systemd 252 inosvika nerutsigiro rweUKI, kuvandudzwa uye nezvimwe

systemd

systemd seti yehurongwa hwekutonga madhimoni, maraibhurari, uye maturusi akagadzirwa seyepakati gadziriso uye manejimendi chikuva chekupindirana neiyo system kernel. 

Mushure memwedzi mishanu yekuvandudza kuburitswa kweiyo vhezheni itsva ye systemd 252 yakaziviswa, shanduro mairi shanduko yakakosha mushanduro itsva yaive kubatanidzwa kwe kutsigira chirongwa chemazuva ano chebhoti, iyo inobvumira kuonesa kwete chete kernel uye bootloader, asiwo zvikamu zvepazasi system nharaunda uchishandisa siginecha yedhijitari.

Iyo yakarongwa nzira inosanganisira kushandiswa kweUKI yakabatana kernel mufananidzo (Yakabatana kernel mufananidzo) pamutoro, unobatanidza mutyairi wekurodha kernel kubva kuUEFI (UEFI boot stub), mufananidzo weLinux kernel, uye initrd system nharaunda yakarongedzerwa mundangariro, yakashandiswa kutanga kwekutanga munhanho yapfuura kusvika kuFS mudzi gomo. .

Akavimbika Boot
Nyaya inoenderana:
Ivo vanokurudzira kugadzirisa iyo Linux boot process

Kunyanya, zvikomborero systemd-cryptsetup, systemd-cryptenroll uye systemd-creds yakagadziridzwa kushandisa ruzivo urwu, saka iwe unogona kuve nechokwadi chekuti encrypted disk partitions inosungirirwa kune yakasainwa kernel (munyaya iyi, kupinda kune yakavharidzirwa partition inopihwa chete kana iyo UKI mufananidzo wapfuura dijitari siginecha verification zvichibva mumaparamita akaiswa mu. TPM).

Uye zvakare, iyo systemd-pcrphase utility inosanganisirwa, iyo inokutendera iwe kudzora kusungirirwa kwematanho akasiyana-siyana ebhutsu kune maparameter akaiswa mundangariro ne cryptoprocessors inotsigira TPM 2.0 kutsanangurwa (semuenzaniso, unogona kuita iyo partition decryption kiyi LUKS2 inowanikwa chete. mumufananidzo wekutanga uye vhara kupinda kwairi pane zvinotevera kurodha).

Main nyowani maficha e systemd 252

Dzimwe shanduko dzinomira pachena mu systemd 252, ndeye se akava nechokwadi chekuti nzvimbo yakagara ndeye C.UTF-8 kana pasina imwe nzvimbo inotsanangurwa mukugadziriswa.

Pamusoro payo mu systemd 252 zvakare yakashandisa kugona kuita yakazara sevhisi preset oparesheni ("systemctl preset") panguva yekutanga boot. Kugonesa preset panguva yebhutsu kunoda kuvaka ne "-Dfirst-boot-full-preset" sarudzo, asi yakarongwa kuti igoneswe nekusarudzika mukuburitswa mune ramangwana.

Mumashandisi emushandisi manejimendi shandisa iyo CPU resource controller, izvo zvakaita kuti zvive nechokwadi chokuti CPUWeight setting inoshandiswa kune zvikamu zvose zvechidimbu zvinoshandiswa kuparadzanisa hurongwa muzvidimbu (app.slice, background.slice, session.slice) kuparadzanisa zviwanikwa pakati pevashandi vakasiyana-siyana, kukwikwidzana neCPU zviwanikwa. CPUWeight inotsigirawo "isimbe" kukosha kukonzeresa iyo chaiyo yekurenda modhi.

Kune rumwe rutivi, mukutanga maitiro (PID 1), yakawedzera kugona kupinza zvitupa kubva kuSMBIOS minda (Type 11, "OEM provider cheni") pamwe nekudzitsanangura kuburikidza neqemu_fwcfg, iyo inorerutsa kupa magwaro kumashini chaiwo uye kubvisa kudiwa kwezvishandiso zvechitatu senge gore -init uye kubatidza.

Munguva yekuvhara, iyo pfungwa yekudzikisa chaiwo faira masisitimu (proc, sys) yakashandurwa, uye ruzivo nezve maitiro ekuvharira faira system kudonha inochengetwa kurogi.

Iyo sd bootloader yakawedzera kugona kubhutsu mune yakasanganiswa modhi, uchimhanyisa 64-bit Linux kernel kubva ku32-bit UEFI firmware. Yakawedzera kugona kuyedza kuisa otomatiki SecureBoot makiyi kubva kumafaira ari paESP (EFI System Partition).

Yakawedzera sarudzo nyowani kubootctl utility "-all-architectures" kuisa mabhinari kune ese anotsigirwa EFI architecture, «-mudzi = "uye"-mufananidzo=» kushanda nedhairekitori kana dhisiki mufananidzo, «--install-source=»kutsanangura font yekuisa, «-efi-boot-option-descript=»kutonga mazita ezvinyorwa zvebhoti.

Yeimwe shanduko izvo zvinomira kunze kubva systemd 252:

  • systemd-nspawn inobvumira kushandiswa kwehama dzefaira nzira mune "-bind =" uye "-overlay=" sarudzo. Yakawedzera tsigiro ye 'rootidmap' sarudzo kune "-bind = "sarudzo yekusunga mudzi wemushandisi ID pamudziyo kune muridzi weakakwidzwa dhairekitori padivi rekugamuchira.
  • systemd-yakagadziriswa inoshandisa iyo OpenSSL package seyakavanzika backend nekukasira (rutsigiro rwegnutls runochengetwa senge sarudzo). Zvisina kutsigirwa DNSSEC maalgorithms ave kubatwa seasina kuchengeteka pane kudzosa kukanganisa (SERVFAIL).
  • systemd-sysusers, systemd-tmpfiles, uye systemd-sysctl shandisa kugona kupfuudza gadziriso kuburikidza neyekuchengetera michina.
  • Yakawedzera 'kuenzanisa mavhezheni' kuraira ku systemd-kuongorora kuenzanisa tambo nenhamba dzeshanduro (yakafanana ne 'rpmdev-vercmp' uye 'dpkg -compare-versions').
  • Yakawedzera kugona kusefa madhiraivha nemasiki kune iyo 'systemd-ongorora dump' yekuraira.
  • Paunenge uchisarudza yakawanda-nhanho yekurara modhi (kurara wobva warara, hibernate mushure mekurara), iyo nguva inopedzerwa mukumira modhi ikozvino yasarudzwa zvichienderana neyasara hupenyu hwebhatiri.
  • Shanduko yekukurumidza kuenda kumodhi yekurara inoitwa kana paine isingasviki 5% bhatiri kuchaja.

Izvo zvakakoshawo kutaura izvo muna 2024, systemd inoronga kumira kutsigira cgroup v1 resource capping mechanism, yakaderedzwa muvhezheni 248 ye systemd. Mamaneja anorairwa kuti atore masevhisi ekufambisa akabatana necgroup v1 kune cgroup v2 pamberi.

Musiyano wakakosha pakati pemapoka v2 uye v1 iko kushandiswa kweakajairika cgroups hierarchy kune ese marudzi ezvishandiso, pane akaparadzana hierarchies yeCPU zviwanikwa zvekugovera, ndangariro manejimendi, uye I/O. Akaparadzana mahierarchies anotungamira kumatambudziko mukuronga kudyidzana pakati pevatyairi uye yekuwedzera kernel resource mitengo pakushandisa mitemo yemaitiro ane zita mune akasiyana hierarchies.

Muchikamu chechipiri cha2023, zvakarongwa kumisa kutsigira kupatsanurwa kwedhairekitori, kana / usr yakamisikidzwa yakaparadzana nemidzi, kana / bin uye / usr / bin, / lib uye / usr / lib madhairekitori akaparadzaniswa.


Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako

  1.   luix akadaro

    mamwe marara kubva lennart..

  2.   anonymous akadaro

    Mukomana uyu mushandi…uye mushandi akanaka…anonyatsoenderana nemushandirwi wake.