]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
9 days agomkosi: update debian commit reference to 56402b2bde258999a8f01a8b04465fde9242d6a1 40802/head
Luca Boccassi [Mon, 20 Jul 2026 09:58:51 +0000 (10:58 +0100)] 
mkosi: update debian commit reference to 56402b2bde258999a8f01a8b04465fde9242d6a1

56402b2bde Drop symlink to systemd-udevd-control.socket
3afaaf4f89 Install new files for upstream build

11 days agomkosi/opensuse: do not try to package non-existent symlink to systemd-udevd-control...
Yu Watanabe [Thu, 4 Jun 2026 19:07:45 +0000 (04:07 +0900)] 
mkosi/opensuse: do not try to package non-existent symlink to systemd-udevd-control.socket

11 days agoNEWS: mention the removeal of legacy udev control socket
Yu Watanabe [Thu, 4 Jun 2026 19:18:48 +0000 (04:18 +0900)] 
NEWS: mention the removeal of legacy udev control socket

11 days agoudev: drop home-grown udev-ctrl socket
Yu Watanabe [Sun, 22 Feb 2026 16:01:45 +0000 (01:01 +0900)] 
udev: drop home-grown udev-ctrl socket

Nowadays, varlink is used to control systemd-udevd. Let's drop the
legacy socket.

Note, the existence of /run/udev/control socket is widely used in both
our code and external projects. Also, the dependency to
systemd-udevd-control.socket is widely used in many projects.
Hence, we need to create a symlink to the socket file and .socket unit
file.

11 days agonspawn: do not try to connect udevd
Yu Watanabe [Tue, 2 Jun 2026 02:45:15 +0000 (11:45 +0900)] 
nspawn: do not try to connect udevd

nspawn itself does not require to control udevd process.

Only necessary points are
- udevd is available, and
- we are in the main network namespace.

Let's check them explicitly.

This also makes the check is skipped when we are talking to mountfsd, as
the check is pointless in that case.

11 days agosd-device: use network_namespace_is_init()
Yu Watanabe [Tue, 2 Jun 2026 02:37:52 +0000 (11:37 +0900)] 
sd-device: use network_namespace_is_init()

11 days agonamespace-util: introduce network_namespace_is_init()
Yu Watanabe [Tue, 2 Jun 2026 02:32:26 +0000 (11:32 +0900)] 
namespace-util: introduce network_namespace_is_init()

11 days agodocs: clarify scope of portable services
acandoo [Fri, 17 Jul 2026 19:09:07 +0000 (15:09 -0400)] 
docs: clarify scope of portable services

Removed note clarifying that portable services are only for system services and not user services, and changed comparisons to "system services" with just "services". With newer systemd versions, `systemd-portabled` can be run as a user service.

11 days agosd-dlopen: make header self-standing again
Luca Boccassi [Fri, 17 Jul 2026 11:10:01 +0000 (12:10 +0100)] 
sd-dlopen: make header self-standing again

The purpose of this header was to provide MIT-0 sources that can be copied
and pasted liberally. Including an LGPL-2.1+ header from it deafeats its
purpose. Make it self-standing again.

Follow-up for aa0db003cf537aeb051cc51a2f7e95d51a5756cd

11 days agoupdate TODO
Lennart Poettering [Thu, 16 Jul 2026 14:30:12 +0000 (16:30 +0200)] 
update TODO

12 days agonspawn: use chase() for creating dev nodes (#43037)
Luca Boccassi [Fri, 17 Jul 2026 08:02:28 +0000 (09:02 +0100)] 
nspawn: use chase() for creating dev nodes (#43037)

12 days agonspawn: use chase() for creating dev nodes 43037/head
Luca Boccassi [Thu, 16 Jul 2026 16:41:05 +0000 (17:41 +0100)] 
nspawn: use chase() for creating dev nodes

Follow-up for de40a3037af944f6803375f2f5269cffc4247f56

12 days agonspawn: log at error level before exiting if parsing OCI fails
Luca Boccassi [Wed, 15 Jul 2026 14:39:40 +0000 (15:39 +0100)] 
nspawn: log at error level before exiting if parsing OCI fails

Currently it silently errors out, with nothing at all printed on the
console

Follow-up for de40a3037af944f6803375f2f5269cffc4247f56

12 days agoboot: fix MEMMAP_DEVICE_PATH EndingAddress field calculation
Lennart Poettering [Thu, 16 Jul 2026 13:59:08 +0000 (15:59 +0200)] 
boot: fix MEMMAP_DEVICE_PATH EndingAddress field calculation

Let's do what EDK2 does.

Fixes: #43038
12 days agoudev-util: bound leading whitespace skip in udev_replace_whitespace (#42757)
Yu Watanabe [Thu, 16 Jul 2026 16:16:07 +0000 (01:16 +0900)] 
udev-util: bound leading whitespace skip in udev_replace_whitespace (#42757)

udev_replace_whitespace() is documented to read at most 'len' bytes from
'str':
- the strspn() skip of leading whitespace stops at a non-space byte or
NUL, not at 'len'
- ata_id passes the space padded, non-NUL-terminated ATA IDENTIFY
model/serial/fw fields
- an all-blank field reads off the end of the 512-byte hd_driveid stack
struct
Capped the skip to 'len'; existing outputs are unchanged. Added a
regression test.

12 days agoAssorted remote/shared/resolved hardening fixes flagged by kres (#42978)
Yu Watanabe [Thu, 16 Jul 2026 16:12:32 +0000 (01:12 +0900)] 
Assorted remote/shared/resolved hardening fixes flagged by kres (#42978)

12 days agoRebased and reapplied the fix, dropped the test case.
xiahualiu [Tue, 14 Jul 2026 15:07:29 +0000 (08:07 -0700)] 
Rebased and reapplied the fix, dropped the test case.

12 days agodiscover-image: don't ignore symlinks to raw images
Frantisek Sumsal [Tue, 14 Jul 2026 11:37:38 +0000 (13:37 +0200)] 
discover-image: don't ignore symlinks to raw images

Since 5c6bb289990ba53898cbc62db6e732ecb9dc87ac image_discover() uses
chaseat() to chase the path to the image. This however breaks the raw
image check in image_make() as "path" is now not the symlink itself, but
the symlink target.

So with:

$ ls -l /var/lib/machines
total 872104
lrwxrwxrwx. 1 root root         12 Jul 14 06:10 foo.raw -> foo.squashfs
-rw-r--r--. 1 root root 5368709120 Jul 13 02:07 foo.squashfs

The endswith(path, ".raw") check is now performed on "/.../foo.squashfs"
instead of "/.../foo.raw", making it false and thus ignoring the image
symlink completely.

Address this by also checking if the pretty name is set - if so, and the
path is a regular file, the caller must've been image_find() or
image_discover() which already checked if the original path ends in .raw
and is a regular file.

Follow-up for 5c6bb289990ba53898cbc62db6e732ecb9dc87ac.

Resolves: #41656

12 days agohomed: fix verification of local identity file
Luca Boccassi [Tue, 14 Jul 2026 18:23:28 +0000 (19:23 +0100)] 
homed: fix verification of local identity file

Follow-up for 70a5db5822c8056b53d9a4a9273ad12cb5f87a92

12 days agoAssorted coverity issues (#43035)
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 12:20:25 +0000 (14:20 +0200)] 
Assorted coverity issues (#43035)

12 days agoAssorted network hardening fixes flagged by kres (#43014)
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 12:15:18 +0000 (14:15 +0200)] 
Assorted network hardening fixes flagged by kres (#43014)

13 days agosysupdate: add config file with metadata for sysupdate components (#42651)
Luca Boccassi [Thu, 16 Jul 2026 11:48:10 +0000 (12:48 +0100)] 
sysupdate: add config file with metadata for sysupdate components (#42651)

This carries some metadata for components. It's supposed to grow a bit,
and include a way to enable/disable transfers, and to condition them.

13 days agorepart,dissect: explicitly support DDIs that are both signed *and* encrypted (#43009)
Lennart Poettering [Thu, 16 Jul 2026 11:40:49 +0000 (13:40 +0200)] 
repart,dissect: explicitly support DDIs that are both signed *and* encrypted (#43009)

This is a pretty relevant usecase: preparing an image on some trusted
host, submitting it to some other host that authenticates it and
decrypts it, and consumes it only then.

Let's support this explicitly.

13 days agomachined: Allow user ids in open_shell for machine-dbus
cidkidnix [Tue, 7 Jul 2026 19:04:30 +0000 (14:04 -0500)] 
machined: Allow user ids in open_shell for machine-dbus

Previously "machinectl shell --uid=1000 <container>" resulted in a
sucessful drop into a shell in the respective target machine. After
commit a9e9288288567beae57337ae903dd3b6c774001c this is no longer the
case.

This fixes the above breaking change brought in commit a9e9288288567beae57337ae903dd3b6c774001c

13 days agoudev-util: bound leading whitespace skip in udev_replace_whitespace 42757/head
Syed Mohammed Nayyar [Mon, 29 Jun 2026 06:02:14 +0000 (11:32 +0530)] 
udev-util: bound leading whitespace skip in udev_replace_whitespace

The function documents that at most 'len' bytes are read from 'str',
but the leading whitespace skip used strspn(), which is bounded only
by a non-whitespace byte or a NUL. ata_id passes the space padded,
non-NUL-terminated ATA IDENTIFY fields, so an all-blank model reads
past the buffer. Use strnspn() to cap the skip to 'len'.

13 days agostring-util: add strnspn()
Syed Mohammed Nayyar [Mon, 29 Jun 2026 06:02:14 +0000 (11:32 +0530)] 
string-util: add strnspn()

Like strspn(), but reads at most 'n' bytes from the input. strspn()
is bounded only by a non-matching byte or a NUL, so it over-reads a
buffer that is all matching bytes and not NUL terminated within 'n'.

13 days agoci: add test suite for verity+luks disk images 43009/head
Lennart Poettering [Mon, 13 Jul 2026 13:41:36 +0000 (15:41 +0200)] 
ci: add test suite for verity+luks disk images

13 days agodissect-image: support activating luks+verity partitions
Lennart Poettering [Mon, 13 Jul 2026 13:41:21 +0000 (15:41 +0200)] 
dissect-image: support activating luks+verity partitions

Let's properly activate images that have both LUKS and Verity enabled
for a partition.

13 days agorepart: say when we are calculating Verity data
Lennart Poettering [Tue, 14 Jul 2026 08:56:19 +0000 (10:56 +0200)] 
repart: say when we are calculating Verity data

We say when we encrypt a partition, let's also say when we calculate
verity protection data.

13 days agorepart: support generating LUKS+Verity partitions
Lennart Poettering [Mon, 13 Jul 2026 13:40:56 +0000 (15:40 +0200)] 
repart: support generating LUKS+Verity partitions

For various cases it is interesting to both sign and encrypted a file
system, for example to prepare it on one host and provide it to another.
Let's explicitly support preparing this in systemd-repart via setting
both Verity= and Encrypt=.

13 days agoupdate TODO
Lennart Poettering [Thu, 16 Jul 2026 05:04:26 +0000 (07:04 +0200)] 
update TODO

13 days agosysext: validate work directory metadata before removal 42978/head
Luca Boccassi [Fri, 10 Jul 2026 18:08:57 +0000 (19:08 +0100)] 
sysext: validate work directory metadata before removal

unmerge_hierarchy() joined the persisted work_dir value directly with
--root=. An empty value therefore resolved to the root itself and was passed
to rm_rf().

Require the decoded metadata to name a non-empty, safe, normalized relative
path before constructing the removal target. Add coverage using a disposable
root with deliberately emptied metadata.

Follow-up for 9cfad502f4aa103ef0d2191cbb6b82fecfbc5044

13 days agoshift-uid: close consumed directory fds on early return
Luca Boccassi [Fri, 10 Jul 2026 17:48:35 +0000 (18:48 +0100)] 
shift-uid: close consumed directory fds on early return

recurse_fd() consumes each directory fd passed to it, but it has no
cleanup set up until after take_fdopendir() succeeds.
Errors and skipped procfs, sysfs, or read-only subtrees therefore leak the
incoming fd.

Follow-up for b1fb2d971c810e0bdf9ff0ae567a1c6c230e4e5d

13 days agorm-rf: fail closed when the root check fails
Luca Boccassi [Fri, 10 Jul 2026 17:22:34 +0000 (18:22 +0100)] 
rm-rf: fail closed when the root check fails

path_is_root_at() returns a negative errno when it cannot determine whether
a target is the root file system. rm_rf_at() treats those errors as a
negative answer and continued with destructive operations.

Propagate root-check errors before modifying the target, while preserving
REMOVE_MISSING_OK for an absent path.

Follow-up for c0228b4fa3e4e633afa5eb8417e6cd3e311cd250

13 days agovconsole: reject empty layout during keymap conversion with error
Luca Boccassi [Fri, 10 Jul 2026 16:59:24 +0000 (17:59 +0100)] 
vconsole: reject empty layout during keymap conversion with error

A leading-dash console keymap or leading-comma X11 layout can produce an
empty layout while converting between the two formats. find_converted_keymap()
then asserts on it, allowing malformed input to abort callers such as localed.

Return EINVAL for an empty derived layout instead.

Follow-up for 6d0f5027364518ef17ef91b61dad945e1c4fd0f5

13 days agoresolved: preserve unchanged question on asymmetric redirect
Luca Boccassi [Fri, 10 Jul 2026 16:51:53 +0000 (17:51 +0100)] 
resolved: preserve unchanged question on asymmetric redirect

dns_question_cname_redirect() returns no replacement when a question
already matches a CNAME target or a DNAME does not apply. If only one of
the UTF-8 and IDNA questions redirects, dns_query_cname_redirect() then
installs NULL for the unchanged side.

Keep a reference to the original question on whichever side does not
redirect, and update the existing asymmetric DNAME test to verify it.

Follow-up for 23b298bce75a0d1f4f15f34458af9678b4a30c3a

13 days agojournal-remote: zero-initialize MHD daemon wrapper
Luca Boccassi [Fri, 10 Jul 2026 15:09:49 +0000 (16:09 +0100)] 
journal-remote: zero-initialize MHD daemon wrapper

MHDDaemonWrapper_free() unconditionally unrefs both event sources, but
setup_microhttpd_server() could return before initializing either pointer.
Zero-initialize the wrapper so cleanup after MHD startup failures safely
unrefs NULL.

Follow-up for 3c67c8bd4c5784bbcc644e489b9a39c0d2bc0e42

13 days agojournal-remote: remove disabled compression entry before freeing
Luca Boccassi [Fri, 10 Jul 2026 14:38:22 +0000 (15:38 +0100)] 
journal-remote: remove disabled compression entry before freeing

compression_config_put() frees the COMPRESSION_NONE value when a later
algorithm is selected, but lefts the map entry pointing at it. Remove the
entry first so subsequent parsing, mangling, and teardown cannot access or
free stale memory.

Follow-up for c259c9e25329c93cb1b7363f89d917ffa5ce57c1

13 days agonetwork: cancel netlink calls for detached requests 43014/head
Luca Boccassi [Mon, 13 Jul 2026 18:44:58 +0000 (19:44 +0100)] 
network: cancel netlink calls for detached requests

Store the asynchronous netlink slot in the Request object and release it
when the request is detached. This cancels the pending callback instead of
keeping the request alive until its reply arrives.

Follow-up for 80d62d4f1aa62c03828e4cbe2c2dfb2a19765af8

13 days agonetwork: compare all multipath route nexthops
Luca Boccassi [Mon, 13 Jul 2026 18:23:21 +0000 (19:23 +0100)] 
network: compare all multipath route nexthops

The multipath route comparator looks up every nexthop in the first
route and hence compares each entry with itself. Compare both ordered
nexthop sets instead, including weights, as the hash function does.

Follow-up for 47420573a778e83f2bddd536cf185cd5829e8ba9

13 days agotpm2-util: keep the measurement log's torn-write marker intact
Paul Meyer [Tue, 14 Jul 2026 11:26:56 +0000 (13:26 +0200)] 
tpm2-util: keep the measurement log's torn-write marker intact

The userspace measurement log carries a sticky-bit marker while a writer
is between updating a measurement register and appending the matching
record, so that a writer dying in between leaves the log detectably
incomplete.

However, the next successful writer used to clear the marker again after
appending its own record, erasing the evidence that an earlier writer
had died and the log is still missing a record. Keep the marker set in
that case instead; the new record is appended and synced regardless. The
marker likewise stays set if the measurement itself fails, so that any
non-clean completion remains flagged: a spurious flag on a failed but
harmless measurement is preferable to erasing evidence of a real gap,
and PCR replay stays authoritative either way.

Finally, warn when systemd-pcrlock loads a marked log, so the resulting
PCR validation failures come with a hint at their cause.

Signed-off-by: Paul Meyer <katexochen0@gmail.com>
13 days agojournalctl: reject field listing with filters
dongshengyuan [Mon, 13 Jul 2026 07:33:09 +0000 (15:33 +0800)] 
journalctl: reject field listing with filters

Reproducer:
  journalctl -F _SYSTEMD_UNIT -u test.service --no-pager
  journalctl -u test.service --no-pager -n 1

Before, the field listing ignored the unit filter and listed unrelated
units, while the normal journal query applied the filter.

sd_journal_query_unique() cannot represent journalctl filters such as
unit, boot, time, cursor, or grep filters. Walking the journal line by
line would make field listing linear in the number of entries and
duplicate unique-value handling.

Keep the scope-option predicate next to add_filters(), and reject field
listings combined with options that actually limit the journal.
Display-only options such as --pager-end are left alone.

13 days agoclonesetup: check target table size for overflow 43035/head
Luca Boccassi [Wed, 15 Jul 2026 11:06:02 +0000 (12:06 +0100)] 
clonesetup: check target table size for overflow

The target parameter length is added to two headers and aligned before
allocation. Check each operation and reject payloads that cannot be
represented by the device-mapper ioctl header.

CID#1663846

Follow-up for 104970a8bd7a3b53067f6e50283183406a579f0b

13 days agoclonesetup: check target message size for overflow
Luca Boccassi [Wed, 15 Jul 2026 11:05:04 +0000 (12:05 +0100)] 
clonesetup: check target message size for overflow

Build the variable-length ioctl size with checked additions. Reject an
oversized message before allocating and copying it into the buffer.

CID#1663845

Follow-up for 104970a8bd7a3b53067f6e50283183406a579f0b

13 days agotest: make NSS IPv4 tuple bounds explicit
Luca Boccassi [Wed, 15 Jul 2026 11:07:20 +0000 (12:07 +0100)] 
test: make NSS IPv4 tuple bounds explicit

gaih_addrtuple.addr has room for an IPv6 address, while IPv4 uses only
the first struct in_addr. Express the remaining range directly in terms
of that type so static analysis can prove the access remains within the
array.

CID#1663899

Follow-up for 2d85bba6b9ddd20b74992c740fab7f82c9c03f01

13 days agomkosi: update debian commit reference to 88c420c621dbd1b988950cf26fc60789fc989453
Luca Boccassi [Wed, 15 Jul 2026 14:21:12 +0000 (15:21 +0100)] 
mkosi: update debian commit reference to 88c420c621dbd1b988950cf26fc60789fc989453

88c420c621 Install new files for upstream build
5b7f67b86a Update changelog for 261.1-3 release
3f91c8567c NEWS: update about removal of sd-tpm dep
e13ba94737 Drop obsolete TODO
b0c5def366 systemd: downgrade systemd-tpm and mount to recommends
e9eb859a3a systemd-tpm: depend on tpm-udev for rules and tmpfiles.d
42f74bb110 Drop obsolete comment from d/control
fc40986137 debian/extra/network: use NamePolicy=keep mac on USB wifi devices

13 days agooci-util: Don't fall back to default registry for explicit registries
Kai Lüke [Wed, 15 Jul 2026 07:09:13 +0000 (16:09 +0900)] 
oci-util: Don't fall back to default registry for explicit registries

When a reference specifies a registry like ghcr.io or quay.io for which
we don't have a registry config file, the fallback forced the default
registry which is wrong.

Only use the default as fallback when there is no explicit registry.

13 days agoCleanup argument and return values for copy_bytes_full helpers (#43034)
Yu Watanabe [Wed, 15 Jul 2026 16:32:04 +0000 (01:32 +0900)] 
Cleanup argument and return values for copy_bytes_full helpers (#43034)

Follow-up for #43004.

13 days agoboot: guard missing Windows auto entry
dongshengyuan [Tue, 14 Jul 2026 11:40:15 +0000 (19:40 +0800)] 
boot: guard missing Windows auto entry

config_add_entry_loader_auto() returns NULL when the Windows loader
is missing. With reboot-for-bitlocker enabled, the caller still
assigned e->call and could dereference NULL.

This can happen when reboot-for-bitlocker is enabled but the ESP does
not contain EFI/Microsoft/Boot/bootmgfw.efi.

Before:
  systemd-boot could dereference NULL while building the menu

Follow-up for: 661615a0afacee3545cde0a48286c0fef983f8fe.

13 days agojournalctl: use root machine ID for namespaces
dongshengyuan [Tue, 14 Jul 2026 11:34:21 +0000 (19:34 +0800)] 
journalctl: use root machine ID for namespaces

journalctl --root=... --list-namespaces scans the target root's
journal tree, but used the host machine ID when matching namespace
directories.

Reproducer:
  root="$(mktemp -d)"
  mid=11111111111111111111111111111111
  mkdir -p "$root/etc" "$root/var/log/journal/$mid.testns"
  printf '%s\n' "$mid" >"$root/etc/machine-id"
  journalctl --root="$root" --list-namespaces --quiet

Before:
  no output

Follow-up for: 68f66a171398e27280a95e58ae7464219cccaaec.

13 days agonetwork: add IPv4ProxyARPAddress= and consolidate proxy ARP/NDP handling
Aritra Basu [Sun, 7 Jun 2026 06:04:11 +0000 (02:04 -0400)] 
network: add IPv4ProxyARPAddress= and consolidate proxy ARP/NDP handling

This adds an IPv4 counterpart to `IPv6ProxyNDPAddress=` for adding
manual entries to the kernel's IPv4 neighbour proxy table (check via
`ip -4 neighbour show proxy dev <dev>`). systemd-networkd only exposed
`IPv4ProxyARP=` for per-interface `proxy_arp` sysctl (automatic proxy
ARP) with no way to manage manual entries from a .network file.

To avoid duplicating the IPv6 proxy NDP code path, both families are
now combined into a single new `networkd-neighbor-proxy` module. The
IPv6 behaviour is preserved: `IPv6ProxyNDPAddress=` still implies
`IPv6ProxyNDP=yes` unless `IPv6ProxyNDP=` is explicitly disabled and
entries are still dropped if the kernel has no IPv6 support.
The same rule is applied to `IPv4ProxyARPAddress=`. It implies
`IPv4ProxyARP=yes` when the sysctl is not explicitly set and has no
effect if `IPv4ProxyARP=` has been set to false.

This keeps the user model symmetric and predictable across both
families: a single per-address setting that turns on the matching
per-interface sysctl automatically, while still letting system
administrators opt out by setting the boolean explicitly to false.

Note that the IPv4 manual NTF_PROXY entries installed here would
actually function without `proxy_arp` (unlike IPv6, where `proxy_ndp`
gates the manual entries); the implication is kept for symmetry with
`IPv6ProxyNDPAddress=` and is now called out explicitly in the man
page, together with the fact that enabling `proxy_arp` also activates
interface-wide automatic proxy ARP for routed-toward addresses on
connected subnets.

Parser-time validation rejects addresses the kernel would refuse:
the ANY/null address for both families, IPv4 and IPv6 multicast
and the IPv4 limited broadcast 255.255.255.255.

Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
2 weeks agoshared/copy: simplify argument convention for reflink_range 43034/head
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jul 2026 10:59:45 +0000 (12:59 +0200)] 
shared/copy: simplify argument convention for reflink_range

reflink_range() would treat size==UINT64_MAX as "copy everything", but
only if the offsets were 0. There are only two callers: one always passes
a fixed size, the other translated size==UINT64_MAX to 0. Make things
more uniform by always treating size==UINT64_MAX the same as size==0.

2 weeks agoshared/copy: simplify return convention for try_reflink_copy_bytes
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jul 2026 10:39:30 +0000 (12:39 +0200)] 
shared/copy: simplify return convention for try_reflink_copy_bytes

Follow-up for 5a12005c834eab92d7c76d61c7090aa78b61cdfb.

Also a rescue a comment from the discussion in the PR.

2 weeks agoupdate TODO 42651/head
Lennart Poettering [Wed, 24 Jun 2026 11:32:03 +0000 (13:32 +0200)] 
update TODO

2 weeks agoci: add test for the various new sysupdate features
Lennart Poettering [Wed, 1 Jul 2026 20:32:45 +0000 (22:32 +0200)] 
ci: add test for the various new sysupdate features

2 weeks agoshell-completion: add shell completion for systemd-sysupdate
Lennart Poettering [Wed, 1 Jul 2026 13:29:38 +0000 (15:29 +0200)] 
shell-completion: add shell completion for systemd-sysupdate

2 weeks agoman: document the new .component files
Lennart Poettering [Wed, 1 Jul 2026 16:22:13 +0000 (18:22 +0200)] 
man: document the new .component files

2 weeks agoman: document the new systemd-sysupdate switches and verbs
Lennart Poettering [Wed, 1 Jul 2026 12:58:28 +0000 (14:58 +0200)] 
man: document the new systemd-sysupdate switches and verbs

2 weeks agounits: add unit that can auto-enables all suggested component/features
Lennart Poettering [Wed, 1 Jul 2026 17:51:51 +0000 (19:51 +0200)] 
units: add unit that can auto-enables all suggested component/features

if enabled it will plug itself before systemd-sysupdate-update.service
and enable every component + feature that is suggested.

2 weeks agounits: update all components in systemd-sysupdate-update.service
Lennart Poettering [Wed, 1 Jul 2026 21:28:01 +0000 (23:28 +0200)] 
units: update all components in systemd-sysupdate-update.service

Let's beef up systemd-sysupdate-update.service and update not just one
component but all enables ones.

2 weeks agosysupdate: add support for 'update --component-all'
Lennart Poettering [Tue, 30 Jun 2026 20:55:45 +0000 (22:55 +0200)] 
sysupdate: add support for 'update --component-all'

Let's add a way to quickly update all components that are enabled.

2 weeks agotpm2-util: initialize NvPCRs on first extension
Paul Meyer [Mon, 13 Jul 2026 07:47:40 +0000 (09:47 +0200)] 
tpm2-util: initialize NvPCRs on first extension

Both callers of tpm2_nvpcr_extend_bytes() duplicate the same dance: on
-ENETDOWN, i.e. when the NvPCR isn't anchored yet because
systemd-tpm2-setup hasn't run, they acquire the anchor secret,
initialize the NvPCR, and extend again. Move this into
tpm2_nvpcr_extend_bytes() itself. The only caller-specific bit, whether
the anchor secret shall be synced to /var, is passed in as a parameter.

Signed-off-by: Paul Meyer <katexochen0@gmail.com>
2 weeks agocopy: drop COPY_REFLINK
Daan De Meyer [Sun, 12 Jul 2026 19:50:42 +0000 (21:50 +0200)] 
copy: drop COPY_REFLINK

Reflinking is a safe optimization whenever the source and destination are
regular, seekable files on a filesystem that supports cloning. Requiring each
caller to opt in through COPY_REFLINK adds flag plumbing without changing the
necessary fallback behavior.

Drop COPY_REFLINK, renumber the remaining flags, and have copy_bytes_full()
unconditionally try FICLONE or FICLONERANGE before entering its normal copy
loop. Isolate the clone attempt and its file-offset bookkeeping in a helper so
copy_bytes_full() only has to handle its cloned, unavailable, and error results.
A successful clone therefore completes in one operation, while an unsupported
or rejected clone falls back to progress-limited copy_file_range(), sendfile(),
or buffered copying. Keep the public reflink helpers for operations that
specifically require clone semantics.

Existing test-copy coverage exercises both bounded and unbounded regular-file
copies through copy_bytes_full().

Signed-off-by: Daan De Meyer <daan@amutable.com>
2 weeks agorepart: make COW behavior configurable
Daan De Meyer [Tue, 14 Jul 2026 11:04:17 +0000 (13:04 +0200)] 
repart: make COW behavior configurable

systemd-repart currently forces newly created image files into NOCOW mode.
That prevents files from being reflinked into the image, making image builds
slower and increasing their disk usage on filesystems that support cloning.

Add a tristate --cow= option. By default, leave the filesystem or parent
directory COW policy unchanged. With --cow=yes, explicitly enable COW; with
--cow=no, retain the previous behavior of forcing NOCOW. Add XO_COW as the
counterpart to XO_NOCOW so xopenat_full() applies either policy while retaining
its normal creation-error cleanup.

Document the new option and extend TEST-58-REPART to verify inherited COW and
NOCOW policies as well as explicit COW and NOCOW overrides. Compare the unset
behavior with the filesystem default so the test also works on nodatacow
mounts, and skip it when the inode attribute is unsupported.

Signed-off-by: Daan De Meyer <daan@amutable.com>
2 weeks agorules: install 60-persistent-media-controller.rules
Jason Yang [Tue, 14 Jul 2026 02:38:25 +0000 (10:38 +0800)] 
rules: install 60-persistent-media-controller.rules

Commit 04f19d673587 ("udev: Add /dev/media/by-path symlinks for media
controllers") added the rule file and the feature was announced in the
v256 NEWS, but the file was never added to the rules.d/meson.build
install list, so no build has ever shipped it and the advertised
/dev/media/by-path/ symlinks are never created.

Add it to the unconditionally installed rules.

2 weeks agosd-dhcp-relay: fix off-by-one when discarding BOOTREQUEST messages by hops count
hanjinpeng [Wed, 8 Jul 2026 07:05:51 +0000 (03:05 -0400)] 
sd-dhcp-relay: fix off-by-one when discarding BOOTREQUEST messages by hops count

According to RFC specifications
```
RFC 1542 section 4.1.1 states:
The relay agent MUST silently discard BOOTREQUEST messages whose 'hops'
   field exceeds the value 16."
```

"Exceeds the value 16" means hops > 16, i.e. a message that arrives with
hops == 16 is still valid and must be relayed (after which its hops field
becomes 17). The code used ">= 16", which silently dropped a valid message
that had legitimately traversed exactly 16 relay agents, one hop too early.

This matches the wording of the adjacent comment, which already says
"exceeds the value 16".

2 weeks agodlopen-note: drop unnecessary header
Yu Watanabe [Fri, 10 Jul 2026 16:13:10 +0000 (01:13 +0900)] 
dlopen-note: drop unnecessary header

It unexpectedly snuck in there.

Follow-up for a74b3e1778ec00a21f5d1f10947daef2c02c6ffe.

2 weeks agobcd, id128, sysupdate: tighten edge-case handling (#43018)
Luca Boccassi [Tue, 14 Jul 2026 23:03:03 +0000 (00:03 +0100)] 
bcd, id128, sysupdate: tighten edge-case handling (#43018)

2 weeks agoAssorted udev hardening fixes flagged by kres (#42903)
Luca Boccassi [Tue, 14 Jul 2026 22:21:53 +0000 (23:21 +0100)] 
Assorted udev hardening fixes flagged by kres  (#42903)

2 weeks agoresolved: fix spurious BrowseServices add/remove flapping with ifindex=0 (#42982)
Lennart Poettering [Tue, 14 Jul 2026 21:58:34 +0000 (23:58 +0200)] 
resolved: fix spurious BrowseServices add/remove flapping with ifindex=0 (#42982)

## Problem
A `BrowseServices` subscription with `"ifindex":0` (browse all
interfaces) receives a continuous flap of `added`/`removed` events for a
service that is still present — within a second, and with no goodbye
packet involved.

## Root cause
For `ifindex==0`, `mdns_browser_revisit_cache()` looked up each mDNS
scope's cache separately and called `mdns_manage_services_answer()`
**once per scope**. That function derives `removed` events by diffing
the browser's *global* discovered-service list (all interfaces, filtered
only by owner family) against the single answer it's handed. So with ≥2
mDNS-relevant interfaces of the same family, a service present on
interface A isn't in interface B's answer and is spuriously removed
while B is reconciled, then re-added on the next revisit tick.

## Fix
Accumulate the pruned cache answers from every matching mDNS scope into
one combined `DnsAnswer` and reconcile **once**, so removals diff the
global list against the union across interfaces. Items are merged with
`dns_answer_add_full()` (not `dns_answer_extend()`, which defaults each
item's `until` to `USEC_INFINITY` and would skew the RFC 6762 §5.2
TTL-maintenance schedule). The single-interface (`ifindex>0`) path is
unchanged.

## Test
`TEST-89-RESOLVED-MDNS.sh` gains `testcase_browse_ifindex_zero_no_flap`:
it adds a service-less dummy mDNS link to guarantee ≥2 same-family
scopes (the flap precondition), browses `ifindex=0`, waits for
discovery, then asserts **zero** `removed` events while every publisher
stays up. The subscription uses `varlinkctl --timeout=infinity`, since
it sits idle after discovery and the default 45s idle timeout would
sever it (and the assertion) mid-observation.

## Testing status
Builds clean; `shellcheck -x` clean. First CI round: `TEST-89`
(including this testcase) passed on all mkosi platforms; the failing
jobs all traced to unrelated flakes/infra.

2 weeks agoversion_is_valid() tweaks (#43025)
Lennart Poettering [Tue, 14 Jul 2026 21:46:40 +0000 (23:46 +0200)] 
version_is_valid() tweaks (#43025)

We have two validators, and neither really makes sense. Let's unify and
clean things up.

2 weeks agoboot: downgrade EFI_MEMORY_ATTRIBUTE_PROTOCOL warning
Aswin Murugan [Tue, 14 Jul 2026 06:07:14 +0000 (11:37 +0530)] 
boot: downgrade EFI_MEMORY_ATTRIBUTE_PROTOCOL warning

U-Boot currently does not implement EFI_MEMORY_ATTRIBUTE_PROTOCOL
even when reporting EFI version >= 2.10. Consequently, systemd-boot
emits a warning on every boot when running on U-Boot firmware.

The absence of EFI_MEMORY_ATTRIBUTE_PROTOCOL is a current
U-Boot limitation and not a condition users can remedy.
Furthermore, the EFI specification does not require all
firmware advertising EFI 2.10 or newer to implement the
protocol. As a result, the warning provides little value on
U-Boot systems while causing log_wait() to impose a 2.5-second
boot delay.

Downgrade the message to LOG_DEBUG, this keeps the diagnostic
available for debugging purposes without penalizing normal
boot time.

Signed-off-by: Aswin Murugan <aswin.murugan@oss.qualcomm.com>
2 weeks agoAssorted basic/shared/home/import hardening fixes flagged by kres (#42950)
Lennart Poettering [Tue, 14 Jul 2026 21:31:53 +0000 (23:31 +0200)] 
Assorted basic/shared/home/import hardening fixes flagged by kres (#42950)

2 weeks agosysupdate: Add ListFeatures() and ListTargets() varlink methods (#42900)
Lennart Poettering [Tue, 14 Jul 2026 21:14:22 +0000 (23:14 +0200)] 
sysupdate: Add ListFeatures() and ListTargets() varlink methods (#42900)

Following on from adding the basic varlink scaffolding to sysupdate,
let’s varlinkify a couple of the D-Bus methods. Because varlink doesn’t
have a concept of object paths, the D-Bus path structure which allows a
target to be selected has been squashed down to a target argument for
each relevant method.

Varlinkify the way to list targets, and also the way to list features
because that was simple to do at the same time.

More methods need varlinkifying in the future, but let’s do it in small
and manageable chunks.

2 weeks agotest: extend version_is_valid() testcase a bit 43025/head
Lennart Poettering [Tue, 14 Jul 2026 13:41:23 +0000 (15:41 +0200)] 
test: extend version_is_valid() testcase a bit

2 weeks agobootspec: log about invalid version strings
Lennart Poettering [Tue, 14 Jul 2026 13:41:09 +0000 (15:41 +0200)] 
bootspec: log about invalid version strings

2 weeks agoman: update version formatting requirements in os-release
Lennart Poettering [Tue, 14 Jul 2026 13:30:42 +0000 (15:30 +0200)] 
man: update version formatting requirements in os-release

Allow full UAPI.10 version strings, i.e. "+", "_", "~" and "^" too, to
match the recent reworking.

These version strings are generally distro-managed, hence use the more
liberal alphabet.

Fixes: #32785
2 weeks agostring-util: replace version_is_valid()/version_is_valid_version_spec() by a common...
Lennart Poettering [Tue, 14 Jul 2026 12:40:14 +0000 (14:40 +0200)] 
string-util: replace version_is_valid()/version_is_valid_version_spec() by a common call

Let's take inspiration from string_is_safe() and take a flags field that
allows fine tuning the validation.

Then port over all current users of either function to the new logic.
Note that this *does* change behaviour in various cases:

1. Generally: we'll now always accept the full UAPI.10 alphabet,
   including the "~" and "^" characters. As far as I can see there's no
   downside to this liberalization as none of the current consumers of
   the two functions uses these characters for anything else.

2. systemd-analyze compare-version will now accept version strings with
   "_" and "+" without complaining. I see no downside here, it just
   normalizes these debugging tools, to make them accept what most our
   other tools accept.

3. "bootctl link" will not accept empty version strings anymore
   Which is a bugfix I guess.

4. vpick will now refuse "_" and "+" in version strings. It kinda
   already did, because when parsing versions from filenames it uses "_"
   and "+" as name, architecture and attempt counter separators. We now
   systematically refuse it everywhere else in vpick too. This is hence
   a clean-up.

Fixes: #28906
Replaces: #42815 #41937

2 weeks agostring-util: reorder characters in version charset
Lennart Poettering [Tue, 14 Jul 2026 12:44:01 +0000 (14:44 +0200)] 
string-util: reorder characters in version charset

Let's bring the version string character set into a systematic order,
matching the order in which they appear and are defined in the UAPI.10
specification text.

This makes it easier to compare the relevant functions.

2 weeks agostring-util: do not accept ',' in version strings
Lennart Poettering [Tue, 14 Jul 2026 12:42:49 +0000 (14:42 +0200)] 
string-util: do not accept ',' in version strings

Allowing this apparently has been cargo-culted from my initial sysupdate
PR, but Claude and me could not find a single other software package
that uses "," as a character within version strings. Hence, let's remove
this, even though this is a compat breakage of a kind, in the hope
nobody notices. We can easily restore this if this later shows to be an
issue for people.

2 weeks agosysupdate: use strverscmp_improved() like everywhere else
Lennart Poettering [Tue, 14 Jul 2026 09:53:14 +0000 (11:53 +0200)] 
sysupdate: use strverscmp_improved() like everywhere else

At one location we accidentally called strverscmp() instead of
strverscmp_improved()

2 weeks agotimedatectl: display RTCTimeUSec in UTC format
lzwind [Tue, 14 Jul 2026 13:05:01 +0000 (21:05 +0800)] 
timedatectl: display RTCTimeUSec in UTC format

Fixes #39930

The RTCTimeUSec property was being displayed in local time format
when using 'timedatectl show', while 'timedatectl status' correctly
displayed it in UTC format. This inconsistency was due to the
bus_print_all_properties() function using TIMESTAMP_PRETTY style
for all timestamps, which formats in local time.

This fix adds special handling for RTCTimeUSec to use TIMESTAMP_UTC
style, ensuring consistent UTC display across both commands.

2 weeks agoRename basic-forward.h, sd-forward.h, and shared-forward.h to forward.h
Yu Watanabe [Fri, 10 Jul 2026 11:44:44 +0000 (20:44 +0900)] 
Rename basic-forward.h, sd-forward.h, and shared-forward.h to forward.h

Follow-up for 74d392ed1bab578e901699ee272faa0c8b922128.

2 weeks agonetwork: do not use assert() on a call with side effects
Zbigniew Jędrzejewski-Szmek [Tue, 14 Jul 2026 13:17:56 +0000 (15:17 +0200)] 
network: do not use assert() on a call with side effects

Fixes bf943a9d49941801b45e4631f010359619173d12.

2 weeks agodissect-image: don't assert() on partition geometry from blkid 42950/head
Luca Boccassi [Thu, 9 Jul 2026 14:42:38 +0000 (15:42 +0100)] 
dissect-image: don't assert() on partition geometry from blkid

The per-partition loop in dissect_image() reads the start and size (in
512-byte sectors) of each partition from libblkid and guards the
following byte conversions with assert(). Images sizes are input,
rather than programming, so return an error instead of asserting.

Follow-up for 88b3300fdc64d5320fb50d0f369d3fc0885e15e8

2 weeks agohomework-luks: add new key slots before destroying old ones
Luca Boccassi [Thu, 9 Jul 2026 14:07:54 +0000 (15:07 +0100)] 
homework-luks: add new key slots before destroying old ones

home_passwd_luks() rotates the LUKS key slots with a single loop that
destroys slot i before adding its replacement at the same index. If
adding the replacement fails (e.g.: argon2 OOMs), slot i is left
destroyed with no replacement and no rollback. If the user has only
one password, its only key slot is now gone and the home directory can
no longer be unlocked.

Rotate in two passes instead: first add every new password into a free
slot (CRYPT_ANY_SLOT), and only once all adds succeed, destroy the old
slots. If an add fails, roll back the slots added so far and return
with the pre-existing slots untouched, so at least one valid key slot
always remains for each password the user holds.

Follow-up for 70a5db5822c8056b53d9a4a9273ad12cb5f87a92

2 weeks agopull-oci: switch assert() to assert_se() for set_remove() call
Luca Boccassi [Thu, 9 Jul 2026 13:44:22 +0000 (14:44 +0100)] 
pull-oci: switch assert() to assert_se() for set_remove() call

This has obvious side effects so switch it over

Follow-up for a9f6ba04969d6eb2e629e30299fab7538ef42a57

2 weeks agocopy: avoid following fifo/node chmod target
Luca Boccassi [Thu, 9 Jul 2026 10:35:50 +0000 (11:35 +0100)] 
copy: avoid following fifo/node chmod target

Use AT_SYMLINK_NOFOLLOW when applying copied FIFO and device
node modes, matching the adjacent ownership and timestamp updates.

Follow-up for e69cc9eb36fd6e76710b4d5f4bb7013980fb5174

2 weeks agolog: add upper bound to journal iovec accounting
Luca Boccassi [Thu, 9 Jul 2026 10:30:02 +0000 (11:30 +0100)] 
log: add upper bound to journal iovec accounting

Use checked arithmetic before clamping the journal iovec length.
Stop copying input iovecs once the fixed journal vector is full.

Follow-up for e69cc9eb36fd6e76710b4d5f4bb7013980fb5174

2 weeks agostring-util: add upper bound to ellipsize_mem UTF-8 walks
Luca Boccassi [Thu, 9 Jul 2026 10:15:32 +0000 (11:15 +0100)] 
string-util: add upper bound to ellipsize_mem UTF-8 walks

Validate UTF-8 characters against the caller-provided byte slice.
This stops truncated sequences from borrowing bytes past old_length.

Follow-up for e69cc9eb36fd6e76710b4d5f4bb7013980fb5174

2 weeks agosysupdate: Allow multiple documentation URLs for a feature 42900/head
Philip Withnall [Mon, 13 Jul 2026 14:55:41 +0000 (15:55 +0100)] 
sysupdate: Allow multiple documentation URLs for a feature

Change the varlink API for Feature structs to allow multiple
documentation URLs for them, to match what systemd already does for
units etc.

This is a deviation from what the sysupdated D-Bus API allows and, for
the moment, from what’s supported internally by sysupdate. Internally it
continues to support 0-1 URLs for now.

But by defining the API as a strv, multiple URLs can be supported in
future without API breaks.

2 weeks agosysupdate: Run ListFeatures in offline mode
Philip Withnall [Thu, 9 Jul 2026 12:55:01 +0000 (13:55 +0100)] 
sysupdate: Run ListFeatures in offline mode

Historically, the ListFeatures API (in both D-Bus and now varlink) was
run without an `--offline` flag. This appears like it’s an oversight, but
actually `verb_features()` always unconditionally loaded in offline
mode.

In any case, there doesn’t appear to be a reason for the context to be
online (i.e. for it to check sources for available updates). Features are
defined in local config files and are loaded by `read_features()`, which
is called in both offline and online mode.

When the varlink ListFeatures API was added, it was put into online mode
in order to match the lack of `--offline` argument in the existing D-Bus
API implementation. Change both of them to be explicitly in offline mode.

Signed-off-by: Philip Withnall <pwithnall@gnome.org>
2 weeks agotest: Remove a redundant exit call
Philip Withnall [Mon, 22 Jun 2026 19:22:16 +0000 (20:22 +0100)] 
test: Remove a redundant exit call

`[[ blah ]] || exit 1` is equivalent to `[[ blah ]]`.

Fixes: b0ca987cd96
2 weeks agosysupdate: Downgrade an info to a debug log message
Philip Withnall [Mon, 22 Jun 2026 19:20:20 +0000 (20:20 +0100)] 
sysupdate: Downgrade an info to a debug log message

Since we now enumerate all targets on a varlink call (to validate the
requested target), this message gets printed multiple times in the log.
It’s not really necessary, so downgrade it to a debug message.

2 weeks agosysupdate: Add varlink ListTargets() method
Philip Withnall [Tue, 2 Jun 2026 14:56:28 +0000 (15:56 +0100)] 
sysupdate: Add varlink ListTargets() method

And add integration tests for it using `jq`.

2 weeks agosysupdate: Add varlink ListFeatures() method
Philip Withnall [Mon, 1 Jun 2026 17:35:54 +0000 (18:35 +0100)] 
sysupdate: Add varlink ListFeatures() method

And add integration tests for it using `jq`.

2 weeks agosysupdate: Factor out core of `features` verb
Philip Withnall [Tue, 2 Jun 2026 14:49:18 +0000 (15:49 +0100)] 
sysupdate: Factor out core of `features` verb

This will be used in the following commit to add a varlink interface for
it.

This introduces no functional changes.

2 weeks agoman: update gpt-auto-generator ESP mounting behavior
CrtlTom [Wed, 8 Jul 2026 18:14:15 +0000 (20:14 +0200)] 
man: update gpt-auto-generator ESP mounting behavior

Remove the stipulation that /boot/ must exist for the ESP to be mounted
there to reflect the change in #34550.

2 weeks agomeson: speed up building standalone binaries
Yu Watanabe [Fri, 10 Jul 2026 17:53:11 +0000 (02:53 +0900)] 
meson: speed up building standalone binaries

Previously, files listed in 'sources' were built twice:
once when building the main binary, and again when building the
statically linked one.

This change ensures that all object files from the main binary are
reused when building the static binary. Hence, the only step now
necessary for the static binary is linking the object files.

Follow-up for 39d00e1d20717e56285795335fe3172fc24f3577.

2 weeks agorepart: Properly pre-calculate auto size of images
Jonas Dreßler [Mon, 6 Jul 2026 16:23:51 +0000 (18:23 +0200)] 
repart: Properly pre-calculate auto size of images

When passing --size=auto to repart, it will pre-calculate the image size and
resize the image to that size before partitioning. Currently, that fails when
passing a large grain size, complaining that the auto-sized image is too small
to fit the data.

The reason for this is that the current code simply assumes the GPT metadata
size taken away from the usable size by fdisk is static (1044KiB), when it
actually is more complicated than that:

There's two ranges of GPT metadata: One at the beginning of the image, and one
at the end of the image. And there's the first usable block that is defined by
fdisk when creating the partition table.

The static value of 1044KiB usually works, because fdisk sets the first usable
block to 1MiB (so 1024KiB), leaving 20KiB of leeway for the secondary GPT at
the end of the image.

Now as soon as the first partition starts at an offset higher than 1024KiB, we
lose the 20KiB leeway for the secondary GPT, and the partitions will no longer
fit.

What we should do, is first of all round up to the grain size instead of 4096
(as that's the minimum offset our first partition will start at), and second of
all properly subtract the secondary GPT at the end.

Also confirm we don't regress on this anymore by adding a test that uses a 2MiB
grain size, breaking the old code.