!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

612 Members
NixOS ❤️ systemd173 Servers

Load older messages


SenderMessageTime
4 Mar 2025
@arianvp:matrix.orgArian So when ProtectSystem is set in system.conf then initrd remounts /usr as read-only. I wonder if we should patch that behaviour in pid1 to do the same for /nix/store ? 13:55:29
@arianvp:matrix.orgArian * So when ProtectSystem is set in system.conf then pid1 remounts /usr as read-only. I wonder if we should patch that behaviour in pid1 to do the same for /nix/store ? 13:55:42
@raitobezarius:matrix.orgraitobezarius isn't /nix/store already RO? 13:57:01
@emilazy:matrix.orgemilydon't we already do a fancy bind-mount thing for the store?13:57:30
@emilazy:matrix.orgemilyor are you proposing we use systemd to do it?13:57:36
@arianvp:matrix.orgArian/nix/store is not RO in initrd13:58:27
@arianvp:matrix.orgArianit’s writeable13:58:29
@emilazy:matrix.orgemilyyikes13:58:42
@raitobezarius:matrix.orgraitobezarius no problem: https://gerrit.lix.systems/c/lix/+/2690 13:59:05
@arianvp:matrix.orgArianit’s just /sysroot/nix/store that we remount as read-only13:59:06
@emilazy:matrix.orgemilyand I guess we don't need the fancy bind mount stuff because the daemon isn't running in stage 1 anyway?13:59:07
@emilazy:matrix.orgemilytypo: "Flancher" 😆13:59:42
@raitobezarius:matrix.orgraitobezariusthis is the 2nd time someone told me13:59:50
@raitobezarius:matrix.orgraitobezariusi am fixing it now13:59:51
@raitobezarius:matrix.orgraitobezariusElvish never told me the typo btw13:59:54
@raitobezarius:matrix.orgraitobezariusdone14:00:06
@arianvp:matrix.orgAriancpio archives preserve fsverity info?14:00:07
@arianvp:matrix.orgArianI assume they do?14:00:12
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
cpio archives preserve fsverity info?
actually they probably don't
14:00:22
@arianvp:matrix.orgArian then this doesn’t work :D 14:00:28
@raitobezarius:matrix.orgraitobezariusfsverity exist only for ext4 & f2fs iirc14:00:33
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
then this doesn’t work :D
yes but you know what is the fix
14:00:37
@emilazy:matrix.orgemilyit's already been hashed into immutable metadata and verity would complain, easier to just get a legal name change14:00:39
@arianvp:matrix.orgArianso I guess deprecate initramfs and go back to initrd :D14:01:00
@raitobezarius:matrix.orgraitobezariusthis is how identity leaks should be handled14:01:02
@raitobezarius:matrix.orgraitobezariusyou just rotate your identity14:01:06
@raitobezarius:matrix.orgraitobezarius
In reply to @arianvp:matrix.org
so I guess deprecate initramfs and go back to initrd :D
no but we can just fix her
14:01:13
@arianvp:matrix.orgArian
In reply to @emilazy:matrix.org
and I guess we don't need the fancy bind mount stuff because the daemon isn't running in stage 1 anyway?
systemd does exactly this fancy bind mount stuff
14:01:20
@arianvp:matrix.orgArianbut for /usr14:01:24
@emilazy:matrix.orgemilyfinally the option names will be correct again14:01:29

Show newer messages


Back to Room ListRoom Version: 6