Version 252 of systemd, as expected, locks down the Linux boot process
- Reference: 1667475307
- News link: https://www.theregister.co.uk/2022/11/03/version_252_systemd/
- Source link:
The 113th version has the usual long feature list of very specific, targeted elements outlined in the [1]release announcement. However, as one might expect following recent events, several of the headline features relate to [2]the new UKI fully signed boot process .
UKI is short for "Unified Kernel Image" and combines the Linux kernel and initrd into a single file, along with some other smaller components, allowing the whole thing to be cryptographically signed. The purpose is to tighten up security on the Linux boot process.
[3]
This version also has new functions and modules concerned with manipulating the Platform Configuration Registers (PCRs) of Trusted Platform Module 2.0 chips – as also [4]favored by VMware as well as [5]Windows Server and Windows 11, [6]unless you use Rufus or other tools to turn this off.
[7]
[8]
The enhanced TPM2 support will enable linking a drive's encryption keys to the keys held in compatible firmware so that an encrypted disk can be unlocked automatically during boot – but can't be unlocked by other distros. The result will be improved security for users, especially corporate users, but we foresee this hindering data-recovery efforts.
There is improved support for picking up data from the hypervisor while VMs are starting, as well as for booting RISC-V machines. The [9]systemd-boot module now supports starting a 64-bit kernel on 32-bit UEFI, which may help owners of older Intel Macs. Some early models, no longer supported by macOS, make it very tricky to run Linux. Not many distros use this, though. So far, The Reg FOSS desk has only seen it in Pop!_OS.
[10]Microsoft's Lennart Poettering proposes tightening up Linux boot process
[11]OpenBSD 7.2: The other other FOSS xNix released, runs on Apple M2 Macs
[12]Ubuntu 22.10 is out, with an extra remix in the family: Unity
[13]Red Hat backs CNCF project, spills TEE support over Kubernetes
A new feature that will upset some but we feel could prove useful is detecting when the OS passes its end-of-life date then sets a "taint" flag called support-ended . The date is picked up from a new field in the /etc/os-release file.
The systemd project is now mature enough that old functionality is getting deprecated and removed. Support for version 1 of the cgroups feature, [14]originally donated by Google , will be removed soon, and apps must move to cgroups 2, which [15]appeared in 2016 . Support for unmerged /usr folders, [16]as The Reg described when Debian adopted it , is also going away. Both are anticipated to be removed by the end of 2023.
[17]
Although Ubuntu's second release of the year has come and gone, there's a small chance that version 252 might still make it into Fedora 37, which has been [18]delayed several weeks due to an [19]OpenSSL security issue which turned out to be a damp squib . If not, this version will be in the spring releases of both Ubuntu and Fedora, as well as Debian 12. ®
Bootnote
This is actually the 113th release of systemd because when the project merged in the [20]udev tool in 2012, its maintainers bumped the version number directly from [21]44 to 183 in order to match the version number of udev.
Far be it from us to suggest that anyone would bump a version number, say, to make it look more mature and trustworthy.
Get our [22]Tech Resources
[1] https://github.com/systemd/systemd/releases/tag/v252
[2] https://www.theregister.com/2022/10/26/tightening_linux_boot_process_microsoft_poettering/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2PzrM0IAyEyYxhyQiZ4zwAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2021/02/11/new_vsphere_7_security_guidance/
[5] https://www.theregister.com/2020/06/15/windows_server_hardware_security/
[6] https://www.theregister.com/2022/07/04/rufus_explorerpatcher_windows_11/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2PzrM0IAyEyYxhyQiZ4zwAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2PzrM0IAyEyYxhyQiZ4zwAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.freedesktop.org/software/systemd/man/systemd-boot.html
[10] https://www.theregister.com/2022/10/26/tightening_linux_boot_process_microsoft_poettering/
[11] https://www.theregister.com/2022/10/21/openbsd_72_released/
[12] https://www.theregister.com/2022/10/20/ubuntu_2210_kinetic_kudu/
[13] https://www.theregister.com/2022/10/10/confidential_containers_encrypted_k8s/
[14] https://www.theregister.com/2014/05/23/google_containerization_two_billion/
[15] https://www.theregister.com/2016/07/05/containers_state_of_the_art/
[16] https://www.theregister.com/2016/11/24/debian_testing_merged_codeusrcode/
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2PzrM0IAyEyYxhyQiZ4zwAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[18] https://fedorapeople.org/groups/schedule/f-37/f-37-key-tasks.html
[19] https://www.theregister.com/2022/11/01/openssl_downgrades_bugs/
[20] https://wiki.archlinux.org/title/udev
[21] https://lwn.net/Articles/499480/
[22] https://whitepapers.theregister.com/
Re: For a second....
We all have that dream.
Re: we can dream
As another commentator regarding Linux noted, it is amazing how much systemd is "hated" yet how prevalent it is in the Linux distro world.
So the hatred seems to be on the users because the devs of the distros seem to love the thing.
Therefore it is reasonable to believe that systemd solves more problems than it brings to the distro builders, but conversely if systemd is that "bad", or that hated by the user community, why don't the devs listen to the users instead?? Apparently there is a level of disconnect between user's desires on an OS that promises user choice, versus what you are actually given - and one must wonder why .
Re: we can dream
People hate changes unless they are the ones making the change.
Re: we can dream
What I dislike about systemd is that it gets it tendrils even into stuff that is separate from any "init process" stuff. It now controls everything, network, even sound (and don't get me started on pulseaudio...).
OK, and that I dislike change for the sake of it (yes, I get some of the motivation behing systemd, but seriously, telling me that simple human readable scripts are less easy to maintain and use than this - pull one of the others, this one has bells on it)
Re: we can dream
As someone once noted, systemd was never intended to be solely a replacement for init.
That was just the pretext the camel used to get its nose in the tent.
Re: For a second....
I don't think Liam's mother-tongue is American English. I wish the changed house style were changed to allow article authors to use the English they are most comfortable in, so American authors use an American idiom, Australians Australian, Indians Indian, and Irish Irish, and so on.
My first thought was questioning what ' [1]The Fall ' had to do with systemd. Their cover version of systemd would be interesting.
[1] https://en.wikipedia.org/wiki/The_Fall_(band)
Re: For a second....
Or maybe even SYSTEM of a Down
Re: For a second....
Its a good example why not to standardise on American English: "fall" confuses the rest of us while Americans would know perfectly well what is meant by "autumn".
User unambiguous words wherever possible. Avoid ambiguous ones.
Re: For a second....
There are publishers who do this. Of course, in Norway, there are even two written languages, so I am used to reading articles in both bokmaal and nynorsk (but I was more referring to Lost Art Press, who publish the books in the native idiom (American, British, ..) of the author.
Re: For a second....
"Fall" might be thought of as American English but its actually a regional word. On the west coast you're more likely to find the word "Autumn": used (its also closer to the Spanish word "Otono").
Most of the time if you use a certain amount of imagination you can figure these things out.
Re: For a second....
I misread fall as fail... which only reflects on what I think of systemd.
Re: For a second....
All of which would have been avoided if proper Englishg was used rther than Yankie slang.
Free as in Freedom
How does all that cryptographic stuff relate to the ability to compile your own? Do we get to approve our personal key? Or have they [1]tivoized the whole thing?
For myself I can't be arsed with all that, but having the option is still essential.
[1] https://en.wikipedia.org/wiki/Tivoization
Re: Free as in Freedom
That's the one thing I'm certain they won't be able to fuck up.
Dual-boot, anybody?
How does this magic new lockdown deal with dual-boot systems?
How far does Poettering have to go before he starts upsetting his disciples with stuff that sticks even in their throats?
Re: Dual-boot, anybody?
Why should dual-boot break if the keys for both kernels are enrolled in the TPM / secure boot keystore / wherever?
Re: Dual-boot, anybody?
Why dual boot when you can use one or more VMs?
Re: Dual-boot, anybody?
The most pressing reason to dual-boot is that the user wants to use the full bare-metal capabilities of the hardware. At a previous job, I dual-booted my work laptop because I wanted a OS running on my system which was for personal use and unconstrained by corporate IT, and said constraints were restrictive to virtual machine usage. Some people might be driver developers who need access to the hardware for testing their code. Etc. Those are just some use cases which spring immediately to mind; I'm sure other commentards can suggest others.
I'm so happy
Finally the promise of the future is here. I'm so happy this is at long last available. Everything will be nicely locked to two or three hardware vendors, a nice OS duo- or triopoly, all the AMZN content at our fingertips, bots are going to be filtered out, no more captchas - remote attestation from a approved edge providers through approved carriers and approved last mile providers through approved and signed OS and one true good browser right to the CPU core, where the digital signature will live right next to the reliable and secure out of band management system and then back again, everything signed and secure and reliable (apart from the signed and approved backdoors for secure and relieable and accountable government agencies).
I'm sure corporate Windows users are going to love this! Wait...
Re: I'm so happy
It isn't the secure-boot system itself, but how it's implemented.
You can have a dystopian system like that, but you can also have a system where you trust nothing but your own personal signing key* and have *that* sign things downstream.
____
* your key, your certification authority, OpenSSL, your standard C library, the OS, the computer generating the key, the hardware manufacturer, and the country that said hardware manufacturer comes from. Also see the famous Reflections on Trusting Trust essay/talk.
Re: I'm so happy
Of course, I can even get the whole world under lock and key, by putting myself in the cage.
What I was pointing at is the Wintel creep and where it's headed with systemd.
My personal belief is there will always be token plurality available, just like with Firefox, which reportedly lives mostly off Google's money. It appears to be cheaper than monopoly lawsuits of the Microsoft Internet Explorer fashion.
Re: I'm so happy
What I was pointing at is the Wintel creep
Well, that's one name for Lennart Poettering.
Re: I'm so happy
to read the essay:
https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf
I spend my days, when not coding, having to administer a fleet of Windows laptops.
There are a number of Dell laptops that tend to suffer TPM failures, rendering the OS useless. Especially as we march towards Windows 11 where it requires at least TPM v1.2.
If the TPM fails, it's fucked. The laptop is scrap essentially if you need to run Bitlocker or any sort of encryption on the disk.
Now we're trundling in to a Poettering world where we're having this shit enforced on us? Only those who have not had to deal with the delight of a dead TPM on a laptop would ever think this implementation is a good idea.
-> Now we're trundling in to a Poettering world where we're having this shit enforced on us?
You can always fork it. Nobody is forcing you to use a vendor-supplied kernel.
As I have mentioned several times previously, the top contributors to the Linux kernel are corporations. They pay people and those people put in what they want to put in or what they are told to put in.
Linux today is not the Linux of 20 years ago. Sure, anyone can make a new distro with this feature and that feature. They generally don't last long.
Sure, anyone can make a new distro with this feature and that feature. They generally don't last long.
EL Reg normally gives us two or three starry-eyed reviews of Ubuntu remixes each week. It would be interesting to know how many of them ever make it to a second version. It might happen sometimes, I suppose.
Mint still doing well, thank you!
Personal preference remains with Manjaro; though I await the project's reception of these systemd growths. (I'm not going to call them changes, because that is disingenuous).
So, you can fork it, but it's pointless and naive...?
That is the Linux way. We are told time and time again that if we don't like something we can take the source code, fork it, and build our own version. Extending that for a moment to distros, that is why there are so many distros. Some distros last far longer than others, others are built to specifically not have a particular subsystem (eg Devuan).
What we seem to have, what I see a lot of, is quite a few Linux people thinking they can influence the way Linux should be - it should not have systemd or it should not have a secure boot feature, for example. All they have to do is pick a distro which meets their criteria and use it, or if it does not exist they can build it. Open source does not mean you have control over what somebody else does, yet that seems to be how some people think it is.
So, you wrote that forking is "pointless and naive". In some cases, with the plethora of distros adding one more Ubuntu remix with marginally different bells and whistles, I think it is pointless. But in general? You seem to be turning the open source world on its head.
Edit: For the record I have expressed several times my dislike for systemd in general and its tentacles. This is just another tentacle.
"If the TPM fails, it's fucked. The laptop is scrap essentially if you need to run Bitlocker or any sort of encryption on the disk."
Aren't there ways to backup the bitlocker encryption key to an external location?
There are. You have the option to print them off and keep them in a secure safe somewhere, or you can use a 3rd party application such as Sophos.
Except, in my experience, there have been times the latter doesn't work. I've had 3 laptops require access to the bitlocker key and in those 3 instances the key Sophos listed didn't unlock the laptop.
Experience of the former is that, while it's more rudimentary, the key can sometimes not work either.
This is the best advertisment
for either
Devuan (see https://distrowatch.com/table.php?distribution=devuan )
or
MX linux (see https://distrowatch.com/table.php?distribution=mx )
Been on Ubuntu since Warty, I feel I've been ejected/rejected...
Re: This is the best advertisment
Don't forget PCLinuxOS or Slackware.
Texstar and Patrick Volkerding know what they are doing and will have nothing to do with systemd.
Re: This is the best advertisment
Also Void, Gobo, Guix, Alipne, Gentoo, Artix and others:
BSDs are another option.
https://nosystemd.org/ has a partial list
Re: This is the best advertisment
I somehow lost a tiny bit of trust in Debian for not being on this list.
Re: This is the best advertisment
+1 (Devuan here - although used Slackware exclusively until had to switch to RHEL6 for work...)
Systemd or not....
It doesn't really matter... seriously...
Life is too short.......
Boot security
That's nice. But why does it have to be lumped into the same package with the init subsystem, networking, audio, kernel logging, user home directory mounting and the kitchen sink?
Have I forgotten anything.
For a second....
I misread the first line as "The fall of systemd is here" but alas, not today it seems...