This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly. Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.
When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:
1. deassert all net/ conditions
2. open a new (temporary) netlink socket
3. send RTM_GETLINK and re-assert all interfaces using nl_link()
4. send RTM_GETROUTE and re-assert all routes with nl_route()
Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves. This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.
The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down. When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch restores parts of 4febd28, but in a more orderly fashion, in
order to get a standard Debian system to boot properly with X and tools.
The patch adds fs_finalize() which checks if /dev/sh/, /dev/pts, /run,
and /tmp have been mounted properly from /etc/fstab. If not, then the
function makes sure to mount tmfps (or devpts) file systems as expected
by most modern systems.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch changes the behavior of SIGUSR1. Previously USR1 could be
used to halt a running Finit system, similar to BusyBox init. However,
compatibility with sysvinit and systemd has been deemed more important.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name. This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c
https://code.woboq.org/linux/linux/net/core/dev.c.html#1020
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
sulogin should return OK (exit code 0) when the user presses Ctrl-D,
regardless of the prompt shown. Otherwise Finit may look for another
sulogin to run straight after this one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Simplify build system.
The logit tool is, as of v4.0, installed into /libexec/finit/logit and
thus not part of the system $PATH. If a sysadmin or distro wants to
remove it from the system it's entirely possible since Finit always
checks for logit availability before attempting to use it.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Before 4e5d06b the only way to go into rescue mode was to skip certain
steps and then attempt to load /lib/finit/rescue.conf. After 4e5d06b
we keep the old handling as a fallback in case early sulogin fails.
The new tty option 'rescue' is added, which recue.conf is updated with.
This option implies notty mode and will try sulogin (again) before it
falls back to start /bin/sh as a login shell.
The reason we keep this is to be able to handle all possible use-cases
and also allow sysadmins to set up the behavior that fits their needs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch does two things:
1. A system with a root account that has no password is now
allowed to login without password, as one expects.
2. A systems with a locked root account, is treated as (1).
The latter of the two may very well turn out to be a really bad idea.
Much angst have been poured into it, yet the end decision is to allow
access.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Most major init systems have a way to start a rescue shell. This is
usally started when the string `rescue` is read from the kernel's
command line.
The traditional Finit way of handling this has been to skip certain
phases of the standard boot, skip /etc/finit.conf et al, and go for a
/lib/finit/rescue.conf instead. This pratice has been imroved over
the last few commits with a sulogin. However, there was no way to
resume boot, like most other init systems offer.
This patch implements a very simple rescue mode, utilizing the new
sulogin, replacing the old (and experimental) emergency shell. If
Ctrl-D is pressed at the maintenance login prompt the boot is now
resumed. The same goes for exit/Ctrl-D from the maintenace shell.
The preferred sulogin is the bundled /libexec/finit/sulogin, but
if that isn't installed, the first one in $PATH is used. If no
sulogin at all is found, Finit proceeds as before this patch, to
skip certains steps and go for a /lib/finit/rescue.conf. Hence,
al steps can be controlled by an administrator.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- splice out sh() as a separate function
- make sh() session leader and set controlling TTY (TIOCSCTTY)
to make it a proper login shell with Ctrl-C functionality
- simplify call to execl()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.
Essentially, only services in rescue.conf should run in rescue mode.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Check if watchdogd *and* `WDT_DEVNODE` exists before registering the
built-in watchdogd at boot
- Update bootstrap.md with this additional constraint
- Update config.md with references to bootstrap and the new constraint
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes an issue where services that support SIGHUP are not
properly stop/started on changes to their command line arguments.
A change to a service's env: file, e.g. /etc/default/foo for service
foo, must also be counted as a change to the foo args.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This changes the default to redirect output from run/task/services to
/dev/null. Use --disable-redirect to get the old pre v4.0 behavior.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We need at least the softdog watchdog driver loaded for proper watchdog
reset at reboot. This can safely be replaced with a hardware specific
module that provides /dev/watchdog ... without one Finit will try to
restart the built-in finit-watchdog service 10 times to no avail.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch changes the configure option to enable the built-in watchdog
from --enable-watchdog to --with-watchdog[=DEV]. This is the convention
for features that take arguments.
Also, improve log messages to aid debugging when finit-watchdogd does
not start properly. This means flushing logs to syslogd with closelog()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch restores the start of the built-in/bundled watchdogd. It is
tracked in the `wdog` variable and handled as an exception at shutdown.
This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external. External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
If we get a notification and the service dies immediately, and also
removes its pid file, we need to take corrective action.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch updates the service state machine with two new states: SETUP
and CLEANUP. If an executable pre:/path/to/script is defined for a
service, it is called every time the task goes to READY state. If an
executable post:/path/to/script is defined for a service, it is called
when the task goes to HALTED state.
Each of these two scripts default to a three (3) second execution time
before they are SIGKILLed. This can be adjusted with the `kill:SEC`
option for the service. There are no execution guarantees, nor are
there any way of detecting if the script was killed before completion or
not -- except for running Finit in debug mode and inspecting the result
printed by system_monitor().
Note: the post:script MUST be idempotent since transitions between READY
and HALTED can take place any number of times before a task goes
to its RUNNING state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
These two BusyBox daemon's run in concert so it makes sense they also
share the same cgroup. In Finit that means sharing the same .conf file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Before this patch bootclean() ran first in setup() which caused to to
remove the entire /var/run/finit directory, and other files as well,
created earlier. Only possible fix is to split clean and setup in
two and make sure to call clean as soon as we've mounted everything.
Note: this introduces a new behavior, and anyone hooking into the
same point to do good-stuff(tm) may be affected by this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Avoid using reserved C++ keyword 'new'
- Rename new -> next
- Rename old -> prev
- Add debug for value being set to cond path
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Drop vhangup(), how did things ever work *with* this in?!
- setsid() + TIOCSCTTY are best buds, see notty code
- Allow storing any non-NULL string as tty->dev, expand in service_register()
- Reorder parse_cmdline_args(), we need to expand @console to current dev
- Fix tty arg parser, swapparoo for external getty
- Refactor tty_atcon(), iterated over by service_register()
- New arg format, need to translate for old run_getty2()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch re-enables the fallback shell handling after the big TTY
refactor. We do this by allowing the fallback shell to run as a
regular service.
Note: this also adds the "hidden" support for 'notty' option for
tty configurations stanzas. This is just to pick up from
where the kernel left us, reusing stdin + stdout.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>