Make it absolutely clear that the operator group grants access privileges that might not be immediately obvious.
Also catching up on a bit of documentation to reflect that GELI has been passing TRIM/UNMAP requests since 2015.
Differential D23585
Include warning about unintended consequences of using the operator account, and add note about GELI passing TRIM/UNMAP requests to ZFS FAQ debdrup on Feb 8 2020, 5:57 PM. Authored by Tags None Referenced Files
Subscribers
Details Make it absolutely clear that the operator group grants access privileges that might not be immediately obvious. Also catching up on a bit of documentation to reflect that GELI has been passing TRIM/UNMAP requests since 2015. Ran igor on it, passed without incident for the few lines I added.
Diff Detail
Event TimelineComment Actions Do you think some actual examples might help? As an example perhaps the shutdown privilege, but can you think of any others? In your commit message, best to say 'group' rather than 'account'. Comment Actions To quote Mastering FreeBSD and OpenBSD Security:
Comment Actions Add some examples as suggested by cress. This should at least give an overview of how broad the unintended consequences can be. Comment Actions Looks great. If no one else does so, I'll commit this in a few days when I get a chance. Comment Actions I hope it's okay that I'm (apparently) combining two reviews into one? Or should I resubmit on each? I thought arc could handle multiple outstanding reviews, but apparently not. Comment Actions They are separate actions, so should be separate commits and therefore separate reviews, but I'm happy to split them this time. Comment Actions I don't wish to cause unnecessary noise, but it seems the accepted-status got lost in bumping things, so I'm wondering if you lost track of this review as I did? |