eaon
eaon
@MRZHD1 assigned to you, as before, feel free to ask questions if you have any!
Reopening this as we're currently exploring FDE options. (Ironically, this is an idea that came to me tonight and I found this issue by researching grsec and kexec compatibility :laughing:)...
Because we have `CONFIG_KEXEC_FILE` enabled already, I can confirm that we are able to "soft reboot" with `kexec` if we use the `-s` argument, instructing it to use the file...
Migration still missing, it should revert `rc.local` on `sd-log` and `sd-gpg` on existing installs.
Pretty much! 1. The `qubes-features` key-value store extension would only define the "base" namespace (or tree, technically), the keys we use for configuring anything else is up to future-us, and...
Looks like the infrastructure necessary to do this will be taken care of by R4.2 :smile: Thank you @marmarta and @marmarek :raised_hands:
I think you covered everything we talked about, thanks a lot for summarising it in a concise manner! The only thing I'd want to expand on at this stage (to...
> export/print flows could be compromised by vulnerabilities that pending updates might fix I think SecEng input would be useful here (poke @lsd-cat), but I don't think I agree with...
Likely ran into this while working on #859
Nice find @rocodes! Regarding how to fix this though, IMO, basically all of the "we're just placing files in particular places" operations should not be done with Salt but instead...