Commit Graph
284 Commits
Author SHA1 Message Date
Joachim Nilsson 2fac65becb Fix long-standing bug, runparts() should run before runlevel change
The difference between `runparts DIR` and `/etc/rc.local` is that one
should run just before the first runlevel change (to the configured
runlevel) at the end of bootstrap, whereas the other should run just
before launcing the TTYs, i.e. after all tasks in the configured
runlevel have been started.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:48:47 +01:00
Joachim Nilsson b04983c3f3 conf: Make rlimit [hard|soft] optional => possible to set both
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 20:15:12 +01:00
Joachim Nilsson f2d142ef57 Only reload .conf and services if any .conf file has changed
This patch is an optimization.  Now that we monitor for any .conf file
changes (as soon as the event loop starts) we can skip automatic reload
of all .conf files and services if no .conf file has changed.  Unless
the user issues an `initctl reload`, `init q`, or sends us SIGHUP.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 19:22:01 +01:00
Joachim Nilsson 33ce746e58 parse_conf(): Increase log with actual limits in case of problems.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:57:36 +01:00
Joachim Nilsson 6ecb86b4a7 conf_reload(): No need to reload global rlimits again
This patch removes duplicate reload of global_rlimit[], which
parse_conf() already has done.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:56:30 +01:00
Joachim Nilsson 338810b886 Fix #92: Load .conf files and initialize global_rlimit[] earlier
As reported in #92, systems with an udevd very early register a service
using global_rlimit[].  The change was introduced in b68c5c1 but did
not take the ordering problem into consideration, global_rlimit[] was
left uninitialized, which likely led to severely limited udevd that
was continously crashing.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-29 16:51:49 +01:00
Joachim Nilsson c1344e89ff api_exit(): Only shutdown() of API socket at runtime
Not needed at shutdown/reboot.  Also, it may segfault at that stage.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:48:44 +01:00
Joachim Nilsson bc35b42bd2 inet_stop(): Check argument and skip shutdown(), just close() socket
- Validate function argument
- Skip¹ shutdown() when closing a TCP socket, not needed

___
¹ also, shutdown() segfaults a late shutdown/reboot

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:46:19 +01:00
Joachim Nilsson dcf8fbe235 do_shutdown(): Advise watchdog using SIGPWR, system is going down
On shutdown/reboot, send SIGPR as a heads-up to watchdogd that the
system is going down.  All file systems are about to be unmounted.
It's just about the last process left running in the system, so we
give it two seconds to complete its work before we continue.

When everything has been unmounted and we're ready to call reboot(),
we send SIGTERM to the registered watchdog, to give ti the chance to
let the WDT reset the system.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:45:02 +01:00
Joachim Nilsson c82a2ce215 Built-in watchdog: on SIGPWR, exit main loop and prepare for SIGTERM
When Finit enters shutdown/reboot we need to advise any watchdogd that
we are going down *before* we unmount any file systems.  This to let
the user save any state, e.g. reboot counters, to disk.  Right before
we call reboot() in Finit we send SIGTERM to the watchdogd to give it
the chance to use the WDT to reboot the system.

The WDT cricuitry on embedded systems is often connected to the RESETn
logic of all relevant board compoents, whereas reboot() only reboots the
SoC with the CPU.  Hence, a WDT reboot is more efficient and more like a
regular power cycle, which users of embedded systems often want.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:24:32 +01:00
Joachim Nilsson e1bb5e3396 Add --disable-redirect-output to configure script
This patch makes it possible to control the default redirection of
(misbehaving) services output to /dev/null.  With this disabled,
a service may write to its stdout/stderr and mess up the console.

By default all service/run/tasks stdout/stderr is redirected.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-28 20:22:06 +01:00
Joachim Nilsson 0d19842aa1 conf_changed(): Fix possible NULL ptr deref, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:35:07 +01:00
Joachim Nilsson 6f665ab283 inet_dgram_drop(): Fix control flow logic, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:31:19 +01:00
Joachim Nilsson 3f731aa5a3 inet_dgram_drop(): Check return value from recv()
Found by Coverity Scan.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:28:22 +01:00
Joachim Nilsson 9e8a01669e api: Fix possible descriptor leak, found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 10:02:49 +01:00
Joachim Nilsson 72bc3b1a91 Fix #91: Add support for tty nologin, to start /bin/sh immediately
This patch adds a `nologin` flag to the `tty` configuration directive,
making it possible to set up really simple embedded systems with no
login.

Example, put the following line in `/etc/finit.d/getty.conf` to get
a "Please press Enter to ..." prompt before being presented with a
root shell prompt.

    tty [12345] @console noclear nologin

Needless to say, this is not very secure, but can be really useful
for developer setups, during board bringup, or similar.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-24 01:54:07 +01:00
Joachim Nilsson d6ea1c0cab Protect internal services like dbus-daemon and udevd
In f3669c7 the difference between static and dynamic services was
removed.  This led to a regression in handling internally created
services for, e.g., dbus-daemon and udevd, mentioned in issue #90.

This patch introduces a "protected" flag for svc_t to prevent the
mark-and-sweep handling of regularly loaded services.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 21:57:31 +01:00
Joachim Nilsson 3258edc246 Fix #90: Restore tmpfs mount of /dev/shm, removed in d7401b2
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:02:06 +01:00
Joachim Nilsson 32b7a14cb3 Add ismnt() helper function, wrap fismnt()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 19:00:41 +01:00
Joachim Nilsson 0e37bb0924 Follow-up to b0663d0, cond_init() must run before first hooks
The new condition triggered hooks requrie /var/run/finit/cond to
be set up before calling the first user-configurable hooks.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 11:19:35 +01:00
Joachim Nilsson 360f3e72bc Audit b0663d0, add newline to generation ID in cond files
- Add newline to cond generation ID, like PID files, easier when
  debugging.  Does not affect fscanf() in cond_get_gen()
- Update copyright years

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 10:05:45 +01:00
Joachim Nilsson e94d2a8c08 Merge branch 'master' into cond-generation 2017-12-23 09:31:41 +01:00
Joachim Nilsson f7c0366fa2 Fix segfault on X86_64, call va_end()+va_start() for each vfprintf()
... varargs is a special kind of hell.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 00:38:01 +01:00
Joachim Nilsson 8992e7bf2b Refactor svc_iterator() into a proper iterator, add first flag
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 23:56:14 +01:00
Joachim Nilsson 95518df62d Some systems rely on /dev/shm being there for mount -a
This was accidentally removed in d7401b2, when svc_t was refactored
from using shared memory.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 16:44:52 +01:00
Joachim Nilsson b439ac670d .conf: don't rely on mtime to determine if service needs reloading
Until now Finit has used mtime to determine if a file has been changed,
or simply touched to request reload, when `initctl reload` is called.
Using mtime for this purpose is a monumentally bad idea since time can
be changed at any point: a user may adjust the time, NTP continously
tunes the clock, and time stamps are stored as the walltime.  So if we
compare timestamps against the last time we (booted or) did reload, we
would miss .conf file changes.

This patch replaces the mtime mistake with an inotify watcher for the
following files: /etc/finit.d/*.conf, /etc/finit.d/available/*.conf,
and /etc/finit.conf.  All file changes between (bootstraps and) calls
to `initctl reload` are tracked, like the mtime backend it replaces.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:08:38 +01:00
Joachim Nilsson bb3d9c8670 initctl: Add support for touch <CONF>, mark .conf for reload
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:50:18 +01:00
Joachim Nilsson c59f7d23f4 Add and improve debug messages, clean out old dev. comments
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 12:40:43 +01:00
Tobias Waldekranz b0663d04e4 cond: don't rely on mtime for condition management
TIL, using mtimes for tracking event orderings is a monumentally bad
idea (queue the nodding UNIX-beards). Mtimes are in wallclock time which
is not necessarily monotonically increasing. A user may adjust the time,
an NTP daemon will continously tune the clock and so on.

Instead, store an explicit generation number in each condition file,
which will be monotonically increased by finit on each reconf.
2017-12-21 11:10:47 +01:00
Joachim Nilsson e7cca05fe3 Reserve certain configuration directives for bootstrap only
The following configuration directives, previously only allowed
in /etc/finit.conf, are now also only allowed in runlevel S, i.e.
at bootstrap:

- host
- mknod
- network
- runparts
- runlevel

This change is in preparation for allowing reload of finit.conf
as well as /etc/finit.d/*.conf, which we already support.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:16:55 +01:00
Joachim Nilsson f3669c7537 svc: Remove svc_dynamic_iterator(), soon no difference between svc's
This is a prelude to a major behavioral change.  The difference between
a static and dynamic service will be removed in Finit v3.1.  This means
all .conf files, including /etc/finit.conf, will be re-read on reload.

However, not all configuration directives will be re-read, some will
only be applicable at bootstrap, i.e. runlevel S.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:04:14 +01:00
Joachim Nilsson a9456cec41 svc: Remove unused function, svc_foreach_dynamic()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 09:02:38 +01:00
Joachim Nilsson 61a9926442 Minor, staticify
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 00:13:21 +01:00
Joachim Nilsson 7784480abe Postpone networking stuff, + hooks, a bit to the finalize() step
This patch moves the networking bit to the latter part of bootstrap,
called finalize(), in favor of starting the event loop earlier.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-20 00:10:29 +01:00
Joachim Nilsson db50c09ec5 initctl: Improve show SVC command output a bit, provide summary
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 21:04:17 +01:00
Joachim Nilsson 0f1f51b5ad Refactor, change from static array of svc_t to linked list
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 17:50:02 +01:00
Joachim Nilsson d7401b2a96 Follow-up to issue #81: remove SysV shared memory IPC altogether
This change removes a long standing kernel requirement and architectural
mishap in the design of Finit v1.  It is no longer necessary to include
CONFIG_SYSVIPC in the kernel to use Finit and its command line tool
initctl.  It is also no longer possible to connect to the internals of
PID 1 using shmat(), the initctl tool has already been updated to use
the domain socket API.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 11:20:21 +01:00
Joachim Nilsson c0515d112e New client side API to access svc_t entries without shared memory
This change is one of the required intermediate steps to remove the
shared memory store for all svc_t, this in turn to avoid any external
programs manipulating the internal memory of PID 1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 11:06:19 +01:00
Joachim Nilsson 9a8b55737f Move svc_status() + svc_dirtystr() to header file as static inline
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 11:03:15 +01:00
Joachim Nilsson d7d8b8487d Refactor other iterators to use new re-entrant svc_iterator1() API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 07:49:45 +01:00
Joachim Nilsson 7f04382eee Refactor, use new re-entrant svc_iterator1() API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 00:21:07 +01:00
Joachim Nilsson bf004d9ec4 svc: Re-entrant replacement to svc_iterator() --> svc_iterator1()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 00:18:13 +01:00
Joachim Nilsson d6b2ac94dd Fix regression in 32b9096, only pick next :ID for inetd services
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-17 14:54:46 +01:00
Joachim Nilsson 7362e6d00a initctl: Fix error handling for intictl start/stop if missing arg
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-17 12:12:57 +01:00
Joachim Nilsson d94d11e00a initctl: Allow short forms of commands
For ease of use, allow short forms of commands, like:

   initctl h
   initctl c d
   initctl l

Also, default to show conditions if no argument to cond is given.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-17 12:09:41 +01:00
Joachim Nilsson f06a0fcb71 initctl: Support printing previous runlevel
This patch adds support for "PREVLEVEL RUNLEVEL" output to the initctl
runlevel command.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-17 10:54:06 +01:00
Joachim Nilsson cae61ad6df initctl refactor, break out domain socket/client API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-16 12:15:28 +01:00
Joachim Nilsson 27e4af5ed8 Rename, client.c --> telinit.c
We need the name client.c for the client side of api.c, so let's rename
the client to its traditional name.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-15 14:00:11 +01:00
Lennart Eriksson 0c75e59b77 Drop UDP packets from unwanted interfaces
Previously UDP packets were never dropped and if a request came
from a not valid interface inetd got stuck in an inifinite
loop looking at the same packet every time and not dropping it.

Signed-off-by: Lennart Eriksson <lennart.eriksson@westermo.se>
2017-12-14 10:34:07 +01:00
Joachim Nilsson 32b9096e31 Fix #87: Allow inetd services to be registered with an id != 1
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-13 22:20:30 +01:00