Joachim Wiberg d710a23513 dbus: gate the bus socket like INIT_SOCKET
The D-Bus socket was bound world read/write, on the reasoning that
SO_PEERCRED authorizes each method anyway.  That leaves the read-only
surface open to every local user, and it quietly ignores --with-group:
a system that restricts initctl to the wheel group still handed the
same service state to anyone who asked over the bus.

Bind it 0660 and chown it to the configured group, the same gate the
fallback socket has always had.  libink takes the mode as an argument
rather than assuming one, since who may connect is the embedder's
policy, not the library's.

The mode is applied at bind(), so there is no window where the socket
is more permissive than intended.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:14:48 +02:00
…
2026-08-05 17:59:09 +02:00
2025-07-10 15:35:46 +02:00
2025-07-10 14:34:16 +02:00
2025-12-26 13:28:43 +01:00

License Badge Release Badge GitHub Status Coverity Status Finit: Fast Init

Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.

Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka

For detailed information, explore our extensive documentation
📚 http://finit-project.github.io

Alpine screenshot

For working examples, see the 🚀 contrib/ section or these tutorials:

Note

Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.

For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.

Languages
C 84.3%
Shell 11.9%
Makefile 2.1%
M4 1.7%