For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program. However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.
The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Before 4e5d06b the only way to go into rescue mode was to skip certain
steps and then attempt to load /lib/finit/rescue.conf. After 4e5d06b
we keep the old handling as a fallback in case early sulogin fails.
The new tty option 'rescue' is added, which recue.conf is updated with.
This option implies notty mode and will try sulogin (again) before it
falls back to start /bin/sh as a login shell.
The reason we keep this is to be able to handle all possible use-cases
and also allow sysadmins to set up the behavior that fits their needs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch re-enables the fallback shell handling after the big TTY
refactor. We do this by allowing the fallback shell to run as a
regular service.
Note: this also adds the "hidden" support for 'notty' option for
tty configurations stanzas. This is just to pick up from
where the kernel left us, reusing stdin + stdout.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Initial refactor of the tty implementation to use the service/run/task
general backend. This enables all the features of services also for
ttys, except logging because it makes no sense.
Work in progress:
- plugins/tty.c does not work anymore, could possibly be removed in
favor of usinga (a new) condition instead (if-tty-exists)
- fallback tty does not work anymore, should we remove it, or can we
handle it as an optional built-in with (a new) condition?
- @console does not work anymore, needs to generate N cloned services
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The main purpose of this patch is to remove top-level cgroups when they
are remvoed from finit.conf. However, this is tricky, becasue there may
still be supervised services (and children of them) running. We must
postpone removal until a cgroup.events change. To make matters worse,
events may arrive out-of-order, i.e. the last-child event for the parent
cgroup before the sub-group.
A spin-off from this patch is that we can now support arbitrarily long
group names and group config. (Only applies to top-level cgroups, not
run/task/services.)
Limitations:
- Processes in "removed" cgroups are not migrated/orphaned, the reasons
are several: overhead and complexity and the fact that memory cannot
be migrated
- A lingering child of a moved service may prevent an old top-level
cgroup from being removed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
No need to zero out whole buffer for strlcat(), or other string check
ops. Also drop a few completely useless memset() calls.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.
Services can now be assigned to a cgroup, with optional extra settings
for that particular process group. The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.
cgroup maint cpu.weight:123,mem.max:10000
Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.
cgroup.maint
service foo
service bar cgroup:mem.max:1000
This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.
NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When reloading we check if service .conf files have been modified since
the last time we read them. In 3bb1e41 we changed it so we load only
the enabled/*.conf files, which led to our no longer properly detecting
changed files since we monitor changes in what the symlinks point to.
This patch fixes that by checking the target for changes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In debug mode it's highly confusing to see Finit load available/*.conf
files when you expect it to only load finit.conf and enabled/*.conf,
so let's keep the dangling symlink check to itself and actually load
and parse from enabled/ as it was intended :)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Provided a configuration that looks like this:
ospfd.conf:
service [2345] <!pid/zebra> log ospfd -A 127.0.0.1 -u root -g root -- OSPF daemon
zebra.conf:
service [2345] <!> log zebra -A 127.0.0.1 -u root -g root -- Zebra Routing daemon
If zebra.conf is changed, we restart it when `initctl reload` is issued.
This change ensures that ospfd is also restarted, because ospfd depends
on zebra, we must restart it too.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fix ev->len validation; must check against sz read(), not total buffer
size. Also, fix off-by-one in comparison.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
While skimming through the results of the latest Coverity Scan, I
discovered that that the reset logic of global rlimits was broken.
This it seems to have been since its first introduction in Finit.
We fix this by reading initial rlimits at bootstrap, then for each
reconf, including the first, we seed global rlimits with the initial
ones -- thus resetting between each reconf.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Both Debian and Builroot based systems use /etc/default and
Alpine Linux use /etc/conf.d, so let's just put both in by
default. If the directories exist we monitor them.
The --with-syconfig configure option is now disabled by default.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The module setting is deprecated, other mechanisms exist. This change
is to ensure we don't try to (re)load any modules at runtime, only at
bootstrap.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch collapses the two similar functions parse_conf() and
parse_conf_dynamic() into a single function. It also lifts old
restrictions on what config stanzas are allowed in /etc/finit.d
The only remaining restriction is the global rlimits, they remain
as the last setting only possible to define /etc/finit.conf which
then applies to all other services.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Services that are instantiated by plugins, and thus don't have a .conf
file, tried to use uninitialized rlimits. This caused the kernel to
immediately kill those services for violating their own rlimits.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add support for monitoring environment files for services declared with
the `env:[-]/path/to/file` option. The default path to such files has
been chosen to follow Debian and Buildroot /etc/default/*
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Use iwatch, modeled after pidfile plugin
- Use one .conf watcher for all *.conf paths/files
- Use full path of conf file for changes, from realpath().
This fixes a long-standing limitation on unique filenames
for services, that absolutely nobody knew about
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes a long standing issue where removing a service from
/etc/finit.conf does not stop and unregister it. The issue was caused
by the Finit support for "protected" services, e.g. services created
by plugins like hotplug.so
To reproduce issue before this fix:
cat /etc/finit.d/available/ntpd.conf >> /etc/finit.conf
initctl reload
The NTP service now runs smoothly, as expected. Later on, we decide to
drop it from our system:
sed -i 1,2d /etc/finit.conf
initctl reload
... and the NTP service continues to run unaffected. Not what most sane
users expect.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The tzset() function sets the global variables 'daylight', 'timezone' and 'tzname'
according to the value of the TZ environment variable, or to the value of the
_CS_TIMEZONE configuration string if TZ isn't set, or to UTC0 if neither is set.
Signed-off-by: Andreas Egeberg <andreas.egeberg@gmail.com>
Modeled after systemd.show_status, currently without the 'auto' setting.
- finit.debug[=bool]
- finit.show_status[=bool]
- finit.status_style[=old,classic,new,modern]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer. The
resulting code and configure script is a lot simpler to understand and
maintain:
- No more --enable-progress or --enable-progress-classic configure
flags. Instead a progress_style variable in helpers.c that can
be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option. This turned out to
be *very* confusing to many users who believed it was some sort of
graphical splash screen à la Plymouth.
Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch removes the built-in inetd support from Finit. We recommend
using an external inetd instead, e.g. xinetd.
If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it. We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.
So long for now, old friend.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Change service conditions from the non-obvious <svc/path/to/foo> to
<pid/foo:id>, utilizing the unique name of the service instead of the
weird composition of paths from /run and PID file names. Hopefully
making it more clear that one service's pidfile is another service's
`<pid/foo>` condition.
Note: this is an incompatible change to the condition system!
The Finit major version will be stepped to indicate this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation. Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.
However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit. To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.
Connecting the dots between these wasn't obvious.
This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser. Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
As documented in the kernel docs and systemd[1], the default system
console is the first listed in /sys/class/tty/console/active, which
is the reverse order of console= given on the kernel cmdline.
Some distros don't have console= on their default command line in
their bootloader, e.g. Alpine Linux, some multiple, e.g Buildroot.
Instead of relying on the value given at configure time we probe
sysfs and open all (at most three) consoles listed. This way we
at least get the default console for our progress output.
- drop old --with-console from configure script
- drop /proc/cmdline fishing in favor of sysfs
- replace CONSOLE from configure with new console()
[1]: http://0pointer.de/blog/projects/serial-console.html
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some targets, like Raspberry Pi, have both serial and HDMI console
enabled. Depending on the order of arguments on the kernel cmdline
either one were selected the default 'stderr', which finit used.
This patch adds support for parsing the console= string(s) and
opening multiple outputs for system startup/progress. In the
end, however, a getty still needs to be started on each of the
consoles to use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Up until now Finit has only read /proc/cmdline to determine debug level,
single user mode, etc. This patch is one in a series to make enable it
to run also in containers.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds initial support for starting a SysV init script in a
runlevel, and stopping it when leaving a runlevel.
sysv [LVLS] <COND> /path/to/script.sh -- Optional Description
The SysV /etc/inittab file, which may use /etc/init.d, or /etc/rcN.d,
is still not supported. A separate plugin would be required for this,
see the documentation for more information.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>