Try out navigation.tabs, if we don't like it we can revert.
Reorg for stricter sections, what information actually belongs where?
E.g., introduction is now in a Getting Started section.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some 'respawn' type services, like gettys, may hog the CPU in error
states if the service immediately exits. E.g., due to missing dev.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
During /bin/login phase the TTY device node is chowned and chmodded to
the authenticated user. It will remain in this state until the next
call to getty.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A user reports inability to re-start getty on the console after logging
out from a serial console. After some digging it was found that the tty
was owned by the last user logged in and 600. Even thougn getty runs as
root, it did not have permission to re-open the device node.
Turns out there was a minor bug in the new capability code that cleared
all capabilities from the root user. A surprising amount of programs
worked just fine, but restarting getty gave it away.
The fix is to only call cap_setuid() when capabilities are set for the
service, otherwise we just fall back to setuid().
Also, refactor service_register() wrt. capabilities a bit so that we can
give users an early warning if the configuration is invalid, by adding a
parse_caps() helper function that calls cap_iab_from_text() to verify.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Implement supplementary group support for services, allowing them to
access resources owned by multiple groups. Uses the @user:group,sup1,sup2
syntax to explicitly specify supplementary groups, in addition to now
reading group membership from /etc/group.
Cgroups v2 limits are hierarchical - a process is constrained by the
most restrictive limit in its ancestor chain, not just its immediate
cgroup. This patch updates cg_conf() to walk up the hierarchy and
report effective limits by comparing values at each level.
This fixes incorrect "max" (unlimited) reporting in 'initctl --json
status', 'initctl cgroup', and 'initctl top' when child cgroups have
no explicit limits but parents do.
For memory.max and cpu.max: take minimum (most restrictive)
For memory.min: take maximum (most protection)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Comment-out code that makes the cursor "jump" around at boot before
displaying: Please press Enter to activate this console.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
libite v2.6.2 is not yet in Buildroot, so let's relax the dependency a
bit. Load bearing functionality was in v2.6.0, any fixes on top is a
nice-to-have only.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We now require readsnf() introduced in libite 2.6.0, with bug fixes
this effectively means v2.6.2.
The libuev bump is for 64-bit time_t, with bug fix => v2.4.1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes an issue where the mouse scroll wheel and Shift+PgUp/PgDn
sometimes would not work properly after login.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Drop clear screen to fix flickering in 'initctl top' output. Also, make
sure to not garble the display if the the terminal is too small.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Instead of /system/10-hotplug/ we now place udevd, mdevd, and others, in
more aptly named groups using the new 'name:' syntax.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This should not be needed, but for some reason we don't get events when
early processes exit, so we end up with lingering cgroups.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The container monitor that podman forks off when starting a container
instance creates subgroups in the cgroup v2 hieararchy that we want to
reuse. This patch adds cgroup_move_svc() which we call from the pidfile
plugins to relocate the conmon process.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit activates the use of clone3() for service_fork(), to allow
Linux to create the new process directly in the correct cgroup instead
of later moving it there -- much cheaper and less error prone.
To facilitate this a few new helper cgroup functions have been added and
two new configuration directives introduced: delegate and name:leafname.
The delegate option is for running, e.g., container runtimes that want
to create their own cgroup v2 structur, and the name:leafname allows a
user to change the name of the subgroup under user/system/init.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The PTY approach caused isatty() to return true for services using
the log directive, triggering programs like fprintd (using glib) to
emit ANSI escape codes and other TTY-specific formatting in syslog.
Using a standard pipe ensures isatty() correctly returns false, so
programs produce plain text output suitable for logging.
For services that require line-buffered output, users can wrap the
command with `stdbuf -oL` as documented in doc/config/logging.md.
Fixes#455
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When setting up a new system with Finit it is very common to make small
logical mistakes that cause "hangs" at boot. This is when Finit waits
for 180 sec. for run/tasks to complete before moving to the configured
runlevel. This patch adds console input monitoring during bootstrap
wait that allows users to press Ctrl-C to skip waiting and proceed to
the configured runlevel.
When Ctrl-C is detected, all incomplete run/task/services are logged
to syslog for later troubleshooting after login.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Relax the constraints introduced in a39ee0b, for issue #342, a bit on
when start/stop/restart/reload service can be called. Also, allow
'initctl reload', but ignore it when the system is in runlevels S/0/6.
This makes it possible to start manual:yes type services at botostrap,
for example, which has been a common feature request.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>