Subject: Re: disklabel(8) and machdep on-disk structures issues
To: None <tech-kern@netbsd.org, tech-security@netbsd.org>
From: Thor Lancelot Simon <tls@rek.tjls.com>
List: tech-security
Date: 11/08/2003 02:04:03
On Sat, Nov 08, 2003 at 01:53:09AM -0500, der Mouse wrote:
> >> I still think we should change DIOCWDINFO to write the raw label,
> >> even if there is no raw label.  [...]
> > I agree -- I like encapsulating this code in one place, and only one
> > place; and we can then prohibit user writes of the disklabel sectors
> > all the time, no matter what,
> 
> I would find this last significantly annoying if it were to ever make
> it into any version I use; I regularly clone whole disks with (the

It's already there, and has been for years.  See the discussion of 
securelevel in the init manual page.