X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=TODO;h=feb4944191444566c9e79a1ace7ba1864de845ae;hp=9ba1de01cb1935a02402663d34d50a7797944337;hb=0bee65f0622c4faa8ac8ae771cc0c8a936dfa284;hpb=76d5a71de99b6fe0ecc9bfd82ec641a5d408e191 diff --git a/TODO b/TODO index 9ba1de01c..d63e13e31 100644 --- a/TODO +++ b/TODO @@ -1,6 +1,8 @@ Bugfixes: -* systemctl status *.path shows all logs, not only the ones since the unit is - active +* enabling an instance unit creates a pointless link, and + the unit will be started with getty@getty.service: + $ systemctl enable getty@.service + ln -s '/usr/lib/systemd/system/getty@.service' '/etc/systemd/system/getty.target.wants/getty@.service' * check systemd-tmpfiles for selinux context hookup for mknod(), symlink() and similar @@ -10,33 +12,215 @@ Bugfixes: automount points even when the original .automount file did not exist anymore. Only the .mount unit was still around. -* make polkit checks async - * properly handle .mount unit state tracking when two mount points are stacked one on top of another on the exact same mount point. -Fedora 19: +* When we detect invalid UTF-8, we cannot use it in an error message: + log...("Path is not UTF-8 clean, ignoring assignment: %s", rvalue); + +* shorten the message to sane length: -* external: maybe it is time to patch procps so that "ps" links to - libsystemd-logind to print a pretty service name, seat name, session - name in its output. Currently it only shows cgroup membership, but - that's sometimes kinda hard to parse for a human. + Cannot add dependency job for unit display-manager.service, ignoring: Unit display-manager.service failed to load: No such file or directory. See system logs and 'systemctl status display-manager.service' for details. -* cgroup attrs: - - update dbus interface docs in wiki +Fedora 20: + +* external: ps should gain colums for slice * localed: - localectl: support new converted x11→console keymaps +* when installing fedora with yum --installroot /var/run is a directory, not a symlink + https://bugzilla.redhat.com/show_bug.cgi?id=975864 + +CGroup Rework Completion: + +* implement system-wide DefaultCPUAccounting=1 switch (and similar for blockio, memory?) + +* implement per-slice CPUFairScheduling=1 switch + +* handle jointly mounted controllers correctly + +* introduce high-level settings for RT budget, swappiness + Features: -* libsystemd-journal: - - return ECHILD as soon as somebody tries to reuse a journal object across a fork() +* general: get rid of readdir_r/dirent_storage stuff, it's unnecessary on Linux + +* add API to clone sd_bus_message objects + +* sd-bus: synthesized messages should get serial number (uint32_t) -1 + +* sd-event: allow multiple signal handlers per signal + +* when we detect low battery and no AC on boot, show pretty splash and refuse boot + +* move libasyncns into systemd as libsystemd-asyncns + +* calendarspec: support value ranges with ".." notation. Example: 2013-4..8-1 + +* sd-bus: when triggering property change events, allow a NULL strv indicate that all properties listed as such are send out as changed + +* sd-bus: enforce signatures on response messages + +* sd-bus: see if we can drop more message validation on the sending side + +* sd-bus: introduce sd_bus_creds object and attach it to messages as well as allow querying it for names + +* sd-bus: support "const" properties as flag + +* sd-event: when a handler returns an error, just turn off its event + source, but do not return anything up to the event loop + caller. Instead add parameter to sd_event_request_quit() to take + retval. This way errors rippling upwards are the option, not the + default + +* sd-event: child pid handling: first invoke waitid(WNOHANG) and call event handler, only afterwards reap the process + +* sd-event: native support for watchdog stuff + +* machined, localed: when we try to kill an empty cgroup, generate an ESRCH call over the bus + +* sd-bus: SD_BUS_COMMENT() macro for inclusion in vtables, syntax inspired by gdbus + +* libsystemd-journal, libsystemd-login, libudev: add calls to easily attach these objects to sd-event event loops + +* be more careful what we export on the bus as (usec_t) 0 and (usec_t) -1 + +* increase journal files by a few MB each time, instead of piecemeal + +* add field to transient units that indicate whether systemd or somebody else saves/restores its settings, for integration with libvirt + +* systemctl: rework wait filter to not require match callback + +* unify dispatch table in systemctl_main() and friends + +* bus: access policy as vtable flag + +* journalctl: support -M to read journal of containers and determine journal directory from root directory of container + +* tmpfiles: to make sure we don't delete unpacked tarballs with old timestamps right-away never delete stuff that is inside a directory with a new mtime + +* "systemctl mask" should find all names by which a unit is accessible + (i.e. by scanning for symlinks to it) and link them all to /dev/null + +* Automatically configure swap partition to use for hibernation by looking for largest swap partition on the root disk? + +* remove NSS usage from PID 1 (notably the specifiers) + +* socket-proxyd: + - Use a nonblocking alternative to getaddrinfo + - Until we can start daemons directly, find a less ugly, less racy alternative than shell scripts for the second man page example. + - Support starting daemons directly without requiring a shell script; update man pages + +* "systemctl cat" or "systemctl view" command or or so, that cats the backing unit file of a service, plus its drop-ins and shows them in a pager + +* rfkill,backlight: we probably should run the load tools inside of the udev rules so that the state is properly initialized by the time other software sees it + +* Add a new Distribute=$NUMBER key to socket units that makes use of SO_REUSEPORT to distribute network traffic on $NUMBER instances + +* tmpfiles: when applying ownership to /run/log/journal, also do this for the journal fails contained in it + +* we probably should replace the left-over uses of strv_append() and replace them by strv_push() or strv_extend() + +* move config_parse_path_strv() out of conf-parser.c + +* libdsystemd-bus should expose utf8 validation calls + +* After coming back from hibernation reset hibernation swap partition using the /dev/snapshot ioctl APIs + +* If we try to find a unit via a dangling symlink, generate a clean + error. Currently, we just ignore it and read the unit from the search + path anyway. + +* When a Type=forking service fails and needed another service, that + service is not cleaned up again when it has StopWhenUnneeded=yes + http://lists.freedesktop.org/archives/systemd-devel/2013-July/012141.html + +* refuse boot if /etc/os-release is missing or /etc/machine-id cannot be set up + +* ensure scope units may be started only a single time + +* better error message if you run systemctl without systemd running + +* systemctl status output should should include list of triggering units and their status + +* for transient units, instead of writing out drop-ins for all properties consider serializing them in the normal serialization stream + +* logind: when logging out, remove user-owned sysv and posix IPC objects + +* session scopes/user unit: add RequiresMountsFor for the home directory of the user + +* add a man page containing packaging guidelines and recommending usage of things like Documentation=, PrivateTmp=, PrivateNetwork= and ReadOnlyDirectories=/etc /usr. + +* journalctl: instead --after-cursor= maybe have a --cursor=XYZ+1 syntax? + +* given that logind/machined now let PID 1 do all nasty work, we can + probably reduce the capability set they retain substantially. + +* btrfs raid assembly: some .device jobs stay stuck in the queue + +* Fedora: add an rpmlint check that verifies that all unit files in the RPM are listed in %systemd_post macros. + +* Fedora: post FPC ticket to move add %tmpfiles_create to the packaging guidelines + +* make sure gdm doesn't use multi-user-x but the new default X configuration file, and then remove multi-user-x from systemd + +* when parsing calendar timestamps support the UTC timezone (even if we won't support arbitrary timezone specs, support UTC itself certainly makes sense), also support syntaxes such as +0200 + +* when a kernel driver logs in a tight loop, we should ratelimit that too. + +* "systemctl disable" of a unit instance removes all symlinks, but should + only remove the instance symlink (systemctl disable of a template + unit however should remove them all). + +* journald: optionally, log debug messages to /run but everything else to /var + +* systemctl list-unit-files should list generated files (and probably with a new state "generated" for them, or so) + +* journald: when we drop syslog messages because the syslog socket is + full, make sure to write how many messages are lost as first thing + to syslog when it works again. + +* man: the documentation of Restart= currently is very misleading and suggests the tools from ExecStartPre= might get restarted. + +* load .d/*.conf dropins for device units + +* service_coldplug() appears to reinstall the wrong stop timeout watch. + +* transient units: allow creating auxiliary units with the same call + +* how to reset dynamically changed attributes sanely? + +* when reloading configuration, apply new cgroup configuration + +* journald: make sure ratelimit is actually really per-service with the new cgroup changes + +* gparted needs to disable auto-activation of mount units somehow, or + maybe we should stop doing auto-activation of this after boot + entirely. https://bugzilla.gnome.org/show_bug.cgi?id=701676 + Maybe take a BSD lock at the disk device node and teach udev to + check for that and suppress event handling. + +* when recursively showing the cgroup hierarchy, optionally also show + the hierarchies of child processes + +* document logic of auto/noauto and fail/nofail in fstab in systemd.mount or systemd-fstab-generator man page + +* something pulls in pcre as shared object dependency into our daemons such as hostnamed. + +* document systemd-journal-flush.service properly + +* change systemd-journal-flush into a service that stays around during + boot, and causes the journal to be moved back to /run on shutdown, + so that we don't keep /var busy. This needs to happen synchronously, + hence doing this via signals is not going to work. + +* allow implementation of InaccessibleDirectories=/ plus + ReadOnlyDirectories=... for whitelisting files for a service. * libsystemd-bus: - default policy (allow uid == 0 and our own uid) - enforce alignment of pointers passed in - when kdbus doesn't take our message without memfds, try again with memfds - - kdbus: generate correct bloom filter for matches - implement translator service - port systemd to new library - implement busname unit type in systemd @@ -44,12 +228,10 @@ Features: - merge busctl into systemctl or so? - synthesize sd_bus_message objects from kernel messages - properly implement name registry ioctls for kdbus - - get rid of object hash table, use decision tree everyhwere instead? - implement monitor logic - - object vtable logic + - properly map matches with well-known names against messages with unique names - longer term: * priority queues - * worker threads * priority inheritance * in the final killing spree, detect processes from the root directory, and @@ -64,12 +246,9 @@ Features: * Introduce a way how we can kill the main process of a service with KillSignal, but all processes with SIGKILL later on https://bugzilla.redhat.com/show_bug.cgi?id=952634 -* maybe add a warning to the unit file parses whern the acces mode of unit files is non-sensical. - -* investigate endianess issues of UUID vs. GUID +* maybe add a warning to the unit file parses where the access mode of unit files is nonsensical. -* see if we can fix https://bugs.freedesktop.org/show_bug.cgi?id=63672 - without dropping the location cache entirely. +* investigate endianness issues of UUID vs. GUID * dbus: when a unit failed to load (i.e. is in UNIT_ERROR state), we should be able to safely try another attempt when the bus call LoadUnit() is invoked. @@ -89,16 +268,12 @@ Features: * logind: add Suspend() bus calls which take timestamps to fix double suspend issues when somebody hits suspend and closes laptop quickly. -* we need dynamic units - * cgtop: make cgtop useful in a container * test/: - add 'set -e' to scripts in test/ - make stuff in test/ work with separate output dir - - remove all the duplicated code in test/ - -* suppress log output on shutdown when "quiet" is used + - qemu wrapper script: http://www.spinics.net/lists/kvm/msg72389.html * systemctl delete x.snapshot leaves no trace in logs (at least at default level). @@ -106,30 +281,18 @@ Features: so that the coredump is properly written to the user's own journal file. -* move /usr/lib/modules/$(uname -r)/modules.devname parsing from udevd to - kmod static-nodes - call kmod as an early service, and drop CAP_MKNOD from udevd.service - * seems that when we follow symlinks to units we prefer the symlink destination path over /etc and /usr. We shouldn't do that. Instead /etc should always override /run+/usr and also any symlink destination. -* remove duplicate default deps logic from fstab-generator vs. mount.c - * when isolating, try to figure out a way how we implicitly can order all units we stop before the isolating unit... -* teach udev + logind's uaccess to somehow handle the "dead" device nodes from: - /lib/modules/$(uname -r)/modules.devname - and apply ACLs to them if they have TAG=="uaccess" in udev rules. - * add ConditionArchitecture= or so * teach ConditionKernelCommandLine= globs or regexes (in order to match foobar={no,0,off}) -* we should log capabilities too - * Support SO_REUSEPORT with socket activation: - Let systemd maintain a pool of servers. - Use for seamless upgrades, by running the new server before stopping the @@ -150,7 +313,7 @@ Features: and we might want to requeue the mounts local-fs acquired through that automatically. -* rework specifier logic so that we can distuingish OOM errors from other errors +* rework specifier logic so that we can distinguish OOM errors from other errors * systemd-inhibit: make taking delay locks useful: support sending SIGINT or SIGTERM on PrepareForSleep() @@ -160,13 +323,13 @@ Features: * documentation: recommend to connect the timer units of a service to the service via Also= in [Install] -* add a tool that lists active timer units plus their next elapstion and the time the units ran last +* add a tool that lists active timer units plus their next elapse and the time the units ran last * man: document the very specific env the shutdown drop-in tools live in * shutdown logging: store to EFI var, and store to USB stick? -* man: extend runlevel(8) to mention that runlevels suck, and are dead. Maybe add runlevel(7) with a note about that too +* man: extend runlevel(8) to mention that runlevels suck, and are dead. Maybe add runlevel(7) with a note about that too * systemctl: maybe add "systemctl add-wants" or so... @@ -187,9 +350,6 @@ Features: * timedate: have global on/off switches for auto-time (NTP), and auto-timezone that connman can subscribe to. -* Honour "-" prefix for InaccessibleDirectories= and ReadOnlyDirectories= to - suppress errors of the specified path doesn't exist - * dev-setup.c: when running in a container, create a tiny stub udev database with the systemd tag set for all network interfaces found, so that libudev reports them as present, and systemd's .device units @@ -200,11 +360,10 @@ Features: * introduce ExecCondition= in services * EFI: - - fsck hookup for the ESP mount is missing - write man page for efi boot generator - honor language efi variables for default language selection (if there are any?) - honor timezone efi variables for default timezone selection (if there are any?) - - introduce bootctl (backed by systemd-bootd) to control temporary and persistent default boot goal plus efi variables + - change bootctl to be backed by systemd-bootd to control temporary and persistent default boot goal plus efi variables * maybe do not install getty@tty1.service symlink in /etc but in /usr? @@ -223,17 +382,13 @@ Features: - logind: wakelock/opportunistic suspend support - Add pretty name for seats in logind - logind: allow showing logout dialog from system? - - logind: spawn user@..service on login - logind: non-local X11 server handling - logind: add equivalent to sd_pid_get_owner_uid() to the D-Bus API - pam: when leaving a session explicitly exclude the ReleaseSession() caller process from the killing spree - - logind: GetSessionByPID() should accept 0 as PID value - we should probably handle SIGTERM/SIGINT to not leave dot files around, just in case * exec: when deinitializating a tty device fix the perms and group, too, not only when initializing. Set access mode/gid to 0620/tty. -* DeviceAllow/DeviceDeny: disallow everything by default, but whitelist /dev/zero, /dev/null and friends - * service: watchdog logic: for testing purposes allow ping, but do not require pong * journal: @@ -262,14 +417,13 @@ Features: - journal-send.c, log.c: when the log socket is clogged, and we drop, count this and write a message about this when it gets unclogged again. - journal: find a way to allow dropping history early, based on priority, other rules - journal: When used on NFS, check payload hashes - - Introduce journalctl -b to show journal messages of a previous boot - journald: check whether it is OK if the client can still modify delivered journal entries - journal live copy, based on libneon (client) and libmicrohttpd (server) - journald: add kernel cmdline option to disable ratelimiting for debug purposes - refuse taking lower-case variable names in sd_journal_send() and friends. - journald: we currently rotate only after MaxUse+MaxFilesize has been reached. - journal: deal nicely with byte-by-byte copied files, especially regards header - - journalctl: show multiline log messages sanely, expand tabs, and show all valid utf8 messages + - journalctl: expand tabs - journal: store euid in journal if it differs from uid - journal: sanely deal with entries which are larger than the individual file size, but where the components would fit - Replace utmp, wtmp, btmp, and lastlog completely with journal @@ -306,12 +460,13 @@ Features: * deal with sendmail/postfix exclusivity * timer units: - - configurable jitter for timer events - timer events with system resume - timer units should get the ability to trigger when: o CLOCK_REALTIME makes jumps (TFD_TIMER_CANCEL_ON_SET) o DST changes - Support 2012-02~4 as syntax for specifying the fourth to last day of the month. + - Modulate timer frequency based on battery state + - anacron-like feature * update the kernel's TZ (sys_tz) when DST changes @@ -322,10 +477,6 @@ Features: mode, it will never touch the RTC if the no reliable time source is active or the user did not request anything like it. -* hwdb: - - implement conditional properties (dmi matches) - - hwdb --filter=ID_DRIVE_* - * if booted in "quiet" mode, and an error happens, turn on status output again, so that the emergency mode isn't totally surprising. Also, terminate plymouth. @@ -386,6 +537,7 @@ Features: - nspawn: maybe add a way to drop additional caps, in addition to add additional caps - nspawn: maybe explicitly reset loginuid? - nspawn: make it work for dwalsh and shared /usr containers -- tmpfs mounts as command line parameters, selinux exec context + - refuses to boot containers without /etc/machine-id (OK?), and with empty /etc/machine-id (not OK). * cryptsetup: - cryptsetup-generator: allow specification of passwords in crypttab itself @@ -413,8 +565,6 @@ Features: * Query Paul Moore about relabelling socket fds while they are open -* system.conf should have controls for cgroups - * allow writing multiple conditions in unit files on one line * explore multiple service instances per listening socket idea @@ -432,8 +582,6 @@ Features: when done. That means clients don't get a successful method reply, but much rather a disconnect on success. -* remember which condition failed for services, not just the fact that something failed - * use opterr = 0 for all getopt tools * properly handle loop back mounts via fstab, especially regards to fsck/passno @@ -464,8 +612,6 @@ Features: * when breaking cycles drop sysv services first, then services from /run, then from /etc, then from /usr -* move passno parsing to fstab generator - * automount: implement expire: - set superblock timeout AUTOFS_DEV_IOCTL_TIMEOUT_CMD - periodically run AUTOFS_DEV_IOCTL_EXPIRE_CMD @@ -484,7 +630,6 @@ Features: * udev: - remove src/udev/udev-builtin-firmware.c (CONFIG_FW_LOADER_USER_HELPER=n) - move to LGPL - - unify utf8 validator code with shared/ - kill scsi_id - add trigger --subsystem-match=usb/usb_device device @@ -508,10 +653,6 @@ Features: * support crash reporting operation modes (https://live.gnome.org/GnomeOS/Design/Whiteboards/ProblemReporting) -* clean up session cgroups that remain after logout (think sshd), but eventually run empty - -* when an instanced service exits, remove its parent cgroup too if possible. - * default to actual 32bit PIDs, via /proc/sys/kernel/pid_max * be able to specify a forced restart of service A where service B depends on, in case B @@ -545,6 +686,8 @@ Features: when we start a service in order to avoid confusion when a user assumes starting a service is enough to make it accessible +* support User= and Group= attributes for AF_UNIX sockets. + * Make it possible to set the keymap independently from the font on the kernel cmdline. Right now setting one resets also the other. @@ -622,6 +765,14 @@ Features: - document initcall_debug - kernel cmdline "bootchart" option for simplicity? +* udev-link-config: + - Make sure ID_PATH is always exported and complete for + network devices where possible, so we can safely rely + on Path= matching + - NamePolicy= replace the current naming rules + - MACPolicy= support 'firmware', 'synthetic' and 'random' + - Check if Driver= is broken, or just my driver (bcma) + External: * dbus: