Release of the system manager systemd 253

After three and a half months of development, the release of the system manager systemd 253 has been presented.

Among the changes in the new release:

  • The package includes the utility ‘ukify’, intended for building, checking, and creating signatures for unified kernel images (UKI), which combine a handler for booting the kernel from UEFI (UEFI boot stub), the Linux kernel image, and the initial ramdisk (initrd) used for early initialization before mounting the root file system. This utility replaces the functionality previously provided by the command ‘dracut --uefi’ and adds capabilities for automatically calculating offsets in PE files, merging initrd, signing embedded kernel images, creating combined images with sbsign, heuristics for determining the kernel uname, checking the splash image, and adding signed PCR policies generated by the utility systemd-measure.
  • Support has been added for initrd environments that are not limited by memory allocation, where overlayfs is used instead of tmpfs. For such environments, systemd does not remove all files in initrd after switching the root file system.
  • A parameter ‘OpenFile’ has been added to services for opening arbitrary files in the file system (or connecting to Unix sockets) and passing the associated file descriptors to the executed process (for example, when access to a file is needed for a non-privileged service without changing the file's access rights).
  • In systemd-cryptenroll, a new feature has been implemented to unlock encrypted partitions using FIDO2 tokens (—unlock-fido2-device) without the need to enter a password. It ensures the storage of a salted user-defined PIN code to complicate brute-force attempts.
  • Settings ReloadLimitIntervalSec and ReloadLimitBurst have been added, along with kernel command line options (systemd.reload_limit_interval_sec and /systemd.reload_limit_burst) to limit the intensity of restarting background processes.
  • For units, an option ‘MemoryZSwapMax’ has been implemented to configure the property memory.zswap.max, which determines the maximum size of zswap.
  • For units, an option ‘LogFilterPatterns’ has been implemented, allowing the specification of regular expressions for filtering information output to the log (this can be used to exclude certain outputs or retain only specific data).
  • The scope units now support configuring the 'OOMPolicy' to define the behavior during eviction attempts due to memory shortages (for login sessions, OOMPolicy is set to continue so that the OOM killer does not forcibly terminate them).
  • A new type of service has been defined — 'Type=notify-reload', which extends the 'Type=notify' by allowing it to wait for the completion of the reload signal processing (SIGHUP). The systemd-networkd.service, systemd-udevd.service, and systemd-logind services have been converted to use this new type.
  • A new naming scheme for network devices has been implemented in udev, where ID_NET_NAME_PATH is now set for non-PCI USB devices to ensure more predictable naming. For SYMLINK variables, the operator '-=' has been implemented, which leaves symbolic links unset if a rule for their addition has been previously defined.
  • In systemd-boot, the seeding transfer for the kernel's pseudorandom number generators and for the disk backend has been redesigned. Support has been added for loading the kernel not only from the ESP (EFI System Partition), but also from firmware or directly for QEMU. SMBIOS parameter parsing has been implemented to determine if the boot is in a virtualization environment. A new 'if-safe' mode has been implemented, where the certificate for UEFI Secure Boot is loaded from the ESP only if deemed safe (booted in virtual machine).
  • The bootctl utility generates system tokens on all EFI systems, except for virtualization environments. New commands 'kernel-identify' and 'kernel-inspect' have been added to display the kernel image type and information about the command line options and kernel version, 'unlink' for removing the file associated with the first type of boot entries, and 'cleanup' for deleting all files from the 'entry-token' directory in the ESP and XBOOTLDR that are not associated with the first type of boot entries. The KERNEL_INSTALL_CONF_ROOT variable is handled.
  • In the 'systemctl list-dependencies' command, the options '--type' and '--state' are supported, and in the 'systemctl kexec' command, support for Xen hypervisor-based environments has been added.
  • In .network files under the [DHCPv4] section, support for SocketPriority and QuickAck options has been added, RouteMetric=high|medium|low.
  • The systemd-repart now includes the options "--include-partitions", "--exclude-partitions", and "--defer-partitions" for filtering partitions by UUID type, allowing, for example, the creation of images where one partition is based on the contents of another partition. An option "--sector-size" has also been added to specify the size of the sector used when creating a partition. Support for generating the erofs filesystem has been introduced. The Minimize setting has implemented handling of the value "best" to choose the minimally possible image size.
  • The systemd-journal-remote now allows the use of the settings MaxUse, KeepFree, MaxFileSize, and MaxFiles to limit disk space consumption.
  • Support for sending anticipatory requests to FIDO2 tokens to check their availability before authentication has been added to systemd-cryptsetup.
  • New parameters tpm2-measure-bank and tpm2-measure-pcr have been added to crypttab.
  • The systemd-gpt-auto-generator now mounts ESP and XBOOTLDR partitions with the "noexec,nosuid,nodev" modes, and accounts for kernel parameters rootfstype and rootflags passed via the command line.
  • In systemd-resolved, it is now possible to configure resolver parameters by specifying the nameserver, domain, network.dns, and network.search_domains options in the kernel command line.
  • The command "systemd-analyze plot" now supports output in JSON format when the "--json" flag is specified. New options "--table" and "--no-legend" have also been added to control the output.
  • In 2023, support for cgroups v1 and separate directory hierarchies (when /usr is mounted separately from root or the /bin and /usr/bin, /lib and /usr/lib directories are separated) is planned to be discontinued.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster