SYSTEMD-REPART(8) systemd-repart SYSTEMD-REPART(8) systemd-repart systemd-repart.service - (DDIs) systemd-repart [...] [_] systemd-repart.service systemd-repart repart.d(5). . systemd-repart . . systemd-repart . initrd /sysroot/ . --image= . systemd-repart.service initrd . "-" ( ) systemd-repart / . systemd-repart : . repart.d/*.conf . : o . o /home/ swap /srv/. o ( ...) A/B . ("A") ("B") . systemd-repart : 1. repart.d/*.conf ( ). ".d". 2. . 3. repart.d/*.conf UUID GPT. . . "" . . 4. . . . . . . . . 5. GPT -- -- . . . 6. UUID UUID . UUID UUID ( ) . . . 7. UUID . . 8. ( ). / BLKDISCARD . "" . 9. . . " " systemd-repart . --factory-reset=yes systemd.factory_reset=yes EFI FactoryResetRequest (UUID 8cf2644b-4b0b-428f-9387-6d876050dc67) "yes". : FactoryReset= . systemd-repart Format=. systemd-growfs(8) systemd-makefs. UUIDs ( UUID ) . machine-id(5) UUIDs . ( --seed=random ) UUIDs . UUID --seed=. UUIDs . . --empty=create . : --dry-run= . --dry-run=yes . systemd-repart . --dry-run=no systemd-repart . 245. --empty= "refuse" "allow" "require" "force" "create". / . "refuse". "refuse" systemd-repart . "allow" . "require" . "force" . "force" . : . "create" --size= . 245. --discard= . --discard=yes . / BLKDISCARD . . . 245. --size= K M G T "auto". . "auto" ( ). . . 4096. --empty=create . --size=auto . : ( ) . CopyFiles=: . 246. --factory-reset= . --factory-reset=no . " " . true FactoryReset= yes . . FactoryReset= off. . : EFI . 245. --can-factory-reset . FactoryReset=. . systemd-repart. 245. --root= repart.d/*.conf CopyFiles= CopyBlocks=. /. initrd /sysroot/ . --copy-source= CopyFiles=. 245. --image= --root= . 249. --image-policy= systemd.image-policy(7). --image= . "*" . --seed= UUID random. UUID UUIDs . ( --root=) . --seed=random . . 245. --pretty= . on off . . 245. --definitions= . *.conf /usr/lib/repart.d/*.conf /etc/repart.d/*.conf /run/repart.d/*.conf. . 245. --key-file= . LUKS2 Encrypt=key-file . AF_UNIX . . KeyFile= ( ). . 247. --private-key= . Verity=signature . 252. --private-key-source= "file" "engine" "provider". "engine" "provider" OpenSSL. Verity=signature . 256. --certificate= . X.509 PEM Verity=signature . 252. --certificate-source= "file" "provider". "provider" OpenSSL. X.509 Verity=signature . 257. --join-signature= Verity Verity=hash PKCS7 DER ASCII base64 DER "base64:". --defer-partitions=root-verity-sig . --private-key= . 258. --tpm2-device=, --tpm2-pcrs= TPM2 PCRs LUKS2 Encrypt=tpm2. systemd-cryptenroll(1) TPM2. 248. --tpm2-device-key=PATH, --tpm2-seal-key-handle=HANDLE SRK TPM2 . systemd-cryptenroll(1) . 255. --tpm2-public-key= --tpm2-public-key-pcrs=PCR[+PCR...] PCR TPM2 . systemd-cryptenroll(1) . 252. --tpm2-pcrlock= pcrlock TPM2 . systemd-cryptenroll(1) . 255. --split=BOOL SplitName=. SplitName= . SplitName=. ".raw" ".raw" . --split --dry-run. --dry-run --split . 252. --include-partitions=PARTITIONS, --exclude-partitions=PARTITIONS systemd-repart. --include-partitions= . --exclude-partitions= . UUIDs GPT ( Type= repart.d(5)). 253. --defer-partitions=PARTITIONS systemd-repart. . systemd-repart systemd-repart. 253. --defer-partitions-empty=yes --defer-partitions= Format=empty Label=_empty. --defer-partitions= --defer-partitions-factory-reset=yes . 259. --defer-partitions-factory-reset=yes --defer-partitions= FactoryReset=yes . --defer-partitions= --defer-partitions-empty=yes . 259. --sector-size= systemd-repart. "2" "512" "4096". . 253. --architecture= . "arm64" "root-x86-64" repart.d/ "root-arm64" . "alpha" "arc" "arm" "arm64" "ia64" "loongarch64" "mips-le" "mips64-le" "parisc" "ppc" "ppc64" "ppc64-le" "riscv32" "riscv64" "s390" "s390x" "tilegx" "x86" "x86-64". 254. --offline=_ systemd-repart . "auto". "auto". . . . "auto" systemd-repart . 254. --copy-from= systemd-repart . . . . . . 255. --copy-source=PATH, -s PATH CopyFiles= . --root= CopyFiles=. --root= --copy-source= CopyFiles= . 255. --make-ddi= "sysext" "confext" "portable". (DDI) (sysext systemd-sysext(8) ) (confext) [1]. "erofs" Verity . /usr/lib/repart.d/*.conf --definitions= DDI . --copy-source= DDI . etc/ "confext". "sysext" usr/ opt/ . "portable" . --empty=create --size=auto --seed=random ( ). DDI --private-key= --certificate=. 255. -S, -C, -P --make-ddi=sysext --make-ddi=confext --make-ddi=portable . 255. --append-fstab= "no" "auto" "replace". fstab(5) --generate-fstab= . "no" systemd-repart . . "replace" . "auto" systemd-repart . "# Start section v of automatically generated fstab by systemd-repart" "# End section ^ of automatically generated fstab by systemd-repart". . 258. --generate-fstab=PATH fstab(5) MountPoint= --copy-source= --root= . . 256. --generate-crypttab=PATH crypttab EncryptedVolume= --copy-source= --root= . . 256. --list-devices . . 257. -h --help . --version . --no-pager (pager). --no-legend . --json= JSON. : "short" ( ) "pretty" ( ) "off" ( JSON ). 0 . 1. DDI (confext) /etc/motd: mkdir -p tree/etc/extension-release.d echo "Hello World" >tree/etc/motd cat >tree/etc/extension-release.d/extension-release.my-motd < DDI systemd-confext(1). 2. PKCS11 DDI (sysext) /usr/foo PKCS11: mkdir -p tree/usr/lib/extension-release.d echo "Hello World" >tree/usr/foo cat >tree/usr/lib/extension-release.d/extension-release.my-foo < DDI systemd-sysext(8). 3. dm-verity dm-verity : mkdir -p repart.d/ /tmp/tree/usr/lib/ cat >/tmp/tree/usr/lib/os-release <repart.d/10-root.conf <repart.d/11-root-verity.conf <repart.d/12-root-verity-sig.conf < /tmp/img.roothash openssl smime -sign -in /tmp/img.roothash \ -inkey verity-private-key.pem \ -signer verity-certificate.pem \ -noattr -binary -outform der \ -out /tmp/img.roothash.p7s systemd-repart --definitions repart.d \ --dry-run=no --root=/tmp/tree/ \ --join-signature="$(cat /tmp/img.roothash):/tmp/img.roothash.p7s" \ --certificate=verity-certificate.pem \ /tmp/img.raw systemd(1), repart.d(5), machine-id(5), systemd-cryptenroll(1), portablectl(1), systemd-sysext(8) 1. https://systemd.io/PORTABLE_SERVICES 3 . . : . systemd 260.2 SYSTEMD-REPART(8)