1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2010 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <dbus/dbus.h>
28 #include <sys/types.h>
34 #include <sys/prctl.h>
35 #include <sys/mount.h>
39 #include "load-fragment.h"
42 #include "conf-parser.h"
43 #include "dbus-common.h"
51 #include "path-util.h"
52 #include "switch-root.h"
53 #include "capability.h"
57 #include "sd-daemon.h"
58 #include "sd-messages.h"
60 #include "mount-setup.h"
61 #include "loopback-setup.h"
63 #include "kmod-setup.h"
65 #include "hostname-setup.h"
66 #include "machine-id-setup.h"
67 #include "selinux-setup.h"
68 #include "ima-setup.h"
70 #include "smack-setup.h"
77 ACTION_DUMP_CONFIGURATION_ITEMS,
79 } arg_action = ACTION_RUN;
81 static char *arg_default_unit = NULL;
82 static SystemdRunningAs arg_running_as = _SYSTEMD_RUNNING_AS_INVALID;
84 static bool arg_dump_core = true;
85 static bool arg_crash_shell = false;
86 static int arg_crash_chvt = -1;
87 static bool arg_confirm_spawn = false;
88 static bool arg_show_status = true;
89 static bool arg_switched_root = false;
90 static char ***arg_join_controllers = NULL;
91 static ExecOutput arg_default_std_output = EXEC_OUTPUT_JOURNAL;
92 static ExecOutput arg_default_std_error = EXEC_OUTPUT_INHERIT;
93 static usec_t arg_runtime_watchdog = 0;
94 static usec_t arg_shutdown_watchdog = 10 * USEC_PER_MINUTE;
95 static char **arg_default_environment = NULL;
96 static struct rlimit *arg_default_rlimit[RLIMIT_NLIMITS] = {};
97 static uint64_t arg_capability_bounding_set_drop = 0;
98 static nsec_t arg_timer_slack_nsec = (nsec_t) -1;
100 static FILE* serialization = NULL;
102 static void nop_handler(int sig) {
105 _noreturn_ static void crash(int sig) {
108 /* Pass this on immediately, if this is not PID 1 */
110 else if (!arg_dump_core)
111 log_error("Caught <%s>, not dumping core.", signal_to_string(sig));
113 struct sigaction sa = {
114 .sa_handler = nop_handler,
115 .sa_flags = SA_NOCLDSTOP|SA_RESTART,
119 /* We want to wait for the core process, hence let's enable SIGCHLD */
120 sigaction(SIGCHLD, &sa, NULL);
124 log_error("Caught <%s>, cannot fork for core dump: %s", signal_to_string(sig), strerror(errno));
127 struct rlimit rl = {};
129 /* Enable default signal handler for core dump */
131 sa.sa_handler = SIG_DFL;
132 sigaction(sig, &sa, NULL);
134 /* Don't limit the core dump size */
135 rl.rlim_cur = RLIM_INFINITY;
136 rl.rlim_max = RLIM_INFINITY;
137 setrlimit(RLIMIT_CORE, &rl);
139 /* Just to be sure... */
142 /* Raise the signal again */
145 assert_not_reached("We shouldn't be here...");
152 /* Order things nicely. */
153 r = wait_for_terminate(pid, &status);
155 log_error("Caught <%s>, waitpid() failed: %s", signal_to_string(sig), strerror(-r));
156 else if (status.si_code != CLD_DUMPED)
157 log_error("Caught <%s>, core dump failed.", signal_to_string(sig));
159 log_error("Caught <%s>, dumped core as pid %lu.", signal_to_string(sig), (unsigned long) pid);
164 chvt(arg_crash_chvt);
166 if (arg_crash_shell) {
167 struct sigaction sa = {
168 .sa_handler = SIG_IGN,
169 .sa_flags = SA_NOCLDSTOP|SA_NOCLDWAIT|SA_RESTART,
173 log_info("Executing crash shell in 10s...");
176 /* Let the kernel reap children for us */
177 assert_se(sigaction(SIGCHLD, &sa, NULL) == 0);
181 log_error("Failed to fork off crash shell: %m");
183 make_console_stdio();
184 execl("/bin/sh", "/bin/sh", NULL);
186 log_error("execl() failed: %m");
190 log_info("Successfully spawned crash shell as pid %lu.", (unsigned long) pid);
193 log_info("Freezing execution.");
197 static void install_crash_handler(void) {
198 struct sigaction sa = {
200 .sa_flags = SA_NODEFER,
203 sigaction_many(&sa, SIGNALS_CRASH_HANDLER, -1);
206 static int console_setup(bool do_reset) {
209 /* If we are init, we connect stdin/stdout/stderr to /dev/null
210 * and make sure we don't have a controlling tty. */
217 tty_fd = open_terminal("/dev/console", O_WRONLY|O_NOCTTY|O_CLOEXEC);
219 log_error("Failed to open /dev/console: %s", strerror(-tty_fd));
223 /* We don't want to force text mode.
224 * plymouth may be showing pictures already from initrd. */
225 r = reset_terminal_fd(tty_fd, false);
227 log_error("Failed to reset /dev/console: %s", strerror(-r));
229 close_nointr_nofail(tty_fd);
233 static int set_default_unit(const char *u) {
242 free(arg_default_unit);
243 arg_default_unit = c;
248 static int parse_proc_cmdline_word(const char *word) {
250 static const char * const rlmap[] = {
251 "emergency", SPECIAL_EMERGENCY_TARGET,
252 "-b", SPECIAL_EMERGENCY_TARGET,
253 "single", SPECIAL_RESCUE_TARGET,
254 "-s", SPECIAL_RESCUE_TARGET,
255 "s", SPECIAL_RESCUE_TARGET,
256 "S", SPECIAL_RESCUE_TARGET,
257 "1", SPECIAL_RESCUE_TARGET,
258 "2", SPECIAL_RUNLEVEL2_TARGET,
259 "3", SPECIAL_RUNLEVEL3_TARGET,
260 "4", SPECIAL_RUNLEVEL4_TARGET,
261 "5", SPECIAL_RUNLEVEL5_TARGET,
266 if (startswith(word, "systemd.unit=")) {
269 return set_default_unit(word + 13);
271 } else if (startswith(word, "rd.systemd.unit=")) {
274 return set_default_unit(word + 16);
276 } else if (startswith(word, "systemd.log_target=")) {
278 if (log_set_target_from_string(word + 19) < 0)
279 log_warning("Failed to parse log target %s. Ignoring.", word + 19);
281 } else if (startswith(word, "systemd.log_level=")) {
283 if (log_set_max_level_from_string(word + 18) < 0)
284 log_warning("Failed to parse log level %s. Ignoring.", word + 18);
286 } else if (startswith(word, "systemd.log_color=")) {
288 if (log_show_color_from_string(word + 18) < 0)
289 log_warning("Failed to parse log color setting %s. Ignoring.", word + 18);
291 } else if (startswith(word, "systemd.log_location=")) {
293 if (log_show_location_from_string(word + 21) < 0)
294 log_warning("Failed to parse log location setting %s. Ignoring.", word + 21);
296 } else if (startswith(word, "systemd.dump_core=")) {
299 if ((r = parse_boolean(word + 18)) < 0)
300 log_warning("Failed to parse dump core switch %s. Ignoring.", word + 18);
304 } else if (startswith(word, "systemd.crash_shell=")) {
307 if ((r = parse_boolean(word + 20)) < 0)
308 log_warning("Failed to parse crash shell switch %s. Ignoring.", word + 20);
312 } else if (startswith(word, "systemd.confirm_spawn=")) {
315 if ((r = parse_boolean(word + 22)) < 0)
316 log_warning("Failed to parse confirm spawn switch %s. Ignoring.", word + 22);
318 arg_confirm_spawn = r;
320 } else if (startswith(word, "systemd.crash_chvt=")) {
323 if (safe_atoi(word + 19, &k) < 0)
324 log_warning("Failed to parse crash chvt switch %s. Ignoring.", word + 19);
328 } else if (startswith(word, "systemd.show_status=")) {
331 if ((r = parse_boolean(word + 20)) < 0)
332 log_warning("Failed to parse show status switch %s. Ignoring.", word + 20);
335 } else if (startswith(word, "systemd.default_standard_output=")) {
338 if ((r = exec_output_from_string(word + 32)) < 0)
339 log_warning("Failed to parse default standard output switch %s. Ignoring.", word + 32);
341 arg_default_std_output = r;
342 } else if (startswith(word, "systemd.default_standard_error=")) {
345 if ((r = exec_output_from_string(word + 31)) < 0)
346 log_warning("Failed to parse default standard error switch %s. Ignoring.", word + 31);
348 arg_default_std_error = r;
349 } else if (startswith(word, "systemd.setenv=")) {
350 _cleanup_free_ char *cenv = NULL;
352 cenv = strdup(word + 15);
356 if (env_assignment_is_valid(cenv)) {
359 env = strv_env_set(arg_default_environment, cenv);
361 arg_default_environment = env;
363 log_warning("Setting environment variable '%s' failed, ignoring: %m", cenv);
365 log_warning("Environment variable name '%s' is not valid. Ignoring.", cenv);
367 } else if (startswith(word, "systemd.") ||
368 (in_initrd() && startswith(word, "rd.systemd."))) {
372 /* Ignore systemd.journald.xyz and friends */
374 if (startswith(c, "rd."))
376 if (startswith(c, "systemd."))
378 if (c[strcspn(c, ".=")] != '.') {
380 log_warning("Unknown kernel switch %s. Ignoring.", word);
382 log_info("Supported kernel switches:\n"
383 "systemd.unit=UNIT Default unit to start\n"
384 "rd.systemd.unit=UNIT Default unit to start when run in initrd\n"
385 "systemd.dump_core=0|1 Dump core on crash\n"
386 "systemd.crash_shell=0|1 Run shell on crash\n"
387 "systemd.crash_chvt=N Change to VT #N on crash\n"
388 "systemd.confirm_spawn=0|1 Confirm every process spawn\n"
389 "systemd.show_status=0|1 Show status updates on the console during bootup\n"
390 "systemd.log_target=console|kmsg|journal|journal-or-kmsg|syslog|syslog-or-kmsg|null\n"
392 "systemd.log_level=LEVEL Log level\n"
393 "systemd.log_color=0|1 Highlight important log messages\n"
394 "systemd.log_location=0|1 Include code location in log messages\n"
395 "systemd.default_standard_output=null|tty|syslog|syslog+console|kmsg|kmsg+console|journal|journal+console\n"
396 " Set default log output for services\n"
397 "systemd.default_standard_error=null|tty|syslog|syslog+console|kmsg|kmsg+console|journal|journal+console\n"
398 " Set default log error output for services\n"
399 "systemd.setenv=ASSIGNMENT Set an environment variable for all spawned processes\n");
402 } else if (streq(word, "quiet"))
403 arg_show_status = false;
404 else if (streq(word, "debug")) {
405 /* Log to kmsg, the journal socket will fill up before the
406 * journal is started and tools running during that time
407 * will block with every log message for for 60 seconds,
408 * before they give up. */
409 log_set_max_level(LOG_DEBUG);
410 log_set_target(LOG_TARGET_KMSG);
411 } else if (!in_initrd()) {
414 /* SysV compatibility */
415 for (i = 0; i < ELEMENTSOF(rlmap); i += 2)
416 if (streq(word, rlmap[i]))
417 return set_default_unit(rlmap[i+1]);
423 #define DEFINE_SETTER(name, func, descr) \
424 static int name(const char *unit, \
425 const char *filename, \
427 const char *section, \
428 const char *lvalue, \
430 const char *rvalue, \
442 log_syntax(unit, LOG_ERR, filename, line, -r, \
443 "Invalid " descr "'%s': %s", \
444 rvalue, strerror(-r)); \
449 DEFINE_SETTER(config_parse_level2, log_set_max_level_from_string, "log level")
450 DEFINE_SETTER(config_parse_target, log_set_target_from_string, "target")
451 DEFINE_SETTER(config_parse_color, log_show_color_from_string, "color" )
452 DEFINE_SETTER(config_parse_location, log_show_location_from_string, "location")
455 static int config_parse_cpu_affinity2(const char *unit,
456 const char *filename,
475 FOREACH_WORD_QUOTED(w, l, rvalue, state) {
480 if (!(t = strndup(w, l)))
483 r = safe_atou(t, &cpu);
487 if (!(c = cpu_set_malloc(&ncpus)))
490 if (r < 0 || cpu >= ncpus) {
491 log_syntax(unit, LOG_ERR, filename, line, -r,
492 "Failed to parse CPU affinity '%s'", rvalue);
497 CPU_SET_S(cpu, CPU_ALLOC_SIZE(ncpus), c);
501 if (sched_setaffinity(0, CPU_ALLOC_SIZE(ncpus), c) < 0)
502 log_warning_unit(unit, "Failed to set CPU affinity: %m");
510 static void strv_free_free(char ***l) {
522 static void free_join_controllers(void) {
523 strv_free_free(arg_join_controllers);
524 arg_join_controllers = NULL;
527 static int config_parse_join_controllers(const char *unit,
528 const char *filename,
545 free_join_controllers();
547 FOREACH_WORD_QUOTED(w, length, rvalue, state) {
550 s = strndup(w, length);
554 l = strv_split(s, ",");
559 if (strv_length(l) <= 1) {
564 if (!arg_join_controllers) {
565 arg_join_controllers = new(char**, 2);
566 if (!arg_join_controllers) {
571 arg_join_controllers[0] = l;
572 arg_join_controllers[1] = NULL;
579 t = new0(char**, n+2);
587 for (a = arg_join_controllers; *a; a++) {
589 if (strv_overlap(*a, l)) {
592 c = strv_merge(*a, l);
615 t[n++] = strv_uniq(l);
617 strv_free_free(arg_join_controllers);
618 arg_join_controllers = t;
625 static int parse_config_file(void) {
627 const ConfigTableItem items[] = {
628 { "Manager", "LogLevel", config_parse_level2, 0, NULL },
629 { "Manager", "LogTarget", config_parse_target, 0, NULL },
630 { "Manager", "LogColor", config_parse_color, 0, NULL },
631 { "Manager", "LogLocation", config_parse_location, 0, NULL },
632 { "Manager", "DumpCore", config_parse_bool, 0, &arg_dump_core },
633 { "Manager", "CrashShell", config_parse_bool, 0, &arg_crash_shell },
634 { "Manager", "ShowStatus", config_parse_bool, 0, &arg_show_status },
635 { "Manager", "CrashChVT", config_parse_int, 0, &arg_crash_chvt },
636 { "Manager", "CPUAffinity", config_parse_cpu_affinity2, 0, NULL },
637 { "Manager", "DefaultStandardOutput", config_parse_output, 0, &arg_default_std_output },
638 { "Manager", "DefaultStandardError", config_parse_output, 0, &arg_default_std_error },
639 { "Manager", "JoinControllers", config_parse_join_controllers, 0, &arg_join_controllers },
640 { "Manager", "RuntimeWatchdogSec", config_parse_sec, 0, &arg_runtime_watchdog },
641 { "Manager", "ShutdownWatchdogSec", config_parse_sec, 0, &arg_shutdown_watchdog },
642 { "Manager", "CapabilityBoundingSet", config_parse_bounding_set, 0, &arg_capability_bounding_set_drop },
643 { "Manager", "TimerSlackNSec", config_parse_nsec, 0, &arg_timer_slack_nsec },
644 { "Manager", "DefaultEnvironment", config_parse_environ, 0, &arg_default_environment },
645 { "Manager", "DefaultLimitCPU", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_CPU]},
646 { "Manager", "DefaultLimitFSIZE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_FSIZE]},
647 { "Manager", "DefaultLimitDATA", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_DATA]},
648 { "Manager", "DefaultLimitSTACK", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_STACK]},
649 { "Manager", "DefaultLimitCORE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_CORE]},
650 { "Manager", "DefaultLimitRSS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RSS]},
651 { "Manager", "DefaultLimitNOFILE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NOFILE]},
652 { "Manager", "DefaultLimitAS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_AS]},
653 { "Manager", "DefaultLimitNPROC", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NPROC]},
654 { "Manager", "DefaultLimitMEMLOCK", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_MEMLOCK]},
655 { "Manager", "DefaultLimitLOCKS", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_LOCKS]},
656 { "Manager", "DefaultLimitSIGPENDING",config_parse_limit, 0, &arg_default_rlimit[RLIMIT_SIGPENDING]},
657 { "Manager", "DefaultLimitMSGQUEUE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_MSGQUEUE]},
658 { "Manager", "DefaultLimitNICE", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_NICE]},
659 { "Manager", "DefaultLimitRTPRIO", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RTPRIO]},
660 { "Manager", "DefaultLimitRTTIME", config_parse_limit, 0, &arg_default_rlimit[RLIMIT_RTTIME]},
661 { NULL, NULL, NULL, 0, NULL }
664 _cleanup_fclose_ FILE *f;
668 fn = arg_running_as == SYSTEMD_SYSTEM ? PKGSYSCONFDIR "/system.conf" : PKGSYSCONFDIR "/user.conf";
674 log_warning("Failed to open configuration file '%s': %m", fn);
678 r = config_parse(NULL, fn, f, "Manager\0", config_item_table_lookup, (void*) items, false, false, NULL);
680 log_warning("Failed to parse configuration file: %s", strerror(-r));
685 static int parse_proc_cmdline(void) {
686 _cleanup_free_ char *line = NULL;
691 /* Don't read /proc/cmdline if we are in a container, since
692 * that is only relevant for the host system */
693 if (detect_container(NULL) > 0)
696 r = read_one_line_file("/proc/cmdline", &line);
698 log_warning("Failed to read /proc/cmdline, ignoring: %s", strerror(-r));
702 FOREACH_WORD_QUOTED(w, l, line, state) {
703 _cleanup_free_ char *word;
705 word = strndup(w, l);
709 r = parse_proc_cmdline_word(word);
711 log_error("Failed on cmdline argument %s: %s", word, strerror(-r));
719 static int parse_argv(int argc, char *argv[]) {
722 ARG_LOG_LEVEL = 0x100,
731 ARG_DUMP_CONFIGURATION_ITEMS,
739 ARG_DEFAULT_STD_OUTPUT,
740 ARG_DEFAULT_STD_ERROR
743 static const struct option options[] = {
744 { "log-level", required_argument, NULL, ARG_LOG_LEVEL },
745 { "log-target", required_argument, NULL, ARG_LOG_TARGET },
746 { "log-color", optional_argument, NULL, ARG_LOG_COLOR },
747 { "log-location", optional_argument, NULL, ARG_LOG_LOCATION },
748 { "unit", required_argument, NULL, ARG_UNIT },
749 { "system", no_argument, NULL, ARG_SYSTEM },
750 { "user", no_argument, NULL, ARG_USER },
751 { "test", no_argument, NULL, ARG_TEST },
752 { "help", no_argument, NULL, 'h' },
753 { "version", no_argument, NULL, ARG_VERSION },
754 { "dump-configuration-items", no_argument, NULL, ARG_DUMP_CONFIGURATION_ITEMS },
755 { "dump-core", optional_argument, NULL, ARG_DUMP_CORE },
756 { "crash-shell", optional_argument, NULL, ARG_CRASH_SHELL },
757 { "confirm-spawn", optional_argument, NULL, ARG_CONFIRM_SPAWN },
758 { "show-status", optional_argument, NULL, ARG_SHOW_STATUS },
759 { "deserialize", required_argument, NULL, ARG_DESERIALIZE },
760 { "switched-root", no_argument, NULL, ARG_SWITCHED_ROOT },
761 { "introspect", optional_argument, NULL, ARG_INTROSPECT },
762 { "default-standard-output", required_argument, NULL, ARG_DEFAULT_STD_OUTPUT, },
763 { "default-standard-error", required_argument, NULL, ARG_DEFAULT_STD_ERROR, },
775 while ((c = getopt_long(argc, argv, "hDbsz:", options, NULL)) >= 0)
780 if ((r = log_set_max_level_from_string(optarg)) < 0) {
781 log_error("Failed to parse log level %s.", optarg);
789 if ((r = log_set_target_from_string(optarg)) < 0) {
790 log_error("Failed to parse log target %s.", optarg);
799 if ((r = log_show_color_from_string(optarg)) < 0) {
800 log_error("Failed to parse log color setting %s.", optarg);
804 log_show_color(true);
808 case ARG_LOG_LOCATION:
811 if ((r = log_show_location_from_string(optarg)) < 0) {
812 log_error("Failed to parse log location setting %s.", optarg);
816 log_show_location(true);
820 case ARG_DEFAULT_STD_OUTPUT:
822 if ((r = exec_output_from_string(optarg)) < 0) {
823 log_error("Failed to parse default standard output setting %s.", optarg);
826 arg_default_std_output = r;
829 case ARG_DEFAULT_STD_ERROR:
831 if ((r = exec_output_from_string(optarg)) < 0) {
832 log_error("Failed to parse default standard error output setting %s.", optarg);
835 arg_default_std_error = r;
840 if ((r = set_default_unit(optarg)) < 0) {
841 log_error("Failed to set default unit %s: %s", optarg, strerror(-r));
848 arg_running_as = SYSTEMD_SYSTEM;
852 arg_running_as = SYSTEMD_USER;
856 arg_action = ACTION_TEST;
860 arg_action = ACTION_VERSION;
863 case ARG_DUMP_CONFIGURATION_ITEMS:
864 arg_action = ACTION_DUMP_CONFIGURATION_ITEMS;
868 r = optarg ? parse_boolean(optarg) : 1;
870 log_error("Failed to parse dump core boolean %s.", optarg);
876 case ARG_CRASH_SHELL:
877 r = optarg ? parse_boolean(optarg) : 1;
879 log_error("Failed to parse crash shell boolean %s.", optarg);
885 case ARG_CONFIRM_SPAWN:
886 r = optarg ? parse_boolean(optarg) : 1;
888 log_error("Failed to parse confirm spawn boolean %s.", optarg);
891 arg_confirm_spawn = r;
894 case ARG_SHOW_STATUS:
895 r = optarg ? parse_boolean(optarg) : 1;
897 log_error("Failed to parse show status boolean %s.", optarg);
903 case ARG_DESERIALIZE: {
907 r = safe_atoi(optarg, &fd);
908 if (r < 0 || fd < 0) {
909 log_error("Failed to parse deserialize option %s.", optarg);
910 return r < 0 ? r : -EINVAL;
913 fd_cloexec(fd, true);
917 log_error("Failed to open serialization fd: %m");
922 fclose(serialization);
929 case ARG_SWITCHED_ROOT:
930 arg_switched_root = true;
933 case ARG_INTROSPECT: {
934 const char * const * i = NULL;
936 for (i = bus_interface_table; *i; i += 2)
937 if (!optarg || streq(i[0], optarg)) {
938 fputs(DBUS_INTROSPECT_1_0_XML_DOCTYPE_DECL_NODE
941 fputs("</node>\n", stdout);
948 log_error("Unknown interface %s.", optarg);
950 arg_action = ACTION_DONE;
955 arg_action = ACTION_HELP;
959 log_set_max_level(LOG_DEBUG);
965 /* Just to eat away the sysvinit kernel
966 * cmdline args without getopt() error
967 * messages that we'll parse in
968 * parse_proc_cmdline_word() or ignore. */
973 log_error("Unknown option code %c", c);
980 if (optind < argc && getpid() != 1) {
981 /* Hmm, when we aren't run as init system
982 * let's complain about excess arguments */
984 log_error("Excess arguments.");
988 if (detect_container(NULL) > 0) {
991 /* All /proc/cmdline arguments the kernel didn't
992 * understand it passed to us. We're not really
993 * interested in that usually since /proc/cmdline is
994 * more interesting and complete. With one exception:
995 * if we are run in a container /proc/cmdline is not
996 * relevant for the container, hence we rely on argv[]
999 for (a = argv; a < argv + argc; a++)
1000 if ((r = parse_proc_cmdline_word(*a)) < 0) {
1001 log_error("Failed on cmdline argument %s: %s", *a, strerror(-r));
1009 static int help(void) {
1011 printf("%s [OPTIONS...]\n\n"
1012 "Starts up and maintains the system or user services.\n\n"
1013 " -h --help Show this help\n"
1014 " --test Determine startup sequence, dump it and exit\n"
1015 " --dump-configuration-items Dump understood unit configuration items\n"
1016 " --introspect[=INTERFACE] Extract D-Bus interface data\n"
1017 " --unit=UNIT Set default unit\n"
1018 " --system Run a system instance, even if PID != 1\n"
1019 " --user Run a user instance\n"
1020 " --dump-core[=0|1] Dump core on crash\n"
1021 " --crash-shell[=0|1] Run shell on crash\n"
1022 " --confirm-spawn[=0|1] Ask for confirmation when spawning processes\n"
1023 " --show-status[=0|1] Show status updates on the console during bootup\n"
1024 " --log-target=TARGET Set log target (console, journal, syslog, kmsg, journal-or-kmsg, syslog-or-kmsg, null)\n"
1025 " --log-level=LEVEL Set log level (debug, info, notice, warning, err, crit, alert, emerg)\n"
1026 " --log-color[=0|1] Highlight important log messages\n"
1027 " --log-location[=0|1] Include code location in log messages\n"
1028 " --default-standard-output= Set default standard output for services\n"
1029 " --default-standard-error= Set default standard error output for services\n",
1030 program_invocation_short_name);
1035 static int version(void) {
1036 puts(PACKAGE_STRING);
1037 puts(SYSTEMD_FEATURES);
1042 static int prepare_reexecute(Manager *m, FILE **_f, FDSet **_fds, bool switching_root) {
1051 r = manager_open_serialization(m, &f);
1053 log_error("Failed to create serialization file: %s", strerror(-r));
1057 /* Make sure nothing is really destructed when we shut down */
1059 bus_broadcast_reloading(m, true);
1064 log_error("Failed to allocate fd set: %s", strerror(-r));
1068 r = manager_serialize(m, f, fds, switching_root);
1070 log_error("Failed to serialize state: %s", strerror(-r));
1074 if (fseeko(f, 0, SEEK_SET) < 0) {
1075 log_error("Failed to rewind serialization fd: %m");
1079 r = fd_cloexec(fileno(f), false);
1081 log_error("Failed to disable O_CLOEXEC for serialization: %s", strerror(-r));
1085 r = fdset_cloexec(fds, false);
1087 log_error("Failed to disable O_CLOEXEC for serialization fds: %s", strerror(-r));
1105 static int bump_rlimit_nofile(struct rlimit *saved_rlimit) {
1109 assert(saved_rlimit);
1111 /* Save the original RLIMIT_NOFILE so that we can reset it
1112 * later when transitioning from the initrd to the main
1113 * systemd or suchlike. */
1114 if (getrlimit(RLIMIT_NOFILE, saved_rlimit) < 0) {
1115 log_error("Reading RLIMIT_NOFILE failed: %m");
1119 /* Make sure forked processes get the default kernel setting */
1120 if (!arg_default_rlimit[RLIMIT_NOFILE]) {
1123 rl = newdup(struct rlimit, saved_rlimit, 1);
1127 arg_default_rlimit[RLIMIT_NOFILE] = rl;
1130 /* Bump up the resource limit for ourselves substantially */
1131 nl.rlim_cur = nl.rlim_max = 64*1024;
1132 r = setrlimit_closest(RLIMIT_NOFILE, &nl);
1134 log_error("Setting RLIMIT_NOFILE failed: %s", strerror(-r));
1141 static void test_mtab(void) {
1144 /* Check that /etc/mtab is a symlink */
1146 if (readlink_malloc("/etc/mtab", &p) >= 0) {
1149 b = streq(p, "/proc/self/mounts") || streq(p, "/proc/mounts");
1156 log_warning("/etc/mtab is not a symlink or not pointing to /proc/self/mounts. "
1157 "This is not supported anymore. "
1158 "Please make sure to replace this file by a symlink to avoid incorrect or misleading mount(8) output.");
1161 static void test_usr(void) {
1163 /* Check that /usr is not a separate fs */
1165 if (dir_is_empty("/usr") <= 0)
1168 log_warning("/usr appears to be on its own filesytem and is not already mounted. This is not a supported setup. "
1169 "Some things will probably break (sometimes even silently) in mysterious ways. "
1170 "Consult http://freedesktop.org/wiki/Software/systemd/separate-usr-is-broken for more information.");
1173 static void test_cgroups(void) {
1175 if (access("/proc/cgroups", F_OK) >= 0)
1178 log_warning("CONFIG_CGROUPS was not set when your kernel was compiled. "
1179 "Systems without control groups are not supported. "
1180 "We will now sleep for 10s, and then continue boot-up. "
1181 "Expect breakage and please do not file bugs. "
1182 "Instead fix your kernel and enable CONFIG_CGROUPS. "
1183 "Consult http://0pointer.de/blog/projects/cgroups-vs-cgroups.html for more information.");
1188 static int initialize_join_controllers(void) {
1189 /* By default, mount "cpu" + "cpuacct" together, and "net_cls"
1190 * + "net_prio". We'd like to add "cpuset" to the mix, but
1191 * "cpuset" does't really work for groups with no initialized
1194 arg_join_controllers = new(char**, 3);
1195 if (!arg_join_controllers)
1198 arg_join_controllers[0] = strv_new("cpu", "cpuacct", NULL);
1199 arg_join_controllers[1] = strv_new("net_cls", "net_prio", NULL);
1200 arg_join_controllers[2] = NULL;
1202 if (!arg_join_controllers[0] || !arg_join_controllers[1]) {
1203 free_join_controllers();
1210 int main(int argc, char *argv[]) {
1212 int r, retval = EXIT_FAILURE;
1213 usec_t before_startup, after_startup;
1214 char timespan[FORMAT_TIMESPAN_MAX];
1216 bool reexecute = false;
1217 const char *shutdown_verb = NULL;
1218 dual_timestamp initrd_timestamp = { 0ULL, 0ULL };
1219 dual_timestamp userspace_timestamp = { 0ULL, 0ULL };
1220 dual_timestamp kernel_timestamp = { 0ULL, 0ULL };
1221 static char systemd[] = "systemd";
1222 bool skip_setup = false;
1224 bool loaded_policy = false;
1225 bool arm_reboot_watchdog = false;
1226 bool queue_default_job = false;
1227 char *switch_root_dir = NULL, *switch_root_init = NULL;
1228 static struct rlimit saved_rlimit_nofile = { 0, 0 };
1230 #ifdef HAVE_SYSV_COMPAT
1231 if (getpid() != 1 && strstr(program_invocation_short_name, "init")) {
1232 /* This is compatibility support for SysV, where
1233 * calling init as a user is identical to telinit. */
1236 execv(SYSTEMCTL_BINARY_PATH, argv);
1237 log_error("Failed to exec " SYSTEMCTL_BINARY_PATH ": %m");
1242 dual_timestamp_from_monotonic(&kernel_timestamp, 0);
1243 dual_timestamp_get(&userspace_timestamp);
1245 /* Determine if this is a reexecution or normal bootup. We do
1246 * the full command line parsing much later, so let's just
1247 * have a quick peek here. */
1248 if (strv_find(argv+1, "--deserialize"))
1251 /* If we have switched root, do all the special setup
1253 if (strv_find(argv+1, "--switched-root"))
1256 /* If we get started via the /sbin/init symlink then we are
1257 called 'init'. After a subsequent reexecution we are then
1258 called 'systemd'. That is confusing, hence let's call us
1259 systemd right-away. */
1260 program_invocation_short_name = systemd;
1261 prctl(PR_SET_NAME, systemd);
1266 log_show_color(isatty(STDERR_FILENO) > 0);
1268 /* Disable the umask logic */
1272 if (getpid() == 1 && detect_container(NULL) <= 0) {
1274 /* Running outside of a container as PID 1 */
1275 arg_running_as = SYSTEMD_SYSTEM;
1277 log_set_target(LOG_TARGET_KMSG);
1281 initrd_timestamp = userspace_timestamp;
1284 mount_setup_early();
1285 if (selinux_setup(&loaded_policy) < 0)
1287 if (ima_setup() < 0)
1289 if (smack_setup() < 0)
1293 if (label_init(NULL) < 0)
1297 if (hwclock_is_localtime() > 0) {
1300 /* The first-time call to settimeofday() does a time warp in the kernel */
1301 r = hwclock_set_timezone(&min);
1303 log_error("Failed to apply local time delta, ignoring: %s", strerror(-r));
1305 log_info("RTC configured in localtime, applying delta of %i minutes to system time.", min);
1306 } else if (!in_initrd()) {
1308 * Do dummy first-time call to seal the kernel's time warp magic
1310 * Do not call this this from inside the initrd. The initrd might not
1311 * carry /etc/adjtime with LOCAL, but the real system could be set up
1312 * that way. In such case, we need to delay the time-warp or the sealing
1313 * until we reach the real system.
1315 hwclock_reset_timezone();
1317 /* Tell the kernel our timezone */
1318 r = hwclock_set_timezone(NULL);
1320 log_error("Failed to set the kernel's timezone, ignoring: %s", strerror(-r));
1324 /* Set the default for later on, but don't actually
1325 * open the logs like this for now. Note that if we
1326 * are transitioning from the initrd there might still
1327 * be journal fd open, and we shouldn't attempt
1328 * opening that before we parsed /proc/cmdline which
1329 * might redirect output elsewhere. */
1330 log_set_target(LOG_TARGET_JOURNAL_OR_KMSG);
1332 } else if (getpid() == 1) {
1333 /* Running inside a container, as PID 1 */
1334 arg_running_as = SYSTEMD_SYSTEM;
1335 log_set_target(LOG_TARGET_CONSOLE);
1338 /* For the later on, see above... */
1339 log_set_target(LOG_TARGET_JOURNAL);
1341 /* clear the kernel timestamp,
1342 * because we are in a container */
1343 kernel_timestamp.monotonic = 0ULL;
1344 kernel_timestamp.realtime = 0ULL;
1347 /* Running as user instance */
1348 arg_running_as = SYSTEMD_USER;
1349 log_set_target(LOG_TARGET_AUTO);
1352 /* clear the kernel timestamp,
1353 * because we are not PID 1 */
1354 kernel_timestamp.monotonic = 0ULL;
1355 kernel_timestamp.realtime = 0ULL;
1358 /* Initialize default unit */
1359 r = set_default_unit(SPECIAL_DEFAULT_TARGET);
1361 log_error("Failed to set default unit %s: %s", SPECIAL_DEFAULT_TARGET, strerror(-r));
1365 r = initialize_join_controllers();
1369 /* Mount /proc, /sys and friends, so that /proc/cmdline and
1370 * /proc/$PID/fd is available. */
1371 if (getpid() == 1) {
1372 r = mount_setup(loaded_policy);
1377 /* Reset all signal handlers. */
1378 assert_se(reset_all_signal_handlers() == 0);
1380 ignore_signals(SIGNALS_IGNORE, -1);
1382 if (parse_config_file() < 0)
1385 if (arg_running_as == SYSTEMD_SYSTEM)
1386 if (parse_proc_cmdline() < 0)
1389 log_parse_environment();
1391 if (parse_argv(argc, argv) < 0)
1394 if (arg_action == ACTION_TEST &&
1396 log_error("Don't run test mode as root.");
1400 if (arg_running_as == SYSTEMD_USER &&
1401 arg_action == ACTION_RUN &&
1403 log_error("Trying to run as user instance, but the system has not been booted with systemd.");
1407 if (arg_running_as == SYSTEMD_SYSTEM &&
1408 arg_action == ACTION_RUN &&
1409 running_in_chroot() > 0) {
1410 log_error("Cannot be run in a chroot() environment.");
1414 if (arg_action == ACTION_HELP) {
1417 } else if (arg_action == ACTION_VERSION) {
1420 } else if (arg_action == ACTION_DUMP_CONFIGURATION_ITEMS) {
1421 unit_dump_config_items(stdout);
1422 retval = EXIT_SUCCESS;
1424 } else if (arg_action == ACTION_DONE) {
1425 retval = EXIT_SUCCESS;
1429 assert_se(arg_action == ACTION_RUN || arg_action == ACTION_TEST);
1431 /* Close logging fds, in order not to confuse fdset below */
1434 /* Remember open file descriptors for later deserialization */
1435 r = fdset_new_fill(&fds);
1437 log_error("Failed to allocate fd set: %s", strerror(-r));
1440 fdset_cloexec(fds, true);
1443 assert_se(fdset_remove(fds, fileno(serialization)) >= 0);
1445 if (arg_running_as == SYSTEMD_SYSTEM)
1446 /* Become a session leader if we aren't one yet. */
1449 /* Move out of the way, so that we won't block unmounts */
1450 assert_se(chdir("/") == 0);
1452 /* Make sure D-Bus doesn't fiddle with the SIGPIPE handlers */
1453 dbus_connection_set_change_sigpipe(FALSE);
1455 /* Reset the console, but only if this is really init and we
1456 * are freshly booted */
1457 if (arg_running_as == SYSTEMD_SYSTEM && arg_action == ACTION_RUN)
1458 console_setup(getpid() == 1 && !skip_setup);
1460 /* Open the logging devices, if possible and necessary */
1463 /* Make sure we leave a core dump without panicing the
1465 if (getpid() == 1) {
1466 install_crash_handler();
1468 r = mount_cgroup_controllers(arg_join_controllers);
1473 if (arg_running_as == SYSTEMD_SYSTEM) {
1474 const char *virtualization = NULL;
1476 log_info(PACKAGE_STRING " running in system mode. (" SYSTEMD_FEATURES ")");
1478 detect_virtualization(&virtualization);
1480 log_info("Detected virtualization '%s'.", virtualization);
1483 log_info("Running in initial RAM disk.");
1486 log_debug(PACKAGE_STRING " running in user mode. (" SYSTEMD_FEATURES ")");
1488 if (arg_running_as == SYSTEMD_SYSTEM && !skip_setup) {
1489 if (arg_show_status || plymouth_running())
1504 if (arg_running_as == SYSTEMD_SYSTEM && arg_runtime_watchdog > 0)
1505 watchdog_set_timeout(&arg_runtime_watchdog);
1507 if (arg_timer_slack_nsec != (nsec_t) -1)
1508 if (prctl(PR_SET_TIMERSLACK, arg_timer_slack_nsec) < 0)
1509 log_error("Failed to adjust timer slack: %m");
1511 if (arg_capability_bounding_set_drop) {
1512 r = capability_bounding_set_drop_usermode(arg_capability_bounding_set_drop);
1514 log_error("Failed to drop capability bounding set of usermode helpers: %s", strerror(-r));
1517 r = capability_bounding_set_drop(arg_capability_bounding_set_drop, true);
1519 log_error("Failed to drop capability bounding set: %s", strerror(-r));
1524 if (arg_running_as == SYSTEMD_USER) {
1525 /* Become reaper of our children */
1526 if (prctl(PR_SET_CHILD_SUBREAPER, 1) < 0) {
1527 log_warning("Failed to make us a subreaper: %m");
1528 if (errno == EINVAL)
1529 log_info("Perhaps the kernel version is too old (< 3.4?)");
1533 if (arg_running_as == SYSTEMD_SYSTEM)
1534 bump_rlimit_nofile(&saved_rlimit_nofile);
1536 r = manager_new(arg_running_as, !!serialization, &m);
1538 log_error("Failed to allocate manager object: %s", strerror(-r));
1542 m->confirm_spawn = arg_confirm_spawn;
1543 m->default_std_output = arg_default_std_output;
1544 m->default_std_error = arg_default_std_error;
1545 m->runtime_watchdog = arg_runtime_watchdog;
1546 m->shutdown_watchdog = arg_shutdown_watchdog;
1547 m->userspace_timestamp = userspace_timestamp;
1548 m->kernel_timestamp = kernel_timestamp;
1549 m->initrd_timestamp = initrd_timestamp;
1551 manager_set_default_rlimits(m, arg_default_rlimit);
1553 if (arg_default_environment)
1554 manager_environment_add(m, arg_default_environment);
1556 manager_set_show_status(m, arg_show_status);
1558 /* Remember whether we should queue the default job */
1559 queue_default_job = !serialization || arg_switched_root;
1561 before_startup = now(CLOCK_MONOTONIC);
1563 r = manager_startup(m, serialization, fds);
1565 log_error("Failed to fully start up daemon: %s", strerror(-r));
1567 /* This will close all file descriptors that were opened, but
1568 * not claimed by any unit. */
1572 if (serialization) {
1573 fclose(serialization);
1574 serialization = NULL;
1577 if (queue_default_job) {
1579 Unit *target = NULL;
1580 Job *default_unit_job;
1582 dbus_error_init(&error);
1584 log_debug("Activating default unit: %s", arg_default_unit);
1586 r = manager_load_unit(m, arg_default_unit, NULL, &error, &target);
1588 log_error("Failed to load default target: %s", bus_error(&error, r));
1589 dbus_error_free(&error);
1590 } else if (target->load_state == UNIT_ERROR || target->load_state == UNIT_NOT_FOUND)
1591 log_error("Failed to load default target: %s", strerror(-target->load_error));
1592 else if (target->load_state == UNIT_MASKED)
1593 log_error("Default target masked.");
1595 if (!target || target->load_state != UNIT_LOADED) {
1596 log_info("Trying to load rescue target...");
1598 r = manager_load_unit(m, SPECIAL_RESCUE_TARGET, NULL, &error, &target);
1600 log_error("Failed to load rescue target: %s", bus_error(&error, r));
1601 dbus_error_free(&error);
1603 } else if (target->load_state == UNIT_ERROR || target->load_state == UNIT_NOT_FOUND) {
1604 log_error("Failed to load rescue target: %s", strerror(-target->load_error));
1606 } else if (target->load_state == UNIT_MASKED) {
1607 log_error("Rescue target masked.");
1612 assert(target->load_state == UNIT_LOADED);
1614 if (arg_action == ACTION_TEST) {
1615 printf("-> By units:\n");
1616 manager_dump_units(m, stdout, "\t");
1619 r = manager_add_job(m, JOB_START, target, JOB_ISOLATE, false, &error, &default_unit_job);
1621 log_debug("Default target could not be isolated, starting instead: %s", bus_error(&error, r));
1622 dbus_error_free(&error);
1624 r = manager_add_job(m, JOB_START, target, JOB_REPLACE, false, &error, &default_unit_job);
1626 log_error("Failed to start default target: %s", bus_error(&error, r));
1627 dbus_error_free(&error);
1631 log_error("Failed to isolate default target: %s", bus_error(&error, r));
1632 dbus_error_free(&error);
1636 m->default_unit_job_id = default_unit_job->id;
1638 after_startup = now(CLOCK_MONOTONIC);
1639 log_full(arg_action == ACTION_TEST ? LOG_INFO : LOG_DEBUG,
1640 "Loaded units and determined initial transaction in %s.",
1641 format_timespan(timespan, sizeof(timespan), after_startup - before_startup, 0));
1643 if (arg_action == ACTION_TEST) {
1644 printf("-> By jobs:\n");
1645 manager_dump_jobs(m, stdout, "\t");
1646 retval = EXIT_SUCCESS;
1652 r = manager_loop(m);
1654 log_error("Failed to run mainloop: %s", strerror(-r));
1658 switch (m->exit_code) {
1661 retval = EXIT_SUCCESS;
1665 case MANAGER_RELOAD:
1666 log_info("Reloading.");
1667 r = manager_reload(m);
1669 log_error("Failed to reload: %s", strerror(-r));
1672 case MANAGER_REEXECUTE:
1674 if (prepare_reexecute(m, &serialization, &fds, false) < 0)
1678 log_notice("Reexecuting.");
1681 case MANAGER_SWITCH_ROOT:
1682 /* Steal the switch root parameters */
1683 switch_root_dir = m->switch_root;
1684 switch_root_init = m->switch_root_init;
1685 m->switch_root = m->switch_root_init = NULL;
1687 if (!switch_root_init)
1688 if (prepare_reexecute(m, &serialization, &fds, true) < 0)
1692 log_notice("Switching root.");
1695 case MANAGER_REBOOT:
1696 case MANAGER_POWEROFF:
1698 case MANAGER_KEXEC: {
1699 static const char * const table[_MANAGER_EXIT_CODE_MAX] = {
1700 [MANAGER_REBOOT] = "reboot",
1701 [MANAGER_POWEROFF] = "poweroff",
1702 [MANAGER_HALT] = "halt",
1703 [MANAGER_KEXEC] = "kexec"
1706 assert_se(shutdown_verb = table[m->exit_code]);
1707 arm_reboot_watchdog = m->exit_code == MANAGER_REBOOT;
1709 log_notice("Shutting down.");
1714 assert_not_reached("Unknown exit code.");
1722 for (j = 0; j < RLIMIT_NLIMITS; j++)
1723 free(arg_default_rlimit[j]);
1725 free(arg_default_unit);
1726 free_join_controllers();
1733 unsigned i, args_size;
1735 /* Close and disarm the watchdog, so that the new
1736 * instance can reinitialize it, but doesn't get
1737 * rebooted while we do that */
1738 watchdog_close(true);
1740 /* Reset the RLIMIT_NOFILE to the kernel default, so
1741 * that the new systemd can pass the kernel default to
1742 * its child processes */
1743 if (saved_rlimit_nofile.rlim_cur > 0)
1744 setrlimit(RLIMIT_NOFILE, &saved_rlimit_nofile);
1746 if (switch_root_dir) {
1747 /* Kill all remaining processes from the
1748 * initrd, but don't wait for them, so that we
1749 * can handle the SIGCHLD for them after
1751 broadcast_signal(SIGTERM, false);
1753 /* And switch root */
1754 r = switch_root(switch_root_dir);
1756 log_error("Failed to switch root, ignoring: %s", strerror(-r));
1759 args_size = MAX(6, argc+1);
1760 args = newa(const char*, args_size);
1762 if (!switch_root_init) {
1765 /* First try to spawn ourselves with the right
1766 * path, and with full serialization. We do
1767 * this only if the user didn't specify an
1768 * explicit init to spawn. */
1770 assert(serialization);
1773 snprintf(sfd, sizeof(sfd), "%i", fileno(serialization));
1777 args[i++] = SYSTEMD_BINARY_PATH;
1778 if (switch_root_dir)
1779 args[i++] = "--switched-root";
1780 args[i++] = arg_running_as == SYSTEMD_SYSTEM ? "--system" : "--user";
1781 args[i++] = "--deserialize";
1785 /* do not pass along the environment we inherit from the kernel or initrd */
1786 if (switch_root_dir)
1789 assert(i <= args_size);
1790 execv(args[0], (char* const*) args);
1793 /* Try the fallback, if there is any, without any
1794 * serialization. We pass the original argv[] and
1795 * envp[]. (Well, modulo the ordering changes due to
1796 * getopt() in argv[], and some cleanups in envp[],
1797 * but let's hope that doesn't matter.) */
1799 if (serialization) {
1800 fclose(serialization);
1801 serialization = NULL;
1809 /* Reopen the console */
1810 make_console_stdio();
1812 for (j = 1, i = 1; j < argc; j++)
1813 args[i++] = argv[j];
1815 assert(i <= args_size);
1817 if (switch_root_init) {
1818 args[0] = switch_root_init;
1819 execv(args[0], (char* const*) args);
1820 log_warning("Failed to execute configured init, trying fallback: %m");
1823 args[0] = "/sbin/init";
1824 execv(args[0], (char* const*) args);
1826 if (errno == ENOENT) {
1827 log_warning("No /sbin/init, trying fallback");
1829 args[0] = "/bin/sh";
1831 execv(args[0], (char* const*) args);
1832 log_error("Failed to execute /bin/sh, giving up: %m");
1834 log_warning("Failed to execute /sbin/init, giving up: %m");
1838 fclose(serialization);
1843 if (shutdown_verb) {
1844 const char * command_line[] = {
1845 SYSTEMD_SHUTDOWN_BINARY_PATH,
1851 if (arm_reboot_watchdog && arg_shutdown_watchdog > 0) {
1854 /* If we reboot let's set the shutdown
1855 * watchdog and tell the shutdown binary to
1856 * repeatedly ping it */
1857 watchdog_set_timeout(&arg_shutdown_watchdog);
1858 watchdog_close(false);
1860 /* Tell the binary how often to ping */
1861 snprintf(e, sizeof(e), "WATCHDOG_USEC=%llu", (unsigned long long) arg_shutdown_watchdog);
1864 env_block = strv_append(environ, e);
1866 env_block = strv_copy(environ);
1867 watchdog_close(true);
1870 /* Avoid the creation of new processes forked by the
1871 * kernel; at this point, we will not listen to the
1873 if (detect_container(NULL) <= 0)
1874 cg_uninstall_release_agent(SYSTEMD_CGROUP_CONTROLLER);
1876 execve(SYSTEMD_SHUTDOWN_BINARY_PATH, (char **) command_line, env_block);
1878 log_error("Failed to execute shutdown binary, freezing: %m");