mirror of
https://github.com/flatcar/scripts.git
synced 2025-08-17 18:06:59 +02:00
sys-apps/systemd: Sync with gentoo
It's from gentoo commit 909ff1217e19ce803fefbd16a67869426232f432.
This commit is contained in:
parent
fdc395e8de
commit
4ff26d05db
@ -1 +1 @@
|
|||||||
DIST systemd-stable-249.7.tar.gz 10608252 BLAKE2B a5597c4973b24c962779622cae47dbf8351af49f8cd898d9c16a967c6f3600c6feb293e9b03eab0423b860eef5b04b287185fb9827cb323429d0ab9fc6d809b2 SHA512 4daf8570621fdcda5c94d982908c64eddfeef989005f4fd79a10f199dbc6f366354177bb59dff34bcb14764fb4423a870ffabac1163849ec53592e29760105fc
|
DIST systemd-stable-250.3.tar.gz 11125151 BLAKE2B 659c39994e76f94407dd9079e28fc644981d3475a0ed440b9895e8f201c3ce1fc47aa8c4d599ad85ed89ddfb6ca8e514aee2a739e93640745cf46647f99efe56 SHA512 81847fb088ff271138b1ea318995a2ca2ee5d4c5d839c9dd81f0210d366198049199d59c49b25ef8783df2c6b8dd9fcdf2d916777788b1a6d42deec9da8e9da5
|
||||||
|
@ -0,0 +1,6 @@
|
|||||||
|
[Service]
|
||||||
|
# By running with these options instead of root, networkd is allowed to request
|
||||||
|
# a hostname change via DBUS when policykit is not present
|
||||||
|
User=systemd-network
|
||||||
|
Group=systemd-hostname
|
||||||
|
AmbientCapabilities=CAP_SYS_ADMIN
|
@ -1,32 +0,0 @@
|
|||||||
From eb00b0bf1014fd9da26fc1ed2612c579cbcf09ce Mon Sep 17 00:00:00 2001
|
|
||||||
From: David Michael <dm0@redhat.com>
|
|
||||||
Date: Tue, 16 Apr 2019 02:44:51 +0000
|
|
||||||
Subject: [PATCH 1/5] wait-online: set --any by default
|
|
||||||
|
|
||||||
The systemd-networkd-wait-online command would normally continue
|
|
||||||
waiting after a network interface is usable if other interfaces are
|
|
||||||
still configuring. There is a new flag --any to change this.
|
|
||||||
|
|
||||||
Preserve previous Container Linux behavior for compatibility by
|
|
||||||
setting the --any flag by default. See patches from v241 (or
|
|
||||||
earlier) for the original implementation.
|
|
||||||
---
|
|
||||||
src/network/wait-online/wait-online.c | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/network/wait-online/wait-online.c b/src/network/wait-online/wait-online.c
|
|
||||||
index 1b24b6f1a6..dedbd50725 100644
|
|
||||||
--- a/src/network/wait-online/wait-online.c
|
|
||||||
+++ b/src/network/wait-online/wait-online.c
|
|
||||||
@@ -20,7 +20,7 @@ static Hashmap *arg_interfaces = NULL;
|
|
||||||
static char **arg_ignore = NULL;
|
|
||||||
static LinkOperationalStateRange arg_required_operstate = { _LINK_OPERSTATE_INVALID, _LINK_OPERSTATE_INVALID };
|
|
||||||
static AddressFamily arg_required_family = ADDRESS_FAMILY_NO;
|
|
||||||
-static bool arg_any = false;
|
|
||||||
+static bool arg_any = true;
|
|
||||||
|
|
||||||
STATIC_DESTRUCTOR_REGISTER(arg_interfaces, hashmap_free_free_freep);
|
|
||||||
STATIC_DESTRUCTOR_REGISTER(arg_ignore, strv_freep);
|
|
||||||
--
|
|
||||||
2.30.2
|
|
||||||
|
|
@ -1,24 +0,0 @@
|
|||||||
From 9acb14187bacd1d716adaed491813ea1cde12237 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Nick Owens <nick.owens@coreos.com>
|
|
||||||
Date: Tue, 2 Jun 2015 18:22:32 -0700
|
|
||||||
Subject: [PATCH 2/5] networkd: default to "kernel" IPForwarding setting
|
|
||||||
|
|
||||||
---
|
|
||||||
src/network/networkd-network.c | 1 +
|
|
||||||
1 file changed, 1 insertion(+)
|
|
||||||
|
|
||||||
diff --git a/src/network/networkd-network.c b/src/network/networkd-network.c
|
|
||||||
index 850b4f449e..951c2d0815 100644
|
|
||||||
--- a/src/network/networkd-network.c
|
|
||||||
+++ b/src/network/networkd-network.c
|
|
||||||
@@ -398,6 +398,7 @@ int network_load_one(Manager *manager, OrderedHashmap **networks, const char *fi
|
|
||||||
.ipv6ll_address_gen_mode = _IPV6_LINK_LOCAL_ADDRESS_GEN_MODE_INVALID,
|
|
||||||
|
|
||||||
.ipv4_accept_local = -1,
|
|
||||||
+ .ip_forward = _ADDRESS_FAMILY_INVALID,
|
|
||||||
.ipv4_route_localnet = -1,
|
|
||||||
.ipv6_privacy_extensions = IPV6_PRIVACY_EXTENSIONS_NO,
|
|
||||||
.ipv6_accept_ra = -1,
|
|
||||||
--
|
|
||||||
2.30.2
|
|
||||||
|
|
@ -1,58 +0,0 @@
|
|||||||
From e073ce40241db173d160d5d9986129820a98270a Mon Sep 17 00:00:00 2001
|
|
||||||
From: Alex Crawford <alex.crawford@coreos.com>
|
|
||||||
Date: Wed, 2 Mar 2016 10:46:33 -0800
|
|
||||||
Subject: [PATCH 3/5] needs-update: don't require strictly newer usr
|
|
||||||
|
|
||||||
Updates should be triggered whenever usr changes, not only when it is newer.
|
|
||||||
---
|
|
||||||
man/systemd-update-done.service.xml | 2 +-
|
|
||||||
src/shared/condition.c | 6 +++---
|
|
||||||
2 files changed, 4 insertions(+), 4 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/man/systemd-update-done.service.xml b/man/systemd-update-done.service.xml
|
|
||||||
index 3393010ff6..5478baca25 100644
|
|
||||||
--- a/man/systemd-update-done.service.xml
|
|
||||||
+++ b/man/systemd-update-done.service.xml
|
|
||||||
@@ -50,7 +50,7 @@
|
|
||||||
<varname>ConditionNeedsUpdate=</varname> (see
|
|
||||||
<citerefentry><refentrytitle>systemd.unit</refentrytitle><manvolnum>5</manvolnum></citerefentry>)
|
|
||||||
condition to make sure to run when <filename>/etc/</filename> or
|
|
||||||
- <filename>/var/</filename> are older than <filename>/usr/</filename>
|
|
||||||
+ <filename>/var/</filename> aren't the same age as <filename>/usr/</filename>
|
|
||||||
according to the modification times of the files described above.
|
|
||||||
This requires that updates to <filename>/usr/</filename> are always
|
|
||||||
followed by an update of the modification time of
|
|
||||||
diff --git a/src/shared/condition.c b/src/shared/condition.c
|
|
||||||
index b2ec690bc3..4cf6523b90 100644
|
|
||||||
--- a/src/shared/condition.c
|
|
||||||
+++ b/src/shared/condition.c
|
|
||||||
@@ -593,7 +593,7 @@ static int condition_test_needs_update(Condition *c, char **env) {
|
|
||||||
* First, compare seconds as they are always accurate...
|
|
||||||
*/
|
|
||||||
if (usr.st_mtim.tv_sec != other.st_mtim.tv_sec)
|
|
||||||
- return usr.st_mtim.tv_sec > other.st_mtim.tv_sec;
|
|
||||||
+ return true;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* ...then compare nanoseconds.
|
|
||||||
@@ -604,7 +604,7 @@ static int condition_test_needs_update(Condition *c, char **env) {
|
|
||||||
* (otherwise the filesystem supports nsec timestamps, see stat(2)).
|
|
||||||
*/
|
|
||||||
if (usr.st_mtim.tv_nsec == 0 || other.st_mtim.tv_nsec > 0)
|
|
||||||
- return usr.st_mtim.tv_nsec > other.st_mtim.tv_nsec;
|
|
||||||
+ return usr.st_mtim.tv_nsec != other.st_mtim.tv_nsec;
|
|
||||||
|
|
||||||
_cleanup_free_ char *timestamp_str = NULL;
|
|
||||||
r = parse_env_file(NULL, p, "TIMESTAMP_NSEC", ×tamp_str);
|
|
||||||
@@ -623,7 +623,7 @@ static int condition_test_needs_update(Condition *c, char **env) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
- return timespec_load_nsec(&usr.st_mtim) > timestamp;
|
|
||||||
+ return timespec_load_nsec(&usr.st_mtim) != timestamp;
|
|
||||||
}
|
|
||||||
|
|
||||||
static int condition_test_first_boot(Condition *c, char **env) {
|
|
||||||
--
|
|
||||||
2.26.2
|
|
||||||
|
|
@ -1,65 +0,0 @@
|
|||||||
From 3acaafc6fcd34b272e5249c49e498ff7facb564e Mon Sep 17 00:00:00 2001
|
|
||||||
From: Sayan Chowdhury <sayan@kinvolk.io>
|
|
||||||
Date: Thu, 22 Apr 2021 20:08:33 +0530
|
|
||||||
Subject: [PATCH] core: use max for DefaultTasksMax
|
|
||||||
|
|
||||||
Since systemd v228, systemd has a DefaultTasksMax which defaulted
|
|
||||||
to 512, later 15% of the system's maximum number of PIDs. This
|
|
||||||
limit is low and a change in behavior that people running services
|
|
||||||
in containers will hit frequently, so revert to previous behavior.
|
|
||||||
|
|
||||||
Though later the TasksMax was changed in the a dynamic property to
|
|
||||||
accommodate stale values.
|
|
||||||
|
|
||||||
This change is built on previous patch by David Michael(dm0-).
|
|
||||||
|
|
||||||
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
|
|
||||||
---
|
|
||||||
man/systemd-system.conf.xml | 2 +-
|
|
||||||
src/core/main.c | 2 +-
|
|
||||||
src/core/system.conf.in | 2 +-
|
|
||||||
3 files changed, 3 insertions(+), 3 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/man/systemd-system.conf.xml b/man/systemd-system.conf.xml
|
|
||||||
index d39928ec23..4d89a68b16 100644
|
|
||||||
--- a/man/systemd-system.conf.xml
|
|
||||||
+++ b/man/systemd-system.conf.xml
|
|
||||||
@@ -376,7 +376,7 @@
|
|
||||||
<listitem><para>Configure the default value for the per-unit <varname>TasksMax=</varname> setting. See
|
|
||||||
<citerefentry><refentrytitle>systemd.resource-control</refentrytitle><manvolnum>5</manvolnum></citerefentry>
|
|
||||||
for details. This setting applies to all unit types that support resource control settings, with the exception
|
|
||||||
- of slice units. Defaults to 15% of the minimum of <varname>kernel.pid_max=</varname>, <varname>kernel.threads-max=</varname>
|
|
||||||
+ of slice units. Defaults to 100% of the minimum of <varname>kernel.pid_max=</varname>, <varname>kernel.threads-max=</varname>
|
|
||||||
and root cgroup <varname>pids.max</varname>.
|
|
||||||
Kernel has a default value for <varname>kernel.pid_max=</varname> and an algorithm of counting in case of more than 32 cores.
|
|
||||||
For example with the default <varname>kernel.pid_max=</varname>, <varname>DefaultTasksMax=</varname> defaults to 4915,
|
|
||||||
diff --git a/src/core/main.c b/src/core/main.c
|
|
||||||
index 0ddd629851..5e25a1b4b7 100644
|
|
||||||
--- a/src/core/main.c
|
|
||||||
+++ b/src/core/main.c
|
|
||||||
@@ -91,7 +91,7 @@
|
|
||||||
#include <sanitizer/lsan_interface.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
-#define DEFAULT_TASKS_MAX ((TasksMax) { 15U, 100U }) /* 15% */
|
|
||||||
+#define DEFAULT_TASKS_MAX ((TasksMax) { 100U, 100U }) /* 100% */
|
|
||||||
|
|
||||||
static enum {
|
|
||||||
ACTION_RUN,
|
|
||||||
diff --git a/src/core/system.conf.in b/src/core/system.conf.in
|
|
||||||
index fa6fb690c7..1e6df17d94 100644
|
|
||||||
--- a/src/core/system.conf.in
|
|
||||||
+++ b/src/core/system.conf.in
|
|
||||||
@@ -55,7 +55,7 @@
|
|
||||||
#DefaultBlockIOAccounting=no
|
|
||||||
#DefaultMemoryAccounting=@MEMORY_ACCOUNTING_DEFAULT@
|
|
||||||
#DefaultTasksAccounting=yes
|
|
||||||
-#DefaultTasksMax=15%
|
|
||||||
+#DefaultTasksMax=100%
|
|
||||||
#DefaultLimitCPU=
|
|
||||||
#DefaultLimitFSIZE=
|
|
||||||
#DefaultLimitDATA=
|
|
||||||
--
|
|
||||||
2.30.2
|
|
||||||
|
|
||||||
|
|
@ -1,29 +0,0 @@
|
|||||||
From f83a1a190139d6f7752e0d7c86396330f845b261 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Matthew Garrett <mjg59@coreos.com>
|
|
||||||
Date: Tue, 20 Dec 2016 16:43:22 +0000
|
|
||||||
Subject: [PATCH 5/5] systemd: Disable SELinux permissions checks
|
|
||||||
|
|
||||||
We don't care about the interaction between systemd and SELinux policy, so
|
|
||||||
let's just disable these checks rather than having to incorporate policy
|
|
||||||
support. This has no impact on our SELinux use-case, which is purely intended
|
|
||||||
to limit containers and not anything running directly on the host.
|
|
||||||
---
|
|
||||||
src/core/selinux-access.c | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/core/selinux-access.c b/src/core/selinux-access.c
|
|
||||||
index 1d52b5ff04..1653d241f6 100644
|
|
||||||
--- a/src/core/selinux-access.c
|
|
||||||
+++ b/src/core/selinux-access.c
|
|
||||||
@@ -2,7 +2,7 @@
|
|
||||||
|
|
||||||
#include "selinux-access.h"
|
|
||||||
|
|
||||||
-#if HAVE_SELINUX
|
|
||||||
+#if 0
|
|
||||||
|
|
||||||
#include <errno.h>
|
|
||||||
#include <selinux/avc.h>
|
|
||||||
--
|
|
||||||
2.26.2
|
|
||||||
|
|
@ -1,84 +0,0 @@
|
|||||||
From 67d9962aa637401a1332069b6c8ad99a54e2b451 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Sayan Chowdhury <sayan@kinvolk.io>
|
|
||||||
Date: Wed, 8 Sep 2021 12:10:35 +0530
|
|
||||||
Subject: [PATCH] core: handle lookup paths being symlinks
|
|
||||||
|
|
||||||
With a recent change paths leaving the statically known lookup paths
|
|
||||||
would be treated differently then those that remained within those. That
|
|
||||||
was done (AFAIK) to consistently handle alias names. Unfortunately that
|
|
||||||
means that on some distributions, especially those where /etc/ consists
|
|
||||||
mostly of symlinks, would trigger that new detection for every single
|
|
||||||
unit in /etc/systemd/system. The reason for that is that the units
|
|
||||||
directory itself is already a symlink.
|
|
||||||
|
|
||||||
Original Patch from: https://github.com/systemd/systemd/pull/20479
|
|
||||||
|
|
||||||
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
|
|
||||||
---
|
|
||||||
src/basic/unit-file.c | 33 +++++++++++++++++++++++++++++++--
|
|
||||||
1 file changed, 31 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/src/basic/unit-file.c b/src/basic/unit-file.c
|
|
||||||
index 884a0674a9..3ae2a115d0 100644
|
|
||||||
--- a/src/basic/unit-file.c
|
|
||||||
+++ b/src/basic/unit-file.c
|
|
||||||
@@ -254,6 +254,7 @@ int unit_file_build_name_map(
|
|
||||||
|
|
||||||
_cleanup_hashmap_free_ Hashmap *ids = NULL, *names = NULL;
|
|
||||||
_cleanup_set_free_free_ Set *paths = NULL;
|
|
||||||
+ _cleanup_strv_free_ char **expanded_search_paths = NULL;
|
|
||||||
uint64_t timestamp_hash;
|
|
||||||
char **dir;
|
|
||||||
int r;
|
|
||||||
@@ -273,6 +274,34 @@ int unit_file_build_name_map(
|
|
||||||
return log_oom();
|
|
||||||
}
|
|
||||||
|
|
||||||
+ /* Go over all our search paths, chase their symlinks and store the
|
|
||||||
+ * result in the expanded_search_paths list.
|
|
||||||
+ *
|
|
||||||
+ * This is important for cases where any of the unit directories itself
|
|
||||||
+ * are symlinks into other directories and would therefore cause all of
|
|
||||||
+ * the unit files to be recognized as linked units.
|
|
||||||
+ *
|
|
||||||
+ * This is important for distributions such as NixOS where most paths
|
|
||||||
+ * in /etc/ are symlinks to some other location on the filesystem (e.g.
|
|
||||||
+ * into /nix/store/).
|
|
||||||
+ */
|
|
||||||
+ STRV_FOREACH(dir, (char**) lp->search_path) {
|
|
||||||
+ _cleanup_free_ char *resolved_dir = NULL;
|
|
||||||
+ r = strv_extend(&expanded_search_paths, *dir);
|
|
||||||
+ if (r < 0)
|
|
||||||
+ return log_oom();
|
|
||||||
+
|
|
||||||
+ r = chase_symlinks(*dir, NULL, 0, &resolved_dir, NULL);
|
|
||||||
+ if (r < 0) {
|
|
||||||
+ if (r != -ENOENT)
|
|
||||||
+ log_warning_errno(r, "Failed to resolve symlink %s, ignoring: %m", *dir);
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ if (strv_consume(&expanded_search_paths, TAKE_PTR(resolved_dir)) < 0)
|
|
||||||
+ return log_oom();
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
STRV_FOREACH(dir, (char**) lp->search_path) {
|
|
||||||
struct dirent *de;
|
|
||||||
_cleanup_closedir_ DIR *d = NULL;
|
|
||||||
@@ -351,11 +380,11 @@ int unit_file_build_name_map(
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
- /* Check if the symlink goes outside of our search path.
|
|
||||||
+ /* Check if the symlink goes outside of our (expanded) search path.
|
|
||||||
* If yes, it's a linked unit file or mask, and we don't care about the target name.
|
|
||||||
* Let's just store the link source directly.
|
|
||||||
* If not, let's verify that it's a good symlink. */
|
|
||||||
- char *tail = path_startswith_strv(simplified, lp->search_path);
|
|
||||||
+ char *tail = path_startswith_strv(simplified, expanded_search_paths);
|
|
||||||
if (!tail) {
|
|
||||||
log_debug("%s: linked unit file: %s → %s",
|
|
||||||
__func__, filename, simplified);
|
|
||||||
--
|
|
||||||
2.30.2
|
|
||||||
|
|
@ -1,26 +0,0 @@
|
|||||||
From f2c57d4f3805775e0ffdc80ce578eaa737017d31 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mike Gilbert <floppym@gentoo.org>
|
|
||||||
Date: Fri, 9 Jul 2021 13:05:23 -0400
|
|
||||||
Subject: [PATCH] libudev: add "Libs.private: -lrt -pthread" to libudev.pc
|
|
||||||
|
|
||||||
This resolves a failure when linking cryptsetup.static against libudev.a.
|
|
||||||
|
|
||||||
```
|
|
||||||
libtool: link: x86_64-pc-linux-gnu-gcc -Wall -O2 -pipe -march=amdfam10 -static -O2 -o cryptsetup.static lib/utils_crypt.o lib/utils_loop.o lib/utils_io.o lib/utils_blkid.o src/utils_tools.o src/utils_password.o src/utils_luks2.o src/utils_blockdev.o src/cryptsetup.o -pthread -pthread -Wl,--as-needed ./.libs/libcryptsetup.a -largon2 -lrt -ljson-c -lpopt -luuid -lblkid -lssl -lcrypto -lz -ldl -ldevmapper -lm -lpthread -ludev -pthread
|
|
||||||
/usr/lib/gcc/x86_64-pc-linux-gnu/11.1.0/../../../../x86_64-pc-linux-gnu/bin/ld: /usr/lib/gcc/x86_64-pc-linux-gnu/11.1.0/../../../../lib64/libudev.a(src_libsystemd_sd-daemon_sd-daemon.c.o): in function `sd_is_mq':
|
|
||||||
(.text.sd_is_mq+0x3a): undefined reference to `mq_getattr'
|
|
||||||
```
|
|
||||||
---
|
|
||||||
src/libudev/libudev.pc.in | 1 +
|
|
||||||
1 file changed, 1 insertion(+)
|
|
||||||
|
|
||||||
diff --git a/src/libudev/libudev.pc.in b/src/libudev/libudev.pc.in
|
|
||||||
index 89028aaa6bf2..1d6487fa4084 100644
|
|
||||||
--- a/src/libudev/libudev.pc.in
|
|
||||||
+++ b/src/libudev/libudev.pc.in
|
|
||||||
@@ -16,4 +16,5 @@ Name: libudev
|
|
||||||
Description: Library to access udev device information
|
|
||||||
Version: {{PROJECT_VERSION}}
|
|
||||||
Libs: -L${libdir} -ludev
|
|
||||||
+Libs.private: -lrt -pthread
|
|
||||||
Cflags: -I${includedir}
|
|
@ -1,2 +0,0 @@
|
|||||||
# Do not enable any services if /etc is detected as empty.
|
|
||||||
disable *
|
|
@ -0,0 +1,26 @@
|
|||||||
|
From 91182cc273d2dd8325d856fd683d2d8e038abd91 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mike Gilbert <floppym@gentoo.org>
|
||||||
|
Date: Tue, 25 Dec 2018 22:52:50 -0500
|
||||||
|
Subject: [PATCH] path-lookup: look for generators in
|
||||||
|
/usr/lib/systemd/system-generators
|
||||||
|
|
||||||
|
Bug: https://bugs.gentoo.org/625402
|
||||||
|
---
|
||||||
|
src/basic/path-lookup.c | 1 +
|
||||||
|
1 file changed, 1 insertion(+)
|
||||||
|
|
||||||
|
diff --git a/src/basic/path-lookup.c b/src/basic/path-lookup.c
|
||||||
|
index 52968dee34..0cb10b1116 100644
|
||||||
|
--- a/src/basic/path-lookup.c
|
||||||
|
+++ b/src/basic/path-lookup.c
|
||||||
|
@@ -798,6 +798,7 @@ char **generator_binary_paths(UnitFileScope scope) {
|
||||||
|
add = strv_new("/run/systemd/system-generators",
|
||||||
|
"/etc/systemd/system-generators",
|
||||||
|
"/usr/local/lib/systemd/system-generators",
|
||||||
|
+ "/usr/lib/systemd/system-generators",
|
||||||
|
SYSTEM_GENERATOR_DIR);
|
||||||
|
break;
|
||||||
|
|
||||||
|
--
|
||||||
|
2.26.1
|
||||||
|
|
40
sdk_container/src/third_party/coreos-overlay/sys-apps/systemd/files/gentoo-journald-audit.patch
vendored
Normal file
40
sdk_container/src/third_party/coreos-overlay/sys-apps/systemd/files/gentoo-journald-audit.patch
vendored
Normal file
@ -0,0 +1,40 @@
|
|||||||
|
From 593db1c78011ddce551051ce17eda6feac079b3d Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mike Gilbert <floppym@gentoo.org>
|
||||||
|
Date: Fri, 21 Aug 2020 13:16:17 -0400
|
||||||
|
Subject: [PATCH] journald: do not change the kernel audit setting by default
|
||||||
|
|
||||||
|
Bug: https://bugs.gentoo.org/736910
|
||||||
|
---
|
||||||
|
man/journald.conf.xml | 2 +-
|
||||||
|
src/journal/journald-server.c | 2 +-
|
||||||
|
2 files changed, 2 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/man/journald.conf.xml b/man/journald.conf.xml
|
||||||
|
index bfd359a903..7e93d4050e 100644
|
||||||
|
--- a/man/journald.conf.xml
|
||||||
|
+++ b/man/journald.conf.xml
|
||||||
|
@@ -411,7 +411,7 @@
|
||||||
|
<command>systemd-journald</command> collects generated audit records, it just controls whether it
|
||||||
|
tells the kernel to generate them. This means if another tool turns on auditing even if
|
||||||
|
<command>systemd-journald</command> left it off, it will still collect the generated
|
||||||
|
- messages. Defaults to on.</para></listitem>
|
||||||
|
+ messages.</para></listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
diff --git a/src/journal/journald-server.c b/src/journal/journald-server.c
|
||||||
|
index 5865bf9809..163be685a8 100644
|
||||||
|
--- a/src/journal/journald-server.c
|
||||||
|
+++ b/src/journal/journald-server.c
|
||||||
|
@@ -2208,7 +2208,7 @@ int server_init(Server *s, const char *namespace) {
|
||||||
|
.compress.threshold_bytes = (uint64_t) -1,
|
||||||
|
.seal = true,
|
||||||
|
|
||||||
|
- .set_audit = true,
|
||||||
|
+ .set_audit = -1,
|
||||||
|
|
||||||
|
.watchdog_usec = USEC_INFINITY,
|
||||||
|
|
||||||
|
--
|
||||||
|
2.28.0
|
||||||
|
|
@ -0,0 +1,25 @@
|
|||||||
|
From d9059d2ef1b0d6034267cc8ff44871d0f82f840f Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mike Gilbert <floppym@gentoo.org>
|
||||||
|
Date: Sun, 8 Nov 2020 12:34:11 -0500
|
||||||
|
Subject: [PATCH] systemctl: disable synchronizaion of sysv init scripts
|
||||||
|
|
||||||
|
---
|
||||||
|
src/systemctl/systemctl-sysv-compat.c | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/src/systemctl/systemctl-sysv-compat.c b/src/systemctl/systemctl-sysv-compat.c
|
||||||
|
index 2dca9e480f..5dcf13ba17 100644
|
||||||
|
--- a/src/systemctl/systemctl-sysv-compat.c
|
||||||
|
+++ b/src/systemctl/systemctl-sysv-compat.c
|
||||||
|
@@ -111,7 +111,7 @@ int parse_shutdown_time_spec(const char *t, usec_t *ret) {
|
||||||
|
int enable_sysv_units(const char *verb, char **args) {
|
||||||
|
int r = 0;
|
||||||
|
|
||||||
|
-#if HAVE_SYSV_COMPAT
|
||||||
|
+#if 0
|
||||||
|
_cleanup_(lookup_paths_free) LookupPaths paths = {};
|
||||||
|
unsigned f = 0;
|
||||||
|
|
||||||
|
--
|
||||||
|
2.29.0
|
||||||
|
|
27
sdk_container/src/third_party/coreos-overlay/sys-apps/systemd/files/nsswitch.conf
vendored
Normal file
27
sdk_container/src/third_party/coreos-overlay/sys-apps/systemd/files/nsswitch.conf
vendored
Normal file
@ -0,0 +1,27 @@
|
|||||||
|
# Sample nss configuration for systemd
|
||||||
|
|
||||||
|
# systemd-specific modules
|
||||||
|
# See the manual pages fore further information.
|
||||||
|
# nss-myhostname - host resolution for the local hostname
|
||||||
|
# nss-mymachines - host, user, group resolution for containers
|
||||||
|
# nss-resolve - host resolution using resolved
|
||||||
|
# nss-systemd - dynamic user/group resolution (DynamicUser in unit files)
|
||||||
|
|
||||||
|
passwd: files mymachines systemd
|
||||||
|
shadow: files
|
||||||
|
group: files mymachines systemd
|
||||||
|
gshadow: files
|
||||||
|
|
||||||
|
hosts: files mymachines resolve [!UNAVAIL=return] dns myhostname
|
||||||
|
networks: files
|
||||||
|
|
||||||
|
services: db files
|
||||||
|
protocols: db files
|
||||||
|
rpc: db files
|
||||||
|
ethers: db files
|
||||||
|
netmasks: files
|
||||||
|
netgroup: files
|
||||||
|
bootparams: files
|
||||||
|
|
||||||
|
automount: files
|
||||||
|
aliases: files
|
@ -0,0 +1,11 @@
|
|||||||
|
<?xml version="1.0"?> <!--*-nxml-*-->
|
||||||
|
<!DOCTYPE busconfig PUBLIC "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
|
||||||
|
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
|
||||||
|
|
||||||
|
<busconfig>
|
||||||
|
<policy group="systemd-hostname">
|
||||||
|
<allow own="org.freedesktop.hostname1"/>
|
||||||
|
<allow send_destination="org.freedesktop.hostname1"/>
|
||||||
|
<allow receive_sender="org.freedesktop.hostname1"/>
|
||||||
|
</policy>
|
||||||
|
</busconfig>
|
@ -1,14 +0,0 @@
|
|||||||
d /etc/binfmt.d - - - - -
|
|
||||||
d /etc/kernel/install.d - - - - -
|
|
||||||
d /etc/modules-load.d - - - - -
|
|
||||||
d /etc/sysctl.d - - - - -
|
|
||||||
d /etc/systemd - - - - -
|
|
||||||
d /etc/systemd/network - - - - -
|
|
||||||
d /etc/systemd/system - - - - -
|
|
||||||
d /etc/systemd/user - - - - -
|
|
||||||
d /etc/tmpfiles.d - - - - -
|
|
||||||
d /etc/sysusers.d - - - - -
|
|
||||||
d /etc/udev/hwdb.d - - - - -
|
|
||||||
d /etc/udev/rules.d - - - - -
|
|
||||||
d /var/lib/systemd - - - - -
|
|
||||||
d /var/log/journal/remote - systemd-journal-remote systemd-journal-remote - -
|
|
@ -1,2 +0,0 @@
|
|||||||
d /run/systemd/network - - - - -
|
|
||||||
L /run/systemd/network/resolv.conf - - - - ../resolve/resolv.conf
|
|
@ -1,5 +1,5 @@
|
|||||||
<?xml version="1.0" encoding="UTF-8"?>
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
|
<!DOCTYPE pkgmetadata SYSTEM "https://www.gentoo.org/dtd/metadata.dtd">
|
||||||
<pkgmetadata>
|
<pkgmetadata>
|
||||||
<maintainer type="project">
|
<maintainer type="project">
|
||||||
<email>systemd@gentoo.org</email>
|
<email>systemd@gentoo.org</email>
|
||||||
@ -17,14 +17,16 @@
|
|||||||
<flag name="dns-over-tls">Enable DNS-over-TLS support</flag>
|
<flag name="dns-over-tls">Enable DNS-over-TLS support</flag>
|
||||||
<flag name="gnuefi">Enable EFI boot manager and stub loader (built using <pkg>sys-boot/gnu-efi</pkg>)</flag>
|
<flag name="gnuefi">Enable EFI boot manager and stub loader (built using <pkg>sys-boot/gnu-efi</pkg>)</flag>
|
||||||
<flag name="elfutils">Enable coredump stacktraces in the journal</flag>
|
<flag name="elfutils">Enable coredump stacktraces in the journal</flag>
|
||||||
|
<flag name="fido2">Enable FIDO2 support</flag>
|
||||||
<flag name="gcrypt">Enable sealing of journal files using gcrypt</flag>
|
<flag name="gcrypt">Enable sealing of journal files using gcrypt</flag>
|
||||||
<flag name="homed">Enable portable home directories</flag>
|
<flag name="homed">Enable portable home directories</flag>
|
||||||
|
<flag name="hostnamed-fallback">Enable setting hostname with networkd/hostnamed without polkit (requires running <pkg>sys-apps/dbus-broker</pkg>)</flag>
|
||||||
<flag name="http">Enable embedded HTTP server in journald</flag>
|
<flag name="http">Enable embedded HTTP server in journald</flag>
|
||||||
<flag name="hwdb">Enable support for the hardware database</flag>
|
|
||||||
<flag name="importd">Enable import daemon</flag>
|
<flag name="importd">Enable import daemon</flag>
|
||||||
<flag name="kmod">Enable kernel module loading via <pkg>sys-apps/kmod</pkg></flag>
|
<flag name="kmod">Enable kernel module loading via <pkg>sys-apps/kmod</pkg></flag>
|
||||||
<flag name="lz4">Enable lz4 compression for the journal</flag>
|
<flag name="lz4">Enable lz4 compression for the journal</flag>
|
||||||
<flag name="nat">Enable support for network address translation in networkd</flag>
|
<flag name="nat">Enable support for network address translation in networkd</flag>
|
||||||
|
<flag name="openssl">Enable use of <pkg>dev-libs/openssl</pkg></flag>
|
||||||
<flag name="pkcs11">Enable PKCS#11 support for cryptsetup and homed</flag>
|
<flag name="pkcs11">Enable PKCS#11 support for cryptsetup and homed</flag>
|
||||||
<flag name="pwquality">Enable password quality checking in homed</flag>
|
<flag name="pwquality">Enable password quality checking in homed</flag>
|
||||||
<flag name="repart">Enable support for growing/adding partitions</flag>
|
<flag name="repart">Enable support for growing/adding partitions</flag>
|
||||||
|
@ -1 +0,0 @@
|
|||||||
systemd-9999.ebuild
|
|
@ -1,8 +1,11 @@
|
|||||||
# Copyright 2011-2021 Gentoo Authors
|
# Copyright 2011-2022 Gentoo Authors
|
||||||
# Distributed under the terms of the GNU General Public License v2
|
# Distributed under the terms of the GNU General Public License v2
|
||||||
|
|
||||||
EAPI=7
|
EAPI=7
|
||||||
PYTHON_COMPAT=( python3_{6..10} )
|
PYTHON_COMPAT=( python3_{8..10} )
|
||||||
|
|
||||||
|
# Avoid QA warnings
|
||||||
|
TMPFILES_OPTIONAL=1
|
||||||
|
|
||||||
if [[ ${PV} == 9999 ]]; then
|
if [[ ${PV} == 9999 ]]; then
|
||||||
EGIT_REPO_URI="https://github.com/systemd/systemd.git"
|
EGIT_REPO_URI="https://github.com/systemd/systemd.git"
|
||||||
@ -17,33 +20,35 @@ else
|
|||||||
MY_P=${MY_PN}-${MY_PV}
|
MY_P=${MY_PN}-${MY_PV}
|
||||||
S=${WORKDIR}/${MY_P}
|
S=${WORKDIR}/${MY_P}
|
||||||
SRC_URI="https://github.com/systemd/${MY_PN}/archive/v${MY_PV}/${MY_P}.tar.gz"
|
SRC_URI="https://github.com/systemd/${MY_PN}/archive/v${MY_PV}/${MY_P}.tar.gz"
|
||||||
KEYWORDS="~alpha amd64 arm arm64 ~hppa ~ia64 ~mips ppc ppc64 ~riscv sparc x86"
|
KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ia64 ~mips ~ppc ~ppc64 ~riscv ~sparc ~x86"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Flatcar: We don't use gen_usr_ldscript so dropping usr-ldscript
|
inherit bash-completion-r1 linux-info meson-multilib pam python-any-r1 systemd toolchain-funcs udev usr-ldscript
|
||||||
TMPFILES_OPTIONAL=1
|
|
||||||
inherit bash-completion-r1 linux-info meson-multilib pam python-any-r1 systemd toolchain-funcs udev user tmpfiles
|
|
||||||
|
|
||||||
DESCRIPTION="System and service manager for Linux"
|
DESCRIPTION="System and service manager for Linux"
|
||||||
HOMEPAGE="https://www.freedesktop.org/wiki/Software/systemd"
|
HOMEPAGE="https://www.freedesktop.org/wiki/Software/systemd"
|
||||||
|
|
||||||
LICENSE="GPL-2 LGPL-2.1 MIT public-domain"
|
LICENSE="GPL-2 LGPL-2.1 MIT public-domain"
|
||||||
SLOT="0/2"
|
SLOT="0/2"
|
||||||
# Flatcar: Dropped static-libs, we don't care about static libraries.
|
IUSE="
|
||||||
IUSE="acl apparmor audit build cgroup-hybrid cryptsetup curl dns-over-tls elfutils +gcrypt gnuefi homed http idn importd +kmod +lz4 lzma nat pam pcre pkcs11 policykit pwquality qrcode repart +resolvconf +seccomp selinux split-usr +sysv-utils test tpm vanilla xkb +zstd"
|
acl apparmor audit build cgroup-hybrid cryptsetup curl +dns-over-tls elfutils
|
||||||
|
fido2 +gcrypt gnuefi gnutls homed hostnamed-fallback http idn importd +kmod
|
||||||
|
+lz4 lzma nat +openssl pam pcre pkcs11 policykit pwquality qrcode
|
||||||
|
+resolvconf +seccomp selinux split-usr +sysv-utils test tpm vanilla xkb +zstd
|
||||||
|
"
|
||||||
REQUIRED_USE="
|
REQUIRED_USE="
|
||||||
homed? ( cryptsetup pam )
|
dns-over-tls? ( || ( gnutls openssl ) )
|
||||||
importd? ( curl gcrypt lzma )
|
homed? ( cryptsetup pam openssl )
|
||||||
|
importd? ( curl lzma || ( gcrypt openssl ) )
|
||||||
|
policykit? ( !hostnamed-fallback )
|
||||||
pwquality? ( homed )
|
pwquality? ( homed )
|
||||||
"
|
"
|
||||||
RESTRICT="!test? ( test )"
|
RESTRICT="!test? ( test )"
|
||||||
|
|
||||||
MINKV="3.11"
|
MINKV="3.11"
|
||||||
|
|
||||||
OPENSSL_DEP=">=dev-libs/openssl-1.1.0:0="
|
COMMON_DEPEND="
|
||||||
|
>=sys-apps/util-linux-2.30:0=[${MULTILIB_USEDEP}]
|
||||||
COMMON_DEPEND=">=sys-apps/util-linux-2.30:0=[${MULTILIB_USEDEP}]
|
|
||||||
sys-libs/libcap:0=[${MULTILIB_USEDEP}]
|
sys-libs/libcap:0=[${MULTILIB_USEDEP}]
|
||||||
virtual/libcrypt:=[${MULTILIB_USEDEP}]
|
virtual/libcrypt:=[${MULTILIB_USEDEP}]
|
||||||
acl? ( sys-apps/acl:0= )
|
acl? ( sys-apps/acl:0= )
|
||||||
@ -51,14 +56,11 @@ COMMON_DEPEND=">=sys-apps/util-linux-2.30:0=[${MULTILIB_USEDEP}]
|
|||||||
audit? ( >=sys-process/audit-2:0= )
|
audit? ( >=sys-process/audit-2:0= )
|
||||||
cryptsetup? ( >=sys-fs/cryptsetup-2.0.1:0= )
|
cryptsetup? ( >=sys-fs/cryptsetup-2.0.1:0= )
|
||||||
curl? ( net-misc/curl:0= )
|
curl? ( net-misc/curl:0= )
|
||||||
dns-over-tls? ( >=net-libs/gnutls-3.6.0:0= )
|
|
||||||
elfutils? ( >=dev-libs/elfutils-0.158:0= )
|
elfutils? ( >=dev-libs/elfutils-0.158:0= )
|
||||||
|
fido2? ( dev-libs/libfido2:0= )
|
||||||
gcrypt? ( >=dev-libs/libgcrypt-1.4.5:0=[${MULTILIB_USEDEP}] )
|
gcrypt? ( >=dev-libs/libgcrypt-1.4.5:0=[${MULTILIB_USEDEP}] )
|
||||||
homed? ( ${OPENSSL_DEP} )
|
gnutls? ( >=net-libs/gnutls-3.6.0:0= )
|
||||||
http? (
|
http? ( >=net-libs/libmicrohttpd-0.9.33:0=[epoll(+)] )
|
||||||
>=net-libs/libmicrohttpd-0.9.33:0=[epoll(+)]
|
|
||||||
>=net-libs/gnutls-3.1.4:0=
|
|
||||||
)
|
|
||||||
idn? ( net-dns/libidn2:= )
|
idn? ( net-dns/libidn2:= )
|
||||||
importd? (
|
importd? (
|
||||||
app-arch/bzip2:0=
|
app-arch/bzip2:0=
|
||||||
@ -68,12 +70,12 @@ COMMON_DEPEND=">=sys-apps/util-linux-2.30:0=[${MULTILIB_USEDEP}]
|
|||||||
lz4? ( >=app-arch/lz4-0_p131:0=[${MULTILIB_USEDEP}] )
|
lz4? ( >=app-arch/lz4-0_p131:0=[${MULTILIB_USEDEP}] )
|
||||||
lzma? ( >=app-arch/xz-utils-5.0.5-r1:0=[${MULTILIB_USEDEP}] )
|
lzma? ( >=app-arch/xz-utils-5.0.5-r1:0=[${MULTILIB_USEDEP}] )
|
||||||
nat? ( net-firewall/iptables:0= )
|
nat? ( net-firewall/iptables:0= )
|
||||||
|
openssl? ( >=dev-libs/openssl-1.1.0:0= )
|
||||||
pam? ( sys-libs/pam:=[${MULTILIB_USEDEP}] )
|
pam? ( sys-libs/pam:=[${MULTILIB_USEDEP}] )
|
||||||
pkcs11? ( app-crypt/p11-kit:0= )
|
pkcs11? ( app-crypt/p11-kit:0= )
|
||||||
pcre? ( dev-libs/libpcre2 )
|
pcre? ( dev-libs/libpcre2 )
|
||||||
pwquality? ( dev-libs/libpwquality:0= )
|
pwquality? ( dev-libs/libpwquality:0= )
|
||||||
qrcode? ( media-gfx/qrencode:0= )
|
qrcode? ( media-gfx/qrencode:0= )
|
||||||
repart? ( ${OPENSSL_DEP} )
|
|
||||||
seccomp? ( >=sys-libs/libseccomp-2.3.3:0= )
|
seccomp? ( >=sys-libs/libseccomp-2.3.3:0= )
|
||||||
selinux? ( sys-libs/libselinux:0= )
|
selinux? ( sys-libs/libselinux:0= )
|
||||||
tpm? ( app-crypt/tpm2-tss:0= )
|
tpm? ( app-crypt/tpm2-tss:0= )
|
||||||
@ -87,22 +89,39 @@ DEPEND="${COMMON_DEPEND}
|
|||||||
gnuefi? ( >=sys-boot/gnu-efi-3.0.2 )
|
gnuefi? ( >=sys-boot/gnu-efi-3.0.2 )
|
||||||
"
|
"
|
||||||
|
|
||||||
# Flatcar: We drop a few of the acct-group and acct-user as the gid provided by
|
# baselayout-2.2 has /run
|
||||||
# the upstream does not match with the ones we carry in baselayout.
|
|
||||||
RDEPEND="${COMMON_DEPEND}
|
RDEPEND="${COMMON_DEPEND}
|
||||||
>=acct-group/adm-0-r1
|
>=acct-group/adm-0-r1
|
||||||
>=acct-group/wheel-0-r1
|
>=acct-group/wheel-0-r1
|
||||||
>=acct-group/kmem-0-r1
|
>=acct-group/kmem-0-r1
|
||||||
>=acct-group/tty-0-r1
|
>=acct-group/tty-0-r1
|
||||||
>=acct-group/utmp-0-r1
|
>=acct-group/utmp-0-r1
|
||||||
|
>=acct-group/audio-0-r1
|
||||||
|
>=acct-group/cdrom-0-r1
|
||||||
|
>=acct-group/dialout-0-r1
|
||||||
|
>=acct-group/disk-0-r1
|
||||||
|
>=acct-group/input-0-r1
|
||||||
>=acct-group/kvm-0-r1
|
>=acct-group/kvm-0-r1
|
||||||
|
>=acct-group/lp-0-r1
|
||||||
|
>=acct-group/render-0-r1
|
||||||
acct-group/sgx
|
acct-group/sgx
|
||||||
|
>=acct-group/tape-0-r1
|
||||||
acct-group/users
|
acct-group/users
|
||||||
|
>=acct-group/video-0-r1
|
||||||
|
>=acct-group/systemd-journal-0-r1
|
||||||
>=acct-user/root-0-r1
|
>=acct-user/root-0-r1
|
||||||
acct-user/nobody
|
acct-user/nobody
|
||||||
|
>=acct-user/systemd-journal-remote-0-r1
|
||||||
>=acct-user/systemd-coredump-0-r1
|
>=acct-user/systemd-coredump-0-r1
|
||||||
|
>=acct-user/systemd-network-0-r1
|
||||||
acct-user/systemd-oom
|
acct-user/systemd-oom
|
||||||
|
>=acct-user/systemd-resolve-0-r1
|
||||||
>=acct-user/systemd-timesync-0-r1
|
>=acct-user/systemd-timesync-0-r1
|
||||||
|
>=sys-apps/baselayout-2.2
|
||||||
|
hostnamed-fallback? (
|
||||||
|
acct-group/systemd-hostname
|
||||||
|
sys-apps/dbus-broker
|
||||||
|
)
|
||||||
selinux? ( sec-policy/selinux-base-policy[systemd] )
|
selinux? ( sec-policy/selinux-base-policy[systemd] )
|
||||||
sysv-utils? (
|
sysv-utils? (
|
||||||
!sys-apps/openrc[sysv-utils(-)]
|
!sys-apps/openrc[sysv-utils(-)]
|
||||||
@ -122,9 +141,8 @@ RDEPEND="${COMMON_DEPEND}
|
|||||||
"
|
"
|
||||||
|
|
||||||
# sys-apps/dbus: the daemon only (+ build-time lib dep for tests)
|
# sys-apps/dbus: the daemon only (+ build-time lib dep for tests)
|
||||||
#
|
|
||||||
# Flatcar: We don't have sys-fs/udev-init-scripts-34, so it's dropped.
|
|
||||||
PDEPEND=">=sys-apps/dbus-1.9.8[systemd]
|
PDEPEND=">=sys-apps/dbus-1.9.8[systemd]
|
||||||
|
>=sys-fs/udev-init-scripts-34
|
||||||
policykit? ( sys-auth/polkit )
|
policykit? ( sys-auth/polkit )
|
||||||
!vanilla? ( sys-apps/gentoo-systemd-integration )"
|
!vanilla? ( sys-apps/gentoo-systemd-integration )"
|
||||||
|
|
||||||
@ -163,8 +181,8 @@ pkg_pretend() {
|
|||||||
ewarn "See https://bugs.gentoo.org/674458."
|
ewarn "See https://bugs.gentoo.org/674458."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
local CONFIG_CHECK="~AUTOFS4_FS ~BLK_DEV_BSG ~CGROUPS
|
local CONFIG_CHECK="~AUTOFS4_FS ~BINFMT_MISC ~BLK_DEV_BSG ~CGROUPS
|
||||||
~CHECKPOINT_RESTORE ~DEVTMPFS ~EPOLL ~FANOTIFY ~FHANDLE
|
~DEVTMPFS ~EPOLL ~FANOTIFY ~FHANDLE
|
||||||
~INOTIFY_USER ~IPV6 ~NET ~NET_NS ~PROC_FS ~SIGNALFD ~SYSFS
|
~INOTIFY_USER ~IPV6 ~NET ~NET_NS ~PROC_FS ~SIGNALFD ~SYSFS
|
||||||
~TIMERFD ~TMPFS_XATTR ~UNIX ~USER_NS
|
~TIMERFD ~TMPFS_XATTR ~UNIX ~USER_NS
|
||||||
~CRYPTO_HMAC ~CRYPTO_SHA256 ~CRYPTO_USER_API_HASH
|
~CRYPTO_HMAC ~CRYPTO_SHA256 ~CRYPTO_USER_API_HASH
|
||||||
@ -177,6 +195,12 @@ pkg_pretend() {
|
|||||||
kernel_is -lt 4 7 && CONFIG_CHECK+=" ~DEVPTS_MULTIPLE_INSTANCES"
|
kernel_is -lt 4 7 && CONFIG_CHECK+=" ~DEVPTS_MULTIPLE_INSTANCES"
|
||||||
kernel_is -ge 4 10 && CONFIG_CHECK+=" ~CGROUP_BPF"
|
kernel_is -ge 4 10 && CONFIG_CHECK+=" ~CGROUP_BPF"
|
||||||
|
|
||||||
|
if kernel_is -lt 5 10 20; then
|
||||||
|
CONFIG_CHECK+=" ~CHECKPOINT_RESTORE"
|
||||||
|
else
|
||||||
|
CONFIG_CHECK+=" ~KCMP"
|
||||||
|
fi
|
||||||
|
|
||||||
if linux_config_exists; then
|
if linux_config_exists; then
|
||||||
local uevent_helper_path=$(linux_chkconfig_string UEVENT_HELPER_PATH)
|
local uevent_helper_path=$(linux_chkconfig_string UEVENT_HELPER_PATH)
|
||||||
if [[ -n ${uevent_helper_path} ]] && [[ ${uevent_helper_path} != '""' ]]; then
|
if [[ -n ${uevent_helper_path} ]] && [[ ${uevent_helper_path} != '""' ]]; then
|
||||||
@ -213,28 +237,15 @@ src_prepare() {
|
|||||||
|
|
||||||
# Add local patches here
|
# Add local patches here
|
||||||
PATCHES+=(
|
PATCHES+=(
|
||||||
# Flatcar: Adding our own patches here.
|
|
||||||
"${FILESDIR}/249-libudev-static.patch"
|
|
||||||
"${FILESDIR}/0001-networkd-disable-managing-of-foreign-routes-rules-by-default.patch"
|
|
||||||
"${FILESDIR}/0004-wait-online-set-any-by-default.patch"
|
|
||||||
"${FILESDIR}/0005-networkd-default-to-kernel-IPForwarding-setting.patch"
|
|
||||||
"${FILESDIR}/0006-needs-update-don-t-require-strictly-newer-usr.patch"
|
|
||||||
"${FILESDIR}/0007-core-use-max-for-DefaultTasksMax.patch"
|
|
||||||
"${FILESDIR}/0008-systemd-Disable-SELinux-permissions-checks.patch"
|
|
||||||
"${FILESDIR}/0009-core-handle-lookup-paths-being-symlinks.patch"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
# Flatcar: We carry our own patches, we don't use the ones
|
if ! use vanilla; then
|
||||||
# from Gentoo. Thus we dropped the `if ! use vanilla` code
|
PATCHES+=(
|
||||||
# here.
|
"${FILESDIR}/gentoo-generator-path-r2.patch"
|
||||||
|
"${FILESDIR}/gentoo-systemctl-disable-sysv-sync-r1.patch"
|
||||||
# Flatcar: The Kubelet takes /etc/resolv.conf for, e.g., CoreDNS which has dnsPolicy "default", but unless
|
"${FILESDIR}/gentoo-journald-audit.patch"
|
||||||
# the kubelet --resolv-conf flag is set to point to /run/systemd/resolve/resolv.conf this won't work with
|
)
|
||||||
# /etc/resolv.conf pointing to /run/systemd/resolve/stub-resolv.conf which configures 127.0.0.53.
|
fi
|
||||||
# See https://kubernetes.io/docs/tasks/administer-cluster/dns-debugging-resolution/#known-issues
|
|
||||||
# This means that users who need split DNS to work should point /etc/resolv.conf back to /run/systemd/resolve/stub-resolv.conf
|
|
||||||
# (and if using K8s configure the kubelet resolvConf variable/--resolv-conf flag to /run/systemd/resolve/resolv.conf).
|
|
||||||
sed -i -e 's,/run/systemd/resolve/stub-resolv.conf,/run/systemd/resolve/resolv.conf,' tmpfiles.d/etc.conf.in || die
|
|
||||||
|
|
||||||
default
|
default
|
||||||
}
|
}
|
||||||
@ -248,25 +259,21 @@ src_configure() {
|
|||||||
multilib-minimal_src_configure
|
multilib-minimal_src_configure
|
||||||
}
|
}
|
||||||
|
|
||||||
get_rootprefix() {
|
|
||||||
usex split-usr "${EPREFIX:-/}" "${EPREFIX}/usr"
|
|
||||||
}
|
|
||||||
|
|
||||||
multilib_src_configure() {
|
multilib_src_configure() {
|
||||||
local myconf=(
|
local myconf=(
|
||||||
--localstatedir="${EPREFIX}/var"
|
--localstatedir="${EPREFIX}/var"
|
||||||
# Flatcar: Point to our user mailing list.
|
-Dsupport-url="https://gentoo.org/support/"
|
||||||
-Dsupport-url="https://groups.google.com/forum/#!forum/flatcar-linux-user"
|
|
||||||
-Dpamlibdir="$(getpam_mod_dir)"
|
-Dpamlibdir="$(getpam_mod_dir)"
|
||||||
# avoid bash-completion dep
|
# avoid bash-completion dep
|
||||||
-Dbashcompletiondir="$(get_bashcompdir)"
|
-Dbashcompletiondir="$(get_bashcompdir)"
|
||||||
# make sure we get /bin:/sbin in PATH
|
# make sure we get /bin:/sbin in PATH
|
||||||
$(meson_use split-usr)
|
$(meson_use split-usr)
|
||||||
-Dsplit-bin=true
|
-Dsplit-bin=true
|
||||||
-Drootprefix="$(get_rootprefix)"
|
-Drootprefix="$(usex split-usr "${EPREFIX:-/}" "${EPREFIX}/usr")"
|
||||||
-Drootlibdir="${EPREFIX}/usr/$(get_libdir)"
|
-Drootlibdir="${EPREFIX}/usr/$(get_libdir)"
|
||||||
# Avoid infinite exec recursion, bug 642724
|
# Avoid infinite exec recursion, bug 642724
|
||||||
-Dtelinit-path="${EPREFIX}/lib/sysvinit/telinit"
|
-Dtelinit-path="${EPREFIX}/lib/sysvinit/telinit"
|
||||||
|
# no deps
|
||||||
-Dima=true
|
-Dima=true
|
||||||
-Ddefault-hierarchy=$(usex cgroup-hybrid hybrid unified)
|
-Ddefault-hierarchy=$(usex cgroup-hybrid hybrid unified)
|
||||||
# Optional components/dependencies
|
# Optional components/dependencies
|
||||||
@ -277,10 +284,11 @@ multilib_src_configure() {
|
|||||||
$(meson_native_use_bool curl libcurl)
|
$(meson_native_use_bool curl libcurl)
|
||||||
$(meson_native_use_bool dns-over-tls dns-over-tls)
|
$(meson_native_use_bool dns-over-tls dns-over-tls)
|
||||||
$(meson_native_use_bool elfutils)
|
$(meson_native_use_bool elfutils)
|
||||||
|
$(meson_native_use_bool fido2 libfido2)
|
||||||
$(meson_use gcrypt)
|
$(meson_use gcrypt)
|
||||||
$(meson_native_use_bool gnuefi gnu-efi)
|
$(meson_native_use_bool gnuefi gnu-efi)
|
||||||
|
$(meson_native_use_bool gnutls)
|
||||||
-Defi-includedir="${ESYSROOT}/usr/include/efi"
|
-Defi-includedir="${ESYSROOT}/usr/include/efi"
|
||||||
-Defi-ld="$(tc-getLD)"
|
|
||||||
-Defi-libdir="${ESYSROOT}/usr/$(get_libdir)"
|
-Defi-libdir="${ESYSROOT}/usr/$(get_libdir)"
|
||||||
$(meson_native_use_bool homed)
|
$(meson_native_use_bool homed)
|
||||||
$(meson_native_use_bool http microhttpd)
|
$(meson_native_use_bool http microhttpd)
|
||||||
@ -293,23 +301,21 @@ multilib_src_configure() {
|
|||||||
$(meson_use lzma xz)
|
$(meson_use lzma xz)
|
||||||
$(meson_use zstd)
|
$(meson_use zstd)
|
||||||
$(meson_native_use_bool nat libiptc)
|
$(meson_native_use_bool nat libiptc)
|
||||||
|
$(meson_native_use_bool openssl)
|
||||||
$(meson_use pam)
|
$(meson_use pam)
|
||||||
$(meson_native_use_bool pkcs11 p11kit)
|
$(meson_native_use_bool pkcs11 p11kit)
|
||||||
$(meson_native_use_bool pcre pcre2)
|
$(meson_native_use_bool pcre pcre2)
|
||||||
$(meson_native_use_bool policykit polkit)
|
$(meson_native_use_bool policykit polkit)
|
||||||
$(meson_native_use_bool pwquality)
|
$(meson_native_use_bool pwquality)
|
||||||
$(meson_native_use_bool qrcode qrencode)
|
$(meson_native_use_bool qrcode qrencode)
|
||||||
$(meson_native_use_bool repart)
|
|
||||||
$(meson_native_use_bool seccomp)
|
$(meson_native_use_bool seccomp)
|
||||||
$(meson_native_use_bool selinux)
|
$(meson_native_use_bool selinux)
|
||||||
$(meson_native_use_bool tpm tpm2)
|
$(meson_native_use_bool tpm tpm2)
|
||||||
$(meson_native_use_bool test dbus)
|
$(meson_native_use_bool test dbus)
|
||||||
$(meson_native_use_bool xkb xkbcommon)
|
$(meson_native_use_bool xkb xkbcommon)
|
||||||
# Flatcar: Use our ntp servers.
|
-Dntp-servers="0.gentoo.pool.ntp.org 1.gentoo.pool.ntp.org 2.gentoo.pool.ntp.org 3.gentoo.pool.ntp.org"
|
||||||
-Dntp-servers="0.flatcar.pool.ntp.org 1.flatcar.pool.ntp.org 2.flatcar.pool.ntp.org 3.flatcar.pool.ntp.org"
|
|
||||||
# Breaks screen, tmux, etc.
|
# Breaks screen, tmux, etc.
|
||||||
-Ddefault-kill-user-processes=false
|
-Ddefault-kill-user-processes=false
|
||||||
# Flatcar: TODO: Investigate if we want this.
|
|
||||||
-Dcreate-log-dirs=false
|
-Dcreate-log-dirs=false
|
||||||
|
|
||||||
# multilib options
|
# multilib options
|
||||||
@ -332,43 +338,6 @@ multilib_src_configure() {
|
|||||||
$(meson_native_true timesyncd)
|
$(meson_native_true timesyncd)
|
||||||
$(meson_native_true tmpfiles)
|
$(meson_native_true tmpfiles)
|
||||||
$(meson_native_true vconsole)
|
$(meson_native_true vconsole)
|
||||||
|
|
||||||
# Flatcar: Specify this, or meson breaks due to no
|
|
||||||
# /etc/login.defs.
|
|
||||||
-Dsystem-gid-max=999
|
|
||||||
-Dsystem-uid-max=999
|
|
||||||
|
|
||||||
# Flatcar: DBus paths.
|
|
||||||
-Ddbussessionservicedir="${EPREFIX}/usr/share/dbus-1/services"
|
|
||||||
-Ddbussystemservicedir="${EPREFIX}/usr/share/dbus-1/system-services"
|
|
||||||
|
|
||||||
# Flatcar: PAM config directory.
|
|
||||||
-Dpamconfdir=/usr/share/pam.d
|
|
||||||
|
|
||||||
# Flatcar: The CoreOS epoch, Mon Jul 1 00:00:00 UTC
|
|
||||||
# 2013. Used by timesyncd as a sanity check for the
|
|
||||||
# minimum acceptable time. Explicitly set to avoid
|
|
||||||
# using the current build time.
|
|
||||||
-Dtime-epoch=1372636800
|
|
||||||
|
|
||||||
# Flatcar: No default name servers.
|
|
||||||
-Ddns-servers=
|
|
||||||
|
|
||||||
# Flatcar: Disable the "First Boot Wizard", it isn't
|
|
||||||
# very applicable to us.
|
|
||||||
-Dfirstboot=false
|
|
||||||
|
|
||||||
# Flatcar: Set latest network interface naming scheme
|
|
||||||
# for
|
|
||||||
# https://github.com/flatcar-linux/Flatcar/issues/36
|
|
||||||
-Ddefault-net-naming-scheme=latest
|
|
||||||
|
|
||||||
# Flatcar: Unported options, still needed?
|
|
||||||
-Defi-cc="$(tc-getCC)"
|
|
||||||
-Dquotaon-path=/usr/sbin/quotaon
|
|
||||||
-Dquotacheck-path=/usr/sbin/quotacheck
|
|
||||||
|
|
||||||
# Flatcar: No static libs.
|
|
||||||
)
|
)
|
||||||
|
|
||||||
meson_src_configure "${myconf[@]}"
|
meson_src_configure "${myconf[@]}"
|
||||||
@ -386,8 +355,7 @@ multilib_src_install_all() {
|
|||||||
mv "${ED}"/usr/share/doc/{systemd,${PF}} || die
|
mv "${ED}"/usr/share/doc/{systemd,${PF}} || die
|
||||||
|
|
||||||
einstalldocs
|
einstalldocs
|
||||||
# Flatcar: Do not install sample nsswitch.conf, we don't
|
dodoc "${FILESDIR}"/nsswitch.conf
|
||||||
# provide it.
|
|
||||||
|
|
||||||
if ! use resolvconf; then
|
if ! use resolvconf; then
|
||||||
rm -f "${ED}${rootprefix}"/sbin/resolvconf || die
|
rm -f "${ED}${rootprefix}"/sbin/resolvconf || die
|
||||||
@ -406,11 +374,29 @@ multilib_src_install_all() {
|
|||||||
rmdir "${ED}${rootprefix}"/sbin || die
|
rmdir "${ED}${rootprefix}"/sbin || die
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Flatcar: Upstream uses keepdir commands to keep some empty
|
# https://bugs.gentoo.org/761763
|
||||||
# directories.
|
rm -r "${ED}"/usr/lib/sysusers.d || die
|
||||||
#
|
|
||||||
# Flatcar: TODO: Consider using that instead of
|
# Preserve empty dirs in /etc & /var, bug #437008
|
||||||
# dotmpfiles "${FILESDIR}"/systemd-flatcar.conf below.
|
keepdir /etc/{binfmt.d,modules-load.d,tmpfiles.d}
|
||||||
|
keepdir /etc/kernel/install.d
|
||||||
|
keepdir /etc/systemd/{network,system,user}
|
||||||
|
keepdir /etc/udev/rules.d
|
||||||
|
|
||||||
|
keepdir /etc/udev/hwdb.d
|
||||||
|
|
||||||
|
keepdir "${rootprefix}"/lib/systemd/{system-sleep,system-shutdown}
|
||||||
|
keepdir /usr/lib/{binfmt.d,modules-load.d}
|
||||||
|
keepdir /usr/lib/systemd/user-generators
|
||||||
|
keepdir /var/lib/systemd
|
||||||
|
keepdir /var/log/journal
|
||||||
|
|
||||||
|
# Symlink /etc/sysctl.conf for easy migration.
|
||||||
|
dosym ../../../etc/sysctl.conf /usr/lib/sysctl.d/99-sysctl.conf
|
||||||
|
|
||||||
|
if use pam; then
|
||||||
|
newpamd "${FILESDIR}"/systemd-user.pam systemd-user
|
||||||
|
fi
|
||||||
|
|
||||||
if use split-usr; then
|
if use split-usr; then
|
||||||
# Avoid breaking boot/reboot
|
# Avoid breaking boot/reboot
|
||||||
@ -418,100 +404,17 @@ multilib_src_install_all() {
|
|||||||
dosym ../../../lib/systemd/systemd-shutdown /usr/lib/systemd/systemd-shutdown
|
dosym ../../../lib/systemd/systemd-shutdown /usr/lib/systemd/systemd-shutdown
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Flatcar: Ensure journal directory has correct ownership/mode
|
# workaround for https://github.com/systemd/systemd/issues/13501
|
||||||
# in inital image. This is fixed by systemd-tmpfiles *but*
|
if use hostnamed-fallback; then
|
||||||
# journald starts before that and will create the journal if
|
# this file requires dbus-broker
|
||||||
# the filesystem is already read-write. Conveniently the
|
insinto /usr/share/dbus-1/system.d/
|
||||||
# systemd Makefile sets this up completely wrong.
|
doins "${FILESDIR}/org.freedesktop.hostname1_no_polkit.conf"
|
||||||
#
|
|
||||||
# Flatcar: TODO: Is this still a problem?
|
|
||||||
dodir /var/log/journal
|
|
||||||
fowners root:systemd-journal /var/log/journal
|
|
||||||
fperms 2755 /var/log/journal
|
|
||||||
|
|
||||||
# Flatcar: Don't prune systemd dirs.
|
insinto "${rootprefix}/lib/systemd/system/systemd-hostnamed.service.d/"
|
||||||
#
|
doins "${FILESDIR}/00-hostnamed-network-user.conf"
|
||||||
# Flatcar: TODO: Upstream probably fixed it in different way -
|
|
||||||
# it's using some keepdir commands.
|
|
||||||
dotmpfiles "${FILESDIR}"/systemd-flatcar.conf
|
|
||||||
# Flatcar: Add tmpfiles rule for resolv.conf. This path has
|
|
||||||
# changed after v213 so it must be handled here instead of
|
|
||||||
# baselayout now.
|
|
||||||
dotmpfiles "${FILESDIR}"/systemd-resolv.conf
|
|
||||||
|
|
||||||
# Flatcar: Don't default to graphical.target.
|
|
||||||
local unitdir=$(builddir_systemd_get_systemunitdir)
|
|
||||||
dosym multi-user.target "${unitdir}"/default.target
|
|
||||||
|
|
||||||
# Flatcar: Don't set any extra environment variables by default.
|
|
||||||
rm "${ED}/usr/lib/environment.d/99-environment.conf" || die
|
|
||||||
|
|
||||||
# Flatcar: These lines more or less follow the systemd's
|
|
||||||
# preset file (90-systemd.preset). We do it that way, to avoid
|
|
||||||
# putting symlink in /etc. Please keep the lines in the same
|
|
||||||
# order as the "enable" lines appear in the preset file.
|
|
||||||
builddir_systemd_enable_service multi-user.target remote-fs.target
|
|
||||||
builddir_systemd_enable_service multi-user.target remote-cryptsetup.target
|
|
||||||
builddir_systemd_enable_service multi-user.target machines.target
|
|
||||||
# Flatcar: getty@.service is enabled manually below.
|
|
||||||
builddir_systemd_enable_service sysinit.target systemd-timesyncd.service
|
|
||||||
builddir_systemd_enable_service multi-user.target systemd-networkd.service
|
|
||||||
# Flatcar: For systemd-networkd.service, it has it in Also, which also
|
|
||||||
# needs to be enabled
|
|
||||||
builddir_systemd_enable_service sockets.target systemd-networkd.socket
|
|
||||||
# Flatcar: For systemd-networkd.service, it has it in Also, which also
|
|
||||||
# needs to be enabled
|
|
||||||
builddir_systemd_enable_service network-online.target systemd-networkd-wait-online.service
|
|
||||||
builddir_systemd_enable_service multi-user.target systemd-resolved.service
|
|
||||||
if use homed; then
|
|
||||||
builddir_systemd_enable_service multi-user.target systemd-homed.target
|
|
||||||
# Flatcar: systemd-homed.target has
|
|
||||||
# Also=systemd-userdbd.service, but the service has no
|
|
||||||
# WantedBy entry. It's likely going to be executed through
|
|
||||||
# systemd-userdbd.socket, which is enabled in upstream's
|
|
||||||
# presets file.
|
|
||||||
builddir_systemd_enable_service sockets.target systemd-userdbd.socket
|
|
||||||
fi
|
fi
|
||||||
builddir_systemd_enable_service sysinit.target systemd-pstore.service
|
|
||||||
# Flatcar: not enabling reboot.target - it has no WantedBy
|
|
||||||
# entry.
|
|
||||||
|
|
||||||
# Flatcar: Enable getty manually.
|
gen_usr_ldscript -a systemd udev
|
||||||
dodir "${unitdir}/getty.target.wants"
|
|
||||||
dosym ../getty@.service "${unitdir}/getty.target.wants/getty@tty1.service"
|
|
||||||
|
|
||||||
# Flatcar: Use an empty preset file, because systemctl
|
|
||||||
# preset-all puts symlinks in /etc, not in /usr. We don't use
|
|
||||||
# /etc, because it is not autoupdated. We do the "preset" above.
|
|
||||||
rm "${ED}$(usex split-usr '' /usr)/lib/systemd/system-preset/90-systemd.preset" || die
|
|
||||||
insinto $(usex split-usr '' /usr)/lib/systemd/system-preset
|
|
||||||
doins "${FILESDIR}"/99-default.preset
|
|
||||||
|
|
||||||
# Flatcar: Do not ship distro-specific files (nsswitch.conf
|
|
||||||
# pam.d). This conflicts with our own configuration provided
|
|
||||||
# by baselayout.
|
|
||||||
rm -rf "${ED}"/usr/share/factory
|
|
||||||
sed -i "${ED}"/usr/lib/tmpfiles.d/etc.conf \
|
|
||||||
-e '/^C!* \/etc\/nsswitch\.conf/d' \
|
|
||||||
-e '/^C!* \/etc\/pam\.d/d' \
|
|
||||||
-e '/^C!* \/etc\/issue/d'
|
|
||||||
|
|
||||||
# Flatcar: gen_usr_ldscript is likely for static libs, so we
|
|
||||||
# dropped it.
|
|
||||||
}
|
|
||||||
|
|
||||||
builddir_systemd_get_systemunitdir() {
|
|
||||||
echo "$(get_rootprefix)/lib/systemd/system"
|
|
||||||
}
|
|
||||||
|
|
||||||
builddir_systemd_enable_service() {
|
|
||||||
local target=${1}
|
|
||||||
local service=${2}
|
|
||||||
local ud=$(builddir_systemd_get_systemunitdir)
|
|
||||||
local destname=${service##*/}
|
|
||||||
|
|
||||||
dodir "${ud}"/"${target}".wants && \
|
|
||||||
dosym ../"${service}" "${ud}"/"${target}".wants/"${destname}"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
migrate_locale() {
|
migrate_locale() {
|
||||||
@ -589,19 +492,18 @@ pkg_postinst() {
|
|||||||
# between OpenRC & systemd
|
# between OpenRC & systemd
|
||||||
migrate_locale
|
migrate_locale
|
||||||
|
|
||||||
# Flatcar: We enable getty and remote-fs targets in /usr
|
if [[ -z ${REPLACING_VERSIONS} ]]; then
|
||||||
# ourselves above.
|
if type systemctl &>/dev/null; then
|
||||||
|
systemctl --root="${ROOT:-/}" enable getty@.service remote-fs.target || FAIL=1
|
||||||
|
fi
|
||||||
|
elog "To enable a useful set of services, run the following:"
|
||||||
|
elog " systemctl preset-all --preset-mode=enable-only"
|
||||||
|
fi
|
||||||
|
|
||||||
if [[ -L ${EROOT}/var/lib/systemd/timesync ]]; then
|
if [[ -L ${EROOT}/var/lib/systemd/timesync ]]; then
|
||||||
rm "${EROOT}/var/lib/systemd/timesync"
|
rm "${EROOT}/var/lib/systemd/timesync"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -z ${ROOT} && -d /run/systemd/system ]]; then
|
|
||||||
ebegin "Reexecuting system manager"
|
|
||||||
systemctl daemon-reexec
|
|
||||||
eend $?
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ ${FAIL} ]]; then
|
if [[ ${FAIL} ]]; then
|
||||||
eerror "One of the postinst commands failed. Please check the postinst output"
|
eerror "One of the postinst commands failed. Please check the postinst output"
|
||||||
eerror "for errors. You may need to clean up your system and/or try installing"
|
eerror "for errors. You may need to clean up your system and/or try installing"
|
Loading…
Reference in New Issue
Block a user