1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2010 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <dbus/dbus.h>
28 #include <sys/types.h>
34 #include <sys/prctl.h>
35 #include <sys/mount.h>
39 #include "load-fragment.h"
42 #include "conf-parser.h"
43 #include "bus-errors.h"
51 #include "path-util.h"
52 #include "switch-root.h"
53 #include "capability.h"
57 #include "sd-daemon.h"
59 #include "mount-setup.h"
60 #include "loopback-setup.h"
62 #include "kmod-setup.h"
64 #include "hostname-setup.h"
65 #include "machine-id-setup.h"
66 #include "locale-setup.h"
67 #include "selinux-setup.h"
68 #include "ima-setup.h"
75 ACTION_DUMP_CONFIGURATION_ITEMS,
77 } arg_action = ACTION_RUN;
79 static char *arg_default_unit = NULL;
80 static SystemdRunningAs arg_running_as = _SYSTEMD_RUNNING_AS_INVALID;
82 static bool arg_dump_core = true;
83 static bool arg_crash_shell = false;
84 static int arg_crash_chvt = -1;
85 static bool arg_confirm_spawn = false;
86 static bool arg_show_status = true;
87 static bool arg_switched_root = false;
88 static char **arg_default_controllers = NULL;
89 static char ***arg_join_controllers = NULL;
90 static ExecOutput arg_default_std_output = EXEC_OUTPUT_JOURNAL;
91 static ExecOutput arg_default_std_error = EXEC_OUTPUT_INHERIT;
92 static usec_t arg_runtime_watchdog = 0;
93 static usec_t arg_shutdown_watchdog = 10 * USEC_PER_MINUTE;
94 static struct rlimit *arg_default_rlimit[RLIMIT_NLIMITS] = {};
95 static uint64_t arg_capability_bounding_set_drop = 0;
96 static nsec_t arg_timer_slack_nsec = (nsec_t) -1;
98 static FILE* serialization = NULL;
100 static void nop_handler(int sig) {
103 _noreturn_ static void crash(int sig) {
106 log_error("Caught <%s>, not dumping core.", signal_to_string(sig));
111 /* We want to wait for the core process, hence let's enable SIGCHLD */
113 sa.sa_handler = nop_handler;
114 sa.sa_flags = SA_NOCLDSTOP|SA_RESTART;
115 assert_se(sigaction(SIGCHLD, &sa, NULL) == 0);
117 if ((pid = fork()) < 0)
118 log_error("Caught <%s>, cannot fork for core dump: %s", signal_to_string(sig), strerror(errno));
123 /* Enable default signal handler for core dump */
125 sa.sa_handler = SIG_DFL;
126 assert_se(sigaction(sig, &sa, NULL) == 0);
128 /* Don't limit the core dump size */
130 rl.rlim_cur = RLIM_INFINITY;
131 rl.rlim_max = RLIM_INFINITY;
132 setrlimit(RLIMIT_CORE, &rl);
134 /* Just to be sure... */
135 assert_se(chdir("/") == 0);
137 /* Raise the signal again */
140 assert_not_reached("We shouldn't be here...");
147 /* Order things nicely. */
148 if ((r = wait_for_terminate(pid, &status)) < 0)
149 log_error("Caught <%s>, waitpid() failed: %s", signal_to_string(sig), strerror(-r));
150 else if (status.si_code != CLD_DUMPED)
151 log_error("Caught <%s>, core dump failed.", signal_to_string(sig));
153 log_error("Caught <%s>, dumped core as pid %lu.", signal_to_string(sig), (unsigned long) pid);
158 chvt(arg_crash_chvt);
160 if (arg_crash_shell) {
164 log_info("Executing crash shell in 10s...");
167 /* Let the kernel reap children for us */
169 sa.sa_handler = SIG_IGN;
170 sa.sa_flags = SA_NOCLDSTOP|SA_NOCLDWAIT|SA_RESTART;
171 assert_se(sigaction(SIGCHLD, &sa, NULL) == 0);
175 log_error("Failed to fork off crash shell: %m");
177 make_console_stdio();
178 execl("/bin/sh", "/bin/sh", NULL);
180 log_error("execl() failed: %m");
184 log_info("Successfully spawned crash shell as pid %lu.", (unsigned long) pid);
187 log_info("Freezing execution.");
191 static void install_crash_handler(void) {
196 sa.sa_handler = crash;
197 sa.sa_flags = SA_NODEFER;
199 sigaction_many(&sa, SIGNALS_CRASH_HANDLER, -1);
202 static int console_setup(bool do_reset) {
205 /* If we are init, we connect stdin/stdout/stderr to /dev/null
206 * and make sure we don't have a controlling tty. */
213 tty_fd = open_terminal("/dev/console", O_WRONLY|O_NOCTTY|O_CLOEXEC);
215 log_error("Failed to open /dev/console: %s", strerror(-tty_fd));
219 /* We don't want to force text mode.
220 * plymouth may be showing pictures already from initrd. */
221 r = reset_terminal_fd(tty_fd, false);
223 log_error("Failed to reset /dev/console: %s", strerror(-r));
225 close_nointr_nofail(tty_fd);
229 static int set_default_unit(const char *u) {
238 free(arg_default_unit);
239 arg_default_unit = c;
244 static int parse_proc_cmdline_word(const char *word) {
246 static const char * const rlmap[] = {
247 "emergency", SPECIAL_EMERGENCY_TARGET,
248 "-b", SPECIAL_EMERGENCY_TARGET,
249 "single", SPECIAL_RESCUE_TARGET,
250 "-s", SPECIAL_RESCUE_TARGET,
251 "s", SPECIAL_RESCUE_TARGET,
252 "S", SPECIAL_RESCUE_TARGET,
253 "1", SPECIAL_RESCUE_TARGET,
254 "2", SPECIAL_RUNLEVEL2_TARGET,
255 "3", SPECIAL_RUNLEVEL3_TARGET,
256 "4", SPECIAL_RUNLEVEL4_TARGET,
257 "5", SPECIAL_RUNLEVEL5_TARGET,
262 if (startswith(word, "systemd.unit=")) {
265 return set_default_unit(word + 13);
267 } else if (startswith(word, "rd.systemd.unit=")) {
270 return set_default_unit(word + 16);
272 } else if (startswith(word, "systemd.log_target=")) {
274 if (log_set_target_from_string(word + 19) < 0)
275 log_warning("Failed to parse log target %s. Ignoring.", word + 19);
277 } else if (startswith(word, "systemd.log_level=")) {
279 if (log_set_max_level_from_string(word + 18) < 0)
280 log_warning("Failed to parse log level %s. Ignoring.", word + 18);
282 } else if (startswith(word, "systemd.log_color=")) {
284 if (log_show_color_from_string(word + 18) < 0)
285 log_warning("Failed to parse log color setting %s. Ignoring.", word + 18);
287 } else if (startswith(word, "systemd.log_location=")) {
289 if (log_show_location_from_string(word + 21) < 0)
290 log_warning("Failed to parse log location setting %s. Ignoring.", word + 21);
292 } else if (startswith(word, "systemd.dump_core=")) {
295 if ((r = parse_boolean(word + 18)) < 0)
296 log_warning("Failed to parse dump core switch %s. Ignoring.", word + 18);
300 } else if (startswith(word, "systemd.crash_shell=")) {
303 if ((r = parse_boolean(word + 20)) < 0)
304 log_warning("Failed to parse crash shell switch %s. Ignoring.", word + 20);
308 } else if (startswith(word, "systemd.confirm_spawn=")) {
311 if ((r = parse_boolean(word + 22)) < 0)
312 log_warning("Failed to parse confirm spawn switch %s. Ignoring.", word + 22);
314 arg_confirm_spawn = r;
316 } else if (startswith(word, "systemd.crash_chvt=")) {
319 if (safe_atoi(word + 19, &k) < 0)
320 log_warning("Failed to parse crash chvt switch %s. Ignoring.", word + 19);
324 } else if (startswith(word, "systemd.show_status=")) {
327 if ((r = parse_boolean(word + 20)) < 0)
328 log_warning("Failed to parse show status switch %s. Ignoring.", word + 20);
331 } else if (startswith(word, "systemd.default_standard_output=")) {
334 if ((r = exec_output_from_string(word + 32)) < 0)
335 log_warning("Failed to parse default standard output switch %s. Ignoring.", word + 32);
337 arg_default_std_output = r;
338 } else if (startswith(word, "systemd.default_standard_error=")) {
341 if ((r = exec_output_from_string(word + 31)) < 0)
342 log_warning("Failed to parse default standard error switch %s. Ignoring.", word + 31);
344 arg_default_std_error = r;
345 } else if (startswith(word, "systemd.setenv=")) {
346 _cleanup_free_ char *cenv = NULL;
350 cenv = strdup(word + 15);
354 eq = strchr(cenv, '=');
356 if (!env_name_is_valid(cenv))
357 log_warning("Environment variable name '%s' is not valid. Ignoring.", cenv);
361 log_warning("Unsetting environment variable '%s' failed, ignoring: %m", cenv);
364 if (!env_assignment_is_valid(cenv))
365 log_warning("Environment variable assignment '%s' is not valid. Ignoring.", cenv);
368 r = setenv(cenv, eq + 1, 1);
370 log_warning("Setting environment variable '%s=%s' failed, ignoring: %m", cenv, eq + 1);
374 } else if (startswith(word, "systemd.") ||
375 (in_initrd() && startswith(word, "rd.systemd."))) {
377 log_warning("Unknown kernel switch %s. Ignoring.", word);
379 log_info("Supported kernel switches:\n"
380 "systemd.unit=UNIT Default unit to start\n"
381 "rd.systemd.unit=UNIT Default unit to start when run in initrd\n"
382 "systemd.dump_core=0|1 Dump core on crash\n"
383 "systemd.crash_shell=0|1 Run shell on crash\n"
384 "systemd.crash_chvt=N Change to VT #N on crash\n"
385 "systemd.confirm_spawn=0|1 Confirm every process spawn\n"
386 "systemd.show_status=0|1 Show status updates on the console during bootup\n"
387 "systemd.log_target=console|kmsg|journal|journal-or-kmsg|syslog|syslog-or-kmsg|null\n"
389 "systemd.log_level=LEVEL Log level\n"
390 "systemd.log_color=0|1 Highlight important log messages\n"
391 "systemd.log_location=0|1 Include code location in log messages\n"
392 "systemd.default_standard_output=null|tty|syslog|syslog+console|kmsg|kmsg+console|journal|journal+console\n"
393 " Set default log output for services\n"
394 "systemd.default_standard_error=null|tty|syslog|syslog+console|kmsg|kmsg+console|journal|journal+console\n"
395 " Set default log error output for services\n"
396 "systemd.setenv=ASSIGNMENT Set an environment variable for all spawned processes\n");
398 } else if (streq(word, "quiet"))
399 arg_show_status = false;
400 else if (!in_initrd()) {
403 /* SysV compatibility */
404 for (i = 0; i < ELEMENTSOF(rlmap); i += 2)
405 if (streq(word, rlmap[i]))
406 return set_default_unit(rlmap[i+1]);
412 static int config_parse_level2(
413 const char *filename,
426 log_set_max_level_from_string(rvalue);
430 static int config_parse_target(
431 const char *filename,
444 log_set_target_from_string(rvalue);
448 static int config_parse_color(
449 const char *filename,
462 log_show_color_from_string(rvalue);
466 static int config_parse_location(
467 const char *filename,
480 log_show_location_from_string(rvalue);
484 static int config_parse_cpu_affinity2(
485 const char *filename,
504 FOREACH_WORD_QUOTED(w, l, rvalue, state) {
509 if (!(t = strndup(w, l)))
512 r = safe_atou(t, &cpu);
516 if (!(c = cpu_set_malloc(&ncpus)))
519 if (r < 0 || cpu >= ncpus) {
520 log_error("[%s:%u] Failed to parse CPU affinity: %s", filename, line, rvalue);
525 CPU_SET_S(cpu, CPU_ALLOC_SIZE(ncpus), c);
529 if (sched_setaffinity(0, CPU_ALLOC_SIZE(ncpus), c) < 0)
530 log_warning("Failed to set CPU affinity: %m");
538 static void strv_free_free(char ***l) {
550 static void free_join_controllers(void) {
551 if (!arg_join_controllers)
554 strv_free_free(arg_join_controllers);
555 arg_join_controllers = NULL;
558 static int config_parse_join_controllers(
559 const char *filename,
576 free_join_controllers();
578 FOREACH_WORD_QUOTED(w, length, rvalue, state) {
581 s = strndup(w, length);
585 l = strv_split(s, ",");
590 if (strv_length(l) <= 1) {
595 if (!arg_join_controllers) {
596 arg_join_controllers = new(char**, 2);
597 if (!arg_join_controllers) {
602 arg_join_controllers[0] = l;
603 arg_join_controllers[1] = NULL;
610 t = new0(char**, n+2);
618 for (a = arg_join_controllers; *a; a++) {
620 if (strv_overlap(*a, l)) {
623 c = strv_merge(*a, l);
646 t[n++] = strv_uniq(l);
648 strv_free_free(arg_join_controllers);
649 arg_join_controllers = t;
656 static int parse_config_file(void) {
658 const ConfigTableItem items[] = {
659 { "Manager", "LogLevel", config_parse_level2, 0, NULL },
660 { "Manager", "LogTarget", config_parse_target, 0, NULL },
661 { "Manager", "LogColor", config_parse_color, 0, NULL },
662 { "Manager", "LogLocation", config_parse_location, 0, NULL },
663 { "Manager", "DumpCore", config_parse_bool, 0, &arg_dump_core },
664 { "Manager", "CrashShell", config_parse_bool, 0, &arg_crash_shell },
665 { "Manager", "ShowStatus", config_parse_bool, 0, &arg_show_status },
666 { "Manager", "CrashChVT", config_parse_int, 0, &arg_crash_chvt },
667 { "Manager", "CPUAffinity", config_parse_cpu_affinity2, 0, NULL },
668 { "Manager", "DefaultControllers", config_parse_strv, 0, &arg_default_controllers },
669 { "Manager", "DefaultStandardOutput", config_parse_output, 0, &arg_default_std_output },
670 { "Manager", "DefaultStandardError", config_parse_output, 0, &arg_default_std_error },
671 { "Manager", "JoinControllers", config_parse_join_controllers, 0, &arg_join_controllers },
672 { "Manager", "RuntimeWatchdogSec", config_parse_usec, 0, &arg_runtime_watchdog },
673 { "Manager", "ShutdownWatchdogSec", config_parse_usec, 0, &arg_shutdown_watchdog },
674 { "Manager", "CapabilityBoundingSet", config_parse_bounding_set, 0, &arg_capability_bounding_set_drop },
675 { "Manager", "TimerSlackNSec", config_parse_nsec, 0, &arg_timer_slack_nsec },
676 { "Manager", "DefaultLimitCPU", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_CPU]},
677 { "Manager", "DefaultLimitFSIZE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_FSIZE]},
678 { "Manager", "DefaultLimitDATA", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_DATA]},
679 { "Manager", "DefaultLimitSTACK", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_STACK]},
680 { "Manager", "DefaultLimitCORE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_CORE]},
681 { "Manager", "DefaultLimitRSS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RSS]},
682 { "Manager", "DefaultLimitNOFILE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NOFILE]},
683 { "Manager", "DefaultLimitAS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_AS]},
684 { "Manager", "DefaultLimitNPROC", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NPROC]},
685 { "Manager", "DefaultLimitMEMLOCK", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_MEMLOCK]},
686 { "Manager", "DefaultLimitLOCKS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_LOCKS]},
687 { "Manager", "DefaultLimitSIGPENDING",config_parse_limit, 0, &arg_default_rlimit[RLIMIT_SIGPENDING]},
688 { "Manager", "DefaultLimitMSGQUEUE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_MSGQUEUE]},
689 { "Manager", "DefaultLimitNICE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NICE]},
690 { "Manager", "DefaultLimitRTPRIO", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RTPRIO]},
691 { "Manager", "DefaultLimitRTTIME", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RTTIME]},
692 { NULL, NULL, NULL, 0, NULL }
699 fn = arg_running_as == SYSTEMD_SYSTEM ? SYSTEM_CONFIG_FILE : USER_CONFIG_FILE;
705 log_warning("Failed to open configuration file '%s': %m", fn);
709 r = config_parse(fn, f, "Manager\0", config_item_table_lookup, (void*) items, false, NULL);
711 log_warning("Failed to parse configuration file: %s", strerror(-r));
718 static int parse_proc_cmdline(void) {
719 char *line, *w, *state;
723 /* Don't read /proc/cmdline if we are in a container, since
724 * that is only relevant for the host system */
725 if (detect_container(NULL) > 0)
728 if ((r = read_one_line_file("/proc/cmdline", &line)) < 0) {
729 log_warning("Failed to read /proc/cmdline, ignoring: %s", strerror(-r));
733 FOREACH_WORD_QUOTED(w, l, line, state) {
736 if (!(word = strndup(w, l))) {
741 r = parse_proc_cmdline_word(word);
743 log_error("Failed on cmdline argument %s: %s", word, strerror(-r));
758 static int parse_argv(int argc, char *argv[]) {
761 ARG_LOG_LEVEL = 0x100,
770 ARG_DUMP_CONFIGURATION_ITEMS,
778 ARG_DEFAULT_STD_OUTPUT,
779 ARG_DEFAULT_STD_ERROR
782 static const struct option options[] = {
783 { "log-level", required_argument, NULL, ARG_LOG_LEVEL },
784 { "log-target", required_argument, NULL, ARG_LOG_TARGET },
785 { "log-color", optional_argument, NULL, ARG_LOG_COLOR },
786 { "log-location", optional_argument, NULL, ARG_LOG_LOCATION },
787 { "unit", required_argument, NULL, ARG_UNIT },
788 { "system", no_argument, NULL, ARG_SYSTEM },
789 { "user", no_argument, NULL, ARG_USER },
790 { "test", no_argument, NULL, ARG_TEST },
791 { "help", no_argument, NULL, 'h' },
792 { "version", no_argument, NULL, ARG_VERSION },
793 { "dump-configuration-items", no_argument, NULL, ARG_DUMP_CONFIGURATION_ITEMS },
794 { "dump-core", optional_argument, NULL, ARG_DUMP_CORE },
795 { "crash-shell", optional_argument, NULL, ARG_CRASH_SHELL },
796 { "confirm-spawn", optional_argument, NULL, ARG_CONFIRM_SPAWN },
797 { "show-status", optional_argument, NULL, ARG_SHOW_STATUS },
798 { "deserialize", required_argument, NULL, ARG_DESERIALIZE },
799 { "switched-root", no_argument, NULL, ARG_SWITCHED_ROOT },
800 { "introspect", optional_argument, NULL, ARG_INTROSPECT },
801 { "default-standard-output", required_argument, NULL, ARG_DEFAULT_STD_OUTPUT, },
802 { "default-standard-error", required_argument, NULL, ARG_DEFAULT_STD_ERROR, },
814 while ((c = getopt_long(argc, argv, "hDbsz:", options, NULL)) >= 0)
819 if ((r = log_set_max_level_from_string(optarg)) < 0) {
820 log_error("Failed to parse log level %s.", optarg);
828 if ((r = log_set_target_from_string(optarg)) < 0) {
829 log_error("Failed to parse log target %s.", optarg);
838 if ((r = log_show_color_from_string(optarg)) < 0) {
839 log_error("Failed to parse log color setting %s.", optarg);
843 log_show_color(true);
847 case ARG_LOG_LOCATION:
850 if ((r = log_show_location_from_string(optarg)) < 0) {
851 log_error("Failed to parse log location setting %s.", optarg);
855 log_show_location(true);
859 case ARG_DEFAULT_STD_OUTPUT:
861 if ((r = exec_output_from_string(optarg)) < 0) {
862 log_error("Failed to parse default standard output setting %s.", optarg);
865 arg_default_std_output = r;
868 case ARG_DEFAULT_STD_ERROR:
870 if ((r = exec_output_from_string(optarg)) < 0) {
871 log_error("Failed to parse default standard error output setting %s.", optarg);
874 arg_default_std_error = r;
879 if ((r = set_default_unit(optarg)) < 0) {
880 log_error("Failed to set default unit %s: %s", optarg, strerror(-r));
887 arg_running_as = SYSTEMD_SYSTEM;
891 arg_running_as = SYSTEMD_USER;
895 arg_action = ACTION_TEST;
899 arg_action = ACTION_VERSION;
902 case ARG_DUMP_CONFIGURATION_ITEMS:
903 arg_action = ACTION_DUMP_CONFIGURATION_ITEMS;
907 r = optarg ? parse_boolean(optarg) : 1;
909 log_error("Failed to parse dump core boolean %s.", optarg);
915 case ARG_CRASH_SHELL:
916 r = optarg ? parse_boolean(optarg) : 1;
918 log_error("Failed to parse crash shell boolean %s.", optarg);
924 case ARG_CONFIRM_SPAWN:
925 r = optarg ? parse_boolean(optarg) : 1;
927 log_error("Failed to parse confirm spawn boolean %s.", optarg);
930 arg_confirm_spawn = r;
933 case ARG_SHOW_STATUS:
934 r = optarg ? parse_boolean(optarg) : 1;
936 log_error("Failed to parse show status boolean %s.", optarg);
942 case ARG_DESERIALIZE: {
946 r = safe_atoi(optarg, &fd);
947 if (r < 0 || fd < 0) {
948 log_error("Failed to parse deserialize option %s.", optarg);
949 return r < 0 ? r : -EINVAL;
952 fd_cloexec(fd, true);
956 log_error("Failed to open serialization fd: %m");
961 fclose(serialization);
968 case ARG_SWITCHED_ROOT:
969 arg_switched_root = true;
972 case ARG_INTROSPECT: {
973 const char * const * i = NULL;
975 for (i = bus_interface_table; *i; i += 2)
976 if (!optarg || streq(i[0], optarg)) {
977 fputs(DBUS_INTROSPECT_1_0_XML_DOCTYPE_DECL_NODE
980 fputs("</node>\n", stdout);
987 log_error("Unknown interface %s.", optarg);
989 arg_action = ACTION_DONE;
994 arg_action = ACTION_HELP;
998 log_set_max_level(LOG_DEBUG);
1004 /* Just to eat away the sysvinit kernel
1005 * cmdline args without getopt() error
1006 * messages that we'll parse in
1007 * parse_proc_cmdline_word() or ignore. */
1011 if (getpid() != 1) {
1012 log_error("Unknown option code %c", c);
1019 if (optind < argc && getpid() != 1) {
1020 /* Hmm, when we aren't run as init system
1021 * let's complain about excess arguments */
1023 log_error("Excess arguments.");
1027 if (detect_container(NULL) > 0) {
1030 /* All /proc/cmdline arguments the kernel didn't
1031 * understand it passed to us. We're not really
1032 * interested in that usually since /proc/cmdline is
1033 * more interesting and complete. With one exception:
1034 * if we are run in a container /proc/cmdline is not
1035 * relevant for the container, hence we rely on argv[]
1038 for (a = argv; a < argv + argc; a++)
1039 if ((r = parse_proc_cmdline_word(*a)) < 0) {
1040 log_error("Failed on cmdline argument %s: %s", *a, strerror(-r));
1048 static int help(void) {
1050 printf("%s [OPTIONS...]\n\n"
1051 "Starts up and maintains the system or user services.\n\n"
1052 " -h --help Show this help\n"
1053 " --test Determine startup sequence, dump it and exit\n"
1054 " --dump-configuration-items Dump understood unit configuration items\n"
1055 " --introspect[=INTERFACE] Extract D-Bus interface data\n"
1056 " --unit=UNIT Set default unit\n"
1057 " --system Run a system instance, even if PID != 1\n"
1058 " --user Run a user instance\n"
1059 " --dump-core[=0|1] Dump core on crash\n"
1060 " --crash-shell[=0|1] Run shell on crash\n"
1061 " --confirm-spawn[=0|1] Ask for confirmation when spawning processes\n"
1062 " --show-status[=0|1] Show status updates on the console during bootup\n"
1063 " --log-target=TARGET Set log target (console, journal, syslog, kmsg, journal-or-kmsg, syslog-or-kmsg, null)\n"
1064 " --log-level=LEVEL Set log level (debug, info, notice, warning, err, crit, alert, emerg)\n"
1065 " --log-color[=0|1] Highlight important log messages\n"
1066 " --log-location[=0|1] Include code location in log messages\n"
1067 " --default-standard-output= Set default standard output for services\n"
1068 " --default-standard-error= Set default standard error output for services\n",
1069 program_invocation_short_name);
1074 static int version(void) {
1075 puts(PACKAGE_STRING);
1076 puts(SYSTEMD_FEATURES);
1081 static int prepare_reexecute(Manager *m, FILE **_f, FDSet **_fds, bool serialize_jobs) {
1090 /* Make sure nothing is really destructed when we shut down */
1093 r = manager_open_serialization(m, &f);
1095 log_error("Failed to create serialization file: %s", strerror(-r));
1102 log_error("Failed to allocate fd set: %s", strerror(-r));
1106 r = manager_serialize(m, f, fds, serialize_jobs);
1108 log_error("Failed to serialize state: %s", strerror(-r));
1112 if (fseeko(f, 0, SEEK_SET) < 0) {
1113 log_error("Failed to rewind serialization fd: %m");
1117 r = fd_cloexec(fileno(f), false);
1119 log_error("Failed to disable O_CLOEXEC for serialization: %s", strerror(-r));
1123 r = fdset_cloexec(fds, false);
1125 log_error("Failed to disable O_CLOEXEC for serialization fds: %s", strerror(-r));
1143 static int bump_rlimit_nofile(struct rlimit *saved_rlimit) {
1147 assert(saved_rlimit);
1149 /* Save the original RLIMIT_NOFILE so that we can reset it
1150 * later when transitioning from the initrd to the main
1151 * systemd or suchlike. */
1152 if (getrlimit(RLIMIT_NOFILE, saved_rlimit) < 0) {
1153 log_error("Reading RLIMIT_NOFILE failed: %m");
1157 /* Make sure forked processes get the default kernel setting */
1158 if (!arg_default_rlimit[RLIMIT_NOFILE]) {
1161 rl = newdup(struct rlimit, saved_rlimit, 1);
1165 arg_default_rlimit[RLIMIT_NOFILE] = rl;
1168 /* Bump up the resource limit for ourselves substantially */
1169 nl.rlim_cur = nl.rlim_max = 64*1024;
1170 r = setrlimit_closest(RLIMIT_NOFILE, &nl);
1172 log_error("Setting RLIMIT_NOFILE failed: %s", strerror(-r));
1179 static struct dual_timestamp* parse_initrd_timestamp(struct dual_timestamp *t) {
1181 unsigned long long a, b;
1185 e = getenv("RD_TIMESTAMP");
1189 if (sscanf(e, "%llu %llu", &a, &b) != 2)
1192 t->realtime = (usec_t) a;
1193 t->monotonic = (usec_t) b;
1198 static void test_mtab(void) {
1201 /* Check that /etc/mtab is a symlink */
1203 if (readlink_malloc("/etc/mtab", &p) >= 0) {
1206 b = streq(p, "/proc/self/mounts") || streq(p, "/proc/mounts");
1213 log_warning("/etc/mtab is not a symlink or not pointing to /proc/self/mounts. "
1214 "This is not supported anymore. "
1215 "Please make sure to replace this file by a symlink to avoid incorrect or misleading mount(8) output.");
1218 static void test_usr(void) {
1220 /* Check that /usr is not a separate fs */
1222 if (dir_is_empty("/usr") <= 0)
1225 log_warning("/usr appears to be on its own filesytem and is not already mounted. This is not a supported setup. "
1226 "Some things will probably break (sometimes even silently) in mysterious ways. "
1227 "Consult http://freedesktop.org/wiki/Software/systemd/separate-usr-is-broken for more information.");
1230 static void test_cgroups(void) {
1232 if (access("/proc/cgroups", F_OK) >= 0)
1235 log_warning("CONFIG_CGROUPS was not set when your kernel was compiled. "
1236 "Systems without control groups are not supported. "
1237 "We will now sleep for 10s, and then continue boot-up. "
1238 "Expect breakage and please do not file bugs. "
1239 "Instead fix your kernel and enable CONFIG_CGROUPS. "
1240 "Consult http://0pointer.de/blog/projects/cgroups-vs-cgroups.html for more information.");
1245 static int initialize_join_controllers(void) {
1246 /* By default, mount "cpu" + "cpuacct" together, and "net_cls"
1247 * + "net_prio". We'd like to add "cpuset" to the mix, but
1248 * "cpuset" does't really work for groups with no initialized
1251 arg_join_controllers = new(char**, 3);
1252 if (!arg_join_controllers)
1255 arg_join_controllers[0] = strv_new("cpu", "cpuacct", NULL);
1256 if (!arg_join_controllers[0])
1259 arg_join_controllers[1] = strv_new("net_cls", "net_prio", NULL);
1260 if (!arg_join_controllers[1])
1263 arg_join_controllers[2] = NULL;
1267 int main(int argc, char *argv[]) {
1269 int r, retval = EXIT_FAILURE;
1270 usec_t before_startup, after_startup;
1271 char timespan[FORMAT_TIMESPAN_MAX];
1273 bool reexecute = false;
1274 const char *shutdown_verb = NULL;
1275 dual_timestamp initrd_timestamp = { 0ULL, 0ULL };
1276 static char systemd[] = "systemd";
1277 bool skip_setup = false;
1279 bool loaded_policy = false;
1280 bool arm_reboot_watchdog = false;
1281 bool queue_default_job = false;
1282 char *switch_root_dir = NULL, *switch_root_init = NULL;
1283 static struct rlimit saved_rlimit_nofile = { 0, 0 };
1285 #ifdef HAVE_SYSV_COMPAT
1286 if (getpid() != 1 && strstr(program_invocation_short_name, "init")) {
1287 /* This is compatibility support for SysV, where
1288 * calling init as a user is identical to telinit. */
1291 execv(SYSTEMCTL_BINARY_PATH, argv);
1292 log_error("Failed to exec " SYSTEMCTL_BINARY_PATH ": %m");
1297 /* Determine if this is a reexecution or normal bootup. We do
1298 * the full command line parsing much later, so let's just
1299 * have a quick peek here. */
1300 for (j = 1; j < argc; j++)
1301 if (streq(argv[j], "--deserialize")) {
1306 /* If we have switched root, do all the special setup
1308 for (j = 1; j < argc; j++)
1309 if (streq(argv[j], "--switched-root")) {
1314 /* If we get started via the /sbin/init symlink then we are
1315 called 'init'. After a subsequent reexecution we are then
1316 called 'systemd'. That is confusing, hence let's call us
1317 systemd right-away. */
1318 program_invocation_short_name = systemd;
1319 prctl(PR_SET_NAME, systemd);
1324 log_show_color(isatty(STDERR_FILENO) > 0);
1326 if (getpid() == 1 && detect_container(NULL) <= 0) {
1328 /* Running outside of a container as PID 1 */
1329 arg_running_as = SYSTEMD_SYSTEM;
1331 log_set_target(LOG_TARGET_KMSG);
1335 char *rd_timestamp = NULL;
1337 dual_timestamp_get(&initrd_timestamp);
1338 asprintf(&rd_timestamp, "%llu %llu",
1339 (unsigned long long) initrd_timestamp.realtime,
1340 (unsigned long long) initrd_timestamp.monotonic);
1342 setenv("RD_TIMESTAMP", rd_timestamp, 1);
1348 if (selinux_setup(&loaded_policy) < 0)
1350 if (ima_setup() < 0)
1354 if (label_init(NULL) < 0)
1358 if (hwclock_is_localtime() > 0) {
1361 /* The first-time call to settimeofday() does a time warp in the kernel */
1362 r = hwclock_set_timezone(&min);
1364 log_error("Failed to apply local time delta, ignoring: %s", strerror(-r));
1366 log_info("RTC configured in localtime, applying delta of %i minutes to system time.", min);
1367 } else if (!in_initrd()) {
1369 * Do dummy first-time call to seal the kernel's time warp magic
1371 * Do not call this this from inside the initrd. The initrd might not
1372 * carry /etc/adjtime with LOCAL, but the real system could be set up
1373 * that way. In such case, we need to delay the time-warp or the sealing
1374 * until we reach the real system.
1376 hwclock_reset_timezone();
1378 /* Tell the kernel our time zone */
1379 r = hwclock_set_timezone(NULL);
1381 log_error("Failed to set the kernel's time zone, ignoring: %s", strerror(-r));
1385 /* Set the default for later on, but don't actually
1386 * open the logs like this for now. Note that if we
1387 * are transitioning from the initrd there might still
1388 * be journal fd open, and we shouldn't attempt
1389 * opening that before we parsed /proc/cmdline which
1390 * might redirect output elsewhere. */
1391 log_set_target(LOG_TARGET_JOURNAL_OR_KMSG);
1393 } else if (getpid() == 1) {
1395 /* Running inside a container, as PID 1 */
1396 arg_running_as = SYSTEMD_SYSTEM;
1397 log_set_target(LOG_TARGET_CONSOLE);
1400 /* For the later on, see above... */
1401 log_set_target(LOG_TARGET_JOURNAL);
1405 /* Running as user instance */
1406 arg_running_as = SYSTEMD_USER;
1407 log_set_target(LOG_TARGET_AUTO);
1411 /* Initialize default unit */
1412 r = set_default_unit(SPECIAL_DEFAULT_TARGET);
1414 log_error("Failed to set default unit %s: %s", SPECIAL_DEFAULT_TARGET, strerror(-r));
1418 r = initialize_join_controllers();
1422 /* Mount /proc, /sys and friends, so that /proc/cmdline and
1423 * /proc/$PID/fd is available. */
1424 if (geteuid() == 0 && !getenv("SYSTEMD_SKIP_API_MOUNTS")) {
1425 r = mount_setup(loaded_policy);
1430 /* Reset all signal handlers. */
1431 assert_se(reset_all_signal_handlers() == 0);
1433 /* If we are init, we can block sigkill. Yay. */
1434 ignore_signals(SIGNALS_IGNORE, -1);
1436 if (parse_config_file() < 0)
1439 if (arg_running_as == SYSTEMD_SYSTEM)
1440 if (parse_proc_cmdline() < 0)
1443 log_parse_environment();
1445 if (parse_argv(argc, argv) < 0)
1448 if (arg_action == ACTION_TEST &&
1450 log_error("Don't run test mode as root.");
1454 if (arg_running_as == SYSTEMD_USER &&
1455 arg_action == ACTION_RUN &&
1457 log_error("Trying to run as user instance, but the system has not been booted with systemd.");
1461 if (arg_running_as == SYSTEMD_SYSTEM &&
1462 arg_action == ACTION_RUN &&
1463 running_in_chroot() > 0) {
1464 log_error("Cannot be run in a chroot() environment.");
1468 if (arg_action == ACTION_HELP) {
1471 } else if (arg_action == ACTION_VERSION) {
1474 } else if (arg_action == ACTION_DUMP_CONFIGURATION_ITEMS) {
1475 unit_dump_config_items(stdout);
1476 retval = EXIT_SUCCESS;
1478 } else if (arg_action == ACTION_DONE) {
1479 retval = EXIT_SUCCESS;
1483 assert_se(arg_action == ACTION_RUN || arg_action == ACTION_TEST);
1485 /* Close logging fds, in order not to confuse fdset below */
1488 /* Remember open file descriptors for later deserialization */
1489 r = fdset_new_fill(&fds);
1491 log_error("Failed to allocate fd set: %s", strerror(-r));
1494 fdset_cloexec(fds, true);
1497 assert_se(fdset_remove(fds, fileno(serialization)) >= 0);
1499 /* Set up PATH unless it is already set */
1501 #ifdef HAVE_SPLIT_USR
1502 "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
1504 "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin",
1506 arg_running_as == SYSTEMD_SYSTEM);
1508 if (arg_running_as == SYSTEMD_SYSTEM) {
1509 /* Parse the data passed to us. We leave this
1510 * variables set, but the manager later on will not
1511 * pass them on to our children. */
1513 parse_initrd_timestamp(&initrd_timestamp);
1515 /* Unset some environment variables passed in from the
1516 * kernel that don't really make sense for us. */
1520 /* When we are invoked by a shell, these might be set,
1521 * but make little sense to pass on */
1526 /* When we are invoked by a chroot-like tool such as
1527 * nspawn, these might be set, but make little sense
1530 unsetenv("LOGNAME");
1532 /* We suppress the socket activation env vars, as
1533 * we'll try to match *any* open fd to units if
1535 unsetenv("LISTEN_FDS");
1536 unsetenv("LISTEN_PID");
1538 /* All other variables are left as is, so that clients
1539 * can still read them via /proc/1/environ */
1542 /* Move out of the way, so that we won't block unmounts */
1543 assert_se(chdir("/") == 0);
1545 if (arg_running_as == SYSTEMD_SYSTEM) {
1546 /* Become a session leader if we aren't one yet. */
1549 /* Disable the umask logic */
1553 /* Make sure D-Bus doesn't fiddle with the SIGPIPE handlers */
1554 dbus_connection_set_change_sigpipe(FALSE);
1556 /* Reset the console, but only if this is really init and we
1557 * are freshly booted */
1558 if (arg_running_as == SYSTEMD_SYSTEM && arg_action == ACTION_RUN)
1559 console_setup(getpid() == 1 && !skip_setup);
1561 /* Open the logging devices, if possible and necessary */
1564 /* Make sure we leave a core dump without panicing the
1567 install_crash_handler();
1569 if (geteuid() == 0 && !getenv("SYSTEMD_SKIP_API_MOUNTS")) {
1570 r = mount_cgroup_controllers(arg_join_controllers);
1575 if (arg_running_as == SYSTEMD_SYSTEM) {
1576 const char *virtualization = NULL;
1578 log_info(PACKAGE_STRING " running in system mode. (" SYSTEMD_FEATURES ")");
1580 detect_virtualization(&virtualization);
1582 log_info("Detected virtualization '%s'.", virtualization);
1585 log_info("Running in initial RAM disk.");
1588 log_debug(PACKAGE_STRING " running in user mode. (" SYSTEMD_FEATURES ")");
1590 if (arg_running_as == SYSTEMD_SYSTEM && !skip_setup) {
1593 if (arg_show_status || plymouth_running())
1608 if (arg_running_as == SYSTEMD_SYSTEM && arg_runtime_watchdog > 0)
1609 watchdog_set_timeout(&arg_runtime_watchdog);
1611 if (arg_timer_slack_nsec != (nsec_t) -1)
1612 if (prctl(PR_SET_TIMERSLACK, arg_timer_slack_nsec) < 0)
1613 log_error("Failed to adjust timer slack: %m");
1615 if (arg_capability_bounding_set_drop) {
1616 r = capability_bounding_set_drop(arg_capability_bounding_set_drop, true);
1618 log_error("Failed to drop capability bounding set: %s", strerror(-r));
1621 r = capability_bounding_set_drop_usermode(arg_capability_bounding_set_drop);
1623 log_error("Failed to drop capability bounding set of usermode helpers: %s", strerror(-r));
1628 if (arg_running_as == SYSTEMD_USER) {
1629 /* Become reaper of our children */
1630 if (prctl(PR_SET_CHILD_SUBREAPER, 1) < 0) {
1631 log_warning("Failed to make us a subreaper: %m");
1632 if (errno == EINVAL)
1633 log_info("Perhaps the kernel version is too old (< 3.4?)");
1637 if (arg_running_as == SYSTEMD_SYSTEM)
1638 bump_rlimit_nofile(&saved_rlimit_nofile);
1640 r = manager_new(arg_running_as, &m);
1642 log_error("Failed to allocate manager object: %s", strerror(-r));
1646 m->confirm_spawn = arg_confirm_spawn;
1647 m->default_std_output = arg_default_std_output;
1648 m->default_std_error = arg_default_std_error;
1649 m->runtime_watchdog = arg_runtime_watchdog;
1650 m->shutdown_watchdog = arg_shutdown_watchdog;
1652 manager_set_default_rlimits(m, arg_default_rlimit);
1654 if (dual_timestamp_is_set(&initrd_timestamp))
1655 m->initrd_timestamp = initrd_timestamp;
1657 if (arg_default_controllers)
1658 manager_set_default_controllers(m, arg_default_controllers);
1660 manager_set_show_status(m, arg_show_status);
1662 /* Remember whether we should queue the default job */
1663 queue_default_job = !serialization || arg_switched_root;
1665 before_startup = now(CLOCK_MONOTONIC);
1667 r = manager_startup(m, serialization, fds);
1669 log_error("Failed to fully start up daemon: %s", strerror(-r));
1671 /* This will close all file descriptors that were opened, but
1672 * not claimed by any unit. */
1675 if (serialization) {
1676 fclose(serialization);
1677 serialization = NULL;
1680 if (queue_default_job) {
1682 Unit *target = NULL;
1683 Job *default_unit_job;
1685 dbus_error_init(&error);
1687 log_debug("Activating default unit: %s", arg_default_unit);
1689 r = manager_load_unit(m, arg_default_unit, NULL, &error, &target);
1691 log_error("Failed to load default target: %s", bus_error(&error, r));
1692 dbus_error_free(&error);
1693 } else if (target->load_state == UNIT_ERROR)
1694 log_error("Failed to load default target: %s", strerror(-target->load_error));
1695 else if (target->load_state == UNIT_MASKED)
1696 log_error("Default target masked.");
1698 if (!target || target->load_state != UNIT_LOADED) {
1699 log_info("Trying to load rescue target...");
1701 r = manager_load_unit(m, SPECIAL_RESCUE_TARGET, NULL, &error, &target);
1703 log_error("Failed to load rescue target: %s", bus_error(&error, r));
1704 dbus_error_free(&error);
1706 } else if (target->load_state == UNIT_ERROR) {
1707 log_error("Failed to load rescue target: %s", strerror(-target->load_error));
1709 } else if (target->load_state == UNIT_MASKED) {
1710 log_error("Rescue target masked.");
1715 assert(target->load_state == UNIT_LOADED);
1717 if (arg_action == ACTION_TEST) {
1718 printf("-> By units:\n");
1719 manager_dump_units(m, stdout, "\t");
1722 r = manager_add_job(m, JOB_START, target, JOB_REPLACE, false, &error, &default_unit_job);
1724 log_error("Failed to start default target: %s", bus_error(&error, r));
1725 dbus_error_free(&error);
1728 m->default_unit_job_id = default_unit_job->id;
1730 after_startup = now(CLOCK_MONOTONIC);
1731 log_full(arg_action == ACTION_TEST ? LOG_INFO : LOG_DEBUG,
1732 "Loaded units and determined initial transaction in %s.",
1733 format_timespan(timespan, sizeof(timespan), after_startup - before_startup));
1735 if (arg_action == ACTION_TEST) {
1736 printf("-> By jobs:\n");
1737 manager_dump_jobs(m, stdout, "\t");
1738 retval = EXIT_SUCCESS;
1744 r = manager_loop(m);
1746 log_error("Failed to run mainloop: %s", strerror(-r));
1750 switch (m->exit_code) {
1753 retval = EXIT_SUCCESS;
1757 case MANAGER_RELOAD:
1758 log_info("Reloading.");
1759 r = manager_reload(m);
1761 log_error("Failed to reload: %s", strerror(-r));
1764 case MANAGER_REEXECUTE:
1766 if (prepare_reexecute(m, &serialization, &fds, true) < 0)
1770 log_notice("Reexecuting.");
1773 case MANAGER_SWITCH_ROOT:
1774 /* Steal the switch root parameters */
1775 switch_root_dir = m->switch_root;
1776 switch_root_init = m->switch_root_init;
1777 m->switch_root = m->switch_root_init = NULL;
1779 if (!switch_root_init)
1780 if (prepare_reexecute(m, &serialization, &fds, false) < 0)
1784 log_notice("Switching root.");
1787 case MANAGER_REBOOT:
1788 case MANAGER_POWEROFF:
1790 case MANAGER_KEXEC: {
1791 static const char * const table[_MANAGER_EXIT_CODE_MAX] = {
1792 [MANAGER_REBOOT] = "reboot",
1793 [MANAGER_POWEROFF] = "poweroff",
1794 [MANAGER_HALT] = "halt",
1795 [MANAGER_KEXEC] = "kexec"
1798 assert_se(shutdown_verb = table[m->exit_code]);
1799 arm_reboot_watchdog = m->exit_code == MANAGER_REBOOT;
1801 log_notice("Shutting down.");
1806 assert_not_reached("Unknown exit code.");
1814 for (j = 0; j < RLIMIT_NLIMITS; j++)
1815 free(arg_default_rlimit[j]);
1817 free(arg_default_unit);
1818 strv_free(arg_default_controllers);
1819 free_join_controllers();
1826 unsigned i, args_size;
1828 /* Close and disarm the watchdog, so that the new
1829 * instance can reinitialize it, but doesn't get
1830 * rebooted while we do that */
1831 watchdog_close(true);
1833 /* Reset the RLIMIT_NOFILE to the kernel default, so
1834 * that the new systemd can pass the kernel default to
1835 * its child processes */
1836 if (saved_rlimit_nofile.rlim_cur > 0)
1837 setrlimit(RLIMIT_NOFILE, &saved_rlimit_nofile);
1839 if (switch_root_dir) {
1840 /* Kill all remaining processes from the
1841 * initrd, but don't wait for them, so that we
1842 * can handle the SIGCHLD for them after
1844 broadcast_signal(SIGTERM, false);
1846 /* And switch root */
1847 r = switch_root(switch_root_dir);
1849 log_error("Failed to switch root, ignoring: %s", strerror(-r));
1852 args_size = MAX(6, argc+1);
1853 args = newa(const char*, args_size);
1855 if (!switch_root_init) {
1858 /* First try to spawn ourselves with the right
1859 * path, and with full serialization. We do
1860 * this only if the user didn't specify an
1861 * explicit init to spawn. */
1863 assert(serialization);
1866 snprintf(sfd, sizeof(sfd), "%i", fileno(serialization));
1870 args[i++] = SYSTEMD_BINARY_PATH;
1871 if (switch_root_dir)
1872 args[i++] = "--switched-root";
1873 args[i++] = arg_running_as == SYSTEMD_SYSTEM ? "--system" : "--user";
1874 args[i++] = "--deserialize";
1878 assert(i <= args_size);
1879 execv(args[0], (char* const*) args);
1882 /* Try the fallback, if there is any, without any
1883 * serialization. We pass the original argv[] and
1884 * envp[]. (Well, modulo the ordering changes due to
1885 * getopt() in argv[], and some cleanups in envp[],
1886 * but let's hope that doesn't matter.) */
1888 if (serialization) {
1889 fclose(serialization);
1890 serialization = NULL;
1898 /* Reopen the console */
1899 make_console_stdio();
1901 for (j = 1, i = 1; j < argc; j++)
1902 args[i++] = argv[j];
1904 assert(i <= args_size);
1906 if (switch_root_init) {
1907 args[0] = switch_root_init;
1908 execv(args[0], (char* const*) args);
1909 log_warning("Failed to execute configured init, trying fallback: %m");
1912 args[0] = "/sbin/init";
1913 execv(args[0], (char* const*) args);
1915 if (errno == ENOENT) {
1916 log_warning("No /sbin/init, trying fallback");
1918 args[0] = "/bin/sh";
1920 execv(args[0], (char* const*) args);
1921 log_error("Failed to execute /bin/sh, giving up: %m");
1923 log_warning("Failed to execute /sbin/init, giving up: %m");
1927 fclose(serialization);
1932 if (shutdown_verb) {
1933 const char * command_line[] = {
1934 SYSTEMD_SHUTDOWN_BINARY_PATH,
1940 if (arm_reboot_watchdog && arg_shutdown_watchdog > 0) {
1943 /* If we reboot let's set the shutdown
1944 * watchdog and tell the shutdown binary to
1945 * repeatedly ping it */
1946 watchdog_set_timeout(&arg_shutdown_watchdog);
1947 watchdog_close(false);
1949 /* Tell the binary how often to ping */
1950 snprintf(e, sizeof(e), "WATCHDOG_USEC=%llu", (unsigned long long) arg_shutdown_watchdog);
1953 env_block = strv_append(environ, e);
1955 env_block = strv_copy(environ);
1956 watchdog_close(true);
1959 execve(SYSTEMD_SHUTDOWN_BINARY_PATH, (char **) command_line, env_block);
1961 log_error("Failed to execute shutdown binary, freezing: %m");