]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
20 months agoportablectl: add --force attach/detach
Luca Boccassi [Thu, 29 Sep 2022 21:41:55 +0000 (22:41 +0100)] 
portablectl: add --force attach/detach

Allows to skip check that ensures units must not be running.

I have a use case that would use reattach, except the orchestrator
is using a non-standard versioning scheme, so image matching cannot
work. As a workaround, need to be able to detach and then attach
manually, without stopping the units to avoid extended downtimes
and loss of FD store.

20 months agoMerge pull request #24831 from poettering/dbus-dump-doc
Franck Bui [Fri, 30 Sep 2022 12:23:59 +0000 (14:23 +0200)] 
Merge pull request #24831 from poettering/dbus-dump-doc

man: clarify that D-Bus Dump() call is a debugging interface with no guarantees

20 months agoresolve: do not cache mDNS goodbye packet
Yu Watanabe [Thu, 29 Sep 2022 07:50:27 +0000 (16:50 +0900)] 
resolve: do not cache mDNS goodbye packet

Fixes #24842.

20 months agoMerge pull request #24820 from keszybz/tmpfiles-warning
Yu Watanabe [Fri, 30 Sep 2022 09:50:31 +0000 (18:50 +0900)] 
Merge pull request #24820 from keszybz/tmpfiles-warning

Downgrade warning about unitialized-/etc in tmpfiles

20 months agotest: wait until the unit finishes before checking the log
Frantisek Sumsal [Fri, 30 Sep 2022 07:31:47 +0000 (09:31 +0200)] 
test: wait until the unit finishes before checking the log

Otherwise we might read an incomplete log and fail:

```
test_added_after (__main__.ExecutionResumeTest) ... FAIL
test_added_before (__main__.ExecutionResumeTest) ... ok
test_interleaved (__main__.ExecutionResumeTest) ... ok
test_issue_6533 (__main__.ExecutionResumeTest) ... ok
test_no_change (__main__.ExecutionResumeTest) ... ok
test_removal (__main__.ExecutionResumeTest) ... ok
test_swapped (__main__.ExecutionResumeTest) ... ok

======================================================================
FAIL: test_added_after (__main__.ExecutionResumeTest)
----------------------------------------------------------------------
Traceback (most recent call last):
  File "/build/./test/test-exec-deserialization.py", line 152, in test_added_after
    self.check_output(expected_output)
  File "/build/./test/test-exec-deserialization.py", line 107, in check_output
    self.assertEqual(output, expected_output)
AssertionError: 'foo\n' != 'foo\nbar\n'
  foo
+ bar

----------------------------------------------------------------------
Ran 7 tests in 27.470s
```

20 months agotest: kill the machine on oops/panic/soft_lockup
Frantisek Sumsal [Fri, 30 Sep 2022 06:48:53 +0000 (08:48 +0200)] 
test: kill the machine on oops/panic/soft_lockup

Otherwise the machine will hang on the panic until the timeout happens,
which might waste quite a considerable amount of time in certain cases.

20 months agomanager: make clear internal Dump() logic is debugging only. 24831/head
Lennart Poettering [Tue, 27 Sep 2022 10:18:47 +0000 (12:18 +0200)] 
manager: make clear internal Dump() logic is debugging only.

20 months agoman: document the Dump() calls of the PID 1 D-Bus interface, and what they are
Lennart Poettering [Tue, 27 Sep 2022 10:18:43 +0000 (12:18 +0200)] 
man: document the Dump() calls of the PID 1 D-Bus interface, and what they are

20 months agokbd-model-map: correct variants for cz-qwerty to include comma
Adam Williamson [Thu, 29 Sep 2022 19:58:03 +0000 (12:58 -0700)] 
kbd-model-map: correct variants for cz-qwerty to include comma

As explained by @poncovka , the 'xvariant' string should contain
the same number of comma-separated elements as 'xlayout'. When
we have two layouts we need two items in xvariant, in this case
one of them is empty.

See https://github.com/rhinstaller/anaconda/pull/4355#pullrequestreview-1119913870
for @poncovka's full explanation.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
20 months agoMerge pull request #24865 from yuwata/udevadm-tweaks
Frantisek Sumsal [Thu, 29 Sep 2022 22:01:48 +0000 (00:01 +0200)] 
Merge pull request #24865 from yuwata/udevadm-tweaks

udevadm: fix misleading error message

20 months agoAdd special keyboard combos for Thinkpad P1 Gen 3 (#24862)
JeroenHD [Thu, 29 Sep 2022 20:23:42 +0000 (22:23 +0200)] 
Add special keyboard combos for Thinkpad P1 Gen 3 (#24862)

* Add special keyboard combos for Thinkpad P1 Gen 3

These are based on the key codes I've found with evtest. See issue
https://github.com/systemd/systemd/issues/24814 for more details.

I'm not entirely sure what some of these keys are supposed to do,
notably Fn+RShift; this doesn't seem to do anything in Windows on
my machine. Binding them to prog# makes them available to desktop
managers' key bindings at least, in case someone wishes to make
use of this extra keybind possibility.

20 months agotest-64-udev-storage: use wait command instead of hackish "udevadm lock true" 24865/head
Yu Watanabe [Thu, 29 Sep 2022 17:38:22 +0000 (02:38 +0900)] 
test-64-udev-storage: use wait command instead of hackish "udevadm lock true"

Otherwise, "udevadm lock true" may lock a block device earlier than
"udevadm lock sfdisk &".

20 months agoudevadm: do not try to find device unit when a path like string is provided
Yu Watanabe [Thu, 29 Sep 2022 17:03:32 +0000 (02:03 +0900)] 
udevadm: do not try to find device unit when a path like string is provided

Otherwise, we provide misleading error message.
Before:
---
$ udevadm info /sys/class/foo
Bad argument "/sys/class/foo", expected an absolute path in /dev/ or /sys/ or a unit name: Invalid argument
---
After:
---
$ udevadm info /sys/class/foo
Unknown device "/sys/class/foo": No such device
---

20 months agodocs/CONTRIBUTING: explain various labels and add link to "reviewable" PRs
Zbigniew Jędrzejewski-Szmek [Thu, 29 Sep 2022 12:30:24 +0000 (14:30 +0200)] 
docs/CONTRIBUTING: explain various labels and add link to "reviewable" PRs

The linked filter gives an up-to-date list of pull requests that need review.
(Yes, there's too many.) We used to set 'needs-review' label, but that is
not available to non-members, and also every pull requests which is not labeled
'reviewed/needs-rework'/'ci-fails/needs-rework'/'needs-rebase' can and should
be reviewed.

If this is merged, I'll drop the 'needs-review' label.

20 months agotest: bump the `reattach` timeout when running w/ plain QEMU
Frantisek Sumsal [Thu, 29 Sep 2022 12:23:11 +0000 (14:23 +0200)] 
test: bump the `reattach` timeout when running w/ plain QEMU

As it might sometimes take slightly longer without the acceleration:

```
[  176.805681] testsuite-29.sh[534]: + cp /usr/share/app1.raw /tmp/app1_2.raw
[  176.885365] testsuite-29.sh[534]: + timeout 30 portablectl reattach --now --runtime --extension /tmp/app1_2.raw /usr/share/minimal_1.raw app1
[  177.053358] portablectl[993]: (Matching unit files with prefixes 'app1'.)
[  177.138770] kernel: loop0: detected capacity change from 0 to 2965504
[  177.343137] kernel: loop1: detected capacity change from 0 to 4096
...
[  201.932062] systemd[1]: app1.service: Deactivated successfully.
[  202.009310] systemd[1]: Stopped app1.service.
[  202.053776] systemd[1]: app1.service: Consumed 2.183s CPU time.
[  202.125061] systemd[1]: Stopping app1.service...
[  202.611760] systemd[1]: Starting modprobe@dm_mod.service...
[  202.851031] systemd[1]: Starting modprobe@dm_verity.service...
[  202.909352] systemd[1]: Starting modprobe@loop.service...
[  203.198918] systemd[1]: Starting app1.service...
[  207.145494] kernel: audit: type=1130 audit(1663770336.105:428): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=testsuite-29 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
[  207.652545] systemd[1]: testsuite-29.service: Main process exited, code=exited, status=124/n/a
[  207.665088] systemd[1]: testsuite-29.service: Failed with result 'exit-code'.
[  207.830522] systemd[1]: Failed to start testsuite-29.service.
...
[  208.889449] script1.sh[1035]: ID="centos"
[  208.889449] script1.sh[1035]: VERSION_ID="8"
[  208.889449] script1.sh[1035]: SYSEXT_SCOPE=portable
[  208.889449] script1.sh[1035]: PORTABLE_PREFIXES=app1
...
[  214.155097] systemd[1]: app1.service: Deactivated successfully.
```

Spotted in Ubuntu CI and CentOS CI.

Follow-up to 706c9a30ac.

20 months agostub: Remove unused function parameter
Jan Janssen [Thu, 29 Sep 2022 07:09:52 +0000 (09:09 +0200)] 
stub: Remove unused function parameter

20 months agoresolved: paranoia: restrict socket mode as much as we can
Lennart Poettering [Tue, 27 Sep 2022 12:32:35 +0000 (14:32 +0200)] 
resolved: paranoia: restrict socket mode as much as we can

20 months agotest: wrap `ls` and `stat` to make it work w/ sanitizers in specific cases
Frantisek Sumsal [Wed, 28 Sep 2022 15:01:55 +0000 (17:01 +0200)] 
test: wrap `ls` and `stat` to make it work w/ sanitizers in specific cases

When `/etc/nsswitch.conf` uses `systemd` together with `[SUCCESS=merge]`,
`ls -l` will pull in `libnss_systemd` causing `SIGABRT`, as `ls` is not
instrumented (by default):

```
-bash-5.1# strace -f -e %file ls -l /dev
execve("/usr/bin/ls", ["ls", "-l", "/dev"], 0x7ffc3bb211c8 /* 24 vars*/) = 0
...
openat(AT_FDCWD, "/etc/passwd", O_RDONLY|O_CLOEXEC) = 3
newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=1896, ...}, AT_EMPTY_PATH) = 0
newfstatat(AT_FDCWD, "/etc/nsswitch.conf", {st_mode=S_IFREG|0644, st_size=359, ...}, 0) = 0
openat(AT_FDCWD, "/etc/group", O_RDONLY|O_CLOEXEC) = 3
newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=965, ...}, AT_EMPTY_PATH) = 0
openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=10779, ...}, AT_EMPTY_PATH) = 0
openat(AT_FDCWD, "/usr/lib/libnss_systemd.so.2", O_RDONLY|O_CLOEXEC) = 3
newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=16195176, ...}, AT_EMPTY_PATH) = 0
openat(AT_FDCWD, "/usr/lib/libasan.so.8", O_RDONLY|O_CLOEXEC) = 3
...
readlink("/proc/self/exe", "/usr/bin/ls", 4096) = 11
open("/proc/self/cmdline", O_RDONLY)    = 3
open("/proc/self/environ", O_RDONLY)    = 3
==620==ASan runtime does not come first in initial library list; you should either link runtime to your application or manually preload it with LD_PRELOAD.
--- SIGABRT {si_signo=SIGABRT, si_code=SI_TKILL, si_pid=620, si_uid=0} ---
+++ killed by SIGABRT (core dumped) +++
Aborted (core dumped)
```

This also happens with `stat`. Let's add both `ls` and `stat` to the "wrap list"
to work around this.

Spotted on Arch Linux.

20 months agoresolvectl: add line breaks for readability
Lennart Poettering [Wed, 28 Sep 2022 10:45:31 +0000 (12:45 +0200)] 
resolvectl: add line breaks for readability

20 months agoresolved: don't access sshfp fields from tlsa printer
Lennart Poettering [Wed, 28 Sep 2022 15:12:20 +0000 (17:12 +0200)] 
resolved: don't access sshfp fields from tlsa printer

20 months agoresolved: return regular varlink invalid parameter error if more is not specified...
Lennart Poettering [Wed, 28 Sep 2022 09:44:57 +0000 (11:44 +0200)] 
resolved: return regular varlink invalid parameter error if more is not specified on monitor call

No point in returning EINVAL if we can just return a proper varlink
invalid parameter error

20 months agoresolved: fix parameter reuse in DNS_ANSWER_FOREACH_ITEM() iterator macro
Lennart Poettering [Wed, 28 Sep 2022 09:44:18 +0000 (11:44 +0200)] 
resolved: fix parameter reuse in DNS_ANSWER_FOREACH_ITEM() iterator macro

20 months agotest: fix a copy-paste error
Frantisek Sumsal [Wed, 28 Sep 2022 09:30:13 +0000 (11:30 +0200)] 
test: fix a copy-paste error

20 months agoMerge pull request #24837 from yuwata/kernel-install
Daan De Meyer [Wed, 28 Sep 2022 08:50:55 +0000 (10:50 +0200)] 
Merge pull request #24837 from yuwata/kernel-install

kernel-install: two fixlets

20 months agofuzz: tighten acceptable data size
Yu Watanabe [Wed, 28 Sep 2022 04:42:01 +0000 (13:42 +0900)] 
fuzz: tighten acceptable data size

Fixes oss-fuzz#51887 (https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51887).
Fixes #24833.

20 months agodocs/NETWORK_ONLINE: systemd.network hyperlink fix
Sarah Brofeldt [Wed, 28 Sep 2022 06:43:30 +0000 (08:43 +0200)] 
docs/NETWORK_ONLINE: systemd.network hyperlink fix

20 months agokernel-install: do not fail if a plugin exits with 77 24837/head
Yu Watanabe [Wed, 28 Sep 2022 04:35:49 +0000 (13:35 +0900)] 
kernel-install: do not fail if a plugin exits with 77

20 months agokernel-install: do not fail if $layout is not "bls"
Yu Watanabe [Wed, 28 Sep 2022 04:27:19 +0000 (13:27 +0900)] 
kernel-install: do not fail if $layout is not "bls"

Fixes #24836.

20 months agoresolve: persist DNSOverTLS configuration in state file
msizanoen1 [Tue, 27 Sep 2022 14:48:48 +0000 (21:48 +0700)] 
resolve: persist DNSOverTLS configuration in state file

Currently, NetworkManager will set DNSOverTLS according to its
`connection.dnsovertls` configuration only once during connection,
instead of every single restart of systemd-resolved, causing resolved to
lose the configuration on restart.

Fix this by persisting DNSOverTLS in the runtime state file, which will
also make it more consistent with other interface-specific settings.

20 months agohwdb: fix Positivo-vaio FE14 V2 key toggle touchpad #24822 (#24825)
Edson Juliano Drosdeck [Tue, 27 Sep 2022 23:06:34 +0000 (19:06 -0400)] 
hwdb: fix Positivo-vaio FE14 V2 key toggle touchpad #24822  (#24825)

20 months agoresolved notifications: follow-up fixes
Luca Boccassi [Mon, 26 Sep 2022 14:33:35 +0000 (15:33 +0100)] 
resolved notifications: follow-up fixes

Further review comments from: https://github.com/systemd/systemd/pull/22845

20 months agoMerge pull request #24832 from mrc0mmand/more-TEST-64-tweaks
Yu Watanabe [Tue, 27 Sep 2022 17:26:55 +0000 (02:26 +0900)] 
Merge pull request #24832 from mrc0mmand/more-TEST-64-tweaks

A couple of performance tweaks for TEST-64 under QEMU

20 months agotmpfiles: downgrade message about unitialized-/etc 24820/head
Zbigniew Jędrzejewski-Szmek [Mon, 26 Sep 2022 12:46:08 +0000 (14:46 +0200)] 
tmpfiles: downgrade message about unitialized-/etc

If we're running with --root, or in a chroot (*), it's expected that machine-id
and other specifiers will be unresolvable, so downgrade the warning to debug.

Fixes #24655.

(*) sd_booted() in principle means more than that, but nowadays systemd
dominates and those others things are infrequently seen.

20 months agotmpfiles: fix detection of unitialized-/etc
Zbigniew Jędrzejewski-Szmek [Mon, 26 Sep 2022 12:22:49 +0000 (14:22 +0200)] 
tmpfiles: fix detection of unitialized-/etc

In 6ec4c852c910b1aca649e87ba3143841334f01fa I changed specifier_machine_id() to
return EUNATCH, but the code catching in tmpfiles wasn't adjusted.

Instead of translating errors at various levels, let the "original" errno value
(whatever was returned by the low-level reading function) propagate all the way
to the logging function, and only check which errnos to suppress there. This
makes it easier to follow the flow of data through all the layers. Also, we
don't need to provide wrapper functions for each place where we want to do the
supression.

The common set of errnos that have similar meaning are are caught using
ERRNO_IS_NOINFO(). It is more managable to use a wider net than to figure out
which errors could be returned in specific cases.

20 months agotest: use fewer partitions/LVs when running with plain QEMU 24832/head
Frantisek Sumsal [Tue, 27 Sep 2022 11:57:04 +0000 (13:57 +0200)] 
test: use fewer partitions/LVs when running with plain QEMU

20 months agotest: make the symlink helpers a bit more quiet
Frantisek Sumsal [Tue, 27 Sep 2022 11:47:59 +0000 (13:47 +0200)] 
test: make the symlink helpers a bit more quiet

and show only errors/warnings.

20 months agotest: ignore tty* devices when checking device units
Frantisek Sumsal [Tue, 27 Sep 2022 11:06:27 +0000 (13:06 +0200)] 
test: ignore tty* devices when checking device units

This lower the runtime of `check_device_units()` in a plain QEMU VM from
~45 seconds to ~25 seconds.

20 months agotest: lower the # of iterations when running with plain QEMU
Frantisek Sumsal [Tue, 27 Sep 2022 11:05:43 +0000 (13:05 +0200)] 
test: lower the # of iterations when running with plain QEMU

20 months agotest: support open-iscsi >= 2.1.2
Frantisek Sumsal [Mon, 26 Sep 2022 21:14:18 +0000 (23:14 +0200)] 
test: support open-iscsi >= 2.1.2

Since open-iscsi 2.1.2 [0] the initiator name should be generated via
a one-time service instead of distro package's post-install scripts.
However, some distros still use this approach even after this patch,
so prefer the already existing initiatorname.iscsi file if it exists.

[0] https://github.com/open-iscsi/open-iscsi/commit/f37d5b653f9f251845db3f29b1a3dcb90ec89731

20 months agoMerge pull request #24805 from yuwata/sd-network
Lennart Poettering [Tue, 27 Sep 2022 09:28:25 +0000 (11:28 +0200)] 
Merge pull request #24805 from yuwata/sd-network

sd-network: several cleanups

20 months agosystemctl: add support for --image option
Richard Phibel [Wed, 7 Sep 2022 10:53:09 +0000 (03:53 -0700)] 
systemctl: add support for --image option

All tools that support --root= should also learn --image=
so that they can operate on disk images directly.

20 months agoMerge pull request #24812 from yuwata/udev-drop-netlink
Yu Watanabe [Tue, 27 Sep 2022 05:10:02 +0000 (14:10 +0900)] 
Merge pull request #24812 from yuwata/udev-drop-netlink

udev: drop workaround for slow read of phys_port_name sysattr

20 months agosd-network: make sd_network_link_get_dns() or friends return -ENODATA 24805/head
Yu Watanabe [Sat, 24 Sep 2022 00:31:00 +0000 (09:31 +0900)] 
sd-network: make sd_network_link_get_dns() or friends return -ENODATA

To make them consistent with other functions.

20 months agosd-network: drop fallback values
Yu Watanabe [Sat, 24 Sep 2022 00:22:03 +0000 (09:22 +0900)] 
sd-network: drop fallback values

This drops spurious lines in `networkctl status` for unmanaged interfaces.
Before:
```
$ networkctl status --lines 0 lo
● 1: lo
                     Link File: n/a
                  Network File: n/a
                          Type: loopback
                         State: carrier (unmanaged)
                  Online state: unknown
                    HW Address: 00:00:00:00:00:00
                           MTU: 65536
                         QDisc: noqueue
  IPv6 Address Generation Mode: eui64
          Queue Length (Tx/Rx): 1/1
                       Address: 127.0.0.1
                                ::1
             Activation Policy: up
           Required For Online: yes
```
After:
```
$ networkctl status --lines 0 lo
● 1: lo
                     Link File: n/a
                  Network File: n/a
                         State: carrier (unmanaged)
                  Online state: unknown
                          Type: loopback
              Hardware Address: 00:00:00:00:00:00
                           MTU: 65536
                         QDisc: noqueue
  IPv6 Address Generation Mode: eui64
      Number of Queues (Tx/Rx): 1/1
                       Address: 127.0.0.1
                                ::1
```

That is, the lines for Activation Policy and Required For Online are
dropped.

20 months agosd-network: introduce network_link_get_boolean() helper function
Yu Watanabe [Sat, 24 Sep 2022 00:20:36 +0000 (09:20 +0900)] 
sd-network: introduce network_link_get_boolean() helper function

20 months agosd-network: accept all space-like separators
Yu Watanabe [Sat, 24 Sep 2022 00:05:05 +0000 (09:05 +0900)] 
sd-network: accept all space-like separators

20 months agosd-network: propagate -ENOENT
Yu Watanabe [Sat, 24 Sep 2022 00:01:58 +0000 (09:01 +0900)] 
sd-network: propagate -ENOENT

On -ENOENT, it suggests that network-manager is not running, and
interfaces are not unmanaged. Such information may be useful for
callers.

20 months agosd-network: rename function arguments for storing return value
Yu Watanabe [Fri, 23 Sep 2022 22:50:18 +0000 (07:50 +0900)] 
sd-network: rename function arguments for storing return value

20 months agonetworkctl: use table_add_string_line() at one more place
Yu Watanabe [Fri, 23 Sep 2022 22:47:14 +0000 (07:47 +0900)] 
networkctl: use table_add_string_line() at one more place

20 months agonetworkctl: handle all errors in sd_network_link_get_setup_state() as "unmanaged"
Yu Watanabe [Fri, 23 Sep 2022 22:46:31 +0000 (07:46 +0900)] 
networkctl: handle all errors in sd_network_link_get_setup_state() as "unmanaged"

We have already ignored all errors in other fields.

20 months agoudev: drop workaround for slow read of phys_port_name sysattr 24812/head
Yu Watanabe [Sun, 25 Sep 2022 04:18:24 +0000 (13:18 +0900)] 
udev: drop workaround for slow read of phys_port_name sysattr

TL;DR
This effectively reverts 8327fd1b11c5fb6529d46dfb40e2af981ffa8545,
eaba9bb3e69635d2c490c5e1b0d262b763753e1d, and its follow-ups, as the
original issue was already fixed by the kernel side.

The original issue that the above commits tried to 'fix' is that reading
phys_port_name triggers a lock in the kernel, hence processing multiple
interfaces at the same time causes extreme slow down.
To workaround the issue, the above commits made several necessary
information retrieved through netlink instead of sysfs attributes.

A patch set for the kernel was proposed as a fix for the issue:
https://lore.kernel.org/all/20210928125500.167943-1-atenart@kernel.org/
and some of them were merged to v5.16:
https://github.com/torvalds/linux/commit/146e5e733310379f51924111068f08a3af0db830,
It has been already backported to 5.4.160, 5.10.80, 5.14.19, and 5.15.3.

When these commits were proposed, it is already claimed that such issue
should be fixed by the kernel side, and udevd should not workaround it.
Neverthless the feature was introduced, as these have theoretical
performance improvement, even if phys_port_name sysattr does not have the
above issue, as in that way udevd can obtain multiple information about
the interface with a single netlink socket operation. See the discussion
in #20744.

However, in reality, only `iflink`, `type`, `address`, and `phys_port_name`
attributes from netlink are used in the udev net_id builtin command. Hence,
after the original issue being fixed in the kernel side, there should be
almost no performance improvement for udevd.
Furthermore, combining attributes from netlink and sysfs makes hard to
test net_id builtin. See #21725.

Let's drop mostly meaningless code, and make net_id builtin easily testable.

Closes #21725.

20 months agoman: document that setting Storage= in namespaces journald menas LogDirectory= in...
Lennart Poettering [Mon, 26 Sep 2022 14:13:20 +0000 (16:13 +0200)] 
man: document that setting Storage= in namespaces journald menas LogDirectory= in unit file needs setting too

Replaces: #24789

20 months agoMerge pull request #24757 from yuwata/sd-device-get-child-first
Lennart Poettering [Mon, 26 Sep 2022 17:03:15 +0000 (19:03 +0200)] 
Merge pull request #24757 from yuwata/sd-device-get-child-first

sd-device: introduce sd_device_get_child_first() and _next()

20 months agoMerge pull request #24808 from medhefgo/fuzz
Lennart Poettering [Mon, 26 Sep 2022 16:37:08 +0000 (18:37 +0200)] 
Merge pull request #24808 from medhefgo/fuzz

fuzz: Add fuzzer for some efi string functions

20 months agounits: udev: partially emulate ProtectClock=
Topi Miettinen [Sun, 25 Sep 2022 17:47:53 +0000 (20:47 +0300)] 
units: udev: partially emulate ProtectClock=

Drop CAP_SYS_TIME and CAP_WAKE_ALARM capabilities and block clock-related
system calls. Update TODO.

20 months agoupdate TODO
Lennart Poettering [Mon, 26 Sep 2022 08:06:11 +0000 (10:06 +0200)] 
update TODO

20 months agoboot: Make efi_fnmatch non-backtracking 24808/head
Jan Janssen [Sat, 24 Sep 2022 11:33:10 +0000 (13:33 +0200)] 
boot: Make efi_fnmatch non-backtracking

20 months agofuzz: Add fuzzer for some efi string functions
Jan Janssen [Fri, 23 Sep 2022 08:07:25 +0000 (10:07 +0200)] 
fuzz: Add fuzzer for some efi string functions

20 months agofuzz: Introduce DO_NOT_OPTIMIZE
Jan Janssen [Fri, 23 Sep 2022 07:54:03 +0000 (09:54 +0200)] 
fuzz: Introduce DO_NOT_OPTIMIZE

The compiler may decide computations like these are not doing anything
and decide to optimize them away. This would defeat the whole fuzzing
exercise. This macro will force the compiler to materialize the value
no matter what. It should be less prone to accidents compared to using
log functions, which would either slow things down or still optimize the
value away (or simply move it into the if branch the log macros create).

The benefit over assert_se would be that no requirement is made on the
value itself. If we are fine getting a string of any size (including
zero), an assert_se would either create a noisy compiler warning about
conditions that would alawys be met or yet again optimize the whole
thing away.

20 months agofuzz-bcd: Do not include bcd.c
Jan Janssen [Fri, 23 Sep 2022 07:47:26 +0000 (09:47 +0200)] 
fuzz-bcd: Do not include bcd.c

This is not needed anymore, so do it the proper way now.

20 months agoAdd Asus G14 GA402 to hwdb
Albert Mikaelyan [Sat, 24 Sep 2022 22:18:26 +0000 (01:18 +0300)] 
Add Asus G14 GA402 to hwdb

20 months agoMerge pull request #24811 from yuwata/build-without-openssl
Luca Boccassi [Sun, 25 Sep 2022 09:51:45 +0000 (10:51 +0100)] 
Merge pull request #24811 from yuwata/build-without-openssl

meson,tpm2: fix build without openssl

20 months agosd-device: introduce device_get_sysattr_int()
Yu Watanabe [Sun, 25 Sep 2022 04:17:20 +0000 (13:17 +0900)] 
sd-device: introduce device_get_sysattr_int()

20 months agotpm2-util: fix build with -Dopenssl=false 24811/head
Yu Watanabe [Sat, 24 Sep 2022 22:41:07 +0000 (07:41 +0900)] 
tpm2-util: fix build with -Dopenssl=false

Fixes #24800.

20 months agomeson: libfido2 requires openssl
Yu Watanabe [Sat, 24 Sep 2022 22:33:52 +0000 (07:33 +0900)] 
meson: libfido2 requires openssl

Fixes compile error with -Dopenssl=false.
```
In file included from ../../home/watanabe/git/systemd/src/shared/pkcs11-util.h:12,
                 from ../../home/watanabe/git/systemd/src/cryptenroll/cryptenroll.c:24:
../../home/watanabe/git/systemd/src/shared/openssl-util.h:56:21: error: conflicting types for ‘X509’; have ‘struct X509’
   56 | typedef struct X509 X509;
      |                     ^~~~
In file included from /usr/include/openssl/crypto.h:25,
                 from /usr/include/openssl/bio.h:20,
                 from /usr/include/openssl/asn1.h:16,
                 from /usr/include/openssl/ec.h:17,
                 from /usr/include/fido.h:10,
                 from ../../home/watanabe/git/systemd/src/shared/libfido2-util.h:18,
                 from ../../home/watanabe/git/systemd/src/cryptenroll/cryptenroll-fido2.h:7,
                 from ../../home/watanabe/git/systemd/src/cryptenroll/cryptenroll.c:6:
/usr/include/openssl/ossl_typ.h:123:24: note: previous declaration of ‘X509’ with type ‘X509’ {aka ‘struct x509_st’}
  123 | typedef struct x509_st X509;
      |                        ^~~~
```

20 months agotmpfiles: fix wrong return value
Yu Watanabe [Sat, 24 Sep 2022 01:10:51 +0000 (10:10 +0900)] 
tmpfiles: fix wrong return value

Follow-up for 27f6aa0b7112024c1236957abd909071b06869a8.

20 months agocore: respect SELinuxContext= for socket creation
Christian Göttsche [Fri, 23 Sep 2022 17:00:22 +0000 (19:00 +0200)] 
core: respect SELinuxContext= for socket creation

On socket creation respect the SELinuxContext= setting of the associated
service, such that the initial created socket has the same label as the
future process accepting the connection (since w.r.t SELinux sockets
normally have the same label as the owning process).

Triggered by #24702

20 months agotree-wide: fix typo
Yu Watanabe [Sat, 24 Sep 2022 01:43:58 +0000 (10:43 +0900)] 
tree-wide: fix typo

20 months agoMerge pull request #24799 from poettering/initrd-ftw
Luca Boccassi [Fri, 23 Sep 2022 19:43:15 +0000 (20:43 +0100)] 
Merge pull request #24799 from poettering/initrd-ftw

use "initrd" rather than "initial RAM disk" or "initramfs" to refernce the concept

20 months agoMerge pull request #24635 from DaanDeMeyer/repart-verity-sig
Daan De Meyer [Fri, 23 Sep 2022 16:53:04 +0000 (18:53 +0200)] 
Merge pull request #24635 from DaanDeMeyer/repart-verity-sig

repart: Add support for generating verity sig partitions

20 months agorepart: Add support for generating verity sig partitions 24635/head
Daan De Meyer [Sun, 11 Sep 2022 08:49:24 +0000 (10:49 +0200)] 
repart: Add support for generating verity sig partitions

20 months agoopenssl-util: Add x509_fingerprint()
Daan De Meyer [Fri, 23 Sep 2022 13:01:15 +0000 (15:01 +0200)] 
openssl-util: Add x509_fingerprint()

20 months agoopenssl-util: Allow declaring openssl struct pointers without openssl
Daan De Meyer [Fri, 23 Sep 2022 12:17:20 +0000 (14:17 +0200)] 
openssl-util: Allow declaring openssl struct pointers without openssl

20 months agoTODO
Lennart Poettering [Fri, 23 Sep 2022 14:12:54 +0000 (16:12 +0200)] 
TODO

20 months agoMerge pull request #24700 from poettering/ssh-creds
Lennart Poettering [Fri, 23 Sep 2022 14:01:09 +0000 (16:01 +0200)] 
Merge pull request #24700 from poettering/ssh-creds

support easy provisioning for SSH key of root user

20 months agoMerge pull request #24628 from medhefgo/boot-sections
Lennart Poettering [Fri, 23 Sep 2022 13:45:28 +0000 (15:45 +0200)] 
Merge pull request #24628 from medhefgo/boot-sections

boot: Try to detect overlapping PE sections

20 months agoMerge pull request #24796 from yuwata/doc-update
Lennart Poettering [Fri, 23 Sep 2022 13:13:18 +0000 (15:13 +0200)] 
Merge pull request #24796 from yuwata/doc-update

documentation updates

20 months agoMerge pull request #24794 from DaanDeMeyer/repart-follow-ups
Lennart Poettering [Fri, 23 Sep 2022 13:12:56 +0000 (15:12 +0200)] 
Merge pull request #24794 from DaanDeMeyer/repart-follow-ups

repart: Extend squashfs logic to all read-only filesystems

20 months agotree-wide: also settle on "initrd" instead of "initial RAM disk" 24799/head
Lennart Poettering [Fri, 23 Sep 2022 13:10:06 +0000 (15:10 +0200)] 
tree-wide: also settle on "initrd" instead of "initial RAM disk"

With this the concept is now called the same way everywhere except where
historical info is relevant or where the other names are API.

20 months agotree-wide: use the term "initrd" at most places we so far used "initramfs"
Lennart Poettering [Fri, 23 Sep 2022 12:59:02 +0000 (14:59 +0200)] 
tree-wide: use the term "initrd" at most places we so far used "initramfs"

In most cases we refernced the concept as "initrd". Let's convert most
remaining uses of "initramfs" to "initrd" too, to stay internally
consistent.

This leaves "initramfs" only where it's relevant to explain historical
concepts or where "initramfs" is part of the API (i.e. in
/run/initramfs).

Follow-up for: b66a6e1a5838b874b789820c090dd6850cf10513

20 months agodocs: Mention that "certificateFingerprint" source should be in DER
Daan De Meyer [Fri, 23 Sep 2022 12:08:40 +0000 (14:08 +0200)] 
docs: Mention that "certificateFingerprint" source should be in DER

20 months agobasic: Add strgrowpad0()
Daan De Meyer [Fri, 23 Sep 2022 10:40:13 +0000 (12:40 +0200)] 
basic: Add strgrowpad0()

20 months agoMerge pull request #24686 from d4nuu8/delta_output
Lennart Poettering [Fri, 23 Sep 2022 11:33:55 +0000 (13:33 +0200)] 
Merge pull request #24686 from d4nuu8/delta_output

shared/logs-show: add new --output= format "short-delta"

20 months agodissect: Process verity sig partitions if a root hash is specified
Daan De Meyer [Sun, 18 Sep 2022 13:36:59 +0000 (15:36 +0200)] 
dissect: Process verity sig partitions if a root hash is specified

If a root hash is specified, we should be checking that it matches
the root hash in the verity signature partition, so let's not skip
processing of the verity signature partitions if a root hash is
specified.

20 months agotest: Install openssl 3 extra library dependencies
Daan De Meyer [Sat, 17 Sep 2022 20:35:19 +0000 (22:35 +0200)] 
test: Install openssl 3 extra library dependencies

20 months agodissect: Log when we fail to load the verity signature partition
Daan De Meyer [Sat, 17 Sep 2022 20:34:56 +0000 (22:34 +0200)] 
dissect: Log when we fail to load the verity signature partition

20 months agorepart: Rename verity integration test definition files
Daan De Meyer [Sun, 11 Sep 2022 11:43:17 +0000 (13:43 +0200)] 
repart: Rename verity integration test definition files

20 months agorepart: Improve missing libcryptsetup error message
Daan De Meyer [Sun, 11 Sep 2022 08:47:18 +0000 (10:47 +0200)] 
repart: Improve missing libcryptsetup error message

20 months agorepart: Rename context_verity() to context_verity_hash()
Daan De Meyer [Sat, 10 Sep 2022 20:12:57 +0000 (22:12 +0200)] 
repart: Rename context_verity() to context_verity_hash()

20 months agoupdate TODO
Lennart Poettering [Fri, 23 Sep 2022 09:43:53 +0000 (11:43 +0200)] 
update TODO

20 months agoREADME: drop graphs counting issues or PRs 24796/head
Yu Watanabe [Thu, 22 Sep 2022 22:55:50 +0000 (07:55 +0900)] 
README: drop graphs counting issues or PRs

These cannot be accessible anymore.

20 months agodoc: drop remaining references to LGTM.com
Yu Watanabe [Thu, 22 Sep 2022 22:54:12 +0000 (07:54 +0900)] 
doc: drop remaining references to LGTM.com

20 months agoUpdated Lenovo ThinkPad T440p/T440 touchpad fuzz (#24779)
Avamander [Fri, 23 Sep 2022 09:26:01 +0000 (12:26 +0300)] 
Updated Lenovo ThinkPad T440p/T440 touchpad fuzz (#24779)

20 months agoshared/logs-show: add new --output= format "short-delta" 24686/head
Daniel Braunwarth [Thu, 22 Sep 2022 16:35:19 +0000 (18:35 +0200)] 
shared/logs-show: add new --output= format "short-delta"

This new output formatting option is similar to "short-monotonic" but
also shows the time delta between two messages.

This fixes #24641.

20 months agologs-show: move timestamp reading into show_journal_entry()
Daniel Braunwarth [Tue, 20 Sep 2022 17:51:36 +0000 (19:51 +0200)] 
logs-show: move timestamp reading into show_journal_entry()

20 months agoshared: Don't try to generate read-only filesystem that we don't support 24794/head
Daan De Meyer [Fri, 23 Sep 2022 07:55:26 +0000 (09:55 +0200)] 
shared: Don't try to generate read-only filesystem that we don't support

We need explicit support to generate read-only filesystems, since we
always need to pass a source tree to the mkfs binary to populate the
filesystem. As such, let's add an explicit check to return a
recognizable error when users try to generate a read-only filesystem
that we don't support.

20 months agorepart: Extend squashfs logic to all read-only filesystems
Daan De Meyer [Thu, 22 Sep 2022 19:28:58 +0000 (21:28 +0200)] 
repart: Extend squashfs logic to all read-only filesystems

The same logic will apply to every read-only filesystem that we
might add support for in the future, so let's make this a bit more
future proof.

20 months agoupdate TODO 24700/head
Lennart Poettering [Fri, 16 Sep 2022 15:33:54 +0000 (16:33 +0100)] 
update TODO

(let's also merge all TODO items about adding creds support to various
tools into one item)

20 months agoman: add man page decribing well known system credentials
Lennart Poettering [Fri, 16 Sep 2022 14:58:00 +0000 (15:58 +0100)] 
man: add man page decribing well known system credentials

20 months agotest: add test case for new ':' uid/gid/access modifier in tmpfiles.d
Lennart Poettering [Fri, 16 Sep 2022 14:12:14 +0000 (15:12 +0100)] 
test: add test case for new ':' uid/gid/access modifier in tmpfiles.d