Changes:
- autovt@.service moved from a static meson-installed symlink to an
[Install] Alias= on getty@.service upstream. We do not process
[Install] sections, and logind still hardcodes spawning
autovt@ttyN.service on VT switch, so recreate the alias.
- kmscon: suppress getty@.service instead of autovt@.service.
Add static pull-in of kmsconvt@tty1 via getty.target since logind
does not spawn autovt on tty1 by design.
- modprobe@.service: upstream switched ExecStart from /sbin/modprobe to
a bare 'modprobe' relying on PATH. Update the substitution to match
the new form, since DEFAULT_PATH on NixOS is systemd's own bindir
which has no modprobe.
- Remove stale substituteInPlace patterns for paths removed upstream
(/bin/echo in test-fileio.c, /bin/cat in cat.c, /usr/bin/getent in
nspawn-setuid.c)
- Remove dead CFLAGS overrides for POLKIT_AGENT_BINARY_PATH (replaced
by runtime find_executable) and SYSTEMD_CGROUP_AGENTS_PATH (cgroup-v1
leftover, gone before v259). Use --replace-fail for the remaining
config.h substitution so future removals fail loudly.
- Remove deprecated meson options (sysvinit-path, sysvrcnd-path, libidn)
- Handle new pull-oci.c tar references
- Drop upstreamed patch 0017-meson.build-do-not-create-systemdstatedir.patch
The default systemd sysctl snippet contains various security‐relevant
settings, it is however only installed if systemd.coredump.enable is
enabled, despite these settings not being strictly related to
systemd-coredump.
Trigger re-installation of grub files when the store path of the grub
package changes.
This is consistent with how side-effects are executed in other parts of
NixOS, e.g. systemd service management, and ensures that the actually
running grub stays in sync with the grub package in the Nix store that
is part of the system closure.
In particular, this causes security patches or dependency changes to be
taken into effect without the need to bump the package version.
Impact:
This change causes a re-installation of grub for all systems,
due to the lack of a persisted grub store path in existing state files.
Background:
So far we only re-installed grub outside of the store when its its
version, the package name, or some flags changed.
This leads to the various security patches only fixing new installations
of grub and not existing ones. This has been like this for over a decade,
but it remains unclear why the implementation decision had been to
be overly cautious with modifying boot loader side effects.
Fixes#486315
PL-135147
Nowadays, the RTC is fully managed by systemd and the kernel.
In userspace, timedated is enabled by default and the clock can be
adjusted with timedatectl.
Further, NixOS enables timesyncd by default, so the clock should be
synced to NTP as long as the system is connected to the internet.
Since early 2013 (Linux 3.9), CONFIG_RTC_SYSTOHC is available and on by
default. [1]
When userspace reports that NTP is synced, this causes the kernel to
periodically update the RTC.
It therefore makes no sense to keep this service enabled when using NTP.
The kernel has seemingly loaded the time from the RTC at bootup for a
very long time. [2]
Manual `hwclock --hctosys` was removed in #165684.
This all seem to make manual RTC fiddling redundant.
My Arch systems don't do it and they've never had any trouble keeping
the time.
The only remaining raison d'être for this service is offline drift
compensation as documented in hwclock(8). [3]
This isn't implemented in NixOS, and the (unmaintained) tool [4] for
this isn't even packaged.
I don't think anyone is relying on this functionality, and it doesn't
seem right to only implement it partially rather than within a more
complete module.
One thing this service actually implemented, rather shakily, is
time.hardwareClockInLocalTime.
This can more reliably be achieved by creating /etc/adjtime directly.
[1]: 023f333a99
[2]: 0c86edc0d4
[3]: https://man.archlinux.org/man/hwclock.8#Keeping_Time_without_External_Synchronization
[4]: https://github.com/rogers0/adjtimex
Replace the stringly-typed systemd.sleep.extraConfig option (types.lines)
with systemd.sleep.settings.Sleep, a freeformType submodule using
types.attrsOf unitOption. This follows the same pattern already used by
systemd.settings.Manager, services.logind.settings.Login, and other
systemd modules that have been migrated to RFC42.
The sleep.conf file is now rendered via settingsToSections instead of raw
string interpolation.
A mkRemovedOptionModule is added for the old option path to give users a
clear migration message.
This is done to prepare the removal of
0006-hostnamed-localed-timedated-disable-methods-that-cha.patch from
systemd.
Pointing the daemon to /etc/static will make imperative changes to these
files (e.g. via hostnamectl) fail because systemd cannot edit them.