XNUMXãæã®éçºæéãçµãŠ
ã¡ã€ã³
- è¿œå ãµãŒãã¹
systemd ããŒã ãããŒã¿ãã« ããŒã ãã£ã¬ã¯ããªã®ç®¡çãæäŸããŸããããŠã³ããããã€ã¡ãŒãž ãã¡ã€ã«ã®åœ¢åŒã§é ä¿¡ãããããŒã¿ã¯æå·åãããŸãã Systemd-homed ã䜿çšãããšãèå¥åã®åæãæ©å¯æ§ãæ°ã«ããã«ãç°ãªãã·ã¹ãã éã§è»¢éã§ãããŠãŒã¶ãŒ ããŒã¿çšã®èªå·±å®çµåç°å¢ãäœæã§ããŸãããŠãŒã¶ãŒèªèšŒæ å ±ã¯ãã·ã¹ãã èšå®ã§ã¯ãªãããŒã ãã£ã¬ã¯ããªã«é¢é£ä»ããããŸãã/etc/passwdã/etc/groupã/etc/shadow ã®ä»£ããã«ã次ã®åœ¢åŒã®ãããã¡ã€ã«ã䜿çšãããŸããJSONã® ã詳现ã«ã€ããŠã¯ããåç §ããŠãã ãããæåŸã®ãç¥ãã systemd ããŒã ã - systemd ããŒã ã®ã³ã³ãããªã³ ã³ã³ããŒãã³ããè¿œå ããŸããã
ãŠãŒã¶ãŒããŒã¿ããŒã¹ ãïŒãsystemd-userdbãïŒãããã¯ãUNIX/glibc NSS ã¢ã«ãŠã³ãã JSON ã¬ã³ãŒãã«å€æããã¬ã³ãŒãã®ã¯ãšãªãšå埩ã®ããã®çµ±åããã Varlink API ãæäŸããŸããããŒã ãã£ã¬ã¯ããªã«é¢é£ä»ãããã JSON ãããã¡ã€ã«ã¯ããŠãŒã¶ãŒåããã¹ã¯ãŒã ããã·ã¥ãæå·åããŒãã¯ã©ãŒã¿ãããããžã§ãã³ã°ããããªãœãŒã¹ãªã©ããŠãŒã¶ãŒã®äœæ¥ã«å¿ èŠãªãã©ã¡ãŒã¿ãæå®ããŸãããããã¡ã€ã«ã¯ãå€éš Yubikey ããŒã¯ã³ã«ä¿åãããŠããããžã¿ã«çœ²åã䜿çšããŠèªèšŒã§ããŸãããããã¡ã€ã«ã管çããããã«ããuserdbctlããŠãŒãã£ãªãã£ãææ¡ãããŠããŸãã JSON ãããã¡ã€ã«ã®ãµããŒãããsystemd-logind ã pam-systemd ãªã©ã®ããŸããŸãª systemd ã³ã³ããŒãã³ãã«è¿œå ãããããŒã¿ãã« ãã£ã¬ã¯ããªã®ãŠãŒã¶ãŒãèªèšŒããã°ã€ã³ãç°å¢å€æ°ã®èšå®ãã»ãã·ã§ã³ã®äœæãå¶éã®èšå®ãªã©ãã§ããããã«ãªããŸãããå°æ¥çã«ã¯ãsssd ãã¬ãŒã ã¯ãŒã¯ã LDAP ã«ä¿åããããŠãŒã¶ãŒèšå®ãå«ã JSON ãããã¡ã€ã«ãçæã§ããããã«ãªããšäºæ³ãããŸãã - GPT 圢åŒã§ãã£ã¹ã¯ ããŒãã£ã·ã§ã³ ããŒãã«ãåããŒãã£ã·ã§ã³åããããã«èšèšãããæ°ãããŠãŒãã£ãªãã£ãsystemd-repartããè¿œå ãããŸãããããŒãã£ã·ã§ã³æ§é ã¯ãã©ã®ããŒãã£ã·ã§ã³ãååšãã¹ããããŸãã¯ååšã§ããããèšè¿°ãããã¡ã€ã«ãéããŠå®£èšåœ¢åŒã§å®çŸ©ãããŸããèµ·åã®ãã³ã«ãå®éã®ããŒãã£ã·ã§ã³ ããŒãã«ããããã®ãã¡ã€ã«ãšæ¯èŒããããã®åŸãäžè¶³ããŠããããŒãã£ã·ã§ã³ãè¿œå ãããããèšå®ã§å®çŸ©ãããçžå¯Ÿãµã€ãºãŸãã¯çµ¶å¯Ÿãµã€ãºãäžèŽããªãå Žåã¯ãæ¢åã®ããŒãã£ã·ã§ã³ã®ãµã€ãºãå¢å ããŸããå¢åå€æŽã®ã¿ãèš±å¯ãããŸããã€ãŸãããµã€ãºã®åé€ãçž®å°ã¯ã§ãããããŒãã£ã·ã§ã³ã®è¿œå ãšæ¡å€§ã®ã¿ãå¯èœã§ãã
ãã®ãŠãŒãã£ãªãã£ã¯ initrd ããèµ·åãããããã«èšèšãããŠãããã«ãŒã ããŒãã£ã·ã§ã³ãé 眮ãããŠãããã£ã¹ã¯ãèªåçã«æ€åºããŸããããã«ã¯ãå€æŽã®å®çŸ©ãå«ãŸãããã¡ã€ã«ãé€ããè¿œå ã®æ§æã¯å¿ èŠãããŸãããå®éã«ã¯ãsystemd-repart ã¯ãæåã¯æå°éã®åœ¢åŒã§åºè·ãããæåã®èµ·ååŸã«æ¢åã®ããã㯠ããã€ã¹ã®ãµã€ãºã«æ¡åŒµããããè¿œå ã®ããŒãã£ã·ã§ã³ (ã«ãŒããªã©) ã§è£å®ãããã§ãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã€ã¡ãŒãžã«åœ¹ç«ã¡ãŸããããŒãã£ã·ã§ã³ãæ¡åŒµããŠãã£ã¹ã¯å šäœãã«ããŒããããšããæåã®èµ·ååŸã«ã¹ã¯ãã ããŒãã£ã·ã§ã³ãŸã㯠/home ãäœæããããšãã§ããŸãããã XNUMX ã€ã®çšéã¯ãXNUMX ã€ã®å転ããŒãã£ã·ã§ã³ãåããæ§æã§ããæåã¯æåã®ããŒãã£ã·ã§ã³ã®ã¿ãæäŸãããXNUMX çªç®ã®ããŒãã£ã·ã§ã³ã¯æåã®èµ·åæã«äœæãããŸãã
- systemd-journald ã®è€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãèµ·åããŠããããããç¬èªã®åå空éã«ãã°ãä¿æã§ããããã«ãªããŸãããã¡ã€ã³ã® systemd-journald.service ã«å ããŠã.service ãã£ã¬ã¯ããªã¯ããLogNamespaceããã£ã¬ã¯ãã£ãã䜿çšããŠåå空éã«ãã€ã³ããããè¿œå ã®ã€ã³ã¹ã¿ã³ã¹ãäœæããããã®ãã³ãã¬ãŒããæäŸããŸããåãã°åå空éã¯ãç¬èªã®èšå®ãšå¶éã®ã»ãããæã€åå¥ã®ããã¯ã°ã©ãŠã³ã ããã»ã¹ã«ãã£ãŠæäŸãããŸããææ¡ãããæ©èœã¯ã倧éã®ãã°ã®è² è·åæ£ãã¢ããªã±ãŒã·ã§ã³ã®åé¢ã®åŒ·åã«åœ¹ç«ã€å¯èœæ§ããããŸããã¯ãšãªãæå®ãããåå空éã®ã¿ã«å¶éããããã«ãjournalctl ã«ã--namespaceããªãã·ã§ã³ãè¿œå ãããŸããã
- Systemd-udevd ããã³ãã®ä»ã® systemd ã³ã³ããŒãã³ãã¯ããããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«ä»£æ¿åãå²ãåœãŠãã¡ã«ããºã ã®ãµããŒããè¿œå ãã128 ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«å¯ŸããŠè€æ°ã®ååãåæã«äœ¿çšã§ããããã«ããŸãããååã¯æ倧 16 æåãŸã§å ¥åã§ããŸã (以åã¯ããããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹å㯠XNUMX æåã«å¶éãããŠããŸãã)ãããã©ã«ãã§ã¯ãsystemd-udevd ã¯åãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«ããµããŒããããŠããåœåã¹ããŒã ã«ãã£ãŠçæããããã¹ãŠã®ããªã¢ã³ãåãå²ãåœãŠãããã«ãªããŸããããã®åäœã¯ã.link ãã¡ã€ã«ã®æ°ãã AlternativeName ããã³ AlternativeNamesPolicy èšå®ãéããŠå€æŽã§ããŸãã systemd-nspawn ã¯ããã¹ãåŽã§äœæããã veth ãªã³ã¯ã®å®å šãªã³ã³ããåã䜿çšãã代æ¿åã®çæãå®è£ ããŸãã
- sd-event.h API ã¯ãPID åå©çšã®ç¶æ³ãåŠçããããã« Linux ã«ãŒãã« ãµãã·ã¹ãã ãpidfdãã®ãµããŒããè¿œå ããŸã (pidfd ã¯ç¹å®ã®ããã»ã¹ã«é¢é£ä»ããããŠããå€æŽãããŸããããPID ã¯çŸåšã®ããã»ã¹ã®åŸã«å¥ã®ããã»ã¹ã«é¢é£ä»ããããšãã§ããŸã)ããã«é¢é£ä»ããããŠãããã®ã¯ããã® PID ãçµäºããŸã)ããµãã·ã¹ãã ãçŸåšã®ã«ãŒãã«ã§ãµããŒããããŠããå ŽåãPID 1 ãé€ããã¹ãŠã® systemd ã³ã³ããŒãã³ãã¯ãpidfds ã䜿çšããããã«å€æãããŠããŸãã
- systemd-logind ã¯ãPolicyKit ãä»ããä»®æ³ç«¯æ«å€æŽæäœã®ã¢ã¯ã»ã¹ ãã§ãã¯ãæäŸããŸããããã©ã«ãã§ã¯ãã¢ã¯ãã£ããªç«¯æ«ãå€æŽããæš©éã¯ãããŒã«ã«ä»®æ³ç«¯æ«ã§å°ãªããšã XNUMX åã»ãã·ã§ã³ãéå§ãããŠãŒã¶ãŒã«ã®ã¿ä»äžãããŸãã
- systemd ã䜿çšã㊠initrd ã€ã¡ãŒãžãç°¡åã«äœæã§ããããã«ããããã«ãPID 1 ãã³ãã©ãŒã¯ initrd ã§äœ¿çšãããŠãããã©ãããæ€åºãããã®å Žåãdefault.target ã®ä»£ããã« initrd.target ãèªåçã«ããŒãããããã«ãªããŸããããã®ã¢ãããŒãã§ã¯ãinitrd ã€ã¡ãŒãžãšã¡ã€ã³ ã·ã¹ãã ã€ã¡ãŒãžã¯ã/etc/initrd-release ãã¡ã€ã«ãååšããå Žåã«ã®ã¿ç°ãªãããšãã§ããŸãã
- æ°ããã«ãŒãã« ã³ãã³ã ã©ã€ã³ ãã©ã¡ãŒã¿ãsystemd.cpu_affinityããè¿œå ãããŸããããã㯠/etc/systemd/system.conf ã® CPUAffinity ãªãã·ã§ã³ã«çžåœããPID 1 ããã³ãã®ä»ã®ããã»ã¹ã® CPU ã¢ãã£ãã㣠ãã¹ã¯ãèšå®ã§ããããã«ãªããŸãã
- ãsystemctl daemon-reloadããªã©ã®ã³ãã³ãã䜿çšã㊠PID 1 ãåèµ·åãããšãšãã«ãSELinux ããŒã¿ããŒã¹ã®åããŒããæå¹ã«ããŸããã
- ãsystemd.show-status=errorãèšå®ã PID 1 ãã³ãã©ãŒã«è¿œå ãããŸãããèšå®ãããšããšã©ãŒ ã¡ãã»ãŒãžãšèªã¿èŸŒã¿äžã®å€§å¹ ãªé 延ã®ã¿ãã³ã³ãœãŒã«ã«è¡šç€ºãããŸãã
- systemd-sysusers ã¯ããŠãŒã¶ãŒåãšã¯ç°ãªããã©ã€ã㪠ã°ã«ãŒãåãæã€ãŠãŒã¶ãŒãäœæããããã®ãµããŒããè¿œå ããŸããã
- systemd-growfs ã§ã¯ã以åã«ãµããŒããããŠãã Ext4 ããã³ Btrfs ã«ããããŒãã£ã·ã§ã³æ¡åŒµã«å ãã/etc/fstab ã® x-systemd.growfs ããŠã³ã ãªãã·ã§ã³ãä»ãã XFS ããŒãã£ã·ã§ã³æ¡åŒµã®ãµããŒããå°å ¥ãããŸããã
- initrd 段éã§ãã§ã«ããã¯ã解é€ãããŠããæå·åããŒãã£ã·ã§ã³ãå®çŸ©ããããã® x-initrd.attach ãªãã·ã§ã³ã /etc/crypttab ã«è¿œå ããŸããã
- systemd-cryptsetup ã¯ãPKCS#11 ã¹ããŒãã«ãŒãã䜿çšããŠæå·åãããããŒãã£ã·ã§ã³ã®ããã¯ã解é€ããããã®ãµããŒã (/etc/crypttab ã® pkcs11-uri ãªãã·ã§ã³) ãè¿œå ããŸãã (ããšãã°ãYubiKey ã«ããŒãã£ã·ã§ã³æå·åãæ·»ä»ãããã)ã
- æ°ããããŠã³ã ãªãã·ã§ã³ãx-systemd.required-byãããã³ãx-systemd.wanted-byãã /etc/fstab ã«è¿œå ãããlocal-fs.target ããã³ãªã¢ãŒãã®ä»£ããã«åŒã³åºãããããŠã³ãæäœãå®çŸ©ãããŠããããæ瀺çã«æ§æã§ããããã«ãªããŸããã -fs .target.
- æ°ãããµãŒãã¹ ãµã³ãããã¯ã¹ ãªãã·ã§ã³ã§ãã ProtectClock ãè¿œå ãããŸãããããã¯ãã·ã¹ãã ã¯ããã¯ãžã®æžã蟌ã¿ãå¶éããŸã (ã¢ã¯ã»ã¹ã¯ã/dev/rtcãã·ã¹ãã ã³ãŒã«ãããã³ CAP_SYS_TIME/CAP_WAKE_ALARM æš©éã®ã¬ãã«ã§ãããã¯ãããŸã)ã
- ä»æ§ãž
æ€åºå¯èœãªããŒãã£ã·ã§ã³ systemd-gpt-auto-generator ã«ããããŒãã£ã·ã§ã³æ€åºãè¿œå ãããŸãã
/var ãš /var/tmpã - ãsystemctl list-unit-filesãã§ã¯ããŠãããã®ãªã¹ãã衚瀺ãããšãã«ããã®ã¿ã€ãã®ãŠãããã«å¯ŸããŠã¡ãŒã«ãŒã®ããªã»ããã§æäŸãããŠããæå¹ç¶æ ãåæ ããæ°ããåã衚瀺ãããŸãã
- ãªãã·ã§ã³ã-with-dependencyãããsystemctlãã«è¿œå ãããŸãããã€ã³ã¹ããŒã«ããããšããsystemctl statusãããsystemctl catããªã©ã®ã³ãã³ãã¯ã察å¿ãããã¹ãŠã®ãŠãããã ãã§ãªããããããäŸåãããŠãããã衚瀺ããŸãã
- systemd-networkd ã§ã¯ãqdisc æ§æã«ãTBF (ããŒã¯ã³ ãã±ãã ãã£ã«ã¿ãŒ)ãSFQ (確ççå ¬å¹³æ§ãã¥ãŒã€ã³ã°)ãCoDel (å¶åŸ¡é 延ã¢ã¯ãã£ã ãã¥ãŒç®¡ç)ãããã³ FQ (ãã§ã¢ ãã¥ãŒ) ãã©ã¡ãŒã¿ãŒãæ§æããæ©èœãè¿œå ãããŸããã
- systemd-networkd 㯠IFB ãããã¯ãŒã¯ ããã€ã¹ã®ãµããŒããè¿œå ããŸãã (
äžéæ©èœããã㯠). - Systemd-networkd ã¯ã[Route] ã»ã¯ã·ã§ã³ã« MultiPathRoute ãã©ã¡ãŒã¿ãŒãå®è£ ããŠããã«ããã¹ ã«ãŒããæ§æããŸãã
- DHCPv4 ã¯ã©ã€ã¢ã³ãã® systemd-networkd ã§ã¯ãSendDecline ãªãã·ã§ã³ãè¿œå ãããŸããããã®ãªãã·ã§ã³ãæå®ãããå Žåãã¢ãã¬ã¹ãå«ã DHCP å¿çãåä¿¡ããåŸãéè€ã¢ãã¬ã¹ ãã§ãã¯ãå®è¡ãããã¢ãã¬ã¹ã®ç«¶åãæ€åºãããå Žåãçºè¡ãããã¢ãã¬ã¹ã¯æåŠãããŸãã RouteMTUBytes ãªãã·ã§ã³ã DHCPv4 ã¯ã©ã€ã¢ã³ãã«è¿œå ãããIP ã¢ãã¬ã¹ ãã€ã³ãã£ã³ã° (ãªãŒã¹) ããçæãããã«ãŒãã® MTU ãµã€ãºã決å®ã§ããããã«ãªããŸããã
- .network ãã¡ã€ã«ã® [Address] ã»ã¯ã·ã§ã³ã® PrefixRoute èšå®ã¯éæšå¥šã«ãªããŸãããããã¯ãéã®æå³ãæã€ãAddPrefixRouteãèšå®ã«çœ®ãæããããŸããã
- .network ãã¡ã€ã«ã§ã¯ãæ°ããå€ã_dhcpãã®ãµããŒããã[Route]ãã»ã¯ã·ã§ã³ã®ã²ãŒããŠã§ã€èšå®ã«è¿œå ãããŸãããèšå®ãããšãDHCP çµç±ã§æ§æãããã²ãŒããŠã§ã€ã«åºã¥ããŠéçã«ãŒããéžæãããŸãã
- èšå®ã¯ã.network ãã¡ã€ã«ã®ã[RoutingPolicyRule]ãã»ã¯ã·ã§ã³ã«è¡šç€ºãããŠããŸãã
User ããã³ SuppressPrefixLength ã䜿çšããŠãUID ç¯å²ãšãã¬ãã£ãã¯ã¹ ãµã€ãºã«åºã¥ããŠãœãŒã¹ ã«ãŒãã£ã³ã°ãæå®ããŸãã - networkctl ã®ãstatusãã³ãã³ãã¯ãåãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«é¢ãããã°ã衚瀺ããæ©èœãæäŸããŸãã
- systemd-networkd-wait-online ã¯ãã€ã³ã¿ãŒãã§ã€ã¹ãåäœå¯èœã«ãªããŸã§åŸ æ©ããæ倧æéãšãã€ã³ã¿ãŒãã§ã€ã¹ãããŠã³ãããŸã§åŸ æ©ããæ倧æéãèšå®ããããã®ãµããŒããè¿œå ããŸãã
- ã[Match]ãã»ã¯ã·ã§ã³ã空ãŸãã¯ã³ã¡ã³ãã¢ãŠããããŠãã .link ããã³ .network ãã¡ã€ã«ã®åŠçãåæ¢ããŸããã
- .link ãã¡ã€ã«ãš .network ãã¡ã€ã«ã®ã[Match]ãã»ã¯ã·ã§ã³ã«ãçæãããã©ã³ãã MAC ã䜿çšããå Žåã«ããã€ã¹ã®æ°žç¶ MAC ã¢ãã¬ã¹ã確èªããããã®ãPermanentMACAddressãèšå®ãè¿œå ãããŸããã
- .network ãã¡ã€ã«ã®ã[TrafficControlQueueingDiscipline]ãã»ã¯ã·ã§ã³ã®ååãã[NetworkEmulator]ãã«å€æŽãããé¢é£ããèšå®ã®ååãããNetworkEmulatorããã¬ãã£ãã¯ã¹ãåé€ãããŸããã
- DNS-over-TLS ã® systemd-resolved ã¯ãSNI ãã§ãã¯ã®ãµããŒããè¿œå ããŸãã
åºæïŒ ãªãŒãã³ããã.ru