RE: IPv6 Compliance for networkd

2023-12-11 Thread Muggeridge, Matt
> -Original Message- > From: Demi Marie Obenour > Sent: Tuesday, December 12, 2023 11:38 AM > To: Muggeridge, Matt ; systemd- > de...@lists.freedesktop.org > Subject: Re: IPv6 Compliance for networkd > > On Mon, Dec 11, 2023 at 10:52:31PM +, Muggeridge, Matt wrote: > > > > > > >

Re: IPv6 Compliance for networkd

2023-12-11 Thread Demi Marie Obenour
On Mon, Dec 11, 2023 at 10:52:31PM +, Muggeridge, Matt wrote: > > > > -Original Message- > > From: Demi Marie Obenour > > Sent: Tuesday, December 12, 2023 7:14 AM > > To: Muggeridge, Matt ; systemd- > > de...@lists.freedesktop.org > > Subject: Re: IPv6 Compliance for networkd > > >

RE: IPv6 Compliance for networkd

2023-12-11 Thread Muggeridge, Matt
> -Original Message- > From: Demi Marie Obenour > Sent: Tuesday, December 12, 2023 7:14 AM > To: Muggeridge, Matt ; systemd- > de...@lists.freedesktop.org > Subject: Re: IPv6 Compliance for networkd > > On Mon, Dec 11, 2023 at 07:14:27PM +, Muggeridge, Matt wrote: > > Hello,

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Luca Boccassi
On Mon, 11 Dec 2023 at 21:20, Demi Marie Obenour wrote: > > On Mon, Dec 11, 2023 at 08:58:58PM +, Luca Boccassi wrote: > > On Mon, 11 Dec 2023 at 20:43, Demi Marie Obenour > > wrote: > > > > > > -BEGIN PGP SIGNED MESSAGE- > > > Hash: SHA512 > > > > > > On Mon, Dec 11, 2023 at

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 20:59, Luca Boccassi wrote: > > On Mon, 11 Dec 2023 at 20:43, Demi Marie Obenour > wrote: > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA512 > > > > On Mon, Dec 11, 2023 at 08:15:27PM +, Luca Boccassi wrote: > > > On Mon, 11 Dec 2023 at 17:30, Demi Marie

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Demi Marie Obenour
On Mon, Dec 11, 2023 at 08:58:58PM +, Luca Boccassi wrote: > On Mon, 11 Dec 2023 at 20:43, Demi Marie Obenour > wrote: > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA512 > > > > On Mon, Dec 11, 2023 at 08:15:27PM +, Luca Boccassi wrote: > > > On Mon, 11 Dec 2023 at 17:30, Demi

Re: IPv6 Compliance for networkd

2023-12-11 Thread Demi Marie Obenour
On Mon, Dec 11, 2023 at 07:14:27PM +, Muggeridge, Matt wrote: > Hello, networkd developer community, > > I am hoping to rally support for making networkd IPv6 compliant and I'm will > to help, but cannot do it alone. Is there any interest in making > systemd-networkd IPv6 compliant? > >

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Luca Boccassi
On Mon, 11 Dec 2023 at 20:43, Demi Marie Obenour wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On Mon, Dec 11, 2023 at 08:15:27PM +, Luca Boccassi wrote: > > On Mon, 11 Dec 2023 at 17:30, Demi Marie Obenour > > wrote: > > > > > > On Mon, Dec 11, 2023 at 10:57:58AM +0100,

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Demi Marie Obenour
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, Dec 11, 2023 at 08:15:27PM +, Luca Boccassi wrote: > On Mon, 11 Dec 2023 at 17:30, Demi Marie Obenour > wrote: > > > > On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > > > On Fr, 08.12.23 17:59, Eric Curtin

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Luca Boccassi
On Mon, 11 Dec 2023 at 17:30, Demi Marie Obenour wrote: > > On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > > > Here is the boot sequence with initoverlayfs integrated, the > > > mini-initramfs contains

IPv6 Compliance for networkd

2023-12-11 Thread Muggeridge, Matt
Hello, networkd developer community, I am hoping to rally support for making networkd IPv6 compliant and I'm will to help, but cannot do it alone. Is there any interest in making systemd-networkd IPv6 compliant? There are many organizations (especially US Government) that mandate IPv6

Re: [systemd-devel] Manual start of user@.service failed with permission denied

2023-12-11 Thread Andrei Borzenkov
On 11.12.2023 18:28, Christopher Wong wrote: Hi Mantas, I have added ExecStartPre to user@.service to run “id” and “ls -la”: Dec 11 15:50:34 host systemd-user-runtime-dir[40287]: Will mount /run/user/1001 owned by 1001:118 Dec 11 15:50:34 host

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Demi Marie Obenour
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, Dec 11, 2023 at 05:03:13PM +, Eric Curtin wrote: > On Mon, 11 Dec 2023 at 16:36, Demi Marie Obenour > wrote: > > > > On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > > > On Fr, 08.12.23 17:59, Eric Curtin

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Neal Gompa
On Mon, Dec 11, 2023 at 12:30 PM Demi Marie Obenour wrote: > > On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > > > Here is the boot sequence with initoverlayfs integrated, the > > > mini-initramfs

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 16:36, Demi Marie Obenour wrote: > > On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > > > Here is the boot sequence with initoverlayfs integrated, the > > > mini-initramfs contains

Re: [systemd-devel] Manual start of user@.service failed with permission denied

2023-12-11 Thread Mantas Mikulėnas
On Mon, Dec 11, 2023, 17:28 Christopher Wong wrote: > Hi Mantas, > > > > I have added ExecStartPre to user@.service to run “id” and “ls -la”: > > > > Dec 11 15:50:34 host systemd-user-runtime-dir[40287]: Will mount > /run/user/1001 owned by 1001:118 > > Dec 11 15:50:34 host

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Demi Marie Obenour
On Mon, Dec 11, 2023 at 10:57:58AM +0100, Lennart Poettering wrote: > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > Here is the boot sequence with initoverlayfs integrated, the > > mini-initramfs contains just enough to get storage drivers loaded and > > storage devices

Re: [systemd-devel] Manual start of user@.service failed with permission denied

2023-12-11 Thread Christopher Wong
Hi Andrei, As indicated in the logs no SELINUX nor APPARMOR is enabled. Best regards, Christopher Wong From: systemd-devel on behalf of Andrei Borzenkov Date: Saturday, 9 December 2023 at 07:13 To: systemd-devel@lists.freedesktop.org Subject: Re: [systemd-devel] Manual start of

Re: [systemd-devel] Manual start of user@.service failed with permission denied

2023-12-11 Thread Christopher Wong
Hi Mantas, I have added ExecStartPre to user@.service to run “id” and “ls -la”: Dec 11 15:50:34 host systemd-user-runtime-dir[40287]: Will mount /run/user/1001 owned by 1001:118 Dec 11 15:50:34 host systemd-user-runtime-dir[40287]: Mounting tmpfs (tmpfs) on

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 12:48, Eric Curtin wrote: > > On Mon, 11 Dec 2023 at 11:51, Lennart Poettering > wrote: > > > > On Mo, 11.12.23 11:28, Eric Curtin (ecur...@redhat.com) wrote: > > > > > > > For the items listed above I think you can find different solutions > > > > > which do not

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 11:51, Lennart Poettering wrote: > > On Mo, 11.12.23 11:28, Eric Curtin (ecur...@redhat.com) wrote: > > > > > For the items listed above I think you can find different solutions > > > > which do not necessarily compromise security as much. > > > > > > > > So, in the list

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Lennart Poettering
On Mo, 11.12.23 11:42, Eric Curtin (ecur...@redhat.com) wrote: > I am also thinking, what is the difference between "make the > bootloader load the erofs into contiguous memory" part and doing > something like storage-init. Well, from my PoV there's value in reducing the stages of the boot

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Lennart Poettering
On Mo, 11.12.23 11:28, Eric Curtin (ecur...@redhat.com) wrote: > > > For the items listed above I think you can find different solutions > > > which do not necessarily compromise security as much. > > > > > > So, in the list above you could address the latter three like this: > > > > > > 2. Use

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
I am also thinking, what is the difference between "make the bootloader load the erofs into contiguous memory" part and doing something like storage-init. They are similar approaches, introduce something in the middle to handle the erofs. Is mise le meas/Regards, Eric Curtin On Mon, 11 Dec

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 11:20, Eric Curtin wrote: > > On Mon, 11 Dec 2023 at 10:06, Lennart Poettering wrote: > > > > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > > > Here is the boot sequence with initoverlayfs integrated, the > > > mini-initramfs contains just enough to

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Eric Curtin
On Mon, 11 Dec 2023 at 10:06, Lennart Poettering wrote: > > On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > > > Here is the boot sequence with initoverlayfs integrated, the > > mini-initramfs contains just enough to get storage drivers loaded and > > storage devices initialized.

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Lennart Poettering
On Mo, 11.12.23 10:57, Lennart Poettering (mzerq...@0pointer.de) wrote: > Which leaves item 1, which is a bit harder to address. We have been > discussing this off an on internally too. A generic solution to this > is hard. My current thinking for this could be something like this, > covering the

Re: [RFC] initoverlayfs - a scalable initial filesystem

2023-12-11 Thread Lennart Poettering
On Fr, 08.12.23 17:59, Eric Curtin (ecur...@redhat.com) wrote: > Here is the boot sequence with initoverlayfs integrated, the > mini-initramfs contains just enough to get storage drivers loaded and > storage devices initialized. storage-init is a process that is not > designed to replace init, it