From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Tue, 17 Jun 2025 16:27:01 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-qv1-f59.google.com (mail-qv1-f59.google.com [209.85.219.59]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 55HEQxxa030751 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 17 Jun 2025 16:27:00 +0200 Received: by mail-qv1-f59.google.com with SMTP id 6a1803df08f44-6fb5664c771sf41818576d6.0 for ; Tue, 17 Jun 2025 07:27:00 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1750170414; cv=pass; d=google.com; s=arc-20240605; b=P63jZY5Kc5yQoYDrPGpy3P4gmvY5DohtvXNes9HVc7+xN9nsrgViz3DaK639anpdRU y5bgmRlqAs3HdDaMOWfLCRhyDAJK8rnc6PKWhMGbT+MGWsHWqGwMptVMIguCvSPSOMIK wvSfX+m9MoC51aItAJz69IRv4Szdw/OsC19mcDGH6hQBHCHAov16XfYGdX6FhcjPE4yY yE5by3rO4KGSROqlkvd1UVicFvpKbwN8iEH7nQCXD2sXmCsehDXf1mNrGf3X+VxyIx5w nPUBT1r7bU8IsQBD/5cafsK9IS7sxHOkZvBZeKEwqFAT1Jps63HiADaNB3nLKuc8MS7C gt1g== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:date :message-id:dkim-signature; bh=HuJZjwVDwmQs1wShsHdoVf43s8CmEckxL37yBFtM4bo=; fh=3A75RhOiwSeLnEBgS4XnJSyWZd4tXeVQAPiy4fFUeA4=; b=VzX/BmjiJeRGdXKj79D7W1qhb+1qbaRAlsnZEwQELT501jRC74Lb1dmIzr+kn8Wsae zteELhMRR4VgKkgQ+dNn0W263IS9Hv04C8A+XhVbzL7ENgOcf/FpYikHRg+pXM2zN6SU h094UJzLfWwsVsvb3oJu4/obdHGgKb5N14cvD5lxZWp6CW0I01nsEi8cxG5mK6obyLuP X1sWGd7BlF1E5pMDnWJencJdjEmq3iPXNKzlTij+tWKLKO9vIJAZFRBHHYkFGjbfMySy i5fFQw9xM5qtUCvQXR/YfAToe4hwKXwTRsn6sx1j5Y6xpD/zLczrfGMdlrfiOlRTvrot 4/9w==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=LKo9YJd6; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1750170414; x=1750775214; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:date :message-id:from:to:cc:subject:date:message-id:reply-to; bh=HuJZjwVDwmQs1wShsHdoVf43s8CmEckxL37yBFtM4bo=; b=BsKupNUGuJLVYYDGaI872IM94g5hxdVJdR6t+6XW33ucPu0Yju+XlS/pMpVhiktbpO s2sn74BUkJEum2lIZOT5i/ExO6IHzaO+ROHPYETt8zzWp0hoNshEXZNLQI5Y6QV3RW8X yylVA1nFtrISgi0zNnJOfQVimRP7gZRAiY88spLzVLO0y4GwP4mxP2p3WQ34260oEHtP cNbXoAbYJPQ1gEnbdrLtmWZ1p8R5F6paw8aflBOtegEfUa+Y9ljuvz+bok/KnVQfW7UU vbIwPMiz9hiBS2C0/QeLqCOMJMQ6+uaU4r/zRzXWvr7AZXP6yVgf7TzYtAkAwaRbUcXm 7s6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1750170414; x=1750775214; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:date :message-id:x-beenthere:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=HuJZjwVDwmQs1wShsHdoVf43s8CmEckxL37yBFtM4bo=; b=FmTBK/t1X/2t98lNA5inpu2szgQA40nalBjmoGNjp8i/Rtu7Z8hJUU439R84puvn4z ZUPGnDwsZD4RHNuPk1oV5pFsIQOARnROvZhcnbq3P8+GVe/eijOZy4YNXIXc7Q6Wr8QW dTR4wnoel8syV/lZRP9dRQKUbyE2wU0JyazWZ6qjci+6bp/Z6JpBUyKo3JW8zTqdvn8o A4w9IwmujV1ldkh/jX0FFuVMna4Eu1kHN8THdjN2e79rPiE/GaSa3TnqSBMQnREpNePp 0pe2JSMeBqHNgbajfZa51X3WneYOub9fGqaGEaxwbF0yeofQXRSreIXkwtbc/3K9tQmS 8srQ== X-Forwarded-Encrypted: i=3; AJvYcCXC/mcLyjB+nde4Kg6W1C5Gzubsf0rsNWZ8FPIqATbxN4HHaRQ2SlFM5w1t2JN4nshvNK4c@ilbers.de X-Gm-Message-State: AOJu0YzTZ5lK+wC14fdSTKKbwHaK8Ef+Pyr+OsFdAfQwkcpZL3/slQyB aIhVYw44+JuS0Fzt9FaNKcwj13zepzSdvdvjyDOlPLiGLHLKubYI+HNN X-Google-Smtp-Source: AGHT+IFZma5grdBs8+xH1ShZmkwWKeOF2Bf4YZdtZ2z/8Y35ZBmXvSjPxaiGC1Pxf5lxPD80bFxzBQ== X-Received: by 2002:a05:6214:4001:b0:6fa:cc39:90 with SMTP id 6a1803df08f44-6fb477e473emr176140766d6.29.1750170413725; Tue, 17 Jun 2025 07:26:53 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h=AZMbMZcmKLCPAuQFO4XFiK6Ly6pUzrDbjcdJMUjuC+oqaSgyHw== Received: by 2002:a05:6214:2266:b0:6fb:4bc7:dc0d with SMTP id 6a1803df08f44-6fb4bc7de25ls62725886d6.1.-pod-prod-06-us; Tue, 17 Jun 2025 07:26:52 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCWdRYyEyWgrgzdHxZjYHgKB/+lsJ3R3JZ8P+9Hm35src1Sg8nQrOmTD+MQncq4hjojWS15E3Q2jF/ZM@googlegroups.com X-Received: by 2002:a05:6102:2927:b0:4e6:245b:cf5e with SMTP id ada2fe7eead31-4e7f62a5240mr9092793137.17.1750170412592; Tue, 17 Jun 2025 07:26:52 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1750170412; cv=pass; d=google.com; s=arc-20240605; b=dtQt00MyET8lARv0gmVZu75vMGL6oNp6qYIPuyHo4IzKHfOsOy4phoIUeZ6qAv/5X+ 7Qx+R3U5l4PUaOCz4DFauNpddtJI0Oio+Fz3D0k3pbJRJGrFH8ZQ1S82l4KX4c+e54gh cyoqpBjxzblo0uFXSi3qsWGDLK/zPCGYhXy70Wt8g5RuToiRPDHphAAJRxmvpxQLjQ53 7WqfwmavaXGYGbpObnSWtZOOTm3n8Jt5fC2FuAfstPDlPqrl8tzP/TT7HOoGnKmmVayx gcdY1hEB6dcuVjSaesRtW4Olp+bTUnN6g/OtVWpUav/OnNIN8ipJiUf6LXVt33aYTfjM k5/A== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:date :message-id:dkim-signature; bh=jemuO+HiqlPJDil7xEhwzQbfKR9B5MfXZlMY8hTPKtI=; fh=QOz2QpOzegCiyOxlRtV6VaZRPfDJ7mgkmI8SDzvpa7U=; b=JtFteH/qTkx+JlsYhLWDEB9xqt5iTtSt9IDF0h90hqt5HgM3Qjo1dxmF1dH/TP1hqc ghS+rAMCMs1KvMwLfTOzlyjzyGU5ryVe4yFv5AvXLHU7TBumIvslUmPfURhUIGK1JNN+ zeXeCGfOb6gww3euSPXsBtv0OtAz+BSsdsGTLnuDqsNbck7UlZeRZKKbd06H6xLuPPl1 t4MnOkB5jfH0VRJRHTHXwClYlw78Lja57KaAKZKfblyrrjpvoNuma79lLi5n+CEylv+4 wa62VnUsV5nbNfU3sF6Ldryq/2NDTpaRNCyparnoiMH5aoHiCcQ71C0uiJPQTRssoBLB 8tYA==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=LKo9YJd6; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from DU2PR03CU002.outbound.protection.outlook.com (mail-northeuropeazlp170110003.outbound.protection.outlook.com. [2a01:111:f403:c200::3]) by gmr-mx.google.com with ESMTPS id ada2fe7eead31-4e7e6f7c752si426860137.2.2025.06.17.07.26.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 17 Jun 2025 07:26:51 -0700 (PDT) Received-SPF: pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) client-ip=2a01:111:f403:c200::3; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=CSgh682KFThPzd8VR4Uk1R+Rz/6+K14g0vJ4THJbCmfG9TjoP2rLF5kQnykiW+kvp4EZnJYVQsLJqnXEc4CoLqxg8Xxx4MP5Kwfxb9I292M0Sd/h0+dP3bPajWy/7eCC9EUBPUJtf9Zk/K7wItFD3mkvJ3YP0nkUNM4G5pfR1AUGnQcYiG6/6DPDlDKdbJgpcOFA2HMxJnDYXzxDpmjsDSxsphWTkEDQ/7PmiKZx49IDo60Q5br5F3nDWJPYkZ4t5mdHMc0zuUPXxoq3Xd3SDFrjyzDV236mS9tYMMqkq4NMlJLCtRCTbe8s2AHDcR12+yFOmvOT1r1FIAe8EC3Log== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=jemuO+HiqlPJDil7xEhwzQbfKR9B5MfXZlMY8hTPKtI=; b=PaD+w/bKCgkPQs336D2MqrFjAODKqE4/0w+g1APmnMFX5xzI89n8M6BDDhMhsagsphRiGxYAgZFv64yGPhvV2H0kHfFHXz2XE4NNckvU0YUyKPJhYmdy7ReHqx3b/5iB457Ge0QYu9iWA4eFAhzf9cWOIRlE3IKIOJSy3dFA1hsCjzCB3JHfqABT0sfuj4giILmGfJKptG0e4e3MlrLBRj/spQ/EYguzCLeFb4m8Ir4+Dz9UTX2zRYciMkLrOk+AXOF1HJmGeNOKRHBIigYTfmWeM6075bqeNLc+QQZzxZfwSYvRjv6rkOFzaD4XCieJW3oGHqrXI3NdIk4V0MaIdA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) by DB9PR10MB5380.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:333::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8835.29; Tue, 17 Jun 2025 14:26:48 +0000 Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::8fe1:7e71:cf4a:7408]) by AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::8fe1:7e71:cf4a:7408%5]) with mapi id 15.20.8835.027; Tue, 17 Jun 2025 14:26:48 +0000 Message-ID: <92946c61-7192-44db-a3c6-489e7e1cf911@siemens.com> Date: Tue, 17 Jun 2025 16:26:46 +0200 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] rootfs: do not expose /sys/firmware while building root file-systems To: "MOESSBAUER, Felix" , "isar-users@googlegroups.com" , "cedric.hombourger@siemens.com" Cc: "Arjunan, Srinu" References: <20250617123507.2245-1-cedric.hombourger@siemens.com> <23351a3bdc42f238a0b8341afd2d3611d5cbca03.camel@siemens.com> Content-Language: en-US From: "'Jan Kiszka' via isar-users" Autocrypt: addr=jan.kiszka@siemens.com; keydata= xsFNBGZY+hkBEACkdtFD81AUVtTVX+UEiUFs7ZQPQsdFpzVmr6R3D059f+lzr4Mlg6KKAcNZ uNUqthIkgLGWzKugodvkcCK8Wbyw+1vxcl4Lw56WezLsOTfu7oi7Z0vp1XkrLcM0tofTbClW xMA964mgUlBT2m/J/ybZd945D0wU57k/smGzDAxkpJgHBrYE/iJWcu46jkGZaLjK4xcMoBWB I6hW9Njxx3Ek0fpLO3876bszc8KjcHOulKreK+ezyJ01Hvbx85s68XWN6N2ulLGtk7E/sXlb 79hylHy5QuU9mZdsRjjRGJb0H9Buzfuz0XrcwOTMJq7e7fbN0QakjivAXsmXim+s5dlKlZjr L3ILWte4ah7cGgqc06nFb5jOhnGnZwnKJlpuod3pc/BFaFGtVHvyoRgxJ9tmDZnjzMfu8YrA +MVv6muwbHnEAeh/f8e9O+oeouqTBzgcaWTq81IyS56/UD6U5GHet9Pz1MB15nnzVcyZXIoC roIhgCUkcl+5m2Z9G56bkiUcFq0IcACzjcRPWvwA09ZbRHXAK/ao/+vPAIMnU6OTx3ejsbHn oh6VpHD3tucIt+xA4/l3LlkZMt5FZjFdkZUuAVU6kBAwElNBCYcrrLYZBRkSGPGDGYZmXAW/ VkNUVTJkRg6MGIeqZmpeoaV2xaIGHBSTDX8+b0c0hT/Bgzjv8QARAQABzSNKYW4gS2lzemth IDxqYW4ua2lzemthQHNpZW1lbnMuY29tPsLBlAQTAQoAPhYhBABMZH11cs99cr20+2mdhQqf QXvYBQJmWPvXAhsDBQkFo5qABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEGmdhQqfQXvY zPAP/jGiVJ2VgPcRWt2P8FbByfrJJAPCsos+SZpncRi7tl9yTEpS+t57h7myEKPdB3L+kxzg K3dt1UhYp4FeIHA3jpJYaFvD7kNZJZ1cU55QXrJI3xu/xfB6VhCs+VAUlt7XhOsOmTQqCpH7 pRcZ5juxZCOxXG2fTQTQo0gfF5+PQwQYUp0NdTbVox5PTx5RK3KfPqmAJsBKdwEaIkuY9FbM 9lGg8XBNzD2R/13cCd4hRrZDtyegrtocpBAruVqOZhsMb/h7Wd0TGoJ/zJr3w3WnDM08c+RA 5LHMbiA29MXq1KxlnsYDfWB8ts3HIJ3ROBvagA20mbOm26ddeFjLdGcBTrzbHbzCReEtN++s gZneKsYiueFDTxXjUOJgp8JDdVPM+++axSMo2js8TwVefTfCYt0oWMEqlQqSqgQwIuzpRO6I ik7HAFq8fssy2cY8Imofbj77uKz0BNZC/1nGG1OI9cU2jHrqsn1i95KaS6fPu4EN6XP/Gi/O 0DxND+HEyzVqhUJkvXUhTsOzgzWAvW9BlkKRiVizKM6PLsVm/XmeapGs4ir/U8OzKI+SM3R8 VMW8eovWgXNUQ9F2vS1dHO8eRn2UqDKBZSo+qCRWLRtsqNzmU4N0zuGqZSaDCvkMwF6kIRkD ZkDjjYQtoftPGchLBTUzeUa2gfOr1T4xSQUHhPL8zsFNBGZY+hkBEADb5quW4M0eaWPIjqY6 aC/vHCmpELmS/HMa5zlA0dWlxCPEjkchN8W4PB+NMOXFEJuKLLFs6+s5/KlNok/kGKg4fITf Vcd+BQd/YRks3qFifckU+kxoXpTc2bksTtLuiPkcyFmjBph/BGms35mvOA0OaEO6fQbauiHa QnYrgUQM+YD4uFoQOLnWTPmBjccoPuiJDafzLxwj4r+JH4fA/4zzDa5OFbfVq3ieYGqiBrtj tBFv5epVvGK1zoQ+Rc+h5+dCWPwC2i3cXTUVf0woepF8mUXFcNhY+Eh8vvh1lxfD35z2CJeY txMcA44Lp06kArpWDjGJddd+OTmUkFWeYtAdaCpj/GItuJcQZkaaTeiHqPPrbvXM361rtvaw XFUzUlvoW1Sb7/SeE/BtWoxkeZOgsqouXPTjlFLapvLu5g9MPNimjkYqukASq/+e8MMKP+EE v3BAFVFGvNE3UlNRh+ppBqBUZiqkzg4q2hfeTjnivgChzXlvfTx9M6BJmuDnYAho4BA6vRh4 Dr7LYTLIwGjguIuuQcP2ENN+l32nidy154zCEp5/Rv4K8SYdVegrQ7rWiULgDz9VQWo2zAjo TgFKg3AE3ujDy4V2VndtkMRYpwwuilCDQ+Bpb5ixfbFyZ4oVGs6F3jhtWN5Uu43FhHSCqUv8 FCzl44AyGulVYU7hTQARAQABwsF8BBgBCgAmFiEEAExkfXVyz31yvbT7aZ2FCp9Be9gFAmZY +hkCGwwFCQWjmoAACgkQaZ2FCp9Be9hN3g/8CdNqlOfBZGCFNZ8Kf4tpRpeN3TGmekGRpohU bBMvHYiWW8SvmCgEuBokS+Lx3pyPJQCYZDXLCq47gsLdnhVcQ2ZKNCrr9yhrj6kHxe1Sqv1S MhxD8dBqW6CFe/mbiK9wEMDIqys7L0Xy/lgCFxZswlBW3eU2Zacdo0fDzLiJm9I0C9iPZzkJ gITjoqsiIi/5c3eCY2s2OENL9VPXiH1GPQfHZ23ouiMf+ojVZ7kycLjz+nFr5A14w/B7uHjz uL6tnA+AtGCredDne66LSK3HD0vC7569sZ/j8kGKjlUtC+zm0j03iPI6gi8YeCn9b4F8sLpB lBdlqo9BB+uqoM6F8zMfIfDsqjB0r/q7WeJaI8NKfFwNOGPuo93N+WUyBi2yYCXMOgBUifm0 T6Hbf3SHQpbA56wcKPWJqAC2iFaxNDowcJij9LtEqOlToCMtDBekDwchRvqrWN1mDXLg+av8 qH4kDzsqKX8zzTzfAWFxrkXA/kFpR3JsMzNmvextkN2kOLCCHkym0zz5Y3vxaYtbXG2wTrqJ 8WpkWIE8STUhQa9AkezgucXN7r6uSrzW8IQXxBInZwFIyBgM0f/fzyNqzThFT15QMrYUqhhW ZffO4PeNJOUYfXdH13A6rbU0y6xE7Okuoa01EqNi9yqyLA8gPgg/DhOpGtK8KokCsdYsTbk= In-Reply-To: <23351a3bdc42f238a0b8341afd2d3611d5cbca03.camel@siemens.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: FR2P281CA0160.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:99::9) To AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS4PR10MB6181:EE_|DB9PR10MB5380:EE_ X-MS-Office365-Filtering-Correlation-Id: d4e8ed50-fbae-40af-777a-08ddadaafe29 X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014; X-Microsoft-Antispam-Message-Info: =?utf-8?B?SGxwSDFsNUYweWJFSjhrakFkSzlITGtOUDlxWVhHaWxpQ1l3MUNmbkxIOHFu?= =?utf-8?B?TFVURVdqUHEzQTQyS0VpVWdKaEFaWUw1Ym4wbWJMUWIzL0FPOC9XVEJHQlNW?= =?utf-8?B?KzRJTUVaR1krYUltZm52d2F6UGVEaTBKdmJTbmtYNGNIY0JQMlByUnBjQTNq?= =?utf-8?B?ZVBnZGVGNWR5cXRkalZZcWd0cjgyUXNHWDJMYXI5T0FXN0w3U0F0bXBYR1Fr?= =?utf-8?B?RGMzd1h1cFg5R09kWHJxMUZ3aU9qUDQvejFkeW5kVGZQUTB0SUxwd0JXVUZG?= =?utf-8?B?dXBRMU14WGQvQnE3bUFEMU9xbG54OGFySXVpSUtBSVpvOXNHNTd2N0lKZ2NF?= =?utf-8?B?QklPQ25icDdVbnVJVVlGMzBEd0Y3RGl4bktvT0ZYQVR0R1M4bCtja3gvcjVQ?= =?utf-8?B?Wk92WEYrK0lObzZuUUlvOFJOM0tPQThpNERvQldodmJnSVN5UzFuYXd0alZh?= =?utf-8?B?OGF0bHFkeU5oRitIUVA0ZmJ6MWlnRTMxNTJ6cnJVR2J5L0xFUEJPZGNJMHJJ?= =?utf-8?B?VUMxbE1FTnk4SWdOdG9nblZ0VXlFUStwUlV3NjM2aEtwTjI5ZkJoZ20rREJG?= =?utf-8?B?ZFdBSVdxY3hSL1plYTQ1U2xZZTUzVlc4cTJldFVBbzNiMSsxL3dBR0g0dnhs?= =?utf-8?B?NE9RZWRJV2JWQmxOTE1sRlpCUXdRZURqSk8zNy92VmpjeGhDbjU2Q1ZUWUJL?= =?utf-8?B?RVJmUXMzMEpWVjFXVWF2ak5PdGg3aDFEeFpQS0hMWGxGVEgyR29sNEEwb2pu?= =?utf-8?B?UENIWHU3VVZJNGs3M2ppV0x0NEdhWXY5WmVGdnpjc3IveGVudEg5K2ttVWJo?= =?utf-8?B?NnBGeFFZLzZidlNPalp4cnJDNGNwQW53T3FHT3N1bitXZU83eGJITU42UG1S?= =?utf-8?B?dlFWV2xWVk5UdXlzSERoc1A5M0pWMHh0Y3gxemN6bzZRTE11WU0xOHNGTkx1?= =?utf-8?B?Mk9DSnFiVlNrZXcxeGY0TWxzdXJTaTlTSzAzVDVhWkNVZlAreW1TQlkyS1c2?= =?utf-8?B?cnZzazhCTDM2cnNKZXZ0dDhpV3FFcU9DWlBZdm1SNWxZL09vRU9CZHVpQ29G?= =?utf-8?B?SUdWRzU1ZkNVbGFmQ0xGeis2REdMNlIrbWE1QVF0ZDl2YWQvN2JPNXB3Wkxu?= =?utf-8?B?ZDV6eWZHdmV3WCsvUHIwSE5HUnlFMTdYeHFrUWVzMkJGRmM0b1NwUDlobDA5?= =?utf-8?B?dW9Qc21wT3c5ejJ1U2tnMnNnM1BINTNJVmJ1bmZKNmUweFF6VXk3d1pFVS9z?= =?utf-8?B?c2lIVVhGSVpiSnNoR3N0bktWalVqbGhmZldTNFNXYlVNT1hKYXNXSmhEc0dT?= =?utf-8?B?ZlplZFVEbWtYdy96Y2dNRzFGSjU0d3o1MkpzSG9MWTZWM0pSckxRNFFxYnBI?= =?utf-8?B?dmhZU1BHandjZ1d2WEhoS3dJemEyWW1IRlJhVXpoSEFjYno0V0E1T3NPNTFq?= =?utf-8?B?YUM4ZXZJSUpaT05ZTXVmampWenp3SWxveDc4UEdtemxrSTR5SFV5SGJRRk1q?= =?utf-8?B?SGdmeko2d0YreXB0Y3Q2akNrUktnVVhMbElzR3V3VHdDTXZYVFo5bUliY0tY?= =?utf-8?B?aloveVFldVNDYVpqcm82Q0JDU052Zlk4OWYrVWZ4VGZEbFhBZkhOdU0wdlhZ?= =?utf-8?B?R0R3bHROeFVoU1hVU0VmZURPazJFdzlvNnNLMThxQmVCTkFGaDhSWjZCbnZK?= =?utf-8?B?WDZXakpqVU5NbXAzd2ZtL2pKOFBMVkFPRmN5QXJodmlIOWt5M29aOGFESnpB?= =?utf-8?B?bURsWThhZ240OUI4bEFSV3ZiREhnOUY4ZGx6djE2YUpaNU1lTmp2Yjc3b0w3?= =?utf-8?B?ZXZhMGJHNHRjeWJIY1JRcm9pT2gwTGxmSldOMTAyMmE2WHVmNU55dlFOb2gr?= =?utf-8?B?Z0JmaENXMjhuUEwzSGh3M280VHhoVWVRR0hYa3pEWWJJZ3QyWFJhNnFGaVhl?= =?utf-8?Q?p8RT3QSZ/j0=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?N3NVUTFnWm9rRmd4cDJPWmZuYk1nNUd6REdXSDAwdHlFdFQ3S1lISmlwT2ht?= =?utf-8?B?TWlBQVMxeFhYRmg0ci8rQjdFWGlBYmVZUHh4UXBhVnNmLzh3aEtHaThVdHha?= =?utf-8?B?dzlyRnJlRm56RW0vUGZyUTM0c0FINCtVSnpqRHFjdDVOSnlqRCtrNTM2ek1N?= =?utf-8?B?cnhnWVh3dTNiMVlmK3lJNEF2U095bXlXZ3F4c0EwN0gwZVFoMFVwb1BxVjNr?= =?utf-8?B?Q21XMEtIQ1lwZW5zM1MwUjlGM3BXNUlMRUUrQVVhSjI5OTJpY09tNkd1K0Jz?= =?utf-8?B?S0NxdFdFbFdHeUFLU09KdmxpT0l1bzRHY09vNk9XcEloTnY5cUxIWkJMcGIw?= =?utf-8?B?SDQzNHEraWJzWkluOUYrOWQzVGd1OFNRa2thVnlSVnUwNUNyQUdZTHkzcHVO?= =?utf-8?B?Tnd2bTBLVXFkUFByRERRMGlIamt0K2txL2NLcEhvbTJPMFcvbVhEWXpoUnpr?= =?utf-8?B?dldaN3NyUTlmbnJOM2JNTUQ5ZUZHQndhVVBLbUJYdmM3Qnpoa1pJdCtTeVFs?= =?utf-8?B?SWRJOFZoTmxGWFd6bFRiUXpTbENJbHBDTkF4eHVHa25PYk83NE4yREFHZzQ0?= =?utf-8?B?UkNNVDcxR3RLcmRjbnVmYlpHNWlDZGgwck85NHdmL0dRWmsxbnkvaDRENk4r?= =?utf-8?B?REtGZnZ2NFlkN2JLb3RkNnBERXk5cjB4aksza3RtY1lVblBCZ05paW9CZGto?= =?utf-8?B?ZEZkQytoZHowYmJPMDV5UFU4NlNPMGZTbU1RZ3RyYVhPNGJDRWdUNFBPNTJE?= =?utf-8?B?TlZ2NW1jMkRVOXU5c3hoeGdxdFJFZllmWkpWTzZvejFXUys3Wis3N2Rjbkpm?= =?utf-8?B?R2E3VWtndFQ2NHkvUEJJRHR1aFhTZDhJbXI5ZWUwSE1ZN1BwOW9tZzZnNmJV?= =?utf-8?B?aTcraU9QaWpkdjlWMHNGNWR1c0tFbFFyN0toMGpwWVhrTDBJWXo4c0dkMGhj?= =?utf-8?B?M1RXS2UvWnlEeUY1UzdPTC9jYUNpajZrdXhNQTQvQlpDRi9TY2htcXFUWXhG?= =?utf-8?B?S2hBNElOcXF1Q1IzSkpBTk15WXY5Z3V3c1Mxd2kwMUFBWTlVUDN4SWdxcUNM?= =?utf-8?B?ZUFLamhnWU4rWGpjeTd5bnA3T3RYOFJaeFdWZ3VaTmhvRHFERmVySDc0R0tl?= =?utf-8?B?VFBYaklVL3EwcWRNbHJZakQvTGFEY0pqVk8yOHgzY0JBTXZzVDVJcWE2aFFW?= =?utf-8?B?dktCM3dKQmhHUm9zWWkxWWhrMXM1MzFUdnlZclNQN1VxSUFESEZyVXFCbkhV?= =?utf-8?B?ejNWOG5JQk8ySlhFTnAwNnk1QzliMlZOTU01MTQ3WTdVSEVnWXN1dHloRWlP?= =?utf-8?B?R1MrY0UySWxpVFQ0djdsWmovME1XUm5NQTVuUFQ0b1Vtb25sWXBVSnZhbjdr?= =?utf-8?B?NHBwL2QyY2lJK1dhY2wvcVlGVTBHZU0vY2dwdlFWM0VKbENmakxOQnVWY3F3?= =?utf-8?B?RnovNmhwK3hjK2szQ2pNeVI0OUd1RGI4Z3lFbWxISUZqS0Y3eXUyYmRPdFg2?= =?utf-8?B?V2tVNHdqUURDcE10MnRFeXRqUjRPNG82amV4cTZVa2VlVXVnK0RKNk1NSEY1?= =?utf-8?B?NWZ5cFVNa2ZoeHBrQmxuemg5MGkzOWtIaUpkYU9yeFo1NFZZKzlWeWFUN0hV?= =?utf-8?B?S21GNU12eUVLYkViTmhDdGtjVnFjdFBTcnZ4a04xaDN2eG1McFpJYVgrbWJO?= =?utf-8?B?b04rZmZBNVVSY3YxaHNLQTlIVEQ4c2Z4Wm1NTmF6aVp2eVBVaXZSbm03YkhK?= =?utf-8?B?ZHVwWEQvK2dmRHZxdXJKT0VBTytROUJrQko3Z2JyeFQyQ0NuUHllVFRNRUVQ?= =?utf-8?B?MmV4R0ZxZHQ3V25yS2ZtaHF3UWx2YWRWUHAyN1VtdFl4N0ZmQWRXOGF3ZXo3?= =?utf-8?B?UEFpTDZXaDh4bktjb3hDZDV5cFkyNkZWc29PUXVWUzJ3c0drYUpyRk1ONHF6?= =?utf-8?B?TTYwMy9TNFRnVk1xU295MGt0SVFHUnc4VHZ4cjVuQ3BDZlE0Q1QyY0FGMWRP?= =?utf-8?B?SXRlRzRDaWtYbklUOXlhcWpWeGFPQjJNbHdxSmxiczJMR1o3cE50MFpQUjhv?= =?utf-8?B?U0N2d3o0YlU1Nmw2TTJ5NW94QzJBV2dndzQxWnhqT2o2akdTaGtSTjNUL1BD?= =?utf-8?B?bC9lRXNDWTE3NkdEcjhSbHE0U09JS21lN3dhV09talFpNHQ4U1duL2lGck04?= =?utf-8?B?UlE9PQ==?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: d4e8ed50-fbae-40af-777a-08ddadaafe29 X-MS-Exchange-CrossTenant-AuthSource: AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jun 2025 14:26:48.1069 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: ibzQypeIyhqPR1+On+CxF/9z+CQA/vEveUIteLuiJx7UIsWb0vKiCAo3MqXnGicCATd9JYY/Fkq2WjsgDqg9Lg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR10MB5380 X-Original-Sender: jan.kiszka@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=LKo9YJd6; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Jan Kiszka Reply-To: Jan Kiszka Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: L4KWGQj87ILH On 17.06.25 14:58, 'MOESSBAUER, Felix' via isar-users wrote: > On Tue, 2025-06-17 at 14:35 +0200, 'Cedric Hombourger' via isar-users > wrote: >> We need /sys while assembling the target root file-system but it >> exposes >> more than the build really needs. Some maintainer scripts (e.g. >> mdmadm) >> check /sys/firmware/efi/efivars while configuring themselves. This >> would >> normally be fine but for Isar builds, any information extracted from >> there >> is for the host doing the build and not for the target we are >> building for. >> In addition, packages seeing /sys/firmware/efi will mount efivars >> there >> and will cause do_rootfs_umount to fail unmounting /sys (because of >> that >> extra mount). By mounting a (small) tmpfs as /sys/firmware in the >> root >> file-system, we hide host details from the build; that extra mount >> needs >> to be removed before we attempt to unmount /sys (but we are in >> control). >=20 > Good catch! Eventually all these mountpoints should be documented as > well. >=20 >> >> Signed-off-by: Cedric Hombourger >> --- >> =C2=A0meta/classes/rootfs.bbclass | 9 +++++++++ >> =C2=A01 file changed, 9 insertions(+) >> >> diff --git a/meta/classes/rootfs.bbclass >> b/meta/classes/rootfs.bbclass >> index 5f877962..7b7859b9 100644 >> --- a/meta/classes/rootfs.bbclass >> +++ b/meta/classes/rootfs.bbclass >> @@ -48,6 +48,12 @@ rootfs_do_mounts() { >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= mount -o bind,private /sys '${ROOTFSDIR}/sys' >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 mount --make-rslave '${= ROOTFSDIR}/sys' >> =C2=A0 >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # Mount a tmpfs on /sys/firm= ware to avoid host contamination >> problems >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # (maintainer scripts should= n't pull host data from there) >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 if [ -d '${ROOTFSDIR}/sys/fi= rmware' ]; then >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 moun= t -t tmpfs -o size=3D1m,nosuid,nodev none >> '${ROOTFSDIR}/sys/firmware' >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 fi >> + >=20 > Would bubblewrap help in this case? I'm also wondering if we really > should bind-mount the devices from the host or better mknod them in the > chroot. >=20 > Anyways, this discussion should not stop the patch from being merged. ...but what should be considered first if such an opt-out list only needs to contain firmware or rather even more folders? Or sub-mounts on sysfs in general? Jan --=20 Siemens AG, Foundational Technologies Linux Expert Center --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= 92946c61-7192-44db-a3c6-489e7e1cf911%40siemens.com.