Fix ev->len validation; must check against sz read(), not total buffer
size. Also, fix off-by-one in comparison.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fix ev->len validation; must check against sz read(), not total buffer
size. Also, fix off-by-one in comparison.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Check for spaces and slashes in interface name to prevent path based
attacks. Found by Coverity Scan.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a major refactor to use the same construct as in the pidfile.so
plugin to parse kernel inotify events for when TTYs are added removed
from the system.
Found by Coverity Scan.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With the redesign from <svc/path/to/pidfile> to <pid/name:id> in d1fac6f
we moved to matching svc_t only against their PID, which could pop up in
any *.pid or */pid in /var/run. This patch drops the (hopefully) last
remnants of the old <svc/> legacy.
To ensure we don't try reading the PID value from socket files, like
/var/run/initctl, we add simple fnmatch() of the inotified file. Two
calls to fnmatch(), for portability reasons, not every system has GNU
libc extensions like FNM_EXTMATCH.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
On systems with udevd, or systemd-udevd, we must wait for udevd to start
before calling udevadm. This patch updates service and runtask stanzas
to the new condition system naming and adds 'log' to the udevadm cmds.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch reverts back to the progress/status behavior of Finit < v3.0
because this is what most users expect, including the maintainer. The
resulting code and configure script is a lot simpler to understand and
maintain:
- No more --enable-progress or --enable-progress-classic configure
flags. Instead a progress_style variable in helpers.c that can
be changed at compile time for those that really need it.
- No more 'splash' kernel commnand line option. This turned out to
be *very* confusing to many users who believed it was some sort of
graphical splash screen à la Plymouth.
Also, when Finit debug is enabled we now have a global 'debug' flag
which now alo controls if klogctl() should be called to prevent the
kernel logs to the console or not.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The SysV API compatibility layer gives too little value to be worth
the effort of maintaining it. Users are encouraged to use the
`initctl` tool instead.
Signed-off-by: Jacques de Laval <jacques@de-laval.se>
This patch removes the built-in inetd support from Finit. We recommend
using an external inetd instead, e.g. xinetd.
If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it. We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.
So long for now, old friend.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation. Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.
However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit. To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.
Connecting the dots between these wasn't obvious.
This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser. Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The recently updated pidfile plugin now also watches the subdirectories
in /var/run, but for that to work it must witness the creation of these
subdirectories. The bootmisc plugin creates several, e.g., /run/quagga/
in which PID files like zebra.pid are created.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Even musl libc supports %m today, as well as most syslog daemons, but
that's no excuse to use this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Define MODULES_LOAD_PATH only when it's unset, this allows it to be
overridden, for instance, by passing CFLAGS.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
This patch makes the RTC plugin a bit more stand-alone, it is now also
back in the hands of the user to set a default timezone.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch sets the TZ variable to a sane default, UTC. Fixing, at
least, the time restore problems of the RTC plugin.
Also, let the C library figure out DST, as the docs say -1 does ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Unlike find(1), nftw(3) defaults to follow symlinks. For some kernel
configurations this turned out to be detrimental and caused the plugin
to loop forever scanning modalias files.
Also, check if /sys is mounted before even calling nftw().
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,
- /var/run/teamd/a1.pid -- For aggregate A1
- /var/run/dbus/pid
- /var/run/lxc/foo.pid -- For container foo
This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).
To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax. This pid file name
is also used to create the condition this service asserts using the
following formula:
svc/ + <dirname of service> + <subdir and file without .pid>
E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'
The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory. It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid. Matching files follow the teamd
case. The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'
One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo. The service stanza:
service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo
This command has no leading path so the condition is composed entirely
from the PID file location:
svc/ + '' + lxc/foo => svc/lxc/foo
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds a new plugin to Finit called modprobe. It probes in
/sys/devices after modalias files and then calls 'modprobe -ab' for
each alias listed.
For hot-plugging we recommend adding the following to /etc/mdev.conf
$MODALIAS=.* root:root 0660 @modprobe -b "$MODALIAS"
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The BusyBox hwclock is really bad at handling, or rather displaying,
errors properly. When the kernel signals EINVAL, or ENOENT, it just
shows that message on stderr.
This patch implements proper RTC load/store at boot/halt with quite
some improved error handling suitable for embedded systems.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>