Add support for changing the initial hard and soft resource limits for
finit and any processes it launches.
See /etc/finit.conf section in README.md for more information.
When a service changes type from inetd to a regular daemon we must make
sure to first deregister the currently running inetd service properly.
Example: a system boots up with httpd.conf as an inetd service, so Finit
opens a socket 0.0.0.0:80 pending connections to start `httpd -i`.
After a while a user changes httpd.conf to be a regular service and
calls `initctl reload`. Without this patch the socket will remain
open and prevent httpd from opening and binding to the same port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes a problem with lingering inet sockets when inetd
services are removed. When removing an inetd service we must stop
the watcher and close the socket.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We cannot clear the svc_t memory because other applications may have
connected to the same shared memory. An application may be inspecting
the current list of services (initctl) and pulling the rug from under
them could cause some really unpredicatble results.
This reverts commit 06d1e90bac.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Both the original MIT Athena inetd and the GNU inetutils inetd only keep
a backlog of 10 connections in listen() for TCP sockets. This patch
adjusts the Finit hard coded default accordingly.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When starting an inetd service in verbose mode we print a progress
message to the console appended with "Connection". This patch simply
changes that to append with "connection" in lower case.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes several issues related to the problem of launching
UDP inetd services:
- Make sure to disable O_NONBLOCK on the socket before passing it to
the inetd service, that's what is expected. This goes for both UDP
and TCP (accepted) connections -- there is no guarantee even for TCP
sockets that they do *not* inherit the parent socket's flags.
- Mark the UDP inetd parent's SVC as busy and stop its watcher before
starting the child task to service the connection. The watcher must
be stopped or multiple child tasks may be spawned!
- Only copy the most relevant parts to the UDP task. In particular
must *not* copy the libuEv watcher data to the task!
- With the child task done and the parent inetd service unblocked we
must restore O_NONBLOCK to the socket before restarting the watcher
When a UDP inetd service connection is handled we create a child task
to service the request, meanwhile we block the parent service. There
was a problem with blocking the parent since we called inetd_stop(),
which both did a shutdown() and close() of the socket ... this patch
introduces separate handling of blocked (busy) inetd services in the
inetd_stop() function and also make sure to handle restarting the
parent watcher in inetd_start() when the child task is done.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Both the new initctl API and the new pidfile watcher plugin failed to
set CLOEXEC on their sockets. This caused forked-off and exec()'d
children to inherit all these descriptors.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch prevents too early start of services depending on other
services. E.g, if service B depends on A then we must wait for A to
signal that it is ready before we allow B to start -- in a Finit based
system A does this by creating, or touching (updating mtime), its PID
file. Services (like A) that support SIGHUP should call utime(), or
utimensat(), on the PID file at the end of their SIGHUP handler.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
When a service's condition transitions to `flux`, put it in the
waiting state, even if it does not support SIGHUP. That way, if the
condition returns to `on` we can simply SIGCONT it. If it goes to
`off` it will still be stop/started as before.
When reloading dynamic services, inetd services deleted marker was not
being cleaned. This caused finit to stop and start all inetd services
at every other reload.
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.
As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
During documentation of the state machine, some theoretical problems
where discovered that could have lead finit to spawn a new instance of
a daemon before the previous one had been collected.
Now a service will always go through the STOPPING state when leaving
RUNNING. This ensures that the PID has been collected before any calls
to service_start.
...documenting your work is, apparently, not a bad idea. :)
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
Parser would erroneously interpret an event specification containing
slashes as an inet service/proto specification.
E.g. "<net/gw>" was interpreted as port "<net" using protocol "gw>".
Stopped services are now (again) listed as "stopped" and halted
services, due to a runlevel change, are listed as "halted". Several
users complained that this change was just not intuitive. I agreee.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
By popular request, this patch adds support for querying status of a
single service. The syntax is similar to that of stop/start/reload.
Both `initctl show ...` and `initctl status ...` is supported.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When no services were stopped we must ensure to start/SIGHUP any new or
SIGHUP:able services as the last pass of the `initctl reload` cycle.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes a hang when performing a system reconfiguration using
`initctl reload`, `SIGHUP` or running `(f)init q`, which caused Finit
to wait for SIGHUP:able services to stop.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch reenables verbose mode at shutdown/reboot, if it was disabled
at boot. This allows the user to see the output from the `urandom.so`
and `hwclock.so` plugins at reboot.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The urandom.so plugin uncovered that `print_desc()` does not honor the
`verbose` flag. At runtime `print_desc()` et al should no be displaying
anyting when we finit operates in terse mode.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Leverage new svc_t states in initctl status/show output. Also, ensure
different svc_t types have correct start state.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
new postponed stop handling tried to reload already stopped and removed
services. We should of course skip already stopped services and halt
those that have been removed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>