Skip to content

add OpenRC service script and config file for ntp-daemon - #2526

Draft
zyxhere wants to merge 1 commit into
pendulum-project:mainfrom
zyxhere:openrc
Draft

zyxhere wants to merge 1 commit into
pendulum-project:mainfrom
zyxhere:openrc

Conversation

@zyxhere

@zyxhere zyxhere commented Oct 3, 2026 •

Copy link
Copy Markdown

Add OpenRC service script and a config file to go along with it, these are supposed to be installed to the init.d directory usually in /etc at /etc/init.d/ntpd-rs and /etc/conf.d/ntpd-rs respectively.

The user can customize ntp-daemon's -c and -l commands by editing the /etc/conf.d/ntpd-rs file

With this configuration OpenRC:

  • starts ntpd-rs as RUST_LOG=info /usr/bin/ntp-daemon -c /etc/ntpd-rs/ntp.toml -l info
  • as unprivileged user ntpd-rs:ntpd-rs
  • with the capabilites cap_net_bind_service and cap_sys_time
  • with NO_NEW_PRIVS enabled
  • after the chosen networking service

But before the service actually starts OpenRC:

  • validates that the config file is correct via ntp-ctl validate or fail to start
  • checks and creates /var/lib/ntpd-rs, /run/ntpd-rs and /var/log/ntpd-rs as ntpd-rs:ntpd-rs if they don't exist

And if the service if restarted OpenRC:

  • checks that the config file is correct first via ntp-ctl validate or else fail to restart with a broken config

And if the service is reloaded via OpenRC with rc-service ntpd-rs reload

  • first check the config file is correct via ntp-ctl validate or fail to start

Thats all.

Comment thread docs/examples/conf/ntpd-rs-OpenRC-initd Outdated
command=/usr/bin/ntp-daemon
command_args="-c ${CONFIG} -l ${LOG_LEVEL}"
# log the stderror and stdout to the logger program
output_logger="logger -t $RC_SVCNAME -p daemon.info"

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we use daemon.notice instead? is ntpd-rs noisy on stdout or does it actually only give out important messages in which case I think we should use notice.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are currently actively working to make ntpd-rs less noisy, so I think we should aspire to daemon.notice I think.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be more appropriate to log to a seperate log file then

@zyxhere
zyxhere force-pushed the openrc branch 2 times, most recently from 5d28ac2 to 6167525 Compare October 3, 2026 07:50
@zyxhere
zyxhere marked this pull request as draft October 3, 2026 07:55
@zyxhere

zyxhere commented Oct 3, 2026 •

Copy link
Copy Markdown
Author

Converting to draft, because of some bugs either in the script, OpenRC or ntpd-rs:

  • The service fails to stop, I don't really know why but if I restart instead of stop then that works..., also if I comment out the stop_pre() function then it stops successfully. nevermind was missing a return 0
  • ntpd-rs doesn't seem to be using /run/ntpd-rs at all so ntpc-tl status errors out with a Could not open socket at /var/run/ntpd-rs/observe: No such file or directory (os error 2), seems like a ntpd-rs bug.
  • the /var/lib/ntpd-rs directory is also empty but that might be ok?

@zyxhere
zyxhere force-pushed the openrc branch 3 times, most recently from 92b7255 to 8062aba Compare October 3, 2026 17:24
@davidv1992

Copy link
Copy Markdown
Member

Thank you for providing this.

To answer some of your questions:
For the observation socket, we are currently in a fairly major migration, and have accepted that currently the main branch is not entirely functional. In particular, observability is in that spot right now where it isn't fully functional. For testing, it may be easier to use the 1.9 version for now.
As to the /var/lib/ntpd-rs folder, we don't currently use that.

@zyxhere

zyxhere commented Oct 9, 2026 via email •

Copy link
Copy Markdown
Author

@davidv1992

Copy link
Copy Markdown
Member

Apologies, forgot we use it to store the cookie keys when running as an NTS server. That is configuration dependent though and will only happen when configured as described in the NTS guide. We include it in the example systemd file to make sure these configurations work out of the box.

As for the observability, which configuration are you testing with? It needs to configure an observability path for the socket to get created.

@zyxhere

zyxhere commented Oct 9, 2026 via email

Copy link
Copy Markdown
Author

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants