blob: 417110181c5d97d222578894ec21468e1f7e68f2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
|
#!/bin/bash
sd_booted() {
[[ -d run/systemd/system && ! -L run/systemd/system ]]
}
add_journal_acls() {
# ignore errors, since the filesystem might not support ACLs
setfacl -Rnm g:wheel:rx,d:g:wheel:rx,g:adm:rx,d:g:adm:rx var/log/journal/ 2>/dev/null
:
}
post_common() {
systemd-sysusers
journalctl --update-catalog
}
_216_2_changes() {
echo ':: Coredumps are handled by systemd by default. Collection behavior can be'
echo ' tuned in /etc/systemd/coredump.conf.'
}
_219_2_changes() {
if mkdir -m2755 var/log/journal/remote 2>/dev/null; then
chgrp systemd-journal-remote var/log/journal/remote
fi
}
_219_4_changes() {
if ! systemctl is-enabled -q remote-fs.target; then
systemctl enable -q remote-fs.target
fi
}
_230_1_changes() {
echo ':: systemd-bootchart is no longer included with systemd'
}
_232_8_changes() {
# paper over possible effects of CVE-2016-10156
local stamps=(/var/lib/systemd/timers/*.timer)
if [[ -f ${stamps[0]} ]]; then
chmod 0644 "${stamps[@]}"
fi
}
_233_75_3_changes() {
# upstream installs services to /etc, which we remove
# to keep bus activation we re-enable systemd-resolved
if systemctl is-enabled -q systemd-resolved.service; then
systemctl reenable systemd-resolved.service 2>/dev/null
fi
}
_242_0_2_changes() {
if [[ -L var/lib/systemd/timesync ]]; then
rm var/lib/systemd/timesync
if [[ -d var/lib/private/systemd/timesync ]]; then
mv var/lib/{private/,}systemd/timesync
fi
fi
}
post_install() {
systemd-machine-id-setup
post_common "$@"
add_journal_acls
# enable some services by default, but don't track them
systemctl enable getty@tty1.service remote-fs.target
echo ":: Append 'init=/usr/lib/systemd/systemd' to your kernel command line in your"
echo " bootloader to replace sysvinit with systemd, or install systemd-sysvcompat"
# group 'systemd-journal-remote' is created by systemd-sysusers
mkdir -m2755 var/log/journal/remote
chgrp systemd-journal-remote var/log/journal/remote
}
post_upgrade() {
post_common "$@"
# don't reexec if the old version is 231-1 or 231-2.
# https://github.com/systemd/systemd/commit/bd64d82c1c
if [[ $1 != 231-[12] ]] && sd_booted; then
systemctl --system daemon-reexec
fi
local v upgrades=(
216-2
219-2
219-4
230-1
232-8
233.75-3
242.0-2
)
for v in "${upgrades[@]}"; do
if [[ $(vercmp "$v" "$2") -eq 1 ]]; then
"_${v//[.-]/_}_changes"
fi
done
}
# vim:set ts=2 sw=2 et:
|