Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1016707

Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase

From Guilhem Moulin <guilhem@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase
Date 2020-07-06 01:10 +0200
Message-ID <AplVM-4LC-7@gated-at.bofh.it> (permalink)
References (6 earlier) <Ap9UC-5KM-3@gated-at.bofh.it> <ApdYe-86M-13@gated-at.bofh.it> <AplM5-4t1-1@gated-at.bofh.it> <AorAd-2Lr-1@gated-at.bofh.it> <AplM5-4t1-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, 06 Jul 2020 at 00:54:42 +0200, Vincent Lefevre wrote:
> On 2020-07-05 16:34:05 +0200, Guilhem Moulin wrote:
>> The raison d'être of wait_for_dropbear() is to avoid handing the
>> execution over to init(1) with a running ipconfig process or unclean
>> network stack.  This is what the race condition described in #943459 is
>> about.  wait_for_dropbear() somewhat of a hack, but ipconfig doesn't
>> seem to react to SIGTERM and I couldn't do better at the time.
> 
> How about SIGKILL, then?

No.
 
>> Consider a slow DHCP setup where ipconfig gets a lease after 45s or so.
> 
> With a temporary DHCP server failure, it can be more than the current
> timeout of 60 seconds.

Of course.  Like most thresholds this is at attempt at finding a
reasonable default, not something that covers all cases…
 
>> While it's running you unlock drives so the boot process can proceed.
>> If the execution is handed over to init(1) right away, without waiting
>> for ipconfig to settle or give up (nor for dropbear to start), then
>> ipconfig and dropbear will race with the network stack resp. SSHd of the
>> main system.  This might yield a static IP being overwritten by DHCP,
>> like in #943459, and/or OpenSSH failing to start because dropbear
>> listens on 22/tcp already.
> 
> The user has more knowledge than initramfs. For instance, he knows
> whether the link is present. And he generally knows the typical
> time he has to wait for the DHCP server (unless a major problem
> occurs with the server, in which case he may have to wait any time).
> So it's better to leave the control to the user.

I could certainly make the timeout configurable, but that's be an option
hardcoded in the initramfs (or the kernel command line) so probably not
ideal to manually flip occasionally when the users knows there is no
link present.

-- 
Guilhem.

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-03 13:00 +0200
  Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-03 16:20 +0200
    Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-04 00:30 +0200
      Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-04 00:40 +0200
        Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-04 01:00 +0200
          Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-04 01:10 +0200
            Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-05 12:20 +0200
              Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-05 16:40 +0200
                Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-06 01:00 +0200
                Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-06 01:10 +0200
                Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-06 02:00 +0200
                Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Guilhem Moulin <guilhem@debian.org> - 2020-07-06 02:40 +0200
                Bug#964187: cryptsetup: takes one minute to unlock the disk with a passphrase Vincent Lefevre <vincent@vinc17.net> - 2020-07-06 19:20 +0200

csiph-web