started · updated
systemd v262 release candidate introduces major security overhauls
The systemd project has released the first release candidate for version 262 (v262-rc1), introducing significant security enhancements and architectural changes to the Linux init system. This update features a major overhaul of the Trusted Platform Module (TPM) subsystem, where credentials sealed to TPMs are now pinned to the Storage Root Key to prevent man-in-the-middle attacks.
Key technical shifts include the migration of internal communication to the Varlink protocol, replacing legacy UNIX sockets. The release also adds support for confidential computing platforms, such as Intel TDX and AMD SEV-SNP, enabling hardware-attested security for virtual machines.
Additional improvements focus on service orchestration and container environments. The update includes mechanisms to prevent synchronized restart loops during service failures and allows for a fully static compilation of systemd, which facilitates initialization in minimal cloud environments without on-disk configuration files. The release involves contributions from approximately 250 developers, including project lead Lennart Poettering.
Entities
Amutable · Intel · Lennart Poettering · Varlink · systemd