4 ms·
With LinuxBoot you can use any filesystem that Linux supports, not just FAT. You can update boot entries by editing shell scripts, rather than manipulating opa
by thudson 9y ago
With LinuxBoot you can use any filesystem that Linux supports, not just FAT.
You can update boot entries by editing shell scripts, rather than manipulating opaque NVRAM variables.
You can run Linux applications straight from the ROM if you want to do that.
You can avoid legacy partitions entirely and use LVM for flexible volume management.
And...
You can build it yourself and verify that the reproducible build matches what others have built to ensure that the firmware is clean.
You can have the firmware attest to you via TOTP that it hasn't been changed.
You can have a fully encrypted disk, with secrets sealed in the TPM and only unsealed if the firmware is unmodified.
You can include device drivers for things that UEFI doesn't support.
You can use external hardware tokens like a Yubikey to sign the OS install and have the firmware validate the GPG signature.
Or what ever else you might want to do...
- Annatar 9y agoAll very good and very valid points. Just wouldn’t want to do that with Linux. OpenBSD or FreeBSD, yes; illumos, yes; Linux - out of the question.
- pferde 9y agoYou're probably getting downvoted because you did not follow up with "...because $reasons", so your post comes off as petty Linux hate (is there such word as "anti-fanboyism"?).
- Annatar 9y agoThanks for the clarification. In the context, most other posts here contain no technical detail whatsoever either and are nothing more than unsubstantiated opinions (same as mine); they just really dislike that there is someone out there who doesn’t think that Linux is phenomenal. In the days of Microsoft dominance, we called that monoculture. Volumes have been written and videos filmed on all the inadequacies of the GNU/Linux kernel, far more than I could cram into one “Hacker News” post. I for example get a painful reminder of just how unfit the Linux kernel is as firmware every time I turn on my television set which runs it (ARM V7 Linux for the curious). After that, I don’t want any more. That is not an isolated scenario. Apropos petty, my hate of GNU/Linux is epic.
- O_H_E 9y agoI seriously would be interested to learn more about that, can you point me to some resources
- Annatar 9y agoWhy certainly! This is as good of a place to start as any: https://www.youtube.com/watch?v=wTVfAMRj-7E https://www.youtube.com/watch?v=wTVfAMRj-7E
- Fnoord 9y agoA 4h40m interview on YouTube is considered a source these days. How about written text? Makes it much easier to read and quote.
- Annatar 9y agoThe delivery medium is irrelevant. And yes, this particular video is a good source, since the person in the video is an authority on kernel engineering; his teams have managed to deliver a fully functional storage appliance, a volume manager/filesystem from the future, infinitely extensible kernel and userspace debuggers, a dynamic tracing framework, a very high performance operating system which for more than two decades was the textbook on large scale symmetric multiprocessing, and a large scale cloud solution which mops the competition in efficiency and design of use. Oh, and a parallel startup/shutdown mechanism as part of a larger self-healing framework. I have a sneaking suspicion that this person might know what he’s talking about after having written and debugged a good portion of that code. I’m not putting in Linux as firmware because I already have it in the products and infrastructure I use and not only is it piss poor slow and inefficient and crashes all of the time, but greenhorns who think they know best keep introducing compatibility-breaking changes. Out of the question, no more. And polishing a piss poor solution is no solution either. Start with a solid foundation, which excludes Linux immediately from the consideration.
- Fnoord 9y ago
- Fnoord 9y agoLiterally nobody cares that you don't wanna do that with Linux. That's like your problem. The world needs practical solutions; not *NIX wars or zealotry.
- Annatar 9y agoThere are practical solutions: FreeBSD, OpenBSD, SmartOS. Linux for firmware is not one of those, but if you think it is, good luck with using it for that. Don't bother to let me know how it worked out for you.