Re: s6/s6-rc policy for Gentoo: XDG Base Directory Specification

Paul Sopka <[email protected]> Sun, 7 Jul 2024 11:06:13 +0200
Newsgroups gmane.comp.sysutils.supervision.general
Message-ID <[email protected]>
> I don't think avoiding Turnstile (and similar projects) in favor of s6
> services is reasonable, given the concerns you've raised in the first
> block ofhttps://skarnet.org/lists/supervision/3122.html  (especially
> "I'd like for the user supervision tree to only start on-demand").

I do not want to avoid them, they are straight up required to setup 
option B) from https://skarnet.org/lists/supervision/3114.html.

Instead, I want to delegate as few functionality to them as possible. 
Why should I e.g. delegate the creation a directory to a binary, 
configured through its own config file, if it would just be one line in 
a script that loads the defining variables and is ran anyway?


> Turnstile's interface is reasonably simple and easy to implement in an
> alternative: backends are effectively supervised 'run' (in the
> s6/runit sense) scripts for the service manager with extra arguments,
> and I believe it to be pretty much the minimum viable program for
> adding XDG_RUNTIME_DIR compliance to any given service manager.
I experimented with Turnstile yesterday and hit major roadblocks.

Here is what I have understood it does:

once the user first logs in:

a1) execute "${BACKEND} run ${notification_fd}"    with an environment 
of ${USER}, ${HOME}, ...

  once ${BACKEND} writes back to ${notification_fd}:

a2) execute "${BACKEND} ready ${string}"/    without /the environment, 
but passing what was written back to ${notification_fd} beforehand as 
${string}

once the user last logs out:

b1) execute "${BACKEND} stop"

b2) kill the process started in a1) (in our case s6-svscan)

 From that structure I naturally would propose the following script, 
having ${XDG_RUNTIME_DIR} managed by Turnstile:


#!/usr/bin/env execlineb

importas directive 1
importas readinessPipe 2
importas -S XDG_RUNTIME_DIR
importas -S USER

case ${directive}
{
     run
     {
         foreground {
             install -d -o ${USER} -g ${USER} ${XDG_RUNTIME_DIR}/service
         }
         redirfd -w 3 ${readinessPipe} s6-svscan -d3 
${XDG_RUNTIME_DIR}/service
     }
     ready
     {
         foreground {
             s6-rc-init -c /home/${USER}/.local/share/s6-rc/compiled -l 
${XDG_RUNTIME_DIR}/s6-rc ${XDG_RUNTIME_DIR}/service
         }
         s6-rc -v2 -l ${XDG_RUNTIME_DIR}/s6-rc -up change default
     }
     stop
     {
         s6-rc -l ${XDG_RUNTIME_DIR}/s6-rc -bDa change
     }
}

exit 100


This does not work, since when a2) is invoked to run the "ready" part, 
we do not have ${XDG_RUNTIME_DIR} anymore. I do not see how to solve 
this without a workaround.

A possible workaround would be doubly defining XDG_RUNTIME_DIR, once in 
the Turnstile config and once in an env file which is sourced in the 
"ready" "function".


I have two major issues here:

A) ${BACKEND} is always invoked with the user's privileges, thus it can 
not create ${XDG_RUNTIME_DIR} itself.

B) a2) happens without the environment, see the issue with the script.


I think A) is a problem, since I am planning:

a)  to have a central user env file, preferably at 
/home/${USER}/.config/s6-env (${XDG_CONFIG_HOME}/s6-env), for the user 
to tweak his settings, e.g. ${DBUS_SESSION_BUS_ADDRESS}

b) to have a central sysadmin env file, preferably at /etc/s6-rc/config 
(or similar), for the system admin to tweak the settings, e.g. the 
${XDG_RUNTIME_DIR} general structure, the creation of which has to be 
delegated to Turnstile, since the script does not have enough 
permissions. This would then have to be doubly defined(once in the 
Turnstile config and once in the env-file)


> Saying "this will make it easier to implement an alternative"
> overlooks the fact that the complexity will be shifted into the
> service set and the service manager. Is it really worth it to go
> through dynamic services and events (at least, one `install -d`
> oneshot per user, and a first login/last logout event source), and
> probably other things required to make this more reliable, pretty much
> just to make a folder?
I agree about the complexity shift. But I think the solution of using 
Turnstile just as a "notifications-system" is the best: ideally it 
should do the following: if ${USER} first logs in, start the system 
service ${USER}, if he logs out of the last instance stop the system 
service ${USER}.

This yields the following advantages:

A) The added complexity is in my opinion negligible(see my current 
scripts here: https://skarnet.org/lists/supervision/3123.html).

B) My idea gives the sysadmin and the user more control over their 
system (e.g. basing the location of ${XDG_RUNTIME_DIR} on a central env 
file where other settings are set too).

C) My idea allows plugging the user supervision tree directly into the 
system supervision tree, with the following advantages

     1) Allowing to directly attach a "catch all" logger separated from 
the logger of Turnstile

     2) Keeping the chain of efficient and reliable "skarware" from the 
top of the tree until the last user service, without Turnstile in between.

D) Now if I want to replace Turnstile I only need to tell the 
Replacement the system service to start and stop. I think it is 
reasonable to plan that, since Turnstile is based on PAM and as Bercot 
said in https://skarnet.org/lists/supervision/3114.html:

>   I'm not going to write such a program in the s6 suite, because all the
> stuff around PAM and utmp is 1. very Linux-specific and 2. extremely
> brittle and badly/underspecified. At some point, however, I intend to
> take a good look at PAM and brainstorm about a replacement, because the
> current situation is just holding with massive amounts of duct tape,
> good
> will and headaches, and this makes me fearful for the future. 


Thank you for your valuable input!

Have a nice Sunday!


Paul
OpenPGP_0x71C7C85A2EA30F62.asc (application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGW5FlEBEACi9wDm7vnwoxMy6ejpZQh2Z1Mpr4fTKJyWLn3sZFAjmQKcsT/O
Rt0rVSBO5eXoGjbk5Hor2l67mui85a4KWawHbYFC95hpA9K/alfGyQH56SnL5G55
DDcz3avkLrJ9bHJD4y4ScEzweYW2IjYr90FKqZWWcdqzYDqmqRtf5/rdkmY6YVtp
BISIfYNbBRPE3CJuY7HOpQ4sqAmb5iRsXN38hv7UQj9MsJl5Q0cxgcFcRGy9dAM5
voX1Xh+h9svS1MZuaxzyLR0YvCzAcY8c7uUsXjj67/NmeHpl5pYHiT19g/wcHbud
YLI+pikx4EcskinZ1peZbrbBdVdBeOtukBzaMuFedOcSpAWbDDK7e4cwZnPse130
FjNECzIrNAB2lK2rb9f2PCyZSRCW7QBG63IUREWZTLBm47DyavMzh+wGV6Jx6kig
dngJDtIXXDzw2ZWAMMT2MEPX4HC1POH8b1DZ/QxzC+2SQbJNfrQitm0KkOo8o2gq
MpuBABAYzQwRJXNteeW5ZccbgdQ0+m61kV/P71bmeiasvJGyecxzOfRUDei7b3Lh
8O5xPHP1dq23E9R76fCaCCiutfiZT5zT5dbn8XGqBmKI9z8VGEfCBdFbopZd4fpQ
PmVNWlR0yrM7DnHST1OJtGZ2/gwk0Py2dO+lbZDQMqVRVYXT1dYenwYa5QARAQAB
zRxQYXVsIFNvcGthIDxwc29wa2FAc29wa2EuY2g+wsGUBBMBCgA+FiEEklpwGqZx
1YzBW1hqccfIWi6jD2IFAmW5FlECGwMFCQeEzgAFCwkIBwMFFQoJCAsFFgIDAQAC
HgUCF4AACgkQccfIWi6jD2KbNw//QSMh6QRTxCRHVJGp4vHAz6hWt/zimRbVkO0t
4Q/5uXClRnMzZqqE+TLubNRy560Y/LxuQ4phB/O4mcHRqbV9Xrarx98jWNqMgsGh
D60W3uxr6RRObeB0+PpRHVhzzqAMtWh6OZGQ9+vJJf3Q4Axwo/cafNgm2V0MOWsV
FUxUVUbDsR8aZP7RyDRJRv5v6T4pu4Jjd9BH+UxfsG5dvE2Jqj4/a5OIcJ0XlMSk
JxHorDjxLGNFJ8pTcH3/Y7eWmPL0U6kKS99ol763V5LEOnQnqpbwqCalwumgYoXw
HCahiZlmX2Zl4omf9zHvgzADk66rNvZUvBAIMXDWAoWjL9IxxqTIVUjJk0cv3jN8
fZc309s40jDQze3LDSCp9+7SP//jlgADsvfUxJemvoqDYpANrt/wEZ9lxr5doi0R
2CEPbfPkmWyaGUcFBdlVAaYCL5Sg++OfyjCeu4MAC1JZfHOBjQbzwKhG4MqZs8O1
Snr42JvbyzonDckl7UJUZwChUPO4GrFu8zQxqa2ZDx/zok6+bMD0ggDXj6svGUzG
qMxOr4bJa7MxUQ1iIXYl0WTEFbTT9GTi3nxXt0ZPyHN1f9GXgGAB5Qc8hpgm6VFe
wjeohNvaxOpcMCXBYWX9DcuNuKMwofOpGV2hse3bOwy13+ci7sb/A2RBC0wBKV/2
0iuLxFrOwU0EZbkWUQEQAMMWfQpVgrSLCMspW5lkjvl+0Bz1XurJzUF9OcLP2DSR
HEuYNlc+XBvPxh1F3vJfv1Ts79ayDi7YQn+sVTtkGja2RnzXIzrfnodgYe4F71mW
9IjYN6Pl3oUBCBB8vJt1oTwNfRugLGP0ZA5T8ntHP3ryUnBlSr3rTQp8JuOJ/9An
thWDHHoP8qIy9HNDdinDNVpHhGJ4w4CtM2QwFh33ZYXY7qFGOwKdnU1AehJ/Ld5O
/XIVPHmaNGuWgXKVlvrCejifD03cRfbwqQA08VQk6/8rLco25EXpKKfqZpKQHibF
TvNF0bKWs7RhFmHqqzqxAWTsXK/S9yOpbad/HShHBpDiKtyit2zaU+DBg2JsHW1K
tISO6ssYyQ1yN8THF4xbOO1xT/bGsfZKC16bZHG9nemzDgcR05recLvZrti8z+55
GHL19SJzVAKZ4TdX/2MGIfPoywMcrs5OIswzIWILz9KwmhqlFop3MzG0Fmv7dxW9
Zf3MFd0Zw1BwuQxm0D1+gFHViuhRi803Stfb9qP+CwSNwsjAQznMFeFKKO/S6yWp
K0bMxt3Io09+rlW/rwhPwl/j8Xwcynr9PDhyBbjhsM30tNzLvJyy0l8aF+GBGX9J
cqjHU1bxM1RQTDHJI1erJaaySZzKqdjYVI/4buGCsUt2lJds6jyy/GPTZKGV9iAL
ABEBAAHCwXwEGAEKACYWIQSSWnAapnHVjMFbWGpxx8haLqMPYgUCZbkWUQIbDAUJ
B4TOAAAKCRBxx8haLqMPYjOmD/9UjqgchWIApSbllaT+o+rf2ZSDVCCcMnv6sVzs
04dAGtn9EyUueishIsbOOH11eRpwnQOMoK4/7MltnRIf0ksX9uho7pDtpPJfveQI
KZ+sTwpOdiy1yQdlT2j1RDtzph+v96KEqa7B9AI4F/34/0a86OJiLs85ystwMw2m
Txiz6Qi0W+nCSxpJr1s1HVfltzkU8ggXfeas0o955VoSHkgwDTjT+gw75nOX/26k
MjFQ8zImWPIf/jvPhq+9yMBuP0iQS+hs1m8xQ7Gd7tG2I5G6kLGEack3bphGzlsP
atSznHi6rnmzVOQI3/vag7oXvNJI6GAZMIUQ5h+lNbGnOBb/M3inTVgyJruNP7Q1
fPIUHG++/5DXWP1uuKJxYGGI/As2tz2lHbWzP7y6jaJvBBjGqPk8JwBfK98JSH4V
vJStF9Ga+QFCCXb2TUeIIS/mVQ3gAln0g2hsZ0QsMvuohk300noV97YnXEKGUXKw
OnfpHAxCYreqzMHInyDm6YciMR2JADhB5tS7KUWmQP2j0lYrEZZJmZ+bu9Edrv/v
67mNDnzCANN1UhuoKODK2Wijcmbtu/7d78SBzxTEjh3RXMZKLS57N78fNnEGnuF9
IS9vOU43y5QCmGCCZsf/r5d5hx2yxqrNInoPiGuY64XUMJXfFbA36ZPoLsvxoK0+
8QRhtw==
=hu4K
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEklpwGqZx1YzBW1hqccfIWi6jD2IFAmaKWoUFAwAAAAAACgkQccfIWi6jD2KY
6w/+PwLF2yS7FXIlN/tJkVLI8hvuR5+kOkVxJEOo7xhZdSCSdRgjA0JBAxKm5lZ2qHWcBO5ZMzZ+
4r5yJJOfnBodkC/RrnlQsSVK/EHG2UWeegp50CkL/pZ0tgrB54G9xNd9n/k3jD7ojb0R7y+SvYuU
ZkJfEz/CTSH3I+0YmqznbpFBukoRVaptqTd+RJQTIeo4uyYRgTDIZO3lN5exsS3+gD8LHrAH48Ts
Qe83SagNCJwtdwcSYO2BqYhg9Fgnzb3gyZDHxbCXX+oX7IUnB0rQ1pmy4m6enzvPDgG9+nJUWrLs
cmgaLPeGDRZPWsFXOSGzzXxsky3/e/N0tfCE+Y8f3UYELcucgh2J5/G7zpCWz5H3wtm/KpHWQYaw
o3aDkBfFZCrAQ6hDHY116/Zv+QqtskFs/WmpDch6gt6sE7iYcyDqhR2TXnlXROE4R6mrR3c7ste5
wIsvC4+studKJQG6k+rLzIjH0PVXEZyacU+Kdmuv0SAP3yQCZHbnYuKVX9KRCaSoMV8N6+nzFyuO
aKsH7f7PPJkZCjZXb1huE5q/Dym0QEEQY5+9JGeIL/TuxhF7ng+iAkofVwpdwXRk+ftTpBQMdpkA
EirJIpKCZny9FpPHbEV9C8ZBNCanYl3G/nQUsNjboAy1yZWJRdteoEZwfiYDx7+eVAyz6LiVKTEd
kOE=
=Zq4O
-----END PGP SIGNATURE-----