News: 1676647811

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

systemd 253: You're looking at the future of enterprise Linux boot processes

(2023/02/17)


The first systemd release of 2023 is here, and it introduces a brand spanking new tool for building Unified Kernel Image (UKI) files.

Fresh versions of systemd appear roughly twice a year, apart from release candidates. We reported on the last version, [1]systemd 252, in November last year . As we said at the time, systemd 252 brought in support for Agent P's [2]new, more secure Linux boot process . Those two stories have details of the UKI boot files and how they work.

The support and tooling for UKI continues to improve, and one of the headline features in [3]version 253 is a tool for building these unified kernel images , which is called ukify . As the systemd release notes say:

A tool ukify tool to build, measure, and sign Unified Kernel Images (UKIs) has been added. This replaces functionality provided by dracut --uefi and extends it […]

From the new program's [4]manual page :

Note: this command is experimental for now. While it is intended to become a regular component of systemd, it might still change in behaviour and interface.

Like it or not, it certainly seems likely that UKIs will become the standard way to start many enterprise Linux distros, if only because of their support for automatically unlocking drives using Full Disk Encryption (FDE) by retrieving keys from the machines' integrated TPM2 chips. Three of the last four new laptops that have landed on The Reg FOSS desk came with Windows' Bitlocker FDE turned on by default. (The only one that didn't was [5]Tuxedo Computers' Stellaris gen 4 , a gaming laptop with a multicolor illuminated mechanical keyboard. As a machine intended to run Linux, that's not really a surprise.)

Many users might never even notice it, unless they try to dual-boot the computer with a non-Windows OS and find that nothing else can read the disk. Never fear: we have [6]described how to turn it off and make such a machine ready to dual-boot .

[7]

There are of course lots of other changes, but they should be less visible to most people. There's a new option to limit the amount of memory assigned to the compression pool if you use zswap swap area compression, a feature [8]added to "Linux for Workgroups", AKA kernel 3.11 way back in 2013. We [9]suggested enabling this last year as a way to improve the performance of desktops or laptops with limited RAM, and it can help quite a lot, but the price of reduced swap usage is increased CPU strain and the need for a block of memory for the compressed cache.

[10]Ubuntu Advantage is being wired deeper into the distro

[11]There's no place like... KDE: Plasma 5.27 is out and GNOME 44 hits beta

[12]The quest to make Linux bulletproof

[13]Make Linux safer… or die trying

As [14]described in some kernel patches last year, zswap is a complicated tool and its interactions on a system running lots of cgroup2 containers is not easy to [15]debug .

Tweaks to the [16]systemd OOM killer suggest that this is still causing issues, as it did [17]even back in Fedora 33 , which is why [18]Linux Mint 21 disabled it altogether .

[19]

The systemd-boot tool, which is used in [20]Pop!_OS and caused us grief , now supports other ways of loading the kernel in the Xen hypervisor and QEMU hypervisor/emulator, such as from locations other than the UEFI ESP.

Handling of several file system issues has been improved. If systemd finds a swap volume with a different page size to the one that system needs, it will automatically reformat it, and it has better handling of an initrd that isn't a pure RAMdisk, such as an overlayfs . There's also direct support for a technology we'd not met before: [21]HS SRE , or to give it its full name, Lockheed-Martin Hardened Security for Intel processors .

[22]

Many won't like it, but expect systemd 253 to appear in the next version of most mainstream distros. If that thought is too much to bear, there are still a decent [23]selection of distros that don't have it. ®

Get our [24]Tech Resources



[1] https://www.theregister.com/2022/11/03/version_252_systemd/

[2] https://www.theregister.com/2022/10/26/tightening_linux_boot_process_microsoft_poettering/

[3] https://github.com/systemd/systemd/releases/tag/v253

[4] https://www.freedesktop.org/software/systemd/man/ukify.html

[5] https://www.theregister.com/2022/11/08/tuxedo_stellaris_amd_gen_4/

[6] https://www.theregister.com/2022/07/22/linux_nonapproved_laptop

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y@@ysezfCHtUhQINr67PTgAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[8] https://www.theregister.com/2013/07/15/linux_for_workgroups/

[9] https://www.theregister.com/2022/07/18/improve_linux_performance/

[10] https://www.theregister.com/2023/02/17/ubuntu_advantage/

[11] https://www.theregister.com/2023/02/16/kde_plasma_527_gnome_44/

[12] https://www.theregister.com/2023/02/16/bulletproof_linux/

[13] https://www.theregister.com/2023/02/14/make_linux_safer_p1/

[14] https://lore.kernel.org/lkml/20220510152847.230957-1-hannes@cmpxchg.org/T/

[15] https://lore.kernel.org/lkml/20220510152847.230957-7-hannes@cmpxchg.org/

[16] https://www.theregister.com/2021/04/01/systemd_248/

[17] https://www.theregister.com/2020/10/02/fedora_33_beta/

[18] https://www.theregister.com/2022/07/14/mint_21_beta/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@@ysezfCHtUhQINr67PTgAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[20] https://www.theregister.com/2021/12/16/pop_os_2110_new_system76/

[21] https://www.lockheedmartin.com/en-us/products/hardened-security-for-intel-processors.html

[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@@ysezfCHtUhQINr67PTgAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[23] https://itsfoss.com/systemd-free-distros/

[24] https://whitepapers.theregister.com/



systemd 253: You're looking at the future of enterprise Linux boot processes

TVU

I'm not sure I like that scenario and I'd much prefer to see systemd 451 that automatically replaces itself with sysVinit and then self combusts in flames never to be seen again.

I wrote previously that systemd will become a layer on top of the kernel

VoiceOfTruth

Now it will be building that kernel too.

I do wish systemd would just fuck off

Dizzy Dwarf

Way to ruin the weekend. Thanks for that.

Re: I do wish systemd would just fuck off

GrumpenKraut

Dear systemd

Fuck off.

Then keep fucking off.

Fuck off until you come up to a gate with a sign saying "You Can't Fuck Off Past Here".

Climb over the gate, dream the impossible dream, and keep fucking off forever.

This is perfect for a Friday story

Greg 38

The systemd haters haven't had their pot stirred in some time. Today is the day then, hurrah! I've off to get a pint and a packet of crisps while the thumbs down pile on. There needs be an icon for "old man yells at cloud".

Re: This is perfect for a Friday story

Will Godfrey

You're right, there should be.

There also should be an icon for "kids think they know better than their parents and have to learn the hard way".

so...?

Steve Davies 3

how does all this work with kernels built from you know those pesky things called sources?

If you must have a signed kernel then unless there is a workaround this move sounds the death knell for custom kernels.

"Linux poses a real challenge for those with a taste for late-night
hacking (and/or conversations with God)."
(By Matt Welsh)