platform/upstream/systemd.git
8 years agoresolved: rework SERVFAIL handling
Lennart Poettering [Thu, 23 Jun 2016 21:24:38 +0000 (23:24 +0200)]
resolved: rework SERVFAIL handling

There might be two reasons why we get a SERVFAIL response from our selected DNS
server: because this DNS server itself is bad, or because the DNS server
actually serving the zone upstream is bad. So far we immediately downgraded our
server feature level when getting SERVFAIL, under the assumption that the first
case is the only possible case. However, this meant we'd downgrade immediately
even if we encountered the second case described above.

With this commit handling of SERVFAIL is reworked. As soon as we get a SERVFAIL
on a transaction we retry the transaction with a lower feature level, without
changing the feature level tracked for the DNS server itself. If that fails
too, we downgrade further, and so on. If during this downgrading the SERVFAIL
goes away we assume that the DNS server we are talking to is bad, but the zone
is fine and propagate the detected feature level to the information we track
about the DNS server. Should the SERVFAIL not go away this way we let the
transaction fail and accept the SERVFAIL.

8 years agoudev: bump TasksMax to inifinity (#3593)
Franck Bui [Thu, 23 Jun 2016 20:31:01 +0000 (22:31 +0200)]
udev: bump TasksMax to inifinity (#3593)

udevd already limits its number of workers/children: the max number is actually
twice the number of CPUs the system is using.

(The limit can also be raised with udev.children-max= kernel command line
option BTW).

On some servers, this limit can easily exceed the maximum number of tasks that
systemd put on all services, which is 512 by default.

Since udevd has already its limitation logic, simply disable the static
limitation done by TasksMax.

8 years agofstab-generator: ignore root=/dev/nfs (#3591)
Harald Hoyer [Thu, 23 Jun 2016 16:47:03 +0000 (17:47 +0100)]
fstab-generator: ignore root=/dev/nfs (#3591)

root=/dev/nfs is a legacy option for the kernel to handle root on NFS.

Documentation for this kernel command line option
can be found in the kernel source tree:

Documentation/filesystems/nfs/nfsroot.txt

8 years agoMerge pull request #3583 from poettering/restrict-realtime
Ronny Chevalier [Thu, 23 Jun 2016 12:11:58 +0000 (13:11 +0100)]
Merge pull request #3583 from poettering/restrict-realtime

add new RestrictRealtime= option to services (and other fixes)

8 years agoMerge pull request #3581 from dobyrch/master
Ronny Chevalier [Thu, 23 Jun 2016 09:15:40 +0000 (10:15 +0100)]
Merge pull request #3581 from dobyrch/master

systemctl:  Add missing "/" to files created by 'edit --runtime'

8 years agobuild-sys: move fdset.[ch] src/basic → src/shared (#3580)
Lennart Poettering [Thu, 23 Jun 2016 02:10:53 +0000 (04:10 +0200)]
build-sys: move fdset.[ch] src/basic → src/shared (#3580)

It makes use of the sd_listen_fds() call, and as such should live in
src/shared, as the distinction between src/basic and src/shared is that the
latter may use libsystemd APIs, the former does not.

Note that btrfs-util.[ch] and log.[ch] also include header files from
libsystemd, but they only need definitions, they do not invoke any function
from it. Hence they may stay in src/basic.

8 years agoexecute: add a new easy-to-use RestrictRealtime= option to units
Lennart Poettering [Wed, 22 Jun 2016 23:45:45 +0000 (01:45 +0200)]
execute: add a new easy-to-use RestrictRealtime= option to units

It takes a boolean value. If true, access to SCHED_RR, SCHED_FIFO and
SCHED_DEADLINE is blocked, which my be used to lock up the system.

8 years agoexecute: be a little less drastic when MemoryDenyWriteExecute= hits
Lennart Poettering [Wed, 22 Jun 2016 23:35:04 +0000 (01:35 +0200)]
execute: be a little less drastic when MemoryDenyWriteExecute= hits

Let's politely refuse with EPERM rather than kill the whole thing right-away.

8 years agoexecute: set PR_SET_NO_NEW_PRIVS also in case the exec memory protection is used
Lennart Poettering [Wed, 22 Jun 2016 23:33:07 +0000 (01:33 +0200)]
execute: set PR_SET_NO_NEW_PRIVS also in case the exec memory protection is used

This was forgotten when MemoryDenyWriteExecute= was added: we should set NNP in
all cases when we set seccomp filters.

8 years agoexecute: use the return value of setrlimit_closest() properly
Lennart Poettering [Wed, 22 Jun 2016 23:31:24 +0000 (01:31 +0200)]
execute: use the return value of setrlimit_closest() properly

It's a function defined by us, hence we should look for the error in its return
value, not in "errno".

8 years agocore: when writing transient unit files, make sure all lines end with a newline
Lennart Poettering [Wed, 22 Jun 2016 23:29:33 +0000 (01:29 +0200)]
core: when writing transient unit files, make sure all lines end with a newline

This is a fix-up for 2a9a6f8ac04a69ca36d645f9305a33645f22a22b which covered
non-transient units, but missed the case for transient units.

8 years agonspawn: improve man page (#3577)
Lennart Poettering [Wed, 22 Jun 2016 21:30:36 +0000 (23:30 +0200)]
nspawn: improve man page (#3577)

This change documents the existance of the systemd-nspawn@.service template
unit file, which was previously not mentioned at all. Since the unit file uses
slightly different default than nspawn invoked from the command line, these
defaults are now explicitly documented too.

A couple of further additions and changes are made, too.

Replaces: #3497

8 years agoman: document that %f in units always unescapes (#3578)
Lennart Poettering [Wed, 22 Jun 2016 21:28:12 +0000 (23:28 +0200)]
man: document that %f in units always unescapes (#3578)

8 years agosystemctl: Add missing "/" to files created by 'edit --runtime'
Douglas Christman [Wed, 22 Jun 2016 19:09:33 +0000 (15:09 -0400)]
systemctl:  Add missing "/" to files created by 'edit --runtime'

8 years agomachinectl: do not escape the unit name (#3554)
Elias Probst [Wed, 22 Jun 2016 15:10:52 +0000 (17:10 +0200)]
machinectl: do not escape the unit name (#3554)

Otherwise starting a machine named `foo-bar-baz` will end up in
machinectl attempting to start the service unit
`systemd-nspawn@foo\x2dbar\x2dbaz` instead of
`systemd-nspawn@foo-bar-baz`.

8 years agowatchdog: Support changing watchdog_usec during runtime (#3492)
Minkyung [Wed, 22 Jun 2016 11:26:05 +0000 (20:26 +0900)]
watchdog: Support changing watchdog_usec during runtime (#3492)

Add sd_notify() parameter to change watchdog_usec during runtime.

Application can change watchdog_usec value by
sd_notify like this. Example. sd_notify(0, "WATCHDOG_USEC=20000000").

To reset watchdog_usec as configured value in service file,
restart service.

Notice.
sd_event is not currently supported. If application uses
sd_event_set_watchdog, or sd_watchdog_enabled, do not use
"WATCHDOG_USEC" option through sd_notify.

8 years agoNEWS: start section for 231, with tmpfs.mount option changes (#3576)
Martin Pitt [Wed, 22 Jun 2016 11:22:47 +0000 (13:22 +0200)]
NEWS: start section for 231, with tmpfs.mount option changes (#3576)

This documents the "add nosuid and nodev options to tmp.mount" change from
commit 2f9df7c96a2.

8 years agoMerge pull request #3526 from fbuihuu/fix-console-log-color
Lennart Poettering [Wed, 22 Jun 2016 10:34:25 +0000 (12:34 +0200)]
Merge pull request #3526 from fbuihuu/fix-console-log-color

Fix console log color

8 years agounits: add nosuid and nodev options to tmp.mount (#3575)
Martin Pitt [Wed, 22 Jun 2016 10:32:59 +0000 (12:32 +0200)]
units: add nosuid and nodev options to tmp.mount (#3575)

This makes privilege escalation attacks harder by putting traps and exploits
into /tmp.

https://bugs.debian.org/826377

8 years agopid1: initialize status color mode after setting up TERM
Franck Bui [Mon, 20 Jun 2016 19:45:28 +0000 (21:45 +0200)]
pid1: initialize status color mode after setting up TERM

Also we had to connect PID's stdio to null later since colors_enabled()
assume that stdout is connected to the console.

8 years agopid1: initialize TERM environment variable correctly
Franck Bui [Mon, 20 Jun 2016 16:54:21 +0000 (18:54 +0200)]
pid1: initialize TERM environment variable correctly

When systemd is started by the kernel, the kernel set the TERM
environment variable unconditionnally to "linux" no matter the console
device used. This might be an issue for dumb devices with no colors
support.

This patch uses default_term_for_tty() for getting a more accurate
value. But it makes sure to keep the user preferences (if any) which
might be passed via the kernel command line. For that purpose /proc
should be mounted.

8 years agoman: document some sd-bus functions (#3567)
mahkoh [Tue, 21 Jun 2016 15:52:32 +0000 (17:52 +0200)]
man: document some sd-bus functions (#3567)

* sd_bus_add_match
* sd_bus_get_fd
* sd_bus_message_read_basic
* sd_bus_process

8 years agoDo not ellipsize cgroups when showing slices in --full mode (#3560)
Ian Lee [Tue, 21 Jun 2016 14:10:31 +0000 (15:10 +0100)]
Do not ellipsize cgroups when showing slices in --full mode (#3560)

Do not ellipsize cgroups when showing slices in --full mode

8 years agoemergency.service: Don't say "Welcome" when it's an emergency (#3569)
Lennart Poettering [Tue, 21 Jun 2016 14:09:47 +0000 (16:09 +0200)]
emergency.service: Don't say "Welcome" when it's an emergency (#3569)

Quoting @cgwalters:

        Just uploading this as an RFC.  Now I know reading the code that systemd says
        `Welcome to $OS` as a generic thing, but my initial impression on seeing this
        was that it was almost sarcastic =)

        Let's say "You are in emergency mode" as a more neutral/less excited phrase.

This patch is based on #3556, but makes the same change for rescue mode.

8 years agocore: log the right set of the supported controllers (#3558)
Evgeny Vereshchagin [Mon, 20 Jun 2016 18:40:46 +0000 (21:40 +0300)]
core: log the right set of the supported controllers (#3558)

Jun 16 05:12:08 systemd[1]: Controller 'io' supported: yes
Jun 16 05:12:08 systemd[1]: Controller 'memory' supported: yes
Jun 16 05:12:08 systemd[1]: Controller 'pids' supported: yes

instead of

Jun 16 04:06:50 systemd[1]: Controller 'memory' supported: yes
Jun 16 04:06:50 systemd[1]: Controller 'devices' supported: yes
Jun 16 04:06:50 systemd[1]: Controller 'pids' supported: yes

8 years agoRevert "do not pass-along the environment from the kernel or initrd"
Franck Bui [Mon, 20 Jun 2016 16:54:21 +0000 (18:54 +0200)]
Revert "do not pass-along the environment from the kernel or initrd"

This reverts commit ce8aba568156f2b9d0d3b023e960cda3d9d7db81.

We should pass an environment as close as possible to what we originally
got.

8 years agopid1: reconnect to the console before being re-executed
Franck Bui [Mon, 13 Jun 2016 14:10:06 +0000 (16:10 +0200)]
pid1: reconnect to the console before being re-executed

When re-executed, reconnect the console to PID1's stdios as it was the case
when PID1 was initially started by the kernel.

8 years agoMerge pull request #3564 from evverx/valgrind-tests-fixes
Ronny Chevalier [Mon, 20 Jun 2016 07:41:06 +0000 (08:41 +0100)]
Merge pull request #3564 from evverx/valgrind-tests-fixes

tests: fix memory leak, don't run test_get_process_cmdline_harder under valgrind

8 years agotests: don't run test_get_process_cmdline_harder under valgrind
Evgeny Vereshchagin [Sun, 19 Jun 2016 23:43:35 +0000 (23:43 +0000)]
tests: don't run test_get_process_cmdline_harder under valgrind

See https://github.com/systemd/systemd/pull/3555#issuecomment-226564908

8 years agoman: match runlevel symlinks recommendation with our makefile (#3563)
Lukáš Nykrýn [Sun, 19 Jun 2016 17:22:46 +0000 (19:22 +0200)]
man: match runlevel symlinks recommendation with our makefile (#3563)

In makefile we create symlinks runlevel5.target to graphical.target and
runlevel2-4.target to multi-user.target. Let's say the same thing in
systemd.special manpage.

8 years agotests: fix memory leak in test-keymap-util
Evgeny Vereshchagin [Sun, 19 Jun 2016 15:02:51 +0000 (15:02 +0000)]
tests: fix memory leak in test-keymap-util

Fixes:
==27917== 3 bytes in 1 blocks are definitely lost in loss record 1 of 1
==27917==    at 0x4C28BF6: malloc (vg_replace_malloc.c:299)
==27917==    by 0x55083D9: strdup (in /usr/lib64/libc-2.22.so)
==27917==    by 0x1140DA: find_converted_keymap (keymap-util.c:524)
==27917==    by 0x110844: test_find_converted_keymap (test-keymap-util.c:52)
==27917==    by 0x1124FE: main (test-keymap-util.c:213)
==27917==

8 years agoEnsure kdbus isn't used (#3501)
Dave Reisner [Fri, 10 Jun 2016 13:50:16 +0000 (09:50 -0400)]
Ensure kdbus isn't used (#3501)

Delete the dbus1 generator and some critical wiring. This prevents
kdbus from being loaded or detected. As such, it will never be used,
even if the user still has a useful kdbus module loaded on their system.

Sort of fixes #3480. Not really, but it's better than the current state.

8 years agoMerge pull request #3557 from whot/hwdb-updates
Lennart Poettering [Fri, 17 Jun 2016 09:38:56 +0000 (11:38 +0200)]
Merge pull request #3557 from whot/hwdb-updates

Hwdb updates

8 years agoRevert "hwdb: change the Logitech MX500 to 1100 dpi (#3517)"
Peter Hutterer [Fri, 17 Jun 2016 01:00:45 +0000 (11:00 +1000)]
Revert "hwdb: change the Logitech MX500 to 1100 dpi (#3517)"

Likely bad measurement and all other websites refer to it being 1000dpi.

See https://bugs.freedesktop.org/show_bug.cgi?id=96225#c13

This reverts commit e7b90ddc345d1817ca48bfcc4e3e73836c8051af.

8 years agohwdb: touchpad ranges for Dell Precision M4700
Peter Hutterer [Thu, 16 Jun 2016 00:24:51 +0000 (10:24 +1000)]
hwdb: touchpad ranges for Dell Precision M4700

From https://bugs.freedesktop.org/show_bug.cgi?id=95417

8 years agoprocess-util: fix two bugs in get_process_cmdline() (#3555)
Lennart Poettering [Thu, 16 Jun 2016 20:46:44 +0000 (22:46 +0200)]
process-util: fix two bugs in get_process_cmdline() (#3555)

See:

https://github.com/systemd/systemd/pull/3529#issuecomment-226421007

8 years agoMerge pull request #3546 from keszybz/systemctl-fixes
Lennart Poettering [Thu, 16 Jun 2016 16:40:53 +0000 (18:40 +0200)]
Merge pull request #3546 from keszybz/systemctl-fixes

Systemctl fixes

8 years agoresolved: when restarting a transaction make sure to not touch it anymore (#3553)
Lennart Poettering [Thu, 16 Jun 2016 16:37:11 +0000 (18:37 +0200)]
resolved: when restarting a transaction make sure to not touch it anymore (#3553)

dns_transaction_maybe_restart() is supposed to return 1 if the the transaction
has been restarted and 0 otherwise. dns_transaction_process_dnssec() relies on
this behaviour. Before this change in case of restart we'd call
dns_transaction_go() when restarting the lookup, returning its return value
unmodified. This is wrong however, as that function returns 1 if the
transaction is pending, and 0 if it completed immediately, which is a very
different set of return values. Fix this, by always returning 1 on redirection.

The wrong return value resulted in all kinds of bad memory accesses as we might
continue processing a transaction that was redirected and completed immediately
(and thus freed).

This patch also adds comments to the two functions to clarify the return values
for the future.

Most likely fixes: #2942 #3475 #3484

8 years agoupdate TODO
Lennart Poettering [Thu, 16 Jun 2016 14:48:16 +0000 (16:48 +0200)]
update TODO

8 years agosystemctl: delay pager/polkit agent opening as much as possible
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jun 2016 13:11:32 +0000 (09:11 -0400)]
systemctl: delay pager/polkit agent opening as much as possible

In https://github.com/systemd/systemd/issues/3543, we would open the pager
before starting ssh, and the pipe fd was "leaked" into the ssh child as the
stderr fd. Previous commit fixes bus-socket to nullify stderr before launching
the child, but it seems reasonable to also delay starting the pager.
If we are going to croak when trying to open the transport, it seems better
to do this before starting the pager.

This commit would also fix #3543 on its own.

8 years agosystemctl: make sure we terminate the bus connection first, and then close the pager...
Lennart Poettering [Thu, 16 Jun 2016 13:29:16 +0000 (15:29 +0200)]
systemctl: make sure we terminate the bus connection first, and then close the pager (#3550)

If "systemctl -H" is used, let's make sure we first terminate the bus
connection, and only then close the pager. If done in this order ssh will get
an EOF on stdin (as we speak D-Bus through ssh's stdin/stdout), and then
terminate. This makes sure the standard error we were invoked on is released by
ssh, and only that makes sure we don't deadlock on the pager which waits for
all clients closing its input pipe.

(Similar fixes for the various other xyzctl tools that support both pagers and
-H)

Fixes: #3543

8 years agoMerge pull request #3511 from andir/networkd-vrf
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jun 2016 13:15:45 +0000 (09:15 -0400)]
Merge pull request #3511 from andir/networkd-vrf

networkd: add support for vrf interfaces (#3316)

8 years agoMerge pull request #3481 from poettering/relative-memcg
Lennart Poettering [Thu, 16 Jun 2016 11:56:23 +0000 (13:56 +0200)]
Merge pull request #3481 from poettering/relative-memcg

various changes, most importantly regarding memory metrics

8 years agoMerge pull request #3537 from poettering/journal-stream-env
Zbigniew Jędrzejewski-Szmek [Thu, 16 Jun 2016 01:30:59 +0000 (21:30 -0400)]
Merge pull request #3537 from poettering/journal-stream-env

Permit services to detect whether their stdout/stderr is connected to the journal.

8 years agonetworkd: vrf: add support for enslaving devices to VRFs
Andreas Rammhold [Sun, 12 Jun 2016 23:05:49 +0000 (01:05 +0200)]
networkd: vrf: add support for enslaving devices to VRFs

8 years agonetworkd: added support for vrf interfaces (#3316)
Andreas Rammhold [Thu, 9 Jun 2016 23:57:51 +0000 (01:57 +0200)]
networkd: added support for vrf interfaces (#3316)

8 years agoload-fragment: ignore ENOTDIR/EACCES errors (#3510)
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jun 2016 21:02:27 +0000 (17:02 -0400)]
load-fragment: ignore ENOTDIR/EACCES errors (#3510)

If for whatever reason the file system is "corrupted", we want
to be resilient and ignore the error, as long as we can load the units
from a different place.

Arch bug https://bugs.archlinux.org/task/49547.

A user had an ntfs symlink (essentially a file) instead of a directory after
restoring from backup. We should just ignore that like we would treat a missing
directory, for general resiliency.

We should treat permission errors similarly. For example an unreadable
/usr/local/lib directory would prevent (user) instances of systemd from
loading any units. It seems better to continue.

8 years agocore: set $JOURNAL_STREAM to the dev_t/ino_t of the journal stream of executed services
Lennart Poettering [Tue, 14 Jun 2016 14:50:45 +0000 (16:50 +0200)]
core: set $JOURNAL_STREAM to the dev_t/ino_t of the journal stream of executed services

This permits services to detect whether their stdout/stderr is connected to the
journal, and if so talk to the journal directly, thus permitting carrying of
metadata.

As requested by the gtk folks: #2473

8 years agoexecute: minor coding style improvements
Lennart Poettering [Tue, 14 Jun 2016 14:50:35 +0000 (16:50 +0200)]
execute: minor coding style improvements

8 years agosystemctl: also fall back to ListUnitsFiltered on access denied
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jun 2016 14:03:33 +0000 (10:03 -0400)]
systemctl: also fall back to ListUnitsFiltered on access denied

When running systemctl from git on systemd from systemd-229-8.fc24.x86_64,
ListUnitsByPatterns results in org.freedesktop.DBus.Error.AccessDenied.

8 years agosystemctl: do not open pager twice
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jun 2016 12:21:15 +0000 (08:21 -0400)]
systemctl: do not open pager twice

Second attempt had no effect anyway.

8 years agosocket-util: Run the fallback when the kernel complains about the null buffer (#3541)
Kai Ruhnau [Wed, 15 Jun 2016 10:33:24 +0000 (12:33 +0200)]
socket-util: Run the fallback when the kernel complains about the null buffer (#3541)

Calling recv with a NULL buffer returns EFAULT instead of EOPNOTSUPP on
older kernels (3.14).

Fixes #3407

Signed-off-by: Kai Ruhnau <kai.ruhnau@target-sg.com>
8 years agoMerge pull request #3540 from poettering/resolved-various
Zbigniew Jędrzejewski-Szmek [Wed, 15 Jun 2016 01:08:36 +0000 (21:08 -0400)]
Merge pull request #3540 from poettering/resolved-various

three resolved fixes

8 years agotree-wide: htonl() is weird, let's use htobe32() instead (#3538)
Lennart Poettering [Tue, 14 Jun 2016 23:26:01 +0000 (01:26 +0200)]
tree-wide: htonl() is weird, let's use htobe32() instead (#3538)

Super-important change, yeah!

8 years agoutil-lib: rework get_process_cmdline() (#3529)
Lennart Poettering [Tue, 14 Jun 2016 21:52:29 +0000 (23:52 +0200)]
util-lib: rework get_process_cmdline() (#3529)

This reworks get_process_cmdline() quite substantially, fixing the following:

- Fixes:
  https://github.com/systemd/systemd/pull/3512/commits/a4e3bf4d7ac2de51191ce136ee9361ba319e106c#r66837630

- The passed max_length is also applied to the "comm" name, if comm_fallback is
  set.

- The right thing happens if max_length == 1 is specified

- when the cmdline "foobar" is abbreviated to 6 characters the result is not
  "foobar" instead of "foo...".

- trailing whitespace are removed before the ... suffix is appended. The 7
  character abbreviation of "foo barz" is hence "foo..." instead of "foo ...".

- leading whitespace are suppressed from the cmdline

- a comprehensive test case is added

8 years agoMerge pull request #3539 from keszybz/udevadm-man-fix
Lennart Poettering [Tue, 14 Jun 2016 21:41:00 +0000 (23:41 +0200)]
Merge pull request #3539 from keszybz/udevadm-man-fix

Udevadm man fix

8 years agoresolved: in the ResolveHostname() bus call, accept IP addresses with scope
Lennart Poettering [Tue, 14 Jun 2016 21:37:16 +0000 (23:37 +0200)]
resolved: in the ResolveHostname() bus call, accept IP addresses with scope

When we get a literal IP address as string that includes a zone suffix, process
this properly and return the parsed ifindex back to the client, and include it
in the canonical name in case of a link-local IP address.

8 years agoresolved: make sure we initialize the ifindex of direct zone answers properly
Lennart Poettering [Tue, 14 Jun 2016 21:28:54 +0000 (23:28 +0200)]
resolved: make sure we initialize the ifindex of direct zone answers properly

Previously, after checking the local zone for a reply and finding one we'd not
initialize the answer ifindex from that. Let's fix that.

8 years agoresolve: port resolve tool to in_addr_ifindex_{from_string_auto|to_string}()
Lennart Poettering [Tue, 14 Jun 2016 21:27:30 +0000 (23:27 +0200)]
resolve: port resolve tool to in_addr_ifindex_{from_string_auto|to_string}()

We can reuse some code here, so let's do it.

8 years agoman: fix option letter in udevadm control -e
Zbigniew Jędrzejewski-Szmek [Tue, 14 Jun 2016 21:11:46 +0000 (17:11 -0400)]
man: fix option letter in udevadm control -e

-x never worked, so let's just correct the man page.

Fixes #3524.

8 years agoudevadm: trivial simplification
Zbigniew Jędrzejewski-Szmek [Tue, 14 Jun 2016 21:05:42 +0000 (17:05 -0400)]
udevadm: trivial simplification

8 years agoupdate TODO
Lennart Poettering [Thu, 9 Jun 2016 14:15:07 +0000 (16:15 +0200)]
update TODO

8 years agounit: properly comment generated comments in unit files
Lennart Poettering [Thu, 9 Jun 2016 17:53:45 +0000 (19:53 +0200)]
unit: properly comment generated comments in unit files

Fix-up for 2a9a6f8ac04a69ca36d645f9305a33645f22a22b

8 years agosd-ndisc: add missing cast
Lennart Poettering [Thu, 9 Jun 2016 17:49:48 +0000 (19:49 +0200)]
sd-ndisc: add missing cast

Apparently newer gcc versions are a bit more forgiving when assigning an
"unsigned char*" pointer to something of a different type. Let's add the
missing cast so that old gcc versions are fine, too.

8 years agosystemctl: allow percent-based MemoryLimit= settings via systemctl set-property
Lennart Poettering [Wed, 8 Jun 2016 18:52:06 +0000 (20:52 +0200)]
systemctl: allow percent-based MemoryLimit= settings via systemctl set-property

The unit files already accept relative, percent-based memory limit
specification, let's make sure "systemctl set-property" support this too.

Since we want the physical memory size of the destination machine to apply we
pass the percentage in a new set of properties that only exist for this
purpose, and can only be set.

8 years agoutil: introduce physical_memory_scale() to unify how we scale by physical memory
Lennart Poettering [Wed, 8 Jun 2016 18:45:32 +0000 (20:45 +0200)]
util: introduce physical_memory_scale() to unify how we scale by physical memory

The various bits of code did the scaling all different, let's unify this,
given that the code is not trivial.

8 years agocore: make sure to use "infinity" in unit files, not "max"
Lennart Poettering [Wed, 8 Jun 2016 18:05:14 +0000 (20:05 +0200)]
core: make sure to use "infinity" in unit files, not "max"

THe latter is a kernelism, we only understand "infinity".

8 years agocore: when receiving a memory limit via the bus, refuse 0
Lennart Poettering [Wed, 8 Jun 2016 18:04:22 +0000 (20:04 +0200)]
core: when receiving a memory limit via the bus, refuse 0

When parsing unit files we already refuse unit memory limits of zero, let's
also refuse it when the value is set via the bus.

8 years agoman: minor fixes
Lennart Poettering [Wed, 8 Jun 2016 17:37:42 +0000 (19:37 +0200)]
man: minor fixes

8 years agocore: optionally, accept a percentage value for MemoryLimit= and related settings
Lennart Poettering [Wed, 8 Jun 2016 17:36:09 +0000 (19:36 +0200)]
core: optionally, accept a percentage value for MemoryLimit= and related settings

If a percentage is used, it is taken relative to the installed RAM size. This
should make it easier to write generic unit files that adapt to the local system.

8 years agoutil-lib: introduce parse_percent() for parsing percent specifications
Lennart Poettering [Wed, 8 Jun 2016 17:25:38 +0000 (19:25 +0200)]
util-lib: introduce parse_percent() for parsing percent specifications

And port a couple of users over to it.

8 years agoutil: when determining the amount of memory on this system, take cgroup limit into...
Lennart Poettering [Wed, 8 Jun 2016 16:56:20 +0000 (18:56 +0200)]
util: when determining the amount of memory on this system, take cgroup limit into account

When determining the amount of RAM in the system, let's make sure we also read
the root-level cgroup memory limit into account. This isn't particularly useful
on the host, but in containers it makes sure that whatever memory the container
got assigned is actually used for RAM size calculations.

8 years agonetworkd: Tunnel add support to configure key for VTI/VTI6 (#3532)
Susant Sahani [Tue, 14 Jun 2016 17:11:57 +0000 (22:41 +0530)]
networkd: Tunnel add support to configure key for VTI/VTI6 (#3532)

fixes #3298

8 years agoMerge pull request #3527 from poettering/systemctl-fixes
Daniel Mack [Tue, 14 Jun 2016 12:25:43 +0000 (14:25 +0200)]
Merge pull request #3527 from poettering/systemctl-fixes

Systemctl fixes

8 years agomanager: reduce complexity of unit_gc_sweep (#3507)
Lukáš Nykrýn [Tue, 14 Jun 2016 12:20:56 +0000 (14:20 +0200)]
manager: reduce complexity of unit_gc_sweep (#3507)

When unit is marked as UNSURE, we are trying to find if it state was
changed over and over again. So lets not go through the UNSURE states
again. Also when we find a GOOD unit lets propagate the GOOD state to
all units that this unit reference.

This is a problem on machines with a lot of initscripts with different
starting priority, since those units will reference each other and the
original algorithm might get to n! complexity.

Thanks HATAYAMA Daisuke for the expand_good_state code.

8 years agocore: on unified we don't need to check u->pids: we can use proper notifications...
Evgeny Vereshchagin [Tue, 14 Jun 2016 12:08:01 +0000 (15:08 +0300)]
core: on unified we don't need to check u->pids: we can use proper notifications (#3531)

Fixes: #3483

8 years agobuild: fix missing symbol for old kernel headers (#3530)
Andrew Jeddeloh [Tue, 14 Jun 2016 09:09:06 +0000 (02:09 -0700)]
build: fix missing symbol for old kernel headers (#3530)

Fix issue where IN6_ADDR_GEN_MODE_STABLE_PRIVACY is undefined but
IFLA_INET6_ADDR_GEN_MODE is defined and thus the former does not get
fixed in missing.h. This occurs with kernel headers new enough to have
the IFLA_INET6_ADDR_GEN_MODE but old enough to not yet have
IN6_ADDR_GEN_MODE_STABLE_PRIVACY (e.g. 3.18).

8 years agosystemctl: rework "systemctl status" a bit
Lennart Poettering [Mon, 13 Jun 2016 17:11:26 +0000 (19:11 +0200)]
systemctl: rework "systemctl status" a bit

This reworks "systemctl status" and "systemctl show" a bit. It removes the
definition of the `property_info` structure, because we can simply reuse the
existing UnitStatusInfo type for that.

The "could not be found" message is now printed by show_one() itself (and not
its caller), so that it is shown regardless by who the function is called.
(This makes it necessary to pass the unit name to the function.)

This also adds all properties found to a set, and then checks if any of the
properties passed via "--property=" is mising in it, if so, a proper error is
generated.

Support for checking the PID file of a unit is removed, as this cannot be done
reasonably client side (since the systemd instance we are talking to might sit
on another host)

Replaces: #3411
Fixes: #3425
Also see: #3504

8 years agosystemctl: fix assertion hit when showing state of a unit without control group
Lennart Poettering [Mon, 13 Jun 2016 16:54:36 +0000 (18:54 +0200)]
systemctl: fix assertion hit when showing state of a unit without control group

8 years agounit-name: remove spurious newline
Lennart Poettering [Mon, 13 Jun 2016 16:47:42 +0000 (18:47 +0200)]
unit-name: remove spurious newline

8 years agoMerge pull request #3491 from poettering/hwdb-acpi
Tom Gundersen [Mon, 13 Jun 2016 16:41:15 +0000 (18:41 +0200)]
Merge pull request #3491 from poettering/hwdb-acpi

hwdb: update UEFI/ACPI/PNP/EISA/EDID database from UEFI web site

8 years agoMerge pull request #3498 from poettering/syscall-filter-fixes
Lennart Poettering [Mon, 13 Jun 2016 14:54:21 +0000 (16:54 +0200)]
Merge pull request #3498 from poettering/syscall-filter-fixes

Syscall filter fixes, tighter nspawn seccomp sandbox by default

8 years agocore: parse `rd.rescue` and `rd.emergency` as initrd-specific shorthands (#3488)
Ivan Shapovalov [Mon, 13 Jun 2016 14:28:42 +0000 (18:28 +0400)]
core: parse `rd.rescue` and `rd.emergency` as initrd-specific shorthands (#3488)

Typing `rd.rescue` is easier than `rd.systemd.unit=rescue.target`.

8 years agoMerge pull request #3384 from keszybz/localed-keymap
Lennart Poettering [Mon, 13 Jun 2016 14:27:52 +0000 (16:27 +0200)]
Merge pull request #3384 from keszybz/localed-keymap

More verbose logging in localed, unit tests, and a few tweaks to keymap conversions

8 years agonspawn: lock down system call filter a bit
Lennart Poettering [Fri, 10 Jun 2016 16:04:02 +0000 (18:04 +0200)]
nspawn: lock down system call filter a bit

Let's block access to the kernel keyring and a number of obsolete system calls.
Also, update list of syscalls that may alter the system clock, and do raw IO
access. Filter ptrace() if CAP_SYS_PTRACE is not passed to the container and
acct() if CAP_SYS_PACCT is not passed.

This also changes things so that kexec(), some profiling calls, the swap calls
and quotactl() is never available to containers, not even if CAP_SYS_ADMIN is
passed. After all we currently permit CAP_SYS_ADMIN to containers by default,
but these calls should not be available, even then.

8 years agounits: tighten system call filters a bit
Lennart Poettering [Fri, 10 Jun 2016 16:00:12 +0000 (18:00 +0200)]
units: tighten system call filters a bit

Take away kernel keyring access, CPU emulation system calls and various debug
system calls from the various daemons we have.

8 years agocore: improve seccomp syscall grouping a bit
Lennart Poettering [Fri, 10 Jun 2016 15:43:38 +0000 (17:43 +0200)]
core: improve seccomp syscall grouping a bit

This adds three new seccomp syscall groups: @keyring for kernel keyring access,
@cpu-emulation for CPU emulation features, for exampe vm86() for dosemu and
suchlike, and @debug for ptrace() and related calls.

Also, the @clock group is updated with more syscalls that alter the system
clock. capset() is added to @privileged, and pciconfig_iobase() is added to
@raw-io.

Finally, @obsolete is a cleaned up. A number of syscalls that never existed on
Linux and have no number assigned on any architecture are removed, as they only
exist in the man pages and other operating sytems, but not in code at all.
create_module() is moved from @module to @obsolete, as it is an obsolete system
call. mem_getpolicy() is removed from the @obsolete list, as it is not
obsolete, but simply a NUMA API.

8 years agonspawn: order caps to retain alphabetically
Lennart Poettering [Fri, 10 Jun 2016 15:31:06 +0000 (17:31 +0200)]
nspawn: order caps to retain alphabetically

8 years agoupdate TODO
Lennart Poettering [Fri, 10 Jun 2016 15:30:35 +0000 (17:30 +0200)]
update TODO

8 years agoresolved: use single message for both dbus and signal calls (#3515)
Zbigniew Jędrzejewski-Szmek [Mon, 13 Jun 2016 14:24:48 +0000 (10:24 -0400)]
resolved: use single message for both dbus and signal calls (#3515)

Follow-up for #3502.

8 years agoMerge pull request #3520 from keszybz/add-release.md
Lennart Poettering [Mon, 13 Jun 2016 14:13:41 +0000 (16:13 +0200)]
Merge pull request #3520 from keszybz/add-release.md

Add RELEASE.md

8 years agoMerge pull request #3518 from keszybz/test-process-util
Lennart Poettering [Mon, 13 Jun 2016 14:01:44 +0000 (16:01 +0200)]
Merge pull request #3518 from keszybz/test-process-util

Enhance test-process-util to take the PID to look at

8 years agonetworkd: fix NULL pointer (#3523)
Susant Sahani [Mon, 13 Jun 2016 13:57:38 +0000 (19:27 +0530)]
networkd: fix NULL pointer (#3523)

Not every link has kind associated with it.

(gdb) r
Starting program: /home/sus/tt/systemd/systemd-networkd
Missing separate debuginfos, use: dnf debuginfo-install
glibc-2.23.1-7.fc24.x86_64
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
vboxnet0: Gained IPv6LL
wlp3s0: Gained IPv6LL
enp0s25: Gained IPv6LL
Enumeration completed

Program received signal SIGSEGV, Segmentation fault.
0x00007ffff6e27ade in __strcmp_sse2_unaligned () from /lib64/libc.so.6
(gdb) bt
src/network/networkd-link.c:2008
src/network/networkd-link.c:2059
src/network/networkd-link.c:2442
m=0x555555704a30, userdata=0x55555570bfe0) at src/network/networkd-link.c:2497
at src/libsystemd/sd-netlink/sd-netlink.c:347
src/libsystemd/sd-netlink/sd-netlink.c:402
src/libsystemd/sd-netlink/sd-netlink.c:432
userdata=0x5555556f7470) at src/libsystemd/sd-netlink/sd-netlink.c:739
src/libsystemd/sd-event/sd-event.c:2275
src/libsystemd/sd-event/sd-event.c:2626
timeout=18446744073709551615) at src/libsystemd/sd-event/sd-event.c:2685
bus=0x5555556f9af0, name=0x555555692315 "org.freedesktop.network1",
timeout=30000000,
    check_idle=0x55555556ac84 <manager_check_idle>, userdata=0x5555556f6b20) at
src/shared/bus-util.c:134
src/network/networkd-manager.c:1128
src/network/networkd.c:127
(gdb) f 1
src/network/networkd-link.c:2008
2008            if (link->network->bridge || streq("bridge", link->kind)) {
(gdb) p link->kind
$1 = 0x0

8 years agonetworkd: route priority replace parsing config_parse_uint32 with safe_atou32 (#3522)
Susant Sahani [Mon, 13 Jun 2016 13:57:17 +0000 (19:27 +0530)]
networkd: route priority replace parsing config_parse_uint32 with safe_atou32 (#3522)

8 years agocore/execute: pass env vars to PAM session setup (#3503)
Jouke Witteveen [Mon, 13 Jun 2016 10:50:12 +0000 (12:50 +0200)]
core/execute: pass env vars to PAM session setup (#3503)

Move the merger of environment variables before setting up the PAM
session and pass the aggregate environment to PAM setup. This allows
control over the PAM session hooks through environment variables.

PAM session initiation may update the environment. On successful
initiation of a PAM session, we adopt the environment of the
PAM context.

8 years agosystemctl: disallow systemctl --user reboot (#3519)
Zbigniew Jędrzejewski-Szmek [Mon, 13 Jun 2016 04:57:28 +0000 (00:57 -0400)]
systemctl: disallow systemctl --user reboot (#3519)

... as well as halt/poweroff/kexec/suspend/hibernate/hybrid-sleep.
Running those commands will fail in user mode, but we try to set the wall
message first, which might even succeed for privileged users. Best to nip
the whole sequence in the bud.

https://github.com/systemd/systemd/pull/3453#issuecomment-225455156

8 years agoAdd RELEASE.md file which lists the steps needed for release
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2016 17:43:41 +0000 (13:43 -0400)]
Add RELEASE.md file which lists the steps needed for release

I put it in .github, so it doesn't stand out too much; after all
it's not interesting to most people.

8 years agoCONTRIBUTING: ask people to comment after after force-push
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2016 17:32:23 +0000 (13:32 -0400)]
CONTRIBUTING: ask people to comment after after force-push

8 years agoCONTRIBUTING: remove line wrapping
Zbigniew Jędrzejewski-Szmek [Tue, 31 May 2016 17:27:41 +0000 (13:27 -0400)]
CONTRIBUTING: remove line wrapping

GitHub displays this file poorly, because it preserves the newlines.
Let's try how things look without any wrapping.

8 years agoprocess-util: remove broken support for pid==0
Zbigniew Jędrzejewski-Szmek [Mon, 13 Jun 2016 00:57:41 +0000 (20:57 -0400)]
process-util: remove broken support for pid==0

Our functions that query /proc/pid/ support using pid==0 to mean
self. get_process_id also seemed to support that, but it was not implemented
correctly: the result should be in *uid, not returned, and also it gave
completely bogus result when called from get_process_gid(). But afaict,
get_process_{uid,gid} were never called with pid==0, so it's not an actual
bug. Remove the broken code to avoid confusion.