From cdf2337346b2553c9bbb6553f1002562224bcfe1 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Sat, 29 Aug 2026 13:54:19 +0200 Subject: [PATCH] configure: build sulogin, watchdogd, and libsystemd by default v5.0 ships keventd and the D-Bus support enabled out of the box, but the remaining bundled pieces stayed opt-in, and the help text for two of them already claimed otherwise. Default all three to yes; --without-sulogin, --without-watchdog, and --without-libsystemd opt out. The distcheck and CI configure lines drop the flags they no longer need, so CI exercises the defaults. Signed-off-by: Joachim Wiberg --- .github/workflows/build.yml | 5 ++--- .github/workflows/coverity.yml | 3 +-- .github/workflows/release.yml | 3 +-- Makefile.am | 7 +++---- configure.ac | 10 +++++----- doc/ChangeLog.md | 6 ++++++ doc/build.md | 20 +++++++++++++++----- doc/watchdog.md | 8 ++++---- 8 files changed, 37 insertions(+), 25 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 83607094..ca76a674 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -116,8 +116,7 @@ jobs: - name: Regular Finit run: | ./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \ - --enable-x11-common-plugin --enable-testserv-plugin --with-watchdog \ - --with-keventd \ + --enable-x11-common-plugin --enable-testserv-plugin \ CFLAGS="-fsanitize=address -ggdb" make -j9 clean make -j9 V=1 @@ -173,7 +172,7 @@ jobs: run: | ./autogen.sh ./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \ - --disable-dbus --enable-testserv-plugin --with-keventd + --disable-dbus --enable-testserv-plugin make -j9 V=1 - name: Verify no bus artifacts run: | diff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml index f49b44a0..fc926137 100644 --- a/.github/workflows/coverity.yml +++ b/.github/workflows/coverity.yml @@ -66,8 +66,7 @@ jobs: - name: Configure run: | ./autogen.sh - ./configure --prefix= --enable-x11-common-plugin --with-watchdog \ - --with-keventd --with-libsystemd + ./configure --prefix= --enable-x11-common-plugin - name: Build run: | export PATH=`pwd`/coverity/bin:$PATH diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index cb1a1a24..96283b68 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -46,8 +46,7 @@ jobs: ./autogen.sh ./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc \ --localstatedir=/var --enable-x11-common-plugin \ - --enable-testserv-plugin --with-watchdog \ - --with-keventd --with-libsystemd + --enable-testserv-plugin - name: Enable unprivileged userns (unshare) run: | sudo sysctl kernel.apparmor_restrict_unprivileged_userns=0 diff --git a/Makefile.am b/Makefile.am index 9123fc13..f3b3d31c 100644 --- a/Makefile.am +++ b/Makefile.am @@ -63,7 +63,6 @@ release: distcheck printf "$$file.sha256\t"; cat ../$$file.sha256 | cut -f1 -d' '; \ done -DISTCHECK_CONFIGURE_FLAGS = --prefix=/usr --sysconfdir=/etc --localstatedir=/var \ - --enable-testserv-plugin --enable-x11-common-plugin \ - --with-watchdog --with-keventd --with-fstab=/etc/fstab \ - --with-libsystemd --with-bash-completion-dir=no +DISTCHECK_CONFIGURE_FLAGS = --prefix=/usr --sysconfdir=/etc --localstatedir=/var \ + --enable-testserv-plugin --enable-x11-common-plugin \ + --with-fstab=/etc/fstab --with-bash-completion-dir=no diff --git a/configure.ac b/configure.ac index 7a05a9e5..8305d72d 100644 --- a/configure.ac +++ b/configure.ac @@ -184,15 +184,15 @@ AC_ARG_WITH(udev-rules, AS_HELP_STRING([--without-udev-rules], [Skip install of curated udev rules under /lib/udev/rules.d, default: yes when keventd enabled]),, [with_udev_rules=yes]) AC_ARG_WITH(sulogin, - AS_HELP_STRING([--with-sulogin@<:@=USER@:>@], [Enable built-in sulogin, optional USER to request password for (default root), default: no.]),[sulogin=$withval],[with_sulogin=no]) + AS_HELP_STRING([--with-sulogin@<:@=USER@:>@], [Built-in sulogin, optional USER to request password for, default: yes (root)]),[sulogin=$withval],[with_sulogin=yes sulogin=yes]) AC_ARG_WITH(watchdog, - AS_HELP_STRING([--with-watchdog@<:@=DEV@:>@], [Enable built-in watchdog, default: /dev/watchdog]), - [watchdog=$withval], [with_watchdog=no watchdog=]) + AS_HELP_STRING([--with-watchdog@<:@=DEV@:>@], [Built-in watchdog, default: yes (/dev/watchdog)]), + [watchdog=$withval], [with_watchdog=yes watchdog=yes]) AC_ARG_WITH(libsystemd, - AS_HELP_STRING([--with-libsystemd], [Build replacement libsystemd library, default: yes]), - [with_libsystemd=$withval], [with_libsystemd=no]) + AS_HELP_STRING([--without-libsystemd], [Skip replacement libsystemd library, default: yes]), + [with_libsystemd=$withval], [with_libsystemd=yes]) AC_ARG_WITH(hook-scripts-path, AS_HELP_STRING([--with-hook-scripts-path=DIR], [Base directory for hook scripts, default $libexecdir/finit/hook]), diff --git a/doc/ChangeLog.md b/doc/ChangeLog.md index 215adbac..8b6b2d33 100644 --- a/doc/ChangeLog.md +++ b/doc/ChangeLog.md @@ -69,6 +69,12 @@ All relevant changes are documented in this file. `tmpfiles.d/dbus.conf`, so both can be overridden from `/etc` like any other system file. Those directories are no longer chowned to `messagebus`, matching how Finit ships directories for other daemons +- The bundled `sulogin` and `watchdogd`, and the replacement `libsystemd`, + are now built and installed by default, like keventd and the D-Bus + support. `--without-sulogin`, `--without-watchdog`, and + `--without-libsystemd` opt out. Note, Finit starts `watchdogd` by + itself when the WDT device node exists, and `libsystemd.so` is + installed to `$libdir`, where a system with systemd already has one - The `tty` block takes `passenv`, which the line-based format has had since v4.4 (issue #286) and the block format was missing - New `provides` setting for run/task/service/sysv blocks, naming conditions diff --git a/doc/build.md b/doc/build.md index 309f404c..d843cf08 100644 --- a/doc/build.md +++ b/doc/build.md @@ -79,9 +79,20 @@ Below are a few of the main switches to configure: run mdev, mdevd, or udevd instead. Enabled by default, and the only thing that pulls in libblkid. See [Bundled Device Manager](keventd.md). -* `--with-sulogin`: Enable bundled `sulogin` program. Default is to use the - system `sulogin(8)`. The sulogin shipped with Finit *allows password-less* - login if the `root` user is disabled or has no password at all. +* `--without-sulogin`: Drop the bundled `sulogin`, enabled by default, + and use the system `sulogin(8)` instead. The one shipped with Finit + *allows password-less* login if the `root` user is disabled or has no + password at all. `--with-sulogin=USER` prompts for another user's + password than `root`'s. + +* `--without-watchdog`: Drop the bundled `watchdogd`, enabled by default + on `/dev/watchdog`, `--with-watchdog=DEV` selects another device. + Finit starts it when the device node exists, see [Watchdog](watchdog.md). + +* `--without-libsystemd`: Drop the replacement `libsystemd`, built and + installed by default, which lets programs that use `sd_notify()` talk + to Finit without systemd. Note, it installs `libsystemd.so` in + `$libdir`, where a system with systemd already has one. For more configure flags, see ./configure --help @@ -108,8 +119,7 @@ Then configure, build and install: ```shell $ ./configure --prefix=/usr --exec-prefix= \ - --sysconfdir=/etc --localstatedir=/var \ - --with-keventd --with-watchdog + --sysconfdir=/etc --localstatedir=/var $ make . . diff --git a/doc/watchdog.md b/doc/watchdog.md index f75406b6..afec61e6 100644 --- a/doc/watchdog.md +++ b/doc/watchdog.md @@ -1,10 +1,10 @@ Bundled Watchdog Daemon ======================= -When built `--with-watchdog` a separate service is built and installed -in `/libexec/finit/watchdogd`. If this exists at runtime, and the WDT -device node exists, Finit will start it and treat it as the elected -watchdog service to delegate its reboot to. This delegation is to +A separate service is built and installed in `/libexec/finit/watchdogd`, +unless disabled with `--without-watchdog`. If this exists at runtime, +and the WDT device node exists, Finit will start it and treat it as the +elected watchdog service to delegate its reboot to. This delegation is to ensure that the system is rebooted by a hardware watchdog timer -- on many embedded systems this is crucial to ensure all circuits on the board are properly reset for the next boot, in effect ensuring the