Release of the system manager systemd 262

After three months of development, the release of the system manager systemd 262 is now available. This new version includes the integration of a minimal set of unit files into the process, support for static linking builds, integration with dm-clone for block device cloning, the ability to maintain a database of installed files in systemd-sysupdate, and cryptographic verification of systemd-report logs.

Among the changes in the new release:

  • The executable file of the system manager includes a set of basic unit files (basic.target, sysinit.target, multi-user.target, reboot.target, shutdown.target, systemd-poweroff.service, etc.), which are used when it is impossible to load unit files from disk. This integration allows containers with an init process (PID1) based on systemd to run without having to install unit files.
  • Support has been added for building a single statically linked executable file, which can be used for initializing and launching services in containers with minimal overhead. For static linking builds, when starting meson, the following flags should be specified: "—default-library=static —prefer-static -Dbuild-static=true -Dsystemd-multicall-binary=true".
  • Support for the dm-clone kernel module has been integrated, allowing the creation of a writable clone based on a block device available in read-only mode. Settings from /etc/clonetab are processed by the systemd-clonesetup-generator and saved as units systemd-clonesetup@.service, linked to clonesetup.target. A utility systemd-clonesetup has been added for creating and deleting clones of block devices.
  • The capabilities of the systemd-sysupdate tool have been expanded to automatically detect, download, and install updates using an atomic mechanism for replacing partitions, files, or directories (two independent partitions/files/directories are used, with one containing the currently active resource and the other installing the next update, after which the partitions/files/directories swap places). A database has been implemented to maintain information about all installed files. A command "systemd-sysupdate cleanup" has been added to remove files that have become unnecessary after system updates or do not match the current configuration template. Commands "systemd-sysupdate enable-feature/disable-feature/enable-component/disable-component" have been added to manage the enabling of features and components. The concept of suggested components has been implemented; for example, the command "systemd-sysupdate enable-component --component-suggested" can enable drivers necessary for the operation of existing hardware. The command "systemd-sysupdate update" has been enhanced with the option "--component-all" to update all components at once.
  • A new option "--sign=" has been added to systemd-report, implementing the ability to sign reports generated by the "generate" and "upload" commands with a digital signature. Three backends have been proposed for signing reports: systemd-report-sign-plain (Ed25519), systemd-report-sign-tsm (configfs TSM), and systemd-report-sign-tpm2 (TPM2 PCR).
  • To smooth the load in case of mass restarts of services after failures, the parameter RestartRandomizedDelaySec has been proposed, which adds a random delay before automatically restarting the service, limited by specified boundaries.
  • The slice units have been enhanced with the parameter ActivatingConcurrencyMax to limit the maximum number of concurrently activated units in the hierarchy.
  • For services, the parameter LUOSession has been implemented, intended to create Live Update Orchestrator sessions used for updating the kernel in Live mode without stopping the operation and without losing the system's state, devices, and processes.
  • In socket units, parameters XAttrEntryPoint, XAttrListen, and XAttrAccept have been implemented, allowing the attachment of extended attributes (xattr) to UNIX sockets for marking them.
  • A new placeholder symbol "$" has been implemented for automatically assigning memorable host names (/etc/hostname), which is replaced by an element from a list of words selected via hashing tied to the system ID.
  • The run0 utility has added sudo-compatible options -k/—reset-timestamp, -K/—remove-timestamp, and -v/—validate for revoking or updating temporal authorization performed via polkit.
  • The systemd-escape utility has added the "—stdin" option to read strings from standard input.
  • The vconsole has introduced an environment variable FONT_SCALE to set the font scaling level, similar to the kernel parameter vconsole.font_scale (only 100% and 200% values are currently supported).
  • All commands supporting the "—help" option have added the "—introspect-cli" option to output hints in JSON format to simplify the automation of checking for the required options from overlays and scripts.
  • When authenticating using FIDO2 tokens, the counter for remaining PIN entry attempts is displayed.
  • In systemd-networkd, the "[Match]" section of .link, .network, and .netdev files has added a MachineTag check that ties network settings to the presence or absence of certain tags. The "networkctl reload" command has added an option "—no-reconfigure" to reload .network and .netdev files from disk without reconfiguring existing network links. In .network files, multiple network device names can now be specified in the IPoIB, IPVLAN, IPVTAP, MACsec, MACVLAN, MACVTAP, Tunnel, VLAN, VXLAN, and Xfrm parameters, separated by spaces.
  • In systemd-journald, the FSS (Forward Secure Sealing) mechanism, which guarantees the integrity of logs, has been transitioned to using cryptographic functions from the OpenSSL library instead of libgcrypt. The libsystemd library is no longer linked with libgcrypt.
  • The systemd-sysctl utility has added a "—verify" option, where the sysctl parameter value is read after setting and compared with the original value to verify if the change was applied. Options "—save=FILENAME" and "—revert=FILENAME" have been added to save and restore sysctl settings stored in the /run/sysctl.d/ directory.
  • Support for building with OpenSSL 4 has been added.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster