Don't try to source an optional env:file if it is missing. Otherwise
execution of pre/post/ready/cleanup script will fail.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Introduced to work-around systems with broken RTCs, it also introduced a
dormant bug in Finit, triggered at shutdown on some systems. The call
to dlclose() removed the memory to the rtc_timer which libuev later then
referenced.
Fixes#429
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Initiating a shutdown/reboot from `initctl` should not cause `initctl`
to be killed in do_shutdown().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a user sets up a TTY without a device, triggering the tty->notty
code path, the tty->dev will be NULL and tty_parse_args() still return
OK result.
Found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Enhance fallback entropy generation by mixing in multiple sources:
runtime statistics, PID, and high-resolution timestamps.
This provides better initialization for the PRNG when neither saved
entropy nor hardware RNG are available during early boot.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When using Finit with an external getty that supports alternative login
program argument, the tty_parse_args() function did not check if a getty
command had already been registered:
tty [12345] /sbin/agetty -L -l /bin/login console noclear
This caused Finit to try /bin/login as the getty program.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change introduces two new states for the big Finit state machine:
runlevel-clean and reload-clean. Here Finit now waits for any post or
cleanup script to finish before returning OK to the initctl command.
Additionally, the service state machine has been updated to ensure a
run/task/sysv/service calls any post or cleanup script before they are
removed. A new 'dead' state for svc_t is introduced which any removed
svc_t ends up in now instead of becing collected from 'halted' state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add cleanup:script support, runs at service removal
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some subsystems call iwatch_add() without first calling iwatch_del() on
the same path. E.g., cgroup_config().
Issue #417 but unclear atm. if this is the root cause.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A long running pre/post/ready script must be killed properly, not by
targeting its process group. Process group cleanup is handled by the
service_monitor() when reaping the script's PID.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
New test adds /bin/fail.sh to verify that a failing pre:script (that
also takes too long to run) is detected: exit code and timeout.
Ensure existing test pass full path to /sbin/fail.sh script.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check exit status of `pre:` scripts, on failure drive service/sysv to
`crashed` state. The exit code of `post:` scripts remain ignored for
now.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Syntax:
[pre|post|ready]:[0-3600,]/path/to/script
Description:
Before this patch all pre/post/ready scripts used the global kill
delay as timeout. After this patch it is possible to disable the
timeout as well as set a timeout >60, which is max kill delay.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Follow-up to 465bc17, which addressed unintended restart of siblings.
This patch fixes a problem where template instantiated services are not
properly reloaded/restarted when marked as "dirty" with `initctl touch`.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>