• 2 Posts
  • 37 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle
rss
  • So if you want to use systemd-boot as the bootloader you have to (apparently) install the systemd-utils package. Or you can just use GRUB / efistub.

    Edit: looks like groche beat me to it 😁

    It’s probably been 4 years since I last had to rebuild my Gentoo, but I would be very surprised if there weren’t good OpenRC instructions. I built mine with systemd and Gentoo handbook instructions always felt like ‘Are you sure you don’t want to use OpenRC? Ok, here are the systemd steps I guess’



  • But how to get the OS to recognize it?

    My approach for doing this in Gentoo with an encrypted /home is to configure dracut to make a slightly customized initrd.

    Thanks to dracut modules, not too much configuration is needed - it prompts on boot for the password to decrypt, and then fstab is just configured to mount the decrypted uuid.

    Someone else mentioned using multiple key slots, but I think this is your only real secure option.

    Edit: on second thought, you may be able to get this to work in grub simply by adding rd.luks.uuid=xxx as a kernel boot parameter, and then having the decrypted /dev/mapper uuid in fstab for /home









  • I went camping once with my dad and a few of his buddies when it was frigid cold outside. We piled 5 adult bodies into a camper, and they also left a Coleman gas lantern lit inside the camper all night for warmth.

    I couldn’t sleep for two reasons:

    1. One of my dad’s buddies had horrible snoring, and

    2. I could feel myself choking on the stale air. I ventured outside every so often and would hold the camper door open for a few minutes (or until I would get yelled at). I don’t remember 100% but I think I had a persistent headache that night.

    I’m still convinced we could have all died.











  • I’m using Gentoo with systemd and a customized kernel, and additionally I have the /usr partition LUKS encrypted. Because /usr is absolutely essential for systemd to function, I configured dracut to make a specially crafted initrd which activates the luks lvm and prompts for the password to decrypt and mount /usr on startup before systemd init tries to run.

    About a year or two ago, some update to dracut or some other dependency (assumption) caused the dracut generated initrd’s to kernel panic. After multiple days of troubleshooting, I discovered that just copying forward an older initrd in /boot and naming it to match the new kernel, e.g. initramfs-6.6.38-gentoo.img , allows the system to boot normally .

    So, my Gentoo is booting a kernel 6.6.something with a ramdisk generated in the 5.9 kernel era. I am dreading the day when this behavior breaks and I can no longer update my kernel 😳