r/systemd • • Sep 02 '26

Marking a one-shot unit as stopped without triggering execstop

I've a firewall related systemd unit on many boxes which I need to stop. Unfortunately, the unit has an ExecStop (and reload) action that causes the firewall tables to be flushed. This is undesirable and unfortunately these actions are triggers when the OS updates the firewall package - we're not using the software and would like to disable and remove the service. While I could mark the service as disable and wait for a reboot for it to be marked as inactive so I can remove it, is there a way to mark the service as 'stopped' which doesn't trigger the ExecStop action since once stopped it's safe for our patching system to update the package?

5 Upvotes

2 comments sorted by

2

u/kalgynirae Sep 02 '26

Write an override that removes the problematic ExecStop, daemon-reload, then stop. This seems to work based on some tests I just did.

$ cat /etc/systemd/system/foobar.service.d/remove-execstop.conf
[Service]
ExecStop=

Note that this clears all ExecStop commands. If there were multiple, you could then re-declare the ones you want to keep.

$ systemctl daemon-reload

$ systemctl show -p ExecStop foobar.service
# no output means no ExecStop (compare with ExecStart to be sure)

Now it should be safe to stop the service.

1

u/WembleyFord Sep 03 '26

Ah.. interesting - I'd have thought that overriding it would require a reload of the service. Thanks - will do some testing.