]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
6 months agoman/systemd.exec: reword description of RestrictAddressFamilies= 37367/head
Zbigniew Jędrzejewski-Szmek [Tue, 6 May 2025 18:59:59 +0000 (20:59 +0200)] 
man/systemd.exec: reword description of RestrictAddressFamilies=

The text is reordered and broken into more paragraphs.
A recommendation to combine RestrictAddressFamilies= with
SystemCallFilter=@service is added.

6 months agoman/systemd.exec: reword description of SystemCallFilter=
Zbigniew Jędrzejewski-Szmek [Tue, 6 May 2025 19:04:00 +0000 (21:04 +0200)] 
man/systemd.exec: reword description of SystemCallFilter=

The existing text grew organically as features were added and was
not very organized. Reorder it and break into paragraphs grouped
by topic. The description of the :errno syntax is replaced by a short
reference to the SystemCallErrorNumber= setting. This makes the
text shorter and makes it easier to explain how the two settings combine.

6 months agostring-util: Remove utf8.h and alloc-util.h includes
Daan De Meyer [Sun, 4 May 2025 15:43:09 +0000 (17:43 +0200)] 
string-util: Remove utf8.h and alloc-util.h includes

6 months agocleanup: bugprone argument issues (#37346)
Yu Watanabe [Tue, 6 May 2025 09:56:07 +0000 (18:56 +0900)] 
cleanup: bugprone argument issues (#37346)

Follow up from https://github.com/systemd/systemd/pull/37281

6 months agoVarious preparatory changes from #37344 (#37348)
Daan De Meyer [Tue, 6 May 2025 09:23:15 +0000 (11:23 +0200)] 
Various preparatory changes from #37344 (#37348)

6 months agohashmap: Drop debug params 37348/head
Daan De Meyer [Sun, 4 May 2025 11:31:07 +0000 (13:31 +0200)] 
hashmap: Drop debug params

Passing in the func, file and line information complicates the
interface. On top of that, it prevents forward declaring Hashmap in
strv.h, as we need to pass the macros everywhere that we allocate a
hashmap, which means we have to include the hashmap header everywhere
we have a function that allocates a hashmap instead of just having to
forward declare Hashmap.

Let's drop the file, func and line information from the debug information.
Instead, in the future we can add a description field to hashmaps like we
already have in various other structs to describe the purpose of the hashmap
which should be much more useful than having the file, line and function where
the hashmap was allocated.

6 months agomacro: Introduce ABS() macro and use it in header files
Daan De Meyer [Tue, 6 May 2025 07:53:56 +0000 (09:53 +0200)] 
macro: Introduce ABS() macro and use it in header files

abs() requires including the entirety of stdlib.h just for a single
trivial function. Let's introduce the ABS() macro and use it in header
files instead so we can get rid of stdlib.h transitive includes in header
files in a later commit.

6 months agostring-table: Move more implementation logic into functions
Daan De Meyer [Sat, 3 May 2025 15:59:19 +0000 (17:59 +0200)] 
string-table: Move more implementation logic into functions

Let's move some more implementation logic into functions. We keep
the logic that requires the macro in the macro and move the rest into
functions.

While we're at it, let's also make the parameter declarations of
all the string table macros less clausthrophobic.

6 months agomain-func: Reduce transitive includes
Daan De Meyer [Mon, 5 May 2025 20:06:17 +0000 (22:06 +0200)] 
main-func: Reduce transitive includes

Let's move some logic from _DEFINE_MAIN_FUNCTION() and other places
in main-func.h into functions that we implement in main-func.c to
allow moving some included headers from the header to the .c file.

6 months agoshared: fix leftover bool value from flags conversion 37346/head
Jelle van der Waa [Tue, 6 May 2025 07:31:50 +0000 (09:31 +0200)] 
shared: fix leftover bool value from flags conversion

Follow-up for 5c48335ef4cc1c930c86c6e893f3ab3e5472f7f6

6 months agohibernate-resume: automatically decrypt dissected swap (#37335)
Yu Watanabe [Tue, 6 May 2025 04:00:24 +0000 (13:00 +0900)] 
hibernate-resume: automatically decrypt dissected swap (#37335)

Closes https://github.com/systemd/systemd/issues/27247
(https://github.com/systemd/systemd/pull/35328,
https://github.com/systemd/systemd/issues/37330)

6 months agonetwork,udev: several improvements for logging (#37337)
Yu Watanabe [Tue, 6 May 2025 03:43:15 +0000 (12:43 +0900)] 
network,udev: several improvements for logging (#37337)

No functional changes. Continuation of #37269.

6 months agoprioq: coding style fixes
Yu Watanabe [Mon, 5 May 2025 13:28:16 +0000 (22:28 +0900)] 
prioq: coding style fixes

6 months agoshared: rename type to fstype
Jelle van der Waa [Mon, 5 May 2025 19:34:31 +0000 (21:34 +0200)] 
shared: rename type to fstype

Follow the argument comment naming already used.

6 months agonetwork: correct argument comments
Jelle van der Waa [Mon, 5 May 2025 17:47:49 +0000 (19:47 +0200)] 
network: correct argument comments

6 months agolibsystemd-network: fix typo in argument comment
Jelle van der Waa [Mon, 5 May 2025 17:38:18 +0000 (19:38 +0200)] 
libsystemd-network: fix typo in argument comment

6 months agohibernate-resume: automatically decrypt dissected swap if told so via autoSwap 37335/head
Mike Yuan [Sat, 3 May 2025 16:41:00 +0000 (18:41 +0200)] 
hibernate-resume: automatically decrypt dissected swap if told so via autoSwap

With the addition of /dev/disk/by-designator/ along with
ID_DISSECT_PART_DESIGNATOR attr, it is now trivial to tell
whether the swap device we hibernated into is the "auto" one.
Hence use that bit of info and generate cryptsetup unit
in hibernate-resume-generator if that's the case.

Ideally, gpt-auto should really just handle swap already
in initrd, which would save us a myriad of trouble and
the system behaves more consistently. But I don't see that
happening anytime soon. This is the second best option
we have I reckon.

Closes #27247 (#35328, #37330)

6 months agosleep: record whether the hibernation device is auto swap (with "swap" designator)
Mike Yuan [Sat, 3 May 2025 16:02:54 +0000 (18:02 +0200)] 
sleep: record whether the hibernation device is auto swap (with "swap" designator)

6 months agotreewide: correct argument comments for sd_notifyf
Jelle van der Waa [Mon, 5 May 2025 17:34:07 +0000 (19:34 +0200)] 
treewide: correct argument comments for sd_notifyf

6 months agoshared: fix typo in read_etc_hostname definition
Jelle van der Waa [Mon, 5 May 2025 17:32:52 +0000 (19:32 +0200)] 
shared: fix typo in read_etc_hostname definition

6 months agoresolve: update argument comments
Jelle van der Waa [Mon, 5 May 2025 17:31:13 +0000 (19:31 +0200)] 
resolve: update argument comments

6 months agoblockdev-util: don't use mixed style of retval in block_device_get_originating
Mike Yuan [Sat, 3 May 2025 19:01:54 +0000 (21:01 +0200)] 
blockdev-util: don't use mixed style of retval in block_device_get_originating

We have two typical styles of 'ret' param assignment + retval:

1) < 0 on actual error, 0 on nothing (ret == NULL), > 0 on something
2) recognizable errno on nothing, < 0 on other errors, >= 0 on something

but never use both at the same time.

6 months agocore/cgroup: block_get_originating() doesn't return > 0
Mike Yuan [Sat, 3 May 2025 19:00:15 +0000 (21:00 +0200)] 
core/cgroup: block_get_originating() doesn't return > 0

Follow-up for 612fc70fc0f5445817f3f5c033dd3d5b5fd058ea

6 months agomeson: Ensure that distribution packages own systemenvgeneratordir
Debarshi Ray [Fri, 2 May 2025 19:08:55 +0000 (21:08 +0200)] 
meson: Ensure that distribution packages own systemenvgeneratordir

Currently, Fedora's systemd RPM doesn't own systemenvgeneratordir
(ie., /usr/lib/systemd/system-environment-generators) [1] because it's
not created when systemd is installed.  In contrast, userenvgeneratordir
(ie., /usr/lib/systemd/user-environment-generators) is created, unless
the environment-d Meson option is explicitly disabled.

While this can be worked around elsewhere, it's better if the upstream
build system created the directories consistently.  It will avoid
repetition, and prevent silly bugs or deviations from creeping in.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=2284085

6 months agomeson: Make sure check-filesystems.sh runs from the build directory
Daan De Meyer [Mon, 5 May 2025 15:00:24 +0000 (17:00 +0200)] 
meson: Make sure check-filesystems.sh runs from the build directory

run_command()'s working directory is documented as undefined but it
seems to be the current source directory as when the -ftime-trace
clang option is enabled, -.json is written to src/basic/meson.build
every time meson is run.

Let's make sure the command is executed in the build directory so that
any auxiliary files are written there as well.

6 months agounits: two tweaks for socket units (#37309)
Mike Yuan [Mon, 5 May 2025 13:13:00 +0000 (15:13 +0200)] 
units: two tweaks for socket units (#37309)

6 months agoudev/net: update log message 37337/head
Yu Watanabe [Sun, 4 May 2025 16:46:37 +0000 (01:46 +0900)] 
udev/net: update log message

6 months agoudev/net: mention which SR-IOV setting could not be applied in log message
Yu Watanabe [Sun, 4 May 2025 16:44:51 +0000 (01:44 +0900)] 
udev/net: mention which SR-IOV setting could not be applied in log message

6 months agonetwork/sriov: mention which setting could not be applied in log message
Yu Watanabe [Sun, 4 May 2025 16:36:40 +0000 (01:36 +0900)] 
network/sriov: mention which setting could not be applied in log message

6 months agonetwork: make log_link_message_full_errno() take format string
Yu Watanabe [Sun, 4 May 2025 16:33:05 +0000 (01:33 +0900)] 
network: make log_link_message_full_errno() take format string

6 months agonetwork/nexthop: split out nexthop_to_string()
Yu Watanabe [Sun, 4 May 2025 16:30:55 +0000 (01:30 +0900)] 
network/nexthop: split out nexthop_to_string()

6 months agonetwork/route: split out route_to_string() from log_route_debug()
Yu Watanabe [Sun, 4 May 2025 16:30:01 +0000 (01:30 +0900)] 
network/route: split out route_to_string() from log_route_debug()

6 months agohwdb: add HP 150 Wired Mouse (#37341)
madroach [Mon, 5 May 2025 12:34:33 +0000 (14:34 +0200)] 
hwdb: add HP 150 Wired Mouse (#37341)

6 months agoman/systemctl: add preposition for clarity
Alexander Stepchenko [Mon, 5 May 2025 10:48:30 +0000 (13:48 +0300)] 
man/systemctl: add preposition for clarity

6 months agoman/network: Note .link early boot caveat, and .network .netdev usage.
Tim Small [Fri, 2 May 2025 12:40:00 +0000 (13:40 +0100)] 
man/network: Note .link early boot caveat, and .network .netdev usage.

Document .link .network and .netdev file type distinctions in early
introductory text, and document distro-specific need to sync link files
with early-boot copies, see Debian bug 1005282:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1005282 for an
example.

6 months agoVmspawn fixes (#37320)
Yu Watanabe [Sun, 4 May 2025 03:24:04 +0000 (12:24 +0900)] 
Vmspawn fixes (#37320)

Fixes
https://github.com/systemd/systemd/pull/36618#issuecomment-2844694845

and

```
qemu-kvm: -device vmgenid,guid=5f303a47-6fae-4dd7-969c-6c1ea61e816e: 'vmgenid' is not a valid device model name
```

6 months agocore: rename core-varlink -> varlink
Mike Yuan [Thu, 1 May 2025 20:48:01 +0000 (22:48 +0200)] 
core: rename core-varlink -> varlink

To make things consistent with dbus.[ch]

6 months agoVarious changes to prepare for running IWYU on the repository (#37319)
Daan De Meyer [Fri, 2 May 2025 11:41:31 +0000 (13:41 +0200)] 
Various changes to prepare for running IWYU on the repository (#37319)

These are various commits that were required to get things compiling
after running IWYU. I think all of them make sense on their own, hence
this split PR to merge them ahead of time.

6 months agovmspawn: fix grow_image: Assertion `path' failed. 37320/head
Arian van Putten [Thu, 1 May 2025 11:58:21 +0000 (11:58 +0000)] 
vmspawn: fix grow_image: Assertion `path' failed.

arg_image might be NULL (e.g. when booting a USI, or when passing -D)

6 months agovmspawn: don't use vmgenid on aarch64 as it's not supported
Arian van Putten [Thu, 1 May 2025 11:19:24 +0000 (13:19 +0200)] 
vmspawn: don't use vmgenid on aarch64 as it's not supported

fixes:

```
qemu-kvm: -device vmgenid,guid=5f303a47-6fae-4dd7-969c-6c1ea61e816e: 'vmgenid' is not a valid device model name
```

6 months agotest: Remove unused sources from tests 37319/head
Daan De Meyer [Thu, 1 May 2025 12:39:58 +0000 (14:39 +0200)] 
test: Remove unused sources from tests

6 months agosocket-util: Replace sockaddr length macros with functions
Daan De Meyer [Wed, 30 Apr 2025 20:09:37 +0000 (22:09 +0200)] 
socket-util: Replace sockaddr length macros with functions

There's no need for these to be macros, let's just make them regular
functions instead.

6 months agonetworkd-network-gperf.gperf: Add various missing includes
Daan De Meyer [Wed, 30 Apr 2025 20:39:07 +0000 (22:39 +0200)] 
networkd-network-gperf.gperf: Add various missing includes

We currently include these transitively but to allow using IWYU to
remove headers later, let's add these as direct includes so the IWYU
changes don't break compilation.

6 months agoshared: Make sure ip-protocol-xxx.h headers include <netinet/in.h>
Daan De Meyer [Wed, 30 Apr 2025 19:48:39 +0000 (21:48 +0200)] 
shared: Make sure ip-protocol-xxx.h headers include <netinet/in.h>

These headers use macros from <netinet/in.h> so let's make sure they
include the header.

6 months agoshared: Add blkid-util.c
Daan De Meyer [Wed, 30 Apr 2025 19:35:43 +0000 (21:35 +0200)] 
shared: Add blkid-util.c

IWYU analyzes source files and their corresponding header file so
let's add a source file blkid-util.c so blkid-util.h is analyzed as
well.

6 months agobasic: Add our own net/if_arp.h header
Daan De Meyer [Wed, 30 Apr 2025 19:11:07 +0000 (21:11 +0200)] 
basic: Add our own net/if_arp.h header

To avoid conflicts with <linux/if_arp.h>.

6 months agodaemon-util: Rename starting/stopping message constants
Daan De Meyer [Wed, 30 Apr 2025 10:20:40 +0000 (12:20 +0200)] 
daemon-util: Rename starting/stopping message constants

Currently, NOTIFY_READY from daemon-util.h conflicts with NOTIFY_READY
from NotifyState from service.h so let's rename the constants to avoid
the conflict.

6 months agosd-id128: Use static instead of _SD_ARRAY_STATIC in source files
Daan De Meyer [Wed, 30 Apr 2025 08:09:00 +0000 (10:09 +0200)] 
sd-id128: Use static instead of _SD_ARRAY_STATIC in source files

When compiling the source files, we know static is going to be available
so there's no need to use the macro from _sd-common.h and we can just use
static instead.

6 months agofundamental: Insert some missing conditional includes
Daan De Meyer [Fri, 25 Apr 2025 13:50:50 +0000 (15:50 +0200)] 
fundamental: Insert some missing conditional includes

IWYU can't insert these inside the correct condition itself so we
add these manually in a separate commit.

6 months agobuild(deps): bump softprops/action-gh-release from 2.2.1 to 2.2.2
dependabot[bot] [Thu, 1 May 2025 09:09:47 +0000 (09:09 +0000)] 
build(deps): bump softprops/action-gh-release from 2.2.1 to 2.2.2

Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.2.1 to 2.2.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda...da05d552573ad5aba039eaac05058a918a7bf631)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
6 months agobuild(deps): bump redhat-plumbers-in-action/gather-pull-request-metadata
dependabot[bot] [Thu, 1 May 2025 09:09:45 +0000 (09:09 +0000)] 
build(deps): bump redhat-plumbers-in-action/gather-pull-request-metadata

Bumps [redhat-plumbers-in-action/gather-pull-request-metadata](https://github.com/redhat-plumbers-in-action/gather-pull-request-metadata) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/redhat-plumbers-in-action/gather-pull-request-metadata/releases)
- [Commits](https://github.com/redhat-plumbers-in-action/gather-pull-request-metadata/compare/17821d3bc27c1efed339595898c2e622accc5a1b...5da2967931dd7c4b9ccd22f49b045e2c1f05165b)

---
updated-dependencies:
- dependency-name: redhat-plumbers-in-action/gather-pull-request-metadata
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
6 months agovarious: convert more readers of /proc/ to plain read_full_file() (#37299)
Yu Watanabe [Thu, 1 May 2025 06:28:34 +0000 (15:28 +0900)] 
various: convert more readers of /proc/ to plain read_full_file() (#37299)

Continuation of #36734

Apparently I was wrong about everything under `/proc/` being seq_file,
but at least there're some more to convert and we can leverage our
helper func while doing so.

6 months agoaudit-util: use read_full_virtual_file() 37299/head
Mike Yuan [Thu, 13 Mar 2025 15:03:42 +0000 (16:03 +0100)] 
audit-util: use read_full_virtual_file()

Conversely this one is "raw" file, but let's switch to
static inline helper for it.

6 months agorlimit-util: use read_full_file() for /proc/PID/limits
Mike Yuan [Thu, 13 Mar 2025 17:04:52 +0000 (18:04 +0100)] 
rlimit-util: use read_full_file() for /proc/PID/limits

This one uses "seq_file", i.e. normal FILE stream just works.

6 months agosd-bus/bus-creds: use plain read_full_file() for process cmdline
Mike Yuan [Thu, 13 Mar 2025 15:04:33 +0000 (16:04 +0100)] 
sd-bus/bus-creds: use plain read_full_file() for process cmdline

This one uses "seq_file", i.e. normal FILE stream just works.

6 months agoprocess-util: use procfs_file_get_field() where appropriate
Mike Yuan [Thu, 13 Mar 2025 14:46:03 +0000 (15:46 +0100)] 
process-util: use procfs_file_get_field() where appropriate

6 months agoprocess-util: introduce procfs_file_get_field() wrapper
Mike Yuan [Wed, 30 Apr 2025 17:34:23 +0000 (19:34 +0200)] 
process-util: introduce procfs_file_get_field() wrapper

which combines procfs_file_alloca() and get_proc_field()

6 months agoprocess-util: assert on pid in procfs_file_alloca(), use strjoina()
Mike Yuan [Wed, 30 Apr 2025 17:43:20 +0000 (19:43 +0200)] 
process-util: assert on pid in procfs_file_alloca(), use strjoina()

6 months agomountpoint-util: use get_proc_field()
Mike Yuan [Thu, 13 Mar 2025 15:09:55 +0000 (16:09 +0100)] 
mountpoint-util: use get_proc_field()

6 months agopidfd-util: use get_proc_field() for pidfd_get_pid_fdinfo()
Mike Yuan [Thu, 13 Mar 2025 13:54:04 +0000 (14:54 +0100)] 
pidfd-util: use get_proc_field() for pidfd_get_pid_fdinfo()

6 months agofileio: modernize get_proc_field()
Mike Yuan [Thu, 13 Mar 2025 13:49:13 +0000 (14:49 +0100)] 
fileio: modernize get_proc_field()

- Drop effectively unused "terminator" param, imply whitespace
- Make ret param optional
- Return ENODATA if the requested key is not found, rather than
  ENOENT
- Turn ENOENT -> ENOSYS if /proc/ is not mounted
- Don't skip whitespaces before ':', nothing needs this handling
  anyways
- Remove the special treatment for all "0"s. We don't actually
  use this for capabilities given pidref_get_capability() exists
- Switch away from read_full_virtual_file() - files using "field"
  scheme under /proc/ seem all to be "seq_file"s (refer to
  da65941c3ee03495541c3bffbccc9012c8d9a5f8 for details on file types)

6 months agosocket-activate: drop unused accept param for open_sockets()
Mike Yuan [Tue, 29 Apr 2025 15:35:10 +0000 (17:35 +0200)] 
socket-activate: drop unused accept param for open_sockets()

6 months agosd-stub: fix assertion failure when cleaning up initrd pages
Luca Boccassi [Wed, 30 Apr 2025 22:21:46 +0000 (23:21 +0100)] 
sd-stub: fix assertion failure when cleaning up initrd pages

When linux_exec() fails, the initrd pages cleanup attempts to run,
and an assertion is triggered:

../src/boot/linux.c:125@linux_exec: Error loading kernel image: Security violation
../src/boot/util.h:81@cleanup_pages: Error freeing pages: Not found
../src/boot/log.c:30@efi_assert: systemd-boot: Assertion 'r == EFI_SUCCESS' failed at ../src/boot/util.h:82@cleanup_pages, halting.

(log message is new)

This was introduced by https://github.com/systemd/systemd/pull/36715

Before that change, given the argument to xmalloc_pages() was passed as EFI_SIZE_TO_PAGES(n_pages), that's
what ended up in Pages.n_pages. After this change, n_pages gets assigned without being transformed by
EFI_SIZE_TO_PAGES, so the cleanup can find them again. That change causes the assertion failure to trigger.
Changing this to .n_pages = EFI_SIZE_TO_PAGES(n_pages) fixes the assertion.

Follow-up for c5a50467921f615846b3bbe3c3ff592953a6163a

6 months agoresolve: Simplify and optimize meson file
Daan De Meyer [Wed, 30 Apr 2025 14:20:15 +0000 (16:20 +0200)] 
resolve: Simplify and optimize meson file

We were compiling the same resolved sources over and over again (up to
10 times) which had a substantial effect on build times. Let's make sure
we only compile the resolved sources once by having one static library
containing the objects for all the resolved sources.

While we're at it, get rid of unnecessary variables and includes in the
resolve meson file and generally clean things up a bit.

Before (recorded with ClangBuildAnalyzer):

**** Time summary:
Compilation (1823 times):
  Parsing (frontend):          675.5 s
  Codegen & opts (backend):     81.6 s

After:

**** Time summary:
Compilation (1585 times):
  Parsing (frontend):          553.6 s
  Codegen & opts (backend):     70.7 s

6 months agomkosi: update debian commit reference to 9c54c974f07038bf6737fa02d78f20d340107f5c
Luca Boccassi [Thu, 1 May 2025 00:53:02 +0000 (01:53 +0100)] 
mkosi: update debian commit reference to 9c54c974f07038bf6737fa02d78f20d340107f5c

9c54c974f0 d/systemd-resolved.install: install new socket units for upstream profile

6 months agonetworkd-test: stop resolved socket units in setUpModule()
Nick Rosbrook [Wed, 30 Apr 2025 23:47:42 +0000 (19:47 -0400)] 
networkd-test: stop resolved socket units in setUpModule()

Avoid warnings about the socket units when stopping systemd-resolved.

6 months agounits: enable RemoveOnStop= for oomd and userdbd sockets 37309/head
Mike Yuan [Wed, 30 Apr 2025 19:23:19 +0000 (21:23 +0200)] 
units: enable RemoveOnStop= for oomd and userdbd sockets

We usually don't care, but here the existence of socket
is public API to a certain degree and signals availability
of the service (userdbd in particular, oomd is checked in
core-varlink.c). Hence let's be more careful and remove them
if stopped.

6 months agounits: unify deps between service and socket units
Mike Yuan [Wed, 30 Apr 2025 19:05:02 +0000 (21:05 +0200)] 
units: unify deps between service and socket units

The current arrangement of service and socket units is
sort of all over the place. Let's clean it up a little,
roughly following the principles below:

- socket units have implicit ordering deps (not to be confused
  with default ones which are subject to DefaultDependencies=)
  before associated service, so drop any explicit After=

- If socket can be enabled, remember to link to it in service
  via Also= and Sockets= (the latter replaces Wants=).
  If the service Requires= socket however, Sockets= is omitted.

- If socket is statically enabled, no need for service
  to pull it in - machined

6 months agowait-online: handle varlink connection errors while waiting for DNS (#37283)
Yu Watanabe [Wed, 30 Apr 2025 16:55:04 +0000 (01:55 +0900)] 
wait-online: handle varlink connection errors while waiting for DNS (#37283)

Currently, if systemd-networkd-wait-online is started with --dns, and
systemd-resolved is not running, it will exit with an error right away.
Similarly, if systemd-resolved is restarted while waiting for DNS
configuration, systemd-networkd-wait-online will not attempt to
re-connect, and will potentially never see subsequent DNS
configurations.

Improve this by adding socket units for the systemd-resolved varlink
servers, and re-establish the connection in systemd-networkd-wait-online
when we receive `SD_VARLINK_ERROR_DISCONNECTED`.

6 months agobusctl: validate argvs on get-property/set-property too
Luca Boccassi [Wed, 30 Apr 2025 14:24:20 +0000 (15:24 +0100)] 
busctl: validate argvs on get-property/set-property too

Otherwise passing invalid data means asserts get hit instead of
handling it gracefully. Other verbs already do the same checks.

busctl get-property org.freedesktop.systemd1 '*' org.freedesktop.systemd1.Manager Version
Assertion 'object_path_is_valid(path)' failed at src/libsystemd/sd-bus/bus-message.c:562, function sd_bus_message_new_method_call(). Aborting.
Aborted (core dumped)

6 months agoTEST-17: drop unnecessary $PATH setting
Yu Watanabe [Wed, 30 Apr 2025 12:07:48 +0000 (21:07 +0900)] 
TEST-17: drop unnecessary $PATH setting

My local setting was unintentionally inserted by the commit
7cb4508c5af465ab1be1b103e6c2b613eb58e63c.

6 months agotest: add a test for resolved and wait-online interactions 37283/head
Nick Rosbrook [Mon, 28 Apr 2025 16:44:20 +0000 (12:44 -0400)] 
test: add a test for resolved and wait-online interactions

Specifically, add a test case that ensures systemd-networkd-wait-online --dns
is robust against (a) systemd-resolved absence, and (b) systemd-resolved
restarts.

6 months agowait-online: attempt to re-connect after varlink disconnects
Nick Rosbrook [Tue, 29 Apr 2025 19:16:45 +0000 (15:16 -0400)] 
wait-online: attempt to re-connect after varlink disconnects

Now that systemd-resolved has socket activation for it's varlink
sockets, this should should be enough to make the DNS configuration
logic robust against systemd-resolved stops and restarts.

6 months agoresolved: support socket activation via varlink sockets
Nick Rosbrook [Tue, 29 Apr 2025 19:14:32 +0000 (15:14 -0400)] 
resolved: support socket activation via varlink sockets

Add two new socket units, one for each of systemd-resolved's varlink
servers:

 systemd-resolved-varlink.socket
 systemd-resolved-monitor.socket

Add logic to grab socket fds via sd_varlink_server_listen_name(), but
fallback to the existing sd_varlink_server_listen_address() calls if no
fds were given.

This will be used to make systemd-networkd-wait-online --dns more robust
against systemd-resolved restarts etc.

6 months agonetwork/ndisc: drop only default gateway via the host when a neighbor announcement...
Yu Watanabe [Sat, 26 Apr 2025 01:50:26 +0000 (10:50 +0900)] 
network/ndisc: drop only default gateway via the host when a neighbor announcement without router flag is received

A host can send Router Advertisements (RAs) without acting as a router.
In such cases, the lifetime of the RA header should be zero, but may
contain several options, and clients can configure addresses, routes,
and so on with the message. The host may (should?) send Neighbor
Announcements (NAs) without the router flag in that case.

So, when a NA without the router flag is received, let's not drop
configurations based on the previous RA options, but only drop the
default gateway configured based on the RA header.

See RFC 4861 Neighbor Discovery in IPv6, section 6.3.4:
https://www.rfc-editor.org/rfc/rfc4861#section-6.3.4:~:text=%2D%20The%20IsRouter%20flag,as%20a%20host.
> - The IsRouter flag in the cache entry MUST be set based on the Router
>   flag in the received advertisement. In those cases where the IsRouter
>   flag changes from TRUE to FALSE as a result of this update, the node
>   MUST remove that router from the Default Router List and update the
>   Destination Cache entries for all destinations using that neighbor as
>   a router as specified in Section 7.3.3. This is needed to detect when
>   a node that is used as a router stops forwarding packets due to being
>   configured as a host.

Fixes a regression caused by 87a33c0740524e894a170f75638012c2c5f90f24 (v256).
Fixes #37198.

6 months agosd-bus,busctl: introduce sd_bus_message_dump_json() and use it (#37266)
Yu Watanabe [Wed, 30 Apr 2025 13:16:14 +0000 (22:16 +0900)] 
sd-bus,busctl: introduce sd_bus_message_dump_json() and use it (#37266)

6 months agonetwork,udev: several fixlets for setting up SR-IOV VFs (#37269)
Yu Watanabe [Wed, 30 Apr 2025 13:14:41 +0000 (22:14 +0900)] 
network,udev: several fixlets for setting up SR-IOV VFs (#37269)

Closes #37257 and #37275.

6 months agonetwork/tuntap: verify User=/Group= earlier and refuse non-system users/groups (...
Yu Watanabe [Wed, 30 Apr 2025 13:12:56 +0000 (22:12 +0900)] 
network/tuntap: verify User=/Group= earlier and refuse non-system users/groups (#37294)

Similar to #36123.
Closes #37279.

6 months agonetwork/tuntap: deny non-system users/groups from owning Tun/Tap interfaces 37294/head
Yu Watanabe [Tue, 29 Apr 2025 14:16:02 +0000 (23:16 +0900)] 
network/tuntap: deny non-system users/groups from owning Tun/Tap interfaces

This is analogous to #36123, but for Tun/Tap interfaces created by
systemd-networkd.

If a regular user account want to control a Tun/Tap interface, then
assign the interface to a system group, e.g., vpn, and add the user
to the group.

Closes #37279.

6 months agonetwork/tuntap: verify User=/Group= settings earlier
Yu Watanabe [Tue, 29 Apr 2025 13:51:50 +0000 (22:51 +0900)] 
network/tuntap: verify User=/Group= settings earlier

and ignore the settings if we cannot find the specified user/group.

This also replaces get_user_creds()/get_group_creds() with
userdb_by_name()/groupdb_by_name().

6 months agosysext: Include index=off in overlay mount options
Nick Labich [Fri, 25 Apr 2025 05:38:04 +0000 (01:38 -0400)] 
sysext: Include index=off in overlay mount options

Enable reuse of upper/work dirs with different lower layer paths.

Fixes https://github.com/systemd/systemd/issues/37245

6 months agosd-bus/bus-dump,busctl: downgrade log level in sd_bus_message_dump(), and log in... 37266/head
Yu Watanabe [Mon, 28 Apr 2025 00:45:33 +0000 (09:45 +0900)] 
sd-bus/bus-dump,busctl: downgrade log level in sd_bus_message_dump(), and log in the caller side

6 months agosd-bus/bus-dump: several coding style cleanups
Yu Watanabe [Mon, 28 Apr 2025 00:37:03 +0000 (09:37 +0900)] 
sd-bus/bus-dump: several coding style cleanups

6 months agobusctl: split out bus_message_dump()
Yu Watanabe [Sun, 27 Apr 2025 13:42:31 +0000 (22:42 +0900)] 
busctl: split out bus_message_dump()

No functional change, just refactoring.

6 months agosd-bus: introduce sd_bus_message_dump_json()
Yu Watanabe [Sun, 27 Apr 2025 14:06:34 +0000 (23:06 +0900)] 
sd-bus: introduce sd_bus_message_dump_json()

We have already expose sd_bus_message_dump(). Let's also expose how
we convert dbus message into json format in busctl.

6 months agosd-varlink: enforce some queuing limits + document associated api functions (#37289)
Lennart Poettering [Wed, 30 Apr 2025 10:19:21 +0000 (12:19 +0200)] 
sd-varlink: enforce some queuing limits + document associated api functions (#37289)

6 months agoAdd our own <netinet/in.h> and <net/if.h> headers and sort includes tree-wide with...
Daan De Meyer [Wed, 30 Apr 2025 08:42:57 +0000 (10:42 +0200)] 
Add our own <netinet/in.h> and <net/if.h> headers and sort includes tree-wide with clang-format (#37278)

6 months agoTODO 37289/head
Lennart Poettering [Fri, 25 Apr 2025 18:13:22 +0000 (20:13 +0200)] 
TODO

6 months agoman: fix include line in sd_varlink_set_description() man page
Lennart Poettering [Tue, 29 Apr 2025 08:41:31 +0000 (10:41 +0200)] 
man: fix include line in sd_varlink_set_description() man page

6 months agoman: document sd_varlink_send()
Lennart Poettering [Tue, 29 Apr 2025 08:41:14 +0000 (10:41 +0200)] 
man: document sd_varlink_send()

6 months agosd-varlink: put a limit on queued outgoing messages
Lennart Poettering [Fri, 25 Apr 2025 18:02:27 +0000 (20:02 +0200)] 
sd-varlink: put a limit on queued outgoing messages

This is only a safety net for runaway programs: it puts a limit on
outgoing messages, i.e. not on resources accessible directly from
outside, but only on resources taken by trusted local code.

6 months agoman: document sd_varlink_push_fd()
Lennart Poettering [Fri, 25 Apr 2025 17:59:49 +0000 (19:59 +0200)] 
man: document sd_varlink_push_fd()

6 months agosd-varlink: refuse accepting more than 253 fds to send along with a Varlink message
Lennart Poettering [Fri, 25 Apr 2025 17:58:22 +0000 (19:58 +0200)] 
sd-varlink: refuse accepting more than 253 fds to send along with a Varlink message

253 is the max number of fds one can send at once on a Linux AF_UNIX
socket. Hence refuse to send more early.

6 months agodocs: add more markdown markup to UIDS_GIDS.md
Lennart Poettering [Wed, 30 Apr 2025 08:23:43 +0000 (10:23 +0200)] 
docs: add more markdown markup to UIDS_GIDS.md

6 months agotree-wide: Sort includes 37278/head
Daan De Meyer [Mon, 28 Apr 2025 13:08:57 +0000 (15:08 +0200)] 
tree-wide: Sort includes

This was done by running a locally built clang-format with
https://github.com/llvm/llvm-project/pull/137617 and
https://github.com/llvm/llvm-project/pull/137840 applied on all .c
and .h files.

6 months agoclang-format: Disable for src/basic/include/linux
Daan De Meyer [Wed, 30 Apr 2025 07:21:55 +0000 (09:21 +0200)] 
clang-format: Disable for src/basic/include/linux

We shouldn't try to format these headers, so add a custom .clang-format
that disables formatting for the directory.

6 months agoclang-format: Add include sorting directives
Daan De Meyer [Mon, 28 Apr 2025 12:17:05 +0000 (14:17 +0200)] 
clang-format: Add include sorting directives

Let's make sure clang-format sorts includes according to our style
guide.

6 months agoresolve: Remove unnecessary ENABLE_DNS_OVER_TLS check
Daan De Meyer [Wed, 30 Apr 2025 07:30:14 +0000 (09:30 +0200)] 
resolve: Remove unnecessary ENABLE_DNS_OVER_TLS check

6 months agonetwork,udev: configure SR-IOV VF attribute one-by-one 37269/head
Yu Watanabe [Wed, 30 Apr 2025 06:37:28 +0000 (15:37 +0900)] 
network,udev: configure SR-IOV VF attribute one-by-one

When a [SR-IOV] section has no setting, e.g.
```ini
[SR-IOV]
VirtualFunction=0
```
then the kernel previously replied -EINVAL, as we send a rtnl message
with an empty IFLA_VF_INFO container.
See See do_setvfinfo() in net/core/rtnetlink.c of the kernel.

When a [SR-IOV] section that has an unsupported settings by the
interface driver, then previously the kernel partially applied
settings and returned -EOPNOTSUPP. E.f.
```ini
[SR-IOV]
VirtualFunction=0
LinkState=auto
Trust=true
MACAddress=02:01:00:3e:61:34
```
and the interface does not support configuring the link state, then
the MAC address is assigned, but the trust is not applied:
```
enp3s0f0: Failed to configure SR-IOV virtual function 0, ignoring: Operation not supported
    vf 0     link/ether 02:01:00:3e:61:34 brd ff:ff:ff:ff:ff:ff, spoof checking on, link-state auto, trust off
```

To fix such issues, this makes networkd/udevd send each attribute
for VF one-by-one.

Fixes #37257 and #37275.

6 months agonetif-sriov: align table
Yu Watanabe [Wed, 30 Apr 2025 05:47:40 +0000 (14:47 +0900)] 
netif-sriov: align table