mirror of
https://github.com/troglobit/finit.git
synced 2026-10-01 05:22:48 +07:00
63aabaa6df5afad0eb3d50417d7f4402de103475
On the local bus SO_PEERCRED says who is calling and the kernel is the one saying it. Behind a broker one connection carries every caller, so that credential describes dbus-daemon and nothing else, and every privileged method was refused there, root included. Ask the bus driver instead. libink parks the call and hands us the sender; we ask GetConnectionUnixUser and answer when the reply lands, through the same event loop as everything else. Nothing blocks: blocking in PID 1 is why libuEv exists. That needs calls libink can make on a connection it already has, so it gained those too. Answers are cached, since a bus never reuses a unique name while it runs. Not across a restart though: a new dbus-daemon numbers from scratch and :1.7 becomes somebody else, so the cache goes when the broker does. A sender name too long to key on is refused rather than truncated, two callers sharing a truncated key would share an identity. Privilege is no longer uid 0 alone. The socket is already owned by the --with-group group, so refusing its members every method that changes anything left a wheel user able to open the bus and unable to reboot. Both gates now say the same thing. Group membership needs NSS, which the C library loads with dlopen(), so the lookup is compiled out where Finit is built to link statically. That leaves such a build root-only, which is worth saying out loud rather than leaving to be discovered. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
…
Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.
Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka
For detailed information, explore our extensive documentation
📚 http://finit-project.github.io
For working examples, see the 🚀 contrib/ section or these tutorials:
- 🛠️ Buildroot embedded Linux,
- 📦 Debian GNU/Linux,
- ⛰️ Alpine Linux, and
- 🌌 Void Linux
Note
Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.
For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.
Languages
C
84.3%
Shell
11.9%
Makefile
2.1%
M4
1.7%

