On Wed, Sep 23, 2026, at 4:28 PM, Tomas Volf wrote:
> "Zack Weinberg" <[email protected]> writes:
>> more code means more bugs, and if process 1 crashes it takes out the
>> entire system.
>
> Well, if the real Shepherd dies, the system will probably not be able
> to recover regardless whether it was PID 1 or PID 2.  Even if you
> would have shell open at the moment, `shutdown' will not work (it
> talks to shepherd).

That's true right now, but having the main service manager not be PID 1
opens up possibilities for recovering from a crash that aren't available
when it runs as PID 1.  For example, the main service manager could be
PID 3, with PID 2 another little shim that restarts it if it fails, or
executes a *clean* reboot instead of a crash.

(I considered giving "nanoreaper" the ability to respawn the "rc script"
if if exits but decided that that would add unwanted extra complexity to
a program that currently fits in a single page of executable machine
code (with some caveats about the C library) and possibly also be too
inflexible.  I'm open to reconsidering that decision>)

>> These are proof-of-concept implementations right now; notably, I do
>> not know whether it is *useful* for "nanoreaper" to forward orphaned
>> process exit notifications to the real Shepherd, and nothing has been
>> tested in "real life" usage.  But they should be robust enough to
>> experiment with, at least.  I'd like to hear whatever you have to say
>> about them.
>
> Obvious question I guess is why not just use `tini'?  It works well,
> is packaged in Guix and battle-tested.

I was not previously familiar with 'tini', thanks for pointing it out.
There are two key differences.  'tini' is designed for use in containers,
and has features that are unnecessary or undesirable in system-wide PID
1 (signal forwarding, parent death tracking).  Conversely, 'tini' *lacks*
the feature of being able to forward *process exit* notifications to
another program, which I think may be needed for use with a complex
systemwide service manager like the Shepherd.

zw

Reply via email to