `lost.so`.
Customer request.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
To distinguish between variables and functions in comments Finit use ()
at the end of function names.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
When a service's condition transitions to `flux`, put it in the
waiting state, even if it does not support SIGHUP. That way, if the
condition returns to `on` we can simply SIGCONT it. If it goes to
`off` it will still be stop/started as before.
When reloading dynamic services, inetd services deleted marker was not
being cleaned. This caused finit to stop and start all inetd services
at every other reload.
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.
As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
During documentation of the state machine, some theoretical problems
where discovered that could have lead finit to spawn a new instance of
a daemon before the previous one had been collected.
Now a service will always go through the STOPPING state when leaving
RUNNING. This ensures that the PID has been collected before any calls
to service_start.
...documenting your work is, apparently, not a bad idea. :)
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
Parser would erroneously interpret an event specification containing
slashes as an inet service/proto specification.
E.g. "<net/gw>" was interpreted as port "<net" using protocol "gw>".
When no services were stopped we must ensure to start/SIGHUP any new or
SIGHUP:able services as the last pass of the `initctl reload` cycle.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes a hang when performing a system reconfiguration using
`initctl reload`, `SIGHUP` or running `(f)init q`, which caused Finit
to wait for SIGHUP:able services to stop.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Leverage new svc_t states in initctl status/show output. Also, ensure
different svc_t types have correct start state.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
new postponed stop handling tried to reload already stopped and removed
services. We should of course skip already stopped services and halt
those that have been removed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch reverts the change in behavior introduced in Finit v2.2,
commit 924bf041, where `initctl restart JOB` changed from 'stop + start'
to `SIGHUP` for services that support `SIGHUP`.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When `service_stop_done()` is called with a `NULL` argument and no
dynamic services have been stopped, this regression is triggered.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for declaring *why* a service is being stopped
or reloaded. This is later used when all stopped services have been
collected by the `service_monitor()` to issue start or postponed SIGHUP.
As an added benefit we can now also see why a service is not running.
If it has been paused by a user, halted when moving to another runlevel,
waiting for a condition (event), or similar.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes a race condition when doing an ordered RELOAD and STOP
event sequence. For services that shall be stopped it is imperative
that we wait for them to be colleced by the `service_monitor()`, so that
we know they have really been stopped, before calling HOOK_SVC_RECONF.
The latter is a promise to external services that all services have been
indeed stopped.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
service.c:
Don't declare find_inetd_svc() if inetd is disabled.
api.c:
Disable inetd API
initctl.c:
Disable presentation of inetd services
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
After forking off a new child, all signals that are blocked by finit
should be unblocked before exec-ing the final binary. Also, finit now
blocks SIGHUP, so add it to the set of signals that should be
unblocked.
This commit adds support for event based services to Finit. Along with
the previously added support for multiple instances of the same process,
the feature scope for Finit v2.0 has been reached!
As of now a service can be declared in /etc/finit.conf or /etc/finit.d/
like this:
service :1 [2345] <!IFUP:eth0,GW> /sbin/dropbear -R -F -p 22 -- SSH daemon
Here the first instance `:1` of dropbear is declared to run in runlevels
2-5, but only if eth0 `IFUP:eth0` is up and a gateway `GW` is set. When
the configuration changes, a new gateway is set, or somehow a new `IFUP`
event for eth0 is received, then dropbear is not SIGHUP'ed, but instead
stop-started `<!>`. The latter trick applies to all services, even
those that do not define any events.
Currently inetd services are not supported for event based starting, but
it could easily be added. Likely scenario is to deny incoming requests
on, e.g., eth0 if there is no gateway.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Previously `HOOK_SVC_RECONF` was only called on `initctl reload`,
now we also call it on `initctl emit "STOP"`. This seems like a
good idea atm, hopefully it will remain a good idea.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When Finit receives SIGHUP or a reload command all services listed in
/etc/finit.d/*.conf are first stopped and then started again. I.e.,
removed/changed services are stopped and then new/changed services are
started again. In between we call HOOK_SVC_RECONF. It should always be
called, even though no services were removed/changed/added. This to
allow plugins connected to that hook may need to run as intended.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit. When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances. For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Fix side effect with run stanza children not being collected if finit is
not run in verbose mode. Regression introduced in release cycle.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch changes the syntax for custom inetd services and adds support
for deny filters. The new syntax is:
inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>
This means the second column now defines what@from and the third to/what
process. For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin. Here follows a few examples:
inetd time/udp wait [2345] internal -- UNIX rdate service
inetd time/tcp nowait [2345] internal -- UNIX rdate service
inetd 3737/tcp nowait [2345] internal.time -- UNIX rdate service
inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 2323/tcp@eth1,eth2,eth0 nowait [2345] /sbin/telnetd -i -F -- Telnet service
inetd 222/tcp@eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
inetd ssh/tcp@*,!eth0 nowait [2345] /sbin/dropbear -i -R -F -- SSH service
Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`. The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`. The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.
NOTE: This patch breaks syntax compatibility with Finit v1.12!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch further extends the capabilities of the client with the
ability to control the running state of services:
finit <stop|start|reload|restart> JOB
Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch. A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier. See the output of `finit status` for the JOB id.
Also, with the introduction of multiple instances we broke support for
multiple related inetd services. This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Turns out that #ID syntax for multiple instances, introduced in cb07556,
was very cumbersome to reference from the shell command line in the new
Finit client. This patch changes the syntax from #ID to :ID, which also
means that listing services/jobs in the shell will look like JOB:ID.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Lots of cleanup and simplification of the main code in this commit.
Most notably libev has been added to take care of the main loop and
monitor services. Still TODO is migrating to use the libev signal
handling.
Convert initctl.c:listen_initctl() to a plugin instead. This also
meant introducing a new form of I/O plugin to finit, also handled
by libev.
Load plugins *after* we've setup the base filesystem (BASEFS) in case
plugins reside on a filesystem not reachable before "mount -a" has run.
This also has the side effect of lining up nicely with the first level
plugin hooks.
If a plugin wants to hook up with a loded service we connect them by
their respective numeric IDs in plugin_register(). I.e., the service
monitor checks if a service has a registered callback, which in turn
decides if a service should be started, stopped or reloaded.
Rip out old EeePC distribution defines from finit.h, none of it really
applies anymore. If you need distribution specific settings this is
the place to put them.
Make hookpoint names (#defines) clearer: after BASEFS, after networking,
after all setup, etc.
Use #inlude_next <signal.h> in signal.h to include system header file!
Simplify service monitor: move essential code to svc.c and rip out
the TIPC dependency. Write your own service.so plugin, or wait for
a more complete example of how to extend service monitoring using
the primitives in svc.c
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
finit.conf:
Use this as /etc/finit.conf on a Debian 6.0 based system with X
installed and sysklogd instead of rsyslogd. Works.
services:
Alternative method for extending the finit boot procedure. Simply
place this script file in an /etc/finit.d/ directory. The script
uses the standard run-parts tool to chain load other start scripts.
helpers.c:
o New functions:
- run(): home grown system() replacement
- run_interactive(): display progress and status when called
o Bugfix start_process(), make sure to use same signal setup for
children as in run() and run_interactive(). Also, use execvp()
instead of execv() to allow searching $PATH for executables.
finit.h:
o Move signal specific code to new signal.h.
o Bypass verbosity setting to let echo() always print to screen.
finit.c:
o Make run_parts() the default, remove external deps, it works.
o Use run() and run_interactive() to speed up execution further
on embedded systems where forking is expensive.
o Kernel cmdline "quiet" should not close STDIO since this makes
it impossible to run some daemons and start scripts. Instead,
we let "quiet" toggle the finit verbosity setting.
o Remove kernel cmdline "--verbose" (Upstart compat), to be used
to enable verbose finit when kernel should be quiet.
o Setup kernel specific settings in /etc/sysctl.conf
o Fix D-Bus startup problems. Probably what caused X from not
working initially. Silly rabbit.
o Use system() workaround to start X, cannot get it to start
at all using run() or run_interactive() at the moment.
signal.h:
New file, header file for signal.c. Was about time.
signal.c:
Remove blocking of SIGCHLD from sig_setup(), instead we setup
SIGCHLD early in sig_init() to handle fork() in run() & C:o.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>