X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?a=blobdiff_plain;f=TODO;h=62b5ebf6e4054b0c6ee8f37b26eed35d00806951;hb=dcf76484ec0612b909e8a160c9a1374f5a6a1cb8;hp=c2113f881eeb352b4e95c759cfb4015932d71fc2;hpb=acb14d318b84bda00d1e666d7dab6794d5bbeb3f;p=elogind.git diff --git a/TODO b/TODO index c2113f881..66100a0e1 100644 --- a/TODO +++ b/TODO @@ -1,15 +1,17 @@ Bugfixes: +* always open() tty6 to keep X from using it; move debug shell to tty6 -* swap units that are activated by one name but shown in the kernel under another are semi-broken - -* NM should pull in network.target (PENDING) - https://bugzilla.redhat.com/show_bug.cgi?id=692008 +* there is nothing to warn about here :) + $ systemctl stop systemd-udevd.service systemd-udevd-kernel.socket systemd-udevd-control.socket + Warning: Stopping systemd-udevd.service, but it can still be activated by: + systemd-udevd-control.socket + systemd-udevd-kernel.socket -* make anaconda write timeout=0 for encrypted devices +* check systemd-tmpfiles for selinux context hookup for mknod(), symlink() and similar -* service: pid file reading after reload doesn't work, since we don't reset the pid variable +* swap units that are activated by one name but shown in the kernel under another are semi-broken -* make sure timeouts are applied to Type=oneshot services. +* make anaconda write timeout=0 for encrypted devices * Dangling symlinks of .automount unit files in .wants/ directories, set up automount points even when the original .automount file did not exist @@ -19,86 +21,355 @@ Bugfixes: * properly handle .mount unit state tracking when two mount points are stacked one on top of another on the exact same mount point. +* we pull src/core/manager.h into src/shared/src/shared/path-lookup.c which is the wrong direction + rename enum "ManagerRunningAs" to "SystemdRunningAs" and move it to shared/ + +* crash happens when running a service as forking and then changing it to simple and reloading. + + Jul 09 18:20:57 mop systemd[1]: usbmuxd.service operation timed out. Terminating. + Jul 09 18:20:57 mop systemd[1]: Unit usbmuxd.service entered failed state. + Jul 09 18:22:24 mop systemd[1]: PID 21814 read from file /var/run/usbmuxd.pid does not exist. + Jul 09 18:22:24 mop systemd[1]: Unit usbmuxd.service entered failed state. + Jul 09 18:22:33 mop systemd[1]: Reloading. + Jul 09 18:22:37 mop systemd[1]: Assertion 's->type == SERVICE_FORKING' failed at src/core/service.c:3007, function service_sigchld_eve...Aborting. + Jul 09 18:22:37 mop systemd[1]: Caught , dumped core as pid 21865. + Jul 09 18:22:37 mop systemd[1]: Freezing execution. + Jul 09 18:22:37 mop [21866]: Process 21865 (systemd) dumped core. + +* support *static* (/run) hibernate inhibitors. All rpm -i actions should completely prevent any + sort of hibernate action until the next reboot. If the kernel or any other base tool is replaced + by rpm, the resume path might fail, the for resume needed kernel might even be uninstalled, and + the whole situation leads directly to data loss. + Features: -* dbus: in fedora, make the machine a symlink to /etc/machine-id +* make nspawn work without terminal -* journald: reuse XZ context +* hw watchdog: optionally try to use the preset watchdog timeout instead of always overriding it -* logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API +* after deserializing sockets in socket.c we should reapply sockopts and things -* Fedora: disable journald's /proc/kmsg reading on Fedora for now +* journald: warn if we drop messages we forward to the syslog socket -* write RPM spec macros for presets +* does vasprintf advance the struct vaargs? http://pastie.org/pastes/4712773/text -* write man pages for systemd-cat +* do shutdown audit/utmp msgs inside of PID 1, get rid of systemd-update-utmp-runlevel -* journal: write man pages for API +* make timer units go away after they elapsed -* journal: OR matches are borked +* refuse automount triggers when automount is queued for stop, much like we refuse socket triggers when sockets are queued for stop -* journal: extend hash tables as we go +* perfomance messages for selinux are gone from debug log? -* journal: API for looking for retrieving "all values of this field" +* http://lists.freedesktop.org/archives/systemd-devel/2012-September/006502.html -* journal: deal nicely with byte-by-byte copied files, especially regards header +* don't use writev() in tmpfiles for sake of compat with sysfs? -* journal: local deserializer of export mode, http server +* come up with a nice way to write queue/read_ahead_kb for a block device without interfering with readahead -* journal: message catalog +* journald: add kernel cmdline option to disable ratelimiting for debug purposes -* journal: forward-secure signatures +* Add a way to reference the machine/boot ID from ExecStart= and similar command lines -* document the exit codes when services fail before they are exec()ed +* move PID 1 segfaults to /var/lib/systemd/coredump? -* rework namespace support, don't use pivot_root, and mount things after creating the namespace, not before +* Document word splitting syntax for ExecStart= and friends -* systemctl journal command +* when writing journal entries order field items by their address to improve speed on rotating media -* journalctl: --cursor support, priority filtering +* create /sbin/init symlinks from the build system -* systemctl status: show coredumps +* Query Paul Moore about relabelling socket fds while they are open -* systemctl status: show whether journal was rotated since service started +* move keymaps to /usr/lib/... rather than /usr/lib/udev/... -* save coredump in Windows/Mozilla minidump format +* journald: check whether it is OK if the client can still modify delivered journal entries -* support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting) +* json: use jensson -* allow per-entry control on /var vs. /run (think incognito browser mode) +* json: properly serialize multiple fields with the same name per entry -* clean up session cgroups that remain after logout (think sshd), but eventually run empty +* journal live copy, based on libneon (client) and libmicrohttpd -* support "systemctl stop foobar@.service" to stop all units matching a certain template +* document in wiki json serialization -* move to LGPL2+ +* system-wide seccomp filter -* logind: allow showing logout dialog from system +* securityfs: don't mount in container -* document that %% can be used to write % in a string that is specifier extended +* slave/shared remount root fs in container might clash with CAP_SYS_MOUNTS -* check utf8 everywhere +* ability to pass fds into systemd -* when an instanced service exits, remove its parent cgroup too if possible. +* system.conf should have controls for cgroups -* Make libselinux, libattr, libcap, libdl dependencies only of the tools which actually need them. +* bind mount read-only the cgroup tree higher than than nspawn -* as Tom Gundersen pointed out there's a always a dep loop if people use crypto file systems with random keys +* currently system services appear not to generate core dumps... -* unset container= in PID1? +* wall messages for shutdown should move to logind -* automatically escape unit names passed on the service (i.e. think "systemctl start serial-getty.service@serial/by-path/jshdfjsdfhkjh" being automatically escaped as necessary. +* allow writing multiple conditions in unit files on one line -* if we can not get user quota for tmpfs, mount a separate tmpfs instance - for every user in /run/user/$USER with a configured maximum size +* There's something wrong with escaping unit names: http://lists.freedesktop.org/archives/systemd-devel/2012-August/006292.html -* default to actual 32bit PIDs, via /proc/sys/kernel/pid_max +* cleanup ellipsation for log output in journalctl and systemctl status: have a sane way to disable ellipsation, and disable it by default when invoked in less/more + +* enforce limits on fds openened by socket units + +* explore multiple service instances per listening socket idea + +* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server. + +* maybe make systemd-detect-virt suid? or use fscaps? + +* shutdown: don't read-only mount anything when running in container + +* nspawn: --read-only is not applied recursively to submounts + +* MountFlags=shared acts as MountFlags=slave right now. + +* ReadOnlyDirectories= is not applied recursively to submounts + +* drop PID 1 reloading, only do reexecing (difficult: Reload() + currently is properly synchronous, Reexec() is weird, because we + can't delay the response properly until we are back, so instead of + being properly synchronous we just keep open the fd and close it + when done. That means clients don't get a succesful method reply, + but much rather a disconnect on success. + +* document that service reload may be implemented as service reexec + +* remember which condition failed for services, not just the fact that something failed + +* use opterr = 0 for all getopt tools + +* properly handle loop back mounts via fstab, especially regards to fsck/passno + +* allow services with no ExecStart= but with an ExecStop= + +* add proper journal support to "systemctl --user status ..." + +* add _SYSTEMD_USER_UNIT= field to journal entries + +* dracut-shutdown needs to be ordered before unmounting /boot + +* wiki: document new logind LockSessions() call + +* initialize the hostname from the fs label of /, if /etc/hostname does not exist? + +* logind: different policy actions for idle, suspend, shutdown blockers: allow idle blockers by default, don't allow suspend blockers by default + +* install README to /etc/rc.d/init.d (if support for that is enabled) helping people who use "ls" there to figure out which services exist. + +* logind: ignore inactive login screens when checking whether power key should be handled + +* rename "userspace" to "core-os" + +* systemctl: "Journal has been rotated since unit was started." message is misleading + +* syscall filter: add knowledge about compat syscalls + +* syscall filter: don't enforce no new privs? + +* syscall filter: option to return EPERM rather than SIGSYS? + +* syscall filter: port to libseccomp + +* logind: wakelock/opportunistic suspend support + +* systemd-analyze post-boot is broken for initrd + +* man: clarify that time-sync.target is not only sysv compat but also useful otherwise. Same for similar targets + +* .device aliases need to be implemented with the "following" logic, probably. + +* refuse taking lower-case variable names in sd_journal_send() and friends. + +* load-fragment: when loading a unit file via a chain of symlinks + verify that it isn't masked via any of the names traversed. + +* journald: we currently rotate only after MaxUse+MaxFilesize has been reached. + +* Document: + - PID 1 D-Bus API + +* introduce Type=pid-file + +* systemctl list-unit-files appears to be broken for symlinked units in /usr/lib + +* maybe allow services with ExecStop= set, but no ExecStart=? + +* efi: implement /forcefsck as uefi variables thus not requiring file system altering to trigger a file system check + +* efi: honour language efi variables for default language selection + +* efi: honour timezone efi variables for default timezone selection + +* efi: automatically mount EFI partition to /boot if no such entry exists in /etc/fstab and /boot is empty + gummiboot exports the EFI system partion (ESP) device: + /sys/firmware/efi/vars/LoaderDeviceIdentifier-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + Acpi(PNP0A03,0)/Pci(1F|2)/?/HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1) + '/' is the separator for the device path list + HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1) contains the GPT UUID of the ESP + +* read the bootloader performance data (raw TSC) in systemd-analyze + /sys/firmware/efi/vars/LoaderTicksExec-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + 19066159288 + /sys/firmware/efi/vars/LoaderTicksInit-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + 17442940316 + /sys/firmware/efi/vars/LoaderTicksStartMenu-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + (only set if the menu was active) + +* change Requires=basic.target to RequisiteOverride=basic.target + +* support rd.luks.allow-discards= kernel cmdline params in cryptsetup generator + +* systemctl: when stopping a service which has triggres and warning about it actually check the TriggeredBy= deps fields + +* journal: hook up with EFI firmware log + +* nspawn: make use of device cgroup contrller by default + +* drop accountsservice's StandardOutput=syslog and Type=dbus fields + +* when breaking cycles drop sysv services first, then services from /run, then from /etc, then from /usr + +* readahead: when bumping /sys readahead variable save mtime and compare later to detect changes + +* (attempt to) make Debianites happy: + - implement .d/ auto includes for unit files + - add syntax to reset ExecStart= lists (and similar) + +* move passno parsing to fstab generator + +* improve !/proc/*/loginuid situation: make /proc/*/loginuid less dependent on CONFIG_AUDIT, + or use the users cgroup information when /proc/*/loginuid is not available. + +* pam_systemd: try to get old session id from cgroup, if audit sessionid cannot be determined + +* pam: when leaving a session explicitly exclude the ReleaseSession() caller process from the killing spree + +* maybe introduce ~/.config/locale.conf and apply it within PAM -* add an option to make mounts private/shareable and so on, enable this for root by default +* readahead: make use of EXT4_IOC_MOVE_EXT, as used by http://e4rat.sourceforge.net/ -* internal restart counter for units (focus on auto-respawn) +* automount: implement expire -* finer-grained auto-respawn settings (rate-limit) +* logind: auto-suspend, auto-shutdown: + IdleAction=(none|suspend|opportunistic|hibernate|poweroff) + IdleActionDelay=... + SessionIdleMode=(explicit|ignore|login) + ForceShutdown=(yes|no) + +* services which create their own subcgroups break cgroup-empty notification (needs to be fixed in the kernel) + +* don't delete /tmp/systemd-namespace-* before a process is gone down + +* vconsole: implement setterm -store -foreground xxx --background zzz + +* ExecOnFailure=/usr/bin/foo + +* fedora: make sshd and pam_loginuid work in nspawn containers + +* fix utmp for console logins in containers + +* Add pretty name for seats in logind + +* selinux: merge systemd selinux access controls (dwalsh) + +* ConditionSecurity= should learn about IMA + +* Auke: merge Auke's bootchart + +* udev: move to LGPL + +* udev systemd unify: + - strpcpy(), strpcpyl(), strscpy(), strscpyl() + - utf8 validator code + - now() vs. now_usec() + +* udev: remove network interface renaming, sleep and retry logic, we do + no support renaming of interfaces in the conflicting kernel + namespace + +* udev: find a way to tell udev to not cancel firmware requests when running in initramfs + +* udev: scsi_id -> sg3_utils -> kill scsi_id + +* udev: add trigger --subsystem-match=usb/usb_device device + +* allow configuration of console width/height in vconsole.conf + +* cleanup syslog 'priority' vs. 'level' wording + +* dbus upstream still refers to dbus.target and shouldn't + +* when a service has the same env var set twice we actually store it twice and return that in systemctl show -p... We should only show the last setting + +* support container_ttys= + +* introduce mix of BindTo and Requisite + +* journalctl: show multiline log messages sanely, expand tabs, and show all valid utf8 messages + +* add DeleteSocketsOnStop=yes|no option to socket units + +* journal: store euid in journal if it differs from uid + +* There's currently no way to cancel fsck (used to be possible via C-c or c on the console) + +* journal: sanely deal with entries which are larger than the individual file size, but where the componets would fit + +* add command to systemctl to plot dependency graph as tree (see rhbz 795365) + +* make logind reserve tty9 or so for text logins, so that gdm never picks it up + +* add option to sockets to avoid activation. Instead just drop packets/connections, see http://cyberelk.net/tim/2012/02/15/portreserve-systemd-solution/ + +* default unix qlen is too small (10). bump sysctl? add sockopt? + +* Possibly, detect whether SysV init scripts can do reloading by looking for "echo Usage:" lines + +* figure out whether we should leave dbus around during shutdown + +* dbus: in fedora, make the machine a symlink to /etc/machine-id + +* dbus: move dbus to early boot + +* journald: reuse XZ context + +* logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API + +* journal: API for looking for retrieving "all values of this field" + +* journal: deal nicely with byte-by-byte copied files, especially regards header + +* journal: local deserializer of export mode, http server + +* journal: message catalog + +* document the exit codes when services fail before they are exec()ed + +* systemctl journal command + +* journalctl: --cursor support + +* save coredump in Windows/Mozilla minidump format + +* support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting) + +* clean up session cgroups that remain after logout (think sshd), but eventually run empty + +* support "systemctl stop foobar@.service" to stop all units matching a certain template + +* logind: allow showing logout dialog from system + +* document that %% can be used to write % in a string that is specifier extended + +* when an instanced service exits, remove its parent cgroup too if possible. + +* default to actual 32bit PIDs, via /proc/sys/kernel/pid_max * be able to specify a forced restart of service A where service B depends on, in case B needs to be auto-respawned? @@ -109,15 +380,13 @@ Features: * something like ConditionExec= or ExecStartPre= without failure state -* service restart retry configuration - * tmpfiles: apply "x" on "D" too (see patch from William Douglas) * don't set $HOME in services unless requested * hide PAM/TCPWrap options in fragment parser when compile time disabled -* when we automatically restart a service, ensure we retsart its rdeps, too. +* when we automatically restart a service, ensure we restart its rdeps, too. * allow Type=simple with PIDFile= https://bugzilla.redhat.com/show_bug.cgi?id=723942 @@ -156,14 +425,10 @@ Features: * drop /.readahead on bigger upgrades with yum -* add inode nr check to readahead to suppress preloading changed files - * add support for /bin/mount -s * GC unreferenced jobs (such as .device jobs) -* when failing to start a service due to ratelimiting, try again later, if restart=always is set - * write blog stories about: - enabling dbus services - status update @@ -172,6 +437,9 @@ Features: - how to pass throw-away units to systemd, or dynamically change properties of existing units - how to integrate cgconfig and suchlike with systemd - resource control in systemd + - inhibiting + - testing with Harald's awesome test kit + - restart * allow port=0 in .socket units @@ -197,7 +465,8 @@ Features: * timer events with system resume -* timer events on calendar time +* timer events on calendar time: + maybe use this time syntax? http://ohse.de/uwe/uschedule/uschedule.html * dot output for --test showing the 'initial transaction' @@ -205,7 +474,7 @@ Features: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=99ee5315dac6211e972fa3f23bcc9a0343ff58c4 * implicitly import "defaults" settings file into all types -* exec settings override + * writable cgroups dbus properties for live changes * read config fragments for all units from /lib/systemd/system/foobar.service.d/ to override/extend specific settings @@ -219,41 +488,28 @@ Features: - bluetoothd (/var/run/sdp! @/org/bluez/audio!) - distccd -* auditd service files - * fingerprint.target, wireless.target, gps.target, netdevice.target * io priority during initialization -* if a service fails too often, make the service enter failed mode, and the socket, too. - * systemctl list-jobs - show dependencies * add systemctl switch to dump transaction without executing it -* suspend, resume support? - * drop cap bounding set in readahead and other services External: * dbus: - - get process transport into dbus for systemctl -P/-H (PENDING) - dbus --user - natively watch for dbus-*.service symlinks (PENDING) - allow specification of socket mode/umask when allocating DBusServer - allow disabling of fd passing when connecting a AF_UNIX connection - allow disabling of UID passing for AUTH EXTERNAL - -* systemd --user - PR_SET_CHILD_REAPER patch: https://lkml.org/lkml/2011/7/28/426 + - always pass cred data along each message * fix alsa mixer restore to not print error when no config is stored -* udisks should not use udisks-part-id, instead use blkid. also not probe /dev/loopxxx - -* snd-seq should go, https://bugzilla.redhat.com/show_bug.cgi?id=676095 - * gnome-shell python script/glxinfo/is-accelerated must die * make cryptsetup lower --iter-time @@ -266,12 +522,6 @@ External: we are in 11-minutes-mode. When we trust the system time to NTP we also want the RTC to sync up. -* patch kernel for cpu feature modalias for autoloading aes/kvm/... - (patches in linux-next, on the way to the next kernel) - -* kernel: add /proc/sys file exposing CAP_LAST_CAP? sysconf? - merged: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=commit;h=73efc0394e148d0e15583e13712637831f926720 - * kernel: add device_type = "fb", "fbcon" to class "graphics" Regularly: @@ -282,8 +532,14 @@ Regularly: * Use PR_SET_PROCTITLE_AREA if it becomes available in the kernel -* %m in printf() instead of strerror(); +* %m in printf() instead of strerror(errno); * pahole * set_put(), hashmap_put() return values check. i.e. == 0 doesn't free()! + +* use __secure_getenv() instead of getenv() where appropriate + +Scheduled for removal (or fixing): + +* xxxOverridable dependencies