Lennart Poettering | d657c51 | 2012-01-25 02:20:38 +0100 | [diff] [blame] | 1 | systemd System and Service Manager |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 2 | |
| 3 | DETAILS: |
| 4 | http://0pointer.de/blog/projects/systemd.html |
| 5 | |
| 6 | WEB SITE: |
AsciiWolf | 19d9372 | 2017-02-21 15:56:04 +0100 | [diff] [blame] | 7 | https://www.freedesktop.org/wiki/Software/systemd |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 8 | |
| 9 | GIT: |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 10 | git@github.com:systemd/systemd.git |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 11 | https://github.com/systemd/systemd |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 12 | |
| 13 | MAILING LIST: |
AsciiWolf | 19d9372 | 2017-02-21 15:56:04 +0100 | [diff] [blame] | 14 | https://lists.freedesktop.org/mailman/listinfo/systemd-devel |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 15 | |
| 16 | IRC: |
| 17 | #systemd on irc.freenode.org |
| 18 | |
| 19 | BUG REPORTS: |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 20 | https://github.com/systemd/systemd/issues |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 21 | |
| 22 | AUTHOR: |
Lennart Poettering | 5430f7f | 2012-04-12 00:20:58 +0200 | [diff] [blame] | 23 | Lennart Poettering |
| 24 | Kay Sievers |
| 25 | ...and many others |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 26 | |
Lennart Poettering | 673eab9 | 2011-07-14 23:53:53 +0200 | [diff] [blame] | 27 | LICENSE: |
Lennart Poettering | 5430f7f | 2012-04-12 00:20:58 +0200 | [diff] [blame] | 28 | LGPLv2.1+ for all code |
Kay Sievers | a095315 | 2015-06-09 14:27:33 +0200 | [diff] [blame] | 29 | - except src/basic/MurmurHash2.c which is Public Domain |
| 30 | - except src/basic/siphash24.c which is CC0 Public Domain |
Kay Sievers | 8542472 | 2013-08-14 22:58:21 +0200 | [diff] [blame] | 31 | - except src/journal/lookup3.c which is Public Domain |
| 32 | - except src/udev/* which is (currently still) GPLv2, GPLv2+ |
Lennart Poettering | 673eab9 | 2011-07-14 23:53:53 +0200 | [diff] [blame] | 33 | |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 34 | REQUIREMENTS: |
Michael Biebl | dcce98a | 2017-03-02 19:11:37 +0100 | [diff] [blame] | 35 | Linux kernel >= 3.13 |
Lennart Poettering | a0c3e16 | 2015-09-06 15:58:20 +0200 | [diff] [blame] | 36 | Linux kernel >= 4.2 for unified cgroup hierarchy support |
Kay Sievers | 23aedd0 | 2014-03-22 18:27:35 +0100 | [diff] [blame] | 37 | |
| 38 | Kernel Config Options: |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 39 | CONFIG_DEVTMPFS |
Jan Engelhardt | d28315e | 2014-05-03 19:15:23 +0200 | [diff] [blame] | 40 | CONFIG_CGROUPS (it is OK to disable all controllers) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 41 | CONFIG_INOTIFY_USER |
| 42 | CONFIG_SIGNALFD |
| 43 | CONFIG_TIMERFD |
| 44 | CONFIG_EPOLL |
Kay Sievers | 4193869 | 2013-03-06 19:51:52 +0100 | [diff] [blame] | 45 | CONFIG_NET |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 46 | CONFIG_SYSFS |
Shawn Landden | 06d461e | 2013-12-09 07:04:06 -0800 | [diff] [blame] | 47 | CONFIG_PROC_FS |
Kay Sievers | 5d31974 | 2014-02-15 17:21:49 +0100 | [diff] [blame] | 48 | CONFIG_FHANDLE (libudev, mount and bind mount handling) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 49 | |
Mike Gilbert | 9c7f7d8 | 2017-02-25 22:42:27 -0500 | [diff] [blame] | 50 | Kernel crypto/hash API |
| 51 | CONFIG_CRYPTO_USER_API_HASH |
| 52 | CONFIG_CRYPTO_HMAC |
| 53 | CONFIG_CRYPTO_SHA256 |
| 54 | |
Kay Sievers | be2ea72 | 2014-08-30 11:34:20 +0200 | [diff] [blame] | 55 | udev will fail to work with the legacy sysfs layout: |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 56 | CONFIG_SYSFS_DEPRECATED=n |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 57 | |
| 58 | Legacy hotplug slows down the system and confuses udev: |
| 59 | CONFIG_UEVENT_HELPER_PATH="" |
| 60 | |
Kay Sievers | be2ea72 | 2014-08-30 11:34:20 +0200 | [diff] [blame] | 61 | Userspace firmware loading is not supported and should |
| 62 | be disabled in the kernel: |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 63 | CONFIG_FW_LOADER_USER_HELPER=n |
| 64 | |
| 65 | Some udev rules and virtualization detection relies on it: |
| 66 | CONFIG_DMIID |
| 67 | |
Kay Sievers | a5c724b | 2013-09-15 07:29:25 +0200 | [diff] [blame] | 68 | Support for some SCSI devices serial number retrieval, to |
| 69 | create additional symlinks in /dev/disk/ and /dev/tape: |
| 70 | CONFIG_BLK_DEV_BSG |
| 71 | |
Lennart Poettering | 0ca48bb | 2017-02-06 21:13:21 +0100 | [diff] [blame] | 72 | Required for PrivateNetwork= and PrivateDevices= in service units: |
Mike Gilbert | 1346882 | 2014-03-31 14:28:23 -0400 | [diff] [blame] | 73 | CONFIG_NET_NS |
Zbigniew Jędrzejewski-Szmek | b52a4a3 | 2014-12-30 09:57:01 -0500 | [diff] [blame] | 74 | CONFIG_DEVPTS_MULTIPLE_INSTANCES |
| 75 | Note that systemd-localed.service and other systemd units use |
| 76 | PrivateNetwork and PrivateDevices so this is effectively required. |
Mike Gilbert | 1346882 | 2014-03-31 14:28:23 -0400 | [diff] [blame] | 77 | |
Lennart Poettering | 0ca48bb | 2017-02-06 21:13:21 +0100 | [diff] [blame] | 78 | Required for PrivateUsers= in service units: |
Lucas Werkmeister | 87fe170 | 2017-01-24 03:18:07 +0100 | [diff] [blame] | 79 | CONFIG_USER_NS |
| 80 | |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 81 | Optional but strongly recommended: |
| 82 | CONFIG_IPV6 |
| 83 | CONFIG_AUTOFS4_FS |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 84 | CONFIG_TMPFS_XATTR |
Zbigniew Jędrzejewski-Szmek | a6cccd8 | 2015-03-03 09:00:39 -0500 | [diff] [blame] | 85 | CONFIG_{TMPFS,EXT4,XFS,BTRFS_FS,...}_POSIX_ACL |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 86 | CONFIG_SECCOMP |
Felipe Sateler | fd74fa7 | 2016-09-05 19:16:13 -0300 | [diff] [blame] | 87 | CONFIG_SECCOMP_FILTER (required for seccomp support) |
Lennart Poettering | 3b920d7 | 2015-05-18 16:35:24 +0200 | [diff] [blame] | 88 | CONFIG_CHECKPOINT_RESTORE (for the kcmp() syscall) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 89 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 90 | Required for CPUShares= in resource control unit settings |
Umut Tezduyar Lindskog | a21b467 | 2014-06-10 23:29:30 +0200 | [diff] [blame] | 91 | CONFIG_CGROUP_SCHED |
| 92 | CONFIG_FAIR_GROUP_SCHED |
| 93 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 94 | Required for CPUQuota= in resource control unit settings |
WaLyong Cho | 0acd5a0 | 2014-11-19 00:13:43 +0900 | [diff] [blame] | 95 | CONFIG_CFS_BANDWIDTH |
| 96 | |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 97 | For UEFI systems: |
Thomas Bächler | f33016f | 2014-03-22 01:41:12 +0100 | [diff] [blame] | 98 | CONFIG_EFIVAR_FS |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 99 | CONFIG_EFI_PARTITION |
| 100 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 101 | We recommend to turn off Real-Time group scheduling in the |
| 102 | kernel when using systemd. RT group scheduling effectively |
| 103 | makes RT scheduling unavailable for most userspace, since it |
| 104 | requires explicit assignment of RT budgets to each unit whose |
| 105 | processes making use of RT. As there's no sensible way to |
| 106 | assign these budgets automatically this cannot really be |
| 107 | fixed, and it's best to disable group scheduling hence. |
| 108 | CONFIG_RT_GROUP_SCHED=n |
| 109 | |
Lennart Poettering | f5a93d5 | 2017-07-24 11:28:04 +0200 | [diff] [blame] | 110 | It's a good idea to disable the implicit creation of networking bonding |
| 111 | devices by the kernel networking bonding module, so that the |
| 112 | automatically created "bond0" interface doesn't conflict with any such |
Dimitri John Ledkov | 582faeb | 2017-08-02 13:41:18 +0100 | [diff] [blame^] | 113 | device created by systemd-networkd (or other tools). Ideally there |
| 114 | would be a kernel compile-time option for this, but there currently |
| 115 | isn't. The next best thing is to make this change through a modprobe.d |
| 116 | drop-in. This is shipped by default, see modprobe.d/systemd.conf. |
Lennart Poettering | f5a93d5 | 2017-07-24 11:28:04 +0200 | [diff] [blame] | 117 | |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 118 | Note that kernel auditing is broken when used with systemd's |
| 119 | container code. When using systemd in conjunction with |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 120 | containers, please make sure to either turn off auditing at |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 121 | runtime using the kernel command line option "audit=0", or |
| 122 | turn it off at kernel compile time using: |
| 123 | CONFIG_AUDIT=n |
Lennart Poettering | a7b1c39 | 2014-03-11 05:40:36 +0100 | [diff] [blame] | 124 | If systemd is compiled with libseccomp support on |
| 125 | architectures which do not use socketcall() and where seccomp |
| 126 | is supported (this effectively means x86-64 and ARM, but |
Jan Engelhardt | 70a44af | 2014-05-03 19:15:24 +0200 | [diff] [blame] | 127 | excludes 32-bit x86!), then nspawn will now install a |
Lennart Poettering | a7b1c39 | 2014-03-11 05:40:36 +0100 | [diff] [blame] | 128 | work-around seccomp filter that makes containers boot even |
| 129 | with audit being enabled. This works correctly only on kernels |
| 130 | 3.14 and newer though. TL;DR: turn audit off, still. |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 131 | |
Łukasz Stelmach | 3dd26f3 | 2015-04-10 19:39:17 +0200 | [diff] [blame] | 132 | glibc >= 2.16 |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 133 | libcap |
Martin Pitt | 1d40ddb | 2015-11-02 10:05:20 -0600 | [diff] [blame] | 134 | libmount >= 2.27.1 (from util-linux) |
Zbigniew Jędrzejewski-Szmek | f089206 | 2017-05-12 04:49:48 -0400 | [diff] [blame] | 135 | (util-linux < 2.29 *must* be built with --enable-libmount-force-mountinfo, |
| 136 | and later versions without --enable-libmount-support-mtab.) |
hbrueckner | 6abfd30 | 2016-10-05 13:58:55 +0200 | [diff] [blame] | 137 | libseccomp >= 2.3.1 (optional) |
Gabriel de Perthuis | d47f6ca | 2014-12-13 01:56:56 +0100 | [diff] [blame] | 138 | libblkid >= 2.24 (from util-linux) (optional) |
Tom Gundersen | a18535d | 2013-10-17 19:49:19 +0200 | [diff] [blame] | 139 | libkmod >= 15 (optional) |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 140 | PAM >= 1.1.2 (optional) |
| 141 | libcryptsetup (optional) |
| 142 | libaudit (optional) |
Zbigniew Jędrzejewski-Szmek | 19d5d4c | 2011-07-12 13:57:48 +0200 | [diff] [blame] | 143 | libacl (optional) |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 144 | libselinux (optional) |
Zbigniew Jędrzejewski-Szmek | 19d5d4c | 2011-07-12 13:57:48 +0200 | [diff] [blame] | 145 | liblzma (optional) |
Zbigniew Jędrzejewski-Szmek | a509e0e | 2014-07-07 18:29:19 -0400 | [diff] [blame] | 146 | liblz4 >= 119 (optional) |
Lennart Poettering | 7b17a7d | 2012-09-28 00:46:32 +0200 | [diff] [blame] | 147 | libgcrypt (optional) |
| 148 | libqrencode (optional) |
| 149 | libmicrohttpd (optional) |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 150 | libpython (optional) |
Zbigniew Jędrzejewski-Szmek | 87057e2 | 2017-05-09 21:56:34 -0400 | [diff] [blame] | 151 | libidn2 or libidn (optional) |
Lennart Poettering | 5b24471 | 2014-06-23 12:42:17 +0200 | [diff] [blame] | 152 | elfutils >= 158 (optional) |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 153 | pkg-config |
| 154 | gperf >= 3.1 |
| 155 | docbook-xsl (optional, required for documentation) |
| 156 | xsltproc (optional, required for documentation) |
| 157 | python-lxml (optional, required to build the indices) |
| 158 | python, meson, ninja |
| 159 | gcc, awk, sed, grep, m4, and similar tools |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 160 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 161 | During runtime, you need the following additional |
| 162 | dependencies: |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 163 | |
Martin Pitt | 1d40ddb | 2015-11-02 10:05:20 -0600 | [diff] [blame] | 164 | util-linux >= v2.27.1 required |
Mike Gilbert | ecf4f0a | 2016-12-20 04:53:53 -0500 | [diff] [blame] | 165 | dbus >= 1.4.0 (strictly speaking optional, but recommended) |
| 166 | NOTE: If using dbus < 1.9.18, you should override the default |
| 167 | policy directory (--with-dbuspolicydir=/etc/dbus-1/system.d). |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 168 | dracut (optional) |
Lennart Poettering | 46ba8aa | 2013-02-13 22:56:43 +0100 | [diff] [blame] | 169 | PolicyKit (optional) |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 170 | |
Zbigniew Jędrzejewski-Szmek | 3e609a8 | 2017-04-18 21:52:30 -0400 | [diff] [blame] | 171 | To build in directory build/: |
| 172 | meson build/ && ninja -C build |
| 173 | |
| 174 | Any configuration options can be specfied as -Darg=value... arguments |
| 175 | to meson. After the build directory is initially configured, meson will |
| 176 | refuse to run again, and options must be changed with: |
| 177 | mesonconf -Darg=value... |
| 178 | mesonconf without any arguments will print out available options and |
| 179 | their current values. |
| 180 | |
| 181 | Useful commands: |
| 182 | ninja -v some/target |
| 183 | ninja test |
| 184 | sudo ninja install |
| 185 | DESTDIR=... ninja install |
| 186 | |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 187 | A tarball can be created with: |
Kay Sievers | 8262706 | 2015-06-23 13:40:53 +0200 | [diff] [blame] | 188 | git archive --format=tar --prefix=systemd-222/ v222 | xz > systemd-222.tar.xz |
| 189 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 190 | When systemd-hostnamed is used, it is strongly recommended to |
| 191 | install nss-myhostname to ensure that, in a world of |
| 192 | dynamically changing hostnames, the hostname stays resolvable |
Lennart Poettering | fff2e5b | 2011-05-17 19:35:56 +0200 | [diff] [blame] | 193 | under all circumstances. In fact, systemd-hostnamed will warn |
Kay Sievers | bf9e477 | 2013-01-24 10:31:34 +0100 | [diff] [blame] | 194 | if nss-myhostname is not installed. |
Lennart Poettering | fff2e5b | 2011-05-17 19:35:56 +0200 | [diff] [blame] | 195 | |
Zbigniew Jędrzejewski-Szmek | a2fc3d8 | 2016-10-15 20:51:19 -0400 | [diff] [blame] | 196 | Additional packages are necessary to run some tests: |
| 197 | - busybox (used by test/TEST-13-NSPAWN-SMOKE) |
| 198 | - nc (used by test/TEST-12-ISSUE-3171) |
| 199 | - python3-pyparsing |
| 200 | - python3-evdev (used by hwdb parsing tests) |
| 201 | - strace (used by test/test-functions) |
Zbigniew Jędrzejewski-Szmek | e94681a | 2017-02-12 00:22:20 -0500 | [diff] [blame] | 202 | - capsh (optional, used by test-execute) |
Zbigniew Jędrzejewski-Szmek | a2fc3d8 | 2016-10-15 20:51:19 -0400 | [diff] [blame] | 203 | |
Lennart Poettering | a24c64f | 2013-03-05 18:53:21 +0100 | [diff] [blame] | 204 | USERS AND GROUPS: |
Lennart Poettering | 37495ee | 2013-03-05 19:15:31 +0100 | [diff] [blame] | 205 | Default udev rules use the following standard system group |
| 206 | names, which need to be resolvable by getgrnam() at any time, |
| 207 | even in the very early boot stages, where no other databases |
| 208 | and network are available: |
| 209 | |
Kay Sievers | 3dff3e0 | 2014-06-12 14:59:53 +0200 | [diff] [blame] | 210 | audio, cdrom, dialout, disk, input, kmem, lp, tape, tty, video |
Kay Sievers | 37c0e8f | 2013-03-05 19:04:48 +0100 | [diff] [blame] | 211 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 212 | During runtime, the journal daemon requires the |
Michael Biebl | 1a9ce3f | 2013-03-05 19:19:26 +0100 | [diff] [blame] | 213 | "systemd-journal" system group to exist. New journal files will |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 214 | be readable by this group (but not writable), which may be used |
Zbigniew Jędrzejewski-Szmek | a48a62a | 2015-01-18 15:05:40 -0500 | [diff] [blame] | 215 | to grant specific users read access. In addition, system |
| 216 | groups "wheel" and "adm" will be given read-only access to |
| 217 | journal files using systemd-tmpfiles.service. |
Lennart Poettering | a24c64f | 2013-03-05 18:53:21 +0100 | [diff] [blame] | 218 | |
Lennart Poettering | 37495ee | 2013-03-05 19:15:31 +0100 | [diff] [blame] | 219 | The journal gateway daemon requires the |
Michael Biebl | 1a9ce3f | 2013-03-05 19:19:26 +0100 | [diff] [blame] | 220 | "systemd-journal-gateway" system user and group to |
Lennart Poettering | 37495ee | 2013-03-05 19:15:31 +0100 | [diff] [blame] | 221 | exist. During execution this network facing service will drop |
| 222 | privileges and assume this uid/gid for security reasons. |
| 223 | |
Jan Engelhardt | 8d0e0dd | 2014-06-28 00:48:28 +0200 | [diff] [blame] | 224 | Similarly, the NTP daemon requires the "systemd-timesync" system |
Lennart Poettering | 323a2f0 | 2014-06-04 11:17:32 +0200 | [diff] [blame] | 225 | user and group to exist. |
Lennart Poettering | a349eb1 | 2014-05-17 20:33:47 +0200 | [diff] [blame] | 226 | |
Jan Engelhardt | 8d0e0dd | 2014-06-28 00:48:28 +0200 | [diff] [blame] | 227 | Similarly, the network management daemon requires the |
Lennart Poettering | 323a2f0 | 2014-06-04 11:17:32 +0200 | [diff] [blame] | 228 | "systemd-network" system user and group to exist. |
Lennart Poettering | e15007b | 2014-06-01 09:35:19 +0200 | [diff] [blame] | 229 | |
Jan Engelhardt | 8d0e0dd | 2014-06-28 00:48:28 +0200 | [diff] [blame] | 230 | Similarly, the name resolution daemon requires the |
Lennart Poettering | 323a2f0 | 2014-06-04 11:17:32 +0200 | [diff] [blame] | 231 | "systemd-resolve" system user and group to exist. |
| 232 | |
Lennart Poettering | 888e378 | 2016-02-08 23:35:24 +0100 | [diff] [blame] | 233 | Similarly, the coredump support requires the |
| 234 | "systemd-coredump" system user and group to exist. |
| 235 | |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 236 | NSS: |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 237 | systemd ships with four glibc NSS modules: |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 238 | |
| 239 | nss-myhostname resolves the local hostname to locally |
| 240 | configured IP addresses, as well as "localhost" to |
| 241 | 127.0.0.1/::1. |
| 242 | |
| 243 | nss-resolve enables DNS resolution via the systemd-resolved |
| 244 | DNS/LLMNR caching stub resolver "systemd-resolved". |
| 245 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 246 | nss-mymachines enables resolution of all local containers registered |
| 247 | with machined to their respective IP addresses. It also maps UID/GIDs |
| 248 | ranges used by containers to useful names. |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 249 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 250 | nss-systemd enables resolution of all dynamically allocated service |
| 251 | users. (See the DynamicUser= setting in unit files.) |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 252 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 253 | To make use of these NSS modules, please add them to the "hosts:", |
| 254 | "passwd:" and "group:" lines in /etc/nsswitch.conf. The "resolve" |
| 255 | module should replace the glibc "dns" module in this file (and don't |
| 256 | worry, it chain-loads the "dns" module if it can't talk to resolved). |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 257 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 258 | The four modules should be used in the following order: |
| 259 | |
| 260 | passwd: compat mymachines systemd |
| 261 | group: compat mymachines systemd |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 262 | hosts: files mymachines resolve myhostname |
| 263 | |
Martin Pitt | 0f0467e | 2015-05-27 17:04:49 +0200 | [diff] [blame] | 264 | SYSV INIT.D SCRIPTS: |
| 265 | When calling "systemctl enable/disable/is-enabled" on a unit which is a |
| 266 | SysV init.d script, it calls /usr/lib/systemd/systemd-sysv-install; |
| 267 | this needs to translate the action into the distribution specific |
| 268 | mechanism such as chkconfig or update-rc.d. Packagers need to provide |
| 269 | this script if you need this functionality (you don't if you disabled |
| 270 | SysV init support). |
| 271 | |
| 272 | Please see src/systemctl/systemd-sysv-install.SKELETON for how this |
| 273 | needs to look like, and provide an implementation at the marked places. |
| 274 | |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 275 | WARNINGS: |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 276 | systemd will warn you during boot if /usr is on a different |
| 277 | file system than /. While in systemd itself very little will |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 278 | break if /usr is on a separate partition, many of its |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 279 | dependencies very likely will break sooner or later in one |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 280 | form or another. For example, udev rules tend to refer to |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 281 | binaries in /usr, binaries that link to libraries in /usr or |
| 282 | binaries that refer to data files in /usr. Since these |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 283 | breakages are not always directly visible, systemd will warn |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 284 | about this, since this kind of file system setup is not really |
| 285 | supported anymore by the basic set of Linux OS components. |
Lennart Poettering | fc7a744 | 2011-03-01 23:44:26 +0100 | [diff] [blame] | 286 | |
Lennart Poettering | 47bc23c | 2014-02-26 02:54:37 +0100 | [diff] [blame] | 287 | systemd requires that the /run mount point exists. systemd also |
Ronny Chevalier | 8f42ccd | 2015-05-30 10:31:41 +0200 | [diff] [blame] | 288 | requires that /var/run is a symlink to /run. |
Lennart Poettering | 47bc23c | 2014-02-26 02:54:37 +0100 | [diff] [blame] | 289 | |
Lennart Poettering | aa16713 | 2011-03-04 05:07:01 +0100 | [diff] [blame] | 290 | For more information on this issue consult |
AsciiWolf | c6749ba | 2017-02-21 18:26:23 +0100 | [diff] [blame] | 291 | https://www.freedesktop.org/wiki/Software/systemd/separate-usr-is-broken |
Lennart Poettering | aa16713 | 2011-03-04 05:07:01 +0100 | [diff] [blame] | 292 | |
Zbigniew Jędrzejewski-Szmek | 1b4bb4f | 2012-10-12 12:56:19 +0000 | [diff] [blame] | 293 | To run systemd under valgrind, compile with VALGRIND defined |
| 294 | (e.g. ./configure CPPFLAGS='... -DVALGRIND=1'). Otherwise, |
| 295 | false positives will be triggered by code which violates |
| 296 | some rules but is actually safe. |
Lennart Poettering | 2b671e9 | 2014-11-06 15:27:13 +0100 | [diff] [blame] | 297 | |
Lennart Poettering | ada64a0 | 2015-12-10 11:57:08 +0100 | [diff] [blame] | 298 | ENGINEERING AND CONSULTING SERVICES: |
| 299 | Kinvolk (https://kinvolk.io) offers professional engineering |
| 300 | and consulting services for systemd. Please contact Chris Kühl |
| 301 | <chris@kinvolk.io> for more information. |