Commit Graph
155 Commits
Author SHA1 Message Date
Joachim Wiberg 41319a8cf8 Work around forbidden chars in wordexp(): | < > & ;
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-26 14:54:34 +01:00
Joachim Wiberg 74d3194775 Follow-up to f4a0b99: track modifications of service env: files
Add support for monitoring environment files for services declared with
the `env:[-]/path/to/file` option.  The default path to such files has
been chosen to follow Debian and Buildroot /etc/default/*

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:14:26 +01:00
Joachim Wiberg 3d9ee49759 Follow-up to 6cdcacf, fix minor regression, premature clear of pid
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:23:45 +01:00
Joachim Wiberg 477b50b7a6 Check return value from kill(pid, SIGHUP), maybe lost pid
This patch handles a corner case when Finit may not have detected a
supervised process has died.  When a user calls `initctl restart foo`
we now send such lost PIDs to the service_monitor() for restart.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 23:58:25 +01:00
Joachim Wiberg 6cdcacf20b Refactor, shared cleanup fn for service_kill() and service_monitor()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 23:45:14 +01:00
Joachim Wiberg d37c20f467 Terminate children in the same process group when monitored PID dies
Really kill them, our monitored process may be about to restart, so we
don't want any unintended side effects from lingering children in prior
instances.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 23:43:03 +01:00
Joachim Wiberg 14f0443bd7 Allow services to be added *and removed* from /etc/finit.conf
This patch fixes a long standing issue where removing a service from
/etc/finit.conf does not stop and unregister it.  The issue was caused
by the Finit support for "protected" services, e.g. services created
by plugins like hotplug.so

To reproduce issue before this fix:

    cat /etc/finit.d/available/ntpd.conf >> /etc/finit.conf
    initctl reload

The NTP service now runs smoothly, as expected.  Later on, we decide to
drop it from our system:

    sed -i 1,2d /etc/finit.conf
    initctl reload

... and the NTP service continues to run unaffected.  Not what most sane
users expect.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Joachim Wiberg f4a0b99df8 Fix #155: add support for env:/a/bc to service/run/task
This patch makes it possible to create a service with optional
arguments, similar to the systemd EnvironmentFile= setting.

The major difference to systemd, is that Finit does not attempt
to start a service if it cannot find the env. file, unless it
is prefixed with '-'.

Example:

    /etc/default/syslogd:
    SYSLOGD_OPTS="-m0 -r 128k:10 -s"

    /etc/finit.d/enabled/syslogd.conf
    service env:-/etc/default/syslogd syslogd -F $SYSLOGD_OPTS

Only downside, right now, is that changing the contents of the file
/etc/default/syslogd does not mark the syslogd.conf as modified and
a subsequent `initctl reload` will *not* restart syslogd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-22 16:18:22 +01:00
Joachim Wiberg 97a0baaf93 Fix regression introduced in 13893b9
The refactor in 13893b9 caused a regression in composing service
arguments.  This patch should rectify that.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-21 00:57:21 +01:00
Joachim Wiberg dda59503ac Refactor, drop #ifdefs and logger fallback, probe for logit
Simplify log redirection, probe for logit early and fall back to
use a while-loop of syslog() instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-17 13:00:58 +01:00
Magnus Malm 4d4fd40286 Follow-up to 72a892e, Add missing '/'
Signed-off-by: Magnus Malm <magnusmalm@gmail.com>
2021-02-17 11:46:39 +01:00
Joachim Wiberg 27aa7ad1e1 Follow-up to 72a892e, fix string concatenation
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-17 11:41:49 +01:00
Magnus Malm 72a892ef55 Fix #151: Install logit in libexec
Signed-off-by: Magnus Malm <magnusmalm@gmail.com>
2021-02-17 11:33:48 +01:00
Joachim Wiberg 13893b9f32 Refactor, simplify command + args composition for readability
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-17 11:06:46 +01:00
Jacques de Laval 06aea7d3f3 Keep logit alive until stdin is closed
By not putting logit in the same process group as the service whose
output is consumed by logit, we can send signals to the service,
and it's group, without affecting logit. This means that logit will
continue to log away until it's stdin is closed, which will happen
when the service is reaped.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-17 00:00:50 +01:00
Jacques de Laval 703ae0caf3 Avoid lingering stdout fd logit process
Delay duplication of stdout/stderr until after forking a logit
process, otherwise we'd have a ligering reference to stdout/stderr.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-17 00:00:37 +01:00
Joachim Wiberg 272db0d41d Use fallback to syslog if logit tool is not installed
In the case of redirect to a logfile, if logit tool is not enabled,
then log to syslog instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-15 08:00:24 +01:00
Joachim Wiberg 35e4e0d073 Drop confusing splash cmdline and --enable-progress configure option
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer.  The
resulting code and configure script is a lot simpler to understand and
maintain:

- No more --enable-progress or --enable-progress-classic configure
  flags.  Instead a progress_style variable in helpers.c that can
  be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option.  This turned out to
  be *very* confusing to many users who believed it was some sort of
  graphical splash screen à la Plymouth.

Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:08 +01:00
Joachim Wiberg 5fbcf6814c Warn if a new service asserts the same condition as an existing one
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-13 12:07:20 +01:00
Joachim Wiberg eb6ac5ee22 Fix service state transition regression introduced in e88a9b1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 17:01:08 +01:00
Joachim Wiberg e88a9b14ff Fix #101: remove built-in inetd from finit
This patch removes the built-in inetd support from Finit.  We recommend
using an external inetd instead, e.g. xinetd.

If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it.  We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.

So long for now, old friend.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 12:46:40 +01:00
Joachim Wiberg 3e9c170e6b Refactor syslog output from ca210f5 to new canonical format
From, e.g.,

	Starting foo:, PID: 123
to
	Starting foo[123]

or, when an ID has been given

	Starting foo:id[123]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 07:55:25 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg a8b113185d Major change, rename <svc/...> conditions to <pid/...> conditions
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation.  Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.

However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit.  To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.

Connecting the dots between these wasn't obvious.

This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser.  Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 82664396d6 Refactor 3e8d63c: use consoles from /sys/class/tty/console/active
As documented in the kernel docs and systemd[1], the default system
console is the first listed in /sys/class/tty/console/active, which
is the reverse order of console= given on the kernel cmdline.

Some distros don't have console= on their default command line in
their bootloader, e.g. Alpine Linux, some multiple, e.g Buildroot.
Instead of relying on the value given at configure time we probe
sysfs and open all (at most three) consoles listed.  This way we
at least get the default console for our progress output.

- drop old --with-console from configure script
- drop /proc/cmdline fishing in favor of sysfs
- replace CONSOLE from configure with new console()

[1]: http://0pointer.de/blog/projects/serial-console.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-08 20:09:49 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson c0b74c5e53 Fix minor build warning for --disable-inetd
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 18:06:25 +02:00
Joachim Nilsson 88a6864fd4 Relocate docs/ --> doc/, like most other projects have
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 17:53:36 +02:00
Joachim Nilsson 8fe4aad53e Make run/task/service :ID optional, default to zero/NULL
This patch makes the ':ID' field optional when registering non-inetd
run/taks/service etc.  It has always been optional in the .conf files,
but internally we defaulted to ':1'.

To open up for more useful conditions we now default to zero/NULL :ID,
meaning the user now *must* keep track of the :ID field if they have
multiple services with the same name.  This should already have been
an issue since such services would likely have conflicted with their
PID files (same name).  So it's unlikely to affect any user severely.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 15:21:28 +02:00
Joachim Nilsson b0a1d6bd61 Fix warning message when service doesn't exist: !. -> .
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 21:15:48 +02:00
Joachim Nilsson af45166814 src: Add critical debug messages for debugging condition handling
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 21:15:48 +02:00
Joachim Nilsson 770a79fa89 Fix #120: Redirect stdin to /dev/null for services by default
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-11 22:24:33 +02:00
Joachim Nilsson ff24ee3553 Fix #124: reap all children in same process group of dying parent
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-11 21:55:40 +02:00
Joachim Nilsson 25c194ef93 Create unique service cgroup based on name:id
We want to have unique cgroups per instance.  I.e., a DHCP client for
eth0 should have its own cgroup separate from a DHCP client for eth1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-11 21:50:38 +02:00
Joachim Nilsson 91a9c83928 Send signal to every process in the same process group
When stopping a run/task/service we must send SIGTERM/KILL to all every
process in the same process group.  Otherwise we may end up with stray
processes like 'logit' when log redirection is enabled.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-08 18:00:48 +02:00
Joachim Nilsson bf6e599584 Handle log redirect to syslog when logit is disabled
`--disable-logit` at configure time means redirecting stdout from a
service to a file is completely disabled.  Fallback to `logger` can
not be guaranteed to provide log file rotation, so all logs will be
sent to syslog instead.  In case logger is also missing, a simple
redirect using fork() + syslog() is used as fallback.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-03-30 11:53:43 +02:00
Joachim Nilsson 89c7171223 Refactor run/task/service stdout redirection after setsid() addition
This patch refactors redirect_null() and adds support for redirecting
stdout to console when 'log:console' is enabled.  This was previously
sort of the default, but with the addition of the long-sought-after
setsid() call we needed to change things.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-03-30 10:11:29 +02:00
Joachim Nilsson c41f3f4a06 Call setsid() by default to detach from controlling terminal
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-03-29 17:39:35 +02:00
Joachim Nilsson 0ad99ce054 Fix use-after-close in service.c:redirect(), found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:42:53 +01:00
Joachim Nilsson 54cfa74042 Fix #109: Support PID files in subdirectories to /var/run
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,

   - /var/run/teamd/a1.pid    -- For aggregate A1
   - /var/run/dbus/pid
   - /var/run/lxc/foo.pid     -- For container foo

This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).

To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax.  This pid file name
is also used to create the condition this service asserts using the
following formula:

   svc/ + <dirname of service> + <subdir and file without .pid>

E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'

The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory.  It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid.  Matching files follow the teamd
case.  The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'

One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo.  The service stanza:

   service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo

This command has no leading path so the condition is composed entirely
from the PID file location:

   svc/  + '' + lxc/foo => svc/lxc/foo

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:39:53 +01:00
Joachim Nilsson 97ce0aa519 Rename local variable shadowing variable in outer scope
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 14:36:14 +01:00
Joachim Nilsson b66069278f Support for a custom kill:DELAY, default 3 sec
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 18:49:47 +01:00
Joachim Nilsson 1192506d43 Support for custom halt:signal, default SIGTERM
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 18:28:02 +01:00
Joachim Nilsson decdc1560a Support for monitoring forking services/sysv daemons
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 14:10:47 +01:00
Joachim Nilsson 6ab9c8fad6 Allow services to be started without absolute path, trust $PATH
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:39:17 +01:00
Joachim Nilsson 619bd03551 Drop old comment related to service plugins (now removed)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:38:50 +01:00
Joachim Nilsson 3b67afe480 Change semantics for SysV start/stop scripts
If a start/stop script returns OK we classify it as 'started' and leave
it in running state, despite having collected its PID.  This way we can
track what scripts need to be called with 'stop' when changing to a
runlevel they are not declared for.

Also, clean up related debug messages from earlier commit.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:35:15 +01:00
Joachim Nilsson 9a9a9f4bfe Remove old blocking (!) waitpid() call in service_start()
Remnant from when processes were collected in service_start(), now all
handled by service_monitor() from SIGCHLD and service_step().

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:32:04 +01:00
Joachim Nilsson f38299bfca Redirect stdout/stderr according to .conf when stopping SysV service
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:31:21 +01:00
Joachim Nilsson 99901782ff Factor out stdout/stderr redirection to from service_start()
This new function can then be used also by service_stop(), e.g. for SysV
start/stop scripts.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:30:00 +01:00