ืžืขืจื›ืช systemd ื’ืจืกื” 242

[:he]

ืœืื—ืจ ื—ื•ื“ืฉื™ื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืžื ื”ืœ ื”ืžืขืจื›ืช ื‘ืžืงื•ื 242. ื‘ื™ืŸ ื”ื—ื™ื“ื•ืฉื™ื ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืชืžื™ื›ื” ื‘ืžื ื”ืจื•ืช L2TP, ื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ื”ืชื ื”ื’ื•ืช systemd-login ื‘ื”ืคืขืœื” ืžื—ื“ืฉ ื“ืจืš ืžืฉืชื ื™ ืกื‘ื™ื‘ื”, ืชืžื™ื›ื” ื‘ืžื—ื™ืฆื•ืช ืืชื—ื•ืœ XBOOTLDR ืžื•ืจื—ื‘ื•ืช ืœื”ืจื›ื‘ื”/ืืชื—ื•ืœ, ื™ื›ื•ืœืช ืœืืชื—ืœ ืขื ืžื—ื™ืฆืช ืฉื•ืจืฉ ื‘ืฉื›ื‘ื•ืช-ืขืœ, ื›ืžื• ื’ื ืžืกืคืจ ืจื‘ ืฉืœ ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช ืœืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ื™ื—ื™ื“ื•ืช.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • systemd-networkd ืžืกืคืงืช ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื ื”ืจื•ืช L2TP;
  • sd-boot ื•-bootctl ืžืกืคืงื™ื ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื—ื™ืฆื•ืช XBOOTLDR (ื˜ื•ืขืŸ ืืชื—ื•ืœ ื”ืžื•ืจื—ื‘) ื”ืžื™ื•ืขื“ื•ืช ืœื”ืจื›ื‘ื” ืขืœ /boot, ื‘ื ื•ืกืฃ ืœืžื—ื™ืฆื•ืช ESP ื”ืžื•ืชืงื ื•ืช ืขืœ /efi ืื• /boot/efi. ื›ืขืช ื ื™ืชืŸ ืœืืชื—ืœ ื’ืจืขื™ื ื™ื, ื”ื’ื“ืจื•ืช, ืชืžื•ื ื•ืช initrd ื•-EFI ื’ื ืžืžื—ื™ืฆื•ืช ESP ื•ื’ื ืฉืœ XBOOTLDR. ืฉื™ื ื•ื™ ื–ื” ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘-bootloader ืฉืœ sd-boot ื‘ืชืจื—ื™ืฉื™ื ืฉืžืจื ื™ื™ื ื™ื•ืชืจ, ื›ืืฉืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืขืฆืžื• ืžืžื•ืงื ื‘-ESP, ื•ื”ืงืจื ืœื™ื ื”ื˜ืขื•ื ื™ื ื•ื”ืžื˜ื-ื ืชื•ื ื™ื ื”ืงืฉื•ืจื™ื ืžืžื•ืงืžื™ื ื‘ืงื˜ืข ื ืคืจื“;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ืœืืชื—ืœ ืขื ืืคืฉืจื•ืช "systemd.volatile=overlay" ืฉื”ื•ืขื‘ืจื” ืœืงืจื ืœ, ื”ืžืืคืฉืจืช ืœืžืงื ืืช ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ื‘ืฉื›ื‘ื•ืช-ืขืœ ื•ืœืืจื’ืŸ ืขื‘ื•ื“ื” ืขืœ ื’ื‘ื™ ืชืžื•ื ื” ืœืงืจื™ืื” ื‘ืœื‘ื“ ืฉืœ ืกืคืจื™ื™ืช ื”ืฉื•ืจืฉ ืขื ืฉื™ื ื•ื™ื™ื ืฉื ื›ืชื‘ื• ืœ- ืกืคืจื™ื™ื” ื ืคืจื“ืช ื‘-tmpfs (ืฉื™ื ื•ื™ื™ื ื‘ืชืฆื•ืจื” ื–ื• ืื•ื‘ื“ื™ื ืœืื—ืจ ื”ืคืขืœื” ืžื—ื“ืฉ). ื‘ืื ืœื•ื’ื™ื”, systemd-nspawn ื”ื•ืกื™ืคื” ืืช ื”ืืคืฉืจื•ืช "--volatile=overlay" ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื“ื•ืžื” ื‘ืงื•ื ื˜ื™ื™ื ืจื™ื;
  • systemd-nspawn ื”ื•ืกื™ืคื” ืืช ื”ืืคืฉืจื•ืช "--oci-bundle" ื›ื“ื™ ืœืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ื—ื‘ื™ืœื•ืช ื–ืžืŸ ืจื™ืฆื” ื›ื“ื™ ืœืกืคืง ื”ืฉืงื” ืžื‘ื•ื“ื“ืช ืฉืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืชื•ืืžื™ื ืœืžืคืจื˜ Open Container Initiative (OCI). ืœืฉื™ืžื•ืฉ ื‘ื™ื—ื™ื“ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•-nspawn, ืžื•ืฆืขืช ืชืžื™ื›ื” ื‘ืืคืฉืจื•ื™ื•ืช ืฉื•ื ื•ืช ื”ืžืชื•ืืจื•ืช ื‘ืžืคืจื˜ OCI, ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ื™ื•ืช "--ืœื ื ื’ื™ืฉ" ื•"ืœื ื ื’ื™ืฉ" ื›ื“ื™ ืœื ืœื›ืœื•ืœ ื—ืœืงื™ื ืžืžืขืจื›ืช ื”ืงื‘ืฆื™ื, ื•ื”ืืคืฉืจื•ื™ื•ืช " ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช --console" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื–ืจืžื™ ืคืœื˜ ืกื˜ื ื“ืจื˜ื™ื™ื ื•-"-pipe";
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ื”ืชื ื”ื’ื•ืช ืฉืœ systemd-login ื‘ืืžืฆืขื•ืช ืžืฉืชื ื™ ืกื‘ื™ื‘ื”: $SYSTEMD_REBOOT_ TO_FIRMWARE_SETUP,
    $SYSTEMD_REBOOT_TO_BOOT_LOADER_MENU ื•
    $SYSTEMD_REBOOT_ TO_BOOT_LOADER_ENTRY. ื‘ืืžืฆืขื•ืช ืžืฉืชื ื™ื ืืœื”, ืืชื” ื™ื›ื•ืœ ืœื—ื‘ืจ ืžื˜ืคืœื™ื ืžืฉืœืš ื‘ืชื”ืœื™ืš ื”ืืชื—ื•ืœ (/run/systemd/reboot-to-firmware-setup, /run/systemd/reboot-to-boot-loader-menu ื•
    /run/systemd/reboot-to-boot-loader-entry) ืื• ื”ืฉื‘ืช ืื•ืชื ืœื—ืœื•ื˜ื™ืŸ (ืื ื”ืขืจืš ืžื•ื’ื“ืจ ื›-false);

  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช "-boot-load-menu=" ื•
    "โ€”boot-loader-entry=", ื”ืžืืคืฉืจ ืœืš ืœื‘ื—ื•ืจ ืคืจื™ื˜ ืกืคืฆื™ืคื™ ื‘ืชืคืจื™ื˜ ื”ืืชื—ื•ืœ ืื• ืžืฆื‘ ืืชื—ื•ืœ ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ;

  • ื ื•ืกืคื” ืคืงื•ื“ืช ื‘ื™ื“ื•ื“ ื—ื“ืฉื” ืฉืœ ืืจื’ื– ื—ื•ืœ "RestrictSUIDSGID=", ื”ืžืฉืชืžืฉืช ื‘-seccomp ื›ื“ื™ ืœืืกื•ืจ ื™ืฆื™ืจืช ืงื‘ืฆื™ื ืขื ื“ื’ืœื™ SUID/SGID;
  • ื•ื“ื ืฉื”ื’ื‘ืœื•ืช "NoNewPrivileges" ื•-"RestrictSUIDSGID" ืžื™ื•ืฉืžื•ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืฉื™ืจื•ืชื™ื ืขื ืžืฆื‘ ื™ืฆื™ืจืช ืžื–ื”ื” ืžืฉืชืžืฉ ื“ื™ื ืžื™ ("DynamicUser" ืžื•ืคืขืœ);
  • ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ MACAddressPolicy=ื”ื’ื“ืจืช ืžืชืžืฉื›ืช ื‘ืงื‘ืฆื™ .link ืฉื•ื ืชื” ื›ื“ื™ ืœื›ืกื•ืช ืžื›ืฉื™ืจื™ื ื ื•ืกืคื™ื. ื”ืžืžืฉืงื™ื ืฉืœ ื’ืฉืจื™ ืจืฉืช, ืžื ื”ืจื•ืช (tun, tap) ื•ืงื™ืฉื•ืจื™ื ืžืฆื˜ื‘ืจื™ื (bond) ืื™ื ื ืžื–ื”ื™ื ืืช ืขืฆืžื ืืœื ืœืคื™ ืฉื ืžืžืฉืง ื”ืจืฉืช, ื•ืœื›ืŸ ืฉื ื–ื” ืžืฉืžืฉ ื›ืขืช ื›ื‘ืกื™ืก ืœืงืฉื™ืจืช ื›ืชื•ื‘ื•ืช MAC ื•-IPv4. ื‘ื ื•ืกืฃ, ื ื•ืกืคื” ื”ื”ื’ื“ืจื” "MACAddressPolicy=random", ืฉื‘ื” ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœืื’ื“ ื›ืชื•ื‘ื•ืช MAC ื•-IPv4 ืœืžื›ืฉื™ืจื™ื ื‘ืกื“ืจ ืืงืจืื™;
  • ืงื‘ืฆื™ ื™ื—ื™ื“ื•ืช ".device" ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช systemd-fstab-generator ืื™ื ื ื›ื•ืœืœื™ื ืขื•ื“ ืืช ื™ื—ื™ื“ื•ืช ".mount" ื”ืžืชืื™ืžื•ืช ื›ืชืœื•ืช ื‘ืกืขื™ืฃ "Wants=". ืคืฉื•ื˜ ื—ื™ื‘ื•ืจ ื”ืชืงืŸ ื›ื‘ืจ ืœื ืžืคืขื™ืœ ืื•ื˜ื•ืžื˜ื™ืช ื™ื—ื™ื“ื” ืœื”ืจื›ื‘ื”, ืืš ืขื“ื™ื™ืŸ ื ื™ืชืŸ ืœื”ืคืขื™ืœ ื™ื—ื™ื“ื•ืช ื›ืืœื” ืžืกื™ื‘ื•ืช ืื—ืจื•ืช, ื›ื’ื•ืŸ ื›ื—ืœืง ืž-local-fs.target ืื• ื›ืชืœื•ืช ื‘ื™ื—ื™ื“ื•ืช ืื—ืจื•ืช ื”ืชืœื•ื™ื•ืช ื‘-local-fs.target ;
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืกื™ื›ื•ืช ("*", ื•ื›ื•') ืœืคืงื•ื“ื•ืช "networkctl list/status/lldp" ื›ื“ื™ ืœืกื ืŸ ืงื‘ื•ืฆื•ืช ืžืกื•ื™ืžื•ืช ืฉืœ ืžืžืฉืงื™ ืจืฉืช ืœืคื™ ื—ืœืง ืžื”ืฉื ืฉืœื”ื;
  • ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $PIDFILE ืžื•ื’ื“ืจ ื›ืขืช ื‘ืืžืฆืขื•ืช ื”ื ืชื™ื‘ ื”ืžื•ื—ืœื˜ ืฉื”ื•ื’ื“ืจ ื‘ืฉื™ืจื•ืชื™ื ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ "PIDFile=;".
  • ืฉืจืชื™ Cloudflare ืฆื™ื‘ื•ืจื™ื™ื (1.1.1.1) ื ื•ืกืคื• ืœืžืกืคืจ ืฉืจืชื™ ื”-DNS ืœื’ื™ื‘ื•ื™ ื‘ืฉื™ืžื•ืฉ ืื ื”-DNS ื”ืจืืฉื™ ืื™ื ื• ืžื•ื’ื“ืจ ื‘ืžืคื•ืจืฉ. ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืžื—ื“ืฉ ืืช ืจืฉื™ืžืช ืฉืจืชื™ ื”-DNS ืœื’ื™ื‘ื•ื™, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช "-Ddns-servers=";
  • ื‘ืขืช ื–ื™ื”ื•ื™ ื ื•ื›ื—ื•ืช ืฉืœ ื‘ืงืจ ื”ืชืงื ื™ USB, ืžืคืขื™ืœ usb-gadget.target ื—ื“ืฉ ืžื•ืคืขืœ ืื•ื˜ื•ืžื˜ื™ืช (ื›ืืฉืจ ื”ืžืขืจื›ืช ืคื•ืขืœืช ืขืœ ื”ืชืงืŸ USB ื”ื™ืงืคื™);
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื•ืช, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "CPUQuotaPeriodSec=", ืฉืงื•ื‘ืขืช ืืช ืคืจืง ื”ื–ืžืŸ ื”ื™ื—ืกื™ ืืœื™ื• ื ืžื“ื“ืช ืžื›ืกืช ื–ืžืŸ ื”-CPU, ืฉื ืงื‘ืขื” ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "CPUQuota=";
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "ProtectHostname=", ื”ืื•ืกืจืช ืขืœ ืฉื™ืจื•ืชื™ื ืœืฉื ื•ืช ืžื™ื“ืข ืขืœ ืฉื ื”ืžืืจื—, ื’ื ืื ื™ืฉ ืœื”ื ืืช ื”ื”ืจืฉืื•ืช ื”ืžืชืื™ืžื•ืช;
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "NetworkNamespacePath=", ื”ืžืืคืฉืจืช ืœืš ืœืื’ื“ ืžืจื—ื‘ ืฉืžื•ืช ืœืฉื™ืจื•ืชื™ื ืื• ืœื™ื—ื™ื“ื•ืช ืฉืงืข ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ ืžืจื—ื‘ ื”ืฉืžื•ืช ื‘-pseudo-FS /proc;
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื‘ื˜ืœ ื”ื—ืœืคื” ืฉืœ ืžืฉืชื ื™ ืกื‘ื™ื‘ื” ืขื‘ื•ืจ ืชื”ืœื™ื›ื™ื ืฉื”ื•ืฉืงื• ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "ExecStart=" ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืชื• ":" ืœืคื ื™ ืคืงื•ื“ืช ื”ื”ืชื—ืœื”;
  • ืขื‘ื•ืจ ื˜ื™ื™ืžืจื™ื (ื™ื—ื™ื“ื•ืช ื˜ื™ื™ืžืจ) ื“ื’ืœื™ื ื—ื“ืฉื™ื "OnClockChange=" ื•
    "OnTimezoneChange=", ืฉื‘ืืžืฆืขื•ืชื• ืชื•ื›ืœ ืœืฉืœื•ื˜ ื‘ืงืจื™ืืช ื”ื™ื—ื™ื“ื” ื›ืืฉืจ ื”ื–ืžืŸ ืื• ืื–ื•ืจ ื”ื–ืžืŸ ืฉืœ ื”ืžืขืจื›ืช ืžืฉืชื ื”;

  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช "ConditionMemory=" ื•-"ConditionCPUs=", ืืฉืจ ืงื•ื‘ืขื•ืช ืืช ื”ืชื ืื™ื ืœื”ืชืงืฉืจื•ืช ืœื™ื—ื™ื“ื” ื‘ื”ืชืื ืœื’ื•ื“ืœ ื”ื–ื™ื›ืจื•ืŸ ื•ืžืกืคืจ ืœื™ื‘ื•ืช ื”-CPU (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืคืขื™ืœ ืฉื™ืจื•ืช ืขืชื™ืจ ืžืฉืื‘ื™ื ืจืง ืื ื”ื›ืžื•ืช ื”ื ื“ืจืฉืช ืฉืœ ื–ื™ื›ืจื•ืŸ RAM ื–ืžื™ืŸ);
  • ื ื•ืกืคื” ื™ื—ื™ื“ืช time-set.target ื—ื“ืฉื” ื”ืžืงื‘ืœืช ืืช ื–ืžืŸ ื”ืžืขืจื›ืช ื”ืžื•ื’ื“ืจ ื‘ืื•ืคืŸ ืžืงื•ืžื™, ืœืœื ืฉื™ืžื•ืฉ ื‘ื”ืชืืžื” ืขื ืฉืจืชื™ ื–ืžืŸ ื—ื™ืฆื•ื ื™ื™ื ื‘ืืžืฆืขื•ืช ื™ื—ื™ื“ืช time-sync.target. ื”ื™ื—ื™ื“ื” ื”ื—ื“ืฉื” ื™ื›ื•ืœื” ืœืฉืžืฉ ืฉื™ืจื•ืชื™ื ื”ื–ืงื•ืงื™ื ืœื“ื™ื•ืง ืฉืœ ืฉืขื•ื ื™ื ืžืงื•ืžื™ื™ื ืœื ืžืกื•ื ื›ืจื ื™ื;
  • ื”ืืคืฉืจื•ืช "--show-transaction" ื ื•ืกืคื” ืœ-"systemctl start" ื•ืคืงื•ื“ื•ืช ื“ื•ืžื•ืช, ื›ืืฉืจ ืฆื•ื™ื ื”, ืžื•ืฆื’ ืกื™ื›ื•ื ืฉืœ ื›ืœ ื”ืžืฉื™ืžื•ืช ืฉื ื•ืกืคื• ืœืชื•ืจ ืขืงื‘ ื”ืคืขื•ืœื” ื”ืžื‘ื•ืงืฉืช;
  • systemd-networkd ืžื™ื™ืฉืžืช ืืช ื”ื”ื’ื“ืจื” ืฉืœ ืžืฆื‘ 'ืžืฉื•ืขื‘ื“' ื—ื“ืฉ, ื”ืžืฉืžืฉ ื‘ืžืงื•ื 'ืžื•ืฉืคืœ' ืื• 'ืกืคืง' ืขื‘ื•ืจ ืžืžืฉืงื™ ืจืฉืช ืฉื”ื ื—ืœืง ืžืงื™ืฉื•ืจื™ื ืžืฆื˜ื‘ืจื™ื ืื• ืžื’ืฉืจื™ ืจืฉืช. ืขื‘ื•ืจ ืžืžืฉืงื™ื ืจืืฉื•ื ื™ื™ื, ื‘ืžืงืจื” ืฉืœ ื‘ืขื™ื•ืช ื‘ืื—ื“ ืžื”ืงื™ืฉื•ืจื™ื ื”ืžืจื•ื›ื‘ื™ื, ื”ืชื•ื•ืกืฃ ืžืฆื‘ 'ื”ืกืคืง ื”ืคื’ื•ืข';
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "IgnoreCarrierLoss=" ืœื™ื—ื™ื“ื•ืช .network ื›ื“ื™ ืœืฉืžื•ืจ ื”ื’ื“ืจื•ืช ืจืฉืช ื‘ืžืงืจื” ืฉืœ ืื•ื‘ื“ืŸ ื—ื™ื‘ื•ืจ;
  • ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "RequiredForOnline=" ื‘ื™ื—ื™ื“ื•ืช .network, ื›ืขืช ืชื•ื›ืœ ืœื”ื’ื“ื™ืจ ืืช ืžืฆื‘ ื”ืงื™ืฉื•ืจ ื”ืžื™ื ื™ืžืœื™ ื”ืžืงื•ื‘ืœ ื”ื ื“ืจืฉ ืœื”ืขื‘ืจืช ืžืžืฉืง ื”ืจืฉืช ืœ-"online" ื•ืœื”ืคืขื™ืœ ืืช ื”ืžื˜ืคืœ systemd-networkd-wait-online;
  • ื”ื•ืกืคื” ืืช ื”ืืคืฉืจื•ืช "--any" ืœ-systemd-networkd-wait-online ื›ื“ื™ ืœื”ืžืชื™ืŸ ืœืžื•ื›ื ื•ืช ืฉืœ ื›ืœ ืื—ื“ ืžืžืžืฉืงื™ ื”ืจืฉืช ืฉืฆื•ื™ื ื• ื‘ืžืงื•ื ื›ื•ืœื, ื›ืžื• ื’ื ืืช ื”ืืคืฉืจื•ืช "--operational-state=" ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืžืฆื‘ ืฉืœ ื”ืงื™ืฉื•ืจ ื”ืžืฆื™ื™ืŸ ืžื•ื›ื ื•ืช;
  • ื”ื•ืกืคืช ื”ื’ื“ืจื•ืช "UseAutonomousPrefix=" ื•-"UseOnLinkPrefix=" ืœื™ื—ื™ื“ื•ืช .network, ืฉื‘ื”ืŸ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื”ืชืขืœื ืžืงื™ื“ื•ืžื•ืช ื‘ืขืช ืงื‘ืœืช
    ื”ื•ื“ืขื” ืžื ืชื‘ IPv6 (RA, ื ืชื‘ ืคืจืกื•ืžืช);

  • ื‘ื™ื—ื™ื“ื•ืช .network, ื”ื”ื’ื“ืจื•ืช "MulticastFlood=", "NeighborSuppression=" ื•-"Learning=" ื ื•ืกืคื• ื›ื“ื™ ืœืฉื ื•ืช ืืช ืคืจืžื˜ืจื™ ื”ื”ืคืขืœื” ืฉืœ ื’ืฉืจ ื”ืจืฉืช, ื›ืžื• ื’ื ืืช ื”ื”ื’ื“ืจื” "TripleSampling=" ืœืฉื™ื ื•ื™ ืžืฆื‘ TRIPLE-SAMPLING ืฉืœ ืžืžืฉืงื™ CAN ื•ื™ืจื˜ื•ืืœื™ื™ื;
  • ื”ื’ื“ืจื•ืช "PrivateKeyFile=" ื•-"PresharedKeyFile=" ื ื•ืกืคื• ืœื™ื—ื™ื“ื•ืช .netdev, ืฉื‘ืืžืฆืขื•ืชืŸ ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื•ืžืฉื•ืชืคื™ื (PSK) ืขื‘ื•ืจ ืžืžืฉืงื™ WireGuard VPN;
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืฉืœ ืื•ืชื•-ืžืขื‘ื“-crypt ื•-submit-from-crypt-cpus ืœ-/etc/crypttab, ื”ืฉื•ืœื˜ื•ืช ื‘ื”ืชื ื”ื’ื•ืช ื”ืžืชื–ืžืŸ ื‘ืขืช โ€‹โ€‹ื”ืขื‘ืจืช ืขื‘ื•ื“ื” ื”ืงืฉื•ืจื” ืœื”ืฆืคื ื” ื‘ื™ืŸ ืœื™ื‘ื•ืช CPU;
  • systemd-tmpfiles ืžืกืคืง ืขื™ื‘ื•ื“ ืงื‘ืฆื™ ื ืขื™ืœื” ืœืคื ื™ ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื‘ืกืคืจื™ื•ืช ืขื ืงื‘ืฆื™ื ื–ืžื ื™ื™ื, ืžื” ืฉืžืืคืฉืจ ืœืš ืœื”ืฉื‘ื™ืช ืขื‘ื•ื“ื” ืขืœ ื ื™ืงื•ื™ ืงื‘ืฆื™ื ืžื™ื•ืฉื ื™ื ืœืžืฉืš ืคืขื•ืœื•ืช ืžืกื•ื™ืžื•ืช (ืœื“ื•ื’ืžื”, ื‘ืขืช ืคืจื™ืงืช ืืจื›ื™ื•ืŸ tar ื‘-/tmp, ืงื‘ืฆื™ื ื™ืฉื ื™ื ืžืื•ื“ ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ื ืคืชื—ื• ืฉืœื ื ื™ืชืŸ ืœืžื—ื•ืง ืœืคื ื™ ืชื•ื ื”ืคืขื•ืœื” ืื™ืชื);
  • ื”ืคืงื•ื“ื” "systemd-analyze cat-config" ืžืกืคืงืช ืืช ื”ื™ื›ื•ืœืช ืœื ืชื— ืชืฆื•ืจื” ื”ืžื—ื•ืœืงืช ืœืžืกืคืจ ืงื‘ืฆื™ื, ืœืžืฉืœ, ื”ื’ื“ืจื•ืช ืงื‘ื•ืขื•ืช ืžืจืืฉ ืฉืœ ื”ืžืฉืชืžืฉ ื•ื”ืžืขืจื›ืช, ื”ืชื•ื›ืŸ ืฉืœ tmpfiles.d ื•-sysusers.d, ื—ื•ืงื™ udev ื•ื›ื•'.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--cursor-file=" ืœ-"journalctl" ื›ื“ื™ ืœืฆื™ื™ืŸ ืงื•ื‘ืฅ ืœื˜ืขื™ื ื” ื•ืœืฉืžื™ืจื” ืฉืœ ืกืžืŸ ื”ืžื™ืงื•ื;
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ ACRN hypervisor ื•ืชืช ืžืขืจื›ืช WSL (Windows Subsystem for Linux) ืœ-systemd-detect-virt ืœื”ืกืชืขืคื•ืช ืœืื—ืจ ืžื›ืŸ ื‘ืืžืฆืขื•ืช ื”ืื•ืคืจื˜ื•ืจ ื”ืžื•ืชื ื” "ConditionVirtualization";
  • ื‘ืžื”ืœืš ื”ืชืงื ืช ืžืขืจื›ืช (ื‘ืขืช ื‘ื™ืฆื•ืข "ื”ืชืงื ืช ื ื™ื ื’'ื”"), ื™ืฆื™ืจืช ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ืœืงื‘ืฆื™ื systemd-networkd.service, systemd-networkd.socket,
    systemd-resolved.service, remote-cryptsetup.target, remote-fs.target,
    systemd-networkd-wait-online.service ื•-systemd-timesyncd.service. ื›ื“ื™ ืœื™ืฆื•ืจ ืงื‘ืฆื™ื ืืœื”, ื›ืขืช ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” "systemctl preset-all".

ืžืงื•ืจOpenNet.ru

[: he]

ืœืื—ืจ ื—ื•ื“ืฉื™ื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืžื ื”ืœ ื”ืžืขืจื›ืช ื‘ืžืงื•ื 242. ื‘ื™ืŸ ื”ื—ื™ื“ื•ืฉื™ื ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืชืžื™ื›ื” ื‘ืžื ื”ืจื•ืช L2TP, ื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ื”ืชื ื”ื’ื•ืช systemd-login ื‘ื”ืคืขืœื” ืžื—ื“ืฉ ื“ืจืš ืžืฉืชื ื™ ืกื‘ื™ื‘ื”, ืชืžื™ื›ื” ื‘ืžื—ื™ืฆื•ืช ืืชื—ื•ืœ XBOOTLDR ืžื•ืจื—ื‘ื•ืช ืœื”ืจื›ื‘ื”/ืืชื—ื•ืœ, ื™ื›ื•ืœืช ืœืืชื—ืœ ืขื ืžื—ื™ืฆืช ืฉื•ืจืฉ ื‘ืฉื›ื‘ื•ืช-ืขืœ, ื›ืžื• ื’ื ืžืกืคืจ ืจื‘ ืฉืœ ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช ืœืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ื™ื—ื™ื“ื•ืช.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • systemd-networkd ืžืกืคืงืช ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื ื”ืจื•ืช L2TP;
  • sd-boot ื•-bootctl ืžืกืคืงื™ื ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื—ื™ืฆื•ืช XBOOTLDR (ื˜ื•ืขืŸ ืืชื—ื•ืœ ื”ืžื•ืจื—ื‘) ื”ืžื™ื•ืขื“ื•ืช ืœื”ืจื›ื‘ื” ืขืœ /boot, ื‘ื ื•ืกืฃ ืœืžื—ื™ืฆื•ืช ESP ื”ืžื•ืชืงื ื•ืช ืขืœ /efi ืื• /boot/efi. ื›ืขืช ื ื™ืชืŸ ืœืืชื—ืœ ื’ืจืขื™ื ื™ื, ื”ื’ื“ืจื•ืช, ืชืžื•ื ื•ืช initrd ื•-EFI ื’ื ืžืžื—ื™ืฆื•ืช ESP ื•ื’ื ืฉืœ XBOOTLDR. ืฉื™ื ื•ื™ ื–ื” ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘-bootloader ืฉืœ sd-boot ื‘ืชืจื—ื™ืฉื™ื ืฉืžืจื ื™ื™ื ื™ื•ืชืจ, ื›ืืฉืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืขืฆืžื• ืžืžื•ืงื ื‘-ESP, ื•ื”ืงืจื ืœื™ื ื”ื˜ืขื•ื ื™ื ื•ื”ืžื˜ื-ื ืชื•ื ื™ื ื”ืงืฉื•ืจื™ื ืžืžื•ืงืžื™ื ื‘ืงื˜ืข ื ืคืจื“;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ืœืืชื—ืœ ืขื ืืคืฉืจื•ืช "systemd.volatile=overlay" ืฉื”ื•ืขื‘ืจื” ืœืงืจื ืœ, ื”ืžืืคืฉืจืช ืœืžืงื ืืช ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ื‘ืฉื›ื‘ื•ืช-ืขืœ ื•ืœืืจื’ืŸ ืขื‘ื•ื“ื” ืขืœ ื’ื‘ื™ ืชืžื•ื ื” ืœืงืจื™ืื” ื‘ืœื‘ื“ ืฉืœ ืกืคืจื™ื™ืช ื”ืฉื•ืจืฉ ืขื ืฉื™ื ื•ื™ื™ื ืฉื ื›ืชื‘ื• ืœ- ืกืคืจื™ื™ื” ื ืคืจื“ืช ื‘-tmpfs (ืฉื™ื ื•ื™ื™ื ื‘ืชืฆื•ืจื” ื–ื• ืื•ื‘ื“ื™ื ืœืื—ืจ ื”ืคืขืœื” ืžื—ื“ืฉ). ื‘ืื ืœื•ื’ื™ื”, systemd-nspawn ื”ื•ืกื™ืคื” ืืช ื”ืืคืฉืจื•ืช "--volatile=overlay" ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื“ื•ืžื” ื‘ืงื•ื ื˜ื™ื™ื ืจื™ื;
  • systemd-nspawn ื”ื•ืกื™ืคื” ืืช ื”ืืคืฉืจื•ืช "--oci-bundle" ื›ื“ื™ ืœืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ื—ื‘ื™ืœื•ืช ื–ืžืŸ ืจื™ืฆื” ื›ื“ื™ ืœืกืคืง ื”ืฉืงื” ืžื‘ื•ื“ื“ืช ืฉืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืชื•ืืžื™ื ืœืžืคืจื˜ Open Container Initiative (OCI). ืœืฉื™ืžื•ืฉ ื‘ื™ื—ื™ื“ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•-nspawn, ืžื•ืฆืขืช ืชืžื™ื›ื” ื‘ืืคืฉืจื•ื™ื•ืช ืฉื•ื ื•ืช ื”ืžืชื•ืืจื•ืช ื‘ืžืคืจื˜ OCI, ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ื™ื•ืช "--ืœื ื ื’ื™ืฉ" ื•"ืœื ื ื’ื™ืฉ" ื›ื“ื™ ืœื ืœื›ืœื•ืœ ื—ืœืงื™ื ืžืžืขืจื›ืช ื”ืงื‘ืฆื™ื, ื•ื”ืืคืฉืจื•ื™ื•ืช " ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช --console" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื–ืจืžื™ ืคืœื˜ ืกื˜ื ื“ืจื˜ื™ื™ื ื•-"-pipe";
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ื”ืชื ื”ื’ื•ืช ืฉืœ systemd-login ื‘ืืžืฆืขื•ืช ืžืฉืชื ื™ ืกื‘ื™ื‘ื”: $SYSTEMD_REBOOT_ TO_FIRMWARE_SETUP,
    $SYSTEMD_REBOOT_TO_BOOT_LOADER_MENU ื•
    $SYSTEMD_REBOOT_ TO_BOOT_LOADER_ENTRY. ื‘ืืžืฆืขื•ืช ืžืฉืชื ื™ื ืืœื”, ืืชื” ื™ื›ื•ืœ ืœื—ื‘ืจ ืžื˜ืคืœื™ื ืžืฉืœืš ื‘ืชื”ืœื™ืš ื”ืืชื—ื•ืœ (/run/systemd/reboot-to-firmware-setup, /run/systemd/reboot-to-boot-loader-menu ื•
    /run/systemd/reboot-to-boot-loader-entry) ืื• ื”ืฉื‘ืช ืื•ืชื ืœื—ืœื•ื˜ื™ืŸ (ืื ื”ืขืจืš ืžื•ื’ื“ืจ ื›-false);

  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช "-boot-load-menu=" ื•
    "โ€”boot-loader-entry=", ื”ืžืืคืฉืจ ืœืš ืœื‘ื—ื•ืจ ืคืจื™ื˜ ืกืคืฆื™ืคื™ ื‘ืชืคืจื™ื˜ ื”ืืชื—ื•ืœ ืื• ืžืฆื‘ ืืชื—ื•ืœ ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ;

  • ื ื•ืกืคื” ืคืงื•ื“ืช ื‘ื™ื“ื•ื“ ื—ื“ืฉื” ืฉืœ ืืจื’ื– ื—ื•ืœ "RestrictSUIDSGID=", ื”ืžืฉืชืžืฉืช ื‘-seccomp ื›ื“ื™ ืœืืกื•ืจ ื™ืฆื™ืจืช ืงื‘ืฆื™ื ืขื ื“ื’ืœื™ SUID/SGID;
  • ื•ื“ื ืฉื”ื’ื‘ืœื•ืช "NoNewPrivileges" ื•-"RestrictSUIDSGID" ืžื™ื•ืฉืžื•ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืฉื™ืจื•ืชื™ื ืขื ืžืฆื‘ ื™ืฆื™ืจืช ืžื–ื”ื” ืžืฉืชืžืฉ ื“ื™ื ืžื™ ("DynamicUser" ืžื•ืคืขืœ);
  • ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ MACAddressPolicy=ื”ื’ื“ืจืช ืžืชืžืฉื›ืช ื‘ืงื‘ืฆื™ .link ืฉื•ื ืชื” ื›ื“ื™ ืœื›ืกื•ืช ืžื›ืฉื™ืจื™ื ื ื•ืกืคื™ื. ื”ืžืžืฉืงื™ื ืฉืœ ื’ืฉืจื™ ืจืฉืช, ืžื ื”ืจื•ืช (tun, tap) ื•ืงื™ืฉื•ืจื™ื ืžืฆื˜ื‘ืจื™ื (bond) ืื™ื ื ืžื–ื”ื™ื ืืช ืขืฆืžื ืืœื ืœืคื™ ืฉื ืžืžืฉืง ื”ืจืฉืช, ื•ืœื›ืŸ ืฉื ื–ื” ืžืฉืžืฉ ื›ืขืช ื›ื‘ืกื™ืก ืœืงืฉื™ืจืช ื›ืชื•ื‘ื•ืช MAC ื•-IPv4. ื‘ื ื•ืกืฃ, ื ื•ืกืคื” ื”ื”ื’ื“ืจื” "MACAddressPolicy=random", ืฉื‘ื” ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœืื’ื“ ื›ืชื•ื‘ื•ืช MAC ื•-IPv4 ืœืžื›ืฉื™ืจื™ื ื‘ืกื“ืจ ืืงืจืื™;
  • ืงื‘ืฆื™ ื™ื—ื™ื“ื•ืช ".device" ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช systemd-fstab-generator ืื™ื ื ื›ื•ืœืœื™ื ืขื•ื“ ืืช ื™ื—ื™ื“ื•ืช ".mount" ื”ืžืชืื™ืžื•ืช ื›ืชืœื•ืช ื‘ืกืขื™ืฃ "Wants=". ืคืฉื•ื˜ ื—ื™ื‘ื•ืจ ื”ืชืงืŸ ื›ื‘ืจ ืœื ืžืคืขื™ืœ ืื•ื˜ื•ืžื˜ื™ืช ื™ื—ื™ื“ื” ืœื”ืจื›ื‘ื”, ืืš ืขื“ื™ื™ืŸ ื ื™ืชืŸ ืœื”ืคืขื™ืœ ื™ื—ื™ื“ื•ืช ื›ืืœื” ืžืกื™ื‘ื•ืช ืื—ืจื•ืช, ื›ื’ื•ืŸ ื›ื—ืœืง ืž-local-fs.target ืื• ื›ืชืœื•ืช ื‘ื™ื—ื™ื“ื•ืช ืื—ืจื•ืช ื”ืชืœื•ื™ื•ืช ื‘-local-fs.target ;
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืกื™ื›ื•ืช ("*", ื•ื›ื•') ืœืคืงื•ื“ื•ืช "networkctl list/status/lldp" ื›ื“ื™ ืœืกื ืŸ ืงื‘ื•ืฆื•ืช ืžืกื•ื™ืžื•ืช ืฉืœ ืžืžืฉืงื™ ืจืฉืช ืœืคื™ ื—ืœืง ืžื”ืฉื ืฉืœื”ื;
  • ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $PIDFILE ืžื•ื’ื“ืจ ื›ืขืช ื‘ืืžืฆืขื•ืช ื”ื ืชื™ื‘ ื”ืžื•ื—ืœื˜ ืฉื”ื•ื’ื“ืจ ื‘ืฉื™ืจื•ืชื™ื ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ "PIDFile=;".
  • ืฉืจืชื™ Cloudflare ืฆื™ื‘ื•ืจื™ื™ื (1.1.1.1) ื ื•ืกืคื• ืœืžืกืคืจ ืฉืจืชื™ ื”-DNS ืœื’ื™ื‘ื•ื™ ื‘ืฉื™ืžื•ืฉ ืื ื”-DNS ื”ืจืืฉื™ ืื™ื ื• ืžื•ื’ื“ืจ ื‘ืžืคื•ืจืฉ. ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืžื—ื“ืฉ ืืช ืจืฉื™ืžืช ืฉืจืชื™ ื”-DNS ืœื’ื™ื‘ื•ื™, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช "-Ddns-servers=";
  • ื‘ืขืช ื–ื™ื”ื•ื™ ื ื•ื›ื—ื•ืช ืฉืœ ื‘ืงืจ ื”ืชืงื ื™ USB, ืžืคืขื™ืœ usb-gadget.target ื—ื“ืฉ ืžื•ืคืขืœ ืื•ื˜ื•ืžื˜ื™ืช (ื›ืืฉืจ ื”ืžืขืจื›ืช ืคื•ืขืœืช ืขืœ ื”ืชืงืŸ USB ื”ื™ืงืคื™);
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื•ืช, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "CPUQuotaPeriodSec=", ืฉืงื•ื‘ืขืช ืืช ืคืจืง ื”ื–ืžืŸ ื”ื™ื—ืกื™ ืืœื™ื• ื ืžื“ื“ืช ืžื›ืกืช ื–ืžืŸ ื”-CPU, ืฉื ืงื‘ืขื” ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "CPUQuota=";
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "ProtectHostname=", ื”ืื•ืกืจืช ืขืœ ืฉื™ืจื•ืชื™ื ืœืฉื ื•ืช ืžื™ื“ืข ืขืœ ืฉื ื”ืžืืจื—, ื’ื ืื ื™ืฉ ืœื”ื ืืช ื”ื”ืจืฉืื•ืช ื”ืžืชืื™ืžื•ืช;
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” "NetworkNamespacePath=", ื”ืžืืคืฉืจืช ืœืš ืœืื’ื“ ืžืจื—ื‘ ืฉืžื•ืช ืœืฉื™ืจื•ืชื™ื ืื• ืœื™ื—ื™ื“ื•ืช ืฉืงืข ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ ืžืจื—ื‘ ื”ืฉืžื•ืช ื‘-pseudo-FS /proc;
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื‘ื˜ืœ ื”ื—ืœืคื” ืฉืœ ืžืฉืชื ื™ ืกื‘ื™ื‘ื” ืขื‘ื•ืจ ืชื”ืœื™ื›ื™ื ืฉื”ื•ืฉืงื• ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "ExecStart=" ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืชื• ":" ืœืคื ื™ ืคืงื•ื“ืช ื”ื”ืชื—ืœื”;
  • ืขื‘ื•ืจ ื˜ื™ื™ืžืจื™ื (ื™ื—ื™ื“ื•ืช ื˜ื™ื™ืžืจ) ื“ื’ืœื™ื ื—ื“ืฉื™ื "OnClockChange=" ื•
    "OnTimezoneChange=", ืฉื‘ืืžืฆืขื•ืชื• ืชื•ื›ืœ ืœืฉืœื•ื˜ ื‘ืงืจื™ืืช ื”ื™ื—ื™ื“ื” ื›ืืฉืจ ื”ื–ืžืŸ ืื• ืื–ื•ืจ ื”ื–ืžืŸ ืฉืœ ื”ืžืขืจื›ืช ืžืฉืชื ื”;

  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช "ConditionMemory=" ื•-"ConditionCPUs=", ืืฉืจ ืงื•ื‘ืขื•ืช ืืช ื”ืชื ืื™ื ืœื”ืชืงืฉืจื•ืช ืœื™ื—ื™ื“ื” ื‘ื”ืชืื ืœื’ื•ื“ืœ ื”ื–ื™ื›ืจื•ืŸ ื•ืžืกืคืจ ืœื™ื‘ื•ืช ื”-CPU (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืคืขื™ืœ ืฉื™ืจื•ืช ืขืชื™ืจ ืžืฉืื‘ื™ื ืจืง ืื ื”ื›ืžื•ืช ื”ื ื“ืจืฉืช ืฉืœ ื–ื™ื›ืจื•ืŸ RAM ื–ืžื™ืŸ);
  • ื ื•ืกืคื” ื™ื—ื™ื“ืช time-set.target ื—ื“ืฉื” ื”ืžืงื‘ืœืช ืืช ื–ืžืŸ ื”ืžืขืจื›ืช ื”ืžื•ื’ื“ืจ ื‘ืื•ืคืŸ ืžืงื•ืžื™, ืœืœื ืฉื™ืžื•ืฉ ื‘ื”ืชืืžื” ืขื ืฉืจืชื™ ื–ืžืŸ ื—ื™ืฆื•ื ื™ื™ื ื‘ืืžืฆืขื•ืช ื™ื—ื™ื“ืช time-sync.target. ื”ื™ื—ื™ื“ื” ื”ื—ื“ืฉื” ื™ื›ื•ืœื” ืœืฉืžืฉ ืฉื™ืจื•ืชื™ื ื”ื–ืงื•ืงื™ื ืœื“ื™ื•ืง ืฉืœ ืฉืขื•ื ื™ื ืžืงื•ืžื™ื™ื ืœื ืžืกื•ื ื›ืจื ื™ื;
  • ื”ืืคืฉืจื•ืช "--show-transaction" ื ื•ืกืคื” ืœ-"systemctl start" ื•ืคืงื•ื“ื•ืช ื“ื•ืžื•ืช, ื›ืืฉืจ ืฆื•ื™ื ื”, ืžื•ืฆื’ ืกื™ื›ื•ื ืฉืœ ื›ืœ ื”ืžืฉื™ืžื•ืช ืฉื ื•ืกืคื• ืœืชื•ืจ ืขืงื‘ ื”ืคืขื•ืœื” ื”ืžื‘ื•ืงืฉืช;
  • systemd-networkd ืžื™ื™ืฉืžืช ืืช ื”ื”ื’ื“ืจื” ืฉืœ ืžืฆื‘ 'ืžืฉื•ืขื‘ื“' ื—ื“ืฉ, ื”ืžืฉืžืฉ ื‘ืžืงื•ื 'ืžื•ืฉืคืœ' ืื• 'ืกืคืง' ืขื‘ื•ืจ ืžืžืฉืงื™ ืจืฉืช ืฉื”ื ื—ืœืง ืžืงื™ืฉื•ืจื™ื ืžืฆื˜ื‘ืจื™ื ืื• ืžื’ืฉืจื™ ืจืฉืช. ืขื‘ื•ืจ ืžืžืฉืงื™ื ืจืืฉื•ื ื™ื™ื, ื‘ืžืงืจื” ืฉืœ ื‘ืขื™ื•ืช ื‘ืื—ื“ ืžื”ืงื™ืฉื•ืจื™ื ื”ืžืจื•ื›ื‘ื™ื, ื”ืชื•ื•ืกืฃ ืžืฆื‘ 'ื”ืกืคืง ื”ืคื’ื•ืข';
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "IgnoreCarrierLoss=" ืœื™ื—ื™ื“ื•ืช .network ื›ื“ื™ ืœืฉืžื•ืจ ื”ื’ื“ืจื•ืช ืจืฉืช ื‘ืžืงืจื” ืฉืœ ืื•ื‘ื“ืŸ ื—ื™ื‘ื•ืจ;
  • ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "RequiredForOnline=" ื‘ื™ื—ื™ื“ื•ืช .network, ื›ืขืช ืชื•ื›ืœ ืœื”ื’ื“ื™ืจ ืืช ืžืฆื‘ ื”ืงื™ืฉื•ืจ ื”ืžื™ื ื™ืžืœื™ ื”ืžืงื•ื‘ืœ ื”ื ื“ืจืฉ ืœื”ืขื‘ืจืช ืžืžืฉืง ื”ืจืฉืช ืœ-"online" ื•ืœื”ืคืขื™ืœ ืืช ื”ืžื˜ืคืœ systemd-networkd-wait-online;
  • ื”ื•ืกืคื” ืืช ื”ืืคืฉืจื•ืช "--any" ืœ-systemd-networkd-wait-online ื›ื“ื™ ืœื”ืžืชื™ืŸ ืœืžื•ื›ื ื•ืช ืฉืœ ื›ืœ ืื—ื“ ืžืžืžืฉืงื™ ื”ืจืฉืช ืฉืฆื•ื™ื ื• ื‘ืžืงื•ื ื›ื•ืœื, ื›ืžื• ื’ื ืืช ื”ืืคืฉืจื•ืช "--operational-state=" ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืžืฆื‘ ืฉืœ ื”ืงื™ืฉื•ืจ ื”ืžืฆื™ื™ืŸ ืžื•ื›ื ื•ืช;
  • ื”ื•ืกืคืช ื”ื’ื“ืจื•ืช "UseAutonomousPrefix=" ื•-"UseOnLinkPrefix=" ืœื™ื—ื™ื“ื•ืช .network, ืฉื‘ื”ืŸ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื”ืชืขืœื ืžืงื™ื“ื•ืžื•ืช ื‘ืขืช ืงื‘ืœืช
    ื”ื•ื“ืขื” ืžื ืชื‘ IPv6 (RA, ื ืชื‘ ืคืจืกื•ืžืช);

  • ื‘ื™ื—ื™ื“ื•ืช .network, ื”ื”ื’ื“ืจื•ืช "MulticastFlood=", "NeighborSuppression=" ื•-"Learning=" ื ื•ืกืคื• ื›ื“ื™ ืœืฉื ื•ืช ืืช ืคืจืžื˜ืจื™ ื”ื”ืคืขืœื” ืฉืœ ื’ืฉืจ ื”ืจืฉืช, ื›ืžื• ื’ื ืืช ื”ื”ื’ื“ืจื” "TripleSampling=" ืœืฉื™ื ื•ื™ ืžืฆื‘ TRIPLE-SAMPLING ืฉืœ ืžืžืฉืงื™ CAN ื•ื™ืจื˜ื•ืืœื™ื™ื;
  • ื”ื’ื“ืจื•ืช "PrivateKeyFile=" ื•-"PresharedKeyFile=" ื ื•ืกืคื• ืœื™ื—ื™ื“ื•ืช .netdev, ืฉื‘ืืžืฆืขื•ืชืŸ ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื•ืžืฉื•ืชืคื™ื (PSK) ืขื‘ื•ืจ ืžืžืฉืงื™ WireGuard VPN;
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืฉืœ ืื•ืชื•-ืžืขื‘ื“-crypt ื•-submit-from-crypt-cpus ืœ-/etc/crypttab, ื”ืฉื•ืœื˜ื•ืช ื‘ื”ืชื ื”ื’ื•ืช ื”ืžืชื–ืžืŸ ื‘ืขืช โ€‹โ€‹ื”ืขื‘ืจืช ืขื‘ื•ื“ื” ื”ืงืฉื•ืจื” ืœื”ืฆืคื ื” ื‘ื™ืŸ ืœื™ื‘ื•ืช CPU;
  • systemd-tmpfiles ืžืกืคืง ืขื™ื‘ื•ื“ ืงื‘ืฆื™ ื ืขื™ืœื” ืœืคื ื™ ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื‘ืกืคืจื™ื•ืช ืขื ืงื‘ืฆื™ื ื–ืžื ื™ื™ื, ืžื” ืฉืžืืคืฉืจ ืœืš ืœื”ืฉื‘ื™ืช ืขื‘ื•ื“ื” ืขืœ ื ื™ืงื•ื™ ืงื‘ืฆื™ื ืžื™ื•ืฉื ื™ื ืœืžืฉืš ืคืขื•ืœื•ืช ืžืกื•ื™ืžื•ืช (ืœื“ื•ื’ืžื”, ื‘ืขืช ืคืจื™ืงืช ืืจื›ื™ื•ืŸ tar ื‘-/tmp, ืงื‘ืฆื™ื ื™ืฉื ื™ื ืžืื•ื“ ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ื ืคืชื—ื• ืฉืœื ื ื™ืชืŸ ืœืžื—ื•ืง ืœืคื ื™ ืชื•ื ื”ืคืขื•ืœื” ืื™ืชื);
  • ื”ืคืงื•ื“ื” "systemd-analyze cat-config" ืžืกืคืงืช ืืช ื”ื™ื›ื•ืœืช ืœื ืชื— ืชืฆื•ืจื” ื”ืžื—ื•ืœืงืช ืœืžืกืคืจ ืงื‘ืฆื™ื, ืœืžืฉืœ, ื”ื’ื“ืจื•ืช ืงื‘ื•ืขื•ืช ืžืจืืฉ ืฉืœ ื”ืžืฉืชืžืฉ ื•ื”ืžืขืจื›ืช, ื”ืชื•ื›ืŸ ืฉืœ tmpfiles.d ื•-sysusers.d, ื—ื•ืงื™ udev ื•ื›ื•'.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--cursor-file=" ืœ-"journalctl" ื›ื“ื™ ืœืฆื™ื™ืŸ ืงื•ื‘ืฅ ืœื˜ืขื™ื ื” ื•ืœืฉืžื™ืจื” ืฉืœ ืกืžืŸ ื”ืžื™ืงื•ื;
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ ACRN hypervisor ื•ืชืช ืžืขืจื›ืช WSL (Windows Subsystem for Linux) ืœ-systemd-detect-virt ืœื”ืกืชืขืคื•ืช ืœืื—ืจ ืžื›ืŸ ื‘ืืžืฆืขื•ืช ื”ืื•ืคืจื˜ื•ืจ ื”ืžื•ืชื ื” "ConditionVirtualization";
  • ื‘ืžื”ืœืš ื”ืชืงื ืช ืžืขืจื›ืช (ื‘ืขืช ื‘ื™ืฆื•ืข "ื”ืชืงื ืช ื ื™ื ื’'ื”"), ื™ืฆื™ืจืช ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ืœืงื‘ืฆื™ื systemd-networkd.service, systemd-networkd.socket,
    systemd-resolved.service, remote-cryptsetup.target, remote-fs.target,
    systemd-networkd-wait-online.service ื•-systemd-timesyncd.service. ื›ื“ื™ ืœื™ืฆื•ืจ ืงื‘ืฆื™ื ืืœื”, ื›ืขืช ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” "systemctl preset-all".

ืžืงื•ืจ: OpenNet.ru

[:]

ื”ื•ืกืคืช ืชื’ื•ื‘ื”