Files
finit/mkdocs.yml
T
Joachim Wiberg 61b0e0f3e6 Fix #420: run services inside a PAM session
Apply a PAM session to run/task/sysv/services Finit starts, pam_limits
above all, so a service running as a given user picks up that user's
limits the way a login does.

Add a new `pam` setting for the new block format (only), like the
per-service directories, naming a file in /etc/pam.d:

    service weston {
        user    = "weston"
        pam     = "weston-autologin"
        command = "/usr/bin/weston --continue-without-input"
    }

pam_close_session() has to be called by a process still holding the
handle, and the handle does not survive exec().  Hence the keeper: it
holds the handle, drops to the service's credentials, and waits for a
parent-death signal before closing the session.  Same shape as
systemd's (sd-pam), for the same reason, and one per fork, so the
script hooks open and close their own.

The keeper closes the descriptors it inherited from Finit and only
those.  Closing everything would also take out what pam_open_session()
opened for itself, a keyring fd or a lock file, and leave the modules
to close a session with those pulled out from under them.  Closing
nothing, as (sd-pam) does, would leave it holding the write end of the
notify pipe for the service's whole lifetime and starve notify = "s6"
services of their ready signal.  So the fds open before pam_start()
are snapshotted and exactly those are closed, while the ones PAM opens
after are marked close-on-exec so the daemon does not inherit them
either.

A refused value, a denied account stack, an uninstalled pam.d file,
and a build without PAM support all keep the service from starting
rather than running it with the stacks skipped: one that quietly loses
pam_limits and its private /tmp, with nothing said.  Capabilities a
module like pam_cap.so granted are merged into the IAB Finit applies
instead of being replaced by it, which only helps a service that also
sets capabilities, the other arm being a plain setuid() with nothing
left to restore once permitted is empty.

The test sysroot gains pam_permit.so, pam_deny.so and pam_limits.so,
which ldd cannot see, libpam dlopen()s them, and the test skips when
the host has none to stage.  The negative cases pin the exit status
rather than only asserting crashed, which serv reports for any early
exit, so a bad command or an unwritable pidfile cannot pass for a
rejected session.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-09-23 16:30:14 +02:00

158 lines
4.0 KiB
YAML

site_name: User's Guide
site_description: Fast Init for Linux Systems
site_url: https://finit-project.github.io
repo_url: https://github.com/finit-project/finit
repo_name: Finit Project
copyright: Copyright &copy; 2008-2026 Joachim Wiberg
docs_dir: doc/
edit_uri: edit/master/doc/
extra_css:
- extra.css
exclude_docs: |
TODO.md
ChangeLog.md
README.md
nav:
- Getting Started:
- Introduction: index.md
- Features: features.md
- Quick Example: example.md
- Building: build.md
- Configuration:
- Overview: config/index.md
- Migration Guide: config/migration.md
- Files & Layout: config/files.md
- Conditions: conditions.md
- Runlevels: config/runlevels.md
- One-shot Tasks: config/task-and-run.md
- Services:
- Syntax: config/services.md
- Options: config/service-opts.md
- Environment: config/service-env.md
- Synchronization: config/service-sync.md
- Wrapper Scripts: config/service-wrappers.md
- Run-parts Scripts: config/runparts.md
- TTY & Console: config/tty.md
- Environment Variables: config/env.md
- Logging: config/logging.md
- Cgroups: config/cgroups.md
- Capabilities: config/capabilities.md
- PAM Sessions: config/pam.md
- Templating: config/templating.md
- SysV Compatibility: config/sysv.md
- Rescue Mode: config/rescue.md
- Limitations: config/limitations.md
- Usage:
- Commands & Status: initctl.md
- Switch Root: switchroot.md
- Rebooting & Halting: commands.md
- Command Line Options: cmdline.md
- Managing Services: service.md
- Signals: signals.md
- Reference:
- Runlevels Overview: runlevels.md
- Runparts & rc.local: runparts.md
- Plugins: plugins.md
- Watchdog: watchdog.md
- Device Manager: keventd.md
- D-Bus Integration: dbus.md
- Service State Machine: state-machine.md
- Distributions: distro.md
- Requirements: requirements.md
theme:
logo: img/logo.png
name: material
features:
- toc.follow
# - toc.integrate
- navigation.path
- navigation.instant
- navigation.instant.progress
- navigation.tracking
- navigation.indexes
# - navigation.tabs
# - navigation.sections
# - navigation.expand
# - navigation.top
# - navigation.footer
- search.highlight
- search.share
# - content.action.edit
- content.code.copy
- content.code.annotate
- content.footnote.tooltips
palette:
- media: "(prefers-color-scheme: light)"
scheme: default
primary: orange
accent: orange
toggle:
icon: material/weather-night
name: Switch to dark mode
- media: "(prefers-color-scheme: dark)"
scheme: slate
primary: black
accent: black
toggle:
icon: material/weather-sunny
name: Switch to light mode
markdown_extensions:
- admonition
- attr_list
- footnotes
- pymdownx.blocks.caption
- pymdownx.critic
- pymdownx.caret
- pymdownx.keys
- pymdownx.mark
- pymdownx.tilde
- pymdownx.details
- pymdownx.superfences
- pymdownx.highlight:
anchor_linenums: true
- pymdownx.inlinehilite
- pymdownx.emoji:
emoji_index: !!python/name:material.extensions.emoji.twemoji
emoji_generator: !!python/name:material.extensions.emoji.to_svg
- pymdownx.snippets
- pymdownx.tabbed:
alternate_style: true
- tables
- toc:
permalink: true
plugins:
- search
- callouts
- glightbox:
touchNavigation: true
loop: false
effect: zoom
slide_effect: slide
width: 100%
height: auto
zoomable: true
draggable: true
skip_classes:
- custom-skip-class-name
auto_themed: true
auto_caption: false
caption_position: bottom
background: black
shadow: false
manual: false
extra:
generator: false
homepage: https://finit-project.github.io/
version:
provider: mike
social:
- icon: fontawesome/brands/github
link: https://github.com/finit-project/finit
name: Finit on GitHub