!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

574 Members
NixOS ❤️ systemd158 Servers

Load older messages


SenderMessageTime
7 Feb 2025
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgsure17:58:54
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgbut if upstream defaults to true, then we need to disable it in stage 1, right?17:59:41
@arianvp:matrix.orgArianif stage-1 doesn’t have auditing enabled (doesn’t ship auditd; and also journald doesn’t enable it) then the audit logs will just buffer in ak ernel buffer17:59:44
@arianvp:matrix.orgArianyeh good point. but I don’t think we ship the socket in stage-1 which means the whole functionality is disabled18:00:03
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgah ok that'll do then18:00:15
@arianvp:matrix.orgArianI can fix that too; but then will also have to default Audit=null in the stage-1 kernel config18:00:29
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgyea best leave stage 1 out of it entirely if we can18:00:45
@arianvp:matrix.orgArianhow is the stage-1 journal configured anyway? if at all?18:00:50
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgit's not :P18:00:56
@arianvp:matrix.orgArianthen I suggest we just don’t ship the socket in stage-118:01:11
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgthough I think there's an open issue about maybe duplicating the stage 2 config in stage 118:01:15
@arianvp:matrix.orgArian(which I think is already the case today?)18:01:30
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgYea, I think we currently don't ship that socket and I agree we probably shouldn't18:01:47
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgso no action required, it seems18:02:15
@arianvp:matrix.orgAriangood callout though18:02:24
@terrorjack:matrix.orgterrorjack joined the room.22:46:14
8 Feb 2025
@terrorjack:matrix.orgterrorjack set a profile picture.02:24:25
@terrorjack:matrix.orgterrorjack removed their profile picture.02:24:59
@marcel:envs.net@marcel:envs.net joined the room.20:27:51
9 Feb 2025
@informatic:hackerspace.plinfowski joined the room.22:34:51
@tired:fairydust.space@tired:fairydust.space left the room.22:50:18
11 Feb 2025
@arianvp:matrix.orgArian hmm I wanna try to get systemd-vmspawn work 11:57:38
@arianvp:matrix.orgArian

it looks for firmware config in /usr/share/qemu/firmware and /etc/qemu/firmware

which obviously doesn’t work. but I have two options here:

  1. Make it in NixOS config to re-expose ${qemu}/share/qemu to /etc/qemu
  2. Patch systemd and add a dependency on qemu
11:59:20
@arianvp:matrix.orgArianoption 1 seems better right? it’s calling qemu as a binary — it just needs to be able to discover the configs shipped with qemu11:59:45
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgDepends on if you want to use this within the nix build sandbox, I guess12:02:01
@k900:0upti.meK900Can you not give it a firmware at runtime?12:02:08
@k900:0upti.meK900Also IIRC libvirt does something like that already with /run/libvirt/firmware12:03:00
@k900:0upti.meK900So maybe there should be one standard place for that12:03:10
@arianvp:matrix.orgArianyeh there’s a —firmware argumentb12:03:41
@arianvp:matrix.orgArianbut by default it points to /etc/qemu/firmware12:03:50

Show newer messages


Back to Room ListRoom Version: 6