The system manager systemd 259 is now available.

After three months of development, the release of the system manager systemd 259 is now available. Key changes include support for the Musl standard library, the 'run0 --empower' command for performing privileged actions without changing UID, dynamic loading of third-party libraries requested in libsystemd, and the ability to ignore configuration files by adding '.ignore' to the filename.

Among the changes in the new release:

  • Partial support for the Musl standard C library has been added, enabled by setting the 'musl' value in the 'libc' options in the Meson build system. Since the Musl library does not provide NSS functionality, components such as nss-systemd, nss-resolve, systemd-homed, systemd-nsresourced, and systemd-userdbd are unavailable when building systemd with Musl, as well as the DynamicUser parameter and the ability to run systemd-nspawn unprivileged. The systemd developers do not currently guarantee that Musl support will remain in future releases, as the decision will depend on the outcome of developing a layer that implements additional functionality on top of Musl, as well as the project's demand and reports of Musl-specific bugs.
  • The run0 utility, presented as a secure replacement for the sudo program that operates over systemd-run, has added the '--empower' option, which allows starting a new session with elevated privileges without switching to the root user. Performing privileged actions without changing UID is organized through setting capabilities flags such as CAP_SYS_ADMIN, which are sufficient for accessing most privileged system calls. The processes launched are also placed in a separate 'empower' group, which has access to most Polkit actions.
  • It has been decided to remove support for service scripts in System V format in the next release. The components targeted for removal include systemd-sysv-install, systemd-rc-local-generator, and systemd-sysv-generator. The next release will also increase the minimum version requirements: Linux kernel 5.10, glibc 2.34, openssl 3.0.0, python 3.9.0, libxcrypt 4.4.0, util-linux 2.37, elfutils 0.177, and cryptsetup 2.4.0.
  • As part of the initiative to reduce dependencies, libsystemd has implemented dynamic loading of the libraries libacl, libblkid, libseccomp, libselinux, and libmount using the dlopen() call in situations where their functions are truly needed. The interaction with the Linux audit subsystem and PAM is also implemented through dlopen(). Functionality previously called through the libcap library has been integrated into libsystemd.
  • systemd-resolved now allows local handlers to be attached, which are called for each local name resolution request. Handlers are placed in the directory /run/systemd/resolve.hook/.
  • A UUID field has been added to the user database, and the userdbctl utility has been updated with the ‘—uuid’ option for searching by UUID.
  • Files with names ending in ‘.ignore’ are now ignored in the configuration files.
  • systemd-importd has integrated built-in logic for working with TAR archives, utilizing libarchive instead of calling the GNU tar utility. It is now possible to run systemd-machined and systemd-importd in user-specific mode, not system-wide, loading system images into ~/.local/state/machines/. The importctl utility has been enhanced with the ‘—user’ and ‘—system’ options to choose the mode of operation.
  • The default journal storage mode has been changed from ‘auto’ to ‘persistent’ (previously, the mode depended on the presence of the /var/log/journal directory).
  • In systemd-networkd and systemd-nspawn, support for creating NAT (Network Address Translation) rules via iptables/libiptc has been discontinued. Only nftables support remains.
  • In systemd-boot and systemd-stub, support for TPM 1.2 has been discontinued (support for TPM 2.0 remains).
  • systemd-machined now defaults to mounting ‘hidden’ disk images, whose names start with a dot, in read-only mode.
  • The API based on the Varlink protocol has been expanded, which can now be used to access service settings. IPC calls Reload() and Reexecute() have been implemented. Calls have been added to access the functionality and settings of systemd-repart, systemd-resolved, and systemd-networkd.
  • The ExecReloadPost setting has been added, allowing for executing commands after the service configuration is reloaded.
  • For services, properties OOMKills and ManagedOOMKills have been implemented, containing the number of processes forcibly terminated by the kernel or systemd-oomd due to memory exhaustion.
  • For transient services, the property RootDirectoryFileDescriptor has been added, defining the file descriptor for the root directory.
  • The UserNamespacePath setting has been added, allowing the binding of a unit to the user namespace by specifying a path in the pseudo-FS /proc, similarly to the IPCNamespacePath and NetworkNamespacePath settings. In systemd-nspawn, the NamespacePath setting has been added to the [Network] section of .nspawn files for specifying the network namespace.
  • In systemd-sysext and systemd-confext, support for separate configuration files /etc/systemd/systemd-sysext.conf and /etc/systemd/systemd-confext.conf has been implemented. The ability to use the environment variable SYSTEMD_SYSEXT_OVERLAYFS_MOUNT_OPTIONS and $SYSTEMD_CONFEXT_OVERLAYFS_MOUNT_OPTIONS for configuring Overlayfs mount options has been added.
  • In systemd-udevd, the OPTIONS="dump-json" setting has been added for outputting the current event state in JSON format. The net_id function implements the generation of predictable names for wireless network interfaces on systems with DeviceTree. Symbolic links /dev/gpio/by-id/… have been generated for GPIO devices.
  • The command "homectl update" has been enhanced with the option "—recovery-key" to add backup keys to an existing user account (previously, such keys could only be added during user creation).
  • In systemd-homed, the options "—prompt-shell" and "—prompt-groups" have been added for interactive selection of the shell and group during the first boot using the systemd-homed-firstboot.service. An option "—prompt-keymap-auto" has been added in systemd-firstboot to request the keyboard layout when working through the local console during the initial boot.
  • In systemd-boot, the ability to set the log detail level through the log-level parameter in loader.conf or SMBIOS field io.systemd.boot.loglevel has been added.
  • In systemd-networkd, the EmitDomain and Domain options have been added for the DHCP server, and a handler for determining host names provided via DHCP through DNS resolution has been implemented.
  • In systemd-run, the option "—root-directory" has been added for running a service in a specified root directory. The options "—same-root-dir" ("-R") have been added in systemd-run and run0 for running a service in the same root directory as the initiator.
  • In systemd-modules-load, parallel loading of kernel modules has been implemented.
  • In systemd-integrity-setup, support for HMAC-SHA256, PHMAC-SHA256, and PHMAC-SHA512 algorithms has been added.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster