ReferenceEvery page
panel-masterd(8)
panel supervisor
Name
panel-masterd — panel supervisor
Synopsis
panel-masterd [-v] [-f file]
Description
panel-masterd starts and supervises the panel. It is the only process that begins as root and remains so. panel-brokerd(8), panel-api(8) and every installed module are its children, each under its own account.
Each module daemon runs as _panel-id, which panel-masterd makes at every start, while it is root, with the group module_group (see panel.conf(5)). It hands a daemon the capabilities its manifest names as ambient capabilities (of the three it keeps to hand on: net_admin, net_raw and kill), and gives its group read on the logs its manifest names.
Because the supervisor is privileged, it binds every socket itself, with the owner and mode each one needs, and hands the descriptor to the child already open. A module therefore needs no write access to the directory its socket lives in, and the interface can answer on a privileged port without the process that parses requests having been privileged at any point.
Children are started in order: the broker, then the modules, then the interface. panel-installd(8) is the exception: it is started only when the broker connects to its socket, for a job, and leaving when it has none is not treated as a failure.
A child that exits is restarted after a delay that doubles to a maximum of thirty seconds and is forgotten once the child has run for a minute. SIGTERM stops them all.
The options are as follows:
-ffile-
Read configuration from file instead of
/etc/panel/panel.conf. -v- Print the version and exit.
Modules are discovered under module_dir. A manifest that is malformed, or that claims a permission, channel or verb outside its own namespace, is refused and logged; the panel still starts, because it is how the problem would be fixed.
Which accounts may call the broker is worked out from the manifests, so installing a module does not mean editing a configuration file.
Files
/etc/panel/panel.conf/var/run/panel/broker.sock/var/run/panel/installer.sock/var/run/panel/mod/usr/local/share/panel/modules
Exit status
The program exits 0 on success, and more than 0 if an error occurs.
See also
panelctl(1), panel.conf(5), panel-api(8), panel-brokerd(8), panel-installd(8)