Commit Graph
67 Commits
Author SHA1 Message Date
Joachim Wiberg 6b03a1ec8f conf: adopt the systemd semantics for per-service directories
Aaron Andersen points out in the #492 discussion that the *Directory
settings carry more contract than create-and-chown: per-directory
modes, specific ownership rules, and cleanup toggles.  Without them
config-dir was chowned to the service user, which systemd never does,
an existing directory with drifted ownership was left wrong, and the
runtime directory could not survive a restart.

Now matching systemd.exec(5), and where the man page is vague, the
code in setup_exec_directory():

  - each directory takes a matching -mode key, octal with the leading
    zero, default 0755.  The mode of the named directory is locked
    down again on every start, also when it already exists
  - config-dir is created but never chowned
  - the contents of an existing directory are left alone as long as
    the owner is right; on drift everything under it is chowned back
  - runtime-dir-preserve = no | restart | yes maps
    RuntimeDirectoryPreserve=.  A service still qualified to run when
    the runtime directory would be removed is restarting, not
    stopping, which is what svc_enabled() answers

The dir mechanics move to mksubsysd(), taking resolved ids, with
mksubsys() reduced to a name-resolving wrapper for the dbus plugin.
The child resolves uid/gid once for both directory setup and
privilege drop.

The symlink form, RuntimeDirectory=foo:bar, is not adopted.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:23:38 +02:00
Joachim Wiberg 7f8a64dd39 util: promote rmrf() from tmpfiles.c, fix silent mksubsys() skip
rmrf() is needed outside tmpfiles.c.  The move also deduplicates the
nftw callback: the contents-only removal used by tmpfiles 'D' entries
is now rmcontents(), sharing the callback with rmrf().

mksubsys() did nothing at all when the user could not be resolved, no
directory and no message, and callers had no way to tell.  Now the
directory is always created, ownership is best effort, and an unknown
user is warned about.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:23:37 +02:00
Joachim Wiberg 0721b0fec2 util: one whole-file reader for all tools
Three private ones had grown: fnread() in util.c, flen() behind
pid_cmdline()/pid_cgroup() in cgutil.c, and conf_read_template() in
conf.c.  Two of them were also wrong in ways the others were not.

fnread() formatted the path into a char[256] and stat()ed it before
opening, so a longer path was silently truncated and then read from
whichever file the truncation happened to name, and the size could
change between the look and the read.  flen() existed because neither
of those approaches works on procfs at all, where stat() reports zero
and the only way to learn the size is to read to EOF.

Add fslurp() to util.[ch], which every tool already links.  It opens
first and sizes the fd it holds, treats st_size as a hint, and reads
until EOF, so procfs and regular files take the same path.  Paths are
formatted by libite's vfopenf(), which allocates to fit.  Callers that
need the byte count, /proc/PID/cmdline embeds NUL, ask for it.

fnread() keeps its signature and becomes a bounded copy out of the
result, so its one caller is unaffected.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:27 +02:00
Joachim Wiberg 47a18140c1 conf: cleanup and relocation of common parsing functions and helpers
- legacy.[ch]: strictly legacy .conf parser boilerplate only
 - conf.[ch]: .conf parser and generic configuration functionality

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:26 +02:00
Joachim Wiberg d0176612c9 Default to user/group root for services and check for errors
This is a refactor of getuser() and getgroup() so that they always
return a valid user, and group, for all normal use-cases.  When an
error occurs we now handle it properly in service_fork() so as to
not attempt to start services with an invalid user/group setting
as root.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:29:28 +01:00
Joachim Wiberg a3d9b6e9b1 initctl: fix remaining lingering artifacts in 'top' output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:38 +01:00
Joachim Wiberg a02760f499 Minor, constify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-14 10:00:39 +01:00
Joachim Wiberg 8377f0e736 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 14:34:16 +02:00
Joachim Wiberg b18b21830a Relocate functions helpers.c -> util.c
The file helpers.c should strictly only be used for misc. helper
functions to the main Finit daemon.  The functions moved in this
commit are generic enough to be used by any deamon or programs,
and for that we have util.c

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:14:00 +02:00
Mathias Thore a0685219cf Avoid remounting already mounted /run and /tmp directories
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
2024-08-05 14:33:43 +02:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Joachim Wiberg 791df0c986 Refactor, ensure basenm() returns a const char pointer of its arg.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 23:46:17 +01:00
Stargirl-chan cbea83b369 Simplified function comment and follow coding style 2023-12-29 13:37:08 +01:00
Stargirl-chan 42cd8d284b Implement custom basename function (basenm)
There exist two possible basename functions, a xpg compliant one in libgen.h
and a GLIBC exclusive one declared in string.h, that was previously also declared by musl libc.
Both implementations are expecting different parameter types (`const char *` for GLIBC and `char *` for xpg)

With the removal of the basename function from string.h in musl libc, we could only rely on the xpg implementation.

Unfortunately, the xpg implementation of basename does modify the contents of whatever you put in it,
even though that there really is no need for it.

This is an issue in some cases, where we might want to get the basename of a read-only variable, e.g. a `const char *`,
as trying to modify something read-only is undefined behavior.

So in order to keep things consistent for us, we implement our own version of basename called `basenm`,
that does not modify the passed argument.
2023-12-29 10:44:40 +01:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg 82c6e4680f Fix issue with pid://../run/foo..pid parser
Unfortunately we cannot use realpath(3) here since the the PID files
usually do not yet exist at this point.

Add and modify my ugly de_dotdot() from Merecat httpd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 18:16:27 +01:00
Joachim Wiberg bd5cf7c9eb Drop confusing leading / in sig2str() and code2str()
This was added for the benefit of `initctl status foo`, but we have
other users of these functions that don't expect a leading slash.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-08 22:37:13 +01:00
Joachim Wiberg 37e3be9a0d Refactor to share err/warn log API between daemon and client code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-05 09:57:45 +02:00
Joachim Wiberg 181d9556a1 Drop config.h include from helpers.h, exported header file
Drop the config.h include from helpers.h after a report from a colleague
trying to build an external plugin from the latest GIT sources.

Instead, make sure config.h is included, and properly commented, in all
.c files that have configure #ifdefs and other deps.  Also, move more
ot the includes from helpers.h to their respective .c file instead to
reduce the amount of headers an external plugin pulls in.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-05 14:48:30 +02:00
Joachim Wiberg d6c55282ef Fix #253: use reentrant getmntent_r() API
When iterating over the system fstab file to call fsck, Finit calls the
helper function ismnt(), which opens /proc/mounts to make sure mounted
file systems are not fsck'ed.  Both the main function and ismnt() used
the same non-reentrant getmntent() API which caused ismnt() to set the
fstab pointer for the first out of whack.

This change replaces getmntent() in the two critical functions with the
getmntent_r() API instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 21:43:13 +02:00
Joachim Wiberg 108bbf56dd Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:35:49 +02:00
Joachim Wiberg f33261af6b Fix fnread() string fmt, no format args.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-17 11:30:43 +02:00
Joachim Wiberg bd9bb92ca0 Replace reboot(RB_SW_SUSPEND) w/ internal /sys/power/state API
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-16 23:59:32 +02:00
Joachim Wiberg 69800537f2 Minor, rename local variable for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-25 07:18:54 +01:00
Joachim Wiberg 61014431aa Minor refactor
- Simplify, no need for additional local variable
  - Use established nomenclature

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-25 07:15:43 +01:00
Joachim Wiberg 85b29d9407 Minor whitespace and comment cleanup
- Comments preferably at beginning of func/sect
  - Reorder code slightly, add whitespace for readability
  - Drop useless comment

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-25 07:15:03 +01:00
Jörgen Sigvardsson 62da379472 initctl signal command parsing: done 2022-02-15 12:29:40 +01:00
Ming Liu 3e0063e874 Fix filesystems not unmounted at shutdown
Instead of unconditionally waiting 2 seconds for processes to die,
check continuously for remaining processes, and break the loop when
none remain.

Turn PID 1 to a RT process with highest priority 99 during shutdown,
this ensures it would not be preempted by other RT processes.

Signed-off-by: Robert Andersson <robert.m.andersson@atlascopco.com>
Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2022-02-07 10:06:36 +01:00
Joachim Wiberg d331b72dfd Relocate ismnt() and fismnt() to util.c, for sharing with initctl
initctl cannot link with helpers.c, so let's relocate these helper
functions to util.c instead.  Need them to probe for cgroup support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-10 20:26:37 +01:00
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
Joachim Wiberg 2f34315634 fnread(): make sure to NUL terminate buffer
Note, this is dead code, currently unsused in Finit.  Possibly an
external plugin makes use of it, but even that is highly unlikely.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-14 11:19:57 +02:00
Joachim Wiberg 94c0d1b833 Refactor built-in getty into a standalone getty in /libexec
This patch moves the built-in getty out of Finit into /libexec/finit/,
reducing the size of the Finit binary and simplifying the code.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg cbb8935660 New functions: fnread() and fngetint(), companions to fnwrite()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-11 07:02:30 +02:00
Joachim Wiberg 23a13fe1b6 initctl: add hidden command line option -d,--debug
For developer use only.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:23:58 +02:00
Joachim Wiberg 6d380082eb ttinit: check retun value from tcgetattr(), only restore if OK
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 10:11:06 +02:00
Joachim Wiberg eff4453de9 initctl: add missing comma in signames[], found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 15:54:11 +02:00
Joachim Wiberg c9e1c2f80f initctl: show exit status/signaled like systemctl
- Show if exited/signaled
 - Show status code and the std /NAME
 - Show signal value and the std /NAME

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 11:51:29 +02:00
Joachim Wiberg 12eaa3073a fnwrite(): call fclose() separately, found by Coverity Scan
If any of the fputs() calls fails we will not call fclose() and thus
cause resource loss.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 14:32:12 +02:00
Joachim Wiberg 3de9643893 fnwrite(): fix resource leak, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:26:56 +02:00
Joachim Wiberg b1bee31d61 Helper functions for setting TTY in raw and cooked mode
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 10:07:26 +02:00
Joachim Wiberg 522276b80d Minor, rename internal functions/variables screen_* -> tt*
- Shorter
 - Follows old UNIX tradition
 - Lines up with next commit

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 10:06:01 +02:00
Joachim Wiberg d59f55b90c initctl: new command 'cgroup' to show cgroup config
This is intended to be used with the 'top' command to aid in setting up
and verifying proper limits for services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-06 12:03:20 +02:00
Joachim Wiberg 665d212bd6 Add support for configuring cgroups and their settings on services
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.

Services can now be assigned to a cgroup, with optional extra settings
for that particular process group.  The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.

   cgroup maint cpu.weight:123,mem.max:10000

Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.

    cgroup.maint
    service foo
    service bar cgroup:mem.max:1000

This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.

NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-30 10:21:01 +02:00
Joachim Wiberg fcb8ec9967 Refactor, factor out and export memsz() util function
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-19 09:30:52 +01:00
Joachim Wiberg 6e24f2ff13 echo(): refactor and rename helper function -> fnwrite()
More often than not, the file to write to in sysfs changes rather than
the value.  This patch changes echo() into a fnwrite(), flipping what
is vsnprintf()'ed, and adds a stupid str() function that converts any
value (float/int/double/uint64_t) to a static string buffer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:25:11 +01:00
Joachim Wiberg 74d715243c sanitize(): avoid strlen() to check string for NUL termination
The strlen() function can easiliy go out of bounds.  Use memchr()
instead, we have the max buffer len as argument anyway.

Also fix call to sanitize() which used wrong length.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:50 +01:00
Joachim Wiberg 4bcfd606b4 Refactor screen_init(), use methods developed in pimd project
- Refactor screen_init()
  - use native impl. of TTY probing from pimd project
    - check if TIOCWINSZ works
    - check if we're running in watch(1), for initctl
  - check if ANSI goto(999,999) escape seq. works (invasive)
  - fallback to 80x24
- Drop screen_exit()
- Rename screen_init() to get_width(), for now, matching pimd
- Relocate call in main() to banner(), first fn to write to TTY

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:23:31 +01:00
Joachim Wiberg d9b705ab98 Runtime detection of working UTMP/WTMP support in system
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 04:17:15 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00