SYSTEMD.EXEC(5) systemd.exec SYSTEMD.EXEC(5) (NAME) systemd.exec - systemd (SYNOPSIS) service.service, socket.socket, mount.mount, swap.swap (DESCRIPTION) (services) (sockets) (mount points) (swap devices) . . systemd.unit(5) systemd.service(5) systemd.socket(5) systemd.swap(5) systemd.mount(5) . [Service] [Socket] [Mount] [Swap] . (cgroups) systemd.resource-control(5) . . (IMPLICIT DEPENDENCIES) : o WorkingDirectory= RootDirectory= RootImage= RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= Requires= After= . RequiresMountsFor= . o PrivateTmp= /tmp/ /var/tmp/ . After= systemd-tmpfiles-setup.service(8) . o journal kmsg ( ) After= systemd-journald.socket . o LogNamespace= systemd-journald@.service . (PATHS) . ".." . ExecSearchPath= Exec*= ( ExecStart= ExecStop= ) . ExecSearchPath= /home/debian/.cargo/bin:/home/debian/.local/bin:/home/debian/.local/bin:/usr/local/bin:/home/debian/.cargo/bin:/home/debian/.local/bin:/mnt/data/mahdidev/ollama/bin/bin:/home/debian/.deno/bin:/home/debian/.npm- global/bin:/home/debian/.local/bin:/home/debian/.cargo/bin:/home/debian/.local/bin:/usr/bin:/bin:/usr/games:/usr/local/games /home/debian/.cargo/bin:/home/debian/.local/bin:/home/debian/.local/bin:/usr/local/bin:/home/debian/.cargo/bin:/home/debian/.local/bin:/mnt/data/mahdidev/ollama/bin/bin:/home/debian/.deno/bin:/home/debian/.npm- global/bin:/home/debian/.local/bin:/home/debian/.cargo/bin:/home/debian/.local/bin:/usr/bin:/bin:/usr/games:/usr/local/games Environment= EnvironmentFile= PassEnvironment= . ExecSearchPath= . 250. WorkingDirectory= RootDirectory= "~" . . "~" User= . systemd . "-" . RootDirectory=/RootImage= WorkingDirectory= . ( ). RootDirectory= ( ) . pivot_root(2) chroot(2) . . ( ). MountAPIVFS= PrivateUsers= RootDirectory= . . RootDirectory=/RootImage= NotifyAccess= (mount) . RootDirectory=/RootImage= syslog journal : os-release(5) ( ) /run/host/os-release . (soft reboot : systemd- soft-reboot.service(8)) . 1. BindReadOnlyPaths=/dev/log /run/systemd/journal/socket /run/systemd/journal/stdout ".v/" systemd.v(7) . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). RootImage= . RootDirectory= loopback (mount) . MBR/MS-DOS GPT GPT Discoverable Partitions Specification[1] . DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow= . DevicePolicy= DeviceAllow= systemd.resource-control(5) . PrivateDevices= DevicePolicy= . RootImage= After= systemd-udevd.service . os-release(5) ( ) /run/host/os-release . (soft reboot : systemd-soft- reboot.service(8)) . ".v/" systemd.v(7) . - . 233. RootImageOptions= (mount options) RootImage= . "root" . . . . mount(8) . Discoverable Partitions Specification[1] : root usr home srv esp xbootldr tmp var. - . 247. RootEphemeral= . (ephemeral) . /var/lib/systemd/ephemeral-trees/ . RootDirectory= (subvolume) (snapshot) . /var/lib/systemd/ephemeral-trees/ . RootEphemeral= btrfs(5) systemd snapshot . reflink . - . 254. RootHash= (dm-verity) ASCII . dm-verity ( ) RootVerity= . 256 ( 64 ) ( SHA256). "user.verity.roothash" ( xattr(7) ) . ( ) .roothash ( .raw ) . /usr/ Verity "user.verity.usrhash" .usrhash . /usr/ . - . 246. RootHashSignature= PKCS7 RootHash= DER base64 DER "base64:" . dm-verity (keyring) . .roothash.p7s ( .raw ) . /usr/ Verity .usrhash.p7s . /usr/ . - . 246. RootVerity= (dm-verity) . dm-verity RootImage= . . .verity ( .raw verity ) verity . . GPT Verity Discoverable Partitions Specification[1] . - . 246. RootImagePolicy= MountImagePolicy= ExtensionImagePolicy= systemd.image-policy(7) (DDI) RootImage= MountImage= ExtensionImage= . RootImagePolicy= MountImagePolicy= : root=verity+signed+encrypted+unprotected+absent: \ usr=verity+signed+encrypted+unprotected+absent: \ home=encrypted+unprotected+absent: \ srv=encrypted+unprotected+absent: \ tmp=encrypted+unprotected+absent: \ var=encrypted+unprotected+absent ExtensionImagePolicy= : root=verity+signed+encrypted+unprotected+absent: \ usr=verity+signed+encrypted+unprotected+absent 254. MountAPIVFS= . (mount namespace) API /proc/ /sys/ /dev/ /run/ ( "tmpfs" ) . RootDirectory=/RootImage= 1:1 . PrivateDevices= /dev/ bind . /dev/ PrivateDevices= . /run/systemd/propagate/ /run/host/incoming/ . 233. BindLogSockets= . systemd- journald.socket(8) bind mount . /run/ sd-journal(3) . LogNamespace= MountAPIVFS=yes PrivateDevices=yes RootDirectory= RootImage= . 257. ProtectProc= "noaccess" "invisible" "ptraceable" "default" ( ) . "hidepid=" "procfs" (/proc/PID) : "noaccess" /proc/ . "invisible" /proc/ . "ptraceable" ptrace() . "default" /proc/ . The /proc Filesystem[2] . "invisible" . . root User= DynamicUser=yes "CAP_SYS_PTRACE" . . MountAPIVFS= . hidepid= . - . 247. ProcSubset= "all" () "pid" . "pid" /proc/ . "subset=" "procfs" . The /proc Filesystem[2] . API /proc/ . API . ProtectProc= : MountAPIVFS= . ProtectProc= "subset=" "procfs" . 247. BindPaths= BindReadOnlyPaths= bind . bind . bind . bind . . . "rbind" "norbind" bind . . bind "-" . BindPaths= bind ( ) BindReadOnlyPaths= bind . bind . bind . bind . PrivateMounts= ( ). RootDirectory=/RootImage= . . systemd . InaccessiblePaths= /home/ ProtectHome=yes . TemporaryFileSystem= ":ro" ProtectHome=tmpfs . 233. MountImages= RootImage= loopback . . . . RootImageOptions= . "-" . . ":" "\:" (escape) . RootImage= . . . . systemd . InaccessiblePaths= /home/ ProtectHome=yes . DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow= . DevicePolicy= DeviceAllow= systemd.resource-control(5) . PrivateDevices= DevicePolicy= . - . 247. ExtensionImages= MountImages= loopback (overlay) . . . OverlayFS /usr/ /opt/ sysext /etc/ confext . overlay : overlayfs . . RootImageOptions= . "-" . . ":" "\:" . RootImage= . . . . sysext /usr/lib/extension-release.d/extension-release.IMAGE confext /etc/extension-release.d/extension-release.IMAGE RootImage=/RootDirectory= . : os-release(5). extension-release x-systemd.relax-extension-release-check . DevicePolicy= "closed" "strict" "auto" DeviceAllow= /dev/loop-control rw "block-loop" "block-blkext" rwm DeviceAllow= . DevicePolicy= DeviceAllow= systemd.resource-control(5) . PrivateDevices= DevicePolicy= . ".v/" systemd.v(7) . - . 248. ExtensionDirectories= BindReadOnlyPaths= (overlay) . . OverlayFS /usr/ /opt/ sysext /etc/ confext . overlay : overlayfs . ExtensionDirectories= "-" . . . . sysext /usr/lib/extension-release.d/extension-release.IMAGE confext /etc/extension-release.d/extension-release.IMAGE RootImage=/RootDirectory= . : os-release(5). overlayfs 5.11 . ".v/" systemd.v(7) . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 251. / (USER/GROUP IDENTITY) - . User= Group= (UNIX) . (ID) . ( PID 1 ) root ( root systemd --user) "root" User= . . . "+" . / / : a-z A-Z 0-9 "_" "-" a-z A-Z "_" ( "-" ). / . / . User/Group Name Syntax[3] . DynamicUser= / -- ( ). DynamicUser= sysusers.d(5) . . User= (supplementary groups) . SupplementaryGroups= ( ). DynamicUser= . (UNIX) . /etc/passwd /etc/group . glibc NSS nss-systemd(8) / . User= Group= ( ). / / . . / . User= . Group= . / UID/GID 61184 65519 . . UID/GID / . UID/GID . / / UID/GID . DynamicUser= RemoveIPC= ( ). IPC / . /tmp/ /var/tmp/ PrivateTmp= "true" "disconnected" . / . NoNewPrivileges= RestrictSUIDSGID= ( ) SUID/SGID . ProtectSystem=strict ProtectHome=read-only . ReadWritePaths= UID/GID . RuntimeDirectory= ( ) / . StateDirectory= CacheDirectory= LogsDirectory= UID ( ). . BindPaths= AF_UNIX / . D-Bus D-Bus ( D-Bus ). (off) . 232. SupplementaryGroups= (Unix) . . . . . "+" . SetLoginEnvironment= /home/debian debian /usr/bin/zsh . User= DynamicUser= PAMName= true false . true "root" . false User= DynamicUser= PAMName= . - . 255. PAMName= PAM (session) . PAM . User= . PAM . pam(8) . PAM PAM . "(sd-pam)" . ( PAM) (session scope unit) . : ( PAMName= ) . . NotifyAccess=all . . PAMName= NotifyAccess=all . (CAPABILITIES) - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). CapabilityBoundingSet= (bounding set) . capabilities(7) . CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE. . "~" . (effective) (permitted) (inheritable) . . OR ( "~" AND) ( ). . "~" ( ) . "+" . capability systemd-analyze(1) . : : CapabilityBoundingSet=CAP_A CAP_B CapabilityBoundingSet=CAP_B CAP_C CAP_A CAP_B CAP_C . "~" : CapabilityBoundingSet=CAP_A CAP_B CapabilityBoundingSet=~CAP_B CAP_C CAP_A . AmbientCapabilities= (ambient capabilities) . CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE. ( CapabilityBoundingSet= ). "~" . . "~" ( ) . . . keep-caps SecureBits= . AmbientCapabilities= "+" . 229. (SECURITY) NoNewPrivileges= . true execve() ( setuid setgid ). . false . SELinux MS_NOSUID . No New Privileges Flag[4] . ( ) . at(1) crontab(1) systemd-run(1) IPC . 187. SecureBits= (secure bits) . : keep-caps keep-caps-locked no-setuid-fixup no-setuid-fixup-locked noroot noroot-locked. OR . 0 . "+" . capabilities(7) . (MANDATORY ACCESS CONTROL) SELinuxContext= (security context) SELinux . (automated domain transition) . . SELinux . "-" SELinux execve() . "+" . setexeccon(3) . 209. AppArmorProfile= (profile) . . . "-" . AppArmor . "+" . - . 210. SmackProcessLabel= SMACK64 . SMACK . SMACK64EXEC . systemd . SMACK . "-" . . "+" . - . 218. (PROCESS PROPERTIES) LimitCPU= LimitFSIZE= LimitDATA= LimitSTACK= LimitCORE= LimitRSS= LimitNOFILE= LimitAS= LimitNPROC= LimitMEMLOCK= LimitLOCKS= LimitSIGPENDING= LimitMSGQUEUE= LimitNICE= LimitRTPRIO= LimitRTTIME= (soft) (hard) . setrlimit(2) . : soft:hard ( "LimitAS=4G:16G"). infinity . K M G T P E ( 1024) ( "LimitAS=16G"). ms s min h ( systemd.time(7) ). LimitCPU= LimitRTTIME= . (granularity) . LimitCPU= 1s . LimitNICE= : "+" "-" nice -20 19 . 0 40 ( 0 1 ) . (fork) . LimitRSS= . systemd.resource-control(5) . MemoryMax= ( ) LimitRSS= . LimitNPROC= UID () (fork ) . UID . root ( ) LimitNPROC= . TasksMax= ( systemd.resource-control(5) ) LimitNPROC= . DefaultLimitCPU= DefaultLimitFSIZE= systemd- system.conf(5) - - - ( ). . ( - ) . . . PAM user@.service . . 1. ulimit +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ | | | | | | | ulimit | | | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitCPU= | ulimit -t | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitFSIZE= | ulimit -f | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitDATA= | ulimit -d | | . | | | | | | | | | | | | | | | | | | | | ! | | | | | | | | | | | | | | | . | | | | | | | | | | MemoryMax= | | | | | systemd.resource-control(5) | | | | | . | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitSTACK= | ulimit -s | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitCORE= | ulimit -c | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitRSS= | ulimit -m | | . | | | | | | | | | | . | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitNOFILE= | ulimit -n | | . | | | | | | | | | | | | | | | 1024 | | | | | select(2) | | | | | | | | | | | | | | | 1023 | | | | | . | | | | | | | | | | | | | | | 524288 | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | 1023 | | | | | | | | | | ( | | | | | select(2) | | | | | ) | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | MemoryMax= | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitAS= | ulimit -v | | . | | | | | | | | | | | | | | | | | | | | ! | | | | | | | | | | | | | | | . | | | | | | | | | | MemoryMax= | | | | | systemd.resource-control(5) | | | | | . | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitNPROC= | ulimit -u | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | TasksMax= | | | | | | | | | | systemd.resource-control(5) | | | | | . | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitMEMLOCK= | ulimit -l | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitLOCKS= | ulimit -x | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitSIGPENDING= | ulimit -i | | - | | | | | | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitMSGQUEUE= | ulimit -q | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitNICE= | ulimit -e | Nice | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitRTPRIO= | ulimit -r | | - | | | | | | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ |LimitRTTIME= | ulimit -R | | - | +-------------------------------+-----------------+-----------------------------------------------+-----------------------------------------------+ UMask= (umask) . (octal) . umask(2) . 0022 . - ( 0022 -- PAM ). umask - UMask= user@.service . umask umask JSON User Record[5] ( systemd- homed.service(8) homectl --umask= ). PAM pam_umask(8) . CoredumpFilter= (core dump) ( /proc/pid/coredump_filter). ( 16). : private-anonymous shared-anonymous private-file-backed shared-file-backed elf-headers private-huge shared-huge private-dax shared-dax all ( ) default ( "private-anonymous shared-anonymous elf-headers private-huge"). core(5) . OR . . 2. DAX CoredumpFilter=default private-dax shared-dax 246. KeyringMode= (keyring) ( keyring session-keyring(7) ). inherit private shared . inherit . private . ( root) . shared private User= . . inherit (invocation ID ) "invocation_id" . private inherit . 235. OOMScoreAdjust= (OOM Killer) . -1000 ( OOM) 1000 ( ) . The /proc Filesystem[6] . OOM 0 . OOMPolicy= OOM systemd-oomd . systemd.service(5) . TimerSlackNSec= (timer slack) . . prctl(2) . . . Personality= uname(2) . arm64 arm64-be arm arm-be x86 x86-64 ppc ppc-le ppc64 ppc64-le s390 s390x . personality . personality . x86-64 personality x86-64 x86 . personality . personality personality . m68k ( ) alpha ( ) . 209. IgnoreSIGPIPE= . true SIGPIPE . true SIGPIPE (shell pipelines) . (SCHEDULING) Nice= nice ( ) . -20 ( ) 19 ( ) . . setpriority(2) . CPUSchedulingPolicy= CPU . other batch idle fifo rr . sched_setscheduler(2) . CPUSchedulingPriority= CPU . CPU ( ). (real-time) 1 ( ) 99 ( ) . CPU CPU . sched_setscheduler(2) . CPUSchedulingResetOnFork= . true CPU fork(2) . sched_setscheduler(2) . false . CPUAffinity= CPU ( CPU affinity) . CPU . "numa" systemd CPU NUMAMask= . CPU CPU . CPU . . sched_setaffinity(2) . NUMAPolicy= NUMA . : default preferred bind interleave local . NUMA NUMAMask= . set_mempolicy(2) . NUMA numa(7) . 243. NUMAMask= NUMA NUMA . NUMA CPU CPUAffinity= "all" NUMA . NUMA default local preferred NUMA . 243. IOSchedulingClass= I/O . realtime best-effort idle . best-effort 4 . IOSchedulingClass= IOSchedulingPriority= . ioprio_set(2) . IOSchedulingPriority= I/O . 0 ( ) 7 ( ) . I/O I/O . I/O ( ). IOSchedulingClass= IOSchedulingPriority= . (best-effort) 4 . ioprio_set(2) . (SANDBOXING) (sandboxing) . . . ProtectSystem= . RestrictRealtime= SECCOMP . ( - ) . ( ProtectSystem=) . PrivateUsers=true . ( ProtectSystem= ReadOnlyPaths= ) AF_UNIX . IPC . ProtectSystem= "full" "strict" . true /usr/ (/boot /efi) . "full" /etc/ . "strict" API /dev/ /proc/ /sys/ ( PrivateDevices= ProtectKernelTunables= ProtectControlGroups= ). ( ) . . ReadWritePaths= . StateDirectory= LogsDirectory= ( ) ProtectSystem= . DynamicUser= . . ReadOnlyPaths= . (off) . ProtectSystem= "strict" PrivateTmp= /tmp/ /var/tmp/ . 214. ProtectHome= "read-only" "tmpfs" . true /home/ /root /run/user . "read-only" . "tmpfs" . "tmpfs" BindPaths= BindReadOnlyPaths= . "yes" InaccessiblePaths= . "read-only" ReadOnlyPaths= "tmpfs" TemporaryFileSystem= ":ro" . ( ) . DynamicUser= . . ReadOnlyPaths= . . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 214. RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . ".." . ( ) . . (":") . DynamicUser= (id-mapped mounts)[7] "nobody" UID/GID ( ). . 2. +----------------------------+-----------------------+-----------------------+-----------------------------+ | | | | | | | | | | | | | | | | | | | | | | | | | +----------------------------+-----------------------+-----------------------+-----------------------------+ |RuntimeDirectory= | /run/ | /run/user/1000 | | +----------------------------+-----------------------+-----------------------+-----------------------------+ |StateDirectory= | /var/lib/ | | | +----------------------------+-----------------------+-----------------------+-----------------------------+ |CacheDirectory= | /var/cache/ | | | +----------------------------+-----------------------+-----------------------+-----------------------------+ |LogsDirectory= | /var/log/ | /log/ | | +----------------------------+-----------------------+-----------------------+-----------------------------+ |ConfigurationDirectory= | /etc/ | | | +----------------------------+-----------------------+-----------------------+-----------------------------+ RuntimeDirectory= . RuntimeDirectoryPreserve= restart yes ( ). StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . ConfigurationDirectory= User= Group= . . . RuntimeDirectoryMode= StateDirectoryMode= CacheDirectoryMode= LogsDirectoryMode= ConfigurationDirectoryMode= . BindPaths= . RootDirectory= RootImage= . DynamicUser= CacheDirectory= LogsDirectory= StateDirectory= : /var/cache/private /var/log/private /var/lib/private . (symlinks) . /var/cache /var/log /var/lib . RuntimeDirectory= . /run/ . tmpfiles.d(5) . RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ":" . (symlink) . BindPaths= TemporaryFileSystem= . . 257 ro . ConfigurationDirectory= . . : ConfigurationDirectory=foo::ro systemd (/var/ /run/ /etc/ ) . . tmpfiles.d(5) . tmpfiles.d . systemctl clean ... systemctl(1) . : : RuntimeDirectory=foo/bar baz /run/foo ( ) /run/foo/bar /run/baz . /run/foo/bar /run/baz /run/foo User= Group= . : : RuntimeDirectory=foo/bar StateDirectory=aaa/bbb ccc "RUNTIME_DIRECTORY" "/run/foo/bar" "STATE_DIRECTORY" "/var/lib/aaa/bbb:/var/lib/ccc" . : : RuntimeDirectory=foo:bar foo:baz /run/foo ( ) /run/bar /run/baz /run/foo . 211. RuntimeDirectoryMode= StateDirectoryMode= CacheDirectoryMode= LogsDirectoryMode= ConfigurationDirectoryMode= RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= (octal) . 0755 . Permissions path_resolution(7) . 234. RuntimeDirectoryPreserve= restart . no () RuntimeDirectory= . restart . Restart= systemctl restart foo.service . yes . /run/ "tmpfs" RuntimeDirectory= . 235. TimeoutCleanSec= systemctl clean ... systemctl(1) . infinity . . 244. ReadWritePaths= ReadOnlyPaths= InaccessiblePaths= ExecPaths= NoExecPaths= . . ( ) . RootDirectory=/RootImage= . ReadWritePaths= . ReadOnlyPaths= . ReadWritePaths= ReadOnlyPaths= . ProtectSystem=strict ReadWritePaths= . ReadWritePaths= (superblock) . . ReadWritePaths= . InaccessiblePaths= . ReadWritePaths= ReadOnlyPaths= BindPaths= BindReadOnlyPaths= . TemporaryFileSystem= . NoExecPaths= . ExecPaths= NoExecPaths= . . . . ReadWritePaths= ReadOnlyPaths= InaccessiblePaths= ExecPaths= NoExecPaths= "-" . "+" RootDirectory=/RootImage= ( ). "-" "+" "-" "+" . . . ReadWritePaths= ReadOnlyPaths= . ReadOnlyPaths= ! . . . CapabilityBoundingSet=~CAP_SYS_ADMIN SystemCallFilter=~@mount . API ( MountAPIVFS= ) . /run/ . : [Service] ReadOnlyPaths=/ ReadWritePaths=/var /run InaccessiblePaths=-/lost+found NoExecPaths=/ ExecPaths=/usr/sbin/my_daemon /usr/lib /usr/lib64 - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 231. TemporaryFileSystem= (tmpfs) . . . . (":") "size=10%" "ro" . "nodev,strictatime,mode=0755" . "dev" "nostrictatime" . BindPaths= BindReadOnlyPaths= : : : TemporaryFileSystem=/var:ro BindReadOnlyPaths=/var/lib/systemd /var/ /var/lib/systemd . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 238. PrivateTmp= "disconnected" . /tmp/ /var/tmp/ . "true" /tmp/ /var/tmp/ . "disconnected" tmpfs . false . /tmp/ /var/tmp/ . "disconnected" /tmp/ /var/tmp/ JoinsNamespaceOf= systemd.unit(5) . DynamicUser= . ReadOnlyPaths= . "true" ( "disconnected") Requires= After= /tmp/ /var/tmp/ . After= systemd-tmpfiles-setup.service(8) . ( ) . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). PrivateDevices= . true /dev/ API /dev/null /dev/zero /dev/random ( TTY) /dev/sda /dev/mem /dev/port . . false . I/O @raw-io CAP_MKNOD CAP_SYS_RAWIO DevicePolicy=closed ( systemd.resource-control(5) ). ( ). . /dev/ 'noexec' . mmap(2) /dev/zero MAP_ANON . ReadOnlyPaths= . ( ) . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). ( ) DeviceAllow= . systemd.resource-control(5) . 209. PrivateNetwork= . true loopback "lo" . . . false . JoinsNamespaceOf= systemd.unit(5) . AF_NETLINK AF_UNIX. AF_NETLINK systemd- udevd.service(8) . AF_UNIX AF_UNIX ( ). ( ) . PrivateMounts= /sys . (bind) . JoinsNamespaceOf= . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). NetworkNamespacePath= ( /proc//ns/net bind mount symlink ). . fork . PrivateNetwork= . JoinsNamespaceOf= PrivateNetwork= NetworkNamespacePath= . PrivateMounts= /sys . bind . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 242. PrivateIPC= . true IPC . IPC System V IPC POSIX . IPC . false . IPC JoinsNamespaceOf= systemd.unit(5) . IPC AF_UNIX IPC . AF_UNIX . IPC System V IPC ( ) POSIX ( AF_UNIX/SOCK_SEQPACKET ) . IPC POSIX ( ) . ipc_namespaces(7) . ( IPC ) . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 248. IPCNamespacePath= IPC ( /proc//ns/ipc bind mount symlink ). . fork . PrivateIPC= . JoinsNamespaceOf= PrivateIPC= IPCNamespacePath= . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 248. MemoryKSM= . KSM ( Kernel Samepage Merging) . KSM . . . Kernel Samepage Merging[8] . KSM KSM prctl(2) . 254. PrivatePIDs= . false . PID . PID 1 -- init -- . /proc/ PID . PrivatePIDs= MountAPIVFS=yes . PrivatePIDs= . Type=forking init PID . PID . ( - ) /proc/ ( /proc/kmsg tmpfs systemd-nspawn(1) ) PrivatePIDs=yes . /proc/ . 257. PrivateUsers= "self" "identity" . false . . "self" "root" "nobody" . . IPC / "root" / "nobody" . "identity" 65536 UID/GID . UID/GID 65536 "nobody" . UID/GID UID/GID UID . ( / "root" ). . CapabilityBoundingSet= . - "root" ( root ). - . PrivateUsers=true - . RootDirectory=/RootImage= "root" "nobody" . ( ) . 232. ProtectHostname= . UTS . . . ( UTS ) . . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 242. ProtectClock= . . . CAP_SYS_TIME CAP_WAKE_ALARM DeviceAllow=char-rtc r . . /dev/rtc0 /dev/rtc1 . DeviceAllow= systemd.resource-control(5) . . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 245. ProtectKernelTunables= . true /proc/sys/ /sys/ /proc/sysrq-trigger /proc/latency_stats /proc/acpi /proc/timer_stats /proc/fs /proc/irq /proc/kallsyms /proc/kcore . sysctl.d(5). . ReadOnlyPaths= . . IPC . InaccessiblePaths= IPC . ProtectKernelTunables= MountAPIVFS=yes . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 232. ProtectKernelModules= . true . . . . CAP_SYS_MODULE /usr/lib/modules . ReadOnlyPaths= . . kernel.modules_disabled sysctl.d(5) /proc/sys/kernel/modules_disabled . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 232. ProtectKernelLogs= . true (kernel log ring buffer) . . CAP_SYSLOG syslog(2) ( API C syslog(3) ) . /dev/kmsg /proc/kmsg . . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 244. ProtectControlGroups= "private" "strict" . true (cgroups(7)) /sys/fs/cgroup/ . "private" cgroup /sys/fs/cgroup/ . "strict" cgroup /sys/fs/cgroup/ . . ProtectControlGroups= MountAPIVFS=yes . "private" "strict" false true cgroup . ProtectControlGroups= true "strict" . ReadOnlyPaths= . - . 232. RestrictAddressFamilies= . "none" AF_UNIX AF_INET AF_INET6. "none" . "~" . . . "+" . AF_PACKET . AF_UNIX syslog(2) . socket(2) . ( systemd.socket(5) ) . socketpair() ( AF_UNIX ) io_uring(7) . SystemCallFilter=@service . ABI x86-64 32 x86 s390 s390x mips mips-le ppc ppc-le ppc64 ppc64-le . ABI ( x86/x86-64) ABI . SystemCallArchitectures=native . 211. RestrictFileSystems= . . ( ). "~" : ( ). . ( ) ( ). . : : RestrictFileSystems=ext4 tmpfs RestrictFileSystems=ext2 ext4 ext4 tmpfs ext2 . : : RestrictFileSystems=ext4 tmpfs RestrictFileSystems=~ext4 tmpfs . : : RestrictFileSystems=~ext4 tmpfs RestrictFileSystems=ext4 tmpfs . . "@" . 3. +-------------------+--------------------------------+ | | | +-------------------+--------------------------------+ |@basic-api | API | | | . | +-------------------+--------------------------------+ |@auxiliary-api | API | | | . | +-------------------+--------------------------------+ |@common-block | | | | | | | | | | . | +-------------------+--------------------------------+ |@historical-block | | | | | | | | | | | | | . | +-------------------+--------------------------------+ |@network | | | | | | | | | | . | +-------------------+--------------------------------+ |@privileged-api | API | | | . | +-------------------+--------------------------------+ |@temporary | | | | : | | | tmpfs, ramfs. | +-------------------+--------------------------------+ |@known | | | | | | | | | | | | | | | | . | | | | | | | | | systemd | | | | | | | | | | | | | | | | | | systemd | | | | | | | | | . | | | | | | | | | | | | | | | | | | . | +-------------------+--------------------------------+ filesystems systemd-analyze(1) . ( LSM eBPF ). . "+" . 250. RestrictNamespaces= . namespaces(7) . . false () . true . : cgroup ipc net mnt pid user uts. ( ). ("~") : ( ). false . OR ( "~" AND) ( ). unshare(2) clone(2) setns(2) . -- -- ( true ) setns() . x86 x86-64 mips mips-le mips64 mips64-le mips64-n32 mips64-le-n32 ppc64 ppc64-le s390 s390x . : : RestrictNamespaces=cgroup ipc RestrictNamespaces=cgroup net cgroup ipc net . "~" : RestrictNamespaces=cgroup ipc RestrictNamespaces=~cgroup net ipc . 233. LockPersonality= . personality(2) personality Personality= . personality . 235. MemoryDenyWriteExecute= . . ( prctl(2) ) mmap(2) PROT_EXEC PROT_WRITE mprotect(2) pkey_mprotect(2) PROT_EXEC shmat(2) SHM_EXEC . JIT "trampoline" C . . noexec ( /dev/shm) memfd_create() . ( InaccessiblePaths=/dev/shm) (SystemCallFilter=~memfd_create) . x86-64 x86 . shmat() x86 . ABI ( x86/x86-64) ABI . SystemCallArchitectures=native . 231. RestrictRealtime= . (realtime) . SCHED_FIFO SCHED_RR SCHED_DEADLINE . sched(7) . CPU (Denial-of-Service) . . . 231. RestrictSUIDSGID= . set-user-ID (SUID) set-group-ID (SGID) ( inode(7) ). SUID/SGID SUID/SGID . ( SGID ) . DynamicUser= . . 242. RemoveIPC= . System V POSIX IPC . User= Group= DynamicUser= . IPC root . System V System V POSIX . IPC . DynamicUser= . - . 232. PrivateMounts= . () . . . mount_namespaces(7) . . : CLONE_NEWNS MS_SLAVE ( ). MountFlags= . fork . ExecStartPre= fork ExecStart= ( ). JoinsNamespaceOf= /tmp/ /var/tmp/ . -- PrivateTmp= PrivateDevices= ProtectSystem= ProtectHome= ReadOnlyPaths= InaccessiblePaths= ReadWritePaths= BindPaths= BindReadOnlyPaths= -- . . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). 239. MountFlags= : shared slave private . mount(2) . . ( PrivateMounts= ) slave . shared . - - shared - - slave . private ( ) fork . PrivateMounts= . - PrivateUsers= ( sysctl "kernel.unprivileged_userns_clone=" ). (SYSTEM CALL FILTERING) SystemCallFilter= . ( ). "~" : ( ). . . "+" . execve() exit() exit_group() getrlimit() rt_sigreturn() sigreturn() (sleep) . SIGSYS . SystemCallErrorNumber= . (":") SystemCallErrorNumber= . SystemCallErrorNumber= . ('seccomp filtering') . ABI ( x86/x86-64) ABI . SystemCallArchitectures=native . . execve() -- . (: ) . . ( ) ( ). . ( read() write() write() write() .) . "@" . &4. & +-------------------+-----------------------------------------------+ | | | +-------------------+-----------------------------------------------+ |@aio | / | | | (io_setup(2) | | | io_submit(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@basic-io | | | | I/O | | | : | | | (seek) | | | | | | | | | (read(2) | | | write(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@chown | | | | (chown(2) fchownat(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@clock | | | | | | | | | | (adjtimex(2) settimeofday(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@cpu-emulation | | | | | | | | | | | | | (vm86(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@debug | | | | | | | | | | (ptrace(2) | | | perf_event_open(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@file-system | | | | : | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | +-------------------+-----------------------------------------------+ |@io-event | | | | | | | (poll(2) select(2) | | | epoll(7) eventfd(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@ipc | (Pipes) SysV IPC | | | POSIX | | | IPC | | | (mq_overview(7) svipc(7)) | +-------------------+-----------------------------------------------+ |@keyring | | | | (keyring) | | | (keyctl(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@memlock | | | | RAM (mlock(2) mlockall(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@module | | | | | | | (init_module(2) delete_module(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@mount | | | | | | | (mount(2) chroot(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@network-io | / | | | ( AF_UNIX ): | | | socket(7) unix(7) | +-------------------+-----------------------------------------------+ |@obsolete | | | | | | | | | | (create_module(2) gtty(2) | | | ) | +-------------------+-----------------------------------------------+ |@pkey | | | | | | | | | | (pkeys(7)) | +-------------------+-----------------------------------------------+ |@privileged | | | | | | | | | | | | | | | | (capabilities(7)) | +-------------------+-----------------------------------------------+ |@process | | | | | | | (clone(2) | | | kill(2) namespaces(7) ) | +-------------------+-----------------------------------------------+ |@raw-io | | | | I/O (ioperm(2) iopl(2) | | | pciconfig_read() ) | +-------------------+-----------------------------------------------+ |@reboot | | | | | | | | | | | | | | | | (reboot(2) kexec() ) | +-------------------+-----------------------------------------------+ |@resources | | | | | | | | | | | | | | | | | | | (setrlimit(2) | | | setpriority(2) ) | +-------------------+-----------------------------------------------+ |@sandbox | | | | | | | | | | (seccomp(2) | | | | | | Landlock ) | +-------------------+-----------------------------------------------+ |@setuid | | | | | | | | | | | | | (setuid(2) setgid(2) setresuid(2) | | | ) | +-------------------+-----------------------------------------------+ |@signal | | | | | | | | | | | | | (signal(2) | | | sigprocmask(2) ) | +-------------------+-----------------------------------------------+ |@swap | | | | | | | / | | | | | | swap (swapon(2) swapoff(2)) | +-------------------+-----------------------------------------------+ |@sync | | | | | | | (fsync(2) msync(2) | | | | | | ) | +-------------------+-----------------------------------------------+ |@system-service | | | | | | | | | | | | | | | | | | | | | | | | | . | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | . | | | API | | | : | | | "@clock" "@mount" "@swap" "@reboot". | +-------------------+-----------------------------------------------+ |@timer | | | | | | | | | | | | | (alarm(2) timer_create(2) | | | ) | +-------------------+-----------------------------------------------+ |@known | | | | | | | | | | | | | . | | | | | | systemd | | | | | | | | | systemd | | | | | | . | | | | | | | | | | | | . | +-------------------+-----------------------------------------------+ . systemd . systemd . systemd-analyze syscall-filter . ( ) . . : [Service] SystemCallFilter=@system-service SystemCallErrorNumber=EPERM : . pidfd_send_signal() kill() . . . (dynamic linker) . ( : ELF ). ( open() openat() mmap()) . SystemCallFilter=~@mount . : PrivateTmp= PrivateDevices= ProtectSystem= ProtectHome= ProtectKernelTunables= ProtectControlGroups= ProtectKernelLogs= ProtectClock= ReadOnlyPaths= InaccessiblePaths= ReadWritePaths=. 187. SystemCallErrorNumber= "errno" ( 1 4095) errno EPERM EACCES EUCLEAN SystemCallFilter= . errno(3) . "kill" . 209. SystemCallArchitectures= . ConditionArchitecture= systemd.unit(5) x32 mips64-n32 mips64-le-n32 native. native ( : ) . . . x32 x86-64 . x32 . . x86 ABI -- x86-64 . ABI -- x86/x86-64 -- ABI ABI . SystemCallArchitectures=native ABI . SystemCallArchitectures= . systemd-system.conf(5) . 209. SystemCallLog= . . "~" : . Secure Computing Mode 2 ('seccomp filtering') . . . "+" . 247. (ENVIRONMENT) Environment= . "Quoting" systemd.syntax(7) . . "$" . (specifiers) "Specifiers" systemd.unit(5) . . . . ASCII . . . : Environment="VAR1=word1 word2" VAR2=word3 "VAR3=$word 5 6" "VAR1" "VAR2" "VAR3" "word1 word2" "word3" "$word 5 6" . environ(7) . ( ) . D-Bus IPC . ( setuid/setgid) . LoadCredential= LoadCredentialEncrypted= SetCredentialEncrypted= ( ) . EnvironmentFile= Environment= . . "=" ";" "#" () . UTF-8 . (unicode scalar values)[9] (unicode noncharacters)[10] U+0000 NUL U+FEFF (unicode byte order mark)[11]. NUL . "=" POSIX[12] . ( carriage return) . . "\" "\\" "\" . "'" "=" POSIX[13]. . . "=" POSIX[14] . ("\") " . . . . wildcard "-" . . . (: . . bind mount ). Environment= . . PassEnvironment= . . . . . . . Environment= EnvironmentFile= . : PassEnvironment=VAR1 VAR2 VAR3 "VAR1" "VAR2" "VAR3" PID1 . environ(7) . 228. UnsetEnvironment= . . / . / . (: "=" ) . ( "=" ) . UnsetEnvironment= . Environment= EnvironmentFile= PassEnvironment= ( $NOTIFY_SOCKET ) PAM ( PAMName= ). " " . environ(7) . 235. / (LOGGING AND STANDARD INPUT/OUTPUT) StandardInput= 0 (STDIN) . null tty tty-force tty-fail data file:path socket fd:name . null /dev/null EOF . tty TTY ( TTYPath= ) . . tty-force tty . tty-fail tty . data . StandardInputText=/StandardInputData= ( ). ( UNIX ) . EOF . file:path . ":" FIFO . AF_UNIX (stream socket) . . socket ( systemd.socket(5) ) Accept=yes . inetd(8) ( $LISTEN_FDS socket ). fd:name . ":" ( "fd:foobar"). "stdin" ( "fd" "fd:stdin" ). Sockets= . . FileDescriptorName= systemd.socket(5) . null StandardInputText=/StandardInputData= data . StandardOutput= 1 (stdout) . inherit null tty journal kmsg journal+console kmsg+console file:path append:path truncate:path socket fd:name . inherit . null /dev/null . tty tty ( TTYPath= ). TTY . : TTY . SetShowStatus() . org.freedesktop.systemd1(5) . journal (journal) journalctl(1) . kmsg ( ) superset . ( syslog .) kmsg dmesg(1) . kmsg journal . journal+console kmsg+console . file:path . StandardInput= . path ( systemd ) (truncate) . -- -- . AF_UNIX . append:path file:path (append mode) . truncate:path file:path (truncate) . Type=oneshot ExecStart= ExecCondition= ExecStartPre= ExecStartPost= truncate . truncate ExecReload= ExecStart= NUL (sparse file) . truncate:path ExecStart= ExecStartPost= ExecReload= ExecStop= . socket . StandardInput= . fd:name . ":" ( "fd:foobar"). "stdout" ( "fd" "fd:stdout" ). Sockets= . . FileDescriptorName= systemd.socket(5) . ( ) After= systemd-journald.socket ( " " ). stdout ( stderr ) AF_UNIX FIFO . echo "hello" > /dev/stderr stderr . echo "hello" >&2 . StandardInput= tty tty-force tty-fail socket fd:name inherit . DefaultStandardOutput= systemd-system.conf(5) journal . ( ). StandardError= 2 (stderr) . StandardOutput= : inherit fd:name "stderr" . DefaultStandardError= systemd-system.conf(5) inherit . ( ). StandardInputText= StandardInputData= 0 (STDIN) . StandardInput= data ( StandardInput= StandardInputText=/StandardInputData= ). . StandardInputText= . C "%" . ( ). . ( "\n" ). StandardInputData= Base64[15] . . . StandardInputText= StandardInputData= . . . ( ) "\" ( systemd.unit(5) ). . : ... StandardInput=data StandardInputData=V2XigLJyZSBubyBzdHJhbmdlcnMgdG8gbG92ZQpZb3Uga25vdyB0aGUgcnVsZXMgYW5kIHNvIGRv \ IEkKQSBmdWxsIGNvbW1pdG1lbnQncyB3aGF0IEnigLJtIHRoaW5raW5nIG9mCllvdSB3b3VsZG4n \ dCBnZXQgdGhpcyBmcm9tIGFueSBvdGhlciBndXkKSSBqdXN0IHdhbm5hIHRlbGwgeW91IGhvdyBJ \ J20gZmVlbGluZwpHb3R0YSBtYWtlIHlvdSB1bmRlcnN0YW5kCgpOZXZlciBnb25uYSBnaXZlIHlv \ dSB1cApOZXZlciBnb25uYSBsZXQgeW91IGRvd24KTmV2ZXIgZ29ubmEgcnVuIGFyb3VuZCBhbmQg \ ZGVzZXJ0IHlvdQpOZXZlciBnb25uYSBtYWtlIHlvdSBjcnkKTmV2ZXIgZ29ubmEgc2F5IGdvb2Ri \ eWUKTmV2ZXIgZ29ubmEgdGVsbCBhIGxpZSBhbmQgaHVydCB5b3UK ... 236. LogLevelMax= . syslog : emerg ( ) alert crit err warning notice info debug ( ). syslog(3) . ( debug ). . LogLevelMax=info (debug) . (PID 1) . . . MaxLevelStore= journald.conf(5) LogLevelMax= . 236. LogExtraFields= systemd . "FIELD=VALUE" . systemd.journal-fields(7) . UTF-8 . (") . ( ). . . -. 236. LogRateLimitIntervalSec= LogRateLimitBurst= (rate limiting) . LogRateLimitIntervalSec= LogRateLimitBurst= . . LogRateLimitIntervalSec= : "s" "min" "h" "ms" "us". systemd.time(7) . RateLimitIntervalSec= RateLimitBurst= journald.conf(5) . systemd- journald.service(8). stderr StandardOutput=file:... ( syslog(3) ). 240. LogFilterPatterns= (extended regular expression) MESSAGE= . "~" . . . "~" "\x7e" "~" . "~foobar" "foobar" "\x7efoobar" "~foobar" . ( ) ( ) . . . . . LogFilterPatterns= systemd(1) . syslog (kmsg) systemd (wall) . -. 253. LogNamespace= . . systemd-journald.service . ( syslog() stdout/stderr ) systemd-journald@.service . . systemd- journald.service(8) . AF_UNIX . ReadOnlyPaths= . . systemd-journald@.service . journalctl(1) --namespace= . - . 245. SyslogIdentifier= (" syslog") . . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr . SyslogFacility= (facility) syslog . kern user mail daemon auth syslog lpr news uucp cron authpriv ftp local0 local1 local2 local3 local4 local5 local6 local7. syslog(3) . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr . daemon . SyslogLevel= syslog . emerg alert crit err warning notice info debug. syslog(3) . StandardOutput= StandardError= journal kmsg ( +console) stdout stderr . . SyslogLevelPrefix= . sd-daemon(3) . info . SyslogLevelPrefix= . true StandardOutput= StandardError= journal kmsg ( +console) . false . stdout stderr . sd-daemon(3) . true . TTYPath= TTY ( ). /dev/console . TTYReset= TTYPath= . ( TTYVTDisallocate= ). "no" . TTYVHangup= TTYPath= . "no" . TTYColumns= TTYRows= TTY TTYPath= . ANSI ( 80x24) . 250. TTYVTDisallocate= TTYPath= TTY (deallocate) . (scrollback) . TTY ANSI . "no" . (CREDENTIALS) LoadCredential=ID[:PATH] LoadCredentialEncrypted=ID[:PATH] (credential) . . ( ) . ( ) swap . User=/DynamicUser= ( ) . $CREDENTIALS_DIRECTORY . LoadCredential= . ASCII . . AF_UNIX ( ) IPC . -- ( ) . /etc/credstore/ /run/credstore/ /usr/lib/credstore/ -- . LoadCredentialEncrypted= /run/credstore.encrypted/ /etc/credstore.encrypted/ /usr/lib/credstore.encrypted/ . . . . ( ) . "_$FILENAME" ( "Key_file1"). . / NUL. LoadCredentialEncrypted= LoadCredential= . systemd-creds(1) . LoadCredential= . TPM2 /var/lib/systemd/credentials.secret / . . . DevicePolicy= "closed" "strict" "auto" DeviceAllow= PrivateDevices= /dev/tpmrm0 rw DeviceAllow= . DevicePolicy= DeviceAllow= systemd.resource-control(5) . - systemd-creds encrypt --user --user . . / IPC : . DynamicUser= UID ( UID ) . ExecStart= "${CREDENTIALS_DIRECTORY}/mycred" "ExecStart=cat ${CREDENTIALS_DIRECTORY}/mycred". Environment= "%d/mycred" "Environment=MYCREDPATH=%d/mycred". ( ) "/run/credentials/UNITNAME" . $CREDENTIALS_DIRECTORY . 1 . . Container Interface[16] . OEM DMI/SMBIOS[17] ( 11) "io.systemd.credential:" "io.systemd.credential.binary:" . / "=" Base64 ( ). qemu[18]: "-smbios type=11,value=io.systemd.credential:xx=yy" "-smbios type=11,value=io.systemd.credential.binary:rick=TmV2ZXIgR29ubmEgR2l2ZSBZb3UgVXA=". "fw_cfg" qemu "opt/io.systemd.credentials/" . qemu: "-fw_cfg name=opt/io.systemd.credentials/mycred,string=supersecret". UEFI systemd-stub(7) initrd ( systemd(1) ) "systemd.set_credential=" "systemd.set_credential_binary=" ( systemd(1) -- ). AF_UNIX . getpeername(2) . NUL RANDOM "/unit/" UNIT "/" ID NUL ( ) ( -) "/unit/" "/" . : "\0adf9d86b6eda275e/unit/foobar.service/credx" "credx" "foobar.service" . . System and Service Credentials[19] . 247. ImportCredential=GLOB . -- ( ) . glob glob . /etc/credstore/ /run/credstore/ /usr/lib/credstore/ /run/credstore.encrypted/ /etc/credstore.encrypted/ /usr/lib/credstore.encrypted/ . . globbing glob(7) : "*" . "?" "[]" "*" glob . . glob . "ImportCredential=my.original.cred:my.renamed.cred" "my.original.cred" "my.renamed.cred" . "ImportCredential=my.original.*:my.renamed." "my.original." "my.renamed.xxx" . ImportCredential= . LoadCredential= LoadCredentialEncrypted= ImportCredential= . 254. SetCredential=ID:VALUE SetCredentialEncrypted=ID:VALUE SetCredential= LoadCredential= (literal) . IPC . . LoadCredential= . C ( "\n" "\x00" NUL). SetCredentialEncrypted= SetCredential= . . -p systemd-creds(1) SetCredentialEncrypted= . LoadCredentialEncrypted= . LoadCredential= LoadCredentialEncrypted= ImportCredential= SetCredential= . SetCredential= . LoadCredential= LoadCredentialEncrypted= . 247. System V (SYSTEM V COMPATIBILITY) UtmpIdentifier= utmp(5) wtmp . getty ( agetty(8)) utmp/wtmp getty ( ). . %I . utmp/wtmp . UtmpMode= "init" "login" "user" . UtmpIdentifier= utmp(5)/wtmp . UtmpIdentifier= . "init" INIT_PROCESS utmp/wtmp getty . "login" INIT_PROCESS LOGIN_PROCESS . utmp/wtmp login(1) . "user" INIT_PROCESS LOGIN_PROCESS USER_PROCESS . (session leader) . "init" . 225. (ENVIRONMENT VARIABLES IN SPAWNED PROCESSES) . ( PassEnvironment= ) . : o DefaultEnvironment= systemd-system.conf(5) systemd.setenv= systemd(1) set-environment systemctl(1). o ( ). o ( PassEnvironment= ). o Environment= . o EnvironmentFile= . o PAM PAMName= pam_env(8). -- -- . UnsetEnvironment= . . (PID 1) . PAM . . . : systemd-run -P env systemd-run --user -P env . (Environment Variables Set or Propagated by the Service Manager) : $PATH . systemd "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin" . . $PATH . 208. $LANG (Locale). locale.conf(5) ( systemd(1) kernel-command-line(7) ). 208. $USER $LOGNAME $HOME $SHELL ( ) . $USER $HOME $LOGNAME $SHELL User= SetLoginEnvironment= true . . passwd(5) . 208. $INVOCATION_ID 128 32 . . . 232. $XDG_RUNTIME_DIR ( IPC) (volatile). systemd PAMName= PAM pam_systemd . pam_systemd(8) . 208. $RUNTIME_DIRECTORY $STATE_DIRECTORY $CACHE_DIRECTORY $LOGS_DIRECTORY $CONFIGURATION_DIRECTORY RuntimeDirectory= StateDirectory= CacheDirectory= LogsDirectory= ConfigurationDirectory= . 244. $CREDENTIALS_DIRECTORY ImportCredential=/LoadCredential=/SetCredential=. swap ( ) UID User= DynamicUser= ( ) . 247. $MAINPID (PID) . ExecReload= . 209. $MANAGERPID (PID) systemd . 208. $LISTEN_FDS $LISTEN_PID $LISTEN_FDNAMES . sd_listen_fds(3) . 208. $NOTIFY_SOCKET sd_notify() . sd_notify(3) . 229. $WATCHDOG_PID $WATCHDOG_USEC (keep-alive) (watchdog). sd_watchdog_enabled(3) . 229. $SYSTEMD_EXEC_PID (PID) ( ExecStart=). PID ( sd_listen_fds(3) $LISTEN_PID $LISTEN_FDS). 248. $TERM (StandardInput=tty StandardOutput=tty StandardError=tty). termcap(5) . 209. $LOG_NAMESPACE LogNamespace= . 246. $JOURNAL_STREAM ( StandardError=journal) $JOURNAL_STREAM inode (":") . . inode . $JOURNAL_STREAM . . ( inode .) ( sd_journal_print(3) ) . 231. $SERVICE_RESULT . ExecStop= ExecStopPost= "" . : &5. & $SERVICE_RESULT +------------------+--------------------------------------------+ | | | +------------------+--------------------------------------------+ |"success" | | | | | | | . | +------------------+--------------------------------------------+ |"protocol" | | | | : | | | | | | | | | | | | | | | ( | | | | | | Type= | | | | | | ). | +------------------+--------------------------------------------+ |"timeout" | | | | | | | . | +------------------+--------------------------------------------+ |"exit-code" | | | | | | | $EXIT_CODE | | | | | | | | | | | | . | +------------------+--------------------------------------------+ |"signal" | | | | | | | | | | | | | (core dump) | | | . $EXIT_CODE | | | | | | | | | | | | . | +------------------+--------------------------------------------+ |"core-dump" | | | | | | | | | | | | | | | | . $EXIT_CODE | | | | | | | | | . | +------------------+--------------------------------------------+ |"watchdog" | | | | | | | | | | | | | | | | . | +------------------+--------------------------------------------+ |"exec-condition" | | | | ExecCondition= | | | | | | ( | | | | | | 1 254 ( | | | ) ). | +------------------+--------------------------------------------+ |"oom-kill" | | | | | | | (OOM Killer) | | | . | +------------------+--------------------------------------------+ |"start-limit-hit" | | | | | | | | | | | | | | | | . | | | | | | StartLimitIntervalSec= | | | StartLimitBurst= systemd.unit(5) | | | . | +------------------+--------------------------------------------+ |"resources" | | | | | | | | | | | | | . | +------------------+--------------------------------------------+ . ExecStop= ExecStopPost= . 232. $EXIT_CODE $EXIT_STATUS . ExecStop= ExecStopPost= / . wait(2) . $EXIT_CODE "exited" "killed" "dumped" . $EXIT_STATUS $EXIT_CODE "exited" . . &6. & +------------------+--------------------------------+--------------------------------+ |$SERVICE_RESULT | $EXIT_CODE | $EXIT_STATUS | +------------------+--------------------------------+--------------------------------+ |"success" | "killed" | "HUP", "INT", "TERM", "PIPE" | | +--------------------------------+--------------------------------+ | | "exited" | "0" | +------------------+--------------------------------+--------------------------------+ |"protocol" | | | | +--------------------------------+--------------------------------+ | | "exited" | "0" | +------------------+--------------------------------+--------------------------------+ |"timeout" | "killed" | "TERM", "KILL" | | +--------------------------------+--------------------------------+ | | "exited" | "0", "1", "2", "3", ..., "255" | +------------------+--------------------------------+--------------------------------+ |"exit-code" | "exited" | "1", "2", "3", ..., "255" | +------------------+--------------------------------+--------------------------------+ |"signal" | "killed" | "HUP", "INT", "KILL", ... | +------------------+--------------------------------+--------------------------------+ |"core-dump" | "dumped" | "ABRT", "SEGV", "QUIT", ... | +------------------+--------------------------------+--------------------------------+ |"watchdog" | "dumped" | "ABRT" | | +--------------------------------+--------------------------------+ | | "killed" | "TERM", "KILL" | | +--------------------------------+--------------------------------+ | | "exited" | "0", "1", "2", "3", ..., "255" | +------------------+--------------------------------+--------------------------------+ |"exec-condition" | "exited" | "1", "2", "3", "4", ..., "254" | +------------------+--------------------------------+--------------------------------+ |"oom-kill" | "killed" | "TERM", "KILL" | +------------------+--------------------------------+--------------------------------+ |"start-limit-hit" | | | +------------------+--------------------------------+--------------------------------+ |"resources" | | | | | | | +------------------+--------------------------------+--------------------------------+ |: | | systemd | | . | | | | | | | | . | | "timeout" "watchdog" | | systemd | | . | | SuccessExitStatus= | | | | | | . | +------------------------------------------------------------------------------------+ 232. $MONITOR_SERVICE_RESULT $MONITOR_EXIT_CODE $MONITOR_EXIT_STATUS $MONITOR_INVOCATION_ID $MONITOR_UNIT . ExecStart= ExecStartPre= OnFailure= OnSuccess= . $MONITOR_SERVICE_RESULT $MONITOR_EXIT_CODE $MONITOR_EXIT_STATUS ExecStop= ExecStopPost= . $MONITOR_INVOCATION_ID $MONITOR_UNIT . OnFailure= OnSuccess= . : "OnFailure=handler@%n.service" "OnFailure=handler@%p-%i.service" . 251. $PIDFILE PID PIDFile= systemd.service(5) . PID . . 242. $REMOTE_ADDR $REMOTE_PORT ( Accept=yes) (peer) . IPv4 IPv6 $REMOTE_ADDR IP $REMOTE_PORT . AF_UNIX $REMOTE_ADDR ("/") at ("@") . $REMOTE_PORT AF_UNIX . 220. $TRIGGER_UNIT $TRIGGER_PATH $TRIGGER_TIMER_REALTIME_USEC $TRIGGER_TIMER_MONOTONIC_USEC (: ) . (best-effort) . . . 252. $MEMORY_PRESSURE_WATCH $MEMORY_PRESSURE_WRITE . Memory Pressure Handling[20] . 254. $FDSTORE . FileDescriptorStoreMax= ( systemd.service(5) ). sd_pid_notify_with_fds(3) . 254. $DEBUG_INVOCATION RestartMode=debug . systemd.service(5) . 257. PAMName= pam_systemd PAM systemd . $XDG_SEAT $XDG_VTNR pam_systemd(8) . (PROCESS EXIT CODES) . . ( fork(2) execve(2) .) C LSB systemd . C . &7. & C +--------------------+--------------------+-----------------------+ | | | | | | | | +--------------------+--------------------+-----------------------+ |0 | EXIT_SUCCESS | | | | | | | | | . | +--------------------+--------------------+-----------------------+ |1 | EXIT_FAILURE | | | | | | | | | | | | | . | +--------------------+--------------------+-----------------------+ LSB[21] . &8. & LSB +--------------------+----------------------+------------------------------------------------+ | | | | | | | | +--------------------+----------------------+------------------------------------------------+ |2 | EXIT_INVALIDARGUMENT | | | | | . | +--------------------+----------------------+------------------------------------------------+ |3 | EXIT_NOTIMPLEMENTED | | | | | . | +--------------------+----------------------+------------------------------------------------+ |4 | EXIT_NOPERMISSION | | | | | | | | | . | +--------------------+----------------------+------------------------------------------------+ |5 | EXIT_NOTINSTALLED | | | | | . | +--------------------+----------------------+------------------------------------------------+ |6 | EXIT_NOTCONFIGURED | | | | | . | +--------------------+----------------------+------------------------------------------------+ |7 | EXIT_NOTRUNNING | | | | | . | +--------------------+----------------------+------------------------------------------------+ LSB 200 . : &9. & systemd +--------------------+------------------------------+-----------------------------------------------+ | | | | +--------------------+------------------------------+-----------------------------------------------+ |200 | EXIT_CHDIR | | | | | | | | | | | | | . WorkingDirectory= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |201 | EXIT_NICE | | | | | | | | | | | | | ( nice) | | | | . Nice= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |202 | EXIT_FDS | | | | | | | | | | | | | | | | | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |203 | EXIT_EXEC | | | | | ( | | | | | | | | execve(2)) | | | | . | | | | | | | | | | | | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |204 | EXIT_MEMORY | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |205 | EXIT_LIMITS | | | | | | | | | | | | | . LimitCPU= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |206 | EXIT_OOM_ADJUST | OOM | | | | . | | | | OOMScoreAdjust= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |207 | EXIT_SIGNAL_MASK | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |208 | EXIT_STDIN | | | | | | | | | . | | | | StandardInput= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |209 | EXIT_STDOUT | | | | | | | | | . | | | | StandardOutput= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |210 | EXIT_CHROOT | | | | | (chroot(2)) | | | | . | | | | RootDirectory=/RootImage= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |211 | EXIT_IOPRIO | | | | | | | | | IO | | | | . | | | | IOSchedulingClass=/IOSchedulingPriority= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |212 | EXIT_TIMERSLACK | | | | | | | | | . TimerSlackNSec= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |213 | EXIT_SECUREBITS | | | | | | | | | . | | | | SecureBits= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |214 | EXIT_SETSCHEDULER | | | | | | | | | | | | | . | | | | CPUSchedulingPolicy=/CPUSchedulingPriority= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |215 | EXIT_CPUAFFINITY | | | | | | | | | (CPU | | | | affinity) | | | | . CPUAffinity= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |216 | EXIT_GROUP | | | | | | | | | . | | | | Group=/SupplementaryGroups= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |217 | EXIT_USER | | | | | | | | | | | | | | | | | | | | | | | | | . User=/PrivateUsers= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |218 | EXIT_CAPABILITIES | | | | | | | | | | | | | (ambient) | | | | . | | | | CapabilityBoundingSet=/AmbientCapabilities= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |219 | EXIT_CGROUP | | | | | (cgroup) | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |220 | EXIT_SETSID | (session) | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |221 | EXIT_CONFIRM | | | | | . | | | | | | | | | | | | systemd.confirm_spawn= | | | | kernel-command-line(7) . | +--------------------+------------------------------+-----------------------------------------------+ |222 | EXIT_STDERR | | | | | | | | | | | | | . | | | | StandardError= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |224 | EXIT_PAM | | | | | PAM | | | | . PAMName= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |225 | EXIT_NETWORK | | | | | | | | | . | | | | PrivateNetwork= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |226 | EXIT_NAMESPACE | | | | | mount UTS | | | | IPC | | | | . ReadOnlyPaths= | | | | ProtectHostname= PrivateIPC= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |227 | EXIT_NO_NEW_PRIVILEGES | | | | | | | | | . | | | | NoNewPrivileges=yes | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |228 | EXIT_SECCOMP | | | | | | | | | . | | | | SystemCallFilter= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |229 | EXIT_SELINUX_CONTEXT | | | | | SELinux | | | | . | | | | SELinuxContext= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |230 | EXIT_PERSONALITY | | | | | (personality) | | | | . | | | | Personality= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |231 | EXIT_APPARMOR_PROFILE | | | | | AppArmor | | | | . | | | | AppArmorProfile= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |232 | EXIT_ADDRESS_FAMILIES | | | | | | | | | | | | | . | | | | RestrictAddressFamilies= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |233 | EXIT_RUNTIME_DIRECTORY | | | | | | | | | | | | | . RuntimeDirectory= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |235 | EXIT_CHOWN | | | | | | | | | . | | | | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |236 | EXIT_SMACK_PROCESS_LABEL | SMACK | | | | . | | | | SmackProcessLabel= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |237 | EXIT_KEYRING | | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |238 | EXIT_STATE_DIRECTORY | | | | | | | | | | | | | . StateDirectory= | | | | | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |239 | EXIT_CACHE_DIRECTORY | | | | | | | | | (cache) | | | | . | | | | CacheDirectory= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |240 | EXIT_LOGS_DIRECTORY | | | | | | | | | | | | | . | | | | LogsDirectory= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |241 | EXIT_CONFIGURATION_DIRECTORY | | | | | | | | | | | | | . | | | | ConfigurationDirectory= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |242 | EXIT_NUMA_POLICY | | | | | NUMA | | | | | | | | . NUMAPolicy= | | | | NUMAMask= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |243 | EXIT_CREDENTIALS | | | | | | | | | | | | | . | | | | ImportCredential= LoadCredential= | | | | SetCredential= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ |245 | EXIT_BPF | | | | | BPF | | | | . | | | | RestrictFileSystems= | | | | . | +--------------------+------------------------------+-----------------------------------------------+ BSD : &10. & BSD +--------------------+--------------------+---------------------------------+ | | | | | | | | +--------------------+--------------------+---------------------------------+ |64 | EX_USAGE | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |65 | EX_DATAERR | | | | | | +--------------------+--------------------+---------------------------------+ |66 | EX_NOINPUT | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |67 | EX_NOUSER | | | | | | +--------------------+--------------------+---------------------------------+ |68 | EX_NOHOST | | | | | | +--------------------+--------------------+---------------------------------+ |69 | EX_UNAVAILABLE | | | | | | +--------------------+--------------------+---------------------------------+ |70 | EX_SOFTWARE | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |71 | EX_OSERR | | | | | ( | | | | | | | | fork) | +--------------------+--------------------+---------------------------------+ |72 | EX_OSFILE | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |73 | EX_CANTCREAT | | | | | | | | | | | | | () | +--------------------+--------------------+---------------------------------+ |74 | EX_IOERR | | | | | / | +--------------------+--------------------+---------------------------------+ |75 | EX_TEMPFAIL | | | | | | | | | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |76 | EX_PROTOCOL | | | | | | | | | | +--------------------+--------------------+---------------------------------+ |77 | EX_NOPERM | | | | | ( | | | | ) | +--------------------+--------------------+---------------------------------+ |78 | EX_CONFIG | | | | | | +--------------------+--------------------+---------------------------------+ (EXAMPLES) &3. & $MONITOR_* myfailer.service OnFailure= . [Unit] Description=Service which can trigger an OnFailure= dependency OnFailure=myhandler.service [Service] ExecStart=/bin/myprogram mysuccess.service OnSuccess= . [Unit] Description=Service which can trigger an OnSuccess= dependency OnSuccess=myhandler.service [Service] ExecStart=/bin/mysecondprogram myhandler.service . [Unit] Description=Acts on service failing or succeeding [Service] ExecStart=/bin/bash -c "echo $MONITOR_SERVICE_RESULT $MONITOR_EXIT_CODE $MONITOR_EXIT_STATUS $MONITOR_INVOCATION_ID $MONITOR_UNIT" myfailer.service myhandler.service : MONITOR_SERVICE_RESULT=exit-code MONITOR_EXIT_CODE=exited MONITOR_EXIT_STATUS=1 MONITOR_INVOCATION_ID=cc8fdc149b2b4ca698d4f259f4054236 MONITOR_UNIT=myfailer.service mysuccess.service myhandler.service : MONITOR_SERVICE_RESULT=success MONITOR_EXIT_CODE=exited MONITOR_EXIT_STATUS=0 MONITOR_INVOCATION_ID=6ab9af147b8c4a3ebe36e7a5f8611697 MONITOR_UNIT=mysuccess.service (SEE ALSO) systemd(1), systemctl(1), systemd-analyze(1), journalctl(1), systemd- system.conf(5), systemd.unit(5), systemd.service(5), systemd.socket(5), systemd.swap(5), systemd.mount(5), systemd.kill(5), systemd.resource- control(5), systemd.time(7), systemd.directives(7), tmpfiles.d(5), exec(3), fork(2) (NOTES) 1. Discoverable Partitions Specification https://uapi- group.org/specifications/specs/discoverable_partitions_specification 2. The /proc Filesystem https://docs.kernel.org/filesystems/proc.html#mount-options 3. User/Group Name Syntax https://systemd.io/USER_NAMES 4. No New Privileges Flag https://docs.kernel.org/userspace-api/no_new_privs.html 5. JSON User Record https://systemd.io/USER_RECORD 6. The /proc Filesystem https://docs.kernel.org/filesystems/proc.html 7. id-mapped mounts https://lwn.net/Articles/896255 8. Kernel Samepage Merging https://docs.kernel.org/admin-guide/mm/ksm.html 9. unicode scalar values https://www.unicode.org/glossary/#unicode_scalar_value 10. unicode noncharacters https://www.unicode.org/glossary/#noncharacter 11. unicode byte order mark https://www.unicode.org/glossary/#byte_order_mark 12. POSIX shell unquoted text https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_01 13. POSIX shell single-quoted text https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_02 14. POSIX shell double-quoted text https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_02_03 15. Base64 https://tools.ietf.org/html/rfc2045#section-6.8 16. Container Interface https://systemd.io/CONTAINER_INTERFACE 17. DMI/SMBIOS https://www.dmtf.org/standards/smbios 18. qemu https://www.qemu.org/docs/master/system/index.html 19. System and Service Credentials https://systemd.io/CREDENTIALS 20. Memory Pressure Handling https://systemd.io/MEMORY_PRESSURE 21. LSB specification https://refspecs.linuxbase.org/LSB_5.0.0/LSB-Core-generic/LSB-Core- generic/iniscrptact.html systemd 257.13 SYSTEMD.EXEC(5)