mirror of
https://github.com/troglobit/finit.git
synced 2026-10-02 22:13:01 +07:00
d710a235130fe5fd009ba887166be1d6315e0efc
The D-Bus socket was bound world read/write, on the reasoning that SO_PEERCRED authorizes each method anyway. That leaves the read-only surface open to every local user, and it quietly ignores --with-group: a system that restricts initctl to the wheel group still handed the same service state to anyone who asked over the bus. Bind it 0660 and chown it to the configured group, the same gate the fallback socket has always had. libink takes the mode as an argument rather than assuming one, since who may connect is the embedder's policy, not the library's. The mode is applied at bind(), so there is no window where the socket is more permissive than intended. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
…
Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.
Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka
For detailed information, explore our extensive documentation
📚 http://finit-project.github.io
For working examples, see the 🚀 contrib/ section or these tutorials:
- 🛠️ Buildroot embedded Linux,
- 📦 Debian GNU/Linux,
- ⛰️ Alpine Linux, and
- 🌌 Void Linux
Note
Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.
For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.
Languages
C
84.3%
Shell
11.9%
Makefile
2.1%
M4
1.7%

