Age | Commit message (Collapse) | Author | |
---|---|---|---|
2010-08-10 | update fixme | Kay Sievers | |
2010-08-10 | build-sys: prepare release 7systemd/v7 | Lennart Poettering | |
2010-08-10 | unit: hook plymouth into the boot | Lennart Poettering | |
https://bugzilla.redhat.com/show_bug.cgi?id=619922 | |||
2010-08-10 | units: ignore exit codes of killall scripts | Lennart Poettering | |
2010-08-10 | update fixme | Lennart Poettering | |
2010-08-10 | getty: properly synchronize of tty devices being plugged in | Lennart Poettering | |
2010-08-10 | units: make sure that killall does not wait for the tty | Lennart Poettering | |
2010-08-09 | main: fix auto restarting of units after a configuration reload | Lennart Poettering | |
2010-08-09 | swap: properly enter maintenance mode on failure | Lennart Poettering | |
2010-08-09 | manager: when two pending jobs conflict, keep the one that "conflicts", ↵ | Lennart Poettering | |
remove the one that is "conflicted" This gives the writer of units control which unit is kept and which is stopped when two units conflict. | |||
2010-08-09 | service: hide output of sysv scripts if quiet is passed on the kernel cmdline | Lennart Poettering | |
2010-08-09 | service: properly remember if a sysv is actually enabled | Lennart Poettering | |
Previously we checked the SysV priority value to figure out if a SysV unit was enabled or not, since th value was mostly read from the S startup links. Since we read this value from the LSB headers as a fallback we hence ended up considering a lot more services enabled than were actually enabled. This patch adds an explicit boolean which encodes whether a sysv service is enabled or not via S links. https://bugzilla.redhat.com/show_bug.cgi?id=615293 | |||
2010-08-09 | service: show restart value in dump | Lennart Poettering | |
2010-08-09 | dbus: don't call bus_path_escape() with NULL unit name | Lennart Poettering | |
Fixes an assertion triggerable via D-Bus. https://bugzilla.redhat.com/show_bug.cgi?id=622008 | |||
2010-08-09 | systemctl: show exit code only if it is actually set | Lennart Poettering | |
2010-08-09 | update fixme | Kay Sievers | |
2010-08-07 | man: minor man page fix | Lennart Poettering | |
2010-08-07 | systemctl: fix parsing of DBus reply in 'dot' | Michal Schmidt | |
"systemctl dot" has been broken since the addition of the "Following=" property. | |||
2010-08-06 | man: minor man page fix | Lennart Poettering | |
2010-08-06 | util: when formatting timestamps return '0' for 0 timestamps instead of ↵ | Lennart Poettering | |
empty string | |||
2010-08-06 | sd-daemon: fix compilation on old systems lacking SOCK_CLOEXEC | Lennart Poettering | |
2010-08-06 | update fixme | Kay Sievers | |
2010-08-06 | build-sys: prepare new releasesystemd/v6 | Lennart Poettering | |
2010-08-06 | man: document %triggerin usage | Lennart Poettering | |
2010-08-06 | device: properly handle devices that are referenced before they show up | Lennart Poettering | |
2010-08-06 | cgroup: if the system bus cannot be found, send cgroup empty msg directly to ↵ | Lennart Poettering | |
init proces | |||
2010-08-06 | manager: downgrade a few log msgs regarding conflicting but fixable jobs | Lennart Poettering | |
2010-08-06 | automount: order automount units after fsck, too | Lennart Poettering | |
2010-08-06 | units: add missing fsck.target file | Lennart Poettering | |
2010-08-06 | units: split fsck.target from sysinit.target for suse compat | Lennart Poettering | |
2010-08-06 | main: automatically spawn a getty on the kernel configured serial console | Lennart Poettering | |
2010-08-05 | manager: fix conflicting job check | Lennart Poettering | |
2010-08-05 | manager: when breaking ordering cycle show full cycle loop | Lennart Poettering | |
2010-08-05 | units: always send HUP when dealing with shells/gettys/logins | Lennart Poettering | |
2010-08-05 | service: read special startup dirs only on the respective distros | Lennart Poettering | |
2010-08-05 | selinux: minor error handling fix | Lennart Poettering | |
2010-08-05 | service: always sort services from suse B runlevel before services from ↵ | Lennart Poettering | |
normal runlevels | |||
2010-08-05 | reboot: handle -p switch properly | Michal Schmidt | |
https://bugzilla.redhat.com/show_bug.cgi?id=618678 | |||
2010-08-05 | selinux: fix labels only when configured for it | Lennart Poettering | |
2010-08-04 | units: getty - suse: login wants SIGHUP | Kay Sievers | |
2010-08-04 | units: suse - reboot: do not wait for tty | Kay Sievers | |
2010-08-04 | reboot: don't wait for input tty | Lennart Poettering | |
2010-08-04 | prepare new releasesystemd/v5 | Lennart Poettering | |
2010-08-04 | units: remove redundant ordering dependency | Lennart Poettering | |
2010-08-04 | selinux: rework selinux tests a little | Lennart Poettering | |
2010-08-04 | selinux: fix if vs. ifdef mixup | Lennart Poettering | |
2010-08-03 | units: make sure that prefdm wins over the getty if both are pulled in | Lennart Poettering | |
2010-08-03 | units: add conflicts between prefdm and getty@tty1 to avoid race for tty1 | Lennart Poettering | |
2010-08-03 | Systemd is causing mislabeled devices to be created and then attempting to ↵ | Daniel J Walsh | |
read them. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 07/28/2010 05:57 AM, Kay Sievers wrote: > On Wed, Jul 28, 2010 at 11:43, Lennart Poettering > <lennart@poettering.net> wrote: >> On Mon, 26.07.10 16:42, Daniel J Walsh (dwalsh@redhat.com) wrote: >>> tcontext=system_u:object_r:device_t:s0 tclass=chr_file >>> type=1400 audit(1280174589.476:7): avc: denied { read } for pid=1 >>> comm="systemd" name="autofs" dev=devtmpfs ino=9482 >>> scontext=system_u:system_r:init_t:s0 >>> tcontext=system_u:object_r:device_t:s0 tclass=chr_file >>> type=1400 audit(1280174589.476:8): avc: denied { read } for pid=1 >>> comm="systemd" name="autofs" dev=devtmpfs ino=9482 >>> scontext=system_u:system_r:init_t:s0 >>> tcontext=system_u:object_r:device_t:s0 tclass=chr_file >>> >>> Lennart, we talked about this earlier. I think this is caused by the >>> modprobe calls to create /dev/autofs. Since udev is not created at the >>> point that init loads the kernel modules, the devices get created with >>> the wrong label. Once udev starts the labels get fixed. >>> >>> I can allow init_t to read device_t chr_files. >> >> Hmm, I think a cleaner fix would be to make systemd relabel this device >> properly before accessing it? Given that this is only one device this >> should not be a problem for us to maintain, I think? How would the >> fixing of the label work? Would we have to spawn restorecon for this, or >> can we actually do this in C without too much work? > > I guess we can just do what udev is doing, and call setfilecon(), with > a context of an earlier matchpathcon(). > > Kay > _______________________________________________ > systemd-devel mailing list > systemd-devel@lists.freedesktop.org > http://lists.freedesktop.org/mailman/listinfo/systemd-devel Here is the updated patch with a fix for the labeling of /dev/autofs -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.14 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAkxQMyoACgkQrlYvE4MpobNviACfWgxsjW2xzz1qznFex8RVAQHf gIEAmwRmRcLvGqYtwQaZ3WKIg8wmrwNk =pC2e | |||
2010-08-03 | update fixme | Lennart Poettering | |