!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

192 Members
49 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
19 Jul 2021
@andi:kack.itandi-The current VM infrastructure doesnt allow that. You have to run an additional daemon 07:13:39
@mic92:nixos.devMic92 (Old)Could you run two VMs for that?11:48:55
@andi:kack.itandi-No, you have to pass a socket to one of the daemons to QEMUs CLI. Forking off the software TPM before starting QEMU is probably good enough in a sandboxed test. For interactive testing you want more process control.11:49:44
@mic92:nixos.devMic92 (Old)There is some bridging possible with vsockets, but I guess it would get hacky11:50:04
@mic92:nixos.devMic92 (Old)Maybe socat?11:50:10
@andi:kack.itandi-Yeah, probably but not very elegant. Would be nicer to teach our test driver to take care of "sidecars"11:50:31
@mic92:nixos.devMic92 (Old)vsocket also need root with qemu I just remeber11:51:07
@mic92:nixos.devMic92 (Old)*remember11:51:12
@mic92:nixos.devMic92 (Old)It would be also nice for virtiofsd to have qemu side cars11:51:38
@andi:kack.itandi-yeah but that also requires root access IIRC11:51:58
@mic92:nixos.devMic92 (Old)Why because virtiofsd needs to change uids?11:53:58
@mic92:nixos.devMic92 (Old)Maybe there could be a uid mapping mode in virtiofsd to map some uid to uid 011:54:14
@mic92:nixos.devMic92 (Old)That would be enough for the nix store.11:54:24

Show newer messages


Back to Room ListRoom Version: 6