]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
2 months agotest: Add cases for failures to import the hierarchy 31801/head
Krzesimir Nowak [Thu, 29 Feb 2024 07:19:16 +0000 (08:19 +0100)] 
test: Add cases for failures to import the hierarchy

2 months agosysext: Fail when trying to import mutable layer that's a symlink to hierarchy
Krzesimir Nowak [Wed, 28 Feb 2024 15:34:05 +0000 (16:34 +0100)] 
sysext: Fail when trying to import mutable layer that's a symlink to hierarchy

2 months agotest, sysext: Actually fail the whole operation if sd-merge worker failed
Krzesimir Nowak [Wed, 28 Feb 2024 14:41:46 +0000 (15:41 +0100)] 
test, sysext: Actually fail the whole operation if sd-merge worker failed

This also fixes a wrong merge failure check.

2 months agotest: Add test cases for sysext ephemeral-import mode
Krzesimir Nowak [Thu, 29 Feb 2024 07:18:43 +0000 (08:18 +0100)] 
test: Add test cases for sysext ephemeral-import mode

2 months agoman: Document sysext ephemeral-import mode
Krzesimir Nowak [Wed, 28 Feb 2024 13:50:05 +0000 (14:50 +0100)] 
man: Document sysext ephemeral-import mode

2 months agosysext: Implement ephemeral import mode
Krzesimir Nowak [Wed, 28 Feb 2024 13:23:22 +0000 (14:23 +0100)] 
sysext: Implement ephemeral import mode

To enable it, use "ephemeral-import" either for mutable mode environment
variable or for value of "--mutable=" flag.

This is a combination of "ephemeral" and "import" modes. It results in a
mutable hierarchy that includes contents of the mutable extension data, but the
modifications are thrown away when the hierarchy is unmerged.

2 months agotest: Extend sysext tests with cases using ephemeral mode
Krzesimir Nowak [Wed, 28 Feb 2024 08:59:18 +0000 (09:59 +0100)] 
test: Extend sysext tests with cases using ephemeral mode

2 months agoman: Document sysext ephemeral mode
Krzesimir Nowak [Wed, 28 Feb 2024 08:42:25 +0000 (09:42 +0100)] 
man: Document sysext ephemeral mode

2 months agosysext: Implement ephemeral mode
Krzesimir Nowak [Wed, 28 Feb 2024 08:17:27 +0000 (09:17 +0100)] 
sysext: Implement ephemeral mode

To enable it, use "ephemeral" either for mutable mode environment variable or
for value of "--mutable=" flag.

Instead of using mutable dir in /var/lib/extensions.mutable/<hierarchy>, we
create a directory for overlayfs upperdir and workdir in the same tmpfs mount
that sysext worker process creates in /run/systemd/sysext. As the path for the
workdir will be gone when the worker quits, there is no need to do any
additional cleanup. As such, there is also no need to store a path to workdir
in the metadata directory.

2 months agosysext: Add missing --mutable mode in help output
Krzesimir Nowak [Tue, 27 Feb 2024 15:29:08 +0000 (16:29 +0100)] 
sysext: Add missing --mutable mode in help output

2 months agoman: Install sysext man pages when ENABLE_SYSEXT is true
Krzesimir Nowak [Tue, 19 Mar 2024 13:47:36 +0000 (14:47 +0100)] 
man: Install sysext man pages when ENABLE_SYSEXT is true

2 months agotest: Extend sysext tests with cases using env var for mutable mode
Krzesimir Nowak [Tue, 27 Feb 2024 13:52:30 +0000 (14:52 +0100)] 
test: Extend sysext tests with cases using env var for mutable mode

2 months agotest: Fail sysext test if reusing a root directory
Krzesimir Nowak [Tue, 19 Mar 2024 13:40:57 +0000 (14:40 +0100)] 
test: Fail sysext test if reusing a root directory

2 months agodocs: Document SYSTEMD_SYSEXT_MUTABLE_MODE env var
Krzesimir Nowak [Wed, 20 Mar 2024 07:34:41 +0000 (08:34 +0100)] 
docs: Document SYSTEMD_SYSEXT_MUTABLE_MODE env var

2 months agosysext: Add support for mutable mode environment variables
Krzesimir Nowak [Tue, 19 Mar 2024 13:01:00 +0000 (14:01 +0100)] 
sysext: Add support for mutable mode environment variables

The environment variable names are SYSTEMD_SYSEXT_MUTABLE_MODE for
systemd-sysext and SYSTEMD_CONFEXT_MUTABLE_MODE for systemd-confext. These
override the default mutable mode setting, but can be still overridden by a
command-line flag.

2 months agosysext: Move parsing mutable mode to a separate function
Krzesimir Nowak [Tue, 19 Mar 2024 12:20:46 +0000 (13:20 +0100)] 
sysext: Move parsing mutable mode to a separate function

2 months agobasic/virt: Fix virtualbox detection on proprietary system via board_vendor
Friedrich Altheide [Wed, 20 Mar 2024 16:48:39 +0000 (17:48 +0100)] 
basic/virt: Fix virtualbox detection on proprietary system via board_vendor

Identify an virtualbox instance even if product_name, sys_vendor and bios_vendor reflect the
information of the real hardware, by checking if board_vendor == "Oracle Corporation"

This fixes #13429 again
The previous fix was removed in #21127

2 months agopo: Translated using Weblate (French)
Pierre GRASSER [Fri, 22 Mar 2024 10:36:04 +0000 (11:36 +0100)] 
po: Translated using Weblate (French)

Currently translated at 100.0% (233 of 233 strings)

Co-authored-by: Pierre GRASSER <pierre.grasser@proton.me>
Translate-URL: https://translate.fedoraproject.org/projects/systemd/main/fr/
Translation: systemd/main

2 months agotest: explain how Ubuntu CI log URLs are created
Luca Boccassi [Sun, 24 Mar 2024 13:02:56 +0000 (13:02 +0000)] 
test: explain how Ubuntu CI log URLs are created

Not trivially obvious, so add a couple of paragraph to explain it

2 months agoshared: Fix TPM2 unsealing when PCR values change
Gabríel Arthúr Pétursson [Wed, 20 Mar 2024 16:48:36 +0000 (16:48 +0000)] 
shared: Fix TPM2 unsealing when PCR values change

Recreate the encryption session on each retry. It's invalidated along
with the policy session when freed, failing subsequent retries.

Unsealing HMAC key.
WARNING:esys:src/tss2-esys/api/Esys_Unseal.c:295:Esys_Unseal_Finish() Received TPM Error
ERROR:esys:src/tss2-esys/api/Esys_Unseal.c:98:Esys_Unseal() Esys Finish ErrorCode (0x00000128)
A PCR value changed during the TPM2 policy session, restarting HMAC key unsealing (30 tries left).
Missing encryption session
Failed to unseal secret using TPM2: Invalid argument

Fixes #31881

2 months agoMerge pull request #31919 from YHNdnzj/analyze-verify
Luca Boccassi [Sun, 24 Mar 2024 11:50:44 +0000 (11:50 +0000)] 
Merge pull request #31919 from YHNdnzj/analyze-verify

Some fixes/improvements for analyze

2 months agoMerge pull request #31916 from YHNdnzj/socket-load-service
Luca Boccassi [Sun, 24 Mar 2024 11:43:37 +0000 (11:43 +0000)] 
Merge pull request #31916 from YHNdnzj/socket-load-service

core/socket: validate service unit load state before continuing

2 months agoMerge pull request #31886 from DaanDeMeyer/logind
Mike Yuan [Sun, 24 Mar 2024 11:19:12 +0000 (19:19 +0800)] 
Merge pull request #31886 from DaanDeMeyer/logind

logind: Add fallback for when the PIDFDs= property is not available

2 months agoMerge pull request #31917 from keszybz/path-equal-ptr-drop
Luca Boccassi [Sun, 24 Mar 2024 11:10:58 +0000 (11:10 +0000)] 
Merge pull request #31917 from keszybz/path-equal-ptr-drop

Drop unnecessary path_equal_ptr() wrapper

2 months agoMerge pull request #31913 from YHNdnzj/dynamic-user-unref
Luca Boccassi [Sun, 24 Mar 2024 11:10:10 +0000 (11:10 +0000)] 
Merge pull request #31913 from YHNdnzj/dynamic-user-unref

core/dynamic-user: trivial modernization

2 months agobpf-socket-bind: fix unexpected behavior with either 0 allow or deny rules
networkException [Sun, 10 Mar 2024 17:55:06 +0000 (18:55 +0100)] 
bpf-socket-bind: fix unexpected behavior with either 0 allow or deny rules

This patch fixes an issue where, when not specifiying either at least one
`SocketBindAllow` or `SocketBindDeny` rule, behavior for the bind syscall
filtering would be unexpected.

For example, when trying to bind to a port with only "SocketBindDeny=any"
given, the syscall would succeed:

> systemd-run -t -p "SocketBindDeny=any" nc -l 8080

Expected with this set of rules (also in accordance with the documentation)
would be an Operation not permitted error.

This behavior occurs because a default initialized socket_bind_rule struct
matches what "any" represents. When creating the bpf list all elements get
default initialized, as such represeting "any". Seemingly it is necressarry
to set the size of the map to at least one, as such if no allow rule is
given default initialization and minimal map size cause one any allow rule
to be in the map, causing the behavior observed above.

This patch solves this by introducing a new "match nothing" magic stored in
the rule's address family and setting such a rule as the first one if no
rule is given, making sure that default initialized rule structs are never
used.

Resolves #30556

2 months agoAdded resolution for Huion Kamvas Pro 19
mkubiak [Sat, 23 Mar 2024 16:53:01 +0000 (17:53 +0100)] 
Added resolution for Huion Kamvas Pro 19

2 months agoMerge pull request #31552 from AdrianVovk/homed-update-policy-v2-split
Luca Boccassi [Sun, 24 Mar 2024 10:11:09 +0000 (10:11 +0000)] 
Merge pull request #31552 from AdrianVovk/homed-update-policy-v2-split

Homed update policy: offline updates & use keyring

2 months agoanalyze: refuse --global dot/verify 31919/head
Mike Yuan [Fri, 22 Mar 2024 16:35:09 +0000 (00:35 +0800)] 
analyze: refuse --global dot/verify

I don't quite understand the rationale of making these
verbs work with --global back in the day. But realistically
they interact with/spawn manager, while there's no
--global runtime scope manager. And to verify/inspect user
units it's sufficient to just use --user.

Fixes #31911

2 months agoanalyze-dot: also show BindsTo= in --require
Mike Yuan [Fri, 22 Mar 2024 19:18:42 +0000 (03:18 +0800)] 
analyze-dot: also show BindsTo= in --require

2 months agoanalyze-dot: minor modernization
Mike Yuan [Fri, 22 Mar 2024 16:34:53 +0000 (00:34 +0800)] 
analyze-dot: minor modernization

2 months agoanalyze-security: use FOREACH_ARRAY
Mike Yuan [Fri, 22 Mar 2024 16:49:45 +0000 (00:49 +0800)] 
analyze-security: use FOREACH_ARRAY

2 months agocore/socket: use FOREACH_ARRAY at one more place 31916/head
Mike Yuan [Sat, 23 Mar 2024 17:07:30 +0000 (01:07 +0800)] 
core/socket: use FOREACH_ARRAY at one more place

2 months agocore/socket: clean up socket peer handling a bit
Mike Yuan [Sat, 23 Mar 2024 11:55:27 +0000 (19:55 +0800)] 
core/socket: clean up socket peer handling a bit

Currently, SocketPeer object acquired through
socket_acquire_peer() are referenced twice
in socket_enter_running and service_set_socket_fd,
and the reference taken by former gets dropped
through _cleanup_. This is a bit confusing.
Let's just pass ownership instead.

2 months agocore/socket: remove duplicate unit_add_two_dependencies
Mike Yuan [Sat, 23 Mar 2024 09:27:46 +0000 (17:27 +0800)] 
core/socket: remove duplicate unit_add_two_dependencies

2 months agocore/socket: validate service unit load state before continuing
Mike Yuan [Sat, 23 Mar 2024 09:26:55 +0000 (17:26 +0800)] 
core/socket: validate service unit load state before continuing

Fixes #31915

2 months agocore: introduce UNIT_IS_LOAD_ERROR helper
Mike Yuan [Sat, 23 Mar 2024 09:37:36 +0000 (17:37 +0800)] 
core: introduce UNIT_IS_LOAD_ERROR helper

2 months agoshared/install: use PATH_IN_SET() 31917/head
Zbigniew Jędrzejewski-Szmek [Sat, 23 Mar 2024 12:30:24 +0000 (13:30 +0100)] 
shared/install: use PATH_IN_SET()

2 months agoDrop unnecessary path_equal_ptr() wrapper
Zbigniew Jędrzejewski-Szmek [Sat, 23 Mar 2024 12:18:24 +0000 (13:18 +0100)] 
Drop unnecessary path_equal_ptr() wrapper

path_equal already works with NULL pointers.

2 months agocore/swap: another try on memory mgmt
Mike Yuan [Sat, 23 Mar 2024 08:53:50 +0000 (16:53 +0800)] 
core/swap: another try on memory mgmt

Follow-up for ba31a5018f99864c22dd4e0f10712456c7abc934

Another stupid mistake... Shouldn't have
written anything when I was tired.

2 months agoFix bpf-framework build failure with gcc-bpf
Michael Biebl [Fri, 22 Mar 2024 12:26:45 +0000 (13:26 +0100)] 
Fix bpf-framework build failure with gcc-bpf

The -mkernel option was dropped in
https://github.com/gcc-mirror/gcc/commit/da445a5858299ed2a72af1089c225a438ab93ce2

We also need to ensure that the include paths are properly set for the
linux kernel headers.

Fixes: #31869
2 months agoMerge pull request #31907 from mrc0mmand/efi-shenanigans
Zbigniew Jędrzejewski-Szmek [Sat, 23 Mar 2024 11:04:14 +0000 (12:04 +0100)] 
Merge pull request #31907 from mrc0mmand/efi-shenanigans

efi: check if all sections of our EFI binaries are properly aligned

2 months agoMerge pull request #31779 from keszybz/elf2efi-clang-18
Zbigniew Jędrzejewski-Szmek [Sat, 23 Mar 2024 11:02:34 +0000 (12:02 +0100)] 
Merge pull request #31779 from keszybz/elf2efi-clang-18

Make elf2efi work with clang-18

2 months agoTEST-46-HOMED: Disable auth rate-limiting 31552/head
Adrian Vovk [Tue, 5 Mar 2024 17:25:42 +0000 (12:25 -0500)] 
TEST-46-HOMED: Disable auth rate-limiting

Rate limiting authentication attempts in the test can cause somewhat
sporadic test failures: adding a test case might suddenly cause future
test cases to fail because of too many authentication attempts too
quickly

We're not trying to test the rate-limiting, we're trying to test the
functionality of homed. So we effectively disable rate-limiting on all
the home areas we create

2 months agoupdate TODO
Adrian Vovk [Thu, 1 Feb 2024 19:15:48 +0000 (14:15 -0500)] 
update TODO

2 months agohomework: Implement offline updates
Adrian Vovk [Thu, 1 Feb 2024 18:35:03 +0000 (13:35 -0500)] 
homework: Implement offline updates

This makes it possible to update a home record (and blob directory) of a
home area that's either completely absent (i.e. on a USB stick that's
unplugged) or just inaccessible due to lack of authentication

2 months agohomework: Accept volume key from keyring
Adrian Vovk [Thu, 1 Feb 2024 16:43:48 +0000 (11:43 -0500)] 
homework: Accept volume key from keyring

This bypasses authentication (i.e. user_record_authenticate) if the
volume key was loaded from the keyring and no secret section is
provided.

This also changes Update() and Resize() to always try and load the
volume key from the keyring. This makes the secret section optional for
these methods while still letting them function (as long as the home
area is active)

2 months agohomework: Always upload volume key to keyring
Adrian Vovk [Thu, 1 Feb 2024 04:49:24 +0000 (23:49 -0500)] 
homework: Always upload volume key to keyring

This commit makes homework always upload the LUKS volume key into the
kernel keyring. This is different from previous behavior in three
notable ways:

- Previously, we'd only upload if auto-resize was on. In preparation for
upcoming changes, now we always upload

- Previously, we'd upload the user's actual password (or a password
obtained from a FIDO key or similar). Now, we upload the LUKS volume key
itself, to remove a layer of unnecessary indirection.

- Previously, Lock() wouldn't remove the key from the kernel keyring.
This, of course, defeats the purpose of Lock(), so now it removes the
key

This commit also allows the LUKS volume to be unlocked using the volume
key we obtained from the keyring.

2 months agohomed: Ensure closed FD is handled before bus req
Adrian Vovk [Thu, 21 Mar 2024 17:51:16 +0000 (13:51 -0400)] 
homed: Ensure closed FD is handled before bus req

Before this fix, the following sequence of events was possible:
1. A client holding a Ref() FD closes their FD
2. kernel sends notification that all clients closed their FDs
3. Another client obtains its own Ref() FD from homed
4. homed handles the notification that all clients have closed their
   Ref() FDs. Thus it loses track of the fact that the session is
   actually still being held open by the client from step 3

This change makes sure that homed won't respond to bus messages (and
thus won't open more Ref() FDs) until it has handled all notifications
about the existing FDs being closed.

logind has had a very similar fix applied to it in
e11544a8305ab9dea097c74bb16e296150c9cc10

Fixes https://github.com/systemd/systemd/issues/31518

2 months agocore/dynamic-user: trivial modernization 31913/head
Mike Yuan [Fri, 22 Mar 2024 19:43:30 +0000 (03:43 +0800)] 
core/dynamic-user: trivial modernization

2 months agocore/execute: use STR_IN_SET where appropriate
Mike Yuan [Fri, 22 Mar 2024 17:26:22 +0000 (01:26 +0800)] 
core/execute: use STR_IN_SET where appropriate

2 months agoMerge pull request #31670 from CodethinkLabs/vmspawn/generate_ssh_keys
Luca Boccassi [Fri, 22 Mar 2024 16:28:03 +0000 (16:28 +0000)] 
Merge pull request #31670 from CodethinkLabs/vmspawn/generate_ssh_keys

vmspawn: generate ssh keys

2 months agoMerge pull request #31908 from DaanDeMeyer/mkosi
Luca Boccassi [Fri, 22 Mar 2024 16:22:42 +0000 (16:22 +0000)] 
Merge pull request #31908 from DaanDeMeyer/mkosi

Various mkosi fixes

2 months agotree-wide: Add allow_pidfd argument to bus_append_scope_pidref() 31886/head
Daan De Meyer [Fri, 22 Mar 2024 16:03:35 +0000 (17:03 +0100)] 
tree-wide: Add allow_pidfd argument to bus_append_scope_pidref()

2 months agomkosi: Switch to Arch Linux packaging sources main branch 31908/head
Daan De Meyer [Fri, 22 Mar 2024 15:49:46 +0000 (16:49 +0100)] 
mkosi: Switch to Arch Linux packaging sources main branch

https://gitlab.archlinux.org/archlinux/packaging/packages/systemd/-/merge_requests/8
was merged so let's switch branches to the main branch.

2 months agomkosi: Disable debug package generation on Arch Linux
Daan De Meyer [Fri, 22 Mar 2024 15:49:10 +0000 (16:49 +0100)] 
mkosi: Disable debug package generation on Arch Linux

This is extremely slow since the latest pacman release, and since
we don't strip binaries, not really needed either.

2 months agotools/elf2efi: elif→if to make pylint happy 31779/head
Zbigniew Jędrzejewski-Szmek [Fri, 22 Mar 2024 14:44:17 +0000 (15:44 +0100)] 
tools/elf2efi: elif→if to make pylint happy

2 months agotools/elf2efi: skip empty .got section and its .relro_padding
Zbigniew Jędrzejewski-Szmek [Thu, 14 Mar 2024 09:33:11 +0000 (10:33 +0100)] 
tools/elf2efi: skip empty .got section and its .relro_padding

Resolves https://github.com/systemd/systemd/issues/31637.

lld-18 does the section setup differently than older versions. There is a bunch
of ordering chagnes, but it also inserts the following:

Sections:
Idx Name          Size      VMA               LMA               File off  Algn
...
  9 .got          00000000  00000000000283c0  00000000000283c0  000283c0  2**3
                  CONTENTS, ALLOC, LOAD, DATA
 10 .relro_padding 00000c40  00000000000283c0  00000000000283c0  000283c0  2**0
                  ALLOC
 11 .data         00000024  00000000000293c0  00000000000293c0  000283c0  2**4
                  CONTENTS, ALLOC, LOAD, DATA
...

This causes a problem for us, because we try to map the .got to .rodata,
and the subsequent .data to .data, and round down the VMA to the nearest
page, which causes the PE sections to overlap.

https://github.com/llvm/llvm-project/pull/66042 adds .relro_padding to make
sure that the RELRO segment is properly write protected and allocated. For our
binaries, the .got section is empty, so we can skip it safely, and the
.relro_padding section is not useful once .got has been dropped.

We don't expect .got sections, but they are apparently inserted on i386 and
aarch64 builds. Emit a warning until we figure out why they are there.

2 months agomkosi: Enable log context
Daan De Meyer [Fri, 22 Mar 2024 14:15:01 +0000 (15:15 +0100)] 
mkosi: Enable log context

2 months agomkosi: Make sure man and man-db are installed everywhere
Daan De Meyer [Fri, 22 Mar 2024 14:12:20 +0000 (15:12 +0100)] 
mkosi: Make sure man and man-db are installed everywhere

2 months agotest: Install test journals
Daan De Meyer [Fri, 22 Mar 2024 11:08:52 +0000 (12:08 +0100)] 
test: Install test journals

Let's package these just like we package other test data.

2 months agoMerge pull request #31839 from DaanDeMeyer/log
Daan De Meyer [Fri, 22 Mar 2024 14:11:11 +0000 (15:11 +0100)] 
Merge pull request #31839 from DaanDeMeyer/log

log: Add per target log levels

2 months agoefi: check if all sections of our EFI binaries are properly aligned 31907/head
Frantisek Sumsal [Fri, 22 Mar 2024 12:35:38 +0000 (13:35 +0100)] 
efi: check if all sections of our EFI binaries are properly aligned

2 months agoAdded more ASSERT macro and also make some test file to use them
Unique-Usman [Wed, 20 Mar 2024 17:35:55 +0000 (23:05 +0530)] 
Added more ASSERT macro and also make some test file to use them

2 months agoMerge pull request #31902 from YHNdnzj/swap-followup
Luca Boccassi [Fri, 22 Mar 2024 12:08:53 +0000 (12:08 +0000)] 
Merge pull request #31902 from YHNdnzj/swap-followup

core: some follow-ups

2 months agolog: Add per target log levels 31839/head
Daan De Meyer [Wed, 20 Mar 2024 08:34:46 +0000 (09:34 +0100)] 
log: Add per target log levels

For CI in mkosi, I want to configure systemd to log at debug level
to the journal, but not to the console. While we already have max
level settings for journald's forwarding settings, not every log line
goes to the journal, specifically during early boot and when units
are connected directly to the console (think systemd-firstboot), so
let's extend the log level options we already have to allow specifying
a comma separated list of values and lets allow prefixing values with
the log target they apply to to make this possible.

2 months agoefi: fix mixed indent
Frantisek Sumsal [Fri, 22 Mar 2024 11:11:49 +0000 (12:11 +0100)] 
efi: fix mixed indent

2 months agoMerge pull request #31900 from DaanDeMeyer/dissect
Yu Watanabe [Fri, 22 Mar 2024 11:07:34 +0000 (20:07 +0900)] 
Merge pull request #31900 from DaanDeMeyer/dissect

nspawn logging fix

2 months agocore/mount: use ASSERT_PTR in mount_setup_new_unit 31902/head
Mike Yuan [Fri, 22 Mar 2024 10:36:01 +0000 (18:36 +0800)] 
core/mount: use ASSERT_PTR in mount_setup_new_unit

2 months agocore/swap: fix memory management in swap_setup_unit
Mike Yuan [Fri, 22 Mar 2024 10:26:55 +0000 (18:26 +0800)] 
core/swap: fix memory management in swap_setup_unit

Follow-up for e9fa1bf704ad2f0a7e257e29889315118b0df459

2 months agonspawn: Use dissect_image_mount_and_warn() 31900/head
Daan De Meyer [Fri, 22 Mar 2024 09:48:46 +0000 (10:48 +0100)] 
nspawn: Use dissect_image_mount_and_warn()

2 months agodissect-image: Improve error messages
Daan De Meyer [Fri, 22 Mar 2024 09:48:35 +0000 (10:48 +0100)] 
dissect-image: Improve error messages

2 months agoMerge pull request #31868 from bluca/test_cleanup
Luca Boccassi [Thu, 21 Mar 2024 23:45:49 +0000 (23:45 +0000)] 
Merge pull request #31868 from bluca/test_cleanup

test: delete private images on clean-again

2 months agoMerge pull request #31892 from YHNdnzj/machinectl-minor-cleanup
Yu Watanabe [Thu, 21 Mar 2024 23:10:39 +0000 (08:10 +0900)] 
Merge pull request #31892 from YHNdnzj/machinectl-minor-cleanup

machinectl: minor modernization, use FOREACH_ARRAY

2 months agosd-boot: add support for support enrolling dbx
Gerd Hoffmann [Tue, 19 Mar 2024 13:49:51 +0000 (14:49 +0100)] 
sd-boot: add support for support enrolling dbx

usage:
  (1) get latest revocation list for your architecture
      from https://uefi.org/revocationlistfile
  (2) copy the file to $ESP/loader/keys/$name/dbx.auth

2 months agodocs: Add one more git submodule setting to configure
Daan De Meyer [Thu, 21 Mar 2024 15:07:58 +0000 (16:07 +0100)] 
docs: Add one more git submodule setting to configure

2 months agocgroup-util: use path_find_first_component where appropriate
Mike Yuan [Thu, 21 Mar 2024 10:29:07 +0000 (18:29 +0800)] 
cgroup-util: use path_find_first_component where appropriate

Prompted by 8922a728f732a716ecd17dd67cd39bc1a0fc4aa5

2 months agoMerge pull request #31890 from YHNdnzj/ASSERT_PTR
Yu Watanabe [Thu, 21 Mar 2024 22:57:46 +0000 (07:57 +0900)] 
Merge pull request #31890 from YHNdnzj/ASSERT_PTR

core: use ASSERT_PTR and RET_GATHER more

2 months agodbus-exporter: Set explicit mode on output directory
Daan De Meyer [Thu, 21 Mar 2024 18:14:56 +0000 (19:14 +0100)] 
dbus-exporter: Set explicit mode on output directory

Otherwise the created directory might have the sticky bit or the setgid
bit set as these are inherited from the parent directory.

2 months agomachinectl: minor modernization, use FOREACH_ARRAY 31892/head
Mike Yuan [Thu, 21 Mar 2024 13:53:39 +0000 (21:53 +0800)] 
machinectl: minor modernization, use FOREACH_ARRAY

Prompted by 237bbec1173b41c0e0f2eaf9c30e19ab82073b8d

2 months agonulstr-util: minor cleanup
Mike Yuan [Thu, 21 Mar 2024 11:07:23 +0000 (19:07 +0800)] 
nulstr-util: minor cleanup

2 months agocore: use RET_GATHER more 31890/head
Mike Yuan [Thu, 21 Mar 2024 17:23:07 +0000 (01:23 +0800)] 
core: use RET_GATHER more

2 months agocore: use ASSERT_PTR(CAST(u)) everywhere
Mike Yuan [Thu, 21 Mar 2024 17:22:31 +0000 (01:22 +0800)] 
core: use ASSERT_PTR(CAST(u)) everywhere

2 months agologind: Add fallback for when the PIDFDs= property is not available
Daan De Meyer [Thu, 21 Mar 2024 14:48:54 +0000 (15:48 +0100)] 
logind: Add fallback for when the PIDFDs= property is not available

logind is not zero-downtime restartable yet, specifically it's not yet
restarted in the Fedora spec, so we can end up in situations where we're
running newer logind with older pid1 which doesn't know about the PIDFDs=
property, so let's make sure we have a fallback in place for when that
happens.

2 months agoMerge pull request #31880 from yuwata/network-varlink-trivial-cleanups
Yu Watanabe [Thu, 21 Mar 2024 13:00:52 +0000 (22:00 +0900)] 
Merge pull request #31880 from yuwata/network-varlink-trivial-cleanups

network: trivial varlink cleanups

2 months agobuild(deps): bump pkg/fedora from `2822a03` to `2e32a33`
dependabot[bot] [Thu, 21 Mar 2024 09:39:48 +0000 (09:39 +0000)] 
build(deps): bump pkg/fedora from `2822a03` to `2e32a33`

Bumps pkg/fedora from `2822a03` to `2e32a33`.

---
updated-dependencies:
- dependency-name: pkg/fedora
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months agobuild(deps): bump pkg/debian from `86cd356` to `3b47281`
dependabot[bot] [Thu, 21 Mar 2024 09:39:47 +0000 (09:39 +0000)] 
build(deps): bump pkg/debian from `86cd356` to `3b47281`

Bumps pkg/debian from `86cd356` to `3b47281`.

---
updated-dependencies:
- dependency-name: pkg/debian
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months agotest: run clean-again between tests, not at the end 31868/head
Luca Boccassi [Thu, 21 Mar 2024 11:11:01 +0000 (11:11 +0000)] 
test: run clean-again between tests, not at the end

So that we free up space for the next run, as we are seeing disk space
issues on Ubuntu CI due to the many images built and left around

2 months agotest: delete private images on clean-again
Luca Boccassi [Wed, 20 Mar 2024 12:55:02 +0000 (12:55 +0000)] 
test: delete private images on clean-again

Private images are not reused, they are unique to tests, so delete them
as they take a lot of disk space, and we are starting to run in /var/tmp
space issues on the Ubuntu CI

2 months agovarlink: use varlink_server_description() 31880/head
Yu Watanabe [Thu, 21 Mar 2024 10:54:25 +0000 (19:54 +0900)] 
varlink: use varlink_server_description()

2 months agonetwork: set varlink description
Yu Watanabe [Thu, 21 Mar 2024 10:52:31 +0000 (19:52 +0900)] 
network: set varlink description

2 months agonetworkctl: use varlink_flush_close_unrefp()
Yu Watanabe [Thu, 21 Mar 2024 10:45:03 +0000 (19:45 +0900)] 
networkctl: use varlink_flush_close_unrefp()

2 months agoMerge pull request #31861 from yuwata/journalctl-fix-until
Mike Yuan [Thu, 21 Mar 2024 10:05:36 +0000 (18:05 +0800)] 
Merge pull request #31861 from yuwata/journalctl-fix-until

journalctl: make --until work again with --after-cursor and --lines

2 months agoCI: revert the mmap_rnd_bits kludge
Evgeny Vereshchagin [Thu, 21 Mar 2024 06:56:15 +0000 (06:56 +0000)] 
CI: revert the mmap_rnd_bits kludge

This reverts commit 2e0c2fb8fb15faeedf213930a4c2a3a6d584101f and commit
b7c7498de814b1e9825b43c28e307a7f0af8ffd2 now that
https://github.com/actions/runner-images/issues/9491 is closed.

2 months agoUpdate USB ids of hwdb
Markus Merklinger [Tue, 19 Mar 2024 10:47:04 +0000 (11:47 +0100)] 
Update USB ids of hwdb

2 months agoMerge pull request #31862 from keszybz/add-strdup_to-helper
Yu Watanabe [Thu, 21 Mar 2024 05:47:05 +0000 (14:47 +0900)] 
Merge pull request #31862 from keszybz/add-strdup_to-helper

Add strdup_to() helper

2 months agoMerge pull request #31875 from ml-/docs-fix-socket-section
Yu Watanabe [Thu, 21 Mar 2024 03:32:53 +0000 (12:32 +0900)] 
Merge pull request #31875 from ml-/docs-fix-socket-section

docs: fix keys in wrong section and minor issues in man pages

2 months agoman: fix minor issues 31875/head
Matthias Lisin [Thu, 21 Mar 2024 01:49:38 +0000 (02:49 +0100)] 
man: fix minor issues

2 months agodocs: fix keys in wrong section
Matthias Lisin [Thu, 21 Mar 2024 01:32:26 +0000 (02:32 +0100)] 
docs: fix keys in wrong section

2 months agotest: add test case for issue #31776 31861/head
Yu Watanabe [Tue, 19 Mar 2024 21:22:17 +0000 (06:22 +0900)] 
test: add test case for issue #31776