From: Gao Xiang <hsiangkao@linux.alibaba.com>
To: Askar Safin <safinaskar@zohomail.com>
Cc: "Byron Stanoszek" <gandalf@winds.org>,
"Christoph Hellwig" <hch@lst.de>,
gregkh <gregkh@linuxfoundation.org>,
"julian.stecklina" <julian.stecklina@cyberus-technology.de>,
linux-fsdevel <linux-fsdevel@vger.kernel.org>,
linux-kernel <linux-kernel@vger.kernel.org>,
rafael <rafael@kernel.org>,
torvalds <torvalds@linux-foundation.org>,
viro <viro@zeniv.linux.org.uk>,
"Thomas Weißschuh" <thomas.weissschuh@linutronix.de>,
"Christian Brauner" <brauner@kernel.org>
Subject: Re: [PATCH] initrd: support erofs as initrd
Date: Fri, 29 Aug 2025 01:00:39 +0800 [thread overview]
Message-ID: <18d15255-2a6f-4fe8-bbf7-c4e5cc51692c@linux.alibaba.com> (raw)
In-Reply-To: <198f1915a27.10415eef562419.6441525173245870022@zohomail.com>
On 2025/8/29 00:44, Askar Safin wrote:
> ---- On Wed, 27 Aug 2025 13:58:02 +0400 Gao Xiang <hsiangkao@linux.alibaba.com> wrote ---
> > The additional cpio extraction destroys bit-for-bit identical data
> > protection, or some other new verification approach is needed for
> > initramfs tmpfs.
>
> Put erofs to initramfs and sign whole thing.
>
> Also: initramfs's are concatenatable.
> So, you can put erofs to cpio and sign the result.
> And then concatenate that cpio with another cpio (with init).
>
> Also, you can put erofs to cpio, then sign this thing, and then add init to kernel
> built-in cpio (via INITRAMFS_SOURCE).
Which part of the running system check the cpio signature.
Why users need some cpio format (which even cannot be random accessed)
since it already contains a real filesystem, also which part check the
signature of `init` itself before `init` runs? IOWs, why `init` in
cpio can be trusted to run?
Why users need to extract the whole cpio to tmpfs just for some data
part in the erofs? even some data is never used?
Why the initrd memory cannot be used directly as the dax filesystem
instead of copying to tmpfs instead?
Thanks,
Gao Xiang
next prev parent reply other threads:[~2025-08-28 17:00 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-20 19:28 [PATCH] initrd: support erofs as initrd Julian Stecklina
2025-03-20 19:28 ` Julian Stecklina via B4 Relay
2025-03-21 2:08 ` Al Viro
2025-03-21 8:46 ` Christian Brauner
2025-03-21 12:49 ` Julian Stecklina
2025-03-21 5:01 ` Christoph Hellwig
2025-03-21 5:27 ` Gao Xiang
2025-03-21 13:17 ` Julian Stecklina
2025-03-21 13:57 ` Gao Xiang
2025-04-07 8:57 ` hch
2025-04-07 11:19 ` Julian Stecklina
2025-04-07 16:05 ` Gao Xiang
2025-08-25 18:27 ` Askar Safin
2025-08-26 7:59 ` Christoph Hellwig
2025-08-26 14:21 ` Byron Stanoszek
2025-08-26 15:32 ` Gao Xiang
2025-08-26 16:00 ` Gao Xiang
2025-08-27 9:22 ` Askar Safin
2025-08-27 9:48 ` Gao Xiang
2025-08-27 9:58 ` Gao Xiang
2025-08-28 16:44 ` Askar Safin
2025-08-28 17:00 ` Gao Xiang [this message]
2025-08-28 17:14 ` Gao Xiang
2025-08-30 11:49 ` Askar Safin
2025-08-30 12:23 ` Gao Xiang
2025-08-26 17:00 ` Askar Safin
2025-03-21 8:48 ` Christian Brauner
2025-03-21 9:16 ` Thomas Weißschuh
2025-03-21 13:26 ` Julian Stecklina
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=18d15255-2a6f-4fe8-bbf7-c4e5cc51692c@linux.alibaba.com \
--to=hsiangkao@linux.alibaba.com \
--cc=brauner@kernel.org \
--cc=gandalf@winds.org \
--cc=gregkh@linuxfoundation.org \
--cc=hch@lst.de \
--cc=julian.stecklina@cyberus-technology.de \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=safinaskar@zohomail.com \
--cc=thomas.weissschuh@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.