Re: [systemd-devel] Antw: Re: [systemd‑devel] [EXT] Proposal to extend os‑release/machine‑info with field PREFER_HARDENED_CONFIG

2022-03-09 Thread Stefan Schröder
Let me list the counter arguments to the proposal (to include a new field PREFER_HARDENED_CONFIG) so far: * The packages should be deploying a secure configuration by default. Counter-argument: Yes, but they don't. There are obviuosly competing interests and sometimes convenience wins.

[systemd-devel] Antw: [EXT] Re: [systemd‑devel] PrivateNetwork=yes is memory costly

2022-03-09 Thread Ulrich Windl
>>> Lennart Poettering schrieb am 09.03.2022 um 16:18 in Nachricht : > On Mo, 07.03.22 15:10, Christopher Wong (christopher.w...@axis.com) wrote: > >> Hi, >> >> >> It seems that PrivateNetwork=yes is a memory consuming >> directive. The kernel seems to allocate quite an amount of memory >> for

Re: [systemd-devel] PrivateNetwork=yes is memory costly

2022-03-09 Thread Lennart Poettering
On Mo, 07.03.22 15:10, Christopher Wong (christopher.w...@axis.com) wrote: > Hi, > > > It seems that PrivateNetwork=yes is a memory consuming > directive. The kernel seems to allocate quite an amount of memory > for each service (~50 kB) that has this directive enabled. I wonder > if this is

Re: [systemd-devel] How to grant systemd-nspawn access to USB device?

2022-03-09 Thread Kevin P
Hello Greg and thanks for answering :) I never used strace, so I couldn't figure from the output, but further research led me to this post: http://www.pclinuxos.com/forum/index.php?topic=135714.0 So I just tried (on the host): chmod o+rw /dev/bus/usb/001/005 And it is now working. I was not

Re: [systemd-devel] How to grant systemd-nspawn access to USB device?

2022-03-09 Thread Greg KH
On Wed, Mar 09, 2022 at 03:04:00PM +0100, Kevin P wrote: > Good evening everyone. > I would like a nspawn container on my Raspberry Pi (Raspbian, systemd 247) > to access a RTL2838 DVB-T USB stick. > Inside the container, dump1090 will run and feed aircraft data (piaware and > adsbexchange

[systemd-devel] networkd: changing priorities of default routing poilicy lists

2022-03-09 Thread Marcel Menzel
Hello List, Given the following commands, I am asking if there is a possible solution to achive this the "systemd way" (meaning being able to configure this entirely via networkd configs), instead of having them to put into a unit file:     ip -4 rule add pref 32765 table local     ip -4

[systemd-devel] How to grant systemd-nspawn access to USB device?

2022-03-09 Thread Kevin P
Good evening everyone. I would like a nspawn container on my Raspberry Pi (Raspbian, systemd 247) to access a RTL2838 DVB-T USB stick. Inside the container, dump1090 will run and feed aircraft data (piaware and adsbexchange projects). lsusb gives: Bus 001 Device 005: ID 0bda:2838 Realtek

Re: [systemd-devel] making firewalld an early boot service

2022-03-09 Thread Lennart Poettering
On Mi, 09.03.22 08:17, Michael Biebl (mbi...@gmail.com) wrote: > > firewalld requires D-Bus so it must be started after D-Bus. You cannot > > start it earlier. > > See above, being Type=dbus, it has an explicit > Requires/After=dbus.socket. It has After=dbus.service, not After=dbus.socket, no?

Re: [systemd-devel] making firewalld an early boot service

2022-03-09 Thread Lennart Poettering
On Mi, 09.03.22 08:49, Andrei Borzenkov (arvidj...@gmail.com) wrote: > On 09.03.2022 00:59, Michael Biebl wrote: > > Hi, > > > > I need help with firewalld issue, specifically > > https://github.com/firewalld/firewalld/issues/414 > > > > the TLDR: both firewalld.service and

[systemd-devel] EFI Boot default not honered

2022-03-09 Thread Sietse van Zanen
Hi, After upgrading to 250, systemd efi boot is no longer honoring the default. Neither loader.conf default nor LoaderDefaultEntry EFI variable have any effect. Instead it defaults to the last entry (alphabetically) in the entries/ directory. Anybody els have this issue (or some ideas

Re: [systemd-devel] making firewalld an early boot service

2022-03-09 Thread Andrei Borzenkov
On Wed, Mar 9, 2022 at 10:18 AM Michael Biebl wrote: > > Am Mi., 9. März 2022 um 06:49 Uhr schrieb Andrei Borzenkov > : > > > > On 09.03.2022 00:59, Michael Biebl wrote: > > > Hi, > > > > > > I need help with firewalld issue, specifically > > > https://github.com/firewalld/firewalld/issues/414 >

Re: [systemd-devel] making firewalld an early boot service

2022-03-09 Thread Lennart Poettering
e65;6602;1cOn Di, 08.03.22 22:59, Michael Biebl (mbi...@gmail.com) wrote: > I wonder if firewald should be turned into an early boot service as > well. I doubt you can do that. Thing is that firewalld uses D-Bus, and services that do D-Bus will have a hard time to run during early boot. In