<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.rosa.ru/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://bugzilla.rosa.ru/"
          
          maintainer="d.postnikov@rosa.ru"
>

    <bug>
          <bug_id>11597</bug_id>
          
          <creation_ts>2021-11-04 00:50:55 +0300</creation_ts>
          <short_desc>[fix 21] systemd 249-1.gitfab79a.12</short_desc>
          <delta_ts>2021-11-09 05:48:13 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>2</classification_id>
          <classification>ROSA-based products</classification>
          <product>ROSA Fresh</product>
          <component>Packages from Main</component>
          <version>All</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Normal</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mikhail Novosyolov">m.novosyolov</reporter>
          <assigned_to name="ROSA Linux Bugs">bugs</assigned_to>
          <cc>0861</cc>
    
    <cc>79625490833</cc>
    
    <cc>a.proklov</cc>
    
    <cc>v.potapov</cc>
          
          <cf_platform>2021.1</cf_platform>
          <cf_security_code></cf_security_code>
          <cf_package></cf_package>
          

      

      

      <flag name="qa_verified"
          id="10510"
          type_id="1"
          status="+"
          setter="v.potapov"
    />
    <flag name="published"
          id="10514"
          type_id="3"
          status="+"
          setter="a.proklov"
    />

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>60534</commentid>
    <comment_count>0</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:50:55 +0300</bug_when>
    <thetext>********* QA ADVISORY **********

libseccomp 2.5.2-1

- updated from 2.5.1 to 2.5.2
- fixed building without %check

https://abf.io/build_lists/3950847
https://abf.io/build_lists/3950848
https://abf.io/build_lists/3950858



systemd 249-1.gitfab79a.12
**************************

- Disable DNSSEC in systemd-resolved by default

DNSSEC implementation in systemd-resolved is unreliable and causes random failures of DNSSEC validation. Fedora disables it (https://fedoraproject.org/wiki/Changes/systemd-resolved#DNSSEC). Disable it in ROSA (set -Ddefault-dnssec=no) by default, it can be enabled via /etc/systemd/resolved.conf or resolvectl(1).

Commit: https://abf.io/import/systemd/commit/d0d22ad5b609ce71b6bce9ff017c3b8d68e31098
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11569
**************************

- Disable mDNS resolution via systemd-resolved by default

Let Avahi handle mDNS resolution, see:
https://bugzilla.redhat.com/show_bug.cgi?id=1867830
when both avahi and resolved run, they conflict. If we put mdns_minimal before resolve in /etc/nsswitch.conf, than it is resolved who will actually do DNS resolution, not Avahi.
Avahi, as an implementation of mDNS, is important because it can not only resolve DNS, but also announce local service, we do it in openssh-server for example.
So choosing to leave Avahi as it is for now. resolved will not respond for mDNS-related DNS queries.

Disable LLMNR responding by default to avoid strange problems (see rhbz#1867830) and listening to a port on 0.0.0.0 (security issue).
LLMNR resolving is still enabled by default.

Disabled functionality can be reenabled via /etc/systemd/resolved.conf or resolvectl(1).

Commit: https://abf.io/import/systemd/commit/ec66f86b9ee3905574627f653d9352464a1ad62f
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11570
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11534
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11328
**************************

- Make Yandex DNS have higher priority than Google ones

Most users of ROSA are in Russia. Yandex is a Russian service. Also, many people have ping to Yandex lower than to Google.

Commit: https://abf.io/import/systemd/commit/65ec259466770bd4c8ce86e7d3c9778ec8366b08
**************************

- Fix location of oomd and udev parts

* move all oomd-related files into systemd-oomd subpackage
* move all hwdb-related files into udev subpackage
* explicitly list files in some places instead of useing globs to make this move possible and to track files better
* move some directories from systemd to systemd-units: current subpackage systemd-units does not make much sense, but owning some ramdom directories by systemd while most of the are owned by systemd-units makes even less sense
* remove some no more needed Obsoletes

Commit: https://abf.io/import/systemd/commit/b04e4f7d287feb53d7e294c376d19fa8ccae2e56
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11559
**************************

- add provides for scripts compatibility with OMV (fedya@)
Commit: https://abf.io/import/systemd/commit/5eeaecc0e0d3a75c2e0ce1dce1b69c71e2870d17
**************************

- Remove broken symlink /etc/systemd/system/syslog.service if it points to nowhere

Commit: https://abf.io/import/systemd/commit/5eeaecc0e0d3a75c2e0ce1dce1b69c71e2870d17
**************************

- Remove obsolete udev rule 

&quot;all_partitions&quot; is not known to udev.
udisks2 package has a rule for these devices in another form:

ENV{ID_VENDOR}==&quot;*IOMEGA*&quot;, ENV{ID_MODEL}==&quot;*ZIP*&quot;, ENV{ID_DRIVE_FLOPPY_ZIP}=&quot;1&quot;

&quot;all_partitions&quot; meant creating block devices for every partition in old versions of udev,
there is no such option now. Let&apos;s just remove this line.

See: https://shallowsky.com/blog/linux/udev-static-devices.html
Commit: https://abf.io/import/systemd/commit/9c37ce53f132a94d0f1682682969fb176eaea6e8
**************************

- Disable updater of systemd-boot by default
Grub2 is used in most cases, calling bootctl does not make sense, and it fails.
Commit: https://abf.io/import/systemd/commit/270832d886afa4028d58218af05176c4cf78d58d
**************************

- Fixed licenses
systemd is licensed under LPGL, udev is licensed under GPL
Commit: https://abf.io/import/systemd/commit/e9ac850382dfbf53db3eba4d5ff37dcdede28daa
**************************

- Enable login in emergency mode if root account is locked
Commit: https://abf.io/import/systemd/commit/536a67c4ad9c9b3bf21013787a5f58be95277136
Fixes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=11592
**************************

https://abf.io/build_lists/3953964
https://abf.io/build_lists/3953965
https://abf.io/build_lists/3953966</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60536</commentid>
    <comment_count>1</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:53:05 +0300</bug_when>
    <thetext>*** Bug 11569 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60538</commentid>
    <comment_count>2</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:53:17 +0300</bug_when>
    <thetext>*** Bug 11570 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60540</commentid>
    <comment_count>3</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:53:37 +0300</bug_when>
    <thetext>*** Bug 11534 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60542</commentid>
    <comment_count>4</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:53:45 +0300</bug_when>
    <thetext>*** Bug 11328 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60544</commentid>
    <comment_count>5</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:53:59 +0300</bug_when>
    <thetext>*** Bug 11559 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60546</commentid>
    <comment_count>6</comment_count>
    <who name="Mikhail Novosyolov">m.novosyolov</who>
    <bug_when>2021-11-04 00:54:05 +0300</bug_when>
    <thetext>*** Bug 11592 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60574</commentid>
    <comment_count>7</comment_count>
    <who name="Vladimir Potapov">v.potapov</who>
    <bug_when>2021-11-05 18:44:40 +0300</bug_when>
    <thetext>systemd-249-1.gitfab79a.12
https://abf.io/build_lists/3953964
https://abf.io/build_lists/3953965
https://abf.io/build_lists/3953966

libseccomp-2.5.2-1
https://abf.io/build_lists/3950847
https://abf.io/build_lists/3950848
https://abf.io/build_lists/3950858
******************* Advisory *************************
- Disable DNSSEC in systemd-resolved by default
- Fix location of oomd and udev parts
- Make Yandex DNS have higher priority than Google ones
- add provides for scripts compatibility with OMV (fedya@)
- Disable updater of systemd-boot by default
- Remove broken symlink /etc/systemd/system/syslog.service
- Fixed licenses
- Remove obsolete udev rule
- Enable login in rescue (single) mode if root account is locked
******************************************************
QA Verified</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>