ืžืขืจื›ืช systemd ื’ืจืกื” 253

ืœืื—ืจ ืฉืœื•ืฉื” ื•ื—ืฆื™ ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ื”ื•ืฆื’ ืฉื—ืจื•ืจ ืžื ื”ืœ ื”ืžืขืจื›ืช systemd 253.

ื‘ื™ืŸ ื”ืฉื™ื ื•ื™ื™ื ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื”ื—ื‘ื™ืœื” ื›ื•ืœืœืช ืืช ื”ืฉื™ืจื•ืช 'ukify', ืฉื ื•ืขื“ ืœื‘ื ื•ืช, ืœืืžืช ื•ืœื™ื™ืฆืจ ื—ืชื™ืžื•ืช ืขื‘ื•ืจ ืชืžื•ื ื•ืช ืœื™ื‘ื” ืžืื•ื—ื“ื•ืช (UKI, Unified Kernel Image), ื”ืžืฉืœื‘ืช ืžื˜ืคืœ ืœื˜ืขื™ื ืช ื”ืœื™ื‘ื” ืž-UEFI (UEFI boot stub), ืชืžื•ื ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•- ืกื‘ื™ื‘ืช ืžืขืจื›ืช ื ื˜ืขื ืช ื‘ื–ื™ื›ืจื•ืŸ initrd, ื”ืžืฉืžืฉืช ืœืืชื—ื•ืœ ืจืืฉื•ื ื™ ื‘ืฉืœื‘ ืฉืœืคื ื™ ื”ื˜ืขื™ื ื” ืฉืœ ืžืขืจื›ืช ืงื‘ืฆื™ ื”ืฉื•ืจืฉ. ื›ืœื™ ื”ืฉื™ืจื•ืช ืžื—ืœื™ืฃ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืกื•ืคืงื” ื‘ืขื‘ืจ ืขืœ ื™ื“ื™ ื”ืคืงื•ื“ื” 'dracut -uefi' ื•ืžืฉืœื™ื ืื•ืชื” ืขื ื™ื›ื•ืœื•ืช ืœื—ื™ืฉื•ื‘ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืงื™ื–ื•ื–ื™ื ื‘ืงื‘ืฆื™ PE, ืžื™ื–ื•ื’ ืงื•ื“ื™ื, ื—ืชื™ืžื” ืขืœ ืชืžื•ื ื•ืช ืœื™ื‘ื” ืžืฉื•ื‘ืฆื•ืช, ื™ืฆื™ืจืช ืชืžื•ื ื•ืช ืžืฉื•ืœื‘ื•ืช ืขื sbsign, ื”ื™ื•ืจื™ืกื˜ื™ืงื” ืœืงื‘ื™ืขืช uname ืฉืœ ื”ืœื™ื‘ื”, ื‘ื“ื™ืงืช ืชืžื•ื ื” ืขื ืžืกืš ืคืชื™ื—ื” ื•ื”ื•ืกืคืช ืžื“ื™ื ื™ื•ืช PCR ื—ืชื•ืžื” ืฉื ื•ืฆืจื” ืขืœ ื™ื“ื™ ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-measure.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืกื‘ื™ื‘ื•ืช initrd ืฉืื™ื ืŸ ืžื•ื’ื‘ืœื•ืช ืขืœ ื™ื“ื™ ืžื™ืงื•ื ื–ื™ื›ืจื•ืŸ, ืฉื‘ื”ืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืฉื›ื‘ื•ืช-ืขืœ ื‘ืžืงื•ื tmpfs. ืขื‘ื•ืจ ืกื‘ื™ื‘ื•ืช ื›ืืœื”, systemd ืœื ืžื•ื—ืง ืืช ื›ืœ ื”ืงื‘ืฆื™ื ื‘-initrd ืœืื—ืจ ื”ื—ืœืคืช ืžืขืจื›ืช ืงื‘ืฆื™ ื”ืฉื•ืจืฉ.
  • ื”ืคืจืžื˜ืจ "OpenFile" ื ื•ืกืฃ ืœืฉื™ืจื•ืชื™ื ืœืคืชื™ื—ืช ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื (ืื• ื”ืชื—ื‘ืจื•ืช ืœืฉืงืขื™ Unix) ื•ื”ืขื‘ืจืช ืžืชืืจื™ ื”ืงื‘ืฆื™ื ื”ืžืฉื•ื™ื›ื™ื ืœืชื”ืœื™ืš ื”ื”ืคืขืœื” (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืืชื” ืฆืจื™ืš ืœืืจื’ืŸ ื’ื™ืฉื” ืœืงื•ื‘ืฅ ืขื‘ื•ืจ ืฉื™ืจื•ืช ืœืœื ื”ืจืฉืื•ืช ืžื‘ืœื™ ืœืฉื ื•ืช ืืช ื–ื›ื•ื™ื•ืช ื”ื’ื™ืฉื” ืœืงื•ื‘ืฅ).
  • ื‘-systemd-cryptenroll, ื‘ืขืช ืจื™ืฉื•ื ืžืคืชื—ื•ืช ื—ื“ืฉื™ื, ื ื™ืชืŸ ืœืคืชื•ื— ืžื—ื™ืฆื•ืช ืžื•ืฆืคื ื•ืช ื‘ืืžืฆืขื•ืช ืืกื™ืžื•ื ื™ FIDO2 (--unlock-fido2-device) ืœืœื ืฆื•ืจืš ื‘ืกื™ืกืžื”. ืงื•ื“ PIN ืฉืฆื•ื™ืŸ ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืžืื•ื—ืกืŸ ืขื ืžืœื— ื›ื“ื™ ืœืกื‘ืš ืืช ื–ื™ื”ื•ื™ ื”ื›ื•ื— ื”ื’ืก.
  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ReloadLimitIntervalSec ื•-ReloadLimitBurst, ื›ืžื• ื’ื ืืคืฉืจื•ื™ื•ืช ืฉื•ืจืช ืคืงื•ื“ื” ืœื™ื‘ื” (systemd.reload_limit_interval_sec ื•-/systemd.reload_limit_burst) ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ืขื•ืฆืžืช ื”ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ ืชื”ืœื™ืš ื”ืจืงืข.
  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช, ื”ืืคืฉืจื•ืช "MemoryZSwapMax" ื™ื•ืฉืžื” ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ืžืืคื™ื™ืŸ memory.zswap.max, ื”ืงื•ื‘ืข ืืช ื’ื•ื“ืœ ื”-zswap ื”ืžืงืกื™ืžืœื™.
  • ืขื‘ื•ืจ ื™ื—ื™ื“ื•ืช, ื”ื•ื˜ืžืขื” ืืคืฉืจื•ืช "LogFilterPatterns", ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ื‘ื™ื˜ื•ื™ื™ื ืจื’ื•ืœืจื™ื™ื ืœืกื™ื ื•ืŸ ืคืœื˜ ืžื™ื“ืข ืœื™ื•ืžืŸ (ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœื ืœื›ืœื•ืœ ืคืœื˜ ืžืกื•ื™ื ืื• ืœืฉืžื•ืจ ื ืชื•ื ื™ื ืžืกื•ื™ืžื™ื ื‘ืœื‘ื“).
  • ื™ื—ื™ื“ื•ืช ื”ื™ืงืฃ ืชื•ืžื›ื•ืช ื›ืขืช ื‘ื”ื’ื“ืจืช "OOMPolicy" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ื”ืชื ื”ื’ื•ืช ื‘ืขืช ื ื™ืกื™ื•ืŸ ืœื”ืงื“ื™ื ื›ืืฉืจ ื”ื–ื™ื›ืจื•ืŸ ื ืžื•ืš (ื”ืคืขืœื•ืช ื›ื ื™ืกื” ืžื•ื’ื“ืจื•ืช ืœ-OOMPolicy=ื”ืžืฉืš ื›ืš ืฉื”-OOM Killer ืœื ื™ืคืกื™ืง ืื•ืชืŸ ื‘ื›ื•ื—).
  • ืกื•ื’ ืฉื™ืจื•ืช ื—ื“ืฉ ื”ื•ื’ื“ืจ - "Type=notify-reload", ื”ืžืจื—ื™ื‘ ืืช ืกื•ื’ "Type=notify" ืขื ื”ื™ื›ื•ืœืช ืœื—ื›ื•ืช ืœืื•ืช ื”ื”ืคืขืœื” ืžื—ื“ืฉ ื›ื“ื™ ืœื”ืฉืœื™ื ืืช ื”ืขื™ื‘ื•ื“ (SIGHUP). ื”ืฉื™ืจื•ืชื™ื systemd-networkd.service, systemd-udevd.service ื•-systemd-login ื”ื•ืขื‘ืจื• ืœืกื•ื’ ื”ื—ื“ืฉ.
  • udev ืžืฉืชืžืฉ ื‘ืกื›ื™ืžืช ืฉืžื•ืช ื—ื“ืฉื” ืขื‘ื•ืจ ื”ืชืงื ื™ ืจืฉืช, ื”ื”ื‘ื“ืœ ื”ื•ื ืฉืขื‘ื•ืจ ื”ืชืงื ื™ USB ืฉืื™ื ื ืงืฉื•ืจื™ื ืœืืคื™ืง PCI, ID_NET_NAME_PATH ืžื•ื’ื“ืจ ื›ืขืช ืœื”ื‘ื˜ื™ื— ืฉืžื•ืช ืฆืคื•ื™ื™ื ื™ื•ืชืจ. ื”ืื•ืคืจื˜ื•ืจ '-=' ื™ื•ืฉื ืขื‘ื•ืจ ืžืฉืชื ื™ SYMLINK, ื•ืžืฉืื™ืจ ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ืœื ืžื•ื’ื“ืจื™ื ืื ื›ืœืœ ืœื”ื•ืกืคืชื ื”ื•ื’ื“ืจ ื‘ืขื‘ืจ.
  • ื‘-systemd-boot, ืฉื™ื“ื•ืจ ื”-Seed ืขื‘ื•ืจ ืžื—ื•ืœืœื™ ืžืกืคืจื™ื ืคืกืื•ื“ื•-ืืงืจืื™ื™ื ื‘ืงืจื ืœ ื•ืขื‘ื•ืจ ื”-backend ืฉืœ ื”ื“ื™ืกืง ืขื•ื‘ื“ ืžื—ื“ืฉ. ื ื•ืกืคื” ืชืžื™ื›ื” ืœื˜ืขื™ื ืช ื”ืœื™ื‘ื” ืœื ืจืง ืžื”-ESP (EFI System Partition), ืœืžืฉืœ, ืžื”ืงื•ืฉื—ื” ืื• ื™ืฉื™ืจื•ืช ืขื‘ื•ืจ QEMU. ื ื™ืชื•ื— ืฉืœ ืคืจืžื˜ืจื™ SMBIOS ืžืกื•ืคืง ื›ื“ื™ ืœืงื‘ื•ืข ืืชื—ื•ืœ ื‘ืกื‘ื™ื‘ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”. ื”ื•ื˜ืžืข ืžืฆื‘ ื—ื“ืฉ ืฉืœ 'ืื ื‘ื˜ื•ื—' ืฉื‘ื• ื”ืื™ืฉื•ืจ ืขื‘ื•ืจ UEFI Secure Boot ื ื˜ืขืŸ ืžื”-ESP ืจืง ืื ื”ื•ื ื ื—ืฉื‘ ื‘ื˜ื•ื— (ืคื•ืขืœ ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช).
  • ื›ืœื™ ื”ืฉื™ืจื•ืช bootctl ืžื™ื™ืฉื ื™ืฆื™ืจืช ืืกื™ืžื•ื ื™ ืžืขืจื›ืช ื‘ื›ืœ ืžืขืจื›ื•ืช ื”-EFI, ืœืžืขื˜ ืกื‘ื™ื‘ื•ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”. ื ื•ืกืคื• ืคืงื•ื“ื•ืช 'kernel-identify' ื•-'kernel-inspect' ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ืกื•ื’ ืชืžื•ื ืช ื”ืงืจื ืœ ื•ืžื™ื“ืข ืขืœ ืืคืฉืจื•ื™ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•ื’ืจืกืช ื”ืงืจื ืœ, 'ื‘ื˜ืœ ืงื™ืฉื•ืจ' ื›ื“ื™ ืœื”ืกื™ืจ ืืช ื”ืงื•ื‘ืฅ ื”ืžืฉื•ื™ืš ืœืกื•ื’ ื”ืจืืฉื•ืŸ ืฉืœ ืจืฉื•ืžื•ืช ื”ืืชื—ื•ืœ, 'ื ื™ืงื•ื™' ื›ื“ื™ ืœื”ืกื™ืจ ืืช ื›ืœ ืงื‘ืฆื™ื ืžืกืคืจื™ื™ืช "entry-token" ื‘-ESP ื•-XBOOTLDR, ืฉืื™ื ื ืžืฉื•ื™ื›ื™ื ืœืกื•ื’ ื”ืจืืฉื•ืŸ ืฉืœ ืจืฉื•ืžื•ืช ื”ืืชื—ื•ืœ. ืขื™ื‘ื•ื“ ืฉืœ ื”ืžืฉืชื ื” KERNEL_INSTALL_CONF_ROOT ืกื•ืคืง.
  • ื”ืคืงื•ื“ื” 'systemctl list-dependencies' ืชื•ืžื›ืช ื›ืขืช ื‘ืขื™ื‘ื•ื“ ืฉืœ ื”ืืคืฉืจื•ื™ื•ืช '--type' ื•-'--state', ื•ื”ืคืงื•ื“ื” 'systemctl kexec' ืžื•ืกื™ืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืกื‘ื™ื‘ื•ืช ื”ืžื‘ื•ืกืกื•ืช ืขืœ ื”-Xen hypervisor.
  • ื‘ืงื‘ืฆื™ .network ื‘ืงื˜ืข [DHCPv4], ื ื•ืกืคื” ื›ืขืช ืชืžื™ื›ื” ื‘ืืคืฉืจื•ื™ื•ืช SocketPriority ื•-QuickAck, RouteMetric=high|medium|low.
  • Systemd-repart ื ื•ืกืคื• ืืคืฉืจื•ื™ื•ืช "--include-partitions", "--exclude-partitions" ื•-"-defer-partitions" ืœืกื™ื ื•ืŸ ืžื—ื™ืฆื•ืช ืœืคื™ ืกื•ื’ UUID, ืžื” ืฉืžืืคืฉืจ, ืœืžืฉืœ, ืœื‘ื ื•ืช ืชืžื•ื ื•ืช ืฉื‘ื”ืŸ ืžื—ื™ืฆื” ืื—ืช ื‘ื ื•ื™ื” ืžื‘ื•ืกืก ืขืœ ื”ืชื•ื›ืŸ ืฉืœ ืžื—ื™ืฆื” ืื—ืจืช. ื ื•ืกืคื” ื’ื ื”ืืคืฉืจื•ืช "-sector-size" ื›ื“ื™ ืœืฆื™ื™ืŸ ืืช ื’ื•ื“ืœ ื”ืกืงื˜ื•ืจ ื”ืžืฉืžืฉ ื‘ืขืช ื™ืฆื™ืจืช ื”ืžื—ื™ืฆื”. ื ื•ืกืคื” ืชืžื™ื›ื” ืœื™ืฆื™ืจืช ืงื‘ืฆื™ erofs. ื”ื”ื’ื“ืจื” 'ืžื–ืขื•ืจ' ืžื™ื™ืฉืžืช ืขื™ื‘ื•ื“ ืฉืœ ื”ืขืจืš "ื”ื˜ื•ื‘ ื‘ื™ื•ืชืจ" ืœื‘ื—ื™ืจืช ื’ื•ื“ืœ ื”ืชืžื•ื ื” ื”ืžื™ื ื™ืžืœื™ ื”ืืคืฉืจื™.
  • systemd-journal-remote ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื•ืช MaxUse, KeepFree, MaxFileSize ื•-MaxFiles ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ืฆืจื™ื›ืช ืฉื˜ื— ื”ื“ื™ืกืง.
  • systemd-cryptsetup ืžื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื™ื–ื•ืžื•ืช ืœืืกื™ืžื•ื ื™ FIDO2 ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื ื•ื›ื—ื•ืชื ืœืคื ื™ ืื™ืžื•ืช.
  • ืคืจืžื˜ืจื™ื ื—ื“ืฉื™ื tpm2-measure-bank ื•-tpm2-measure-pcr ื ื•ืกืคื• ืœ-crypttab.
  • systemd-gpt-auto-generator ืžื™ื™ืฉื ื”ืจื›ื‘ื” ืฉืœ ืžื—ื™ืฆื•ืช ESP ื•-XBOOTLDR ื‘ืžืฆื‘ื™ "noexec,nosuid,nodev", ื•ื›ืŸ ืžื•ืกื™ืฃ ื—ืฉื‘ื•ื ื•ืช ืœืคืจืžื˜ืจื™ื rootfstype ื•-rootflags ื”ืžื•ืขื‘ืจื™ื ื“ืจืš ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืœื™ื‘ื”.
  • systemd-resolved ืžืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืคืจืžื˜ืจื™ื ืฉืœ ืคื•ืชืจ ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ืืคืฉืจื•ื™ื•ืช ืฉืจืช ื”ืฉืžื•ืช, ื”ื“ื•ืžื™ื™ืŸ, network.dns ื•-network.search_domains ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื”ืœื™ื‘ื”.
  • ืœืคืงื•ื“ืช "systemd-analyze plot" ื™ืฉ ื›ืขืช ืืช ื”ื™ื›ื•ืœืช ืœื”ื•ืฆื™ื ื‘ืคื•ืจืžื˜ JSON ื‘ืขืช ืฆื™ื•ืŸ ื”ื“ื’ืœ "-json". ื’ื ืืคืฉืจื•ื™ื•ืช ื—ื“ืฉื•ืช "--table" ื•-"-no-legend" ื ื•ืกืคื• ืœืฉืœื™ื˜ื” ื‘ืคืœื˜.
  • ื‘ืฉื ืช 2023, ืื ื• ืžืชื›ื ื ื™ื ืœืกื™ื™ื ืืช ื”ืชืžื™ื›ื” ื‘-cgroups v1 ื•ื‘ื”ื™ืจืจื›ื™ื•ืช ืกืคืจื™ื•ืช ืžืคื•ืฆืœื•ืช (ื›ืืฉืจ /usr ืžื•ืชืงืŸ ื‘ื ืคืจื“ ืžื”ืฉื•ืจืฉ, ืื• /bin ื•- /usr/bin, /lib ื•- /usr/lib ืžื•ืคืจื“ื™ื).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”