Commit Graph
226 Commits
Author SHA1 Message Date
Joachim Wiberg 3231ade38a dbus: fixes from a code review of the branch
A pass over the whole branch before merge, mostly in libink since
that is the new code and the part exposed to the wire.  Grouped here
rather than scattered so the review is easy to read in one place.

libink parser and dispatch:

 - Bound reader lengths so a 32-bit size_t can't wrap a wire length
   past the guard and read out of bounds.  Reachable pre-auth on any
   bus, so it matters on the 32-bit targets Finit runs on.
 - Drop a peer when a reply send fails instead of limping on with a
   half-written frame; a built-in whose send failed used to fall
   through and put a second frame on the wire.

initctl:

 - Copy a D-Bus error name out of the reply before closing the client;
   the reply points into memory the close frees.  Both error paths now
   share one helper so this can't creep back.

Authorization:

 - Take the caller's groups from the kernel (SO_PEERCRED plus
   SO_PEERGROUPS) rather than getpwuid()/getgrouplist(), which go
   through NSS and can block PID 1 on a slow LDAP or SSSD backend.
   The check is now a lookup against the group resolved once at init,
   with no NSS and no 256 KiB array on the stack.  A caller reaching
   us through a broker carries no group set, so system-bus privileged
   methods are root-only; the local bus keeps group support.  See
   libink/README.md for the note on lifting that.

Shutdown:

 - Call dbus_exit() from the shutdown path so the server, its peers,
   and the socket are let go cleanly.  The teardown existed but nobody
   called it.

Tests, CI, docs:

 - A fuzz target for the message parser, run as a quick sweep in the
   suite and properly under libFuzzer in CI, with the corpus carried
   between runs.  The -as-uid tests drop groups the way a login does
   so SO_PEERGROUPS sees the right set, and widen the test socket to
   reach the per-method check behind the 0660 gate.  Bring the GitHub
   actions up to versions that run on Node 24, and tidy a few small
   things a /simplify pass turned up.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-16 08:57:38 +02:00
Joachim Wiberg b55dada80b libink: a message bus is not a peer
libink was written against the only bus it had, its own, where the
peer on the other end is the client.  A broker is not: it routes for
senders it names itself, expects a DESTINATION on anything addressed
through it, and answers on its own schedule rather than next.

Runlevels go on the wire as S and N rather than the digits Finit
keeps internally, since that is what a caller outside Finit means by
one.

The library stays a convenience library, linked into finit and
initctl and installed nowhere: the ABI promise waits until libink is
its own project.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:26 +02:00
Joachim Wiberg 6310d9e760 initctl: the status views over D-Bus
The summary table, the per-service detail, JSON and the quiet and
ident forms all read state Finit already publishes, so they read it
from the bus like everything else rather than through a second path
that has to be kept in step.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:26 +02:00
Joachim Wiberg ebc0ef62e6 libink/finit: properties, and org.finit on the system bus
Runlevel and version are state, not actions, so they belong behind
org.freedesktop.DBus.Properties rather than another method each.

Finit also claims org.finit on the system bus when it finds one, so
ordinary D-Bus clients can reach it without knowing about
/run/finit/bus.  Opportunistic on purpose: no dbus-daemon is a normal
state for the systems Finit runs on, not an error to report.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:14 +02:00
Joachim Wiberg dd1390a6c2 initctl: monitor and condition control over the bus
The bus can already answer questions and change services, so give
initctl the two things it still did another way: watching signals as
they happen, and getting or setting user conditions.

The dbus tests move with it, split by area rather than one file that
grew every time the library did.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:14 +02:00
Joachim Wiberg 0a269f3298 libink: a brokerless D-Bus implementation for Finit
Finit had no way to answer the question every service manager gets
asked: what is running, and change it.  D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.

So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET.  It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top.  Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.

Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 09:28:14 +02:00
Joachim Wiberg ffb1db7d2d conf: add provides, additional conditions a service supplies
A block title is a service identity, so two variants of one service
gated differently per platform cannot share a title.  They do need to
share the barrier condition downstream services wait for, which until
now was spelled by the identity alone and so could not be shared:

    service syslogd:udev {
        if         = "udevd"
        conditions = { "run/udevadm:5/success" }
        provides   = "pid/syslogd"
        command    = "-syslogd -F"
    }

Any namespace is allowed, since the point is publishing a name that
existing configurations already wait on.  A claim on a condition that
is already owned is dropped with a warning naming the owner, and the
service still registers: the overlap is a configuration bug, and an
init system is more useful degraded than refusing to boot.  A real
identity outranks a claim, pid/<ident> is how Finit tracks its own
services, so it is not up for grabs.

Claims are dropped before each reload re-reads the .conf files.  Doing
it per service as it re-registers is not enough, since services are
read in file order and one re-registering would lose to a claim
another had not dropped yet, flipping the owner on every reload.

initctl cond dump asked who owned a condition only for the pid/
namespace and printed 'static' for usr/, which now hides a provider.
It asks first and falls back to what the namespace implies.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-05 17:58:43 +02:00
Joachim Wiberg c4463ec64f initctl: escape special characters in JSON output
Strings like command, description, and environment may contain characters
that need escaping for valid JSON, e.g., embedded quotes in command line
arguments like -V "NanoPi R2S".

Add json_escape() helper to handle quotes, backslashes, and control chars.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-18 23:26:37 +01:00
Aaron Andersen 373738f3d1 Implement switch_root functionality allowing Finit to serve as the init
in an initramfs, then transition to the real root filesystem.  Useful
for systems requiring early boot tasks like LUKS unlock, LVM activation,
or network boot before mounting the real root.

Adds INIT_CMD_SWITCH_ROOT API command, `initctl switch-root` subcommand,
and HOOK_SWITCH_ROOT plugin hook point.  The implementation gracefully
stops services, moves virtual filesystems (/dev, /proc, /sys, /run) to
the new root, deletes initramfs contents to free memory, then execs the
new init as PID 1.

See GitHub Discussion #292 for background.
2026-01-01 19:10:24 -05:00
Joachim Wiberg a3d9b6e9b1 initctl: fix remaining lingering artifacts in 'top' output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:38 +01:00
Joachim Wiberg 390a0f48c1 initctl: minor, simplify code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:38 +01:00
Joachim Wiberg 43ca51c3b1 initctl: add cpu/mem limits as well to json status output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:37 +01:00
Joachim Wiberg fb0ad18d3a initctl: add CPU throttled information alongside memory usage
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:33 +01:00
Richard Alpe c3839edc40 initctl: add memory field to JSON status output
Add missing memory information to JSON output in json_status_one().
The memory field shows cgroup memory usage in bytes when cgroup
support is available and the service has a valid PID, matching
the behavior of the text status output.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-12-01 14:51:27 +01:00
Joachim Wiberg e958189e6a initctl: rename command signal -> kill
Already backwards compatible, both kill and signal map to the same command.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 18:29:39 +02:00
Joachim Wiberg 8377f0e736 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 14:34:16 +02:00
Joachim Wiberg b0b4f7b2ba initctl: refactor pid_cgroup(), return allocated buffer
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-05-30 10:42:50 +02:00
Joachim Wiberg 9684127eb7 initctl: refactor runlevel string composition
Related to issue #437

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-05-05 07:27:06 +02:00
Joachim Wiberg 8d2cfd69fa initctl: buffer overflow in runlevel string formatting
Fix #437

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-05-05 07:19:12 +02:00
Joachim Wiberg 7fec66dc09 Simplify, svc_checkenv() already checks if optional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-17 18:38:31 +01:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Joachim Wiberg a49f27c191 initctl: show runlevel 'N S' instead of 'N 10' during bootstrap
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-09-10 14:05:11 +02:00
Joachim Wiberg 4fbcd1bbad Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-05-05 06:00:34 +02:00
Joachim Wiberg e00fda5dc3 Fix #352: separate runlevel S from runlevel 0
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff.  If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.

This change is quite invasive.  It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-04-22 15:11:27 +02:00
Joachim Wiberg 8f1d1717f8 initctl: let -n ignore errors from enable/disable as well
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-27 14:27:16 +02:00
Joachim Wiberg b65773d508 Drop logically dead code, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-04 12:09:50 +01:00
Joachim Wiberg 8ce35771c3 initctl: fix potential memory leak
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-04 11:43:57 +01:00
Joachim Wiberg 67e80ea989 initctl: ensure the returned plugin buffer data is terminated
Found by Coverity Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-04 11:43:10 +01:00
Tobias Waldekranz c23a867485 initctl: Follow priciple of least surprise for "cond get"
The accepted standard in Unix is to report successful executions with
exitcode 0. Therefore, map a "initctl cond get" of a condition to the
following exitcodes:

- On: 0
- Off: 1
- Flux: 255

Fixes: c3c662fe64 ("initctl: ensure 'cond get' support flux state")
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-02-06 16:01:18 +01:00
Joachim Wiberg 320e91653b initctl: add -n,--noerr to return OK(0) if svc doesn't exist
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-19 19:57:25 +01:00
Joachim Wiberg 2c9265f8c8 initctl: add 'cat' as alias for 'show'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-15 14:13:01 +01:00
Joachim Wiberg c3c662fe64 initctl: ensure 'cond get' support flux state
The 'initctl cond' commands were initiallý added to only manage usr
conditions.  Recently the 'cond get' command was expanded to allow
reading general conditions as well.

However, since general conditions support three states the command
returned 'on' for conditions that were in flux.  This patch fixes
that oversight.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-15 06:34:05 +01:00
Joachim Wiberg d1ebb255c6 initctl: add 'kill' alias to 'signal' command
Principle of least surprise.  When no even the maintainer remembers
the correct command, it is time to add an alias.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-12 09:00:57 +01:00
Joachim Wiberg 2a62fa3d85 Fix #329: add support for multiple args to initctl cond set/clr
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-01-07 14:00:16 +01:00
Joachim Wiberg 006dd12b09 initctl: recactor, share fgetval() with rest of Finit
Note: this highly useful function should probably migrate to libite.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-20 10:43:30 +01:00
Joachim Wiberg 035f06e137 initctl: dump svc type and forking in JSON output
First set of svc_t properties not possible to debug otherwise.  See
issue #313 for a background.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-11 12:11:24 +01:00
Joachim Wiberg 2f91ab5eac Fix #235: support for overriding /etc/finit.conf and /etc/finit.d
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.

For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added.  It in turn can be used by factory.conf
as follows to override /etc/finit.d:

    rcsd /etc/factory.d

Manually verified in myLinux

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-10 17:21:33 +01:00
Joachim Wiberg d27f114742 Document new -j,--json output option in initctl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-09 16:43:11 +01:00
Joachim Wiberg 8425bc313b initctl: add --json support for condition status and dump
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-09 14:11:46 +01:00
Joachim Wiberg f4d3cf2835 Fix #273: add JSON output option to initctl status [foo]
This change adds support for JSON output to `initctl status` using a
`-j` or `--json` command line option.

Example:

    root@anarchy:~# initctl status -j mdevd
    {
      "identity": "mdevd",
      "description": "MDEVD Extended Hotplug Daemon",
      "status": "crashed",
      "exit": { "code": 100 },
      "origin": "built-in",
      "command": "/bin/mdevd -C -O 4",
      "restarts": 10,
      "pidfile": "/run/mdevd.pid",
      "pid": 0,
      "user": "root",
      "group": "root",
      "uptime": 0,
      "runlevels": [ "S", 1, 2, 3, 4, 5, 7, 8, 9 ]
    }

The excellent tool `jq` can be used to extract certain parts of the
output for further scripting.  E.g. `initctl status -j foo | jq .exit`

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-09 13:49:03 +01:00
Joachim Wiberg bd5cf7c9eb Drop confusing leading / in sig2str() and code2str()
This was added for the benefit of `initctl status foo`, but we have
other users of these functions that don't expect a leading slash.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-11-08 22:37:13 +01:00
Joachim Wiberg e177b866a9 initctl: follow-up to e1c59a25, simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 20:01:29 +02:00
Joachim Wiberg af60d8d3ec initctl: fix off-by-one in column width when dumping conditions
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-16 20:01:29 +02:00
Joachim Wiberg 37e3be9a0d Refactor to share err/warn log API between daemon and client code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-09-05 09:57:45 +02:00
Joachim Wiberg a61a8015d7 initctl: new command, list installed plugins
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-15 11:00:39 +02:00
Joachim Wiberg 1c4bad5b73 initctl: only show log if PID != 0
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-12 15:08:14 +02:00
Joachim Wiberg 6c874895dc Fix #295: add reboot/shutdown/poweroff timeout -t SEC to initctl
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-08-12 15:06:54 +02:00
Joachim Wiberg 6cc44a87c9 Fix #275: 'initctl status foo' should list all instances
This is a fix to a regression introduced in e51587c.  The idea is to
have 'initctl status foo' show all instances of foo, provided there are
more than one. E.g.

    root@anarchy:~# initctl -t status foo
    0    foo:1        stopped  [--234-----] hej knekt
    0    foo:2        stopped  [--234-----] hej snigel
    0    foo:3        stopped  [--234-----] hej kalas

And not foobar:

    0    foo:1        stopped  [--234-----] hej knekt
    0    foo:2        stopped  [--234-----] hej snigel
    0    foo:3        stopped  [--234-----] hej kalas
    0    foobar       stopped  [--234-----] hej foobar

If you type an exact match you can drill down like so:

    root@anarchy:~# initctl status foo:1
         Status : stopped (code=exited, status=0/SUCCESS, manual=yes)
       Identity : foo:1
    Description : hej knekt
    ...

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-19 15:39:01 +02:00
Joachim Wiberg 5f908cae49 Fix #274: allow manual:yes on sysv/service/run/task
Prior to this change only service stanzas respected the manual:yes
option, now it (should) work on any svc_t type.  Not tested on ttys.

The initctl tool has been given an extra manual=yes output for these
types of run/task/service entries, shown only when the manual option
is set.

Example:

root@anarchy:~# initctl status foo.sh
     Status : stopped (code=exited, status=0/SUCCESS, manual=yes)
   Identity : foo.sh                                ~~~~~~~~~~~~
Description : Hej foo
     Origin : /etc/finit.d/enabled/foo.conf
Environment :
Condition(s):
    Command : /root/foo.sh
   PID file : none
        PID : 0
       User : root
      Group : root
     Uptime : N/A
     Starts : 1
   Restarts : 0 (0/10)
  Runlevels : [--2345----]

Notice also the new `Starts : 1` which is a counter for the number of
starts in the current runlevel.  On runlevel change it is reset to 0.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-16 17:57:55 +02:00
Joachim Wiberg 6286ede985 initctl: add optional TYPE argument to 'cond dump' command
Allow filtering of conditions in raw dump, i.e., the possibility to show
only conditions of a certain type.  The TYPE argument is not validated
in any way, so any prefix match is allowed, e.g.

   initctl cond dump service/s

Shows all conditions for services starting with 's'.

Fixes issue #272

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-06-12 23:37:03 +02:00