In cases where you have multiple events pending in the cache and some
event may cause later ones, already sent by the kernel to userspace,
to be deleted the pointer returned to the event loop for this later
event may be deleted.
There are two ways around this (accessing deleted memory); 1) use this
function to initialize your event loop and set maxevents to 1, 2) use a
free list in you application that you garbage collect at intervals
relevant to your application.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We allow all run/task/services to complete before changing runlevel.
This means stepping them all while we wait for their completion, since
services may depend on each other.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Reassert condition when an unchanged/unmodified process goes from
WAITING state to RUNNING. I.e. it had a condition that went to flux
during `initctl reload`, which drove it to WAITING and was then sent
SIGSTOP during reconf.
Also, on condition update, loop through all services until no more state
changes are observed. This allows long dependency chains of services to
resolve and actually go back to RUNNING state as intended whenever any
condition changes at runtime.
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When a process, that has been sent SIGTERM by us, takes a full 3 sec to
terminate, the event loop may have both the SIGCHLD event (where we do
the svc_del()) and the 3 sec timeout event to send SIGKILL in its event
cache.
When we call svc_del() it releases the svc_t memory, which can then be
dereferenced by the SIGKILL timer callback and we're doomed.
There are two fixes to this; 1) the event loop, that uses epoll_wait(),
can set maxevents=1 (instead of today's 10). The kernel will then drop
the SIGKILL timer event before it's delivered to the userspace process.
2) we can postpone deleting the svc_t to a "later stage" when all events
in the event cache have been processed.
This patch implements (2). A later patch will use uev_init1(ctx, 1) to
ensure the event cache handles only one event at a time.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Reduce the noise: we don't need to notify the user if a process started
in bootstrap is simply SIGHUPed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If we delete bootstrap (only) run tasks in service_start() when they
complete they may be found and run again if *.conf reload takes place.
Instead, mark them as having been run, like regular runtasks, and set
their state directly to STOPPING. The once flag ensures the svc is not
restarted if its .conf file is reloaded.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
An SVC_TYPE_RUN may be deleted by svc_clean_bootstrap() as soon as it's
been collected. We must not try to dereference that pointer afterwards,
e.g. in svc_is_daemon().
Refactor the whole of it to make the code easier to follow.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
An operator wanting to monitor processes started by Finit could use the
kernel ftrace framework. E.g. execsnoop in perf-tools.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If an inetd service is changed, finit must update the command line
arguments associated with the service.
Signed-off-by: Petrus Hellgren <petrus.hellgren@westermo.se>
Signed-off-by: Petrus Hellgren <petrus.hellgren@gmail.com>
In massively parallel builds we've seen finit fail in the install phase
of the contrib section with:
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/getty.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/keymap.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/modules.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/klogd.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/syslogd.conf': No such file or directory
This patch is a countermeasure since fixing the root cause may take a
while (to be prioritized).
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Do not restart a inetd service if the listening interface is changed.
Only bring down established connection which are no longer allowed,
i.e. do not touch already allowed established connections.
Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
We cannot allow pid_runpath() to return its 'file' argument because that
may be a stack variable in a helper function.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
On systems with the new /run hierarchy the compat symlink from /var/run
may be missing, or not yet be set up by bootmisc.so. This patch adds a
layer of safety to the condition layer, both set and get cond ops now
perform an adjustmed of the condition path if needed.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
In case a user forgets to type in the service to enable, disable, or
touch, we try to be helpful and list available services instead of
bugging out.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
All service/task commands are tracked by the state machine, but run
commands are a bit special since they must run in sequence. Hence,
we must increment their 'once' counter in service_start() instead.
This should fix the issue mentioned in #96 "took a long time before
the next line" -- because Finit was waiting for udevadm to reach a
once count > 0, which we didn't increment.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
We must wait for udevd to be started before we call udevadm. However,
udevd doesn't create a PID file, so we must also fake this. There is
still a slight risk of a race condition: udevd not having properly
started before udevadm tries to connect, but it works OK in Debian.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This reverts commit df89cc79b9. Not all
distros (Debian, Alpine) have a dbus-daemon that supports --syslog-only
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Running Finit on a kernel or system without WDT support built-in should
not trigger an error message from Finit.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Issue #52 suggested calling service_reload_dynamic() automatically after
run-parts and /etc/rc.local. This may seem like a good idea, but not
only does it create extra overhead, it currently also freezes the boot
and fails to present a login prompt if a run-parts directory exists.
Yes, the directory can be empty, it just have to exist to trigger this
regression.
While trying to find the root cause I realized this was all just wrong.
If the user does something that requires reloading finit, they should
call `initctl reload` from the script instead.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
When finit calls out to external tools, like `ifup $IFACE`, that tool in
turn may use other external tools. On systems with BusyBox our calling
`ifup $IFACE` will result in BusyBox casting a magic spell: if $SHELL is
unset it goes looking in the file /etc/passwd for the shell of $USER
which may not be set to a Bourne compatible UNIX shell, so commands like
`ip link ...` or `run-parts ...` will fail hard.
This patch adds SHELL=/bin/sh as a sane early default.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>