All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dale Amon <amon@vnl.com>
To: Joshua Brindle <jbrindle@tresys.com>
Cc: Dale Amon <amon@vnl.com>, Russell Coker <russell@coker.com.au>,
	"Christopher J. PeBenito" <cpebenito@tresys.com>,
	SELinux Mail List <selinux@tycho.nsa.gov>
Subject: Re: Remove unrestricted_admin
Date: Sun, 26 Sep 2004 10:21:51 +0100	[thread overview]
Message-ID: <20040926092151.GA8079@vnl.com> (raw)
In-Reply-To: <415609AD.5000808@tresys.com>

[-- Attachment #1: Type: text/plain, Size: 1572 bytes --]

On Sat, Sep 25, 2004 at 08:13:33PM -0400, Joshua Brindle wrote:
> I _really_ hope you aren't suggesting that you do a dd from a host disk 
> to something else while a machine is in production. This _will_ lead to 
> an inconsistant image and I don't think I need to explain why.

No, I umount the partition first. For system disks
I do the backup as described, with a root-nfs floppy
boot.

Last year I recovered data off a badly bolloxed Thinkpad
disk after someone knocked my laptop off a sofa while
I was travelling for several months. Lots of work had
to be recovered. I used the ability to seek to pull
all the undamaged blocks off and step around the 
blocks which locked up the IDE controller; then I
used a program to reassemble the saved blocks in
order with zero blocks where the destroyed areas
were... and then I loopback mounted the result and
recovered about 99.999%. Actually I recoverd 100%
of what matters.

Since I did this with an NFS boot, it doesn't 
matter to selinux (hell, last spring I was building
selinux into a ghost loopback and then dd'ing it to
the very slow test machines; only the
issue of umount/dd backup/mount of partitions matters
in general usage.

-- 
------------------------------------------------------
   Dale Amon     amon@islandone.org    +44-7802-188325
       International linux systems consultancy
     Hardware & software system design, security
    and networking, systems programming and Admin
	      "Have Laptop, Will Travel"
------------------------------------------------------

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2004-09-26  9:22 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-09-21  5:26 file.te and tmpfs Russell Coker
2004-09-22 20:22 ` James Carter
2004-09-23 13:32   ` Remove unrestricted_admin Daniel J Walsh
2004-09-23 19:09     ` James Carter
2004-09-24 15:05     ` Russell Coker
2004-09-24 17:50       ` Christopher J. PeBenito
2004-09-24 18:27         ` Russell Coker
2004-09-24 18:59           ` Christopher J. PeBenito
2004-09-24 19:13             ` Russell Coker
2004-09-24 22:22               ` Luke Kenneth Casson Leighton
2004-09-25 10:39                 ` Russell Coker
2004-09-25 11:01                   ` Luke Kenneth Casson Leighton
2004-09-25 13:30                   ` Christopher J. PeBenito
2004-09-25 15:21                     ` Russell Coker
2004-09-25 17:09                       ` Chris PeBenito
2004-09-25 17:45                         ` Russell Coker
2004-09-25 22:07                       ` Dale Amon
2004-09-26  0:13                         ` Joshua Brindle
2004-09-26  9:21                           ` Dale Amon [this message]
2004-09-26  9:53                           ` Russell Coker
2004-09-26 10:35                         ` Luke Kenneth Casson Leighton
2004-09-25 23:06             ` Joe Nall
2004-09-26 13:16               ` Russell Coker
2004-09-24 18:49       ` Joshua Brindle

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040926092151.GA8079@vnl.com \
    --to=amon@vnl.com \
    --cc=cpebenito@tresys.com \
    --cc=jbrindle@tresys.com \
    --cc=russell@coker.com.au \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.