__msg_parse() turns bytes off a socket into pointers, before anything
has vouched for the peer, and it is the only place in libink that
does. It had no test of its own beyond whatever the other tests
happened to send it, all of it well-formed.
The target checks the parser's contract, not merely that it survived.
A header field must point into the header field array, and terminate
inside it, and the parse must never claim more bytes than it was
handed. Crash-only would pass a parser that walked into the body and
returned fields from there, since those bytes were handed over too.
The expected bounds are derived from the raw header rather than from
the parser, so the two have to agree independently.
Every input is copied into an allocation sized to it first. Reading
past the end of a roomy buffer stays inside the allocation and the
sanitizer never sees it; against an exact one the same read is a
fault, which is where the sharpest findings come from.
Under libFuzzer it is an ordinary fuzz target and named files replay,
which is how a find gets reproduced. With no arguments it runs a
fixed sweep -- every truncation, every single-byte corruption, every
value of the length that decides where the header ends, and seeded
garbage -- so the suite covers the same contract on every build,
without clang or a corpus in the tree. It takes 40 ms.
CI fuzzes it properly on every pull request, keeps the crashers, and
carries the corpus between runs so it reaches deeper over time than
any single run can. Note that clang links the fuzzer runtime against
the newest GCC tree it finds, so the libstdc++ headers have to match
that one and not the default compiler, which is worth saying since
installing the obvious package leaves you exactly where you started.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Runlevel and version are state, not actions, so they belong behind
org.freedesktop.DBus.Properties rather than another method each.
Finit also claims org.finit on the system bus when it finds one, so
ordinary D-Bus clients can reach it without knowing about
/run/finit/bus. Opportunistic on purpose: no dbus-daemon is a normal
state for the systems Finit runs on, not an error to report.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Finit had no way to answer the question every service manager gets
asked: what is running, and change it. D-Bus is how the rest of
userspace asks, but linking libdbus, sd-bus or GIO into PID 1 buys a
dependency, an allocator and a main loop we do not control.
So libink: the wire format, an object tree, and a bus of Finit's own
at /run/finit/bus, gated like INIT_SOCKET. It speaks the standard
org.freedesktop.DBus, .Peer, .Introspectable interfaces, and Finit's
own Manager1, Service1 and Cond1 on top. Methods that change
something are marked privileged and answered only for a caller the
kernel vouched for, via SO_PEERCRED.
Server and client both, since initctl is the first thing that needs
to talk to it, and its Start/Stop/Restart/Reload now go over the bus
rather than the legacy socket.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit introduces a bare-bones replacement for libsystemd:
- Build .so file and add --with-libsystemd to configure
- Add capabilities support to test/src/serv.c
- Update tests to account for a Finit built w/o libsystemd support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We cannot rely on the auto-detection of Bash completion dir during 'make
distcheck' because autotools does not use DESTDIR, only --prefix for the
install check, and pkg-config returns a system path.
Also, show detected path in configure summary for debug.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This change adds very basic tmpfiles.d/ support to Finit. Much of the
basic types are supported, but not all, so for now, please check the
code for details on what is working.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This adds support for bringing up the system with an alternate fstab at
boot. E.g., when using a primary/secondary setup for boot partitions.
By default /etc/fstab is read, like before, this can now be changed
using configure --with-fstab=/path/to/fstab.primary, which sets the
default that can be overridden using finit.fstab=/etc/fstab.secondary
If mounting, or fsck, fails in any way, Finit calls its own bundled
sulogin, or the system sulogin(8), to let the user handle the issue.
If there is no sulogin available, Finit will try to start up in its
rescue.conf boot mode.
Please note, in either of these rescue modes, use `reboot -f` to get the
system to reboot. Finit is on pause in the background in rescue mode
and cannot be relied on (since there may not be any writable filesystems
available.).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Planned changes will directly change the behavior of conditions, and
instead of having to implement compatibility wrappers and further
complicate the code, we've taken the decision to go for v4 directly.
This allows us to also rip out the complex inetd support.
Other changes in this commit:
- Revert back to .tar.gz distribution archives, by popular demand
- Add .sha256 checksum for .tar.gz archive
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In massively parallel builds we've seen finit fail in the install phase
of the contrib section with:
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/getty.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/keymap.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/modules.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/klogd.conf': No such file or directory
ln: failed to create symbolic link '/home/bob/jenkins/workspace/WeOS-feature_5.x_igmp-mld-snooping/staging/share/doc/finit/contrib/alpine/finit.d/syslogd.conf': No such file or directory
This patch is a countermeasure since fixing the root cause may take a
while (to be prioritized).
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds a simple but effective watchdog daemon with support for
handover to an external daemon, should one register using the API.
Disabled by default, enable by:
configure --enable-watchdog
The watchdog forks to the background, opening /dev/watchdog setting a
three second timeout, and kicking every second. At shutdown/reboot the
daemon will receive SIGPWR from Finit to exit and cause a WDT reboot.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds initial support for handling MD RAID arrays. Adding
a pass at the very end of the shutdown sequence to signal any external
RAID controller to clear its state before we proceed to halt/reboot.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch adds support for a more fine grained approach to what
filesystems are unmounted at shutdown/reboot. This so we later
can add support for `mdadm --wait-clean --scan`, which relies on
/proc, /sys, and /dev being there before we call reboot().
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
The TTY handling in Finit has always been a bit of a patch work. This
commit is an attempt at a first cleanup and simplification.
Included is a brand new built-in getty which should work fine on both
virtual and serial consoles. It is however completely untested on the
latter serial consoles.
Still TODO: add support for /etc/securetty, add support for actually
setting TERM when calling /bin/login.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This patch fixes regressions in --enable-static introduced with the
conversion to the GNU configure and build system.
The default link flag to libtool is set to -static-libtool-libs, meaning
not a fully static build -- the C library will still be used as an .so
which is usually what people want -- whereas libite (-lite) and libuEv
are linked statically.
$ ldd /sbin/finit /sbin/initctl
/sbin/finit:
linux-vdso.so.1 => (0x00007ffffde62000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007f6979ad8000)
/lib64/ld-linux-x86-64.so.2 (0x000055d893e96000)
/sbin/initctl:
linux-vdso.so.1 => (0x00007ffed0dd6000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007feb3a29c000)
/lib64/ld-linux-x86-64.so.2 (0x00005556ebd2b000)
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Finit <3 did not use GNU configure and build system. This patch adds an
install-dev rule that is used by some to install required headers for
external plugin developers.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>