]> git.apps.os.sepia.ceph.com Git - ceph.git/commit
systemd: remove `ProtectClock=true` for `ceph-osd@.service` 40845/head
authorWong Hoi Sing Edison <hswong3i@pantarei-design.com>
Wed, 14 Apr 2021 07:36:17 +0000 (15:36 +0800)
committerWong Hoi Sing Edison <hswong3i@pantarei-design.com>
Wed, 14 Apr 2021 14:19:49 +0000 (22:19 +0800)
commit85bc551b179d940a50cbdfd0c20848e3187c70a6
treef5af79bb460582b819feef504cb33f3a1617d2a3
parentff97629375a4a4e82b79f0fdcdb25f411b74d48d
systemd: remove `ProtectClock=true` for `ceph-osd@.service`

Ceph 16.2.0 Pacific by https://github.com/ceph/ceph/commit/9a84d5a introduce following new systemd restriction:

    ProtectClock=true
    ProtectHostname=true
    ProtectKernelLogs=true
    RestrictSUIDSGID=true

BTW, `ceph-osd@.service` failed with `ProtectClock=true` unexpectly, also see:

  - <https://lists.ceph.io/hyperkitty/list/ceph-users@ceph.io/thread/TNBGGNN6STGDKARAQTQCIPTU4KLIVJQV/>
  - <https://serverfault.com/questions/1059317/bluestore-var-lib-ceph-osd-ceph-2-block-read-bdev-label-failed-to-open-var-l>

This PR intruduce:

  - Remove `ProtectClock=true` for our systemd service templates

Fixes: https://tracker.ceph.com/issues/50347
Signed-off-by: Wong Hoi Sing Edison <hswong3i@pantarei-design.com>
systemd/ceph-fuse@.service.in
systemd/ceph-immutable-object-cache@.service.in
systemd/ceph-mds@.service.in
systemd/ceph-mgr@.service.in
systemd/ceph-mon@.service.in
systemd/ceph-osd@.service.in
systemd/ceph-radosgw@.service.in
systemd/ceph-rbd-mirror@.service.in
systemd/cephfs-mirror@.service.in