]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
8 years agoNEWS: update contributors list
Lennart Poettering [Mon, 7 Sep 2015 23:36:59 +0000 (01:36 +0200)] 
NEWS: update contributors list

8 years agoMerge pull request #1193 from phomes/typos
Daniel Mack [Mon, 7 Sep 2015 21:16:14 +0000 (23:16 +0200)] 
Merge pull request #1193 from phomes/typos

man: typo fixes

8 years agoman: typo fixes 1193/head
Thomas Hindoe Paaboel Andersen [Mon, 7 Sep 2015 18:06:58 +0000 (20:06 +0200)] 
man: typo fixes

8 years agoMerge pull request #1191 from poettering/nspawn-split
Daniel Mack [Mon, 7 Sep 2015 17:08:39 +0000 (19:08 +0200)] 
Merge pull request #1191 from poettering/nspawn-split

nspawn: split up nspawn.c into multiple smaller .c files

8 years agonspawn: sort and clean up included header list 1191/head
Lennart Poettering [Mon, 7 Sep 2015 16:56:54 +0000 (18:56 +0200)] 
nspawn: sort and clean up included header list

Let's remove unnecessary inclusions, and order the list alphabetically
as suggested in CODING_STYLE now.

8 years agonspawn: remove nspawn.h, it's empty now
Lennart Poettering [Mon, 7 Sep 2015 16:47:34 +0000 (18:47 +0200)] 
nspawn: remove nspawn.h, it's empty now

8 years agonspawn: split out --uid= logic into nspawn-setuid.[ch]
Lennart Poettering [Mon, 7 Sep 2015 16:42:14 +0000 (18:42 +0200)] 
nspawn: split out --uid= logic into nspawn-setuid.[ch]

8 years agonspawn: split out machined registration code to nspawn-register.[ch]
Lennart Poettering [Mon, 7 Sep 2015 16:36:05 +0000 (18:36 +0200)] 
nspawn: split out machined registration code to nspawn-register.[ch]

8 years agonspawn: split out cgroup related calls into nspawn-cgroup.[ch]
Lennart Poettering [Mon, 7 Sep 2015 16:25:04 +0000 (18:25 +0200)] 
nspawn: split out cgroup related calls into nspawn-cgroup.[ch]

8 years agonspawn: split out network related code to nspawn-network.[ch]
Lennart Poettering [Mon, 7 Sep 2015 15:43:45 +0000 (17:43 +0200)] 
nspawn: split out network related code to nspawn-network.[ch]

8 years agonspawn: split all port exposure code into nspawn-expose-port.[ch]
Lennart Poettering [Mon, 7 Sep 2015 14:52:24 +0000 (16:52 +0200)] 
nspawn: split all port exposure code into nspawn-expose-port.[ch]

8 years agonspawn: split out mount related functions into a new nspawn-mount.c file
Lennart Poettering [Mon, 7 Sep 2015 13:59:52 +0000 (15:59 +0200)] 
nspawn: split out mount related functions into a new nspawn-mount.c file

8 years agoMerge pull request #1189 from poettering/unit-start
Daniel Mack [Mon, 7 Sep 2015 12:27:13 +0000 (14:27 +0200)] 
Merge pull request #1189 from poettering/unit-start

unit: move "not supported" check after condition check in unit_start()

8 years agounit: move "not supported" check after condition check in unit_start() 1189/head
Lennart Poettering [Mon, 7 Sep 2015 12:08:24 +0000 (14:08 +0200)] 
unit: move "not supported" check after condition check in unit_start()

Make sure we always check conditions before checking whether the unit
type is supported in unit_start(), since condition checks are "clean
errors", while "not supported" errors are fatal.

This cleans up the boot output of systemd in containers, where a lot of
NOTSUPP lines were shown befor this fix.

This partially reverts 8ff4d2ab0d4758e914aea6d86154d85f2b2c787f which
reorder the checks.

8 years agoNEWS: fix typos
Daniel Mack [Mon, 7 Sep 2015 11:06:53 +0000 (13:06 +0200)] 
NEWS: fix typos

8 years agoupdate NEWS
Lennart Poettering [Mon, 7 Sep 2015 10:43:25 +0000 (12:43 +0200)] 
update NEWS

8 years agoMerge pull request #1178 from poettering/gpt-auto-fixes
Daniel Mack [Mon, 7 Sep 2015 10:28:34 +0000 (12:28 +0200)] 
Merge pull request #1178 from poettering/gpt-auto-fixes

handle LUKS root partitions better in gpt-auto, plus other fixes

8 years agoMerge pull request #1183 from dvdhrm/cpename
Lennart Poettering [Mon, 7 Sep 2015 09:12:27 +0000 (11:12 +0200)] 
Merge pull request #1183 from dvdhrm/cpename

man: clarify wording of os-release.CPE_NAME

8 years agoMerge pull request #1182 from martinpitt/master
David Herrmann [Mon, 7 Sep 2015 09:02:40 +0000 (11:02 +0200)] 
Merge pull request #1182 from martinpitt/master

tests: Skip test-cgroup-util test_mask_supported() when not running under systemd

8 years agoman: clarify wording of os-release.CPE_NAME 1183/head
David Herrmann [Mon, 7 Sep 2015 08:57:50 +0000 (10:57 +0200)] 
man: clarify wording of os-release.CPE_NAME

We expect the CPE_NAME to be formatted in URI binding syntax. Make that
clear in the documentation. Furthermore, the CPE-spec has been taken over
by NIST, so adjust the links as well.

Reported by: Ben Harris <bjh21@cam.ac.uk>

8 years agotests: Skip test-cgroup-util test_mask_supported() when not running under systemd 1182/head
Martin Pitt [Mon, 7 Sep 2015 06:09:13 +0000 (08:09 +0200)] 
tests: Skip test-cgroup-util test_mask_supported() when not running under systemd

Commit 5f4c5fef6 introduced this new test case, but this does not work in
build chroots where cgroupfs is not mounted. So skip the test if systemd is not
running.

8 years agoMerge pull request #1181 from evverx/update-systemd-analyze-completion
Daniel Mack [Mon, 7 Sep 2015 03:53:19 +0000 (05:53 +0200)] 
Merge pull request #1181 from evverx/update-systemd-analyze-completion

shell-completion: update systemd-analyze bash-completion

8 years agoshell-completion: update systemd-analyze bash-completion 1181/head
Evgeny Vereshchagin [Mon, 7 Sep 2015 01:44:30 +0000 (04:44 +0300)] 
shell-completion: update systemd-analyze bash-completion

* Change --no-man to --man (see dad29df)
* --{from,to}-pattern require arg

8 years agoMerge pull request #1179 from poettering/sd-event-sigchld-fix
Tom Gundersen [Mon, 7 Sep 2015 01:02:08 +0000 (03:02 +0200)] 
Merge pull request #1179 from poettering/sd-event-sigchld-fix

sd-event: make sure to create a signal queue for the right signal

8 years agoMerge pull request #1165 from poettering/nspawn-files
Tom Gundersen [Mon, 7 Sep 2015 00:59:08 +0000 (02:59 +0200)] 
Merge pull request #1165 from poettering/nspawn-files

various fixes to the core, logind, machined, nspawn

8 years agosd-event: make sure to create a signal queue for the right signal 1179/head
Lennart Poettering [Sun, 6 Sep 2015 22:31:24 +0000 (00:31 +0200)] 
sd-event: make sure to create a signal queue for the right signal

We should never access the "signal" part of the event source unless the
event source is actually for a signal. In this case it's a child pid
handler however, hence make sure to use the right signal.

This is a fix for PR #1177, which in turn was a fix for
9da4cb2be260ed123f2676cb85cb350c527b1492.

8 years agosystemctl: a number of cleanups regarding error handling in systemctl 1178/head
Lennart Poettering [Sun, 6 Sep 2015 22:06:49 +0000 (00:06 +0200)] 
systemctl: a number of cleanups regarding error handling in systemctl

8 years agogpt-auto: minor simplificatin handling the no-auto GPT flag
Lennart Poettering [Sun, 6 Sep 2015 21:06:05 +0000 (23:06 +0200)] 
gpt-auto: minor simplificatin handling the no-auto GPT flag

Let's query the flags only once, and document why we ignore it for the
ESP.

8 years agogpt-auto: try to handle LUKS root partitions better
Lennart Poettering [Sun, 6 Sep 2015 21:04:32 +0000 (23:04 +0200)] 
gpt-auto: try to handle LUKS root partitions better

If the root file system is located on an encrypted root disk, we'll not
find the GPT partition table for it. Let's fix that by following the
slaves/ symlinks in /sys for the device. We only handle devices having
exactly one backing device.

Also see: #1167

8 years agoMerge pull request #1168 from poettering/readme-kernel-version
Daniel Mack [Sun, 6 Sep 2015 22:11:25 +0000 (00:11 +0200)] 
Merge pull request #1168 from poettering/readme-kernel-version

README: bump minimal required kernel version

8 years agoMerge pull request #1177 from phomes/sd-event-bug-fix
Daniel Mack [Sun, 6 Sep 2015 22:11:09 +0000 (00:11 +0200)] 
Merge pull request #1177 from phomes/sd-event-bug-fix

sd-event: fix call to event_make_signal_data

8 years agoNEWS: add more content to both the 225 and 226 NEWS section
Lennart Poettering [Sun, 6 Sep 2015 22:08:12 +0000 (00:08 +0200)] 
NEWS: add more content to both the 225 and 226 NEWS section

8 years agosd-event: fix call to event_make_signal_data 1177/head
Thomas Hindoe Paaboel Andersen [Sun, 6 Sep 2015 20:06:45 +0000 (22:06 +0200)] 
sd-event: fix call to event_make_signal_data

This looks like a typo from commit 9da4cb2b where it was added.

8 years agoMerge pull request #1174 from mbiebl/remove-sphinx-leftover
Lennart Poettering [Sun, 6 Sep 2015 19:07:01 +0000 (21:07 +0200)] 
Merge pull request #1174 from mbiebl/remove-sphinx-leftover

build-sys: remove sphinx binary from configure summary

8 years agoMerge pull request #1176 from piotrdrag/master
Lennart Poettering [Sun, 6 Sep 2015 19:05:49 +0000 (21:05 +0200)] 
Merge pull request #1176 from piotrdrag/master

Updated Polish translation

8 years agoUpdated Polish translation 1176/head
Piotr Drąg [Sun, 6 Sep 2015 18:42:16 +0000 (20:42 +0200)] 
Updated Polish translation

8 years agobuild-sys: remove sphinx binary from configure summary 1174/head
Michael Biebl [Sun, 6 Sep 2015 17:05:35 +0000 (19:05 +0200)] 
build-sys: remove sphinx binary from configure summary

We no longer use sphinx as part of the build process so remove it from
the configure summary as well.
This is a leftover from commit 2799e519cabb6dfa99341b9a56ebd4dc2a4ec22a.

8 years agoREADME: bump minimal required kernel version 1168/head
Lennart Poettering [Sun, 6 Sep 2015 13:58:20 +0000 (15:58 +0200)] 
README: bump minimal required kernel version

We generally try to support 2y old kernels, which allows us bump the
minimal required version to 3.11 now.

Also, clarify that support for the unified cgroup hierarchy requires 4.2
or newer.

8 years agoMerge pull request #1153 from evverx/dot-alias-handling
Lennart Poettering [Sun, 6 Sep 2015 10:34:09 +0000 (12:34 +0200)] 
Merge pull request #1153 from evverx/dot-alias-handling

analyze: add "alias" handling to dot subcommand

8 years agoanalyze: add "alias" handling to dot subcommand 1153/head
Evgeny Vereshchagin [Sat, 5 Sep 2015 05:18:08 +0000 (08:18 +0300)] 
analyze: add "alias" handling to dot subcommand

`systemd-analyze dot default.target` works fine

8 years agoMerge pull request #1159 from AnchorCat/polkit-details/v2
Lennart Poettering [Sun, 6 Sep 2015 00:00:05 +0000 (02:00 +0200)] 
Merge pull request #1159 from AnchorCat/polkit-details/v2

Provide unit name and operation in manage-units polkit checks (v2)

8 years agoMerge pull request #1162 from dvdhrm/bus-recursive-nodes
Lennart Poettering [Sat, 5 Sep 2015 23:58:48 +0000 (01:58 +0200)] 
Merge pull request #1162 from dvdhrm/bus-recursive-nodes

sd-bus: make introspection data non-recursive

8 years agounits: make sure that .nspawn files override the default settings in systemd-nspawn... 1165/head
Lennart Poettering [Sat, 5 Sep 2015 23:32:27 +0000 (01:32 +0200)] 
units: make sure that .nspawn files override the default settings in systemd-nspawn@.service

8 years agonspawn: add new .nspawn files for container settings
Lennart Poettering [Sat, 5 Sep 2015 23:22:14 +0000 (01:22 +0200)] 
nspawn: add new .nspawn files for container settings

.nspawn fiels are simple settings files that may accompany container
images and directories and contain settings otherwise passed on the
nspawn command line. This provides an efficient way to attach execution
data directly to containers.

8 years agoMerge pull request #1161 from dvdhrm/include-order2
Lennart Poettering [Sat, 5 Sep 2015 23:30:08 +0000 (01:30 +0200)] 
Merge pull request #1161 from dvdhrm/include-order2

CODING_STYLE: mandate alphabetical include order (v2)

8 years agoMerge pull request #1160 from dvdhrm/bus-user
Kay Sievers [Sat, 5 Sep 2015 21:06:31 +0000 (23:06 +0200)] 
Merge pull request #1160 from dvdhrm/bus-user

sd-bus: derive uid from cgroup if possible

8 years agomachine: make sure to call unlockpt() even for local host pty connections
Lennart Poettering [Sat, 5 Sep 2015 18:24:52 +0000 (20:24 +0200)] 
machine: make sure to call unlockpt() even for local host pty connections

This fixes breakage for local host pty handling, introduced in
395745ba533ac91fe118f43ec83f13a752c0b473.

Fixes #1139

8 years agologind: make scope of wall message handling smaller
Lennart Poettering [Sat, 5 Sep 2015 18:24:08 +0000 (20:24 +0200)] 
logind: make scope of wall message handling smaller

8 years agounit: make unit_can_start() more accurate
Lennart Poettering [Sat, 5 Sep 2015 18:21:46 +0000 (20:21 +0200)] 
unit: make unit_can_start() more accurate

This funciton is exposed via CanStart on the bus, and should be as
accurate as possible. Hence: make sure to return false for units of unit
types not supported on the system, and for unit types where
configuration failed to load.

Also see #1105.

8 years agocore: don't use uninitialized errno
Lennart Poettering [Sat, 5 Sep 2015 18:21:08 +0000 (20:21 +0200)] 
core: don't use uninitialized errno

8 years agomachine: clarify that /var/lib/containers is legacy
Lennart Poettering [Sat, 5 Sep 2015 18:20:24 +0000 (20:20 +0200)] 
machine: clarify that /var/lib/containers is legacy

8 years agosd-bus: make introspection data non-recursive 1162/head
David Herrmann [Sat, 5 Sep 2015 17:43:29 +0000 (19:43 +0200)] 
sd-bus: make introspection data non-recursive

Currently, our introspection data looks like this:

        <node>
         <interface name="org.freedesktop.DBus.Peer">
           ...
         </interface>
         <interface name="org.freedesktop.DBus.Introspectable">
           ...
         </interface>
         <interface name="org.freedesktop.DBus.Properties">
           ...
         </interface>
         <node name="org"/>
         <node name="org/freedesktop"/>
         <node name="org/freedesktop/login1"/>
         <node name="org/freedesktop/login1/user"/>
         <node name="org/freedesktop/login1/user/self"/>
         <node name="org/freedesktop/login1/user/_1000"/>
         <node name="org/freedesktop/login1/seat"/>
         <node name="org/freedesktop/login1/seat/self"/>
         <node name="org/freedesktop/login1/seat/seat0"/>
         <node name="org/freedesktop/login1/session"/>
         <node name="org/freedesktop/login1/session/self"/>
         <node name="org/freedesktop/login1/session/c1"/>
        </node>

(ordered alphabetically for better visibility)

This is grossly incorrect. The spec says that we're allowed to return
non-directed children, however, it does not allow us to return data
recursively in multiple parents. If we return "org", then we must not
return anything else that starts with "org/".

It is unclear, whether we can include child-nodes as a tree. Moreover, it
is usually not what the caller wants. Hence, this patch changes sd-bus to
never return introspection data recursively. Instead, only a single
child-layer is returned.

This patch relies on enumerators to never return hierarchies. If someone
registers an enumerator via sd_bus_add_enumerator, they better register
sub-enumerators if they support *TRUE* hierarchies. Each enumerator is
treated as a single layer and not filtered.
Enumerators are still allowed to return nested data. However, that data
is still required to be a single hierarchy. For instance, returning
"/org/foo" and "/com/bar" is fine, but including "/com" or "/org" in that
dataset is not.
This should be the default for enumerators and I see no reason to filter
in sd-bus. Moreover, filtering that data-set would require to sort the
strv by path and then do prefix-filtering. This is O(n log n), which
would be fine, but still better to avoid.

Fixes #664.

8 years agoTODO: update networkd section
David Herrmann [Sat, 5 Sep 2015 16:29:14 +0000 (18:29 +0200)] 
TODO: update networkd section

Remove two freshly implemented features, and add TSO support as a new
one.

8 years agoCODING_STYLE: mandate alphabetical include order 1161/head
David Herrmann [Sat, 5 Sep 2015 11:03:59 +0000 (13:03 +0200)] 
CODING_STYLE: mandate alphabetical include order

systemd-internal headers must not rely on include order. That means, they
either must contain forward-declarations of used types/functions, or they
must include all dependencies on their own. Therefore, there is no reason
to mandate an include order on the call-side.

However, global includes should always be ordered first. We don't want
local definitions to leak into global includes, possible changing their
behavior. Apparently, namespacing is a complex problem that people are
incapable of implementing properly..

Apart from "global before local", there is no reason to mandate a random
include order (which we happen to do right now). Instead, mandate
alphabetical ordering. The current rules do not have any benefit at all.
They neither reduce include-complexity, nor allow easy auditing of
include files. But with alphabetical ordering, we get duplicate-detection
for free, it gets *much much* easier to figure out whether a header is
already included, and it is trivial to add new headers.

8 years agosd-bus: derive uid from cgroup if possible 1160/head
David Herrmann [Sat, 5 Sep 2015 15:54:30 +0000 (17:54 +0200)] 
sd-bus: derive uid from cgroup if possible

Whenever we run in a user context, sd_bus_{default_user,open_user}() and
friends should always connect to the user-bus of the current context,
instead of deriving the uid from getuid(). This allows us running
programs via sudo/su, without the nasty side-effect of accidentally
connecting to the root user-bus.

This patch enforces the idea of making su/sudo *not* opening sessions by
default. That is, all they do is raising privileges, but keeping
everything set as before. You can still use su/sudo to open real sessions
by requesting a login-session (or loading pam_systemd otherwise).
However, in this case XDG_RUNTIME_DIR= will not be set (as usual in these
cases), hence, you will not be able to connect to *any* user-bus.

Long story short: With this patch applied, both:
        - ./busctl --user
        - sudo ./busctl --user
..will successfully connect to the user-bus of the local user.

Fixes #390.

8 years agocore: pass details to polkit for some unit actions 1159/head
Michael Chapman [Sat, 5 Sep 2015 14:07:17 +0000 (00:07 +1000)] 
core: pass details to polkit for some unit actions

The following details are passed:

- unit: the primary name of the unit upon which the action was
        invoked (i.e. after resolving any aliases);
- verb: one of 'start', 'stop', 'reload', 'restart', 'try-restart',
        'reload-or-restart', 'reload-or-try-restart', 'kill',
        'reset-failed', or 'set-property', corresponding to the
        systemctl verb used to invoke the action.

Typical use of these details in a polkit policy rule might be:

  // Allow alice to manage example.service;
  // fall back to implicit authorization otherwise.
  polkit.addRule(function(action, subject) {
      if (action.id == "org.freedesktop.systemd1.manage-units" &&
          action.lookup("unit") == "example.service" &&
          subject.user == "alice") {
          return polkit.Result.YES;
      }
  });

We also supply a custom polkit message that includes the unit's name and
the requested operation.

8 years agobus-util: support details in CheckAuthorization calls
Michael Chapman [Sat, 5 Sep 2015 14:07:16 +0000 (00:07 +1000)] 
bus-util: support details in CheckAuthorization calls

Extra details for an action can be supplied when calling polkit's
CheckAuthorization method. Details are a list of key/value string pairs.
Custom policy can use these details when making authorization decisions.

8 years agoMerge pull request #1140 from poettering/sd-event-signals
David Herrmann [Sat, 5 Sep 2015 13:20:21 +0000 (15:20 +0200)] 
Merge pull request #1140 from poettering/sd-event-signals

A variety of sd-event, sd-login and cgroup fixes

8 years agosd-login: minor header commenting improvements 1140/head
Lennart Poettering [Fri, 4 Sep 2015 07:57:51 +0000 (09:57 +0200)] 
sd-login: minor header commenting improvements

8 years agosd-login: add new sd_pid_get_cgroup() API
Lennart Poettering [Fri, 4 Sep 2015 07:54:14 +0000 (09:54 +0200)] 
sd-login: add new sd_pid_get_cgroup() API

This adds a new sd_pid_get_cgroup() call to sd-login which may be used
to query the control path of a process. This is useful for programs when
making use of delegation units, in order to figure out which subtree has
been delegated.

In light of the unified control group hierarchy this is finally safe to
do, hence let's add a proper API for it, to make it easier to use this.

8 years agoMerge pull request #1157 from dvdhrm/logind-wallfix
Daniel Mack [Sat, 5 Sep 2015 12:33:56 +0000 (14:33 +0200)] 
Merge pull request #1157 from dvdhrm/logind-wallfix

login: fix NULL-deref on wall_message

8 years agoMerge pull request #1145 from systemd-mailing-devs/1441372815-12195-1-git-send-email...
Daniel Mack [Sat, 5 Sep 2015 12:32:56 +0000 (14:32 +0200)] 
Merge pull request #1145 from systemd-mailing-devs/1441372815-12195-1-git-send-email-hdegoede@redhat.com

hwdb: Add Thinkpad T550 / W550s to 70-pointingstick.hwdb

8 years agologin: fix NULL-deref on wall_message 1157/head
David Herrmann [Sat, 5 Sep 2015 10:56:04 +0000 (12:56 +0200)] 
login: fix NULL-deref on wall_message

We treat an empty wall-message equal to a NULL wall-message since:

        commit 5744f59a3ee883ef3a78214bd5236157acdc35ba
        Author: Lennart Poettering <lennart@poettering.net>
        Date:   Fri Sep 4 10:34:47 2015 +0200

            logind: treat an empty wall message like a NULL one

Fix the shutdown scheduler to not deref a NULL pointer, but properly
check for an empty wall-message.

Fixes: #1120
8 years agoMerge pull request #1150 from evverx/update-systemctl-completion
Lennart Poettering [Sat, 5 Sep 2015 10:25:52 +0000 (12:25 +0200)] 
Merge pull request #1150 from evverx/update-systemctl-completion

shell-completion: update systemctl bash completion

8 years agoMerge pull request #1149 from martinpitt/fix-dhcp-error-codes
Lennart Poettering [Sat, 5 Sep 2015 10:21:20 +0000 (12:21 +0200)] 
Merge pull request #1149 from martinpitt/fix-dhcp-error-codes

networkd: adjust error codes for nonexisting DHCP data

8 years agoMerge pull request #1146 from martinpitt/master
Lennart Poettering [Sat, 5 Sep 2015 10:14:55 +0000 (12:14 +0200)] 
Merge pull request #1146 from martinpitt/master

tests: Skip tests which need to access /sys/fs/cgroup if that is not …

8 years agoNEWS: add entries for v226
David Herrmann [Sat, 5 Sep 2015 09:09:44 +0000 (11:09 +0200)] 
NEWS: add entries for v226

Initial set of features for the upcoming v226 release next week. This is
mostly about the unified cgroup hierarchy and DHCP.

8 years agoshell-completion: update systemctl bash completion 1150/head
Evgeny Vereshchagin [Fri, 4 Sep 2015 20:04:10 +0000 (23:04 +0300)] 
shell-completion: update systemctl bash completion

Many new options have been added since the bash completion was last
updated.

8 years agonetworkd: adjust error codes for nonexisting DHCP data 1149/head
Martin Pitt [Fri, 4 Sep 2015 19:16:35 +0000 (21:16 +0200)] 
networkd: adjust error codes for nonexisting DHCP data

Commit 0339cd770 changed libsystemd-network's error code for missing DHCP lease
data from ENOENT to ENODATA. Adjust networkd accordingly.

This fixes interfaces being stuck in "degraded/configuring" mode forever.

https://github.com/systemd/systemd/issues/1147

8 years agotests: Skip tests which need to access /sys/fs/cgroup if that is not available 1146/head
Martin Pitt [Fri, 4 Sep 2015 14:34:21 +0000 (16:34 +0200)] 
tests: Skip tests which need to access /sys/fs/cgroup if that is not available

Commit efdb023 ("core: unified cgroup hierarchy support") introduced a new
error ENOEXEC in cg_unified() if /sys/fs/cgroup/ is not available. Adjust the
"skip" checks in various tests accordingly.

Add a corresponding "skip" check to test-bus-creds as well, as
sd_bus_creds_new_from_pid() now calls cg_unified() as well.

This re-fixes "make check" in build chroots without /sys/fs/cgroup.

https://github.com/systemd/systemd/issues/1132

8 years agohwdb: Add Thinkpad T550 / W550s to 70-pointingstick.hwdb 1145/head
Hans de Goede [Fri, 4 Sep 2015 13:20:15 +0000 (15:20 +0200)] 
hwdb: Add Thinkpad T550 / W550s to 70-pointingstick.hwdb

Like many other recent thinkpads the factory default pointingstick
sensitivity on these devices is quite low, making the pointingstick
very slow in moving the cursor.

This extends the existing hwdb rules for tweaking the sensitivity to
also apply to the T550 / W550s models.

BugLink: https://bugzilla.redhat.com/show_bug.cgi?id=1200717
8 years agoMerge pull request #1142 from dvdhrm/proxy-nofile
Lennart Poettering [Fri, 4 Sep 2015 10:45:10 +0000 (12:45 +0200)] 
Merge pull request #1142 from dvdhrm/proxy-nofile

bus-proxy: increase NOFILE limit

8 years agoMerge pull request #1141 from poettering/logind-fixes
Daniel Mack [Fri, 4 Sep 2015 10:13:45 +0000 (12:13 +0200)] 
Merge pull request #1141 from poettering/logind-fixes

Various logind fixes

8 years agobus-proxy: increase NOFILE limit 1142/head
David Herrmann [Fri, 4 Sep 2015 09:13:32 +0000 (11:13 +0200)] 
bus-proxy: increase NOFILE limit

The bus-proxy manages the kdbus connections of all users on the system
(regarding the system bus), hence, it needs an elevated NOFILE.
Otherwise, a single user can trigger ENFILE by opening NOFILE connections
to the bus-proxy.

Note that the bus-proxy still does per-user accounting, indirectly via
the proxy/fake API of kdbus. Hence, the effective per-user limit is not
raised by this. However, we now prevent one user from consuming the whole
FD limit of the shared proxy.

Also note that there is no *perfect* way to set this. The proxy is a
shared object, so it needs a larger NOFILE limit than the highest limit
of all users. This limit can be changed dynamically, though. Hence, we
cannot protect against it. However, a raised NOFILE limit is a privilege,
so we just treat it as such and basically allow these privileged users to
be able to consume more resources than normal users (and, maybe, cause
some limits to be exceeded by this).

Right now, kdbus hard-codes 1024 max connections per user on each bus.
However, we *must not* rely on this. This limits could be easily dropped
entirely, as the NOFILE limit is a suitable limit on its on.

8 years agologind: when parsing a boolean via sd-bus the type must be "int" 1141/head
Lennart Poettering [Fri, 4 Sep 2015 08:35:46 +0000 (10:35 +0200)] 
logind: when parsing a boolean via sd-bus the type must be "int"

And not bool.

8 years agologind: treat an empty wall message like a NULL one
Lennart Poettering [Fri, 4 Sep 2015 08:34:47 +0000 (10:34 +0200)] 
logind: treat an empty wall message like a NULL one

8 years agocgroups: delegation to unprivileged services is safe in the unified hierarchy
Lennart Poettering [Fri, 4 Sep 2015 07:23:07 +0000 (09:23 +0200)] 
cgroups: delegation to unprivileged services is safe in the unified hierarchy

Delegation to unpriviliged processes is safe in the unified hierarchy,
hence allow it. This has the benefit of permitting "systemd --user"
instances to further partition their resources between user services.

8 years agosd-login: rework error handling
Lennart Poettering [Fri, 4 Sep 2015 07:05:52 +0000 (09:05 +0200)] 
sd-login: rework error handling

Makre sure we always return sensible errors for the various, following
the same rules, and document them in a comment in sd-login.c. Also,
update all relevant man pages accordingly.

8 years agosd-event: make sure RT signals are not dropped
Lennart Poettering [Thu, 3 Sep 2015 18:13:09 +0000 (20:13 +0200)] 
sd-event: make sure RT signals are not dropped

RT signals operate in a queue, and we should be careful to never merge
two queued signals into one. Hence, makes sure we only ever dequeue a
single signal at a time and leave the remaining ones queued in the
signalfd. In order to implement correct priorities for the signals
introduce one signalfd per priority, so that we only process the highest
priority signal at a time.

8 years agotest: add one more test case for parse_pid()
Lennart Poettering [Thu, 3 Sep 2015 18:11:58 +0000 (20:11 +0200)] 
test: add one more test case for parse_pid()

8 years agonspawn: enable all controllers we can for the "payload" subcgroup we create
Lennart Poettering [Thu, 3 Sep 2015 18:10:00 +0000 (20:10 +0200)] 
nspawn: enable all controllers we can for the "payload" subcgroup we create

In the unified hierarchy delegating controller access is safe, hence
make sure to enable all controllers for the "payload" subcgroup if we
create it, so that the container will have all controllers enabled the
nspawn service itself has.

8 years agocgroup: always read the supported controllers from the root cgroup of the local container
Lennart Poettering [Thu, 3 Sep 2015 17:50:37 +0000 (19:50 +0200)] 
cgroup: always read the supported controllers from the root cgroup of the local container

Otherwise we might end up thinking that we support more controllers than
actually enabled for the container we are running in.

8 years agocgroup: fix potential access of uninitialized variable
Lennart Poettering [Thu, 3 Sep 2015 17:46:23 +0000 (19:46 +0200)] 
cgroup: fix potential access of uninitialized variable

8 years agocgroup-util: make cg_pid_get_path() return -ENODATA when controller can't be found
Lennart Poettering [Thu, 3 Sep 2015 17:44:02 +0000 (19:44 +0200)] 
cgroup-util: make cg_pid_get_path() return -ENODATA when controller can't be found

If the controller managed by systemd cannot found in /proc/$PID/cgroup,
return ENODATA, the usual error for cases where the data being looked
for does not exist, even if the process does.

8 years agocgroup: fix potential bad memory access
Lennart Poettering [Thu, 3 Sep 2015 17:43:15 +0000 (19:43 +0200)] 
cgroup: fix potential bad memory access

8 years agocgroup: make sure cg_is_empty_recursive() returns 1 for non-existing cgroups
Lennart Poettering [Thu, 3 Sep 2015 16:28:21 +0000 (18:28 +0200)] 
cgroup: make sure cg_is_empty_recursive() returns 1 for non-existing cgroups

Previously, on the legacy hierarchy a non-existing cgroup was considered
identical to an empty one, but the unified hierarchy the check for a
non-existing one returned ENOENT.

8 years agocgroup: when comparing agent paths, use path_equal()
Lennart Poettering [Thu, 3 Sep 2015 16:27:19 +0000 (18:27 +0200)] 
cgroup: when comparing agent paths, use path_equal()

After all a path is a path is a path and we should use path_equal() to
comapre those.

8 years agoaudit: audit calls should return ENODATA when process are not in an audit session
Lennart Poettering [Thu, 3 Sep 2015 16:24:57 +0000 (18:24 +0200)] 
audit: audit calls should return ENODATA when process are not in an audit session

ENODATA is how we usually indicate such "missing info" cases, so we
should do this here, too.

8 years agoutil: document why parse_uid() returns ENXIO
Lennart Poettering [Thu, 3 Sep 2015 16:23:26 +0000 (18:23 +0200)] 
util: document why parse_uid() returns ENXIO

parse_uid() returns EINVAL for invalid strings, but ENXIO for the
(uid_t) -1 user ids in order to distinguish these two cases. Document
this.

8 years agocore: split up manager_get_unit_by_pid()
Lennart Poettering [Thu, 3 Sep 2015 12:57:44 +0000 (14:57 +0200)] 
core: split up manager_get_unit_by_pid()

Let's move the actual cgroup part of it into a new separate function
manager_get_unit_by_pid_cgroup(), and then make
manager_get_unit_by_pid() just a wrapper that also checks the two pid
hashmaps.

Then, let's make sure the various calls that want to deliver events to
the owners of a PID check both hashmaps and the cgroup and deliver the
event to *each* of them. OTOH make sure bus calls like GetUnitByPID()
continue to check the PID hashmaps first and the cgroup only as
fallback.

8 years agocgroup: move controller to dirname translation into join_path_legacy()
Lennart Poettering [Thu, 3 Sep 2015 12:56:26 +0000 (14:56 +0200)] 
cgroup: move controller to dirname translation into join_path_legacy()

Let's simplify things a bit.

8 years agoutil: add new uid_is_valid() call
Lennart Poettering [Thu, 3 Sep 2015 11:29:53 +0000 (13:29 +0200)] 
util: add new uid_is_valid() call

This simply factors out the uid validation checks from parse_uid() and
uses them everywhere. This simply verifies that the passed UID is
neither 64bit -1 nor 32bit -1.

8 years agomacro: introduce new PID_TO_PTR macros and make use of them
Lennart Poettering [Thu, 3 Sep 2015 11:22:51 +0000 (13:22 +0200)] 
macro: introduce new PID_TO_PTR macros and make use of them

This adds a new PID_TO_PTR() macro, plus PTR_TO_PID() and makes use of
it wherever we maintain processes in a hash table. Previously we
sometimes used LONG_TO_PTR() and other times ULONG_TO_PTR() for that,
hence let's make this more explicit and clean up things.

8 years agoman: always use the same example in nss module documentation
Lennart Poettering [Thu, 3 Sep 2015 11:19:17 +0000 (13:19 +0200)] 
man: always use the same example in nss module documentation

Show the same recommended example file in all three man pages, just
highlight the different, relevant parts.

This should be less confusing for users, and clarify what we actually
recommend how /etc/nsswitch.conf is set up.

8 years agohwdb: Update database of Bluetooth company identifiers
Marcel Holtmann [Fri, 4 Sep 2015 00:51:50 +0000 (02:51 +0200)] 
hwdb: Update database of Bluetooth company identifiers

8 years agoudev: ignore ENOEXEC from cgroup lookup
David Herrmann [Thu, 3 Sep 2015 13:18:06 +0000 (15:18 +0200)] 
udev: ignore ENOEXEC from cgroup lookup

The recent cgroup-rework changed the error code for un-mounted cgroupfs to
ENOEXEC. Make sure udev ignores it just like ENOENT and does not spill
warnings on the screen.

8 years agoMerge pull request #1127 from neheb/master
Daniel Mack [Thu, 3 Sep 2015 10:35:48 +0000 (12:35 +0200)] 
Merge pull request #1127 from neheb/master

hwdb: Add Mionix Mouse

8 years agoMerge pull request #1134 from reverendhomer/patch-1
Lennart Poettering [Thu, 3 Sep 2015 09:22:19 +0000 (11:22 +0200)] 
Merge pull request #1134 from reverendhomer/patch-1

cgroup-util: Removed unreachable statement in cg_get_path

8 years agocg_get_path: Removed unreachable statement 1134/head
reverendhomer [Thu, 3 Sep 2015 08:34:47 +0000 (11:34 +0300)] 
cg_get_path: Removed unreachable statement

controller cannot be NULL because if-statement in L509 has return
Coverity #1322379

8 years agoMerge pull request #1123 from phomes/scope-no-bool-vs-int
Lennart Poettering [Wed, 2 Sep 2015 23:12:58 +0000 (01:12 +0200)] 
Merge pull request #1123 from phomes/scope-no-bool-vs-int

scope: do not compare a bool return with "<= 0"