{"id":31333,"date":"2019-10-31T21:40:44","date_gmt":"2019-10-31T18:40:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2\/"},"modified":"2019-10-31T21:40:44","modified_gmt":"2019-10-31T18:40:44","slug":"virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2","title":{"rendered":"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse kan\u00eb r\u00ebnd\u00ebsi dhe si funksionojn\u00eb? Pjesa 2","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>P\u00ebrsh\u00ebndetje t\u00eb gjith\u00ebve, po ndajm\u00eb me ju pjes\u00ebn e dyt\u00eb t\u00eb publikimit \"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse jan\u00eb t\u00eb nevojshme dhe si funksionojn\u00eb?\" Pjesa e par\u00eb mund t\u00eb lexoni <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/446614\/\">k\u00ebtu<\/a><\/noindex>. Le t\u00eb kujtojm\u00eb, kjo seri publikimesh \u00ebsht\u00eb e lidhur me lan\u00e7imin e nj\u00eb fluksi t\u00eb ri n\u00eb kursin <noindex><a rel=\"nofollow\" href=\"https:\/\/otus.pw\/tjnD\/\">\"Administrator Linux\"<\/a><\/noindex>, i cili fillon shum\u00eb shpejt.<\/p>\n<p><b>Si t\u00eb v\u00ebzhgoni VFS me mjetet e eBPF dhe bcc<\/b><\/p>\n<p>M\u00ebnyra m\u00eb e thjesht\u00eb p\u00ebr t\u00eb kuptuar se si operon b\u00ebrthama me skedar\u00ebt <code>sysfs<\/code> \u00ebsht\u00eb t\u00eb shikoni k\u00ebt\u00eb n\u00eb praktik\u00eb, dhe m\u00ebnyra m\u00eb e thjesht\u00eb p\u00ebr t\u00eb par\u00eb ARM64 \u00ebsht\u00eb t\u00eb p\u00ebrdorni eBPF. eBPF (shkurtim p\u00ebr Berkeley Packet Filter) p\u00ebrb\u00ebhet nga nj\u00eb makin\u00eb virtuale q\u00eb ekzekutohet n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/events.linuxfoundation.org\/sites\/events\/files\/slides\/bpf_collabsummit_2015feb20.pdf\">b\u00ebrtham\u00eb<\/a><\/noindex>, t\u00eb cil\u00ebn p\u00ebrdoruesit me privilegje mund ta k\u00ebrkojn\u00eb (<code>query<\/code>) nga linja e komand\u00ebs. Burimet e b\u00ebrthames i tregojn\u00eb lexuesit se \u00e7far\u00eb mund t\u00eb b\u00ebj\u00eb b\u00ebrthama; ekzekutimi i mjeteve t\u00eb eBPF n\u00eb nj\u00eb sistem t\u00eb ngarkuar tregon at\u00eb q\u00eb b\u00ebrthama n\u00eb t\u00eb v\u00ebrtet\u00eb b\u00ebn. <\/p>\n<p><img decoding=\"async\" alt=\"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse kan\u00eb r\u00ebnd\u00ebsi dhe si funksionojn\u00eb? Pjesa 2\" src=\"\/wp-content\/uploads\/2019\/04\/95443cd3b1562b03eb43bf5fd229c508.jpg\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Fatmir\u00ebsisht, fillimi i p\u00ebrdorimit t\u00eb eBPF \u00ebsht\u00eb mjaft i leht\u00eb me ndihm\u00ebn e mjeteve <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/iovisor\/bcc\">bcc<\/a><\/noindex>, t\u00eb cilat jan\u00eb t\u00eb disponueshme si paketa nga distribuimi i p\u00ebrgjithsh\u00ebm <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/iovisor\/bcc\/blob\/master\/INSTALL.md\">Linux<\/a><\/noindex> dhe jan\u00eb dokumentuar n\u00eb detaje <noindex><a rel=\"nofollow\" href=\"http:\/\/brendangregg.com\/ebpf.html\">Bernard Gregg<\/a><\/noindex>. Mjetet <code>bcc<\/code> - jan\u00eb skripte n\u00eb Python me disa inserte t\u00eb kodit n\u00eb C, q\u00eb do t\u00eb thot\u00eb se \u00e7do kush q\u00eb njihet me t\u00eb dyja gjuh\u00ebt mund t'i modifikoj\u00eb leht\u00ebsisht. N\u00eb <code>bcc\/tools<\/code> ka 80 skripte Python, q\u00eb do t\u00eb thot\u00eb se gjasat jan\u00eb q\u00eb zhvilluesi ose administratori i sistemit mund t\u00eb gjej\u00eb di\u00e7ka t\u00eb p\u00ebrshtatshme p\u00ebr t\u00eb zgjidhur detyr\u00ebn. <br \/>\nP\u00ebr t\u00eb marr\u00eb nj\u00eb ide fillestare rreth asaj q\u00eb b\u00ebjn\u00eb VFS n\u00eb nj\u00eb sistem t\u00eb ngarkuar, provojeni <code>vfscount<\/code> \u0438\u043b\u0438 <code>vfsstat<\/code>. Kjo do t\u00eb tregoj\u00eb, p\u00ebr shembull, se dhjet\u00ebra thirrje <code>vfs_open()<\/code> dhe \"miqt\u00eb e tij\" ndodhin literalmente \u00e7do sekond\u00eb.<\/p>\n<p><img decoding=\"async\" alt=\"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse kan\u00eb r\u00ebnd\u00ebsi dhe si funksionojn\u00eb? Pjesa 2\" src=\"\/wp-content\/uploads\/2019\/04\/3479caa65696a29831f00e48782e48b3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<blockquote><p><code>vfsstat.py<\/code> - \u00ebsht\u00eb nj\u00eb skript n\u00eb Python, me inserte t\u00eb kodit n\u00eb C, i cili thjesht num\u00ebron thirrjet e funksioneve t\u00eb VFS.<\/p><\/blockquote>\n<p>Le t\u00eb japim nj\u00eb shembull m\u00eb t\u00eb zakonsh\u00ebm dhe t\u00eb shohim se \u00e7far\u00eb ndodh kur vendosim nj\u00eb USB flash drive n\u00eb kompjuter dhe sistemi e zbulon.<\/p>\n<p><img decoding=\"async\" alt=\"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse kan\u00eb r\u00ebnd\u00ebsi dhe si funksionojn\u00eb? Pjesa 2\" src=\"\/wp-content\/uploads\/2019\/04\/5c756fe1b6d4c5906631e5da24b59dca.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<blockquote><p>Me ndihm\u00ebn e eBPF, mund t\u00eb shikoni se \u00e7far\u00eb ndodh n\u00eb <code>\/sys<\/code>kur nj\u00eb USB flash drive \u00ebsht\u00eb vendosur. K\u00ebtu tregohet nj\u00eb shembull i thjesht\u00eb dhe nj\u00eb m\u00eb kompleks.<\/p><\/blockquote>\n<p>N\u00eb shembullin e treguar lart, <code>bcc<\/code> nj\u00eb mjet <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/iovisor\/bcc\/blob\/master\/tools\/trace_example.txt\">trace.py<\/a><\/noindex> shfaq nj\u00eb mesazh kur ekzekutohet komanda <code>sysfs_create_files()<\/code>. Ne shohim se <code>sysfs_create_files()<\/code> ka qen\u00eb e ekzekutuar me ndihm\u00ebn e <code>kworker<\/code> nj\u00eb rrjedhe n\u00eb p\u00ebrgjigje t\u00eb asaj q\u00eb ishte futur flash drive, por cili skedar u krijua gjat\u00eb k\u00ebsaj? Shembulli i dyt\u00eb tregon t\u00eb gjith\u00eb fuqin\u00eb e eBPF. K\u00ebtu <code>trace.py<\/code> shfaq nj\u00eb gjurm\u00eb t\u00eb trefisht\u00eb t\u00eb b\u00ebrtham\u00ebs (kernel backtrace) (opsioni -K) dhe emrin e skedarit q\u00eb u krijua <code>sysfs_create_files()<\/code>. Inkluzimi n\u00eb shprehjet e vetme \u00ebsht\u00eb nj\u00eb kod n\u00eb C, i cili p\u00ebrfshin nj\u00eb varg formati t\u00eb leht\u00eb p\u00ebr t'u njohur, i ofruar nga nj\u00eb skript Python q\u00eb ekzekuton LLVM <i>kompilator just-in-time<\/i>. Ky varg ai e p\u00ebrpunon dhe e ekzekuton n\u00eb nj\u00eb makin\u00eb virtuale brenda b\u00ebrtham\u00ebs. N\u00ebnshkrimi i plot\u00eb i funksionit <code>sysfs_create_files ()<\/code> duhet t\u00eb riprodhohet n\u00eb komand\u00ebn tjet\u00ebr, n\u00eb m\u00ebnyr\u00eb q\u00eb vargu i formatit t\u00eb mund t\u00eb referohet n\u00eb nj\u00eb nga parametrat. Gabimet n\u00eb k\u00ebt\u00eb fragment t\u00eb kodit n\u00eb C shkaktojn\u00eb gabime t\u00eb njohura t\u00eb kompilatorit C. P\u00ebr shembull, n\u00ebse nj\u00eb paramet\u00ebr -l \u00ebsht\u00eb i munguar, do t\u00eb shihni \"Failed to compile BPF text.\" Zhvilluesit q\u00eb jan\u00eb t\u00eb njohur mir\u00eb me C dhe Python, do t\u00eb gjejn\u00eb mjetet <code>bcc<\/code> t\u00eb lehta p\u00ebr t'u zgjeruar dhe ndryshuar.<\/p>\n<p>Kur pend\u00ebsi USB \u00ebsht\u00eb i futur, gjurma e b\u00ebrtham\u00ebs do t\u00eb tregoj\u00eb se PID 7711 \u00ebsht\u00eb nj\u00eb proces <code>kworker<\/code>, i cili krijoi skedarin <code>\"events\"<\/code> n\u00eb <code>sysfs<\/code>. N\u00eb p\u00ebrputhje me k\u00ebt\u00eb, thirrja me <code>sysfs_remove_files()<\/code> do t\u00eb tregoj\u00eb se heqja e pend\u00ebs ka \u00e7uar n\u00eb heqjen e skedarit <code>events<\/code>, e cila \u00ebsht\u00eb n\u00eb p\u00ebrputhje me konceptin e p\u00ebrgjithsh\u00ebm t\u00eb num\u00ebrimit t\u00eb referencave. Megjithat\u00eb, shikimi <code>sysfs_create_link ()<\/code> me eBPF gjat\u00eb futjes s\u00eb pend\u00ebs USB do t\u00eb tregoj\u00eb se jan\u00eb krijuar t\u00eb pakt\u00ebn 48 lidhje simbolike.<\/p>\n<p>Cili \u00ebsht\u00eb kuptimi i skedarit events? P\u00ebrdorimi i <noindex><a rel=\"nofollow\" href=\"http:\/\/northstar-www.dartmouth.edu\/doc\/solaris-forte\/manuals\/c\/user_guide\/cscope.html\">cscope<\/a><\/noindex> p\u00ebr t\u00eb k\u00ebrkuar <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/tree\/block\/genhd.c#n665\">__device_add_disk()<\/a><\/noindex>, tregon se ajo th\u00ebrret <code>disk_add_events ()<\/code>, dhe ose <code>\"media_change\"<\/code>, ose <code>\"eject_request\"<\/code> mund t\u00eb shkruhen n\u00eb skedarin e ngjarjeve. K\u00ebtu, shtresa bllokuese e b\u00ebrtham\u00ebs e informon userspace p\u00ebr shfaqjen dhe heqjen e \"diskut\". Vini re se sa informativ \u00ebsht\u00eb ky metod i hulumtimit n\u00eb shembullin e futjes s\u00eb pend\u00ebs USB n\u00eb krahasim me p\u00ebrpjekjet p\u00ebr t\u00eb kuptuar se si funksionon gjith\u00e7ka, ekskluzivisht nga burimet.<\/p>\n<p><b>Sistemet e skedar\u00ebve vet\u00ebm p\u00ebr lexim b\u00ebjn\u00eb t\u00eb mundur pajisjet e nd\u00ebrtuara<\/b><\/p>\n<p>Sigurisht, askush nuk e fik serverin apo kompjuterin e tij duke t\u00ebrhequr kabllin nga priz\u00eb. Por pse? Sepse sistemet e skedar\u00ebve t\u00eb montuara n\u00eb pajisjet fizike t\u00eb ruajtjes mund t\u00eb ken\u00eb shkrime t\u00eb vonuara, dhe strukturat e t\u00eb dh\u00ebnave q\u00eb regjistrojn\u00eb gjendjen e tyre mund t\u00eb mos sinkronizohen me regjistrimet n\u00eb ruajtje. Kur ndodh kjo, pronar\u00ebt e sistemit duhet t\u00eb presin ngarkimin e ardhsh\u00ebm p\u00ebr t\u00eb ekzekutuar utilitarin <code>fsck filesystem-recovery<\/code> dhe, n\u00eb rastin m\u00eb t\u00eb keq, t\u00eb humbasin t\u00eb dh\u00ebnat. <\/p>\n<p>Megjithat\u00eb, t\u00eb gjith\u00eb ne e dim\u00eb se shum\u00eb pajisje IoT, si dhe ruter\u00ebt, termostat\u00ebt dhe automobilat tani funksionojn\u00eb n\u00ebn Linux. Shumica e k\u00ebtyre pajisjeve kan\u00eb pothuajse asnj\u00eb nd\u00ebrfaqe p\u00ebrdoruesi, dhe nuk ka asnj\u00eb m\u00ebnyr\u00eb p\u00ebr t'i fikur ato 'n\u00eb m\u00ebnyr\u00eb t\u00eb past\u00ebr'. Imagjinoni t\u00eb nisi nj\u00eb automobil me bateri t\u00eb shkarkuar, kur alimentimi i pajisjes kontrolluese <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.automotivelinux.org\/_media\/eg-rhsa\/agl_referencehardwarespec_v0.1.0_20171018.pdf\">Linux<\/a><\/noindex> ka nj\u00eb alternim t\u00eb vazhduesh\u00ebm lart-posht\u00eb. Si \u00ebsht\u00eb e mundur q\u00eb sistemi ngarkohet pa nj\u00eb <code>fsck<\/code>, kur motori p\u00ebrfundimisht fillon? Dhe p\u00ebrgjigjja \u00ebsht\u00eb e thjesht\u00eb. Pajisjet e integruara mb\u00ebshteten n\u00eb sistemin e skedar\u00ebve rr\u00ebnj\u00ebsor <noindex><a rel=\"nofollow\" href=\"https:\/\/elinux.org\/images\/1\/1f\/Read-only_rootfs.pdf\">t\u00eb lexuesh\u00ebm vet\u00ebm<\/a><\/noindex> (e shkurtuar <code>ro-rootfs<\/code> (sistemi i skedar\u00ebve rr\u00ebnj\u00ebsor t\u00eb lexuesh\u00ebm vet\u00ebm). <\/p>\n<p><code>ro-rootfs<\/code> ofrojn\u00eb shum\u00eb p\u00ebrfitime, t\u00eb cilat jan\u00eb m\u00eb pak t\u00eb dukshme se autenticiteti. Nj\u00eb nga p\u00ebrfitimet \u00ebsht\u00eb se malware nuk mund t\u00eb shkruaj\u00eb n\u00eb <code>\/usr<\/code> \u0438\u043b\u0438 <code>\/lib<\/code>, n\u00ebse asnj\u00eb proces Linux nuk mund t\u00eb shkruaj\u00eb aty. Nj\u00eb tjet\u00ebr \u00ebsht\u00eb se nj\u00eb sistem i skedar\u00ebve kryesisht t\u00eb pandryshuesh\u00ebm \u00ebsht\u00eb thelb\u00ebsor p\u00ebr mb\u00ebshtetje n\u00eb terren p\u00ebr pajisjet e larg\u00ebta, pasi stafi ndihm\u00ebs p\u00ebrdor sisteme lokale, t\u00eb cilat nominalisht jan\u00eb identike me sistemet n\u00eb terren. Ndoshta p\u00ebrfitimi m\u00eb i r\u00ebnd\u00ebsish\u00ebm (por edhe m\u00eb i trazuar) \u00ebsht\u00eb se ro-rootfs detyron zhvilluesit t\u00eb vendosin se cilat objekte sistemike do t\u00eb mbeten t\u00eb pandryshueshme, akoma n\u00eb faz\u00ebn e projektimit t\u00eb sistemit. T\u00eb punosh me ro-rootfs mund t\u00eb jet\u00eb e pak\u00ebndshme dhe e dhimbshme, si\u00e7 ndodh shpesh me variablat const n\u00eb gjuh\u00ebt e programimit, por p\u00ebrfitimet e tyre leht\u00ebsisht justifikojn\u00eb koston e shtuara.<\/p>\n<p>Krijimi <code>rootfs<\/code> t\u00eb lexuesh\u00ebm vet\u00ebm k\u00ebrkon disa p\u00ebrpjekje shtes\u00eb p\u00ebr zhvilluesit e sistemeve t\u00eb integruara, dhe k\u00ebtu hyn n\u00eb sken\u00eb VFS. Linux k\u00ebrkon q\u00eb skedar\u00ebt n\u00eb <code>\/var<\/code> t\u00eb jen\u00eb t\u00eb qassh\u00ebm p\u00ebr shkruajtur, dhe, p\u00ebr m\u00eb tep\u00ebr, shum\u00eb aplikacione popullore q\u00eb drejtojn\u00eb sistemet e integruara, do t\u00eb p\u00ebrpiqen t\u00eb krijojn\u00eb skedar\u00eb konfigurimi <code>dot-files<\/code> n\u00eb <code>$HOME<\/code>. Nj\u00eb nga zgjidhjet p\u00ebr skedar\u00ebt e konfigurimit n\u00eb katalogun e sht\u00ebpis\u00eb zakonisht \u00ebsht\u00eb krijimi i tyre paraprak dhe grumbullimi n\u00eb <code>rootfs<\/code>. P\u00ebr <code>\/var<\/code> nj\u00eb nga qasjet e mundshme \u00ebsht\u00eb ta ngresh n\u00eb nj\u00eb pjes\u00eb t\u00eb ve\u00e7ant\u00eb, t\u00eb qasshme p\u00ebr shkruajtur, nd\u00ebrsa vet\u00eb <code>\/<\/code> ngrihet vet\u00ebm p\u00ebr lexim.<\/p>\n<p><b>Mounts q\u00eb lidhen dhe i zhvendosen, p\u00ebrdorimi i tyre nga kontejner\u00ebt<\/b> <\/p>\n<p>Ekzekutimi i komand\u00ebs <code>man mount<\/code> \u2013 m\u00ebnyra m\u00eb e mir\u00eb p\u00ebr t\u00eb m\u00ebsuar rreth mount-ve t\u00eb lidhura dhe t\u00eb zhvendosura, t\u00eb cilat u japin zhvilluesve dhe administrator\u00ebve t\u00eb sistemit mund\u00ebsin\u00eb t\u00eb krijojn\u00eb nj\u00eb sistem skedarash n\u00eb nj\u00eb rrug\u00eb, dhe m\u00eb pas ta ofrojn\u00eb at\u00eb aplikacioneve n\u00eb nj\u00eb tjet\u00ebr. P\u00ebr sistemet e integruara, kjo do t\u00eb thot\u00eb mund\u00ebsia p\u00ebr t\u00eb ruajtur skedar\u00eb n\u00eb <code>\/var<\/code> n\u00eb nj\u00eb pajisje flash q\u00eb \u00ebsht\u00eb e aksesueshme vet\u00ebm p\u00ebr lexim, por montimi i zhvendosur ose i lidhur i nj\u00eb rruge nga <code>tmpfs<\/code> n\u00eb <code>\/var<\/code> n\u00eb ngarkes\u00eb do t\u00eb lejoj\u00eb aplikacionet t\u00eb shkruajn\u00eb notat atje (scrawl). N\u00eb ndezjen e ardhshme, ndryshimet n\u00eb <code>\/var<\/code> do t\u00eb humbasin. Montimi i zhvendosur krijon nj\u00eb bashk\u00ebngjitje midis <code>tmpfs<\/code> dhe sistemit skedar posht\u00eb dhe lejon ndryshimet e dukshme t\u00eb skedar\u00ebve ekzistues n\u00eb <code>ro-tootf<\/code> nd\u00ebrsa montimi i lidhur mund t\u00eb b\u00ebj\u00eb q\u00eb dosjet e reja t\u00eb zbraz\u00ebta t\u00eb <code>tmpfs<\/code> t\u00eb duken si t\u00eb aksesueshme p\u00ebr shkrim n\u00eb <code>ro-rootfs<\/code> rruga. Nd\u00ebrkoh\u00eb q\u00eb <code>overlayfs<\/code> \u00ebsht\u00eb lloji i duhur (<code>proper<\/code>) i sistemit skedar, montimi i lidhur \u00ebsht\u00eb realizuar n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/tree\/Documentation\/filesystems\/sharedsubtree.txt\">hap\u00ebsir\u00ebn e emrave VFS<\/a><\/noindex>.<\/p>\n<p>Duke u bazuar n\u00eb p\u00ebrshkrimin e montimit t\u00eb zhvendosur dhe t\u00eb lidhur, askush nuk \u00ebsht\u00eb i befasuar se <noindex><a rel=\"nofollow\" href=\"https:\/\/coreos.com\/os\/docs\/latest\/kernel-modules.html\">kontejner\u00ebt Linux<\/a><\/noindex> i p\u00ebrdorin ato aktivisht. Le t\u00eb shikojm\u00eb se \u00e7far\u00eb ndodh kur ne p\u00ebrdorim <noindex><a rel=\"nofollow\" href=\"https:\/\/www.freedesktop.org\/software\/systemd\/man\/systemd-nspawn.html\">systemd-nspawn<\/a><\/noindex> p\u00ebr t\u00eb nisur nj\u00eb kontejner, duke p\u00ebrdorur mjetin <code>mountsnoop<\/code> \u043e\u0442 <code>bcc<\/code>.<\/p>\n<p>Thirrja <code>system-nspawn<\/code> e nis kontejnerin gjat\u00eb pun\u00ebs <code>mountsnoop.py<\/code>.<\/p>\n<p>Le t\u00eb shohim se \u00e7far\u00eb ndodhi:<\/p>\n<p>Nisja <code>mountsnoop<\/code> gjat\u00eb \"ngarkes\u00ebs\" s\u00eb kontejnerit tregon se mjedisi i ekzekutimit t\u00eb kontejnerit varet fort nga montimi i lidhur (Shfaqet vet\u00ebm fillimi i nj\u00eb dalje t\u00eb gjat\u00eb).<\/p>\n<p>K\u00ebtu <code>systemd-nspawn<\/code> siguron skedar\u00ebt e zgjedhur n\u00eb <code>procfs<\/code> \u0438 <code>sysfs<\/code> t\u00eb host-it n\u00eb kontejner si rrug\u00eb n\u00eb t\u00eb <code>rootfs<\/code>. P\u00ebrve\u00e7 <code>MS_BIND<\/code> flamurit q\u00eb vendos montimin e lidhur, disa flamuj t\u00eb tjer\u00eb n\u00eb sistemin e montimit p\u00ebrcaktojn\u00eb marr\u00ebdh\u00ebnien midis ndryshimeve n\u00eb hap\u00ebsir\u00ebn e emrave t\u00eb host-it dhe kontejnerit. P\u00ebr shembull, montimi i lidhur mund t\u00eb lejoj\u00eb ose t\u00eb fsheh\u00eb ndryshimet n\u00eb <code>\/proc<\/code> \u0438 <code>\/sys<\/code> n\u00eb kontejner, n\u00eb var\u00ebsi t\u00eb thirrjes. <\/p>\n<p><b>P\u00ebrfundim<\/b><\/p>\n<p>T\u00eb kuptosh struktur\u00ebn e brendshme t\u00eb Linux mund t\u00eb duket nj\u00eb detyr\u00eb e pamundur, sepse vet\u00eb b\u00ebrthama p\u00ebrmban nj\u00eb sasi t\u00eb madhe kodi, duke l\u00ebn\u00eb m\u00ebnjan\u00eb aplikacionet e hap\u00ebsir\u00ebs p\u00ebrdoruese t\u00eb Linux dhe nd\u00ebrfaqet e thirrjeve sistemike n\u00eb bibliotekat n\u00eb gjuh\u00ebn C, si\u00e7 jan\u00eb <code>glibc<\/code>. Nj\u00eb nga m\u00ebnyrat p\u00ebr t\u00eb arritur p\u00ebrparim \u00ebsht\u00eb t\u00eb lexosh kodin burimor t\u00eb nj\u00eb n\u00ebnsistemi t\u00eb b\u00ebrtham\u00ebs me fokus n\u00eb kuptimin e thirrjeve sistemike dhe titujve q\u00eb i drejtohen hap\u00ebsir\u00ebs s\u00eb p\u00ebrdoruesit, si dhe nd\u00ebrfaqeve kryesore t\u00eb brendshme t\u00eb b\u00ebrtham\u00ebs, p\u00ebr shembull, tabela <code>file_operations<\/code>. Operacionet e skedar\u00ebve ofrojn\u00eb parimin \"\u00e7do gj\u00eb \u00ebsht\u00eb nj\u00eb skedare\", prandaj menaxhimi i tyre \u00ebsht\u00eb ve\u00e7an\u00ebrisht i k\u00ebndsh\u00ebm. Skedar\u00ebt burimor\u00eb t\u00eb b\u00ebrtham\u00ebs n\u00eb gjuh\u00ebn C ndodhen n\u00eb katalogun e nivelit t\u00eb lart\u00eb <code>fs\/<\/code> paraqesin implementimin e sistemeve t\u00eb skedar\u00ebve virtual\u00eb, q\u00eb jan\u00eb nj\u00eb shtres\u00eb mbulese q\u00eb ofron nj\u00eb kompatibilitet t\u00eb gjer\u00eb dhe relativisht t\u00eb thjesht\u00eb me sistemet e skedar\u00ebve dhe pajisjet e ruajtjes. Montimi me lidhje dhe mbivendosje n\u00ebp\u00ebrmjet emrave t\u00eb hap\u00ebsirave Linux \u00ebsht\u00eb magjia VFS, e cila e b\u00ebn t\u00eb mundur krijimin e kontejner\u00ebve dhe sistemeve t\u00eb skedar\u00ebve me lexim vet\u00ebm. N\u00eb kombinim me studimin e kodit burimor, mjeti i b\u00ebrtham\u00ebs eBPF dhe nd\u00ebrfaqja e tij <code>bcc<\/code><br \/>\n e b\u00ebjn\u00eb hulumtimin e b\u00ebrtham\u00ebs m\u00eb t\u00eb leht\u00eb se kurr\u00eb.<\/p>\n<p>Miq, na shkruani n\u00ebse ky artikull ishte i dobish\u00ebm p\u00ebr ju? Ndoshta keni ndonj\u00eb koment apo v\u00ebrejtje? Dhe ata q\u00eb jan\u00eb t\u00eb interesuar p\u00ebr kursin \"Administrator Linux\", i ftojm\u00eb n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/otus.pw\/u5Jw\/\">dit\u00ebn e hapur<\/a><\/noindex>, e cila do t\u00eb zhvillohet m\u00eb 18 prill.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/446614\/\">Pjesa e par\u00eb.<\/a><\/noindex><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/447748\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442, \u0434\u0435\u043b\u0438\u043c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u044c\u044e \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u00ab\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442?\u00bb \u041f\u0435\u0440\u0432\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0442\u0443\u0442. \u041d\u0430\u043f\u043e\u043c\u043d\u0438\u043c, \u0434\u0430\u043d\u043d\u0430\u044f \u0441\u0435\u0440\u0438\u044f \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0439 \u043f\u0440\u0438\u0443\u0440\u043e\u0447\u0435\u043d\u0430 \u043a \u0437\u0430\u043f\u0443\u0441\u043a\u0443 \u043d\u043e\u0432\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430 \u043f\u043e \u043a\u0443\u0440\u0441\u0443 \u00ab\u0410\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440 Linux\u00bb, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u0442\u0430\u0440\u0442\u0443\u0435\u0442 \u0443\u0436\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u0441\u043a\u043e\u0440\u043e. \u041a\u0430\u043a \u043d\u0430\u0431\u043b\u044e\u0434\u0430\u0442\u044c \u0437\u0430 VFS \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 eBPF \u0438 bcc \u0421\u0430\u043c\u044b\u0439 \u043f\u0440\u043e\u0441\u0442\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23299,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31333","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442, \u0434\u0435\u043b\u0438\u043c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u044c\u044e \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u00ab\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442?\u00bb \u041f\u0435\u0440\u0432\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442? \u0427\u0430\u0441\u0442\u044c 2 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442, \u0434\u0435\u043b\u0438\u043c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u044c\u044e \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u00ab\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442?\u00bb \u041f\u0435\u0440\u0432\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:40:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:40:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse kan\u00eb nevoj\u00eb dhe si funksionojn\u00eb? Pjesa 2 | ProHoster","description":"P\u00ebrsh\u00ebndetje t\u00eb gjith\u00ebve, po ndajm\u00eb me ju pjes\u00ebn e dyt\u00eb t\u00eb publikimit \"Sistemet virtuale t\u00eb skedar\u00ebve n\u00eb Linux: p\u00ebrse jan\u00eb t\u00eb nevojshme dhe si funksionojn\u00eb?\" Pjesa e par\u00eb mund t\u00eb lexoni","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442? \u0427\u0430\u0441\u0442\u044c 2 | ProHoster","og:description":"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442, \u0434\u0435\u043b\u0438\u043c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u044c\u044e \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u00ab\u0412\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432 Linux: \u0437\u0430\u0447\u0435\u043c \u043e\u043d\u0438 \u043d\u0443\u0436\u043d\u044b \u0438 \u043a\u0430\u043a \u043e\u043d\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442?\u00bb \u041f\u0435\u0440\u0432\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/virtualnye-fajlovye-sistemy-v-linux-zachem-oni-nuzhny-i-kak-oni-rabotayut-chast-2","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:40:44+00:00","article:modified_time":"2019-10-31T18:40:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31333","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 05:41:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:18:40","updated":"2026-01-21 05:41:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=31333"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31333\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/23299"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=31333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=31333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=31333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}