Commit Graph
1597 Commits
Author SHA1 Message Date
Joachim Nilsson 2fac65becb Fix long-standing bug, runparts() should run before runlevel change
The difference between `runparts DIR` and `/etc/rc.local` is that one
should run just before the first runlevel change (to the configured
runlevel) at the end of bootstrap, whereas the other should run just
before launcing the TTYs, i.e. after all tasks in the configured
runlevel have been started.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:48:47 +01:00
Joachim Nilsson 46b253dea6 doc: The module configuration stanza supports optional args
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:15:29 +01:00
Joachim Nilsson b04983c3f3 conf: Make rlimit [hard|soft] optional => possible to set both
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:15:12 +01:00
Joachim Nilsson f2d142ef57 Only reload .conf and services if any .conf file has changed
This patch is an optimization.  Now that we monitor for any .conf file
changes (as soon as the event loop starts) we can skip automatic reload
of all .conf files and services if no .conf file has changed.  Unless
the user issues an `initctl reload`, `init q`, or sends us SIGHUP.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 19:22:01 +01:00
Joachim Nilsson 33ce746e58 parse_conf(): Increase log with actual limits in case of problems.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:57:36 +01:00
Joachim Nilsson 6ecb86b4a7 conf_reload(): No need to reload global rlimits again
This patch removes duplicate reload of global_rlimit[], which
parse_conf() already has done.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:56:30 +01:00
Joachim Nilsson 338810b886 Fix #92: Load .conf files and initialize global_rlimit[] earlier
As reported in #92, systems with an udevd very early register a service
using global_rlimit[].  The change was introduced in b68c5c1 but did
not take the ordering problem into consideration, global_rlimit[] was
left uninitialized, which likely led to severely limited udevd that
was continously crashing.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:51:49 +01:00
Joachim Nilsson c1344e89ff api_exit(): Only shutdown() of API socket at runtime
Not needed at shutdown/reboot.  Also, it may segfault at that stage.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:48:44 +01:00
Joachim Nilsson bc35b42bd2 inet_stop(): Check argument and skip shutdown(), just close() socket
- Validate function argument
- Skip¹ shutdown() when closing a TCP socket, not needed

___
¹ also, shutdown() segfaults a late shutdown/reboot

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:46:19 +01:00
Joachim Nilsson dcf8fbe235 do_shutdown(): Advise watchdog using SIGPWR, system is going down
On shutdown/reboot, send SIGPR as a heads-up to watchdogd that the
system is going down.  All file systems are about to be unmounted.
It's just about the last process left running in the system, so we
give it two seconds to complete its work before we continue.

When everything has been unmounted and we're ready to call reboot(),
we send SIGTERM to the registered watchdog, to give ti the chance to
let the WDT reset the system.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:45:02 +01:00
Joachim Nilsson c82a2ce215 Built-in watchdog: on SIGPWR, exit main loop and prepare for SIGTERM
When Finit enters shutdown/reboot we need to advise any watchdogd that
we are going down *before* we unmount any file systems.  This to let
the user save any state, e.g. reboot counters, to disk.  Right before
we call reboot() in Finit we send SIGTERM to the watchdogd to give it
the chance to use the WDT to reboot the system.

The WDT cricuitry on embedded systems is often connected to the RESETn
logic of all relevant board compoents, whereas reboot() only reboots the
SoC with the CPU.  Hence, a WDT reboot is more efficient and more like a
regular power cycle, which users of embedded systems often want.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:24:32 +01:00
Joachim Nilsson e1bb5e3396 Add --disable-redirect-output to configure script
This patch makes it possible to control the default redirection of
(misbehaving) services output to /dev/null.  With this disabled,
a service may write to its stdout/stderr and mess up the console.

By default all service/run/tasks stdout/stderr is redirected.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:22:06 +01:00
Joachim Nilsson 8198582c10 Revert "Travis-CI: Disable clang temporarily, for Coverity Scan run"
This reverts commit cbafbaea1d.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 11:01:24 +01:00
Joachim Nilsson 0d19842aa1 conf_changed(): Fix possible NULL ptr deref, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:35:07 +01:00
Joachim Nilsson 6f665ab283 inet_dgram_drop(): Fix control flow logic, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:31:19 +01:00
Joachim Nilsson 3f731aa5a3 inet_dgram_drop(): Check return value from recv()
Found by Coverity Scan.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:28:22 +01:00
Joachim Nilsson 9e8a01669e api: Fix possible descriptor leak, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:02:49 +01:00
Joachim Nilsson cbafbaea1d Travis-CI: Disable clang temporarily, for Coverity Scan run
... so we don't lose tokens ...

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 09:53:14 +01:00
Joachim Nilsson f534368b33 The @console and nologin flags deserve mentioning early
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 09:51:16 +01:00
Joachim Nilsson 78fc9fccc5 Update initctl usage text
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 09:51:04 +01:00
Joachim Nilsson 3f7df3d35e Update ChangeLog with new nologin option to tty configs
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 03:29:38 +01:00
Joachim Nilsson 9fc33418f9 Document nologin option flag to tty configuration directive
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 03:26:31 +01:00
Joachim Nilsson 72bc3b1a91 Fix #91: Add support for tty nologin, to start /bin/sh immediately
This patch adds a `nologin` flag to the `tty` configuration directive,
making it possible to set up really simple embedded systems with no
login.

Example, put the following line in `/etc/finit.d/getty.conf` to get
a "Please press Enter to ..." prompt before being presented with a
root shell prompt.

    tty [12345] @console noclear nologin

Needless to say, this is not very secure, but can be really useful
for developer setups, during board bringup, or similar.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 01:54:07 +01:00
Joachim Nilsson d6ea1c0cab Protect internal services like dbus-daemon and udevd
In f3669c7 the difference between static and dynamic services was
removed.  This led to a regression in handling internally created
services for, e.g., dbus-daemon and udevd, mentioned in issue #90.

This patch introduces a "protected" flag for svc_t to prevent the
mark-and-sweep handling of regularly loaded services.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 21:57:31 +01:00
Joachim Nilsson 523a270f22 Update README slightly, there's systemd-udevd and eudev these days
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:33:27 +01:00
Joachim Nilsson 3258edc246 Fix #90: Restore tmpfs mount of /dev/shm, removed in d7401b2
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:02:06 +01:00
Joachim Nilsson 32b7a14cb3 Add ismnt() helper function, wrap fismnt()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:00:41 +01:00
Joachim Nilsson 55479cc511 Bump version for first -rc, v3.1-rc1
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
3.1-rc1
2017-12-23 11:52:40 +01:00
Joachim Nilsson b702f7eeef Update ChangeLog for upcoming v3.1 release
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 11:52:40 +01:00
Joachim Nilsson 0e37bb0924 Follow-up to b0663d0, cond_init() must run before first hooks
The new condition triggered hooks requrie /var/run/finit/cond to
be set up before calling the first user-configurable hooks.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 11:19:35 +01:00
Joachim Nilsson 360f3e72bc Audit b0663d0, add newline to generation ID in cond files
- Add newline to cond generation ID, like PID files, easier when
  debugging.  Does not affect fscanf() in cond_get_gen()
- Update copyright years

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 10:05:45 +01:00
Joachim Nilsson c1023c03c7 Merge pull request #89 from westermo/cond-generation
Cond generation
2017-12-23 09:37:16 +01:00
Joachim Nilsson e94d2a8c08 Merge branch 'master' into cond-generation 2017-12-23 09:31:41 +01:00
Joachim Nilsson f7c0366fa2 Fix segfault on X86_64, call va_end()+va_start() for each vfprintf()
... varargs is a special kind of hell.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 00:38:01 +01:00
Joachim Nilsson 8992e7bf2b Refactor svc_iterator() into a proper iterator, add first flag
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 23:56:14 +01:00
Joachim Nilsson 95518df62d Some systems rely on /dev/shm being there for mount -a
This was accidentally removed in d7401b2, when svc_t was refactored
from using shared memory.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 16:44:52 +01:00
Joachim Nilsson 85fe95835a doc/build.md: Mention required library versions
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:17:39 +01:00
Joachim Nilsson baf9c4f61f Travis-CI: Update build deps, libite v1.9.2 --> v2.0.1
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:12:04 +01:00
Joachim Nilsson b439ac670d .conf: don't rely on mtime to determine if service needs reloading
Until now Finit has used mtime to determine if a file has been changed,
or simply touched to request reload, when `initctl reload` is called.
Using mtime for this purpose is a monumentally bad idea since time can
be changed at any point: a user may adjust the time, NTP continously
tunes the clock, and time stamps are stored as the walltime.  So if we
compare timestamps against the last time we (booted or) did reload, we
would miss .conf file changes.

This patch replaces the mtime mistake with an inotify watcher for the
following files: /etc/finit.d/*.conf, /etc/finit.d/available/*.conf,
and /etc/finit.conf.  All file changes between (bootstraps and) calls
to `initctl reload` are tracked, like the mtime backend it replaces.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:08:38 +01:00
Joachim Nilsson bb3d9c8670 initctl: Add support for touch <CONF>, mark .conf for reload
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:50:18 +01:00
Joachim Nilsson 2f9b97b3a7 Update libite (-lite) requried version: 1.9.2 --> 2.0.1
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:49:04 +01:00
Joachim Nilsson c59f7d23f4 Add and improve debug messages, clean out old dev. comments
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:40:43 +01:00
Tobias Waldekranz b0663d04e4 cond: don't rely on mtime for condition management
TIL, using mtimes for tracking event orderings is a monumentally bad
idea (queue the nodding UNIX-beards). Mtimes are in wallclock time which
is not necessarily monotonically increasing. A user may adjust the time,
an NTP daemon will continously tune the clock and so on.

Instead, store an explicit generation number in each condition file,
which will be monotonically increased by finit on each reconf.
2017-12-21 11:10:47 +01:00
Joachim Nilsson 6f26f2f9d0 TODO: Idea about addding support for an optional rescue mode
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:30:49 +01:00
Joachim Nilsson e7cca05fe3 Reserve certain configuration directives for bootstrap only
The following configuration directives, previously only allowed
in /etc/finit.conf, are now also only allowed in runlevel S, i.e.
at bootstrap:

- host
- mknod
- network
- runparts
- runlevel

This change is in preparation for allowing reload of finit.conf
as well as /etc/finit.d/*.conf, which we already support.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:16:55 +01:00
Joachim Nilsson f3669c7537 svc: Remove svc_dynamic_iterator(), soon no difference between svc's
This is a prelude to a major behavioral change.  The difference between
a static and dynamic service will be removed in Finit v3.1.  This means
all .conf files, including /etc/finit.conf, will be re-read on reload.

However, not all configuration directives will be re-read, some will
only be applicable at bootstrap, i.e. runlevel S.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:04:14 +01:00
Joachim Nilsson a9456cec41 svc: Remove unused function, svc_foreach_dynamic()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:02:38 +01:00
Joachim Nilsson 61a9926442 Minor, staticify
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 00:13:21 +01:00
Joachim Nilsson 7784480abe Postpone networking stuff, + hooks, a bit to the finalize() step
This patch moves the networking bit to the latter part of bootstrap,
called finalize(), in favor of starting the event loop earlier.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 00:10:29 +01:00
Joachim Nilsson db50c09ec5 initctl: Improve show SVC command output a bit, provide summary
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 21:04:17 +01:00