3 ms·
> fallocate / chmod / mkswap Why not "mkswap --size ... --file ...", which does these three things and more? For instance, according to the mkswap man page, "[
by cesarb 22d ago
> fallocate / chmod / mkswap
Why not "mkswap --size ... --file ...", which does these three things and more? For instance, according to the mkswap man page, "[...] sets the nocow attribute for newly created files [...]" which is a detail that seems to be missing from this gist.
- jwilk 22d agoAlso, fallocate+chmod is racy: between the two calls, an attacker could open the file, and then keep it open until next reboot. OTOH, mkswap creates the swap file with the correct permissions straight away. The --size and --file options are relatively new, though: they were added in util-linux v2.40, released in 2024.
- zahlman 22d ago> between the two calls, an attacker could open the file, and then keep it open until next reboot. I feel like if there's a malicious user (or program) on your system with the necessary access for this, you have much bigger problems.
- jenders 22d agoI wrote this years ago before LLMs made it easy to validate guesswork. I’ll update! Good call
- bigstrat2003 22d agoLLMs are guesswork. You have to validate them, not the other way around.
- jenders 22d agoLooks like this was added in util-linux 2.40. Works with btrfs correctly too! Added.