Commit Graph
227 Commits
Author SHA1 Message Date
Joachim Wiberg 0a269f3298 libink: a brokerless D-Bus implementation for Finit
Finit had no way to answer the question every service manager gets
asked: what is running, and change it.  D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.

So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET.  It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top.  Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.

Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:14 +02:00
Joachim Wiberg c20d64587c conf: relocate global state from legacy parser
Relocate process-wide global variables from legacy parser that ended up
there because it used to be conf.c, but which is now now frozen at the
4.x feature set.  Each variable is moved to their respective "owner".

Give cgroup_current[] and cgroup_settings_current[] named bounds.  Their
extern declarations were unsized, so sizeof() on them stopped compiling
once the definitions moved to another translation unit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:21:25 +02:00
Aaron Andersen 1518eb9466 Add Plymouth boot splash plugin
Manage the plymouthd lifecycle across boot, switch_root, and shutdown.
Activated by the "splash" kernel command line argument.
2026-03-20 09:18:18 -04:00
Aaron Andersen 39044adcf8 Create mount points in fs_init() if they don't exist
In containerized or virtualized environments, standard mount point
directories may not exist at boot.  Ensure they are created before
attempting to mount.
2026-01-19 15:20:43 -05:00
Joachim Wiberg ce40e2b9d2 Rename tty services early from "init" -> "getty"
Finit has support for "Please press Enter to activate this console."
which means there's no getty yet running.  However, when profiling
systems with Finit, and embedded systems in general, a common metric
is the time from power-on to getty has started.

This commit makes sure to rename the process so that BusyBox pidof is
capable of detecting that "getty" has started.  This is mostly for the
bootchart2 project's bootchartd, the native BusyBox bootchartd does not
have this issue.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:34:04 +01:00
Joachim Wiberg 21753e26dd Set critical env PATH + SHELL early
When running Finit under boothcartd (bootchart2 project) the PATH is
lost due to a bug.  This was a wakeup, so set critical variables in
main() early, before calling fs_init().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:29:28 +01:00
Joachim Wiberg 22bc218c84 Fix #462: /dev/pts mounted with wrong mode
Before this fix:

    admin@infix:~$ sudo ls -la /dev/pts/
    total 0
    drwxr-xr-x    2 root     root             0 Dec 24 08:16 .
    drwxr-xr-x   13 root     root         13340 Dec 24 08:16 ..
    cr--------    1 root     tty       136,   0 Dec 24 08:18 0
    crw-rw-rw-    1 root     root        5,   2 Dec 24 08:16 ptmx
    admin@infix:~$ mount | grep devpts
    devpts on /dev/pts type devpts (rw,nosuid,noexec,relatime,gid=5,mode=400,ptmxmode=666)

After:

    admin@infix-00-00-00:~$ sudo ls -l /dev/pts/
    total 0
    crw--w----    1 root     tty       136,   0 Dec 24 08:21 0
    crw-rw-rw-    1 root     root        5,   2 Dec 24 08:20 ptmx
    admin@infix-00-00-00:~$ mount |grep pts
    devpts on /dev/pts type devpts (rw,nosuid,noexec,relatime,gid=5,mode=620,ptmxmode=666)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-24 09:23:30 +01:00
Joachim Wiberg 24f0cee49a Ensure mount/unmount skips 'noauto' entries
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:11 +01:00
Joachim Wiberg 8377f0e736 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 14:34:16 +02:00
Joachim Wiberg 61be1ef880 Follow-up to b4b7ee1, also set process name -> "init"
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 15:15:25 +02:00
Joachim Wiberg b4b7ee1b71 Clear command line arguments after parsing
Fixes #442

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 14:41:40 +02:00
Joachim Wiberg 3df3c51dae Relocate global configuration variables from finit.c -> conf.c
These variables really belong in conf.c.  Relocate and move external
decls. from finit.h -> conf.h to simplify linking of other programs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:14:03 +02:00
Joachim Wiberg 1b9e69414e Refactor state machine control functions
This refactor should have been done years ago when we first introduced
the big state machine.  The old functions service_runvel() and the oddly
named service_reload_dynamic() are actually state machine control fns,
so let relocate them.

Also in this commit, remove the global variable 'sm' and rename a few of
the critical functions to better names.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:13:56 +02:00
Joachim Wiberg 75fa868a4b Fix various typos found by codepsell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 16:46:28 +01:00
Joachim Wiberg 211293a83d Fix possible overflow in return value
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-02-23 04:28:26 +01:00
az 3cfe0a33b8 fstab with UUID/LABEL: nofail handling for fsck
add support for 'nofail' fstab option. if present, finit's fsck invocation ignores errors for this device.

this is useful if you have an fstab entry for a device with UUID= or LABEL= which isn't always present and which you'd like to not
bail on (so you set nofail). in this case finit leaves the presence-or-not decision to fsck, which exits nonzero.

for block devices that are directly listed in fstab this change isn't important, because for such finit looks for the blockdev's existence and skips the fsck if n/a.
2024-12-20 09:09:24 +10:00
Mathias Thore a0685219cf Avoid remounting already mounted /run and /tmp directories
Adds the function fistmpfs to determine if a new tmpfs mount should be
performed on /run and /tmp. The function supports cases where more
complex mount hierarchies are in use, including overlayfs backed mounts.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
2024-08-05 14:33:43 +02:00
Joachim Wiberg 340cae4afd Change default behavior, allow kernel logs to console
A Linux system booted with the kernel command line option 'quiet' only
logs error (and above) severity messages to the console.  For embedded
systems, which is the primary target for Finit, this is what you want
to see.

Hence, and after careful consideration, this patch changes the default
behavior of Finit to allow kernel logs to the console.  A build-time
configure flags, --disable-kernel-logging, has been added to restore
legacy behavior.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-24 12:46:59 +02:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Joachim Wiberg 337ee003bb Mount /dev/mqueue if missing and set sticky bit to /dev/shm
Inspired by Alpine Linux, add /dev/mqueue if missing.  We should check
the /proc/filesystems first, but this is quicker.

The sticky bit ensures only the owner of files in /dev/shm can delete or
rename files.  This is also what Alpine Linux use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-06 23:50:30 +01:00
Joachim Wiberg 0b5c555c7f Add 'notify:pid' style readiness notifaction and 'readiness none'
This change expands the readiness notification system in Finit with the
native 'pid' style, which will remain the default readiness in Finit 4.x

For systems that want to transition to Finit 5.x early, a global option
to set 'readiness none' in /etc/finit.conf, has been added.  This change
the service default notification mode to 'notify:none', which can also
be set by Finit 4.x ('readiness pid') for select services.

Fixes #386.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 19:07:12 +01:00
Joachim Wiberg 6443995fc9 Fix #385: internal conditions are type oneshot, always active
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-12 09:04:35 +01:00
Joachim Wiberg f27998ae4f Assert <int/container> condition if we detect running in container
Useful both for troubleshooting and for triggering if:<int/container> tasks.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-14 08:37:15 +02:00
Joachim Wiberg eb9e94935e Failure to open fstab should log to console, reboot if no sulogin
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-03 17:56:49 +02:00
Joachim Wiberg 6ae1083c99 Add support for SysV-only scripts in runparts
This patch extens the SysV compatibility support in Finit by adding
support for limiting `runparts` to run only SNNfoo, or KNNfoo, style
scripts from a directory.

Additionally, by default `runparts` now runs entirely in the background
without any progress.  To enable progress, an optional argument has been
added to the runparts command line.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 13:25:35 +02:00
Joachim Wiberg 846806747b Fix #366: document fsck.* command line options and simplify code
As pointed out in #366, the configure options --enable-fastboot and
--enable-fsckfix should just alter the default values of the two fsck
command line options.

This commit simplifies the code and makes it possible to override using
the command line regardless of the two build options.

Finally, add the two command line options to doc/cmdline.md

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-24 11:58:07 +02:00
Joachim Wiberg 263aec292a Support for disabling invocation of rescue mode from kernel cmdline
The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-13 12:45:03 +02:00
Joachim Wiberg a22a794f55 Clarify usage text slightly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 13:16:09 +02:00
Joachim Wiberg a58002588e Refactor initial startup, run runparts and rc.local in background
The code refactored in this commit has long been an eyesore.  The
hand-over, from the sequential main() function, to the event loop
was clumsy at best and was very difficult to debug.

Instead of using a series of workers we now delegate everything to
the big state machine by introducing a new SM_BOOTSRTAP_WAIT_STATE.

Both the runparts and rc.local scripts now run in the background, no
longer blocking the event loop from responding to initctl calls.  To
ensure they run at the same point in time two things have been done:

 1. A new <int/bootstrap> condition has been added which triggers
    runparts, which now is a regular task created by conf_init()
 2. /etc/rc.local is started from SM_RUNLEVEL_WAIT_STATE when we
    transition from runlevel S to any other runlevel.

Fixes #356

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-07-30 10:09:34 +02:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg e00fda5dc3 Fix #352: separate runlevel S from runlevel 0
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff.  If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.

This change is quite invasive.  It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-22 15:11:27 +02:00
Joachim Wiberg 5340e47e81 Flush .conf event queue before leaving boostrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-21 11:24:17 +01:00
Joachim Wiberg 1e5ce38928 Return EX_NOPERM for non-root users calling init/telinit
See issue #301 for future per-user support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-05 10:05:24 +01:00
Joachim Wiberg 1e1b3564dd Support for fsck_mode=[auto,skip,force] + fsck_repair=[preen,no,yes]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg 33e504b928 Check if WDT_DEVNODE is defined, may not be enabled in configure
When this code was moved from finit.c we rely on WDT_DEVNODE to be
defined in config.h, which is controlled by configure.  Meaning, before
the relocation, Finit did not honor the configure settings.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 02:00:14 +01:00
Joachim Wiberg e9515971ea Refactor, move registration of static services to conf_init()
All services registered in the system rely on conf_init() having been
set up properly, e.g., global_rlimit.  Having conf_init() be responsible
also for registering static services is only logical, and also helps us
clean up main() a bit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg 82dfa002ff Follow-up to c9fe9afa, proper fix for HOOK_BASFFS_UP mess
Instead of the revert in c9fe9afa, we restore HOOK_BASFFS_UP to its
proper place at the end of fs_mount_all().  For this to not cause any
regressions we add a new hook, HOOK_SVC_PLUGIN, and update all plugins
that call service_register() to run at the new hook.

This will cause regressions for external 3rd party plugins that rely on
HOOK_BASEFS_UP to be called at its previous postion.  Nevertheless, this
is the proper fix to the problem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-05 01:15:49 +01:00
Joachim Wiberg c9fe9afa61 Revert "HOOK_BASEFS_UP must run as soon as all filesystems are mounted"
This reverts commit 5b41c6e since it causes regressions in plugins
adding services to the system.  The proper fix for early bootmisc
is to add a new hook, which will be added in subsequent commits.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-24 10:00:47 +01:00
Joachim Wiberg 311c6be9aa Add support for optional reboot delay
Slightly different take on issue #334 making it optional, possible to
enable per system.

    reboot-delay <0-60>           # default: 0 (disabled)

When enabled (non-zero), runs after filesystems have been unmounted,
the root filesystems has been remounted read-only, and sync(2) has
been called, twice.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-08 09:37:19 +01:00
Joachim Wiberg 5b41c6e327 HOOK_BASEFS_UP must run as soon as all filesystems are mounted
At this hook point the bootmisc.so plugin runs and creates all relevant
system directories.  Much of the rest of system bootstrap relies on this
so it should be called together with the other FS hooks as soon as all
the filesystems have been mounted.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-07 15:09:50 +01:00
Joachim Wiberg 17c69fef3d Fix #185: add devmon support, <dev/foo> condition provider
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-12-18 22:21:15 +01:00
Joachim Wiberg 70c2939596 Fix #315: add environment variables to hook scripts
All hook scripts are called with at least one environment variable set,
FINIT_HOOK_NAME, useful when reusing the same hook script for multiple
hook points.  It is set to the string name, also used by the path, e.g.,
hook/net/up.

For all hook points from hook/sys/shutdown and later, FINIT_SHUTDOWN is
also set, to one of:  halt, poweroff, reboot.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 22:51:40 +01:00
Joachim Wiberg 0498326962 Fix #318: only show "[ OK ] Calling foo" progress for runparts ...
For all other run_parts() use-cases we just give the script control over
stdout/stderr to prevent clobbering ANSI color escape codes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 21:49:30 +01:00
Joachim Wiberg f3fcca6150 Revert "Refactor, enter main event loop earlier"
This reverts commit 03c08d3970 due to it
breaking handling of bootstrap tasks, causing endless boot loop.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-23 17:54:32 +01:00
Joachim Wiberg 2f91ab5eac Fix #235: support for overriding /etc/finit.conf and /etc/finit.d
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.

For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added.  It in turn can be used by factory.conf
as follows to override /etc/finit.d:

    rcsd /etc/factory.d

Manually verified in myLinux

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-10 17:21:33 +01:00
Joachim Wiberg 1f9621cf4b Fix #288: enable built-in sulogin in Alpine and Void Linux builds
Always better to have at least one sulogin available, if the system
provided sulogin isn't available we fall back to the built-in one.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 21:08:44 +02:00
Joachim Wiberg d22dea74e3 Finalize refactor to new log macros, following-up to 37e3be9
This possible also mitigates the issue tracked in #307.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-09 12:52:40 +02:00
Joachim Wiberg 03c08d3970 Refactor, enter main event loop earlier
This delays the start of the .conf monitor and service initialization
slightly to allow the event loop to run earlier to process any events
from the initial setup.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-05 13:47:08 +02:00
Joachim Wiberg 0ce028add1 Fix #283: too quick timeout at bootstrap of lingering tasks
This seemed odd at first, but it turns out we seem to have adjusted the
time scale for the bootstrap worker, so we were off by ... a factor 10.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-03 03:45:10 +02:00
Joachim Wiberg 83aa6abb1c Fix potential NULL ptr dereference, found by Coverity
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-17 14:37:06 +02:00