From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Thu, 07 Aug 2025 17:24:00 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-ed1-f63.google.com (mail-ed1-f63.google.com [209.85.208.63]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 577FNxKi028315 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Thu, 7 Aug 2025 17:23:59 +0200 Received: by mail-ed1-f63.google.com with SMTP id 4fb4d7f45d1cf-617dd0a8151sf3099a12.0 for ; Thu, 07 Aug 2025 08:23:59 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1754580234; cv=pass; d=google.com; s=arc-20240605; b=dwn5ZpgOMQxPaMH9U16B8S9BkO0FfLSwXIcfjVnhCL/ef9myPT/ErvbbOopdnmrLwx zSof42WbRBdv4hIIqOTXX/XtFROlikojXai/R6Ayf309GEnlnnTQ6bT5uXHiFNd+Oxb4 sNfBjWVRi1tzGWbDew7rHv7gfhCjha59krZ7neMOMtiIZiESN8KUnN0YmKDAj8iNSALr KCT3kgCyAsvDU42CJr8gWn0tkVcxMyb6CmibiKn6EbMGPlBmCQqm4oNdvJXqPwiZbdkI XPL4xUEIMronSS2ILEHWm/nLVGTrbSiI1aVc35Y7RjsglXEm1+Z7eE7wut2k6//ySjS3 NqXA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:in-reply-to:content-disposition :mime-version:references:mail-followup-to:message-id:subject:to:from :date:sender:dkim-signature; bh=Snj11vV/lkuVq83kDZNkxtzIFy5xmxMw1HwrR7qmanI=; fh=wWwPFMcKJqcRYax+SRpZb1SZVb9pgAwt5B88BI9KDLM=; b=lcsy051hP5DSwk8QHLwlkdDsAiaDv5gauwM9fMhja++zzxfCJkPNButE5hJUsduugu 9TfVUk7upEkcjXkGGPTBc4R7kfVy6h/7FokRdBGSrnwPDqLnDkdDq4XHY9O0Ppf4myed GMyh4zfM4umrxuqS7reLlzITGBo+dPj0qtizRjZqDiIMr+E/fdWuNE9SV87d3lcPBtvY sH6TGPmqeF7nqI04TSRGLly298yXbPmWBkF9xgxjJ4rY58wda4yTK61yuLAKTnjXAZws WH7uInaHERrR/XLjSKDuuL0kYfQfAbiB0FQlAmjkbiaXcCsjstdynMk7YwLi3UmEB87C wLbw==; darn=ilbers.de ARC-Authentication-Results: i=2; gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1754580234; x=1755185034; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:in-reply-to:content-disposition:mime-version :references:mail-followup-to:message-id:subject:to:from:date:sender :from:to:cc:subject:date:message-id:reply-to; bh=Snj11vV/lkuVq83kDZNkxtzIFy5xmxMw1HwrR7qmanI=; b=kInRMYT1FW1komFSX3AY3MxR+eWGSEoRcNsEA6G4IaRE/H1jhp3+Cr+c/6kwUUyvxi Zd/pexw/4MPvl3REZkpCjlrINyx9FiLHKyMn7ojq2TwpyvXRtZoYgDn4nhVrOl9Asx0v QYXCkgfudZ1Zwi2o5rAdPDPYZYwG93lmBtQr2YXzoQBl6zbkjPlM3WUpq+Br5KZkJLlB 02JwBovdls4Wg08CxRZWSalOZDg9w1V1y0+IPRAW3m9T8baNQYBDIzCzpy1Yo//nUJ3D w00ZtdC/jxnYo3ZMIbT9ei94GCIw8G7SY5avClodSQb3fMPCeb+H26z6r6lIlJk+5ux4 DJIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1754580234; x=1755185034; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence :x-original-authentication-results:x-original-sender:in-reply-to :content-disposition:mime-version:references:mail-followup-to :message-id:subject:to:from:date:x-beenthere:x-gm-message-state :sender:from:to:cc:subject:date:message-id:reply-to; bh=Snj11vV/lkuVq83kDZNkxtzIFy5xmxMw1HwrR7qmanI=; b=kfo78rfivJz3vEVX/BwVo6o5F5bBx9Up24k9yF/SWc/WmAsGoIjn066q89G56c4HMN yYKL+9kKhUIYmP/QMz82uFsCnFgJE7lbKcNNcf2Z3bs/1k8cIp6O6M5JHknWujX6b0b5 a4ljpW09+hXgItalLu6kwybN+2W3kdma0WSZ73DmHllVNwdGUGhPXRTY1hcn7adAENqi BFGAj7ry/Kl0kEEwq3xUiO1b7Qw6ch9Zswz9JS+7UDW0jGEUr4su6MqWZNlO1RVnuL2f T0fHylJ9LI5pxVZ+lQ+0sa1YCNO040UBwnWw1bUjo4CrDp9ZCg0/WNiHtyGnoRrS6rtZ w5bA== Sender: isar-users@googlegroups.com X-Forwarded-Encrypted: i=2; AJvYcCVydnfdLeOOyeV1yZcl/YLhmtF0L52nLB3M/DoYBjxfP5WwZr5OFYGqRB0YuGZOqmp+EaiO@ilbers.de X-Gm-Message-State: AOJu0YyXvmXhmV+R6CZ0juvFDd7rTkaUuygj2Qs1fmOdwzDI72u36wOB TLvNHzGj0blmGo4f5YbWVh0EWscTbH1C+5Q+vS5XAfoAgCaZMKw+FBXM X-Google-Smtp-Source: AGHT+IEVRNeKLzABgmA53R2KeKM7h97pkLUbMnbrX65WeUa8PaLZcE+VfzCLz0IOci6aoM8MOCzPtA== X-Received: by 2002:a05:6402:254e:b0:607:eea1:1038 with SMTP id 4fb4d7f45d1cf-617961ff04amr2594186a12.6.1754580233613; Thu, 07 Aug 2025 08:23:53 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h=AZMbMZdTb2K5EMpiLBhme1GInw3YnXO9Fc8iSs3Lv4MlYxs3JQ== Received: by 2002:a05:6402:5186:b0:609:aa85:8d81 with SMTP id 4fb4d7f45d1cf-617b1ef6f38ls559976a12.2.-pod-prod-00-eu; Thu, 07 Aug 2025 08:23:51 -0700 (PDT) X-Received: by 2002:aa7:d84e:0:b0:614:f9f8:7806 with SMTP id 4fb4d7f45d1cf-617b38f07aemr2362657a12.13.1754580230908; Thu, 07 Aug 2025 08:23:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1754580230; cv=none; d=google.com; s=arc-20240605; b=XwLoxZAoirf5S6KGIM+xD9My6s3SkmBgvQJ/a1831FU6TskaO1TF2D0I13YpZvGUka PMzN7v61IbTakSK7pD1s44HFVaMZpkEnDE8J4cQv2O6ynLVxzea0M49I3BfElrpudEkQ Dd4emWpcvaDKjNZfZdQQaXTWeDJvhMJhnqxtJfW1Kd6aDQ/cYvHGFKDHgt8LsuwyJH+O pRR4Tt3HoiStJCp6gQ1pwlPcZ00lCROsXMfpQWjPBcgU/ssWMdB4E07X2c4fwH9aRt6N 10sWDwdUUf6y/DqqI02Bh8UqNpDQrbSDThV6DnYSgCzPbG9D3F0It4W1N3Xzg2lMZM20 agSg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=in-reply-to:content-disposition:mime-version:references :mail-followup-to:message-id:subject:to:from:date; bh=QAoQBeezozkWy72dHZdcVP/vI2E/0vk+1geXsQnrwgc=; fh=7tclEdh7YbwSQowgJ6LNq720O7H5HTEaqj22NJWRE2E=; b=EmppVRzHzZRXZi4aXQOzw1VkWffELSCqMrPODDYGwaTLtZazu/cTO9bHSV0DKjkhAn KF1lr0NmVwDOQJt+jfGZgGleUXuqmaNeAcXvE1lzXM9EaOl0ZgGX679DArwSQPLDIlAk YkWCT3aEPZA4BYjJcA1/gFpYmsucqyBczRnwgcvtzFHwgX1Meet8Ph9XFmyHukdnyYrc kYhHoOgd+YoMiGHl6egZ2MunNHSlyWKjCsAcu43qYlDWe0y2pY85j2msMYUbzavgfh32 Kr9BUoFAGF01FnhasNKH/KM3oGlCavqAB/4lJs+Dn8rD1lvLSsXv+2A8m/UCMB3M20PC eogw==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net Received: from shymkent.ilbers.de (shymkent.ilbers.de. [85.214.156.166]) by gmr-mx.google.com with ESMTPS id 4fb4d7f45d1cf-615a8673e72si479218a12.0.2025.08.07.08.23.50 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Thu, 07 Aug 2025 08:23:50 -0700 (PDT) Received-SPF: pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) client-ip=85.214.156.166; Received: from abai.de ([88.130.203.42]) (authenticated bits=0) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPSA id 577FNnBg028302 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Thu, 7 Aug 2025 17:23:50 +0200 Date: Thu, 7 Aug 2025 17:23:48 +0200 From: Baurzhan Ismagulov To: isar-users@googlegroups.com Subject: Re: [PATCH] rootfs: do not expose /sys/firmware while building root file-systems Message-ID: Mail-Followup-To: isar-users@googlegroups.com References: <20250617123507.2245-1-cedric.hombourger@siemens.com> MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Disposition: inline In-Reply-To: <20250617123507.2245-1-cedric.hombourger@siemens.com> X-Spam-Status: No, score=-4.6 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-Original-Sender: ibr@radix50.net X-Original-Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-TUID: IrQxFNxR13a7 On 2025-06-17 14:35, 'Cedric Hombourger' via isar-users wrote: > We need /sys while assembling the target root file-system but it exposes > more than the build really needs. Some maintainer scripts (e.g. mdmadm) > check /sys/firmware/efi/efivars while configuring themselves. This would > normally be fine but for Isar builds, any information extracted from there > is for the host doing the build and not for the target we are building for. > In addition, packages seeing /sys/firmware/efi will mount efivars there > and will cause do_rootfs_umount to fail unmounting /sys (because of that > extra mount). By mounting a (small) tmpfs as /sys/firmware in the root > file-system, we hide host details from the build; that extra mount needs > to be removed before we attempt to unmount /sys (but we are in control). Applied to next, thanks. With kind regards, Baurzhan -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/aJTFBNOxaBhG_vie%40abai.de.