Joachim Wiberg 63aabaa6df libink/dbus: identify the caller behind a broker
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it.  Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.

Ask the bus driver instead.  libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else.  Nothing blocks:
blocking in PID 1 is why libuEv exists.  That needs calls libink can
make on a connection it already has, so it gained those too.

Answers are cached, since a bus never reuses a unique name while it
runs.  Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does.  A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.

Privilege is no longer uid 0 alone.  The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot.  Both gates now say the same thing.

Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:06 +02:00
…
2026-08-05 17:59:09 +02:00
2024-01-06 20:02:45 +01:00
2025-07-10 15:35:46 +02:00
2025-07-10 14:34:16 +02:00
2025-12-26 13:28:43 +01:00

License Badge Release Badge GitHub Status Coverity Status Finit: Fast Init

Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.

Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka

For detailed information, explore our extensive documentation
📚 http://finit-project.github.io

Alpine screenshot

For working examples, see the 🚀 contrib/ section or these tutorials:

Note

Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.

For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.

Languages
C 84.3%
Shell 11.9%
Makefile 2.1%
M4 1.7%