Commit Graph
261 Commits
Author SHA1 Message Date
Joachim Wiberg 8a3d55b416 test: refuse to run against a stale sysroot binary
'make check' refreshes the sysroot through the setup-chroot rule, but
running a test script by hand does not, so the test exercises whichever
finit was installed last and reports on code that is no longer there.
Both a passing and a failing run are then meaningless, and nothing says
so.

Compare the built binary against the installed one at startup and fail
with the command that fixes it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:28 +02:00
Joachim Wiberg 2a5190ecff service: do not let a script timeout take PID 1 with it
A stop: or reload: script written with a timeout killed Finit at
config load:

    service stop:5,/bin/true service.sh -- Boom

parse_script() takes the timeout as a pointer and the caller decides
whether it wants one.  However, both stop: and reload: scripts so far
have no timeout, i.e., NULL.  Guard the branch that reads a leading
number.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:27 +02:00
Joachim Wiberg f1393ff8a1 conf: instantiate %i templates for the block format
A template in the block format registered garbage.  conf_parse_file()
routed every file with an '@' in its name straight to the legacy
parser, which read the block line by line: the section header became a
service whose command was the section title, and each key = value line
below it became an environment variable.

    service serv:%i { ... }   ->  service 'serv:eth0' with argument '{'

Substitute %i over the whole file before parsing instead, so format
detection and both parsers see finished text.  A bare name@.conf is
still skipped, it is the template rather than an instance of one.

The legacy parser no longer opens the file or substitutes per line, it
is handed the instantiated buffer, so the template convention now has
one implementation instead of two.  conf_is_template() applies
basenm(), a directory with an '@' in its name is not a template.

libconfuse cannot name a buffer it parses before 3.4, so a typo in a
template would be reported against "[buf]".  Parse through fmemopen()
with the file name preset until the floor moves.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:26 +02:00
Joachim Wiberg 3b866c95e0 conf: add libconfuse block format alongside the one-liner format
The one-liner format has grown crowded and very wide, and every new
service option makes it worse.

Add a second, block-based format, parsed with libconfuse:

    service sshd {
        description = "OpenSSH daemon"
        runlevel    = "2345"
        command     = "/usr/sbin/sshd -D $SSHD_OPTS"
    }

Both formats keep the .conf extension and are detected per file by
content.  Try-parse strictly with libconfuse; on a parse error,
re-parse leniently to tell a block file with a typo from a one-liner
file.  Only a one-liner file reaches the legacy parser, a typo is
reported with its file and line.

Each block is translated to the canonical one-liner and registered
through the existing entry points, so the two formats cannot drift.

The one-liner parser is frozen at the 4.x feature set, new options
land only in the block schema.  libconfuse 3.3 or later is required,
CFGF_KEYSTRVAL does not exist before it.

Covers service, task, run, sysv and tty blocks, the static directives,
and the cgroup, rlimit, set and log blocks.  Templating and the
documentation rewrite are still to come.

The regression test covers translation of a service block to the
one-liner, a block-format /etc/finit.conf booting with set {} applied
at bootstrap, both formats side by side, and rejection of a typo at
block and at root level.

A rejected file must not fall through to the legacy parser, which
registers a bogus unstartable service per line.  assert_num_children
cannot see that, the bogus service has no children either, so the
check is assert_num_services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:25 +02:00
Joachim Wiberg ee5038e7af test: reap the watchdog's sleep in wdkill()
Every test left a stray `sleep 300` behind, reparented to PID 1, where
it lingered for up to five minutes after the test had finished.

wdstart() runs the watchdog in a subshell, so $! is the pid of the
subshell, not of the sleep it forks.  wdkill() killed the subshell and
orphaned the sleep.

Kill the child first, killing the subshell puts the sleep beyond the
reach of pkill -P.  Neither kill is sure to match, and wdkill() runs
from the EXIT trap under set -e, so both must tolerate failure.  Also
return early when wdpid is unset, for failures before wdstart() runs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:24 +02:00
Joachim Wiberg 3febc7d513 test: regression for stale pidfile cleanup after unclean exit
Cover the scenario fixed in "service: clean stale pidfile after
unclean daemon exit": a daemon with a pid:!/path config dies via
SIGKILL, leaving its pidfile behind, and the next instance must
still come up.

Add a 'serv -x' flag (refuse to start when the pidfile already
exists, dbus-style) so the test actually exercises the cleanup --
without it, plain 'serv' would happily overwrite the file and the
test would pass with or without the fix.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-05-12 10:11:49 +02:00
Joachim Wiberg 804f655d87 test: fix depserv.sh after regression in 0b182c06
A service that is reloaded should not trigger dependants to be reloaded
unless the new <~cond> is used.  Which is reserve for tightly coupled
services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-22 20:36:36 +01:00
Joachim Wiberg 03a14bcaa5 Add <~cond> condition modifier for tightly coupled services
Conditions in Finit are dependencies: if A is asserted, service B is
allowed to run.  When A goes through FLUX (e.g., upstream reloads),
dependents are PAUSED and then simply resumed when the condition is
reasserted -- this is the correct behavior for barrier-style deps
like <pid/syslogd>.

However, some setups have tightly coupled services where dependents
must be reloaded/restarted when an upstream service reloads, not just
resumed.  E.g., the FRR routing stack on Infix OS:

    netd <pid/mgmtd> ← zebra <!pid/netd> ← {staticd,ripd} <!pid/zebra>

When netd reloads (SIGHUP), zebra and its dependents must be restarted
to pick up the new configuration.

The new '~' condition prefix marks a dependency as flux-sensitive:

    service <!~pid/netd> name:zebra ...

When the upstream condition goes FLUX and returns to ON, the dependent
is reloaded (SIGHUP) or restarted (noreload '!') instead of merely
resumed.  Transitivity follows naturally through the condition chain.

Closes #416
Closes #476

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-22 15:51:25 +01:00
Joachim Wiberg 4bb2c33859 Dependents not restarted after SIGHUP reload of service
When 'initctl reload' is called after marking a service in a dependency
chain dirty, Finit fails to restart (unfreeze) affected services.

This patch updates the pidfile plugin to watch for IN_ATTRIB changes,
e.g. when a process uses utimensat() to update its pidfile, and adds
service_step_all() at end of reload cycle to guarantee convergence
after conditions are reasserted.

Issue #476

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-17 07:08:30 +01:00
Joachim Wiberg ab81272083 test: new regression test to verify multi-chain deps
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-13 07:30:10 +01:00
Joachim Wiberg 92a2861b1c Merge pull request #473 from mattiaswal/fix-devmon 2026-02-10 20:36:37 +01:00
Mattias Walström b206c3d655 devmon: re-evaluate device conditions on reconf
Device conditions tracked by devmon were lost on `initctl reload`
because the reconf path did not re-assert them.  Add devmon_reconf()
to iterate all tracked device nodes and set or clear their conditions
based on current device presence.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
2026-02-10 20:09:35 +01:00
Joachim Wiberg 0b182c063e test: Extend depserv test with per-service reload, fix slay race
Verify that 'initctl reload foo' properly triggers dependent
services by checking that bar gets a new PID after the reload.
Also change the second test case from service/foo/running to
service/foo/ready which is the actual condition set by pidfile.so.

Fix a race in slay where the target process could exit between
the PID lookup and kill -9, causing spurious test failures in
tight kill loops (e.g., start-kill-service.sh).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-10 16:00:57 +01:00
Joachim Wiberg 3f98220d5d test: simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:54:06 +01:00
Joachim Wiberg 0ca509a42e test: debug sysroot setup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:47:11 +01:00
Joachim Wiberg 329f11b4da test: add barebones /etc/{passwd,group} and an ld.so.conf
Finit now requires being able to query at least for the root user and
group before starting any services.

Also, add support for using libraries installed in /usr/local

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 09:45:06 +01:00
Joachim Wiberg 4f8dab75b2 Update test helper and all workflows to enble libsystemd build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-08-29 14:43:25 +02:00
Joachim Wiberg 4f01856313 test: relocate check.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 16:47:12 +02:00
Ming Liu de4be1557b sd-daemon.c: fix a compilation error
A following compilation error was observed:
| libsystemd/sd-daemon.c:64: undefined reference to `strlcpy'

fix it by include the required libite dependency.

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2025-07-08 11:19:38 +02:00
Joachim Wiberg 167d75ac4a test: update to verify $MAINPID
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-08 07:00:47 +02:00
Joachim Wiberg 261d604ea3 test: minor refactor, relocate "Test done ..." message to setup.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 14:17:42 +02:00
Joachim Wiberg ce7d4cebab test: minor refactor, relocate "Test start ..." message to setup.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 13:31:29 +02:00
Joachim Wiberg 020eefe732 test: extend start-stop-sysv to verify stop:script support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 13:21:50 +02:00
Joachim Wiberg e49763d834 test: extend start-stop-sysv to verify reload:script support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 12:05:58 +02:00
Joachim Wiberg da83462731 libsystemd: new library, refactor sd-daemon.[ch] test code
This commit introduces a bare-bones replacement for libsystemd:

 - Build .so file and add --with-libsystemd to configure
 - Add capabilities support to test/src/serv.c
 - Update tests to account for a Finit built w/o libsystemd support

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:42:06 +02:00
Joachim Wiberg 7cf0a293fd test: adjust unexpected-restart.sh for proper systemd/s6 notify
A systemd service should only use NOTIFY_SOCKET and an s6 style
service reads its notify descript from the command line.  For
details, see notify.sh

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:36:59 +02:00
Joachim Wiberg d0d9b83b66 test: update serv daemon to use proper systemd abstract socket
This commit introduces a stripped down sd_notify(), taken from the
systemd man page example, which is used by the serv daemon in lieu
of the previous broken implementation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:36:59 +02:00
Joachim Wiberg f217d493b4 test: add --map-auto to unshare call
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 16:36:52 +02:00
Joachim Wiberg 75fa868a4b Fix various typos found by codepsell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 16:46:28 +01:00
Joachim Wiberg f1b5b42919 test: enable debug logs for global-envs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-14 10:25:30 +01:00
Joachim Wiberg f546129baf test: debug sysvparts
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-14 10:25:30 +01:00
Joachim Wiberg 5265eee25d test: slightly more robust checkself.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:35 +01:00
Joachim Wiberg bbc83eaa64 test: new test
New test adds /bin/fail.sh to verify that a failing pre:script (that
also takes too long to run) is detected: exit code and timeout.

Ensure existing test pass full path to /sbin/fail.sh script.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:33 +01:00
Joachim Wiberg a8433fcb7f test: ignore unreachable shellcheck warning
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-12 08:39:30 +02:00
Joachim Wiberg 60c676ab2d test: minor, spelling in comment
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 08:11:41 +02:00
Joachim Wiberg eb4eca9607 test: verify pre:/post:scripts also for configlets
For a background, see issue #399

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-23 08:55:42 +01:00
Joachim Wiberg 5913217808 test: add finit.d/available and finit.d/enabled/ dirs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-23 08:17:03 +01:00
Joachim Wiberg 2d9c63e48e test: actually verify the service asserts ready before continuing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 16:31:45 +01:00
Joachim Wiberg 77cf72cb40 test: regression test to reproduce issue #392
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 12:03:33 +01:00
Joachim Wiberg adb25d52cd test: minor, rename test case native -> pid
We now support notify:pid, so let's use it, even though it's the default.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 10:13:13 +01:00
Joachim Wiberg 53aa195ad5 test: update, pid/B is no longer assert by Finit if notify != pid
As of Finit v4.6 we no longer assert the PID condition for services
declaring themselves as notify != pid.  We replace D with a forking
service to catch any future regressions in the pidfile plugin.

No need to check reload PID of D, it is enough to check PID of C.

Also, reduce the number of retries at startup.  If we haven't gone
up within 10 sec with this tiny config something is really wrong.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 06:09:35 +01:00
Joachim Wiberg ca90bbfb04 Fix #387: sanity check environment variables before sourcing
This fixes an issue when finding a global environment variable with
spaces in the variable name:

    set COLORTERM=yes

Literally, 'set COLORTERM' was the name of the variable.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 19:07:54 +01:00
Joachim Wiberg 180faf8a40 test: minor, disable debug as final step in function
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 09:04:15 +01:00
Joachim Wiberg 60bf858302 test: extend svc-env.sh with more common use-case
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 08:37:05 +01:00
Joachim Wiberg 2b4f89ecd1 test: cannot use absolute path to initctl (distcheck)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 22:09:54 +01:00
Joachim Wiberg da6298aecd test: wait for runparts to finish
In Finit v4.5 we've moved the start of rc.local and runparts to the
transtion from bootstrap to multi-user, so we must give it time to
finish.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 21:04:02 +01:00
Joachim Wiberg 304a096877 test: wait for runparts to finish
In Finit v4.5 we've moved the start of rc.local and runparts to the
transtion from bootstrap to multi-user, so we must give it time to
finish.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 18:16:24 +01:00
Joachim Wiberg 50e587f447 test: new test, verify env:file variable expansion
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 13:31:36 +01:00
Joachim Wiberg fb4c560196 test: shellcheck fixes to new test
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 13:31:31 +01:00
Joachim Wiberg 8b5fa5eeaa test: add optional argument to sep() helper function
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 13:31:01 +01:00