Commit Graph
341 Commits
Author SHA1 Message Date
Joachim Wiberg 31cae6a56d plugins: dbus: simplify, use mksubsys(), run as messagebus user
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00
Joachim Wiberg 1fd45c6f2e plugins: bootmisc: refactor, use mksubys() and simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00
Joachim Wiberg cfb3a9f2b9 plugins: pidfile: reduce log noise
With the new practise of keeping record of process pid files, we no
longer need to log/update when reading back the same PID we already
have on file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 00:35:13 +01:00
Joachim Wiberg 280608f30e plugins: pidfile: track PID file in svc, if svc has none declared
Services that create their own PID files usually don't declare one with
Finit.  This patch adds support to track those PID files anywayt at
runtime for the purpose of identifying match svc_t when a PID file is
removed, i.e. when a service exits.

 - On IN_CREATE the pidfile.so plugin saves the pid file name in svc_t
 - On ON_DELETE the pidfile.so plugin finds svc_t based on pid file

Quicker tracking and less dead code, win-win.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:56:49 +01:00
Joachim Wiberg 2711b27971 plugins: pidfile: tricky zebra doesn't close its pid file
This patch fixes a few really hard problems wrt PID files:

 1. Listening for IN_CREATE events means we get notified immediately by
    the kernel when someone calls open()/fopen() on a PID file.  Reading
    the contents returns 0, thank you atoi() ... so we drop IN_CREATE
    and instead look for IN_CLOSE_WRITE, there fixed it!  Not quite ...

 2. Some programs, like Zebra, and other Quagga/Frr daemons, don't
    close() their PID files after creation.  Instead they ftruncate()
    and keep them open, and locked.  Presumably to get a mechanism to
    detect already running instances -- messes life up a bit for the
    rest of us though.  So we need to read files after IN_MODIFY too.

 3. We also want to track IN_DELETE so we can deassert conditions when
    services exit gracefully and clean up their PID files

The rest fo the commit is debug instrumentation changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 8000d361b3 initctl: restore 'cond [set|clr] foo' for user-defined conditions
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user.  That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.

This patch restores the behavior, albeit in a very reduced and simple
format.  All conditions set with this command are constrained to the
'usr/...' namespace.  No subdirectories are allowed.  The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:

    initctl cond set foo:2

creates a static/oneshot condition in /run/finit/cond/usr/foo:2

These conditions are static and are fully handled by the user.  The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.

This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory.  When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.

For instance, the following service is not started by default at boot:

    service <usr/foo> myservice -- MyService

However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.

Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions.  This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 289247dab9 plugins: netlink: slightly stricter ifname validation
Check if ifname contains double periods, this should *not* be a valid
name, though eth0.10 is, et0..10 is not.  Should protect better against
directory traversal attacks.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 13:25:40 +01:00
Joachim Wiberg e44dfde54e plugins: tty: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 5badf4d376 plugins: pidfile: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:48:42 +01:00
Joachim Wiberg 24f274c126 plugins: netlink: validate interface name
Check for spaces and slashes in interface name to prevent path based
attacks.  Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:23:24 +01:00
Joachim Wiberg 1abd43384b plugins: netlink: minor refactor, collapse for-loop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:20:59 +01:00
Joachim Wiberg 6af0446490 plugins: netlink: fix untrusted loop bound, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:28:39 +01:00
Joachim Wiberg ecaf111a4b plugins: tty: possible out-of-bounds read in inotify_event parser
This is a major refactor to use the same construct as in the pidfile.so
plugin to parse kernel inotify events for when TTYs are added removed
from the system.

Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:58:55 +01:00
Joachim Wiberg d6390244ad Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 2857dafaf4 plugins: pidfile: Fall back to /run if _PATH_VARRUN doesn't exist
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-02 20:22:56 +01:00
Joachim Wiberg 064d124e19 Refactor, add new helper fn paste() to concat directory compoents
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:41:39 +01:00
Joachim Wiberg f8a989439b Minor, insert '/' only if pasting components require it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:18:44 +01:00
Joachim Wiberg ea278a6370 plugins: pidfile: simplify, use constructs from src/conf.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:27:28 +01:00
Joachim Wiberg cafbb18626 plugins: hotplug: log output from udevd/systemd-udevd to syslog
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 00:27:29 +01:00
Joachim Wiberg f906bb357a plugins: pidfile: only scan directory if watch added successfully
Also, update condition example in comment.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Joachim Wiberg bc4d4b7f35 plugins: pidfile: set up I/O callback on successful iwatch_init()
In case of trouble, make sure we don't have a callback set up w/o
a valid file descriptor.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 09:52:34 +01:00
Joachim Wiberg dd6ebc3b65 Drop svc pidfile matching, only match against PID in pidfile
With the redesign from <svc/path/to/pidfile> to <pid/name:id> in d1fac6f
we moved to matching svc_t only against their PID, which could pop up in
any *.pid or */pid in /var/run.  This patch drops the (hopefully) last
remnants of the old <svc/> legacy.

To ensure we don't try reading the PID value from socket files, like
/var/run/initctl, we add simple fnmatch() of the inotified file.  Two
calls to fnmatch(), for portability reasons, not every system has GNU
libc extensions like FNM_EXTMATCH.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 20:26:57 +01:00
Joachim Wiberg 8dc1ad00d5 plugins: refactor, break out inotify watcher to src/iwatch.[ch]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 20:26:38 +01:00
Joachim Wiberg 8381976f05 plugins: boilerplate for made-easy integration with FRR
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 15:03:03 +01:00
Joachim Wiberg c0bbb0fc51 plugins: pidfile: rename variables and local fns
- new namespace before breaking out to shared object
- use inotify naming fd -> wd

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 09:04:53 +01:00
Joachim Wiberg 1cb37a3ee7 plugins: update conditions for udevd and udevadm commands
On systems with udevd, or systemd-udevd, we must wait for udevd to start
before calling udevadm.  This patch updates service and runtask stanzas
to the new condition system naming and adds 'log' to the udevadm cmds.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-21 01:12:26 +01:00
Joachim Wiberg 35e4e0d073 Drop confusing splash cmdline and --enable-progress configure option
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer.  The
resulting code and configure script is a lot simpler to understand and
maintain:

- No more --enable-progress or --enable-progress-classic configure
  flags.  Instead a progress_style variable in helpers.c that can
  be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option.  This turned out to
  be *very* confusing to many users who believed it was some sort of
  graphical splash screen à la Plymouth.

Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 20:11:08 +01:00
Joachim Wiberg 13a33d345b plugins: bootmisc: add missing include
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 14:18:08 +01:00
Joachim Wiberg e30e6ad6c9 plugins: bootmisc: skip UTMP/WTMP/BTMP on non-utmp systems (musl)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-14 04:35:26 +01:00
Jacques de Laval cb64c068e3 Fix #136: drop old init client tool
The SysV API compatibility layer gives too little value to be worth
the effort of maintaining it. Users are encouraged to use the
`initctl` tool instead.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-11 17:52:08 +01:00
Joachim Wiberg e88a9b14ff Fix #101: remove built-in inetd from finit
This patch removes the built-in inetd support from Finit.  We recommend
using an external inetd instead, e.g. xinetd.

If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it.  We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.

So long for now, old friend.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 12:46:40 +01:00
Joachim Wiberg 43d73e3c01 plugins: Use len field from inotify_event to calc dest buffer
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-10 12:14:51 +01:00
Joachim Wiberg f6b6ed211c Fix gcc warning, too small destination buffer may be truncated
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-10 11:56:34 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg a8b113185d Major change, rename <svc/...> conditions to <pid/...> conditions
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation.  Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.

However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit.  To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.

Connecting the dots between these wasn't obvious.

This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser.  Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg d068684154 plugins: fix possible ordering bug; pidfile --> bootmisc
The recently updated pidfile plugin now also watches the subdirectories
in /var/run, but for that to work it must witness the creation of these
subdirectories.  The bootmisc plugin creates several, e.g., /run/quagga/
in which PID files like zebra.pid are created.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 15:25:35 +01:00
Joachim Wiberg fccba7cd4c Replace %m GNUism with strerror(errno)
Even musl libc supports %m today, as well as most syslog daemons, but
that's no excuse to use this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-07 13:21:55 +01:00
Tobias Waldekranz adcc78039e Bring back the hotplug-daemon-heuristic as a plugin
This way, the default behavior stays the same, but users can opt out
by disabling the plugin.
2020-10-20 14:57:10 +02:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson df54f5a59c plugins: modprobe: Skip for systems without modules
Skip for systems without modules, e.g. small embedded or containers

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-07-01 13:07:57 +02:00
Ming Liu 1fa6a98e79 modules-load.c: allow MODULES_LOAD_PATH to be overridden
Define MODULES_LOAD_PATH only when it's unset, this allows it to be
overridden, for instance, by passing CFLAGS.

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2020-06-09 10:54:09 +02:00
Joachim Nilsson 1eca65fcda plugins: rtc: Move TZ set/unset to rtc plugin from Finit main
This patch makes the RTC plugin a bit more stand-alone, it is now also
back in the hands of the user to set a default timezone.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-05-03 11:04:48 +02:00
Joachim Nilsson 54fd38adcc Default to set TZ=UTC0 for RTC plugin
This patch sets the TZ variable to a sane default, UTC.  Fixing, at
least, the time restore problems of the RTC plugin.

Also, let the C library figure out DST, as the docs say -1 does ...

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 21:38:07 +02:00
Joachim Nilsson 2a4052bd8d plugins: modprobe: Never follow symlinks in /sys/devices
Unlike find(1), nftw(3) defaults to follow symlinks.  For some kernel
configurations this turned out to be detrimental and caused the plugin
to loop forever scanning modalias files.

Also, check if /sys is mounted before even calling nftw().

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-26 14:55:38 +02:00
Joachim Nilsson 1a881389b2 plugins: pidfile: Handle conditions for PID files in sub-directories
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 21:15:48 +02:00
Joachim Nilsson fe41b9c4b8 Revert "plugins: pidfile: Simplify and clean up developer debug messages"
This reverts commit 69016bb8f5.
2020-03-02 07:22:15 +01:00
Joachim Nilsson 69016bb8f5 plugins: pidfile: Simplify and clean up developer debug messages
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 17:04:27 +01:00
Joachim Nilsson f7d5b588c9 plugins: pidfile: Factor out directory handling from callback
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:52:51 +01:00
Joachim Nilsson 1176961e7b plugins: pidfile: Fix memory leak in pidfile_callback()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:40:06 +01:00
Joachim Nilsson 4e7baa807e Fix #109: Declare PID file path to dbus-daemon in dbus plugin
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:50:57 +01:00