mirror of
https://github.com/troglobit/finit.git
synced 2026-10-05 07:13:44 +07:00
7c8ab7915f984ddce576847d4b49557c8039e34a
be2a0ec, capabilities breaks root access
A user reports inability to re-start getty on the console after logging out from a serial console. After some digging it was found that the tty was owned by the last user logged in and 600. Even thougn getty runs as root, it did not have permission to re-open the device node. Turns out there was a minor bug in the new capability code that cleared all capabilities from the root user. A surprising amount of programs worked just fine, but restarting getty gave it away. The fix is to only call cap_setuid() when capabilities are set for the service, otherwise we just fall back to setuid(). Also, refactor service_register() wrt. capabilities a bit so that we can give users an early warning if the configuration is invalid, by adding a parse_caps() helper function that calls cap_iab_from_text() to verify. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
…
Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.
Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka
For detailed information, explore our extensive documentation
📚 http://finit-project.github.io
For working examples, see the 🚀 contrib/ section or these tutorials:
- 🛠️ Buildroot embedded Linux,
- 📦 Debian GNU/Linux,
- ⛰️ Alpine Linux, and
- 🌌 Void Linux
Note
Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.
For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.
Languages
C
84.3%
Shell
11.9%
Makefile
2.1%
M4
1.7%

