Re: Scripting Stage 3 and 4

Paul Sopka <[email protected]> Sat, 11 Jan 2025 16:15:42 +0100
Newsgroups gmane.comp.sysutils.supervision.general
Message-ID <[email protected]>
>  With no tty? and not even a redirection from/to /dev/console? That's
> going to be a tough recovery 😉
I took redirection from/to /dev/console for granted xD, after all what I 
wrote as only part of a larger script.

>  And sure, you could wrap all your commands in a big if block. But my
> point is that these are *things you need to think about*. I'd rather
> not have to think about new things at shutdown time when I don't have
> to. Why change something and duplicate logic when you could just do
> nothing and keep what's already working and has worked for the whole
> lifetime of the machine? 
So you mean rather than (to quote myself):
> | if -n { mount -o remount,ro / }
> | foreground { s6-svc -U /run/service/recovery } 
You would just not tear down one tty (e.g. 12) or a "minimal recovery 
ssh server listening on an unusual port"?

>  The key to understanding how to manage a shutdown, I think, is to
> realize that boot and shutdown *are not symmetrical*, and so, do not
> need to be handled in a symmetrical way. Because you set up a
> supervision tree at boot time does not mean you need to get rid of it
> at shutdown time.
>
>  When you boot, you're starting from *nothing*, and you need to build
> up to a state where the machine is functional and able to run services,
> that's why it's incremental and deliberate and elaborate. It is
> literally a bootstrap process that needs precise ordering.
>
>  When you shutdown, you're starting from a state where everything is
> already working, so you can rely on many more features, and you're not
> trying to build anything, you're just trying to ensure consistency of
> permanent state (aka disk) before you pull the plug. It's the only
> thing that matters. If you were only ever operating in RAM, starting
> from ROM / ro disk, and never had any mutable permanent state, your
> shutdown procedure could just be an immediate reboot(), or pressing
> the power off button; it is the case for some embedded devices. But
> with mutable permanent state, we need to be more careful, that's why
> we shut down services in an ordered way, and then make sure we can
> unmount the filesystems before powering off. It's the *only* reason;
> apart from that, you can do whatever you want. Who cares? the system is
> going to be down anyway. When the Armageddon comes, you want to make
> sure the time capsules are well sealed and buried for the next
> civilization to find, but you don't have to clean your room.
>
>  So the goals of boot and shutdown are very different.
>
>  I specifically designed s6-linux-init so it would not store any vital
> information in permanent mutable state, and would not hold any writing
> fd on a filesystem. That means s6 will not prevent you from unmounting
> your filesystems, parking your disks, whatever - and that the
> supervision tree can keep running until you pull the plug. It is
> designed to help you while the machine is running, and *especially*
> in delicate situations where you're killing things and want to be sure
> you can recover if something goes wrong rather than brick the system.
> That's why I'm saying it's less effort to keep it in place and work
> with disabling supervision when it needs to be disabled, than to
> dismantle the supervision tree and have to reimplement recovery logic. 
Very interesting, thank you very much for this detailed response, I 
fully agree!
I think it might be worth putting this on the page I cited in the first 
mail.

>> | if -n { mount -o remount,ro / }
>> | foreground { s6-svc -U /run/service/recovery }
>
>  You just tore down the supervision tree, and you want to start a
> recovery... service? :D 

This was meant for the approach of keeping the supervision tree,
to be ran by the shutdown service.
But now it seems to me that it would be another case of

> *things you need to think about*
So, I guess it would be better to have a recovery service right away and 
not stop it,
like I suggested at the start of this mail?

Finally, wouldn't at least one "if" be appropriate,
to be sure whether everything is unmounted properly?


Regards,

Paul
OpenPGP_0x71C7C85A2EA30F62.asc (application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGW5FlEBEACi9wDm7vnwoxMy6ejpZQh2Z1Mpr4fTKJyWLn3sZFAjmQKcsT/O
Rt0rVSBO5eXoGjbk5Hor2l67mui85a4KWawHbYFC95hpA9K/alfGyQH56SnL5G55
DDcz3avkLrJ9bHJD4y4ScEzweYW2IjYr90FKqZWWcdqzYDqmqRtf5/rdkmY6YVtp
BISIfYNbBRPE3CJuY7HOpQ4sqAmb5iRsXN38hv7UQj9MsJl5Q0cxgcFcRGy9dAM5
voX1Xh+h9svS1MZuaxzyLR0YvCzAcY8c7uUsXjj67/NmeHpl5pYHiT19g/wcHbud
YLI+pikx4EcskinZ1peZbrbBdVdBeOtukBzaMuFedOcSpAWbDDK7e4cwZnPse130
FjNECzIrNAB2lK2rb9f2PCyZSRCW7QBG63IUREWZTLBm47DyavMzh+wGV6Jx6kig
dngJDtIXXDzw2ZWAMMT2MEPX4HC1POH8b1DZ/QxzC+2SQbJNfrQitm0KkOo8o2gq
MpuBABAYzQwRJXNteeW5ZccbgdQ0+m61kV/P71bmeiasvJGyecxzOfRUDei7b3Lh
8O5xPHP1dq23E9R76fCaCCiutfiZT5zT5dbn8XGqBmKI9z8VGEfCBdFbopZd4fpQ
PmVNWlR0yrM7DnHST1OJtGZ2/gwk0Py2dO+lbZDQMqVRVYXT1dYenwYa5QARAQAB
zRxQYXVsIFNvcGthIDxwc29wa2FAc29wa2EuY2g+wsGUBBMBCgA+FiEEklpwGqZx
1YzBW1hqccfIWi6jD2IFAmW5FlECGwMFCQeEzgAFCwkIBwMFFQoJCAsFFgIDAQAC
HgUCF4AACgkQccfIWi6jD2KbNw//QSMh6QRTxCRHVJGp4vHAz6hWt/zimRbVkO0t
4Q/5uXClRnMzZqqE+TLubNRy560Y/LxuQ4phB/O4mcHRqbV9Xrarx98jWNqMgsGh
D60W3uxr6RRObeB0+PpRHVhzzqAMtWh6OZGQ9+vJJf3Q4Axwo/cafNgm2V0MOWsV
FUxUVUbDsR8aZP7RyDRJRv5v6T4pu4Jjd9BH+UxfsG5dvE2Jqj4/a5OIcJ0XlMSk
JxHorDjxLGNFJ8pTcH3/Y7eWmPL0U6kKS99ol763V5LEOnQnqpbwqCalwumgYoXw
HCahiZlmX2Zl4omf9zHvgzADk66rNvZUvBAIMXDWAoWjL9IxxqTIVUjJk0cv3jN8
fZc309s40jDQze3LDSCp9+7SP//jlgADsvfUxJemvoqDYpANrt/wEZ9lxr5doi0R
2CEPbfPkmWyaGUcFBdlVAaYCL5Sg++OfyjCeu4MAC1JZfHOBjQbzwKhG4MqZs8O1
Snr42JvbyzonDckl7UJUZwChUPO4GrFu8zQxqa2ZDx/zok6+bMD0ggDXj6svGUzG
qMxOr4bJa7MxUQ1iIXYl0WTEFbTT9GTi3nxXt0ZPyHN1f9GXgGAB5Qc8hpgm6VFe
wjeohNvaxOpcMCXBYWX9DcuNuKMwofOpGV2hse3bOwy13+ci7sb/A2RBC0wBKV/2
0iuLxFrOwU0EZbkWUQEQAMMWfQpVgrSLCMspW5lkjvl+0Bz1XurJzUF9OcLP2DSR
HEuYNlc+XBvPxh1F3vJfv1Ts79ayDi7YQn+sVTtkGja2RnzXIzrfnodgYe4F71mW
9IjYN6Pl3oUBCBB8vJt1oTwNfRugLGP0ZA5T8ntHP3ryUnBlSr3rTQp8JuOJ/9An
thWDHHoP8qIy9HNDdinDNVpHhGJ4w4CtM2QwFh33ZYXY7qFGOwKdnU1AehJ/Ld5O
/XIVPHmaNGuWgXKVlvrCejifD03cRfbwqQA08VQk6/8rLco25EXpKKfqZpKQHibF
TvNF0bKWs7RhFmHqqzqxAWTsXK/S9yOpbad/HShHBpDiKtyit2zaU+DBg2JsHW1K
tISO6ssYyQ1yN8THF4xbOO1xT/bGsfZKC16bZHG9nemzDgcR05recLvZrti8z+55
GHL19SJzVAKZ4TdX/2MGIfPoywMcrs5OIswzIWILz9KwmhqlFop3MzG0Fmv7dxW9
Zf3MFd0Zw1BwuQxm0D1+gFHViuhRi803Stfb9qP+CwSNwsjAQznMFeFKKO/S6yWp
K0bMxt3Io09+rlW/rwhPwl/j8Xwcynr9PDhyBbjhsM30tNzLvJyy0l8aF+GBGX9J
cqjHU1bxM1RQTDHJI1erJaaySZzKqdjYVI/4buGCsUt2lJds6jyy/GPTZKGV9iAL
ABEBAAHCwXwEGAEKACYWIQSSWnAapnHVjMFbWGpxx8haLqMPYgUCZbkWUQIbDAUJ
B4TOAAAKCRBxx8haLqMPYjOmD/9UjqgchWIApSbllaT+o+rf2ZSDVCCcMnv6sVzs
04dAGtn9EyUueishIsbOOH11eRpwnQOMoK4/7MltnRIf0ksX9uho7pDtpPJfveQI
KZ+sTwpOdiy1yQdlT2j1RDtzph+v96KEqa7B9AI4F/34/0a86OJiLs85ystwMw2m
Txiz6Qi0W+nCSxpJr1s1HVfltzkU8ggXfeas0o955VoSHkgwDTjT+gw75nOX/26k
MjFQ8zImWPIf/jvPhq+9yMBuP0iQS+hs1m8xQ7Gd7tG2I5G6kLGEack3bphGzlsP
atSznHi6rnmzVOQI3/vag7oXvNJI6GAZMIUQ5h+lNbGnOBb/M3inTVgyJruNP7Q1
fPIUHG++/5DXWP1uuKJxYGGI/As2tz2lHbWzP7y6jaJvBBjGqPk8JwBfK98JSH4V
vJStF9Ga+QFCCXb2TUeIIS/mVQ3gAln0g2hsZ0QsMvuohk300noV97YnXEKGUXKw
OnfpHAxCYreqzMHInyDm6YciMR2JADhB5tS7KUWmQP2j0lYrEZZJmZ+bu9Edrv/v
67mNDnzCANN1UhuoKODK2Wijcmbtu/7d78SBzxTEjh3RXMZKLS57N78fNnEGnuF9
IS9vOU43y5QCmGCCZsf/r5d5hx2yxqrNInoPiGuY64XUMJXfFbA36ZPoLsvxoK0+
8QRhtw==
=hu4K
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEklpwGqZx1YzBW1hqccfIWi6jD2IFAmeCix4FAwAAAAAACgkQccfIWi6jD2LG
fg/8CUl3i6ZKxcNuEZcpM0Ehvm/Vi2g56xZxq7P7N8dDFBYT9rZq9LERPUGLskLxyh9r9hHVe/nz
Zdt8UUgNSu0YE2rpQb7ifAlFN7yQ+uRDgspKvUIwVtFL/zRMP59qkvdXuLMhTmTPMvbKIS8qdKkH
RwsHvFlkwyNkC+mQ28Wrvgoi5z68TQQFKK4NlBJLCh4IqF7wy1i1TpDQjNYIizPqxKhFH9NxTUTc
lMjbpi2KdRNiMCYWRTl3Yp6k1wZ8aZqqlSoEVHYb7HvEHvp95uzhErVR2EUgkfcXoLbFKpxCYIEz
svvnEcyP6Ebr/laUVfdu6Xa/QqKgvjfa0LDdsV/rF0+Tp6bX3qT9nhogIeGtdiitteP8a4yCwVQl
HdfuDfOzKN5dLjR6WatBiM6cOr0A/Xn+UPcq3ssiMcL3W+u8EmhbTWcUPHS0mwV2s1ZR8hRvGntA
AgejV8fXZkBTvxpGrD49iyB3ojGtRuyNAIxtaeyxSPZesn59DNg+HCOYKjqsmP6xehREnk3TWgjy
9GuoAwLehXGFvY3ojoIhS6Oox0kxM7uYUmnjlkWCl3D4DmyKKctSX0H5NpTtPNDUhUjVYCSMPrl+
37dGRtKwHxLqUZkH+7co2B1iAiFoK6hr6yiHvDjF+Ji9mh2dq3CeuasaQX+p2BvbXti77aC8xmfO
kGo=
=ge2p
-----END PGP SIGNATURE-----