Gentoo Archives: gentoo-dev

From: "M. J. Everitt" <m.j.everitt@×××.org>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] newsitem: openrc-0.28 mounts efivars read only
Date: Thu, 13 Jul 2017 11:36:01
Message-Id: 32458e65-d66d-fcdc-5b0a-97d3c480d14a@iee.org
In Reply to: Re: [gentoo-dev] newsitem: openrc-0.28 mounts efivars read only by Rich Freeman
1 On 13/07/17 12:09, Rich Freeman wrote:
2 > Presumably you'd only want to remount it if it was mounted ro to
3 > start, since it sounds like openrc will be diverging from systemd
4 > behavior here.
5 >
6 > While it seems like a good idea I'm not sure how big an improvement it
7 > is in the larger scheme. We're worried about root accidentially
8 > modifying efivars, but we have no safeguards against root writing to
9 > /dev/sda, and the latter seems much more likely to cause harm, and is
10 > harder to fix.
11 >
12 In case you weren't aware, Rich, rewriting the efivars actually writes
13 to the system BIOS, which renders the computer completely unbootable ..
14 not quite the same as erasing the boot sector of your hard disk, where
15 you simply plug in another device, and Off you go ...

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies