ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืžืขืœื“ื•ื ื’ 242

[:ืจื•]

ื ืึธืš ืฆื•ื•ื™ื™ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื“ืขืจืœืื ื’ื˜ ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืžืขืœื“ื•ื ื’ ืกื™ืกื˜ืขื 242. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื–, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ L2TP ื˜ืึทื ืึทืœื–, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ืกื™ืกื˜ืขืž-ืœืึธื’ื™ืŸ ืื•ื™ืฃ ืจื™ืกื˜ืึทืจื˜ ื“ื•ืจืš ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื–, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืขืงืกื˜ืขื ื“ืขื“ XBOOTLDR ืฉื˜ื™ื•ื•ืœ ืคึผืึทืจื˜ื™ืฉืึทื ื– ืคึฟืึทืจ ืžืึทื•ื ื˜ื™ื ื’ / ืฉื˜ื™ื•ื•ืœ, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื˜ื™ื•ื•ืœ ืžื™ื˜ ืึท ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’ ืื™ืŸ ืึธื•ื•ื•ืขืจืœื™ื™ืคืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื ื™ื™ึทืข ืกืขื˜ื˜ื™ื ื’ืก ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืขื ืข ื˜ื™ื™ืคึผืก ืคื•ืŸ ื•ื ื™ืฅ.

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • systemd-networkd ื’ื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืœ2ื˜ืคึผ ื˜ืึทื ืึทืœื–;
  • sd-boot ืื•ืŸ bootctl ืฆื•ืฉื˜ืขืœืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ XBOOTLDR (ืขืงืกื˜ืขื ื“ืขื“ ื‘ืึธืึธื˜ ืœืึธื•ื“ืขืจ) ืคึผืึทืจื˜ื™ืฉืึทื ื– ื“ื™ื–ื™ื™ื ื“ ืฆื• ื–ื™ื™ืŸ ืžืึธื•ื ื˜ืขื“ ืื•ื™ืฃ / ืฉื˜ื™ื•ื•ืœ, ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ESP ืคึผืึทืจื˜ื™ืฉืึทื ื– ืžืึธื•ื ื˜ืขื“ ืื•ื™ืฃ / ืขืคื™ ืึธื“ืขืจ / ื‘ืึธืึธื˜ / ืขืคื™. ืงืขืจื ืขืœืก, ืกืขื˜ื˜ื™ื ื’ืก, ื™ื ื™ื˜ืจื“ ืื•ืŸ EFI ื‘ื™ืœื“ืขืจ ืงืขื ืขืŸ ืื™ืฆื˜ ื–ื™ื™ืŸ ื‘ื•ื˜ื™ื“ ืคึฟื•ืŸ ื‘ื™ื™ื“ืข ESP ืื•ืŸ XBOOTLDR ืคึผืึทืจื˜ื™ืฉืึทื ื–. ื“ืขืจ ืขื ื“ืขืจื•ื ื’ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ ื“ื™ sd-boot bootloader ืื™ืŸ ืžืขืจ ืงืึธื ืกืขืจื•ื•ืึทื˜ื™ื•ื•ืข ืกื™ื ืขืจื™ืึธื•ื–, ื•ื•ืขืŸ ื“ื™ ื‘ืึธืึธื˜ืœืึธืึทื“ืขืจ ื–ื™ืš ืื™ื– ืœื™ื’ืŸ ืื™ืŸ ื“ื™ ESP, ืื•ืŸ ื“ื™ ืœืึธื•ื“ื™ื“ ืงืขืจื ืึทืœื– ืื•ืŸ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžืขื˜ืึทื“ืึทื˜ืึท ื–ืขื ืขืŸ ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืึธืคึผื˜ื™ื™ืœื•ื ื’;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื˜ื™ื•ื•ืœ ืžื™ื˜ ื“ื™ "systemd.volatile=overlay" ืึธืคึผืฆื™ืข ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื• ื“ื™ ืงืขืจืŸ, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’ ืื™ืŸ ืึธื•ื•ื•ืขืจืœื™ื™ืคืก ืื•ืŸ ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ืึท ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื– ื‘ื™ืœื“ ืคื•ืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืžื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืฆื• ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ืŸ tmpfs (ื˜ืฉืึทื ื’ืขืก ืื™ืŸ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื–ืขื ืขืŸ ืคืึทืจืคืึทืœืŸ ื ืึธืš ืึท ืจื™ืกื˜ืึทืจื˜). ืœื•ื™ื˜ ืึทื ืึทืœืึทื“ื–ืฉื™, systemd-nspawn ื”ืื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ "--ื•ื•ืึทืœืึทื˜ืึทืœ = ืึธื•ื•ื•ืขืจืœื™ื™" ืึธืคึผืฆื™ืข ืฆื• ื ื•ืฆืŸ ืขื ืœืขืš ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–;
  • systemd-nspawn ื”ืื˜ ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ "--oci-bundle" ืึธืคึผืฆื™ืข ืฆื• ืœืึธื–ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืจื•ื ื˜ื™ืžืข ื‘ืึทื ื“ืึทืœื– ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื˜ืขืจ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื•ื•ืึธืก ื ืึธื›ืงื•ืžืขืŸ ืžื™ื˜ ื“ื™ ืกืคึผืขืกืึทืคืึทืงื™ื™ืฉืึทื ื– ืคื•ืŸ Open Container Initiative (OCI). ืคึฟืึทืจ ื ื•ืฆืŸ ืื™ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืื•ืŸ nspawn ื•ื ื™ืฅ, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืŸ ืึธืคึผืฆื™ืขืก ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ ื“ื™ OCI ืกืคึผืขืกื™ืคื™ืงืึทื˜ื™ืึธืŸ ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ื™ "--ื™ื ืึทืงืกืขืกืึทื‘ืึทืœ" ืื•ืŸ "ื™ื ืึทืงืกืขืกืึทื‘ืึทืœ" ืึธืคึผืฆื™ืขืก ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื•ื™ืกืฉืœื™ืกืŸ ื˜ื™ื™ืœืŸ ืคื•ืŸ ื“ืขืจ ื˜ืขืงืข ืกื™ืกื˜ืขื, ืื•ืŸ ื“ื™ " --ืงืึธื ืกืึธืœืข" ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื ืึธืจืžืึทืœ ืจืขื–ื•ืœื˜ืึทื˜ ืกื˜ืจื™ืžื– ืื•ืŸ "-ืจืขืจ";
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ systemd-login ื“ื•ืจืš ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื–: $SYSTEMD_REBOOT_ TO_FIRMWARE_SETUP,
    $SYSTEMD_REBOOT_TO_BOOT_LOADER_MENU ืื•ืŸ
    $SYSTEMD_REBOOT_ TO_BOOT_LOADER_ENTRY. ืžื™ื˜ ื“ื™ ื•ื•ืขืจื™ืึทื‘ืึทืœื–, ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืจืขื‘ืึธืึธื˜ ืคึผืจืึธืฆืขืก ื”ืึทื ื“ืœืขืจืก (/run/systemd/reboot-to-firmware-setup, /run/systemd/reboot-to-boot-loader-menu ืื•ืŸ
    /run/systemd/reboot-to-boot-loader-entry) ืึธื“ืขืจ ื“ื™ืกื™ื™ื‘ืึทืœ ื–ื™ื™ ื‘ืขืกืึทื›ืึทืงืœ (ืื•ื™ื‘ ื“ื™ ื•ื•ืขืจื˜ ืื™ื– ื‘ืึทืฉื˜ื™ืžื˜ ืฆื• ืคืึทืœืฉ);

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึธืคึผืฆื™ืขืก "-boot-load-menu =" ืื•ืŸ
    "-boot-loader-entry =", ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืฉื˜ื™ื•ื•ืœ ืžืขื ื™ื• ื ื•ืžืขืจ ืึธื“ืขืจ ืฉื˜ื™ื•ื•ืœ ืžืึธื“ืข ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜;

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึท ื–ืึทืžื“ืงืึทืกื˜ืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื‘ืึทืคึฟืขืœ "RestrictSUIDSGID =", ื•ื•ืึธืก ื ื™ืฆื˜ ืกืขืงืึธืžืคึผ ืฆื• ืคืึทืจื•ื•ืขืจืŸ ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื˜ืขืงืขืก ืžื™ื˜ SUID / SGID ืคืœืึทื’ืก;
  • ื™ื ืฉื•ืจื“ ืึทื– ื“ื™ "NoNewPrivileges" ืื•ืŸ "RestrictSUIDSGID" ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขื•ื•ืขื ื“ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ืžื™ื˜ ื“ื™ ื“ื™ื ืึทืžื™ืฉ ื‘ืึทื ื™ืฆืขืจ ืฉื™ื™ึทืŸ ื“ื•ืจ ืžืึธื“ืข ("DynamicUser" ืขื ื™ื™ื‘ืึทืœื“);
  • ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ MACAddressPolicy = ืคึผืขืจืกื™ืกื˜ืขื ื˜ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ .ืœื™ื ืง ื˜ืขืงืขืก ืื™ื– ืคืืจืขื ื“ืขืจื˜ ืฆื• ื“ืขืงืŸ ืžืขืจ ื“ืขื•ื•ื™ืกืขืก. ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืคื•ืŸ ื ืขืฅ ื‘ืจื™ืงืŸ, ื˜ืึทื ืึทืœื– (ื˜ื•ืŸ, ืฆืึทืคึผืŸ) ืื•ืŸ ืึทื’ืจืึทื’ื™ื™ื˜ืึทื“ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ (ื‘ื•ื ื“) ื˜ืึธืŸ ื ื™ื˜ ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื–ื™ืš ืึทื—ื•ืฅ ื“ื•ืจืš ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“, ืึทื–ื•ื™ ื“ืขื ื ืึธืžืขืŸ ืื™ื– ืื™ืฆื˜ ื’ืขื ื™ืฆื˜ ื•ื•ื™ ื“ื™ ื™ืงืขืจ ืคึฟืึทืจ ื‘ื™ื™ื ื“ื™ื ื’ MAC ืื•ืŸ IPv4 ืึทื“ืจืขืกืขืก. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ "MACAddressPolicy = ื˜ืจืึทืค" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื‘ื™ื ื“ืŸ MAC ืื•ืŸ IPv4 ืึทื“ืจืขืกืขืก ืฆื• ื“ืขื•ื•ื™ืกืขืก ืื™ืŸ ืึท ื˜ืจืึทืค - ืกื“ืจ;
  • ".device" ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš systemd-fstab-generator ื ื™ื˜ ืžืขืจ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ".mount" ื•ื ื™ืฅ ื•ื•ื™ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืื™ืŸ ื“ื™ "ื•ื•ืึทื ืฅ =" ืึธืคึผื˜ื™ื™ืœื•ื ื’. ืกื™ืžืคึผืœื™ ืคึผืœืึทื’ื™ื ื’ ืึท ืžื™ื˜ืœ ื ื™ื˜ ืžืขืจ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœืึธื ื˜ืฉื™ื– ืึท ืึทืคึผืึทืจืึทื˜ ืฆื• ืึธื ืงืœืึทืคึผืŸ, ืึธื‘ืขืจ ืึทื–ืึท ื•ื ื™ืฅ ืงืขื ืขืŸ ื ืึธืš ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜ ืคึฟืึทืจ ืื ื“ืขืจืข ืกื™ื‘ื•ืช, ืึทื–ืึท ื•ื•ื™ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ local-fs.target ืึธื“ืขืจ ื•ื•ื™ ืึท ื“ืขืคึผืขื ื“ืขื ืกื™ ืื•ื™ืฃ ืื ื“ืขืจืข ื•ื ื™ืฅ ื•ื•ืึธืก ืึธืคืขื ื’ืขืŸ ืื•ื™ืฃ local-fs.target ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืžืึทืกืงืก ("*", ืืื–"ื• ื•) ืฆื• ื“ื™ "ื ืขื˜ื•ื•ืึธืจืงืงื˜ืœ ืจืฉื™ืžื” / ืกื˜ืึทื˜ื•ืก / ืœืœื“ืคึผ" ืงืึทืžืึทื ื“ื– ืฆื• ืคื™ืœื˜ืขืจ ืื•ื™ืก ื–ื™ื›ืขืจ ื’ืจื•ืคึผืขืก ืคื•ืŸ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื“ื•ืจืš ื˜ื™ื™ืœ ืคื•ืŸ ื–ื™ื™ืขืจ ื ืึธืžืขืŸ;
  • ื“ื™ $ PIDFILE ื™ื ื•ื•ื™ื™ืจืึทื ืžืขื ืึทืœ ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง ืื™ื– ืื™ืฆื˜ ื‘ืึทืฉื˜ื™ืžื˜ ื ื™ืฆืŸ ื“ื™ ืึทื‘ืกืึธืœื•ื˜ ื“ืจืš ืงืึทื ืคื™ื’ื™ืขืจื“ ืื™ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ื“ื•ืจืš ื“ื™ "PIDFile =;" ืคึผืึทืจืึทืžืขื˜ืขืจ.
  • ืคึผื•ื‘ืœื™ืง ืงืœืึธื•ื“ืคืœืึทืจืข ืกืขืจื•ื•ืขืจืก (1.1.1.1) ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื‘ืึทืงืึทืคึผ ื“ื ืก ืกืขืจื•ื•ืขืจืก ื’ืขื ื™ืฆื˜ ืื•ื™ื‘ ื“ื™ ื”ื•ื™ืคึผื˜ ื“ื ืก ืื™ื– ื ื™ืฉื˜ ื‘ืคื™ืจื•ืฉ ื“ื™ืคื™ื™ื ื“. ืฆื• ืจื™ื“ื™ืคื™ื™ืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ื‘ืึทืงืึทืคึผ ื“ื ืก ืกืขืจื•ื•ืขืจืก, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ "-Ddns-servers =" ืึธืคึผืฆื™ืข;
  • ื•ื•ืขืŸ ื“ื™ื˜ืขืงื˜ื™ื ื’ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ื•ืกื‘ ื“ื™ื•ื•ื™ื™ืก ืงืึธื ื˜ืจืึธืœืœืขืจ, ืึท ื ื™ื™ึท usb-gadget.target ื”ืึทื ื“ืœืขืจ ืื™ื– ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœืึธื ื˜ืฉื˜ (ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ ืึท ื•ืกื‘ ืคึผืขืจื™ืคืขืจืึทืœ ืžื™ื˜ืœ);
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "CPUQuotaPeriodSec =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ื“ื™ื˜ืขืจืžืึทื ื– ื“ื™ ืฆื™ื™ื˜ ืคึผืขืจื™ืึธื“ ืฆื• ื•ื•ืึธืก ื“ื™ ืงืคึผื• ืฆื™ื™ื˜ ืงื•ื•ืึธื˜ืข ืื™ื– ื’ืขืžืืกื˜ืŸ, ืฉื˜ืขืœืŸ ื“ื•ืจืš ื“ื™ "CPUQuota =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ;
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "ProtectHostname =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ืคึผืจืึธื•ื›ื™ื‘ืึทืฅ ื‘ืึทื“ื™ื ื•ื ื’ืก ืคื•ืŸ ื˜ืฉืึทื ื’ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื‘ืึทืœืขื‘ืึธืก ื ืึธืžืขืŸ, ืืคื™ืœื• ืื•ื™ื‘ ื–ื™ื™ ื”ืึธื‘ืŸ ื“ื™ ืฆื•ื ืขืžืขืŸ ืคึผืขืจืžื™ืฉืึทื ื–;
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "NetworkNamespacePath =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื ื“ืŸ ืึท ื ืึทืžืขืกืคึผืึทืกืข ืฆื• ื‘ืึทื“ื™ื ื•ื ื’ืก ืึธื“ืขืจ ื›ืึธืœืขืœ ื•ื ื™ืฅ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื“ืจืš ืฆื• ื“ื™ ื ืึทืžืขืกืคึผืึทืกืข ื˜ืขืงืข ืื™ืŸ ื“ื™ ืคึผืกืขื•ื•ื“ืึธ-ืคืก / ืคึผืจืึธืง;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื– ืคึฟืึทืจ ืคึผืจืึทืกืขืกืึทื– ืœืึธื ื˜ืฉื˜ ืžื™ื˜ ื“ื™ "ExecStart =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื•ืจืš ืึทื“ื™ื ื’ ืึท ":" ื›ืึทืจืึทืงื˜ืขืจ ืื™ื™ื“ืขืจ ื“ื™ ืึธื ื”ื™ื™ื‘ ื‘ืึทืคึฟืขืœ;
  • ืคึฟืึทืจ ื˜ื™ื™ืžืขืจื– (.ื˜ื™ื™ืžืขืจ ื•ื ื™ืฅ) ื ื™ื™ึท ืคืœืึทื’ืก "ืึธื ืงืœืึธืงืงื˜ืฉืึทื ื’ืข =" ืื•ืŸ
    "OnTimezoneChange =", ืžื™ื˜ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึทืคึผืึทืจืึทื˜ ืจื•ืคืŸ ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ืฆื™ื™ื˜ ืึธื“ืขืจ ืฆื™ื™ื˜ ื–ืึธื ืข ืขื ื“ืขืจื•ื ื’ืขืŸ;

  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื ื™ื™ึทืข ืกืขื˜ื˜ื™ื ื’ืก "ConditionMemory =" ืื•ืŸ "ConditionCPUs =", ื•ื•ืึธืก ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืคึฟืึทืจ ืจื•ืคืŸ ืึท ืึทืคึผืึทืจืึทื˜ ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื–ื™ืงืึธืจืŸ ื’ืจื™ื™ืก ืื•ืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืงืคึผื• ืงืึธืจืขืก (ืœืžืฉืœ, ืึท ืžื™ื˜ืœ-ืื™ื ื˜ืขื ืกื™ื•ื•ืข ื“ื™ื ืกื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜ ื‘ืœื•ื™ื– ืื•ื™ื‘ ื“ื™ ืคืืจืœืื ื’ื˜ ืกื•ืžืข ืคื•ืŸ ื‘ืึทืจืึทืŸ ืื™ื– ื‘ื ื™ืžืฆื);
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึทืข ืฆื™ื™ื˜-ืกืขื˜.ื˜ืึทืจื’ืขื˜ ืึทืคึผืึทืจืึทื˜ ื•ื•ืึธืก ืึทืงืกืขืคึผืฅ ื“ื™ ืœืึธื•ืงืึทืœื™ ื‘ืึทืฉื˜ื™ืžื˜ ืกื™ืกื˜ืขื ืฆื™ื™ื˜, ืึธืŸ ื ื™ืฆืŸ ื•ื™ืกื’ืœื™ื™ึทืš ืžื™ื˜ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืฆื™ื™ื˜ ืกืขืจื•ื•ืขืจืก ื ื™ืฆืŸ ื“ื™ Time-sync.target ืึทืคึผืึทืจืึทื˜. ื“ื™ ื ื™ื™ึทืข ืึทืคึผืึทืจืึทื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืกืขืจื•ื•ื™ืกืขืก ื•ื•ืึธืก ื“ืึทืจืคึฟืŸ ื“ื™ ืึทืงื™ืขืจืึทืกื™ ืคื•ืŸ ืึทื ืกื™ื ื˜ืฉืจืึธื ื™ื–ืขื“ ื”ื™ื’ืข ืงืœืึทืงืก;
  • ื“ื™ "--ื•ื•ื™ื™ึทื–ืŸ-ื˜ืจืึทื ื–ืึทืงืฉืึทืŸ" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• "ืกื™ืกื˜ืขืžืงื˜ืœ ืึธื ื”ื™ื™ื‘" ืื•ืŸ ืขื ืœืขืš ืงืึทืžืึทื ื“ื–, ื•ื•ืขืŸ ืกืคึผืขืกื™ืคื™ืขื“, ืึท ืงื™ืฆืขืจ ืคื•ืŸ ืึทืœืข ื“ื–ืฉืึธื‘ืก ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ืจื™ื™ ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขื‘ืขื˜ืŸ ืึธืคึผืขืจืึทืฆื™ืข ืื™ื– ื’ืขื•ื•ื™ื–ืŸ;
  • systemd-networkd ื™ืžืคึผืœืึทืžืึทื ืฅ ื“ื™ ื“ืขืคึฟื™ื ื™ืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืึท ื ื™ื™ึทืข 'ืขื ืกืœื™ื™ื•ื•ื“' ืฉื˜ืึทื˜, ื’ืขื•ื•ื™ื™ื ื˜ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ 'ื“ื™ื’ืจื™ื™ื“ื™ื“' ืึธื“ืขืจ 'ื˜ืจืขื’ืขืจ' ืคึฟืึทืจ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ืึธืก ื–ืขื ืขืŸ ื˜ื™ื™ืœ ืคื•ืŸ ื’ืขืžื™ื™ื ื–ืึทื ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืึธื“ืขืจ ื ืขืฅ ื‘ืจื™ืงืŸ. ืคึฟืึทืจ ืขืจืฉื˜ื™ืง ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืžืคึผืึธืกื™ื˜ืข ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ, ื“ื™ 'ื“ื™ื’ืจื™ื™ื“-ื˜ืจืขื’ืขืจ' ืฉื˜ืึทื˜ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ;
  • "IgnoreCarrierLoss =" ืึธืคึผืฆื™ืข ืฆื• .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื ืขืฅ ืกืขื˜ื˜ื™ื ื’ืก ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืงืฉืจ ืึธื ื•ื•ืขืจ;
  • ื“ื•ืจืš ื“ื™ "RequiredForOnline =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ืื™ืจ ืงืขื ืขืŸ ืื™ืฆื˜ ืฉื˜ืขืœืŸ ื“ื™ ืžื™ื ื™ืžื•ื ืคึผืึทืกื™ืง ืœื™ื ืง ืฉื˜ืึทื˜ ืคืืจืœืื ื’ื˜ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืฆื• "ืึธื ืœื™ื™ืŸ" ืื•ืŸ ืฆื™ื ื’ืœ ื“ื™ systemd-networkd-wait-online ื”ืึทื ื“ืœืขืจ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ "--ืึทื ื™" ืึธืคึผืฆื™ืข ืฆื• systemd-networkd-wait-online ืฆื• ื•ื•ืึทืจื˜ืŸ ืคึฟืึทืจ ื“ื™ ื’ืจื™ื™ื˜ืงื™ื™ึทื˜ ืคื•ืŸ ืงื™ื™ืŸ ืคื•ืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืึทืœืข, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ "--ืึทืคึผืขืจื™ื™ืฉืึทื ืึทืœ-ืฉื˜ืึทื˜ =" ืึธืคึผืฆื™ืข ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืœื™ื ืง ื•ื•ืึธืก ื™ื ื“ื™ืงื™ื™ืฅ ื’ืจื™ื™ื˜ืงื™ื™ึทื˜;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ "UseAutonomousPrefix=" ืื•ืŸ "UseOnLinkPrefix =" ืกืขื˜ื˜ื™ื ื’ืก ืฆื• .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืื™ื’ื ืึธืจื™ืจืŸ ืคึผืจืขืคื™ืงืก ื•ื•ืขืŸ ืจื™ืกื™ื•ื•ื™ื ื’
    ืžืขืœื“ืŸ ืคื•ืŸ ืึทืŸ IPv6 ืจืึทื•ื˜ืขืจ (ืจืึท, ืจืึทื•ื˜ืขืจ ืึทื“);

  • ืื™ืŸ .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก "MulticastFlood=", "NeighborSuppression=" ืื•ืŸ "Learning=" ื–ืขื ืขืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืคื•ืŸ ื“ื™ ื ืขืฅ ื‘ืจื™ืง, ืื•ืŸ ื“ื™ "TripleSampling=" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ื“ืจื™ื™ึทื™ืง ืžื•ืกื˜ืขืจื•ื ื’ ืžืึธื“ืข. ืคื•ืŸ CAN ื•ื•ื™ืจื˜ื•ืึทืœ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • "PrivateKeyFile =" ืื•ืŸ "PresharedKeyFile =" ืกืขื˜ื˜ื™ื ื’ืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• .ื ืขื˜ื“ืขื•ื• ื•ื ื™ืฅ, ืžื™ื˜ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืคึผืจื™ื•ื•ืึทื˜ ืื•ืŸ ืฉืขืจื“ (PSK) ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ WireGuard VPN ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • ื“ื™ ื–ืขืœื‘ืข-ืงืคึผื•-ืงืจื™ืคึผื˜ ืื•ืŸ ืคืึธืจืœื™ื™ื’ืŸ-ืคื•ืŸ-crypt-cpus ืึธืคึผืฆื™ืขืก ืฆื• /etc/crypttab, ื•ื•ืึธืก ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืกืงืขื“ื–ืฉื•ืœืขืจ ื•ื•ืขืŸ ืžื™ื™ื’ืจื™ื™ื˜ื™ื ื’ ืขื ืงืจื™ืคึผืฉืึทืŸ-ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืึทืจื‘ืขื˜ ืฆื•ื•ื™ืฉืŸ ืงืคึผื• ืงืึธืจืขืก;
  • systemd-tmpfiles ืคึผืจืึธื•ื•ื™ื“ืขืก ืฉืœืึธืก ื˜ืขืงืข ืคึผืจืึทืกืขืกื™ื ื’ ืื™ื™ื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ืึทืคึผืขืจื™ื™ืฉืึทื ื– ืื™ืŸ ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ืžื™ื˜ ืฆื™ื™ึทื˜ื•ื•ื™ื™ึทืœื™ืง ื˜ืขืงืขืก, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืจื™ื™ื ื™ืงื•ื ื’ ืึทื•ื˜ื“ื™ื™ื˜ื™ื“ ื˜ืขืงืขืก ืคึฟืึทืจ ื“ืขืจ ื’ืขื“ื•ื™ืขืจ ืคื•ืŸ ื–ื™ื›ืขืจ ืึทืงืฉืึทื ื– (ืœืžืฉืœ, ื•ื•ืขืŸ ืึทื ืคึผืึทืงื™ื ื’ ืึท ื˜ืึทืจ ืึทืจืงื™ื™ื•ื• ืื™ืŸ / ื˜ืžืคึผ, ื–ื™ื™ืขืจ ืึทืœื˜ ื˜ืขืงืขืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขืขืคื ื˜ ื•ื•ืึธืก ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื•ื™ืกืžืขืงืŸ ืื™ื™ื“ืขืจ ื“ื™ ืกื•ืฃ ืคื•ืŸ ื“ื™ ืึทืงืฆื™ืข ืžื™ื˜ ื–ื™ื™);
  • ื“ื™ "ืกื™ืกื˜ืขื-ืึทื ืึทืœื™ื–ืข ืงืึทื˜-ืงืึธื ืคื™ื’" ื‘ืึทืคึฟืขืœ ื’ื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ืขื˜ืœืขื›ืข ื˜ืขืงืขืก, ืœืžืฉืœ, ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ืกื™ืกื˜ืขื ืคึผืจืขืกืขืฅ, ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ tmpfiles.d ืื•ืŸ sysusers.d, udev ื›ึผืœืœื™ื, ืขื˜ืง.
  • ืฆื•ื’ืขื’ืขื‘ืŸ "--cursor-file=" ืึธืคึผืฆื™ืข ืฆื• "ื–ืฉื•ืจื ืึทืœืงื˜ืœ" ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ื˜ืขืงืข ืฆื• ืžืึทืกืข ืื•ืŸ ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ืฉื˜ืขืœืข ืœื•ื™ืคึฟืขืจ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ืขืคึฟื™ื ื™ืฆื™ืข ืคื•ืŸ โ€‹โ€‹ACRN ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ืื•ืŸ WSL ืกื•ื‘ืกื™ืกื˜ืขื (ื•ื•ื™ื ื“ืึธื•ื– ืกื•ื‘ืกื™ืกื˜ืขื ืคึฟืึทืจ ืœื™ื ื•ืงืก) ืฆื• ืกื™ืกื˜ืขืž-ื“ืขื˜ืขืงื˜-ื•ื•ื™ืจื˜ ืคึฟืึทืจ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ื‘ืจืึทื ื˜ืฉื™ื ื’ ื ื™ืฆืŸ ื“ื™ ืงืึทื ื“ื™ืฉืึทื ืึทืœ ืึธืคึผืขืจืึทื˜ืึธืจ "ืงืึธื ื“ื™ื˜ื™ืึธืŸ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ";
  • ื‘ืขืฉืึทืก ืกื™ืกื˜ืขืž ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ (ื•ื•ืขืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ "ื ื™ื ื“ื–ืฉืึท ื™ื ืกื˜ืึทืœื™ืจืŸ"), ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ืกื™ืžื‘ืึธืœื™ืฉ ืœื™ื ืงืก ืฆื• ื“ื™ ื˜ืขืงืขืก systemd-networkd.service, systemd-networkd.socket,
    systemd-resolved.service, remote-cryptsetup.target, remote-fs.target,
    systemd-networkd-wait-online.service ืื•ืŸ systemd-timesyncd.service. ืฆื• ืฉืึทืคึฟืŸ ื“ื™ ื˜ืขืงืขืก, ืื™ืจ ืื™ืฆื˜ ื“ืึทืจืคึฟืŸ ืฆื• ืœื•ื™ืคืŸ ื“ื™ "ืกื™ืกื˜ืขืžืงื˜ืœ ืคึผืจื™ืกืขื˜-ืึทืœืข" ื‘ืึทืคึฟืขืœ.

ืžืึธืงืขืจopennet.ru

[: en]

ื ืึธืš ืฆื•ื•ื™ื™ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื“ืขืจืœืื ื’ื˜ ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืžืขืœื“ื•ื ื’ ืกื™ืกื˜ืขื 242. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื–, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ L2TP ื˜ืึทื ืึทืœื–, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ืกื™ืกื˜ืขืž-ืœืึธื’ื™ืŸ ืื•ื™ืฃ ืจื™ืกื˜ืึทืจื˜ ื“ื•ืจืš ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื–, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืขืงืกื˜ืขื ื“ืขื“ XBOOTLDR ืฉื˜ื™ื•ื•ืœ ืคึผืึทืจื˜ื™ืฉืึทื ื– ืคึฟืึทืจ ืžืึทื•ื ื˜ื™ื ื’ / ืฉื˜ื™ื•ื•ืœ, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื˜ื™ื•ื•ืœ ืžื™ื˜ ืึท ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’ ืื™ืŸ ืึธื•ื•ื•ืขืจืœื™ื™ืคืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื ื™ื™ึทืข ืกืขื˜ื˜ื™ื ื’ืก ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืขื ืข ื˜ื™ื™ืคึผืก ืคื•ืŸ ื•ื ื™ืฅ.

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • systemd-networkd ื’ื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืœ2ื˜ืคึผ ื˜ืึทื ืึทืœื–;
  • sd-boot ืื•ืŸ bootctl ืฆื•ืฉื˜ืขืœืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ XBOOTLDR (ืขืงืกื˜ืขื ื“ืขื“ ื‘ืึธืึธื˜ ืœืึธื•ื“ืขืจ) ืคึผืึทืจื˜ื™ืฉืึทื ื– ื“ื™ื–ื™ื™ื ื“ ืฆื• ื–ื™ื™ืŸ ืžืึธื•ื ื˜ืขื“ ืื•ื™ืฃ / ืฉื˜ื™ื•ื•ืœ, ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ESP ืคึผืึทืจื˜ื™ืฉืึทื ื– ืžืึธื•ื ื˜ืขื“ ืื•ื™ืฃ / ืขืคื™ ืึธื“ืขืจ / ื‘ืึธืึธื˜ / ืขืคื™. ืงืขืจื ืขืœืก, ืกืขื˜ื˜ื™ื ื’ืก, ื™ื ื™ื˜ืจื“ ืื•ืŸ EFI ื‘ื™ืœื“ืขืจ ืงืขื ืขืŸ ืื™ืฆื˜ ื–ื™ื™ืŸ ื‘ื•ื˜ื™ื“ ืคึฟื•ืŸ ื‘ื™ื™ื“ืข ESP ืื•ืŸ XBOOTLDR ืคึผืึทืจื˜ื™ืฉืึทื ื–. ื“ืขืจ ืขื ื“ืขืจื•ื ื’ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ ื“ื™ sd-boot bootloader ืื™ืŸ ืžืขืจ ืงืึธื ืกืขืจื•ื•ืึทื˜ื™ื•ื•ืข ืกื™ื ืขืจื™ืึธื•ื–, ื•ื•ืขืŸ ื“ื™ ื‘ืึธืึธื˜ืœืึธืึทื“ืขืจ ื–ื™ืš ืื™ื– ืœื™ื’ืŸ ืื™ืŸ ื“ื™ ESP, ืื•ืŸ ื“ื™ ืœืึธื•ื“ื™ื“ ืงืขืจื ืึทืœื– ืื•ืŸ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžืขื˜ืึทื“ืึทื˜ืึท ื–ืขื ืขืŸ ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืึธืคึผื˜ื™ื™ืœื•ื ื’;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื˜ื™ื•ื•ืœ ืžื™ื˜ ื“ื™ "systemd.volatile=overlay" ืึธืคึผืฆื™ืข ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื• ื“ื™ ืงืขืจืŸ, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’ ืื™ืŸ ืึธื•ื•ื•ืขืจืœื™ื™ืคืก ืื•ืŸ ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ืึท ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื– ื‘ื™ืœื“ ืคื•ืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืžื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืฆื• ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ืŸ tmpfs (ื˜ืฉืึทื ื’ืขืก ืื™ืŸ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื–ืขื ืขืŸ ืคืึทืจืคืึทืœืŸ ื ืึธืš ืึท ืจื™ืกื˜ืึทืจื˜). ืœื•ื™ื˜ ืึทื ืึทืœืึทื“ื–ืฉื™, systemd-nspawn ื”ืื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ "--ื•ื•ืึทืœืึทื˜ืึทืœ = ืึธื•ื•ื•ืขืจืœื™ื™" ืึธืคึผืฆื™ืข ืฆื• ื ื•ืฆืŸ ืขื ืœืขืš ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–;
  • systemd-nspawn ื”ืื˜ ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ "--oci-bundle" ืึธืคึผืฆื™ืข ืฆื• ืœืึธื–ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืจื•ื ื˜ื™ืžืข ื‘ืึทื ื“ืึทืœื– ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื˜ืขืจ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื•ื•ืึธืก ื ืึธื›ืงื•ืžืขืŸ ืžื™ื˜ ื“ื™ ืกืคึผืขืกืึทืคืึทืงื™ื™ืฉืึทื ื– ืคื•ืŸ Open Container Initiative (OCI). ืคึฟืึทืจ ื ื•ืฆืŸ ืื™ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืื•ืŸ nspawn ื•ื ื™ืฅ, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืŸ ืึธืคึผืฆื™ืขืก ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ ื“ื™ OCI ืกืคึผืขืกื™ืคื™ืงืึทื˜ื™ืึธืŸ ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ื™ "--ื™ื ืึทืงืกืขืกืึทื‘ืึทืœ" ืื•ืŸ "ื™ื ืึทืงืกืขืกืึทื‘ืึทืœ" ืึธืคึผืฆื™ืขืก ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื•ื™ืกืฉืœื™ืกืŸ ื˜ื™ื™ืœืŸ ืคื•ืŸ ื“ืขืจ ื˜ืขืงืข ืกื™ืกื˜ืขื, ืื•ืŸ ื“ื™ " --ืงืึธื ืกืึธืœืข" ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื ืึธืจืžืึทืœ ืจืขื–ื•ืœื˜ืึทื˜ ืกื˜ืจื™ืžื– ืื•ืŸ "-ืจืขืจ";
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ systemd-login ื“ื•ืจืš ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื–: $SYSTEMD_REBOOT_ TO_FIRMWARE_SETUP,
    $SYSTEMD_REBOOT_TO_BOOT_LOADER_MENU ืื•ืŸ
    $SYSTEMD_REBOOT_ TO_BOOT_LOADER_ENTRY. ืžื™ื˜ ื“ื™ ื•ื•ืขืจื™ืึทื‘ืึทืœื–, ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืจืขื‘ืึธืึธื˜ ืคึผืจืึธืฆืขืก ื”ืึทื ื“ืœืขืจืก (/run/systemd/reboot-to-firmware-setup, /run/systemd/reboot-to-boot-loader-menu ืื•ืŸ
    /run/systemd/reboot-to-boot-loader-entry) ืึธื“ืขืจ ื“ื™ืกื™ื™ื‘ืึทืœ ื–ื™ื™ ื‘ืขืกืึทื›ืึทืงืœ (ืื•ื™ื‘ ื“ื™ ื•ื•ืขืจื˜ ืื™ื– ื‘ืึทืฉื˜ื™ืžื˜ ืฆื• ืคืึทืœืฉ);

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึธืคึผืฆื™ืขืก "-boot-load-menu =" ืื•ืŸ
    "-boot-loader-entry =", ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืฉื˜ื™ื•ื•ืœ ืžืขื ื™ื• ื ื•ืžืขืจ ืึธื“ืขืจ ืฉื˜ื™ื•ื•ืœ ืžืึธื“ืข ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜;

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึท ื–ืึทืžื“ืงืึทืกื˜ืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื‘ืึทืคึฟืขืœ "RestrictSUIDSGID =", ื•ื•ืึธืก ื ื™ืฆื˜ ืกืขืงืึธืžืคึผ ืฆื• ืคืึทืจื•ื•ืขืจืŸ ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื˜ืขืงืขืก ืžื™ื˜ SUID / SGID ืคืœืึทื’ืก;
  • ื™ื ืฉื•ืจื“ ืึทื– ื“ื™ "NoNewPrivileges" ืื•ืŸ "RestrictSUIDSGID" ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขื•ื•ืขื ื“ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ืžื™ื˜ ื“ื™ ื“ื™ื ืึทืžื™ืฉ ื‘ืึทื ื™ืฆืขืจ ืฉื™ื™ึทืŸ ื“ื•ืจ ืžืึธื“ืข ("DynamicUser" ืขื ื™ื™ื‘ืึทืœื“);
  • ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ MACAddressPolicy = ืคึผืขืจืกื™ืกื˜ืขื ื˜ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ .ืœื™ื ืง ื˜ืขืงืขืก ืื™ื– ืคืืจืขื ื“ืขืจื˜ ืฆื• ื“ืขืงืŸ ืžืขืจ ื“ืขื•ื•ื™ืกืขืก. ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืคื•ืŸ ื ืขืฅ ื‘ืจื™ืงืŸ, ื˜ืึทื ืึทืœื– (ื˜ื•ืŸ, ืฆืึทืคึผืŸ) ืื•ืŸ ืึทื’ืจืึทื’ื™ื™ื˜ืึทื“ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ (ื‘ื•ื ื“) ื˜ืึธืŸ ื ื™ื˜ ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื–ื™ืš ืึทื—ื•ืฅ ื“ื•ืจืš ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“, ืึทื–ื•ื™ ื“ืขื ื ืึธืžืขืŸ ืื™ื– ืื™ืฆื˜ ื’ืขื ื™ืฆื˜ ื•ื•ื™ ื“ื™ ื™ืงืขืจ ืคึฟืึทืจ ื‘ื™ื™ื ื“ื™ื ื’ MAC ืื•ืŸ IPv4 ืึทื“ืจืขืกืขืก. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ "MACAddressPolicy = ื˜ืจืึทืค" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื‘ื™ื ื“ืŸ MAC ืื•ืŸ IPv4 ืึทื“ืจืขืกืขืก ืฆื• ื“ืขื•ื•ื™ืกืขืก ืื™ืŸ ืึท ื˜ืจืึทืค - ืกื“ืจ;
  • ".device" ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš systemd-fstab-generator ื ื™ื˜ ืžืขืจ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ".mount" ื•ื ื™ืฅ ื•ื•ื™ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืื™ืŸ ื“ื™ "ื•ื•ืึทื ืฅ =" ืึธืคึผื˜ื™ื™ืœื•ื ื’. ืกื™ืžืคึผืœื™ ืคึผืœืึทื’ื™ื ื’ ืึท ืžื™ื˜ืœ ื ื™ื˜ ืžืขืจ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœืึธื ื˜ืฉื™ื– ืึท ืึทืคึผืึทืจืึทื˜ ืฆื• ืึธื ืงืœืึทืคึผืŸ, ืึธื‘ืขืจ ืึทื–ืึท ื•ื ื™ืฅ ืงืขื ืขืŸ ื ืึธืš ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜ ืคึฟืึทืจ ืื ื“ืขืจืข ืกื™ื‘ื•ืช, ืึทื–ืึท ื•ื•ื™ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ local-fs.target ืึธื“ืขืจ ื•ื•ื™ ืึท ื“ืขืคึผืขื ื“ืขื ืกื™ ืื•ื™ืฃ ืื ื“ืขืจืข ื•ื ื™ืฅ ื•ื•ืึธืก ืึธืคืขื ื’ืขืŸ ืื•ื™ืฃ local-fs.target ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืžืึทืกืงืก ("*", ืืื–"ื• ื•) ืฆื• ื“ื™ "ื ืขื˜ื•ื•ืึธืจืงืงื˜ืœ ืจืฉื™ืžื” / ืกื˜ืึทื˜ื•ืก / ืœืœื“ืคึผ" ืงืึทืžืึทื ื“ื– ืฆื• ืคื™ืœื˜ืขืจ ืื•ื™ืก ื–ื™ื›ืขืจ ื’ืจื•ืคึผืขืก ืคื•ืŸ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื“ื•ืจืš ื˜ื™ื™ืœ ืคื•ืŸ ื–ื™ื™ืขืจ ื ืึธืžืขืŸ;
  • ื“ื™ $ PIDFILE ื™ื ื•ื•ื™ื™ืจืึทื ืžืขื ืึทืœ ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง ืื™ื– ืื™ืฆื˜ ื‘ืึทืฉื˜ื™ืžื˜ ื ื™ืฆืŸ ื“ื™ ืึทื‘ืกืึธืœื•ื˜ ื“ืจืš ืงืึทื ืคื™ื’ื™ืขืจื“ ืื™ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ื“ื•ืจืš ื“ื™ "PIDFile =;" ืคึผืึทืจืึทืžืขื˜ืขืจ.
  • ืคึผื•ื‘ืœื™ืง ืงืœืึธื•ื“ืคืœืึทืจืข ืกืขืจื•ื•ืขืจืก (1.1.1.1) ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื‘ืึทืงืึทืคึผ ื“ื ืก ืกืขืจื•ื•ืขืจืก ื’ืขื ื™ืฆื˜ ืื•ื™ื‘ ื“ื™ ื”ื•ื™ืคึผื˜ ื“ื ืก ืื™ื– ื ื™ืฉื˜ ื‘ืคื™ืจื•ืฉ ื“ื™ืคื™ื™ื ื“. ืฆื• ืจื™ื“ื™ืคื™ื™ืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ื‘ืึทืงืึทืคึผ ื“ื ืก ืกืขืจื•ื•ืขืจืก, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ "-Ddns-servers =" ืึธืคึผืฆื™ืข;
  • ื•ื•ืขืŸ ื“ื™ื˜ืขืงื˜ื™ื ื’ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ื•ืกื‘ ื“ื™ื•ื•ื™ื™ืก ืงืึธื ื˜ืจืึธืœืœืขืจ, ืึท ื ื™ื™ึท usb-gadget.target ื”ืึทื ื“ืœืขืจ ืื™ื– ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœืึธื ื˜ืฉื˜ (ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ ืึท ื•ืกื‘ ืคึผืขืจื™ืคืขืจืึทืœ ืžื™ื˜ืœ);
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "CPUQuotaPeriodSec =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ื“ื™ื˜ืขืจืžืึทื ื– ื“ื™ ืฆื™ื™ื˜ ืคึผืขืจื™ืึธื“ ืฆื• ื•ื•ืึธืก ื“ื™ ืงืคึผื• ืฆื™ื™ื˜ ืงื•ื•ืึธื˜ืข ืื™ื– ื’ืขืžืืกื˜ืŸ, ืฉื˜ืขืœืŸ ื“ื•ืจืš ื“ื™ "CPUQuota =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ;
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "ProtectHostname =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ืคึผืจืึธื•ื›ื™ื‘ืึทืฅ ื‘ืึทื“ื™ื ื•ื ื’ืก ืคื•ืŸ ื˜ืฉืึทื ื’ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื‘ืึทืœืขื‘ืึธืก ื ืึธืžืขืŸ, ืืคื™ืœื• ืื•ื™ื‘ ื–ื™ื™ ื”ืึธื‘ืŸ ื“ื™ ืฆื•ื ืขืžืขืŸ ืคึผืขืจืžื™ืฉืึทื ื–;
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื“ื™ "NetworkNamespacePath =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื ื“ืŸ ืึท ื ืึทืžืขืกืคึผืึทืกืข ืฆื• ื‘ืึทื“ื™ื ื•ื ื’ืก ืึธื“ืขืจ ื›ืึธืœืขืœ ื•ื ื™ืฅ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื“ืจืš ืฆื• ื“ื™ ื ืึทืžืขืกืคึผืึทืกืข ื˜ืขืงืข ืื™ืŸ ื“ื™ ืคึผืกืขื•ื•ื“ืึธ-ืคืก / ืคึผืจืึธืง;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื– ืคึฟืึทืจ ืคึผืจืึทืกืขืกืึทื– ืœืึธื ื˜ืฉื˜ ืžื™ื˜ ื“ื™ "ExecStart =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื•ืจืš ืึทื“ื™ื ื’ ืึท ":" ื›ืึทืจืึทืงื˜ืขืจ ืื™ื™ื“ืขืจ ื“ื™ ืึธื ื”ื™ื™ื‘ ื‘ืึทืคึฟืขืœ;
  • ืคึฟืึทืจ ื˜ื™ื™ืžืขืจื– (.ื˜ื™ื™ืžืขืจ ื•ื ื™ืฅ) ื ื™ื™ึท ืคืœืึทื’ืก "ืึธื ืงืœืึธืงืงื˜ืฉืึทื ื’ืข =" ืื•ืŸ
    "OnTimezoneChange =", ืžื™ื˜ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึทืคึผืึทืจืึทื˜ ืจื•ืคืŸ ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ืฆื™ื™ื˜ ืึธื“ืขืจ ืฆื™ื™ื˜ ื–ืึธื ืข ืขื ื“ืขืจื•ื ื’ืขืŸ;

  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื ื™ื™ึทืข ืกืขื˜ื˜ื™ื ื’ืก "ConditionMemory =" ืื•ืŸ "ConditionCPUs =", ื•ื•ืึธืก ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืคึฟืึทืจ ืจื•ืคืŸ ืึท ืึทืคึผืึทืจืึทื˜ ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื–ื™ืงืึธืจืŸ ื’ืจื™ื™ืก ืื•ืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืงืคึผื• ืงืึธืจืขืก (ืœืžืฉืœ, ืึท ืžื™ื˜ืœ-ืื™ื ื˜ืขื ืกื™ื•ื•ืข ื“ื™ื ืกื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜ ื‘ืœื•ื™ื– ืื•ื™ื‘ ื“ื™ ืคืืจืœืื ื’ื˜ ืกื•ืžืข ืคื•ืŸ ื‘ืึทืจืึทืŸ ืื™ื– ื‘ื ื™ืžืฆื);
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึทืข ืฆื™ื™ื˜-ืกืขื˜.ื˜ืึทืจื’ืขื˜ ืึทืคึผืึทืจืึทื˜ ื•ื•ืึธืก ืึทืงืกืขืคึผืฅ ื“ื™ ืœืึธื•ืงืึทืœื™ ื‘ืึทืฉื˜ื™ืžื˜ ืกื™ืกื˜ืขื ืฆื™ื™ื˜, ืึธืŸ ื ื™ืฆืŸ ื•ื™ืกื’ืœื™ื™ึทืš ืžื™ื˜ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืฆื™ื™ื˜ ืกืขืจื•ื•ืขืจืก ื ื™ืฆืŸ ื“ื™ Time-sync.target ืึทืคึผืึทืจืึทื˜. ื“ื™ ื ื™ื™ึทืข ืึทืคึผืึทืจืึทื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืกืขืจื•ื•ื™ืกืขืก ื•ื•ืึธืก ื“ืึทืจืคึฟืŸ ื“ื™ ืึทืงื™ืขืจืึทืกื™ ืคื•ืŸ ืึทื ืกื™ื ื˜ืฉืจืึธื ื™ื–ืขื“ ื”ื™ื’ืข ืงืœืึทืงืก;
  • ื“ื™ "--ื•ื•ื™ื™ึทื–ืŸ-ื˜ืจืึทื ื–ืึทืงืฉืึทืŸ" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• "ืกื™ืกื˜ืขืžืงื˜ืœ ืึธื ื”ื™ื™ื‘" ืื•ืŸ ืขื ืœืขืš ืงืึทืžืึทื ื“ื–, ื•ื•ืขืŸ ืกืคึผืขืกื™ืคื™ืขื“, ืึท ืงื™ืฆืขืจ ืคื•ืŸ ืึทืœืข ื“ื–ืฉืึธื‘ืก ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ืจื™ื™ ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขื‘ืขื˜ืŸ ืึธืคึผืขืจืึทืฆื™ืข ืื™ื– ื’ืขื•ื•ื™ื–ืŸ;
  • systemd-networkd ื™ืžืคึผืœืึทืžืึทื ืฅ ื“ื™ ื“ืขืคึฟื™ื ื™ืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืึท ื ื™ื™ึทืข 'ืขื ืกืœื™ื™ื•ื•ื“' ืฉื˜ืึทื˜, ื’ืขื•ื•ื™ื™ื ื˜ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ 'ื“ื™ื’ืจื™ื™ื“ื™ื“' ืึธื“ืขืจ 'ื˜ืจืขื’ืขืจ' ืคึฟืึทืจ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ืึธืก ื–ืขื ืขืŸ ื˜ื™ื™ืœ ืคื•ืŸ ื’ืขืžื™ื™ื ื–ืึทื ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืึธื“ืขืจ ื ืขืฅ ื‘ืจื™ืงืŸ. ืคึฟืึทืจ ืขืจืฉื˜ื™ืง ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืžืคึผืึธืกื™ื˜ืข ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ, ื“ื™ 'ื“ื™ื’ืจื™ื™ื“-ื˜ืจืขื’ืขืจ' ืฉื˜ืึทื˜ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ;
  • "IgnoreCarrierLoss =" ืึธืคึผืฆื™ืข ืฆื• .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื ืขืฅ ืกืขื˜ื˜ื™ื ื’ืก ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืงืฉืจ ืึธื ื•ื•ืขืจ;
  • ื“ื•ืจืš ื“ื™ "RequiredForOnline =" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ืื™ืจ ืงืขื ืขืŸ ืื™ืฆื˜ ืฉื˜ืขืœืŸ ื“ื™ ืžื™ื ื™ืžื•ื ืคึผืึทืกื™ืง ืœื™ื ืง ืฉื˜ืึทื˜ ืคืืจืœืื ื’ื˜ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืฆื• "ืึธื ืœื™ื™ืŸ" ืื•ืŸ ืฆื™ื ื’ืœ ื“ื™ systemd-networkd-wait-online ื”ืึทื ื“ืœืขืจ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ "--ืึทื ื™" ืึธืคึผืฆื™ืข ืฆื• systemd-networkd-wait-online ืฆื• ื•ื•ืึทืจื˜ืŸ ืคึฟืึทืจ ื“ื™ ื’ืจื™ื™ื˜ืงื™ื™ึทื˜ ืคื•ืŸ ืงื™ื™ืŸ ืคื•ืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืึทืœืข, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ "--ืึทืคึผืขืจื™ื™ืฉืึทื ืึทืœ-ืฉื˜ืึทื˜ =" ืึธืคึผืฆื™ืข ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืœื™ื ืง ื•ื•ืึธืก ื™ื ื“ื™ืงื™ื™ืฅ ื’ืจื™ื™ื˜ืงื™ื™ึทื˜;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ "UseAutonomousPrefix=" ืื•ืŸ "UseOnLinkPrefix =" ืกืขื˜ื˜ื™ื ื’ืก ืฆื• .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืื™ื’ื ืึธืจื™ืจืŸ ืคึผืจืขืคื™ืงืก ื•ื•ืขืŸ ืจื™ืกื™ื•ื•ื™ื ื’
    ืžืขืœื“ืŸ ืคื•ืŸ ืึทืŸ IPv6 ืจืึทื•ื˜ืขืจ (ืจืึท, ืจืึทื•ื˜ืขืจ ืึทื“);

  • ืื™ืŸ .ื ืขื˜ื•ื•ืึธืจืง ื•ื ื™ืฅ, ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก "MulticastFlood=", "NeighborSuppression=" ืื•ืŸ "Learning=" ื–ืขื ืขืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืคื•ืŸ ื“ื™ ื ืขืฅ ื‘ืจื™ืง, ืื•ืŸ ื“ื™ "TripleSampling=" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ื“ืจื™ื™ึทื™ืง ืžื•ืกื˜ืขืจื•ื ื’ ืžืึธื“ืข. ืคื•ืŸ CAN ื•ื•ื™ืจื˜ื•ืึทืœ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • "PrivateKeyFile =" ืื•ืŸ "PresharedKeyFile =" ืกืขื˜ื˜ื™ื ื’ืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• .ื ืขื˜ื“ืขื•ื• ื•ื ื™ืฅ, ืžื™ื˜ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืคึผืจื™ื•ื•ืึทื˜ ืื•ืŸ ืฉืขืจื“ (PSK) ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ WireGuard VPN ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • ื“ื™ ื–ืขืœื‘ืข-ืงืคึผื•-ืงืจื™ืคึผื˜ ืื•ืŸ ืคืึธืจืœื™ื™ื’ืŸ-ืคื•ืŸ-crypt-cpus ืึธืคึผืฆื™ืขืก ืฆื• /etc/crypttab, ื•ื•ืึธืก ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืกืงืขื“ื–ืฉื•ืœืขืจ ื•ื•ืขืŸ ืžื™ื™ื’ืจื™ื™ื˜ื™ื ื’ ืขื ืงืจื™ืคึผืฉืึทืŸ-ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืึทืจื‘ืขื˜ ืฆื•ื•ื™ืฉืŸ ืงืคึผื• ืงืึธืจืขืก;
  • systemd-tmpfiles ืคึผืจืึธื•ื•ื™ื“ืขืก ืฉืœืึธืก ื˜ืขืงืข ืคึผืจืึทืกืขืกื™ื ื’ ืื™ื™ื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ืึทืคึผืขืจื™ื™ืฉืึทื ื– ืื™ืŸ ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ืžื™ื˜ ืฆื™ื™ึทื˜ื•ื•ื™ื™ึทืœื™ืง ื˜ืขืงืขืก, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืจื™ื™ื ื™ืงื•ื ื’ ืึทื•ื˜ื“ื™ื™ื˜ื™ื“ ื˜ืขืงืขืก ืคึฟืึทืจ ื“ืขืจ ื’ืขื“ื•ื™ืขืจ ืคื•ืŸ ื–ื™ื›ืขืจ ืึทืงืฉืึทื ื– (ืœืžืฉืœ, ื•ื•ืขืŸ ืึทื ืคึผืึทืงื™ื ื’ ืึท ื˜ืึทืจ ืึทืจืงื™ื™ื•ื• ืื™ืŸ / ื˜ืžืคึผ, ื–ื™ื™ืขืจ ืึทืœื˜ ื˜ืขืงืขืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขืขืคื ื˜ ื•ื•ืึธืก ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื•ื™ืกืžืขืงืŸ ืื™ื™ื“ืขืจ ื“ื™ ืกื•ืฃ ืคื•ืŸ ื“ื™ ืึทืงืฆื™ืข ืžื™ื˜ ื–ื™ื™);
  • ื“ื™ "ืกื™ืกื˜ืขื-ืึทื ืึทืœื™ื–ืข ืงืึทื˜-ืงืึธื ืคื™ื’" ื‘ืึทืคึฟืขืœ ื’ื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ืขื˜ืœืขื›ืข ื˜ืขืงืขืก, ืœืžืฉืœ, ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ืกื™ืกื˜ืขื ืคึผืจืขืกืขืฅ, ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ tmpfiles.d ืื•ืŸ sysusers.d, udev ื›ึผืœืœื™ื, ืขื˜ืง.
  • ืฆื•ื’ืขื’ืขื‘ืŸ "--cursor-file=" ืึธืคึผืฆื™ืข ืฆื• "ื–ืฉื•ืจื ืึทืœืงื˜ืœ" ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ื˜ืขืงืข ืฆื• ืžืึทืกืข ืื•ืŸ ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ืฉื˜ืขืœืข ืœื•ื™ืคึฟืขืจ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ืขืคึฟื™ื ื™ืฆื™ืข ืคื•ืŸ โ€‹โ€‹ACRN ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ืื•ืŸ WSL ืกื•ื‘ืกื™ืกื˜ืขื (ื•ื•ื™ื ื“ืึธื•ื– ืกื•ื‘ืกื™ืกื˜ืขื ืคึฟืึทืจ ืœื™ื ื•ืงืก) ืฆื• ืกื™ืกื˜ืขืž-ื“ืขื˜ืขืงื˜-ื•ื•ื™ืจื˜ ืคึฟืึทืจ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ื‘ืจืึทื ื˜ืฉื™ื ื’ ื ื™ืฆืŸ ื“ื™ ืงืึทื ื“ื™ืฉืึทื ืึทืœ ืึธืคึผืขืจืึทื˜ืึธืจ "ืงืึธื ื“ื™ื˜ื™ืึธืŸ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ";
  • ื‘ืขืฉืึทืก ืกื™ืกื˜ืขืž ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ (ื•ื•ืขืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ "ื ื™ื ื“ื–ืฉืึท ื™ื ืกื˜ืึทืœื™ืจืŸ"), ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ืกื™ืžื‘ืึธืœื™ืฉ ืœื™ื ืงืก ืฆื• ื“ื™ ื˜ืขืงืขืก systemd-networkd.service, systemd-networkd.socket,
    systemd-resolved.service, remote-cryptsetup.target, remote-fs.target,
    systemd-networkd-wait-online.service ืื•ืŸ systemd-timesyncd.service. ืฆื• ืฉืึทืคึฟืŸ ื“ื™ ื˜ืขืงืขืก, ืื™ืจ ืื™ืฆื˜ ื“ืึทืจืคึฟืŸ ืฆื• ืœื•ื™ืคืŸ ื“ื™ "ืกื™ืกื˜ืขืžืงื˜ืœ ืคึผืจื™ืกืขื˜-ืึทืœืข" ื‘ืึทืคึฟืขืœ.

ืžืงื•ืจ: opennet.ru

[:]

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’