Commit graph

1,613 commits

Author SHA1 Message Date
Martin Pitt
8c0ffebeea Downgrade kbd dependency to Recommends unconditionally
Commit ab743db0 made the dependency weak for %{with upstream} builds
only, because upstream 3327a411be3e ("vconsole-setup: handle gracefully
if setfont/loadkeys are not available") landed after v260 was released.
Rawhide now has v261.2, so the condition is always true here.

The hard requirement came from 01e2d8a9 (2020, rhbz#1408878), which
"upgraded" the Recommends originally added in 4ebba8aa. Now that
systemd-vconsole-setup logs a notice and skips keymap and font setup
when the binaries are absent, kbd is only needed to actually apply a
non-default console keymap or font.

This again lets minimal images that disable weak dependencies leave out
kbd together with the libxkbcommon, xkeyboard-config, and libxml2 chain
it pulls in: about 9 MB uncompressed. That particularly affects initrds,
which are unpacked into RAM.
2026-07-29 19:27:35 +02:00
Zbigniew Jędrzejewski-Szmek
94948d9db3 Version 261.2
- a bugfix release with correctness and security-relevant fixes too.
  276 patches, so too much to describe here.
2026-07-25 10:49:20 -06:00
Zbigniew Jędrzejewski-Szmek
6282eacf43 Expect report-standalone to be built also for commit builds
[skip changelog]
2026-07-22 12:51:57 +02:00
Zbigniew Jędrzejewski-Szmek
f4e7691d3b Make .conf files non-%doc, install one more license file
Since 99-hardening.conf is supposed to be symlinked as configuration,
it cannot be marked with %doc. Also add one more license file listed
in the License line, and clean things up a bit while at it.

[skip changelog]
2026-07-17 12:15:19 +02:00
Zbigniew Jędrzejewski-Szmek
ec1593fa55 Drop 20-yama-ptrace.conf
20-yama-ptrace.conf has the same (non-comment) content as
/usr/lib/sysctl.d/10-default-yama-scope.conf provided by
elfutils-default-yama-scope. We can drop our file.
And the new 99-kernel-hardening.conf provides a suitable replacement.
2026-07-17 11:39:26 +02:00
Zbigniew Jędrzejewski-Szmek
e48f1014bd Adjust 99-kernel-hardening.conf
Adjust the wording for brevity and fix some typos.

[skip changelog]
2026-07-17 11:38:49 +02:00
Christopher Klooz
eaee67a709 add 99-kernel-hardening.conf 2026-07-17 09:25:44 +00:00
Fedora Release Engineering
4fbce183ce Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild 2026-07-17 07:19:12 +00:00
Stewart Smith
cca95abc46 Add sbin_compat bcond to rely on filesystem file triggers for sbin symlinks
Instead of shipping /usr/sbin symlinks directly in the RPM, rely on
filesystem(unmerged-sbin-symlinks) file triggers to create them at
install time. This avoids file conflicts when the package (built on an
unmerged system) is installed into a merged-sbin buildroot, eliminating
the bootstrap ordering problem with the bin/sbin merge.

On unmerged systems, the filesystem file trigger creates the symlinks
when files are installed to /usr/bin. On merged systems, /usr/sbin is
already a symlink to bin so no action is needed.

The bcond defaults to enabled. Use --without sbin_compat to revert to
the old behavior of shipping sbin symlinks in the package.
2026-07-14 10:45:17 -07:00
Zbigniew Jędrzejewski-Szmek
57cbcf979c Also enable report-standalone for OBS builds
OBS uses version strings like "261.999+587+g900ce6f36".

[skip changelog]
2026-07-07 18:36:12 +02:00
Zbigniew Jędrzejewski-Szmek
d69c17b165 Enable report-standalone for upstream builds
(The definition of the conditional needed to be moved below
Version to work.)

[skip changelog]
2026-07-07 13:49:37 +02:00
Zbigniew Jędrzejewski-Szmek
45c16dd369 Use uniform format for %rhel conditionals
They were supposed to apply on old rhel only, but applied
on Fedora too by mistake.

Also restore the old dracut workaround. It *is* a few years
old at this point, but it's not certain that the dracut patch
has been propagated everywhere so it's safe to keep it.

[skip changelog]
2026-07-07 12:17:50 +02:00
Zbigniew Jędrzejewski-Szmek
034fa693f2 Print the build status also in %build
%prep is not executed in no-prep builds which we use with
mkosi.

[skip changelog]
2026-07-07 09:13:58 +02:00
Zbigniew Jędrzejewski-Szmek
3cc7e03365 Restore definitions of helper macros
Fixes 2d6fd95c70.

[skip changelog]
2026-07-07 09:04:19 +02:00
Zbigniew Jędrzejewski-Szmek
2382c910b7 Disable the standalone report yet again
It should be disabled until the changes are merged upstream.

Also fix and adjust the conditions for package-note use.

[skip changelog]
2026-07-07 00:45:42 +02:00
Zbigniew Jędrzejewski-Szmek
2d6fd95c70 Restore explicit requires for Centos Stream 9 and 10
It seems that CI VMs don't boot without this.

[skip changelog]
2026-07-06 22:11:19 +02:00
Frantisek Sumsal
521ab0fb09 test: skip the integration test suite on Fedora ELN (for now)
The test suite currently fails there during setup, because ELN ships
with a reduced package set and it's missing several tools that mkosi
expects to be available:

Updating and loading repositories:
Repositories loaded.
Failed to resolve the transaction:
No match for argument: apk
No match for argument: apt
No match for argument: apt-utils
No match for argument: archlinux-keyring
No match for argument: coccinelle
No match for argument: gh
No match for argument: gh
No match for argument: lcov
No match for argument: musl-clang
No match for argument: musl-gcc
No match for argument: musl-libc
No match for argument: pacman
No match for argument: python3-mypy
No match for argument: qemu-system-aarch64-core
No match for argument: qemu-system-ppc-core
No match for argument: qemu-system-s390x-core
No match for argument: ruff
No match for argument: sbsigntools
No match for argument: zypper
You can try to add to command line:
  --skip-unavailable to skip unavailable packages

Switching the tools tree to Rawhide doesn't help either, as that breaks
other things:

Updating and loading repositories:
 fedora                                 100% |  69.2 MiB/s |  20.9 MiB |  00m00s
>>> Downloading successful, but checksum doesn't match. Calculated: ...
cannot open file: (95) - Operation not supported [/var/cache/libdnf5/fedora-306b6523e9c8dc02/repodata/fc1f05fc361729498fd568dec450c1e27598bd38e3179f9b80ae01fbc8a0b74d-primary.xml.zck]

We can revisit this later if running the test suite on ELN is desirable.

The "skip" on ELN is slightly unconventional, as using "enabled: false"
here causes Packit to error.

[skip changelog]
2026-07-06 17:26:40 +00:00
Frantisek Sumsal
453447b79b rpminspect: ignore test-coredump-stacktrace in annocheck
As this test is intentionally compiled with a minimal set of hardcoded
options, so it always generates a predictable stack trace.

[skip changelog]
2026-07-06 17:26:40 +00:00
Frantisek Sumsal
9d4edaa576 test: work around a kernel bug in virtio/vsock
There's a virtio/vsock bug in kernel 7.1-rc where a patch for a
potential overflow inadvertently shrunk the receive buffer's effective
size below what was configured, which eventually causes the vsock
connection to get reset with ENOBUFS, that kills the journal forwarding
over vsock:

read(7, ..., 16392): No buffer space available
Entry too big, skipped
read(8, ..., 16392): No buffer space available
Entry too big, skipped
read(12, ..., 16392): No buffer space available
Entry too big, skipped
Finishing after writing 6685 entries

This then affects other systemd components that try to write to the now
broken journal, causing them to fail as well.

Let's just bump the default vsock buffer size to work around this until
the kernel fix lands.

Pending fix: https://lore.kernel.org/netdev/20260518090656.134588-3-sgarzare@redhat.com/

[skip changelog]
2026-07-06 17:26:40 +00:00
Frantisek Sumsal
c53b2fb307 test: cap the number of parallel tests
Cap the number of parallel tests to 4 to not overwhelm beefier hosts.

I tried this with 8 jobs, but it often caused annoying timeouts in
nspawn-based tests; maybe this could be investigated and potentially
addressed in the future.

[skip changelog]
2026-07-06 17:26:40 +00:00
Yaakov Selkowitz
9bd26bb71f Fix ntpvendor for ELN
This has to match a registered vendor, and ELN is one case where the OS and
vendor name are different.

https://github.com/fedora-eln/eln/issues/567
2026-07-06 17:24:52 +00:00
Zbigniew Jędrzejewski-Szmek
de7b685908 Disable reqs for dlopen'ed libraries on CentOS
Unfortunately package-notes >= 0.18 are not available on CentoOS
Stream 9 and 10 right now. We actually want >= 0.20 for the best
expreience. Disable the requirement for now, to allow CI builds to
happen. This will need to be resolved before the builds are used for
real.

[skip changelog]
2026-07-06 12:26:31 +02:00
Zbigniew Jędrzejewski-Szmek
4830641844 Move portabled to systemd-container subpackage
Previously, the idea was that portabled is in -udev because it can be
used to implement generic services, incl. basic system functionality.
But it seems that nobody is doing that… People who _are_ packing
portables, are using them more like containers, i.e. to deliver
external payloads. So let's move it to the -container subpackage to
shrink -udev which is installed almost everywhere.

Also, fix bogus comment and fix typo, effectively moving updatectl to
-udev.
2026-07-03 17:04:38 +02:00
Zbigniew Jędrzejewski-Szmek
893fcd9978 Add missing conditionalization and more debugging
[skip changelog]
2026-07-03 17:04:38 +02:00
Zbigniew Jędrzejewski-Szmek
c783e74791 split-files: improve error message
[skip changelog]
2026-07-03 15:51:45 +02:00
Zbigniew Jędrzejewski-Szmek
ee2dff42d6 Add systemd-report-standalone
This adds the packaging required for
https://github.com/systemd/systemd/pull/42874. The build will work
with the changes here even before that the upstream changes are
merged and is in fact required for upstream CI to pass, so the plan
is to merge it early.

[skip changelog]
2026-07-03 15:00:53 +02:00
Zbigniew Jędrzejewski-Szmek
9c87a3f8ad Load libssl.so.4 rather than libssl.so.3 2026-06-27 22:10:56 +02:00
Zbigniew Jędrzejewski-Szmek
714b0799d2 Version 261.1
- The first batch of fixes post-release
2026-06-26 16:43:23 +02:00
Zbigniew Jędrzejewski-Szmek
054158500a Update to load openssl-4 rather than openssl-3
The autogenerated dependency (Requires:libcrypto.so.3()(64bit) in
systemd-udev.rpm) is causing a failure in coreos.cosa.build-and-test.
2026-06-19 21:44:06 +02:00
Zbigniew Jędrzejewski-Szmek
5a3e750ef8 Version 261
- Still some fixes after -rc4, incl. a change to how
  openssl/libcrypto is loaded and to imds service ordering
  at startup
2026-06-19 20:17:09 +02:00
Zbigniew Jędrzejewski-Szmek
4faee7ab7d Version 261~rc4
- New translations and various other fixes
2026-06-17 00:31:27 +02:00
Yaakov Selkowitz
8ff635a921 Rebuilt for openssl 4.0 2026-06-12 19:52:53 -04:00
Yaakov Selkowitz
0064f73d97 Rebuilt for openssl 4.0 2026-06-12 12:23:09 -04:00
Zbigniew Jędrzejewski-Szmek
14a9aac87e Use dlopen notes again
This requires updated dlopen-notes. A version dependency is introduced.

The levels of various dendencies were adjusted, see comments.

The motivation for this change is to make management of the dependencies
(Requires, Recommends, Suggests). Previously, we had to adjust the
depencencies whenever things were converted to dlopen, or the list
of libraries used was changed. This was tedious and hard to get right.
Now we have good metadata provided by upstream, so we mostly rely on
that only only do some overrides downstream.
2026-06-10 17:04:05 +02:00
Zbigniew Jędrzejewski-Szmek
720fa8259a Do not check ownership of /var/lib/systemd/timesync/ in rpm -V
rpm -V systemd-udev would report that /var/lib/systemd/timesync/ has
wrong ownership. This happens because create the directory via %ghost
and it ends up with the default root:root ownership in the rpm %files
list. We _could_ fix the owernship in the listing, but it's actually OK
if the directory is owned by root or even some other account, as long as
the service is not running. Systemd will change owernship to the
systemd-timesync user:group when starting the service. Disabling of the
ownership verification makes it easier to precreate the timestamp (c.f.
https://src.fedoraproject.org/rpms/systemd/pull-request/238). So let's
just disable the owernship check.
2026-06-10 15:07:53 +02:00
Zbigniew Jędrzejewski-Szmek
06bd9926f2 Version 261~rc3
- Various smaller and larger fixes
- A hint is emitted if init is called with the legacy
  telinit args (rhbz#2479961)
- Various messages for missing dlopened libraries have been
  downgraded (rhbz#2463540)
2026-06-04 18:28:12 +02:00
Zbigniew Jędrzejewski-Szmek
6ddbd499e8 Drop unused tree build dependency
Reported by Marián Konček.

[skip changelog]
2026-06-02 19:13:07 +02:00
Zbigniew Jędrzejewski-Szmek
bd81a14bfc Version 261~rc2
- A few fixes for this and that incl. rhbz#2481304, rhbz#2481466
2026-05-26 23:11:46 +02:00
Zbigniew Jędrzejewski-Szmek
9cb09470c9 Version 261~rc1
- explicit dependencies are added for various libraries loaded
  using dlopen()
2026-05-22 19:46:16 +02:00
Zbigniew Jędrzejewski-Szmek
7d16ad00bd Fix compilation with openssl 4.0 2026-05-22 18:18:43 +02:00
Zbigniew Jędrzejewski-Szmek
3770fa7c92 Revert "Use dlopen-notes to automatically generate library Recommends/Requires/Suggests"
This reverts commit ee6d0b9d27.
The approach with dlopen-notes is not fully cooked yet. In particular,
the case where the note is present in a shared library, but we'd like to
declare the dependency for a binary which is a different package, is
not supported by rpm. Let's revert for now and come back to this later.
2026-05-22 18:12:42 +02:00
Zbigniew Jędrzejewski-Szmek
8b3d1726f5 Add back various explit Requires
The idn feature is in libsystemd-shared, and systemd-resolved doesn't
contain any files that'd tie it to that shared library, so the
genarator doesn't generate this dependency. This is a fundamental
limitation of the rpm interface. Let's add a manual listing for now.

Similarly, systemd-udev would miss many relevant Requires.
2026-05-19 11:56:20 +02:00
d8abb91805 Drop scriptlet workarounds for upgrades from versions < 247
247 was in 2020, so this should be OK.
2026-05-19 11:15:03 +02:00
ee6d0b9d27 Use dlopen-notes to automatically generate library Recommends/Requires/Suggests 2026-05-19 11:14:25 +02:00
32a2038627 spec: drop duplicated line
[skip changelog]
2026-05-19 11:14:19 +02:00
Zbigniew Jędrzejewski-Szmek
ab743db0fe Downgrade kbd dependency to Recommends
Since upstream commit 3327a411be3ef4a203d23ae86e6c50b30d929d50, we
can downgrade the dep.
2026-05-12 12:32:45 +02:00
Yaakov Selkowitz
400494ada4 Update conditionals for RHEL 11
ELN (the future RHEL 11) tracks rawhide and therefore also has the latest
setup and sysusers changes.
2026-04-14 22:10:09 +00:00
Zbigniew Jędrzejewski-Szmek
207e2d0044 Stop building support for openssl engines
It seems that the headers are gone on openssl-4.0.0~beta1. But already
we're seeing build failurs on i686 because openssl-devel-engine is not
available. Most likely multilib setup was borked. So let's drop this
now and hope that the providers in f45 will be good enough.
2026-04-14 16:20:57 +02:00
Zbigniew Jędrzejewski-Szmek
36a234147f Upload sources
[skip changelog]
2026-03-23 21:08:43 +01:00
Zbigniew Jędrzejewski-Szmek
3681163f81 Version 260.1
- Fixes for crashes and misbehaviours in PID1 and other components
2026-03-23 21:06:28 +01:00