DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Andrey Borzenkov <arvidjaar@gmail.com>
To: dm-crypt@saout.de
Subject: [dm-crypt] crypttab "tmp" option and /tmp 1777 permissions
Date: Sun, 9 Feb 2014 09:41:56 +0400	[thread overview]
Message-ID: <20140209094156.17061eb4@opensuse.site> (raw)

Interesting thread
https://forums.opensuse.org/showthread.php/495266-After-update-root-works-but-not-regular-user which boils down to following:

user is using "tmp" option for /tmp crypto container in /etc/crypttab
(in this case it seems it was created by installer without user even
realizing it). This recreates filesystem every time, this resetting
permissions of fs root to default. It in turn breaks KDM which
needs /tmp to be writable.

I wonder what is the proper place to fix it. Reading crypttab manual,
it says

           The encrypted block device will be prepared for using it as /tmp;
           it will be formatted using mke2fs(8). This option implies plain.

And /tmp is almost universally used with 1777 permissions today (and it
is expected to be world writable in any case), so I would say -
cryptsetup should do it; the only question is whether it should do it
unconditionally?

             reply	other threads:[~2014-02-09  6:05 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-02-09  5:41 Andrey Borzenkov [this message]
2014-02-09 10:46 ` [dm-crypt] crypttab "tmp" option and /tmp 1777 permissions Heiko Rosemann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20140209094156.17061eb4@opensuse.site \
    --to=arvidjaar@gmail.com \
    --cc=dm-crypt@saout.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox