Results 1 to 9 of 9

Thread: mnt-system read-only?

  1. #1
    Junior Member
    Join Date
    Aug 2013
    Posts
    4

    mnt-system read-only?

    Hallo,

    is there any way to boot Knoppix 7.20 with mnt-system read-only?
    I have configured my Knoppix with overlays and would like to use the system without write access to my usb-stick.


    Thank's Moritz

  2. #2
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631
    Greetings, moritz.b.

    The purpose of Knoppix using a LiveUSB is usually to allow writing data
    to a persistence file somewhere on it.

    /mnt-system is usually on a fat32 partition with all your cloop-compacted
    overlays. Using a separate reiserfs partition for persistence makes it
    unnecessary to write anything to the fat32 system, unless you want to modify
    some /boot, /efi or reference material there.

    If you actually never want to record ANY changes, then a LiveCD or LiveDVD
    would seem a better and cheaper answer than restricting a LiveUSB to read-only.
    Last edited by utu; 09-02-2013 at 12:12 AM.

  3. #3
    Junior Member
    Join Date
    Aug 2013
    Posts
    4

    Partition with /mnt-system read-only

    Quote Originally Posted by utu View Post
    Greetings, moritz.b.

    /mnt-system is usually on a fat32 partition with all your cloop-compacted
    overlays. Using a separate reiserfs partition for persistence makes it
    unnecessary to write anything to the fat32 system, unless you want to modify
    some /boot, /efi or reference material there.
    Yes, I use a separate reiserfs partition for persistence and I a want to prevent anyone to write on my KNOPPIX-Partition.

    Quote Originally Posted by utu View Post
    If you actually never want to record ANY changes, then a LiveCD or LiveDVD
    would seem a better and cheaper answer than restricting a LiveUSB to read-only.
    Knoppix from stick is very faster.

    Thanks Moritz

  4. #4
    Junior Member
    Join Date
    Aug 2013
    Posts
    4

    knoppix 7.20 mnt-system read-only

    I have my problem solved with a new cheatcode and adaption the init.

    moritz.b

  5. #5
    Member registered user
    Join Date
    Dec 2006
    Posts
    44
    Please post your solution, the boot parameter list and the adaptation to init. I would like to implement it.

  6. #6
    Senior Member registered user
    Join Date
    Sep 2006
    Posts
    802
    This is very interesting in the context of USB, and possibly also SSD-disk, use. If, for example, /mnt-system is mounted ro, and the overlay is on ramdisk, concerns about media wear-out are greatly reduced. Overlay could, for example, be read into ramdisk from /mnt-system, or another partition, on boot, and on shutdown, there could be an option for saving it. There are also safety concerns - if overlay is never saved after performing potentially dangerous operations (typically websites wanting to run scripts modifying your browser configuration), one is much better protected.

    I consider publishing modified init scripts here a part of best Knoppix practices

  7. #7
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631
    Quote Originally Posted by moritz.b View Post
    I have my problem solved with a new cheatcode and adaption the init.

    moritz.b
    I have two concerns with the initial premise here.

    Unless your Knoppix user is denied root privileges,
    making that partition which contains /mnt-system read-only on a write-able
    medium offers no real protection against unauthorized changes to the contents
    of /mnt-system.

    If the Knoppix user is denied root privileges completely,
    there are many useful things his Knoppix can't do.

    I'd like to see how changes to init might get around these considerations.

  8. #8
    Senior Member registered user
    Join Date
    Sep 2006
    Posts
    802
    Quote Originally Posted by utu View Post
    I have two concerns with the initial premise here.

    Unless your Knoppix user is denied root privileges,
    making that partition which contains /mnt-system read-only on a write-able
    medium offers no real protection against unauthorized changes to the contents
    of /mnt-system.

    If the Knoppix user is denied root privileges completely,
    there are many useful things his Knoppix can't do.

    I'd like to see how changes to init might get around these considerations.
    Even if it is possible to remount /mnt-system rw, having it mounted ro by default is clearly a safety measure. And, for example, everything could be placed in loop-mounted ISO images. So that you have to re-create it each time you want to update your persistent store. This could be equivalent to using one or more cloop/squashfs overlays.

  9. #9
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631
    Quote Originally Posted by moritz.b View Post
    I have configured my Knoppix with overlays and would like to use the system without write access to my usb-stick.
    I think of cloops as read-only by definition, only written by specific intent, not somehow 'accidentally'. I count on this myself as
    protection against my overwriting a rw persistence file. Once my rw persistence content is relatively 'mature', I button its content up
    in a cloop to protect against possibly spoiling it myself. This also compacts things and I never really see any performance penalty.

    My expectation is that Moritz might be expecting to protect against another Knoppix user purposefully changing Moritz' product,
    which I expect that user probably can do if he has Knoppix root privileges. If he doesn't, he surely misses a lot of its power.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G picture

A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G

$13.99



Samsung 16GB 2Rx4 PC4-2133P DDR4-17000 1.2V RDIMM ECC Registered Server Memory picture

Samsung 16GB 2Rx4 PC4-2133P DDR4-17000 1.2V RDIMM ECC Registered Server Memory

$16.29



HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin picture

HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin

$12.90



A-Tech 8GB PC3-12800 Desktop DDR3 1600 MHz Non ECC 240-Pin DIMM Memory RAM 1x 8G picture

A-Tech 8GB PC3-12800 Desktop DDR3 1600 MHz Non ECC 240-Pin DIMM Memory RAM 1x 8G

$13.99



8GB PC3L-12800S 1600MHz SODIMM DDR3 RAM | Grade A picture

8GB PC3L-12800S 1600MHz SODIMM DDR3 RAM | Grade A

$12.00



Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM picture

Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM

$13.25



A-Tech 16GB 2 x 8GB PC3-12800 Laptop SODIMM DDR3 1600 Memory RAM PC3L 16G DDR3L picture

A-Tech 16GB 2 x 8GB PC3-12800 Laptop SODIMM DDR3 1600 Memory RAM PC3L 16G DDR3L

$27.98



32GB (4X8GB) DDR3 PC3-12800 1600 NON ECC LOW DENSITY MEMORY F3-12800CL10Q-32GBXL picture

32GB (4X8GB) DDR3 PC3-12800 1600 NON ECC LOW DENSITY MEMORY F3-12800CL10Q-32GBXL

$32.00



A-Tech 256GB 4x 64GB 4Rx4 PC4-19200 ECC Load Reduced LRDIMM Server Memory RAM picture

A-Tech 256GB 4x 64GB 4Rx4 PC4-19200 ECC Load Reduced LRDIMM Server Memory RAM

$287.96



A-Tech 64GB 4x 16GB 2Rx4 PC4-17000R DDR4 2133MHz ECC REG RDIMM Server Memory RAM picture

A-Tech 64GB 4x 16GB 2Rx4 PC4-17000R DDR4 2133MHz ECC REG RDIMM Server Memory RAM

$87.96