Re: s6/s6-rc policy for Gentoo

Paul Sopka <[email protected]> Mon, 8 Jul 2024 11:03:47 +0200
Newsgroups gmane.comp.sysutils.supervision.general
Message-ID <[email protected]>
> Replacing crond with snooze, for example.
> And personally, I want my ssh-agent to stay alive when I log out, so
> that the key is still unlocked if/when I immediately log in again.

You have convinced me, I will see whether it is feasible to have a 
*third* user-service tree. I fear I just have to bite the bullet and 
decide upon one or two options or at least let the sysadmin decide. Yet 
another reason to not integrate extremely tight into Turnstile and 
similar, which would disallow this flexibility.

An alternative would be two main bundles per user service tree, that 
itself always starts on boot:

One to start at boot time.

Another one to start on first login and stop on last login.

This seems the most elegant and efficient. Am I overlooking anything?


> This sounds unnecessarily complicated. Why not simply test for existence
> of a well-known entry point somewhere in $HOME and let that set up the
> user supervision tree however it sees fit (or not at all)?

If I understand correctly, this would only be possible using 
instantiated services, I like the idea and I am looking into this.


> Ugh. I hate this thinking. Server/Desktop is not a binary choice. I
> regularly ssh into otheruser@localhost on my main machine. Sometimes I
> log in as otheruser and startx. Occasionally I start a vnc server as
> otheruser. I have an mpd instance that runs as its own user.
>
> Any desktop-only solution where people argue "you shouldn't do this on a
> server" is one where I'll argue "you shouldn't do this at all".

It looks like I just do not have enough experience, that's why I am 
asking you all on those points. You are right.

Using the idea I stated above, one could use different PAM modules to 
start different bundles tho, e.g. an ssh bundle on ssh login, a getty 
bundle on getty login, a greetd bundle on greetd login.


> * create a unique live dir from the "graphical" template
> * start compositor
> ** in compositor's autostart, have something that exports the
>     WAYLAND_DISPLAY and calls s6-rc start
> ** (if possible) register s6-rc stop as an exit hook with compositor
> * once the compositor exits, tear down everything.

Yes, I have suggested this too, the issues is not the starting part, but 
the proper stopping of the services. This can only be guaranteed if the 
compositor sends SIGTERM to s6-svscan upon exiting. I still need to test 
that, but to not have to rely on the compositor doing that correctly is 
why I have proposed hooking into seatd in the first place.

The finish script of the s6-svscan should then handle cleanup just fine.

> Or just use X11, which properly separates Xserver from WM, avoiding any
> problems caused by uncooperative compositors. <scnr>

I am planning to support an entire distro, thus I need to support them 
all: well behaved compositors, badly behaved compositors, X11, ...


> If it needs a display, it goes into C, otherwise into B.
I guess writing this into a wiki article mandatory for user services 
anyway would be good enough.


> Feasible, sure. Good idea, probably not. A misconfigured compositor
> restarting over and over again is a pain to fix.
Agreed.


> PAM. Assuming you use PAM to create the XDG_RUNTIME_DIR and start the
> dbus.
Using PAM for propagating the env's seems reasonable, since we are using 
it already anyway. Will test.

On a sidenote, I still think creating XDG_RUNTIME_DIR should be the job 
of the system-service managing the user tree.


Thank you for your input!


Paul
OpenPGP_0x71C7C85A2EA30F62.asc (application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGW5FlEBEACi9wDm7vnwoxMy6ejpZQh2Z1Mpr4fTKJyWLn3sZFAjmQKcsT/O
Rt0rVSBO5eXoGjbk5Hor2l67mui85a4KWawHbYFC95hpA9K/alfGyQH56SnL5G55
DDcz3avkLrJ9bHJD4y4ScEzweYW2IjYr90FKqZWWcdqzYDqmqRtf5/rdkmY6YVtp
BISIfYNbBRPE3CJuY7HOpQ4sqAmb5iRsXN38hv7UQj9MsJl5Q0cxgcFcRGy9dAM5
voX1Xh+h9svS1MZuaxzyLR0YvCzAcY8c7uUsXjj67/NmeHpl5pYHiT19g/wcHbud
YLI+pikx4EcskinZ1peZbrbBdVdBeOtukBzaMuFedOcSpAWbDDK7e4cwZnPse130
FjNECzIrNAB2lK2rb9f2PCyZSRCW7QBG63IUREWZTLBm47DyavMzh+wGV6Jx6kig
dngJDtIXXDzw2ZWAMMT2MEPX4HC1POH8b1DZ/QxzC+2SQbJNfrQitm0KkOo8o2gq
MpuBABAYzQwRJXNteeW5ZccbgdQ0+m61kV/P71bmeiasvJGyecxzOfRUDei7b3Lh
8O5xPHP1dq23E9R76fCaCCiutfiZT5zT5dbn8XGqBmKI9z8VGEfCBdFbopZd4fpQ
PmVNWlR0yrM7DnHST1OJtGZ2/gwk0Py2dO+lbZDQMqVRVYXT1dYenwYa5QARAQAB
zRxQYXVsIFNvcGthIDxwc29wa2FAc29wa2EuY2g+wsGUBBMBCgA+FiEEklpwGqZx
1YzBW1hqccfIWi6jD2IFAmW5FlECGwMFCQeEzgAFCwkIBwMFFQoJCAsFFgIDAQAC
HgUCF4AACgkQccfIWi6jD2KbNw//QSMh6QRTxCRHVJGp4vHAz6hWt/zimRbVkO0t
4Q/5uXClRnMzZqqE+TLubNRy560Y/LxuQ4phB/O4mcHRqbV9Xrarx98jWNqMgsGh
D60W3uxr6RRObeB0+PpRHVhzzqAMtWh6OZGQ9+vJJf3Q4Axwo/cafNgm2V0MOWsV
FUxUVUbDsR8aZP7RyDRJRv5v6T4pu4Jjd9BH+UxfsG5dvE2Jqj4/a5OIcJ0XlMSk
JxHorDjxLGNFJ8pTcH3/Y7eWmPL0U6kKS99ol763V5LEOnQnqpbwqCalwumgYoXw
HCahiZlmX2Zl4omf9zHvgzADk66rNvZUvBAIMXDWAoWjL9IxxqTIVUjJk0cv3jN8
fZc309s40jDQze3LDSCp9+7SP//jlgADsvfUxJemvoqDYpANrt/wEZ9lxr5doi0R
2CEPbfPkmWyaGUcFBdlVAaYCL5Sg++OfyjCeu4MAC1JZfHOBjQbzwKhG4MqZs8O1
Snr42JvbyzonDckl7UJUZwChUPO4GrFu8zQxqa2ZDx/zok6+bMD0ggDXj6svGUzG
qMxOr4bJa7MxUQ1iIXYl0WTEFbTT9GTi3nxXt0ZPyHN1f9GXgGAB5Qc8hpgm6VFe
wjeohNvaxOpcMCXBYWX9DcuNuKMwofOpGV2hse3bOwy13+ci7sb/A2RBC0wBKV/2
0iuLxFrOwU0EZbkWUQEQAMMWfQpVgrSLCMspW5lkjvl+0Bz1XurJzUF9OcLP2DSR
HEuYNlc+XBvPxh1F3vJfv1Ts79ayDi7YQn+sVTtkGja2RnzXIzrfnodgYe4F71mW
9IjYN6Pl3oUBCBB8vJt1oTwNfRugLGP0ZA5T8ntHP3ryUnBlSr3rTQp8JuOJ/9An
thWDHHoP8qIy9HNDdinDNVpHhGJ4w4CtM2QwFh33ZYXY7qFGOwKdnU1AehJ/Ld5O
/XIVPHmaNGuWgXKVlvrCejifD03cRfbwqQA08VQk6/8rLco25EXpKKfqZpKQHibF
TvNF0bKWs7RhFmHqqzqxAWTsXK/S9yOpbad/HShHBpDiKtyit2zaU+DBg2JsHW1K
tISO6ssYyQ1yN8THF4xbOO1xT/bGsfZKC16bZHG9nemzDgcR05recLvZrti8z+55
GHL19SJzVAKZ4TdX/2MGIfPoywMcrs5OIswzIWILz9KwmhqlFop3MzG0Fmv7dxW9
Zf3MFd0Zw1BwuQxm0D1+gFHViuhRi803Stfb9qP+CwSNwsjAQznMFeFKKO/S6yWp
K0bMxt3Io09+rlW/rwhPwl/j8Xwcynr9PDhyBbjhsM30tNzLvJyy0l8aF+GBGX9J
cqjHU1bxM1RQTDHJI1erJaaySZzKqdjYVI/4buGCsUt2lJds6jyy/GPTZKGV9iAL
ABEBAAHCwXwEGAEKACYWIQSSWnAapnHVjMFbWGpxx8haLqMPYgUCZbkWUQIbDAUJ
B4TOAAAKCRBxx8haLqMPYjOmD/9UjqgchWIApSbllaT+o+rf2ZSDVCCcMnv6sVzs
04dAGtn9EyUueishIsbOOH11eRpwnQOMoK4/7MltnRIf0ksX9uho7pDtpPJfveQI
KZ+sTwpOdiy1yQdlT2j1RDtzph+v96KEqa7B9AI4F/34/0a86OJiLs85ystwMw2m
Txiz6Qi0W+nCSxpJr1s1HVfltzkU8ggXfeas0o955VoSHkgwDTjT+gw75nOX/26k
MjFQ8zImWPIf/jvPhq+9yMBuP0iQS+hs1m8xQ7Gd7tG2I5G6kLGEack3bphGzlsP
atSznHi6rnmzVOQI3/vag7oXvNJI6GAZMIUQ5h+lNbGnOBb/M3inTVgyJruNP7Q1
fPIUHG++/5DXWP1uuKJxYGGI/As2tz2lHbWzP7y6jaJvBBjGqPk8JwBfK98JSH4V
vJStF9Ga+QFCCXb2TUeIIS/mVQ3gAln0g2hsZ0QsMvuohk300noV97YnXEKGUXKw
OnfpHAxCYreqzMHInyDm6YciMR2JADhB5tS7KUWmQP2j0lYrEZZJmZ+bu9Edrv/v
67mNDnzCANN1UhuoKODK2Wijcmbtu/7d78SBzxTEjh3RXMZKLS57N78fNnEGnuF9
IS9vOU43y5QCmGCCZsf/r5d5hx2yxqrNInoPiGuY64XUMJXfFbA36ZPoLsvxoK0+
8QRhtw==
=hu4K
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEklpwGqZx1YzBW1hqccfIWi6jD2IFAmaLq3MFAwAAAAAACgkQccfIWi6jD2JV
0RAAkbzTDtw8W+9u/vaKgRFux3SzX+zJ5US8jfKhEnL783IKVRkjwqwb3QoSq5bb9ZCu4ko5K8OM
0fD73zLN52Kx+bc/hyLPwNsAgBhekZgrEZEy5BdLWtH8xLdyAhNEO8CR2O7x+PaeWlpW4LPe5ci2
N2u0TRPd7nKXatvtE19xyTa++18GwjZ5QvHz530IQ1WdZwUAFWVNDshm3TV90zBym6or7f3SoULb
yBhTkgipTzaP2k4o62vP3evaDJC7bsqcIoOaBNowzVu6bdZbWMN4yXRqoWvAHPsgsDqxQqw1c0CQ
Eli2sJyWd9N8uewB5dxgT3LZTBKlB9+CHyM3Ow1fRASDQgivOAjpbh1P9aES5fFK1JNdz/g4WOIj
34C7/67+c3BsZcvdcAj8FnIp0TvPdwtR7UiUKGz9H5Qq+JgOskuJr0Kt5IQDaEPzwOcnEO29w88D
lUQpuhYCuYDGyNDbH0HVikPt56Wo73ZTgyMsyLxrBgbG/gT/OGZWWGAE8FEnfhodq9SJHajROmFD
DkuK/UkqdZKRdB+zpuCo0r6skcsOGbOOkOv9NWl0nE4Y/hZ6sfrtFMpCXM34P8+45kMTBP46gbHw
Z6FCFNsEr4F7iLFHU6BdT6ouVHHnFpChJBmxotOHAGLdMLcMl1yxP5nzcXqEtvGA5bnZg6pessaQ
rB0=
=iQx6
-----END PGP SIGNATURE-----