X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=TODO;h=326edb0af89128cd80ce9761492741b37bc0fd95;hp=b3aac5af30e854130a7e4ffcb29c6f5318852dc8;hb=3040728b6691ea2e9df3a2060e2d49a792bbaeda;hpb=59cea26a349cfa8db906b520dac72563dd773ff2 diff --git a/TODO b/TODO index b3aac5af3..ff52822ed 100644 --- a/TODO +++ b/TODO @@ -1,8 +1,4 @@ Bugfixes: -* remove MS_SHARED from src/core/execute.c and src/test/test-ns.c. They are always combined - with MS_REMOUNT, which currently does nothing in the kernel, but might which fail in the - future; https://bugzilla.redhat.com/show_bug.cgi?id=813563 - * check systemd-tmpfiles for selinux context hookup for mknod(), symlink() and similar * swap units that are activated by one name but shown in the kernel under another are semi-broken @@ -17,62 +13,330 @@ Bugfixes: * properly handle .mount unit state tracking when two mount points are stacked one on top of another on the exact same mount point. -* we pull src/core/manager.h into src/shared/src/shared/path-lookup.c which is the wrong direction - rename enum "ManagerRunningAs" to "SystemdRunningAs" and move it to shared/ +F18: + +* Retest multi-seat Features: -* rename systemd-udev.service to systemd-udevd.service +* "systemctl is-failed" to join "systemctl is-active" and "systemctl is-enabled". -* document that journal data is primarily ASCII, UTF-8 where necessary and binary only where nothing else makes sense. +* journal is not closed properly at shutdown when run in a container? -* Document: - - PID 1 D-Bus API - - Update Syslog Interface docs - - Journal C API manual pages +* All log messages generated from socket.c, service.c, ... should + include _SYSTEMD_UNIT= fields so that "systemctl status" can show + them along with the unit -* wiki: document logind's PreparingForShutdown, PreparingForSleep +* define a message ID for "overmounting non-empty directory". -* support debian's console-setup logic +* use polkit "imply" for binding hostname actions together -* introduce Type=pid-file +* journal: when waiting for journal additions always sleep at least 1s or so, in order to minimize wakeups -* systemctl list-unit-files appears to be broken for symlinked units in /usr/lib +* man page for catalog APIs -* maybe allow services with ExecStop= set, but no ExecStart=? +* add catalog api for querying the raw template rather then replaced text -* efi: implement /forcefsck as uefi variables thus not requiring file system altering to trigger a file system check +* When shutdown.target is queued begin with an asynchronous sync()? -* efi: honour language efi variables for default language selection +* Add ConditionBatteryPower= or ConditionACPower=? (but definitely not both) -* efi: honour timezone efi variables for default timezone selection +* add API to close/reopen/get fd for journal client fd in libsystemd-journal. -* new dependency type to "group" services in a target +* maybe add API to send pairs of iovecs via sd_journal_send -* change Requires=basic.target to RequisiteOverride=basic.target +* fallback to /dev/log based logging in libsystemd-journal, if we can't log natively? -* turn $NOTIFY_SOCKET back into an abstract namespace socket for - compatibility with services which chroot() +* declare the local journal protocol stable in the wiki interface chart -* exclude processes marked with argv[0][0]=@ from the normal service killing too +* sd-journal: don't return fields > a threshold by default +* journal: reuse XZ context +* sd-journal: speed up sd_journal_get_data() with transparent hash table in bg -* support rd.luks.allow-discards= kernel cmdline params in cryptsetup generator +* introduce ntp.service (or suchlike) as symlink that is used to arbitrate between various NTP implementations -* systemctl: when stopping a service which has triggres and warning about it actually check the TriggeredBy= deps fields +* timer units should get the ability to trigger when: + - CLOCK_REALTIME makes jumps (TFD_TIMER_CANCEL_ON_SET) + - DST changes -* journal: hook up with EFI firmware log, new kmsg logic +* update the kernel's TZ (sys_tz) when DST changes -* handle C-A-Del in logind, like the power/suspend buttons? +* sync down the system time to the RTC when: + - CLOCK_REALTIME makes jumps (the user explicitely requested a time set) + - DST/timezone changes && ntp is active && RTC-in-localtime (never do it without ntp) + This takes care of syncing ntpdate updates to the RTC, and DST updates for localtime + mode, it will never touch the RTC if the no reliable time source is active or the + user did not request anything like it. -* nspawn: make use of device cgroup contrller by default +* When we begin with system shutdown all kind of suspend/hibernation should be prohibited until shutdown/reboot -* journalctl /dev/sda, journalctl --device=b12:8 (--device=n12, --device=+usb:1-1) +* When we update the kernel all kind of hibernation should be prohibited until shutdown/reboot -* make use of /sys/power/wake_lock in inhibitors +* hwdb: + - implement conditional properties (dmi matches) + - hwdb --filter=ID_DRIVE_* + - find out what to do for blockdevs and skipping scsi modaliases + - move writing code to src/libudev/libudev-hwdb-private.c -* drop accountsservice's StandardOutput=syslog and Type=dbus fields +* if booted in "quiet" mode, and an error happens, turn on status output again, so that the emergency mode isn't totally surprising + +* localectl: add listing support for X11 keymaps, by parsing /usr/share/X11/xkb/rules/xorg.lst + +* libunwind support for coredump pattern hook, and includes this in + the message for coredumps. After all, libunwind is now capable to + unwind coredumps since a few weeks ago. This probably requires that + we have nice support for multi-line messages on display in logs-show.c. + +* figure out relation of --all and --full in the various tools + +* journal: when writing journal auto-rotate if time jumps backwards + +* introduce new "journal" group in place of adm? introduce groups for the various mini daemons? + +* journal: add a setgid "adm" utility to invoke from libsystemd-journal, which passes fds via STDOUT and does PK access + +* link up selected blog stories from man pages? + +* journactl: support negative filtering, i.e. FOOBAR!="waldo", + and !FOOBAR for events without FOOBAR. + +* print nice message from systemctl --failed if there are no entries shown, and hook that into ExecStartPre of rescue.service/emergency.service + +* add libsystemd-password or so to query passwords during boot using the password agent logic + +* journal: when rotating, copy over old acls/access mode + +* journal: document why we do not give ownership to journal files to the user that created them but use FS ACLs for that + +* journal: send out marker messages every now and then, and immediately sync with fdatasync() afterwards, in order to have hourly guaranteed syncs. + +* journal: when we haven't written anything in a while, sync to disk and mark file as offline, in order to be more often than not in a clean state + +* journal-send.c, log.c: when the log socket is clogged, and we drop, count this and write a message about this when it gets unclogged again. + +* If we show an error about a unit (such as not showing up) and it has no Description string, then show a description string generated form the reverse of unit_name_mangle(). + +* fedup: add --unit to systemctl switch-root somehow +* fedup: don't delete initrd on switch-root +* fedup: generator + +* journal: find a way to allow dropping history early, based on priority, other rules + +* journal: When used on NFS, check payload hashes + +* journal: When used on NFS make sure wake up sd_journal_wait() every 2s, to handle missing inotify + +* document that people can use file system ACLs to manage access to journal files, with example + +* don't show cgroup in "systemctl status" if empty/non-existent, especially for foreign .mount units + +* timedated: export boolean that clarifies whether NTP is even available + +* timedated: refuse time changes when NTP is on + +* clean up date formatting and parsing so that all absolute/relative timestamps we format can also be parsed + +* document unit_name_mangle() + +* add new command to systemctl: "systemctl system-reexec" which reexecs as many daemons as virtually possible + +* introduce generic AUGMENT_PID=, AUGMENT_DEVICE= fields + +* deal with sendmail/postfix exclusivity + +* systemctl enable: improve the success messages (i.e. more human readable, less shell-like) + +* systemctl enable: fail if target to alias into doesn't exist? maybe show how many units are enabled afterwards? + +* on shutdown: move utmp, wall, audit logic all into PID 1 itself, get rid of systemd-update-utmp-runlevel + +* add "provisioning" instructions to setup an empty /etc + /var + - used to setup a new container from a shared /usr + - superset of tmpfiles model + - instructions shipped by packages and stored in /usr/lib/ + - compose /etc/passwd and /etc/group, copy files + - able to create uid + gid used by packages, for file ownership + +* make repeated alt-ctrl-del presses printing a dump, or even force a reboot without + waiting for the timeout + +* high level net_prio setting in execution context + +* Introduce journalctl -b to show journal messages of a previous boot + +* hostnamed: before returning information from /etc/machine-info.conf check the modification data and reread. Similar for localed, ... + +* currently x-systemd.timeout is lost in the initrd, since crypttab is copied into dracut, but fstab isn't + +* WorkingDirectory: support env var replacements like in ExecStart= so that people can use $HOME + +* refuse boot if /etc/machine-id is not useful + +* nspawn: consider changing users for -u with su, so that NSS resolving works correctly + +* nspawn: implement personality changes a la linux32(8) + +* nspawn: reset all aux groups + +* cryptsetup-generator: warn if the password files are world-readable + +* cryptsetup-generator: add RequiresMountsFor= to cryptseup service files referencing a file, similar for devices + +* cryptsetup-generator: allow specification of passwords in crypttab itself + +* document that deps in [Unit] sections ignore Alias= fileds in + [Install] units of other units, unless those units are disabled + +* need to update LGPL2.1 text to newest version (with updated FSF address) + +* systemctl: when powering down/suspending check for inhibitors, and warn. + +* instantiated [Install] for target units + https://bugs.freedesktop.org/show_bug.cgi?id=54377 + +* move debug shell to tty6 and make sure this doesn't break the gettys on tty6 + +* move cryptsetup key caching into kernel keyctl? + https://bugs.freedesktop.org/show_bug.cgi?id=54982 + +* make nspawn work without terminal + +* hw watchdog: optionally try to use the preset watchdog timeout instead of always overriding it + https://bugs.freedesktop.org/show_bug.cgi?id=54712 + +* after deserializing sockets in socket.c we should reapply sockopts and things + +* make timer units go away after they elapsed + +* http://lists.freedesktop.org/archives/systemd-devel/2012-September/006502.html + +* come up with a nice way to write queue/read_ahead_kb for a block device without interfering with readahead + +* journald: add kernel cmdline option to disable ratelimiting for debug purposes + +* move PID 1 segfaults to /var/lib/systemd/coredump? + +* Document word splitting syntax for ExecStart= and friends + +* create /sbin/init symlinks from the build system + +* Query Paul Moore about relabelling socket fds while they are open + +* move keymaps to /usr/lib/... rather than /usr/lib/udev/... + +* journald: check whether it is OK if the client can still modify delivered journal entries + +* journal live copy, based on libneon (client) and libmicrohttpd + +* system-wide seccomp filter + +* ability to pass fds into systemd + +* system.conf should have controls for cgroups + +* bind mount read-only the cgroup tree higher than nspawn + +* allow writing multiple conditions in unit files on one line + +* explore multiple service instances per listening socket idea -* make sure show-logs checks for utf8 validity, not ascii validity +* testing tool for socket activation: some binary that listens on a socket and passes it on using the usual socket activation protocol to some server. + +* shutdown: don't read-only mount anything when running in container + +* nspawn: --read-only is not applied recursively to submounts + +* MountFlags=shared acts as MountFlags=slave right now. + +* ReadOnlyDirectories= is not applied recursively to submounts + +* drop PID 1 reloading, only do reexecing (difficult: Reload() + currently is properly synchronous, Reexec() is weird, because we + can't delay the response properly until we are back, so instead of + being properly synchronous we just keep open the fd and close it + when done. That means clients don't get a successful method reply, + but much rather a disconnect on success. + +* document that service reload may be implemented as service reexec + +* remember which condition failed for services, not just the fact that something failed + +* use opterr = 0 for all getopt tools + +* properly handle loop back mounts via fstab, especially regards to fsck/passno + +* allow services with no ExecStart= but with an ExecStop= + +* add proper journal support to "systemctl --user status ..." + +* add _SYSTEMD_USER_UNIT= field to journal entries + +* dracut-shutdown needs to be ordered before unmounting /boot + +* initialize the hostname from the fs label of /, if /etc/hostname does not exist? + +* rename "userspace" to "core-os" + +* systemctl: "Journal has been rotated since unit was started." message is misleading + +* syscall filter: add knowledge about compat syscalls + +* syscall filter: don't enforce no new privs? + +* syscall filter: option to return EPERM rather than SIGSYS? + +* syscall filter: port to libseccomp + +* logind: wakelock/opportunistic suspend support + +* systemd-analyze post-boot is broken for initrd + +* man: clarify that time-sync.target is not only sysv compat but also useful otherwise. Same for similar targets + +* .device aliases need to be implemented with the "following" logic, probably. + +* refuse taking lower-case variable names in sd_journal_send() and friends. + +* load-fragment: when loading a unit file via a chain of symlinks + verify that it isn't masked via any of the names traversed. + +* journald: we currently rotate only after MaxUse+MaxFilesize has been reached. + +* Document: + - PID 1 D-Bus API + +* introduce Type=pid-file + +* maybe allow services with ExecStop= set, but no ExecStart=? + +* efi: implement /forcefsck as uefi variables thus not requiring file system altering to trigger a file system check + +* efi: honor language efi variables for default language selection + +* efi: honor timezone efi variables for default timezone selection + +* efi: automatically mount EFI partition to /boot if no such entry exists in /etc/fstab and /boot is empty + gummiboot exports the EFI system partion (ESP) device: + /sys/firmware/efi/vars/LoaderDeviceIdentifier-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + Acpi(PNP0A03,0)/Pci(1F|2)/?/HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1) + '/' is the separator for the device path list + HD(Part1,Sig1FCBC57F-4BFC-4C2B-91A3-9C84FBCD9AF1) contains the GPT UUID of the ESP + +* read the bootloader performance data (raw TSC) in systemd-analyze + /sys/firmware/efi/vars/LoaderTicksExec-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + 19066159288 + /sys/firmware/efi/vars/LoaderTicksInit-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + 17442940316 + /sys/firmware/efi/vars/LoaderTicksStartMenu-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f/data + (only set if the menu was active) + +* change Requires=basic.target to RequisiteOverride=basic.target + +* support rd.luks.allow-discards= kernel cmdline params in cryptsetup generator + +* nspawn: make use of device cgroup contrller by default + +* drop accountsservice's StandardOutput=syslog and Type=dbus fields * when breaking cycles drop sysv services first, then services from /run, then from /etc, then from /usr @@ -82,12 +346,6 @@ Features: - implement .d/ auto includes for unit files - add syntax to reset ExecStart= lists (and similar) -* manipulate CPU governor during boot, set it to performance - -* steal SBF management from the kernel - -* delay journal /var writeout to after boot if SBF is clean - * move passno parsing to fstab generator * improve !/proc/*/loginuid situation: make /proc/*/loginuid less dependent on CONFIG_AUDIT, @@ -113,8 +371,6 @@ Features: * don't delete /tmp/systemd-namespace-* before a process is gone down -* don't delete /run/users/lennart if lennart is still logged in even if aging is used - * vconsole: implement setterm -store -foreground xxx --background zzz * ExecOnFailure=/usr/bin/foo @@ -125,10 +381,6 @@ Features: * Add pretty name for seats in logind -* nspawn wants dev_setup() for /dev/fd/ and friends? - -* selinux: merge systemd selinux access controls (dwalsh) - * ConditionSecurity= should learn about IMA * Auke: merge Auke's bootchart @@ -138,13 +390,6 @@ Features: * udev systemd unify: - strpcpy(), strpcpyl(), strscpy(), strscpyl() - utf8 validator code - - now() vs. now_usec() - -* udev: remove network interface renaming, sleep and retry logic, we do - no support renaming of interfaces in the conflicting kernel - namespace - -* udev: find a way to tell udev to not cancel firmware requests when running in initramfs * udev: scsi_id -> sg3_utils -> kill scsi_id @@ -154,17 +399,12 @@ Features: * cleanup syslog 'priority' vs. 'level' wording -* journal: if mmap() fails for mapping window try to unmap a a few older maps - * dbus upstream still refers to dbus.target and shouldn't * when a service has the same env var set twice we actually store it twice and return that in systemctl show -p... We should only show the last setting * support container_ttys= -* journald: make configurable "store-on-var", "store-on-run", "dont-store", "auto" - (store-persistent, store-volatile?) - * introduce mix of BindTo and Requisite * journalctl: show multiline log messages sanely, expand tabs, and show all valid utf8 messages @@ -173,58 +413,30 @@ Features: * journal: store euid in journal if it differs from uid -* support chrony in addition to ntpd in timedated - * There's currently no way to cancel fsck (used to be possible via C-c or c on the console) -* journal: sanely deal with entries which are larger than the individual file size, but where the componets would fit +* journal: sanely deal with entries which are larger than the individual file size, but where the components would fit * add command to systemctl to plot dependency graph as tree (see rhbz 795365) -* make logind reserve tty9 or so for text logins, so that gdm never picks it up - * add option to sockets to avoid activation. Instead just drop packets/connections, see http://cyberelk.net/tim/2012/02/15/portreserve-systemd-solution/ * default unix qlen is too small (10). bump sysctl? add sockopt? -* Possibly, detect whether SysV init scripts can do reloading by looking for "echo Usage:" lines - * figure out whether we should leave dbus around during shutdown * dbus: in fedora, make the machine a symlink to /etc/machine-id -* journald: reuse XZ context +* dbus: move dbus to early boot * logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API -* write RPM spec macros for presets - -* journal: write man pages for API - -* journal: OR matches are borked - -* journal: extend hash tables as we go - -* journal: API for looking for retrieving "all values of this field" - * journal: deal nicely with byte-by-byte copied files, especially regards header * journal: local deserializer of export mode, http server -* journal: message catalog - -* journal: forward-secure signatures - * document the exit codes when services fail before they are exec()ed -* rework namespace support, don't use pivot_root, and mount things after creating the namespace, not before - -* systemctl journal command - -* journalctl: --cursor support, priority filtering - -* systemctl status: show coredumps - * save coredump in Windows/Mozilla minidump format * support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting) @@ -239,15 +451,8 @@ Features: * when an instanced service exits, remove its parent cgroup too if possible. -* automatically escape unit names passed on the service (i.e. think "systemctl start serial-getty.service@serial/by-path/jshdfjsdfhkjh" being automatically escaped as necessary. - -* if we can not get user quota for tmpfs, mount a separate tmpfs instance - for every user in /run/user/$USER with a configured maximum size - * default to actual 32bit PIDs, via /proc/sys/kernel/pid_max -* add an option to make mounts private/shareable and so on, enable this for root by default - * be able to specify a forced restart of service A where service B depends on, in case B needs to be auto-respawned? @@ -270,8 +475,6 @@ Features: * move PAM code into its own binary -* warn if the user stops a service but not its associated socket - * logind: spawn user@..service on login * logind: non-local X11 server handling @@ -306,22 +509,24 @@ Features: * GC unreferenced jobs (such as .device jobs) -* when failing to start a service due to ratelimiting, try again later, if restart=always is set - * write blog stories about: + - hwdb: what belongs into it, lsusb - enabling dbus services - status update - how to make changes to sysctl and sysfs attributes - remote access - how to pass throw-away units to systemd, or dynamically change properties of existing units - how to integrate cgconfig and suchlike with systemd - - resource control in systemd - - inhibiting - testing with Harald's awesome test kit + - auto-restart + - how to develop against journal browsing APIs + - the journal HTTP iface + - non-cgroup resource management + - refreshed, longer missions statement * allow port=0 in .socket units -* move readahead files into /var, look for them with .path units +* move readahead files into /var (look for them with .path units?) * teach dbus to activate all services it finds in /etc/systemd/services/org-*.service @@ -343,19 +548,13 @@ Features: * timer events with system resume -* timer events on calendar time - * dot output for --test showing the 'initial transaction' -* calendar time support in timer, iCalendar semantics for the timer stuff (RFC2445) - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=99ee5315dac6211e972fa3f23bcc9a0343ff58c4 +* calendar time support in timer: + https://docs.google.com/document/pub?id=1bAMyFAjWLpzR3GTDYdgj5FWRMxoZiWw5zmUHEtvdHKA -* implicitly import "defaults" settings file into all types -* exec settings override * writable cgroups dbus properties for live changes -* read config fragments for all units from /lib/systemd/system/foobar.service.d/ to override/extend specific settings - * port over to LISTEN_FDS/LISTEN_PID: - rpcbind (/var/run/rpcbind.sock!) HAVEPATCH - cups HAVEPATCH @@ -365,8 +564,6 @@ Features: - bluetoothd (/var/run/sdp! @/org/bluez/audio!) - distccd -* auditd service files - * fingerprint.target, wireless.target, gps.target, netdevice.target * io priority during initialization @@ -411,12 +608,18 @@ Regularly: * Use PR_SET_PROCTITLE_AREA if it becomes available in the kernel -* %m in printf() instead of strerror(); +* %m in printf() instead of strerror(errno); * pahole * set_put(), hashmap_put() return values check. i.e. == 0 doesn't free()! -Scheduled for removal (or fixing): +* use secure_getenv() instead of getenv() where appropriate + +Scheduled for removal or fixing: + +* xxxOverridable dependencies (probably: fix) + +* support for early-boot SysV services (definitely: remove) -* xxxOverridable dependencies +* insserv support (definitely: remove)