summaryrefslogtreecommitdiffstats
path: root/upstream/mageia-cauldron/man3/sd_notify.3
blob: 48274b00972bbcdd4217afd3c4360f79ec18d36c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
'\" t
.TH "SD_NOTIFY" "3" "" "systemd 255" "sd_notify"
.\" -----------------------------------------------------------------
.\" * Define some portability stuff
.\" -----------------------------------------------------------------
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.\" http://bugs.debian.org/507673
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.ie \n(.g .ds Aq \(aq
.el       .ds Aq '
.\" -----------------------------------------------------------------
.\" * set default formatting
.\" -----------------------------------------------------------------
.\" disable hyphenation
.nh
.\" disable justification (adjust text to left margin only)
.ad l
.\" -----------------------------------------------------------------
.\" * MAIN CONTENT STARTS HERE *
.\" -----------------------------------------------------------------
.SH "NAME"
sd_notify, sd_notifyf, sd_pid_notify, sd_pid_notifyf, sd_pid_notify_with_fds, sd_pid_notifyf_with_fds, sd_notify_barrier, sd_pid_notify_barrier \- Notify service manager about start\-up completion and other service status changes
.SH "SYNOPSIS"
.sp
.ft B
.nf
#include <systemd/sd\-daemon\&.h>
.fi
.ft
.HP \w'int\ sd_notify('u
.BI "int sd_notify(int\ " "unset_environment" ", const\ char\ *" "state" ");"
.HP \w'int\ sd_notifyf('u
.BI "int sd_notifyf(int\ " "unset_environment" ", const\ char\ *" "format" ", \&...);"
.HP \w'int\ sd_pid_notify('u
.BI "int sd_pid_notify(pid_t\ " "pid" ", int\ " "unset_environment" ", const\ char\ *" "state" ");"
.HP \w'int\ sd_pid_notifyf('u
.BI "int sd_pid_notifyf(pid_t\ " "pid" ", int\ " "unset_environment" ", const\ char\ *" "format" ", \&...);"
.HP \w'int\ sd_pid_notify_with_fds('u
.BI "int sd_pid_notify_with_fds(pid_t\ " "pid" ", int\ " "unset_environment" ", const\ char\ *" "state" ", const\ int\ *" "fds" ", unsigned\ " "n_fds" ");"
.HP \w'int\ sd_pid_notifyf_with_fds('u
.BI "int sd_pid_notifyf_with_fds(pid_t\ " "pid" ", int\ " "unset_environment" ", const\ int\ *" "fds" ", size_t\ " "n_fds" ", const\ char\ *" "format" ", \&...);"
.HP \w'int\ sd_notify_barrier('u
.BI "int sd_notify_barrier(int\ " "unset_environment" ", uint64_t\ " "timeout" ");"
.HP \w'int\ sd_pid_notify_barrier('u
.BI "int sd_pid_notify_barrier(pid_t\ " "pid" ", int\ " "unset_environment" ", uint64_t\ " "timeout" ");"
.SH "DESCRIPTION"
.PP
\fBsd_notify()\fR
may be called by a service to notify the service manager about state changes\&. It can be used to send arbitrary information, encoded in an environment\-block\-like string\&. Most importantly, it can be used for start\-up or reload completion notifications\&.
.PP
If the
\fIunset_environment\fR
parameter is non\-zero,
\fBsd_notify()\fR
will unset the
\fI$NOTIFY_SOCKET\fR
environment variable before returning (regardless of whether the function call itself succeeded or not)\&. Further calls to
\fBsd_notify()\fR
will then fail, and the variable is no longer inherited by child processes\&.
.PP
The
\fIstate\fR
parameter should contain a newline\-separated list of variable assignments, similar in style to an environment block\&. A trailing newline is implied if none is specified\&. The string may contain any kind of variable assignments, but see the next section for a list of assignments understood by the service manager\&.
.PP
Note that systemd will accept status data sent from a service only if the
\fINotifyAccess=\fR
option is correctly set in the service definition file\&. See
\fBsystemd.service\fR(5)
for details\&.
.PP
Note that
\fBsd_notify()\fR
notifications may be attributed to units correctly only if either the sending process is still around at the time PID 1 processes the message, or if the sending process is explicitly runtime\-tracked by the service manager\&. The latter is the case if the service manager originally forked off the process, i\&.e\&. on all processes that match
\fINotifyAccess=\fR\fBmain\fR
or
\fINotifyAccess=\fR\fBexec\fR\&. Conversely, if an auxiliary process of the unit sends an
\fBsd_notify()\fR
message and immediately exits, the service manager might not be able to properly attribute the message to the unit, and thus will ignore it, even if
\fINotifyAccess=\fR\fBall\fR
is set for it\&.
.PP
Hence, to eliminate all race conditions involving lookup of the client\*(Aqs unit and attribution of notifications to units correctly,
\fBsd_notify_barrier()\fR
may be used\&. This call acts as a synchronization point and ensures all notifications sent before this call have been picked up by the service manager when it returns successfully\&. Use of
\fBsd_notify_barrier()\fR
is needed for clients which are not invoked by the service manager, otherwise this synchronization mechanism is unnecessary for attribution of notifications to the unit\&.
.PP
\fBsd_notifyf()\fR
is similar to
\fBsd_notify()\fR
but takes a
\fBprintf()\fR\-like format string plus arguments\&.
.PP
\fBsd_pid_notify()\fR
and
\fBsd_pid_notifyf()\fR
are similar to
\fBsd_notify()\fR
and
\fBsd_notifyf()\fR
but take a process ID (PID) to use as originating PID for the message as first argument\&. This is useful to send notification messages on behalf of other processes, provided the appropriate privileges are available\&. If the PID argument is specified as 0, the process ID of the calling process is used, in which case the calls are fully equivalent to
\fBsd_notify()\fR
and
\fBsd_notifyf()\fR\&.
.PP
\fBsd_pid_notify_with_fds()\fR
is similar to
\fBsd_pid_notify()\fR
but takes an additional array of file descriptors\&. These file descriptors are sent along the notification message to the service manager\&. This is particularly useful for sending
"FDSTORE=1"
messages, as described above\&. The additional arguments are a pointer to the file descriptor array plus the number of file descriptors in the array\&. If the number of file descriptors is passed as 0, the call is fully equivalent to
\fBsd_pid_notify()\fR, i\&.e\&. no file descriptors are passed\&. Note that file descriptors sent to the service manager on a message without
"FDSTORE=1"
are immediately closed on reception\&.
.PP
\fBsd_pid_notifyf_with_fds()\fR
is a combination of
\fBsd_pid_notify_with_fds()\fR
and
\fBsd_notifyf()\fR, i\&.e\&. it accepts both a PID and a set of file descriptors as input, and processes a format string to generate the state string\&.
.PP
\fBsd_notify_barrier()\fR
allows the caller to synchronize against reception of previously sent notification messages and uses the
\fIBARRIER=1\fR
command\&. It takes a relative
\fItimeout\fR
value in microseconds which is passed to
\fBppoll\fR(2)\&. A value of UINT64_MAX is interpreted as infinite timeout\&.
.PP
\fBsd_pid_notify_barrier()\fR
is just like
\fBsd_notify_barrier()\fR, but allows specifying the originating PID for the notification message\&.
.SH "WELL\-KNOWN ASSIGNMENTS"
.PP
The following assignments have a defined meaning:
.PP
READY=1
.RS 4
Tells the service manager that service startup is finished, or the service finished re\-loading its configuration\&. This is only used by systemd if the service definition file has
\fIType=notify\fR
or
\fIType=notify\-reload\fR
set\&. Since there is little value in signaling non\-readiness, the only value services should send is
"READY=1"
(i\&.e\&.
"READY=0"
is not defined)\&.
.RE
.PP
RELOADING=1
.RS 4
Tells the service manager that the service is beginning to reload its configuration\&. This is useful to allow the service manager to track the service\*(Aqs internal state, and present it to the user\&. Note that a service that sends this notification must also send a
"READY=1"
notification when it completed reloading its configuration\&. Reloads the service manager is notified about with this mechanisms are propagated in the same way as they are when originally initiated through the service manager\&. This message is particularly relevant for
\fIType=notify\-reload\fR
services, to inform the service manager that the request to reload the service has been received and is now being processed\&.
.sp
Added in version 217\&.
.RE
.PP
STOPPING=1
.RS 4
Tells the service manager that the service is beginning its shutdown\&. This is useful to allow the service manager to track the service\*(Aqs internal state, and present it to the user\&.
.sp
Added in version 217\&.
.RE
.PP
MONOTONIC_USEC=\&...
.RS 4
A field carrying the monotonic timestamp (as per
\fBCLOCK_MONOTONIC\fR) formatted in decimal in μs, when the notification message was generated by the client\&. This is typically used in combination with
"RELOADING=1", to allow the service manager to properly synchronize reload cycles\&. See
\fBsystemd.service\fR(5)
for details, specifically
"Type=notify\-reload"\&.
.sp
Added in version 253\&.
.RE
.PP
STATUS=\&...
.RS 4
Passes a single\-line UTF\-8 status string back to the service manager that describes the service state\&. This is free\-form and can be used for various purposes: general state feedback, fsck\-like programs could pass completion percentages and failing programs could pass a human\-readable error message\&. Example:
"STATUS=Completed 66% of file system check\&..."
.sp
Added in version 233\&.
.RE
.PP
NOTIFYACCESS=\&...
.RS 4
Reset the access to the service status notification socket during runtime, overriding
\fINotifyAccess=\fR
setting in the service unit file\&. See
\fBsystemd.service\fR(5)
for details, specifically
"NotifyAccess="
for a list of accepted values\&.
.sp
Added in version 254\&.
.RE
.PP
ERRNO=\&...
.RS 4
If a service fails, the errno\-style error code, formatted as string\&. Example:
"ERRNO=2"
for ENOENT\&.
.sp
Added in version 233\&.
.RE
.PP
BUSERROR=\&...
.RS 4
If a service fails, the D\-Bus error\-style error code\&. Example:
"BUSERROR=org\&.freedesktop\&.DBus\&.Error\&.TimedOut"\&. Note that this assignment is currently not used by
\fBsystemd\fR\&.
.sp
Added in version 233\&.
.RE
.PP
EXIT_STATUS=\&...
.RS 4
The exit status of a service or the manager itself\&. Note that
\fBsystemd\fR
currently does not consume this value when sent by services, so this assignment is only informational\&. The manager will send this notification to
\fIits\fR
notification socket, which may be used to to collect an exit status from the system (a container or VM) as it shuts down\&. For example,
\fBmkosi\fR(1)
makes use of this\&. The value to return may be set via the
\fBsystemctl\fR(1)
\fBexit\fR
verb\&.
.sp
Added in version 254\&.
.RE
.PP
MAINPID=\&...
.RS 4
The main process ID (PID) of the service, in case the service manager did not fork off the process itself\&. Example:
"MAINPID=4711"\&.
.sp
Added in version 233\&.
.RE
.PP
WATCHDOG=1
.RS 4
Tells the service manager to update the watchdog timestamp\&. This is the keep\-alive ping that services need to issue in regular intervals if
\fIWatchdogSec=\fR
is enabled for it\&. See
\fBsystemd.service\fR(5)
for information how to enable this functionality and
\fBsd_watchdog_enabled\fR(3)
for the details of how the service can check whether the watchdog is enabled\&.
.RE
.PP
WATCHDOG=trigger
.RS 4
Tells the service manager that the service detected an internal error that should be handled by the configured watchdog options\&. This will trigger the same behaviour as if
\fIWatchdogSec=\fR
is enabled and the service did not send
"WATCHDOG=1"
in time\&. Note that
\fIWatchdogSec=\fR
does not need to be enabled for
"WATCHDOG=trigger"
to trigger the watchdog action\&. See
\fBsystemd.service\fR(5)
for information about the watchdog behavior\&.
.sp
Added in version 243\&.
.RE
.PP
WATCHDOG_USEC=\&...
.RS 4
Reset
\fIwatchdog_usec\fR
value during runtime\&. Notice that this is not available when using
\fBsd_event_set_watchdog()\fR
or
\fBsd_watchdog_enabled()\fR\&. Example :
"WATCHDOG_USEC=20000000"
.sp
Added in version 233\&.
.RE
.PP
EXTEND_TIMEOUT_USEC=\&...
.RS 4
Tells the service manager to extend the startup, runtime or shutdown service timeout corresponding the current state\&. The value specified is a time in microseconds during which the service must send a new message\&. A service timeout will occur if the message isn\*(Aqt received, but only if the runtime of the current state is beyond the original maximum times of
\fITimeoutStartSec=\fR,
\fIRuntimeMaxSec=\fR, and
\fITimeoutStopSec=\fR\&. See
\fBsystemd.service\fR(5)
for effects on the service timeouts\&.
.sp
Added in version 236\&.
.RE
.PP
FDSTORE=1
.RS 4
Store file descriptors in the service manager\&. File descriptors sent this way will be held for the service by the service manager and will later be handed back using the usual file descriptor passing logic at the next start or restart of the service, see
\fBsd_listen_fds\fR(3)\&. Any open sockets and other file descriptors which should not be closed during a restart may be stored this way\&. When a service is stopped, its file descriptor store is discarded and all file descriptors in it are closed, except when overridden with
\fIFileDescriptorStorePreserve=\fR, see
\fBsystemd.service\fR(5)\&.
.sp
The service manager will accept messages for a service only if its
\fIFileDescriptorStoreMax=\fR
setting is non\-zero (defaults to zero, see
\fBsystemd.service\fR(5))\&. The service manager will set the
\fI$FDSTORE\fR
environment variable for services that have the file descriptor store enabled, see
\fBsystemd.exec\fR(5)\&.
.sp
If
\fIFDPOLL=0\fR
is not set and the file descriptors are pollable (see
\fBepoll_ctl\fR(2)), then any
\fBEPOLLHUP\fR
or
\fBEPOLLERR\fR
event seen on them will result in their automatic removal from the store\&.
.sp
Multiple sets of file descriptors may be sent in separate messages, in which case the sets are combined\&. The service manager removes duplicate file descriptors (those pointing to the same object) before passing them to the service\&.
.sp
This functionality should be used to implement services that can restart after an explicit request or a crash without losing state\&. Application state can either be serialized to a file in
/run/, or better, stored in a
\fBmemfd_create\fR(2)
memory file descriptor\&. Use
\fBsd_pid_notify_with_fds()\fR
to send messages with
"FDSTORE=1"\&. It is recommended to combine
\fIFDSTORE=\fR
with
\fIFDNAME=\fR
to make it easier to manage the stored file descriptors\&.
.sp
For further information on the file descriptor store see the
\m[blue]\fBFile Descriptor Store\fR\m[]\&\s-2\u[1]\d\s+2
overview\&.
.sp
Added in version 219\&.
.RE
.PP
FDSTOREREMOVE=1
.RS 4
Removes file descriptors from the file descriptor store\&. This field needs to be combined with
\fIFDNAME=\fR
to specify the name of the file descriptors to remove\&.
.sp
Added in version 236\&.
.RE
.PP
FDNAME=\&...
.RS 4
When used in combination with
\fIFDSTORE=1\fR, specifies a name for the submitted file descriptors\&. When used with
\fIFDSTOREREMOVE=1\fR, specifies the name for the file descriptors to remove\&. This name is passed to the service during activation, and may be queried using
\fBsd_listen_fds_with_names\fR(3)\&. File descriptors submitted without this field will be called
"stored"\&.
.sp
The name may consist of arbitrary ASCII characters except control characters or
":"\&. It may not be longer than 255 characters\&. If a submitted name does not follow these restrictions, it is ignored\&.
.sp
Note that if multiple file descriptors are submitted in a single message, the specified name will be used for all of them\&. In order to assign different names to submitted file descriptors, submit them in separate messages\&.
.sp
Added in version 233\&.
.RE
.PP
FDPOLL=0
.RS 4
When used in combination with
\fIFDSTORE=1\fR, disables polling of the stored file descriptors regardless of whether or not they are pollable\&. As this option disables automatic cleanup of the stored file descriptors on EPOLLERR and EPOLLHUP, care must be taken to ensure proper manual cleanup\&. Use of this option is not generally recommended except for when automatic cleanup has unwanted behavior such as prematurely discarding file descriptors from the store\&.
.sp
Added in version 246\&.
.RE
.PP
BARRIER=1
.RS 4
Tells the service manager that the client is explicitly requesting synchronization by means of closing the file descriptor sent with this command\&. The service manager guarantees that the processing of a
\fIBARRIER=1\fR
command will only happen after all previous notification messages sent before this command have been processed\&. Hence, this command accompanied with a single file descriptor can be used to synchronize against reception of all previous status messages\&. Note that this command cannot be mixed with other notifications, and has to be sent in a separate message to the service manager, otherwise all assignments will be ignored\&. Note that sending 0 or more than 1 file descriptor with this command is a violation of the protocol\&.
.sp
Added in version 246\&.
.RE
.PP
The notification messages sent by services are interpreted by the service manager\&. Unknown assignments may be logged, but are otherwise ignored\&. Thus, it is not useful to send assignments which are not in this list\&. The service manager also sends some messages to
\fIits\fR
notification socket, which are then consumed by the machine or container manager\&.
.SH "RETURN VALUE"
.PP
On failure, these calls return a negative errno\-style error code\&. If
\fI$NOTIFY_SOCKET\fR
was not set and hence no status message could be sent, 0 is returned\&. If the status was sent, these functions return a positive value\&. In order to support both service managers that implement this scheme and those which do not, it is generally recommended to ignore the return value of this call\&. Note that the return value simply indicates whether the notification message was enqueued properly, it does not reflect whether the message could be processed successfully\&. Specifically, no error is returned when a file descriptor is attempted to be stored using
\fIFDSTORE=1\fR
but the service is not actually configured to permit storing of file descriptors (see above)\&.
.SH "NOTES"
.PP
Functions described here are available as a shared library, which can be compiled against and linked to with the
\fBlibsystemd\fR\ \&\fBpkg-config\fR(1)
file\&.
.PP
The code described here uses
\fBgetenv\fR(3), which is declared to be not multi\-thread\-safe\&. This means that the code calling the functions described here must not call
\fBsetenv\fR(3)
from a parallel thread\&. It is recommended to only do calls to
\fBsetenv()\fR
from an early phase of the program when no other threads have been started\&.
.PP
These functions send a single datagram with the state string as payload to the socket referenced in the
\fI$NOTIFY_SOCKET\fR
environment variable\&. If the first character of
\fI$NOTIFY_SOCKET\fR
is
"/"
or
"@", the string is understood as an
\fBAF_UNIX\fR
or Linux abstract namespace socket (respectively), and in both cases the datagram is accompanied by the process credentials of the sending service, using SCM_CREDENTIALS\&. If the string starts with
"vsock:"
then the string is understood as an
\fBAF_VSOCK\fR
address, which is useful for hypervisors/VMMs or other processes on the host to receive a notification when a virtual machine has finished booting\&. Note that in case the hypervisor does not support
\fBSOCK_DGRAM\fR
over
\fBAF_VSOCK\fR,
\fBSOCK_SEQPACKET\fR
will be used instead\&. The address should be in the form:
"vsock:CID:PORT"\&. Note that unlike other uses of vsock, the CID is mandatory and cannot be
"VMADDR_CID_ANY"\&. Note that PID1 will send the VSOCK packets from a privileged port (i\&.e\&.: lower than 1024), as an attempt to address concerns that unprivileged processes in the guest might try to send malicious notifications to the host, driving it to make destructive decisions based on them\&.
.PP
Note that, while using this library should be preferred in order to avoid code duplication, it is also possible to reimplement the simple readiness notification protocol without external dependencies, as demonstrated in the following self\-contained example:
.sp
.if n \{\
.RS 4
.\}
.nf
/* SPDX\-License\-Identifier: MIT\-0 */

/* Implement the systemd notify protocol without external dependencies\&.
 * Supports both readiness notification on startup and on reloading,
 * according to the protocol defined at:
 * https://www\&.freedesktop\&.org/software/systemd/man/latest/sd_notify\&.html
 * This protocol is guaranteed to be stable as per:
 * https://systemd\&.io/PORTABILITY_AND_STABILITY/ */

#include <errno\&.h>
#include <inttypes\&.h>
#include <signal\&.h>
#include <stdbool\&.h>
#include <stddef\&.h>
#include <stdlib\&.h>
#include <stdio\&.h>
#include <sys/socket\&.h>
#include <sys/un\&.h>
#include <time\&.h>
#include <unistd\&.h>

#define _cleanup_(f) __attribute__((cleanup(f)))

static void closep(int *fd) {
  if (!fd || *fd < 0)
    return;

  close(*fd);
  *fd = \-1;
}

static int notify(const char *message) {
  union sockaddr_union {
    struct sockaddr sa;
    struct sockaddr_un sun;
  } socket_addr = {
    \&.sun\&.sun_family = AF_UNIX,
  };
  size_t path_length, message_length;
  _cleanup_(closep) int fd = \-1;
  const char *socket_path;

  socket_path = getenv("NOTIFY_SOCKET");
  if (!socket_path)
    return 0; /* Not running under systemd? Nothing to do */

  if (!message)
    return \-EINVAL;

  message_length = strlen(message);
  if (message_length == 0)
    return \-EINVAL;

  /* Only AF_UNIX is supported, with path or abstract sockets */
  if (socket_path[0] != \*(Aq/\*(Aq && socket_path[0] != \*(Aq@\*(Aq)
    return \-EAFNOSUPPORT;

  path_length = strlen(socket_path);
  /* Ensure there is room for NUL byte */
  if (path_length >= sizeof(socket_addr\&.sun\&.sun_path))
    return \-E2BIG;

  memcpy(socket_addr\&.sun\&.sun_path, socket_path, path_length);

  /* Support for abstract socket */
  if (socket_addr\&.sun\&.sun_path[0] == \*(Aq@\*(Aq)
    socket_addr\&.sun\&.sun_path[0] = 0;

  fd = socket(AF_UNIX, SOCK_DGRAM|SOCK_CLOEXEC, 0);
  if (fd < 0)
    return \-errno;

  if (connect(fd, &socket_addr\&.sa, offsetof(struct sockaddr_un, sun_path) + path_length) != 0)
    return \-errno;

  ssize_t written = write(fd, message, message_length);
  if (written != (ssize_t) message_length)
    return written < 0 ? \-errno : \-EPROTO;

  return 1; /* Notified! */
}

static int notify_ready(void) {
  return notify("READY=1");
}

static int notify_reloading(void) {
  /* A buffer with length sufficient to format the maximum UINT64 value\&. */
  char reload_message[sizeof("RELOADING=1\enMONOTONIC_USEC=18446744073709551615")];
  struct timespec ts;
  uint64_t now;

  /* Notify systemd that we are reloading, including a CLOCK_MONOTONIC timestamp in usec
   * so that the program is compatible with a Type=notify\-reload service\&. */

  if (clock_gettime(CLOCK_MONOTONIC, &ts) < 0)
    return \-errno;

  if (ts\&.tv_sec < 0 || ts\&.tv_nsec < 0 ||
      (uint64_t) ts\&.tv_sec > (UINT64_MAX \- (ts\&.tv_nsec / 1000ULL)) / 1000000ULL)
    return \-EINVAL;

  now = (uint64_t) ts\&.tv_sec * 1000000ULL + (uint64_t) ts\&.tv_nsec / 1000ULL;

  if (snprintf(reload_message, sizeof(reload_message), "RELOADING=1\enMONOTONIC_USEC=%" PRIu64, now) < 0)
    return \-EINVAL;

  return notify(reload_message);
}

static volatile sig_atomic_t reloading = 0;
static volatile sig_atomic_t terminating = 0;

static void signal_handler(int sig) {
  if (sig == SIGHUP)
    reloading = 1;
  else if (sig == SIGINT || sig == SIGTERM)
    terminating = 1;
}

int main(int argc, char **argv) {
  struct sigaction sa = {
    \&.sa_handler = signal_handler,
    \&.sa_flags = SA_RESTART,
  };
  int r;

  /* Setup signal handlers */
  sigemptyset(&sa\&.sa_mask);
  sigaction(SIGHUP, &sa, NULL);
  sigaction(SIGINT, &sa, NULL);
  sigaction(SIGTERM, &sa, NULL);

  /* Do more service initialization work here \&... */

  /* Now that all the preparations steps are done, signal readiness */

  r = notify_ready();
  if (r < 0) {
    fprintf(stderr, "Failed to notify readiness to $NOTIFY_SOCKET: %s\en", strerror(\-r));
    return EXIT_FAILURE;
  }

  while (!terminating) {
    if (reloading) {
      reloading = false;

      /* As a separate but related feature, we can also notify the manager
       * when reloading configuration\&. This allows accurate state\-tracking,
       * and also automated hook\-in of \*(Aqsystemctl reload\*(Aq without having to
       * specify manually an ExecReload= line in the unit file\&. */

      r = notify_reloading();
      if (r < 0) {
        fprintf(stderr, "Failed to notify reloading to $NOTIFY_SOCKET: %s\en", strerror(\-r));
        return EXIT_FAILURE;
      }

      /* Do some reconfiguration work here \&... */

      r = notify_ready();
      if (r < 0) {
        fprintf(stderr, "Failed to notify readiness to $NOTIFY_SOCKET: %s\en", strerror(\-r));
        return EXIT_FAILURE;
      }
    }

    /* Do some daemon work here \&... */
    sleep(5);
  }

  return EXIT_SUCCESS;
}
.fi
.if n \{\
.RE
.\}
.SH "ENVIRONMENT"
.PP
\fI$NOTIFY_SOCKET\fR
.RS 4
Set by the service manager for supervised processes for status and start\-up completion notification\&. This environment variable specifies the socket
\fBsd_notify()\fR
talks to\&. See above for details\&.
.RE
.SH "EXAMPLES"
.PP
\fBExample\ \&1.\ \&Start\-up Notification\fR
.PP
When a service finished starting up, it might issue the following call to notify the service manager:
.sp
.if n \{\
.RS 4
.\}
.nf
sd_notify(0, "READY=1");
.fi
.if n \{\
.RE
.\}
.PP
\fBExample\ \&2.\ \&Extended Start\-up Notification\fR
.PP
A service could send the following after completing initialization:
.sp
.if n \{\
.RS 4
.\}
.nf
sd_notifyf(0, "READY=1\en"
           "STATUS=Processing requests\&...\en"
           "MAINPID=%lu",
           (unsigned long) getpid());
.fi
.if n \{\
.RE
.\}
.PP
\fBExample\ \&3.\ \&Error Cause Notification\fR
.PP
A service could send the following shortly before exiting, on failure:
.sp
.if n \{\
.RS 4
.\}
.nf
sd_notifyf(0, "STATUS=Failed to start up: %s\en"
           "ERRNO=%i",
           strerror_r(errnum, (char[1024]){}, 1024),
           errnum);
.fi
.if n \{\
.RE
.\}
.PP
\fBExample\ \&4.\ \&Store a File Descriptor in the Service Manager\fR
.PP
To store an open file descriptor in the service manager, in order to continue operation after a service restart without losing state, use
"FDSTORE=1":
.sp
.if n \{\
.RS 4
.\}
.nf
sd_pid_notify_with_fds(0, 0, "FDSTORE=1\enFDNAME=foobar", &fd, 1);
.fi
.if n \{\
.RE
.\}
.PP
\fBExample\ \&5.\ \&Eliminating race conditions\fR
.PP
When the client sending the notifications is not spawned by the service manager, it may exit too quickly and the service manager may fail to attribute them correctly to the unit\&. To prevent such races, use
\fBsd_notify_barrier()\fR
to synchronize against reception of all notifications sent before this call is made\&.
.sp
.if n \{\
.RS 4
.\}
.nf
sd_notify(0, "READY=1");
/* set timeout to 5 seconds */
sd_notify_barrier(0, 5 * 1000000);
      
.fi
.if n \{\
.RE
.\}
.SH "HISTORY"
.PP
\fBsd_pid_notify()\fR,
\fBsd_pid_notifyf()\fR, and
\fBsd_pid_notify_with_fds()\fR
were added in version 219\&.
.PP
\fBsd_notify_barrier()\fR
was added in version 246\&.
.PP
\fBsd_pid_notifyf_with_fds()\fR
and
\fBsd_pid_notify_barrier()\fR
were added in version 254\&.
.SH "SEE ALSO"
.PP
\fBsystemd\fR(1),
\fBsd-daemon\fR(3),
\fBsd_listen_fds\fR(3),
\fBsd_listen_fds_with_names\fR(3),
\fBsd_watchdog_enabled\fR(3),
\fBdaemon\fR(7),
\fBsystemd.service\fR(5)
.SH "NOTES"
.IP " 1." 4
File Descriptor Store
.RS 4
\%https://systemd.io/FILE_DESCRIPTOR_STORE
.RE