Commit Graph
415 Commits
Author SHA1 Message Date
Joachim Nilsson eee6ffe95c Refactor end of service_start() to prevent deref freed svc
An SVC_TYPE_RUN may be deleted by svc_clean_bootstrap() as soon as it's
been collected.  We must not try to dereference that pointer afterwards,
e.g. in svc_is_daemon().

Refactor the whole of it to make the code easier to follow.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-09-28 06:50:33 +02:00
Joachim Nilsson a5491b3ded Remove HOOK_SVC_START, caused more problems than it was worth
An operator wanting to monitor processes started by Finit could use the
kernel ftrace framework.  E.g. execsnoop in perf-tools.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-09-28 06:49:49 +02:00
Joachim Nilsson fa0a4e8579 Merge branch 'dev' 2018-07-10 22:38:45 +02:00
Joachim Nilsson a487a30814 Refactor wdog tracking and hand-over to use svc_t instead of PID
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 40db4f4f58 Minor, refactor to avoid namespace confusion with service.c API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 3a1ad67e92 Convert built-in watchdog to a standalone mini watchdogd
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-09 23:49:04 +02:00
Joachim Nilsson 43942ab513 watchdog.c: Update copyright years and reflow license header
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-07-08 19:21:26 +02:00
Joachim Nilsson 3b2f2690e7 initctl: start and restart should behave the same if svc has crashed
Found by Mattias Walström, Westermo.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-06-18 18:33:49 +02:00
Jonas Johansson 59f22c7d27 fixup! inetd: only restart inetd services when neccessary
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2018-05-07 09:25:55 +02:00
Jonas Johansson f522a26125 inetd: only restart inetd services when neccessary
Do not restart a inetd service if the listening interface is changed.
Only bring down established connection which are no longer allowed,
i.e. do not touch already allowed established connections.

Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2018-05-03 08:57:19 +02:00
Joachim Nilsson efb1d40ffd Merge pull request #107 from jonasj76/inetd-stop-children
Stop inetd spawned child processes when stopping inetd service
2018-03-23 15:48:02 +01:00
Jonas Johansson af9a06466c inetd: stop inetd spawned child processes when stopping inetd service
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2018-03-23 15:40:42 +01:00
Jonas Johansson 7ed9f2ad05 inetd: do not mark inetd connections for deletion when reloading services
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
2018-03-23 15:32:41 +01:00
Joachim Nilsson 65ccc407fa Follow-up #100: Remove buggy "optimization", caught by Coverity Scan
We cannot allow pid_runpath() to return its 'file' argument because that
may be a stack variable in a helper function.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-22 08:08:48 +01:00
Joachim Nilsson 24299ab5d9 Fix #105: Only remove /etc/nologin when moving from runlevel 0, 1, 6
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-21 08:44:14 +01:00
Joachim Nilsson e9670b87b3 Refactor, convert struct tty members to static strings
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-18 19:19:45 +01:00
Joachim Nilsson 406339e755 Refactor, unify finit_tty_t + tty_node_t --> struct tty
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-18 18:19:31 +01:00
Joachim Nilsson dc7039b8d8 Fix #100: Adjust path to COND_RECONF /var/run symlink may be missing
On systems with the new /run hierarchy the compat symlink from /var/run
may be missing, or not yet be set up by bootmisc.so.  This patch adds a
layer of safety to the condition layer, both set and get cond ops now
perform an adjustmed of the condition path if needed.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-18 11:49:27 +01:00
Joachim Nilsson 90249e50ef initctl: Show available services if none given
In case a user forgets to type in the service to enable, disable, or
touch, we try to be helpful and list available services instead of
bugging out.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-06 18:41:36 +01:00
Joachim Nilsson b8e6954c46 Issue #96: Remember to track run commands having run once as well
All service/task commands are tracked by the state machine, but run
commands are a bit special since they must run in sequence.  Hence,
we must increment their 'once' counter in service_start() instead.

This should fix the issue mentioned in #96 "took a long time before
the next line" -- because Finit was waiting for udevadm to reach a
once count > 0, which we didn't increment.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:50 +01:00
Joachim Nilsson 4585aa0fb4 Issue #96: Add udevd condition to udevadm trigger commands
We must wait for udevd to be started before we call udevadm.  However,
udevd doesn't create a PID file, so we must also fake this.  There is
still a slight risk of a race condition: udevd not having properly
started before udevadm tries to connect, but it works OK in Debian.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:27 +01:00
Joachim Nilsson f2655d14c8 Bootstrap condition subsystem as soon as possible
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:27 +01:00
Joachim Nilsson 6d1d51b28c Remove duplicate 'services' in debug message
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 23:57:27 +01:00
Joachim Nilsson b9d233d19e Issue #96: Register two unique (!) udev triggers, run device trig 1st
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 08:43:15 +01:00
Joachim Nilsson 2ec132c75a Fix #96: Start udevd as a proper service
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-01 01:06:32 +01:00
Joachim Nilsson 829405f966 watchdog: Do not emit error message if user has no /dev/watchdog
Running Finit on a kernel or system without WDT support built-in should
not trigger an error message from Finit.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 23:05:24 +01:00
Joachim Nilsson 72526d9e88 Revert #52: don't reload .conf files after run-parts and rc.local
Issue #52 suggested calling service_reload_dynamic() automatically after
run-parts and /etc/rc.local.  This may seem like a good idea, but not
only does it create extra overhead, it currently also freezes the boot
and fails to present a login prompt if a run-parts directory exists.
Yes, the directory can be empty, it just have to exist to trigger this
regression.

While trying to find the root cause I realized this was all just wrong.
If the user does something that requires reloading finit, they should
call `initctl reload` from the script instead.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 22:13:02 +01:00
Joachim Nilsson f704eab6d7 Increase debug level when starting a TTY
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 22:11:32 +01:00
Joachim Nilsson a50bfc016e Set $SHELL to a sane default value, used by BusyBox
When finit calls out to external tools, like `ifup $IFACE`, that tool in
turn may use other external tools.  On systems with BusyBox our calling
`ifup $IFACE` will result in BusyBox casting a magic spell: if $SHELL is
unset it goes looking in the file /etc/passwd for the shell of $USER
which may not be set to a Bourne compatible UNIX shell, so commands like
`ip link ...` or `run-parts ...` will fail hard.

This patch adds SHELL=/bin/sh as a sane early default.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-26 22:07:31 +01:00
Joachim Nilsson dedf885b92 Prefer udev to handle /dev if mdev is also available on the system
Some systems, usually those built around BusyBox, have mdev installed
but have an option to install udev.  In those cases the user likely
prefers to use udev over mdev and this patch addresses that.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-17 16:06:22 +01:00
Joachim Nilsson 93a21197ab Fix artefact bug with missing OS/Finit title in banner
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-17 16:06:22 +01:00
Joachim Nilsson 7fdb280712 initctl: Introduce -b[atch] mode for non-interactive use
This patch introduces a new option to initctl; -b, --batch skips
screen_init(), which might otherwise leak ANSI screen resize codes
to the console.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-02-16 10:06:37 +01:00
Tobias Waldekranz fd837a4242 Do not try to SIGKILL inetd services, they are not backed by a pid
As a precaution, services who are being stopped are automatically sent
a SIGKILL after 3 seconds if they refuse to go away willingly.

Unfortunately this backup mechanism was also enabled for inetd
services which are not backed by a real process. When the service was
freed the timer was not stopped, since it was not expected to be
armed. The timer would then trigger, causing a use-after-free on the
timer watcher containing a bogus callback pointer.
2018-02-09 14:11:48 +01:00
Joachim Nilsson 29fe8cc73d Move run/tasks to stopping state when they exit, like services
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-29 18:40:41 +01:00
Joachim Nilsson 2b6f00f126 Minor, whitespace
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-27 17:53:23 +01:00
Joachim Nilsson 86e534095d Always check svc_t pointer before dereferencing it
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-26 12:47:45 +01:00
Joachim Nilsson 865a3a7a4a Regression, unblock (UDP) parent for terminating inetd connections
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-26 12:46:15 +01:00
Joachim Nilsson 2dc7de3aa2 Make sure to unblock inetd UDP svc when connection terminates
When an UDP inetd connection terminates we must make sure to unblock the
parent, which is (currently) blocked during the transaction.

This patch is a fix to a regression introduced in 2c904b5, for v3.1

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-25 19:14:59 +01:00
Joachim Nilsson a3eadb72a7 Fix #98, handle --disable-inetd case in service_unregister()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 15:48:41 +01:00
Joachim Nilsson ad98f69560 Ignore return value from rename(), ofile may not exist yet.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 14:03:07 +01:00
Joachim Nilsson 710a3d2c8f Fix Coverity warning, array cannot be NULL
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 11:45:15 +01:00
Joachim Nilsson 658fb9b037 Check return value from rename(), fall back to truncate() on error
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 11:39:50 +01:00
Joachim Nilsson eeb13dba74 Toggle silent mode (progress) when toggling debug mode
Starting in debug mode and disabling debug at runtime did not exhibit
the same behavior as if starting in normal mode and toggling debug mode
at runtime.  This patch adds toggling of silent mode (progress output)
to runtime debug toggling.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 09:44:44 +01:00
Joachim Nilsson 3d20237959 Follow-up to f858d94, only reinitialize screen when toggling debug mode
The screen_init() call for each print() & C:o caused serious screen
artefacts in debug mode.  This patch reworks f858d94 to only re-init
screen when toggling debug.

Also, avoid screen_init() completely if started in debug mode.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 09:33:24 +01:00
Joachim Nilsson ddf1bce642 Add screen_exit() fn to restore screen defaults in debug mode
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 09:31:44 +01:00
Joachim Nilsson 1df6a91a94 Document sufficiently complex, yet deceptively simple, function
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 00:44:40 +01:00
Joachim Nilsson c64a71ff30 Follow-up to ba2ab4b, crashing services may not have a PID rn
- Don't warn of missing PID, even if only _d(), perfectly normal
- Allow stopping restart timer of non-services (e.g. task/run)
- Allow stopping services with no PID rn, i.e. stop libuEv timer

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-23 00:17:02 +01:00
Joachim Nilsson ba2ab4b446 Follow-up to 2683049, only stop running, non-inet, services
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 20:52:37 +01:00
Joachim Nilsson 3d68ebbf54 Fix off-by-one in condition reassert()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 15:24:11 +01:00
Joachim Nilsson 6e017025aa Fix bad string pointer arithmetic in condition reassert
On `initctl reload` we reassert conditions, i.e. bring each still viable
condition back in sync with the new reconf generation.  This patch fixes
an assumption in the reassert() callback that caused the following nasty
transformation:

	/run/finit/cond/net/lo/up --> /run/finit/cond/lo/up

The transformation was caused by the reassert() code assuming a /var/run
prefix rather than /run.  We must check the actual runpath, or like this
patch does, use a path neutral way to find the base condition string.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 15:17:07 +01:00