Skip to content
EN

Back to the catalog

0pointer.net
atom

Pid Eins

0pointer.net

atom

Open the feed

https://0pointer.net/blog/index.atom

Last post
Jun 25, 2026
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
Germany
Site title
http://0pointer.net/
Format
atom

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. Mastodon Stories for systemd v261
    Jun 25, 2026 · original
    On June 19 we released systemd v261 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd261 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 27 posts: Post #1: El-Torito/ISO9660 Support in systemd-repart Post #2: ConditionFraction= Post #3: Minimal Uptime Post #4: Automatic console= Initialization from UEFI Post #5: bootctl link Post #6: Importing UEFI Keyboard/Language Settings into the OS Post #7: systemd-sysinstall Post #8: Machine Tags Post #9: IMDS Support Post #10: Boot Secrets Post #11: Automatic Software TPM Support Post #12: systemd-boot A/B Post #13: Sector Size Adjustment for Boot Block Devices Post #14: kexec Handover Post #15: systemd-repart 's BlockDeviceReplace= Post #16: .rr Drop-ins for systemd-
  2. Mastodon Stories for systemd v260
    Mar 26, 2026 · original
    On March 17 we released systemd v260 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd260 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 21 posts: Post #1: NvPCR Measurements for Activated DDIs Post #2: Varlink Transport Plugins Post #3: Well-Known Varlink Services Post #4: .mstack Overlay Mount Stacks Post #5: RefreshOnReload= in Service Units Post #6: FANCY_NAME= in /etc/os-release Post #7: BindNetworkInterface= in Service Units Post #8: importctl pull-oci for Acquiring OCI Containers Post #9: systemd-report and Metrics API Post #10: udev's tpm2_id built-in and the TPM2 Quirks Database Post #11: Devicetree/CHID Database Post #12: Varlink IPC for systemd-networkd Post #13: systemd-vmspawn knows --ephemeral
  3. Introducing Amutable
    Jan 26, 2026 · original
    Today, we announce Amutable, our ✨ new ✨ company. We – @blixtra@hachyderm.io , @brauner@mastodon.social , @davidstrauss@mastodon.social , @rodrigo_rata@mastodon.social , @michaelvogt@mastodon.social , @pothos@fosstodon.org , @zbyszek@fosstodon.org , @daandemeyer@mastodon.social @cyphar@mastodon.social , @jrocha@floss.social and yours truly – are building the 🚀 next generation of Linux systems, with integrity, determinism, and verification – every step of the way. For more information see → https://amutable.com/blog/introducing-amutable
  4. Mastodon Stories for systemd v259
    Dec 30, 2025 · original
    On Dec 17 we released systemd v259 into the wild . In the weeks leading up to that release (and since then) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd259 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 25 posts: Post #1: systemd-resolved Hooks Post #2: dlopen() everything Post #3: systemd-analyze dlopen-metadata Post #4: run0 --empower Post #5: systemd-vmspawn --bind-user= Post #6: Musl libc support Post #7: systemd-repart without device name Post #8: Parallel kmod loading in systemd-modules-load.service Post #9: NvPCR Support Post #10: systemd-analyze nvcpcrs Post #11: systemd-repart Varlink IPC API Post #12: systemd-vmspawn block device serial Post #13: systemd-repart --defer-partitions-empty= + --defer-partitions-factory-reset= Post #14: userdb support for UUID queries
  5. Mastodon Stories for systemd v258
    Nov 17, 2025 · original
    Already on Sep 17 we released systemd v258 into the wild . In the weeks leading up to that release I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd258 hash tag. It was my intention to post a link list here on this blog right after completing that series, but I simply forgot! Hence, in case you aren't using Mastodon, but would like to read up, here's a list of all 37 posts: Post #1: systemctl start -v Post #2: Home areas Post #3: systemd-resolved delegate zones Post #4: Foreign UID range Post #5: /etc/hostname ??? wildcards Post #6: Quota on /tmp/ Post #7: ConcurretnySoftMax= + ConcurrencyHardMax= Post #8: Product UUID in ConditionHost= Post #9: Context OSC terminal sequences Post #10: uki-url Boot Loader Spec Type #1 fields Post #11: rd.break= boot breakpoints Post #12: Factory Reset Rework Post #13: systemd-resolved DNS C
  6. ASG! 2025 CfP Closes Tomorrow!
    Jun 11, 2025 · original
    The All Systems Go! 2025 Call for Participation Closes Tomorrow! The Call for Participation (CFP) for All Systems Go! 2025 will close tomorrow , on 13th of June! We’d like to invite you to submit your proposals for consideration to the CFP submission site quickly!
  7. Announcing systemd v257
    Dec 16, 2024 · original
    Last week we released systemd v257 into the wild . In the weeks leading up to this release (and the week after) I have posted a series of serieses of posts to Mastodon about key new features in this release, under the #systemd257 hash tag. In case you aren't using Mastodon, but would like to read up, here's a list of all 37 posts: Post #1: Fully Locked Accounts with systemd-sysusers Post #2: Combined Signed PCR and Locally Managed PCR Policies for Disk Encryption Post #3: Progress Indication via Terminal ANSI Sequence Post #4: Multi-Profile UKIs Post #5: The New sd-varlink & sd-json APIs in libsystemd Post #6: Querying for Passwords in User Scope Post #7: Secure Attention Key Logic in systemd-logind Post #8: systemd-nspawn --bind-user= Now Copies User's SSH Key Post #9: The New DeferReactivation= Switch in .timer Units Post #10: Support for the New IPE LSM Post #11: Environment Variables
  8. Announcing systemd v256
    Jun 11, 2024 · original
    Yesterday evening we released systemd v256 into the wild. While other projects, such as Firefox are just about to leave the 7bit world and enter 8bit territory, we already entered 9bit version territory! For details about the release, see our announcement mail . In the weeks leading up to this release I have posted a series of serieses of posts to Mastodon about key new features in this release. Mastodon has its goods and its bads. Among the latter is probably that it isn't that great for posting listings of serieses of posts. Hence let me provide you with a list of the relevant first post in the series of posts here: Post #1: .v/ Directories Post #2: User-Scoped Encrypted Service Credentials Post #3: X_SYSTEMD_UNIT_ACTIVE= sd_notify() Messages Post #4: System-wide ProtectSystem= Post #5: run0 As sudo Replacement Post #6: System Credentials Post #7: Unprivileged DDI Mounts + Unprivileged
  9. A re-introduction to mkosi -- A Tool for Generating OS Images
    Jan 9, 2024 · original
    This is a guest post written by Daan De Meyer, systemd and mkosi maintainer Almost 7 years ago, Lennart first wrote about mkosi on this blog. Some years ago, I took over development and there's been a huge amount of changes and improvements since then. So I figure this is a good time to re-introduce mkosi . mkosi stands for Make Operating System Image . It generates OS images that can be used for a variety of purposes. If you prefer watching a video over reading a blog post, you can also watch my presentation on mkosi at All Systems Go 2023. What is mkosi? mkosi was originally written as a tool to simplify hacking on systemd and for experimenting with images using many of the new concepts being introduced in systemd at the time. In the meantime, it has evolved into a general purpose image builder that can be used in a multitude of scenarios. Instructions to install mkosi can be found in
  10. ASG! 2023 CfP Closes Soon
    Jul 3, 2023 · original
    The All Systems Go! 2023 Call for Participation Closes in Three Days! The Call for Participation (CFP) for All Systems Go! 2023 will close in three days , on 7th of July! We’d like to invite you to submit your proposals for consideration to the CFP submission site quickly! All topics relevant to foundational open-source Linux technologies are welcome. In particular, however, we are looking for proposals including, but not limited to, the following topics: The CFP will close on July 7th, 2023 . A response will be sent to all submitters on or before July 14th, 2023. The conference takes place in 🗺️ Berlin, Germany 🇩🇪 on Sept. 13-14th. All Systems Go! 2023 is all about foundational open-source Linux technologies. We are primarily looking for deeply technical talks by and for developers, engineers and other technical roles. We focus on the userspace side of things, so while kernel topics
  11. Linux Boot Partitions
    Nov 2, 2022 · original
    💽 Linux Boot Partitions and How to Set Them Up 🚀 Let’s have a look how traditional Linux distributions set up /boot/ and the ESP, and how this could be improved. How Linux distributions traditionally have been setting up their “boot” file systems has been varying to some degree, but the most common choice has been to have a separate partition mounted to /boot/ . Usually the partition is formatted as a Linux file system such as ext2/ext3/ext4. The partition contains the kernel images, the initrd and various boot loader resources. Some distributions, like Debian and Ubuntu, also store ancillary files associated with the kernel here, such as kconfig or System.map . Such a traditional boot partition is only defined within the context of the distribution, and typically not immediately recognizable as such when looking just at the partition table (i.e. it uses the generic Linux partition typ
  12. Brave New Trusted Boot World
    Oct 23, 2022 · original
    🔐 Brave New Trusted Boot World 🚀 This document looks at the boot process of general purpose Linux distributions. It covers the status quo and how we envision Linux boot to work in the future with a focus on robustness and simplicity. This document will assume that the reader has comprehensive familiarity with TPM 2.0 security chips and their capabilities (e.g., PCRs, measurements, SRK), boot loaders, the shim binary, Linux, initrds, UEFI Firmware, PE binaries, and SecureBoot. Problem Description Status quo ante of the boot logic on typical Linux distributions: Most popular Linux distributions generate initrds locally, and they are unsigned, thus not protected through SecureBoot (since that would require local SecureBoot key enrollment, which is generally not done), nor TPM PCRs. Boot chain is typically Firmware → shim → grub → Linux kernel → initrd ( dracut or similar) → root file syst
  13. Fitting Everything Together
    May 2, 2022 · original
    TLDR: Hermetic /usr/ is awesome; let's popularize image-based OSes with modernized security properties built around immutability, SecureBoot, TPM2, adaptability, auto-updating, factory reset, uniformity – built from traditional distribution packages, but deployed via images. Over the past years, systemd gained a number of components for building Linux-based operating systems. While these components individually have been adopted by many distributions and products for specific purposes, we did not publicly communicate a broader vision of how they should all fit together in the long run. In this blog story I hope to provide that from my personal perspective, i.e. explain how I personally would build an OS and where I personally think OS development with Linux should go. I figure this is going to be a longer blog story, but I hope it will be equally enlightening. Please understand though th
  14. Testing my System Code in /usr/ Without Modifying /usr/
    Apr 26, 2022 · original
    I recently blogged about how to run a volatile systemd-nspawn container from your host's /usr/ tree, for quickly testing stuff in your host environment, sharing your home drectory, but all that without making a single modification to your host, and on an isolated node. The one-liner discussed in that blog story is great for testing during system software development. Let's have a look at another systemd tool that I regularly use to test things during systemd development, in a relatively safe environment, but still taking full benefit of my host's setup. Since a while now, systemd has been shipping with a simple component called systemd-sysext . It's primary usecase goes something like this: on one hand OS systems with immutable /usr/ hierarchies are fantastic for security, robustness, updating and simplicity, but on the other hand not being able to quickly add stuff to /usr/ is just anno
  15. Running a Container off the Host /usr/
    Apr 5, 2022 · original
    Apparently, in some parts of this world , the /usr/ -merge transition is still ongoing. Let's take the opportunity to have a look at one specific way to take benefit of the /usr/ -merge (and associated work) IRL. I develop system-level software as you might know. Oftentimes I want to run my development code on my PC but be reasonably sure it cannot destroy or otherwise negatively affect my host system. Now I could set up a container tree for that, and boot into that. But often I am too lazy for that, I don't want to bother with a slow package manager setting up a new OS tree for me. So here's what I often do instead — and this only works because of the /usr/ -merge. I run a command like the following (without any preparatory work): systemd-nspawn \ --directory = / \ --volatile = yes \ -U \ --set-credential = passwd.hashed-password.root: $( mkpasswd mysecret ) \ --set-credential = firstbo
  16. Authenticated Boot and Disk Encryption on Linux
    Sep 22, 2021 · original
    The Strange State of Authenticated Boot and Disk Encryption on Generic Linux Distributions TL;DR: Linux has been supporting Full Disk Encryption (FDE) and technologies such as UEFI SecureBoot and TPMs for a long time. However, the way they are set up by most distributions is not as secure as they should be, and in some ways quite frankly weird. In fact, right now, your data is probably more secure if stored on current ChromeOS, Android, Windows or MacOS devices, than it is on typical Linux distributions. Generic Linux distributions (i.e. Debian, Fedora, Ubuntu, …) adopted Full Disk Encryption (FDE) more than 15 years ago, with the LUKS/cryptsetup infrastructure. It was a big step forward to a more secure environment. Almost ten years ago the big distributions started adding UEFI SecureBoot to their boot process. Support for Trusted Platform Modules (TPMs) has been added to the distributi
  17. The Wondrous World of Discoverable GPT Disk Images
    Jun 10, 2021 · original
    TL;DR: Tag your GPT partitions with the right, descriptive partition types, and the world will become a better place. A number of years ago we started the Discoverable Partitions Specification which defines GPT partition type UUIDs and partition flags for the various partitions Linux systems typically deal with. Before the specification all Linux partitions usually just used the same type, basically saying "Hey, I am a Linux partition" and not much else. With this specification the GPT partition type, flags and label system becomes a lot more expressive, as it can tell you: What kind of data a partition contains (i.e. is this swap data, a file system or Verity data?) What the purpose/mount point of a partition is (i.e. is this a /home/ partition or a root file system?) What CPU architecture a partition is intended for (i.e. is this a root partition for x86-64 or for aarch64?) Shall this
  18. File Descriptor Limits
    May 18, 2021 · original
    TL;DR: don't use select() + bump the RLIMIT_NOFILE soft limit to the hard limit in your modern programs. The primary way to reference, allocate and pin runtime OS resources on Linux today are file descriptors ("fds"). Originally they were used to reference open files and directories and maybe a bit more, but today they may be used to reference almost any kind of runtime resource in Linux userspace, including open devices, memory ( memfd_create(2) ), timers ( timefd_create(2) ) and even processes (with the new pidfd_open(2) system call). In a way, the philosophically skewed UNIX concept of "everything is a file" through the proliferation of fds actually acquires a bit of sensible meaning: "everything has a file descriptor " is certainly a much better motto to adopt. Because of this proliferation of fds, non-trivial modern programs tend to have to deal with substantially more fds at the sa
  19. Unlocking LUKS2 volumes with TPM2, FIDO2, PKCS#11 Security Hardware on systemd 248
    Jan 12, 2021 · original
    TL;DR: It's now easy to unlock your LUKS2 volume with a FIDO2 security token (e.g. YubiKey, Nitrokey FIDO2, AuthenTrend ATKey.Pro). And TPM2 unlocking is easy now too. Blogging is a lot of work, and a lot less fun than hacking. I mostly focus on the latter because of that, but from time to time I guess stuff is just too interesting to not be blogged about. Hence here, finally, another blog story about exciting new features in systemd. With the upcoming systemd v248 the systemd-cryptsetup component of systemd (which is responsible for assembling encrypted volumes during boot) gained direct support for unlocking encrypted storage with three types of security hardware: Unlocking with FIDO2 security tokens (well, at least with those which implement the hmac-secret extension; most do). i.e. your YubiKeys (series 5 and above), Nitrokey FIDO2, AuthenTrend ATKey.Pro and such. Unlocking with TPM2
  20. ASG! 2019 CfP Re-Opened!
    Jul 14, 2019 · original
    The All Systems Go! 2019 Call for Participation Re-Opened for ONE DAY! Due to popular request we have re-opened the Call for Participation (CFP) for All Systems Go! 2019 for one day. It will close again TODAY , on 15 of July 2019, midnight Central European Summit Time! If you missed the deadline so far, we’d like to invite you to submit your proposals for consideration to the CFP submission site quickly! (And yes, this is the last extension, there's not going to be any more extensions.) All Systems Go! is everybody's favourite low-level Userspace Linux conference, taking place in Berlin, Germany in September 20-22, 2019. For more information please visit our conference website !

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_0pointer_net_5ec748bb3aff5803. More from this site: 0pointer.net in the Feeds tab.