!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

579 Members
NixOS ❤️ systemd159 Servers

Load older messages


SenderMessageTime
4 Mar 2025
@raitobezarius:matrix.orgraitobezariusthis is the 2nd time someone told me13:59:50
@raitobezarius:matrix.orgraitobezariusi am fixing it now13:59:51
@raitobezarius:matrix.orgraitobezariusElvish never told me the typo btw13:59:54
@raitobezarius:matrix.orgraitobezariusdone14:00:06
@arianvp:matrix.orgAriancpio archives preserve fsverity info?14:00:07
@arianvp:matrix.orgArianI assume they do?14:00:12
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
cpio archives preserve fsverity info?
actually they probably don't
14:00:22
@arianvp:matrix.orgArian then this doesn’t work :D 14:00:28
@raitobezarius:matrix.orgraitobezariusfsverity exist only for ext4 & f2fs iirc14:00:33
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
then this doesn’t work :D
yes but you know what is the fix
14:00:37
@emilazy:matrix.orgemilyit's already been hashed into immutable metadata and verity would complain, easier to just get a legal name change14:00:39
@arianvp:matrix.orgArianso I guess deprecate initramfs and go back to initrd :D14:01:00
@raitobezarius:matrix.orgraitobezariusthis is how identity leaks should be handled14:01:02
@raitobezarius:matrix.orgraitobezariusyou just rotate your identity14:01:06
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
so I guess deprecate initramfs and go back to initrd :D
no but we can just fix her
14:01:13
@arianvp:matrix.orgArian
In reply to @emilazy:matrix.org
and I guess we don't need the fancy bind mount stuff because the daemon isn't running in stage 1 anyway?
systemd does exactly this fancy bind mount stuff
14:01:20
@arianvp:matrix.orgArianbut for /usr14:01:24
@emilazy:matrix.orgemilyfinally the option names will be correct again14:01:29
@arianvp:matrix.orgArianhttps://github.com/systemd/systemd/blob/facc9439a76b4c3a5c273c71bd7a676e4c74778c/src/core/main.c#L1871-L188414:01:50
@emilazy:matrix.orgemilyI mean, including the part where there's a secret writable version?14:02:27
@emilazy:matrix.orgemily I assume systemd has no need to write to /usr unlike the Nix daemon 14:02:27
@emilazy:matrix.orgemily(but like I said I guess irrelevant since running the daemon in stage 1 is nuts)14:02:39
@raitobezarius:matrix.orgraitobezarius(actually)14:02:53
@arianvp:matrix.orgArian me sweats I’m not supposed to run `nix-daemon in stage1? 14:02:56
@raitobezarius:matrix.orgraitobezarius(there's a good reason to do that: store verification)14:02:58
@raitobezarius:matrix.orgraitobezariusand people who does fancy immutable A/B schemas might do nix-build in stage 114:03:16
@raitobezarius:matrix.orgraitobezariusto obtain their upgrades14:03:18
@raitobezarius:matrix.orgraitobezariusbecause the userspace is under dm-verity14:03:27
@raitobezarius:matrix.orgraitobezariusthis is your last chance to swap the dm-verity by something else14:03:38
@emilazy:matrix.orgemilyI was thinking about that, but I figured anyone implementing such a scheme would take my statement as a compliment14:04:19

Show newer messages


Back to Room ListRoom Version: 6