RE: [cip-dev] [isar-cip-core][PATCH] Revise README files to reflect the latest changes
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <TY3PR01MB110758EEF7898CFF2649036BDC7E82@TY3PR01MB11075.jpnprd01.prod.outlook.com> |
Hi Jan, > If we need to install that package only for having lsblk showing more details, I would not consider this a worthwhile step. Anyway, the key is understanding what is happening here, then we can decide. The information about why "system-cryptsetup" is required in trixie is mentioned here https://gitlab.com/cip-project/cip-testing/cip-security-tests/-/work_items/8#note_2986054640, please have a look at it. As mentioned here this package is already installed as part of security image. If we don't install this package then the lsblk doesn't show any information about the current root device, in that case we should change the confirmation method (rootfs switch) to use "df -h" or some other command instead of "lsblk". Please let me know your opinion. I will check it further. Thanks & Regards Shivanand K -----Original Message----- From: [email protected] <[email protected]> On Behalf Of Jan Kiszka via lists.cip-project.org Sent: 23 June 2026 18:01 To: kunijadar shivanand(TSIP DITC_DIT-OST) <[email protected]>; [email protected] Cc: balakumar adithya(TSIP DITC_DIT-OST) <[email protected]>; dinesh kumar(TSIP DITC_DIT-OST) <[email protected]>; hayashi kazuhiro(林 和宏 □DITC○CPT) <[email protected]> Subject: Re: [cip-dev] [isar-cip-core][PATCH] Revise README files to reflect the latest changes On 23.06.26 13:15, [email protected] wrote: > Hi Jan, > >>> Your dump is missing the verityroot container. Does lsblk no longer list it by default, or were/are there inconsistencies what was >>configured vs. >>> what was run? > >> I also noticed this missing verityroot container in the image. I confirmed the secure boot is enabled from the boot as well as dmesg logs. >However, the "lsblk" command does not show the verityroot by default. > >> Probably we may have to install "systemd-cryptsetup" for non-security image as well, see the fix for security image here[1]. >> This package is available from trixie onwards. > >> [1] >> https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/36b111 >> 92674082aaa1228c60e8c0239fa7c94111 > > Any comments on this update? > Oh, that was a question: If we need to install that package only for having lsblk showing more details, I would not consider this a worthwhile step. Anyway, the key is understanding what is happening here, then we can decide. Jan -- Siemens AG, Foundational Technologies Linux Expert Center