Frantisek Sumsal [Wed, 17 May 2023 19:49:20 +0000 (21:49 +0200)]
test: create nspawn config files when collecting coverage
Which bind-mounts the $BUILD_DIR into the container. This whole coverage
thing is getting slightly ridiculous.
Follow-up to
3b2823a749, but for non-machinectl containers.
Frantisek Sumsal [Wed, 17 May 2023 13:35:10 +0000 (15:35 +0200)]
test: cover --bind-user=
Frantisek Sumsal [Wed, 17 May 2023 12:57:50 +0000 (14:57 +0200)]
test: add a couple of sanity tests for --port=
Frantisek Sumsal [Wed, 17 May 2023 11:57:37 +0000 (13:57 +0200)]
test: drop "check" from test case names
Frantisek Sumsal [Wed, 17 May 2023 11:09:02 +0000 (13:09 +0200)]
test: exercise a couple of error paths in nspawn's OCI code as well
Frantisek Sumsal [Wed, 17 May 2023 09:06:40 +0000 (11:06 +0200)]
nspawn: clean up & unify cleanup handlers
Also, make them follow our naming conventions.
Frantisek Sumsal [Wed, 17 May 2023 08:53:57 +0000 (10:53 +0200)]
nspawn: use ASSERT_PTR() more
Mateusz Poliwczak [Wed, 17 May 2023 15:55:42 +0000 (17:55 +0200)]
nss-resolve: report EAI_NODATA
Matt Johnston [Thu, 18 May 2023 04:28:06 +0000 (12:28 +0800)]
busctl: Add space before "tree" paths for copying
This allows a double-click on the path in a terminal to select the
whole path. Otherwise the leading '-' character is also included in
the copied path.
```
New output:
./busctl tree org.freedesktop.network1
`- /org
`- /org/freedesktop
|- /org/freedesktop/LogControl1
`- /org/freedesktop/network1
|- /org/freedesktop/network1/link
| |- /org/freedesktop/network1/link/_31
| |- /org/freedesktop/network1/link/_32
```
Yu Watanabe [Thu, 18 May 2023 08:54:33 +0000 (17:54 +0900)]
Merge pull request #27673 from YHNdnzj/restartsteps-transient
core,bus-unit-util: add missing RestartSteps and RestartMaxDelaySec to bus_append_service_property
Yu Watanabe [Thu, 18 May 2023 08:49:41 +0000 (17:49 +0900)]
README: drop busybox requirement
Follow-up for
5656759d0617594ee8e850a258a21d3e187bf02c.
Yu Watanabe [Thu, 18 May 2023 08:47:02 +0000 (17:47 +0900)]
Merge pull request #27677 from mrc0mmand/test-followups
test: get rid of the busybox stuff
Mike Yuan [Wed, 17 May 2023 15:47:53 +0000 (23:47 +0800)]
Revert (partially) "man: Clarify when OnFailure= activates after restarts (#7646)"
This reverts part of commit
bd2538b50ba283c9ce39142d5d16d90184a55b90,
specifically changes to the description of service state between auto-restarts.
Fixes #27594
Frantisek Sumsal [Wed, 17 May 2023 18:14:05 +0000 (20:14 +0200)]
test: explicitly use bash
To avoid unexpected surprised in CIs with different default shell.
Frantisek Sumsal [Wed, 17 May 2023 17:10:55 +0000 (19:10 +0200)]
test: get rid of the busybox stuff
It already required a lot of workarounds, since the busybox utilities
often work differently than their "full" counterparts, and putting
the container together using our "tools" is quite simple anyway.
Mike Yuan [Wed, 17 May 2023 15:33:05 +0000 (23:33 +0800)]
bus-unit-util: add missing RestartSteps and RestartMaxDelaySec to bus_append_service_property
Follow-up for
be1adc27fc61ba723bd0392199f7b82ef9f1c970
Mike Yuan [Wed, 17 May 2023 16:15:23 +0000 (00:15 +0800)]
core: rename RestartSecMax to RestartMaxDelaySec
Frantisek Sumsal [Wed, 17 May 2023 07:05:04 +0000 (09:05 +0200)]
test: mangle the machine ID only for the QEMU test part
systemd-nspawn doesn't like invalid machine IDs and refuses to boot with one:
TEST-74-AUX-UTILS RUN: Tests for auxiliary utilities
...
Spawning container TEST-74-AUX-UTILS--3 on /var/tmp/systemd-test-TEST-74-AUX-UTILS_3/root.
Press Ctrl-] three times within 1s to kill container.
Failed to read machine ID from container image: Structure needs cleaning
E: nspawn failed with exit code 1
Follow-up to
b4d42a82eb.
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 12:12:33 +0000 (14:12 +0200)]
Merge pull request #27669 from keszybz/man-fixes-254
Some simple man page fixes to reduce the list of issues tagged for v254
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 12:12:08 +0000 (14:12 +0200)]
Merge pull request #27671 from keszybz/manpage-fixes-254-2
man: fixes for assorted issues reported by the manpage-l10n project
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 10:24:04 +0000 (12:24 +0200)]
man: fixes for assorted issues reported by the manpage-l10n project
Fixes #26761.
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 09:16:56 +0000 (11:16 +0200)]
man/tmpfiles: fix off-by-one in example
Reported and diagnosed by gitterman. Fixes #26617.
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 09:12:32 +0000 (11:12 +0200)]
man: explain allowed values for /sys/power/{disk,state}
Also fix the grammar: "neither" can only be used with two values, and
here we have an inderminate number >= 1.
Fixes #26460.
Zbigniew Jędrzejewski-Szmek [Wed, 17 May 2023 07:52:17 +0000 (09:52 +0200)]
man: say that ProtectClock= also affects reads
Fixes #26413: the docs said that the filter prevents writes, but it just a
filter at the system call level, and some of those calls are used for writing
and reading. This is confusing esp. when a higher level library call like
ntp_gettime() is denied.
I don't think it's realistic that we'll make the filter smarter in the near
future, so let's change the docs to describe the implementation.
Also, split out the advice part into a separate paragraph.
Yu Watanabe [Wed, 17 May 2023 00:53:58 +0000 (09:53 +0900)]
Merge pull request #27664 from mrc0mmand/test-merge
test: let's merge more tests together
Frantisek Sumsal [Tue, 16 May 2023 20:41:03 +0000 (22:41 +0200)]
test: move runas() to the shared utility library
Frantisek Sumsal [Tue, 16 May 2023 18:55:45 +0000 (20:55 +0200)]
test: make shellcheck happy again
No functional changes.
Frantisek Sumsal [Tue, 16 May 2023 18:41:35 +0000 (20:41 +0200)]
test: merge TEST-48-START-STOP-NO-RELOAD into TEST-23-UNIT-FILE
Frantisek Sumsal [Tue, 16 May 2023 18:31:49 +0000 (20:31 +0200)]
test: merge TEST-49-RUNTIME-BIND-PATHS into TEST-23-UNIT-FILE
Frantisek Sumsal [Tue, 16 May 2023 17:56:30 +0000 (19:56 +0200)]
test: clean up test artifacts
So we don't run into unexpected fails when two tests use the same paths.
Frantisek Sumsal [Tue, 16 May 2023 17:45:56 +0000 (19:45 +0200)]
test: merge TEST-28-PERCENTJ-WANTEDBY into TEST-23-UNIT-FILE
Frantisek Sumsal [Tue, 16 May 2023 17:26:42 +0000 (19:26 +0200)]
test: merge TEST-56-EXIT-TYPE into TEST-19-CGROUP
And clean it up a bit.
Frantisek Sumsal [Tue, 16 May 2023 17:17:40 +0000 (19:17 +0200)]
test: rename TEST-19-DELEGATE to TEST-19-CGROUP
And clean it up a bit.
Frantisek Sumsal [Tue, 16 May 2023 17:11:51 +0000 (19:11 +0200)]
test: introduce get_cgroup_hierarchy()
Frantisek Sumsal [Tue, 16 May 2023 17:09:13 +0000 (19:09 +0200)]
test: rename assert.sh to util.sh
So we can extend it with additional utility functions without making it
confusing.
No functional change.
Frantisek Sumsal [Tue, 16 May 2023 16:50:43 +0000 (18:50 +0200)]
test: merge TEST-33-CLEAN-UNIT into TEST-23-UNIT-FILE
Frantisek Sumsal [Tue, 16 May 2023 16:42:14 +0000 (18:42 +0200)]
test: merge TEST-27-STDOUTFILE into TEST-23-UNIT-FILE
Frantisek Sumsal [Tue, 16 May 2023 16:31:45 +0000 (18:31 +0200)]
test: merge TEST-14-MACHINE-ID into TEST-74-AUX-UTILS
Antonio Alvarez Feijoo [Tue, 16 May 2023 14:49:28 +0000 (16:49 +0200)]
man/systemd-sysext: correct explanation of confexts directories
Lennart Poettering [Mon, 15 May 2023 19:31:38 +0000 (21:31 +0200)]
switch-root: add a comment regarding the safety limits of rm_rf_children()
Yu Watanabe [Tue, 16 May 2023 16:41:13 +0000 (01:41 +0900)]
Merge pull request #27606 from YHNdnzj/loginctl-list-show-state
loginctl: list-{users,sessions}: add a column for showing state
Yu Watanabe [Tue, 16 May 2023 16:39:40 +0000 (01:39 +0900)]
Merge pull request #27655 from yuwata/udev-net-assign-alternative-names-only-on-add-event
udev/net: assign alternative names only on add event
Frantisek Sumsal [Tue, 16 May 2023 15:26:25 +0000 (17:26 +0200)]
Merge pull request #27651 from mrc0mmand/more-nspawn-tests
nspawn: OCI related fixes & tests
Mike Yuan [Tue, 16 May 2023 14:00:57 +0000 (22:00 +0800)]
Merge pull request #27659 from yuwata/memfd-seal
memfd-util: handle F_SEAL_EXEC flag
Mike Yuan [Tue, 16 May 2023 13:53:24 +0000 (21:53 +0800)]
Merge pull request #27638 from YHNdnzj/upheldby-unit-file
unit-file: support UpheldBy= in [Install] settings (adding Upholds= deps from .upholds/)
Lennart Poettering [Tue, 16 May 2023 13:46:29 +0000 (06:46 -0700)]
Merge pull request #27573 from poettering/sd-bus-description
sd-bus: pass bus description (and comm name) to per via socket address binding on AF_UNIX
Lennart Poettering [Tue, 16 May 2023 12:26:48 +0000 (05:26 -0700)]
Merge pull request #27648 from poettering/common-dissect-dir
pid1: add common root dir inode to mount disk images to in private namespaces
Lennart Poettering [Tue, 16 May 2023 12:26:09 +0000 (05:26 -0700)]
Merge pull request #27647 from poettering/mount-setup-tweaklets
mount-setup: minor tweaks
Lennart Poettering [Tue, 16 May 2023 12:25:43 +0000 (05:25 -0700)]
Merge pull request #27658 from poettering/base-fs-run
base-filesystem: also set up /run/ mount point if missing
Lennart Poettering [Tue, 16 May 2023 07:35:39 +0000 (09:35 +0200)]
man: indicate that the JOB parameter to "systemctl cancel" is optional
As per:
https://social.treehouse.systems/@grawity/
110376583742207755
Mike Yuan [Mon, 15 May 2023 05:45:33 +0000 (13:45 +0800)]
test: add test for state in loginctl list-{users,sessions}
Mike Yuan [Thu, 11 May 2023 05:21:37 +0000 (13:21 +0800)]
loginctl: list-sessions: also show state
Mike Yuan [Thu, 11 May 2023 05:17:59 +0000 (13:17 +0800)]
loginctl: list-sessions: minor modernization
Mike Yuan [Thu, 11 May 2023 05:05:39 +0000 (13:05 +0800)]
loginctl: list-users: also show state
Lennart Poettering [Fri, 5 May 2023 19:33:56 +0000 (21:33 +0200)]
busctl: set a description for the bus connection
Unlike most other bus connections in our codebase this one is created
manually and every setting set invididually. It hence does not have a
description by default (as all automatic connections have). Set one
explicitly.
Lennart Poettering [Fri, 5 May 2023 19:45:54 +0000 (21:45 +0200)]
pid1: debug log client comm/description strings if available for incoming connections
Very useful for debugging, to see which clients actually connect.
Lennart Poettering [Fri, 5 May 2023 19:47:02 +0000 (21:47 +0200)]
test: add testcase for the new sockaddr metainfo logic
Lennart Poettering [Fri, 5 May 2023 19:43:57 +0000 (21:43 +0200)]
sd-bus: use the new information in the client's sockaddr in the creds structure
Now that clients might convey comm/description strings via the sockaddr,
let's actually use them on the other side, read the data via
getpeername() parse it, and include it in the "owner" creds (which is
how we call the peer's creds).
Yu Watanabe [Tue, 16 May 2023 09:59:25 +0000 (18:59 +0900)]
test: add basic test for memfd_set_sealed() and memfd_get_sealed()
Yu Watanabe [Tue, 16 May 2023 09:50:39 +0000 (18:50 +0900)]
memfd-util: set F_SEAL_EXEC flag if supported
Yu Watanabe [Tue, 16 May 2023 09:48:29 +0000 (18:48 +0900)]
memfd-util: memfd may also have F_SEAL_EXEC flag
Follow-up for
c29715a8f77d96cd731b4a3083b3a852b3b61eb8.
Fixes #27608.
Yu Watanabe [Tue, 16 May 2023 09:46:16 +0000 (18:46 +0900)]
missing: add more F_SEAL_XYZ flags
Lennart Poettering [Tue, 16 May 2023 09:44:27 +0000 (11:44 +0200)]
base-filesystem: mention why we don't carry an entry for /tmp/ for now
Frantisek Sumsal [Tue, 16 May 2023 09:40:33 +0000 (11:40 +0200)]
nspawn: make sure the device type survives when setting device mode
Lennart Poettering [Mon, 15 May 2023 19:20:36 +0000 (21:20 +0200)]
base-filesystem: also set up /run/ mount point if missing
We don't support images without, hence create this one too, like we
create all other relevant mount points we definitely require for
booting.
Yu Watanabe [Tue, 16 May 2023 07:28:54 +0000 (16:28 +0900)]
test: add tests for renaming network interface
Frantisek Sumsal [Mon, 15 May 2023 19:10:07 +0000 (21:10 +0200)]
fuzz: update the base JSON for fuzz-nspawn-oci
Frantisek Sumsal [Mon, 15 May 2023 16:57:55 +0000 (18:57 +0200)]
test: add a couple of tests for nspawn's OCI stuff
Frantisek Sumsal [Mon, 15 May 2023 18:25:43 +0000 (20:25 +0200)]
nspawn: fix a global-buffer-overflow
Whoopsie.
=================================================================
==
3789231==ERROR: AddressSanitizer: global-buffer-overflow on address 0x00000051d0b8 at pc 0x7f70850bc904 bp 0x7ffd9bbdf660 sp 0x7ffd9bbdf658
READ of size 8 at 0x00000051d0b8 thread T0
#0 0x7f70850bc903 in json_dispatch ../src/shared/json.c:4347
#1 0x4a5b54 in oci_seccomp_syscalls ../src/nspawn/nspawn-oci.c:1838
#2 0x7f70850bd359 in json_dispatch ../src/shared/json.c:4395
#3 0x4a668c in oci_seccomp ../src/nspawn/nspawn-oci.c:1905
#4 0x7f70850bd359 in json_dispatch ../src/shared/json.c:4395
#5 0x4a7d8c in oci_linux ../src/nspawn/nspawn-oci.c:2030
#6 0x7f70850bd359 in json_dispatch ../src/shared/json.c:4395
#7 0x4aa31c in oci_load ../src/nspawn/nspawn-oci.c:2198
#8 0x446cec in load_oci_bundle ../src/nspawn/nspawn.c:4744
#9 0x44ffa7 in run ../src/nspawn/nspawn.c:5477
#10 0x4552fb in main ../src/nspawn/nspawn.c:5920
#11 0x7f7083a4a50f in __libc_start_call_main (/lib64/libc.so.6+0x2750f)
#12 0x7f7083a4a5c8 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x275c8)
#13 0x40d284 in _start (/home/fsumsal/repos/@systemd/systemd/build-san/systemd-nspawn+0x40d284)
0x00000051d0b8 is located 40 bytes to the left of global variable 'bus_standard_errors_copy_0' defined in '../src/libsystemd/sd-bus/bus-error.h:57:1' (0x51d0e0) of size 8
0x00000051d0b8 is located 0 bytes to the right of global variable 'table' defined in '../src/nspawn/nspawn-oci.c:1829:43' (0x51d040) of size 120
SUMMARY: AddressSanitizer: global-buffer-overflow ../src/shared/json.c:4347 in json_dispatch
Shadow bytes around the buggy address:
0x00008009b9c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009b9d0: 00 00 00 00 f9 f9 f9 f9 00 00 00 00 00 00 00 00
0x00008009b9e0: 00 00 f9 f9 f9 f9 f9 f9 00 00 00 00 00 00 00 00
0x00008009b9f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009ba00: 00 f9 f9 f9 f9 f9 f9 f9 00 00 00 00 00 00 00 00
=>0x00008009ba10: 00 00 00 00 00 00 00[f9]f9 f9 f9 f9 00 f9 f9 f9
0x00008009ba20: f9 f9 f9 f9 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009ba30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009ba40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009ba50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x00008009ba60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==
3789231==ABORTING
Frantisek Sumsal [Mon, 15 May 2023 18:10:05 +0000 (20:10 +0200)]
nspawn: fix inverted condition
Frantisek Sumsal [Mon, 15 May 2023 17:45:13 +0000 (19:45 +0200)]
nspawn: call json_dispatch() with a correct pointer
Otherwise hilarity ensues:
AddressSanitizer:DEADLYSIGNAL
=================================================================
==722==ERROR: AddressSanitizer: SEGV on unknown address 0xffffffff00000000 (pc 0x7f8d50ca9ffb bp 0x7fff11b0d4a0 sp 0x7fff11b0cc30 T0)
==722==The signal is caused by a READ memory access.
#0 0x7f8d50ca9ffb in __interceptor_strcmp.part.0 (/lib64/libasan.so.8+0xa9ffb)
#1 0x7f8d4f9cf5a1 in strcmp_ptr ../src/fundamental/string-util-fundamental.h:33
#2 0x7f8d4f9cf5f8 in streq_ptr ../src/fundamental/string-util-fundamental.h:46
#3 0x7f8d4f9d74d2 in free_and_strdup ../src/basic/string-util.c:948
#4 0x49139a in free_and_strdup_warn ../src/basic/string-util.h:197
#5 0x4923eb in oci_absolute_path ../src/nspawn/nspawn-oci.c:139
#6 0x7f8d4f6bd359 in json_dispatch ../src/shared/json.c:4395
#7 0x4a8831 in oci_hooks_array ../src/nspawn/nspawn-oci.c:2089
#8 0x7f8d4f6bd359 in json_dispatch ../src/shared/json.c:4395
#9 0x4a8b56 in oci_hooks ../src/nspawn/nspawn-oci.c:2112
#10 0x7f8d4f6bd359 in json_dispatch ../src/shared/json.c:4395
#11 0x4aa298 in oci_load ../src/nspawn/nspawn-oci.c:2197
#12 0x446cec in load_oci_bundle ../src/nspawn/nspawn.c:4744
#13 0x44ffa7 in run ../src/nspawn/nspawn.c:5477
#14 0x4552fb in main ../src/nspawn/nspawn.c:5920
#15 0x7f8d4e04a50f in __libc_start_call_main (/lib64/libc.so.6+0x2750f)
#16 0x7f8d4e04a5c8 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x275c8)
#17 0x40d284 in _start (/usr/bin/systemd-nspawn+0x40d284)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV (/lib64/libasan.so.8+0xa9ffb) in __interceptor_strcmp.part.0
==722==ABORTING
Frantisek Sumsal [Mon, 15 May 2023 17:44:15 +0000 (19:44 +0200)]
nspawn: all hooks should be arrays of objects, not just objects
See: https://github.com/opencontainers/runtime-spec/blob/v1.0.0/config.md#posix-platform-hooks
Frantisek Sumsal [Mon, 15 May 2023 17:06:14 +0000 (19:06 +0200)]
nspawn: use the just returned errno in the log message
Use the returned errno even though we are going to ignore it, otherwise
the log message is just confusing:
config.json:119:13: Failed to resolve device node 4:2, ignoring: Success
Frantisek Sumsal [Mon, 15 May 2023 16:42:08 +0000 (18:42 +0200)]
nspawn: disableOOMKiller should be boolean, not int
See: https://github.com/opencontainers/runtime-spec/blob/v1.0.0/config-linux.md#memory
Frantisek Sumsal [Tue, 16 May 2023 06:19:09 +0000 (08:19 +0200)]
nspawn: modernize the cleanup functions a bit
Frantisek Sumsal [Tue, 16 May 2023 06:18:32 +0000 (08:18 +0200)]
nspawn: avoid NULL pointer dereference
When merging the settings we take the pointer to the array of extra
devices, but don't reset the array counter to zero. This later leads to
a NULL pointer dereference, where device_node_array_free() attempts to
loop over a NULL pointer:
+ systemd-nspawn --oci-bundle=/var/lib/machines/testsuite-13.oci-bundle.Npo
../src/nspawn/nspawn-settings.c:118:29: runtime error: member access within null pointer of type 'struct DeviceNode'
#0 0x4b91ee in device_node_array_free ../src/nspawn/nspawn-settings.c:118
#1 0x4ba42a in settings_free ../src/nspawn/nspawn-settings.c:161
#2 0x410b79 in settings_freep ../src/nspawn/nspawn-settings.h:249
#3 0x446ce8 in load_oci_bundle ../src/nspawn/nspawn.c:4733
#4 0x44ff42 in run ../src/nspawn/nspawn.c:5476
#5 0x455296 in main ../src/nspawn/nspawn.c:5919
#6 0x7f0cb7a4a50f in __libc_start_call_main (/lib64/libc.so.6+0x2750f)
#7 0x7f0cb7a4a5c8 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x275c8)
#8 0x40d284 in _start (/usr/bin/systemd-nspawn+0x40d284)
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior ../src/nspawn/nspawn-settings.c:118:29 in
Also, add an appropriate assert to catch such issues in the future.
Lennart Poettering [Fri, 5 May 2023 19:35:19 +0000 (21:35 +0200)]
sd-bus: bind outgoing AF_UNIX sockets to abstract addresses conveying client comm + bus description string
Let's pass some additional meta information along bus connections
without actually altering the communication protocol.
Pass the client comm and client description string of the bus via
including it in the abstract namespace client socket address we connect
to. This is purely informational (and entirely user controlled), but has
the benefit that servers can make use of the information if they want,
but really don't have to. It works entirely transparently.
This takes inspiration from how we convey similar information via
credential socket connections.
Lennart Poettering [Fri, 5 May 2023 19:47:43 +0000 (21:47 +0200)]
test-bus-server: minor modernizations
Lennart Poettering [Fri, 5 May 2023 18:01:05 +0000 (20:01 +0200)]
test-bus-chat: modernize a few things
Lennart Poettering [Mon, 15 May 2023 09:53:07 +0000 (11:53 +0200)]
mount-setup: minor modernization
Lennart Poettering [Mon, 15 May 2023 09:52:47 +0000 (11:52 +0200)]
mount-setup: minor log improvement
Lennart Poettering [Mon, 15 May 2023 09:52:33 +0000 (11:52 +0200)]
mount-setup: port to logging about mount attempts via mount_*follow_verbose()
Yu Watanabe [Tue, 16 May 2023 03:28:23 +0000 (12:28 +0900)]
udev/net: assign alternative names only on add uevent
Previously, we first assign alternative names to a network interface,
then later change its main name if requested. So, we could not assign
the name that currently assigned as the main name of an interface as an
alternative name. So, we retry to assign the previous main name as an
alternative name on later move uevent.
However, that causes some confusing situation. E.g. if a .link file has
```
Name=foo
AlternativeNames=foo baz
```
then even if the interface is renamed by a user e.g. by invoking 'ip link'
command manually, the interface can be still referenced as 'foo', as the
name is now assigned as an alternative name.
This makes the order of name assignment inverse: the main name is first
changed, and then the requested alternative names are assigned. And
udevd do not assign alternative names on move uevent.
Replaces #27506.
Yu Watanabe [Tue, 16 May 2023 04:29:37 +0000 (13:29 +0900)]
sd-netlink: make rtnl_set_link_name() optionally append alternative names
Yu Watanabe [Tue, 16 May 2023 04:05:09 +0000 (13:05 +0900)]
udev/net: generate new network interface name only on add uevent
On other uevents, the name will be anyway ignored in rename_netif() in
udev-event.c.
Yu Watanabe [Tue, 16 May 2023 02:46:11 +0000 (11:46 +0900)]
udev/net: verify ID_NET_XYZ before trying to assign it as an alternative name
Yu Watanabe [Tue, 16 May 2023 02:29:49 +0000 (11:29 +0900)]
udev: make udev_builtin_run() take UdevEvent*
No functional change, preparation for later commits.
Yu Watanabe [Tue, 16 May 2023 07:34:31 +0000 (16:34 +0900)]
udev: use SYNTHETIC_ERRNO() at one more place
Lennart Poettering [Mon, 15 May 2023 09:49:48 +0000 (11:49 +0200)]
dissect-image: port mount_image_privately_interactively() to use /run/systemd/mount-rootfs/ too
Let's use the same common directory as the unit logic uses.
This means we have less to clean up, and opens the door to eventually
allow unprivileged operation of the
mount_image_privately_interactively() logic.
Lennart Poettering [Mon, 15 May 2023 10:32:54 +0000 (12:32 +0200)]
pid1: port unit namespacing to new /run/systemd/mount-rootfs dir
Lennart Poettering [Mon, 15 May 2023 09:35:15 +0000 (11:35 +0200)]
namespace: introduce a common dir in /run/ that we can use to see new root fs up on
This creates a new dir /run/systemd/mount-rootfs/ early in PID 1 that
thus always exists. It's supposed to be used by any code that creates
its own mount namespace and then sets up a new root dir to switch into.
So far in many cases we used a temporary dir (which needed explicit
clean-up) or a purpose-specific fixed dir.
Let's create a common dir instead, that always exists (as it is created
in PID 1 early on, always).
Besides making things more robust, as manual clean-up of the inode is
not necessary anymore this also opens the door for unprivileged programs
to use the same dir, since it now always exists.
Set the access mode to 555 (instead of the otherwise previously used
0755, 0700 or similar), so that unprivileged programs can access it, but
we make clear it's not supposed to be written directly to, by anyone,
not even root.
Lennart Poettering [Thu, 20 Apr 2023 16:45:09 +0000 (18:45 +0200)]
mount-util: add umount_and_free() helper
Zbigniew Jędrzejewski-Szmek [Tue, 16 May 2023 06:51:19 +0000 (08:51 +0200)]
Merge pull request #27652 from keszybz/readme-more
Add man page for libsystemd, extend readme and stability promise
Zbigniew Jędrzejewski-Szmek [Mon, 15 May 2023 20:48:50 +0000 (22:48 +0200)]
docs: list all public headers in stability promise
We provide the same stability for all the headers that are public.
Also, mark id128 as portable to other systems. There is really nothing in the
code that would make it hard. It would probably work out-of-the-box.
Zbigniew Jędrzejewski-Szmek [Mon, 15 May 2023 20:35:10 +0000 (22:35 +0200)]
README: describe how our libraries are linked
In https://github.com/systemd/systemd/pull/27637#issuecomment-
1547517316
we discussed disclaiming warranty when distros do version mixing.
But to make this disclaimer meaningful, we need to document what options are
available.
Yu Watanabe [Mon, 15 May 2023 23:30:44 +0000 (08:30 +0900)]
meson: fix description for link-udev-shared option
nikstur [Mon, 15 May 2023 21:34:27 +0000 (23:34 +0200)]
man: use correct name for --bank option
saikat0511 [Mon, 15 May 2023 20:58:50 +0000 (02:28 +0530)]
hwdb: fix keyboard entry for IdeapadFlex5 (#27643)
Fixes a bug caused by
19db450f3a243fcaf0949beebafc3025f8e3a98e (#27211).
Also this makes the model more specific.
Zbigniew Jędrzejewski-Szmek [Mon, 15 May 2023 13:17:13 +0000 (15:17 +0200)]
man: add libsystemd(3)
Before libsystemd-daemon, libsystemd-journal, libsystemd-id128, etc., were
merged into libsystemd, it was enough to have individual man pages for them.
But they have been delivered as one thing for many years, so it's better to
have a landing page for libsystemd. It mostly directs to individual pages
anyway.
Zbigniew Jędrzejewski-Szmek [Mon, 15 May 2023 20:37:20 +0000 (22:37 +0200)]
meson: add sd_pid_notify_barrier link
Fixup for
0de343187127f6a5a93602608812e60fc4092c9a.