systemd: act as the runtime's account can, and never read a failure as an answer

The node tools runtime runs as the operator account, not root, and gives its bundles no
session words (novox/hq ADR 0175, 0188, 0193). So, per hq to-be 41 WP4:

- system-scope start/stop/restart/enable/disable go through sudo -n when not root, as the
  packet filter and intrusion prevention do, and a refusal is named by how it failed;
- user scope is plain --user with XDG_RUNTIME_DIR and the session bus of /run/user/<uid>;
  the dead --machine branches are gone;
- a failed systemctl or journalctl is an error, and an unreachable user manager is said
  even when systemctl exits 0; systemd_failed reports it beside the other manager's answer
  instead of claiming nothing failed;
- status says whether the mesh declares the unit: its loaded unit file begins with the
  header the host writes for a module's process. Only such a unit carries the restore note;
- the package resource goes: the service manager is always present, and it collided with
  systemd-networkd's identical declaration;
- calls are bounded below the runtime's call limit, a unit name is never an option, and
  the runner is injected so the tests use a fake one.
This commit is contained in:
jochen
2026-10-04 03:58:19 +02:00
parent a1d7b9ad5a
commit 0596503db5
5 changed files with 367 additions and 55 deletions
+1 -9
View File
@@ -2,8 +2,7 @@
"module": "systemd",
"version": "1",
"capabilities": [
"service-manager",
"package-manager"
"service-manager"
],
"claims": [
{
@@ -24,13 +23,6 @@
"tools": [
"systemd_failed"
],
"resources": [
{
"id": "package",
"type": "package",
"package": "systemd"
}
],
"build": {
"artifacts": [
{