Matija Skala [Fri, 19 May 2017 12:36:12 +0000 (14:36 +0200)]
timesync/timesyncd-manager: fix format-specifier issues
timex::time::tv_usec and timex::freq can have different sizes
depending on the host architecture. On x32 in particular,
it is 8 bytes long while the long int type is only 4 bytes
long. Hence, using li as a format specifier will trigger
a format error. Thus, introduce a new format specifier
PRI_TIMEX which is defined as PRIi64 on x32 and li
everywhere else.
John Paul Adrian Glaubitz [Wed, 22 Mar 2017 20:40:51 +0000 (21:40 +0100)]
udev/udevadm-monitor: fix format-specifier issue
timespec::tv_nsec can have different sizes depending on the
host architecture. On x32 in particular, it is 8 bytes long
while the long int type is only 4 bytes long. Hence, using
ld as a format specifier will trigger a format error. Thus,
explicitly cast timespec::tv_nsec to nsec_t and use PRI_NSEC
as the format specifier to make sure the sizes for both match.
John Paul Adrian Glaubitz [Wed, 22 Mar 2017 20:34:32 +0000 (21:34 +0100)]
journal/journald-console: fix format-specifier issue
timespec::tv_nsec can have different sizes depending on the
host architecture. On x32 in particular, it is 8 bytes long
while the long int type is only 4 bytes long. Hence, using
ld as a format specifier will trigger a format error. Thus,
explicitly cast timespec::tv_nsec to nsec_t and use PRI_NSEC
as the format specifier to make sure the sizes for both match.
Lennart Poettering [Fri, 19 May 2017 09:37:30 +0000 (11:37 +0200)]
man: fix typo m86k → m68k (#5993)
Lennart Poettering [Fri, 19 May 2017 09:17:07 +0000 (11:17 +0200)]
Merge pull request #5598 from pfl/ndisc_prefix_delegation
Initial Router Advertisment implementation
Peter Hutterer [Fri, 19 May 2017 08:56:29 +0000 (18:56 +1000)]
udev: skip EVDEV_ABS override on devices without EV_ABS (#5984)
When we first handle a device with an EVDEV_ABS override, check if it has
EV_ABS bits. If not, print a warning and continue. This is required on devices
where the match string applies to multiple device nodes, not all of which may
have absolute axes.
Fixes https://github.com/systemd/systemd/issues/5079
Evgeny Vereshchagin [Fri, 19 May 2017 06:34:39 +0000 (09:34 +0300)]
Merge pull request #5988 from poettering/man-and-gcc
minor man page and gcc fixes
Lennart Poettering [Thu, 18 May 2017 16:25:02 +0000 (18:25 +0200)]
udev: turn off -Wformat-nonliteral for one safe case
c20e6de897b2378bc3f936e1e265d2d2e2450a73 introduced a format string as
variable, but didn't turn off -Wformat-nonliteral warnings on it, thus
breaking the build. Let's fix that, by simply turning off the warning in
this case, as we know it's safe.
Lennart Poettering [Thu, 18 May 2017 16:24:17 +0000 (18:24 +0200)]
man: extend documentation on sd_bus_add_match a bit()
Explain briefly how the concept of "sd_bus_slot" works.
This recently came up on the mailing list, hence let's document this for
the next time.
Susant Sahani [Thu, 18 May 2017 10:56:36 +0000 (10:56 +0000)]
sd-netlink: Make use of IN_SET (#5977)
Daniel Wang [Thu, 18 May 2017 00:14:58 +0000 (17:14 -0700)]
gitignore: ignore /test-sd-dhcp-lease (#5983)
Lennart Poettering [Wed, 17 May 2017 15:02:55 +0000 (17:02 +0200)]
Merge pull request #5957 from keszybz/test-c++
Test compilation under C++
Dimitri John Ledkov [Wed, 17 May 2017 13:28:35 +0000 (14:28 +0100)]
udev: net_id add support for platform bus (ACPI, mostly arm64) devices (#5933)
Fixes: #5894
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2017 09:40:49 +0000 (05:40 -0400)]
calendarspec: parse unix timestamps (@...) (#5947)
Fixes #5810.
Lennart Poettering [Wed, 17 May 2017 09:39:44 +0000 (11:39 +0200)]
Merge pull request #5883 from garyttierney/fix-selinux
selinux: enable labeling and access checks for unprivileged users
Yu Watanabe [Tue, 16 May 2017 00:51:22 +0000 (09:51 +0900)]
meson: do not use generate_gperfs.py for keyboard-keys-from-name.gperf (#5968)
Fixes #5967.
Charles Plessy [Mon, 15 May 2017 12:16:16 +0000 (21:16 +0900)]
Add Lenovo UltraNav SK-8845 (#5963)
Closes #5952.
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 13:19:21 +0000 (09:19 -0400)]
meson: add rules for RA sources
Patrik Flykt [Fri, 12 May 2017 13:48:39 +0000 (16:48 +0300)]
test-ndisc-ra: Add Router Advertisement test cases
Add tests for prefix creation, router variable setting and finally
verify that a Router Advertisement is properly formatted when sending.
Also check that there is a Router Advertisment with zero lifetime
when Router Advertisement sending is stopped.
Patrik Flykt [Fri, 12 May 2017 13:48:38 +0000 (16:48 +0300)]
sd-radv: Receive Router Solicitations
Receive Router Solicitations and send a unicast Router Advertisment
in response. Refactor ICMPv6 packet handling code so that the common
ICMPv6 validation parts are reused between the existing router
discovery and the new functionality adding reception of Router
Solicitation messages.
Patrik Flykt [Fri, 12 May 2017 13:48:37 +0000 (16:48 +0300)]
sd-radv: Send Router Advertisments
Create and remove the ICMPv6 Router Advertisement socket file
descriptor and implement Router Advertisment sending. As not
all options are mandatory, use IO vectors to point to the included
options and the prefix information.
Patrik Flykt [Fri, 12 May 2017 13:48:36 +0000 (16:48 +0300)]
icmp6-util: Move multicast address definitions
As the Router Advertisment sending code needs these multicast
address definitions, move them to the header file.
Patrik Flykt [Fri, 12 May 2017 13:48:35 +0000 (16:48 +0300)]
icmp6-util: Bind Router Advertisement socket
Reuse and refactor the functionality already present for Router
Solicitations in order to create a socket for sending Router
Advertisements. Anticipate reception of incoming Router
Solicitations by setting the ICMPv6 filter accordingly. Also set
the unicast hop limit to 255 for ICMPv6 sockets as unicast Router
Advertisments are to be sent in response to Router Solicitations.
Update the Router Solicitation test case code with a function
definition in order to keep the test case working.
Patrik Flykt [Fri, 12 May 2017 13:48:34 +0000 (16:48 +0300)]
sd-radv: Implement Router Advertisement timeout handling
Router Advertisements are sent uniformly distributed between a
minimum and maximum time according to RFC 4861, Section 6.2.4.
Default values from RFC 4861 are for now used as minimum and
maximum Router Advertisement timeouts.
When stopping, a Router Advertisement with a router lifetime set
to zero is sent in order to inform any nodes that the interface
on this host no longer is a router.
Patrik Flykt [Fri, 12 May 2017 13:48:33 +0000 (16:48 +0300)]
networkd-link.c: Add Router Advertisement starting and stopping
Start and stop Router Advertisement sending once the link has acquired
a link-local IPv6 address.
Patrik Flykt [Fri, 12 May 2017 13:48:32 +0000 (16:48 +0300)]
networkd-radv: Helper function for Router Advertisement initialization
Add a helper function for configuring Router Advertisement on a
specific network link. Add the prefixes that are going to be advertised.
Patrik Flykt [Fri, 12 May 2017 13:48:31 +0000 (16:48 +0300)]
sd-radv: Add Router Advertisement functionality
Add Router Advertisement header files, data structures and core
functionality that is quite similar to other parts of networkd.
Patrik Flykt [Fri, 12 May 2017 13:48:30 +0000 (16:48 +0300)]
networkd: Add Router Advertisement variables
Add variables for enabling Router Advertisements, router lifetime as
well as managed and other information flags indicating use of DHCPv6.
Add configuration of default router preferences as defined in RFC 4191.
IPv6PrefixDelegation in the [Network] section has to be set in order
to enable prefix delegation. The rest of the prefix delegation values
are stored in the [IPv6PrefixDelegation] section. The host will act as
a default router if it is given a non-zero lifetime with
RouterLifetimeSec. Managed and OtherInformation booleans set the level
of DHCPv6 support, and the RouterPreference configures the router's
preference between low, medium and high. Words 'normal' and 'default'
are added as synonyms for 'medium' just to make configuration simpler.
This adds a section like the following to .network configuration files:
[Network]
IPv6PrefixDelegation=true
[IPv6PrefixDelegation]
RouterLifetimeSec=2000
Managed=false
OtherInformation=true
RouterPreference=medium
Patrik Flykt [Fri, 12 May 2017 13:48:29 +0000 (16:48 +0300)]
networkd: Add IPv6Prefix sections to the network configuration files
Support zero or more [IPv6Prefix] sections in the network configuration
files. Each section can have one Prefix=<subnet>[/<prefixlength>]
option, with the preferred and valid lifetimes specified by
ValidLifetimeSec and PreferredLifetimeSec measured in seconds, and
with onlink and address autoconfiguration booleans specified by
OnLink and AddressAutoconfiguration variables.
This adds a section like the following to .network configuration files:
[IPv6Prefix]
Prefix=2001:db8:dead:beef::/64
OnLink=true
AddressAutoconfiguration=true
ValidLifetimeSec=1500
PreferredLifetimeSec=1000
Patrik Flykt [Fri, 12 May 2017 13:48:28 +0000 (16:48 +0300)]
networkd: Add initial prefix handling for network configuration
Add initial code for handling prefixes in network configuration files.
Add hash map and list storing the information in systemd-networkd.
Patrik Flykt [Fri, 12 May 2017 13:48:27 +0000 (16:48 +0300)]
sd-radv: Add Router Advertisement prefix handling
Define Router Advertisement prefix structure. Add the Prefix
Information ICMPv6 option defined in RFC 4861 to the prefix
information structure, as it will simplify sending a Prefix
Information option later on. In order to handle endianness
correctly, the structure is redefined here instead of using
the one in netinet/icmp6.h.
Add functions to create and modify prefix information and set
default values as defined in RFC 4861, Section 6.2.1.
Zbigniew Jędrzejewski-Szmek [Sun, 14 May 2017 19:09:29 +0000 (15:09 -0400)]
test-bus-vtable: add SD_BUS_PROPERTY
Without
cc9daff228, this results in:
src/libsystemd/sd-bus/test-bus-vtable-cc.cc:56:1: sorry, unimplemented: non-trivial designated initializers not supported
};
^
Zbigniew Jędrzejewski-Szmek [Sun, 14 May 2017 14:31:12 +0000 (10:31 -0400)]
Merge pull request #5961 from ronnychevalier/rc/conf-parser-strv-typo
conf-parser: fix wrong argument given to log_syntax_invalid_utf8
Ronny Chevalier [Sun, 14 May 2017 14:30:40 +0000 (16:30 +0200)]
env-util: fix memory leak (#5962)
If cunescape succeeds, but the assignment is not valid, uce is not freed.
Ronny Chevalier [Sun, 14 May 2017 11:19:11 +0000 (13:19 +0200)]
test-conf-parser: add valid and invalid utf8 test for config_parse_path
Ronny Chevalier [Sun, 14 May 2017 11:19:11 +0000 (13:19 +0200)]
conf-parser: fix wrong argument given to log_syntax_invalid_utf8
The condition is on "word", hence we give word instead of rvalue.
An assert would be triggered if !utf8_is_valid(word) is true and
rvalue == NULL, since log_syntax_invalid_utf8 calls utf8_escape_invalid
which calls assert(str).
A test case has been added to test with valid and invalid utf8.
Zbigniew Jędrzejewski-Szmek [Sat, 13 May 2017 17:23:28 +0000 (13:23 -0400)]
tests,meson: add test-bus-vtable, compiled as C and C++
This test is mostly a compilation test that checks that various defines in
sd-bus-vtable.h are valid C++. The code is executed, but the results are not
checked (apart from sd-bus functions not returning an error). test-bus-objects
contains pretty extensive tests for this functionality.
The C++ version is only added to meson, since it's simpler there.
Because of the .cc extension, meson will compile the executable with c++.
This test is necessary to properly check the macros in sd-bus-vtable.h. Just
running the headers through g++ is not enough, because the macros are not
exercised.
Follow-up for #5941.
Zbigniew Jędrzejewski-Szmek [Sat, 13 May 2017 15:47:36 +0000 (11:47 -0400)]
test-ipv4ll: use assert_se consistently
We use assert_se in tests so that the asserts get evaluated even if compiled with NDEBUG.
Zbigniew Jędrzejewski-Szmek [Sat, 13 May 2017 15:44:51 +0000 (11:44 -0400)]
tree-wide: drop assert.h includes
We provide an independent reimplementation in macro.h, and that's the one
we want to use. Including the system header is unnecessary and confusing.
Zbigniew Jędrzejewski-Szmek [Fri, 12 May 2017 19:20:54 +0000 (15:20 -0400)]
tests: make sure that our headers are valid c++
This adds a meson test because it fits nicely into the existing framework.
It should be enough to run this test once in a while, so I don't think it's
crucial to also have it under autotools.
Michael Biebl [Sat, 13 May 2017 19:07:04 +0000 (21:07 +0200)]
Merge pull request #5956 from eliasp/fix-typo-network-zones
man: fix typo (`--network-zones` → `--network-zone`)
Elias Probst [Sat, 13 May 2017 18:55:03 +0000 (20:55 +0200)]
man: fix typo (`--network-zones` → `--network-zone`)
Daniel Wang [Sat, 13 May 2017 14:19:32 +0000 (07:19 -0700)]
network: Implement DHCP Option 119 (Domain Search List) (#5932)
This adds a modified version of dhcp6_option_parse_domainname() that is
able to parse compressed domain names, borrowing the idea from
dns_packet_read_name(). It also adds pieces in networkd-link and
networkd-manager to properly save/load the added option field.
Resolves #2710.
Gary Tierney [Tue, 2 May 2017 20:05:32 +0000 (21:05 +0100)]
audit-fd: check for CAP_AUDIT_WRITE before opening an audit socket
Adds a check to audit-fd.c to ensure that CAP_AUDIT_WRITE is present in
the set of effective capabilities before opening an audit netlink
socket. This ensures that unprivileged systemd instances (MANAGER_USER)
don't try to log AVC permission checks with the audit subsystem when
CAP_AUDIT_WRITE is not present.
Gary Tierney [Tue, 2 May 2017 16:42:19 +0000 (17:42 +0100)]
Revert "selinux: split up mac_selinux_have() from mac_selinux_use()"
This reverts commit
6355e75610a8d47fc3ba5ab8bd442172a2cfe574.
The previously mentioned commit inadvertently broke a lot of SELinux related
functionality for both unprivileged users and systemd instances running as
MANAGER_USER. In particular, setting the correct SELinux context after a User=
directive is used would fail to work since we attempt to set the security
context after changing UID. Additionally, it causes activated socket units to
be mislabeled for systemd --user processes since setsockcreatecon() would never
be called.
Reverting this fixes the issues with labeling outlined above, and reinstates
SELinux access checks on unprivileged user services.
Lennart Poettering [Fri, 12 May 2017 13:22:46 +0000 (15:22 +0200)]
Merge pull request #5432 from keszybz/udev-logging
udev logging separation
Zbigniew Jędrzejewski-Szmek [Fri, 12 May 2017 12:31:46 +0000 (08:31 -0400)]
nss-resolve: drop the internal fallback to libnss_dns (#5945)
If we could not communicate with systemd-resolved, we would call into
libnss_dns. libnss_dns would return NOTFOUND for stuff like "localhost" and
other names resolved by nss-myhostname, which we would fall under the !UNAVAIL=
condition and cause resolution to fail. So the following recommended
configuration in nsswitch.conf would not work:
hosts: resolve [!UNAVAIL=return] dns myhostname
Remove the internal fallback code completely so that the fallback logic
can be configured in nsswitch.conf.
Tested with
hosts: resolve [!UNAVAIL=return] myhostname
and
hosts: resolve [!UNAVAIL=return] dns myhostname
Fixes #5742.
Lennart Poettering [Fri, 12 May 2017 10:01:40 +0000 (12:01 +0200)]
Merge pull request #5928 from keszybz/libidn2
Use idn2 instead of idn
Lennart Poettering [Fri, 12 May 2017 10:00:24 +0000 (12:00 +0200)]
Merge pull request #5942 from keszybz/timestamp-writing
Allow timestamp to be set by the file writing utility functions
Lennart Poettering [Fri, 12 May 2017 09:58:13 +0000 (11:58 +0200)]
Merge pull request #5946 from evverx/test-sigbus-fixes
test-sigbus: use posix_fallocate rather than fallocate
Zbigniew Jędrzejewski-Szmek [Fri, 12 May 2017 08:49:48 +0000 (04:49 -0400)]
README: update util-linux required compilation options (#5949)
Fixes #5563.
Zbigniew Jędrzejewski-Szmek [Fri, 12 May 2017 01:53:12 +0000 (21:53 -0400)]
networkd: remove unused variables (#5948)
Fixup for
36423ff433.
Evgeny Vereshchagin [Thu, 11 May 2017 22:56:39 +0000 (01:56 +0300)]
tests: stop creating /TEST (#5943)
Closes #5856.
Matthijs van Duin [Thu, 11 May 2017 22:55:26 +0000 (00:55 +0200)]
sd-bus: fix c++ compatibility (#5941)
g++ annoyingly requires a non-empty struct-initializer to initialize all
struct members, in order of declaration.
Signed-off-by: Matthijs van Duin <matthijsvanduin@gmail.com>
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 22:53:35 +0000 (18:53 -0400)]
Merge pull request #5936 from ssahani/net-route
networkd: route replace parse prefix with generic in_addr_prefix_from_string
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 02:09:45 +0000 (22:09 -0400)]
mkosi: switch over to libidn2
Zbigniew Jędrzejewski-Szmek [Wed, 10 May 2017 01:56:34 +0000 (21:56 -0400)]
resolved: support libidn2 in addition to libidn
libidn2 2.0.0 supports IDNA2008, in contrast to libidn which supports IDNA2003.
https://bugzilla.redhat.com/show_bug.cgi?id=1449145
From that bug report:
Internationalized domain names exist for quite some time (IDNA2003), although
the protocols describing them have evolved in an incompatible way (IDNA2008).
These incompatibilities will prevent applications written for IDNA2003 to
access certain problematic domain names defined with IDNA2008, e.g., faß.de is
translated to domain xn--fa-hia.de with IDNA2008, while in IDNA2003 it is
translated to fass.de domain. That not only causes incompatibility problems,
but may be used as an attack vector to redirect users to different web sites.
v2:
- keep libidn support
- require libidn2 >= 2.0.0
v3:
- keep dns_name_apply_idna caller dumb, and keep the #ifdefs inside of the
function.
- use both ±IDN and ±IDN2 in the version string
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 18:00:25 +0000 (14:00 -0400)]
networkd: pretiffy message about invalid prefix
We know how the field we are parsing is called, let's put this information in
the error message:
"Route Source= prefix is invalid, ignoring assignment: ..."
"Route Destination= prefix is invalid, ignoring assignment: ..."
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 14:29:34 +0000 (10:29 -0400)]
update-done: use newly added library function to write the file
Fixes #5861.
Lennart Poettering [Thu, 11 May 2017 17:42:42 +0000 (19:42 +0200)]
Merge pull request #5893 from keszybz/memorydenywriteexecute
Add support for more arches for MemoryDenyWriteExecute
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 16:12:41 +0000 (12:12 -0400)]
pid1: improve logging when failing to remount / ro (#5940)
https://bugzilla.redhat.com/show_bug.cgi?id=1227736#c49
We counted how many filesystems could not be unmounted, but only for those
filesystems which we tried to unmount. Since we only remount / ro, without
attempting to unmount, we would emit a confusing error message:
Remounting '/' read-only with options 'seclabel,space_cache,subvolid=5,subvol=/'.
Remounting '/' read-only with options 'seclabel,space_cache,subvolid=5,subvol=/'.
Remounting '/' read-only with options 'seclabel,space_cache,subvolid=5,subvol=/'.
All filesystems unmounted.
Warn when remount-ro fails, and for filesystems which we won't try to unmount,
include the failure to remount-ro in n_failed.
A few minor cleanups:
- remove unecessary goto which jumps to the next line anyway
- always calculate n_failed, even if log_error is false. This causes no change
in behaviour, but I think the code is easier to follow, since the log setting
cannot influence other logic.
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 14:23:36 +0000 (10:23 -0400)]
basic/fileio: extend atomic file writing with timestamp setting
There should be no functional change.
Tom Gundersen [Thu, 11 May 2017 13:56:55 +0000 (15:56 +0200)]
busctl: monitor - only start printing messages once we have become a monitor (#5931)
A connection becomes a monitor the moment it loses its unique name, so any
messages received before that should not be dumped to the console.
Currently, we print NameAcquired and NameLost for the unique name of the
peer that becomes the monitor, simply discard all messages until we
receive our NameLost signal.
Zbigniew Jędrzejewski-Szmek [Thu, 11 May 2017 06:15:28 +0000 (02:15 -0400)]
core: fix warning about unsigned variable (#5935)
Fixup for
d8c92e8bc7351f553936b5235e1922c18ebd817a.
Susant Sahani [Thu, 11 May 2017 04:42:54 +0000 (10:12 +0530)]
networkd: route replace parse prefix with generic in_addr_prefix_from_string
Peter Hutterer [Thu, 11 May 2017 02:29:15 +0000 (12:29 +1000)]
hwdb: add the X200/X201 to the existing X201s entry (#5934)
https://bugs.freedesktop.org/show_bug.cgi?id=100628
Ray Strode [Thu, 11 May 2017 02:23:54 +0000 (22:23 -0400)]
man: fix LD_LIBRARY_PATH example in environment.d (#5929)
The example for LD_LIBRARY_PATH in the environment.d man page is wrong.
When setting LD_LIBRARY_PATH, the new directory usually needs to be at
the front so it overrides old directories.
In the example, the colon delimiter is correctly prepended to the front, but
the actual new path is erroneously appended to the end.
This commit moves it to the front where it belongs.
Peter Hutterer [Wed, 10 May 2017 19:22:00 +0000 (05:22 +1000)]
udev: don't allow pointing stick sensitivities greater than 255 (#5927)
It gets truncated, so the result is that people mess with the const accel
because the sensitivity isn't the expected 300 but the too-low 45.
One example: https://bugs.freedesktop.org/show_bug.cgi?id=100965
Lennart Poettering [Wed, 10 May 2017 17:46:13 +0000 (19:46 +0200)]
Merge pull request #5920 from fbuihuu/sysusers-disable-gshadow
Sysusers disable group shadow support
Zbigniew Jędrzejewski-Szmek [Tue, 9 May 2017 22:57:10 +0000 (18:57 -0400)]
seccomp: enable RestrictAddressFamilies on ppc64, autodetect SECCOMP_RESTRICT_ADDRESS_FAMILIES_BROKEN
We expect that if socket() syscall is available, seccomp works for that
architecture. So instead of explicitly listing all architectures where we know
it is not available, just assume it is broken if the number is not defined.
This should have the same effect, except that other architectures where it is
also broken will pass tests without further changes. (Architectures where the
filter should work, but does not work because of missing entries in
seccomp-util.c, will still fail.)
i386, s390, s390x are the exception — setting the filter fails, even though
socket() is available, so it needs to be special-cased
(https://github.com/systemd/systemd/issues/5215#issuecomment-
277241488).
This remove the last define in seccomp-util.h that was only used in test-seccomp.c. Porting
the seccomp filter to new architectures should be simpler because now only two places need
to be modified.
RestrictAddressFamilies seems to work on ppc64[bl]e, so enable it (the tests pass).
Franck Bui [Wed, 10 May 2017 12:28:41 +0000 (14:28 +0200)]
sysusers: make use of cleanup(unlink_and_freep) in write_files() and its auxiliary helpers
No functional changes.
Anchor Cat [Wed, 10 May 2017 11:23:58 +0000 (21:23 +1000)]
automount: ack automount requests even when already mounted (#5916)
If a process accesses an autofs filesystem while systemd is in the
middle of starting the mount unit on top of it, it is possible for the
autofs_ptype_missing_direct request from the kernel to be received after
the mount unit has been fully started:
systemd forks and execs mount ...
... access autofs, blocks
mount exits ...
systemd receives SIGCHLD ...
... kernel sends request
systemd receives request ...
systemd needs to respond to this request, otherwise the kernel will
continue to block access to the mount point.
Zbigniew Jędrzejewski-Szmek [Wed, 10 May 2017 11:09:52 +0000 (07:09 -0400)]
units: make descriptions of api filesystems less generic (#5914)
All those names were very generic. Fixes #5911.
Evgeny Vereshchagin [Wed, 10 May 2017 08:54:52 +0000 (08:54 +0000)]
test-sigbus: skip the test under valgrind
Evgeny Vereshchagin [Wed, 10 May 2017 08:47:39 +0000 (08:47 +0000)]
test-sigbus: use posix_fallocate rather than fallocate
Some filesystems do not support fallocate, so we need to fall back on
something like posix_fallocate.
Closes #5833
Franck Bui [Tue, 9 May 2017 12:02:37 +0000 (14:02 +0200)]
sysusers: make group shadow support configurable
Some distros (openSUSE) don't have group shadow support enabled. This can lead
to the following error:
# systemd-sysusers
Creating group foofoo with gid 478.
# systemd-sysusers
# groupdel foofoo
# systemd-sysusers
Creating group foofoo with gid 478.
Failed to write files: File exists
This patch adds --disable-gshadow option to configure. If used,
systemd-sysvusers won't consider /etc/gshadow.
Franck Bui [Tue, 9 May 2017 07:37:37 +0000 (09:37 +0200)]
sysusers: split make_files()
This patch extracts the code which is in charge to write the new users or
groups into temporary files and move it into 4 dedicated functions.
This part was previously inlined in makes_files() making this function quite
big and hard to read and maintain.
There should be no functional change.
Lennart Poettering [Tue, 9 May 2017 19:10:55 +0000 (21:10 +0200)]
50-udev-default.rules.in: set correct group for mediaX/cecX (#5921)
The /dev/mediaX and /dev/cecX devices belong to the video group.
Add two default rules for that.
The /dev/cecX devices were introduced in kernel 4.8 in staging and moved
out of staging in 4.10. These devices support the HDMI CEC bus.
The /dev/mediaX devices are much older, but because they are not used very
frequently nobody got around to adding this rule to systemd. They let the
user control complex media pipelines.
Max Resch [Tue, 9 May 2017 18:57:40 +0000 (20:57 +0200)]
sd-boot: added shim signature/MOK validation (#5702)
Adds support for booting in a SecureBoot environment with shim as a
preloader. Install an appropriate UEFI security policy to check PE
signature of a chained kernel or UEFI application (using LoadImage())
against the MOK database maintained by shim, using shim's installed
BootServices.
Implementation details for installing the security policy are based on
code from the LinuxFoundation's SecureBoot PreLoader, part of efitools
licensed under LGPL 2.1
Current signed (by Microsoft) versions of shim (Versions 0.8 & 0.9)
so not install a security policy by themselves, future Versions of
shim might (a compile time switch exists in rectent git versions),
so in the future this PR might become unnecessary.
Lennart Poettering [Tue, 9 May 2017 18:49:17 +0000 (20:49 +0200)]
Merge pull request #5619 from fbuihuu/fully-restore-unit-cgroup-state
core: when deserializing a unit, fully restore its cgroup state
Lennart Poettering [Tue, 9 May 2017 18:42:32 +0000 (20:42 +0200)]
Merge pull request #5420 from OpenDZ/tixxdz/namespace-fixes-v2
Namespace: RootImage= RootDirectory= and MountAPIVFS fixes
Susant Sahani [Tue, 9 May 2017 18:25:11 +0000 (18:25 +0000)]
network: add support for vlan confs(MVRP, reorder header, loose binding) (#5834)
Ted W [Tue, 9 May 2017 18:22:04 +0000 (13:22 -0500)]
man: Clarify Restart= exception for systemctl stop (#5891)
Lennart Poettering [Tue, 9 May 2017 18:12:52 +0000 (20:12 +0200)]
Merge pull request #5906 from keszybz/man-links
man page link fixes
Hristo Venev [Tue, 9 May 2017 18:04:55 +0000 (19:04 +0100)]
networkd: add IPv6ProxyNDP (#5913)
This allows enabling proxy_ndp even if no addresses are configured in
networkd, as well as disabling proxy_ndp from a drop-in.
Susant Sahani [Tue, 9 May 2017 18:01:25 +0000 (18:01 +0000)]
networkd: add support to configure route protocol. (#5890)
Closes: #5889
Lennart Poettering [Tue, 9 May 2017 17:32:25 +0000 (19:32 +0200)]
Merge pull request #5919 from glaubitz/suse
Fix meson build on openSUSE Tumbleweed
John Paul Adrian Glaubitz [Tue, 9 May 2017 17:31:38 +0000 (19:31 +0200)]
build: Add missing SECCOMP_CFLAGS to test-seccomp and test-execute targets (#5924)
John Paul Adrian Glaubitz [Tue, 9 May 2017 11:00:26 +0000 (13:00 +0200)]
meson: Add missing dependency on libkmod for libudev_core
John Paul Adrian Glaubitz [Tue, 9 May 2017 10:58:32 +0000 (12:58 +0200)]
meson: Add missing dependency on libseccomp for libcore
Aggelos Avgerinos [Mon, 8 May 2017 23:09:22 +0000 (02:09 +0300)]
execute: Properly log errors considering socket fds (#5910)
Till now if the params->n_fds was 0, systemd was logging that there were
more than one sockets.
Thanks @gregoryp and @VFXcode who did the most work debugging this.
Mark Stosberg [Mon, 8 May 2017 23:05:34 +0000 (19:05 -0400)]
man: improve readability of time shorthands and their normalized forms. (#5912)
Zbigniew Jędrzejewski-Szmek [Thu, 23 Feb 2017 08:18:42 +0000 (03:18 -0500)]
udev/collect: remove now-unused struct udev
Zbigniew Jędrzejewski-Szmek [Thu, 23 Feb 2017 08:16:44 +0000 (03:16 -0500)]
Rip out setting of the log level from udev_new and put it in a new function
This function is internal to systemd code, so external users of libudev
will not see those log messages. I think this is better. If we want to
allow that, the function could be put in libudev and exported.
v2: check that the string is more than one char before stripping quotes
Zbigniew Jędrzejewski-Szmek [Thu, 23 Feb 2017 04:13:22 +0000 (23:13 -0500)]
udev: use LOG_REALM_UDEV in all udev code
Any call to set/query/use the log level in the code with LOG_REALM=LOG_REALM_UDEV
refers to log_max_level[1]. In particular this means that systemd code using
the libudev library uses does not set the log level for log calls done in libudev.
Fixes #4525.
v2:
- also update meson's meson.build
Zbigniew Jędrzejewski-Szmek [Thu, 23 Feb 2017 03:57:34 +0000 (22:57 -0500)]
basic/log: split max log level into multiple "realms"
The single log level is split into an array of log levels. Which index in the
array is used can be determined for each compilation unit separately by setting
a macro before including log.h. All compilation units use the same index
(LOG_REALM_SYSTEMD), so there should be no functional change.
v2:
- the "realm" is squished into the level (upper bits that are not used by
priority or facility), and unsquished later in functions in log.c.
v3:
- rename REALM_PLUS_LEVEL to LOG_REALM_PLUS_LEVEL and REALM to LOG_REALM_REMOVE_LEVEL.
Pascal S. de Kloe [Mon, 8 May 2017 01:46:31 +0000 (03:46 +0200)]
hwdb: add axis range for Panasonic Toughbook CF-19, CF-30 and CF31 (#5908)
Michael Biebl [Mon, 8 May 2017 00:30:27 +0000 (02:30 +0200)]
Merge pull request #5907 from keszybz/mark-python-scripts-+x
Mark python scripts executable
Ian Wienand [Mon, 8 May 2017 00:23:49 +0000 (10:23 +1000)]
Add short-iso-precise for journalctl output (#5884)
This adds a short-iso-precise option for journalctl output. It is similar to
short-iso, but includes microseconds.
Zbigniew Jędrzejewski-Szmek [Sun, 7 May 2017 15:35:32 +0000 (11:35 -0400)]
Mark python scripts executable
Since all our python scripts have a proper python3 shebang, there is no benefit
to letting meson autodetect them. On linux, meson will just uses exec(), so the
shebang is used anyway. The only difference should be in how meson reports the
script and that the detection won't fail for (most likely misconfigured)
non-UTF8 locales.
Closes #5855.