A pass over the whole branch before merge, mostly in libink since
that is the new code and the part exposed to the wire. Grouped here
rather than scattered so the review is easy to read in one place.
libink parser and dispatch:
- Bound reader lengths so a 32-bit size_t can't wrap a wire length
past the guard and read out of bounds. Reachable pre-auth on any
bus, so it matters on the 32-bit targets Finit runs on.
- Drop a peer when a reply send fails instead of limping on with a
half-written frame; a built-in whose send failed used to fall
through and put a second frame on the wire.
initctl:
- Copy a D-Bus error name out of the reply before closing the client;
the reply points into memory the close frees. Both error paths now
share one helper so this can't creep back.
Authorization:
- Take the caller's groups from the kernel (SO_PEERCRED plus
SO_PEERGROUPS) rather than getpwuid()/getgrouplist(), which go
through NSS and can block PID 1 on a slow LDAP or SSSD backend.
The check is now a lookup against the group resolved once at init,
with no NSS and no 256 KiB array on the stack. A caller reaching
us through a broker carries no group set, so system-bus privileged
methods are root-only; the local bus keeps group support. See
libink/README.md for the note on lifting that.
Shutdown:
- Call dbus_exit() from the shutdown path so the server, its peers,
and the socket are let go cleanly. The teardown existed but nobody
called it.
Tests, CI, docs:
- A fuzz target for the message parser, run as a quick sweep in the
suite and properly under libFuzzer in CI, with the corpus carried
between runs. The -as-uid tests drop groups the way a login does
so SO_PEERGROUPS sees the right set, and widen the test socket to
reach the per-method check behind the 0660 gate. Bring the GitHub
actions up to versions that run on Node 24, and tidy a few small
things a /simplify pass turned up.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
libink was written against the only bus it had, its own, where the
peer on the other end is the client. A broker is not: it routes for
senders it names itself, expects a DESTINATION on anything addressed
through it, and answers on its own schedule rather than next.
Runlevels go on the wire as S and N rather than the digits Finit
keeps internally, since that is what a caller outside Finit means by
one.
The library stays a convenience library, linked into finit and
initctl and installed nowhere: the ABI promise waits until libink is
its own project.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The summary table, the per-service detail, JSON and the quiet and
ident forms all read state Finit already publishes, so they read it
from the bus like everything else rather than through a second path
that has to be kept in step.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Runlevel and version are state, not actions, so they belong behind
org.freedesktop.DBus.Properties rather than another method each.
Finit also claims org.finit on the system bus when it finds one, so
ordinary D-Bus clients can reach it without knowing about
/run/finit/bus. Opportunistic on purpose: no dbus-daemon is a normal
state for the systems Finit runs on, not an error to report.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The bus can already answer questions and change services, so give
initctl the two things it still did another way: watching signals as
they happen, and getting or setting user conditions.
The dbus tests move with it, split by area rather than one file that
grew every time the library did.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Finit had no way to answer the question every service manager gets
asked: what is running, and change it. D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.
So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET. It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top. Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.
Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A block title is a service identity, so two variants of one service
gated differently per platform cannot share a title. They do need to
share the barrier condition downstream services wait for, which until
now was spelled by the identity alone and so could not be shared:
service syslogd:udev {
if = "udevd"
conditions = { "run/udevadm:5/success" }
provides = "pid/syslogd"
command = "-syslogd -F"
}
Any namespace is allowed, since the point is publishing a name that
existing configurations already wait on. A claim on a condition that
is already owned is dropped with a warning naming the owner, and the
service still registers: the overlap is a configuration bug, and an
init system is more useful degraded than refusing to boot. A real
identity outranks a claim, pid/<ident> is how Finit tracks its own
services, so it is not up for grabs.
Claims are dropped before each reload re-reads the .conf files. Doing
it per service as it re-registers is not enough, since services are
read in file order and one re-registering would lose to a claim
another had not dropped yet, flipping the owner on every reload.
initctl cond dump asked who owned a condition only for the pid/
namespace and printed 'static' for usr/, which now hides a provider.
It asks first and falls back to what the namespace implies.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Strings like command, description, and environment may contain characters
that need escaping for valid JSON, e.g., embedded quotes in command line
arguments like -V "NanoPi R2S".
Add json_escape() helper to handle quotes, backslashes, and control chars.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
in an initramfs, then transition to the real root filesystem. Useful
for systems requiring early boot tasks like LUKS unlock, LVM activation,
or network boot before mounting the real root.
Adds INIT_CMD_SWITCH_ROOT API command, `initctl switch-root` subcommand,
and HOOK_SWITCH_ROOT plugin hook point. The implementation gracefully
stops services, moves virtual filesystems (/dev, /proc, /sys, /run) to
the new root, deletes initramfs contents to free memory, then execs the
new init as PID 1.
See GitHub Discussion #292 for background.
Add missing memory information to JSON output in json_status_one().
The memory field shows cgroup memory usage in bytes when cgroup
support is available and the service has a valid PID, matching
the behavior of the text status output.
Signed-off-by: Richard Alpe <richard@bit42.se>
Due to an old design decision runlevel S was encoded internally as '0',
meaning it was the same as halt/poweroff. If you want to run scripts at
system shutdown this was less then ideal since it meant your scripts
also ran at bootstrap.
This change is quite invasive. It introduces INIT_LEVEL (10) as the
value for runlevel S, meaning all code that parses and/or evaluates
anything for runlevel 0/S was affected and had to be reworked.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The accepted standard in Unix is to report successful executions with
exitcode 0. Therefore, map a "initctl cond get" of a condition to the
following exitcodes:
- On: 0
- Off: 1
- Flux: 255
Fixes: c3c662fe64 ("initctl: ensure 'cond get' support flux state")
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
The 'initctl cond' commands were initiallý added to only manage usr
conditions. Recently the 'cond get' command was expanded to allow
reading general conditions as well.
However, since general conditions support three states the command
returned 'on' for conditions that were in flux. This patch fixes
that oversight.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Principle of least surprise. When no even the maintainer remembers
the correct command, it is time to add an alias.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds support for a new command line option finit.config=PATH
which can be used to tell Finit to start with /etc/factory.conf instead
of /etc/finit.conf.
For the complete experience a new top-level configuration file directive
`rcsd PATH` has aslo been added. It in turn can be used by factory.conf
as follows to override /etc/finit.d:
rcsd /etc/factory.d
Manually verified in myLinux
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds support for JSON output to `initctl status` using a
`-j` or `--json` command line option.
Example:
root@anarchy:~# initctl status -j mdevd
{
"identity": "mdevd",
"description": "MDEVD Extended Hotplug Daemon",
"status": "crashed",
"exit": { "code": 100 },
"origin": "built-in",
"command": "/bin/mdevd -C -O 4",
"restarts": 10,
"pidfile": "/run/mdevd.pid",
"pid": 0,
"user": "root",
"group": "root",
"uptime": 0,
"runlevels": [ "S", 1, 2, 3, 4, 5, 7, 8, 9 ]
}
The excellent tool `jq` can be used to extract certain parts of the
output for further scripting. E.g. `initctl status -j foo | jq .exit`
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This was added for the benefit of `initctl status foo`, but we have
other users of these functions that don't expect a leading slash.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a fix to a regression introduced in e51587c. The idea is to
have 'initctl status foo' show all instances of foo, provided there are
more than one. E.g.
root@anarchy:~# initctl -t status foo
0 foo:1 stopped [--234-----] hej knekt
0 foo:2 stopped [--234-----] hej snigel
0 foo:3 stopped [--234-----] hej kalas
And not foobar:
0 foo:1 stopped [--234-----] hej knekt
0 foo:2 stopped [--234-----] hej snigel
0 foo:3 stopped [--234-----] hej kalas
0 foobar stopped [--234-----] hej foobar
If you type an exact match you can drill down like so:
root@anarchy:~# initctl status foo:1
Status : stopped (code=exited, status=0/SUCCESS, manual=yes)
Identity : foo:1
Description : hej knekt
...
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Prior to this change only service stanzas respected the manual:yes
option, now it (should) work on any svc_t type. Not tested on ttys.
The initctl tool has been given an extra manual=yes output for these
types of run/task/service entries, shown only when the manual option
is set.
Example:
root@anarchy:~# initctl status foo.sh
Status : stopped (code=exited, status=0/SUCCESS, manual=yes)
Identity : foo.sh ~~~~~~~~~~~~
Description : Hej foo
Origin : /etc/finit.d/enabled/foo.conf
Environment :
Condition(s):
Command : /root/foo.sh
PID file : none
PID : 0
User : root
Group : root
Uptime : N/A
Starts : 1
Restarts : 0 (0/10)
Runlevels : [--2345----]
Notice also the new `Starts : 1` which is a counter for the number of
starts in the current runlevel. On runlevel change it is reset to 0.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Allow filtering of conditions in raw dump, i.e., the possibility to show
only conditions of a certain type. The TYPE argument is not validated
in any way, so any prefix match is allowed, e.g.
initctl cond dump service/s
Shows all conditions for services starting with 's'.
Fixes issue #272
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>