XNUMXãæã®éçºæéãçµãŠ
äž»ãªå€æŽç¹ïŒ
- ã¡ã¢ãªäžè¶³ (ã¡ã¢ãªäžè¶³ãOOM) ã«é¢ããã«ãŒãã«çæä¿¡å·ã®èªèã PID 1 ãã³ãã©ãŒã«è¿œå ãããã¡ã¢ãªæ¶è²»å¶éã«éãããŠãããã匷å¶çµäºãããªãã·ã§ã³æ©èœãåããç¹å¥ãªç¶æ ã«ç§»è¡ããŸãããŸãã¯åæ¢ããŸãã
- ãŠããã ãã¡ã€ã«ã®å Žåãæ°ãããã©ã¡ãŒã¿ IPIngressFilterPath ããã³
IPEgressFilterPathãBPF ããã°ã©ã ãä»»æã®ãã³ãã©ãŒã«æ¥ç¶ããŠããã®ãŠãããã«é¢é£ä»ããããããã»ã¹ã«ãã£ãŠçæãããåä¿¡ããã³éä¿¡ IP ãã±ããããã£ã«ã¿ãªã³ã°ã§ããŸãã ææ¡ãããæ©èœã䜿çšãããšãsystemd ãµãŒãã¹çšã®äžçš®ã®ãã¡ã€ã¢ãŠã©ãŒã«ãäœæã§ããŸããæžãæ¹äŸ BPF ã«åºã¥ãåçŽãªãããã¯ãŒã¯ ãã£ã«ã¿ãŒã - ãã£ãã·ã¥ãã©ã³ã¿ã€ã ãã¡ã€ã«ãã¹ããŒã¿ã¹æ å ±ããã° ãã£ã¬ã¯ããªãåé€ãããcleanãã³ãã³ãã systemctl ãŠãŒãã£ãªãã£ã«è¿œå ãããŸããã
- systemd-networkd ã¯ãMACsecãnlmonãIPVTAPãããã³ Xfrm ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã®ãµããŒããè¿œå ããŸãã
- systemd-networkd ã¯ãæ§æãã¡ã€ã«ã®ã[DHCPv4]ãã»ã¯ã·ã§ã³ãšã[DHCPv6]ãã»ã¯ã·ã§ã³ãéããŠãDHCPv4 ã¹ã¿ãã¯ãš DHCPv6 ã¹ã¿ãã¯ã®åå¥ã®æ§æãå®è£ ããŸãã DHCP ãµãŒããŒããåä¿¡ãããã©ã¡ãŒã¿ãŒã§æå®ããã DNS ãµãŒããŒã«å¥ã®ã«ãŒããè¿œå ãã RoutesToDNS ãªãã·ã§ã³ãè¿œå ããŸãã (ããã«ãããDNS ãžã®ãã©ãã£ãã¯ã¯ãDHCP ããåä¿¡ããã¡ã€ã³ ã«ãŒããšåããªã³ã¯ãä»ããŠéä¿¡ãããŸã)ã DHCPv4 ã«æ°ãããªãã·ã§ã³ãè¿œå ãããŸããã MaxAttempts - ã¢ãã¬ã¹ãååŸããããã®ãªã¯ãšã¹ãã®æ倧æ°ãBlackList - DHCP ãµãŒããŒã®ãã©ã㯠ãªã¹ããSendRelease - ã»ãã·ã§ã³çµäºæã® DHCP RELEASE ã¡ãã»ãŒãžã®éä¿¡ãæå¹ã«ããŸãã
- æ°ããã³ãã³ãã systemd-analyze ãŠãŒãã£ãªãã£ã«è¿œå ãããŸããã
- ãsystemd-analyze timestampã - æéã®è§£æãšå€æã
- ãsystemd-analyze timespanã - æéã®åæãšå€æã
- ãsystemd-analyze æ¡ä»¶ã - ConditionXYZ åŒã®è§£æãšãã¹ãã
- ãsystemd-analyze exit-statusã - çµäºã³ãŒãã解æããæ°å€ããååãžããŸãã¯ãã®éã«å€æããŸãã
- ãsystemd-analyze Unit-filesã - ãŠããããšãŠããã ãšã€ãªã¢ã¹ã®ãã¹ãŠã®ãã¡ã€ã« ãã¹ããªã¹ãããŸãã
- ãªãã·ã§ã³ SuccessExitStatusãRestartPreventExitStatusãããã³
RestartForceExitStatus ã¯ãæ°å€ãªã¿ãŒã³ ã³ãŒãã ãã§ãªãããã®ããã¹ãèå¥å (ãDATAERRããªã©) ããµããŒãããããã«ãªããŸããã ãsytemd-analyze exit-statusãã³ãã³ãã䜿çšãããšãèå¥åã«å²ãåœãŠãããã³ãŒãã®ãªã¹ãã衚瀺ã§ããŸãã - ä»®æ³ãããã¯ãŒã¯ ããã€ã¹ãåé€ãããdeleteãã³ãã³ãã networkctl ãŠãŒãã£ãªãã£ã«è¿œå ãããŸããããŸããããã€ã¹çµ±èšã衚瀺ããã-statsããªãã·ã§ã³ãè¿œå ãããŸããã
- ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¹ã«ãŒããããå®æçã«æž¬å®ããããã«ãSpeedMeter ããã³ SpeedMeterIntervalSec èšå®ã networkd.conf ã«è¿œå ãããŸããã 枬å®çµæããåŸãããçµ±èšã¯ããnetworkctl statusãã³ãã³ãã®åºåã§ç¢ºèªã§ããŸãã
- ãã¡ã€ã«ãçæããããã®æ°ãããŠãŒãã£ãªã㣠systemd-network-generator ãè¿œå ããŸãã
.networkã.netdevãããã³ .link ã¯ãDracut èšå®åœ¢åŒã® Linux ã«ãŒãã« ã³ãã³ã ã©ã€ã³çµç±ã§èµ·åãããšãã«æž¡ããã IP èšå®ã«åºã¥ããŸãã - 64 ããã ã·ã¹ãã ã® sysctl "kernel.pid_max" å€ã¯ãããã©ã«ã㧠4194304 (22 ãããã§ã¯ãªã 16 ããã PID) ã«èšå®ãããããã«ãªããŸãããããã«ãããPID ãå²ãåœãŠãéã®è¡çªã®å¯èœæ§ãæžããåæã«å®è¡ã§ããæ°ã®å¶éãå¢å ããŸããå®è¡äžã®ããã»ã¹ãä¿è·ããã»ãã¥ãªãã£ã«ãã©ã¹ã®åœ±é¿ãäžããŸãã ãã®å€æŽã«ããäºææ§ã®åé¡ãçºçããå¯èœæ§ããããŸãããå®éã«ã¯ãã®ãããªåé¡ã¯ãŸã å ±åãããŠããŸããã
- ããã©ã«ãã§ã¯ããã«ã段éã¯çµ±åéå±€ cgroups-v2 (ã-Ddefault-hierarchy=unifiedã) ã«åãæ¿ãããŸãã 以åã¯ãããã©ã«ãã¯ãã€ããªãã ã¢ãŒã (ã-Ddefault-hierarchy=hybridã) ã§ããã
- ã·ã¹ãã ã³ãŒã« ãã£ã«ã¿ãŒ (SystemCallFilter) ã®åäœãå€æŽãããŸãããçŠæ¢ãããã·ã¹ãã ã³ãŒã«ã®å Žåãåã ã®ã¹ã¬ãããçµäºãããšäºæãã¬åé¡ãçºçããå¯èœæ§ããããããåã ã®ã¹ã¬ããã§ã¯ãªãããã»ã¹å šäœãçµäºããããã«ãªããŸããã ãã®å€æŽã¯ãLinux ã«ãŒãã« 4.14 以éããã³ libseccomp 2.4.0 以éã䜿çšããŠããå Žåã«ã®ã¿é©çšãããŸãã
- ç¹æš©ã®ãªãããã°ã©ã ã«ã¯ãã°ã«ãŒãã®ç¯å²å šäœ (ãã¹ãŠã®ããã»ã¹) ã«å¯Ÿã㊠sysctl "net.ipv4.ping_group_range" ãèšå®ããããšã«ãã£ãŠãICMP ãšã³ãŒ (ping) ãã±ãããéä¿¡ããæ©èœãäžããããŸãã
- ãã«ãããã»ã¹ãé«éåããããã«ãããã¥ã¢ã«ã®çæã¯ããã©ã«ãã§åæ¢ãããŠããŸã (å®å šãªããã¥ã¡ã³ãããã«ãããã«ã¯ãHTML 圢åŒã®ããã¥ã¢ã«ã®å Žåã¯ãªãã·ã§ã³ã-Dman=trueããŸãã¯ã-Dhtml=trueãã䜿çšããå¿ èŠããããŸã)ã ããã¥ã¡ã³ããèŠãããããããã«ãèå³ã®ããããã¥ã¢ã«ãçæããã³ãã¬ãã¥ãŒããããã® build/man/man ããã³ build/man/html ãšãã XNUMX ã€ã®ã¹ã¯ãªãããå«ãŸããŠããŸãã
- ååœèªã®ã¢ã«ãã¡ãããã®æåãå«ããã¡ã€ã³åãåŠçããã«ã¯ãããã©ã«ã㧠libidn2 ã©ã€ãã©ãªã䜿çšãããŸã (libidn ãè¿ãã«ã¯ãã-Dlibidn=trueããªãã·ã§ã³ã䜿çšããŸã)ã
- ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§åºãé åžãããŠããªãæ©èœãæäŸããŠãã /usr/sbin/halt.local å®è¡å¯èœãã¡ã€ã«ã®ãµããŒãã¯äžæ¢ãããŸããã ã·ã£ããããŠã³æã«ã³ãã³ãã®èµ·åãæŽçããã«ã¯ã/usr/lib/systemd/system-shutdown/ ã®ã¹ã¯ãªããã䜿çšããããfinal.target ã«äŸåããæ°ãããŠããããå®çŸ©ããããšããå§ãããŸãã
- ã·ã£ããããŠã³ã®æçµæ®µéã§ãsystemd 㯠sysctlãkernel.printkãã®ãã° ã¬ãã«ãèªåçã«äžããããã«ãªããŸãããããã«ãããéåžžã®ãã®ã³ã° ããŒã¢ã³ããã§ã«å®äºããŠããã·ã£ããããŠã³ã®åŸå段éã§çºçããã€ãã³ãããã°ã«è¡šç€ºããåé¡ã解決ãããŸãã ;
- ãã°ã衚瀺ããjournalctlããã®ä»ã®ãŠãŒãã£ãªãã£ã§ã¯ãèŠåã¯é»è²ã§åŒ·èª¿è¡šç€ºãããç£æ»ã¬ã³ãŒãã¯éè²ã§åŒ·èª¿è¡šç€ºããã矀è¡ããèŠèŠçã«åŒ·èª¿è¡šç€ºãããŸãã
- $PATH ç°å¢å€æ°ã§ã¯ãbin/ ãžã®ãã¹ã sbin/ ãžã®ãã¹ã®åã«æ¥ãããã«ãªããŸããã äž¡æ¹ã®ãã£ã¬ã¯ããªã«åãååã®å®è¡å¯èœãã¡ã€ã«ãããå Žåã¯ãbin/ ã®ãã¡ã€ã«ãå®è¡ãããŸãã
- systemd-logind ã¯ãã»ãã·ã§ã³ããšã«ç»é¢ã®æãããå®å šã«å€æŽããããã® SetBrightness() åŒã³åºããæäŸããŸãã
- ããã€ã¹ã®åæåãåŸ æ©ããããã®ã--wait-for-initializationããã©ã°ããudevadm infoãã³ãã³ãã«è¿œå ãããŸããã
- ã·ã¹ãã ã®ããŒãäžã«ãPID 1 ãã³ãã©ãŒã¯ã説æãå«ãè¡ã®ä»£ããã«ãŠãããã®ååã衚瀺ããããã«ãªããŸããã 以åã®åäœã«æ»ãã«ã¯ã/etc/systemd/system.conf ã® StatusUnitFormat ãªãã·ã§ã³ããŸã㯠systemd.status_unit_format ã«ãŒãã« ãªãã·ã§ã³ã䜿çšã§ããŸãã
- ãŠã©ããããã° PID 1 ã® KExecWatchdogSec ãªãã·ã§ã³ã /etc/systemd/system.conf ã«è¿œå ããŸãããããã¯ãkexec ã䜿çšããåèµ·åã®ã¿ã€ã ã¢ãŠããæå®ããŸãã å€ãèšå®
ShutdownWatchdogSec 㯠RebootWatchdogSec ã«ååãå€æŽãããã·ã£ããããŠã³ãŸãã¯éåžžã®åèµ·åäžã®ãžã§ãã®ã¿ã€ã ã¢ãŠããå®çŸ©ããŸãã - ãµãŒãã¹ã«æ°ãããªãã·ã§ã³ãè¿œå ãããŸãã
å®è¡æ¡ä»¶ ã䜿çšãããšãExecStartPre ã®åã«å®è¡ãããã³ãã³ããæå®ã§ããŸãã ã³ãã³ãã«ãã£ãŠè¿ããããšã©ãŒ ã³ãŒãã«åºã¥ããŠããŠãããã®ãã®åŸã®å®è¡ã決å®ãããŸããã³ãŒã 0 ãè¿ãããå ŽåããŠãããã®èµ·åã¯ç¶è¡ãããŸãã1 ïœ 254 ã®å Žåããšã©ãŒ ãã©ã°ãªãã§éãã«çµäºãã255 ã®å Žåããšã©ãŒ ãã©ã°ãä»ããŠçµäºããŸãã倱æãã©ã°ã - sys/fs/pstore/ ããããŒã¿ãæœåºãããããªãåæã®ããã« /var/lib/pstore ã«ä¿åããããã®æ°ãããµãŒãã¹ systemd-pstore.service ãè¿œå ããŸããã
- ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«é¢é£ã㊠systemd-timesyncd ã® NTP ãã©ã¡ãŒã¿ãæ§æããããã®æ°ããã³ãã³ãã timedatectl ãŠãŒãã£ãªãã£ã«è¿œå ãããŸããã
- ãlocalectl list-localesãã³ãã³ãã¯ãUTF-8 以å€ã®ãã±ãŒã«ã衚瀺ããªããªããŸããã
- å€æ°åãæåã-ãã§å§ãŸãå Žåãsysctl.d/ ãã¡ã€ã«å ã®å€æ°å²ãåœãŠãšã©ãŒãç¡èŠãããããã«ããŸãã
- ãµãŒãã¹
systemd-random-seed.service Linux ã«ãŒãã«ã®æ¬äŒŒä¹±æ°ãžã§ãã¬ãŒã¿ãŒã®ãšã³ããã㌠ããŒã«ã®åæåãå®å šã«æ åœããããã«ãªããŸããã æ£ããåæåããã /dev/urandom ãå¿ èŠãšãããµãŒãã¹ã¯ãsystemd-random-seed.service ã®åŸã«éå§ããå¿ èŠããããŸãã - systemd-boot ããŒã ããŒããŒã¯ããµããŒããããªãã·ã§ã³ã®æ©èœãæäŸããŸãã
ã·ãŒããã¡ã€ã« EFI ã·ã¹ãã ããŒãã£ã·ã§ã³ (ESP) å ã®ã©ã³ãã ã·ãŒã±ã³ã¹ã - æ°ããã³ãã³ãã bootctl ãŠãŒãã£ãªãã£ã«è¿œå ãããŸãããESP ã§ã·ãŒã ãã¡ã€ã«ãçæãããbootctl random-seedããšãsystemd-boot ããŒã ããŒããŒã®ã€ã³ã¹ããŒã«ã確èªãããbootctl is-installedãã§ãã ãŸããbootctl ã¯ãæ£ããæ§æãããŠããªãããŒã ãšã³ã㪠(ããšãã°ãã«ãŒãã« ã€ã¡ãŒãžãåé€ããããããããããŒãããããã®ãšã³ããªãæ®ã£ãŠããå Žå) ã«é¢ããèŠåã衚瀺ããããã«èª¿æŽãããŸããã
- ã·ã¹ãã ãã¹ãªãŒã ã¢ãŒãã«ãªããšãã«ãã¹ã¯ãã ããŒãã£ã·ã§ã³ãèªåçã«éžæããŸãã ããŒãã£ã·ã§ã³ã¯ããã®ããŒãã£ã·ã§ã³ã«èšå®ãããåªå é äœã«å¿ããŠéžæãããåªå é äœãåãå Žåã¯ç©ºãé åã®éã«å¿ããŠéžæãããŸãã
- /etc/crypttab ã« keyfile-timeout ãªãã·ã§ã³ãè¿œå ããæå·åããŒãæã€ããã€ã¹ãæå·åããŒãã£ã·ã§ã³ã«ã¢ã¯ã»ã¹ããããã®ãã¹ã¯ãŒãã®å ¥åãæ±ãããŸã§åŸ æ©ããæéãèšå®ããŸããã
- BFQ ã¹ã±ãžã¥ãŒã©ã® I/O éã¿ãèšå®ãã IOWeight ãªãã·ã§ã³ãè¿œå ããŸããã
- systemd-resolved ã¯ãDNS-over-TLS ã«ãstrictãã¢ãŒããè¿œå ããè¯å®ç㪠DNS å¿çã®ã¿ããã£ãã·ã¥ããæ©èœãå®è£ ããŸãã (resolved.conf ã®ãCache no-negativeã)ã
- VXLAN ã®å Žåãsystemd-networkd 㯠VXLAN ãããã³ã«æ¡åŒµãæå¹ã«ãã GenericProtocolExtension ãªãã·ã§ã³ãè¿œå ããŸããã VXLAN ããã³ GENEVE ã®å Žåãéä¿¡ãã±ããã®ãã©ã°ã¡ã³ããŒã·ã§ã³çŠæ¢ãã©ã°ãèšå®ãã IPDoNotFragment ãªãã·ã§ã³ãè¿œå ãããŸããã
- systemd-networkd ã®ã[Route]ãã»ã¯ã·ã§ã³ã«ãTTLPropagate ãªãã·ã§ã³ãšåæ§ã«ãåã ã®ã«ãŒãã«é¢é£ã㊠TCP æ¥ç¶ãè¿ éã«éãããã®ã¡ã«ããºã (TFO - TCP Fast OpenãRFC 7413) ãæå¹ã«ãã FastOpenNoCookie ãªãã·ã§ã³ãç»å ŽããŸããã TTL LSP (ã©ãã« ã¹ã€ããã ãã¹) ãèšå®ããŸãã ãã¿ã€ãããªãã·ã§ã³ã¯ãããŒã«ã«ããããŒããã£ã¹ãããšããŒãã£ã¹ãããã«ããã£ã¹ããanyãããã³ xresolve ã«ãŒãã£ã³ã° ã¢ãŒãã®ãµããŒããæäŸããŸãã
- Systemd-networkd ã¯ãã[Network]ãã»ã¯ã·ã§ã³ã« DefaultRouteOnDevice ãªãã·ã§ã³ãæäŸããç¹å®ã®ãããã¯ãŒã¯ ããã€ã¹ã®ããã©ã«ã ã«ãŒããèªåçã«æ§æããŸãã
- Systemd-networkd 㯠ProxyARP ãè¿œå ãã
ãããã· ARP ã®åäœãèšå®ããããã® ProxyARPWifiããã«ããã£ã¹ã ã¢ãŒãã§ã«ãŒãã£ã³ã° ãã©ã¡ãŒã¿ãèšå®ããããã® MulticastRouterããã«ããã£ã¹ãã® IGMP (ã€ã³ã¿ãŒããã ã°ã«ãŒã管çãããã³ã«) ããŒãžã§ã³ãå€æŽããããã® MulticastIGMPVersionã - Systemd-networkd ã«ã¯ãããŒã«ã«ããã³ãªã¢ãŒãã® IP ã¢ãã¬ã¹ãããã³ãããã¯ãŒã¯ ããŒãçªå·ãæ§æããããã® FooOverUDP ãã³ãã«ã® LocalãPeerãããã³ PeerPort ãªãã·ã§ã³ãè¿œå ãããŸããã TUN ãã³ãã«ã®å ŽåãGSO (æ±çšã»ã°ã¡ã³ã ãªãããŒã) ãµããŒããæ§æããããã« VnetHeader ãªãã·ã§ã³ãè¿œå ãããŸããã
- systemd-networkd ã§ã¯ã[Match] ã»ã¯ã·ã§ã³ã® .network ããã³ .link ãã¡ã€ã«ã« Property ãªãã·ã§ã³ã衚瀺ãããudev ã®ç¹å®ã®ããããã£ã«ãã£ãŠããã€ã¹ãèå¥ã§ããããã«ãªããŸããã
- systemd-networkd ã§ã¯ããã³ãã«ã®çµç«¯ãã«ãŒããã㯠ããã€ã¹ãloãã«å²ãåœãŠããã©ãããå¶åŸ¡ãã AssignToLoopback ãªãã·ã§ã³ãè¿œå ãããŸããã
- systemd-networkd ã¯ãIPv6 ã¹ã¿ãã¯ã sysctl disable_ipv6 ã«ãã£ãŠãããã¯ãããŠããå Žåã«èªåçã«ã¢ã¯ãã£ãåããŸããIPv6 èšå® (éçãŸã㯠DHCPv6) ããããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«å®çŸ©ãããŠããå ŽåãIPv6 ã¯ã¢ã¯ãã£ãåãããŸãããã以å€ã®å Žåã¯ããã§ã«èšå®ãããŠãã sysctl å€ã¯å€æŽãããŸããã
- .network ãã¡ã€ã«ã§ã¯ãCriticalConnection èšå®ã KeepConfiguration ãªãã·ã§ã³ã«çœ®ãæããããsystemd-networkd ãå¿ èŠãšããç¶æ³ (ãyesãããstaticãããdhcp-on-stopãããdhcpã) ãå®çŸ©ããããã®ããå€ãã®æ段ãæäŸãããŸããèµ·åæã«æ¢åã®æ¥ç¶ã«è§Šããªãã§ãã ããã
- è匱æ§ãä¿®æ£ãããŸãã
CVE-2019-15718 ããã¯ãD-Bus ã€ã³ã¿ãŒãã§ã€ã¹ systemd-resolved ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ã®æ¬ åŠãåå ã§ãã ãã®åé¡ã«ãããç¹æš©ã®ãªããŠãŒã¶ãŒããDNS èšå®ã®å€æŽã DNS ã¯ãšãªãäžæ£ãªãµãŒããŒã«éä¿¡ãããªã©ã管çè ã®ã¿ãå®è¡ã§ããæäœãå®è¡ã§ããããã«ãªããŸãã - è匱æ§ãä¿®æ£ãããŸãã
CVE-2019-9619 ããã¯ãé察話åã»ãã·ã§ã³ã«å¯Ÿã㊠pam_systemd ãæå¹ã«ããªãããšã«é¢é£ããŠãããã¢ã¯ãã£ããªã»ãã·ã§ã³ã®ã¹ããŒãã£ã³ã°ãå¯èœã«ãªããŸãã
åºæïŒ ãªãŒãã³ããã.ru