This adds a new function conf_save_service() replacing service_register() for
plugins and bundled services like watchdogd, keventd, runparts, etc.
The benefits to this change are several:
- Plugin/Bundled services no longer risk starting before udev or other
critical services/task have started
- Definitions can be overridden by an administrator (see docs)
- Increases visibility (user: where are all these services coming from?)
Previously the origin (file the service was loaded from) was NULL.
- Adds another level of extensibility to Finit
The most notable change is that dbus is no longer started before udevd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
No more changes are expected after -rc3. Will be used for testing in
Infix and br2-ext-finit before the final v4.5 GA.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rescue mode that can be invoked from the kernel command line is
potentially unsafe. Many systems lock the root user account, or use
another account for managing, e.g. 'admin'. The sulogin program(s)
would on such systems give the user a root prompt.
In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough. On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.
The only, truly safe, approach on such systems is to disable rescue mode
completely. Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.
it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slowly migrating away from hard-coded services in plugins. This way
it's possible for the user to both inspect and override as needed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The tmpfilesd() glob sorts files according to name, we could name our
.conf as 00finit.conf to prevent ordering issues with, e.g. dnsmasq,
but this is more elegant and allows for multi-level override.
NOTE: bootmisc depends on the pidfile plugins since the latter need
to set up its iwatches of /run before bootmisc creates /run.
Depending on if it's a system with /var/run or /run we need to
drop /var/run before recreating it.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds very basic tmpfiles.d/ support to Finit. Much of the
basic types are supported, but not all, so for now, please check the
code for details on what is working.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With all the change and revert mess of the HOOK_BASEFS_UP tests started
failing due to usr.so and sys.so failed to set up their conditions. It
then became clear that boomisc.so cleaned up /run ... with the revert
we got service_register() to be called before global_rlimit[] was setup
causing services registered by plugins, before conf_init(), to crash.
This plugin and test is here to ensure we catch this problem in case of
any future refactor.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds the mdevd[1] plugin from Andy's fork of Finit, only
minor whitespace adjustment and group fix introduced, along with
updates to configure.ac and the documentation.
Currently the hotplug.sh calls mdevd-coldplug (instad of mdev -s), but
since mdevd is not guaranteed to have started and be ready, it is also
started with mdevd -C. A better solution is to use the s6 notify code
to synchronize the start of mdevd-coldplug. Support for this is coming
soon to Finit.
[1]: https://github.com/hongkongkiwi/finit/blob/master/plugins/mdevd.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add a plugin that will allow the user to trigger the execution of
scripts from plugin hook points. This is particularly useful for early
boot debugging that needs to take place before regular services are
available.
For example, let's say that you want to enable some kernel tracing
before modules are loaded. With hook-scripts, you can just drop in a
shell script in /libexec/finit/hook/mount/all/ that will poke the
right control files in tracefs.
The bundled sulogin could be considered insecure, so leave it up to the
administrator, or system integrator, to decide which sulogin(8) is best
suited.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When iterating over the system fstab file to call fsck, Finit calls the
helper function ismnt(), which opens /proc/mounts to make sure mounted
file systems are not fsck'ed. Both the main function and ismnt() used
the same non-reentrant getmntent() API which caused ismnt() to set the
fstab pointer for the first out of whack.
This change replaces getmntent() in the two critical functions with the
getmntent_r() API instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This adds support for bringing up the system with an alternate fstab at
boot. E.g., when using a primary/secondary setup for boot partitions.
By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary
If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.
Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot. Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The setfsent() family of APIs was never standardized and on Linux only
GLIBC implement them. We've tried to overcome this limitation, and to
support uClibc/uClibc-ng and musl libc, by providing replacements APIs
in helpers.c.
However, and since we want to support alternative /etc/fstab files, the
setmntent() family of APIs is more widespread and supports reading from
any fstab or mtab file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch allows disabling (enabled by default) the modprobe and tty
plugins. They are not particularly useful in container use-cases.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>