From 90ad0890562fb67efc797211a2fb963529f8c9d9 Mon Sep 17 00:00:00 2001 From: Gitea Date: Fri, 16 Feb 2024 15:38:16 +0100 Subject: [PATCH] committing changes in /etc after apt run Package changes: +cgroupfs-mount 1.4 all +containerd 1.6.20~ds1-1+b1 amd64 +criu 3.17.1-2 amd64 +docker.io 20.10.24+dfsg1-1+b3 amd64 +libintl-perl 1.33-1 all +libintl-xs-perl 1.33-1 amd64 +libmodule-find-perl 0.16-2 all +libmodule-scandeps-perl 1.31-2 all +libnet1 1.1.6+dfsg-3.2 amd64 +libnftables1 1.0.6-2+deb12u2 amd64 +libproc-processtable-perl 0.634-1+b2 amd64 +libprotobuf32 3.21.12-3 amd64 +libsort-naturally-perl 1.03-4 all +needrestart 3.6-4+deb12u1 all +python3-protobuf 3.21.12-3 amd64 +runc 1.1.5+ds1-1+deb12u1 amd64 +tini 0.19.0-1 amd64 --- .etckeeper | 33 ++- apt/apt.conf.d/99needrestart | 8 + containerd/config.toml | 9 + default/docker | 12 + docker/key.json | 1 + dpkg/dpkg.cfg.d/needrestart | 7 + group | 1 + group- | 3 +- gshadow | 1 + gshadow- | 1 + init.d/cgroupfs-mount | 76 ++++++ init.d/docker | 143 +++++++++++ needrestart/conf.d/README.needrestart | 5 + needrestart/hook.d/10-dpkg | 87 +++++++ needrestart/hook.d/20-rpm | 82 +++++++ needrestart/hook.d/90-none | 63 +++++ needrestart/iucode.sh | 16 ++ needrestart/needrestart.conf | 223 ++++++++++++++++++ needrestart/notify.conf | 20 ++ needrestart/notify.d/200-write | 44 ++++ needrestart/notify.d/400-notify-send | 57 +++++ needrestart/notify.d/600-mail | 48 ++++ needrestart/notify.d/README.needrestart | 28 +++ needrestart/restart.d/README.needrestart | 12 + needrestart/restart.d/dbus.service | 81 +++++++ needrestart/restart.d/systemd-manager | 13 + needrestart/restart.d/sysv-init | 13 + rc0.d/K01cgroupfs-mount | 1 + rc0.d/K01docker | 1 + rc1.d/K01cgroupfs-mount | 1 + rc1.d/K01docker | 1 + rc2.d/S01cgroupfs-mount | 1 + rc2.d/S01docker | 1 + rc3.d/S01cgroupfs-mount | 1 + rc3.d/S01docker | 1 + rc4.d/S01cgroupfs-mount | 1 + rc4.d/S01docker | 1 + rc5.d/S01cgroupfs-mount | 1 + rc5.d/S01docker | 1 + rc6.d/K01cgroupfs-mount | 1 + rc6.d/K01docker | 1 + .../containerd.service | 1 + .../multi-user.target.wants/docker.service | 1 + .../system/sockets.target.wants/docker.socket | 1 + 44 files changed, 1102 insertions(+), 2 deletions(-) create mode 100644 apt/apt.conf.d/99needrestart create mode 100644 containerd/config.toml create mode 100644 default/docker create mode 100644 docker/key.json create mode 100644 dpkg/dpkg.cfg.d/needrestart create mode 100755 init.d/cgroupfs-mount create mode 100755 init.d/docker create mode 100644 needrestart/conf.d/README.needrestart create mode 100755 needrestart/hook.d/10-dpkg create mode 100755 needrestart/hook.d/20-rpm create mode 100755 needrestart/hook.d/90-none create mode 100644 needrestart/iucode.sh create mode 100644 needrestart/needrestart.conf create mode 100644 needrestart/notify.conf create mode 100755 needrestart/notify.d/200-write create mode 100755 needrestart/notify.d/400-notify-send create mode 100755 needrestart/notify.d/600-mail create mode 100644 needrestart/notify.d/README.needrestart create mode 100644 needrestart/restart.d/README.needrestart create mode 100755 needrestart/restart.d/dbus.service create mode 100755 needrestart/restart.d/systemd-manager create mode 100755 needrestart/restart.d/sysv-init create mode 120000 rc0.d/K01cgroupfs-mount create mode 120000 rc0.d/K01docker create mode 120000 rc1.d/K01cgroupfs-mount create mode 120000 rc1.d/K01docker create mode 120000 rc2.d/S01cgroupfs-mount create mode 120000 rc2.d/S01docker create mode 120000 rc3.d/S01cgroupfs-mount create mode 120000 rc3.d/S01docker create mode 120000 rc4.d/S01cgroupfs-mount create mode 120000 rc4.d/S01docker create mode 120000 rc5.d/S01cgroupfs-mount create mode 120000 rc5.d/S01docker create mode 120000 rc6.d/K01cgroupfs-mount create mode 120000 rc6.d/K01docker create mode 120000 systemd/system/multi-user.target.wants/containerd.service create mode 120000 systemd/system/multi-user.target.wants/docker.service create mode 120000 systemd/system/sockets.target.wants/docker.socket diff --git a/.etckeeper b/.etckeeper index fe3adfdf..9f2998e8 100755 --- a/.etckeeper +++ b/.etckeeper @@ -14,10 +14,10 @@ mkdir -p './calendar' mkdir -p './clamav/onerrorexecute.d' mkdir -p './clamav/onupdateexecute.d' mkdir -p './clamav/virusevent.d' +mkdir -p './cni/net.d' mkdir -p './dbus-1/session.d' mkdir -p './dbus-1/system.d' mkdir -p './dkms/framework.conf.d' -mkdir -p './dpkg/dpkg.cfg.d' mkdir -p './fail2ban/fail2ban.d' mkdir -p './gss/mech.d' mkdir -p './initramfs-tools/hooks' @@ -335,6 +335,7 @@ maybe chmod 0644 'apt/apt.conf.d/20listchanges' maybe chmod 0644 'apt/apt.conf.d/50unattended-upgrades' maybe chmod 0644 'apt/apt.conf.d/70debconf' maybe chmod 0644 'apt/apt.conf.d/90rkhunter' +maybe chmod 0644 'apt/apt.conf.d/99needrestart' maybe chmod 0755 'apt/auth.conf.d' maybe chmod 0755 'apt/keyrings' maybe chmod 0644 'apt/keyrings/rspamd.gpg' @@ -440,6 +441,8 @@ maybe chmod 0644 'cloud/templates/sources.list.ubuntu.tmpl' maybe chmod 0644 'cloud/templates/systemd.resolved.conf.tmpl' maybe chmod 0644 'cloud/templates/timesyncd.conf.tmpl' maybe chmod 0600 'cmk-update-agent.state' +maybe chmod 0755 'cni' +maybe chmod 0700 'cni/net.d' maybe chmod 0755 'console-setup' maybe chmod 0644 'console-setup/cached_Lat15-Fixed16.psf.gz' maybe chmod 0644 'console-setup/cached_Lat15-VGA16.psf.gz' @@ -475,6 +478,8 @@ maybe chmod 0644 'console-setup/compose.KOI8-U.inc' maybe chmod 0644 'console-setup/compose.TIS-620.inc' maybe chmod 0644 'console-setup/compose.VISCII.inc' maybe chmod 0644 'console-setup/remap.inc' +maybe chmod 0755 'containerd' +maybe chmod 0644 'containerd/config.toml' maybe chmod 0755 'cracklib' maybe chmod 0644 'cracklib/cracklib.conf' maybe chmod 0700 'cron.d' @@ -530,6 +535,7 @@ maybe chmod 0644 'default/console-setup' maybe chmod 0644 'default/cron' maybe chmod 0644 'default/dbus' maybe chmod 0644 'default/debsums' +maybe chmod 0644 'default/docker' maybe chmod 0644 'default/dovecot' maybe chmod 0644 'default/fail2ban' maybe chmod 0644 'default/grub' @@ -579,6 +585,8 @@ maybe chmod 0644 'dkms/framework.conf' maybe chmod 0755 'dkms/framework.conf.d' maybe chmod 0755 'dkms/template-dkms-mkdeb' maybe chmod 0755 'dkms/template-dkms-mkdeb/debian' +maybe chmod 0755 'docker' +maybe chmod 0600 'docker/key.json' maybe chmod 0755 'dovecot' maybe chmod 0755 'dovecot/conf.d' maybe chmod 0644 'dovecot/conf.d/10-auth.conf' @@ -626,6 +634,7 @@ maybe chmod 0644 'dovecot/ssl-params.conf' maybe chmod 0755 'dpkg' maybe chmod 0644 'dpkg/dpkg.cfg' maybe chmod 0755 'dpkg/dpkg.cfg.d' +maybe chmod 0644 'dpkg/dpkg.cfg.d/needrestart' maybe chmod 0755 'dpkg/origins' maybe chmod 0644 'dpkg/origins/debian' maybe chmod 0644 'dpkg/shlibs.default' @@ -947,6 +956,7 @@ maybe chmod 0755 'init.d/amavis' maybe chmod 0755 'init.d/amavis-mc' maybe chmod 0755 'init.d/amavisd-snmp-subagent' maybe chmod 0755 'init.d/apparmor' +maybe chmod 0755 'init.d/cgroupfs-mount' maybe chmod 0755 'init.d/clamav-daemon' maybe chmod 0755 'init.d/clamav-freshclam' maybe chmod 0755 'init.d/cloud-config' @@ -956,6 +966,7 @@ maybe chmod 0755 'init.d/cloud-init-local' maybe chmod 0755 'init.d/console-setup.sh' maybe chmod 0755 'init.d/cron' maybe chmod 0755 'init.d/dbus' +maybe chmod 0755 'init.d/docker' maybe chmod 0755 'init.d/dovecot' maybe chmod 0755 'init.d/fail2ban' maybe chmod 0755 'init.d/firewall' @@ -2809,6 +2820,26 @@ maybe chmod 0644 'mysql/mariadb.conf.d/provider_snappy.cnf' maybe chmod 0755 'myssl' maybe chmod 0644 'myssl/dh4096.pem' maybe chmod 0644 'nanorc' +maybe chmod 0755 'needrestart' +maybe chmod 0755 'needrestart/conf.d' +maybe chmod 0644 'needrestart/conf.d/README.needrestart' +maybe chmod 0755 'needrestart/hook.d' +maybe chmod 0755 'needrestart/hook.d/10-dpkg' +maybe chmod 0755 'needrestart/hook.d/20-rpm' +maybe chmod 0755 'needrestart/hook.d/90-none' +maybe chmod 0644 'needrestart/iucode.sh' +maybe chmod 0644 'needrestart/needrestart.conf' +maybe chmod 0644 'needrestart/notify.conf' +maybe chmod 0755 'needrestart/notify.d' +maybe chmod 0755 'needrestart/notify.d/200-write' +maybe chmod 0755 'needrestart/notify.d/400-notify-send' +maybe chmod 0755 'needrestart/notify.d/600-mail' +maybe chmod 0644 'needrestart/notify.d/README.needrestart' +maybe chmod 0755 'needrestart/restart.d' +maybe chmod 0644 'needrestart/restart.d/README.needrestart' +maybe chmod 0755 'needrestart/restart.d/dbus.service' +maybe chmod 0755 'needrestart/restart.d/systemd-manager' +maybe chmod 0755 'needrestart/restart.d/sysv-init' maybe chmod 0644 'netconfig' maybe chmod 0755 'network' maybe chmod 0755 'network/if-down.d' diff --git a/apt/apt.conf.d/99needrestart b/apt/apt.conf.d/99needrestart new file mode 100644 index 00000000..1c6639c1 --- /dev/null +++ b/apt/apt.conf.d/99needrestart @@ -0,0 +1,8 @@ +# needrestart - Restart daemons after library updates. +# +# Call needrestart after package upgrades/installations and check +# for pending service restarts. Should only be triggered if there +# was no error during installation. +# + +DPkg::Post-Invoke {"test -x /usr/lib/needrestart/apt-pinvoke && /usr/lib/needrestart/apt-pinvoke || true"; }; diff --git a/containerd/config.toml b/containerd/config.toml new file mode 100644 index 00000000..1196bbd1 --- /dev/null +++ b/containerd/config.toml @@ -0,0 +1,9 @@ +version = 2 + +[plugins] + [plugins."io.containerd.grpc.v1.cri"] + [plugins."io.containerd.grpc.v1.cri".cni] + bin_dir = "/usr/lib/cni" + conf_dir = "/etc/cni/net.d" + [plugins."io.containerd.internal.v1.opt"] + path = "/var/lib/containerd/opt" diff --git a/default/docker b/default/docker new file mode 100644 index 00000000..ba4d332c --- /dev/null +++ b/default/docker @@ -0,0 +1,12 @@ +# Here in Debian, this file is sourced by: +# - /etc/init.d/docker (sysvinit) +# - /etc/init/docker (upstart) +# - systemd's docker.service + +# Use of this file for configuring your Docker daemon is discouraged. + +# The recommended alternative is "/etc/docker/daemon.json", as described in: +# https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-configuration-file + +# If that does not suit your needs, try a systemd drop-in file, as described in: +# https://docs.docker.com/config/daemon/systemd/ diff --git a/docker/key.json b/docker/key.json new file mode 100644 index 00000000..988574c6 --- /dev/null +++ b/docker/key.json @@ -0,0 +1 @@ +{"crv":"P-256","d":"Uvv3AXYbks_QpmLqb0be3uvb1RSwxYdOwSk1r-y9O-E","kid":"OSKX:7ZDK:MLRA:24MM:K7AM:TJB5:TVTB:5NR5:IXAY:R3ZO:OQ5Z:DAYP","kty":"EC","x":"mTwLpudBvkuqMcUV-IMmgRhLvN0AK3muTOO0cJA118o","y":"o35DWCg7TwCGPeIQXTXX6XAZcmCH0N40JYX4b8uezlI"} \ No newline at end of file diff --git a/dpkg/dpkg.cfg.d/needrestart b/dpkg/dpkg.cfg.d/needrestart new file mode 100644 index 00000000..2477d13a --- /dev/null +++ b/dpkg/dpkg.cfg.d/needrestart @@ -0,0 +1,7 @@ +# needrestart - Restart daemons after library updates. +# +# Scan for (successfully) installed packages, +# triggers needrestart in apt's Dpkg::Post-Invoke +# hook. + +status-logger=(test -x /usr/lib/needrestart/dpkg-status && /usr/lib/needrestart/dpkg-status || cat > /dev/null) diff --git a/group b/group index d55b4d44..0d61e6b8 100644 --- a/group +++ b/group @@ -73,3 +73,4 @@ sgx:x:128: plocate:x:129: _ssh:x:111: ntpsec:x:130: +docker:x:131: diff --git a/group- b/group- index 237740c0..d55b4d44 100644 --- a/group- +++ b/group- @@ -50,7 +50,7 @@ messagebus:x:110: systemd-coredump:x:999: caelebfi:x:1000: mysql:x:112: -redis:x:113:_rspamd +redis:x:113:_rspamd,www-data ssl-cert:x:114: ntp:x:115: postfix:x:116: @@ -72,3 +72,4 @@ zerotier-one:x:997: sgx:x:128: plocate:x:129: _ssh:x:111: +ntpsec:x:130: diff --git a/gshadow b/gshadow index b402af8e..8ef7d6f2 100644 --- a/gshadow +++ b/gshadow @@ -73,3 +73,4 @@ sgx:!:: plocate:!:: _ssh:!:: ntpsec:!:: +docker:!:: diff --git a/gshadow- b/gshadow- index 99ed0054..b402af8e 100644 --- a/gshadow- +++ b/gshadow- @@ -72,3 +72,4 @@ zerotier-one:!:: sgx:!:: plocate:!:: _ssh:!:: +ntpsec:!:: diff --git a/init.d/cgroupfs-mount b/init.d/cgroupfs-mount new file mode 100755 index 00000000..5651d2d4 --- /dev/null +++ b/init.d/cgroupfs-mount @@ -0,0 +1,76 @@ +#!/bin/sh +set -e + +### BEGIN INIT INFO +# Provides: cgroupfs-mount +# Required-Start: $syslog $remote_fs +# Required-Stop: $syslog $remote_fs +# Default-Start: 2 3 4 5 +# Default-Stop: 0 1 6 +# Short-Description: Set up cgroupfs mounts. +# Description: +# Control groups are a kernel mechanism for tracking and imposing +# limits on resource usage on groups of tasks. +### END INIT INFO + +BASE=cgroupfs-mount + +# Test for systemd and bail (we have to test before sourcing init-functions, or systemd hijacks us) +# We bail because systemd already mounts cgroups sanely, so we just silently pretend we were successful in mounting them here +if [ -d /run/systemd/system ]; then + exit 0 +fi + +# Get lsb functions +. /lib/lsb/init-functions + +if [ -f /etc/default/$BASE ]; then + . /etc/default/$BASE +fi + +# see also init_is_upstart in /lib/lsb/init-functions (which isn't available in Ubuntu 12.04, or we'd use it) +if [ -x /sbin/initctl ] && /sbin/initctl version 2>/dev/null | /bin/grep -q upstart; then + log_failure_msg "$BASE is managed via upstart, try using service $BASE $1" + exit 1 +fi + +case "$1" in + start) + test -x /usr/bin/cgroupfs-mount || exit 0 + log_begin_msg 'Mounting cgroupfs hierarchy' + /usr/bin/cgroupfs-mount + log_end_msg $? + ;; + + stop) + test -x /usr/bin/cgroupfs-umount || exit 0 + log_begin_msg 'Unmounting cgroupfs hierarchy' + /usr/bin/cgroupfs-umount + log_end_msg $? + ;; + + restart|force-reload) + if mountpoint -q /sys/fs/cgroup; then + $0 stop + fi + exec $0 start + ;; + + status) + if mountpoint -q /sys/fs/cgroup; then + # TODO decide whether to detect "partial mounted" status (ie, whether all available subsystems are mounted correctly) + log_success_msg 'cgroupfs hierarchy is mounted' + exit 0 + else + log_failure_msg 'cgroupfs hierarchy is not mounted' + exit 1 + fi + ;; + + *) + echo "Usage: $0 {start|stop|restart|status}" + exit 1 + ;; +esac + +exit 0 diff --git a/init.d/docker b/init.d/docker new file mode 100755 index 00000000..f4fcb77b --- /dev/null +++ b/init.d/docker @@ -0,0 +1,143 @@ +#!/bin/sh +set -e + +### BEGIN INIT INFO +# Provides: docker +# Required-Start: $syslog $remote_fs +# Required-Stop: $syslog $remote_fs +# Should-Start: cgroupfs-mount cgroup-lite +# Should-Stop: cgroupfs-mount cgroup-lite +# Default-Start: 2 3 4 5 +# Default-Stop: 0 1 6 +# Short-Description: Create lightweight, portable, self-sufficient containers. +# Description: +# Docker is an open-source project to easily create lightweight, portable, +# self-sufficient containers from any application. The same container that a +# developer builds and tests on a laptop can run at scale, in production, on +# VMs, bare metal, OpenStack clusters, public clouds and more. +### END INIT INFO + +export PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin + +BASE=docker + +# modify these in /etc/default/$BASE (/etc/default/docker) +DOCKERD=/usr/sbin/dockerd +# This is the pid file managed by docker itself +DOCKER_PIDFILE=/var/run/$BASE.pid +# This is the pid file created/managed by start-stop-daemon +DOCKER_SSD_PIDFILE=/var/run/$BASE-ssd.pid +DOCKER_LOGFILE=/var/log/$BASE.log +DOCKER_OPTS= +DOCKER_DESC="Docker" + +# Get lsb functions +. /lib/lsb/init-functions + +if [ -f /etc/default/$BASE ]; then + . /etc/default/$BASE +fi + +# Check docker is present +if [ ! -x $DOCKERD ]; then + log_failure_msg "$DOCKERD not present or not executable" + exit 1 +fi + +fail_unless_root() { + if [ "$(id -u)" != '0' ]; then + log_failure_msg "$DOCKER_DESC must be run as root" + exit 1 + fi +} + +cgroupfs_mount() { + # see also https://github.com/tianon/cgroupfs-mount/blob/master/cgroupfs-mount + if grep -v '^#' /etc/fstab | grep -q cgroup \ + || [ ! -e /proc/cgroups ] \ + || [ ! -d /sys/fs/cgroup ]; then + return + fi + if ! mountpoint -q /sys/fs/cgroup; then + mount -t tmpfs -o uid=0,gid=0,mode=0755 cgroup /sys/fs/cgroup + fi + ( + cd /sys/fs/cgroup + for sys in $(awk '!/^#/ { if ($4 == 1) print $1 }' /proc/cgroups); do + mkdir -p $sys + if ! mountpoint -q $sys; then + if ! mount -n -t cgroup -o $sys cgroup $sys; then + rmdir $sys || true + fi + fi + done + ) +} + +case "$1" in + start) + fail_unless_root + + cgroupfs_mount + + touch "$DOCKER_LOGFILE" + chgrp docker "$DOCKER_LOGFILE" + + ulimit -n 1048576 + + # Having non-zero limits causes performance problems due to accounting overhead + # in the kernel. We recommend using cgroups to do container-local accounting. + if [ "$BASH" ]; then + ulimit -u unlimited + else + ulimit -p unlimited + fi + + log_begin_msg "Starting $DOCKER_DESC: $BASE" + $0 status >>/dev/null \ + || start-stop-daemon --start --background \ + --no-close \ + --exec "$DOCKERD" \ + --pidfile "$DOCKER_SSD_PIDFILE" \ + --make-pidfile \ + -- \ + -p "$DOCKER_PIDFILE" \ + $DOCKER_OPTS \ + >> "$DOCKER_LOGFILE" 2>&1 + log_end_msg $? + ;; + + stop) + fail_unless_root + if [ -f "$DOCKER_SSD_PIDFILE" ]; then + log_begin_msg "Stopping $DOCKER_DESC: $BASE" + start-stop-daemon --stop --pidfile "$DOCKER_SSD_PIDFILE" --remove-pidfile --retry 10 + log_end_msg $? + else + log_warning_msg "Docker already stopped - file $DOCKER_SSD_PIDFILE not found." + fi + ;; + + restart) + fail_unless_root + docker_pid=$(cat "$DOCKER_SSD_PIDFILE" 2> /dev/null) + [ -n "$docker_pid" ] \ + && ps -p $docker_pid > /dev/null 2>&1 \ + && $0 stop + $0 start + ;; + + force-reload) + fail_unless_root + $0 restart + ;; + + status) + status_of_proc -p "$DOCKER_SSD_PIDFILE" "$DOCKERD" "$DOCKER_DESC" + ;; + + *) + echo "Usage: service docker {start|stop|restart|status}" + exit 1 + ;; +esac diff --git a/needrestart/conf.d/README.needrestart b/needrestart/conf.d/README.needrestart new file mode 100644 index 00000000..5a1649cb --- /dev/null +++ b/needrestart/conf.d/README.needrestart @@ -0,0 +1,5 @@ +Files ending with .conf and located in the /etc/needrestart/conf.d +directory are parsed by needrestart's default configuration file. + +Files are parsed in order (using Perl's sort sub) and override or +modify any previously set config option. diff --git a/needrestart/hook.d/10-dpkg b/needrestart/hook.d/10-dpkg new file mode 100755 index 00000000..7705472d --- /dev/null +++ b/needrestart/hook.d/10-dpkg @@ -0,0 +1,87 @@ +#!/usr/bin/perl + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this package; if not, write to the Free Software +# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA +# + +# This DPKG hook tries to find the run-level scripts of the package's binary +# which has old libraries in use. Some logic is taken from the checkrestart +# (part of the debian-goodies package) package by Matt Zimmerman , +# Javier Fernandez-Sanguino et. al. + +use Getopt::Std; + +use strict; +use warnings; + +system("type dpkg-query 1> /dev/null 2> /dev/null"); +exit 0 if ($? != -1 && $? >> 8); + +our $opt_v; +getopts('v'); + +sub fork_pipe(@) { + my $pid = open(HPIPE, '-|'); + defined($pid) || die "Can't fork: $!\n"; + + if($pid == 0) { + close(STDIN); + close(STDERR) unless($opt_v); + + exec(@_); + exit; + } + + \*HPIPE +} + +my $FN = shift || die "Usage: $0 \n"; +my $psearch = fork_pipe(qw(dpkg-query --search), $FN); + +my @pkgs; +while(<$psearch>) { + chomp; + + next if(/^local diversion/); + next unless(/:/); + + next unless(/(\S+): $FN$/); + + push(@pkgs, $1); +} +close($psearch); + +exit(0) unless($#pkgs > -1); + +foreach my $pkg (@pkgs) { + print "PACKAGE|$pkg\n"; + + my $plist = fork_pipe(qw(dpkg-query --listfiles), $pkg); + while(<$plist>) { + chomp; + print "RC|$1\n" if(m@^/etc/init.d/(.+)$@ && -x $_); + } + close($plist); +} + +exit(1); diff --git a/needrestart/hook.d/20-rpm b/needrestart/hook.d/20-rpm new file mode 100755 index 00000000..fc5f769f --- /dev/null +++ b/needrestart/hook.d/20-rpm @@ -0,0 +1,82 @@ +#!/usr/bin/perl + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this package; if not, write to the Free Software +# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA +# + +# This RPM hook tries to find the run-level scripts of the package's binary +# which has old libraries in use. + +use Getopt::Std; + +use strict; +use warnings; + +system("type rpm 1> /dev/null 2> /dev/null"); +exit 0 if ($? != -1 && $? >> 8); + +our $opt_v; +getopts('c:v'); + +sub fork_pipe(@) { + my $pid = open(HPIPE, '-|'); + defined($pid) || die "Can't fork: $!\n"; + + if($pid == 0) { + close(STDIN); + close(STDERR) unless($opt_v); + + exec(@_); + exit; + } + + \*HPIPE +} + +my $FN = shift || die "Usage: $0 \n"; +my $psearch = fork_pipe(qw(rpm -q --file), $FN); + +my @pkgs; +while(<$psearch>) { + chomp; + + next if(/^file .+ is not owned by any package/); + + push(@pkgs, $_); +} +close($psearch); + +exit(0) unless($#pkgs > -1); + +foreach my $pkg (@pkgs) { + print "PACKAGE|$pkg\n"; + + my $plist = fork_pipe(qw(rpm -q --filesbypkg), $pkg); + while(<$plist>) { + chomp; + print "RC|$2\n" if(m@^\S+\s+/etc(/rc\.d)?/init\.d/(.+)$@ && -x $_); + } + close($plist); +} + +exit(1); diff --git a/needrestart/hook.d/90-none b/needrestart/hook.d/90-none new file mode 100755 index 00000000..06357248 --- /dev/null +++ b/needrestart/hook.d/90-none @@ -0,0 +1,63 @@ +#!/usr/bin/perl + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this package; if not, write to the Free Software +# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA +# + +# This fallback hook tries the guess the rc script name from the binary name. +# It might work with programs which are not installed via an (supported) +# package manager like dpkg or rpm. + +use Getopt::Std; + +use strict; +use warnings; + +our $opt_v; +getopts('c:v'); + +sub check_rc($) { + my $bn = shift; + my $rc = "/etc/init.d/$bn"; + + return ($bn) if(-x $rc); + + return (); +} + +my $FN = shift || die "Usage: $0 \n"; + +$FN =~ m@/(([^/]+)d?)$@; + +my @rc; +push(@rc, check_rc($1)); +push(@rc, check_rc($2)) if($1 ne $2); + +exit(0) unless($#rc > -1); + +foreach my $rc (@rc) { + print "PACKAGE|$rc\n"; + print "RC|$rc\n"; +} + +exit(1); diff --git a/needrestart/iucode.sh b/needrestart/iucode.sh new file mode 100644 index 00000000..48c0267b --- /dev/null +++ b/needrestart/iucode.sh @@ -0,0 +1,16 @@ +# needrestart - Restart daemons after library updates. +# +# This shell script is sourced in /usr/lib/needrestart/iucode-scan-versions +# before calling iucode_tool to detect microcode updates for Intel CPUs. +# +# If required you may exec iucode_tool with customized parameters. You should +# keep the `-l $filter` option and add a final exit statement in case the +# exec call fails. + +# Example (generic): +# exec iucode_tool -l $filter --ignore-broken -tb /lib/firmware/intel-ucode -ta /usr/share/misc/intel-microcode* 2>&1 +# exit $? + +# Example (RHEL and derivatives): +# lsinitrd -f kernel/x86/microcode/GenuineIntel.bin | iucode_tool -t b -l - +# exit $? diff --git a/needrestart/needrestart.conf b/needrestart/needrestart.conf new file mode 100644 index 00000000..6ee72dbe --- /dev/null +++ b/needrestart/needrestart.conf @@ -0,0 +1,223 @@ +# needrestart - Restart daemons after library updates. +# +# This is the configuration file of needrestart. This is perl syntax. +# needrestart uses reasonable default values, you might not need to +# change anything. +# + +# Verbosity: +# 0 => quiet +# 1 => normal (default) +# 2 => verbose +#$nrconf{verbosity} = 2; + +# Path of the package manager hook scripts. +#$nrconf{hook_d} = '/etc/needrestart/hook.d'; + +# Path of user notification scripts. +#$nrconf{notify_d} = '/etc/needrestart/notify.d'; + +# Path of restart scripts. +#$nrconf{restart_d} = '/etc/needrestart/restart.d'; + +# Disable sending notifications to user sessions running obsolete binaries +# using scripts from $nrconf{notify_d}. +#$nrconf{sendnotify} = 0; + +# If needrestart detects systemd it assumes that you use systemd's pam module. +# This allows needrestart to easily detect user session. In case you use +# systemd *without* pam_systemd.so you should set has_pam_systemd to false +# to enable legacy session detection! +#$nrconf{has_pam_systemd} = 0; + +# Restart mode: (l)ist only, (i)nteractive or (a)utomatically. +# +# ATTENTION: If needrestart is configured to run in interactive mode but is run +# non-interactive (i.e. unattended-upgrades) it will fallback to list only mode. +# +#$nrconf{restart} = 'i'; + +# Use preferred UI package. +#$nrconf{ui} = 'NeedRestart::UI::stdio'; + +# Change default answer to 'no' in (i)nteractive mode. +#$nrconf{defno} = 1; + +# Set UI mode to (e)asy or (a)dvanced. +#$nrconf{ui_mode} = 'e'; + +# Print a combined `systemctl restart` command line for skipped services. +#$nrconf{systemctl_combine} = 1; + +# Blacklist binaries (list of regex). +$nrconf{blacklist} = [ + # ignore sudo (not a daemon) + qr(^/usr/bin/sudo(\.dpkg-new)?$), + + # ignore DHCP clients + qr(^/sbin/(dhclient|dhcpcd5|pump|udhcpc)(\.dpkg-new)?$), + + # ignore apt-get (Debian Bug#784237) + qr(^/usr/bin/apt-get(\.dpkg-new)?$), +]; + +# Blacklist services (list of regex) - USE WITH CARE. +# You should prefer to put services to $nrconf{override_rc} instead. +# Any service listed in $nrconf{blacklist_rc} will be ignored completely! +#$nrconf{blacklist_rc} = [ +#]; + +# Override service default selection (hash of regex). +$nrconf{override_rc} = { + # DBus + qr(^dbus) => 0, + + # display managers + qr(^gdm) => 0, + qr(^kdm) => 0, + qr(^nodm) => 0, + qr(^sddm) => 0, + qr(^wdm) => 0, + qr(^xdm) => 0, + qr(^lightdm) => 0, + qr(^slim) => 0, + qr(^lxdm) => 0, + + # networking stuff + qr(^bird) => 0, + qr(^network) => 0, + qr(^NetworkManager) => 0, + qr(^ModemManager) => 0, + qr(^wpa_supplicant) => 0, + qr(^openvpn) => 0, + qr(^quagga) => 0, + qr(^frr) => 0, + qr(^tinc) => 0, + qr(^(open|free|libre|strong)swan) => 0, + qr(^bluetooth) => 0, + + # gettys + qr(^getty@.+\.service) => 0, + qr(^serial-getty@.+\.service) => 0, + + # systemd --user + qr(^user@\d+\.service) => 0, + + # misc + qr(^zfs-fuse) => 0, + qr(^mythtv-backend) => 0, + qr(^xendomains) => 0, + qr(^lxcfs) => 0, + qr(^libvirt) => 0, + qr(^virtlogd) => 0, + qr(^virtlockd) => 0, + qr(^docker) => 0, + + # systemd stuff + # (see also Debian Bug#784238 & #784437) + qr(^emergency\.service$) => 0, + qr(^rescue\.service$) => 0, + qr(^elogind) => 0, + + # do not restart oneshot services, see also #862840 + qr(^apt-daily\.service$) => 0, + qr(^apt-daily-upgrade\.service$) => 0, + qr(^unattended-upgrades\.service$) => 0, + # do not restart oneshot services from systemd-cron, see also #917073 + qr(^cron-.*\.service$) => 0, + + # ignore rc-local.service, see #852864 + qr(^rc-local\.service$) => 0, + + # don't restart systemd-logind, see #798097 + qr(^systemd-logind) => 0, +}; + +# Override container default selection (hash of regex). +$nrconf{override_cont} = { +}; + +# Disable interpreter scanners. +#$nrconf{interpscan} = 0; + +# Ignore script files matching these regexs: +$nrconf{blacklist_interp} = [ + # ignore temporary files + qr(^/tmp/), + qr(^/var/), + qr(^/run/), + +]; + +# Ignore +x mapped files matching one of these regexs: +$nrconf{blacklist_mappings} = [ + # special device paths + qr(^/(SYSV00000000( \(deleted\))?|drm(\s|$)|dev/)), + + # ignore memfd mappings + qr(^/memfd:), + + # aio(7) mapping + qr(^/\[aio\]), + + # Oil Runtime Compiler's JIT files + qr#/orcexec\.[\w\d]+( \(deleted\))?$#, + + # plasmashell (issue #65) + qr(/#\d+( \(deleted\))?$), + + # Java Native Access (issues #142 #185) + qr#/jna\d+\.tmp( \(deleted\))?$#, + + # temporary stuff + qr#^(/var)?/tmp/#, + qr#^(/var)?/run/#, +]; + +# Verify mapped files in filesystem: +# 0 : enabled +# -1: ignore non-existing files, workaround for chroots and broken grsecurity kernels (default) +# 1 : disable check completely, rely on content of maps file only +$nrconf{skip_mapfiles} = -1; + +# Enable/disable hints on pending kernel upgrades: +# 1: requires the user to acknowledge pending kernels +# 0: disable kernel checks completely +# -1: print kernel hints to stderr only +#$nrconf{kernelhints} = -1; + +# Filter kernel image filenames by regex. This is required on Raspian having +# multiple kernel image variants installed in parallel. +#$nrconf{kernelfilter} = qr(kernel7\.img); + +# Enable/disable CPU microcode update hints: +# 1: requires the user to acknowledge pending updates +# 0: disable microcode checks completely +#$nrconf{ucodehints} = 0; + +# Nagios Plugin: configure return code use by nagios +# as service status[1]. +# +# [1] https://nagios-plugins.org/doc/guidelines.html#AEN78 +# +# Default: +# 'nagios-status' => { +# 'sessions' => 1, +# 'services' => 2, +# 'kernel' => 2, +# 'ucode' => 2, +# 'containers' => 1 +# }, +# +# Example: to ignore outdated sessions (status OK) +# $nrconf{'nagios-status'}->{sessions} = 0; + + +# Read additional config snippets. +if(-d q(/etc/needrestart/conf.d)) { + foreach my $fn (sort ) { + print STDERR "$LOGPREF eval $fn\n" if($nrconf{verbosity} > 1); + eval do { local(@ARGV, $/) = $fn; <>}; + die "Error parsing $fn: $@" if($@); + } +} diff --git a/needrestart/notify.conf b/needrestart/notify.conf new file mode 100644 index 00000000..99e23d5c --- /dev/null +++ b/needrestart/notify.conf @@ -0,0 +1,20 @@ +# needrestart - Restart daemons after library updates. +# +# Configure notification globals (shell syntax) +# + +# Disable write to tty (notify.d/200-write) +#NR_NOTIFYD_DISABLE_WRITE='1' + +# Disable needrestart-session (notify.d/300-needrestart-session) +#NR_NOTIFYD_DISABLE_NEEDRESTART_SESSION='1' + +# Disable libnotify (notify.d/400-notify-send) +#NR_NOTIFYD_DISABLE_NOTIFY_SEND='1' + +# Disable mail to user (notify.d/600-mail) +NR_NOTIFYD_DISABLE_MAIL='1' + + +# Where to find the shell function library from gettext-base +#GETTEXTLIB='/usr/bin/gettext.sh' diff --git a/needrestart/notify.d/200-write b/needrestart/notify.d/200-write new file mode 100755 index 00000000..13f97ee7 --- /dev/null +++ b/needrestart/notify.d/200-write @@ -0,0 +1,44 @@ +#!/bin/sh + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# + +# Use write to notify users on TTYs. + +. /usr/lib/needrestart/notify.d.sh + +if [ "$NR_NOTIFYD_DISABLE_WRITE" = '1' ]; then + echo "[$0] disabled in global config" 1>&2 + exit 1 +fi + +case "$NR_SESSION" in + /dev/tty*|/dev/pts*) + echo "[$0] notify user $NR_USERNAME on $NR_SESSION" 1>&2 + { + echo + gettext 'Your session is running obsolete binaries or libraries as listed below. +Please consider a relogin or restart of the affected processes!' + echo + echo + cat -n + echo + } | write "$NR_USERNAME" "$NR_SESSION" 2> /dev/null + ;; + *) + echo "[$0] skip session w/o tty" 1>&2 + exit 1 + ;; +esac diff --git a/needrestart/notify.d/400-notify-send b/needrestart/notify.d/400-notify-send new file mode 100755 index 00000000..77abb124 --- /dev/null +++ b/needrestart/notify.d/400-notify-send @@ -0,0 +1,57 @@ +#!/bin/sh + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# + +# Use notify-send (from libnotify-bin) to notify a user session via dbus. + +NSEND='/usr/bin/notify-send' +test -x "$NSEND" || exit 1 + +. /usr/lib/needrestart/notify.d.sh + +if [ "$NR_NOTIFYD_DISABLE_NOTIFY_SEND" = '1' ]; then + echo "[$0] disabled in global config" 1>&2 + exit 1 +fi + +case "$NR_SESSION" in + session*) + DBUS_SESSION_BUS_ADDRESS=$(sed -z -n s/^DBUS_SESSION_BUS_ADDRESS=//p "/proc/$NR_SESSPPID/environ") + if [ -z "$DBUS_SESSION_BUS_ADDRESS" ]; then + unset DBUS_SESSION_BUS_ADDRESS + fi + + export DISPLAY=$(sed -z -n s/^DISPLAY=//p "/proc/$NR_SESSPPID/environ") + export XAUTHORITY=$(sed -z -n s/^XAUTHORITY=//p "/proc/$NR_SESSPPID/environ") + + if [ -z "$DISPLAY" ]; then + echo "[$0] could not find DISPLAY for $NR_USERNAME on $NR_SESSION" 1>&2 + exit 1 + fi + + echo "[$0] notify user $NR_USERNAME on $DISPLAY" 1>&2 + + MSGTITLE=$(gettext 'Relogin or restarts required!') + MSGBODY=$(gettext 'Your session is running obsolete binaries or libraries as listed below. +Please consider a relogin or restart of the affected processes!')'\n'$(cat) + + su -p -s /bin/sh -c "$NSEND -a needrestart -u critical -i dialog-warning \"$MSGTITLE\" \"$MSGBODY\"" "$NR_USERNAME" + ;; + *) + echo "[$0] skip session '$NR_SESSION'" 1>&2 + exit 1; + ;; +esac diff --git a/needrestart/notify.d/600-mail b/needrestart/notify.d/600-mail new file mode 100755 index 00000000..f1b8761a --- /dev/null +++ b/needrestart/notify.d/600-mail @@ -0,0 +1,48 @@ +#!/bin/sh + +# needrestart - Restart daemons after library updates. +# +# Authors: +# Thomas Liske +# +# Copyright Holder: +# 2013 - 2022 (C) Thomas Liske [http://fiasko-nw.net/~thomas/] +# +# License: +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# + +# Use /usr/bin/mail to notify a user via e-mail. + +MAILX='/usr/bin/mail' +test -x "$MAILX" || exit 1 + +. /usr/lib/needrestart/notify.d.sh + +if [ "$NR_NOTIFYD_DISABLE_MAIL" = '1' ]; then + echo "[$0] disabled in global config" 1>&2 + exit 1 +fi + +# Skip system users +NR_USERID=$(id -u "$NR_USERNAME") +if [ "0$NR_USERID" -gt 0 ] && [ "0$NR_USERID" -lt 1000 ]; then + echo "[$0] do not notify system-user $NR_USERNAME via mail" 1>&2 + exit 1 +fi + +echo "[$0] notify user $NR_USERNAME on $NR_SESSION via mail" 1>&2 + +{ + _NR_FQDN=$(hostname -f) + eval_gettext 'Your session on host $_NR_FQDN ($NR_SESSION) is running obsolete binaries or libraries as listed below.' + echo + echo + gettext "Please consider a relogin or restart of the affected processes!" + echo + echo + cat +} | fold -s -w 72 | "$MAILX" -s "Relogin or restarts on host $(hostname) required!" "$NR_USERNAME" diff --git a/needrestart/notify.d/README.needrestart b/needrestart/notify.d/README.needrestart new file mode 100644 index 00000000..aa06bf48 --- /dev/null +++ b/needrestart/notify.d/README.needrestart @@ -0,0 +1,28 @@ +Files located in /etc/needrestart/notify.d are used to notify running +user sessions about usage of outdated libraries. + +needrestart runs any executable file (except *~, *.dpkg-*, *.ex) naturally +sorted by the filename for each notification. If the result code is 0 than +needrestart will stop to run the remaining notification binaries. + + +The following environment variables are set: + +- NR_SESSION + Session identifier (tty device node or systemd's session name). +- NR_SESSPPID + The first pid in the session detected by needrestart. +- NR_UID + User ID of the session owner. +- NR_USERNAME + Username of the session owner. + + +The following file descriptors are used: + +- /dev/stdin + The list of obsolete processes. +- /dev/stdout + Closed. +- /dev/stderr + Available in verbose mode (-v). diff --git a/needrestart/restart.d/README.needrestart b/needrestart/restart.d/README.needrestart new file mode 100644 index 00000000..2c80b7eb --- /dev/null +++ b/needrestart/restart.d/README.needrestart @@ -0,0 +1,12 @@ +Files located in /etc/needrestart/restart.d are used for services +requiring a special procedure for restarting instead of +systemctl/service command. + +Needrestart uses executable files matching the complete service +names. If the host uses systemd the service names have '.service' as a +suffix (dbus vs. dbus.service). Needrestart uses the systemctl/service +command if no executable file is available to override the default +behavior. + +The environment variable NR_VERBOSE will be set to '1' if the +executable should be verbose. diff --git a/needrestart/restart.d/dbus.service b/needrestart/restart.d/dbus.service new file mode 100755 index 00000000..2e99a268 --- /dev/null +++ b/needrestart/restart.d/dbus.service @@ -0,0 +1,81 @@ +#!/bin/bash + +# by Vladimir Kudrya +# https://github.com/Vladimir-csp/ +# +# This script is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 2 of the License, or +# (at your option) any later version. See . + +# This is a replacement for original dbus.service script by Thomas Liske +# Dbus dependencies are enumerated dynamically and restarted after dbus and systemd daemon reexec + +# enable xtrace if we should be verbose +if [ "$NR_VERBOSE" = '1' ]; then + set -x +fi + +if [ "$(id -ru)" != "0" ] +then + echo "Not root, exiting" >&2 + exit 1 +fi + +INIT_EXEC="$(readlink /proc/1/exe)" + +if [ "$(basename "$INIT_EXEC")" != "systemd" ] +then + echo "Init system is not systemd ($INIT_EXEC), doing nothing" + exit 0 +fi + +get_active_deps(){ + # return all dbus dependencies, filter out dbus and DM, leave only active + { + systemctl list-dependencies -l --reverse --plain dbus.socket + systemctl list-dependencies -l --reverse --plain dbus.service + } | grep -o '[^[:space:]]\+.service' | sort -u | while read SERVICE + do + if [ "$SERVICE" != "dbus.service" -a "$SERVICE" != "$DISPLAY_MANAGER" ] && systemctl -q is-active "$SERVICE" + then + echo "$SERVICE" + fi + done +} + +# if DM is active, return canonical ID +DISPLAY_MANAGER="$(systemctl -q is-active display-manager.service && systemctl show --value -p Id display-manager.service)" + +# get dependencies +ACTIVE_DEPS="$(get_active_deps)" + +# get logind sessions +SESSIONS="$(loginctl list-sessions --no-legend | grep -o '^[[:space:]]*[0-9]\+' | tr '\n' ' ')" + +cat << EOF +!!! In $PAUSE seconds dbus restart will be performed !!! +User sessions to be terminated: $SESSIONS + +Services to be restarted: +$ACTIVE_DEPS +$DISPLAY_MANAGER +EOF + +[ -t 0 ] && read -p "Press Enter to continue > " PRESSENTER + +# prepare list to be a CLI arg +ACTIVE_DEPS="$(echo "$ACTIVE_DEPS" | tr '\n' ' ')" + +# run restart sequence as transient unit... +if [ -n "$DISPLAY_MANAGER" ] +then + # terminate user sessions, stop DM, restart dbus, reexec systemd, restart dbus dependencies, start DM + systemd-run -G --unit=restart-dbus sh -c "loginctl terminate-session $SESSIONS ; systemctl stop $DISPLAY_MANAGER ; systemctl restart dbus.service ; sleep 1 ; systemctl daemon-reexec ; sleep 1 ; systemctl restart $ACTIVE_DEPS ; systemctl start $DISPLAY_MANAGER" +else + # terminate user sessions, restart dbus, reexec systemd, restart dbus dependencies + systemd-run -G --unit=restart-dbus sh -c "loginctl terminate-session $SESSIONS ; systemctl restart dbus.service ; sleep 1 ; systemctl daemon-reexec ; sleep 1 ; systemctl restart $ACTIVE_DEPS" +fi + +# restart sequence runs as a unit, so it is possible to view its output in the log if, any: +# journalctl -u restart-dbus diff --git a/needrestart/restart.d/systemd-manager b/needrestart/restart.d/systemd-manager new file mode 100755 index 00000000..8b705ff7 --- /dev/null +++ b/needrestart/restart.d/systemd-manager @@ -0,0 +1,13 @@ +#!/bin/sh + +# needrestart - Restart daemons after library updates. +# +# Restarting systemd using special systemctl call. +# + +# enable xtrace if we should be verbose +if [ "$NR_VERBOSE" = '1' ]; then + set -x +fi + +exec systemctl daemon-reexec diff --git a/needrestart/restart.d/sysv-init b/needrestart/restart.d/sysv-init new file mode 100755 index 00000000..a4e53587 --- /dev/null +++ b/needrestart/restart.d/sysv-init @@ -0,0 +1,13 @@ +#!/bin/sh + +# needrestart - Restart daemons after library updates. +# +# Restart SysV's init. +# + +# enable xtrace if we should be verbose +if [ "$NR_VERBOSE" = '1' ]; then + set -x +fi + +exec telinit u diff --git a/rc0.d/K01cgroupfs-mount b/rc0.d/K01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc0.d/K01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc0.d/K01docker b/rc0.d/K01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc0.d/K01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc1.d/K01cgroupfs-mount b/rc1.d/K01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc1.d/K01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc1.d/K01docker b/rc1.d/K01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc1.d/K01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc2.d/S01cgroupfs-mount b/rc2.d/S01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc2.d/S01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc2.d/S01docker b/rc2.d/S01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc2.d/S01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc3.d/S01cgroupfs-mount b/rc3.d/S01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc3.d/S01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc3.d/S01docker b/rc3.d/S01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc3.d/S01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc4.d/S01cgroupfs-mount b/rc4.d/S01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc4.d/S01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc4.d/S01docker b/rc4.d/S01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc4.d/S01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc5.d/S01cgroupfs-mount b/rc5.d/S01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc5.d/S01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc5.d/S01docker b/rc5.d/S01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc5.d/S01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/rc6.d/K01cgroupfs-mount b/rc6.d/K01cgroupfs-mount new file mode 120000 index 00000000..d4a94692 --- /dev/null +++ b/rc6.d/K01cgroupfs-mount @@ -0,0 +1 @@ +../init.d/cgroupfs-mount \ No newline at end of file diff --git a/rc6.d/K01docker b/rc6.d/K01docker new file mode 120000 index 00000000..567023b7 --- /dev/null +++ b/rc6.d/K01docker @@ -0,0 +1 @@ +../init.d/docker \ No newline at end of file diff --git a/systemd/system/multi-user.target.wants/containerd.service b/systemd/system/multi-user.target.wants/containerd.service new file mode 120000 index 00000000..7e11de06 --- /dev/null +++ b/systemd/system/multi-user.target.wants/containerd.service @@ -0,0 +1 @@ +/lib/systemd/system/containerd.service \ No newline at end of file diff --git a/systemd/system/multi-user.target.wants/docker.service b/systemd/system/multi-user.target.wants/docker.service new file mode 120000 index 00000000..a06e3f51 --- /dev/null +++ b/systemd/system/multi-user.target.wants/docker.service @@ -0,0 +1 @@ +/lib/systemd/system/docker.service \ No newline at end of file diff --git a/systemd/system/sockets.target.wants/docker.socket b/systemd/system/sockets.target.wants/docker.socket new file mode 120000 index 00000000..6d81ae16 --- /dev/null +++ b/systemd/system/sockets.target.wants/docker.socket @@ -0,0 +1 @@ +/lib/systemd/system/docker.socket \ No newline at end of file