Commit Graph
97 Commits
Author SHA1 Message Date
Joachim Wiberg 39d21ca0bd .github: build leg without D-Bus
The D-Bus support is default-enabled, so the HAVE_DBUS paths only
bit-rot silently without this: the leg caught initctl failing to
build with --disable-dbus on its first local run.  Also asserts the
binaries carry no bus references and smoke-runs one non-dbus test.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 22:03:41 +02:00
Joachim Wiberg 153a1de043 keventd: record the libblkid build requirement
keventd is the only thing in the tree that links libblkid, so a tree
that used to build now stops in configure with no hint of which package
to install.  Say so where people look for dependencies, and give CI the
package it now needs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 22:03:32 +02:00
Joachim Wiberg e62b463852 .github: bump actions to node24
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg c28acf21a1 test: fuzz target for the message parser
__msg_parse() turns bytes off a socket into pointers, before anything
has vouched for the peer, and it is the only place in libink that
does.  It had no test of its own beyond whatever the other tests
happened to send it, all of it well-formed.

The target checks the parser's contract, not merely that it survived.
A header field must point into the header field array, and terminate
inside it, and the parse must never claim more bytes than it was
handed.  Crash-only would pass a parser that walked into the body and
returned fields from there, since those bytes were handed over too.
The expected bounds are derived from the raw header rather than from
the parser, so the two have to agree independently.

Every input is copied into an allocation sized to it first.  Reading
past the end of a roomy buffer stays inside the allocation and the
sanitizer never sees it; against an exact one the same read is a
fault, which is where the sharpest findings come from.

Under libFuzzer it is an ordinary fuzz target and named files replay,
which is how a find gets reproduced.  With no arguments it runs a
fixed sweep -- every truncation, every single-byte corruption, every
value of the length that decides where the header ends, and seeded
garbage -- so the suite covers the same contract on every build,
without clang or a corpus in the tree.  It takes 40 ms.

CI fuzzes it properly on every pull request, keeps the crashers, and
carries the corpus between runs so it reaches deeper over time than
any single run can.  Note that clang links the fuzzer runtime against
the newest GCC tree it finds, so the libstdc++ headers have to match
that one and not the default compiler, which is worth saying since
installing the obvious package leaves you exactly where you started.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg 127049d925 test: Finit against a real dbus-daemon
The other dbus-*.sh tests drive libink's own client, so the wire format
was only ever checked against the implementation that wrote it, and the
broker path had no coverage at all.  Every bug found in it so far was
found by hand on a target.

Let the dbus plugin bring up a real dbus-daemon, wait for Finit to
claim org.finit, then talk to Finit with dbus-send, which shares no
code with us.  The privileged call is the interesting one: it can only
be answered by parking the call and asking the broker who sent it.
The bus reads the policy Finit installs, so a malformed org.finit.conf
fails here rather than on a target.

Tests no longer build --with-libsystemd.  Our replacement carries the
real soname but only the sd_notify() symbols, so in the test root it
shadowed the libsystemd the host's libdbus-1 wants and dbus-daemon
died on a missing sd_is_socket.  Nothing under test needs the shared
library: serv is the only consumer and it compiles sd-daemon.c
straight in, which it now does regardless of the flag so notify.sh
keeps testing notify:systemd either way.

Staged from the host by lib/sysroot.mk like any other binary, and
skipped when the host has neither program.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00
Joachim Wiberg b55dada80b libink: a message bus is not a peer
libink was written against the only bus it had, its own, where the
peer on the other end is the client.  A broker is not: it routes for
senders it names itself, expects a DESTINATION on anything addressed
through it, and answers on its own schedule rather than next.

Runlevels go on the wire as S and N rather than the digits Finit
keeps internally, since that is what a caller outside Finit means by
one.

The library stays a convenience library, linked into finit and
initctl and installed nowhere: the ABI promise waits until libink is
its own project.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:26 +02:00
Joachim Wiberg 6310d9e760 initctl: the status views over D-Bus
The summary table, the per-service detail, JSON and the quiet and
ident forms all read state Finit already publishes, so they read it
from the bus like everything else rather than through a second path
that has to be kept in step.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:26 +02:00
Joachim Wiberg 3062f49370 Merge pull request #493 from finit-project/file-format
New file format
2026-08-01 10:08:19 +02:00
Joachim Wiberg cdf8ec932a .github: fix another stale link and refresh
Fix stale link to kernel coding style and refresh the contributing guidelines.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-31 11:39:12 +02:00
Eric Henziger 652479d8fa doc: Update link to Pro Git commit guidelines 2026-07-31 11:00:20 +02:00
Joachim Wiberg 153f719e33 .github: install libconfuse-dev, mandatory since the new .conf format
The workflows install libuev and libite from source and everything
else from apt, but never libconfuse, so every build job on this
branch dies in configure:

    checking for libconfuse >= 3.3... no

Ubuntu ships libconfuse 3.3 with the static library included, which
covers both the static and regular builds.  Staying on 3.3 in CI is
deliberate: it exercises the fallback paths marked
"XXX: Workaround for libConfuse <3.4" that a from-source 3.4 would
leave untested.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:31:46 +02:00
Joachim Wiberg b56ffc155e doc: version the published User Guide by major release
Finit 5.0 changes the .conf syntax, which has been essentially
unchanged since 1.x.  The published docs track master, so when 5.x
lands, 4.x users lose their reference.

Publish the site under a per-major directory, /4.x/ for now, with
the Material version selector to switch between them.  The selector
only needs mike's file layout -- a versions.json at the site root --
which the deploy job now generates from the version directories in
the pages repo, so mike itself is not needed.

The major comes from AC_INIT and the future 4.x maintenance branch
is already in the workflow triggers, so once 5.0 is on master, doc
fixes on the 4.x branch keep /4.x/ updated.  A root index.html
redirects to the newest version, and a 404.html rewrites
pre-versioned deep links so old bookmarks and search hits land in
the right place.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 12:27:27 +02:00
Joachim Wiberg d7fd5bc902 .github: ensure regression tests do not run in parallel
At least the sysvpart.sh regression test cannot run in parallel yet with
other tests (probably runparts.sh), so we must ensure the tests never
run in parallel, in particular at release.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 16:34:16 +01:00
Joachim Wiberg 3f98220d5d test: simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:54:06 +01:00
Joachim Wiberg d17144d16f .github: extract test results dir at release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:46:43 +01:00
Joachim Wiberg a608c5a5c9 .github: always upload test results, regardless
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:46:10 +01:00
Joachim Wiberg 9b44b99480 .github: remember to ldconfig
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 15:40:06 +01:00
Joachim Wiberg 9ce95fe8c0 .github: fix logic in weekly workflow
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 09:51:02 +01:00
Joachim Wiberg 06889cc014 .github: verify system can find .so libs in /usr/local
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 09:48:33 +01:00
Joachim Wiberg 0b27778c96 .github: install missing glightbox plugin for mkdocs
This is for automatic image zoom.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-27 15:21:06 +01:00
Joachim Wiberg 804060444a .github: fix deploy issue
- We already have the SHA
 - Use 'git add -A' to handle deleted files too

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-26 13:16:45 +01:00
Joachim Wiberg de544a5b36 .github: deploy docs to project's pages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-26 12:47:25 +01:00
Joachim Wiberg 85baafe99c doc: update links to new project home and add release badge
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:08 +01:00
Joachim Wiberg e635ea882a Bump required libite and libuev versions
We now require readsnf() introduced in libite 2.6.0, with bug fixes
this effectively means v2.6.2.

The libuev bump is for 64-bit time_t, with bug fix => v2.4.1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:08 +01:00
Aaron Andersen be2a0ec3e7 Add support for Linux capabilities
Implement Linux capability support for services, allowing them to run
with minimal required privileges instead of running as root. This uses
the modern IAB (Inheritable, Ambient, Bounding) API from libcap.
2025-11-30 11:36:53 -05:00
Joachim Wiberg 4f8dab75b2 Update test helper and all workflows to enble libsystemd build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-08-29 14:43:25 +02:00
Joachim Wiberg 2aa9e5bad6 doc: relocate AUTHORS and ChangeLog
Part of project cleanup-root

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 16:45:48 +02:00
Joachim Wiberg 6c133e85f2 .github: restrict workflow permissions
As suggested by CodeQL scanning.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 16:24:34 +02:00
Joachim Wiberg 31b78817dd .github: trim number of runners started on push + pr
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-09 11:50:39 +02:00
Joachim Wiberg 5599aca0a3 .github: generate documentation using mkdocs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-09 11:50:38 +02:00
Joachim Wiberg 4f252858e4 Enable address sanitizer, credits to @chipitsine
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-05-05 06:55:08 +02:00
Joachim Wiberg 994e51e34f Convert **Note:** et al to GitHub Markdown alerts
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-27 10:23:10 +01:00
Joachim Wiberg 617609cbc5 .github: allow running coverity scan on workflow dispatch
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 12:35:48 +01:00
Joachim Wiberg 0f4a487328 .github: tests share same sysroot, must run in sequence
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-14 10:28:16 +01:00
Joachim Wiberg 003faae9e9 .github: disable apparmarmor to allow testing in unshare
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-03 10:23:45 +01:00
Joachim Wiberg d02d65feeb .github: minor, bump action version
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-19 09:20:03 +02:00
Joachim Wiberg 836bfff08b .github: update actions
... and try to fix weekly trigger

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 19:47:12 +01:00
Joachim Wiberg 379a63fce4 .github: adjust path for cov-build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 19:55:55 +01:00
Joachim Wiberg b1f9a11809 .github: update actions, sync coverity with latest
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 19:51:37 +01:00
Joachim Wiberg fb230f2137 .github: add makeLatest flag based on non-rc/beta/alpha
Note, the makeLatest flag can also be set to 'legacy', which takes
latest date and version.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 17:42:20 +02:00
Joachim Wiberg 6aa48a8b32 .github: fix pre-release flag input
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 17:41:52 +02:00
Joachim Wiberg a436a1c8cb .github: speed up release job, and support for setting pre-release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-14 09:40:55 +02:00
Joachim Wiberg 4edfa9859e .github: fix variable sharing between jobs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-14 09:14:28 +02:00
Joachim Wiberg 138546d008 .github: debug failing tests in release build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-07 21:06:17 +02:00
Joachim Wiberg 7af4ad5c24 .github: Release General needs a new uniform!
We've prepared this at one of the finest tailors at Saville Row.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-07 20:53:25 +02:00
Joachim Wiberg 4d472273e1 .github: debug weekly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-23 16:47:47 +02:00
Joachim Wiberg 13f1359b3a .github: fix and simplify weekly distcheck job
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-22 15:46:06 +02:00
Joachim Wiberg 2566e00ef0 .github: finit -h now require super user privs.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-05 10:12:56 +01:00
Joachim Wiberg 6a4f197cc0 .github: enable new testserv plugin, regression testing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:48:57 +01:00
Joachim Wiberg 96b5991355 .github: ::set-output is deprecated
https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-07 18:04:45 +01:00