]> git.ipfire.org Git - thirdparty/systemd.git/blame - TODO
selinux: use existing library calls for audit data
[thirdparty/systemd.git] / TODO
CommitLineData
71092d70 1Bugfixes:
d086fe4e
KS
2* there is nothing to warn about here :)
3 $ systemctl stop systemd-udevd.service systemd-udevd-kernel.socket systemd-udevd-control.socket
4 Warning: Stopping systemd-udevd.service, but it can still be activated by:
5 systemd-udevd-control.socket
6 systemd-udevd-kernel.socket
7
7c66aeba
KS
8* check systemd-tmpfiles for selinux context hookup for mknod(), symlink() and similar
9
c904f64d
LP
10* swap units that are activated by one name but shown in the kernel under another are semi-broken
11
05677bb7 12* make anaconda write timeout=0 for encrypted devices
73090dc8 13
f957632b
KS
14* Dangling symlinks of .automount unit files in .wants/ directories, set up
15 automount points even when the original .automount file did not exist
16 anymore. Only the .mount unit was still around.
17
9a366075
LP
18* make polkit checks async
19
a40593a0 20* properly handle .mount unit state tracking when two mount points are stacked one on top of another on the exact same mount point.
20ffc4c4 21
871206d3
KS
22* we pull src/core/manager.h into src/shared/src/shared/path-lookup.c which is the wrong direction
23 rename enum "ManagerRunningAs" to "SystemdRunningAs" and move it to shared/
24
4ce84985
LP
25F18:
26
e9ace802 27* https://bugzilla.gnome.org/show_bug.cgi?id=680689
4ce84985 28
c3090674
LP
29* Retest multi-seat
30
4ce84985
LP
31* selinux: merge systemd selinux access controls (dwalsh)
32
71092d70 33Features:
dcfc4b2e 34
178cc770
LP
35* instantiated target units
36
bfba3256
LP
37* support *static* (/run) hibernate inhibitors. All rpm -i actions should completely prevent any
38 sort of hibernate action until the next reboot. If the kernel or any other base tool is replaced
39 by rpm, the resume path might fail, the for resume needed kernel might even be uninstalled, and
40 the whole situation leads directly to data loss.
41
de34a42b
LP
42* move debug shell to tty6 and make sure this doesn't break the gettys on tty6
43
98a77df5
LP
44* move cryptsetup key caching into kernel keyctl?
45
dcf76484
LP
46* make nspawn work without terminal
47
424a19f8
LP
48* hw watchdog: optionally try to use the preset watchdog timeout instead of always overriding it
49
50* after deserializing sockets in socket.c we should reapply sockopts and things
51
a1cccad1
LP
52* does vasprintf advance the struct vaargs? http://pastie.org/pastes/4712773/text
53
54* do shutdown audit/utmp msgs inside of PID 1, get rid of systemd-update-utmp-runlevel
55
a1cccad1
LP
56* make timer units go away after they elapsed
57
8556879e
LP
58* http://lists.freedesktop.org/archives/systemd-devel/2012-September/006502.html
59
60* don't use writev() in tmpfiles for sake of compat with sysfs?
61
62* come up with a nice way to write queue/read_ahead_kb for a block device without interfering with readahead
63
64* journald: add kernel cmdline option to disable ratelimiting for debug purposes
65
66* Add a way to reference the machine/boot ID from ExecStart= and similar command lines
67
4a30847b
LP
68* move PID 1 segfaults to /var/lib/systemd/coredump?
69
b5b46d59
LP
70* Document word splitting syntax for ExecStart= and friends
71
5e8b2883
LP
72* when writing journal entries order field items by their address to improve speed on rotating media
73
74* create /sbin/init symlinks from the build system
75
d87be9b0
LP
76* Query Paul Moore about relabelling socket fds while they are open
77
438bacd1
LP
78* move keymaps to /usr/lib/... rather than /usr/lib/udev/...
79
88f89a9b
LP
80* journald: check whether it is OK if the client can still modify delivered journal entries
81
d87be9b0
LP
82* json: use jensson
83
88f89a9b
LP
84* json: properly serialize multiple fields with the same name per entry
85
cb7ed9df 86* journal live copy, based on libneon (client) and libmicrohttpd
88f89a9b
LP
87
88* document in wiki json serialization
89
88f89a9b
LP
90* system-wide seccomp filter
91
92* securityfs: don't mount in container
93
a6e87e90 94* slave/shared remount root fs in container might clash with CAP_SYS_MOUNTS
88f89a9b
LP
95
96* ability to pass fds into systemd
97
98* system.conf should have controls for cgroups
99
88f89a9b
LP
100* bind mount read-only the cgroup tree higher than than nspawn
101
1946b0bd
LP
102* currently system services appear not to generate core dumps...
103
cde9cb34 104* wall messages for shutdown should move to logind
877d54e9 105
38a60d71
LP
106* allow writing multiple conditions in unit files on one line
107
c0ca7aee
LP
108* cleanup ellipsation for log output in journalctl and systemctl status: have a sane way to disable ellipsation, and disable it by default when invoked in less/more
109
110* enforce limits on fds openened by socket units
111
d8b78264
LP
112* explore multiple service instances per listening socket idea
113
114* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server.
115
50b3e64e
LP
116* maybe make systemd-detect-virt suid? or use fscaps?
117
7560fffc
LP
118* shutdown: don't read-only mount anything when running in container
119
5a7e9599
LP
120* nspawn: --read-only is not applied recursively to submounts
121
68f16003 122* MountFlags=shared acts as MountFlags=slave right now.
0790b9fe 123
5a7e9599
LP
124* ReadOnlyDirectories= is not applied recursively to submounts
125
68f16003
LP
126* drop PID 1 reloading, only do reexecing (difficult: Reload()
127 currently is properly synchronous, Reexec() is weird, because we
128 can't delay the response properly until we are back, so instead of
129 being properly synchronous we just keep open the fd and close it
130 when done. That means clients don't get a succesful method reply,
131 but much rather a disconnect on success.
0790b9fe 132
68f16003 133* document that service reload may be implemented as service reexec
df1c8f6a 134
5aea932f
LP
135* remember which condition failed for services, not just the fact that something failed
136
918943c7
LP
137* use opterr = 0 for all getopt tools
138
fd4d89b2
LP
139* properly handle loop back mounts via fstab, especially regards to fsck/passno
140
8230e26d
LP
141* allow services with no ExecStart= but with an ExecStop=
142
dcfc4b2e
LP
143* add proper journal support to "systemctl --user status ..."
144
145* add _SYSTEMD_USER_UNIT= field to journal entries
146
4d9909c9
LP
147* dracut-shutdown needs to be ordered before unmounting /boot
148
47ae7201
LP
149* initialize the hostname from the fs label of /, if /etc/hostname does not exist?
150
decab960
LP
151* install README to /etc/rc.d/init.d (if support for that is enabled) helping people who use "ls" there to figure out which services exist.
152
919a7f39
LP
153* logind: ignore inactive login screens when checking whether power key should be handled
154
88a6c589 155* rename "userspace" to "core-os"
8351ceae 156
6a735368
LP
157* systemctl: "Journal has been rotated since unit was started." message is misleading
158
6b78f9b4
LP
159* syscall filter: add knowledge about compat syscalls
160
9f8d2983
LP
161* syscall filter: don't enforce no new privs?
162
163* syscall filter: option to return EPERM rather than SIGSYS?
164
68f16003
LP
165* syscall filter: port to libseccomp
166
b7def684
LP
167* logind: wakelock/opportunistic suspend support
168
c66d36e5
LP
169* systemd-analyze post-boot is broken for initrd
170
c66d36e5
LP
171* man: clarify that time-sync.target is not only sysv compat but also useful otherwise. Same for similar targets
172
be0aa784
LP
173* .device aliases need to be implemented with the "following" logic, probably.
174
461b1822
LP
175* refuse taking lower-case variable names in sd_journal_send() and friends.
176
9946996c
LP
177* load-fragment: when loading a unit file via a chain of symlinks
178 verify that it isn't masked via any of the names traversed.
179
d1970645
LP
180* journald: we currently rotate only after MaxUse+MaxFilesize has been reached.
181
b4efdf97
LP
182* Document:
183 - PID 1 D-Bus API
b4efdf97 184
3471bedc
LP
185* introduce Type=pid-file
186
5231084b
LP
187* systemctl list-unit-files appears to be broken for symlinked units in /usr/lib
188
eeb87514
LP
189* maybe allow services with ExecStop= set, but no ExecStart=?
190
a32f224a
LP
191* efi: implement /forcefsck as uefi variables thus not requiring file system altering to trigger a file system check
192
193* efi: honour language efi variables for default language selection
194
195* efi: honour timezone efi variables for default timezone selection
196
347e1b6d
KS
197* efi: automatically mount EFI partition to /boot if no such entry exists in /etc/fstab and /boot is empty
198 gummiboot exports the EFI system partion (ESP) device:
199 /sys/firmware/efi/vars/LoaderDeviceIdentifier-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data
200 Acpi(PNP0A03,0)/Pci(1F|2)/?/HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1)
201 '/' is the separator for the device path list
202 HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1) contains the GPT UUID of the ESP
203
204* read the bootloader performance data (raw TSC) in systemd-analyze
205 /sys/firmware/efi/vars/LoaderTicksExec-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data
206 19066159288
207 /sys/firmware/efi/vars/LoaderTicksInit-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data
208 17442940316
209 /sys/firmware/efi/vars/LoaderTicksStartMenu-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data
210 (only set if the menu was active)
166503da 211
59cea26a 212* change Requires=basic.target to RequisiteOverride=basic.target
35eb6b12 213
94734142 214* support rd.luks.allow-discards= kernel cmdline params in cryptsetup generator
f1a8e221 215
24f3a374
LP
216* systemctl: when stopping a service which has triggres and warning about it actually check the TriggeredBy= deps fields
217
99add6fd 218* journal: hook up with EFI firmware log
24f3a374 219
069cfc85
LP
220* nspawn: make use of device cgroup contrller by default
221
7b63bde1
LP
222* drop accountsservice's StandardOutput=syslog and Type=dbus fields
223
5b40d337
LP
224* when breaking cycles drop sysv services first, then services from /run, then from /etc, then from /usr
225
f7f21d33
LP
226* readahead: when bumping /sys readahead variable save mtime and compare later to detect changes
227
27b5482c
LP
228* (attempt to) make Debianites happy:
229 - implement .d/ auto includes for unit files
230 - add syntax to reset ExecStart= lists (and similar)
231
b86fa936
LP
232* move passno parsing to fstab generator
233
a26336da
KS
234* improve !/proc/*/loginuid situation: make /proc/*/loginuid less dependent on CONFIG_AUDIT,
235 or use the users cgroup information when /proc/*/loginuid is not available.
e85647f7 236
eecd1362
LP
237* pam_systemd: try to get old session id from cgroup, if audit sessionid cannot be determined
238
14038c2e
LP
239* pam: when leaving a session explicitly exclude the ReleaseSession() caller process from the killing spree
240
465349c0
LP
241* maybe introduce ~/.config/locale.conf and apply it within PAM
242
243* readahead: make use of EXT4_IOC_MOVE_EXT, as used by http://e4rat.sourceforge.net/
244
245* automount: implement expire
246
eecd1362 247* logind: auto-suspend, auto-shutdown:
d889a206 248 IdleAction=(none|suspend|opportunistic|hibernate|poweroff)
eecd1362
LP
249 IdleActionDelay=...
250 SessionIdleMode=(explicit|ignore|login)
251 ForceShutdown=(yes|no)
252
06dab8e1
LP
253* services which create their own subcgroups break cgroup-empty notification (needs to be fixed in the kernel)
254
7e2668c6
LP
255* don't delete /tmp/systemd-namespace-* before a process is gone down
256
e85647f7
LP
257* vconsole: implement setterm -store -foreground xxx --background zzz
258
e01a15b7 259* ExecOnFailure=/usr/bin/foo
a888b352 260
3b2d5b02
LP
261* fedora: make sshd and pam_loginuid work in nspawn containers
262
0f0dbc46
LP
263* fix utmp for console logins in containers
264
3d9a4122
LP
265* Add pretty name for seats in logind
266
a0a38448
LP
267* ConditionSecurity= should learn about IMA
268
9efaf380
LP
269* Auke: merge Auke's bootchart
270
4ee71782
KS
271* udev: move to LGPL
272
5ba2dc25
KS
273* udev systemd unify:
274 - strpcpy(), strpcpyl(), strscpy(), strscpyl()
275 - utf8 validator code
276 - now() vs. now_usec()
20ffc4c4 277
762f91fa
KS
278* udev: remove network interface renaming, sleep and retry logic, we do
279 no support renaming of interfaces in the conflicting kernel
280 namespace
281
b45f770f 282* udev: find a way to tell udev to not cancel firmware requests when running in initramfs
b8217b7b 283
b45f770f
KS
284* udev: scsi_id -> sg3_utils -> kill scsi_id
285
286* udev: add trigger --subsystem-match=usb/usb_device device
b8217b7b 287
08f23fd2
LP
288* allow configuration of console width/height in vconsole.conf
289
18b754d3 290* cleanup syslog 'priority' vs. 'level' wording
068665b6 291
231931ff
LP
292* dbus upstream still refers to dbus.target and shouldn't
293
169c4f65
LP
294* when a service has the same env var set twice we actually store it twice and return that in systemctl show -p... We should only show the last setting
295
bd08f242
LP
296* support container_ttys=
297
fb0864e7
LP
298* introduce mix of BindTo and Requisite
299
18da4953
LP
300* journalctl: show multiline log messages sanely, expand tabs, and show all valid utf8 messages
301
9586cdfa
LP
302* add DeleteSocketsOnStop=yes|no option to socket units
303
9586cdfa
LP
304* journal: store euid in journal if it differs from uid
305
7f110ff9
LP
306* There's currently no way to cancel fsck (used to be possible via C-c or c on the console)
307
101f0776
LP
308* journal: sanely deal with entries which are larger than the individual file size, but where the componets would fit
309
f7f964eb
LP
310* add command to systemctl to plot dependency graph as tree (see rhbz 795365)
311
d0e5a333
LP
312* add option to sockets to avoid activation. Instead just drop packets/connections, see http://cyberelk.net/tim/2012/02/15/portreserve-systemd-solution/
313
d0e5a333
LP
314* default unix qlen is too small (10). bump sysctl? add sockopt?
315
15e9fbd8
LP
316* Possibly, detect whether SysV init scripts can do reloading by looking for "echo Usage:" lines
317
53ed2eeb
LP
318* figure out whether we should leave dbus around during shutdown
319
680a1dbc
LP
320* dbus: in fedora, make the machine a symlink to /etc/machine-id
321
a6e87e90 322* dbus: move dbus to early boot
88f89a9b 323
7e64c73a
LP
324* journald: reuse XZ context
325
c4aa65e7 326* logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API
7e64c73a 327
a558d003
LP
328* journal: API for looking for retrieving "all values of this field"
329
330* journal: deal nicely with byte-by-byte copied files, especially regards header
331
332* journal: local deserializer of export mode, http server
333
334* journal: message catalog
335
05aa9edd
LP
336* document the exit codes when services fail before they are exec()ed
337
62f21ec9
LP
338* systemctl journal command
339
f7357f59 340* journalctl: --cursor support
62f21ec9 341
87a8baa3
LP
342* save coredump in Windows/Mozilla minidump format
343
344* support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting)
345
5ba081b0
LP
346* clean up session cgroups that remain after logout (think sshd), but eventually run empty
347
b3fa47e0
LP
348* support "systemctl stop foobar@.service" to stop all units matching a certain template
349
7f3e6257
LP
350* logind: allow showing logout dialog from system
351
352* document that %% can be used to write % in a string that is specifier extended
353
4cbd9ecf
LP
354* when an instanced service exits, remove its parent cgroup too if possible.
355
65c0cf71
LP
356* default to actual 32bit PIDs, via /proc/sys/kernel/pid_max
357
f957632b
KS
358* be able to specify a forced restart of service A where service B depends on, in case B
359 needs to be auto-respawned?
360
a2f5666d
LP
361* Something is wrong with symlink handling of "autovt@.service" in "systemctl list-unit-files"
362
ad740100
LP
363* when a bus name of a service disappears from the bus make sure to queue further activation requests
364
c821bd28
LP
365* something like ConditionExec= or ExecStartPre= without failure state
366
de6c78f8 367* tmpfiles: apply "x" on "D" too (see patch from William Douglas)
7d441ddb 368
14e639ae
LP
369* don't set $HOME in services unless requested
370
ff01d048
LP
371* hide PAM/TCPWrap options in fragment parser when compile time disabled
372
d3c7d7dd 373* when we automatically restart a service, ensure we restart its rdeps, too.
72b9ed82 374
1d6702e8
LP
375* allow Type=simple with PIDFile=
376 https://bugzilla.redhat.com/show_bug.cgi?id=723942
377
71092d70
LP
378* move PAM code into its own binary
379
380* warn if the user stops a service but not its associated socket
0a55b298 381
97f73ffb
LP
382* logind: spawn user@..service on login
383
85f248b2
LP
384* logind: non-local X11 server handling
385
1258097c
LP
386* implement Register= switch in .socket units to enable registration
387 in Avahi, RPC and other socket registration services.
388
a4c279f8
LP
389* make sure systemd-ask-password-wall does not shutdown systemd-ask-password-console too early
390
d3fc81bd
LP
391* readahead: use BTRFS_IOC_DEFRAG_RANGE instead of BTRFS_IOC_DEFRAG ioctl, with START_IO
392
393* readahead: check whether a btrfs volume includes ssd by checking mount flag "ssd"
394
7c697168 395* support sd_notify() style notification when reload begins (RELOADING=1), reload is finished (READY=1), and add ReloadSignal= then to use in combination
253ee27a 396
71092d70 397* support sd_notify() style notification when shutting down, to make auto-exit bus services work (STOPPING=1)
8d0e38a2 398
f28f1daf
LP
399* verify that the AF_UNIX sockets of a service in the fs still exist
400 when we start a service in order to avoid confusion when a user
401 assumes starting a service is enough to make it accessible
402
88a07670
LP
403* Make it possible to set the keymap independently from the font on
404 the kernel cmdline. Right now setting one resets also the other.
405
916abb21
LP
406* move nss-myhostname into systemd
407
71092d70 408* and a dbus call to generate target from current state
916abb21 409
b23de6af
LP
410* drop /.readahead on bigger upgrades with yum
411
21bdae12
LP
412* add support for /bin/mount -s
413
9534ce54
LP
414* GC unreferenced jobs (such as .device jobs)
415
68c7d001 416* write blog stories about:
68c7d001
LP
417 - enabling dbus services
418 - status update
7a2a0b90 419 - how to make changes to sysctl and sysfs attributes
253ee27a 420 - remote access
5d0fcd7c
LP
421 - how to pass throw-away units to systemd, or dynamically change properties of existing units
422 - how to integrate cgconfig and suchlike with systemd
acb14d31 423 - resource control in systemd
8bbabc44
LP
424 - inhibiting
425 - testing with Harald's awesome test kit
abdf7993 426 - restart
73090dc8 427
44143309 428* allow port=0 in .socket units
3d57c6ab 429
b9a2a36b
LP
430* move readahead files into /var, look for them with .path units
431
ba1a5515 432* teach dbus to activate all services it finds in /etc/systemd/services/org-*.service
9408a2d2 433
71092d70 434* support systemd.mask= on the kernel command line.
3f7a8c4e 435
f9276855
LP
436* when key file cannot be found, read it from kbd in cryptsetup
437
260abb78
LP
438* reuse mkdtemp namespace dirs in /tmp?
439
260abb78 440* recreate systemd's D-Bus private socket file on SIGUSR2
2791a8f8 441
a8f11321
LP
442* Support --test based on current system state
443
21bdae12
LP
444* investigate whether the gnome pty helper should be moved into systemd, to provide cgroup support.
445
c32e0c40
LP
446* maybe introduce ExecRestartPre=
447
35f10fcc
LP
448* configurable jitter for timer events
449
cc9784c6
LP
450* timer events with system resume
451
5e8b2883
LP
452* timer events on calendar time:
453 maybe use this time syntax? http://ohse.de/uwe/uschedule/uschedule.html
71092d70 454
59fee421
LP
455* dot output for --test showing the 'initial transaction'
456
8c6db833 457* calendar time support in timer, iCalendar semantics for the timer stuff (RFC2445)
8bf7fea5 458 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=99ee5315dac6211e972fa3f23bcc9a0343ff58c4
351c7e74 459
129126f3 460* implicitly import "defaults" settings file into all types
773ba909 461
71092d70 462* writable cgroups dbus properties for live changes
75787bb7 463
0cdad5c0
LP
464* read config fragments for all units from /lib/systemd/system/foobar.service.d/ to override/extend specific settings
465
129126f3 466* port over to LISTEN_FDS/LISTEN_PID:
7d9e57d2
KS
467 - rpcbind (/var/run/rpcbind.sock!) HAVEPATCH
468 - cups HAVEPATCH
a625ac1a 469 - postfix, saslauthd
a625ac1a
LP
470 - apache/samba
471 - libvirtd (/var/run/libvirt/libvirt-sock-ro)
472 - bluetoothd (/var/run/sdp! @/org/bluez/audio!)
a625ac1a
LP
473 - distccd
474
71092d70 475* fingerprint.target, wireless.target, gps.target, netdevice.target
246756ca 476
50f2a90d 477* io priority during initialization
8fe914ec 478
71092d70 479* systemctl list-jobs - show dependencies
20604ebc 480
20604ebc
LP
481* add systemctl switch to dump transaction without executing it
482
9534ce54
LP
483* drop cap bounding set in readahead and other services
484
2f8cd170 485External:
74fe1fe3 486
cc9784c6 487* dbus:
cc9784c6 488 - dbus --user
3377af3e 489 - natively watch for dbus-*.service symlinks (PENDING)
cc9784c6
LP
490 - allow specification of socket mode/umask when allocating DBusServer
491 - allow disabling of fd passing when connecting a AF_UNIX connection
3377af3e 492 - allow disabling of UID passing for AUTH EXTERNAL
b69d29ce 493 - always pass cred data along each message
cc9784c6 494
71092d70
LP
495* fix alsa mixer restore to not print error when no config is stored
496
7d9e57d2 497* gnome-shell python script/glxinfo/is-accelerated must die
f959c5e6 498
74fe1fe3
LP
499* make cryptsetup lower --iter-time
500
44143309 501* patch kernel for xattr support in /dev, /proc/, /sys and /sys/fs/cgroup?
06ae4bfe 502
69b1c674
KS
503* NTP: the kernel's 11-minutes-mode syncs the system time to the RTC, but only
504 in an ~30 minutes window. It does not adjust larger differences. Find a way
505 to tell the kernel, to always do a full time sync when the RTC is in UTC and
506 we are in 11-minutes-mode. When we trust the system time to NTP we also want
507 the RTC to sync up.
508
71092d70 509* kernel: add device_type = "fb", "fbcon" to class "graphics"
14bd37fe 510
129126f3 511Regularly:
874aa2cc 512
129126f3 513* look for close() vs. close_nointr() vs. close_nointr_nofail()
5021be21 514
129126f3 515* check for strerror(r) instead of strerror(-r)
5b6319dc
LP
516
517* Use PR_SET_PROCTITLE_AREA if it becomes available in the kernel
8c6db833 518
14212119 519* %m in printf() instead of strerror(errno);
444a79d3
LP
520
521* pahole
522
71092d70 523* set_put(), hashmap_put() return values check. i.e. == 0 doesn't free()!
a3a3e5b6 524
4db17f29 525* use secure_getenv() instead of getenv() where appropriate
88fae6e0 526
a3a3e5b6
LP
527Scheduled for removal (or fixing):
528
529* xxxOverridable dependencies