Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. 2️⃣0️⃣ Here's the 20th post highlighting key new features of the recently published v260 release of systemd.

2️⃣0️⃣ Here's the 20th post highlighting key new features of the recently published v260 release of systemd.

Scheduled Pinned Locked Moved Uncategorized
systemd260systemd
3 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • pid_eins@mastodon.socialP This user is from outside of this forum
    pid_eins@mastodon.socialP This user is from outside of this forum
    pid_eins@mastodon.social
    wrote last edited by
    #1

    2️⃣0️⃣ Here's the 20th post highlighting key new features of the recently published v260 release of systemd. #systemd260 #systemd

    One ongoing project inside of systemd is to rework systemd-nspawn to not do its own namespacing/sandboxing but make it mostly just a frontend to systemd's own namespacing/sandboxing that is implemented for system services. The goal is to make it play a role similar to systemd-run: i.e. a command line tool that just allocates a transient service, and thus simplify…

    pid_eins@mastodon.socialP 1 Reply Last reply
    0
    • pid_eins@mastodon.socialP pid_eins@mastodon.social

      2️⃣0️⃣ Here's the 20th post highlighting key new features of the recently published v260 release of systemd. #systemd260 #systemd

      One ongoing project inside of systemd is to rework systemd-nspawn to not do its own namespacing/sandboxing but make it mostly just a frontend to systemd's own namespacing/sandboxing that is implemented for system services. The goal is to make it play a role similar to systemd-run: i.e. a command line tool that just allocates a transient service, and thus simplify…

      pid_eins@mastodon.socialP This user is from outside of this forum
      pid_eins@mastodon.socialP This user is from outside of this forum
      pid_eins@mastodon.social
      wrote last edited by
      #2

      …and unify currently distinct but similar codepaths in systemd's service management and systemd-nspawn's codebase.

      With v260 we filled in one major gap to get there: the existing PrivateUsers= setting for services now supports a new value "managed". If selected then a new delegated user namespace UID range is allocated dynamically via systemd-nsresourced, and assigned to the service. Or in other words: there's now a way to spawn a service with a full set of private, transient, 64K UIDs…

      pid_eins@mastodon.socialP 1 Reply Last reply
      1
      0
      • pid_eins@mastodon.socialP pid_eins@mastodon.social

        …and unify currently distinct but similar codepaths in systemd's service management and systemd-nspawn's codebase.

        With v260 we filled in one major gap to get there: the existing PrivateUsers= setting for services now supports a new value "managed". If selected then a new delegated user namespace UID range is allocated dynamically via systemd-nsresourced, and assigned to the service. Or in other words: there's now a way to spawn a service with a full set of private, transient, 64K UIDs…

        pid_eins@mastodon.socialP This user is from outside of this forum
        pid_eins@mastodon.socialP This user is from outside of this forum
        pid_eins@mastodon.social
        wrote last edited by
        #3

        …which is enough to run a full OS inside a system service. Yay!

        And not just that: it also works unprivileged, i.e. it's enough to also run a full OS with 64K UIDs from a user controlled directory tree. Yippieh yay!

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups