more things
This commit is contained in:
parent
1cd4394841
commit
6e60709283
15 changed files with 1403 additions and 294 deletions
92
README.md
92
README.md
|
|
@ -15,14 +15,13 @@ format.
|
|||
|
||||
roadmap:
|
||||
|
||||
- user/group privilege drop (`user`, `group`, supplementary groups)
|
||||
- `SIGCHLD` crash-window limiting (rate-limited restarts; `crash-threshold`/
|
||||
`crash-window` are parsed but not yet enforced by the reaper)
|
||||
- dependency ordering between services
|
||||
- `SIGCHLD` crash-window limiting (rate-limited restarts)
|
||||
- property triggers (`property:<k>=<v>`) and `setprop`/`getprop`
|
||||
- per-service logging to files
|
||||
- `reboot`/`poweroff` path with ordered unmount
|
||||
- `SIGHUP` config reload
|
||||
- SELinux
|
||||
- readiness/socket activation
|
||||
|
||||
## building
|
||||
|
||||
|
|
@ -62,17 +61,18 @@ See [`etc/init.rc`](etc/init.rc) for a complete example.
|
|||
|
||||
```rc
|
||||
service NAME /path/to/exe [args...]
|
||||
user root|other # privilege level (drop, planned)
|
||||
group GROUP [GROUP...]
|
||||
oneshot # run once and exit, never respawn
|
||||
disabled # not started by the boot sequence
|
||||
console # bind stdio to /dev/console
|
||||
class NAME # grouping (default "default")
|
||||
respawn never|on-failure|always # restart policy (default always)
|
||||
crash-threshold N # restarts allowed per window
|
||||
crash-window SECS
|
||||
setenv K=V # extra environment (repeatable)
|
||||
cwd /path
|
||||
user = root|other # uid after the privilege drop (name or number)
|
||||
group = GROUP [GROUP...] # primary gid + supplementary groups (names/numbers)
|
||||
oneshot # run once and exit, never respawn
|
||||
disabled # not started by the boot sequence
|
||||
console # bind stdio to /dev/console
|
||||
class = NAME # grouping (default "default")
|
||||
respawn = never|on-failure|always # restart policy (default always)
|
||||
crash-threshold = N # restarts allowed per window
|
||||
crash-window = SECS
|
||||
seclabel = CONTEXT # SELinux exec context (--selinux build)
|
||||
setenv = K=V # extra environment (repeatable)
|
||||
cwd = /path
|
||||
```
|
||||
|
||||
### actions
|
||||
|
|
@ -91,6 +91,62 @@ on TRIGGER
|
|||
log message
|
||||
```
|
||||
|
||||
boot triggers fire in order: `early-init`, `init`, `boot`. `shutdown` is
|
||||
reserved (planned wiring to the signal path). property/`service-*` triggers
|
||||
are on the roadmap.
|
||||
boot triggers fire in order: `early-init`, `init`, `boot`. `shutdown` triggers
|
||||
fire when the system is winding down. property/`service-*` triggers are on the
|
||||
roadmap.
|
||||
|
||||
Services run as `root` by default; `user`/`group` trigger a full privilege
|
||||
drop (supplementary groups, then gid, then uid) before exec.
|
||||
|
||||
## control
|
||||
|
||||
A running init listens on an abstract unix socket (`@bajia`). The bundled
|
||||
`bctl` client drives it:
|
||||
|
||||
```sh
|
||||
bctl status # list services + state
|
||||
bctl start NAME # start a service
|
||||
bctl stop NAME # graceful stop (SIGTERM)
|
||||
bctl restart NAME # restart a service
|
||||
bctl trigger EVENT # fire an action trigger
|
||||
bctl reload # re-parse init.rc and reconcile services
|
||||
bctl shutdown [poweroff|reboot]
|
||||
```
|
||||
|
||||
`reload` (also `kill -HUP 1`) re-parses the rc files: removed services are
|
||||
stopped, added services registered, and running services whose definition
|
||||
changed are restarted with the new definition. A parse error rejects the
|
||||
reload and keeps the live config.
|
||||
|
||||
## SELinux (experimental)
|
||||
|
||||
SELinux support is opt-in (`configure.py --selinux`, adds `-DBAJIA_SELINUX`
|
||||
+ `-lselinux`). With it enabled, PID 1 mounts selinuxfs, loads the policy
|
||||
from `/etc/selinux/config`, calls `selinux_restorecon` on the core tree, and
|
||||
applies a per-service exec label via the `seclabel = CONTEXT` service option.
|
||||
|
||||
To bring up a policy without hand-writing one, reuse the host's installed
|
||||
policy (Fedora/SELinux hosts have one at `/etc/selinux/<type>/`) in
|
||||
permissive mode:
|
||||
|
||||
```sh
|
||||
python3 tools/run_vm.py --selinux
|
||||
```
|
||||
|
||||
This bundles the host `policy.policy.<vers>` and `file_contexts` into the
|
||||
initramfs, writes `SELINUX=permissive`, and boots `selinux=1 enforcing=0`.
|
||||
Watch the serial console for `selinux: policy loaded, enforcing=0`; a
|
||||
`selinux-probe` service prints the runtime exec contexts:
|
||||
|
||||
```
|
||||
probe-ctx=system_u:system_r:init_t:s0 init-ctx=system_u:system_r:kernel_t:s0
|
||||
```
|
||||
|
||||
The guest kernel must support SELinux and the policy version must match the
|
||||
kernel's (`cat /sys/fs/selinux/policyvers`). Once permissive is stable,
|
||||
read `avc: denied` lines from dmesg and iterate toward a minimal custom
|
||||
policy with `checkpolicy`/`audit2allow`, then flip to `enforcing=1`.
|
||||
|
||||
Limitations: uses the dynamic libselinux (no static build on Fedora), so the
|
||||
`--selinux` init is dynamically linked and the loader + libs (`libselinux`,
|
||||
`libpcre2-8`, glibc) are bundled into the initramfs.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue