Commit Graph
772 Commits
Author SHA1 Message Date
Joachim Wiberg 9842786453 cgroups: fix cpu.shares assignment and set memory hierarchy
- Fix obvious refactor mistake in cpu.shares assignment
- For unified memory hierarchy we need to set .use_hierarch=1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 12:27:46 +01:00
Joachim Wiberg 6d0c679e05 initctl: show comm and cmdline in ps output
The ps command currently only lists processes in the three main control
groups: init, system, user.  Kernel threads are not show at all.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:12:42 +01:00
Joachim Wiberg 5428dea5bf cgroup: refactor, use a unified hierarchy for finit
As of now, the default finit cgroup behavior is to use a unified
hierarchy of controllers under /sys/fs/cgroup/finit.

We mount cpu,cpuacct,cpuset,memory (if available) and gain the
ability to control our three major groups: init, system, user.

The default CPU share setup is ~10% for init and user, and 90% for
system.  These are guaranteed CPU shares to ensure we do not starve
PID 1 or user processes.  Support for configuring these limits will
be added in a later commit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:07:13 +01:00
Joachim Wiberg 4e84ecae89 Set umask(022) early, in fs_init(), and no place else
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:05:12 +01:00
Joachim Wiberg 084b4ce8d3 cgroup: minor refactor/simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:40:52 +01:00
Joachim Wiberg 46995fe446 Add mksusbys() to helpers.c, a kind-of tmpfiles.d in C
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 00:37:47 +01:00
Joachim Wiberg 600b2874e6 initctl: add bug report address to usage text, like finit -h
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 17:08:36 +01:00
Joachim Wiberg b080b970b7 initctl: don't warn on missing env file if it's optional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 17:08:12 +01:00
Joachim Wiberg 6106574e13 initctl: minor refactor, use systemf() instead of snprintf+system
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 16:49:01 +01:00
Joachim Wiberg 2385a1209b initctl: don't fall back to default command for wrong commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 16:48:58 +01:00
Joachim Wiberg e8b942cf95 Fix regression in starting built-in services, introduced in 5b9d990
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 16:28:16 +01:00
Joachim Wiberg ac17d7f5a7 Silence output from gzip in logrotate()
- system may not have gzip (we're opportunistic)
- system may not have the log file (yet)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 13:26:50 +01:00
Joachim Wiberg 1edc4356a6 initctl: improve error message for unprivileged users
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 13:26:16 +01:00
Joachim Wiberg 9f06a2db99 Silence developer API debug message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 13:25:50 +01:00
Joachim Wiberg 8aba63a9e3 Track oldpid of services to fix empty pid in restart message
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 00:13:15 +01:00
Joachim Wiberg 3d98ad293b Restore telinit symlink to finit, compat only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 23:59:39 +01:00
Joachim Wiberg cbec78dbbc initctl: show pid file and condition for foo in 'status foo' command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 22:01:42 +01:00
Joachim Wiberg 572291a1d9 Don't guess pid file name, either there's one declared or not
The previous patch just added dynamic tracking of non-declared pid
files, so we no longer need to make stuff up.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 22:00:29 +01:00
Joachim Wiberg 280608f30e plugins: pidfile: track PID file in svc, if svc has none declared
Services that create their own PID files usually don't declare one with
Finit.  This patch adds support to track those PID files anywayt at
runtime for the purpose of identifying match svc_t when a PID file is
removed, i.e. when a service exits.

 - On IN_CREATE the pidfile.so plugin saves the pid file name in svc_t
 - On ON_DELETE the pidfile.so plugin finds svc_t based on pid file

Quicker tracking and less dead code, win-win.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:56:49 +01:00
Joachim Wiberg 5c4146cfe4 Export pid_file_set() function, useful to other subsystems as well
Rename, refactor, and export.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:52:44 +01:00
Joachim Wiberg 30e3f5a33c Wait only one second at shutdown/reboot for lingering processes
Transitioning to runlevel 0 or 6 handles graceful shutdown of any
managed run/task/sysv/services.  So we can replace the old 2 sec delay
with a shorter one for any non-managed still lingering process.

Also, some minor cleanup.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:48:49 +01:00
Joachim Wiberg 2c12379a30 Only reload .conf files when not going to shutdown or reboot
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:47:22 +01:00
Joachim Wiberg 5f026c8149 initctl: when svc has status missing, highlight what is missing
To aid with debugging, highlight if env file, binary, or both are the
missing component(s) and causing status 'missing'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 15:58:36 +01:00
Joachim Wiberg 90005235e8 initctl: minor, rename local variable
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 15:11:16 +01:00
Joachim Wiberg 6b688c4211 Refactor, share env helper fns with initctl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 15:10:10 +01:00
Joachim Wiberg bdf5f8fc90 initctl: show halted state status reason in bold everywhere
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 14:35:09 +01:00
Joachim Wiberg 79f7a8ccfb Reclaim 900 msec in boot time from final_worker() at bootstrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 14:03:15 +01:00
Joachim Wiberg 3b19db04e3 initctl: add cond, user, group and visual hints for status command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 12:52:05 +01:00
Joachim Wiberg 93402b81d7 initctl: disable ctrl chars also in runlevel_string() when -p
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 12:51:23 +01:00
Joachim Wiberg 6dec4c9ca0 Set default user/group for services that don't specify any
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 12:49:14 +01:00
Joachim Wiberg 548acf27cf Minor refactor, rename RESPAWN_MAX -> SVC_RESPAWN_MAX
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 12:48:44 +01:00
Joachim Wiberg cd0bc57ca8 Clear stale PID conditions when a service stops
Protect against corner cases where pid conditions are not cleaned up.
We don't want such conditions to remain asserted when the process has
terminated.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 11a3318c02 Properly set status 'missing' for missing binaries and/or env files
When we try to start a service/run/task we call whichp() to see if the
binary exists, either tha absolute path given in the .conf file, or in
the $PATH we run with.  If binary, or the env: file, doesn't exist we
now set svc_missing() state.

On `initctl reload` we unblock the service to be able to check again.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 2711b27971 plugins: pidfile: tricky zebra doesn't close its pid file
This patch fixes a few really hard problems wrt PID files:

 1. Listening for IN_CREATE events means we get notified immediately by
    the kernel when someone calls open()/fopen() on a PID file.  Reading
    the contents returns 0, thank you atoi() ... so we drop IN_CREATE
    and instead look for IN_CLOSE_WRITE, there fixed it!  Not quite ...

 2. Some programs, like Zebra, and other Quagga/Frr daemons, don't
    close() their PID files after creation.  Instead they ftruncate()
    and keep them open, and locked.  Presumably to get a mechanism to
    detect already running instances -- messes life up a bit for the
    rest of us though.  So we need to read files after IN_MODIFY too.

 3. We also want to track IN_DELETE so we can deassert conditions when
    services exit gracefully and clean up their PID files

The rest fo the commit is debug instrumentation changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 8000d361b3 initctl: restore 'cond [set|clr] foo' for user-defined conditions
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user.  That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.

This patch restores the behavior, albeit in a very reduced and simple
format.  All conditions set with this command are constrained to the
'usr/...' namespace.  No subdirectories are allowed.  The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:

    initctl cond set foo:2

creates a static/oneshot condition in /run/finit/cond/usr/foo:2

These conditions are static and are fully handled by the user.  The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.

This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory.  When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.

For instance, the following service is not started by default at boot:

    service <usr/foo> myservice -- MyService

However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.

Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions.  This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg e3c8febe3b Refactor; common nomenclature, ordering, possib. security fix
- Use _PATH_foo for all condition paths, *with* trailing /
- Read condition file first, may not exist, in which case we save time
- Change from libte makepath() to mkpath(), this changes from hard-coded
  0777 perms on all cond dirs to 0755 -- possible security fix

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 32ca117949 initctl: refactor command line parser, use concept from mroutectl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg b966d031c8 initctl: enable plain mode for ls and utmp commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-09 21:30:11 +01:00
Joachim Wiberg 905c2678a3 Fix path to fallback console and handle leading /dev from cmdline
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-08 09:33:16 +01:00
Joachim Wiberg 7d429bdbb1 initctl: restore -p,--plain output for headings and ps listing
This is the same output style as used in the mroutectl and pimctl tools.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 23:30:13 +01:00
Joachim Wiberg 4d05bf9359 Mark affected services as dirty if their rdeps are dirty
Provided a configuration that looks like this:

ospfd.conf:
    service [2345] <!pid/zebra> log ospfd -A 127.0.0.1 -u root -g root -- OSPF daemon

zebra.conf:
    service [2345] <!> log zebra -A 127.0.0.1 -u root -g root -- Zebra Routing daemon

If zebra.conf is changed, we restart it when `initctl reload` is issued.

This change ensures that ospfd is also restarted, because ospfd depends
on zebra, we must restart it too.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 14:52:19 +01:00
Joachim Wiberg 35b200d3a9 Validate inotify event against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 70a1acc210 Highly unlikekly, but chdir() needs to be checked
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:40:25 +01:00
Joachim Wiberg ecaf111a4b plugins: tty: possible out-of-bounds read in inotify_event parser
This is a major refactor to use the same construct as in the pidfile.so
plugin to parse kernel inotify events for when TTYs are added removed
from the system.

Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:58:55 +01:00
Joachim Wiberg 32ec25b070 Check return value from remove(), found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:34:23 +01:00
Joachim Wiberg 305ad302f2 Refactor, reduce code duplication
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:28:54 +01:00
Joachim Wiberg 790a316607 Log rotate: improved handling of return values from syscalls
- Align the two implementations in logit.c and utmp-api.c
 - Use libite APIs to handle common constructs
 - If gzip fails, don't remove rotated-to file
 - Don't try gzip if rename fails
 - Issues found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 77aa941e84 Mounting devtmpfs may fail if already mounted
Ignore EBUSY errors, the kernel has the ability to automount /dev as
soon as the rootfs has been mounted.  This may be added to procfs and
sysfs later, so we make this a general change in fs_init().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:48:02 +01:00
Joachim Wiberg e0a65f67c9 Minor, staticify, reduce includes and allow debug to kmsg
The loglevel setting should control all logging, regardless of
where we target it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-06 23:55:54 +01:00
Joachim Wiberg 3ed291789c Fix GCC warnings with _FORTIFY_SOURCE=2
- Decleare some return values with (void)fn(), for cases where
  we don't care (dropping table headers), or best effor
- Check return value from fgets() and chdir() in some cases that
  are valid, i.e., continuing execution is pointless

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 12:36:48 +01:00