TweetFollow Us on Twitter

MacEnterprise: launchd for Lunch

Volume Number: 25
Issue Number: 09
Column Tag: MacEnterprise

MacEnterprise: launchd for Lunch

Recipes for using launchd for systems administration

By Greg Neagle, MacEnterprise.org

Introduction

A few months ago, we looked at how to run administrative scripts - how a systems administrator could run a script at startup, or a schedule, at user login, and more. There are many mechanisms to launch scripts at specific times and under specific conditions, but the one that came up over and over was launchd.

This shouldn't be surprising. Apple introduced launchd with the release of OS X 10.4 Tiger, and their stated goal was to make launchd replace most the other ways of launching processes on OS X. Specifically, launchd was designed to take over tasks from cron, xinetd, mach_init, and init, and to largely replace the StartupItem mechanism.

Recently on the MacEnterprise mailing list there was a discussion about accomplishing a certain task with a login hook. There was a reply that if one could accomplish the task using a launchd LaunchAgent, that would be preferred. Then the floodgates opened. A big discussion ensued about LaunchAgents versus login and logout hooks, launchd jobs as compared to cron jobs, and so on. It was quickly apparent that launchd was still not completely understood or trusted by many Mac OS X systems administrators. More specifically, it became clear there is still a need for concrete examples of how systems administrators can use launchd to replace other launching methods, like cron or a StartupItem, and to do things those launching mechanisms cannot. So in this column, I will present some "launchd recipes" - code snippets you can adapt to use for your own tasks.

Recipe Ingredients

Before we can look at some recipes, let's do a quick review of some of the ingredients we'll be working with.

A key concept is that launchd is just a mechanism to launch processes under certain conditions, and to optionally keep them running even if they unexpectedly exit. Launchd is not a scripting language. To do anything useful with launchd, you must have two ingredients:

A launchd plist. This is a configuration file that tells launchd what to launch, and under which conditions. We'll be looking at several example plists in this month's column.

The actual executable task. This can be a script, or a pre-compiled binary. This is what launchd runs for you when the conditions described in the launchd plist are met.

In most of these recipes, I leave it to you to supply the script. The focus of this column is how to get launchd to execute your script under the right conditions.

If you compare launchd to some of the more traditional methods of running tasks, you'll see the other methods support a more limited set of conditions. For example, the StartupItem mechanism can run a task only at startup. cron can run a task only at a certain time. periodic runs tasks only at certain intervals. xinetd can run a task only when a connection is attempted on a certain network port. Login items are executed when a user logs in. Launchd can run tasks based on all of these conditions, and more.

Launchd plists typically go in one of three locations: /Library/LaunchDaemons, /Library/LaunchAgents, and ~/Library/LaunchAgents. (There are two more directories containing launchd plists - /System/Library/LaunchAgents and /System/Library/LaunchDaemons, but these are reserved for use by Apple.) The launchd plists in /Library/LaunchDaemons are loaded at startup (this does not necessarily mean that the jobs themselves are run at startup, though) and the plists in the two LaunchAgents directories are loaded at user login (or other login-related contexts).

Two more things to know about launchd plists: they must be owned by root, and have permissions 0644. If launchd doesn't like the ownership or permissions of a plist, it will refuse to load it.

Now that we've reviewed the ingredients - on to the recipes!

Recipe 1: Run a script at startup

This is the simplest recipe. We have a script we'd like to run at startup.

Create a plist in /Library/LaunchDaemons with contents similar to these:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN"
      "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
   <key>Label</key>
   <string>org.myorg.startup.scriptname</string>
   <key>ProgramArguments</key>
   <array>
      <string>/path/to/script</string>
      <string>-argument</string>
   </array>
   <key>RunAtLoad</key>
   <true/>
</dict>
</plist>

You can name the plist anything you'd like ending in ".plist,' but the normal convention is to use the same name as the Label, so this plist would be named "org.myorg.startup.scriptname.plist". This launchd plist defines only three keys: Label, ProgramArguments, and RunAtLoad. Label defines a unique name for this launchd job. ProgramArguments contains the path to the command or script, plus any arguments, options, or switches to be passed to the command. If you wanted to remove the Apple Type Services databases at each startup, this command:

atsutil databases -remove

would become this in a launchd plist:

<key>ProgramArguments</key>
<array>
   <string>/usr/bin/atsutil</string>
   <string>databases</string>
   <string>-remove</string>
</array>

Note that this doesn't work:

<key>ProgramArguments</key>
<array>
   <string>/usr/bin/atsutil databases -remove</string>
</array>

The script or command itself and each argument or flag must be in a separate <string> element.

The RunAtLoad key simply tells launchd to run the job as soon as it loads this plist. Since a plist in /Library/LaunchDaemons is loaded at startup, the job is run at startup.

Recipe Variation: Run once at startup, but never again

A common systems administration need is for "run-once" startup scripts - typically these do some sort of configuration and so only need to run once. Unfortunately, launchd plists provide no explicit support for this sort of thing. (The man page for launchd.plist mentions a "LaunchOnlyOnce" key - but this causes a job to be launched only once per boot.) Your options for a job that runs only once are:

Have the script delete the launchd plist after it runs. On the next boot, since the launchd plist no longer exists, the job will not be run again.

Have the script execute

 launchctl unload -w /Library/LaunchDaemons/myjobname.plist 

as the last thing it does. This adds the Disabled key to the launchd plist and sets its value to True, so the job won't load on future reboots unless you remove the Disabled key or set it to False. You must call launchctl unload as the last thing the script does, though, because a side effect of unloading the plist is that the script will be killed as well.

Alternately, you could use a tool like PlistBuddy to write the Disabled key to the plist; this would avoid the issue of killing the process at the same time. Here's a Perl snippet, stolen from /usr/libexec/configureLocalKDC:

my $rerun_plist = '/System/Library/LaunchDaemons/com.apple.configureLocalKDC.plist';
chomp (my $status = qx{/usr/libexec/PlistBuddy -c "Print :Disabled" $rerun_plist});
if ($status ne 'true') {
        system '/usr/libexec/PlistBuddy', '-c', 'Add :Disabled bool True', $rerun_plist;
}

Have the script check for something else to see if it has already run. The script will still run at every startup, but if it finds the existence of a certain file or directory, it exits without doing anything else. An example of something using this strategy is the Setup Assistant that runs when you first install OS X, or when you first startup a new Mac. If the file /var/db/.AppleSetupDone doesn't exist, the Setup Assistant runs on boot. When the Setup Assistant exits, it creates the .AppleSetupDone file, stopping the Setup Assistant from running on future boots. An advantage of this approach is that if you ever need to re-run the script or application for any reason, you can remove the flag file to do so.

Recipe 2: Run a script on a repeating schedule

Cron and periodic are two traditional ways to run jobs on repeating schedules. Periodic is typically used to run a job on a daily, weekly, or monthly schedule. Cron can run a job on virtually any schedule you can imagine - once a minute; every Friday at 3:45pm; every two hours between 8AM and 6PM, Monday through Friday, and more. Cron and periodic are still around in OS X Leopard (and work fine), but launchd can replace most of what they do.

Here's an example of a launchd plist that runs a script every day at 5:15 AM:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN"
"http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>  
   <key>Label</key>
   <string>org.myorg.daily.radmind</string>
   <key>ProgramArguments</key>
   <array> 
      <string>/usr/local/radmind/run_radmind</string>
   </array>
   <key>StartCalendarInterval</key>
   <dict>  
      <key>Hour</key>
      <integer>5</integer>
      <key>Minute</key>
      <integer>15</integer>
   </dict>
</dict>
</plist>

This plist has no RunAtLoad key, since we don't want the script to run at startup. Instead, it has a StartCalendarInterval key, which describes the repeating schedule for the script. StartCalendarInterval is either a single dictionary or an array of dictionaries. Each dictionary can have any combination of the keys Hour, Minute, Day, Weekday, and Month. In this example, the job will run whenever the hour is 5 and the minute is 15. Since the keys Day, Weekday, and Month aren't specified, the job will run every day of every month. The only key that might be non-obvious is Weekday. This takes an integer from 0 to 7, and both 0 and 7 correspond to Sunday.

It's possible to replicate almost all of the scheduling possibilities that cron offers, though the launchd plist version will be much more verbose. You can specify multiple calendar intervals by setting the StartCalendarInterval value to an array of dictionaries, like this:

<key>StartCalendarInterval</key>
<array>
   <dict>
      <key>Hour</key>
      <integer>3</integer>
      <key>Minute</key>
      <integer>15</integer>
   </dict>
   <dict>
      <key>Hour</key>
      <integer>10</integer>
      <key>Minute</key>
      <integer>30</integer>
   </dict>
</array>

This StartCalendarInterval would cause the job to be run at 3:15 AM and 10:30 AM.

The other launchd key that is of interest in scheduling repeating jobs is StartInterval. The value for this key is an integer representing the number of seconds between job runs. The following example causes the job to be run every five minutes:

<key>StartInterval</key>
<integer>300</integer>

Variation: Run a script at startup and on a schedule

If you have a script you'd like to run at startup and also on a regular schedule - for example, a script that uploads asset information about the current machine - you can add both a StartCalendarInterval and a RunAtLoad key to the launchd plist:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN"
"http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>  
   <key>Label</key>
   <string>org.myorg.assetinfoupload</string>
   <key>ProgramArguments</key>
   <array> 
      <string>/usr/local/scripts/asset_info_update</string>
   </array>
   <key>StartCalendarInterval</key>
   <dict>  
      <key>Hour</key>
      <integer>12</integer>
      <key>Minute</key>
      <integer>15</integer>
   </dict>
   <key>RunAtLoad</key>
   <true/>
</dict>
</plist>

Recipe 3: Run a script on filesystem change

Launchd can run a job when a file or directory changes. There are two relevant keys: WatchPaths, which takes an array of strings, each of which is a path to a file or a directory, and QueueDirectories, which also takes an array of strings, but these must point to directories only.

When using WatchPaths, any change to the path triggers the job. In the case of a file, touching the file or changing its contents will cause the launchd job to run. With directories, adding or removing files will start the job.

QueueDirectories are monitored a bit differently. If a QueueDirectory is not empty, your job will be started. If your job quits and the directory is still not empty, your job will be started again. The idea here is a script or program that is started when items appear in a directory, processes each one, and removes each item from the directory as it goes. This acts much like a mail queue or print queue. Prior to launchd, systems administrators would often implement a cron job that ran every minute or so and checked the directory to see if anything had been added. With launchd, you can just let launchd notify you if something appears in the directory.

A WatchPaths example:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Label</key>
  <string>org.myorg.sudoers-check</string>
  <key>ProgramArguments</key>
  <array>
    <string>/usr/bin/logger</string>
    <string>/etc/sudoers was changed!</string>
  </array>
  <key>WatchPaths</key>
  <array>
    <string>/etc/sudoers</string>
  </array>
</dict>
</plist>

This launchd job watches the /etc/sudoers file and writes a message to the log if it changes. If you were really interested in being notified when the sudoers file changed, you'd probably want to use a mechanism that sent email or posted data to a database or via a web CGI.

Recipe 4: Allow a non-admin to run a script as root

Sometimes there is a need to allow a standard user to run a command or script that only works properly when run as root. Building on Recipe 3, we can use launchd to enable this. By default, jobs run by launchd LaunchDaemons run as root. (LaunchAgents are a different matter.) If we set up launchd to run our script when a file changes, and that file is changeable by a standard user, then the user can run the script by changing the file.

This recipe requires some additional ingredients. We need a file that the user can change but not accidentally remove, since launchd's behavior is - shall we say - inconsistent if the WatchPath disappears. One way to do this is to create a directory that is readable by everyone, but writeable only by root:

mkdir /Library/Management/Triggers
sudo chown root /Library/Management/Triggers
sudo chmod 755 /Library/Management/Triggers

Within this directory, create a file to use as the trigger, but make it world-writable:

sudo touch /Library/Management/Triggers/softwareupdate
sudo chmod 666 /Library/Management/Triggers/softwareupdate

Now any user may change the softwareupdate file, but only root can remove it. Our launchd plist can now specify our trigger file as an item in the WatchPaths array:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Label</key>
  <string>org.myorg.softwareupdate</string>
  <key>ProgramArguments</key>
  <array>
    <string>/usr/sbin/softwareupdate</string>
    <string>--install</string>
      <string>--all</string>
  </array>
  <key>WatchPaths</key>
  <array>
    <string>/Library/Management/Triggers/softwareupdate </string>
  </array>
</dict>
</plist>

This launchd plist watches the trigger file. When it changes, it runs:

softwareupdate --install --all

We need one more ingredient - a way for the user to easily modify the file. You could tell the user to open a Terminal window and type "touch /Library/Management/Triggers/softwareupdate", but they'd look at you like you're insane. So let's do something a little more "Mac-like". This could simply be an AppleScript applet that touches the file:

display dialog "Do you want to run Software Update and install all available updates?" buttons {"No", "Yes"} default button "Yes"
if button returned of result is "Yes" then
   do shell script "touch /Library/Management/Triggers/softwareupdate"
end if

When compiled and run the AppleScript presents the dialog in Figure 1.


Figure 1 - A GUI to trigger softwareupdate as root

If the user clicks Yes, the AppleScript touches our trigger file. launchd notices the change, and runs softwareupdate as root.

This example would need a lot more fleshing out before I'd consider deploying it to real users. Instead of directly calling softwareupdate, you'd probably want to write a script that called softwareupdate, provided progress feedback to the user, and handled the case where a restart is needed after updates are installed. The launchd job could then call that script. Still, the basic idea is there: a method to allow a non-privileged user to run a process as root.

Hungry for more recipes?

There are at least a few more things systems administrators might want to do with launchd. Some examples:

Run a script (or an application) when any user logs in.

Run a script when the loginwindow loads.

Run a script when a volume is mounted.

I hope to have some recipes for these and more, and maybe cover some new Snow Leopard features in a future MacEnterprise column. Until then, you can find more info here:

"Getting Started with launchd" - hhttp://developer.apple.com/macosx/launchd.html

"Creating launchd daemons and agents" -

http://developer.apple.com/documentation/MacOSX/Conceptual/BPSystemStartup/Articles/LaunchOnDemandDaemons.html

"Launchd in depth" - http://www.afp548.com/article.php?story=20050620071558293 (This one is a few years old; written when Tiger was new - but has a good example of WatchPaths and a quick introduction to launchctl.)

And of course, read the man pages for launchd, launchd.plist, and launchctl!


Greg Neagle is a member of the steering committee of the Mac OS X Enterprise Project (macenterprise.org) and is a senior systems engineer at a large animation studio. Greg has been working with the Mac since 1984, and with OS X since its release. He can be reached at gregneagle@mac.com.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Visual Studio Code 1.48.0 - Cross-platfo...
Visual Studio Code provides developers with a new choice of developer tool that combines the simplicity and streamlined experience of a code editor with the best of what developers need for their... Read more
DiskCatalogMaker 8.2.1 - Catalog your di...
DiskCatalogMaker is a simple disk management tool which catalogs disks. Simple, light-weight, and fast Finder-like intuitive look and feel Super-fast search algorithm Can compress catalog data for... Read more
Apple iOS 13.6.1 - The latest version of...
iOS 13 sets a new standard for what is already the world’s most advanced mobile operating system. It makes iPhone better than before. It makes iPad more capable than ever. And now it opens up both to... Read more
DEVONthink Pro 3.5.2 - Knowledge base, i...
DEVONthink is DEVONtechnologies' document and information management solution. It supports a large variety of file formats and stores them in a database enhanced by artificial intelligence (AI). Many... Read more
Microsoft Office 365, 2019 16.40 - Popul...
Microsoft Office 365. The essentials to get it all done. Unmistakably Office, designed for Mac Get started quickly with new, modern versions of Word, Excel, PowerPoint, Outlook and OneNote-... Read more
Microsoft Office 2016 16.16.25 - Popular...
Microsoft Office 2016 - Unmistakably Office, designed for Mac. The new versions of Word, Excel, PowerPoint, Outlook, and OneNote provide the best of both worlds for Mac users - the familiar Office... Read more
Wireshark 3.2.6 - Network protocol analy...
Wireshark is one of the world's foremost network protocol analyzers, and is the standard in many parts of the industry. It is the continuation of a project that started in 1998. Hundreds of... Read more
Notion 2.0.8 - A unified workspace for m...
Notion is the unified workspace for modern teams. Notion Features: Integration with Slack Documents Wikis Tasks Version 2.0.8: Note: Free tier has limitations. More info here Bug fixes &... Read more
ClamXAV 3.1 - Virus checker based on Cla...
ClamXAV is a popular virus checker for OS X. Time to take control ClamXAV keeps threats at bay and puts you firmly in charge of your Mac’s security. Scan a specific file or your entire hard drive.... Read more
Dash 5.3.0 - Instant search and offline...
Dash is an API documentation browser and code snippet manager. Dash helps you store snippets of code, as well as instantly search and browse documentation for almost any API you might use (for a full... Read more

Latest Forum Discussions

See All

Everything you need to know about Cataly...
Super Evil Megacorp, the minds behind long-standing mobile MOBA Vainglory, are back with a new game called Catalyst Black. This new title is a team-based shooter that focuses on equippable loot, and although it isn't out yet, the game recently... | Read more »
Robotics! lets you build the battle robo...
Robotics! is the latest release from Zeptolab, the company behind Cut the Rope. It's a creative action game where you'll use a selection of spare parts and weapons to build the battle robot of your dreams. [Read more] | Read more »
Zombie Puzzles Quest is a match-three pu...
Zombies and match-three puzzles are two topics that are often viewed as being fairly overdone in the gaming realm. That doesn't appear to have deterred developer 37Games from combining the two into one game with their latest title Zombie Puzzles... | Read more »
Clash Royale: The Road to Legendary Aren...
Supercell recently celebrated its 10th anniversary and their best title, Clash Royale, is as good as it's ever been. Even for lapsed players, returning to the game is as easy as can be. If you want to join us in picking the game back up, we've put... | Read more »
Scrappers receives a major update that a...
Q-Games' Scrappers has received a fairly sizeable new update that adds fresh gameplay features and a host of quality-of-life tweaks. [Read more] | Read more »
Motorball is a car football game from No...
A few years back Noodlecake Studios announced that they would be dipping in the multiplayer gaming realm with two different games. The first of those, Golf Blitz, released a while back and has proven to be very popular. Now, the second has arrived... | Read more »
SINoALICE's latest update introduce...
SINoALICE's latest update has now arrived, adding several fan-favourite characters from popular RPG series NieR. Young Nier, Kaine, and Young Emil are available in-game as part of a limited-time crossover event set to run until August 20th. [Read... | Read more »
Rocat Jumpurr is an intense roguelite pl...
Rocat Jumpurr is a roguelite platformer from developer Mousetrap Games. You might already be familiar with it if you follow the Big Indie Pitch, where it won first place during this year's Pocket Gamer Connects London competition. Following its... | Read more »
PUBG Mobile's Play As One campaign...
Back in mid-July, we reported that PUGB Mobile had teamed up with Direct Relief to help raise money for the charity's COVID-19 response project. It focused on an in-game running challenge for players, which lead to the PUBG Mobile donating $2... | Read more »
Marvel Contest of Champions' latest...
Marvel Contest of Champions' latest motion comic has arrived, and it shows off new fighters Air-Walker and Dragon Man. Both characters are set to arrive in-game this month. [Read more] | Read more »

Price Scanner via MacPrices.net

Apple restocks clearance, refurbished 2019 13...
Apple has restocked Certified Refurbished 2019 13″ 1.4GHz 4-Core Touch Bar MacBook Pros starting at $979 and up to $440 off original MSRP. Apple’s one-year warranty is included, shipping is free, and... Read more
Apple’s new 2020 27″ 5K iMacs are on sale for...
Apple reseller DataVision has new 2020 27″ 5K iMacs in stock and on sale today for up to $51 off MSRP. DataVision charges sales tax for NY, NJ, MA, PA, MD, TN, MS, and CA residents only. In addition... Read more
Apple’s 3.6GHz 4-core Mac mini on sale for $7...
Apple reseller Expercom has the 2020 3.6GHz 4-core Mac mini on sale for $758.16 shipped. Their price is $41 off Apple’s MSRP, and it’s currently the cheapest price for a new Mac mini from any of the... Read more
Apple Offers Free AirPods For Back To School,...
FEATURE: 08.12.20 – If you’re a student headed for, or back to, college and are in need of new tech to help you with your studies, Apple has some sound advice on one of its products that can provide... Read more
New 2020 27″ 5K iMacs on sale today for $50 o...
Apple reseller Adorama is offering a $50 discount on Apple’s new 2020 27″ 5K iMacs. The following models are in stock and offered at this discount today: – 27″ 3.1GHz 6-core iMac: $1749 $50 off MSRP... Read more
Apple has clearance iPhone 7 models available...
Apple has clearance 32GB iPhone 7 and iPhone 7 Plus models available in their clearance section starting at $349. These iPhone are new, clearance stock and are ‘unlocked, SIM-free, Model A1660.’ At... Read more
Apple drops prices on clearance 27″ 5K iMacs,...
Apple has dropped prices on Certified Refurbished 2019 27″ iMacs to a new low of $1439 and up to $520 off their original MSRP. Apple’s one-year warranty is standard and shipping is free. The... Read more
Price drop: Clearance 8-core iMac Pro for $38...
Apple has dropped their price on Certified Refurbished 27″ 3.2GHz 8-Core iMac Pros to $3819 including free shipping. Their price is $1180 off the original MSRP of new models. A standard Apple one-... Read more
Monday sale: New 13″ 2.0GHz MacBook Pros for...
Amazon has new 2020 13″ 2.0GHz/512GB MacBook Pros back in stock on sale today for $200 off Apple’s MSRP. Shipping is free. Be sure to purchase the MacBook Pro from Amazon, rather than a third-party... Read more
Sale! Apple’s 16″ MacBook Pros for up to $349...
Apple Authorized Reseller Adorama has new 2019 16″ MacBook Pros in stock on sale today for $100-$349 off Apple’s MSRP, each including free shipping. Their prices for 8-core models ($349 off) are the... Read more

Jobs Board

*Apple* Certified Repair Technician - Utah S...
…selected candidate will work in the USU Campus Store Tech Department as an Apple Certified Repair Technician and floor associate. This position is for both summer Read more
*Apple* Certified Macintosh Technician - Exc...
Apple Certified Macintosh Technician Summary Title: Apple Certified Macintosh Technician ID:350 Department:All Location:Falls Church, VA Description Apple Read more
*Apple* Mobility Sales Professional - Best B...
**771364BR** **Job Title:** Apple Mobility Sales Professional **Job Category:** Store Associates **Store Number or Department:** 000809-Riverhead-Store **Job Read more
*Apple* Systems Administrator - Randstad (Un...
Apple Systems Administrator **job details:** + location:Fort Lauderdale, FL + salary:$65,000 - $70,000 per year + date posted:Tuesday, August 11, 2020 + job Read more
Cub Foods - *Apple* Valley - Now Hiring Par...
Cub Foods - Apple Valley - Now Hiring Part Time! United States of America, Minnesota, Apple Valley Retail Post Date Aug 04, 2020 Requisition # 122305 Sign Up for Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.