803fb7
From d066c82a5a5c63c50617be27409ae0bb4bd3a356 Mon Sep 17 00:00:00 2001
803fb7
From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= <zbyszek@in.waw.pl>
803fb7
Date: Sat, 14 Mar 2015 22:35:30 -0400
803fb7
Subject: [PATCH] cryptsetup-generator: remove warning about crypttab access
803fb7
 mode
803fb7
MIME-Version: 1.0
803fb7
Content-Type: text/plain; charset=UTF-8
803fb7
Content-Transfer-Encoding: 8bit
803fb7
803fb7
This file contains no privileged data — just names of devices to decrypt
803fb7
and files containing keys. On a running system most of this can be inferred from
803fb7
the device tree anyway.
803fb7
803fb7
(cherry picked from commit 71e4e1258436e7e81d772aed52a02bb5d9c87cb8)
803fb7
---
803fb7
 src/cryptsetup/cryptsetup-generator.c | 7 -------
803fb7
 1 file changed, 7 deletions(-)
803fb7
803fb7
diff --git a/src/cryptsetup/cryptsetup-generator.c b/src/cryptsetup/cryptsetup-generator.c
803fb7
index dfbca8754..d191def5f 100644
803fb7
--- a/src/cryptsetup/cryptsetup-generator.c
803fb7
+++ b/src/cryptsetup/cryptsetup-generator.c
803fb7
@@ -377,13 +377,6 @@ static int add_crypttab_devices(void) {
803fb7
                 return 0;
803fb7
         }
803fb7
 
803fb7
-        /* If we readd support for specifying passphrases
803fb7
-         * directly in crypttab we should upgrade the warning
803fb7
-         * below, though possibly only if a passphrase is
803fb7
-         * specified directly. */
803fb7
-        if (st.st_mode & 0005)
803fb7
-                log_debug("/etc/crypttab is world-readable. This is usually not a good idea.");
803fb7
-
803fb7
         for (;;) {
803fb7
                 int r, k;
803fb7
                 char line[LINE_MAX], *l, *uuid;