]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
6 weeks agoman: add machinectl import-raw example for vmspawn
Sam Leonard [Fri, 12 Apr 2024 13:05:43 +0000 (14:05 +0100)] 
man: add machinectl import-raw example for vmspawn

6 weeks agovmspawn: Fix shared memory check
Daan De Meyer [Fri, 19 Apr 2024 11:41:49 +0000 (13:41 +0200)] 
vmspawn: Fix shared memory check

We need the shared memory added if we're doing runtime mounts as well.

6 weeks agoman: document the last remaining bits of the hostnamed D-Bus interface
Lennart Poettering [Fri, 19 Apr 2024 13:25:43 +0000 (15:25 +0200)] 
man: document the last remaining bits of the hostnamed D-Bus interface

6 weeks agomkosi: Build command line into the image 32337/head
Daan De Meyer [Fri, 19 Apr 2024 11:25:31 +0000 (13:25 +0200)] 
mkosi: Build command line into the image

This allows using systemd-vmspawn itself while still getting a decent
experience.

6 weeks agoMerge pull request #32349 from yuwata/sd-event-source-get-inotify-path
Luca Boccassi [Fri, 19 Apr 2024 10:19:06 +0000 (12:19 +0200)] 
Merge pull request #32349 from yuwata/sd-event-source-get-inotify-path

sd-event: introduce sd_event_source_get_inotify_path()

6 weeks agoMerge pull request #32345 from yuwata/sd-radv-send
Luca Boccassi [Fri, 19 Apr 2024 09:59:08 +0000 (11:59 +0200)] 
Merge pull request #32345 from yuwata/sd-radv-send

sd-radv: introduce sd_radv_send(), and reset timer on sending unsplicited RA

6 weeks agoMerge pull request #31978 from nolange/fix_openssl_deprecations
Luca Boccassi [Fri, 19 Apr 2024 09:20:44 +0000 (11:20 +0200)] 
Merge pull request #31978 from nolange/fix_openssl_deprecations

Fix openssl deprecations

6 weeks agosd-event,sd-journal: fix error handling of inotify_add_watch_fd()
Yu Watanabe [Fri, 19 Apr 2024 04:19:00 +0000 (13:19 +0900)] 
sd-event,sd-journal: fix error handling of inotify_add_watch_fd()

Fixes a bug in 97ef5391697c34ee1c763fa9bddcd20a29ff3159 and
858749f7312bd0adb5433075a92e1c35a2fb56ac.

6 weeks agoupdate TODO
Lennart Poettering [Fri, 19 Apr 2024 08:54:07 +0000 (10:54 +0200)] 
update TODO

6 weeks agomkosi: Fix FORTIFY_SOURCE (again)
Daan De Meyer [Fri, 19 Apr 2024 06:30:53 +0000 (08:30 +0200)] 
mkosi: Fix FORTIFY_SOURCE (again)

CentOS/Fedora use annobin which will complain if FORTIFY_SOURCE=0
is used so we disable those checks to avoid the warnings.

We also make sure that when we query the compilation flags so we can
add more, we set _fortify_level=0 and undefine _lto_flags so that we
don't get those flags in the result.

6 weeks agosd-event: introduce sd_event_source_get_inotify_path() 32349/head
Yu Watanabe [Fri, 19 Apr 2024 04:55:35 +0000 (13:55 +0900)] 
sd-event: introduce sd_event_source_get_inotify_path()

This may be useful when there are multiple inotify event sources exist.
Without this, users need to manage the event sources and paths.

6 weeks agoman: drop spurious version info for error code
Yu Watanabe [Fri, 19 Apr 2024 04:44:10 +0000 (13:44 +0900)] 
man: drop spurious version info for error code

Follow-up for 87fe0a69606920dbdb11854be9223ddeef823fa1.

6 weeks agosd-event: rename argument for storing result
Yu Watanabe [Fri, 19 Apr 2024 04:35:04 +0000 (13:35 +0900)] 
sd-event: rename argument for storing result

6 weeks agoMerge pull request #32340 from YHNdnzj/wait-for-unit-cleanup
Yu Watanabe [Fri, 19 Apr 2024 03:36:48 +0000 (12:36 +0900)] 
Merge pull request #32340 from YHNdnzj/wait-for-unit-cleanup

bus-wait-for-units: some cleanup

6 weeks agosd-radv: reset timer on sending unsolicited RA 32345/head
Yu Watanabe [Tue, 16 Apr 2024 10:00:15 +0000 (19:00 +0900)] 
sd-radv: reset timer on sending unsolicited RA

Addresses https://github.com/systemd/systemd/pull/32267#discussion_r1567078807.

6 weeks agosd-radv: expose sd_radv_send()
Yu Watanabe [Mon, 15 Apr 2024 02:53:51 +0000 (11:53 +0900)] 
sd-radv: expose sd_radv_send()

To allow library users manually send RA.
Currently, this is not used, but will be used later.

6 weeks agoMerge pull request #32290 from yuwata/network-conf-parser-cleanups
Yu Watanabe [Fri, 19 Apr 2024 02:53:22 +0000 (11:53 +0900)] 
Merge pull request #32290 from yuwata/network-conf-parser-cleanups

network,nspawn: several cleanups for conf-parsers

6 weeks agobus-wait-for-units: simplify property_map_job_id 32340/head
Mike Yuan [Wed, 17 Apr 2024 19:31:29 +0000 (03:31 +0800)] 
bus-wait-for-units: simplify property_map_job_id

6 weeks agobus-wait-for-units: drop 'current' field
Mike Yuan [Wed, 17 Apr 2024 18:43:39 +0000 (02:43 +0800)] 
bus-wait-for-units: drop 'current' field

This is not used anywhere.

6 weeks agobus-wait-for-units: check for existing unit first, use hashmap_ensure_put
Mike Yuan [Tue, 16 Apr 2024 12:02:33 +0000 (20:02 +0800)] 
bus-wait-for-units: check for existing unit first, use hashmap_ensure_put

6 weeks agobus-wait-for-units: make callback type end with "_t"
Mike Yuan [Tue, 16 Apr 2024 06:43:23 +0000 (14:43 +0800)] 
bus-wait-for-units: make callback type end with "_t"

6 weeks agobus-wait-for-units: drop ready_callback
Mike Yuan [Tue, 16 Apr 2024 06:39:36 +0000 (14:39 +0800)] 
bus-wait-for-units: drop ready_callback

This is never used, and given that bus_wait_for_units_run
returns BusWaitForUnits.state it's not really useful.

6 weeks agosystemctl-start-unit: Subscribe() is unnecessary if we RefUnit explicitly
Mike Yuan [Tue, 16 Apr 2024 17:32:27 +0000 (01:32 +0800)] 
systemctl-start-unit: Subscribe() is unnecessary if we RefUnit explicitly

Subscribe() enables full signal delivery on API bus. But aside from
that, if a unit/job is explicitly Ref()'d, manager also emits the
signal. See bus_foreach_bus() for details.

bus-wait-for-units refs every unit to wait for, so there's no need
to Subscribe() on top of that. In verb_clean_or_freeze() Subscribe()
is not called either.

6 weeks agosystemctl: use FOREACH_ARRAY and FOREACH_ELEMENT more
Mike Yuan [Tue, 16 Apr 2024 07:08:14 +0000 (15:08 +0800)] 
systemctl: use FOREACH_ARRAY and FOREACH_ELEMENT more

6 weeks agocore/dbus: modernize bus_foreach_bus
Mike Yuan [Tue, 16 Apr 2024 06:53:14 +0000 (14:53 +0800)] 
core/dbus: modernize bus_foreach_bus

6 weeks agocore/unit: use UNIT_IS_INACTIVE_OR_FAILED at one more place
Mike Yuan [Fri, 19 Apr 2024 02:07:13 +0000 (10:07 +0800)] 
core/unit: use UNIT_IS_INACTIVE_OR_FAILED at one more place

6 weeks agotest: initialize _cleanup_ variables
Luca Boccassi [Fri, 19 Apr 2024 00:04:35 +0000 (01:04 +0100)] 
test: initialize _cleanup_ variables

Missed one in a previous PR.

Follow-up for e5689f04dd3d57a4e680ab88c643fa971eb0afc2

6 weeks agoconf-parser: move config_parse_timezone() to conf-parser.[ch] 32290/head
Yu Watanabe [Tue, 16 Apr 2024 01:28:06 +0000 (10:28 +0900)] 
conf-parser: move config_parse_timezone() to conf-parser.[ch]

Even though it is currently only used by networkd, the parser itself
is quite generic. Let's move it to the shared library.

6 weeks agonspawn: rename config_parse_timezone() -> config_parse_timezone_mode()
Yu Watanabe [Tue, 16 Apr 2024 02:12:46 +0000 (11:12 +0900)] 
nspawn: rename config_parse_timezone() -> config_parse_timezone_mode()

The parser does not parse timezone, but timezone mode. Let's rename the
parser to more specific name.

6 weeks agonspawn: align tables
Yu Watanabe [Tue, 16 Apr 2024 02:10:04 +0000 (11:10 +0900)] 
nspawn: align tables

6 weeks agonetwork: introduce link_get_use_ntp()
Yu Watanabe [Tue, 16 Apr 2024 01:13:14 +0000 (10:13 +0900)] 
network: introduce link_get_use_ntp()

No functional change, just refactoring.

6 weeks agonetwork: move NTP related conf parsers to networkd-ntp.[ch]
Yu Watanabe [Tue, 16 Apr 2024 00:58:25 +0000 (09:58 +0900)] 
network: move NTP related conf parsers to networkd-ntp.[ch]

No functional change, just refactoring.

6 weeks agonetwork: introduce link_get_use_dns()
Yu Watanabe [Mon, 15 Apr 2024 07:16:13 +0000 (16:16 +0900)] 
network: introduce link_get_use_dns()

No functional change, just refactoring.

6 weeks agonetwork: introduce link_get_use_domains()
Yu Watanabe [Mon, 15 Apr 2024 06:47:12 +0000 (15:47 +0900)] 
network: introduce link_get_use_domains()

No functional change, just refactoring.

6 weeks agonetwork: move DNS related conf parsers to networkd-dns.[ch]
Yu Watanabe [Mon, 15 Apr 2024 06:15:09 +0000 (15:15 +0900)] 
network: move DNS related conf parsers to networkd-dns.[ch]

No functional change, just refactoring.

6 weeks agonetwork: rename DHCPUseDomains -> UseDomains
Yu Watanabe [Mon, 15 Apr 2024 05:47:44 +0000 (14:47 +0900)] 
network: rename DHCPUseDomains -> UseDomains

As it is also used for NDisc.

6 weeks agocopy: ignore -EOPNOTSUPP from copy_file_range()
Nick Rosbrook [Thu, 18 Apr 2024 16:01:42 +0000 (12:01 -0400)] 
copy: ignore -EOPNOTSUPP from copy_file_range()

According to copy_file_range (2), errno will be set to EOPNOTSUPP when
the file system does not support copy_file_range(). Since there is
already fallback logic in place here for other kinds of errors, add
-EOPNOTSUPP to the list of ignored errors.

6 weeks agoMerge pull request #32299 from yuwata/network-radv-ignore-rs-from-the-same-interface
Luca Boccassi [Thu, 18 Apr 2024 21:45:06 +0000 (23:45 +0200)] 
Merge pull request #32299 from yuwata/network-radv-ignore-rs-from-the-same-interface

network/radv: ignore RS message from the same interface

6 weeks agoMerge pull request #32292 from yuwata/sd-radv-send-on-stop
Luca Boccassi [Thu, 18 Apr 2024 21:24:42 +0000 (23:24 +0200)] 
Merge pull request #32292 from yuwata/sd-radv-send-on-stop

sd-radv: set only basic information in RA message on stop

6 weeks agoMerge pull request #31790 from poettering/pcrlock-policy-fix
Lennart Poettering [Thu, 18 Apr 2024 19:11:27 +0000 (21:11 +0200)] 
Merge pull request #31790 from poettering/pcrlock-policy-fix

Replace PolicyAuthValue by PolicySigned as access policy for pcrlock policy nvindex

6 weeks agoMerge pull request #32121 from CodethinkLabs/basic-mkosi-integration-tests
Luca Boccassi [Thu, 18 Apr 2024 19:02:41 +0000 (21:02 +0200)] 
Merge pull request #32121 from CodethinkLabs/basic-mkosi-integration-tests

Basic mkosi integration tests

6 weeks agoMerge pull request #32336 from teknoraver/foreach_element
Mike Yuan [Thu, 18 Apr 2024 17:40:33 +0000 (01:40 +0800)] 
Merge pull request #32336 from teknoraver/foreach_element

Foreach element

6 weeks agoMerge pull request #32144 from bluca/portable_clean
Luca Boccassi [Thu, 18 Apr 2024 16:15:20 +0000 (18:15 +0200)] 
Merge pull request #32144 from bluca/portable_clean

portablectl: add --clean parameter for detaching

6 weeks agoci: update tests to showcase new option a bit 31790/head
Lennart Poettering [Thu, 18 Apr 2024 16:12:12 +0000 (18:12 +0200)] 
ci: update tests to showcase new option a bit

6 weeks agoupdate NEWS
Lennart Poettering [Wed, 17 Apr 2024 08:48:42 +0000 (10:48 +0200)] 
update NEWS

6 weeks agopcrlock: rework --recovery-pin= to take three different arguments
Lennart Poettering [Wed, 17 Apr 2024 17:04:29 +0000 (19:04 +0200)] 
pcrlock: rework --recovery-pin= to take three different arguments

This reworkds --recovery-pin= from a parameter that takes a boolean to
an enum supporting one of "hide", "show", "query".

If "hide" (default behaviour) we'll generate a recovery pin
automatically, but never show it, and thus just seal it and good.

If "show" we'll generate a recovery pin automatically, but display it in
the output, so the user can write it down.

If "query" we'll ask the user for a recovery pin, and not automatically
generate any.

For compatibility the old boolean behaviour is kept.

With this you can now do "systemd-pcrlock make-policy
--recovery-pin=show" to set up the first policy, write down the recovery
PIN. Later, if the PCR prediction didn't work out one day you can then
do "systemd-pcrlock make-policy --recovery-pin=query" and enter the
recovery key and write a new policy.

6 weeks agopcrlock: generate recovery PINs via make_recovery_key()
Lennart Poettering [Wed, 17 Apr 2024 17:02:18 +0000 (19:02 +0200)] 
pcrlock: generate recovery PINs via make_recovery_key()

We already have infrastructure for generating nice recovery keys, for
the usual cryptenroll recovery keys. Let's reuse them here, as they are
nicer to read and type than the base64 encoded randomness we so far
used.

Previously valid recovery keys remain valid, in their original format.
For future enrollments we'll however have nicer, easier recovery keys to
deal with.

6 weeks agotpm2-util: now that we don't use PolicyAuthValue anymore, let's not set an authValue...
Lennart Poettering [Wed, 17 Apr 2024 08:17:20 +0000 (10:17 +0200)] 
tpm2-util: now that we don't use PolicyAuthValue anymore, let's not set an authValue anymore for the policy nvindex

We have now switched from PolicyAuthValue to PolicySigned to control
access to the policy nvindex to. This means there's no point in setting
an authValue on the nvindex anymore, hence drop this.

6 weeks agopcrlock: switch access policy for nvindex to store policy in from PolicyAuthValue...
Lennart Poettering [Tue, 16 Apr 2024 11:46:58 +0000 (13:46 +0200)] 
pcrlock: switch access policy for nvindex to store policy in from PolicyAuthValue to PolicySigned (with an HMAC-SHA256 key)

So far the nvindex to store the pcrlock policy in was protected via a
PolicyAuthValue policy (i.e. with a simple PIN set on the nvindex).
That's a bad idea however, as it means an attacker can simply remove and
re-create the nvindex and the "name" of the nvindex does not change,
thus defeating the logic. (This is because the authValue is *not* part
of the "name" of an nvindex!).

Fix this by switching from PolicyAuthValue to PolicySigned with an
HMAC-SHA256 key. Behaviour is very similar: however, the PIN is now part
of of the access policy hash, which *is* part of the "name" of an
nvindex. Thus, if an attacker removes and recreates the nvindex it has
to provide the same PIN again or the "name" of the nvindex will change.
Mission accomplished.

I'd like to thank Chris Coulson for finding this issue (and helping me
address it). Thank you!

6 weeks agotpm2-util: add comment explaining what tpm2_define_policy_nv_index() actually does
Lennart Poettering [Wed, 17 Apr 2024 08:10:56 +0000 (10:10 +0200)] 
tpm2-util: add comment explaining what tpm2_define_policy_nv_index() actually does

6 weeks agotpm2-util: load external key into NULL hierarchy if private key is provided
Lennart Poettering [Tue, 16 Apr 2024 13:01:41 +0000 (15:01 +0200)] 
tpm2-util: load external key into NULL hierarchy if private key is provided

If we load an external key into the TPM we must do so in the NULL
hierarchy. An external key after all is one that is not wrapped by any
hierarchy's seed.

See TPM2 spec, Part 3, Section 12.3.1

6 weeks agotpm2-util: rename tpm2_get_pin_auth() → tpm2_auth_value_from_pin()
Lennart Poettering [Tue, 16 Apr 2024 11:52:30 +0000 (13:52 +0200)] 
tpm2-util: rename tpm2_get_pin_auth() â†’ tpm2_auth_value_from_pin()

Just some renaming. I found the old name a bit confusing since it sounds
as if this would get the pin from somewhere, but it really doesn't. It
just converts a PIN into an auth_value, and I think saying so explicitly
makes things easier to grok.

6 weeks agotpm2: export tpm2_get_name()
Lennart Poettering [Tue, 16 Apr 2024 11:45:00 +0000 (13:45 +0200)] 
tpm2: export tpm2_get_name()

We later want to use this from pcrlock.c, hence export it.

6 weeks agotpm2-util: import two more symbols from tpm2-tss libraries
Lennart Poettering [Tue, 16 Apr 2024 11:43:07 +0000 (13:43 +0200)] 
tpm2-util: import two more symbols from tpm2-tss libraries

We want to make use of TPM_PolicySigned soon, hence import the necessary
symbols from tpm2-tss.

6 weeks agoman/systemd-stub: fix typo
Antonio Alvarez Feijoo [Thu, 18 Apr 2024 14:43:25 +0000 (16:43 +0200)] 
man/systemd-stub: fix typo

6 weeks agouse FOREACH_ELEMENT 32336/head
Matteo Croce [Thu, 18 Apr 2024 12:31:39 +0000 (14:31 +0200)] 
use FOREACH_ELEMENT

Use FOREACH_ELEMENT where possible. Generated with this command,
and checked manually:

    git grep -l 'FOREACH_ARRAY.*ELEMENTSOF' | \
    xargs sed -ri 's/FOREACH_ARRAY\((.*), (.*), (ELEMENTSOF.*)\)/FOREACH_ELEMENT(\1, \2)/'

6 weeks agointroduce FOREACH_ELEMENT
Matteo Croce [Thu, 18 Apr 2024 12:24:03 +0000 (14:24 +0200)] 
introduce FOREACH_ELEMENT

Add a FOREACH_ELEMENT() macro which just passes ELEMENTSOF(v)
as third argument to FOREACH_ARRAY().

6 weeks agotest: Add mkosi-based integration test runner 32121/head
Richard Maw [Fri, 5 Apr 2024 16:19:59 +0000 (17:19 +0100)] 
test: Add mkosi-based integration test runner

The first two tests are included to ensure parallel test execution is
demonstrable.

6 weeks agomkosi: Extend default device timeout to 20 seconds
Richard Maw [Sat, 3 Feb 2024 14:56:42 +0000 (14:56 +0000)] 
mkosi: Extend default device timeout to 20 seconds

A moderately heavily loaded system booting an image without a rootfs
may timeout before the root device appears.
20 seconds is enough for a VM with 2 CPUs and 2GB RAM.

6 weeks agoMerge pull request #32328 from YHNdnzj/deserialize-objective
Luca Boccassi [Thu, 18 Apr 2024 15:07:32 +0000 (17:07 +0200)] 
Merge pull request #32328 from YHNdnzj/deserialize-objective

core: follow-ups for objective serialization

6 weeks agoMerge pull request #32330 from poettering/status-invocation
Lennart Poettering [Thu, 18 Apr 2024 13:47:20 +0000 (15:47 +0200)] 
Merge pull request #32330 from poettering/status-invocation

systemctl: show invocation ID in unit status output

6 weeks agoMerge pull request #32335 from DaanDeMeyer/fix
Daan De Meyer [Thu, 18 Apr 2024 13:02:51 +0000 (15:02 +0200)] 
Merge pull request #32335 from DaanDeMeyer/fix

mkosi: undefine FORTIFY_SOURCE instead of setting it zero

6 weeks agomkosi: undefine FORTIFY_SOURCE instead of setting it zero 32335/head
Daan De Meyer [Thu, 18 Apr 2024 12:27:38 +0000 (14:27 +0200)] 
mkosi: undefine FORTIFY_SOURCE instead of setting it zero

Newer gcc complains if FORTIFY_SOURCE=0 is set so just undefine it
instead.

6 weeks agocore/manager: log about previous objective 32328/head
Mike Yuan [Thu, 18 Apr 2024 00:59:10 +0000 (08:59 +0800)] 
core/manager: log about previous objective

Addresses https://github.com/systemd/systemd/pull/32320#discussion_r1569192295

6 weeks agocore/manager-serialize: serialize objective string
Mike Yuan [Thu, 18 Apr 2024 00:57:28 +0000 (08:57 +0800)] 
core/manager-serialize: serialize objective string

Follow-up for 8c15bf36e117054cf54b4f0cca59615b7531a545

I just realized that we should not serialize the number
of internal enum, as that's subject to changes and such
changes would be hard to notice. Let's serialize strings
properly instead.

6 weeks agocore/manager: introduce ManagerObjective string table lookup
Mike Yuan [Thu, 18 Apr 2024 00:53:50 +0000 (08:53 +0800)] 
core/manager: introduce ManagerObjective string table lookup

6 weeks agocore/manager: also log soft-reboot count along with timespan
Mike Yuan [Thu, 18 Apr 2024 00:46:20 +0000 (08:46 +0800)] 
core/manager: also log soft-reboot count along with timespan

6 weeks agocore: switch j->unit->manager to j->manager
Mike Yuan [Thu, 18 Apr 2024 00:43:48 +0000 (08:43 +0800)] 
core: switch j->unit->manager to j->manager

6 weeks agomkosi: Disable bash debugging in Arch build script
Daan De Meyer [Thu, 18 Apr 2024 12:21:31 +0000 (14:21 +0200)] 
mkosi: Disable bash debugging in Arch build script

6 weeks agoMerge pull request #32333 from DaanDeMeyer/mkosi
Daan De Meyer [Thu, 18 Apr 2024 12:17:44 +0000 (14:17 +0200)] 
Merge pull request #32333 from DaanDeMeyer/mkosi

mkosi: Various improvements

6 weeks agoboot: fix assignment of ret_* variables in `initrd_prepare()`
Antonio Alvarez Feijoo [Thu, 18 Apr 2024 09:58:07 +0000 (11:58 +0200)] 
boot: fix assignment of ret_* variables in `initrd_prepare()`

6 weeks agoMerge pull request #32326 from jonathan-conder/man_pam_loadkey
Luca Boccassi [Thu, 18 Apr 2024 12:10:40 +0000 (14:10 +0200)] 
Merge pull request #32326 from jonathan-conder/man_pam_loadkey

man: pam_system_loadkey additions and fixes

6 weeks agoudev: permanent symlinks with USB revision for /dev/media*
Max Staudt [Wed, 17 Apr 2024 06:30:44 +0000 (15:30 +0900)] 
udev: permanent symlinks with USB revision for /dev/media*

As a follow-up in the style of:
  873be895ed ("udev: add USB revision in ID_PATH")
this patch adds a second symlink for media controllers, this time
including the USB revision.

This means that in addition to persistent symlinks like:
  pci-0000:04:00.3-usb-0:1:1.0-media-controller -> ../../media0

We now also get:
  pci-0000:04:00.3-usbv2-0:1:1.0-media-controller -> ../../media0

...which helps distinguish media devices plugged into different USB root
hubs provided by the same PCI card, at least as long as they are for
different USB revisions.

Fixes: 04f19d6735 ("udev: Add /dev/media/by-path symlinks for media controllers")
6 weeks agosystemctl: add --clean= values to documentation and shell completion
Luca Boccassi [Mon, 8 Apr 2024 01:20:18 +0000 (02:20 +0100)] 
systemctl: add --clean= values to documentation and shell completion

6 weeks agomkosi: Install debug packages when WITH_DEBUG=1 is enabled 32333/head
Daan De Meyer [Thu, 18 Apr 2024 11:29:12 +0000 (13:29 +0200)] 
mkosi: Install debug packages when WITH_DEBUG=1 is enabled

When we're building debuginfo packages, the original binaries and
libraries are stripped so make sure we install the debuginfo
packages to make sure debugging in the container/VM still works.

6 weeks agomkosi: Setup --ffile-prefix-map= for opensuse as well
Daan De Meyer [Thu, 18 Apr 2024 11:28:17 +0000 (13:28 +0200)] 
mkosi: Setup --ffile-prefix-map= for opensuse as well

This doesn't actually work because the opensuse spec doesn't allow
adding extra build flags, but I'm working on fixing that, so let's
already set things up for later.

6 weeks agomkosi: Undefine FORTIFY_SOURCE before setting it again
Daan De Meyer [Thu, 18 Apr 2024 12:00:30 +0000 (14:00 +0200)] 
mkosi: Undefine FORTIFY_SOURCE before setting it again

Otherwise we get warnings from gcc.

6 weeks agomkosi: Install more packages
Daan De Meyer [Thu, 18 Apr 2024 11:27:43 +0000 (13:27 +0200)] 
mkosi: Install more packages

Let's install everything we can to get more coverage and make sure
all build outputs are available in mkosi containers or VMs.

6 weeks agomkosi: Drop systemd-repart from package lists
Daan De Meyer [Thu, 18 Apr 2024 11:27:05 +0000 (13:27 +0200)] 
mkosi: Drop systemd-repart from package lists

This is just a Provides for systemd-udev.

6 weeks agomkosi: Update to latest
Daan De Meyer [Thu, 18 Apr 2024 11:26:44 +0000 (13:26 +0200)] 
mkosi: Update to latest

6 weeks agobash completion: add missing parameters for portablectl 32144/head
Luca Boccassi [Mon, 8 Apr 2024 00:57:26 +0000 (01:57 +0100)] 
bash completion: add missing parameters for portablectl

6 weeks agoportablectl: add --clean parameter for detaching
Luca Boccassi [Mon, 8 Apr 2024 00:34:12 +0000 (01:34 +0100)] 
portablectl: add --clean parameter for detaching

Calls CleanUnit on each portable service being removed, after it has
stopped

6 weeks agoNEWS: mention GNOME Foundation in contributors list
Luca Boccassi [Thu, 18 Apr 2024 09:46:19 +0000 (10:46 +0100)] 
NEWS: mention GNOME Foundation in contributors list

Sponsored work on homed

6 weeks agosystemctl: show invocation ID in unit status output 32330/head
Lennart Poettering [Thu, 18 Apr 2024 09:18:35 +0000 (11:18 +0200)] 
systemctl: show invocation ID in unit status output

I think we should put more emphasis on the invocation ID as a handle for
a specific runtime cycle of a unit. Let's start with actually showing it
to users.

See: #16035

6 weeks agoman: document other keyname options for pam_systemd_loadkey 32326/head
Jonathan Conder [Wed, 17 Apr 2024 20:01:27 +0000 (08:01 +1200)] 
man: document other keyname options for pam_systemd_loadkey

6 weeks agoMerge pull request #32324 from mrc0mmand/more-website-fixes
Luca Boccassi [Thu, 18 Apr 2024 08:55:01 +0000 (10:55 +0200)] 
Merge pull request #32324 from mrc0mmand/more-website-fixes

docs: use absolute links for our pages

6 weeks agodoc: fix .ssh credential examples
Lennart Poettering [Wed, 17 Apr 2024 19:56:41 +0000 (21:56 +0200)] 
doc: fix .ssh credential examples

Let's create the .ssh dir with the right perms first.

Suggested by @gcb.

Fixes: #28172
6 weeks agodocs: Add note on packages produced by mkosi builds
Daan De Meyer [Wed, 17 Apr 2024 21:38:14 +0000 (23:38 +0200)] 
docs: Add note on packages produced by mkosi builds

6 weeks agoopenssl-util: compatible with restricted openssl3 31978/head
Norbert Lange [Tue, 26 Mar 2024 23:41:41 +0000 (00:41 +0100)] 
openssl-util: compatible with restricted openssl3

openssl can be built without support for engines or with deprecated
definitions disabled.
This also will not pull in most headers automatically,
so add the rsa.h and ec.h header explicitly.

Remove Engine stuff from the header - it is only needed in one
source file.

Make Engine support dependent on the macros.

6 weeks agoresolved-dnstls: remove deprecated openssl functions
Norbert Lange [Tue, 26 Mar 2024 23:29:14 +0000 (00:29 +0100)] 
resolved-dnstls: remove deprecated openssl functions

There are replacements available in OpenSLL 1.1.0,
but those should not be needed. To quote the docs:

> As of version 1.1.0 OpenSSL will automatically allocate all resources
> that it needs so no explicit initialisation is required.
> Similarly it will also automatically deinitialise as required.

6 weeks agoudev: fix assignment of ret_truncated
Yu Watanabe [Thu, 18 Apr 2024 05:25:52 +0000 (14:25 +0900)] 
udev: fix assignment of ret_truncated

Follow-ups for 089bef66316e5bdc91b9984148e5a6455449c1da.

6 weeks agoblockdev-util: fix typo
Yu Watanabe [Thu, 18 Apr 2024 04:08:09 +0000 (13:08 +0900)] 
blockdev-util: fix typo

Follow-up for 33ff155957327f51dde740a7a75f19122bff1ebc.

6 weeks agoMerge pull request #32192 from yuwata/part-scan
Yu Watanabe [Thu, 18 Apr 2024 02:38:48 +0000 (11:38 +0900)] 
Merge pull request #32192 from yuwata/part-scan

blockdev-util: fix detection of partscan

6 weeks agoMerge pull request #32249 from CodethinkLabs/vmspawn/predicatable_tap_names
Yu Watanabe [Thu, 18 Apr 2024 01:26:07 +0000 (10:26 +0900)] 
Merge pull request #32249 from CodethinkLabs/vmspawn/predicatable_tap_names

vmspawn: generate predicatable TAP device names and MAC addresses

6 weeks agoblockdev-util: also read 'ext_range' sysattr to check if the partscan is enabled 32192/head
Yu Watanabe [Mon, 8 Apr 2024 02:57:42 +0000 (11:57 +0900)] 
blockdev-util: also read 'ext_range' sysattr to check if the partscan is enabled

The 'capability' sysattr was deprecated by
https://github.com/torvalds/linux/commit/e81cd5a983bb35dabd38ee472cf3fea1c63e0f23 (v6.3).

6 weeks agosd-device: introduce device_get_sysattr_unsigned_full()
Yu Watanabe [Mon, 8 Apr 2024 02:56:58 +0000 (11:56 +0900)] 
sd-device: introduce device_get_sysattr_unsigned_full()

6 weeks agoman: fix wrong version info (#31949)
Yu Watanabe [Thu, 18 Apr 2024 00:45:51 +0000 (09:45 +0900)] 
man: fix wrong version info (#31949)

Fixes #31920.

6 weeks agosystemctl: allow user to suppress output when no action scheduled (#32278)
MaxHearnden [Thu, 18 Apr 2024 00:44:22 +0000 (01:44 +0100)] 
systemctl: allow user to suppress output when no action scheduled (#32278)

6 weeks agojournalctl: update help to say "priority range" (#32323)
Winterhuman [Thu, 18 Apr 2024 00:43:28 +0000 (00:43 +0000)] 
journalctl: update help to say "priority range" (#32323)

Clarify that `-p, --priority=` always treats its option as a priority range, even when given
a single log level per the full man page description.

Co-authored-by: Mike Yuan <me@yhndnzj.com>
6 weeks agotest-network: add test case of RS sent by the same interface 32299/head
Yu Watanabe [Tue, 16 Apr 2024 08:47:18 +0000 (17:47 +0900)] 
test-network: add test case of RS sent by the same interface