]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
2 years agorepart: Add ExcludeFiles= option 26437/head
Daan De Meyer [Thu, 16 Feb 2023 12:23:47 +0000 (13:23 +0100)] 
repart: Add ExcludeFiles= option

2 years agorepart: Make config_parse_copy_files() more generic
Daan De Meyer [Thu, 16 Feb 2023 11:45:13 +0000 (12:45 +0100)] 
repart: Make config_parse_copy_files() more generic

2 years agomkosi: Enable debug logging in CI
Daan De Meyer [Wed, 15 Feb 2023 10:16:28 +0000 (11:16 +0100)] 
mkosi: Enable debug logging in CI

"Failed to dissect image: connection timed out" messages have been
appearing sporadically in mkosi CI. Let's enable debug logging to
help figure out why.

2 years agojournalctl: actually run the static destructors
Frantisek Sumsal [Wed, 15 Feb 2023 17:08:35 +0000 (18:08 +0100)] 
journalctl: actually run the static destructors

In journalctl we don't run the static destructors defined via
the STATIC_DESTRUCTOR_REGISTER() macro, since it requires a corresponding
static_destruct() call. In most cases this is handled by
the DEFINE_(TEST_)?MAIN*() macros, but journalctl defines its own main
function, so let's handle that as well.

$ valgrind --suppressions=valgrind.supp --show-leak-kinds=all --leak-check=full build/journalctl --no-pager -u system.slice -n 10 >/dev/null
==2778093== Memcheck, a memory error detector
==2778093== Copyright (C) 2002-2022, and GNU GPL'd, by Julian Seward et al.
==2778093== Using Valgrind-3.19.0 and LibVEX; rerun with -h for copyright info
==2778093== Command: build/journalctl --no-pager -u system.slice -n 10
==2778093==
==2778093==
==2778093== HEAP SUMMARY:
==2778093==     in use at exit: 8,221 bytes in 4 blocks
==2778093==   total heap usage: 458 allocs, 454 frees, 255,182 bytes allocated
==2778093==
==2778093== 13 bytes in 1 blocks are still reachable in loss record 1 of 4
==2778093==    at 0x484586F: malloc (vg_replace_malloc.c:381)
==2778093==    by 0x4DA256D: strdup (strdup.c:42)
==2778093==    by 0x4ADB747: strv_extend_with_size (strv.c:544)
==2778093==    by 0x405386: strv_extend (strv.h:45)
==2778093==    by 0x40816F: parse_argv (journalctl.c:933)
==2778093==    by 0x40EAB5: main (journalctl.c:2111)
==2778093==
==2778093== 16 bytes in 1 blocks are still reachable in loss record 2 of 4
==2778093==    at 0x484578A: malloc (vg_replace_malloc.c:380)
==2778093==    by 0x484A70B: realloc (vg_replace_malloc.c:1437)
==2778093==    by 0x4ADB2A3: strv_push_with_size (strv.c:423)
==2778093==    by 0x4ADB620: strv_consume_with_size (strv.c:496)
==2778093==    by 0x4ADB770: strv_extend_with_size (strv.c:548)
==2778093==    by 0x405386: strv_extend (strv.h:45)
==2778093==    by 0x40816F: parse_argv (journalctl.c:933)
==2778093==    by 0x40EAB5: main (journalctl.c:2111)
==2778093==
==2778093== LEAK SUMMARY:
==2778093==    definitely lost: 0 bytes in 0 blocks
==2778093==    indirectly lost: 0 bytes in 0 blocks
==2778093==      possibly lost: 0 bytes in 0 blocks
==2778093==    still reachable: 29 bytes in 2 blocks
==2778093==         suppressed: 8,192 bytes in 2 blocks
==2778093==
==2778093== For lists of detected and suppressed errors, rerun with: -s
==2778093== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0)

2 years agoresolved: Fall back to TCP if UDP is blocked
Joan Bruguera [Sun, 12 Feb 2023 20:06:08 +0000 (20:06 +0000)] 
resolved: Fall back to TCP if UDP is blocked

If UDP is blocked on the system (e.g. by iptables or BPF), the kernel will
return EPERM on some or all of the system calls (connect, sendmsg, etc.).
In this case, try to fall back to TCP, which hopefully will not be blocked.

2 years agocore: add support for Startup memory limits
Luca Boccassi [Mon, 6 Feb 2023 14:13:09 +0000 (14:13 +0000)] 
core: add support for Startup memory limits

We support separate Startup configurations for CPU and I/O, so
add it for memory too. Only cover cgroupsv2 settings.

2 years agovconsole: allow setting default keymap through build option
Mike Yuan [Tue, 17 Jan 2023 17:21:59 +0000 (01:21 +0800)] 
vconsole: allow setting default keymap through build option

Allow defining the default keymap to be used by
vconsole-setup through a build option. A template
vconsole.conf also gets populated by tmpfiles if
it doesn't exist.

2 years agojournal: cat: set JOURNAL_STREAM before exec-ing
Mike Yuan [Tue, 7 Feb 2023 16:21:33 +0000 (00:21 +0800)] 
journal: cat: set JOURNAL_STREAM before exec-ing

Make the behavior of systemd-cat match
that of core/execute.

Closes #25880

2 years agoMerge pull request #26307 from yuwata/test-execute-credentials
Luca Boccassi [Wed, 15 Feb 2023 19:59:28 +0000 (19:59 +0000)] 
Merge pull request #26307 from yuwata/test-execute-credentials

test-execute: drop capabilities when testing with user manager

2 years agoMerge pull request #26213 from poettering/journal-rework-seqnum
Luca Boccassi [Wed, 15 Feb 2023 19:58:58 +0000 (19:58 +0000)] 
Merge pull request #26213 from poettering/journal-rework-seqnum

journal sequence number rework

2 years agoMerge pull request #26410 from DaanDeMeyer/xattr-symlink
Luca Boccassi [Wed, 15 Feb 2023 19:55:04 +0000 (19:55 +0000)] 
Merge pull request #26410 from DaanDeMeyer/xattr-symlink

Copy symlink xattrs

2 years agoNEWS: finalize v253
Luca Boccassi [Wed, 15 Feb 2023 18:11:21 +0000 (18:11 +0000)] 
NEWS: finalize

2 years agoMerge pull request #26427 from bluca/hwdb
Luca Boccassi [Wed, 15 Feb 2023 19:08:36 +0000 (19:08 +0000)] 
Merge pull request #26427 from bluca/hwdb

Update news and hwdb

2 years agohwdb: update 26427/head
Luca Boccassi [Wed, 15 Feb 2023 18:05:43 +0000 (18:05 +0000)] 
hwdb: update

2 years agoNEWS: update contributors list
Luca Boccassi [Wed, 15 Feb 2023 18:03:15 +0000 (18:03 +0000)] 
NEWS: update contributors list

2 years agocryptsetup: do not assert when unsealing token without salt
Luca Boccassi [Wed, 15 Feb 2023 00:44:01 +0000 (00:44 +0000)] 
cryptsetup: do not assert when unsealing token without salt

Salt was added in v253. We are not checking whether it was actually found
(non-zero size), so when an old tpm+pin enrollment is opened things go boom.
For good measure, check both the buffer and the size in both places.

Assertion 'saltlen > 0' failed at src/shared/tpm2-util.c:2490, function tpm2_util_pbkdf2_hmac_sha256(). Aborting.

2 years agoukify: fix padding length
Yu Watanabe [Wed, 15 Feb 2023 16:59:08 +0000 (01:59 +0900)] 
ukify: fix padding length

2 years agoMerge pull request #26417 from yuwata/sysusers-root-group
Luca Boccassi [Wed, 15 Feb 2023 17:03:59 +0000 (17:03 +0000)] 
Merge pull request #26417 from yuwata/sysusers-root-group

sysusers: also create root group

2 years agoMerge pull request #26424 from ldv-alt/fix-typos
Yu Watanabe [Wed, 15 Feb 2023 15:10:18 +0000 (00:10 +0900)] 
Merge pull request #26424 from ldv-alt/fix-typos

Fix a few typos in NEWS, docs and comments

2 years agoman/tc: Fix hexadecimals being with an O
Raul Tambre [Wed, 15 Feb 2023 14:21:21 +0000 (16:21 +0200)] 
man/tc: Fix hexadecimals being with an O

2 years agotreewide: fix a few typos in NEWS, docs and comments 26424/head
Dmitry V. Levin [Wed, 15 Feb 2023 08:00:00 +0000 (08:00 +0000)] 
treewide: fix a few typos in NEWS, docs and comments

2 years agoNEWS: mention that the default mDNS mode is now "yes"
Yu Watanabe [Wed, 15 Feb 2023 10:17:54 +0000 (19:17 +0900)] 
NEWS: mention that the default mDNS mode is now "yes"

C.f. issue #25252, PR #25255, and
RHBZ#2169786 (https://bugzilla.redhat.com/show_bug.cgi?id=2169786).

2 years agosrc: fix several typos in log messages
Dmitry V. Levin [Wed, 15 Feb 2023 08:00:00 +0000 (08:00 +0000)] 
src: fix several typos in log messages

2 years agotest-sysusers: add test for basic.conf 26417/head
Yu Watanabe [Wed, 15 Feb 2023 01:49:14 +0000 (10:49 +0900)] 
test-sysusers: add test for basic.conf

2 years agosysusers: also add root group
Yu Watanabe [Wed, 15 Feb 2023 01:29:07 +0000 (10:29 +0900)] 
sysusers: also add root group

Follow-up for 49bb7fe5f88fc35b8529d7d8dfcd4c151a9aaf1a.

Fixes an issue reported at
https://github.com/systemd/systemd/pull/26270#issuecomment-1428945403.

2 years agohwdb: Add HP ENVY x360 2-in-1
Jean-Tiare Le Bigot [Tue, 14 Feb 2023 22:40:38 +0000 (23:40 +0100)] 
hwdb: Add HP ENVY x360 2-in-1

Since #26144, RFKILL events are disabled for HP ENVY x360 Convertible.
This commit adds a variation of the name.

2 years agobootctl: avoid using __WORDSIZE macro
Mike Gilbert [Tue, 14 Feb 2023 19:46:25 +0000 (14:46 -0500)] 
bootctl: avoid using __WORDSIZE macro

__WORDSIZE does not seem to be documented anywhere, and is probably
meant to be used internally by glibc headers.

In systemd, it was only being used in warning messages. We can avoid
using it by rewording the messages slightly.

Fixes a build error with musl libc.

Bug: https://bugs.gentoo.org/894430

2 years agotest-execute: add basic tests for LoadCredential= and SetCredential= 26307/head
Yu Watanabe [Fri, 3 Feb 2023 00:26:56 +0000 (09:26 +0900)] 
test-execute: add basic tests for LoadCredential= and SetCredential=

2 years agotest-execute: drop capabilities when testing with user manager
Yu Watanabe [Fri, 3 Feb 2023 03:28:31 +0000 (12:28 +0900)] 
test-execute: drop capabilities when testing with user manager

Before this, tests are split into two categories, system and user, but
both are running in fully privileged environment. Hence, unprivileged
user scope was mostly not covered by the test.

Let's run all tests in both system and user scopes, and drop capabilities
when Manager is running in user scope.

This also makes the host environment protected more from the test run.

2 years agocore/execute: fix comment
Yu Watanabe [Thu, 2 Feb 2023 18:15:13 +0000 (03:15 +0900)] 
core/execute: fix comment

2 years agotree-wide: fix typo and comment style update
Yu Watanabe [Wed, 15 Feb 2023 01:08:16 +0000 (10:08 +0900)] 
tree-wide: fix typo and comment style update

2 years agorepart: Remove outdated comment 26410/head
Daan De Meyer [Tue, 14 Feb 2023 14:09:54 +0000 (15:09 +0100)] 
repart: Remove outdated comment

2 years agomount-setup: Fix typo
Daan De Meyer [Tue, 14 Feb 2023 14:09:32 +0000 (15:09 +0100)] 
mount-setup: Fix typo

2 years agorepart: Initialize root directory metadata correctly
Daan De Meyer [Tue, 14 Feb 2023 10:19:43 +0000 (11:19 +0100)] 
repart: Initialize root directory metadata correctly

Let's make sure we copy the root directory metadata from an
appropriate source directory.

2 years agorepart: Create temporary root directory using var_tmp_dir()
Daan De Meyer [Tue, 14 Feb 2023 10:17:32 +0000 (11:17 +0100)] 
repart: Create temporary root directory using var_tmp_dir()

This allows users to override the directory used with environment
variables.

2 years agocopy: Copy symlink xattrs
Daan De Meyer [Mon, 13 Feb 2023 20:56:31 +0000 (21:56 +0100)] 
copy: Copy symlink xattrs

Symlinks can have xattrs as well, let's make sure we copy those
as well.

2 years agocopy: Make copy_xattr() more generic
Daan De Meyer [Mon, 13 Feb 2023 20:51:11 +0000 (21:51 +0100)] 
copy: Make copy_xattr() more generic

Let's make copy_xattr() a little more generic in preparation for
copying symlink xattrs.

2 years agoxattr-util: Add xsetxattr()
Daan De Meyer [Mon, 13 Feb 2023 20:49:38 +0000 (21:49 +0100)] 
xattr-util: Add xsetxattr()

Like getxattr_malloc() but for setxattr() and friends.

2 years agotest-boot-timestamp: Handle ERANGE error
Daan De Meyer [Mon, 13 Feb 2023 13:27:24 +0000 (14:27 +0100)] 
test-boot-timestamp: Handle ERANGE error

Timestampfs from sysfs files can be zero in which case ERANGE will
be returned so let's make sure we catch that.

2 years agoboot: Ensure raise() is not dropped by LTO
Jan Janssen [Sun, 12 Feb 2023 19:23:18 +0000 (20:23 +0100)] 
boot: Ensure raise() is not dropped by LTO

2 years agomkosi: Stop installing kernel headers to /usr
Daan De Meyer [Sun, 12 Feb 2023 17:16:06 +0000 (18:16 +0100)] 
mkosi: Stop installing kernel headers to /usr

The selftests automatically pick up the headers from the kernel
build directory so we don't have to install them to /usr ourselves.

2 years agoMerge pull request #26400 from ml-/fix-directory-and-typos
Yu Watanabe [Sun, 12 Feb 2023 08:33:41 +0000 (17:33 +0900)] 
Merge pull request #26400 from ml-/fix-directory-and-typos

Fix directory for user home bind mounts in log error and man page

2 years agoman: fix typos 26400/head
ml [Sat, 11 Feb 2023 23:54:07 +0000 (00:54 +0100)] 
man: fix typos

2 years agoman: fix directory for user home bind mounts
ml [Sat, 11 Feb 2023 23:30:28 +0000 (00:30 +0100)] 
man: fix directory for user home bind mounts

2 years agonspawn: fix directory in logged error
ml [Sat, 11 Feb 2023 23:22:52 +0000 (00:22 +0100)] 
nspawn: fix directory in logged error

2 years agoci(labeler): fix missing emoji in `dont-merge` label
Jan Macku [Sat, 11 Feb 2023 06:38:28 +0000 (07:38 +0100)] 
ci(labeler): fix missing emoji in `dont-merge` label

2 years agoci(labeler): fix missing emoji in `quick-review` label
Jan Macku [Sat, 11 Feb 2023 06:35:07 +0000 (07:35 +0100)] 
ci(labeler): fix missing emoji in `quick-review` label

2 years agoNEWS: update date v253-rc3
Luca Boccassi [Fri, 10 Feb 2023 17:12:31 +0000 (17:12 +0000)] 
NEWS: update date

2 years agoMerge pull request #26392 from bluca/news
Zbigniew Jędrzejewski-Szmek [Fri, 10 Feb 2023 17:05:17 +0000 (18:05 +0100)] 
Merge pull request #26392 from bluca/news

Update hwdb and news

2 years agodissect-image: unknown/unsupported diskseq is indicated by 0, not by UINT64_MAX
Lennart Poettering [Fri, 10 Feb 2023 15:03:46 +0000 (16:03 +0100)] 
dissect-image: unknown/unsupported diskseq is indicated by 0, not by UINT64_MAX

At almost all places if diskseq is not supported we encode this as
diskseq zero. But in two places we got the check for that wrong,
assuming it was UINT64_MAX.

Fix that.

2 years agohwdb: update database 26392/head
Luca Boccassi [Fri, 10 Feb 2023 16:17:24 +0000 (16:17 +0000)] 
hwdb: update database

2 years agoNEWS: update contributors list
Luca Boccassi [Fri, 10 Feb 2023 16:14:06 +0000 (16:14 +0000)] 
NEWS: update contributors list

2 years agocore: when isolating to a unit, also keep units running that are triggered by units...
Lennart Poettering [Fri, 10 Feb 2023 12:38:08 +0000 (13:38 +0100)] 
core: when isolating to a unit, also keep units running that are triggered by units we keep running

Inspired by: #26364

(this might even "fix" #26364, but without debug logs it's hard to make
such claims)

Fixes: #23055
2 years agouserdb: Use json_dispatch_user_group_name() to parse GetMembership fields
Samuel Cabrero [Fri, 10 Feb 2023 13:04:27 +0000 (14:04 +0100)] 
userdb: Use json_dispatch_user_group_name() to parse GetMembership fields

It allows to relax the checks and allow characters like '\', used by
windows to split the domain name and user name.

For reference, discussion in the systemd-devel mailing list:
https://lists.freedesktop.org/archives/systemd-devel/2023-February/048804.html

Signed-off-by: Samuel Cabrero <scabrero@suse.de>
2 years agomkosi: Use globs instead of prepare script to install extra packages
Daan De Meyer [Fri, 10 Feb 2023 14:33:31 +0000 (15:33 +0100)] 
mkosi: Use globs instead of prepare script to install extra packages

This allows us to install everything in the same dnf command instead
of having to use a prepare script to run dnf from within the image.

This is a hack until mkosi supports release specific dropin files.

2 years agoMerge pull request #26387 from bluca/swapon_util_linux
Luca Boccassi [Fri, 10 Feb 2023 14:23:16 +0000 (14:23 +0000)] 
Merge pull request #26387 from bluca/swapon_util_linux

README/NEWS: note that we now explicitly require util-linux's swapon due to new option

2 years agoNEWS: note that we require a swapon that supports --fixpgsz 26387/head
Luca Boccassi [Fri, 10 Feb 2023 12:00:21 +0000 (12:00 +0000)] 
NEWS: note that we require a swapon that supports --fixpgsz

2 years agoREADME: explicitly note that util-linux's mount/swap are required
Luca Boccassi [Fri, 10 Feb 2023 11:58:20 +0000 (11:58 +0000)] 
README: explicitly note that util-linux's mount/swap are required

These are the most visible and hard requirements, as we use options that
busybox does not provide, so list them explicitly to avoid surprises

2 years agocryptenroll: drop deadcode
Yu Watanabe [Fri, 10 Feb 2023 09:22:57 +0000 (18:22 +0900)] 
cryptenroll: drop deadcode

Follow-up for b0fc23fae51d244d2c33d70c10003aa5d5840223.

After the commit, 'signature_path' is now always non-NULL, hence the
condition can be dropped.

Fixes CID#1504492.

2 years agomkosi: Update to latest
Daan De Meyer [Thu, 9 Feb 2023 08:53:05 +0000 (09:53 +0100)] 
mkosi: Update to latest

Let's make sure we're testing unprivileged builds properly. Usage
of SourceFileTransfer= and SourceFileTransferFinal= are removed as
they were dropped by mkosi. SourceFileTransfer=mount is now the
default in mkosi so behavior for the build script is unchanged. We
stop copying sources in the final image until mkosi adds support
for virtiofs.

2 years agoboot: Fix undefined reference to raise() on arm
Jan Janssen [Thu, 9 Feb 2023 20:03:14 +0000 (21:03 +0100)] 
boot: Fix undefined reference to raise() on arm

This is just a workaround. Once we drop gnu-efi, the arm build system
for EFI binaries should be changed to use the arm-none-eabi toolchain,
which should not exhibit this behavior.

2 years agovarious: boldify version output
Zbigniew Jędrzejewski-Szmek [Thu, 9 Feb 2023 13:50:47 +0000 (14:50 +0100)] 
various: boldify version output

Follow-up for 4453ebe4db0511d25bed1040930ea6430c1bed91.
With the feature list all dandified, the most important part of the
output, i.e. the project name and version, are less visible.

2 years agoboot: Make sure we take --root into account everywhere.
Daan De Meyer [Thu, 9 Feb 2023 09:53:16 +0000 (10:53 +0100)] 
boot: Make sure we take --root into account everywhere.

2 years agoMerge pull request #26377 from keszybz/doc-fixups-2
Luca Boccassi [Thu, 9 Feb 2023 14:45:40 +0000 (14:45 +0000)] 
Merge pull request #26377 from keszybz/doc-fixups-2

Fix links in man pages

2 years agoman: fix links to man pages 26377/head
Zbigniew Jędrzejewski-Szmek [Thu, 9 Feb 2023 13:30:43 +0000 (14:30 +0100)] 
man: fix links to man pages

Done using linkchecker as usual.

2 years agoman: fix section number
Zbigniew Jędrzejewski-Szmek [Thu, 9 Feb 2023 13:04:26 +0000 (14:04 +0100)] 
man: fix section number

Fixes #26376.

2 years agounits: change assert to condition to skip running in initrd/os
Luca Boccassi [Wed, 8 Feb 2023 23:06:27 +0000 (23:06 +0000)] 
units: change assert to condition to skip running in initrd/os

These units are also present in the initrd, so instead of an assert,
just use a condition so they are skipped where they need to be skipped.

Fixes https://github.com/systemd/systemd/issues/26358

2 years agobootctl: Add missing %m
Daan De Meyer [Thu, 9 Feb 2023 09:44:35 +0000 (10:44 +0100)] 
bootctl: Add missing %m

2 years agoMerge pull request #26366 from yuwata/nss-myhostname
Luca Boccassi [Thu, 9 Feb 2023 10:04:14 +0000 (10:04 +0000)] 
Merge pull request #26366 from yuwata/nss-myhostname

nss-myhostname: two fixlets

2 years agonss-myhostname: do not return empty result with NSS_STATUS_SUCCESS 26366/head
Yu Watanabe [Wed, 8 Feb 2023 21:07:13 +0000 (06:07 +0900)] 
nss-myhostname: do not return empty result with NSS_STATUS_SUCCESS

Fixes a bug introduced by db50d326a46beca3cc24b6354b6e1b3591902d45.

Fixes RHBZ#2167468 (https://bugzilla.redhat.com/show_bug.cgi?id=2167468).

2 years agonss-myhostname: fix inverted condition in
Yu Watanabe [Wed, 8 Feb 2023 20:55:42 +0000 (05:55 +0900)] 
nss-myhostname: fix inverted condition in

Fixes a bug introduced by db50d326a46beca3cc24b6354b6e1b3591902d45.

2 years agoMerge pull request #26354 from bluca/news
Luca Boccassi [Wed, 8 Feb 2023 20:25:10 +0000 (20:25 +0000)] 
Merge pull request #26354 from bluca/news

NEWS: add future incompatible changes notice

2 years agoprocess-util: add missing error check
Lennart Poettering [Wed, 8 Feb 2023 17:02:27 +0000 (18:02 +0100)] 
process-util: add missing error check

2 years agohwdb: add override for IdeaPad5 insert key
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 16:31:45 +0000 (17:31 +0100)] 
hwdb: add override for IdeaPad5 insert key

Fixes #25968.

I wrote the rule to assume that all IdeaPad5 thingies are like that.

2 years agoMerge pull request #26225 from qdeslandes/fix_delegate_cgroup_logs_filtering
Luca Boccassi [Wed, 8 Feb 2023 19:36:21 +0000 (19:36 +0000)] 
Merge pull request #26225 from qdeslandes/fix_delegate_cgroup_logs_filtering

Fix delegate cgroup logs filtering

2 years agoukify: add explanatory message when import fails
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 15:17:30 +0000 (16:17 +0100)] 
ukify: add explanatory message when import fails

2 years agojournal: modernize sd_journal_get_realtime_usec() a bit
Lennart Poettering [Wed, 8 Feb 2023 10:05:46 +0000 (11:05 +0100)] 
journal: modernize sd_journal_get_realtime_usec() a bit

This does what 404803e6caad2de2d8e74caab0b79ec3f030f801 did for the
monotonic timestamp getter, but for the realtime timestamp.

It also also makes the return value optional, exactly as for the
monotonic timestamp logic.

2 years agoNEWS: note about future implicit PrivateUsers= in user units 26354/head
Luca Boccassi [Wed, 8 Feb 2023 13:38:38 +0000 (13:38 +0000)] 
NEWS: note about future implicit PrivateUsers= in user units

2 years agoMerge pull request #26350 from keszybz/reload-messages
Luca Boccassi [Wed, 8 Feb 2023 17:05:16 +0000 (17:05 +0000)] 
Merge pull request #26350 from keszybz/reload-messages

Improve messages emitted when Reload or Reexec is requested

2 years agodocs/NETWORK_ONLINE: fix example
Geert Lorang [Wed, 8 Feb 2023 16:10:28 +0000 (17:10 +0100)] 
docs/NETWORK_ONLINE: fix example

Type=oneshot is necessary for systemd to actually wait for the service
to return. With RemainAfterExit=yes it won't be started again.

Fixes #26342.

2 years agojournald: fix ignored filtering patterns for delegated cgroups 26225/head
Quentin Deslandes [Thu, 26 Jan 2023 18:44:10 +0000 (19:44 +0100)] 
journald: fix ignored filtering patterns for delegated cgroups

If a service defines Delegate=yes, its subcgroup won't inherit the
LogFilterPatterns= option, because the option is stored on the unit's
cgroup attributes, not on the subcgroup.

Fixed by using the unit's cgroup attributes instead.

2 years agocore: add cg_path_get_unit_path()
Quentin Deslandes [Thu, 26 Jan 2023 18:39:08 +0000 (19:39 +0100)] 
core: add cg_path_get_unit_path()

From a given cgroup path, cg_path_get_unit() allows to retrieve the
unit's name. Although, this removes the path to the unit's cgroup,
preventing the result to be used to fetch xattrs.

Introduce cg_path_get_unit_path() which provides the path to the unit's
cgroup. This function behave similarly to cg_path_get_unit() (checking
the validity and escaping the unit's name).

2 years agosd-bus: adjust line breaks 26350/head
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 10:58:23 +0000 (11:58 +0100)] 
sd-bus: adjust line breaks

2 years agomanager: improve message about Reload/Reexec requests
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 10:36:22 +0000 (11:36 +0100)] 
manager: improve message about Reload/Reexec requests

If we fail to get the necessary information, let's just not print that
part of the message. 'n/a' looks pretty ugly.

I used a bunch of ternary operators instead of seperate log lines because
with two components that might or might not be there, we need four different
combinations.

Also, the unit name doesn't need to be quoted, it's always printable.

2 years agomanager: "downgrade" message about command vanishing from the unit file
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 10:30:13 +0000 (11:30 +0100)] 
manager: "downgrade" message about command vanishing from the unit file

We would print "Current command vanished from the unit file, execution of
the command list won't be resumed." as a warning, but most of the time there
is nothing to resume, because a unit has just one command. So let's detect
the case where the command that was active is the last command in the sequence
and skip the warning.

I was considering how to store the information that the command is last. An
important consideration is not to use a format that would confuse older versions
of systemd. (It wouldn't be a big problem if older systemd just refused the
new serialization, since we require systemd to be newer, but we should avoid
the case where the deserialization is "successful", but actually incorrect.)
Similarly, the deserialization from the old systemd must not confuse new systemd.
For this command, we have a list of arguments at the end, so just adding a
new field either in the middle or at the end is problematic because it's hard
to ensure that we don't mix up the positional and variable arguments.

We actually need to store just one bit of information, so '+' is prefixed on
the index of the last command and used by new systemd to skip the warning.
When deserializing from older systemd, '+' is not present, so we detect all
commands as "not last", and still emit the warning, so we err on the side of
caution. If the user were to deserialize from newer to older systemd, nothing
untoward would happen, because the '+' is ignored. (Users shouldn't do this,
but we know that this occasionally happens with initrds or exitrds and package
downgrades.)

2 years agoNEWS: copy future incompatible changes notice from 252
Luca Boccassi [Wed, 8 Feb 2023 13:38:15 +0000 (13:38 +0000)] 
NEWS: copy future incompatible changes notice from 252

These are in the future, so it's good to re-emphasize on every release until they
actually happen

2 years agoci: Add names to steps in labeler workflow
Jan Macku [Wed, 8 Feb 2023 12:02:49 +0000 (13:02 +0100)] 
ci: Add names to steps in labeler workflow

This makes it easier to see what step failed/was skipped in the GitHub
Actions UI. It also makes future debugging easier.

2 years agotest: add basic seqnum test 26213/head
Lennart Poettering [Tue, 31 Jan 2023 13:40:03 +0000 (14:40 +0100)] 
test: add basic seqnum test

2 years agoman: document __SEQNUM=/__SEQNUM_ID= journal pseudo fields
Lennart Poettering [Thu, 26 Jan 2023 10:16:51 +0000 (11:16 +0100)] 
man: document __SEQNUM=/__SEQNUM_ID= journal pseudo fields

2 years agoman: document the new sd_journal_get_seqnum() call
Lennart Poettering [Thu, 26 Jan 2023 10:04:44 +0000 (11:04 +0100)] 
man: document the new sd_journal_get_seqnum() call

2 years agojournald: maintain entry seqnum counter in mmap()ed file in /run/
Lennart Poettering [Mon, 23 Jan 2023 20:21:21 +0000 (21:21 +0100)] 
journald: maintain entry seqnum counter in mmap()ed file in /run/

Let's ensure that entry seqnums remain stable and monotonic across the
entire runtime of the system, even if local storage is turned off. Let's
do this by maintainer a counter file in /run/ which we mmap() and
wherein we maintain the counter from early-boot on till late shutdown.

This takes inspiration of the kernel-seqnum file we already maintain
like that that tracks which kmsg messages we already processed. In fact,
we reuse the same code for maintaining it.

This should allow the behaviour entry seqnums to be more predictable, in
particular when journal local storage is turned off. Previously, we'd
maintain the seqnum simply by always bumping it to the maximum of the
last written entry seqnum plus one, and the biggest seqnum so far
written to the journal file on disk. If we'd never write a file on disk,
or if no journal file was existing during the initrd→seqnum transition
we'd completely lose the current seqnum position during daemon restarts
(such as the one happening during the switch-root operation).

This also will cause a journal file rotation whenever we try to write to
a journal file with multiple sequence number IDs, so that we know that
from early boot trhough the entire runtime we'll have stable sequence
numbers that do not jump, and thus can be used to determine "lost"
messages.

2 years agologs-show: show seqnum info in export+json output mode
Lennart Poettering [Thu, 19 Jan 2023 21:42:03 +0000 (22:42 +0100)] 
logs-show: show seqnum info in export+json output mode

2 years agosd-journal: add high-level API for querying seqnum for journal entries, along with...
Lennart Poettering [Thu, 12 Jan 2023 16:48:43 +0000 (17:48 +0100)] 
sd-journal: add high-level API for querying seqnum for journal entries, along with seqnum id

2 years agohwdb: Add HP Envy x360 Convertible 15-cn0xxx to existing entry
Fabian Gurtner [Thu, 2 Feb 2023 09:28:23 +0000 (10:28 +0100)] 
hwdb: Add HP Envy x360 Convertible 15-cn0xxx to existing entry

2 years agotest-parse-util: add tests with explicit plus character
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 09:54:49 +0000 (10:54 +0100)] 
test-parse-util: add tests with explicit plus character

I expected this to work, but our tests did not cover this
explicitly.

2 years agocore/service: constify ExecCommand* in two functions
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 08:40:24 +0000 (09:40 +0100)] 
core/service: constify ExecCommand* in two functions

2 years agocore: imply DeviceAllow=/dev/tpmrm0 with LoadCredentialEncrypted
Luca Boccassi [Wed, 8 Feb 2023 00:25:00 +0000 (00:25 +0000)] 
core: imply DeviceAllow=/dev/tpmrm0 with LoadCredentialEncrypted

If the device access policy is restricted, add implicitly access to the TPM
if at least one encrypted credential needs to be loaded.

Fixes https://github.com/systemd/systemd/issues/26042

2 years agocryptenroll: do not implicitly verify with default tpm policy signature
Luca Boccassi [Wed, 8 Feb 2023 02:10:28 +0000 (02:10 +0000)] 
cryptenroll: do not implicitly verify with default tpm policy signature

If it was not requested to use a tpm2 signature file when enrolling, do
not fallback to the default /run/systemd/tpm2-pcr-signature.json as it
likely will be unrelated if it exists.

Fixes https://github.com/systemd/systemd/issues/25435

2 years agounit: always return 1 in log_kill
msizanoen1 [Tue, 7 Feb 2023 13:17:21 +0000 (20:17 +0700)] 
unit: always return 1 in log_kill

This ensures that cg_kill_items returns the correct value to let the
manager know that a process was killed.

2 years agoMerge pull request #26328 from yuwata/udev-worker-set-process-name
Zbigniew Jędrzejewski-Szmek [Wed, 8 Feb 2023 07:57:05 +0000 (08:57 +0100)] 
Merge pull request #26328 from yuwata/udev-worker-set-process-name

udev: set worker process name