Files
Joachim Wiberg 61b0e0f3e6 Fix #420: run services inside a PAM session
Apply a PAM session to run/task/sysv/services Finit starts, pam_limits
above all, so a service running as a given user picks up that user's
limits the way a login does.

Add a new `pam` setting for the new block format (only), like the
per-service directories, naming a file in /etc/pam.d:

    service weston {
        user    = "weston"
        pam     = "weston-autologin"
        command = "/usr/bin/weston --continue-without-input"
    }

pam_close_session() has to be called by a process still holding the
handle, and the handle does not survive exec().  Hence the keeper: it
holds the handle, drops to the service's credentials, and waits for a
parent-death signal before closing the session.  Same shape as
systemd's (sd-pam), for the same reason, and one per fork, so the
script hooks open and close their own.

The keeper closes the descriptors it inherited from Finit and only
those.  Closing everything would also take out what pam_open_session()
opened for itself, a keyring fd or a lock file, and leave the modules
to close a session with those pulled out from under them.  Closing
nothing, as (sd-pam) does, would leave it holding the write end of the
notify pipe for the service's whole lifetime and starve notify = "s6"
services of their ready signal.  So the fds open before pam_start()
are snapshotted and exactly those are closed, while the ones PAM opens
after are marked close-on-exec so the daemon does not inherit them
either.

A refused value, a denied account stack, an uninstalled pam.d file,
and a build without PAM support all keep the service from starting
rather than running it with the stacks skipped: one that quietly loses
pam_limits and its private /tmp, with nothing said.  Capabilities a
module like pam_cap.so granted are merged into the IAB Finit applies
instead of being replaced by it, which only helps a service that also
sets capabilities, the other arm being a plain setuid() with nothing
left to restore once permitted is empty.

The test sysroot gains pam_permit.so, pam_deny.so and pam_limits.so,
which ldd cannot see, libpam dlopen()s them, and the test skips when
the host has none to stage.  The negative cases pin the exit status
rather than only asserting crashed, which serv reports for any early
exit, so a bad command or an unwritable pidfile cannot pass for a
rejected session.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-09-23 16:30:14 +02:00
..
2026-08-01 11:25:38 +02:00
2026-08-05 17:59:09 +02:00
2026-08-05 17:59:11 +02:00

This section provides an overview of Finit's configuration system. For detailed information on specific topics, see the individual sections in the navigation menu.

Configuration File Syntax

A .conf file is a series of blocks. Every setting is a key inside one, so nothing has to be remembered by position:

service sysklogd {
    description = "System log daemon"
    runlevel    = "S123456789"
    envfile     = "-/etc/default/sysklogd"
    command     = "syslogd -F $SYSLOGD_ARGS"
}

Values are quoted strings, bare words, or integers. Lists use braces, and a block may carry a title, which becomes the service identity:

# shell comment
// C++ comment
/* C comment */

key      = "value"                 # string
number   = 20                      # integer
flag     = true                    # boolean
list     = { "one", "two" }        # string list
block title { key = "value" }      # titled section

path = "${HOME}/thing"             # environment expansion
include("/etc/finit.d/extra.conf") # include another file

Bare words work wherever a string is expected, so memory.max = 65M and restart = always need no quotes.

Two conventions

Keys are kebab-case, never snake_case or CamelCase: restart-sec, stop-timeout, reboot-watchdog.

Keys that take a list are plural: conditions, conflicts, capabilities, modules, extra-groups. Two imperatives keep their singular form because they are verbs rather than nouns: mknod and include.

Short forms

Nine keys have an alias. An alias may abbreviate the canonical name, or preserve the spelling the line-based format used; it never renames.

Canonical Alias Canonical Alias
description desc manual-start manual
conditions cond remain-after-exit remain
capabilities caps stop-signal halt
modules mod stop-timeout kill
envfile env

Optional paths

A leading - on a path means carry on if it is not there:

service foo {
    envfile = "-/etc/default/foo"   # skip the file if missing
    command = "-/usr/sbin/foo"      # skip the whole block if missing
}

That is the only mark meaning "optional". Two others mean something else: ! on runlevel inverts the set, e.g. runlevel = "!12345", and ~ on a condition propagates a reload from the service it names. Both are covered where they apply.

Both Formats Are Read

Finit also reads the line-based format it has always used, where a stanza is a keyword followed by values whose meaning comes from their position:

service [S123456789] env:-/etc/default/sysklogd syslogd -F $SYSLOGD_ARGS -- System log daemon

That format still works and is not going away. It is frozen at the Finit 4.x feature set, so new settings appear only in the block format, and the documentation is written in blocks throughout. To convert a file, see the Syntax Migration Guide.

There is no new file extension and no marker line. Every file is still *.conf, and Finit decides which format a file is in by reading it: if it parses as blocks it is a block file, otherwise it goes to the line-based parser. A file is one format or the other, never a mix.

Because the two are told apart before either parser commits, a typo reports its own file and line instead of being mistaken for the other format:

parse error: /etc/finit.d/foo.conf:3: no such option 'commnad'

The .conf files /etc/finit.conf and /etc/finit.d/* support many settings. Some are restricted, e.g., only available at bootstrap, runlevel S. Read on in Files & Layout for more on how to structure your .conf files.

For details on restrictions, see Limitations.