Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

2017-11-27

ATA Security Erase

It is best to run these commands under tmux or screen to make sure that the erase is not interrupted.

FreeBSD

Check security status

camcontrol security adaX

If the drive security is frozen reconnect the power cable or suspend to ram:

zzz

Execute enhanced SECURITY ERASE UNIT

camcontrol security adaX -U user -s Eins
date; time camcontrol security adaX -U user -h Eins

OR issue the SCSI SANITIZE command CRYPTO SCRAMBLE EXT for instant secure erase (should be faster for rotating disks as only the crypto key is changed rendering the data unreadable) The -r option is used to report status.

date; time camcontrol sanitize adaX -U -a crypto
camcontrol sanitize adaX -U -r

Linux

Check security status

hdparm -I /dev/sdX

If the drive security is frozen reconnect the power cable or suspend to ram:

echo -n mem > /sys/power/state

Execute enhanced SECURITY ERASE UNIT

hdparm --security-set-pass Eins /dev/sdX
date; time hdparm --security-erase-enhanced Eins /dev/sdX

2011-10-11

*nix tips

Find all unique ip addresses from webserver logs:
# awk '{print $1}' access.log | sort | uniq
# zcat access.log.gz | awk '{print $1}' | sort | uniq

Copy files using tar (this preserves metadata. add 'p' option to also preserve ownership data):
# cd source-dir
# tar cSf - . | tar xSf - -C target-dir

Count total size in bytes of files in current directory tree (different from disk usage):
# find . -type f -ls | awk '{total += $7} END {print total}'

2011-09-26

ZFS with 4k sectors on Debian GNU/kFreeBSD

Debian GNU/kFreeBSD is an operating system for IA-32 and x86-64 computer architectures. It is a distribution of GNU with Debian package management APT and the kernel of FreeBSD. The 'k' in kFreeBSD is an abbreviation for kernel of, and reflects the fact that only the kernel of the complete FreeBSD operating system is used.

Current stable distribution (Squeeze) provides zpool version 14.
Current testing distribution (Wheezy) provides zpool version 15.
FreeBSD 9.0-BETA2 provides zpool version 28.

For some reason the current kFreeBSD ZFS implementation creates zpools with property whole_disk=0 even when creating a zpool with whole device vdev. To remedy this, one can use FreeBSD 9.0-BETA2 to create a zpool with whole_disk=1 and with an older zpool version. Then export it and import to Debian.
# zpool create -o version=14 <pool> <vdev>

When creating raidz zpools to be used with 4k advanced format hard drives,  it is best to use raidz1 with 3, 5 or 9 disks, raidz2 with 6 or 10 disks, and raidz3 with 11 or 19 disks.

ZFS aligns zpools with hard disk logical sector size. All current hard drives (including the 4k advanced format ones) report 512 bytes as the logical sector size (ashift=9, 2⁹ = 512). To make ZFS align zpools with 4k sectors the ashift value has to be ashift=12, 2¹² = 4096.

I have created this way a 12 TB NAS using six Western Digital 3 TB disks in raidz2.

Install zfsutils which provides zpool, zfs and zdb commands, and freebsd-geom which provides gnop (through geom nop).
# aptitude install zfsutils
# aptitude install freebsd-geom

Find out the device names in your system.
# atacontrol list

or if using FreeBSD-9 kernel:
# camcontrol devlist

Create a NOP device for simulating 4k sector.
# geom nop create -v -S 4096 ad6

Create a zfs pool and export it.
# zpool create datapool ad6.nop
# zpool export datapool

Destroy the NOP device since it's only needed to set ashift=12 when creating the pool.
# geom nop destroy -v ad6.nop

Import back the pool.
# zpool import datapool

Confirm that the ashift value is 12.
# zdb datapool | grep ashift


(For testing the zpool creation with files one can use):
# dd if=/dev/zero of=<file> bs=1G seek=4096 count=0
# zpool create <pool> `mdconfig -f <file> -S 4096`


The zdb command seems to have a bug even still in Solaris 11 Express, when using it with an older zpool version. Update: this is fixed in Solaris 11 EA.
# zpool create -o version=14 <pool> <vdev>
# zdb <pool>
Assertion failed: mp->initialized == B_TRUE, file ../common/kernel.c, line 127,
function mutex_enter


How to mount an ext2 filesystem with FreeBSD?
# kldload -v ext2fs
# mount -t ext2fs <device> <mountpoint>

2011-09-20

Solaris

Solaris OS x86-64 and its derivatives seem to mainly use 32-bit applications although the kernel is 64-bit.

Unlike on x86_64, 64-bit SPARC code requires more memory for no performance gain over 32-bit, so it is best only used when the 32-bit address space is insufficient. SPARC userspace is therefore 32-bit by default, even when the hardware and kernel are 64-bit.

"By default, perl-5.6.0 (or later) is compiled as a 32-bit application with largefile and long-long support.", and the Sun docs say this: "The Solaris version of Perl was compiled to include system malloc, 64-bit integer and large file support. In addition, appropriate patches have been applied."

You should have what they promised. A 32-bit application that can do 64-bit integer arithmetic and will not have problems with files over 2 GB in size. But it internally uses 32 bit pointers and so should be linked to the 32-bit library.

Solaris 11 Express 2010.11 64-bit
Perl 5.8.4 ELF 32-bit LSB executable 80386, built for i86pc-solaris-64int
PHP 5.2.12 32-bit

NexentaCore 3.1 (Hardy 8.04/b134+) SunOS Release 5.11 Version NexentaOS_134f 64-bit
Perl 5.8.8 ELF 32-bit LSB executable, Intel 80386, built for i386pc-solaris2.11-thread-multi
PHP 5.2.4-build1 with Susoshin-Patch 0.9.6.2 (cli) ELF 32-bit LSB executable, Intel 80386

GNU/kFreeBSD debian 8.2.1-amd64
Perl 5.12.4 ELF 64-bit LSB executable, x86-64, built for x86_64-kfreebsd-gnu-thread-multi
PHP 5.3.8-1 with Susoshin-Patch (cli) ELF 64-bit LSB executable, x86-64


$large_number = 9223372036854775807;var_dump($large_number);                     // int(9223372036854775807)

This above php-script outputs int if php is compiled for 64-bit. If php is 32-bit it outputs float.
The only OS which passed this 64-bit test was Debian/kFreeBSD-amd64.


Some useful Solaris commands:

Find out the kernel architecture in use:
# isainfo -k

Find out a service state:
# svcs -a | grep <service name>

Enable / disable / restart / refresh a service:
# svcadm -v enable/disable/restart/refresh <service name>

Find out disk sizes:
# iostat -E

Find out device names:
# format

Install Apache, MySQL and PHP (default document root is at /var/apache2/2.2/htdocs/):
# pkg install amp
# svcadm enable mysql
# svcadm enable http

Create a large (20 TiB) sparse file and create a loop device to use with ZFS testing:
# dd if=/dev/zero of=<file> bs=1G seek=20480 count=0
# zpool create <pool> `lofiadm -a <file>`

2011-01-14

How to securely erase MBA SSD

1. boot linux from usb key using grub-efi
2. run 'hdparm -I /dev/sda'
3. see that the disk security is frozen
4. put mba to sleep
5. resume from sleep
6. run 'hdparm -I /dev/sda' again
7. see that the disk security is not frozen
8. follow instructions from tinyapps.org/docs/wipe_drives_hdparm.html