Compare commits
9 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0fb3c977c5 | ||
|
|
845cc59e1d | ||
|
|
652365b911 | ||
|
|
521674aa1a | ||
|
|
56c68aab53 | ||
|
|
ff357ca778 | ||
|
|
2a37c31478 | ||
|
|
462b3a073e | ||
|
|
eab1f7edad |
12 changed files with 327 additions and 339 deletions
88
0001-Revert-units-drop-runlevel-0-6-.target.patch
Normal file
88
0001-Revert-units-drop-runlevel-0-6-.target.patch
Normal file
|
|
@ -0,0 +1,88 @@
|
||||||
|
From 61750e265ce3f7783a8dba831e91140f84ad89f2 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= <zbyszek@in.waw.pl>
|
||||||
|
Date: Wed, 5 Nov 2025 17:52:16 +0100
|
||||||
|
Subject: [PATCH 1/3] Revert "units: drop runlevel[0-6].target"
|
||||||
|
|
||||||
|
This partially reverts commit e58ba80a40fb6e96543d56774a5bc5aa9cdadbf3.
|
||||||
|
The unit are still needed for compat.
|
||||||
|
---
|
||||||
|
units/meson.build | 27 ++++++++++++++++++++++-----
|
||||||
|
1 file changed, 22 insertions(+), 5 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/units/meson.build b/units/meson.build
|
||||||
|
index 2e04c4aa2b..46eaac4073 100644
|
||||||
|
--- a/units/meson.build
|
||||||
|
+++ b/units/meson.build
|
||||||
|
@@ -1,5 +1,7 @@
|
||||||
|
# SPDX-License-Identifier: LGPL-2.1-or-later
|
||||||
|
|
||||||
|
+with_runlevels = conf.get('HAVE_SYSV_COMPAT') == 1
|
||||||
|
+
|
||||||
|
units = [
|
||||||
|
{ 'file' : 'basic.target' },
|
||||||
|
{ 'file' : 'blockdev@.target' },
|
||||||
|
@@ -49,7 +51,7 @@ units = [
|
||||||
|
},
|
||||||
|
{
|
||||||
|
'file' : 'graphical.target',
|
||||||
|
- 'symlinks' : ['default.target'],
|
||||||
|
+ 'symlinks' : ['default.target'] + (with_runlevels ? ['runlevel5.target'] : []),
|
||||||
|
},
|
||||||
|
{ 'file' : 'halt.target' },
|
||||||
|
{
|
||||||
|
@@ -142,7 +144,10 @@ units = [
|
||||||
|
'conditions' : ['ENABLE_MACHINED'],
|
||||||
|
},
|
||||||
|
{ 'file' : 'modprobe@.service' },
|
||||||
|
- { 'file' : 'multi-user.target' },
|
||||||
|
+ {
|
||||||
|
+ 'file' : 'multi-user.target',
|
||||||
|
+ 'symlinks' : with_runlevels ? ['runlevel2.target', 'runlevel3.target', 'runlevel4.target'] : [],
|
||||||
|
+ },
|
||||||
|
{
|
||||||
|
'file' : 'systemd-mute-console.socket',
|
||||||
|
'symlinks' : ['sockets.target.wants/']
|
||||||
|
@@ -155,7 +160,10 @@ units = [
|
||||||
|
{ 'file' : 'nss-lookup.target' },
|
||||||
|
{ 'file' : 'nss-user-lookup.target' },
|
||||||
|
{ 'file' : 'paths.target' },
|
||||||
|
- { 'file' : 'poweroff.target' },
|
||||||
|
+ {
|
||||||
|
+ 'file' : 'poweroff.target',
|
||||||
|
+ 'symlinks' : with_runlevels ? ['runlevel0.target'] : [],
|
||||||
|
+ },
|
||||||
|
{ 'file' : 'printer.target' },
|
||||||
|
{
|
||||||
|
'file' : 'proc-sys-fs-binfmt_misc.automount',
|
||||||
|
@@ -180,7 +188,7 @@ units = [
|
||||||
|
},
|
||||||
|
{
|
||||||
|
'file' : 'reboot.target',
|
||||||
|
- 'symlinks' : ['ctrl-alt-del.target'],
|
||||||
|
+ 'symlinks' : ['ctrl-alt-del.target'] + (with_runlevels ? ['runlevel6.target'] : []),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
'file' : 'remote-cryptsetup.target',
|
||||||
|
@@ -200,7 +208,10 @@ units = [
|
||||||
|
'symlinks' : ['initrd-root-device.target.wants/'],
|
||||||
|
},
|
||||||
|
{ 'file' : 'rescue.service.in' },
|
||||||
|
- { 'file' : 'rescue.target' },
|
||||||
|
+ {
|
||||||
|
+ 'file' : 'rescue.target',
|
||||||
|
+ 'symlinks' : with_runlevels ? ['runlevel1.target'] : [],
|
||||||
|
+ },
|
||||||
|
{ 'file' : 'rpcbind.target' },
|
||||||
|
{ 'file' : 'serial-getty@.service.in' },
|
||||||
|
{ 'file' : 'shutdown.target' },
|
||||||
|
@@ -1001,4 +1012,10 @@ else
|
||||||
|
dbussessionservicedir / 'org.freedesktop.systemd1.service'))
|
||||||
|
endif
|
||||||
|
|
||||||
|
+if conf.get('HAVE_SYSV_COMPAT') == 1
|
||||||
|
+ foreach i : [1, 2, 3, 4, 5]
|
||||||
|
+ install_emptydir(systemunitdir / 'runlevel@0@.target.wants'.format(i))
|
||||||
|
+ endforeach
|
||||||
|
+endif
|
||||||
|
+
|
||||||
|
subdir('user')
|
||||||
|
|
@ -1,42 +0,0 @@
|
||||||
From 7d7965620490b28ccfb9cf45a91b8596be811c90 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgzones@googlemail.com>
|
|
||||||
Date: Sat, 30 Aug 2025 13:55:56 +0200
|
|
||||||
Subject: [PATCH 1/2] core: create userdb root directory with correct label
|
|
||||||
|
|
||||||
Set up the /run/systemd/userdb directory with the default SELinux context
|
|
||||||
on creation.
|
|
||||||
|
|
||||||
With version 257.7-1 on Debian the directory was automatically created with the
|
|
||||||
correct label. Starting with version 258 (only tested with 258~rc3-1) it no
|
|
||||||
longer is. Regression introduced in 736349958efe34089131ca88950e2e5bb391d36a.
|
|
||||||
|
|
||||||
[zjs: edited the patch to apply comments from review and update the description.]
|
|
||||||
---
|
|
||||||
src/core/varlink.c | 7 ++++++-
|
|
||||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/core/varlink.c b/src/core/varlink.c
|
|
||||||
index 79a198f14d..f32071a161 100644
|
|
||||||
--- a/src/core/varlink.c
|
|
||||||
+++ b/src/core/varlink.c
|
|
||||||
@@ -9,6 +9,7 @@
|
|
||||||
#include "json-util.h"
|
|
||||||
#include "manager.h"
|
|
||||||
#include "metrics.h"
|
|
||||||
+#include "mkdir.h"
|
|
||||||
#include "path-util.h"
|
|
||||||
#include "pidref.h"
|
|
||||||
#include "stdio-util.h"
|
|
||||||
@@ -523,7 +524,11 @@ static int varlink_server_listen_many_idempotent_sentinel(
|
|
||||||
if (!known_fresh && varlink_server_contains_socket(s, address))
|
|
||||||
continue;
|
|
||||||
|
|
||||||
- r = sd_varlink_server_listen_address(s, address, 0666 | SD_VARLINK_SERVER_MODE_MKDIR_0755);
|
|
||||||
+ r = mkdir_parents_label(address, 0755);
|
|
||||||
+ if (r < 0)
|
|
||||||
+ log_warning_errno(r, "Failed to create parent directory of '%s', ignoring: %m", address);
|
|
||||||
+
|
|
||||||
+ r = sd_varlink_server_listen_address(s, address, 0666);
|
|
||||||
if (r < 0) {
|
|
||||||
log_error_errno(r, "Failed to bind to varlink socket '%s': %m", address);
|
|
||||||
break;
|
|
||||||
|
|
@ -1,17 +1,17 @@
|
||||||
From fb62136683406e18f58517ec13c9b18bc2c9cf9a Mon Sep 17 00:00:00 2001
|
From 8d6d86d1d7e45eeae921e88adde55d6524027c96 Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= <zbyszek@in.waw.pl>
|
From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= <zbyszek@in.waw.pl>
|
||||||
Date: Wed, 26 Nov 2025 22:29:53 +0100
|
Date: Wed, 26 Nov 2025 22:29:53 +0100
|
||||||
Subject: [PATCH 2/2] machined: continue without resolve.hook socket
|
Subject: [PATCH 3/3] machined: continue without resolve.hook socket
|
||||||
|
|
||||||
---
|
---
|
||||||
src/machine/machined-varlink.c | 12 +++++++++---
|
src/machine/machined-varlink.c | 12 +++++++++---
|
||||||
1 file changed, 9 insertions(+), 3 deletions(-)
|
1 file changed, 9 insertions(+), 3 deletions(-)
|
||||||
|
|
||||||
diff --git a/src/machine/machined-varlink.c b/src/machine/machined-varlink.c
|
diff --git a/src/machine/machined-varlink.c b/src/machine/machined-varlink.c
|
||||||
index ae121395c0..29c75cc076 100644
|
index f83cbb8562..0b30cd0531 100644
|
||||||
--- a/src/machine/machined-varlink.c
|
--- a/src/machine/machined-varlink.c
|
||||||
+++ b/src/machine/machined-varlink.c
|
+++ b/src/machine/machined-varlink.c
|
||||||
@@ -914,9 +914,15 @@ static int manager_varlink_init_resolve_hook(Manager *m) {
|
@@ -894,9 +894,15 @@ static int manager_varlink_init_resolve_hook(Manager *m) {
|
||||||
|
|
||||||
r = sd_varlink_server_listen_address(s, VARLINK_PATH_MACHINED_RESOLVE_HOOK,
|
r = sd_varlink_server_listen_address(s, VARLINK_PATH_MACHINED_RESOLVE_HOOK,
|
||||||
0666 | SD_VARLINK_SERVER_MODE_MKDIR_0755);
|
0666 | SD_VARLINK_SERVER_MODE_MKDIR_0755);
|
||||||
|
|
|
||||||
42
20-yama-ptrace.conf
Normal file
42
20-yama-ptrace.conf
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
# The ptrace system call is used for interprocess services,
|
||||||
|
# communication and introspection (like synchronisation, signaling,
|
||||||
|
# debugging, tracing and profiling) of processes.
|
||||||
|
#
|
||||||
|
# Usage of ptrace is restricted by normal user permissions. Normal
|
||||||
|
# unprivileged processes cannot use ptrace on processes that they
|
||||||
|
# cannot send signals to or processes that are running set-uid or
|
||||||
|
# set-gid. Nevertheless, processes running under the same uid will
|
||||||
|
# usually be able to ptrace one another.
|
||||||
|
#
|
||||||
|
# Fedora enables the Yama security mechanism which restricts ptrace
|
||||||
|
# even further. Sysctl setting kernel.yama.ptrace_scope can have one
|
||||||
|
# of the following values:
|
||||||
|
#
|
||||||
|
# 0 - Normal ptrace security permissions.
|
||||||
|
# 1 - Restricted ptrace. Only child processes plus normal permissions.
|
||||||
|
# 2 - Admin-only attach. Only executables with CAP_SYS_PTRACE.
|
||||||
|
# 3 - No attach. No process may call ptrace at all. Irrevocable.
|
||||||
|
#
|
||||||
|
# For more information see Documentation/security/Yama.txt in the
|
||||||
|
# kernel sources.
|
||||||
|
#
|
||||||
|
# The default is 1., which allows tracing of child processes, but
|
||||||
|
# forbids tracing of arbitrary processes. This allows programs like
|
||||||
|
# gdb or strace to work when the most common way of having the
|
||||||
|
# debugger start the debuggee is used:
|
||||||
|
# gdb /path/to/program ...
|
||||||
|
# Attaching to already running programs is NOT allowed:
|
||||||
|
# gdb -p ...
|
||||||
|
# This default setting is suitable for the common case, because it
|
||||||
|
# reduces the risk that one hacked process can be used to attack other
|
||||||
|
# processes. (For example, a hacked firefox process in a user session
|
||||||
|
# will not be able to ptrace the keyring process and extract passwords
|
||||||
|
# stored only in memory.)
|
||||||
|
#
|
||||||
|
# Developers and administrators might want to disable those protections
|
||||||
|
# to be able to attach debuggers to existing processes. Use
|
||||||
|
# sysctl kernel.yama.ptrace_scope=0
|
||||||
|
# for change the setting temporarily, or copy this file to
|
||||||
|
# /etc/sysctl.d/20-yama-ptrace.conf to set it for future boots.
|
||||||
|
|
||||||
|
kernel.yama.ptrace_scope = 0
|
||||||
42
38769.patch
Normal file
42
38769.patch
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
From 00d70f36a0866660693347009446b7f872a05bf4 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgzones@googlemail.com>
|
||||||
|
Date: Sat, 30 Aug 2025 13:55:56 +0200
|
||||||
|
Subject: [PATCH] core: create userdb root directory with correct label
|
||||||
|
|
||||||
|
Set up the /run/systemd/userdb directory with the default SELinux context
|
||||||
|
on creation.
|
||||||
|
|
||||||
|
With version 257.7-1 on Debian the directory was automatically created with the
|
||||||
|
correct label. Starting with version 258 (only tested with 258~rc3-1) it no
|
||||||
|
longer is. Regression introduced in 736349958efe34089131ca88950e2e5bb391d36a.
|
||||||
|
|
||||||
|
[zjs: edited the patch to apply comments from review and update the description.]
|
||||||
|
---
|
||||||
|
src/core/varlink.c | 7 ++++++-
|
||||||
|
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/src/core/varlink.c b/src/core/varlink.c
|
||||||
|
index 99f12c59e5..71a8ffd0e5 100644
|
||||||
|
--- a/src/core/varlink.c
|
||||||
|
+++ b/src/core/varlink.c
|
||||||
|
@@ -5,6 +5,7 @@
|
||||||
|
#include "constants.h"
|
||||||
|
#include "errno-util.h"
|
||||||
|
#include "manager.h"
|
||||||
|
+#include "mkdir-label.h"
|
||||||
|
#include "path-util.h"
|
||||||
|
#include "pidref.h"
|
||||||
|
#include "string-util.h"
|
||||||
|
@@ -441,7 +442,11 @@ static int manager_varlink_init_system(Manager *m) {
|
||||||
|
if (!fresh && varlink_server_contains_socket(m->varlink_server, address))
|
||||||
|
continue;
|
||||||
|
|
||||||
|
- r = sd_varlink_server_listen_address(m->varlink_server, address, 0666 | SD_VARLINK_SERVER_MODE_MKDIR_0755);
|
||||||
|
+ r = mkdir_parents_label(address, 0755);
|
||||||
|
+ if (r < 0)
|
||||||
|
+ log_warning_errno(r, "Failed to create parent directory of '%s', ignoring: %m", address);
|
||||||
|
+
|
||||||
|
+ r = sd_varlink_server_listen_address(m->varlink_server, address, 0666);
|
||||||
|
if (r < 0)
|
||||||
|
return log_error_errno(r, "Failed to bind to varlink socket '%s': %m", address);
|
||||||
|
}
|
||||||
|
|
@ -1,66 +0,0 @@
|
||||||
# This file is disabled by default. It provides a few kernel
|
|
||||||
# hardening settings. This file is automatically updated.
|
|
||||||
#
|
|
||||||
# Please read the Fedora hardening page for further information
|
|
||||||
# about this file (section 'Fedora-maintained (self-updating)
|
|
||||||
# hardening for general and average use cases' and
|
|
||||||
# section 'Fedora-maintained self-updating kernel hardening'):
|
|
||||||
# https://docs.fedoraproject.org/en-US/security/topics/hardening
|
|
||||||
#
|
|
||||||
# If you want to enable the hardening, create a symlink:
|
|
||||||
# sudo ln -s /usr/share/doc/systemd/99-kernel-hardening.conf /etc/sysctl.d/
|
|
||||||
# -> do NOT copy or move or hardlink this file because
|
|
||||||
# this would break the automatic updates!
|
|
||||||
#
|
|
||||||
#
|
|
||||||
# Enabling this ptrace restriction can cause issues to some software
|
|
||||||
# developers: the need to use ptrace is restricted in the hardening
|
|
||||||
# because of the security issues it may cause in some
|
|
||||||
# circumstances: to use applications like gdb or strace when the
|
|
||||||
# hardening is enabled, users need to temporarily enable ptrace
|
|
||||||
# during the runtime of their ptrace-dependent application.
|
|
||||||
# Enabling ptrace implies disabling yama.ptrace_scope (which is
|
|
||||||
# the security measure enabled below).
|
|
||||||
# You can enable temporarily ptrace with:
|
|
||||||
# sysctl kernel.yama.ptrace_scope=0
|
|
||||||
# You can subsequently disable it again with:
|
|
||||||
# sysctl kernel.yama.ptrace_scope=2
|
|
||||||
# -> it will be reset automatically after reboot.
|
|
||||||
# For more information, read the Fedora hardening page
|
|
||||||
# mentioned above.
|
|
||||||
#
|
|
||||||
# Details: https://docs.kernel.org/admin-guide/sysctl/net.html
|
|
||||||
# Details: https://wiki.archlinux.org/title/Security#BPF_hardening
|
|
||||||
# Minor / partially-related side note: Fedora's kernel is compiled
|
|
||||||
# with CONFIG_BPF_JIT_ALWAYS_ON=True
|
|
||||||
net.core.bpf_jit_harden = 2
|
|
||||||
|
|
||||||
# Details: https://docs.kernel.org/admin-guide/LSM/Yama.html
|
|
||||||
# Details: https://wiki.archlinux.org/title/Security#ptrace_scope
|
|
||||||
# Side note: 'setsebool -P deny_ptrace on' can add a
|
|
||||||
# largely-overlapping security layer to achieve redundancy in
|
|
||||||
# restricting ptrace: it is suggested to read the Fedora hardening
|
|
||||||
# page (link above) section 'Fedora-maintained (self-updating)
|
|
||||||
# hardening for general and average use cases' and section
|
|
||||||
# 'Fedora-maintained 'enable & forget' SELinux & firewalld hardening'
|
|
||||||
# for further information about this.
|
|
||||||
kernel.yama.ptrace_scope = 2
|
|
||||||
|
|
||||||
# Details: https://docs.kernel.org/admin-guide/sysctl/kernel.html#kptr-restrict
|
|
||||||
# Details: https://wiki.archlinux.org/title/Security#Restricting_access_to_kernel_pointers_in_the_proc_filesystem
|
|
||||||
# This is formally not adding security because Fedora and its
|
|
||||||
# downstream use pre-compiled kernels, but it increases
|
|
||||||
# the knowledge required for successful exploitation.
|
|
||||||
kernel.kptr_restrict = 2
|
|
||||||
|
|
||||||
# This is unlikely to cause exploitable attack surface in average use
|
|
||||||
# cases of OS that are appropriately pre-configured, but for the same
|
|
||||||
# reason it is unlikely to cause issues to the users.
|
|
||||||
# In case of a doubt, it mitigates some potential for attack surface,
|
|
||||||
# including some attack surface the user might create themselves by
|
|
||||||
# accident. Even if the latter applies, it is unlikely to cause an
|
|
||||||
# impact except mitigate exploitation
|
|
||||||
# Details: https://docs.kernel.org/admin-guide/sysctl/fs.html#protected-fifos
|
|
||||||
fs.protected_fifos = 2
|
|
||||||
# Details: https://docs.kernel.org/admin-guide/sysctl/fs.html#protected-regular
|
|
||||||
fs.protected_regular = 2
|
|
||||||
|
|
@ -89,23 +89,16 @@ if [[ ! -e /dev/kvm ]]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
NPROC="$(nproc)"
|
NPROC="$(nproc)"
|
||||||
if [[ "$NPROC" -gt 4 ]]; then
|
if [[ "$NPROC" -ge 10 ]]; then
|
||||||
# Cap the number of parallel tests to 4 to not overwhelm larger hosts
|
export TEST_JOURNAL_USE_TMP=1
|
||||||
NPROC=4
|
NPROC="$((NPROC / 3))"
|
||||||
|
else
|
||||||
|
NPROC="$((NPROC - 1))"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Workaround for a kernel 7.x virtio/vsock bug, where a patch for a potential overflow inadvertently shrunk
|
|
||||||
# the receive buffer's effective size below what was configured, which eventually causes the vsock connection
|
|
||||||
# to get reset with ENOBUFS, that kills the journal forwarding over vsock
|
|
||||||
#
|
|
||||||
# Pending fix: https://lore.kernel.org/netdev/20260518090656.134588-3-sgarzare@redhat.com/
|
|
||||||
sysctl -w net.core.rmem_max=16777216
|
|
||||||
sysctl -w net.core.wmem_max=16777216
|
|
||||||
|
|
||||||
# This test is only really useful if we're building with sanitizers and takes a long time, so let's skip it
|
# This test is only really useful if we're building with sanitizers and takes a long time, so let's skip it
|
||||||
# for now.
|
# for now.
|
||||||
export TEST_SKIP="TEST-21-DFUZZER ${TEST_SKIP:-}"
|
export TEST_SKIP="TEST-21-DFUZZER ${TEST_SKIP:-}"
|
||||||
export TEST_JOURNAL_USE_TMP=1
|
|
||||||
|
|
||||||
mkosi genkey
|
mkosi genkey
|
||||||
mkosi summary
|
mkosi summary
|
||||||
|
|
|
||||||
|
|
@ -17,10 +17,6 @@ prepare:
|
||||||
exclude:
|
exclude:
|
||||||
- systemd-standalone-.*
|
- systemd-standalone-.*
|
||||||
execute:
|
execute:
|
||||||
how: tmt
|
how: tmt
|
||||||
script: exec plans/run-integration-tests.sh
|
script: exec plans/run-integration-tests.sh
|
||||||
duration: 2h
|
duration: 2h
|
||||||
adjust:
|
|
||||||
- when: distro == fedora-eln
|
|
||||||
execute:
|
|
||||||
script: echo skipped
|
|
||||||
|
|
|
||||||
|
|
@ -1,10 +1,4 @@
|
||||||
annocheck:
|
# Disable badfuncs check that has tons of false positives.
|
||||||
ignore:
|
|
||||||
# This test is intentionally compiled with a minimal set of hardcoded
|
|
||||||
# options, so it always generates a predictable stack trace
|
|
||||||
- /usr/lib/systemd/tests/unit-tests/manual/test-coredump-stacktrace
|
|
||||||
|
|
||||||
# Disable badfuncs check that has tons of false positives.
|
|
||||||
badfuncs:
|
badfuncs:
|
||||||
allowed:
|
allowed:
|
||||||
/usr/lib/systemd/tests/unit-tests/*:
|
/usr/lib/systemd/tests/unit-tests/*:
|
||||||
|
|
|
||||||
2
sources
2
sources
|
|
@ -1 +1 @@
|
||||||
SHA512 (systemd-262-rc2.tar.gz) = 8d4f8d41e0af6b058d922490896bdbc8487927b2b1db488a9c24614bac4fc3a14bafcd50901251d4ad4095cc2f56782f900fb32e0a70aab56f6a69fdfd257442
|
SHA512 (systemd-259.8.tar.gz) = 02d441090a58b7cde5cc314b41e4b67d73e04e0190b79dda90ffdfc93a25e480c2416d08022c92718af2956237ce06e832fb54a6d34c04f5840caff826b0a232
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,7 @@
|
||||||
import re, sys, os, collections
|
import re, sys, os, collections
|
||||||
|
|
||||||
buildroot = sys.argv[1]
|
buildroot = sys.argv[1]
|
||||||
|
no_bootloader = '--no-bootloader' in sys.argv
|
||||||
potentially_empty_outputs = [
|
|
||||||
'standalone-report',
|
|
||||||
*(['boot'] if '--no-bootloader' in sys.argv else []),
|
|
||||||
]
|
|
||||||
|
|
||||||
known_files = '''
|
known_files = '''
|
||||||
%ghost %config(noreplace) /etc/crypttab
|
%ghost %config(noreplace) /etc/crypttab
|
||||||
|
|
@ -30,8 +26,8 @@ known_files = '''
|
||||||
%ghost %dir /var/lib/private/systemd
|
%ghost %dir /var/lib/private/systemd
|
||||||
%ghost %dir /var/lib/private/systemd/journal-upload
|
%ghost %dir /var/lib/private/systemd/journal-upload
|
||||||
%ghost /var/lib/private/systemd/journal-upload/state
|
%ghost /var/lib/private/systemd/journal-upload/state
|
||||||
%ghost %dir %verify(not user group) /var/lib/systemd/timesync
|
%ghost %dir /var/lib/systemd/timesync
|
||||||
%ghost %verify(not user group) /var/lib/systemd/timesync/clock
|
%ghost /var/lib/systemd/timesync/clock
|
||||||
%ghost %dir /var/lib/systemd/backlight
|
%ghost %dir /var/lib/systemd/backlight
|
||||||
%ghost /var/lib/systemd/catalog/database
|
%ghost /var/lib/systemd/catalog/database
|
||||||
%ghost %dir /var/lib/systemd/coredump
|
%ghost %dir /var/lib/systemd/coredump
|
||||||
|
|
@ -77,7 +73,6 @@ outputs = {suffix: open(f'.file-list-{suffix}', 'w')
|
||||||
'resolve',
|
'resolve',
|
||||||
'tests',
|
'tests',
|
||||||
'standalone-repart',
|
'standalone-repart',
|
||||||
'standalone-report',
|
|
||||||
'standalone-tmpfiles',
|
'standalone-tmpfiles',
|
||||||
'standalone-sysusers',
|
'standalone-sysusers',
|
||||||
'standalone-shutdown',
|
'standalone-shutdown',
|
||||||
|
|
@ -99,11 +94,10 @@ for file in files(buildroot):
|
||||||
/usr/lib.*/(security|pkgconfig)$|
|
/usr/lib.*/(security|pkgconfig)$|
|
||||||
/usr/lib/rpm(/macros.d|)$|
|
/usr/lib/rpm(/macros.d|)$|
|
||||||
/usr/lib/firewalld(/services|)$|
|
/usr/lib/firewalld(/services|)$|
|
||||||
/usr/share/(locale|licenses)| # no $
|
/usr/share/(locale|licenses|doc)| # no $
|
||||||
LICENSE|
|
|
||||||
/etc(/pam\.d|/xdg|/X11|/X11/xinit|/X11.*\.d|)$|
|
/etc(/pam\.d|/xdg|/X11|/X11/xinit|/X11.*\.d|)$|
|
||||||
/etc/(dnf|dnf/protected.d)$|
|
/etc/(dnf|dnf/protected.d)$|
|
||||||
/usr/(src|lib/debug)| # no $
|
/usr/(src|lib/debug)| # no $
|
||||||
/run$|
|
/run$|
|
||||||
/var(/cache|/log|/lib|/run|)$
|
/var(/cache|/log|/lib|/run|)$
|
||||||
''', n, re.X):
|
''', n, re.X):
|
||||||
|
|
@ -112,8 +106,6 @@ for file in files(buildroot):
|
||||||
if n.endswith('.standalone'):
|
if n.endswith('.standalone'):
|
||||||
if 'repart' in n:
|
if 'repart' in n:
|
||||||
o = outputs['standalone-repart']
|
o = outputs['standalone-repart']
|
||||||
elif 'report' in n:
|
|
||||||
o = outputs['standalone-report']
|
|
||||||
elif 'tmpfiles' in n:
|
elif 'tmpfiles' in n:
|
||||||
o = outputs['standalone-tmpfiles']
|
o = outputs['standalone-tmpfiles']
|
||||||
elif 'sysusers' in n:
|
elif 'sysusers' in n:
|
||||||
|
|
@ -121,7 +113,7 @@ for file in files(buildroot):
|
||||||
elif 'shutdown' in n:
|
elif 'shutdown' in n:
|
||||||
o = outputs['standalone-shutdown']
|
o = outputs['standalone-shutdown']
|
||||||
else:
|
else:
|
||||||
assert False, f'Found {n} not belonging to known standalone packages'
|
assert False, 'Found .standalone not belonging to known packages'
|
||||||
|
|
||||||
elif '/security/pam_' in n or '/man8/pam_' in n:
|
elif '/security/pam_' in n or '/man8/pam_' in n:
|
||||||
o = outputs['pam']
|
o = outputs['pam']
|
||||||
|
|
@ -129,7 +121,7 @@ for file in files(buildroot):
|
||||||
o = outputs['rpm-macros']
|
o = outputs['rpm-macros']
|
||||||
elif '/usr/lib/systemd/tests' in n:
|
elif '/usr/lib/systemd/tests' in n:
|
||||||
o = outputs['tests']
|
o = outputs['tests']
|
||||||
elif ('ukify' in n or '/hwids/' in n) and '/man/' not in n:
|
elif 'ukify' in n and '/man/' not in n:
|
||||||
o = outputs['ukify']
|
o = outputs['ukify']
|
||||||
elif re.search(r'/libsystemd-core-.*\.so$', n):
|
elif re.search(r'/libsystemd-core-.*\.so$', n):
|
||||||
o = outputs['main']
|
o = outputs['main']
|
||||||
|
|
@ -159,7 +151,6 @@ for file in files(buildroot):
|
||||||
mount.ddi|
|
mount.ddi|
|
||||||
importctl|
|
importctl|
|
||||||
portablectl|
|
portablectl|
|
||||||
portabled|portable1|
|
|
||||||
systemd-nspawn|
|
systemd-nspawn|
|
||||||
systemd\.nspawn|
|
systemd\.nspawn|
|
||||||
systemd-vmspawn|
|
systemd-vmspawn|
|
||||||
|
|
@ -242,12 +233,8 @@ for file in files(buildroot):
|
||||||
integritysetup|
|
integritysetup|
|
||||||
integritytab|
|
integritytab|
|
||||||
remount-fs|
|
remount-fs|
|
||||||
tpm2|
|
|
||||||
/initrd|
|
/initrd|
|
||||||
systemd-sysinstall|
|
|
||||||
systemd[.-]pcr|
|
systemd[.-]pcr|
|
||||||
systemd-imdsd|
|
|
||||||
systemd-loop|
|
|
||||||
/pcrlock\.d|
|
/pcrlock\.d|
|
||||||
systemd-measure|
|
systemd-measure|
|
||||||
/boot$|
|
/boot$|
|
||||||
|
|
@ -257,15 +244,17 @@ for file in files(buildroot):
|
||||||
binfmt|
|
binfmt|
|
||||||
sysctl|
|
sysctl|
|
||||||
coredump|
|
coredump|
|
||||||
homectl|
|
|
||||||
homed|home1|
|
homed|home1|
|
||||||
sysupdate|updatectl|
|
sysupdate|updatctl|
|
||||||
oomd
|
oomd|
|
||||||
''', n, re.X):
|
portabled|portable1
|
||||||
|
''', n, re.X): # coredumpctl, homectl, portablectl are included in the main package because
|
||||||
|
# they can be used to interact with remote daemons. Also, the user could be
|
||||||
|
# confused if those user-facing binaries are not available.
|
||||||
o = outputs['udev']
|
o = outputs['udev']
|
||||||
|
|
||||||
elif re.search(r'''/boot/efi|
|
elif re.search(r'''/boot/efi|
|
||||||
/usr/lib/systemd/boot/efi|
|
/usr/lib/systemd/boot|
|
||||||
sd-boot|systemd-boot\.|loader.conf
|
sd-boot|systemd-boot\.|loader.conf
|
||||||
''', n, re.X):
|
''', n, re.X):
|
||||||
o = outputs['boot']
|
o = outputs['boot']
|
||||||
|
|
@ -284,8 +273,7 @@ for file in files(buildroot):
|
||||||
prefix = known_files[n].split()[:-1]
|
prefix = known_files[n].split()[:-1]
|
||||||
elif file.is_dir(follow_symlinks=False):
|
elif file.is_dir(follow_symlinks=False):
|
||||||
prefix = ['%dir']
|
prefix = ['%dir']
|
||||||
# Allow .conf files to be linked as config. They must not be %doc.
|
elif 'README' in n:
|
||||||
elif ('README' in n or '/doc/' in n) and not n.endswith('.conf'):
|
|
||||||
prefix = ['%doc']
|
prefix = ['%doc']
|
||||||
elif n.startswith('/etc'):
|
elif n.startswith('/etc'):
|
||||||
prefix = ['%config(noreplace)']
|
prefix = ['%config(noreplace)']
|
||||||
|
|
@ -302,10 +290,9 @@ for file in files(buildroot):
|
||||||
for file in o:
|
for file in o:
|
||||||
print(f'{prefix}{n}{suffix}', file=file)
|
print(f'{prefix}{n}{suffix}', file=file)
|
||||||
|
|
||||||
|
if [print(f'ERROR: no file names were written to {o.name}')
|
||||||
if [
|
for name, o in outputs.items()
|
||||||
print(f'ERROR: no file names were written to {o.name}')
|
if (o.tell() == 0 and
|
||||||
for name, o in outputs.items()
|
not (no_bootloader and name == 'boot'))
|
||||||
if o.tell() == 0 and name not in potentially_empty_outputs
|
]:
|
||||||
]:
|
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
|
||||||
288
systemd.spec
288
systemd.spec
|
|
@ -7,6 +7,11 @@
|
||||||
%global system_unit_dir %{pkgdir}/system
|
%global system_unit_dir %{pkgdir}/system
|
||||||
%global user_unit_dir %{pkgdir}/user
|
%global user_unit_dir %{pkgdir}/user
|
||||||
|
|
||||||
|
%if 0%{?__isa_bits} == 64
|
||||||
|
%global elf_bits (64bit)
|
||||||
|
%global elf_suffix ()%{elf_bits}
|
||||||
|
%endif
|
||||||
|
|
||||||
%bcond bzip2 1
|
%bcond bzip2 1
|
||||||
%bcond gnutls 1
|
%bcond gnutls 1
|
||||||
%bcond lz4 1
|
%bcond lz4 1
|
||||||
|
|
@ -19,15 +24,6 @@
|
||||||
%bcond bootstrap 0
|
%bcond bootstrap 0
|
||||||
%bcond tests 1
|
%bcond tests 1
|
||||||
|
|
||||||
# When enabled, rely on filesystem(unmerged-sbin-symlinks) file triggers to
|
|
||||||
# create /usr/sbin symlinks instead of shipping them in the package. This
|
|
||||||
# avoids file conflicts when installing on merged-sbin systems and eliminates
|
|
||||||
# bootstrap ordering issues with the bin/sbin merge.
|
|
||||||
#
|
|
||||||
# So far only Fedora >= 43 ships a filesystem package with those file
|
|
||||||
# triggers and the required matching virtual provides.
|
|
||||||
%bcond sbin_compat %[0%{?fedora} >= 43]
|
|
||||||
|
|
||||||
# riscv64 has LTO disabled globally
|
# riscv64 has LTO disabled globally
|
||||||
%bcond lto %["%_arch" != "riscv64"]
|
%bcond lto %["%_arch" != "riscv64"]
|
||||||
|
|
||||||
|
|
@ -73,11 +69,6 @@
|
||||||
%define noarch_requires_version %{version}-%{release}
|
%define noarch_requires_version %{version}-%{release}
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if 0%{?__isa_bits} == 64
|
|
||||||
%global elf_bits (64bit)
|
|
||||||
%global elf_suffix ()%{elf_bits}
|
|
||||||
%endif
|
|
||||||
|
|
||||||
Name: systemd
|
Name: systemd
|
||||||
Url: https://systemd.io
|
Url: https://systemd.io
|
||||||
# Allow users to specify the version and release when building the rpm by
|
# Allow users to specify the version and release when building the rpm by
|
||||||
|
|
@ -85,7 +76,7 @@ Url: https://systemd.io
|
||||||
# But don't do that on OBS, otherwise the version subst fails, and will be
|
# But don't do that on OBS, otherwise the version subst fails, and will be
|
||||||
# like 257-123-gabcd257.1 instead of 257-123-gabcd
|
# like 257-123-gabcd257.1 instead of 257-123-gabcd
|
||||||
%if %{without obs}
|
%if %{without obs}
|
||||||
Version: %{?version_override}%{!?version_override:262~rc2}
|
Version: %{?version_override}%{!?version_override:259.8}
|
||||||
%else
|
%else
|
||||||
Version: %{?version_override}%{!?version_override:%(cat meson.version)}
|
Version: %{?version_override}%{!?version_override:%(cat meson.version)}
|
||||||
%endif
|
%endif
|
||||||
|
|
@ -93,9 +84,6 @@ Release: %autorelease
|
||||||
|
|
||||||
%global stable %(c="%version"; [ "$c" = "${c#*.*}" ]; echo $?)
|
%global stable %(c="%version"; [ "$c" = "${c#*.*}" ]; echo $?)
|
||||||
|
|
||||||
# Temporary macro to enable systemd-report.standalone
|
|
||||||
%bcond report_standalone %[ v"%{version}" >= v"261.999" || %{defined commit} ]
|
|
||||||
|
|
||||||
# For a breakdown of the licensing, see README
|
# For a breakdown of the licensing, see README
|
||||||
License: LGPL-2.1-or-later AND MIT AND GPL-2.0-or-later
|
License: LGPL-2.1-or-later AND MIT AND GPL-2.0-or-later
|
||||||
Summary: System and Service Manager
|
Summary: System and Service Manager
|
||||||
|
|
@ -122,6 +110,7 @@ Source6: inittab
|
||||||
Source7: sysctl.conf.README
|
Source7: sysctl.conf.README
|
||||||
Source8: systemd-journal-remote.xml
|
Source8: systemd-journal-remote.xml
|
||||||
Source9: systemd-journal-gatewayd.xml
|
Source9: systemd-journal-gatewayd.xml
|
||||||
|
Source10: 20-yama-ptrace.conf
|
||||||
Source11: systemd-udev-trigger-no-reload.conf
|
Source11: systemd-udev-trigger-no-reload.conf
|
||||||
# https://fedoraproject.org/wiki/How_to_filter_libabigail_reports
|
# https://fedoraproject.org/wiki/How_to_filter_libabigail_reports
|
||||||
Source13: libabigail.abignore
|
Source13: libabigail.abignore
|
||||||
|
|
@ -131,7 +120,7 @@ Source15: 10-oomd-per-slice-defaults.conf
|
||||||
Source16: 10-timeout-abort.conf
|
Source16: 10-timeout-abort.conf
|
||||||
Source17: 10-map-count.conf
|
Source17: 10-map-count.conf
|
||||||
Source18: 60-block-scheduler.rules
|
Source18: 60-block-scheduler.rules
|
||||||
Source19: 99-kernel-hardening.conf
|
|
||||||
Source20: macros.sysusers.compat
|
Source20: macros.sysusers.compat
|
||||||
Source21: macros.sysusers
|
Source21: macros.sysusers
|
||||||
Source22: sysusers.attr
|
Source22: sysusers.attr
|
||||||
|
|
@ -156,16 +145,20 @@ Patch: https://github.com/systemd/systemd/pull/26494.patch
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=2251843
|
# https://bugzilla.redhat.com/show_bug.cgi?id=2251843
|
||||||
Patch: 30846.patch
|
Patch: 30846.patch
|
||||||
|
|
||||||
|
# Again create runlevelX.target. Dropping those files breaks upgrades.
|
||||||
|
# https://bugzilla.redhat.com/show_bug.cgi?id=2411195
|
||||||
|
Patch: 0001-Revert-units-drop-runlevel-0-6-.target.patch
|
||||||
|
|
||||||
# userdb: create userdb root directory with correct label
|
# userdb: create userdb root directory with correct label
|
||||||
# We can drop this after SELinux policy is updated to handle the transition.
|
# We can drop this after SELinux policy is updated to handle the transition.
|
||||||
Patch: 0001-core-create-userdb-root-directory-with-correct-label.patch
|
Patch: 38769.patch
|
||||||
|
|
||||||
# Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=2415701
|
# Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=2415701
|
||||||
Patch: 0002-machined-continue-without-resolve.hook-socket.patch
|
Patch: 0002-machined-continue-without-resolve.hook-socket.patch
|
||||||
|
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%ifarch %{ix86} x86_64 aarch64 riscv64 loongarch64
|
%ifarch %{ix86} x86_64 aarch64 riscv64
|
||||||
%global want_bootloader 1
|
%global want_bootloader 1
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
|
|
@ -187,13 +180,6 @@ BuildRequires: cryptsetup-devel
|
||||||
# We use the %%systemd_{post,preun,…} macros for various services.
|
# We use the %%systemd_{post,preun,…} macros for various services.
|
||||||
BuildRequires: systemd-rpm-macros
|
BuildRequires: systemd-rpm-macros
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if !%{defined rhel} || 0%{?rhel} > 10
|
|
||||||
# Use dlopen-notes to generate Requires/Recommends from embedded metadata.
|
|
||||||
# Currently, package-notes are not available on Centos Stream 9 or 10.
|
|
||||||
BuildRequires: package-notes >= 0.20
|
|
||||||
%endif
|
|
||||||
|
|
||||||
BuildRequires: dbus-devel
|
BuildRequires: dbus-devel
|
||||||
BuildRequires: util-linux
|
BuildRequires: util-linux
|
||||||
# /usr/bin/getfacl is needed by test-acl-util
|
# /usr/bin/getfacl is needed by test-acl-util
|
||||||
|
|
@ -220,7 +206,7 @@ BuildRequires: libcurl-devel
|
||||||
BuildRequires: kmod-devel
|
BuildRequires: kmod-devel
|
||||||
BuildRequires: elfutils-devel
|
BuildRequires: elfutils-devel
|
||||||
BuildRequires: openssl-devel
|
BuildRequires: openssl-devel
|
||||||
%if 0%{?fedora} >= 41 && 0%{?fedora} < 45
|
%if 0%{?fedora} >= 41
|
||||||
BuildRequires: openssl-devel-engine
|
BuildRequires: openssl-devel-engine
|
||||||
%endif
|
%endif
|
||||||
%if %{with gnutls}
|
%if %{with gnutls}
|
||||||
|
|
@ -247,6 +233,7 @@ BuildRequires: docbook-style-xsl
|
||||||
BuildRequires: pkgconfig
|
BuildRequires: pkgconfig
|
||||||
BuildRequires: gperf
|
BuildRequires: gperf
|
||||||
BuildRequires: gawk
|
BuildRequires: gawk
|
||||||
|
BuildRequires: tree
|
||||||
BuildRequires: hostname
|
BuildRequires: hostname
|
||||||
BuildRequires: python3
|
BuildRequires: python3
|
||||||
BuildRequires: python3-devel
|
BuildRequires: python3-devel
|
||||||
|
|
@ -304,15 +291,9 @@ Requires: systemd-libs%{_isa} = %{version}-%{release}
|
||||||
%{?fedora:Recommends: systemd-resolved = %{version}-%{release}}
|
%{?fedora:Recommends: systemd-resolved = %{version}-%{release}}
|
||||||
Requires: systemd-shared%{_isa} = %{version}-%{release}
|
Requires: systemd-shared%{_isa} = %{version}-%{release}
|
||||||
Requires: /usr/bin/systemd-sysusers
|
Requires: /usr/bin/systemd-sysusers
|
||||||
|
|
||||||
# The standalone version doesn't Provide the _isa suffix,
|
# The standalone version doesn't Provide the _isa suffix,
|
||||||
# so this biases towards the common version.
|
# so this biases towards the common version.
|
||||||
Recommends: systemd-sysusers%{_isa} = %{version}-%{release}
|
Recommends: systemd-sysusers%{_isa} = %{version}-%{release}
|
||||||
|
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
Requires: libzstd.so.1%{?elf_suffix}
|
|
||||||
%endif
|
|
||||||
|
|
||||||
Recommends: diffutils
|
Recommends: diffutils
|
||||||
Requires: (util-linux-core or util-linux)
|
Requires: (util-linux-core or util-linux)
|
||||||
Requires: (libbpf >= 2:1.4.7 if libbpf)
|
Requires: (libbpf >= 2:1.4.7 if libbpf)
|
||||||
|
|
@ -329,7 +310,7 @@ Conflicts: initscripts < 9.56.1
|
||||||
%if 0%{?fedora}
|
%if 0%{?fedora}
|
||||||
Conflicts: fedora-release < 23-0.12
|
Conflicts: fedora-release < 23-0.12
|
||||||
%endif
|
%endif
|
||||||
%if 0%{?fedora} >= 41 || 0%{?rhel} >= 11
|
%if 0%{?fedora} >= 41
|
||||||
BuildRequires: setup >= 2.15.0-3
|
BuildRequires: setup >= 2.15.0-3
|
||||||
BuildRequires: python3
|
BuildRequires: python3
|
||||||
Conflicts: setup < 2.15.0-3
|
Conflicts: setup < 2.15.0-3
|
||||||
|
|
@ -345,16 +326,12 @@ Conflicts: dracut < 060-2
|
||||||
Conflicts: dracut < 059-16
|
Conflicts: dracut < 059-16
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if %{with report_standalone}
|
|
||||||
Conflicts: systemd-standalone-report
|
|
||||||
Provides: systemd-report = %{version}-%{release}
|
|
||||||
%endif
|
|
||||||
Conflicts: systemd-standalone-tmpfiles
|
Conflicts: systemd-standalone-tmpfiles
|
||||||
Provides: systemd-tmpfiles = %{version}-%{release}
|
Provides: systemd-tmpfiles = %{version}-%{release}
|
||||||
Conflicts: systemd-standalone-shutdown
|
Conflicts: systemd-standalone-shutdown
|
||||||
Provides: systemd-shutdown = %{version}-%{release}
|
Provides: systemd-shutdown = %{version}-%{release}
|
||||||
|
|
||||||
%if %{with sbin_compat} || "%{_sbindir}" == "%{_bindir}"
|
%if "%{_sbindir}" == "%{_bindir}"
|
||||||
# Compat symlinks for Requires in other packages.
|
# Compat symlinks for Requires in other packages.
|
||||||
# We rely on filesystem to create the symlinks for us.
|
# We rely on filesystem to create the symlinks for us.
|
||||||
Requires: filesystem(unmerged-sbin-symlinks)
|
Requires: filesystem(unmerged-sbin-symlinks)
|
||||||
|
|
@ -365,42 +342,45 @@ Provides: /usr/sbin/reboot
|
||||||
Provides: /usr/sbin/shutdown
|
Provides: /usr/sbin/shutdown
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
# libmount is always required, even in containers, so make it a hard dependency.
|
# libmount is always required, even in containers, so make it a hard dependency.
|
||||||
Requires: libmount.so.1%{?elf_suffix}
|
Requires: libmount.so.1%{?elf_suffix}
|
||||||
Requires: libmount.so.1(MOUNT_2.26)%{?elf_bits}
|
Requires: libmount.so.1(MOUNT_2.26)%{?elf_bits}
|
||||||
# Various systemd services have syscall filters so make libseccomp a hard dependency.
|
# Various systemd services have syscall filters so make libseccomp a hard dependency.
|
||||||
Requires: libseccomp.so.2%{?elf_suffix}
|
Requires: libseccomp.so.2%{?elf_suffix}
|
||||||
Requires: libacl.so.1%{?elf_suffix}
|
|
||||||
|
# Recommends to replace normal Requires deps for stuff that is dlopen()ed
|
||||||
|
Recommends: libxkbcommon.so.0%{?elf_suffix}
|
||||||
|
Recommends: libidn2.so.0%{?elf_suffix}
|
||||||
|
Recommends: libidn2.so.0(IDN2_0.0.0)%{?elf_bits}
|
||||||
|
Recommends: libpcre2-8.so.0%{?elf_suffix}
|
||||||
|
Recommends: libpwquality.so.1%{?elf_suffix}
|
||||||
|
Recommends: libpwquality.so.1(LIBPWQUALITY_1.0)%{?elf_bits}
|
||||||
|
%if 0%{?fedora}
|
||||||
|
Recommends: libqrencode.so.4%{?elf_suffix}
|
||||||
%endif
|
%endif
|
||||||
|
Recommends: libbpf.so.1%{?elf_suffix}
|
||||||
|
Recommends: libbpf.so.1(LIBBPF_0.4.0)%{?elf_bits}
|
||||||
|
|
||||||
%define dlopen_notes_features %{expand:
|
# used by systemd-coredump and systemd-analyze
|
||||||
# Various systemd services have syscall filters so make libseccomp a hard dependency.
|
Recommends: libdw.so.1%{?elf_suffix}
|
||||||
systemd:seccomp:required
|
Recommends: libdw.so.1(ELFUTILS_0.186)%{?elf_bits}
|
||||||
|
Recommends: libelf.so.1%{?elf_suffix}
|
||||||
|
Recommends: libelf.so.1(ELFUTILS_1.7)%{?elf_bits}
|
||||||
|
|
||||||
# zstd is used for compression in the journal
|
# used by dissect, integritysetup, veritysetyp, growfs, repart, cryptenroll, home
|
||||||
systemd:zstd:required
|
Recommends: libcryptsetup.so.12%{?elf_suffix}
|
||||||
|
Recommends: libcryptsetup.so.12(CRYPTSETUP_2.4)%{?elf_bits}
|
||||||
|
|
||||||
# Libkmod is used to load modules. Assume that if we need udevd, we certainly
|
# Libkmod is used to load modules.
|
||||||
# want to load modules, so make this into a hard dependency here.
|
Recommends: libkmod.so.2%{?elf_suffix}
|
||||||
systemd-udev:kmod:required
|
# kmod_list_next, kmod_load_resources, kmod_module_get_initstate,
|
||||||
|
# kmod_module_get_module, kmod_module_get_name, kmod_module_new_from_lookup,
|
||||||
|
# kmod_module_probe_insert_module, kmod_module_unref, kmod_module_unref_list,
|
||||||
|
# kmod_new, kmod_set_log_fn, kmod_unref, kmod_validate_resources
|
||||||
|
# are part of LIBKMOD_5.
|
||||||
|
Recommends: libkmod.so.2(LIBKMOD_5)%{?elf_bits}
|
||||||
|
|
||||||
# We want to always use idn with resolved.
|
Recommends: libarchive.so.13%{?elf_suffix}
|
||||||
systemd-resolved:idn:required
|
|
||||||
|
|
||||||
# libcurl is required by systemd-imdsd and systemd-report.
|
|
||||||
# Downgrade the dep for now.
|
|
||||||
systemd:curl:recommended
|
|
||||||
systemd-udev:curl:recommended
|
|
||||||
|
|
||||||
# libssl + libcrypto are required by systemd-resolved/resolvectl.
|
|
||||||
# Downgrade the dep in the main package.
|
|
||||||
systemd:libssl:recommended
|
|
||||||
systemd:libcrypto:recommended
|
|
||||||
|
|
||||||
# Disable qrencode on non-fedora builds
|
|
||||||
%{!?fedora:*:qrencode:ignored}
|
|
||||||
}
|
|
||||||
|
|
||||||
%description
|
%description
|
||||||
systemd is a system and service manager that runs as PID 1 and starts the rest
|
systemd is a system and service manager that runs as PID 1 and starts the rest
|
||||||
|
|
@ -490,18 +470,6 @@ Requires(preun): systemd%{_isa} = %{version}-%{release}
|
||||||
Requires(postun): systemd%{_isa} = %{version}-%{release}
|
Requires(postun): systemd%{_isa} = %{version}-%{release}
|
||||||
Requires(post): grep
|
Requires(post): grep
|
||||||
Requires: kmod >= 18-4
|
Requires: kmod >= 18-4
|
||||||
|
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
# Libkmod is used to load modules. Assume that if we need udevd, we certainly
|
|
||||||
# want to load modules, so make this into a hard dependency here.
|
|
||||||
Requires: libkmod.so.2%{?elf_suffix}
|
|
||||||
Requires: libkmod.so.2(LIBKMOD_5)%{?elf_bits}
|
|
||||||
# udev uses libblkid in various builtins so make it a hard dependency.
|
|
||||||
Requires: libblkid.so.1%{?elf_suffix}
|
|
||||||
Requires: libblkid.so.1(BLKID_2.30)%{?elf_bits}
|
|
||||||
Requires: libfdisk.so.1%{?elf_suffix}
|
|
||||||
%endif
|
|
||||||
|
|
||||||
Provides: udev = %{version}
|
Provides: udev = %{version}
|
||||||
Provides: udev%{_isa} = %{version}
|
Provides: udev%{_isa} = %{version}
|
||||||
%if 0%{?fedora} || 0%{?rhel} >= 10
|
%if 0%{?fedora} || 0%{?rhel} >= 10
|
||||||
|
|
@ -519,7 +487,6 @@ Provides: systemd-timesyncd = %{version}-%{release}
|
||||||
%endif
|
%endif
|
||||||
Conflicts: systemd-networkd < %{version}-%{release}
|
Conflicts: systemd-networkd < %{version}-%{release}
|
||||||
|
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
# Libkmod is used to load modules. Assume that if we need udevd, we certainly
|
# Libkmod is used to load modules. Assume that if we need udevd, we certainly
|
||||||
# want to load modules, so make this into a hard dependency here.
|
# want to load modules, so make this into a hard dependency here.
|
||||||
Requires: libkmod.so.2%{?elf_suffix}
|
Requires: libkmod.so.2%{?elf_suffix}
|
||||||
|
|
@ -527,13 +494,29 @@ Requires: libkmod.so.2(LIBKMOD_5)%{?elf_bits}
|
||||||
# udev uses libblkid in various builtins so make it a hard dependency.
|
# udev uses libblkid in various builtins so make it a hard dependency.
|
||||||
Requires: libblkid.so.1%{?elf_suffix}
|
Requires: libblkid.so.1%{?elf_suffix}
|
||||||
Requires: libblkid.so.1(BLKID_2.30)%{?elf_bits}
|
Requires: libblkid.so.1(BLKID_2.30)%{?elf_bits}
|
||||||
%endif
|
|
||||||
|
# Recommends to replace normal Requires deps for stuff that is dlopen()ed
|
||||||
|
# used by dissect, integritysetup, veritysetyp, growfs, repart, cryptenroll, home
|
||||||
|
Recommends: libcryptsetup.so.12%{?elf_suffix}
|
||||||
|
Recommends: libcryptsetup.so.12(CRYPTSETUP_2.4)%{?elf_bits}
|
||||||
|
|
||||||
|
# used by systemd-coredump and systemd-analyze
|
||||||
|
Recommends: libdw.so.1%{?elf_suffix}
|
||||||
|
Recommends: libdw.so.1(ELFUTILS_0.186)%{?elf_bits}
|
||||||
|
Recommends: libelf.so.1%{?elf_suffix}
|
||||||
|
Recommends: libelf.so.1(ELFUTILS_1.7)%{?elf_bits}
|
||||||
|
|
||||||
|
# used by home, cryptsetup, cryptenroll, logind
|
||||||
|
Recommends: libfido2.so.1%{?elf_suffix}
|
||||||
|
Recommends: libp11-kit.so.0%{?elf_suffix}
|
||||||
|
Recommends: libtss2-esys.so.0%{?elf_suffix}
|
||||||
|
Recommends: libtss2-mu.so.0%{?elf_suffix}
|
||||||
|
Recommends: libtss2-rc.so.0%{?elf_suffix}
|
||||||
|
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1377733#c9
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1377733#c9
|
||||||
Suggests: systemd-bootchart
|
Suggests: systemd-bootchart
|
||||||
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1408878
|
||||||
# v261 handles missing setfont/loadkeys gracefully
|
Requires: kbd
|
||||||
Recommends: kbd
|
|
||||||
|
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1753381
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1753381
|
||||||
Provides: u2f-hidraw-policy = 1.0.2-40
|
Provides: u2f-hidraw-policy = 1.0.2-40
|
||||||
|
|
@ -546,7 +529,7 @@ Provides: systemd-repart = %{version}-%{release}
|
||||||
Conflicts: xorg-x11-drv-evdev < 2.11.0
|
Conflicts: xorg-x11-drv-evdev < 2.11.0
|
||||||
Conflicts: xorg-x11-drv-libinput < 1.5.0
|
Conflicts: xorg-x11-drv-libinput < 1.5.0
|
||||||
|
|
||||||
%if %{with sbin_compat} || "%{_sbindir}" == "%{_bindir}"
|
%if "%{_sbindir}" == "%{_bindir}"
|
||||||
# Compat symlinks for Requires in other packages.
|
# Compat symlinks for Requires in other packages.
|
||||||
# We rely on filesystem to create the symlinks for us.
|
# We rely on filesystem to create the symlinks for us.
|
||||||
Requires: filesystem(unmerged-sbin-symlinks)
|
Requires: filesystem(unmerged-sbin-symlinks)
|
||||||
|
|
@ -571,8 +554,7 @@ Requires: (systemd-boot if %{shrink:(
|
||||||
filesystem(x86-32) or
|
filesystem(x86-32) or
|
||||||
filesystem(x86-64) or
|
filesystem(x86-64) or
|
||||||
filesystem(aarch64) or
|
filesystem(aarch64) or
|
||||||
filesystem(riscv64) or
|
filesystem(riscv64)
|
||||||
filesystem(loongarch64)
|
|
||||||
)})
|
)})
|
||||||
Requires: python3dist(pefile)
|
Requires: python3dist(pefile)
|
||||||
Requires: python3dist(zstandard)
|
Requires: python3dist(zstandard)
|
||||||
|
|
@ -647,7 +629,6 @@ Recommends: qemu-kvm-core
|
||||||
Recommends: qemu-device-display-virtio-gpu
|
Recommends: qemu-device-display-virtio-gpu
|
||||||
Recommends: qemu-device-display-virtio-vga
|
Recommends: qemu-device-display-virtio-vga
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
# Bias the system towards libcurl-minimal if nothing pulls in full libcurl (#1997040)
|
# Bias the system towards libcurl-minimal if nothing pulls in full libcurl (#1997040)
|
||||||
Suggests: libcurl-minimal
|
Suggests: libcurl-minimal
|
||||||
License: LGPL-2.1-or-later
|
License: LGPL-2.1-or-later
|
||||||
|
|
@ -666,10 +647,6 @@ License: LGPL-2.1-or-later
|
||||||
Requires: firewalld-filesystem
|
Requires: firewalld-filesystem
|
||||||
Provides: systemd-journal-gateway = %{version}-%{release}
|
Provides: systemd-journal-gateway = %{version}-%{release}
|
||||||
Provides: systemd-journal-gateway%{_isa} = %{version}-%{release}
|
Provides: systemd-journal-gateway%{_isa} = %{version}-%{release}
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
Requires: libmicrohttpd.so.12%{?elf_suffix}
|
|
||||||
Requires: libcurl.so.4%{?elf_suffix}
|
|
||||||
%endif
|
|
||||||
# Bias the system towards libcurl-minimal if nothing pulls in full libcurl (#1997040)
|
# Bias the system towards libcurl-minimal if nothing pulls in full libcurl (#1997040)
|
||||||
Suggests: libcurl-minimal
|
Suggests: libcurl-minimal
|
||||||
|
|
||||||
|
|
@ -706,10 +683,8 @@ enabled for this to have any effect.
|
||||||
%package resolved
|
%package resolved
|
||||||
Summary: Network Name Resolution manager
|
Summary: Network Name Resolution manager
|
||||||
Requires: systemd%{_isa} = %{version}-%{release}
|
Requires: systemd%{_isa} = %{version}-%{release}
|
||||||
%if %{defined rhel} && 0%{?rhel} <= 10
|
|
||||||
Requires: libidn2.so.0%{?elf_suffix}
|
Requires: libidn2.so.0%{?elf_suffix}
|
||||||
Requires: libidn2.so.0(IDN2_0.0.0)%{?elf_bits}
|
Requires: libidn2.so.0(IDN2_0.0.0)%{?elf_bits}
|
||||||
%endif
|
|
||||||
Requires(posttrans): grep
|
Requires(posttrans): grep
|
||||||
|
|
||||||
%description resolved
|
%description resolved
|
||||||
|
|
@ -751,21 +726,7 @@ RemovePathPostfixes: .standalone
|
||||||
%description standalone-repart
|
%description standalone-repart
|
||||||
Standalone systemd-repart binary with no dependencies on the systemd-shared
|
Standalone systemd-repart binary with no dependencies on the systemd-shared
|
||||||
library or other libraries from systemd-libs. This package conflicts with the
|
library or other libraries from systemd-libs. This package conflicts with the
|
||||||
systemd-udev package and is meant for use on systems without systemd-udev.
|
main systemd package and is meant for use on systems without systemd.
|
||||||
|
|
||||||
%if %{with report_standalone}
|
|
||||||
%package standalone-report
|
|
||||||
Summary: Standalone systemd-report binaries for use on systems without systemd
|
|
||||||
Provides: systemd-report = %{version}-%{release}
|
|
||||||
Conflicts: systemd
|
|
||||||
RemovePathPostfixes: .standalone
|
|
||||||
|
|
||||||
%description standalone-report
|
|
||||||
Standalone systemd-report, systemd-report-basic, systemd-report-sign-plain, …
|
|
||||||
binaries with no dependencies on the systemd-shared library or other libraries
|
|
||||||
from systemd-libs. This package conflicts with the main systemd package and
|
|
||||||
is meant for use on systems without systemd or with older version of it.
|
|
||||||
%endif
|
|
||||||
|
|
||||||
%package standalone-tmpfiles
|
%package standalone-tmpfiles
|
||||||
Summary: Standalone systemd-tmpfiles binary for use on systems without systemd
|
Summary: Standalone systemd-tmpfiles binary for use on systems without systemd
|
||||||
|
|
@ -802,30 +763,7 @@ Standalone systemd-shutdown binary with no dependencies on the systemd-shared
|
||||||
library or other libraries from systemd-libs. This package conflicts with the
|
library or other libraries from systemd-libs. This package conflicts with the
|
||||||
main systemd package and is meant for use in exitrds.
|
main systemd package and is meant for use in exitrds.
|
||||||
|
|
||||||
%define status %{shrink:
|
|
||||||
'**'
|
|
||||||
bzip2=%{?with_bzip2}%{!?with_bzip2:0}
|
|
||||||
gnutls=%{?with_gnutls}%{!?with_gnutls:0}
|
|
||||||
lz4=%{?with_lz4}%{!?with_lz4:0}
|
|
||||||
xz=%{?with_xz}%{!?with_xz:0}
|
|
||||||
zlib=%{?with_zlib}%{!?with_zlib:0}
|
|
||||||
zstd=%{?with_zstd}%{!?with_zstd:0}
|
|
||||||
bootstrap=%{?with_bootstrap}%{!?with_bootstrap:0}
|
|
||||||
tests=%{?with_tests}%{!?with_tests:0}
|
|
||||||
lto=%{?with_lto}%{!?with_lto:0}
|
|
||||||
docs=%{?with_docs}%{!?with_docs:0}
|
|
||||||
upstream=%{?with_upstream}%{!?with_upstream:0}
|
|
||||||
obs=%{?with_obs}%{!?with_obs:0}
|
|
||||||
report_standalone=%{?with_report_standalone}%{!?with_report_standalone:0}
|
|
||||||
fedora=%{?fedora}
|
|
||||||
rhel=%{?rhel}
|
|
||||||
_arch=%{_arch}
|
|
||||||
'**'}
|
|
||||||
|
|
||||||
%prep
|
%prep
|
||||||
# Print varius with's and without's to make it easier to figure out what is going on
|
|
||||||
echo %{status}
|
|
||||||
|
|
||||||
%if %{with obs}
|
%if %{with obs}
|
||||||
# Recipe files in the OBS build are in a distro-specific dir, as they conflict (e.g. with SUSE ones)
|
# Recipe files in the OBS build are in a distro-specific dir, as they conflict (e.g. with SUSE ones)
|
||||||
mv %{_sourcedir}/%{name}.fedora/* %{_sourcedir}
|
mv %{_sourcedir}/%{name}.fedora/* %{_sourcedir}
|
||||||
|
|
@ -841,17 +779,8 @@ mv %{_sourcedir}/%{name}.fedora/* %{_sourcedir}
|
||||||
# https://github.com/rpm-software-management/rpm/issues/3450
|
# https://github.com/rpm-software-management/rpm/issues/3450
|
||||||
sed -r -i 's/^u!/u/' sysusers.d/*.conf*
|
sed -r -i 's/^u!/u/' sysusers.d/*.conf*
|
||||||
|
|
||||||
# Disable the preset for systemd-coredumd to work with old SELinux policy
|
|
||||||
sed -r -i '/enable systemd-coredumpd.service/d' presets/90-systemd.preset
|
|
||||||
|
|
||||||
%build
|
%build
|
||||||
echo %{status}
|
|
||||||
|
|
||||||
%if 0%{?eln}
|
|
||||||
%global ntpvendor fedora
|
|
||||||
%else
|
|
||||||
%global ntpvendor %(source /etc/os-release; echo ${ID})
|
%global ntpvendor %(source /etc/os-release; echo ${ID})
|
||||||
%endif
|
|
||||||
%{!?ntpvendor: echo 'NTP vendor zone is not set!'; exit 1}
|
%{!?ntpvendor: echo 'NTP vendor zone is not set!'; exit 1}
|
||||||
|
|
||||||
VMLINUX_H_PATH=''
|
VMLINUX_H_PATH=''
|
||||||
|
|
@ -879,6 +808,8 @@ VMLINUX_H_PATH=$(%python3 -c '%find_vmlinux_h')
|
||||||
CONFIGURE_OPTS=(
|
CONFIGURE_OPTS=(
|
||||||
-Dmode=release
|
-Dmode=release
|
||||||
-Dslow-tests=true
|
-Dslow-tests=true
|
||||||
|
-Dsysvinit-path=/etc/rc.d/init.d
|
||||||
|
-Drc-local=/etc/rc.d/rc.local
|
||||||
-Dntp-servers='0.%{ntpvendor}.pool.ntp.org 1.%{ntpvendor}.pool.ntp.org 2.%{ntpvendor}.pool.ntp.org 3.%{ntpvendor}.pool.ntp.org'
|
-Dntp-servers='0.%{ntpvendor}.pool.ntp.org 1.%{ntpvendor}.pool.ntp.org 2.%{ntpvendor}.pool.ntp.org 3.%{ntpvendor}.pool.ntp.org'
|
||||||
-Ddns-servers=
|
-Ddns-servers=
|
||||||
-Dservice-watchdog=
|
-Dservice-watchdog=
|
||||||
|
|
@ -909,6 +840,7 @@ CONFIGURE_OPTS=(
|
||||||
-Daudit=enabled
|
-Daudit=enabled
|
||||||
-Delfutils=enabled
|
-Delfutils=enabled
|
||||||
-Dlibcryptsetup=%[%{with bootstrap}?"disabled":"enabled"]
|
-Dlibcryptsetup=%[%{with bootstrap}?"disabled":"enabled"]
|
||||||
|
-Delfutils=enabled
|
||||||
-Drepart=enabled
|
-Drepart=enabled
|
||||||
-Dpwquality=enabled
|
-Dpwquality=enabled
|
||||||
-Dqrencode=%[%{defined rhel}?"disabled":"enabled"]
|
-Dqrencode=%[%{defined rhel}?"disabled":"enabled"]
|
||||||
|
|
@ -916,6 +848,7 @@ CONFIGURE_OPTS=(
|
||||||
-Dmicrohttpd=enabled
|
-Dmicrohttpd=enabled
|
||||||
-Dvmspawn=enabled
|
-Dvmspawn=enabled
|
||||||
-Dlibidn2=enabled
|
-Dlibidn2=enabled
|
||||||
|
-Dlibiptc=disabled
|
||||||
-Dlibcurl=enabled
|
-Dlibcurl=enabled
|
||||||
-Dlibfido2=enabled
|
-Dlibfido2=enabled
|
||||||
-Dxenctrl=%[0%{?have_xen}?"enabled":"disabled"]
|
-Dxenctrl=%[0%{?have_xen}?"enabled":"disabled"]
|
||||||
|
|
@ -1035,7 +968,7 @@ sed -r 's|/system/|/user/|g' %{SOURCE16} >10-timeout-abort.conf.user
|
||||||
%meson_install
|
%meson_install
|
||||||
|
|
||||||
# udev links
|
# udev links
|
||||||
%if !%{with sbin_compat} && "%{_sbindir}" != "%{_bindir}"
|
%if "%{_sbindir}" != "%{_bindir}"
|
||||||
mkdir -p %{buildroot}/%{_sbindir}
|
mkdir -p %{buildroot}/%{_sbindir}
|
||||||
ln -sf ../bin/udevadm %{buildroot}%{_sbindir}/udevadm
|
ln -sf ../bin/udevadm %{buildroot}%{_sbindir}/udevadm
|
||||||
%endif
|
%endif
|
||||||
|
|
@ -1135,8 +1068,9 @@ EOF
|
||||||
|
|
||||||
install -Dm0644 -t %{buildroot}/usr/lib/firewalld/services/ %{SOURCE8} %{SOURCE9}
|
install -Dm0644 -t %{buildroot}/usr/lib/firewalld/services/ %{SOURCE8} %{SOURCE9}
|
||||||
|
|
||||||
# Install kernel hardening file. Disabled by default.
|
# Install additional docs
|
||||||
install -Dm0644 -t %{buildroot}%{_pkgdocdir}/ %{SOURCE19}
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1234951
|
||||||
|
install -Dm0644 -t %{buildroot}%{_pkgdocdir}/ %{SOURCE10}
|
||||||
|
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1378974
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1378974
|
||||||
install -Dm0644 -t %{buildroot}%{system_unit_dir}/systemd-udev-trigger.service.d/ %{SOURCE11}
|
install -Dm0644 -t %{buildroot}%{system_unit_dir}/systemd-udev-trigger.service.d/ %{SOURCE11}
|
||||||
|
|
@ -1164,7 +1098,7 @@ install -Dm0644 -t %{buildroot}%{_prefix}/lib/udev/rules.d/ %{SOURCE18}
|
||||||
|
|
||||||
sed -i 's|#!/usr/bin/env python3|#!%{__python3}|' %{buildroot}/usr/lib/systemd/tests/run-unit-tests.py
|
sed -i 's|#!/usr/bin/env python3|#!%{__python3}|' %{buildroot}/usr/lib/systemd/tests/run-unit-tests.py
|
||||||
|
|
||||||
%if 0%{?fedora} >= 42 || 0%{?rhel} >= 11
|
%if 0%{?fedora} >= 42
|
||||||
install -m 0644 -D %{SOURCE21} %{buildroot}%{_rpmconfigdir}/macros.d/macros.sysusers
|
install -m 0644 -D %{SOURCE21} %{buildroot}%{_rpmconfigdir}/macros.d/macros.sysusers
|
||||||
%else
|
%else
|
||||||
install -m 0644 -D %{SOURCE20} %{buildroot}%{_rpmconfigdir}/macros.d/macros.sysusers
|
install -m 0644 -D %{SOURCE20} %{buildroot}%{_rpmconfigdir}/macros.d/macros.sysusers
|
||||||
|
|
@ -1183,20 +1117,20 @@ install -Dm0644 -t %{buildroot}%{_prefix}/lib/systemd/network/ %{SOURCE25}
|
||||||
ln -s --relative %{buildroot}%{_bindir}/kernel-install %{buildroot}%{_sbindir}/installkernel
|
ln -s --relative %{buildroot}%{_bindir}/kernel-install %{buildroot}%{_sbindir}/installkernel
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if %{with sbin_compat} || "%{_sbindir}" == "%{_bindir}"
|
%if "%{_sbindir}" == "%{_bindir}"
|
||||||
# Systemd has the split-sbin option which is also used to select the directory
|
# Systemd has the split-sbin option which is also used to select the directory
|
||||||
# for alias symlinks. We need to keep split-sbin=true for now, to support
|
# for alias symlinks. We need to keep split-sbin=true for now, to support
|
||||||
# unmerged systems. Move the symlinks here instead.
|
# unmerged systems. Move the symlinks here instead.
|
||||||
mv -v %{buildroot}/usr/sbin/* %{buildroot}%{_bindir}/
|
mv -v %{buildroot}/usr/sbin/* %{buildroot}%{_bindir}/
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%if 0%{?fedora} >= 41 || 0%{?rhel} >= 11
|
%if 0%{?fedora} >= 41
|
||||||
%if %{without upstream}
|
%if %{without upstream}
|
||||||
# This requires https://pagure.io/setup/pull-request/50
|
# This requires https://pagure.io/setup/pull-request/50
|
||||||
# and https://src.fedoraproject.org/rpms/setup/pull-request/10.
|
# and https://src.fedoraproject.org/rpms/setup/pull-request/10.
|
||||||
# We skip this on upstream builds so that new users and groups
|
# We skip this on upstream builds so that new users and groups
|
||||||
# can be added without breaking the build.
|
# can be added without breaking the build.
|
||||||
%if 0%{?fedora} >= 43 || 0%{?rhel} >= 11
|
%if 0%{?fedora} >= 43
|
||||||
IGNORED=empower \
|
IGNORED=empower \
|
||||||
%{python3} %{SOURCE4} /usr/lib/sysusers.d/setup.conf %{buildroot}/usr/lib/sysusers.d/basic.conf
|
%{python3} %{SOURCE4} /usr/lib/sysusers.d/setup.conf %{buildroot}/usr/lib/sysusers.d/basic.conf
|
||||||
%else
|
%else
|
||||||
|
|
@ -1257,10 +1191,6 @@ fi \
|
||||||
%post
|
%post
|
||||||
systemd-machine-id-setup &>/dev/null || :
|
systemd-machine-id-setup &>/dev/null || :
|
||||||
|
|
||||||
# This is for upgrades from previous versions before getty@.service needed to be enabled
|
|
||||||
[ $1 -gt 1 ] && systemctl is-enabled getty@tty1.service &>/dev/null && \
|
|
||||||
touch %{_localstatedir}/lib/rpm-state/systemd-getty-was-active || :
|
|
||||||
|
|
||||||
[ $1 -eq 1 ] || exit 0
|
[ $1 -eq 1 ] || exit 0
|
||||||
|
|
||||||
# create /var/log/journal only on initial installation,
|
# create /var/log/journal only on initial installation,
|
||||||
|
|
@ -1288,8 +1218,6 @@ if [ $1 -ge 2 ]; then
|
||||||
systemctl daemon-reexec || :
|
systemctl daemon-reexec || :
|
||||||
|
|
||||||
systemd-tmpfiles --create &>/dev/null || :
|
systemd-tmpfiles --create &>/dev/null || :
|
||||||
|
|
||||||
rm -f %{_localstatedir}/lib/rpm-state/systemd-getty-was-active || :
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
%systemd_posttrans_with_restart systemd-timedated.service systemd-hostnamed.service systemd-journald.service systemd-localed.service systemd-userdbd.service
|
%systemd_posttrans_with_restart systemd-timedated.service systemd-hostnamed.service systemd-journald.service systemd-localed.service systemd-userdbd.service
|
||||||
|
|
@ -1307,15 +1235,16 @@ fi
|
||||||
# This is for upgrades from previous versions before systemd restart was moved to %%postun
|
# This is for upgrades from previous versions before systemd restart was moved to %%postun
|
||||||
systemctl daemon-reexec || :
|
systemctl daemon-reexec || :
|
||||||
|
|
||||||
%triggerpostun -- systemd < 260~rc1
|
%triggerpostun -- systemd < 253~rc1-2
|
||||||
if [ -f %{_localstatedir}/lib/rpm-state/systemd-getty-was-active ]; then
|
# This is for upgrades from previous versions where systemd-journald-audit.socket
|
||||||
systemctl --no-reload enable getty@.service || :
|
# had a static enablement symlink.
|
||||||
fi
|
# We use %%triggerpostun here because rpm doesn't allow a second %%triggerun with
|
||||||
|
# a different package version.
|
||||||
|
systemctl --no-reload preset systemd-journald-audit.socket &>/dev/null || :
|
||||||
|
|
||||||
%global udev_services %{shrink:
|
%global udev_services %{shrink:
|
||||||
cryptsetup-pre.target
|
cryptsetup-pre.target
|
||||||
cryptsetup.target
|
cryptsetup.target
|
||||||
getty@.service
|
|
||||||
hibernate.target
|
hibernate.target
|
||||||
hybrid-sleep.target
|
hybrid-sleep.target
|
||||||
initrd-cleanup.service
|
initrd-cleanup.service
|
||||||
|
|
@ -1378,7 +1307,6 @@ fi
|
||||||
systemd-pcrlock.socket
|
systemd-pcrlock.socket
|
||||||
systemd-pcrlock@.service
|
systemd-pcrlock@.service
|
||||||
systemd-pcrmachine.service
|
systemd-pcrmachine.service
|
||||||
systemd-pcrosseparator.service
|
|
||||||
systemd-pcrphase-initrd.service
|
systemd-pcrphase-initrd.service
|
||||||
systemd-pcrphase-sysinit.service
|
systemd-pcrphase-sysinit.service
|
||||||
systemd-pcrphase.service
|
systemd-pcrphase.service
|
||||||
|
|
@ -1395,7 +1323,7 @@ fi
|
||||||
systemd-suspend.service
|
systemd-suspend.service
|
||||||
systemd-sysctl.service
|
systemd-sysctl.service
|
||||||
systemd-timesyncd.service
|
systemd-timesyncd.service
|
||||||
systemd-tmpfiles-clean.service
|
systemd-tmpfiles-clear.service
|
||||||
systemd-tmpfiles-setup-dev-early.service
|
systemd-tmpfiles-setup-dev-early.service
|
||||||
systemd-tmpfiles-setup-dev.service
|
systemd-tmpfiles-setup-dev.service
|
||||||
systemd-udev-load-credentials.service
|
systemd-udev-load-credentials.service
|
||||||
|
|
@ -1417,6 +1345,18 @@ fi
|
||||||
}
|
}
|
||||||
|
|
||||||
%post udev
|
%post udev
|
||||||
|
# Move old stuff around in /var/lib
|
||||||
|
mv %{_localstatedir}/lib/random-seed %{_localstatedir}/lib/systemd/random-seed &>/dev/null
|
||||||
|
mv %{_localstatedir}/lib/backlight %{_localstatedir}/lib/systemd/backlight &>/dev/null
|
||||||
|
if [ -L %{_localstatedir}/lib/systemd/timesync ]; then
|
||||||
|
rm %{_localstatedir}/lib/systemd/timesync
|
||||||
|
mv %{_localstatedir}/lib/private/systemd/timesync %{_localstatedir}/lib/systemd/timesync
|
||||||
|
fi
|
||||||
|
if [ -f %{_localstatedir}/lib/systemd/clock ]; then
|
||||||
|
mkdir -p %{_localstatedir}/lib/systemd/timesync
|
||||||
|
mv %{_localstatedir}/lib/systemd/clock %{_localstatedir}/lib/systemd/timesync/.
|
||||||
|
fi
|
||||||
|
|
||||||
systemd-hwdb update &>/dev/null
|
systemd-hwdb update &>/dev/null
|
||||||
|
|
||||||
%systemd_post %udev_services
|
%systemd_post %udev_services
|
||||||
|
|
@ -1425,6 +1365,11 @@ systemd-hwdb update &>/dev/null
|
||||||
/usr/lib/systemd/systemd-random-seed save 2>&1 | \
|
/usr/lib/systemd/systemd-random-seed save 2>&1 | \
|
||||||
grep -v 'Failed to open /dev/urandom' || :
|
grep -v 'Failed to open /dev/urandom' || :
|
||||||
|
|
||||||
|
# Replace obsolete keymaps
|
||||||
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1151958
|
||||||
|
grep -q -E '^KEYMAP="?fi-latin[19]"?' /etc/vconsole.conf 2>/dev/null &&
|
||||||
|
sed -i.rpm.bak -r 's/^KEYMAP="?fi-latin[19]"?/KEYMAP="fi"/' /etc/vconsole.conf || :
|
||||||
|
|
||||||
%preun udev
|
%preun udev
|
||||||
%systemd_preun %udev_services
|
%systemd_preun %udev_services
|
||||||
|
|
||||||
|
|
@ -1463,7 +1408,20 @@ fi
|
||||||
}
|
}
|
||||||
|
|
||||||
%post networkd
|
%post networkd
|
||||||
%systemd_post %networkd_services
|
# systemd-networkd was split out in systemd-246.6-2.
|
||||||
|
# Ideally, we would have a trigger scriptlet to record enablement
|
||||||
|
# state when upgrading from systemd <= systemd-246.6-1. But, AFAICS,
|
||||||
|
# rpm doesn't allow us to trigger on another package, short of
|
||||||
|
# querying the rpm database ourselves, which seems risky. For rpm,
|
||||||
|
# systemd and systemd-networkd are completely unrelated. So let's use
|
||||||
|
# a hack to detect if an old systemd version is currently present in
|
||||||
|
# the file system.
|
||||||
|
# https://bugzilla.redhat.com/show_bug.cgi?id=1943263
|
||||||
|
if [ $1 -eq 1 ] && ls /usr/lib/systemd/libsystemd-shared-24[0-6].so &>/dev/null; then
|
||||||
|
echo "Skipping presets for systemd-networkd.service, seems we are upgrading from old systemd."
|
||||||
|
else
|
||||||
|
%systemd_post %networkd_services
|
||||||
|
fi
|
||||||
|
|
||||||
%preun networkd
|
%preun networkd
|
||||||
%systemd_preun %networkd_services
|
%systemd_preun %networkd_services
|
||||||
|
|
@ -1536,10 +1494,10 @@ fi
|
||||||
%global _docdir_fmt %{name}
|
%global _docdir_fmt %{name}
|
||||||
|
|
||||||
%files -f %{name}.lang -f .file-list-main
|
%files -f %{name}.lang -f .file-list-main
|
||||||
|
%doc %{_pkgdocdir}
|
||||||
%exclude %{_pkgdocdir}/LICENSE*
|
%exclude %{_pkgdocdir}/LICENSE*
|
||||||
# Only the licenses texts for the licenses in License line are included.
|
# Only the licenses texts for the licenses in License line are included.
|
||||||
%license LICENSE.GPL2
|
%license LICENSE.GPL2
|
||||||
%license LICENSE.LGPL2.1
|
|
||||||
%license LICENSES/MIT.txt
|
%license LICENSES/MIT.txt
|
||||||
%ghost %dir %attr(0755,-,-) /etc/systemd/system/basic.target.wants
|
%ghost %dir %attr(0755,-,-) /etc/systemd/system/basic.target.wants
|
||||||
%ghost %dir %attr(0755,-,-) /etc/systemd/system/bluetooth.target.wants
|
%ghost %dir %attr(0755,-,-) /etc/systemd/system/bluetooth.target.wants
|
||||||
|
|
@ -1602,10 +1560,6 @@ fi
|
||||||
|
|
||||||
%files standalone-repart -f .file-list-standalone-repart
|
%files standalone-repart -f .file-list-standalone-repart
|
||||||
|
|
||||||
%if %{with report_standalone}
|
|
||||||
%files standalone-report -f .file-list-standalone-report
|
|
||||||
%endif
|
|
||||||
|
|
||||||
%files standalone-tmpfiles -f .file-list-standalone-tmpfiles
|
%files standalone-tmpfiles -f .file-list-standalone-tmpfiles
|
||||||
|
|
||||||
%files standalone-sysusers -f .file-list-standalone-sysusers
|
%files standalone-sysusers -f .file-list-standalone-sysusers
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue