Re: Have an external script wait for a oneshot service
Paul Sopka <[email protected]> Thu, 5 Dec 2024 14:52:42 +0100
| Newsgroups | gmane.comp.sysutils.supervision.general |
|---|---|
| Message-ID | <[email protected]> |
On 05.12.24 09:05, Laurent Bercot wrote:
>
>> To be more precise, I have the following setup:
>> - A longrun L setting up s6-svscan for a user-service-tree.
>>
>> - A oneshot O setting up "s6-rc-init" and "s6-rc start default".
>>
>> (two allow users to have services running on boot without login)
>>
>> - A script run on login (bee it by PAM, .profile or another way),
>> that starts user services only useful after login, e.g. pipewire.
>>
>> Now of course the script should only be ran after the the
>> "s6-rc-init" oneshot.
>
> I get the feeling there's an XY problem here, or some confusion (but
> maybe just in my own brain) because user services are an underspecified
> concept. Can you please describe the details of your setup: at what
> time do you want to start up a supervision tree and an s6-rc-init
> process for a given user?
> - at boot time? if so, how do you decide what users to start a
> tree for?
> - at login time? if so, you have a script that you run at login time,
> I don't see the problem here: start the tree and the s6-rc-init in that
> script, not as a part of a set of s6-rc services.
>
> --
> Laurent
>
After the discussions about user services conducted here a couple of
months ago,
I came to the conclusion that the following would be the best solution:
- All user-trees are started at boot time.
- The user-trees are be prepared in two ways:
1 One system-longrun service per user:
- 1a Have the admin create one system-longrun running
"s6-svscan" per user (e.g. automated via a script).
- 1b Have the admin create one system-oneshot per user to:
- 1bi Prepare the live directory for the user-tree
(preferably under /run/user/${USER}).
- 1bii Start "s6-rc-init" and "s6-rc start default".
2 One instantiated system-longrun for all users:
- 2a Have a system-longrun which is an instantiated "s6-svscan",
with one instance per user
and a (root controlled) config C specifying which users
to instantiate for.
- 2b This config C shall then be parsed by an additional
system-oneshot to do the actual instantiation.
- 2c A third system-oneshot does:
- 2ci Prepare the live directory for the user-tree for each
user specified in config C (preferably under /run/user/${USER}).
- 2cii Run "s6-rc-init" and "s6-rc start default" for each
user specified in config C.
(this can be merged with the instantiation system-oneshot if
desired.)
- Upon login, a login script L shall invoke an "s6-rc start login" with
("login" being a bundle) for the user logging in.
(this can be further extended using PAM to run "s6-rc start
${PAM_TYPE}" to differentiate different types of logins)
The script L can be started by PAM, .profile or in some other way.
- Upon last logout, meaning the logout that causes no logged in sessions
for the user to be left,
the script invokes "s6-rc -pu change default" to stop all the login
services.
This has the following advantages:
- A user can have always running user services (e.g. snooze based timed
services, calculations, ...)
no matter whether the user is logged in.
- Services only required during login (e.g. pipewire, mpd, ...) only run
when the user is logged in.
- Who gets to have a user-tree is decided by root creating the
user-services as in 1 or instantiation config C as in 2,
which feels natural, since root also decides who gets a user account
in the first place.
And the following implications:
- The login script needs to wait for "s6-lrc-init" to be finished before
it can call "s6-rc start login".
It hence needs to wait for the corresponding system-oneshot 1b/2c.
Which (as far as I have found) can be solved in one of the following ways:
- S1 Script s6-fifodir functionality in bot the system-oneshot 1b/2c
and the script L.
- S2 Add a readiness api for s6-rc oneshots like s6 longruns have and
wait for that of system-oneshot 1b/2c in the script.
- S3 Have the script L do the same as system-oneshot 1b/2c:
- 1bi/2ci Prepare the live directory for the user-tree
(preferably under /run/user/${USER}).
- 1bii/2cii Start "s6-rc-init -b" and "s6-rc start login".
Utilizing blocking locks and tests to work parallel to system-oneshot
1b/2c.
This can only be done if the script is ran through PAM, since 1bi/2ci
requires root privileges.
Since I find solution S2 to be the most elegant,
I wanted to ask whether you are willing to add a proper readiness api to
oneshots too.
This would generally be a nice addition, as I am sure there are other
applications to this feature
I can currently not imagine.
Further, I argue that it would make the system more consistent, since
longruns have this functionality too.
Regards
Paul
OpenPGP_0x71C7C85A2EA30F62.asc
(application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK----- xsFNBGW5FlEBEACi9wDm7vnwoxMy6ejpZQh2Z1Mpr4fTKJyWLn3sZFAjmQKcsT/O Rt0rVSBO5eXoGjbk5Hor2l67mui85a4KWawHbYFC95hpA9K/alfGyQH56SnL5G55 DDcz3avkLrJ9bHJD4y4ScEzweYW2IjYr90FKqZWWcdqzYDqmqRtf5/rdkmY6YVtp BISIfYNbBRPE3CJuY7HOpQ4sqAmb5iRsXN38hv7UQj9MsJl5Q0cxgcFcRGy9dAM5 voX1Xh+h9svS1MZuaxzyLR0YvCzAcY8c7uUsXjj67/NmeHpl5pYHiT19g/wcHbud YLI+pikx4EcskinZ1peZbrbBdVdBeOtukBzaMuFedOcSpAWbDDK7e4cwZnPse130 FjNECzIrNAB2lK2rb9f2PCyZSRCW7QBG63IUREWZTLBm47DyavMzh+wGV6Jx6kig dngJDtIXXDzw2ZWAMMT2MEPX4HC1POH8b1DZ/QxzC+2SQbJNfrQitm0KkOo8o2gq MpuBABAYzQwRJXNteeW5ZccbgdQ0+m61kV/P71bmeiasvJGyecxzOfRUDei7b3Lh 8O5xPHP1dq23E9R76fCaCCiutfiZT5zT5dbn8XGqBmKI9z8VGEfCBdFbopZd4fpQ PmVNWlR0yrM7DnHST1OJtGZ2/gwk0Py2dO+lbZDQMqVRVYXT1dYenwYa5QARAQAB zRxQYXVsIFNvcGthIDxwc29wa2FAc29wa2EuY2g+wsGUBBMBCgA+FiEEklpwGqZx 1YzBW1hqccfIWi6jD2IFAmW5FlECGwMFCQeEzgAFCwkIBwMFFQoJCAsFFgIDAQAC HgUCF4AACgkQccfIWi6jD2KbNw//QSMh6QRTxCRHVJGp4vHAz6hWt/zimRbVkO0t 4Q/5uXClRnMzZqqE+TLubNRy560Y/LxuQ4phB/O4mcHRqbV9Xrarx98jWNqMgsGh D60W3uxr6RRObeB0+PpRHVhzzqAMtWh6OZGQ9+vJJf3Q4Axwo/cafNgm2V0MOWsV FUxUVUbDsR8aZP7RyDRJRv5v6T4pu4Jjd9BH+UxfsG5dvE2Jqj4/a5OIcJ0XlMSk JxHorDjxLGNFJ8pTcH3/Y7eWmPL0U6kKS99ol763V5LEOnQnqpbwqCalwumgYoXw HCahiZlmX2Zl4omf9zHvgzADk66rNvZUvBAIMXDWAoWjL9IxxqTIVUjJk0cv3jN8 fZc309s40jDQze3LDSCp9+7SP//jlgADsvfUxJemvoqDYpANrt/wEZ9lxr5doi0R 2CEPbfPkmWyaGUcFBdlVAaYCL5Sg++OfyjCeu4MAC1JZfHOBjQbzwKhG4MqZs8O1 Snr42JvbyzonDckl7UJUZwChUPO4GrFu8zQxqa2ZDx/zok6+bMD0ggDXj6svGUzG qMxOr4bJa7MxUQ1iIXYl0WTEFbTT9GTi3nxXt0ZPyHN1f9GXgGAB5Qc8hpgm6VFe wjeohNvaxOpcMCXBYWX9DcuNuKMwofOpGV2hse3bOwy13+ci7sb/A2RBC0wBKV/2 0iuLxFrOwU0EZbkWUQEQAMMWfQpVgrSLCMspW5lkjvl+0Bz1XurJzUF9OcLP2DSR HEuYNlc+XBvPxh1F3vJfv1Ts79ayDi7YQn+sVTtkGja2RnzXIzrfnodgYe4F71mW 9IjYN6Pl3oUBCBB8vJt1oTwNfRugLGP0ZA5T8ntHP3ryUnBlSr3rTQp8JuOJ/9An thWDHHoP8qIy9HNDdinDNVpHhGJ4w4CtM2QwFh33ZYXY7qFGOwKdnU1AehJ/Ld5O /XIVPHmaNGuWgXKVlvrCejifD03cRfbwqQA08VQk6/8rLco25EXpKKfqZpKQHibF TvNF0bKWs7RhFmHqqzqxAWTsXK/S9yOpbad/HShHBpDiKtyit2zaU+DBg2JsHW1K tISO6ssYyQ1yN8THF4xbOO1xT/bGsfZKC16bZHG9nemzDgcR05recLvZrti8z+55 GHL19SJzVAKZ4TdX/2MGIfPoywMcrs5OIswzIWILz9KwmhqlFop3MzG0Fmv7dxW9 Zf3MFd0Zw1BwuQxm0D1+gFHViuhRi803Stfb9qP+CwSNwsjAQznMFeFKKO/S6yWp K0bMxt3Io09+rlW/rwhPwl/j8Xwcynr9PDhyBbjhsM30tNzLvJyy0l8aF+GBGX9J cqjHU1bxM1RQTDHJI1erJaaySZzKqdjYVI/4buGCsUt2lJds6jyy/GPTZKGV9iAL ABEBAAHCwXwEGAEKACYWIQSSWnAapnHVjMFbWGpxx8haLqMPYgUCZbkWUQIbDAUJ B4TOAAAKCRBxx8haLqMPYjOmD/9UjqgchWIApSbllaT+o+rf2ZSDVCCcMnv6sVzs 04dAGtn9EyUueishIsbOOH11eRpwnQOMoK4/7MltnRIf0ksX9uho7pDtpPJfveQI KZ+sTwpOdiy1yQdlT2j1RDtzph+v96KEqa7B9AI4F/34/0a86OJiLs85ystwMw2m Txiz6Qi0W+nCSxpJr1s1HVfltzkU8ggXfeas0o955VoSHkgwDTjT+gw75nOX/26k MjFQ8zImWPIf/jvPhq+9yMBuP0iQS+hs1m8xQ7Gd7tG2I5G6kLGEack3bphGzlsP atSznHi6rnmzVOQI3/vag7oXvNJI6GAZMIUQ5h+lNbGnOBb/M3inTVgyJruNP7Q1 fPIUHG++/5DXWP1uuKJxYGGI/As2tz2lHbWzP7y6jaJvBBjGqPk8JwBfK98JSH4V vJStF9Ga+QFCCXb2TUeIIS/mVQ3gAln0g2hsZ0QsMvuohk300noV97YnXEKGUXKw OnfpHAxCYreqzMHInyDm6YciMR2JADhB5tS7KUWmQP2j0lYrEZZJmZ+bu9Edrv/v 67mNDnzCANN1UhuoKODK2Wijcmbtu/7d78SBzxTEjh3RXMZKLS57N78fNnEGnuF9 IS9vOU43y5QCmGCCZsf/r5d5hx2yxqrNInoPiGuY64XUMJXfFbA36ZPoLsvxoK0+ 8QRhtw== =hu4K -----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc
(application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEklpwGqZx1YzBW1hqccfIWi6jD2IFAmdRsCoFAwAAAAAACgkQccfIWi6jD2Jg mg//TdnkodGoxKlGEq4HQpU+CYiJs+/wlCqVinkaj9tkl9fR7Fta0vgWZYQNH2A+RnjSfM+YcK6H n2xQT2zgfUMpQjkAsax1VM1UCh8nEum1QZ6M9OWLRCaDaZLdxD0g+wqLjt2OKwur/ZzdDoFjZo7p XL7cdr6/yDNLXxYvIdq0/ww0Y8EIYbDS7HBhelz2jFo/PlC379XSQwYhCaXH3TYDfKR9o8tYYkrj lWJDvy9rC+h8LLeQA9u7Nx0GnB0/L+MaZYyCkAWuIOsc2HXyCXTB0rR/iUraGWILqipABEZczxeP /ha3EabwmdDwL2REgr48TlPtUH64Y4rjB77Ww+U3mC2GghMZw2zy68BKtYPaO9N5wL4XlFnAP7ZC WIU+LraazCGndnfiHJi1vm0bXj4M0wRk811Cy4ARlfBbHLT6O/z48xhTMMjNUV6O3yjzkQgJ0UO7 NEV7c0eMQLli1t3PUX4EcRsQtu9sHQ2q3MRxIyKcEVKhAQHAg1cVmrZGWZV21fMwBtaVn5fjEV8n f548in3ZOJ46hWHC8vSIzcFipaXK91divvjwCowtiEZhkOtjo8FjwOrrUju3PwdxxRejUOV83E0t 7Ay1YCKae0oD7yPZbVTVdzUPGeG+oKoaH51Gq/c3e1NQDlucXMFnru27FjK3IEA51Ych9ccVBiel MyA= =nkN3 -----END PGP SIGNATURE-----