33 Commits
Author SHA1 Message Date
Aaron Andersen 7110ae4427 libsystemd: guard sd-daemon.h with extern C for c++ consumers 2026-08-21 16:08:15 -04:00
Aaron Andersen a7ee24662f docs: cleanup some development work 2026-08-19 21:00:48 -04:00
Aaron Andersen 287a385e63 cond: fixup path buffer size to fit the longest condition name
cond_path() and cond_checkpath() built the /run/finit/cond/ path in a
MAX_ARG_LEN buffer, so condition names longer than ~40 chars were
truncated.
2026-08-05 18:51:27 -04:00
Aaron Andersen ad76e15949 tmpfiles.d: update /var/tmp mode
`/var/tmp` mode should match `/tmp`
2026-04-18 09:17:10 +09:00
Aaron Andersen c058b3f9ce plugins/plymouth.c: fixup email address 2026-04-14 09:03:19 +09:00
Aaron Andersen 1518eb9466 Add Plymouth boot splash plugin
Manage the plymouthd lifecycle across boot, switch_root, and shutdown.
Activated by the "splash" kernel command line argument.
2026-03-20 09:18:18 -04:00
Aaron Andersen 98ec30d308 tmpfiles: add --exclude-prefix and -E flags
Add support for the --exclude-prefix=PATH option to skip rules whose
path starts with the specified prefix.  The option can be specified
multiple times to exclude multiple path prefixes.

The -E flag is a shortcut for:

    --exclude-prefix=/dev --exclude-prefix=/proc \
    --exclude-prefix=/run --exclude-prefix=/sys

This is useful to avoid creating files below virtual or memory-backed
file system mount points.
2026-02-23 15:39:44 +00:00
Aaron Andersen 5f7e8457af Add remain:yes option for run/task oneshot commands
Similar to systemd's RemainAfterExit=yes.  Prevents the task from
re-running on runlevel re-entry and ensures the post: script runs
when explicitly stopped or when leaving valid runlevels.

Useful for tasks that set up persistent state like firewall rules:

    task [2345] remain:yes \
         post:/usr/sbin/teardown-firewall \
         /usr/sbin/setup-firewall -- Firewall setup

Not supported for bootstrap-only tasks (runlevel S only) since these
are deleted immediately after completion.
2026-02-05 22:08:22 -05:00
Aaron Andersen 39044adcf8 Create mount points in fs_init() if they don't exist
In containerized or virtualized environments, standard mount point
directories may not exist at boot.  Ensure they are created before
attempting to mount.
2026-01-19 15:20:43 -05:00
Aaron Andersen c9fd4418e7 tmpfiles: fix f/F to apply ownership when writing content
When f or F types write content to a file, the mode and ownership
specified in the config should be applied. Previously, ownership was
only applied when create() was used (i.e., when no argument was
specified).

Now we explicitly apply mode and ownership after writing content to
the file.
2026-01-18 18:59:20 -05:00
Aaron Andersen 7206f745a2 tmpfiles: fix 'e' type to only adjust existing directories
According to tmpfiles.d(5), the 'e' type adjusts the mode and ownership
of existing paths but should not create them. Previously, mksubsys()
was used which could create directories.

Now we explicitly check if the path is an existing directory before
adjusting its permissions.
2026-01-18 18:59:20 -05:00
Aaron Andersen 25bcde12d4 tmpfiles: add support for numeric uid/gid in config files
Add parse_uid() and parse_gid() helper functions that support both
numeric IDs and name lookups. Update the d/D directory creation
handlers to use these new functions.

This allows config files to specify ownership using numeric UIDs and
GIDs instead of only usernames and group names, matching systemd-tmpfiles
behavior.
2026-01-18 18:59:20 -05:00
Aaron Andersen 7459ede806 tmpfiles: fix L+ to replace non-directory entries
The L+ type should replace existing entries with a symlink. Previously,
rmrf() was always called which is only appropriate for directories.
Now we check if the path is a directory first, and use erase() for
files and symlinks.
2026-01-18 18:59:20 -05:00
Aaron Andersen 6bf35513c3 tmpfiles: add support for config files on command line
Allow specifying one or more configuration files as command line
arguments instead of always processing all files in the standard
tmpfiles.d directories.

This enables targeted operations on specific config files:

    tmpfiles --create /etc/tmpfiles.d/myapp.conf
    tmpfiles --clean /tmp/test.conf /tmp/other.conf

When no config files are specified, the existing behavior of
processing all *.conf files in the standard directories is preserved.

Also refactors file processing into a helper function to reduce
code duplication.
2026-01-18 18:59:20 -05:00
Aaron Andersen 0b8d39329a tmpfiles: add --clean flag for age-based cleanup
Add support for the --clean (-C) flag to remove files and directories
older than the age specified in tmpfiles.d configuration entries.

The age field (6th column) in tmpfiles.d entries can now be used with
'd', 'D', and 'e' type entries to clean up old files.  Supported time
suffixes are: s (seconds), m (minutes), h (hours), d (days), w (weeks).

Example configuration:
    d /tmp/cache 0755 root root 10d

When run with --clean, files in /tmp/cache older than 10 days will be
removed.  The directory itself is preserved.

Uses a conservative cleanup approach matching systemd-tmpfiles:
 - Files: kept if ANY of atime, ctime, mtime is recent
 - Directories: kept if ANY of atime, mtime is recent (ctime excluded
   because cleanup itself updates directory ctime)

A value of "-" or "0" for age disables cleanup for that entry.

Note: x/X exclusion patterns are recognized but not yet implemented.
2026-01-18 18:59:20 -05:00
Aaron Andersen 84098dd8b7 tmpfiles: rename flags for clarity
Rename the command-line flag variables to be more descriptive:

  c_flag -> create_flag
  r_flag -> remove_flag

This improves code readability.
2026-01-18 18:59:20 -05:00
Aaron Andersen 29029bb78f netlink: enumerate existing interfaces at startup
The netlink plugin only receives RTM_NEWLINK events for interfaces that
appear after the plugin starts.  Interfaces that already exist at boot
(e.g., virtio-net in QEMU) never generate events, so their conditions
like net/eth0/exist were never set.

Moving enumeration to PLUGIN_INIT doesn't work because it runs before
cond_init(), so the condition filesystem isn't ready yet.

Fix by registering an HOOK_SVC_PLUGIN callback that queries existing
interfaces and routes.  This hook runs during conf_init(), after the
condition system is initialized.
2026-01-14 15:58:22 -05:00
Aaron Andersen abaad560f0 Set USER and LOGNAME environment variables when dropping privileges
When a service is configured to run as a non-root user (@user), finit
correctly drops privileges via setuid() and sets HOME and PATH, but
does not set the USER and LOGNAME environment variables. They remain
set to "root" from boot time.

This causes problems for software that determines its identity from
the environment rather than getuid(). For example, rootless Podman
checks os.Getenv("USER") first when looking up subordinate UID/GID
ranges in /etc/subuid and /etc/subgid.

With USER=root but UID=1000, Podman looks up root's subuid entry
instead of the actual user's, causing applications like newuidmap
to fail. Setting USER and LOGNAME to match the actual user identity
follows POSIX conventions and matches the behavior of su, sudo, and
login.
2026-01-10 21:36:58 -05:00
Aaron Andersen 8e7d1b7bb5 Refactor: drop do_ prefix from iterate_proc() and switch_root()
The do_ prefix is conventionally reserved for local helper functions.
Move switch_root() declaration to private.h alongside iterate_proc()
and remove the now-empty initramfs.h header.
2026-01-02 18:13:00 -05:00
Aaron Andersen 373738f3d1 Implement switch_root functionality allowing Finit to serve as the init
in an initramfs, then transition to the real root filesystem.  Useful
for systems requiring early boot tasks like LUKS unlock, LVM activation,
or network boot before mounting the real root.

Adds INIT_CMD_SWITCH_ROOT API command, `initctl switch-root` subcommand,
and HOOK_SWITCH_ROOT plugin hook point.  The implementation gracefully
stops services, moves virtual filesystems (/dev, /proc, /sys, /run) to
the new root, deletes initramfs contents to free memory, then execs the
new init as PID 1.

See GitHub Discussion #292 for background.
2026-01-01 19:10:24 -05:00
Aaron Andersen e6d3eb2526 Handle already-mounted cgroups in cgroup_init()
Add handling for EBUSY when mounting cgroup2 filesystem, which occurs
when cgroups are already mounted. This can happen after switch_root
when cgroups were moved from the initramfs, or in container environments.

Verify the existing mount is actually cgroup2 before proceeding, and
track whether we mounted to avoid unmounting on error if we didn't.
2026-01-01 16:02:36 -05:00
Aaron Andersen b46592e818 Add support for supplementary groups
Implement supplementary group support for services, allowing them to
access resources owned by multiple groups. Uses the @user:group,sup1,sup2
syntax to explicitly specify supplementary groups, in addition to now
reading group membership from /etc/group.
2025-12-24 09:54:37 -05:00
Aaron Andersen be2a0ec3e7 Add support for Linux capabilities
Implement Linux capability support for services, allowing them to run
with minimal required privileges instead of running as root. This uses
the modern IAB (Inheritable, Ambient, Bounding) API from libcap.
2025-11-30 11:36:53 -05:00
Aaron Andersen 0459bb432a service.c/parse_cmdline_args: handle loooooong arguments 2025-07-01 20:31:59 -04:00
Aaron Andersen 5993b4bb5d tmpfiles: refactor code into new is_dir_empty function
The existing implementation seemed useful enough to warrant a new
helper function. Care was taken to ensure the revised code no longer
suffers any memory leaks.
2025-06-05 20:53:25 -04:00
Aaron Andersen 2957246092 tmpfiles: implement remove logic for 'D'
> D
> Similar to d, but in addition the contents of the directory will be removed when --remove is used.
2025-06-02 19:27:24 -04:00
Aaron Andersen a5710125f6 tmpfiles: add --create and --remove flags
Allow execution of tmpfiles to specify which mode(s) of operation to run in.
2025-06-02 19:27:24 -04:00
Aaron Andersen ff95ebeb91 tmpfiles: split up create & remove logic
The tmpfiles.d spec contains entry types that should be acted upon in different modes
of operation: create, clean, remove, and purge - split up create & remove logic to
clarify the modes of operation finit supports.
2025-06-02 19:27:24 -04:00
Aaron Andersen 1921b3f2c5 tmpfiles: refactor into separate executable
The tmpfiles.d spec has proven useful in systemd, enough so that some developers
are starting to ship tmpfiles.d configuration files with their software.
By splitting the tmpfiles functionality in finit out into a separate executable
we are providing a useful piece of software that package managers can hook into.
2025-06-02 19:27:24 -04:00
Aaron Andersen fa13cddc28 improve notify:s6 compatibility 2025-03-29 08:03:43 -04:00
Aaron Andersen 02e0aa7383 fixup: links in config.md 2025-03-22 18:06:05 +00:00
Aaron Andersen 0d742d6ae8 allow sysctl path to be configured at build time 2025-02-19 15:31:09 -05:00
Aaron Andersen 048302f06a add systemd-nspawn to the list of container types 2025-02-02 08:58:36 -05:00