Inspired by Alpine Linux, add /dev/mqueue if missing. We should check
the /proc/filesystems first, but this is quicker.
The sticky bit ensures only the owner of files in /dev/shm can delete or
rename files. This is also what Alpine Linux use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change expands the readiness notification system in Finit with the
native 'pid' style, which will remain the default readiness in Finit 4.x
For systems that want to transition to Finit 5.x early, a global option
to set 'readiness none' in /etc/finit.conf, has been added. This change
the service default notification mode to 'notify:none', which can also
be set by Finit 4.x ('readiness pid') for select services.
Fixes#386.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.
Additionally, by default `runparts` now runs entirely in the background
without any progress. To enable progress, an optional argument has been
added to the runparts command line.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
As pointed out in #366, the configure options --enable-fastboot and
--enable-fsckfix should just alter the default values of the two fsck
command line options.
This commit simplifies the code and makes it possible to override using
the command line regardless of the two build options.
Finally, add the two command line options to doc/cmdline.md
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The code refactored in this commit has long been an eyesore. The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.
Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.
Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls. To
ensure they run at the same point in time two things have been done:
1. A new <int/bootstrap> condition has been added which triggers
runparts, which now is a regular task created by conf_init()
2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
transition from runlevel S to any other runlevel.
Fixes#356
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff. If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.
This change is quite invasive. It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When this code was moved from finit.c we rely on WDT_DEVNODE to be
defined in config.h, which is controlled by configure. Meaning, before
the relocation, Finit did not honor the configure settings.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
All services registered in the system rely on conf_init() having been
set up properly, e.g., global_rlimit. Having conf_init() be responsible
also for registering static services is only logical, and also helps us
clean up main() a bit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of the revert in c9fe9afa, we restore HOOK_BASFFS_UP to its
proper place at the end of fs_mount_all(). For this to not cause any
regressions we add a new hook, HOOK_SVC_PLUGIN, and update all plugins
that call service_register() to run at the new hook.
This will cause regressions for external 3rd party plugins that rely on
HOOK_BASEFS_UP to be called at its previous postion. Nevertheless, this
is the proper fix to the problem.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This reverts commit 5b41c6e since it causes regressions in plugins
adding services to the system. The proper fix for early bootmisc
is to add a new hook, which will be added in subsequent commits.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slightly different take on issue #334 making it optional, possible to
enable per system.
reboot-delay <0-60> # default: 0 (disabled)
When enabled (non-zero), runs after filesystems have been unmounted,
the root filesystems has been remounted read-only, and sync(2) has
been called, twice.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
At this hook point the bootmisc.so plugin runs and creates all relevant
system directories. Much of the rest of system bootstrap relies on this
so it should be called together with the other FS hooks as soon as all
the filesystems have been mounted.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
All hook scripts are called with at least one environment variable set,
FINIT_HOOK_NAME, useful when reusing the same hook script for multiple
hook points. It is set to the string name, also used by the path, e.g.,
hook/net/up.
For all hook points from hook/sys/shutdown and later, FINIT_SHUTDOWN is
also set, to one of: halt, poweroff, reboot.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For all other run_parts() use-cases we just give the script control over
stdout/stderr to prevent clobbering ANSI color escape codes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This reverts commit 03c08d3970 due to it
breaking handling of bootstrap tasks, causing endless boot loop.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.
For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added. It in turn can be used by factory.conf
as follows to override /etc/finit.d:
rcsd /etc/factory.d
Manually verified in myLinux
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Always better to have at least one sulogin available, if the system
provided sulogin isn't available we fall back to the built-in one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This delays the start of the .conf monitor and service initialization
slightly to allow the event loop to run earlier to process any events
from the initial setup.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This seemed odd at first, but it turns out we seem to have adjusted the
time scale for the bootstrap worker, so we were off by ... a factor 10.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In some conditions, typically when the same command is used for multiple
services, e.g. the modules-load plugin, the svc_find() function returned
an existing "similar" entry instead of NULL, causing loss of config.
When creating, and searching for, a run/task/service we must follow the
new name:id paradigm to the letter. Always create based on name:id and
always search for matching name:id. The name may be derived from the
command, but they cannot be used interchangably.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Finit can now track and set environment variables from finit.conf. The
syntax is pretty much what you'd expect:
foo=bar
baz="qux"
On reload of .conf files, all tracked environment variables are cleared
so if `foo=bar` is removed from finit.conf, or any finit.d/*.conf file,
it will no longer be used by Finit or any new (!) started run/tasks or
services.
The only variables reset to sane defaults on .conf reload are:
PATH=_PATH_STDPATH
SHELL=_PATH_BSHELL
LOGNAME=root
USER=root
It is entirely possible to override these as well from the .conf files,
but be careful. Changing SHELL changes the behavior of system() and a
lot of other commands as well.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When iterating over the system fstab file to call fsck, Finit calls the
helper function ismnt(), which opens /proc/mounts to make sure mounted
file systems are not fsck'ed. Both the main function and ismnt() used
the same non-reentrant getmntent() API which caused ismnt() to set the
fstab pointer for the first out of whack.
This change replaces getmntent() in the two critical functions with the
getmntent_r() API instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some systems have /dev/root declared in their /etc/fastb as /. This is
as special device node created by the kernel based on the root=, and a
few other variables. This may be a symlink, and if so, and on a mdev
system, the symlink may point to the wrong device node ... so we must
try to figure out the major:minor from / and then traverse /sys/block
to find our root device.
Note: this commit also does a bit of refactoring for readability and
also adds a few debug lines that may be dropped before release.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A subtle regression was introduced in 5593372f, when moving to get
getmntent() family of APIs. Finding the 'ro' flag (or not) in the
system fstab broke and Finit never tried to remount / read-write.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The swapon and swapoff commands do not support a custom fstab, they
assume /etc/fstab is the only true source of swap devices and files.
This change adds rudimentary (!) support for figuring out any swap
device or file to use from any finit.fstab. Please note, options are
not supported at the moment.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This adds support for bringing up the system with an alternate fstab at
boot. E.g., when using a primary/secondary setup for boot partitions.
By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary
If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.
Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot. Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The setfsent() family of APIs was never standardized and on Linux only
GLIBC implement them. We've tried to overcome this limitation, and to
support uClibc/uClibc-ng and musl libc, by providing replacements APIs
in helpers.c.
However, and since we want to support alternative /etc/fstab files, the
setmntent() family of APIs is more widespread and supports reading from
any fstab or mtab file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Calling `initctl debug` is supposed to toggle Finit debug messages on
the boot console. This broke in ae09272b when improving support for
running Finit in containers.
Part of this change is a slight refactor of who calles log_init() when
starting up, and when to call ttinit(). We now call ttinit() every time
we toggle debug.
Also, toggling back to normal logging had a bug. The new default log
level for Finit is LOG_INFO, but toggling back set it to LOG_NOTICE.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
To silence warnings at startup/shutdown, check for existance of swapon
and swapoff before calling them.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for optional logging of output from all run()
commands. For run_interactive() we've opted to log instead of just
redirect, meaning output on error is till on console but also in log.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>