Commit Graph
21 Commits
Author SHA1 Message Date
Joachim Nilsson 6e07dd8dec Add support for starting/stopping services on Netlink events
This commit adds support for event based services to Finit.  Along with
the previously added support for multiple instances of the same process,
the feature scope for Finit v2.0 has been reached!

As of now a service can be declared in /etc/finit.conf or /etc/finit.d/
like this:

    service :1 [2345] <!IFUP:eth0,GW> /sbin/dropbear -R -F -p 22 -- SSH daemon

Here the first instance `:1` of dropbear is declared to run in runlevels
2-5, but only if eth0 `IFUP:eth0` is up and a gateway `GW` is set.  When
the configuration changes, a new gateway is set, or somehow a new `IFUP`
event for eth0 is received, then dropbear is not SIGHUP'ed, but instead
stop-started `<!>`.  The latter trick applies to all services, even
those that do not define any events.

Currently inetd services are not supported for event based starting, but
it could easily be added.  Likely scenario is to deny incoming requests
on, e.g., eth0 if there is no gateway.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-09-15 09:13:33 +02:00
Joachim Nilsson f9ddb1bdfc Make sure to always run HOOK_SVC_RECONF when services have been stopped.
Previously `HOOK_SVC_RECONF` was only called on `initctl reload`,
now we also call it on `initctl emit "STOP"`.  This seems like a
good idea atm, hopefully it will remain a good idea.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-09-11 08:58:39 +02:00
Joachim Nilsson 0bd57a7826 Fix missing overwrite argument to setenv().
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-09-02 16:05:42 +02:00
Joachim Nilsson 814ffd9259 Fix missing default PATH for root and non-root users.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-09-02 14:50:46 +02:00
Joachim Nilsson 8b8ddc43b5 Refactor: Further API cleanup -- hide svc_t internals.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-29 01:50:21 +02:00
Joachim Nilsson 838ec0423d Fix: Loss of dynamic service on second reload (unmodified).
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-29 01:25:45 +02:00
Joachim Nilsson a05f920292 Refactor: Cleanup internal API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-28 17:23:07 +02:00
Joachim Nilsson f1807a32ca Make it possible to distribute finit.h in 'make dev-install'
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 8e12dba8d9 Refactor: Move conf.c declarations from finit.h --> conf.h
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 589a7ea8a5 Always run HOOK_SVC_RECONF on SIGHUP/reload
When Finit receives SIGHUP or a reload command all services listed in
/etc/finit.d/*.conf are first stopped and then started again.  I.e.,
removed/changed services are stopped and then new/changed services are
started again.  In between we call HOOK_SVC_RECONF.  It should always be
called, even though no services were removed/changed/added.  This to
allow plugins connected to that hook may need to run as intended.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-22 15:12:20 +02:00
Joachim Nilsson 577622c945 Add support for calling initctl with process name as well as JOBID
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit.  When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances.  For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-21 15:54:47 +02:00
Joachim Nilsson 66f472bb05 service_start(): Make sure to collect the run child.
Fix side effect with run stanza children not being collected if finit is
not run in verbose mode.  Regression introduced in release cycle.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 0de4fb0cbf inetd: Fix naming of built-in service on custom port.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-17 13:36:36 +02:00
Joachim Nilsson 03573b41ca Add support for a deny filter syntax to inetd services
This patch changes the syntax for custom inetd services and adds support
for deny filters.  The new syntax is:

    inetd service/proto[@iface,!iface,...] </path/to/cmd | internal[.service]>

This means the second column now defines what@from and the third to/what
process.  For internal services on a custom port the internal.service
syntax must be specified, so Finit can properly bind the inetd service
to the correct plugin.  Here follows a few examples:

    inetd time/udp                    wait [2345] internal                -- UNIX rdate service
    inetd time/tcp                  nowait [2345] internal                -- UNIX rdate service
    inetd 3737/tcp                  nowait [2345] internal.time           -- UNIX rdate service
    inetd telnet/tcp@*,!eth1,!eth0, nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 2323/tcp@eth1,eth2,eth0   nowait [2345] /sbin/telnetd -i -F     -- Telnet service
    inetd 222/tcp@eth0              nowait [2345] /sbin/dropbear -i -R -F -- SSH service
    inetd ssh/tcp@*,!eth0           nowait [2345] /sbin/dropbear -i -R -F -- SSH service

Access to telnet on port `2323` is only possible from interfaces `eth0`,
`eth1` and `eth2`.  The standard telnet port (`23`) is available from
all other interfaces, but also `eth2`.  The `*` notation used in the ssh
stanza means *any* interface, however, here `eth0` is not allowed.

NOTE: This patch breaks syntax compatibility with Finit v1.12!

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-15 14:15:39 +02:00
Joachim Nilsson 24e1d284ad Add support for finit <stop|start|reload|restart> JOB
This patch further extends the capabilities of the client with the
ability to control the running state of services:

    finit <stop|start|reload|restart> JOB

Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch.  A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier.  See the output of `finit status` for the JOB id.

Also, with the introduction of multiple instances we broke support for
multiple related inetd services.  This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 08:32:49 +02:00
Joachim Nilsson 720324b256 Change syntax for multiple instances: #ID --> :ID
Turns out that #ID syntax for multiple instances, introduced in cb07556,
was very cumbersome to reference from the shell command line in the new
Finit client.  This patch changes the syntax from #ID to :ID, which also
means that listing services/jobs in the shell will look like JOB:ID.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-08 01:07:41 +02:00
Joachim Nilsson 0dd97de046 Add --enable-quiet to configure, makes Finit real quiet.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 15:57:11 +02:00
Joachim Nilsson 97a48ec5fb Refactor: move advanced service methods from svc.c --> service.c
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2015-06-07 03:23:46 +02:00
Joachim Nilsson 0e02429e75 Convert finit to use libev and fix so plugin ctors runs on dlopen().
Lots of cleanup and simplification of the main code in this commit.
Most notably libev has been added to take care of the main loop and
monitor services. Still TODO is migrating to use the libev signal
handling.

Convert initctl.c:listen_initctl() to a plugin instead.  This also
meant introducing a new form of I/O plugin to finit, also handled
by libev.

Load plugins *after* we've setup the base filesystem (BASEFS) in case
plugins reside on a filesystem not reachable before "mount -a" has run.
This also has the side effect of lining up nicely with the first level
plugin hooks.

If a plugin wants to hook up with a loded service we connect them by
their respective numeric IDs in plugin_register().  I.e., the service
monitor checks if a service has a registered callback, which in turn
decides if a service should be started, stopped or reloaded.

Rip out old EeePC distribution defines from finit.h, none of it really
applies anymore.  If you need distribution specific settings this is
the place to put them.

Make hookpoint names (#defines) clearer: after BASEFS, after networking,
after all setup, etc.

Use #inlude_next <signal.h> in signal.h to include system header file!

Simplify service monitor: move essential code to svc.c and rip out
the TIPC dependency. Write your own service.so plugin, or wait for
a more complete example of how to extend service monitoring using
the primitives in svc.c

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-09-25 14:23:23 +02:00
Joachim Nilsson 077a7e82e0 Debian now boots to X!
finit.conf:
        Use this as /etc/finit.conf on a Debian 6.0 based system with X
        installed and sysklogd instead of rsyslogd.  Works.

services:
        Alternative method for extending the finit boot procedure. Simply
        place this script file in an /etc/finit.d/ directory.  The script
        uses the standard run-parts tool to chain load other start scripts.

helpers.c:
        o New functions:
          - run(): home grown system() replacement
          - run_interactive(): display progress and status when called

        o Bugfix start_process(), make sure to use same signal setup for
          children as in run() and run_interactive(). Also, use execvp()
          instead of execv() to allow searching $PATH for executables.

finit.h:
        o Move signal specific code to new signal.h.
        o Bypass verbosity setting to let echo() always print to screen.

finit.c:
        o Make run_parts() the default, remove external deps, it works.

        o Use run() and run_interactive() to speed up execution further
          on embedded systems where forking is expensive.

        o Kernel cmdline "quiet" should not close STDIO since this makes
          it impossible to run some daemons and start scripts.  Instead,
          we let "quiet" toggle the finit verbosity setting.

        o Remove kernel cmdline "--verbose" (Upstart compat), to be used
          to enable verbose finit when kernel should be quiet.

        o Setup kernel specific settings in /etc/sysctl.conf

        o Fix D-Bus startup problems. Probably what caused X from not
          working initially. Silly rabbit.

        o Use system() workaround to start X, cannot get it to start
          at all using run() or run_interactive() at the moment.

signal.h:
        New file, header file for signal.c.  Was about time.

signal.c:
        Remove blocking of SIGCHLD from sig_setup(), instead we setup
        SIGCHLD early in sig_init() to handle fork() in run() & C:o.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-09-20 17:50:53 +02:00
Joachim Nilsson d21dc2b477 Westermo service starter and supervisor, inspired by daemontools
finit.c:
        o New service and shell_service stanzas for finit.conf
        o Run service_startup() before /etc/finit.d/ hooks
        o Run service_monitor() at end of startup

helpers.c:
        o Several new functions:
          - print_desc() displays a service starting up
          - print_result() shows if service started OK or not
          - start_process() is used by the services framework

svc.c:
        Generic API for managing svc_t structures

ipc.o:
        TIPC based framework for communicating with the service monitor.
        E.g., to relay (re)configuration signals from a Web/CLI
        front-end via finit to one or many setup daemons, and back.

services.c:
        Service monitor framework

strlcpy.c:
        Secure strncpy() replacement from OpenBSD under the free ISC License.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2012-09-20 01:16:00 +02:00