Release of the system manager systemd 255

After four months of development, the release of the system manager systemd 255 has been presented. Among the most important improvements are: support for exporting drives via NVMe-TCP, the systemd-bsod component for full-screen error messages, the systemd-vmspawn utility for launching virtual machines, the varlinkctl utility for managing Varlink services, the systemd-pcrlock utility for analyzing TPM2 PCR registers and generating access rules, and the pam_systemd_loadkey.so authentication module.

Key changes in the new release:

  • The 'systemd-storagetm' component has been added, allowing for the automatic export of all local block devices using the NVMe-TCP driver (NVMe over TCP), enabling access to NVMe drives over the network (NVM Express over Fabrics) using the TCP protocol. Access in NVMe over TCP mode is managed by the new unit 'storage-target-mode.target', which can be enabled during boot by specifying 'rd.systemd.unit=storage-target-mode.target' in the kernel command line, for example, when remote access to the drive is needed for diagnostic purposes.
  • The 'systemd-bsod' component has been added, implementing an equivalent of the 'blue screen of death' that allows for displaying critical error messages (LOG_EMERG) during boot as a full-screen notification.
  • The 'systemd-vmspawn' utility has been added, which serves as an equivalent to the systemd-nspawn utility for launching an operating system image in a virtual machine (the systemd-nspawn utility is designed for container execution, while systemd-vmspawn provides a similar interface for of virtual machines). Currently, only the QEMU-based backend is available for launching virtual machines.
  • The 'varlinkctl' utility has been added for invoking and introspecting services that use the Varlink protocol.
  • A utility called "systemd-pcrlock" has been added for analyzing and predicting the states of TPM2 PCR (Platform Configuration Register) registers and forming access rules stored in the TPM2 NV index. These rules allow access to TPM2 objects, such as disk encryption keys, only from verified digitally signed components that are initialized during the verified boot stage. The input data for analysis can be the result of a PCR state request from TPM2, generated by UEFI firmware event logs of the current boot (\/sys\/kernel\/security\/tpm0\/binary_bios_measurements) or a locally saved TPM2 log (\/run\/log\/systemd\/tpm2-measure.log). Support for stored access rules has been added to systemd-cryptsetup, systemd-cryptenroll, and systemd-repart.
  • The PAM module pam_systemd_loadkey.so has been added, designed for automatically extracting the passphrase from the keyring in the kernel, which is used in cryptsetup to unlock the encrypted root filesystem, and providing this passphrase as an authentication token (PAM authtok). The module can be used, for example, to configure auto-unlock access to GNOME Keyring and KDE Wallet when automatic login is enabled.
  • Support for transitioning to hibernation while saving the memory contents in swap files stored in Btrfs filesystem has been added.
  • Units have been enhanced with properties MemoryPeak, MemorySwapPeak, MemorySwapCurrent, and MemoryZSwapCurrent, corresponding to the cgroup v2 properties memory.peak, memory.swap.peak, memory.swap.current, and memory.zswap.current. Data regarding these properties is included in the output of "systemctl status".
  • The method of starting services has been revised and is now using the posix_spawn call with CLONE_VM and CLONE_VFORK options for process initialization, applying a separate executable file systemd-executor for configuring the launched process. Previously, processes were forked using the fork function, which copied the memory of the controlling process in copy-on-write mode and performed the necessary setups (mounting namespaces and setting up CGroup) before executing the target executable file via the exec call. This approach caused issues due to the inability to access some Glibc APIs during the stage between executing the fork and exec functions.
  • The code for tracking internal processes has been updated to use PIDFD instead of PID in environments with a kernel that supports PIDFD (PIDFD is tied to a specific process and does not change, whereas PID may be assigned to another process after the current process associated with that PID is terminated). The ability to create scope units using PIDFD instead of PID for process selection has been implemented.
  • Support for separate directory hierarchies (when /usr is mounted separately from the root or the /bin and /usr/bin, /lib and /usr/lib directories are separated) has been discontinued. In the future, support for cgroups v1, System V service scripts, and Systemd EFI variables will also be dropped.
  • The ‘systemctl switch-root’ command is restricted for use only in initrd. To replace the root filesystem in a regular environment, use ‘systemctl soft-reboot’.
  • The parameters SuspendMode, HybridSleepMode, HibernateStat, and HybridSleepState in the ‘[Sleep]’ section of the systemd-sleep.conf file have been deprecated. These parameters are now ignored and can only take default values.
  • A SurviveFinalKillSignal option has been added to units, allowing the final SIGTERM/SIGKILL signal sent during shutdown to be ignored, which can be useful for keeping the unit running during a soft reboot of the system.
  • A NFTSet configuration has been added, allowing cgroup identifiers to be used to switch logic in firewall rules.
  • The ConditionSecurity=measured-uki option has been added, ensuring that the unit can only be started in a system booted with a verified kernel image in UKI format.
  • New hotkeys ‘B’ and ‘O’ have been added to systemd-boot for rebooting and shutting down the system from the boot menu. A ‘menu-disabled’ option has been added to disable the display of the boot menu.
  • New options ‘—copy-from’ have been added to the systemd-repart utility for obtaining partition descriptions from the specified filesystem image, ‘—copy-source’ for specifying the base directory for the CopyFiles parameter, ‘—make-ddi=confext’, ‘—make-ddi=sysext’, and ‘—make-ddi=portable’ for generating various types of DDI, and ‘—tpm2-device-key’ for binding the disk to a specific public TPM2 key.
  • In the journalctl utility, the ‘—lines’ parameter has been enhanced with a ‘+N’ value to output the N oldest entries.
  • A ‘—json’ flag has been added to udevadm for output in JSON format.
  • The utilities systemd-analyze, systemd-tmpfiles, systemd-sysusers, systemd-sysctl, and systemd-binfmt have added the option "--tldr" to display only the actual configuration parameters without whitespace and comments.
  • The seccomp subsystem has added support for the LoongArch64 architecture. The use of seccomp for filtering system calls is allowed in services that do not run as the root user without enabling the NoNewPrivileges=yes setting.
  • The utility systemd-mount has added the option "--tmpfs" for mounting a new instance of 'tmpfs'.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster