source: general/sysutils/systemd.xml@ dc96204

10.0 10.1 11.0 11.1 11.2 11.3 12.0 12.1 kea ken/TL2024 ken/inkscape-core-mods ken/tuningfonts lazarus lxqt plabs/newcss plabs/python-mods python3.11 qt5new rahul/power-profiles-daemon renodr/vulkan-addition trunk upgradedb xry111/intltool xry111/llvm18 xry111/soup3 xry111/test-20220226 xry111/xf86-video-removal
Last change on this file since dc96204 was eebce9e6, checked in by Douglas R. Reno <renodr@…>, 4 years ago

Fix a segfault in systemd-udevd

git-svn-id: svn://svn.linuxfromscratch.org/BLFS/trunk/BOOK@23315 af4574ff-66df-0310-9fd7-8a98e5e911e0

  • Property mode set to 100644
File size: 15.5 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!-- <!ENTITY systemd-download-http "http://anduin.linuxfromscratch.org/LFS/systemd-&systemd-version;-&systemd-stable;.tar.xz"> For whenever we move to a stable snapshot for backports -->
8 <!ENTITY systemd-download-http "https://github.com/systemd/systemd/archive/v&systemd-version;/systemd-&systemd-version;.tar.gz">
9 <!ENTITY systemd-download-ftp " ">
10 <!ENTITY systemd-md5sum "04f02d9841ea5992a16f6b03c873da28">
11 <!ENTITY systemd-size "8.6 MB">
12 <!ENTITY systemd-buildsize "246 MB (with tests)">
13 <!ENTITY systemd-time "2.1 SBU (with tests)">
14
15]>
16
17<sect1 id="systemd" xreflabel="Systemd-&systemd-version;" revision="systemd">
18 <?dbhtml filename="systemd.html"?>
19
20 <sect1info>
21 <othername>$LastChangedBy$</othername>
22 <date>$Date$</date>
23 </sect1info>
24
25 <title>Systemd-&systemd-version;</title>
26 <!-- Whenever we switch back to stable backports, make sure to add the systemd-stable reference back. -->
27
28 <indexterm zone="systemd">
29 <primary sortas="a-systemd">systemd</primary>
30 </indexterm>
31
32 <sect2 role="package">
33 <title>Introduction to systemd</title>
34
35 <para>
36 While <application>systemd</application> was installed when
37 building LFS, there are many features provided by the package that
38 were not included in the initial installation because
39 <application>Linux-PAM</application> was not yet installed.
40 The <application>systemd</application> package needs to be
41 rebuilt to provide a working <command>systemd-logind</command> service,
42 which provides many additional features for dependent packages.
43 </para>
44
45 &lfs91_checked;
46
47 <bridgehead renderas="sect3">Package Information</bridgehead>
48 <itemizedlist spacing="compact">
49 <listitem>
50 <para>
51 Download (HTTP): <ulink url="&systemd-download-http;"/>
52 </para>
53 </listitem>
54 <listitem>
55 <para>
56 Download (FTP): <ulink url="&systemd-download-ftp;"/>
57 </para>
58 </listitem>
59 <listitem>
60 <para>
61 Download MD5 sum: &systemd-md5sum;
62 </para>
63 </listitem>
64 <listitem>
65 <para>
66 Download size: &systemd-size;
67 </para>
68 </listitem>
69 <listitem>
70 <para>
71 Estimated disk space required: &systemd-buildsize;
72 </para>
73 </listitem>
74 <listitem>
75 <para>
76 Estimated build time: &systemd-time;
77 </para>
78 </listitem>
79 </itemizedlist>
80
81 <bridgehead renderas="sect3">Additional Downloads</bridgehead>
82 <itemizedlist spacing="compact">
83 <listitem>
84 <para>
85 Required patch:
86 <ulink url="&patch-root;/systemd-&systemd-version;-gcc_10-fixes-2.patch"/>
87 </para>
88 </listitem>
89 </itemizedlist>
90
91 <bridgehead renderas="sect3">systemd Dependencies</bridgehead>
92
93 <bridgehead renderas="sect4">Required</bridgehead>
94 <para role="required">
95 <xref linkend="linux-pam"/>
96 </para>
97
98 <bridgehead renderas="sect4">Recommended Runtime Dependencies</bridgehead>
99 <para role="recommended">
100 <xref role="runtime" linkend="polkit"/>
101 </para>
102
103 <bridgehead renderas="sect4">Optional</bridgehead>
104 <para role="optional">
105 <xref linkend="btrfs-progs"/> <!-- homed may support it, see the C.E.-->
106 <xref linkend="curl"/>,
107 <xref linkend="cryptsetup"/>,
108 <xref linkend="git"/>,
109 <xref linkend="gnutls"/>,
110 <xref linkend="iptables"/>,
111 <xref linkend="libgcrypt"/>,
112 <xref linkend="libidn2"/>,
113 <xref linkend="libpwquality"/>,
114 <xref linkend="libseccomp"/>,
115 <xref linkend="libxkbcommon"/>,
116 <xref linkend="make-ca"/>,
117 <xref linkend="pcre2"/>,
118 <xref linkend="qemu"/>,
119 <xref linkend="valgrind"/>,
120 <xref linkend="zsh"/> (for the zsh completions),
121 <ulink url="http://sourceforge.net/projects/gnu-efi/">gnu-efi</ulink>,
122 <ulink url="https://www.kernel.org/pub/linux/utils/kernel/kexec/">kexec-tools</ulink>,
123 <ulink url="https://www.gnu.org/software/libmicrohttpd/">libmicrohttpd</ulink>,
124 <ulink url="http://lz4.github.io/lz4/">lz4</ulink>,
125 <ulink url="http://fukuchi.org/works/qrencode/">qrencode</ulink>,
126 <ulink url="http://sourceforge.net/projects/linuxquota/">quota-tools</ulink> and
127 <ulink url="https://pypi.python.org/pypi/Sphinx">Sphinx</ulink>
128 </para>
129
130 <bridgehead renderas="sect4">Optional (to rebuild the manual pages)</bridgehead>
131 <para role="optional">
132 <xref linkend="DocBook"/>,
133 <xref linkend="docbook-xsl"/>,
134 <xref linkend="libxslt"/>, and
135 <xref linkend="lxml"/> (to build the index of systemd manual pages)
136 </para>
137
138 <para condition="html" role="usernotes">User Notes:
139 <ulink url="&blfs-wiki;/systemd"/>
140 </para>
141 </sect2>
142
143 <sect2 role="installation">
144 <title>Installation of systemd</title>
145
146 <para>
147 Apply a patch to fix a build failure when building with GCC-10 as well as
148 a segmentation fault in systemd-udevd on some platforms:
149 </para>
150
151<screen><userinput remap="pre">patch -Np1 -i ../systemd-&systemd-version;-gcc_10-fixes-2.patch</userinput></screen>
152
153
154 <para>
155 Remove an unneeded group,
156 <systemitem class="groupname">render</systemitem>, from the default udev
157 rules:
158 </para>
159
160<screen><userinput remap="pre">sed -i 's/GROUP="render", //' rules.d/50-udev-default.rules.in</userinput></screen>
161
162 <para>
163 Rebuild <application>systemd</application> by running the
164 following commands:
165 </para>
166
167<screen><userinput>mkdir build &amp;&amp;
168cd build &amp;&amp;
169
170meson --prefix=/usr \
171 --sysconfdir=/etc \
172 --localstatedir=/var \
173 -Dblkid=true \
174 -Dbuildtype=release \
175 -Ddefault-dnssec=no \
176 -Dfirstboot=false \
177 -Dinstall-tests=false \
178 -Dldconfig=false \
179 -Dman=auto \
180 -Drootprefix= \
181 -Drootlibdir=/lib \
182 -Dsplit-usr=true \
183 -Dsysusers=false \
184 -Drpmmacrosdir=no \
185 -Db_lto=false \
186 -Dhomed=false \
187 -Duserdb=false \
188 .. &amp;&amp;
189
190ninja</userinput></screen>
191<!-- Regarding homed and userdb, see the note below in Command Explanations-->
192
193 <note>
194 <para>
195 For the best test results, make sure you run the testsuite from
196 a system that is booted by the same
197 <application>systemd</application> version you are rebuilding.
198 </para>
199 </note>
200
201 <para>
202 To test the results, issue: <command>ninja test</command>. <!--One test,
203 <filename>udev-test</filename> (test 273) fails due to changes in
204 the Linux 5.3+ kernel. It does not affect the package's
205 functionality. NO LONGER APPLICABLE AS OF 244 -->
206 </para>
207
208<!--
209 <warning>
210 <para>
211 Installing the package will overwrite all files installed by
212 <application>systemd</application> in LFS. It is critical that
213 nothing uses either <application>systemd</application> or
214 <application>Udev</application> libraries during the installation.
215 The best way to ensure that these libraries are not being used is to
216 run the installation in rescue mode. To switch to rescue mode,
217 run the following command as the
218 <systemitem class="username">root</systemitem> user (from a TTY):
219 </para>
220
221<screen role="root"><userinput>systemctl isolate rescue.target</userinput></screen>
222 </warning>
223 Nobody has reported problems with this in years. Let's comment it. -->
224
225 <para>
226 Now, as the <systemitem class="username">root</systemitem> user:
227 </para>
228
229<screen role="root"><userinput>ninja install</userinput></screen>
230 <!-- No longer needed as of systemd-244.
231 <para>
232 Remove a configuration file that causes some problems with PID files:
233 </para>
234
235<screen role="root"><userinput>rm -fv /etc/sysctl.d/50-pid-max.conf</userinput></screen>
236 -->
237 </sect2>
238
239 <sect2 role="commands">
240 <title>Command Explanations</title>
241
242<!-- Not needed with the patch
243 <para>
244 <parameter>-Dc_args=-Wno-format-overflow</parameter>: Prevents an error
245 when building with <application>GCC 10</application>. The default is
246 <option>-Werror=format-overflow</option>,
247 which generates false positives. This switch may be used with previous
248 versions of GCC too.
249 </para>
250-->
251
252 <para>
253 <parameter>-Duserdb=false</parameter>: Removes a daemon that does not
254 offer any use under a BLFS configuration. If you wish to enable the
255 <application>userdbd</application> daemon, replace "false" with "true"
256 in the above meson command.
257 </para>
258
259 <para>
260 <parameter>-Dhomed=false</parameter>: Remove a daemon that does not offer
261 any use under a traditional BLFS configuration, especially using accounts
262 created with useradd. To enable systemd-homed, first ensure that you have
263 <xref linkend="cryptsetup"/> and <xref linkend="libpwquality"/>, and then
264 change "false" to "true" in the above meson command.
265 </para>
266
267 <!-- EDITORS NOTE: Explanation on removing userdbd and homed:
268 In BLFS, we do not fully support disk encryption. We offer instructions for
269 building 'cryptsetup' as a dependency, but we do not offer instructions for
270 actually configuring it. In addition, we generally do not include
271 functionality that could potentially conflict with other packages, or that
272 is not of any use to us (in an enterprise configuration using Thin Clients
273 or laptops with LUKS encryption, it could make sense though, but that isn't
274 the configuration that we natively support).
275
276 A few of the complications of systemd-homed include:
277 - SSH Logins
278 - Disk Space Assignments
279 - UID Assignments (chown() on login)
280 (See https://cfp.all-systems-go.io/media/homed-asg2019.pdf)
281
282 In an article I read when systemd-homed was originally unveiled, I remember
283 reading about systemd-homed causing problems with OpenSSH Private Key Auth
284 because the user would have to login at the console in order to unlock
285 their home directory, thus allowing the private key to be unlocked and
286 processed by OpenSSH. Since BLFS does not fully support encrypted disks,
287 and because systemd-homed is incompatible with our usage of useradd /
288 traditional UNIX users and groups, I advise that we take the following
289 approach to avoid any confusion:
290
291 - Leave the added Short Descriptions for homectl and userdbctl
292 - Add the above command explanations and restore the previous behavior
293
294 Should we decide to enable homed by default anytime in the future,
295 let's move cryptsetup to recommended or required.
296
297 I would be open to discussing this after the next systemd version when
298 systemd-homed has matured a bit more. -renodr -->
299
300 </sect2>
301
302 <sect2 role="configuration">
303 <title>Configuring systemd</title>
304
305 <para>
306 The <filename>/etc/pam.d/system-session</filename> file needs to
307 be modified and a new file needs to be created in order for
308 <command>systemd-logind</command> to work correctly. Run the following
309 commands as the <systemitem class="username">root</systemitem> user:
310 </para>
311
312<screen role="root"><userinput>cat &gt;&gt; /etc/pam.d/system-session &lt;&lt; "EOF"
313<literal># Begin Systemd addition
314
315session required pam_loginuid.so
316session optional pam_systemd.so
317
318# End Systemd addition</literal>
319EOF
320
321cat &gt; /etc/pam.d/systemd-user &lt;&lt; "EOF"
322<literal># Begin /etc/pam.d/systemd-user
323
324account required pam_access.so
325account include system-account
326
327session required pam_env.so
328session required pam_limits.so
329session required pam_unix.so
330session required pam_loginuid.so
331session optional pam_keyinit.so force revoke
332session optional pam_systemd.so
333
334auth required pam_deny.so
335password required pam_deny.so
336
337# End /etc/pam.d/systemd-user</literal>
338EOF</userinput></screen>
339
340<!--
341 <para>
342 At this point, you should reload the systemd daemon, and reenter
343 multi-user mode with the following commands (as the
344 <systemitem class="username">root</systemitem> user). If a desktop
345 manager is installed and you wish to reenter the graphical mode,
346 replace <userinput>multi-user.target</userinput> with
347 <userinput>graphical.target</userinput>:
348 </para>
349
350<screen role="root"><userinput>systemctl daemon-reexec
351systemctl start multi-user.target</userinput></screen>-->
352
353 <warning>
354 <para>
355 If upgrading from a previous version of systemd and an
356 initrd is used for system boot, you should generate a new initrd before
357 rebooting the system.
358 </para>
359 </warning>
360
361 </sect2>
362
363 <sect2 role="content">
364 <title>Contents</title>
365
366 <para>
367 A list of the installed files, along with their short
368 descriptions can be found at
369 <ulink url="&lfs-root;/chapter06/systemd.html#contents-systemd"/>.
370 </para>
371
372 <para>
373 Listed below are the newly installed libraries and directories
374 along with short descriptions.
375 </para>
376
377 <segmentedlist>
378 <segtitle>Installed Programs</segtitle>
379 <segtitle>Installed Libraries</segtitle>
380 <segtitle>Installed Directories</segtitle>
381
382 <seglistitem>
383 <seg>
384 <!-- maybe userdbd/userdbctl can go in LFS, try at next time -->
385 homectl (if <xref linkend="cryptsetup"/> is installed)
386 and userdbctl (optionally)
387 </seg>
388 <seg>
389 pam_systemd.so
390 (in <filename class="directory">/lib/security</filename>)
391 </seg>
392 <seg>
393 None
394 </seg>
395 </seglistitem>
396 </segmentedlist>
397
398 <variablelist>
399 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
400 <?dbfo list-presentation="list"?>
401 <?dbhtml list-presentation="table"?>
402
403 <varlistentry id="homectl">
404 <term><command>homectl</command></term>
405 <listitem>
406 <para>
407 is a tool to create, remove, change, or inspect a home directory
408 managed by <command>systemd-homed</command>; note that it's
409 useless for the classic UNIX users and home directories which
410 we are using in LFS/BLFS book
411 </para>
412 <indexterm zone="systemd homectl">
413 <primary sortas="b-homectl">homectl</primary>
414 </indexterm>
415 </listitem>
416 </varlistentry>
417
418 <varlistentry id="userdbctl">
419 <term><command>userdbctl</command></term>
420 <listitem>
421 <para>
422 inspect users, groups, and group memberships
423 </para>
424 <indexterm zone="systemd userdbctl">
425 <primary sortas="b-userdbctl">userdbctl</primary>
426 </indexterm>
427 </listitem>
428 </varlistentry>
429
430 <varlistentry id="pam_systemd">
431 <term><filename class="libraryfile">pam_systemd.so</filename></term>
432 <listitem>
433 <para>
434 is a PAM module used to register user sessions with the
435 <application>systemd</application> login manager,
436 <command>systemd-logind</command>.
437 </para>
438 <indexterm zone="systemd pam_systemd">
439 <primary sortas="c-pam_systemd">pam_systemd.so</primary>
440 </indexterm>
441 </listitem>
442 </varlistentry>
443
444 </variablelist>
445
446 </sect2>
447
448</sect1>
Note: See TracBrowser for help on using the repository browser.