Commit Graph
154 Commits
Author SHA1 Message Date
Joachim Wiberg b852878a4a Follow-up, coding style fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-09-09 09:10:16 +02:00
Ming Liu 940f1f7486 Introduce two more configure options
fastboot: once enabled, fsck would be skipped on filesystems listed in
          /etc/fstab.
fsckfix: once enabled, 'fsck -ys' would be run instead of 'fsck -a',
         and check the return value larger than 1 as a failure and goes
         to login console.

They are both disabled by default, no functional changes unless an end
user choose to enable them.

The idea derives from Sysvinit's "FASTBOOT" and "FSCKFIX".

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-09-09 09:08:14 +02:00
Joachim Wiberg 522a06f864 Merge pull request #181 from yangfl/typo
Fix typo
2021-06-25 07:43:08 +02:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg f0622a692e Minor, format style change of comment block
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg ef7042dd9d finit: early log, "entering runlevel S", just after printing banner
This patch adds "the missing" first runlevel log entry when Finit has
printed the console banner and begins its bootstrap phase.

At this point we know syslogd hasn't been started yet, so we rely on
logit() to redirect this to /dev/kmsg in the meantime.  Later syslogd
will pick this up, see that it's not from the kernel, and log it to
the proper log file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-22 17:20:17 +02:00
Joachim Wiberg 47fbe49861 Wrap all mount(2) calls so we at least get an error message
If any of these mount() calls fail, not counting EBUSY because that
would mean sth is already mounted, there really isn't much we can do.
So the least we should do is warn on console if it happens.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-14 11:20:08 +02:00
Joachim Wiberg 39d879f240 Add support for auto-detetcing OS heading for progress
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY".  As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release.  It is now possible
to also disable the heading entirely using --without-heading

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-05 14:28:49 +02:00
Joachim Wiberg 9867fd82df Check correct struct member to determine if / has 'ro' flag
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 12:50:48 +02:00
Joachim Wiberg 09b9e26b2d fs_init(): skip mounting proc/dev/sys if already mounted
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 17:35:07 +02:00
Joachim Wiberg 25683221cc Set default envs like sysvinit and busybox does; TERM, LOGNAME, USER
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 13:22:50 +02:00
Joachim Wiberg c251304146 Refactor sys condition plugin into a standalone keventd
This patch is a refactor of the prototype sys condition plugin.  It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition.  The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them.  This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:31:08 +02:00
Joachim Wiberg b04dc4d457 Ensure services in plugins and from finit.c belong to a cgroup
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup.  This is a workaround to ensure they are assigned one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:27:59 +02:00
Joachim Wiberg 3f3e70c686 Mount /dev/pts with gid of tty group and set nosuid, noexec flags
Note, this code only runs if /dev/pts was not mounted in /etc/fstab

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 073b040981 Prevent user DoS by mounting /run/lock as separate tmpfs
This patch does several things related to /run and system reliability.

 - Mount /run with MAX 10% of usable RAM
 - Create and mount /run/lock as a separate tmpfs with max 5 MiB

As a spin-off, this patch also fixes permisions on /run/lock to 0777
so regular users can create lock files.

Note: none of this code runs if /run is mounted alread in /etc/fstab

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 6fc71b7528 Follow-up to a1af8e8: mount /tmp with perms for all users
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 565820325b Follow-up to a1af8e8: nodev is a mount flag as well
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-04 07:36:41 +02:00
Joachim Wiberg 6bb4d67d92 Follow-up to a1af8e8: fix mount options vs mount flags
The nosuid, noexec, and relatime arguments are not mount options, but flags.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-04 07:34:39 +02:00
Joachim Wiberg a1af8e8687 Follow-up to 4febd28: restore mount of /dev/shm et al for Debian
This patch restores parts of 4febd28, but in a more orderly fashion, in
order to get a standard Debian system to boot properly with X and tools.

The patch adds fs_finalize() which checks if /dev/sh/, /dev/pts, /run,
and /tmp have been mounted properly from /etc/fstab.  If not, then the
function makes sure to mount tmfps (or devpts) file systems as expected
by most modern systems.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-02 15:21:50 +02:00
Joachim Wiberg 4e5d06b580 Replace experimental emergency shell with actual rescue mode
Most major init systems have a way to start a rescue shell.  This is
usally started when the string `rescue` is read from the kernel's
command line.

The traditional Finit way of handling this has been to skip certain
phases of the standard boot, skip /etc/finit.conf et al, and go for a
/lib/finit/rescue.conf instead.  This pratice has been imroved over
the last few commits with a sulogin.  However, there was no way to
resume boot, like most other init systems offer.

This patch implements a very simple rescue mode, utilizing the new
sulogin, replacing the old (and experimental) emergency shell.  If
Ctrl-D is pressed at the maintenance login prompt the boot is now
resumed.  The same goes for exit/Ctrl-D from the maintenace shell.

The preferred sulogin is the bundled /libexec/finit/sulogin, but
if that isn't installed, the first one in $PATH is used.  If no
sulogin at all is found, Finit proceeds as before this patch, to
skip certains steps and go for a /lib/finit/rescue.conf.  Hence,
al steps can be controlled by an administrator.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 21:32:35 +02:00
Joachim Wiberg fe334135ce Fix small memory leak, use whichp() to query, not which()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 19:47:15 +02:00
Joachim Wiberg 6dced29b49 Add another constraint for the built-in watchdog, device exists
- Check if watchdogd *and* `WDT_DEVNODE` exists before registering the
   built-in watchdogd at boot
 - Update bootstrap.md with this additional constraint
 - Update config.md with references to bootstrap and the new constraint

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 10:33:57 +02:00
Joachim Wiberg dd437bf0a5 Follow-up to 18ab7d3: restore start of built-in watchdogd
This patch restores the start of the built-in/bundled watchdogd.  It is
tracked in the `wdog` variable and handled as an exception at shutdown.

This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external.  External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg f17b5b3cd3 init: move bug report+homepage from -h to -v
Also, detect progname to improve usage text slightly.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 05:52:36 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg a24fc941a6 telinit: call initctl with '-b' to prevent screen size probing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-29 22:23:34 +02:00
Joachim Wiberg f307ad060b Follow-up to 0641b1a, prevent hang regression in bootstrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-28 16:38:07 +02:00
Joachim Wiberg 0641b1a73e Split finalize() in two separate tasks
The finalize() function is a bit too long, which means it may block the
API socket initctl (from the final runlevel switch at the beginning) use
to contact os via.

We should perhaps break it up even more, but at least once like this to
give the event loop a chance to interleave with an API callback.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-25 17:24:32 +01:00
Joachim Wiberg d9993860cb cgroup: add inotify support for cgroup.events
Replaces previous cgreaper.sh functionality for release notification and
cleanup of service groups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:38 +01:00
Joachim Wiberg 6a6f3a8291 cgroup: refactor for cgroups v2, much cleaner + unified hieararchy
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1.  Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.

Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
            in cgroups v1 was handled by cgreaper.sh.  This is fixed
	    in the next commit in the series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:35 +01:00
Joachim Wiberg 4e84ecae89 Set umask(022) early, in fs_init(), and no place else
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:05:12 +01:00
Joachim Wiberg 79f7a8ccfb Reclaim 900 msec in boot time from final_worker() at bootstrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 14:03:15 +01:00
Joachim Wiberg 70a1acc210 Highly unlikekly, but chdir() needs to be checked
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:40:25 +01:00
Joachim Wiberg 77aa941e84 Mounting devtmpfs may fail if already mounted
Ignore EBUSY errors, the kernel has the ability to automount /dev as
soon as the rootfs has been mounted.  This may be added to procfs and
sysfs later, so we make this a general change in fs_init().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:48:02 +01:00
Joachim Wiberg cf3d3f6f8e Properly check return value from mount(2) and display error message
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 10:15:46 +01:00
Joachim Wiberg 4bcfd606b4 Refactor screen_init(), use methods developed in pimd project
- Refactor screen_init()
  - use native impl. of TTY probing from pimd project
    - check if TIOCWINSZ works
    - check if we're running in watch(1), for initctl
  - check if ANSI goto(999,999) escape seq. works (invasive)
  - fallback to 80x24
- Drop screen_exit()
- Rename screen_init() to get_width(), for now, matching pimd
- Relocate call in main() to banner(), first fn to write to TTY

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:23:31 +01:00
Joachim Wiberg c001349dd3 Wrapper for init q and init -t sec 0, used by sysvnit shutdown
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 07:54:16 +01:00
Joachim Wiberg 7ef25abecf Refactor, use new iwatch module for inotify of Finit *.conf files
- Use iwatch, modeled after pidfile plugin
- Use one .conf watcher for all *.conf paths/files
- Use full path of conf file for changes, from realpath().
  This fixes a long-standing limitation on unique filenames
  for services, that absolutely nobody knew about

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:28:03 +01:00
Joachim Wiberg 70ca64a392 New cmdline options to control debug and progress/status
Modeled after systemd.show_status, currently without the 'auto' setting.

- finit.debug[=bool]
- finit.show_status[=bool]
- finit.status_style[=old,classic,new,modern]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:45 +01:00
Joachim Wiberg 35e4e0d073 Drop confusing splash cmdline and --enable-progress configure option
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer.  The
resulting code and configure script is a lot simpler to understand and
maintain:

- No more --enable-progress or --enable-progress-classic configure
  flags.  Instead a progress_style variable in helpers.c that can
  be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option.  This turned out to
  be *very* confusing to many users who believed it was some sort of
  graphical splash screen à la Plymouth.

Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:08 +01:00
Joachim Wiberg 10d4964106 Remove last traces of inetd support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 21:50:17 +01:00
Jacques de Laval cb64c068e3 Fix #136: drop old init client tool
The SysV API compatibility layer gives too little value to be worth
the effort of maintaining it. Users are encouraged to use the
`initctl` tool instead.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-11 17:52:08 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg ff41868b59 Reorder, call conf_init() *after* all cond_init()
This to ensure that services, and conditions they may create, actually
are recorded in the condition subsystem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 15:27:29 +01:00
Joachim Wiberg 82664396d6 Refactor 3e8d63c: use consoles from /sys/class/tty/console/active
As documented in the kernel docs and systemd[1], the default system
console is the first listed in /sys/class/tty/console/active, which
is the reverse order of console= given on the kernel cmdline.

Some distros don't have console= on their default command line in
their bootloader, e.g. Alpine Linux, some multiple, e.g Buildroot.
Instead of relying on the value given at configure time we probe
sysfs and open all (at most three) consoles listed.  This way we
at least get the default console for our progress output.

- drop old --with-console from configure script
- drop /proc/cmdline fishing in favor of sysfs
- replace CONSOLE from configure with new console()

[1]: http://0pointer.de/blog/projects/serial-console.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-08 20:09:49 +01:00
Joachim Wiberg 18359ef448 Follow-up to 4febd28: bring back /dev, /proc, and /sys
We need /proc for rs_remount_root() and conf_parse_cmdline(), /dev for
early multi-console support, and /sys for the cgroups support.  All of
these may be in the system /etc/fstab, which fs_mount() later remounts.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-07 12:53:35 +01:00
Joachim Wiberg 84c6ab737e Silence kernel output on console when starting up
Many systems have a very verbose kernel by default.  This patch calls
`klogctl(SYSLOG_ACTION_CONSOLE_OFF, NULL, 0)`, which is sysklogd also
calls but later when it starts emptying /dev/kmsg.

We do this to get an undisturbed console while starting up.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-06 20:37:41 +01:00
Joachim Wiberg 9e73fda2ac Follow-up to 4febd28: remount / as rw requires /proc to be mounted
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-06 20:37:41 +01:00
Tobias Waldekranz bdceeb83d5 Ensure that plugins are loaded before the first hook point
We want plugins to be able to register themselves at the banner hook
point, but that requires that we have actually loaded them before
then.
2020-10-20 09:48:33 +02:00
Tobias Waldekranz 100cea5d9f Read configuration after filesystem mount
The contents of /etc/finit.conf and friends could potentially change
after mounting /etc/fstab. If, for example, /etc was to be re-mounted
from ro to rw using an overlay filesystem, we want any user changes to
the configuration to take effect.
2020-10-20 09:31:58 +02:00