1407 Commits
Author SHA1 Message Date
Joachim Wiberg b4d10cbade Always ensure /run/finit/system exists before saving runtime service
This fixes the regression in the tests, which runs in a very stripped
down world without tmpfiles.d etc.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:48:13 +02:00
Joachim Wiberg 5d703fd39e Support delayed load of services from plugins and bundled services
This adds a new function conf_save_service() replacing service_register() for
plugins and bundled services like watchdogd, keventd, runparts, etc.

The benefits to this change are several:

 - Plugin/Bundled services no longer risk starting before udev or other
   critical services/task have started
 - Definitions can be overridden by an administrator (see docs)
 - Increases visibility (user: where are all these services coming from?)
   Previously the origin (file the service was loaded from) was NULL.
 - Adds another level of extensibility to Finit

The most notable change is that dbus is no longer started before udevd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:37:43 +02:00
Joachim Wiberg eaaf8d862e Minor, append _ to PATH constant
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:25:09 +02:00
Joachim Wiberg 1889b88aab Log execution order at bootstrap to /run/finit/exec.order
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 17:21:11 +02:00
Joachim Wiberg 0d70023bfe Log conf file evaluation order at bootstrap to /run/finit/conf.order
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 17:20:15 +02:00
Joachim Wiberg 41648a073b Fix evaluation order of /lib/finit/system/* vs /etc/finit.d/*
See updated documentation and inline comment for details.

Fix #371

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 17:20:15 +02:00
Joachim Wiberg eb9e94935e Failure to open fstab should log to console, reboot if no sulogin
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 17:56:49 +02:00
Joachim Wiberg 38791616e0 Add commented-out developer debug for svc_enabled()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 16:39:46 +02:00
Joachim Wiberg a46a33238d Display 'run' stanza progress only when they've completed
This is a follow-up to 4701ede.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 16:39:46 +02:00
Joachim Wiberg afe0488bf2 Add support for runtime evaluation of if:<condition> statements
The if: statement, introduced in v4.4, allows for discarding run/task/services
that depend on other services, based on that service's name, or condition.
Discarding in this context means unloading from the configuration.

At runtime, however, it has proven quite useful to be able to conditionally
qualify a run/task/service based on a condition.  Consider this example from
the Infix operating system:

run name:startup log:prio:user.notice \
	[S] <pid/sysrepo> confd -b --load startup-config -- Loading startup-config

run name:failure log:prio:user.critical if:<usr/fail-startup> \
	[S] <pid/sysrepo> confd --load failure-config -- Loading failure-config

The two run statements reside in the same .conf file so Finit runs them in true
sequence.  If loading the file `startup-config` fails confd sets the condition
usr/fail-startup, thus allowing the next run statement to load `failure-config`.

Notice the difference between <pid/sysrepo> condition and if:<usr/fail-startup>.
The former is a condition for starting and the latter is a condition to check if
a run/task/service is qualified to even be considerered.  The best comparison is
with the [runlevel] option, it too is used to qualify.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 16:39:46 +02:00
Joachim Wiberg ec5e42694d Silence noisy debug messages, useful only to developers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 15:14:02 +02:00
Joachim Wiberg 2e73563eea Fix #369: allow runlevel change using initctl during bootstrap
This change opens up the runlevel change API from bootstrap.  The twist
is that the change is only queued, i.e., the call `initctl runlevel 9`
during bootstrap only changes the configured runlevel to go to after
bootstrap has completed.

Effectively, this change allows overriding the `runlevel` directive in
/etc/finit.conf without having to change the file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 15:11:33 +02:00
Joachim Wiberg 6ae1083c99 Add support for SysV-only scripts in runparts
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.

Additionally, by default `runparts` now runs entirely in the background
without any progress.  To enable progress, an optional argument has been
added to the runparts command line.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 13:25:35 +02:00
Joachim Wiberg 846806747b Fix #366: document fsck.* command line options and simplify code
As pointed out in #366, the configure options --enable-fastboot and
--enable-fsckfix should just alter the default values of the two fsck
command line options.

This commit simplifies the code and makes it possible to override using
the command line regardless of the two build options.

Finally, add the two command line options to doc/cmdline.md

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 11:58:07 +02:00
Joachim Wiberg 1ee6c9f46b watchdogd: drop startup message, leaks to console
We use LOG_CONS to ensure log messages reach the operator, but since
watchdogd starts very early this means non-critical messages like the
initial greeting leaks to console because syslogd has not yet started.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-15 09:47:42 +02:00
Joachim Wiberg 939ae02a6a Increase MAX command, and arg., length: 64 -> 256
With non-standard paths, e.g., when running `make distcheck`, the
absolute path to some commands become ridiculously long.  However,
this has been a recurring issue for some users in the past, so it
is time to increase the capabilibieies of Finit to cover this.

Yes, a better way is probably to allocate all these strings when they
are used, but that would require a redesign of the initctl API and
likely cause a lot of regressions before everything has stabilized.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-14 09:15:55 +02:00
Joachim Wiberg 756b7c3fb6 Document advanced hooks/plugins to trigger rescue.conf
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 13:03:20 +02:00
Joachim Wiberg 263aec292a Support for disabling invocation of rescue mode from kernel cmdline
The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 12:45:03 +02:00
Joachim Wiberg 6e7a2fb6d5 Fix #357: allow sulogin with user different from 'root'
In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.

it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 11:37:15 +02:00
Joachim Wiberg ddedcf77e8 Follow-up to 4701ede: reschedule bootstrap check while not done
Non-trivial systems, like Infix[1], require more than one lap around the
track to warm up.  This is a follow-up to issue #362, commit 4701ede, in
fixing an obvious oversight in the new sm_check_bootstrap() work.  While
there are still outstanding bootstrap tasks or services that have not
yet started, we must reschedule the worker.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 09:35:02 +02:00
Joachim Wiberg a49f27c191 initctl: show runlevel 'N S' instead of 'N 10' during bootstrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 14:05:11 +02:00
Joachim Wiberg 4701edef4c Fix #362: prevent blocking main loop when starting run tasks
Drop complete() logic, waiting for run tasks to finish, from the
service_start() funciton to the general service_monitor().  This
refactor frees up the main loop and allows us to answer any API
calls from initctl even from the run task itself.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg 3e269c632f Start runparts with -d in debug mode, otherwise -p for progress
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg f2507d9fd7 runparts: fix arg handling and skip backup files
For some specialized forms of runparts, e.g., start-stop scripts in SysV
init replacements, there is a need to append an argument.  Typically
this is 'start' or 'stop'.

This functionality has been broken for quite some time, meaning we
should consider it being unused by current users of Finit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg e9f403bceb runparts: simplify and adjust log levels
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg 11430f83c8 Use unbuffered stderr for runparts logging result and progress
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg a22a794f55 Clarify usage text slightly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg 5556501287 dbg(): add missing \n for stderr logginge
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg a58002588e Refactor initial startup, run runparts and rc.local in background
The code refactored in this commit has long been an eyesore.  The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.

Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.

Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls.  To
ensure they run at the same point in time two things have been done:

 1. A new <int/bootstrap> condition has been added which triggers
    runparts, which now is a regular task created by conf_init()
 2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
    transition from runlevel S to any other runlevel.

Fixes #356

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-30 10:09:34 +02:00
Joachim Wiberg 28e101aaae Minor, ensure we can call exec_runtask() with NULL args
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-29 23:22:07 +02:00
Joachim Wiberg 6da8af8136 Minor, add debug logs and clarify comment
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-29 23:21:27 +02:00
Joachim Wiberg 3069e753e1 getty: add missing '-p' in usage text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-27 13:34:45 +02:00
Joachim Wiberg aafd5c1010 Allow overriding SCREEN_WIDTH
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-27 13:33:57 +02:00
Joachim Wiberg d1130473fc Follow-up to 1fc0f36, missing %s argument
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-27 13:33:00 +02:00
Joachim Wiberg 1fc0f36c6c initctl: check [enable | disable] for absolute path, not supported
For reference, see issue #359.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-11 08:06:46 +02:00
Joachim Wiberg 4153c7966d Fix #358: fix modify events for /etc/finit.conf
- iwatch events return filenames in dir field, ignore file for those
 - improve warning message on failure
 - drop bogus "Out of memory" error log message

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-10 14:20:36 +02:00
Joachim Wiberg 63b5db38df Refactor, ensure pre:/post:/ready: scripts run in the same cgroup
Related to issue #361.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-10 13:25:11 +02:00
Joachim Wiberg 9c8cd6c024 Improved logging on failure to execvp() in forked child
The execvp() call always fails with -1, so only logging exit code when
collecting the PID is not enough.  When debugging the user needs to see
the errno from execvp(), e.g., "No such file or directory", when the
command was missing the absolute path to the executable.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-10 10:23:20 +02:00
Joachim Wiberg 450f498061 Fix #361: cgroup move fail if starting service as non-root
Regression in v4.4

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-10 10:23:20 +02:00
Joachim Wiberg dc61969164 Check in service_stop() if the process is already dead
Related to 6f0d448 in that we check if the kernel knows about this
process before we try to stop it.  If it's already dead we clean up
and return.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-06-27 12:22:59 +02:00
Joachim Wiberg 6f0d448765 Fix #227: delayed service_kill() may stall shutdown/reboot
This turns out to be the root-cause of #227.  Finit is waiting forever
for proceeses to stop at shutdown/reboot, while a subreaper has already
collected the PID, or Finit for some reason did not collect the PID.

When the process timeout calls service_kill() we now check if the kernel
actually knows of this process or not.  If it's already been collected,
we can notify Finit of this by calling service_monitor() to clean up the
'svc' and in turn call sm_step() to finalize the state transition.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-06-27 12:18:09 +02:00
Joachim Wiberg 5db2fb2c32 initctl: let -f force-skip check for built-in service
When calling `initctl -b create` from a start script at bootstrap you
risk blocking the boot since Finit currently cannot reply to IPC during
that period.

This patch allows -f to override this builtin check for the following
initctl commands:

 - touch
 - show
 - edit
 - create
 - delete

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-20 10:25:02 +02:00
Joachim Wiberg 51befb492c Allow conflicting services to start when conflict is resolved
These changes add a new svc_block_t type: SVC_BLOCK_CONFLICT so a user
can more clearly see why a run/task/service has not been started by
Finit.  The reason for the block is by default logged, which can be
escaped by using the `nowarn` flag.

Also, when the conflict is resolved, allow the service to start.

With these changes, the system/hotplug.conf should work better and
cause less questions about "strange" log messages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-15 16:23:40 +02:00
Joachim Wiberg 7850378e15 Fix issue with messed up linewrap in qemu-system-x86_64
Apparently the qemu-system-x86_64 in -nographics mode does all sorts of
crazy things to the terminal.  Most annoying, it disables linewrap.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-15 16:05:59 +02:00
Joachim Wiberg 712f68f9da Fix #355: regression stopping a process and its group
In 91a9c83 a regression was introduced that affects the way Finit stops
a supervised process and its process group.

Instead of sending SIGTERM to the process, delegating the responsibility
to that process to inform any children it may have, Finit as of 91a9c83
sends SIGTERM to the entire process group.  For SIGKILL this is fine,
SIGKILL only runs as cleanup and as a last ditch effort if the process
doesn't respond to SIGTERM.

This regression, introduced in v3.2, directly affects services like
avahi-autoipd that have forked off children that it needs to tell to
exit cleanly before it returns. With the patch in question these
children are never allowed to complete, which in turn causes lingering
169.254 link-local addresses on interfaces.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-14 09:27:09 +02:00
Joachim Wiberg 2526431d8e Allow Finit to inherit PATH and SHELL from env.
When started as a monitor in a container, or for the test suite run from
distcheck, we must allow Finit to find its own tools like initctl.  This
should also be a more generic solution that cover more cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-08 09:52:59 +02:00
Joachim Wiberg 47d8a83668 Drop hard coded path limit in glob of *.conf files
A simple distcheck revealed that the local path[] was too small to store
something like /home/jocke/src/finit/finit-4.4-rc1/usr/lib/finit/system/

This refactor should cover all cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-08 09:52:21 +02:00
Joachim Wiberg f72f3febf9 Follow-up to e00fda5, allow runlevel 0 for kevent and watchdogd
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-08 09:49:06 +02:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg b6c5498f43 initctl: refactor serv_enable() for readability and coding style
Also apply the same logic to serv_disable() to drop 40 char limit on
service names.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 05:40:26 +02:00