2012-01-25 02:20:38 +01:00
systemd System and Service Manager
2010-05-13 03:30:21 +02:00
DETAILS:
http://0pointer.de/blog/projects/systemd.html
WEB SITE:
2017-02-21 15:56:04 +01:00
https://www.freedesktop.org/wiki/Software/systemd
2010-05-13 03:30:21 +02:00
GIT:
2015-06-02 15:57:50 -07:00
git@github.com:systemd/systemd.git
https://github.com/systemd/systemd
2010-05-13 03:30:21 +02:00
MAILING LIST:
2017-02-21 15:56:04 +01:00
https://lists.freedesktop.org/mailman/listinfo/systemd-devel
2010-05-13 03:30:21 +02:00
IRC:
#systemd on irc.freenode.org
BUG REPORTS:
2015-06-02 15:57:50 -07:00
https://github.com/systemd/systemd/issues
2010-05-13 03:30:21 +02:00
AUTHOR:
2012-04-12 00:20:58 +02:00
Lennart Poettering
Kay Sievers
...and many others
2010-05-13 03:30:21 +02:00
2011-07-14 23:53:53 +02:00
LICENSE:
2012-04-12 00:20:58 +02:00
LGPLv2.1+ for all code
2015-06-09 14:27:33 +02:00
- except src/basic/MurmurHash2.c which is Public Domain
- except src/basic/siphash24.c which is CC0 Public Domain
2013-08-14 22:58:21 +02:00
- except src/journal/lookup3.c which is Public Domain
- except src/udev/* which is (currently still) GPLv2, GPLv2+
2011-07-14 23:53:53 +02:00
2010-05-13 03:30:21 +02:00
REQUIREMENTS:
2017-03-02 19:11:37 +01:00
Linux kernel >= 3.13
2015-09-06 15:58:20 +02:00
Linux kernel >= 4.2 for unified cgroup hierarchy support
2014-03-22 18:27:35 +01:00
Kernel Config Options:
2013-03-06 19:36:39 +01:00
CONFIG_DEVTMPFS
2014-05-03 19:15:23 +02:00
CONFIG_CGROUPS (it is OK to disable all controllers)
2013-03-06 19:36:39 +01:00
CONFIG_INOTIFY_USER
CONFIG_SIGNALFD
CONFIG_TIMERFD
CONFIG_EPOLL
2013-03-06 19:51:52 +01:00
CONFIG_NET
2013-03-06 19:36:39 +01:00
CONFIG_SYSFS
2013-12-09 07:04:06 -08:00
CONFIG_PROC_FS
2014-02-15 17:21:49 +01:00
CONFIG_FHANDLE (libudev, mount and bind mount handling)
2013-03-06 19:36:39 +01:00
2017-02-25 22:42:27 -05:00
Kernel crypto/hash API
CONFIG_CRYPTO_USER_API_HASH
CONFIG_CRYPTO_HMAC
CONFIG_CRYPTO_SHA256
2014-08-30 11:34:20 +02:00
udev will fail to work with the legacy sysfs layout:
2013-03-06 20:01:45 +01:00
CONFIG_SYSFS_DEPRECATED=n
2013-03-06 19:36:39 +01:00
Legacy hotplug slows down the system and confuses udev:
CONFIG_UEVENT_HELPER_PATH=""
2014-08-30 11:34:20 +02:00
Userspace firmware loading is not supported and should
be disabled in the kernel:
2013-03-06 19:36:39 +01:00
CONFIG_FW_LOADER_USER_HELPER=n
Some udev rules and virtualization detection relies on it:
CONFIG_DMIID
2013-09-15 07:29:25 +02:00
Support for some SCSI devices serial number retrieval, to
create additional symlinks in /dev/disk/ and /dev/tape:
CONFIG_BLK_DEV_BSG
2017-02-06 21:13:21 +01:00
Required for PrivateNetwork= and PrivateDevices= in service units:
2014-03-31 14:28:23 -04:00
CONFIG_NET_NS
2014-12-30 09:57:01 -05:00
CONFIG_DEVPTS_MULTIPLE_INSTANCES
Note that systemd-localed.service and other systemd units use
PrivateNetwork and PrivateDevices so this is effectively required.
2014-03-31 14:28:23 -04:00
2017-02-06 21:13:21 +01:00
Required for PrivateUsers= in service units:
2017-01-24 03:18:07 +01:00
CONFIG_USER_NS
2013-03-06 19:36:39 +01:00
Optional but strongly recommended:
CONFIG_IPV6
CONFIG_AUTOFS4_FS
CONFIG_TMPFS_XATTR
2015-03-03 09:00:39 -05:00
CONFIG_{TMPFS,EXT4,XFS,BTRFS_FS,...}_POSIX_ACL
2013-03-06 20:01:45 +01:00
CONFIG_SECCOMP
2016-09-05 19:16:13 -03:00
CONFIG_SECCOMP_FILTER (required for seccomp support)
2015-05-18 16:35:24 +02:00
CONFIG_CHECKPOINT_RESTORE (for the kcmp() syscall)
2013-03-06 19:36:39 +01:00
2015-07-11 14:18:35 -03:00
Required for CPUShares= in resource control unit settings
2014-06-10 23:29:30 +02:00
CONFIG_CGROUP_SCHED
CONFIG_FAIR_GROUP_SCHED
2015-07-11 14:18:35 -03:00
Required for CPUQuota= in resource control unit settings
2014-11-19 00:13:43 +09:00
CONFIG_CFS_BANDWIDTH
2013-03-06 20:01:45 +01:00
For UEFI systems:
2014-03-22 01:41:12 +01:00
CONFIG_EFIVAR_FS
2013-03-06 20:01:45 +01:00
CONFIG_EFI_PARTITION
2015-07-11 14:18:35 -03:00
We recommend to turn off Real-Time group scheduling in the
kernel when using systemd. RT group scheduling effectively
makes RT scheduling unavailable for most userspace, since it
requires explicit assignment of RT budgets to each unit whose
processes making use of RT. As there's no sensible way to
assign these budgets automatically this cannot really be
fixed, and it's best to disable group scheduling hence.
CONFIG_RT_GROUP_SCHED=n
2017-07-24 11:28:04 +02:00
It's a good idea to disable the implicit creation of networking bonding
devices by the kernel networking bonding module, so that the
automatically created "bond0" interface doesn't conflict with any such
2017-08-02 13:41:18 +01:00
device created by systemd-networkd (or other tools). Ideally there
would be a kernel compile-time option for this, but there currently
isn't. The next best thing is to make this change through a modprobe.d
drop-in. This is shipped by default, see modprobe.d/systemd.conf.
2017-07-24 11:28:04 +02:00
2013-05-10 00:14:12 +02:00
Note that kernel auditing is broken when used with systemd's
container code. When using systemd in conjunction with
2013-10-22 01:50:48 +02:00
containers, please make sure to either turn off auditing at
2013-05-10 00:14:12 +02:00
runtime using the kernel command line option "audit=0", or
turn it off at kernel compile time using:
CONFIG_AUDIT=n
2014-03-11 05:40:36 +01:00
If systemd is compiled with libseccomp support on
architectures which do not use socketcall() and where seccomp
is supported (this effectively means x86-64 and ARM, but
2014-05-03 19:15:24 +02:00
excludes 32-bit x86!), then nspawn will now install a
2014-03-11 05:40:36 +01:00
work-around seccomp filter that makes containers boot even
with audit being enabled. This works correctly only on kernels
3.14 and newer though. TL;DR: turn audit off, still.
2013-05-10 00:14:12 +02:00
2015-04-10 19:39:17 +02:00
glibc >= 2.16
2011-02-16 19:09:11 +01:00
libcap
2015-11-02 10:05:20 -06:00
libmount >= 2.27.1 (from util-linux)
2017-05-12 04:49:48 -04:00
(util-linux < 2.29 *must* be built with --enable-libmount-force-mountinfo,
and later versions without --enable-libmount-support-mtab.)
2016-10-05 13:58:55 +02:00
libseccomp >= 2.3.1 (optional)
2014-12-13 01:56:56 +01:00
libblkid >= 2.24 (from util-linux) (optional)
2013-10-17 19:49:19 +02:00
libkmod >= 15 (optional)
2011-02-16 19:09:11 +01:00
PAM >= 1.1.2 (optional)
libcryptsetup (optional)
libaudit (optional)
2011-07-12 13:57:48 +02:00
libacl (optional)
2011-02-16 19:09:11 +01:00
libselinux (optional)
2011-07-12 13:57:48 +02:00
liblzma (optional)
2014-07-07 18:29:19 -04:00
liblz4 >= 119 (optional)
2012-09-28 00:46:32 +02:00
libgcrypt (optional)
libqrencode (optional)
libmicrohttpd (optional)
2012-11-22 15:30:50 +01:00
libpython (optional)
2017-05-09 21:56:34 -04:00
libidn2 or libidn (optional)
2014-06-23 12:42:17 +02:00
elfutils >= 158 (optional)
2017-07-02 20:21:34 -04:00
pkg-config
2017-08-05 18:30:37 -04:00
gperf
2017-07-02 20:21:34 -04:00
docbook-xsl (optional, required for documentation)
xsltproc (optional, required for documentation)
python-lxml (optional, required to build the indices)
python, meson, ninja
gcc, awk, sed, grep, m4, and similar tools
2012-11-22 15:30:50 +01:00
2013-10-22 01:50:48 +02:00
During runtime, you need the following additional
dependencies:
2012-11-22 15:30:50 +01:00
2015-11-02 10:05:20 -06:00
util-linux >= v2.27.1 required
2016-12-20 04:53:53 -05:00
dbus >= 1.4.0 (strictly speaking optional, but recommended)
NOTE: If using dbus < 1.9.18, you should override the default
policy directory (--with-dbuspolicydir=/etc/dbus-1/system.d).
2012-11-22 15:30:50 +01:00
dracut (optional)
2013-02-13 22:56:43 +01:00
PolicyKit (optional)
2011-02-16 19:09:11 +01:00
2017-04-18 21:52:30 -04:00
To build in directory build/:
meson build/ && ninja -C build
Any configuration options can be specfied as -Darg=value... arguments
to meson. After the build directory is initially configured, meson will
refuse to run again, and options must be changed with:
mesonconf -Darg=value...
mesonconf without any arguments will print out available options and
their current values.
Useful commands:
ninja -v some/target
ninja test
sudo ninja install
DESTDIR=... ninja install
2017-07-02 20:21:34 -04:00
A tarball can be created with:
2015-06-23 13:40:53 +02:00
git archive --format=tar --prefix=systemd-222/ v222 | xz > systemd-222.tar.xz
2013-10-22 01:50:48 +02:00
When systemd-hostnamed is used, it is strongly recommended to
install nss-myhostname to ensure that, in a world of
dynamically changing hostnames, the hostname stays resolvable
2011-05-17 19:35:56 +02:00
under all circumstances. In fact, systemd-hostnamed will warn
2013-01-24 10:31:34 +01:00
if nss-myhostname is not installed.
2011-05-17 19:35:56 +02:00
2016-10-15 20:51:19 -04:00
Additional packages are necessary to run some tests:
- busybox (used by test/TEST-13-NSPAWN-SMOKE)
- nc (used by test/TEST-12-ISSUE-3171)
- python3-pyparsing
- python3-evdev (used by hwdb parsing tests)
- strace (used by test/test-functions)
2017-02-12 00:22:20 -05:00
- capsh (optional, used by test-execute)
2016-10-15 20:51:19 -04:00
2013-03-05 18:53:21 +01:00
USERS AND GROUPS:
2013-03-05 19:15:31 +01:00
Default udev rules use the following standard system group
names, which need to be resolvable by getgrnam() at any time,
even in the very early boot stages, where no other databases
and network are available:
2014-06-12 14:59:53 +02:00
audio, cdrom, dialout, disk, input, kmem, lp, tape, tty, video
2013-03-05 19:04:48 +01:00
2013-10-22 01:50:48 +02:00
During runtime, the journal daemon requires the
2013-03-05 19:19:26 +01:00
"systemd-journal" system group to exist. New journal files will
2013-10-22 01:50:48 +02:00
be readable by this group (but not writable), which may be used
2015-01-18 15:05:40 -05:00
to grant specific users read access. In addition, system
groups "wheel" and "adm" will be given read-only access to
journal files using systemd-tmpfiles.service.
2013-03-05 18:53:21 +01:00
2013-03-05 19:15:31 +01:00
The journal gateway daemon requires the
2013-03-05 19:19:26 +01:00
"systemd-journal-gateway" system user and group to
2013-03-05 19:15:31 +01:00
exist. During execution this network facing service will drop
privileges and assume this uid/gid for security reasons.
2014-06-28 00:48:28 +02:00
Similarly, the NTP daemon requires the "systemd-timesync" system
2014-06-04 11:17:32 +02:00
user and group to exist.
2014-06-28 00:48:28 +02:00
Similarly, the network management daemon requires the
2014-06-04 11:17:32 +02:00
"systemd-network" system user and group to exist.
2014-06-28 00:48:28 +02:00
Similarly, the name resolution daemon requires the
2014-06-04 11:17:32 +02:00
"systemd-resolve" system user and group to exist.
2016-02-08 23:35:24 +01:00
Similarly, the coredump support requires the
"systemd-coredump" system user and group to exist.
2014-08-19 21:55:10 +02:00
NSS:
2016-07-14 19:19:49 +02:00
systemd ships with four glibc NSS modules:
2014-08-19 21:55:10 +02:00
nss-myhostname resolves the local hostname to locally
configured IP addresses, as well as "localhost" to
127.0.0.1/::1.
nss-resolve enables DNS resolution via the systemd-resolved
DNS/LLMNR caching stub resolver "systemd-resolved".
2016-07-14 19:19:49 +02:00
nss-mymachines enables resolution of all local containers registered
with machined to their respective IP addresses. It also maps UID/GIDs
ranges used by containers to useful names.
2014-08-19 21:55:10 +02:00
2016-07-14 19:19:49 +02:00
nss-systemd enables resolution of all dynamically allocated service
users. (See the DynamicUser= setting in unit files.)
2014-08-19 21:55:10 +02:00
2016-07-14 19:19:49 +02:00
To make use of these NSS modules, please add them to the "hosts:",
"passwd:" and "group:" lines in /etc/nsswitch.conf. The "resolve"
module should replace the glibc "dns" module in this file (and don't
worry, it chain-loads the "dns" module if it can't talk to resolved).
2014-08-19 21:55:10 +02:00
2016-07-14 19:19:49 +02:00
The four modules should be used in the following order:
passwd: compat mymachines systemd
group: compat mymachines systemd
2014-08-19 21:55:10 +02:00
hosts: files mymachines resolve myhostname
2015-05-27 17:04:49 +02:00
SYSV INIT.D SCRIPTS:
When calling "systemctl enable/disable/is-enabled" on a unit which is a
SysV init.d script, it calls /usr/lib/systemd/systemd-sysv-install;
this needs to translate the action into the distribution specific
mechanism such as chkconfig or update-rc.d. Packagers need to provide
this script if you need this functionality (you don't if you disabled
SysV init support).
Please see src/systemctl/systemd-sysv-install.SKELETON for how this
needs to look like, and provide an implementation at the marked places.
2011-02-23 01:12:07 +01:00
WARNINGS:
systemd will warn you during boot if /usr is on a different
file system than /. While in systemd itself very little will
2013-10-22 01:50:48 +02:00
break if /usr is on a separate partition, many of its
2011-02-23 01:12:07 +01:00
dependencies very likely will break sooner or later in one
2013-10-22 01:50:48 +02:00
form or another. For example, udev rules tend to refer to
2011-02-23 01:12:07 +01:00
binaries in /usr, binaries that link to libraries in /usr or
binaries that refer to data files in /usr. Since these
2013-10-22 01:50:48 +02:00
breakages are not always directly visible, systemd will warn
2011-02-23 01:12:07 +01:00
about this, since this kind of file system setup is not really
supported anymore by the basic set of Linux OS components.
2011-03-01 23:44:26 +01:00
2014-02-26 02:54:37 +01:00
systemd requires that the /run mount point exists. systemd also
2015-05-30 10:31:41 +02:00
requires that /var/run is a symlink to /run.
2014-02-26 02:54:37 +01:00
2011-03-04 05:07:01 +01:00
For more information on this issue consult
2017-02-21 18:26:23 +01:00
https://www.freedesktop.org/wiki/Software/systemd/separate-usr-is-broken
2011-03-04 05:07:01 +01:00
2012-10-12 12:56:19 +00:00
To run systemd under valgrind, compile with VALGRIND defined
(e.g. ./configure CPPFLAGS='... -DVALGRIND=1'). Otherwise,
false positives will be triggered by code which violates
some rules but is actually safe.
2014-11-06 15:27:13 +01:00
2015-12-10 11:57:08 +01:00
ENGINEERING AND CONSULTING SERVICES:
Kinvolk (https://kinvolk.io) offers professional engineering
and consulting services for systemd. Please contact Chris Kühl
<chris@kinvolk.io> for more information.