From owner-freebsd-current@freebsd.org Fri Jan 27 17:37:21 2017 Return-Path: Delivered-To: freebsd-current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id A9E2DCBF2FF for ; Fri, 27 Jan 2017 17:37:21 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id 7FB7C1D71 for ; Fri, 27 Jan 2017 17:37:21 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mailman.ysv.freebsd.org (Postfix) id 7BBF0CBF2FD; Fri, 27 Jan 2017 17:37:21 +0000 (UTC) Delivered-To: current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 7B5D3CBF2FC for ; Fri, 27 Jan 2017 17:37:21 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-qt0-x22b.google.com (mail-qt0-x22b.google.com [IPv6:2607:f8b0:400d:c0d::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 2F7451D6F for ; Fri, 27 Jan 2017 17:37:21 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-qt0-x22b.google.com with SMTP id v23so145648053qtb.0 for ; Fri, 27 Jan 2017 09:37:21 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=hzf/MEzWXd/61OngfIem6kvo0Zz9iXJl5KL1AQJ8c7U=; b=fBGLsjK/v+KGVQSUhUcrOdZnIyadLNOgBcUkGCwbGSBtcMHadj8hCbQFpwt1++G7Z+ dGzC2xFXVPCmCaXoP7BlRQA/uRPvE94OX4xoAgSP5wfs+O9zSkGR8GMguF3iIM32kJvt VO+axUDl3fORegfU7VcSFzv4QiEHwgrbJkJi3nu3slO5gZCFlV7csuOB+sJm9JYvfmJX 1r2J+6hl/SNuyEAtUKTuWi1VKb3SgZhfXb4mlkLbZRrXlOLnGLAlVy0ebEA82sd0dS5O w7MG7PGfmKhWFacpzXT5UruvMxPPlR4sbgqnJugkee4ixxusBMT1pM/sQmh/I3PSO5t6 6Waw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=hzf/MEzWXd/61OngfIem6kvo0Zz9iXJl5KL1AQJ8c7U=; b=ECJWbpujz8e6axPdm/NT2mbI/PYuxrb9s6bEpXL0BMcKXkX4QIVO57GZLKDeZpE8yW 4D23iT0rhCnrtDSVEnWocH0pOo84DlIR/FPLBLc3nqn2X+esLrpNOeaexSCvYaxS2a08 XSMb+pu/IEJN0SIHh94jAfmXidSTfdehE//EFURC0aFxsLDBb3+iorHlUcL6A5PanmI+ v5mAACUCX5tl93bMFP4Bu1VsoBVUGFpAaUHBHyrSrnrQF5Arhyjxph1ukCyvfihvTu0V POIfsjK9AkiZ2qH89smKGJeFScAaRBtLMxTZE7IdQ98z+hyFzorqaUaNErtsS8XwFeKB BxUA== X-Gm-Message-State: AIkVDXInpa7AfofyCbGpCb4wFGpA9CvM+pt41ShmQpopcRCPqf9fVW5vnOjgWAtJSo57JQrk X-Received: by 10.200.43.33 with SMTP id 30mr8669463qtu.107.1485538640358; Fri, 27 Jan 2017 09:37:20 -0800 (PST) Received: from mutt-hardenedbsd ([63.88.83.66]) by smtp.gmail.com with ESMTPSA id d191sm4676402qke.15.2017.01.27.09.37.19 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Fri, 27 Jan 2017 09:37:19 -0800 (PST) Date: Fri, 27 Jan 2017 12:37:19 -0500 From: Shawn Webb To: Allan Jude Cc: Warner Losh , Toomas Soome , "Ngie Cooper (yaneurabeya)" , FreeBSD Current Subject: Re: gptzfsboot grew a lot after skein support was added; need knob to control bloat Message-ID: <20170127173719.atrbjuj7mpwmf3o3@mutt-hardenedbsd> References: <444df1a4-1f27-49a8-6fa6-81f5853e6d80@freebsd.org> <20170127173338.wv6dul7zhxaaw4f4@mutt-hardenedbsd> <94f227b6-1f94-e54a-825a-dd9554c3bea3@freebsd.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="kam6yvtrhj75rx5j" Content-Disposition: inline In-Reply-To: <94f227b6-1f94-e54a-825a-dd9554c3bea3@freebsd.org> X-Operating-System: FreeBSD mutt-hardenedbsd 12.0-CURRENT-HBSD FreeBSD 12.0-CURRENT-HBSD X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: NeoMutt/20161126 (1.7.1) X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 27 Jan 2017 17:37:21 -0000 --kam6yvtrhj75rx5j Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Jan 27, 2017 at 12:35:21PM -0500, Allan Jude wrote: > On 2017-01-27 12:33, Shawn Webb wrote: > > On Fri, Jan 27, 2017 at 12:30:17PM -0500, Allan Jude wrote: > >> On 2017-01-27 12:05, Warner Losh wrote: > >>> On Fri, Jan 27, 2017 at 12:34 AM, Toomas Soome wrote: > >>>> > >>>>> On 27. jaan 2017, at 1:40, Ngie Cooper (yaneurabeya) wrote: > >>>>> > >>>>> Hi, > >>>>> I tried upgrading one of my workstations and unfortunately th= e freebsd-boot partition is too small (I follow manpage directions, exactly= , and those seem to be too small as of 10.3-RELEASE timeframe), and I don??= ?t have enough space or ability to resize the partition and make it bigger.= So, I???m in need of a build knob to control the bloat, and/or having an a= lternative boot loader without geli/skein/crypto support compiled in. Would= you be opposed to the work? > >>>>> Thanks, > >>>>> -Ngie > >>>> > >>>> > >>>> I do agree that since the geli knob is already there, it may do. Of = course we also can think of additional knobs, but there is an issue - it wo= nt help just to exclude some files, the additional features also do sit in = the code, so the replacement stubs will be needed, also testing them all ov= er will take some time. And the preprocessor spaghetti really is nasty thin= g to deal with;) > >>>> > >>>> And then there is another issue (partly why I did the feature suppor= t in first place) - as the kernel does not block user from enabling the fea= tures, the user can end up facing non-bootable setup which is also not good= , as user is using perfectly legal options, and still the whole thing is ju= st rendered unusable??? > >>> > >>> I'm curious why you can't find the space for a bigger partition? > >>> Almost all drives these days are partitioned with a little wasted > >>> space, and that wasted space should be more than enough to cover us > >>> here. Also, most drives have a swap partition that can be shrunk a > >>> trivial amount to get space for this... > >>> > >>> Warner > >>> > >> > >> I need to do some testing to make a recipe that works for it, but the > >> other option is to use the ZFS bootcode area. > >> > >> ZFS it self, reserves something like 3.5 mb of space in the ZFS > >> partition, for boot code. This is how we boot ZFS on MBR. > >> > >> It should be possible to use this on GPT as well, we just don't. > >=20 > > In the future, maybe it'd be a good idea for the installer to leave > > more space (a few MB, perhaps?) between the freebsd-boot and > > freebsd-swap partitions? At least, for ZFS installs. > >=20 > > Thanks, > >=20 >=20 > The PMBR code has a limitation for 536kb, and it all has to fit under > the 640k barrier, so the current 512kb size is plenty. The issue is some > people are upgrading from systems that were isntalled long ago, when > 64kb or less was the default. Gotcha. Thanks for the explanation. --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --kam6yvtrhj75rx5j Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKrq2ve9q9Ia+iT2eaoRlj1JFbu4FAliLhU4ACgkQaoRlj1JF bu7C5A//X9awaexjUsyO4sG9BAhgy+6BdlKZMGx4Hg5AEI71Sh6oRI5C96eMriOa vcZKzktTGH8AW/3hl0MMP2XIQPrfGhpegYjPQe0YXAnrdePiDrNQPmJeYW1mB7J4 FcgrSxAxBdrQ1FLZKflZUQkKeXC5ByIStWSPtu7CxZGc36qYPDIgMZHcW9FEboXp ErFTYfgnNRBr5k2PaR1bymN32sg8Q5vp2+PJ7KkOFIujfOSO+QhyDeoBIEQRAZ5w nF+a5A8y8T5HcYWRL3Rivdhwmw1wMfIIl6gLFeHa/rrELy0i5QHlgCkQumYq/R5k RSSHfMORHZ5oktZVfOG17bZ3f6OEMuBVXHsEo/2qQcTsMGGysT16qE3wVM1dEh27 YKaNtdPahqJeMkgooQBXEv6YyarA/azVfvmIvRtADxi/qJ0AvZ621M0HZQHh1VtB 63lLQnFk9E5k/AoSx88o5XOvOC7galkxmEoLC18+glKatdS0LPB4AbkzFgNoUWdO j6KV6P8W5fPJI7YWYYjWWB+U/9gYTyUGDCmOauiAhd6QlASybgdc1NkFMia+Z3/h hO93MlPeToFMNqhN8HHRAQ8Jha8y5m6VfhtC7uLvs5Z9HmCvJhxyGMOABD5YpSX7 AS3N8otHDw/i+CjR5WSrmRb0j5VqjBl6Wt7zRN2ug8JBl9SSJh0= =rCrY -----END PGP SIGNATURE----- --kam6yvtrhj75rx5j--