From owner-freebsd-current@freebsd.org Wed Nov 15 16:06:17 2017 Return-Path: Delivered-To: freebsd-current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 5702BDE10E6 for ; Wed, 15 Nov 2017 16:06:17 +0000 (UTC) (envelope-from eric@metricspace.net) Received: from mail.metricspace.net (mail.metricspace.net [IPv6:2001:470:1f11:617::107]) by mx1.freebsd.org (Postfix) with ESMTP id 110597087D; Wed, 15 Nov 2017 16:06:17 +0000 (UTC) (envelope-from eric@metricspace.net) Received: from [10.82.163.165] (mobile-166-171-184-196.mycingular.net [166.171.184.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) (Authenticated sender: eric) by mail.metricspace.net (Postfix) with ESMTPSA id C765019FA; Wed, 15 Nov 2017 16:06:15 +0000 (UTC) Date: Wed, 15 Nov 2017 11:06:14 -0500 User-Agent: K-9 Mail for Android In-Reply-To: References: MIME-Version: 1.0 Subject: Re: GELI with UEFI supporting Boot Environments goes to HEAD when? To: Warner Losh ,Tommi Pernila CC: "imp@freebsd.org" , freebsd-current , "[ScaleEngine] Allan Jude" From: Eric McCorkle Message-ID: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.25 X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Nov 2017 16:06:17 -0000 I'll reply in more detail later on, when I'm not on a phone On November 15, 2017 9:47:54 AM EST, Warner Losh wrote: >On Wed, Nov 15, 2017 at 3:28 AM, Tommi Pernila > >wrote: > >> Hi All, >> >> Anyone have an idea when the GELI with UEFI supporting Boot >> Environments goes to HEAD? >> >> The Phabricator reviews for this seem to done=2E >> Also recently I have seen quite a few commits done by @imp which >touch >> GELI, >> Are these related to this feature or something else? >> >> So it could be that this feature is already in HEAD, or are still >some >> parts pending? >> > >It will be available once we move to loader=2Eefi and ditch boot1=2Eefi, >which >is some weeks away=2E > >Warner > > >> Below a clip from Allan describing the feature i'm looking for: >> >> >> On Tue, 11 Jul 2017 at 18=2E31, Allan Jude >wrote: >> >>> >>> Boot environments with a bootpool do not work=2E Support for GELI with >>> UEFI is coming soon=2E This will allow you to move /boot into the GELI >>> encrypted pool, and get rid of the bootpool, and properly use boot >>> environments=2E >>> >>> -- >>> Allan Jude >> >> >> >> Br, >> >> Tommi >> --=20 Sent from my Android device with K-9 Mail=2E Please excuse my brevity=2E From owner-freebsd-current@freebsd.org Wed Nov 15 15:35:45 2017 Return-Path: Delivered-To: freebsd-current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id D92E1DE0319 for ; Wed, 15 Nov 2017 15:35:45 +0000 (UTC) (envelope-from tommi.pernila@gmail.com) Received: from mail-qt0-f178.google.com (mail-qt0-f178.google.com [209.85.216.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id A0BF06F81C; Wed, 15 Nov 2017 15:35:45 +0000 (UTC) (envelope-from tommi.pernila@gmail.com) Received: by mail-qt0-f178.google.com with SMTP id e19so30404739qte.8; Wed, 15 Nov 2017 07:35:45 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=T++LgAFeesr0NADuyWzqG9uT/WG2HhXOxD4tgRnfBfk=; b=n39pB0PC6Rf8NAgxp04v1NONXDCW6z/kRmA9PAHndHGA21THTIiaNXgKc62JjOBlGX X/SW1wszaE7pti7lQ9x0mymzUyqzT3bcRLpz+KFN617C1r/DhAUrUhibw9aqgmE1SWlY uJY2N02CsqKm9LlGk6LUSCjLeATHpXTPzDidAdw2zyOtYHxZtAXGApry5osxViNPuO1p tbqT4QfbrDQAizaIv8KBnYyg8cp/SaQr7SfuqsghJccT3slM7ZSK7ytNABXG55U2BepR bUQ81jaDd3/MpqSFB/0wqqAgQ/IaWRPGtUMRaj8NoCs6pL1qh8S0OGUZwJ3TXBd+qoew 80dg== X-Gm-Message-State: AJaThX4IbFInK3+zXs8BXclAYJp7CkKX1fij05awdPRbU7o9sRF3JeEV UczqZyb1eHAQ9l9wY874sKy9CugbdAPT9bPoQsQ6sg== X-Google-Smtp-Source: AGs4zMY1kTdqbCqFEEuQkCkZjqCl8uVkxb4BqloH5EgRnTVSpnFhqLmjrcAMvFZRCLKy7nMzxAnvAG/NGd5y0SioOyo= X-Received: by 10.55.73.129 with SMTP id w123mr25859877qka.156.1510760143816; Wed, 15 Nov 2017 07:35:43 -0800 (PST) MIME-Version: 1.0 References: In-Reply-To: From: Tommi Pernila Date: Wed, 15 Nov 2017 15:35:29 +0000 Message-ID: Subject: Re: GELI with UEFI supporting Boot Environments goes to HEAD when? To: Warner Losh Cc: Eric McCorkle , "[ScaleEngine] Allan Jude" , freebsd-current , "imp@freebsd.org" X-Mailman-Approved-At: Wed, 15 Nov 2017 16:55:00 +0000 Content-Type: text/plain; charset="UTF-8" X-Content-Filtered-By: Mailman/MimeDel 2.1.25 X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Nov 2017 15:35:45 -0000 On Wed, 15 Nov 2017 at 16.47, Warner Losh wrote: > On Wed, Nov 15, 2017 at 3:28 AM, Tommi Pernila > wrote: > >> Hi All, >> >> Anyone have an idea when the GELI with UEFI supporting Boot >> Environments goes to HEAD? >> >> The Phabricator reviews for this seem to done. >> Also recently I have seen quite a few commits done by @imp which touch >> GELI, >> Are these related to this feature or something else? >> >> So it could be that this feature is already in HEAD, or are still some >> parts pending? >> > > It will be available once we move to loader.efi and ditch boot1.efi, which > is some weeks away. > > Warner > Ok. Thanks Warner and Eric for all of your work :) -Tommi > >> Below a clip from Allan describing the feature i'm looking for: >> >> >> On Tue, 11 Jul 2017 at 18.31, Allan Jude wrote: >> >>> >>> Boot environments with a bootpool do not work. Support for GELI with >>> UEFI is coming soon. This will allow you to move /boot into the GELI >>> encrypted pool, and get rid of the bootpool, and properly use boot >>> environments. >>> >>> -- >>> Allan Jude >> >> >> >> Br, >> >> Tommi >> >