35 Commits
Author SHA1 Message Date
Joachim Wiberg 847f4db974 dbus: install the bus policy in $datadir/dbus-1/system.d
make distcheck fails in install:

    /usr/bin/install: cannot create regular file '/etc/dbus-1/system.d/org.finit.conf': Permission denied

The policy was installed to $sysconfdir/dbus-1/system.d.  distcheck only
overrides the prefix, so the file escaped its sandbox and aimed for the
real /etc.

Install it where dbus looks for package owned policy, leaving
/etc/dbus-1/system.d to the admin.  The test bus config reads it
relative to itself.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-29 13:54:14 +02:00
Joachim Wiberg e5040385f5 test: fix flaky crashing.sh
Two races, both around the post:script Finit runs when it gives up on a
service.

Finit marks the service crashed before it forks post:script, so the file
the test greps for lands a moment later.  Waiting for the state is not
enough.

slay then takes the PID from initctl status, and service_post_script()
sets svc->pid to the script's PID, so once Finit has given up the PID
reported for the service is the post:script.  Killing that takes out the
script instead of the service and the file never arrives at all.  The
guard for this was already there, with a comment describing it, but
inside the loop that waits for a PID to appear, so it only covered the
case where there was none.  A PID that was already there went straight
to kill -9.  Hence the gcc leg killing once more at lap 13, after Finit
had stopped restarting, where clang stopped at 12.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-22 10:25:28 +02:00
Joachim Wiberg 8138b402a0 test: don't slay a service Finit has given up on
Once it gives up it forks the post:script and reports that PID as the
service's, so a slay still waiting for the service to come back killed
the script instead, and crashing.sh lost the /tmp/post it checks for.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 22:03:36 +02:00
Joachim Wiberg 127049d925 test: Finit against a real dbus-daemon
The other dbus-*.sh tests drive libink's own client, so the wire format
was only ever checked against the implementation that wrote it, and the
broker path had no coverage at all.  Every bug found in it so far was
found by hand on a target.

Let the dbus plugin bring up a real dbus-daemon, wait for Finit to
claim org.finit, then talk to Finit with dbus-send, which shares no
code with us.  The privileged call is the interesting one: it can only
be answered by parking the call and asking the broker who sent it.
The bus reads the policy Finit installs, so a malformed org.finit.conf
fails here rather than on a target.

Tests no longer build --with-libsystemd.  Our replacement carries the
real soname but only the sd_notify() symbols, so in the test root it
shadowed the libsystemd the host's libdbus-1 wants and dbus-daemon
died on a missing sd_is_socket.  Nothing under test needs the shared
library: serv is the only consumer and it compiles sd-daemon.c
straight in, which it now does regardless of the flag so notify.sh
keeps testing notify:systemd either way.

Staged from the host by lib/sysroot.mk like any other binary, and
skipped when the host has neither program.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg 63aabaa6df libink/dbus: identify the caller behind a broker
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it.  Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.

Ask the bus driver instead.  libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else.  Nothing blocks:
blocking in PID 1 is why libuEv exists.  That needs calls libink can
make on a connection it already has, so it gained those too.

Answers are cached, since a bus never reuses a unique name while it
runs.  Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does.  A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.

Privilege is no longer uid 0 alone.  The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot.  Both gates now say the same thing.

Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:06 +02:00
Joachim Wiberg 0b182c063e test: Extend depserv test with per-service reload, fix slay race
Verify that 'initctl reload foo' properly triggers dependent
services by checking that bar gets a new PID after the reload.
Also change the second test case from service/foo/running to
service/foo/ready which is the actual condition set by pidfile.so.

Fix a race in slay where the target process could exit between
the PID lookup and kill -9, causing spurious test failures in
tight kill loops (e.g., start-kill-service.sh).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-02-10 16:00:57 +01:00
Joachim Wiberg 329f11b4da test: add barebones /etc/{passwd,group} and an ld.so.conf
Finit now requires being able to query at least for the root user and
group before starting any services.

Also, add support for using libraries installed in /usr/local

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 09:45:06 +01:00
Joachim Wiberg e49763d834 test: extend start-stop-sysv to verify reload:script support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 12:05:58 +02:00
Joachim Wiberg bbc83eaa64 test: new test
New test adds /bin/fail.sh to verify that a failing pre:script (that
also takes too long to run) is detected: exit code and timeout.

Ensure existing test pass full path to /sbin/fail.sh script.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-11 10:17:33 +01:00
Joachim Wiberg 5913217808 test: add finit.d/available and finit.d/enabled/ dirs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-23 08:17:03 +01:00
Joachim Wiberg 60bf858302 test: extend svc-env.sh with more common use-case
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 08:37:05 +01:00
Joachim Wiberg 50e587f447 test: new test, verify env:file variable expansion
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 13:31:36 +01:00
Joachim Wiberg 6ae1083c99 Add support for SysV-only scripts in runparts
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.

Additionally, by default `runparts` now runs entirely in the background
without any progress.  To enable progress, an optional argument has been
added to the runparts command line.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 13:25:35 +02:00
Joachim Wiberg efed0db16b test: reindent, don't warn on PID 0
PID 0 for a collected task is not a bug, 1 or < 0 is a bug.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-16 10:28:48 +02:00
Joachim Wiberg 924ec2ef80 test: add missing runlevel/ref.log
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 21:18:28 +02:00
Joachim Wiberg b41b4ce989 test: new, verify runparts order
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 14:04:26 +02:00
Joachim Wiberg 13dddb6912 test: new regression test for issue #351
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-21 11:24:17 +01:00
Joachim Wiberg 91540fd793 Issue #351: unable to reproduce
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-05 10:48:45 +01:00
Joachim Wiberg 2eb3ebb404 test: /var a tmpfs to prevent tests from trampling on each other
Multiple parallel tests writing to the same /var leads to quite
unexpected results.  Let's start fresh in each test instead.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg 4f7e726a3e test: initial regression test for #351 (WIP)
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-11 16:48:21 +01:00
Joachim Wiberg bd25bf65ce test: ensure /run is a unique ramdisk for each test instance
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-11 21:54:01 +01:00
Joachim Wiberg a7e81f45c6 test: slay must cache oldpid to an instance specific ramdisk
Running tests in massive parallel causes failing startk-kill-service.sh.
This in turn was caused by the shared test tool 'slay' that cached its
"oldpid" file to a shared area of the rootfs (tenv-root).  It must use a
test instance-specific ramdisk.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-11 12:38:14 +01:00
Joachim Wiberg d5f542dcca test: slay must wait up to five seconds before giving up
Default max delay before restarting a crashing service is five seconds.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-06 13:54:55 +01:00
Joachim Wiberg fb86042cb3 test: add crashing.sh, verify oncrash:script support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-06 13:07:10 +01:00
Joachim Wiberg c9f1bff419 Refactor ready:script to support new notify framework
Follow-up to abcb3ce, calling the service ready:script when readiness
has been signaled to or detected by Finit.

Issue #300

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 22:11:12 +02:00
Joachim Wiberg 165d0633f6 test: add support for make -j17 check massive parallel testing
This was a tough nut to crack.  Spent 3-4 calendar weeks (getting blurry
now) to try and figure it all out.  In the end, the following changes
were necessary:

 - Ensure setup-root.sh is guaranteed to run before any of the tests
 - Give all tests their unique /etc, /tmp, and /run inside the chroot.
   Turns out tmpfs+overlayfs can be used unprivileged inside an unshare
 - A static BusyBox binary with support for mount helpers so we can
   do the mkdir magic in skel/etc/fstab for the /etc overlay

The last item turned out to be a bit of a roller coaster ride of its
own.  First of all, the original binary we used was from the upstream
BusyBox project[1].  I was sure it couldn't be that hard to enable the
CONFIG_FEATURE_MOUNT_HELPERS ... oh boy was I wrong.  To make long and
tedious story short; two new projects on GitHub were created for this
task: 1) troglobit/misc[2] to house a mirror of https://musl.cc
toolchains and 2) troglobit/busybox-builder[3] to download, patch, and
build the thing using a .config from the myLinux[4] project.  Patching
this .config was necessary, however, since musl libc is strict POSIX
and does not have any of the BSD extensions, e.g. REG_STARTEND that is
in GLIBC regex(3).

[1]: https://busybox.net/downloads/binaries/1.31.0-defconfig-multiarch-musl/
[2]: https://github.com/troglobit/misc/releases/tag/11-20211120
[3]: https://github.com/troglobit/busybox-builder/releases/tag/1_35_0
[4]: https://github.com/troglobit/myLinux

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-25 04:38:24 +02:00
Joachim Wiberg 9f7ba1ba79 test: upgrade BusyBox binary to v1.35.0 w/ mount helpers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-25 04:37:16 +02:00
Joachim Wiberg 762bf5f031 test: minor shellcheck fix of chrootsetup.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-23 09:44:24 +02:00
Joachim Wiberg 060e97d64e test: minor, drop comment within comment confusing shellcheck
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-06 08:07:44 +02:00
Joachim Wiberg 837bca3947 test: new test, verify sysv services are restarted properly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-06 07:57:08 +02:00
Joachim Wiberg 561387ce57 test: new test, verify pre:post: scripts with optional env:file
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-30 08:46:05 +02:00
Joachim Wiberg 539d215d0e test: add missing finit.d to skeleton rootfs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-22 17:51:04 +02:00
Joachim Wiberg 05e6b3e752 test: new test, verify task behavior with conditions
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-21 20:52:34 +02:00
Joachim Wiberg 209e140ddd test: let Finit's bootmisc plugin create the /var/run symlink
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-10 22:46:15 +02:00
Joachim Wiberg 7f8a96a73e test: refactor test framework to use a rootfs skeleton
Instead of having to create files, and copying them in place for each
test, we move all static test files to a skeleton rootfs.  This makes
it a lot easier to get an overview of how things and how they work.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-08 07:22:33 +02:00