On the local bus SO_PEERCRED says who is calling and the kernel is the one saying it. Behind a broker one connection carries every caller, so that credential describes dbus-daemon and nothing else, and every privileged method was refused there, root included. Ask the bus driver instead. libink parks the call and hands us the sender; we ask GetConnectionUnixUser and answer when the reply lands, through the same event loop as everything else. Nothing blocks: blocking in PID 1 is why libuEv exists. That needs calls libink can make on a connection it already has, so it gained those too. Answers are cached, since a bus never reuses a unique name while it runs. Not across a restart though: a new dbus-daemon numbers from scratch and :1.7 becomes somebody else, so the cache goes when the broker does. A sender name too long to key on is refused rather than truncated, two callers sharing a truncated key would share an identity. Privilege is no longer uid 0 alone. The socket is already owned by the --with-group group, so refusing its members every method that changes anything left a wheel user able to open the bus and unable to reboot. Both gates now say the same thing. Group membership needs NSS, which the C library loads with dlopen(), so the lookup is compiled out where Finit is built to link statically. That leaves such a build root-only, which is worth saying out loud rather than leaving to be discovered. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Introduction
Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka
Finit is a process starter and supervisor designed to run as PID 1 on Linux systems. It consists of a set of plugins and can be set up using configuration files. Plugins start at hook points and can run various set up tasks and/or install event handlers that later provide runtime services, e.g., PID file monitoring, or conditions.
Features
- Runlevels, defined per service
- One-shot tasks, services (daemons), or SysV init start/stop scripts
- Runparts and
/etc/rc.localsupport - Process supervision similar to systemd
- Fine-grained privilege control:
- Linux capabilities for minimal required privileges
- Supplementary groups for multi-group resource access
- Sourcing environment files
- Conditions for network/process/custom dependencies
- Readiness notification; PID files (native) for synchronizing system startup, support for systemd sd_notify(), or s6 style too
- Limited support for tmpfiles.d(5) (no aging, attributes, or subvolumes)
- Pre/Post script actions
- Rudimentary templating support
- Tooling to enable/disable services
- Automatic reload of modified configuration files (optional)
- Built-in getty
- Built-in watchdog, with support for hand-over to watchdogd
- Built-in support for Debian/BusyBox
/etc/network/interfaces - Cgroups v2, both configuration and monitoring in
initctl top - Plugin support for customization
- Proper rescue mode with bundled
suloginfor protected maintenance shell - Switch root support for initramfs-to-real-root transitions
- Integration with watchdogd for full system supervision
- Logging to kernel ring buffer before
syslogdhas started, see the recommended sysklogd project for complete logging integration and how to log to the kernel ring buffer from scripts usinglogger
For a more thorough overview, see the Features section.
Tip
See SysV Init Compatibility for help to quickly get going with an existing SysV or BusyBox init setup.
Origin
This project is based on the original finit by Claudio Matsuoka which was reverse engineered from syscalls of the EeePC fastinit.
Finit is developed and maintained by Joachim Wiberg at GitHub. Please file bug reports, clone it, or send pull requests for bug fixes and proposed extensions.
