Commit Graph
91 Commits
Author SHA1 Message Date
Joachim Nilsson 5fd5e722a8 Only mount /proc if it isn't already mounted
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 15:05:17 +02:00
Joachim Nilsson e16a6ad4f0 Check if /sys exists and only mount if /sys isn't already mounted
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 15:04:56 +02:00
Joachim Nilsson 2f87c10cf1 Remount / as read-write as soon as possible (after fsck)
We may need to create directories early, e.g., /sys and directories in
/var that plugins rely on.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 14:56:45 +02:00
Joachim Nilsson 389328c99f Allow fsck for read-only mounted filesystems
When starting up a system booted from initramfs / may already be
mounted (read-only), so we can safely fsck it before proceeding
to remount it as read-write later (possibly).

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 14:55:38 +02:00
Joachim Nilsson e3884597a5 Delay mount of /proc & /sys to *after* emergency_shell()
In case we run into problems mounting /sys or /proc we should have
signals and the optional emergency shell available for recovery.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 14:55:38 +02:00
Joachim Nilsson 3f5ff0d339 Export ismnt() and fismnt() helper functions, for modprobe plugin
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 14:55:38 +02:00
Joachim Nilsson 70c0a38307 Provide description to built-in watchdog daemon
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 23:00:21 +02:00
Joachim Nilsson 6462bac249 finit: /run: Follow-up to 7c8b0df7, use MS_ mount flags instead
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 21:28:48 +02:00
Joachim Nilsson aa08221666 configure: Remove --enable-rw-rootfs detect using /etc/fstab instead
This patch removes the --enable-rw-rootfs build flag.  Like OpenRC we
now check /etc/fstab instad; if `/` is listed *and* doesn't have the
`ro` flag set, we remount / read-write.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 20:08:52 +02:00
Joachim Nilsson 7c8b0df720 finit: /run: Mount with nosuid,nodev,noexec for added security
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-15 19:28:23 +02:00
Joachim Nilsson cb802cd54e finit: devpts: Mount with recommended ptmxmode=0666
For details https://www.kernel.org/doc/Documentation/filesystems/devpts.txt

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-15 19:28:13 +02:00
Joachim Nilsson c391e04983 Hide command line arguments from ps, for forked children like getty
The built-in gety in Finit forks but does not execv().  To prevent
confusion on the part of the user, this patch hides all command line
arguments to PID 1 so it won't show up in ps listings of children.

Finit currently reads its arguments from the kernel /proc/cmdline,
it has hard-coded paths to /etc/finit.conf etc.  A future version
of Finit may take command line params, in which case this patch
should be moved after any getopt() handling.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-06 18:49:14 +01:00
Joachim Nilsson 636f6678ed Introducing Finit progress 𝓜𝓸𝓭𝓮𝓻𝓷
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-02 14:59:32 +01:00
Joachim Nilsson f51fde4d46 Initial support for cgroups
Similar to how systemd creates cgroups for all services, for purposes of
tracking, Finit now does the same.  We also mount all available cgroups
in the /sys/fs/cgroup namespace.

This patch adds support for grouping processes in logical cgroups, like
systemd, and an `initctl ps` command to list the hieararchy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-02-05 18:35:36 +01:00
Joachim Nilsson 2094d2a53a Warn if Finit fail to mount /proc and /sys
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-02-05 10:31:36 +01:00
Jonas Johansson f5f1a55747 Add support to specify service ID as a string
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2018-12-11 16:43:05 +01:00
Joachim Nilsson df22628183 Refactor end of bootstrap using new work queue helper
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-09 07:14:33 +02:00
Joachim Nilsson fb16abd855 Require new libuEV API: uev_init1() to enforce a small event cache
In cases where you have multiple events pending in the cache and some
event may cause later ones, already sent by the kernel to userspace,
to be deleted the pointer returned to the event loop for this later
event may be deleted.

There are two ways around this (accessing deleted memory); 1) use this
function to initialize your event loop and set maxevents to 1, 2) use a
free list in you application that you garbage collect at intervals
relevant to your application.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-04 21:53:36 +02:00
Joachim Nilsson 060de93b5b Wait for all services to complete before changing runlevel
We allow all run/task/services to complete before changing runlevel.
This means stepping them all while we wait for their completion, since
services may depend on each other.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-03 08:40:23 +02:00
Joachim Nilsson a487a30814 Refactor wdog tracking and hand-over to use svc_t instead of PID
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 3a1ad67e92 Convert built-in watchdog to a standalone mini watchdogd
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 4585aa0fb4 Issue #96: Add udevd condition to udevadm trigger commands
We must wait for udevd to be started before we call udevadm.  However,
udevd doesn't create a PID file, so we must also fake this.  There is
still a slight risk of a race condition: udevd not having properly
started before udevadm tries to connect, but it works OK in Debian.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:27 +01:00
Joachim Nilsson f2655d14c8 Bootstrap condition subsystem as soon as possible
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:27 +01:00
Joachim Nilsson b9d233d19e Issue #96: Register two unique (!) udev triggers, run device trig 1st
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 08:43:15 +01:00
Joachim Nilsson 2ec132c75a Fix #96: Start udevd as a proper service
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 01:06:32 +01:00
Joachim Nilsson 72526d9e88 Revert #52: don't reload .conf files after run-parts and rc.local
Issue #52 suggested calling service_reload_dynamic() automatically after
run-parts and /etc/rc.local.  This may seem like a good idea, but not
only does it create extra overhead, it currently also freezes the boot
and fails to present a login prompt if a run-parts directory exists.
Yes, the directory can be empty, it just have to exist to trigger this
regression.

While trying to find the root cause I realized this was all just wrong.
If the user does something that requires reloading finit, they should
call `initctl reload` from the script instead.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 22:13:02 +01:00
Joachim Nilsson a50bfc016e Set $SHELL to a sane default value, used by BusyBox
When finit calls out to external tools, like `ifup $IFACE`, that tool in
turn may use other external tools.  On systems with BusyBox our calling
`ifup $IFACE` will result in BusyBox casting a magic spell: if $SHELL is
unset it goes looking in the file /etc/passwd for the shell of $USER
which may not be set to a Bourne compatible UNIX shell, so commands like
`ip link ...` or `run-parts ...` will fail hard.

This patch adds SHELL=/bin/sh as a sane early default.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 22:07:31 +01:00
Joachim Nilsson dedf885b92 Prefer udev to handle /dev if mdev is also available on the system
Some systems, usually those built around BusyBox, have mdev installed
but have an option to install udev.  In those cases the user likely
prefers to use udev over mdev and this patch addresses that.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-17 16:06:22 +01:00
Joachim Nilsson 93a21197ab Fix artefact bug with missing OS/Finit title in banner
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-17 16:06:22 +01:00
Joachim Nilsson 3d20237959 Follow-up to f858d94, only reinitialize screen when toggling debug mode
The screen_init() call for each print() & C:o caused serious screen
artefacts in debug mode.  This patch reworks f858d94 to only re-init
screen when toggling debug.

Also, avoid screen_init() completely if started in debug mode.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 09:33:24 +01:00
Joachim Nilsson 7f62a69f74 New hook/mount/post, runs after mount -a but before hook/mount/all
This gives the operator a way to add a post-mount script, e.g. to peform
a 2nd stage mount or mount preparations, before the bootmisc.so plugin
and others run in hook/mount/all

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-18 13:34:28 +01:00
Joachim Nilsson b60d8ce4b6 Fix bootstrap ordering problem, inotify watchers *after* HOOK_BASEFS_UP
An external plugin to set up /etc can use HOOK_BASEFS_UP, but the Finit
conf_monitor() must then be called *after* not before that hook, or the
inotify watchers will listen on the wrong inode.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-15 15:23:25 +01:00
Joachim Nilsson d35a8bbda9 Fix problem building external plugins
The file plugin.h is installed to $prefix/include and used by external
plugins.  Therefore it must not include, or depend on, features set by
the configure script in config.h

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-15 15:07:24 +01:00
Joachim Nilsson 6d1c245985 Update documentation, debug replaces --debug and finit_debug
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:56:24 +01:00
Joachim Nilsson 5309ece2f9 Add support for splash progress mode from kernel cmdline
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:28:30 +01:00
Joachim Nilsson 6480850ee2 Enforce *no networking* in single-user mode, runlevel 1
This is a quite intrusive change.  In addition to the already reserved
runlevels 0 and 6, halt and reboot, respectively, this patch reserves
runlevel 1 as *no networking*, like the traditional SysV init did.  One
of the reasons for this change is the new 'single' user mode, introduced
earlier.  Most users when entering 'S' or 'single' on the kernel cmdline
expect the single user mode (runlevel 1) to be without networking.

This leaves 2, 3, 4, 5, and 7, 8, 9 as fully user-configurable runlevels
with networking.

Of course, networking can still be enabled in runlevel 1 using ifconfig
or ifupdown, or change runlevel.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson eaa82377c4 Add support for single (S) user mode from kernel cmdline
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson 3f7e03e813 Refactor, re-order a bit so screen_init() doesn't run in rescue mode
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson ab723d2f31 Add support for a rescue (recovery) mode from kernel cmdline
This patch adds a rescue (revovery) mode to Finit.  Simply add `rescue`
to the kernel cmdline at boot and the following steps at bootstrap will
be skipped:

- Load of services/run/task/etc in /etc/finit.conf + /etc/finit.d/*.conf
- fsck of filesystems in /etc/fstab
- Remount of / to read-write
- Mount of all filesystems in /etc/fstab
- swapon
- A few plugin hooks:
  - HOOK_ROOTFS_UP
  - HOOK_MOUNT_ERROR
  - HOOK_BASEFS_UP
- `runparts DIR`
- /etc/rc.local

Instead of loading /etc/finit.conf and /etc/finit.d/*.conf Finit loads
the file /lib/finit/rescue.conf, which can be overridden by the operator
if needed.  If this file is removed (or lost), Finit falls back to start
a simple root shell, without any login.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson db3263c441 Refactor conf_parse_cmdline(), support 'debug' as well as '--debug'
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:19:55 +01:00
Joachim Nilsson 2fac65becb Fix long-standing bug, runparts() should run before runlevel change
The difference between `runparts DIR` and `/etc/rc.local` is that one
should run just before the first runlevel change (to the configured
runlevel) at the end of bootstrap, whereas the other should run just
before launcing the TTYs, i.e. after all tasks in the configured
runlevel have been started.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:48:47 +01:00
Joachim Nilsson f2d142ef57 Only reload .conf and services if any .conf file has changed
This patch is an optimization.  Now that we monitor for any .conf file
changes (as soon as the event loop starts) we can skip automatic reload
of all .conf files and services if no .conf file has changed.  Unless
the user issues an `initctl reload`, `init q`, or sends us SIGHUP.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 19:22:01 +01:00
Joachim Nilsson 338810b886 Fix #92: Load .conf files and initialize global_rlimit[] earlier
As reported in #92, systems with an udevd very early register a service
using global_rlimit[].  The change was introduced in b68c5c1 but did
not take the ordering problem into consideration, global_rlimit[] was
left uninitialized, which likely led to severely limited udevd that
was continously crashing.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:51:49 +01:00
Joachim Nilsson 3258edc246 Fix #90: Restore tmpfs mount of /dev/shm, removed in d7401b2
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:02:06 +01:00
Joachim Nilsson 32b7a14cb3 Add ismnt() helper function, wrap fismnt()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:00:41 +01:00
Joachim Nilsson 0e37bb0924 Follow-up to b0663d0, cond_init() must run before first hooks
The new condition triggered hooks requrie /var/run/finit/cond to
be set up before calling the first user-configurable hooks.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 11:19:35 +01:00
Joachim Nilsson e94d2a8c08 Merge branch 'master' into cond-generation 2017-12-23 09:31:41 +01:00
Joachim Nilsson 95518df62d Some systems rely on /dev/shm being there for mount -a
This was accidentally removed in d7401b2, when svc_t was refactored
from using shared memory.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 16:44:52 +01:00
Joachim Nilsson b439ac670d .conf: don't rely on mtime to determine if service needs reloading
Until now Finit has used mtime to determine if a file has been changed,
or simply touched to request reload, when `initctl reload` is called.
Using mtime for this purpose is a monumentally bad idea since time can
be changed at any point: a user may adjust the time, NTP continously
tunes the clock, and time stamps are stored as the walltime.  So if we
compare timestamps against the last time we (booted or) did reload, we
would miss .conf file changes.

This patch replaces the mtime mistake with an inotify watcher for the
following files: /etc/finit.d/*.conf, /etc/finit.d/available/*.conf,
and /etc/finit.conf.  All file changes between (bootstraps and) calls
to `initctl reload` are tracked, like the mtime backend it replaces.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:08:38 +01:00
Joachim Nilsson c59f7d23f4 Add and improve debug messages, clean out old dev. comments
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:40:43 +01:00