Files
finit/doc
Joachim Wiberg ddda905487 service: warn when capabilities cannot take effect
An ambient capability only reaches the effective set when euid is
non-zero, so a service that pairs `capabilities = { "^cap_..." }` with a
root user gets none of the restriction it asks for, and keeps the full
root set instead.  Finit read the list, applied it, and said nothing.  A
build without libcap dropped the list on the floor just as quietly.

Both now warn, naming the service:

    nginx: ambient capabilities ('^') have no effect as root, use a
    non-root user, or '%' and '!' entries

The ambient entries are read back from the parsed IAB value rather than
matched in the text, so inheritable ('%') and bounding ('!') entries stay
silent -- those work fine as root.

The warning repeats when the .conf files are re-read on runlevel change,
as parse warnings here already do.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:23:35 +02:00
..
2025-07-10 16:45:48 +02:00
2025-08-29 12:54:06 +02:00

Introduction

Alpine screenshot{ align=right width=40% }

Reverse engineered from the EeePC fastinit
"gaps filled with frog DNA …"
— Claudio Matsuoka

Finit is a process starter and supervisor designed to run as PID 1 on Linux systems. It consists of a set of plugins and can be set up using configuration files. Plugins start at hook points and can run various set up tasks and/or install event handlers that later provide runtime services, e.g., PID file monitoring, or conditions.

Features

For a more thorough overview, see the Features section.

Tip

See SysV Init Compatibility for help to quickly get going with an existing SysV or BusyBox init setup.

Origin

This project is based on the original finit by Claudio Matsuoka which was reverse engineered from syscalls of the EeePC fastinit.

Finit is developed and maintained by Joachim Wiberg at GitHub. Please file bug reports, clone it, or send pull requests for bug fixes and proposed extensions.