summaryrefslogtreecommitdiff
path: root/tmpfiles.d
Commit message (Collapse)AuthorAge
* namespace: include boot id in private tmp directoriesLennart Poettering2013-12-13
| | | | | | | | This way it is easy to only exclude directories from the current boot from automatic clean up in /var/tmp. Also, pick a longer name for the directories so that are globs in tmp.conf can be simpler yet equally accurate.
* tmpfiles: adjust excludes for the new per-service private dirsZbigniew Jędrzejewski-Szmek2013-11-16
| | | | | In d8c9d3a (systemd: use unit name in PrivateTmp directories) I forgot to update the tmpfiles config.
* tmpfiles.d: include setgid perms for /run/log/journalDave Reisner2013-10-02
| | | | | | | 4608af4333d0f7f5 set permissions for journal storage on persistent disk but not the volatile storage. ref: https://bugs.archlinux.org/task/37170
* Add a bit more explicit message, to help confused usersMichael Scherer2013-09-27
| | | | | | | Seeing http://www.happyassassin.net/2013/09/27/further-sysadmin-adventures-wheres-my-freeipa-badge/ it seems that the default message is a bit confusing for people who never encountered it before, so adding a link to the manpage could help them.
* journald: avoid NSS in journaldLennart Poettering2013-09-17
| | | | | | | | | | | | In order to avoid a deadlock between journald looking up the "systemd-journal" group name, and nscd (or anyother NSS backing daemon) logging something back to the journal avoid all NSS in journald the same way as we avoid it from PID 1. With this change we rely on the kernel file system logic to adjust the group of created journal files via the SETGID bit on the journal directory. To ensure that it is always set, even after the user created it with a simply "mkdir" on the shell we fix it up via tmpfiles on boot.
* machined: split out machine registration stuff from logindLennart Poettering2013-07-02
| | | | | | | Embedded folks don't need the machine registration stuff, hence it's nice to make this optional. Also, I'd expect that machinectl will grow additional commands quickly, for example to join existing containers and suchlike, hence it's better keeping that separate from loginctl.
* Make PrivateTmp dirs also inaccessible from the outsideZbigniew Jędrzejewski-Szmek2013-03-20
| | | | | | | | | | | Currently, PrivateTmp=yes means that the service cannot see the /tmp shared by rest of the system and is isolated from other services using PrivateTmp, but users can access and modify /tmp as seen by the service. Move the private /tmp and /var/tmp directories into a 0077-mode directory. This way unpriviledged users on the system cannot see (or modify) /tmp as seen by the service.
* tmpfiles: exclude /var/tmp/systemd-private-* tooZbigniew Jędrzejewski-Szmek2013-01-26
|
* tmpfiles: exclude /tmp/systemd-private-* from cleanupZbigniew Jędrzejewski-Szmek2013-01-25
| | | | | See http://thread.gmane.org/gmane.comp.sysutils.systemd.devel/6874/focus=6891 Should fix https://bugzilla.redhat.com/show_bug.cgi?id=866693
* tmpfiles: do not make /run/nologin executableMichał Bartoszkiewicz2013-01-19
|
* tmpfiles: move legacy flag-files handling to legacy.confTom Gundersen2013-01-07
|
* tmpfiles: write /run/nologin during early boot to disallow too early user loginsLennart Poettering2012-06-25
| | | | | systemd-user-sessoins.service will later on remove the flag file, thus permitting user logins when the time has come.
* tmpfiles: exclude the first level directories in /run/user from automatic ↵Lennart Poettering2012-06-20
| | | | | | | clean up It's logind's job to maintain those user dirs, so avoid automatic clean up for them. However, we do cover everything within them.
* relicense to LGPLv2.1 (with exceptions)Lennart Poettering2012-04-12
| | | | | | | | | | | | | | We finally got the OK from all contributors with non-trivial commits to relicense systemd from GPL2+ to LGPL2.1+. Some udev bits continue to be GPL2+ for now, but we are looking into relicensing them too, to allow free copy/paste of all code within systemd. The bits that used to be MIT continue to be MIT. The big benefit of the relicensing is that closed source code may now link against libsystemd-login.so and friends.
* shutdownd: rework interface, allow subscribing to scheduled shutdownsLennart Poettering2012-04-11
| | | | | | | | | | | This extends the shutdownd interface to expose schedule shutdown information in /run/systemd/shutdown/schedule. This also cleans up the shutdownd protocol and documents it in a header file sd-shutdown.h. This is supposed to be used by client code that wants to control and monitor scheduled shutdown.
* journal: add preliminary incomplete implementationLennart Poettering2011-10-07
|
* tmpfiles: Move /tmp and /var/tmp to a separate tmpfiles.d file to ease ↵Josh Triplett2011-08-24
| | | | | | | | | | | | | | | overrides via /etc Many people prefer to avoid clearing /tmp and /var/tmp, and distributions often have explicit settings for how often to clear them if at all. Overriding those with systemd currently requires overriding all of /usr/lib/tmpfiles.d/systemd.conf via /etc/tmpfiles.d/systemd.conf, copying across all the other entries, and updating that override when systemd.conf changes. Move the /tmp and /var/tmp entries from systemd.conf to a separate tmp.conf, making them easier to override without affecting the rest of systemd.conf.
* tmpfiles: Remove X11 lock files for displays :10 and higher tooJosh Triplett2011-08-24
|
* sd-login: beef up login api, to add monitoring and enumeratingLennart Poettering2011-07-22
|
* path: optionally, create watched directories in .path unitsLennart Poettering2011-04-10
|
* move /var/lock to HAVE_SYSV_COMPATKay Sievers2011-04-03
|
* tmpfiles: split off rules for legacy systems into legacy.confLennart Poettering2011-04-02
|
* tmpfiles: enforce new /var/lock semanticsLennart Poettering2011-04-01
| | | | http://lists.freedesktop.org/archives/systemd-devel/2011-March/001823.html
* tmpfiles fix /run/lock permissionsKay Sievers2011-03-29
| | | | | | <mbiebl> kay: just wondering: d /run/lock 0755 root lock - <mbiebl> shouldn't that rather be 0775? <mbiebl> otherwise it doesn't make sense
* use /run instead of /dev/.runKay Sievers2011-03-28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Instead of the /dev/.run trick we have currently implemented, we decided to move the early-boot runtime dir to /run. An existing /var/run directory is bind-mounted to /run. If /var/run is already a symlink, no action is taken. An existing /var/lock directory is bind-mounted to /run/lock. If /var/lock is already a symlink, no action is taken. To implement the directory vs. symlink logic, we have a: ConditionPathIsDirectory= now, which is used in the mount units. Skipped mount unit in case of symlink: $ systemctl status var-run.mount var-run.mount - Runtime Directory Loaded: loaded (/lib/systemd/system/var-run.mount) Active: inactive (dead) start condition failed at Fri, 25 Mar 2011 04:51:41 +0100; 6min ago Where: /var/run What: /run CGroup: name=systemd:/system/var-run.mount The systemd rpm needs to make sure to add something like: %pre mkdir -p -m0755 /run >/dev/null 2>&1 || : or it needs to be added to filesystem.rpm. Udev -git already uses /run if that exists, and is writable at bootup. Otherwise it falls back to the current /dev/.udev. Dracut and plymouth need to be adopted to switch from /dev/.run to run too. Cheers, Kay
* tmpfiles: simplify default tmpfiles configuration by using globsLennart Poettering2011-02-13
|
* tmpfiles: include reference to man page in tmpfiles filesLennart Poettering2010-11-10
|
* tmpfiles: Don't clean /var/lock/subsys; it is not aged contentBill Nottingham2010-10-25
| | | | It will get 'cleaned' on boot due to being tmpfs anyway.
* tmpfiles: Make wtmp match utmp perms, and add btmp.Bill Nottingham2010-10-25
|
* tmpfiles: remove forcefsck/fastboot flag files after bootLennart Poettering2010-10-19
|
* tmpfiles: integrate kay's directory cleanup code and otherwise beef up ↵Lennart Poettering2010-10-18
| | | | tmpfiles quite a bit
* tmpfiles: install default tmpfiles configurationLennart Poettering2010-09-28