title: Service Restart Needed: Services Still Using Replaced Libraries
agents: linux
catalog: os/misc
license: GPLv2
distribution: check_mk
description:
 Lists system services that still run code from shared libraries which an update
 has replaced on disk -- the update is not effective for them until they are
 restarted. Example: after an openssl update, nginx keeps using the old libssl
 until it is restarted.

 The agent plug-in scans {/proc/*/maps} of all processes for replaced
 ({(deleted)}) shared objects and maps each process to its systemd unit via
 {/proc/<pid>/cgroup}. Without systemd (e.g. many containers), the process name
 is shown instead. PID 1 is left out (see the {Reboot Required} service), as are
 user sessions. Works the same on every Linux distribution, no extra package
 needed; programs in interpreted languages whose modules were updated are not
 detected.

 The summary shows the number and names of affected services, the details list
 each service with its replaced libraries. The state when services need a restart
 is configurable ({OK}, {WARN} (default), {CRIT}); services matching configured
 regular expressions are listed separately as ignored and don't affect the state.

item:
 None, this is a single service per host.

discovery:
 One service is created per Linux host whose agent plug-in reports the
 {system_updates_services} section (agent plug-in v0.4.17 or newer).
