Commit Graph
35 Commits
Author SHA1 Message Date
Tobias Waldekranz c23a867485 initctl: Follow priciple of least surprise for "cond get"
The accepted standard in Unix is to report successful executions with
exitcode 0. Therefore, map a "initctl cond get" of a condition to the
following exitcodes:

- On: 0
- Off: 1
- Flux: 255

Fixes: c3c662fe64 ("initctl: ensure 'cond get' support flux state")
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-02-06 16:01:18 +01:00
Tobias Waldekranz 5fb4a6ae8f plugins: modprobe: Support for coldplugging more devices
As it turns out, not all buses in Linux will add `modalias` attributes
to their devices in sysfs. One notable exception are MDIO buses. The
plugin's scan routine would thus not pick them up.

Fortunately, the information is always available in the device's
`uevent` attribute.

Therefore, default to looking for modaliases in the device's `uevent`
attribute instead, falling back to `modalias` only if `uevent` is not
availble (this should never happen).
2022-06-23 14:23:04 +02:00
Tobias Waldekranz e84333662e plugins: hotplug: Run after modprobe plugin, if available
Since the modprobe plugin (unsurpricingly) may cause new modules to be
loaded, it makes sense to to delay the initial device node scan until
we know that no mode nodes will show up within the next few
microseconds.
2022-06-23 14:19:30 +02:00
Tobias Waldekranz b62c975dc4 plugins: hook-scripts: Add
Add a plugin that will allow the user to trigger the execution of
scripts from plugin hook points. This is particularly useful for early
boot debugging that needs to take place before regular services are
available.

For example, let's say that you want to enable some kernel tracing
before modules are loaded. With hook-scripts, you can just drop in a
shell script in /libexec/finit/hook/mount/all/ that will poke the
right control files in tracefs.
2022-05-06 10:36:37 +02:00
Tobias Waldekranz adcc78039e Bring back the hotplug-daemon-heuristic as a plugin
This way, the default behavior stays the same, but users can opt out
by disabling the plugin.
2020-10-20 14:57:10 +02:00
Tobias Waldekranz bdceeb83d5 Ensure that plugins are loaded before the first hook point
We want plugins to be able to register themselves at the banner hook
point, but that requires that we have actually loaded them before
then.
2020-10-20 09:48:33 +02:00
Tobias Waldekranz 100cea5d9f Read configuration after filesystem mount
The contents of /etc/finit.conf and friends could potentially change
after mounting /etc/fstab. If, for example, /etc was to be re-mounted
from ro to rw using an overlay filesystem, we want any user changes to
the configuration to take effect.
2020-10-20 09:31:58 +02:00
Tobias Waldekranz cc655609e2 Do not exempt basefs up hook in rescue mode
No other hook is treated in this fashion, so it seems silly to single
out poor HOOK_BASEFS_UP.
2020-10-20 09:31:58 +02:00
Tobias Waldekranz 18ab7d3183 Remove hard-coded hotplug and watchdog daemons
Instead of heuristically trying to determine the correct hotplug
daemon to use (mdev/udev), defer to the user to specify it in the
configuration.  Same goes for the built-in watchdog.
2020-10-20 09:31:58 +02:00
Tobias Waldekranz 4febd288ef Defer all filesystem setup to the user via /etc/fstab
Traditionally, Finit has setup _some_ filesystems that are Nice To
Have (tm), using options that do the Right Thing (tm).

On the one hand, this is very convenient for users that don't
necessarily know what a reasonable mode= value is for /tmp etc. (pun
intended).  It also means that mountpoints can be created if they
don't exist.

On the other hand it means that all users are forced to submit to the
choices made by Finit.  Also, different filesystems where spread out
at many different points in `main()`, meaning that the fact that
`/proc` was available at a given hook point did not imply that `/sys`
was, for example.

Instead, defer _all_ filesystem setup to the user by simply calling
`mount -a`.  We then ship an example `fstab` that shows how to
re-create the old behavior.
2020-10-20 09:31:58 +02:00
Tobias Waldekranz b280c8a16a Remove comments from fsck 2020-10-13 15:26:51 +02:00
Tobias Waldekranz 9c8df123e8 Always run banner plugin hook
Upcoming external plugin support means that even though there are no
internal plugins that depend on this hook, there might be external
ones.
2020-10-13 15:23:41 +02:00
Tobias Waldekranz e558d5871b Move argument-hiding magic together with argument parsing
Everything else Finit does related to parsing the incoming arguments
is in conf.c, so it makes sense for this block to also reside there.
2020-10-12 13:09:41 +02:00
Tobias Waldekranz fd837a4242 Do not try to SIGKILL inetd services, they are not backed by a pid
As a precaution, services who are being stopped are automatically sent
a SIGKILL after 3 seconds if they refuse to go away willingly.

Unfortunately this backup mechanism was also enabled for inetd
services which are not backed by a real process. When the service was
freed the timer was not stopped, since it was not expected to be
armed. The timer would then trigger, causing a use-after-free on the
timer watcher containing a bogus callback pointer.
2018-02-09 14:11:48 +01:00
Tobias Waldekranz b0663d04e4 cond: don't rely on mtime for condition management
TIL, using mtimes for tracking event orderings is a monumentally bad
idea (queue the nodding UNIX-beards). Mtimes are in wallclock time which
is not necessarily monotonically increasing. A user may adjust the time,
an NTP daemon will continously tune the clock and so on.

Instead, store an explicit generation number in each condition file,
which will be monotonically increased by finit on each reconf.
2017-12-21 11:10:47 +01:00
Tobias Waldekranz 10b72f1d7f service: kill stubborn services, wait before restart
Add support for registering callbacks to be called after a given
timeout.

Use this to implement forceful termination of services that refuse to
terminate upon receiving a SIGTERM. If the service PID is not collected
within 3 seconds, send a SIGKILL to it.

Also, rework restarting of crashing services. When a service crashes for
the first time, try to restart it immediately. If it crashes again, wait
a few seconds before trying again. Just as before, if it continues to
crash, block the service.
2016-09-13 20:26:28 +02:00
Tobias Waldekranz 6d84fd010e Resource limit manipulation (setrlimit)
Add support for changing the initial hard and soft resource limits for
finit and any processes it launches.

See /etc/finit.conf section in README.md for more information.
2016-04-28 09:36:22 +02:00
Tobias Waldekranz 2555fe8e96 inetd: Flush existing filters on reload
Flush any existing filter rules when a configuration file is
updated. Otherwise filters are simply appended to the old
configuration which can cause finit to accept connections on
interfaces that are blocked in the new configuration.
2016-02-19 12:53:39 +01:00
Tobias Waldekranz c41016ef32 Only default to SIGHUP support on daemons
When parsing a service configuration, only default to SIGHUP support
if the service is a daemon. inetd services must be stop/started on
change.
2016-02-19 12:50:24 +01:00
Tobias Waldekranz c6055031b8 Avoid unnecessary restarts of services that do not support SIGHUP
When a service's condition transitions to `flux`, put it in the
waiting state, even if it does not support SIGHUP. That way, if the
condition returns to `on` we can simply SIGCONT it. If it goes to
`off` it will still be stop/started as before.
2016-02-05 13:45:06 +01:00
Tobias Waldekranz e8d699c194 Mark inetd services as clean on dynamic reload
When reloading dynamic services, inetd services deleted marker was not
being cleaned. This caused finit to stop and start all inetd services
at every other reload.
2016-01-28 14:52:49 +01:00
Tobias Waldekranz 80273555c5 Do all service transitions in a helper function
This eases development, since it makes it easy to set a breakpoint on
a specific state transition.
2016-01-28 13:44:27 +01:00
Tobias Waldekranz 6ece4b8fa3 inetd: Re-integrate the inetd subsystem into the new service model
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
2016-01-15 10:07:15 +01:00
Tobias Waldekranz 0beb566e45 git: Ignore Emacs backup files 2016-01-13 16:02:46 +01:00
Tobias Waldekranz c641a1374e Do not ignore updated services when cleaning up removed ones
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.

As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
2016-01-13 15:14:27 +01:00
Tobias Waldekranz 171d611b14 Improve service state machine debug messages
In addition to logging state transitions, also log the parameters that
might trigger a transition.
2016-01-13 15:09:04 +01:00
Tobias Waldekranz 02eb68f46c Ensure that a service has stopped before taking any further action
During documentation of the state machine, some theoretical problems
where discovered that could have lead finit to spawn a new instance of
a daemon before the previous one had been collected.

Now a service will always go through the STOPPING state when leaving
RUNNING. This ensures that the PID has been collected before any calls
to service_start.

...documenting your work is, apparently, not a bad idea. :)
2016-01-07 11:00:52 +01:00
Tobias Waldekranz 7fe4c3355f doc: Add service state machine documentation 2016-01-07 11:00:51 +01:00
Tobias Waldekranz aa1da0e9f2 doc: Add documentation for conditions 2016-01-05 17:24:31 +01:00
Tobias Waldekranz 2232aea0f7 Dynamically manage service states based on user defined conditions
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.

In order to accomodate this, the service management has been
redesigned to use a state machine.
2016-01-05 15:01:58 +01:00
Tobias Waldekranz 7a3408c173 Optionally skip stripping binaries during install-exec
One may wish to build and install with debug symbols intact, so allow
overriding the arguments sent to install.
2016-01-05 14:50:13 +01:00
Tobias Waldekranz af7b6c17cb Correctly parse service configuration stanzas containing slashes
Parser would erroneously interpret an event specification containing
slashes as an inet service/proto specification.

E.g. "<net/gw>" was interpreted as port "<net" using protocol "gw>".
2016-01-05 14:50:13 +01:00
Tobias Waldekranz b19ea16e9d Only trigger on events that matches the service's specification
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
2015-11-22 19:59:01 +01:00
Tobias Waldekranz a3193b34a6 Unblock blocked signals after forking off a child
After forking off a new child, all signals that are blocked by finit
should be unblocked before exec-ing the final binary. Also, finit now
blocks SIGHUP, so add it to the set of signals that should be
unblocked.
2015-10-16 18:32:53 +02:00
Tobias Waldekranz ae15988eb8 Add hook point on fstab mount failure
Check return code from `mount -na`, if there where any errors give
plugins a chance to do something about it.

Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-09-29 22:38:06 +02:00