X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=TODO;h=1654db5c0c4fd13cfe99cae8301ad882ee4d705a;hp=c7f789b9b6e1bd4ea2c19a5a6dc38cc012abc234;hb=7a43e910ce00eef22fd42925ae4c85cbea1b1320;hpb=d87be9b0af81a6e07d4fb3028e45c4409100dc26 diff --git a/TODO b/TODO index c7f789b9b..1654db5c0 100644 --- a/TODO +++ b/TODO @@ -1,18 +1,4 @@ Bugfixes: -* there is nothing to warn about here :) - $ systemctl stop systemd-udevd.service systemd-udevd-kernel.socket systemd-udevd-control.socket - Warning: Stopping systemd-udevd.service, but it can still be activated by: - systemd-udevd-control.socket - systemd-udevd-kernel.socket - -* kill /etc/timezone handling entirely? What does it provide? - - /etc/localtime carries the same information already: - $ ls -l /etc/localtime; cat /etc/timezone - lrwxrwxrwx 1 root root 33 Jul 27 09:55 /etc/localtime -> /usr/share/zoneinfo/Europe/Berlin - Europe/Berlin - - systemd enforces /usr to be available at bootup, so we can - enforce the use of the symlink - * check systemd-tmpfiles for selinux context hookup for mknod(), symlink() and similar * swap units that are activated by one name but shown in the kernel under another are semi-broken @@ -27,87 +13,203 @@ Bugfixes: * properly handle .mount unit state tracking when two mount points are stacked one on top of another on the exact same mount point. -* we pull src/core/manager.h into src/shared/src/shared/path-lookup.c which is the wrong direction - rename enum "ManagerRunningAs" to "SystemdRunningAs" and move it to shared/ +F18: -* crash happens when running a service as forking and then changing it to simple and reloading. +* Retest multi-seat - Jul 09 18:20:57 mop systemd[1]: usbmuxd.service operation timed out. Terminating. - Jul 09 18:20:57 mop systemd[1]: Unit usbmuxd.service entered failed state. - Jul 09 18:22:24 mop systemd[1]: PID 21814 read from file /var/run/usbmuxd.pid does not exist. - Jul 09 18:22:24 mop systemd[1]: Unit usbmuxd.service entered failed state. - Jul 09 18:22:33 mop systemd[1]: Reloading. - Jul 09 18:22:37 mop systemd[1]: Assertion 's->type == SERVICE_FORKING' failed at src/core/service.c:3007, function service_sigchld_eve...Aborting. - Jul 09 18:22:37 mop systemd[1]: Caught , dumped core as pid 21865. - Jul 09 18:22:37 mop systemd[1]: Freezing execution. - Jul 09 18:22:37 mop [21866]: Process 21865 (systemd) dumped core. +Features: -* support *static* (/run) hibernate inhibitors. All rpm -i actions should completely prevent any - sort of hibernate action until the next reboot. If the kernel or any other base tool is replaced - by rpm, the resume path might fail, the for resume needed kernel might even be uninstalled, and - the whole situation leads directly to data loss. +* introduce ntp.service (or suchlike) as symlink that is used to arbitrate between various + NTP implementations -Features: +* timer units should get the ability to trigger when: + - CLOCK_REALTIME makes jumps (TFD_TIMER_CANCEL_ON_SET) + - DST changes -* Query Paul Moore about relabelling socket fds while they are open +* update the kernel's TZ (sys_tz) when DST changes -* log fewer journal internal messages to the kernel kmsg +* sync down the system time to the RTC when: + - CLOCK_REALTIME makes jumps (the user explicitely requested a time set) + - DST changes && ntp is active && RTC-in-localtime (never do it without ntp) + This takes care of syncing ntpdate updates to the RTC, and DST updates for localtime + mode, it will never touch the RTC if the no reliable time source is active or the + user did not request anything like it. -* move keymaps to /usr/lib/... rather than /usr/lib/udev/... +* When we begin with system shutdown all kind of suspend/hibernation should be prohibited until shutdown/reboot -* journald: check whether it is OK if the client can still modify delivered journal entries +* When we update the kernel all kind of hibernation should be prohibited until shutdown/reboot -* json: use jensson +* hwdb: + - implement conditional properties (dmi matches) + - hwdb --filter=ID_DRIVE_* + - find out what to do for blockdevs and skipping scsi modaliases + - move writing code to src/libudev/libudev-hwdb-private.c -* json: properly serialize multiple fields with the same name per entry +* sd_journal_enumerate_data() implies XZ-decoding compressed field, this sucks hard -* journalctl: make -l the default +* if booted in "quiet" mode, and an error happens, turn on status output again, so that the emergency mode isn't totally surprising -* journald: add option to choose between "split up nothing", "split up login user journals", "split up all user journals" +* localectl: add listing support for X11 keymaps, by parsing /usr/share/X11/xkb/rules/xorg.lst -* journal live copy, bsaed on libneon (client) and libmicrohttpd +* libunwind support for coredump pattern hook, and includes this in + the message for coredumps. After all, libunwind is now capable to + unwind coredumps since a few weeks ago. This probably requires that + we have nice support for multi-line messages on display in logs-show.c. -* document in wiki json serialization +* figure out relation of --all and --full in the various tools -* python-journal merge +* journal: when writing journal auto-rotate if time jumps backwards -* system-wide seccomp filter +* introduce new "journal" group in place of adm? introduce groups for the various mini daemons? -* securityfs: don't mount in container +* journal: add a setgid "adm" utility to invoke from libsystemd-journal, which passes fds via STDOUT and does PK access -* slave/shared remount root fs in container might clash with CAP_SYS_MOUNTS +* link up selected blog stories from man pages? -* ability to pass fds into systemd +* journactl: support negative filtering, i.e. FOOBAR!="waldo", + and !FOOBAR for events without FOOBAR. -* system.conf should have controls for cgroups +* print nice message from systemctl --failed if there are no entries shown, and hook that into ExecStartPre of rescue.service/emergency.service -* tmpfiles: skip mknod if CAP_MKNOD is missing +* add libsystemd-password or so to query passwords during boot using the password agent logic -* bind mount read-only the cgroup tree higher than than nspawn +* journal: when rotating, copy over old acls/access mode -* currently system services appear not to generate core dumps... +* journal: document why we do not give ownership to journal files to the user that created them but use FS ACLs for that -* introduce /run/kmsg in containers? +* journal: send out marker messages every now and then, and immediately sync with fdatasync() afterwards, in order to have hourly guaranteed syncs. -* wall messages for shutdown should move to logind +* journal: when we haven't written anything in a while, sync to disk and mark file as offline, in order to be more often than not in a clean state -* allow writing multiple conditions in unit files on one line +* journal-send.c, log.c: when the log socket is clogged, and we drop, count this and write a message about this when it gets unclogged again. -* journal: json output needs to be able to deal with multiple assignments of the same field +* If we show an error about a unit (such as not showing up) and it has no Description string, then show a description string generated form the reverse of unit_name_mangle(). -* There's something wrong with escaping unit names: http://lists.freedesktop.org/archives/systemd-devel/2012-August/006292.html +* fedup: add --unit to systemctl switch-root somehow +* fedup: don't delete initrd on switch-root +* fedup: generator -* cleanup ellipsation for log output in journalctl and systemctl status: have a sane way to disable ellipsation, and disable it by default when invoked in less/more +* journal: find a way to allow dropping history early, based on priority, other rules -* enforce limits on fds openened by socket units +* journal: When used on NFS, check payload hashes -* explore multiple service instances per listening socket idea +* journal: When used on NFS make sure wake up sd_journal_wait() every 2s, to handle missing inotify -* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server. +* document that people can use file system ACLs to manage access to journal files, with example + +* don't show cgroup in "systemctl status" if empty/non-existant, especially for foreign .mount units + +* timedated: export boolean that clarifies whether NTP is even available + +* timedated: refuse time changes when NTP is on + +* clean up date formatting and parsing so that all absolute/relative timestamps we format can also be parsed + +* document unit_name_mangle() + +* add new command to systemctl: "systemctl system-reexec" which reexecs as many daemons as virtually possible + +* introduce generic AUGMENT_PID=, AUGMENT_DEVICE= fields + +* deal with sendmail/postfix exclusivity + +* systemctl enable: improve the success messages (i.e. more human readable, less shell-like) + +* systemctl enable: fail if target to alias into doesn't exist? maybe show how many units are enabled afterwards? + +* on shutdown: move utmp, wall, audit logic all into PID 1 itself, get rid of systemd-update-utmp-runlevel + +* add "provisioning" instructions to setup an empty /etc + /var + - used to setup a new container from a shared /usr + - superset of tmpfiles model + - instructions shipped by packages and stored in /usr/lib/ + - compose /etc/passwd and /etc/group, copy files + - able to create uid + gid used by packages, for file ownership + +* make repeated alt-ctrl-del presses printing a dump, or even force a reboot without + waiting for the timeout + +* high level net_prio setting in execution context + +* Introduce journalctl -b to show journal messages of a previous boot + +* hostnamed: before returning information from /etc/machine-info.conf check the modification data and reread. Similar for localed, ... + +* currently x-systemd.timeout is lost in the initrd, since crypttab is copied into dracut, but fstab isn't + +* WorkingDirectory: support env var replacements like in ExecStart= so that people can use $HOME + +* refuse boot if /etc/machine-id is not useful + +* nspawn: consider changing users for -u with su, so that NSS resolving works correctly + +* nspawn: implement personality changes a la linux32(8) + +* nspawn: reset all aux groups + +* cryptsetup-generator: warn if the password files are world-readable + +* cryptsetup-generator: add RequiresMountsFor= to cryptseup service files referencing a file, similar for devices + +* cryptsetup-generator: allow specification of passwords in crypttab itself + +* document that deps in [Unit] sections ignore Alias= fileds in + [Install] units of other units, unless those units are disabled + +* need to update LGPL2.1 text to newest version (with updated FSF address) + +* systemctl: when powering down/suspending check for inhibitors, and warn. + +* instantiated [Install] for target units + https://bugs.freedesktop.org/show_bug.cgi?id=54377 + +* move debug shell to tty6 and make sure this doesn't break the gettys on tty6 + +* move cryptsetup key caching into kernel keyctl? + https://bugs.freedesktop.org/show_bug.cgi?id=54982 + +* make nspawn work without terminal + +* hw watchdog: optionally try to use the preset watchdog timeout instead of always overriding it + https://bugs.freedesktop.org/show_bug.cgi?id=54712 + +* after deserializing sockets in socket.c we should reapply sockopts and things + +* make timer units go away after they elapsed + +* http://lists.freedesktop.org/archives/systemd-devel/2012-September/006502.html + +* come up with a nice way to write queue/read_ahead_kb for a block device without interfering with readahead + +* journald: add kernel cmdline option to disable ratelimiting for debug purposes -* maybe make systemd-detect-virt suid? or use fscaps? +* move PID 1 segfaults to /var/lib/systemd/coredump? -* man: document in ExecStart= explicitly that we don't take shell command lines, only executable names with arguments +* Document word splitting syntax for ExecStart= and friends + +* create /sbin/init symlinks from the build system + +* Query Paul Moore about relabelling socket fds while they are open + +* move keymaps to /usr/lib/... rather than /usr/lib/udev/... + +* journald: check whether it is OK if the client can still modify delivered journal entries + +* journal live copy, based on libneon (client) and libmicrohttpd + +* system-wide seccomp filter + +* ability to pass fds into systemd + +* system.conf should have controls for cgroups + +* bind mount read-only the cgroup tree higher than than nspawn + +* allow writing multiple conditions in unit files on one line + +* explore multiple service instances per listening socket idea + +* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server. * shutdown: don't read-only mount anything when running in container @@ -138,23 +240,10 @@ Features: * add _SYSTEMD_USER_UNIT= field to journal entries -* remove Fedora /dev/null logic from localed.c, now that system-config-keyboard is gone - delete /etc/X11/xorg.conf.d/00-system-setup-keyboard.conf from spec file - -* journal: expose current disk usage - * dracut-shutdown needs to be ordered before unmounting /boot -* wiki: document new logind LockSessions() call - * initialize the hostname from the fs label of /, if /etc/hostname does not exist? -* logind: different policy actions for idle, suspend, shutdown blockers: allow idle blockers by default, don't allow suspend blockers by default - -* install README to /etc/rc.d/init.d (if support for that is enabled) helping people who use "ls" there to figure out which services exist. - -* logind: ignore inactive login screens when checking whether power key should be handled - * rename "userspace" to "core-os" * systemctl: "Journal has been rotated since unit was started." message is misleading @@ -169,8 +258,6 @@ Features: * logind: wakelock/opportunistic suspend support -* switch-root: sockets need relabelling - * systemd-analyze post-boot is broken for initrd * man: clarify that time-sync.target is not only sysv compat but also useful otherwise. Same for similar targets @@ -189,8 +276,6 @@ Features: * introduce Type=pid-file -* systemctl list-unit-files appears to be broken for symlinked units in /usr/lib - * maybe allow services with ExecStop= set, but no ExecStart=? * efi: implement /forcefsck as uefi variables thus not requiring file system altering to trigger a file system check @@ -218,12 +303,6 @@ Features: * support rd.luks.allow-discards= kernel cmdline params in cryptsetup generator -* systemctl: when stopping a service which has triggres and warning about it actually check the TriggeredBy= deps fields - -* journal: hook up with EFI firmware log - -* handle C-A-Del in logind, like the power/suspend buttons? - * nspawn: make use of device cgroup contrller by default * drop accountsservice's StandardOutput=syslog and Type=dbus fields @@ -271,8 +350,6 @@ Features: * Add pretty name for seats in logind -* selinux: merge systemd selinux access controls (dwalsh) - * ConditionSecurity= should learn about IMA * Auke: merge Auke's bootchart @@ -284,12 +361,6 @@ Features: - utf8 validator code - now() vs. now_usec() -* udev: remove network interface renaming, sleep and retry logic, we do - no support renaming of interfaces in the conflicting kernel - namespace - -* udev: find a way to tell udev to not cancel firmware requests when running in initramfs - * udev: scsi_id -> sg3_utils -> kill scsi_id * udev: add trigger --subsystem-match=usb/usb_device device @@ -318,14 +389,10 @@ Features: * add command to systemctl to plot dependency graph as tree (see rhbz 795365) -* make logind reserve tty9 or so for text logins, so that gdm never picks it up - * add option to sockets to avoid activation. Instead just drop packets/connections, see http://cyberelk.net/tim/2012/02/15/portreserve-systemd-solution/ * default unix qlen is too small (10). bump sysctl? add sockopt? -* Possibly, detect whether SysV init scripts can do reloading by looking for "echo Usage:" lines - * figure out whether we should leave dbus around during shutdown * dbus: in fedora, make the machine a symlink to /etc/machine-id @@ -336,8 +403,6 @@ Features: * logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API -* journal: API for looking for retrieving "all values of this field" - * journal: deal nicely with byte-by-byte copied files, especially regards header * journal: local deserializer of export mode, http server @@ -346,12 +411,6 @@ Features: * document the exit codes when services fail before they are exec()ed -* systemctl journal command - -* journalctl: --cursor support - -* systemctl status: show coredumps - * save coredump in Windows/Mozilla minidump format * support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting) @@ -366,9 +425,6 @@ Features: * when an instanced service exits, remove its parent cgroup too if possible. -* if we can not get user quota for tmpfs, mount a separate tmpfs instance - for every user in /run/user/$USER with a configured maximum size - * default to actual 32bit PIDs, via /proc/sys/kernel/pid_max * be able to specify a forced restart of service A where service B depends on, in case B @@ -393,8 +449,6 @@ Features: * move PAM code into its own binary -* warn if the user stops a service but not its associated socket - * logind: spawn user@..service on login * logind: non-local X11 server handling @@ -430,20 +484,22 @@ Features: * GC unreferenced jobs (such as .device jobs) * write blog stories about: + - hwdb: what belongs into it, lsusb - enabling dbus services - status update - how to make changes to sysctl and sysfs attributes - remote access - how to pass throw-away units to systemd, or dynamically change properties of existing units - how to integrate cgconfig and suchlike with systemd - - resource control in systemd - - inhibiting - testing with Harald's awesome test kit - - restart + - auto-restart + - how to develop against journal browsing APIs + - the journal HTTP iface + - non-cgroup resource management * allow port=0 in .socket units -* move readahead files into /var, look for them with .path units +* move readahead files into /var (look for them with .path units?) * teach dbus to activate all services it finds in /etc/systemd/services/org-*.service @@ -465,19 +521,13 @@ Features: * timer events with system resume -* timer events on calendar time - * dot output for --test showing the 'initial transaction' -* calendar time support in timer, iCalendar semantics for the timer stuff (RFC2445) - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=99ee5315dac6211e972fa3f23bcc9a0343ff58c4 - -* implicitly import "defaults" settings file into all types +* calendar time support in timer: + https://docs.google.com/document/pub?id=1bAMyFAjWLpzR3GTDYdgj5FWRMxoZiWw5zmUHEtvdHKA * writable cgroups dbus properties for live changes -* read config fragments for all units from /lib/systemd/system/foobar.service.d/ to override/extend specific settings - * port over to LISTEN_FDS/LISTEN_PID: - rpcbind (/var/run/rpcbind.sock!) HAVEPATCH - cups HAVEPATCH @@ -487,8 +537,6 @@ Features: - bluetoothd (/var/run/sdp! @/org/bluez/audio!) - distccd -* auditd service files - * fingerprint.target, wireless.target, gps.target, netdevice.target * io priority during initialization @@ -539,8 +587,12 @@ Regularly: * set_put(), hashmap_put() return values check. i.e. == 0 doesn't free()! -* use __secure_getenv() instead of getenv() where appropriate +* use secure_getenv() instead of getenv() where appropriate + +Scheduled for removal or fixing: + +* xxxOverridable dependencies (probably: fix) -Scheduled for removal (or fixing): +* support for early-boot SysV services (definitely: remove) -* xxxOverridable dependencies +* insserv support (definitely: remove)