1 /*-*- Mode: C; c-basic-offset: 8 -*-*/
4 This file is part of systemd.
6 Copyright 2010 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 2 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <sys/types.h>
27 #include <sys/epoll.h>
29 #include <arpa/inet.h>
34 #include "load-dropin.h"
35 #include "load-fragment.h"
37 #include "unit-name.h"
38 #include "dbus-socket.h"
41 #include "bus-errors.h"
43 static const UnitActiveState state_translation_table
[_SOCKET_STATE_MAX
] = {
44 [SOCKET_DEAD
] = UNIT_INACTIVE
,
45 [SOCKET_START_PRE
] = UNIT_ACTIVATING
,
46 [SOCKET_START_POST
] = UNIT_ACTIVATING
,
47 [SOCKET_LISTENING
] = UNIT_ACTIVE
,
48 [SOCKET_RUNNING
] = UNIT_ACTIVE
,
49 [SOCKET_STOP_PRE
] = UNIT_DEACTIVATING
,
50 [SOCKET_STOP_PRE_SIGTERM
] = UNIT_DEACTIVATING
,
51 [SOCKET_STOP_PRE_SIGKILL
] = UNIT_DEACTIVATING
,
52 [SOCKET_STOP_POST
] = UNIT_DEACTIVATING
,
53 [SOCKET_FINAL_SIGTERM
] = UNIT_DEACTIVATING
,
54 [SOCKET_FINAL_SIGKILL
] = UNIT_DEACTIVATING
,
55 [SOCKET_MAINTENANCE
] = UNIT_MAINTENANCE
58 static void socket_init(Unit
*u
) {
59 Socket
*s
= SOCKET(u
);
62 assert(u
->meta
.load_state
== UNIT_STUB
);
64 s
->backlog
= SOMAXCONN
;
65 s
->timeout_usec
= DEFAULT_TIMEOUT_USEC
;
66 s
->directory_mode
= 0755;
67 s
->socket_mode
= 0666;
69 s
->max_connections
= 64;
76 exec_context_init(&s
->exec_context
);
78 s
->control_command_id
= _SOCKET_EXEC_COMMAND_INVALID
;
81 static void socket_unwatch_control_pid(Socket
*s
) {
84 if (s
->control_pid
<= 0)
87 unit_unwatch_pid(UNIT(s
), s
->control_pid
);
91 static void socket_done(Unit
*u
) {
92 Socket
*s
= SOCKET(u
);
98 while ((p
= s
->ports
)) {
99 LIST_REMOVE(SocketPort
, port
, s
->ports
, p
);
102 unit_unwatch_fd(UNIT(s
), &p
->fd_watch
);
103 close_nointr_nofail(p
->fd
);
110 exec_context_done(&s
->exec_context
);
111 exec_command_free_array(s
->exec_command
, _SOCKET_EXEC_COMMAND_MAX
);
112 s
->control_command
= NULL
;
114 socket_unwatch_control_pid(s
);
118 free(s
->bind_to_device
);
119 s
->bind_to_device
= NULL
;
121 unit_unwatch_timer(u
, &s
->timer_watch
);
123 /* Make sure no service instance refers to us anymore. */
124 LIST_FOREACH(units_per_type
, i
, u
->meta
.manager
->units_per_type
[UNIT_SERVICE
]) {
125 Service
*service
= (Service
*) i
;
127 if (service
->socket
== s
)
128 service
->socket
= NULL
;
132 static int socket_instantiate_service(Socket
*s
) {
139 /* This fills in s->service if it isn't filled in yet. For
140 * Accept=yes sockets we create the next connection service
141 * here. For Accept=no this is mostly a NOP since the service
142 * is figured out at load time anyway. */
149 if (!(prefix
= unit_name_to_prefix(s
->meta
.id
)))
152 r
= asprintf(&name
, "%s@%u.service", prefix
, s
->n_accepted
);
158 r
= manager_load_unit(s
->meta
.manager
, name
, NULL
, NULL
, &u
);
164 s
->service
= SERVICE(u
);
168 static bool have_non_accept_socket(Socket
*s
) {
176 LIST_FOREACH(port
, p
, s
->ports
) {
178 if (p
->type
!= SOCKET_SOCKET
)
181 if (!socket_address_can_accept(&p
->address
))
188 static int socket_verify(Socket
*s
) {
191 if (s
->meta
.load_state
!= UNIT_LOADED
)
195 log_error("%s lacks Listen setting. Refusing.", s
->meta
.id
);
199 if (s
->accept
&& have_non_accept_socket(s
)) {
200 log_error("%s configured for accepting sockets, but sockets are non-accepting. Refusing.", s
->meta
.id
);
204 if (s
->accept
&& s
->max_connections
<= 0) {
205 log_error("%s's MaxConnection setting too small. Refusing.", s
->meta
.id
);
209 if (s
->exec_context
.pam_name
&& s
->exec_context
.kill_mode
!= KILL_CONTROL_GROUP
) {
210 log_error("%s has PAM enabled. Kill mode must be set to 'control-group'. Refusing.", s
->meta
.id
);
217 static bool socket_needs_mount(Socket
*s
, const char *prefix
) {
222 LIST_FOREACH(port
, p
, s
->ports
) {
224 if (p
->type
== SOCKET_SOCKET
) {
225 if (socket_address_needs_mount(&p
->address
, prefix
))
228 assert(p
->type
== SOCKET_FIFO
);
229 if (path_startswith(p
->path
, prefix
))
237 int socket_add_one_mount_link(Socket
*s
, Mount
*m
) {
243 if (s
->meta
.load_state
!= UNIT_LOADED
||
244 m
->meta
.load_state
!= UNIT_LOADED
)
247 if (!socket_needs_mount(s
, m
->where
))
250 if ((r
= unit_add_two_dependencies(UNIT(s
), UNIT_AFTER
, UNIT_REQUIRES
, UNIT(m
), true)) < 0)
256 static int socket_add_mount_links(Socket
*s
) {
262 LIST_FOREACH(units_per_type
, other
, s
->meta
.manager
->units_per_type
[UNIT_MOUNT
])
263 if ((r
= socket_add_one_mount_link(s
, (Mount
*) other
)) < 0)
269 static int socket_add_device_link(Socket
*s
) {
275 if (!s
->bind_to_device
)
278 if (asprintf(&t
, "/sys/subsystem/net/devices/%s", s
->bind_to_device
) < 0)
281 r
= unit_add_node_link(UNIT(s
), t
, false);
287 static int socket_add_default_dependencies(Socket
*s
) {
291 if (s
->meta
.manager
->running_as
== MANAGER_SYSTEM
)
292 if ((r
= unit_add_two_dependencies_by_name(UNIT(s
), UNIT_AFTER
, UNIT_REQUIRES
, SPECIAL_SYSINIT_TARGET
, NULL
, true)) < 0)
295 return unit_add_two_dependencies_by_name(UNIT(s
), UNIT_BEFORE
, UNIT_CONFLICTS
, SPECIAL_SHUTDOWN_TARGET
, NULL
, true);
298 static int socket_load(Unit
*u
) {
299 Socket
*s
= SOCKET(u
);
303 assert(u
->meta
.load_state
== UNIT_STUB
);
305 if ((r
= unit_load_fragment_and_dropin(u
)) < 0)
308 /* This is a new unit? Then let's add in some extras */
309 if (u
->meta
.load_state
== UNIT_LOADED
) {
311 if (have_non_accept_socket(s
)) {
312 if ((r
= unit_load_related_unit(u
, ".service", (Unit
**) &s
->service
)) < 0)
315 if ((r
= unit_add_dependency(u
, UNIT_BEFORE
, UNIT(s
->service
), true)) < 0)
319 if ((r
= socket_add_mount_links(s
)) < 0)
322 if ((r
= socket_add_device_link(s
)) < 0)
325 if ((r
= unit_add_exec_dependencies(u
, &s
->exec_context
)) < 0)
328 if ((r
= unit_add_default_cgroup(u
)) < 0)
331 if (s
->meta
.default_dependencies
)
332 if ((r
= socket_add_default_dependencies(s
)) < 0)
336 return socket_verify(s
);
339 static const char* listen_lookup(int type
) {
341 if (type
== SOCK_STREAM
)
342 return "ListenStream";
343 else if (type
== SOCK_DGRAM
)
344 return "ListenDatagram";
345 else if (type
== SOCK_SEQPACKET
)
346 return "ListenSequentialPacket";
348 assert_not_reached("Unknown socket type");
352 static void socket_dump(Unit
*u
, FILE *f
, const char *prefix
) {
355 Socket
*s
= SOCKET(u
);
363 p2
= strappend(prefix
, "\t");
364 prefix2
= p2
? p2
: prefix
;
367 "%sSocket State: %s\n"
368 "%sBindIPv6Only: %s\n"
370 "%sSocketMode: %04o\n"
371 "%sDirectoryMode: %04o\n"
374 prefix
, socket_state_to_string(s
->state
),
375 prefix
, socket_address_bind_ipv6_only_to_string(s
->bind_ipv6_only
),
377 prefix
, s
->socket_mode
,
378 prefix
, s
->directory_mode
,
379 prefix
, yes_no(s
->keep_alive
),
380 prefix
, yes_no(s
->free_bind
));
382 if (s
->control_pid
> 0)
384 "%sControl PID: %lu\n",
385 prefix
, (unsigned long) s
->control_pid
);
387 if (s
->bind_to_device
)
389 "%sBindToDevice: %s\n",
390 prefix
, s
->bind_to_device
);
395 "%sNConnections: %u\n"
396 "%sMaxConnections: %u\n",
397 prefix
, s
->n_accepted
,
398 prefix
, s
->n_connections
,
399 prefix
, s
->max_connections
);
401 if (s
->priority
>= 0)
404 prefix
, s
->priority
);
406 if (s
->receive_buffer
> 0)
408 "%sReceiveBuffer: %zu\n",
409 prefix
, s
->receive_buffer
);
411 if (s
->send_buffer
> 0)
413 "%sSendBuffer: %zu\n",
414 prefix
, s
->send_buffer
);
426 if (s
->pipe_size
> 0)
429 prefix
, s
->pipe_size
);
436 LIST_FOREACH(port
, p
, s
->ports
) {
438 if (p
->type
== SOCKET_SOCKET
) {
443 if ((r
= socket_address_print(&p
->address
, &k
)) < 0)
448 fprintf(f
, "%s%s: %s\n", prefix
, listen_lookup(p
->address
.type
), k
);
451 fprintf(f
, "%sListenFIFO: %s\n", prefix
, p
->path
);
454 exec_context_dump(&s
->exec_context
, f
, prefix
);
456 for (c
= 0; c
< _SOCKET_EXEC_COMMAND_MAX
; c
++) {
457 if (!s
->exec_command
[c
])
460 fprintf(f
, "%s-> %s:\n",
461 prefix
, socket_exec_command_to_string(c
));
463 exec_command_dump_list(s
->exec_command
[c
], f
, prefix2
);
469 static int instance_from_socket(int fd
, unsigned nr
, char **instance
) {
474 struct sockaddr_un un
;
475 struct sockaddr_in in
;
476 struct sockaddr_in6 in6
;
477 struct sockaddr_storage storage
;
484 if (getsockname(fd
, &local
.sa
, &l
) < 0)
488 if (getpeername(fd
, &remote
.sa
, &l
) < 0)
491 switch (local
.sa
.sa_family
) {
495 a
= ntohl(local
.in
.sin_addr
.s_addr
),
496 b
= ntohl(remote
.in
.sin_addr
.s_addr
);
499 "%u.%u.%u.%u:%u-%u.%u.%u.%u:%u",
500 a
>> 24, (a
>> 16) & 0xFF, (a
>> 8) & 0xFF, a
& 0xFF,
501 ntohs(local
.in
.sin_port
),
502 b
>> 24, (b
>> 16) & 0xFF, (b
>> 8) & 0xFF, b
& 0xFF,
503 ntohs(remote
.in
.sin_port
)) < 0)
510 static const char ipv4_prefix
[] = {
511 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0xFF, 0xFF
514 if (memcmp(&local
.in6
.sin6_addr
, ipv4_prefix
, sizeof(ipv4_prefix
)) == 0 &&
515 memcmp(&remote
.in6
.sin6_addr
, ipv4_prefix
, sizeof(ipv4_prefix
)) == 0) {
517 *a
= local
.in6
.sin6_addr
.s6_addr
+12,
518 *b
= remote
.in6
.sin6_addr
.s6_addr
+12;
521 "%u.%u.%u.%u:%u-%u.%u.%u.%u:%u",
522 a
[0], a
[1], a
[2], a
[3],
523 ntohs(local
.in6
.sin6_port
),
524 b
[0], b
[1], b
[2], b
[3],
525 ntohs(remote
.in6
.sin6_port
)) < 0)
528 char a
[INET6_ADDRSTRLEN
], b
[INET6_ADDRSTRLEN
];
532 inet_ntop(AF_INET6
, &local
.in6
.sin6_addr
, a
, sizeof(a
)),
533 ntohs(local
.in6
.sin6_port
),
534 inet_ntop(AF_INET6
, &remote
.in6
.sin6_addr
, b
, sizeof(b
)),
535 ntohs(remote
.in6
.sin6_port
)) < 0)
546 if (getsockopt(fd
, SOL_SOCKET
, SO_PEERCRED
, &ucred
, &l
) < 0)
552 (unsigned long) ucred
.pid
,
553 (unsigned long) ucred
.uid
) < 0)
560 assert_not_reached("Unhandled socket type.");
567 static void socket_close_fds(Socket
*s
) {
572 LIST_FOREACH(port
, p
, s
->ports
) {
576 unit_unwatch_fd(UNIT(s
), &p
->fd_watch
);
577 close_nointr_nofail(p
->fd
);
579 /* One little note: we should never delete any sockets
580 * in the file system here! After all some other
581 * process we spawned might still have a reference of
582 * this fd and wants to continue to use it. Therefore
583 * we delete sockets in the file system before we
584 * create a new one, not after we stopped using
591 static void socket_apply_socket_options(Socket
*s
, int fd
) {
596 int b
= s
->keep_alive
;
597 if (setsockopt(fd
, SOL_SOCKET
, SO_KEEPALIVE
, &b
, sizeof(b
)) < 0)
598 log_warning("SO_KEEPALIVE failed: %m");
601 if (s
->priority
>= 0)
602 if (setsockopt(fd
, SOL_SOCKET
, SO_PRIORITY
, &s
->priority
, sizeof(s
->priority
)) < 0)
603 log_warning("SO_PRIORITY failed: %m");
605 if (s
->receive_buffer
> 0) {
606 int value
= (int) s
->receive_buffer
;
607 if (setsockopt(fd
, SOL_SOCKET
, SO_RCVBUF
, &value
, sizeof(value
)) < 0)
608 log_warning("SO_RCVBUF failed: %m");
611 if (s
->send_buffer
> 0) {
612 int value
= (int) s
->send_buffer
;
613 if (setsockopt(fd
, SOL_SOCKET
, SO_SNDBUF
, &value
, sizeof(value
)) < 0)
614 log_warning("SO_SNDBUF failed: %m");
618 if (setsockopt(fd
, SOL_SOCKET
, SO_MARK
, &s
->mark
, sizeof(s
->mark
)) < 0)
619 log_warning("SO_MARK failed: %m");
622 if (setsockopt(fd
, IPPROTO_IP
, IP_TOS
, &s
->ip_tos
, sizeof(s
->ip_tos
)) < 0)
623 log_warning("IP_TOS failed: %m");
625 if (s
->ip_ttl
>= 0) {
628 r
= setsockopt(fd
, IPPROTO_IP
, IP_TTL
, &s
->ip_ttl
, sizeof(s
->ip_ttl
));
629 x
= setsockopt(fd
, IPPROTO_IPV6
, IPV6_UNICAST_HOPS
, &s
->ip_ttl
, sizeof(s
->ip_ttl
));
632 log_warning("IP_TTL/IPV6_UNICAST_HOPS failed: %m");
636 static void socket_apply_fifo_options(Socket
*s
, int fd
) {
640 if (s
->pipe_size
> 0)
641 if (fcntl(fd
, F_SETPIPE_SZ
, s
->pipe_size
) < 0)
642 log_warning("F_SETPIPE_SZ: %m");
645 static int fifo_address_create(
647 mode_t directory_mode
,
649 /* FIXME SELINUX: pass SELinux context object here */
659 mkdir_parents(path
, directory_mode
);
661 /* FIXME SELINUX: The mkfifo here should be done with
662 * the right SELinux context set */
664 /* Enforce the right access mode for the fifo */
665 old_mask
= umask(~ socket_mode
);
667 /* Include the original umask in our mask */
668 umask(~socket_mode
| old_mask
);
670 r
= mkfifo(path
, socket_mode
);
678 if ((fd
= open(path
, O_RDWR
|O_CLOEXEC
|O_NOCTTY
|O_NONBLOCK
|O_NOFOLLOW
)) < 0) {
683 if (fstat(fd
, &st
) < 0) {
688 if (!S_ISFIFO(st
.st_mode
) ||
689 st
.st_mode
!= (socket_mode
& ~old_mask
) ||
690 st
.st_uid
!= getuid() ||
691 st
.st_gid
!= getgid()) {
702 close_nointr_nofail(fd
);
707 static int socket_open_fds(Socket
*s
) {
713 /* FIXME SELINUX: Somewhere here we must set the the SELinux
714 context for the created sockets and FIFOs. To figure out
715 the executable name for this, use
716 socket_instantiate_service() and then access the executable
718 s->service->exec_command[SERVICE_EXEC_START]->path. Example:
720 if ((r = socket_instantiate_service(s)) < 0)
723 log_debug("Socket unit %s will spawn service unit %s with executable path %s.",
726 s->service->exec_command[SERVICE_EXEC_START]->path);
729 LIST_FOREACH(port
, p
, s
->ports
) {
734 if (p
->type
== SOCKET_SOCKET
) {
736 if ((r
= socket_address_listen(
744 /* FIXME SELINUX: Pass the SELinux context object here */
748 socket_apply_socket_options(s
, p
->fd
);
750 } else if (p
->type
== SOCKET_FIFO
) {
752 if ((r
= fifo_address_create(
756 /* FIXME SELINUX: Pass the SELinux context object here */
760 socket_apply_fifo_options(s
, p
->fd
);
763 assert_not_reached("Unknown port type");
773 static void socket_unwatch_fds(Socket
*s
) {
778 LIST_FOREACH(port
, p
, s
->ports
) {
782 unit_unwatch_fd(UNIT(s
), &p
->fd_watch
);
786 static int socket_watch_fds(Socket
*s
) {
792 LIST_FOREACH(port
, p
, s
->ports
) {
796 p
->fd_watch
.socket_accept
=
798 p
->type
== SOCKET_SOCKET
&&
799 socket_address_can_accept(&p
->address
);
801 if ((r
= unit_watch_fd(UNIT(s
), p
->fd
, EPOLLIN
, &p
->fd_watch
)) < 0)
808 socket_unwatch_fds(s
);
812 static void socket_set_state(Socket
*s
, SocketState state
) {
813 SocketState old_state
;
816 old_state
= s
->state
;
819 if (state
!= SOCKET_START_PRE
&&
820 state
!= SOCKET_START_POST
&&
821 state
!= SOCKET_STOP_PRE
&&
822 state
!= SOCKET_STOP_PRE_SIGTERM
&&
823 state
!= SOCKET_STOP_PRE_SIGKILL
&&
824 state
!= SOCKET_STOP_POST
&&
825 state
!= SOCKET_FINAL_SIGTERM
&&
826 state
!= SOCKET_FINAL_SIGKILL
) {
827 unit_unwatch_timer(UNIT(s
), &s
->timer_watch
);
828 socket_unwatch_control_pid(s
);
829 s
->control_command
= NULL
;
830 s
->control_command_id
= _SOCKET_EXEC_COMMAND_INVALID
;
833 if (state
!= SOCKET_LISTENING
)
834 socket_unwatch_fds(s
);
836 if (state
!= SOCKET_START_POST
&&
837 state
!= SOCKET_LISTENING
&&
838 state
!= SOCKET_RUNNING
&&
839 state
!= SOCKET_STOP_PRE
&&
840 state
!= SOCKET_STOP_PRE_SIGTERM
&&
841 state
!= SOCKET_STOP_PRE_SIGKILL
)
844 if (state
!= old_state
)
845 log_debug("%s changed %s -> %s",
847 socket_state_to_string(old_state
),
848 socket_state_to_string(state
));
850 unit_notify(UNIT(s
), state_translation_table
[old_state
], state_translation_table
[state
]);
853 static int socket_coldplug(Unit
*u
) {
854 Socket
*s
= SOCKET(u
);
858 assert(s
->state
== SOCKET_DEAD
);
860 if (s
->deserialized_state
!= s
->state
) {
862 if (s
->deserialized_state
== SOCKET_START_PRE
||
863 s
->deserialized_state
== SOCKET_START_POST
||
864 s
->deserialized_state
== SOCKET_STOP_PRE
||
865 s
->deserialized_state
== SOCKET_STOP_PRE_SIGTERM
||
866 s
->deserialized_state
== SOCKET_STOP_PRE_SIGKILL
||
867 s
->deserialized_state
== SOCKET_STOP_POST
||
868 s
->deserialized_state
== SOCKET_FINAL_SIGTERM
||
869 s
->deserialized_state
== SOCKET_FINAL_SIGKILL
) {
871 if (s
->control_pid
<= 0)
874 if ((r
= unit_watch_pid(UNIT(s
), s
->control_pid
)) < 0)
877 if ((r
= unit_watch_timer(UNIT(s
), s
->timeout_usec
, &s
->timer_watch
)) < 0)
881 if (s
->deserialized_state
== SOCKET_START_POST
||
882 s
->deserialized_state
== SOCKET_LISTENING
||
883 s
->deserialized_state
== SOCKET_RUNNING
||
884 s
->deserialized_state
== SOCKET_STOP_PRE
||
885 s
->deserialized_state
== SOCKET_STOP_PRE_SIGTERM
||
886 s
->deserialized_state
== SOCKET_STOP_PRE_SIGKILL
)
887 if ((r
= socket_open_fds(s
)) < 0)
890 if (s
->deserialized_state
== SOCKET_LISTENING
)
891 if ((r
= socket_watch_fds(s
)) < 0)
894 socket_set_state(s
, s
->deserialized_state
);
900 static int socket_spawn(Socket
*s
, ExecCommand
*c
, pid_t
*_pid
) {
909 if ((r
= unit_watch_timer(UNIT(s
), s
->timeout_usec
, &s
->timer_watch
)) < 0)
912 if (!(argv
= unit_full_printf_strv(UNIT(s
), c
->argv
))) {
921 s
->meta
.manager
->environment
,
925 s
->meta
.manager
->confirm_spawn
,
926 s
->meta
.cgroup_bondings
,
933 if ((r
= unit_watch_pid(UNIT(s
), pid
)) < 0)
934 /* FIXME: we need to do something here */
942 unit_unwatch_timer(UNIT(s
), &s
->timer_watch
);
947 static void socket_enter_dead(Socket
*s
, bool success
) {
953 socket_set_state(s
, s
->failure
? SOCKET_MAINTENANCE
: SOCKET_DEAD
);
956 static void socket_enter_signal(Socket
*s
, SocketState state
, bool success
);
958 static void socket_enter_stop_post(Socket
*s
, bool success
) {
965 socket_unwatch_control_pid(s
);
967 s
->control_command_id
= SOCKET_EXEC_STOP_POST
;
969 if ((s
->control_command
= s
->exec_command
[SOCKET_EXEC_STOP_POST
])) {
970 if ((r
= socket_spawn(s
, s
->control_command
, &s
->control_pid
)) < 0)
973 socket_set_state(s
, SOCKET_STOP_POST
);
975 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, true);
980 log_warning("%s failed to run 'stop-post' task: %s", s
->meta
.id
, strerror(-r
));
981 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, false);
984 static void socket_enter_signal(Socket
*s
, SocketState state
, bool success
) {
993 if (s
->exec_context
.kill_mode
!= KILL_NONE
) {
994 int sig
= (state
== SOCKET_STOP_PRE_SIGTERM
|| state
== SOCKET_FINAL_SIGTERM
) ? s
->exec_context
.kill_signal
: SIGKILL
;
996 if (s
->exec_context
.kill_mode
== KILL_CONTROL_GROUP
) {
998 if ((r
= cgroup_bonding_kill_list(s
->meta
.cgroup_bondings
, sig
)) < 0) {
999 if (r
!= -EAGAIN
&& r
!= -ESRCH
)
1005 if (!sent
&& s
->control_pid
> 0)
1006 if (kill(s
->exec_context
.kill_mode
== KILL_PROCESS
? s
->control_pid
: -s
->control_pid
, sig
) < 0 && errno
!= ESRCH
) {
1012 if (sent
&& s
->control_pid
> 0) {
1013 if ((r
= unit_watch_timer(UNIT(s
), s
->timeout_usec
, &s
->timer_watch
)) < 0)
1016 socket_set_state(s
, state
);
1017 } else if (state
== SOCKET_STOP_PRE_SIGTERM
|| state
== SOCKET_STOP_PRE_SIGKILL
)
1018 socket_enter_stop_post(s
, true);
1020 socket_enter_dead(s
, true);
1025 log_warning("%s failed to kill processes: %s", s
->meta
.id
, strerror(-r
));
1027 if (state
== SOCKET_STOP_PRE_SIGTERM
|| state
== SOCKET_STOP_PRE_SIGKILL
)
1028 socket_enter_stop_post(s
, false);
1030 socket_enter_dead(s
, false);
1033 static void socket_enter_stop_pre(Socket
*s
, bool success
) {
1040 socket_unwatch_control_pid(s
);
1042 s
->control_command_id
= SOCKET_EXEC_STOP_PRE
;
1044 if ((s
->control_command
= s
->exec_command
[SOCKET_EXEC_STOP_PRE
])) {
1045 if ((r
= socket_spawn(s
, s
->control_command
, &s
->control_pid
)) < 0)
1048 socket_set_state(s
, SOCKET_STOP_PRE
);
1050 socket_enter_stop_post(s
, true);
1055 log_warning("%s failed to run 'stop-pre' task: %s", s
->meta
.id
, strerror(-r
));
1056 socket_enter_stop_post(s
, false);
1059 static void socket_enter_listening(Socket
*s
) {
1063 if ((r
= socket_watch_fds(s
)) < 0) {
1064 log_warning("%s failed to watch sockets: %s", s
->meta
.id
, strerror(-r
));
1068 socket_set_state(s
, SOCKET_LISTENING
);
1072 socket_enter_stop_pre(s
, false);
1075 static void socket_enter_start_post(Socket
*s
) {
1079 if ((r
= socket_open_fds(s
)) < 0) {
1080 log_warning("%s failed to listen on sockets: %s", s
->meta
.id
, strerror(-r
));
1084 socket_unwatch_control_pid(s
);
1086 s
->control_command_id
= SOCKET_EXEC_START_POST
;
1088 if ((s
->control_command
= s
->exec_command
[SOCKET_EXEC_START_POST
])) {
1089 if ((r
= socket_spawn(s
, s
->control_command
, &s
->control_pid
)) < 0) {
1090 log_warning("%s failed to run 'start-post' task: %s", s
->meta
.id
, strerror(-r
));
1094 socket_set_state(s
, SOCKET_START_POST
);
1096 socket_enter_listening(s
);
1101 socket_enter_stop_pre(s
, false);
1104 static void socket_enter_start_pre(Socket
*s
) {
1108 socket_unwatch_control_pid(s
);
1110 s
->control_command_id
= SOCKET_EXEC_START_PRE
;
1112 if ((s
->control_command
= s
->exec_command
[SOCKET_EXEC_START_PRE
])) {
1113 if ((r
= socket_spawn(s
, s
->control_command
, &s
->control_pid
)) < 0)
1116 socket_set_state(s
, SOCKET_START_PRE
);
1118 socket_enter_start_post(s
);
1123 log_warning("%s failed to run 'start-pre' task: %s", s
->meta
.id
, strerror(-r
));
1124 socket_enter_dead(s
, false);
1127 static void socket_enter_running(Socket
*s
, int cfd
) {
1132 dbus_error_init(&error
);
1134 /* We don't take connections anymore if we are supposed to
1135 * shut down anyway */
1136 if (s
->meta
.job
&& s
->meta
.job
->type
== JOB_STOP
) {
1138 close_nointr_nofail(cfd
);
1140 /* Flush all sockets by closing and reopening them */
1141 socket_close_fds(s
);
1143 if ((r
= socket_watch_fds(s
)) < 0) {
1144 log_warning("%s failed to watch sockets: %s", s
->meta
.id
, strerror(-r
));
1145 socket_enter_stop_pre(s
, false);
1153 if ((r
= manager_add_job(s
->meta
.manager
, JOB_START
, UNIT(s
->service
), JOB_REPLACE
, true, &error
, NULL
)) < 0)
1156 socket_set_state(s
, SOCKET_RUNNING
);
1158 char *prefix
, *instance
= NULL
, *name
;
1161 if (s
->n_connections
>= s
->max_connections
) {
1162 log_warning("Too many incoming connections (%u)", s
->n_connections
);
1163 close_nointr_nofail(cfd
);
1167 if ((r
= socket_instantiate_service(s
)) < 0)
1170 if ((r
= instance_from_socket(cfd
, s
->n_accepted
, &instance
)) < 0)
1173 if (!(prefix
= unit_name_to_prefix(s
->meta
.id
))) {
1179 name
= unit_name_build(prefix
, instance
, ".service");
1188 if ((r
= unit_add_name(UNIT(s
->service
), name
)) < 0) {
1193 service
= s
->service
;
1197 unit_choose_id(UNIT(service
), name
);
1200 if ((r
= service_set_socket_fd(service
, cfd
, s
)) < 0)
1204 s
->n_connections
++;
1206 if ((r
= manager_add_job(s
->meta
.manager
, JOB_START
, UNIT(service
), JOB_REPLACE
, true, &error
, NULL
)) < 0)
1213 log_warning("%s failed to queue socket startup job: %s", s
->meta
.id
, bus_error(&error
, r
));
1214 socket_enter_stop_pre(s
, false);
1217 close_nointr_nofail(cfd
);
1219 dbus_error_free(&error
);
1222 static void socket_run_next(Socket
*s
, bool success
) {
1226 assert(s
->control_command
);
1227 assert(s
->control_command
->command_next
);
1232 socket_unwatch_control_pid(s
);
1234 s
->control_command
= s
->control_command
->command_next
;
1236 if ((r
= socket_spawn(s
, s
->control_command
, &s
->control_pid
)) < 0)
1242 log_warning("%s failed to run next task: %s", s
->meta
.id
, strerror(-r
));
1244 if (s
->state
== SOCKET_START_POST
)
1245 socket_enter_stop_pre(s
, false);
1246 else if (s
->state
== SOCKET_STOP_POST
)
1247 socket_enter_dead(s
, false);
1249 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, false);
1252 static int socket_start(Unit
*u
) {
1253 Socket
*s
= SOCKET(u
);
1257 /* We cannot fulfill this request right now, try again later
1259 if (s
->state
== SOCKET_STOP_PRE
||
1260 s
->state
== SOCKET_STOP_PRE_SIGKILL
||
1261 s
->state
== SOCKET_STOP_PRE_SIGTERM
||
1262 s
->state
== SOCKET_STOP_POST
||
1263 s
->state
== SOCKET_FINAL_SIGTERM
||
1264 s
->state
== SOCKET_FINAL_SIGKILL
)
1267 if (s
->state
== SOCKET_START_PRE
||
1268 s
->state
== SOCKET_START_POST
)
1271 /* Cannot run this without the service being around */
1273 if (s
->service
->meta
.load_state
!= UNIT_LOADED
)
1276 /* If the service is alredy actvie we cannot start the
1278 if (s
->service
->state
!= SERVICE_DEAD
&&
1279 s
->service
->state
!= SERVICE_MAINTENANCE
&&
1280 s
->service
->state
!= SERVICE_AUTO_RESTART
)
1284 assert(s
->state
== SOCKET_DEAD
|| s
->state
== SOCKET_MAINTENANCE
);
1287 socket_enter_start_pre(s
);
1291 static int socket_stop(Unit
*u
) {
1292 Socket
*s
= SOCKET(u
);
1297 if (s
->state
== SOCKET_STOP_PRE
||
1298 s
->state
== SOCKET_STOP_PRE_SIGTERM
||
1299 s
->state
== SOCKET_STOP_PRE_SIGKILL
||
1300 s
->state
== SOCKET_STOP_POST
||
1301 s
->state
== SOCKET_FINAL_SIGTERM
||
1302 s
->state
== SOCKET_FINAL_SIGKILL
)
1305 /* If there's already something running we go directly into
1307 if (s
->state
== SOCKET_START_PRE
||
1308 s
->state
== SOCKET_START_POST
) {
1309 socket_enter_signal(s
, SOCKET_STOP_PRE_SIGTERM
, true);
1313 assert(s
->state
== SOCKET_LISTENING
|| s
->state
== SOCKET_RUNNING
);
1315 socket_enter_stop_pre(s
, true);
1319 static int socket_serialize(Unit
*u
, FILE *f
, FDSet
*fds
) {
1320 Socket
*s
= SOCKET(u
);
1328 unit_serialize_item(u
, f
, "state", socket_state_to_string(s
->state
));
1329 unit_serialize_item(u
, f
, "failure", yes_no(s
->failure
));
1330 unit_serialize_item_format(u
, f
, "n-accepted", "%u", s
->n_accepted
);
1332 if (s
->control_pid
> 0)
1333 unit_serialize_item_format(u
, f
, "control-pid", "%lu", (unsigned long) s
->control_pid
);
1335 if (s
->control_command_id
>= 0)
1336 unit_serialize_item(u
, f
, "control-command", socket_exec_command_to_string(s
->control_command_id
));
1338 LIST_FOREACH(port
, p
, s
->ports
) {
1344 if ((copy
= fdset_put_dup(fds
, p
->fd
)) < 0)
1347 if (p
->type
== SOCKET_SOCKET
) {
1350 if ((r
= socket_address_print(&p
->address
, &t
)) < 0)
1353 unit_serialize_item_format(u
, f
, "socket", "%i %i %s", copy
, p
->address
.type
, t
);
1356 assert(p
->type
== SOCKET_FIFO
);
1357 unit_serialize_item_format(u
, f
, "fifo", "%i %s", copy
, p
->path
);
1364 static int socket_deserialize_item(Unit
*u
, const char *key
, const char *value
, FDSet
*fds
) {
1365 Socket
*s
= SOCKET(u
);
1373 if (streq(key
, "state")) {
1376 if ((state
= socket_state_from_string(value
)) < 0)
1377 log_debug("Failed to parse state value %s", value
);
1379 s
->deserialized_state
= state
;
1380 } else if (streq(key
, "failure")) {
1383 if ((b
= parse_boolean(value
)) < 0)
1384 log_debug("Failed to parse failure value %s", value
);
1386 s
->failure
= b
|| s
->failure
;
1388 } else if (streq(key
, "n-accepted")) {
1391 if ((r
= safe_atou(value
, &k
)) < 0)
1392 log_debug("Failed to parse n-accepted value %s", value
);
1395 } else if (streq(key
, "control-pid")) {
1398 if ((r
= parse_pid(value
, &pid
)) < 0)
1399 log_debug("Failed to parse control-pid value %s", value
);
1401 s
->control_pid
= pid
;
1402 } else if (streq(key
, "control-command")) {
1403 SocketExecCommand id
;
1405 if ((id
= socket_exec_command_from_string(value
)) < 0)
1406 log_debug("Failed to parse exec-command value %s", value
);
1408 s
->control_command_id
= id
;
1409 s
->control_command
= s
->exec_command
[id
];
1411 } else if (streq(key
, "fifo")) {
1415 if (sscanf(value
, "%i %n", &fd
, &skip
) < 1 || fd
< 0 || !fdset_contains(fds
, fd
))
1416 log_debug("Failed to parse fifo value %s", value
);
1419 LIST_FOREACH(port
, p
, s
->ports
)
1420 if (streq(p
->path
, value
+skip
))
1425 close_nointr_nofail(p
->fd
);
1426 p
->fd
= fdset_remove(fds
, fd
);
1430 } else if (streq(key
, "socket")) {
1431 int fd
, type
, skip
= 0;
1434 if (sscanf(value
, "%i %i %n", &fd
, &type
, &skip
) < 2 || fd
< 0 || type
< 0 || !fdset_contains(fds
, fd
))
1435 log_debug("Failed to parse socket value %s", value
);
1438 LIST_FOREACH(port
, p
, s
->ports
)
1439 if (socket_address_is(&p
->address
, value
+skip
, type
))
1444 close_nointr_nofail(p
->fd
);
1445 p
->fd
= fdset_remove(fds
, fd
);
1450 log_debug("Unknown serialization key '%s'", key
);
1455 static UnitActiveState
socket_active_state(Unit
*u
) {
1458 return state_translation_table
[SOCKET(u
)->state
];
1461 static const char *socket_sub_state_to_string(Unit
*u
) {
1464 return socket_state_to_string(SOCKET(u
)->state
);
1467 static bool socket_check_gc(Unit
*u
) {
1468 Socket
*s
= SOCKET(u
);
1472 return s
->n_connections
> 0;
1475 static void socket_fd_event(Unit
*u
, int fd
, uint32_t events
, Watch
*w
) {
1476 Socket
*s
= SOCKET(u
);
1482 if (s
->state
!= SOCKET_LISTENING
)
1485 log_debug("Incoming traffic on %s", u
->meta
.id
);
1487 if (events
!= EPOLLIN
) {
1488 log_error("Got invalid poll event on socket.");
1492 if (w
->socket_accept
) {
1495 if ((cfd
= accept4(fd
, NULL
, NULL
, SOCK_NONBLOCK
)) < 0) {
1500 log_error("Failed to accept socket: %m");
1507 socket_apply_socket_options(s
, cfd
);
1510 socket_enter_running(s
, cfd
);
1514 socket_enter_stop_pre(s
, false);
1517 static void socket_sigchld_event(Unit
*u
, pid_t pid
, int code
, int status
) {
1518 Socket
*s
= SOCKET(u
);
1524 if (pid
!= s
->control_pid
)
1529 success
= is_clean_exit(code
, status
);
1531 if (s
->control_command
) {
1532 exec_status_exit(&s
->control_command
->exec_status
, pid
, code
, status
);
1534 if (s
->control_command
->ignore
)
1538 log_full(success
? LOG_DEBUG
: LOG_NOTICE
,
1539 "%s control process exited, code=%s status=%i", u
->meta
.id
, sigchld_code_to_string(code
), status
);
1540 s
->failure
= s
->failure
|| !success
;
1542 if (s
->control_command
&& s
->control_command
->command_next
&& success
) {
1543 log_debug("%s running next command for state %s", u
->meta
.id
, socket_state_to_string(s
->state
));
1544 socket_run_next(s
, success
);
1546 s
->control_command
= NULL
;
1547 s
->control_command_id
= _SOCKET_EXEC_COMMAND_INVALID
;
1549 /* No further commands for this step, so let's figure
1550 * out what to do next */
1552 log_debug("%s got final SIGCHLD for state %s", u
->meta
.id
, socket_state_to_string(s
->state
));
1556 case SOCKET_START_PRE
:
1558 socket_enter_start_post(s
);
1560 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, false);
1563 case SOCKET_START_POST
:
1565 socket_enter_listening(s
);
1567 socket_enter_stop_pre(s
, false);
1570 case SOCKET_STOP_PRE
:
1571 case SOCKET_STOP_PRE_SIGTERM
:
1572 case SOCKET_STOP_PRE_SIGKILL
:
1573 socket_enter_stop_post(s
, success
);
1576 case SOCKET_STOP_POST
:
1577 case SOCKET_FINAL_SIGTERM
:
1578 case SOCKET_FINAL_SIGKILL
:
1579 socket_enter_dead(s
, success
);
1583 assert_not_reached("Uh, control process died at wrong time.");
1588 static void socket_timer_event(Unit
*u
, uint64_t elapsed
, Watch
*w
) {
1589 Socket
*s
= SOCKET(u
);
1592 assert(elapsed
== 1);
1593 assert(w
== &s
->timer_watch
);
1597 case SOCKET_START_PRE
:
1598 log_warning("%s starting timed out. Terminating.", u
->meta
.id
);
1599 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, false);
1601 case SOCKET_START_POST
:
1602 log_warning("%s starting timed out. Stopping.", u
->meta
.id
);
1603 socket_enter_stop_pre(s
, false);
1606 case SOCKET_STOP_PRE
:
1607 log_warning("%s stopping timed out. Terminating.", u
->meta
.id
);
1608 socket_enter_signal(s
, SOCKET_STOP_PRE_SIGTERM
, false);
1611 case SOCKET_STOP_PRE_SIGTERM
:
1612 log_warning("%s stopping timed out. Killing.", u
->meta
.id
);
1613 socket_enter_signal(s
, SOCKET_STOP_PRE_SIGKILL
, false);
1616 case SOCKET_STOP_PRE_SIGKILL
:
1617 log_warning("%s still around after SIGKILL. Ignoring.", u
->meta
.id
);
1618 socket_enter_stop_post(s
, false);
1621 case SOCKET_STOP_POST
:
1622 log_warning("%s stopping timed out (2). Terminating.", u
->meta
.id
);
1623 socket_enter_signal(s
, SOCKET_FINAL_SIGTERM
, false);
1626 case SOCKET_FINAL_SIGTERM
:
1627 log_warning("%s stopping timed out (2). Killing.", u
->meta
.id
);
1628 socket_enter_signal(s
, SOCKET_FINAL_SIGKILL
, false);
1631 case SOCKET_FINAL_SIGKILL
:
1632 log_warning("%s still around after SIGKILL (2). Entering maintenance mode.", u
->meta
.id
);
1633 socket_enter_dead(s
, false);
1637 assert_not_reached("Timeout at wrong time.");
1641 int socket_collect_fds(Socket
*s
, int **fds
, unsigned *n_fds
) {
1650 /* Called from the service code for requesting our fds */
1653 LIST_FOREACH(port
, p
, s
->ports
)
1657 if (!(rfds
= new(int, rn_fds
)) < 0)
1661 LIST_FOREACH(port
, p
, s
->ports
)
1665 assert(k
== rn_fds
);
1673 void socket_notify_service_dead(Socket
*s
) {
1676 /* The service is dead. Dang!
1678 * This is strictly for one-instance-for-all-connections
1681 if (s
->state
== SOCKET_RUNNING
) {
1682 log_debug("%s got notified about service death.", s
->meta
.id
);
1683 socket_enter_listening(s
);
1687 void socket_connection_unref(Socket
*s
) {
1690 /* The service is dead. Yay!
1692 * This is strictly for one-onstance-per-connection
1695 assert(s
->n_connections
> 0);
1698 log_debug("%s: One connection closed, %u left.", s
->meta
.id
, s
->n_connections
);
1701 static void socket_reset_maintenance(Unit
*u
) {
1702 Socket
*s
= SOCKET(u
);
1706 if (s
->state
== SOCKET_MAINTENANCE
)
1707 socket_set_state(s
, SOCKET_DEAD
);
1712 static const char* const socket_state_table
[_SOCKET_STATE_MAX
] = {
1713 [SOCKET_DEAD
] = "dead",
1714 [SOCKET_START_PRE
] = "start-pre",
1715 [SOCKET_START_POST
] = "start-post",
1716 [SOCKET_LISTENING
] = "listening",
1717 [SOCKET_RUNNING
] = "running",
1718 [SOCKET_STOP_PRE
] = "stop-pre",
1719 [SOCKET_STOP_PRE_SIGTERM
] = "stop-pre-sigterm",
1720 [SOCKET_STOP_PRE_SIGKILL
] = "stop-pre-sigkill",
1721 [SOCKET_STOP_POST
] = "stop-post",
1722 [SOCKET_FINAL_SIGTERM
] = "final-sigterm",
1723 [SOCKET_FINAL_SIGKILL
] = "final-sigkill",
1724 [SOCKET_MAINTENANCE
] = "maintenance"
1727 DEFINE_STRING_TABLE_LOOKUP(socket_state
, SocketState
);
1729 static const char* const socket_exec_command_table
[_SOCKET_EXEC_COMMAND_MAX
] = {
1730 [SOCKET_EXEC_START_PRE
] = "StartPre",
1731 [SOCKET_EXEC_START_POST
] = "StartPost",
1732 [SOCKET_EXEC_STOP_PRE
] = "StopPre",
1733 [SOCKET_EXEC_STOP_POST
] = "StopPost"
1736 DEFINE_STRING_TABLE_LOOKUP(socket_exec_command
, SocketExecCommand
);
1738 const UnitVTable socket_vtable
= {
1739 .suffix
= ".socket",
1741 .init
= socket_init
,
1742 .done
= socket_done
,
1743 .load
= socket_load
,
1745 .coldplug
= socket_coldplug
,
1747 .dump
= socket_dump
,
1749 .start
= socket_start
,
1750 .stop
= socket_stop
,
1752 .serialize
= socket_serialize
,
1753 .deserialize_item
= socket_deserialize_item
,
1755 .active_state
= socket_active_state
,
1756 .sub_state_to_string
= socket_sub_state_to_string
,
1758 .check_gc
= socket_check_gc
,
1760 .fd_event
= socket_fd_event
,
1761 .sigchld_event
= socket_sigchld_event
,
1762 .timer_event
= socket_timer_event
,
1764 .reset_maintenance
= socket_reset_maintenance
,
1766 .bus_message_handler
= bus_socket_message_handler