Files
finit/test
Joachim Wiberg 63aabaa6df libink/dbus: identify the caller behind a broker
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it.  Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.

Ask the bus driver instead.  libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else.  Nothing blocks:
blocking in PID 1 is why libuEv exists.  That needs calls libink can
make on a connection it already has, so it gained those too.

Answers are cached, since a bus never reuses a unique name while it
runs.  Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does.  A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.

Privilege is no longer uid 0 alone.  The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot.  Both gates now say the same thing.

Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:06 +02:00
..
2026-08-13 09:28:26 +02:00
2026-08-13 09:28:26 +02:00
2023-02-05 18:19:23 +01:00
2025-02-11 10:17:33 +01:00

Finit Test Suite

Finit comes with a set of tests and a small framework for running them. Contributors are encouraged to write new tests when implementing features, or fixing bugs.

Each test is run in isolation, in it's own namespace. Finit will therefore be able to be launched as PID 1. Since it's also running with it's own root directory it will be able to function properly without having any super user privileges in the host environment.

Running tests

To run the test suite, first build Finit, e.g:

./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var --enable-testserv-plugin
make -j9 clean all

Then run (parallel does not work atm):

make check

make check will set up the required assets for the test environment, and then run the full set of tests. The environment is not removed afterwards so at this point individual tests can be executed without having to run the entire test suite, which is handy when developing new tests or debugging existing test. To execute an individual test, simply invoke the script containing it:

./test/name-of-the-test.sh

Another way to run a single (or more) test(s) is to define the TESTS environment variable:

TESTS="start-kill-service" make check