ืžืขืจื›ืช systemd ื’ืจืกื” 250

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ื”ื•ืฆื’ื” ื”ืžื”ื“ื•ืจื” ืฉืœ ืžืขืจื›ืช ืžื ื”ืœ ื”ืžืขืจื›ืช systemd 250. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ื”ืฆื™ื’ื” ืืช ื”ื™ื›ื•ืœืช ืœืื—ืกืŸ ืื™ืฉื•ืจื™ื ื‘ืฆื•ืจื” ืžื•ืฆืคื ืช, ื”ื˜ืžืขืช ืื™ืžื•ืช ืฉืœ ืžื—ื™ืฆื•ืช GPT ืฉื–ื•ื”ื• ืื•ื˜ื•ืžื˜ื™ืช ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ืžื™ื“ืข ืžืฉื•ืคืจ ืขืœ ื”ื’ื•ืจืžื™ื ืœืขื™ื›ื•ื‘ื™ื ื›ืืฉืจ. ื”ืชื—ืœืช ืฉื™ืจื•ืชื™ื, ื•ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืœื”ื’ื‘ืœืช ื’ื™ืฉื” ืœืฉื™ืจื•ืชื™ื ืœืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื•ืžืžืฉืงื™ ืจืฉืช ืžืกื•ื™ืžื•ืช, ื ื™ืชื ืช ืชืžื™ื›ื” ื‘ื ื™ื˜ื•ืจ ืฉืœืžื•ืช ื”ืžื—ื™ืฆื•ืช ื‘ืืžืฆืขื•ืช ืžื•ื“ื•ืœ dm-integrity ื•ืชืžื™ื›ื” ื‘ืขื“ื›ื•ืŸ ืื•ื˜ื•ืžื˜ื™ ืฉืœ sd-boot.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืื™ืฉื•ืจื™ื ืžื•ืฆืคื ื™ื ื•ืžืื•ืžืชื™ื, ืฉื™ื›ื•ืœื” ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ืช ืœืื—ืกื•ืŸ ืžืื•ื‘ื˜ื— ืฉืœ ื—ื•ืžืจื™ื ืจื’ื™ืฉื™ื ื›ื’ื•ืŸ ืžืคืชื—ื•ืช SSL ื•ืกื™ืกืžืื•ืช ื’ื™ืฉื”. ืคืขื ื•ื— ื”ืื™ืฉื•ืจื™ื ืžืชื‘ืฆืข ืจืง ื‘ืขืช ื”ืฆื•ืจืš ื•ื‘ืงืฉืจ ืœื”ืชืงื ื” ืื• ืœืฆื™ื•ื“ ื”ืžืงื•ืžื™. ื”ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื ืื•ื˜ื•ืžื˜ื™ืช ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชืžื™ ื”ืฆืคื ื” ืกื™ืžื˜ืจื™ื™ื, ืฉื”ืžืคืชื— ืขื‘ื•ืจื ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืžื•ืงื ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื, ื‘ืฉื‘ื‘ TPM2, ืื• ื‘ืืžืฆืขื•ืช ืขืจื›ืช ืฉื™ืœื•ื‘. ื›ืืฉืจ ื”ืฉื™ืจื•ืช ืžืชื—ื™ืœ, ื”ืื™ืฉื•ืจื™ื ืžืคื•ืขื ื—ื™ื ืื•ื˜ื•ืžื˜ื™ืช ื•ื”ื•ืคื›ื™ื ืœื–ืžื™ื ื™ื ืœืฉื™ืจื•ืช ื‘ืฆื•ืจืชื• ื”ืจื’ื™ืœื”. ื›ื“ื™ ืœืขื‘ื•ื“ ืขื ืื™ืฉื•ืจื™ื ืžื•ืฆืคื ื™ื, ื ื•ืกืคื” ื›ืœื™ ื”ืฉื™ืจื•ืช 'systemd-creds', ื•ื”ื”ื’ื“ืจื•ืช LoadCredentialEncrypted ื•-SetCredentialEncrypted ื”ื•ืฆืขื• ืœืฉื™ืจื•ืชื™ื.
  • sd-stub, ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืฉืœ EFI ื”ืžืืคืฉืจ ืœืงื•ืฉื—ื” EFI ืœื˜ืขื•ืŸ ืืช ืœื™ื‘ืช ืœื™ื ื•ืงืก, ืชื•ืžืš ื›ืขืช ื‘ืืชื—ื•ืœ ื”ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ LINUX_EFI_INITRD_MEDIA_GUID EFI. ื›ืžื• ื›ืŸ, ื ื•ืกืคื” ืœ-sd-stub ื”ื™ื›ื•ืœืช ืœืืจื•ื– ืื™ืฉื•ืจื™ื ื•ืงื‘ืฆื™ sysext ืœืชื•ืš ืืจื›ื™ื•ืŸ cpio ื•ืœื”ืขื‘ื™ืจ ืืช ื”ืืจื›ื™ื•ืŸ ื”ื–ื” ืœืงืจื ืœ ื™ื—ื“ ืขื ื”-initrd (ืงื‘ืฆื™ื ื ื•ืกืคื™ื ืžืžื•ืงืžื™ื ื‘ืกืคืจื™ื™ืช /.extra/). ืชื›ื•ื ื” ื–ื• ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืžืฉ ื‘ืกื‘ื™ื‘ืช initrd ื‘ืœืชื™ ื ื™ืชื ืช ืœืื™ืžื•ืช, ืžืฉืœื™ืžื” ืขืœ ื™ื“ื™ sysexts ื•ื ืชื•ื ื™ ืื™ืžื•ืช ืžื•ืฆืคื ื™ื.
  • ืžืคืจื˜ ื”ืžื—ื™ืฆื•ืช ื”ื ื™ืชื ื•ืช ืœื’ื™ืœื•ื™ ื”ื•ืจื—ื‘ ืžืฉืžืขื•ืชื™ืช, ื•ืžืกืคืง ื›ืœื™ื ืœื–ื™ื”ื•ื™, ื”ืจื›ื‘ื” ื•ื”ืคืขืœื” ืฉืœ ืžื—ื™ืฆื•ืช ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช GPT (GUID Partition Tables). ื‘ื”ืฉื•ื•ืื” ืœืžื”ื“ื•ืจื•ืช ืงื•ื“ืžื•ืช, ื”ืžืคืจื˜ ืชื•ืžืš ื›ืขืช ื‘ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ื•ื‘ืžื—ื™ืฆืช /usr ืขื‘ื•ืจ ืจื•ื‘ ื”ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช, ื›ื•ืœืœ ืคืœื˜ืคื•ืจืžื•ืช ืฉืื™ื ืŸ ืžืฉืชืžืฉื•ืช ื‘-UEFI.

    Discoverable Partitions ืžื•ืกื™ืคื” ื’ื ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื—ื™ืฆื•ืช ืฉืฉืœืžื•ืชืŸ ืžืื•ืžืชืช ืขืœ ื™ื“ื™ ืžื•ื“ื•ืœ dm-verity ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช PKCS#7, ืžื” ืฉืžืงืœ ืขืœ ื™ืฆื™ืจืช ืชืžื•ื ื•ืช ื“ื™ืกืง ืžืื•ืžืชื•ืช ื‘ืžืœื•ืืŸ. ืชืžื™ื›ืช ืื™ืžื•ืช ืžืฉื•ืœื‘ืช ื‘ื›ืœื™ ืฉื™ืจื•ืช ืฉื•ื ื™ื ื”ืžื˜ืคืœื™ื ื‘ืชืžื•ื ื•ืช ื“ื™ืกืง, ื›ื•ืœืœ systemd-nspawn, systemd-sysext, systemd-dissect, ืฉื™ืจื•ืชื™ RootImage, systemd-tmpfiles ื•-systemd-sysusers.

  • ืœื™ื—ื™ื“ื•ืช ืฉืœื•ืงื— ื”ืจื‘ื” ื–ืžืŸ ืœื”ืชื—ื™ืœ ืื• ืœื”ืคืกื™ืง, ื‘ื ื•ืกืฃ ืœื”ืฆื’ืช ืกืจื’ืœ ื”ืชืงื“ืžื•ืช ืžื•ื ืคืฉ, ื ื™ืชืŸ ืœื”ืฆื™ื’ ืžื™ื“ืข ืกื˜ื˜ื•ืก ื”ืžืืคืฉืจ ืœื”ื‘ื™ืŸ ืžื” ื‘ื“ื™ื•ืง ืงื•ืจื” ื‘ืฉื™ืจื•ืช ื›ืจื’ืข ื•ืื™ื–ื” ืฉื™ืจื•ืช ื”ื•ื ืžื ื”ืœ ื”ืžืขืจื›ืช ื›ืจื’ืข ืžื—ื›ื” ืœื”ืฉืœืžื”.
  • ื”ื•ืกื™ืฃ ืืช ื”ืคืจืžื˜ืจ DefaultOOMScoreAdjust ืœ-/etc/systemd/system.conf ื•-/etc/systemd/user.conf, ื”ืžืืคืฉืจ ืœืš ืœื”ืชืื™ื ืืช ืกืฃ OOM-killer ืขื‘ื•ืจ ื–ื™ื›ืจื•ืŸ ื ืžื•ืš, ื”ื—ืœ ืขืœ ืชื”ืœื™ื›ื™ื ืฉื”ืžืขืจื›ืช ืžืชื—ื™ืœื” ืขื‘ื•ืจ ื”ืžืขืจื›ืช ื•ื”ืžืฉืชืžืฉื™ื. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžืฉืงืœ ืฉื™ืจื•ืชื™ ื”ืžืขืจื›ืช ื’ื‘ื•ื” ืžื–ื” ืฉืœ ืฉื™ืจื•ืชื™ ื”ืžืฉืชืžืฉ, ื›ืœื•ืžืจ. ื›ืืฉืจ ืื™ืŸ ืžืกืคื™ืง ื–ื™ื›ืจื•ืŸ, ื”ื”ืกืชื‘ืจื•ืช ืœื”ืคืกืงืช ืฉื™ืจื•ืชื™ ื”ืžืฉืชืžืฉ ื’ื‘ื•ื”ื” ืžื–ื• ืฉืœ ืฉื™ืจื•ืชื™ ื”ืžืขืจื›ืช.
  • ื ื•ืกืคื” ื”ื”ื’ื“ืจื” RestrictFileSystems, ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืฉืœ ืฉื™ืจื•ืชื™ื ืœืกื•ื’ื™ื ืžืกื•ื™ืžื™ื ืฉืœ ืžืขืจื›ื•ืช ืงื‘ืฆื™ื. ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ืกื•ื’ื™ ืžืขืจื›ื•ืช ื”ืงื‘ืฆื™ื ื”ื–ืžื™ื ื™ื, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” "systemd-analyze filesystems". ื‘ืื ืœื•ื’ื™ื”, ื”ื•ื˜ืžืขื” ืืคืฉืจื•ืช RestrictNetworkInterfaces, ื”ืžืืคืฉืจืช ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœืžืžืฉืงื™ ืจืฉืช ืžืกื•ื™ืžื™ื. ื”ื”ื˜ืžืขื” ืžื‘ื•ืกืกืช ืขืœ ืžื•ื“ื•ืœ BPF LSM, ื”ืžื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืฉืœ ืงื‘ื•ืฆืช ืชื”ืœื™ื›ื™ื ืœืื•ื‘ื™ื™ืงื˜ื™ ืœื™ื‘ื”.
  • ื ื•ืกืคื• ืงื•ื‘ืฅ ืชืฆื•ืจื” ื—ื“ืฉ /etc/integritytab ื•ื›ืœื™ ืฉื™ืจื•ืช systemd-integritysetup ืฉืžื’ื“ื™ืจื™ื ืืช ืžื•ื“ื•ืœ dm-integrity ืœืฉืœื•ื˜ ื‘ืฉืœืžื•ืช ื”ื ืชื•ื ื™ื ื‘ืจืžืช ื”ืกืงื˜ื•ืจ, ืœืžืฉืœ, ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืช ื”ื‘ืœืชื™ ื ื™ืชื ื•ืช ืœืฉื™ื ื•ื™ ืฉืœ ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื (ื”ืฆืคื ื” ืžืื•ืžืชืช, ืžื‘ื˜ื™ื—ื” ืฉื‘ืœื•ืง ื ืชื•ื ื™ื ื™ืฉ ืœื ืฉื•ื ืชื” ื‘ืกื™ื‘ื•ื‘). ื”ืคื•ืจืžื˜ ืฉืœ ื”ืงื•ื‘ืฅ /etc/integritytab ื“ื•ืžื” ืœืงื‘ืฆื™ /etc/crypttab ื•-/etc/veritytab, ืืœื ืฉื”ืฉื™ืžื•ืฉ ื‘-dm-integrity ื‘ืžืงื•ื dm-crypt ื•-dm-verity.
  • ื”ืชื•ื•ืกืฃ ืงื•ื‘ืฅ ื™ื—ื™ื“ื” ื—ื“ืฉ systemd-boot-update.service, ื›ืืฉืจ ื”ื•ื ืžื•ืคืขืœ ื•-sd-bootloader ืžื•ืชืงืŸ, systemd ื™ืขื“ื›ืŸ ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ื’ืจืกื” ืฉืœ sd-bootloader, ืชื•ืš ืฉืžื™ืจื” ืขืœ ืงื•ื“ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืžืขื•ื“ื›ืŸ ืชืžื™ื“. sd-boot ืขืฆืžื• ื ื‘ื ื” ื›ืขืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ SBAT (UEFI Secure Boot Advanced Targeting), ื”ืคื•ืชืจ ื‘ืขื™ื•ืช ืขื ืฉืœื™ืœืช ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ UEFI Secure Boot. ื‘ื ื•ืกืฃ, sd-boot ืžืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื ืชื— ืืช ื”ื’ื“ืจื•ืช ื”ืืชื—ื•ืœ ืฉืœ Microsoft Windows ื›ื“ื™ ืœื™ืฆื•ืจ ื‘ืฆื•ืจื” ื ื›ื•ื ื” ืืช ื”ืฉืžื•ืช ืฉืœ ืžื—ื™ืฆื•ืช ื”ืืชื—ื•ืœ ืขื Windows ื•ืœื”ืฆื™ื’ ืืช ื’ืจืกืช Windows.

    sd-boot ืžืกืคืง ื’ื ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืขืจื›ืช ืฆื‘ืขื™ื ื‘ื–ืžืŸ ื”ื‘ื ื™ื™ื”. ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืืชื—ื•ืœ, ื”ื•ืกืคื” ืชืžื™ื›ื” ืœืฉื™ื ื•ื™ ืจื–ื•ืœื•ืฆื™ื™ืช ื”ืžืกืš ืขืœ ื™ื“ื™ ืœื—ื™ืฆื” ืขืœ ืžืงืฉ "r". ื ื•ืกืฃ ืžืงืฉ ืงื™ืฆื•ืจ "f" ื›ื“ื™ ืœืขื‘ื•ืจ ืœืžืžืฉืง ืชืฆื•ืจืช ื”ืงื•ืฉื—ื”. ื ื•ืกืฃ ืžืฆื‘ ืœืืชื—ื•ืœ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ื”ืžืขืจื›ืช ื”ืชื•ืื ืœืคืจื™ื˜ ื”ืชืคืจื™ื˜ ืฉื ื‘ื—ืจ ื‘ืžื”ืœืš ื”ืืชื—ื•ืœ ื”ืื—ืจื•ืŸ. ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื˜ืขื•ืŸ ืื•ื˜ื•ืžื˜ื™ืช ืžื ื”ืœื™ ื”ืชืงื ื™ื ืฉืœ EFI ื”ืžืžื•ืงืžื™ื ื‘ืกืคืจื™ื™ืช /EFI/systemd/drivers/ ื‘ืกืขื™ืฃ ESP (ืžื—ื™ืฆืช ืžืขืจื›ืช EFI).

  • ื›ืœื•ืœ ืงื•ื‘ืฅ ื™ื—ื™ื“ื” ื—ื“ืฉ factory-reset.target, ืืฉืจ ืžืขื•ื‘ื“ ื‘-systemd-login ื‘ืื•ืคืŸ ื“ื•ืžื” ืœืคืขื•ืœื•ืช ืืชื—ื•ืœ, ื›ื™ื‘ื•ื™, ื”ืฉืขื™ื” ื•-hibernate, ื•ืžืฉืžืฉ ืœื™ืฆื™ืจืช ืžื˜ืคืœื™ื ืœื‘ื™ืฆื•ืข ืื™ืคื•ืก ืœื”ื’ื“ืจื•ืช ื”ื™ืฆืจืŸ.
  • ื”ืชื”ืœื™ืš ืฉื ืคืชืจ ื‘ืžืขืจื›ืช ื™ื•ืฆืจ ื›ืขืช ืฉืงืข ื”ืื–ื ื” ื ื•ืกืฃ ื‘-127.0.0.54 ื‘ื ื•ืกืฃ ืœ-127.0.0.53. ื‘ืงืฉื•ืช ื”ืžื’ื™ืขื•ืช ืœ-127.0.0.54 ืžื•ืคื ื•ืช ืชืžื™ื“ ืœืฉืจืช DNS ื‘ืžืขืœื” ื”ื–ืจื ื•ืื™ื ืŸ ืžืขื•ื‘ื“ื•ืช ื‘ืื•ืคืŸ ืžืงื•ืžื™.
  • ืกื™ืคืง ืืช ื”ื™ื›ื•ืœืช ืœื‘ื ื•ืช systemd-importd ื•-systemd-resolved ืขื ืกืคืจื™ื™ืช OpenSSL ื‘ืžืงื•ื libgcrypt.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืจืืฉื•ื ื™ืช ื‘ืืจื›ื™ื˜ืงื˜ื•ืจืช LoongArch ื”ืžืฉืžืฉืช ื‘ืžืขื‘ื“ื™ Loongson.
  • systemd-gpt-auto-generator ืžืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืžื—ื™ืฆื•ืช ื”ื—ืœืคื” ื”ืžื•ื’ื“ืจื•ืช ืขืœ ื™ื“ื™ ื”ืžืขืจื›ืช ื”ืžื•ืฆืคื ื•ืช ืขืœ ื™ื“ื™ ืชืช-ื”ืžืขืจื›ืช LUKS2.
  • ืงื•ื“ ื ื™ืชื•ื— ื”ืชืžื•ื ื•ืช ืฉืœ GPT ื”ืžืฉืžืฉ ื‘ื›ืœื™ ืขื–ืจ systemd-nspawn, systemd-dissect ื•ื“ื•ืžื™ื• ืžื™ื™ืฉื ืืช ื”ื™ื›ื•ืœืช ืœืคืขื ื— ืชืžื•ื ื•ืช ืขื‘ื•ืจ ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช ืื—ืจื•ืช, ื•ืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘-systemd-nspawn ืœื”ืคืขืœืช ืชืžื•ื ื•ืช ืขืœ ืืžื•ืœื˜ื•ืจื™ื ืฉืœ ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช ืื—ืจื•ืช.
  • ื‘ืขืช ื‘ื“ื™ืงืช ืชืžื•ื ื•ืช ื“ื™ืกืง, systemd-dissect ืžืฆื™ื’ ื›ืขืช ืžื™ื“ืข ืขืœ ืžื˜ืจืช ื”ืžื—ื™ืฆื”, ื›ื’ื•ืŸ ื”ืชืืžื” ืœืืชื—ื•ืœ ื“ืจืš UEFI ืื• ืจื™ืฆื” ื‘ืงื•ื ื˜ื™ื™ื ืจ.
  • ื”ืฉื“ื” "SYSEXT_SCOPE" ื ื•ืกืฃ ืœืงื‘ืฆื™ system-extension.d/, ื”ืžืืคืฉืจ ืœืš ืœืฆื™ื™ืŸ ืืช ื”ื™ืงืฃ ืชืžื•ื ืช ื”ืžืขืจื›ืช - "initrd", "system" ืื• "ื ื™ื™ื“".
  • ืฉื“ื” "PORTABLE_PREFIXES" ื ื•ืกืฃ ืœืงื•ื‘ืฅ OS-release, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ืชืžื•ื ื•ืช ื ื™ื™ื“ื•ืช ื›ื“ื™ ืœืงื‘ื•ืข ืงื™ื“ื•ืžื•ืช ื ืชืžื›ื•ืช ืฉืœ ืงื‘ืฆื™ ื™ื—ื™ื“ื”.
  • systemd-logind ืžืฆื™ื’ ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช HandlePowerKeyLongPress, HandleRebootKeyLongPress, HandleSuspendKeyLongPress ื•-HandleHibernateKeyLongPress, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ื›ื“ื™ ืœืงื‘ื•ืข ืžื” ืงื•ืจื” ื›ืืฉืจ ืžืงืฉื™ื ืžืกื•ื™ืžื™ื ืžื•ื—ื–ืงื™ื ืœืžืฉืš ื™ื•ืชืจ ืž-5 ืฉื ื™ื•ืช (ืœื“ื•ื’ืžื”, ืœื—ื™ืฆื” ืขืœ ืžืงืฉ ื”ื”ืฉืขื™ื” ื›ื“ื™ ืœืขื‘ื•ืจ ืœืžืฆื‘ ื”ืžืชื ื” ื‘ืžื”ื™ืจื•ืช ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžื•ื’ื“ืจืช , ื•ื›ืืฉืจ ืžื—ื–ื™ืงื™ื ืื•ืชื•, ื”ื•ื ื™ืœืš ืœื™ืฉื•ืŸ).
  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช, ื”ื”ื’ื“ืจื•ืช StartupAllowedCPUs ื•-StartupAllowedMemoryNodes ืžื™ื•ืฉืžื•ืช, ืืฉืจ ืฉื•ื ื•ืช ืžื”ื’ื“ืจื•ืช ื“ื•ืžื•ืช ืœืœื ืงื™ื“ื•ืžืช ื”-Start-up ื‘ื›ืš ืฉื”ืŸ ืžื™ื•ืฉืžื•ืช ืจืง ื‘ืฉืœื‘ ื”ืืชื—ื•ืœ ื•ื”ื›ื™ื‘ื•ื™, ืžื” ืฉืžืืคืฉืจ ืœืš ืœื”ื’ื“ื™ืจ ืžื’ื‘ืœื•ืช ืžืฉืื‘ื™ื ืื—ืจื•ืช ื‘ืžื”ืœืš ื”ืืชื—ื•ืœ.
  • ื ื•ืกืฃ [ืžืฆื‘|ื”ืฆื”ืจื”][ื–ื™ื›ืจื•ืŸ|CPU|IO]ื‘ื“ื™ืงื•ืช ืœื—ืฅ ื”ืžืืคืฉืจื•ืช ืœื“ืœื’ ืขืœ ื”ืคืขืœืช ื™ื—ื™ื“ื” ืื• ืœื”ื™ื›ืฉืœ ืื ืžื ื’ื ื•ืŸ ื”-PSI ืžื–ื”ื” ืขื•ืžืก ืจื‘ ืขืœ ื”ื–ื™ื›ืจื•ืŸ, ื”ืžืขื‘ื“ ื•ื”-I/O ื‘ืžืขืจื›ืช.
  • ืžื’ื‘ืœืช ื”-inode ื”ืžืงืกื™ืžืœื™ืช ืฉื”ื•ื’ื“ืจื” ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื”ื•ื’ื“ืœื” ืขื‘ื•ืจ ืžื—ื™ืฆืช /dev ืž-64k ืœ-1M, ื•ืขื‘ื•ืจ ืžื—ื™ืฆืช /tmp ืž-400k ืœ-1M.
  • ื”ื•ืฆืขื” ื”ื’ื“ืจื” ืฉืœ ExecSearchPath ืœืฉื™ืจื•ืชื™ื, ื”ืžืืคืฉืจืช ืœืฉื ื•ืช ืืช ื”ื ืชื™ื‘ ืœื—ื™ืคื•ืฉ ืงื‘ืฆื™ ื”ืคืขืœื” ื”ืžื•ืคืขืœื™ื ื‘ืืžืฆืขื•ืช ื”ื’ื“ืจื•ืช ื›ืžื• ExecStart.
  • ื ื•ืกืคื” ื”ื”ื’ื“ืจื” RuntimeRandomizedExtraSec, ื”ืžืืคืฉืจืช ืœืš ืœื”ื›ื ื™ืก ืกื˜ื™ื•ืช ืืงืจืื™ื•ืช ืœืคืกืง ื”ื–ืžืŸ ืฉืœ RuntimeMaxSec, ื”ืžื’ื‘ื™ืœ ืืช ื–ืžืŸ ื”ื‘ื™ืฆื•ืข ืฉืœ ื™ื—ื™ื“ื”.
  • ื”ืชื—ื‘ื™ืจ ืฉืœ ื”ื”ื’ื“ืจื•ืช RuntimeDirectory, StateDirectory, CacheDirectory ื•-LogsDirectory ื”ื•ืจื—ื‘, ืฉื‘ื”ืŸ ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ืขืจืš ื ื•ืกืฃ ืžื•ืคืจื“ ื‘ื ืงื•ื“ืชื™ื™ื, ื›ืขืช ื ื™ืชืŸ ืœืืจื’ืŸ ื™ืฆื™ืจืช ืงื™ืฉื•ืจ ืกืžืœื™ ืœืกืคืจื™ื™ื” ื ืชื•ื ื” ืœืืจื’ื•ืŸ ื’ื™ืฉื” ืœืื•ืจืš ืžืกืคืจ ื ืชื™ื‘ื™ื.
  • ืขื‘ื•ืจ ืฉื™ืจื•ืชื™ื, ื”ื’ื“ืจื•ืช TTYRows ื•-TTYColumns ืžื•ืฆืขื•ืช ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ืžืกืคืจ ื”ืฉื•ืจื•ืช ื•ื”ืขืžื•ื“ื•ืช ื‘ืžื›ืฉื™ืจ ื”-TTY.
  • ื ื•ืกืคื” ื”ื”ื’ื“ืจื” ExitType, ื”ืžืืคืฉืจืช ืœืš ืœืฉื ื•ืช ืืช ื”ื”ื™ื’ื™ื•ืŸ ืœืงื‘ื™ืขืช ืกื•ืฃ ืฉื™ืจื•ืช. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, systemd ืขื•ืงื‘ืช ืจืง ืื—ืจ ื”ืžื•ื•ืช ืฉืœ ื”ืชื”ืœื™ืš ื”ืจืืฉื™, ืืš ืื ืžื•ื’ื“ืจ ExitType=cgroup, ืžื ื”ืœ ื”ืžืขืจื›ืช ื™ืžืชื™ืŸ ืœืกื™ื•ื ื”ืชื”ืœื™ืš ื”ืื—ืจื•ืŸ ื‘-cgroup.
  • ื”ื”ื˜ืžืขื” ืฉืœ systemd-cryptsetup ืฉืœ ืชืžื™ื›ืช TPM2/FIDO2/PKCS11 ื‘ื ื•ื™ื” ื›ืขืช ื’ื ื›ืชื•ืกืฃ cryptsetup, ื”ืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ืช cryptsetup ื”ืจื’ื™ืœื” ื›ื“ื™ ืœืคืชื•ื— ืžื—ื™ืฆื” ืžื•ืฆืคื ืช.
  • ื”ืžื˜ืคืœ TPM2 ื‘-systemd-cryptsetup/systemd-cryptsetup ืžื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืžืคืชื—ื•ืช RSA ืจืืฉื™ื™ื ื‘ื ื•ืกืฃ ืœืžืคืชื—ื•ืช ECC ื›ื“ื™ ืœืฉืคืจ ืืช ื”ืชืื™ืžื•ืช ืขื ืฉื‘ื‘ื™ื ืฉืื™ื ื ECC.
  • ืืคืฉืจื•ืช ืคืกืง ื”ื–ืžืŸ ืฉืœ ื”ืืกื™ืžื•ืŸ ื ื•ืกืคื” ืœ-/etc/crypttab, ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ืืช ื”ื–ืžืŸ ื”ืžืงืกื™ืžืœื™ ืœื”ืžืชื ื” ืœื—ื™ื‘ื•ืจ ืืกื™ืžื•ืŸ PKCS#11/FIDO2, ื•ืœืื—ืจ ืžื›ืŸ ืชืชื‘ืงืฉ ืœื”ื–ื™ืŸ ืกื™ืกืžื” ืื• ืžืคืชื— ืฉื—ื–ื•ืจ.
  • systemd-timesyncd ืžื™ื™ืฉืžืช ืืช ื”ื”ื’ื“ืจื” SaveIntervalSec, ื”ืžืืคืฉืจืช ืœืฉืžื•ืจ ืžืขืช ืœืขืช ืืช ื–ืžืŸ ื”ืžืขืจื›ืช ื”ื ื•ื›ื—ื™ ืœื“ื™ืกืง, ืœืžืฉืœ, ื›ื“ื™ ืœื™ื™ืฉื ืฉืขื•ืŸ ืžื•ื ื•ื˜ื•ื ื™ ื‘ืžืขืจื›ื•ืช ืœืœื RTC.
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืœื›ืœื™ ื”ืฉื™ืจื•ืช systemd-analyze: "--image" ื•-"--root" ืœื‘ื“ื™ืงืช ืงื‘ืฆื™ ื™ื—ื™ื“ื” ื‘ืชื•ืš ืชืžื•ื ื” ืื• ืกืคืจื™ื™ืช ืฉื•ืจืฉ ื ืชื•ื ื”, "--recursive-errors" ืœืฆื•ืจืš ื”ืชื—ืฉื‘ื•ืช ื‘ื™ื—ื™ื“ื•ืช ืชืœื•ื™ื•ืช ื‘ืขืช ืฉื’ื™ืื” ื–ื•ื”ื”, "--offline" ืœื‘ื“ื™ืงืช ืงื‘ืฆื™ ื™ื—ื™ื“ื” ืฉื ืฉืžืจื• ื‘ื“ื™ืกืง ื‘ื ืคืจื“, "-json" ืœืคืœื˜ ื‘ืคื•ืจืžื˜ JSON, "-quiet" ื›ื“ื™ ืœื”ืฉื‘ื™ืช ื”ื•ื“ืขื•ืช ืœื ื—ืฉื•ื‘ื•ืช, "-profile" ื›ื“ื™ ืœืื’ื“ ืœืคืจื•ืคื™ืœ ื ื™ื™ื“. ื›ืžื• ื›ืŸ ื ื•ืกืคื” ื”ืคืงื•ื“ื” inspect-elf ืœื ื™ืชื•ื— ืงื‘ืฆื™ ืœื™ื‘ื” ื‘ืคื•ืจืžื˜ ELF ื•ื”ื™ื›ื•ืœืช ืœื‘ื“ื•ืง ืงื‘ืฆื™ ื™ื—ื™ื“ื” ืขื ืฉื ื™ื—ื™ื“ื” ื ืชื•ืŸ, ืœืœื ืงืฉืจ ืื ืฉื ื–ื” ืชื•ืื ืœืฉื ื”ืงื•ื‘ืฅ.
  • systemd-networkd ื”ืจื—ื™ื‘ื” ืืช ื”ืชืžื™ื›ื” ื‘ืืคื™ืง Controller Area Network (CAN). ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ืœืฉืœื™ื˜ื” ื‘ืžืฆื‘ื™ CAN: Loopback, OneShot, PresumeAck ื•-ClassicDataLengthCode. ื ื•ืกืคื• TimeQuantaNSec, PropagationSegment, PhaseBufferSegment1, PhaseBufferSegment2, SyncJumpWidth, DataTimeQuantaNSec, DataPropagationSegment, DataPhaseBufferSegment1, DataPhaseBufferSegment2 ื•-DataSyncJumpWidth ืœืืคืฉืจื•ื™ื•ืช ื”ืฉืœื™ื˜ื” ื‘-[CAN] ืฉืœ ืงื‘ืฆื™ ืกื™ื ื›ืจื•ืŸ ืฉืœ ืงื‘ืฆื™ [CAN].
  • Systemd-networkd ื”ื•ืกื™ืคื” ืืคืฉืจื•ืช ืชื•ื•ื™ืช ืขื‘ื•ืจ ืœืงื•ื— DHCPv4, ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ืืช ืชื•ื•ื™ืช ื”ื›ืชื•ื‘ืช ื”ืžืฉืžืฉืช ื‘ืขืช ื”ื’ื“ืจืช ื›ืชื•ื‘ื•ืช IPv4.
  • systemd-udevd ืขื‘ื•ืจ "ethtool" ืžื™ื™ืฉืžืช ืชืžื™ื›ื” ื‘ืขืจื›ื™ "ืžืงืกื™ืžื•ื" ืžื™ื•ื—ื“ื™ื ืฉืžื’ื“ื™ืจื™ื ืืช ื’ื•ื“ืœ ื”ืžืื’ืจ ืœืขืจืš ื”ืžืจื‘ื™ ืฉื ืชืžืš ืขืœ ื™ื“ื™ ื”ื—ื•ืžืจื”.
  • ื‘ืงื‘ืฆื™ .link ืขื‘ื•ืจ systemd-udevd ืืชื” ื™ื›ื•ืœ ื›ืขืช ืœื”ื’ื“ื™ืจ ืคืจืžื˜ืจื™ื ืฉื•ื ื™ื ืœืฉื™ืœื•ื‘ ืžืชืืžื™ ืจืฉืช ื•ื—ื™ื‘ื•ืจ ืžื˜ืคืœื™ ื—ื•ืžืจื” (offload).
  • systemd-networkd ืžืฆื™ืข ืงื‘ืฆื™ .network ื—ื“ืฉื™ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ: 80-container-vb.network ืœื”ื’ื“ืจืช ื’ืฉืจื™ ืจืฉืช ืฉื ื•ืฆืจื• ื‘ืขืช ื”ืคืขืœืช systemd-nspawn ืขื ื”ืืคืฉืจื•ื™ื•ืช "--network-bridge" ืื• "--network-zone"; 80-6rd-tunnel.network ืœื”ื’ื“ืจืช ืžื ื”ืจื•ืช ืฉื ื•ืฆืจื•ืช ืื•ื˜ื•ืžื˜ื™ืช ื‘ืขืช ืงื‘ืœืช ืชื’ื•ื‘ืช DHCP ืขื ืืคืฉืจื•ืช 6RD.
  • Systemd-networkd ื•-systemd-udevd ื”ื•ืกื™ืคื• ืชืžื™ื›ื” ื‘ื”ืขื‘ืจืช IP ืขืœ ืžืžืฉืงื™ InfiniBand, ืฉืขื‘ื•ืจื ื”ืกืขื™ืฃ "[IPoIB]" ื ื•ืกืฃ ืœืงื‘ืฆื™ systemd.netdev, ื•ืขื™ื‘ื•ื“ ืฉืœ ืขืจืš "ipoib" ื™ื•ืฉื ื‘-Kind ื”ื’ื“ืจื”.
  • systemd-networkd ืžืกืคืงืช ืชืฆื•ืจืช ืžืกืœื•ืœ ืื•ื˜ื•ืžื˜ื™ืช ืขื‘ื•ืจ ื›ืชื•ื‘ื•ืช ืฉืฆื•ื™ื ื• ื‘ืคืจืžื˜ืจ AllowedIPs, ืฉื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจื™ื RouteTable ื•-RouteMetric ื‘ืกืขื™ืคื™ื [WireGuard] ื•-[WireGuardPeer].
  • systemd-networkd ืžืกืคืงืช ื™ืฆื™ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ื›ืชื•ื‘ื•ืช MAC ืฉืื™ื ืŸ ืžืฉืชื ื•ืช ืขื‘ื•ืจ ืžืžืฉืงื™ batadv ื•-bridge. ื›ื“ื™ ืœื”ืฉื‘ื™ืช ื”ืชื ื”ื’ื•ืช ื–ื•, ืชื•ื›ืœ ืœืฆื™ื™ืŸ MACAddress=none ื‘ืงื‘ืฆื™ .netdev.
  • ื”ื’ื“ืจืช WakeOnLanPassword ื ื•ืกืคื” ืœืงื‘ืฆื™ .link ื‘ืกืขื™ืฃ "[ืงื™ืฉื•ืจ]" ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืกื™ืกืžื” ื›ืืฉืจ WoL ืคื•ืขืœ ื‘ืžืฆื‘ "SecureOn".
  • ื”ื•ืกืคืช ื”ื’ื“ืจื•ืช AutoRateIngress, CompensationMode, FlowIsolationMode, NAT, MPUBytes, PriorityQueueingPreset, FirewallMark, Wash, SplitGSO ื•-UseRawPacketSize ืœืงื˜ืข "[CAKE]" ืฉืœ ืงื‘ืฆื™ .network ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ืคืจืžื˜ืจื™ื ืฉืœ CAKE (Common Applications Kept Enhanced) .
  • ื”ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ IgnoreCarrierLoss ืœืงื˜ืข "[ืจืฉืช]" ืฉืœ ืงื‘ืฆื™ .network, ื”ืžืืคืฉืจืช ืœืš ืœืงื‘ื•ืข ื›ืžื” ื–ืžืŸ ืœื—ื›ื•ืช ืœืคื ื™ ืฉืชื’ื™ื‘ ืœืื•ื‘ื“ืŸ ืื•ืช ื”ืกืคืง.
  • Systemd-nspawn, homectl, machinectl ื•-systemd-run ื”ืจื—ื™ื‘ื• ืืช ื”ืชื—ื‘ื™ืจ ืฉืœ ื”ืคืจืžื˜ืจ "--setenv" - ืื ืจืง ืฉื ื”ืžืฉืชื ื” ืฆื•ื™ืŸ (ืœืœื "="), ื”ืขืจืš ื™ื™ืœืงื— ืžืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” ื”ืžืชืื™ื (ืขื‘ื•ืจ ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืžืฆื™ื™ื ื™ื "--setenv=FOO" ื”ืขืจืš ื™ื™ืœืงื— ืžืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $FOO ื•ื™ืฉืžืฉ ื‘ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” ื‘ืื•ืชื• ืฉื ืฉื”ื•ื’ื“ืจ ื‘ืžื™ื›ืœ).
  • systemd-nspawn ื”ื•ืกื™ืคื” ืืคืฉืจื•ืช "--suppress-sync" ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืงืจื™ืื•ืช ืžืขืจื›ืช sync()/fsync()/fdatasync() ื‘ืขืช ื™ืฆื™ืจืช ืงื•ื ื˜ื™ื™ื ืจ (ืฉื™ืžื•ืฉื™ ื›ืืฉืจ ื”ืžื”ื™ืจื•ืช ื”ื™ื ื‘ืจืืฉ ืกื“ืจ ื”ืขื“ื™ืคื•ื™ื•ืช ื•ืฉืžื™ืจื” ืขืœ ื—ืคืฆื™ ื‘ื ื™ื™ื” ื‘ืžืงืจื” ืฉืœ ื›ืฉืœ ืื™ื ื• ื—ืฉื•ื‘, ืžื›ื™ื•ื•ืŸ ืฉื ื™ืชืŸ ืœื™ืฆื•ืจ ืื•ืชื ืžื—ื“ืฉ ื‘ื›ืœ ืขืช).
  • ื ื•ืกืฃ ื‘ืกื™ืก ื ืชื•ื ื™ื hwdb ื—ื“ืฉ ื”ื›ื•ืœืœ ืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ืžื ืชื—ื™ ืื•ืชื•ืช (ืžื•ืœื˜ื™ืžื˜ืจื™ื, ืžื ืชื—ื™ ืคืจื•ื˜ื•ืงื•ืœื™ื, ืื•ืกื™ืœื•ืกืงื•ืคื™ื ื•ืขื•ื“). ืžื™ื“ืข ืขืœ ืžืฆืœืžื•ืช ื‘-hwdb ื”ื•ืจื—ื‘ ืขื ืฉื“ื” ืขื ืžื™ื“ืข ืขืœ ืกื•ื’ ื”ืžืฆืœืžื” (ืจื’ื™ืœื” ืื• ืื™ื ืคืจื ืื“ื•ื) ื•ืžื™ืงื•ื ื”ืขื“ืฉื” (ืงื“ืžื™ืช ืื• ืื—ื•ืจื™ืช).
  • ื™ืฆื™ืจืช ื™ืฆื™ืจืช ืฉืžื•ืช ืžืžืฉืงื™ ืจืฉืช ืœื ืžืฉืชื ื™ื ืขื‘ื•ืจ ื”ืชืงื ื™ Netfront ื”ืžืฉืžืฉื™ื ื‘-Xen.
  • ื”ื ื™ืชื•ื— ืฉืœ ืงื‘ืฆื™ ื”ืœื™ื‘ื” ืขืœ ื™ื“ื™ ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-coredump ื”ืžื‘ื•ืกืก ืขืœ ืกืคืจื™ื•ืช libdw/libelf ืžื‘ื•ืฆืข ื›ืขืช ื‘ืชื”ืœื™ืš ื ืคืจื“, ืžื‘ื•ื“ื“ ื‘ืกื‘ื™ื‘ืช ืืจื’ื– ื—ื•ืœ.
  • systemd-importd ื”ื•ืกื™ืคื” ืชืžื™ื›ื” ื‘ืžืฉืชื ื™ ื”ืกื‘ื™ื‘ื” $SYSTEMD_IMPORT_BTRFS_SUBVOL, $SYSTEMD_IMPORT_BTRFS_QUOTA, $SYSTEMD_IMPORT_SYNC, ืฉื‘ืืžืฆืขื•ืชื ื ื™ืชืŸ ืœื”ืฉื‘ื™ืช ืืช ื”ื™ืฆื™ืจื” ืฉืœ ืžื—ื™ืฆื•ืช ืžืฉื ื” ืฉืœ Btrfs, ื•ื›ืŸ ืœื”ื’ื“ื™ืจ ืžื›ืกื•ืช ื•ืกื ื›ืจื•ืŸ ื“ื™ืกืงื™ื.
  • ื‘-systemd-journald, ื‘ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื”ืชื•ืžื›ื•ืช ื‘ืžืฆื‘ ื”ืขืชืงื”-ืขืœ-ื›ืชื™ื‘ื”, ืžืฆื‘ COW ืžื•ืคืขืœ ืžื—ื“ืฉ ืขื‘ื•ืจ ื™ื•ืžื ื™ื ื‘ืืจื›ื™ื•ืŸ, ืžื” ืฉืžืืคืฉืจ ืœื“ื—ื•ืก ืื•ืชื ื‘ืืžืฆืขื•ืช Btrfs.
  • systemd-journald ืžื™ื™ืฉืžืช ื‘ื™ื˜ื•ืœ ื›ืคื™ืœื•ืช ืฉืœ ืฉื“ื•ืช ื–ื”ื™ื ื‘ื”ื•ื“ืขื” ื‘ื•ื“ื“ืช, ื”ืžืชื‘ืฆืขืช ื‘ืฉืœื‘ ืฉืœืคื ื™ ื”ื›ื ืกืช ื”ื”ื•ื“ืขื” ื‘ื™ื•ืžืŸ.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--show" ืœืคืงื•ื“ืช ื›ื™ื‘ื•ื™ ืœื”ืฆื’ืช ื›ื™ื‘ื•ื™ ืžืชื•ื–ืžืŸ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”