Joachim Wiberg ddda905487 service: warn when capabilities cannot take effect
An ambient capability only reaches the effective set when euid is
non-zero, so a service that pairs `capabilities = { "^cap_..." }` with a
root user gets none of the restriction it asks for, and keeps the full
root set instead.  Finit read the list, applied it, and said nothing.  A
build without libcap dropped the list on the floor just as quietly.

Both now warn, naming the service:

    nginx: ambient capabilities ('^') have no effect as root, use a
    non-root user, or '%' and '!' entries

The ambient entries are read back from the parsed IAB value rather than
matched in the text, so inheritable ('%') and bounding ('!') entries stay
silent -- those work fine as root.

The warning repeats when the .conf files are re-read on runlevel change,
as parse warnings here already do.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:23:35 +02:00
…
2025-07-10 15:35:46 +02:00
2025-07-10 14:34:16 +02:00
2025-12-26 13:28:43 +01:00

License Badge Release Badge GitHub Status Coverity Status Finit: Fast Init

Finit is a fast, simple alternative to SysV init and systemd, designed for small and embedded Linux systems. It can also run on desktop and server systems, like finix.

Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka

For detailed information, explore our extensive documentation
📚 http://finit-project.github.io

Alpine screenshot

For working examples, see the 🚀 contrib/ section or these tutorials:

Note

Finit can run on various Linux distributions, but the bundled install scripts are examples only. They have been tested on amd64 (x86_64) systems with standard configurations.

For embedded systems, see these Buildroot-based examples: myLinux, Infix, or br2-finit-demo.

Languages
C 84.3%
Shell 11.9%
Makefile 2.1%
M4 1.7%