!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

169 Members
43 Servers

Load older messages


SenderMessageTime
18 Aug 2022
@florian:web3.foundation@florian:web3.foundation changed their profile picture.09:21:49
19 Aug 2022
@kayla.fire:matrix.orgkayla (she/they) changed their display name from kayla.fire to kayla (she/they).01:39:58
21 Aug 2022
@greaka:greaka.degreaka changed their display name from greaka ⚡️ to greaka .09:25:58
23 Aug 2022
@callmeecho:matrix.orgEcho joined the room.00:50:12
24 Aug 2022
@tinybronca:sibnsk.net@tinybronca:sibnsk.net changed their display name from tinybronca to underpantsgnome.23:04:15
30 Aug 2022
@aruzeta:matrix.org@aruzeta:matrix.org joined the room.14:43:03
@aruzeta:matrix.org@aruzeta:matrix.org left the room.14:55:33
2 Sep 2022
@me:linj.techlinj joined the room.12:43:36
4 Sep 2022
@raitobezarius:matrix.orgraitobezariushttps://github.com/NixOS/nixpkgs/pull/18967613:31:03
5 Sep 2022
@grahamc:nixos.org@grahamc:nixos.orgattempt #3 :x 01:22:12
@ronnypfannschmidt:matrix.org@ronnypfannschmidt:matrix.org joined the room.06:02:13
7 Sep 2022
@alexandre:iooss.fr@alexandre:iooss.fr joined the room.09:40:54
11 Sep 2022
@ronnypfannschmidt:matrix.org@ronnypfannschmidt:matrix.org changed their profile picture.21:27:04
14 Sep 2022
@elvishjerricco:matrix.orgElvishJerricco joined the room.23:27:09
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: So moving over here because it seems more relevant: That patch doesn't seem to apply to NixOS. Based on the Loaded initrd from command line option message you see when booting with systemd-boot, that code path in that patch doesn't seem to measure the initrd 23:28:25
@elvishjerricco:matrix.orgElvishJerriccowhich is odd. I dunno why you'd only measure one of those two branches. Either it's measured elsewhere or this is a kernel bug23:30:45
@elvishjerricco:matrix.orgElvishJerriccoThough honestly I guess it doesn't matter. The attacker can always override the cmdline if you're not using a UKI anyway. So UKI it is23:53:37
15 Sep 2022
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @elvishjerricco:matrix.org
Zhaofeng Li: So moving over here because it seems more relevant: That patch doesn't seem to apply to NixOS. Based on the Loaded initrd from command line option message you see when booting with systemd-boot, that code path in that patch doesn't seem to measure the initrd
Wow, that's certainly very weird. What are those two code paths?
01:16:07
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: This branch does measure it, but this branch doesn't, which seems to be the one we hit with nixos 01:18:00
@zhaofeng:zhaofeng.liZhaofeng LiAh, so supplying initrd= via the cmdline doesn't trigger the measurement, awkward01:25:19
@elvishjerricco:matrix.orgElvishJerriccoand I can't imagine why they wouldn't want to measure it. It seems perfectly possible there01:25:40
@elvishjerricco:matrix.orgElvishJerricco Like, just move the measurement call to after the if else if block or something 01:26:25
@zhaofeng:zhaofeng.liZhaofeng LiNice opportunity to cook up a patch, it seems 👀01:28:36
@zhaofeng:zhaofeng.liZhaofeng LiAlso an opportunity to move to using the initrd directive in systemd-boot instead of adding the initrd= in the cmdline01:29:09
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: We do use the initrd directive. But (and I can't remember where I read this), I believe systemd-boot just converts that directive into an initrd= cmdline option. 01:31:41
@zhaofeng:zhaofeng.liZhaofeng LiIf this is the case, the systemd-boot docs are dangerously incorrect. This is very surprising.01:33:00
@elvishjerricco:matrix.orgElvishJerriccoThat's what this wiki says: https://www.freedesktop.org/wiki/Software/systemd/systemd-boot/01:33:48
@elvishjerricco:matrix.orgElvishJerriccoWhere are the docs wrong about this?01:34:05
@elvishjerricco:matrix.orgElvishJerriccoAnd yea, my boot entries on my desktop have an initrd directive, but obviously I still get that "Loaded initrd from command line option" message01:34:39
@zhaofeng:zhaofeng.liZhaofeng LiI mean, the docs are wrong about initrd being measured in PCR 9 under normal usecases (the initrd directive)01:36:47

Show newer messages


Back to Room ListRoom Version: 6