NEWS revision 78b6b7ceb2c76a3e29aeaa4b00c257be0706bffc
71092d70af35567dd154d3de2ce04ce62e157a7cLennart Poetteringsystemd System and Service Manager
7c66aeba0f28cb82027d6015405ed71afa3b6059Kay SieversCHANGES WITH 217:
c904f64d84db8c4eebedf210ba10893f19ba05edLennart Poettering * journalctl gained the new options -t/--identifier= to match
f957632b960a0a42999b38ded7089fa602b41745Kay Sievers on the syslog identifier (aka "tag"), as well as --utc to
f957632b960a0a42999b38ded7089fa602b41745Kay Sievers show log timestamps in the UTC timezone. journalctl now also
f957632b960a0a42999b38ded7089fa602b41745Kay Sievers accepts -n/--lines=all to disable line capping in a pager.
9a36607584bbd1d78775353e022a51794b4e27b1Lennart Poettering * Services can notify the manager before they start a reload
9a36607584bbd1d78775353e022a51794b4e27b1Lennart Poettering (by sending RELOADING=1) or shutdown (by sending
a40593a0d0d740efa387e35411e1e456a6c5aba7Lennart Poettering STOPPING=1). This allows the manager to track and show the
20ffc4c4a9226b0e45cc02ad9c0108981626c0bbKay Sievers internal state of daemons and closes a race condition when
7bcd865d386d96caac83cb1c589fdb8f9ce3b081Zbigniew Jędrzejewski-Szmek the process is still running but has closed its D-Bus
2f8d077ece024b985f2501dc8c904c2d29967acbKay Sievers * Services with Type=oneshot do not have to have any ExecStart
2f8d077ece024b985f2501dc8c904c2d29967acbKay Sievers commands anymore.
2f8d077ece024b985f2501dc8c904c2d29967acbKay Sievers * User units are now loaded also from
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering $XDG_RUNTIME_DIR/systemd/user/. This is similar to the
c0fe5db522b52f27e030655ce2c03e05cbbc1558Kay Sievers /run/systemd/user directory that was already previously
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering supported, but is under the control of the user.
c3090674833c8bd34fbdb0e743f1c47d85dd14fbLennart Poettering * A timeout for the bootup of the whole system can now be
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering configured. The system can be configured to reboot or
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering poweroff if the basic system default target is not reached
2d19f95caef8668aeb5c05a18b39c6b79f710856Kay Sievers before the timeout (new StartTimeoutSec=,
2d19f95caef8668aeb5c05a18b39c6b79f710856Kay Sievers StartTimeoutAction=, StartTimeoutRebootArgument= options).
bfb7ec0ebab18a0bc8a99997f541c980a323c867Lennart Poettering * systemd-logind can be configured to also handle lid switch
a4cc3e5ccc0a3033d764a9eb3ae5ee90db560682Lennart Poettering events even when the machine is docked or multiple displays
a4cc3e5ccc0a3033d764a9eb3ae5ee90db560682Lennart Poettering are attached (HandleLidSwitchDocked= option).
0028da22f194f7c0ca7169a48cf32e1bc0f9138aLennart Poettering * A helper binary and a service have been added which can be
a4cc3e5ccc0a3033d764a9eb3ae5ee90db560682Lennart Poettering used to resume from hibernation in the initramfs. A
7e2c2bcf1285d124c9c656ff46cafa4db0a987c9Lennart Poettering generator will parse the resume= option on the kernel
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering command-line to trigger resume.
7e2c2bcf1285d124c9c656ff46cafa4db0a987c9Lennart Poettering * A user console daemon systemd-consoled has been
7e2c2bcf1285d124c9c656ff46cafa4db0a987c9Lennart Poettering added. Currently, it is a preview, and will so far open a
7e2c2bcf1285d124c9c656ff46cafa4db0a987c9Lennart Poettering single terminal on each session of the user marked as
7b4da18c1717f811bae67ea3d39290495857c03eLennart Poettering Desktop=SYSTEMD-CONSOLE.
788f75a0e766738c052086e856b7c1b1b676de6bLennart Poettering * Route metrics can be specified for DHCP routes added by
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering systemd-networkd.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * The SELinux context of socket-actived services can be set
95b4be171988fc2ea33377b1b4450e5d410add7bLennart Poettering from the information provided by the networking stack
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering (SELinuxContextFromNet= option).
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering * Userspace firmware loading support has been removed and
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering the minimum supported kernel version is thus bumped to 3.7.
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering * Timeout for udev workers has been increased from 1 to 3
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering minutes, but a warning will be printed after 1 minute to
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering help diagnose kernel modules that take a long time to load.
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering * Udev rules can now remove tags on devices with TAG-="foobar".
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering * systemd's readahead implementation has been removed. In many
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering circumstatances it didn't give expected benefits even for
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering rotational disk drives and was becoming less relevant in the
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering age of SSDs. As none of the developers has been using
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering rotating media anymore, and nobody stepped up to actively
f8aeee1f1fe432924b355f48f01f09c9a552ed97Lennart Poettering maintain this component of systemd it has now been removed.
390b5e558c8d1fc550386f52969ee8dc256e9b3dLennart Poettering * Swap units can use Discard= to specify discard options.
390b5e558c8d1fc550386f52969ee8dc256e9b3dLennart Poettering Discard options specified for swaps in /etc/fstab are now
490b7e47093d491a2bdb1084fe92b796f4e07eefLennart Poettering * Docker containers are now detected as a separate type of
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering virtualization.
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering * The Password Agent protocol gained support for queries where
490b7e47093d491a2bdb1084fe92b796f4e07eefLennart Poettering the user input is shown, useful e.g. for usernames.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering systemd-ask-password gained a new --echo option to turn that
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * The default sysctl.d/ snippets will now set:
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering This selects Fair Queueing Controlled Delay as the default
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering queueing discipline for network interfaces. fq_codel helps
e41814846c19a48f4490169d82e359e005c4db45Lennart Poettering fight the network bufferbloat problem. It is believed to be
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering a good default with no tuning required for most workloads.
81d112a8f0522a09fcfe317f420363a2b728137cLennart Poettering Downstream distributions may override this choice. On 10Gbit
c0fe5db522b52f27e030655ce2c03e05cbbc1558Kay Sievers servers that do not do forwarding, "fq" may perform better.
e9fd44b728ff1fc0d1f24fccb87a767f6865df27Lennart Poettering Systems without a good clocksource should use "pfifo_fast".
e9fd44b728ff1fc0d1f24fccb87a767f6865df27Lennart Poettering * If kdbus is enabled during build a new option BusPolicy= is
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering available for service units, that allows locking all service
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering processes into a stricter bus policy, in order to limit
3040728b6691ea2e9df3a2060e2d49a792bbaedaLennart Poettering access to various bus services, or even hide most of them
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering from the service's view entirely.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * networkctl will now show the .network and .link file
e6c6e7afffa80ad74efdb1ddfa815294624f1608Lennart Poettering networkd has applied to a specific interface.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * sd-login gained a new API call sd_session_get_desktop() to
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering query which desktop environment has been selected for a
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * UNIX utmp support is now compile-time optional to support
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering legacy-free systems.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * systemctl gained two new commands "add-wants" and
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering "add-requires" for pulling in units from specific targets
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * If the word "rescue" is specified on the kernel command line
e673ad0415d89c322e5b1a121e411f1b1d8075c0Lennart Poettering the system will now boot into rescue mode (aka
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering rescue.target), which was previously available only by
e673ad0415d89c322e5b1a121e411f1b1d8075c0Lennart Poettering specifying "1" or "systemd.unit=rescue.target" on the kernel
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering command line. This new kernel command line option nicely
e673ad0415d89c322e5b1a121e411f1b1d8075c0Lennart Poettering mirrors the already existing "emergency" kernel command line
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * New kernel command line options mount.usr=, mount.usrflags=,
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering usrfstype= have been added that match root=, rootflags=,
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering rootfstype= but allow mounting a specific file system to
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * The $NOTIFY_SOCKET is now also passed to control processesof
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering services, not only the main process.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * This version reenables support for fsck's -l switch. This
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering means at least version v2.25 of util-linux is required for
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering operation, otherwise dead-locks on device nodes may
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering occur. Again: you need to update util-linux to at least
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering v2.25 when updating systemd to v217.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart PoetteringCHANGES WITH 216:
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * timedated no longer reads NTP implementation unit names from
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering /usr/lib/systemd/ntp-units.d/*.list. Alternative NTP
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering implementations should add a
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering to their unit files to take over and replace systemd's NTP
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering default functionality.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * systemd-sysusers gained a new line type "r" for configuring
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering which UID/GID ranges to allocate system users/groups
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering from. Lines of type "u" may now add an additional column
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering that specifies the home directory for the system user to be
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering created. Also, systemd-sysusers may now optionally read user
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering information from STDIN instead of a file. This is useful for
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering invoking it from RPM preinst scriptlets that need to create
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering users before the first RPM file is installed since these
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering files might need to be owned by them. A new
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering %sysusers_create_inline RPM macro has been introduced to do
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering just that. systemd-sysusers now updates the shadow files as
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering well as the user/group databases, which should enhance
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering compatibility with certain tools like grpck.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * A number of bus APIs of PID 1 now optionally consult
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering PolicyKit to permit access for otherwise unprivileged
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering clients under certain conditions. Note that this currently
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering doesn't support interactive authentication yet, but this is
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering expected to be added eventually, too.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * /etc/machine-info now has new fields for configuring the
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering deployment environment of the machine, as well as the
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering location of the machine. hostnamectl has been updated with
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering new command to update these fields.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * systemd-timesyncd has been updated to automatically acquire
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering NTP server information from systemd-networkd, which might
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering have been discovered via DHCP.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * systemd-resolved now includes a caching DNS stub resolver
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering and a complete LLMNR name resolution implementation. A new
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering NSS module "nss-resolve" has been added which can be used
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering instead of glibc's own "nss-dns" to resolve hostnames via
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering systemd-resolved. Hostnames, addresses and arbitrary RRs may
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering be resolved via systemd-resolved D-Bus APIs. In contrast to
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering the glibc internal resolver systemd-resolved is aware of
8b04b925e587ff56568c62ff5ad3f2ea2b34ca7aLennart Poettering multi-homed system, and keeps DNS server and caches separate
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering and per-interface. Queries are sent simultaneously on all
7361c3b4e1e28a7eb4354a3da354b22e79782141Lennart Poettering interfaces that have DNS servers configured, in order to
e673ad0415d89c322e5b1a121e411f1b1d8075c0Lennart Poettering properly handle VPNs and local LANs which might resolve
e673ad0415d89c322e5b1a121e411f1b1d8075c0Lennart Poettering separate sets of domain names. systemd-resolved may acquire
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering DNS server information from systemd-networkd automatically,
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering which in turn might have discovered them via DHCP. A tool
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering "systemd-resolve-host" has been added that may be used to
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering query the DNS logic in resolved. systemd-resolved implements
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering IDNA and automatically uses IDNA or UTF-8 encoding depending
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering on whether classic DNS or LLMNR is used as transport. In the
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering next releases we intend to add a DNSSEC and mDNS/DNS-SD
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering implementation to systemd-resolved.
d2e83c23f5f0cdd3b6ec05c5c40209708721e704Kay Sievers * A new NSS module nss-mymachines has been added, that
d2e83c23f5f0cdd3b6ec05c5c40209708721e704Kay Sievers automatically resolves the names of all local registered
d2e83c23f5f0cdd3b6ec05c5c40209708721e704Kay Sievers containers to their respective IP addresses.
f6113d42d015ad9f3a9e702a09eb8006511a4424Kay Sievers * A new client tool "networkctl" for systemd-networkd has been
d2e83c23f5f0cdd3b6ec05c5c40209708721e704Kay Sievers added. It currently is entirely passive and will query
7a43e910ce00eef22fd42925ae4c85cbea1b1320Kay Sievers networking configuration from udev, rtnetlink and networkd,
d2e83c23f5f0cdd3b6ec05c5c40209708721e704Kay Sievers and present it to the user in a very friendly
c55b1b59b837dfd924b704d457ed77c55f8bfeabLennart Poettering way. Eventually, we hope to extend it to become a full
6c1703cc35b3a5f93ad3cc813fea10cb9a636102Kay Sievers control utility for networkd.
6c1703cc35b3a5f93ad3cc813fea10cb9a636102Kay Sievers * .socket units gained a new DeferAcceptSec= setting that
08f9588885c5d65694b324846b0ed19211d2c178Lennart Poettering controls the kernels' TCP_DEFER_ACCEPT sockopt for
59704f3e937c664f7324bfbb08483c358dfbc4c6Lennart Poettering TCP. Similar, support for controlling TCP keep-alive
59704f3e937c664f7324bfbb08483c358dfbc4c6Lennart Poettering settings has been added (KeepAliveTimeSec=,
59704f3e937c664f7324bfbb08483c358dfbc4c6Lennart Poettering KeepAliveIntervalSec=, KeepAliveProbes=). Also, support for
9ec82de1725ddaab333149171b790d62c47ae133Lennart Poettering turning off Nagle's algorithm on TCP has been added
e707c49485b8f4f2ec040d3da232d39153e650b9Lennart Poettering * logind learned a new session type "web", for use in projects
7f8732835295fce29479b1afc9e8ee801852db09Lennart Poettering like Cockpit which register web clients as PAM sessions.
7f8732835295fce29479b1afc9e8ee801852db09Lennart Poettering * timer units with at least one OnCalendar= setting will now
e707c49485b8f4f2ec040d3da232d39153e650b9Lennart Poettering be started only after timer-sync.target has been
e707c49485b8f4f2ec040d3da232d39153e650b9Lennart Poettering reached. This way they will not elapse before the system
e707c49485b8f4f2ec040d3da232d39153e650b9Lennart Poettering clock has been corrected by a local NTP client or
a19554ed92a7460b4e709cc40c558cde827ab85bLennart Poettering similar. This is particular useful on RTC-less embedded
a19554ed92a7460b4e709cc40c558cde827ab85bLennart Poettering machines, that come up with an invalid system clock.
1cb88f2c61f590083847d65cd5a518e834da87d3Lennart Poettering * systemd-nspawn's --network-veth= switch should now result in
1cb88f2c61f590083847d65cd5a518e834da87d3Lennart Poettering stable MAC addresses for both the outer and the inner side
603cd8fe07cb03e8b11722d1a732e569e5a46347Lennart Poettering * systemd-nspawn gained a new --volatile= switch for running
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering container instances with /etc or /var unpopulated.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * The kdbus client code has been updated to use the new Linux
6d0274f11547a0f11200bb82bf598a5a253e12cfLennart Poettering 3.17 memfd subsystem instead of the old kdbus-specific one.
a7a3f28be404875eff20443a0fa8088bcc4c18dfLennart Poettering * systemd-networkd's DHCP client and server now support
9b27910bb0c23e5225fc1177176e4f9bf9bf787bLennart Poettering FORCERENEW. There are also new configuration options to
9b27910bb0c23e5225fc1177176e4f9bf9bf787bLennart Poettering configure the vendor client identifier and broadcast mode
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers * systemd will no longer inform the kernel about the current
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers timezone, as this is necessarily incorrect and racy as the
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers kernel has no understanding of DST and similar
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers concepts. This hence means FAT timestamps will be always
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers considered UTC, similar to what Android is already
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers doing. Also, when the RTC is configured to the local time
7d8197d1f25c1291855bb6cffc705444978c6d8dKay Sievers (rather than UTC) systemd will never synchronize back to it,
9ee58bddeb6eb044753167e0047fe836479ca5dbKay Sievers as this might confuse Windows at a later boot.
dcfc4b2e5c1af6375488c00bdc6fb8122f86c4d7Lennart Poettering * systemd-analyze gained a new command "verify" for offline
71ef24d09573874c0f7bc323c07c3aec2a458707Lennart Poettering validation of unit files.
71ef24d09573874c0f7bc323c07c3aec2a458707Lennart Poettering * systemd-networkd gained support for a couple of additional
71ef24d09573874c0f7bc323c07c3aec2a458707Lennart Poettering settings for bonding networking setups. Also, the metric for
1b89884ba31cbe98f159ce2c7d6fac5f6a57698fLennart Poettering statically configured routes may now be configured. For
1b89884ba31cbe98f159ce2c7d6fac5f6a57698fLennart Poettering network interfaces where this is appropriate the peer IP
1920e37ef9fec04a1fd882f66bfa7a9a5b91c536Lennart Poettering address may now be configured.
15abdb9a6f34628b04b887e0b9649fa582d6cd37Lennart Poettering * systemd-networkd's DHCP client will no longer request
1920e37ef9fec04a1fd882f66bfa7a9a5b91c536Lennart Poettering broadcasting by default, as this tripped up some networks.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering For hardware where broadcast is required the feature should
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering be switched back on using RequestBroadcast=yes.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * systemd-networkd will now set up IPv4LL addresses (when
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering enabled) even if DHCP is configured successfully.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * udev will now default to respect network device names given
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering by the kernel when the kernel indicates that these are
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering predictable. This behavior can be tweaked by changing
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering NamePolicy= in the relevant .link file.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * A new library systemd-terminal has been added that
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering implements full TTY stream parsing and rendering. This
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering library is supposed to be used later on for implementing a
f801968466fed39d50d410b30ac828c26722cc95Lennart Poettering full userspace VT subsystem, replacing the current kernel
41f9172f427bdbb8221c64029f78364b8dd4e527Lennart Poettering implementation.
178cc7700c23ac088cd7190d7854282075028d91Lennart Poettering * A new tool systemd-journal-upload has been added to push
de34a42bcad31f0648ac0f249801310e0dbf83f9Lennart Poettering journal data to a remote system running
de34a42bcad31f0648ac0f249801310e0dbf83f9Lennart Poettering systemd-journal-remote.
41f9172f427bdbb8221c64029f78364b8dd4e527Lennart Poettering * journald will no longer forward all local data to another
424a19f8a2061c6b058283228734010b2fa24db4Lennart Poettering running syslog daemon. This change has been made because
424a19f8a2061c6b058283228734010b2fa24db4Lennart Poettering rsyslog (which appears to be the most commonly used syslog
424a19f8a2061c6b058283228734010b2fa24db4Lennart Poettering implementation these days) no longer makes use of this, and
a1cccad1fe88ddd6943e18af97cf7f466296970fLennart Poettering instead pulls the data out of the journal on its own. Since
a1cccad1fe88ddd6943e18af97cf7f466296970fLennart Poettering forwarding the messages to a non-existent syslog server is
8556879e0d14925ce897875c6c264368e2d048c2Lennart Poettering more expensive than we assumed we have now turned this
d05c556b6b2a680ec8b51ecbbc99a9ab14c28eedZbigniew Jędrzejewski-Szmek off. If you run a syslog server that is not a recent rsyslog
8556879e0d14925ce897875c6c264368e2d048c2Lennart Poettering version, you have to turn this option on again
8556879e0d14925ce897875c6c264368e2d048c2Lennart Poettering (ForwardToSyslog= in journald.conf).
4a30847b9d71e0381948d68279c8f775b9de7850Lennart Poettering * journald now optionally supports the LZ4 compressor for
4a30847b9d71e0381948d68279c8f775b9de7850Lennart Poettering larger journal fields. This compressor should perform much
5e8b28838e493b59628322b69580097ef7dd9384Lennart Poettering better than XZ which was the previous default.
d87be9b0af81a6e07d4fb3028e45c4409100dc26Lennart Poettering * machinectl now shows the IP addresses of local containers,
d87be9b0af81a6e07d4fb3028e45c4409100dc26Lennart Poettering if it knows them, plus the interface name of the container.
88f89a9b6d25dfcb89691727c8cdaf01f4090b72Lennart Poettering * A new tool "systemd-escape" has been added that makes it
38a60d7112d33ffd596b23e8df53d75a7c09e71bLennart Poettering easy to escape strings to build unit names and similar.
d8b78264a5245307babbf5af8e39d6d4a1ae095fLennart Poettering * sd_notify() messages may now include a new ERRNO= field
d8b78264a5245307babbf5af8e39d6d4a1ae095fLennart Poettering which is parsed and collected by systemd and shown among the
d8b78264a5245307babbf5af8e39d6d4a1ae095fLennart Poettering "systemctl status" output for a service.
7560fffcd2531786b9c1ca657667a43e90331326Lennart Poettering * A new component "systemd-firstboot" has been added that
7560fffcd2531786b9c1ca657667a43e90331326Lennart Poettering queries the most basic systemd information (timezone,
68f160039eb78fe122cfe0d4c49695ae91f6f0d1Lennart Poettering hostname, root password) interactively on first
0790b9fed42eefc4e22dbbe2337cba9713b7848cLennart Poettering boot. Alternatively it may also be used to provision these
5a7e959984788cf89719dec31999409b63bb802bLennart Poettering things offline on OS images installed into directories.
68f160039eb78fe122cfe0d4c49695ae91f6f0d1Lennart Poettering * The default sysctl.d/ snippets will now set
68f160039eb78fe122cfe0d4c49695ae91f6f0d1Lennart Poettering net.ipv4.conf.default.promote_secondaries=1
edca2e2348b314e2d892fe6f8ae276fdc223f014Thomas Hindoe Paaboel Andersen This has the benefit of no flushing secondary IP addresses
68f160039eb78fe122cfe0d4c49695ae91f6f0d1Lennart Poettering when primary addresses are removed.
5aea932fd54db835b77709ddeba30732648aae53Lennart Poettering Contributions from: Ansgar Burchardt, Bastien Nocera, Colin
5aea932fd54db835b77709ddeba30732648aae53Lennart Poettering Walters, Dan Dedrick, Daniel Buch, Daniel Korostil, Daniel
918943c75fbd9dee87ff396de3a7c63a8d228433Lennart Poettering Mack, Dan Williams, Dave Reisner, David Herrmann, Denis
918943c75fbd9dee87ff396de3a7c63a8d228433Lennart Poettering Kenzior, Eelco Dolstra, Eric Cook, Hannes Reinecke, Harald
fd4d89b2c0b31da01d134301e30916931ae3c7d9Lennart Poettering Hoyer, Hong Shick Pak, Hui Wang, Jean-André Santoni, Jóhann
fd4d89b2c0b31da01d134301e30916931ae3c7d9Lennart Poettering B. Guðmundsson, Jon Severinsson, Karel Zak, Kay Sievers, Kevin
8230e26dc954a40d8c9dbc8ddd9376117021f9d2Lennart Poettering Wells, Lennart Poettering, Lukas Nykryn, Mantas Mikulėnas,
8230e26dc954a40d8c9dbc8ddd9376117021f9d2Lennart Poettering Marc-Antoine Perennou, Martin Pitt, Michael Biebl, Michael
4d9909c93e9c58789c71b34555a1908307c6849eLennart Poettering Marineau, Michael Olbrich, Michal Schmidt, Michal Sekletar,
4d9909c93e9c58789c71b34555a1908307c6849eLennart Poettering Miguel Angel Ajo, Mike Gilbert, Olivier Brunel, Robert
47ae7201b1df43bd3da83a19e38483b0e5694c99Lennart Poettering Schiele, Ronny Chevalier, Simon McVittie, Sjoerd Simons, Stef
47ae7201b1df43bd3da83a19e38483b0e5694c99Lennart Poettering Walter, Steven Noonan, Susant Sahani, Tanu Kaskinen, Thomas
88a6c5894c9d3f85d63b87b040c130366b4006ceKay Sievers Blume, Thomas Hindoe Paaboel Andersen, Timofey Titovets,
8351ceaea9480d9c2979aa2ff0f4982cfdfef58dLennart Poettering Tobias Geerinckx-Rice, Tomasz Torcz, Tom Gundersen, Umut
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering Tezduyar Lindskog, Zbigniew Jędrzejewski-Szmek
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering -- Berlin, 2014-08-19
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart PoetteringCHANGES WITH 215:
c66d36e5b5ae81f3c5297d6dacadc13c88c530f6Lennart Poettering * A new tool systemd-sysusers has been added. This tool
c649f72baed31c54c8384c3ca1d203fab6e98d08David Strauss creates system users and groups in /etc/passwd and
c649f72baed31c54c8384c3ca1d203fab6e98d08David Strauss /etc/group, based on static declarative system user/group
be0aa78406c73a6625308dc0672b5ff27ec6f9a8Lennart Poettering definitions in /usr/lib/sysusers.d/. This is useful to
be0aa78406c73a6625308dc0672b5ff27ec6f9a8Lennart Poettering enable factory resets and volatile systems that boot up with
9946996cda11a18b44d82344676e5a0e96339408Lennart Poettering an empty /etc directory, and thus need system users and
9946996cda11a18b44d82344676e5a0e96339408Lennart Poettering groups created during early boot. systemd now also ships
9946996cda11a18b44d82344676e5a0e96339408Lennart Poettering with two default sysusers.d/ files for the most basic
3471bedc005fab03f40b99bf6599645330adcd9eLennart Poettering users and groups systemd and the core operating system
eeb875144e5a80d0521461a139f13fc8014d77d8Lennart Poettering * A new tmpfiles snippet has been added that rebuilds the
59cea26a349cfa8db906b520dac72563dd773ff2Lennart Poettering essential files in /etc on boot, should they be missing.
9473414219330b9febc1d0712bbf49ad74cf962fLennart Poettering * A directive for ensuring automatic clean-up of
f1a8e221ecacea23883df57951e291a910463948Lennart Poettering /var/cache/man/ has been removed from the default
7b63bde1ed0d4f30c799c9b4737fa926465929f9Lennart Poettering configuration. This line should now be shipped by the man
7b63bde1ed0d4f30c799c9b4737fa926465929f9Lennart Poettering implementation. The necessary change has been made to the
5b40d33761376354116a8cddb9b9fbdb6c4727d6Lennart Poettering man-db implementation. Note that you need to update your man
5b40d33761376354116a8cddb9b9fbdb6c4727d6Lennart Poettering implementation to one that ships this line, otherwise no
b86fa936ce36976cd6a96034cf14ea267695bcb2Lennart Poettering automatic clean-up of /var/cache/man will take place.
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers * A new condition ConditionNeedsUpdate= has been added that
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers may conditionalize services to only run when /etc or /var
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers are "older" than the vendor operating system resources in
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers /usr. This is useful for reconstructing or updating /etc
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers after an offline update of /usr or a factory reset, on the
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers next reboot. Services that want to run once after such an
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers update or reset should use this condition and order
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers themselves before the new systemd-update-done.service, which
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers will mark the two directories as fully updated. A number of
d3a3f22267a7dac426b07a7ed0baa1632f5daf04Kay Sievers service files have been added making use of this, to rebuild
465349c06d994dd2cc6b6fc4109ac0b9952d500aLennart Poettering the udev hardware database, the journald message catalog and
06dab8e18aebf822392c7ca66c5bf3c1200fdec8Lennart Poettering dynamic loader cache (ldconfig). The systemd-sysusers tool
06dab8e18aebf822392c7ca66c5bf3c1200fdec8Lennart Poettering described above also makes use of this now. With this in
e01a15b71e18bf2008aec7e75041ffa42eb80b80Kay Sievers place it is now possible to start up a minimal operating
a888b352eb53b07daa24fa859ceeb254336b293dLennart Poettering system with /etc empty cleanly. For more information on the
98ef27df896f36f0407eaa7ed9e295203b9c271bLennart Poettering concepts involved see this recent blog story:
abd55b16547d0bb0ed1c31e72e16838f0f59f48bKay Sievers * A new system group "input" has been introduced, and all
abd55b16547d0bb0ed1c31e72e16838f0f59f48bKay Sievers input device nodes get this group assigned. This is useful
abd55b16547d0bb0ed1c31e72e16838f0f59f48bKay Sievers for system-level software to get access to input devices. It
abd55b16547d0bb0ed1c31e72e16838f0f59f48bKay Sievers complements what is already done for "audio" and "video".
18b754d345ecb0b15e369978aaffa72e9814b86aKay Sievers * systemd-networkd learnt minimal DHCPv4 server support in
068665b6fd9839f27bcace7e8f56c0baa6935272Lennart Poettering addition to the existing DHCPv4 client support. It also
231931ffba1bca9d8759bbd6f797e56f8c6971faLennart Poettering learnt DHCPv6 client and IPv6 Router Solicitation client
231931ffba1bca9d8759bbd6f797e56f8c6971faLennart Poettering support. The DHCPv4 client gained support for static routes
169c4f65131fbc7bcb51e7d5487a715cdcd0e0ebLennart Poettering passed in from the server. Note that the [DHCPv4] section
169c4f65131fbc7bcb51e7d5487a715cdcd0e0ebLennart Poettering known in older systemd-networkd versions has been renamed to
bd08f2422491169e92dc0899d5ba848fcae4c15cLennart Poettering [DHCP] and is now also used by the DHCPv6 client. Existing
bd08f2422491169e92dc0899d5ba848fcae4c15cLennart Poettering .network files using settings of this section should be
fb0864e7b9c6d26269ccea6ec5c0fd921c029781Lennart Poettering updated, though compatibility is maintained. Optionally, the
fb0864e7b9c6d26269ccea6ec5c0fd921c029781Lennart Poettering client hostname may now be sent to the DHCP server.
9586cdfab6a2638078702b7fea7e16b3a71899e2Lennart Poettering * networkd gained support for vxlan virtual networks as well
7f110ff9b8828b477e87de7b28c708cf69a3d008Lennart Poettering as tun/tap and dummy devices.
d0e5a33374cee92962af33dfc03873e470b014f6Lennart Poettering * networkd gained support for automatic allocation of address
d0e5a33374cee92962af33dfc03873e470b014f6Lennart Poettering ranges for interfaces from a system-wide pool of
d0e5a33374cee92962af33dfc03873e470b014f6Lennart Poettering addresses. This is useful for dynamically managing a large
d0e5a33374cee92962af33dfc03873e470b014f6Lennart Poettering number of interfaces with a single network configuration
53ed2eeb2e709a6c0d152d7bdf2d9a4b9f997a16Lennart Poettering file. In particular this is useful to easily assign
53ed2eeb2e709a6c0d152d7bdf2d9a4b9f997a16Lennart Poettering appropriate IP addresses to the veth links of a large number
abd55b16547d0bb0ed1c31e72e16838f0f59f48bKay Sievers of nspawn instances.
a6e87e90ede66815989ba2db92a07102a69906feLennart Poettering * RPM macros for processing sysusers, sysctl and binfmt
88f89a9b6d25dfcb89691727c8cdaf01f4090b72Lennart Poettering drop-in snippets at package installation time have been
87a8baa35d6d65ac3b58ae8e26e338e67f8ae8edLennart Poettering * The /etc/os-release file should now be placed in
87a8baa35d6d65ac3b58ae8e26e338e67f8ae8edLennart Poettering /usr/lib/os-release. The old location is automatically
5ba081b0fb02380cee4c2ff5bc7e05f869eb8415Lennart Poettering created as symlink. /usr/lib is the more appropriate
5ba081b0fb02380cee4c2ff5bc7e05f869eb8415Lennart Poettering location of this file, since it shall actually describe the
4cbd9ecf45f64c3a9acc99d473fbf3be3687ae24Lennart Poettering vendor operating system shipped in /usr, and not the
4cbd9ecf45f64c3a9acc99d473fbf3be3687ae24Lennart Poettering configuration stored in /etc.
65c0cf7108ae3537a357c74b4586a783baba82f9Lennart Poettering * .mount units gained a new boolean SloppyOptions= setting
f957632b960a0a42999b38ded7089fa602b41745Kay Sievers that maps to mount(8)'s -s option which enables permissive
f957632b960a0a42999b38ded7089fa602b41745Kay Sievers parsing of unknown mount options.
ad740100d108282d0244d5739d4dcc86fe4c5fdeLennart Poettering * tmpfiles learnt a new "L+" directive which creates a symlink
ad740100d108282d0244d5739d4dcc86fe4c5fdeLennart Poettering but (unlike "L") deletes a pre-existing file first, should
de6c78f8795743894431a099d26ec562a8acf3dfLennart Poettering it already exist and not already be the correct
7d441ddb5ca090b5a97f58ac4b4d97b3e84fa81eLennart Poettering symlink. Similar, "b+", "c+" and "p+" directives have been
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering added as well, which create block and character devices, as
14e639ae7a1dbf156273ce697d30fbc6c6594209Lennart Poettering well as fifos in the filesystem, possibly removing any
ff01d048b4c1455241c894cf7982662c9d28fd34Lennart Poettering pre-existing files of different types.
d3c7d7dd77b2b72315164b672462825cef6c0f9aKay Sievers * For tmpfiles' "L", "L+", "C" and "C+" directives the final
72b9ed828bd22f3ddd74b6853c183eebf006d6d8Lennart Poettering 'argument' field (which so far specified the source to
1d6702e8d3877c0bebf3ac817dc45ff72f5ecfa9Lennart Poettering symlink/copy the files from) is now optional. If omitted the
1d6702e8d3877c0bebf3ac817dc45ff72f5ecfa9Lennart Poettering same file os copied from /usr/share/factory/ suffixed by the
1d6702e8d3877c0bebf3ac817dc45ff72f5ecfa9Lennart Poettering full destination path. This is useful for populating /etc
71092d70af35567dd154d3de2ce04ce62e157a7cLennart Poettering with essential files, by copying them from vendor defaults
1258097cd3cdbc5dd3d264850119e553a29c5068Lennart Poettering * A new command "systemctl preset-all" has been added that
1258097cd3cdbc5dd3d264850119e553a29c5068Lennart Poettering applies the service preset settings to all installed unit
a4c279f87451186b8beb1b8cc21c7cad561ecf4bLennart Poettering files. A new switch --preset-mode= has been added that
a4c279f87451186b8beb1b8cc21c7cad561ecf4bLennart Poettering controls whether only enable or only disable operations
7c697168102cb64c5cb65a542959684014da99c7Lennart Poettering shall be executed.
71092d70af35567dd154d3de2ce04ce62e157a7cLennart Poettering * A new command "systemctl is-system-running" has been added
8d0e38a2b966799af884e78a54fd6a2dffa44788Lennart Poettering that allows checking the overall state of the system, for
f28f1daf754a9a07de90e6fc4ada581bf5de677dLennart Poettering example whether it is fully up and running.
f28f1daf754a9a07de90e6fc4ada581bf5de677dLennart Poettering * When the system boots up with an empty /etc, the equivalent
f28f1daf754a9a07de90e6fc4ada581bf5de677dLennart Poettering to "systemctl preset-all" is executed during early boot, to
88a07670cfa974a605c7c7b520b8a3135fce37f9Lennart Poettering make sure all default services are enabled after a factory
71092d70af35567dd154d3de2ce04ce62e157a7cLennart Poettering * systemd now contains a minimal preset file that enables the
916abb21d0a6653e0187b91591e492026886b0a4Lennart Poettering most basic services systemd ships by default.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * Unit files' [Install] section gained a new DefaultInstance=
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering field for defining the default instance to create if a
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering template unit is enabled with no instance specified.
b44be3ecf6326c27aa2c6c6d1fe34e22e22592a0Lennart Poettering * A new passive target cryptsetup-pre.target has been added
b23de6af893c11da4286bc416455cd0926d1532eLennart Poettering that may be used by services that need to make they run and
21bdae12e11ae20460715475d8a0c991f15464acLennart Poettering finish before the first LUKS cryptographic device is set up.
9534ce54858c67363b841cdbdc315140437bfdb4Lennart Poettering * The /dev/loop-control and /dev/btrfs-control device nodes
9534ce54858c67363b841cdbdc315140437bfdb4Lennart Poettering are now owned by the "disk" group by default, opening up
68c7d001f4117f0c3d0a4582e32cbb03ae5fac57Lennart Poettering access to this group.
68c7d001f4117f0c3d0a4582e32cbb03ae5fac57Lennart Poettering * systemd-coredump will now automatically generate a
68c7d001f4117f0c3d0a4582e32cbb03ae5fac57Lennart Poettering stack trace of all core dumps taking place on the system,
7a2a0b907b5cc60f5d9a871997d7d6e7f62bf4d8Lennart Poettering based on elfutils' libdw library. This stack trace is logged
253ee27a0c7a410d27d490bb79ea97caed6a2b68Lennart Poettering to the journal.
5d0fcd7c8d29340ac9425c309e8ac436a9af699cLennart Poettering * systemd-coredump may now optionally store coredumps directly
8bbabc447b1d913bd21faf97c7b17d20d315d2b4Lennart Poettering on disk (in /var/lib/systemd/coredump, possibly compressed),
f530371f1f85a070d7d0fb5112146a43533ae00bLennart Poettering instead of storing them unconditionally in the journal. This
e707c49485b8f4f2ec040d3da232d39153e650b9Lennart Poettering mode is the new default. A new configuration file
a19554ed92a7460b4e709cc40c558cde827ab85bLennart Poettering /etc/systemd/coredump.conf has been added to configure this
a73d88fa024b5668ed7dde681e99547d41e6a864Lennart Poettering and other parameters of systemd-coredump.
3040728b6691ea2e9df3a2060e2d49a792bbaedaLennart Poettering * coredumpctl gained a new "info" verb to show details about a
a74a8793b04de9886b4f6987b9cb86fa02c73520Lennart Poettering specific coredump. A new switch "-1" has also been added
73090dc815390f4fca4e3ed8a7e1d3806605daaaLennart Poettering that makes sure to only show information about the most
44143309dd0b37d61d7d842ca58f01a65646ec71Kay Sievers recent entry instead of all entries. Also, as the tool is
3d57c6ab801f4437f12948e29589e3d00c3ad9dbLennart Poettering generally useful now the "systemd-" prefix of the binary
71092d70af35567dd154d3de2ce04ce62e157a7cLennart Poettering name has been removed. Distributions that want to maintain
3f7a8c4e9f1d3ce48919e24eb2c9d56dd6fd88d8Kay Sievers compatibility with the old name should add a symlink from
260abb780a135e4cae8c10715c7e85675efc345aLennart Poettering the old name to the new name.
260abb780a135e4cae8c10715c7e85675efc345aLennart Poettering * journald's SplitMode= now defaults to "uid". This makes sure
2791a8f8dc8764a9247cdba3562bd4c04010f144Lennart Poettering that unprivileged users can access their own coredumps with
a8f11321c209830a35edd0357e8def5d4437d854Lennart Poettering coredumpctl without restrictions.
21bdae12e11ae20460715475d8a0c991f15464acLennart Poettering * New kernel command line options "systemd.wants=" (for
21bdae12e11ae20460715475d8a0c991f15464acLennart Poettering pulling an additional unit during boot), "systemd.mask="
c32e0c40f7e706e3ebcd101187d5ced96f083491Lennart Poettering (for masking a specific unit for the boot), and