source: general/sysutils/systemd.xml@ dfb8390

12.0 12.1 ken/TL2024 ken/tuningfonts lazarus plabs/newcss python3.11 rahul/power-profiles-daemon renodr/vulkan-addition trunk xry111/llvm18
Last change on this file since dfb8390 was dfb8390, checked in by Xi Ruoyao <xry111@…>, 11 months ago

systemd: Update to systemd-254

  • Property mode set to 100644
File size: 15.5 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!-- <!ENTITY systemd-download-http "https://anduin.linuxfromscratch.org/LFS/systemd-&systemd-version;-&systemd-stable;.tar.xz"> For whenever we move to a stable snapshot for backports -->
8 <!ENTITY systemd-download-http "https://github.com/systemd/systemd/archive/v&systemd-version;/systemd-&systemd-version;.tar.gz">
9 <!ENTITY systemd-download-ftp " ">
10 <!ENTITY systemd-md5sum "0d266e5361dc72097b6c18cfde1c0001">
11 <!ENTITY systemd-size "14 MB">
12 <!ENTITY systemd-buildsize "198 MB (with tests)">
13 <!ENTITY systemd-time "3.7 SBU (with tests using 4 cores)">
14
15]>
16
17<sect1 id="systemd" xreflabel="Systemd-&systemd-version;" revision="systemd">
18 <?dbhtml filename="systemd.html"?>
19
20
21 <title>Systemd-&systemd-version;</title>
22 <!-- Whenever we switch back to stable backports, make sure to add the systemd-stable reference back. -->
23
24 <indexterm zone="systemd">
25 <primary sortas="a-systemd">systemd</primary>
26 </indexterm>
27
28 <sect2 role="package">
29 <title>Introduction to systemd</title>
30
31 <para>
32 While <application>systemd</application> was installed when
33 building LFS, there are many features provided by the package that
34 were not included in the initial installation because
35 <application>Linux-PAM</application> was not yet installed.
36 The <application>systemd</application> package needs to be
37 rebuilt to provide a working <command>systemd-logind</command> service,
38 which provides many additional features for dependent packages.
39 </para>
40
41 &lfs113_checked;
42
43 <bridgehead renderas="sect3">Package Information</bridgehead>
44 <itemizedlist spacing="compact">
45 <listitem>
46 <para>
47 Download (HTTP): <ulink url="&systemd-download-http;"/>
48 </para>
49 </listitem>
50 <listitem>
51 <para>
52 Download (FTP): <ulink url="&systemd-download-ftp;"/>
53 </para>
54 </listitem>
55 <listitem>
56 <para>
57 Download MD5 sum: &systemd-md5sum;
58 </para>
59 </listitem>
60 <listitem>
61 <para>
62 Download size: &systemd-size;
63 </para>
64 </listitem>
65 <listitem>
66 <para>
67 Estimated disk space required: &systemd-buildsize;
68 </para>
69 </listitem>
70 <listitem>
71 <para>
72 Estimated build time: &systemd-time;
73 </para>
74 </listitem>
75 </itemizedlist>
76
77<!-- Keep here in case a patch will be needed.-->
78<!--
79 <bridgehead renderas="sect3">Additional Downloads</bridgehead>
80 <itemizedlist spacing="compact">
81 <listitem>
82 <para>
83 Required patch:
84 <ulink url="&patch-root;/systemd-&systemd-version;-security_fix-1.patch"/>
85 </para>
86 </listitem>
87 </itemizedlist>
88-->
89 <bridgehead renderas="sect3">systemd Dependencies</bridgehead>
90
91 <bridgehead renderas="sect4">Recommended</bridgehead>
92
93 <note>
94 <para>
95 <xref linkend='linux-pam'/> is not strictly required to build
96 <application>systemd</application>, but the main reason to rebuild
97 <application>systemd</application> in BLFS (it's already built in
98 LFS anyway) is for the <command>systemd-logind</command> daemon and
99 the
100 <filename class='libraryfile'>pam_systemd.so</filename> PAM module.
101 <xref linkend='linux-pam'/> is required for them. All packages in
102 BLFS book with a dependency on <application>systemd</application>
103 expects it has been rebuilt with <xref linkend='linux-pam'/>.
104 </para>
105 </note>
106
107 <para role="recommended">
108 <xref linkend="linux-pam"/> and
109 <xref role="runtime" linkend="polkit"/> (runtime)
110 </para>
111
112 <bridgehead renderas="sect4">Optional</bridgehead>
113 <para role="optional">
114 <xref linkend="btrfs-progs"/>, <!-- homed may support it, see the C.E.-->
115 <xref linkend="curl"/>,
116 <xref linkend="cryptsetup"/>,
117 <xref linkend="git"/>,
118 <xref linkend="gnutls"/>,
119 <xref linkend="iptables"/>,
120 <xref linkend="libgcrypt"/>,
121 <xref linkend="libidn2"/>,
122 <xref linkend="libpwquality"/>,
123 <xref linkend="libseccomp"/>,
124 <xref linkend="libxkbcommon"/>,
125 <xref linkend="make-ca"/>,
126 <xref linkend="p11-kit"/>,
127 <xref linkend="pcre2"/>,
128 <xref linkend="qemu"/>,
129 <xref linkend="qrencode"/>,
130 <xref linkend="rsync"/>,
131 <xref linkend="sphinx"/>,
132 <xref linkend="valgrind"/>,
133 <xref linkend="zsh"/> (for the zsh completions),
134 <ulink url="https://www.apparmor.net/">AppArmor</ulink>,
135 <ulink url="https://github.com/linux-audit/audit-userspace">audit-userspace</ulink>,
136 <ulink url="https://github.com/scop/bash-completion">bash-completion</ulink>,
137 <ulink url="https://jekyllrb.com/">jekyll</ulink>,
138 <ulink url="https://www.kernel.org/pub/linux/utils/kernel/kexec/">kexec-tools</ulink>,
139 <ulink url="https://github.com/libbpf/libbpf">libbpf</ulink>,
140 <ulink url="https://sourceware.org/elfutils/">libdw</ulink>,
141 <ulink url="https://developers.yubico.com/libfido2/">libfido2</ulink>,
142 <ulink url="https://www.gnu.org/software/libmicrohttpd/">libmicrohttpd</ulink>,
143 <ulink url="https://lz4.github.io/lz4/">lz4</ulink>,
144 <ulink url="https://pypi.org/project/pyelftools/">pyelftools</ulink>,
145 <ulink url="https://sourceforge.net/projects/linuxquota/">quota-tools</ulink>,
146 <ulink url="https://rpm.org/">rpm</ulink>,
147 <ulink url="https://github.com/SELinuxProject/selinux">SELinux</ulink>,
148 <ulink url="https://sourceware.org/systemtap/">systemtap</ulink>,
149 <ulink url="https://tpm2-tss.readthedocs.io/en/latest/">tpm2-tss</ulink>
150 and <ulink url="https://xenproject.org">Xen</ulink>
151 </para>
152
153 <bridgehead renderas="sect4">Optional (to rebuild the manual pages)</bridgehead>
154 <para role="optional">
155 <xref linkend="DocBook"/>,
156 <xref linkend="docbook-xsl"/>,
157 <xref linkend="libxslt"/>, and
158 <xref linkend="lxml"/> (to build the index of systemd manual pages)
159 </para>
160
161 </sect2>
162
163 <sect2 role="installation">
164 <title>Installation of systemd</title>
165<!--
166 <para>
167 First, fix a security issue in systemd-coredump:
168 </para>
169
170<screen><userinput>patch -Np1 -i ../systemd-&systemd-version;-security_fix-1.patch</userinput></screen>
171-->
172
173 <para>
174 Remove two unneeded groups,
175 <systemitem class="groupname">render</systemitem> and
176 <systemitem class="groupname">sgx</systemitem>, from the default udev
177 rules:
178 </para>
179
180<screen><userinput remap="pre">sed -i -e 's/GROUP="render"/GROUP="video"/' \
181 -e 's/GROUP="sgx", //' rules.d/50-udev-default.rules.in</userinput></screen>
182
183 <para>
184 Rebuild <application>systemd</application> by running the
185 following commands:
186 </para>
187
188<screen><userinput>mkdir build &amp;&amp;
189cd build &amp;&amp;
190
191meson setup .. \
192 --prefix=/usr \
193 --buildtype=release \
194 -Ddefault-dnssec=no \
195 -Dfirstboot=false \
196 -Dinstall-tests=false \
197 -Dldconfig=false \
198 -Dman=auto \
199 -Dsysusers=false \
200 -Drpmmacrosdir=no \
201 -Dhomed=false \
202 -Duserdb=false \
203 -Dmode=release \
204 -Dpam=true \
205 -Dpamconfdir=/etc/pam.d \
206 -Ddev-kvm-mode=0660 \
207 -Ddocdir=/usr/share/doc/systemd-&systemd-version; &amp;&amp;
208
209ninja</userinput></screen>
210<!-- Regarding homed and userdb, see the note below in Command Explanations-->
211
212 <note>
213 <para>
214 For the best test results, make sure you run the test suite from
215 a system that is booted by the same
216 <application>systemd</application> version you are rebuilding.
217 </para>
218 </note>
219
220 <para>
221 To test the results, issue: <command>ninja test</command>.
222 <!-- test-netlink: https://github.com/systemd/systemd/issues/27969 -->
223 The test named <filename>test-stat-util</filename> and
224 <filename>test-netlink</filename> are known to fail
225 if some kernel features are not enabled.
226 If the test suite is ran as the &root; user, some
227 other tests may fail because they depend on various kernel
228 configuration options.
229 </para>
230
231 <para>
232 Now, as the <systemitem class="username">root</systemitem> user:
233 </para>
234
235<screen role="root"><userinput>ninja install</userinput></screen>
236
237 </sect2>
238
239 <sect2 role="commands">
240 <title>Command Explanations</title>
241
242 <xi:include xmlns:xi="http://www.w3.org/2001/XInclude"
243 href="../../xincludes/meson-buildtype-release.xml"/>
244
245 <para>
246 <parameter>-Dpamconfdir=/etc/pam.d</parameter>: Forces the PAM files to
247 be installed in /etc/pam.d rather than /usr/lib/pam.d.
248 </para>
249
250 <para>
251 <parameter>-Duserdb=false</parameter>: Removes a daemon that does not
252 offer any use under a BLFS configuration. If you wish to enable the
253 <application>userdbd</application> daemon, replace "false" with "true"
254 in the above meson command.
255 </para>
256
257 <para>
258 <parameter>-Dhomed=false</parameter>: Removes a daemon that does not offer
259 any use under a traditional BLFS configuration, especially using accounts
260 created with useradd. To enable systemd-homed, first ensure that you have
261 <xref linkend="cryptsetup"/> and <xref linkend="libpwquality"/> installed,
262 and then change "false" to "true" in the above meson command.
263 </para>
264
265 <!-- EDITORS NOTE: Explanation on removing userdbd and homed:
266 In BLFS, we do not fully support disk encryption. We offer instructions for
267 building 'cryptsetup' as a dependency, but we do not offer instructions for
268 actually configuring it. In addition, we generally do not include
269 functionality that could potentially conflict with other packages, or that
270 is not of any use to us (in an enterprise configuration using Thin Clients
271 or laptops with LUKS encryption, it could make sense though, but that isn't
272 the configuration that we natively support).
273
274 A few of the complications of systemd-homed include:
275 - SSH Logins
276 - Disk Space Assignments
277 - UID Assignments (chown() on login)
278 (See https://cfp.all-systems-go.io/media/homed-asg2019.pdf)
279
280 In an article I read when systemd-homed was originally unveiled, I remember
281 reading about systemd-homed causing problems with OpenSSH Private Key Auth
282 because the user would have to login at the console in order to unlock
283 their home directory, thus allowing the private key to be unlocked and
284 processed by OpenSSH. Since BLFS does not fully support encrypted disks,
285 and because systemd-homed is incompatible with our usage of useradd /
286 traditional UNIX users and groups, I advise that we take the following
287 approach to avoid any confusion:
288
289 - Leave the added Short Descriptions for homectl and userdbctl
290 - Add the above command explanations and restore the previous behavior
291
292 Should we decide to enable homed by default anytime in the future,
293 let's move cryptsetup to recommended or required.
294
295 I would be open to discussing this after the next systemd version when
296 systemd-homed has matured a bit more. -renodr -->
297
298 </sect2>
299
300 <sect2 role="configuration">
301 <title>Configuring systemd</title>
302
303 <para>
304 The <filename>/etc/pam.d/system-session</filename> file needs to
305 be modified and a new file needs to be created in order for
306 <command>systemd-logind</command> to work correctly. Run the following
307 commands as the <systemitem class="username">root</systemitem> user:
308 </para>
309
310<screen role="root"><userinput>grep 'pam_systemd' /etc/pam.d/system-session ||
311cat &gt;&gt; /etc/pam.d/system-session &lt;&lt; "EOF"
312<literal># Begin Systemd addition
313
314session required pam_loginuid.so
315session optional pam_systemd.so
316
317# End Systemd addition</literal>
318EOF
319
320cat &gt; /etc/pam.d/systemd-user &lt;&lt; "EOF"
321<literal># Begin /etc/pam.d/systemd-user
322
323account required pam_access.so
324account include system-account
325
326session required pam_env.so
327session required pam_limits.so
328session required pam_unix.so
329session required pam_loginuid.so
330session optional pam_keyinit.so force revoke
331session optional pam_systemd.so
332
333auth required pam_deny.so
334password required pam_deny.so
335
336# End /etc/pam.d/systemd-user</literal>
337EOF</userinput></screen>
338
339 <warning>
340 <para>
341 If upgrading from a previous version of systemd and an
342 initrd is used for system boot, you should generate a new initrd before
343 rebooting the system.
344 </para>
345 </warning>
346
347 </sect2>
348
349 <sect2 role="content">
350 <title>Contents</title>
351
352 <para>
353 A list of the installed files, along with their short
354 descriptions can be found at
355 <ulink url="&lfs-root;/chapter08/systemd.html#contents-systemd"/>.
356 </para>
357
358 <para>
359 Listed below are the newly installed programs
360 along with short descriptions.
361 </para>
362
363 <segmentedlist>
364 <segtitle>Installed Programs</segtitle>
365
366 <seglistitem>
367 <seg>
368 <!-- maybe userdbd/userdbctl can go in LFS, try at next time -->
369 homectl (optional),
370 systemd-cryptenroll (if <xref linkend="cryptsetup"/> is installed),
371 and userdbctl (optional)
372 </seg>
373 </seglistitem>
374 </segmentedlist>
375
376 <variablelist>
377 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
378 <?dbfo list-presentation="list"?>
379 <?dbhtml list-presentation="table"?>
380
381 <varlistentry id="homectl">
382 <term><command>homectl</command></term>
383 <listitem>
384 <para>
385 is a tool to create, remove, change, or inspect a home directory
386 managed by <command>systemd-homed</command>; note that it's
387 useless for the classic UNIX users and home directories which
388 we are using in LFS/BLFS book
389 </para>
390 <indexterm zone="systemd homectl">
391 <primary sortas="b-homectl">homectl</primary>
392 </indexterm>
393 </listitem>
394 </varlistentry>
395
396 <varlistentry id="systemd-cryptenroll">
397 <term><command>systemd-cryptenroll</command></term>
398 <listitem>
399 <para>
400 Is used to enroll or remove a system from full disk encryption,
401 as well as set and query private keys and recovery keys
402 </para>
403 <indexterm zone="systemd systemd-cryptenroll">
404 <primary sortas="b-systemd-cryptenroll">systemd-cryptenroll</primary>
405 </indexterm>
406 </listitem>
407 </varlistentry>
408
409 <varlistentry id="userdbctl">
410 <term><command>userdbctl</command></term>
411 <listitem>
412 <para>
413 inspects users, groups, and group memberships
414 </para>
415 <indexterm zone="systemd userdbctl">
416 <primary sortas="b-userdbctl">userdbctl</primary>
417 </indexterm>
418 </listitem>
419 </varlistentry>
420
421 <varlistentry id="pam_systemd">
422 <term><filename class="libraryfile">pam_systemd.so</filename></term>
423 <listitem>
424 <para>
425 is a PAM module used to register user sessions with the
426 <application>systemd</application> login manager,
427 <command>systemd-logind</command>
428 </para>
429 <indexterm zone="systemd pam_systemd">
430 <primary sortas="c-pam_systemd">pam_systemd.so</primary>
431 </indexterm>
432 </listitem>
433 </varlistentry>
434
435 </variablelist>
436
437 </sect2>
438
439</sect1>
Note: See TracBrowser for help on using the repository browser.