!PSmBFWNKoXmlQBzUQf:helsinki-systems.de

Stage 1 systemd

87 Members
systemd in NixOs's stage 1, replacing the current bash tooling https://github.com/NixOS/nixpkgs/projects/5128 Servers

Load older messages


SenderMessageTime
1 Jun 2023
@hexa:lossy.network@hexa:lossy.networkwow, yeah!11:56:08
@elvishjerricco:matrix.org@elvishjerricco:matrix.org Arian: my intention is that systemd initrd is still considered experimental in 23.05, and that it will (hopefully) reach stability for 23.11, with a slight possibility of becoming default in 24.05 11:57:37
@arianvp:matrix.orgArianWe could announce it as experimental? :D11:57:56
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgIf that warrants an announcement in 23.05, then cool :P11:57:57
@arianvp:matrix.orgArianI think so11:58:02
@elvishjerricco:matrix.org@elvishjerricco:matrix.org
In reply to @janne.hess:helsinki-systems.de
Since it's likely that somebody has already tried: Does anyone know if there's a systemd-cryptenroll way to use fido2+password? In a way where I need both to unlock?
So the only reason it supports a passphrase for the tpm is because it can literally pass the passphrase to the tpm and let it control the security
12:07:52
@raphi:tapesoftware.net@raphi:tapesoftware.net changed their display name from raphi to raphi (element unread channel fix when).13:03:16
@lukegb:zxcvbnm.ninjalukegb (he/him)Can you set a PIN on a FIDO2 key you use for systemd-cryptenroll or does it not support that14:27:54
@lukegb:zxcvbnm.ninjalukegb (he/him)Admittedly that's *for the entire authenticator* and not just that credential but still14:29:16
@elvishjerricco:matrix.org@elvishjerricco:matrix.org lukegb (he/him): According to man systemd-cryptenroll, there's --fido2-with-client-pin=BOOL 14:29:23
2 Jun 2023
@charles:computer.surgeryCharles ⚡️
In reply to @charles:computer.surgery
it just kinda started happening
well, it just kinda stopped happening
20:05:57
@charles:computer.surgeryCharles ⚡️so that's cool i guess20:06:00
@ckie:ckie.dev@ckie:ckie.dev changed their display name from ckie (they/them; limited keyboard usage, voice preferred) to ckie (they/them).22:15:27
4 Jun 2023
@mberndt:matrix.org@mberndt:matrix.org left the room.11:56:53
5 Jun 2023
@nikstur:matrix.org@nikstur:matrix.org I just came across something curious: I'm currently building a custom kernel for an Nvidia BlueField2 and when I try to boot it with the systemd initrd, it fails to load the overlay module, giving me this error: overlay: module has no symbols (stripped?). When I use the legacy initrd, it is able to load the module. Could this happen because of the way makeInitrdNG works? 12:25:12
@elvishjerricco:matrix.org@elvishjerricco:matrix.org

Could this happen because of the way makeInitrdNG works?

That would be pretty surprising, but I have no idea

12:26:14
@elvishjerricco:matrix.org@elvishjerricco:matrix.org we copy the whole modulesClosure derivation in 12:26:23
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.de
In reply to @nikstur:matrix.org
I just came across something curious: I'm currently building a custom kernel for an Nvidia BlueField2 and when I try to boot it with the systemd initrd, it fails to load the overlay module, giving me this error: overlay: module has no symbols (stripped?). When I use the legacy initrd, it is able to load the module. Could this happen because of the way makeInitrdNG works?
we have the same issue on rpi4
12:26:30
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.desolution is to disable stripping12:26:35
@nikstur:matrix.org@nikstur:matrix.orgIs there an issue for that already?12:26:45
@nikstur:matrix.org@nikstur:matrix.orgI guess its an AARCH64 thing then12:26:53
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.de boot.initrd.systemd.strip 12:26:55
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.deI don't think so, we thought it was a random oddity with our kernel12:27:05
@elvishjerricco:matrix.org@elvishjerricco:matrix.orghuh, how am I only just now realizing I never enabled systemd initrd on my two rpi cm4s....12:27:58
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgMaybe I tried it, experienced this, disabled it, and forgot about it :P12:28:13
@nikstur:matrix.org@nikstur:matrix.org
In reply to @janne.hess:helsinki-systems.de
I don't think so, we thought it was a random oddity with our kernel
Mhmm, might be worth looking into... another time
12:28:56
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.de
In reply to @nikstur:matrix.org
Mhmm, might be worth looking into... another time
Once iscsi support is there i can also try it on our mac
12:29:23
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgis iscsi going to be particularly difficult? I don't know what all is involved in that one12:30:09
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.deI don't think so, the main blocker was networking support12:30:57
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgah, cool12:31:15

Show newer messages


Back to Room ListRoom Version: 6