Commit Graph
208 Commits
Author SHA1 Message Date
Joachim Wiberg 337ee003bb Mount /dev/mqueue if missing and set sticky bit to /dev/shm
Inspired by Alpine Linux, add /dev/mqueue if missing.  We should check
the /proc/filesystems first, but this is quicker.

The sticky bit ensures only the owner of files in /dev/shm can delete or
rename files.  This is also what Alpine Linux use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 23:50:30 +01:00
Joachim Wiberg 0b5c555c7f Add 'notify:pid' style readiness notifaction and 'readiness none'
This change expands the readiness notification system in Finit with the
native 'pid' style, which will remain the default readiness in Finit 4.x

For systems that want to transition to Finit 5.x early, a global option
to set 'readiness none' in /etc/finit.conf, has been added.  This change
the service default notification mode to 'notify:none', which can also
be set by Finit 4.x ('readiness pid') for select services.

Fixes #386.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 19:07:12 +01:00
Joachim Wiberg 6443995fc9 Fix #385: internal conditions are type oneshot, always active
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 09:04:35 +01:00
Joachim Wiberg f27998ae4f Assert <int/container> condition if we detect running in container
Useful both for troubleshooting and for triggering if:<int/container> tasks.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-14 08:37:15 +02:00
Joachim Wiberg eb9e94935e Failure to open fstab should log to console, reboot if no sulogin
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 17:56:49 +02:00
Joachim Wiberg 6ae1083c99 Add support for SysV-only scripts in runparts
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.

Additionally, by default `runparts` now runs entirely in the background
without any progress.  To enable progress, an optional argument has been
added to the runparts command line.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 13:25:35 +02:00
Joachim Wiberg 846806747b Fix #366: document fsck.* command line options and simplify code
As pointed out in #366, the configure options --enable-fastboot and
--enable-fsckfix should just alter the default values of the two fsck
command line options.

This commit simplifies the code and makes it possible to override using
the command line regardless of the two build options.

Finally, add the two command line options to doc/cmdline.md

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 11:58:07 +02:00
Joachim Wiberg 263aec292a Support for disabling invocation of rescue mode from kernel cmdline
The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 12:45:03 +02:00
Joachim Wiberg a22a794f55 Clarify usage text slightly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg a58002588e Refactor initial startup, run runparts and rc.local in background
The code refactored in this commit has long been an eyesore.  The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.

Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.

Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls.  To
ensure they run at the same point in time two things have been done:

 1. A new <int/bootstrap> condition has been added which triggers
    runparts, which now is a regular task created by conf_init()
 2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
    transition from runlevel S to any other runlevel.

Fixes #356

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-30 10:09:34 +02:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg e00fda5dc3 Fix #352: separate runlevel S from runlevel 0
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff.  If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.

This change is quite invasive.  It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-22 15:11:27 +02:00
Joachim Wiberg 5340e47e81 Flush .conf event queue before leaving boostrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-21 11:24:17 +01:00
Joachim Wiberg 1e5ce38928 Return EX_NOPERM for non-root users calling init/telinit
See issue #301 for future per-user support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-05 10:05:24 +01:00
Joachim Wiberg 1e1b3564dd Support for fsck_mode=[auto,skip,force] + fsck_repair=[preen,no,yes]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg 33e504b928 Check if WDT_DEVNODE is defined, may not be enabled in configure
When this code was moved from finit.c we rely on WDT_DEVNODE to be
defined in config.h, which is controlled by configure.  Meaning, before
the relocation, Finit did not honor the configure settings.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 02:00:14 +01:00
Joachim Wiberg e9515971ea Refactor, move registration of static services to conf_init()
All services registered in the system rely on conf_init() having been
set up properly, e.g., global_rlimit.  Having conf_init() be responsible
also for registering static services is only logical, and also helps us
clean up main() a bit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg 82dfa002ff Follow-up to c9fe9afa, proper fix for HOOK_BASFFS_UP mess
Instead of the revert in c9fe9afa, we restore HOOK_BASFFS_UP to its
proper place at the end of fs_mount_all().  For this to not cause any
regressions we add a new hook, HOOK_SVC_PLUGIN, and update all plugins
that call service_register() to run at the new hook.

This will cause regressions for external 3rd party plugins that rely on
HOOK_BASEFS_UP to be called at its previous postion.  Nevertheless, this
is the proper fix to the problem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg c9fe9afa61 Revert "HOOK_BASEFS_UP must run as soon as all filesystems are mounted"
This reverts commit 5b41c6e since it causes regressions in plugins
adding services to the system.  The proper fix for early bootmisc
is to add a new hook, which will be added in subsequent commits.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-24 10:00:47 +01:00
Joachim Wiberg 311c6be9aa Add support for optional reboot delay
Slightly different take on issue #334 making it optional, possible to
enable per system.

    reboot-delay <0-60>           # default: 0 (disabled)

When enabled (non-zero), runs after filesystems have been unmounted,
the root filesystems has been remounted read-only, and sync(2) has
been called, twice.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-08 09:37:19 +01:00
Joachim Wiberg 5b41c6e327 HOOK_BASEFS_UP must run as soon as all filesystems are mounted
At this hook point the bootmisc.so plugin runs and creates all relevant
system directories.  Much of the rest of system bootstrap relies on this
so it should be called together with the other FS hooks as soon as all
the filesystems have been mounted.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-07 15:09:50 +01:00
Joachim Wiberg 17c69fef3d Fix #185: add devmon support, <dev/foo> condition provider
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-12-18 22:21:15 +01:00
Joachim Wiberg 70c2939596 Fix #315: add environment variables to hook scripts
All hook scripts are called with at least one environment variable set,
FINIT_HOOK_NAME, useful when reusing the same hook script for multiple
hook points.  It is set to the string name, also used by the path, e.g.,
hook/net/up.

For all hook points from hook/sys/shutdown and later, FINIT_SHUTDOWN is
also set, to one of:  halt, poweroff, reboot.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 22:51:40 +01:00
Joachim Wiberg 0498326962 Fix #318: only show "[ OK ] Calling foo" progress for runparts ...
For all other run_parts() use-cases we just give the script control over
stdout/stderr to prevent clobbering ANSI color escape codes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 21:49:30 +01:00
Joachim Wiberg f3fcca6150 Revert "Refactor, enter main event loop earlier"
This reverts commit 03c08d3970 due to it
breaking handling of bootstrap tasks, causing endless boot loop.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 17:54:32 +01:00
Joachim Wiberg 2f91ab5eac Fix #235: support for overriding /etc/finit.conf and /etc/finit.d
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.

For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added.  It in turn can be used by factory.conf
as follows to override /etc/finit.d:

    rcsd /etc/factory.d

Manually verified in myLinux

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-10 17:21:33 +01:00
Joachim Wiberg 1f9621cf4b Fix #288: enable built-in sulogin in Alpine and Void Linux builds
Always better to have at least one sulogin available, if the system
provided sulogin isn't available we fall back to the built-in one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 21:08:44 +02:00
Joachim Wiberg d22dea74e3 Finalize refactor to new log macros, following-up to 37e3be9
This possible also mitigates the issue tracked in #307.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-09 12:52:40 +02:00
Joachim Wiberg 03c08d3970 Refactor, enter main event loop earlier
This delays the start of the .conf monitor and service initialization
slightly to allow the event loop to run earlier to process any events
from the initial setup.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-05 13:47:08 +02:00
Joachim Wiberg 0ce028add1 Fix #283: too quick timeout at bootstrap of lingering tasks
This seemed odd at first, but it turns out we seem to have adjusted the
time scale for the bootstrap worker, so we were off by ... a factor 10.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-03 03:45:10 +02:00
Joachim Wiberg 83aa6abb1c Fix potential NULL ptr dereference, found by Coverity
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-17 14:37:06 +02:00
Joachim Wiberg a27b8462d1 Fix #260: drop limit on device name in "Checking filesystem" output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-08 09:59:51 +02:00
Joachim Wiberg 0cce69892a Fix #261: support for overriding default runlevel from command line
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-08 09:57:18 +02:00
Joachim Wiberg d3c6351ed8 Fix nasty service matcher bug
In some conditions, typically when the same command is used for multiple
services, e.g. the modules-load plugin, the svc_find() function returned
an existing "similar" entry instead of NULL, causing loss of config.

When creating, and searching for, a run/task/service we must follow the
new name:id paradigm to the letter.  Always create based on name:id and
always search for matching name:id.  The name may be derived from the
command, but they cannot be used interchangably.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-06 07:57:08 +02:00
Joachim Wiberg 8db521d379 Fix minor memory leak in sulogin() handling
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-03 05:58:24 +02:00
Joachim Wiberg 38db52aa4e Add support for setting environment variables from finit.conf
Finit can now track and set environment variables from finit.conf.  The
syntax is pretty much what you'd expect:

    foo=bar
    baz="qux"

On reload of .conf files, all tracked environment variables are cleared
so if `foo=bar` is removed from finit.conf, or any finit.d/*.conf file,
it will no longer be used by Finit or any new (!) started run/tasks or
services.

The only variables reset to sane defaults on .conf reload are:

    PATH=_PATH_STDPATH
    SHELL=_PATH_BSHELL
    LOGNAME=root
    USER=root

It is entirely possible to override these as well from the .conf files,
but be careful.  Changing SHELL changes the behavior of system() and a
lot of other commands as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-02 00:02:44 +02:00
Joachim Wiberg d6c55282ef Fix #253: use reentrant getmntent_r() API
When iterating over the system fstab file to call fsck, Finit calls the
helper function ismnt(), which opens /proc/mounts to make sure mounted
file systems are not fsck'ed.  Both the main function and ismnt() used
the same non-reentrant getmntent() API which caused ismnt() to set the
fstab pointer for the first out of whack.

This change replaces getmntent() in the two critical functions with the
getmntent_r() API instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 21:43:13 +02:00
Joachim Wiberg 1015124530 Use sys/sysmacros.h, if available, for minor() and major()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 20:50:17 +02:00
Joachim Wiberg 38885aaa67 Issue #253: handle fsck of magic /dev/root device
Some systems have /dev/root declared in their /etc/fastb as /.  This is
as special device node created by the kernel based on the root=, and a
few other variables.  This may be a symlink, and if so, and on a mdev
system, the symlink may point to the wrong device node ... so we must
try to figure out the major:minor from / and then traverse /sys/block
to find our root device.

Note: this commit also does a bit of refactoring for readability and
      also adds a few debug lines that may be dropped before release.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 19:31:51 +02:00
Joachim Wiberg a685b698c2 Follow-up to 5593372f, regression in remounting read-write at boot
A subtle regression was introduced in 5593372f, when moving to get
getmntent() family of APIs.  Finding the 'ro' flag (or not) in the
system fstab broke and Finit never tried to remount / read-write.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 19:28:50 +02:00
Joachim Wiberg 605c489937 Follow-up to 57c97d8, issue #224: add swapon/swapoff fstab wrappers
The swapon and swapoff commands do not support a custom fstab, they
assume /etc/fstab is the only true source of swap devices and files.

This change adds rudimentary (!) support for figuring out any swap
device or file to use from any finit.fstab.  Please note, options are
not supported at the moment.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-26 22:57:22 +02:00
Joachim Wiberg 26409bc860 Follow-up to 57c97d8, issue #224: fsck needs FSTAB_FILE env. set
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-26 21:59:11 +02:00
Joachim Wiberg 57c97d8190 Fix #224: support for cmdline -- finit.fstab=/etc/fstab.secondary
This adds support for bringing up the system with an alternate fstab at
boot.  E.g., when using a primary/secondary setup for boot partitions.

By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary

If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.

Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot.  Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-25 21:44:33 +02:00
Joachim Wiberg 5593372ffb Refactor, replace deprecated setfsent() & C:o with setmntent()
The setfsent() family of APIs was never standardized and on Linux only
GLIBC implement them.  We've tried to overcome this limitation, and to
support uClibc/uClibc-ng and musl libc, by providing replacements APIs
in helpers.c.

However, and since we want to support alternative /etc/fstab files, the
setmntent() family of APIs is more widespread and supports reading from
any fstab or mtab file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-20 07:20:33 +02:00
Joachim Wiberg 108bbf56dd Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:35:49 +02:00
Joachim Wiberg f39626f132 Minor, fix format string to systemf()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-17 14:25:32 +02:00
Joachim Wiberg 01cb088e51 Fix initctl debug toggle regression introduced in ae09272b
Calling `initctl debug` is supposed to toggle Finit debug messages on
the boot console.  This broke in ae09272b when improving support for
running Finit in containers.

Part of this change is a slight refactor of who calles log_init() when
starting up, and when to call ttinit().  We now call ttinit() every time
we toggle debug.

Also, toggling back to normal logging had a bug.  The new default log
level for Finit is LOG_INFO, but toggling back set it to LOG_NOTICE.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-14 11:55:17 +02:00
Joachim Wiberg 3e51ed1c55 Run swapon interactively, let user know what's happening.
Let's try this, should be OK for all types of systems.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-12 21:45:37 +02:00
Joachim Wiberg 0e695aa0c7 Only run swapon/swapoff if they exist
To silence warnings at startup/shutdown, check for existance of swapon
and swapoff before calling them.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-03-07 14:01:25 +01:00
Joachim Wiberg 6fa3aa41df run(): add support for logging/redirect
This patch adds support for optional logging of output from all run()
commands.  For run_interactive() we've opted to log instead of just
redirect, meaning output on error is till on console but also in log.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-03-01 20:46:01 +01:00