[packages/incus] Resurrect spec, 7.0.1 LTS
arekm
arekm at pld-linux.org
Sun Sep 13 11:07:52 CEST 2026
commit 9d9091747758222da283994e02ce3b3f78c31079
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Sun Sep 13 01:20:35 2026 +0200
Resurrect spec, 7.0.1 LTS
incus-dnsmasq.conf | 4 +
incus-rsync-apparmor.patch | 41 ++++++
incus-shutdown.sh | 9 ++
incus-startup.service | 16 +++
incus-sysctl.conf | 3 +
incus-user.service | 11 ++
incus-user.socket | 11 ++
incus-wrapper.sh | 4 +
incus.init | 125 ++++++++++++++++
incus.service | 21 +++
incus.socket | 13 ++
incus.spec | 352 +++++++++++++++++++++++++++++++++++++++++++++
incus.sysconfig | 10 ++
incus.sysusers | 2 +
incus.tmpfiles | 4 +
15 files changed, 626 insertions(+)
---
diff --git a/incus.spec b/incus.spec
new file mode 100644
index 0000000..04f4def
--- /dev/null
+++ b/incus.spec
@@ -0,0 +1,352 @@
+Summary: System container and virtual machine manager
+Summary(pl.UTF-8): Zarządzanie kontenerami systemowymi i maszynami wirtualnymi
+Name: incus
+Version: 7.0.1
+Release: 1
+License: Apache v2.0
+Group: Daemons
+# release tarball ships vendor/ with all Go modules; GitHub archive does not
+Source0: https://linuxcontainers.org/downloads/incus/%{name}-%{version}.tar.xz
+# Source0-md5: 17c40cc2e6547333df85c6553415da8f
+Source1: %{name}.socket
+Source2: %{name}.service
+Source3: %{name}-startup.service
+Source4: %{name}-user.socket
+Source5: %{name}-user.service
+Source6: %{name}.sysusers
+Source7: %{name}.tmpfiles
+Source8: %{name}-dnsmasq.conf
+Source9: %{name}-sysctl.conf
+Source10: %{name}-shutdown.sh
+Source11: %{name}.init
+Source12: %{name}.sysconfig
+Source13: %{name}-wrapper.sh
+Patch0: %{name}-rsync-apparmor.patch
+URL: https://linuxcontainers.org/incus/
+BuildRequires: acl-devel
+# go-cowsql bindings refuse a libcowsql older than 1.14 at runtime
+BuildRequires: cowsql-devel >= 1.14.0
+BuildRequires: file
+BuildRequires: gettext-tools
+BuildRequires: golang >= 1.25.11
+BuildRequires: libcap-devel
+BuildRequires: lxc-devel >= 6.0.0
+BuildRequires: pkgconfig
+BuildRequires: rpmbuild(macros) >= 1.644
+BuildRequires: sqlite3-devel >= 3.25.0
+BuildRequires: tar >= 1:1.22
+BuildRequires: udev-devel
+BuildRequires: xz
+Requires(post,preun): /sbin/chkconfig
+# usermod --add-subuids
+Requires(post): shadow >= 4.9
+Requires(postun): /usr/sbin/groupdel
+Requires(pre): /usr/bin/getgid
+Requires(pre): /usr/sbin/groupadd
+Requires: %{name}-client = %{version}-%{release}
+Requires: attr
+Requires: cowsql >= 1.14.0
+Requires: dnsmasq >= 2.90
+Requires: iproute2
+Requires: lxc-libs >= 6.0.0
+Requires: lxcfs
+Requires: nftables >= 1.0.0
+Requires: rc-scripts
+Requires: rsync
+Requires: squashfs
+Requires: squashfs-tools-ng
+Requires: systemd-units >= 38
+Requires: tar
+Requires: uidmap
+Requires: uname(release) >= 6.12
+Requires: xz
+Suggests: %{name}-agent = %{version}-%{release}
+Suggests: cdrkit-mkisofs
+Suggests: qemu-img >= 8.2
+%ifarch %{x8664}
+Suggests: qemu-system-x86 >= 8.2
+%endif
+Suggests: swtpm
+Suggests: virtiofsd
+Provides: group(incus)
+Provides: group(incus-admin)
+ExclusiveArch: %{x8664} aarch64
+BuildRoot: %{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+# Go binaries: no separate debug sources to package
+%define _enable_debug_packages 0
+
+%define incusdir %{_libexecdir}/%{name}
+
+%description
+Incus is a system container and virtual machine manager built on LXC
+and QEMU. It offers a REST API to manage instances locally or over the
+network, using an image based workflow, with support for snapshots,
+live migration, clustering and a wide range of storage and network
+backends.
+
+This package contains the Incus daemon.
+
+%description -l pl.UTF-8
+Incus to system zarządzania kontenerami systemowymi i maszynami
+wirtualnymi oparty na LXC i QEMU. Udostępnia API REST do zarządzania
+instancjami lokalnie lub przez sieć, pracuje na obrazach i obsługuje
+migawki, migrację na żywo, klastry oraz wiele backendów
+przechowywania danych i sieci.
+
+Ten pakiet zawiera demona Incusa.
+
+%package client
+Summary: Incus command line client
+Summary(pl.UTF-8): Klient Incusa dla linii poleceń
+Group: Applications/System
+
+%description client
+Command line client for Incus. It talks to local or remote Incus
+daemons over the REST API.
+
+%description client -l pl.UTF-8
+Klient Incusa dla linii poleceń. Komunikuje się z lokalnymi lub
+zdalnymi demonami Incusa przez API REST.
+
+%package agent
+Summary: Incus virtual machine guest agent
+Summary(pl.UTF-8): Agent Incusa dla gości maszyn wirtualnych
+Group: Daemons
+
+%description agent
+Statically linked agent that Incus injects into virtual machines to
+provide exec, file transfer and state reporting from inside the guest.
+Install it on the Incus host to enable agent injection.
+
+%description agent -l pl.UTF-8
+Statycznie zlinkowany agent, który Incus wstrzykuje do maszyn
+wirtualnych, aby udostępnić wykonywanie poleceń, przesyłanie plików
+i raportowanie stanu z wnętrza gościa. Instalowany na hoście Incusa.
+
+%package tools
+Summary: Incus extra tools
+Summary(pl.UTF-8): Dodatkowe narzędzia Incusa
+Group: Applications/System
+Requires: %{name} = %{version}-%{release}
+# fuidshift is also shipped by lxd-tools
+Conflicts: lxd-tools
+
+%description tools
+Extra tools shipped with Incus:
+- fuidshift - map/unmap filesystem uids/gids
+- incus-benchmark - Incus benchmark utility
+- incus-migrate - physical to instance migration tool
+- incus-simplestreams - simplestreams image server management
+- lxc-to-incus - migrate LXC containers to Incus
+- lxd-to-incus - migrate an existing LXD installation to Incus
+
+%description tools -l pl.UTF-8
+Dodatkowe narzędzia dostarczane z Incusem:
+- fuidshift - przesuwanie uid/gid w systemie plików
+- incus-benchmark - narzędzie do testów wydajności Incusa
+- incus-migrate - migracja fizycznej maszyny do instancji
+- incus-simplestreams - zarządzanie serwerem obrazów simplestreams
+- lxc-to-incus - migracja kontenerów LXC do Incusa
+- lxd-to-incus - migracja istniejącej instalacji LXD do Incusa
+
+%package -n bash-completion-%{name}
+Summary: Bash completion for incus command
+Summary(pl.UTF-8): Bashowe uzupełnianie nazw dla polecenia incus
+Group: Applications/Shells
+Requires: %{name}-client = %{version}-%{release}
+Requires: bash-completion >= 1:2.0
+BuildArch: noarch
+
+%description -n bash-completion-%{name}
+Bash completion for incus command.
+
+%description -n bash-completion-%{name} -l pl.UTF-8
+Bashowe uzupełnianie nazw dla polecenia incus.
+
+%package -n fish-completion-%{name}
+Summary: fish completion for incus command
+Summary(pl.UTF-8): Uzupełnianie nazw w fish dla polecenia incus
+Group: Applications/Shells
+Requires: %{name}-client = %{version}-%{release}
+Requires: fish
+BuildArch: noarch
+
+%description -n fish-completion-%{name}
+fish completion for incus command.
+
+%description -n fish-completion-%{name} -l pl.UTF-8
+Uzupełnianie nazw w fish dla polecenia incus.
+
+%package -n zsh-completion-%{name}
+Summary: zsh completion for incus command
+Summary(pl.UTF-8): Uzupełnianie nazw w zsh dla polecenia incus
+Group: Applications/Shells
+Requires: %{name}-client = %{version}-%{release}
+Requires: zsh
+BuildArch: noarch
+
+%description -n zsh-completion-%{name}
+zsh completion for incus command.
+
+%description -n zsh-completion-%{name} -l pl.UTF-8
+Uzupełnianie nazw w zsh dla polecenia incus.
+
+%prep
+%setup -q
+%patch -P0 -p1
+
+# C sources of cowsql and raft for "make deps"; the build links system libraries
+%{__rm} -r vendor/cowsql vendor/raft
+
+%build
+export CGO_CFLAGS="%{rpmcflags}"
+export CGO_LDFLAGS="%{rpmldflags}"
+# upstream Makefile: flags used by liblxc/cowsql cgo bindings
+export CGO_LDFLAGS_ALLOW='(-Wl,-wrap,pthread_create)|(-Wl,-z,now)'
+
+for cmd in incusd incus-user incus fuidshift incus-benchmark incus-simplestreams lxc-to-incus lxd-to-incus; do
+ %__go build -v -mod=vendor -tags libsqlite3 -o bin/$cmd ./cmd/$cmd
+done
+# incus-migrate and incus-agent run on foreign systems (VM guests): fully static
+CGO_ENABLED=0 %__go build -v -mod=vendor -tags netgo -o bin/incus-migrate ./cmd/incus-migrate
+CGO_ENABLED=0 %__go build -v -mod=vendor -tags agent,netgo -o bin/incus-agent ./cmd/incus-agent
+
+%{__make} build-mo
+
+# the client insists on a writable config dir even for manpage/completion
+export INCUS_CONF=$(pwd)/.incus-conf
+install -d man completions
+bin/incus manpage man
+bin/incusd manpage man
+bin/incus completion bash > completions/incus.bash
+bin/incus completion fish > completions/incus.fish
+bin/incus completion zsh > completions/incus.zsh
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{_bindir},%{incusdir},%{_mandir}/man1} \
+ $RPM_BUILD_ROOT{%{systemdunitdir},%{systemdtmpfilesdir},%{_sysusersdir},%{_sysctldir}} \
+ $RPM_BUILD_ROOT/etc/{rc.d/init.d,sysconfig,dnsmasq.d} \
+ $RPM_BUILD_ROOT{%{bash_compdir},%{fish_compdir},%{zsh_compdir}} \
+ $RPM_BUILD_ROOT/var/{lib,log,cache}/%{name}
+
+install -p bin/{incusd,incus-user} $RPM_BUILD_ROOT%{incusdir}
+install -p %{SOURCE10} $RPM_BUILD_ROOT%{incusdir}/incus-shutdown
+install -p %{SOURCE13} $RPM_BUILD_ROOT%{incusdir}/incus-wrapper
+install -p bin/{incus,incus-agent,incus-benchmark,incus-migrate,incus-simplestreams,fuidshift,lxc-to-incus,lxd-to-incus} $RPM_BUILD_ROOT%{_bindir}
+
+cp -p man/*.1 $RPM_BUILD_ROOT%{_mandir}/man1
+
+cp -p %{SOURCE1} %{SOURCE2} %{SOURCE3} %{SOURCE4} %{SOURCE5} $RPM_BUILD_ROOT%{systemdunitdir}
+cp -p %{SOURCE6} $RPM_BUILD_ROOT%{_sysusersdir}/%{name}.conf
+cp -p %{SOURCE7} $RPM_BUILD_ROOT%{systemdtmpfilesdir}/%{name}.conf
+cp -p %{SOURCE8} $RPM_BUILD_ROOT/etc/dnsmasq.d/%{name}.conf
+cp -p %{SOURCE9} $RPM_BUILD_ROOT%{_sysctldir}/10-%{name}-inotify.conf
+install -p %{SOURCE11} $RPM_BUILD_ROOT/etc/rc.d/init.d/%{name}
+cp -p %{SOURCE12} $RPM_BUILD_ROOT/etc/sysconfig/%{name}
+
+cp -p completions/incus.bash $RPM_BUILD_ROOT%{bash_compdir}/incus
+cp -p completions/incus.fish $RPM_BUILD_ROOT%{fish_compdir}/incus.fish
+cp -p completions/incus.zsh $RPM_BUILD_ROOT%{zsh_compdir}/_incus
+
+for mo in po/*.mo; do
+ # header-only catalogs (no translated strings) are skipped by find_lang too
+ if file $mo | grep -q ', 1 message'; then
+ continue
+ fi
+ lang=$(basename $mo .mo)
+ install -D -p $mo $RPM_BUILD_ROOT%{_datadir}/locale/$lang/LC_MESSAGES/%{name}.mo
+done
+
+%find_lang %{name}
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%pre
+%groupadd -g 364 %{name}-admin
+%groupadd -g 365 %{name}
+
+%post
+# unprivileged containers need a subordinate id range for root; PLD's
+# /etc/subuid and /etc/subgid ship without one
+if ! grep -qs '^root:' /etc/subuid; then
+ /usr/sbin/usermod --add-subuids 1000000-1000999999 root
+fi
+if ! grep -qs '^root:' /etc/subgid; then
+ /usr/sbin/usermod --add-subgids 1000000-1000999999 root
+fi
+/sbin/chkconfig --add %{name}
+# no service restart here: stopping incusd via the init script shuts down every instance
+%systemd_post %{name}.socket %{name}.service %{name}-startup.service %{name}-user.socket %{name}-user.service
+
+%preun
+if [ "$1" = "0" ]; then
+ %service -q %{name} stop
+ /sbin/chkconfig --del %{name}
+fi
+%systemd_preun %{name}.socket %{name}.service %{name}-startup.service %{name}-user.socket %{name}-user.service
+
+%postun
+%systemd_reload
+if [ "$1" = "0" ]; then
+ %groupremove %{name}
+ %groupremove %{name}-admin
+fi
+
+%files
+%defattr(644,root,root,755)
+%doc AUTHORS README.md SECURITY.md
+%attr(754,root,root) /etc/rc.d/init.d/%{name}
+%config(noreplace) %verify(not md5 mtime size) /etc/sysconfig/%{name}
+%config(noreplace) %verify(not md5 mtime size) /etc/dnsmasq.d/%{name}.conf
+%{systemdunitdir}/%{name}.socket
+%{systemdunitdir}/%{name}.service
+%{systemdunitdir}/%{name}-startup.service
+%{systemdunitdir}/%{name}-user.socket
+%{systemdunitdir}/%{name}-user.service
+%{systemdtmpfilesdir}/%{name}.conf
+%{_sysusersdir}/%{name}.conf
+%{_sysctldir}/10-%{name}-inotify.conf
+%dir %{incusdir}
+%attr(755,root,root) %{incusdir}/incusd
+%attr(755,root,root) %{incusdir}/incus-user
+%attr(755,root,root) %{incusdir}/incus-shutdown
+%attr(755,root,root) %{incusdir}/incus-wrapper
+%{_mandir}/man1/incusd.1*
+%{_mandir}/man1/incusd.*.1*
+%dir %attr(711,root,root) /var/lib/%{name}
+%dir %attr(700,root,root) /var/log/%{name}
+%dir %attr(700,root,root) /var/cache/%{name}
+
+%files client -f %{name}.lang
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/incus
+%{_mandir}/man1/incus.1*
+%{_mandir}/man1/incus.*.1*
+
+%files agent
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/incus-agent
+
+%files tools
+%defattr(644,root,root,755)
+%attr(755,root,root) %{_bindir}/fuidshift
+%attr(755,root,root) %{_bindir}/incus-benchmark
+%attr(755,root,root) %{_bindir}/incus-migrate
+%attr(755,root,root) %{_bindir}/incus-simplestreams
+%attr(755,root,root) %{_bindir}/lxc-to-incus
+%attr(755,root,root) %{_bindir}/lxd-to-incus
+
+%files -n bash-completion-%{name}
+%defattr(644,root,root,755)
+%{bash_compdir}/incus
+
+%files -n fish-completion-%{name}
+%defattr(644,root,root,755)
+%{fish_compdir}/incus.fish
+
+%files -n zsh-completion-%{name}
+%defattr(644,root,root,755)
+%{zsh_compdir}/_incus
diff --git a/incus-dnsmasq.conf b/incus-dnsmasq.conf
new file mode 100644
index 0000000..f8a8d3c
--- /dev/null
+++ b/incus-dnsmasq.conf
@@ -0,0 +1,4 @@
+# Make a system-wide dnsmasq bind to explicit interfaces and leave the
+# Incus bridge alone; incusd runs its own dnsmasq on incusbr0.
+bind-interfaces
+except-interface=incusbr0
diff --git a/incus-rsync-apparmor.patch b/incus-rsync-apparmor.patch
new file mode 100644
index 0000000..d6b6c82
--- /dev/null
+++ b/incus-rsync-apparmor.patch
@@ -0,0 +1,41 @@
+# rsync 3.5.0 opens every ancestor of the destination; the generated AppArmor
+# profile denied that, so snapshots and VM agent setup failed (lxc/incus#3968)
+# https://github.com/lxc/incus/commit/040909b969
+diff --git a/internal/server/apparmor/rsync.go b/internal/server/apparmor/rsync.go
+index 6a0b059d2fe..5a1da30d695 100644
+--- a/internal/server/apparmor/rsync.go
++++ b/internal/server/apparmor/rsync.go
+@@ -44,6 +44,9 @@ profile "{{ .name }}" flags=(attach_disconnected,mediate_deleted) {
+ {{- end }}
+
+ {{- if .dstPath }}
++{{- range .dstParents }}
++ {{ . }} r,
++{{- end }}
+ {{ .dstPath }}/** rwkl,
+ {{ .dstPath }}/ rwkl,
+ {{- end }}
+@@ -165,12 +168,23 @@ func rsyncProfile(sysOS *sys.OS, name string, sourcePath string, dstPath string)
+ execPath = fullPath
+ }
+
++ // rsync 3.5+ resolves the destination component by component from /.
++ dstParents := []string{}
++ if dstPath != "" {
++ for dir := filepath.Dir(filepath.Clean(dstPath)); dir != "/"; dir = filepath.Dir(dir) {
++ dstParents = append(dstParents, dir+"/")
++ }
++
++ dstParents = append(dstParents, "/")
++ }
++
+ sb := &strings.Builder{}
+ err = rsyncProfileTpl.Execute(sb, map[string]any{
+ "name": name,
+ "execPath": execPath,
+ "sourcePath": sourcePath,
+ "dstPath": dstPath,
++ "dstParents": dstParents,
+ "logPath": logPath,
+ "libraryPath": strings.Split(os.Getenv("LD_LIBRARY_PATH"), ":"),
+ })
diff --git a/incus-shutdown.sh b/incus-shutdown.sh
new file mode 100644
index 0000000..bbfde76
--- /dev/null
+++ b/incus-shutdown.sh
@@ -0,0 +1,9 @@
+#!/bin/sh
+# Stop all instances cleanly when incus-startup.service stops, but only
+# if the daemon is actually running (activateifneeded may have left it off).
+
+if ! systemctl -q is-active incus.service; then
+ exit 0
+fi
+
+exec /usr/libexec/incus/incusd shutdown
diff --git a/incus-startup.service b/incus-startup.service
new file mode 100644
index 0000000..64d7057
--- /dev/null
+++ b/incus-startup.service
@@ -0,0 +1,16 @@
+[Unit]
+Description=Incus - Instance startup
+Documentation=man:incusd(1)
+After=incus.socket incus.service
+Requires=incus.socket
+
+[Service]
+Type=oneshot
+ExecStart=/usr/libexec/incus/incusd activateifneeded
+ExecStop=/usr/libexec/incus/incus-shutdown
+TimeoutStartSec=600s
+TimeoutStopSec=600s
+RemainAfterExit=yes
+
+[Install]
+WantedBy=multi-user.target
diff --git a/incus-sysctl.conf b/incus-sysctl.conf
new file mode 100644
index 0000000..7505bda
--- /dev/null
+++ b/incus-sysctl.conf
@@ -0,0 +1,3 @@
+# Each running container costs inotify instances on the host; the kernel
+# default of 128 is exhausted after a few dozen instances.
+fs.inotify.max_user_instances = 1024
diff --git a/incus-user.service b/incus-user.service
new file mode 100644
index 0000000..d0242b1
--- /dev/null
+++ b/incus-user.service
@@ -0,0 +1,11 @@
+[Unit]
+Description=Incus - User daemon
+After=incus-user.socket incus.service
+Requires=incus-user.socket
+
+[Service]
+ExecStart=/usr/libexec/incus/incus-user --group incus
+Restart=on-failure
+
+[Install]
+Also=incus-user.socket
diff --git a/incus-user.socket b/incus-user.socket
new file mode 100644
index 0000000..5c14276
--- /dev/null
+++ b/incus-user.socket
@@ -0,0 +1,11 @@
+[Unit]
+Description=Incus - Daemon (user unix socket)
+
+[Socket]
+ListenStream=/var/lib/incus/unix.socket.user
+SocketGroup=incus
+SocketMode=0660
+Service=incus-user.service
+
+[Install]
+WantedBy=sockets.target
diff --git a/incus-wrapper.sh b/incus-wrapper.sh
new file mode 100644
index 0000000..29f1637
--- /dev/null
+++ b/incus-wrapper.sh
@@ -0,0 +1,4 @@
+#!/bin/sh
+# incusd keeps writing to stderr after startup; under rc-scripts that pipe
+# is gone once initlog exits and the Go runtime dies on the resulting SIGPIPE
+exec /usr/libexec/incus/incusd --logfile /var/log/incus/incusd.log "$@" >/dev/null 2>&1
diff --git a/incus.init b/incus.init
new file mode 100644
index 0000000..404ebc1
--- /dev/null
+++ b/incus.init
@@ -0,0 +1,125 @@
+#!/bin/sh
+#
+# incus System container and virtual machine manager
+#
+# chkconfig: 345 20 80
+#
+# description: Incus is a system container and virtual machine manager \
+# built on LXC and QEMU, with a REST API and the incus CLI.
+# processname: incusd
+# pidfile: /var/run/incusd.pid
+#
+
+# Source function library
+. /etc/rc.d/init.d/functions
+
+# Get network config
+. /etc/sysconfig/network
+
+# Check that networking is up.
+if is_yes "${NETWORKING}"; then
+ if [ ! -f /var/lock/subsys/network -a "$1" != stop -a "$1" != status ]; then
+ msg_network_down "Incus"
+ exit 1
+ fi
+else
+ exit 0
+fi
+
+# Get service config - may override defaults
+[ -f /etc/sysconfig/incus ] && . /etc/sysconfig/incus
+
+pidfile="/var/run/incusd.pid"
+incusd="/usr/libexec/incus/incusd"
+wrapper="/usr/libexec/incus/incus-wrapper"
+
+start() {
+ if [ -f /var/lock/subsys/incus ]; then
+ msg_already_running "Incus"
+ return
+ fi
+
+ # lxcfs makes /proc inside containers reflect their cgroup limits
+ if [ -x /etc/rc.d/init.d/lxcfs ] && [ ! -f /var/lock/subsys/lxcfs ]; then
+ /etc/rc.d/init.d/lxcfs start
+ fi
+
+ msg_starting "Incus"
+ daemon --makepid --pidfile $pidfile --waitforname incusd \
+ $wrapper --group incus-admin $OPTIONS
+ RETVAL=$?
+ if [ $RETVAL -eq 0 ]; then
+ show "Waiting for Incus to become ready"
+ busy
+ if $incusd waitready --timeout=600; then
+ ok
+ touch /var/lock/subsys/incus
+ else
+ fail
+ RETVAL=1
+ fi
+ fi
+}
+
+stop() {
+ if [ ! -f /var/lock/subsys/incus ]; then
+ msg_not_running "Incus"
+ return
+ fi
+
+ # Stop daemons.
+ msg_stopping "Incus"
+ # stops all instances, then the daemon; the API call returns before the process is gone
+ $incusd shutdown --timeout=600
+ for i in $(seq 1 30); do
+ status --pidfile $pidfile incusd incus >/dev/null 2>&1 || break
+ sleep 1
+ done
+ if status --pidfile $pidfile incusd incus >/dev/null 2>&1; then
+ killproc --pidfile $pidfile incusd
+ else
+ ok
+ fi
+ rm -f /var/lock/subsys/incus $pidfile
+}
+
+condrestart() {
+ if [ ! -f /var/lock/subsys/incus ]; then
+ msg_not_running "Incus"
+ RETVAL=$1
+ return
+ fi
+
+ stop
+ start
+}
+
+RETVAL=0
+# See how we were called.
+case "$1" in
+ start)
+ start
+ ;;
+ stop)
+ stop
+ ;;
+ restart)
+ stop
+ start
+ ;;
+ try-restart)
+ condrestart 0
+ ;;
+ force-reload)
+ condrestart 7
+ ;;
+ status)
+ status --pidfile $pidfile incusd incus
+ RETVAL=$?
+ ;;
+ *)
+ msg_usage "$0 {start|stop|restart|try-restart|force-reload|status}"
+ exit 3
+esac
+
+exit $RETVAL
diff --git a/incus.service b/incus.service
new file mode 100644
index 0000000..c203ec4
--- /dev/null
+++ b/incus.service
@@ -0,0 +1,21 @@
+[Unit]
+Description=Incus - Daemon
+Documentation=man:incusd(1)
+After=network-online.target openvswitch-switch.service lxcfs.service incus.socket
+Requires=network-online.target lxcfs.service incus.socket
+
+[Service]
+EnvironmentFile=-/etc/sysconfig/incus
+ExecStart=/usr/libexec/incus/incusd --group incus-admin $OPTIONS
+ExecStartPost=/usr/libexec/incus/incusd waitready --timeout=600
+KillMode=process
+TimeoutStartSec=600s
+TimeoutStopSec=30s
+Restart=on-failure
+Delegate=yes
+LimitNOFILE=1048576
+LimitNPROC=infinity
+TasksMax=infinity
+
+[Install]
+Also=incus-startup.service incus.socket
diff --git a/incus.socket b/incus.socket
new file mode 100644
index 0000000..0b2aa8d
--- /dev/null
+++ b/incus.socket
@@ -0,0 +1,13 @@
+[Unit]
+Description=Incus - Daemon (unix socket)
+Documentation=man:incusd(1)
+
+[Socket]
+FileDescriptorName=unix
+ListenStream=/var/lib/incus/unix.socket
+SocketGroup=incus-admin
+SocketMode=0660
+Service=incus.service
+
+[Install]
+WantedBy=sockets.target
diff --git a/incus.sysconfig b/incus.sysconfig
new file mode 100644
index 0000000..28037c6
--- /dev/null
+++ b/incus.sysconfig
@@ -0,0 +1,10 @@
+# Customized settings for incusd
+
+# Define nice level for incusd (init script only)
+SERVICE_RUN_NICE_LEVEL="+0"
+
+# Max open files and max processes (init script only, systemd unit sets its own)
+SERVICE_LIMITS="-n 1048576 -u 1048576"
+
+# Extra options for incusd (see incusd --help)
+#OPTIONS=""
diff --git a/incus.sysusers b/incus.sysusers
new file mode 100644
index 0000000..efdbe66
--- /dev/null
+++ b/incus.sysusers
@@ -0,0 +1,2 @@
+g incus-admin 364 - -
+g incus 365 - -
diff --git a/incus.tmpfiles b/incus.tmpfiles
new file mode 100644
index 0000000..2e66a6d
--- /dev/null
+++ b/incus.tmpfiles
@@ -0,0 +1,4 @@
+d /var/cache/incus 0700 root root - -
+d /var/log/incus 0700 root root - -
+d /var/lib/incus 0711 root root - -
+d /run/incus 0711 root root - -
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/incus.git/commitdiff/9d9091747758222da283994e02ce3b3f78c31079
More information about the pld-cvs-commit
mailing list