Commit Graph
984 Commits
Author SHA1 Message Date
Robert Andersson 595e2b4e81 Ensure all filesystems listed in /proc/mounts are unmounted
The iterator function getmntent() is not stable. It may skip
entries if the contents of the iterated file changes, which
is the case with /proc/mounts when filesystems are unmounted.
As a result, some filesystems were never unmounted.

To fix this, iteratation is now restarted after every
sucessful unmount.

Signed-off-by: Robert Andersson <robert.m.andersson@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-08-30 10:16:00 +02:00
Joachim Wiberg 522a06f864 Merge pull request #181 from yangfl/typo
Fix typo
2021-06-25 07:43:08 +02:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg 64e41e066b Change default loglevel to LOG_INFO from LOG_NOTICE
We've had several logit() messages of LOG_INFO level that never
really made it to syslog because we classified it as "debug".

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg 2a71f35005 Reduce log level of watchdog handover, this is not an error condition
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg 961a337a5e Minor, we no longer know if it's an external or bundled getty
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg f0622a692e Minor, format style change of comment block
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg ef7042dd9d finit: early log, "entering runlevel S", just after printing banner
This patch adds "the missing" first runlevel log entry when Finit has
printed the console banner and begins its bootstrap phase.

At this point we know syslogd hasn't been started yet, so we rely on
logit() to redirect this to /dev/kmsg in the meantime.  Later syslogd
will pick this up, see that it's not from the kernel, and log it to
the proper log file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg 046ecfa329 Fix #180: user managed services started by initctl reload
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-14 13:16:14 +02:00
Joachim Wiberg 47fbe49861 Wrap all mount(2) calls so we at least get an error message
If any of these mount() calls fail, not counting EBUSY because that
would mean sth is already mounted, there really isn't much we can do.
So the least we should do is warn on console if it happens.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-14 11:20:08 +02:00
Joachim Wiberg 2f34315634 fnread(): make sure to NUL terminate buffer
Note, this is dead code, currently unsused in Finit.  Possibly an
external plugin makes use of it, but even that is highly unlikely.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-14 11:19:57 +02:00
Joachim Wiberg 97bebe52c9 Fix logic expression in release_heading(), found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-06 16:57:52 +02:00
Joachim Wiberg cdc8873f5b Let cond_update() return if any svc_t was affected
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-06 00:33:36 +02:00
Joachim Wiberg 39d879f240 Add support for auto-detetcing OS heading for progress
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY".  As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release.  It is now possible
to also disable the heading entirely using --without-heading

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-05 14:28:49 +02:00
Jacques de Laval 2f5c00f2bd Also accept \n for "Please press Enter to activate ..."
Shouldn't be needed for real cases, but we have seen automated scripts send
'\n' instead of '\r', or '\r' + '\n'.

Signed-off-by: Jacques de Laval <Jacques.De.Laval@westermo.com>
2021-06-04 13:20:14 +02:00
Joachim Wiberg dc36b313ff getty: attempt to steal ctty if don't already have it
This fixes the following classic problem

    login: root
    -sh: can't access tty; job control turned off

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-04 08:39:48 +02:00
Joachim Wiberg 093fa0107a getty: skip 5 sec delay introduced in 94c0d1b refactor
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-04 08:33:58 +02:00
Joachim Wiberg e8f5ec2579 Simplify, drop SYNC_SHUTDOWN state file, not needed anymore
Similar to 6224166 (previous commit), this old code is a remnant of a
bygone era and not needed anymore.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-03 12:51:59 +02:00
Joachim Wiberg 62241668df Drop SIGSTOP/TSTP/CONT handlers, not needed anymore
Once upon a time, SIGSTOP was used to pause Finit during flashing (MTD)
of a system image.  This to prevent Finit from accidentally starting any
programs, i.e., reading from flash disk during or after upgrade.

This was quite intrusive, and has possible nasty side effects, e.g., any
process with root access sends SIGSTOP prevents TTY login.  So this patch
now removes the functionality and recommends using a dedcicated runlevel
for such critical tasks instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-03 12:18:08 +02:00
Jacques de Laval ee67c08b64 Reset the starting flag of a service when stopping it
When a service is started and then stopped before it has created it's pid file,
it could be left forever in the "stopping" state, if we don't reset the
starting flag.

Signed-off-by: Jacques de Laval <Jacques.De.Laval@westermo.com>
2021-06-02 17:01:01 +02:00
Joachim Wiberg 41a14391a2 Refactor sigchld_cb(), handle EINTR properly, restart waitpid()
The waitpid() function can return -1 due to EINTR (signal), so we should
restart it to make sure we collect all zombies.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-02 16:34:24 +02:00
Joachim Wiberg 9867fd82df Check correct struct member to determine if / has 'ro' flag
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 12:50:48 +02:00
Joachim Wiberg 09b9e26b2d fs_init(): skip mounting proc/dev/sys if already mounted
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 17:35:07 +02:00
Joachim Wiberg d25c1d5564 logit: avoid modifying argv[] strings
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 17:03:10 +02:00
Joachim Wiberg d4358ed3f7 Drop nasty hide_args() hack, should not be needed anymore
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 16:51:08 +02:00
Joachim Wiberg cc6ffa35fc Drop parsing of /proc/cmdline by default, instead use argc + argv[]
For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program.  However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.

The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 16:51:08 +02:00
Joachim Wiberg 473116f603 Drop experimental multiple console output support
It has barely worked and only caused more problems than solved annoying
issues.  We have one console for output, /dev/console, which the kernel
sets up for us.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 10:48:37 +02:00
Joachim Wiberg e18d63df4a Always make sure to not acquire controlling TTY for output redirect
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 10:48:04 +02:00
Joachim Wiberg d1d5d39144 Fix possible NULL ptr deref, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 07:43:29 +02:00
Joachim Wiberg c24207516d keventd: properly zero terminate buffer, found by Coverity Scan
Also, fix default: case in error handling, must always continue back to
poll() on any recv() error.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 07:22:50 +02:00
Joachim Wiberg 2a23bce78d Hide progress output also on stop/shutdown for services w/o -- descr
Progress at startup has been hidden for services w/o -- description, but
for some reason this check was not added to service_stop().  This patch
rectifies the situation, finally.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 07:17:48 +02:00
Joachim Wiberg a19b82ea5f Allow tty's to always respawn, no max restart count
This patch adds a `respawn` flag for services and ttys, always set for
ttys, that allows bypassing the crash/restart counter and immediately
restart a 'crashing' service.

For tty type services this is the expected behavior, but for regular
services it is not.  That is why `respawn` flags is not advertised in
the docs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 06:29:11 +02:00
Joachim Wiberg ed9590aef1 Fix tty default :ID => tty:S0 instead of tty:ttyS0
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 06:27:59 +02:00
Joachim Wiberg 25683221cc Set default envs like sysvinit and busybox does; TERM, LOGNAME, USER
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 13:22:50 +02:00
Joachim Wiberg 9cc9e3ddbb getty: if we cannot execute /bin/login, try sulogin before /bin/sh
Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 12:42:48 +02:00
Joachim Wiberg 654f8aeb19 getty: handle variable number of arguments, only tty required
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:55:21 +02:00
Joachim Wiberg e349abb897 stty: allow utf8 input characters
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 3027a6755f Adjust logic in finding system consoles for progress/debug output
By default, Linux gives us /dev/console for output.  This is a pseudo
device that uses the same actual device as the last console=foo listed
in /proc/cmdline.  The last one listed is the main console, which is
also the *first* one listed in /sys/class/tty/console/active, so we skip
that when we check for system consoles to avoid duplicating output.

The getty code in tty.c currently has its own handling of @console,
which we keep for now.  Ideally, however, the code should be merged.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 5404aa6037 Refactor run_getty() and run_getty2() into one
By moving the built-in getty to a stand-alone bundled getty we can now
refactor the old run_getty() functions into a single one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg a319e32438 Clean up prepare_tty()
When TTYs became first class citizens in Finit 4.0 much of the
boilerplate setup is now down by service_start().  Also, the calls to
TIOCSCTTY, VINTR, and SIGINT ignore is not necessary to do here, it
should be done by the getty used, if any.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 2eaf57fc67 stty: simplify and ignore BREAK/SIGINT
It is up to /bin/login, sulogin, or plain shells to unblock SIGINT.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 88ec4a55cb Call setsid() before redirecting stdio or unblocking signals
We must detach from the controlling TTY before enabling signals and
setting up new stdio.  TTYs have their own handling of stdio.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 0acbc60ec1 initctl: drop confusing 'errno 0' from "Timed out" message
errno is not set when we timeout waiting for a reply from Finit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 4362971c6a run(): Drop extra sig_unblock()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 94c0d1b833 Refactor built-in getty into a standalone getty in /libexec
This patch moves the built-in getty out of Finit into /libexec/finit/,
reducing the size of the Finit binary and simplifying the code.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 1e795d4e16 Fix #175: Ensure finit does not acquire 'dev' as controlling TTY
When starting a getty Finit checks first that the configured TTY device
actually exists and is a TTY.  This patch, by Tobias Waldekranz, ensures
Finit (PID 1) doesn't acquire the TTY device as a controlling TTY.  If
that happens PID 1 will get all signals sent to the process actually
started with the device as its controlling TTY.

Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 00:33:31 +02:00
Joachim Wiberg 5f3958fab4 getty: max username is 32 chars, according to useradd(1)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-27 11:18:06 +02:00
Joachim Wiberg 1351b708fe Fix parse error for detecting external getty
When an external getty is used, and an absolute path is not given, the
parser tried to use access() to determine built-in vs external getty.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-27 11:18:06 +02:00
Joachim Wiberg e867e039bb Follow-up, document SIGINT/SIGPWR in comment, add missing include
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-27 11:18:06 +02:00
Jacques de Laval e91f1ea1b2 logging: Disregard logging facility when comparing log levels
If we don't extract the level (disregarding facility), statements such as
"logit(LOG_CONSOLE | LOG_NOTICE, ...)" would never reach the kernel log.

Signed-off-by: Jacques de Laval <Jacques.De.Laval@westermo.com>
2021-05-20 17:19:53 +02:00