SYSTEMD.EXEC(5) systemd.exec SYSTEMD.EXEC(5) systemd.exec - service.service, socket.socket, mount.mount, swap.swap . . systemd.unit(5) systemd.service(5) systemd.socket(5) systemd.swap(5) systemd.mount(5) . [Service] [Socket] [Mount] [Swap] . (cgroups) systemd.resource-control(5). . : o WorkingDirectory= RootDirectory= RootImage= RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= Requires= After= . RequiresMountsFor=. o PrivateTmp=yes Wants= After= /tmp/ /var/tmp/ After= systemd-tmpfiles-setup.service(8) DefaultDependencies=no. DefaultDependencies=no RequiresMountsFor=/tmp/ WantsMountsFor=/tmp/ After=tmp.mount RootDirectory=/RootImage= PrivateTmp=yes PrivateTmp=disconnected. o PrivateTmp=disconnected Wants= After= /var/ DefaultDependencies=no / RootDirectory=/RootImage=. DefaultDependencies=no RequiresMountsFor=/var/ WantsMountsFor=/var/ After=var.mount RootDirectory=/RootImage= /tmp/ /var/tmp/ $TMPDIR . o journal kmsg ( ) After= systemd-journald.socket. o LogNamespace= systemd-journald@.service. . "..". ExecSearchPath= Exec*= ( ExecStart= ExecStop= ). ExecSearchPath= $PATH Environment= EnvironmentFile= PassEnvironment=. ExecSearchPath= . 250. WorkingDirectory= RootDirectory= "~". . "~" User=. systemd . "-" . RootDirectory=/RootImage= WorkingDirectory= . ( ). RootDirectory= ( ). pivot_root(2) chroot(2). . ( ). MountAPIVFS= PrivateUsers= RootDirectory=. . RootDirectory=/RootImage= NotifyAccess= . RootDirectory=/RootImage= syslog journal : os-release(5) ( ) /run/host/os-release. (: systemd-soft-reboot.service(8)) . 1. BindReadOnlyPaths=/dev/log /run/systemd/journal/socket /run/systemd/journal/stdout ".v/" systemd.v(7) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). RootImage= . RootDirectory= . MBR/MS-DOS GPT GPT UAPI.2 Discoverable Partitions Specification[1]. DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow=. systemd.resource-control(5) DevicePolicy= DeviceAllow=. PrivateDevices= DevicePolicy=. RootImage= After= systemd-udevd.service. os-release(5) ( ) /run/host/os-release. (: systemd-soft-reboot.service(8)) . ".v/" systemd.v(7) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). 233. RootImageOptions= RootImage=. "root" . . . mount(8). Discoverable Partitions Specification[1]: root, usr, home, srv, esp, xbootldr, tmp, var. . . polkit[2] : 3. polkit nosuid /etc/polkit-1/rules.d/mountoptions.rules: polkit.addRule(function(action, subject) { if (action.id == "io.systemd.mount-file-system.mount-untrusted-image-privately" && action.lookup("mount_options") == "root:nosuid") { return polkit.Result.YES; } }); 247. RootEphemeral= . . /var/lib/systemd/ephemeral-trees/ . RootDirectory= . /var/lib/systemd/ephemeral-trees/. RootEphemeral= btrfs(5) systemd . (reflinks) . . 254. RootHash= (dm-verity) ASCII. dm-verity ( ) RootVerity=. 256 ( 64 ) ( SHA256 ). "user.verity.roothash" ( xattr(7)) . ( ) .roothash ( .raw ) . /usr/ Verity "user.verity.usrhash" .usrhash . /usr/ . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). 246. RootHashSignature= PKCS7 RootHash= DER ASCII base64 DER "base64:". dm-verity . .roothash.p7s ( .raw ) . /usr/ Verity .usrhash.p7s . /usr/ . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). 246. RootVerity= (dm-verity). dm-verity RootImage= . . .verity ( .raw verity ) verity . . GPT Verity Discoverable Partitions Specification[1]. PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). 246. RootImagePolicy= MountImagePolicy= ExtensionImagePolicy= systemd.image-policy(7) (DDI) RootImage= MountImage= ExtensionImage= . RootImagePolicy= MountImagePolicy: root=verity+signed+encrypted+unprotected+absent: \ usr=verity+signed+encrypted+unprotected+absent: \ home=encrypted+unprotected+absent: \ srv=encrypted+unprotected+absent: \ tmp=encrypted+unprotected+absent: \ var=encrypted+unprotected+absent ExtensionImagePolicy= : root=verity+signed+encrypted+unprotected+absent: \ usr=verity+signed+encrypted+unprotected+absent 254. RootMStack= systemd.mstack(7) . RootDirectory= RootImage= "overlayfs". .mstack/ (DDIs) RootMStack= RootImage=. ".v/" systemd.v(7) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). 260. MountAPIVFS= . /proc/ /sys/ /dev/ /run/ ( "tmpfs" ) . RootDirectory=/RootImage= 1:1 . /dev/ PrivateDevices=. /dev/ PrivateDevices=. /run/systemd/propagate/ /run/host/incoming/ . 233. BindLogSockets= . systemd-journald.socket(8) . /run/ sd-journal(3). LogNamespace= MountAPIVFS=yes PrivateDevices=yes RootDirectory= RootImage=. 257. ProtectProc= "noaccess" "invisible" "ptraceable" "default" ( ). "hidepid=" "procfs" (/proc/PID) : "noaccess" /proc/ . "invisible" /proc/. "ptraceable" ptrace() . "default" /proc/ . The /proc Filesystem[3]. "invisible". . User= DynamicUser=yes "CAP_SYS_PTRACE" . . MountAPIVFS=. hidepid= . . 247. ProcSubset= "all" () "pid". "pid" /proc/ . "subset=" "procfs" . The /proc Filesystem[3]. /proc/ . . ProtectProc= : MountAPIVFS=. ProtectProc= "subset=" "procfs". 247. BindPaths=, BindReadOnlyPaths= . . . . . . "rbind" "norbind" . . "-" . BindPaths= ( ) BindReadOnlyPaths= . . . . PrivateMounts= ( ). RootDirectory=/RootImage=. . systemd . InaccessiblePaths= /home/ ProtectHome=yes. TemporaryFileSystem= ":ro" ProtectHome=tmpfs . 233. MountImages= RootImage= . . . . RootImageOptions= . "-" . . ":" "\:". RootImage=. . . . systemd . InaccessiblePaths= /home/ ProtectHome=yes. DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow=. systemd.resource-control(5) DevicePolicy= DeviceAllow=. PrivateDevices= DevicePolicy=. PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). . polkit[2] : 5. polkit nosuid /etc/polkit-1/rules.d/mountoptions.rules: polkit.addRule(function(action, subject) { if (action.id == "io.systemd.mount-file-system.mount-untrusted-image-privately" && action.lookup("mount_options") == "root:nosuid") { return polkit.Result.YES; } }); 247. ExtensionImages= MountImages= . . . OverlayFS /usr/ /opt/ sysext /etc/ confext. : overlayfs . . RootImageOptions= . "-" . . ":" "\:". RootImage=. . . . sysext /usr/lib/extension-release.d/extension-release.IMAGE confext /etc/extension-release.d/extension-release.IMAGE RootImage=/RootDirectory= . : os-release(5). extension-release x-systemd.relax-extension-release-check. systemd.v(7) RefreshOnReload=extensions ( ) confext . confext. daemon-reload confext (no-op) . systemd.service(5) . DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow=. systemd.resource-control(5) DevicePolicy= DeviceAllow=. PrivateDevices= DevicePolicy=. ".v/" systemd.v(7) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=") systemd-mountfsd.service(8). . polkit[2] : 7. polkit nosuid /etc/polkit-1/rules.d/mountoptions.rules: polkit.addRule(function(action, subject) { if (action.id == "io.systemd.mount-file-system.mount-untrusted-image-privately" && action.lookup("mount_options") == "root:nosuid") { return polkit.Result.YES; } }); 248. ExtensionDirectories= BindReadOnlyPaths= (overlay). . (OverlayFS) /usr/ /opt/ sysext /etc/ confext. : overlayfs . ExtensionDirectories= "-" . . . . sysext /usr/lib/extension-release.d/extension-release.IMAGE confext /etc/extension-release.d/extension-release.IMAGE RootImage=/RootDirectory= . : os-release(5). systemd.v(7) RefreshOnReload=extensions ( ) confext . confext. daemon-reload confext (no-op) . systemd.service(5) . overlayfs v5.11. ".v/" systemd.v(7) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 251. / . User=, Group= UNIX . . ( PID 1) ( root systemd --user) "root" User= . . . "+". / / : a-z A-Z 0-9 "_" "-" a-z A-Z "_" ( "-" ). / 31 . / Linux. /[4]. DynamicUser= / -- ( ). DynamicUser= sysusers.d(5) . . User= . SupplementaryGroups= ( ). DynamicUser= (boolean). UNIX . /etc/passwd /etc/group . nss-systemd(8) glibc NSS / . User= Group= ( ). / / . (hash) . / . User= . Group= . / UID/GID 61184...65519. . UID/GID / . UID/GID . / / UID/GID . DynamicUser= RemoveIPC= ( ). IPC / . /tmp/ /var/tmp/ PrivateTmp= "true" "disconnected" . / . NoNewPrivileges= RestrictSUIDSGID= ( ) SUID/SGID. ProtectSystem=strict ProtectHome=read-only . ReadWritePaths= UID/GID . RuntimeDirectory= ( ) / . StateDirectory= CacheDirectory= LogsDirectory= UID ( ). . BindPaths= AF_UNIX / . D-Bus D-Bus ( D-Bus ). . 232. SupplementaryGroups= Unix . . . . . "+". SetLoginEnvironment= $HOME $LOGNAME $SHELL. (true) User= DynamicUser= PAMName= (false) . true "root". false User= DynamicUser= PAMName= . . 255. PAMName= PAM . PAM . User= . PAM . pam(8) . PAM PAM. "(sd-pam)" . ( PAM) . : ( PAMName=) . . NotifyAccess=all . . PAMName= NotifyAccess=all. PAM ( ) ( SetCredential= ImportCredential= ) pam.authtok. pamservice pamservice PAM PAMName=. ( !) [5]. PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). CapabilityBoundingSet= (capabilities) . capabilities(7) . CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE. . "~", . . . OR AND "~" ( ). . "~" ( ) . "+". capability systemd-analyze(1) . : CapabilityBoundingSet=CAP_A CAP_B CapabilityBoundingSet=CAP_B CAP_C CAP_A CAP_B CAP_C. "~" : CapabilityBoundingSet=CAP_A CAP_B CapabilityBoundingSet=~CAP_B CAP_C CAP_A . AmbientCapabilities= (ambient) . CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE. ( CapabilityBoundingSet=). "~", . . "~" ( ) . . . keep-caps SecureBits= . AmbientCapabilities= "+". 229. NoNewPrivileges= . (true) execve() ( setuid setgid ). . (false). SELinux MS_NOSUID. [6]. ( ). at(1) crontab(1) systemd-run(1) IPC . 187. SecureBits= (secure bits) . : keep-caps keep-caps-locked no-setuid-fixup no-setuid-fixup-locked noroot noroot-locked. OR. 0. "+". capabilities(7) . SELinuxContext= SELinux . . . SELinux . "-" SELinux execve() . "+". setexeccon(3) . 209. AppArmorProfile= . . . "-" . AppArmor . "+". . 210. SmackProcessLabel= SMACK64 . SMACK . SMACK64EXEC . systemd. SMACK . "-" . . "+". . 218. LimitCPU= LimitFSIZE= LimitDATA= LimitSTACK= LimitCORE= LimitRSS= LimitNOFILE= LimitAS= LimitNPROC= LimitMEMLOCK= LimitLOCKS= LimitSIGPENDING= LimitMSGQUEUE= LimitNICE= LimitRTPRIO= LimitRTTIME= (soft) (hard) . setrlimit(2) . : soft:hard ( "LimitAS=4G:16G"). infinity . K M G T P E ( 1024) ( "LimitAS=16G"). ms s min h ( systemd.time(7) ). LimitCPU= LimitRTTIME= . (granularity) . LimitCPU= . LimitNICE= : "+" "-" nice Linux -20...19. 0...40 ( 0 1). (per-process) (fork) . LimitRSS= Linux . systemd.resource-control(5) . MemoryMax= ( ) LimitRSS=. LimitNPROC= () (UID) ( ) . UID. LimitNPROC= root ( ). TasksMax= ( systemd.resource-control(5)) LimitNPROC=. DefaultLimitCPU= DefaultLimitFSIZE= ... systemd-system.conf(5) -- -- ( ). . ( ) . . . PAM user@.service. . 1. ulimit +----------------------+-----------------+--------------------------------+------------------------------+ | | | | | | | | | | | | ulimit | | | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitCPU= | ulimit -t | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitFSIZE= | ulimit -f | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitDATA= | ulimit -d | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ! | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | MemoryMax= | | | | | | | | | | systemd.resource-control(5). | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitSTACK= | ulimit -s | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitCORE= | ulimit -c | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitRSS= | ulimit -m | | | | | | | . | | | | | | | | | | | | | | | Linux. | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitNOFILE= | ulimit -n | | | | | | | . | | | | | | | | | | | | | | | | | | | | 1024 | | | | | | | | | | select(2) | | | | | | | | | | | | | | | | | | | | | | | | | 1023 Linux. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | 524288 | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | 1023 | | | | | | | | | | select(2). | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | MemoryMax= | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitAS= | ulimit -v | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ! | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | MemoryMax= | | | | | | | | | | systemd.resource-control(5). | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitNPROC= | ulimit -u | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | TasksMax= | | | | | systemd.resource-control(5). | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitMEMLOCK= | ulimit -l | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitLOCKS= | ulimit -x | | - | | | | | | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitSIGPENDING= | ulimit -i | | - | | | | | | | | | | | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitMSGQUEUE= | ulimit -q | | - | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitNICE= | ulimit -e | | - | | | | | | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitRTPRIO= | ulimit -r | | - | | | | | | | | | | | +----------------------+-----------------+--------------------------------+------------------------------+ |LimitRTTIME= | ulimit -R | | - | +----------------------+-----------------+--------------------------------+------------------------------+ UMask= (umask). . umask(2) . 0022 . ( 0022 -- PAM). UMask= user@.service . umask umask JSON[7] ( systemd-homed.service(8) homectl --umask=). PAM pam_umask(8). CoredumpFilter= (core dump) ( /proc/pid/coredump_filter). ( 16). private-anonymous shared-anonymous private-file-backed shared-file-backed elf-headers private-huge shared-huge private-dax shared-dax all ( ) default ( "private-anonymous shared-anonymous elf-headers private-huge"). core(5) . OR . . 8. DAX CoredumpFilter=default private-dax shared-dax 246. KeyringMode= (kernel session keyring) ( session-keyring(7) ). inherit private shared. inherit . private . ( root) . shared private User= . . inherit ( ) "invocation_id" . private inherit . 235. OOMScoreAdjust= (OOM killer score) Linux . -1000 ( ) 1000 ( ). /proc[8] . OOM 0. OOMPolicy= OOM systemd-oomd . systemd.service(5) . TimerSlackNSec= (timer slack) . . prctl(2) . . . Personality= uname(2) . arm64 arm64-be arm arm-be x86 x86-64 ppc ppc-le ppc64 ppc64-le s390 s390x. (personality architectures) . 64- 32- . x86-64 x86-64 x86 . 32- 64-. . m68k (32- ) alpha (64- ). 209. IgnoreSIGPIPE= . (true) SIGPIPE . true SIGPIPE (shell pipelines). Nice= nice ( ) . -20 ( ) 19 ( ). . setpriority(2) . CPUSchedulingPolicy= (CPU) . other batch idle fifo rr ext. sched_setscheduler(2) . CPUSchedulingPriority= (CPU) . CPU ( ). 1 ( ) 99 ( ). . sched_setscheduler(2) . CPUSchedulingResetOnFork= (boolean). (true) fork(2) . sched_setscheduler(2) . (false). CPUAffinity= (CPU affinity) . . "numa" systemd NUMAMask=. . . . sched_setaffinity(2) . NUMAPolicy= NUMA . : default preferred bind interleave local. NUMA NUMAMask=. set_mempolicy(2). NUMA numa(7). 243. NUMAMask= NUMA NUMA . NUMA CPUAffinity= "all" NUMA . NUMA default local preferred NUMA . 243. IOSchedulingClass= / . realtime best-effort idle. best-effort 4. IOSchedulingClass= IOSchedulingPriority= . ioprio_set(2) . IOSchedulingPriority= / . 0 ( ) 7 ( ). / / . / ( ). IOSchedulingClass= IOSchedulingPriority= . (best-effort) 4. ioprio_set(2) . (sandboxing) . . . ProtectSystem= . RestrictRealtime= SECCOMP . ( ). ( ProtectSystem=) . PrivateUsers=true. ( ProtectSystem= ReadOnlyPaths= ...) AF_UNIX . (IPC). ProtectSystem= "full" "strict". (true) /usr/ (/boot /efi) . "full" /etc/ . "strict" (API) /dev/ /proc/ /sys/ ( PrivateDevices= ProtectKernelTunables= ProtectControlGroups=). ( ) . . ReadWritePaths= . StateDirectory= LogsDirectory= ... ( ) ProtectSystem=. DynamicUser=. . ReadOnlyPaths= . (off). ProtectSystem= "strict" PrivateTmp= /tmp/ /var/tmp/ . 214. ProtectHome= "read-only" "tmpfs". /home/ /root /run/user . "read-only" . "tmpfs" . "tmpfs" BindPaths= BindReadOnlyPaths=. "yes" InaccessiblePaths=. "read-only" ReadOnlyPaths= "tmpfs" TemporaryFileSystem= ":ro". ( ) . DynamicUser=. . ReadOnlyPaths= . . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 214. RuntimeDirectory=, StateDirectory=, CacheDirectory=, LogsDirectory=, ConfigurationDirectory= . "..". ( ) . . (":"). DynamicUser= id-mapped mounts[9] "nobody" ( ) / (UID/GID) . id-mapped . 2. +------------------------+--------------------+--------------------------+--------------------------+ | | | | | | | | | | | | | | | | | | | | +------------------------+--------------------+--------------------------+--------------------------+ |RuntimeDirectory= | /run/ | $XDG_RUNTIME_DIR | $RUNTIME_DIRECTORY | +------------------------+--------------------+--------------------------+--------------------------+ |StateDirectory= | /var/lib/ | $XDG_STATE_HOME | $STATE_DIRECTORY | +------------------------+--------------------+--------------------------+--------------------------+ |CacheDirectory= | /var/cache/ | $XDG_CACHE_HOME | $CACHE_DIRECTORY | +------------------------+--------------------+--------------------------+--------------------------+ |LogsDirectory= | /var/log/ | $XDG_STATE_HOME/log/ | $LOGS_DIRECTORY | +------------------------+--------------------+--------------------------+--------------------------+ |ConfigurationDirectory= | /etc/ | $XDG_CONFIG_HOME | $CONFIGURATION_DIRECTORY | +------------------------+--------------------+--------------------------+--------------------------+ RuntimeDirectory= . RuntimeDirectoryPreserve= restart yes ( ). StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . ConfigurationDirectory= User= Group=. . . RuntimeDirectoryMode= StateDirectoryMode= CacheDirectoryMode= LogsDirectoryMode= ConfigurationDirectoryMode=. BindPaths= . RootDirectory= RootImage= . DynamicUser= CacheDirectory= LogsDirectory= StateDirectory= : /var/cache/private /var/log/private /var/lib/private . . /var/cache /var/log /var/lib . RuntimeDirectory= (daemon). /run/ . tmpfiles.d(5). RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ":". . BindPaths= TemporaryFileSystem= . . v257 ro . ConfigurationDirectory=. . : ConfigurationDirectory=foo::ro systemd (/var/ /run/ /etc/ ...). . tmpfiles.d(5) . tmpfiles.d . systemctl clean ... systemctl(1) . : RuntimeDirectory=foo/bar baz /run/foo ( ) /run/foo/bar /run/baz. /run/foo/bar /run/baz /run/foo User= Group= . : RuntimeDirectory=foo/bar StateDirectory=aaa/bbb ccc "RUNTIME_DIRECTORY" "/run/foo/bar" "STATE_DIRECTORY" "/var/lib/aaa/bbb:/var/lib/ccc". : RuntimeDirectory=foo:bar foo:baz /run/foo ( ) /run/bar /run/baz /run/foo. 211. RuntimeDirectoryMode=, StateDirectoryMode=, CacheDirectoryMode=, LogsDirectoryMode=, ConfigurationDirectoryMode= RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . 0755. "Permissions" path_resolution(7) . 234. StateDirectoryQuota=, CacheDirectoryQuota=, LogsDirectoryQuota= StateDirectory= CacheDirectory= LogsDirectory= . (inodes) quotactl[10]. . K M G T ( 1024) . ( ). . (off) . . . prjquota ( tune2fs -Q prjquota). quotaon.[11] 258. StateDirectoryAccounting=, CacheDirectoryAccounting=, LogsDirectoryAccounting= . StateDirectory= CacheDirectory= LogsDirectory= ( repquota[12]). (false). StateDirectoryQuota= CacheDirectoryQuota= LogsDirectoryQuota=. 258. RuntimeDirectoryPreserve= restart. no () RuntimeDirectory= . restart . Restart= systemctl restart foo.service. yes . /run/ "tmpfs" RuntimeDirectory= . DynamicUser= RuntimeDirectoryPreserve= no : RuntimeDirectory= /run/private/ . . /run/ . 235. TimeoutCleanSec= systemctl clean ... systemctl(1) . (infinity) . . 244. ReadWritePaths= ReadOnlyPaths= InaccessiblePaths= ExecPaths= NoExecPaths= . . ( ). RootDirectory=/RootImage=. ReadWritePaths= . ReadOnlyPaths= . ReadWritePaths= ReadOnlyPaths= . ReadWritePaths= ProtectSystem=strict. ReadWritePaths= (superblock) . . ReadWritePaths= . InaccessiblePaths= . ReadWritePaths= ReadOnlyPaths= BindPaths= BindReadOnlyPaths= . TemporaryFileSystem=. NoExecPaths= . ExecPaths= NoExecPaths= . . . . ReadWritePaths= ReadOnlyPaths= InaccessiblePaths= ExecPaths= NoExecPaths= "-" . "+" RootDirectory=/RootImage= ( ). "-" "+" "-" "+" . (propagation of mounts) . . ReadWritePaths= ReadOnlyPaths= . ReadOnlyPaths=! . . . CapabilityBoundingSet=~CAP_SYS_ADMIN SystemCallFilter=~@mount. (API) ( MountAPIVPS=) . /run/ . : [Service] ReadOnlyPaths=/ ReadWritePaths=/var /run InaccessiblePaths=-/lost+found NoExecPaths=/ ExecPaths=/usr/sbin/my_daemon /usr/lib /usr/lib64 PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 231. TemporaryFileSystem= (tmpfs). . . . (":") "size=10%" "ro". "nodev,strictatime,mode=0755". "dev" "nostrictatime". BindPaths= BindReadOnlyPaths=: : TemporaryFileSystem=/var:ro BindReadOnlyPaths=/var/lib/systemd /var/ /var/lib/systemd . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 238. PrivateTmp= "disconnected". /tmp/ /var/tmp/ . ReadOnlyPaths= . /tmp/ /var/tmp/ . DynamicUser= "disconnected" . (false). "true" /tmp/ /var/tmp/ . /tmp/ /var/tmp/ JoinsNamespaceOf= systemd.unit(5) . Wants= After= /tmp/ /var/tmp/ . After= systemd-tmpfiles-setup.service(8). "disconnected" tmpfs . tmpfs JoinsNamespaceOf=. DefaultDependencies=no RequiresMountsFor=/WantsMountsFor= /var/ RootDirectory=/RootImage= tmpfs /tmp/ /var/tmp . $TMPDIR "/tmp" /tmp/ . WantsMountsFor=/var/ DefaultDependencies=no / RootDirectory=/RootImage=. 3. PrivateTmp=disconnected +--------------------------+-----------+---------------+-----------------------------------+ | | tmpfs on | $TMPVAR | | | | /var/tmp/ | | | +--------------------------+-----------+---------------+-----------------------------------+ |( ) | | ( | WantsMountsFor=/var/ | | | | ) | | +--------------------------+-----------+---------------+-----------------------------------+ |RootDirectory=/RootImage= | | ( | ( ) | | | | ) | | +--------------------------+-----------+---------------+-----------------------------------+ |DefaultDependency=no, | | ( | ( ) | |RequiresMountsFor=/var/ | | ) | | +--------------------------+-----------+---------------+-----------------------------------+ |DefaultDependency=no, | | ( | ( ) | |WantsMountsFor=/var/ | | ) | | +--------------------------+-----------+---------------+-----------------------------------+ |DefaultDependency=no | no | $TMPDIR=/tmp | ( ) | +--------------------------+-----------+---------------+-----------------------------------+ ( ) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). PrivateDevices= . /dev/ (API pseudo devices) /dev/null /dev/zero /dev/random ( TTY ) /dev/sda /dev/mem /dev/port . . (false). / @raw-io CAP_MKNOD CAP_SYS_RAWIO DevicePolicy=closed ( systemd.resource-control(5) ). ( ). . /dev/ 'noexec'. mmap(2) /dev/zero MAP_ANON. ReadOnlyPaths= . ( ) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). DeviceAllow= . systemd.resource-control(5). 209. PrivateNetwork= . "lo" . . . (false). JoinsNamespaceOf= systemd.unit(5) . AF_NETLINK AF_UNIX. AF_NETLINK systemd-udevd.service(8) . AF_UNIX AF_UNIX ( ). ( ) . PrivateMounts= /sys . . JoinsNamespaceOf= . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). UserNamespacePath= ( /proc/$PID/ns/user ). . . PrivateUsers= . . 259. NetworkNamespacePath= ( /proc/$PID/ns/net ). . . PrivateNetwork= . JoinsNamespaceOf= PrivateNetwork= NetworkNamespacePath= . PrivateMounts= /sys . . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 242. PrivateIPC= . (true) IPC . IPC System V IPC POSIX . IPC. (false). IPC JoinsNamespaceOf= systemd.unit(5) . IPC AF_UNIX IPC . AF_UNIX . IPC SysV IPC ( ) POSIX ( AF_UNIX/SOCK_SEQPACKET ). IPC POSIX ( ) . ipc_namespaces(7) . ( IPC ) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 248. IPCNamespacePath= IPC ( /proc/$PID/ns/ipc ). . . PrivateIPC= . JoinsNamespaceOf= PrivateIPC= IPCNamespacePath= . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 248. MemoryKSM= . (KSM) . KSM . . . Kernel Samepage Merging[13] . KSM KSM prctl(2). 254. MemoryTHP= (THPs) (2 x86 4 ). . . THP /sys/kernel/mm/transparent_hugepage/enabled. prctl(2). MemoryTHP= THPs THPs . MemoryTHP= "inherit" systemd THP prctl(2) PR_SET_THP_DISABLE. "disable" MemoryTHP= THPs THP. "madvise" MemoryTHP= THPs madvise(2) MADV_HUGEPAGE MADV_COLLAPSE. "system" MemoryTHP= THP . systemd THPs PR_SET_THP_DISABLE THP . Transparent Hugepage Support[14] . THP THP prctl(2). 260. PrivatePIDs= . (false). PID . PID 1 - (init) - . /proc/ PID. PrivatePIDs= MountAPIVFS=yes. PrivatePIDs= . Type=forking PID init. PID. ( ) PrivatePIDs=yes /proc/ ( /proc/kmsg tmpfs systemd-nspawn(1)). /proc/. 257. PrivateUsers= : "self" "identity" "full" "managed". (false). . "self" "root" "nobody". (sandbox) . IPC / "root" / "nobody". "identity" 65536 UIDs/GIDs. UIDs/GIDs 65536 "nobody" . UID/GID UIDs/GIDs UID . "full" UIDs/GIDs. "full" setgroups() ( /proc/pid/setgroups "allow"). "identity" UID/GID . ( / "root" ). . CapabilityBoundingSet= . "managed" 65536 UIDs/GIDs UID/GID UID/GID 0 UID/GID . UID/GID ( UID ) ( 0). UID UID "" UID . "root" ( root). . PrivateUsers=true . RootDirectory=/RootImage= "root" "nobody" . 232. ProtectHostname= "private". UTS . ( "yes:foo" "private:host.example.com") UTS . sethostname() setdomainname(). "private" UTS . (off). ( UTS ) . . hostnamectl. User= Group= . SetHostname() org.freedesktop.hostname1(5) . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 242. ProtectClock= . . (off). CAP_SYS_TIME CAP_WAKE_ALARM DeviceAllow=char-rtc r. . /dev/rtc0 /dev/rtc1 . systemd.resource-control(5) DeviceAllow=. . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 245. ProtectKernelTunables= . (true) /proc/sys/ /sys/ /proc/sysrq-trigger /proc/latency_stats /proc/acpi /proc/timer_stats /proc/fs /proc/irq /proc/kallsyms /proc/kcore . sysctl.d(5). . ReadOnlyPaths= . (off). IPC . InaccessiblePaths= IPC . ProtectKernelTunables= MountAPIVFS=yes. PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 232. ProtectKernelModules= . (true) . . . (off). CAP_SYS_MODULE /usr/lib/modules . ReadOnlyPaths= . . kernel.modules_disabled sysctl.d(5) /proc/sys/kernel/modules_disabled. PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 232. ProtectKernelLogs= . (true) . . CAP_SYSLOG syslog(2) ( libc syslog(3) ). /dev/kmsg /proc/kmsg. . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 244. ProtectControlGroups= "private" "strict". (true) (cgroups(7)) /sys/fs/cgroup/ . "private" cgroup /sys/fs/cgroup/. "strict" cgroup /sys/fs/cgroup/. (off). ProtectControlGroups= MountAPIVFS=yes. "private" (false) "strict" (true) cgroup. ProtectControlGroups= (true) "strict" . ReadOnlyPaths= . . 232. RestrictAddressFamilies= . "none" ( ) AF_UNIX AF_INET AF_INET6 address_families(7) . "none" . "~" . . . "+". AF_PACKET. AF_UNIX syslog(2). socket(2) . ( systemd.socket(5)). socketpair() ( AF_UNIX ) io_uring(7) . SystemCallFilter=@service . ABI x86-64 32-bit x86 s390 s390x mips mips-le ppc ppc-le ppc64 ppc64-le . ABI ( x86/x86-64) ABI . SystemCallArchitectures=native . 211. RestrictFileSystems= . . ( ). "~" : ( ). . ( ) ( ). . : RestrictFileSystems=ext4 tmpfs RestrictFileSystems=ext2 ext4 ext4 tmpfs ext2 . : RestrictFileSystems=ext4 tmpfs RestrictFileSystems=~ext4 tmpfs. : RestrictFileSystems=~ext4 tmpfs RestrictFileSystems=ext4 tmpfs. . "@" . 4. +-------------------------+---------------------------------+ | | | +-------------------------+---------------------------------+ |@basic-api | | | | | | | | | | | | | . | +-------------------------+---------------------------------+ |@auxiliary-api | | | | | | | | | | | | | . | +-------------------------+---------------------------------+ |@common-block | | | | | | | | | | . | +-------------------------+---------------------------------+ |@historical-block | | | | | | | | | | . | +-------------------------+---------------------------------+ |@network | | | | | | | | | | . | +-------------------------+---------------------------------+ |@privileged-api | | | | | | | | | | | | | . | +-------------------------+---------------------------------+ |@temporary | | | | | | | : tmpfs, | | | ramfs. | +-------------------------+---------------------------------+ |@known | | | | | | | | | | | | | . | | | | | | | | | | | | systemd | | | | | | | | | | | | | | | systemd . | | | | | | | | | | | | . | +-------------------------+---------------------------------+ filesystems systemd-analyze(1) . ( LSM eBPF ). . "+" . 250. RestrictNamespaces= . namespaces(7). . (false) . (true) . : cgroup ipc net mnt pid user uts time. ( ). ("~") : ( ). (false). OR AND "~" ( ). unshare(2) clone(2) setns(2) . -- -- ( ) setns() . x86 x86-64 mips mips-le mips64 mips64-le mips64-n32 mips64-le-n32 ppc64 ppc64-le s390 s390x . : RestrictNamespaces=cgroup ipc RestrictNamespaces=cgroup net cgroup ipc net. "~" : RestrictNamespaces=cgroup ipc RestrictNamespaces=~cgroup net ipc . 233. DelegateNamespaces= . namespaces(7). . (false) . (true) ( ) . : cgroup ipc net mnt pid uts. ( ). ("~") : ( ). (false). OR AND "~" ( ). systemd. . . . . DelegateNamespaces= PrivateUsers=self PrivateUsers= . PrivateNetwork= PrivateMounts=. VFS PrivatePIDs= ProtectControlGroups=private/strict PrivateNetwork=. . 258. PrivateBPF= . BPF /sys/fs/bpf/ bpffs . ProtectKernelTunables= . (false). bpffs BPF . BPF fsopen() BPF . bpffs BPF bpffs. LWN [15]. 258. BPFDelegateCommands= BPF "any" . (none). : BPFMapCreate BPFMapLookupElem BPFMapUpdateElem BPFMapDeleteElem BPFMapGetNextKey BPFProgLoad BPFObjPin BPFObjGet BPFProgAttach BPFProgDetach BPFProgTestRun BPFProgGetNextId BPFMapGetNextId BPFProgGetFdById BPFMapGetFdById BPFObjGetInfoByFd BPFProgQuery BPFRawTracepointOpen BPFBtfLoad BPFBtfGetFdById BPFTaskFdQuery BPFMapLookupAndDeleteElem BPFMapFreeze BPFBtfGetNextId BPFMapLookupBatch BPFMapLookupAndDeleteBatch BPFMapUpdateBatch BPFMapDeleteBatch BPFLinkCreate BPFLinkUpdate BPFLinkGetFdById BPFLinkGetNextId BPFEnableStats BPFIterCreate BPFLinkDetach BPFProgBindMap BPFTokenCreate BPFProgStreamReadByFd BPFProgAssocStructOps. bpffs delegate_cmds. PrivateBPF=yes PrivateBPF= . 258. BPFDelegateMaps= BPF "any" . (none). : BPFMapTypeUnspec BPFMapTypeHash BPFMapTypeArray BPFMapTypeProgArray BPFMapTypePerfEventArray BPFMapTypePercpuHash BPFMapTypePercpuArray BPFMapTypeStackTrace BPFMapTypeCgroupArray BPFMapTypeLruHash BPFMapTypeLruPercpuHash BPFMapTypeLpmTrie BPFMapTypeArrayOfMaps BPFMapTypeHashOfMaps BPFMapTypeDevmap BPFMapTypeSockmap BPFMapTypeCpumap BPFMapTypeXskmap BPFMapTypeSockhash BPFMapTypeCgroupStorageDeprecated BPFMapTypeReuseportSockarray BPFMapTypePercpuCgroupStorageDeprecated BPFMapTypeQueue BPFMapTypeStack BPFMapTypeSkStorage BPFMapTypeDevmapHash BPFMapTypeStructOps BPFMapTypeRingbuf BPFMapTypeInodeStorage BPFMapTypeTaskStorage BPFMapTypeBloomFilter BPFMapTypeUserRingbuf BPFMapTypeCgrpStorage BPFMapTypeArena BPFMapTypeInsnArray. bpffs delegate_maps. PrivateBPF=yes PrivateBPF= . 258. BPFDelegatePrograms= BPF "any" . (none). : BPFProgTypeUnspec BPFProgTypeSocketFilter BPFProgTypeKprobe BPFProgTypeSchedCls BPFProgTypeSchedAct BPFProgTypeTracepoint BPFProgTypeXdp BPFProgTypePerfEvent BPFProgTypeCgroupSkb BPFProgTypeCgroupSock BPFProgTypeLwtIn BPFProgTypeLwtOut BPFProgTypeLwtXmit BPFProgTypeSockOps BPFProgTypeSkSkb BPFProgTypeCgroupDevice BPFProgTypeSkMsg BPFProgTypeRawTracepoint BPFProgTypeCgroupSockAddr BPFProgTypeLwtSeg6local BPFProgTypeLircMode2 BPFProgTypeSkReuseport BPFProgTypeFlowDissector BPFProgTypeCgroupSysctl BPFProgTypeRawTracepointWritable BPFProgTypeCgroupSockopt BPFProgTypeTracing BPFProgTypeStructOps BPFProgTypeExt BPFProgTypeLsm BPFProgTypeSkLookup BPFProgTypeNetfilter. bpffs delegate_progs. PrivateBPF=yes PrivateBPF= . 258. BPFDelegateAttachments= BPF "any" . (none). : BPFCgroupInetIngress BPFCgroupInetEgress BPFCgroupInetSockCreate BPFCgroupSockOps BPFSkSkbStreamParser BPFSkSkbStreamVerdict BPFCgroupDevice BPFSkMsgVerdict BPFCgroupInet4Bind BPFCgroupInet6Bind BPFCgroupInet4Connect BPFCgroupInet6Connect BPFCgroupInet4PostBind BPFCgroupInet6PostBind BPFCgroupUdp4Sendmsg BPFCgroupUdp6Sendmsg BPFLircMode2 BPFFlowDissector BPFCgroupSysctl BPFCgroupUdp4Recvmsg BPFCgroupUdp6Recvmsg BPFCgroupGetsockopt BPFCgroupSetsockopt BPFTraceRawTp BPFTraceFentry BPFTraceFexit BPFModifyReturn BPFLsmMac BPFTraceIter BPFCgroupInet4Getpeername BPFCgroupInet6Getpeername BPFCgroupInet4Getsockname BPFCgroupInet6Getsockname BPFXdpDevmap BPFCgroupInetSockRelease BPFXdpCpumap BPFSkLookup BPFXdp BPFSkSkbVerdict BPFSkReuseportSelect BPFSkReuseportSelectOrMigrate BPFPerfEvent BPFTraceKprobeMulti BPFLsmCgroup BPFStructOps BPFNetfilter BPFTcxIngress e BPFTcxEgress BPFTraceUprobeMulti BPFCgroupUnixConnect BPFCgroupUnixSendmsg BPFCgroupUnixRecvmsg BPFCgroupUnixGetpeername BPFCgroupUnixGetsockname BPFNetkitPrimary BPFNetkitPeer BPFTraceKprobeSession BPFTraceUprobeSession BPFTraceFsession. bpffs delegate_attachs. PrivateBPF=yes PrivateBPF= . 258. LockPersonality= . personality(2) (personality) Personality=. . 235. MemoryDenyWriteExecute= . . ( prctl(2)) mmap(2) PROT_EXEC PROT_WRITE mprotect(2) pkey_mprotect(2) PROT_EXEC shmat(2) SHM_EXEC. JIT "trampoline" C. . noexec ( /dev/shm) memfd_create(). ( InaccessiblePaths=/dev/shm) (SystemCallFilter=~memfd_create). x86-64 x86. shmat() x86. ABI ( x86/x86-64) ABI . SystemCallArchitectures=native . 231. RestrictRealtime= . . SCHED_FIFO SCHED_RR SCHED_DEADLINE. sched(7) . . . . 231. RestrictSUIDSGID= . (SUID) (SGID) ( inode(7)). SUID/SGID SUID/SGID . ( SGID ). DynamicUser=. DefaultRestrictSUIDSGID= systemd-system.conf(5) . 242. RemoveIPC= . IPC System V POSIX . User= Group= DynamicUser=. IPC (root). System V System V POSIX. IPC . DynamicUser=. . 232. PrivateMounts= . () . . . mount_namespaces(7) . . : CLONE_NEWNS MS_SLAVE ( ). MountFlags= . . ExecStartPre= ExecStart= ( ). JoinsNamespaceOf= /tmp/ /var/tmp/. -- PrivateTmp= PrivateDevices= ProtectSystem= ProtectHome= ReadOnlyPaths= InaccessiblePaths= ReadWritePaths= BindPaths= BindReadOnlyPaths= -- . . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). 239. MountFlags= : shared () slave () private () . mount(2) . . ( PrivateMounts= ) slave . shared . -- -- shared -- -- slave . private ( ) . PrivateMounts= . PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone="). SystemCallFilter= . ( ). "~", : ( ). . . "+" . execve() exit() exit_group() getrlimit() rt_sigreturn() sigreturn() . SIGSYS. SystemCallErrorNumber= . (":") SystemCallErrorNumber= . SystemCallErrorNumber=. 2 (Secure Computing Mode 2) (' seccomp') . (ABIs) ( x86/x86-64) ABI . SystemCallArchitectures=native . . execve() -- . ( : ) . . ( ) ( ). . ( read() write() write() write() .) . "@" . 5. +-------------------------+---------------------------------------------+ | | | +-------------------------+---------------------------------------------+ |@aio | / | | | | | | (io_setup(2) io_submit(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@basic-io | | | | | | | / | | | : | | | | | | | | | | | | | | | (read(2) write(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@chown | | | | (chown(2) fchownat(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@clock | | | | | | | | | | (adjtimex(2) settimeofday(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@cpu-emulation | | | | | | | | | | (vm86(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@debug | | | | | | | (ptrace(2) | | | perf_event_open(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@file-system | | | | : | | | | | | | | | | | | | | | | | | | | | | | | | | | | +-------------------------+---------------------------------------------+ |@io-event | | | | (poll(2) | | | select(2) epoll(7) eventfd(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@ipc | SysV IPC | | | POSIX | | | IPC | | | (mq_overview(7) svipc(7)) | +-------------------------+---------------------------------------------+ |@keyring | | | | | | | (keyctl(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@memlock | | | | (mlock(2) mlockall(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@module | | | | | | | (init_module(2) | | | delete_module(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@mount | | | | (mount(2) | | | chroot(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@network-io | / | | | ( | | | AF_UNIX ): | | | socket(7) unix(7) | +-------------------------+---------------------------------------------+ |@obsolete | | | | | | | (create_module(2) | | | gtty(2) ) | +-------------------------+---------------------------------------------+ |@pkey | | | | | | | | | | | | | (pkeys(7)) | +-------------------------+---------------------------------------------+ |@privileged | | | | | | | | | | | | | | | | (capabilities(7)) | +-------------------------+---------------------------------------------+ |@process | | | | | | | | | | | | | (clone(2) kill(2) | | | namespaces(7) ) | +-------------------------+---------------------------------------------+ |@raw-io | | | | | | | / | | | (ioperm(2) iopl(2) | | | pciconfig_read() ) | +-------------------------+---------------------------------------------+ |@reboot | | | | | | | | | | | | | (reboot(2) kexec() ) | +-------------------------+---------------------------------------------+ |@resources | | | | | | | | | | | | | | | | (setrlimit(2) | | | setpriority(2) ) | +-------------------------+---------------------------------------------+ |@sandbox | | | | | | | (seccomp(2) | | | | | | Landlock ) | +-------------------------+---------------------------------------------+ |@setuid | | | | | | | | | | | | | | | | (setuid(2) setgid(2) | | | setresuid(2) ) | +-------------------------+---------------------------------------------+ |@signal | | | | | | | | | | | | | (signal(2) | | | sigprocmask(2) ) | +-------------------------+---------------------------------------------+ |@swap | | | | | | | / | | | | | | (swapon(2) swapoff(2)) | +-------------------------+---------------------------------------------+ |@sync | | | | | | | (fsync(2) msync(2) | | | | | | ) | +-------------------------+---------------------------------------------+ |@system-service | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | : "@clock" | | | "@mount" "@swap" "@reboot". | +-------------------------+---------------------------------------------+ |@timer | | | | | | | | | | (alarm(2) | | | timer_create(2) ) | +-------------------------+---------------------------------------------+ |@known | | | | | | | . | | | | | | | | | systemd | | | | | | | | | | | | systemd . | | | | | | . | +-------------------------+---------------------------------------------+ . systemd . systemd . systemd-analyze syscall-filter . ( ) . . : [Service] SystemCallFilter=@system-service SystemCallErrorNumber=EPERM : . pidfd_send_signal() kill() . . . . (: ELF ). ( open() openat() mmap()) . SystemCallFilter=~@mount . : PrivateTmp= PrivateDevices= ProtectSystem= ProtectHome= ProtectKernelTunables= ProtectControlGroups= ProtectKernelLogs= ProtectClock= ReadOnlyPaths= InaccessiblePaths= ReadWritePaths=. 187. SystemCallErrorNumber= "errno" ( 1 4095) EPERM EACCES EUCLEAN SystemCallFilter= . errno(3) . "kill" . 209. SystemCallArchitectures= . ConditionArchitecture= systemd.unit(5) x32 mips64-n32 mips64-le-n32 native. native ( : ). . (native) . x32 x86-64. x32. . x86 ABI -- x86-64 . ABI -- x86/x86-64 -- ABI ABI . SystemCallArchitectures=native ABI . SystemCallArchitectures= . systemd-system.conf(5) . 209. SystemCallLog= . . "~", : . 2 (Secure Computing Mode 2) (' seccomp') . . . "+". 247. Environment= Orc. "Quoting" systemd.syntax(7) . . "$" . "Specifiers" systemd.unit(5). . . . ASCII (_). . . : Environment="VAR1=word1 word2" VAR2=word3 "VAR3=$word 5 6" "VAR1" "VAR2" "VAR3" "word1 word2" "word3" "$word 5 6". environ(7) . ( ) . D-Bus IPC . ( setuid/setgid) . LoadCredential= LoadCredentialEncrypted= SetCredentialEncrypted= ( ) . EnvironmentFile= Environment= . . "=" ";" "#" . UTF-8. unicode scalar values[16] unicode noncharacters[17] U+0000 NUL U+FEFF unicode byte order mark[18]. NUL . "=" POSIX [19] . ( ) . . "\" "\\" "\". "'" "=" POSIX [20]. . . """ "=" POSIX [21]. ("\") ""\`$" . . . . (wildcard). . "-" . . . "$HOME" . -"%" "%h" . ( . . bind mounts). Environment=. . PassEnvironment= . . . . . . . Environment= EnvironmentFile=. : PassEnvironment=VAR1 VAR2 VAR3 "VAR1" "VAR2" "VAR3" PID1. environ(7) . 228. UnsetEnvironment= . . / . / . (: "=" ) . ( "=" ) . UnsetEnvironment= . Environment= EnvironmentFile= PassEnvironment= ( $NOTIFY_SOCKET ) PAM ( PAMName=). " " . environ(7) . 235. / StandardInput= 0 (STDIN) . : null tty tty-force tty-fail data file:path socket fd:name. null /dev/null (EOF) . tty TTY ( TTYPath= ) . . tty-force tty . tty-fail tty . data . StandardInputText=/StandardInputData= ( ). ( UNIX ...) . EOF. file:path . ":" FIFO . AF_UNIX . . socket ( systemd.socket(5) ) Accept=yes . (daemons) inetd(8) ( $LISTEN_FDS ( ) socket). fd:name . ":" ( : "fd:foobar"). "stdin" ( "fd" "fd:stdin"). Sockets= . . FileDescriptorName= systemd.socket(5) . null StandardInputText= StandardInputData= data. StandardOutput= 1 (stdout) . : inherit null tty journal kmsg journal+console kmsg+console file:path append:path truncate:path socket fd:name. inherit . null /dev/null . tty tty ( TTYPath= ). TTY . : TTY . SetShowStatus() . org.freedesktop.systemd1(5) . journal (journal) journalctl(1). kmsg ( ) . ( syslog .) kmsg dmesg(1) . kmsg journal. journal+console kmsg+console (console) . file:path . StandardInput= . path ( systemd) . -- -- . AF_UNIX . append:path file:path (append mode). truncate:path file:path . Type=oneshot ExecStart= ExecCondition= ExecStartPre= ExecStartPost= . ExecReload= ExecStart= NUL (sparse file). truncate:path ExecStart= ExecStartPost= ExecReload= ExecStop= . socket . StandardInput= . fd:name . ":" ( : "fd:foobar"). "stdout" ( "fd" "fd:stdout"). Sockets= . . FileDescriptorName= systemd.socket(5) . ( ) After= systemd-journald.socket ( " " ). stdout ( stderr ) AF_UNIX FIFO . echo "hello" > /dev/stderr stderr . echo "hello" >&2 . StandardInput= tty tty-force tty-fail socket fd:name inherit. DefaultStandardOutput= systemd-system.conf(5) journal. ( ). StandardError= 2 (stderr) . StandardOutput= : inherit fd:name "stderr". DefaultStandardError= systemd-system.conf(5) inherit. ( ). StandardInputText= StandardInputData= 0 (STDIN) . StandardInput= data ( StandardInput= StandardInputText=/StandardInputData=). . StandardInputText= . C "%" . ( ). . ( "\n" ). StandardInputData= Base64[22]. . . StandardInputText= StandardInputData= . . . ( ) "\" ( systemd.unit(5) ). . : ... StandardInput=data StandardInputData=V2XigLJyZSBubyBzdHJhbmdlcnMgdG8gbG92ZQpZb3Uga25vdyB0aGUgcnVsZXMgYW5kIHNvIGRv \ IEkKQSBmdWxsIGNvbW1pdG1lbnQncyB3aGF0IEnigLJtIHRoaW5raW5nIG9mCllvdSB3b3VsZG4n \ dCBnZXQgdGhpcyBmcm9tIGFueSBvdGhlciBndXkKSSBqdXN0IHdhbm5hIHRlbGwgeW91IGhvdyBJ \ J20gZmVlbGluZwpHb3R0YSBtYWtlIHlvdSB1bmRlcnN0YW5kCgpOZXZlciBnb25uYSBnaXZlIHlv \ dSB1cApOZXZlciBnb25uYSBsZXQgeW91IGRvd24KTmV2ZXIgZ29ubmEgcnVuIGFyb3VuZCBhbmQg \ ZGVzZXJ0IHlvdQpOZXZlciBnb25uYSBtYWtlIHlvdSBjcnkKTmV2ZXIgZ29ubmEgc2F5IGdvb2Ri \ eWUKTmV2ZXIgZ29ubmEgdGVsbCBhIGxpZSBhbmQgaHVydCB5b3UK ... 236. LogLevelMax= . syslog : emerg ( ) alert crit err warning notice info debug ( ). syslog(3) . . . LogLevelMax=info . LogLevelMax=debug. . . . MaxLevelStore= journald.conf(5) LogLevelMax= . 236. LogExtraFields= systemd. "FIELD=VALUE" . systemd.journal-fields(7) . UTF-8 . ("). ( ). . . . 236. LogRateLimitIntervalSec=, LogRateLimitBurst= . LogRateLimitIntervalSec= LogRateLimitBurst= . . LogRateLimitIntervalSec= : "s" "min" "h" "ms" "us". systemd.time(7) . RateLimitIntervalSec= RateLimitBurst= journald.conf(5). systemd-journald.service(8). stderr StandardOutput=file:... ( syslog(3) ). 240. LogFilterPatterns= MESSAGE= . "~" . . . "~" "\x7e" "~". "~foobar" "foobar" "\x7efoobar" "~foobar" . ( ) ( ). . . . . LogFilterPatterns= systemd(1) . syslog (kmsg) systemd (wall messages) . . 253. LogNamespace= (journal namespace) . . systemd-journald.service. ( syslog() journal native stdout/stderr) systemd-journald@.service . . systemd-journald.service(8) . (Linux mount namespacing) (over-mounting) AF_UNIX . ReadOnlyPaths= . . systemd-journald@.service . journalctl(1) --namespace=. . 245. SyslogIdentifier= (" syslog") . . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr. SyslogFacility= syslog . : kern user mail daemon auth syslog lpr news uucp cron authpriv ftp local0 local1 local2 local3 local4 local5 local6 local7. syslog(3) . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr. daemon. SyslogLevel= syslog . : emerg alert crit err warning notice info debug. syslog(3) . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr. . SyslogLevelPrefix= . sd-daemon(3). info. SyslogLevelPrefix= . (true) StandardOutput= StandardError= journal kmsg ( +console) . (false) . stdout stderr. sd-daemon(3). (true). TTYPath= TTY ( ). /dev/console. TTYReset= TTYPath= . ( TTYVTDisallocate= ). "no". TTYVHangup= TTYPath= . "no". TTYColumns=, TTYRows= TTY TTYPath=. ANSI ( 80x24). 250. TTYVTDisallocate= TTYPath= TTY . . TTY ANSI. "no". LoadCredential=ID[:PATH] LoadCredentialEncrypted=ID[:PATH] (credential) . . ( ) . ( ) (non-swappable). User=/DynamicUser= ( superuser). $CREDENTIALS_DIRECTORY . LoadCredential= (ID) . ASCII . . AF_UNIX ( ) IPC . -- (: ) . /etc/credstore/ /run/credstore/ /usr/lib/credstore/ -- . LoadCredentialEncrypted= /run/credstore.encrypted/ /etc/credstore.encrypted/ /usr/lib/credstore.encrypted/ . $XDG_CONFIG_HOME/credstore/ $XDG_RUNTIME_DIR/credstore/ $HOME/.local/lib/credstore/ ( .../credstore.encrypted/) . systemd-path(1) . credstore . . . ( ) . "_$FILENAME" (: "Key_file1"). . / NUL. LoadCredentialEncrypted= LoadCredential= . systemd-creds(1). LoadCredential=. / TPM2 /var/lib/systemd/credential.secret . . . systemd.resource-control(5) DevicePolicy= DeviceAllow=. systemd-creds encrypt --user --user. . / IPC : . DynamicUser= (UID) ( ) . ExecStart= "${CREDENTIALS_DIRECTORY}/mycred" : "ExecStart=cat ${CREDENTIALS_DIRECTORY}/mycred". Environment= "%d/mycred" : "Environment=MYCREDPATH=%d/mycred". "/run/credentials/UNITNAME" : . $CREDENTIALS_DIRECTORY . 1 . (VM hypervisor). Container Interface[23] . OEM DMI/SMBIOS[24] ( 11) "io.systemd.credential:" "io.systemd.credential.binary:". / "=". Base64 ( ). qemu[25]: "-smbios type=11,value=io.systemd.credential:xx=yy" "-smbios type=11,value=io.systemd.credential.binary:rick=TmV2ZXIgR29ubmEgR2l2ZSBZb3UgVXA=". "fw_cfg" qemu "opt/io.systemd.credentials/". qemu: "-fw_cfg name=opt/io.systemd.credentials/mycred,string=supersecret". UEFI systemd-stub(7) initrd ( systemd(1)) "systemd.set_credential=" "systemd.set_credential_binary=" ( systemd(1) - ). AF_UNIX . getpeername(2) . NUL RANDOM "/unit/" UNIT "/" ID NUL ( ) ( ) "/unit/" "/" . : "\0adf9d86b6eda275e/unit/foobar.service/credx" "credx" "foobar.service". . System and Service Credentials[26]. 247. ImportCredential=GLOB . -- (: ) . (glob) . /etc/credstore/ /run/credstore/ /usr/lib/credstore/ /run/credstore.encrypted/ /etc/credstore.encrypted/ /usr/lib/credstore.encrypted/ . . glob(7): "*" . "?" "[]" "*" . . . "ImportCredential=my.original.cred:my.renamed.cred" "my.original.cred" "my.renamed.cred" . "ImportCredential=my.original.*:my.renamed." "my.original." "my.renamed.xxx" . ImportCredential= . LoadCredential= LoadCredentialEncrypted= ImportCredential=. ImportCredential= ( ). SetCredentialEncrypted=/LoadCredentialEncrypted= / . 254. SetCredential=ID:VALUE SetCredentialEncrypted=ID:VALUE SetCredential= LoadCredential= . IPC. . LoadCredential=. C ( "\n" "\x00" NUL). SetCredentialEncrypted= SetCredential= . . -p systemd-creds(1) SetCredentialEncrypted= . LoadCredentialEncrypted= . LoadCredential= LoadCredentialEncrypted= ImportCredential= SetCredential=. SetCredential= . LoadCredential= LoadCredentialEncrypted= . 247. SYSTEM V UtmpIdentifier= utmp(5) wtmp . getty ( agetty(8)) utmp/wtmp getty ( ). . %I. utmp/wtmp . UtmpMode= "init" "login" "user". UtmpIdentifier= utmp(5)/wtmp . UtmpIdentifier= . "init" INIT_PROCESS utmp/wtmp getty. "login" INIT_PROCESS LOGIN_PROCESS. utmp/wtmp login(1). "user" INIT_PROCESS LOGIN_PROCESS USER_PROCESS. . "init". 225. . ( PassEnvironment=) . : o DefaultEnvironment= systemd-system.conf(5) systemd.setenv= systemd(1) set-environment systemctl(1). o ( ). o ( PassEnvironment= ). o Environment= . o EnvironmentFile= . o PAM PAMName= pam_env(8). -- -- . UnsetEnvironment= . . (PID 1) . PAM . . . : systemd-run -P env systemd-run --user -P env . : $PATH . systemd "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin" . . $PATH. 208. $LANG (Locale). locale.conf(5) ( systemd(1) kernel-command-line(7)). 208. $USER, $LOGNAME, $HOME, $SHELL () . $USER $HOME $LOGNAME $SHELL User= SetLoginEnvironment= true. . passwd(5). 208. $INVOCATION_ID 128 32 . . . 232. $XDG_RUNTIME_DIR ( IPC) . systemd PAMName= PAM pam_systemd. pam_systemd(8) . 208. $RUNTIME_DIRECTORY, $STATE_DIRECTORY, $CACHE_DIRECTORY, $LOGS_DIRECTORY, $CONFIGURATION_DIRECTORY RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . 244. $CREDENTIALS_DIRECTORY ImportCredential=/LoadCredential=/SetCredential=. ( ) UID User= DynamicUser= ( ). 247. $TMPDIR "/tmp" PrivateTmp=disconnected DefaultDependencies=no RootDirectory=/RootImage= RequiresMountsFor=/WantsMountsFor= /var/. PrivateTmp= . 258. $MAINPID (PID) . ExecReload= . 209. $MAINPIDFDID inode 64 pidfd_open(3) ( ). ExecReload= . 258. $MANAGERPID (PID) systemd . 208. $MANAGERPIDFDID inode pidfd_open() ( ) systemd . 258. $LISTEN_FDS $LISTEN_PID $LISTEN_PIDFDID $LISTEN_FDNAMES . sd_listen_fds(3). 208. $NOTIFY_SOCKET sd_notify(). sd_notify(3). 229. $WATCHDOG_PID, $WATCHDOG_USEC (keep-alive) (watchdog). sd_watchdog_enabled(3). 229. $SYSTEMD_EXEC_PID (PID) ( ExecStart=). PID ( sd_listen_fds(3) $LISTEN_PID $LISTEN_FDS). 248. $TERM (StandardInput=tty StandardOutput=tty StandardError=tty). termcap(5). 209. $LOG_NAMESPACE LogNamespace=. 246. $JOURNAL_STREAM ( StandardError=journal) $JOURNAL_STREAM inode (":"). . inode . $JOURNAL_STREAM . . ( inode .) ( sd_journal_print(3) ) . 231. $SERVICE_RESULT . ExecStop= ExecStopPost= "" . : 6. $SERVICE_RESULT +-------------------+---------------------------------+ | | | +-------------------+---------------------------------+ |"success" | | | | | | | . | +-------------------+---------------------------------+ |"protocol" | | | | : | | | | | | | | | | | | | | | | | | | | | ( | | | | | | Type= | | | ). | +-------------------+---------------------------------+ |"timeout" | | | | | | | . | +-------------------+---------------------------------+ |"exit-code" | | | | | | | | | | | | | $EXIT_CODE | | | | | | | | | | | | . | +-------------------+---------------------------------+ |"signal" | | | | | | | | | | | | | | | | | | | | | | (core | | | dump). $EXIT_CODE | | | | | | | | | | | | | | | | | | . | +-------------------+---------------------------------+ |"core-dump" | | | | | | | | | | | | | | | | | | | (core | | | dump). $EXIT_CODE | | | | | | | | | | | | | | | . | +-------------------+---------------------------------+ |"watchdog" | | | | | | | (Watchdog | | | keep-alive ping) | | | | | | | | | | | | . | +-------------------+---------------------------------+ |"exec-condition" | | | | | | | ExecCondition= | | | ( | | | | | | | | | 1 254 | | | ()). | +-------------------+---------------------------------+ |"oom-kill" | | | | | | | | | | | | | | | | (OOM killer). | +-------------------+---------------------------------+ |"start-limit-hit" | | | | | | | | | | | | | | | | | | | | | | . | | | StartLimitIntervalSec= | | | StartLimitBurst= | | | | | | systemd.unit(5) | | | . | +-------------------+---------------------------------+ |"resources" | | | | | | | | | | . | +-------------------+---------------------------------+ . ExecStop= ExecStopPost= . 232. $EXIT_CODE, $EXIT_STATUS . ExecStop= ExecStopPost= / . wait(2). $EXIT_CODE "exited" "killed" "dumped". $EXIT_STATUS $EXIT_CODE "exited" . . 7. +------------------+------------------+---------------------+ |$SERVICE_RESULT | $EXIT_CODE | $EXIT_STATUS | +------------------+------------------+---------------------+ |"success" | "killed" | "HUP", "INT", | | | | "TERM", "PIPE" | | +------------------+---------------------+ | | "exited" | "0" | +------------------+------------------+---------------------+ |"protocol" | not set | not set | | +------------------+---------------------+ | | "exited" | "0" | +------------------+------------------+---------------------+ |"timeout" | "killed" | "TERM", "KILL" | | +------------------+---------------------+ | | "exited" | "0", "1", "2", "3", | | | | ..., "255" | +------------------+------------------+---------------------+ |"exit-code" | "exited" | "1", "2", "3", ..., | | | | "255" | +------------------+------------------+---------------------+ |"signal" | "killed" | "HUP", "INT", | | | | "KILL", ... | +------------------+------------------+---------------------+ |"core-dump" | "dumped" | "ABRT", "SEGV", | | | | "QUIT", ... | +------------------+------------------+---------------------+ |"watchdog" | "dumped" | "ABRT" | | +------------------+---------------------+ | | "killed" | "TERM", "KILL" | | +------------------+---------------------+ | | "exited" | "0", "1", "2", "3", | | | | ..., "255" | +------------------+------------------+---------------------+ |"exec-condition" | "exited" | "1", "2", "3", "4", | | | | ..., "254" | +------------------+------------------+---------------------+ |"oom-kill" | "killed" | "TERM", "KILL" | +------------------+------------------+---------------------+ |"start-limit-hit" | not set | not set | +------------------+------------------+---------------------+ |"resources" | | | | | | | +------------------+------------------+---------------------+ |: | | | | systemd. | | | | | | | | | | . | | "timeout" "watchdog" | | | | | |systemd. | | SuccessExitStatus= | | | | | | | | | |. | +-----------------------------------------------------------+ 232. $MONITOR_SERVICE_RESULT, $MONITOR_EXIT_CODE, $MONITOR_EXIT_STATUS, $MONITOR_INVOCATION_ID, $MONITOR_UNIT . ExecStart= ExecStartPre= OnFailure= OnSuccess=. $MONITOR_SERVICE_RESULT $MONITOR_EXIT_CODE $MONITOR_EXIT_STATUS ExecStop= ExecStopPost=. $MONITOR_INVOCATION_ID $MONITOR_UNIT . OnFailure= OnSuccess= . (template handler unit) : "OnFailure=handler@%n.service" "OnFailure=handler@%p-%i.service" . 251. $PIDFILE PID PIDFile= systemd.service(5) . PID . . 242. $REMOTE_ADDR, $REMOTE_PORT ( Accept=yes) . IPv4 IPv6 $REMOTE_ADDR IP $REMOTE_PORT . AF_UNIX $REMOTE_ADDR ("/") ("@") . $REMOTE_PORT AF_UNIX. 220. $SO_COOKIE ( Accept=yes) (cookie) . getsockopt(7). 258. $TRIGGER_UNIT, $TRIGGER_PATH, $TRIGGER_TIMER_REALTIME_USEC, $TRIGGER_TIMER_MONOTONIC_USEC (: ) . . . . 252. $MEMORY_PRESSURE_WATCH, $MEMORY_PRESSURE_WRITE . [27] . 254. $FDSTORE . FileDescriptorStoreMax= ( systemd.service(5) ). sd_pid_notify_with_fds(3). 254. $DEBUG_INVOCATION RestartMode=debug . systemd.service(5) . 257. PAMName= pam_systemd PAM systemd . $XDG_SEAT $XDG_VTNR pam_systemd(8) . . . ( fork(2) execve(2).) C LSB systemd . C. 8. C +-------------------+--------------------+---------------------+ | | | | | | | | +-------------------+--------------------+---------------------+ |0 | EXIT_SUCCESS | | | | | | | | | . | +-------------------+--------------------+---------------------+ |1 | EXIT_FAILURE | | | | | | | | | | | | | . | +-------------------+--------------------+---------------------+ LSB[28]. 9. LSB +-------------------+----------------------+--------------------------+ | | | | | | | | +-------------------+----------------------+--------------------------+ |2 | EXIT_INVALIDARGUMENT | | | | | | | | | | | | | . | +-------------------+----------------------+--------------------------+ |3 | EXIT_NOTIMPLEMENTED | | | | | . | +-------------------+----------------------+--------------------------+ |4 | EXIT_NOPERMISSION | | | | | | | | | | | | | | | | | . | +-------------------+----------------------+--------------------------+ |5 | EXIT_NOTINSTALLED | | | | | . | +-------------------+----------------------+--------------------------+ |6 | EXIT_NOTCONFIGURED | | | | | | | | | . | +-------------------+----------------------+--------------------------+ |7 | EXIT_NOTRUNNING | | | | | . | +-------------------+----------------------+--------------------------+ LSB 200 . : 10. systemd +-------------------+------------------------------+---------------------------------------------+ | | | | | | | | +-------------------+------------------------------+---------------------------------------------+ |200 | EXIT_CHDIR | | | | | | | | | . | | | | WorkingDirectory= . | +-------------------+------------------------------+---------------------------------------------+ |201 | EXIT_NICE | | | | | | | | | ( nice). Nice= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |202 | EXIT_FDS | | | | | | | | | | | | | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |203 | EXIT_EXEC | | | | | | | | | ( | | | | execve(2)). | | | | | | | | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |204 | EXIT_MEMORY | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |205 | EXIT_LIMITS | | | | | . | | | | LimitCPU= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |206 | EXIT_OOM_ADJUST | | | | | OOM. OOMScoreAdjust= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |207 | EXIT_SIGNAL_MASK | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |208 | EXIT_STDIN | | | | | . | | | | StandardInput= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |209 | EXIT_STDOUT | | | | | . | | | | StandardOutput= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |210 | EXIT_CHROOT | | | | | (chroot(2)). | | | | RootDirectory=/RootImage= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |211 | EXIT_IOPRIO | | | | | | | | | /. | | | | IOSchedulingClass=/IOSchedulingPriority= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |212 | EXIT_TIMERSLACK | | | | | . | | | | TimerSlackNSec= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |213 | EXIT_SECUREBITS | | | | | . | | | | SecureBits= . | +-------------------+------------------------------+---------------------------------------------+ |214 | EXIT_SETSCHEDULER | | | | | . | | | | | | | | CPUSchedulingPolicy=/CPUSchedulingPriority= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |215 | EXIT_CPUAFFINITY | | | | | . | | | | CPUAffinity= . | +-------------------+------------------------------+---------------------------------------------+ |216 | EXIT_GROUP | | | | | | | | | | | | | . | | | | Group=/SupplementaryGroups= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |217 | EXIT_USER | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | User=/PrivateUsers= . | +-------------------+------------------------------+---------------------------------------------+ |218 | EXIT_CAPABILITIES | | | | | | | | | | | | | . | | | | CapabilityBoundingSet=/AmbientCapabilities= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |219 | EXIT_CGROUP | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |220 | EXIT_SETSID | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |221 | EXIT_CONFIRM | | | | | . | | | | | | | | | | | | systemd.confirm_spawn= | | | | kernel-command-line(7) | | | | . | +-------------------+------------------------------+---------------------------------------------+ |222 | EXIT_STDERR | | | | | . | | | | StandardError= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |224 | EXIT_PAM | | | | | PAM. PAMName= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |225 | EXIT_NETWORK | | | | | | | | | . | | | | PrivateNetwork= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |226 | EXIT_NAMESPACE | | | | | | | | | UTS | | | | IPC. ReadOnlyPaths= | | | | ProtectHostname= PrivateIPC= | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |227 | EXIT_NO_NEW_PRIVILEGES | | | | | | | | | . | | | | NoNewPrivileges=yes . | +-------------------+------------------------------+---------------------------------------------+ |228 | EXIT_SECCOMP | | | | | | | | | . | | | | SystemCallFilter= | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |229 | EXIT_SELINUX_CONTEXT | | | | | SELinux. | | | | SELinuxContext= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |230 | EXIT_PERSONALITY | | | | | | | | | (). | | | | Personality= . | +-------------------+------------------------------+---------------------------------------------+ |231 | EXIT_APPARMOR_PROFILE | | | | | | | | | AppArmor. AppArmorProfile= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |232 | EXIT_ADDRESS_FAMILIES | | | | | | | | | . | | | | RestrictAddressFamilies= . | +-------------------+------------------------------+---------------------------------------------+ |233 | EXIT_RUNTIME_DIRECTORY | | | | | | | | | . | | | | RuntimeDirectory= | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |235 | EXIT_CHOWN | | | | | . | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |236 | EXIT_SMACK_PROCESS_LABEL | | | | | SMACK. SmackProcessLabel= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |237 | EXIT_KEYRING | | | | | | | | | . | +-------------------+------------------------------+---------------------------------------------+ |238 | EXIT_STATE_DIRECTORY | | | | | | | | | . | | | | StateDirectory= . | +-------------------+------------------------------+---------------------------------------------+ |239 | EXIT_CACHE_DIRECTORY | | | | | | | | | . | | | | CacheDirectory= . | +-------------------+------------------------------+---------------------------------------------+ |240 | EXIT_LOGS_DIRECTORY | | | | | | | | | . | | | | LogsDirectory= . | +-------------------+------------------------------+---------------------------------------------+ |241 | EXIT_CONFIGURATION_DIRECTORY | | | | | . | | | | ConfigurationDirectory= | | | | . | +-------------------+------------------------------+---------------------------------------------+ |242 | EXIT_NUMA_POLICY | | | | | NUMA | | | | . | | | | NUMAPolicy= NUMAMask= . | +-------------------+------------------------------+---------------------------------------------+ |243 | EXIT_CREDENTIALS | | | | | | | | | . | | | | ImportCredential= LoadCredential= | | | | SetCredential= . | +-------------------+------------------------------+---------------------------------------------+ |245 | EXIT_BPF | | | | | BPF. | | | | RestrictFileSystems= . | +-------------------+------------------------------+---------------------------------------------+ BSD : 11. BSD +-------------------+--------------------+---------------------------------------------+ | | | | | | | | +-------------------+--------------------+---------------------------------------------+ |64 | EX_USAGE | | | | | | +-------------------+--------------------+---------------------------------------------+ |65 | EX_DATAERR | | | | | | +-------------------+--------------------+---------------------------------------------+ |66 | EX_NOINPUT | | | | | | +-------------------+--------------------+---------------------------------------------+ |67 | EX_NOUSER | | | | | | +-------------------+--------------------+---------------------------------------------+ |68 | EX_NOHOST | | | | | | +-------------------+--------------------+---------------------------------------------+ |69 | EX_UNAVAILABLE | | | | | | +-------------------+--------------------+---------------------------------------------+ |70 | EX_SOFTWARE | | | | | | +-------------------+--------------------+---------------------------------------------+ |71 | EX_OSERR | | | | | ( | | | | (fork)) | +-------------------+--------------------+---------------------------------------------+ |72 | EX_OSFILE | | | | | | +-------------------+--------------------+---------------------------------------------+ |73 | EX_CANTCREAT | | | | | | | | | () | +-------------------+--------------------+---------------------------------------------+ |74 | EX_IOERR | | | | | / | +-------------------+--------------------+---------------------------------------------+ |75 | EX_TEMPFAIL | | | | | | | | | | +-------------------+--------------------+---------------------------------------------+ |76 | EX_PROTOCOL | | | | | | +-------------------+--------------------+---------------------------------------------+ |77 | EX_NOPERM | | +-------------------+--------------------+---------------------------------------------+ |78 | EX_CONFIG | | +-------------------+--------------------+---------------------------------------------+ 9. $MONITOR_* myfailer.service OnFailure=. [Unit] Description=Service which can trigger an OnFailure= dependency OnFailure=myhandler.service [Service] ExecStart=/bin/myprogram mysuccess.service OnSuccess=. [Unit] Description=Service which can trigger an OnSuccess= dependency OnSuccess=myhandler.service [Service] ExecStart=/bin/mysecondprogram myhandler.service . [Unit] Description=Acts on service failing or succeeding [Service] ExecStart=/bin/bash -c "echo $MONITOR_SERVICE_RESULT $MONITOR_EXIT_CODE $MONITOR_EXIT_STATUS $MONITOR_INVOCATION_ID $MONITOR_UNIT" myfailer.service myhandler.service : MONITOR_SERVICE_RESULT=exit-code MONITOR_EXIT_CODE=exited MONITOR_EXIT_STATUS=1 MONITOR_INVOCATION_ID=cc8fdc149b2b4ca698d4f259f4054236 MONITOR_UNIT=myfailer.service mysuccess.service myhandler.service : MONITOR_SERVICE_RESULT=success MONITOR_EXIT_CODE=exited MONITOR_EXIT_STATUS=0 MONITOR_INVOCATION_ID=6ab9af147b8c4a3ebe36e7a5f8611697 MONITOR_UNIT=mysuccess.service systemd(1) systemctl(1) systemd-analyze(1) journalctl(1) systemd-system.conf(5) systemd.unit(5) systemd.service(5) systemd.socket(5) systemd.swap(5) systemd.mount(5) systemd.kill(5) systemd.resource-control(5) systemd.time(7) systemd.directives(7) tmpfiles.d(5) exec(3) fork(2) 1. UAPI.2 https://uapi-group.org/specifications/specs/discoverable_partitions_specification 2. polkit https://www.freedesktop.org/software/polkit/docs/latest/ 3. /proc https://docs.kernel.org/filesystems/proc.html#mount-options 4. / https://systemd.io/USER_NAMES 5. https://systemd.io/PASSWORD_AGENTS 6. https://docs.kernel.org/userspace-api/no_new_privs.html 7. JSON https://systemd.io/USER_RECORD 8. /proc https://docs.kernel.org/filesystems/proc.html 9. (id-mapped mounts) https://lwn.net/Articles/896255/ 10. quotactl https://man7.org/linux/man-pages/man2/quotactl.2.html 11. quotaon. https://linux.die.net/man/8/quotaon 12. repquota https://man7.org/linux/man-pages/man8/repquota.8.html 13. (Kernel Samepage Merging) https://docs.kernel.org/admin-guide/mm/ksm.html 14. https://docs.kernel.org/admin-guide/mm/transhuge.html 15. LWN https://lwn.net/Articles/947173/ 16. https://www.unicode.org/glossary/#unicode_scalar_value 17. https://www.unicode.org/glossary/#noncharacter 18. https://www.unicode.org/glossary/#byte_order_mark 19. POSIX https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_01 20. POSIX https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_02 21. POSIX https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_03 22. Base64 https://tools.ietf.org/html/rfc2045#section-6.8 23. https://systemd.io/CONTAINER_INTERFACE 24. DMI/SMBIOS https://www.dmtf.org/standards/smbios 25. qemu https://www.qemu.org/docs/master/system/index.html 26. https://systemd.io/CREDENTIALS 27. https://systemd.io/MEMORY_PRESSURE 28. LSB https://refspecs.linuxbase.org/LSB_5.0.0/LSB-Core-generic/LSB-Core-generic/iniscrptact.html 3 . . : . systemd 260.2 SYSTEMD.EXEC(5)