]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
5 months agoman/systemd.mount: tmpfs automatically gains After=swap.target dep 30284/head
Mike Yuan [Thu, 7 Dec 2023 10:22:23 +0000 (18:22 +0800)] 
man/systemd.mount: tmpfs automatically gains After=swap.target dep

5 months agofstab-generator: disable default deps if x-systemd.{wanted,required}-by= is used
Mike Yuan [Fri, 1 Dec 2023 11:32:45 +0000 (19:32 +0800)] 
fstab-generator: disable default deps if x-systemd.{wanted,required}-by= is used

Fixes #30273

5 months agoman/systemd.mount: update implicit deps on device unit
Mike Yuan [Thu, 7 Dec 2023 10:06:03 +0000 (18:06 +0800)] 
man/systemd.mount: update implicit deps on device unit

See also: 707ecf1423ba8797ccc3ced016cc9e0f23635838

5 months agoMerge pull request #30363 from yuwata/analyze-find-template
Luca Boccassi [Mon, 11 Dec 2023 15:56:21 +0000 (15:56 +0000)] 
Merge pull request #30363 from yuwata/analyze-find-template

analyze: also find template unit when an instance is specified

5 months agoexecutor: don't duplicate FD array to avoid double closing
Luca Boccassi [Mon, 11 Dec 2023 01:03:39 +0000 (01:03 +0000)] 
executor: don't duplicate FD array to avoid double closing

Just use ExecParam directly, as these are all internal to sd-exec now
anyway. Avoids double close when execution fails after FDs are set up
for inheritance and were already re-arranged.

Fixes https://github.com/systemd/systemd/issues/30412

5 months agoMerge pull request #30422 from yuwata/network-tiny-fixes
Yu Watanabe [Mon, 11 Dec 2023 15:23:11 +0000 (00:23 +0900)] 
Merge pull request #30422 from yuwata/network-tiny-fixes

network: tiny fixes

5 months agokernel-install: Fix inspect with --root= when no version is specified
Daan De Meyer [Sun, 10 Dec 2023 16:02:38 +0000 (17:02 +0100)] 
kernel-install: Fix inspect with --root= when no version is specified

Using the kernel version from the host is incorrect in this case, so
fix the logic so it handles no version being specified correctly with
--root=.

5 months agobootctl: fix case-sensitive comparisons in reporting bootloader entries
ksaleem [Wed, 6 Dec 2023 16:44:24 +0000 (11:44 -0500)] 
bootctl: fix case-sensitive comparisons in reporting bootloader entries

Fixes #30159

5 months agoMerge pull request #30389 from keszybz/test-ukify-du
Yu Watanabe [Mon, 11 Dec 2023 09:37:05 +0000 (18:37 +0900)] 
Merge pull request #30389 from keszybz/test-ukify-du

Remove temporary directories created by test_ukify

5 months agokernel-install: Look for uki.conf in /usr/lib/kernel as well
Daan De Meyer [Sun, 10 Dec 2023 13:20:08 +0000 (14:20 +0100)] 
kernel-install: Look for uki.conf in /usr/lib/kernel as well

5 months agonetwork: drop unused Manager.routes_foreign 30422/head
Yu Watanabe [Mon, 11 Dec 2023 06:44:08 +0000 (15:44 +0900)] 
network: drop unused Manager.routes_foreign

5 months agonetwork: adjust log message
Yu Watanabe [Mon, 11 Dec 2023 06:19:02 +0000 (15:19 +0900)] 
network: adjust log message

The address or neighbor processed here may not be foreign.

5 months agotest: add test cases for issue #30357 30363/head
Yu Watanabe [Fri, 8 Dec 2023 01:41:49 +0000 (10:41 +0900)] 
test: add test cases for issue #30357

5 months agoanalyze: also find template unit when a template instance is specified
Yu Watanabe [Thu, 7 Dec 2023 10:29:29 +0000 (19:29 +0900)] 
analyze: also find template unit when a template instance is specified

Fixes a regression caused by 2f6181ad4d6c126e3ebf6880ba30b3b0059c6fc8.

Fixes #30357.

Co-authored-by: Jeff King <peff@peff.net>
5 months agonetwork/neighbor: add missing OOM check
Yu Watanabe [Sun, 10 Dec 2023 07:03:52 +0000 (16:03 +0900)] 
network/neighbor: add missing OOM check

5 months agoAdding Trekstor Primebook C13 rotation to 60-sensor.hwdb (#30415)
JmbFountain [Sun, 10 Dec 2023 22:37:44 +0000 (23:37 +0100)] 
Adding Trekstor Primebook C13 rotation to 60-sensor.hwdb (#30415)

* Adding Trekstor Primebook C13 rotation to 60-sensor.hwdb

5 months agomkosi: Copy /boot into the ESP as well
Daan De Meyer [Sun, 10 Dec 2023 17:13:01 +0000 (18:13 +0100)] 
mkosi: Copy /boot into the ESP as well

Newer mkosi will start installing UKIs to /boot so prepare for that
by making sure we also copy /boot into the ESP.

5 months agoMerge pull request #30406 from yuwata/resolve-clean-exit
Luca Boccassi [Sun, 10 Dec 2023 18:42:24 +0000 (18:42 +0000)] 
Merge pull request #30406 from yuwata/resolve-clean-exit

resolve: make resolved exit cleanly

5 months agoMerge pull request #30404 from yuwata/network-peer
Luca Boccassi [Sun, 10 Dec 2023 14:13:37 +0000 (14:13 +0000)] 
Merge pull request #30404 from yuwata/network-peer

network/route: fix reachability check when peer address is specified

5 months agoMerge pull request #30407 from yuwata/network-clean-exit
Luca Boccassi [Sun, 10 Dec 2023 12:54:17 +0000 (12:54 +0000)] 
Merge pull request #30407 from yuwata/network-clean-exit

network: make networkd exit cleanly

5 months agotest: update log message and use SYNTHETIC_ERRNO()
Yu Watanabe [Wed, 6 Dec 2023 05:41:42 +0000 (14:41 +0900)] 
test: update log message and use SYNTHETIC_ERRNO()

Follow-up for ce5a6d5307568671cec7c253e984ffc0eafa726b.

Addresses https://github.com/systemd/systemd/pull/30049#discussion_r1395453408.

5 months agoelf2efi: remove outdated comment mentioning linker script
Mike Yuan [Sun, 10 Dec 2023 11:05:27 +0000 (19:05 +0800)] 
elf2efi: remove outdated comment mentioning linker script

Follow-up for 142f0c61a37091e233b80f02375cff1114dab24a

5 months agoresolve: fix wrong error cause assignment to log_debug_errno()
Yu Watanabe [Sun, 10 Dec 2023 05:33:48 +0000 (14:33 +0900)] 
resolve: fix wrong error cause assignment to log_debug_errno()

Fixes #30392.

5 months agocore/exec-invoke: sigwait() returns positive errno and never EINTR
Mike Yuan [Fri, 8 Dec 2023 18:22:04 +0000 (02:22 +0800)] 
core/exec-invoke: sigwait() returns positive errno and never EINTR

Follow-up for 5b6319dceedd81f3f1ce7eb70ea5defaef43bcec (gosh this is
ancient), and effectively reverts 3dead8d925ea9db1fbd65b702b6b807e49ddeacf.

sigwait() is documented to "suspend execution of the calling thread
until one of the signals specified in the signal set becomes pending".
And the only error it returns is EINVAL, when "set contains an invalid
signal number". Therefore, there's no need to run it in a loop or
to check for runtime error.

5 months agotest-network: check if networkd exits cleanly 30407/head
Yu Watanabe [Thu, 7 Dec 2023 05:57:29 +0000 (14:57 +0900)] 
test-network: check if networkd exits cleanly

5 months agonetwork/ipv4ll: do not start sd-ipv4ll on exit
Yu Watanabe [Thu, 7 Dec 2023 05:45:07 +0000 (14:45 +0900)] 
network/ipv4ll: do not start sd-ipv4ll on exit

When assert_return() is critical, the following assertion is triggered
on exit:
---
 #0  0x00007f8b1f6b0884 in __pthread_kill_implementation () from target:/lib64/libc.so.6
 #1  0x00007f8b1f65fafe in raise () from target:/lib64/libc.so.6
 #2  0x00007f8b1f64887f in abort () from target:/lib64/libc.so.6
 #3  0x00007f8b208d02d6 in log_assert_failed (text=0x7f8b210009e0 "e->state != SD_EVENT_FINISHED", file=0x7f8b20fff403 "src/libsystemd/sd-event/sd-event.c",
     line=1252, func=0x7f8b21004400 <__func__.154> "sd_event_add_io") at ../src/basic/log.c:948
 #4  0x00007f8b208d0457 in log_assert_failed_return (text=0x7f8b210009e0 "e->state != SD_EVENT_FINISHED",
     file=0x7f8b20fff403 "src/libsystemd/sd-event/sd-event.c", line=1252, func=0x7f8b21004400 <__func__.154> "sd_event_add_io") at ../src/basic/log.c:967
 #5  0x00007f8b20c7d102 in sd_event_add_io (e=0x617000000080, ret=0x60c000000a20, fd=11, events=1, callback=0x7dfd85 <ipv4acd_on_packet>,
     userdata=0x60c000000a00) at ../src/libsystemd/sd-event/sd-event.c:1252
 #6  0x00000000007e3934 in sd_ipv4acd_start (acd=0x60c000000a00, reset_conflicts=true) at ../src/libsystemd-network/sd-ipv4acd.c:597
 #7  0x00000000007e72b9 in ipv4ll_start_internal (ll=0x6080000006a0, reset_generation=true) at ../src/libsystemd-network/sd-ipv4ll.c:278
 #8  0x00000000007e7462 in sd_ipv4ll_start (ll=0x6080000006a0) at ../src/libsystemd-network/sd-ipv4ll.c:298
 #9  0x00000000006047a1 in dhcp4_handler (client=0x617000000400, event=0, userdata=0x61a000000680) at ../src/network/networkd-dhcp4.c:1183
 #10 0x000000000075b1ed in client_notify (client=0x617000000400, event=0) at ../src/libsystemd-network/sd-dhcp-client.c:783
 #11 0x000000000075bf8d in client_stop (client=0x617000000400, error=0) at ../src/libsystemd-network/sd-dhcp-client.c:821
 #12 0x000000000077710f in sd_dhcp_client_stop (client=0x617000000400) at ../src/libsystemd-network/sd-dhcp-client.c:2388
 #13 0x000000000065cdd1 in link_stop_engines (link=0x61a000000680, may_keep_dhcp=true) at ../src/network/networkd-link.c:336
 #14 0x000000000041f214 in manager_free (m=0x618000000080) at ../src/network/networkd-manager.c:613
 #15 0x00000000004124e3 in manager_freep (p=0x7f8b1c800040) at ../src/network/networkd-manager.h:128
 #16 0x00000000004139f6 in run (argc=1, argv=0x7ffffe4522e8) at ../src/network/networkd.c:24
 #17 0x0000000000413b20 in main (argc=1, argv=0x7ffffe4522e8) at ../src/network/networkd.c:119
---
Prompted by https://github.com/systemd/systemd/pull/30049#issuecomment-1844087965.

5 months agotest: check if resolved exits cleanly 30406/head
Yu Watanabe [Thu, 7 Dec 2023 06:19:10 +0000 (15:19 +0900)] 
test: check if resolved exits cleanly

5 months agoresolve: do not trigger assertion on exit
Yu Watanabe [Thu, 7 Dec 2023 05:28:12 +0000 (14:28 +0900)] 
resolve: do not trigger assertion on exit

By making assert_return() critical, we observe the following:
---
 Program received signal SIGABRT, Aborted.
 0x00007f01320b0884 in __pthread_kill_implementation () from /lib64/libc.so.6
 (gdb) bt
 #0  0x00007f01320b0884 in __pthread_kill_implementation ()
    from /lib64/libc.so.6
 #1  0x00007f013205fafe in raise () from /lib64/libc.so.6
 #2  0x00007f013204887f in abort () from /lib64/libc.so.6
 #3  0x00007f01338d02d6 in log_assert_failed (
     text=0x7f01340009e0 "e->state != SD_EVENT_FINISHED",
     file=0x7f0133fff403 "src/libsystemd/sd-event/sd-event.c", line=1399,
     func=0x7f01340045a0 <__func__.148> "sd_event_add_time")
     at ../src/basic/log.c:948
 #4  0x00007f01338d0457 in log_assert_failed_return (
     text=0x7f01340009e0 "e->state != SD_EVENT_FINISHED",
     file=0x7f0133fff403 "src/libsystemd/sd-event/sd-event.c", line=1399,
     func=0x7f01340045a0 <__func__.148> "sd_event_add_time")
     at ../src/basic/log.c:967
 #5  0x00007f0133c7ed83 in sd_event_add_time (e=0x617000022280,
     ret=0x610000007e98, clock=7, usec=24054941030, accuracy=0,
     callback=0x4625b4 <on_announcement_timeout>, userdata=0x610000007e40)
     at ../src/libsystemd/sd-event/sd-event.c:1399
 #6  0x00007f0133c7f725 in sd_event_add_time_relative (e=0x617000022280,
     ret=0x610000007e98, clock=7, usec=1000000, accuracy=0,
     callback=0x4625b4 <on_announcement_timeout>, userdata=0x610000007e40)
     at ../src/libsystemd/sd-event/sd-event.c:1462
 #7  0x0000000000464cac in dns_scope_announce (scope=0x610000007e40, goodbye=true) at ../src/resolve/resolved-dns-scope.c:1530
 #8  0x0000000000504d08 in link_free (l=0x612000023d40) at ../src/resolve/resolved-link.c:83
 #9  0x000000000052dbbd in manager_free (m=0x619000000a80) at ../src/resolve/resolved-manager.c:697
 #10 0x0000000000562328 in manager_freep (p=0x7f012f800040) at ../src/resolve/resolved-manager.h:198
 #11 0x000000000056315a in run (argc=1, argv=0x7fff22b06468) at ../src/resolve/resolved.c:25
 #12 0x0000000000563284 in main (argc=1, argv=0x7fff22b06468) at ../src/resolve/resolved.c:99
---
Prompted by https://github.com/systemd/systemd/pull/30049#issuecomment-1844087965.

5 months agosystemctl: fix typo
Yu Watanabe [Sun, 10 Dec 2023 05:26:30 +0000 (14:26 +0900)] 
systemctl: fix typo

Follow-up for 329050c5e2c7e9561699f87b5edb72edd0d54c96.

5 months agonetworkctl: fix typo
Yu Watanabe [Sun, 10 Dec 2023 05:25:31 +0000 (14:25 +0900)] 
networkctl: fix typo

Follow-up for 2b98926f9809eb858a5abe4f64ebd067df5059d5.

5 months agocore/executor: do destruct static variables and selinux before exiting
Mike Yuan [Fri, 8 Dec 2023 16:06:16 +0000 (00:06 +0800)] 
core/executor: do destruct static variables and selinux before exiting

I was wondering why I couldn't trigger the assertion in safe_fclose()
when submitting #30251. It turned out that the static destructor was
not run at all :/

Replace main() with a minimized version of main-func.h. This also
prevents emitting negative exit codes.

5 months agoMerge pull request #30399 from YHNdnzj/memory-accounting-always-peak
Yu Watanabe [Sun, 10 Dec 2023 05:11:05 +0000 (14:11 +0900)] 
Merge pull request #30399 from YHNdnzj/memory-accounting-always-peak

systemctl-show: always show memory peak if available

5 months agohibernate-util: de-duplicate clear_efi_hibernate_location
Mike Yuan [Sat, 9 Dec 2023 14:34:43 +0000 (22:34 +0800)] 
hibernate-util: de-duplicate clear_efi_hibernate_location

5 months agoMerge pull request #30400 from bluca/coverity
Yu Watanabe [Sun, 10 Dec 2023 05:07:37 +0000 (14:07 +0900)] 
Merge pull request #30400 from bluca/coverity

Assorted coverity fixes

5 months agotest-network: add test case for issue #30403 30404/head
Yu Watanabe [Sun, 10 Dec 2023 05:04:28 +0000 (14:04 +0900)] 
test-network: add test case for issue #30403

5 months agonetwork/route: fix reachability check when peer address is specified
Yu Watanabe [Sun, 10 Dec 2023 04:56:46 +0000 (13:56 +0900)] 
network/route: fix reachability check when peer address is specified

When an address with peer address is specified, the kernel by default
adds the prefix route for the peer address. When ManageForeignRoute=no
is set, then we also needs to check the prefix for the peer address.

Fixes #30403.

5 months agotest-login: remove dead code 30400/head
Luca Boccassi [Sat, 9 Dec 2023 13:10:18 +0000 (13:10 +0000)] 
test-login: remove dead code

HANDLE_SLEEP is == _HANDLE_ACTION_SLEEP_LAST and the loop is bounded
by < _HANDLE_ACTION_SLEEP_LAST, so no need to check for it

CID#1529414

5 months agologind: use ASSERT_PTR to validate result before use
Luca Boccassi [Sat, 9 Dec 2023 13:04:51 +0000 (13:04 +0000)] 
logind: use ASSERT_PTR to validate result before use

handle_action_lookup() in general can return NULL, but not
here as the handle is checked before, so add an assert.

CID#1529415
CID#1529416

5 months agosystemctl: fix copy/paste
Luca Boccassi [Sat, 9 Dec 2023 12:58:48 +0000 (12:58 +0000)] 
systemctl: fix copy/paste

on_circle is set twice to the same value

CID#1529418

5 months agojournal-remote: set upper length bound when parsing incoming headers
Luca Boccassi [Sat, 9 Dec 2023 12:09:42 +0000 (12:09 +0000)] 
journal-remote: set upper length bound when parsing incoming headers

CID#1529420

5 months agosystemctl-show: always show memory peak if available 30399/head
Mike Yuan [Sat, 9 Dec 2023 12:19:57 +0000 (20:19 +0800)] 
systemctl-show: always show memory peak if available

5 months agocore/cgroup: cache the last memory usage values before destroying cgroup
Mike Yuan [Sat, 9 Dec 2023 12:10:31 +0000 (20:10 +0800)] 
core/cgroup: cache the last memory usage values before destroying cgroup

Currently, memory accounting values are only cached if it was queued
at least once before destroying cgroup. Let's always cache it like
what we already do for CPU usage.

Preparation for later changes.

5 months agomount: check that MountParameters is valid before use
Luca Boccassi [Sat, 9 Dec 2023 11:56:50 +0000 (11:56 +0000)] 
mount: check that MountParameters is valid before use

Follow-up for 6c75eff6afd90

CID#1530430

5 months agoNEWS: fix typo s/show/shown/
Florian Schmaus [Sat, 9 Dec 2023 11:42:17 +0000 (12:42 +0100)] 
NEWS: fix typo s/show/shown/

5 months agoMerge pull request #30387 from mrc0mmand/TEST-17-tweaks
Luca Boccassi [Sat, 9 Dec 2023 11:06:37 +0000 (11:06 +0000)] 
Merge pull request #30387 from mrc0mmand/TEST-17-tweaks

test: a couple of tweaks for TEST-17-UDEV

5 months agoMerge pull request #30384 from YHNdnzj/rename-process
Mike Yuan [Sat, 9 Dec 2023 11:04:07 +0000 (19:04 +0800)] 
Merge pull request #30384 from YHNdnzj/rename-process

core/executor: save argv for later use by rename_process()

5 months agoMerge pull request #30362 from mrc0mmand/cat-highlight-directives
Yu Watanabe [Sat, 9 Dec 2023 09:54:46 +0000 (18:54 +0900)] 
Merge pull request #30362 from mrc0mmand/cat-highlight-directives

shared: highlight directives when dumping configs

5 months agoRevert "packit: don't take ownership of /etc/ssh/sshd_config.d/"
Zbigniew Jędrzejewski-Szmek [Fri, 8 Dec 2023 17:40:15 +0000 (18:40 +0100)] 
Revert "packit: don't take ownership of /etc/ssh/sshd_config.d/"

This reverts commit 9f7d1899235a237ba7a6000479cbf3965b224fd9.
systemd.spec was updated in [1], so we don't need this here anymore.

[1] https://src.fedoraproject.org/rpms/systemd/c/245a2587e095a08a61af4e48f7daa57dee3629e6

5 months agotest_ukify: raise timeout 30389/head
Zbigniew Jędrzejewski-Szmek [Fri, 8 Dec 2023 18:17:14 +0000 (19:17 +0100)] 
test_ukify: raise timeout

With a sufficiently large initrd, the tests take 25 s on my laptop.
Normally, they'd be quicker, but since we use what we find on the
system, we don't control this. Let's raise the timeout to reduce the
chances of a spurious failure.

5 months agotest_ukify: formatting
Zbigniew Jędrzejewski-Szmek [Fri, 8 Dec 2023 18:15:50 +0000 (19:15 +0100)] 
test_ukify: formatting

5 months agotest_ukify: explicitly remove big temporary directories
Zbigniew Jędrzejewski-Szmek [Fri, 8 Dec 2023 18:10:09 +0000 (19:10 +0100)] 
test_ukify: explicitly remove big temporary directories

pytest intentionally keeps around a limited number of the previous test
temporary directories [1]. This is generally OK, but in our tests that generate
initrds, we create a few very large files (both the initrd and kernel in a few
copies), which quickly adds up. I had a particularly large initrd (because of
some mkosi-initrd shenanigans), and I unded up with dozens of gigabytes of
temporary files from the tests. Let's just nuke the dirs where we write
kernel data.

[1] https://github.com/pytest-dev/pytest/issues/543

5 months agotest_ukify: use Path-based fixtures
Zbigniew Jędrzejewski-Szmek [Fri, 8 Dec 2023 18:01:27 +0000 (19:01 +0100)] 
test_ukify: use Path-based fixtures

Quoting https://docs.pytest.org/en/stable/how-to/tmp_path.html#the-default-base-temporary-directory:
> The tmpdir and tmpdir_factory fixtures are similar to tmp_path and
> tmp_path_factory, but use/return legacy py.path.local objects rather than
> standard pathlib.Path objects.
>
> These days, it is preferred to use tmp_path and tmp_path_factory.

5 months agotest: backup /etc/udev/udev.conf only if it exists 30387/head
Frantisek Sumsal [Fri, 8 Dec 2023 17:38:41 +0000 (18:38 +0100)] 
test: backup /etc/udev/udev.conf only if it exists

On Fedora systemd recently moved all of its configuration files to
/usr/lib/ [0], so make sure we account for this case as well.

[   42.450325] testsuite-17.sh[800]: + mkdir -p /run/udev/rules.d
[   42.466504] testsuite-17.sh[800]: + cp -f /etc/udev/udev.conf /etc/udev/udev.conf.bckp
[   42.503348] testsuite-17.sh[802]: cp: cannot stat '/etc/udev/udev.conf': No such file or directory

[0] https://src.fedoraproject.org/rpms/systemd/c/29eb35530b29232eed65718d0cd96d67cd7ffd6b?branch=rawhide

5 months agotest: reset systemd-udevd.service restart counter
Frantisek Sumsal [Fri, 8 Dec 2023 17:01:42 +0000 (18:01 +0100)] 
test: reset systemd-udevd.service restart counter

Since we restart systemd-udevd here a couple of times, we might hit the
rate limit in later tests:

[   26.028355] testsuite-17.sh[2074]: + udevadm control -e
[   26.028355] testsuite-17.sh[2074]: + udevadm control -l emerg
[   26.126160] systemd[1]: systemd-udevd.service: Start request repeated too quickly.
[   26.126213] systemd[1]: systemd-udevd.service: Failed with result 'start-limit-hit'.
[   26.140310] systemd[1]: Failed to start systemd-udevd.service.
[   26.140897] systemd[1]: systemd-udevd-control.socket: Failed with result 'service-start-limit-hit'.
[   26.141286] systemd[1]: systemd-udevd-kernel.socket: Failed with result 'service-start-limit-hit'.
[   26.142225] testsuite-17.sh[2074]: + udevadm control -l alert
[   26.149206] udevadm[2088]: Failed to send request to set log level: No such file or directory

Follow-up to: 6ef512c0bb

5 months agocore/executor: save argv for later use by rename_process() 30384/head
Mike Yuan [Fri, 8 Dec 2023 13:14:11 +0000 (21:14 +0800)] 
core/executor: save argv for later use by rename_process()

Partially fixes #30352

5 months agocore/exec-invoke: voidify one rename_process call
Mike Yuan [Fri, 8 Dec 2023 11:46:53 +0000 (19:46 +0800)] 
core/exec-invoke: voidify one rename_process call

5 months agorepart: Don't look for --make-ddi= definitions inside --root=
Daan De Meyer [Thu, 7 Dec 2023 13:26:10 +0000 (14:26 +0100)] 
repart: Don't look for --make-ddi= definitions inside --root=

It doesn't really make sense to go looking for these inside the
given root directory. While we should resolve specifiers and such
based on the given root directory, let's look up the image definitions
on the host system as there's a good chance they're coupled to the
repart version we're using so there's all kinds of chances for problems
if we use the definitions from the image we're building instead of those
from the host.

5 months agocore: create workdir/upperdir when mounting a Type=overlay mount unit
Luca Boccassi [Thu, 7 Dec 2023 23:19:36 +0000 (23:19 +0000)] 
core: create workdir/upperdir when mounting a Type=overlay mount unit

So far we created the target directory, and the source for bind mounts,
but not workdir/upperdir for overlays, so it has to be done separately
and strictly before the unit is started, which is annoying. Check the
options when creating directories, and if upper/work directories are
specified, create them.

5 months agoinstall: don't translate unit instances to paths when reenabling them
Frantisek Sumsal [Wed, 6 Dec 2023 15:24:21 +0000 (16:24 +0100)] 
install: don't translate unit instances to paths when reenabling them

For unit instances install_info_discover() returns path to the template,
which then generates confusing errors when passed to
do_unit_file_enable():

~# build/systemctl --root=/tmp/systemctl-test.N9ysbz reenable templ1@two.service
Unit name: templ1@two.service; p: /etc/systemd/system/templ1@.service
Removed "/tmp/systemctl-test.N9ysbz/etc/systemd/system/services.target.wants/templ1@two.service".
Failed to reenable templ1@.service, destination unit services.target is a non-template unit.

This can also be seen with a different reproducer using getty@.service
and a simple bind mount to / - there's no error this time, but it tries
to create a symlink for the default instance (from DefaultInstance=tty1),
which is also incorrect:

~# SYSTEMD_LOG_LEVEL=debug systemctl --root /mnt/bindroot/ reenable getty@test.service
Symlink /mnt/bindroot/etc/systemd/system/getty.target.wants/getty@tty1.service → /usr/lib/systemd/system/getty@.service already exists

Follow-up to: 29a7c59abbe
Resolves: #24740

5 months agocore: relax dependency on RootImage= storage from Requires= to Wants=
Luca Boccassi [Mon, 27 Nov 2023 23:32:31 +0000 (23:32 +0000)] 
core: relax dependency on RootImage= storage from Requires= to Wants=

If a unit is running in an image and wants to survive a soft-reboot,
then it can't be deactivated by the storage of the image going away.
Relax the dependency to a Wants=. Access to the image is not needed
when the unit is running anyway, so downgrade to Wants=.

5 months agocore: do not make private /dev/ read-only too soon
Luca Boccassi [Thu, 7 Dec 2023 22:19:11 +0000 (22:19 +0000)] 
core: do not make private /dev/ read-only too soon

The read-only bit is flipped after setting up all the mounts, so that
bind mounts can be added. Remove the early config, and add a unit
test.

Fixes https://github.com/systemd/systemd/issues/30372

5 months agorepart: Re-open file descriptor to partition target after mkfs
Daan De Meyer [Tue, 5 Dec 2023 13:56:00 +0000 (14:56 +0100)] 
repart: Re-open file descriptor to partition target after mkfs

The mkfs binary might unlink the path we give it and replace it with
a new file so let's make sure that our fd points to any new file rather
than the old deleted file.

Specifically this fixes erofs partition generation.

5 months agotmpfiles.d/systemd-nologin.conf: use f+ instead of F (deprecated)
Mike Yuan [Thu, 7 Dec 2023 15:14:35 +0000 (23:14 +0800)] 
tmpfiles.d/systemd-nologin.conf: use f+ instead of F (deprecated)

Fixes #30368

5 months agofirstboot: remove /etc/localtime on --reset
Nick Rosbrook [Thu, 7 Dec 2023 21:21:51 +0000 (16:21 -0500)] 
firstboot: remove /etc/localtime on --reset

The --reset option is supposed to remove all files configured by
firstboot, but currently it does not remove /etc/localtime.

5 months agotest: avoid NO_CAST.INTEGER_OVERFLOW in test-oomd-util (#30365)
aslepykh [Fri, 8 Dec 2023 01:54:52 +0000 (04:54 +0300)] 
test: avoid NO_CAST.INTEGER_OVERFLOW in test-oomd-util (#30365)

The  `.mem_total` variable has `uint64_t` type, therefore, when multiplying the number
`20971512` by the number `1024` with the suffix `U`, we will not get the expected result of
`21,474,828,288`, since the number `20971512` without an explicit type indication has
`uint32_t` type.

First, multiplication will occur in accordance with the `uint32_t` type; this operation will
cause a **type overflow**, and only then will this result be assigned to a `uint64_t` type
variable.

It's worth adding the `UL` suffix to the number `20971512` to avoid **overflow**.

Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Author A. Slepykh.

5 months agovarious: don't log synthetic EIO for fwrite
Mike Yuan [Thu, 7 Dec 2023 16:49:17 +0000 (00:49 +0800)] 
various: don't log synthetic EIO for fwrite

Follow-up for f9568765d4d3d57de1ec01d85f0a0682920f4d10

5 months agoman: correct the path for location of "machinectl edit" setting file
Shulhan [Thu, 7 Dec 2023 13:58:58 +0000 (20:58 +0700)] 
man: correct the path for location of "machinectl edit" setting file

The correct path where setting file located should be
"under /etc/systemd/nspawn", not "under /etc".

5 months agoanalyze: dump system config files with highlighted sections/directives 30362/head
Frantisek Sumsal [Thu, 7 Dec 2023 13:44:21 +0000 (14:44 +0100)] 
analyze: dump system config files with highlighted sections/directives

5 months agoshared: highlight directives when dumping configs
Frantisek Sumsal [Thu, 7 Dec 2023 09:52:40 +0000 (10:52 +0100)] 
shared: highlight directives when dumping configs

We already highlight sections and "de-highlight" comments, so let's add
the last piece of the puzzle and highlight the configuration directives
to visually distinguish them from the values.

Closes: #13416
5 months agopackit: don't take ownership of /etc/ssh/sshd_config.d/
Frantisek Sumsal [Thu, 7 Dec 2023 08:36:52 +0000 (09:36 +0100)] 
packit: don't take ownership of /etc/ssh/sshd_config.d/

7e3607996a creates a symlink under /etc/ssh/sshd_config.d/ and with
current Rawhide RPM stuff the systemd RPM tries to take ownership of
that directory which conflicts with the openssh-server package. Let's
temporarily tweak the regex in split-files.py until this changes makes
it to Rawhide.

5 months agoMerge pull request #30060 from poettering/analyze-archs
Yu Watanabe [Thu, 7 Dec 2023 06:47:30 +0000 (15:47 +0900)] 
Merge pull request #30060 from poettering/analyze-archs

analyze: add "archs" verb that lists all known architectures

5 months agojournalctl: don't skip over messages not matching the cursor
Frantisek Sumsal [Tue, 5 Dec 2023 16:38:25 +0000 (17:38 +0100)] 
journalctl: don't skip over messages not matching the cursor

When --after-cursor=/--cursor-file= is used together with a journal
filter, we still skipped over the first matching entry even if it wasn't
the entry the cursor points at, thus missing one "valid" entry
completely. Let's fix this by checking if the entry cursor after seeking
matches the user provided cursor, and skip to the next entry only when
the cursors match.

Resolves: #30288

5 months agoMerge pull request #30312 from yuwata/journal-cleanups
Yu Watanabe [Thu, 7 Dec 2023 04:23:06 +0000 (13:23 +0900)] 
Merge pull request #30312 from yuwata/journal-cleanups

journal: several cleanups

5 months agonspawn: Check later whether to keep/drop CAP_NET_BIND_SERVICE
Daan De Meyer [Tue, 5 Dec 2023 09:24:13 +0000 (10:24 +0100)] 
nspawn: Check later whether to keep/drop CAP_NET_BIND_SERVICE

Currently the check doesn't take any settings from nspawn settings
files into account, so let's delay the check until after we've
loaded any settings file.

5 months agogpt-auto-generator: Pass cryptsetup credentials to cryptsetup
Daan De Meyer [Sun, 3 Dec 2023 19:19:08 +0000 (20:19 +0100)] 
gpt-auto-generator: Pass cryptsetup credentials to cryptsetup

cryptsetup reads a bunch of credentials now but we don't pass import
those in any service units yet. Let's pass through all cryptsetup
prefixed credentials to the systemd-cryptsetup@root instance.

5 months agoMerge pull request #30322 from YHNdnzj/hibernate-improvements
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:29:43 +0000 (22:29 +0100)] 
Merge pull request #30322 from YHNdnzj/hibernate-improvements

A few improvements for hibernate-util/hibernate-resume

5 months agoMerge pull request #30316 from mrc0mmand/revert-journal-upload-user
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:28:34 +0000 (22:28 +0100)] 
Merge pull request #30316 from mrc0mmand/revert-journal-upload-user

Revert "sysusers.d: create the user for systemd-journal-upload.service"

5 months agoMerge pull request #30302 from keszybz/systemd-edit-stdin
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:28:02 +0000 (22:28 +0100)] 
Merge pull request #30302 from keszybz/systemd-edit-stdin

systemctl edit --stdin

5 months agoMerge pull request #30085 from YHNdnzj/networkctl-edit-runtime
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:27:01 +0000 (22:27 +0100)] 
Merge pull request #30085 from YHNdnzj/networkctl-edit-runtime

networkctl: introduce --runtime for editing network config under /run/

5 months agoMerge pull request #30271 from YHNdnzj/executor-cloexec
Lennart Poettering [Wed, 6 Dec 2023 21:26:40 +0000 (22:26 +0100)] 
Merge pull request #30271 from YHNdnzj/executor-cloexec

fdset,core/executor: ocloexecification ™️

5 months agoMerge pull request #29987 from yuwata/network-bridge-vlan
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:25:42 +0000 (22:25 +0100)] 
Merge pull request #29987 from yuwata/network-bridge-vlan

network: remove unnecessary bridge vlan IDs

5 months agoMerge pull request #29853 from YHNdnzj/sleep-automated
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:25:13 +0000 (22:25 +0100)] 
Merge pull request #29853 from YHNdnzj/sleep-automated

logind: support Sleep() that automatically choose a sleep operation

5 months agoMerge pull request #30338 from keszybz/fwrite-error-handling
Lennart Poettering [Wed, 6 Dec 2023 21:24:28 +0000 (22:24 +0100)] 
Merge pull request #30338 from keszybz/fwrite-error-handling

Fix fwrite() error handling

5 months agoREADME.md: irc:// URLs are not rendered as links by markdown on Github
Luca Boccassi [Wed, 6 Dec 2023 18:33:03 +0000 (18:33 +0000)] 
README.md: irc:// URLs are not rendered as links by markdown on Github

Use the webchat link and spell out the channel and server instead

5 months agojournal-gatewayd: add since/until parameters for /entries
Samuel BF [Thu, 5 Oct 2023 19:39:45 +0000 (21:39 +0200)] 
journal-gatewayd: add since/until parameters for /entries

Request with Range header like 'entries=<cursor>:' (with a colon at the end,
invalid syntax per the doc), is now rejected with error 400 Bad Request.

fix #4883

5 months agoudev: generate system-unique storage symlinks using device path
Roland Hieber [Mon, 18 Sep 2023 09:52:06 +0000 (11:52 +0200)] 
udev: generate system-unique storage symlinks using device path

When the same disk image is written to multiple storage units, for
example an external SD card and an internal eMMC, the symlinks in
/dev/disk/by-{label,uuid,partlabel,partuuid}/ are no longer unique, and
will point to the device that is probed last.

Adressing partitions via labels and UUIDs is nice to work with, and
depending on the use case, it might also be more robust than using the
symlinks in /dev/disk/by-path/ containing the partition number. Combine
the two approaches to create unique symlinks containing both the device
path as well as the respective UUIDs or labels, and throw in a symlink
using the devpath and the partition number for the sake of completeness.

For an exemplary GPT-partitioned disk at "platform-2198000.mmc" with a
partition containing an ext4 file system, this might create symlinks of
the following form:

  /dev/disk/by-path/platform-2198000.mmc-part/by-partnum/1
  /dev/disk/by-path/platform-2198000.mmc-part/by-partuuid/e5a75233-3b90-4aec-8075-b4dd7132b48d
  /dev/disk/by-path/platform-2198000.mmc-part/by-partlabel/rootfs
  /dev/disk/by-path/platform-2198000.mmc-part/by-uuid/b2c92f24-8215-4680-b931-f423aae5f1c9
  /dev/disk/by-path/platform-2198000.mmc-part/by-label/rootfs

Signed-off-by: Roland Hieber <rhi@pengutronix.de>
5 months agoMerge pull request #30353 from bluca/news
Zbigniew Jędrzejewski-Szmek [Wed, 6 Dec 2023 21:20:13 +0000 (22:20 +0100)] 
Merge pull request #30353 from bluca/news

Version bumps

5 months agoanalyze: teach "exit-status" verb json output too 30060/head
Lennart Poettering [Mon, 20 Nov 2023 13:52:31 +0000 (14:52 +0100)] 
analyze: teach "exit-status" verb json output too

5 months agoanalyze: teach "capability" verb JSON output too
Lennart Poettering [Mon, 20 Nov 2023 13:50:56 +0000 (14:50 +0100)] 
analyze: teach "capability" verb JSON output too

5 months agoanalyze: add "architectures" verb that lists all known architectures
Lennart Poettering [Thu, 16 Nov 2023 15:08:15 +0000 (16:08 +0100)] 
analyze: add "architectures" verb that lists all known architectures

5 months agosystemctl-whoami: use pidfd to refer to processes
Mike Yuan [Sat, 25 Nov 2023 14:10:16 +0000 (22:10 +0800)] 
systemctl-whoami: use pidfd to refer to processes

While at it, rephrase the output a bit. Before this commit, if
the pid doesn't exist, we output something hard to interpret -
"Failed to get unit for ourselves".

5 months agoMerge pull request #30101 from poettering/underline-rework
Lennart Poettering [Wed, 6 Dec 2023 21:13:12 +0000 (22:13 +0100)] 
Merge pull request #30101 from poettering/underline-rework

systemctl: "list-units" table tweaks

5 months agorecurse-dir: add new readdir_all_at() helper
Lennart Poettering [Wed, 22 Nov 2023 09:55:20 +0000 (10:55 +0100)] 
recurse-dir: add new readdir_all_at() helper

This new helper combines open() with readdir_all() to simplify a few
callers.

5 months agoMerge pull request #30295 from yuwata/hostnamectl-machine-id
Luca Boccassi [Wed, 6 Dec 2023 21:12:36 +0000 (21:12 +0000)] 
Merge pull request #30295 from yuwata/hostnamectl-machine-id

hostnamectl: read machine ID and boot ID through DBus

5 months agoMerge pull request #30183 from poettering/nlcr
Lennart Poettering [Wed, 6 Dec 2023 21:12:17 +0000 (22:12 +0100)] 
Merge pull request #30183 from poettering/nlcr

NL → CRNL conversion fixes when logging at the same time as ptyfwd runs

5 months agoshow-status: suffix output ith CRNL rather than just NL
Lennart Poettering [Fri, 24 Nov 2023 15:41:47 +0000 (16:41 +0100)] 
show-status: suffix output ith CRNL rather than just NL

This is similar to #30183 but focusses on the status output rather than
the log output.

Since the status output always goes to a TTY we don't have to
conditionalize things on isatty().

Fixes: #30184
5 months agouser-util: add new helper fully_set_uid_gid()
Lennart Poettering [Wed, 29 Nov 2023 16:45:06 +0000 (17:45 +0100)] 
user-util: add new helper fully_set_uid_gid()

Usually when we do setresuid() we also do setesgid() and setgroups().
Let's add a common helper that does all three, and use it everywhere.

5 months agomime: register confext/sysext images in shared-mime-info
Lennart Poettering [Mon, 20 Nov 2023 10:51:47 +0000 (11:51 +0100)] 
mime: register confext/sysext images in shared-mime-info

This make them recognized by file managers and stuff. Maybe one day we
should properly register mime types in the "vnd." namespace with IANA,
but I am too lazy to deal with the bureaucracy for that, hence let's
stick with the x. namespace for now.

This defines confext/sysext DDIs as subtype of:

https://www.iana.org/assignments/media-types/application/vnd.efi.img

Which is what everyone appears to use for raw disk images, in particular
if they contain a GPT partition table.

5 months agouserdbctl: enable ssh-authorized-keys logic by default
Lennart Poettering [Thu, 16 Nov 2023 17:47:52 +0000 (18:47 +0100)] 
userdbctl: enable ssh-authorized-keys logic by default

sshd now supports config file drop-ins, hence let's install one to hook
up "userdb ssh-authorized-keys", so that things just work.

We put the drop-in relatively early, so that other drop-ins generally
will override this.

Ideally sshd would support such drop-ins in /usr/ rather than /etc/, but
let's take what we can get. It's not that sshd's upstream was
particularly open to weird ideas from Linux people.

5 months agopid1: add ProtectSystem= as system-wide configuration, and default it to true in...
Lennart Poettering [Wed, 29 Nov 2023 17:52:28 +0000 (18:52 +0100)] 
pid1: add ProtectSystem= as system-wide configuration, and default it to true in the initrd

This adds a new ProtectSystem= setting that mirrors the option of the
same of services, but in a more restrictive way. If enabled will remount
/usr/ to read-only, very early at boot. Takes a special value "auto"
(which is the default) which is equivalent to true in the initrd, and
false otherwise.

Unlike the per-service option we don't support full/strict modes, but
the door is open to eventually support that too if it makes sense. It's
not entirely trivial though as we have very little mounted this early,
and hence the mechanism might not apply 1:1. Hence in this PR is a
conservative first step.

My primary goal with this is to lock down initrds a bit, since they
conceptually are mostly immutable, but they are unpacked into a mutable
tmpfs. let's tighten the screws a bit on that, and at least make /usr/
immutable.

This is particularly nice on USIs (i.e. Unified System Images, that pack
a whole OS into a UKI without transitioning out of it), such as
diskomator.