Do not tag log messages with service description, but use process name.
Possibly add :ID later to denote instance if multiple instances exist.
Also, add priority daemon.info log level.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds protection against a common inetd attack vector wherein
the reply port to UDP inetd services is forged to an internal inetd
service port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Libraries and system headers should be included with <> instead of "".
This makes a great difference for the automatic dependency tracking.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Make sure to check return value of remove(), it may actually signal
something useful. Log useful errors.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
- Must check return value from open(), found by Coverity Scan
- Minor refactor (and cleanup) to reduce code complexity
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When a service changes type from inetd to a regular daemon we must make
sure to first deregister the currently running inetd service properly.
Example: a system boots up with httpd.conf as an inetd service, so Finit
opens a socket 0.0.0.0:80 pending connections to start `httpd -i`.
After a while a user changes httpd.conf to be a regular service and
calls `initctl reload`. Without this patch the socket will remain
open and prevent httpd from opening and binding to the same port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Adds an extra 'log' parameter to services that routes STDOUT and STDERR to syslog.
Uses a PTY rather than a pipe, as this prevents log messages hanging around in a buffer indefinitely.
In service_start() the SIGCHLD handler is reenabled before calling complete(), so the service could be reaped by the SIGCHLD handler leaving service_start() waiting forever
Also remove code that duplicates sig_unblock()
This patch replaces the verbose and kernel-quiet runtime options with
a (hopefully) more useful quiet and silent modes of operation.
By default Finit progressively shows all services it starts at boot, but
when boot has completed and services are started/restarted Finit prints
nothing. If `--disable-quiet` is given all started/restared/stoppping
messages are shown even after boot.
However, if `--enable-silent` is given Finit is completely silent even
at boot, no progress is shown, until the first service is started, which
on most systems is login.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch prevents too early start of services depending on other
services. E.g, if service B depends on A then we must wait for A to
signal that it is ready before we allow B to start -- in a Finit based
system A does this by creating, or touching (updating mtime), its PID
file. Services (like A) that support SIGHUP should call utime(), or
utimensat(), on the PID file at the end of their SIGHUP handler.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for the runtime `HOOK_SVC_LOST` and the (very
noisy) *example* plugin `lost.so`.
Customer request.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
To distinguish between variables and functions in comments Finit use ()
at the end of function names.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
When a service's condition transitions to `flux`, put it in the
waiting state, even if it does not support SIGHUP. That way, if the
condition returns to `on` we can simply SIGCONT it. If it goes to
`off` it will still be stop/started as before.
When reloading dynamic services, inetd services deleted marker was not
being cleaned. This caused finit to stop and start all inetd services
at every other reload.
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.
As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
During documentation of the state machine, some theoretical problems
where discovered that could have lead finit to spawn a new instance of
a daemon before the previous one had been collected.
Now a service will always go through the STOPPING state when leaving
RUNNING. This ensures that the PID has been collected before any calls
to service_start.
...documenting your work is, apparently, not a bad idea. :)
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
Parser would erroneously interpret an event specification containing
slashes as an inet service/proto specification.
E.g. "<net/gw>" was interpreted as port "<net" using protocol "gw>".
When no services were stopped we must ensure to start/SIGHUP any new or
SIGHUP:able services as the last pass of the `initctl reload` cycle.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes a hang when performing a system reconfiguration using
`initctl reload`, `SIGHUP` or running `(f)init q`, which caused Finit
to wait for SIGHUP:able services to stop.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Leverage new svc_t states in initctl status/show output. Also, ensure
different svc_t types have correct start state.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
new postponed stop handling tried to reload already stopped and removed
services. We should of course skip already stopped services and halt
those that have been removed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>