The current vm detection lacks the distinction between Xen dom0 and Xen domU.
Both, dom0 and domU are running inside the hypervisor.
Therefore systemd-detect-virt and the ConditionVirtualization directive detect
dom0 as a virtual machine.
dom0 is not using virtual devices but is accessing the real hardware.
Therefore dom0 should be considered the virtualisation host and not a virtual
machine.
https://bugs.freedesktop.org/show_bug.cgi?id=77271
(cherry picked from commit 37287585b6)
(cherry picked from commit f22d2ebe68)
Conflicts:
src/shared/virt.c
I am getting
"Error calling EVIOCSKEYCODE (scan code 0xc022d, key code 418): Invalid
argument", the error message does not tell on which specific device the
problem is, add that info.
(cherry picked from commit a52ec8ed88)
(cherry picked from commit 55cf7f15b4)
Conflicts:
src/udev/udev-builtin-keyboard.c
ignore_file currently allows any file ending with '~' while it
seems that the opposite was intended:
a228a22fda
(cherry picked from commit 93f1a06374)
(cherry picked from commit c4a42680d7)
Re-apply the keymaps when "udevadm trigger" is called. Hooking into
"add" only would just remove all keymap content from the udev database
instead of applying the new config.
(cherry picked from commit 49804365ea)
(cherry picked from commit 8d9518eb8f)
This undoes part of commit e6a4a517be.
Instead of removing the error message about non-empty journal bind mount
directories, simply downgrade the message to a warning and proceed.
(cherry picked from commit cdb2b9d05a)
(cherry picked from commit 2b1f027f8e)
Currently if nspawn was called with --link-journal=host or
--link-journal=auto and the right /var/log/journal/machine-id/ exists
then the bind mount the subdirectory into the container might fail due
to the ~/mycontainer/var/log/journal/machine-id/ of the container not
being empty.
There is no reason to check if the container journal subdir is empty
since there will be a bind mount on top of it. The user asked for a bind
mount so give it.
Note: a next call with --link-journal=guest may fail due to the
/var/log/journal/machine-id/ on the host not being empty.
https://bugs.freedesktop.org/show_bug.cgi?id=76193
Reported-by: Tobias Hunger <tobias.hunger@gmail.com>
(cherry picked from commit e6a4a517be)
(cherry picked from commit 8113d58e81)
When you switch-root into a new root that has SELinux policy, you're
supposed to to run selinux_init_load_policy() to set up SELinux and load
policy. Normally this gets handled by selinux_setup().
But if SELinux was already initialized, selinux_setup() skips loading
policy and returns 0. So if you load policy normally, and then you
switch-root to a new root that has new policy, selinux_setup() never
loads the new policy. What gives?
As far as I can tell, this check is an artifact of how selinux_setup()
worked when it was first written (see commit c4dcdb9 / systemd v12):
* when systemd starts, run selinux_setup()
* if selinux_setup() loads policy OK, restart systemd
So the "if policy already loaded, skip load and return 0" check was
there to prevent an infinite re-exec loop.
Modern systemd only calls selinux_setup() on initial load and after
switch-root, and selinux_setup() no longer restarts systemd, so we don't
need that check to guard against the infinite loop anymore.
So: this patch removes the "return 0", thus allowing selinux_setup() to
actually perform SELinux setup after switch-root.
We still want to check to see if SELinux is initialized, because if
selinux_init_load_policy() fails *but* SELinux is initialized that means
we still have (old) policy active. So we don't need to halt if
enforce=1.
(cherry picked from commit 68d3acaccb)
(cherry picked from commit f5ad306cb9)
7-space indentation is just too weird to leave alone.
Make it 8 spaces, as per CODING_STYLE. No other changes.
(cherry picked from commit 4ab72d6fb4)
Conflicts:
src/core/ima-setup.c
[zj: just selinux-setup.c, as needed for futher commits.]
(cherry picked from commit 31b1d7a4f7)
Source code has "files-max" and XML has --max-files.
(cherry picked from commit 332bc31992)
(cherry picked from commit 78db70d9c7)
Conflicts:
man/systemd-readahead-replay.service.xml
src/readahead/readahead.c
THere's no reason why hibernate should be better protected then
suspendor poweroff, so sync the policies.
(cherry picked from commit 301f9684e6)
(cherry picked from commit 219b398853)
safe_close() automatically becomes a NOP when a negative fd is passed,
and returns -1 unconditionally. This makes it easy to write lines like
this:
fd = safe_close(fd);
Which will close an fd if it is open, and reset the fd variable
correctly.
By making use of this new scheme we can drop a > 200 lines of code that
was required to test for non-negative fds or to reset the closed fd
variable afterwards.
(cherry-picked from commit 03e334a1c7)
(cherry picked from commit 4529ad1def)
Conflicts:
src/core/automount.c
src/core/busname.c
src/core/dbus.c
src/core/execute.c
src/core/manager.c
src/core/path.c
src/core/socket.c
src/journal/journalctl.c
src/journal/journald-console.c
src/journal/journald-kmsg.c
src/journal/journald-server.c
src/journal/journald-stream.c
src/libsystemd-dhcp/dhcp-network.c
src/libsystemd-dhcp/sd-dhcp-client.c
src/libsystemd/sd-bus/bus-container.c
src/libsystemd/sd-bus/bus-kernel.c
src/libsystemd/sd-bus/bus-message.c
src/libsystemd/sd-bus/sd-bus.c
src/libsystemd/sd-bus/sd-memfd.c
src/libsystemd/sd-event/sd-event.c
src/libsystemd/sd-resolve/sd-resolve.c
src/libsystemd/sd-rtnl/sd-rtnl.c
src/login/logind-inhibit.c
src/login/logind-session.c
src/login/pam-module.c
src/machine/machinectl.c
src/nspawn/nspawn.c
src/shared/logs-show.c
src/shared/util.c
src/socket-proxy/socket-proxyd.c
src/udev/net/link-config.c
Running systemctl enable/disable/set-default/... with the --root
option under strace reveals that it accessed various files and
directories in the main fs, and not underneath the specified root.
This can lead to correct results only when the layout and
configuration in the container are identical, which often is not the
case. Fix this by adding the specified root to all file access
operations.
This patch does not handle some corner cases: symlinks which point
outside of the specified root might be interpreted differently than
they would be by the kernel if the specified root was the real root.
But systemctl does not create such symlinks by itself, and I think
this is enough of a corner case not to be worth the additional
complexity of reimplementing link chasing in systemd.
Also, simplify the code in a few places and remove an hypothetical
memory leak on error.
(cherry picked from commit 12ed81d9c8)
Conflicts:
TODO
(cherry picked from commit fd516dfa06)
Conflicts:
src/shared/install.c
The conf_files_list family accepts an alternate root path to prefix all
directories in the list but path_strv_canonicalize_uniq doesn't use it.
This results in the suspicious behavior of resolving directory symlinks
based on the contents of / instead of the alternate root.
This adds a prefix argument to path_strv_canonicalize which will now
prepend the prefix, if given, to every path in the list. To avoid
answering what a relative path means when called with a root prefix
path_strv_canonicalize is now path_strv_canonicalize_absolute and only
considers absolute paths. Fortunately all users of already call
path_strv_canonicalize with a list of absolute paths.
(cherry picked from commit 112cfb1814)
After 1ea972174b err is no longer
set unless we hit a special case. Initialize it to 0 and remove
a check that will never fail.
(cherry picked from commit bf9bead187)
Conflicts:
src/udev/udevd.c
(cherry picked from commit 6c160b0f7a)
Most likely the facility needed is actual connectivity, rather than whether or not the
network managment daemon is running.
We also need to explicitly pull in the network-online.target, as it is not active by
default.
This means {systemd-networkd,NetworkManager}-wait-online.service, can be enabled by default
as part of network-online.target, and only delay boot when some service actively pulls it in.
See: <https://bugzilla.gnome.org/show_bug.cgi?id=728965>
Cc: Pavel Šimerda <psimerda@redhat.com>
Cc: Michal Sekletar <msekleta@redhat.com>
(cherry picked from commit 0404c609f3)
(cherry picked from commit 81d4159e6e)
When we have job installed and added to run queue for service which is
still in dead state and systemd initiates reload then after reload we
never add deserialized job to the run queue again. This is caused by
check in service_coldplug() where we check if deserialized state is
something else than dead state, which is not the case thus we never call
service_set_state() and finally unit_notify() where we would have added
job to the run queue.
Thanks to Michal Sekletar <msekleta@redhat.com> for the original patch.
(cherry picked from commit 20a83d7bf4)
Conflicts:
src/core/job.c
(cherry picked from commit 39cdf9313c)
Conflicts:
src/core/job.c
This includes the fixup in ae6feb2a01.
Under some conditions, in udev_rules_apply_to_event the fact that
result is 1024 bytes, creates problems if the output of the running
command/app is bigger then 1024 bytes.
(cherry picked from commit 209b031e4f)
(cherry picked from commit aa8c95a158)
The command line key-size is in bits but the libcryptsetup API expects bytes.
Note that the modulo 8 check is in the original cryptsetup binary as well, so
it's no new limitation.
(v2: changed the point at which the /= 8 is performed, rebased, removed tabs)
(cherry picked from commit 6131a78b4d)
Conflicts:
src/cryptsetup/cryptsetup.c
(cherry picked from commit 19ef179118)