Re: [systemd-devel] systemd-shutdown disarms hardware watchdog when finished

2024-05-29 Thread Luca Boccassi
On Wed, 29 May 2024 at 11:01, Andreas Svensson wrote: > > Hello, > > I have a system that should keep the hardware watchdog active while > rebooting the system. It has worked fine up to systemd version v254. > > I noticed that since systemd version v254 my system stops the hardware > watchdog

Re: [systemd-devel] systemd-shutdown disarms hardware watchdog when finished

2024-05-29 Thread Andreas Svensson
On 5/29/24 11:22, Lennart Poettering wrote: On Mi, 29.05.24 10:51, Andreas Svensson (andreas.svens...@axis.com) wrote: Hello, I have a system that should keep the hardware watchdog active while rebooting the system. It has worked fine up to systemd version v254. I noticed that since systemd

Re: [systemd-devel] systemd-shutdown disarms hardware watchdog when finished

2024-05-29 Thread Lennart Poettering
On Mi, 29.05.24 10:51, Andreas Svensson (andreas.svens...@axis.com) wrote: > Hello, > > I have a system that should keep the hardware watchdog active while > rebooting the system. It has worked fine up to systemd version v254. > > I noticed that since systemd version v254 my system stops the

[systemd-devel] systemd-shutdown disarms hardware watchdog when finished

2024-05-29 Thread Andreas Svensson
Hello, I have a system that should keep the hardware watchdog active while rebooting the system. It has worked fine up to systemd version v254. I noticed that since systemd version v254 my system stops the hardware watchdog after systemd-shutdown completes. I think it's the

[systemd-devel] systemd prerelease 256-rc3

2024-05-22 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v256-rc3.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] systemd-run unset OnFailure property

2024-05-16 Thread Etienne Champetier
I'm trying to add a global OnFailure= to all the services and excluding some non important services with /dev/null symlinks Now when using systemd-run in some cases I also don't want to run the OnFailure handler I tried (and multiple small variations) ``` systemd-run --unit=test

[systemd-devel] systemd prerelease 256-rc2

2024-05-14 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v256-rc2.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Lennart Poettering
On Fr, 26.04.24 09:49, Neal Gompa (ngomp...@gmail.com) wrote: > > Well, people moved off split-usr quite successfully, which is a bigger > > feat than cleaning up the /boot/efi/ mess I'd say. > > > > Fedora is currently merging /usr/bin/ and /usr/sbin/, which I am pretty > > sure is a bigger

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Lennart Poettering
On Fr, 26.04.24 09:47, Neal Gompa (ngomp...@gmail.com) wrote: > > > > * systemd-gpt-auto-generator will stop generating units for ESP > > > > or > > > > XBOOTLDR partitions if it finds mount entries for or below > > > > the /boot/ > > > > or /efi/ hierarchies in

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Neal Gompa
On Fri, Apr 26, 2024 at 9:46 AM Lennart Poettering wrote: > > On Fr, 26.04.24 10:39, Dan Nicholson (d...@endlessos.org) wrote: > > > On Fri, Apr 26, 2024 at 10:11 AM Adrian Vovk wrote: > > > > > > Perhaps Fedora can be adjusted to follow the BLS's recommended mount > > > points? > > > > The

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Neal Gompa
On Fri, Apr 26, 2024 at 9:41 AM Lennart Poettering wrote: > > On Do, 25.04.24 18:52, Neal Gompa (ngomp...@gmail.com) wrote: > > > > * systemd-gpt-auto-generator will stop generating units for ESP or > > > XBOOTLDR partitions if it finds mount entries for or below the > > >

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Lennart Poettering
On Fr, 26.04.24 10:39, Dan Nicholson (d...@endlessos.org) wrote: > On Fri, Apr 26, 2024 at 10:11 AM Adrian Vovk wrote: > > > > Perhaps Fedora can be adjusted to follow the BLS's recommended mount points? > > The problem with all of these type of "we've realized a better way and > the old way is

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Lennart Poettering
On Do, 25.04.24 18:52, Neal Gompa (ngomp...@gmail.com) wrote: > > * systemd-gpt-auto-generator will stop generating units for ESP or > > XBOOTLDR partitions if it finds mount entries for or below the > > /boot/ > > or /efi/ hierarchies in /etc/fstab. This is to

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Dan Nicholson
On Fri, Apr 26, 2024 at 10:11 AM Adrian Vovk wrote: > > Perhaps Fedora can be adjusted to follow the BLS's recommended mount points? The problem with all of these type of "we've realized a better way and the old way is obsolete" is that it's left as someone else's issue to actually change

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-26 Thread Adrian Vovk
systemd has been recommending against an arrangement like that for a long time now. These partitions are often fragile (read from bootloader code, or worse firmware! VFAT has no data integrity), and they really have no reason to be mounted unless they're about to be accessed. Stacking the mount

Re: [systemd-devel] systemd prerelease 256-rc1

2024-04-25 Thread Neal Gompa
On Thu, Apr 25, 2024 at 6:15 PM systemd tag bot wrote: > > A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the > tarball here: > > https://github.com/systemd/systemd/archive/v256-rc1.tar.gz > > NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production

[systemd-devel] systemd prerelease 256-rc1

2024-04-25 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v256-rc1.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] systemd-oomd kill a lot of process instead of one service

2024-03-04 Thread maxime . deroucy
Hello, I am running an uptodate archlinux, with gnome desktop. Please find the logs attached. In those logs we see that systemd-oomd is triggered, and select this scope for killing:

[systemd-devel] systemd journal remote filling disk with supposedly corrupted files

2024-02-26 Thread Wolfgang Scheicher
Hello, I'm trying to use systemd journal remote. Occasionally the system goes crazy, spams errors like this: systemd-journal-remote[]: File /var/log/journal/remote//remote-.journal corrupted or uncleanly shut down, renaming and replacing. When this happens, this leads to tens of 8MB .journal~

Re: [systemd-devel] systemd-pcrlock Failed to submit super PCR policy

2024-02-05 Thread Lennart Poettering
On Mo, 05.02.24 09:24, Dominick Grift (dominick.gr...@defensec.nl) wrote: Please run "SYSTEMD_LOG_LEVEL=debug systemd-pcrlock make-policy" from the command line, then file a github issue about this, and pastethe output there. Lennart -- Lennart Poettering, Berlin

[systemd-devel] systemd-pcrlock Failed to submit super PCR policy

2024-02-05 Thread Dominick Grift
systemd v255 Debian Testing Linux nimbus 6.6.13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.6.13-1 (2024-01-20) x86_64 GNU/Linux systemd-pcrlock Feb 04 20:00:02 nimbus audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=sys.id:sys.role:sys.subj:s0

Re: [systemd-devel] Systemd units complains about cgroup with 5.15.x kernel

2024-02-01 Thread Thierry Bultel
Dear Lennart, thanks for the tips. The distro is buildroot, that compiles systemd with " -Ddefault-hierarchy=unified ". Should I consider that the named kernel has incomplete cgroupsv2 support ? (How can I check that ?). I would need to cleanup the log before pasting it in a mail, but what I

Re: [systemd-devel] Systemd units complains about cgroup with 5.15.x kernel

2024-02-01 Thread Lennart Poettering
On Do, 01.02.24 16:30, Thierry Bultel (thierry.bul...@linatsea.fr) wrote: > Hi, > > I am using systemd v255, > and currently using a kernel vendor branch : > > g...@github.com:varigit/linux-imx.git > lf-5.15.y_var01 > imx_v7_defconfig > > I had no issue with the older 5.4 kernel. > > I have

[systemd-devel] Systemd units complains about cgroup with 5.15.x kernel

2024-02-01 Thread Thierry Bultel
Hi, I am using systemd v255, and currently using a kernel vendor branch : g...@github.com:varigit/linux-imx.git lf-5.15.y_var01 imx_v7_defconfig I had no issue with the older 5.4 kernel. I have verified that the kernel has the following options: CONFIG_DEVTMPFS=y CONFIG_CGROUPS=y

Re: [systemd-devel] Systemd-nspawn single process

2023-12-15 Thread Warex61 YTB
Hello, Thanks for the tip, I've taken a more recent version of systemd-nspawn and it now works. I now have another question: I want to set up a signle process. I have a problem on the network side, I want to launch my signle process by connecting it to a bridge. In the .nspawn file, in the

[systemd-devel] systemd 255 released

2023-12-06 Thread systemd tag bot
 A new, official systemd release has just  been  tagged . Please download the tarball here: https://github.com/systemd/systemd/archive/v255.tar.gz Changes since the previous release: Announcements of Future Feature Removals and Incompatible Changes: * Support for

[systemd-devel] systemd-pcrlock: what prevents unauthorized changes to the NV index?

2023-12-05 Thread Demi Marie Obenour
What prevents unauthorized changes to the NV index used by systemd-pcrlock? Is the secret key itself stored in the NV index, with the policy deciding who can read the key? Or does the policy on the NV index require that the policy established by systemd-pcrlock is itself satisfied before the NV

Re: [systemd-devel] systemd: questions about dbus dependency service

2023-12-04 Thread Lennart Poettering
On Mo, 04.12.23 13:01, Pintu Agarwal (pintu.p...@gmail.com) wrote: > Hi, > Any comments or suggestions on the below ? I already replied. https://lists.freedesktop.org/archives/systemd-devel/2023-November/049706.html Lennart -- Lennart Poettering, Berlin

Re: [systemd-devel] systemd: questions about dbus dependency service

2023-12-03 Thread Pintu Agarwal
Hi, Any comments or suggestions on the below ? On Tue, 28 Nov 2023 at 22:48, Pintu Agarwal wrote: > > Hi, > > I need some clarification about systemd services that are dependent on dbus > service. > > We have a service that depends on dbus.service, so our service has to be > started after

[systemd-devel] systemd prerelease 255-rc4

2023-12-01 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v255-rc4.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

Re: [systemd-devel] Systemd-nspawn single process

2023-12-01 Thread Lennart Poettering
On Fr, 01.12.23 14:03, Warex61 YTB (thomasdabou...@gmail.com) wrote: > Hello, > I would like to use systemd-nspawn to create a container that can launch a > single process as pid 1 and mount its configuration files. I want the > container to be as light as possible. Is there any way of creating a

[systemd-devel] Systemd-nspawn single process

2023-12-01 Thread Warex61 YTB
Hello, I would like to use systemd-nspawn to create a container that can launch a single process as pid 1 and mount its configuration files. I want the container to be as light as possible. Is there any way of creating a container using nspawn without using bootstrap ? For example, using this

Re: [systemd-devel] systemd: questions about dbus dependency service

2023-11-28 Thread Lennart Poettering
On Di, 28.11.23 22:48, Pintu Agarwal (pintu.p...@gmail.com) wrote: > Hi, > > I need some clarification about systemd services that are dependent on dbus > service. > > We have a service that depends on dbus.service, so our service has to be > started after dbus.socket and dbus.service. It's

[systemd-devel] systemd: questions about dbus dependency service

2023-11-28 Thread Pintu Agarwal
Hi, I need some clarification about systemd services that are dependent on dbus service. We have a service that depends on dbus.service, so our service has to be started after dbus.socket and dbus.service. But dbus.service comes after local-fs.target and sysinit.target. However, our service

[systemd-devel] Systemd-logind StopIdleSessionSec option ignored for multiplexed (control master) ssh sessions?

2023-11-28 Thread Juergen Salk
Hi, not sure if this is the right place to ask. If it's not then just ignore this post. systemd-logind has recently introduced an option StopIdleSessionSec which has become available in Rocky 8.7 and onward as well as in Rocky 9. >From logind.conf(5): StopIdleSessionSec= Specifies a timeout in

[systemd-devel] systemd-networkd code design documentation?

2023-11-27 Thread Muggeridge, Matt
Hi, As I start looking at the code, is there any design documentation for developers that describes systemd-networkd? Specifically, I'm looking for an overview of the data-flow when an IPv6 Router Advertisement is received, where it is processed and where it generates the reply. I'm slowly

[systemd-devel] systemd prerelease 255-rc3

2023-11-22 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v255-rc3.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] systemd prerelease 255-rc2

2023-11-15 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v255-rc2.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] systemd prerelease 255-rc1

2023-11-06 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v255-rc1.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

Re: [systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Marc
> In the past prior to systemd-resolve as a default solution the order I > think was followed. From what I understand windows > https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows- > server-2008-R2-and-2008/dd197552(v=ws.10) > prefers first server on the list (it doesn't

Re: [systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Marc
> > Obviously there are other solutions to the problem described above (eg > having multiple internal servers, although my experience was in the SOHO > environment where that would be excessive). If as Rafał says Windows > prioritises the first DNS option then I'm pretty sure that wasn't always

Re: [systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Mark Rogers
On Wed, 11 Oct 2023 at 09:37, Marc wrote: > Having 3 different nameservers reporting different results? > An example I have seen quite frequently is where there is an internal DNS which resolves local (internal) server resources and forwards anything else to an external server such as 8.8.8.8.

Re: [systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Marc
> > I hope this is the right mailing list to ask that kind of question. I'm > following what is recommended on github issue tracker: > https://github.com/systemd/systemd/issues/new/choose > If it's not - feel free to point me to a different place. > > I use azure ubuntu 20.04 build with

Re: [systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Rafał Jankowski
W dniu 2023-10-11 09:50, Marc napisał(a): I think this is not how resolv.conf was designed to be used. Are you 100% sure this is the only way to solve your issue? Having 3 different nameservers reporting different results? Can't you do something with views and sorting? What about just giving

[systemd-devel] systemd-resolve and name servers order

2023-10-11 Thread Rafał Jankowski
I hope this is the right mailing list to ask that kind of question. I'm following what is recommended on github issue tracker: https://github.com/systemd/systemd/issues/new/choose If it's not - feel free to point me to a different place. I use azure ubuntu 20.04 build with nameservers obtained

Re: [systemd-devel] systemd-tmpfiles service related queries

2023-10-02 Thread Mantas Mikulėnas
On Mon, Oct 2, 2023 at 2:36 PM Pintu Agarwal wrote: > Hi All, > > I have a doubt related to systemd-tmpfiles-setup.service. > This service is mentioned to be started after local-fs.target. > {{{ > After=local-fs.target systemd-sysusers.service > Before=sysinit.target shutdown.target > }}} > In

[systemd-devel] systemd-tmpfiles service related queries

2023-10-02 Thread Pintu Agarwal
Hi All, I have a doubt related to systemd-tmpfiles-setup.service. This service is mentioned to be started after local-fs.target. {{{ After=local-fs.target systemd-sysusers.service Before=sysinit.target shutdown.target }}} In this case this service takes only ~125ms. systemd-tmpfiles-setup.service

Re: [systemd-devel] systemd-nspawn/systemd.nspawn machinectl enable/start

2023-10-02 Thread Mantas Mikulėnas
Each nspawn container that's managed via machinectl is run as an instance of "systemd-nspawn@.service". Add a [Service] ExecStartPre= to the instance you need, using `systemctl edit` or similar. On Mon, Oct 2, 2023 at 1:37 AM Rob Ert wrote: > Hello all, > > As I have not been able to find an

[systemd-devel] systemd-nspawn/systemd.nspawn machinectl enable/start

2023-10-01 Thread Rob Ert
Hello all, As I have not been able to find an answer to my question after consulting man pages and google, I am turning to this mailing list. I have a systemd-nspawn os container that I have set to automatically start with machinectl enable. I would like to automatically have a bcachefs snapshot

Re: [systemd-devel] Systemd cgroup setup issue in containers

2023-09-29 Thread Lennart Poettering
On Fr, 29.09.23 10:53, Lewis Gaul (lewis.g...@gmail.com) wrote: > Hi systemd team, > > I've encountered an issue when running systemd inside a container using > cgroups v2, where if a container exec process is created at the wrong > moment during early startup then systemd will fail to move all

Re: [systemd-devel] Systemd cgroup setup issue in containers

2023-09-29 Thread Lewis Gaul
> Wouldn't it be better to have the container inform the host via NOTIFY_SOCKET (the Type=notify mechanism)? I believe systemd has had support for sending readiness notifications from init to a container manager for quite a while. > Use the notify socket and you'll get a notification back when

Re: [systemd-devel] Systemd cgroup setup issue in containers

2023-09-29 Thread Luca Boccassi
On Fri, 29 Sept 2023 at 12:00, Lewis Gaul wrote: > > Hi systemd team, > > I've encountered an issue when running systemd inside a container using > cgroups v2, where if a container exec process is created at the wrong moment > during early startup then systemd will fail to move all processes

Re: [systemd-devel] Systemd cgroup setup issue in containers

2023-09-29 Thread Mantas Mikulėnas
On Fri, Sep 29, 2023, 12:54 Lewis Gaul wrote: > Hi systemd team, > > I've encountered an issue when running systemd inside a container using > cgroups v2, where if a container exec process is created at the wrong > moment during early startup then systemd will fail to move all processes > into a

[systemd-devel] Systemd cgroup setup issue in containers

2023-09-29 Thread Lewis Gaul
Hi systemd team, I've encountered an issue when running systemd inside a container using cgroups v2, where if a container exec process is created at the wrong moment during early startup then systemd will fail to move all processes into a child cgroup, and therefore fail to enable controllers due

Re: [systemd-devel] systemd-repart /etc automount via discoverable partition specification

2023-09-11 Thread Nils Kattenbeck
On Mon, Sep 11, 2023 at 11:49 AM Lennart Poettering wrote: > > On Mo, 11.09.23 11:39, Nils Kattenbeck (nilskem...@gmail.com) wrote: > > > On Mon, Sep 11, 2023, 10:54 Lennart Poettering > > wrote: > > > > > The discoverable partition scheme has no concept of /etc/ discovery. It > > > focusses on

Re: [systemd-devel] systemd-repart /etc automount via discoverable partition specification

2023-09-11 Thread Lennart Poettering
On Mo, 11.09.23 11:39, Nils Kattenbeck (nilskem...@gmail.com) wrote: > On Mon, Sep 11, 2023, 10:54 Lennart Poettering > wrote: > > > On So, 10.09.23 00:33, Nils Kattenbeck (nilskem...@gmail.com) wrote: > > > > > Hello, I am currently trying to build a linux image with discoverable > > >

Re: [systemd-devel] systemd-repart /etc automount via discoverable partition specification

2023-09-11 Thread Nils Kattenbeck
On Mon, Sep 11, 2023, 10:54 Lennart Poettering wrote: > On So, 10.09.23 00:33, Nils Kattenbeck (nilskem...@gmail.com) wrote: > > > Hello, I am currently trying to build a linux image with discoverable > > partitions in an A/B+etc+var scheme. > > The discoverable partition scheme has no concept

Re: [systemd-devel] systemd-repart /etc automount via discoverable partition specification

2023-09-11 Thread Lennart Poettering
On So, 10.09.23 00:33, Nils Kattenbeck (nilskem...@gmail.com) wrote: > Hello, I am currently trying to build a linux image with discoverable > partitions in an A/B+etc+var scheme. The discoverable partition scheme has no concept of /etc/ discovery. It focusses on three basic setups: 1. writable

[systemd-devel] systemd-repart /etc automount via discoverable partition specification

2023-09-09 Thread Nils Kattenbeck
Hello, I am currently trying to build a linux image with discoverable partitions in an A/B+etc+var scheme. I know that /usr and /var have a corresponding partition UUID for automatically mounting them as per DPS. However, I am not sure how to mount the /etc partition? Do I have to specify it as

[systemd-devel] systemd dns smart?

2023-08-24 Thread Marc
I was just 'cleaning up' a bit an ubuntu server from unnecessary running processes. I think I removed also some things from systemd. Now I have that some external auth that is slow due to the fact that the external auth host has two ip addresses configured. One of those ip addresses is not

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-23 Thread Andrei Borzenkov
On Wed, Aug 23, 2023 at 12:50 PM Aleksandar Kostadinov wrote: > > On Wed, Aug 23, 2023 at 10:49 AM Andrei Borzenkov wrote: > <...> > > > > Sure, if you allow unencrypted systems to boot in your OS then all > > > > bets are off. You shouldn't do that of course. > > > > > > > > (in my model of

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-23 Thread Aleksandar Kostadinov
On Wed, Aug 23, 2023 at 10:49 AM Andrei Borzenkov wrote: <...> > > > Sure, if you allow unencrypted systems to boot in your OS then all > > > bets are off. You shouldn't do that of course. > > > > > > (in my model of mind, where automatic GPT image dissection is used the > > > image dissection

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-23 Thread Andrei Borzenkov
On Tue, Aug 22, 2023 at 10:45 PM Aleksandar Kostadinov wrote: > > On Tue, Aug 22, 2023 at 8:10 PM Lennart Poettering > wrote: > > On Di, 22.08.23 19:16, Aleksandar Kostadinov (akost...@redhat.com) wrote: > <...> > > > If attacker replaces volume with unencrypted one, and it boots without > > >

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-23 Thread Lennart Poettering
On Di, 22.08.23 22:35, Aleksandar Kostadinov (akost...@redhat.com) wrote: > On Tue, Aug 22, 2023 at 8:10 PM Lennart Poettering > wrote: > > On Di, 22.08.23 19:16, Aleksandar Kostadinov (akost...@redhat.com) wrote: > <...> > > > If attacker replaces volume with unencrypted one, and it boots

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-22 Thread Aleksandar Kostadinov
On Tue, Aug 22, 2023 at 8:10 PM Lennart Poettering wrote: > On Di, 22.08.23 19:16, Aleksandar Kostadinov (akost...@redhat.com) wrote: <...> > > If attacker replaces volume with unencrypted one, and it boots without > > messing up the sealing PCRs, then probably attacker can query the TPM > > and

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-22 Thread Lennart Poettering
On Di, 22.08.23 19:16, Aleksandar Kostadinov (akost...@redhat.com) wrote: > > > I'm concerned though about an attacker replacing the encrypted root volume > > > with a non-encrypted one. Which may result in system booting an attacker > > > controlled environment while PCRs may be in a state that

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-22 Thread Aleksandar Kostadinov
On Tue, Aug 22, 2023 at 4:16 PM Lennart Poettering wrote: > > On Mo, 21.08.23 17:40, Aleksandar Kostadinov (akost...@redhat.com) wrote: > > > Hello, > > > > This is more of a user question but I didn't find any other suitable forum > > to ask. > > > > I want to install a server that should have

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-22 Thread Lennart Poettering
On Mo, 21.08.23 19:56, Aleksandar Kostadinov (akost...@redhat.com) wrote: > Thanks, this is what I was also considering the feasibility of. And whether > it made sense to begin with. Any idea how can this be done with systemd? > > In man I read: > > > Note that currently when enrolling a

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-22 Thread Lennart Poettering
On Mo, 21.08.23 17:40, Aleksandar Kostadinov (akost...@redhat.com) wrote: > Hello, > > This is more of a user question but I didn't find any other suitable forum > to ask. > > I want to install a server that should have an encrypted root but be able > to reboot unattended. > > systemd-cryptenroll

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-21 Thread Aleksandar Kostadinov
Thanks, this is what I was also considering the feasibility of. And whether it made sense to begin with. Any idea how can this be done with systemd? In man I read: > Note that currently when enrolling a new key of one of the five > supported types listed above, it is required to

Re: [systemd-devel] systemd-cryptenroll with TPM2

2023-08-21 Thread Mantas Mikulėnas
Have your initramfs *extend* a PCR after it retrieves the key from the TPM, before it switches to (or even unlocks) the rootfs. As most PCRs cannot be rolled back without a reboot, this would prevent the key from being unsealed from a running system even if it manages to boot (without causing the

[systemd-devel] systemd-cryptenroll with TPM2

2023-08-21 Thread Aleksandar Kostadinov
Hello, This is more of a user question but I didn't find any other suitable forum to ask. I want to install a server that should have an encrypted root but be able to reboot unattended. systemd-cryptenroll with TPM2 looks like a viable option. I'm concerned about which PCRs to pin so that an

Re: [systemd-devel] systemd-coredump stack traces

2023-08-11 Thread Aaron Brice
Thanks. Adding libdw as dependency does get the stack traces working. From: Richard Purdie Sent: Friday, August 11, 2023 3:57 AM To: Lennart Poettering ; Aaron Brice Cc: systemd-devel@lists.freedesktop.org Subject: Re: [systemd-devel] systemd-coredump stack

Re: [systemd-devel] systemd-coredump stack traces

2023-08-11 Thread Richard Purdie
On Fri, 2023-08-11 at 12:34 +0200, Lennart Poettering wrote: > On Do, 10.08.23 20:34, Aaron Brice (aaron.br...@nikolamotor.com) wrote: > > > I am trying to enable stack traces for core dumps with > > systemd-coredump. I have a yocto build for aarch64 containing > > systemd 250 with the coredump

Re: [systemd-devel] systemd-coredump stack traces

2023-08-11 Thread Lennart Poettering
On Do, 10.08.23 20:34, Aaron Brice (aaron.br...@nikolamotor.com) wrote: > I am trying to enable stack traces for core dumps with > systemd-coredump. I have a yocto build for aarch64 containing > systemd 250 with the coredump and elfutils options enabled in the > build, and the binaries I'm

[systemd-devel] systemd-coredump stack traces

2023-08-10 Thread Aaron Brice
I am trying to enable stack traces for core dumps with systemd-coredump. I have a yocto build for aarch64 containing systemd 250 with the coredump and elfutils options enabled in the build, and the binaries I'm trying to debug are not stripped. coredumpctl list shows the core files and I can

[systemd-devel] systemd 254: systemctl return code change after polkit authentication rework

2023-08-09 Thread Romain Naour
Hello, I noticed a change in the return code of systemctl command between systemd 253 and 254 when the polkit authentication is refused: /bin/systemctl restart systemd-timesyncd.service The return code changed from 1 to 4. The Buildroot Polkit test case "TestPolkitSystemd" expected 1 as return

[systemd-devel] systemd talk on Fedora Flock 2023

2023-08-03 Thread Luna Jernberg
https://youtu.be/GkYURkrIzx0 Zbigniew Jędrzejewski-Szmek talking about systemd for users at Fedoras developer conference Flock 2023 in Cork, Ireland at the moment :)

[systemd-devel] systemd service freeze my keyboard and mouse for few seconds in gdm screen

2023-07-29 Thread Ahmad Ismail
I have a service like: sudo tee /etc/systemd/system/index-directories.service << END [Unit] Description=Index Directories Using Plocate RequiresMountsFor=/media/ismail/8TBRaid0 RequiresMountsFor=/media/ismail/SSDWorking [Service]

[systemd-devel] systemd 254 released

2023-07-28 Thread systemd tag bot
 A new, official systemd release has just  been  tagged . Please download the tarball here: https://github.com/systemd/systemd/archive/v254.tar.gz Changes since the previous release: Announcements of Future Feature Removals and Incompatible Changes: * The next

[systemd-devel] systemd-boot cross compilation for AARCH64 from AMD machine

2023-07-24 Thread Rakesh
Hi All, Please share info on systemd-boot cross compilation for AARCH64 from AMD machine. Thanks, Rakesh

[systemd-devel] systemd prerelease 254-rc3

2023-07-24 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v254-rc3.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] systemd prerelease 254-rc2

2023-07-14 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v254-rc2.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

Re: [systemd-devel] Systemd-cryptsetup triggers a black screen after upgrading to 6.4.1

2023-07-10 Thread Lennart Poettering
On Do, 06.07.23 18:07, Felix Rubio (fe...@kngnt.org) wrote: > Using arch linux, I have had my kernel upgraded from 6.3.9 to 6.4.1. After > regenerating the UKI, that works, I get just a black screen when > systemd-cryptsetup should be either using the TPM to unlock the drive or to > ask me the

Re: [systemd-devel] Systemd-cryptsetup triggers a black screen after upgrading to 6.4.1

2023-07-08 Thread Felix Rubio
Nope: AMD Ryzen 7 6800H, But thank you for the suggestion! Felix On 2023-07-07 09:07, Christian Hesse wrote: Felix Rubio on Thu, 2023/07/06 18:07: Using arch linux, I have had my kernel upgraded from 6.3.9 to 6.4.1. After regenerating the UKI, that works, I get just a black screen when

Re: [systemd-devel] Systemd-cryptsetup triggers a black screen after upgrading to 6.4.1

2023-07-07 Thread Christian Hesse
Felix Rubio on Thu, 2023/07/06 18:07: > Using arch linux, I have had my kernel upgraded from 6.3.9 to 6.4.1. > After regenerating the UKI, that works, I get just a black screen when > systemd-cryptsetup should be either using the TPM to unlock the drive or > to ask me the rescue password.

[systemd-devel] systemd prerelease 254-rc1

2023-07-06 Thread systemd tag bot
A new systemd ☠️ pre-release ☠️ has just been tagged. Please download the tarball here: https://github.com/systemd/systemd/archive/v254-rc1.tar.gz NOTE: This is ☠️ pre-release ☠️ software. Do not run this on production systems, but please test this and report any issues you find to

[systemd-devel] Systemd-cryptsetup triggers a black screen after upgrading to 6.4.1

2023-07-06 Thread Felix Rubio
Using arch linux, I have had my kernel upgraded from 6.3.9 to 6.4.1. After regenerating the UKI, that works, I get just a black screen when systemd-cryptsetup should be either using the TPM to unlock the drive or to ask me the rescue password. Luckily I have an old UKI with 6.3.9 (also the

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Valentin David
On Mon, Jun 5, 2023 at 11:09 AM Lennart Poettering wrote: > On Mo, 05.06.23 10:41, Valentin David (valentin.da...@canonical.com) > wrote: > > > On Mon, Jun 5, 2023 at 9:56 AM Lennart Poettering < > lenn...@poettering.net> > > wrote: > > > > > On So, 04.06.23 14:25, Valentin David

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Lennart Poettering
On Mo, 05.06.23 11:09, Lennart Poettering (lenn...@poettering.net) wrote: > On Mo, 05.06.23 10:41, Valentin David (valentin.da...@canonical.com) wrote: > > > On Mon, Jun 5, 2023 at 9:56 AM Lennart Poettering > > wrote: > > > > > On So, 04.06.23 14:25, Valentin David

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Lennart Poettering
On Mo, 05.06.23 10:41, Valentin David (valentin.da...@canonical.com) wrote: > On Mon, Jun 5, 2023 at 9:56 AM Lennart Poettering > wrote: > > > On So, 04.06.23 14:25, Valentin David (valentin.da...@canonical.com) > > wrote: > > > > > I have been trying to create a root partition from initrd with

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Valentin David
I think that behavior was introduced by https://github.com/systemd/systemd/commit/48a09a8fff480aab9a68e95e95cc37f6b1438751 On Mon, Jun 5, 2023 at 10:41 AM Valentin David wrote: > > > On Mon, Jun 5, 2023 at 9:56 AM Lennart Poettering > wrote: > >> On So, 04.06.23 14:25, Valentin David

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Valentin David
On Mon, Jun 5, 2023 at 9:56 AM Lennart Poettering wrote: > On So, 04.06.23 14:25, Valentin David (valentin.da...@canonical.com) > wrote: > > > I have been trying to create a root partition from initrd with > > systemd-repart. The repart.d file for this partition is as follow: > > > > [Partition]

Re: [systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-05 Thread Lennart Poettering
On So, 04.06.23 14:25, Valentin David (valentin.da...@canonical.com) wrote: > I have been trying to create a root partition from initrd with > systemd-repart. The repart.d file for this partition is as follow: > > [Partition] > Type=root > Label=root > Encrypt=tpm2 > Format=ext4 >

[systemd-devel] systemd-repart very slow creation of partitions with Encrypt=

2023-06-04 Thread Valentin David
I have been trying to create a root partition from initrd with systemd-repart. The repart.d file for this partition is as follow: [Partition] Type=root Label=root Encrypt=tpm2 Format=ext4 FactoryReset=yes I am just using systemd-repart.service in initrd, without modification (that is, it finds

Re: [systemd-devel] systemd boot up hung after sysroot.mount in initrd phase

2023-05-10 Thread Benjamin Godfrey
> I'm trying to be helpful, but it could still be an issue with the systemd-fsck-root.service > The initrd phase is typically very fast because it doesn't need to load many files. > You might try booting from a live USB to boot. You can use the Gparted tool to check the root file system for

Re: [systemd-devel] systemd-devel Digest, Vol 157, Issue 8

2023-05-10 Thread Dave Howorth
On Tue, 9 May 2023 18:43:33 -0700 Benjamin Godfrey wrote: > I'm trying to be helpful, breaking threading, top-posting and repeatedly using a gneneric subject line doesn't seem to be be 'trying to be helpful'. It seems more like 'trying to irritate the people you'd like to help'. PS please don't

Re: [systemd-devel] systemd boot up hung after sysroot.mount in initrd phase

2023-05-10 Thread RAJESH DASARI
On Wed, May 10, 2023 at 4:43 AM Benjamin Godfrey wrote: > > I'm trying to be helpful, but it could still be an issue with the > systemd-fsck-root.service > The initrd phase is typically very fast because it doesn't need to load many > files. > You might try booting from a live USB to boot. You

Re: [systemd-devel] systemd-devel Digest, Vol 157, Issue 8

2023-05-09 Thread Benjamin Godfrey
I'm trying to be helpful, but it could still be an issue with the systemd-fsck-root.service The initrd phase is typically very fast because it doesn't need to load many files. You might try booting from a live USB to boot. You can use the Gparted tool to check the root file system for errors.

Re: [systemd-devel] systemd-devel Digest, Vol 157, Issue 4

2023-05-05 Thread Benjamin Godfrey
1. When attaching a service with an extension, the portablectl list shows the base image as 'attached' but the extension as 'detached'. Is the 'detached' state expected or an indication that something is wrong? You can expect a detached state because the extension is not actually running in the

  1   2   3   4   5   6   7   8   9   10   >