18fae3551SRodney W. Grimes /*- 28a16b7a1SPedro F. Giffuni * SPDX-License-Identifier: BSD-3-Clause 38a16b7a1SPedro F. Giffuni * 48fae3551SRodney W. Grimes * Copyright (c) 1991, 1993 58fae3551SRodney W. Grimes * The Regents of the University of California. All rights reserved. 68fae3551SRodney W. Grimes * 78fae3551SRodney W. Grimes * This code is derived from software contributed to Berkeley by 88fae3551SRodney W. Grimes * Donn Seeley at Berkeley Software Design, Inc. 98fae3551SRodney W. Grimes * 108fae3551SRodney W. Grimes * Redistribution and use in source and binary forms, with or without 118fae3551SRodney W. Grimes * modification, are permitted provided that the following conditions 128fae3551SRodney W. Grimes * are met: 138fae3551SRodney W. Grimes * 1. Redistributions of source code must retain the above copyright 148fae3551SRodney W. Grimes * notice, this list of conditions and the following disclaimer. 158fae3551SRodney W. Grimes * 2. Redistributions in binary form must reproduce the above copyright 168fae3551SRodney W. Grimes * notice, this list of conditions and the following disclaimer in the 178fae3551SRodney W. Grimes * documentation and/or other materials provided with the distribution. 18fbbd9655SWarner Losh * 3. Neither the name of the University nor the names of its contributors 198fae3551SRodney W. Grimes * may be used to endorse or promote products derived from this software 208fae3551SRodney W. Grimes * without specific prior written permission. 218fae3551SRodney W. Grimes * 228fae3551SRodney W. Grimes * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 238fae3551SRodney W. Grimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 248fae3551SRodney W. Grimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 258fae3551SRodney W. Grimes * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 268fae3551SRodney W. Grimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 278fae3551SRodney W. Grimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 288fae3551SRodney W. Grimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 298fae3551SRodney W. Grimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 308fae3551SRodney W. Grimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 318fae3551SRodney W. Grimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 328fae3551SRodney W. Grimes * SUCH DAMAGE. 338fae3551SRodney W. Grimes */ 348fae3551SRodney W. Grimes 358fae3551SRodney W. Grimes #ifndef lint 365df42cf4SPhilippe Charnier static const char copyright[] = 378fae3551SRodney W. Grimes "@(#) Copyright (c) 1991, 1993\n\ 388fae3551SRodney W. Grimes The Regents of the University of California. All rights reserved.\n"; 398fae3551SRodney W. Grimes #endif /* not lint */ 408fae3551SRodney W. Grimes 418fae3551SRodney W. Grimes #ifndef lint 425df42cf4SPhilippe Charnier #if 0 438fae3551SRodney W. Grimes static char sccsid[] = "@(#)init.c 8.1 (Berkeley) 7/15/93"; 445df42cf4SPhilippe Charnier #endif 455df42cf4SPhilippe Charnier static const char rcsid[] = 467f3dea24SPeter Wemm "$FreeBSD$"; 478fae3551SRodney W. Grimes #endif /* not lint */ 488fae3551SRodney W. Grimes 498fae3551SRodney W. Grimes #include <sys/param.h> 508889c700SDavid Nugent #include <sys/ioctl.h> 513f5ac575SEdward Tomasz Napierala #include <sys/mman.h> 5257622f22SPoul-Henning Kamp #include <sys/mount.h> 538fae3551SRodney W. Grimes #include <sys/sysctl.h> 548fae3551SRodney W. Grimes #include <sys/wait.h> 5586bf62dcSDavid Nugent #include <sys/stat.h> 561f083b1eSMaxime Henrion #include <sys/uio.h> 578fae3551SRodney W. Grimes 588fae3551SRodney W. Grimes #include <db.h> 598fae3551SRodney W. Grimes #include <errno.h> 608fae3551SRodney W. Grimes #include <fcntl.h> 611a7bec91SWarner Losh #include <kenv.h> 62423b6a39SAndrey A. Chernov #include <libutil.h> 631a37aa56SDavid E. O'Brien #include <paths.h> 648fae3551SRodney W. Grimes #include <signal.h> 658fae3551SRodney W. Grimes #include <stdio.h> 668fae3551SRodney W. Grimes #include <stdlib.h> 678fae3551SRodney W. Grimes #include <string.h> 688fae3551SRodney W. Grimes #include <syslog.h> 698fae3551SRodney W. Grimes #include <time.h> 708fae3551SRodney W. Grimes #include <ttyent.h> 718fae3551SRodney W. Grimes #include <unistd.h> 72e460cfd3SNate Williams #include <sys/reboot.h> 73c5842835SPhilippe Charnier #include <err.h> 748fae3551SRodney W. Grimes 758fae3551SRodney W. Grimes #include <stdarg.h> 768fae3551SRodney W. Grimes 778fae3551SRodney W. Grimes #ifdef SECURE 788fae3551SRodney W. Grimes #include <pwd.h> 798fae3551SRodney W. Grimes #endif 808fae3551SRodney W. Grimes 811ef60eb1SDavid Nugent #ifdef LOGIN_CAP 821ef60eb1SDavid Nugent #include <login_cap.h> 831ef60eb1SDavid Nugent #endif 841ef60eb1SDavid Nugent 853f5ac575SEdward Tomasz Napierala #include "mntopts.h" 868fae3551SRodney W. Grimes #include "pathnames.h" 878fae3551SRodney W. Grimes 888fae3551SRodney W. Grimes /* 898fae3551SRodney W. Grimes * Sleep times; used to prevent thrashing. 908fae3551SRodney W. Grimes */ 918fae3551SRodney W. Grimes #define GETTY_SPACING 5 /* N secs minimum getty spacing */ 928fae3551SRodney W. Grimes #define GETTY_SLEEP 30 /* sleep N secs after spacing problem */ 93b5df27e2SAndrey A. Chernov #define GETTY_NSPACE 3 /* max. spacing count to bring reaction */ 948fae3551SRodney W. Grimes #define WINDOW_WAIT 3 /* wait N secs after starting window */ 958fae3551SRodney W. Grimes #define STALL_TIMEOUT 30 /* wait N secs after warning */ 968fae3551SRodney W. Grimes #define DEATH_WATCH 10 /* wait N secs for procs to die */ 975df42cf4SPhilippe Charnier #define DEATH_SCRIPT 120 /* wait for 2min for /etc/rc.shutdown */ 98e82d5545SDavid Nugent #define RESOURCE_RC "daemon" 99e82d5545SDavid Nugent #define RESOURCE_WINDOW "default" 100e82d5545SDavid Nugent #define RESOURCE_GETTY "default" 1018fae3551SRodney W. Grimes 10245cfb1dcSXin LI static void handle(sig_t, ...); 10345cfb1dcSXin LI static void delset(sigset_t *, ...); 1048fae3551SRodney W. Grimes 10545cfb1dcSXin LI static void stall(const char *, ...) __printflike(1, 2); 10645cfb1dcSXin LI static void warning(const char *, ...) __printflike(1, 2); 10745cfb1dcSXin LI static void emergency(const char *, ...) __printflike(1, 2); 10845cfb1dcSXin LI static void disaster(int); 10945cfb1dcSXin LI static void badsys(int); 1103f5ac575SEdward Tomasz Napierala static void revoke_ttys(void); 11145cfb1dcSXin LI static int runshutdown(void); 112ab03e6d5SXin LI static char *strk(char *); 1138fae3551SRodney W. Grimes 1148fae3551SRodney W. Grimes /* 1158fae3551SRodney W. Grimes * We really need a recursive typedef... 1168fae3551SRodney W. Grimes * The following at least guarantees that the return type of (*state_t)() 1178fae3551SRodney W. Grimes * is sufficiently wide to hold a function pointer. 1188fae3551SRodney W. Grimes */ 11973bf18edSWarner Losh typedef long (*state_func_t)(void); 12073bf18edSWarner Losh typedef state_func_t (*state_t)(void); 1218fae3551SRodney W. Grimes 12245cfb1dcSXin LI static state_func_t single_user(void); 12345cfb1dcSXin LI static state_func_t runcom(void); 12445cfb1dcSXin LI static state_func_t read_ttys(void); 12545cfb1dcSXin LI static state_func_t multi_user(void); 12645cfb1dcSXin LI static state_func_t clean_ttys(void); 12745cfb1dcSXin LI static state_func_t catatonia(void); 12845cfb1dcSXin LI static state_func_t death(void); 129acf0ab06SJilles Tjoelker static state_func_t death_single(void); 1303f5ac575SEdward Tomasz Napierala static state_func_t reroot(void); 1313f5ac575SEdward Tomasz Napierala static state_func_t reroot_phase_two(void); 1328fae3551SRodney W. Grimes 13345cfb1dcSXin LI static state_func_t run_script(const char *); 1341a7bec91SWarner Losh 1351efe3c6bSEd Schouten static enum { AUTOBOOT, FASTBOOT } runcom_mode = AUTOBOOT; 13677103ea3SPoul-Henning Kamp #define FALSE 0 13777103ea3SPoul-Henning Kamp #define TRUE 1 13877103ea3SPoul-Henning Kamp 1391efe3c6bSEd Schouten static int Reboot = FALSE; 1401efe3c6bSEd Schouten static int howto = RB_AUTOBOOT; 1418fae3551SRodney W. Grimes 1421efe3c6bSEd Schouten static int devfs; 143377b6d1eSEdward Tomasz Napierala static char *init_path_argv0; 14457622f22SPoul-Henning Kamp 14545cfb1dcSXin LI static void transition(state_t); 14645cfb1dcSXin LI static state_t requested_transition; 147acf0ab06SJilles Tjoelker static state_t current_state = death_single; 1488fae3551SRodney W. Grimes 1494c2c7b2cSEd Schouten static void open_console(void); 15045cfb1dcSXin LI static const char *get_shell(void); 15145cfb1dcSXin LI static void write_stderr(const char *message); 1528fae3551SRodney W. Grimes 1538fae3551SRodney W. Grimes typedef struct init_session { 1548fae3551SRodney W. Grimes pid_t se_process; /* controlling process */ 1558fae3551SRodney W. Grimes time_t se_started; /* used to avoid thrashing */ 1568fae3551SRodney W. Grimes int se_flags; /* status of session */ 1578fae3551SRodney W. Grimes #define SE_SHUTDOWN 0x1 /* session won't be restarted */ 158b0b670eeSAlfred Perlstein #define SE_PRESENT 0x2 /* session is in /etc/ttys */ 159*1cde387cSEdward Tomasz Napierala #define SE_IFEXISTS 0x4 /* session defined as "onifexists" */ 160*1cde387cSEdward Tomasz Napierala #define SE_IFCONSOLE 0x8 /* session defined as "onifconsole" */ 161b5df27e2SAndrey A. Chernov int se_nspace; /* spacing count */ 1628fae3551SRodney W. Grimes char *se_device; /* filename of port */ 1638fae3551SRodney W. Grimes char *se_getty; /* what to run on that port */ 164b5df27e2SAndrey A. Chernov char *se_getty_argv_space; /* pre-parsed argument array space */ 1658fae3551SRodney W. Grimes char **se_getty_argv; /* pre-parsed argument array */ 1668fae3551SRodney W. Grimes char *se_window; /* window system (started only once) */ 167b5df27e2SAndrey A. Chernov char *se_window_argv_space; /* pre-parsed argument array space */ 1688fae3551SRodney W. Grimes char **se_window_argv; /* pre-parsed argument array */ 169b5df27e2SAndrey A. Chernov char *se_type; /* default terminal type */ 1708fae3551SRodney W. Grimes struct init_session *se_prev; 1718fae3551SRodney W. Grimes struct init_session *se_next; 1728fae3551SRodney W. Grimes } session_t; 1738fae3551SRodney W. Grimes 17445cfb1dcSXin LI static void free_session(session_t *); 1750b57dd6bSJilles Tjoelker static session_t *new_session(session_t *, struct ttyent *); 17645cfb1dcSXin LI static session_t *sessions; 1778fae3551SRodney W. Grimes 17845cfb1dcSXin LI static char **construct_argv(char *); 17945cfb1dcSXin LI static void start_window_system(session_t *); 18045cfb1dcSXin LI static void collect_child(pid_t); 18145cfb1dcSXin LI static pid_t start_getty(session_t *); 18245cfb1dcSXin LI static void transition_handler(int); 18345cfb1dcSXin LI static void alrm_handler(int); 18445cfb1dcSXin LI static void setsecuritylevel(int); 18545cfb1dcSXin LI static int getsecuritylevel(void); 18645cfb1dcSXin LI static int setupargv(session_t *, struct ttyent *); 187e82d5545SDavid Nugent #ifdef LOGIN_CAP 18845cfb1dcSXin LI static void setprocresources(const char *); 189e82d5545SDavid Nugent #endif 19045cfb1dcSXin LI static int clang; 1918fae3551SRodney W. Grimes 19245cfb1dcSXin LI static int start_session_db(void); 19345cfb1dcSXin LI static void add_session(session_t *); 19445cfb1dcSXin LI static void del_session(session_t *); 19545cfb1dcSXin LI static session_t *find_session(pid_t); 19645cfb1dcSXin LI static DB *session_db; 1978fae3551SRodney W. Grimes 1988fae3551SRodney W. Grimes /* 1998fae3551SRodney W. Grimes * The mother of all processes. 2008fae3551SRodney W. Grimes */ 2018fae3551SRodney W. Grimes int 20273bf18edSWarner Losh main(int argc, char *argv[]) 2038fae3551SRodney W. Grimes { 2041a7bec91SWarner Losh state_t initial_transition = runcom; 2051a7bec91SWarner Losh char kenv_value[PATH_MAX]; 2063f5ac575SEdward Tomasz Napierala int c, error; 2078fae3551SRodney W. Grimes struct sigaction sa; 2088fae3551SRodney W. Grimes sigset_t mask; 2098fae3551SRodney W. Grimes 2108fae3551SRodney W. Grimes /* Dispose of random users. */ 211c5842835SPhilippe Charnier if (getuid() != 0) 212c5842835SPhilippe Charnier errx(1, "%s", strerror(EPERM)); 2138fae3551SRodney W. Grimes 2148fae3551SRodney W. Grimes /* System V users like to reexec init. */ 2151681d659SRuslan Ermilov if (getpid() != 1) { 2161681d659SRuslan Ermilov #ifdef COMPAT_SYSV_INIT 2171681d659SRuslan Ermilov /* So give them what they want */ 2181681d659SRuslan Ermilov if (argc > 1) { 2191681d659SRuslan Ermilov if (strlen(argv[1]) == 1) { 2203d438ad6SDavid E. O'Brien char runlevel = *argv[1]; 2213d438ad6SDavid E. O'Brien int sig; 2228fae3551SRodney W. Grimes 2231681d659SRuslan Ermilov switch (runlevel) { 2241681d659SRuslan Ermilov case '0': /* halt + poweroff */ 2251681d659SRuslan Ermilov sig = SIGUSR2; 2261681d659SRuslan Ermilov break; 2271681d659SRuslan Ermilov case '1': /* single-user */ 2281681d659SRuslan Ermilov sig = SIGTERM; 2291681d659SRuslan Ermilov break; 2301681d659SRuslan Ermilov case '6': /* reboot */ 2311681d659SRuslan Ermilov sig = SIGINT; 2321681d659SRuslan Ermilov break; 2331681d659SRuslan Ermilov case 'c': /* block further logins */ 2341681d659SRuslan Ermilov sig = SIGTSTP; 2351681d659SRuslan Ermilov break; 2361681d659SRuslan Ermilov case 'q': /* rescan /etc/ttys */ 2371681d659SRuslan Ermilov sig = SIGHUP; 2381681d659SRuslan Ermilov break; 2393f5ac575SEdward Tomasz Napierala case 'r': /* remount root */ 2403f5ac575SEdward Tomasz Napierala sig = SIGEMT; 2413f5ac575SEdward Tomasz Napierala break; 2421681d659SRuslan Ermilov default: 2431681d659SRuslan Ermilov goto invalid; 2441681d659SRuslan Ermilov } 2451681d659SRuslan Ermilov kill(1, sig); 2461681d659SRuslan Ermilov _exit(0); 2471681d659SRuslan Ermilov } else 2481681d659SRuslan Ermilov invalid: 2491681d659SRuslan Ermilov errx(1, "invalid run-level ``%s''", argv[1]); 2501681d659SRuslan Ermilov } else 2511681d659SRuslan Ermilov #endif 2521681d659SRuslan Ermilov errx(1, "already running"); 2531681d659SRuslan Ermilov } 254377b6d1eSEdward Tomasz Napierala 255377b6d1eSEdward Tomasz Napierala init_path_argv0 = strdup(argv[0]); 256377b6d1eSEdward Tomasz Napierala if (init_path_argv0 == NULL) 257377b6d1eSEdward Tomasz Napierala err(1, "strdup"); 258377b6d1eSEdward Tomasz Napierala 2598fae3551SRodney W. Grimes /* 2608fae3551SRodney W. Grimes * Note that this does NOT open a file... 2618fae3551SRodney W. Grimes * Does 'init' deserve its own facility number? 2628fae3551SRodney W. Grimes */ 26306224a94SNeel Natu openlog("init", LOG_CONS, LOG_AUTH); 2648fae3551SRodney W. Grimes 2658fae3551SRodney W. Grimes /* 2668fae3551SRodney W. Grimes * Create an initial session. 2678fae3551SRodney W. Grimes */ 2683f5ac575SEdward Tomasz Napierala if (setsid() < 0 && (errno != EPERM || getsid(0) != 1)) 2698fae3551SRodney W. Grimes warning("initial setsid() failed: %m"); 2708fae3551SRodney W. Grimes 2718fae3551SRodney W. Grimes /* 2728fae3551SRodney W. Grimes * Establish an initial user so that programs running 2738fae3551SRodney W. Grimes * single user do not freak out and die (like passwd). 2748fae3551SRodney W. Grimes */ 2758fae3551SRodney W. Grimes if (setlogin("root") < 0) 2768fae3551SRodney W. Grimes warning("setlogin() failed: %m"); 2778fae3551SRodney W. Grimes 2788fae3551SRodney W. Grimes /* 2798fae3551SRodney W. Grimes * This code assumes that we always get arguments through flags, 2808fae3551SRodney W. Grimes * never through bits set in some random machine register. 2818fae3551SRodney W. Grimes */ 2823f5ac575SEdward Tomasz Napierala while ((c = getopt(argc, argv, "dsfr")) != -1) 2838fae3551SRodney W. Grimes switch (c) { 28457622f22SPoul-Henning Kamp case 'd': 28557622f22SPoul-Henning Kamp devfs = 1; 28657622f22SPoul-Henning Kamp break; 2878fae3551SRodney W. Grimes case 's': 2881a7bec91SWarner Losh initial_transition = single_user; 2898fae3551SRodney W. Grimes break; 2908fae3551SRodney W. Grimes case 'f': 2918fae3551SRodney W. Grimes runcom_mode = FASTBOOT; 2928fae3551SRodney W. Grimes break; 2933f5ac575SEdward Tomasz Napierala case 'r': 2943f5ac575SEdward Tomasz Napierala initial_transition = reroot_phase_two; 2953f5ac575SEdward Tomasz Napierala break; 2968fae3551SRodney W. Grimes default: 2978fae3551SRodney W. Grimes warning("unrecognized flag '-%c'", c); 2988fae3551SRodney W. Grimes break; 2998fae3551SRodney W. Grimes } 3008fae3551SRodney W. Grimes 3018fae3551SRodney W. Grimes if (optind != argc) 3028fae3551SRodney W. Grimes warning("ignoring excess arguments"); 3038fae3551SRodney W. Grimes 3041a7bec91SWarner Losh /* 3051a7bec91SWarner Losh * We catch or block signals rather than ignore them, 3061a7bec91SWarner Losh * so that they get reset on exec. 3071a7bec91SWarner Losh */ 3081a7bec91SWarner Losh handle(badsys, SIGSYS, 0); 309091abe40SDavid E. O'Brien handle(disaster, SIGABRT, SIGFPE, SIGILL, SIGSEGV, SIGBUS, SIGXCPU, 310091abe40SDavid E. O'Brien SIGXFSZ, 0); 3113f5ac575SEdward Tomasz Napierala handle(transition_handler, SIGHUP, SIGINT, SIGEMT, SIGTERM, SIGTSTP, 31235c1d16eSWarner Losh SIGUSR1, SIGUSR2, SIGWINCH, 0); 3131a7bec91SWarner Losh handle(alrm_handler, SIGALRM, 0); 3141a7bec91SWarner Losh sigfillset(&mask); 3151a7bec91SWarner Losh delset(&mask, SIGABRT, SIGFPE, SIGILL, SIGSEGV, SIGBUS, SIGSYS, 3163f5ac575SEdward Tomasz Napierala SIGXCPU, SIGXFSZ, SIGHUP, SIGINT, SIGEMT, SIGTERM, SIGTSTP, 31735c1d16eSWarner Losh SIGALRM, SIGUSR1, SIGUSR2, SIGWINCH, 0); 3181a7bec91SWarner Losh sigprocmask(SIG_SETMASK, &mask, (sigset_t *) 0); 3191a7bec91SWarner Losh sigemptyset(&sa.sa_mask); 3201a7bec91SWarner Losh sa.sa_flags = 0; 3211a7bec91SWarner Losh sa.sa_handler = SIG_IGN; 322091abe40SDavid E. O'Brien sigaction(SIGTTIN, &sa, (struct sigaction *)0); 323091abe40SDavid E. O'Brien sigaction(SIGTTOU, &sa, (struct sigaction *)0); 3241a7bec91SWarner Losh 3251a7bec91SWarner Losh /* 3261a7bec91SWarner Losh * Paranoia. 3271a7bec91SWarner Losh */ 3281a7bec91SWarner Losh close(0); 3291a7bec91SWarner Losh close(1); 3301a7bec91SWarner Losh close(2); 3311a7bec91SWarner Losh 3321a7bec91SWarner Losh if (kenv(KENV_GET, "init_script", kenv_value, sizeof(kenv_value)) > 0) { 3331a7bec91SWarner Losh state_func_t next_transition; 3341a7bec91SWarner Losh 3352ef6931aSMarcelo Araujo if ((next_transition = run_script(kenv_value)) != NULL) 3361a7bec91SWarner Losh initial_transition = (state_t) next_transition; 3371a7bec91SWarner Losh } 3381a7bec91SWarner Losh 3391a7bec91SWarner Losh if (kenv(KENV_GET, "init_chroot", kenv_value, sizeof(kenv_value)) > 0) { 3401a7bec91SWarner Losh if (chdir(kenv_value) != 0 || chroot(".") != 0) 3411a7bec91SWarner Losh warning("Can't chroot to %s: %m", kenv_value); 3421a7bec91SWarner Losh } 3431a7bec91SWarner Losh 3441a7bec91SWarner Losh /* 3451a7bec91SWarner Losh * Additional check if devfs needs to be mounted: 3461a7bec91SWarner Losh * If "/" and "/dev" have the same device number, 3471a7bec91SWarner Losh * then it hasn't been mounted yet. 3481a7bec91SWarner Losh */ 3491a7bec91SWarner Losh if (!devfs) { 3501a7bec91SWarner Losh struct stat stst; 3511a7bec91SWarner Losh dev_t root_devno; 3521a7bec91SWarner Losh 3531a7bec91SWarner Losh stat("/", &stst); 3541a7bec91SWarner Losh root_devno = stst.st_dev; 3551a7bec91SWarner Losh if (stat("/dev", &stst) != 0) 3561a7bec91SWarner Losh warning("Can't stat /dev: %m"); 3571a7bec91SWarner Losh else if (stst.st_dev == root_devno) 3581a7bec91SWarner Losh devfs++; 3591a7bec91SWarner Losh } 3601a7bec91SWarner Losh 36157622f22SPoul-Henning Kamp if (devfs) { 3621f083b1eSMaxime Henrion struct iovec iov[4]; 363421b0201SPoul-Henning Kamp char *s; 364421b0201SPoul-Henning Kamp int i; 365421b0201SPoul-Henning Kamp 366ab03e6d5SXin LI char _fstype[] = "fstype"; 367ab03e6d5SXin LI char _devfs[] = "devfs"; 368ab03e6d5SXin LI char _fspath[] = "fspath"; 369ab03e6d5SXin LI char _path_dev[]= _PATH_DEV; 370ab03e6d5SXin LI 371ab03e6d5SXin LI iov[0].iov_base = _fstype; 372ab03e6d5SXin LI iov[0].iov_len = sizeof(_fstype); 373ab03e6d5SXin LI iov[1].iov_base = _devfs; 374ab03e6d5SXin LI iov[1].iov_len = sizeof(_devfs); 375ab03e6d5SXin LI iov[2].iov_base = _fspath; 376ab03e6d5SXin LI iov[2].iov_len = sizeof(_fspath); 377421b0201SPoul-Henning Kamp /* 378421b0201SPoul-Henning Kamp * Try to avoid the trailing slash in _PATH_DEV. 379421b0201SPoul-Henning Kamp * Be *very* defensive. 380421b0201SPoul-Henning Kamp */ 381421b0201SPoul-Henning Kamp s = strdup(_PATH_DEV); 382421b0201SPoul-Henning Kamp if (s != NULL) { 383421b0201SPoul-Henning Kamp i = strlen(s); 384421b0201SPoul-Henning Kamp if (i > 0 && s[i - 1] == '/') 385421b0201SPoul-Henning Kamp s[i - 1] = '\0'; 3861f083b1eSMaxime Henrion iov[3].iov_base = s; 3871f083b1eSMaxime Henrion iov[3].iov_len = strlen(s) + 1; 388421b0201SPoul-Henning Kamp } else { 389ab03e6d5SXin LI iov[3].iov_base = _path_dev; 390ab03e6d5SXin LI iov[3].iov_len = sizeof(_path_dev); 39157622f22SPoul-Henning Kamp } 3921f083b1eSMaxime Henrion nmount(iov, 4, 0); 3931f083b1eSMaxime Henrion if (s != NULL) 3941f083b1eSMaxime Henrion free(s); 395421b0201SPoul-Henning Kamp } 39657622f22SPoul-Henning Kamp 3973f5ac575SEdward Tomasz Napierala if (initial_transition != reroot_phase_two) { 3983f5ac575SEdward Tomasz Napierala /* 3993f5ac575SEdward Tomasz Napierala * Unmount reroot leftovers. This runs after init(8) 4003f5ac575SEdward Tomasz Napierala * gets reexecuted after reroot_phase_two() is done. 4013f5ac575SEdward Tomasz Napierala */ 4023f5ac575SEdward Tomasz Napierala error = unmount(_PATH_REROOT, MNT_FORCE); 4033f5ac575SEdward Tomasz Napierala if (error != 0 && errno != EINVAL) 4043f5ac575SEdward Tomasz Napierala warning("Cannot unmount %s: %m", _PATH_REROOT); 4053f5ac575SEdward Tomasz Napierala } 4063f5ac575SEdward Tomasz Napierala 4078fae3551SRodney W. Grimes /* 4088fae3551SRodney W. Grimes * Start the state machine. 4098fae3551SRodney W. Grimes */ 4101a7bec91SWarner Losh transition(initial_transition); 4118fae3551SRodney W. Grimes 4128fae3551SRodney W. Grimes /* 4138fae3551SRodney W. Grimes * Should never reach here. 4148fae3551SRodney W. Grimes */ 4158fae3551SRodney W. Grimes return 1; 4168fae3551SRodney W. Grimes } 4178fae3551SRodney W. Grimes 4188fae3551SRodney W. Grimes /* 4198fae3551SRodney W. Grimes * Associate a function with a signal handler. 4208fae3551SRodney W. Grimes */ 42145cfb1dcSXin LI static void 4228fae3551SRodney W. Grimes handle(sig_t handler, ...) 4238fae3551SRodney W. Grimes { 4248fae3551SRodney W. Grimes int sig; 4258fae3551SRodney W. Grimes struct sigaction sa; 42639034633SJames Raynard sigset_t mask_everything; 4278fae3551SRodney W. Grimes va_list ap; 4288fae3551SRodney W. Grimes va_start(ap, handler); 4298fae3551SRodney W. Grimes 4308fae3551SRodney W. Grimes sa.sa_handler = handler; 4318fae3551SRodney W. Grimes sigfillset(&mask_everything); 4328fae3551SRodney W. Grimes 43330e8350cSBruce Evans while ((sig = va_arg(ap, int)) != 0) { 4348fae3551SRodney W. Grimes sa.sa_mask = mask_everything; 4358fae3551SRodney W. Grimes /* XXX SA_RESTART? */ 4368fae3551SRodney W. Grimes sa.sa_flags = sig == SIGCHLD ? SA_NOCLDSTOP : 0; 4378fae3551SRodney W. Grimes sigaction(sig, &sa, (struct sigaction *) 0); 4388fae3551SRodney W. Grimes } 4398fae3551SRodney W. Grimes va_end(ap); 4408fae3551SRodney W. Grimes } 4418fae3551SRodney W. Grimes 4428fae3551SRodney W. Grimes /* 4438fae3551SRodney W. Grimes * Delete a set of signals from a mask. 4448fae3551SRodney W. Grimes */ 44545cfb1dcSXin LI static void 4468fae3551SRodney W. Grimes delset(sigset_t *maskp, ...) 4478fae3551SRodney W. Grimes { 4488fae3551SRodney W. Grimes int sig; 4498fae3551SRodney W. Grimes va_list ap; 4508fae3551SRodney W. Grimes va_start(ap, maskp); 4518fae3551SRodney W. Grimes 45230e8350cSBruce Evans while ((sig = va_arg(ap, int)) != 0) 4538fae3551SRodney W. Grimes sigdelset(maskp, sig); 4548fae3551SRodney W. Grimes va_end(ap); 4558fae3551SRodney W. Grimes } 4568fae3551SRodney W. Grimes 4578fae3551SRodney W. Grimes /* 4588fae3551SRodney W. Grimes * Log a message and sleep for a while (to give someone an opportunity 4598fae3551SRodney W. Grimes * to read it and to save log or hardcopy output if the problem is chronic). 4608fae3551SRodney W. Grimes * NB: should send a message to the session logger to avoid blocking. 4618fae3551SRodney W. Grimes */ 46245cfb1dcSXin LI static void 4635979df34SKris Kennaway stall(const char *message, ...) 4648fae3551SRodney W. Grimes { 4658fae3551SRodney W. Grimes va_list ap; 4668fae3551SRodney W. Grimes va_start(ap, message); 4678fae3551SRodney W. Grimes 4688fae3551SRodney W. Grimes vsyslog(LOG_ALERT, message, ap); 4698fae3551SRodney W. Grimes va_end(ap); 4708fae3551SRodney W. Grimes sleep(STALL_TIMEOUT); 4718fae3551SRodney W. Grimes } 4728fae3551SRodney W. Grimes 4738fae3551SRodney W. Grimes /* 4748fae3551SRodney W. Grimes * Like stall(), but doesn't sleep. 4758fae3551SRodney W. Grimes * If cpp had variadic macros, the two functions could be #defines for another. 4768fae3551SRodney W. Grimes * NB: should send a message to the session logger to avoid blocking. 4778fae3551SRodney W. Grimes */ 47845cfb1dcSXin LI static void 4795979df34SKris Kennaway warning(const char *message, ...) 4808fae3551SRodney W. Grimes { 4818fae3551SRodney W. Grimes va_list ap; 4828fae3551SRodney W. Grimes va_start(ap, message); 4838fae3551SRodney W. Grimes 4848fae3551SRodney W. Grimes vsyslog(LOG_ALERT, message, ap); 4858fae3551SRodney W. Grimes va_end(ap); 4868fae3551SRodney W. Grimes } 4878fae3551SRodney W. Grimes 4888fae3551SRodney W. Grimes /* 4898fae3551SRodney W. Grimes * Log an emergency message. 4908fae3551SRodney W. Grimes * NB: should send a message to the session logger to avoid blocking. 4918fae3551SRodney W. Grimes */ 49245cfb1dcSXin LI static void 4935979df34SKris Kennaway emergency(const char *message, ...) 4948fae3551SRodney W. Grimes { 4958fae3551SRodney W. Grimes va_list ap; 4968fae3551SRodney W. Grimes va_start(ap, message); 4978fae3551SRodney W. Grimes 4988fae3551SRodney W. Grimes vsyslog(LOG_EMERG, message, ap); 4998fae3551SRodney W. Grimes va_end(ap); 5008fae3551SRodney W. Grimes } 5018fae3551SRodney W. Grimes 5028fae3551SRodney W. Grimes /* 5038fae3551SRodney W. Grimes * Catch a SIGSYS signal. 5048fae3551SRodney W. Grimes * 5058fae3551SRodney W. Grimes * These may arise if a system does not support sysctl. 5068fae3551SRodney W. Grimes * We tolerate up to 25 of these, then throw in the towel. 5078fae3551SRodney W. Grimes */ 50845cfb1dcSXin LI static void 50973bf18edSWarner Losh badsys(int sig) 5108fae3551SRodney W. Grimes { 5118fae3551SRodney W. Grimes static int badcount = 0; 5128fae3551SRodney W. Grimes 5138fae3551SRodney W. Grimes if (badcount++ < 25) 5148fae3551SRodney W. Grimes return; 5158fae3551SRodney W. Grimes disaster(sig); 5168fae3551SRodney W. Grimes } 5178fae3551SRodney W. Grimes 5188fae3551SRodney W. Grimes /* 5198fae3551SRodney W. Grimes * Catch an unexpected signal. 5208fae3551SRodney W. Grimes */ 52145cfb1dcSXin LI static void 52273bf18edSWarner Losh disaster(int sig) 5238fae3551SRodney W. Grimes { 524091abe40SDavid E. O'Brien 5258fae3551SRodney W. Grimes emergency("fatal signal: %s", 5268889c700SDavid Nugent (unsigned)sig < NSIG ? sys_siglist[sig] : "unknown signal"); 5278fae3551SRodney W. Grimes 5288fae3551SRodney W. Grimes sleep(STALL_TIMEOUT); 5298fae3551SRodney W. Grimes _exit(sig); /* reboot */ 5308fae3551SRodney W. Grimes } 5318fae3551SRodney W. Grimes 5328fae3551SRodney W. Grimes /* 5338fae3551SRodney W. Grimes * Get the security level of the kernel. 5348fae3551SRodney W. Grimes */ 53545cfb1dcSXin LI static int 53673bf18edSWarner Losh getsecuritylevel(void) 5378fae3551SRodney W. Grimes { 5388fae3551SRodney W. Grimes #ifdef KERN_SECURELVL 5398fae3551SRodney W. Grimes int name[2], curlevel; 5408fae3551SRodney W. Grimes size_t len; 5418fae3551SRodney W. Grimes 5428fae3551SRodney W. Grimes name[0] = CTL_KERN; 5438fae3551SRodney W. Grimes name[1] = KERN_SECURELVL; 5448fae3551SRodney W. Grimes len = sizeof curlevel; 5458fae3551SRodney W. Grimes if (sysctl(name, 2, &curlevel, &len, NULL, 0) == -1) { 5468fae3551SRodney W. Grimes emergency("cannot get kernel security level: %s", 5478fae3551SRodney W. Grimes strerror(errno)); 5488fae3551SRodney W. Grimes return (-1); 5498fae3551SRodney W. Grimes } 5508fae3551SRodney W. Grimes return (curlevel); 5518fae3551SRodney W. Grimes #else 5528fae3551SRodney W. Grimes return (-1); 5538fae3551SRodney W. Grimes #endif 5548fae3551SRodney W. Grimes } 5558fae3551SRodney W. Grimes 5568fae3551SRodney W. Grimes /* 5578fae3551SRodney W. Grimes * Set the security level of the kernel. 5588fae3551SRodney W. Grimes */ 55945cfb1dcSXin LI static void 56073bf18edSWarner Losh setsecuritylevel(int newlevel) 5618fae3551SRodney W. Grimes { 5628fae3551SRodney W. Grimes #ifdef KERN_SECURELVL 5638fae3551SRodney W. Grimes int name[2], curlevel; 5648fae3551SRodney W. Grimes 5658fae3551SRodney W. Grimes curlevel = getsecuritylevel(); 5668fae3551SRodney W. Grimes if (newlevel == curlevel) 5678fae3551SRodney W. Grimes return; 5688fae3551SRodney W. Grimes name[0] = CTL_KERN; 5698fae3551SRodney W. Grimes name[1] = KERN_SECURELVL; 5708fae3551SRodney W. Grimes if (sysctl(name, 2, NULL, NULL, &newlevel, sizeof newlevel) == -1) { 5718fae3551SRodney W. Grimes emergency( 5728fae3551SRodney W. Grimes "cannot change kernel security level from %d to %d: %s", 5738fae3551SRodney W. Grimes curlevel, newlevel, strerror(errno)); 5748fae3551SRodney W. Grimes return; 5758fae3551SRodney W. Grimes } 5768fae3551SRodney W. Grimes #ifdef SECURE 5778fae3551SRodney W. Grimes warning("kernel security level changed from %d to %d", 5788fae3551SRodney W. Grimes curlevel, newlevel); 5798fae3551SRodney W. Grimes #endif 5808fae3551SRodney W. Grimes #endif 5818fae3551SRodney W. Grimes } 5828fae3551SRodney W. Grimes 5838fae3551SRodney W. Grimes /* 5848fae3551SRodney W. Grimes * Change states in the finite state machine. 5858fae3551SRodney W. Grimes * The initial state is passed as an argument. 5868fae3551SRodney W. Grimes */ 58745cfb1dcSXin LI static void 58873bf18edSWarner Losh transition(state_t s) 5898fae3551SRodney W. Grimes { 590091abe40SDavid E. O'Brien 591acf0ab06SJilles Tjoelker current_state = s; 5928fae3551SRodney W. Grimes for (;;) 593acf0ab06SJilles Tjoelker current_state = (state_t) (*current_state)(); 5948fae3551SRodney W. Grimes } 5958fae3551SRodney W. Grimes 5968fae3551SRodney W. Grimes /* 5978fae3551SRodney W. Grimes * Start a session and allocate a controlling terminal. 5988fae3551SRodney W. Grimes * Only called by children of init after forking. 5998fae3551SRodney W. Grimes */ 60045cfb1dcSXin LI static void 6014c2c7b2cSEd Schouten open_console(void) 6028fae3551SRodney W. Grimes { 6038fae3551SRodney W. Grimes int fd; 6048fae3551SRodney W. Grimes 6056ee5808bSEd Schouten /* 6066ee5808bSEd Schouten * Try to open /dev/console. Open the device with O_NONBLOCK to 6076ee5808bSEd Schouten * prevent potential blocking on a carrier. 6086ee5808bSEd Schouten */ 6094c2c7b2cSEd Schouten revoke(_PATH_CONSOLE); 6104c2c7b2cSEd Schouten if ((fd = open(_PATH_CONSOLE, O_RDWR | O_NONBLOCK)) != -1) { 6116ee5808bSEd Schouten (void)fcntl(fd, F_SETFL, fcntl(fd, F_GETFL) & ~O_NONBLOCK); 6124c2c7b2cSEd Schouten if (login_tty(fd) == 0) 6134c2c7b2cSEd Schouten return; 6144c2c7b2cSEd Schouten close(fd); 6154c2c7b2cSEd Schouten } 6164c2c7b2cSEd Schouten 6174c2c7b2cSEd Schouten /* No luck. Log output to file if possible. */ 6184c2c7b2cSEd Schouten if ((fd = open(_PATH_DEVNULL, O_RDWR)) == -1) { 6194c2c7b2cSEd Schouten stall("cannot open null device."); 6208fae3551SRodney W. Grimes _exit(1); 6218fae3551SRodney W. Grimes } 6224c2c7b2cSEd Schouten if (fd != STDIN_FILENO) { 6234c2c7b2cSEd Schouten dup2(fd, STDIN_FILENO); 6244c2c7b2cSEd Schouten close(fd); 6258fae3551SRodney W. Grimes } 6264c2c7b2cSEd Schouten fd = open(_PATH_INITLOG, O_WRONLY | O_APPEND | O_CREAT, 0644); 6274c2c7b2cSEd Schouten if (fd == -1) 6284c2c7b2cSEd Schouten dup2(STDIN_FILENO, STDOUT_FILENO); 6294c2c7b2cSEd Schouten else if (fd != STDOUT_FILENO) { 6304c2c7b2cSEd Schouten dup2(fd, STDOUT_FILENO); 6314c2c7b2cSEd Schouten close(fd); 6324c2c7b2cSEd Schouten } 6334c2c7b2cSEd Schouten dup2(STDOUT_FILENO, STDERR_FILENO); 6348fae3551SRodney W. Grimes } 6358fae3551SRodney W. Grimes 63645cfb1dcSXin LI static const char * 6371a7bec91SWarner Losh get_shell(void) 6381a7bec91SWarner Losh { 6391a7bec91SWarner Losh static char kenv_value[PATH_MAX]; 6401a7bec91SWarner Losh 6411a7bec91SWarner Losh if (kenv(KENV_GET, "init_shell", kenv_value, sizeof(kenv_value)) > 0) 6421a7bec91SWarner Losh return kenv_value; 6431a7bec91SWarner Losh else 6441a7bec91SWarner Losh return _PATH_BSHELL; 6451a7bec91SWarner Losh } 6461a7bec91SWarner Losh 64745cfb1dcSXin LI static void 6481a7bec91SWarner Losh write_stderr(const char *message) 6491a7bec91SWarner Losh { 650091abe40SDavid E. O'Brien 6511a7bec91SWarner Losh write(STDERR_FILENO, message, strlen(message)); 6521a7bec91SWarner Losh } 6531a7bec91SWarner Losh 6543f5ac575SEdward Tomasz Napierala static int 6553f5ac575SEdward Tomasz Napierala read_file(const char *path, void **bufp, size_t *bufsizep) 6563f5ac575SEdward Tomasz Napierala { 6573f5ac575SEdward Tomasz Napierala struct stat sb; 6583f5ac575SEdward Tomasz Napierala size_t bufsize; 6593f5ac575SEdward Tomasz Napierala void *buf; 6603f5ac575SEdward Tomasz Napierala ssize_t nbytes; 6613f5ac575SEdward Tomasz Napierala int error, fd; 6623f5ac575SEdward Tomasz Napierala 6633f5ac575SEdward Tomasz Napierala fd = open(path, O_RDONLY); 6643f5ac575SEdward Tomasz Napierala if (fd < 0) { 6653f5ac575SEdward Tomasz Napierala emergency("%s: %s", path, strerror(errno)); 6663f5ac575SEdward Tomasz Napierala return (-1); 6673f5ac575SEdward Tomasz Napierala } 6683f5ac575SEdward Tomasz Napierala 6693f5ac575SEdward Tomasz Napierala error = fstat(fd, &sb); 6703f5ac575SEdward Tomasz Napierala if (error != 0) { 6713f5ac575SEdward Tomasz Napierala emergency("fstat: %s", strerror(errno)); 672b9124fc3SEdward Tomasz Napierala close(fd); 6733f5ac575SEdward Tomasz Napierala return (error); 6743f5ac575SEdward Tomasz Napierala } 6753f5ac575SEdward Tomasz Napierala 6763f5ac575SEdward Tomasz Napierala bufsize = sb.st_size; 6773f5ac575SEdward Tomasz Napierala buf = malloc(bufsize); 6783f5ac575SEdward Tomasz Napierala if (buf == NULL) { 6793f5ac575SEdward Tomasz Napierala emergency("malloc: %s", strerror(errno)); 680b9124fc3SEdward Tomasz Napierala close(fd); 6813f5ac575SEdward Tomasz Napierala return (error); 6823f5ac575SEdward Tomasz Napierala } 6833f5ac575SEdward Tomasz Napierala 6843f5ac575SEdward Tomasz Napierala nbytes = read(fd, buf, bufsize); 6853f5ac575SEdward Tomasz Napierala if (nbytes != (ssize_t)bufsize) { 6863f5ac575SEdward Tomasz Napierala emergency("read: %s", strerror(errno)); 687b9124fc3SEdward Tomasz Napierala close(fd); 6883f5ac575SEdward Tomasz Napierala free(buf); 6893f5ac575SEdward Tomasz Napierala return (error); 6903f5ac575SEdward Tomasz Napierala } 6913f5ac575SEdward Tomasz Napierala 6923f5ac575SEdward Tomasz Napierala error = close(fd); 6933f5ac575SEdward Tomasz Napierala if (error != 0) { 6943f5ac575SEdward Tomasz Napierala emergency("close: %s", strerror(errno)); 6953f5ac575SEdward Tomasz Napierala free(buf); 6963f5ac575SEdward Tomasz Napierala return (error); 6973f5ac575SEdward Tomasz Napierala } 6983f5ac575SEdward Tomasz Napierala 6993f5ac575SEdward Tomasz Napierala *bufp = buf; 7003f5ac575SEdward Tomasz Napierala *bufsizep = bufsize; 7013f5ac575SEdward Tomasz Napierala 7023f5ac575SEdward Tomasz Napierala return (0); 7033f5ac575SEdward Tomasz Napierala } 7043f5ac575SEdward Tomasz Napierala 7053f5ac575SEdward Tomasz Napierala static int 706b9124fc3SEdward Tomasz Napierala create_file(const char *path, const void *buf, size_t bufsize) 7073f5ac575SEdward Tomasz Napierala { 7083f5ac575SEdward Tomasz Napierala ssize_t nbytes; 7093f5ac575SEdward Tomasz Napierala int error, fd; 7103f5ac575SEdward Tomasz Napierala 7113f5ac575SEdward Tomasz Napierala fd = open(path, O_WRONLY | O_CREAT | O_EXCL, 0700); 7123f5ac575SEdward Tomasz Napierala if (fd < 0) { 7133f5ac575SEdward Tomasz Napierala emergency("%s: %s", path, strerror(errno)); 7143f5ac575SEdward Tomasz Napierala return (-1); 7153f5ac575SEdward Tomasz Napierala } 7163f5ac575SEdward Tomasz Napierala 7173f5ac575SEdward Tomasz Napierala nbytes = write(fd, buf, bufsize); 7183f5ac575SEdward Tomasz Napierala if (nbytes != (ssize_t)bufsize) { 7193f5ac575SEdward Tomasz Napierala emergency("write: %s", strerror(errno)); 720b9124fc3SEdward Tomasz Napierala close(fd); 7213f5ac575SEdward Tomasz Napierala return (-1); 7223f5ac575SEdward Tomasz Napierala } 7233f5ac575SEdward Tomasz Napierala 7243f5ac575SEdward Tomasz Napierala error = close(fd); 7253f5ac575SEdward Tomasz Napierala if (error != 0) { 7263f5ac575SEdward Tomasz Napierala emergency("close: %s", strerror(errno)); 7273f5ac575SEdward Tomasz Napierala return (-1); 7283f5ac575SEdward Tomasz Napierala } 7293f5ac575SEdward Tomasz Napierala 7303f5ac575SEdward Tomasz Napierala return (0); 7313f5ac575SEdward Tomasz Napierala } 7323f5ac575SEdward Tomasz Napierala 7333f5ac575SEdward Tomasz Napierala static int 7343f5ac575SEdward Tomasz Napierala mount_tmpfs(const char *fspath) 7353f5ac575SEdward Tomasz Napierala { 7363f5ac575SEdward Tomasz Napierala struct iovec *iov; 7373f5ac575SEdward Tomasz Napierala char errmsg[255]; 7383f5ac575SEdward Tomasz Napierala int error, iovlen; 7393f5ac575SEdward Tomasz Napierala 7403f5ac575SEdward Tomasz Napierala iov = NULL; 7413f5ac575SEdward Tomasz Napierala iovlen = 0; 7423f5ac575SEdward Tomasz Napierala memset(errmsg, 0, sizeof(errmsg)); 7433f5ac575SEdward Tomasz Napierala build_iovec(&iov, &iovlen, "fstype", 7443f5ac575SEdward Tomasz Napierala __DECONST(void *, "tmpfs"), (size_t)-1); 7453f5ac575SEdward Tomasz Napierala build_iovec(&iov, &iovlen, "fspath", 7463f5ac575SEdward Tomasz Napierala __DECONST(void *, fspath), (size_t)-1); 7473f5ac575SEdward Tomasz Napierala build_iovec(&iov, &iovlen, "errmsg", 7483f5ac575SEdward Tomasz Napierala errmsg, sizeof(errmsg)); 7493f5ac575SEdward Tomasz Napierala 7503f5ac575SEdward Tomasz Napierala error = nmount(iov, iovlen, 0); 7513f5ac575SEdward Tomasz Napierala if (error != 0) { 7523f5ac575SEdward Tomasz Napierala if (*errmsg != '\0') { 7533f5ac575SEdward Tomasz Napierala emergency("cannot mount tmpfs on %s: %s: %s", 7543f5ac575SEdward Tomasz Napierala fspath, errmsg, strerror(errno)); 7553f5ac575SEdward Tomasz Napierala } else { 7563f5ac575SEdward Tomasz Napierala emergency("cannot mount tmpfs on %s: %s", 7573f5ac575SEdward Tomasz Napierala fspath, strerror(errno)); 7583f5ac575SEdward Tomasz Napierala } 7593f5ac575SEdward Tomasz Napierala return (error); 7603f5ac575SEdward Tomasz Napierala } 7613f5ac575SEdward Tomasz Napierala return (0); 7623f5ac575SEdward Tomasz Napierala } 7633f5ac575SEdward Tomasz Napierala 7643f5ac575SEdward Tomasz Napierala static state_func_t 7653f5ac575SEdward Tomasz Napierala reroot(void) 7663f5ac575SEdward Tomasz Napierala { 7673f5ac575SEdward Tomasz Napierala void *buf; 768377b6d1eSEdward Tomasz Napierala size_t bufsize; 769377b6d1eSEdward Tomasz Napierala int error; 7703f5ac575SEdward Tomasz Napierala 771b9124fc3SEdward Tomasz Napierala buf = NULL; 772b9124fc3SEdward Tomasz Napierala bufsize = 0; 773b9124fc3SEdward Tomasz Napierala 7743f5ac575SEdward Tomasz Napierala revoke_ttys(); 7753f5ac575SEdward Tomasz Napierala runshutdown(); 7763f5ac575SEdward Tomasz Napierala 7773f5ac575SEdward Tomasz Napierala /* 7783f5ac575SEdward Tomasz Napierala * Make sure nobody can interfere with our scheme. 779126ba219SEdward Tomasz Napierala * Ignore ESRCH, which can apparently happen when 780126ba219SEdward Tomasz Napierala * there are no processes to kill. 7813f5ac575SEdward Tomasz Napierala */ 7823f5ac575SEdward Tomasz Napierala error = kill(-1, SIGKILL); 783126ba219SEdward Tomasz Napierala if (error != 0 && errno != ESRCH) { 7843f5ac575SEdward Tomasz Napierala emergency("kill(2) failed: %s", strerror(errno)); 7853f5ac575SEdward Tomasz Napierala goto out; 7863f5ac575SEdward Tomasz Napierala } 7873f5ac575SEdward Tomasz Napierala 7883f5ac575SEdward Tomasz Napierala /* 7893f5ac575SEdward Tomasz Napierala * Copy the init binary into tmpfs, so that we can unmount 7903f5ac575SEdward Tomasz Napierala * the old rootfs without committing suicide. 7913f5ac575SEdward Tomasz Napierala */ 792377b6d1eSEdward Tomasz Napierala error = read_file(init_path_argv0, &buf, &bufsize); 7933f5ac575SEdward Tomasz Napierala if (error != 0) 7943f5ac575SEdward Tomasz Napierala goto out; 7953f5ac575SEdward Tomasz Napierala error = mount_tmpfs(_PATH_REROOT); 7963f5ac575SEdward Tomasz Napierala if (error != 0) 7973f5ac575SEdward Tomasz Napierala goto out; 7983f5ac575SEdward Tomasz Napierala error = create_file(_PATH_REROOT_INIT, buf, bufsize); 7993f5ac575SEdward Tomasz Napierala if (error != 0) 8003f5ac575SEdward Tomasz Napierala goto out; 8013f5ac575SEdward Tomasz Napierala 8023f5ac575SEdward Tomasz Napierala /* 8033f5ac575SEdward Tomasz Napierala * Execute the temporary init. 8043f5ac575SEdward Tomasz Napierala */ 8053f5ac575SEdward Tomasz Napierala execl(_PATH_REROOT_INIT, _PATH_REROOT_INIT, "-r", NULL); 8063f5ac575SEdward Tomasz Napierala emergency("cannot exec %s: %s", _PATH_REROOT_INIT, strerror(errno)); 8073f5ac575SEdward Tomasz Napierala 8083f5ac575SEdward Tomasz Napierala out: 8093f5ac575SEdward Tomasz Napierala emergency("reroot failed; going to single user mode"); 810b9124fc3SEdward Tomasz Napierala free(buf); 8113f5ac575SEdward Tomasz Napierala return (state_func_t) single_user; 8123f5ac575SEdward Tomasz Napierala } 8133f5ac575SEdward Tomasz Napierala 8143f5ac575SEdward Tomasz Napierala static state_func_t 8153f5ac575SEdward Tomasz Napierala reroot_phase_two(void) 8163f5ac575SEdward Tomasz Napierala { 8173f5ac575SEdward Tomasz Napierala char init_path[PATH_MAX], *path, *path_component; 8183f5ac575SEdward Tomasz Napierala size_t init_path_len; 8193f5ac575SEdward Tomasz Napierala int nbytes, error; 8203f5ac575SEdward Tomasz Napierala 8213f5ac575SEdward Tomasz Napierala /* 8223f5ac575SEdward Tomasz Napierala * Ask the kernel to mount the new rootfs. 8233f5ac575SEdward Tomasz Napierala */ 8243f5ac575SEdward Tomasz Napierala error = reboot(RB_REROOT); 8253f5ac575SEdward Tomasz Napierala if (error != 0) { 8263f5ac575SEdward Tomasz Napierala emergency("RB_REBOOT failed: %s", strerror(errno)); 8273f5ac575SEdward Tomasz Napierala goto out; 8283f5ac575SEdward Tomasz Napierala } 8293f5ac575SEdward Tomasz Napierala 8303f5ac575SEdward Tomasz Napierala /* 8313f5ac575SEdward Tomasz Napierala * Figure out where the destination init(8) binary is. Note that 8323f5ac575SEdward Tomasz Napierala * the path could be different than what we've started with. Use 8333f5ac575SEdward Tomasz Napierala * the value from kenv, if set, or the one from sysctl otherwise. 8343f5ac575SEdward Tomasz Napierala * The latter defaults to a hardcoded value, but can be overridden 8353f5ac575SEdward Tomasz Napierala * by a build time option. 8363f5ac575SEdward Tomasz Napierala */ 8373f5ac575SEdward Tomasz Napierala nbytes = kenv(KENV_GET, "init_path", init_path, sizeof(init_path)); 8383f5ac575SEdward Tomasz Napierala if (nbytes <= 0) { 8393f5ac575SEdward Tomasz Napierala init_path_len = sizeof(init_path); 8403f5ac575SEdward Tomasz Napierala error = sysctlbyname("kern.init_path", 8413f5ac575SEdward Tomasz Napierala init_path, &init_path_len, NULL, 0); 8423f5ac575SEdward Tomasz Napierala if (error != 0) { 8433f5ac575SEdward Tomasz Napierala emergency("failed to retrieve kern.init_path: %s", 8443f5ac575SEdward Tomasz Napierala strerror(errno)); 8453f5ac575SEdward Tomasz Napierala goto out; 8463f5ac575SEdward Tomasz Napierala } 8473f5ac575SEdward Tomasz Napierala } 8483f5ac575SEdward Tomasz Napierala 8493f5ac575SEdward Tomasz Napierala /* 8503f5ac575SEdward Tomasz Napierala * Repeat the init search logic from sys/kern/init_path.c 8513f5ac575SEdward Tomasz Napierala */ 8523f5ac575SEdward Tomasz Napierala path_component = init_path; 8533f5ac575SEdward Tomasz Napierala while ((path = strsep(&path_component, ":")) != NULL) { 8543f5ac575SEdward Tomasz Napierala /* 8553f5ac575SEdward Tomasz Napierala * Execute init(8) from the new rootfs. 8563f5ac575SEdward Tomasz Napierala */ 8573f5ac575SEdward Tomasz Napierala execl(path, path, NULL); 8583f5ac575SEdward Tomasz Napierala } 8593f5ac575SEdward Tomasz Napierala emergency("cannot exec init from %s: %s", init_path, strerror(errno)); 8603f5ac575SEdward Tomasz Napierala 8613f5ac575SEdward Tomasz Napierala out: 8623f5ac575SEdward Tomasz Napierala emergency("reroot failed; going to single user mode"); 8633f5ac575SEdward Tomasz Napierala return (state_func_t) single_user; 8643f5ac575SEdward Tomasz Napierala } 8653f5ac575SEdward Tomasz Napierala 8668fae3551SRodney W. Grimes /* 8678fae3551SRodney W. Grimes * Bring the system up single user. 8688fae3551SRodney W. Grimes */ 86945cfb1dcSXin LI static state_func_t 87073bf18edSWarner Losh single_user(void) 8718fae3551SRodney W. Grimes { 8728fae3551SRodney W. Grimes pid_t pid, wpid; 8738fae3551SRodney W. Grimes int status; 8748fae3551SRodney W. Grimes sigset_t mask; 8751a7bec91SWarner Losh const char *shell; 8768fae3551SRodney W. Grimes char *argv[2]; 8778402d33aSKonstantin Belousov struct timeval tv, tn; 8788fae3551SRodney W. Grimes #ifdef SECURE 8798fae3551SRodney W. Grimes struct ttyent *typ; 8808fae3551SRodney W. Grimes struct passwd *pp; 8818fae3551SRodney W. Grimes static const char banner[] = 8828fae3551SRodney W. Grimes "Enter root password, or ^D to go multi-user\n"; 8838fae3551SRodney W. Grimes char *clear, *password; 8848fae3551SRodney W. Grimes #endif 88563322c28SPoul-Henning Kamp #ifdef DEBUGSHELL 88663322c28SPoul-Henning Kamp char altshell[128]; 88763322c28SPoul-Henning Kamp #endif 8888fae3551SRodney W. Grimes 889db8ad19dSJordan K. Hubbard if (Reboot) { 890a0a549c7SRuslan Ermilov /* Instead of going single user, let's reboot the machine */ 891e460cfd3SNate Williams sync(); 892e10037dfSKonstantin Belousov if (reboot(howto) == -1) { 893e10037dfSKonstantin Belousov emergency("reboot(%#x) failed, %s", howto, 894e10037dfSKonstantin Belousov strerror(errno)); 895e10037dfSKonstantin Belousov _exit(1); /* panic and reboot */ 896e10037dfSKonstantin Belousov } 897e10037dfSKonstantin Belousov warning("reboot(%#x) returned", howto); 898e10037dfSKonstantin Belousov _exit(0); /* panic as well */ 899e460cfd3SNate Williams } 900e460cfd3SNate Williams 9011a7bec91SWarner Losh shell = get_shell(); 9021a7bec91SWarner Losh 9038fae3551SRodney W. Grimes if ((pid = fork()) == 0) { 9048fae3551SRodney W. Grimes /* 9058fae3551SRodney W. Grimes * Start the single user session. 9068fae3551SRodney W. Grimes */ 9074c2c7b2cSEd Schouten open_console(); 9088fae3551SRodney W. Grimes 9098fae3551SRodney W. Grimes #ifdef SECURE 9108fae3551SRodney W. Grimes /* 9118fae3551SRodney W. Grimes * Check the root password. 9128fae3551SRodney W. Grimes * We don't care if the console is 'on' by default; 9138fae3551SRodney W. Grimes * it's the only tty that can be 'off' and 'secure'. 9148fae3551SRodney W. Grimes */ 9158fae3551SRodney W. Grimes typ = getttynam("console"); 9168fae3551SRodney W. Grimes pp = getpwnam("root"); 917a69497d7SMatthew Dillon if (typ && (typ->ty_status & TTY_SECURE) == 0 && 918a69497d7SMatthew Dillon pp && *pp->pw_passwd) { 9191a7bec91SWarner Losh write_stderr(banner); 9208fae3551SRodney W. Grimes for (;;) { 9218fae3551SRodney W. Grimes clear = getpass("Password:"); 9222ef6931aSMarcelo Araujo if (clear == NULL || *clear == '\0') 9238fae3551SRodney W. Grimes _exit(0); 9248fae3551SRodney W. Grimes password = crypt(clear, pp->pw_passwd); 9258fae3551SRodney W. Grimes bzero(clear, _PASSWORD_LEN); 9262c9a33f5SConrad Meyer if (password != NULL && 92729dcf726SKevin Lo strcmp(password, pp->pw_passwd) == 0) 9288fae3551SRodney W. Grimes break; 9298fae3551SRodney W. Grimes warning("single-user login failed\n"); 9308fae3551SRodney W. Grimes } 9318fae3551SRodney W. Grimes } 9328fae3551SRodney W. Grimes endttyent(); 9338fae3551SRodney W. Grimes endpwent(); 9348fae3551SRodney W. Grimes #endif /* SECURE */ 9358fae3551SRodney W. Grimes 9368fae3551SRodney W. Grimes #ifdef DEBUGSHELL 9378fae3551SRodney W. Grimes { 93863322c28SPoul-Henning Kamp char *cp = altshell; 9398fae3551SRodney W. Grimes int num; 9408fae3551SRodney W. Grimes 9411a7bec91SWarner Losh #define SHREQUEST "Enter full pathname of shell or RETURN for " 9421a7bec91SWarner Losh write_stderr(SHREQUEST); 9431a7bec91SWarner Losh write_stderr(shell); 9441a7bec91SWarner Losh write_stderr(": "); 9458fae3551SRodney W. Grimes while ((num = read(STDIN_FILENO, cp, 1)) != -1 && 9468fae3551SRodney W. Grimes num != 0 && *cp != '\n' && cp < &altshell[127]) 9478fae3551SRodney W. Grimes cp++; 9488fae3551SRodney W. Grimes *cp = '\0'; 9498fae3551SRodney W. Grimes if (altshell[0] != '\0') 9508fae3551SRodney W. Grimes shell = altshell; 9518fae3551SRodney W. Grimes } 9528fae3551SRodney W. Grimes #endif /* DEBUGSHELL */ 9538fae3551SRodney W. Grimes 9548fae3551SRodney W. Grimes /* 9558fae3551SRodney W. Grimes * Unblock signals. 9568fae3551SRodney W. Grimes * We catch all the interesting ones, 9578fae3551SRodney W. Grimes * and those are reset to SIG_DFL on exec. 9588fae3551SRodney W. Grimes */ 9598fae3551SRodney W. Grimes sigemptyset(&mask); 9608fae3551SRodney W. Grimes sigprocmask(SIG_SETMASK, &mask, (sigset_t *) 0); 9618fae3551SRodney W. Grimes 9628fae3551SRodney W. Grimes /* 9638fae3551SRodney W. Grimes * Fire off a shell. 9648fae3551SRodney W. Grimes * If the default one doesn't work, try the Bourne shell. 9658fae3551SRodney W. Grimes */ 966ab03e6d5SXin LI 967ab03e6d5SXin LI char name[] = "-sh"; 968ab03e6d5SXin LI 969ab03e6d5SXin LI argv[0] = name; 9708fae3551SRodney W. Grimes argv[1] = 0; 9718fae3551SRodney W. Grimes execv(shell, argv); 9728fae3551SRodney W. Grimes emergency("can't exec %s for single user: %m", shell); 9738fae3551SRodney W. Grimes execv(_PATH_BSHELL, argv); 9748fae3551SRodney W. Grimes emergency("can't exec %s for single user: %m", _PATH_BSHELL); 9758fae3551SRodney W. Grimes sleep(STALL_TIMEOUT); 9768fae3551SRodney W. Grimes _exit(1); 9778fae3551SRodney W. Grimes } 9788fae3551SRodney W. Grimes 9798fae3551SRodney W. Grimes if (pid == -1) { 9808fae3551SRodney W. Grimes /* 9818fae3551SRodney W. Grimes * We are seriously hosed. Do our best. 9828fae3551SRodney W. Grimes */ 9838fae3551SRodney W. Grimes emergency("can't fork single-user shell, trying again"); 9848fae3551SRodney W. Grimes while (waitpid(-1, (int *) 0, WNOHANG) > 0) 9858fae3551SRodney W. Grimes continue; 9868fae3551SRodney W. Grimes return (state_func_t) single_user; 9878fae3551SRodney W. Grimes } 9888fae3551SRodney W. Grimes 9898fae3551SRodney W. Grimes requested_transition = 0; 9908fae3551SRodney W. Grimes do { 9918fae3551SRodney W. Grimes if ((wpid = waitpid(-1, &status, WUNTRACED)) != -1) 9928fae3551SRodney W. Grimes collect_child(wpid); 9938fae3551SRodney W. Grimes if (wpid == -1) { 9948fae3551SRodney W. Grimes if (errno == EINTR) 9958fae3551SRodney W. Grimes continue; 9968fae3551SRodney W. Grimes warning("wait for single-user shell failed: %m; restarting"); 9978fae3551SRodney W. Grimes return (state_func_t) single_user; 9988fae3551SRodney W. Grimes } 9998fae3551SRodney W. Grimes if (wpid == pid && WIFSTOPPED(status)) { 10008fae3551SRodney W. Grimes warning("init: shell stopped, restarting\n"); 10018fae3551SRodney W. Grimes kill(pid, SIGCONT); 10028fae3551SRodney W. Grimes wpid = -1; 10038fae3551SRodney W. Grimes } 10048fae3551SRodney W. Grimes } while (wpid != pid && !requested_transition); 10058fae3551SRodney W. Grimes 10068fae3551SRodney W. Grimes if (requested_transition) 10078fae3551SRodney W. Grimes return (state_func_t) requested_transition; 10088fae3551SRodney W. Grimes 10098fae3551SRodney W. Grimes if (!WIFEXITED(status)) { 10108fae3551SRodney W. Grimes if (WTERMSIG(status) == SIGKILL) { 10118fae3551SRodney W. Grimes /* 10128fae3551SRodney W. Grimes * reboot(8) killed shell? 10138fae3551SRodney W. Grimes */ 10148fae3551SRodney W. Grimes warning("single user shell terminated."); 10158402d33aSKonstantin Belousov gettimeofday(&tv, NULL); 10168402d33aSKonstantin Belousov tn = tv; 10178402d33aSKonstantin Belousov tv.tv_sec += STALL_TIMEOUT; 10188402d33aSKonstantin Belousov while (tv.tv_sec > tn.tv_sec || (tv.tv_sec == 10198402d33aSKonstantin Belousov tn.tv_sec && tv.tv_usec > tn.tv_usec)) { 10208402d33aSKonstantin Belousov sleep(1); 10218402d33aSKonstantin Belousov gettimeofday(&tn, NULL); 10228402d33aSKonstantin Belousov } 10238fae3551SRodney W. Grimes _exit(0); 10248fae3551SRodney W. Grimes } else { 10258fae3551SRodney W. Grimes warning("single user shell terminated, restarting"); 10268fae3551SRodney W. Grimes return (state_func_t) single_user; 10278fae3551SRodney W. Grimes } 10288fae3551SRodney W. Grimes } 10298fae3551SRodney W. Grimes 10308fae3551SRodney W. Grimes runcom_mode = FASTBOOT; 10318fae3551SRodney W. Grimes return (state_func_t) runcom; 10328fae3551SRodney W. Grimes } 10338fae3551SRodney W. Grimes 10348fae3551SRodney W. Grimes /* 10358fae3551SRodney W. Grimes * Run the system startup script. 10368fae3551SRodney W. Grimes */ 103745cfb1dcSXin LI static state_func_t 103873bf18edSWarner Losh runcom(void) 10398fae3551SRodney W. Grimes { 10401a7bec91SWarner Losh state_func_t next_transition; 10411a7bec91SWarner Losh 10422ef6931aSMarcelo Araujo if ((next_transition = run_script(_PATH_RUNCOM)) != NULL) 10431a7bec91SWarner Losh return next_transition; 10441a7bec91SWarner Losh 10451a7bec91SWarner Losh runcom_mode = AUTOBOOT; /* the default */ 10461a7bec91SWarner Losh return (state_func_t) read_ttys; 10471a7bec91SWarner Losh } 10481a7bec91SWarner Losh 10491a7bec91SWarner Losh /* 10501a7bec91SWarner Losh * Run a shell script. 10511a7bec91SWarner Losh * Returns 0 on success, otherwise the next transition to enter: 10521a7bec91SWarner Losh * - single_user if fork/execv/waitpid failed, or if the script 10531a7bec91SWarner Losh * terminated with a signal or exit code != 0. 1054acf0ab06SJilles Tjoelker * - death_single if a SIGTERM was delivered to init(8). 10551a7bec91SWarner Losh */ 105645cfb1dcSXin LI static state_func_t 10571a7bec91SWarner Losh run_script(const char *script) 10581a7bec91SWarner Losh { 10598fae3551SRodney W. Grimes pid_t pid, wpid; 10608fae3551SRodney W. Grimes int status; 10618fae3551SRodney W. Grimes char *argv[4]; 10621a7bec91SWarner Losh const char *shell; 10638fae3551SRodney W. Grimes struct sigaction sa; 10648fae3551SRodney W. Grimes 10651a7bec91SWarner Losh shell = get_shell(); 10661a7bec91SWarner Losh 10678fae3551SRodney W. Grimes if ((pid = fork()) == 0) { 10688fae3551SRodney W. Grimes sigemptyset(&sa.sa_mask); 10698fae3551SRodney W. Grimes sa.sa_flags = 0; 10708fae3551SRodney W. Grimes sa.sa_handler = SIG_IGN; 1071091abe40SDavid E. O'Brien sigaction(SIGTSTP, &sa, (struct sigaction *)0); 1072091abe40SDavid E. O'Brien sigaction(SIGHUP, &sa, (struct sigaction *)0); 10738fae3551SRodney W. Grimes 10744c2c7b2cSEd Schouten open_console(); 10758fae3551SRodney W. Grimes 1076ab03e6d5SXin LI char _sh[] = "sh"; 1077ab03e6d5SXin LI char _autoboot[] = "autoboot"; 1078ab03e6d5SXin LI 1079ab03e6d5SXin LI argv[0] = _sh; 10801a7bec91SWarner Losh argv[1] = __DECONST(char *, script); 1081ab03e6d5SXin LI argv[2] = runcom_mode == AUTOBOOT ? _autoboot : 0; 10828fae3551SRodney W. Grimes argv[3] = 0; 10838fae3551SRodney W. Grimes 10848fae3551SRodney W. Grimes sigprocmask(SIG_SETMASK, &sa.sa_mask, (sigset_t *) 0); 10858fae3551SRodney W. Grimes 10861ef60eb1SDavid Nugent #ifdef LOGIN_CAP 10871ef60eb1SDavid Nugent setprocresources(RESOURCE_RC); 10881ef60eb1SDavid Nugent #endif 10891a7bec91SWarner Losh execv(shell, argv); 10901a7bec91SWarner Losh stall("can't exec %s for %s: %m", shell, script); 10918fae3551SRodney W. Grimes _exit(1); /* force single user mode */ 10928fae3551SRodney W. Grimes } 10938fae3551SRodney W. Grimes 10948fae3551SRodney W. Grimes if (pid == -1) { 10951a7bec91SWarner Losh emergency("can't fork for %s on %s: %m", shell, script); 10968fae3551SRodney W. Grimes while (waitpid(-1, (int *) 0, WNOHANG) > 0) 10978fae3551SRodney W. Grimes continue; 10988fae3551SRodney W. Grimes sleep(STALL_TIMEOUT); 10998fae3551SRodney W. Grimes return (state_func_t) single_user; 11008fae3551SRodney W. Grimes } 11018fae3551SRodney W. Grimes 11028fae3551SRodney W. Grimes /* 11038fae3551SRodney W. Grimes * Copied from single_user(). This is a bit paranoid. 11048fae3551SRodney W. Grimes */ 11056e8ff8b7SDag-Erling Smørgrav requested_transition = 0; 11068fae3551SRodney W. Grimes do { 11078fae3551SRodney W. Grimes if ((wpid = waitpid(-1, &status, WUNTRACED)) != -1) 11088fae3551SRodney W. Grimes collect_child(wpid); 11098fae3551SRodney W. Grimes if (wpid == -1) { 11103f5ac575SEdward Tomasz Napierala if (requested_transition == death_single || 11113f5ac575SEdward Tomasz Napierala requested_transition == reroot) 11123f5ac575SEdward Tomasz Napierala return (state_func_t) requested_transition; 11138fae3551SRodney W. Grimes if (errno == EINTR) 11148fae3551SRodney W. Grimes continue; 11151a7bec91SWarner Losh warning("wait for %s on %s failed: %m; going to " 11161a7bec91SWarner Losh "single user mode", shell, script); 11178fae3551SRodney W. Grimes return (state_func_t) single_user; 11188fae3551SRodney W. Grimes } 11198fae3551SRodney W. Grimes if (wpid == pid && WIFSTOPPED(status)) { 11208fae3551SRodney W. Grimes warning("init: %s on %s stopped, restarting\n", 11211a7bec91SWarner Losh shell, script); 11228fae3551SRodney W. Grimes kill(pid, SIGCONT); 11238fae3551SRodney W. Grimes wpid = -1; 11248fae3551SRodney W. Grimes } 11258fae3551SRodney W. Grimes } while (wpid != pid); 11268fae3551SRodney W. Grimes 11278fae3551SRodney W. Grimes if (WIFSIGNALED(status) && WTERMSIG(status) == SIGTERM && 11288fae3551SRodney W. Grimes requested_transition == catatonia) { 11298fae3551SRodney W. Grimes /* /etc/rc executed /sbin/reboot; wait for the end quietly */ 11308fae3551SRodney W. Grimes sigset_t s; 11318fae3551SRodney W. Grimes 11328fae3551SRodney W. Grimes sigfillset(&s); 11338fae3551SRodney W. Grimes for (;;) 11348fae3551SRodney W. Grimes sigsuspend(&s); 11358fae3551SRodney W. Grimes } 11368fae3551SRodney W. Grimes 11378fae3551SRodney W. Grimes if (!WIFEXITED(status)) { 11381a7bec91SWarner Losh warning("%s on %s terminated abnormally, going to single " 11391a7bec91SWarner Losh "user mode", shell, script); 11408fae3551SRodney W. Grimes return (state_func_t) single_user; 11418fae3551SRodney W. Grimes } 11428fae3551SRodney W. Grimes 11438fae3551SRodney W. Grimes if (WEXITSTATUS(status)) 11448fae3551SRodney W. Grimes return (state_func_t) single_user; 11458fae3551SRodney W. Grimes 11461a7bec91SWarner Losh return (state_func_t) 0; 11478fae3551SRodney W. Grimes } 11488fae3551SRodney W. Grimes 11498fae3551SRodney W. Grimes /* 11508fae3551SRodney W. Grimes * Open the session database. 11518fae3551SRodney W. Grimes * 11528fae3551SRodney W. Grimes * NB: We could pass in the size here; is it necessary? 11538fae3551SRodney W. Grimes */ 115445cfb1dcSXin LI static int 115573bf18edSWarner Losh start_session_db(void) 11568fae3551SRodney W. Grimes { 11578fae3551SRodney W. Grimes if (session_db && (*session_db->close)(session_db)) 11588fae3551SRodney W. Grimes emergency("session database close: %s", strerror(errno)); 115914adaa14SMarcelo Araujo if ((session_db = dbopen(NULL, O_RDWR, 0, DB_HASH, NULL)) == NULL) { 11608fae3551SRodney W. Grimes emergency("session database open: %s", strerror(errno)); 11618fae3551SRodney W. Grimes return (1); 11628fae3551SRodney W. Grimes } 11638fae3551SRodney W. Grimes return (0); 11648fae3551SRodney W. Grimes 11658fae3551SRodney W. Grimes } 11668fae3551SRodney W. Grimes 11678fae3551SRodney W. Grimes /* 11688fae3551SRodney W. Grimes * Add a new login session. 11698fae3551SRodney W. Grimes */ 117045cfb1dcSXin LI static void 117173bf18edSWarner Losh add_session(session_t *sp) 11728fae3551SRodney W. Grimes { 11738fae3551SRodney W. Grimes DBT key; 11748fae3551SRodney W. Grimes DBT data; 11758fae3551SRodney W. Grimes 11768fae3551SRodney W. Grimes key.data = &sp->se_process; 11778fae3551SRodney W. Grimes key.size = sizeof sp->se_process; 11788fae3551SRodney W. Grimes data.data = &sp; 11798fae3551SRodney W. Grimes data.size = sizeof sp; 11808fae3551SRodney W. Grimes 11818fae3551SRodney W. Grimes if ((*session_db->put)(session_db, &key, &data, 0)) 11828fae3551SRodney W. Grimes emergency("insert %d: %s", sp->se_process, strerror(errno)); 11838fae3551SRodney W. Grimes } 11848fae3551SRodney W. Grimes 11858fae3551SRodney W. Grimes /* 11868fae3551SRodney W. Grimes * Delete an old login session. 11878fae3551SRodney W. Grimes */ 118845cfb1dcSXin LI static void 118973bf18edSWarner Losh del_session(session_t *sp) 11908fae3551SRodney W. Grimes { 11918fae3551SRodney W. Grimes DBT key; 11928fae3551SRodney W. Grimes 11938fae3551SRodney W. Grimes key.data = &sp->se_process; 11948fae3551SRodney W. Grimes key.size = sizeof sp->se_process; 11958fae3551SRodney W. Grimes 11968fae3551SRodney W. Grimes if ((*session_db->del)(session_db, &key, 0)) 11978fae3551SRodney W. Grimes emergency("delete %d: %s", sp->se_process, strerror(errno)); 11988fae3551SRodney W. Grimes } 11998fae3551SRodney W. Grimes 12008fae3551SRodney W. Grimes /* 12018fae3551SRodney W. Grimes * Look up a login session by pid. 12028fae3551SRodney W. Grimes */ 120345cfb1dcSXin LI static session_t * 12048fae3551SRodney W. Grimes find_session(pid_t pid) 12058fae3551SRodney W. Grimes { 12068fae3551SRodney W. Grimes DBT key; 12078fae3551SRodney W. Grimes DBT data; 12088fae3551SRodney W. Grimes session_t *ret; 12098fae3551SRodney W. Grimes 12108fae3551SRodney W. Grimes key.data = &pid; 12118fae3551SRodney W. Grimes key.size = sizeof pid; 12128fae3551SRodney W. Grimes if ((*session_db->get)(session_db, &key, &data, 0) != 0) 12138fae3551SRodney W. Grimes return 0; 12148fae3551SRodney W. Grimes bcopy(data.data, (char *)&ret, sizeof(ret)); 12158fae3551SRodney W. Grimes return ret; 12168fae3551SRodney W. Grimes } 12178fae3551SRodney W. Grimes 12188fae3551SRodney W. Grimes /* 12198fae3551SRodney W. Grimes * Construct an argument vector from a command line. 12208fae3551SRodney W. Grimes */ 122145cfb1dcSXin LI static char ** 122273bf18edSWarner Losh construct_argv(char *command) 12238fae3551SRodney W. Grimes { 12243d438ad6SDavid E. O'Brien int argc = 0; 12253d438ad6SDavid E. O'Brien char **argv = (char **) malloc(((strlen(command) + 1) / 2 + 1) 12268fae3551SRodney W. Grimes * sizeof (char *)); 12278fae3551SRodney W. Grimes 12282ef6931aSMarcelo Araujo if ((argv[argc++] = strk(command)) == NULL) { 12296be40c95SRuslan Ermilov free(argv); 12306be40c95SRuslan Ermilov return (NULL); 12316be40c95SRuslan Ermilov } 12328889c700SDavid Nugent while ((argv[argc++] = strk((char *) 0)) != NULL) 12338fae3551SRodney W. Grimes continue; 12348fae3551SRodney W. Grimes return argv; 12358fae3551SRodney W. Grimes } 12368fae3551SRodney W. Grimes 12378fae3551SRodney W. Grimes /* 12388fae3551SRodney W. Grimes * Deallocate a session descriptor. 12398fae3551SRodney W. Grimes */ 124045cfb1dcSXin LI static void 124173bf18edSWarner Losh free_session(session_t *sp) 12428fae3551SRodney W. Grimes { 12438fae3551SRodney W. Grimes free(sp->se_device); 12448fae3551SRodney W. Grimes if (sp->se_getty) { 12458fae3551SRodney W. Grimes free(sp->se_getty); 1246b5df27e2SAndrey A. Chernov free(sp->se_getty_argv_space); 12478fae3551SRodney W. Grimes free(sp->se_getty_argv); 12488fae3551SRodney W. Grimes } 12498fae3551SRodney W. Grimes if (sp->se_window) { 12508fae3551SRodney W. Grimes free(sp->se_window); 1251b5df27e2SAndrey A. Chernov free(sp->se_window_argv_space); 12528fae3551SRodney W. Grimes free(sp->se_window_argv); 12538fae3551SRodney W. Grimes } 1254b5df27e2SAndrey A. Chernov if (sp->se_type) 1255b5df27e2SAndrey A. Chernov free(sp->se_type); 12568fae3551SRodney W. Grimes free(sp); 12578fae3551SRodney W. Grimes } 12588fae3551SRodney W. Grimes 12598fae3551SRodney W. Grimes /* 12608fae3551SRodney W. Grimes * Allocate a new session descriptor. 1261b0b670eeSAlfred Perlstein * Mark it SE_PRESENT. 12628fae3551SRodney W. Grimes */ 126345cfb1dcSXin LI static session_t * 12640b57dd6bSJilles Tjoelker new_session(session_t *sprev, struct ttyent *typ) 12658fae3551SRodney W. Grimes { 12663d438ad6SDavid E. O'Brien session_t *sp; 12678fae3551SRodney W. Grimes 12688fae3551SRodney W. Grimes if ((typ->ty_status & TTY_ON) == 0 || 12698fae3551SRodney W. Grimes typ->ty_name == 0 || 12708fae3551SRodney W. Grimes typ->ty_getty == 0) 12718fae3551SRodney W. Grimes return 0; 12728fae3551SRodney W. Grimes 12731054bb1eSAndrey A. Chernov sp = (session_t *) calloc(1, sizeof (session_t)); 12748fae3551SRodney W. Grimes 1275b0b670eeSAlfred Perlstein sp->se_flags |= SE_PRESENT; 12768fae3551SRodney W. Grimes 1277*1cde387cSEdward Tomasz Napierala if ((typ->ty_status & TTY_IFEXISTS) != 0) 1278*1cde387cSEdward Tomasz Napierala sp->se_flags |= SE_IFEXISTS; 1279*1cde387cSEdward Tomasz Napierala 1280*1cde387cSEdward Tomasz Napierala if ((typ->ty_status & TTY_IFCONSOLE) != 0) 1281*1cde387cSEdward Tomasz Napierala sp->se_flags |= SE_IFCONSOLE; 1282*1cde387cSEdward Tomasz Napierala 128395595f99SXin LI if (asprintf(&sp->se_device, "%s%s", _PATH_DEV, typ->ty_name) < 0) 128495595f99SXin LI err(1, "asprintf"); 12858fae3551SRodney W. Grimes 12868fae3551SRodney W. Grimes if (setupargv(sp, typ) == 0) { 12878fae3551SRodney W. Grimes free_session(sp); 12888fae3551SRodney W. Grimes return (0); 12898fae3551SRodney W. Grimes } 12908fae3551SRodney W. Grimes 12918fae3551SRodney W. Grimes sp->se_next = 0; 129214adaa14SMarcelo Araujo if (sprev == NULL) { 12938fae3551SRodney W. Grimes sessions = sp; 12948fae3551SRodney W. Grimes sp->se_prev = 0; 12958fae3551SRodney W. Grimes } else { 12968fae3551SRodney W. Grimes sprev->se_next = sp; 12978fae3551SRodney W. Grimes sp->se_prev = sprev; 12988fae3551SRodney W. Grimes } 12998fae3551SRodney W. Grimes 13008fae3551SRodney W. Grimes return sp; 13018fae3551SRodney W. Grimes } 13028fae3551SRodney W. Grimes 13038fae3551SRodney W. Grimes /* 13048fae3551SRodney W. Grimes * Calculate getty and if useful window argv vectors. 13058fae3551SRodney W. Grimes */ 130645cfb1dcSXin LI static int 130773bf18edSWarner Losh setupargv(session_t *sp, struct ttyent *typ) 13088fae3551SRodney W. Grimes { 13098fae3551SRodney W. Grimes 13108fae3551SRodney W. Grimes if (sp->se_getty) { 13118fae3551SRodney W. Grimes free(sp->se_getty); 1312b5df27e2SAndrey A. Chernov free(sp->se_getty_argv_space); 13138fae3551SRodney W. Grimes free(sp->se_getty_argv); 13148fae3551SRodney W. Grimes } 131595595f99SXin LI if (asprintf(&sp->se_getty, "%s %s", typ->ty_getty, typ->ty_name) < 0) 131695595f99SXin LI err(1, "asprintf"); 1317b5df27e2SAndrey A. Chernov sp->se_getty_argv_space = strdup(sp->se_getty); 1318b5df27e2SAndrey A. Chernov sp->se_getty_argv = construct_argv(sp->se_getty_argv_space); 131914adaa14SMarcelo Araujo if (sp->se_getty_argv == NULL) { 13208fae3551SRodney W. Grimes warning("can't parse getty for port %s", sp->se_device); 13218fae3551SRodney W. Grimes free(sp->se_getty); 1322b5df27e2SAndrey A. Chernov free(sp->se_getty_argv_space); 1323b5df27e2SAndrey A. Chernov sp->se_getty = sp->se_getty_argv_space = 0; 13248fae3551SRodney W. Grimes return (0); 13258fae3551SRodney W. Grimes } 1326b5df27e2SAndrey A. Chernov if (sp->se_window) { 13278fae3551SRodney W. Grimes free(sp->se_window); 1328b5df27e2SAndrey A. Chernov free(sp->se_window_argv_space); 1329b5df27e2SAndrey A. Chernov free(sp->se_window_argv); 1330b5df27e2SAndrey A. Chernov } 1331b5df27e2SAndrey A. Chernov sp->se_window = sp->se_window_argv_space = 0; 1332b5df27e2SAndrey A. Chernov sp->se_window_argv = 0; 1333b5df27e2SAndrey A. Chernov if (typ->ty_window) { 13348fae3551SRodney W. Grimes sp->se_window = strdup(typ->ty_window); 1335b5df27e2SAndrey A. Chernov sp->se_window_argv_space = strdup(sp->se_window); 1336b5df27e2SAndrey A. Chernov sp->se_window_argv = construct_argv(sp->se_window_argv_space); 133714adaa14SMarcelo Araujo if (sp->se_window_argv == NULL) { 13388fae3551SRodney W. Grimes warning("can't parse window for port %s", 13398fae3551SRodney W. Grimes sp->se_device); 1340b5df27e2SAndrey A. Chernov free(sp->se_window_argv_space); 13418fae3551SRodney W. Grimes free(sp->se_window); 1342b5df27e2SAndrey A. Chernov sp->se_window = sp->se_window_argv_space = 0; 13438fae3551SRodney W. Grimes return (0); 13448fae3551SRodney W. Grimes } 13458fae3551SRodney W. Grimes } 1346b5df27e2SAndrey A. Chernov if (sp->se_type) 1347b5df27e2SAndrey A. Chernov free(sp->se_type); 1348b5df27e2SAndrey A. Chernov sp->se_type = typ->ty_type ? strdup(typ->ty_type) : 0; 13498fae3551SRodney W. Grimes return (1); 13508fae3551SRodney W. Grimes } 13518fae3551SRodney W. Grimes 13528fae3551SRodney W. Grimes /* 13538fae3551SRodney W. Grimes * Walk the list of ttys and create sessions for each active line. 13548fae3551SRodney W. Grimes */ 135545cfb1dcSXin LI static state_func_t 135673bf18edSWarner Losh read_ttys(void) 13578fae3551SRodney W. Grimes { 13583d438ad6SDavid E. O'Brien session_t *sp, *snext; 13593d438ad6SDavid E. O'Brien struct ttyent *typ; 13608fae3551SRodney W. Grimes 13618fae3551SRodney W. Grimes /* 13628fae3551SRodney W. Grimes * Destroy any previous session state. 13638fae3551SRodney W. Grimes * There shouldn't be any, but just in case... 13648fae3551SRodney W. Grimes */ 13658fae3551SRodney W. Grimes for (sp = sessions; sp; sp = snext) { 13668fae3551SRodney W. Grimes snext = sp->se_next; 13678fae3551SRodney W. Grimes free_session(sp); 13688fae3551SRodney W. Grimes } 13698fae3551SRodney W. Grimes sessions = 0; 13708fae3551SRodney W. Grimes if (start_session_db()) 13718fae3551SRodney W. Grimes return (state_func_t) single_user; 13728fae3551SRodney W. Grimes 13738fae3551SRodney W. Grimes /* 13748fae3551SRodney W. Grimes * Allocate a session entry for each active port. 13758fae3551SRodney W. Grimes * Note that sp starts at 0. 13768fae3551SRodney W. Grimes */ 13778889c700SDavid Nugent while ((typ = getttyent()) != NULL) 13780b57dd6bSJilles Tjoelker if ((snext = new_session(sp, typ)) != NULL) 13798fae3551SRodney W. Grimes sp = snext; 13808fae3551SRodney W. Grimes 13818fae3551SRodney W. Grimes endttyent(); 13828fae3551SRodney W. Grimes 13838fae3551SRodney W. Grimes return (state_func_t) multi_user; 13848fae3551SRodney W. Grimes } 13858fae3551SRodney W. Grimes 13868fae3551SRodney W. Grimes /* 13878fae3551SRodney W. Grimes * Start a window system running. 13888fae3551SRodney W. Grimes */ 138945cfb1dcSXin LI static void 139073bf18edSWarner Losh start_window_system(session_t *sp) 13918fae3551SRodney W. Grimes { 13928fae3551SRodney W. Grimes pid_t pid; 13938fae3551SRodney W. Grimes sigset_t mask; 1394b5df27e2SAndrey A. Chernov char term[64], *env[2]; 13955010c3b6SKonstantin Belousov int status; 13968fae3551SRodney W. Grimes 13978fae3551SRodney W. Grimes if ((pid = fork()) == -1) { 13988fae3551SRodney W. Grimes emergency("can't fork for window system on port %s: %m", 13998fae3551SRodney W. Grimes sp->se_device); 14008fae3551SRodney W. Grimes /* hope that getty fails and we can try again */ 14018fae3551SRodney W. Grimes return; 14028fae3551SRodney W. Grimes } 1403091abe40SDavid E. O'Brien if (pid) { 14045010c3b6SKonstantin Belousov waitpid(-1, &status, 0); 14058fae3551SRodney W. Grimes return; 14065010c3b6SKonstantin Belousov } 14075010c3b6SKonstantin Belousov 14085010c3b6SKonstantin Belousov /* reparent window process to the init to not make a zombie on exit */ 14095010c3b6SKonstantin Belousov if ((pid = fork()) == -1) { 14105010c3b6SKonstantin Belousov emergency("can't fork for window system on port %s: %m", 14115010c3b6SKonstantin Belousov sp->se_device); 14125010c3b6SKonstantin Belousov _exit(1); 14135010c3b6SKonstantin Belousov } 14145010c3b6SKonstantin Belousov if (pid) 14155010c3b6SKonstantin Belousov _exit(0); 14168fae3551SRodney W. Grimes 14178fae3551SRodney W. Grimes sigemptyset(&mask); 14188fae3551SRodney W. Grimes sigprocmask(SIG_SETMASK, &mask, (sigset_t *) 0); 14198fae3551SRodney W. Grimes 14208fae3551SRodney W. Grimes if (setsid() < 0) 14218fae3551SRodney W. Grimes emergency("setsid failed (window) %m"); 14228fae3551SRodney W. Grimes 14231ef60eb1SDavid Nugent #ifdef LOGIN_CAP 14241ef60eb1SDavid Nugent setprocresources(RESOURCE_WINDOW); 14251ef60eb1SDavid Nugent #endif 1426b5df27e2SAndrey A. Chernov if (sp->se_type) { 1427b5df27e2SAndrey A. Chernov /* Don't use malloc after fork */ 1428b5df27e2SAndrey A. Chernov strcpy(term, "TERM="); 142995595f99SXin LI strlcat(term, sp->se_type, sizeof(term)); 1430b5df27e2SAndrey A. Chernov env[0] = term; 1431b5df27e2SAndrey A. Chernov env[1] = 0; 1432b5df27e2SAndrey A. Chernov } 1433b5df27e2SAndrey A. Chernov else 1434b5df27e2SAndrey A. Chernov env[0] = 0; 1435b5df27e2SAndrey A. Chernov execve(sp->se_window_argv[0], sp->se_window_argv, env); 14368fae3551SRodney W. Grimes stall("can't exec window system '%s' for port %s: %m", 14378fae3551SRodney W. Grimes sp->se_window_argv[0], sp->se_device); 14388fae3551SRodney W. Grimes _exit(1); 14398fae3551SRodney W. Grimes } 14408fae3551SRodney W. Grimes 14418fae3551SRodney W. Grimes /* 14428fae3551SRodney W. Grimes * Start a login session running. 14438fae3551SRodney W. Grimes */ 144445cfb1dcSXin LI static pid_t 144573bf18edSWarner Losh start_getty(session_t *sp) 14468fae3551SRodney W. Grimes { 14478fae3551SRodney W. Grimes pid_t pid; 14488fae3551SRodney W. Grimes sigset_t mask; 14498fae3551SRodney W. Grimes time_t current_time = time((time_t *) 0); 1450228d7ef2SAndrey A. Chernov int too_quick = 0; 1451b5df27e2SAndrey A. Chernov char term[64], *env[2]; 14528fae3551SRodney W. Grimes 1453bb2e87c4SMike Pritchard if (current_time >= sp->se_started && 1454228d7ef2SAndrey A. Chernov current_time - sp->se_started < GETTY_SPACING) { 1455228d7ef2SAndrey A. Chernov if (++sp->se_nspace > GETTY_NSPACE) { 1456228d7ef2SAndrey A. Chernov sp->se_nspace = 0; 1457228d7ef2SAndrey A. Chernov too_quick = 1; 1458228d7ef2SAndrey A. Chernov } 1459228d7ef2SAndrey A. Chernov } else 1460228d7ef2SAndrey A. Chernov sp->se_nspace = 0; 1461228d7ef2SAndrey A. Chernov 14628fae3551SRodney W. Grimes /* 14638fae3551SRodney W. Grimes * fork(), not vfork() -- we can't afford to block. 14648fae3551SRodney W. Grimes */ 14658fae3551SRodney W. Grimes if ((pid = fork()) == -1) { 14668fae3551SRodney W. Grimes emergency("can't fork for getty on port %s: %m", sp->se_device); 14678fae3551SRodney W. Grimes return -1; 14688fae3551SRodney W. Grimes } 14698fae3551SRodney W. Grimes 14708fae3551SRodney W. Grimes if (pid) 14718fae3551SRodney W. Grimes return pid; 14728fae3551SRodney W. Grimes 1473228d7ef2SAndrey A. Chernov if (too_quick) { 1474b5df27e2SAndrey A. Chernov warning("getty repeating too quickly on port %s, sleeping %d secs", 1475b5df27e2SAndrey A. Chernov sp->se_device, GETTY_SLEEP); 14768fae3551SRodney W. Grimes sleep((unsigned) GETTY_SLEEP); 14778fae3551SRodney W. Grimes } 14788fae3551SRodney W. Grimes 14798fae3551SRodney W. Grimes if (sp->se_window) { 14808fae3551SRodney W. Grimes start_window_system(sp); 14818fae3551SRodney W. Grimes sleep(WINDOW_WAIT); 14828fae3551SRodney W. Grimes } 14838fae3551SRodney W. Grimes 14848fae3551SRodney W. Grimes sigemptyset(&mask); 14858fae3551SRodney W. Grimes sigprocmask(SIG_SETMASK, &mask, (sigset_t *) 0); 14868fae3551SRodney W. Grimes 14871ef60eb1SDavid Nugent #ifdef LOGIN_CAP 14881ef60eb1SDavid Nugent setprocresources(RESOURCE_GETTY); 14891ef60eb1SDavid Nugent #endif 1490b5df27e2SAndrey A. Chernov if (sp->se_type) { 1491b5df27e2SAndrey A. Chernov /* Don't use malloc after fork */ 1492b5df27e2SAndrey A. Chernov strcpy(term, "TERM="); 149395595f99SXin LI strlcat(term, sp->se_type, sizeof(term)); 1494b5df27e2SAndrey A. Chernov env[0] = term; 1495b5df27e2SAndrey A. Chernov env[1] = 0; 1496091abe40SDavid E. O'Brien } else 1497b5df27e2SAndrey A. Chernov env[0] = 0; 1498b5df27e2SAndrey A. Chernov execve(sp->se_getty_argv[0], sp->se_getty_argv, env); 14998fae3551SRodney W. Grimes stall("can't exec getty '%s' for port %s: %m", 15008fae3551SRodney W. Grimes sp->se_getty_argv[0], sp->se_device); 15018fae3551SRodney W. Grimes _exit(1); 15028fae3551SRodney W. Grimes } 15038fae3551SRodney W. Grimes 15048fae3551SRodney W. Grimes /* 1505*1cde387cSEdward Tomasz Napierala * Return 1 if the session is defined as "onifexists" 1506*1cde387cSEdward Tomasz Napierala * or "onifconsole" and the device node does not exist. 1507*1cde387cSEdward Tomasz Napierala */ 1508*1cde387cSEdward Tomasz Napierala static int 1509*1cde387cSEdward Tomasz Napierala session_has_no_tty(session_t *sp) 1510*1cde387cSEdward Tomasz Napierala { 1511*1cde387cSEdward Tomasz Napierala int fd; 1512*1cde387cSEdward Tomasz Napierala 1513*1cde387cSEdward Tomasz Napierala if ((sp->se_flags & SE_IFEXISTS) == 0 && 1514*1cde387cSEdward Tomasz Napierala (sp->se_flags & SE_IFCONSOLE) == 0) 1515*1cde387cSEdward Tomasz Napierala return (0); 1516*1cde387cSEdward Tomasz Napierala 1517*1cde387cSEdward Tomasz Napierala fd = open(sp->se_device, O_RDONLY | O_NONBLOCK, 0); 1518*1cde387cSEdward Tomasz Napierala if (fd < 0) { 1519*1cde387cSEdward Tomasz Napierala if (errno == ENOENT) 1520*1cde387cSEdward Tomasz Napierala return (1); 1521*1cde387cSEdward Tomasz Napierala return (0); 1522*1cde387cSEdward Tomasz Napierala } 1523*1cde387cSEdward Tomasz Napierala 1524*1cde387cSEdward Tomasz Napierala close(fd); 1525*1cde387cSEdward Tomasz Napierala return (0); 1526*1cde387cSEdward Tomasz Napierala } 1527*1cde387cSEdward Tomasz Napierala 1528*1cde387cSEdward Tomasz Napierala /* 15298fae3551SRodney W. Grimes * Collect exit status for a child. 15308fae3551SRodney W. Grimes * If an exiting login, start a new login running. 15318fae3551SRodney W. Grimes */ 153245cfb1dcSXin LI static void 15338fae3551SRodney W. Grimes collect_child(pid_t pid) 15348fae3551SRodney W. Grimes { 15353d438ad6SDavid E. O'Brien session_t *sp, *sprev, *snext; 15368fae3551SRodney W. Grimes 15378fae3551SRodney W. Grimes if (! sessions) 15388fae3551SRodney W. Grimes return; 15398fae3551SRodney W. Grimes 15408fae3551SRodney W. Grimes if (! (sp = find_session(pid))) 15418fae3551SRodney W. Grimes return; 15428fae3551SRodney W. Grimes 15438fae3551SRodney W. Grimes del_session(sp); 15448fae3551SRodney W. Grimes sp->se_process = 0; 15458fae3551SRodney W. Grimes 1546*1cde387cSEdward Tomasz Napierala if (sp->se_flags & SE_SHUTDOWN || 1547*1cde387cSEdward Tomasz Napierala session_has_no_tty(sp)) { 15488889c700SDavid Nugent if ((sprev = sp->se_prev) != NULL) 15498fae3551SRodney W. Grimes sprev->se_next = sp->se_next; 15508fae3551SRodney W. Grimes else 15518fae3551SRodney W. Grimes sessions = sp->se_next; 15528889c700SDavid Nugent if ((snext = sp->se_next) != NULL) 15538fae3551SRodney W. Grimes snext->se_prev = sp->se_prev; 15548fae3551SRodney W. Grimes free_session(sp); 15558fae3551SRodney W. Grimes return; 15568fae3551SRodney W. Grimes } 15578fae3551SRodney W. Grimes 15588fae3551SRodney W. Grimes if ((pid = start_getty(sp)) == -1) { 15598fae3551SRodney W. Grimes /* serious trouble */ 15608fae3551SRodney W. Grimes requested_transition = clean_ttys; 15618fae3551SRodney W. Grimes return; 15628fae3551SRodney W. Grimes } 15638fae3551SRodney W. Grimes 15648fae3551SRodney W. Grimes sp->se_process = pid; 15658fae3551SRodney W. Grimes sp->se_started = time((time_t *) 0); 15668fae3551SRodney W. Grimes add_session(sp); 15678fae3551SRodney W. Grimes } 15688fae3551SRodney W. Grimes 15698fae3551SRodney W. Grimes /* 15708fae3551SRodney W. Grimes * Catch a signal and request a state transition. 15718fae3551SRodney W. Grimes */ 157245cfb1dcSXin LI static void 157373bf18edSWarner Losh transition_handler(int sig) 15748fae3551SRodney W. Grimes { 15758fae3551SRodney W. Grimes 15768fae3551SRodney W. Grimes switch (sig) { 15778fae3551SRodney W. Grimes case SIGHUP: 1578acf0ab06SJilles Tjoelker if (current_state == read_ttys || current_state == multi_user || 1579acf0ab06SJilles Tjoelker current_state == clean_ttys || current_state == catatonia) 15808fae3551SRodney W. Grimes requested_transition = clean_ttys; 15818fae3551SRodney W. Grimes break; 158235c1d16eSWarner Losh case SIGWINCH: 1583a0a549c7SRuslan Ermilov case SIGUSR2: 158435c1d16eSWarner Losh howto = sig == SIGUSR2 ? RB_POWEROFF : RB_POWERCYCLE; 1585a0a549c7SRuslan Ermilov case SIGUSR1: 1586a0a549c7SRuslan Ermilov howto |= RB_HALT; 1587e460cfd3SNate Williams case SIGINT: 1588db8ad19dSJordan K. Hubbard Reboot = TRUE; 15898fae3551SRodney W. Grimes case SIGTERM: 1590acf0ab06SJilles Tjoelker if (current_state == read_ttys || current_state == multi_user || 1591acf0ab06SJilles Tjoelker current_state == clean_ttys || current_state == catatonia) 15928fae3551SRodney W. Grimes requested_transition = death; 1593acf0ab06SJilles Tjoelker else 1594acf0ab06SJilles Tjoelker requested_transition = death_single; 15958fae3551SRodney W. Grimes break; 15968fae3551SRodney W. Grimes case SIGTSTP: 1597acf0ab06SJilles Tjoelker if (current_state == runcom || current_state == read_ttys || 1598acf0ab06SJilles Tjoelker current_state == clean_ttys || 1599acf0ab06SJilles Tjoelker current_state == multi_user || current_state == catatonia) 16008fae3551SRodney W. Grimes requested_transition = catatonia; 16018fae3551SRodney W. Grimes break; 16023f5ac575SEdward Tomasz Napierala case SIGEMT: 16033f5ac575SEdward Tomasz Napierala requested_transition = reroot; 16043f5ac575SEdward Tomasz Napierala break; 16058fae3551SRodney W. Grimes default: 16068fae3551SRodney W. Grimes requested_transition = 0; 16078fae3551SRodney W. Grimes break; 16088fae3551SRodney W. Grimes } 16098fae3551SRodney W. Grimes } 16108fae3551SRodney W. Grimes 16118fae3551SRodney W. Grimes /* 16128fae3551SRodney W. Grimes * Take the system multiuser. 16138fae3551SRodney W. Grimes */ 161445cfb1dcSXin LI static state_func_t 161573bf18edSWarner Losh multi_user(void) 16168fae3551SRodney W. Grimes { 16178fae3551SRodney W. Grimes pid_t pid; 16183d438ad6SDavid E. O'Brien session_t *sp; 16198fae3551SRodney W. Grimes 16208fae3551SRodney W. Grimes requested_transition = 0; 16218fae3551SRodney W. Grimes 16228fae3551SRodney W. Grimes /* 16238fae3551SRodney W. Grimes * If the administrator has not set the security level to -1 16248fae3551SRodney W. Grimes * to indicate that the kernel should not run multiuser in secure 16258fae3551SRodney W. Grimes * mode, and the run script has not set a higher level of security 16268fae3551SRodney W. Grimes * than level 1, then put the kernel into secure mode. 16278fae3551SRodney W. Grimes */ 16288fae3551SRodney W. Grimes if (getsecuritylevel() == 0) 16298fae3551SRodney W. Grimes setsecuritylevel(1); 16308fae3551SRodney W. Grimes 16318fae3551SRodney W. Grimes for (sp = sessions; sp; sp = sp->se_next) { 16328fae3551SRodney W. Grimes if (sp->se_process) 16338fae3551SRodney W. Grimes continue; 1634*1cde387cSEdward Tomasz Napierala if (session_has_no_tty(sp)) 1635*1cde387cSEdward Tomasz Napierala continue; 16368fae3551SRodney W. Grimes if ((pid = start_getty(sp)) == -1) { 16378fae3551SRodney W. Grimes /* serious trouble */ 16388fae3551SRodney W. Grimes requested_transition = clean_ttys; 16398fae3551SRodney W. Grimes break; 16408fae3551SRodney W. Grimes } 16418fae3551SRodney W. Grimes sp->se_process = pid; 16428fae3551SRodney W. Grimes sp->se_started = time((time_t *) 0); 16438fae3551SRodney W. Grimes add_session(sp); 16448fae3551SRodney W. Grimes } 16458fae3551SRodney W. Grimes 16468fae3551SRodney W. Grimes while (!requested_transition) 16478fae3551SRodney W. Grimes if ((pid = waitpid(-1, (int *) 0, 0)) != -1) 16488fae3551SRodney W. Grimes collect_child(pid); 16498fae3551SRodney W. Grimes 16508fae3551SRodney W. Grimes return (state_func_t) requested_transition; 16518fae3551SRodney W. Grimes } 16528fae3551SRodney W. Grimes 16538fae3551SRodney W. Grimes /* 1654b0b670eeSAlfred Perlstein * This is an (n*2)+(n^2) algorithm. We hope it isn't run often... 16558fae3551SRodney W. Grimes */ 165645cfb1dcSXin LI static state_func_t 165773bf18edSWarner Losh clean_ttys(void) 16588fae3551SRodney W. Grimes { 16593d438ad6SDavid E. O'Brien session_t *sp, *sprev; 16603d438ad6SDavid E. O'Brien struct ttyent *typ; 16613d438ad6SDavid E. O'Brien int devlen; 1662b5df27e2SAndrey A. Chernov char *old_getty, *old_window, *old_type; 16638fae3551SRodney W. Grimes 1664b0b670eeSAlfred Perlstein /* 1665b0b670eeSAlfred Perlstein * mark all sessions for death, (!SE_PRESENT) 1666b0b670eeSAlfred Perlstein * as we find or create new ones they'll be marked as keepers, 1667b0b670eeSAlfred Perlstein * we'll later nuke all the ones not found in /etc/ttys 1668b0b670eeSAlfred Perlstein */ 1669b0b670eeSAlfred Perlstein for (sp = sessions; sp != NULL; sp = sp->se_next) 1670b0b670eeSAlfred Perlstein sp->se_flags &= ~SE_PRESENT; 1671b0b670eeSAlfred Perlstein 16728fae3551SRodney W. Grimes devlen = sizeof(_PATH_DEV) - 1; 16738889c700SDavid Nugent while ((typ = getttyent()) != NULL) { 16748fae3551SRodney W. Grimes for (sprev = 0, sp = sessions; sp; sprev = sp, sp = sp->se_next) 16758fae3551SRodney W. Grimes if (strcmp(typ->ty_name, sp->se_device + devlen) == 0) 16768fae3551SRodney W. Grimes break; 16778fae3551SRodney W. Grimes 16788fae3551SRodney W. Grimes if (sp) { 1679b0b670eeSAlfred Perlstein /* we want this one to live */ 1680b0b670eeSAlfred Perlstein sp->se_flags |= SE_PRESENT; 16818fae3551SRodney W. Grimes if ((typ->ty_status & TTY_ON) == 0 || 16828fae3551SRodney W. Grimes typ->ty_getty == 0) { 16838fae3551SRodney W. Grimes sp->se_flags |= SE_SHUTDOWN; 16848fae3551SRodney W. Grimes kill(sp->se_process, SIGHUP); 16858fae3551SRodney W. Grimes continue; 16868fae3551SRodney W. Grimes } 16878fae3551SRodney W. Grimes sp->se_flags &= ~SE_SHUTDOWN; 1688b5df27e2SAndrey A. Chernov old_getty = sp->se_getty ? strdup(sp->se_getty) : 0; 1689b5df27e2SAndrey A. Chernov old_window = sp->se_window ? strdup(sp->se_window) : 0; 1690b5df27e2SAndrey A. Chernov old_type = sp->se_type ? strdup(sp->se_type) : 0; 16918fae3551SRodney W. Grimes if (setupargv(sp, typ) == 0) { 16928fae3551SRodney W. Grimes warning("can't parse getty for port %s", 16938fae3551SRodney W. Grimes sp->se_device); 16948fae3551SRodney W. Grimes sp->se_flags |= SE_SHUTDOWN; 16958fae3551SRodney W. Grimes kill(sp->se_process, SIGHUP); 16968fae3551SRodney W. Grimes } 1697b5df27e2SAndrey A. Chernov else if ( !old_getty 16988889c700SDavid Nugent || (!old_type && sp->se_type) 16998889c700SDavid Nugent || (old_type && !sp->se_type) 17008889c700SDavid Nugent || (!old_window && sp->se_window) 17018889c700SDavid Nugent || (old_window && !sp->se_window) 17028889c700SDavid Nugent || (strcmp(old_getty, sp->se_getty) != 0) 17038889c700SDavid Nugent || (old_window && strcmp(old_window, sp->se_window) != 0) 17048889c700SDavid Nugent || (old_type && strcmp(old_type, sp->se_type) != 0) 1705b5df27e2SAndrey A. Chernov ) { 1706b5df27e2SAndrey A. Chernov /* Don't set SE_SHUTDOWN here */ 1707b5df27e2SAndrey A. Chernov sp->se_nspace = 0; 1708b5df27e2SAndrey A. Chernov sp->se_started = 0; 1709b5df27e2SAndrey A. Chernov kill(sp->se_process, SIGHUP); 1710b5df27e2SAndrey A. Chernov } 1711b5df27e2SAndrey A. Chernov if (old_getty) 1712b5df27e2SAndrey A. Chernov free(old_getty); 17132d887af5SMike Heffner if (old_window) 1714b5df27e2SAndrey A. Chernov free(old_window); 1715b5df27e2SAndrey A. Chernov if (old_type) 1716b5df27e2SAndrey A. Chernov free(old_type); 17178fae3551SRodney W. Grimes continue; 17188fae3551SRodney W. Grimes } 17198fae3551SRodney W. Grimes 17200b57dd6bSJilles Tjoelker new_session(sprev, typ); 17218fae3551SRodney W. Grimes } 17228fae3551SRodney W. Grimes 17238fae3551SRodney W. Grimes endttyent(); 17248fae3551SRodney W. Grimes 1725b0b670eeSAlfred Perlstein /* 1726b0b670eeSAlfred Perlstein * sweep through and kill all deleted sessions 1727b0b670eeSAlfred Perlstein * ones who's /etc/ttys line was deleted (SE_PRESENT unset) 1728b0b670eeSAlfred Perlstein */ 1729b0b670eeSAlfred Perlstein for (sp = sessions; sp != NULL; sp = sp->se_next) { 1730b0b670eeSAlfred Perlstein if ((sp->se_flags & SE_PRESENT) == 0) { 1731b0b670eeSAlfred Perlstein sp->se_flags |= SE_SHUTDOWN; 1732b0b670eeSAlfred Perlstein kill(sp->se_process, SIGHUP); 1733b0b670eeSAlfred Perlstein } 1734b0b670eeSAlfred Perlstein } 1735b0b670eeSAlfred Perlstein 17368fae3551SRodney W. Grimes return (state_func_t) multi_user; 17378fae3551SRodney W. Grimes } 17388fae3551SRodney W. Grimes 17398fae3551SRodney W. Grimes /* 17408fae3551SRodney W. Grimes * Block further logins. 17418fae3551SRodney W. Grimes */ 174245cfb1dcSXin LI static state_func_t 174373bf18edSWarner Losh catatonia(void) 17448fae3551SRodney W. Grimes { 17453d438ad6SDavid E. O'Brien session_t *sp; 17468fae3551SRodney W. Grimes 17478fae3551SRodney W. Grimes for (sp = sessions; sp; sp = sp->se_next) 17488fae3551SRodney W. Grimes sp->se_flags |= SE_SHUTDOWN; 17498fae3551SRodney W. Grimes 17508fae3551SRodney W. Grimes return (state_func_t) multi_user; 17518fae3551SRodney W. Grimes } 17528fae3551SRodney W. Grimes 17538fae3551SRodney W. Grimes /* 17548fae3551SRodney W. Grimes * Note SIGALRM. 17558fae3551SRodney W. Grimes */ 175645cfb1dcSXin LI static void 175773bf18edSWarner Losh alrm_handler(int sig) 17588fae3551SRodney W. Grimes { 1759091abe40SDavid E. O'Brien 17608889c700SDavid Nugent (void)sig; 17618fae3551SRodney W. Grimes clang = 1; 17628fae3551SRodney W. Grimes } 17638fae3551SRodney W. Grimes 17648fae3551SRodney W. Grimes /* 17658fae3551SRodney W. Grimes * Bring the system down to single user. 17668fae3551SRodney W. Grimes */ 176745cfb1dcSXin LI static state_func_t 176873bf18edSWarner Losh death(void) 17698fae3551SRodney W. Grimes { 17702eb0015aSColin Percival int block, blocked; 17712eb0015aSColin Percival size_t len; 17722eb0015aSColin Percival 17732eb0015aSColin Percival /* Temporarily block suspend. */ 17742eb0015aSColin Percival len = sizeof(blocked); 17752eb0015aSColin Percival block = 1; 17762eb0015aSColin Percival if (sysctlbyname("kern.suspend_blocked", &blocked, &len, 17772eb0015aSColin Percival &block, sizeof(block)) == -1) 17782eb0015aSColin Percival blocked = 0; 17798fae3551SRodney W. Grimes 17804ae35b5dSEd Schouten /* 17814ae35b5dSEd Schouten * Also revoke the TTY here. Because runshutdown() may reopen 17824ae35b5dSEd Schouten * the TTY whose getty we're killing here, there is no guarantee 17834ae35b5dSEd Schouten * runshutdown() will perform the initial open() call, causing 17844ae35b5dSEd Schouten * the terminal attributes to be misconfigured. 17854ae35b5dSEd Schouten */ 17863f5ac575SEdward Tomasz Napierala revoke_ttys(); 17878fae3551SRodney W. Grimes 17888889c700SDavid Nugent /* Try to run the rc.shutdown script within a period of time */ 1789091abe40SDavid E. O'Brien runshutdown(); 17908889c700SDavid Nugent 17912eb0015aSColin Percival /* Unblock suspend if we blocked it. */ 17922eb0015aSColin Percival if (!blocked) 17932eb0015aSColin Percival sysctlbyname("kern.suspend_blocked", NULL, NULL, 17942eb0015aSColin Percival &blocked, sizeof(blocked)); 17952eb0015aSColin Percival 1796acf0ab06SJilles Tjoelker return (state_func_t) death_single; 1797acf0ab06SJilles Tjoelker } 1798acf0ab06SJilles Tjoelker 1799acf0ab06SJilles Tjoelker /* 1800acf0ab06SJilles Tjoelker * Do what is necessary to reinitialize single user mode or reboot 1801acf0ab06SJilles Tjoelker * from an incomplete state. 1802acf0ab06SJilles Tjoelker */ 1803acf0ab06SJilles Tjoelker static state_func_t 1804acf0ab06SJilles Tjoelker death_single(void) 1805acf0ab06SJilles Tjoelker { 1806acf0ab06SJilles Tjoelker int i; 1807acf0ab06SJilles Tjoelker pid_t pid; 1808acf0ab06SJilles Tjoelker static const int death_sigs[2] = { SIGTERM, SIGKILL }; 1809acf0ab06SJilles Tjoelker 1810acf0ab06SJilles Tjoelker revoke(_PATH_CONSOLE); 1811acf0ab06SJilles Tjoelker 1812c3d7c52eSAndrey A. Chernov for (i = 0; i < 2; ++i) { 18138fae3551SRodney W. Grimes if (kill(-1, death_sigs[i]) == -1 && errno == ESRCH) 18148fae3551SRodney W. Grimes return (state_func_t) single_user; 18158fae3551SRodney W. Grimes 18168fae3551SRodney W. Grimes clang = 0; 18178fae3551SRodney W. Grimes alarm(DEATH_WATCH); 18188fae3551SRodney W. Grimes do 18198fae3551SRodney W. Grimes if ((pid = waitpid(-1, (int *)0, 0)) != -1) 18208fae3551SRodney W. Grimes collect_child(pid); 18218fae3551SRodney W. Grimes while (clang == 0 && errno != ECHILD); 18228fae3551SRodney W. Grimes 18238fae3551SRodney W. Grimes if (errno == ECHILD) 18248fae3551SRodney W. Grimes return (state_func_t) single_user; 18258fae3551SRodney W. Grimes } 18268fae3551SRodney W. Grimes 18278fae3551SRodney W. Grimes warning("some processes would not die; ps axl advised"); 18288fae3551SRodney W. Grimes 18298fae3551SRodney W. Grimes return (state_func_t) single_user; 18308fae3551SRodney W. Grimes } 18318889c700SDavid Nugent 18323f5ac575SEdward Tomasz Napierala static void 18333f5ac575SEdward Tomasz Napierala revoke_ttys(void) 18343f5ac575SEdward Tomasz Napierala { 18353f5ac575SEdward Tomasz Napierala session_t *sp; 18363f5ac575SEdward Tomasz Napierala 18373f5ac575SEdward Tomasz Napierala for (sp = sessions; sp; sp = sp->se_next) { 18383f5ac575SEdward Tomasz Napierala sp->se_flags |= SE_SHUTDOWN; 18393f5ac575SEdward Tomasz Napierala kill(sp->se_process, SIGHUP); 18403f5ac575SEdward Tomasz Napierala revoke(sp->se_device); 18413f5ac575SEdward Tomasz Napierala } 18423f5ac575SEdward Tomasz Napierala } 18433f5ac575SEdward Tomasz Napierala 18448889c700SDavid Nugent /* 18458889c700SDavid Nugent * Run the system shutdown script. 18468889c700SDavid Nugent * 18478889c700SDavid Nugent * Exit codes: XXX I should document more 18488889c700SDavid Nugent * -2 shutdown script terminated abnormally 18498889c700SDavid Nugent * -1 fatal error - can't run script 18508889c700SDavid Nugent * 0 good. 18518889c700SDavid Nugent * >0 some error (exit code) 18528889c700SDavid Nugent */ 185345cfb1dcSXin LI static int 185473bf18edSWarner Losh runshutdown(void) 18558889c700SDavid Nugent { 18568889c700SDavid Nugent pid_t pid, wpid; 18578889c700SDavid Nugent int status; 18588889c700SDavid Nugent int shutdowntimeout; 18598889c700SDavid Nugent size_t len; 1860a69497d7SMatthew Dillon char *argv[4]; 18611a7bec91SWarner Losh const char *shell; 18628889c700SDavid Nugent struct sigaction sa; 186386bf62dcSDavid Nugent struct stat sb; 186486bf62dcSDavid Nugent 186586bf62dcSDavid Nugent /* 186686bf62dcSDavid Nugent * rc.shutdown is optional, so to prevent any unnecessary 186786bf62dcSDavid Nugent * complaints from the shell we simply don't run it if the 186886bf62dcSDavid Nugent * file does not exist. If the stat() here fails for other 186986bf62dcSDavid Nugent * reasons, we'll let the shell complain. 187086bf62dcSDavid Nugent */ 187186bf62dcSDavid Nugent if (stat(_PATH_RUNDOWN, &sb) == -1 && errno == ENOENT) 187286bf62dcSDavid Nugent return 0; 18738889c700SDavid Nugent 18741a7bec91SWarner Losh shell = get_shell(); 18751a7bec91SWarner Losh 18768889c700SDavid Nugent if ((pid = fork()) == 0) { 18778889c700SDavid Nugent sigemptyset(&sa.sa_mask); 18788889c700SDavid Nugent sa.sa_flags = 0; 18798889c700SDavid Nugent sa.sa_handler = SIG_IGN; 1880091abe40SDavid E. O'Brien sigaction(SIGTSTP, &sa, (struct sigaction *)0); 1881091abe40SDavid E. O'Brien sigaction(SIGHUP, &sa, (struct sigaction *)0); 18828889c700SDavid Nugent 18834c2c7b2cSEd Schouten open_console(); 1884ab03e6d5SXin LI 1885ab03e6d5SXin LI char _sh[] = "sh"; 1886ab03e6d5SXin LI char _reboot[] = "reboot"; 1887ab03e6d5SXin LI char _single[] = "single"; 1888ab03e6d5SXin LI char _path_rundown[] = _PATH_RUNDOWN; 1889ab03e6d5SXin LI 1890ab03e6d5SXin LI argv[0] = _sh; 1891ab03e6d5SXin LI argv[1] = _path_rundown; 1892ab03e6d5SXin LI argv[2] = Reboot ? _reboot : _single; 1893a69497d7SMatthew Dillon argv[3] = 0; 18948889c700SDavid Nugent 18958889c700SDavid Nugent sigprocmask(SIG_SETMASK, &sa.sa_mask, (sigset_t *) 0); 18968889c700SDavid Nugent 189725cf4a54SAndrey A. Chernov #ifdef LOGIN_CAP 189825cf4a54SAndrey A. Chernov setprocresources(RESOURCE_RC); 189925cf4a54SAndrey A. Chernov #endif 19001a7bec91SWarner Losh execv(shell, argv); 19011a7bec91SWarner Losh warning("can't exec %s for %s: %m", shell, _PATH_RUNDOWN); 19028889c700SDavid Nugent _exit(1); /* force single user mode */ 19038889c700SDavid Nugent } 19048889c700SDavid Nugent 19058889c700SDavid Nugent if (pid == -1) { 19061a7bec91SWarner Losh emergency("can't fork for %s on %s: %m", shell, _PATH_RUNDOWN); 19078889c700SDavid Nugent while (waitpid(-1, (int *) 0, WNOHANG) > 0) 19088889c700SDavid Nugent continue; 19098889c700SDavid Nugent sleep(STALL_TIMEOUT); 19108889c700SDavid Nugent return -1; 19118889c700SDavid Nugent } 19128889c700SDavid Nugent 19138889c700SDavid Nugent len = sizeof(shutdowntimeout); 1914091abe40SDavid E. O'Brien if (sysctlbyname("kern.init_shutdown_timeout", &shutdowntimeout, &len, 1915091abe40SDavid E. O'Brien NULL, 0) == -1 || shutdowntimeout < 2) 19168889c700SDavid Nugent shutdowntimeout = DEATH_SCRIPT; 19178889c700SDavid Nugent alarm(shutdowntimeout); 19188889c700SDavid Nugent clang = 0; 19198889c700SDavid Nugent /* 19208889c700SDavid Nugent * Copied from single_user(). This is a bit paranoid. 19218889c700SDavid Nugent * Use the same ALRM handler. 19228889c700SDavid Nugent */ 19238889c700SDavid Nugent do { 19248889c700SDavid Nugent if ((wpid = waitpid(-1, &status, WUNTRACED)) != -1) 19258889c700SDavid Nugent collect_child(wpid); 19268889c700SDavid Nugent if (clang == 1) { 19278889c700SDavid Nugent /* we were waiting for the sub-shell */ 19288889c700SDavid Nugent kill(wpid, SIGTERM); 19291a7bec91SWarner Losh warning("timeout expired for %s on %s: %m; going to " 19301a7bec91SWarner Losh "single user mode", shell, _PATH_RUNDOWN); 19318889c700SDavid Nugent return -1; 19328889c700SDavid Nugent } 19338889c700SDavid Nugent if (wpid == -1) { 19348889c700SDavid Nugent if (errno == EINTR) 19358889c700SDavid Nugent continue; 19361a7bec91SWarner Losh warning("wait for %s on %s failed: %m; going to " 19371a7bec91SWarner Losh "single user mode", shell, _PATH_RUNDOWN); 19388889c700SDavid Nugent return -1; 19398889c700SDavid Nugent } 19408889c700SDavid Nugent if (wpid == pid && WIFSTOPPED(status)) { 19418889c700SDavid Nugent warning("init: %s on %s stopped, restarting\n", 19421a7bec91SWarner Losh shell, _PATH_RUNDOWN); 19438889c700SDavid Nugent kill(pid, SIGCONT); 19448889c700SDavid Nugent wpid = -1; 19458889c700SDavid Nugent } 19468889c700SDavid Nugent } while (wpid != pid && !clang); 19478889c700SDavid Nugent 19488889c700SDavid Nugent /* Turn off the alarm */ 19498889c700SDavid Nugent alarm(0); 19508889c700SDavid Nugent 19518889c700SDavid Nugent if (WIFSIGNALED(status) && WTERMSIG(status) == SIGTERM && 19528889c700SDavid Nugent requested_transition == catatonia) { 19538889c700SDavid Nugent /* 19548889c700SDavid Nugent * /etc/rc.shutdown executed /sbin/reboot; 19558889c700SDavid Nugent * wait for the end quietly 19568889c700SDavid Nugent */ 19578889c700SDavid Nugent sigset_t s; 19588889c700SDavid Nugent 19598889c700SDavid Nugent sigfillset(&s); 19608889c700SDavid Nugent for (;;) 19618889c700SDavid Nugent sigsuspend(&s); 19628889c700SDavid Nugent } 19638889c700SDavid Nugent 19648889c700SDavid Nugent if (!WIFEXITED(status)) { 19651a7bec91SWarner Losh warning("%s on %s terminated abnormally, going to " 19661a7bec91SWarner Losh "single user mode", shell, _PATH_RUNDOWN); 19678889c700SDavid Nugent return -2; 19688889c700SDavid Nugent } 19698889c700SDavid Nugent 19708889c700SDavid Nugent if ((status = WEXITSTATUS(status)) != 0) 19718889c700SDavid Nugent warning("%s returned status %d", _PATH_RUNDOWN, status); 19728889c700SDavid Nugent 19738889c700SDavid Nugent return status; 19748889c700SDavid Nugent } 19758889c700SDavid Nugent 1976ab03e6d5SXin LI static char * 197781ab7fb2SAndrey A. Chernov strk(char *p) 197881ab7fb2SAndrey A. Chernov { 197981ab7fb2SAndrey A. Chernov static char *t; 198081ab7fb2SAndrey A. Chernov char *q; 198181ab7fb2SAndrey A. Chernov int c; 198281ab7fb2SAndrey A. Chernov 198381ab7fb2SAndrey A. Chernov if (p) 198481ab7fb2SAndrey A. Chernov t = p; 198581ab7fb2SAndrey A. Chernov if (!t) 198681ab7fb2SAndrey A. Chernov return 0; 198781ab7fb2SAndrey A. Chernov 198881ab7fb2SAndrey A. Chernov c = *t; 198981ab7fb2SAndrey A. Chernov while (c == ' ' || c == '\t' ) 199081ab7fb2SAndrey A. Chernov c = *++t; 199181ab7fb2SAndrey A. Chernov if (!c) { 199281ab7fb2SAndrey A. Chernov t = 0; 199381ab7fb2SAndrey A. Chernov return 0; 199481ab7fb2SAndrey A. Chernov } 199581ab7fb2SAndrey A. Chernov q = t; 199681ab7fb2SAndrey A. Chernov if (c == '\'') { 199781ab7fb2SAndrey A. Chernov c = *++t; 199881ab7fb2SAndrey A. Chernov q = t; 199981ab7fb2SAndrey A. Chernov while (c && c != '\'') 200081ab7fb2SAndrey A. Chernov c = *++t; 200181ab7fb2SAndrey A. Chernov if (!c) /* unterminated string */ 200281ab7fb2SAndrey A. Chernov q = t = 0; 200381ab7fb2SAndrey A. Chernov else 200481ab7fb2SAndrey A. Chernov *t++ = 0; 200581ab7fb2SAndrey A. Chernov } else { 200681ab7fb2SAndrey A. Chernov while (c && c != ' ' && c != '\t' ) 200781ab7fb2SAndrey A. Chernov c = *++t; 200881ab7fb2SAndrey A. Chernov *t++ = 0; 200981ab7fb2SAndrey A. Chernov if (!c) 201081ab7fb2SAndrey A. Chernov t = 0; 201181ab7fb2SAndrey A. Chernov } 201281ab7fb2SAndrey A. Chernov return q; 201381ab7fb2SAndrey A. Chernov } 20141ef60eb1SDavid Nugent 20151ef60eb1SDavid Nugent #ifdef LOGIN_CAP 201645cfb1dcSXin LI static void 201773bf18edSWarner Losh setprocresources(const char *cname) 20181ef60eb1SDavid Nugent { 2019e82d5545SDavid Nugent login_cap_t *lc; 2020a2ee73bcSAndrey A. Chernov if ((lc = login_getclassbyname(cname, NULL)) != NULL) { 2021091abe40SDavid E. O'Brien setusercontext(lc, (struct passwd*)NULL, 0, 2022595ab563SJilles Tjoelker LOGIN_SETPRIORITY | LOGIN_SETRESOURCES | 2023595ab563SJilles Tjoelker LOGIN_SETLOGINCLASS | LOGIN_SETCPUMASK); 20241ef60eb1SDavid Nugent login_close(lc); 20251ef60eb1SDavid Nugent } 20261ef60eb1SDavid Nugent } 20271ef60eb1SDavid Nugent #endif 2028