Introduced to work-around systems with broken RTCs, it also introduced a
dormant bug in Finit, triggered at shutdown on some systems. The call
to dlclose() removed the memory to the rtc_timer which libuev later then
referenced.
Fixes#429
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Initiating a shutdown/reboot from `initctl` should not cause `initctl`
to be killed in do_shutdown().
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a user sets up a TTY without a device, triggering the tty->notty
code path, the tty->dev will be NULL and tty_parse_args() still return
OK result.
Found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Enhance fallback entropy generation by mixing in multiple sources:
runtime statistics, PID, and high-resolution timestamps.
This provides better initialization for the PRNG when neither saved
entropy nor hardware RNG are available during early boot.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When using Finit with an external getty that supports alternative login
program argument, the tty_parse_args() function did not check if a getty
command had already been registered:
tty [12345] /sbin/agetty -L -l /bin/login console noclear
This caused Finit to try /bin/login as the getty program.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change introduces two new states for the big Finit state machine:
runlevel-clean and reload-clean. Here Finit now waits for any post or
cleanup script to finish before returning OK to the initctl command.
Additionally, the service state machine has been updated to ensure a
run/task/sysv/service calls any post or cleanup script before they are
removed. A new 'dead' state for svc_t is introduced which any removed
svc_t ends up in now instead of becing collected from 'halted' state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add cleanup:script support, runs at service removal
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some subsystems call iwatch_add() without first calling iwatch_del() on
the same path. E.g., cgroup_config().
Issue #417 but unclear atm. if this is the root cause.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A long running pre/post/ready script must be killed properly, not by
targeting its process group. Process group cleanup is handled by the
service_monitor() when reaping the script's PID.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
New test adds /bin/fail.sh to verify that a failing pre:script (that
also takes too long to run) is detected: exit code and timeout.
Ensure existing test pass full path to /sbin/fail.sh script.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check exit status of `pre:` scripts, on failure drive service/sysv to
`crashed` state. The exit code of `post:` scripts remain ignored for
now.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Syntax:
[pre|post|ready]:[0-3600,]/path/to/script
Description:
Before this patch all pre/post/ready scripts used the global kill
delay as timeout. After this patch it is possible to disable the
timeout as well as set a timeout >60, which is max kill delay.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Follow-up to 465bc17, which addressed unintended restart of siblings.
This patch fixes a problem where template instantiated services are not
properly reloaded/restarted when marked as "dirty" with `initctl touch`.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.
this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.
for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
Consider the case where container@.conf is an available template. When
creating a container@foo.conf it will share the same base .conf as an
existing container@bar.conf, but we do not expect to restart bar just
because foo is instantiated.
Up until this change, all template siblings were considered "dirty" if a
new one was created or updated. Skipping realpath() for all files that
have a '@' works around the problem.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>