Commit Graph
58 Commits
Author SHA1 Message Date
Joachim Nilsson 8b8ddc43b5 Refactor: Further API cleanup -- hide svc_t internals.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-29 01:50:21 +02:00
Joachim Nilsson 838ec0423d Fix: Loss of dynamic service on second reload (unmodified).
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-29 01:25:45 +02:00
Joachim Nilsson d0da3b8b98 Followup to 'initctl with process name as well as JOBID'
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 17:56:41 +02:00
Joachim Nilsson 577622c945 Add support for calling initctl with process name as well as JOBID
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit.  When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances.  For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 15:54:47 +02:00
Joachim Nilsson 6c58a7d774 Fix Coverty CID #96209: Dereference NULL return value.
The new iterators `svc_inetd_iterator()` and `svc_dynamic_iterator()`
used unsafe constructs that could cause them, at least the latter, to
dereference a `NULL` pointer.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:06 +02:00
Joachim Nilsson 1a1f24721f Refactor: introduce telinit and a new initctl tool w/ API
- Reduce size of `helpers.c`, for linking against new `initctl` tool,
  by moving out functions to `pid.c` and `exec.c`
- Add `AF_UNIX` API to Finit, to complement old `/dev/initctl` FIFO
- Let old FIFO API be used by init/telinit: `init <q | 1-9>`
- Move all advanced initctl code from `client.c` to `initctl.c`, yes
  its a bit confusing to call the *new* tool the same as the old FIFO
  but this is more in line with what, e.g Upstart does.
- Move all advanced server side code from `plugins/initctl.c` to `api.c`
- Update TODO with upcoming inetd syntax change and dynamic events.
- Temporarily fix display of inetd services from `initctl status -v`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-13 12:26:16 +02:00
Joachim Nilsson 24e1d284ad Add support for finit <stop|start|reload|restart> JOB
This patch further extends the capabilities of the client with the
ability to control the running state of services:

    finit <stop|start|reload|restart> JOB

Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch.  A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier.  See the output of `finit status` for the JOB id.

Also, with the introduction of multiple instances we broke support for
multiple related inetd services.  This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 08:32:49 +02:00
Joachim Nilsson 0dd97de046 Add --enable-quiet to configure, makes Finit real quiet.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 15:57:11 +02:00
Joachim Nilsson 97a48ec5fb Refactor: move advanced service methods from svc.c --> service.c
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 03:23:46 +02:00
Joachim Nilsson 2c1f3b1f7a Make sure to also reload all .conf files in /etc/finit.d/ when changing runlevel.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-05-31 22:45:30 +02:00
Joachim Nilsson f5584ecc3c Add two new hook points: HOOK_SVC_RECONF and HOOK_RUNLEVEL_CHANGE.
These two new hooks run when SIGHUP is received and when changing
system runlevel.  The hooks are called when all services have been
stopped, just before starting up new/modified services.  Making it
the perfect hook for reconfiguring the system/hardware before new
services or modified services are started up again.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-05-31 22:07:46 +02:00
Joachim Nilsson cb075560ed Add support for multiple instances of the same command
This patch adds support for starting and supervising multiple
services (run, task, or service) using an extra #ID number.

service #1 [2345] /sbin/httpd -f -h /http -p 80   -- Web server
service #2 [2345] /sbin/httpd -f -h /http -p 8080 -- Old web server

Also included in this patch is a fix for endless respawn of faulty
services.  For instance, a buggy daemon that crashes repeatedly will now
be stopped after 10 respawns.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-05-31 01:58:20 +02:00
Joachim Nilsson 687f52b0b5 Add support for adding/removing services from /etc/finit.d at runtime.
This patch adds support for adding and removing services from Finit at
runtime.  Configuration file stanzas for service, run and task may now
be written to files in /etc/finit.d/*.conf, using the exact same syntax
as before in /etc/finit.conf.  When a file is added, removed or modified
the user may simply SIGHUP Finit (PID 1) to activate the changes.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-05-31 01:55:39 +02:00
Joachim Nilsson 32587d341c Overhaul build system and add support for disabling inetd support.
This patch adds support for a configure script and with it
support for disabling inetd support.  See the output from

    ./configure --help

* Add configure script
* Sprinkle #ifdef fairy dust on svc.c when inetd support is disabled
* Use GCC built-in autodep calculator (-MMD -MP)
* Fix name space issue with include files, use relative paths
* Disable username/group name to uid/gid functions in static builds
* Bug out (error) if a user tries to build the bootmisc plugin static

Possibly fixes GitHub issue #5 and issue #6.

NOTE: The static build has not received any testing at all!

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-10 10:25:46 +01:00
Joachim Nilsson c769fbda0f svc.c: Add debug to svc_runlevel().
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-04 14:45:04 +01:00
Joachim Nilsson 703b7537cf Refactor inetd support to add support for switching runlevels.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-03-01 02:35:30 +01:00
Joachim Nilsson 12c470667f Only restart daemons when getting SIGCONT after SIGSTOP
Fix `restart_any_lost_procs()`, called when finit recovers from being
stopped for a while.  This function should not restart task/run/inetd
services when called -- must check for type `SVC_CMD_SERVICE` when
iterating over all registered `svc_t`, just like a regular lost pid.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:55:15 +01:00
Joachim Nilsson fc9758da8e Fix Coverity CID #87811 Double close
Fix double close of TCP socket introduced in GIT ded4b39,
replaced with closing all open stdio descriptors, which
shouldn't really be needed.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:39:30 +01:00
Joachim Nilsson 216701ce3c Attempt to fix Coverity CID #87810 Dereference null return value
Fixes, or rather works around the Coverity warning of possible NULL
pointer dereference.  (Not an error.)

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 16:34:38 +01:00
Joachim Nilsson ded4b3926e Refactor inetd support, now with support for custom ports and iface filtering
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth1:22/tcp  nowait [2345] /usr/sbin/sshd -i

In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively.  Attempting to connect
from any other interface is denied.  Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.

If eth0 is your upstream interface you may want to avoid using the
default port.  To run ssh on port 222, and all others on port 22:

    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i

This actually adds a deny rule for eth0 on ssh/tcp, implicitly.  You can
even list the services in the reverse order with the same result:

    inetd ssh/tcp          nowait [2345] /usr/sbin/sshd -i
    inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i

There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-26 01:37:11 +01:00
Joachim Nilsson 8c955836dd Load plugins before finit.conf is parsed, needed by internal inetd services
This patch is slightly sub-optimal, since it will causes us to load all
availble plugins, not just those referenced by finit.conf.  However, in
the short term perspective we need to reference internal inted services
provided by plugins from finit.conf, so the dependency order is clear.

In the midterm perspective we want to add support for SIGHUP to reload
finit.conf, but not plugins.  So again, this is an OK patch.

One fix would be to allow loading of all plugins, parse finit.conf and
then unload all unused plugins before continuing.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:04:36 +01:00
Joachim Nilsson 183022ebe4 Initial support for RFC 868 (rdate), internal inetd service.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-18 22:04:31 +01:00
Joachim Nilsson 58cc96115c Initial support for figuring out inbound interface for inetd connections
This patch adds initial support (only SOCK_STREAM verified!) for
figuring out the inbound interface for inetd service connections.

The intention is to use this later on for a very simple tcpwrappers
replacement, e.g: `deny telnet eth0 eth3`

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:26:54 +01:00
Joachim Nilsson b4b63d3722 Trap segfaults caused by service callbacks in separate process context
This patch traps segfaults caused by 3rd party service callbacks in a
separate process context.  Effectively preventing a single programming
mistake from taking down the entire system.  Previously it was up to the
callback coder to write error free code so that PID 1 did not crash.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-16 10:21:03 +01:00
Joachim Nilsson d6efe85a57 Silence launch of inetd services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:57:21 +01:00
Joachim Nilsson 51b27e8372 Revert "Use vfork() instead of fork() before exec()"
This reverts commit 074686b520.  Which
turned out to not work so well after all.  For instance, launching TTYs
in a background process completely blocked inetd services from even
starting up listening sockets ... proper fork seems to work fine though.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:45:09 +01:00
Joachim Nilsson a5b9f566b3 Initial support for inetd/on-demand services \o/
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-02-09 00:43:15 +01:00
Joachim Nilsson 6f6ab6bc33 Minor whitespace fixes
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-29 12:34:30 +01:00
Joachim Nilsson 425cd17e57 Initial conversion to use libuEv for all event handling.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-18 00:53:14 +01:00
Joachim Nilsson 074686b520 Use vfork() instead of fork() before exec()
If running on older Linux systems, or any BSD UNIX, vfork()
is more efficient when we are about to call exec() anyway.

For more info on vfork() vs fork(), see Stack Exchange:
http://stackoverflow.com/questions/4259629/what-is-the-difference-between-fork-and-vfork

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-01-06 23:38:47 +01:00
Joachim Nilsson 02a97e8d7d Fix various problems with unchecked return values from syscalls.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-11-27 00:12:07 +01:00
Joachim Nilsson d37c451e81 svc_start(): Fix out of bounds write to args[] array.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-11-26 17:20:27 +01:00
Joachim Nilsson a7ff1a61d5 svc_start(): Fix swapped arguments to dup2() and add close(fd), descriptor leak.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-11-26 17:17:47 +01:00
Joachim Nilsson 22ed4e7f73 svc.c - Break out nested function.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-10-31 14:58:13 +01:00
Joachim Nilsson 71fff76111 svc.[ch]: Fix possible out of bounds and NULL ptr deref
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-04-12 16:41:20 +02:00
Joachim Nilsson 1d6cbe31fe Initial support for restarting lost processes during norespawn
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2014-02-24 23:33:38 +01:00
Jonas Johansson cb874d7a94 Handle SIGHUP requst from service when switching runlevel
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2014-02-24 23:33:38 +01:00
Joachim Nilsson 4171fbdfd3 Store RUN_LVL in UTMP and change RUNLEVEL_BOOT from 10 to 0
Standard init implementations save current and previous runlevels
in utmp, now finit does too.  Also, the initial runlevel at boot
has changed from 10 to the more obvious 0.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-06-06 18:19:26 +02:00
Joachim Nilsson 0f60aa2289 Refactor TTY code to honor runlevels and use I/O plugin to watch /dev
Add support for runlevels to tty command and support for reading baud
rate and TERM variable from finit.conf.

The tty-watcher thread has been converted to a standard I/O plugin.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-06-06 18:19:26 +02:00
Joachim Nilsson f97aab4699 Rename stat_restart_counter --> restart_counter
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-06-06 18:19:18 +02:00
Joachim Nilsson 25cc9f3b9b Improve runlevel support by adding a bootstrap phase, also adds task/run cmd
Most systems need an early bootstrap phase for one-shot tasks and
necessary one-time probing.  This phase usually runs well before any
networking is setup.  This commit adds support for that 'S' runlevel,
and also extends the number of possible total runlevels to nine.

For the one-shot tasks that run in bootstrap two new finit.conf cmds
have been added:

   - task: For one-shot tasks that can be started in parallell
   - run:  For one-shot tasks that must run in sequence

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-06-04 09:25:05 +02:00
Joachim Nilsson c3b76fdccf Add basic support for runlevels and bugfix FIFO I/O plugins
Like most other init implementations do, when entering runlevel 1, finit
creates the file /etc/nologin to prevent users from logging in during
single-user mode, this file is then removed upon leaving runlevel 1.

Also, bugfix how FIFO I/O plugins are handled in finit.  A FIFO will
need to be reopened by the server side when the client closes the pipe.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-05-19 19:01:44 +02:00
Joachim Nilsson 89675403d8 Add support for service restart counter.
This commit adds a statistics counter to the finit svc_t process struct
which is incremented every time a process is restarted by the service
monitor.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2013-05-19 18:00:31 +02:00
Joachim Nilsson 7e3465a022 Clear recorded PID of lost service.
Many callbacks check their svc->pid to determine SVC_RELOAD or SVC_START,
they rely on it to be updated.  When a service is lost we must therefore
clear its recorded PID before asking the callback what to do.

Also, swap comparison in debug code for dumping service arguments ...

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-07 02:00:16 +02:00
Joachim Nilsson f29d2733c7 Fix incorrect use of variable arguments in run_parts() and simplify code
The run_parts() implementation used variable arguments in a bad way,
resulting in it not working properly.  Replaced va_*() code with a
simple cmd argument that's passed to each script called.

Also, the opendir()/readdir() code has been replaced with scandir()
using regular alphasort(). This simplifies the code somewhat as well.

Otherwise, minor cleanups.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-06 15:45:42 +02:00
Joachim Nilsson af59174e49 Prevent endless restart of non-existing services and support start-stop scripts
Sometimes people type in the wrong path to a service directive in
finit.conf, or the executable isn't installed.  This commit makes
sure to check if the command exists before attempting to start it.
This also means that we now require service commands to start with
/ to indicate an absolute path.  We used to search the PATH for a
suitable executable, using execvp(), but that's rather insecure as
well, so we now use only execv().

Also, added support for adding "start" or "stop" to entries found
in /etc/finit.d starting with SNNname, or KNNname, where NN is a
number.  This makes it possible to simply import sysvinit style
start scripts from /etc/rcS.d and /etc/rcN.d/.

The alsa-utils plugin also had some minor fixes, added -g option
to ignore non-existing soundcards and fixed cut-paste bug on the
_d() debug messages.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-06 13:56:26 +02:00
Joachim Nilsson 65c9e7ebc6 Fix I/O plugin watcher, load plugins earlier to enable a new early hook!
Restructure start by calling the plugin loader earlier. This makes it
possible to run hooks even earlier.  This also adds a new hook:
HOOK_ROOTFS_UP which runs as soon as the system root (/) is available.

Another very notable change is the slow refactor of helpers.c into a finit
helper library called libite.so (-lite). This is a light-weight

Also, lots of misc. fixes all over the place. Signal handling still really
needs to be looked into once more!

Makefile:
        Add dependency handling for parallell build
        Add libite library

ChangeLog:
        Update with new 1.4 release. There is a lot of fixes!

libite/:
        Collection of utility functions and C library extensions for
        finit & its plugins

reboot.c:
        New reboot tool. Simply sends SIGINT to PID 1

finit.h:
        Cleanup old LISTEN_INITCTL define, code is in an optional plugin now

finit.c:
        Let mdev/udev run *after* cls()
        Add useful debug statement for /proc/cmdline
        Earlier plugin load => new early hook point
        Show OK/FAIL for total plugin load, not for each plugin => speedup

helpers.h:
        Rename syslog macros to prevent common name clashes (DEBUG/ERROR)
        Add __FILE__ to _e(), _d() and _pe() macros

helpers.c:
        In ifconfig() the addr and mask arguments are now optional
        The copyfile() has been moved to libite.so
        Temporarily remove const directive from some functions to build
        Use DFLSIG() macro in run_getty() to simplify code

plugin.h:
        Add new HOOK_ROOTFS_UP hook

plugin.c:
        Fix init_plugins() to actually register the plugin's I/O fd
        Skip verbose listing of all plugins in plugin_load_all()

svc.c:
        svc_start(): Dito

plugins/Makefile:
        Inherit CFLAGS and LDFLAGS, but make sure to filter out -rdynamic
        from LDFLAGS, it's used by the daemon, only

plugins/initctl.c:
        New includes after helpers.h refactor

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-02 08:25:50 +02:00
Joachim Nilsson 5116cd66ef Greatly simplify svc hook for external plugins
This commit removes a lot of unnecessary overhead for handling external
service plugins.  Instead of traversing the plugin array every time a
service callback should run we set the plugin callback in the svc_t when
the plugin is registered.

Also, make sure to check for norespawn/SIGSTOP in svc_reload() as well.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-02 06:39:26 +02:00
Joachim Nilsson f55f68d032 Cleanup and refactor of public plugin API
Improve upon API names, both internal and external, to make it clearer
where methods are located and clarify responsibility.

Add new Makefile target "dev" to create untagged development snapshots.

Bump version for upcoming release.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-10-02 06:39:19 +02:00
Joachim Nilsson 5e99b5e735 Minor API change.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-09-29 15:13:13 +02:00