Commit Graph
45 Commits
Author SHA1 Message Date
Joachim Wiberg 966ae9fb0d Rename FINIT_LIBPATH_ -> FINIT_EXECPATH_
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:48:25 +01:00
Joachim Wiberg 311c6be9aa Add support for optional reboot delay
Slightly different take on issue #334 making it optional, possible to
enable per system.

    reboot-delay <0-60>           # default: 0 (disabled)

When enabled (non-zero), runs after filesystems have been unmounted,
the root filesystems has been remounted read-only, and sync(2) has
been called, twice.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-08 09:37:19 +01:00
Joachim Wiberg 2f91ab5eac Fix #235: support for overriding /etc/finit.conf and /etc/finit.d
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.

For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added.  It in turn can be used by factory.conf
as follows to override /etc/finit.d:

    rcsd /etc/factory.d

Manually verified in myLinux

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-10 17:21:33 +01:00
Joachim Wiberg 912a281ee2 Fix #299: add support for service readiness notification
This patch adds service readiness notification to support daemons
employing systemd and s6 notification.  Complementing the native
Finit readiness support using PID files that exist already.

The two have slightly different ways of implementing readiness:

 - https://www.freedesktop.org/software/systemd/man/sd_notify.html
 - https://skarnet.org/software/s6/notifywhenup.html

Finit now provides both a NOTIFY_SOCKET environemnt variable, for
systemd, and a way to start s6 daemons with a descriptor argument.

For details on the syntax, see the `service` documentation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 20:06:26 +02:00
Joachim Wiberg a61a8015d7 initctl: new command, list installed plugins
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-15 11:00:39 +02:00
Joachim Wiberg 0cce69892a Fix #261: support for overriding default runlevel from command line
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-08 09:57:18 +02:00
Joachim Wiberg 57c97d8190 Fix #224: support for cmdline -- finit.fstab=/etc/fstab.secondary
This adds support for bringing up the system with an alternate fstab at
boot.  E.g., when using a primary/secondary setup for boot partitions.

By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary

If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.

Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot.  Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-25 21:44:33 +02:00
Joachim Wiberg b0d0ca76cf Minor, coding style
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-25 21:37:59 +02:00
Joachim Wiberg 108bbf56dd Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:35:49 +02:00
Jörgen Sigvardsson 62da379472 initctl signal command parsing: done 2022-02-15 12:29:40 +01:00
Joachim Wiberg 5ff27c4fe2 Allow kernel log messages to console with loglevel=7
Since Finit v4.0 kernel console output has been silenced just prior to
the banner being printed, unless finit.debug mode was enabled.  This
patch makes sure to check the kernel loglevel, if it's >= 7, finit no
longer disables kernel console ouput.

Consequently, you now need 'quiet' on your kernel command line, or a
loglevel < 7 for a quiet boot, at least until a syslogd takes over.

This means that you now can debug the kernel and finit independently,
which should be a great comfort to anyone doing bringup or any form of
kernel debugging.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-02 01:34:49 +01:00
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
Joachim Wiberg 39d879f240 Add support for auto-detetcing OS heading for progress
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY".  As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release.  It is now possible
to also disable the heading entirely using --without-heading

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-05 14:28:49 +02:00
Joachim Wiberg 9cc9e3ddbb getty: if we cannot execute /bin/login, try sulogin before /bin/sh
Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 12:42:48 +02:00
Joachim Wiberg 5404aa6037 Refactor run_getty() and run_getty2() into one
By moving the built-in getty to a stand-alone bundled getty we can now
refactor the old run_getty() functions into a single one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 221ab20898 tty: add basic security, call sulogin in rescue mode (notty)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:27:26 +02:00
Joachim Wiberg 96534789db Minor, rename LOGIT_PATH -> _PATH_LOGIT for consistency
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:26:52 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 3c4eca60b7 initctl: fix restart of run/tasks, stuck in DONE state
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 19:51:03 +02:00
Joachim Wiberg 6a6f3a8291 cgroup: refactor for cgroups v2, much cleaner + unified hieararchy
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1.  Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.

Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
            in cgroups v1 was handled by cgreaper.sh.  This is fixed
	    in the next commit in the series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:35 +01:00
Joachim Wiberg 464bc831a5 Minor refactor, create FINIT_CGPATH in finit.h to reduce duplicaiton
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:48:57 +01:00
Joachim Wiberg 649a269526 Add reboot/halt/poweroff/suspend commands to Finit API
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-21 10:49:13 +01:00
Joachim Wiberg dda59503ac Refactor, drop #ifdefs and logger fallback, probe for logit
Simplify log redirection, probe for logit early and fall back to
use a while-loop of syslog() instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-17 13:00:58 +01:00
Joachim Wiberg 35e4e0d073 Drop confusing splash cmdline and --enable-progress configure option
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer.  The
resulting code and configure script is a lot simpler to understand and
maintain:

- No more --enable-progress or --enable-progress-classic configure
  flags.  Instead a progress_style variable in helpers.c that can
  be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option.  This turned out to
  be *very* confusing to many users who believed it was some sort of
  graphical splash screen à la Plymouth.

Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:08 +01:00
Joachim Wiberg b175b4a2ae initctl: add PID and IDENT to 'cond dump' command
Instead of just walking /run/finit/cond, also show the source of each
condition.  The hook and net conditions are hard-coded to init[1] atm.
and unknown conditions are shown as unknown[0].

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-13 12:07:20 +01:00
Joachim Wiberg 10d4964106 Remove last traces of inetd support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 21:50:17 +01:00
Jacques de Laval cb64c068e3 Fix #136: drop old init client tool
The SysV API compatibility layer gives too little value to be worth
the effort of maintaining it. Users are encouraged to use the
`initctl` tool instead.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-11 17:52:08 +01:00
Joachim Wiberg e147cf7a8c Relocate IPC socket file from /run/finit.sock -> /run/finit/socket
We have our own subdirectory alread in /run, for conditions, and the FHS
recommends services maintain their own subdirectory if they have >1 file
for runtime storage.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Jonas Holmberg ca210f5431 Add support for logging security related events
This patch introduces the LOG_CONSOLE syslog facility for logging common
events.  In industrial applications aiming for IEC 62443 compliance the
following events are central for system observability:

- Change of runlevel - i.e., starting up, shutting down, upgrade, etc.
  Facility: console, severity: notice
- Service starting
  Facility: console, severity: notice
- Service restarting
  Facility: console, severity: notice
- Service stopping
  Facility: console, severity: notice
- Service failed to start
  Facility: console, severity: warning

The use of facility console for this makes it easier to filter out when
forwarding syslog messages from an embedded system to a remote log sink.
Otherwise messages of facility daemon would be used, which include a lot
more, and mostly irrelevant, information.

Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:38:21 +01:00
Joachim Nilsson 212083b922 Introduce strterm(), hard-add terminating '\0' at end of buffer
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 03:02:39 +01:00
Joachim Nilsson 744719219e initctl: Remove experimental cond set/clear commands
The commands are both unsafe (insecure) and send the wrong message,
that initctl can be used to script conditions.  Only plugins are
officially supported to manage conditions.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 00:35:13 +01:00
Joachim Nilsson 7bf2fcb6e3 Fix Coverity CID 265222, guard init_request::data member
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-06 23:56:59 +01:00
Joachim Nilsson a487a30814 Refactor wdog tracking and hand-over to use svc_t instead of PID
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 5309ece2f9 Add support for splash progress mode from kernel cmdline
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:28:30 +01:00
Joachim Nilsson eaa82377c4 Add support for single (S) user mode from kernel cmdline
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson ab723d2f31 Add support for a rescue (recovery) mode from kernel cmdline
This patch adds a rescue (revovery) mode to Finit.  Simply add `rescue`
to the kernel cmdline at boot and the following steps at bootstrap will
be skipped:

- Load of services/run/task/etc in /etc/finit.conf + /etc/finit.d/*.conf
- fsck of filesystems in /etc/fstab
- Remount of / to read-write
- Mount of all filesystems in /etc/fstab
- swapon
- A few plugin hooks:
  - HOOK_ROOTFS_UP
  - HOOK_MOUNT_ERROR
  - HOOK_BASEFS_UP
- `runparts DIR`
- /etc/rc.local

Instead of loading /etc/finit.conf and /etc/finit.d/*.conf Finit loads
the file /lib/finit/rescue.conf, which can be overridden by the operator
if needed.  If this file is removed (or lost), Finit falls back to start
a simple root shell, without any login.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson c0515d112e New client side API to access svc_t entries without shared memory
This change is one of the required intermediate steps to remove the
shared memory store for all svc_t, this in turn to avoid any external
programs manipulating the internal memory of PID 1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 11:06:19 +01:00
Joachim Nilsson c76a58ef7a Remove long since deprecated finit.conf: console <DEV> support
All this code did was trigger prctl() to set process name to "console",
which you could use as a simple means of figuring out if a process was
started from the system console.

There are other ways to do this, which Finit should not be involved in.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-23 19:28:11 +02:00
Joachim Nilsson a2f4b35e4e Fix #77: Remove deprecated startx and user .conf settings
It is strongly recommended to instead use the service stanza to start
XDM/GDM, or use startx after a regular login.

Note: the `user NAME` setting was always reserved for use with startx

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-08-30 15:01:05 +02:00
Joachim Nilsson cd947a69a8 log.c: New functions to hide access to quiet and silent flags
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-02 12:42:44 +02:00
Joachim Nilsson 51e1a907e6 log.c: New log_is_debug() function, hide access to debug variable
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-02 12:40:50 +02:00
crazy 67435d2034 finit.h: added fallback for _PATH_{STDPATH,VARRUN} in case is not defined
That should never be needed , however I saw
  already systems with broken paths.h so better
  have something around in case something breaks.

Signed-off-by: crazy <crazy@frugalware.org>
2017-03-28 13:21:14 +02:00
Joachim Nilsson fff68b7b06 Relocate source files to an src/ subdirectory
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-16 01:31:02 +01:00