RE: [cip-dev] [isar-cip-core][PATCH] Revise README files to reflect the latest changes

<[email protected]>
Newsgroups org.cip-project.lists.cip-dev
Message-ID <TY3PR01MB110756A3B581CA3043809212CC7E82@TY3PR01MB11075.jpnprd01.prod.outlook.com>
Hi Jan, 

> Just as I wrote: Adding the package only for visualizing is overkill. If there are other use cases where we need it, then we can add it >
>unconditionally. If not, then continue to leave this to the final integrator to pull it in or not.

Thanks, understood. 
I'll update the secure boot readme to use other commands to show the rootfs switch instead of lsblk, will send out v2 patch for this.

Thanks & Regards
Shivanand K

-----Original Message-----
From: Jan Kiszka <[email protected]> 
Sent: 29 June 2026 15:48
To: kunijadar shivanand(TSIP DITC_DIT-OST) <[email protected]>; [email protected]
Cc: balakumar adithya(TSIP DITC_DIT-OST) <[email protected]>; dinesh kumar(TSIP DITC_DIT-OST) <[email protected]>; hayashi kazuhiro(林 和宏 □DITC○CPT) <[email protected]>
Subject: Re: [cip-dev] [isar-cip-core][PATCH] Revise README files to reflect the latest changes

On 29.06.26 09:14, [email protected] wrote:
> Hi Jan,
> 
>> If we need to install that package only for having lsblk showing more details, I would not consider this a worthwhile step. Anyway, the key is understanding what is happening here, then we can decide.
> 
> The information about why "system-cryptsetup" is required in trixie is mentioned here https://gitlab.com/cip-project/cip-testing/cip-security-tests/-/work_items/8#note_2986054640, please have a look at it. As mentioned here this package is already installed as part of security image.  
> 
> If we don't install this package then the lsblk doesn't show any information about the current root device, in that case we should change the confirmation method (rootfs switch) to use "df -h" or some other command instead of "lsblk". Please let me know your opinion. I will check it further.  

Just as I wrote: Adding the package only for visualizing is overkill. If there are other use cases where we need it, then we can add it unconditionally. If not, then continue to leave this to the final integrator to pull it in or not.

Jan

> 
> Thanks & Regards
> Shivanand K
> 
> -----Original Message-----
> From: [email protected] <[email protected]> On 
> Behalf Of Jan Kiszka via lists.cip-project.org
> Sent: 23 June 2026 18:01
> To: kunijadar shivanand(TSIP DITC_DIT-OST) 
> <[email protected]>; [email protected]
> Cc: balakumar adithya(TSIP DITC_DIT-OST) 
> <[email protected]>; dinesh kumar(TSIP DITC_DIT-OST) 
> <[email protected]>; hayashi kazuhiro(林 和宏 □DITC○CPT) 
> <[email protected]>
> Subject: Re: [cip-dev] [isar-cip-core][PATCH] Revise README files to 
> reflect the latest changes
> 
> On 23.06.26 13:15, [email protected] wrote:
>> Hi Jan,
>>
>>>> Your dump is missing the verityroot container. Does lsblk no longer list it by default, or were/are there inconsistencies what was >>configured vs.
>>>> what was run?
>>
>>> I also noticed this missing verityroot container in the image. I confirmed the secure boot is enabled from the boot as well as dmesg logs. >However, the "lsblk" command does not show the verityroot by default. 
>>
>>> Probably we may have to install "systemd-cryptsetup" for non-security image as well, see the fix for security image here[1]. 
>>> This package is available from trixie onwards. 
>>
>>> [1]
>>> https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/36b11
>>> 1
>>> 92674082aaa1228c60e8c0239fa7c94111
>>
>> Any comments on this update? 
>>
> 
> Oh, that was a question: If we need to install that package only for having lsblk showing more details, I would not consider this a worthwhile step. Anyway, the key is understanding what is happening here, then we can decide.
> 
> Jan
> 
> --
> Siemens AG, Foundational Technologies
> Linux Expert Center


--
Siemens AG, Foundational Technologies
Linux Expert Center
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.