Path: csiph.com!weretis.net!feeder7.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod From: Vincent Lefevre Newsgroups: linux.debian.bugs.dist Subject: Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Date: Mon, 06 Jul 2020 19:20:02 +0200 Message-ID: References: X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Mon Jul 6 17:15:09 2020 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -0.45 Reply-To: Vincent Lefevre , 964187@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Guilhem Moulin X-Debian-Pr-Message: followup 964187 X-Debian-Pr-Package: dropbear-initramfs X-Debian-Pr-Source: dropbear X-Spam-Bayes: score:0.0000 Tokens: new, 10; hammy, 150; neutral, 87; spammy, 0. spammytokens: hammytokens:0.000-+--H*F:D*vinc17.net, 0.000-+--H*rp:D*vinc17.net, 0.000-+--HX-Mailer-Info:mutt, 0.000-+--HX-Mailer-Info:www.vinc17.net, 0.000-+--H*M:vinc17 MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit X-Mailer-Info: https://www.vinc17.net/mutt/ User-Agent: Mutt/1.14.5+76 (bb407ec3) vl-127292 (2020-06-24) X-Debian-Message: from BTS X-Mailing-List: archive/latest/1612253 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 39 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Mon, 6 Jul 2020 19:11:17 +0200 X-Original-Message-ID: <20200706171117.GG25541@zira.vinc17.org> X-Original-References: <20200703221859.GA21501@zira.vinc17.org> <20200703223004.GA1205958@debian.org> <20200703225453.GA25541@zira.vinc17.org> <20200703230715.GA1240953@debian.org> <20200705100841.GB25541@zira.vinc17.org> <20200705143405.GA7361@debian.org> <20200705225442.GD25541@zira.vinc17.org> <20200705230658.GA472000@debian.org> <20200705234845.GE25541@zira.vinc17.org> <20200706003456.GA473337@debian.org> <20200703105317.GA34296@zira.vinc17.org> <20200706003456.GA473337@debian.org> Xref: csiph.com linux.debian.bugs.dist:1016791 On 2020-07-06 02:34:56 +0200, Guilhem Moulin wrote: > On Mon, 06 Jul 2020 at 01:48:45 +0200, Vincent Lefevre wrote: > > If you let the user run a script that controls the timeout, that > > would be better. For instance, a typical setting when dropbear is > > used to unlock the disk(s) would be to set the timeout so that the > > following conditions are *both* satisfied: > > > > 1. Some lower bound has been reached (say 10 seconds). > > > > 2. The passphrase has been validated. > > > > This makes sense because in this case, it is useless to abort > > wait_for_dropbear() while the passphrase has not been validated > > yet. > > wait_for_dropbear() runs at init-bottom stage, so after dm-crypt devices > have been mapped (if cryptsetup-initramfs is installed and the crypttab > is not empty, that is). So you're essentially asking to set the timeout > to 10s. OK, so that's even simpler. A configurable timeout would be sufficient. > > BTW, I've just noticed that the timeout introduces a second annoying > > regression: If there is a temporary issue with the DHCP server just > > after the machine has been restarted, so that the timeout is reached, > > the user will not be able to unlock the disk until he can go back in > > front of his machine! > > You mean the timeout from configure_networking() it init-premout stage? [...] Please forget that. I meant wait_for_dropbear(), but since it runs after dm-crypt devices have been mapped, there is no issue. -- Vincent Lefèvre - Web: 100% accessible validated (X)HTML - Blog: Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)