4 ms·
Why is there a dedicated 10GB partition for /usr/X11R6?
by qplex 9y ago
Why is there a dedicated 10GB partition for /usr/X11R6?
- jeromenerf 9y agoHere are some hints from the FAQ : https://www.openbsd.org/faq/faq4.html#Partitioning https://www.openbsd.org/faq/faq4.html#Partitioning Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are: Security: Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed. Stability: A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted. Integrity: If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK. fsck(8): You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption. Edit: verbatim format
- floatboth 9y agoThat's fine with soft partitions like ZFS datasets, HAMMER pseudofilesystems or btrfs subvolumes. But OpenBSD doesn't have anything like that. The pain of "my /usr is not big enough and it's a hard disklabel partition with a completely separate filesystem omg how do I resize it" makes the partitioning sooooo not worth it.
- Gracana 9y agoThis is not really an issue in practice, it just requires you to consider what you'll use the system for.
- majewsky 9y agoThat's assuming that the answer to this question is constant. I'm frequently running into the problem of / being too small on my notebook (I only have /, /home and /boot partitions) since I didn't anticipate my 2017 needs when installing the system in 2012. I really need to set aside some time to reinstall it...
- the_af 9y agoThis always makes me very anxious with Linux. I don't know beforehand what I'll use my laptop for, it's not a server! Some development, some gaming, some general use. Who knows? I always end up creating 3 partitions: /boot (is this really necessary?), a single huge /, and swap. I know a separate /home is recommended (something about backups and seamless distro upgrades, which I never do anyway), but I never know how to size it relative to /. I admit I do cargo-cult partitioning. I don't really know whether the recommendations out there are current, outdated, mistaken or what. I find a lot of recommendations about partitioning, swap, memory etc, at least for Linux, are cargo cult anyway, or at least outdated and/or poorly explained, which amounts to the same.
- saghm 9y agoOne potential solution for this is to use LVM, which lets you resize the partitions later. Even if you do just want to use /, /boot, and swap, it can be useful if you later want to change your swap size or reduce the root partition size to add new partitions if you decide you want to dual boot.
- floatboth 9y agoEasy example: create a 10gb EC2 instance with OpenBSD, start installing stuff, boom, you're out of space on some partition. But really, just having rigid partitions makes me feel uneasy. ZFS datasets all share the same space, and you can set quotas if you want that can be changed anytime.
- Gracana 9y agoThat is an example of not considering your use case and failing, yes. :P Flexible/resizable partitions are definitely easier, but I think you could have gotten the fixed scheme right if you had tried.
- floatboth 9y agoWhen could I try? The scheme was already there: > create a 10gb EC2 instance
- dredmorbius 9y agoNB: Codeblock formatting on HN wraps exceptionally poorly (which is to say, not at all), on most devices. Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are: Security: Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed. Stability: A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted. Integrity: If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK. fsck(8): You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption.
- protomyth 9y agoThe recent changes to /usr and /usr/local are a good example: https://www.openbsd.org/faq/upgrade60.html https://www.openbsd.org/faq/upgrade60.html The wxallowed mount option. W^X is now strictly enforced by default; a program can only violate it if it is located on a filesystem mounted with the wxallowed mount(8) option. This allows the base system to be more secure as long as /usr/local is a separate filesystem. The base system has no W^X-violating programs, but the ports tree contains quite a few: chromium, mono, node, gnome, libreoffice, jdk, zeal, etc. If you want to run any of these ports on a regular basis, you need to add wxallowed to the mount options for /usr/local in fstab(5), e.g.: 01020304050607.h /usr/local ffs rw,nodev,wxallowed 1 2 Small disks may not have a separate partition for /usr/local. In that case, add wxallowed to the smallest partition containing it: /usr or /. Starting a W^X-violating program from a partition without the wxallowed mount option will produce a core dump and the dmesg(8) will contain an entry such as soffice.bin(15529): mprotect W^X violation. You can temporarily allow W^X-violating ports by issuing mount -uo wxallowed /usr/local.
- dredmorbius 9y agoFor those to whom "wxallowed" and W^X aren't immediately clear: https://en.m.wikipedia.org/wiki/W%5EX https://en.m.wikipedia.org/wiki/W%5EX W^X ("Write XOR Execute"; spoken as W xor X) is a security feature in operating systems and virtual machines. It is a memory protection policy whereby every page in a process's or kernel's address space may be either writable or executable, but not both. Without such protection, a program can write (as data) CPU instructions in an area of memory intended for data and then arrange to run (as executable) those instructions. This can be dangerous if the writer of the memory is malicious.
- mulander 9y agoThe auto layout depends on the target drive size, your needs may vary but I set /usr/X11R6 to 1 GB and rarely see more used than 250 MB. Generally I use the auto layout as a strong hint on how many partitions to make and the general size suggestions - then alter based on my needs (ie. bumping var instead of home for servers).