more things

This commit is contained in:
Hedy88 2026-08-27 22:50:44 +01:00
commit 6e60709283
No known key found for this signature in database
15 changed files with 1403 additions and 294 deletions

View file

@ -15,14 +15,13 @@ format.
roadmap:
- user/group privilege drop (`user`, `group`, supplementary groups)
- `SIGCHLD` crash-window limiting (rate-limited restarts; `crash-threshold`/
`crash-window` are parsed but not yet enforced by the reaper)
- dependency ordering between services
- `SIGCHLD` crash-window limiting (rate-limited restarts)
- property triggers (`property:<k>=<v>`) and `setprop`/`getprop`
- per-service logging to files
- `reboot`/`poweroff` path with ordered unmount
- `SIGHUP` config reload
- SELinux
- readiness/socket activation
## building
@ -62,17 +61,18 @@ See [`etc/init.rc`](etc/init.rc) for a complete example.
```rc
service NAME /path/to/exe [args...]
user root|other # privilege level (drop, planned)
group GROUP [GROUP...]
oneshot # run once and exit, never respawn
disabled # not started by the boot sequence
console # bind stdio to /dev/console
class NAME # grouping (default "default")
respawn never|on-failure|always # restart policy (default always)
crash-threshold N # restarts allowed per window
crash-window SECS
setenv K=V # extra environment (repeatable)
cwd /path
user = root|other # uid after the privilege drop (name or number)
group = GROUP [GROUP...] # primary gid + supplementary groups (names/numbers)
oneshot # run once and exit, never respawn
disabled # not started by the boot sequence
console # bind stdio to /dev/console
class = NAME # grouping (default "default")
respawn = never|on-failure|always # restart policy (default always)
crash-threshold = N # restarts allowed per window
crash-window = SECS
seclabel = CONTEXT # SELinux exec context (--selinux build)
setenv = K=V # extra environment (repeatable)
cwd = /path
```
### actions
@ -91,6 +91,62 @@ on TRIGGER
log message
```
boot triggers fire in order: `early-init`, `init`, `boot`. `shutdown` is
reserved (planned wiring to the signal path). property/`service-*` triggers
are on the roadmap.
boot triggers fire in order: `early-init`, `init`, `boot`. `shutdown` triggers
fire when the system is winding down. property/`service-*` triggers are on the
roadmap.
Services run as `root` by default; `user`/`group` trigger a full privilege
drop (supplementary groups, then gid, then uid) before exec.
## control
A running init listens on an abstract unix socket (`@bajia`). The bundled
`bctl` client drives it:
```sh
bctl status # list services + state
bctl start NAME # start a service
bctl stop NAME # graceful stop (SIGTERM)
bctl restart NAME # restart a service
bctl trigger EVENT # fire an action trigger
bctl reload # re-parse init.rc and reconcile services
bctl shutdown [poweroff|reboot]
```
`reload` (also `kill -HUP 1`) re-parses the rc files: removed services are
stopped, added services registered, and running services whose definition
changed are restarted with the new definition. A parse error rejects the
reload and keeps the live config.
## SELinux (experimental)
SELinux support is opt-in (`configure.py --selinux`, adds `-DBAJIA_SELINUX`
+ `-lselinux`). With it enabled, PID 1 mounts selinuxfs, loads the policy
from `/etc/selinux/config`, calls `selinux_restorecon` on the core tree, and
applies a per-service exec label via the `seclabel = CONTEXT` service option.
To bring up a policy without hand-writing one, reuse the host's installed
policy (Fedora/SELinux hosts have one at `/etc/selinux/<type>/`) in
permissive mode:
```sh
python3 tools/run_vm.py --selinux
```
This bundles the host `policy.policy.<vers>` and `file_contexts` into the
initramfs, writes `SELINUX=permissive`, and boots `selinux=1 enforcing=0`.
Watch the serial console for `selinux: policy loaded, enforcing=0`; a
`selinux-probe` service prints the runtime exec contexts:
```
probe-ctx=system_u:system_r:init_t:s0 init-ctx=system_u:system_r:kernel_t:s0
```
The guest kernel must support SELinux and the policy version must match the
kernel's (`cat /sys/fs/selinux/policyvers`). Once permissive is stable,
read `avc: denied` lines from dmesg and iterate toward a minimal custom
policy with `checkpolicy`/`audit2allow`, then flip to `enforcing=1`.
Limitations: uses the dynamic libselinux (no static build on Fedora), so the
`--selinux` init is dynamically linked and the loader + libs (`libselinux`,
`libpcre2-8`, glibc) are bundled into the initramfs.