systemd中文文档 - 启动: http://systemd.cn/docs/Booting/ - 自动启动评估: http://systemd.cn/docs/Booting/AUTOMATIC_BOOT_ASSESSMENT/ - 启动组件和根文件系统探测: http://systemd.cn/docs/Booting/ROOTFS_DISCOVERY/ - 引导加载程序接口: http://systemd.cn/docs/Booting/BOOT_LOADER_INTERFACE/ - 恢复出厂设置: http://systemd.cn/docs/Booting/FACTORY_RESET/ - 挂载点可用性要求: http://systemd.cn/docs/Booting/MOUNT_REQUIREMENTS/ - TPM2 PCR测量: http://systemd.cn/docs/Booting/TPM2_PCR_MEASUREMENTS/ - Boot Loader Specification: http://systemd.cn/docs/BOOT_LOADER_SPECIFICATION/ - Discoverable Partitions: http://systemd.cn/docs/DISCOVERABLE_PARTITIONS/ - Elf Dlopen Metadata: http://systemd.cn/docs/ELF_DLOPEN_METADATA/ - Osc Context: http://systemd.cn/docs/OSC_CONTEXT/ - Package Metadata for Executable Files: http://systemd.cn/docs/PACKAGE_METADATA_FOR_EXECUTABLE_FILES/ - API File Systems: http://systemd.cn/docs/API_FILE_SYSTEMS/ - Appstream Bundle: http://systemd.cn/docs/APPSTREAM_BUNDLE/ - Backports: http://systemd.cn/docs/BACKPORTS/ - Booting Without /usr is Broken: http://systemd.cn/docs/SEPARATE_USR_IS_BROKEN/ - Code Quality Tools: http://systemd.cn/docs/CODE_QUALITY/ - Coding Style: http://systemd.cn/docs/CODING_STYLE/ - Compatibility with SysV: http://systemd.cn/docs/INCOMPATIBILITIES/ - Container Interface: http://systemd.cn/docs/CONTAINER_INTERFACE/ - Contributing: http://systemd.cn/docs/CONTRIBUTING/ - Control Group APIs and Delegation: http://systemd.cn/docs/CGROUP_DELEGATION/ - Converting Existing Users to systemd-homed: http://systemd.cn/docs/CONVERTING_TO_HOMED/ - Credentials: http://systemd.cn/docs/CREDENTIALS/ - Desktop Environment Integration: http://systemd.cn/docs/DESKTOP_ENVIRONMENTS/ - Diagnosing Boot Problems: http://systemd.cn/docs/DEBUGGING/ - File Descriptor Store: http://systemd.cn/docs/FILE_DESCRIPTOR_STORE/ - Frequently Asked Questions: http://systemd.cn/docs/FAQ/ - Governance: http://systemd.cn/docs/GOVERNANCE/ - Hacking on systemd: http://systemd.cn/docs/HACKING/ - Home Directories: http://systemd.cn/docs/HOME_DIRECTORY/ - Inhibitor Locks: http://systemd.cn/docs/INHIBITOR_LOCKS/ - Initrd Interface: http://systemd.cn/docs/INITRD_INTERFACE/ - Journal Export Formats: http://systemd.cn/docs/JOURNAL_EXPORT_FORMATS/ - Journal File Format: http://systemd.cn/docs/JOURNAL_FILE_FORMAT/ - Journal Message Catalogs: http://systemd.cn/docs/CATALOG/ - JSON Group Records: http://systemd.cn/docs/GROUP_RECORD/ - JSON User Records: http://systemd.cn/docs/USER_RECORD/ - Known Environment Variables: http://systemd.cn/docs/ENVIRONMENT/ - Locking Block Device Access: http://systemd.cn/docs/BLOCK_DEVICE_LOCKING/ - Minimal Builds: http://systemd.cn/docs/MINIMAL_BUILDS/ - My Service Can't Get Realtime!: http://systemd.cn/docs/MY_SERVICE_CANT_GET_REALTIME/ - Native Journal Protocol: http://systemd.cn/docs/JOURNAL_NATIVE_PROTOCOL/ - New Control Group Interfaces: http://systemd.cn/docs/CONTROL_GROUP_INTERFACE/ - Notes for Translators: http://systemd.cn/docs/TRANSLATORS/ - Password Agents: http://systemd.cn/docs/PASSWORD_AGENTS/ - Pax Controla Groupiana: http://systemd.cn/docs/PAX_CONTROL_GROUPS/ - Portability and Stability: http://systemd.cn/docs/PORTABILITY_AND_STABILITY/ - Portable Services Introduction: http://systemd.cn/docs/PORTABLE_SERVICES/ - Porting systemd To New Distributions: http://systemd.cn/docs/DISTRO_PORTING/ - Porting to New Architectures: http://systemd.cn/docs/PORTING_TO_NEW_ARCHITECTURES/ - Predictable Network Interface Names: http://systemd.cn/docs/PREDICTABLE_INTERFACE_NAMES/ - Presets: http://systemd.cn/docs/PRESET/ - Project IDs for Disk Quotas on Exec Directories: http://systemd.cn/docs/DISK-QUOTAS-PROJECTIDS/ - Random Seeds: http://systemd.cn/docs/RANDOM_SEEDS/ - Reporting of Security Vulnerabilities: http://systemd.cn/docs/SECURITY/ - Resource Pressure Handling: http://systemd.cn/docs/PRESSURE/ - Running Services After the Network Is Up: http://systemd.cn/docs/NETWORK_ONLINE/ - Safely Building Images: http://systemd.cn/docs/BUILDING_IMAGES/ - Socket Activation with Popular Daemons: http://systemd.cn/docs/DAEMON_SOCKET_ACTIVATION/ - Steps to a Successful Release: http://systemd.cn/docs/RELEASE/ - Storage Daemons for the Root File System: http://systemd.cn/docs/ROOT_STORAGE_DAEMONS/ - systemd Community Conduct Guidelines: http://systemd.cn/docs/CODE_OF_CONDUCT/ - systemd Coredump Handling: http://systemd.cn/docs/COREDUMP/ - systemd File Hierarchy Requirements: http://systemd.cn/docs/SYSTEMD_FILE_HIERARCHY_REQUIREMENTS/ - systemd Optimizations: http://systemd.cn/docs/OPTIMIZATIONS/ - systemd Repository Architecture: http://systemd.cn/docs/ARCHITECTURE/ - systemd-boot UEFI Boot Manager: http://systemd.cn/docs/BOOT/ - systemd-homed and JSON User/Group Record Support in Desktop Environments: http://systemd.cn/docs/USERDB_AND_DESKTOPS/ - systemd-resolved and VPNs: http://systemd.cn/docs/RESOLVED-VPNS/ - Testing systemd Using Sanitizers: http://systemd.cn/docs/TESTING_WITH_SANITIZERS/ - The Case for the /usr Merge: http://systemd.cn/docs/THE_CASE_FOR_THE_USR_MERGE/ - Tips And Tricks: http://systemd.cn/docs/TIPS_AND_TRICKS/ - User Record Blob Directories: http://systemd.cn/docs/USER_RECORD_BLOB_DIRS/ - User/Group Name Syntax: http://systemd.cn/docs/USER_NAMES/ - User/Group Record Lookup API via Varlink: http://systemd.cn/docs/USER_GROUP_API/ - Users, Groups, UIDs and GIDs on systemd Systems: http://systemd.cn/docs/UIDS-GIDS/ - Using /tmp/ and /var/tmp/ Safely: http://systemd.cn/docs/TEMPORARY_DIRECTORIES/ - Varlink API Style: http://systemd.cn/docs/VARLINK/ - VM Interface: http://systemd.cn/docs/VM_INTERFACE/ - What Settings Are Currently Available For Transient Units?: http://systemd.cn/docs/TRANSIENT-SETTINGS/ - Writing Desktop Environments: http://systemd.cn/docs/WRITING_DESKTOP_ENVIRONMENTS/ - Writing Display Managers: http://systemd.cn/docs/WRITING_DISPLAY_MANAGERS/ - Writing Network Configuration Managers: http://systemd.cn/docs/WRITING_NETWORK_CONFIGURATION_MANAGERS/ - Writing Resolver Clients: http://systemd.cn/docs/WRITING_RESOLVER_CLIENTS/ - Writing syslog Daemons Which Cooperate Nicely With systemd: http://systemd.cn/docs/SYSLOG/ - Writing VM and Container Managers: http://systemd.cn/docs/WRITING_VM_AND_CONTAINER_MANAGERS/ # User Record Blob Directories The blob directories are for storing binary or unstructured data that would otherwise be stored in [JSON User Records](/USER_RECORD). For instance, this includes image files such as the user's avatar picture. This data, like most of the user record, will be made publicly available to the system. The JSON User Record specifies the location of the blob directory via the `blobDirectory` field. If the field is unset, then there is no blob directory and thus no blob files to look for. Note that `blobDirectory` can exist in the `regular`, `perMachine`, and `status` sections. The blob directory is completely owned and managed by the service that owns the rest of the user record (as specified in the `service` field). For consistency, blob directories have certain restrictions placed on them that may be enforced by their owning service. Services implementing blob directories are free to ignore these restrictions, but software that wishes to store some of its data in blob directories must adhere to the following: * The directory only contains regular files; no sub-directories or any special files are permitted. * Filenames inside of the directory are restricted to [URI Unreserved Characters](https://www.rfc-editor.org/rfc/rfc3986#section-2.3) (alphanumeric, `-`, `.`, `_`, and `~`), and must not start with a dot. * The total size of the directory should not exceed 64M. * File ownership and permissions will not be preserved. The service may reset the mode of the files to 0644, and ownership to whatever it wishes. * Timestamps, xattrs, ACLs, or any other metadata on the files will not be preserved. Services are required to ensure that the directory and its contents are world-readable. Aside from this requirement, services are free to provide the directory and its contents in whatever manner they like, including but not limited to synthesizing the directory at runtime using external data or keeping around multiple copies. Thus, only the service that owns the directory is permitted to write to this directory in any way: for all other software the directory is strictly read-only. Services may choose to provide some way to change user records. Services that provide this functionality should support changing the blob directory also. Care must be taken to avoid exposing sensitive data to malicious clients. This includes but is not limited to disallowing symlinks and using file descriptors (excluding O_PATH!) to ensure that the client actually has permission to access the data it wants the service to publish. Services that make use of the `signature` section in the records they manage should enforce `blobManifest`. This ensures that the contents of the blob directory are part of the cryptographically signed data. ## Known Files Various files in the blob directories have known semantic meanings. The following files are currently defined: `avatar` → An image file that should be used as the user's avatar picture. The exact file type and resolution of this image are left unspecified, and requirements will depend on the capabilities of the components that will display it. However, we suggest the use of commonly-supported picture formats (i.e. PNG or JPEG) and a resolution of 512 x 512. This image should not have any transparency. If missing, of an incompatible file type, or otherwise unusable, then the user does not have a profile picture and a default will be used instead. `login-background` → An image file that will be used as the user's background on the login screen (i.e. in GDM). The exact file type and resolution are left unspecified and are ultimately up to the components that will render this background image. This image should not have any transparency. If missing, of an incompatible file type, or otherwise unusable, a fallback background of some kind will be used. ## Extending These Directories Like JSON User Records, the blob directories are intended to be extendable for various applications. In general, subsystems are free to introduce their own files, as long as: * The requirements listed above are all met. * Care is taken to avoid namespace clashes. Please prefix your file names with a short identifier of your project to avoid ambiguities and incompatibilities. * This specification is supposed to be a living specification. If you need additional files, please consider defining them upstream for inclusion in this specification. If they are reasonably universally useful, it would be best to list them here. ## Examples The simplest way to define a user record is via the drop-in directories (as documented in [nss-systemd(8)](https://www.freedesktop.org/software/systemd/man/latest/nss-systemd.html) and [systemd-userdb.service(8)](https://www.freedesktop.org/software/systemd/man/latest/systemd-userdbd.service.html)). Such records can have blob directories by simply referring to some persistent place from the record, possibly next to the record itself. For instance, `/etc/userdb/grobie.user` may contain: ```json { "userName": "grobie", "disposition": "regular", "homeDirectory": "/home/grobie", "blobDirectory": "/etc/userdb/grobie.blob/", } ``` In this case, `/etc/userdb/grobie.blob/` will be the blob directory for the user `grobie`. A more complicated case is a home directory managed by `systemd-homed.service`. When it manages a home directory, it maintains and synchronizes two separate blob directories: one belonging to the system in `/var/cache/systemd/home`, and another belonging to the home directory in `~/.identity-blob`. The system blob directory ensures that the blob data is available while the home directory is encrypted or otherwise unavailable, and the home blob directory ensures that the user account remains portable between systems. To implement this behavior, `systemd-homed.service` always sets `blobDirectory` to the system blob directory in the `binding` section of the user record (i.e. this is _not_ persisted to `~/.identity`). If some client tries to update the user record with a new blob directory, `systemd-homed.service` will copy the updated blob directory into both the system and home blob locations.