| 27 Nov 2022 |
@me:linj.tech | but now, it is stopped after stage 2 | 23:29:54 |
@elvishjerricco:matrix.org | That's not quite accurate | 23:30:22 |
@elvishjerricco:matrix.org | Stage 1 has two big systemd transactions. First is initrd.target, and after that there's a service called initrd-cleanup.service that does systemctl isolate initrd-switch-root.target, which is the second transaction. This causes everything else to be stopped | 23:31:49 |
@elvishjerricco:matrix.org | So that second transaction is in some ways very similar to system shutdown | 23:32:08 |
@elvishjerricco:matrix.org | Any services in initrd that aren't supposed to be stopped by this (e.g. plymouth) need to either be wanted by initrd-switch-root.target, or have IgnoreOnIsolate=true | 23:33:37 |
Arian | In reply to @me:linj.tech my keyfile has a pre-defined key in it Then don't use /dev/urandom | 23:34:18 |
Arian | But the keyfile :) | 23:35:03 |
@me:linj.tech | interesting, will try that later | 23:35:07 |
@elvishjerricco:matrix.org | In reply to @me:linj.tech emm, what I want is somewhat weird: generate a keyfile on the fly for luks without storing that keyfile in initrd I am curious what exactly you mean by this. If it's not randomly generated, then where is this key file you're actually trying to use? | 23:36:07 |
@me:linj.tech | In reply to @elvishjerricco:matrix.org I am curious what exactly you mean by this. If it's not randomly generated, then where is this key file you're actually trying to use? mkdir -p ${luksKeyFileDir}
mount -t ramfs none ${luksKeyFileDir}
echo -n password > ${luksKeyFile}
chown 0:0 ${luksKeyFile}
chmod 0400 ${luksKeyFile}
| 23:37:14 |
@elvishjerricco:matrix.org | so it is stored in the initrd? Just in the form of a script? | 23:37:54 |
@me:linj.tech | I want to run that before unlocking luks | 23:37:58 |
@me:linj.tech | yeah | 23:38:53 |
| 30 Nov 2022 |
| @chillermiller3:matrix.org left the room. | 05:29:40 |
| 1 Dec 2022 |
| @jkarlson:kapsi.fi changed their display name from Emil Karlson to Emil Thorsoe. | 08:20:44 |
| @jkarlson:kapsi.fi changed their display name from Emil Thorsoe to Emil Thorsøe. | 08:25:10 |
| @hexa:lossy.network changed their display name from hexa to hexa (22.11 now). | 13:08:44 |
| @hexa:lossy.network changed their display name from hexa (22.11 now) to hexa. | 14:38:33 |
| 5 Dec 2022 |
@janne.hess:helsinki-systems.de | ElvishJerricco: did we have stripping enabled by default on 22.05 already? | 18:29:44 |
@elvishjerricco:matrix.org | Janne Heß: I don't remember how that panned out off the top of my head. I think we enabled stripping by default for initrd but not for shutdown ramfs? | 18:31:13 |
@janne.hess:helsinki-systems.de | Yeah that wasn't too great for some reason | 18:31:28 |
@janne.hess:helsinki-systems.de | My Pi didn't boot because it couldn't load dm_mod because of: https://linux-tips.com/t/how-to-strip-linux-kernel-modules/472 | 18:31:40 |
@janne.hess:helsinki-systems.de | (only took me 2 days to debug this - the kernel even hinted what could be the issue) | 18:31:55 |
@elvishjerricco:matrix.org | Yea we didn't want binutils in the runtime closure of a system. It's not needed at runtime for initrd but it would be for shutdown ramfs | 18:32:38 |
@janne.hess:helsinki-systems.de | hmm looks like we have always stripped, there was only a PR that made that fact configurable by Linux Hackerman | 18:34:26 |
@janne.hess:helsinki-systems.de | this: https://github.com/NixOS/nixpkgs/commit/6fc909a1cc89b32c9bc27d69da6333b8a0d4b87e | 18:35:16 |
@elvishjerricco:matrix.org | In reply to @janne.hess:helsinki-systems.de this: https://github.com/NixOS/nixpkgs/commit/6fc909a1cc89b32c9bc27d69da6333b8a0d4b87e Right, and because the STRIP env variable isn't set when generating the shutdown ramfs, it doesn't depend on strip | 18:37:35 |
| 6 Dec 2022 |
@mlyx:matrix.org | ElvishJerricco: How to add postMountCommands in systemd initrd? It is very useful when kexec into a new kernel. https://github.com/nix-community/nixos-images/blob/36056317a6b32d4bf3377037c63bcac4d47bbc12/nix/kexec-installer/module.nix#L126 | 02:19:09 |
@mlyx:matrix.org | * ElvishJerricco: How to add postMountCommands in systemd initrd? It is very useful when kexec into a new kernel and initrd. https://github.com/nix-community/nixos-images/blob/36056317a6b32d4bf3377037c63bcac4d47bbc12/nix/kexec-installer/module.nix#L126 | 02:20:47 |
@elvishjerricco:matrix.org | mlyx: You would make a new initrd systemd service that has wantedBy = ["initrd.target"];. You also want the service to be ordered after file systems are mounted, but if you don't have DefaultDependencies=no, then it'll have After=local-fs.target by default anyway. But eventually we're going to change it so systemd-initrd uses initrd-fs.target like we're supposed to, which services don't get ordered after by default | 02:23:40 |