diff --git a/Makefile.am b/Makefile.am index f71de8b0..f4aa4f74 100644 --- a/Makefile.am +++ b/Makefile.am @@ -1,5 +1,5 @@ ACLOCAL_AMFLAGS = -I m4 -SUBDIRS = man plugins src test +SUBDIRS = man plugins src test tmpfiles.d doc_DATA = README.md LICENSE contrib/finit.conf EXTRA_DIST = README.md LICENSE ChangeLog.md contrib/finit.conf diff --git a/README.md b/README.md index 0ee9e402..8755cf1d 100644 --- a/README.md +++ b/README.md @@ -39,6 +39,7 @@ Features include: * Conditions for network/process/custom dependencies * Readiness notification; PID files (native) for synchronizing system startup, support for systemd [sd_notify()][], or [s6 style][] too + * Limited support for [tmpfiles.d(5)][] (no aging, attributes, or subvolumes) * Pre/Post script actions * Tooling to enable/disable services * Built-in getty @@ -700,6 +701,7 @@ and proposed extensions. [sd_notify()]: https://www.freedesktop.org/software/systemd/man/sd_notify.html [s6 style]: https://skarnet.org/software/s6/notifywhenup.html [run-parts(8)]: https://manpages.debian.org/cgi-bin/man.cgi?query=run-parts +[tmpfiles.d(5)]: https://www.freedesktop.org/software/systemd/man/tmpfiles.d.html [original finit]: http://helllabs.org/finit/ [EeePC fastinit]: https://web.archive.org/web/20071208212450/http://wiki.eeeuser.com/boot_process:the_boot_process [Claudio Matsuoka]: https://github.com/cmatsuoka diff --git a/configure.ac b/configure.ac index a5641382..89d12eb7 100644 --- a/configure.ac +++ b/configure.ac @@ -14,6 +14,7 @@ AC_CONFIG_FILES([Makefile man/Makefile plugins/Makefile src/Makefile + tmpfiles.d/Makefile test/test.env test/Makefile test/lib/Makefile test/src/Makefile]) @@ -280,6 +281,10 @@ AC_EXPAND_DIR(plugin_path, "$libdir/finit/plugins") AC_SUBST(plugin_path) AC_DEFINE_UNQUOTED(PLUGIN_PATH, "$plugin_path", [Finit plugin path]) +AC_EXPAND_DIR(tmpfiles_path, "$libdir/tmpfiles.d") +AC_SUBST(tmpfiles_path) +AC_DEFINE_UNQUOTED(TMPFILES_PATH, "$tmpfiles_path", [Main tmpfiles.d/, override in /etc]) + AC_EXPAND_DIR(rescue_conf, "$libdir/finit/rescue.conf") AC_DEFINE_UNQUOTED(RESCUE_CONF, "$rescue_conf", [Finit rescue mode .conf]) AC_EXPAND_DIR(sample_conf, "$libdir/finit/sample.conf") diff --git a/man/finit.8 b/man/finit.8 index fd563e66..99a88439 100644 --- a/man/finit.8 +++ b/man/finit.8 @@ -50,6 +50,10 @@ as reconfiguration at runtime. Natively PID files are used, but systemd .Cm sd_notify() and s6 notification is also supported. .It +Limited support for +.Xr tmpfiles.d 5 , +no aging, attributes, or subvolumes +.It Pre/Post script actions .It Tooling to enable/disable services @@ -268,6 +272,7 @@ Runtime files, including the condition subsystem .Sh SEE ALSO .Xr finit.conf 5 .Xr initctl 8 +.Xr tmpfiles.d 5 .Sh AUTHORS .Nm was conceived and reverse engineered by Claudio Matsuoka. Since v1.0, diff --git a/plugins/bootmisc.c b/plugins/bootmisc.c index 484ebe44..2e084949 100644 --- a/plugins/bootmisc.c +++ b/plugins/bootmisc.c @@ -38,6 +38,7 @@ #include "finit.h" #include "helpers.h" #include "plugin.h" +#include "tmpfiles.h" #include "util.h" #include "utmp-api.h" @@ -158,79 +159,24 @@ static void setup(void *arg) prev = umask(0); - dbg("Setting up FHS structure in /var ..."); - makedir("/var/cache", 0755); - makedir("/var/db", 0755); /* _PATH_VARDB on some systems */ - makedir("/var/games", 0755); - makedir("/var/lib", 0755); - makedir("/var/lib/misc", 0755); /* _PATH_VARDB on some systems */ - makedir("/var/lib/alarm", 0755); - makedir("/var/lib/urandom",0755); - if (fisdir("/run")) { - dbg("System with new /run tmpfs ..."); - if (!fisdir("/run/lock")) - makedir("/run/lock", 01777); - ln("/run/lock", "/var/lock"); - ln("/dev/shm", "/run/shm"); - - /* compat only, should really be set up by OS/dist */ - ln("/run", "/var/run"); - } else { - makedir("/var/lock", 01777); - makedir("/var/run", 0755); - } - makedir("/var/log", 0755); - makedir("/var/mail", 0755); - makedir("/var/opt", 0755); - makedir("/var/spool", 0755); - makedir("/var/spool/cron", 0755); - makedir("/var/tmp", 0755); - makedir("/var/empty", 0755); - /* - * UTMP actually needs multiple db files + * REQUIRED for compatibility with, e.g. _PATH_VARRUN! + * Should be set up by OS/dist, this is a fallback. */ - if (has_utmp()) { - dbg("Setting up necessary UTMP files ..."); - create("/var/run/utmp", 0644, "root", "utmp"); /* Currently logged in */ - create("/var/log/wtmp", 0644, "root", "utmp"); /* Login history */ - create("/var/log/btmp", 0600, "root", "utmp"); /* Failed logins */ - create("/var/log/lastlog", 0644, "root", "utmp"); + if (fismnt("/run")) { + rmdir("/var/run"); + ln("../run", "/var/run"); } - /* Set BOOT_TIME UTMP entry */ - utmp_set_boot(); - - dbg("Setting up misc files ..."); - makedir("/var/run/network",0755); /* Needed by Debian/Ubuntu ifupdown */ - makedir("/var/run/lldpd", 0755); /* Needed by lldpd */ - makedir("/var/run/pluto", 0755); /* Needed by Openswan */ - mksubsys("/var/run/dnsmasq", 0755, "nobody", "nobody"); - mksubsys("/var/run/quagga", 0755, "quagga", "quagga"); - mksubsys("/var/log/quagga", 0755, "quagga", "quagga"); - mksubsys("/var/run/frr", 0755, "frr", "frr"); - mksubsys("/var/log/frr", 0755, "frr", "frr"); - makedir("/var/run/sshd", 01755); /* OpenSSH */ - - if (!fexist("/etc/mtab")) - ln("../proc/self/mounts", "/etc/mtab"); - - /* Void Linux has a uuidd that runs as uuid:uuid and needs /run/uuid */ - mksubsys("/var/run/uuidd", 0755, "uuidd", "uuidd"); - - /* Debian has /run/sudo, ensure correct perms and SELinux label */ - mksubsys("/var/run/sudo", 0711, "root", "root"); - mksubsys("/var/run/sudo/ts", 0700, "root", "root"); - if (whichp("restorecon")) - run("restorecon /var/run/sudo /var/run/sudo/ts", "restorecon"); - - /* XXX: temporary workaround pending new tmpfiles.so plugin */ - mksubsys("/var/cache/nginx", 0755, "www-data", "www-data"); - makedir("/var/run/clixon", 0755); - /* Kernel symlinks, e.g. /proc/self/fd -> /dev/fd */ kernel_links(); + /* Create all system tmpfiles.d(5) */ + tmpfilesd(); + + /* Set BOOT_TIME UTMP entry */ + utmp_set_boot(); + umask(prev); } diff --git a/plugins/x11-common.c b/plugins/x11-common.c index 6af53a8d..f7a03e91 100644 --- a/plugins/x11-common.c +++ b/plugins/x11-common.c @@ -36,39 +36,13 @@ static void setup(void *arg) { - const char *username = "nobody"; - char line[LINE_SIZE]; - mode_t prev; -#ifdef PAM_CONSOLE - int fd; -#endif - if (rescue) { dbg("Skipping %s plugin in rescue mode.", __FILE__); return; } - prev = umask(0); - - makedir("/var/run/console", 01777); - snprintf(line, sizeof(line), "/var/run/console/%s", username); - touch(line); - -#ifdef PAM_CONSOLE - if ((fd = open("/var/run/console/console.lock", O_CREAT|O_WRONLY|O_TRUNC, 0644)) >= 0) { - write(fd, username, strlen(username)); - close(fd); + if (fexist("/var/run/console/console.lock")) run("pam_console_apply", "pam-console"); - } -#endif - - makedir("/tmp/.X11-unix", 01777); - makedir("/tmp/.ICE-unix", 01777); - - if (whichp("restorecon")) - run("restorecon /tmp/.ICE-unix /tmp/.X11-unix", "restorecon"); - - umask(prev); } static plugin_t plugin = { diff --git a/src/Makefile.am b/src/Makefile.am index c947f7b4..e57c3f18 100644 --- a/src/Makefile.am +++ b/src/Makefile.am @@ -59,6 +59,7 @@ finit_SOURCES = api.c cgroup.c cgroup.h \ sig.c sig.h \ sm.c sm.h \ svc.c svc.h \ + tmpfiles.c tmpfiles.h \ tty.c tty.h \ util.c util.h \ utmp-api.c utmp-api.h diff --git a/src/tmpfiles.c b/src/tmpfiles.c new file mode 100644 index 00000000..1e10b122 --- /dev/null +++ b/src/tmpfiles.c @@ -0,0 +1,501 @@ +/* Limited tmpfiles.d implementation + * + * Copyright (c) 2023 Joachim Wiberg + * + * Permission is hereby granted, free of charge, to any person obtaining a copy + * of this software and associated documentation files (the "Software"), to deal + * in the Software without restriction, including without limitation the rights + * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell + * copies of the Software, and to permit persons to whom the Software is + * furnished to do so, subject to the following conditions: + * + * The above copyright notice and this permission notice shall be included in + * all copies or substantial portions of the Software. + * + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN + * THE SOFTWARE. + */ + +#include "config.h" /* Generated by configure script */ + +#include +#include "finit.h" +#include "helpers.h" +#include "tmpfiles.h" +#include "util.h" + +static int glob_do(const char *path, int (*cb)(const char *)) +{ + int rc = 0; + glob_t gl; + + rc = glob(path, GLOB_NOESCAPE, NULL, &gl); + if (rc) { + if (rc == GLOB_NOMATCH) { + errno = ENOENT; + return -1; + } + return 0; + } + + for (size_t i = 0; i < gl.gl_pathc; i++) + rc += cb(gl.gl_pathv[i]); + + return rc; +} + +static int parse_mm(char *arg, int *major, int *minor) +{ + char *ptr; + + if (!arg) { + inval: + errno = EINVAL; + return -1; + } + + ptr = strchr(arg, ':'); + if (!ptr) + goto inval; + + *ptr++ = 0; + *major = atoi(arg); + *minor = atoi(ptr); + + if (!*major || !*minor) + return -1; + + return 0; +} + +static int do_delete(const char *fpath, const struct stat *sb, int tflag, struct FTW *ftw) +{ + if (ftw->level == 0) + return 1; + + if (remove(fpath)) + warn("Failed removing condition %s", fpath); + + return 0; + +} + +static int rmrf(const char *path) +{ + if (!fisdir(path)) + return 0; + + nftw(path, do_delete, 20, FTW_DEPTH); + if (remove(path) && errno != ENOENT) + warn("Failed removing path %s", path); + + return 0; +} + +static void mkparent(char *path, mode_t mode) +{ + mkpath(dirname(strdupa(path)), mode); +} + +static char *write_hex(FILE *fp, char *p) +{ + unsigned char val; + char num[4], *ptr; + int i, len = 0; + + for (i = 0; p[i] && len < 2; i++) { + char c = p[i]; + + if ((c >= '0' && c <= '7') || + (c >= 'a' && c <= 'f') || + (c >= 'A' && c <= 'F')) + num[len++] = c; + else + break; + } + + num[len] = 0; + if (len == 0) { + fputs("x", fp); + return p; + } + + errno = 0; + val = strtoul(num, &ptr, 16); + if (errno || ptr == num) + goto end; + + fputc(val & 0xff, fp); +end: + return &p[i]; +} + +static char *write_num(FILE *fp, char *p) +{ + unsigned char val; + char num[4], *ptr; + int i, len = 0; + + for (i = 0; p[i] && len < 3; i++) { + char c = p[i]; + + if (c >= '0' && c <= '7') + num[len++] = c; + else + break; + } + + num[len] = 0; + if (len == 0) + return p; + + errno = 0; + val = strtoul(num, &ptr, 8); + if (errno || ptr == num) + goto end; + + fputc(val & 0xff, fp); +end: + return &p[i]; +} + +static void write_arg(FILE *fp, char *arg) +{ + char *p; + + if (!arg) + return; + + while (*arg && (p = strchr(arg, '\\'))) { + fwrite(arg, sizeof(char), p - arg, fp); + + *p++ = 0; + switch (*p) { + case '\\': + fputc('\\', fp); + arg = p + 1; + break; + case '\'': + fputc('\'', fp); + arg = p + 1; + break; + case '"': + fputc('"', fp); + arg = p + 1; + break; + case 'a': + fputc('\a', fp); + arg = p + 1; + break; + case 'b': + fputc('\b', fp); + arg = p + 1; + break; + case 'e': + fputc('\e', fp); + arg = p + 1; + break; + case 'n': + fputc('\n', fp); + arg = p + 1; + break; + case 't': + fputc('\t', fp); + arg = p + 1; + break; + case 'x': + arg = write_hex(fp, &p[1]); + break; + case '0' ... '7': + arg = write_num(fp, p); + break; + default: + fputc(*p, fp); + arg = p + 1; + break; + } + } + fputs(arg, fp); +} + +/* + * The configuration format is one line per path, containing type, path, + * mode, ownership, age, and argument fields. The lines are separated by + * newlines, the fields by whitespace: + * + * #Type Path Mode User Group Age Argument… + * d /run/user 0755 root root 10d - + * L /tmp/foobar - - - - /dev/null + * + * https://www.freedesktop.org/software/systemd/man/tmpfiles.d.html + */ +static void tmpfiles(char *line) +{ + char *type, *path, *token, *user, *group, *age, *arg; + char *dst = NULL, *opts = ""; + int major, minor; + int strc, rc = 0; + mode_t mode = 0; + FILE *fp = NULL; + struct stat st; + char buf[1024]; + glob_t gl; + + type = strtok(line, "\t "); + if (!type) + return; + + path = strtok(NULL, "\t "); + if (!path) + return; + if (strchr(path, '%')) { + errx(1, "Path name specifiers unsupported, skipping."); + return; + } + + token = strtok(NULL, "\t "); + if (token) { + errno = 0; + mode = strtoul(token, &arg, 8); + if (errno || arg == token) + mode = 0; + } + + user = strtok(NULL, "\t "); + if (!user || !strcmp(user, "-")) + user = "root"; + group = strtok(NULL, "\t "); + if (!group || !strcmp(group, "-")) + group = "root"; + + age = strtok(NULL, "\t "); + (void)age; /* unused atm. */ + arg = strtok(NULL, "\n"); + + strc = stat(path, &st); + + switch (type[0]) { + case 'b': + rc = parse_mm(arg, &major, &minor); + if (rc) + break; + if (!strc) { + if (type[1] != '+') + break; + erase(path); + } + mkparent(path, 0755); + rc = blkdev(path, mode ?: 0644, major, minor); + break; + case 'c': + rc = parse_mm(arg, &major, &minor); + if (rc) + break; + if (!strc) { + if (type[1] != '+') + break; + erase(path); + } + mkparent(path, 0755); + rc = chardev(path, mode ?: 0644, major, minor); + break; + case 'C': + if (!arg) { + paste(buf, sizeof(buf), "/usr/share/factory", path); + arg = buf; + } + if (!strc) { + struct dirent **namelist; + int num; + + if (!S_ISDIR(st.st_mode)) + break; + num = scandir(path, &namelist, NULL, NULL); + free(namelist); + if (num >= 3) + break; /* not empty */ + } + if (fisdir(arg) && !fisslashdir(arg)) { + size_t len = strlen(arg) + 2; + + dst = malloc(len); + if (!dst) + break; + snprintf(dst, len, "%s/", arg); + arg = dst; + } + mkparent(path, 0755); + rc = rsync(arg, path, LITE_FOPT_KEEP_MTIME, NULL); + if (rc && errno == ENOENT) + rc = 0; + if (dst) + free(dst); + break; + case 'd': + case 'D': + mkparent(path, 0755); + rc = mksubsys(path, mode ?: 0755, user, group); + break; + case 'e': + if (glob(path, GLOB_NOESCAPE, NULL, &gl)) + break; + + for (size_t i = 0; i < gl.gl_pathc; i++) + mksubsys(gl.gl_pathv[i], mode ?: 0755, user, group); + break; + case 'f': + case 'F': + mkparent(path, 0755); + if (type[1] == '+' || type[0] == 'F') { + /* f+/F will create or truncate the file */ + if (!arg) { + rc = create(path, mode ?: 0644, user, group); + break; + } + fp = fopen(path, "w+"); + } else { + /* f will create the file if it doesn't exist */ + if (strc) + fp = fopen(path, "w"); + } + + if (fp) { + write_arg(fp, arg); + rc = fclose(fp); + } + break; + case 'L': + if (!strc) { + if (type[1] != '+') + break; + erase(path); + } + mkparent(path, 0755); + if (!arg) { + paste(buf, sizeof(buf), "/usr/share/factory", path); + arg = buf; + } + rc = ln(arg, path); + if (rc && errno == EEXIST) + rc = 0; + break; + case 'p': + if (!strc) { + if (type[1] != '+') + break; + erase(path); + } + mkparent(path, 0755); + rc = mkfifo(path, mode ?: 0644); + break; + case 'r': + rc = glob_do(path, erase); + if (rc && errno == ENOENT) + rc = 0; + break; + case 'R': + rc = glob_do(path, rmrf); + break; + case 'w': + if (!arg) + break; + + if (glob(path, GLOB_NOESCAPE, NULL, &gl)) + break; + + for (size_t i = 0; i < gl.gl_pathc; i++) { + fp = fopen(gl.gl_pathv[i], type[1] == '+' ? "a" : "w"); + if (fp) { + write_arg(fp, arg); + rc = fclose(fp); + } + } + break; + case 'Z': + opts = "-R"; + /* fallthrough */ + case 'z': + if (!whichp("restorecon")) + break; + if (glob(path, GLOB_NOESCAPE, NULL, &gl)) + break; + + for (size_t i = 0; i < gl.gl_pathc; i++) { + snprintf(buf, sizeof(buf), "restorecon %s %s", opts, gl.gl_pathv[i]); + run(buf, "restorecon"); + } + break; + default: + errx(1, "Unsupported tmpfiles command '%s'", type); + return; + } + + if (rc) + warn("Failed %s operation on path %s", type, path); +} + +void tmpfilesd(void) +{ + /* in priority order */ + char *dir[] = { + TMPFILES_PATH "/*.conf", /* Finit specific, not in tmpfiles.d(5) */ + "/usr/lib/tmpfiles.d/*.conf", + "/run/tmpfiles.d/*.conf", + "/etc/tmpfiles.d/*.conf", /* local admin overrides */ + }; + int flags = GLOB_NOESCAPE; + glob_t gl; + size_t i; + + for (i = 0; i < NELEMS(dir); i++) { + glob(dir[i], flags, NULL, &gl); + flags |= GLOB_APPEND; + } + + for (i = 0; i < gl.gl_pathc; i++) { + char *fn = gl.gl_pathv[i]; + size_t j; + FILE *fp; + + /* check for overrides */ + for (j = i + 1; j < gl.gl_pathc; j++) { + if (strcmp(basename(fn), basename(gl.gl_pathv[j]))) + continue; + fn = NULL; + break; + } + + if (!fn) + continue; /* skip, override exists */ + + fp = fopen(fn, "r"); + if (!fp) + continue; + + while (!feof(fp)) { + char *line; + + line = fparseln(fp, NULL, NULL, NULL, FPARSELN_UNESCCOMM); + if (!line) + continue; + + tmpfiles(line); + } + + fclose(fp); + } + + globfree(&gl); +} + +/** + * Local Variables: + * indent-tabs-mode: t + * c-file-style: "linux" + * End: + */ diff --git a/src/tmpfiles.h b/src/tmpfiles.h new file mode 100644 index 00000000..e23faf5e --- /dev/null +++ b/src/tmpfiles.h @@ -0,0 +1,42 @@ +/* Limited tmpfiles.d implementation + * + * Copyright (c) 2023 Joachim Wiberg + * + * Permission is hereby granted, free of charge, to any person obtaining a copy + * of this software and associated documentation files (the "Software"), to deal + * in the Software without restriction, including without limitation the rights + * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell + * copies of the Software, and to permit persons to whom the Software is + * furnished to do so, subject to the following conditions: + * + * The above copyright notice and this permission notice shall be included in + * all copies or substantial portions of the Software. + * + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN + * THE SOFTWARE. + */ + +#ifndef TMPFILES_H_ +#define TMPFILES_H_ + +#include +#include +#include +#include + +#include +#include +#ifdef _LIBITE_LITE +# include +#else +# include +#endif + +void tmpfilesd(void); + +#endif /* TMPFILES_H_ */ diff --git a/tmpfiles.d/.gitignore b/tmpfiles.d/.gitignore new file mode 100644 index 00000000..282522db --- /dev/null +++ b/tmpfiles.d/.gitignore @@ -0,0 +1,2 @@ +Makefile +Makefile.in diff --git a/tmpfiles.d/Makefile.am b/tmpfiles.d/Makefile.am new file mode 100644 index 00000000..bb6487c3 --- /dev/null +++ b/tmpfiles.d/Makefile.am @@ -0,0 +1,4 @@ +tmpfilesdir = $(tmpfiles_path) +dist_tmpfiles_DATA = etc.conf legacy.conf var.conf x11.conf +dist_tmpfiles_DATA += dnsmasq.conf frr.conf lldpd.conf openswan.conf \ + quagga.conf sshd.conf uuidd.conf diff --git a/tmpfiles.d/dnsmasq.conf b/tmpfiles.d/dnsmasq.conf new file mode 100644 index 00000000..3e0e0be8 --- /dev/null +++ b/tmpfiles.d/dnsmasq.conf @@ -0,0 +1 @@ +d /var/run/dnsmasq 0755 nobody nobody - diff --git a/tmpfiles.d/etc.conf b/tmpfiles.d/etc.conf new file mode 100644 index 00000000..d094bdc3 --- /dev/null +++ b/tmpfiles.d/etc.conf @@ -0,0 +1,7 @@ +L /etc/os-release - - - - ../usr/lib/os-release +L+ /etc/mtab - - - - ../proc/self/mounts +C! /etc/locale.conf - - - - +C! /etc/nsswitch.conf - - - - +C! /etc/vconsole.conf - - - - +C! /etc/pam.d - - - - +C! /etc/issue - - - - diff --git a/tmpfiles.d/frr.conf b/tmpfiles.d/frr.conf new file mode 100644 index 00000000..9fad6c6c --- /dev/null +++ b/tmpfiles.d/frr.conf @@ -0,0 +1,2 @@ +d /var/run/frr 0755 frr frr - +d /var/log/frr 0755 frr frr - diff --git a/tmpfiles.d/legacy.conf b/tmpfiles.d/legacy.conf new file mode 100644 index 00000000..1f8040fe --- /dev/null +++ b/tmpfiles.d/legacy.conf @@ -0,0 +1,11 @@ +d /run/lock 0755 root root - +L /var/lock - - - - ../run/lock + +d /run/lock/subsys 0755 root root - + +L /run/shm - - - - ../dev/shm + +# These are not supported by Finit, see command line options +r! /forcefsck +r! /fastboot +r! /forcequotacheck diff --git a/tmpfiles.d/lldpd.conf b/tmpfiles.d/lldpd.conf new file mode 100644 index 00000000..9d87f04b --- /dev/null +++ b/tmpfiles.d/lldpd.conf @@ -0,0 +1 @@ +d /var/run/lldpd 0755 - - - diff --git a/tmpfiles.d/openswan.conf b/tmpfiles.d/openswan.conf new file mode 100644 index 00000000..1733f7b8 --- /dev/null +++ b/tmpfiles.d/openswan.conf @@ -0,0 +1 @@ +d /var/run/pluto 0755 - - - diff --git a/tmpfiles.d/quagga.conf b/tmpfiles.d/quagga.conf new file mode 100644 index 00000000..d8276cf2 --- /dev/null +++ b/tmpfiles.d/quagga.conf @@ -0,0 +1,2 @@ +d /var/run/quagga 0755 quagga quagga - +d /var/log/quagga 0755 quagga quagga - diff --git a/tmpfiles.d/sshd.conf b/tmpfiles.d/sshd.conf new file mode 100644 index 00000000..b6033274 --- /dev/null +++ b/tmpfiles.d/sshd.conf @@ -0,0 +1 @@ +d /var/run/sshd 01755 - - - diff --git a/tmpfiles.d/uuidd.conf b/tmpfiles.d/uuidd.conf new file mode 100644 index 00000000..dc04f0a2 --- /dev/null +++ b/tmpfiles.d/uuidd.conf @@ -0,0 +1,2 @@ +# Void Linux uuidd +d /var/run/uuidd 0755 uuidd uuidd diff --git a/tmpfiles.d/var.conf b/tmpfiles.d/var.conf new file mode 100644 index 00000000..a6184765 --- /dev/null +++ b/tmpfiles.d/var.conf @@ -0,0 +1,40 @@ +# Standard FHS 2.3 structure in /var and /var/run, err /run + +d /var/cache 0755 - - - +d /var/db 0755 - - - +d /var/games 0755 - - - +d /var/lib 0755 - - - +d /var/lib/alarm 0755 - - - +d /var/lib/misc 0755 - - - +d /var/lib/urandom 0755 - - - +d /var/spool 0755 - - - + +# Compat symlink to new /run ramdisk +L /var/run - - - - ../run + +# Used by pam_console(8) +d /run/console 1777 - - - +f /run/console/nobody 0644 - - - +f /run/console/console.lock 0644 - - - nobody + +# Needed by Debian/Ubuntu ifupdown +d /var/run/network 0755 - - - + +# Debian has /run/sudo, ensure correct perms and SELinux label +d /run/sudo 0711 root root +d /run/sudo/ts 0700 root root +Z /run/sudo - - - - + +d /var/empty 0755 - - - +d /var/log 0755 - - - +d /var/mail 0755 - - - +d /var/opt 0755 - - - +d /var/spool 0755 - - - +d /var/spool/cron 0755 - - - + +# UTMP actually needs multiple db files +f /var/run/utmp 0664 root utmp - +f /var/log/wtmp 0664 root utmp - +f /var/log/btmp 0660 root utmp - +f /var/log/lastlog 0664 root utmp - + diff --git a/tmpfiles.d/x11.conf b/tmpfiles.d/x11.conf new file mode 100644 index 00000000..a7afc58e --- /dev/null +++ b/tmpfiles.d/x11.conf @@ -0,0 +1,11 @@ +D! /tmp/.X11-unix 1777 root root +D! /tmp/.ICE-unix 1777 root root +D! /tmp/.XIM-unix 1777 root root +D! /tmp/.font-unix 1777 root root + +z /tmp/.X11-unix +z /tmp/.ICE-unix +z /tmp/.XIM-unix +z /tmp/.font-unix + +r! /tmp/.X[0-9]*-lock