Re: Producing verifiable initramfs images

2020-02-06 Thread Matthew Garrett
On Thu, Feb 6, 2020 at 12:07 AM Anthony DeRobertis wrote: > > An interesting challenge you've taken up, I fear it's going to be a lot > of work. Heh. It's work we're doing internally, so it'd be good to get it into an upstream-acceptable form. > On almost all of my older installs, the initramfs

Re: Producing verifiable initramfs images

2020-02-06 Thread Anthony DeRobertis
An interesting challenge you've taken up, I fear it's going to be a lot of work. On almost all of my older installs, the initramfs is built with MODULES=dep, because otherwise /boot runs out of space; the amount of space MODULES=most takes is ever-increasing. So the kernel packages plopping

Re: Producing verifiable initramfs images

2020-02-05 Thread Sam Hartman
This is not a disagreement with anything you write. I've noticed that there is a lot more configuration that gets encoded in the initramfs than I thought. The most surprising for me is that if you want to control the names of network devices or anything else set by the .link file, that ends up