fix(execute): make sure Type=exec and PAMName= work together - #417
Open
deepin-ci-robot wants to merge 1 commit into
Open
fix(execute): make sure Type=exec and PAMName= work together#417deepin-ci-robot wants to merge 1 commit into
deepin-ci-robot wants to merge 1 commit into
Conversation
If PAMName= is used we'll spawn a PAM session for the service, and leave a process around that closes the PAM session eventually. That process must close the "exec_fd" that we use to implement Type=exec. After all the logic relies on the fact that execve() will implicitly close the exec_fd, and the EOF seen on it is hence indication for the service manager that execve() has worked. But if we keep an fd open in the PAM service process, then this is not going to work. Hence close the fd explicitly so that it definitely doesn't stay pinned in the child. Changes: - Add debian/patches/fix-execute-type-exec-pamname-work-together.patch - Modify debian/patches/series - Modify debian/changelog Upstream: systemd/systemd@5863f1d Generated-By: glm-5.3-flash Co-Authored-By: deepin-ci-robot <packages@deepin.org>
Contributor
Author
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
TAG Bot TAG: 255.2-4deepin68 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem Before the Change
When a service unit combined
Type=execwithPAMName=, systemd spawned a separate PAM child process (sd-pam) to handle the PAM session cleanup. That child inherited the service'sexec_fd, which is used to implementType=exec. The manager relies on seeing EOF onexec_fd— induced byexecve()implicitly closing it — to detect that the service successfully started. Because the PAM child kept the fd open, EOF never arrived and the manager waited forever, deadlocking service startup.What This PR Changes
Backport of upstream systemd commit 5863f1da:
setup_pam()now receives theexec_fdas a parameter and explicitly closes it (safe_close()) in the PAM child process, so the fd is no longer pinned in the child and the manager's EOF detection works as intended.Problem Solved After the Change
Services with both
Type=execandPAMName=start reliably: once the main process callsexecve(), the manager observes EOF onexec_fdand transitions the service out of the "starting" state instead of hanging indefinitely.Changes
Upstream
systemd/systemd@5863f1d (upstream PR: #30733)
Generated-By: glm-5.3-flash
Co-Authored-By: deepin-ci-robot packages@deepin.org