Commit Graph
1626 Commits
Author SHA1 Message Date
Aaron Andersen c9fd4418e7 tmpfiles: fix f/F to apply ownership when writing content
When f or F types write content to a file, the mode and ownership
specified in the config should be applied. Previously, ownership was
only applied when create() was used (i.e., when no argument was
specified).

Now we explicitly apply mode and ownership after writing content to
the file.
2026-01-18 18:59:20 -05:00
Aaron Andersen 7206f745a2 tmpfiles: fix 'e' type to only adjust existing directories
According to tmpfiles.d(5), the 'e' type adjusts the mode and ownership
of existing paths but should not create them. Previously, mksubsys()
was used which could create directories.

Now we explicitly check if the path is an existing directory before
adjusting its permissions.
2026-01-18 18:59:20 -05:00
Aaron Andersen 25bcde12d4 tmpfiles: add support for numeric uid/gid in config files
Add parse_uid() and parse_gid() helper functions that support both
numeric IDs and name lookups. Update the d/D directory creation
handlers to use these new functions.

This allows config files to specify ownership using numeric UIDs and
GIDs instead of only usernames and group names, matching systemd-tmpfiles
behavior.
2026-01-18 18:59:20 -05:00
Aaron Andersen 7459ede806 tmpfiles: fix L+ to replace non-directory entries
The L+ type should replace existing entries with a symlink. Previously,
rmrf() was always called which is only appropriate for directories.
Now we check if the path is a directory first, and use erase() for
files and symlinks.
2026-01-18 18:59:20 -05:00
Aaron Andersen 6bf35513c3 tmpfiles: add support for config files on command line
Allow specifying one or more configuration files as command line
arguments instead of always processing all files in the standard
tmpfiles.d directories.

This enables targeted operations on specific config files:

    tmpfiles --create /etc/tmpfiles.d/myapp.conf
    tmpfiles --clean /tmp/test.conf /tmp/other.conf

When no config files are specified, the existing behavior of
processing all *.conf files in the standard directories is preserved.

Also refactors file processing into a helper function to reduce
code duplication.
2026-01-18 18:59:20 -05:00
Aaron Andersen 0b8d39329a tmpfiles: add --clean flag for age-based cleanup
Add support for the --clean (-C) flag to remove files and directories
older than the age specified in tmpfiles.d configuration entries.

The age field (6th column) in tmpfiles.d entries can now be used with
'd', 'D', and 'e' type entries to clean up old files.  Supported time
suffixes are: s (seconds), m (minutes), h (hours), d (days), w (weeks).

Example configuration:
    d /tmp/cache 0755 root root 10d

When run with --clean, files in /tmp/cache older than 10 days will be
removed.  The directory itself is preserved.

Uses a conservative cleanup approach matching systemd-tmpfiles:
 - Files: kept if ANY of atime, ctime, mtime is recent
 - Directories: kept if ANY of atime, mtime is recent (ctime excluded
   because cleanup itself updates directory ctime)

A value of "-" or "0" for age disables cleanup for that entry.

Note: x/X exclusion patterns are recognized but not yet implemented.
2026-01-18 18:59:20 -05:00
Aaron Andersen 84098dd8b7 tmpfiles: rename flags for clarity
Rename the command-line flag variables to be more descriptive:

  c_flag -> create_flag
  r_flag -> remove_flag

This improves code readability.
2026-01-18 18:59:20 -05:00
Joachim Wiberg c4463ec64f initctl: escape special characters in JSON output
Strings like command, description, and environment may contain characters
that need escaping for valid JSON, e.g., embedded quotes in command line
arguments like -V "NanoPi R2S".

Add json_escape() helper to handle quotes, backslashes, and control chars.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-18 23:26:37 +01:00
Joachim Wiberg 34bf9a7776 Fix #467: TTY services stuck in restart state after non-zero exit
When a TTY exited with non-zero code (e.g., user with shell=/sbin/false),
it would enter restart state but never recover, requiring manual restart.

The throttling logic from commit f0032ab had two issues:

  1. Duplicate exit code check in service_retry() created infinite timer loop
  2. TTYs lacked default restart_tmo, causing timer to never start

Fix by removing duplicate check and ensuring TTYs get a 2-second default
restart_tmo for proper throttling.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-12 19:31:39 +01:00
Aaron Andersen abaad560f0 Set USER and LOGNAME environment variables when dropping privileges
When a service is configured to run as a non-root user (@user), finit
correctly drops privileges via setuid() and sets HOME and PATH, but
does not set the USER and LOGNAME environment variables. They remain
set to "root" from boot time.

This causes problems for software that determines its identity from
the environment rather than getuid(). For example, rootless Podman
checks os.Getenv("USER") first when looking up subordinate UID/GID
ranges in /etc/subuid and /etc/subgid.

With USER=root but UID=1000, Podman looks up root's subuid entry
instead of the actual user's, causing applications like newuidmap
to fail. Setting USER and LOGNAME to match the actual user identity
follows POSIX conventions and matches the behavior of su, sudo, and
login.
2026-01-10 21:36:58 -05:00
Aaron Andersen 8e7d1b7bb5 Refactor: drop do_ prefix from iterate_proc() and switch_root()
The do_ prefix is conventionally reserved for local helper functions.
Move switch_root() declaration to private.h alongside iterate_proc()
and remove the now-empty initramfs.h header.
2026-01-02 18:13:00 -05:00
Aaron Andersen 373738f3d1 Implement switch_root functionality allowing Finit to serve as the init
in an initramfs, then transition to the real root filesystem.  Useful
for systems requiring early boot tasks like LUKS unlock, LVM activation,
or network boot before mounting the real root.

Adds INIT_CMD_SWITCH_ROOT API command, `initctl switch-root` subcommand,
and HOOK_SWITCH_ROOT plugin hook point.  The implementation gracefully
stops services, moves virtual filesystems (/dev, /proc, /sys, /run) to
the new root, deletes initramfs contents to free memory, then execs the
new init as PID 1.

See GitHub Discussion #292 for background.
2026-01-01 19:10:24 -05:00
Aaron Andersen e6d3eb2526 Handle already-mounted cgroups in cgroup_init()
Add handling for EBUSY when mounting cgroup2 filesystem, which occurs
when cgroups are already mounted. This can happen after switch_root
when cgroups were moved from the initramfs, or in container environments.

Verify the existing mount is actually cgroup2 before proceeding, and
track whether we mounted to avoid unmounting on error if we didn't.
2026-01-01 16:02:36 -05:00
Joachim Wiberg eb92a915d3 initctl: drop logically dead code, found by Coverity Scan
The defines already check for plain mode.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 10:46:48 +01:00
Joachim Wiberg 69a4f2c115 Drop logically dead code, found by Coverity Scan
Checks for uid and gid introduced in d017661

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-01-01 10:42:41 +01:00
Joachim Wiberg ce40e2b9d2 Rename tty services early from "init" -> "getty"
Finit has support for "Please press Enter to activate this console."
which means there's no getty yet running.  However, when profiling
systems with Finit, and embedded systems in general, a common metric
is the time from power-on to getty has started.

This commit makes sure to rename the process so that BusyBox pidof is
capable of detecting that "getty" has started.  This is mostly for the
bootchart2 project's bootchartd, the native BusyBox bootchartd does not
have this issue.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:34:04 +01:00
Joachim Wiberg d0176612c9 Default to user/group root for services and check for errors
This is a refactor of getuser() and getgroup() so that they always
return a valid user, and group, for all normal use-cases.  When an
error occurs we now handle it properly in service_fork() so as to
not attempt to start services with an invalid user/group setting
as root.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:29:28 +01:00
Joachim Wiberg 21753e26dd Set critical env PATH + SHELL early
When running Finit under boothcartd (bootchart2 project) the PATH is
lost due to a bug.  This was a wakeup, so set critical variables in
main() early, before calling fs_init().

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:29:28 +01:00
Joachim Wiberg 0dc2513b32 Follow-up to 702a606, too long string to hide cursor
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-31 23:29:27 +01:00
Joachim Wiberg d16bfa789b Follow-up to 7c8ab79, missing semicolon
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-27 15:22:09 +01:00
Joachim Wiberg f0032ab6b7 Throttle failing services, e.g., tty, on error exit code
Some 'respawn' type services, like gettys, may hog the CPU in error
states if the service immediately exits.  E.g., due to missing dev.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-27 12:32:01 +01:00
Joachim Wiberg 53c5d0e55a Always reset ownership and permissions on TTY device nodes
During /bin/login phase the TTY device node is chowned and chmodded to
the authenticated user.  It will remain in this state until the next
call to getty.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-27 12:12:18 +01:00
Joachim Wiberg 7c8ab7915f Fix #458: follow-up to be2a0ec, capabilities breaks root access
A user reports inability to re-start getty on the console after logging
out from a serial console.  After some digging it was found that the tty
was owned by the last user logged in and 600.  Even thougn getty runs as
root, it did not have permission to re-open the device node.

Turns out there was a minor bug in the new capability code that cleared
all capabilities from the root user.  A surprising amount of programs
worked just fine, but restarting getty gave it away.

The fix is to only call cap_setuid() when capabilities are set for the
service, otherwise we just fall back to setuid().

Also, refactor service_register() wrt. capabilities a bit so that we can
give users an early warning if the configuration is invalid, by adding a
parse_caps() helper function that calls cap_iab_from_text() to verify.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-27 00:49:48 +01:00
Joachim Wiberg 0d48d1df49 Merge pull request #461 from aanderse/master
Add support for supplementary groups
2025-12-26 10:28:51 +01:00
Aaron Andersen b46592e818 Add support for supplementary groups
Implement supplementary group support for services, allowing them to
access resources owned by multiple groups. Uses the @user:group,sup1,sup2
syntax to explicitly specify supplementary groups, in addition to now
reading group membership from /etc/group.
2025-12-24 09:54:37 -05:00
Joachim Wiberg 22bc218c84 Fix #462: /dev/pts mounted with wrong mode
Before this fix:

    admin@infix:~$ sudo ls -la /dev/pts/
    total 0
    drwxr-xr-x    2 root     root             0 Dec 24 08:16 .
    drwxr-xr-x   13 root     root         13340 Dec 24 08:16 ..
    cr--------    1 root     tty       136,   0 Dec 24 08:18 0
    crw-rw-rw-    1 root     root        5,   2 Dec 24 08:16 ptmx
    admin@infix:~$ mount | grep devpts
    devpts on /dev/pts type devpts (rw,nosuid,noexec,relatime,gid=5,mode=400,ptmxmode=666)

After:

    admin@infix-00-00-00:~$ sudo ls -l /dev/pts/
    total 0
    crw--w----    1 root     tty       136,   0 Dec 24 08:21 0
    crw-rw-rw-    1 root     root        5,   2 Dec 24 08:20 ptmx
    admin@infix-00-00-00:~$ mount |grep pts
    devpts on /dev/pts type devpts (rw,nosuid,noexec,relatime,gid=5,mode=620,ptmxmode=666)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-24 09:23:30 +01:00
Joachim Wiberg 702a606d26 Hide cursor at boot and shutdown
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:39 +01:00
Joachim Wiberg a3d9b6e9b1 initctl: fix remaining lingering artifacts in 'top' output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:38 +01:00
Joachim Wiberg 390a0f48c1 initctl: minor, simplify code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:38 +01:00
Joachim Wiberg f4a13687e8 initctl: resolve hierarchical cgroup limits
Cgroups v2 limits are hierarchical - a process is constrained by the
most restrictive limit in its ancestor chain, not just its immediate
cgroup.  This patch updates cg_conf() to walk up the hierarchy and
report effective limits by comparing values at each level.

This fixes incorrect "max" (unlimited) reporting in 'initctl --json
status', 'initctl cgroup', and 'initctl top' when child cgroups have
no explicit limits but parents do.

For memory.max and cpu.max: take minimum (most restrictive)
For memory.min: take maximum (most protection)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:37 +01:00
Joachim Wiberg 43ca51c3b1 initctl: add cpu/mem limits as well to json status output
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:37 +01:00
Joachim Wiberg 864b71af14 Follow-up to d87d298, prevent "cursor jumps"
Comment-out code that makes the cursor "jump" around at boot before
displaying: Please press Enter to activate this console.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-17 08:19:36 +01:00
Joachim Wiberg f908c8d43a Fix possible out-of-bounds write, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:07 +01:00
Joachim Wiberg 308f75b209 Silence false positive from Coverity Scan
51static int is_dir_empty(const char *path)
    52{
	 1. var_decl: Declaring variable namelist without initializer.
    53        struct dirent **namelist;
    54        int num;
    55

   CID 898746: (#1 of 1): Uninitialized pointer read (UNINIT)
   2. uninit_use_in_call: Using uninitialized value namelist when calling scandir.
    56        num = scandir(path, &namelist, NULL, NULL);
    57        if (num < 0)
    58                return 0;

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:07 +01:00
Joachim Wiberg d87d298c85 getty: fix terminal scrollback issues after login on console
Fixes an issue where the mouse scroll wheel and Shift+PgUp/PgDn
sometimes would not work properly after login.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:06 +01:00
Joachim Wiberg 8422d2715c initctl: fix flickering in 'top' and handle smaller screens
Drop clear screen to fix flickering in 'initctl top' output.  Also, make
sure to not garble the display if the the terminal is too small.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:34 +01:00
Joachim Wiberg 2eefaa5db6 initctl: fix file descriptor leak causing 'initctl top' to crash
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:33 +01:00
Joachim Wiberg fb0ad18d3a initctl: add CPU throttled information alongside memory usage
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:33 +01:00
Joachim Wiberg dd36116a97 Add housekeeping functions to clean up unused cgroups
This should not be needed, but for some reason we don't get events when
early processes exit, so we end up with lingering cgroups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:32 +01:00
Joachim Wiberg e756d6f8ac Allow forking sysv/services like podman to move between cgroups
The container monitor that podman forks off when starting a container
instance creates subgroups in the cgroup v2 hieararchy that we want to
reuse.  This patch adds cgroup_move_svc() which we call from the pidfile
plugins to relocate the conmon process.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:32 +01:00
Joachim Wiberg 567c695954 Start services with clone3() and place in cgroup directly
This commit activates the use of clone3() for service_fork(), to allow
Linux to create the new process directly in the correct cgroup instead
of later moving it there -- much cheaper and less error prone.

To facilitate this a few new helper cgroup functions have been added and
two new configuration directives introduced: delegate and name:leafname.
The delegate option is for running, e.g., container runtimes that want
to create their own cgroup v2 structur, and the name:leafname allows a
user to change the name of the subgroup under user/system/init.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:04:31 +01:00
Joachim Wiberg 4877aecc1e Add support for clone3() to replace fork()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 09:32:03 +01:00
Joachim Wiberg 65644f5956 Follow-up to d9a0c2d, dead code
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-14 10:04:01 +01:00
Joachim Wiberg a02760f499 Minor, constify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-14 10:00:39 +01:00
Joachim Wiberg d9a0c2dce9 Switch from PTY to pipe for service log redirection
The PTY approach caused isatty() to return true for services using
the log directive, triggering programs like fprintd (using glib) to
emit ANSI escape codes and other TTY-specific formatting in syslog.

Using a standard pipe ensures isatty() correctly returns false, so
programs produce plain text output suitable for logging.

For services that require line-buffered output, users can wrap the
command with `stdbuf -oL` as documented in doc/config/logging.md.

Fixes #455

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:13 +01:00
Joachim Wiberg 178301baf2 Change default reboot to SOC reset from WDT reset
Fixes #460

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:13 +01:00
Joachim Wiberg 4e18affa9b Allow skipping bootstrap wait with Ctrl-C
When setting up a new system with Finit it is very common to make small
logical mistakes that cause "hangs" at boot.  This is when Finit waits
for 180 sec. for run/tasks to complete before moving to the configured
runlevel.  This patch adds console input monitoring during bootstrap
wait that allows users to press Ctrl-C to skip waiting and proceed to
the configured runlevel.

When Ctrl-C is detected, all incomplete run/task/services are logged
to syslog for later troubleshooting after login.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:12 +01:00
Joachim Wiberg 21f40fb95e Allow more initctl commands in runlevels S/0/6
Relax the constraints introduced in a39ee0b, for issue #342, a bit on
when start/stop/restart/reload service can be called.  Also, allow
'initctl reload', but ignore it when the system is in runlevels S/0/6.

This makes it possible to start manual:yes type services at botostrap,
for example, which has been a common feature request.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:12 +01:00
Joachim Wiberg 24f0cee49a Ensure mount/unmount skips 'noauto' entries
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-07 09:38:11 +01:00
Joachim Wiberg fee38d4359 Merge pull request #458 from aanderse/master
Add support for Linux capabilities
2025-12-05 12:53:04 +01:00