| 3 Oct 2022 |
@oxalica:matrix.org | I'm still waiting for https://github.com/NixOS/nixpkgs/pull/189676 for non-password LUKS unlocking | 13:45:46 |
| spacesbot - keeps a log of public NixOS channels joined the room. | 14:25:43 |
| 4 Oct 2022 |
Arian | oh thanks for the poke | 07:03:02 |
Arian | I agree with that the increase in initrd size is worth it | 07:03:33 |
Arian | lets merge once rebased | 07:03:39 |
Arian | I can press the button for you today | 07:04:09 |
Zhaofeng Li | Ok, I just added the FIDO2 test by oxalica. There is one weird thing that I noticed, but other than that the PR seems ready to go. | 08:40:22 |
flokli | We can't really put this as a blocker for the release. Feature parity is quite off still, no? | 20:51:28 |
flokli | (in reply to Arian | 20:51:45 |
@elvishjerricco:matrix.org | flokli: I don't think we're talking about blocking the release on systemd stage 1 being default or anything. Just unhiding the docs for now | 20:54:47 |
@elvishjerricco:matrix.org | I don't want systemd stage 1 to be default until the docs have been unhidden for at least one release | 20:55:14 |
@elvishjerricco:matrix.org | but feature parity is basically just missing the fancy luks stuff and networking, so I feel fairly comfortable unhiding docs this release, assuming we can get the two PRs for those things merged by next release | 20:56:03 |
@elvishjerricco:matrix.org | basically I just want it to go from "experimental" status to "beta" status | 20:57:23 |
flokli | Yeah, unhiding the docs is probably something that can be done before the release, if they're "ready enough", and what's still not supported is documented somewhere accessible enough | 21:04:07 |
@elvishjerricco:matrix.org | Yea the work required it's non-negligible. We've got some docs that need improvement and (IMO) we need to avoid duplicating all the systemd docs yet again. | 21:05:08 |
@elvishjerricco:matrix.org | But it's not a ton of work | 21:05:16 |
flokli | I'm worried figuring out all the small bits to get the last 10% to work will be much more work than expected | 21:06:03 |
flokli | Like, networking, root on NFS/iso/... | 21:06:20 |
@elvishjerricco:matrix.org | I think we're very close to already being there. | 21:06:25 |
@elvishjerricco:matrix.org | Like on the networking PR I commented the remaining open questions and they're not far fetched | 21:06:50 |
flokli | There's so much domain specific knowledge hacked into brittle shell scripts, with not too much test coverage | 21:07:03 |
@elvishjerricco:matrix.org | I think someone is even using NFS root right now | 21:07:07 |
@elvishjerricco:matrix.org | colemickensIIRC? | 21:07:21 |
@elvishjerricco:matrix.org | we do also need to fix the iso though. Frankly I don't know how the current one functions at all lol | 21:07:50 |
colemickens | ElvishJerricco: I was, but have dropped it due to NFS issues and kept having issues rebasing your net PR. But yes, it did work just fine. | 21:07:53 |
Zhaofeng Li | I have one more question about #189676/cryptenroll: Should we include the tpm kernel modules by default, or should we drop this for this PR? | 21:08:01 |
colemickens | (and by fine, I mean it actually worked whereas the non-systemd-network has racey issues) | 21:08:08 |
colemickens | Zhaofeng Li I was just about to ask that, and about whether or not the fido2-device arg is needed or if it's implied to be auto? | 21:08:31 |
@elvishjerricco:matrix.org | In reply to @zhaofeng:zhaofeng.li I have one more question about #189676/cryptenroll: Should we include the tpm kernel modules by default, or should we drop this for this PR? yea so that's a pretty small thing in the grand scheme. Enough to block the PR on, but not enough to move systemd stage 1 into "documented and beta" status | 21:09:34 |
colemickens | I guess someone is likely to notice they need the modules as they enroll, so at least they wouldn't be likely to reboot and be unexpectedly having to enter their password due to modules missing. | 21:09:39 |