Commit Graph
2605 Commits
Author SHA1 Message Date
Joachim Wiberg 33deada6f0 README: mention new rescue mode in feature list overview
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-26 00:52:40 +02:00
Joachim Wiberg 9d1506bb7e Revert "Travis-CI: disable clang for coverity scan run"
This reverts commit e011dac98b.
2021-04-26 00:45:57 +02:00
Joachim Wiberg c3f115c9ec sulogin: fix build issue
Keyboard suddenly lost CapsLock -> Ctrl remapping ...

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-26 00:39:39 +02:00
Joachim Wiberg 430d402b14 sulogin: check for Ctrl-D also if no pwd to abort and continue boot
Signed-off-by: Joachim Wiberg <joachim.nilsson@westermo.se>
2021-04-26 00:25:24 +02:00
Joachim Wiberg e011dac98b Travis-CI: disable clang for coverity scan run
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 23:57:41 +02:00
Joachim Wiberg 42b84d1ccb Update ChangeLog for v4.0 GA
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 23:57:02 +02:00
Joachim Wiberg 288105eac7 sulogin: must fflush() prompt on Alpine Linux (musl libc)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 23:14:05 +02:00
Joachim Wiberg 842b522e68 Drop --disable-logit configure option, no longer in $PATH
Simplify build system.

The logit tool is, as of v4.0, installed into /libexec/finit/logit and
thus not part of the system $PATH.  If a sysadmin or distro wants to
remove it from the system it's entirely possible since Finit always
checks for logit availability before attempting to use it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:53:34 +02:00
Joachim Wiberg e6f36974c8 Document all facets of rescue mode; traditional and fallback
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:46:43 +02:00
Joachim Wiberg 679b4df881 Fallback rescue mode handling
Before 4e5d06b the only way to go into rescue mode was to skip certain
steps and then attempt to load /lib/finit/rescue.conf.  After 4e5d06b
we keep the old handling as a fallback in case early sulogin fails.

The new tty option 'rescue' is added, which recue.conf is updated with.
This option implies notty mode and will try sulogin (again) before it
falls back to start /bin/sh as a login shell.

The reason we keep this is to be able to handle all possible use-cases
and also allow sysadmins to set up the behavior that fits their needs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:10:42 +02:00
Joachim Wiberg 666cae6f49 service_start(): allow notty TTYs without device to start
A notty TTY can be declared with or without a device, it requires none.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:09:07 +02:00
Joachim Wiberg be2ac1d1b1 sulogin: handle no password and locked account (treated as no pwd)
This patch does two things:

 1. A system with a root account that has no password is now
    allowed to login without password, as one expects.
 2. A systems with a locked root account, is treated as (1).

The latter of the two may very well turn out to be a really bad idea.
Much angst have been poured into it, yet the end decision is to allow
access.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 21:43:39 +02:00
Joachim Wiberg 266e5b30eb Drop all mention of old fallback shell from comments
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 21:43:16 +02:00
Joachim Wiberg 4e5d06b580 Replace experimental emergency shell with actual rescue mode
Most major init systems have a way to start a rescue shell.  This is
usally started when the string `rescue` is read from the kernel's
command line.

The traditional Finit way of handling this has been to skip certain
phases of the standard boot, skip /etc/finit.conf et al, and go for a
/lib/finit/rescue.conf instead.  This pratice has been imroved over
the last few commits with a sulogin.  However, there was no way to
resume boot, like most other init systems offer.

This patch implements a very simple rescue mode, utilizing the new
sulogin, replacing the old (and experimental) emergency shell.  If
Ctrl-D is pressed at the maintenance login prompt the boot is now
resumed.  The same goes for exit/Ctrl-D from the maintenace shell.

The preferred sulogin is the bundled /libexec/finit/sulogin, but
if that isn't installed, the first one in $PATH is used.  If no
sulogin at all is found, Finit proceeds as before this patch, to
skip certains steps and go for a /lib/finit/rescue.conf.  Hence,
al steps can be controlled by an administrator.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 21:32:35 +02:00
Joachim Wiberg fe334135ce Fix small memory leak, use whichp() to query, not which()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 19:47:15 +02:00
Joachim Wiberg aef10fb5e7 Revert "Travis-CI: disable clang for coverity scan run"
This reverts commit 550ae9c784.
2021-04-25 19:47:04 +02:00
Joachim Wiberg 86707c1f0b sulogin: minor refactor, splice out sh() as separate function
- splice out sh() as a separate function
 - make sh() session leader and set controlling TTY (TIOCSCTTY)
   to make it a proper login shell with Ctrl-C functionality
 - simplify call to execl()

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 19:28:03 +02:00
Joachim Wiberg a28d5b3c09 sulogin: fix minor issue found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 19:27:42 +02:00
Joachim Wiberg 550ae9c784 Travis-CI: disable clang for coverity scan run
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:45:44 +02:00
Joachim Wiberg cd5b91680a sulogin: home cooked version, can be built -static
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:43:54 +02:00
Joachim Wiberg 221ab20898 tty: add basic security, call sulogin in rescue mode (notty)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:27:26 +02:00
Joachim Wiberg 96534789db Minor, rename LOGIT_PATH -> _PATH_LOGIT for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:26:52 +02:00
Joachim Wiberg 26128dd788 plugins: skip plugin in rescue mode
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.

Essentially, only services in rescue.conf should run in rescue mode.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 19:46:43 +02:00
Joachim Wiberg 799e992542 tty: minor, rename local variables for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:58 +02:00
Joachim Wiberg fa524eec60 contrib: debian: add elogind.conf and update recommendations
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:57 +02:00
Joachim Wiberg 6dced29b49 Add another constraint for the built-in watchdog, device exists
- Check if watchdogd *and* `WDT_DEVNODE` exists before registering the
   built-in watchdogd at boot
 - Update bootstrap.md with this additional constraint
 - Update config.md with references to bootstrap and the new constraint

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:57 +02:00
Joachim Wiberg 2ea613a42b Make sure built-in watchdog is disabled by default
Omitting --without-watchdog caused the watchdog to be enabled.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 09:43:27 +02:00
Joachim Wiberg 985df20519 cgroup: don't warn on cgroup.events EINVAL for top-level groups
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 07:42:31 +02:00
Joachim Wiberg f6161b9be9 doc: Add blurb on bundled vs external watchdog, handover and reset
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 07:41:46 +02:00
Joachim Wiberg 25c5014d3c Also check env: file for changes to detect svc->args_dirty
This patch fixes an issue where services that support SIGHUP are not
properly stop/started on changes to their command line arguments.

A change to a service's env: file, e.g. /etc/default/foo for service
foo, must also be counted as a change to the foo args.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-23 17:12:59 +02:00
Joachim Wiberg b8b7b53d96 External plugins require exporting cgroup.h, svc.h needs it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-20 01:48:03 +02:00
Joachim Wiberg 7707c4b8e6 initctl: only show key capture in debug mode
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 15:56:39 +02:00
Joachim Wiberg 437f95f00f Bump version for final (?) release candidate, v4.0-rc4
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
4.0-rc4
2021-04-19 15:40:26 +02:00
Joachim Wiberg 099672fabb configure: change --enable-redirect -> --disable-redirect
This changes the default to redirect output from run/task/services to
/dev/null.  Use --disable-redirect to get the old pre v4.0 behavior.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 15:25:57 +02:00
Joachim Wiberg 860515a716 contrib: load softdog module on Alpine/Void Linux for finit-watchdog
We need at least the softdog watchdog driver loaded for proper watchdog
reset at reboot.  This can safely be replaced with a hardware specific
module that provides /dev/watchdog ... without one Finit will try to
restart the built-in finit-watchdog service 10 times to no avail.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 14:52:28 +02:00
Joachim Wiberg c85551a42e watchdog: wait for WDT reset only if watchdogd is running
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 14:41:48 +02:00
Joachim Wiberg 79dc6e7472 Update Travis, Alpine, and Void build options
- Fallback shell has been removed
 - Built-in watchdog has been renamed

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 13:55:24 +02:00
Joachim Wiberg 06e456384c watchdog: Enable --with-watchdog[=DEV] and improve log messages
This patch changes the configure option to enable the built-in watchdog
from --enable-watchdog to --with-watchdog[=DEV].  This is the convention
for features that take arguments.

Also, improve log messages to aid debugging when finit-watchdogd does
not start properly.  This means flushing logs to syslogd with closelog()

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 13:41:31 +02:00
Joachim Wiberg 38f7d24a80 tty: clean up developer debug messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg 145c78ef3e Follow-up to 7f76202: Remove fallback-shell from configure summary
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg dd437bf0a5 Follow-up to 18ab7d3: restore start of built-in watchdogd
This patch restores the start of the built-in/bundled watchdogd.  It is
tracked in the `wdog` variable and handled as an exception at shutdown.

This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external.  External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg d82d119729 plugins: handle corner case when PID file doesn't exist
If we get a notification and the service dies immediately, and also
removes its pid file, we need to take corrective action.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 09:45:57 +02:00
Joachim Wiberg 7f76202865 Simplify, drop --enable-fallback-shell from configure script
Recommend using `notty` option in tty stanza instead.  See the updated
docs for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 23:13:19 +02:00
Joachim Wiberg aee92751ac Minor, add env: and sysv examples to first example .conf
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 16:24:19 +02:00
Joachim Wiberg 2ea7236d45 Add feature list immediately after screenshot
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 14:52:50 +02:00
Joachim Wiberg cedc04e1e3 Revert "Travis-CI: disable clang for coverity scan run"
This reverts commit 0168b765c1.
2021-04-18 12:37:21 +02:00
Joachim Wiberg edc6eb1747 initctl: fix too small destination buffer (unlikely)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:24:49 +02:00
Joachim Wiberg be5ec94fdf Fix GCC warnings for unhandled return value
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:24:32 +02:00
Joachim Wiberg 23a13fe1b6 initctl: add hidden command line option -d,--debug
For developer use only.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 12:23:58 +02:00
Joachim Wiberg 0168b765c1 Travis-CI: disable clang for coverity scan run
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 11:55:25 +02:00