41 Commits
Author SHA1 Message Date
Joachim Wiberg 61b0e0f3e6 Fix #420: run services inside a PAM session
Apply a PAM session to run/task/sysv/services Finit starts, pam_limits
above all, so a service running as a given user picks up that user's
limits the way a login does.

Add a new `pam` setting for the new block format (only), like the
per-service directories, naming a file in /etc/pam.d:

    service weston {
        user    = "weston"
        pam     = "weston-autologin"
        command = "/usr/bin/weston --continue-without-input"
    }

pam_close_session() has to be called by a process still holding the
handle, and the handle does not survive exec().  Hence the keeper: it
holds the handle, drops to the service's credentials, and waits for a
parent-death signal before closing the session.  Same shape as
systemd's (sd-pam), for the same reason, and one per fork, so the
script hooks open and close their own.

The keeper closes the descriptors it inherited from Finit and only
those.  Closing everything would also take out what pam_open_session()
opened for itself, a keyring fd or a lock file, and leave the modules
to close a session with those pulled out from under them.  Closing
nothing, as (sd-pam) does, would leave it holding the write end of the
notify pipe for the service's whole lifetime and starve notify = "s6"
services of their ready signal.  So the fds open before pam_start()
are snapshotted and exactly those are closed, while the ones PAM opens
after are marked close-on-exec so the daemon does not inherit them
either.

A refused value, a denied account stack, an uninstalled pam.d file,
and a build without PAM support all keep the service from starting
rather than running it with the stacks skipped: one that quietly loses
pam_limits and its private /tmp, with nothing said.  Capabilities a
module like pam_cap.so granted are merged into the IAB Finit applies
instead of being replaced by it, which only helps a service that also
sets capabilities, the other arm being a plain setuid() with nothing
left to restore once permitted is empty.

The test sysroot gains pam_permit.so, pam_deny.so and pam_limits.so,
which ldd cannot see, libpam dlopen()s them, and the test skips when
the host has none to stage.  The negative cases pin the exit status
rather than only asserting crashed, which serv reports for any early
exit, so a bad command or an unwritable pidfile cannot pass for a
rejected session.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-09-23 16:30:14 +02:00
Joachim Wiberg a274677f05 configure: keep the replacement libsystemd opt-in
Building it by default installs our libsystemd.so.0 in $libdir.  Where
the real one is already present, and contrib/debian/build.sh configures
--prefix=/usr --exec-prefix= on a Debian host, ours outranks it in the
loader cache, and every program linking libsystemd loses
sd_journal_stream_fd and the LIBSYSTEMD_209 symbol versions.  The test
sysroot ran into exactly that, dbus-daemon exited 127 on every restart.

Restore the default to no.  sulogin and watchdogd stay on, they only add
binaries.  distcheck asks for the library so it stays covered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-29 15:21:29 +02:00
Joachim Wiberg cdf2337346 configure: build sulogin, watchdogd, and libsystemd by default
v5.0 ships keventd and the D-Bus support enabled out of the box, but the
remaining bundled pieces stayed opt-in, and the help text for two of them
already claimed otherwise.

Default all three to yes; --without-sulogin, --without-watchdog, and
--without-libsystemd opt out.  The distcheck and CI configure lines drop
the flags they no longer need, so CI exercises the defaults.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-29 13:54:19 +02:00
Joachim Wiberg 153a1de043 keventd: record the libblkid build requirement
keventd is the only thing in the tree that links libblkid, so a tree
that used to build now stops in configure with no hint of which package
to install.  Say so where people look for dependencies, and give CI the
package it now needs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 22:03:32 +02:00
Joachim Wiberg 3231ade38a dbus: fixes from a code review of the branch
A pass over the whole branch before merge, mostly in libink since
that is the new code and the part exposed to the wire.  Grouped here
rather than scattered so the review is easy to read in one place.

libink parser and dispatch:

 - Bound reader lengths so a 32-bit size_t can't wrap a wire length
   past the guard and read out of bounds.  Reachable pre-auth on any
   bus, so it matters on the 32-bit targets Finit runs on.
 - Drop a peer when a reply send fails instead of limping on with a
   half-written frame; a built-in whose send failed used to fall
   through and put a second frame on the wire.

initctl:

 - Copy a D-Bus error name out of the reply before closing the client;
   the reply points into memory the close frees.  Both error paths now
   share one helper so this can't creep back.

Authorization:

 - Take the caller's groups from the kernel (SO_PEERCRED plus
   SO_PEERGROUPS) rather than getpwuid()/getgrouplist(), which go
   through NSS and can block PID 1 on a slow LDAP or SSSD backend.
   The check is now a lookup against the group resolved once at init,
   with no NSS and no 256 KiB array on the stack.  A caller reaching
   us through a broker carries no group set, so system-bus privileged
   methods are root-only; the local bus keeps group support.  See
   libink/README.md for the note on lifting that.

Shutdown:

 - Call dbus_exit() from the shutdown path so the server, its peers,
   and the socket are let go cleanly.  The teardown existed but nobody
   called it.

Tests, CI, docs:

 - A fuzz target for the message parser, run as a quick sweep in the
   suite and properly under libFuzzer in CI, with the corpus carried
   between runs.  The -as-uid tests drop groups the way a login does
   so SO_PEERGROUPS sees the right set, and widen the test socket to
   reach the per-method check behind the 0660 gate.  Bring the GitHub
   actions up to versions that run on Node 24, and tidy a few small
   things a /simplify pass turned up.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 08:57:38 +02:00
Joachim Wiberg c28acf21a1 test: fuzz target for the message parser
__msg_parse() turns bytes off a socket into pointers, before anything
has vouched for the peer, and it is the only place in libink that
does.  It had no test of its own beyond whatever the other tests
happened to send it, all of it well-formed.

The target checks the parser's contract, not merely that it survived.
A header field must point into the header field array, and terminate
inside it, and the parse must never claim more bytes than it was
handed.  Crash-only would pass a parser that walked into the body and
returned fields from there, since those bytes were handed over too.
The expected bounds are derived from the raw header rather than from
the parser, so the two have to agree independently.

Every input is copied into an allocation sized to it first.  Reading
past the end of a roomy buffer stays inside the allocation and the
sanitizer never sees it; against an exact one the same read is a
fault, which is where the sharpest findings come from.

Under libFuzzer it is an ordinary fuzz target and named files replay,
which is how a find gets reproduced.  With no arguments it runs a
fixed sweep -- every truncation, every single-byte corruption, every
value of the length that decides where the header ends, and seeded
garbage -- so the suite covers the same contract on every build,
without clang or a corpus in the tree.  It takes 40 ms.

CI fuzzes it properly on every pull request, keeps the crashers, and
carries the corpus between runs so it reaches deeper over time than
any single run can.  Note that clang links the fuzzer runtime against
the newest GCC tree it finds, so the libstdc++ headers have to match
that one and not the default compiler, which is worth saying since
installing the obvious package leaves you exactly where you started.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg 2e0b1d6f8b plugin: start a system bus by default
Finit speaks D-Bus itself now and claims org.finit on the system bus
when it finds one, but nothing in a default build ever brings that bus
up.  The plugin that does was opt-in, so the built-in support sat idle
unless the integrator knew to ask for both halves.

Defaulting it on is only reasonable if the result stays the admin's to
change, and a service registered from C through conf_save_service() is
not: it lands in the run path where it cannot be overridden or emptied
out.  So the daemon moves to 20-dbus.conf and its directories to
tmpfiles.d/dbus.conf, the same way hotplug and every other daemon we
ship them for.  The plugin keeps only what has to look at the running
system, the stale pidfile and the machine UUID.

Those directories are no longer chowned to messagebus.  tmpfiles.d
skips a line whose user does not exist rather than falling back, so
the plugin's messagebus/dbus/root ladder has no equivalent there, and
dbus-daemon binds its socket before dropping privileges anyway.

The plugin already bows out where there is no dbus-daemon installed,
so systems that never wanted a bus are unaffected, and
--disable-dbus-plugin is there for those that have one and would still
rather init left it alone.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg 63aabaa6df libink/dbus: identify the caller behind a broker
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it.  Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.

Ask the bus driver instead.  libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else.  Nothing blocks:
blocking in PID 1 is why libuEv exists.  That needs calls libink can
make on a connection it already has, so it gained those too.

Answers are cached, since a bus never reuses a unique name while it
runs.  Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does.  A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.

Privilege is no longer uid 0 alone.  The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot.  Both gates now say the same thing.

Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:06 +02:00
Joachim Wiberg b55dada80b libink: a message bus is not a peer
libink was written against the only bus it had, its own, where the
peer on the other end is the client.  A broker is not: it routes for
senders it names itself, expects a DESTINATION on anything addressed
through it, and answers on its own schedule rather than next.

Runlevels go on the wire as S and N rather than the digits Finit
keeps internally, since that is what a caller outside Finit means by
one.

The library stays a convenience library, linked into finit and
initctl and installed nowhere: the ABI promise waits until libink is
its own project.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:26 +02:00
Joachim Wiberg 4299ce8839 doc: document command candidates and the duplicate title rule
The migration guide covered a stanza at a time, which is the wrong
shape for the two idioms that repeated a whole stanza.  One of them,
several candidate binaries for one service, is now a command list.
The other, one service gated differently per platform, has no block
equivalent: those blocks share an identity because they share the
barrier condition downstream services wait for, so they cannot be
given separate titles.  For that one the guide says to split the
variants across files, or leave that file in the line-based format,
which Finit still reads.

The udevd example in services.md taught the merge-broken form, and
system/10-hotplug.conf.in pointed readers at it for their syslogd.

Also lists libConfuse among the build dependencies.  It has been
mandatory since the new .conf format landed, and build.md still said
two libraries.  And corrects the note on variable expansion: it is
${VAR} that libconfuse expands when the file is read, with
${VAR:-default} supported.  A plain $VAR reaches the service, which is
what makes `command = "syslogd -F $SYSLOGD_ARGS"` work with envfile.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-05 17:57:56 +02:00
Joachim Wiberg b9ad9bcb21 doc: convert the documentation to the block format
The syntax overview no longer describes a line-based format, since that
is not what the rest of the documentation shows.  It now covers the
grammar, the two naming conventions, the nine aliases, and the leading
'-' on a path, and it says plainly that both formats are still read and
told apart per file by content.  Without that, a reader with an
existing configuration is left wondering what happened to it.

service-opts.md was a list of modifiers to place between a directive
and its command, so it needed rewriting rather than translating: there
are no positions left to describe.  It is now grouped by what the
settings do.

conditions.md needed correcting.  It presented '!' as a condition
prefix alongside '~'.  It is neither a condition nor a negation, it is
a flag on the block that means one thing on a service and another on a
run or task, so it is spelled reload-signal and required here, and the
page maps the old form to both.

Two things the pages claimed are not true.  The kill delay range is
1-300, not 1-60, and stop and reload scripts are no longer run without
a timeout.

ChangeLog.md keeps its line-based examples.  Those sit in historical
release entries, and rewriting them in a syntax that did not exist at
the time would misdate the format.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:31 +02:00
Joachim Wiberg b5beb2b8d4 Minor, update URLs and clean up a bit
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:53:56 +01:00
Joachim Wiberg d77773d8ee doc: massive refactor and simplification to migrate to mkdocs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-09 11:50:38 +02:00
Joachim Wiberg 994e51e34f Convert **Note:** et al to GitHub Markdown alerts
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-27 10:23:10 +01:00
Joachim Wiberg ddb42fda70 Fix #289: minor spelling issue in build.md
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-21 22:28:00 +02:00
Joachim Wiberg bf72e6b9c8 Make bundled sulogin optional, use ./configure --with-sulogin
The bundled sulogin could be considered insecure, so leave it up to the
administrator, or system integrator, to decide which sulogin(8) is best
suited.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-03 05:58:57 +02:00
Joachim Wiberg addb8c4019 Fix #247: fall back to reboot -f in sulogin mode
When logged in from sulogin we cannot send IPC to Finit, not even
signals, to delegate reboot.  For usability, attempt to tell reboot that
it's in sulogin mode -- provided the bundled sulogin is used -- to let
reboot trigger over to forced reboot.

We cannot do much about initctl, just document this as a limitation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-25 21:44:33 +02:00
Joachim Wiberg a3ec792b44 doc: minor updates to build script, again
- Mention why configure script is missing from GIT
  - Adjust command line for enabling Finit debug
  - Plus some minor formatting issues

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-12 08:33:50 +02:00
Joachim Wiberg 639fb76f5a doc: update build ref, add "or later" to required libraries
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-11 21:14:35 +02:00
yangfl fa14ed1649 Fix typo
with the love from codespell
2021-06-25 13:08:14 +08:00
Joachim Wiberg 39d879f240 Add support for auto-detetcing OS heading for progress
This patch removes the cognitive overhead of having to manually set your
OS heading, --with-heading="Foo OS vX.YY".  As of this patch, Finit by
default extracts PRETTY_NAME from /etc/os-release.  It is now possible
to also disable the heading entirely using --without-heading

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-06-05 14:28:49 +02:00
Joachim Wiberg cc6ffa35fc Drop parsing of /proc/cmdline by default, instead use argc + argv[]
For most use-cases the kernel will give Finit its arguments as proper
command line args in argc + argv[], like any other program.  However,
for some users, most notably Alpine Linux, there is a slightly broken
initramfs that cannot forward more than one argument using init_args,
for such systems you can re-enable the old behavior with a configure
switch --enable-kernel-cmdline -- it's not ideal but what can you do.

The main reason for removing this feature by default is to support
use-cases where Finit runs as the init for container apps that can read
/proc -- we do not want them to use the init args from the host.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-31 16:51:08 +02:00
Joachim Wiberg 31cdc113fc doc: update build instructions and examples
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-17 00:32:21 +02:00
Joachim Wiberg 7f76202865 Simplify, drop --enable-fallback-shell from configure script
Recommend using `notty` option in tty stanza instead.  See the updated
docs for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-18 23:13:19 +02:00
Joachim Wiberg 3b64b155d4 Update build deps, need libite (-lite) at least v2.2.0 for systemf()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-28 23:17:47 +01:00
Joachim Wiberg 6b1ba37438 doc: bump required versions of libuEv and libite
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-26 10:57:30 +01:00
Joachim Wiberg 10d4964106 Remove last traces of inetd support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-11 21:50:17 +01:00
Joachim Wiberg 1a5aabc034 Update configure examples and build scripts with correct paths
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-08 17:27:05 +01:00
Joachim Wiberg 06fdcf51b9 configure: revert to using GNU defaults, update summary
- Changing the GNU defaults is messy.  The best way is to leave them
  alone and let the user set their install locations themselves.
- Show --exec-prefix in config Summary, that's where the binaries go

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-08 07:58:25 +01:00
Joachim Nilsson 88a6864fd4 Relocate docs/ --> doc/, like most other projects have
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-23 17:53:36 +02:00
Joachim Nilsson 4011b5a3b8 Relocate all docs from doc/* to docs/*, integrates better w/ GitHub
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2018-01-10 02:28:33 +01:00
Joachim Nilsson 205915d42f Document new rescue (recovery) mode
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:58:26 +01:00
Joachim Nilsson 6d1c245985 Update documentation, debug replaces --debug and finit_debug
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-30 21:56:24 +01:00
Joachim Nilsson 85fe95835a doc/build.md: Mention required library versions
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-12-22 13:17:39 +01:00
Joachim Nilsson 510b53e62d Add simple ToC
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-14 16:35:51 +02:00
Joachim Nilsson 23481b197b build.md: Simplify and sectionalize better
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-14 16:34:09 +02:00
Joachim Nilsson 3d5128be77 Remove Emacs Local Variables, not really needed and looks bad
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-10-12 19:01:25 +02:00
Joachim Nilsson 5ed54d79fc Update configure flags
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-09-27 09:27:15 +02:00
Joachim Nilsson bcb9fe039a Move running and debugging to doc/build.md
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-09-27 09:22:04 +02:00
Joachim Nilsson 37d391d53a doc/build.md: Remove mention of --enable-embedded configure option
As suggested in GitHub issue #68.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2017-03-17 16:55:02 +01:00
Joachim Nilsson 72a484b639 Break out building and bootstrap to separate files
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2016-07-23 00:25:14 +02:00