Commit Graph
55 Commits
Author SHA1 Message Date
Joachim Wiberg 17c69fef3d Fix #185: add devmon support, <dev/foo> condition provider
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-12-18 22:21:15 +01:00
Joachim Wiberg 912a281ee2 Fix #299: add support for service readiness notification
This patch adds service readiness notification to support daemons
employing systemd and s6 notification.  Complementing the native
Finit readiness support using PID files that exist already.

The two have slightly different ways of implementing readiness:

 - https://www.freedesktop.org/software/systemd/man/sd_notify.html
 - https://skarnet.org/software/s6/notifywhenup.html

Finit now provides both a NOTIFY_SOCKET environemnt variable, for
systemd, and a way to start s6 daemons with a descriptor argument.

For details on the syntax, see the `service` documentation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 20:06:26 +02:00
Joachim Wiberg 37e3be9a0d Refactor to share err/warn log API between daemon and client code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-05 09:57:45 +02:00
Joachim Wiberg 59525b80e3 Export finit/conf.h and finit/service.h for external plugins
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-06 10:38:19 +02:00
Joachim Wiberg bf72e6b9c8 Make bundled sulogin optional, use ./configure --with-sulogin
The bundled sulogin could be considered insecure, so leave it up to the
administrator, or system integrator, to decide which sulogin(8) is best
suited.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-03 05:58:57 +02:00
Joachim Wiberg 9cc9e3ddbb getty: if we cannot execute /bin/login, try sulogin before /bin/sh
Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 12:42:48 +02:00
Joachim Wiberg 94c0d1b833 Refactor built-in getty into a standalone getty in /libexec
This patch moves the built-in getty out of Finit into /libexec/finit/,
reducing the size of the Finit binary and simplifying the code.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-30 11:26:41 +02:00
Joachim Wiberg 4c8baaf7c0 Make kevent a configure option, disbled by default
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-17 00:26:57 +02:00
Joachim Wiberg d13e39e345 keventd ftbfs: add missing include path to libite
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-16 23:35:39 +02:00
Joachim Wiberg c251304146 Refactor sys condition plugin into a standalone keventd
This patch is a refactor of the prototype sys condition plugin.  It
moves most of the logic to monitor kernel events into a keventd that,
currently only, sets and clears the sys/pwr/ac condition.  The sys
plugin itself is now only a monitor of conditions and ensures Finit
follows them.  This is a lot more secure and moves (at least one piece
of) netlink processing out from PID 1.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:31:08 +02:00
Joachim Wiberg 842b522e68 Drop --disable-logit configure option, no longer in $PATH
Simplify build system.

The logit tool is, as of v4.0, installed into /libexec/finit/logit and
thus not part of the system $PATH.  If a sysadmin or distro wants to
remove it from the system it's entirely possible since Finit always
checks for logit availability before attempting to use it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-25 22:53:34 +02:00
Joachim Wiberg cd5b91680a sulogin: home cooked version, can be built -static
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-24 20:43:54 +02:00
Joachim Wiberg b8b7b53d96 External plugins require exporting cgroup.h, svc.h needs it
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-20 01:48:03 +02:00
Joachim Wiberg dd437bf0a5 Follow-up to 18ab7d3: restore start of built-in watchdogd
This patch restores the start of the built-in/bundled watchdogd.  It is
tracked in the `wdog` variable and handled as an exception at shutdown.

This is also a follow-up to 7b74c99, ensuring that we only kill/stop the
built-in watchdog, not any external.  External ones can register to be
the controlling watchdogd in the system -- Finit is not the arbiter for
singletons, this is up to the system engineer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-19 11:05:07 +02:00
Joachim Wiberg 02936de993 initctl: initical conversion to use libuEv for top command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-05 23:56:39 +02:00
Joachim Wiberg 6a6f3a8291 cgroup: refactor for cgroups v2, much cleaner + unified hieararchy
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1.  Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.

Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
            in cgroups v1 was handled by cgreaper.sh.  This is fixed
	    in the next commit in the series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:35 +01:00
Joachim Wiberg 74a26f559d initctl: refactor, split into multiple files
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-16 09:23:04 +01:00
Joachim Wiberg 3d98ad293b Restore telinit symlink to finit, compat only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 23:59:39 +01:00
Joachim Wiberg 305ad302f2 Refactor, reduce code duplication
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 10:28:54 +01:00
Joachim Wiberg 790a316607 Log rotate: improved handling of return values from syscalls
- Align the two implementations in logit.c and utmp-api.c
 - Use libite APIs to handle common constructs
 - If gzip fails, don't remove rotated-to file
 - Don't try gzip if rename fails
 - Issues found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 09:57:07 +01:00
Joachim Wiberg 774a24cdd8 Allow building with -D_FORTIFY_SOURCE[=1,2]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 11:17:59 +01:00
Joachim Wiberg 2bfede2cfe Add /lib/finit/sample.conf for initctl create
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 10:26:39 +01:00
Joachim Wiberg 7e3b18a38d Refactor install/uninstall of rescue.conf
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 09:34:36 +01:00
Joachim Wiberg 8dc1ad00d5 plugins: refactor, break out inotify watcher to src/iwatch.[ch]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-23 20:26:38 +01:00
Joachim Wiberg 7e42203627 Fix #147: refactor reboot as multi-call to initctl
This patch drops the stand-alone reboot binary and folds it into the
initctl tool, which now becomes a multi-call binary.

With this change the reboot/shutdown/poweroff/halt/suspend commands also
no longer default to sending signals to PID 1, instead it now uses the
initctl <--> finit UNIX domain socket API.  Signals are only used as a
fallback in case of non-working domain socket.  The -f,--force mode of
operation still works, where `reboot(2)` is called directly.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-21 10:59:08 +01:00
Magnus Malm 72a892ef55 Fix #151: Install logit in libexec
Signed-off-by: Magnus Malm <magnusmalm@gmail.com>
2021-02-17 11:33:48 +01:00
Jacques de Laval cb64c068e3 Fix #136: drop old init client tool
The SysV API compatibility layer gives too little value to be worth
the effort of maintaining it. Users are encouraged to use the
`initctl` tool instead.

Signed-off-by: Jacques de Laval <jacques@de-laval.se>
2021-02-11 17:52:08 +01:00
Joachim Wiberg e88a9b14ff Fix #101: remove built-in inetd from finit
This patch removes the built-in inetd support from Finit.  We recommend
using an external inetd instead, e.g. xinetd.

If you liked the feature set our inetd provided; filtering per interface
and port redirection, then please let us know or use the code in this
patch (MIT licensed) to recreate it.  We are open to reintroducing it,
but then as a stand-alone daemon like the bundled watchdogd and getty.

So long for now, old friend.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 12:46:40 +01:00
Joachim Nilsson 6a7f48970c Add cgreaper.sh to dist
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-12 00:29:39 +02:00
Joachim Nilsson 33bb6ed5ac Add --enable-logit to configure, disabled by default
Since sysklogd now ships an excellent enhanced logger tool there is no
need for Finit to provide its own tool for the same purpose by default.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:02:06 +01:00
Joachim Nilsson f51fde4d46 Initial support for cgroups
Similar to how systemd creates cgroups for all services, for purposes of
tracking, Finit now does the same.  We also mount all available cgroups
in the /sys/fs/cgroup namespace.

This patch adds support for grouping processes in logical cgroups, like
systemd, and an `initctl ps` command to list the hieararchy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-02-05 18:35:36 +01:00
Joachim Nilsson 859c216347 schedule: Add simple work queue helper
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-07 21:29:10 +02:00
Joachim Nilsson 3a1ad67e92 Convert built-in watchdog to a standalone mini watchdogd
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 8c1d84305d Minor, refactor
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 08:38:52 +01:00
Joachim Nilsson 45c10edad6 Fix static build, libplug.la is now in ../plugins/, not plugins/
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-15 16:05:39 +01:00
Joachim Nilsson 8063b1bfe1 Include rescue.conf in distribution
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-15 12:19:51 +01:00
Joachim Nilsson c315fb5637 Add logit v1.0 to Finit distribution
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-15 06:58:44 +01:00
Joachim Nilsson a1c33dec21 Refactor, move all PID file related functions to the same module
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-11 10:48:17 +01:00
Joachim Nilsson ab723d2f31 Add support for a rescue (recovery) mode from kernel cmdline
This patch adds a rescue (revovery) mode to Finit.  Simply add `rescue`
to the kernel cmdline at boot and the following steps at bootstrap will
be skipped:

- Load of services/run/task/etc in /etc/finit.conf + /etc/finit.d/*.conf
- fsck of filesystems in /etc/fstab
- Remount of / to read-write
- Mount of all filesystems in /etc/fstab
- swapon
- A few plugin hooks:
  - HOOK_ROOTFS_UP
  - HOOK_MOUNT_ERROR
  - HOOK_BASEFS_UP
- `runparts DIR`
- /etc/rc.local

Instead of loading /etc/finit.conf and /etc/finit.d/*.conf Finit loads
the file /lib/finit/rescue.conf, which can be overridden by the operator
if needed.  If this file is removed (or lost), Finit falls back to start
a simple root shell, without any login.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson c605874b26 Remove --with-plugindir=DIR, use --prefix or --libdir instead
The /lib/finit/plugins path is as of this patch not longer possible to
change.  Use --prefix or --libdir instead to change the leading path.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson c33ba6a477 Remove reboot symlinks properly on uninstall
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:20:06 +01:00
Joachim Nilsson c0515d112e New client side API to access svc_t entries without shared memory
This change is one of the required intermediate steps to remove the
shared memory store for all svc_t, this in turn to avoid any external
programs manipulating the internal memory of PID 1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 11:06:19 +01:00
Joachim Nilsson cae61ad6df initctl refactor, break out domain socket/client API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-16 12:15:28 +01:00
Joachim Nilsson 27e4af5ed8 Rename, client.c --> telinit.c
We need the name client.c for the client side of api.c, so let's rename
the client to its traditional name.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-15 14:00:11 +01:00
Joachim Nilsson 250e26f2f6 Fix #84: Reset TTY w/ stty() before taking any pre-getty action
This patch moves the stty() function from getty.c to a separate file so
it can be called from exec.c as well.  The fix to #84 is simply to call
stty() in prepare_tty(), which is shared by run_getty() and run_getty2()
and called before "Please press Enter ...".

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-29 11:59:48 +01:00
Joachim Nilsson 1677436137 initctl: Allow C99 style
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-09-26 10:39:45 +02:00
Joachim Nilsson 99f3f0291a Makefile.am: Fix cut-and-paste error
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-04 21:48:16 +02:00
Joachim Nilsson 6d3d190134 reboot: Add search path to libite (-lite) headers and .so
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-04 21:40:46 +02:00
Joachim Nilsson 30822f0d68 Remove UNUSED() macro and disable the compiler warning instead
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-02 21:59:23 +02:00
Joachim Nilsson 9a4f46dba4 Install log.h for external plugins
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-01 20:36:47 +02:00