!PSmBFWNKoXmlQBzUQf:helsinki-systems.de

Stage 1 systemd

86 Members
systemd in NixOs's stage 1, replacing the current bash tooling https://github.com/NixOS/nixpkgs/projects/5128 Servers

Load older messages


SenderMessageTime
1 Jun 2023
@elvishjerricco:matrix.org@elvishjerricco:matrix.org Lily Foster: What creates /dev/nixos/root? 00:00:25
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgThat's not a normal path for a LUKS device00:00:30
@elvishjerricco:matrix.org@elvishjerricco:matrix.org Charles ⚡️: that's... interesting. I have no idea what that means 00:01:23
@charles:computer.surgeryCharles ⚡️cool lol00:01:35
@charles:computer.surgeryCharles ⚡️i'm running a few-days-old nixpkgs so i'll try updating and see if it goes away00:01:48
@charles:computer.surgeryCharles ⚡️but this wasn't happening in association with another upgrade or bios change or anything00:02:07
@charles:computer.surgeryCharles ⚡️it just kinda started happening00:02:10
@charles:computer.surgeryCharles ⚡️same behavior after updating00:11:54
@lily:lily.flowers@lily:lily.flowers
In reply to @elvishjerricco:matrix.org
That's not a normal path for a LUKS device
It's an LVM inside LUKS. Which was maybe not my best idea and I now realize is probably related to why I'm encountering timeouts
00:23:42
@elvishjerricco:matrix.org@elvishjerricco:matrix.org Lily Foster: Oh, no that seems entirely reasonable. I still don't understand why that would lead to timeouts though... 00:24:38
@lily:lily.flowers@lily:lily.flowersSee disko here: https://github.com/lilyinstarlight/foosteros/blob/ab117ba2dd69d77fffc6384c1ace1f3227221490/hosts/bina/disks.nix00:24:53
@lily:lily.flowers@lily:lily.flowersFor disk layout00:24:57
@elvishjerricco:matrix.org@elvishjerricco:matrix.org so as for the ISO stuff I wanted to look into this week, turns out we do something really kinda weird? 02:35:08
@elvishjerricco:matrix.org@elvishjerricco:matrix.org We use root= on the cmdline for... /iso, not / 02:36:23
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgis that normal for live cd images?02:36:37
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgbecause I hate it02:36:40
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.de Since it's likely that somebody has already tried: Does anyone know if there's a systemd-cryptenroll way to use fido2+password? In a way where I need both to unlock? 09:56:49
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.deah looks like it's not possible: https://github.com/systemd/systemd/issues/2108810:29:02
@lily:lily.flowers@lily:lily.flowers
In reply to @elvishjerricco:matrix.org
is that normal for live cd images?
That specifically I don't think is normal. We are a tad special there. But doing special things for ISO images is (unfortunately) normal
10:35:53
@arianvp:matrix.orgArianwe missed announcing systemd-initrd in the NixOS 23.05 release notes!11:55:00
@arianvp:matrix.orgAriando we still want to add it?11:55:04
@hexa:lossy.network@hexa:lossy.networkwow, yeah!11:56:08
@elvishjerricco:matrix.org@elvishjerricco:matrix.org Arian: my intention is that systemd initrd is still considered experimental in 23.05, and that it will (hopefully) reach stability for 23.11, with a slight possibility of becoming default in 24.05 11:57:37
@arianvp:matrix.orgArianWe could announce it as experimental? :D11:57:56
@elvishjerricco:matrix.org@elvishjerricco:matrix.orgIf that warrants an announcement in 23.05, then cool :P11:57:57
@arianvp:matrix.orgArianI think so11:58:02
@elvishjerricco:matrix.org@elvishjerricco:matrix.org
In reply to @janne.hess:helsinki-systems.de
Since it's likely that somebody has already tried: Does anyone know if there's a systemd-cryptenroll way to use fido2+password? In a way where I need both to unlock?
So the only reason it supports a passphrase for the tpm is because it can literally pass the passphrase to the tpm and let it control the security
12:07:52
@raphi:tapesoftware.net@raphi:tapesoftware.net changed their display name from raphi to raphi (element unread channel fix when).13:03:16
@lukegb:zxcvbnm.ninjalukegb (he/him)Can you set a PIN on a FIDO2 key you use for systemd-cryptenroll or does it not support that14:27:54
@lukegb:zxcvbnm.ninjalukegb (he/him)Admittedly that's *for the entire authenticator* and not just that credential but still14:29:16

Show newer messages


Back to Room ListRoom Version: 6