Skip to content

fix(execute): make sure Type=exec and PAMName= work together - #417

Open
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-execute-type-exec-pamname
Open

fix(execute): make sure Type=exec and PAMName= work together#417
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-execute-type-exec-pamname

Conversation

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

Problem Before the Change

When a service unit combined Type=exec with PAMName=, systemd spawned a separate PAM child process (sd-pam) to handle the PAM session cleanup. That child inherited the service's exec_fd, which is used to implement Type=exec. The manager relies on seeing EOF on exec_fd — induced by execve() implicitly closing it — to detect that the service successfully started. Because the PAM child kept the fd open, EOF never arrived and the manager waited forever, deadlocking service startup.

What This PR Changes

Backport of upstream systemd commit 5863f1da: setup_pam() now receives the exec_fd as a parameter and explicitly closes it (safe_close()) in the PAM child process, so the fd is no longer pinned in the child and the manager's EOF detection works as intended.

Problem Solved After the Change

Services with both Type=exec and PAMName= start reliably: once the main process calls execve(), the manager observes EOF on exec_fd and transitions the service out of the "starting" state instead of hanging indefinitely.

Changes

  • Add debian/patches/fix-execute-type-exec-pamname-work-together.patch
  • Modify debian/patches/series
  • Modify debian/changelog

Upstream

systemd/systemd@5863f1d (upstream PR: #30733)

Generated-By: glm-5.3-flash
Co-Authored-By: deepin-ci-robot packages@deepin.org

If PAMName= is used we'll spawn a PAM session for the service, and leave
a process around that closes the PAM session eventually. That process
must close the "exec_fd" that we use to implement Type=exec. After all
the logic relies on the fact that execve() will implicitly close the
exec_fd, and the EOF seen on it is hence indication for the service
manager that execve() has worked. But if we keep an fd open in the PAM
service process, then this is not going to work.

Hence close the fd explicitly so that it definitely doesn't stay pinned
in the child.

Changes:
  - Add debian/patches/fix-execute-type-exec-pamname-work-together.patch
  - Modify debian/patches/series
  - Modify debian/changelog

Upstream: systemd/systemd@5863f1d

Generated-By: glm-5.3-flash
Co-Authored-By: deepin-ci-robot <packages@deepin.org>
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign liujianqiang-niu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

TAG Bot

TAG: 255.2-4deepin68
EXISTED: no
DISTRIBUTION: unstable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant