-
mnt-system read-only?
Hallo,
is there any way to boot Knoppix 7.20 with mnt-system read-only?
I have configured my Knoppix with overlays and would like to use the system without write access to my usb-stick.
Thank's Moritz
-
Senior Member
registered user
Greetings, moritz.b.
The purpose of Knoppix using a LiveUSB is usually to allow writing data
to a persistence file somewhere on it.
/mnt-system is usually on a fat32 partition with all your cloop-compacted
overlays. Using a separate reiserfs partition for persistence makes it
unnecessary to write anything to the fat32 system, unless you want to modify
some /boot, /efi or reference material there.
If you actually never want to record ANY changes, then a LiveCD or LiveDVD
would seem a better and cheaper answer than restricting a LiveUSB to read-only.
Last edited by utu; 09-02-2013 at 12:12 AM.
-
Partition with /mnt-system read-only
![Quote](images/misc/quote_icon.png)
Originally Posted by
utu
Greetings, moritz.b.
/mnt-system is usually on a fat32 partition with all your cloop-compacted
overlays. Using a separate reiserfs partition for persistence makes it
unnecessary to write anything to the fat32 system, unless you want to modify
some /boot, /efi or reference material there.
Yes, I use a separate reiserfs partition for persistence and I a want to prevent anyone to write on my KNOPPIX-Partition.
![Quote](images/misc/quote_icon.png)
Originally Posted by
utu
If you actually never want to record ANY changes, then a LiveCD or LiveDVD
would seem a better and cheaper answer than restricting a LiveUSB to read-only.
Knoppix from stick is very faster.
Thanks Moritz
-
knoppix 7.20 mnt-system read-only
I have my problem solved with a new cheatcode and adaption the init.
moritz.b
-
Please post your solution, the boot parameter list and the adaptation to init. I would like to implement it.
-
Senior Member
registered user
This is very interesting in the context of USB, and possibly also SSD-disk, use. If, for example, /mnt-system is mounted ro, and the overlay is on ramdisk, concerns about media wear-out are greatly reduced. Overlay could, for example, be read into ramdisk from /mnt-system, or another partition, on boot, and on shutdown, there could be an option for saving it. There are also safety concerns - if overlay is never saved after performing potentially dangerous operations (typically websites wanting to run scripts modifying your browser configuration), one is much better protected.
I consider publishing modified init scripts here a part of best Knoppix practices
-
Senior Member
registered user
![Quote](images/misc/quote_icon.png)
Originally Posted by
moritz.b
I have my problem solved with a new cheatcode and adaption the init.
moritz.b
I have two concerns with the initial premise here.
Unless your Knoppix user is denied root privileges,
making that partition which contains /mnt-system read-only on a write-able
medium offers no real protection against unauthorized changes to the contents
of /mnt-system.
If the Knoppix user is denied root privileges completely,
there are many useful things his Knoppix can't do.
I'd like to see how changes to init might get around these considerations.
-
Senior Member
registered user
![Quote](images/misc/quote_icon.png)
Originally Posted by
utu
I have two concerns with the initial premise here.
Unless your Knoppix user is denied root privileges,
making that partition which contains /mnt-system read-only on a write-able
medium offers no real protection against unauthorized changes to the contents
of /mnt-system.
If the Knoppix user is denied root privileges completely,
there are many useful things his Knoppix can't do.
I'd like to see how changes to init might get around these considerations.
Even if it is possible to remount /mnt-system rw, having it mounted ro by default is clearly a safety measure. And, for example, everything could be placed in loop-mounted ISO images. So that you have to re-create it each time you want to update your persistent store. This could be equivalent to using one or more cloop/squashfs overlays.
-
Senior Member
registered user
![Quote](images/misc/quote_icon.png)
Originally Posted by
moritz.b
I have configured my Knoppix with overlays and would like to use the system without write access to my usb-stick.
I think of cloops as read-only by definition, only written by specific intent, not somehow 'accidentally'. I count on this myself as
protection against my overwriting a rw persistence file. Once my rw persistence content is relatively 'mature', I button its content up
in a cloop to protect against possibly spoiling it myself. This also compacts things and I never really see any performance penalty.
My expectation is that Moritz might be expecting to protect against another Knoppix user purposefully changing Moritz' product,
which I expect that user probably can do if he has Knoppix root privileges. If he doesn't, he surely misses a lot of its power.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
![1TB/2TB USB 3.0 Flash Drive Thumb U Disk Memory Stick Pen PC Laptop Storage lot picture](/store/img/g/PDMAAOSwlhdmFJ5R/s-l225/1TB-2TB-USB-3-0-Flash-Drive-Thumb-U-Disk-Memory-St.jpg)
1TB/2TB USB 3.0 Flash Drive Thumb U Disk Memory Stick Pen PC Laptop Storage lot
$80.39
![Type C USB 3.0 Flash Drive Thumb Drive Memory Stick for PC Laptop 1TB 2TB lot picture](/store/img/g/oroAAOSwsJNmFPcr/s-l225/Type-C-USB-3-0-Flash-Drive-Thumb-Drive-Memory-Stic.jpg)
Type C USB 3.0 Flash Drive Thumb Drive Memory Stick for PC Laptop 1TB 2TB lot
$73.29
![Internal HDD SATA 3.5](/store/img/g/PDYAAOSw-ONkwOKE/s-l225/Internal-HDD-SATA-3-5-250GB-2TB-Hard-Drive-with-Le.jpg)
Internal HDD SATA 3.5" 250GB-2TB Hard Drive with Legacy Windows 11 Pro Installed
$29.15
![Samsung - 990 980 970 PRO & EVO 4TB 2TB 1 TB Internal PCle Gen 4x4 NVMe M.2SSD picture](/store/img/g/4jMAAOSwtO5maEst/s-l225/Samsung-990-980-970-PRO-EVO-4TB-2TB-1-TB-Internal-.jpg)
Samsung - 990 980 970 PRO & EVO 4TB 2TB 1 TB Internal PCle Gen 4x4 NVMe M.2SSD
$320.00
![CISCO A03-D1TBSATA 1TB 7.2K 6G 2.5INCH SATA HDD picture](/store/img/g/qqcAAOSw~xVgcyGX/s-l225/CISCO-A03-D1TBSATA-1TB-7-2K-6G-2-5INCH-SATA-HDD.jpg)
CISCO A03-D1TBSATA 1TB 7.2K 6G 2.5INCH SATA HDD
$9.00
![WD - Blue SN580 1TB Internal SSD PCIe Gen 4 x4 NVMe picture](/store/img/g/QjsAAOSwx-JlMDZh/s-l225/WD-Blue-SN580-1TB-Internal-SSD-PCIe-Gen-4-x4-NVMe.jpg)
WD - Blue SN580 1TB Internal SSD PCIe Gen 4 x4 NVMe
$79.99
![1TB HDD/SSD 2.5](/store/img/g/IlgAAOSwtgpmKHfn/s-l225/1TB-HDD-SSD-2-5-SATA-Hard-Drive-for-Laptop-with-Wi.jpg)
1TB HDD/SSD 2.5" SATA Hard Drive for Laptop with Win 10/Win 11 Pro Pre-installed
$28.99
![Samsung - Geek Squad Certified Refurbished 870 EVO 1TB SATA Solid State Drive picture](/store/img/g/25EAAOSw2gplntqr/s-l225/Samsung-Geek-Squad-Certified-Refurbished-870-EVO-1.jpg)
Samsung - Geek Squad Certified Refurbished 870 EVO 1TB SATA Solid State Drive
$67.99
![Samsung 1TB 850 EVO 2.5](/store/img/g/flYAAOSwzBNmPSrL/s-l225/Samsung-1TB-850-EVO-2-5-SATA-Solid-State-Drive-MZ7.jpg)
Samsung 1TB 850 EVO 2.5" SATA Solid State Drive MZ7LE1T0 ** READ **
$48.99
![1TB HDD/SSD 2.5](/store/img/g/Q0IAAOSwcE9mThpW/s-l225/1TB-HDD-SSD-2-5-SATA-Hard-Drive-Laptop-with-Window.jpg)
1TB HDD/SSD 2.5" SATA Hard Drive Laptop with Windows 11 Pro Installed
$27.99