Re: Have an external script wait for a oneshot service

Paul Sopka <[email protected]> Thu, 5 Dec 2024 14:52:42 +0100
Newsgroups gmane.comp.sysutils.supervision.general
Message-ID <[email protected]>
On 05.12.24 09:05, Laurent Bercot wrote:
>
>> To be more precise, I have the following setup:
>> - A longrun L setting up s6-svscan for a user-service-tree.
>>
>> - A oneshot O setting up "s6-rc-init" and "s6-rc start default".
>>
>> (two allow users to have services running on boot without login)
>>
>> - A script run on login (bee it by PAM, .profile or another way),
>>   that starts user services only useful after login, e.g. pipewire.
>>
>> Now of course the script should only be ran after the the 
>> "s6-rc-init" oneshot.
>
>  I get the feeling there's an XY problem here, or some confusion (but
> maybe just in my own brain) because user services are an underspecified
> concept. Can you please describe the details of your setup: at what
> time do you want to start up a supervision tree and an s6-rc-init
> process for a given user?
>  - at boot time? if so, how do you decide what users to start a
> tree for?
>  - at login time? if so, you have a script that you run at login time,
> I don't see the problem here: start the tree and the s6-rc-init in that
> script, not as a part of a set of s6-rc services.
>
> -- 
>  Laurent
>
After the discussions about user services conducted here a couple of 
months ago,
I came to the conclusion that the following would be the best solution:

- All user-trees are started at boot time.

- The user-trees are be prepared in two ways:

     1    One system-longrun service per user:
     - 1a     Have the admin create one system-longrun running 
"s6-svscan" per user (e.g. automated via a script).
     - 1b     Have the admin create one system-oneshot per user to:
         - 1bi     Prepare the live directory for the user-tree 
(preferably under /run/user/${USER}).
         - 1bii     Start "s6-rc-init" and "s6-rc start default".

     2    One instantiated system-longrun for all users:
     - 2a    Have a system-longrun which is an instantiated "s6-svscan", 
with one instance per user
               and a (root controlled) config C specifying which users 
to instantiate for.
     - 2b    This config C shall then be parsed by an additional 
system-oneshot to do the actual instantiation.
     - 2c    A third system-oneshot does:
         - 2ci    Prepare the live directory for the user-tree for each 
user specified in config C (preferably under /run/user/${USER}).
         - 2cii    Run "s6-rc-init" and "s6-rc start default" for each 
user specified in config C.
       (this can be merged with the instantiation system-oneshot if 
desired.)

- Upon login, a login script L shall invoke an "s6-rc start login" with 
("login" being a bundle) for the user logging in.
   (this can be further extended using PAM to run "s6-rc start 
${PAM_TYPE}" to differentiate different types of logins)
   The script L can be started by PAM, .profile or in some other way.

- Upon last logout, meaning the logout that causes no logged in sessions 
for the user to be left,
   the script invokes "s6-rc -pu change default" to stop all the login 
services.

This has the following advantages:

- A user can have always running user services (e.g. snooze based timed 
services, calculations, ...)
   no matter whether the user is logged in.

- Services only required during login (e.g. pipewire, mpd, ...) only run 
when the user is logged in.

- Who gets to have a user-tree is decided by root creating the 
user-services as in 1 or instantiation config C as in 2,
   which feels natural, since root also decides who gets a user account 
in the first place.

And the following implications:

- The login script needs to wait for "s6-lrc-init" to be finished before 
it can call "s6-rc start login".
   It hence needs to wait for the corresponding system-oneshot 1b/2c.

Which (as far as I have found) can be solved in one of the following ways:

- S1    Script s6-fifodir functionality in bot the system-oneshot 1b/2c 
and the script L.

- S2    Add a readiness api for s6-rc oneshots like s6 longruns have and 
wait for that of system-oneshot 1b/2c in the script.

- S3    Have the script L do the same as system-oneshot 1b/2c:
         - 1bi/2ci    Prepare the live directory for the user-tree 
(preferably under /run/user/${USER}).
         - 1bii/2cii    Start "s6-rc-init -b" and "s6-rc start login".
   Utilizing blocking locks and tests to work parallel to system-oneshot 
1b/2c.
   This can only be done if the script is ran through PAM, since 1bi/2ci 
requires root privileges.

Since I find solution S2 to be the most elegant,
I wanted to ask whether you are willing to add a proper readiness api to 
oneshots too.
This would generally be a nice addition, as I am sure there are other 
applications to this feature
I can currently not imagine.
Further, I argue that it would make the system more consistent, since 
longruns have this functionality too.

Regards

Paul
OpenPGP_0x71C7C85A2EA30F62.asc (application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGW5FlEBEACi9wDm7vnwoxMy6ejpZQh2Z1Mpr4fTKJyWLn3sZFAjmQKcsT/O
Rt0rVSBO5eXoGjbk5Hor2l67mui85a4KWawHbYFC95hpA9K/alfGyQH56SnL5G55
DDcz3avkLrJ9bHJD4y4ScEzweYW2IjYr90FKqZWWcdqzYDqmqRtf5/rdkmY6YVtp
BISIfYNbBRPE3CJuY7HOpQ4sqAmb5iRsXN38hv7UQj9MsJl5Q0cxgcFcRGy9dAM5
voX1Xh+h9svS1MZuaxzyLR0YvCzAcY8c7uUsXjj67/NmeHpl5pYHiT19g/wcHbud
YLI+pikx4EcskinZ1peZbrbBdVdBeOtukBzaMuFedOcSpAWbDDK7e4cwZnPse130
FjNECzIrNAB2lK2rb9f2PCyZSRCW7QBG63IUREWZTLBm47DyavMzh+wGV6Jx6kig
dngJDtIXXDzw2ZWAMMT2MEPX4HC1POH8b1DZ/QxzC+2SQbJNfrQitm0KkOo8o2gq
MpuBABAYzQwRJXNteeW5ZccbgdQ0+m61kV/P71bmeiasvJGyecxzOfRUDei7b3Lh
8O5xPHP1dq23E9R76fCaCCiutfiZT5zT5dbn8XGqBmKI9z8VGEfCBdFbopZd4fpQ
PmVNWlR0yrM7DnHST1OJtGZ2/gwk0Py2dO+lbZDQMqVRVYXT1dYenwYa5QARAQAB
zRxQYXVsIFNvcGthIDxwc29wa2FAc29wa2EuY2g+wsGUBBMBCgA+FiEEklpwGqZx
1YzBW1hqccfIWi6jD2IFAmW5FlECGwMFCQeEzgAFCwkIBwMFFQoJCAsFFgIDAQAC
HgUCF4AACgkQccfIWi6jD2KbNw//QSMh6QRTxCRHVJGp4vHAz6hWt/zimRbVkO0t
4Q/5uXClRnMzZqqE+TLubNRy560Y/LxuQ4phB/O4mcHRqbV9Xrarx98jWNqMgsGh
D60W3uxr6RRObeB0+PpRHVhzzqAMtWh6OZGQ9+vJJf3Q4Axwo/cafNgm2V0MOWsV
FUxUVUbDsR8aZP7RyDRJRv5v6T4pu4Jjd9BH+UxfsG5dvE2Jqj4/a5OIcJ0XlMSk
JxHorDjxLGNFJ8pTcH3/Y7eWmPL0U6kKS99ol763V5LEOnQnqpbwqCalwumgYoXw
HCahiZlmX2Zl4omf9zHvgzADk66rNvZUvBAIMXDWAoWjL9IxxqTIVUjJk0cv3jN8
fZc309s40jDQze3LDSCp9+7SP//jlgADsvfUxJemvoqDYpANrt/wEZ9lxr5doi0R
2CEPbfPkmWyaGUcFBdlVAaYCL5Sg++OfyjCeu4MAC1JZfHOBjQbzwKhG4MqZs8O1
Snr42JvbyzonDckl7UJUZwChUPO4GrFu8zQxqa2ZDx/zok6+bMD0ggDXj6svGUzG
qMxOr4bJa7MxUQ1iIXYl0WTEFbTT9GTi3nxXt0ZPyHN1f9GXgGAB5Qc8hpgm6VFe
wjeohNvaxOpcMCXBYWX9DcuNuKMwofOpGV2hse3bOwy13+ci7sb/A2RBC0wBKV/2
0iuLxFrOwU0EZbkWUQEQAMMWfQpVgrSLCMspW5lkjvl+0Bz1XurJzUF9OcLP2DSR
HEuYNlc+XBvPxh1F3vJfv1Ts79ayDi7YQn+sVTtkGja2RnzXIzrfnodgYe4F71mW
9IjYN6Pl3oUBCBB8vJt1oTwNfRugLGP0ZA5T8ntHP3ryUnBlSr3rTQp8JuOJ/9An
thWDHHoP8qIy9HNDdinDNVpHhGJ4w4CtM2QwFh33ZYXY7qFGOwKdnU1AehJ/Ld5O
/XIVPHmaNGuWgXKVlvrCejifD03cRfbwqQA08VQk6/8rLco25EXpKKfqZpKQHibF
TvNF0bKWs7RhFmHqqzqxAWTsXK/S9yOpbad/HShHBpDiKtyit2zaU+DBg2JsHW1K
tISO6ssYyQ1yN8THF4xbOO1xT/bGsfZKC16bZHG9nemzDgcR05recLvZrti8z+55
GHL19SJzVAKZ4TdX/2MGIfPoywMcrs5OIswzIWILz9KwmhqlFop3MzG0Fmv7dxW9
Zf3MFd0Zw1BwuQxm0D1+gFHViuhRi803Stfb9qP+CwSNwsjAQznMFeFKKO/S6yWp
K0bMxt3Io09+rlW/rwhPwl/j8Xwcynr9PDhyBbjhsM30tNzLvJyy0l8aF+GBGX9J
cqjHU1bxM1RQTDHJI1erJaaySZzKqdjYVI/4buGCsUt2lJds6jyy/GPTZKGV9iAL
ABEBAAHCwXwEGAEKACYWIQSSWnAapnHVjMFbWGpxx8haLqMPYgUCZbkWUQIbDAUJ
B4TOAAAKCRBxx8haLqMPYjOmD/9UjqgchWIApSbllaT+o+rf2ZSDVCCcMnv6sVzs
04dAGtn9EyUueishIsbOOH11eRpwnQOMoK4/7MltnRIf0ksX9uho7pDtpPJfveQI
KZ+sTwpOdiy1yQdlT2j1RDtzph+v96KEqa7B9AI4F/34/0a86OJiLs85ystwMw2m
Txiz6Qi0W+nCSxpJr1s1HVfltzkU8ggXfeas0o955VoSHkgwDTjT+gw75nOX/26k
MjFQ8zImWPIf/jvPhq+9yMBuP0iQS+hs1m8xQ7Gd7tG2I5G6kLGEack3bphGzlsP
atSznHi6rnmzVOQI3/vag7oXvNJI6GAZMIUQ5h+lNbGnOBb/M3inTVgyJruNP7Q1
fPIUHG++/5DXWP1uuKJxYGGI/As2tz2lHbWzP7y6jaJvBBjGqPk8JwBfK98JSH4V
vJStF9Ga+QFCCXb2TUeIIS/mVQ3gAln0g2hsZ0QsMvuohk300noV97YnXEKGUXKw
OnfpHAxCYreqzMHInyDm6YciMR2JADhB5tS7KUWmQP2j0lYrEZZJmZ+bu9Edrv/v
67mNDnzCANN1UhuoKODK2Wijcmbtu/7d78SBzxTEjh3RXMZKLS57N78fNnEGnuF9
IS9vOU43y5QCmGCCZsf/r5d5hx2yxqrNInoPiGuY64XUMJXfFbA36ZPoLsvxoK0+
8QRhtw==
=hu4K
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEklpwGqZx1YzBW1hqccfIWi6jD2IFAmdRsCoFAwAAAAAACgkQccfIWi6jD2Jg
mg//TdnkodGoxKlGEq4HQpU+CYiJs+/wlCqVinkaj9tkl9fR7Fta0vgWZYQNH2A+RnjSfM+YcK6H
n2xQT2zgfUMpQjkAsax1VM1UCh8nEum1QZ6M9OWLRCaDaZLdxD0g+wqLjt2OKwur/ZzdDoFjZo7p
XL7cdr6/yDNLXxYvIdq0/ww0Y8EIYbDS7HBhelz2jFo/PlC379XSQwYhCaXH3TYDfKR9o8tYYkrj
lWJDvy9rC+h8LLeQA9u7Nx0GnB0/L+MaZYyCkAWuIOsc2HXyCXTB0rR/iUraGWILqipABEZczxeP
/ha3EabwmdDwL2REgr48TlPtUH64Y4rjB77Ww+U3mC2GghMZw2zy68BKtYPaO9N5wL4XlFnAP7ZC
WIU+LraazCGndnfiHJi1vm0bXj4M0wRk811Cy4ARlfBbHLT6O/z48xhTMMjNUV6O3yjzkQgJ0UO7
NEV7c0eMQLli1t3PUX4EcRsQtu9sHQ2q3MRxIyKcEVKhAQHAg1cVmrZGWZV21fMwBtaVn5fjEV8n
f548in3ZOJ46hWHC8vSIzcFipaXK91divvjwCowtiEZhkOtjo8FjwOrrUju3PwdxxRejUOV83E0t
7Ay1YCKae0oD7yPZbVTVdzUPGeG+oKoaH51Gq/c3e1NQDlucXMFnru27FjK3IEA51Ych9ccVBiel
MyA=
=nkN3
-----END PGP SIGNATURE-----