Lennart Poettering | d657c51 | 2012-01-25 02:20:38 +0100 | [diff] [blame] | 1 | systemd System and Service Manager |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 2 | |
| 3 | DETAILS: |
| 4 | http://0pointer.de/blog/projects/systemd.html |
| 5 | |
| 6 | WEB SITE: |
AsciiWolf | 19d9372 | 2017-02-21 15:56:04 +0100 | [diff] [blame] | 7 | https://www.freedesktop.org/wiki/Software/systemd |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 8 | |
| 9 | GIT: |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 10 | git@github.com:systemd/systemd.git |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 11 | https://github.com/systemd/systemd |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 12 | |
| 13 | MAILING LIST: |
AsciiWolf | 19d9372 | 2017-02-21 15:56:04 +0100 | [diff] [blame] | 14 | https://lists.freedesktop.org/mailman/listinfo/systemd-devel |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 15 | |
| 16 | IRC: |
| 17 | #systemd on irc.freenode.org |
| 18 | |
| 19 | BUG REPORTS: |
Jonathan Boulle | eb0914f | 2015-06-02 15:57:50 -0700 | [diff] [blame] | 20 | https://github.com/systemd/systemd/issues |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 21 | |
| 22 | AUTHOR: |
Lennart Poettering | 5430f7f | 2012-04-12 00:20:58 +0200 | [diff] [blame] | 23 | Lennart Poettering |
| 24 | Kay Sievers |
| 25 | ...and many others |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 26 | |
Lennart Poettering | 673eab9 | 2011-07-14 23:53:53 +0200 | [diff] [blame] | 27 | LICENSE: |
Lennart Poettering | 5430f7f | 2012-04-12 00:20:58 +0200 | [diff] [blame] | 28 | LGPLv2.1+ for all code |
Kay Sievers | a095315 | 2015-06-09 14:27:33 +0200 | [diff] [blame] | 29 | - except src/basic/MurmurHash2.c which is Public Domain |
| 30 | - except src/basic/siphash24.c which is CC0 Public Domain |
Kay Sievers | 8542472 | 2013-08-14 22:58:21 +0200 | [diff] [blame] | 31 | - except src/journal/lookup3.c which is Public Domain |
| 32 | - except src/udev/* which is (currently still) GPLv2, GPLv2+ |
Tim Teichmann | 0490b44 | 2019-10-06 17:59:53 +0200 | [diff] [blame] | 33 | - except tools/chromiumos/* which is BSD-style |
Lennart Poettering | 673eab9 | 2011-07-14 23:53:53 +0200 | [diff] [blame] | 34 | |
Lennart Poettering | 31cee6f | 2010-05-13 03:30:21 +0200 | [diff] [blame] | 35 | REQUIREMENTS: |
Michael Biebl | dcce98a | 2017-03-02 19:11:37 +0100 | [diff] [blame] | 36 | Linux kernel >= 3.13 |
Lennart Poettering | a0c3e16 | 2015-09-06 15:58:20 +0200 | [diff] [blame] | 37 | Linux kernel >= 4.2 for unified cgroup hierarchy support |
Luca Boccassi | c2923fd | 2020-06-02 15:35:58 +0100 | [diff] [blame] | 38 | Linux kernel >= 5.4 for signed Verity images support |
Kay Sievers | 23aedd0 | 2014-03-22 18:27:35 +0100 | [diff] [blame] | 39 | |
| 40 | Kernel Config Options: |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 41 | CONFIG_DEVTMPFS |
Jan Engelhardt | d28315e | 2014-05-03 19:15:23 +0200 | [diff] [blame] | 42 | CONFIG_CGROUPS (it is OK to disable all controllers) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 43 | CONFIG_INOTIFY_USER |
| 44 | CONFIG_SIGNALFD |
| 45 | CONFIG_TIMERFD |
| 46 | CONFIG_EPOLL |
Kay Sievers | 4193869 | 2013-03-06 19:51:52 +0100 | [diff] [blame] | 47 | CONFIG_NET |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 48 | CONFIG_SYSFS |
Shawn Landden | 06d461e | 2013-12-09 07:04:06 -0800 | [diff] [blame] | 49 | CONFIG_PROC_FS |
Kay Sievers | 5d31974 | 2014-02-15 17:21:49 +0100 | [diff] [blame] | 50 | CONFIG_FHANDLE (libudev, mount and bind mount handling) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 51 | |
Mike Gilbert | 9c7f7d8 | 2017-02-25 22:42:27 -0500 | [diff] [blame] | 52 | Kernel crypto/hash API |
| 53 | CONFIG_CRYPTO_USER_API_HASH |
| 54 | CONFIG_CRYPTO_HMAC |
| 55 | CONFIG_CRYPTO_SHA256 |
| 56 | |
Kay Sievers | be2ea72 | 2014-08-30 11:34:20 +0200 | [diff] [blame] | 57 | udev will fail to work with the legacy sysfs layout: |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 58 | CONFIG_SYSFS_DEPRECATED=n |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 59 | |
| 60 | Legacy hotplug slows down the system and confuses udev: |
| 61 | CONFIG_UEVENT_HELPER_PATH="" |
| 62 | |
Kay Sievers | be2ea72 | 2014-08-30 11:34:20 +0200 | [diff] [blame] | 63 | Userspace firmware loading is not supported and should |
| 64 | be disabled in the kernel: |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 65 | CONFIG_FW_LOADER_USER_HELPER=n |
| 66 | |
| 67 | Some udev rules and virtualization detection relies on it: |
| 68 | CONFIG_DMIID |
| 69 | |
Kay Sievers | a5c724b | 2013-09-15 07:29:25 +0200 | [diff] [blame] | 70 | Support for some SCSI devices serial number retrieval, to |
| 71 | create additional symlinks in /dev/disk/ and /dev/tape: |
| 72 | CONFIG_BLK_DEV_BSG |
| 73 | |
Alan Jenkins | 45a582d | 2018-01-15 16:55:11 +0000 | [diff] [blame] | 74 | Required for PrivateNetwork= in service units: |
Mike Gilbert | 1346882 | 2014-03-31 14:28:23 -0400 | [diff] [blame] | 75 | CONFIG_NET_NS |
Zbigniew Jędrzejewski-Szmek | b52a4a3 | 2014-12-30 09:57:01 -0500 | [diff] [blame] | 76 | Note that systemd-localed.service and other systemd units use |
Alan Jenkins | 45a582d | 2018-01-15 16:55:11 +0000 | [diff] [blame] | 77 | PrivateNetwork so this is effectively required. |
Mike Gilbert | 1346882 | 2014-03-31 14:28:23 -0400 | [diff] [blame] | 78 | |
Lennart Poettering | 0ca48bb | 2017-02-06 21:13:21 +0100 | [diff] [blame] | 79 | Required for PrivateUsers= in service units: |
Lucas Werkmeister | 87fe170 | 2017-01-24 03:18:07 +0100 | [diff] [blame] | 80 | CONFIG_USER_NS |
| 81 | |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 82 | Optional but strongly recommended: |
| 83 | CONFIG_IPV6 |
| 84 | CONFIG_AUTOFS4_FS |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 85 | CONFIG_TMPFS_XATTR |
George G | 0ceced3 | 2018-01-04 07:53:44 +0000 | [diff] [blame] | 86 | CONFIG_{TMPFS,EXT4_FS,XFS,BTRFS_FS,...}_POSIX_ACL |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 87 | CONFIG_SECCOMP |
Felipe Sateler | fd74fa7 | 2016-09-05 19:16:13 -0300 | [diff] [blame] | 88 | CONFIG_SECCOMP_FILTER (required for seccomp support) |
Lennart Poettering | 3b920d7 | 2015-05-18 16:35:24 +0200 | [diff] [blame] | 89 | CONFIG_CHECKPOINT_RESTORE (for the kcmp() syscall) |
Kay Sievers | 713bc0c | 2013-03-06 19:36:39 +0100 | [diff] [blame] | 90 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 91 | Required for CPUShares= in resource control unit settings |
Umut Tezduyar Lindskog | a21b467 | 2014-06-10 23:29:30 +0200 | [diff] [blame] | 92 | CONFIG_CGROUP_SCHED |
| 93 | CONFIG_FAIR_GROUP_SCHED |
| 94 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 95 | Required for CPUQuota= in resource control unit settings |
WaLyong Cho | 0acd5a0 | 2014-11-19 00:13:43 +0900 | [diff] [blame] | 96 | CONFIG_CFS_BANDWIDTH |
| 97 | |
Andrew Jeddeloh | b1b9638 | 2017-11-21 14:54:20 -0800 | [diff] [blame] | 98 | Required for IPAddressDeny= and IPAddressAllow= in resource control |
| 99 | unit settings |
| 100 | CONFIG_CGROUP_BPF |
| 101 | |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 102 | For UEFI systems: |
Thomas Bächler | f33016f | 2014-03-22 01:41:12 +0100 | [diff] [blame] | 103 | CONFIG_EFIVAR_FS |
Kay Sievers | f28cbd0 | 2013-03-06 20:01:45 +0100 | [diff] [blame] | 104 | CONFIG_EFI_PARTITION |
| 105 | |
Luca Boccassi | c2923fd | 2020-06-02 15:35:58 +0100 | [diff] [blame] | 106 | Required for signed Verity images support: |
| 107 | CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG |
| 108 | |
Lennart Poettering | f4e74be | 2015-07-11 14:18:35 -0300 | [diff] [blame] | 109 | We recommend to turn off Real-Time group scheduling in the |
| 110 | kernel when using systemd. RT group scheduling effectively |
| 111 | makes RT scheduling unavailable for most userspace, since it |
| 112 | requires explicit assignment of RT budgets to each unit whose |
| 113 | processes making use of RT. As there's no sensible way to |
| 114 | assign these budgets automatically this cannot really be |
| 115 | fixed, and it's best to disable group scheduling hence. |
| 116 | CONFIG_RT_GROUP_SCHED=n |
| 117 | |
Lennart Poettering | f5a93d5 | 2017-07-24 11:28:04 +0200 | [diff] [blame] | 118 | It's a good idea to disable the implicit creation of networking bonding |
| 119 | devices by the kernel networking bonding module, so that the |
| 120 | automatically created "bond0" interface doesn't conflict with any such |
Dimitri John Ledkov | 582faeb | 2017-08-02 13:41:18 +0100 | [diff] [blame] | 121 | device created by systemd-networkd (or other tools). Ideally there |
| 122 | would be a kernel compile-time option for this, but there currently |
| 123 | isn't. The next best thing is to make this change through a modprobe.d |
| 124 | drop-in. This is shipped by default, see modprobe.d/systemd.conf. |
Lennart Poettering | f5a93d5 | 2017-07-24 11:28:04 +0200 | [diff] [blame] | 125 | |
Alan Jenkins | 45a582d | 2018-01-15 16:55:11 +0000 | [diff] [blame] | 126 | Required for systemd-nspawn: |
| 127 | CONFIG_DEVPTS_MULTIPLE_INSTANCES or Linux kernel >= 4.7 |
| 128 | |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 129 | Note that kernel auditing is broken when used with systemd's |
| 130 | container code. When using systemd in conjunction with |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 131 | containers, please make sure to either turn off auditing at |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 132 | runtime using the kernel command line option "audit=0", or |
| 133 | turn it off at kernel compile time using: |
| 134 | CONFIG_AUDIT=n |
Lennart Poettering | a7b1c39 | 2014-03-11 05:40:36 +0100 | [diff] [blame] | 135 | If systemd is compiled with libseccomp support on |
| 136 | architectures which do not use socketcall() and where seccomp |
| 137 | is supported (this effectively means x86-64 and ARM, but |
Jan Engelhardt | 70a44af | 2014-05-03 19:15:24 +0200 | [diff] [blame] | 138 | excludes 32-bit x86!), then nspawn will now install a |
Lennart Poettering | a7b1c39 | 2014-03-11 05:40:36 +0100 | [diff] [blame] | 139 | work-around seccomp filter that makes containers boot even |
| 140 | with audit being enabled. This works correctly only on kernels |
| 141 | 3.14 and newer though. TL;DR: turn audit off, still. |
Lennart Poettering | 77b6e19 | 2013-05-10 00:14:12 +0200 | [diff] [blame] | 142 | |
Łukasz Stelmach | 3dd26f3 | 2015-04-10 19:39:17 +0200 | [diff] [blame] | 143 | glibc >= 2.16 |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 144 | libcap |
Zbigniew Jędrzejewski-Szmek | d6e8096 | 2017-09-15 14:47:57 +0200 | [diff] [blame] | 145 | libmount >= 2.30 (from util-linux) |
| 146 | (util-linux *must* be built without --enable-libmount-support-mtab) |
hbrueckner | 6abfd30 | 2016-10-05 13:58:55 +0200 | [diff] [blame] | 147 | libseccomp >= 2.3.1 (optional) |
Gabriel de Perthuis | d47f6ca | 2014-12-13 01:56:56 +0100 | [diff] [blame] | 148 | libblkid >= 2.24 (from util-linux) (optional) |
Tom Gundersen | a18535d | 2013-10-17 19:49:19 +0200 | [diff] [blame] | 149 | libkmod >= 15 (optional) |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 150 | PAM >= 1.1.2 (optional) |
Luca Boccassi | c2923fd | 2020-06-02 15:35:58 +0100 | [diff] [blame] | 151 | libcryptsetup (optional), >= 2.3.0 required for signed Verity images support |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 152 | libaudit (optional) |
Zbigniew Jędrzejewski-Szmek | 19d5d4c | 2011-07-12 13:57:48 +0200 | [diff] [blame] | 153 | libacl (optional) |
Anita Zhang | e71f558 | 2020-08-17 23:09:38 -0700 | [diff] [blame] | 154 | libfdisk >= 2.33 (from util-linux) (optional) |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 155 | libselinux (optional) |
Zbigniew Jędrzejewski-Szmek | 19d5d4c | 2011-07-12 13:57:48 +0200 | [diff] [blame] | 156 | liblzma (optional) |
Zbigniew Jędrzejewski-Szmek | e0a1d4b | 2018-10-29 18:32:51 +0100 | [diff] [blame] | 157 | liblz4 >= 1.3.0 / 130 (optional) |
Norbert Lange | ef5924a | 2020-04-12 01:09:05 +0200 | [diff] [blame] | 158 | libzstd >= 1.4.0 (optional) |
Lennart Poettering | 7b17a7d | 2012-09-28 00:46:32 +0200 | [diff] [blame] | 159 | libgcrypt (optional) |
| 160 | libqrencode (optional) |
| 161 | libmicrohttpd (optional) |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 162 | libpython (optional) |
Zbigniew Jędrzejewski-Szmek | 87057e2 | 2017-05-09 21:56:34 -0400 | [diff] [blame] | 163 | libidn2 or libidn (optional) |
Iwan Timmer | 38e053c | 2019-10-29 20:26:05 +0100 | [diff] [blame] | 164 | gnutls >= 3.1.4 (optional, >= 3.6.0 is required to support DNS-over-TLS with gnutls) |
Iwan Timmer | 096cbdc | 2018-07-26 22:47:50 +0100 | [diff] [blame] | 165 | openssl >= 1.1.0 (optional, required to support DNS-over-TLS with openssl) |
Lennart Poettering | 5b24471 | 2014-06-23 12:42:17 +0200 | [diff] [blame] | 166 | elfutils >= 158 (optional) |
Zbigniew Jędrzejewski-Szmek | d79a2f5 | 2017-11-13 21:54:45 +0100 | [diff] [blame] | 167 | polkit (optional) |
Zbigniew Jędrzejewski-Szmek | 781748a | 2019-02-28 15:37:06 +0100 | [diff] [blame] | 168 | tzdata >= 2014f (optional) |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 169 | pkg-config |
Mike Gilbert | 8f968c7 | 2017-08-05 18:30:37 -0400 | [diff] [blame] | 170 | gperf |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 171 | docbook-xsl (optional, required for documentation) |
| 172 | xsltproc (optional, required for documentation) |
| 173 | python-lxml (optional, required to build the indices) |
Yu Watanabe | 40f116f | 2019-01-13 09:42:28 +0900 | [diff] [blame] | 174 | python >= 3.5 |
| 175 | meson >= 0.46 (>= 0.49 is required to build position-independent executables) |
| 176 | ninja |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 177 | gcc, awk, sed, grep, m4, and similar tools |
Lennart Poettering | 3ede835 | 2011-02-16 19:09:11 +0100 | [diff] [blame] | 178 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 179 | During runtime, you need the following additional |
| 180 | dependencies: |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 181 | |
Martin Pitt | 1d40ddb | 2015-11-02 10:05:20 -0600 | [diff] [blame] | 182 | util-linux >= v2.27.1 required |
Lennart Poettering | b895fa0 | 2019-12-20 12:26:17 +0100 | [diff] [blame] | 183 | dbus >= 1.4.0 (strictly speaking optional, but recommended) |
| 184 | NOTE: If using dbus < 1.9.18, you should override the default |
| 185 | policy directory (--with-dbuspolicydir=/etc/dbus-1/system.d). |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 186 | dracut (optional) |
Zbigniew Jędrzejewski-Szmek | d35f51e | 2018-07-16 12:44:24 +0200 | [diff] [blame] | 187 | polkit (optional) |
Zbigniew Jędrzejewski-Szmek | 2cc86f0 | 2012-11-22 15:30:50 +0100 | [diff] [blame] | 188 | |
Zbigniew Jędrzejewski-Szmek | 3e609a8 | 2017-04-18 21:52:30 -0400 | [diff] [blame] | 189 | To build in directory build/: |
| 190 | meson build/ && ninja -C build |
| 191 | |
Ben Boeckel | 5238e95 | 2019-04-26 20:22:40 -0400 | [diff] [blame] | 192 | Any configuration options can be specified as -Darg=value... arguments |
Zbigniew Jędrzejewski-Szmek | 3e609a8 | 2017-04-18 21:52:30 -0400 | [diff] [blame] | 193 | to meson. After the build directory is initially configured, meson will |
| 194 | refuse to run again, and options must be changed with: |
| 195 | mesonconf -Darg=value... |
| 196 | mesonconf without any arguments will print out available options and |
| 197 | their current values. |
| 198 | |
| 199 | Useful commands: |
| 200 | ninja -v some/target |
| 201 | ninja test |
| 202 | sudo ninja install |
| 203 | DESTDIR=... ninja install |
| 204 | |
Zbigniew Jędrzejewski-Szmek | 72cdb3e | 2017-07-02 20:21:34 -0400 | [diff] [blame] | 205 | A tarball can be created with: |
Kay Sievers | 8262706 | 2015-06-23 13:40:53 +0200 | [diff] [blame] | 206 | git archive --format=tar --prefix=systemd-222/ v222 | xz > systemd-222.tar.xz |
| 207 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 208 | When systemd-hostnamed is used, it is strongly recommended to |
| 209 | install nss-myhostname to ensure that, in a world of |
| 210 | dynamically changing hostnames, the hostname stays resolvable |
Lennart Poettering | fff2e5b | 2011-05-17 19:35:56 +0200 | [diff] [blame] | 211 | under all circumstances. In fact, systemd-hostnamed will warn |
Kay Sievers | bf9e477 | 2013-01-24 10:31:34 +0100 | [diff] [blame] | 212 | if nss-myhostname is not installed. |
Lennart Poettering | fff2e5b | 2011-05-17 19:35:56 +0200 | [diff] [blame] | 213 | |
Lennart Poettering | 01c8938 | 2017-11-17 11:39:14 +0100 | [diff] [blame] | 214 | nss-systemd must be enabled on systemd systems, as that's required for |
| 215 | DynamicUser= to work. Note that we ship services out-of-the-box that |
| 216 | make use of DynamicUser= now, hence enabling nss-systemd is not |
| 217 | optional. |
| 218 | |
Lennart Poettering | 1815dfb | 2018-07-16 12:18:36 +0200 | [diff] [blame] | 219 | Note that the build prefix for systemd must be /usr. (Moreover, |
| 220 | packages systemd relies on — such as D-Bus — really should use the same |
| 221 | prefix, otherwise you are on your own.) -Dsplit-usr=false (which is the |
| 222 | default and does not need to be specified) is the recommended setting, |
| 223 | and -Dsplit-usr=true should be used on systems which have /usr on a |
| 224 | separate partition. |
Lennart Poettering | 01c8938 | 2017-11-17 11:39:14 +0100 | [diff] [blame] | 225 | |
Zbigniew Jędrzejewski-Szmek | a2fc3d8 | 2016-10-15 20:51:19 -0400 | [diff] [blame] | 226 | Additional packages are necessary to run some tests: |
| 227 | - busybox (used by test/TEST-13-NSPAWN-SMOKE) |
| 228 | - nc (used by test/TEST-12-ISSUE-3171) |
| 229 | - python3-pyparsing |
| 230 | - python3-evdev (used by hwdb parsing tests) |
| 231 | - strace (used by test/test-functions) |
Zbigniew Jędrzejewski-Szmek | e94681a | 2017-02-12 00:22:20 -0500 | [diff] [blame] | 232 | - capsh (optional, used by test-execute) |
Zbigniew Jędrzejewski-Szmek | a2fc3d8 | 2016-10-15 20:51:19 -0400 | [diff] [blame] | 233 | |
Lennart Poettering | a24c64f | 2013-03-05 18:53:21 +0100 | [diff] [blame] | 234 | USERS AND GROUPS: |
Lennart Poettering | 37495ee | 2013-03-05 19:15:31 +0100 | [diff] [blame] | 235 | Default udev rules use the following standard system group |
| 236 | names, which need to be resolvable by getgrnam() at any time, |
| 237 | even in the very early boot stages, where no other databases |
| 238 | and network are available: |
| 239 | |
Lennart Poettering | 2422bd2 | 2017-11-20 12:30:42 +0100 | [diff] [blame] | 240 | audio, cdrom, dialout, disk, input, kmem, kvm, lp, render, tape, tty, video |
Kay Sievers | 37c0e8f | 2013-03-05 19:04:48 +0100 | [diff] [blame] | 241 | |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 242 | During runtime, the journal daemon requires the |
Michael Biebl | 1a9ce3f | 2013-03-05 19:19:26 +0100 | [diff] [blame] | 243 | "systemd-journal" system group to exist. New journal files will |
Jan Engelhardt | 19aadac | 2013-10-22 01:50:48 +0200 | [diff] [blame] | 244 | be readable by this group (but not writable), which may be used |
Zbigniew Jędrzejewski-Szmek | a48a62a | 2015-01-18 15:05:40 -0500 | [diff] [blame] | 245 | to grant specific users read access. In addition, system |
| 246 | groups "wheel" and "adm" will be given read-only access to |
| 247 | journal files using systemd-tmpfiles.service. |
Lennart Poettering | a24c64f | 2013-03-05 18:53:21 +0100 | [diff] [blame] | 248 | |
Yu Watanabe | f959c5c | 2018-05-01 15:15:44 +0900 | [diff] [blame] | 249 | The journal remote daemon requires the |
| 250 | "systemd-journal-remote" system user and group to |
Lennart Poettering | 37495ee | 2013-03-05 19:15:31 +0100 | [diff] [blame] | 251 | exist. During execution this network facing service will drop |
| 252 | privileges and assume this uid/gid for security reasons. |
| 253 | |
Jan Engelhardt | 8d0e0dd | 2014-06-28 00:48:28 +0200 | [diff] [blame] | 254 | Similarly, the network management daemon requires the |
Lennart Poettering | 323a2f0 | 2014-06-04 11:17:32 +0200 | [diff] [blame] | 255 | "systemd-network" system user and group to exist. |
Lennart Poettering | e15007b | 2014-06-01 09:35:19 +0200 | [diff] [blame] | 256 | |
Jan Engelhardt | 8d0e0dd | 2014-06-28 00:48:28 +0200 | [diff] [blame] | 257 | Similarly, the name resolution daemon requires the |
Lennart Poettering | 323a2f0 | 2014-06-04 11:17:32 +0200 | [diff] [blame] | 258 | "systemd-resolve" system user and group to exist. |
| 259 | |
Lennart Poettering | 888e378 | 2016-02-08 23:35:24 +0100 | [diff] [blame] | 260 | Similarly, the coredump support requires the |
| 261 | "systemd-coredump" system user and group to exist. |
| 262 | |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 263 | NSS: |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 264 | systemd ships with four glibc NSS modules: |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 265 | |
Lennart Poettering | 38ccb55 | 2020-07-07 21:58:12 +0200 | [diff] [blame] | 266 | nss-myhostname resolves the local hostname to locally configured IP |
| 267 | addresses, as well as "localhost" to 127.0.0.1/::1. |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 268 | |
Lennart Poettering | 38ccb55 | 2020-07-07 21:58:12 +0200 | [diff] [blame] | 269 | nss-resolve enables DNS resolution via the systemd-resolved DNS/LLMNR |
| 270 | caching stub resolver "systemd-resolved". |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 271 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 272 | nss-mymachines enables resolution of all local containers registered |
Lennart Poettering | 38ccb55 | 2020-07-07 21:58:12 +0200 | [diff] [blame] | 273 | with machined to their respective IP addresses. |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 274 | |
Lennart Poettering | 38ccb55 | 2020-07-07 21:58:12 +0200 | [diff] [blame] | 275 | nss-systemd enables resolution of users/group registered via the |
| 276 | User/Group Record Lookup API (https://systemd.io/USER_GROUP_API/), |
| 277 | including all dynamically allocated service users. (See the |
| 278 | DynamicUser= setting in unit files.) |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 279 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 280 | To make use of these NSS modules, please add them to the "hosts:", |
| 281 | "passwd:" and "group:" lines in /etc/nsswitch.conf. The "resolve" |
| 282 | module should replace the glibc "dns" module in this file (and don't |
| 283 | worry, it chain-loads the "dns" module if it can't talk to resolved). |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 284 | |
Lennart Poettering | 409093f | 2016-07-14 19:19:49 +0200 | [diff] [blame] | 285 | The four modules should be used in the following order: |
| 286 | |
Lennart Poettering | 38ccb55 | 2020-07-07 21:58:12 +0200 | [diff] [blame] | 287 | passwd: compat systemd |
| 288 | group: compat systemd |
Yu Watanabe | a42d4f5 | 2018-05-01 15:18:10 +0900 | [diff] [blame] | 289 | hosts: files mymachines resolve [!UNAVAIL=return] dns myhostname |
Lennart Poettering | a4a7960 | 2014-08-19 21:55:10 +0200 | [diff] [blame] | 290 | |
Martin Pitt | 0f0467e | 2015-05-27 17:04:49 +0200 | [diff] [blame] | 291 | SYSV INIT.D SCRIPTS: |
| 292 | When calling "systemctl enable/disable/is-enabled" on a unit which is a |
| 293 | SysV init.d script, it calls /usr/lib/systemd/systemd-sysv-install; |
| 294 | this needs to translate the action into the distribution specific |
| 295 | mechanism such as chkconfig or update-rc.d. Packagers need to provide |
| 296 | this script if you need this functionality (you don't if you disabled |
| 297 | SysV init support). |
| 298 | |
| 299 | Please see src/systemctl/systemd-sysv-install.SKELETON for how this |
| 300 | needs to look like, and provide an implementation at the marked places. |
| 301 | |
Lennart Poettering | 21bc923 | 2011-02-23 01:12:07 +0100 | [diff] [blame] | 302 | WARNINGS: |
Lennart Poettering | 9e93f6f | 2017-11-17 11:39:48 +0100 | [diff] [blame] | 303 | systemd will warn during early boot if /usr is not already mounted at |
| 304 | this point (that means: either located on the same file system as / or |
| 305 | already mounted in the initrd). While in systemd itself very little |
| 306 | will break if /usr is on a separate, late-mounted partition, many of |
| 307 | its dependencies very likely will break sooner or later in one form or |
| 308 | another. For example, udev rules tend to refer to binaries in /usr, |
| 309 | binaries that link to libraries in /usr or binaries that refer to data |
| 310 | files in /usr. Since these breakages are not always directly visible, |
| 311 | systemd will warn about this, since this kind of file system setup is |
| 312 | not really supported anymore by the basic set of Linux OS components. |
Lennart Poettering | fc7a744 | 2011-03-01 23:44:26 +0100 | [diff] [blame] | 313 | |
Lennart Poettering | 47bc23c | 2014-02-26 02:54:37 +0100 | [diff] [blame] | 314 | systemd requires that the /run mount point exists. systemd also |
Ronny Chevalier | 8f42ccd | 2015-05-30 10:31:41 +0200 | [diff] [blame] | 315 | requires that /var/run is a symlink to /run. |
Lennart Poettering | 47bc23c | 2014-02-26 02:54:37 +0100 | [diff] [blame] | 316 | |
Lennart Poettering | aa16713 | 2011-03-04 05:07:01 +0100 | [diff] [blame] | 317 | For more information on this issue consult |
AsciiWolf | c6749ba | 2017-02-21 18:26:23 +0100 | [diff] [blame] | 318 | https://www.freedesktop.org/wiki/Software/systemd/separate-usr-is-broken |
Lennart Poettering | aa16713 | 2011-03-04 05:07:01 +0100 | [diff] [blame] | 319 | |
Zbigniew Jędrzejewski-Szmek | d18cb39 | 2018-05-13 22:28:24 +0200 | [diff] [blame] | 320 | To run systemd under valgrind, compile with meson option |
| 321 | -Dvalgrind=true and have valgrind development headers installed |
| 322 | (i.e. valgrind-devel or equivalent). Otherwise, false positives will be |
| 323 | triggered by code which violates some rules but is actually safe. Note |
| 324 | that valgrind generates nice output only on exit(), hence on shutdown |
| 325 | we don't execve() systemd-shutdown. |
Lennart Poettering | 2b671e9 | 2014-11-06 15:27:13 +0100 | [diff] [blame] | 326 | |
Filipe Brandenburger | ba9e3fc | 2019-02-15 11:05:04 -0800 | [diff] [blame] | 327 | STABLE BRANCHES AND BACKPORTS: |
Lennart Poettering | bfeb370 | 2020-08-16 18:25:18 +0200 | [diff] [blame] | 328 | Stable branches with backported patches are available in the |
| 329 | systemd-stable repo at https://github.com/systemd/systemd-stable. |
Zbigniew Jędrzejewski-Szmek | 94ac201 | 2018-03-26 10:40:45 +0200 | [diff] [blame] | 330 | |
Lennart Poettering | bfeb370 | 2020-08-16 18:25:18 +0200 | [diff] [blame] | 331 | Stable branches are started for certain releases of systemd and named |
| 332 | after them, e.g. v238-stable. Stable branches are managed by |
| 333 | distribution maintainers on an as needed basis. See |
| 334 | https://www.freedesktop.org/wiki/Software/systemd/Backports/ for some |
| 335 | more information and examples. |
Zbigniew Jędrzejewski-Szmek | 94ac201 | 2018-03-26 10:40:45 +0200 | [diff] [blame] | 336 | |
Lennart Poettering | ada64a0 | 2015-12-10 11:57:08 +0100 | [diff] [blame] | 337 | ENGINEERING AND CONSULTING SERVICES: |
| 338 | Kinvolk (https://kinvolk.io) offers professional engineering |
| 339 | and consulting services for systemd. Please contact Chris Kühl |
| 340 | <chris@kinvolk.io> for more information. |