Commit Graph
1936 Commits
Author SHA1 Message Date
Joachim Nilsson fe41b9c4b8 Revert "plugins: pidfile: Simplify and clean up developer debug messages"
This reverts commit 69016bb8f5.
2020-03-02 07:22:15 +01:00
Joachim Nilsson 7cf3ef80db Revert "Travic-CI: Disable clang temporarily for Coverity run"
This reverts commit 27c839bc92.
2020-02-29 17:10:28 +01:00
Joachim Nilsson 69016bb8f5 plugins: pidfile: Simplify and clean up developer debug messages
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 17:04:27 +01:00
Joachim Nilsson f7d5b588c9 plugins: pidfile: Factor out directory handling from callback
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:52:51 +01:00
Joachim Nilsson 0ad99ce054 Fix use-after-close in service.c:redirect(), found by Coverity Scan
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:42:53 +01:00
Joachim Nilsson 1176961e7b plugins: pidfile: Fix memory leak in pidfile_callback()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:40:06 +01:00
Joachim Nilsson 27c839bc92 Travic-CI: Disable clang temporarily for Coverity run
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-29 16:32:05 +01:00
Joachim Nilsson 6149e93aca docs: Update documentation on svc conditions
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 17:16:24 +01:00
Joachim Nilsson 4e7baa807e Fix #109: Declare PID file path to dbus-daemon in dbus plugin
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:50:57 +01:00
Joachim Nilsson 54cfa74042 Fix #109: Support PID files in subdirectories to /var/run
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,

   - /var/run/teamd/a1.pid    -- For aggregate A1
   - /var/run/dbus/pid
   - /var/run/lxc/foo.pid     -- For container foo

This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).

To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax.  This pid file name
is also used to create the condition this service asserts using the
following formula:

   svc/ + <dirname of service> + <subdir and file without .pid>

E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'

The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory.  It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid.  Matching files follow the teamd
case.  The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'

One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo.  The service stanza:

   service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo

This command has no leading path so the condition is composed entirely
from the PID file location:

   svc/  + '' + lxc/foo => svc/lxc/foo

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:39:53 +01:00
Joachim Nilsson 97ce0aa519 Rename local variable shadowing variable in outer scope
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 14:36:14 +01:00
Joachim Nilsson e72b61c9c9 Minor, fix dead EeePC fastinit link and adjust distro ordering
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-27 23:08:20 +01:00
Joachim Nilsson b66069278f Support for a custom kill:DELAY, default 3 sec
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 18:49:47 +01:00
Joachim Nilsson 1192506d43 Support for custom halt:signal, default SIGTERM
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 18:28:02 +01:00
Joachim Nilsson decdc1560a Support for monitoring forking services/sysv daemons
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 14:10:47 +01:00
Joachim Nilsson f6372de6a9 New function pid_file_read(), returns PID from a pid file
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:40:44 +01:00
Joachim Nilsson 9052248127 Check for an actual /proc file, not directory, in pid_alive()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:40:18 +01:00
Joachim Nilsson 6ab9c8fad6 Allow services to be started without absolute path, trust $PATH
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:39:17 +01:00
Joachim Nilsson 619bd03551 Drop old comment related to service plugins (now removed)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:38:50 +01:00
Joachim Nilsson e301877b16 Follow-up to 12d14aa, configurable auto-reload of .conf files
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-26 11:13:06 +01:00
Joachim Nilsson 3b67afe480 Change semantics for SysV start/stop scripts
If a start/stop script returns OK we classify it as 'started' and leave
it in running state, despite having collected its PID.  This way we can
track what scripts need to be called with 'stop' when changing to a
runlevel they are not declared for.

Also, clean up related debug messages from earlier commit.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:35:15 +01:00
Joachim Nilsson 9a9a9f4bfe Remove old blocking (!) waitpid() call in service_start()
Remnant from when processes were collected in service_start(), now all
handled by service_monitor() from SIGCHLD and service_step().

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:32:04 +01:00
Joachim Nilsson f38299bfca Redirect stdout/stderr according to .conf when stopping SysV service
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:31:21 +01:00
Joachim Nilsson 99901782ff Factor out stdout/stderr redirection to from service_start()
This new function can then be used also by service_stop(), e.g. for SysV
start/stop scripts.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 12:30:00 +01:00
Joachim Nilsson 912a336997 Only show [ OK ] startup/status if run tasks exit normally
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 07:52:36 +01:00
Joachim Nilsson c3eca9fe8f Save process exit status to svc_t
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-05 07:23:06 +01:00
Joachim Nilsson 225510a270 Remove gratuitous newline when finit stops its own log service
This patch fixes an annoying thing when typing reboot/shutdown/poweroff
that caused an extra newline to be printed before displaying services
stopping.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-30 18:29:45 +01:00
Joachim Nilsson 4389fbd8bc Merge pull request #122 from jackuess/fix-inaccurate-sleep
Switch to using nanosleep in favour of sleep
2020-01-30 18:01:46 +01:00
Jacques de Laval 920382518f Switch to using nanosleep in favour of sleep
The remaining sleep time returned by sleep is not accurate enough to be
used as a means to achieve "signal safe"-sleep. nanosleep can be used
in similar fashion instead and is granular enough for our purposes.

This issue was identified during reboot, when Finit is bombarded with
SIGCHLD, aborting the sleep that we do to give daemons a chance to shut
down gracefully. The total delay ended up being less than a second when
in fact two seconds were the intended delay.
2020-01-30 15:39:46 +01:00
Joachim Nilsson 997a699b7e Add more debug logs for /etc/finit.d*/ inotify and exec_runtask()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:48:56 +01:00
Joachim Nilsson 21db27ee75 Minor, coding style cleanup
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:48:42 +01:00
Joachim Nilsson fa0c63070c Add support for starting/stopping SysV init scripts
This patch adds initial support for starting a SysV init script in a
runlevel, and stopping it when leaving a runlevel.

    sysv [LVLS] <COND> /path/to/script.sh -- Optional Description

The SysV /etc/inittab file, which may use /etc/init.d, or /etc/rcN.d,
is still not supported.  A separate plugin would be required for this,
see the documentation for more information.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:45:08 +01:00
Joachim Nilsson 9bfc9092b8 Document new mdules-load and modprobe plugins
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-15 22:53:24 +01:00
Joachim Nilsson 1c6464a7a8 Add support for cold plugging devices, auto-loading of modules
This patch adds a new plugin to Finit called modprobe.  It probes in
/sys/devices after modalias files and then calls 'modprobe -ab' for
each alias listed.

For hot-plugging we recommend adding the following to /etc/mdev.conf

  $MODALIAS=.*	root:root	0660	@modprobe -b "$MODALIAS"

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-12 20:00:47 +01:00
Joachim Nilsson 51adba4387 Slight update, we won't be releasing in 2018 ...
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-08 12:08:24 +01:00
Joachim Nilsson bb1aed1010 initctl: Follow-up to 6a5f439, don't fail if directory already exists
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-08 12:06:41 +01:00
Joachim Nilsson cf4a1332f9 Revert "Travis-CI: Disable clang for Coverity Scan run"
This reverts commit fc37b854ae.
2020-01-07 20:46:49 +01:00
Joachim Nilsson d70fb85aaf Make MIT badge more readable, teal is also a nice color
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 20:45:53 +01:00
Joachim Nilsson fc37b854ae Travis-CI: Disable clang for Coverity Scan run
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:55:03 +01:00
Jonas Holmberg ca210f5431 Add support for logging security related events
This patch introduces the LOG_CONSOLE syslog facility for logging common
events.  In industrial applications aiming for IEC 62443 compliance the
following events are central for system observability:

- Change of runlevel - i.e., starting up, shutting down, upgrade, etc.
  Facility: console, severity: notice
- Service starting
  Facility: console, severity: notice
- Service restarting
  Facility: console, severity: notice
- Service stopping
  Facility: console, severity: notice
- Service failed to start
  Facility: console, severity: warning

The use of facility console for this makes it easier to filter out when
forwarding syslog messages from an embedded system to a remote log sink.
Otherwise messages of facility daemon would be used, which include a lot
more, and mostly irrelevant, information.

Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:38:21 +01:00
Jonas Holmberg a19a3c774e Fix issue where svc_find() finds the wrong service
This issue may arise in situations where the name of the service being
compared is a sub-string of the service we want to see if it exist.

Example:
  - Two different services: teamd, teamdagentd
  - They have the same id, 1 being the default if none is specified
  - The service with the shortest name is created first

While checking if the "teamdagentd" service exists we eventually compare
it to the "teamd" service.  Prior to this fix we only compare the names
names with the length of the existing service.  Hence, teamdagentd will
seem to be the same as teamd since the first part of the string is equal
to the existing.

Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:23:53 +01:00
Joachim Nilsson a4f1330eae Simplify, no need to check svc->id, is always a valid string
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:21:46 +01:00
Joachim Nilsson 38d768ac9e Travis-CI: Enable all -Wfoo CFLAGS globally and build logit in all
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:07:27 +01:00
Joachim Nilsson 36b14f9ff7 Travis-CI: Move environment variable PKG_CONFIG_PATH to env:->global:
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:06:55 +01:00
Joachim Nilsson bdbd2afc40 Travis-CI: Re-enable clang builds after Coverity Scan run
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:05:26 +01:00
Joachim Nilsson 33bb6ed5ac Add --enable-logit to configure, disabled by default
Since sysklogd now ships an excellent enhanced logger tool there is no
need for Finit to provide its own tool for the same purpose by default.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 13:02:06 +01:00
Joachim Nilsson 212083b922 Introduce strterm(), hard-add terminating '\0' at end of buffer
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 03:02:39 +01:00
Joachim Nilsson 55c49a0bf0 Sanitize job[:id] tuple read from UNIX socket using a regex
This is a really tight check for a single "job[:id]" tuple, not much
escapes it, Coverity should be a lot more happy about our addressing
CWE-20 with this one.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 02:51:15 +01:00
Joachim Nilsson b369e1cfa2 Refactor svc_parse_jobstr(), use tokstr() instead of strtok_r()
This is a safer version of strtok() that makes sure we do not step
outside of string bounds.  Coverity complained about this, but was
likely more concerned with the lacking sanitize() and trusting data
read from a UNIX domain socket ...

Note: not only is tokstr() not re-entrant, it is also hard-coded
      to only check for whitespace as token separator.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 02:51:15 +01:00
Joachim Nilsson cfefe23275 Fix another GCC 9 string truncation warning
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-07 02:51:15 +01:00