Adds an extra 'log' parameter to services that routes STDOUT and STDERR to syslog.
Uses a PTY rather than a pipe, as this prevents log messages hanging around in a buffer indefinitely.
This patch prevents too early start of services depending on other
services. E.g, if service B depends on A then we must wait for A to
signal that it is ready before we allow B to start -- in a Finit based
system A does this by creating, or touching (updating mtime), its PID
file. Services (like A) that support SIGHUP should call utime(), or
utimensat(), on the PID file at the end of their SIGHUP handler.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch introduces a new service type called SVC_TYPE_INETD_CONN,
which represents a running inetd connection. These are handled in much
the same way as tasks. I.e. they are considered one-time jobs, with
the difference that they are removed upon completion.
When cleaning up removed services, the assumption was made that if a
service was not 'removed', it was 'clean'. In reality, it could also
be 'updated', which was then overwritten, causing services not being
restarted. Don't do that.
As a future precaution, make the dirty field const, only allowing
updates from accessor methods.
Old event system has been replaced with a more generic condition
concept. The idea is that finit plugins may provide arbitrary
conditions that services may specify as dependencies that they require
to run.
In order to accomodate this, the service management has been
redesigned to use a state machine.
This patch fixes a hang when performing a system reconfiguration using
`initctl reload`, `SIGHUP` or running `(f)init q`, which caused Finit
to wait for SIGHUP:able services to stop.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for declaring *why* a service is being stopped
or reloaded. This is later used when all stopped services have been
collected by the `service_monitor()` to issue start or postponed SIGHUP.
As an added benefit we can now also see why a service is not running.
If it has been paused by a user, halted when moving to another runlevel,
waiting for a condition (event), or similar.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit adds support for event based services to Finit. Along with
the previously added support for multiple instances of the same process,
the feature scope for Finit v2.0 has been reached!
As of now a service can be declared in /etc/finit.conf or /etc/finit.d/
like this:
service :1 [2345] <!IFUP:eth0,GW> /sbin/dropbear -R -F -p 22 -- SSH daemon
Here the first instance `:1` of dropbear is declared to run in runlevels
2-5, but only if eth0 `IFUP:eth0` is up and a gateway `GW` is set. When
the configuration changes, a new gateway is set, or somehow a new `IFUP`
event for eth0 is received, then dropbear is not SIGHUP'ed, but instead
stop-started `<!>`. The latter trick applies to all services, even
those that do not define any events.
Currently inetd services are not supported for event based starting, but
it could easily be added. Likely scenario is to deny incoming requests
on, e.g., eth0 if there is no gateway.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch makes it possible to communicate process name or JOB[:ID]
from initctl to Finit. When the process name translates into a service
with multiple instances Finit applies the requested command to all
instances. For example, two Dropbear SSH services running on two
different ports, calling `initctl stop dropbear` stops both services.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch further extends the capabilities of the client with the
ability to control the running state of services:
finit <stop|start|reload|restart> JOB
Since services can now exist with multiple instances the concept of
"jobs" is introduced in this patch. A job is a numeric identifier of
the form `NUM[:NUM]`, the latter `:NUM` is the new instance syntax
introduced earlier. See the output of `finit status` for the JOB id.
Also, with the introduction of multiple instances we broke support for
multiple related inetd services. This became obvious when the shiny new
`finit status` was tested ... hence, this patch also contains fixes to
the inetd support.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch refactors svc.c into two files: svc.c now as a low-level
svc_t API and service.c for the more advanced rest.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for starting and supervising multiple
services (run, task, or service) using an extra #ID number.
service #1 [2345] /sbin/httpd -f -h /http -p 80 -- Web server
service #2 [2345] /sbin/httpd -f -h /http -p 8080 -- Old web server
Also included in this patch is a fix for endless respawn of faulty
services. For instance, a buggy daemon that crashes repeatedly will now
be stopped after 10 respawns.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for adding and removing services from Finit at
runtime. Configuration file stanzas for service, run and task may now
be written to files in /etc/finit.d/*.conf, using the exact same syntax
as before in /etc/finit.conf. When a file is added, removed or modified
the user may simply SIGHUP Finit (PID 1) to activate the changes.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for a configure script and with it
support for disabling inetd support. See the output from
./configure --help
* Add configure script
* Sprinkle #ifdef fairy dust on svc.c when inetd support is disabled
* Use GCC built-in autodep calculator (-MMD -MP)
* Fix name space issue with include files, use relative paths
* Disable username/group name to uid/gid functions in static builds
* Bug out (error) if a user tries to build the bootmisc plugin static
Possibly fixes GitHub issue #5 and issue #6.
NOTE: The static build has not received any testing at all!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for custom port and interface filtering to inetd
services, in a very condensed syntax:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth1:22/tcp nowait [2345] /usr/sbin/sshd -i
In this example eth0 and eth1 are allowed inbound interfaces for SSH
connections, on port 222 and 22, respectively. Attempting to connect
from any other interface is denied. Also, if the system is not in
runlevel 2, 3, 4, or 5, ports 222 and 22 will not even be opened.
If eth0 is your upstream interface you may want to avoid using the
default port. To run ssh on port 222, and all others on port 22:
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
This actually adds a deny rule for eth0 on ssh/tcp, implicitly. You can
even list the services in the reverse order with the same result:
inetd ssh/tcp nowait [2345] /usr/sbin/sshd -i
inetd ssh@eth0:222/tcp nowait [2345] /usr/sbin/sshd -i
There is no specific deny syntax available yet, see the TODO file for
more details on how this can be implemented.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Try to do better by the user, by default, if no tty is specified in the
finit.conf. This way the user will at least have a way to interact with
the system and repair it.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Standard init implementations save current and previous runlevels
in utmp, now finit does too. Also, the initial runlevel at boot
has changed from 10 to the more obvious 0.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Most systems need an early bootstrap phase for one-shot tasks and
necessary one-time probing. This phase usually runs well before any
networking is setup. This commit adds support for that 'S' runlevel,
and also extends the number of possible total runlevels to nine.
For the one-shot tasks that run in bootstrap two new finit.conf cmds
have been added:
- task: For one-shot tasks that can be started in parallell
- run: For one-shot tasks that must run in sequence
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Like most other init implementations do, when entering runlevel 1, finit
creates the file /etc/nologin to prevent users from logging in during
single-user mode, this file is then removed upon leaving runlevel 1.
Also, bugfix how FIFO I/O plugins are handled in finit. A FIFO will
need to be reopened by the server side when the client closes the pipe.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit adds a statistics counter to the finit svc_t process struct
which is incremented every time a process is restarted by the service
monitor.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit removes a lot of unnecessary overhead for handling external
service plugins. Instead of traversing the plugin array every time a
service callback should run we set the plugin callback in the svc_t when
the plugin is registered.
Also, make sure to check for norespawn/SIGSTOP in svc_reload() as well.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Improve upon API names, both internal and external, to make it clearer
where methods are located and clarify responsibility.
Add new Makefile target "dev" to create untagged development snapshots.
Bump version for upcoming release.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Move utility macros from finit.h to helpers.h and continue refactoring
and streamlining of public plugin API.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Due to time constraints I had to revert the new libev backend to the
service, I/O and signals monitor. Employed instead is the tried and
tested signals based service monitor, with a small extension for an
additional I/O monitor using poll() for the I/O plugins to use.
Tried restoring the startx finit.conf directive on top of the service
implementation. However, it's currently not usable to run /usr/bin/startx
for any other user than root. I recommend using the examples/finit.conf
and run /usr/sbin/gdm instead.
finit.c:
New run_loop() function, replaces libev ev_run().
helpers.c:
Refactor start_process() into svc_start().
plugin.c:
Add fds[] array for use in the io_monitor() called by the
new run_loop().
signal.c:
Ignore SIGCHLD. Handled by waitpid() in svc_monitor() now,
which is called by the new run_loop().
svc.c:
svc_register(): Optional @username parsing for the command line.
svc_monitor(): Replaced libev callback with waitpid()
svc_start(): Refactored to use most of helpers.c:start_process()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>