started · updated
Systemd 262 released with TPM2 security and static binary support
The systemd service manager has released version 262, introducing significant security enhancements and architectural optimizations. A primary focus of this release is hardware-rooted security, which binds TPM credentials to the TPM's Supreme Root Key to mitigate interposer attacks during the boot process. Additionally, TPM2 login PINs can now be hardened using Argon2id via systemd-cryptenroll.
For container environments, systemd 262 offers the ability to be compiled as a single static binary. This allows it to function as a minimal PID 1 process in lightweight containers by avoiding dynamic library loading and utilizing embedded unit files for essential targets. This design reduces the system footprint and ensures the container can boot even without explicit unit files on disk.
Other technical updates include improved kexec-based live updates for zero-downtime reboots and new service management features. To prevent synchronized service failures, a new RestartRandomizedDelaySec parameter adds a random delay to service restarts. The release also introduces ActivatingConcurrencyMax to limit the number of simultaneous unit activations within a slice hierarchy.