Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,
- /var/run/teamd/a1.pid -- For aggregate A1
- /var/run/dbus/pid
- /var/run/lxc/foo.pid -- For container foo
This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).
To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax. This pid file name
is also used to create the condition this service asserts using the
following formula:
svc/ + <dirname of service> + <subdir and file without .pid>
E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'
The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory. It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid. Matching files follow the teamd
case. The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'
One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo. The service stanza:
service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo
This command has no leading path so the condition is composed entirely
from the PID file location:
svc/ + '' + lxc/foo => svc/lxc/foo
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
If a start/stop script returns OK we classify it as 'started' and leave
it in running state, despite having collected its PID. This way we can
track what scripts need to be called with 'stop' when changing to a
runlevel they are not declared for.
Also, clean up related debug messages from earlier commit.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Remnant from when processes were collected in service_start(), now all
handled by service_monitor() from SIGCHLD and service_step().
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes an annoying thing when typing reboot/shutdown/poweroff
that caused an extra newline to be printed before displaying services
stopping.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The remaining sleep time returned by sleep is not accurate enough to be
used as a means to achieve "signal safe"-sleep. nanosleep can be used
in similar fashion instead and is granular enough for our purposes.
This issue was identified during reboot, when Finit is bombarded with
SIGCHLD, aborting the sleep that we do to give daemons a chance to shut
down gracefully. The total delay ended up being less than a second when
in fact two seconds were the intended delay.
This patch adds initial support for starting a SysV init script in a
runlevel, and stopping it when leaving a runlevel.
sysv [LVLS] <COND> /path/to/script.sh -- Optional Description
The SysV /etc/inittab file, which may use /etc/init.d, or /etc/rcN.d,
is still not supported. A separate plugin would be required for this,
see the documentation for more information.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds a new plugin to Finit called modprobe. It probes in
/sys/devices after modalias files and then calls 'modprobe -ab' for
each alias listed.
For hot-plugging we recommend adding the following to /etc/mdev.conf
$MODALIAS=.* root:root 0660 @modprobe -b "$MODALIAS"
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch introduces the LOG_CONSOLE syslog facility for logging common
events. In industrial applications aiming for IEC 62443 compliance the
following events are central for system observability:
- Change of runlevel - i.e., starting up, shutting down, upgrade, etc.
Facility: console, severity: notice
- Service starting
Facility: console, severity: notice
- Service restarting
Facility: console, severity: notice
- Service stopping
Facility: console, severity: notice
- Service failed to start
Facility: console, severity: warning
The use of facility console for this makes it easier to filter out when
forwarding syslog messages from an embedded system to a remote log sink.
Otherwise messages of facility daemon would be used, which include a lot
more, and mostly irrelevant, information.
Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This issue may arise in situations where the name of the service being
compared is a sub-string of the service we want to see if it exist.
Example:
- Two different services: teamd, teamdagentd
- They have the same id, 1 being the default if none is specified
- The service with the shortest name is created first
While checking if the "teamdagentd" service exists we eventually compare
it to the "teamd" service. Prior to this fix we only compare the names
names with the length of the existing service. Hence, teamdagentd will
seem to be the same as teamd since the first part of the string is equal
to the existing.
Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Since sysklogd now ships an excellent enhanced logger tool there is no
need for Finit to provide its own tool for the same purpose by default.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This is a really tight check for a single "job[:id]" tuple, not much
escapes it, Coverity should be a lot more happy about our addressing
CWE-20 with this one.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This is a safer version of strtok() that makes sure we do not step
outside of string bounds. Coverity complained about this, but was
likely more concerned with the lacking sanitize() and trusting data
read from a UNIX domain socket ...
Note: not only is tokstr() not re-entrant, it is also hard-coded
to only check for whitespace as token separator.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>