It would be good if we can control the services more specifically with
the following parameters like:
restart:N - how many times shall the service to be restarted on
failures (<10), the default max is 10.
restart_tmo - the timeout of the restarting.
norestart - dont restart on failures.
oncrash - once all retrying also fail, how to deal with it,
rebooting or ignoring the failures.
Signed-off-by: Robert Andersson <robert.m.andersson@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
It's configurable in /etc/login.defs as NOLOGINS_FILE, avoid to hard
coding it here, introduce a macro FINIT_NOLOGIN_PATH instead which is
configurable from compiler flags, it's not defined, then back to
_PATH_NOLOGIN from /usr/include/paths.h.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
fastboot: once enabled, fsck would be skipped on filesystems listed in
/etc/fstab.
fsckfix: once enabled, 'fsck -ys' would be run instead of 'fsck -a',
and check the return value larger than 1 as a failure and goes
to login console.
They are both disabled by default, no functional changes unless an end
user choose to enable them.
The idea derives from Sysvinit's "FASTBOOT" and "FSCKFIX".
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
The iterator function getmntent() is not stable. It may skip
entries if the contents of the iterated file changes, which
is the case with /proc/mounts when filesystems are unmounted.
As a result, some filesystems were never unmounted.
To fix this, iteratation is now restarted after every
sucessful unmount.
Signed-off-by: Robert Andersson <robert.m.andersson@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
"protected" is a C++ key word, replace it with "is_protected" avoid
compiling failures with C++ compiler.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
There are small typos in:
- doc/conditions.md
- src/mount.c
- src/svc.h
Fixes:
- Should read `satisfied` rather than `satsifed`.
- Should read `process` rather than `prorcess`.
- Should read `measure` rather than `meausre`.
We've had several logit() messages of LOG_INFO level that never
really made it to syslog because we classified it as "debug".
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds "the missing" first runlevel log entry when Finit has
printed the console banner and begins its bootstrap phase.
At this point we know syslogd hasn't been started yet, so we rely on
logit() to redirect this to /dev/kmsg in the meantime. Later syslogd
will pick this up, see that it's not from the kernel, and log it to
the proper log file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
If any of these mount() calls fail, not counting EBUSY because that
would mean sth is already mounted, there really isn't much we can do.
So the least we should do is warn on console if it happens.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Note, this is dead code, currently unsused in Finit. Possibly an
external plugin makes use of it, but even that is highly unlikely.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY". As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release. It is now possible
to also disable the heading entirely using --without-heading
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Shouldn't be needed for real cases, but we have seen automated scripts send
'\n' instead of '\r', or '\r' + '\n'.
Signed-off-by: Jacques de Laval <Jacques.De.Laval@westermo.com>
Similar to 6224166 (previous commit), this old code is a remnant of a
bygone era and not needed anymore.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Once upon a time, SIGSTOP was used to pause Finit during flashing (MTD)
of a system image. This to prevent Finit from accidentally starting any
programs, i.e., reading from flash disk during or after upgrade.
This was quite intrusive, and has possible nasty side effects, e.g., any
process with root access sends SIGSTOP prevents TTY login. So this patch
now removes the functionality and recommends using a dedcicated runlevel
for such critical tasks instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a service is started and then stopped before it has created it's pid file,
it could be left forever in the "stopping" state, if we don't reset the
starting flag.
Signed-off-by: Jacques de Laval <Jacques.De.Laval@westermo.com>
The waitpid() function can return -1 due to EINTR (signal), so we should
restart it to make sure we collect all zombies.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program. However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.
The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
It has barely worked and only caused more problems than solved annoying
issues. We have one console for output, /dev/console, which the kernel
sets up for us.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Also, fix default: case in error handling, must always continue back to
poll() on any recv() error.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Progress at startup has been hidden for services w/o -- description, but
for some reason this check was not added to service_stop(). This patch
rectifies the situation, finally.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds a `respawn` flag for services and ttys, always set for
ttys, that allows bypassing the crash/restart counter and immediately
restart a 'crashing' service.
For tty type services this is the expected behavior, but for regular
services it is not. That is why `respawn` flags is not advertised in
the docs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
By default, Linux gives us /dev/console for output. This is a pseudo
device that uses the same actual device as the last console=foo listed
in /proc/cmdline. The last one listed is the main console, which is
also the *first* one listed in /sys/class/tty/console/active, so we skip
that when we check for system consoles to avoid duplicating output.
The getty code in tty.c currently has its own handling of @console,
which we keep for now. Ideally, however, the code should be merged.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
By moving the built-in getty to a stand-alone bundled getty we can now
refactor the old run_getty() functions into a single one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>