[packages/incus] Resurrect spec, 7.0.1 LTS

arekm arekm at pld-linux.org
Sun Sep 13 11:07:52 CEST 2026


commit 9d9091747758222da283994e02ce3b3f78c31079
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Sun Sep 13 01:20:35 2026 +0200

    Resurrect spec, 7.0.1 LTS

 incus-dnsmasq.conf         |   4 +
 incus-rsync-apparmor.patch |  41 ++++++
 incus-shutdown.sh          |   9 ++
 incus-startup.service      |  16 +++
 incus-sysctl.conf          |   3 +
 incus-user.service         |  11 ++
 incus-user.socket          |  11 ++
 incus-wrapper.sh           |   4 +
 incus.init                 | 125 ++++++++++++++++
 incus.service              |  21 +++
 incus.socket               |  13 ++
 incus.spec                 | 352 +++++++++++++++++++++++++++++++++++++++++++++
 incus.sysconfig            |  10 ++
 incus.sysusers             |   2 +
 incus.tmpfiles             |   4 +
 15 files changed, 626 insertions(+)
---
diff --git a/incus.spec b/incus.spec
new file mode 100644
index 0000000..04f4def
--- /dev/null
+++ b/incus.spec
@@ -0,0 +1,352 @@
+Summary:	System container and virtual machine manager
+Summary(pl.UTF-8):	Zarządzanie kontenerami systemowymi i maszynami wirtualnymi
+Name:		incus
+Version:	7.0.1
+Release:	1
+License:	Apache v2.0
+Group:		Daemons
+# release tarball ships vendor/ with all Go modules; GitHub archive does not
+Source0:	https://linuxcontainers.org/downloads/incus/%{name}-%{version}.tar.xz
+# Source0-md5:	17c40cc2e6547333df85c6553415da8f
+Source1:	%{name}.socket
+Source2:	%{name}.service
+Source3:	%{name}-startup.service
+Source4:	%{name}-user.socket
+Source5:	%{name}-user.service
+Source6:	%{name}.sysusers
+Source7:	%{name}.tmpfiles
+Source8:	%{name}-dnsmasq.conf
+Source9:	%{name}-sysctl.conf
+Source10:	%{name}-shutdown.sh
+Source11:	%{name}.init
+Source12:	%{name}.sysconfig
+Source13:	%{name}-wrapper.sh
+Patch0:		%{name}-rsync-apparmor.patch
+URL:		https://linuxcontainers.org/incus/
+BuildRequires:	acl-devel
+# go-cowsql bindings refuse a libcowsql older than 1.14 at runtime
+BuildRequires:	cowsql-devel >= 1.14.0
+BuildRequires:	file
+BuildRequires:	gettext-tools
+BuildRequires:	golang >= 1.25.11
+BuildRequires:	libcap-devel
+BuildRequires:	lxc-devel >= 6.0.0
+BuildRequires:	pkgconfig
+BuildRequires:	rpmbuild(macros) >= 1.644
+BuildRequires:	sqlite3-devel >= 3.25.0
+BuildRequires:	tar >= 1:1.22
+BuildRequires:	udev-devel
+BuildRequires:	xz
+Requires(post,preun):	/sbin/chkconfig
+# usermod --add-subuids
+Requires(post):	shadow >= 4.9
+Requires(postun):	/usr/sbin/groupdel
+Requires(pre):	/usr/bin/getgid
+Requires(pre):	/usr/sbin/groupadd
+Requires:	%{name}-client = %{version}-%{release}
+Requires:	attr
+Requires:	cowsql >= 1.14.0
+Requires:	dnsmasq >= 2.90
+Requires:	iproute2
+Requires:	lxc-libs >= 6.0.0
+Requires:	lxcfs
+Requires:	nftables >= 1.0.0
+Requires:	rc-scripts
+Requires:	rsync
+Requires:	squashfs
+Requires:	squashfs-tools-ng
+Requires:	systemd-units >= 38
+Requires:	tar
+Requires:	uidmap
+Requires:	uname(release) >= 6.12
+Requires:	xz
+Suggests:	%{name}-agent = %{version}-%{release}
+Suggests:	cdrkit-mkisofs
+Suggests:	qemu-img >= 8.2
+%ifarch %{x8664}
+Suggests:	qemu-system-x86 >= 8.2
+%endif
+Suggests:	swtpm
+Suggests:	virtiofsd
+Provides:	group(incus)
+Provides:	group(incus-admin)
+ExclusiveArch:	%{x8664} aarch64
+BuildRoot:	%{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+# Go binaries: no separate debug sources to package
+%define		_enable_debug_packages	0
+
+%define		incusdir	%{_libexecdir}/%{name}
+
+%description
+Incus is a system container and virtual machine manager built on LXC
+and QEMU. It offers a REST API to manage instances locally or over the
+network, using an image based workflow, with support for snapshots,
+live migration, clustering and a wide range of storage and network
+backends.
+
+This package contains the Incus daemon.
+
+%description -l pl.UTF-8
+Incus to system zarządzania kontenerami systemowymi i maszynami
+wirtualnymi oparty na LXC i QEMU. Udostępnia API REST do zarządzania
+instancjami lokalnie lub przez sieć, pracuje na obrazach i obsługuje
+migawki, migrację na żywo, klastry oraz wiele backendów
+przechowywania danych i sieci.
+
+Ten pakiet zawiera demona Incusa.
+
+%package client
+Summary:	Incus command line client
+Summary(pl.UTF-8):	Klient Incusa dla linii poleceń
+Group:		Applications/System
+
+%description client
+Command line client for Incus. It talks to local or remote Incus
+daemons over the REST API.
+
+%description client -l pl.UTF-8
+Klient Incusa dla linii poleceń. Komunikuje się z lokalnymi lub
+zdalnymi demonami Incusa przez API REST.
+
+%package agent
+Summary:	Incus virtual machine guest agent
+Summary(pl.UTF-8):	Agent Incusa dla gości maszyn wirtualnych
+Group:		Daemons
+
+%description agent
+Statically linked agent that Incus injects into virtual machines to
+provide exec, file transfer and state reporting from inside the guest.
+Install it on the Incus host to enable agent injection.
+
+%description agent -l pl.UTF-8
+Statycznie zlinkowany agent, który Incus wstrzykuje do maszyn
+wirtualnych, aby udostępnić wykonywanie poleceń, przesyłanie plików
+i raportowanie stanu z wnętrza gościa. Instalowany na hoście Incusa.
+
+%package tools
+Summary:	Incus extra tools
+Summary(pl.UTF-8):	Dodatkowe narzędzia Incusa
+Group:		Applications/System
+Requires:	%{name} = %{version}-%{release}
+# fuidshift is also shipped by lxd-tools
+Conflicts:	lxd-tools
+
+%description tools
+Extra tools shipped with Incus:
+- fuidshift - map/unmap filesystem uids/gids
+- incus-benchmark - Incus benchmark utility
+- incus-migrate - physical to instance migration tool
+- incus-simplestreams - simplestreams image server management
+- lxc-to-incus - migrate LXC containers to Incus
+- lxd-to-incus - migrate an existing LXD installation to Incus
+
+%description tools -l pl.UTF-8
+Dodatkowe narzędzia dostarczane z Incusem:
+- fuidshift - przesuwanie uid/gid w systemie plików
+- incus-benchmark - narzędzie do testów wydajności Incusa
+- incus-migrate - migracja fizycznej maszyny do instancji
+- incus-simplestreams - zarządzanie serwerem obrazów simplestreams
+- lxc-to-incus - migracja kontenerów LXC do Incusa
+- lxd-to-incus - migracja istniejącej instalacji LXD do Incusa
+
+%package -n bash-completion-%{name}
+Summary:	Bash completion for incus command
+Summary(pl.UTF-8):	Bashowe uzupełnianie nazw dla polecenia incus
+Group:		Applications/Shells
+Requires:	%{name}-client = %{version}-%{release}
+Requires:	bash-completion >= 1:2.0
+BuildArch:	noarch
+
+%description -n bash-completion-%{name}
+Bash completion for incus command.
+
+%description -n bash-completion-%{name} -l pl.UTF-8
+Bashowe uzupełnianie nazw dla polecenia incus.
+
+%package -n fish-completion-%{name}
+Summary:	fish completion for incus command
+Summary(pl.UTF-8):	Uzupełnianie nazw w fish dla polecenia incus
+Group:		Applications/Shells
+Requires:	%{name}-client = %{version}-%{release}
+Requires:	fish
+BuildArch:	noarch
+
+%description -n fish-completion-%{name}
+fish completion for incus command.
+
+%description -n fish-completion-%{name} -l pl.UTF-8
+Uzupełnianie nazw w fish dla polecenia incus.
+
+%package -n zsh-completion-%{name}
+Summary:	zsh completion for incus command
+Summary(pl.UTF-8):	Uzupełnianie nazw w zsh dla polecenia incus
+Group:		Applications/Shells
+Requires:	%{name}-client = %{version}-%{release}
+Requires:	zsh
+BuildArch:	noarch
+
+%description -n zsh-completion-%{name}
+zsh completion for incus command.
+
+%description -n zsh-completion-%{name} -l pl.UTF-8
+Uzupełnianie nazw w zsh dla polecenia incus.
+
+%prep
+%setup -q
+%patch -P0 -p1
+
+# C sources of cowsql and raft for "make deps"; the build links system libraries
+%{__rm} -r vendor/cowsql vendor/raft
+
+%build
+export CGO_CFLAGS="%{rpmcflags}"
+export CGO_LDFLAGS="%{rpmldflags}"
+# upstream Makefile: flags used by liblxc/cowsql cgo bindings
+export CGO_LDFLAGS_ALLOW='(-Wl,-wrap,pthread_create)|(-Wl,-z,now)'
+
+for cmd in incusd incus-user incus fuidshift incus-benchmark incus-simplestreams lxc-to-incus lxd-to-incus; do
+	%__go build -v -mod=vendor -tags libsqlite3 -o bin/$cmd ./cmd/$cmd
+done
+# incus-migrate and incus-agent run on foreign systems (VM guests): fully static
+CGO_ENABLED=0 %__go build -v -mod=vendor -tags netgo -o bin/incus-migrate ./cmd/incus-migrate
+CGO_ENABLED=0 %__go build -v -mod=vendor -tags agent,netgo -o bin/incus-agent ./cmd/incus-agent
+
+%{__make} build-mo
+
+# the client insists on a writable config dir even for manpage/completion
+export INCUS_CONF=$(pwd)/.incus-conf
+install -d man completions
+bin/incus manpage man
+bin/incusd manpage man
+bin/incus completion bash > completions/incus.bash
+bin/incus completion fish > completions/incus.fish
+bin/incus completion zsh > completions/incus.zsh
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{_bindir},%{incusdir},%{_mandir}/man1} \
+	$RPM_BUILD_ROOT{%{systemdunitdir},%{systemdtmpfilesdir},%{_sysusersdir},%{_sysctldir}} \
+	$RPM_BUILD_ROOT/etc/{rc.d/init.d,sysconfig,dnsmasq.d} \
+	$RPM_BUILD_ROOT{%{bash_compdir},%{fish_compdir},%{zsh_compdir}} \
+	$RPM_BUILD_ROOT/var/{lib,log,cache}/%{name}
+
+install -p bin/{incusd,incus-user} $RPM_BUILD_ROOT%{incusdir}
+install -p %{SOURCE10} $RPM_BUILD_ROOT%{incusdir}/incus-shutdown
+install -p %{SOURCE13} $RPM_BUILD_ROOT%{incusdir}/incus-wrapper
+install -p bin/{incus,incus-agent,incus-benchmark,incus-migrate,incus-simplestreams,fuidshift,lxc-to-incus,lxd-to-incus} $RPM_BUILD_ROOT%{_bindir}
+
+cp -p man/*.1 $RPM_BUILD_ROOT%{_mandir}/man1
+
+cp -p %{SOURCE1} %{SOURCE2} %{SOURCE3} %{SOURCE4} %{SOURCE5} $RPM_BUILD_ROOT%{systemdunitdir}
+cp -p %{SOURCE6} $RPM_BUILD_ROOT%{_sysusersdir}/%{name}.conf
+cp -p %{SOURCE7} $RPM_BUILD_ROOT%{systemdtmpfilesdir}/%{name}.conf
+cp -p %{SOURCE8} $RPM_BUILD_ROOT/etc/dnsmasq.d/%{name}.conf
+cp -p %{SOURCE9} $RPM_BUILD_ROOT%{_sysctldir}/10-%{name}-inotify.conf
+install -p %{SOURCE11} $RPM_BUILD_ROOT/etc/rc.d/init.d/%{name}
+cp -p %{SOURCE12} $RPM_BUILD_ROOT/etc/sysconfig/%{name}
+
+cp -p completions/incus.bash $RPM_BUILD_ROOT%{bash_compdir}/incus
+cp -p completions/incus.fish $RPM_BUILD_ROOT%{fish_compdir}/incus.fish
+cp -p completions/incus.zsh $RPM_BUILD_ROOT%{zsh_compdir}/_incus
+
+for mo in po/*.mo; do
+	# header-only catalogs (no translated strings) are skipped by find_lang too
+	if file $mo | grep -q ', 1 message'; then
+		continue
+	fi
+	lang=$(basename $mo .mo)
+	install -D -p $mo $RPM_BUILD_ROOT%{_datadir}/locale/$lang/LC_MESSAGES/%{name}.mo
+done
+
+%find_lang %{name}
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%pre
+%groupadd -g 364 %{name}-admin
+%groupadd -g 365 %{name}
+
+%post
+# unprivileged containers need a subordinate id range for root; PLD's
+# /etc/subuid and /etc/subgid ship without one
+if ! grep -qs '^root:' /etc/subuid; then
+	/usr/sbin/usermod --add-subuids 1000000-1000999999 root
+fi
+if ! grep -qs '^root:' /etc/subgid; then
+	/usr/sbin/usermod --add-subgids 1000000-1000999999 root
+fi
+/sbin/chkconfig --add %{name}
+# no service restart here: stopping incusd via the init script shuts down every instance
+%systemd_post %{name}.socket %{name}.service %{name}-startup.service %{name}-user.socket %{name}-user.service
+
+%preun
+if [ "$1" = "0" ]; then
+	%service -q %{name} stop
+	/sbin/chkconfig --del %{name}
+fi
+%systemd_preun %{name}.socket %{name}.service %{name}-startup.service %{name}-user.socket %{name}-user.service
+
+%postun
+%systemd_reload
+if [ "$1" = "0" ]; then
+	%groupremove %{name}
+	%groupremove %{name}-admin
+fi
+
+%files
+%defattr(644,root,root,755)
+%doc AUTHORS README.md SECURITY.md
+%attr(754,root,root) /etc/rc.d/init.d/%{name}
+%config(noreplace) %verify(not md5 mtime size) /etc/sysconfig/%{name}
+%config(noreplace) %verify(not md5 mtime size) /etc/dnsmasq.d/%{name}.conf
+%{systemdunitdir}/%{name}.socket
+%{systemdunitdir}/%{name}.service
+%{systemdunitdir}/%{name}-startup.service
+%{systemdunitdir}/%{name}-user.socket
+%{systemdunitdir}/%{name}-user.service
+%{systemdtmpfilesdir}/%{name}.conf
+%{_sysusersdir}/%{name}.conf
+%{_sysctldir}/10-%{name}-inotify.conf
+%dir %{incusdir}
+%attr(755,root,root) %{incusdir}/incusd
+%attr(755,root,root) %{incusdir}/incus-user
+%attr(755,root,root) %{incusdir}/incus-shutdown
+%attr(755,root,root) %{incusdir}/incus-wrapper
+%{_mandir}/man1/incusd.1*
+%{_mandir}/man1/incusd.*.1*
+%dir %attr(711,root,root) /var/lib/%{name}
+%dir %attr(700,root,root) /var/log/%{name}
+%dir %attr(700,root,root) /var/cache/%{name}
+
+%files client -f %{name}.lang
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/incus
+%{_mandir}/man1/incus.1*
+%{_mandir}/man1/incus.*.1*
+
+%files agent
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/incus-agent
+
+%files tools
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/fuidshift
+%attr(755,root,root) %{_bindir}/incus-benchmark
+%attr(755,root,root) %{_bindir}/incus-migrate
+%attr(755,root,root) %{_bindir}/incus-simplestreams
+%attr(755,root,root) %{_bindir}/lxc-to-incus
+%attr(755,root,root) %{_bindir}/lxd-to-incus
+
+%files -n bash-completion-%{name}
+%defattr(644,root,root,755)
+%{bash_compdir}/incus
+
+%files -n fish-completion-%{name}
+%defattr(644,root,root,755)
+%{fish_compdir}/incus.fish
+
+%files -n zsh-completion-%{name}
+%defattr(644,root,root,755)
+%{zsh_compdir}/_incus
diff --git a/incus-dnsmasq.conf b/incus-dnsmasq.conf
new file mode 100644
index 0000000..f8a8d3c
--- /dev/null
+++ b/incus-dnsmasq.conf
@@ -0,0 +1,4 @@
+# Make a system-wide dnsmasq bind to explicit interfaces and leave the
+# Incus bridge alone; incusd runs its own dnsmasq on incusbr0.
+bind-interfaces
+except-interface=incusbr0
diff --git a/incus-rsync-apparmor.patch b/incus-rsync-apparmor.patch
new file mode 100644
index 0000000..d6b6c82
--- /dev/null
+++ b/incus-rsync-apparmor.patch
@@ -0,0 +1,41 @@
+# rsync 3.5.0 opens every ancestor of the destination; the generated AppArmor
+# profile denied that, so snapshots and VM agent setup failed (lxc/incus#3968)
+# https://github.com/lxc/incus/commit/040909b969
+diff --git a/internal/server/apparmor/rsync.go b/internal/server/apparmor/rsync.go
+index 6a0b059d2fe..5a1da30d695 100644
+--- a/internal/server/apparmor/rsync.go
++++ b/internal/server/apparmor/rsync.go
+@@ -44,6 +44,9 @@ profile "{{ .name }}" flags=(attach_disconnected,mediate_deleted) {
+ {{- end }}
+ 
+ {{- if .dstPath }}
++{{- range .dstParents }}
++  {{ . }} r,
++{{- end }}
+   {{ .dstPath }}/** rwkl,
+   {{ .dstPath }}/ rwkl,
+ {{- end }}
+@@ -165,12 +168,23 @@ func rsyncProfile(sysOS *sys.OS, name string, sourcePath string, dstPath string)
+ 		execPath = fullPath
+ 	}
+ 
++	// rsync 3.5+ resolves the destination component by component from /.
++	dstParents := []string{}
++	if dstPath != "" {
++		for dir := filepath.Dir(filepath.Clean(dstPath)); dir != "/"; dir = filepath.Dir(dir) {
++			dstParents = append(dstParents, dir+"/")
++		}
++
++		dstParents = append(dstParents, "/")
++	}
++
+ 	sb := &strings.Builder{}
+ 	err = rsyncProfileTpl.Execute(sb, map[string]any{
+ 		"name":        name,
+ 		"execPath":    execPath,
+ 		"sourcePath":  sourcePath,
+ 		"dstPath":     dstPath,
++		"dstParents":  dstParents,
+ 		"logPath":     logPath,
+ 		"libraryPath": strings.Split(os.Getenv("LD_LIBRARY_PATH"), ":"),
+ 	})
diff --git a/incus-shutdown.sh b/incus-shutdown.sh
new file mode 100644
index 0000000..bbfde76
--- /dev/null
+++ b/incus-shutdown.sh
@@ -0,0 +1,9 @@
+#!/bin/sh
+# Stop all instances cleanly when incus-startup.service stops, but only
+# if the daemon is actually running (activateifneeded may have left it off).
+
+if ! systemctl -q is-active incus.service; then
+	exit 0
+fi
+
+exec /usr/libexec/incus/incusd shutdown
diff --git a/incus-startup.service b/incus-startup.service
new file mode 100644
index 0000000..64d7057
--- /dev/null
+++ b/incus-startup.service
@@ -0,0 +1,16 @@
+[Unit]
+Description=Incus - Instance startup
+Documentation=man:incusd(1)
+After=incus.socket incus.service
+Requires=incus.socket
+
+[Service]
+Type=oneshot
+ExecStart=/usr/libexec/incus/incusd activateifneeded
+ExecStop=/usr/libexec/incus/incus-shutdown
+TimeoutStartSec=600s
+TimeoutStopSec=600s
+RemainAfterExit=yes
+
+[Install]
+WantedBy=multi-user.target
diff --git a/incus-sysctl.conf b/incus-sysctl.conf
new file mode 100644
index 0000000..7505bda
--- /dev/null
+++ b/incus-sysctl.conf
@@ -0,0 +1,3 @@
+# Each running container costs inotify instances on the host; the kernel
+# default of 128 is exhausted after a few dozen instances.
+fs.inotify.max_user_instances = 1024
diff --git a/incus-user.service b/incus-user.service
new file mode 100644
index 0000000..d0242b1
--- /dev/null
+++ b/incus-user.service
@@ -0,0 +1,11 @@
+[Unit]
+Description=Incus - User daemon
+After=incus-user.socket incus.service
+Requires=incus-user.socket
+
+[Service]
+ExecStart=/usr/libexec/incus/incus-user --group incus
+Restart=on-failure
+
+[Install]
+Also=incus-user.socket
diff --git a/incus-user.socket b/incus-user.socket
new file mode 100644
index 0000000..5c14276
--- /dev/null
+++ b/incus-user.socket
@@ -0,0 +1,11 @@
+[Unit]
+Description=Incus - Daemon (user unix socket)
+
+[Socket]
+ListenStream=/var/lib/incus/unix.socket.user
+SocketGroup=incus
+SocketMode=0660
+Service=incus-user.service
+
+[Install]
+WantedBy=sockets.target
diff --git a/incus-wrapper.sh b/incus-wrapper.sh
new file mode 100644
index 0000000..29f1637
--- /dev/null
+++ b/incus-wrapper.sh
@@ -0,0 +1,4 @@
+#!/bin/sh
+# incusd keeps writing to stderr after startup; under rc-scripts that pipe
+# is gone once initlog exits and the Go runtime dies on the resulting SIGPIPE
+exec /usr/libexec/incus/incusd --logfile /var/log/incus/incusd.log "$@" >/dev/null 2>&1
diff --git a/incus.init b/incus.init
new file mode 100644
index 0000000..404ebc1
--- /dev/null
+++ b/incus.init
@@ -0,0 +1,125 @@
+#!/bin/sh
+#
+# incus		System container and virtual machine manager
+#
+# chkconfig:	345 20 80
+#
+# description:	Incus is a system container and virtual machine manager \
+#		built on LXC and QEMU, with a REST API and the incus CLI.
+# processname:	incusd
+# pidfile:	/var/run/incusd.pid
+#
+
+# Source function library
+. /etc/rc.d/init.d/functions
+
+# Get network config
+. /etc/sysconfig/network
+
+# Check that networking is up.
+if is_yes "${NETWORKING}"; then
+	if [ ! -f /var/lock/subsys/network -a "$1" != stop -a "$1" != status ]; then
+		msg_network_down "Incus"
+		exit 1
+	fi
+else
+	exit 0
+fi
+
+# Get service config - may override defaults
+[ -f /etc/sysconfig/incus ] && . /etc/sysconfig/incus
+
+pidfile="/var/run/incusd.pid"
+incusd="/usr/libexec/incus/incusd"
+wrapper="/usr/libexec/incus/incus-wrapper"
+
+start() {
+	if [ -f /var/lock/subsys/incus ]; then
+		msg_already_running "Incus"
+		return
+	fi
+
+	# lxcfs makes /proc inside containers reflect their cgroup limits
+	if [ -x /etc/rc.d/init.d/lxcfs ] && [ ! -f /var/lock/subsys/lxcfs ]; then
+		/etc/rc.d/init.d/lxcfs start
+	fi
+
+	msg_starting "Incus"
+	daemon --makepid --pidfile $pidfile --waitforname incusd \
+		$wrapper --group incus-admin $OPTIONS
+	RETVAL=$?
+	if [ $RETVAL -eq 0 ]; then
+		show "Waiting for Incus to become ready"
+		busy
+		if $incusd waitready --timeout=600; then
+			ok
+			touch /var/lock/subsys/incus
+		else
+			fail
+			RETVAL=1
+		fi
+	fi
+}
+
+stop() {
+	if [ ! -f /var/lock/subsys/incus ]; then
+		msg_not_running "Incus"
+		return
+	fi
+
+	# Stop daemons.
+	msg_stopping "Incus"
+	# stops all instances, then the daemon; the API call returns before the process is gone
+	$incusd shutdown --timeout=600
+	for i in $(seq 1 30); do
+		status --pidfile $pidfile incusd incus >/dev/null 2>&1 || break
+		sleep 1
+	done
+	if status --pidfile $pidfile incusd incus >/dev/null 2>&1; then
+		killproc --pidfile $pidfile incusd
+	else
+		ok
+	fi
+	rm -f /var/lock/subsys/incus $pidfile
+}
+
+condrestart() {
+	if [ ! -f /var/lock/subsys/incus ]; then
+		msg_not_running "Incus"
+		RETVAL=$1
+		return
+	fi
+
+	stop
+	start
+}
+
+RETVAL=0
+# See how we were called.
+case "$1" in
+  start)
+	start
+	;;
+  stop)
+	stop
+	;;
+  restart)
+	stop
+	start
+	;;
+  try-restart)
+	condrestart 0
+	;;
+  force-reload)
+	condrestart 7
+	;;
+  status)
+	status --pidfile $pidfile incusd incus
+	RETVAL=$?
+	;;
+  *)
+	msg_usage "$0 {start|stop|restart|try-restart|force-reload|status}"
+	exit 3
+esac
+
+exit $RETVAL
diff --git a/incus.service b/incus.service
new file mode 100644
index 0000000..c203ec4
--- /dev/null
+++ b/incus.service
@@ -0,0 +1,21 @@
+[Unit]
+Description=Incus - Daemon
+Documentation=man:incusd(1)
+After=network-online.target openvswitch-switch.service lxcfs.service incus.socket
+Requires=network-online.target lxcfs.service incus.socket
+
+[Service]
+EnvironmentFile=-/etc/sysconfig/incus
+ExecStart=/usr/libexec/incus/incusd --group incus-admin $OPTIONS
+ExecStartPost=/usr/libexec/incus/incusd waitready --timeout=600
+KillMode=process
+TimeoutStartSec=600s
+TimeoutStopSec=30s
+Restart=on-failure
+Delegate=yes
+LimitNOFILE=1048576
+LimitNPROC=infinity
+TasksMax=infinity
+
+[Install]
+Also=incus-startup.service incus.socket
diff --git a/incus.socket b/incus.socket
new file mode 100644
index 0000000..0b2aa8d
--- /dev/null
+++ b/incus.socket
@@ -0,0 +1,13 @@
+[Unit]
+Description=Incus - Daemon (unix socket)
+Documentation=man:incusd(1)
+
+[Socket]
+FileDescriptorName=unix
+ListenStream=/var/lib/incus/unix.socket
+SocketGroup=incus-admin
+SocketMode=0660
+Service=incus.service
+
+[Install]
+WantedBy=sockets.target
diff --git a/incus.sysconfig b/incus.sysconfig
new file mode 100644
index 0000000..28037c6
--- /dev/null
+++ b/incus.sysconfig
@@ -0,0 +1,10 @@
+# Customized settings for incusd
+
+# Define nice level for incusd (init script only)
+SERVICE_RUN_NICE_LEVEL="+0"
+
+# Max open files and max processes (init script only, systemd unit sets its own)
+SERVICE_LIMITS="-n 1048576 -u 1048576"
+
+# Extra options for incusd (see incusd --help)
+#OPTIONS=""
diff --git a/incus.sysusers b/incus.sysusers
new file mode 100644
index 0000000..efdbe66
--- /dev/null
+++ b/incus.sysusers
@@ -0,0 +1,2 @@
+g incus-admin 364 - -
+g incus 365 - -
diff --git a/incus.tmpfiles b/incus.tmpfiles
new file mode 100644
index 0000000..2e66a6d
--- /dev/null
+++ b/incus.tmpfiles
@@ -0,0 +1,4 @@
+d /var/cache/incus 0700 root root - -
+d /var/log/incus 0700 root root - -
+d /var/lib/incus 0711 root root - -
+d /run/incus 0711 root root - -
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/incus.git/commitdiff/9d9091747758222da283994e02ce3b3f78c31079



More information about the pld-cvs-commit mailing list