We use LOG_CONS to ensure log messages reach the operator, but since
watchdogd starts very early this means non-critical messages like the
initial greeting leaks to console because syslogd has not yet started.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With non-standard paths, e.g., when running `make distcheck`, the
absolute path to some commands become ridiculously long. However,
this has been a recurring issue for some users in the past, so it
is time to increase the capabilibieies of Finit to cover this.
Yes, a better way is probably to allocate all these strings when they
are used, but that would require a redesign of the initctl API and
likely cause a lot of regressions before everything has stabilized.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.
it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Non-trivial systems, like Infix[1], require more than one lap around the
track to warm up. This is a follow-up to issue #362, commit 4701ede, in
fixing an obvious oversight in the new sm_check_bootstrap() work. While
there are still outstanding bootstrap tasks or services that have not
yet started, we must reschedule the worker.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Drop complete() logic, waiting for run tasks to finish, from the
service_start() funciton to the general service_monitor(). This
refactor frees up the main loop and allows us to answer any API
calls from initctl even from the run task itself.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For some specialized forms of runparts, e.g., start-stop scripts in SysV
init replacements, there is a need to append an argument. Typically
this is 'start' or 'stop'.
This functionality has been broken for quite some time, meaning we
should consider it being unused by current users of Finit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Bootstrap-only tests that just verify basic functionality are often very
short. This change handles that by retrying SIGUSR2 until Finit has had
the chance to finalize bootstrap and enable signals.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The code refactored in this commit has long been an eyesore. The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.
Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.
Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls. To
ensure they run at the same point in time two things have been done:
1. A new <int/bootstrap> condition has been added which triggers
runparts, which now is a regular task created by conf_init()
2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
transition from runlevel S to any other runlevel.
Fixes#356
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This should clarify the messup on the behalf of the mainatiner in not
documenting this properly, including the deviations introduced in v4.4
See issue #359 for a background.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- iwatch events return filenames in dir field, ignore file for those
- improve warning message on failure
- drop bogus "Out of memory" error log message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The execvp() call always fails with -1, so only logging exit code when
collecting the PID is not enough. When debugging the user needs to see
the errno from execvp(), e.g., "No such file or directory", when the
command was missing the absolute path to the executable.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Related to 6f0d448 in that we check if the kernel knows about this
process before we try to stop it. If it's already dead we clean up
and return.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This turns out to be the root-cause of #227. Finit is waiting forever
for proceeses to stop at shutdown/reboot, while a subreaper has already
collected the PID, or Finit for some reason did not collect the PID.
When the process timeout calls service_kill() we now check if the kernel
actually knows of this process or not. If it's already been collected,
we can notify Finit of this by calling service_monitor() to clean up the
'svc' and in turn call sm_step() to finalize the state transition.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When calling `initctl -b create` from a start script at bootstrap you
risk blocking the boot since Finit currently cannot reply to IPC during
that period.
This patch allows -f to override this builtin check for the following
initctl commands:
- touch
- show
- edit
- create
- delete
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These changes add a new svc_block_t type: SVC_BLOCK_CONFLICT so a user
can more clearly see why a run/task/service has not been started by
Finit. The reason for the block is by default logged, which can be
escaped by using the `nowarn` flag.
Also, when the conflict is resolved, allow the service to start.
With these changes, the system/hotplug.conf should work better and
cause less questions about "strange" log messages.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Apparently the qemu-system-x86_64 in -nographics mode does all sorts of
crazy things to the terminal. Most annoying, it disables linewrap.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In 91a9c83 a regression was introduced that affects the way Finit stops
a supervised process and its process group.
Instead of sending SIGTERM to the process, delegating the responsibility
to that process to inform any children it may have, Finit as of 91a9c83
sends SIGTERM to the entire process group. For SIGKILL this is fine,
SIGKILL only runs as cleanup and as a last ditch effort if the process
doesn't respond to SIGTERM.
This regression, introduced in v3.2, directly affects services like
avahi-autoipd that have forked off children that it needs to tell to
exit cleanly before it returns. With the patch in question these
children are never allowed to complete, which in turn causes lingering
169.254 link-local addresses on interfaces.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When started as a monitor in a container, or for the test suite run from
distcheck, we must allow Finit to find its own tools like initctl. This
should also be a more generic solution that cover more cases.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A simple distcheck revealed that the local path[] was too small to store
something like /home/jocke/src/finit/finit-4.4-rc1/usr/lib/finit/system/
This refactor should cover all cases.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The user may have their own setup of things, by default we should not
cause unnecessary warnings in syslog.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff. If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.
This change is quite invasive. It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some services (openresolv) tries to talk to it very early, so lets get
dbus up and running as soon as possible.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The logger redirection process was sometimes in the init group instead
of the system/<svc>/ group. This was due to the parent PID being moved
after the logger was forked.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>