We use LOG_CONS to ensure log messages reach the operator, but since
watchdogd starts very early this means non-critical messages like the
initial greeting leaks to console because syslogd has not yet started.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With non-standard paths, e.g., when running `make distcheck`, the
absolute path to some commands become ridiculously long. However,
this has been a recurring issue for some users in the past, so it
is time to increase the capabilibieies of Finit to cover this.
Yes, a better way is probably to allocate all these strings when they
are used, but that would require a redesign of the initctl API and
likely cause a lot of regressions before everything has stabilized.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.
it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Non-trivial systems, like Infix[1], require more than one lap around the
track to warm up. This is a follow-up to issue #362, commit 4701ede, in
fixing an obvious oversight in the new sm_check_bootstrap() work. While
there are still outstanding bootstrap tasks or services that have not
yet started, we must reschedule the worker.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Drop complete() logic, waiting for run tasks to finish, from the
service_start() funciton to the general service_monitor(). This
refactor frees up the main loop and allows us to answer any API
calls from initctl even from the run task itself.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For some specialized forms of runparts, e.g., start-stop scripts in SysV
init replacements, there is a need to append an argument. Typically
this is 'start' or 'stop'.
This functionality has been broken for quite some time, meaning we
should consider it being unused by current users of Finit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Bootstrap-only tests that just verify basic functionality are often very
short. This change handles that by retrying SIGUSR2 until Finit has had
the chance to finalize bootstrap and enable signals.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The code refactored in this commit has long been an eyesore. The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.
Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.
Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls. To
ensure they run at the same point in time two things have been done:
1. A new <int/bootstrap> condition has been added which triggers
runparts, which now is a regular task created by conf_init()
2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
transition from runlevel S to any other runlevel.
Fixes#356
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This should clarify the messup on the behalf of the mainatiner in not
documenting this properly, including the deviations introduced in v4.4
See issue #359 for a background.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- iwatch events return filenames in dir field, ignore file for those
- improve warning message on failure
- drop bogus "Out of memory" error log message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>