ืžืขืจื›ืช systemd ื’ืจืกื” 246

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืžื ื”ืœ ื”ืžืขืจื›ืช ื‘ืžืงื•ื 246. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ื›ื•ืœืœืช ืชืžื™ื›ื” ื‘ื”ืงืคืืช ื™ื—ื™ื“ื•ืช, ื™ื›ื•ืœืช ืœืืžืช ืืช ืชืžื•ื ืช ื”ื“ื™ืกืง ื”ื‘ืกื™ืกื™ืช ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ืชืžื™ื›ื” ื‘ื“ื—ื™ืกืช ื™ื•ืžืŸ ื•-core dumps ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชื ZSTD, ื™ื›ื•ืœืช ืœืคืชื•ื— ืกืคืจื™ื•ืช ื‘ื™ืชื™ื•ืช ื ื™ื™ื“ื•ืช ื‘ืืžืฆืขื•ืช ืืกื™ืžื•ื ื™ FIDO2, ืชืžื™ื›ื” ื‘ืคืชื™ื—ืช ื ืขื™ืœื” ืฉืœ Microsoft BitLocker. ืžื—ื™ืฆื•ืช ื“ืจืš /etc/ crypttab, ื”ืฉื ื”ืฉื—ื•ืจื” ืฉื•ื ื” ืœ-DenyList.

ื”ืขื™ืงืจื™ ืฉื™ื ื•ื™ื™ื:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ื‘ืงืจ ื”ืžืฉืื‘ื™ื ื”ืžืงืคื™ื ื”ืžื‘ื•ืกืก ืขืœ cgroups v2, ืฉื‘ืืžืฆืขื•ืชื• ืืชื” ื™ื›ื•ืœ ืœืขืฆื•ืจ ืชื”ืœื™ื›ื™ื ื•ืœืคื ื•ืช ื–ืžื ื™ืช ืžืฉืื‘ื™ื ืžืกื•ื™ืžื™ื (CPU, I/O, ื•ืื•ืœื™ ืืคื™ืœื• ื–ื™ื›ืจื•ืŸ) ืœื‘ื™ืฆื•ืข ืžืฉื™ืžื•ืช ืื—ืจื•ืช. ื”ื”ืงืคืื” ื•ื”ื”ืคืฉืจื” ืฉืœ ื™ื—ื™ื“ื•ืช ื ืฉืœื˜ืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ื—ื“ืฉื” "systemctl freeze" ืื• ื‘ืืžืฆืขื•ืช D-Bus.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœืื™ืžื•ืช ืชืžื•ื ืช ื“ื™ืกืง ื”ืฉื•ืจืฉ ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช. ื”ืื™ืžื•ืช ืžืชื‘ืฆืข ื‘ืืžืฆืขื•ืช ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช ื‘ื™ื—ื™ื“ื•ืช ืฉื™ืจื•ืช: RootHash (hash root ืœืื™ืžื•ืช ืชืžื•ื ืช ื”ื“ื™ืกืง ืฉืฆื•ื™ื ื” ื“ืจืš ืืคืฉืจื•ืช RootImage) ื•-RootHashSignature (ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื‘ืคื•ืจืžื˜ PKCS#7 ืขื‘ื•ืจ ื”-Root hash).
  • ื”ืžื˜ืคืœ ื‘-PID 1 ืžื™ื™ืฉื ืืช ื”ื™ื›ื•ืœืช ืœื˜ืขื•ืŸ ืื•ื˜ื•ืžื˜ื™ืช ื›ืœืœื™ AppArmor ืฉื”ื•ื’ื“ืจื• ืžืจืืฉ (/etc/apparmor/earlypolicy) ื‘ืฉืœื‘ ื”ืืชื—ื•ืœ ื”ืจืืฉื•ื ื™.
  • ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ ืงื•ื‘ืฅ ื™ื—ื™ื“ื” ื ื•ืกืคื•: ConditionPathIsEncrypted ื•-AssertPathIsEncrypted ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ืžื™ืงื•ื ื”ื ืชื™ื‘ ืฉืฆื•ื™ืŸ ื‘ื”ืชืงืŸ ื‘ืœื•ืง ื”ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” (dm-crypt/LUKS), ConditionEnvironment ื•-AssertEnvironment ื›ื“ื™ ืœื‘ื“ื•ืง ืžืฉืชื ื™ ืกื‘ื™ื‘ื” (ืœื“ื•ื’ืžื”, ืืœื” ืฉื”ื•ื’ื“ืจื• ืขืœ ื™ื“ื™ PAM ืื• ื‘ืขืช ื”ืงืžืช ืžื›ื•ืœื•ืช).
  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช *.mount, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” ReadWriteOnly, ื”ืื•ืกืจืช ืขืœ ื”ืจื›ื‘ืช ืžื—ื™ืฆื” ื‘ืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“ ืื ืœื ื ื™ืชืŸ ื”ื™ื” ืœื”ืขืœื•ืช ืื•ืชื” ืœืงืจื™ืื” ื•ื›ืชื™ื‘ื”. ื‘ืžืฆื‘ /etc/fstab ืžืฆื‘ ื–ื” ืžื•ื’ื“ืจ ื‘ืืžืฆืขื•ืช ื”ืืคืฉืจื•ืช "x-systemd.rw-only".
  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช *.socket, ื ื•ืกืคื” ื”ื”ื’ื“ืจื” PassPacketInfo, ื”ืžืืคืฉืจืช ืœืœื™ื‘ื” ืœื”ื•ืกื™ืฃ ืžื˜ื ื ืชื•ื ื™ื ื ื•ืกืคื™ื ืขื‘ื•ืจ ื›ืœ ืžื ื” ืฉื ืงืจืืช ืžื”ืฉืงืข (ืžืืคืฉืจืช ืืช ืžืฆื‘ื™ IP_PKTINFO, IPV6_RECVPKTINFO ื•-NETLINK_PKTINFO ืขื‘ื•ืจ ื”ืฉืงืข).
  • ืขื‘ื•ืจ ืฉื™ืจื•ืชื™ื (*.service units), ืžื•ืฆืขื•ืช ื”ื’ื“ืจื•ืช CoredumpFilter (ืžื’ื“ื™ืจ ืงื˜ืขื™ ื–ื™ื›ืจื•ืŸ ืฉื™ืฉ ืœื›ืœื•ืœ ื‘-Dempings ื”ืœื™ื‘ื”) ื•
    TimeoutStartFailureMode/TimeoutStopFailureMode (ืžื’ื“ื™ืจ ืืช ืื•ืคืŸ ื”ืคืขื•ืœื” (SIGTERM, SIGABRT ืื• SIGKILL) ื›ืืฉืจ ืžืชืจื—ืฉ ืคืกืง ื–ืžืŸ ื‘ืขืช โ€‹โ€‹ื”ืคืขืœื” ืื• ืขืฆื™ืจื” ืฉืœ ืฉื™ืจื•ืช).

  • ืจื•ื‘ ื”ืืคืฉืจื•ื™ื•ืช ืชื•ืžื›ื•ืช ื›ืขืช ื‘ืขืจื›ื™ื ื”ืงืกื“ืฆื™ืžืœื™ื™ื ืฉืฆื•ื™ื ื• ื‘ืืžืฆืขื•ืช ื”ืงื™ื“ื•ืžืช "0x".
  • ื‘ืคืจืžื˜ืจื™ื ืฉื•ื ื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•ืงื‘ืฆื™ ืชืฆื•ืจื” ื”ืงืฉื•ืจื™ื ืœื”ื’ื“ืจืช ืžืคืชื—ื•ืช ืื• ืื™ืฉื•ืจื™ื, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืœืฉืงืขื™ ื™ื•ื ื™ืงืก (AF_UNIX) ืœื”ืขื‘ืจืช ืžืคืชื—ื•ืช ื•ืชืขื•ื“ื•ืช ื‘ืืžืฆืขื•ืช ืงืจื™ืื•ืช ืœืฉื™ืจื•ืชื™ IPC ื›ืืฉืจ ืœื ืจืฆื•ื™ ืœืžืงื ืื™ืฉื•ืจื™ื ืขืœ ื“ื™ืกืง ืœื ืžื•ืฆืคืŸ ืึดื—ืกื•ึผืŸ.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืฉื™ืฉื” ืžืคืจื˜ื™ื ื—ื“ืฉื™ื ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘ื™ื—ื™ื“ื•ืช, tmpfiles.d/, sysusers.d/ ื•ืงื•ื‘ืฆื™ ืชืฆื•ืจื” ืื—ืจื™ื: %a ืœื”ื—ืœืคืช ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ื ื•ื›ื—ื™ืช, %o/%w/%B/%W ืœื”ื—ืœืคืช ืฉื“ื•ืช ืขื ืžื–ื”ื™ื ืž-/etc/os-release ื•-%l ืœื”ื—ืœืคืช ืฉื ืžืืจื— ืงืฆืจ.
  • ืงื•ื‘ืฆื™ ื™ื—ื™ื“ื” ืื™ื ื ืชื•ืžื›ื™ื ืขื•ื“ ื‘ืชื—ื‘ื™ืจ ".include", ืฉื”ื•ืฆื ืžืฉื™ืžื•ืฉ ืœืคื ื™ 6 ืฉื ื™ื.
  • ื”ื’ื“ืจื•ืช StandardError ื•-StandardOutput ืื™ื ืŸ ืชื•ืžื›ื•ืช ืขื•ื“ ื‘ืขืจื›ื™ื "syslog" ื•-"syslog-console", ืืฉืจ ื™ื•ืžืจื• ืื•ื˜ื•ืžื˜ื™ืช ืœ-"journal" ื•-"journal+console".
  • ืขื‘ื•ืจ ื ืงื•ื“ื•ืช ื”ืจื›ื‘ื” ื”ืžื‘ื•ืกืกื•ืช ืขืœ tmpfs ืฉื ื•ืฆืจื• ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ (/tmp, /run, /dev/shm ื•ื›ื•'), ืžืกื•ืคืงื•ืช ื”ื’ื‘ืœื•ืช ืขืœ ื’ื•ื“ืœ ื•ืžืกืคืจ ื”ืื™ื ื•ื“ื™ื, ื”ืžืงื‘ื™ืœื•ืช ืœ-50% ืžื’ื•ื“ืœ ื”-RAM ืขื‘ื•ืจ /tmp ื•-/dev/ shm, ื•-10% ืž-RAM ืขื‘ื•ืจ ื›ืœ ื”ืฉืืจ.
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ื—ื“ืฉื•ืช ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืœื™ื‘ื”: systemd.hostname ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ืฉื ื”ืžืืจื— ื‘ืฉืœื‘ ื”ืืชื—ื•ืœ ื”ืจืืฉื•ื ื™, udev.blockdev_read_only ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ื›ืœ ื”ืชืงื ื™ ื”ื—ืกื™ืžื” ื”ืžืฉื•ื™ื›ื™ื ืœื›ื•ื ื ื™ื ืคื™ื–ื™ื™ื ืœืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“ (ืชื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” "blockdev --setrw" ื›ื“ื™ ื‘ื™ื˜ื•ืœ ืกืœืงื˜ื™ื‘ื™), systemd .swap ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ื”ืคืขืœื” ื”ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžื—ื™ืฆืช ื”ื”ื—ืœืคื”, systemd.clock-usec ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ืฉืขื•ืŸ ื”ืžืขืจื›ืช ื‘ืžื™ืงืจื•-ืฉื ื™ื•ืช, systemd.condition-needs-update ื•-systemd.condition-first-boot ื›ื“ื™ ืœืขืงื•ืฃ ืืช ConditionNeedsUpdate ื•-ConditionFirstBoot ื”ืžื—ืื•ืช.
  • ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, sysctl fs.suid_dumpable ืžื•ื’ื“ืจ ืœ-2 ("suidsafe"), ืžื” ืฉืžืืคืฉืจ ืฉืžื™ืจืช dump ื”ืœื™ื‘ื” ืขื‘ื•ืจ ืชื”ืœื™ื›ื™ื ืขื ื“ื’ืœ suid.
  • ื”ืงื•ื‘ืฅ /usr/lib/udev/hwdb.d/60-autosuspend.hwdb ื”ื•ืฉืืœ ืœืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ื”ื—ื•ืžืจื” ืž-ChromiumOS, ื”ื›ื•ืœืœ ืžื™ื“ืข ืขืœ ื”ืชืงื ื™ PCI ื•-USB ื”ืชื•ืžื›ื™ื ื‘ืžืฆื‘ ืฉื™ื ื” ืื•ื˜ื•ืžื˜ื™.
  • ื”ื’ื“ืจืช ManageForeignRoutes ื ื•ืกืคื” ืœ-networkd.conf, ื›ืืฉืจ ื”ื™ื ืžื•ืคืขืœืช, systemd-networkd ื™ืชื—ื™ืœ ืœื ื”ืœ ืืช ื›ืœ ื”ืžืกืœื•ืœื™ื ืฉื”ื•ื’ื“ืจื• ืขืœ ื™ื“ื™ ื›ืœื™ ืฉื™ืจื•ืช ืื—ืจื™ื.
  • ืงื˜ืข "[SR-IOV]" ื ื•ืกืฃ ืœืงื‘ืฆื™ โ€Ž.network ืขื‘ื•ืจ ื”ื’ื“ืจืช ื”ืชืงื ื™ ืจืฉืช ื”ืชื•ืžื›ื™ื ื‘-SR-IOV (ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ืฉืœ ืฉื•ืจืฉ ื™ื—ื™ื“ I/O).
  • ื‘-systemd-networkd, ื”ื”ื’ื“ืจื” IPv4AcceptLocal ื ื•ืกืคื” ืœืžืงื˜ืข "[ืจืฉืช]" ื›ื“ื™ ืœืืคืฉืจ ืงื‘ืœืช ืžื ื•ืช ื”ืžื’ื™ืขื•ืช ืขื ื›ืชื•ื‘ืช ืžืงื•ืจ ืžืงื•ืžื™ืช ื‘ืžืžืฉืง ื”ืจืฉืช.
  • systemd-networkd ื”ื•ืกื™ืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื“ื™ืกืฆื™ืคืœื™ื ื•ืช ืฉืœ ืชืขื“ื•ืฃ ืชืขื‘ื•ืจืช HTB ื‘ืืžืฆืขื•ืช [HierarchyTokenBucket] ื•
    [HierarchyTokenBucketClass], "pfifo" ื“ืจืš [PFIFO], "GRED" ื“ืจืš [GenericRandomEarlyDetection], "SFB" ื“ืจืš [StochasticFairBlue], "cake"
    ื“ืจืš [CAKE], "PIE" ื“ืจืš [PIE], "DRR" ื“ืจืš [DeficitRoundRobinScheduler] ื•
    [DeficitRoundRobinSchedulerClass], "BFIFO" ื“ืจืš [BFIFO],
    "PFIFOHeadDrop" ื“ืจืš [PFIFOHeadDrop], "PFIFOFast" ื“ืจืš [PFIFOFast], "HHF"
    ื“ืจืš [HeavyHitterFilter], "ETS" ื“ืจืš [EnhancedTransmissionSelection],
    "QFQ" ื“ืจืš [QuickFairQueueing] ื•-[QuickFairQueueingClass].

  • ื‘-systemd-networkd, ื ื•ืกืคื” ื”ื’ื“ืจืช UseGateway ืœืžืงื˜ืข [DHCPv4] ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ืฉื™ืžื•ืฉ ื‘ืžื™ื“ืข ืฉืขืจ ืฉื”ื•ืฉื’ ื‘ืืžืฆืขื•ืช DHCP.
  • ื‘-systemd-networkd, ื‘ืกืขื™ืคื™ื [DHCPv4] ื•-[DHCPServer], ื ื•ืกืคื” ื”ื’ื“ืจืช SendVendorOption ืœื”ืชืงื ื” ื•ืขื™ื‘ื•ื“ ืืคืฉืจื•ื™ื•ืช ืกืคืง ื ื•ืกืคื•ืช.
  • systemd-networkd ืžื™ื™ืฉืžืช ืงื‘ื•ืฆื” ื—ื“ืฉื” ืฉืœ ืืคืฉืจื•ื™ื•ืช EmitPOP3/POP3, EmitSMTP/SMTP ื•-EmitLPR/LPR ื‘ืกืขื™ืฃ [DHCPServer] ื›ื“ื™ ืœื”ื•ืกื™ืฃ ืžื™ื“ืข ืขืœ ืฉืจืชื™ POP3, SMTP ื•-LPR.
  • ื‘-systemd-networkd, ื‘ืงื‘ืฆื™ .netdev ื‘ืกืขื™ืฃ [ื’ืฉืจ], ื ื•ืกืคื” ื”ื’ื“ืจืช VLANProtocol ื›ื“ื™ ืœื‘ื—ื•ืจ ืืช ืคืจื•ื˜ื•ืงื•ืœ ื”-VLAN ืœืฉื™ืžื•ืฉ.
  • ื‘-systemd-networkd, ื‘ืงื‘ืฆื™ .network ื‘ืงื˜ืข [ืงื™ืฉื•ืจ], ื”ื’ื“ืจืช ื”ืงื‘ื•ืฆื” ืžื™ื•ืฉืžืช ืœื ื™ื”ื•ืœ ืงื‘ื•ืฆืช ืงื™ืฉื•ืจื™ื.
  • ื”ื’ื“ืจื•ืช ื”ืจืฉื™ืžื” ื”ืฉื—ื•ืจื” ืฉื•ื ื• ืœ-DenyList (ืฉืžื™ืจื” ืขืœ ื˜ื™ืคื•ืœ ื‘ืฉืžื•ืช ื™ืฉื ื™ื ืœืฆื•ืจืš ืชืื™ืžื•ืช ืœืื—ื•ืจ).
  • Systemd-networkd ื”ื•ืกื™ืคื” ื—ืœืง ื’ื“ื•ืœ ืžื”ื”ื’ื“ืจื•ืช ื”ืงืฉื•ืจื•ืช ืœ-IPv6 ื•-DHCPv6.
  • ื ื•ืกืคื” ืคืงื•ื“ืช "forcerenew" ืœ-networkctl ื›ื“ื™ ืœืืœืฅ ืืช ื›ืœ ื›ืจื™ื›ื•ืช ื”ื›ืชื•ื‘ื•ืช ืœื”ืชืขื“ื›ืŸ (ื—ื›ื™ืจื”).
  • ื‘-systemd-resolved, ื‘ืชืฆื•ืจืช DNS, ื ื™ืชืŸ ื”ื™ื” ืœืฆื™ื™ืŸ ืืช ืžืกืคืจ ื”ื™ืฆื™ืื” ื•ืฉื ื”ืžืืจื— ืขื‘ื•ืจ ืื™ืžื•ืช ืื™ืฉื•ืจ DNS-over-TLS. ื™ื™ืฉื•ื DNS-over-TLS ื”ื•ืกื™ืฃ ืชืžื™ื›ื” ืœื‘ื“ื™ืงืช SNI.
  • ืœ-Systemd-resolved ื™ืฉ ื›ืขืช ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืฉืœ ืฉืžื•ืช DNS ื‘ืชื•ื•ื™ืช ืื—ืช (ืชื•ื•ื™ืช ืื—ืช, ืžืฉื ืžืืจื— ืื—ื“).
  • systemd-journald ืžืกืคืง ืชืžื™ื›ื” ืœืฉื™ืžื•ืฉ ื‘ืืœื’ื•ืจื™ืชื zstd ืœื“ื—ื™ืกืช ืฉื“ื•ืช ื’ื“ื•ืœื™ื ื‘ื™ื•ืžื ื™ื. ื ืขืฉืชื” ืขื‘ื•ื“ื” ืœื”ื’ื ื” ืžืคื ื™ ื”ืชื ื’ืฉื•ื™ื•ืช ื‘ื˜ื‘ืœืื•ืช ื’ื™ื‘ื•ื‘ ื”ืžืฉืžืฉื•ืช ื‘ื™ื•ืžื ื™ื.
  • ื›ืชื•ื‘ื•ืช URL ื”ื ื™ืชื ื•ืช ืœืœื—ื™ืฆื” ืขื ืงื™ืฉื•ืจื™ื ืœืชื™ืขื•ื“ ื ื•ืกืคื• ืœ-journalctl ื‘ืขืช ื”ืฆื’ืช ื”ื•ื“ืขื•ืช ื™ื•ืžืŸ.
  • ื ื•ืกืคื” ื”ื’ื“ืจืช Audit ืœ-journald.conf ื›ื“ื™ ืœืงื‘ื•ืข ืื ื”ื‘ื™ืงื•ืจืช ืžื•ืคืขืœืช ื‘ืžื”ืœืš ืืชื—ื•ืœ ืฉืœ systemd-journald.
  • ืœ-Systemd-coredump ื™ืฉ ื›ืขืช ืืช ื”ื™ื›ื•ืœืช ืœื“ื—ื•ืก dump ื”ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช ื”ืืœื’ื•ืจื™ืชื zstd.
  • ื ื•ืกืคื” ื”ื’ื“ืจืช UUID ืœ-systemd-repart ื›ื“ื™ ืœื”ืงืฆื•ืช UUID ืœืžื—ื™ืฆื” ืฉื ื•ืฆืจื”.
  • ื”ืฉื™ืจื•ืช systemd-homed, ื”ืžืกืคืง ื ื™ื”ื•ืœ ืฉืœ ืกืคืจื™ื•ืช ื‘ื™ืชื™ื•ืช ื ื™ื™ื“ื•ืช, ื”ื•ืกื™ืฃ ืืช ื”ื™ื›ื•ืœืช ืœืคืชื•ื— ืกืคืจื™ื•ืช ื‘ื™ืชื™ื•ืช ื‘ืืžืฆืขื•ืช ืืกื™ืžื•ื ื™ FIDO2. ื”ืงืฆื” ื”ืื—ื•ืจื™ ืฉืœ ื”ืฆืคื ืช ืžื—ื™ืฆื•ืช LUKS ื”ื•ืกื™ืฃ ืชืžื™ื›ื” ืœื”ื—ื–ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ื‘ืœื•ืงื™ื ืจื™ืงื™ื ืฉืœ ืžืขืจื›ืช ืงื‘ืฆื™ื ื›ืืฉืจ ื”ืคืขืœื” ืžืกืชื™ื™ืžืช. ื ื•ืกืคื” ื”ื’ื ื” ืžืคื ื™ ื”ืฆืคื ื” ื›ืคื•ืœื” ืฉืœ ื ืชื•ื ื™ื ืื ื ืงื‘ืข ืฉืžื—ื™ืฆืช /home ื‘ืžืขืจื›ืช ื›ื‘ืจ ืžื•ืฆืคื ืช.
  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ืœ-/etc/crypttab: "keyfile-erase" ื›ื“ื™ ืœืžื—ื•ืง ืžืคืชื— ืœืื—ืจ ื”ืฉื™ืžื•ืฉ ื•-"try-empty-password" ื›ื“ื™ ืœื ืกื•ืช ืœืคืชื•ื— ืžื—ื™ืฆื” ืขื ืกื™ืกืžื” ืจื™ืงื” ืœืคื ื™ ื‘ืงืฉืช ื”ืžืฉืชืžืฉ ืœื”ื–ื™ืŸ ืกื™ืกืžื” (ืฉื™ืžื•ืฉื™ ืœื”ืชืงื ืช ืชืžื•ื ื•ืช ืžื•ืฆืคื ื•ืช ืขื ืกื™ืกืžื” ืฉื”ื•ืงืฆืชื” ืœืื—ืจ ื”ืืชื—ื•ืœ ื”ืจืืฉื•ืŸ, ืœื ื‘ืžื”ืœืš ื”ื”ืชืงื ื”).
  • systemd-cryptsetup ืžื•ืกื™ืฃ ืชืžื™ื›ื” ืœืคืชื™ื—ืช ืžื—ื™ืฆื•ืช BitLocker ืฉืœ Microsoft ื‘ื–ืžืŸ ื”ืืชื—ื•ืœ ื‘ืืžืฆืขื•ืช /etc/crypttab. ื ื•ืกืคื” ื’ื ื™ื›ื•ืœืช ืงืจื™ืื”
    ืžืคืชื—ื•ืช ืœื‘ื™ื˜ื•ืœ ื ืขื™ืœื” ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืžื—ื™ืฆื•ืช ืžื”ืงื‘ืฆื™ื /etc/cryptsetup-keys.d/ .key ื•-/run/cryptsetup-keys.d/ .ืžึทืคึฐืชึตื—ึท.

  • ื ื•ืกืฃ systemd-xdg-autostart-generator ืœื™ืฆื™ืจืช ืงื‘ืฆื™ ื™ื—ื™ื“ื” ืžืงื•ื‘ืฆื™ .desktop autostart.
  • ื ื•ืกืคื” ืคืงื•ื“ืช "ืืชื—ื•ืœ-ืœืงื•ืฉื—ื”" ืœ-"bootctl".
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืœ-systemd-firstboot: "--image" ื›ื“ื™ ืœืฆื™ื™ืŸ ืืช ืชืžื•ื ืช ื”ื“ื™ืกืง ืœืืชื—ื•ืœ, "--kernel-command-line" ื›ื“ื™ ืœืืชื—ืœ ืืช ื”ืงื•ื‘ืฅ /etc/kernel/cmdline, "--root-password-hashed" ื›ื“ื™ ืฆื™ื™ืŸ ืืช ืกื™ืกืžืช ื”ื‘ืกื™ืก, ื•ืืช "--delete-root-password" ื›ื“ื™ ืœืžื—ื•ืง ืืช ืกื™ืกืžืช ื”ืฉื•ืจืฉ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”