Commit Graph
272 Commits
Author SHA1 Message Date
Joachim Wiberg e2ef6e9c34 plugins: sys: drop conditions not affecting any svc_t
- Fix bug when calling sys_update_conds() when dir already exists
  and we're not being called from the scandir() handler.  I.e.,
  every time but the first for each new condition sub-family

- Drop sys conditions that don't affect any svc_t.  This may seem
  counterintuitive, and we should probably not use oneshot conds,
  but if we leave these conds asserted they may cause inadvertent
  trigger if a finit.conf is loaded which ha this sys cond.  E.g.,
  if ctrlaltdel is asserted and we enable a task in finit.conf and
  call `initctl reload`, the task would start immediately, even
  though ctrl-alt-del may have been pressed a week ago

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-06 00:34:11 +02:00
Joachim Wiberg 1c941fdfbb plugins: add support for disabling RTC and urandom plugins
Some systems may want to handle RTC and /dev/urandom by themselves, or
not at all as in the case of containers where the host does all this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 11:43:58 +02:00
Joachim Wiberg 0ba67a72f8 plugins: add missing x11-common plugin to static libplug.la
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-01 11:43:26 +02:00
Joachim Wiberg 2641256254 plugins: sys: no need to compose path, name is already absolute path
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 13:58:30 +02:00
Joachim Wiberg 93a027ca23 plugins: netlink: fix gcc signed vs unsigned comparsion warning
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-27 11:18:06 +02:00
Joachim Wiberg c251304146 Refactor sys condition plugin into a standalone keventd
This patch is a refactor of the prototype sys condition plugin.  It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition.  The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them.  This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:31:08 +02:00
Joachim Wiberg b04dc4d457 Ensure services in plugins and from finit.c belong to a cgroup
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup.  This is a workaround to ensure they are assigned one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:27:59 +02:00
Joachim Wiberg 2018c82ea1 plugins: sys: watch uevent to prevent feedback loop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-13 21:20:08 +02:00
Joachim Wiberg c27f3603e6 plugins: sys: use counting semaphores to handle >1 AC supply
- Track number of ac and ac online
 - Use systemd logic to assert sys/pwr/ac also when no supply

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-13 08:45:49 +02:00
Joachim Wiberg 6f82b806ad plugins: new sys condition event monitor (wip)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-11 07:02:49 +02:00
Joachim Wiberg 21ebbb942f plugins: bootmisc: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 988ecd95e3 plugins: bootmisc: only create /run/lock if missing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg cbc7b8c3c7 plugins: bootmisc: add S02sudo setup for Debian systems
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-09 14:38:16 +02:00
Joachim Wiberg 424db825a3 plugins: netlink: error handling fixes
Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 17:02:09 +02:00
Joachim Wiberg b9cc4cd629 Revert "plugins: fix #173, increase size of netlink socket receive buffer"
This reverts commit add55cfc2a.
2021-05-07 16:50:04 +02:00
Joachim Wiberg 243b8f025b plugins: netlink: refactor and reduce recv() buffer
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel.  As a result, the recv() buffer can be reduced
down to 4k again.

Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling.  If we get ENOBUFS in resync, we
are screwed anyway.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 16:42:42 +02:00
Joachim Wiberg 6c60b67588 plugins: netlink: fix resync request size alignment with kernel
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.

This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used.  We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop.  Plan is to refactor this mess in a later commit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 15:20:25 +02:00
Joachim Wiberg 910bb13711 plugins: netlink: redesign to handle ENOBUFS with kernel resync
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly.  Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.

When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:

  1. deassert all net/ conditions
  2. open a new (temporary) netlink socket
  3. send RTM_GETLINK  and re-assert all interfaces using nl_link()
  4. send RTM_GETROUTE and re-assert all routes with nl_route()

Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves.  This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.

The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 13:06:47 +02:00
Joachim Wiberg add55cfc2a plugins: fix #173, increase size of netlink socket receive buffer
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-04 13:19:54 +02:00
Joachim Wiberg ea8c46cd30 Fix #170: check for loss of default route when interfaces go down
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down.  When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-03 15:18:25 +02:00
Joachim Wiberg 3872077ff1 plugins: netlink: stricter interface name validation
Coverity suggests validating against only a set of known characters.
However, the kernel allows just about all characters in an interface
name.  This version of valdiate_ifname() is blatantly stolen, more
or less, from linux/net/core/dev.c

 https://code.woboq.org/linux/linux/net/core/dev.c.html#1020

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-29 17:19:19 +02:00
Joachim Wiberg 26128dd788 plugins: skip plugin in rescue mode
These plugins should not run in rescue mode, because the system may be
in a very bad state and we do not want to make the situation any worse
than it already is.

Essentially, only services in rescue.conf should run in rescue mode.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 19:46:43 +02:00
Joachim Wiberg d82d119729 plugins: handle corner case when PID file doesn't exist
If we get a notification and the service dies immediately, and also
removes its pid file, we need to take corrective action.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 09:45:57 +02:00
Joachim Wiberg be343a3b34 plugins: call bootmisc:bootclean() in HOOK_MOUNT_POST
Before this patch bootclean() ran first in setup() which caused to to
remove the entire /var/run/finit directory, and other files as well,
created earlier.  Only possible fix is to split clean and setup in
two and make sure to call clean as soon as we've mounted everything.

Note: this introduces a new behavior, and anyone hooking into the
      same point to do good-stuff(tm) may be affected by this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:34:48 +02:00
Joachim Wiberg 0ac0e5c7d3 plugins: create /var/run/finit/cond/pid directory
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:34:29 +02:00
Joachim Wiberg eaeddc36c2 Restore tty plugin after tty refactor
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 09:02:28 +02:00
Joachim Wiberg 30020263ba Refactor tty handling to use service backend enabling conditions etc.
Initial refactor of the tty implementation to use the service/run/task
general backend.  This enables all the features of services also for
ttys, except logging because it makes no sense.

Work in progress:

 - plugins/tty.c does not work anymore, could possibly be removed in
   favor of usinga (a new) condition instead (if-tty-exists)
 - fallback tty does not work anymore, should we remove it, or can we
   handle it as an optional built-in with (a new) condition?
 - @console does not work anymore, needs to generate N cloned services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-14 16:29:19 +02:00
Joachim Wiberg 9e6e653c57 plugins: pidfile: fix subtle memory leak
Since the introduction of the iwatch framework we can now safely free
the memory allocated by realpath() and prevent leaks in a more elegant
way than before.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-29 23:20:00 +02:00
Joachim Wiberg d4bbebeb93 plugins: hotplug: ensure we always call setup() *after* bootmisc
The bootmisc plugin creates lots of required system directories which
udev, and possibly also mdev, need to operate.  E.g., a system which
has an empty tmpfs for /var need to populate that before we run.

The plugin loader handled this dependency implicitly before, loading all
plugins in alphabetical order.  We should not rely on that for proper
operation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-24 13:16:12 +01:00
Joachim Wiberg 1a22b4f0aa plugins: dbus: allow in all runlevels and start already in 'S'
This plugin should be able to start much earlier than on network UP,
it uses a UNIX domain socket to communicate so loopback should not be
needed.

Also, Finit supports runvels up to 9 (0 and 6 are special), so allow
dbus to run in all these runlevels.  It is up to the user/OS to set
any policy for what runlevels to use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-24 13:13:35 +01:00
Joachim Wiberg 959c9fe5aa plugins: restore previous umask() after plugin ops
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:04:29 +01:00
Joachim Wiberg 31cae6a56d plugins: dbus: simplify, use mksubsys(), run as messagebus user
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00
Joachim Wiberg 1fd45c6f2e plugins: bootmisc: refactor, use mksubys() and simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:26:14 +01:00
Joachim Wiberg cfb3a9f2b9 plugins: pidfile: reduce log noise
With the new practise of keeping record of process pid files, we no
longer need to log/update when reading back the same PID we already
have on file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-12 00:35:13 +01:00
Joachim Wiberg 280608f30e plugins: pidfile: track PID file in svc, if svc has none declared
Services that create their own PID files usually don't declare one with
Finit.  This patch adds support to track those PID files anywayt at
runtime for the purpose of identifying match svc_t when a PID file is
removed, i.e. when a service exits.

 - On IN_CREATE the pidfile.so plugin saves the pid file name in svc_t
 - On ON_DELETE the pidfile.so plugin finds svc_t based on pid file

Quicker tracking and less dead code, win-win.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 21:56:49 +01:00
Joachim Wiberg 2711b27971 plugins: pidfile: tricky zebra doesn't close its pid file
This patch fixes a few really hard problems wrt PID files:

 1. Listening for IN_CREATE events means we get notified immediately by
    the kernel when someone calls open()/fopen() on a PID file.  Reading
    the contents returns 0, thank you atoi() ... so we drop IN_CREATE
    and instead look for IN_CLOSE_WRITE, there fixed it!  Not quite ...

 2. Some programs, like Zebra, and other Quagga/Frr daemons, don't
    close() their PID files after creation.  Instead they ftruncate()
    and keep them open, and locked.  Presumably to get a mechanism to
    detect already running instances -- messes life up a bit for the
    rest of us though.  So we need to read files after IN_MODIFY too.

 3. We also want to track IN_DELETE so we can deassert conditions when
    services exit gracefully and clean up their PID files

The rest fo the commit is debug instrumentation changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 8000d361b3 initctl: restore 'cond [set|clr] foo' for user-defined conditions
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user.  That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.

This patch restores the behavior, albeit in a very reduced and simple
format.  All conditions set with this command are constrained to the
'usr/...' namespace.  No subdirectories are allowed.  The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:

    initctl cond set foo:2

creates a static/oneshot condition in /run/finit/cond/usr/foo:2

These conditions are static and are fully handled by the user.  The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.

This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory.  When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.

For instance, the following service is not started by default at boot:

    service <usr/foo> myservice -- MyService

However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.

Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions.  This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 289247dab9 plugins: netlink: slightly stricter ifname validation
Check if ifname contains double periods, this should *not* be a valid
name, though eth0.10 is, et0..10 is not.  Should protect better against
directory traversal attacks.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 13:25:40 +01:00
Joachim Wiberg e44dfde54e plugins: tty: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:55:12 +01:00
Joachim Wiberg 5badf4d376 plugins: pidfile: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:48:42 +01:00
Joachim Wiberg 24f274c126 plugins: netlink: validate interface name
Check for spaces and slashes in interface name to prevent path based
attacks.  Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:23:24 +01:00
Joachim Wiberg 1abd43384b plugins: netlink: minor refactor, collapse for-loop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:20:59 +01:00
Joachim Wiberg 6af0446490 plugins: netlink: fix untrusted loop bound, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 11:28:39 +01:00
Joachim Wiberg ecaf111a4b plugins: tty: possible out-of-bounds read in inotify_event parser
This is a major refactor to use the same construct as in the pidfile.so
plugin to parse kernel inotify events for when TTYs are added removed
from the system.

Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:58:55 +01:00
Joachim Wiberg d6390244ad Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 2857dafaf4 plugins: pidfile: Fall back to /run if _PATH_VARRUN doesn't exist
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-02 20:22:56 +01:00
Joachim Wiberg 064d124e19 Refactor, add new helper fn paste() to concat directory compoents
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:41:39 +01:00
Joachim Wiberg f8a989439b Minor, insert '/' only if pasting components require it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:18:44 +01:00
Joachim Wiberg ea278a6370 plugins: pidfile: simplify, use constructs from src/conf.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:27:28 +01:00
Joachim Wiberg cafbb18626 plugins: hotplug: log output from udevd/systemd-udevd to syslog
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 00:27:29 +01:00