ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืžืขืœื“ื•ื ื’ 243

ื ืึธืš ืคื™ื ืฃ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื“ืขืจืœืื ื’ื˜ ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืžืขืœื“ื•ื ื’ ืกื™ืกื˜ืขื 243. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื–, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ื“ื™ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืื™ืŸ PID 1 ืคื•ืŸ ืึท ื”ืึทื ื“ืœืขืจ ืคึฟืึทืจ ื ื™ื“ืขืจื™ืง ื–ื›ึผืจื•ืŸ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืึทื˜ืึทื˜ืฉื™ื ื’ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข BPF ืžื’ื™ืœื” ืคึฟืึทืจ ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ ืึทืคึผืึทืจืึทื˜ ืคืึทืจืงืขืจ, ืคื™ืœืข ื ื™ื™ึทืข ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ systemd-networkd, ืึท ืžืึธื“ืข ืคึฟืึทืจ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื“ื™ ื‘ืึทื ื“ื•ื•ื™ื“ื˜ ืคื•ืŸ ื ืขืฅ. ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ื‘ื™ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื•ื™ืฃ 64-ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ 22-ื‘ื™ืกืœ PID ื ื•ืžืขืจืŸ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ 16-ื‘ื™ืกืœ, ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ืึท ื™ื•ื ืึทืคื™ื™ื“ ืงื’ืจื•ืคึผืก ื›ื™ื™ืขืจืึทืจืงื™, ื™ื ืงืœื•ื–ืฉืึทืŸ ืื™ืŸ ืกื™ืกื˜ืขืž-ื ืขื˜ื•ื•ืึธืจืง-ื’ืขื ืขืจืึทื˜ืึธืจ.

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ื“ืขืจืงืขื ื•ื ื’ ืคื•ืŸ ืงืขืจื ืขืœ-ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืกื™ื’ื ืึทืœื– ื•ื•ืขื’ืŸ ืึธืŸ ื–ื›ึผืจื•ืŸ (ืื•ื™ืก-ืคื•ืŸ-ื–ื™ืงืึธืจืŸ, OOM) ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ PID 1 ื”ืึทื ื“ืœืขืจ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื•ื ื™ืฅ ื•ื•ืึธืก ื”ืึธื‘ืŸ ืจื™ื˜ืฉื˜ ื“ื™ ื–ื™ืงืึธืจืŸ ืงืึทื ืกืึทืžืฉืึทืŸ ืœื™ืžื™ื˜ ืื™ืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืฉื˜ืึทื˜ ืžื™ื˜ ื“ื™ ืึทืคึผืฉืึทื ืึทืœ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฆื•ื•ื™ื ื’ืขืŸ ื–ื™ื™ ืฆื• ืคืึทืจืขื ื“ื™ืงืŸ ืึธื“ืขืจ ื”ืึทืœื˜ืŸ;
  • ืคึฟืึทืจ ืึทืคึผืึทืจืึทื˜ ื˜ืขืงืขืก, ื ื™ื™ึท ืคึผืึทืจืึทืžืขื˜ืขืจืก IPIngressFilterPath ืื•ืŸ
    IPEgressFilterPath, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ BPF ืžื’ื™ืœื” ืžื™ื˜ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื”ืึทื ื“ืœืขืจืก ืฆื• ืคื™ืœื˜ืขืจ ื™ื ืงืึทืžื™ื ื’ ืื•ืŸ ืึทื•ื˜ื’ืึธื•ื™ื ื’ IP ืคึผืึทืงื™ืฅ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ืคึผืจืึทืกืขืกืึทื– ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ืขื ืึทืคึผืึทืจืึทื˜. ื“ื™ ืคืืจื’ืขืœื™ื™ื’ื˜ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืœืึธื–ืŸ ืื™ืจ ืฆื• ืฉืึทืคึฟืŸ ืึท ืžื™ืŸ ืคื•ืŸ ืคื™ื™ืจื•ื•ืึทืœ ืคึฟืึทืจ ืกื™ืกื˜ืขื ื‘ืึทื“ื™ื ื•ื ื’ืก. ืฉืจื™ื™ื‘ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ ืึท ืคึผืฉื•ื˜ ื ืขืฅ ืคื™ืœื˜ืขืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ BPF;

  • ื“ื™ "ืจื™ื™ืŸ" ื‘ืึทืคึฟืขืœ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ systemctl ื ื•ืฆืŸ ืฆื• ื•ื™ืกืžืขืงืŸ ื“ื™ ืงืึทืฉ, ืจื•ื ื˜ื™ืžืข ื˜ืขืงืขืก, ืกื˜ืึทื˜ื•ืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ืงืœืึธืฅ ื“ื™ืจืขืงื˜ืขืจื™ื–;
  • systemd-networkd ืžื•ืกื™ืฃ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ MACsec, nlmon, IPVTAP ืื•ืŸ Xfrm ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • systemd-networkd ื™ืžืคึผืœืึทืžืึทื ืฅ ื‘ืึทื–ื•ื ื“ืขืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ DHCPv4 ืื•ืŸ DHCPv6 ืกื˜ืึทืงืก ื“ื•ืจืš ื“ื™ "[DHCPv4]" ืื•ืŸ "[DHCPv6]" ืกืขืงืฉืึทื ื– ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข. ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ RoutesToDNS ืึธืคึผืฆื™ืข ืฆื• ืœื™ื™ื’ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืžืึทืจืฉืจื•ื˜ ืฆื• ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ DHCP ืกืขืจื•ื•ืขืจ (ืึทื–ื•ื™ ืึทื– ืคืึทืจืงืขืจ ืฆื• ื“ื™ ื“ื ืก ืื™ื– ื’ืขืฉื™ืงื˜ ื“ื•ืจืš ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืœื™ื ืง ื•ื•ื™ ื“ื™ ื”ื•ื™ืคึผื˜ ืžืึทืจืฉืจื•ื˜ ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ DHCP). ื ื™ื• ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืคึฟืึทืจ DHCPv4: MaxAttempts - ืžืึทืงืกื™ืžื•ื ื ื•ืžืขืจ ืคื•ืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทืŸ ืึทื“ืจืขืก, BlackList - ืฉื•ื•ืึทืจืฅ ืจืฉื™ืžื” ืคื•ืŸ DHCP ืกืขืจื•ื•ืขืจืก, SendRelease - ื’ืขื‘ืŸ ืฉื™ืงื˜ DHCP RELEASE ืึทืจื˜ื™ืงืœืขืŸ ื•ื•ืขืŸ ื“ื™ ืกืขืกื™ืข ืขื ื“ืก;
  • ื ื™ื™ึทืข ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ืžื•ืกื™ืฃ ืฆื• ื“ื™ systemd-analyze ื ื•ืฆืŸ:
    • "ืกื™ืกื˜ืขืžื“-ืึทื ืึทืœื™ื–ื™ืจืŸ ื˜ื™ืžืขืกื˜ืึทืžืคึผ" - ืฆื™ื™ื˜ ืคึผืึทืจืกื™ื ื’ ืื•ืŸ ืงืึทื ื•ื•ืขืจื–ืฉืึทืŸ;
    • "ืกื™ืกื˜ืขื-ืึทื ืึทืœื™ื–ื™ืจืŸ ืฆื™ื™ื˜ ืฉืคึผืึทืŸ" - ืึทื ืึทืœื™ืกื™ืก ืื•ืŸ ืงืึทื ื•ื•ืขืจื–ืฉืึทืŸ ืคื•ืŸ ืฆื™ื™ื˜ ืคึผื™ืจื™ืึทื“ื–;
    • "ืกื™ืกื˜ืขื-ืึทื ืึทืœื™ื–ืข ืฆื•ืฉื˜ืึทื ื“" - ืคึผืึทืจืกื™ื ื’ ืื•ืŸ ื˜ืขืกื˜ื™ื ื’ ืงืึธื ื“ื™ื˜ื™ืึธืŸืงืกื™ื– ืื•ื™ืกื“ืจื•ืงืŸ;
    • "ืกื™ืกื˜ืขื-ืึทื ืึทืœื™ื–ื™ืจืŸ ืึทืจื•ื™ืกื’ืึทื ื’-ืกื˜ืึทื˜ื•ืก" - ืคึผืึทืจืกื™ื ื’ ืื•ืŸ ืงืึทื ื•ื•ืขืจื˜ื™ื ื’ ืึทืจื•ื™ืกื’ืึทื ื’ ืงืึธื•ื“ื– ืคื•ืŸ ื ื•ืžืขืจืŸ ืฆื• ื ืขืžืขืŸ ืื•ืŸ ื•ื•ื™ืฆืข ื•ื•ืขืจืกืึท;
    • "ืกื™ืกื˜ืขืžื“-ืึทื ืึทืœื™ื–ืข ืึทืคึผืึทืจืึทื˜-ืคื™ื™ืœืก" - ืจืฉื™ืžื•ืช ืึทืœืข ื˜ืขืงืข ืคึผืึทื˜ืก ืคึฟืึทืจ ื•ื ื™ืฅ ืื•ืŸ ืึทืคึผืึทืจืึทื˜ ื™ื™ืœื™ืึทืกื™ื–.
  • ืึธืคึผืฆื™ืขืก ื”ืฆืœื—ื” ืขืงืกื™ื˜ืกื˜ืึทื˜ื•ืก, ืจื™ืกื˜ืึทืจื˜ ืคึผืจืขื•ื•ืขื ื˜ ืขืงืกื™ื˜ืกื˜ืึทื˜ื•ืก ืื•ืŸ
    RestartForceExitStatus ืื™ืฆื˜ ืฉื˜ื™ืฆื˜ ื ื™ื˜ ื‘ืœื•ื™ื– ื ื•ืžืขืจื™ืง ืฆื•ืจื™ืงืงื•ืžืขืŸ ืงืึธื•ื“ื–, ืึธื‘ืขืจ ืื•ื™ืš ื–ื™ื™ืขืจ ื˜ืขืงืกื˜ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ (ืœืžืฉืœ, "DATAERR"). ืื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ืงืึธื•ื“ื– ืึทืกื™ื™ื ื“ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืขืจืก ื ื™ืฆืŸ ื“ื™ "ืกื™ื˜ืขืžื“-ืึทื ืึทืœื™ื–ืข ืึทืจื•ื™ืกื’ืึทื ื’-ืกื˜ืึทื˜ื•ืก" ื‘ืึทืคึฟืขืœ;

  • ื“ื™ "ื•ื™ืกืžืขืงืŸ" ื‘ืึทืคึฟืขืœ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ Networkctl ื ื•ืฆืŸ ืฆื• ื•ื™ืกืžืขืงืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ื ืขืฅ ื“ืขื•ื•ื™ืกืขืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ "-ืกื˜ืึทื˜ืก" ืึธืคึผืฆื™ืข ืฆื• ืึทืจื•ื™ืกื•ื•ื™ื™ึทื–ืŸ ืžื™ื˜ืœ ืกื˜ืึทื˜ื™ืกื˜ื™ืง;
  • SpeedMeter ืื•ืŸ SpeedMeterIntervalSec ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• networkd.conf ืคึฟืึทืจ ืคึผื™ืจื™ืึทื“ื™ืงืœื™ ืžืขืกื˜ืŸ ื“ื™ ื˜ืจื•ืคึผื•ื˜ ืคื•ืŸ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–. ืกื˜ืึทื˜ื™ืกื˜ื™ืง ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ ืžืขื–ืฉืขืจืžืึทื ื˜ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื•ื•ื™ื•ื“ ืื™ืŸ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ 'ื ืขื˜ื•ื•ืึธืจืงืงื˜ืœ ืกื˜ืึทื˜ื•ืก' ื‘ืึทืคึฟืขืœ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื ื™ื™ึท ื ื•ืฆืŸ ืกื™ืกื˜ืขืž-ื ืขื˜ื•ื•ืึธืจืง-ื’ืขื ืขืจืึทื˜ืึธืจ ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ื˜ืขืงืขืก
    .ื ืขื˜ื•ื•ืึธืจืง, .ื ืขื˜ื“ืขื•ื• ืื•ืŸ .ืœื™ื ืง ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ IP ืกืขื˜ื˜ื™ื ื’ืก ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ื•ื•ืขืŸ ืœืึธื ื˜ืฉื˜ ื“ื•ืจืš ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืื™ืŸ Dracut ืกืขื˜ื˜ื™ื ื’ืก ืคึฟืึธืจืžืึทื˜;

  • ื“ื™ sysctl "kernel.pid_max" ื•ื•ืขืจื˜ ืื•ื™ืฃ 64-ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ ืื™ื– ืื™ืฆื˜ ื‘ืึทืฉื˜ื™ืžื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืฆื• 4194304 (22-ื‘ื™ืกืœ ืคึผื™ื“ืก ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ 16-ื‘ื™ืฅ), ื•ื•ืึธืก ืจืึทื“ื•ืกืึทื– ื“ื™ ืœื™ืงืขืœื™ื”ืึธืึธื“ ืคื•ืŸ ืงืึทืœื™ื–ืฉืึทื ื– ื•ื•ืขืŸ ืึทืกื™ื™ื ื™ื ื’ ืคึผื™ื“ืก, ื™ื ืงืจื™ืกื™ื– ื“ื™ ืฉื™ืขื•ืจ ืื•ื™ืฃ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™. ืคืœื™ืกื ื“ื™ืง ืคึผืจืึทืกืขืกืึทื–, ืื•ืŸ ื”ืื˜ ืึท positive ืคึผืจืึทืœ ืื•ื™ืฃ ื–ื™ื›ืขืจื”ื™ื™ื˜. ื“ืขืจ ืขื ื“ืขืจื•ื ื’ ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ื™ืฉื•ื–, ืึธื‘ืขืจ ืึทื–ืึท ื™ืฉื•ื– ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื ืึธืš ื’ืขืžืืœื“ืŸ ืื™ืŸ ืคื™ืจ;
  • ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ื‘ื•ื™ืขืŸ ื‘ื™ื ืข ืกื•ื•ื™ื˜ืฉื™ื– ืฆื• ื“ื™ ื™ื•ื ืึทืคื™ื™ื“ ื›ื™ื™ืขืจืึทืจืงื™ cgroups-v2 ("-Ddefault-hierarchy = ื™ื•ื ืึทืคื™ื™ื“"). ื‘ื™ื– ืึทื”ืขืจ, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื™ื– ื›ื™ื™ื‘ืจื™ื“ ืžืึธื“ืข ("-Ddefault-hierarchy = ื›ื™ื™ื‘ืจื™ื“");
  • ื“ื™ ืึธืคึผืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขื ืจื•ืคืŸ ืคื™ืœื˜ืขืจ (SystemCallFilter) ืื™ื– ืคืืจืขื ื“ืขืจื˜, ื•ื•ืึธืก, ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ ืึท ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“ ืกื™ืกื˜ืขื ืจื•ืคืŸ, ืื™ืฆื˜ ื˜ืขืจืžืึทื ื™ื™ืฅ ื“ื™ ื’ืื ืฆืข ืคึผืจืึธืฆืขืก, ืืœื ื•ื•ื™ ื™ื—ื™ื“ ืคึฟืขื“ืขื, ื•ื•ื™ื™ึทืœ ื˜ืขืจืžืึทื ื™ื™ื˜ื™ื ื’ ื™ื—ื™ื“ ืคึฟืขื“ืขื ืงืขืŸ ืคื™ืจืŸ ืฆื• ืึทื ืคึผืจื™ื“ื™ืงื˜ืึทื‘ืึทืœ ืคึผืจืึธื‘ืœืขืžืก. ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ืึทืคึผืœื™ื™ื– ื‘ืœื•ื™ื– ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ ืœื™ื ื•ืงืก ืงืขืจืŸ 4.14+ ืื•ืŸ libsecomp 2.4.0+;
  • ืึทื ืคึผืจื™ื•ื•ื™ืœืขื“ื–ืฉื“ ืžื’ื™ืœื” ื–ืขื ืขืŸ ื’ืขื’ืขื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื™ืงืŸ ICMP Echo (ืคึผื™ื ื’) ืคึผืึทืงื™ืฅ ื“ื•ืจืš ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืกื™ืกื˜ืœ "net.ipv4.ping_group_range" ืคึฟืึทืจ ื“ื™ ื’ืื ืฆืข ืงื™ื™ื˜ ืคื•ืŸ ื’ืจื•ืคึผืขืก (ืคึฟืึทืจ ืึทืœืข ืคึผืจืึทืกืขืกืึทื–);
  • ืฆื• ืคืึทืจื’ื™ื›ืขืจืŸ ื“ืขื ื‘ื•ื™ืขืŸ ืคึผืจืึธืฆืขืก, ื“ื™ ื“ื•ืจ ืคื•ืŸ ืžืึทื ื™ื•ืึทืœื– ืื™ื– ืกื˜ืึทืคึผื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ (ืฆื• ื‘ื•ื™ืขืŸ ืคื•ืœ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื ื•ืฆืŸ ื“ื™ ืึธืคึผืฆื™ืข "-Dman = ืืžืช" ืึธื“ืขืจ "-Dhtml = ืืžืช" ืคึฟืึทืจ ืžืึทื ื™ื•ืึทืœื– ืื™ืŸ HTML ืคึฟืึธืจืžืึทื˜). ืฆื• ืžืึทื›ืŸ ืขืก ื’ืจื™ื ื’ืขืจ ืฆื• ื–ืขืŸ ื“ื™ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ, ืฆื•ื•ื™ื™ ืกืงืจื™ืคึผืก ื–ืขื ืขืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜: ื‘ื•ื™ืขืŸ / ืžืขื ื˜ืฉ / ืžืขื ื˜ืฉ ืื•ืŸ ื‘ื•ื™ืขืŸ / ืžืขื ื˜ืฉ / HTML ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืื•ืŸ ืคึผืจื™ื•ื•ื™ื•ื™ื ื’ ืžืึทื ื™ื•ืึทืœื– ืคื•ืŸ ืื™ื ื˜ืขืจืขืก;
  • ืฆื• ืคึผืจืึธืฆืขืก ืคืขืœื“ ื ืขืžืขืŸ ืžื™ื˜ ืื•ืชื™ื•ืช ืคื•ืŸ ื ืืฆื™ืื ืืœืข ืึทืœืคืึทื‘ืขืฅ, ื“ื™ ืœื™ื‘ื™ื“ื 2 ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ื– ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ (ืฆื• ืฆื•ืจื™ืงืงื•ืžืขืŸ ืœื™ื‘ื™ื“ืŸ, ื ื•ืฆืŸ ื“ื™ "-Dlibidn = ืืžืช" ืึธืคึผืฆื™ืข);
  • ืกื•ืคึผืคึผืึธืจื˜ ืคึฟืึทืจ ื“ื™ /usr/sbin/halt.local ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข, ื•ื•ืึธืก ืฆื•ื’ืขืฉื˜ืขืœื˜ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ื•ื•ื™ื™ื“ืœื™ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ืื™ื– ื“ื™ืกืงืึทื ื˜ื™ื ื™ื•ื“. ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ืงืึทื˜ืขืจ ืคื•ืŸ ืงืึทืžืึทื ื“ื– ื•ื•ืขืŸ ืื™ืจ ืคืึทืจืžืึทื›ืŸ ืึทืจืึธืคึผ, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ื ื•ืฆืŸ ืกืงืจื™ืคึผืก ืื™ืŸ /usr/lib/systemd/system-shutdown/ ืึธื“ืขืจ ื“ืขืคื™ื ื™ืจืŸ ืึท ื ื™ื™ึทืข ืึทืคึผืึทืจืึทื˜ ื•ื•ืึธืก ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ final.target;
  • ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ื‘ื™ื ืข ืคื•ืŸ โ€‹โ€‹ืฉืึทื˜ื“ืึทื•ืŸ, ืกื™ืกื˜ืขื ื™ื ืงืจื™ืกื™ื– ืื™ืฆื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ื™ ืœืึธื’ ืžื“ืจื’ื” ืื™ืŸ ื“ื™ ืกื™ืกื˜ืœ "kernel.printk", ื•ื•ืึธืก ืกืึทืœื•ื•ื– ื“ื™ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ื•ื•ื™ื™ึทื– ืื™ืŸ ื“ื™ ืงืœืึธืฅ ื’ืขืฉืขืขื ื™ืฉืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืคืืจื’ืขืงื•ืžืขืŸ ืื™ืŸ ื“ื™ ืฉืคึผืขื˜ืขืจ ืกื˜ืึทื’ืขืก ืคื•ืŸ ืฉืึทื˜ื“ืึทื•ืŸ, ื•ื•ืขืŸ ื“ื™ ืจืขื’ื•ืœืขืจ ืœืึธื’ื™ื ื’ ื“ืขืžืึธื ืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื’ืขืขื ื“ื™ืงื˜. ;
  • ืื™ืŸ ื“ื–ืฉืึธื•ืจื ืึทืœืงื˜ืœ ืื•ืŸ ืื ื“ืขืจืข ื™ื•ื˜ื™ืœืึทื˜ื™ื– ื•ื•ื™ื™ึทื–ื ื“ื™ืง ืœืึธื’ืก, ื•ื•ืึธืจื ื™ื ื’ื– ื–ืขื ืขืŸ ื›ื™ื™ืœื™ื™ื˜ื™ื“ ืื™ืŸ ื’ืขืœ, ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืจืขืงืึธืจื“ืก ื–ืขื ืขืŸ ื›ื™ื™ืœื™ื™ื˜ื™ื“ ืื™ืŸ ื‘ืœื•ื™ ืฆื• ื•ื•ื™ื–ืฉื•ื•ืึทืœื™ ื”ื•ื™ื›ืคึผื•ื ืงื˜ ื–ื™ื™ ืคื•ืŸ ื“ื™ ืžืึทืกืข;
  • ืื™ืŸ ื“ื™ $PATH ืกื•ื•ื™ื•ื•ืข ื•ื•ืขืจื™ืึทื‘ืึทืœ, ื“ืขืจ ื“ืจืš ืฆื• bin/ ืื™ืฆื˜ ืงื•ืžื˜ ืื™ื™ื“ืขืจ ื“ืขืจ ื“ืจืš ืฆื• sbin/, ื“.ื”. ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ื™ื™ื“ืขื ื™ืงืึทืœ ื ืขืžืขืŸ ืคื•ืŸ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืขืก ืื™ืŸ ื‘ื™ื™ื“ืข ื“ื™ื™ืจืขืงื˜ืขืจื™ื–, ื“ื™ ื˜ืขืงืข ืคึฟื•ืŸ bin/ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“;
  • systemd-login ื’ื™ื˜ ืึท ืจื•ืฃ ืกืขื˜ื‘ืจื™ื’ื”ื˜ื ืขืกืก () ืฆื• ื‘ืขืฉืึธืœืขื ื˜ื•ื™ืฉืŸ ื“ื™ ืคืึทืจืฉื˜ืขืœืŸ ื‘ืจื™ื™ื˜ื ืึทืก ืื•ื™ืฃ ืึท ืคึผืขืจ-ืกืขืกื™ืข ื™ืงืขืจ;
  • ื“ื™ "--ื•ื•ืึทืจื˜ืŸ-ืคึฟืึทืจ-ื™ื ื˜ืึทืœื™ืึทื–ื™ื™ืฉืึทืŸ" ืคืึธืŸ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ "ื•ื“ืขื•ื•ืึทื“ื ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข" ื‘ืึทืคึฟืขืœ ืฆื• ื•ื•ืึทืจื˜ืŸ ื‘ื™ื– ื“ื™ ืžื™ื˜ืœ ืฆื• ื™ื ื™ืฉืึทืœื™ื™ื–;
  • ื‘ืขืฉืึทืก ืกื™ืกื˜ืขื ืฉื˜ื™ื•ื•ืœ, PID 1 ื”ืึทื ื“ืœืขืจ ืื™ืฆื˜ ื“ื™ืกืคึผืœื™ื™ื– ื“ื™ ื ืขืžืขืŸ ืคื•ืŸ ื•ื ื™ืฅ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืึท ืฉื•ืจื” ืžื™ื˜ ื–ื™ื™ืขืจ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’. ืฆื• ืฆื•ืจื™ืงืงื•ืžืขืŸ ืฆื• ืคืึทืจื’ืึทื ื’ืขื ื”ื™ื™ื˜ ื ืึทื˜ื•ืจ, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ StatusUnitFormat ืึธืคึผืฆื™ืข ืื™ืŸ /etc/systemd/system.conf ืึธื“ืขืจ ื“ื™ systemd.status_unit_format ืงืขืจืŸ ืึธืคึผืฆื™ืข;
  • ืฆื•ื’ืขื’ืขื‘ืŸ KExecWatchdogSec ืึธืคึผืฆื™ืข ืฆื• /etc/systemd/system.conf ืคึฟืึทืจ ื•ื•ืึทื˜ืฉื“ืึธื’ PID 1, ื•ื•ืึธืก ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ื“ื™ ื˜ื™ื™ืžืึทื•ื˜ ืคึฟืึทืจ ืจื™ืกื˜ืึทืจื˜ื™ื ื’ ื ื™ืฆืŸ ืงืขืงืกืขืง. ืึทืœื˜ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ
    ShutdownWatchdogSec ืื™ื– ืจื™ื ื™ื™ืžื“ ืฆื• RebootWatchdogSec ืื•ืŸ ื“ื™ืคื™ื™ื ื– ืึท ื˜ื™ื™ืžืึทื•ื˜ ืคึฟืึทืจ ื“ื–ืฉืึธื‘ืก ื‘ืขืฉืึทืก ืฉืึทื˜ื“ืึทื•ืŸ ืึธื“ืขืจ ื ืึธืจืžืึทืœ ืจื™ืกื˜ืึทืจื˜;

  • ื ื ื™ื™ึทืข ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืคึฟืึทืจ ืกืขืจื•ื•ื™ืกืขืก ืขืงืกืขืงืงืึธื ื“ื™ื˜ื™ืึธืŸ, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืงืึทืžืึทื ื“ื– ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื™ื™ื“ืขืจ ExecStartPre. ื‘ืึทื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื˜ืขื•ืช ืงืึธื“ ืื•ืžื’ืขืงืขืจื˜ ื“ื•ืจืš ื“ื™ ื‘ืึทืคึฟืขืœ, ืึท ื‘ืึทืฉืœื•ืก ืื™ื– ื’ืขืžืื›ื˜ ืื•ื™ืฃ ื•ื•ื™ื™ึทื˜ืขืจ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ืึทืคึผืึทืจืึทื˜ - ืื•ื™ื‘ ืงืึธื“ 0 ืื™ื– ืื•ืžื’ืขืงืขืจื˜, ื“ื™ ืงืึทื˜ืขืจ ืคื•ืŸ ื“ื™ ืึทืคึผืึทืจืึทื˜ ื”ืืœื˜, ืื•ื™ื‘ ืคื•ืŸ 1 ืฆื• 254 ืขืก ืขื ื“ืก ื‘ื™ืฉื˜ื™ืงืข ืึธืŸ ืึท ื“ื•ืจื›ืคืึทืœ ืคืึธืŸ, ืื•ื™ื‘ 255 ืขืก ืขื ื“ืก ืžื™ื˜ ืึท ื“ื•ืจื›ืคืึทืœ ืคืึธืŸ;
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึทืข ื“ื™ื ืกื˜ systemd-pstore.service ืฆื• ืขืงืกื˜ืจืึทืงื˜ ื“ืึทื˜ืŸ ืคื•ืŸ sys/fs/pstore/ ืื•ืŸ ืคึฟื•ืŸ ืฉืคึผืึธืจืŸ ืฆื• /var/lib/pstore ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทื ืึทืœื™ืกื™ืก;
  • ื ื™ื• ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ TimeDatectl ื ื•ืฆืŸ ืคึฟืึทืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื ื’ NTP ืคึผืึทืจืึทืžืขื˜ืขืจืก ืคึฟืึทืจ systemd-timesyncd ืื™ืŸ ื‘ืึทืฆื™ื•ื ื’ ืฆื• ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–;
  • ื“ื™ "localectl list-locales" ื‘ืึทืคึฟืขืœ ื ื™ื˜ ืžืขืจ ื“ื™ืกืคึผืœื™ื™ื– ืœืึธื•ืงืึทืœื– ืื ื“ืขืจืข ื•ื•ื™ UTF-8;
  • ื™ื ืฉื•ืจื– ืึทื– ื•ื•ืขืจื™ืึทื‘ืึทืœ ืึทืกื™ื™ื ืžืึทื ื˜ ืขืจืจืึธืจืก ืื™ืŸ sysctl.d/ ื˜ืขืงืขืก ื–ืขื ืขืŸ ืื™ื’ื ืึธืจื™ืจื˜ ืื•ื™ื‘ ื“ื™ ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง ื ืึธืžืขืŸ ื”ื™ื™ื‘ื˜ ืžื™ื˜ ื“ื™ ื›ืึทืจืึทืงื˜ืขืจ "-";
  • ื“ื™ื ืกื˜ systemd-random-seed.service ืื™ื– ืื™ืฆื˜ ื’ืึธืจ ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื ื’ ื“ื™ ืขื ื˜ืจืึธืคึผื™ืข ื‘ืขืงืŸ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ืคึผืกืขื•ื“ืึธืจืึทื ื“ืึธื ื ื•ืžืขืจ ื’ืขื ืขืจืึทื˜ืึธืจ. ืกืขืจื•ื•ื™ืกืขืก ื•ื•ืึธืก ื“ืึทืจืคืŸ ืึท ืจื™ื›ื˜ื™ืง ื™ื ื™ืฉืึทืœื™ื™ื–ื“ /dev/urandom ื–ืึธืœ ื–ื™ื™ืŸ ืกื˜ืึทืจื˜ืขื“ ื ืึธืš systemd-random-seed.service;
  • ื“ื™ systemd-boot boot loader ื’ื™ื˜ ื“ื™ ืึทืคึผืฉืึทื ืึทืœ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื˜ื™ืฆืŸ ื–ื•ื™ืžืขืŸ ื˜ืขืงืข ืžื™ื˜ ื˜ืจืึทืค - ืกื™ืงื•ื•ืึทื ืก ืื™ืŸ ื“ื™ EFI ืกื™ืกื˜ืขื ืฆืขื˜ื™ื™ืœื•ื ื’ (ESP);
  • ื ื™ื™ึท ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ื‘ืึธืึธื˜ืงื˜ืœ ื ื•ืฆืŸ: "ื‘ืึธืึธื˜ืงื˜ืœ ืจืึทื ื“ืึธื-ื–ื•ื™ืžืขืŸ" ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืึท ื–ื•ื™ืžืขืŸ ื˜ืขืงืข ืื™ืŸ ื“ื™ ESP ืื•ืŸ "ื‘ืึธืึธื˜ืงื˜ืœ ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ" ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขืื“-ืฉื˜ื™ื•ื•ืœ ืฉื˜ื™ื•ื•ืœ ืœืึธื•ื“ืขืจ. ื‘ืึธืึธื˜ืงื˜ืœ ืื™ื– ืื•ื™ืš ืึทื“ื–ืฉืึทืกื˜ื™ื“ ืฆื• ื•ื•ื™ื™ึทื–ืŸ ื•ื•ืึธืจื ื™ื ื’ื– ื•ื•ืขื’ืŸ ืคืึทืœืฉ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ืฉื˜ื™ื•ื•ืœ ืื™ื™ื ืกืŸ (ืœืžืฉืœ, ื•ื•ืขืŸ ื“ื™ ืงืขืจืŸ ื‘ื™ืœื“ ืื™ื– ืื•ื™ืกื’ืขืžืขืงื˜, ืึธื‘ืขืจ ื“ื™ ืคึผืึธื–ื™ืฆื™ืข ืคึฟืึทืจ ืœืึธื•ื“ื™ื ื’ ืขืก ืื™ื– ืœื™ื ืงืก);
  • ืคึผืจืึธื•ื•ื™ื“ืขืก ืึธื˜ืึทืžืึทื˜ื™ืง ืกืขืœืขืงืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื•ื™ืกื‘ื™ื™ึทื˜ืŸ ืฆืขื˜ื™ื™ืœื•ื ื’ ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ื’ื™ื™ื˜ ืื™ืŸ ืฉืœืึธืคืŸ ืžืึธื“ืข. ื“ื™ ืฆืขื˜ื™ื™ืœื•ื ื’ ืื™ื– ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื‘ื™ืœื›ืขืจืงื™ื™ึทื˜ ืงืึทื ืคื™ื’ื™ืขืจื“ ืคึฟืึทืจ ืขืก, ืื•ืŸ ืื™ืŸ ื“ื™ ืคืึทืœ ืคื•ืŸ ื™ื™ื“ืขื ื™ืงืึทืœ ืคึผืจื™ื™ืึธืจืึทื˜ื™ื–, ื“ื™ ืกื•ืžืข ืคื•ืŸ โ€‹โ€‹ืคืจื™ื™ ืคึผืœืึทืฅ;
  • ืึทื“ื“ืขื“ ืฉืœื™ืกืœ ื˜ืขืงืข-ื˜ื™ื™ืžืึทื•ื˜ ืึธืคึผืฆื™ืข ืฆื• /etc/crypttab ืฆื• ืฉื˜ืขืœืŸ ื•ื•ื™ ืœืึทื ื’ ื“ื™ ืžื™ื˜ืœ ืžื™ื˜ ื“ื™ ืขื ืงืจื™ืคึผืฉืึทืŸ ืฉืœื™ืกืœ ื•ื•ืขื˜ ื•ื•ืึทืจื˜ืŸ ืื™ื™ื“ืขืจ ืคึผืจืึทืžืคึผื˜ื™ื ื’ ืึท ืคึผืึทืจืึธืœ ืฆื• ืึทืงืกืขืก ื“ื™ ื™ื ืงืจื™ืคึผื˜ื™ื“ ืฆืขื˜ื™ื™ืœื•ื ื’;
  • ืฆื•ื’ืขื’ืขื‘ืŸ IOWeight ืึธืคึผืฆื™ืข ืฆื• ืฉื˜ืขืœืŸ ื“ื™ I/O ื•ื•ืึธื’ ืคึฟืึทืจ ื“ื™ BFQ ืกืงืขื“ื–ืฉื•ืœืขืจ;
  • systemd-resolved ืฆื•ื’ืขื’ืขื‘ืŸ 'ืฉื˜ืจืขื ื’' ืžืึธื“ืข ืคึฟืึทืจ ื“ื ืก-ืื™ื‘ืขืจ-TLS ืื•ืŸ ื™ืžืคึผืœืึทืžืขื ืึทื“ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึทืฉ ื‘ืœื•ื™ื– positive ื“ื ืก ืจืขืกืคึผืึธื ืกืขืก ("ืงืึทืฉ ื ื™ื˜-ื ืขื’ืึทื˜ื™ื•ื•" ืื™ืŸ resolved.conf);
  • ืคึฟืึทืจ VXLAN, systemd-networkd ื”ืื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ืึท GenericProtocolExtension ืึธืคึผืฆื™ืข ืฆื• ื’ืขื‘ืŸ VXLAN ืคึผืจืึธื˜ืึธืงืึธืœ ื™ืงืกื˜ืขื ืฉืึทื ื–. ืคึฟืึทืจ VXLAN ืื•ืŸ GENEVE, ื“ื™ IPDoNotFragment ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ืคืจืึทื’ืžืึทื ื˜ื™ื™ืฉืึทืŸ ืคืึทืจื•ื•ืขืจ ืคืึธืŸ ืคึฟืึทืจ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผืึทืงื™ืฅ;
  • ืื™ืŸ systemd-networkd, ืื™ืŸ ื“ื™ "[ืจื•ื˜]" ืึธืคึผื˜ื™ื™ืœื•ื ื’, ื“ื™ FastOpenNoCookie ืึธืคึผืฆื™ืข ืื™ื– ืืจื•ื™ืก ืฆื• ื’ืขื‘ืŸ ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืคึฟืึทืจ ื’ืขืฉื•ื•ื™ื ื“ ืขืคืŸ ื˜ืงืคึผ ืงืึทื ืขืงืฉืึทื ื– (TFO - TCP Fast Open, RFC 7413) ืื™ืŸ ื‘ืึทืฆื™ื•ื ื’ ืฆื• ื™ื—ื™ื“ ืจื•ืฅ, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ TTLPropagate ืึธืคึผืฆื™ืข ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ TTL LSP (Label Switched Path). ื“ื™ "ื˜ื™ืคึผ" ืึธืคึผืฆื™ืข ื’ื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื”ื™ื’ืข, ื‘ืจืึธื“ืงืึทืกื˜, ืึทื ื™ืงืึทืกื˜, ืžื•ืœื˜ื™ืงืึทืกื˜, ืงื™ื™ืŸ ืื•ืŸ ืงืกืจืขืกืึธืœื•ื•ืข ืจื•ื˜ื™ื ื’ ืžืึธื“ืขืก;
  • Systemd-networkd ืึธืคืคืขืจืก ืึท DefaultRouteOnDevice ืึธืคึผืฆื™ืข ืื™ืŸ ื“ื™ "[ื ืขื˜ื•ื•ืึธืจืง]" ืึธืคึผื˜ื™ื™ืœื•ื ื’ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืงืึทื ืคื™ื’ื™ืขืจ ืึท ืคืขืœื™ืงื™ื™ึทื˜ ืžืึทืจืฉืจื•ื˜ ืคึฟืึทืจ ืึท ื’ืขื’ืขื‘ืŸ ื ืขืฅ ืžื™ื˜ืœ;
  • Systemd-networkd ื”ืื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ProxyARP ืื•ืŸ
    ProxyARPWifi ืคึฟืึทืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืคึผืจืึทืงืกื™ ARP ื ืึทื˜ื•ืจ, MulticastRouter ืคึฟืึทืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืจื•ื˜ื™ื ื’ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ ืžื•ืœื˜ื™ืงืึทืกื˜ ืžืึธื“ืข, MulticastIGMPVersion ืคึฟืึทืจ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ IGMP (Internet Group Management Protocol) ื•ื•ืขืจืกื™ืข ืคึฟืึทืจ ืžื•ืœื˜ื™ืงืึทืกื˜;

  • Systemd-networkd ื”ืื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ืœืืงืืœืข, ืคึผื™ืขืจ ืื•ืŸ ืคึผืขืขืจืคึผืึธืจื˜ ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ FooOverUDP ื˜ืึทื ืึทืœื– ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ื”ื™ื’ืข ืื•ืŸ ื•ื•ื™ื™ึทื˜ IP ืึทื“ืจืขืกืขืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื ืขืฅ ืคึผืึธืจื˜ ื ื•ืžืขืจ. ืคึฟืึทืจ TUN ื˜ืึทื ืึทืœื–, ื“ื™ VnetHeader ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ GSO (ื’ืขื ืขืจื™ืง ืกืขื’ืžืขื ื˜ ืึธืคืœืึธืึทื“) ืฉื˜ื™ืฆืŸ;
  • ืื™ืŸ systemd-networkd, ืื™ืŸ ื“ื™ .ื ืขื˜ื•ื•ืึธืจืง ืื•ืŸ .ืœื™ื ืง ื˜ืขืงืขืก ืื™ืŸ ื“ื™ [ืžืึทื˜ืฉ] ืึธืคึผื˜ื™ื™ืœื•ื ื’, ืึท ืคืึทืจืžืึธื’ ืึธืคึผืฆื™ืข ืื™ื– ืืจื•ื™ืก, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื“ืขื•ื•ื™ืกืขืก ื“ื•ืจืš ื–ื™ื™ืขืจ ืกืคึผืขืฆื™ืคื™ืฉ ืคึผืจืึธืคึผืขืจื˜ื™ืขืก ืื™ืŸ udev;
  • ืื™ืŸ systemd-networkd, ืึทืŸ AssignToLoopback ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืคึฟืึทืจ ื˜ืึทื ืึทืœื–, ื•ื•ืึธืก ืงืึธื ื˜ืจืึธืœืก ืฆื™ ื“ืขืจ ืกื•ืฃ ืคื•ืŸ ื“ืขื ื˜ื•ื ืขืœ ืื™ื– ืึทืกื™ื™ื ื“ ืฆื• ื“ื™ ืœื•ืคึผื‘ืึทืงืง ืžื™ื˜ืœ "ืœืึธ";
  • systemd-networkd ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืึทืงื˜ืึทื•ื•ื™ื™ืฅ ื“ื™ IPv6 ืึธื ืœื™ื™ื’ืŸ ืื•ื™ื‘ ืขืก ืื™ื– ืืคื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš sysctl disable_ipv6 - IPv6 ืื™ื– ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ืื•ื™ื‘ IPv6 ืกืขื˜ื˜ื™ื ื’ืก (ืกื˜ืึทื˜ื™ืง ืึธื“ืขืจ DHCPv6) ื–ืขื ืขืŸ ื“ื™ืคื™ื™ื ื“ ืคึฟืึทืจ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“, ืึทื ื“ืขืจืฉ ื“ื™ ืฉื•ื™ืŸ ื‘ืึทืฉื˜ื™ืžื˜ ืกื™ืกื˜ืœ ื•ื•ืขืจื˜ ื˜ื•ื˜ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ;
  • ืื™ืŸ .ื ืขื˜ื•ื•ืึธืจืง ื˜ืขืงืขืก, ื“ื™ CriticalConnection ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืจื™ืคึผืœื™ื™ืกื˜ ื“ื•ืจืš ื“ื™ KeepConfiguration ืึธืคึผืฆื™ืข, ื•ื•ืึธืก ื’ื™ื˜ ืžืขืจ ืžื™ื˜ืœ ืคึฟืึทืจ ื“ื™ืคื™ื™ื ื™ื ื’ ืกื™ื˜ื•ืึทื˜ื™ืึธื ืก ("ื™ืึธ", "ืกื˜ืึทื˜ื™ืง", "dhcp-on-stop", "dhcp") ืื™ืŸ ื•ื•ืึธืก systemd-networkd ื–ืึธืœ ื ื™ื˜ ืึธื ืจื™ืจืŸ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืขืŸ ืกื˜ืึทืจื˜ืึทืคึผ;
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคืึทืจืคืขืกื˜ื™ืงื˜ CVE-2019-15718, ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืคืขืœืŸ ืคื•ืŸ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ ืฆื• ื“ื™ D-Bus ืฆื•ื‘ื™ื ื“ ืกื™ืกื˜ืขื ืกืึทืœื•ื•ื“. ื“ืขืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึทืœืึทื•ื– ืึท ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึทืคึผืขืจื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื–ืขื ืขืŸ ื‘ืœื•ื™ื– ื‘ื ื™ืžืฆื ืฆื• ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก, ืึทื–ืึท ื•ื•ื™ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื ืก ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ื“ื™ืจืขืงื˜ื™ื ื’ ื“ื ืก ืงื•ื•ื™ืจื™ื– ืฆื• ืึท ื–ืฉื•ืœื™ืง ืกืขืจื•ื•ืขืจ;
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคืึทืจืคืขืกื˜ื™ืงื˜ CVE-2019-9619ืฉื™ื™ึทื›ื•ืช ืฆื• ื ื™ืฉื˜ ื’ืขื‘ืŸ pam_systemd ืคึฟืึทืจ ื ื™ื˜-ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื• ืกืขืฉืึทื ื–, ื•ื•ืึธืก ืึทืœืึทื•ื– ืกืคึผืึธืึธืคื™ื ื’ ืคื•ืŸ ื“ื™ ืึทืงื˜ื™ื•ื• ืกืขืกื™ืข.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’