ืžืขืจื›ืช systemd ื’ืจืกื” 248

ืœืื—ืจ ืืจื‘ืขื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ืžื•ืฆื’ืช ื”ืžื”ื“ื•ืจื” ืฉืœ ืžืขืจื›ืช ืžื ื”ืœ ืžืขืจื›ืช systemd 248. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžืกืคืงืช ืชืžื™ื›ื” ื‘ืชืžื•ื ื•ืช ืœื”ืจื—ื‘ืช ืกืคืจื™ื•ืช ืžืขืจื›ืช, ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” /etc/veritytab, ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-cryptenroll, ืคืชื™ื—ืช ื ืขื™ืœื” ืฉืœ LUKS2 ื‘ืืžืฆืขื•ืช ืฉื‘ื‘ื™ TPM2 ื•-FIDO2 ืืกื™ืžื•ื ื™ื, ื”ืคืขืœืช ื™ื—ื™ื“ื•ืช ื‘ืžืจื—ื‘ ืžื–ื”ื” IPC ืžื‘ื•ื“ื“, ืคืจื•ื˜ื•ืงื•ืœ BATMAN ืขื‘ื•ืจ ืจืฉืชื•ืช ืจืฉืช, nftables backend ืขื‘ื•ืจ systemd-nspawn. Systemd-oomd ื”ืชื™ื™ืฆื‘ื”.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ื”ืžื•ืฉื’ ืฉืœ ืชืžื•ื ื•ืช ื”ืจื—ื‘ืช ืžืขืจื›ืช ื™ื•ืฉื, ืืฉืจ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ื›ื“ื™ ืœื”ืจื—ื™ื‘ ืืช ื”ื”ื™ืจืจื›ื™ื” ืฉืœ ืกืคืจื™ื•ืช /usr/ ื•-/opt/, ื•ืœื”ื•ืกื™ืฃ ืงื‘ืฆื™ื ื ื•ืกืคื™ื ื‘ื–ืžืŸ ืจื™ืฆื”, ื’ื ืื ื”ืกืคืจื™ื•ืช ืฉืฆื•ื™ื ื• ืžื•ืชืงื ื•ืช ืœืงืจื™ืื” ื‘ืœื‘ื“. ื›ืืฉืจ ืžื•ืชืงื ืช ืชืžื•ื ืช ื”ืจื—ื‘ืช ืžืขืจื›ืช, ื”ืชื•ื›ืŸ ืฉืœื” ืžื•ื ื— ืขืœ ื”ื”ื™ืจืจื›ื™ื” /usr/ ื•-/opt/ ื‘ืืžืฆืขื•ืช OverlayFS.

    ื›ืœื™ ืขื–ืจ ื—ื“ืฉ, systemd-sysext, ื”ื•ืฆืข ืœื—ื™ื‘ื•ืจ, ื ื™ืชื•ืง, ื”ืฆื’ื” ื•ืขื“ื›ื•ืŸ ืฉืœ ืชืžื•ื ื•ืช ืฉืœ ื”ืจื—ื‘ื•ืช ืžืขืจื›ืช. ื›ื“ื™ ืœื—ื‘ืจ ืื•ื˜ื•ืžื˜ื™ืช ืชืžื•ื ื•ืช ืฉื›ื‘ืจ ืžื•ืชืงื ื•ืช ื‘ืžื”ืœืš ื”ืืชื—ื•ืœ, ืฉื™ืจื•ืช systemd-sysext.service ื ื•ืกืฃ. ืคืจืžื˜ืจ "SYSEXT_LEVEL=" ื ื•ืกืฃ ืœืงื•ื‘ืฅ OS-release ื›ื“ื™ ืœืงื‘ื•ืข ืืช ืจืžืช ื”ืจื—ื‘ื•ืช ื”ืžืขืจื›ืช ื”ื ืชืžื›ื•ืช.

  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช, ื”ื•ื˜ืžืขื” ื”ื”ื’ื“ืจื” ExtensionImages, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืงืฉืจ ืชืžื•ื ื•ืช ืฉืœ ื”ืจื—ื‘ื•ืช ืžืขืจื›ืช ืœื”ื™ืจืจื›ื™ื™ืช ืžืจื—ื‘ ื”ืฉืžื•ืช ืฉืœ FS ืฉืœ ืฉื™ืจื•ืชื™ื ื‘ื•ื“ื“ื™ื ืžื‘ื•ื“ื“ื™ื.
  • ื ื•ืกืฃ ืงื•ื‘ืฅ ืชืฆื•ืจื” /etc/veritytab ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืื™ืžื•ืช ื ืชื•ื ื™ื ื‘ืจืžืช ื”ื‘ืœื•ืง ื‘ืืžืฆืขื•ืช ืžื•ื“ื•ืœ dm-verity. ืคื•ืจืžื˜ ื”ืงื•ื‘ืฅ ื“ื•ืžื” ืœ-/etc/crypttab - "Section_name device_for_data device_for_hashes check_hash_root options." ื ื•ืกืคื” ืืคืฉืจื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืœื™ื‘ื” systemd.verity.root_options ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื”ืชื ื”ื’ื•ืช dm-verity ืขื‘ื•ืจ ื”ืชืงืŸ ื”ืฉื•ืจืฉ.
  • systemd-cryptsetup ืžื•ืกื™ืฃ ืืช ื”ื™ื›ื•ืœืช ืœื—ืœืฅ ืืช URI ื”ืืกื™ืžื•ืŸ PKCS#11 ื•ื”ืžืคืชื— ื”ืžื•ืฆืคืŸ ืžื›ื•ืชืจืช ื”ืžื˜ื-ื ืชื•ื ื™ื ืฉืœ LUKS2 ื‘ืคื•ืจืžื˜ JSON, ืžื” ืฉืžืืคืฉืจ ืœืฉืœื‘ ืžื™ื“ืข ืขืœ ืคืชื™ื—ืช ื”ืชืงืŸ ืžื•ืฆืคืŸ ื‘ืžื›ืฉื™ืจ ืขืฆืžื• ืžื‘ืœื™ ืœืขืจื‘ ืงื‘ืฆื™ื ื—ื™ืฆื•ื ื™ื™ื.
  • systemd-cryptsetup ืžืกืคืง ืชืžื™ื›ื” ืœืคืชื™ื—ืช ืžื—ื™ืฆื•ืช ืžื•ืฆืคื ื•ืช LUKS2 ื‘ืืžืฆืขื•ืช ืฉื‘ื‘ื™ TPM2 ื•ืืกื™ืžื•ื ื™ FIDO2, ื‘ื ื•ืกืฃ ืœืืกื™ืžื•ื ื™ PKCS#11 ืฉื ืชืžื›ื• ื‘ืขื‘ืจ. ื˜ืขื™ื ืช libfido2 ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช dlopen(), ื›ืœื•ืžืจ. ื”ื–ืžื™ื ื•ืช ื ื‘ื“ืงืช ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”, ื•ืœื ื›ืชืœื•ืช ืงืฉื™ื—ื”.
  • ืืคืฉืจื•ื™ื•ืช ื—ื“ืฉื•ืช "no-write-workqueue" ื•-"no-read-workqueue" ื ื•ืกืคื• ืœ-/etc/crypttab ืขื‘ื•ืจ systemd-cryptsetup ื›ื“ื™ ืœืืคืฉืจ ืขื™ื‘ื•ื“ ืกื™ื ื›ืจื•ื ื™ ืฉืœ ืงืœื˜/ืคืœื˜ ื”ืžืฉื•ื™ืš ืœื”ืฆืคื ื” ื•ืคืขื ื•ื—.
  • ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-repart ื”ื•ืกื™ืฃ ืืช ื”ื™ื›ื•ืœืช ืœื”ืคืขื™ืœ ืžื—ื™ืฆื•ืช ืžื•ืฆืคื ื•ืช ื‘ืืžืฆืขื•ืช ืฉื‘ื‘ื™ TPM2, ืœืžืฉืœ, ื›ื“ื™ ืœื™ืฆื•ืจ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช /var ื‘ืืชื—ื•ืœ ื”ืจืืฉื•ืŸ.
  • ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-cryptenroll ื”ืชื•ื•ืกืฃ ื›ื“ื™ ืœืื’ื“ ืืกื™ืžื•ื ื™ TPM2, FIDO2 ื•-PKCS#11 ืœืžื—ื™ืฆื•ืช LUKS, ื›ืžื• ื’ื ื›ื“ื™ ืœื‘ื˜ืœ ื”ืฆืžื“ื” ื•ื”ืฆื’ื” ืฉืœ ืืกื™ืžื•ื ื™ื, ืœืื’ื“ ืžืคืชื—ื•ืช ื—ื™ืœื•ืฃ ื•ืœื”ื’ื“ื™ืจ ืกื™ืกืžื” ืœื’ื™ืฉื”.
  • ื”ื•ืกื™ืฃ ืืช ื”ืคืจืžื˜ืจ PrivateIPC, ื”ืžืืคืฉืจ ืœืš ืœื”ื’ื“ื™ืจ ืืช ืงื•ื‘ืฅ ื”ื™ื—ื™ื“ื” ืœื”ืคืขื™ืœ ืชื”ืœื™ื›ื™ื ื‘ืžืจื—ื‘ IPC ืžื‘ื•ื“ื“ ืขื ืžื–ื”ื™ื ื ืคืจื“ื™ื ื•ืชื•ืจ ื”ื•ื“ืขื•ืช ื ืคืจื“ื™ื. ื›ื“ื™ ืœื—ื‘ืจ ื™ื—ื™ื“ื” ืœืžืจื—ื‘ ืžื–ื”ื” IPC ืฉื›ื‘ืจ ื ื•ืฆืจ, ืžื•ืฆืขืช ื”ืืคืฉืจื•ืช IPCNamespacePath.
  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ExecPaths ื•-NoExecPaths ื›ื“ื™ ืœืืคืฉืจ ื”ื—ืœืช ื“ื’ืœ noexec ืขืœ ื—ืœืงื™ื ืกืคืฆื™ืคื™ื™ื ืฉืœ ืžืขืจื›ืช ื”ืงื‘ืฆื™ื.
  • systemd-networkd ืžื•ืกื™ืคื” ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืจืฉืช BATMAN (Better Approach To Mobile Adhoc Networking), ื”ืžืืคืฉืจ ื™ืฆื™ืจืช ืจืฉืชื•ืช ืžื‘ื•ื–ืจื•ืช ื‘ื”ืŸ ื›ืœ ืฆื•ืžืช ืžื—ื•ื‘ืจ ื“ืจืš ืฆืžืชื™ื ืฉื›ื ื™ื. ืขื‘ื•ืจ ืชืฆื•ืจื”, ืžื•ืฆืขื™ื ื”ืกืขื™ืฃ [BatmanAdvanced] ื‘-.netdev, ื”ืคืจืžื˜ืจ BatmanAdvanced ื‘ืงื‘ืฆื™ .network ื•ืกื•ื’ ื”ืชืงืŸ ื—ื“ืฉ "batadv".
  • ื”ื™ื™ืฉื•ื ืฉืœ ืžื ื’ื ื•ืŸ ื”ืชื’ื•ื‘ื” ื”ืžื•ืงื“ืžืช ืœื–ื™ื›ืจื•ืŸ ื ืžื•ืš ื‘ืžืขืจื›ืช systemd-oomd ื™ื•ืฆื‘. ื ื•ืกืคื” ืืคืฉืจื•ืช DefaultMemoryPressureDurationSec ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื–ืžืŸ ื”ื”ืžืชื ื” ืœืฉื—ืจื•ืจ ืžืฉืื‘ ืœืคื ื™ ื”ืฉืคืขืชื• ืขืœ ื™ื—ื™ื“ื”. Systemd-oomd ืžืฉืชืžืฉืช ื‘ืชืช ืžืขืจื›ืช ื”ืงืจื ืœ PSI (Pressure Stall Information) ื•ืžืืคืฉืจืช ืœื–ื”ื•ืช ื”ื•ืคืขืช ืขื™ื›ื•ื‘ื™ื ืขืงื‘ ืžื—ืกื•ืจ ื‘ืžืฉืื‘ื™ื ื•ืœืกื™ื™ื ื‘ืื•ืคืŸ ืกืœืงื˜ื™ื‘ื™ ืชื”ืœื™ื›ื™ื ืขืชื™ืจื™ ืžืฉืื‘ื™ื ื‘ืฉืœื‘ ื‘ื• ื”ืžืขืจื›ืช ืขื“ื™ื™ืŸ ืœื ื‘ืžืฆื‘ ืงืจื™ื˜ื™ ื•ืื™ื ื” ืœื”ืชื—ื™ืœ ืœื—ืชื•ืš ื‘ืื•ืคืŸ ืื™ื ื˜ื ืกื™ื‘ื™ ืืช ื”ืžื˜ืžื•ืŸ ื•ืœืขืงื•ืฃ ื ืชื•ื ื™ื ืœืžื—ื™ืฆืช ื”ื—ืœืคื”.
  • ื ื•ืกืฃ ืคืจืžื˜ืจ ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืงืจื ืœ "root=tmpfs", ื”ืžืืคืฉืจ ืœืš ืœืขืœื•ืช ืืช ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ื‘ืื—ืกื•ืŸ ื–ืžื ื™ ื”ืžืžื•ืงื ื‘-RAM ื‘ืืžืฆืขื•ืช Tmpfs.
  • ื”ืคืจืžื˜ืจ /etc/crypttab ื”ืžืฆื™ื™ืŸ ืืช ืงื•ื‘ืฅ ื”ืžืคืชื— ื™ื›ื•ืœ ื›ืขืช ืœื”ืฆื‘ื™ืข ืขืœ ืกื•ื’ื™ ืฉืงืขื™ื AF_UNIX ื•-SOCK_STREAM. ื‘ืžืงืจื” ื–ื”, ื™ืฉ ืœืชืช ืืช ื”ืžืคืชื— ื‘ืขืช ื”ื—ื™ื‘ื•ืจ ืœืฉืงืข, ืฉื‘ืืžืฆืขื•ืชื•, ืœืžืฉืœ, ื ื™ืชืŸ ืœื™ืฆื•ืจ ืฉื™ืจื•ืชื™ื ื”ืžื ืคื™ืงื™ื ืžืคืชื—ื•ืช ื‘ืื•ืคืŸ ื“ื™ื ืžื™.
  • ื›ืขืช ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ืฉื ื”ืžืืจื— ื”ื—ืœื•ืคื™ ืœืฉื™ืžื•ืฉ ืžื ื”ืœ ื”ืžืขืจื›ืช ื•-systemd-hostnamed ื‘ืฉืชื™ ื“ืจื›ื™ื: ื“ืจืš ื”ืคืจืžื˜ืจ DEFAULT_HOSTNAME ื‘-os-release ื•ื“ืจืš ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $SYSTEMD_DEFAULT_HOSTNAME. systemd-hostnamed ืžื˜ืคืœ ื’ื ื‘-"localhost" ื‘ืฉื ื”ืžืืจื— ื•ืžื•ืกื™ืฃ ืืช ื”ื™ื›ื•ืœืช ืœื™ื™ืฆื ืืช ืฉื ื”ืžืืจื— ื•ื›ืŸ ืืช ื”ืžืืคื™ื™ื ื™ื "HardwareVendor" ื•-"HardwareModel" ื‘ืืžืฆืขื•ืช DBus.
  • ื›ืขืช ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ื”ื‘ืœื•ืง ืขื ืžืฉืชื ื™ ืกื‘ื™ื‘ื” ื—ืฉื•ืคื™ื ื“ืจืš ื”ืืคืฉืจื•ืช ื”ื—ื“ืฉื” ManagerEnvironment ื‘-system.conf ืื• user.conf, ื•ืœื ืจืง ื“ืจืš ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืœื™ื‘ื” ื•ื”ื’ื“ืจื•ืช ืงื•ื‘ืฅ ื”ื™ื—ื™ื“ื”.
  • ื‘ื–ืžืŸ ื”ืงื•ืžืคื™ืœืฆื™ื”, ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืงืจื™ืื” ืœืžืขืจื›ืช fexecve() ื›ื“ื™ ืœื”ืชื—ื™ืœ ืชื”ืœื™ื›ื™ื ื‘ืžืงื•ื execve() ื›ื“ื™ ืœืฆืžืฆื ืืช ื”ื”ืฉื”ื™ื” ื‘ื™ืŸ ื‘ื“ื™ืงืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ืœื”ื—ืœืชื•.
  • ืขื‘ื•ืจ ืงื‘ืฆื™ ื™ื—ื™ื“ื”, ื ื•ืกืคื• ืคืขื•ืœื•ืช ืžื•ืชื ื•ืช ื—ื“ืฉื•ืช ConditionSecurity=tpm2 ื•-ConditionCPUFeature ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื ื•ื›ื—ื•ืชื ืฉืœ ื”ืชืงื ื™ TPM2 ื•ื™ื›ื•ืœื•ืช CPU ื‘ื•ื“ื“ื•ืช (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-ConditionCPUFeature=rdrand ื›ื“ื™ ืœื‘ื“ื•ืง ืื ื”ืžืขื‘ื“ ืชื•ืžืš ื‘ืคืขื•ืœืช RDRAND).
  • ืขื‘ื•ืจ ื’ืจืขื™ื ื™ื ื–ืžื™ื ื™ื, ื”ื•ื˜ืžืข ื™ืฆื™ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ื˜ื‘ืœืื•ืช ืงืจื™ืื•ืช ืžืขืจื›ืช ืขื‘ื•ืจ ืžืกื ื ื™ seccomp.
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื—ืœื™ืฃ ืจื›ื™ื‘ื™ ื—ื™ื‘ื•ืจ ื—ื“ืฉื™ื ืœืžืจื—ื‘ื™ ืฉืžื•ืช ืงื™ื™ืžื™ื ืฉืœ ืฉื™ืจื•ืชื™ื, ืžื‘ืœื™ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ื”ืฉื™ืจื•ืชื™ื. ื”ื”ื—ืœืคื” ืžืชื‘ืฆืขืช ืขื ื”ืคืงื•ื“ื•ืช 'systemctl bind ...' ื•-'systemctl mount-image โ€ฆ'.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœืฆื™ื•ืŸ ื ืชื™ื‘ื™ื ื‘ื”ื’ื“ืจื•ืช StandardOutput ื•-StandardError ื‘ืฆื•ืจื” "ืงื˜ื•ืข: ยป ืœื ื™ืงื•ื™ ืœืคื ื™ ื”ืฉื™ืžื•ืฉ.
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ืœื”ืคืขืœื” ืฉืœ ืžืฉืชืžืฉ ืžืกื•ื™ื ื‘ืชื•ืš ืงื•ื ื˜ื™ื™ื ืจ ืžืงื•ืžื™ ืœ-sd-bus. ืœื“ื•ื’ืžื” "systemctl -user -M lennart@ start quux".
  • ื”ืคืจืžื˜ืจื™ื ื”ื‘ืื™ื ืžื™ื•ืฉืžื™ื ื‘ืงื‘ืฆื™ systemd.link ื‘ืงื˜ืข [ืงื™ืฉื•ืจ]:
    • ืžื•ืคืงืจ - ืžืืคืฉืจ ืœืš ืœื”ืขื‘ื™ืจ ืืช ื”ืžื›ืฉื™ืจ ืœืžืฆื‘ "ืžื•ืคืงืจ" ื›ื“ื™ ืœืขื‘ื“ ืืช ื›ืœ ืžื ื•ืช ื”ืจืฉืช, ื›ื•ืœืœ ืืœื” ืฉืื™ื ืŸ ืžืžื•ืขื ื•ืช ืœืžืขืจื›ืช ื”ื ื•ื›ื—ื™ืช;
    • TransmitQueues ื•-ReeiveQueues ืœื”ื’ื“ืจืช ืžืกืคืจ ืชื•ืจื™ TX ื•-RX;
    • TransmitQueueLength ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื’ื•ื“ืœ ืชื•ืจ ื”-TX; GenericSegmentOffloadMaxBytes ื•-GenericSegmentOffloadMaxSegment ืœืงื‘ื™ืขืช ืžื’ื‘ืœื•ืช ืœืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช GRO (Generic Receive Offload).
  • ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช ื ื•ืกืคื• ืœืงื‘ืฆื™ systemd.network:
    • [ืจืฉืช] RouteTable ืœื‘ื—ื™ืจืช ื˜ื‘ืœืช ื ื™ืชื•ื‘;
    • [RoutingPolicyRule] ื”ืงืœื“ ืขื‘ื•ืจ ืกื•ื’ ื”ื ื™ืชื•ื‘ ("ื—ื•ืจ ืฉื—ื•ืจ, "ืœื ื ื™ืชืŸ ืœื”ื’ื™ืข", "ืœืืกื•ืจ");
    • [IPv6AcceptRA] RouteDenyList ื•-RouteAllowList ืœืจืฉื™ืžื•ืช ืฉืœ ืคืจืกื•ืžื•ืช ืžืกืœื•ืœื™ื ืžื•ืชืจื™ื ื•ื“ื—ื•ื™ื™ื;
    • [DHCPv6] ื”ืฉืชืžืฉ ื‘ื›ืชื•ื‘ื•ืช ื›ื“ื™ ืœื”ืชืขืœื ืžื”ื›ืชื•ื‘ืช ืฉื”ื•ื ืคืงื” ืขืœ ื™ื“ื™ DHCP;
    • [DHCPv6PrefixDelegation] ManageTemporaryAddress;
    • ActivationPolicy ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ืžื“ื™ื ื™ื•ืช ืœื’ื‘ื™ ืคืขื™ืœื•ืช ื”ืžืžืฉืง (ืฉืžื•ืจ ืชืžื™ื“ ื‘ืžืฆื‘ UP ืื• DOWN ืื• ืœืืคืฉืจ ืœืžืฉืชืžืฉ ืœืฉื ื•ืช ืžืฆื‘ื™ื ืขื ื”ืคืงื•ื“ื” "ip link set dev").
  • ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช ืคืจื•ื˜ื•ืงื•ืœ [VLAN], IngressQOSMaps, EgressQOSMaps ื•-[MACVLAN] BroadcastMulticastQueueLength ืœืงื‘ืฆื™ systemd.netdev ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืขื™ื‘ื•ื“ ืžื ื•ืช VLAN.
  • ื”ืคืกื™ืง ืœื”ืขืœื•ืช ืืช ืกืคืจื™ื™ืช /dev/ ื‘ืžืฆื‘ noexec ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ื’ื•ืจืžืช ืœื”ืชื ื’ืฉื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื“ื’ืœ ื”ื”ืคืขืœื” ืขื ืงื‘ืฆื™ /dev/sgx. ื›ื“ื™ ืœื”ื—ื–ื™ืจ ืืช ื”ื”ืชื ื”ื’ื•ืช ื”ื™ืฉื ื”, โ€‹โ€‹ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื”ื’ื“ืจื” NoExecPaths=/dev.
  • ื”ืจืฉืื•ืช ื”ืงื•ื‘ืฅ /dev/vsock ืฉื•ื ื• ืœ-0o666, ื•ื”ืงื‘ืฆื™ื /dev/vhost-vsock ื•-/dev/vhost-net ื”ื•ืขื‘ืจื• ืœืงื‘ื•ืฆืช kvm.
  • ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ืžื–ื”ื™ ื”ื—ื•ืžืจื” ื”ื•ืจื—ื‘ ืขื ืงื•ืจืื™ ื˜ื‘ื™ืขื•ืช ืืฆื‘ืข ืžืกื•ื’ USB ื”ืชื•ืžื›ื™ื ื‘ืฆื•ืจื” ื ื›ื•ื ื” ื‘ืžืฆื‘ ืฉื™ื ื”.
  • ืชืžื™ื›ื” ื ื•ืกืคืช ื‘ืคืชืจื•ืŸ systemd ืœื”ื ืคืงืช ืชื’ื•ื‘ื•ืช ืœืฉืื™ืœืชื•ืช DNSSEC ื‘ืืžืฆืขื•ืช ืคื•ืชืจ ืกืชื™ืžื•ืช. ืœืงื•ื—ื•ืช ืžืงื•ืžื™ื™ื ื™ื›ื•ืœื™ื ืœื‘ืฆืข ืื™ืžื•ืช DNSSEC ืขืœ ืขืฆืžื, ื‘ืขื•ื“ ืฉืœืงื•ื—ื•ืช ื—ื™ืฆื•ื ื™ื™ื ืžื•ืขื‘ืจื™ื ืœืœื ืฉื™ื ื•ื™ ืœืฉืจืช ื”-DNS ื”ืื‘.
  • ื”ื•ืกื™ืคื” ืืช ื”ืืคืฉืจื•ืช CacheFromLocalhost ืœ-resolved.conf, ื›ืืฉืจ ื”ื™ื ืžื•ื’ื“ืจืช, systemd-resolved ื™ืฉืชืžืฉ ื‘ืžื˜ืžื•ืŸ ื’ื ืขื‘ื•ืจ ืงืจื™ืื•ืช ืœืฉืจืช ื”-DNS ื‘-127.0.0.1 (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืฉืžื™ืจื” ื‘ืžื˜ืžื•ืŸ ืฉืœ ื‘ืงืฉื•ืช ื›ืืœื” ืžื•ืฉื‘ืชืช ื›ื“ื™ ืœืžื ื•ืข ืฉืžื™ืจื” ื›ืคื•ืœื” ื‘ืžื˜ืžื•ืŸ).
  • systemd-resolved ืžื•ืกื™ืฃ ืชืžื™ื›ื” ืขื‘ื•ืจ RFC-5001 NSIDs ื‘ืคื•ืชืจ ื”-DNS ื”ืžืงื•ืžื™, ื•ืžืืคืฉืจ ืœืœืงื•ื—ื•ืช ืœื”ื‘ื“ื™ืœ ื‘ื™ืŸ ืื™ื ื˜ืจืืงืฆื™ื•ืช ืขื ื”ืคื•ืชืจ ื”ืžืงื•ืžื™ ืœื‘ื™ืŸ ืฉืจืช DNS ืื—ืจ.
  • ื›ืœื™ ื”ืฉื™ืจื•ืช resolvectl ืžื™ื™ืฉื ืืช ื”ื™ื›ื•ืœืช ืœื”ืฆื™ื’ ืžื™ื“ืข ืขืœ ืžืงื•ืจ ื”ื ืชื•ื ื™ื (ืžื˜ืžื•ืŸ ืžืงื•ืžื™, ื‘ืงืฉืช ืจืฉืช, ืชื’ื•ื‘ืช ืžืขื‘ื“ ืžืงื•ืžื™) ื•ืฉื™ืžื•ืฉ ื‘ื”ืฆืคื ื” ื‘ืขืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื. ื”ืืคืฉืจื•ื™ื•ืช --cache, --synthesize, --network, --zone, --trust-anchor ื•--validate ืžืกื•ืคืงื•ืช ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืชื”ืœื™ืš ืงื‘ื™ืขืช ื”ืฉื.
  • systemd-nspawn ืžื•ืกื™ืฃ ืชืžื™ื›ื” ืœื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ ื‘ืืžืฆืขื•ืช nftables ื‘ื ื•ืกืฃ ืœืชืžื™ื›ื” ื”ืงื™ื™ืžืช ื‘-iptables. ื”ื’ื“ืจืช IPMasquerade ื‘-systemd-networkd ื”ื•ืกื™ืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘-backend ืžื‘ื•ืกืก nftables.
  • systemd-localed ื”ื•ืกื™ืคื” ืชืžื™ื›ื” ืœืงืจื™ืื” ืฉืœ locale-gen ื›ื“ื™ ืœื™ืฆื•ืจ ืžืงื•ืžื•ืช ื—ืกืจื™ื.
  • ืืคืฉืจื•ื™ื•ืช --pager/-no-pager/-json= ื ื•ืกืคื• ืœื›ืœื™ ืฉื™ืจื•ืช ืฉื•ื ื™ื ื›ื“ื™ ืœื”ืคืขื™ืœ/ืœื‘ื˜ืœ ืืช ืžืฆื‘ ื”ื”ื—ืœืคื” ื•ืคืœื˜ ื‘ืคื•ืจืžื˜ JSON. ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืืช ืžืกืคืจ ื”ืฆื‘ืขื™ื ื”ืžืฉืžืฉื™ื ื‘ื˜ืจืžื™ื ืœ ื‘ืืžืฆืขื•ืช ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” SYSTEMD_COLORS ("16" ืื• "256").
  • ื”ืžื‘ื ื” ืขื ื”ื™ืจืจื›ื™ื•ืช ืกืคืจื™ื•ืช ื ืคืจื“ื•ืช (ืคื™ืฆื•ืœ / ื• /usr) ื•ืชืžื™ื›ื” ื‘-cgroup v1 ื”ื•ืฆื ืžืฉื™ืžื•ืฉ.
  • ืกื ื™ืฃ ื”ืžืืกื˜ืจ ื‘-Git ืฉื•ื ื” ืž'ืžืืกื˜ืจ' ืœ'ืจืืฉื™'.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”