Commit Graph
59 Commits
Author SHA1 Message Date
Joachim Wiberg 5badf4d376 plugins: pidfile: validate against read() length, not buffer size
Fix ev->len validation; must check against sz read(), not total buffer
size.  Also, fix off-by-one in comparison.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 12:48:42 +01:00
Joachim Wiberg d6390244ad Fix possible out-of-bounds read in inotify_event parser
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 2857dafaf4 plugins: pidfile: Fall back to /run if _PATH_VARRUN doesn't exist
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-02 20:22:56 +01:00
Joachim Wiberg 064d124e19 Refactor, add new helper fn paste() to concat directory compoents
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:41:39 +01:00
Joachim Wiberg f8a989439b Minor, insert '/' only if pasting components require it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 17:18:44 +01:00
Joachim Wiberg ea278a6370 plugins: pidfile: simplify, use constructs from src/conf.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-25 14:27:28 +01:00
Joachim Wiberg f906bb357a plugins: pidfile: only scan directory if watch added successfully
Also, update condition example in comment.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Joachim Wiberg bc4d4b7f35 plugins: pidfile: set up I/O callback on successful iwatch_init()
In case of trouble, make sure we don't have a callback set up w/o
a valid file descriptor.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 09:52:34 +01:00
Joachim Wiberg dd6ebc3b65 Drop svc pidfile matching, only match against PID in pidfile
With the redesign from <svc/path/to/pidfile> to <pid/name:id> in d1fac6f
we moved to matching svc_t only against their PID, which could pop up in
any *.pid or */pid in /var/run.  This patch drops the (hopefully) last
remnants of the old <svc/> legacy.

To ensure we don't try reading the PID value from socket files, like
/var/run/initctl, we add simple fnmatch() of the inotified file.  Two
calls to fnmatch(), for portability reasons, not every system has GNU
libc extensions like FNM_EXTMATCH.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 20:26:57 +01:00
Joachim Wiberg 8dc1ad00d5 plugins: refactor, break out inotify watcher to src/iwatch.[ch]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 20:26:38 +01:00
Joachim Wiberg c0bbb0fc51 plugins: pidfile: rename variables and local fns
- new namespace before breaking out to shared object
- use inotify naming fd -> wd

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 09:04:53 +01:00
Joachim Wiberg e88a9b14ff Fix #101: remove built-in inetd from finit
This patch removes the built-in inetd support from Finit.  We recommend
using an external inetd instead, e.g. xinetd.

If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it.  We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.

So long for now, old friend.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 12:46:40 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg a8b113185d Major change, rename <svc/...> conditions to <pid/...> conditions
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation.  Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.

However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit.  To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.

Connecting the dots between these wasn't obvious.

This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser.  Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg d068684154 plugins: fix possible ordering bug; pidfile --> bootmisc
The recently updated pidfile plugin now also watches the subdirectories
in /var/run, but for that to work it must witness the creation of these
subdirectories.  The bootmisc plugin creates several, e.g., /run/quagga/
in which PID files like zebra.pid are created.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 15:25:35 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson 1a881389b2 plugins: pidfile: Handle conditions for PID files in sub-directories
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-22 21:15:48 +02:00
Joachim Nilsson fe41b9c4b8 Revert "plugins: pidfile: Simplify and clean up developer debug messages"
This reverts commit 69016bb8f5.
2020-03-02 07:22:15 +01:00
Joachim Nilsson 69016bb8f5 plugins: pidfile: Simplify and clean up developer debug messages
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 17:04:27 +01:00
Joachim Nilsson f7d5b588c9 plugins: pidfile: Factor out directory handling from callback
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:52:51 +01:00
Joachim Nilsson 1176961e7b plugins: pidfile: Fix memory leak in pidfile_callback()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:40:06 +01:00
Joachim Nilsson 54cfa74042 Fix #109: Support PID files in subdirectories to /var/run
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,

   - /var/run/teamd/a1.pid    -- For aggregate A1
   - /var/run/dbus/pid
   - /var/run/lxc/foo.pid     -- For container foo

This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).

To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax.  This pid file name
is also used to create the condition this service asserts using the
following formula:

   svc/ + <dirname of service> + <subdir and file without .pid>

E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'

The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory.  It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid.  Matching files follow the teamd
case.  The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'

One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo.  The service stanza:

   service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo

This command has no leading path so the condition is composed entirely
from the PID file location:

   svc/  + '' + lxc/foo => svc/lxc/foo

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:39:53 +01:00
Joachim Nilsson decdc1560a Support for monitoring forking services/sysv daemons
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 14:10:47 +01:00
Robert Andersson 76fc72770e pidfile: monitor renamed files, e.g. rsyslogd.pid.tmp
Signed-off-by: Robert Andersson <robert.m.andersson@se.atlascopco.com>
2018-10-22 12:53:57 +02:00
Joachim Nilsson 931565c425 Simplify pidfile_reconf() thanks to the addition of schedule_wq()
We can now rely on service_step() to continue stepping run/taks/services
until no more state transitions are made.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-07 18:35:12 +02:00
Jonas Johansson dddd45e3b5 Reassert condition when svc_t goes from WAITING --> RUNNING
Reassert condition when an unchanged/unmodified process goes from
WAITING state to RUNNING.  I.e. it had a condition that went to flux
during `initctl reload`, which drove it to WAITING and was then sent
SIGSTOP during reconf.

Also, on condition update, loop through all services until no more state
changes are observed.  This allows long dependency chains of services to
resolve and actually go back to RUNNING state as intended whenever any
condition changes at runtime.

Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-02 19:03:30 +02:00
Joachim Nilsson f9783b4b41 pidfile: Use realpath() to figure out of _PATH_VARRUN is a symlink
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-13 21:49:18 +01:00
Joachim Nilsson 32d9afc7bb Use pid_runpath() in svc_find_by_pidfile(), used by pidfile plugin
The pidfile plugin just listens to changes in files in /run or /var/run,
so when trying to locate an svc_t from a file change we need to compare
using the proper prefix path.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-13 21:47:11 +01:00
Joachim Nilsson 0d4bc69584 pidfile: Use new svc_find_by_pidfile() in plugin
A service may now have a custom PID file, possibly because it doesn't
really create one itself.  This needs to be taken into account also in
the pidfile plugin.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-11 10:50:19 +01:00
Joachim Nilsson 8992e7bf2b Refactor svc_iterator() into a proper iterator, add first flag
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 23:56:14 +01:00
Joachim Nilsson 0f1f51b5ad Refactor, change from static array of svc_t to linked list
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 17:50:02 +01:00
Joachim Nilsson 7f04382eee Refactor, use new re-entrant svc_iterator1() API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 00:21:07 +01:00
Joachim Nilsson 23e0928e5c Minor, unused arguments no longer need magic tricks or hand waving
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 00:17:00 +01:00
Joachim Nilsson 9e31bd8a23 Fix #18: Add support for calling run/tasks on HOOK points
This patch implements support for calling run/task jobs on the built-in
`HOOK_*` points in Finit.  To map each HOOK point to a condition a new
classification was made, as shown in plugin.h and in the example below.

task <hook/mount/root> /sbin/attachubi.sh      # run in parallel with other tasks/services
run  <hook/net/up>     /sbin/dosomething.sh    # run in sequence with other commands

Please note, only rudimentary tested.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-13 17:58:48 +01:00
Joachim Nilsson 6b2678c2ed pidfile: On HOOK_SVC_RECONF the netlink plugin must run first
When performing an `initctl reload` with one (unchanged) service
depending on, e.g. `net/iface/lo`, its condition will not be set
to ON by the pidfile plugin unless the netlink plugin hook runs
first.

Example:

    service <net/iface/lo> /sbin/dropbear ...

Which provides the <svc/sbin/dropbear> condition, will not be
set by pidfile.so during `initctl reload` because dropbear is
still SIGSTP:ed waiting for <net/iface/lo>.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-24 15:55:35 +02:00
Joachim Nilsson faca84a590 Fix GCC 7 string truncation warning, too small temporary buffer
In GCC 7 the -Wall infers the new -Wformat-truncation which finds
problems with string truncation in functions like snprintf().

This patch fixes a problem in condition parsing for very long
PID filenames which might be truncated in internal buffers
causing a mismatch in Finit condition tracking.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-19 09:58:05 +02:00
Joachim Nilsson 30822f0d68 Remove UNUSED() macro and disable the compiler warning instead
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-02 21:59:23 +02:00
Joachim Nilsson fff68b7b06 Relocate source files to an src/ subdirectory
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-16 01:31:02 +01:00
Joachim Nilsson 0cccc629bf pidfile: Ensure svc is always followed by a slash
A service need no longer be fully qualified path.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-16 01:02:40 +01:00
Joachim Nilsson 57181264e9 pidfile: Make sure to set a default name for plugin
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-16 01:02:16 +01:00
Joachim Nilsson d5942f3267 Minor whitespace fixes
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-11 17:40:10 +01:00
Mattias Walström 816aa9a17c pidfile: Run the reconf-callback again until no application are in flux
If a service depend on the service last in the list the application
will be kept in flux state forever.

Signed-off-by: Mattias Walström <mattias.walstrom@westermo.se>
2017-01-11 16:25:04 +01:00
Joachim Nilsson 79b95daf3a The pidfile plugin requires /var/run, so depend on bootmisc
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-06-06 19:44:21 +02:00
Joachim Nilsson cc15d3f77b Merge branch 'finit-sm' of https://github.com/westermo/finit into westermo-finit-sm
Hand merged conflicts in the following files:
	Makefile
	finit.h
	service.c

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-06-04 19:48:08 +02:00
Jonas Johansson c1f725340d plugin/pidfile: also notify on modified pidfiles
Signed-off-by: Jonas Johansson <jonas.johansson@westermo.se>
2016-05-19 13:39:56 +02:00
Joachim Nilsson 4b0f78c1b5 Merge pull request #27 from westermo/wmo/2.4
Westermo fixes for UDP inetd services and more

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 12:06:43 +02:00
Joachim Nilsson 439d9df122 Set CLOEXEC flag to prevent leaking descriptors
Both the new initctl API and the new pidfile watcher plugin failed to
set CLOEXEC on their sockets.  This caused forked-off and exec()'d
children to inherit all these descriptors.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-24 10:52:39 +02:00
Joachim Nilsson 4efdc4fe19 Merge pull request #25 from westermo/wmo/2.4
Westermo fixes to Finit3
2016-04-10 20:08:25 +02:00
Joachim Nilsson da76cf4f75 Check return value from strtok(), may be NULL
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-10 19:58:46 +02:00
Joachim Nilsson a2177a8063 Fix GCC warning for signed vs unsigned comparison
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-04-10 19:58:13 +02:00