| Age | Commit message (Collapse) | Author | 
|---|
|  | Let's remove the tests for cg_path_get_machine_name(), since they no
longer operate solely on the cgroup path, but actually look up data in
/run. Since we have a test for cg_pid_get_machine_name() this shouldn't
be too much of a loss. | 
|  |  | 
|  | Otherwise we get a (harmless) message like:
systemd-logind[30845]: Failed to process message [type=signal sender=:1.36 path=/org/freedesktop/systemd1/job/4674 interface=org.freedesktop.DBus.Properties member=PropertiesChanged signature=sa{sv}as]: Invalid argument | 
|  | KillUserProcesses=yes/no should be ignored when termination is
explicitly requested. | 
|  |  | 
|  |  | 
|  | In function user_get_state() remove the session_is_active() check, just
count on the session_get_state() function to get the correct session
state.
session_is_active() may return true before starting the session scope
and user service, this means it will return true even before the creation
of the session fifo_fd which will produce incorrect states.
So be consistent and just use session_get_state(). | 
|  | disabled | 
|  | or services) as machine with machined | 
|  |  | 
|  |  | 
|  | the container with machined | 
|  |  | 
|  | The .sym file somehow lacks these declarations, so add these. You have to
run "make clean" to make sure the sym-test runs fine afterwards. | 
|  | This fixes a regression introduced in 672682a6b | 
|  | Also limit the range of vlan ids. Other implementations and
documentation use the ranges {0,1}-{4094,4095}, but we use
the one accepted by the kernel: 0-4094.
Reported-by: Oleksii Shevchuk <alxchk@gmail.com> | 
|  |  | 
|  |  | 
|  | We are more likely to catch errors if we don't use '0' as test value. | 
|  |  | 
|  | namespacing | 
|  | Let's always call the security labels the same way:
  SMACK: "Smack Label"
  SELINUX: "SELinux Security Context"
And the low-level encapsulation is called "seclabel". Now let's hope we
stick to this vocabulary in future, too, and don't mix "label"s and
"security contexts" and so on wildly. | 
|  | -, like for others settings.
Also remove call to security_check_context, as this doesn't serve anything, since
setexeccon will fail anyway. | 
|  |  | 
|  | This permit to let system administrators decide of the domain of a service.
This can be used with templated units to have each service in a différent
domain ( for example, a per customer database, using MLS or anything ),
or can be used to force a non selinux enabled system (jvm, erlang, etc)
to start in a different domain for each service. | 
|  | Found by the new check-includes make target. | 
|  | This was noticed in Brussels at the hackfest. The fstab-generator currently
creates a broken symlink pointing to itself in
/run/systemd/generator/local-fs.target.wants/ for systemd-fsck-root.service | 
|  | /etc/os-release is expected for the case for booting a full system, and
need not be required for thin container execution. | 
|  |  | 
|  | I'm not sure why this makes a difference... | 
|  | If the password is a device file, we can add Requires/After dependencies
on the device rather than requiring the user to do so. | 
|  |  | 
|  |  | 
|  |  | 
|  | In the parse_env_file_push() and load_env_file_push() functions, there
are two assert() call to check if the key or value parameters are utf8 valid.
If the strings aren't utf8 valid, assert does abort.
These function are used early by systemd to parse some files. For
example '/etc/locale.conf'. In my case this file contained a not utf8
sequence, which is bad, but systemd crashed during the boot, which
is even worse!
The enclosed patch removes the assert and return -EINVAL if the
sequence is invalid. This is possible because the caller of these
function [1] checks the errors.
So the check of an invalid utf8 sequence is still performed, but
systemd doesn't crash anymore and logs the error.
[1] parse_env_file_internal(), invoked by load_env_file() and
parse_env_file() | 
|  |  | 
|  | the API file systems, nothing else | 
|  |  | 
|  | systemd-user-sessions.service
This way at shutdown we can be sure that the sessions go away before the
network. | 
|  | Both in the configuration file format and everywhere else in the code. | 
|  | The session_send_create_reply() function which notifies clients about
session creation is used for both session and user units. Unify the
shared code in a new function session_jobs_reply().
The session_save() will be called unconditionally on sessions since it
does not make sense to only call it if '!session->started', this will
also allow to update the session state as soon as possible. | 
|  | running empty since systemd will get exactly zero notifications about it | 
|  | scopes we don't need to lower the stop timeout anymore | 
|  | This allows us users of the library to keep copies of old leases. This is
used by networkd to know what addresses to drop (if any) when the lease
expires.
In the future this may be used by DNAv4 and sd-dhcp-server. | 
|  | without working cgroup empty notifications there's no need to set the
stop timeout of sessions scopes low | 
|  | In some cases it is interesting to map a PID to two units at the same
time. For example, when a user logs in via a getty, which is reexeced to
/sbin/login that binary will be explicitly referenced as main pid of the
getty service, as well as implicitly referenced as part of the session
scope. | 
|  |  | 
|  | that's requested | 
|  | Simplify the shutdown logic a bit:
- Keep the session FIFO around in the PAM module, even after the session
  shutdown hook has been finished. This allows logind to track precisely
  when the PAM handler goes away.
- In the ReleaseSession() call start a timer, that will stop terminate
  the session when elapsed.
- Never fiddle with the KillMode of scopes to configure whether user
  processes should be killed or not. Instead, simply leave the scope
  units around when we terminate a session whose processes should not be
  killed.
- When killing is enabled, stop the session scope on FIFO EOF or after
  the ReleaseSession() timeout. When killing is disabled, simply tell
  PID 1 to abandon the scope.
Because the scopes stay around and hence all processes are always member
of a scope, the system shutdown logic should be more robust, as the
scopes can be shutdown as part of the usual shutdown logic. | 
|  | reliable cgroup empty notifier
When a process dies that we can associate with a specific unit, start
watching all other processes of that unit, so that we can associate
those processes with the unit too.
Also, for service units start doing this as soon as we get the first
SIGCHLD for either control or main process, so that we can follow the
processes of the service from one to the other, as long as process that
remain are processes of the ones we watched that died and got reassigned
to us as parent.
Similar, for scope units start doing this as soon as the scope
controller abandons the unit, and thus management entirely reverts to
systemd. To abandon a unit introduce a new Abandon() scope unit method
call. |