- Fix bug when calling sys_update_conds() when dir already exists
and we're not being called from the scandir() handler. I.e.,
every time but the first for each new condition sub-family
- Drop sys conditions that don't affect any svc_t. This may seem
counterintuitive, and we should probably not use oneshot conds,
but if we leave these conds asserted they may cause inadvertent
trigger if a finit.conf is loaded which ha this sys cond. E.g.,
if ctrlaltdel is asserted and we enable a task in finit.conf and
call `initctl reload`, the task would start immediately, even
though ctrl-alt-del may have been pressed a week ago
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY". As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release. It is now possible
to also disable the heading entirely using --without-heading
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Similar to 6224166 (previous commit), this old code is a remnant of a
bygone era and not needed anymore.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Once upon a time, SIGSTOP was used to pause Finit during flashing (MTD)
of a system image. This to prevent Finit from accidentally starting any
programs, i.e., reading from flash disk during or after upgrade.
This was quite intrusive, and has possible nasty side effects, e.g., any
process with root access sends SIGSTOP prevents TTY login. So this patch
now removes the functionality and recommends using a dedcicated runlevel
for such critical tasks instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The waitpid() function can return -1 due to EINTR (signal), so we should
restart it to make sure we collect all zombies.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Some systems may want to handle RTC and /dev/urandom by themselves, or
not at all as in the case of containers where the host does all this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program. However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.
The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
It has barely worked and only caused more problems than solved annoying
issues. We have one console for output, /dev/console, which the kernel
sets up for us.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Also, fix default: case in error handling, must always continue back to
poll() on any recv() error.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Progress at startup has been hidden for services w/o -- description, but
for some reason this check was not added to service_stop(). This patch
rectifies the situation, finally.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds a `respawn` flag for services and ttys, always set for
ttys, that allows bypassing the crash/restart counter and immediately
restart a 'crashing' service.
For tty type services this is the expected behavior, but for regular
services it is not. That is why `respawn` flags is not advertised in
the docs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
By default, Linux gives us /dev/console for output. This is a pseudo
device that uses the same actual device as the last console=foo listed
in /proc/cmdline. The last one listed is the main console, which is
also the *first* one listed in /sys/class/tty/console/active, so we skip
that when we check for system consoles to avoid duplicating output.
The getty code in tty.c currently has its own handling of @console,
which we keep for now. Ideally, however, the code should be merged.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
By moving the built-in getty to a stand-alone bundled getty we can now
refactor the old run_getty() functions into a single one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When TTYs became first class citizens in Finit 4.0 much of the
boilerplate setup is now down by service_start(). Also, the calls to
TIOCSCTTY, VINTR, and SIGINT ignore is not necessary to do here, it
should be done by the getty used, if any.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We must detach from the controlling TTY before enabling signals and
setting up new stdio. TTYs have their own handling of stdio.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch moves the built-in getty out of Finit into /libexec/finit/,
reducing the size of the Finit binary and simplifying the code.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When starting a getty Finit checks first that the configured TTY device
actually exists and is a TTY. This patch, by Tobias Waldekranz, ensures
Finit (PID 1) doesn't acquire the TTY device as a controlling TTY. If
that happens PID 1 will get all signals sent to the process actually
started with the device as its controlling TTY.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When an external getty is used, and an absolute path is not given, the
parser tried to use access() to determine built-in vs external getty.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch drops the default signal handlers for SIGPWR and SIGINT with
optional tasks in /etc/finit.conf, triggered by two new conditions:
sys/pwr/fail and sys/key/ctrlaltdel, respectively.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Apparently fgetln() is available in musl libc, but not glibc. This is a
funciton that first appeared in 4.4BSD. We take a risk that fgetline()
is free in all libc's, getline() is not.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch is a refactor of the prototype sys condition plugin. It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition. The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them. This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The top-level cgroup init is a leaf group and should be treated as such,
even for user setup tasks/services.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The udevd, dbus, bundled watchdog, and others were started without a
valid cgroup. This is a workaround to ensure they are assigned one.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This fixes a long-standanding issue with finit not controlling the
reboot when the user presses ctrl-alt-delete (PC systems).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch does several things related to /run and system reliability.
- Mount /run with MAX 10% of usable RAM
- Create and mount /run/lock as a separate tmpfs with max 5 MiB
As a spin-off, this patch also fixes permisions on /run/lock to 0777
so regular users can create lock files.
Note: none of this code runs if /run is mounted alread in /etc/fstab
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Handle EAGAIN properly, for both regular and resync flow, on any error
in the regular flow (unless ENOBUFS) we want to check for nl_ifdown on
any of the successfully parsed messages.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for calling recv() repeatedly to get the netlink
response from the kernel. As a result, the recv() buffer can be reduced
down to 4k again.
Both the regular flow and the resync flow now follow the exact same code
path, except for the ENOBUFS handling. If we get ENOBUFS in resync, we
are screwed anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For RTM_GETLINK we need a `struct ifinfomsg`, not `struct rtmsg`,
otherwise the kernel will get 8 extra bytes and complain about it.
This patch makes sure to set the correct iface change mask as well, and
increases the debug logs a bit to get a fix on sizes used. We increase
the recv() buffer 8k -> 64k to make sure we can get all data in one big
swoop. Plan is to refactor this mess in a later commit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly. Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.
When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:
1. deassert all net/ conditions
2. open a new (temporary) netlink socket
3. send RTM_GETLINK and re-assert all interfaces using nl_link()
4. send RTM_GETROUTE and re-assert all routes with nl_route()
Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves. This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.
The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch fixes the problem with Linux not sending netlink route change
notifications when interfaces for these routes goes down. When an iface
goes down we now send a route request to the kernel and check the return
message, if no default route is found we deassert net/default/route.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>