Home | History | Annotate | Line # | Download | only in init
init.c revision 1.97
      1  1.97     lukem /*	$NetBSD: init.c,v 1.97 2009/01/18 00:25:13 lukem Exp $	*/
      2  1.19       cgd 
      3   1.8       cgd /*-
      4  1.15        pk  * Copyright (c) 1991, 1993
      5  1.15        pk  *	The Regents of the University of California.  All rights reserved.
      6   1.1       cgd  *
      7   1.8       cgd  * This code is derived from software contributed to Berkeley by
      8   1.8       cgd  * Donn Seeley at Berkeley Software Design, Inc.
      9   1.8       cgd  *
     10   1.1       cgd  * Redistribution and use in source and binary forms, with or without
     11   1.1       cgd  * modification, are permitted provided that the following conditions
     12   1.1       cgd  * are met:
     13   1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     14   1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     15   1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     16   1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     17   1.1       cgd  *    documentation and/or other materials provided with the distribution.
     18  1.61       agc  * 3. Neither the name of the University nor the names of its contributors
     19   1.8       cgd  *    may be used to endorse or promote products derived from this software
     20   1.1       cgd  *    without specific prior written permission.
     21   1.1       cgd  *
     22   1.8       cgd  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     23   1.1       cgd  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     24   1.1       cgd  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     25   1.8       cgd  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     26   1.1       cgd  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     27   1.1       cgd  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     28   1.1       cgd  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     29   1.1       cgd  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     30   1.1       cgd  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     31   1.1       cgd  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     32   1.1       cgd  * SUCH DAMAGE.
     33   1.1       cgd  */
     34   1.3       cgd 
     35  1.26     perry #include <sys/cdefs.h>
     36   1.8       cgd #ifndef lint
     37  1.96     lukem __COPYRIGHT("@(#) Copyright (c) 1991, 1993\
     38  1.96     lukem  The Regents of the University of California.  All rights reserved.");
     39   1.8       cgd #endif /* not lint */
     40   1.8       cgd 
     41   1.8       cgd #ifndef lint
     42  1.19       cgd #if 0
     43  1.25     perry static char sccsid[] = "@(#)init.c	8.2 (Berkeley) 4/28/95";
     44  1.19       cgd #else
     45  1.97     lukem __RCSID("$NetBSD: init.c,v 1.97 2009/01/18 00:25:13 lukem Exp $");
     46  1.19       cgd #endif
     47   1.8       cgd #endif /* not lint */
     48   1.8       cgd 
     49   1.8       cgd #include <sys/param.h>
     50   1.8       cgd #include <sys/sysctl.h>
     51   1.1       cgd #include <sys/wait.h>
     52  1.28  christos #include <sys/mman.h>
     53  1.28  christos #include <sys/stat.h>
     54  1.28  christos #include <sys/mount.h>
     55  1.28  christos #include <machine/cpu.h>
     56   1.8       cgd 
     57   1.8       cgd #include <db.h>
     58   1.8       cgd #include <errno.h>
     59   1.8       cgd #include <fcntl.h>
     60   1.8       cgd #include <signal.h>
     61   1.8       cgd #include <stdio.h>
     62   1.8       cgd #include <stdlib.h>
     63   1.8       cgd #include <string.h>
     64   1.8       cgd #include <syslog.h>
     65   1.8       cgd #include <time.h>
     66   1.1       cgd #include <ttyent.h>
     67   1.1       cgd #include <unistd.h>
     68  1.22       jtc #include <util.h>
     69  1.28  christos #include <paths.h>
     70  1.28  christos #include <err.h>
     71   1.1       cgd 
     72   1.8       cgd #include <stdarg.h>
     73   1.8       cgd 
     74   1.8       cgd #ifdef SECURE
     75   1.5       cgd #include <pwd.h>
     76   1.5       cgd #endif
     77   1.5       cgd 
     78   1.8       cgd #include "pathnames.h"
     79   1.8       cgd 
     80  1.62       dsl #define XSTR(x) #x
     81  1.62       dsl #define STR(x) XSTR(x)
     82  1.62       dsl 
     83   1.8       cgd /*
     84   1.8       cgd  * Sleep times; used to prevent thrashing.
     85   1.8       cgd  */
     86   1.8       cgd #define	GETTY_SPACING		 5	/* N secs minimum getty spacing */
     87   1.8       cgd #define	GETTY_SLEEP		30	/* sleep N secs after spacing problem */
     88   1.8       cgd #define	WINDOW_WAIT		 3	/* wait N secs after starting window */
     89   1.8       cgd #define	STALL_TIMEOUT		30	/* wait N secs after warning */
     90   1.8       cgd #define	DEATH_WATCH		10	/* wait N secs for procs to die */
     91   1.8       cgd 
     92  1.66   mycroft const struct timespec dtrtime = {.tv_sec = 0, .tv_nsec = 250000};
     93  1.56     lukem 
     94  1.56     lukem #if defined(RESCUEDIR)
     95  1.56     lukem #define	INIT_BSHELL	RESCUEDIR "/sh"
     96  1.56     lukem #define	INIT_MOUNT_MFS	RESCUEDIR "/mount_mfs"
     97  1.56     lukem #define	INIT_PATH	RESCUEDIR ":" _PATH_STDPATH
     98  1.56     lukem #else
     99  1.56     lukem #define	INIT_BSHELL	_PATH_BSHELL
    100  1.56     lukem #define	INIT_MOUNT_MFS	"/sbin/mount_mfs"
    101  1.56     lukem #define	INIT_PATH	_PATH_STDPATH
    102  1.52     lukem #endif
    103  1.52     lukem 
    104  1.39       wiz int main(int, char *[]);
    105  1.27     perry 
    106  1.39       wiz void handle(sig_t, ...);
    107  1.39       wiz void delset(sigset_t *, ...);
    108   1.8       cgd 
    109  1.39       wiz void stall(const char *, ...)
    110  1.28  christos     __attribute__((__format__(__printf__,1,2)));
    111  1.39       wiz void warning(const char *, ...)
    112  1.28  christos     __attribute__((__format__(__printf__,1,2)));
    113  1.39       wiz void emergency(const char *, ...)
    114  1.28  christos     __attribute__((__format__(__printf__,1,2)));
    115  1.39       wiz void disaster(int);
    116  1.39       wiz void badsys(int);
    117   1.8       cgd 
    118   1.8       cgd /*
    119   1.8       cgd  * We really need a recursive typedef...
    120   1.8       cgd  * The following at least guarantees that the return type of (*state_t)()
    121   1.8       cgd  * is sufficiently wide to hold a function pointer.
    122   1.8       cgd  */
    123  1.39       wiz typedef long (*state_func_t)(void);
    124  1.39       wiz typedef state_func_t (*state_t)(void);
    125   1.8       cgd 
    126  1.77  christos #define	DEATH		'd'
    127  1.77  christos #define	SINGLE_USER	's'
    128  1.77  christos #define	RUNCOM		'r'
    129  1.77  christos #define	READ_TTYS	't'
    130  1.77  christos #define	MULTI_USER	'm'
    131  1.77  christos #define	CLEAN_TTYS	'T'
    132  1.77  christos #define	CATATONIA	'c'
    133  1.77  christos 
    134  1.39       wiz state_func_t single_user(void);
    135  1.39       wiz state_func_t runcom(void);
    136  1.39       wiz state_func_t read_ttys(void);
    137  1.39       wiz state_func_t multi_user(void);
    138  1.39       wiz state_func_t clean_ttys(void);
    139  1.39       wiz state_func_t catatonia(void);
    140  1.39       wiz state_func_t death(void);
    141   1.8       cgd 
    142   1.8       cgd enum { AUTOBOOT, FASTBOOT } runcom_mode = AUTOBOOT;
    143   1.8       cgd 
    144  1.39       wiz void transition(state_t);
    145  1.40       wiz void setctty(const char *);
    146   1.8       cgd 
    147   1.8       cgd typedef struct init_session {
    148   1.8       cgd 	int	se_index;		/* index of entry in ttys file */
    149   1.8       cgd 	pid_t	se_process;		/* controlling process */
    150  1.77  christos 	struct timeval	se_started;	/* used to avoid thrashing */
    151   1.8       cgd 	int	se_flags;		/* status of session */
    152   1.8       cgd #define	SE_SHUTDOWN	0x1		/* session won't be restarted */
    153  1.21   mycroft #define	SE_PRESENT	0x2		/* session is in /etc/ttys */
    154   1.8       cgd 	char	*se_device;		/* filename of port */
    155   1.8       cgd 	char	*se_getty;		/* what to run on that port */
    156   1.8       cgd 	char	**se_getty_argv;	/* pre-parsed argument array */
    157   1.8       cgd 	char	*se_window;		/* window system (started only once) */
    158   1.8       cgd 	char	**se_window_argv;	/* pre-parsed argument array */
    159   1.8       cgd 	struct	init_session *se_prev;
    160   1.8       cgd 	struct	init_session *se_next;
    161   1.8       cgd } session_t;
    162   1.8       cgd 
    163  1.39       wiz void free_session(session_t *);
    164  1.39       wiz session_t *new_session(session_t *, int, struct ttyent *);
    165   1.8       cgd session_t *sessions;
    166   1.8       cgd 
    167  1.39       wiz char **construct_argv(char *);
    168  1.39       wiz void start_window_system(session_t *);
    169  1.50  christos void collect_child(pid_t, int);
    170  1.39       wiz pid_t start_getty(session_t *);
    171  1.39       wiz void transition_handler(int);
    172  1.39       wiz void alrm_handler(int);
    173  1.39       wiz void setsecuritylevel(int);
    174  1.39       wiz int getsecuritylevel(void);
    175  1.39       wiz int setupargv(session_t *, struct ttyent *);
    176   1.8       cgd int clang;
    177   1.8       cgd 
    178  1.39       wiz int start_session_db(void);
    179  1.39       wiz void add_session(session_t *);
    180  1.39       wiz void del_session(session_t *);
    181  1.39       wiz session_t *find_session(pid_t);
    182   1.8       cgd DB *session_db;
    183   1.8       cgd 
    184  1.73      salo int do_setttyent(void);
    185  1.73      salo 
    186  1.73      salo #ifndef LETS_GET_SMALL
    187  1.73      salo state_t requested_transition = runcom;
    188  1.73      salo 
    189  1.73      salo void clear_session_logs(session_t *, int);
    190  1.73      salo state_func_t runetcrc(int);
    191  1.77  christos #ifdef SUPPORT_UTMPX
    192  1.77  christos static struct timeval boot_time;
    193  1.77  christos state_t current_state = death;
    194  1.77  christos static void session_utmpx(const session_t *, int);
    195  1.77  christos static void make_utmpx(const char *, const char *, int, pid_t,
    196  1.77  christos     const struct timeval *, int);
    197  1.77  christos static char get_runlevel(const state_t);
    198  1.77  christos static void utmpx_set_runlevel(char, char);
    199  1.77  christos #endif
    200  1.73      salo 
    201  1.73      salo #ifdef CHROOT
    202  1.73      salo int did_multiuser_chroot = 0;
    203  1.73      salo char rootdir[PATH_MAX];
    204  1.73      salo int shouldchroot(void);
    205  1.73      salo int createsysctlnode(void);
    206  1.73      salo #endif /* CHROOT */
    207  1.73      salo 
    208  1.73      salo #else /* LETS_GET_SMALL */
    209  1.73      salo state_t requested_transition = single_user;
    210  1.73      salo #endif /* !LETS_GET_SMALL */
    211  1.73      salo 
    212  1.45       abs #ifdef MFS_DEV_IF_NO_CONSOLE
    213  1.58  christos 
    214  1.45       abs static int mfs_dev(void);
    215  1.58  christos 
    216  1.28  christos #endif
    217  1.28  christos 
    218   1.8       cgd /*
    219   1.8       cgd  * The mother of all processes.
    220   1.8       cgd  */
    221   1.8       cgd int
    222  1.43     lukem main(int argc, char **argv)
    223   1.8       cgd {
    224   1.8       cgd 	struct sigaction sa;
    225   1.8       cgd 	sigset_t mask;
    226  1.37     soren #ifndef LETS_GET_SMALL
    227  1.37     soren 	int c;
    228   1.8       cgd 
    229  1.77  christos #ifdef SUPPORT_UTMPX
    230  1.77  christos 	(void)gettimeofday(&boot_time, NULL);
    231  1.77  christos #endif /* SUPPORT_UTMPX */
    232  1.77  christos 
    233   1.8       cgd 	/* Dispose of random users. */
    234   1.8       cgd 	if (getuid() != 0) {
    235  1.28  christos 		errno = EPERM;
    236  1.87    cbiere 		err(1, NULL);
    237   1.8       cgd 	}
    238   1.8       cgd 
    239   1.8       cgd 	/* System V users like to reexec init. */
    240  1.28  christos 	if (getpid() != 1)
    241  1.87    cbiere 		errx(1, "already running");
    242  1.28  christos #endif
    243   1.8       cgd 
    244   1.8       cgd 	/*
    245   1.8       cgd 	 * Create an initial session.
    246   1.8       cgd 	 */
    247   1.8       cgd 	if (setsid() < 0)
    248  1.28  christos 		warn("initial setsid() failed");
    249  1.12       cgd 
    250  1.12       cgd 	/*
    251  1.12       cgd 	 * Establish an initial user so that programs running
    252  1.12       cgd 	 * single user do not freak out and die (like passwd).
    253  1.12       cgd 	 */
    254  1.12       cgd 	if (setlogin("root") < 0)
    255  1.28  christos 		warn("setlogin() failed");
    256  1.28  christos 
    257  1.28  christos 
    258  1.45       abs #ifdef MFS_DEV_IF_NO_CONSOLE
    259  1.45       abs 	if (mfs_dev() == -1)
    260  1.45       abs 		requested_transition = single_user;
    261  1.28  christos #endif
    262  1.28  christos 
    263  1.28  christos #ifndef LETS_GET_SMALL
    264  1.28  christos 	/*
    265  1.28  christos 	 * Note that this does NOT open a file...
    266  1.28  christos 	 * Does 'init' deserve its own facility number?
    267  1.28  christos 	 */
    268  1.42     lukem 	openlog("init", LOG_CONS, LOG_AUTH);
    269  1.28  christos #endif /* LETS_GET_SMALL */
    270  1.28  christos 
    271   1.8       cgd 
    272  1.13       cgd #ifndef LETS_GET_SMALL
    273   1.8       cgd 	/*
    274   1.8       cgd 	 * This code assumes that we always get arguments through flags,
    275   1.8       cgd 	 * never through bits set in some random machine register.
    276   1.8       cgd 	 */
    277   1.8       cgd 	while ((c = getopt(argc, argv, "sf")) != -1)
    278   1.8       cgd 		switch (c) {
    279   1.8       cgd 		case 's':
    280   1.8       cgd 			requested_transition = single_user;
    281   1.8       cgd 			break;
    282   1.8       cgd 		case 'f':
    283   1.8       cgd 			runcom_mode = FASTBOOT;
    284   1.8       cgd 			break;
    285   1.8       cgd 		default:
    286  1.80  christos 			warning("unrecognized flag `%c'", c);
    287   1.8       cgd 			break;
    288   1.8       cgd 		}
    289   1.8       cgd 
    290   1.8       cgd 	if (optind != argc)
    291   1.8       cgd 		warning("ignoring excess arguments");
    292  1.13       cgd #else /* LETS_GET_SMALL */
    293  1.13       cgd 	requested_transition = single_user;
    294  1.13       cgd #endif /* LETS_GET_SMALL */
    295   1.8       cgd 
    296   1.8       cgd 	/*
    297   1.8       cgd 	 * We catch or block signals rather than ignore them,
    298   1.8       cgd 	 * so that they get reset on exec.
    299   1.8       cgd 	 */
    300   1.8       cgd 	handle(badsys, SIGSYS, 0);
    301   1.8       cgd 	handle(disaster, SIGABRT, SIGFPE, SIGILL, SIGSEGV,
    302   1.8       cgd 	       SIGBUS, SIGXCPU, SIGXFSZ, 0);
    303   1.8       cgd 	handle(transition_handler, SIGHUP, SIGTERM, SIGTSTP, 0);
    304   1.8       cgd 	handle(alrm_handler, SIGALRM, 0);
    305  1.47  christos 	(void)sigfillset(&mask);
    306   1.8       cgd 	delset(&mask, SIGABRT, SIGFPE, SIGILL, SIGSEGV, SIGBUS, SIGSYS,
    307  1.47  christos 	    SIGXCPU, SIGXFSZ, SIGHUP, SIGTERM, SIGTSTP, SIGALRM, 0);
    308  1.47  christos 	(void)sigprocmask(SIG_SETMASK, &mask, NULL);
    309  1.47  christos 	(void)sigemptyset(&sa.sa_mask);
    310   1.8       cgd 	sa.sa_flags = 0;
    311   1.8       cgd 	sa.sa_handler = SIG_IGN;
    312  1.47  christos 	(void)sigaction(SIGTTIN, &sa, NULL);
    313  1.47  christos 	(void)sigaction(SIGTTOU, &sa, NULL);
    314   1.8       cgd 
    315   1.8       cgd 	/*
    316   1.8       cgd 	 * Paranoia.
    317   1.8       cgd 	 */
    318  1.47  christos 	(void)close(0);
    319  1.47  christos 	(void)close(1);
    320  1.47  christos 	(void)close(2);
    321   1.8       cgd 
    322  1.73      salo #if !defined(LETS_GET_SMALL) && defined(CHROOT)
    323  1.73      salo 	/* Create "init.root" sysctl node. */
    324  1.84  christos 	(void)createsysctlnode();
    325  1.73      salo #endif /* !LETS_GET_SMALL && CHROOT*/
    326  1.73      salo 
    327   1.8       cgd 	/*
    328   1.8       cgd 	 * Start the state machine.
    329   1.8       cgd 	 */
    330   1.8       cgd 	transition(requested_transition);
    331   1.8       cgd 
    332   1.8       cgd 	/*
    333   1.8       cgd 	 * Should never reach here.
    334   1.8       cgd 	 */
    335   1.8       cgd 	return 1;
    336   1.8       cgd }
    337   1.8       cgd 
    338   1.8       cgd /*
    339   1.8       cgd  * Associate a function with a signal handler.
    340   1.8       cgd  */
    341   1.8       cgd void
    342   1.8       cgd handle(sig_t handler, ...)
    343   1.8       cgd {
    344   1.8       cgd 	int sig;
    345   1.8       cgd 	struct sigaction sa;
    346  1.33   thorpej 	sigset_t mask_everything;
    347   1.8       cgd 	va_list ap;
    348   1.8       cgd 
    349   1.8       cgd 	va_start(ap, handler);
    350   1.7       cgd 
    351   1.8       cgd 	sa.sa_handler = handler;
    352  1.47  christos 	(void)sigfillset(&mask_everything);
    353   1.1       cgd 
    354  1.27     perry 	while ((sig = va_arg(ap, int)) != 0) {
    355   1.8       cgd 		sa.sa_mask = mask_everything;
    356   1.8       cgd 		/* XXX SA_RESTART? */
    357   1.8       cgd 		sa.sa_flags = sig == SIGCHLD ? SA_NOCLDSTOP : 0;
    358  1.47  christos 		(void)sigaction(sig, &sa, NULL);
    359   1.8       cgd 	}
    360   1.8       cgd 	va_end(ap);
    361   1.8       cgd }
    362   1.1       cgd 
    363   1.8       cgd /*
    364   1.8       cgd  * Delete a set of signals from a mask.
    365   1.8       cgd  */
    366   1.8       cgd void
    367   1.8       cgd delset(sigset_t *maskp, ...)
    368   1.8       cgd {
    369   1.8       cgd 	int sig;
    370   1.8       cgd 	va_list ap;
    371   1.8       cgd 
    372   1.8       cgd 	va_start(ap, maskp);
    373   1.1       cgd 
    374  1.27     perry 	while ((sig = va_arg(ap, int)) != 0)
    375  1.47  christos 		(void)sigdelset(maskp, sig);
    376   1.8       cgd 	va_end(ap);
    377   1.8       cgd }
    378   1.8       cgd 
    379  1.91       dsl #if 0	/* Enable to get error messages from init ! */
    380  1.91       dsl #define vsyslog(level, fmt, ap) print_console(level, fmt, ap)
    381  1.91       dsl #define closelog()
    382  1.91       dsl 
    383  1.91       dsl static void
    384  1.91       dsl print_console(int level, const char *message, va_list ap)
    385  1.91       dsl {
    386  1.91       dsl 	/*
    387  1.91       dsl 	 * XXX: syslog seems to just plain not work in console-only
    388  1.91       dsl 	 * XXX: situation... that should be fixed.  Let's leave this
    389  1.91       dsl 	 * XXX: note + code here in case someone gets in trouble and
    390  1.91       dsl 	 * XXX: wants to debug. -- Jachym Holecek <freza (at) liberouter.org>
    391  1.91       dsl 	 */
    392  1.91       dsl 	char errbuf[1024];
    393  1.91       dsl 	int fd, len;
    394  1.91       dsl 
    395  1.91       dsl 	/* We can't do anything on errors, anyway... */
    396  1.91       dsl 	fd = open(_PATH_CONSOLE, O_WRONLY);
    397  1.91       dsl 	if (fd == -1)
    398  1.91       dsl 		return ;
    399  1.91       dsl 
    400  1.91       dsl 	/* %m will get lost... */
    401  1.91       dsl 	len = vsnprintf(errbuf, sizeof(errbuf), message, ap);
    402  1.91       dsl 	(void)write(fd, (void *)errbuf, len);
    403  1.91       dsl 	(void)close(fd);
    404  1.91       dsl }
    405  1.91       dsl #endif
    406  1.91       dsl 
    407   1.8       cgd /*
    408   1.8       cgd  * Log a message and sleep for a while (to give someone an opportunity
    409   1.8       cgd  * to read it and to save log or hardcopy output if the problem is chronic).
    410   1.8       cgd  * NB: should send a message to the session logger to avoid blocking.
    411   1.8       cgd  */
    412   1.8       cgd void
    413  1.28  christos stall(const char *message, ...)
    414   1.8       cgd {
    415   1.8       cgd 	va_list ap;
    416   1.8       cgd 
    417   1.8       cgd 	va_start(ap, message);
    418   1.8       cgd 	vsyslog(LOG_ALERT, message, ap);
    419   1.8       cgd 	va_end(ap);
    420  1.24   mycroft 	closelog();
    421  1.47  christos 	(void)sleep(STALL_TIMEOUT);
    422   1.8       cgd }
    423   1.8       cgd 
    424   1.8       cgd /*
    425   1.8       cgd  * Like stall(), but doesn't sleep.
    426   1.8       cgd  * If cpp had variadic macros, the two functions could be #defines for another.
    427   1.8       cgd  * NB: should send a message to the session logger to avoid blocking.
    428   1.8       cgd  */
    429   1.8       cgd void
    430  1.28  christos warning(const char *message, ...)
    431   1.8       cgd {
    432   1.8       cgd 	va_list ap;
    433   1.8       cgd 
    434   1.8       cgd 	va_start(ap, message);
    435   1.8       cgd 	vsyslog(LOG_ALERT, message, ap);
    436   1.8       cgd 	va_end(ap);
    437  1.24   mycroft 	closelog();
    438   1.8       cgd }
    439   1.1       cgd 
    440   1.8       cgd /*
    441   1.8       cgd  * Log an emergency message.
    442   1.8       cgd  * NB: should send a message to the session logger to avoid blocking.
    443   1.8       cgd  */
    444   1.8       cgd void
    445  1.28  christos emergency(const char *message, ...)
    446   1.8       cgd {
    447   1.8       cgd 	va_list ap;
    448   1.8       cgd 
    449   1.8       cgd 	va_start(ap, message);
    450   1.8       cgd 	vsyslog(LOG_EMERG, message, ap);
    451   1.8       cgd 	va_end(ap);
    452  1.24   mycroft 	closelog();
    453   1.8       cgd }
    454   1.1       cgd 
    455   1.8       cgd /*
    456   1.8       cgd  * Catch a SIGSYS signal.
    457   1.8       cgd  *
    458   1.8       cgd  * These may arise if a system does not support sysctl.
    459   1.8       cgd  * We tolerate up to 25 of these, then throw in the towel.
    460   1.8       cgd  */
    461   1.1       cgd void
    462  1.39       wiz badsys(int sig)
    463   1.1       cgd {
    464   1.8       cgd 	static int badcount = 0;
    465   1.8       cgd 
    466   1.8       cgd 	if (badcount++ < 25)
    467   1.8       cgd 		return;
    468   1.8       cgd 	disaster(sig);
    469   1.1       cgd }
    470   1.1       cgd 
    471   1.8       cgd /*
    472   1.8       cgd  * Catch an unexpected signal.
    473   1.8       cgd  */
    474   1.1       cgd void
    475  1.39       wiz disaster(int sig)
    476   1.8       cgd {
    477  1.43     lukem 
    478  1.20       jtc 	emergency("fatal signal: %s", strsignal(sig));
    479  1.47  christos 	(void)sleep(STALL_TIMEOUT);
    480   1.8       cgd 	_exit(sig);		/* reboot */
    481   1.8       cgd }
    482   1.8       cgd 
    483   1.8       cgd /*
    484   1.8       cgd  * Get the security level of the kernel.
    485   1.8       cgd  */
    486   1.8       cgd int
    487  1.39       wiz getsecuritylevel(void)
    488   1.1       cgd {
    489   1.8       cgd #ifdef KERN_SECURELVL
    490   1.8       cgd 	int name[2], curlevel;
    491   1.8       cgd 	size_t len;
    492   1.8       cgd 
    493   1.8       cgd 	name[0] = CTL_KERN;
    494   1.8       cgd 	name[1] = KERN_SECURELVL;
    495   1.8       cgd 	len = sizeof curlevel;
    496   1.8       cgd 	if (sysctl(name, 2, &curlevel, &len, NULL, 0) == -1) {
    497  1.47  christos 		emergency("cannot get kernel security level: %m");
    498  1.93    dyoung 		return -1;
    499   1.8       cgd 	}
    500  1.93    dyoung 	return curlevel;
    501   1.8       cgd #else
    502  1.93    dyoung 	return -1;
    503   1.8       cgd #endif
    504   1.1       cgd }
    505   1.1       cgd 
    506   1.8       cgd /*
    507   1.8       cgd  * Set the security level of the kernel.
    508   1.8       cgd  */
    509   1.1       cgd void
    510  1.39       wiz setsecuritylevel(int newlevel)
    511   1.1       cgd {
    512   1.8       cgd #ifdef KERN_SECURELVL
    513   1.8       cgd 	int name[2], curlevel;
    514   1.1       cgd 
    515   1.8       cgd 	curlevel = getsecuritylevel();
    516   1.8       cgd 	if (newlevel == curlevel)
    517   1.8       cgd 		return;
    518   1.8       cgd 	name[0] = CTL_KERN;
    519   1.8       cgd 	name[1] = KERN_SECURELVL;
    520   1.8       cgd 	if (sysctl(name, 2, NULL, NULL, &newlevel, sizeof newlevel) == -1) {
    521  1.80  christos 		emergency("cannot change kernel security level from"
    522  1.47  christos 		    " %d to %d: %m", curlevel, newlevel);
    523   1.8       cgd 		return;
    524   1.1       cgd 	}
    525   1.8       cgd #ifdef SECURE
    526   1.8       cgd 	warning("kernel security level changed from %d to %d",
    527   1.8       cgd 	    curlevel, newlevel);
    528   1.8       cgd #endif
    529   1.8       cgd #endif
    530   1.1       cgd }
    531   1.1       cgd 
    532   1.8       cgd /*
    533   1.8       cgd  * Change states in the finite state machine.
    534   1.8       cgd  * The initial state is passed as an argument.
    535   1.8       cgd  */
    536   1.1       cgd void
    537  1.39       wiz transition(state_t s)
    538   1.1       cgd {
    539  1.43     lukem 
    540  1.55  christos 	if (s == NULL)
    541  1.55  christos 		return;
    542  1.77  christos 	for (;;) {
    543  1.78        he #ifdef SUPPORT_UTMPX
    544  1.77  christos #ifndef LETS_GET_SMALL
    545  1.77  christos 		utmpx_set_runlevel(get_runlevel(current_state),
    546  1.77  christos 		    get_runlevel(s));
    547  1.79        he 		current_state = s;
    548  1.77  christos #endif
    549  1.77  christos #endif
    550  1.47  christos 		s = (state_t)(*s)();
    551  1.77  christos 	}
    552   1.1       cgd }
    553   1.1       cgd 
    554  1.64  christos #ifndef LETS_GET_SMALL
    555   1.8       cgd /*
    556   1.8       cgd  * Close out the accounting files for a login session.
    557   1.8       cgd  * NB: should send a message to the session logger to avoid blocking.
    558   1.8       cgd  */
    559   1.8       cgd void
    560  1.50  christos clear_session_logs(session_t *sp, int status)
    561   1.8       cgd {
    562  1.83     isaki #if defined(SUPPORT_UTMP) || defined(SUPPORT_UTMPX)
    563   1.8       cgd 	char *line = sp->se_device + sizeof(_PATH_DEV) - 1;
    564  1.83     isaki #endif
    565  1.55  christos 
    566  1.50  christos #ifdef SUPPORT_UTMPX
    567  1.51  christos 	if (logoutx(line, status, DEAD_PROCESS))
    568  1.50  christos 		logwtmpx(line, "", "", status, DEAD_PROCESS);
    569  1.50  christos #endif
    570  1.50  christos #ifdef SUPPORT_UTMP
    571   1.8       cgd 	if (logout(line))
    572   1.8       cgd 		logwtmp(line, "", "");
    573  1.50  christos #endif
    574   1.8       cgd }
    575  1.64  christos #endif
    576   1.1       cgd 
    577   1.8       cgd /*
    578   1.8       cgd  * Start a session and allocate a controlling terminal.
    579   1.8       cgd  * Only called by children of init after forking.
    580   1.8       cgd  */
    581   1.8       cgd void
    582  1.40       wiz setctty(const char *name)
    583   1.1       cgd {
    584   1.8       cgd 	int fd;
    585   1.1       cgd 
    586  1.84  christos 	(void)revoke(name);
    587  1.84  christos 	(void)nanosleep(&dtrtime, NULL);	/* leave DTR low for a bit */
    588   1.8       cgd 	if ((fd = open(name, O_RDWR)) == -1) {
    589   1.8       cgd 		stall("can't open %s: %m", name);
    590  1.87    cbiere 		_exit(1);
    591   1.7       cgd 	}
    592   1.8       cgd 	if (login_tty(fd) == -1) {
    593   1.8       cgd 		stall("can't get %s for controlling terminal: %m", name);
    594  1.91       dsl 		_exit(2);
    595   1.8       cgd 	}
    596   1.8       cgd }
    597   1.8       cgd 
    598   1.8       cgd /*
    599   1.8       cgd  * Bring the system up single user.
    600   1.8       cgd  */
    601   1.8       cgd state_func_t
    602  1.39       wiz single_user(void)
    603   1.8       cgd {
    604   1.8       cgd 	pid_t pid, wpid;
    605   1.8       cgd 	int status;
    606  1.34       tls 	int from_securitylevel;
    607   1.8       cgd 	sigset_t mask;
    608  1.55  christos 	struct sigaction sa, satstp, sahup;
    609  1.31     perry #ifdef ALTSHELL
    610  1.56     lukem 	const char *shell = INIT_BSHELL;
    611  1.31     perry #endif
    612  1.70  christos 	const char *argv[2];
    613   1.8       cgd #ifdef SECURE
    614   1.8       cgd 	struct ttyent *typ;
    615  1.10       cgd 	struct passwd *pp;
    616   1.8       cgd 	char *clear, *password;
    617   1.7       cgd #endif
    618  1.26     perry #ifdef ALTSHELL
    619  1.26     perry 	char altshell[128];
    620  1.26     perry #endif /* ALTSHELL */
    621   1.7       cgd 
    622  1.73      salo #if !defined(LETS_GET_SMALL) && defined(CHROOT)
    623  1.73      salo 	/* Clear previous idea, just in case. */
    624  1.73      salo 	did_multiuser_chroot = 0;
    625  1.73      salo #endif /* !LETS_GET_SMALL && CHROOT */
    626  1.73      salo 
    627   1.8       cgd 	/*
    628   1.8       cgd 	 * If the kernel is in secure mode, downgrade it to insecure mode.
    629   1.8       cgd 	 */
    630  1.34       tls 	from_securitylevel = getsecuritylevel();
    631  1.34       tls 	if (from_securitylevel > 0)
    632   1.8       cgd 		setsecuritylevel(0);
    633   1.8       cgd 
    634  1.55  christos 	(void)sigemptyset(&sa.sa_mask);
    635  1.55  christos 	sa.sa_flags = 0;
    636  1.55  christos 	sa.sa_handler = SIG_IGN;
    637  1.55  christos 	(void)sigaction(SIGTSTP, &sa, &satstp);
    638  1.55  christos 	(void)sigaction(SIGHUP, &sa, &sahup);
    639   1.8       cgd 	if ((pid = fork()) == 0) {
    640   1.8       cgd 		/*
    641   1.8       cgd 		 * Start the single user session.
    642   1.8       cgd 		 */
    643  1.63       dsl 		if (access(_PATH_CONSTTY, F_OK) == 0)
    644  1.63       dsl 			setctty(_PATH_CONSTTY);
    645  1.63       dsl 		else
    646  1.63       dsl 			setctty(_PATH_CONSOLE);
    647   1.8       cgd 
    648   1.8       cgd #ifdef SECURE
    649   1.8       cgd 		/*
    650   1.8       cgd 		 * Check the root password.
    651   1.8       cgd 		 * We don't care if the console is 'on' by default;
    652   1.8       cgd 		 * it's the only tty that can be 'off' and 'secure'.
    653   1.8       cgd 		 */
    654  1.10       cgd 		typ = getttynam("console");
    655  1.10       cgd 		pp = getpwnam("root");
    656  1.34       tls 		if (typ && (from_securitylevel >=2 || (typ->ty_status
    657  1.34       tls 		    & TTY_SECURE) == 0) && pp && *pp->pw_passwd != '\0') {
    658  1.47  christos 			(void)fprintf(stderr,
    659  1.26     perry 			    "Enter root password, or ^D to go multi-user\n");
    660   1.8       cgd 			for (;;) {
    661   1.8       cgd 				clear = getpass("Password:");
    662   1.8       cgd 				if (clear == 0 || *clear == '\0')
    663  1.87    cbiere 					_exit(0);
    664   1.8       cgd 				password = crypt(clear, pp->pw_passwd);
    665  1.47  christos 				(void)memset(clear, 0, _PASSWORD_LEN);
    666   1.8       cgd 				if (strcmp(password, pp->pw_passwd) == 0)
    667   1.8       cgd 					break;
    668  1.80  christos 				warning("single-user login failed");
    669   1.1       cgd 			}
    670   1.8       cgd 		}
    671  1.84  christos 		(void)endttyent();
    672  1.10       cgd 		endpwent();
    673   1.9       cgd #endif /* SECURE */
    674   1.1       cgd 
    675  1.26     perry #ifdef ALTSHELL
    676  1.47  christos 		(void)fprintf(stderr,
    677  1.52     lukem 		    "Enter pathname of shell or RETURN for %s: ", shell);
    678  1.38       wiz 		if (fgets(altshell, sizeof(altshell), stdin) == NULL) {
    679  1.38       wiz 			altshell[0] = '\0';
    680  1.38       wiz 		} else {
    681  1.38       wiz 			/* nuke \n */
    682  1.38       wiz 			char *p;
    683  1.38       wiz 
    684  1.41       wiz 			if ((p = strchr(altshell, '\n')) != NULL)
    685  1.38       wiz 				*p = '\0';
    686  1.38       wiz 		}
    687  1.26     perry 
    688  1.26     perry 		if (altshell[0])
    689  1.26     perry 			shell = altshell;
    690  1.26     perry #endif /* ALTSHELL */
    691   1.8       cgd 
    692   1.8       cgd 		/*
    693   1.8       cgd 		 * Unblock signals.
    694   1.8       cgd 		 * We catch all the interesting ones,
    695   1.8       cgd 		 * and those are reset to SIG_DFL on exec.
    696   1.8       cgd 		 */
    697  1.47  christos 		(void)sigemptyset(&mask);
    698  1.47  christos 		(void)sigprocmask(SIG_SETMASK, &mask, NULL);
    699   1.8       cgd 
    700   1.8       cgd 		/*
    701   1.8       cgd 		 * Fire off a shell.
    702   1.8       cgd 		 * If the default one doesn't work, try the Bourne shell.
    703   1.8       cgd 		 */
    704   1.8       cgd 		argv[0] = "-sh";
    705   1.8       cgd 		argv[1] = 0;
    706  1.84  christos 		(void)setenv("PATH", INIT_PATH, 1);
    707  1.26     perry #ifdef ALTSHELL
    708  1.26     perry 		if (altshell[0])
    709  1.26     perry 			argv[0] = altshell;
    710  1.70  christos 		(void)execv(shell, __UNCONST(argv));
    711  1.80  christos 		emergency("can't exec `%s' for single user: %m", shell);
    712  1.26     perry 		argv[0] = "-sh";
    713  1.26     perry #endif /* ALTSHELL */
    714  1.70  christos 		(void)execv(INIT_BSHELL, __UNCONST(argv));
    715  1.80  christos 		emergency("can't exec `%s' for single user: %m", INIT_BSHELL);
    716  1.67   mycroft 		(void)sleep(STALL_TIMEOUT);
    717  1.91       dsl 		_exit(3);
    718   1.8       cgd 	}
    719   1.8       cgd 
    720   1.8       cgd 	if (pid == -1) {
    721   1.8       cgd 		/*
    722   1.8       cgd 		 * We are seriously hosed.  Do our best.
    723   1.8       cgd 		 */
    724  1.80  christos 		emergency("can't fork single-user shell: %m, trying again");
    725  1.47  christos 		while (waitpid(-1, NULL, WNOHANG) > 0)
    726   1.8       cgd 			continue;
    727  1.55  christos 		(void)sigaction(SIGTSTP, &satstp, NULL);
    728  1.55  christos 		(void)sigaction(SIGHUP, &sahup, NULL);
    729  1.93    dyoung 		return (state_func_t)single_user;
    730   1.1       cgd 	}
    731   1.8       cgd 
    732   1.8       cgd 	requested_transition = 0;
    733   1.8       cgd 	do {
    734   1.8       cgd 		if ((wpid = waitpid(-1, &status, WUNTRACED)) != -1)
    735  1.50  christos 			collect_child(wpid, status);
    736   1.8       cgd 		if (wpid == -1) {
    737   1.8       cgd 			if (errno == EINTR)
    738   1.8       cgd 				continue;
    739  1.47  christos 			warning("wait for single-user shell failed: %m; "
    740  1.47  christos 			    "restarting");
    741  1.47  christos 			return (state_func_t)single_user;
    742   1.8       cgd 		}
    743   1.8       cgd 		if (wpid == pid && WIFSTOPPED(status)) {
    744  1.80  christos 			warning("shell stopped, restarting");
    745  1.84  christos 			(void)kill(pid, SIGCONT);
    746   1.8       cgd 			wpid = -1;
    747   1.8       cgd 		}
    748   1.8       cgd 	} while (wpid != pid && !requested_transition);
    749   1.1       cgd 
    750  1.55  christos 	if (requested_transition) {
    751  1.55  christos 		(void)sigaction(SIGTSTP, &satstp, NULL);
    752  1.55  christos 		(void)sigaction(SIGHUP, &sahup, NULL);
    753  1.47  christos 		return (state_func_t)requested_transition;
    754  1.55  christos 	}
    755   1.1       cgd 
    756  1.49   mycroft 	if (WIFSIGNALED(status)) {
    757  1.49   mycroft 		if (WTERMSIG(status) == SIGKILL) {
    758  1.49   mycroft 			/* executed /sbin/reboot; wait for the end quietly */
    759  1.49   mycroft 			sigset_t s;
    760  1.49   mycroft 
    761  1.49   mycroft 			(void)sigfillset(&s);
    762  1.49   mycroft 			for (;;)
    763  1.49   mycroft 				(void)sigsuspend(&s);
    764   1.8       cgd 		} else {
    765  1.91       dsl 			warning("single user shell terminated (%x), restarting",
    766  1.91       dsl 				status);
    767  1.55  christos 			(void)sigaction(SIGTSTP, &satstp, NULL);
    768  1.55  christos 			(void)sigaction(SIGHUP, &sahup, NULL);
    769  1.93    dyoung 			return (state_func_t)single_user;
    770   1.1       cgd 		}
    771   1.8       cgd 	}
    772   1.8       cgd 
    773   1.8       cgd 	runcom_mode = FASTBOOT;
    774  1.55  christos 	(void)sigaction(SIGTSTP, &satstp, NULL);
    775  1.55  christos 	(void)sigaction(SIGHUP, &sahup, NULL);
    776  1.13       cgd #ifndef LETS_GET_SMALL
    777  1.93    dyoung 	return (state_func_t)runcom;
    778  1.13       cgd #else /* LETS_GET_SMALL */
    779  1.93    dyoung 	return (state_func_t)single_user;
    780  1.13       cgd #endif /* LETS_GET_SMALL */
    781   1.8       cgd }
    782   1.8       cgd 
    783  1.13       cgd #ifndef LETS_GET_SMALL
    784  1.73      salo 
    785  1.73      salo /* ARGSUSED */
    786   1.8       cgd state_func_t
    787  1.73      salo runetcrc(int trychroot)
    788   1.8       cgd {
    789   1.8       cgd 	pid_t pid, wpid;
    790   1.8       cgd 	int status;
    791  1.70  christos 	const char *argv[4];
    792   1.8       cgd 	struct sigaction sa;
    793   1.8       cgd 
    794  1.47  christos 	switch ((pid = fork())) {
    795  1.47  christos 	case 0:
    796  1.47  christos 		(void)sigemptyset(&sa.sa_mask);
    797   1.8       cgd 		sa.sa_flags = 0;
    798   1.8       cgd 		sa.sa_handler = SIG_IGN;
    799  1.47  christos 		(void)sigaction(SIGTSTP, &sa, NULL);
    800  1.47  christos 		(void)sigaction(SIGHUP, &sa, NULL);
    801   1.8       cgd 
    802   1.8       cgd 		setctty(_PATH_CONSOLE);
    803   1.8       cgd 
    804   1.8       cgd 		argv[0] = "sh";
    805   1.8       cgd 		argv[1] = _PATH_RUNCOM;
    806  1.73      salo 		argv[2] = (runcom_mode == AUTOBOOT ? "autoboot" : 0);
    807   1.8       cgd 		argv[3] = 0;
    808   1.8       cgd 
    809  1.47  christos 		(void)sigprocmask(SIG_SETMASK, &sa.sa_mask, NULL);
    810   1.8       cgd 
    811  1.73      salo #ifdef CHROOT
    812  1.73      salo 		if (trychroot)
    813  1.73      salo 			if (chroot(rootdir) != 0) {
    814  1.80  christos 				warning("failed to chroot to `%s': %m",
    815  1.73      salo 				    rootdir);
    816  1.91       dsl 				_exit(4); 	/* force single user mode */
    817  1.73      salo 			}
    818  1.73      salo #endif /* CHROOT */
    819  1.73      salo 
    820  1.70  christos 		(void)execv(INIT_BSHELL, __UNCONST(argv));
    821  1.80  christos 		stall("can't exec `%s' for `%s': %m", INIT_BSHELL, _PATH_RUNCOM);
    822  1.91       dsl 		_exit(5);	/* force single user mode */
    823  1.47  christos 		/*NOTREACHED*/
    824  1.47  christos 	case -1:
    825  1.80  christos 		emergency("can't fork for `%s' on `%s': %m", INIT_BSHELL,
    826  1.47  christos 		    _PATH_RUNCOM);
    827  1.47  christos 		while (waitpid(-1, NULL, WNOHANG) > 0)
    828   1.1       cgd 			continue;
    829  1.47  christos 		(void)sleep(STALL_TIMEOUT);
    830  1.47  christos 		return (state_func_t)single_user;
    831  1.47  christos 	default:
    832  1.47  christos 		break;
    833   1.8       cgd 	}
    834   1.8       cgd 
    835   1.8       cgd 	/*
    836   1.8       cgd 	 * Copied from single_user().  This is a bit paranoid.
    837   1.8       cgd 	 */
    838   1.8       cgd 	do {
    839   1.8       cgd 		if ((wpid = waitpid(-1, &status, WUNTRACED)) != -1)
    840  1.50  christos 			collect_child(wpid, status);
    841   1.8       cgd 		if (wpid == -1) {
    842   1.8       cgd 			if (errno == EINTR)
    843   1.8       cgd 				continue;
    844  1.80  christos 			warning("wait for `%s' on `%s' failed: %m; going to "
    845  1.56     lukem 			    "single user mode", INIT_BSHELL, _PATH_RUNCOM);
    846  1.47  christos 			return (state_func_t)single_user;
    847   1.8       cgd 		}
    848   1.8       cgd 		if (wpid == pid && WIFSTOPPED(status)) {
    849  1.80  christos 			warning("`%s' on `%s' stopped, restarting",
    850  1.56     lukem 			    INIT_BSHELL, _PATH_RUNCOM);
    851  1.47  christos 			(void)kill(pid, SIGCONT);
    852   1.8       cgd 			wpid = -1;
    853   1.8       cgd 		}
    854   1.8       cgd 	} while (wpid != pid);
    855   1.8       cgd 
    856   1.8       cgd 	if (WIFSIGNALED(status) && WTERMSIG(status) == SIGTERM &&
    857   1.8       cgd 	    requested_transition == catatonia) {
    858   1.8       cgd 		/* /etc/rc executed /sbin/reboot; wait for the end quietly */
    859   1.8       cgd 		sigset_t s;
    860   1.8       cgd 
    861  1.47  christos 		(void)sigfillset(&s);
    862   1.8       cgd 		for (;;)
    863  1.47  christos 			(void)sigsuspend(&s);
    864   1.8       cgd 	}
    865   1.8       cgd 
    866   1.8       cgd 	if (!WIFEXITED(status)) {
    867  1.80  christos 		warning("`%s' on `%s' terminated abnormally, going to "
    868  1.56     lukem 		    "single user mode", INIT_BSHELL, _PATH_RUNCOM);
    869  1.47  christos 		return (state_func_t)single_user;
    870   1.8       cgd 	}
    871   1.8       cgd 
    872   1.8       cgd 	if (WEXITSTATUS(status))
    873  1.47  christos 		return (state_func_t)single_user;
    874   1.8       cgd 
    875  1.93    dyoung 	return (state_func_t)read_ttys;
    876  1.73      salo }
    877  1.73      salo 
    878  1.73      salo /*
    879  1.73      salo  * Run the system startup script.
    880  1.73      salo  */
    881  1.73      salo state_func_t
    882  1.73      salo runcom(void)
    883  1.73      salo {
    884  1.73      salo 	state_func_t next_step;
    885  1.73      salo 
    886  1.73      salo 	/* Run /etc/rc and choose next state depending on the result. */
    887  1.73      salo 	next_step = runetcrc(0);
    888  1.93    dyoung 	if (next_step != (state_func_t)read_ttys)
    889  1.93    dyoung 		return (state_func_t)next_step;
    890  1.73      salo 
    891  1.73      salo #ifdef CHROOT
    892  1.73      salo 	/*
    893  1.73      salo 	 * If init.root sysctl does not point to "/", we'll chroot and run
    894  1.73      salo 	 * The Real(tm) /etc/rc now.  Global variable rootdir will tell us
    895  1.73      salo 	 * where to go.
    896  1.73      salo 	 */
    897  1.73      salo 	if (shouldchroot()) {
    898  1.73      salo 		next_step = runetcrc(1);
    899  1.93    dyoung 		if (next_step != (state_func_t)read_ttys)
    900  1.93    dyoung 			return (state_func_t)next_step;
    901  1.73      salo 
    902  1.73      salo 		did_multiuser_chroot = 1;
    903  1.73      salo 	} else {
    904  1.73      salo 		did_multiuser_chroot = 0;
    905  1.73      salo 	}
    906  1.73      salo #endif /* CHROOT */
    907  1.73      salo 
    908  1.73      salo 	/*
    909  1.73      salo 	 * Regardless of whether in chroot or not, we booted successfuly.
    910  1.73      salo 	 * It's time to spawn gettys (ie. next_step's value at this point).
    911  1.73      salo 	 */
    912   1.8       cgd 	runcom_mode = AUTOBOOT;		/* the default */
    913   1.8       cgd 	/* NB: should send a message to the session logger to avoid blocking. */
    914  1.51  christos #ifdef SUPPORT_UTMPX
    915  1.50  christos 	logwtmpx("~", "reboot", "", 0, INIT_PROCESS);
    916  1.50  christos #endif
    917  1.51  christos #ifdef SUPPORT_UTMP
    918   1.8       cgd 	logwtmp("~", "reboot", "");
    919  1.50  christos #endif
    920  1.93    dyoung 	return (state_func_t)read_ttys;
    921   1.8       cgd }
    922   1.8       cgd 
    923   1.8       cgd /*
    924   1.8       cgd  * Open the session database.
    925   1.8       cgd  *
    926   1.8       cgd  * NB: We could pass in the size here; is it necessary?
    927   1.8       cgd  */
    928   1.8       cgd int
    929  1.39       wiz start_session_db(void)
    930   1.8       cgd {
    931  1.43     lukem 
    932   1.8       cgd 	if (session_db && (*session_db->close)(session_db))
    933  1.47  christos 		emergency("session database close: %m");
    934   1.8       cgd 	if ((session_db = dbopen(NULL, O_RDWR, 0, DB_HASH, NULL)) == 0) {
    935  1.47  christos 		emergency("session database open: %m");
    936  1.93    dyoung 		return 1;
    937   1.8       cgd 	}
    938  1.93    dyoung 	return 0;
    939   1.8       cgd 
    940   1.8       cgd }
    941   1.8       cgd 
    942   1.8       cgd /*
    943   1.8       cgd  * Add a new login session.
    944   1.8       cgd  */
    945   1.8       cgd void
    946  1.39       wiz add_session(session_t *sp)
    947   1.8       cgd {
    948   1.8       cgd 	DBT key;
    949   1.8       cgd 	DBT data;
    950   1.8       cgd 
    951  1.55  christos 	if (session_db == NULL)
    952  1.55  christos 		return;
    953  1.55  christos 
    954   1.8       cgd 	key.data = &sp->se_process;
    955   1.8       cgd 	key.size = sizeof sp->se_process;
    956   1.8       cgd 	data.data = &sp;
    957   1.8       cgd 	data.size = sizeof sp;
    958   1.8       cgd 
    959   1.8       cgd 	if ((*session_db->put)(session_db, &key, &data, 0))
    960  1.47  christos 		emergency("insert %d: %m", sp->se_process);
    961  1.77  christos #ifdef SUPPORT_UTMPX
    962  1.77  christos 	session_utmpx(sp, 1);
    963  1.77  christos #endif
    964   1.8       cgd }
    965   1.8       cgd 
    966   1.8       cgd /*
    967   1.8       cgd  * Delete an old login session.
    968   1.8       cgd  */
    969   1.8       cgd void
    970  1.39       wiz del_session(session_t *sp)
    971   1.8       cgd {
    972   1.8       cgd 	DBT key;
    973   1.8       cgd 
    974   1.8       cgd 	key.data = &sp->se_process;
    975   1.8       cgd 	key.size = sizeof sp->se_process;
    976   1.8       cgd 
    977   1.8       cgd 	if ((*session_db->del)(session_db, &key, 0))
    978  1.47  christos 		emergency("delete %d: %m", sp->se_process);
    979  1.77  christos #ifdef SUPPORT_UTMPX
    980  1.77  christos 	session_utmpx(sp, 0);
    981  1.77  christos #endif
    982   1.8       cgd }
    983   1.8       cgd 
    984   1.8       cgd /*
    985   1.8       cgd  * Look up a login session by pid.
    986   1.8       cgd  */
    987   1.8       cgd session_t *
    988   1.8       cgd find_session(pid_t pid)
    989   1.8       cgd {
    990   1.8       cgd 	DBT key;
    991   1.8       cgd 	DBT data;
    992   1.8       cgd 	session_t *ret;
    993   1.8       cgd 
    994  1.55  christos 	if (session_db == NULL)
    995  1.55  christos 		return NULL;
    996  1.55  christos 
    997   1.8       cgd 	key.data = &pid;
    998   1.8       cgd 	key.size = sizeof pid;
    999   1.8       cgd 	if ((*session_db->get)(session_db, &key, &data, 0) != 0)
   1000   1.8       cgd 		return 0;
   1001  1.47  christos 	(void)memmove(&ret, data.data, sizeof(ret));
   1002   1.8       cgd 	return ret;
   1003   1.8       cgd }
   1004   1.8       cgd 
   1005   1.8       cgd /*
   1006   1.8       cgd  * Construct an argument vector from a command line.
   1007   1.8       cgd  */
   1008   1.8       cgd char **
   1009  1.39       wiz construct_argv(char *command)
   1010   1.8       cgd {
   1011  1.27     perry 	int argc = 0;
   1012  1.47  christos 	char **argv = malloc(((strlen(command) + 1) / 2 + 1) * sizeof (char *));
   1013   1.8       cgd 	static const char separators[] = " \t";
   1014   1.8       cgd 
   1015  1.71     chris 	if (argv == NULL)
   1016  1.93    dyoung 		return NULL;
   1017  1.71     chris 
   1018  1.71     chris 	if ((argv[argc++] = strtok(command, separators)) == 0) {
   1019  1.71     chris 		free(argv);
   1020  1.93    dyoung 		return NULL;
   1021  1.71     chris 	}
   1022  1.47  christos 	while ((argv[argc++] = strtok(NULL, separators)) != NULL)
   1023   1.8       cgd 		continue;
   1024  1.93    dyoung 	return argv;
   1025   1.8       cgd }
   1026   1.8       cgd 
   1027   1.8       cgd /*
   1028   1.8       cgd  * Deallocate a session descriptor.
   1029   1.8       cgd  */
   1030   1.8       cgd void
   1031  1.39       wiz free_session(session_t *sp)
   1032   1.8       cgd {
   1033  1.43     lukem 
   1034   1.8       cgd 	free(sp->se_device);
   1035   1.8       cgd 	if (sp->se_getty) {
   1036   1.8       cgd 		free(sp->se_getty);
   1037   1.8       cgd 		free(sp->se_getty_argv);
   1038   1.8       cgd 	}
   1039   1.8       cgd 	if (sp->se_window) {
   1040   1.8       cgd 		free(sp->se_window);
   1041   1.8       cgd 		free(sp->se_window_argv);
   1042   1.8       cgd 	}
   1043   1.8       cgd 	free(sp);
   1044   1.8       cgd }
   1045   1.8       cgd 
   1046   1.8       cgd /*
   1047   1.8       cgd  * Allocate a new session descriptor.
   1048   1.8       cgd  */
   1049   1.8       cgd session_t *
   1050  1.39       wiz new_session(session_t *sprev, int session_index, struct ttyent *typ)
   1051   1.8       cgd {
   1052  1.27     perry 	session_t *sp;
   1053   1.8       cgd 
   1054  1.47  christos 	if ((typ->ty_status & TTY_ON) == 0 || typ->ty_name == NULL ||
   1055  1.27     perry 	    typ->ty_getty == NULL)
   1056  1.93    dyoung 		return NULL;
   1057   1.8       cgd 
   1058  1.47  christos 	sp = malloc(sizeof (session_t));
   1059  1.55  christos 	if (sp == NULL)
   1060  1.55  christos 		return NULL;
   1061  1.84  christos 	(void)memset(sp, 0, sizeof *sp);
   1062   1.8       cgd 
   1063  1.21   mycroft 	sp->se_flags = SE_PRESENT;
   1064   1.8       cgd 	sp->se_index = session_index;
   1065   1.8       cgd 
   1066  1.59    itojun 	(void)asprintf(&sp->se_device, "%s%s", _PATH_DEV, typ->ty_name);
   1067  1.59    itojun 	if (!sp->se_device)
   1068  1.59    itojun 		return NULL;
   1069   1.8       cgd 
   1070   1.8       cgd 	if (setupargv(sp, typ) == 0) {
   1071   1.8       cgd 		free_session(sp);
   1072  1.93    dyoung 		return NULL;
   1073   1.8       cgd 	}
   1074   1.8       cgd 
   1075  1.27     perry 	sp->se_next = NULL;
   1076  1.27     perry 	if (sprev == NULL) {
   1077   1.8       cgd 		sessions = sp;
   1078  1.27     perry 		sp->se_prev = NULL;
   1079   1.8       cgd 	} else {
   1080   1.8       cgd 		sprev->se_next = sp;
   1081   1.8       cgd 		sp->se_prev = sprev;
   1082   1.8       cgd 	}
   1083   1.8       cgd 
   1084  1.93    dyoung 	return sp;
   1085   1.8       cgd }
   1086   1.8       cgd 
   1087   1.8       cgd /*
   1088   1.8       cgd  * Calculate getty and if useful window argv vectors.
   1089   1.8       cgd  */
   1090   1.8       cgd int
   1091  1.39       wiz setupargv(session_t *sp, struct ttyent *typ)
   1092   1.8       cgd {
   1093   1.8       cgd 
   1094   1.8       cgd 	if (sp->se_getty) {
   1095   1.8       cgd 		free(sp->se_getty);
   1096   1.8       cgd 		free(sp->se_getty_argv);
   1097   1.8       cgd 	}
   1098  1.59    itojun 	(void)asprintf(&sp->se_getty, "%s %s", typ->ty_getty, typ->ty_name);
   1099  1.59    itojun 	if (!sp->se_getty)
   1100  1.93    dyoung 		return 0;
   1101   1.8       cgd 	sp->se_getty_argv = construct_argv(sp->se_getty);
   1102  1.27     perry 	if (sp->se_getty_argv == NULL) {
   1103  1.80  christos 		warning("can't parse getty for port `%s'", sp->se_device);
   1104   1.8       cgd 		free(sp->se_getty);
   1105  1.27     perry 		sp->se_getty = NULL;
   1106  1.93    dyoung 		return 0;
   1107   1.8       cgd 	}
   1108   1.8       cgd 	if (typ->ty_window) {
   1109   1.8       cgd 		if (sp->se_window)
   1110   1.8       cgd 			free(sp->se_window);
   1111   1.8       cgd 		sp->se_window = strdup(typ->ty_window);
   1112   1.8       cgd 		sp->se_window_argv = construct_argv(sp->se_window);
   1113  1.27     perry 		if (sp->se_window_argv == NULL) {
   1114  1.80  christos 			warning("can't parse window for port `%s'",
   1115  1.47  christos 			    sp->se_device);
   1116   1.8       cgd 			free(sp->se_window);
   1117  1.27     perry 			sp->se_window = NULL;
   1118  1.93    dyoung 			return 0;
   1119   1.1       cgd 		}
   1120   1.8       cgd 	}
   1121  1.93    dyoung 	return 1;
   1122   1.8       cgd }
   1123   1.8       cgd 
   1124   1.8       cgd /*
   1125   1.8       cgd  * Walk the list of ttys and create sessions for each active line.
   1126   1.8       cgd  */
   1127   1.8       cgd state_func_t
   1128  1.39       wiz read_ttys(void)
   1129   1.8       cgd {
   1130   1.8       cgd 	int session_index = 0;
   1131  1.27     perry 	session_t *sp, *snext;
   1132  1.27     perry 	struct ttyent *typ;
   1133   1.8       cgd 
   1134  1.77  christos #ifdef SUPPORT_UTMPX
   1135  1.77  christos 	if (sessions == NULL) {
   1136  1.77  christos 		struct stat st;
   1137  1.77  christos 
   1138  1.77  christos 		make_utmpx("", BOOT_MSG, BOOT_TIME, 0, &boot_time, 0);
   1139  1.77  christos 
   1140  1.77  christos 		/*
   1141  1.77  christos 		 * If wtmpx is not empty, pick the the down time from there
   1142  1.77  christos 		 */
   1143  1.87    cbiere 		if (stat(_PATH_WTMPX, &st) != -1 && st.st_size != 0) {
   1144  1.77  christos 			struct timeval down_time;
   1145  1.77  christos 
   1146  1.77  christos 			TIMESPEC_TO_TIMEVAL(&down_time,
   1147  1.77  christos 			    st.st_atime > st.st_mtime ?
   1148  1.77  christos 			    &st.st_atimespec : &st.st_mtimespec);
   1149  1.77  christos 			make_utmpx("", DOWN_MSG, DOWN_TIME, 0, &down_time, 0);
   1150  1.77  christos 		}
   1151  1.77  christos 	}
   1152  1.77  christos #endif
   1153   1.8       cgd 	/*
   1154   1.8       cgd 	 * Destroy any previous session state.
   1155   1.8       cgd 	 * There shouldn't be any, but just in case...
   1156   1.8       cgd 	 */
   1157   1.8       cgd 	for (sp = sessions; sp; sp = snext) {
   1158  1.64  christos #ifndef LETS_GET_SMALL
   1159   1.8       cgd 		if (sp->se_process)
   1160  1.50  christos 			clear_session_logs(sp, 0);
   1161  1.64  christos #endif
   1162   1.8       cgd 		snext = sp->se_next;
   1163   1.8       cgd 		free_session(sp);
   1164   1.8       cgd 	}
   1165  1.27     perry 	sessions = NULL;
   1166  1.73      salo 
   1167  1.73      salo 	if (start_session_db()) {
   1168  1.80  christos 		warning("start_session_db failed, death");
   1169  1.73      salo #ifdef CHROOT
   1170  1.73      salo 		/* If /etc/rc ran in chroot, we want to kill any survivors. */
   1171  1.73      salo 		if (did_multiuser_chroot)
   1172  1.73      salo 			return (state_func_t)death;
   1173  1.73      salo 		else
   1174  1.73      salo #endif /* CHROOT */
   1175  1.73      salo 			return (state_func_t)single_user;
   1176  1.73      salo 	}
   1177  1.73      salo 
   1178  1.84  christos 	(void)do_setttyent();
   1179   1.8       cgd 
   1180   1.8       cgd 	/*
   1181   1.8       cgd 	 * Allocate a session entry for each active port.
   1182   1.8       cgd 	 * Note that sp starts at 0.
   1183   1.8       cgd 	 */
   1184  1.27     perry 	while ((typ = getttyent()) != NULL)
   1185  1.27     perry 		if ((snext = new_session(sp, ++session_index, typ)) != NULL)
   1186   1.8       cgd 			sp = snext;
   1187  1.84  christos 	(void)endttyent();
   1188   1.8       cgd 
   1189  1.47  christos 	return (state_func_t)multi_user;
   1190   1.8       cgd }
   1191   1.8       cgd 
   1192   1.8       cgd /*
   1193   1.8       cgd  * Start a window system running.
   1194   1.8       cgd  */
   1195   1.8       cgd void
   1196  1.39       wiz start_window_system(session_t *sp)
   1197   1.8       cgd {
   1198   1.8       cgd 	pid_t pid;
   1199   1.8       cgd 	sigset_t mask;
   1200   1.8       cgd 
   1201   1.8       cgd 	if ((pid = fork()) == -1) {
   1202  1.80  christos 		emergency("can't fork for window system on port `%s': %m",
   1203  1.47  christos 		    sp->se_device);
   1204   1.8       cgd 		/* hope that getty fails and we can try again */
   1205   1.8       cgd 		return;
   1206   1.8       cgd 	}
   1207   1.8       cgd 
   1208   1.8       cgd 	if (pid)
   1209   1.8       cgd 		return;
   1210   1.8       cgd 
   1211  1.84  christos 	(void)sigemptyset(&mask);
   1212  1.84  christos 	(void)sigprocmask(SIG_SETMASK, &mask, NULL);
   1213   1.8       cgd 
   1214   1.8       cgd 	if (setsid() < 0)
   1215  1.80  christos 		emergency("setsid failed (window): %m");
   1216   1.8       cgd 
   1217  1.47  christos 	(void)execv(sp->se_window_argv[0], sp->se_window_argv);
   1218  1.80  christos 	stall("can't exec window system `%s' for port `%s': %m",
   1219  1.47  christos 	    sp->se_window_argv[0], sp->se_device);
   1220  1.91       dsl 	_exit(6);
   1221   1.8       cgd }
   1222   1.8       cgd 
   1223   1.8       cgd /*
   1224   1.8       cgd  * Start a login session running.
   1225   1.8       cgd  */
   1226   1.8       cgd pid_t
   1227  1.39       wiz start_getty(session_t *sp)
   1228   1.8       cgd {
   1229   1.8       cgd 	pid_t pid;
   1230   1.8       cgd 	sigset_t mask;
   1231  1.47  christos 	time_t current_time = time(NULL);
   1232   1.8       cgd 
   1233   1.8       cgd 	/*
   1234   1.8       cgd 	 * fork(), not vfork() -- we can't afford to block.
   1235   1.8       cgd 	 */
   1236   1.8       cgd 	if ((pid = fork()) == -1) {
   1237  1.80  christos 		emergency("can't fork for getty on port `%s': %m",
   1238  1.80  christos 		    sp->se_device);
   1239   1.8       cgd 		return -1;
   1240   1.8       cgd 	}
   1241   1.8       cgd 
   1242   1.8       cgd 	if (pid)
   1243   1.8       cgd 		return pid;
   1244   1.8       cgd 
   1245  1.73      salo #ifdef CHROOT
   1246  1.73      salo 	/* If /etc/rc did proceed inside chroot, we have to try as well. */
   1247  1.73      salo 	if (did_multiuser_chroot)
   1248  1.73      salo 		if (chroot(rootdir) != 0) {
   1249  1.80  christos 			stall("can't chroot getty `%s' inside `%s': %m",
   1250  1.73      salo 			    sp->se_getty_argv[0], rootdir);
   1251  1.91       dsl 			_exit(7);
   1252  1.73      salo 		}
   1253  1.73      salo #endif /* CHROOT */
   1254  1.73      salo 
   1255  1.77  christos 	if (current_time > sp->se_started.tv_sec &&
   1256  1.77  christos 	    current_time - sp->se_started.tv_sec < GETTY_SPACING) {
   1257  1.80  christos 		warning("getty repeating too quickly on port `%s', sleeping",
   1258  1.47  christos 		    sp->se_device);
   1259  1.47  christos 		(void)sleep(GETTY_SLEEP);
   1260   1.8       cgd 	}
   1261   1.8       cgd 
   1262   1.8       cgd 	if (sp->se_window) {
   1263   1.8       cgd 		start_window_system(sp);
   1264  1.47  christos 		(void)sleep(WINDOW_WAIT);
   1265   1.1       cgd 	}
   1266   1.8       cgd 
   1267  1.47  christos 	(void)sigemptyset(&mask);
   1268  1.47  christos 	(void)sigprocmask(SIG_SETMASK, &mask, (sigset_t *) 0);
   1269   1.8       cgd 
   1270  1.47  christos 	(void)execv(sp->se_getty_argv[0], sp->se_getty_argv);
   1271  1.80  christos 	stall("can't exec getty `%s' for port `%s': %m",
   1272  1.47  christos 	    sp->se_getty_argv[0], sp->se_device);
   1273  1.91       dsl 	_exit(8);
   1274  1.47  christos 	/*NOTREACHED*/
   1275   1.1       cgd }
   1276  1.77  christos #ifdef SUPPORT_UTMPX
   1277  1.77  christos static void
   1278  1.77  christos session_utmpx(const session_t *sp, int add)
   1279  1.77  christos {
   1280  1.77  christos 	const char *name = sp->se_getty ? sp->se_getty :
   1281  1.77  christos 	    (sp->se_window ? sp->se_window : "");
   1282  1.77  christos 	const char *line = sp->se_device + sizeof(_PATH_DEV) - 1;
   1283  1.77  christos 
   1284  1.77  christos 	make_utmpx(name, line, add ? LOGIN_PROCESS : DEAD_PROCESS,
   1285  1.77  christos 	    sp->se_process, &sp->se_started, sp->se_index);
   1286  1.77  christos }
   1287  1.77  christos 
   1288  1.77  christos static void
   1289  1.77  christos make_utmpx(const char *name, const char *line, int type, pid_t pid,
   1290  1.77  christos     const struct timeval *tv, int session)
   1291  1.77  christos {
   1292  1.77  christos 	struct utmpx ut;
   1293  1.87    cbiere 	const char *eline;
   1294  1.77  christos 
   1295  1.77  christos 	(void)memset(&ut, 0, sizeof(ut));
   1296  1.77  christos 	(void)strlcpy(ut.ut_name, name, sizeof(ut.ut_name));
   1297  1.77  christos 	ut.ut_type = type;
   1298  1.77  christos 	(void)strlcpy(ut.ut_line, line, sizeof(ut.ut_line));
   1299  1.77  christos 	ut.ut_pid = pid;
   1300  1.77  christos 	if (tv)
   1301  1.77  christos 		ut.ut_tv = *tv;
   1302  1.77  christos 	else
   1303  1.77  christos 		(void)gettimeofday(&ut.ut_tv, NULL);
   1304  1.77  christos 	ut.ut_session = session;
   1305  1.77  christos 
   1306  1.87    cbiere 	eline = line + strlen(line);
   1307  1.97     lukem 	if ((size_t)(eline - line) >= sizeof(ut.ut_id))
   1308  1.87    cbiere 		line = eline - sizeof(ut.ut_id);
   1309  1.77  christos 	(void)strncpy(ut.ut_id, line, sizeof(ut.ut_id));
   1310  1.77  christos 
   1311  1.77  christos 	if (pututxline(&ut) == NULL)
   1312  1.80  christos 		warning("can't add utmpx record for `%s': %m", ut.ut_line);
   1313  1.84  christos 	endutxent();
   1314  1.77  christos }
   1315  1.77  christos 
   1316  1.77  christos static char
   1317  1.77  christos get_runlevel(const state_t s)
   1318  1.77  christos {
   1319  1.77  christos 	if (s == (state_t)single_user)
   1320  1.77  christos 		return SINGLE_USER;
   1321  1.77  christos 	if (s == (state_t)runcom)
   1322  1.77  christos 		return RUNCOM;
   1323  1.77  christos 	if (s == (state_t)read_ttys)
   1324  1.77  christos 		return READ_TTYS;
   1325  1.77  christos 	if (s == (state_t)multi_user)
   1326  1.77  christos 		return MULTI_USER;
   1327  1.77  christos 	if (s == (state_t)clean_ttys)
   1328  1.77  christos 		return CLEAN_TTYS;
   1329  1.77  christos 	if (s == (state_t)catatonia)
   1330  1.77  christos 		return CATATONIA;
   1331  1.77  christos 	return DEATH;
   1332  1.77  christos }
   1333  1.77  christos 
   1334  1.77  christos static void
   1335  1.77  christos utmpx_set_runlevel(char old, char new)
   1336  1.77  christos {
   1337  1.77  christos 	struct utmpx ut;
   1338  1.77  christos 
   1339  1.81  christos 	/*
   1340  1.81  christos 	 * Don't record any transitions until we did the first transition
   1341  1.81  christos 	 * to read ttys, which is when we are guaranteed to have a read-write
   1342  1.81  christos 	 * /var. Perhaps use a different variable for this?
   1343  1.81  christos 	 */
   1344  1.81  christos 	if (sessions == NULL)
   1345  1.81  christos 		return;
   1346  1.81  christos 
   1347  1.77  christos 	(void)memset(&ut, 0, sizeof(ut));
   1348  1.77  christos 	(void)snprintf(ut.ut_line, sizeof(ut.ut_line), RUNLVL_MSG, new);
   1349  1.77  christos 	ut.ut_type = RUN_LVL;
   1350  1.77  christos 	(void)gettimeofday(&ut.ut_tv, NULL);
   1351  1.77  christos 	ut.ut_exit.e_exit = old;
   1352  1.77  christos 	ut.ut_exit.e_termination = new;
   1353  1.77  christos 	if (pututxline(&ut) == NULL)
   1354  1.80  christos 		warning("can't add utmpx record for `runlevel': %m");
   1355  1.84  christos 	endutxent();
   1356  1.77  christos }
   1357  1.77  christos #endif /* SUPPORT_UTMPX */
   1358  1.77  christos 
   1359  1.13       cgd #endif /* LETS_GET_SMALL */
   1360   1.1       cgd 
   1361   1.8       cgd /*
   1362   1.8       cgd  * Collect exit status for a child.
   1363   1.8       cgd  * If an exiting login, start a new login running.
   1364   1.8       cgd  */
   1365   1.8       cgd void
   1366  1.50  christos collect_child(pid_t pid, int status)
   1367   1.1       cgd {
   1368  1.13       cgd #ifndef LETS_GET_SMALL
   1369  1.27     perry 	session_t *sp, *sprev, *snext;
   1370   1.8       cgd 
   1371   1.8       cgd 	if (! sessions)
   1372   1.8       cgd 		return;
   1373   1.8       cgd 
   1374  1.47  christos 	if ((sp = find_session(pid)) == NULL)
   1375   1.8       cgd 		return;
   1376   1.1       cgd 
   1377  1.50  christos 	clear_session_logs(sp, status);
   1378   1.8       cgd 	del_session(sp);
   1379   1.8       cgd 	sp->se_process = 0;
   1380   1.8       cgd 
   1381   1.8       cgd 	if (sp->se_flags & SE_SHUTDOWN) {
   1382  1.27     perry 		if ((sprev = sp->se_prev) != NULL)
   1383   1.8       cgd 			sprev->se_next = sp->se_next;
   1384   1.8       cgd 		else
   1385   1.8       cgd 			sessions = sp->se_next;
   1386  1.27     perry 		if ((snext = sp->se_next) != NULL)
   1387   1.8       cgd 			snext->se_prev = sp->se_prev;
   1388   1.8       cgd 		free_session(sp);
   1389   1.1       cgd 		return;
   1390   1.1       cgd 	}
   1391   1.8       cgd 
   1392   1.8       cgd 	if ((pid = start_getty(sp)) == -1) {
   1393   1.8       cgd 		/* serious trouble */
   1394   1.8       cgd 		requested_transition = clean_ttys;
   1395   1.1       cgd 		return;
   1396   1.1       cgd 	}
   1397   1.8       cgd 
   1398   1.8       cgd 	sp->se_process = pid;
   1399  1.77  christos 	(void)gettimeofday(&sp->se_started, NULL);
   1400   1.8       cgd 	add_session(sp);
   1401  1.13       cgd #endif /* LETS_GET_SMALL */
   1402   1.8       cgd }
   1403   1.8       cgd 
   1404   1.8       cgd /*
   1405   1.8       cgd  * Catch a signal and request a state transition.
   1406   1.8       cgd  */
   1407   1.8       cgd void
   1408  1.39       wiz transition_handler(int sig)
   1409   1.8       cgd {
   1410   1.8       cgd 
   1411   1.8       cgd 	switch (sig) {
   1412  1.13       cgd #ifndef LETS_GET_SMALL
   1413   1.8       cgd 	case SIGHUP:
   1414   1.8       cgd 		requested_transition = clean_ttys;
   1415   1.8       cgd 		break;
   1416   1.8       cgd 	case SIGTERM:
   1417   1.8       cgd 		requested_transition = death;
   1418   1.8       cgd 		break;
   1419   1.8       cgd 	case SIGTSTP:
   1420   1.8       cgd 		requested_transition = catatonia;
   1421   1.8       cgd 		break;
   1422  1.13       cgd #endif /* LETS_GET_SMALL */
   1423   1.8       cgd 	default:
   1424   1.8       cgd 		requested_transition = 0;
   1425   1.8       cgd 		break;
   1426   1.8       cgd 	}
   1427   1.8       cgd }
   1428   1.8       cgd 
   1429  1.13       cgd #ifndef LETS_GET_SMALL
   1430   1.8       cgd /*
   1431   1.8       cgd  * Take the system multiuser.
   1432   1.8       cgd  */
   1433   1.8       cgd state_func_t
   1434  1.39       wiz multi_user(void)
   1435   1.8       cgd {
   1436   1.8       cgd 	pid_t pid;
   1437  1.50  christos 	int status;
   1438  1.27     perry 	session_t *sp;
   1439   1.8       cgd 
   1440   1.8       cgd 	requested_transition = 0;
   1441   1.8       cgd 
   1442   1.8       cgd 	/*
   1443   1.8       cgd 	 * If the administrator has not set the security level to -1
   1444   1.8       cgd 	 * to indicate that the kernel should not run multiuser in secure
   1445   1.8       cgd 	 * mode, and the run script has not set a higher level of security
   1446   1.8       cgd 	 * than level 1, then put the kernel into secure mode.
   1447   1.8       cgd 	 */
   1448   1.8       cgd 	if (getsecuritylevel() == 0)
   1449   1.8       cgd 		setsecuritylevel(1);
   1450   1.8       cgd 
   1451   1.8       cgd 	for (sp = sessions; sp; sp = sp->se_next) {
   1452   1.8       cgd 		if (sp->se_process)
   1453   1.8       cgd 			continue;
   1454   1.8       cgd 		if ((pid = start_getty(sp)) == -1) {
   1455   1.8       cgd 			/* serious trouble */
   1456   1.8       cgd 			requested_transition = clean_ttys;
   1457   1.1       cgd 			break;
   1458   1.8       cgd 		}
   1459   1.8       cgd 		sp->se_process = pid;
   1460  1.77  christos 		(void)gettimeofday(&sp->se_started, NULL);
   1461   1.8       cgd 		add_session(sp);
   1462   1.1       cgd 	}
   1463   1.8       cgd 
   1464   1.8       cgd 	while (!requested_transition)
   1465  1.50  christos 		if ((pid = waitpid(-1, &status, 0)) != -1)
   1466  1.50  christos 			collect_child(pid, status);
   1467   1.8       cgd 
   1468  1.47  christos 	return (state_func_t)requested_transition;
   1469   1.1       cgd }
   1470   1.1       cgd 
   1471   1.8       cgd /*
   1472   1.8       cgd  * This is an n-squared algorithm.  We hope it isn't run often...
   1473   1.8       cgd  */
   1474   1.8       cgd state_func_t
   1475  1.39       wiz clean_ttys(void)
   1476   1.1       cgd {
   1477  1.27     perry 	session_t *sp, *sprev;
   1478  1.27     perry 	struct ttyent *typ;
   1479  1.27     perry 	int session_index = 0;
   1480  1.27     perry 	int devlen;
   1481   1.8       cgd 
   1482  1.21   mycroft 	for (sp = sessions; sp; sp = sp->se_next)
   1483  1.21   mycroft 		sp->se_flags &= ~SE_PRESENT;
   1484  1.21   mycroft 
   1485  1.84  christos 	(void)do_setttyent();
   1486  1.73      salo 
   1487   1.8       cgd 	devlen = sizeof(_PATH_DEV) - 1;
   1488  1.27     perry 	while ((typ = getttyent()) != NULL) {
   1489   1.8       cgd 		++session_index;
   1490   1.8       cgd 
   1491   1.8       cgd 		for (sprev = 0, sp = sessions; sp; sprev = sp, sp = sp->se_next)
   1492   1.8       cgd 			if (strcmp(typ->ty_name, sp->se_device + devlen) == 0)
   1493   1.8       cgd 				break;
   1494   1.8       cgd 
   1495   1.8       cgd 		if (sp) {
   1496  1.21   mycroft 			sp->se_flags |= SE_PRESENT;
   1497   1.8       cgd 			if (sp->se_index != session_index) {
   1498  1.80  christos 				warning("port `%s' changed utmp index from "
   1499  1.47  christos 				    "%d to %d", sp->se_device, sp->se_index,
   1500  1.47  christos 				    session_index);
   1501   1.8       cgd 				sp->se_index = session_index;
   1502   1.8       cgd 			}
   1503   1.8       cgd 			if ((typ->ty_status & TTY_ON) == 0 ||
   1504   1.8       cgd 			    typ->ty_getty == 0) {
   1505   1.8       cgd 				sp->se_flags |= SE_SHUTDOWN;
   1506  1.55  christos 				if (sp->se_process != 0)
   1507  1.55  christos 					(void)kill(sp->se_process, SIGHUP);
   1508   1.8       cgd 				continue;
   1509   1.8       cgd 			}
   1510   1.8       cgd 			sp->se_flags &= ~SE_SHUTDOWN;
   1511   1.8       cgd 			if (setupargv(sp, typ) == 0) {
   1512  1.80  christos 				warning("can't parse getty for port `%s'",
   1513  1.47  christos 				    sp->se_device);
   1514   1.8       cgd 				sp->se_flags |= SE_SHUTDOWN;
   1515  1.55  christos 				if (sp->se_process != 0)
   1516  1.55  christos 					(void)kill(sp->se_process, SIGHUP);
   1517   1.8       cgd 			}
   1518   1.8       cgd 			continue;
   1519   1.8       cgd 		}
   1520   1.8       cgd 
   1521  1.84  christos 		(void)new_session(sprev, session_index, typ);
   1522   1.8       cgd 	}
   1523   1.8       cgd 
   1524  1.84  christos 	(void)endttyent();
   1525  1.21   mycroft 
   1526  1.21   mycroft 	for (sp = sessions; sp; sp = sp->se_next)
   1527  1.21   mycroft 		if ((sp->se_flags & SE_PRESENT) == 0) {
   1528  1.21   mycroft 			sp->se_flags |= SE_SHUTDOWN;
   1529  1.55  christos 			if (sp->se_process != 0)
   1530  1.55  christos 				(void)kill(sp->se_process, SIGHUP);
   1531  1.21   mycroft 		}
   1532   1.1       cgd 
   1533  1.47  christos 	return (state_func_t)multi_user;
   1534   1.1       cgd }
   1535   1.1       cgd 
   1536   1.8       cgd /*
   1537   1.8       cgd  * Block further logins.
   1538   1.8       cgd  */
   1539   1.8       cgd state_func_t
   1540  1.39       wiz catatonia(void)
   1541   1.1       cgd {
   1542  1.27     perry 	session_t *sp;
   1543   1.8       cgd 
   1544   1.8       cgd 	for (sp = sessions; sp; sp = sp->se_next)
   1545   1.8       cgd 		sp->se_flags |= SE_SHUTDOWN;
   1546   1.1       cgd 
   1547  1.47  christos 	return (state_func_t)multi_user;
   1548   1.1       cgd }
   1549  1.13       cgd #endif /* LETS_GET_SMALL */
   1550   1.1       cgd 
   1551   1.8       cgd /*
   1552   1.8       cgd  * Note SIGALRM.
   1553   1.8       cgd  */
   1554   1.8       cgd void
   1555  1.47  christos /*ARGSUSED*/
   1556  1.39       wiz alrm_handler(int sig)
   1557   1.1       cgd {
   1558  1.43     lukem 
   1559   1.8       cgd 	clang = 1;
   1560   1.1       cgd }
   1561   1.1       cgd 
   1562  1.13       cgd #ifndef LETS_GET_SMALL
   1563   1.8       cgd /*
   1564   1.8       cgd  * Bring the system down to single user.
   1565   1.8       cgd  */
   1566   1.8       cgd state_func_t
   1567  1.39       wiz death(void)
   1568   1.1       cgd {
   1569  1.27     perry 	session_t *sp;
   1570  1.50  christos 	int i, status;
   1571   1.8       cgd 	pid_t pid;
   1572   1.8       cgd 	static const int death_sigs[3] = { SIGHUP, SIGTERM, SIGKILL };
   1573   1.8       cgd 
   1574   1.8       cgd 	for (sp = sessions; sp; sp = sp->se_next)
   1575   1.8       cgd 		sp->se_flags |= SE_SHUTDOWN;
   1576   1.8       cgd 
   1577   1.8       cgd 	/* NB: should send a message to the session logger to avoid blocking. */
   1578  1.50  christos #ifdef SUPPORT_UTMPX
   1579  1.50  christos 	logwtmpx("~", "shutdown", "", 0, INIT_PROCESS);
   1580  1.50  christos #endif
   1581  1.50  christos #ifdef SUPPORT_UTMP
   1582   1.8       cgd 	logwtmp("~", "shutdown", "");
   1583  1.50  christos #endif
   1584   1.8       cgd 
   1585   1.8       cgd 	for (i = 0; i < 3; ++i) {
   1586   1.8       cgd 		if (kill(-1, death_sigs[i]) == -1 && errno == ESRCH)
   1587  1.47  christos 			return (state_func_t)single_user;
   1588   1.8       cgd 
   1589   1.8       cgd 		clang = 0;
   1590  1.84  christos 		(void)alarm(DEATH_WATCH);
   1591   1.8       cgd 		do
   1592  1.50  christos 			if ((pid = waitpid(-1, &status, 0)) != -1)
   1593  1.50  christos 				collect_child(pid, status);
   1594   1.8       cgd 		while (clang == 0 && errno != ECHILD);
   1595   1.8       cgd 
   1596   1.8       cgd 		if (errno == ECHILD)
   1597  1.47  christos 			return (state_func_t)single_user;
   1598   1.8       cgd 	}
   1599   1.8       cgd 
   1600   1.8       cgd 	warning("some processes would not die; ps axl advised");
   1601   1.8       cgd 
   1602  1.47  christos 	return (state_func_t)single_user;
   1603   1.1       cgd }
   1604  1.13       cgd #endif /* LETS_GET_SMALL */
   1605  1.28  christos 
   1606  1.45       abs #ifdef MFS_DEV_IF_NO_CONSOLE
   1607  1.28  christos 
   1608  1.45       abs static int
   1609  1.45       abs mfs_dev(void)
   1610  1.28  christos {
   1611  1.28  christos 	/*
   1612  1.28  christos 	 * We cannot print errors so we bail out silently...
   1613  1.28  christos 	 */
   1614  1.28  christos 	pid_t pid;
   1615  1.30  drochner 	int status;
   1616  1.46     lukem 
   1617  1.45       abs 	/* If we have /dev/console, assume all is OK  */
   1618  1.91       dsl 	if (access(_PATH_CONSOLE, F_OK) == 0)
   1619  1.91       dsl 		return 0;
   1620  1.28  christos 
   1621  1.91       dsl #if 0	/* Useful for testing MAKEDEV */
   1622  1.91       dsl 	/* Mount an mfs over /mnt so we can create a console entry */
   1623  1.28  christos 	switch ((pid = fork())) {
   1624  1.28  christos 	case 0:
   1625  1.62       dsl 		(void)execl(INIT_MOUNT_MFS, "mount_mfs",
   1626  1.62       dsl 		    "-b", "4096", "-f", "512",
   1627  1.91       dsl 		    "-s", 64, "-n", 10,
   1628  1.68       dan 		    "-p", "0755",
   1629  1.91       dsl 		    "swap", "/mnt", NULL);
   1630  1.91       dsl 		_exit(9);
   1631  1.47  christos 		/*NOTREACHED*/
   1632  1.28  christos 
   1633  1.28  christos 	case -1:
   1634  1.45       abs 		return(-1);
   1635  1.28  christos 
   1636  1.28  christos 	default:
   1637  1.28  christos 		if (waitpid(pid, &status, 0) == -1)
   1638  1.45       abs 			return(-1);
   1639  1.28  christos 		if (status != 0)
   1640  1.45       abs 			return(-1);
   1641  1.28  christos 		break;
   1642  1.28  christos 	}
   1643  1.28  christos 
   1644  1.91       dsl 	{
   1645  1.95  christos 		dev_t dev;
   1646  1.28  christos #ifdef CPU_CONSDEV
   1647  1.91       dsl 		static int name[2] = { CTL_MACHDEP, CPU_CONSDEV };
   1648  1.91       dsl 		size_t olen;
   1649  1.91       dsl 		olen = sizeof(dev);
   1650  1.91       dsl 		if (sysctl(name, sizeof(name) / sizeof(name[0]), &dev, &olen,
   1651  1.91       dsl 		    NULL, 0) == -1)
   1652  1.46     lukem #endif
   1653  1.91       dsl 			dev = makedev(0, 0);
   1654  1.95  christos 
   1655  1.95  christos 		/* Make a console for us, so we can see things happening */
   1656  1.95  christos 		if (mknod("/mnt/console", 0666 | S_IFCHR, dev) == -1)
   1657  1.95  christos 			return(-1);
   1658  1.95  christos 		(void)freopen("/mnt/console", "a", stderr);
   1659  1.91       dsl 	}
   1660  1.28  christos 
   1661  1.91       dsl #endif
   1662  1.28  christos 
   1663  1.28  christos 	/* Run the makedev script to create devices */
   1664  1.28  christos 	switch ((pid = fork())) {
   1665  1.28  christos 	case 0:
   1666  1.84  christos 		(void)dup2(2, 1);	/* Give the script stdout */
   1667  1.60       dsl 		if (chdir("/dev") == 0)
   1668  1.62       dsl 			(void)execl(INIT_BSHELL, "sh",
   1669  1.91       dsl 			    access("./MAKEDEV", X_OK) == 0
   1670  1.91       dsl 				? "./MAKEDEV" : "/etc/MAKEDEV",
   1671  1.94       apb 			    "-MM", "init", NULL);
   1672  1.91       dsl 		_exit(10);
   1673  1.73      salo 		/* NOTREACHED */
   1674  1.28  christos 
   1675  1.28  christos 	case -1:
   1676  1.60       dsl 		break;
   1677  1.28  christos 
   1678  1.28  christos 	default:
   1679  1.28  christos 		if (waitpid(pid, &status, 0) == -1)
   1680  1.60       dsl 			break;
   1681  1.47  christos 		if (status != 0) {
   1682  1.47  christos 			errno = EINVAL;
   1683  1.60       dsl 			break;
   1684  1.47  christos 		}
   1685  1.91       dsl 		/* Check /dev/console got created */
   1686  1.91       dsl 		if (access(_PATH_CONSOLE, F_OK) == 0)
   1687  1.91       dsl 			return 0;
   1688  1.91       dsl 		_exit(11);
   1689  1.28  christos 	}
   1690  1.47  christos 	warn("Unable to run MAKEDEV");
   1691  1.91       dsl 	_exit(12);
   1692  1.28  christos }
   1693  1.28  christos #endif
   1694  1.73      salo 
   1695  1.73      salo int
   1696  1.73      salo do_setttyent(void)
   1697  1.73      salo {
   1698  1.84  christos 	(void)endttyent();
   1699  1.73      salo #ifdef CHROOT
   1700  1.73      salo 	if (did_multiuser_chroot) {
   1701  1.73      salo 		char path[PATH_MAX];
   1702  1.73      salo 
   1703  1.84  christos 		(void)snprintf(path, sizeof(path), "%s/%s", rootdir, _PATH_TTYS);
   1704  1.73      salo 
   1705  1.73      salo 		return setttyentpath(path);
   1706  1.73      salo 	} else
   1707  1.73      salo #endif /* CHROOT */
   1708  1.73      salo 		return setttyent();
   1709  1.73      salo }
   1710  1.73      salo 
   1711  1.73      salo #if !defined(LETS_GET_SMALL) && defined(CHROOT)
   1712  1.73      salo 
   1713  1.73      salo int
   1714  1.73      salo createsysctlnode()
   1715  1.73      salo {
   1716  1.73      salo 	struct sysctlnode node;
   1717  1.73      salo 	int mib[2];
   1718  1.73      salo 	size_t len;
   1719  1.73      salo 
   1720  1.73      salo 	/*
   1721  1.73      salo 	 * Create top-level dynamic sysctl node.  Its child nodes will only
   1722  1.73      salo 	 * be readable by the superuser, since regular mortals should not
   1723  1.76      elad 	 * care ("Sssh, it's a secret!").
   1724  1.73      salo 	 */
   1725  1.73      salo 	len = sizeof(struct sysctlnode);
   1726  1.73      salo 	mib[0] = CTL_CREATE;
   1727  1.73      salo 
   1728  1.84  christos 	(void)memset(&node, 0, len);
   1729  1.73      salo 	node.sysctl_flags = SYSCTL_VERSION | CTLFLAG_READWRITE |
   1730  1.74      elad 	    CTLFLAG_PRIVATE | CTLTYPE_NODE;
   1731  1.73      salo 	node.sysctl_num = CTL_CREATE;
   1732  1.84  christos 	(void)snprintf(node.sysctl_name, SYSCTL_NAMELEN, "init");
   1733  1.73      salo 	if (sysctl(&mib[0], 1, &node, &len, &node, len) == -1) {
   1734  1.80  christos 		warning("could not create init node: %m");
   1735  1.93    dyoung 		return -1;
   1736  1.73      salo 	}
   1737  1.73      salo 
   1738  1.73      salo 	/*
   1739  1.73      salo 	 * Create second level dynamic node capable of holding pathname.
   1740  1.73      salo 	 * Provide "/" as the default value.
   1741  1.73      salo 	 */
   1742  1.73      salo 	len = sizeof(struct sysctlnode);
   1743  1.73      salo 	mib[0] = node.sysctl_num;
   1744  1.73      salo 	mib[1] = CTL_CREATE;
   1745  1.73      salo 
   1746  1.84  christos 	(void)memset(&node, 0, len);
   1747  1.73      salo 	node.sysctl_flags = SYSCTL_VERSION | CTLFLAG_READWRITE |
   1748  1.75      elad 	    CTLTYPE_STRING | CTLFLAG_OWNDATA;
   1749  1.73      salo 	node.sysctl_size = _POSIX_PATH_MAX;
   1750  1.73      salo 	node.sysctl_data = __UNCONST("/");
   1751  1.73      salo 	node.sysctl_num = CTL_CREATE;
   1752  1.84  christos 	(void)snprintf(node.sysctl_name, SYSCTL_NAMELEN, "root");
   1753  1.73      salo 	if (sysctl(&mib[0], 2, NULL, NULL, &node, len) == -1) {
   1754  1.80  christos 		warning("could not create init.root node: %m");
   1755  1.93    dyoung 		return -1;
   1756  1.73      salo 	}
   1757  1.73      salo 
   1758  1.93    dyoung 	return 0;
   1759  1.73      salo }
   1760  1.73      salo 
   1761  1.73      salo int
   1762  1.73      salo shouldchroot()
   1763  1.73      salo {
   1764  1.73      salo 	struct sysctlnode node;
   1765  1.73      salo 	size_t len, cnt;
   1766  1.73      salo 	int mib;
   1767  1.73      salo 
   1768  1.73      salo 	len = sizeof(struct sysctlnode);
   1769  1.73      salo 
   1770  1.73      salo 	if (sysctlbyname("init.root", rootdir, &len, NULL, 0) == -1) {
   1771  1.80  christos 		warning("could not read init.root: %m");
   1772  1.73      salo 
   1773  1.73      salo 		/* Child killed our node. Recreate it. */
   1774  1.73      salo 		if (errno == ENOENT) {
   1775  1.73      salo 			/* Destroy whatever is left, recreate from scratch. */
   1776  1.73      salo 			if (sysctlnametomib("init", &mib, &cnt) != -1) {
   1777  1.84  christos 				(void)memset(&node, 0, sizeof(node));
   1778  1.73      salo 				node.sysctl_flags = SYSCTL_VERSION;
   1779  1.73      salo 				node.sysctl_num = mib;
   1780  1.73      salo 				mib = CTL_DESTROY;
   1781  1.73      salo 
   1782  1.73      salo 				(void)sysctl(&mib, 1, NULL, NULL, &node,
   1783  1.73      salo 				    sizeof(node));
   1784  1.73      salo 			}
   1785  1.73      salo 
   1786  1.84  christos 			(void)createsysctlnode();
   1787  1.73      salo 		}
   1788  1.73      salo 
   1789  1.73      salo 		/* We certainly won't chroot. */
   1790  1.93    dyoung 		return 0;
   1791  1.73      salo 	}
   1792  1.73      salo 
   1793  1.73      salo 	if (rootdir[len] != '\0' || strlen(rootdir) != len - 1) {
   1794  1.73      salo 		warning("init.root is not a string");
   1795  1.93    dyoung 		return 0;
   1796  1.73      salo 	}
   1797  1.73      salo 
   1798  1.73      salo 	if (strcmp(rootdir, "/") == 0)
   1799  1.93    dyoung 		return 0;
   1800  1.73      salo 
   1801  1.93    dyoung 	return 1;
   1802  1.73      salo }
   1803  1.73      salo 
   1804  1.73      salo #endif /* !LETS_GET_SMALL && CHROOT */
   1805