Files
finit/doc
Joachim Wiberg d710a23513 dbus: gate the bus socket like INIT_SOCKET
The D-Bus socket was bound world read/write, on the reasoning that
SO_PEERCRED authorizes each method anyway.  That leaves the read-only
surface open to every local user, and it quietly ignores --with-group:
a system that restricts initctl to the wheel group still handed the
same service state to anyone who asked over the bus.

Bind it 0660 and chown it to the configured group, the same gate the
fallback socket has always had.  libink takes the mode as an argument
rather than assuming one, since who may connect is the embedder's
policy, not the library's.

The mode is applied at bind(), so there is no window where the socket
is more permissive than intended.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:14:48 +02:00
..
2025-07-10 16:45:48 +02:00
2026-08-13 09:28:26 +02:00
2025-08-29 12:54:06 +02:00
2026-08-01 11:25:39 +02:00
…

Introduction

Alpine screenshot{ align=right width=40% }

Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka

Finit is a process starter and supervisor designed to run as PID 1 on Linux systems. It consists of a set of plugins and can be set up using configuration files. Plugins start at hook points and can run various set up tasks and/or install event handlers that later provide runtime services, e.g., PID file monitoring, or conditions.

Features

For a more thorough overview, see the Features section.

Tip

See SysV Init Compatibility for help to quickly get going with an existing SysV or BusyBox init setup.

Origin

This project is based on the original finit by Claudio Matsuoka which was reverse engineered from syscalls of the EeePC fastinit.

Finit is developed and maintained by Joachim Wiberg at GitHub. Please file bug reports, clone it, or send pull requests for bug fixes and proposed extensions.