]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
3 years agobash-completion: add systemd-cryptenroll support 23678/head
Antonio Alvarez Feijoo [Thu, 9 Jun 2022 09:47:10 +0000 (11:47 +0200)] 
bash-completion: add systemd-cryptenroll support

3 years agobash-completion: fix typos in comments
Antonio Alvarez Feijoo [Thu, 9 Jun 2022 09:46:50 +0000 (11:46 +0200)] 
bash-completion: fix typos in comments

3 years agoResolve conflicts between #23616 and the recent NFT additions
Zbigniew Jędrzejewski-Szmek [Thu, 9 Jun 2022 08:06:11 +0000 (10:06 +0200)] 
Resolve conflicts between #23616 and the recent NFT additions

3 years agoMerge pull request #23616 from keszybz/in-addr-to-string-formatting
Yu Watanabe [Thu, 9 Jun 2022 06:21:57 +0000 (15:21 +0900)] 
Merge pull request #23616 from keszybz/in-addr-to-string-formatting

Add macros that allocate a fixed buffer for in_addr_to_string(), in_addr_prefix+to_string()

3 years agohwdb: Add HP Dev One
Jeremy Soller [Wed, 8 Jun 2022 13:59:46 +0000 (07:59 -0600)] 
hwdb: Add HP Dev One

This enables the microphone mute and programmable hotkey for the HP Dev
One.

3 years agomeson: Add nspawn-locale meson option
Daan De Meyer [Fri, 3 Jun 2022 11:18:10 +0000 (13:18 +0200)] 
meson: Add nspawn-locale meson option

https://github.com/systemd/systemd/pull/23192 caused breakage in
Arch Linux's build tooling. Let's give users an opt-out aside from
reverting the patch. It's hardly any maintenance work on our side
and gives users an easy way to revert the locale change if needed.

Of course, by default we still pick C.UTF-8 if the option is not
specified.

3 years agoMerge pull request #23675 from enr0n/udev-available-cleanup
Yu Watanabe [Thu, 9 Jun 2022 03:12:01 +0000 (12:12 +0900)] 
Merge pull request #23675 from enr0n/udev-available-cleanup

Use udev_available() where appropriate

3 years agonspawn: use udev_available() 23675/head
Nick Rosbrook [Wed, 8 Jun 2022 19:53:45 +0000 (15:53 -0400)] 
nspawn: use udev_available()

3 years agolibsystemd-network: use udev_available()
Nick Rosbrook [Wed, 8 Jun 2022 19:53:30 +0000 (15:53 -0400)] 
libsystemd-network: use udev_available()

3 years agocifuzz: build fuzzers on i386 as well
Evgeny Vereshchagin [Sun, 29 May 2022 14:15:15 +0000 (14:15 +0000)] 
cifuzz: build fuzzers on i386 as well

It's a follow-up to https://github.com/systemd/systemd/pull/23550.

3 years agopo: Added translation using Weblate (Estonian)
H A [Wed, 8 Jun 2022 20:37:32 +0000 (22:37 +0200)] 
po: Added translation using Weblate (Estonian)

Co-authored-by: H A <contact+fedora@hen.ee>
3 years agocore: firewall integration with DynamicUserNFTSet=
Topi Miettinen [Sun, 22 May 2022 12:17:24 +0000 (15:17 +0300)] 
core: firewall integration with DynamicUserNFTSet=

New directive `DynamicUserNFTSet=` provides a method for integrating
configuration of dynamic users into firewall rules with NFT sets.

Example:
```
table inet filter {
        set u {
                typeof meta skuid
        }

        chain service_output {
                meta skuid != @u drop
                accept
        }
}
```

```
/etc/systemd/system/dunft.service
[Service]
DynamicUser=yes
DynamicUserNFTSet=inet:filter:u
ExecStart=/bin/sleep 1000

[Install]
WantedBy=multi-user.target
```

```
$ sudo nft list set inet filter u
table inet filter {
        set u {
                typeof meta skuid
                elements = { 64864 }
        }
}
$ ps -n --format user,group,pid,command -p `pgrep sleep`
    USER    GROUP     PID COMMAND
   64864    64864   55158 /bin/sleep 1000
```

3 years agocore: firewall integration with ControlGroupNFTSet=
Topi Miettinen [Sun, 22 May 2022 11:21:02 +0000 (14:21 +0300)] 
core: firewall integration with ControlGroupNFTSet=

New directive `ControlGroupNFTSet=` provides a method for integrating services
into firewall rules with NFT sets.

Example:

```
table inet filter {
...
        set timesyncd {
                type cgroupsv2
        }

        chain ntp_output {
                socket cgroupv2 != @timesyncd counter drop
                accept
        }
...
}
```

/etc/systemd/system/systemd-timesyncd.service.d/override.conf
```
[Service]
ControlGroupNFTSet=inet:filter:timesyncd
```

```
$ sudo nft list set inet filter timesyncd
table inet filter {
        set timesyncd {
                type cgroupsv2
                elements = { "system.slice/systemd-timesyncd.service" }
        }
}
```

3 years agonetwork: firewall integration with NFT sets
Topi Miettinen [Sun, 22 May 2022 11:09:06 +0000 (14:09 +0300)] 
network: firewall integration with NFT sets

New directives `NFTSet=`, `IPv4NFTSet=` and `IPv6NFTSet=` provide a method for
integrating configuration of dynamic networks into firewall rules with NFT
sets.

/etc/systemd/network/eth.network
```
[DHCPv4]
...
NFTSet=netdev:filter:eth_ipv4_address
```

```
table netdev filter {
        set eth_ipv4_address {
                type ipv4_addr
                flags interval
        }
        chain eth_ingress {
                type filter hook ingress device "eth0" priority filter; policy drop;
                ip saddr != @eth_ipv4_address drop
                accept
        }
}
```
```
sudo nft list set netdev filter eth_ipv4_address
table netdev filter {
        set eth_ipv4_address {
                type ipv4_addr
                flags interval
                elements = { 10.0.0.0/24 }
        }
}
```

3 years agoMerge pull request #23641 from keszybz/janitorials
Luca Boccassi [Wed, 8 Jun 2022 16:08:13 +0000 (17:08 +0100)] 
Merge pull request #23641 from keszybz/janitorials

Janitorial cleanups

3 years agobasic: Propagate SIGBUS signal info when re-raising signals
Daan De Meyer [Thu, 2 Jun 2022 13:32:44 +0000 (15:32 +0200)] 
basic: Propagate SIGBUS signal info when re-raising signals

raise() won't propagate the siginfo information of the signal that's
re-raised. rt_sigqueueinfo() allows us to provide the original siginfo
struct which makes sure it is propagated to the next signal handler
(or to the coredump).

3 years agobasic/socket-util: align tables 23641/head
Zbigniew Jędrzejewski-Szmek [Mon, 6 Jun 2022 10:33:42 +0000 (12:33 +0200)] 
basic/socket-util: align tables

3 years agoactivate: reduce scope of iterator variables
Zbigniew Jędrzejewski-Szmek [Mon, 6 Jun 2022 10:33:31 +0000 (12:33 +0200)] 
activate: reduce scope of iterator variables

3 years agocore: wrap some long comments
Zbigniew Jędrzejewski-Szmek [Fri, 20 May 2022 15:27:35 +0000 (17:27 +0200)] 
core: wrap some long comments

3 years agoshared/condition: reduce scope of variables
Zbigniew Jędrzejewski-Szmek [Fri, 20 May 2022 10:14:17 +0000 (12:14 +0200)] 
shared/condition: reduce scope of variables

3 years agobootctl: inline iterator variable
Zbigniew Jędrzejewski-Szmek [Wed, 11 May 2022 08:53:25 +0000 (10:53 +0200)] 
bootctl: inline iterator variable

3 years agoMerge pull request #23645 from DaanDeMeyer/journalctl-static-destructor
Daan De Meyer [Tue, 7 Jun 2022 11:28:37 +0000 (12:28 +0100)] 
Merge pull request #23645 from DaanDeMeyer/journalctl-static-destructor

journalctl: Use STATIC_DESTRUCTOR_REGISTER()

3 years agoMerge pull request #23643 from mrc0mmand/asan-tweaks
Frantisek Sumsal [Tue, 7 Jun 2022 11:19:11 +0000 (11:19 +0000)] 
Merge pull request #23643 from mrc0mmand/asan-tweaks

test: fix (not only) TEST-70 under sanitizers

3 years agomeson: adjust rootlibdir default for multiarch
Mike Gilbert [Tue, 7 Jun 2022 00:55:45 +0000 (20:55 -0400)] 
meson: adjust rootlibdir default for multiarch

On Debian, libdir is commonly something like 'lib/x86_64-linux-gnu'.

The result of get_option('libdir') is normalized to a prefix-relative
path by meson, so we can just append it to rootprefixdir.

Fixes https://github.com/systemd/systemd/issues/23648.

3 years agomeson: install libsystemd-shared into rootpkglibdir
Michael Biebl [Wed, 1 Jun 2022 06:23:02 +0000 (08:23 +0200)] 
meson: install libsystemd-shared into rootpkglibdir

Introduce rootpkglibdir for installing libsystemd-{shared,core}.so.
The benefit over using rootlibexecdir is that this path can be
multiarch aware, i.e. this path can be architecture qualified.

This is something we'd like to make use of in Debian/Ubuntu to make
libsystemd-shared co-installable, e.g. for i386 the path would be
/usr/lib/i386-linux-gnu/systemd/libsystemd-shared-*.so and for amd64
/usr/lib/x86_64-linux-gnu/systemd/libsystemd-shared-*.so.
This will allow for example to install and run systemd-boot/i386 on an
amd64 host. It also simplifies/enables cross-building/bootstrapping.

For more infos about Multi-Arch see https://wiki.debian.org/Multiarch.

See also https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990547

3 years agonetworkd: NetLabel integration
Topi Miettinen [Tue, 3 May 2022 20:43:00 +0000 (23:43 +0300)] 
networkd: NetLabel integration

New directive `NetLabel=` provides a method for integrating dynamic network
configuration into Linux NetLabel subsystem rules, used by Linux security
modules (LSMs) for network access control. The option expects a whitespace
separated list of NetLabel labels. The labels must conform to lexical
restrictions of LSM labels. When an interface is configured with IP addresses,
the addresses and subnetwork masks will be appended to the NetLabel Fallback
Peer Labeling rules. They will be removed when the interface is
deconfigured. Failures to manage the labels will be ignored.

Example:
```
[DHCP]
NetLabel=system_u:object_r:localnet_peer_t:s0
```

With the above rules for interface `eth0`, when the interface is configured with
an IPv4 address of 10.0.0.0/8, `systemd-networkd` performs the equivalent of
`netlabelctl` operation

```
$ sudo netlabelctl unlbl add interface eth0 address:10.0.0.0/8 label:system_u:object_r:localnet_peer_t:s0
```

Result:
```
$ sudo netlabelctl -p unlbl list
...
 interface: eth0
   address: 10.0.0.0/8
    label: "system_u:object_r:localnet_peer_t:s0"
...
```

3 years agohwdb: Add accel orientation quirk for the Aya Neo Next
Maccraft123 [Thu, 2 Jun 2022 18:05:22 +0000 (20:05 +0200)] 
hwdb: Add accel orientation quirk for the Aya Neo Next

3 years agoexecute: fix resource leak
Shreenidhi Shedi [Sat, 4 Jun 2022 09:54:08 +0000 (15:24 +0530)] 
execute: fix resource leak

CID#1431998

3 years agojournalctl: Use STATIC_DESTRUCTOR_REGISTER() 23645/head
Daan De Meyer [Mon, 6 Jun 2022 14:04:53 +0000 (16:04 +0200)] 
journalctl: Use STATIC_DESTRUCTOR_REGISTER()

3 years agoshared: Rename pcre2-dlopen.h/c to pcre2-util.h/c
Daan De Meyer [Mon, 6 Jun 2022 14:01:20 +0000 (16:01 +0200)] 
shared: Rename pcre2-dlopen.h/c to pcre2-util.h/c

We already store the dlopen() stuff for other libraries in util headers
as well so let's do the same for pcre2. We also move the definition of
some trivial cleanup functions from journalctl.c to pcre2-util.h

3 years agotest: fix TEST-70 under sanitizers 23643/head
Frantisek Sumsal [Mon, 6 Jun 2022 12:47:03 +0000 (14:47 +0200)] 
test: fix TEST-70 under sanitizers

Addresses:
  * https://github.com/systemd/systemd/issues/23578#issuecomment-1144089821
  * https://github.com/systemd/systemd-centos-ci/pull/496#issuecomment-1144640305

3 years agotest: set $ASAN_RT_PATH along with $LD_PRELOAD to the ASan runtime DSO
Frantisek Sumsal [Mon, 6 Jun 2022 12:45:11 +0000 (14:45 +0200)] 
test: set $ASAN_RT_PATH along with $LD_PRELOAD to the ASan runtime DSO

Since we unset $LD_PRELOAD in the testsuite-* units (due to another
issue), let's store the path to the ASan DSO in another env variable, so
we can easily access it in the testsuite scripts when needed.

3 years agoMerge pull request #23621 from evverx/clang-release
Zbigniew Jędrzejewski-Szmek [Mon, 6 Jun 2022 10:17:48 +0000 (12:17 +0200)] 
Merge pull request #23621 from evverx/clang-release

ci: build systemd with clang with -Dmode=release --optimization=2

3 years agovarious: use CONST_MAX for array allocation 23616/head
Zbigniew Jędrzejewski-Szmek [Sat, 4 Jun 2022 19:07:27 +0000 (21:07 +0200)] 
various: use CONST_MAX for array allocation

IIUC, with MAX() we get a VLA and the size is "decided" at runtime,
even though the result is always the same, but with CONST_MAX() we
get a normal stack variable.

3 years agoCODING_STYLE: say that inet_ntop() is a no no
Zbigniew Jędrzejewski-Szmek [Sat, 4 Jun 2022 18:56:29 +0000 (20:56 +0200)] 
CODING_STYLE: say that inet_ntop() is a no no

3 years agotree-wide: convert inet_ntop() calls to anonymous-buffer macros
Zbigniew Jędrzejewski-Szmek [Sat, 4 Jun 2022 15:01:06 +0000 (17:01 +0200)] 
tree-wide: convert inet_ntop() calls to anonymous-buffer macros

3 years agobasic/in-addr-util: add IN_ADDR_PREFIX_TO_STRING
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 14:37:38 +0000 (16:37 +0200)] 
basic/in-addr-util: add IN_ADDR_PREFIX_TO_STRING

3 years agobasic/in-addr-util: drop check for prefix length in formatting function
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 13:49:40 +0000 (15:49 +0200)] 
basic/in-addr-util: drop check for prefix length in formatting function

The general rule should be to be strict when parsing data, but lenient
when printing it. Or in other words, we should verify data in verification
functions, but not when printing things. It doesn't make sense to refuse
to print a value that we are using internally.

We were tripping ourselves in some of the print functions:
we want to report than an address was configured with too-long prefix, but
the log line would use "n/a" if the prefix was too long. This is not useful.

Most of the time, the removal of the check doesn't make any difference,
because we verified the prefix length on input.

3 years agolibsystemd-network: minor simplification
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 10:21:53 +0000 (12:21 +0200)] 
libsystemd-network: minor simplification

3 years agoresolved: use TAKE_PTR() in one more place
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 10:21:36 +0000 (12:21 +0200)] 
resolved: use TAKE_PTR() in one more place

3 years agonetworkctl: assume that we can always print local networking addresses
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 10:21:12 +0000 (12:21 +0200)] 
networkctl: assume that we can always print local networking addresses

IN6_ADDR_TO_STRING(…) always returns something, so we can simplify the code a
lot. Also, let's not do step-wise concatenation, but instead handle everything
with one str_extendf() call.

3 years agobasic/in-addr-util: add IN_ADDR_TO_STRING
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 09:24:02 +0000 (11:24 +0200)] 
basic/in-addr-util: add IN_ADDR_TO_STRING

Since we don't need the error value, and the buffer is allocated with a fixed
size, the whole logic provided by in_addr_to_string() becomes unnecessary, so
it's enough to wrap inet_ntop() directly.

inet_ntop() can only fail with ENOSPC. But we specify a buffer that is supposed
to be large enough, so this should never fail. A bunch of tests of this are added.
This allows all the wrappers like strna(), strnull(), strempty() to be dropped.

The guard of 'if (DEBUG_LOGGING)' can be dropped from around log_debug(),
because log_debug() implements the check outside of the function call. But
log_link_debug() does not, so it we need it to avoid unnecessary evaluation of
the formatting.

3 years agoMerge pull request #23626 from sshedi/retval-fixes
Zbigniew Jędrzejewski-Szmek [Mon, 6 Jun 2022 07:41:12 +0000 (09:41 +0200)] 
Merge pull request #23626 from sshedi/retval-fixes

Retval fixes

3 years agoRevert "Support -D_FORTIFY_SOURCE=3 by using __builtin_dynamic_object_size." 23621/head
Evgeny Vereshchagin [Fri, 3 Jun 2022 19:06:22 +0000 (19:06 +0000)] 
Revert "Support -D_FORTIFY_SOURCE=3 by using __builtin_dynamic_object_size."

This reverts commit 0bd292567a543d124cd303f7dd61169a209cae64.

It isn't guaranteed anywhere that __builtin_dynamic_object_size can
always deduce the size of every object passed to it so systemd
can end up using either malloc_usable_size or
__builtin_dynamic_object_size when pointers are passed around,
which in turn can lead to actual segfaults like the one mentioned in
https://github.com/systemd/systemd/issues/23619.

Apparently __builtin_object_size can return different results for
pointers referring to the same memory as well but somehow it hasn't
caused any issues yet. Looks like this whole
malloc_usable_size/FORTIFY_SOURCE stuff should be revisited.

Closes https://github.com/systemd/systemd/issues/23619 and
https://github.com/systemd/systemd/issues/23150.

Reopens https://github.com/systemd/systemd/issues/22801

3 years agomanager: ignore return value of unit_watch_pid() 23626/head
Shreenidhi Shedi [Sat, 4 Jun 2022 10:33:30 +0000 (16:03 +0530)] 
manager: ignore return value of unit_watch_pid()

Also, explicitly ignore return value of service_set_main_pid() calls in
few places.

Fixes: CID#1474975
3 years agomachinectl: ignore return value of get_process_comm()
Shreenidhi Shedi [Sat, 4 Jun 2022 10:26:45 +0000 (15:56 +0530)] 
machinectl: ignore return value of get_process_comm()

Fixes: CID#1469720
3 years agopolkit: explicitly ignore fd_wait_for_event()'s return value
Shreenidhi Shedi [Sat, 4 Jun 2022 10:18:09 +0000 (15:48 +0530)] 
polkit: explicitly ignore fd_wait_for_event()'s return value

Fixes: CID#1469718
3 years agoci: build systemd with clang with -Dmode=release --optimization=2
Evgeny Vereshchagin [Fri, 3 Jun 2022 18:16:57 +0000 (18:16 +0000)] 
ci: build systemd with clang with -Dmode=release --optimization=2

This is what's most likely used to build systemd with clang in
practice so let's test it as well.

Preparation for reverting https://github.com/systemd/systemd/commit/0bd292567a543d124cd303f7dd61169a209cae64
(which replaced bogus buffer overflow found with _FORTIFY_SOURCE=3
with actual segfaults).

3 years agoshared/microhttp-util: silence gcc warning
Zbigniew Jędrzejewski-Szmek [Sun, 5 Jun 2022 08:24:15 +0000 (10:24 +0200)] 
shared/microhttp-util: silence gcc warning

../src/journal-remote/microhttpd-util.c: In function ‘check_permissions’:
../src/journal-remote/microhttpd-util.c:301:5: error: function might be candidate for attribute ‘noreturn’ [-Werror=suggest-attribute=noreturn]
  301 | int check_permissions(struct MHD_Connection *connection, int *code, char **hostname) {
      |     ^~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors

Fixes #23630.

3 years agomeson: Switch default-locale default to C.UTF-8
Daan De Meyer [Fri, 3 Jun 2022 11:29:47 +0000 (13:29 +0200)] 
meson: Switch default-locale default to C.UTF-8

We're already using C.UTF-8 as the default locale for nspawn. Let's
make the same change for the default-locale option instead of deciding
what to use based on the locale used by the host system. Users can
still override the locale using the default-locale option if needed.

3 years agocore: suppress message about missing libbpf if in initrd()
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 14:45:47 +0000 (16:45 +0200)] 
core: suppress message about missing libbpf if in initrd()

It is quite likely that libbpf is not present in the initrd, and
there isn't much reason to use the bpf filters there.

https://bugzilla.redhat.com/show_bug.cgi?id=2084955#c25

3 years agocryptenroll: fix typo
Antonio Alvarez Feijoo [Fri, 3 Jun 2022 15:09:23 +0000 (17:09 +0200)] 
cryptenroll: fix typo

3 years agoMerge pull request #23297 from medhefgo/trivial-auto-var-init
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 13:27:51 +0000 (15:27 +0200)] 
Merge pull request #23297 from medhefgo/trivial-auto-var-init

meson: Compile with -ftrivial-auto-var-init

3 years agotest: add dlopen test for pam_systemd_home
Yu Watanabe [Thu, 2 Jun 2022 21:40:43 +0000 (06:40 +0900)] 
test: add dlopen test for pam_systemd_home

3 years agosha256: fix compilation on efi-ia32
Zbigniew Jędrzejewski-Szmek [Fri, 3 Jun 2022 07:32:02 +0000 (09:32 +0200)] 
sha256: fix compilation on efi-ia32

/usr/bin/gcc -c ../src/fundamental/sha256.c -o src/boot/efi/sha256.c.o -Wno-format-signedness -Wno-missing-field-initializers -Wno-unused-parameter -Wdate-time -Wendif-labels -Werror=format=2 -Werror=implicit-function-declaration -Werror=incompatible-pointer-types -Werror=int-conversion -Werror=overflow -Werror=override-init -Werror=return-type -Werror=shift-count-overflow -Werror=shift-overflow=2 -Werror=undef -Wfloat-equal -Wimplicit-fallthrough=5 -Winit-self -Wlogical-op -Wmissing-include-dirs -Wmissing-noreturn -Wnested-externs -Wold-style-definition -Wpointer-arith -Wredundant-decls -Wshadow -Wstrict-aliasing=2 -Wstrict-prototypes -Wsuggest-attribute=noreturn -Wunused-function -Wwrite-strings -Wno-unused-result -fno-stack-protector -fno-strict-aliasing -fpic -fwide-exec-charset=UCS2 -Wall -Wextra -Wsign-compare -nostdlib -std=gnu99 -ffreestanding -fshort-wchar -fvisibility=hidden -isystem /usr/include/efi -isystem /usr/include/efi/ia32 -I /builddir/build/BUILD/systemd-stable-250.7/src/fundamental -DSD_BOOT -DGNU_EFI_USE_MS_ABI -include src/boot/efi/efi_config.h -include version.h -mno-sse -mno-mmx -flto -O2 -flto=auto
../src/fundamental/sha256.c: In function ‘sha256_finish_ctx’:
../src/fundamental/sha256.c:61:25: error: ‘false’ undeclared (first use in this function)
   61 | # define UNALIGNED_P(p) false
      |                         ^~~~~
../src/fundamental/sha256.c:136:21: note: in expansion of macro ‘UNALIGNED_P’
  136 |                 if (UNALIGNED_P(resbuf))
      |                     ^~~~~~~~~~~
../src/fundamental/sha256.c:32:1: note: ‘false’ is defined in header ‘<stdbool.h>’; did you forget to ‘#include <stdbool.h>’?
   31 | #include "sha256.h"
  +++ |+#include <stdbool.h>
   32 |
...

3 years agoMerge pull request #23583 from yuwata/boot-efi-string-follow-ups
Yu Watanabe [Fri, 3 Jun 2022 01:23:24 +0000 (10:23 +0900)] 
Merge pull request #23583 from yuwata/boot-efi-string-follow-ups

boot: follow-ups for efi-string functions

3 years agoshared/utmp-wtmp: fix build without utmp
Christian Hesse [Thu, 2 Jun 2022 18:49:46 +0000 (20:49 +0200)] 
shared/utmp-wtmp: fix build without utmp

Commit 16618332388442f2f1c3e52b0a9fde00121564a3 changed a function to
add an extra argument. The data types used when building without utmp
missed the change.

3 years agologin: fix typo
Yu Watanabe [Thu, 2 Jun 2022 19:27:40 +0000 (04:27 +0900)] 
login: fix typo

Follow-up for ea74f39c24344eafc238d1c69155bd5aca5f2e08.

3 years agoboot: use CMP() macro for safety 23583/head
Yu Watanabe [Tue, 31 May 2022 21:36:55 +0000 (06:36 +0900)] 
boot: use CMP() macro for safety

3 years agoboot: make several functions inline
Yu Watanabe [Tue, 31 May 2022 21:25:52 +0000 (06:25 +0900)] 
boot: make several functions inline

Follow-ups for #23512.

3 years agoboot: fix typo
Yu Watanabe [Tue, 31 May 2022 21:48:45 +0000 (06:48 +0900)] 
boot: fix typo

3 years agoMerge pull request #23596 from keszybz/bpf-messages-more
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 17:48:01 +0000 (19:48 +0200)] 
Merge pull request #23596 from keszybz/bpf-messages-more

Silence messages from libbpf

3 years agotest: enable virtio-rng device for QEMU guests
Franck Bui [Thu, 2 Jun 2022 07:31:55 +0000 (09:31 +0200)] 
test: enable virtio-rng device for QEMU guests

If rngd is included in the host initrd, QEMU guests need at least one source of
entropy otherwise rngd will refuse to start. Hence this patch enables the
virtio RNG device in QEMU guests (exposed as a HW RNG device available at
/dev/hwrng).

As a safety measure, the patch limits the data sent to the guest to 1KB per
second in order to not let the guest starve the host entropy.

3 years agocore: rework variable initialization to avoid gcc warning 23297/head
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 15:30:35 +0000 (17:30 +0200)] 
core: rework variable initialization to avoid gcc warning

In file included from ../src/basic/siphash24.h:11,
                 from ../src/basic/hash-funcs.h:6,
                 from ../src/basic/hashmap.h:8,
                 from ../src/shared/fdset.h:6,
                 from ../src/shared/bpf-program.h:9,
                 from ../src/core/unit.h:11,
                 from ../src/core/all-units.h:4,
                 from ../src/core/manager.c:23:
../src/basic/time-util.h: In function 'manager_dispatch_jobs_in_progress':
../src/basic/time-util.h:140:38: error: 'x' may be used uninitialized [-Werror=maybe-uninitialized]
  140 | #define FORMAT_TIMESPAN(t, accuracy) format_timespan((char[FORMAT_TIMESPAN_MAX]){}, FORMAT_TIMESPAN_MAX, t, accuracy)
      |                                      ^~~~~~~~~~~~~~~
In function 'manager_print_jobs_in_progress',
    inlined from 'manager_dispatch_jobs_in_progress' at ../src/core/manager.c:3007:9:
../src/core/manager.c:219:18: note: 'x' was declared here
  219 |         uint64_t x;
      |                  ^
cc1: all warnings being treated as errors

For some reason this (false positive) warning starts appearing after
-ftrivial-auto-var-init is used.

3 years agoMerge pull request #23576 from yuwata/network-erspan-version
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 14:58:55 +0000 (16:58 +0200)] 
Merge pull request #23576 from yuwata/network-erspan-version

network: support erspan version 0 and 2

3 years agoMerge pull request #23579 from yuwata/sha256-unaligned
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 14:38:19 +0000 (16:38 +0200)] 
Merge pull request #23579 from yuwata/sha256-unaligned

sha256: use memcpy() to accept unaligned result buffer

3 years agoman: add missing arguments to systemd-creds synopsis
Antonio Alvarez Feijoo [Thu, 2 Jun 2022 13:58:33 +0000 (15:58 +0200)] 
man: add missing arguments to systemd-creds synopsis

3 years agoMerge pull request #23582 from bnf/dns-proxy-stub-ifindex
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 14:34:55 +0000 (16:34 +0200)] 
Merge pull request #23582 from bnf/dns-proxy-stub-ifindex

resolved: define source address for proxy-only stub replies

3 years agocore/bpf: prefix log messages from different bpf subsystems 23596/head
Zbigniew Jędrzejewski-Szmek [Thu, 2 Jun 2022 09:15:35 +0000 (11:15 +0200)] 
core/bpf: prefix log messages from different bpf subsystems

When something goes awry, we would get identical log messages from all the
bpf subsystems. E.g. "Failed to load BPF object: %m" appeared 5 times in the
sources. But it is very important to know *which* object we failed to load.
This could be guessed, e.g. from surroudning messages or from filename/line
metadata, but when we get log messages in bug reports, this might not be
available. Let's make the messages distinguishable.

While at it, some messages were adjusted a bit. In particular, we shouldn't use
internal names like BPFProgram which have no meaning outside of the codebase.

3 years agocore: define a helper function for basic bpf checks
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 21:56:25 +0000 (23:56 +0200)] 
core: define a helper function for basic bpf checks

3 years agotest-socket-bind: fix comment
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 22:40:33 +0000 (00:40 +0200)] 
test-socket-bind: fix comment

3 years agotests: drop pointless checks for root
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 22:38:14 +0000 (00:38 +0200)] 
tests: drop pointless checks for root

Testing the error paths is very important. If we are not root, we should
try and get a failure, which we should report nicely and mark the test
as skipped. After those checks are removed, this is what seems to happen.
This way we can see what will happen e.g. in the user manager when we try
to perform some bpf ops.

3 years agoshared/bpf: install log callback and suppress most messages from libbpf
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 22:27:52 +0000 (00:27 +0200)] 
shared/bpf: install log callback and suppress most messages from libbpf

$ build/test-socket-bind
...
libbpf: load bpf program failed: Operation not permitted
libbpf: failed to load program 'sd_bind4'
libbpf: failed to load object 'socket_bind_bpf'
libbpf: failed to load BPF skeleton 'socket_bind_bpf': -1
Failed to load BPF object: Operation not permitted

Now all lines with "libbpf:" are at debug level and will be hidden by
default.

Partially fixes https://bugzilla.redhat.com/show_bug.cgi?id=2084955#c14
(i.e. the error that was exposed when the initial error was fixed.)

3 years agomeson: use files() for libcore_sources too
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 21:58:28 +0000 (23:58 +0200)] 
meson: use files() for libcore_sources too

C.f. f1b98127ff6320648cc3dc876f3b6a5aa3af204b.

3 years agouserwork: use a better errno value
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 15:49:58 +0000 (17:49 +0200)] 
userwork: use a better errno value

ESRCH is literally "No such process".

3 years agovarious: add %m in messages
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 15:49:27 +0000 (17:49 +0200)] 
various: add %m in messages

Sometimes we want to suppress strerror() message because the are providing
something better. But in those cases, it seems it was just forgotten.

3 years agotest: fix indentation 23579/head
Yu Watanabe [Thu, 2 Jun 2022 05:14:12 +0000 (14:14 +0900)] 
test: fix indentation

3 years agotest: add test for sha256
Yu Watanabe [Thu, 2 Jun 2022 05:12:20 +0000 (14:12 +0900)] 
test: add test for sha256

3 years agosha256: use memcpy() when result buffer is unaligned
Yu Watanabe [Tue, 31 May 2022 17:31:10 +0000 (02:31 +0900)] 
sha256: use memcpy() when result buffer is unaligned

Fixes #23578.

3 years agoDocuments the AssertCPUFeature= flag (#23594)
Steve Ramage [Thu, 2 Jun 2022 04:16:48 +0000 (21:16 -0700)] 
Documents the AssertCPUFeature= flag (#23594)

Fixes #23593

3 years agoMove basic/recovery-key.* to shared/
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 09:34:05 +0000 (11:34 +0200)] 
Move basic/recovery-key.* to shared/

No particular reason to have it in basic/. We should let homectl
and other users share the single copy through libsystemd-shared.

3 years agoMerge pull request #23575 from keszybz/logind-wall-message-cleanup
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 14:26:29 +0000 (16:26 +0200)] 
Merge pull request #23575 from keszybz/logind-wall-message-cleanup

Cleanup wall messages emitted by logind and systemctl

3 years agoMerge pull request #23574 from keszybz/logind-pty-wall
Zbigniew Jędrzejewski-Szmek [Wed, 1 Jun 2022 14:26:03 +0000 (16:26 +0200)] 
Merge pull request #23574 from keszybz/logind-pty-wall

Do not print logind wall message to local terminals

3 years agoresolved: choose correct file descriptor for proxy stub replies 23582/head
Benjamin Franzke [Wed, 1 Jun 2022 12:40:51 +0000 (14:40 +0200)] 
resolved: choose correct file descriptor for proxy stub replies

find_socket_fd() does not expect the sender address, but the
listen-address. This is in fact the destination of the DNS packet.
Matching via sender address caused a fallback to the default stub
listener in manager_dns_stub_fd() as the sender address can never
match the proxy stub listen address.

Note that manager_dns_stub_fd() is only used for the default
listener stub and the proxy stub, that means *extra* listeners
stubs (DNSStubListenerExtra=…) have not been affected as
`struct DnsStubListenerExtra` provides a direct link to the event
source.

By using the correct fd we ensure the correct socket options
(like TTL) are used and prevent issues like #23495 in case ifindex
could not be determined.

3 years agobuild(deps): bump actions/upload-artifact from 2.3.1 to 3.1.0
dependabot[bot] [Wed, 1 Jun 2022 10:27:03 +0000 (10:27 +0000)] 
build(deps): bump actions/upload-artifact from 2.3.1 to 3.1.0

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 2.3.1 to 3.1.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/82c141cc518b40d92cc801eee768e7aafc9c2fa2...3cea5372237819ed00197afe530f5a7ea3e805c8)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
3 years agobuild(deps): bump github/super-linter from 4.9.3 to 4.9.4
dependabot[bot] [Wed, 1 Jun 2022 10:26:55 +0000 (10:26 +0000)] 
build(deps): bump github/super-linter from 4.9.3 to 4.9.4

Bumps [github/super-linter](https://github.com/github/super-linter) from 4.9.3 to 4.9.4.
- [Release notes](https://github.com/github/super-linter/releases)
- [Changelog](https://github.com/github/super-linter/blob/main/docs/release-process.md)
- [Commits](https://github.com/github/super-linter/compare/431ee7836e8cdce5a460b0db682d9169563d919b...a320804d310fdeb8d1a46c6c6c1e615d443b10c9)

---
updated-dependencies:
- dependency-name: github/super-linter
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
3 years agosrc: The return value of server_vacuum () is not used and could be modified to void...
Li kunyu [Wed, 18 May 2022 06:52:43 +0000 (14:52 +0800)] 
src: The return value of server_vacuum () is not used and could be modified to void type

3 years agologin: do not issue wall messages on local terminals for suspend and hibernate 23574/head
Christian Göttsche [Fri, 27 May 2022 11:47:23 +0000 (13:47 +0200)] 
login: do not issue wall messages on local terminals for suspend and hibernate

Fixes: #23520
[zjs: I added the comment and tweaked the patch a bit.

The call to reset_scheduled_shutdown() is moved down a bit to allow the
callback to have access to information about the operation being cancelled.
This all happens within the same function, so there should be no observable
change in behaviour.]

3 years agoshared/pager: print the name of the pager we'll try next in debug message 23575/head
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 08:59:12 +0000 (10:59 +0200)] 
shared/pager: print the name of the pager we'll try next in debug message

I had a strange failure where the pager was hanging on invocation (gdm crashed
and the kernel got into a strange state where it was hanging on some tasks).
Based on the logs from 'SYSTEMCTL_LOG_LEVEL=debug journalctl', I couldn't even
tell which pager binary we're executing. So let's shorten the function a bit and
provide a bit more detail.

3 years agoman/systemctl: improve grammar in description of --check-inhibitors
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 08:30:09 +0000 (10:30 +0200)] 
man/systemctl: improve grammar in description of --check-inhibitors

3 years agosystemctl: drop translation of method names to descriptions in error message
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 07:49:29 +0000 (09:49 +0200)] 
systemctl: drop translation of method names to descriptions in error message

We had yet-another table of descriptive strings to use in error messages.
I started thinking how to synchronize them with the strings in logind, but
ultimately I think it's better to remove those altogether. Those strings
should almost never be used: normally if the call fails, logind will provide
an error message itself, which is probably more detailed than what we can
figure out on the client side. And the most important part that we want to
show here is what exactly we called, in particular RebootWithFlags vs. Reboot,
etc. By using the "descriptive strings" we were obfuscating this. So let's just
simplify our code and print the actual method name, since this is more useful
as an error statement that is googlable and unique.

While at it, let's print the correct method name ;)

3 years agosystemctl: make function static
Zbigniew Jędrzejewski-Szmek [Mon, 30 May 2022 10:38:58 +0000 (12:38 +0200)] 
systemctl: make function static

3 years agologind: reduce scope of a few variables
Zbigniew Jędrzejewski-Szmek [Mon, 30 May 2022 12:34:05 +0000 (14:34 +0200)] 
logind: reduce scope of a few variables

3 years agologind: rework wall message about pending shutdown/halt/reboot/…
Zbigniew Jędrzejewski-Szmek [Mon, 30 May 2022 10:08:41 +0000 (12:08 +0200)] 
logind: rework wall message about pending shutdown/halt/reboot/…

Those messages simply *feel* dated: "The system is going for suspend NOW!".
Let's say "The system will suspend|power off|hibernate|… now!" instead.
The exclamation mark is enough to show the urgency.

Also, the "the" seemed out of place. We're not talking about a specific reboot.

3 years agoMerge pull request #23531 from yuwata/sd-bus-drop-version-2
Yu Watanabe [Wed, 1 Jun 2022 05:51:44 +0000 (14:51 +0900)] 
Merge pull request #23531 from yuwata/sd-bus-drop-version-2

sd-bus: drop version 2 format support

3 years agoMerge pull request #23512 from medhefgo/efi-clang
Yu Watanabe [Tue, 31 May 2022 21:16:48 +0000 (06:16 +0900)] 
Merge pull request #23512 from medhefgo/efi-clang

boot: Add string functions

3 years agoresolved: define source address for proxy-only stub replies
Benjamin Franzke [Tue, 31 May 2022 19:36:55 +0000 (21:36 +0200)] 
resolved: define source address for proxy-only stub replies

DnsPacket.ifindex=1 (loopback) is normalized to 0 whenever a message is
received on the loopback iface, so for both listeners, 127.0.0.53 and
127.0.0.54, the ifindex will be set to 0 by manager_recv() for queries
that have a local origin.

Replies to such local messages need to set a proper ifindex in any
case, as the supplied source-address would otherwise be ignored in
manager_ipv4_send() (CMSG generation is skipped due to ifindex > 0 check).

Note that this change only forces `ifindex` to loopback if it was actually
normalized to `0` before (due to a loopback detection) in order to keep the
nat-to-127.0.0.54-from-another-interface usecase that was described in
a8d09063447568d87288a8e868fe386c1da7ce09 intact.
Also note that nat is not supported for the main stub 127.0.0.53 which is
why forcing LOOPBACK_IFINDEX was/is fine for that case.

Fixes #23495

3 years agologind: do not print wall messages to local pseudoterminals
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 13:17:52 +0000 (15:17 +0200)] 
logind: do not print wall messages to local pseudoterminals

Fixes #23520. Replaces #23555.

The problem started with cdf370626f08ed509a5dde9d5618eed29d625032 and
90b1ec03b2ce939f589239133a32f4429f2ad6a6 which together started printing the
wall message in more cases. The motivation for those change was reasonable, but
this clearly causes problems described in #23520: users are getting unexpected
wall messages. Xterm, urxvt, (anything using libutempter?), and tmux (in some
configurations), register local pty sessions in utmp.

So let's try to suppress the message for local pseudo-terminal logins. This
patch based on #23538, but instead of filtering just on /dev/pts, it uses the
.ut_addr_v6 to only filter out local entries.

3 years agotests: add a helper that dumps /run/utmp in detail
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2022 13:23:35 +0000 (15:23 +0200)] 
tests: add a helper that dumps /run/utmp in detail

utmpdump doesn't print all the details. Looking at the list if useful
when trying to tweak the wall filtering logic.

This doesn't do much, but at least it serves as a smoke test for the cleanup
functions.

3 years agotest-network: call networkctl only when specified interface exists 23576/head
Yu Watanabe [Tue, 31 May 2022 19:01:10 +0000 (04:01 +0900)] 
test-network: call networkctl only when specified interface exists

Otherwise, this easily trigger another exception:
```
======================================================================
ERROR: test_erspan_tunnel_v0 (__main__.NetworkdNetDevTests)
----------------------------------------------------------------------
Traceback (most recent call last):
  File "./test/test-network/systemd-networkd-tests.py", line 686, in wait_online
    check_output(*args, env=env)
  File "./test/test-network/systemd-networkd-tests.py", line 65, in check_output
    return subprocess.check_output(command, universal_newlines=True, **kwargs).rstrip()
  File "/usr/lib64/python3.6/subprocess.py", line 356, in check_output
    **kwargs).stdout
  File "/usr/lib64/python3.6/subprocess.py", line 438, in run
    output=stdout, stderr=stderr)
subprocess.CalledProcessError: Command '['/usr/lib/systemd/systemd-networkd-wait-online', '--timeout=20s', '--interface=erspan99:routable', '--interface=erspan98:routable', '--interface=dummy98:degraded']' returned non-zero exit status 1.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "./test/test-network/systemd-networkd-tests.py", line 1808, in test_erspan_tunnel_v0
    self.wait_online(['erspan99:routable', 'erspan98:routable', 'dummy98:degraded'])
  File "./test/test-network/systemd-networkd-tests.py", line 689, in wait_online
    output = check_output(*networkctl_cmd, '-n', '0', 'status', link.split(':')[0], env=env)
  File "./test/test-network/systemd-networkd-tests.py", line 65, in check_output
    return subprocess.check_output(command, universal_newlines=True, **kwargs).rstrip()
  File "/usr/lib64/python3.6/subprocess.py", line 356, in check_output
    **kwargs).stdout
  File "/usr/lib64/python3.6/subprocess.py", line 438, in run
    output=stdout, stderr=stderr)
subprocess.CalledProcessError: Command '['/usr/bin/networkctl', '-n', '0', 'status', 'erspan99']' returned non-zero exit status 1.
```