Auditing and Fixing fstab
Goal
Audit a broken fstab against the rules, fix it, and write a verification script yourself.
Why it matters
fstab is one of the most dangerous files on a system. If you write it wrong, the boot hangs midway, and on a cloud instance with no console there is nothing you can do. In particular, the sixth field, pass (the fsck order), is often wrong — giving 1 to something that is not the root, or giving a value other than 0 to a network filesystem, makes the boot hang. And without nofail, if one data disk dies the whole server does not come up. In practice you always verify before rebooting — rebooting to find out is not verification, it is gambling.
Rules used in this lab
- Rule A: Every entry line must have exactly 6 fields
- Rule B: The
passvalue is1only for the root (/),2for other local filesystems, and0for network/virtual filesystems (nfs,nfs4,tmpfs) - Rule C: The same mount point must not appear twice
- Rule D:
dumpandpassmust be numbers
Steps
- Create the
/root/fstabdirectory and copy/opt/fixtures/st-fstab/fstab.brokento/root/fstab/work.tab. - Convert each entry, excluding comments and blank lines, into a
장치,마운트지점,타입,옵션,dump,passCSV (device, mount point, type, options, dump, pass, in that order) and save it as/root/fstab/fields.csv. For a line with missing fields, write only the ones that are there. - Write the line numbers that violate the four rules above, in ascending order, one per line, in
/root/fstab/audit.txt. Count line numbers from 1 at the top of the file, including comments. - Create
/root/fstab/fixed.tabwith all violations fixed. Keep the original's valid entries as they are, fill in0 2for lines with missing fields, move the later one of duplicated mount points to/var2, and fix wrong pass values to match Rule B. - In
fixed.tab, change the entry written with a device path (/dev/...) to theUUID=1a2b3c4d-0004-4000-8000-000000000004notation. - In
fixed.tab, addnofailto the options of every local entry that is not the root, and add all ofnoexec,nosuid, andnodevto the options of the/tmpentry. - Make sure the options of the NFS entry in
fixed.tabinclude all of_netdev,soft,timeo=600, andretrans=2. - Write
/root/fstab/validate.sh. It must take the fstab file path as its first argument and check Rules A–D, and exit with code 0 if there are no violations and with a nonzero value if there is even one. The grader runs it on bothfixed.tab(must pass) andfstab.broken(must fail).
Notes
- Filter out comments and blank lines with
awk 'NF && $1 !~ /^#/ {print}'. - If you need line numbers, use
grep -norawk '{print NR": "$0}'. - Write the script in step 8 in bash; it does not need execute permission (the grader runs it as
bash validate.sh <파일>, where the placeholder is the file path). - Common mistake 1: counting duplicate devices as a problem in step 3. The rule is about duplicate mount points.
- Common mistake 2: the script in step 8 not taking an argument and reading a fixed path. Be sure to use the first argument.
Make a working copy
Create the /root/fstab directory and copy /opt/fixtures/st-fstab/fstab.broken to /root/fstab/work.tab.
Do not touch the original fixture; work on the copy. The line count must be the same as the original.
Break the fields into CSV
Convert each entry, excluding comments and blank lines, into a 장치,마운트지점,타입,옵션,dump,pass CSV (device, mount point, type, options, dump, pass, in that order) and save it as /root/fstab/fields.csv. For a line with missing fields, write only the ones that are there.
Exclude comments and blank lines. Join the six fields with commas using awk.
Find the lines that violate the rules
Write the line numbers that violate the four rules above, in ascending order, one per line, in /root/fstab/audit.txt. Count line numbers from 1 at the top of the file, including comments.
Apply the four rules one at a time. Line numbers are counted from the top of the file, including comments.
Submit the corrected version
Create /root/fstab/fixed.tab with all violations fixed. Keep the original's valid entries as they are, fill in 0 2 for lines with missing fields, move the later one of duplicated mount points to /var2, and fix wrong pass values to match Rule B.
Fill in lines with missing fields, move one of the duplicate mount points to a different path, and fix wrong pass values to match the rules.
Device name to UUID notation
In fixed.tab, change the entry written with a device path (/dev/...) to the UUID=1a2b3c4d-0004-4000-8000-000000000004 notation.
There is one entry written with a device path. Change it to UUID= notation; you may choose the value arbitrarily.
Add safety options
In fixed.tab, add nofail to the options of every local entry that is not the root, and add all of noexec, nosuid, and nodev to the options of the /tmp entry.
Local entries other than the root need the option that keeps the boot going even on failure, and /tmp needs the three security options.
Write the NFS entry
Make sure the options of the NFS entry in fixed.tab include all of _netdev, soft, timeo=600, and retrans=2.
A network filesystem needs the option that waits for the network to be ready, and its pass must be the value that means no check.
Write the verification script
Write /root/fstab/validate.sh. It must take the fstab file path as its first argument and check Rules A–D, and exit with code 0 if there are no violations and with a nonzero value if there is even one. The grader runs it on both fixed.tab (must pass) and fstab.broken (must fail).
The grader runs it on both a good file and a bad file. It must exit with 0 if the file is good and with a nonzero value if there is a problem.