Posts
715
Following
537
Followers
21
➡️ Now at: https://mastodon.social/@xjamesmorris

Linux Kernel security developer, working for Microsoft. Also W7TXT. Views are my own.
Topics: #Linux #kernel #security, #amateurradio, #RF, #hamradio, #electronics, #science, #radioastronomy, #physics, #space, #arduino.

📡 https://w7txt.net/
🐧 https://blog.namei.org/
☠️ https://www.facebook.com/w7txt


2️⃣8️⃣ Here's the 28th post highlighting key new features of the recently published v262 release of systemd.

The purpose of confext images is to carry configuration files to apply to the system. Typically, these configuration files belong to some system service, and it hence would be useful to restart or reload that service when the confext is applied.

With v262 there's now support for that. The extension-release file that is included in the confext and describes it, …

1
2
1
@thilo are Steam Machines useable for general development?
1
0
0

James Morris (old account)

Edited 1 month ago
➡️ I have moved this account to @xjamesmorris
0
0
0
@BorrisInABox are we 100% sure it's not 1997?
0
0
1

@Richard_Littler

I really liked a feature that LineageOS used to have but removed, where you could lie to apps about what privileges they have.

Oh, you want access to my contacts? Here you go! Yes, sorry, I don’t actually have any contacts. You can put some in there, but no one else will see them.

Oh, you absolutely need my precise location information? Okay, here is a point I selected on the map. Yes, I never move from that spot. Maybe the GPS signal isn’t good?

Oh, you want to send notifications? Of course! Oh, you thought that implied that they would be displayed somewhere?

Applications should not be told about users’ notification preferences. The app should control what kinds of things it sends notifications for. The notification subsystem should choose which are shown and when.

1
1
1

James Morris (old account)

Can anyone recommend a good, simple markdown blog? Using GitHub for this is one option but I would also like to keep the current domain name (blog.namei.org).
3
0
0
@cwebber actually how many does the average person have, including all of their devices, cars, kitchenware, light bulbs etc.
0
0
0
@SwiftOnSecurity I'm choosing to interpret this as buying a new hobby on marketplace.
0
0
0
@nina_kali_nina instructions unclear, my Mac Mini won't boot.
1
0
1
@mjg59 @jwz nobody ever pulls this out of the Criterion closet, but it's there.
1
0
1

No foolin' - We will be back in Pasadena on April 1-4, 2027 for . Our Call for Presentations is open through Nov 1st - and tickets sales are now online. www.socallinuxexpo.org/scale24x/

0
3
1

James Morris (old account)

Theory: every hipster city that is not Seattle, is a Baudrillardian simulation of Seattle.
0
0
0

James Morris (old account)

0
0
1

James Morris (old account)

Got 'emmm.
1
0
0

James Morris (old account)

Edited 1 month ago
@AdrianVovk and btw, a related problem needs to be solved for confidential computing payloads, where IPE is not the source of trust but is needed to authorize execution of code which is runtime-installed in a confidential domain. i.e. enforce delegated trust.
0
0
0

James Morris (old account)

@AdrianVovk you could do this with IPE if desired, it is intended to be extensible (I would use an SELinux label associated with the sandbox), but it does need static kernel code modification vs BPF JIT.

RE: https://fosstodon.org/@AdrianVovk/117043284020566593
1
0
0
Show older