From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from tansi.org (ns.km10532-04.keymachine.de [87.118.102.195]) by mail.saout.de (Postfix) with ESMTP for ; Sun, 27 Jun 2010 01:34:59 +0200 (CEST) Received: from gatewagner.dyndns.org (84-74-164-239.dclient.hispeed.ch [84.74.164.239]) by tansi.org (Postfix) with ESMTPA id 055F22128007 for ; Sun, 27 Jun 2010 01:34:59 +0200 (CEST) Date: Sun, 27 Jun 2010 01:34:58 +0200 From: Arno Wagner Message-ID: <20100626233458.GC2304@tansi.org> References: <1277553580.29791.40.camel@fermat.scientia.net> <20100626125223.GA26185@tansi.org> <1277562112.3245.40.camel@fermat.scientia.net> <20100626183632.GA30731@tansi.org> <4C2653EB.2090606@redhat.com> <1277593981.3239.80.camel@fermat.scientia.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1277593981.3239.80.camel@fermat.scientia.net> Subject: Re: [dm-crypt] FYI: how to (really) cleanly shutdown the system when root is on multiple stacked block devices List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On Sun, Jun 27, 2010 at 01:13:01AM +0200, Christoph Anton Mitterer wrote: > On Sat, 2010-06-26 at 21:24 +0200, Milan Broz wrote: > > fsycn currently in kerenl issues barrier in block layer and then waits for it. > > > > But if because ever reads can cause some metadata updates (last access on file stamp), > > remounting read-only is there. > Just hope that init-systems like sysvinit are really guaranteed to wait > for each of their scripts (and therefore for the blocked umount). > Otherwise they could kill it,.. and while the umount would be still > there and blocked,... it could go on to the next (halt/reboot). > > :/ Hmm. You know, encrypted root is a problem and pretty difficult to do in the rfirt place. Why not just encrypt the critical parts, like /var /home /root? The rest only holds binaries and config files anyways, which are not that sensitive... However, from my experience you cannot actually kill -9 umount/remoute-ro (had a problem with some drive...), but either have to wait it out or do a physical reset or power cycle. Arno -- Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- Cuddly UI's are the manifestation of wishful thinking. -- Dylan Evans If it's in the news, don't worry about it. The very definition of "news" is "something that hardly ever happens." -- Bruce Schneier