Re[2]: gpart destroy, zpool destroy, zfs destroy under securelevel 3

2014-05-29 Thread Vladimir Sharun
Hello, > Ok, you are right. But geom_dev restricts access only from user level > applications. When GEOM object does access directly via GEOM methods > this protection won't work. And it seems it isn't easy to fix, all > classes should have own check. Thank you for better clarification. This is t

Re: gpart destroy, zpool destroy, zfs destroy under securelevel 3

2014-05-29 Thread Andrey V. Elsukov
On 29.05.2014 12:56, Vladimir Sharun wrote: > Hello, > >> if you have root privileges you can just write some random bytes in some >> places and this will be enough to break your system. So, restricting >> some gpart's or zpool's actions depending from securelevel looks like >> protection from kid

Re[2]: gpart destroy, zpool destroy, zfs destroy under securelevel 3

2014-05-29 Thread Vladimir Sharun
Hello, > if you have root privileges you can just write some random bytes in some > places and this will be enough to break your system. So, restricting > some gpart's or zpool's actions depending from securelevel looks like > protection from kids. Having root under securelevel 3 confirmed disall

Re: gpart destroy, zpool destroy, zfs destroy under securelevel 3

2014-05-29 Thread Andrey V. Elsukov
On 26.05.2014 17:31, Vladimir Sharun wrote: > Hello FreeBSD community, > > Recently plays with securelevel and what I discover: no chance for > data to survive against remote root, except backups of course. Maybe > this log can be a proposal for raising securelevel further or include > securelevel

gpart destroy, zpool destroy, zfs destroy under securelevel 3

2014-05-26 Thread Vladimir Sharun
Hello FreeBSD community, Recently plays with securelevel and what I discover: no chance for data to survive against remote root, except backups of course. Maybe this log can be a proposal for raising securelevel further or include securelevel support against the software which can deal with zfs