Commit Graph
95 Commits
Author SHA1 Message Date
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg d4358ed3f7 Drop nasty hide_args() hack, should not be needed anymore
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 16:51:08 +02:00
Joachim Wiberg cc6ffa35fc Drop parsing of /proc/cmdline by default, instead use argc + argv[]
For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program.  However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.

The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 16:51:08 +02:00
Joachim Wiberg 679b4df881 Fallback rescue mode handling
Before 4e5d06b the only way to go into rescue mode was to skip certain
steps and then attempt to load /lib/finit/rescue.conf.  After 4e5d06b
we keep the old handling as a fallback in case early sulogin fails.

The new tty option 'rescue' is added, which recue.conf is updated with.
This option implies notty mode and will try sulogin (again) before it
falls back to start /bin/sh as a login shell.

The reason we keep this is to be able to handle all possible use-cases
and also allow sysadmins to set up the behavior that fits their needs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:10:42 +02:00
Joachim Wiberg 7f76202865 Simplify, drop --enable-fallback-shell from configure script
Recommend using `notty` option in tty stanza instead.  See the updated
docs for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 23:13:19 +02:00
Joachim Wiberg c0368d2b16 Refactor fallback shell handling, run as regular service
This patch re-enables the fallback shell handling after the big TTY
refactor.  We do this by allowing the fallback shell to run as a
regular service.

Note: this also adds the "hidden" support for 'notty' option for
      tty configurations stanzas.  This is just to pick up from
      where the kernel left us, reusing stdin + stdout.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg a50bc331db Fix possible string truncation, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-10 15:56:44 +02:00
Joachim Wiberg a42a789d29 Refactor, clean up removed top-level cgroups
The main purpose of this patch is to remove top-level cgroups when they
are remvoed from finit.conf.  However, this is tricky, becasue there may
still be supervised services (and children of them) running.  We must
postpone removal until a cgroup.events change.  To make matters worse,
events may arrive out-of-order, i.e. the last-child event for the parent
cgroup before the sub-group.

A spin-off from this patch is that we can now support arbitrarily long
group names and group config.  (Only applies to top-level cgroups, not
run/task/services.)

Limitations:
 - Processes in "removed" cgroups are not migrated/orphaned, the reasons
   are several: overhead and complexity and the fact that memory cannot
   be migrated
 - A lingering child of a moved service may prevent an old top-level
   cgroup from being removed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 17:49:55 +02:00
Joachim Wiberg c0716d7f63 Minor optimization, drop expensive memset() ops
No need to zero out whole buffer for strlcat(), or other string check
ops.  Also drop a few completely useless memset() calls.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:41 +02:00
Joachim Wiberg 665d212bd6 Add support for configuring cgroups and their settings on services
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.

Services can now be assigned to a cgroup, with optional extra settings
for that particular process group.  The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.

   cgroup maint cpu.weight:123,mem.max:10000

Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.

    cgroup.maint
    service foo
    service bar cgroup:mem.max:1000

This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.

NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-30 10:21:01 +02:00
Joachim Wiberg bda4da71a6 Fix touch-reload regression from 3bb1e41
When reloading we check if service .conf files have been modified since
the last time we read them.  In 3bb1e41 we changed it so we load only
the enabled/*.conf files, which led to our no longer properly detecting
changed files since we monitor changes in what the symlinks point to.

This patch fixes that by checking the target for changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-29 23:15:36 +02:00
Joachim Wiberg 3bb1e41394 Only check for dangling symlinks, load enabled/*.conf file
In debug mode it's highly confusing to see Finit load available/*.conf
files when you expect it to only load finit.conf and enabled/*.conf,
so let's keep the dangling symlink check to itself and actually load
and parse from enabled/ as it was intended :)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-20 14:40:11 +01:00
Joachim Wiberg e437379939 Minor, style/clarify debug messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-20 14:39:49 +01:00
Joachim Wiberg e8b942cf95 Fix regression in starting built-in services, introduced in 5b9d990
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 16:28:16 +01:00
Joachim Wiberg 4d05bf9359 Mark affected services as dirty if their rdeps are dirty
Provided a configuration that looks like this:

ospfd.conf:
    service [2345] <!pid/zebra> log ospfd -A 127.0.0.1 -u root -g root -- OSPF daemon

zebra.conf:
    service [2345] <!> log zebra -A 127.0.0.1 -u root -g root -- Zebra Routing daemon

If zebra.conf is changed, we restart it when `initctl reload` is issued.

This change ensures that ospfd is also restarted, because ospfd depends
on zebra, we must restart it too.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 14:52:19 +01:00
Joachim Wiberg 35b200d3a9 Validate inotify event against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 6011f91f22 Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 11:16:37 +01:00
Joachim Wiberg 5b9d99011b Fix long-standing bug in reset of rlimits between reconf
While skimming through the results of the latest Coverity Scan, I
discovered that that the reset logic of global rlimits was broken.
This it seems to have been since its first introduction in Finit.

We fix this by reading initial rlimits at bootstrap, then for each
reconf, including the first, we seed global rlimits with the initial
ones -- thus resetting between each reconf.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:44:01 +01:00
Joachim Wiberg 9d949c4186 Fix possible NULL ptr deref in cmdline option parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:21:58 +01:00
Joachim Wiberg 63033d7dcf Drop developer debug message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-02 20:23:43 +01:00
Joachim Wiberg 6862d7cd5f Refactor --with-sysconfig, default to /etc/default and /etc/conf.d
Both Debian and Builroot based systems use /etc/default and
Alpine Linux use /etc/conf.d, so let's just put both in by
default.  If the directories exist we monitor them.

The --with-syconfig configure option is now disabled by default.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 09:53:48 +01:00
Joachim Wiberg f8c07e81ff Reclassify module as BOOTSTRAP only, including minor refactor
The module setting is deprecated, other mechanisms exist.  This change
is to ensure we don't try to (re)load any modules at runtime, only at
bootstrap.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 09:24:04 +01:00
Joachim Wiberg 270512bc97 Refactor, collapse parse_conf() and parse_conf_dynamic()
This patch collapses the two similar functions parse_conf() and
parse_conf_dynamic() into a single function.  It also lifts old
restrictions on what config stanzas are allowed in /etc/finit.d

The only remaining restriction is the global rlimits, they remain
as the last setting only possible to define /etc/finit.conf which
then applies to all other services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 08:38:41 +01:00
Joachim Wiberg 6b7255fdeb Fix regression introduced in 7ef25ab, global rlimits not initialized
Services that are instantiated by plugins, and thus don't have a .conf
file, tried to use uninitialized rlimits.  This caused the kernel to
immediately kill those services for violating their own rlimits.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-26 09:11:56 +01:00
Joachim Wiberg 064d124e19 Refactor, add new helper fn paste() to concat directory compoents
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:41:39 +01:00
Joachim Wiberg 74d3194775 Follow-up to f4a0b99: track modifications of service env: files
Add support for monitoring environment files for services declared with
the `env:[-]/path/to/file` option.  The default path to such files has
been chosen to follow Debian and Buildroot /etc/default/*

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:14:26 +01:00
Joachim Wiberg 7ef25abecf Refactor, use new iwatch module for inotify of Finit *.conf files
- Use iwatch, modeled after pidfile plugin
- Use one .conf watcher for all *.conf paths/files
- Use full path of conf file for changes, from realpath().
  This fixes a long-standing limitation on unique filenames
  for services, that absolutely nobody knew about

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:28:03 +01:00
Joachim Wiberg 14f0443bd7 Allow services to be added *and removed* from /etc/finit.conf
This patch fixes a long standing issue where removing a service from
/etc/finit.conf does not stop and unregister it.  The issue was caused
by the Finit support for "protected" services, e.g. services created
by plugins like hotplug.so

To reproduce issue before this fix:

    cat /etc/finit.d/available/ntpd.conf >> /etc/finit.conf
    initctl reload

The NTP service now runs smoothly, as expected.  Later on, we decide to
drop it from our system:

    sed -i 1,2d /etc/finit.conf
    initctl reload

... and the NTP service continues to run unaffected.  Not what most sane
users expect.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Jacques de Laval 51fe974ee5 Use FINIT_RCSD instead of hard coded value
Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-24 18:58:05 +01:00
Joachim Wiberg 27a4c8cd9a Follow-up to 70ca64a, handle missing bool argument to cmdnline opts
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-21 01:06:02 +01:00
Andreas Egeberg 65f25756bf Fix #139: System timezone changes does not 'take' in Finit
The tzset() function sets the global variables 'daylight', 'timezone' and 'tzname'
according to the value of the TZ environment variable, or to the value of the
_CS_TIMEZONE configuration string if TZ isn't set, or to UTC0 if neither is set.

Signed-off-by: Andreas Egeberg <andreas.egeberg@gmail.com>
2021-02-15 12:38:20 +00:00
Joachim Wiberg 70ca64a392 New cmdline options to control debug and progress/status
Modeled after systemd.show_status, currently without the 'auto' setting.

- finit.debug[=bool]
- finit.show_status[=bool]
- finit.status_style[=old,classic,new,modern]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:45 +01:00
Joachim Wiberg 35e4e0d073 Drop confusing splash cmdline and --enable-progress configure option
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer.  The
resulting code and configure script is a lot simpler to understand and
maintain:

- No more --enable-progress or --enable-progress-classic configure
  flags.  Instead a progress_style variable in helpers.c that can
  be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option.  This turned out to
  be *very* confusing to many users who believed it was some sort of
  graphical splash screen à la Plymouth.

Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:08 +01:00
Joachim Wiberg e88a9b14ff Fix #101: remove built-in inetd from finit
This patch removes the built-in inetd support from Finit.  We recommend
using an external inetd instead, e.g. xinetd.

If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it.  We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.

So long for now, old friend.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 12:46:40 +01:00
Joachim Wiberg d1fac6f5b3 Fix #143: redesign condition subsystem
Change service conditions from the non-obvious <svc/path/to/foo> to
<pid/foo:id>, utilizing the unique name of the service instead of the
weird composition of paths from /run and PID file names.  Hopefully
making it more clear that one service's pidfile is another service's
`<pid/foo>` condition.

Note: this is an incompatible change to the condition system!
      The Finit major version will be stepped to indicate this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 07:58:06 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg a8b113185d Major change, rename <svc/...> conditions to <pid/...> conditions
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation.  Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.

However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit.  To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.

Connecting the dots between these wasn't obvious.

This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser.  Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 82664396d6 Refactor 3e8d63c: use consoles from /sys/class/tty/console/active
As documented in the kernel docs and systemd[1], the default system
console is the first listed in /sys/class/tty/console/active, which
is the reverse order of console= given on the kernel cmdline.

Some distros don't have console= on their default command line in
their bootloader, e.g. Alpine Linux, some multiple, e.g Buildroot.
Instead of relying on the value given at configure time we probe
sysfs and open all (at most three) consoles listed.  This way we
at least get the default console for our progress output.

- drop old --with-console from configure script
- drop /proc/cmdline fishing in favor of sysfs
- replace CONSOLE from configure with new console()

[1]: http://0pointer.de/blog/projects/serial-console.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-08 20:09:49 +01:00
Joachim Wiberg 3e8d63c29c Support for multiple (3) console= on kernel cmdline
Some targets, like Raspberry Pi, have both serial and HDMI console
enabled.  Depending on the order of arguments on the kernel cmdline
either one were selected the default 'stderr', which finit used.

This patch adds support for parsing the console= string(s) and
opening multiple outputs for system startup/progress.  In the
end, however, a getty still needs to be started on each of the
consoles to use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-07 13:15:46 +01:00
Tobias Waldekranz e558d5871b Move argument-hiding magic together with argument parsing
Everything else Finit does related to parsing the incoming arguments
is in conf.c, so it makes sense for this block to also reside there.
2020-10-12 13:09:41 +02:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson fdead062cd Support reading --debug et al from process command line
Up until now Finit has only read /proc/cmdline to determine debug level,
single user mode, etc.  This patch is one in a series to make enable it
to run also in containers.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-07-01 13:08:41 +02:00
Joachim Nilsson e301877b16 Follow-up to 12d14aa, configurable auto-reload of .conf files
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:13:06 +01:00
Joachim Nilsson 997a699b7e Add more debug logs for /etc/finit.d*/ inotify and exec_runtask()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:48:56 +01:00
Joachim Nilsson fa0c63070c Add support for starting/stopping SysV init scripts
This patch adds initial support for starting a SysV init script in a
runlevel, and stopping it when leaving a runlevel.

    sysv [LVLS] <COND> /path/to/script.sh -- Optional Description

The SysV /etc/inittab file, which may use /etc/init.d, or /etc/rcN.d,
is still not supported.  A separate plugin would be required for this,
see the documentation for more information.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:45:08 +01:00
Robert Andersson 12d14aae84 fix service enable/disable support
Signed-off-by: Robert Andersson <robert.m.andersson@se.atlascopco.com>
2018-10-22 12:51:58 +02:00
Joachim Nilsson 510b36645b Fix potential buffer overruns found by GCC 8.2
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-15 22:56:23 +02:00
Joachim Nilsson 470549badb Add debug message to finit.d directory watcher callback
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-09-28 23:41:42 +02:00
Joachim Nilsson 75aa14466f Allow disabling log rotation, log size:0
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-16 07:50:52 +01:00