]> git.ipfire.org Git - thirdparty/systemd.git/log
thirdparty/systemd.git
6 days agohostnamectl: document JSON status object output
dongshengyuan [Wed, 22 Jul 2026 09:23:16 +0000 (17:23 +0800)] 
hostnamectl: document JSON status object output

status with --static, --pretty, or --transient prints only the
selected hostname in regular output. JSON status output is built from
hostnamed's Describe data and remains a full status object.

Document this distinction so callers do not expect the name type
switches to turn JSON status into a single scalar value.

Follow-up for: ac8a4f6b78fe70680d3bc1704b1f85bbcbe7bb55

7 days agohomed: verify privileged worker changes
Luca Boccassi [Fri, 17 Jul 2026 19:22:24 +0000 (20:22 +0100)] 
homed: verify privileged worker changes

Workers may return a newer embedded identity while processing
an owner update. Accept self-modifiable changes, but require
privileged changes to carry a trusted signature.

Follow-up for 70a5db5822c8056b53d9a4a9273ad12cb5f87a92

7 days agorm-rf: downgrade root check log when directory doesn't exist
Luca Boccassi [Wed, 22 Jul 2026 11:14:15 +0000 (12:14 +0100)] 
rm-rf: downgrade root check log when directory doesn't exist

When a unit is stopped we try to destroy the credential mount point,
which might not exist. This logs at error level, which is noisy and
pointless. Downgrade to debug level on ENOENT.

systemd[1]: Failed to determine whether '/run/credentials/run-p119516-i119816.service' is the root file system: No such file or directory

Follow-up for 9dd2dab37e91ab4b000802d98aa7c4713836d53a

7 days agoman: document that ExitType=cgroup is rejected for Type=oneshot
Liu Zheng [Wed, 22 Jul 2026 07:31:24 +0000 (07:31 +0000)] 
man: document that ExitType=cgroup is rejected for Type=oneshot

The ExitType= documentation stated that ExitType=main "cannot be used
with Type=oneshot", which is incorrect: ExitType=main is the default
and works fine with Type=oneshot. The restriction actually enforced by
the code is that ExitType=cgroup is refused for Type=oneshot services
(see service_verify() in src/core/service.c).

Move the "cannot be used with Type=oneshot" note from the ExitType=main
bullet to the ExitType=cgroup bullet where it belongs.

Fixes #42327

Signed-off-by: Liu Zheng <liuzheng@uniontech.com>
8 days agoescape: reject UTF-16 surrogates in \u escapes in cunescape_one() (#43079)
Armaan Sandhu [Tue, 21 Jul 2026 14:40:26 +0000 (20:10 +0530)] 
escape: reject UTF-16 surrogates in \u escapes in cunescape_one() (#43079)

A `\u` escape in `cunescape_one()` was accepted for any 16-bit value
except NUL. That range `0x0000`-`0xFFFF` includes the UTF-16 surrogates
`0xD800`-`0xDFFF`, which are not valid Unicode scalar values and cannot
be encoded as valid UTF-8.

8 days agohome: insert a space before '='
Yu Watanabe [Tue, 21 Jul 2026 04:10:15 +0000 (13:10 +0900)] 
home: insert a space before '='

8 days agoman: update the sample glib/sd-event integration
Beniamino Galvani [Tue, 21 Jul 2026 11:53:24 +0000 (13:53 +0200)] 
man: update the sample glib/sd-event integration

The normal order of operations when iterating the GLib main loop is:

 - prepare()  -> sd_event_prepare()
 - poll the file descriptors
 - check()    -> sd_event_wait()
 - dispatch() -> sd_event_dispatch()

GLib does not guarantee that check() is always called between two
consecutive prepare() invocations. When another thread attaches or
removes a source with poll fds while the main thread is inside
poll(), g_main_context_check_unlocked() returns immediately without
calling any source's check() callback.

Since the sd_event GSource adapter maps prepare/check/dispatch to
sd_event_prepare/sd_event_wait/sd_event_dispatch, a skipped check()
leaves sd_event in ARMED state. The next prepare() then hits
assertion "e->state == SD_EVENT_INITIAL".

The following program reproduces the faulty scenario by creating a
thread that attaches a new fd during the poll phase:

  #include <stdio.h>
  #include <stdlib.h>
  #include <sys/socket.h>
  #include <glib.h>
  #include <systemd/sd-event.h>
  #include <unistd.h>

  /* from glib-event-glue.c */
  extern GSource *g_sd_event_create_source(sd_event *event);

  static gpointer thread_func(gpointer user_data) {
    GSource *source;
    GPollFD pollfd;
    int fd;

    g_usleep(G_USEC_PER_SEC / 10);

    fd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0);
    if (fd < 0)
      abort();

    source = g_source_new(&(GSourceFuncs){0}, sizeof(GSource));
    pollfd.fd = fd;
    pollfd.events = G_IO_IN;
    pollfd.revents = 0;
    g_source_add_poll(source, &pollfd);
    g_source_attach(source, NULL);
    g_source_destroy(source);
    g_source_unref(source);

    close(fd);

    return NULL;
  }

  int main(int argc, char *argv[]) {
    sd_event *event = NULL;
    GSource *source;
    GThread *thread;
    int i, r;

    r = sd_event_default(&event);
    if (r < 0)
      return 1;

    source = g_sd_event_create_source(event);
    if (!source)
      return 1;

    g_source_attach(source, NULL);

    for (i = 0; i < 50; i++) {
      thread = g_thread_new("check-skip", thread_func, NULL);
      g_main_context_iteration(NULL, TRUE);
      g_thread_join(thread);
      g_main_context_iteration(NULL, FALSE);
    }

    g_source_destroy(source);
    g_source_unref(source);
    sd_event_unref(event);

    return 0;
  }

When the program uses the current glue code, it crashes with:

  Assertion 'e->state == SD_EVENT_INITIAL' failed at src/libsystemd/sd-event/sd-event.c:4560, function sd_event_prepare(). Aborting.

Fix the problem by skipping sd_event_prepare() if the event is
already ARMED: it was already prepared in a previous iteration and
it can be polled immediately.

8 days agoman: document unlocked as default IMDS network mode
Guillaume Kehren [Tue, 21 Jul 2026 09:14:33 +0000 (11:14 +0200)] 
man: document unlocked as default IMDS network mode

The default IMDS network mode was changed to unlocked, but the
systemd-imdsd@.service documentation still described locked as the
default.

Fixes #42687

8 days agoprofile/systemd-osc-context: also escape $USER and $HOSTNAME 43091/head
Rasmus Villemoes [Tue, 21 Jul 2026 08:43:22 +0000 (10:43 +0200)] 
profile/systemd-osc-context: also escape $USER and $HOSTNAME

Claude pointed out that while rather unlikely, it is possible for the USER and
HOSTNAME environment variables to contain problematic characters that require
escaping. Now that that escaping no longer involves the fork+exec overhead of
calling sed, let's ensure those fields do get put through the escape routine.

Refactor __systemd_osc_context_escape so that it not only takes the value and
prints that, but also the format specifier used for emitting the field. That
way, we avoid an extra subshell (i.e. fork+pipe and all that overhead), and
combined with the previous commit, we now only spawn one subshell instead of
two per start= sequence.

That could be reduced to zero, if the "callers" were rewritten to something
like

    printf "\033]3008;start=%.64s;type=shell" "$systemd_osc_context_shell_id"
    __systemd_osc_context_common
    printf "\033\\"

but that will mean that the sequence is not emitted with a single write()
system call [which isn't really guaranteed currently either, just very likely],
so some background process could end up writing to the middle of the sequence,
thus losing that output and mangling the OSC3008 info. This in turn could be
overcome by building the whole sequence in a shell variable using 'printf -v'
and only printing at the end, but that would be a somewhat invasive change.

8 days agoprofile/systemd-osc-context: fold emitting cwd= field into __systemd_osc_context_common
Rasmus Villemoes [Tue, 21 Jul 2026 08:32:27 +0000 (10:32 +0200)] 
profile/systemd-osc-context: fold emitting cwd= field into __systemd_osc_context_common

Now that the %s specifier used to embed the common fields in the output appears
immediately before the cwd= field, we can just emit that cwd= field as part of
the common fields.

8 days agoprofile/systemd-osc-context: emit type= field first
Rasmus Villemoes [Tue, 21 Jul 2026 08:25:56 +0000 (10:25 +0200)] 
profile/systemd-osc-context: emit type= field first

Not because it is required by the specification, but it will make the following
patches simpler. Also, the fact that the spec explicitly does call out that
type= can appear at the end or in the middle suggests that people would
normally expect it to appear at the beginning.

8 days agoprofile/systemd-osc-context: don't do arithmetic expansion on systemd_exitstatus
Rasmus Villemoes [Mon, 20 Jul 2026 13:37:34 +0000 (15:37 +0200)] 
profile/systemd-osc-context: don't do arithmetic expansion on systemd_exitstatus

There's really no point in having bash do arithmetic expansion on the
systemd_exitstatus variable, i.e. have it convert the string to a number, do no
actual arithmetic, then convert it back to a string to be used as the argument to
the printf, which will again convert it to a number for the %d specifier, and
finally emit it as a decimal. Also, it deviates for no obvious reason from how
it is passed to printf in the "probably died by signal" case just above.

8 days agoprofile/systemd-osc-context: do not zero-pad pid value
Rasmus Villemoes [Mon, 20 Jul 2026 13:04:21 +0000 (15:04 +0200)] 
profile/systemd-osc-context: do not zero-pad pid value

The %.20d specifier was introduced in 2d738a0aee ("profile/systemd-osc-context:
Enforce length limits"). But, for numeric conversions, the precision is not an
upper bound, but rather a lower bound on the output width, padding as necessary
with 0 on the left. So as-is, this does not in fact limit the output to at most
20 characters.

Of course, in practice, pids on linux are never greater than 2^22, and
certainly never larger than what would fit in a 20-digit decimal. On the other
hand, that more or less guarantees that the pid= field is always emitted with
12+ leadings zeroes, which is a bit silly. Moreover, a leading 0 can cause a
parser to treat it as octal.

Since $$ does expand to the PID in decimal, just print that as a string, with the
enforced 20 character limit.

8 days agoprofile/systemd-osc-context: do not use sed for escaping
Rasmus Villemoes [Mon, 20 Jul 2026 12:49:06 +0000 (14:49 +0200)] 
profile/systemd-osc-context: do not use sed for escaping

Bash is perfectly capable of performing the simple substitutions needed for
escaping according to the OSC 3008 spec, so there is no need for the fork+exec
and other overhead of calling sed.

In fact, when writing a test for ensuring that this is a drop-in replacement, I
found out that the current sed method is flawed: If $PWD contains newline
characters, they are passed through unchanged, because sed obviously is
line-oriented.

I do not know which bash version started supporting
${foo//pattern/replacement}, but I ran the below on all Debian images from docker
hub going back to Debian 6 (EOL 2016), carrying BASH_VERSION =
4.1.5(1)-release, and they all succeeded. Since the logic otherwise relies on
PROMPT_COMMAND being an array variable, which happened in 5.1, this should be
all good.

=== test.sh ===
#!/bin/bash

echo "BASH_VERSION = $BASH_VERSION"
ret=0

using_sed() {
    echo "$1" | sed -e 's/\\/\\x5c/g' -e 's/;/\\x3b/g' -e 's/[[:cntrl:]]/⍰/g'
}

pure_bash() {
    local str="$1"
    str="${str//\\/\\x5c}"
    str="${str//;/\\x3b}"
    str="${str//[[:cntrl:]]/⍰}"
    printf "%s" "${str}"
}

do_test() {
    local r0="$1"
    local r1="$(using_sed "$r0")"
    local r2="$(pure_bash "$r0")"
    local s0="$(printf '%s' "$r0" | od -A x -t x1z -w40 | head -n1)"
    local s1="$(printf '%s' "$r1" | od -A x -t x1z -w40 | head -n1)"
    local s2="$(printf '%s' "$r2" | od -A x -t x1z -w40 | head -n1)"
    if [ "$r1" != "$r2" ] || [ "$s1" != "$s2" ] ; then
        echo "Input: $s0"
        echo "sed:   $s1"
        echo "bash:  $s2"
        ret=1
    fi
}

do_test ''
do_test "one ; semicolon"
do_test "two ; semicolons ;"
do_test 'bs \ sc ; bs \ sc ;'
do_test $'\t'
do_test $'sc ; cntrl \x01 \x02 \x03 \x1f \t bs \\ bs \\ sc ; '
do_test $'sc ; tab \x09 del \x7f  bs \\ ;'

# The last cases show that the existing function doesn't actually work in
# the case of $PWD containing a newline character, because sed is
# line-oriented, so a newline character will never be replaced.
if [ "$1" = "all" ] ; then
    do_test $'embedded \n newline'
    do_test $'ending in newline\n'
fi

exit "$ret"
=== test.sh ===

8 days agoAssorted cleanups for #42978 (#43051)
Yu Watanabe [Tue, 21 Jul 2026 05:03:49 +0000 (14:03 +0900)] 
Assorted cleanups for #42978 (#43051)

https://github.com/systemd/systemd/pull/42978

8 days agohomed/fscrypt: default new homes to v2 policies 42397/head
Ananth Bhaskararaman [Tue, 2 Jun 2026 21:42:04 +0000 (03:12 +0530)] 
homed/fscrypt: default new homes to v2 policies

fscrypt v1 policies bind master keys to the calling process's keyring,
which means files in a homed-managed directory aren't readable when
accessed through a container bind mount, a different mount namespace,
or by any process other than the one that first unlocked the home.
Reading a file from outside such a context first warms the buffer cache
and papers over the symptom (#18280), but the underlying problem (the
key not flowing across keyrings) remains.

v2 policies (Linux 5.4+) route master keys through the filesystem
keyring via FS_IOC_ADD_ENCRYPTION_KEY / FS_IOC_REMOVE_ENCRYPTION_KEY,
so the key is visible to every process accessing the filesystem.

Switch homed to v2:

- Read the existing policy via FS_IOC_GET_ENCRYPTION_POLICY_EX, which
  reports both v1 and v2 policies. The ioctl is available since Linux
  5.4, i.e. on every kernel we support (our baseline is 5.10), so no
  fallback to the v1-only FS_IOC_GET_ENCRYPTION_POLICY is needed.
- Drive slot matching off a full fscrypt_key_specifier (HomeSetup now
  carries that instead of a bare 8-byte descriptor). Slot decryption
  derives either the v1 descriptor (SHA-512 double hash) or the v2
  identifier (HKDF-SHA512 with the kernel's info string), and compares
  against the policy.
- Install the master key the right way per version: add_key("logon", ...)
  to thread+user keyrings for v1, FS_IOC_ADD_ENCRYPTION_KEY for v2.
- home_flush_keyring_fscrypt opens the image directory, looks up the
  policy, and either calls FS_IOC_REMOVE_ENCRYPTION_KEY (v2) or walks
  the user keyring (v1).
- New homes default to v2; fall back to v1 only if the kernel rejects
  FS_IOC_ADD_ENCRYPTION_KEY with ENOTTY/EOPNOTSUPP. The v2 create path
  derives the identifier locally first, passes it to ADD_KEY as
  expected_identifier, and cleans up via REMOVE_KEY if SET_POLICY then
  fails, so the v1 fallback never sees a stranded key. Existing v1
  homes continue to unlock, rekey, and deactivate as before.
- A v2 master key installed to work on an inactive home is always
  removed again unless that home ends up activated. v2 keys persist in
  the filesystem keyring until removed explicitly (v1 keys instead died
  with the homework process' keyring), so a key left behind would leave
  a home nobody activated readable until the next deactivation or reboot.
  home_setup_fscrypt() and home_create_fscrypt() therefore arm a rollback
  right after installing the key; the activation path disarms it once the
  mount is in place (the live home owns the key), while every other path
  -- create, and passwd/update/resize of an inactive home, plus all error
  paths -- rolls it back via home_setup_done(). Activation reinstalls the
  key.

The v1 and v2 on-disk policy formats differ (v1: 8-byte descriptor;
v2: 16-byte identifier) and fscrypt has no in-place upgrade path, so
a v1 home is always unlocked via the v1 code path and a v2 home is
always unlocked via the v2 code path, regardless of kernel version.

Slot xattr format is unchanged: the master key is the same, only how it
binds to the directory changes.

Fixes #18280.

Ananth Bhaskararaman antsub@gmail.com

8 days agoshared/crypto-util: add HKDF (RFC 5869) derivation helper
Ananth Bhaskararaman [Tue, 2 Jun 2026 21:41:59 +0000 (03:11 +0530)] 
shared/crypto-util: add HKDF (RFC 5869) derivation helper

Mirrors the existing kdf_ss_derive / kdf_kb_hmac_derive helpers, wrapping
OpenSSL's "HKDF" EVP_KDF. Inputs and output are passed as struct iovec;
salt and info are optional (pass NULL or an empty iovec to omit). If
salt is omitted HKDF substitutes HashLen zero-bytes per RFC 5869.

The digest is a parameter now, so reimplement the existing SHA256-only
kdf_hkdf_sha256() as a thin wrapper around the new helper, keeping the
OpenSSL HKDF plumbing in one place.

Add test vectors against RFC 5869 Appendix A.1 and against the kernel's
fscrypt v2 master-key identifier construction (HKDF-SHA512 with empty
salt and info "fscrypt\x00\x01"), so future consumers can rely on the
helper matching that exact derivation.

8 days agotools: reject invalid inputs and align machine-readable output (#43040)
Yu Watanabe [Tue, 21 Jul 2026 03:23:00 +0000 (12:23 +0900)] 
tools: reject invalid inputs and align machine-readable output (#43040)

8 days agosd-device: allow non-safe characters in uevent files
Yu Watanabe [Fri, 17 Jul 2026 18:24:34 +0000 (03:24 +0900)] 
sd-device: allow non-safe characters in uevent files

This partially reverts 13ce62caba10e0dfa715dfa5c3ab551dedb02095.

Sometimes, the kernel passes non-safe characters in uevent files,
such as the UNIQ= property for USB serial devices.

Instead of rejecting the entire uevent file, let's only ignore the
specific key-value pairs that contain non-safe characters.

Fixes #43008.

8 days agohwdb: strip the root from filenames when generating hwdb.bin (#43062)
Yu Watanabe [Tue, 21 Jul 2026 03:19:00 +0000 (12:19 +0900)] 
hwdb: strip the root from filenames when generating hwdb.bin (#43062)

The modern hwdb.bin format contains the filenames of the input data that
makes up the database. This is useful but in offline builds where --root
is used, the filenames are the full build paths including the specified
root. This introduces build paths and thus information leakage and
non-reproducible data.

Solve this by stripping the root prefix off the original path when
passing to import_file.

9 days agohwdb: classify PlayStation controller audio as controller form-factor
Julian Bouzas [Mon, 20 Jul 2026 13:54:48 +0000 (09:54 -0400)] 
hwdb: classify PlayStation controller audio as controller form-factor

Add Sony PlayStation controller entries to 70-sound-card.hwdb so that their
ALSA sound devices are tagged with SOUND_FORM_FACTOR=controller:
 - DualSense (054c:0ce6)
 - DualSense Edge (054c:0df2)
 - DualShock 4 CUH-ZCT1x (054c:05c4)
 - DualShock 4 CUH-ZCT2x (054c:09cc)

These controllers expose USB audio but are neither headsets nor speakers.
Pinning them in the hwdb ensures they are identified correctly before any
fallback matching occurs.

9 days agohwdb: strip the root from filenames when generating hwdb.bin 43062/head
Ross Burton [Fri, 17 Jul 2026 16:25:31 +0000 (17:25 +0100)] 
hwdb: strip the root from filenames when generating hwdb.bin

The modern hwdb.bin format contains the filenames of the input data that
makes up the database.  This is useful but in offline builds where
--root is used, the filenames are the full build paths including the
specified root.  This introduces build paths and thus information
leakage and non-reproducible data.

Solve this by stripping the root prefix off the original path when
passing to import_file.

Add TEST-17-UDEV.hwdb.sh to verify that hwdb.bin files contain the
path inside the root, but not the path of the root.

9 days agopo: update Japanese translation
Yu Watanabe [Mon, 20 Jul 2026 06:22:56 +0000 (15:22 +0900)] 
po: update Japanese translation

9 days agoman/network: fix default value for RequiredFamilyForOnline=
Yu Watanabe [Mon, 20 Jul 2026 05:06:40 +0000 (14:06 +0900)] 
man/network: fix default value for RequiredFamilyForOnline=

It was unexpectedly changed by c89efaf9e5b0d8820dff51edfa7a0e576ed8b3b2.

Fixes #43074.

9 days agoFix typos reported by Fossies (#43084)
Luca Boccassi [Mon, 20 Jul 2026 11:38:47 +0000 (12:38 +0100)] 
Fix typos reported by Fossies (#43084)

9 days agoudev: drop home-grown udev-ctrl socket (#40802)
Luca Boccassi [Mon, 20 Jul 2026 11:37:27 +0000 (12:37 +0100)] 
udev: drop home-grown udev-ctrl socket (#40802)

Nowadays, varlink is used to control systemd-udevd. Let's drop the
legacy socket.

Note, the existence of /run/udev/control socket is widely used in both
our code and external projects. Also, the dependency to
systemd-udevd-control.socket is widely used in many projects. Hence, we
need to create a symlink to the socket file and .socket unit file.

9 days agohwdb: add debug logging for the output filename
Ross Burton [Mon, 20 Jul 2026 09:38:43 +0000 (10:38 +0100)] 
hwdb: add debug logging for the output filename

It's useful to see exactly what file was written to when updating the
HWDB.

9 days agomkosi: update debian commit reference to 56402b2bde258999a8f01a8b04465fde9242d6a1 40802/head
Luca Boccassi [Mon, 20 Jul 2026 09:58:51 +0000 (10:58 +0100)] 
mkosi: update debian commit reference to 56402b2bde258999a8f01a8b04465fde9242d6a1

56402b2bde Drop symlink to systemd-udevd-control.socket
3afaaf4f89 Install new files for upstream build

9 days agohostname-util: strip all trailing separators in hostname_cleanup() (#43077)
Armaan Sandhu [Mon, 20 Jul 2026 07:35:12 +0000 (13:05 +0530)] 
hostname-util: strip all trailing separators in hostname_cleanup() (#43077)

Fixes #43054.

9 days agosysinstall: fix typo 43084/head
Yu Watanabe [Mon, 20 Jul 2026 06:02:59 +0000 (15:02 +0900)] 
sysinstall: fix typo

Follow-up for c17d0c7e8505c985dfe8581a7fba1b3edf760d7f.

9 days agotpm2-util: fix typo
Yu Watanabe [Mon, 20 Jul 2026 06:01:28 +0000 (15:01 +0900)] 
tpm2-util: fix typo

Follow-up for 2348941b5dab8b5851553a5271c0dbe7c7ad838a.

9 days agotpm2-util: fix typo
Yu Watanabe [Mon, 20 Jul 2026 06:00:49 +0000 (15:00 +0900)] 
tpm2-util: fix typo

Follow-ups for 5a80137aa449ff0870210eb87077a5ce3ab8680b.

9 days agonetwork: fix typo
Yu Watanabe [Mon, 20 Jul 2026 05:58:30 +0000 (14:58 +0900)] 
network: fix typo

Follow-up for d094067547fb8dd91c637981cf6b1870ee2c08de.

9 days agostring-util: fix typo
Yu Watanabe [Mon, 20 Jul 2026 05:56:32 +0000 (14:56 +0900)] 
string-util: fix typo

Follow-up for 093cac3fe8b4561b2a4662df9151156dac745457.

9 days agoreport: fix typo
Yu Watanabe [Mon, 20 Jul 2026 05:55:11 +0000 (14:55 +0900)] 
report: fix typo

Follow-up for 3c2f7c6002254fa7108e186aeedf2b2c6a86bd4f.

9 days agosysupdate: fix typo
Yu Watanabe [Mon, 20 Jul 2026 05:53:45 +0000 (14:53 +0900)] 
sysupdate: fix typo

Follow-up for d82e256bb9d151b185a8afec1fcacd8fbe80555c.

9 days agoTODO: fix typo
Yu Watanabe [Mon, 20 Jul 2026 05:51:46 +0000 (14:51 +0900)] 
TODO: fix typo

Follow-ups for f61e1e5cf4e39d0bfc1edb4edb17ea25073203ff and
3d0309ac0fe7adf35fe83e43c0261611bce300de.

9 days agonetworkctl,networkd: add --no-reconfigure flag to networkctl reload
Nandakumar Raghavan [Thu, 16 Jul 2026 16:08:27 +0000 (16:08 +0000)] 
networkctl,networkd: add --no-reconfigure flag to networkctl reload

Add a new --no-reconfigure flag to 'networkctl reload' that reloads
.network and .netdev files from disk without reconfiguring any network
interfaces. This may be useful to avoid reconfiguring multiple interfaces
simultaneously when multiple .network files are updated, or when an updated
.network file is applied to multiple interfaces.

On the networkd side, manager_reload() gains a reconfigure_links parameter
that gates the per-link reconfiguration loop. A new io.systemd.Network.Reload
varlink method is added that exposes this as an optional reconfigureLinks
boolean (defaults to true). Both plain 'networkctl reload' and
'--no-reconfigure' now unconditionally call this method first. If an older
networkd returns MethodNotFound, plain reload falls back to
io.systemd.service.Reload for backward compatibility; '--no-reconfigure'
fails with a clear error in that case.

9 days agocore/dbus: do not block the manager on GetId during bus (re-)connection
Sinity [Sat, 11 Jul 2026 14:15:31 +0000 (16:15 +0200)] 
core/dbus: do not block the manager on GetId during bus (re-)connection

bus_init_api() issued a synchronous GetId call on every API bus
(re-)connection to decide whether saved subscription state could be
coldplugged onto the new connection.

If the D-Bus socket unit is listening while the message bus daemon
behind it is gone, connect() succeeds against the socket backlog but
nothing answers the authentication handshake. The synchronous call
then blocks PID 1 for BUS_AUTH_TIMEOUT (90 seconds by default), and
queued bus operations can trigger repeated reconnection attempts.
This was observed during shutdown as roughly 15 minutes of teardown
progressing only in 90-second intervals.

Query the instance ID asynchronously on every connection. Defer API
setup until the reply is processed, so saved subscriptions are
validated and coldplugged before new subscription requests can arrive.
If the query cannot be queued or its reply is invalid, discard the
unvalidated state and expose the API without blocking the manager.

Reset the live bus ID on every connection and serialize pending bus ID
and subscription state across reload and reexec. During daemon-reload,
preserve state that was already awaiting the asynchronous reply while
discarding the duplicate state produced by the reload itself.

Also remove the now-unused synchronous bus_get_instance_id() helper.

10 days agoManage dlopen notes at beginning of execution, and downgrade priorities in shared...
Zbigniew Jędrzejewski-Szmek [Sun, 19 Jul 2026 19:23:47 +0000 (21:23 +0200)] 
Manage dlopen notes at beginning of execution, and downgrade priorities in shared libraries (#43060)

10 days agoportable: tighten image handling and command error reporting (#43033)
Zbigniew Jędrzejewski-Szmek [Sun, 19 Jul 2026 19:09:24 +0000 (21:09 +0200)] 
portable: tighten image handling and command error reporting (#43033)

Let's further improve portable image handling and command error
reporting.

10 days agoImprove sysinstall messages (#43050)
Zbigniew Jędrzejewski-Szmek [Sun, 19 Jul 2026 18:16:06 +0000 (20:16 +0200)] 
Improve sysinstall messages (#43050)

I was trying to use systemd-sysinstall and those are the fixes for
various ugly parts that are immediately obvious when it is used.

10 days agoboot: cover BCD offsets past the buffer
dongshengyuan [Fri, 17 Jul 2026 02:44:03 +0000 (10:44 +0800)] 
boot: cover BCD offsets past the buffer

Add a zero-length test for offset > max so the first bounds guard
is covered separately from the length overflow check.

Follow-up: 231857cfe8da749925ee2beb1352e74fa96f1372

10 days agopassword-quality-util-passwdqc: restore password-quality-util.h include
Alexey Shabalin [Sat, 18 Jul 2026 14:41:33 +0000 (17:41 +0300)] 
password-quality-util-passwdqc: restore password-quality-util.h include

suggest_passwords() references the N_SUGGESTIONS macro, which is defined in
password-quality-util.h. Commit ff33c8f87d ("Extend test-dlopen-so to also
cover cases when built without support") introduced the per-backend split
headers: for the pwquality backend it added the new
password-quality-util-pwquality.h include while keeping password-quality-util.h,
but for the passwdqc backend it replaced password-quality-util.h with
password-quality-util-passwdqc.h (which only pulls in shared-forward.h). As a
result N_SUGGESTIONS is no longer declared in the passwdqc translation unit and
the build fails when the passwdqc backend is enabled.

The passwdqc backend is not exercised by the default CI, so this went
unnoticed. Add the include back, matching the pwquality backend.

10 days agosystemd-imds-generator: fix import docs
Arian van Putten [Sat, 18 Jul 2026 16:02:45 +0000 (18:02 +0200)] 
systemd-imds-generator: fix import docs

We only run import in the initrd by default. Clarify this.

11 days agorun: split out polkit ops into separate .c file (#43047)
Lennart Poettering [Sat, 18 Jul 2026 09:03:36 +0000 (11:03 +0200)] 
run: split out polkit ops into separate .c file (#43047)

11 days agocreds: reject empty validity intervals 43040/head
dongshengyuan [Thu, 16 Jul 2026 06:44:08 +0000 (14:44 +0800)] 
creds: reject empty validity intervals

Reject credentials whose not-after timestamp is equal to the timestamp
at each encryption entry point.

Reproducer: systemd-creds --timestamp=TS --not-after=TS encrypt in out

Before: encryption succeeded, but decrypt refused the credential as not
in order.

Follow-up: 21bc0b6fa1de44b520353b935bf14160f9f70591

11 days agodissect: include image size in JSON output
dongshengyuan [Thu, 16 Jul 2026 06:39:42 +0000 (14:39 +0800)] 
dissect: include image size in JSON output

Use the image metadata size when building JSON output, matching the
value already shown by the text output.

Reproducer: systemd-dissect --json=short image.raw

Before: text output showed Size, but JSON omitted the top-level size
field.

Follow-up: be5bee2a132d2d3b45d79bb3f27b05bbc767cd0a

11 days agosysupdate: keep JSON check-new exit status consistent
dongshengyuan [Thu, 16 Jul 2026 06:37:01 +0000 (14:37 +0800)] 
sysupdate: keep JSON check-new exit status consistent

Return failure for --json check-new when no candidate is available.
Let sysupdated accept that exact JSON no-update result from workers.

Reproducer: systemd-sysupdate --verify=no --json=short check-new

Before: the command printed {"available":null} and exited successfully.

Follow-up: 42c0b689a800b2ec7cceb1528d3834bf9b3417f8

11 days agorepart: skip generated files during dry runs
dongshengyuan [Thu, 16 Jul 2026 06:32:14 +0000 (14:32 +0800)] 
repart: skip generated files during dry runs

Skip generated fstab and crypttab output when --dry-run=yes is used,
after confirming there is eligible content to generate.

Reproducer: systemd-repart --dry-run=yes --generate-fstab=/tmp/root/etc/fstab -

Before: the command exited successfully and still wrote the requested
fstab file.

Follow-up: 1a0541d44c78ced78a566051ec8f63417370aeaa

11 days agofirstboot: validate root shell credentials
dongshengyuan [Thu, 16 Jul 2026 06:23:35 +0000 (14:23 +0800)] 
firstboot: validate root shell credentials

Validate passwd.shell.root after reading the credential so it uses
the same target-root shell checks as --root-shell= and prompted input.

Reproducer: CREDENTIALS_DIRECTORY=... systemd-firstboot --root=...
with passwd.shell.root=/bin/nonexistentshell

Before: /etc/passwd was written with the nonexistent root shell and
the command exited successfully.

Follow-up: 416f7b3a11e00d1a43da950fb4a00bc6c2707013

11 days agosysusers: validate shell credentials
dongshengyuan [Thu, 16 Jul 2026 06:21:02 +0000 (14:21 +0800)] 
sysusers: validate shell credentials

Validate passwd.shell.<user> credentials with the same login-shell
rules used for sysusers.d shell fields before writing passwd entries.

Reproducer: CREDENTIALS_DIRECTORY=... systemd-sysusers --root=...
with --inline 'u creduser 999 "Cred User" / -'

Before: relative-shell was written as the login shell and the command
exited successfully.

Follow-up: 99e9f896fb491d13c6d02f6f5bbfceabae833f05

12 days agorun: simplify timer property handling 43047/head
Lennart Poettering [Thu, 16 Jul 2026 14:44:44 +0000 (16:44 +0200)] 
run: simplify timer property handling

Let's make timer prop handling less special, and more like path/socket
handling. Let's move the checks for at least one OnXYZ= setting to a
common place at the end of parsing, instead of explicit checks for each
property.

12 days agorun: split out polkit ops into separate .c file
Lennart Poettering [Mon, 13 Jul 2026 21:47:34 +0000 (23:47 +0200)] 
run: split out polkit ops into separate .c file

Let's shorten an already very long .c file, by splitting it apart a bit.

Splitting out the polkit code is relatively easy, since it does not
touch any of the arg_xyz variables.

12 days agomkosi/opensuse: do not try to package non-existent symlink to systemd-udevd-control...
Yu Watanabe [Thu, 4 Jun 2026 19:07:45 +0000 (04:07 +0900)] 
mkosi/opensuse: do not try to package non-existent symlink to systemd-udevd-control.socket

12 days agoNEWS: mention the removeal of legacy udev control socket
Yu Watanabe [Thu, 4 Jun 2026 19:18:48 +0000 (04:18 +0900)] 
NEWS: mention the removeal of legacy udev control socket

12 days agoudev: drop home-grown udev-ctrl socket
Yu Watanabe [Sun, 22 Feb 2026 16:01:45 +0000 (01:01 +0900)] 
udev: drop home-grown udev-ctrl socket

Nowadays, varlink is used to control systemd-udevd. Let's drop the
legacy socket.

Note, the existence of /run/udev/control socket is widely used in both
our code and external projects. Also, the dependency to
systemd-udevd-control.socket is widely used in many projects.
Hence, we need to create a symlink to the socket file and .socket unit
file.

12 days agonspawn: do not try to connect udevd
Yu Watanabe [Tue, 2 Jun 2026 02:45:15 +0000 (11:45 +0900)] 
nspawn: do not try to connect udevd

nspawn itself does not require to control udevd process.

Only necessary points are
- udevd is available, and
- we are in the main network namespace.

Let's check them explicitly.

This also makes the check is skipped when we are talking to mountfsd, as
the check is pointless in that case.

12 days agosd-device: use network_namespace_is_init()
Yu Watanabe [Tue, 2 Jun 2026 02:37:52 +0000 (11:37 +0900)] 
sd-device: use network_namespace_is_init()

12 days agonamespace-util: introduce network_namespace_is_init()
Yu Watanabe [Tue, 2 Jun 2026 02:32:26 +0000 (11:32 +0900)] 
namespace-util: introduce network_namespace_is_init()

12 days agodocs: clarify scope of portable services
acandoo [Fri, 17 Jul 2026 19:09:07 +0000 (15:09 -0400)] 
docs: clarify scope of portable services

Removed note clarifying that portable services are only for system services and not user services, and changed comparisons to "system services" with just "services". With newer systemd versions, `systemd-portabled` can be run as a user service.

12 days agodlopen-note: downgrade all dlopen notes in libsystemd.so and libsystemd-shared.so 43060/head
Yu Watanabe [Fri, 10 Jul 2026 16:20:47 +0000 (01:20 +0900)] 
dlopen-note: downgrade all dlopen notes in libsystemd.so and libsystemd-shared.so

Since all executables now manage their required dlopen notes directly
within their own source code with explicit priority levels, it is no
longer necessary to declare high-priority dlopen notes in the shared
libraries themselves.

12 days agotree-wide: drop DLOPEN_FOO() macros
Yu Watanabe [Fri, 10 Jul 2026 14:59:06 +0000 (23:59 +0900)] 
tree-wide: drop DLOPEN_FOO() macros

Since 4c0d8d967300fde858f83ec4b361db19e3e257c8, most dlopen notes are
set at the beginning of the executables. Let's manage all dlopen notes
there, rather than setting them where dlopen is called.

Note that the only exceptions are the LIBBPF_NOTE for networkd and
nsresource. Since dlopen_bpf() is wrapped in an `#if` guard, the notes
are instead set within the corresponding functionality.

As a result, the DLOPEN_FOO() wrapper macros are no longer needed and
can be dropped completely.

12 days agosd-dlopen: make header self-standing again
Luca Boccassi [Fri, 17 Jul 2026 11:10:01 +0000 (12:10 +0100)] 
sd-dlopen: make header self-standing again

The purpose of this header was to provide MIT-0 sources that can be copied
and pasted liberally. Including an LGPL-2.1+ header from it deafeats its
purpose. Make it self-standing again.

Follow-up for aa0db003cf537aeb051cc51a2f7e95d51a5756cd

12 days agoupdate TODO
Lennart Poettering [Thu, 16 Jul 2026 14:30:12 +0000 (16:30 +0200)] 
update TODO

12 days agonspawn: use chase() for creating dev nodes (#43037)
Luca Boccassi [Fri, 17 Jul 2026 08:02:28 +0000 (09:02 +0100)] 
nspawn: use chase() for creating dev nodes (#43037)

12 days agorepart: fix varlink description string 43050/head
Zbigniew Jędrzejewski-Szmek [Fri, 17 Jul 2026 07:21:59 +0000 (09:21 +0200)] 
repart: fix varlink description string

Fixup for 1c76e204d3eb2e43918ddd18c9a93eed8facedfd.

12 days agonetwork: silence false warning about unitialized variable
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 13:17:33 +0000 (15:17 +0200)] 
network: silence false warning about unitialized variable

[1177/3647] Compiling C object systemd-networkd.p/src_network_networkd-bridge-vlan.c.o
In function ‘bridge_vlan_append_set_info’,
    inlined from ‘bridge_vlan_set_message’ at ../src/network/networkd-bridge-vlan.c:257:21:
../src/network/networkd-bridge-vlan.c:162:28: warning: ‘untagged’ may be used uninitialized [-Wmaybe-uninitialized]
  162 |                         if (untagged == u)
      |                            ^
../src/network/networkd-bridge-vlan.c: In function ‘bridge_vlan_set_message’:
../src/network/networkd-bridge-vlan.c:111:14: note: ‘untagged’ was declared here
  111 |         bool untagged, pvid_is_untagged;
      |              ^~~~~~~~

12 days agosysinstall: don't ask whether to erase a disk that contains no partitions
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 16:11:31 +0000 (18:11 +0200)] 
sysinstall: don't ask whether to erase a disk that contains no partitions

When the target disk carried no partitions, the installer still asked:

    Please type 'keep' to install the OS in addition to what the disk
    already contains, or 'erase' to erase all data on the disk:

The question is meaningless in that case: there's nothing on the disk
worth preserving, and both answers lead to the same result.

Modify fsystemd-repart to report in the dry-run reply of
io.systemd.Repart.Run() the number of partitions currently on the disk.
The field is only included if the existing partition table was actually
read, i.e. in the 'refuse' and 'allow' empty modes, and omitted
otherwise.

Make systemd-sysinstall skip the erase question if the reply positively
indicates that there are no partitions, proceeding as if 'keep' was
selected.

12 days agosysinstall: suppress 'no' prompt to begin installation
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 17:03:18 +0000 (19:03 +0200)] 
sysinstall: suppress 'no' prompt to begin installation

The user has to type 'yes', but it doesn't mean that the default of
'no' is ever useful. Suppress it, so the user doesn't have to press
backspace twice.

12 days agoid128: reject app-specific IDs for new
dongshengyuan [Thu, 16 Jul 2026 06:18:01 +0000 (14:18 +0800)] 
id128: reject app-specific IDs for new

Reject --app-specific= for the new verb. The option only makes sense
for verbs that derive IDs from an existing base ID.

Reproducer: systemd-id128 new --app-specific=4f68bce3e8cd4db196e7fbcaf984b709

Before: the command printed a random ID and exited successfully.

Follow-up: 0d1d512f7f42071595f0c950f911f3557fda09ea

13 days agonspawn: use chase() for creating dev nodes 43037/head
Luca Boccassi [Thu, 16 Jul 2026 16:41:05 +0000 (17:41 +0100)] 
nspawn: use chase() for creating dev nodes

Follow-up for de40a3037af944f6803375f2f5269cffc4247f56

13 days agoshift-uid: use TAKE_FD on input fd 43051/head
Luca Boccassi [Thu, 16 Jul 2026 18:21:48 +0000 (19:21 +0100)] 
shift-uid: use TAKE_FD on input fd

Follow-up for c3eafb10a0b886876316bca6f9af06db67308ad0

13 days agorm-rf: use faccessat instead of fstatat
Luca Boccassi [Thu, 16 Jul 2026 18:20:57 +0000 (19:20 +0100)] 
rm-rf: use faccessat instead of fstatat

Follow-up for 9dd2dab37e91ab4b000802d98aa7c4713836d53a

13 days agonspawn: log at error level before exiting if parsing OCI fails
Luca Boccassi [Wed, 15 Jul 2026 14:39:40 +0000 (15:39 +0100)] 
nspawn: log at error level before exiting if parsing OCI fails

Currently it silently errors out, with nothing at all printed on the
console

Follow-up for de40a3037af944f6803375f2f5269cffc4247f56

13 days agoboot: fix MEMMAP_DEVICE_PATH EndingAddress field calculation
Lennart Poettering [Thu, 16 Jul 2026 13:59:08 +0000 (15:59 +0200)] 
boot: fix MEMMAP_DEVICE_PATH EndingAddress field calculation

Let's do what EDK2 does.

Fixes: #43038
13 days agoudev-util: bound leading whitespace skip in udev_replace_whitespace (#42757)
Yu Watanabe [Thu, 16 Jul 2026 16:16:07 +0000 (01:16 +0900)] 
udev-util: bound leading whitespace skip in udev_replace_whitespace (#42757)

udev_replace_whitespace() is documented to read at most 'len' bytes from
'str':
- the strspn() skip of leading whitespace stops at a non-space byte or
NUL, not at 'len'
- ata_id passes the space padded, non-NUL-terminated ATA IDENTIFY
model/serial/fw fields
- an all-blank field reads off the end of the 512-byte hd_driveid stack
struct
Capped the skip to 'len'; existing outputs are unchanged. Added a
regression test.

13 days agoAssorted remote/shared/resolved hardening fixes flagged by kres (#42978)
Yu Watanabe [Thu, 16 Jul 2026 16:12:32 +0000 (01:12 +0900)] 
Assorted remote/shared/resolved hardening fixes flagged by kres (#42978)

13 days agoRebased and reapplied the fix, dropped the test case.
xiahualiu [Tue, 14 Jul 2026 15:07:29 +0000 (08:07 -0700)] 
Rebased and reapplied the fix, dropped the test case.

13 days agodiscover-image: don't ignore symlinks to raw images
Frantisek Sumsal [Tue, 14 Jul 2026 11:37:38 +0000 (13:37 +0200)] 
discover-image: don't ignore symlinks to raw images

Since 5c6bb289990ba53898cbc62db6e732ecb9dc87ac image_discover() uses
chaseat() to chase the path to the image. This however breaks the raw
image check in image_make() as "path" is now not the symlink itself, but
the symlink target.

So with:

$ ls -l /var/lib/machines
total 872104
lrwxrwxrwx. 1 root root         12 Jul 14 06:10 foo.raw -> foo.squashfs
-rw-r--r--. 1 root root 5368709120 Jul 13 02:07 foo.squashfs

The endswith(path, ".raw") check is now performed on "/.../foo.squashfs"
instead of "/.../foo.raw", making it false and thus ignoring the image
symlink completely.

Address this by also checking if the pretty name is set - if so, and the
path is a regular file, the caller must've been image_find() or
image_discover() which already checked if the original path ends in .raw
and is a regular file.

Follow-up for 5c6bb289990ba53898cbc62db6e732ecb9dc87ac.

Resolves: #41656

13 days agohomed: fix verification of local identity file
Luca Boccassi [Tue, 14 Jul 2026 18:23:28 +0000 (19:23 +0100)] 
homed: fix verification of local identity file

Follow-up for 70a5db5822c8056b53d9a4a9273ad12cb5f87a92

13 days agoAssorted coverity issues (#43035)
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 12:20:25 +0000 (14:20 +0200)] 
Assorted coverity issues (#43035)

13 days agoAssorted network hardening fixes flagged by kres (#43014)
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 12:15:18 +0000 (14:15 +0200)] 
Assorted network hardening fixes flagged by kres (#43014)

13 days agorepart: log allocation failure at debug level in Varlink service mode
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 11:45:23 +0000 (13:45 +0200)] 
repart: log allocation failure at debug level in Varlink service mode

When systemd-sysinstall probes whether an installation would fit by
calling io.systemd.Repart.Run() in dry-run mode, systemd-repart runs as
a child process sharing sysinstall's stderr. When the requested
partitions didn't fit, context_ponder() logged its failure at LOG_ERR
before vl_method_run() converted it into a structured Varlink error
(InsufficientFreeSpace or DiskTooSmall), which the client then reports
to the user in its own words. The internal message hence appeared
interleaved with the user-facing report:

    Can't fit requested partitions into available free space (1.9G), refusing.
    The selected disk is not large enough for an OS installation.
    The size of the selected disk is 0B, but a minimal size of 15.7G is required.

Log at LOG_DEBUG when running as a Varlink service, and keep LOG_ERR
for CLI invocations, where this message is the primary error report
shown to the user.

13 days agorepart: report the actual block device size in currentSizeBytes
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jul 2026 11:33:55 +0000 (13:33 +0200)] 
repart: report the actual block device size in currentSizeBytes

The io.systemd.Repart interface documents the currentSizeBytes field as
the size of the selected block device, both in the Run() method's
dry-run reply and in the InsufficientFreeSpace and DiskTooSmall errors.
The implementation however filled it in from the "current size"
computed by determine_auto_size(), which means something else entirely:
the size of the image as it currently exists, i.e. the GPT metadata
overhead plus the sizes of all existing partitions — a metric designed
for growing image files with --size=auto. For a disk that is being
partitioned from scratch (i.e. carries no partition table yet) that
value is 0.

As a result, when systemd-sysinstall was pointed at a blank 2G disk
that is too small for the OS installation, it reported:

    The selected disk is not large enough for an OS installation.
    The size of the selected disk is 0B, but a minimal size of 15.7G is required.

Report context->total instead, i.e. the actual size of the block
device, which is also the value the DiskTooSmall check compares the
required size against. Do this in all three places that send
currentSizeBytes, matching the documented semantics of the field.

13 days agosysupdate: add config file with metadata for sysupdate components (#42651)
Luca Boccassi [Thu, 16 Jul 2026 11:48:10 +0000 (12:48 +0100)] 
sysupdate: add config file with metadata for sysupdate components (#42651)

This carries some metadata for components. It's supposed to grow a bit,
and include a way to enable/disable transfers, and to condition them.

13 days agorepart,dissect: explicitly support DDIs that are both signed *and* encrypted (#43009)
Lennart Poettering [Thu, 16 Jul 2026 11:40:49 +0000 (13:40 +0200)] 
repart,dissect: explicitly support DDIs that are both signed *and* encrypted (#43009)

This is a pretty relevant usecase: preparing an image on some trusted
host, submitting it to some other host that authenticates it and
decrypts it, and consumes it only then.

Let's support this explicitly.

13 days agomachined: Allow user ids in open_shell for machine-dbus
cidkidnix [Tue, 7 Jul 2026 19:04:30 +0000 (14:04 -0500)] 
machined: Allow user ids in open_shell for machine-dbus

Previously "machinectl shell --uid=1000 <container>" resulted in a
sucessful drop into a shell in the respective target machine. After
commit a9e9288288567beae57337ae903dd3b6c774001c this is no longer the
case.

This fixes the above breaking change brought in commit a9e9288288567beae57337ae903dd3b6c774001c

13 days agoudev-util: bound leading whitespace skip in udev_replace_whitespace 42757/head
Syed Mohammed Nayyar [Mon, 29 Jun 2026 06:02:14 +0000 (11:32 +0530)] 
udev-util: bound leading whitespace skip in udev_replace_whitespace

The function documents that at most 'len' bytes are read from 'str',
but the leading whitespace skip used strspn(), which is bounded only
by a non-whitespace byte or a NUL. ata_id passes the space padded,
non-NUL-terminated ATA IDENTIFY fields, so an all-blank model reads
past the buffer. Use strnspn() to cap the skip to 'len'.

13 days agostring-util: add strnspn()
Syed Mohammed Nayyar [Mon, 29 Jun 2026 06:02:14 +0000 (11:32 +0530)] 
string-util: add strnspn()

Like strspn(), but reads at most 'n' bytes from the input. strspn()
is bounded only by a non-matching byte or a NUL, so it over-reads a
buffer that is all matching bytes and not NUL terminated within 'n'.

13 days agoci: add test suite for verity+luks disk images 43009/head
Lennart Poettering [Mon, 13 Jul 2026 13:41:36 +0000 (15:41 +0200)] 
ci: add test suite for verity+luks disk images

13 days agodissect-image: support activating luks+verity partitions
Lennart Poettering [Mon, 13 Jul 2026 13:41:21 +0000 (15:41 +0200)] 
dissect-image: support activating luks+verity partitions

Let's properly activate images that have both LUKS and Verity enabled
for a partition.

13 days agorepart: say when we are calculating Verity data
Lennart Poettering [Tue, 14 Jul 2026 08:56:19 +0000 (10:56 +0200)] 
repart: say when we are calculating Verity data

We say when we encrypt a partition, let's also say when we calculate
verity protection data.

13 days agorepart: support generating LUKS+Verity partitions
Lennart Poettering [Mon, 13 Jul 2026 13:40:56 +0000 (15:40 +0200)] 
repart: support generating LUKS+Verity partitions

For various cases it is interesting to both sign and encrypted a file
system, for example to prepare it on one host and provide it to another.
Let's explicitly support preparing this in systemd-repart via setting
both Verity= and Encrypt=.

13 days agoupdate TODO
Lennart Poettering [Thu, 16 Jul 2026 05:04:26 +0000 (07:04 +0200)] 
update TODO

13 days agoportable: honor --force for directory extensions 43033/head
dongshengyuan [Wed, 15 Jul 2026 08:50:12 +0000 (16:50 +0800)] 
portable: honor --force for directory extensions

Pass relax_extension_release_check through the directory extraction
path instead of hardcoding false. Directory extensions now honor the
same --force relaxation as dissected images.

Reproducer:
  cp -a /tmp/app0 /tmp/app10
  sudo portablectl attach --force --runtime \
      --extension /tmp/app10 /tmp/rootdir app0

Before:
  directory image extraction always used strict extension-release name
  checks. --force relaxed other extension paths but still rejected a
  renamed directory extension with matching metadata.

Follow-up: 06768b90a32ac0d36252ebc5f426ad471bf29fce

2 weeks agosysext: validate work directory metadata before removal 42978/head
Luca Boccassi [Fri, 10 Jul 2026 18:08:57 +0000 (19:08 +0100)] 
sysext: validate work directory metadata before removal

unmerge_hierarchy() joined the persisted work_dir value directly with
--root=. An empty value therefore resolved to the root itself and was passed
to rm_rf().

Require the decoded metadata to name a non-empty, safe, normalized relative
path before constructing the removal target. Add coverage using a disposable
root with deliberately emptied metadata.

Follow-up for 9cfad502f4aa103ef0d2191cbb6b82fecfbc5044

2 weeks agoshift-uid: close consumed directory fds on early return
Luca Boccassi [Fri, 10 Jul 2026 17:48:35 +0000 (18:48 +0100)] 
shift-uid: close consumed directory fds on early return

recurse_fd() consumes each directory fd passed to it, but it has no
cleanup set up until after take_fdopendir() succeeds.
Errors and skipped procfs, sysfs, or read-only subtrees therefore leak the
incoming fd.

Follow-up for b1fb2d971c810e0bdf9ff0ae567a1c6c230e4e5d

2 weeks agorm-rf: fail closed when the root check fails
Luca Boccassi [Fri, 10 Jul 2026 17:22:34 +0000 (18:22 +0100)] 
rm-rf: fail closed when the root check fails

path_is_root_at() returns a negative errno when it cannot determine whether
a target is the root file system. rm_rf_at() treats those errors as a
negative answer and continued with destructive operations.

Propagate root-check errors before modifying the target, while preserving
REMOVE_MISSING_OK for an absent path.

Follow-up for c0228b4fa3e4e633afa5eb8417e6cd3e311cd250

2 weeks agovconsole: reject empty layout during keymap conversion with error
Luca Boccassi [Fri, 10 Jul 2026 16:59:24 +0000 (17:59 +0100)] 
vconsole: reject empty layout during keymap conversion with error

A leading-dash console keymap or leading-comma X11 layout can produce an
empty layout while converting between the two formats. find_converted_keymap()
then asserts on it, allowing malformed input to abort callers such as localed.

Return EINVAL for an empty derived layout instead.

Follow-up for 6d0f5027364518ef17ef91b61dad945e1c4fd0f5