ืžืขืจื›ืช systemd ื’ืจืกื” 243

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืžื ื”ืœ ื”ืžืขืจื›ืช ื‘ืžืงื•ื 243. ื‘ื™ืŸ ื”ื—ื™ื“ื•ืฉื™ื, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืืช ื”ืฉื™ืœื•ื‘ ื‘-PID 1 ืฉืœ ืžื˜ืคืœ ืœื–ื™ื›ืจื•ืŸ ื ืžื•ืš ื‘ืžืขืจื›ืช, ืชืžื™ื›ื” ื‘ืฆื™ืจื•ืฃ ืชื•ื›ื ื™ื•ืช BPF ืžืฉืœืš ืœืกื™ื ื•ืŸ ืชืขื‘ื•ืจืช ื™ื—ื™ื“ื•ืช, ืืคืฉืจื•ื™ื•ืช ื—ื“ืฉื•ืช ืจื‘ื•ืช ืขื‘ื•ืจ systemd-networkd, ืžืฆื‘ ืœื ื™ื˜ื•ืจ ืจื•ื—ื‘ ื”ืคืก ืฉืœ ื”ืจืฉืช ืžืžืฉืงื™ื, ื”ืžืืคืฉืจื™ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืžืขืจื›ื•ืช 64 ืกื™ื‘ื™ื•ืช ืžืกืคืจื™ PID ืฉืœ 22 ืกื™ื‘ื™ื•ืช ื‘ืžืงื•ื 16 ืกื™ื‘ื™ื•ืช, ืžืขื‘ืจ ืœื”ื™ืจืจื›ื™ื™ืช cgroups ืžืื•ื—ื“ืช, ื”ื›ืœืœื” ื‘-systemd-network-generator.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ื–ื™ื”ื•ื™ ืฉืœ ืื•ืชื•ืช ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ืœื™ื‘ื” ื‘ืขืจืš ืžื—ื•ืฅ ืœื–ื™ื›ืจื•ืŸ (Out-Of-Memory, OOM) ื ื•ืกืฃ ืœืžื˜ืคืœ PID 1 ื›ื“ื™ ืœื”ืขื‘ื™ืจ ื™ื—ื™ื“ื•ืช ืฉื”ื’ื™ืขื• ืœืžื’ื‘ืœืช ืฆืจื™ื›ืช ื”ื–ื™ื›ืจื•ืŸ ืœืžืฆื‘ ืžื™ื•ื—ื“ ืขื ื™ื›ื•ืœืช ืื•ืคืฆื™ื•ื ืœื™ืช ืœืืœืฅ ืื•ืชืŸ ืœื”ืคืกื™ืง ืื• ืœื”ืคืกื™ืง;
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ืคืจืžื˜ืจื™ื ื—ื“ืฉื™ื IPIngressFilterPath ื•
    IPEgressFilterPath, ื”ืžืืคืฉืจ ืœืš ืœื—ื‘ืจ ืชื•ื›ื ื™ื•ืช BPF ืขื ืžื˜ืคืœื™ื ืฉืจื™ืจื•ืชื™ื™ื ื›ื“ื™ ืœืกื ืŸ ืžื ื•ืช IP ื ื›ื ืกื•ืช ื•ื™ื•ืฆืื•ืช ืฉื ื•ืฆืจื•ืช ืขืœ ื™ื“ื™ ืชื”ืœื™ื›ื™ื ื”ืงืฉื•ืจื™ื ืœื™ื—ื™ื“ื” ื–ื•. ื”ืชื›ื•ื ื•ืช ื”ืžื•ืฆืขื•ืช ืžืืคืฉืจื•ืช ืœืš ืœื™ืฆื•ืจ ืกื•ื’ ืฉืœ ื—ื•ืžืช ืืฉ ืขื‘ื•ืจ ืฉื™ืจื•ืชื™ ืžืขืจื›ืช. ื“ื•ื’ืžื” ืœื›ืชื™ื‘ื” ืžืกื ืŸ ืจืฉืช ืคืฉื•ื˜ ื”ืžื‘ื•ืกืก ืขืœ BPF;

  • ื”ืคืงื•ื“ื” "ื ืงื”" ื ื•ืกืคื” ืœื›ืœื™ ื”ืฉื™ืจื•ืช systemctl ื›ื“ื™ ืœืžื—ื•ืง ืืช ื”ืžื˜ืžื•ืŸ, ืงื‘ืฆื™ ื–ืžืŸ ื”ืจื™ืฆื”, ืžื™ื“ืข ืกื˜ื˜ื•ืก ื•ืกืคืจื™ื•ืช ื™ื•ืžืŸ;
  • systemd-networkd ืžื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืžืžืฉืงื™ ืจืฉืช MACsec, nlmon, IPVTAP ื•-Xfrm;
  • systemd-networkd ืžื™ื™ืฉืžืช ืชืฆื•ืจื” ื ืคืจื“ืช ืฉืœ ืขืจื™ืžื•ืช DHCPv4 ื•-DHCPv6 ื“ืจืš ื”ืกืขื™ืคื™ื "[DHCPv4]" ื•-"[DHCPv6]" ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื”. ื ื•ืกืคื” ืืคืฉืจื•ืช RoutesToDNS ืœื”ื•ืกืคืช ืžืกืœื•ืœ ื ืคืจื“ ืœืฉืจืช ื”-DNS ืฉืฆื•ื™ืŸ ื‘ืคืจืžื˜ืจื™ื ื”ืžืชืงื‘ืœื™ื ืžืฉืจืช ื”-DHCP (ื›ืš ืฉืชืขื‘ื•ืจื” ืœ-DNS ื ืฉืœื—ืช ื“ืจืš ืื•ืชื• ืงื™ืฉื•ืจ ื›ืžื• ื”ืžืกืœื•ืœ ื”ืจืืฉื™ ื”ืžืชืงื‘ืœ ืžื”-DHCP). ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ื—ื“ืฉื•ืช ืขื‘ื•ืจ DHCPv4: MaxAttempts - ืžืกืคืจ ืžืงืกื™ืžืœื™ ืฉืœ ื‘ืงืฉื•ืช ืœืงื‘ืœืช ื›ืชื•ื‘ืช, BlackList - ืจืฉื™ืžื” ืฉื—ื•ืจื” ืฉืœ ืฉืจืชื™ DHCP, SendRelease - ืžืืคืฉืจื™ื ืฉืœื™ื—ืช ื”ื•ื“ืขื•ืช DHCP RELEASE ืขื ืกื™ื•ื ื”ื”ืคืขืœื”;
  • ืคืงื•ื“ื•ืช ื—ื“ืฉื•ืช ื ื•ืกืคื• ืœื›ืœื™ ื”ืฉื™ืจื•ืช systemd-analyze:
    • "systemd-analyze timestamp" - ื ื™ืชื•ื— ื–ืžืŸ ื•ื”ืžืจื”;
    • "ื–ืžืŸ ืฉื™ื˜ืช ืื ืœื™ื–ื”" - ื ื™ืชื•ื— ื•ื”ืžืจื” ืฉืœ ืคืจืงื™ ื–ืžืŸ;
    • "ืชื ืื™ systemd-analyze" - ื ื™ืชื•ื— ื•ื‘ื“ื™ืงื” ืฉืœ ื‘ื™ื˜ื•ื™ื™ ConditionXYZ;
    • "systemd-analyze exit-status" - ื ื™ืชื•ื— ื•ื”ืžืจืช ืงื•ื“ื™ ื™ืฆื™ืื” ืžืžืกืคืจื™ื ืœืฉืžื•ืช ื•ืœื”ื™ืคืš;
    • "systemd-analyze unit-files" - ืžืคืจื˜ ืืช ื›ืœ ื ืชื™ื‘ื™ ื”ืงื‘ืฆื™ื ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช ื•ื›ื™ื ื•ื™ ื™ื—ื™ื“ื•ืช.
  • ืืคืฉืจื•ื™ื•ืช SuccessExitStatus, RestartPreventExitStatus ื•
    RestartForceExitStatus ืชื•ืžืš ื›ืขืช ืœื ืจืง ื‘ืงื•ื“ื™ ื”ื—ื–ืจื” ืžืกืคืจื™ื™ื, ืืœื ื’ื ื‘ืžื–ื”ื™ ื”ื˜ืงืกื˜ ืฉืœื”ื (ืœื“ื•ื’ืžื”, "DATAERR"). ืืชื” ื™ื›ื•ืœ ืœื”ืฆื™ื’ ืืช ืจืฉื™ืžืช ื”ืงื•ื“ื™ื ืฉื”ื•ืงืฆื• ืœืžื–ื”ื™ื ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” "sytemd-analyze exit-status";

  • ื”ืคืงื•ื“ื” "ืžื—ืง" ื ื•ืกืคื” ืœื›ืœื™ ื”ืฉื™ืจื•ืช networkctl ืœืžื—ื™ืงืช ื”ืชืงื ื™ ืจืฉืช ื•ื™ืจื˜ื•ืืœื™ื™ื, ื›ืžื• ื’ื ื”ืืคืฉืจื•ืช "-stats" ืœื”ืฆื’ืช ืกื˜ื˜ื™ืกื˜ื™ืงื•ืช ืžื›ืฉื™ืจื™ื;
  • ื”ื’ื“ืจื•ืช SpeedMeter ื•-SpeedMeterIntervalSec ื ื•ืกืคื• ืœ-networkd.conf ืœืžื“ื™ื“ื” ืชืงื•ืคืชื™ืช ืฉืœ ื”ืชืคื•ืงื” ืฉืœ ืžืžืฉืงื™ ืจืฉืช. ื ื™ืชืŸ ืœืจืื•ืช ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ื”ืžืชืงื‘ืœื™ื ืžืชื•ืฆืื•ืช ื”ืžื“ื™ื“ื” ื‘ืคืœื˜ ืฉืœ ื”ืคืงื•ื“ื” 'networkctl status';
  • ื ื•ืกืฃ ื›ืœื™ ืขื–ืจ ื—ื“ืฉ systemd-network-generator ืœื”ืคืงืช ืงื‘ืฆื™ื
    .network, .netdev ื•-.link ื‘ื”ืชื‘ืกืก ืขืœ ื”ื’ื“ืจื•ืช IP ืฉื”ื•ืขื‘ืจื• ื‘ืขืช ื”ื”ืฉืงื” ื‘ืืžืฆืขื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ืœื™ื‘ืช ืœื™ื ื•ืงืก ื‘ืคื•ืจืžื˜ ื”ื’ื“ืจื•ืช Dracut;

  • ืขืจืš sysctl "kernel.pid_max" ื‘ืžืขืจื›ื•ืช 64 ืกื™ื‘ื™ื•ืช ืžื•ื’ื“ืจ ื›ืขืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœ-4194304 (22 ืกื™ื‘ื™ื•ืช PID ื‘ืžืงื•ื 16 ืกื™ื‘ื™ื•ืช), ืžื” ืฉืžืคื—ื™ืช ืืช ื”ืกื‘ื™ืจื•ืช ืœื”ืชื ื’ืฉื•ื™ื•ืช ื‘ืขืช ื”ืงืฆืืช PIDs, ืžื’ื“ื™ืœ ืืช ื”ืžื’ื‘ืœื” ืขืœ ืžืกืคืจ ื”-PID ื‘ื•-ื–ืžื ื™ืช ื”ืคืขืœืช ืชื”ืœื™ื›ื™ื, ื•ื™ืฉ ืœื” ื”ืฉืคืขื” ื—ื™ื•ื‘ื™ืช ืขืœ ื”ืื‘ื˜ื—ื”. ื”ืฉื™ื ื•ื™ ืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ืชืื™ืžื•ืช, ืืš ื‘ืขื™ื•ืช ื›ืืœื” ื˜ืจื ื“ื•ื•ื—ื• ื‘ืคื•ืขืœ;
  • ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืฉืœื‘ ื”ื‘ื ื™ื™ื” ืขื•ื‘ืจ ืœื”ื™ืจืจื›ื™ื” ื”ืžืื•ื—ื“ืช cgroups-v2 ("-Ddefault-hierarchy=unified"). ื‘ืขื‘ืจ, ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื™ืชื” ืžืฆื‘ ื”ื™ื‘ืจื™ื“ื™ ("-Ddefault-hierarchy=hybrid");
  • ื”ื”ืชื ื”ื’ื•ืช ืฉืœ ืžืกื ืŸ ืงืจื™ืื•ืช ื”ืžืขืจื›ืช (SystemCallFilter) ืฉื•ื ืชื”, ืืฉืจ ื‘ืžืงืจื” ืฉืœ ืงืจื™ืืช ืžืขืจื›ืช ืืกื•ืจื”, ืžืคืกื™ืง ื›ืขืช ืืช ื”ืชื”ืœื™ืš ื›ื•ืœื•, ื•ืœื ืฉืจืฉื•ืจื™ื ื‘ื•ื“ื“ื™ื, ืฉื›ืŸ ืกื™ื•ื ืฉืจืฉื•ืจื™ื ื‘ื•ื“ื“ื™ื ืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ื‘ืœืชื™ ืฆืคื•ื™ื•ืช. ื”ืฉื™ื ื•ื™ื™ื ื—ืœื™ื ืจืง ืื ื™ืฉ ืœืš ืœื™ื‘ืช Linux 4.14+ ื•-libsecomp 2.4.0+;
  • ืœืชื•ื›ื ื™ื•ืช ืœืœื ืคืจื™ื‘ื™ืœื’ื™ื” ื ื™ืชื ืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื— ืžื ื•ืช ICMP Echo (ping) ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช sysctl "net.ipv4.ping_group_range" ืขื‘ื•ืจ ื›ืœ ืžื’ื•ื•ืŸ ื”ืงื‘ื•ืฆื•ืช (ืขื‘ื•ืจ ื›ืœ ื”ืชื”ืœื™ื›ื™ื);
  • ื›ื“ื™ ืœื”ืื™ืฅ ืืช ืชื”ืœื™ืš ื”ื‘ื ื™ื™ื”, ื”ื™ืฆื™ืจื” ืฉืœ ืžื“ืจื™ื›ื™ื ืœืื“ื ื”ื•ืคืกืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ (ื›ื“ื™ ืœื‘ื ื•ืช ืชื™ืขื•ื“ ืžืœื, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช "-Dman=true" ืื• "-Dhtml=true" ืขื‘ื•ืจ ืžื“ืจื™ื›ื™ื ื‘ืคื•ืจืžื˜ html). ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ืฆืคื™ื™ื” ื‘ืชื™ืขื•ื“, ืฉื ื™ ืกืงืจื™ืคื˜ื™ื ื›ืœื•ืœื™ื: build/man/man ื•-build/man/html ืœื”ืคืงื” ื•ืชืฆื•ื’ื” ืžืงื“ื™ืžื” ืฉืœ ืžื“ืจื™ื›ื™ื ื‘ืขืœื™ ืขื ื™ื™ืŸ;
  • ื›ื“ื™ ืœืขื‘ื“ ืฉืžื•ืช ืžืชื—ื ืขื ืชื•ื•ื™ื ืžืืœืคื‘ื™ืช ืœืื•ืžื™, ืกืคืจื™ื™ืช libidn2 ืžืฉืžืฉืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ (ื›ื“ื™ ืœื”ื—ื–ื™ืจ ืืช libidn, ื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช "-Dlibidn=true");
  • ื”ืชืžื™ื›ื” ื‘ืงื•ื‘ืฅ ื”ื”ืคืขืœื” /usr/sbin/halt.local, ืฉืกื™ืคืง ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœื ื”ื•ืคืฆื” ื‘ืื•ืคืŸ ื ืจื—ื‘ ื‘ื”ืคืฆื•ืช, ื”ื•ืคืกืงื”. ื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ืฉืงืช ื”ืคืงื•ื“ื•ืช ื‘ืขืช ื›ื™ื‘ื•ื™, ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืกืงืจื™ืคื˜ื™ื ื‘- /usr/lib/systemd/system-shutdown/ ืื• ืœื”ื’ื“ื™ืจ ื™ื—ื™ื“ื” ื—ื“ืฉื” ืฉืชืœื•ื™ื” ื‘-final.target;
  • ื‘ืฉืœื‘ ื”ืื—ืจื•ืŸ ืฉืœ ื”ื›ื™ื‘ื•ื™, systemd ืžืขืœื” ื›ืขืช ืื•ื˜ื•ืžื˜ื™ืช ืืช ืจืžืช ื”ื™ื•ืžืŸ ื‘-sysctl "kernel.printk", ืžื” ืฉืคื•ืชืจ ืืช ื”ื‘ืขื™ื” ืขื ื”ืฆื’ืช ื‘ื™ื•ืžืŸ ืื™ืจื•ืขื™ื ืฉื”ืชืจื—ืฉื• ื‘ืฉืœื‘ื™ื ื”ืžืื•ื—ืจื™ื ื™ื•ืชืจ ืฉืœ ื”ื›ื™ื‘ื•ื™, ื›ืืฉืจ ื“ืžื•ื ื™ ื”ืจื™ืฉื•ื ื”ืจื’ื™ืœื™ื ื›ื‘ืจ ื”ื•ืฉืœืžื• ;
  • ื‘-journalctl ื•ื‘ื›ืœื™ ืฉื™ืจื•ืช ืื—ืจื™ื ื”ืžืฆื™ื’ื™ื ื™ื•ืžื ื™ื, ืื–ื”ืจื•ืช ืžืกื•ืžื ื•ืช ื‘ืฆื”ื•ื‘, ื•ืจืฉื•ืžื•ืช ื‘ื™ืงื•ืจืช ืžืกื•ืžื ื•ืช ื‘ื›ื—ื•ืœ ื›ื“ื™ ืœื”ื“ื’ื™ืฉ ืื•ืชืŸ ื•ื™ื–ื•ืืœื™ืช ืžื”ืงื”ืœ;
  • ื‘ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $PATH, ื”ื ืชื™ื‘ ืœ-bin/ ืžื’ื™ืข ื›ืขืช ืœืคื ื™ ื”ื ืชื™ื‘ ืœ-sbin/, ื›ืœื•ืžืจ. ืื ื™ืฉ ืฉืžื•ืช ื–ื”ื™ื ืฉืœ ืงื‘ืฆื™ ื”ืคืขืœื” ื‘ืฉืชื™ ื”ืกืคืจื™ื•ืช, ื”ืงื•ื‘ืฅ ืž-bin/ ื™ื‘ื•ืฆืข;
  • systemd-logind ืžืกืคืงืช ืงืจื™ืื” ืœ-SetBrightness() ื›ื“ื™ ืœืฉื ื•ืช ื‘ื‘ื˜ื—ื” ืืช ื‘ื”ื™ืจื•ืช ื”ืžืกืš ืขืœ ื‘ืกื™ืก ื›ืœ ื”ืคืขืœื”;
  • ื”ื“ื’ืœ "--wait-for-initialization" ื ื•ืกืฃ ืœืคืงื•ื“ื” "udevadm info" ื›ื“ื™ ืœื”ืžืชื™ืŸ ืœืืชื—ื•ืœ ื”ืžื›ืฉื™ืจ;
  • ื‘ืžื”ืœืš ืืชื—ื•ืœ ื”ืžืขืจื›ืช, ื”ืžื˜ืคืœ PID 1 ืžืฆื™ื’ ื›ืขืช ืืช ืฉืžื•ืช ื”ื™ื—ื™ื“ื•ืช ื‘ืžืงื•ื ืฉื•ืจื” ืขื ื”ืชื™ืื•ืจ ืฉืœื”ืŸ. ื›ื“ื™ ืœื—ื–ื•ืจ ืœื”ืชื ื”ื’ื•ืช ืงื•ื“ืžืช, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช StatusUnitFormat ื‘- /etc/systemd/system.conf ืื• ื‘ืืคืฉืจื•ืช ื”ืงืจื ืœ systemd.status_unit_format;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช KExecWatchdogSec ืœ-/etc/systemd/system.conf ืขื‘ื•ืจ Watchdog PID 1, ื”ืžืฆื™ื™ืŸ ืืช ืคืกืง ื”ื–ืžืŸ ืœื”ืคืขืœื” ืžื—ื“ืฉ ื‘ืืžืฆืขื•ืช kexec. ืชืคืื•ืจื” ื™ืฉื ื”
    ืฉื ShutdownWatchdogSec ืฉื•ื ื” ืœ-RebootWatchdogSec ื•ืžื’ื“ื™ืจ ืคืกืง ื–ืžืŸ ืขื‘ื•ืจ ืขื‘ื•ื“ื•ืช ื‘ืžื”ืœืš ื›ื™ื‘ื•ื™ ืื• ื”ืคืขืœื” ืžื—ื“ืฉ ืจื’ื™ืœื”;

  • ื ื•ืกืคื” ืืคืฉืจื•ืช ื—ื“ืฉื” ืœืฉื™ืจื•ืชื™ื ExecCondition, ื”ืžืืคืฉืจ ืœืš ืœืฆื™ื™ืŸ ืคืงื•ื“ื•ืช ืฉื™ื‘ื•ืฆืขื• ืœืคื ื™ ExecStartPre. ื‘ื”ืชื‘ืกืก ืขืœ ืงื•ื“ ื”ืฉื’ื™ืื” ืฉื”ื•ื—ื–ืจ ืขืœ ื™ื“ื™ ื”ืคืงื•ื“ื”, ืžืชืงื‘ืœืช ื”ื—ืœื˜ื” ืขืœ ื”ืžืฉืš ื‘ื™ืฆื•ืข ืฉืœ ื”ื™ื—ื™ื“ื” - ืื ืงื•ื“ 0 ืžื•ื—ื–ืจ, ื”ืฉืงืช ื”ื™ื—ื™ื“ื” ืžืžืฉื™ื›ื”, ืื ืž-1 ืขื“ 254 ื”ื™ื ืžืกืชื™ื™ืžืช ื‘ืฉืงื˜ ืœืœื ื“ื’ืœ ื›ืฉืœ, ืื 255 ื”ื™ื ืžืกืชื™ื™ืžืช ืขื ื“ื’ืœ ื›ื™ืฉืœื•ืŸ;
  • ื ื•ืกืฃ ืฉื™ืจื•ืช ื—ื“ืฉ systemd-pstore.service ื›ื“ื™ ืœื—ืœืฅ ื ืชื•ื ื™ื ืž-sys/fs/pstore/ ื•ืžืฉืžื™ืจื” ื‘-/var/lib/pstore ืœื ื™ืชื•ื— ื ื•ืกืฃ;
  • ืคืงื•ื“ื•ืช ื—ื“ืฉื•ืช ื ื•ืกืคื• ืœื›ืœื™ ื”ืฉื™ืจื•ืช timedatectl ืœื”ื’ื“ืจืช ืคืจืžื˜ืจื™ NTP ืขื‘ื•ืจ systemd-timesyncd ื‘ื™ื—ืก ืœืžืžืฉืงื™ ืจืฉืช;
  • ื”ืคืงื•ื“ื” "localectl list-locales" ื›ื‘ืจ ืœื ืžืฆื™ื’ื” ืžืงื•ืžื•ืช ืื—ืจื™ื ืžืœื‘ื“ UTF-8;
  • ืžื‘ื˜ื™ื— ืฉืžืชืขืœืžื™ื ืžืฉื’ื™ืื•ืช ื”ืงืฆืืช ืžืฉืชื ื™ื ื‘ืงื‘ืฆื™ sysctl.d/ ืื ืฉื ื”ืžืฉืชื ื” ืžืชื—ื™ืœ ื‘ืชื• "-";
  • ืฉื™ืจื•ืช systemd-random-seed.service ื›ืขืช ื”ื•ื ืื—ืจืื™ ืœื—ืœื•ื˜ื™ืŸ ืœืืชื—ื•ืœ ืžืื’ืจ ื”ืื ื˜ืจื•ืคื™ื” ืฉืœ ืžื—ื•ืœืœ ื”ืžืกืคืจื™ื ื”ืคืกืื•ื“ื•-ืืงืจืื™ื™ื ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื™ืฉ ืœื”ืคืขื™ืœ ืฉื™ืจื•ืชื™ื ื”ื“ื•ืจืฉื™ื ืืชื—ื•ืœ /dev/urandom ืœืื—ืจ systemd-random-seed.service;
  • ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ systemd-boot ืžืกืคืง ืืช ื”ื™ื›ื•ืœืช ื”ืื•ืคืฆื™ื•ื ืœื™ืช ืœืชืžื•ืš ืงื•ื‘ืฅ ื–ืจืขื™ื ืขื ืจืฆืฃ ืืงืจืื™ ื‘ืžื—ื™ืฆืช ืžืขืจื›ืช EFI (ESP);
  • ืคืงื•ื“ื•ืช ื—ื“ืฉื•ืช ื ื•ืกืคื• ืœื›ืœื™ ื”ืฉื™ืจื•ืช bootctl: "bootctl random-seed" ื›ื“ื™ ืœื™ืฆื•ืจ ืงื•ื‘ืฅ ื–ืจื™ืขื” ื‘-ESP ื•-"bootctl is-installed" ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ื”ืชืงื ื” ืฉืœ systemd-boot loader. bootctl ื”ื•ืชืื ื’ื ืœื”ืฆื’ืช ืื–ื”ืจื•ืช ืœื’ื‘ื™ ืชืฆื•ืจื” ืฉื’ื•ื™ื” ืฉืœ ืขืจื›ื™ ื”ืืชื—ื•ืœ (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืชืžื•ื ืช ื”ืœื™ื‘ื” ื ืžื—ืงืช, ืืš ื”ืขืจืš ืœื˜ืขื™ื ืชื” ื ืฉืืจ);
  • ืžืกืคืง ื‘ื—ื™ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžื—ื™ืฆืช ื”ื”ื—ืœืคื” ื›ืืฉืจ ื”ืžืขืจื›ืช ืขื•ื‘ืจืช ืœืžืฆื‘ ืฉื™ื ื”. ื”ืžื—ื™ืฆื” ื ื‘ื—ืจืช ื‘ื”ืชืื ืœืขื“ื™ืคื•ืช ืฉื”ื•ื’ื“ืจื” ืขื‘ื•ืจื”, ื•ื‘ืžืงืจื” ืฉืœ ืกื“ืจื™ ืขื“ื™ืคื•ื™ื•ืช ื–ื”ื™ื, ื›ืžื•ืช ื”ืฉื˜ื— ื”ืคื ื•ื™;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ืคืกืง ื–ืžืŸ ืฉืœ ืงื•ื‘ืฅ ืžืคืชื— ืœ-/etc/crypttab ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื›ืžื” ื–ืžืŸ ื”ืžื›ืฉื™ืจ ืขื ืžืคืชื— ื”ื”ืฆืคื ื” ื™ืžืชื™ืŸ ืœืคื ื™ ืฉื™ื‘ืงืฉ ืกื™ืกืžื” ื›ื“ื™ ืœื’ืฉืช ืœืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช IOWeight ืœื”ื’ื“ืจืช ืžืฉืงืœ ื”ืงืœื˜/ืคืœื˜ ืขื‘ื•ืจ ืžืชื–ืžืŸ ื”-BFQ;
  • systemd-resolved ืžื•ืกื™ืฃ ืžืฆื‘ ื”ืคืขืœื” 'ืงืคื“ื ื™' ืขื‘ื•ืจ DNS-over-TLS ื•ืžื™ื™ืฉืžืช ืืช ื”ื™ื›ื•ืœืช ืœืื—ืกืŸ ืชื’ื•ื‘ื•ืช DNS ื—ื™ื•ื‘ื™ื•ืช ื‘ืœื‘ื“ ("Cache no-negative" ื‘-resolved.conf);
  • ืขื‘ื•ืจ VXLAN, systemd-networkd ื”ื•ืกื™ืคื” ืืคืฉืจื•ืช GenericProtocolExtension ื›ื“ื™ ืœืืคืฉืจ ื”ืจื—ื‘ื•ืช ืคืจื•ื˜ื•ืงื•ืœ VXLAN. ืขื‘ื•ืจ VXLAN ื•-GENEVE, ื ื•ืกืคื” ื”ืืคืฉืจื•ืช IPDoNotFragment ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื“ื’ืœ ืื™ืกื•ืจ ื”ืคื™ืฆื•ืœ ืขื‘ื•ืจ ืžื ื•ืช ื™ื•ืฆืื•ืช;
  • ื‘-systemd-networkd, ื‘ืกืขื™ืฃ "[ื ืชื™ื‘]", ื”ื•ืคื™ืขื” ืืคืฉืจื•ืช FastOpenNoCookie ื›ื“ื™ ืœืืคืฉืจ ืืช ื”ืžื ื’ื ื•ืŸ ืœืคืชื™ื—ื” ืžื”ื™ืจื” ืฉืœ ื—ื™ื‘ื•ืจื™ TCP (TFO - TCP Fast Open, RFC 7413) ื‘ื™ื—ืก ืœืžืกืœื•ืœื™ื ื‘ื•ื“ื“ื™ื, ื›ืžื• ื’ื ืืช ืืคืฉืจื•ืช TTLPropagate ื›ื“ื™ ืœื”ื’ื“ื™ืจ TTL LSP (Label Switched Path). ืืคืฉืจื•ืช ื”-"Type" ืžืกืคืงืช ืชืžื™ื›ื” ื‘ืžืฆื‘ื™ ื ื™ืชื•ื‘ ืžืงื•ืžื™, ืฉื™ื“ื•ืจ, Anycast, Multicast, ื›ืœ ื•-xresolve;
  • Systemd-networkd ืžืฆื™ืขื” ืืคืฉืจื•ืช DefaultRouteOnDevice ื‘ืกืขื™ืฃ "[ืจืฉืช]" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ื”ืชืงืŸ ืจืฉืช ื ืชื•ืŸ;
  • Systemd-networkd ื”ื•ืกื™ืคื” ืืช ProxyARP ื•
    ProxyARPWifi ืœื”ื’ื“ืจืช ื”ืชื ื”ื’ื•ืช ืคืจื•ืงืกื™ ARP, MulticastRouter ืœืงื‘ื™ืขืช ืคืจืžื˜ืจื™ ื ื™ืชื•ื‘ ื‘ืžืฆื‘ ืจื™ื‘ื•ื™ ืฉื™ื“ื•ืจ, MulticastIGMPVersion ืœืฉื™ื ื•ื™ ื’ืจืกืช IGMP (Internet Group Management Protocol) ืœืžื•ืœื˜ื™ ืฉื™ื“ื•ืจ;

  • Systemd-networkd ื”ื•ืกื™ืคื” ืืคืฉืจื•ื™ื•ืช Local, Peer ื•-PeerPort ืขื‘ื•ืจ ืžื ื”ืจื•ืช FooOverUDP ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื›ืชื•ื‘ื•ืช ื”-IP ื”ืžืงื•ืžื™ื•ืช ื•ื”ืžืจื•ื—ืงื•ืช, ื›ืžื• ื’ื ืืช ืžืกืคืจ ื™ืฆื™ืืช ื”ืจืฉืช. ืขื‘ื•ืจ ืžื ื”ืจื•ืช TUN, ื ื•ืกืคื” ืืคืฉืจื•ืช VnetHeader ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืชืžื™ื›ื” ื‘-GSO (Generic Segment Offload);
  • ื‘-systemd-networkd, ื‘ืงื‘ืฆื™ .network ื•-.link ื‘ืงื˜ืข [Match], ื”ื•ืคื™ืขื” ืืคืฉืจื•ืช Property, ื”ืžืืคืฉืจืช ืœื–ื”ื•ืช ืžื›ืฉื™ืจื™ื ืœืคื™ ื”ืžืืคื™ื™ื ื™ื ื”ืกืคืฆื™ืคื™ื™ื ืฉืœื”ื ื‘-udev;
  • ื‘-systemd-networkd, ื ื•ืกืคื” ืืคืฉืจื•ืช AssignToLoopback ืขื‘ื•ืจ ืžื ื”ืจื•ืช, ื”ืฉื•ืœื˜ืช ืื ืงืฆื” ื”ืžื ื”ืจื” ืžื•ืงืฆื” ืœืžื›ืฉื™ืจ ื”ืœื•ืœืื” "lo";
  • systemd-networkd ืžืคืขื™ืœ ืื•ื˜ื•ืžื˜ื™ืช ืืช ืžื—ืกื ื™ืช ื”-IPv6 ืื ื”ื™ื ื ื—ืกืžืช ื‘ืืžืฆืขื•ืช sysctl disable_ipv6 - IPv6 ืžื•ืคืขืœ ืื ื”ื’ื“ืจื•ืช IPv6 (ืกื˜ื˜ื™ื•ืช ืื• DHCPv6) ืžื•ื’ื“ืจื•ืช ืขื‘ื•ืจ ืžืžืฉืง ื”ืจืฉืช, ืื—ืจืช ืขืจืš sysctl ืฉื”ื•ื’ื“ืจ ื›ื‘ืจ ืœื ืžืฉืชื ื”;
  • ื‘ืงื‘ืฆื™ .network, ื”ื”ื’ื“ืจื” CriticalConnection ื”ื•ื—ืœืคื” ื‘ืืคืฉืจื•ืช KeepConfiguration, ื”ืžืกืคืงืช ืืžืฆืขื™ื ื ื•ืกืคื™ื ืœื”ื’ื“ืจืช ืžืฆื‘ื™ื ("ื›ืŸ", "ืกื˜ื˜ื™", "dhcp-on-stop", "dhcp") ืฉื‘ื”ื systemd-networkd ืฆืจื™ืš ืœื ืœื’ืขืช ื‘ื—ื™ื‘ื•ืจื™ื ืงื™ื™ืžื™ื ื‘ืขืช ื”ื”ืคืขืœื”;
  • ืคื’ื™ืขื•ืช ืชื•ืงื ื” CVE-2019-15718, ืฉื ื’ืจื ืขืงื‘ ื—ื•ืกืจ ื‘ืงืจืช ื’ื™ืฉื” ืœืžืžืฉืง D-Bus ื ืคืชืจื” ื‘ืžืขืจื›ืช. ื”ื‘ืขื™ื” ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ืœื‘ืฆืข ืคืขื•ืœื•ืช ื”ื–ืžื™ื ื•ืช ืจืง ืœืžื ื”ืœื™ ืžืขืจื›ืช, ื›ื’ื•ืŸ ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช DNS ื•ื”ืคื ื™ื™ืช ืฉืื™ืœืชื•ืช DNS ืœืฉืจืช ื ื•ื›ืœ;
  • ืคื’ื™ืขื•ืช ืชื•ืงื ื” CVE-2019-9619ืงืฉื•ืจ ืœืื™ ื”ืคืขืœืช pam_systemd ืขื‘ื•ืจ ื”ืคืขืœื•ืช ืœื ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ื•ืช, ืžื” ืฉืžืืคืฉืจ ื–ื™ื•ืฃ ืฉืœ ื”ืคื’ื™ืฉื” ื”ืคืขื™ืœื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”