45 Commits
Author SHA1 Message Date
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg cdc8873f5b Let cond_update() return if any svc_t was affected
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-06 00:33:36 +02:00
Joachim Wiberg 57ca937f27 New function to create onshot conds without updating
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-16 23:37:41 +02:00
Joachim Wiberg 6f82b806ad plugins: new sys condition event monitor (wip)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-11 07:02:49 +02:00
Joachim Wiberg 910bb13711 plugins: netlink: redesign to handle ENOBUFS with kernel resync
This is a major redesign of the netlink plugin to be able to handle
ENOBUFS¹ properly.  Pending verification, this change replaces the patch
to increase socket buffer size, which in real life turned out to be
insufficient.

When nl_callback() calls recv() and it fails with ENOBUFS, we consider
our cache of the kernel state invalid and thus:

  1. deassert all net/ conditions
  2. open a new (temporary) netlink socket
  3. send RTM_GETLINK  and re-assert all interfaces using nl_link()
  4. send RTM_GETROUTE and re-assert all routes with nl_route()

Like before, the kernel will not send us a RTM_DELROUTE when it removes
the default route, so we still have to track this ourselves.  This patch
also refactors that functionality to only resync routes when the ifindex
associated previosly with the default route goes down or is removed.

The previous change that added nl_default() to recheck, has been dropped
to instead reuse the standard nl_route() callback.
___
¹ see netlink(7) for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-07 13:06:47 +02:00
Joachim Wiberg 7f272768e4 Log error if reconf cannot be written
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 04:31:56 +02:00
Joachim Wiberg f958aa504e cond_set_path(): minor, improve debug, 'new' -> 'next'
- Avoid using reserved C++ keyword 'new'
 - Rename new -> next
 - Rename old -> prev
 - Add debug for value being set to cond path

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-15 08:44:03 +02:00
Joachim Wiberg 8000d361b3 initctl: restore 'cond [set|clr] foo' for user-defined conditions
In 7447192 we dropped support for 'cond set' and 'cond clear' commands
with the motivation they were unsafe and sent the wrong message to the
user.  That was true, but mostly because it was too generic and required
the user to call `initctl reload` to apply the changes.

This patch restores the behavior, albeit in a very reduced and simple
format.  All conditions set with this command are constrained to the
'usr/...' namespace.  No subdirectories are allowed.  The argument to
the 'cond set|clear' command is disallowed if it contains '/' or '.'
but anything else is supported, for example:

    initctl cond set foo:2

creates a static/oneshot condition in /run/finit/cond/usr/foo:2

These conditions are static and are fully handled by the user.  The
initctl command is the recommended, and only supported, way of setting
and clearing usr conditions.

This patch also includes a new plugin, usr.so, which is a very simple
inotify plugin for the /run/finit/cond/usr/ directory.  When files are
created or removed here the plugin tells the Finit condition engine to
update and trigger service changes.

For instance, the following service is not started by default at boot:

    service <usr/foo> myservice -- MyService

However, as soon as `initctl cond set foo` is called, myservice starts.
Consequently, it is stopped when `initctl cond clr foo` is called.

Another major difference from the original is that this implementation
doesn't send IPC commands to create/delete the conditions.  This makes
calling these new commands non-blocking so they can be used very early
in the bootstrap, by plugins, if needed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg e3c8febe3b Refactor; common nomenclature, ordering, possib. security fix
- Use _PATH_foo for all condition paths, *with* trailing /
- Read condition file first, may not exist, in which case we save time
- Change from libte makepath() to mkpath(), this changes from hard-coded
  0777 perms on all cond dirs to 0755 -- possible security fix

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-11 11:44:23 +01:00
Joachim Wiberg 4d05bf9359 Mark affected services as dirty if their rdeps are dirty
Provided a configuration that looks like this:

ospfd.conf:
    service [2345] <!pid/zebra> log ospfd -A 127.0.0.1 -u root -g root -- OSPF daemon

zebra.conf:
    service [2345] <!> log zebra -A 127.0.0.1 -u root -g root -- Zebra Routing daemon

If zebra.conf is changed, we restart it when `initctl reload` is issued.

This change ensures that ospfd is also restarted, because ospfd depends
on zebra, we must restart it too.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-07 14:52:19 +01:00
Joachim Wiberg 81d8f3cccc Drop unnecessary service_step() in cond_reload()
The cond_reload() fn is called on `initctl reload`, thus we don't need
to call service_step(), since we call service_step_all() later in that
cycle.  So we can drop cond_update(NULL), which calls service_step().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Joachim Wiberg d27b3948af Drop unnecessary and confusing debug message in mkcond()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-24 22:12:05 +01:00
Joachim Wiberg d1fac6f5b3 Fix #143: redesign condition subsystem
Change service conditions from the non-obvious <svc/path/to/foo> to
<pid/foo:id>, utilizing the unique name of the service instead of the
weird composition of paths from /run and PID file names.  Hopefully
making it more clear that one service's pidfile is another service's
`<pid/foo>` condition.

Note: this is an incompatible change to the condition system!
      The Finit major version will be stepped to indicate this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 07:58:06 +01:00
Joachim Wiberg a8b113185d Major change, rename <svc/...> conditions to <pid/...> conditions
The <svc/foo> condition was created to synchronize starting services,
hence the abbreviation.  Example: the Quagga ripd needs to start after
the zebra daemon to ensure its UNIX domain socket is active, otherwise
events may be lost.

However, considering that synchronization was implemented with UNIX PID
files, e.g. waiting for /var/run/quagga/zebra.pid to be created, the
condition abbreviation name <svc/foo> was hard to understand by most
newcomers to Finit.  To make matters worse, a new feature to track or
even create PID files for services that don't create one themselves,
using the syntax 'pid:/path/to/foo.pid' was added.

Connecting the dots between these wasn't obvious.

This patch renames service conditions pid conditions and also adds
a compatibility wrapper to the Finit .conf parser.  Any condition
given in old .conf files with 'svc/' prefix are internally renamed
'pid/', along with a LOG_INFO notice in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Nilsson 8ed37f5fa0 Always append /ID to cond if run/task/service is declared with :ID
This patch is a follow-up to the idea introduced in 1d6737e, but this
time we make sure to always append the svc ID to conditions if their
.conf has been declared with :ID

Meaning, the following .conf:

    service :0 /sbin/teamd --config-file /etc/teamd-lag0.conf
    service :1 /sbin/teamd --config-file /etc/teamd-lag0.conf

results in the following two conditions:

    svc/sbin/teamd/0
    svc/sbin/teamd/1

With a custom 'name:foo':

    service name:lag :0 /sbin/teamd
    service name:lag :1 /sbin/teamd

the resulting conditions look even prettier:

    svc/lag/0
    svc/lag/1

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 15:22:29 +02:00
Joachim Nilsson 1d6737eac1 Custom conditions include :ID; 'name:foo :bar' => svc/foo/bar
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 09:56:30 +02:00
Joachim Nilsson fa0c2f7050 Custom name:foo will now create condition svc/foo w/o path
When registering a service there is the option to set a custom PID file,
and even tell Finit to maintain that PID file in case the daemon doesn't

Until now there hasn't been a way to create custom conditions though ...

This patch leverages the new 'name:foo' argument to tas/run/services to
trigger condition 'svc/foo' (notice lack of path!) when a custom name is
set and either the default, or the custom, PID file is created.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 08:57:12 +02:00
Joachim Nilsson 54cfa74042 Fix #109: Support PID files in subdirectories to /var/run
Services, like dbus and teamd for instance, may create their PID files
in a subdirectory of /var/run (today often /run). E.g.,

   - /var/run/teamd/a1.pid    -- For aggregate A1
   - /var/run/dbus/pid
   - /var/run/lxc/foo.pid     -- For container foo

This patch adds support for dynamically adding inotify watchers to any
new subdirectory created in /var/run (discarding too deep directories).

To match services in this directory the run/task/service/sysv stanza
must contain the pid:!/path/to/pidfile.pid syntax.  This pid file name
is also used to create the condition this service asserts using the
following formula:

   svc/ + <dirname of service> + <subdir and file without .pid>

E.g., the case of teamd (above) gives condition 'svc/usr/bin/teamd/a1'

The special case of dbus is interesting, since it may not be a special
case, but rather the norm for services using a subdirectory.  It is
handled as follows; when a new subdirectory is detected, the directory
is scanned for files matching *.pid.  Matching files follow the teamd
case.  The directory is also scanned for 'pid', which then gives us the
condition 'svc/usr/bin/dbus'

One last example, illustrated by lxc-start, where we want to track the
condition for the LXC container foo.  The service stanza:

   service pid:!/run/lxc/foo.pid lxc-start -n foo -F -p /run/lxc/foo.pid -- Container foo

This command has no leading path so the condition is composed entirely
from the PID file location:

   svc/  + '' + lxc/foo => svc/lxc/foo

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-02-28 16:39:53 +01:00
Joachim Nilsson fa0c63070c Add support for starting/stopping SysV init scripts
This patch adds initial support for starting a SysV init script in a
runlevel, and stopping it when leaving a runlevel.

    sysv [LVLS] <COND> /path/to/script.sh -- Optional Description

The SysV /etc/inittab file, which may use /etc/init.d, or /etc/rcN.d,
is still not supported.  A separate plugin would be required for this,
see the documentation for more information.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-22 15:45:08 +01:00
Joachim Nilsson e410a24d13 Fix %s i _d() message
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-06 21:26:51 +01:00
Joachim Nilsson 3006caf670 Refactor dddd45e, schedule work to iterate over services again
Instead of changing the API of service_step(), and relying on all the
different callers to step again, we can schedule another event to do
this for us.

In addition to handling the cond_update() case this also handles all
other callers of service_step().  Ensuring that nested conditions do
trigger changes.

Also, reverting dddd45e fixes a minor regression in service_monitor()
which caused it to not clean up collected bootstrap tasks.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-07 18:34:42 +02:00
Jonas Johansson dddd45e3b5 Reassert condition when svc_t goes from WAITING --> RUNNING
Reassert condition when an unchanged/unmodified process goes from
WAITING state to RUNNING.  I.e. it had a condition that went to flux
during `initctl reload`, which drove it to WAITING and was then sent
SIGSTOP during reconf.

Also, on condition update, loop through all services until no more state
changes are observed.  This allows long dependency chains of services to
resolve and actually go back to RUNNING state as intended whenever any
condition changes at runtime.

Signed-off-by: Jonas Johansson <jonasj76@gmail.com>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-10-02 19:03:30 +02:00
Joachim Nilsson dc7039b8d8 Fix #100: Adjust path to COND_RECONF /var/run symlink may be missing
On systems with the new /run hierarchy the compat symlink from /var/run
may be missing, or not yet be set up by bootmisc.so.  This patch adds a
layer of safety to the condition layer, both set and get cond ops now
perform an adjustmed of the condition path if needed.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-03-18 11:49:27 +01:00
Joachim Nilsson 3d68ebbf54 Fix off-by-one in condition reassert()
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 15:24:11 +01:00
Joachim Nilsson 6e017025aa Fix bad string pointer arithmetic in condition reassert
On `initctl reload` we reassert conditions, i.e. bring each still viable
condition back in sync with the new reconf generation.  This patch fixes
an assumption in the reassert() callback that caused the following nasty
transformation:

	/run/finit/cond/net/lo/up --> /run/finit/cond/lo/up

The transformation was caused by the reassert() code assuming a /var/run
prefix rather than /run.  We must check the actual runpath, or like this
patch does, use a path neutral way to find the base condition string.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 15:17:07 +01:00
Joachim Nilsson 5f818f917e cond_init(): Create correct condition path, /var/run might not exist
The cond_init() function is called before the bootmisc.so plugin has
run.  It is responsble for setting up the /var/run symlink to /run on
systems with the new layout.  Therefore we must wrap COND_PATH with
pid_runpath() to create the correct runtime path.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-22 15:17:07 +01:00
Joachim Nilsson 1017e7b8e5 Disable conditions for some non-oneshot (runtime) hooks
The SVC_RECONF, SVC_LOST, SVC_START, and RUNLEVEL_CHANGE hooks are not
one-shot, they are also not regular conditions since there exist no
mechanism to reset them from flux.

One idea was to turn them into actions, but the lost + start hooks need
to be called multiple times per trigger, e.g. `initctl reload`, which
turned out to be non-trivial to implement right now.

Therefore, for (at least) the Finit v3.1 release these conditions have
been disabled ("nop") and ignored by Finit.  Only actual C-style plugins
will be called.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-14 11:24:29 +01:00
Joachim Nilsson cc186334e0 Add support for one-shot conditions, like most hooks
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-14 11:24:29 +01:00
Joachim Nilsson 360f3e72bc Audit b0663d0, add newline to generation ID in cond files
- Add newline to cond generation ID, like PID files, easier when
  debugging.  Does not affect fscanf() in cond_get_gen()
- Update copyright years

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-23 10:05:45 +01:00
Joachim Nilsson e94d2a8c08 Merge branch 'master' into cond-generation 2017-12-23 09:31:41 +01:00
Joachim Nilsson 8992e7bf2b Refactor svc_iterator() into a proper iterator, add first flag
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 23:56:14 +01:00
Tobias Waldekranz b0663d04e4 cond: don't rely on mtime for condition management
TIL, using mtimes for tracking event orderings is a monumentally bad
idea (queue the nodding UNIX-beards). Mtimes are in wallclock time which
is not necessarily monotonically increasing. A user may adjust the time,
an NTP daemon will continously tune the clock and so on.

Instead, store an explicit generation number in each condition file,
which will be monotonically increased by finit on each reconf.
2017-12-21 11:10:47 +01:00
Joachim Nilsson 0f1f51b5ad Refactor, change from static array of svc_t to linked list
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 17:50:02 +01:00
Joachim Nilsson 7f04382eee Refactor, use new re-entrant svc_iterator1() API
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-18 00:21:07 +01:00
Joachim Nilsson 5dc4e7c058 cond_update(): Minor, log service description as well as cmd
If you have lots of service/run/tasks using the same cmd it's impossible
to tell them apart in debug mode.  This patch logs description as well
as cmd to improve on this situation a bit.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-13 17:58:48 +01:00
Joachim Nilsson 781ba66905 Revert "Remove reconf condition when .conf reload completes"
This reverts commit 06479aa5f1.
2017-10-24 13:07:48 +02:00
Joachim Nilsson 9a97ab29dc Revert "cond_reassert(): Use cond_set_path(), not cond_clear(), for reconf"
This reverts commit afb3fada50.
2017-10-24 13:07:15 +02:00
Joachim Nilsson 978beb8e7e Don't log if failed to remove non-existing condition
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-18 22:05:00 +02:00
Joachim Nilsson afb3fada50 cond_reassert(): Use cond_set_path(), not cond_clear(), for reconf
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-12 01:23:43 +02:00
Joachim Nilsson 227dda34f7 cond_set_path(): Log error if unlink() fails
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-12 01:23:16 +02:00
Joachim Nilsson 06479aa5f1 Remove reconf condition when .conf reload completes
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-12 01:07:09 +02:00
Joachim Nilsson b6be354508 Minor, whitespace
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-10 23:39:22 +02:00
Joachim Nilsson 30822f0d68 Remove UNUSED() macro and disable the compiler warning instead
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-07-02 21:59:23 +02:00
Joachim Nilsson fff68b7b06 Relocate source files to an src/ subdirectory
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-01-16 01:31:02 +01:00