Commit Graph
188 Commits
Author SHA1 Message Date
Joachim Wiberg d38c333e04 Bump version for final candidate, v4.5-rc5
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-05 08:19:24 +02:00
Joachim Wiberg 5d703fd39e Support delayed load of services from plugins and bundled services
This adds a new function conf_save_service() replacing service_register() for
plugins and bundled services like watchdogd, keventd, runparts, etc.

The benefits to this change are several:

 - Plugin/Bundled services no longer risk starting before udev or other
   critical services/task have started
 - Definitions can be overridden by an administrator (see docs)
 - Increases visibility (user: where are all these services coming from?)
   Previously the origin (file the service was loaded from) was NULL.
 - Adds another level of extensibility to Finit

The most notable change is that dbus is no longer started before udevd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:37:43 +02:00
Joachim Wiberg eaaf8d862e Minor, append _ to PATH constant
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:25:09 +02:00
Joachim Wiberg 5b9cebbfd3 Update ChangeLog and bump version for v4.5-rc4
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 16:51:03 +02:00
Joachim Wiberg 338521a748 Update ChangeLog and bump for v4.5-rc3
No more changes are expected after -rc3.  Will be used for testing in
Infix and br2-ext-finit before the final v4.5 GA.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 14:04:28 +02:00
Joachim Wiberg 7cb91854b0 Update ChangeLog and bump version for v4.5-rc2
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-14 09:22:11 +02:00
Joachim Wiberg eb6291c943 Update ChangeLog and bump version for v4.5-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 13:26:33 +02:00
Joachim Wiberg 263aec292a Support for disabling invocation of rescue mode from kernel cmdline
The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 12:45:03 +02:00
Joachim Wiberg 6e7a2fb6d5 Fix #357: allow sulogin with user different from 'root'
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.

it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 11:37:15 +02:00
Joachim Wiberg 5769500afe Bump devel version and update ChangeLog for v4.5 release cycle
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-06-27 12:33:16 +02:00
Joachim Wiberg f4d3ec1a9f Update ChangeLog and bump version for v4.4 release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-15 16:40:56 +02:00
Joachim Wiberg 8a32ec5c92 Bump version for v4.4-rc2
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-08 09:58:42 +02:00
Joachim Wiberg c0d3705ed5 Bump version for v4.4-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-07 20:45:03 +02:00
Joachim Wiberg 42ef3d3cf7 plugins: add configure support for overriding RTC fallback datetime
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-10 16:35:42 +02:00
Joachim Wiberg 97ca450966 Add support for static services in /lib/finit/system/*.conf
Slowly migrating away from hard-coded services in plugins.  This way
it's possible for the user to both inspect and override as needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg 11da93b759 Add support for Finit specific tmpfiles.d/
The tmpfilesd() glob sorts files according to name, we could name our
.conf as 00finit.conf to prevent ordering issues with, e.g. dnsmasq,
but this is more elegant and allows for multi-level override.

NOTE: bootmisc depends on the pidfile plugins since the latter need
      to set up its iwatches of /run before bootmisc creates /run.
      Depending on if it's a system with /var/run or /run we need to
      drop /var/run before recreating it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg af88b10322 Minor, simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:48:25 +01:00
Joachim Wiberg 966ae9fb0d Rename FINIT_LIBPATH_ -> FINIT_EXECPATH_
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:48:25 +01:00
Joachim Wiberg a4af9ba248 Add limited tmpfiles.d(5) support
This change adds very basic tmpfiles.d/ support to Finit.  Much of the
basic types are supported, but not all, so for now, please check the
code for details on what is working.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:48:25 +01:00
Joachim Wiberg 9c727ed08d test: namespace cleanup, common -> src, tenv -> lib, etc.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 19:04:48 +01:00
Joachim Wiberg f0a888c0d1 test: update Makefile.am and build instructions, new testserv plugin
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 12:07:35 +01:00
Joachim Wiberg a664fd7192 Add plugin and test to reproduce failing tests since c9fe9af
With all the change and revert mess of the HOOK_BASEFS_UP tests started
failing due to usr.so and sys.so failed to set up their conditions.  It
then became clear that boomisc.so cleaned up /run ... with the revert
we got service_register() to be called before global_rlimit[] was setup
causing services registered by plugins, before conf_init(), to crash.

This plugin and test is here to ensure we catch this problem in case of
any future refactor.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg f6bfbc86e9 Drop mdevd plugin, not needed since notify:s6 support was added
For an example how to set it up, see the finit-skel repository:

https://github.com/troglobit/finit-skel/blob/main/skel/etc/finit.d/available/mdevd.conf

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-12-21 11:57:48 +01:00
Joachim Wiberg 3a74310aa6 Drop deprecated autoconf statements
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-12-16 15:45:36 +01:00
Joachim Wiberg b26104466a Overdue version bump into v4.4-dev release cycle
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-11 21:54:22 +01:00
Joachim Wiberg 58b075dbf2 Follow-up to 7cfbca6, remove extra , that disables all plugins
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-08 19:49:23 +01:00
Joachim Wiberg 0e70bdbf6a Handle if building with hook script but no script path
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-07 19:04:59 +01:00
Joachim Wiberg 7cfbca6d74 Add --enable-all-plugins configure flag
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-17 07:49:11 +02:00
Joachim Wiberg d6f35903d6 Fix #195: add mdevd plugin as complement to hotplug.sh
This patch adds the mdevd[1] plugin from Andy's fork of Finit, only
minor whitespace adjustment and group fix introduced, along with
updates to configure.ac and the documentation.

Currently the hotplug.sh calls mdevd-coldplug (instad of mdev -s), but
since mdevd is not guaranteed to have started and be ready, it is also
started with mdevd -C.  A better solution is to use the s6 notify code
to synchronize the start of mdevd-coldplug.  Support for this is coming
soon to Finit.

[1]: https://github.com/hongkongkiwi/finit/blob/master/plugins/mdevd.c

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-16 14:00:57 +02:00
Joachim Wiberg fc3bad2160 Fix #284: search for plugins in /usr and /usr/local
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-07-17 22:08:05 +02:00
Joachim Wiberg f483a8aeaa Update ChangeLog and bump version for v4.3 release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-15 21:57:32 +02:00
Joachim Wiberg ceb2945da9 Update ChangeLog and bump version for v4.3-rc2
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-09 06:55:21 +02:00
Joachim Wiberg 0cce69892a Fix #261: support for overriding default runlevel from command line
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-08 09:57:18 +02:00
Tobias Waldekranz b62c975dc4 plugins: hook-scripts: Add
Add a plugin that will allow the user to trigger the execution of
scripts from plugin hook points. This is particularly useful for early
boot debugging that needs to take place before regular services are
available.

For example, let's say that you want to enable some kernel tracing
before modules are loaded. With hook-scripts, you can just drop in a
shell script in /libexec/finit/hook/mount/all/ that will poke the
right control files in tracefs.
2022-05-06 10:36:37 +02:00
Joachim Wiberg bf72e6b9c8 Make bundled sulogin optional, use ./configure --with-sulogin
The bundled sulogin could be considered insecure, so leave it up to the
administrator, or system integrator, to decide which sulogin(8) is best
suited.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-03 05:58:57 +02:00
Joachim Wiberg bf62bee440 Update project homepage
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 22:43:39 +02:00
Joachim Wiberg d6c55282ef Fix #253: use reentrant getmntent_r() API
When iterating over the system fstab file to call fsck, Finit calls the
helper function ismnt(), which opens /proc/mounts to make sure mounted
file systems are not fsck'ed.  Both the main function and ismnt() used
the same non-reentrant getmntent() API which caused ismnt() to set the
fstab pointer for the first out of whack.

This change replaces getmntent() in the two critical functions with the
getmntent_r() API instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 21:43:13 +02:00
Joachim Wiberg 1015124530 Use sys/sysmacros.h, if available, for minor() and major()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-01 20:50:17 +02:00
Joachim Wiberg 57c97d8190 Fix #224: support for cmdline -- finit.fstab=/etc/fstab.secondary
This adds support for bringing up the system with an alternate fstab at
boot.  E.g., when using a primary/secondary setup for boot partitions.

By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary

If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.

Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot.  Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-25 21:44:33 +02:00
Joachim Wiberg 5593372ffb Refactor, replace deprecated setfsent() & C:o with setmntent()
The setfsent() family of APIs was never standardized and on Linux only
GLIBC implement them.  We've tried to overcome this limitation, and to
support uClibc/uClibc-ng and musl libc, by providing replacements APIs
in helpers.c.

However, and since we want to support alternative /etc/fstab files, the
setmntent() family of APIs is more widespread and supports reading from
any fstab or mtab file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-20 07:20:33 +02:00
Joachim Wiberg a61aa73419 configure: check for fstab.h, no fstaby.h
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:29:01 +02:00
Joachim Wiberg e7516f2b63 Bump version for v4.3-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-17 11:08:15 +02:00
Joachim Wiberg 6416e2a1a4 test: minor refactor in build system
Add Makefile.am in tenv and common for EXTRA_DIST.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-02 12:07:34 +02:00
Joachim Wiberg 1b5b37c06b plugin: allow modprobe and tty plugins to be disabled
This patch allows disabling (enabled by default) the modprobe and tty
plugins.  They are not particularly useful in container use-cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-13 22:45:47 +01:00
Joachim Wiberg ebdc10d1c5 Bump version for 4.3 development cycle
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-30 11:03:10 +01:00
Joachim Wiberg f32e4d4b30 Update changelog and bump version for v4.2 release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-16 05:01:03 +01:00
Joachim Wiberg 495c8c9eac Update changelog and bump version for v4.2-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-10 21:49:24 +01:00
Joachim Wiberg 980152fd53 Add support for non-root users to use initctl, e.g. group wheel
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-11-30 11:44:22 +01:00
Joachim Wiberg be8c89ec00 Bump version for v4.2 release cycle
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-09-23 09:28:44 +02:00
Ming Liu a7c0b42965 configure.ac: add fastboo/fsckfix to config summary output
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-09-10 11:35:45 +02:00