source: general/sysutils/systemd.xml@ 42ddc30

12.0 12.1 kea ken/TL2024 ken/tuningfonts lazarus lxqt plabs/newcss python3.11 rahul/power-profiles-daemon renodr/vulkan-addition trunk xry111/llvm18 xry111/xf86-video-removal
Last change on this file since 42ddc30 was cb594b6c, checked in by Xi Ruoyao <xry111@…>, 12 months ago

general: Remove non-exist User Notes link

Part of User Notes removal by
https://www.linuxfromscratch.org/~xry111/remove-nonexist-usernote.sh

  • Property mode set to 100644
File size: 15.6 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!-- <!ENTITY systemd-download-http "https://anduin.linuxfromscratch.org/LFS/systemd-&systemd-version;-&systemd-stable;.tar.xz"> For whenever we move to a stable snapshot for backports -->
8 <!ENTITY systemd-download-http "https://github.com/systemd/systemd/archive/v&systemd-version;/systemd-&systemd-version;.tar.gz">
9 <!ENTITY systemd-download-ftp " ">
10 <!ENTITY systemd-md5sum "7cf12ee8a91a04306fc6cf290eed42e8">
11 <!ENTITY systemd-size "12 MB">
12 <!ENTITY systemd-buildsize "297 MB (with tests)">
13 <!ENTITY systemd-time "3.7 SBU (with tests using 4 cores)">
14
15]>
16
17<sect1 id="systemd" xreflabel="Systemd-&systemd-version;" revision="systemd">
18 <?dbhtml filename="systemd.html"?>
19
20
21 <title>Systemd-&systemd-version;</title>
22 <!-- Whenever we switch back to stable backports, make sure to add the systemd-stable reference back. -->
23
24 <indexterm zone="systemd">
25 <primary sortas="a-systemd">systemd</primary>
26 </indexterm>
27
28 <sect2 role="package">
29 <title>Introduction to systemd</title>
30
31 <para>
32 While <application>systemd</application> was installed when
33 building LFS, there are many features provided by the package that
34 were not included in the initial installation because
35 <application>Linux-PAM</application> was not yet installed.
36 The <application>systemd</application> package needs to be
37 rebuilt to provide a working <command>systemd-logind</command> service,
38 which provides many additional features for dependent packages.
39 </para>
40
41 &lfs113_checked;
42
43 <bridgehead renderas="sect3">Package Information</bridgehead>
44 <itemizedlist spacing="compact">
45 <listitem>
46 <para>
47 Download (HTTP): <ulink url="&systemd-download-http;"/>
48 </para>
49 </listitem>
50 <listitem>
51 <para>
52 Download (FTP): <ulink url="&systemd-download-ftp;"/>
53 </para>
54 </listitem>
55 <listitem>
56 <para>
57 Download MD5 sum: &systemd-md5sum;
58 </para>
59 </listitem>
60 <listitem>
61 <para>
62 Download size: &systemd-size;
63 </para>
64 </listitem>
65 <listitem>
66 <para>
67 Estimated disk space required: &systemd-buildsize;
68 </para>
69 </listitem>
70 <listitem>
71 <para>
72 Estimated build time: &systemd-time;
73 </para>
74 </listitem>
75 </itemizedlist>
76
77<!-- Keep here in case a patch will be needed.-->
78<!--
79 <bridgehead renderas="sect3">Additional Downloads</bridgehead>
80 <itemizedlist spacing="compact">
81 <listitem>
82 <para>
83 Required patch:
84 <ulink url="&patch-root;/systemd-&systemd-version;-security_fix-1.patch"/>
85 </para>
86 </listitem>
87 </itemizedlist>
88-->
89 <bridgehead renderas="sect3">systemd Dependencies</bridgehead>
90
91 <bridgehead renderas="sect4">Recommended</bridgehead>
92
93 <note>
94 <para>
95 <xref linkend='linux-pam'/> is not strictly required to build
96 <application>systemd</application>, but the main reason to rebuild
97 <application>systemd</application> in BLFS (it's already built in
98 LFS anyway) is for the <command>systemd-logind</command> daemon and
99 the
100 <filename class='libraryfile'>pam_systemd.so</filename> PAM module.
101 <xref linkend='linux-pam'/> is required for them. All packages in
102 BLFS book with a dependency on <application>systemd</application>
103 expects it has been rebuilt with <xref linkend='linux-pam'/>.
104 </para>
105 </note>
106
107 <para role="recommended">
108 <xref linkend="linux-pam"/> and
109 <xref role="runtime" linkend="polkit"/> (runtime)
110 </para>
111
112 <bridgehead renderas="sect4">Optional</bridgehead>
113 <para role="optional">
114 <xref linkend="btrfs-progs"/>, <!-- homed may support it, see the C.E.-->
115 <xref linkend="curl"/>,
116 <xref linkend="cryptsetup"/>,
117 <xref linkend="git"/>,
118 <xref linkend="gnutls"/>,
119 <xref linkend="iptables"/>,
120 <xref linkend="libgcrypt"/>,
121 <xref linkend="libidn2"/>,
122 <xref linkend="libpwquality"/>,
123 <xref linkend="libseccomp"/>,
124 <xref linkend="libxkbcommon"/>,
125 <xref linkend="make-ca"/>,
126 <xref linkend="p11-kit"/>,
127 <xref linkend="pcre2"/>,
128 <xref linkend="qemu"/>,
129 <xref linkend="qrencode"/>,
130 <xref linkend="rsync"/>,
131 <xref linkend="sphinx"/>,
132 <xref linkend="valgrind"/>,
133 <xref linkend="zsh"/> (for the zsh completions),
134 <ulink url="https://sourceforge.net/projects/gnu-efi/">gnu-efi</ulink>,
135 <ulink url="https://www.kernel.org/pub/linux/utils/kernel/kexec/">kexec-tools</ulink>,
136 <ulink url="https://github.com/libbpf/libbpf">libbpf</ulink>,
137 <ulink url="https://sourceware.org/elfutils/">libdw</ulink>,
138 <ulink url="https://developers.yubico.com/libfido2/">libfido2</ulink>,
139 <ulink url="https://www.gnu.org/software/libmicrohttpd/">libmicrohttpd</ulink>,
140 <ulink url="https://lz4.github.io/lz4/">lz4</ulink>,
141 <!--<ulink url="http://fukuchi.org/works/qrencode/">qrencode</ulink>,-->
142 <ulink url="https://sourceforge.net/projects/linuxquota/">quota-tools</ulink>, and
143 <ulink url="https://tpm2-tss.readthedocs.io/en/latest/">tpm2-tss</ulink>
144 </para>
145
146 <bridgehead renderas="sect4">Optional (to rebuild the manual pages)</bridgehead>
147 <para role="optional">
148 <xref linkend="DocBook"/>,
149 <xref linkend="docbook-xsl"/>,
150 <xref linkend="libxslt"/>, and
151 <xref linkend="lxml"/> (to build the index of systemd manual pages)
152 </para>
153
154 </sect2>
155
156 <sect2 role="installation">
157 <title>Installation of systemd</title>
158<!--
159 <para>
160 First, fix a security issue in systemd-coredump:
161 </para>
162
163<screen><userinput>patch -Np1 -i ../systemd-&systemd-version;-security_fix-1.patch</userinput></screen>
164-->
165
166 <para>
167 Remove several inappropriate uses of the <literal>pure</literal>
168 attribute that cause runtime issues when the package is built
169 with gcc-13 or later:
170 </para>
171
172<screen><userinput>sed '/bus_message_type_from_string/s/_pure_//' \
173 -i src/libsystemd/sd-bus/bus-internal.h &amp;&amp;
174sed '/devt_hash_func/s/_pure_//' \
175 -i src/basic/hash-funcs.h &amp;&amp;
176sed '/job_get_timeout/s/_pure_//' \
177 -i src/core/job.h</userinput></screen>
178
179 <para>
180 Remove two unneeded groups,
181 <systemitem class="groupname">render</systemitem> and
182 <systemitem class="groupname">sgx</systemitem>, from the default udev
183 rules:
184 </para>
185
186<screen><userinput remap="pre">sed -i -e 's/GROUP="render"/GROUP="video"/' \
187 -e 's/GROUP="sgx", //' rules.d/50-udev-default.rules.in</userinput></screen>
188
189 <para>
190 Rebuild <application>systemd</application> by running the
191 following commands:
192 </para>
193
194<screen><userinput>mkdir build &amp;&amp;
195cd build &amp;&amp;
196
197meson setup .. \
198 --prefix=/usr \
199 --buildtype=release \
200 -Ddefault-dnssec=no \
201 -Dfirstboot=false \
202 -Dinstall-tests=false \
203 -Dldconfig=false \
204 -Dman=auto \
205 -Dsysusers=false \
206 -Drpmmacrosdir=no \
207 -Dhomed=false \
208 -Duserdb=false \
209 -Dmode=release \
210 -Dpam=true \
211 -Dpamconfdir=/etc/pam.d \
212 -Ddev-kvm-mode=0660 \
213 -Ddocdir=/usr/share/doc/systemd-&systemd-version; &amp;&amp;
214
215ninja</userinput></screen>
216<!-- Regarding homed and userdb, see the note below in Command Explanations-->
217
218 <note>
219 <para>
220 For the best test results, make sure you run the test suite from
221 a system that is booted by the same
222 <application>systemd</application> version you are rebuilding.
223 </para>
224 </note>
225
226 <para>
227 To test the results, issue:
228 <command>PATH+=:/usr/sbin ninja test</command>.
229 <!-- One test named test-repart needs sfdisk, which is in /usr/sbin. -->
230 The test named <filename>test-stat-util</filename> is known to fail
231 if the support for some namespaces is not enabled in the kernel
232 configuration. If the test suite is ran as the &root; user, some
233 other tests may fail because they depend on various kernel
234 configuration options.
235 </para>
236
237 <para>
238 Now, as the <systemitem class="username">root</systemitem> user:
239 </para>
240
241<screen role="root"><userinput>ninja install</userinput></screen>
242
243 </sect2>
244
245 <sect2 role="commands">
246 <title>Command Explanations</title>
247
248 <xi:include xmlns:xi="http://www.w3.org/2001/XInclude"
249 href="../../xincludes/meson-buildtype-release.xml"/>
250
251 <para>
252 <parameter>-Dpamconfdir=/etc/pam.d</parameter>: Forces the PAM files to
253 be installed in /etc/pam.d rather than /usr/lib/pam.d.
254 </para>
255
256 <para>
257 <parameter>-Duserdb=false</parameter>: Removes a daemon that does not
258 offer any use under a BLFS configuration. If you wish to enable the
259 <application>userdbd</application> daemon, replace "false" with "true"
260 in the above meson command.
261 </para>
262
263 <para>
264 <parameter>-Dhomed=false</parameter>: Removes a daemon that does not offer
265 any use under a traditional BLFS configuration, especially using accounts
266 created with useradd. To enable systemd-homed, first ensure that you have
267 <xref linkend="cryptsetup"/> and <xref linkend="libpwquality"/> installed,
268 and then change "false" to "true" in the above meson command.
269 </para>
270
271 <!-- EDITORS NOTE: Explanation on removing userdbd and homed:
272 In BLFS, we do not fully support disk encryption. We offer instructions for
273 building 'cryptsetup' as a dependency, but we do not offer instructions for
274 actually configuring it. In addition, we generally do not include
275 functionality that could potentially conflict with other packages, or that
276 is not of any use to us (in an enterprise configuration using Thin Clients
277 or laptops with LUKS encryption, it could make sense though, but that isn't
278 the configuration that we natively support).
279
280 A few of the complications of systemd-homed include:
281 - SSH Logins
282 - Disk Space Assignments
283 - UID Assignments (chown() on login)
284 (See https://cfp.all-systems-go.io/media/homed-asg2019.pdf)
285
286 In an article I read when systemd-homed was originally unveiled, I remember
287 reading about systemd-homed causing problems with OpenSSH Private Key Auth
288 because the user would have to login at the console in order to unlock
289 their home directory, thus allowing the private key to be unlocked and
290 processed by OpenSSH. Since BLFS does not fully support encrypted disks,
291 and because systemd-homed is incompatible with our usage of useradd /
292 traditional UNIX users and groups, I advise that we take the following
293 approach to avoid any confusion:
294
295 - Leave the added Short Descriptions for homectl and userdbctl
296 - Add the above command explanations and restore the previous behavior
297
298 Should we decide to enable homed by default anytime in the future,
299 let's move cryptsetup to recommended or required.
300
301 I would be open to discussing this after the next systemd version when
302 systemd-homed has matured a bit more. -renodr -->
303
304 </sect2>
305
306 <sect2 role="configuration">
307 <title>Configuring systemd</title>
308
309 <para>
310 The <filename>/etc/pam.d/system-session</filename> file needs to
311 be modified and a new file needs to be created in order for
312 <command>systemd-logind</command> to work correctly. Run the following
313 commands as the <systemitem class="username">root</systemitem> user:
314 </para>
315
316<screen role="root"><userinput>grep 'pam_systemd' /etc/pam.d/system-session ||
317cat &gt;&gt; /etc/pam.d/system-session &lt;&lt; "EOF"
318<literal># Begin Systemd addition
319
320session required pam_loginuid.so
321session optional pam_systemd.so
322
323# End Systemd addition</literal>
324EOF
325
326cat &gt; /etc/pam.d/systemd-user &lt;&lt; "EOF"
327<literal># Begin /etc/pam.d/systemd-user
328
329account required pam_access.so
330account include system-account
331
332session required pam_env.so
333session required pam_limits.so
334session required pam_unix.so
335session required pam_loginuid.so
336session optional pam_keyinit.so force revoke
337session optional pam_systemd.so
338
339auth required pam_deny.so
340password required pam_deny.so
341
342# End /etc/pam.d/systemd-user</literal>
343EOF</userinput></screen>
344
345 <warning>
346 <para>
347 If upgrading from a previous version of systemd and an
348 initrd is used for system boot, you should generate a new initrd before
349 rebooting the system.
350 </para>
351 </warning>
352
353 </sect2>
354
355 <sect2 role="content">
356 <title>Contents</title>
357
358 <para>
359 A list of the installed files, along with their short
360 descriptions can be found at
361 <ulink url="&lfs-root;/chapter08/systemd.html#contents-systemd"/>.
362 </para>
363
364 <para>
365 Listed below are the newly installed programs
366 along with short descriptions.
367 </para>
368
369 <segmentedlist>
370 <segtitle>Installed Programs</segtitle>
371
372 <seglistitem>
373 <seg>
374 <!-- maybe userdbd/userdbctl can go in LFS, try at next time -->
375 homectl (optional),
376 systemd-cryptenroll (if <xref linkend="cryptsetup"/> is installed),
377 and userdbctl (optional)
378 </seg>
379 </seglistitem>
380 </segmentedlist>
381
382 <variablelist>
383 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
384 <?dbfo list-presentation="list"?>
385 <?dbhtml list-presentation="table"?>
386
387 <varlistentry id="homectl">
388 <term><command>homectl</command></term>
389 <listitem>
390 <para>
391 is a tool to create, remove, change, or inspect a home directory
392 managed by <command>systemd-homed</command>; note that it's
393 useless for the classic UNIX users and home directories which
394 we are using in LFS/BLFS book
395 </para>
396 <indexterm zone="systemd homectl">
397 <primary sortas="b-homectl">homectl</primary>
398 </indexterm>
399 </listitem>
400 </varlistentry>
401
402 <varlistentry id="systemd-cryptenroll">
403 <term><command>systemd-cryptenroll</command></term>
404 <listitem>
405 <para>
406 Is used to enroll or remove a system from full disk encryption,
407 as well as set and query private keys and recovery keys
408 </para>
409 <indexterm zone="systemd systemd-cryptenroll">
410 <primary sortas="b-systemd-cryptenroll">systemd-cryptenroll</primary>
411 </indexterm>
412 </listitem>
413 </varlistentry>
414
415 <varlistentry id="userdbctl">
416 <term><command>userdbctl</command></term>
417 <listitem>
418 <para>
419 inspects users, groups, and group memberships
420 </para>
421 <indexterm zone="systemd userdbctl">
422 <primary sortas="b-userdbctl">userdbctl</primary>
423 </indexterm>
424 </listitem>
425 </varlistentry>
426
427 <varlistentry id="pam_systemd">
428 <term><filename class="libraryfile">pam_systemd.so</filename></term>
429 <listitem>
430 <para>
431 is a PAM module used to register user sessions with the
432 <application>systemd</application> login manager,
433 <command>systemd-logind</command>
434 </para>
435 <indexterm zone="systemd pam_systemd">
436 <primary sortas="c-pam_systemd">pam_systemd.so</primary>
437 </indexterm>
438 </listitem>
439 </varlistentry>
440
441 </variablelist>
442
443 </sect2>
444
445</sect1>
Note: See TracBrowser for help on using the repository browser.