Updated behavior with oflag=check:
1.Probe only mounted, LVM PV, and MBR/GPT. No file-system check, no libblkid.
2.No risk detected, or probe failure: continue as before; probing never makes 
dd fail by itself.
3.Risk detected: prompt via /dev/tty. If declined, exit non-zero.
4.If /dev/tty is unavailable: print warning to stderr, treat as refusal, exit 
non-zero (fail closed). This revises my earlier warn-and-continue proposal.
Is oflag=check the right name? Is fail-closed acceptable? Any 
wording/NEWS/manual preferences? 
If you have any suggestions, please feel free to discuss them with me.

Thanks,
Jianing Weng

On 2026-09-09 16:39, ii via GNU coreutils Bug Reports writes:
>The current implementation addresses both concerns as follows:
>1.Opt‑in only: oflag=check is a new, optional flag. Without it, dd behaves 
>exactly as before. The default behavior remains unchanged.
>2.Non‑interactive safety: When /dev/tty is unavailable (e.g., in cron or 
>background jobs), dd prints the warning on stderr and proceeds automatically,
>it never hangs or fails. The function ask_to_proceed() returns true if it 
>cannot open the controlling terminal.
>
>On 2026-09-09 13:50,"Paul Eggert"<[email protected]> writes:
>Something like that might be OK as a new option, but it shouldn't be the 
>default; too many scripts routinely use dd to overwrite devices containing 
>file system>s, and there may not be anybody around to prompt (or the user may 
>not expect a prompt or know what to do with it).
>
>On 2026-09-08 19:26, ii via GNU coreutils Bug Reports wrote:
> The pre-write check is safe and does not affect the write even if probing 
> fails.
> It merely warns and prompts for confirmation
>






        
ii
[email protected]

Reply via email to