!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

626 Members
NixOS ❤️ systemd170 Servers

Load older messages


SenderMessageTime
26 Sep 2021
@jkarlson:kapsi.fiEmil Karlsonwell I guess changing defaults like that is not sane17:01:23
@mic92:nixos.devMic92Well was this possible before already?17:08:34
@jkarlson:kapsi.fiEmil Karlsonyes, but less convenient, also things like sudo do not work17:08:55
@mic92:nixos.devMic92 * Well was this not possible before already?17:09:07
@mic92:nixos.devMic92I think there was a different kernel fix that allow to have per usernamespace setuid binaries before.17:09:42
@mic92:nixos.devMic92 * I think there was a different kernel fix that allowed to have per usernamespace setuid binaries before.17:09:53
@mic92:nixos.devMic92But it makes uid migration cheaper.17:10:07
@jkarlson:kapsi.fiEmil Karlsonmaybe, but sudo checks the libs, it starts properly suided17:10:24
@jkarlson:kapsi.fiEmil Karlsonyou can fix that by copying the libs, but this is probably not the only broken thing17:11:02
@jkarlson:kapsi.fiEmil Karlsonthere is nothing suid in the nix/store anyway afaik17:11:43
@jkarlson:kapsi.fiEmil Karlsonalso having uids mapped guarantees systemd-nspawn can pick non-colliding uid ranges17:13:16
@jkarlson:kapsi.fiEmil Karlsondynamically17:13:33
28 Sep 2021
@eyjhb:eyjhb.dkeyJhb joined the room.13:42:43
@eyjhb:eyjhb.dkeyJhbI've added three new options to networkd https://github.com/NixOS/nixpkgs/pull/139754, as they were just merged with the new systemd update13:44:24
@eyjhb:eyjhb.dkeyJhbIf anyone can look at it, it would be great :)13:44:33
@andi:kack.itandi- eyJhb: I would argue that DUIDType and DIDRawData could need some input validation but I won't -1 if it doesn't get those... 13:56:54
@eyjhb:eyjhb.dkeyJhb andi-: it is taken from the DHCPv4 section, which has none as well :p So I think that should be a separate PR to add for both of them :) 13:57:55
@andi:kack.itandi-The link-layer-time looks daunting to verify13:57:59
@eyjhb:eyjhb.dkeyJhb andi-: does it make sense, that it should be a seperate PR? To add it for both? :) 14:08:44
@andi:kack.itandi-Yeah if you want to tackle that.14:08:58
@andi:kack.itandi-I am fine with the current PR as is14:09:03
@andi:kack.itandi-generally I'd love if we did perform more validation on the Nix side (with escape hatches?).14:09:23
@andi:kack.itandi-The last thing I want is a system without network :D14:09:30
@eyjhb:eyjhb.dkeyJhbI have no idea to do any validation on the DUIDType + DUIDRawData :p I might be able to look into it. But unsure how well that would go14:09:46
@eyjhb:eyjhb.dkeyJhbOhh come on, a system without networking? THat's fun! :D14:09:55
@andi:kack.itandi-I just realized that with v249 the systemd-wait-online program behaves different and now I had to explicitly disable DHCP/AcceptRA on a bond interface where I didn't configure anything.14:10:33
@eyjhb:eyjhb.dkeyJhbI have some weird issue with a tempoary address w/ IPv6. But I am quite sure it's just my ISP screwing around....14:15:36
@andi:kack.itandi-it is always your weird ISP14:17:22
@eyjhb:eyjhb.dkeyJhb Well, you know first hand that my ISP is doing some weird stuff andi- :D 14:18:06
@khalilsantana:matrix.orgkhalil joined the room.15:03:13

There are no newer messages yet.


Back to Room ListRoom Version: 6