mirror of
https://gitlab.com/cryptsetup/cryptsetup.git
synced 2025-12-08 09:20:11 +01:00
Compare commits
697 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
602d7f0bb0 | ||
|
|
53c4fbac2d | ||
|
|
acc846ceba | ||
|
|
89bce3d21b | ||
|
|
1de98c12a6 | ||
|
|
4d62ef49de | ||
|
|
de14f78e25 | ||
|
|
a2d33996f4 | ||
|
|
d59d935308 | ||
|
|
7c62c82c8f | ||
|
|
664f48e29d | ||
|
|
96896efed4 | ||
|
|
bdf16abc53 | ||
|
|
8030bd0593 | ||
|
|
a89e6e6e89 | ||
|
|
a5ed08f2d4 | ||
|
|
f92786a044 | ||
|
|
b282cb2366 | ||
|
|
883bde3f1b | ||
|
|
e969eba2bb | ||
|
|
3c3756fbd7 | ||
|
|
b8359b3652 | ||
|
|
75eaac3fef | ||
|
|
d70e2ba18d | ||
|
|
3a27ce636a | ||
|
|
0a951da27f | ||
|
|
be6ab40fb9 | ||
|
|
29ecd515ac | ||
|
|
0c7ce6215b | ||
|
|
ddd587d78d | ||
|
|
e6ef5bb698 | ||
|
|
b4cf5e2dab | ||
|
|
a1683189da | ||
|
|
a0fc06280e | ||
|
|
830edb22cf | ||
|
|
26bf547bbc | ||
|
|
cec31efee2 | ||
|
|
4ad075e928 | ||
|
|
10a6318b1f | ||
|
|
18528edc31 | ||
|
|
2b91d7c385 | ||
|
|
8d7235b9a9 | ||
|
|
02295bed47 | ||
|
|
0657956351 | ||
|
|
9f50fd2980 | ||
|
|
e32376acf1 | ||
|
|
8ab9c9dc68 | ||
|
|
a5363f184c | ||
|
|
e2637c5d49 | ||
|
|
4a72695241 | ||
|
|
af31af5e3d | ||
|
|
2aa0bb7eac | ||
|
|
8ae62715a8 | ||
|
|
506ba27358 | ||
|
|
4384e50578 | ||
|
|
1623ee71ab | ||
|
|
f425d07ec7 | ||
|
|
d260be02d4 | ||
|
|
4609fd87d7 | ||
|
|
9e90d91446 | ||
|
|
7bbf0796b5 | ||
|
|
fe3148f074 | ||
|
|
5e9c27118e | ||
|
|
c362ba9293 | ||
|
|
e97048dd32 | ||
|
|
5ea0ba61be | ||
|
|
7ae863e380 | ||
|
|
f238e8c075 | ||
|
|
7d9a14fd24 | ||
|
|
2f964d95d8 | ||
|
|
00f419e5ea | ||
|
|
cc698dcde3 | ||
|
|
edced6cfed | ||
|
|
4fb11976d2 | ||
|
|
68ba5b2b36 | ||
|
|
65fa22ff23 | ||
|
|
c25d81d2a1 | ||
|
|
57d16a7a55 | ||
|
|
def397d0c8 | ||
|
|
7843415243 | ||
|
|
5a8b045bdd | ||
|
|
ab62f45d57 | ||
|
|
e521edd6ca | ||
|
|
3a0293a299 | ||
|
|
8a4db1ad7b | ||
|
|
1aba9ab444 | ||
|
|
dfa2755aba | ||
|
|
6e82bdd9a5 | ||
|
|
0dc245401f | ||
|
|
a57f1b1b64 | ||
|
|
1a50fee1d0 | ||
|
|
046e0e5280 | ||
|
|
656b55cd4b | ||
|
|
8d7af433d8 | ||
|
|
dc3de39eb7 | ||
|
|
3d403a7bd0 | ||
|
|
91f6296699 | ||
|
|
bd94eb36b3 | ||
|
|
1a19329b18 | ||
|
|
78a43c053a | ||
|
|
d7d76e72f7 | ||
|
|
dd0dcc05df | ||
|
|
3be8731fef | ||
|
|
86d0ff1a2b | ||
|
|
3adfe80601 | ||
|
|
0bc437d92c | ||
|
|
6b10f30eb9 | ||
|
|
fedd5bc969 | ||
|
|
8aee4f95fb | ||
|
|
1f2d8de95f | ||
|
|
dced269426 | ||
|
|
b834a59eaf | ||
|
|
4f7b413638 | ||
|
|
e4355c2973 | ||
|
|
31a4d552a2 | ||
|
|
6d51e8ab69 | ||
|
|
8157e47ad4 | ||
|
|
62b0138dad | ||
|
|
c13a8003fa | ||
|
|
979aec773e | ||
|
|
b789b011a2 | ||
|
|
ea8864badf | ||
|
|
49335b600f | ||
|
|
7245af59d3 | ||
|
|
f7b61b2617 | ||
|
|
dc40b91cdf | ||
|
|
eccf347568 | ||
|
|
e24a72f84c | ||
|
|
2c70c057d6 | ||
|
|
f16f37233f | ||
|
|
3cffadb508 | ||
|
|
ce30d5f1fd | ||
|
|
6e0f0408a0 | ||
|
|
3d6bcae84c | ||
|
|
b8beedb621 | ||
|
|
fd5c2a5000 | ||
|
|
69bc154fca | ||
|
|
387041ccf2 | ||
|
|
64d6b339a0 | ||
|
|
4f5f1b78c4 | ||
|
|
3e886ecf57 | ||
|
|
210ea612b3 | ||
|
|
3350ff017f | ||
|
|
7b42254975 | ||
|
|
e84b1ed7c0 | ||
|
|
f3f1bfd73a | ||
|
|
89f795d7b4 | ||
|
|
c36a7968f4 | ||
|
|
3762c8b76e | ||
|
|
872becdbbd | ||
|
|
c9694437d2 | ||
|
|
64ad90f73c | ||
|
|
166d23a813 | ||
|
|
59fdf2a6bb | ||
|
|
3640eaa726 | ||
|
|
2250d5f71f | ||
|
|
d9678325a2 | ||
|
|
dc8c47d936 | ||
|
|
5b7100ff87 | ||
|
|
4afa592160 | ||
|
|
54c7a2b0aa | ||
|
|
9cabc9bf05 | ||
|
|
dfd46df8a5 | ||
|
|
25cd4f3a1d | ||
|
|
d5b594dd12 | ||
|
|
803686ea4b | ||
|
|
3add769b51 | ||
|
|
d5a72cd65a | ||
|
|
d63163e46c | ||
|
|
62d690492c | ||
|
|
54d81a6258 | ||
|
|
56679a6e4a | ||
|
|
e0788d9d61 | ||
|
|
833e066853 | ||
|
|
02f860140d | ||
|
|
027cebade3 | ||
|
|
bb8dbfdf5b | ||
|
|
8e380183f8 | ||
|
|
4f89028c67 | ||
|
|
6b4c33d3a5 | ||
|
|
7a2e6990ca | ||
|
|
98ba2f2333 | ||
|
|
4e4d933d7b | ||
|
|
91c739958c | ||
|
|
1a6e1ae918 | ||
|
|
aedf39a9ca | ||
|
|
a274cd3a74 | ||
|
|
6be21469fb | ||
|
|
e0d3ff8aeb | ||
|
|
0614ab6b07 | ||
|
|
49e55c0f42 | ||
|
|
be4edbb460 | ||
|
|
4d30237f7a | ||
|
|
a3c0f6784b | ||
|
|
6d4c2db3b1 | ||
|
|
1436f2a0a0 | ||
|
|
e6a46bf827 | ||
|
|
9563aa33c8 | ||
|
|
6225c901fe | ||
|
|
cad0cbf0c8 | ||
|
|
1fc441f091 | ||
|
|
22849ccd11 | ||
|
|
a809224ec7 | ||
|
|
ae23ecb9b2 | ||
|
|
0db77f3ace | ||
|
|
779c80c581 | ||
|
|
00ced59c1a | ||
|
|
20595f4b14 | ||
|
|
2e97d8f8e8 | ||
|
|
7effba0f71 | ||
|
|
2ad69eba90 | ||
|
|
4d218e4cbd | ||
|
|
a0346a09ce | ||
|
|
f6e85be3ed | ||
|
|
04e921846f | ||
|
|
e37f3728d7 | ||
|
|
2062ece2ab | ||
|
|
a5fa6f1015 | ||
|
|
9bdd5bf4fe | ||
|
|
110ce5607e | ||
|
|
78f938b0e9 | ||
|
|
ad2f50316f | ||
|
|
cf534f3759 | ||
|
|
75c105f853 | ||
|
|
680eb76e45 | ||
|
|
e364041b40 | ||
|
|
de37457a75 | ||
|
|
057db3b3b3 | ||
|
|
461011ad2a | ||
|
|
aa7346bb36 | ||
|
|
5206543902 | ||
|
|
7f93a49cc3 | ||
|
|
bec86e3d5a | ||
|
|
3ba95a822f | ||
|
|
486ec44c3e | ||
|
|
8dc4877697 | ||
|
|
7415c5858d | ||
|
|
8e5411f468 | ||
|
|
3bf40bb8dd | ||
|
|
79956a4d47 | ||
|
|
2d755335de | ||
|
|
d7762c09dd | ||
|
|
957201e758 | ||
|
|
004dc271a4 | ||
|
|
a9b24ccc82 | ||
|
|
c57071a43a | ||
|
|
df27f04f61 | ||
|
|
f3e398afc5 | ||
|
|
65877efe8b | ||
|
|
96acd87f0b | ||
|
|
fcb35d4e73 | ||
|
|
0d47e5eb76 | ||
|
|
f30bbbffe7 | ||
|
|
6b88461553 | ||
|
|
700b558fb6 | ||
|
|
58b5be440f | ||
|
|
626801f7df | ||
|
|
77a345d4cb | ||
|
|
18901fd501 | ||
|
|
5b86cb5cc2 | ||
|
|
ce23225e46 | ||
|
|
09c229fe6c | ||
|
|
db56125708 | ||
|
|
5736b0a114 | ||
|
|
a21c0503f8 | ||
|
|
e52d5f3d98 | ||
|
|
0e96b9d010 | ||
|
|
dcba8c28f2 | ||
|
|
da93a3320b | ||
|
|
53607a0274 | ||
|
|
67d19f3570 | ||
|
|
54c1f71bd3 | ||
|
|
a7e2809466 | ||
|
|
3f66e9fe4b | ||
|
|
f547d0fac3 | ||
|
|
cdf272315e | ||
|
|
31303718da | ||
|
|
4192bdd731 | ||
|
|
c18aa03552 | ||
|
|
b2283f045a | ||
|
|
8e3863aa20 | ||
|
|
79899badd0 | ||
|
|
691b7a63f2 | ||
|
|
154731306b | ||
|
|
d67548adfe | ||
|
|
cfeaaa02fc | ||
|
|
c5270f85d3 | ||
|
|
45931a890d | ||
|
|
1a5c169c06 | ||
|
|
d8fbf43022 | ||
|
|
3be96efe0b | ||
|
|
99a2486b09 | ||
|
|
c3c65ee864 | ||
|
|
db0f5f8d22 | ||
|
|
8b162ca258 | ||
|
|
4f990d5a74 | ||
|
|
1349efa34d | ||
|
|
cf99ecb5a9 | ||
|
|
0d818d0a92 | ||
|
|
42b0ab437a | ||
|
|
a36de633d5 | ||
|
|
8a43d49b89 | ||
|
|
ae9c9cf369 | ||
|
|
db44c27674 | ||
|
|
efa2c7b08b | ||
|
|
a9441043bc | ||
|
|
aaf0cfa3c1 | ||
|
|
2a2444b961 | ||
|
|
2526ec92bd | ||
|
|
9bddc52601 | ||
|
|
1b96e93f91 | ||
|
|
6127b6959f | ||
|
|
330007beb2 | ||
|
|
cbfd48d949 | ||
|
|
f64064fe71 | ||
|
|
f2521889c2 | ||
|
|
642d41970d | ||
|
|
acd069fd27 | ||
|
|
c810b0514e | ||
|
|
e600024908 | ||
|
|
fd5b88449a | ||
|
|
433758e4cb | ||
|
|
5b8f762ab2 | ||
|
|
72db6e4de2 | ||
|
|
2780ccdd62 | ||
|
|
fdcabdfd28 | ||
|
|
40b876f550 | ||
|
|
5cb5aeba36 | ||
|
|
6a1f49c244 | ||
|
|
8613651f18 | ||
|
|
be4fea1928 | ||
|
|
2c4542a590 | ||
|
|
3ce5359523 | ||
|
|
fe4175b551 | ||
|
|
310bf08568 | ||
|
|
c040b4821d | ||
|
|
20149281a4 | ||
|
|
87f1017f80 | ||
|
|
664eff9e76 | ||
|
|
36eb33bc86 | ||
|
|
df8fb84723 | ||
|
|
4de648a77a | ||
|
|
929dc47be4 | ||
|
|
5f222517f0 | ||
|
|
940690be82 | ||
|
|
37ec687237 | ||
|
|
ca75cd940f | ||
|
|
607fd2b977 | ||
|
|
e689eb4a0a | ||
|
|
b6a63c8d5c | ||
|
|
209f1db984 | ||
|
|
dd3fddb0e9 | ||
|
|
ab080ab544 | ||
|
|
d1466f23ed | ||
|
|
918c1a6de1 | ||
|
|
37d52bf01b | ||
|
|
46de69d0e6 | ||
|
|
0946c704bf | ||
|
|
90853cc3ab | ||
|
|
521184ba8b | ||
|
|
05da2ed2c2 | ||
|
|
d4ecc8e24a | ||
|
|
6ae0d725d3 | ||
|
|
6190ad928d | ||
|
|
0451e1c23a | ||
|
|
7eccb7ff50 | ||
|
|
29f21208a0 | ||
|
|
099a2b9d17 | ||
|
|
3b4424226f | ||
|
|
f4a582e3e2 | ||
|
|
e4c4049741 | ||
|
|
83f02e6682 | ||
|
|
069ba220d2 | ||
|
|
54dab83a9e | ||
|
|
caf1f06bcb | ||
|
|
c7dde8f0e8 | ||
|
|
546f0fd0bc | ||
|
|
9163bcef4b | ||
|
|
e030e3bd15 | ||
|
|
c950cf265f | ||
|
|
9ae7b7d1be | ||
|
|
0bd8b9823a | ||
|
|
b86c5a93b3 | ||
|
|
1e3ba81613 | ||
|
|
a83cc1dbf4 | ||
|
|
94d732b411 | ||
|
|
50be50c521 | ||
|
|
b16feb6853 | ||
|
|
32c578729c | ||
|
|
710aad20d3 | ||
|
|
d742e01a32 | ||
|
|
50d5cfa8bc | ||
|
|
80d21c039e | ||
|
|
549ab64358 | ||
|
|
e8d09733d4 | ||
|
|
5f05949425 | ||
|
|
5dc654433c | ||
|
|
05af3a3383 | ||
|
|
2eab3e6402 | ||
|
|
16c82312f3 | ||
|
|
bd494d23c5 | ||
|
|
95daec798b | ||
|
|
ef21960600 | ||
|
|
a4585423fd | ||
|
|
5aef0809d4 | ||
|
|
4d9c7d39f4 | ||
|
|
6a532cb1b5 | ||
|
|
d93e4212cd | ||
|
|
72c111bac4 | ||
|
|
d05f020d5a | ||
|
|
dde57477fc | ||
|
|
ffb6ecc488 | ||
|
|
6123541d80 | ||
|
|
e510dd9c60 | ||
|
|
0461d9e822 | ||
|
|
4f7262aa96 | ||
|
|
eac953c6e4 | ||
|
|
d7fc953fa2 | ||
|
|
f35f34b909 | ||
|
|
34a2176689 | ||
|
|
21756a1969 | ||
|
|
17a8e85cb8 | ||
|
|
1b191e14d0 | ||
|
|
98db3bc0bf | ||
|
|
46cf1c6ce0 | ||
|
|
fbf4c5daf3 | ||
|
|
c81260b3c3 | ||
|
|
8d69e19ac1 | ||
|
|
6ab93841e9 | ||
|
|
52cbbdaf38 | ||
|
|
0996a43dbb | ||
|
|
3faaa8b227 | ||
|
|
c26bb0f38a | ||
|
|
911ffe81f0 | ||
|
|
ecf993834c | ||
|
|
3cbb43a73a | ||
|
|
db97d3d8c8 | ||
|
|
7199662fbb | ||
|
|
a14a2137e7 | ||
|
|
16ac703008 | ||
|
|
24e2ee5812 | ||
|
|
b0d8815dab | ||
|
|
831a0af508 | ||
|
|
488202feee | ||
|
|
193402ad41 | ||
|
|
1b86b7cb4b | ||
|
|
e5dc991ffd | ||
|
|
89e09afdf6 | ||
|
|
bec7fcb14a | ||
|
|
f45d4d0755 | ||
|
|
64558a57e3 | ||
|
|
29e4414c35 | ||
|
|
c2e12440d2 | ||
|
|
1685aa5978 | ||
|
|
6874f564c1 | ||
|
|
4882f70040 | ||
|
|
1aca317c77 | ||
|
|
af2730fe2a | ||
|
|
a6d64d1d44 | ||
|
|
d15dd89bb7 | ||
|
|
961682aa6b | ||
|
|
2f37cfe569 | ||
|
|
5b5c6dccc0 | ||
|
|
d58a5c8cae | ||
|
|
1d5788f779 | ||
|
|
97224b072a | ||
|
|
15442c1747 | ||
|
|
ff9db165eb | ||
|
|
48332d248f | ||
|
|
07815c24cd | ||
|
|
49b018c765 | ||
|
|
65f975655c | ||
|
|
0c1efd1f8a | ||
|
|
bc1cbd8065 | ||
|
|
50a2d89add | ||
|
|
99643a82ae | ||
|
|
fcc35f459c | ||
|
|
a5aa91ed99 | ||
|
|
d83b872c55 | ||
|
|
8ec2651ad7 | ||
|
|
53e269c5f1 | ||
|
|
8b8e206c07 | ||
|
|
e0562f9708 | ||
|
|
6462ee55d3 | ||
|
|
91ba5742c6 | ||
|
|
667e469659 | ||
|
|
37cecb5a5b | ||
|
|
a47ebccf9a | ||
|
|
584d5b8d65 | ||
|
|
8eef5bde4f | ||
|
|
3532be48c7 | ||
|
|
5f7309bfa0 | ||
|
|
fa4a246744 | ||
|
|
321386db88 | ||
|
|
b99b4825a2 | ||
|
|
9b455125e9 | ||
|
|
adcb9bfb7d | ||
|
|
4abfd38169 | ||
|
|
b684fffdaf | ||
|
|
fb3b62ca02 | ||
|
|
c469e458b7 | ||
|
|
be5473f242 | ||
|
|
527c0fe4f9 | ||
|
|
0ec4d4c9cf | ||
|
|
28f860def2 | ||
|
|
42abcc0fac | ||
|
|
a38fcafcff | ||
|
|
c4a533c3d5 | ||
|
|
96f31a2cff | ||
|
|
8f4fb9303f | ||
|
|
336be2da96 | ||
|
|
e129bffce9 | ||
|
|
a9d9a2ad44 | ||
|
|
c0a5293435 | ||
|
|
b9ae00956d | ||
|
|
e37016bf64 | ||
|
|
104c7d6c4f | ||
|
|
b773823a1b | ||
|
|
0894814148 | ||
|
|
cc948df1dd | ||
|
|
35e3660c61 | ||
|
|
28c6901de1 | ||
|
|
dc067454c1 | ||
|
|
32c2bd4222 | ||
|
|
cd4ea1c348 | ||
|
|
8984e47414 | ||
|
|
491e79db4c | ||
|
|
8a1a0547a8 | ||
|
|
9d47892342 | ||
|
|
32cfb1ca25 | ||
|
|
810aef34ca | ||
|
|
b23b3c4dfe | ||
|
|
b9d99a1626 | ||
|
|
496a07ed4c | ||
|
|
fbba97552e | ||
|
|
0cefe2d107 | ||
|
|
768426ad99 | ||
|
|
5a48ff5eb2 | ||
|
|
96c8c7ba56 | ||
|
|
29c2281ab2 | ||
|
|
0d70651c5a | ||
|
|
b1fb2532e0 | ||
|
|
05b695d516 | ||
|
|
44c9b2fc68 | ||
|
|
018205a9a0 | ||
|
|
c333108c61 | ||
|
|
2fcb521c77 | ||
|
|
0dc87d45a8 | ||
|
|
03dc073f2b | ||
|
|
b402f087d7 | ||
|
|
656fbde7d1 | ||
|
|
a89e6c0ca6 | ||
|
|
d380da7a32 | ||
|
|
0de4b65ba6 | ||
|
|
5c7954a0c7 | ||
|
|
62f334cfa5 | ||
|
|
6d2c15ea79 | ||
|
|
4b8f91d0d9 | ||
|
|
c364290be9 | ||
|
|
a14aab5df7 | ||
|
|
47c5b5ed06 | ||
|
|
0eae181092 | ||
|
|
1cbc53e8ee | ||
|
|
7535fdb31b | ||
|
|
de9393879e | ||
|
|
db51a343de | ||
|
|
e2375c8368 | ||
|
|
697c6c9324 | ||
|
|
6d07be898d | ||
|
|
ade21e6c60 | ||
|
|
fcf5b414d6 | ||
|
|
92d1bebdac | ||
|
|
39a5408e98 | ||
|
|
937f969cc4 | ||
|
|
f4101d0f8b | ||
|
|
ce2218ed65 | ||
|
|
cdae1b4c60 | ||
|
|
c4b16923bb | ||
|
|
b016e65daa | ||
|
|
c35839afbc | ||
|
|
cd8826618d | ||
|
|
ab0f7346bc | ||
|
|
9fb8b816c5 | ||
|
|
0e79728f86 | ||
|
|
4b0b82adc5 | ||
|
|
850799802b | ||
|
|
ed1b59fd25 | ||
|
|
fa98297547 | ||
|
|
2949f37587 | ||
|
|
fca7296e6e | ||
|
|
6aa77550c5 | ||
|
|
23e1ac341c | ||
|
|
9ae7e122ac | ||
|
|
73493c1f44 | ||
|
|
65c4c62f78 | ||
|
|
aba52fa878 | ||
|
|
a5cc87b4a5 | ||
|
|
11ee2876a6 | ||
|
|
20eea64334 | ||
|
|
44165a1bbb | ||
|
|
e9bc8e1b35 | ||
|
|
5e52599326 | ||
|
|
4903b8120b | ||
|
|
d0c98af4e6 | ||
|
|
624157ef7b | ||
|
|
08da00c94a | ||
|
|
9910c7dcd0 | ||
|
|
9ff422374d | ||
|
|
5c49268c47 | ||
|
|
7df1d83ebb | ||
|
|
555d5f6e97 | ||
|
|
716e60729d | ||
|
|
65ba7c7f3f | ||
|
|
ed1ab3e498 | ||
|
|
dc371d7174 | ||
|
|
cf1e6fb847 | ||
|
|
45e0942755 | ||
|
|
0f4431d0bb | ||
|
|
54b21c6e46 | ||
|
|
c2a33b480f | ||
|
|
490c17b3cd | ||
|
|
f8aa0bc084 | ||
|
|
ba7d9967a8 | ||
|
|
adaf6d3eb4 | ||
|
|
bbc3339bda | ||
|
|
f720affe8c | ||
|
|
a718369374 | ||
|
|
4b6ec2a8c2 | ||
|
|
e48a808b5c | ||
|
|
f929abacab | ||
|
|
1562879369 | ||
|
|
e1d410953b | ||
|
|
8818eb2687 | ||
|
|
4320327383 | ||
|
|
5c4c3010fc | ||
|
|
c16ebd0aca | ||
|
|
d392737279 | ||
|
|
be204f8978 | ||
|
|
9391477be4 | ||
|
|
09fd551e03 | ||
|
|
ee8425b836 | ||
|
|
2499fa669d | ||
|
|
bd047d03ef | ||
|
|
9511c91a79 | ||
|
|
570b0ecd49 | ||
|
|
80290266e6 | ||
|
|
dc7f97ea5e | ||
|
|
c9279c9818 | ||
|
|
9341679b31 | ||
|
|
78cac9a97c | ||
|
|
075fb8d261 | ||
|
|
9bce441a1e | ||
|
|
5b41568e8f | ||
|
|
0becb1ac46 | ||
|
|
fff8b02b46 | ||
|
|
83564fbeb9 | ||
|
|
b30b53e4a7 | ||
|
|
60d60d971a | ||
|
|
5596294635 | ||
|
|
54bf872663 | ||
|
|
4b109507d8 | ||
|
|
625822e5a1 | ||
|
|
18c4896310 | ||
|
|
d542045645 | ||
|
|
2199076fef | ||
|
|
37902e1287 | ||
|
|
30f7e2310f | ||
|
|
89d9d25a2b | ||
|
|
0d766c5868 | ||
|
|
313e5564fe | ||
|
|
0e52cb902a | ||
|
|
3684a5d833 | ||
|
|
a5aa30be33 | ||
|
|
eb2b03699f | ||
|
|
3da3b415a7 | ||
|
|
03cc3383e1 | ||
|
|
4988c8beea | ||
|
|
3a0ac6c3d3 | ||
|
|
203f2e082d | ||
|
|
b4e2306da8 | ||
|
|
c0d55945d3 | ||
|
|
3a3ff16c39 | ||
|
|
774d1de56e | ||
|
|
01938e3cdd | ||
|
|
24213963fd | ||
|
|
6d8aeb1d58 | ||
|
|
6fe40949f9 | ||
|
|
c1b01c2dc7 | ||
|
|
a24d9cd9b5 | ||
|
|
1b982af46f | ||
|
|
66f042953d | ||
|
|
4f2d4f98e3 | ||
|
|
251c7f434f | ||
|
|
7835b365a7 | ||
|
|
4aee070173 | ||
|
|
ef078587cc | ||
|
|
6e119ab6cc |
4
AUTHORS
4
AUTHORS
@@ -1,3 +1,3 @@
|
|||||||
Christophe Saout <christophe@saout.de>
|
Jana Saout <jana@saout.de>
|
||||||
Clemens Fruhwirth <clemens@endorphin.org>
|
Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
Milan Broz <asi@ucw.cz>
|
Milan Broz <gmazyland@gmail.com>
|
||||||
|
|||||||
41
COPYING
41
COPYING
@@ -1,12 +1,12 @@
|
|||||||
GNU GENERAL PUBLIC LICENSE
|
GNU GENERAL PUBLIC LICENSE
|
||||||
Version 2, June 1991
|
Version 2, June 1991
|
||||||
|
|
||||||
Copyright (C) 1989, 1991 Free Software Foundation, Inc.
|
Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
|
||||||
59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||||
Everyone is permitted to copy and distribute verbatim copies
|
Everyone is permitted to copy and distribute verbatim copies
|
||||||
of this license document, but changing it is not allowed.
|
of this license document, but changing it is not allowed.
|
||||||
|
|
||||||
Preamble
|
Preamble
|
||||||
|
|
||||||
The licenses for most software are designed to take away your
|
The licenses for most software are designed to take away your
|
||||||
freedom to share and change it. By contrast, the GNU General Public
|
freedom to share and change it. By contrast, the GNU General Public
|
||||||
@@ -15,7 +15,7 @@ software--to make sure the software is free for all its users. This
|
|||||||
General Public License applies to most of the Free Software
|
General Public License applies to most of the Free Software
|
||||||
Foundation's software and to any other program whose authors commit to
|
Foundation's software and to any other program whose authors commit to
|
||||||
using it. (Some other Free Software Foundation software is covered by
|
using it. (Some other Free Software Foundation software is covered by
|
||||||
the GNU Library General Public License instead.) You can apply it to
|
the GNU Lesser General Public License instead.) You can apply it to
|
||||||
your programs, too.
|
your programs, too.
|
||||||
|
|
||||||
When we speak of free software, we are referring to freedom, not
|
When we speak of free software, we are referring to freedom, not
|
||||||
@@ -55,8 +55,8 @@ patent must be licensed for everyone's free use or not licensed at all.
|
|||||||
|
|
||||||
The precise terms and conditions for copying, distribution and
|
The precise terms and conditions for copying, distribution and
|
||||||
modification follow.
|
modification follow.
|
||||||
|
|
||||||
GNU GENERAL PUBLIC LICENSE
|
GNU GENERAL PUBLIC LICENSE
|
||||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
||||||
|
|
||||||
0. This License applies to any program or other work which contains
|
0. This License applies to any program or other work which contains
|
||||||
@@ -110,7 +110,7 @@ above, provided that you also meet all of these conditions:
|
|||||||
License. (Exception: if the Program itself is interactive but
|
License. (Exception: if the Program itself is interactive but
|
||||||
does not normally print such an announcement, your work based on
|
does not normally print such an announcement, your work based on
|
||||||
the Program is not required to print an announcement.)
|
the Program is not required to print an announcement.)
|
||||||
|
|
||||||
These requirements apply to the modified work as a whole. If
|
These requirements apply to the modified work as a whole. If
|
||||||
identifiable sections of that work are not derived from the Program,
|
identifiable sections of that work are not derived from the Program,
|
||||||
and can be reasonably considered independent and separate works in
|
and can be reasonably considered independent and separate works in
|
||||||
@@ -168,7 +168,7 @@ access to copy from a designated place, then offering equivalent
|
|||||||
access to copy the source code from the same place counts as
|
access to copy the source code from the same place counts as
|
||||||
distribution of the source code, even though third parties are not
|
distribution of the source code, even though third parties are not
|
||||||
compelled to copy the source along with the object code.
|
compelled to copy the source along with the object code.
|
||||||
|
|
||||||
4. You may not copy, modify, sublicense, or distribute the Program
|
4. You may not copy, modify, sublicense, or distribute the Program
|
||||||
except as expressly provided under this License. Any attempt
|
except as expressly provided under this License. Any attempt
|
||||||
otherwise to copy, modify, sublicense or distribute the Program is
|
otherwise to copy, modify, sublicense or distribute the Program is
|
||||||
@@ -225,7 +225,7 @@ impose that choice.
|
|||||||
|
|
||||||
This section is intended to make thoroughly clear what is believed to
|
This section is intended to make thoroughly clear what is believed to
|
||||||
be a consequence of the rest of this License.
|
be a consequence of the rest of this License.
|
||||||
|
|
||||||
8. If the distribution and/or use of the Program is restricted in
|
8. If the distribution and/or use of the Program is restricted in
|
||||||
certain countries either by patents or by copyrighted interfaces, the
|
certain countries either by patents or by copyrighted interfaces, the
|
||||||
original copyright holder who places the Program under this License
|
original copyright holder who places the Program under this License
|
||||||
@@ -255,7 +255,7 @@ make exceptions for this. Our decision will be guided by the two goals
|
|||||||
of preserving the free status of all derivatives of our free software and
|
of preserving the free status of all derivatives of our free software and
|
||||||
of promoting the sharing and reuse of software generally.
|
of promoting the sharing and reuse of software generally.
|
||||||
|
|
||||||
NO WARRANTY
|
NO WARRANTY
|
||||||
|
|
||||||
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
|
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
|
||||||
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
|
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
|
||||||
@@ -277,9 +277,9 @@ YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
|
|||||||
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
|
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
|
||||||
POSSIBILITY OF SUCH DAMAGES.
|
POSSIBILITY OF SUCH DAMAGES.
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
END OF TERMS AND CONDITIONS
|
||||||
|
|
||||||
How to Apply These Terms to Your New Programs
|
How to Apply These Terms to Your New Programs
|
||||||
|
|
||||||
If you develop a new program, and you want it to be of the greatest
|
If you develop a new program, and you want it to be of the greatest
|
||||||
possible use to the public, the best way to achieve this is to make it
|
possible use to the public, the best way to achieve this is to make it
|
||||||
@@ -303,17 +303,16 @@ the "copyright" line and a pointer to where the full notice is found.
|
|||||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
GNU General Public License for more details.
|
GNU General Public License for more details.
|
||||||
|
|
||||||
You should have received a copy of the GNU General Public License
|
You should have received a copy of the GNU General Public License along
|
||||||
along with this program; if not, write to the Free Software
|
with this program; if not, write to the Free Software Foundation, Inc.,
|
||||||
Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
|
||||||
|
|
||||||
Also add information on how to contact you by electronic and paper mail.
|
Also add information on how to contact you by electronic and paper mail.
|
||||||
|
|
||||||
If the program is interactive, make it output a short notice like this
|
If the program is interactive, make it output a short notice like this
|
||||||
when it starts in an interactive mode:
|
when it starts in an interactive mode:
|
||||||
|
|
||||||
Gnomovision version 69, Copyright (C) year name of author
|
Gnomovision version 69, Copyright (C) year name of author
|
||||||
Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||||
This is free software, and you are welcome to redistribute it
|
This is free software, and you are welcome to redistribute it
|
||||||
under certain conditions; type `show c' for details.
|
under certain conditions; type `show c' for details.
|
||||||
@@ -336,7 +335,7 @@ necessary. Here is a sample; alter the names:
|
|||||||
This General Public License does not permit incorporating your program into
|
This General Public License does not permit incorporating your program into
|
||||||
proprietary programs. If your program is a subroutine library, you may
|
proprietary programs. If your program is a subroutine library, you may
|
||||||
consider it more useful to permit linking proprietary applications with the
|
consider it more useful to permit linking proprietary applications with the
|
||||||
library. If this is what you want to do, use the GNU Library General
|
library. If this is what you want to do, use the GNU Lesser General
|
||||||
Public License instead of this License.
|
Public License instead of this License.
|
||||||
|
|
||||||
-----
|
-----
|
||||||
|
|||||||
517
COPYING.LGPL
Normal file
517
COPYING.LGPL
Normal file
@@ -0,0 +1,517 @@
|
|||||||
|
GNU LESSER GENERAL PUBLIC LICENSE
|
||||||
|
Version 2.1, February 1999
|
||||||
|
|
||||||
|
Copyright (C) 1991, 1999 Free Software Foundation, Inc.
|
||||||
|
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||||
|
Everyone is permitted to copy and distribute verbatim copies
|
||||||
|
of this license document, but changing it is not allowed.
|
||||||
|
|
||||||
|
[This is the first released version of the Lesser GPL. It also counts
|
||||||
|
as the successor of the GNU Library Public License, version 2, hence
|
||||||
|
the version number 2.1.]
|
||||||
|
|
||||||
|
Preamble
|
||||||
|
|
||||||
|
The licenses for most software are designed to take away your
|
||||||
|
freedom to share and change it. By contrast, the GNU General Public
|
||||||
|
Licenses are intended to guarantee your freedom to share and change
|
||||||
|
free software--to make sure the software is free for all its users.
|
||||||
|
|
||||||
|
This license, the Lesser General Public License, applies to some
|
||||||
|
specially designated software packages--typically libraries--of the
|
||||||
|
Free Software Foundation and other authors who decide to use it. You
|
||||||
|
can use it too, but we suggest you first think carefully about whether
|
||||||
|
this license or the ordinary General Public License is the better
|
||||||
|
strategy to use in any particular case, based on the explanations below.
|
||||||
|
|
||||||
|
When we speak of free software, we are referring to freedom of use,
|
||||||
|
not price. Our General Public Licenses are designed to make sure that
|
||||||
|
you have the freedom to distribute copies of free software (and charge
|
||||||
|
for this service if you wish); that you receive source code or can get
|
||||||
|
it if you want it; that you can change the software and use pieces of
|
||||||
|
it in new free programs; and that you are informed that you can do
|
||||||
|
these things.
|
||||||
|
|
||||||
|
To protect your rights, we need to make restrictions that forbid
|
||||||
|
distributors to deny you these rights or to ask you to surrender these
|
||||||
|
rights. These restrictions translate to certain responsibilities for
|
||||||
|
you if you distribute copies of the library or if you modify it.
|
||||||
|
|
||||||
|
For example, if you distribute copies of the library, whether gratis
|
||||||
|
or for a fee, you must give the recipients all the rights that we gave
|
||||||
|
you. You must make sure that they, too, receive or can get the source
|
||||||
|
code. If you link other code with the library, you must provide
|
||||||
|
complete object files to the recipients, so that they can relink them
|
||||||
|
with the library after making changes to the library and recompiling
|
||||||
|
it. And you must show them these terms so they know their rights.
|
||||||
|
|
||||||
|
We protect your rights with a two-step method: (1) we copyright the
|
||||||
|
library, and (2) we offer you this license, which gives you legal
|
||||||
|
permission to copy, distribute and/or modify the library.
|
||||||
|
|
||||||
|
To protect each distributor, we want to make it very clear that
|
||||||
|
there is no warranty for the free library. Also, if the library is
|
||||||
|
modified by someone else and passed on, the recipients should know
|
||||||
|
that what they have is not the original version, so that the original
|
||||||
|
author's reputation will not be affected by problems that might be
|
||||||
|
introduced by others.
|
||||||
|
|
||||||
|
Finally, software patents pose a constant threat to the existence of
|
||||||
|
any free program. We wish to make sure that a company cannot
|
||||||
|
effectively restrict the users of a free program by obtaining a
|
||||||
|
restrictive license from a patent holder. Therefore, we insist that
|
||||||
|
any patent license obtained for a version of the library must be
|
||||||
|
consistent with the full freedom of use specified in this license.
|
||||||
|
|
||||||
|
Most GNU software, including some libraries, is covered by the
|
||||||
|
ordinary GNU General Public License. This license, the GNU Lesser
|
||||||
|
General Public License, applies to certain designated libraries, and
|
||||||
|
is quite different from the ordinary General Public License. We use
|
||||||
|
this license for certain libraries in order to permit linking those
|
||||||
|
libraries into non-free programs.
|
||||||
|
|
||||||
|
When a program is linked with a library, whether statically or using
|
||||||
|
a shared library, the combination of the two is legally speaking a
|
||||||
|
combined work, a derivative of the original library. The ordinary
|
||||||
|
General Public License therefore permits such linking only if the
|
||||||
|
entire combination fits its criteria of freedom. The Lesser General
|
||||||
|
Public License permits more lax criteria for linking other code with
|
||||||
|
the library.
|
||||||
|
|
||||||
|
We call this license the "Lesser" General Public License because it
|
||||||
|
does Less to protect the user's freedom than the ordinary General
|
||||||
|
Public License. It also provides other free software developers Less
|
||||||
|
of an advantage over competing non-free programs. These disadvantages
|
||||||
|
are the reason we use the ordinary General Public License for many
|
||||||
|
libraries. However, the Lesser license provides advantages in certain
|
||||||
|
special circumstances.
|
||||||
|
|
||||||
|
For example, on rare occasions, there may be a special need to
|
||||||
|
encourage the widest possible use of a certain library, so that it becomes
|
||||||
|
a de-facto standard. To achieve this, non-free programs must be
|
||||||
|
allowed to use the library. A more frequent case is that a free
|
||||||
|
library does the same job as widely used non-free libraries. In this
|
||||||
|
case, there is little to gain by limiting the free library to free
|
||||||
|
software only, so we use the Lesser General Public License.
|
||||||
|
|
||||||
|
In other cases, permission to use a particular library in non-free
|
||||||
|
programs enables a greater number of people to use a large body of
|
||||||
|
free software. For example, permission to use the GNU C Library in
|
||||||
|
non-free programs enables many more people to use the whole GNU
|
||||||
|
operating system, as well as its variant, the GNU/Linux operating
|
||||||
|
system.
|
||||||
|
|
||||||
|
Although the Lesser General Public License is Less protective of the
|
||||||
|
users' freedom, it does ensure that the user of a program that is
|
||||||
|
linked with the Library has the freedom and the wherewithal to run
|
||||||
|
that program using a modified version of the Library.
|
||||||
|
|
||||||
|
The precise terms and conditions for copying, distribution and
|
||||||
|
modification follow. Pay close attention to the difference between a
|
||||||
|
"work based on the library" and a "work that uses the library". The
|
||||||
|
former contains code derived from the library, whereas the latter must
|
||||||
|
be combined with the library in order to run.
|
||||||
|
|
||||||
|
GNU LESSER GENERAL PUBLIC LICENSE
|
||||||
|
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
||||||
|
|
||||||
|
0. This License Agreement applies to any software library or other
|
||||||
|
program which contains a notice placed by the copyright holder or
|
||||||
|
other authorized party saying it may be distributed under the terms of
|
||||||
|
this Lesser General Public License (also called "this License").
|
||||||
|
Each licensee is addressed as "you".
|
||||||
|
|
||||||
|
A "library" means a collection of software functions and/or data
|
||||||
|
prepared so as to be conveniently linked with application programs
|
||||||
|
(which use some of those functions and data) to form executables.
|
||||||
|
|
||||||
|
The "Library", below, refers to any such software library or work
|
||||||
|
which has been distributed under these terms. A "work based on the
|
||||||
|
Library" means either the Library or any derivative work under
|
||||||
|
copyright law: that is to say, a work containing the Library or a
|
||||||
|
portion of it, either verbatim or with modifications and/or translated
|
||||||
|
straightforwardly into another language. (Hereinafter, translation is
|
||||||
|
included without limitation in the term "modification".)
|
||||||
|
|
||||||
|
"Source code" for a work means the preferred form of the work for
|
||||||
|
making modifications to it. For a library, complete source code means
|
||||||
|
all the source code for all modules it contains, plus any associated
|
||||||
|
interface definition files, plus the scripts used to control compilation
|
||||||
|
and installation of the library.
|
||||||
|
|
||||||
|
Activities other than copying, distribution and modification are not
|
||||||
|
covered by this License; they are outside its scope. The act of
|
||||||
|
running a program using the Library is not restricted, and output from
|
||||||
|
such a program is covered only if its contents constitute a work based
|
||||||
|
on the Library (independent of the use of the Library in a tool for
|
||||||
|
writing it). Whether that is true depends on what the Library does
|
||||||
|
and what the program that uses the Library does.
|
||||||
|
|
||||||
|
1. You may copy and distribute verbatim copies of the Library's
|
||||||
|
complete source code as you receive it, in any medium, provided that
|
||||||
|
you conspicuously and appropriately publish on each copy an
|
||||||
|
appropriate copyright notice and disclaimer of warranty; keep intact
|
||||||
|
all the notices that refer to this License and to the absence of any
|
||||||
|
warranty; and distribute a copy of this License along with the
|
||||||
|
Library.
|
||||||
|
|
||||||
|
You may charge a fee for the physical act of transferring a copy,
|
||||||
|
and you may at your option offer warranty protection in exchange for a
|
||||||
|
fee.
|
||||||
|
|
||||||
|
2. You may modify your copy or copies of the Library or any portion
|
||||||
|
of it, thus forming a work based on the Library, and copy and
|
||||||
|
distribute such modifications or work under the terms of Section 1
|
||||||
|
above, provided that you also meet all of these conditions:
|
||||||
|
|
||||||
|
a) The modified work must itself be a software library.
|
||||||
|
|
||||||
|
b) You must cause the files modified to carry prominent notices
|
||||||
|
stating that you changed the files and the date of any change.
|
||||||
|
|
||||||
|
c) You must cause the whole of the work to be licensed at no
|
||||||
|
charge to all third parties under the terms of this License.
|
||||||
|
|
||||||
|
d) If a facility in the modified Library refers to a function or a
|
||||||
|
table of data to be supplied by an application program that uses
|
||||||
|
the facility, other than as an argument passed when the facility
|
||||||
|
is invoked, then you must make a good faith effort to ensure that,
|
||||||
|
in the event an application does not supply such function or
|
||||||
|
table, the facility still operates, and performs whatever part of
|
||||||
|
its purpose remains meaningful.
|
||||||
|
|
||||||
|
(For example, a function in a library to compute square roots has
|
||||||
|
a purpose that is entirely well-defined independent of the
|
||||||
|
application. Therefore, Subsection 2d requires that any
|
||||||
|
application-supplied function or table used by this function must
|
||||||
|
be optional: if the application does not supply it, the square
|
||||||
|
root function must still compute square roots.)
|
||||||
|
|
||||||
|
These requirements apply to the modified work as a whole. If
|
||||||
|
identifiable sections of that work are not derived from the Library,
|
||||||
|
and can be reasonably considered independent and separate works in
|
||||||
|
themselves, then this License, and its terms, do not apply to those
|
||||||
|
sections when you distribute them as separate works. But when you
|
||||||
|
distribute the same sections as part of a whole which is a work based
|
||||||
|
on the Library, the distribution of the whole must be on the terms of
|
||||||
|
this License, whose permissions for other licensees extend to the
|
||||||
|
entire whole, and thus to each and every part regardless of who wrote
|
||||||
|
it.
|
||||||
|
|
||||||
|
Thus, it is not the intent of this section to claim rights or contest
|
||||||
|
your rights to work written entirely by you; rather, the intent is to
|
||||||
|
exercise the right to control the distribution of derivative or
|
||||||
|
collective works based on the Library.
|
||||||
|
|
||||||
|
In addition, mere aggregation of another work not based on the Library
|
||||||
|
with the Library (or with a work based on the Library) on a volume of
|
||||||
|
a storage or distribution medium does not bring the other work under
|
||||||
|
the scope of this License.
|
||||||
|
|
||||||
|
3. You may opt to apply the terms of the ordinary GNU General Public
|
||||||
|
License instead of this License to a given copy of the Library. To do
|
||||||
|
this, you must alter all the notices that refer to this License, so
|
||||||
|
that they refer to the ordinary GNU General Public License, version 2,
|
||||||
|
instead of to this License. (If a newer version than version 2 of the
|
||||||
|
ordinary GNU General Public License has appeared, then you can specify
|
||||||
|
that version instead if you wish.) Do not make any other change in
|
||||||
|
these notices.
|
||||||
|
|
||||||
|
Once this change is made in a given copy, it is irreversible for
|
||||||
|
that copy, so the ordinary GNU General Public License applies to all
|
||||||
|
subsequent copies and derivative works made from that copy.
|
||||||
|
|
||||||
|
This option is useful when you wish to copy part of the code of
|
||||||
|
the Library into a program that is not a library.
|
||||||
|
|
||||||
|
4. You may copy and distribute the Library (or a portion or
|
||||||
|
derivative of it, under Section 2) in object code or executable form
|
||||||
|
under the terms of Sections 1 and 2 above provided that you accompany
|
||||||
|
it with the complete corresponding machine-readable source code, which
|
||||||
|
must be distributed under the terms of Sections 1 and 2 above on a
|
||||||
|
medium customarily used for software interchange.
|
||||||
|
|
||||||
|
If distribution of object code is made by offering access to copy
|
||||||
|
from a designated place, then offering equivalent access to copy the
|
||||||
|
source code from the same place satisfies the requirement to
|
||||||
|
distribute the source code, even though third parties are not
|
||||||
|
compelled to copy the source along with the object code.
|
||||||
|
|
||||||
|
5. A program that contains no derivative of any portion of the
|
||||||
|
Library, but is designed to work with the Library by being compiled or
|
||||||
|
linked with it, is called a "work that uses the Library". Such a
|
||||||
|
work, in isolation, is not a derivative work of the Library, and
|
||||||
|
therefore falls outside the scope of this License.
|
||||||
|
|
||||||
|
However, linking a "work that uses the Library" with the Library
|
||||||
|
creates an executable that is a derivative of the Library (because it
|
||||||
|
contains portions of the Library), rather than a "work that uses the
|
||||||
|
library". The executable is therefore covered by this License.
|
||||||
|
Section 6 states terms for distribution of such executables.
|
||||||
|
|
||||||
|
When a "work that uses the Library" uses material from a header file
|
||||||
|
that is part of the Library, the object code for the work may be a
|
||||||
|
derivative work of the Library even though the source code is not.
|
||||||
|
Whether this is true is especially significant if the work can be
|
||||||
|
linked without the Library, or if the work is itself a library. The
|
||||||
|
threshold for this to be true is not precisely defined by law.
|
||||||
|
|
||||||
|
If such an object file uses only numerical parameters, data
|
||||||
|
structure layouts and accessors, and small macros and small inline
|
||||||
|
functions (ten lines or less in length), then the use of the object
|
||||||
|
file is unrestricted, regardless of whether it is legally a derivative
|
||||||
|
work. (Executables containing this object code plus portions of the
|
||||||
|
Library will still fall under Section 6.)
|
||||||
|
|
||||||
|
Otherwise, if the work is a derivative of the Library, you may
|
||||||
|
distribute the object code for the work under the terms of Section 6.
|
||||||
|
Any executables containing that work also fall under Section 6,
|
||||||
|
whether or not they are linked directly with the Library itself.
|
||||||
|
|
||||||
|
6. As an exception to the Sections above, you may also combine or
|
||||||
|
link a "work that uses the Library" with the Library to produce a
|
||||||
|
work containing portions of the Library, and distribute that work
|
||||||
|
under terms of your choice, provided that the terms permit
|
||||||
|
modification of the work for the customer's own use and reverse
|
||||||
|
engineering for debugging such modifications.
|
||||||
|
|
||||||
|
You must give prominent notice with each copy of the work that the
|
||||||
|
Library is used in it and that the Library and its use are covered by
|
||||||
|
this License. You must supply a copy of this License. If the work
|
||||||
|
during execution displays copyright notices, you must include the
|
||||||
|
copyright notice for the Library among them, as well as a reference
|
||||||
|
directing the user to the copy of this License. Also, you must do one
|
||||||
|
of these things:
|
||||||
|
|
||||||
|
a) Accompany the work with the complete corresponding
|
||||||
|
machine-readable source code for the Library including whatever
|
||||||
|
changes were used in the work (which must be distributed under
|
||||||
|
Sections 1 and 2 above); and, if the work is an executable linked
|
||||||
|
with the Library, with the complete machine-readable "work that
|
||||||
|
uses the Library", as object code and/or source code, so that the
|
||||||
|
user can modify the Library and then relink to produce a modified
|
||||||
|
executable containing the modified Library. (It is understood
|
||||||
|
that the user who changes the contents of definitions files in the
|
||||||
|
Library will not necessarily be able to recompile the application
|
||||||
|
to use the modified definitions.)
|
||||||
|
|
||||||
|
b) Use a suitable shared library mechanism for linking with the
|
||||||
|
Library. A suitable mechanism is one that (1) uses at run time a
|
||||||
|
copy of the library already present on the user's computer system,
|
||||||
|
rather than copying library functions into the executable, and (2)
|
||||||
|
will operate properly with a modified version of the library, if
|
||||||
|
the user installs one, as long as the modified version is
|
||||||
|
interface-compatible with the version that the work was made with.
|
||||||
|
|
||||||
|
c) Accompany the work with a written offer, valid for at
|
||||||
|
least three years, to give the same user the materials
|
||||||
|
specified in Subsection 6a, above, for a charge no more
|
||||||
|
than the cost of performing this distribution.
|
||||||
|
|
||||||
|
d) If distribution of the work is made by offering access to copy
|
||||||
|
from a designated place, offer equivalent access to copy the above
|
||||||
|
specified materials from the same place.
|
||||||
|
|
||||||
|
e) Verify that the user has already received a copy of these
|
||||||
|
materials or that you have already sent this user a copy.
|
||||||
|
|
||||||
|
For an executable, the required form of the "work that uses the
|
||||||
|
Library" must include any data and utility programs needed for
|
||||||
|
reproducing the executable from it. However, as a special exception,
|
||||||
|
the materials to be distributed need not include anything that is
|
||||||
|
normally distributed (in either source or binary form) with the major
|
||||||
|
components (compiler, kernel, and so on) of the operating system on
|
||||||
|
which the executable runs, unless that component itself accompanies
|
||||||
|
the executable.
|
||||||
|
|
||||||
|
It may happen that this requirement contradicts the license
|
||||||
|
restrictions of other proprietary libraries that do not normally
|
||||||
|
accompany the operating system. Such a contradiction means you cannot
|
||||||
|
use both them and the Library together in an executable that you
|
||||||
|
distribute.
|
||||||
|
|
||||||
|
7. You may place library facilities that are a work based on the
|
||||||
|
Library side-by-side in a single library together with other library
|
||||||
|
facilities not covered by this License, and distribute such a combined
|
||||||
|
library, provided that the separate distribution of the work based on
|
||||||
|
the Library and of the other library facilities is otherwise
|
||||||
|
permitted, and provided that you do these two things:
|
||||||
|
|
||||||
|
a) Accompany the combined library with a copy of the same work
|
||||||
|
based on the Library, uncombined with any other library
|
||||||
|
facilities. This must be distributed under the terms of the
|
||||||
|
Sections above.
|
||||||
|
|
||||||
|
b) Give prominent notice with the combined library of the fact
|
||||||
|
that part of it is a work based on the Library, and explaining
|
||||||
|
where to find the accompanying uncombined form of the same work.
|
||||||
|
|
||||||
|
8. You may not copy, modify, sublicense, link with, or distribute
|
||||||
|
the Library except as expressly provided under this License. Any
|
||||||
|
attempt otherwise to copy, modify, sublicense, link with, or
|
||||||
|
distribute the Library is void, and will automatically terminate your
|
||||||
|
rights under this License. However, parties who have received copies,
|
||||||
|
or rights, from you under this License will not have their licenses
|
||||||
|
terminated so long as such parties remain in full compliance.
|
||||||
|
|
||||||
|
9. You are not required to accept this License, since you have not
|
||||||
|
signed it. However, nothing else grants you permission to modify or
|
||||||
|
distribute the Library or its derivative works. These actions are
|
||||||
|
prohibited by law if you do not accept this License. Therefore, by
|
||||||
|
modifying or distributing the Library (or any work based on the
|
||||||
|
Library), you indicate your acceptance of this License to do so, and
|
||||||
|
all its terms and conditions for copying, distributing or modifying
|
||||||
|
the Library or works based on it.
|
||||||
|
|
||||||
|
10. Each time you redistribute the Library (or any work based on the
|
||||||
|
Library), the recipient automatically receives a license from the
|
||||||
|
original licensor to copy, distribute, link with or modify the Library
|
||||||
|
subject to these terms and conditions. You may not impose any further
|
||||||
|
restrictions on the recipients' exercise of the rights granted herein.
|
||||||
|
You are not responsible for enforcing compliance by third parties with
|
||||||
|
this License.
|
||||||
|
|
||||||
|
11. If, as a consequence of a court judgment or allegation of patent
|
||||||
|
infringement or for any other reason (not limited to patent issues),
|
||||||
|
conditions are imposed on you (whether by court order, agreement or
|
||||||
|
otherwise) that contradict the conditions of this License, they do not
|
||||||
|
excuse you from the conditions of this License. If you cannot
|
||||||
|
distribute so as to satisfy simultaneously your obligations under this
|
||||||
|
License and any other pertinent obligations, then as a consequence you
|
||||||
|
may not distribute the Library at all. For example, if a patent
|
||||||
|
license would not permit royalty-free redistribution of the Library by
|
||||||
|
all those who receive copies directly or indirectly through you, then
|
||||||
|
the only way you could satisfy both it and this License would be to
|
||||||
|
refrain entirely from distribution of the Library.
|
||||||
|
|
||||||
|
If any portion of this section is held invalid or unenforceable under any
|
||||||
|
particular circumstance, the balance of the section is intended to apply,
|
||||||
|
and the section as a whole is intended to apply in other circumstances.
|
||||||
|
|
||||||
|
It is not the purpose of this section to induce you to infringe any
|
||||||
|
patents or other property right claims or to contest validity of any
|
||||||
|
such claims; this section has the sole purpose of protecting the
|
||||||
|
integrity of the free software distribution system which is
|
||||||
|
implemented by public license practices. Many people have made
|
||||||
|
generous contributions to the wide range of software distributed
|
||||||
|
through that system in reliance on consistent application of that
|
||||||
|
system; it is up to the author/donor to decide if he or she is willing
|
||||||
|
to distribute software through any other system and a licensee cannot
|
||||||
|
impose that choice.
|
||||||
|
|
||||||
|
This section is intended to make thoroughly clear what is believed to
|
||||||
|
be a consequence of the rest of this License.
|
||||||
|
|
||||||
|
12. If the distribution and/or use of the Library is restricted in
|
||||||
|
certain countries either by patents or by copyrighted interfaces, the
|
||||||
|
original copyright holder who places the Library under this License may add
|
||||||
|
an explicit geographical distribution limitation excluding those countries,
|
||||||
|
so that distribution is permitted only in or among countries not thus
|
||||||
|
excluded. In such case, this License incorporates the limitation as if
|
||||||
|
written in the body of this License.
|
||||||
|
|
||||||
|
13. The Free Software Foundation may publish revised and/or new
|
||||||
|
versions of the Lesser General Public License from time to time.
|
||||||
|
Such new versions will be similar in spirit to the present version,
|
||||||
|
but may differ in detail to address new problems or concerns.
|
||||||
|
|
||||||
|
Each version is given a distinguishing version number. If the Library
|
||||||
|
specifies a version number of this License which applies to it and
|
||||||
|
"any later version", you have the option of following the terms and
|
||||||
|
conditions either of that version or of any later version published by
|
||||||
|
the Free Software Foundation. If the Library does not specify a
|
||||||
|
license version number, you may choose any version ever published by
|
||||||
|
the Free Software Foundation.
|
||||||
|
|
||||||
|
14. If you wish to incorporate parts of the Library into other free
|
||||||
|
programs whose distribution conditions are incompatible with these,
|
||||||
|
write to the author to ask for permission. For software which is
|
||||||
|
copyrighted by the Free Software Foundation, write to the Free
|
||||||
|
Software Foundation; we sometimes make exceptions for this. Our
|
||||||
|
decision will be guided by the two goals of preserving the free status
|
||||||
|
of all derivatives of our free software and of promoting the sharing
|
||||||
|
and reuse of software generally.
|
||||||
|
|
||||||
|
NO WARRANTY
|
||||||
|
|
||||||
|
15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO
|
||||||
|
WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW.
|
||||||
|
EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
|
||||||
|
OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY
|
||||||
|
KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE
|
||||||
|
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||||
|
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE
|
||||||
|
LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME
|
||||||
|
THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||||
|
|
||||||
|
16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN
|
||||||
|
WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY
|
||||||
|
AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU
|
||||||
|
FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR
|
||||||
|
CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE
|
||||||
|
LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING
|
||||||
|
RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A
|
||||||
|
FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF
|
||||||
|
SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH
|
||||||
|
DAMAGES.
|
||||||
|
|
||||||
|
END OF TERMS AND CONDITIONS
|
||||||
|
|
||||||
|
How to Apply These Terms to Your New Libraries
|
||||||
|
|
||||||
|
If you develop a new library, and you want it to be of the greatest
|
||||||
|
possible use to the public, we recommend making it free software that
|
||||||
|
everyone can redistribute and change. You can do so by permitting
|
||||||
|
redistribution under these terms (or, alternatively, under the terms of the
|
||||||
|
ordinary General Public License).
|
||||||
|
|
||||||
|
To apply these terms, attach the following notices to the library. It is
|
||||||
|
safest to attach them to the start of each source file to most effectively
|
||||||
|
convey the exclusion of warranty; and each file should have at least the
|
||||||
|
"copyright" line and a pointer to where the full notice is found.
|
||||||
|
|
||||||
|
<one line to give the library's name and a brief idea of what it does.>
|
||||||
|
Copyright (C) <year> <name of author>
|
||||||
|
|
||||||
|
This library is free software; you can redistribute it and/or
|
||||||
|
modify it under the terms of the GNU Lesser General Public
|
||||||
|
License as published by the Free Software Foundation; either
|
||||||
|
version 2.1 of the License, or (at your option) any later version.
|
||||||
|
|
||||||
|
This library is distributed in the hope that it will be useful,
|
||||||
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
Lesser General Public License for more details.
|
||||||
|
|
||||||
|
You should have received a copy of the GNU Lesser General Public
|
||||||
|
License along with this library; if not, write to the Free Software
|
||||||
|
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||||
|
|
||||||
|
Also add information on how to contact you by electronic and paper mail.
|
||||||
|
|
||||||
|
You should also get your employer (if you work as a programmer) or your
|
||||||
|
school, if any, to sign a "copyright disclaimer" for the library, if
|
||||||
|
necessary. Here is a sample; alter the names:
|
||||||
|
|
||||||
|
Yoyodyne, Inc., hereby disclaims all copyright interest in the
|
||||||
|
library `Frob' (a library for tweaking knobs) written by James Random Hacker.
|
||||||
|
|
||||||
|
<signature of Ty Coon>, 1 April 1990
|
||||||
|
Ty Coon, President of Vice
|
||||||
|
|
||||||
|
That's all there is to it!
|
||||||
|
|
||||||
|
-----
|
||||||
|
In addition, as a special exception, the copyright holders give
|
||||||
|
permission to link the code of portions of this program with the
|
||||||
|
OpenSSL library under certain conditions as described in each
|
||||||
|
individual source file, and distribute linked combinations
|
||||||
|
including the two.
|
||||||
|
|
||||||
|
You must obey the GNU Lesser General Public License in all respects
|
||||||
|
for all of the code used other than OpenSSL. If you modify
|
||||||
|
file(s) with this exception, you may extend this exception to your
|
||||||
|
version of the file(s), but you are not obligated to do so. If you
|
||||||
|
do not wish to do so, delete this exception statement from your
|
||||||
|
version. If you delete this exception statement from all source
|
||||||
|
files in the program, then also delete it here.
|
||||||
783
ChangeLog
783
ChangeLog
@@ -1,781 +1,6 @@
|
|||||||
2011-10-25 Milan Broz <mbroz@redhat.com>
|
Since version 1.6 this file is no longer maintained.
|
||||||
* Print informative message in isLuks only in verbose mode.
|
|
||||||
* Version 1.4.0.
|
|
||||||
|
|
||||||
2011-10-10 Milan Broz <mbroz@redhat.com>
|
See docs/*ReleaseNotes for release changes documentation.
|
||||||
* Version 1.4.0-rc1.
|
|
||||||
|
|
||||||
2011-10-05 Milan Broz <mbroz@redhat.com>
|
See version control history for full commit messages.
|
||||||
* Support Nettle 2.4 crypto backend (for ripemd160).
|
https://gitlab.com/cryptsetup/cryptsetup/commits/master
|
||||||
* If device is not rotational, do not use Gutmann wipe method.
|
|
||||||
* Add crypt_last_error() API call.
|
|
||||||
* Fix luksKillSLot exit code if slot is inactive or invalid.
|
|
||||||
* Fix exit code if passphrases do not match in luksAddKey.
|
|
||||||
* Add LUKS on-disk format description into package.
|
|
||||||
|
|
||||||
2011-09-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Support key-slot option for luksOpen (use only explicit keyslot).
|
|
||||||
|
|
||||||
2011-08-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add more paranoid checks for LUKS header and keyslot attributes.
|
|
||||||
* Fix crypt_load to properly check device size.
|
|
||||||
* Use new /dev/loop-control (kernel 3.1) if possible.
|
|
||||||
* Enhance check of device size before writing LUKS header.
|
|
||||||
* Do not allow context format of already formatted device.
|
|
||||||
|
|
||||||
2011-07-25 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Remove hash/hmac restart from crypto backend and make it part of hash/hmac final.
|
|
||||||
* Improve check for invalid offset and size values.
|
|
||||||
|
|
||||||
2011-07-19 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Revert default initialisation of volume key in crypt_init_by_name().
|
|
||||||
* Do not allow key retrieval while suspended (key could be wiped).
|
|
||||||
* Do not allow suspend for non-LUKS devices.
|
|
||||||
* Support retries and timeout parameters for luksSuspend.
|
|
||||||
* Add --header option for detached metadata (on-disk LUKS header) device.
|
|
||||||
* Add crypt_init_by_name_and_header() and crypt_set_data_device() to API.
|
|
||||||
* Allow different data offset setting for detached header.
|
|
||||||
|
|
||||||
2011-07-07 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Remove old API functions (all functions using crypt_options).
|
|
||||||
* Add --enable-discards option to allow discards/TRIM requests.
|
|
||||||
* Add crypt_get_iv_offset() function to API.
|
|
||||||
|
|
||||||
2011-07-01 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add --shared option for creating non-overlapping crypt segments.
|
|
||||||
* Add shared flag to libcryptsetup api.
|
|
||||||
* Fix plain crypt format parameters to include size option (API change).
|
|
||||||
|
|
||||||
2011-06-08 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix return code for status command when device doesn't exists.
|
|
||||||
|
|
||||||
2011-05-24 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.3.1.
|
|
||||||
|
|
||||||
2011-05-17 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix keyfile=- processing in create command (1.3.0).
|
|
||||||
* Simplify device path status check.
|
|
||||||
|
|
||||||
2011-05-03 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Do not ignore size argument for create command (1.2.0).
|
|
||||||
|
|
||||||
2011-04-18 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix error paths in blockwise code and lseek_write call.
|
|
||||||
* Add Nettle crypto backend support.
|
|
||||||
|
|
||||||
2011-04-05 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.3.0.
|
|
||||||
|
|
||||||
2011-03-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Also support --skip and --hash option for loopaesOpen.
|
|
||||||
* Fix return code when passphrase is read from pipe.
|
|
||||||
* Document cryptsetup exit codes.
|
|
||||||
|
|
||||||
2011-03-18 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Respect maximum keyfile size paramater.
|
|
||||||
* Introduce maximum default keyfile size, add configure option.
|
|
||||||
* Require the whole key read from keyfile in create command (broken in 1.2.0).
|
|
||||||
* Fix offset option for loopaesOpen.
|
|
||||||
* Lock memory also in luksDump command.
|
|
||||||
* Version 1.3.0-rc2.
|
|
||||||
|
|
||||||
2011-03-14 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.3.0-rc1.
|
|
||||||
|
|
||||||
2011-03-11 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add loop manipulation code and support mapping of images in file.
|
|
||||||
* Add backing device loop info into status message.
|
|
||||||
* Add luksChangeKey command.
|
|
||||||
|
|
||||||
2011-03-05 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add exception to COPYING for binary distribution linked with OpenSSL library.
|
|
||||||
* Set secure data flag (wipe all ioclt buffers) if devmapper library supports it.
|
|
||||||
|
|
||||||
2011-01-29 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix mapping removal if device disappeared but node still exists.
|
|
||||||
* Fix luksAddKey return code if master key is used.
|
|
||||||
|
|
||||||
2011-01-25 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add loop-AES handling (loopaesOpen and loopaesClose commands).
|
|
||||||
(requires kernel 2.6.38 and above)
|
|
||||||
|
|
||||||
2011-01-05 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix static build (--disable-static-cryptsetup now works properly).
|
|
||||||
|
|
||||||
2010-12-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add compile time crypto backends implementation
|
|
||||||
(gcrypt, OpenSSL, NSS and userspace Linux kernel crypto api).
|
|
||||||
* Currently NSS is lacking ripemd160, cannot provide full plain compatibility.
|
|
||||||
* Use --with-crypto_backend=[gcrypt|openssl|nss|kernel] to configure.
|
|
||||||
|
|
||||||
2010-12-20 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.2.0.
|
|
||||||
|
|
||||||
2010-11-25 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix crypt_activate_by_keyfile() to work with PLAIN devices.
|
|
||||||
* Fix create command to properly handle keyfile size.
|
|
||||||
|
|
||||||
2010-11-16 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.2.0-rc1.
|
|
||||||
|
|
||||||
2010-11-13 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix password callback call.
|
|
||||||
* Fix default plain password entry from terminal in activate_by_passphrase.
|
|
||||||
* Add --dump-master-key option for luksDump to allow volume key dump.
|
|
||||||
* Allow to activate by internally cached volume key
|
|
||||||
(format/activate without keyslots active - used for temporary devices).
|
|
||||||
* Initialize volume key from active device in crypt_init_by_name()
|
|
||||||
* Fix cryptsetup binary exitcodes.
|
|
||||||
* Increase library version (still binary compatible with 1.1.x release).
|
|
||||||
|
|
||||||
2010-11-01 Milan Broz <mbroz@redhat.com>
|
|
||||||
* No longer support luksDelKey, reload and --non-exclusive.
|
|
||||||
* Remove some obsolete info from man page.
|
|
||||||
* Add crypt_get_type(), crypt_resize(), crypt_keyslot_max()
|
|
||||||
and crypt_get_active_device() to API.
|
|
||||||
* Rewrite all implementations in cryptsetup to new API.
|
|
||||||
* Fix luksRemoveKey to behave as documented (do not ask
|
|
||||||
for remaining keyslot passphrase).
|
|
||||||
* Add more regression tests for commands.
|
|
||||||
* Disallow mapping of device which is already in use (mapped or mounted).
|
|
||||||
* Disallow luksFormat on device in use.
|
|
||||||
|
|
||||||
2010-10-27 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Rewrite cryptsetup luksFormat, luksOpen, luksAddKey to use new API
|
|
||||||
to allow adding new features.
|
|
||||||
* Implement --use-random and --use-urandom for luksFormat to allow
|
|
||||||
setting of RNG for volume key generator.
|
|
||||||
* Add crypt_set_rng_type() and crypt_get_rng_type() to API.
|
|
||||||
* Add crypt_set_uuid() to API.
|
|
||||||
* Allow UUID setting in luksFormat and luksUUID (--uuid parameter).
|
|
||||||
* Add --keyfile-size and --new-keyfile-size (in bytes) size and disallow overloading
|
|
||||||
of --key-size for limiting keyfile reads.
|
|
||||||
* Fix luksFormat to properly use key file with --master-key-file switch.
|
|
||||||
* Fix possible double free when handling master key file.
|
|
||||||
|
|
||||||
2010-10-17 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add crypt_get_device_name() to API (get underlying device name).
|
|
||||||
* Change detection for static libraries.
|
|
||||||
* Fix pkg-config use in automake scripts.
|
|
||||||
* Remove --disable-shared-library switch and handle static library build
|
|
||||||
by common libtool logic (using --enable-static).
|
|
||||||
* Add --enable-static-cryptsetup option to build cryptsetup.static binary
|
|
||||||
together with shared build.
|
|
||||||
|
|
||||||
2010-08-05 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Wipe iteration and salt after KillSlot in LUKS header.
|
|
||||||
* Rewrite file differ test to C (and fix it to really work).
|
|
||||||
* Switch to 1MiB default alignment of data.
|
|
||||||
For more info see https://bugzilla.redhat.com/show_bug.cgi?id=621684
|
|
||||||
* Do not query non-existent device twice (cryptsetup status /dev/nonexistent).
|
|
||||||
* Check if requested hash is supported before writing LUKS header.
|
|
||||||
|
|
||||||
2010-07-28 Arno Wagner <arno@wagner.name>
|
|
||||||
* Add FAQ (Frequently Asked Questions) file to distribution.
|
|
||||||
|
|
||||||
2010-07-03 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix udev support for old libdevmapper with not compatible definition.
|
|
||||||
* Version 1.1.3.
|
|
||||||
|
|
||||||
2010-06-01 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix device alignment ioctl calls parameters.
|
|
||||||
* Fix activate_by_* API calls to handle NULL device name as documented.
|
|
||||||
|
|
||||||
2010-05-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Version 1.1.2.
|
|
||||||
|
|
||||||
2010-05-27 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix luksFormat/luksOpen reading passphrase from stdin and "-" keyfile.
|
|
||||||
* Support --key-file/-d option for luksFormat.
|
|
||||||
* Fix description of --key-file and add --verbose and --debug options to man page.
|
|
||||||
* Add verbose log level and move unlocking message there.
|
|
||||||
* Remove device even if underlying device disappeared.
|
|
||||||
* Fix (deprecated) reload device command to accept new device argument.
|
|
||||||
|
|
||||||
2010-05-23 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix luksClose operation for stacked DM devices.
|
|
||||||
* Version 1.1.1.
|
|
||||||
|
|
||||||
2010-05-03 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix automatic dm-crypt module loading.
|
|
||||||
* Escape hyphens in man page.
|
|
||||||
* Version 1.1.1-rc2.
|
|
||||||
|
|
||||||
2010-04-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Try to use pkgconfig for device mapper library.
|
|
||||||
* Detect old dm-crypt module and disable LUKS suspend/resume.
|
|
||||||
* Fix apitest to work on older systems.
|
|
||||||
* Allow no hash specification in plain device constructor.
|
|
||||||
* Fix luksOpen reading of passphrase on stdin (if "-" keyfile specified).
|
|
||||||
* Fix isLuks to initialise crypto backend (blkid instead is suggested anyway).
|
|
||||||
* Version 1.1.1-rc1.
|
|
||||||
|
|
||||||
2010-04-12 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix package config to use proper package version.
|
|
||||||
* Avoid class C++ keyword in library header.
|
|
||||||
* Detect and use devmapper udev support if available (disable by --disable-udev).
|
|
||||||
|
|
||||||
2010-04-06 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Prefer some device paths in status display.
|
|
||||||
* Support device topology detectionfor data alignment.
|
|
||||||
|
|
||||||
2010-02-25 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Do not verify unlocking passphrase in luksAddKey command.
|
|
||||||
* Properly initialise crypto backend in header backup/restore commands.
|
|
||||||
|
|
||||||
2010-01-17 Milan Broz <mbroz@redhat.com>
|
|
||||||
* If gcrypt compiled with capabilities, document workaround for cryptsetup (see lib/gcrypt.c).
|
|
||||||
* Version 1.1.0.
|
|
||||||
|
|
||||||
2010-01-10 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix initialisation of gcrypt duting luksFormat.
|
|
||||||
* Convert hash name to lower case in header (fix sha1 backward comatible header)
|
|
||||||
* Check for minimum required gcrypt version.
|
|
||||||
|
|
||||||
2009-12-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix key slot iteration count calculation (small -i value was the same as default).
|
|
||||||
* The slot and key digest iteration minimun is now 1000.
|
|
||||||
* The key digest iteration # is calculated from iteration time (approx 1/8 of that).
|
|
||||||
* Version 1.1.0-rc4.
|
|
||||||
|
|
||||||
2009-12-11 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix error handling during reading passhrase.
|
|
||||||
|
|
||||||
2009-12-01 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Allow changes of default compiled-in cipher parameters through configure.
|
|
||||||
* Switch default key size for LUKS to 256bits.
|
|
||||||
* Switch default plain mode to aes-cbc-essiv:sha256 (default is backward incompatible!).
|
|
||||||
|
|
||||||
2009-11-14 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add CRYPT_ prefix to enum defined in libcryptsetup.h.
|
|
||||||
* Fix status call to fail when running as non-root user.
|
|
||||||
* Check in configure if selinux libraries are required in static version.
|
|
||||||
* Add temporary debug code to find processes locking internal device.
|
|
||||||
* Simplify build system, use autopoint and clean gettext processing.
|
|
||||||
* Use proper NLS macros and detection (so the message translation works again).
|
|
||||||
* Version 1.1.0-rc3.
|
|
||||||
|
|
||||||
2009-09-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix exported symbols and versions in libcryptsetup.
|
|
||||||
* Do not use internal lib functions in cryptsetup.
|
|
||||||
* Add crypt_log to library.
|
|
||||||
* Fix crypt_remove_device (remove, luksClose) implementation.
|
|
||||||
* Move dm backend initialisation to library calls.
|
|
||||||
* Move duplicate Command failed message to verbose level (error is printed always).
|
|
||||||
* Add some password and used algorithms notes to man page.
|
|
||||||
* Version 1.1.0-rc2.
|
|
||||||
|
|
||||||
2009-09-28 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add luksHeaderBackup and luksHeaderRestore commands.
|
|
||||||
* Fail passphrase read if piped input no longer exists.
|
|
||||||
* Version 1.1.0-rc1.
|
|
||||||
|
|
||||||
2009-09-15 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Initialize crypto library before LUKS header load.
|
|
||||||
* Fix manpage to not require --size which expands to device size by default.
|
|
||||||
|
|
||||||
2009-09-10 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Clean up Makefiles and configure script.
|
|
||||||
* Version 1.1.0-test0.
|
|
||||||
|
|
||||||
2009-09-08 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Use dm-uuid for all crypt devices, contains device type and name now.
|
|
||||||
* Try to read first sector from device to properly check that device is ready.
|
|
||||||
|
|
||||||
2009-09-02 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Add luksSuspend (freeze device and wipe key) and luksResume (with provided passphrase).
|
|
||||||
|
|
||||||
2009-08-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Require device device-mapper to build and do not use backend wrapper for dm calls.
|
|
||||||
* Move memory locking and dm initialization to command layer.
|
|
||||||
* Increase priority of process if memory is locked.
|
|
||||||
* Add log macros and make logging modre consitent.
|
|
||||||
* Move command successful messages to verbose level.
|
|
||||||
* Introduce --debug parameter.
|
|
||||||
* Move device utils code and provide context parameter (for log).
|
|
||||||
* Keyfile now must be provided by path, only stdin file descriptor is used (api only).
|
|
||||||
* Do not call isatty() on closed keyfile descriptor.
|
|
||||||
* Run performance check for PBKDF2 from LUKS code, do not mix hash algoritms results.
|
|
||||||
* Add ability to provide pre-generated master key and UUID in LUKS header format.
|
|
||||||
* Add LUKS function to verify master key digest.
|
|
||||||
* Move key slot manuipulation function into LUKS specific code.
|
|
||||||
* Replace global options struct with separate parameters in helper functions.
|
|
||||||
* Add new libcryptsetup API (documented in libcryptsetup.h).
|
|
||||||
* Implement old API calls using new functions.
|
|
||||||
* Remove old API code helper functions.
|
|
||||||
* Add --master-key-file option for luksFormat and luksAddKey.
|
|
||||||
|
|
||||||
2009-08-17 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix PBKDF2 speed calculation for large passhrases.
|
|
||||||
* Allow using passphrase provided in options struct for LuksOpen.
|
|
||||||
* Allow restrict keys size in LuksOpen.
|
|
||||||
|
|
||||||
2009-07-30 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix errors when compiled with LUKS_DEBUG.
|
|
||||||
* Print error when getline fails.
|
|
||||||
* Remove po/cryptsetup-luks.pot, it's autogenerated.
|
|
||||||
* Return ENOENT for empty keyslots, EINVAL will be used later for other type of error.
|
|
||||||
* Switch PBKDF2 from internal SHA1 to libgcrypt, make hash algorithm not hardcoded to SHA1 here.
|
|
||||||
* Add required parameters for changing hash used in LUKS key setup scheme.
|
|
||||||
* Do not export simple XOR helper now used only inside AF functions.
|
|
||||||
* Completely remove internal SHA1 implementanion code, not needed anymore.
|
|
||||||
* Enable hash algorithm selection for LUKS through -h luksFormat option.
|
|
||||||
|
|
||||||
2009-07-28 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Pad luks header to 512 sector size.
|
|
||||||
* Rework read/write blockwise to not split operation to many pieces.
|
|
||||||
* Use posix_memalign if available.
|
|
||||||
|
|
||||||
2009-07-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Fix segfault if provided slot in luksKillslot is invalid.
|
|
||||||
* Remove unneeded timeout when remove of temporary device succeeded.
|
|
||||||
|
|
||||||
2009-07-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
* version 1.0.7
|
|
||||||
|
|
||||||
2009-07-16 Milan Broz <mbroz@redhat.com>
|
|
||||||
* Allow removal of last slot in luksRemoveKey and luksKillSlot.
|
|
||||||
|
|
||||||
2009-07-11 Milan Broz <mbroz@redhat.com>
|
|
||||||
|
|
||||||
* Add --disable-selinux option and fix static build if selinux is required.
|
|
||||||
* Reject unsupported --offset and --skip options for luksFormat and update man page.
|
|
||||||
|
|
||||||
2009-06-22 Milan Broz <mbroz@redhat.com>
|
|
||||||
|
|
||||||
* Summary of changes in subversion for 1.0.7-rc1:
|
|
||||||
* Various man page fixes.
|
|
||||||
* Set UUID in device-mapper for LUKS devices.
|
|
||||||
* Retain readahead of underlying device.
|
|
||||||
* Display device name when asking for password.
|
|
||||||
* Check device size when loading LUKS header. Remove misleading error message later.
|
|
||||||
* Add error hint if dm-crypt mapping failed.
|
|
||||||
* Use better error messages if device doesn't exist or is already used by other mapping.
|
|
||||||
* Fix make distcheck.
|
|
||||||
* Check if all slots are full during luksAddKey.
|
|
||||||
* Fix segfault in set_error.
|
|
||||||
* Code cleanups, remove precompiled pot files, remove unnecessary files from po directory
|
|
||||||
* Fix uninitialized return value variable in setup.c.
|
|
||||||
* Code cleanups. (thanks to Ivan Stankovic)
|
|
||||||
* Fix wrong output for remaining key at key deletion.
|
|
||||||
* Allow deletion of key slot while other keys have the same key information.
|
|
||||||
* Add missing AM_PROG_CC_C_O to configure.in
|
|
||||||
* Remove duplicate sentence in man page.
|
|
||||||
* Wipe start of device (possible fs signature) before LUKS-formatting.
|
|
||||||
* Do not process configure.in in hidden directories.
|
|
||||||
* Return more descriptive error in case of IO or header format error.
|
|
||||||
* Use remapping to error target instead of calling udevsettle for temporary crypt device.
|
|
||||||
* Check device mapper communication and warn user if device-mapper support missing in kernel.
|
|
||||||
* Fix signal handler to properly close device.
|
|
||||||
* write_lseek_blockwise: declare innerCount outside the if block.
|
|
||||||
* add -Wall to the default CFLAGS. fix some signedness issues.
|
|
||||||
* Error handling improvement.
|
|
||||||
* Add non-exclusive override to interface definition.
|
|
||||||
* Refactor key slot selection into keyslot_from_option.
|
|
||||||
|
|
||||||
2007-05-01 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/backends.c, man/cryptsetup.8: Apply patch from Ludwig Nussel
|
|
||||||
<ludwig.nussel@suse.de>, for old SuSE compat hashing.
|
|
||||||
|
|
||||||
2007-04-16 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Summary of changes in subversion:
|
|
||||||
Fix segfault for key size > 32 bytes.
|
|
||||||
Kick ancient header version conversion.
|
|
||||||
Fix http://bugs.debian.org/403075
|
|
||||||
No passwort retrying for I/O errors.
|
|
||||||
Fix hang on "-i 0".
|
|
||||||
Fix parenthesization error that prevented --tries from working
|
|
||||||
correctly.
|
|
||||||
|
|
||||||
2006-11-28 gettextize <bug-gnu-gettext@gnu.org>
|
|
||||||
|
|
||||||
* m4/gettext.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/glibc2.m4: New file, from gettext-0.15.
|
|
||||||
* m4/intmax.m4: New file, from gettext-0.15.
|
|
||||||
* m4/inttypes-h.m4: New file, from gettext-0.15.
|
|
||||||
* m4/inttypes-pri.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/lib-link.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/lib-prefix.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/lock.m4: New file, from gettext-0.15.
|
|
||||||
* m4/longdouble.m4: New file, from gettext-0.15.
|
|
||||||
* m4/longlong.m4: New file, from gettext-0.15.
|
|
||||||
* m4/nls.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/po.m4: Upgrade to gettext-0.15.
|
|
||||||
* m4/printf-posix.m4: New file, from gettext-0.15.
|
|
||||||
* m4/signed.m4: New file, from gettext-0.15.
|
|
||||||
* m4/size_max.m4: New file, from gettext-0.15.
|
|
||||||
* m4/visibility.m4: New file, from gettext-0.15.
|
|
||||||
* m4/wchar_t.m4: New file, from gettext-0.15.
|
|
||||||
* m4/wint_t.m4: New file, from gettext-0.15.
|
|
||||||
* m4/xsize.m4: New file, from gettext-0.15.
|
|
||||||
* m4/Makefile.am: New file.
|
|
||||||
* configure.in (AC_OUTPUT): Add m4/Makefile.
|
|
||||||
(AM_GNU_GETTEXT_VERSION): Bump to 0.15.
|
|
||||||
|
|
||||||
2006-10-22 David Härdeman <david@hardeman.nu>
|
|
||||||
|
|
||||||
* Allow hashing of keys passed through stdin.
|
|
||||||
|
|
||||||
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: 1.0.4 release
|
|
||||||
|
|
||||||
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* man/cryptsetup.8: Document --tries switch; patch by Jonas
|
|
||||||
Meurer.
|
|
||||||
|
|
||||||
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c: Added terminal timeout rewrite as forwarded by
|
|
||||||
Jonas Meurer
|
|
||||||
|
|
||||||
2006-10-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Merged patch from Marc Merlin <marc@merlins.org> to allow user
|
|
||||||
selection of key slot.
|
|
||||||
|
|
||||||
2006-09-26 gettextize <bug-gnu-gettext@gnu.org>
|
|
||||||
|
|
||||||
* m4/codeset.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/gettext.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/glibc2.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/glibc21.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/iconv.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/intdiv0.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/intmax.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/inttypes.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/inttypes_h.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/inttypes-pri.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/isc-posix.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/lcmessage.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/lib-ld.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/lib-link.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/lib-prefix.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/longdouble.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/longlong.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/nls.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/po.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/printf-posix.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/progtest.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/signed.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/size_max.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/stdint_h.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/uintmax_t.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/ulonglong.m4: Upgrade to gettext-0.14.4.
|
|
||||||
* m4/wchar_t.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/wint_t.m4: New file, from gettext-0.14.4.
|
|
||||||
* m4/xsize.m4: New file, from gettext-0.14.4.
|
|
||||||
* Makefile.am (ACLOCAL_AMFLAGS): New variable.
|
|
||||||
* configure.in (AM_GNU_GETTEXT_VERSION): Bump to 0.14.4.
|
|
||||||
|
|
||||||
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: 1.0.4-rc2
|
|
||||||
|
|
||||||
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/Makefile.am: Add a few regression tests
|
|
||||||
|
|
||||||
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (get_key): Applied patch from David Härdeman
|
|
||||||
<david@2gen.com> for reading binary keys from stdin using
|
|
||||||
the "-" as key file.
|
|
||||||
|
|
||||||
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (__crypt_luks_add_key): For checking options struct
|
|
||||||
(optionsCheck) filter out CRYPT_FLAG_VERIFY and
|
|
||||||
CRYPT_FLAG_VERIFY_IF_POSSIBLE, so that in no case password verification is done
|
|
||||||
for password retrieval.
|
|
||||||
|
|
||||||
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: Merge Patch from http://bugs.gentoo.org/show_bug.cgi?id=132126 for sepol
|
|
||||||
|
|
||||||
2006-07-23 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Applied patches from David Härdeman <david@2gen.com> to fix 64
|
|
||||||
bit compiler warning issues.
|
|
||||||
|
|
||||||
2006-05-19 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Applied patches from Jonas Meurer
|
|
||||||
- fix terminal status after timeout
|
|
||||||
- add remark for --tries to manpage
|
|
||||||
- allow more than 32 chars from standard input.
|
|
||||||
- exit status fix for cryptsetup status.
|
|
||||||
|
|
||||||
2006-05-06 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c (yesDialog): Fix getline problem for 64-bit archs.
|
|
||||||
|
|
||||||
2006-04-05 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: Release 1.0.3.
|
|
||||||
|
|
||||||
* Applied patch by Johannes Weißl for more meaningful exit codes
|
|
||||||
and password retries
|
|
||||||
|
|
||||||
2006-03-30 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (__crypt_create_device): (char *) -> (const char *)
|
|
||||||
|
|
||||||
2006-03-30 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Apply alignPayload patch from Peter Palfrader <weasel@debian.org>
|
|
||||||
|
|
||||||
2006-03-15 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: 1.0.3-rc3. Most unplease release ever.
|
|
||||||
* lib/setup.c (__crypt_create_device): More verbose error message.
|
|
||||||
|
|
||||||
2006-02-26 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c: Revert to 1.0.1 key reading.
|
|
||||||
|
|
||||||
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* man/cryptsetup.8: merge patch from Jonas Meurer
|
|
||||||
|
|
||||||
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: 1.0.3-rc2
|
|
||||||
|
|
||||||
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/libdevmapper.c (dm_create_device): Remove dup check here.
|
|
||||||
* lib/setup.c (__crypt_luks_open): Adopt same dup check as regular
|
|
||||||
create command.
|
|
||||||
|
|
||||||
2006-02-22 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: Spin 1.0.3-rc1
|
|
||||||
|
|
||||||
2006-02-22 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c (action_create): Change defaulting.
|
|
||||||
(action_luksFormat): Change defaulting.
|
|
||||||
|
|
||||||
* lib/setup.c (parse_into_name_and_mode): Revert that default
|
|
||||||
change. This is FORBIDDEN here, as it will change cryptsetup
|
|
||||||
entire default. This is BAD in a non-LUKS world.
|
|
||||||
|
|
||||||
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/keyencryption.c (setup_mapping): Add proper size restriction to mapping.
|
|
||||||
(LUKS_endec_template): Add more verbose error message.
|
|
||||||
|
|
||||||
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/libdevmapper.c (dm_query_device): Incorporate patch from
|
|
||||||
Bastian Blank
|
|
||||||
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344313
|
|
||||||
|
|
||||||
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c: Rename show_error -> show_status.
|
|
||||||
|
|
||||||
2006-02-20 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/libdevmapper.c (dm_create_device): Prevent existing mapping
|
|
||||||
from being removed when a mapping with the same name is added
|
|
||||||
|
|
||||||
* Add timeout patch from Jonas Meurer
|
|
||||||
|
|
||||||
* src/cryptsetup.c: Remove conditional error printing to enable
|
|
||||||
printing the no-error msg (Command successful). Verify passphrase
|
|
||||||
for LUKS volumes.
|
|
||||||
(main): Add no-verify-passphrase
|
|
||||||
|
|
||||||
* lib/setup.c (parse_into_name_and_mode): Change default mode complition to essiv:sha256.
|
|
||||||
|
|
||||||
2006-01-04 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c (help): Merge patch from Gentoo: change gettext(..) to _(..).
|
|
||||||
|
|
||||||
2005-12-06 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* man/cryptsetup.8: Correct "seconds" to "microseconds" in the explaination for -i.
|
|
||||||
|
|
||||||
2005-11-09 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c (main): Add version string.
|
|
||||||
|
|
||||||
2005-11-08 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/backends.c: compile fix.
|
|
||||||
|
|
||||||
2005-09-11 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (get_key): Fixed another incompatibility from my
|
|
||||||
get_key rewrite with original cryptsetup.
|
|
||||||
|
|
||||||
2005-09-11 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Merged changes from Florian Knauf's fk02 branch.
|
|
||||||
|
|
||||||
2005-09-08 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (get_key): Fixed another incompatiblity with
|
|
||||||
original cryptsetup.
|
|
||||||
|
|
||||||
2005-08-20 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* Checked in a patch from Michael Gebetsroither <gebi@sbox.tugraz.at>
|
|
||||||
to silent all confirmation dialogs.
|
|
||||||
|
|
||||||
2005-06-23 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c (help): print PACKAGE_STRING
|
|
||||||
|
|
||||||
2005-06-20 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/keymanage.c (LUKS_set_key): Security check against header manipulation
|
|
||||||
|
|
||||||
* src/cryptsetup.c (action_luksDelKey): Safety check in luksDelKey
|
|
||||||
|
|
||||||
* luks/keymanage.c: Changed disk layout generation to align key material to 4k boundaries.
|
|
||||||
(LUKS_is_last_keyslot): Added LUKS_is_last_keyslot function.
|
|
||||||
|
|
||||||
* Applied patch from Bill Nottingham fixing a lot of prototypes.
|
|
||||||
|
|
||||||
* src/cryptsetup.c (action_luksOpen): Add support for -r flag.
|
|
||||||
|
|
||||||
* configure.in: Version bump 1.0.1
|
|
||||||
|
|
||||||
2005-06-16 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (__crypt_luks_open): Remove mem leaking of dmCipherSpec.
|
|
||||||
(get_key): Fix missing zero termination for read string.
|
|
||||||
|
|
||||||
2005-06-12 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/keyencryption.c (setup_mapping): Added CRYPT_FLAG_READONLY in case of O_RDONLY mode
|
|
||||||
|
|
||||||
2005-06-11 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: Version bump 1.0.1-pre
|
|
||||||
|
|
||||||
2005-06-09 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/utils.c: Added write_llseek_blocksize method to support sector wiping on sector_size != 512
|
|
||||||
media
|
|
||||||
|
|
||||||
2005-05-23 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/setup.c (crypt_luksDelKey): Added missing return statement
|
|
||||||
(setup_leave): Added missing return statement
|
|
||||||
|
|
||||||
* luks/keyencryption.c (clear_mapping): Added missing return statement
|
|
||||||
|
|
||||||
2005-05-19 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* lib/utils.c (write_blockwise, read_blockwise): Changed to soft bsize instead of SECTOR_SIZE
|
|
||||||
|
|
||||||
* luks/keymanage.c (wipe): Changed open mode to O_DIRECT | O_SYNC, and changed write
|
|
||||||
to use the blockwise write helper
|
|
||||||
|
|
||||||
2005-04-21 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* man/cryptsetup.8: Corrected an error, thanks to Dick Middleton.
|
|
||||||
|
|
||||||
2005-04-09 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/sha/hmac.c: Add 64 bit bug fix courtesy to
|
|
||||||
Oliver Paukstadt <pstadt@sourcentral.org>.
|
|
||||||
|
|
||||||
* luks/pbkdf.c, luks/keyencryption.c, luks/keymanage.c, luks/af.c: Added a license
|
|
||||||
disclaimer and remove option for "any future GPL versions".
|
|
||||||
|
|
||||||
2005-03-25 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* configure.in: man page Makefile. Version bump 1.0.
|
|
||||||
|
|
||||||
* man/cryptsetup.8: finalize man page and move to section 8.
|
|
||||||
|
|
||||||
* src/cryptsetup.c (action_luksFormat): Add "are you sure" for interactive sessions.
|
|
||||||
|
|
||||||
* lib/setup.c (crypt_luksDump), src/cryptsetup.c: add LUKS dump command
|
|
||||||
|
|
||||||
2005-03-24 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* src/cryptsetup.c, luks/Makefile.am (test), lib/setup.c (setup_enter):
|
|
||||||
rename luksInit to luksFormat
|
|
||||||
|
|
||||||
2005-03-12 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* man/cryptsetup.1: Add man page.
|
|
||||||
|
|
||||||
* lib/setup.c: Remove unneccessary LUKS_write_phdr call, so the
|
|
||||||
phdr is written after passphrase reading, so the user can change
|
|
||||||
his mind, and not have a partial written LUKS header on it's disk.
|
|
||||||
|
|
||||||
2005-02-09 Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
|
|
||||||
* luks/keymanage.c (LUKS_write_phdr): converted argument phdr to
|
|
||||||
pointer, and make a copy of phdr for conversion
|
|
||||||
|
|
||||||
* configure.in: Version dump.
|
|
||||||
|
|
||||||
* luks/keyencryption.c: Convert to read|write_blockwise.
|
|
||||||
|
|
||||||
* luks/keymanage.c: Convert to read|write_blockwise.
|
|
||||||
|
|
||||||
* lib/utils.c: Add read|write_blockwise functions, to use in
|
|
||||||
O_DIRECT file accesses.
|
|
||||||
|
|
||||||
2004-03-11 Thursday 15:52 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* lib/blockdev.h: BLKGETSIZE64 really uses size_t as third
|
|
||||||
argument, the rest is wrong.
|
|
||||||
|
|
||||||
2004-03-10 Wednesday 17:50 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* lib/: libcryptsetup.h, libdevmapper.c: Small fixes.
|
|
||||||
|
|
||||||
2004-03-09 Tuesday 21:41 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* lib/internal.h, lib/libcryptsetup.h, lib/libdevmapper.c,
|
|
||||||
lib/setup.c, po/de.po, src/cryptsetup.c: Added internal flags to
|
|
||||||
keep track of malloc'ed return values in struct crypt_options and
|
|
||||||
add a function to free the memory. Also add a readonly flag to
|
|
||||||
libcryptsetup.
|
|
||||||
|
|
||||||
2004-03-09 Tuesday 16:03 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* ChangeLog, configure.in, setup-gettext, lib/Makefile.am,
|
|
||||||
lib/backends.c, lib/blockdev.h, lib/gcrypt.c, lib/internal.h,
|
|
||||||
lib/libcryptsetup.h, lib/libdevmapper.c, lib/setup.c,
|
|
||||||
lib/utils.c, po/de.po, src/Makefile.am, src/cryptsetup.c: More
|
|
||||||
reorganization work.
|
|
||||||
|
|
||||||
2004-03-08 Monday 01:38 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* ChangeLog, Makefile.am, acinclude.m4, configure.in,
|
|
||||||
lib/Makefile.am, lib/backends.c, lib/blockdev.h, lib/gcrypt.c,
|
|
||||||
lib/libdevmapper.c, lib/setup.c, lib/utils.c, po/de.po,
|
|
||||||
src/Makefile.am: BLKGETSIZE64 fixes and started modularity
|
|
||||||
enhancements
|
|
||||||
|
|
||||||
2004-03-04 Thursday 21:06 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* Makefile.am, po/de.po, src/cryptsetup.c, src/cryptsetup.h: First
|
|
||||||
backward compatible working version.
|
|
||||||
|
|
||||||
2004-03-04 Thursday 00:42 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* NEWS, AUTHORS, ChangeLog, Makefile.am, README, autogen.sh,
|
|
||||||
configure.in, setup-gettext, po/ChangeLog, po/LINGUAS,
|
|
||||||
po/POTFILES.in, po/de.po, src/cryptsetup.c, src/cryptsetup.h,
|
|
||||||
src/Makefile.am (utags: initial): Initial checkin.
|
|
||||||
|
|
||||||
2004-03-04 Thursday 00:42 Christophe Saout <christophe@saout.de>
|
|
||||||
|
|
||||||
* NEWS, AUTHORS, ChangeLog, Makefile.am, README, autogen.sh,
|
|
||||||
configure.in, setup-gettext, po/ChangeLog, po/LINGUAS,
|
|
||||||
po/POTFILES.in, po/de.po, src/cryptsetup.c, src/cryptsetup.h,
|
|
||||||
src/Makefile.am: Initial revision
|
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
EXTRA_DIST = FAQ docs misc
|
EXTRA_DIST = COPYING.LGPL FAQ docs misc
|
||||||
SUBDIRS = \
|
SUBDIRS = \
|
||||||
lib \
|
lib \
|
||||||
src \
|
src \
|
||||||
man \
|
man \
|
||||||
|
python \
|
||||||
tests \
|
tests \
|
||||||
po
|
po
|
||||||
|
|
||||||
|
|||||||
10
README
10
README
@@ -5,11 +5,11 @@ setup cryptographic volumes for dm-crypt (including LUKS extension)
|
|||||||
|
|
||||||
WEB PAGE:
|
WEB PAGE:
|
||||||
|
|
||||||
http://code.google.com/p/cryptsetup/
|
https://gitlab.com/cryptsetup/cryptsetup/
|
||||||
|
|
||||||
FAQ:
|
FAQ:
|
||||||
|
|
||||||
http://code.google.com/p/cryptsetup/wiki/FrequentlyAskedQuestions
|
https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions
|
||||||
|
|
||||||
MAILING LIST:
|
MAILING LIST:
|
||||||
|
|
||||||
@@ -18,12 +18,12 @@ MAILING LIST:
|
|||||||
|
|
||||||
DOWNLOAD:
|
DOWNLOAD:
|
||||||
|
|
||||||
http://code.google.com/p/cryptsetup/downloads/
|
https://www.kernel.org/pub/linux/utils/cryptsetup/
|
||||||
|
|
||||||
SOURCE CODE:
|
SOURCE CODE:
|
||||||
|
|
||||||
URL: http://code.google.com/p/cryptsetup/source/browse/
|
URL: https://gitlab.com/cryptsetup/cryptsetup/tree/master
|
||||||
Checkout: svn checkout http://cryptsetup.googlecode.com/svn/trunk/ cryptsetup
|
Checkout: git clone https://gitlab.com/cryptsetup/cryptsetup.git
|
||||||
|
|
||||||
NLS (PO TRANSLATIONS):
|
NLS (PO TRANSLATIONS):
|
||||||
|
|
||||||
|
|||||||
84
README.md
Normal file
84
README.md
Normal file
@@ -0,0 +1,84 @@
|
|||||||
|

|
||||||
|
|
||||||
|
What the ...?
|
||||||
|
=============
|
||||||
|
**Cryptsetup** is utility used to conveniently setup disk encryption based
|
||||||
|
on [DMCrypt](https://gitlab.com/cryptsetup/cryptsetup/wikis/DMCrypt) kernel module.
|
||||||
|
|
||||||
|
These include **plain** **dm-crypt** volumes, **LUKS** volumes, **loop-AES**
|
||||||
|
and **TrueCrypt** (including **VeraCrypt** extension) format.
|
||||||
|
|
||||||
|
Project also includes **veritysetup** utility used to conveniently setup
|
||||||
|
[DMVerity](https://gitlab.com/cryptsetup/cryptsetup/wikis/DMVerity) block integrity checking kernel module.
|
||||||
|
|
||||||
|
LUKS Design
|
||||||
|
-----------
|
||||||
|
**LUKS** is the standard for Linux hard disk encryption. By providing a standard on-disk-format, it does not
|
||||||
|
only facilitate compatibility among distributions, but also provides secure management of multiple user passwords.
|
||||||
|
In contrast to existing solution, LUKS stores all setup necessary setup information in the partition header,
|
||||||
|
enabling the user to transport or migrate his data seamlessly.
|
||||||
|
|
||||||
|
Why LUKS?
|
||||||
|
---------
|
||||||
|
* compatiblity via standardization,
|
||||||
|
* secure against low entropy attacks,
|
||||||
|
* support for multiple keys,
|
||||||
|
* effective passphrase revocation,
|
||||||
|
* free.
|
||||||
|
|
||||||
|
[Project home page](https://gitlab.com/cryptsetup/cryptsetup/).
|
||||||
|
-----------------
|
||||||
|
|
||||||
|
[Frequently asked questions (FAQ)](https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions)
|
||||||
|
--------------------------------
|
||||||
|
|
||||||
|
Download
|
||||||
|
--------
|
||||||
|
All release tarballs and release notes are hosted on [kernel.org](https://www.kernel.org/pub/linux/utils/cryptsetup/).
|
||||||
|
|
||||||
|
**The latest cryptsetup version is 1.7.1**
|
||||||
|
* [cryptsetup-1.7.1.tar.xz](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/cryptsetup-1.7.1.tar.xz)
|
||||||
|
* Signature [cryptsetup-1.7.1.tar.sign](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/cryptsetup-1.7.1.tar.sign)
|
||||||
|
_(You need to decompress file first to check signature.)_
|
||||||
|
* [Cryptsetup 1.7.1 Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/v1.7.1-ReleaseNotes).
|
||||||
|
|
||||||
|
Previous versions
|
||||||
|
* [Version 1.7.0](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/cryptsetup-1.7.0.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/cryptsetup-1.7.0.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.7/v1.7.0-ReleaseNotes).
|
||||||
|
* [Version 1.6.8](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.8.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.8.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/v1.6.8-ReleaseNotes).
|
||||||
|
* [Version 1.6.7](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.7.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.7.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/v1.6.7-ReleaseNotes).
|
||||||
|
* [Version 1.6.6](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.6.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.6.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/v1.6.6-ReleaseNotes).
|
||||||
|
* [Version 1.6.5](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.5.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.5.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/v1.6.5-ReleaseNotes).
|
||||||
|
* [Version 1.6.4](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.4.tar.xz) -
|
||||||
|
[Signature](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/cryptsetup-1.6.4.tar.sign) -
|
||||||
|
[Release Notes](https://www.kernel.org/pub/linux/utils/cryptsetup/v1.6/v1.6.4-ReleaseNotes).
|
||||||
|
|
||||||
|
Source and API docs
|
||||||
|
-------------------
|
||||||
|
For development version code, please refer to [source](https://gitlab.com/cryptsetup/cryptsetup/tree/master) page,
|
||||||
|
mirror on [kernel.org](https://git.kernel.org/cgit/utils/cryptsetup/cryptsetup.git/) or [GitHub](https://github.com/mbroz/cryptsetup).
|
||||||
|
|
||||||
|
For libcryptsetup documentation see [libcryptsetup API](https://gitlab.com/cryptsetup/cryptsetup/wikis/API/index.html) page.
|
||||||
|
|
||||||
|
The libcryptsetup API/ABI changes are tracked in [compatibility report](https://gitlab.com/cryptsetup/cryptsetup/wikis/ABI-tracker/timeline/libcryptsetup/index.html).
|
||||||
|
|
||||||
|
NLS PO files are maintained by [TranslationProject](http://translationproject.org/domain/cryptsetup.html).
|
||||||
|
|
||||||
|
Help!
|
||||||
|
-----
|
||||||
|
Please always read [FAQ](https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions) first.
|
||||||
|
For cryptsetup and LUKS related questions, please use the dm-crypt mailing list, [dm-crypt@saout.de](mailto:dm-crypt@saout.de).
|
||||||
|
|
||||||
|
If you want to subscribe just send an empty mail to [dm-crypt-subscribe@saout.de](mailto:dm-crypt-subscribe@saout.de).
|
||||||
|
|
||||||
|
You can also browse [list archive](http://www.saout.de/pipermail/dm-crypt/) or read it through
|
||||||
|
[web interface](http://news.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt).
|
||||||
10
TODO
10
TODO
@@ -1,6 +1,8 @@
|
|||||||
Version 1.5.0:
|
Version 1.7:
|
||||||
- Export wipe device functions
|
- Export wipe device functions
|
||||||
- Support K/M suffixes for align payload (new switch?).
|
- Support K/M suffixes for align payload (new switch?).
|
||||||
- FIPS patches (RNG, volume key restrictions, move changekey to library)
|
- TRIM for keyslots
|
||||||
- online reencryption api?
|
- Do we need crypt_data_path() - path to data device (if differs)?
|
||||||
- integrate more metadata formats
|
- Resync ETA time is not accurate, calculate it better (last minute window?).
|
||||||
|
- Extend existing LUKS header to use another KDF? (https://password-hashing.net/)
|
||||||
|
- Fix all crazy automake warnings (or switch to Cmake).
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ DIE=0
|
|||||||
DIE=1
|
DIE=1
|
||||||
}
|
}
|
||||||
|
|
||||||
(grep "^AM_PROG_LIBTOOL" $srcdir/configure.in >/dev/null) && {
|
(grep "^AM_PROG_LIBTOOL" $srcdir/configure.ac >/dev/null) && {
|
||||||
(libtool --version) < /dev/null > /dev/null 2>&1 || {
|
(libtool --version) < /dev/null > /dev/null 2>&1 || {
|
||||||
echo
|
echo
|
||||||
echo "**Error**: You must have libtool installed."
|
echo "**Error**: You must have libtool installed."
|
||||||
@@ -78,7 +78,7 @@ autopoint --force $AP_OPTS
|
|||||||
libtoolize --force --copy
|
libtoolize --force --copy
|
||||||
aclocal -I m4 $AL_OPTS
|
aclocal -I m4 $AL_OPTS
|
||||||
autoheader $AH_OPTS
|
autoheader $AH_OPTS
|
||||||
automake --add-missing --gnu $AM_OPTS
|
automake --add-missing --copy --gnu $AM_OPTS
|
||||||
autoconf $AC_OPTS
|
autoconf $AC_OPTS
|
||||||
|
|
||||||
if test x$NOCONFIGURE = x; then
|
if test x$NOCONFIGURE = x; then
|
||||||
|
|||||||
@@ -1,15 +1,22 @@
|
|||||||
AC_PREREQ([2.67])
|
AC_PREREQ([2.67])
|
||||||
AC_INIT([cryptsetup],[1.4.0])
|
AC_INIT([cryptsetup],[1.7.2])
|
||||||
|
|
||||||
dnl library version from <major>.<minor>.<release>[-<suffix>]
|
dnl library version from <major>.<minor>.<release>[-<suffix>]
|
||||||
LIBCRYPTSETUP_VERSION=$(echo $PACKAGE_VERSION | cut -f1 -d-)
|
LIBCRYPTSETUP_VERSION=$(echo $PACKAGE_VERSION | cut -f1 -d-)
|
||||||
LIBCRYPTSETUP_VERSION_INFO=4:0:0
|
LIBCRYPTSETUP_VERSION_INFO=11:0:7
|
||||||
|
|
||||||
|
AM_SILENT_RULES([yes])
|
||||||
AC_CONFIG_SRCDIR(src/cryptsetup.c)
|
AC_CONFIG_SRCDIR(src/cryptsetup.c)
|
||||||
AC_CONFIG_MACRO_DIR([m4])
|
AC_CONFIG_MACRO_DIR([m4])
|
||||||
|
|
||||||
AC_CONFIG_HEADERS([config.h:config.h.in])
|
AC_CONFIG_HEADERS([config.h:config.h.in])
|
||||||
AM_INIT_AUTOMAKE(dist-bzip2)
|
|
||||||
|
# We do not want to run test in parallel. Really.
|
||||||
|
# http://lists.gnu.org/archive/html/automake/2013-01/msg00060.html
|
||||||
|
|
||||||
|
# For old automake use this
|
||||||
|
#AM_INIT_AUTOMAKE(dist-xz)
|
||||||
|
AM_INIT_AUTOMAKE([dist-xz 1.12 serial-tests])
|
||||||
|
|
||||||
if test "x$prefix" = "xNONE"; then
|
if test "x$prefix" = "xNONE"; then
|
||||||
sysconfdir=/etc
|
sysconfdir=/etc
|
||||||
@@ -25,28 +32,35 @@ AC_PROG_INSTALL
|
|||||||
AC_PROG_MAKE_SET
|
AC_PROG_MAKE_SET
|
||||||
AC_ENABLE_STATIC(no)
|
AC_ENABLE_STATIC(no)
|
||||||
LT_INIT
|
LT_INIT
|
||||||
|
PKG_PROG_PKG_CONFIG
|
||||||
|
|
||||||
AC_HEADER_DIRENT
|
AC_HEADER_DIRENT
|
||||||
AC_HEADER_STDC
|
AC_HEADER_STDC
|
||||||
AC_CHECK_HEADERS(fcntl.h malloc.h inttypes.h sys/ioctl.h sys/mman.h \
|
AC_CHECK_HEADERS(fcntl.h malloc.h inttypes.h sys/ioctl.h sys/mman.h \
|
||||||
ctype.h unistd.h locale.h)
|
sys/sysmacros.h ctype.h unistd.h locale.h byteswap.h endian.h)
|
||||||
|
|
||||||
AC_CHECK_HEADERS(uuid/uuid.h,,[AC_MSG_ERROR('You need the uuid library')])
|
AC_CHECK_HEADERS(uuid/uuid.h,,[AC_MSG_ERROR([You need the uuid library.])])
|
||||||
AC_CHECK_HEADER(libdevmapper.h,,[AC_MSG_ERROR('You need the device-mapper library')])
|
AC_CHECK_HEADER(libdevmapper.h,,[AC_MSG_ERROR([You need the device-mapper library.])])
|
||||||
|
|
||||||
saved_LIBS=$LIBS
|
saved_LIBS=$LIBS
|
||||||
AC_CHECK_LIB(uuid, uuid_clear, ,[AC_MSG_ERROR('You need the uuid library')])
|
AC_CHECK_LIB(uuid, uuid_clear, ,[AC_MSG_ERROR([You need the uuid library.])])
|
||||||
AC_SUBST(UUID_LIBS, $LIBS)
|
AC_SUBST(UUID_LIBS, $LIBS)
|
||||||
LIBS=$saved_LIBS
|
LIBS=$saved_LIBS
|
||||||
|
|
||||||
AC_CHECK_FUNCS([posix_memalign])
|
AC_SEARCH_LIBS([clock_gettime],[rt posix4])
|
||||||
|
AC_CHECK_FUNCS([posix_memalign clock_gettime])
|
||||||
|
|
||||||
|
if test "x$enable_largefile" = "xno" ; then
|
||||||
|
AC_MSG_ERROR([Building with --disable-largefile is not supported, it can cause data corruption.])
|
||||||
|
fi
|
||||||
|
|
||||||
AC_C_CONST
|
AC_C_CONST
|
||||||
AC_C_BIGENDIAN
|
AC_C_BIGENDIAN
|
||||||
AC_TYPE_OFF_T
|
AC_TYPE_OFF_T
|
||||||
AC_SYS_LARGEFILE
|
AC_SYS_LARGEFILE
|
||||||
|
AC_FUNC_FSEEKO
|
||||||
AC_PROG_GCC_TRADITIONAL
|
AC_PROG_GCC_TRADITIONAL
|
||||||
|
AC_FUNC_STRERROR_R
|
||||||
|
|
||||||
dnl ==========================================================================
|
dnl ==========================================================================
|
||||||
|
|
||||||
@@ -61,11 +75,94 @@ AC_CHECK_LIB(popt, poptConfigFileToString,,
|
|||||||
AC_SUBST(POPT_LIBS, $LIBS)
|
AC_SUBST(POPT_LIBS, $LIBS)
|
||||||
LIBS=$saved_LIBS
|
LIBS=$saved_LIBS
|
||||||
|
|
||||||
|
dnl ==========================================================================
|
||||||
|
dnl FIPS extensions (only for RHEL)
|
||||||
|
AC_ARG_ENABLE([fips], AS_HELP_STRING([--enable-fips],[enable FIPS mode restrictions]),
|
||||||
|
[with_fips=$enableval],
|
||||||
|
[with_fips=no])
|
||||||
|
|
||||||
|
if test "x$with_fips" = "xyes"; then
|
||||||
|
AC_DEFINE(ENABLE_FIPS, 1, [Enable FIPS mode restrictions])
|
||||||
|
|
||||||
|
if test "x$enable_static" = "xyes" -o "x$enable_static_cryptsetup" = "xyes" ; then
|
||||||
|
AC_MSG_ERROR([Static build is not compatible with FIPS.])
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
AC_DEFUN([NO_FIPS], [
|
||||||
|
if test "x$with_fips" = "xyes"; then
|
||||||
|
AC_MSG_ERROR([This option is not compatible with FIPS.])
|
||||||
|
fi
|
||||||
|
])
|
||||||
|
|
||||||
|
dnl ==========================================================================
|
||||||
|
dnl pwquality library (cryptsetup CLI only)
|
||||||
|
AC_ARG_ENABLE([pwquality],
|
||||||
|
AS_HELP_STRING([--enable-pwquality],
|
||||||
|
[enable password quality checking using pwquality library]),
|
||||||
|
[with_pwquality=$enableval],
|
||||||
|
[with_pwquality=no])
|
||||||
|
|
||||||
|
if test "x$with_pwquality" = "xyes"; then
|
||||||
|
AC_DEFINE(ENABLE_PWQUALITY, 1, [Enable password quality checking using pwquality library])
|
||||||
|
PKG_CHECK_MODULES([PWQUALITY], [pwquality >= 1.0.0],,
|
||||||
|
AC_MSG_ERROR([You need pwquality library.]))
|
||||||
|
|
||||||
|
dnl FIXME: this is really hack for now
|
||||||
|
PWQUALITY_STATIC_LIBS="$PWQUALITY_LIBS -lcrack -lz"
|
||||||
|
fi
|
||||||
|
|
||||||
|
dnl ==========================================================================
|
||||||
|
dnl passwdqc library (cryptsetup CLI only)
|
||||||
|
AC_ARG_ENABLE([passwdqc],
|
||||||
|
AS_HELP_STRING([--enable-passwdqc@<:@=CONFIG_PATH@:>@],
|
||||||
|
[enable password quality checking using passwdqc library (optionally with CONFIG_PATH)]),
|
||||||
|
[enable_passwdqc=$enableval],
|
||||||
|
[enable_passwdqc=no])
|
||||||
|
|
||||||
|
case "$enable_passwdqc" in
|
||||||
|
yes|no) use_passwdqc_config="" ;;
|
||||||
|
/*) use_passwdqc_config="$enable_passwdqc"; enable_passwdqc=yes ;;
|
||||||
|
*) AC_MSG_ERROR([Unrecognized --enable-passwdqc parameter.]) ;;
|
||||||
|
esac
|
||||||
|
AC_DEFINE_UNQUOTED([PASSWDQC_CONFIG_FILE], ["$use_passwdqc_config"], [passwdqc library config file])
|
||||||
|
|
||||||
|
if test "x$enable_passwdqc" = "xyes"; then
|
||||||
|
AC_DEFINE(ENABLE_PASSWDQC, 1, [Enable password quality checking using passwdqc library])
|
||||||
|
|
||||||
|
PASSWDQC_LIBS="-lpasswdqc"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if test "x$with_pwquality$enable_passwdqc" = "xyesyes"; then
|
||||||
|
AC_MSG_ERROR([--enable-pwquality and --enable-passwdqc are mutually incompatible.])
|
||||||
|
fi
|
||||||
|
|
||||||
dnl ==========================================================================
|
dnl ==========================================================================
|
||||||
dnl Crypto backend functions
|
dnl Crypto backend functions
|
||||||
|
|
||||||
AC_DEFUN([CONFIGURE_GCRYPT], [
|
AC_DEFUN([CONFIGURE_GCRYPT], [
|
||||||
AM_PATH_LIBGCRYPT(1.1.42,,[AC_MSG_ERROR('You need the gcrypt library')])
|
if test "x$with_fips" = "xyes"; then
|
||||||
|
GCRYPT_REQ_VERSION=1.4.5
|
||||||
|
else
|
||||||
|
GCRYPT_REQ_VERSION=1.1.42
|
||||||
|
fi
|
||||||
|
dnl Check if we can use gcrypt PBKDF2 (1.6.0 supports empty password)
|
||||||
|
AC_ARG_ENABLE([gcrypt-pbkdf2], AS_HELP_STRING([--enable-gcrypt-pbkdf2],[force enable internal gcrypt PBKDF2]),
|
||||||
|
if test "x$enableval" = "xyes"; then
|
||||||
|
[use_internal_pbkdf2=0]
|
||||||
|
else
|
||||||
|
[use_internal_pbkdf2=1]
|
||||||
|
fi,
|
||||||
|
[AM_PATH_LIBGCRYPT([1.6.1], [use_internal_pbkdf2=0], [use_internal_pbkdf2=1])])
|
||||||
|
AM_PATH_LIBGCRYPT($GCRYPT_REQ_VERSION,,[AC_MSG_ERROR([You need the gcrypt library.])])
|
||||||
|
|
||||||
|
AC_MSG_CHECKING([if internal cryptsetup PBKDF2 is compiled-in])
|
||||||
|
if test $use_internal_pbkdf2 = 0; then
|
||||||
|
AC_MSG_RESULT([no])
|
||||||
|
else
|
||||||
|
AC_MSG_RESULT([yes])
|
||||||
|
NO_FIPS([])
|
||||||
|
fi
|
||||||
|
|
||||||
if test x$enable_static_cryptsetup = xyes; then
|
if test x$enable_static_cryptsetup = xyes; then
|
||||||
saved_LIBS=$LIBS
|
saved_LIBS=$LIBS
|
||||||
@@ -80,56 +177,71 @@ AC_DEFUN([CONFIGURE_GCRYPT], [
|
|||||||
CRYPTO_CFLAGS=$LIBGCRYPT_CFLAGS
|
CRYPTO_CFLAGS=$LIBGCRYPT_CFLAGS
|
||||||
CRYPTO_LIBS=$LIBGCRYPT_LIBS
|
CRYPTO_LIBS=$LIBGCRYPT_LIBS
|
||||||
CRYPTO_STATIC_LIBS=$LIBGCRYPT_STATIC_LIBS
|
CRYPTO_STATIC_LIBS=$LIBGCRYPT_STATIC_LIBS
|
||||||
|
|
||||||
|
AC_DEFINE_UNQUOTED(GCRYPT_REQ_VERSION, ["$GCRYPT_REQ_VERSION"], [Requested gcrypt version])
|
||||||
])
|
])
|
||||||
|
|
||||||
AC_DEFUN([CONFIGURE_OPENSSL], [
|
AC_DEFUN([CONFIGURE_OPENSSL], [
|
||||||
PKG_CHECK_MODULES([OPENSSL], [openssl >= 0.9.8],,
|
PKG_CHECK_MODULES([OPENSSL], [openssl >= 0.9.8],,
|
||||||
AC_MSG_ERROR('You need openssl library'))
|
AC_MSG_ERROR([You need openssl library.]))
|
||||||
CRYPTO_CFLAGS=$OPENSSL_CFLAGS
|
CRYPTO_CFLAGS=$OPENSSL_CFLAGS
|
||||||
CRYPTO_LIBS=$OPENSSL_LIBS
|
CRYPTO_LIBS=$OPENSSL_LIBS
|
||||||
|
use_internal_pbkdf2=0
|
||||||
|
|
||||||
if test x$enable_static_cryptsetup = xyes; then
|
if test x$enable_static_cryptsetup = xyes; then
|
||||||
saved_PKG_CONFIG=$PKG_CONFIG
|
saved_PKG_CONFIG=$PKG_CONFIG
|
||||||
PKG_CONFIG="$PKG_CONFIG --static"
|
PKG_CONFIG="$PKG_CONFIG --static"
|
||||||
PKG_CHECK_MODULES([OPENSSL], [openssl])
|
PKG_CHECK_MODULES([OPENSSL_STATIC], [openssl])
|
||||||
CRYPTO_STATIC_LIBS=$OPENSSL_LIBS
|
CRYPTO_STATIC_LIBS=$OPENSSL_STATIC_LIBS
|
||||||
PKG_CONFIG=$saved_PKG_CONFIG
|
PKG_CONFIG=$saved_PKG_CONFIG
|
||||||
fi
|
fi
|
||||||
|
NO_FIPS([])
|
||||||
])
|
])
|
||||||
|
|
||||||
AC_DEFUN([CONFIGURE_NSS], [
|
AC_DEFUN([CONFIGURE_NSS], [
|
||||||
if test x$enable_static_cryptsetup = xyes; then
|
if test x$enable_static_cryptsetup = xyes; then
|
||||||
AC_MSG_ERROR([Static build of cryptsetup is not supported with NSS.]),
|
AC_MSG_ERROR([Static build of cryptsetup is not supported with NSS.])
|
||||||
fi
|
fi
|
||||||
|
|
||||||
AC_MSG_WARN([NSS backend does NOT provide backward compatibility (missing ripemd160 hash).])
|
AC_MSG_WARN([NSS backend does NOT provide backward compatibility (missing ripemd160 hash).])
|
||||||
|
|
||||||
PKG_CHECK_MODULES([NSS], [nss],,
|
PKG_CHECK_MODULES([NSS], [nss],,
|
||||||
AC_MSG_ERROR('You need nss library'))
|
AC_MSG_ERROR([You need nss library.]))
|
||||||
|
|
||||||
|
saved_CFLAGS=$CFLAGS
|
||||||
|
CFLAGS="$CFLAGS $NSS_CFLAGS"
|
||||||
|
AC_CHECK_DECLS([NSS_GetVersion], [], [], [#include <nss.h>])
|
||||||
|
CFLAGS=$saved_CFLAGS
|
||||||
|
|
||||||
CRYPTO_CFLAGS=$NSS_CFLAGS
|
CRYPTO_CFLAGS=$NSS_CFLAGS
|
||||||
CRYPTO_LIBS=$NSS_LIBS
|
CRYPTO_LIBS=$NSS_LIBS
|
||||||
|
use_internal_pbkdf2=1
|
||||||
|
NO_FIPS([])
|
||||||
])
|
])
|
||||||
|
|
||||||
AC_DEFUN([CONFIGURE_KERNEL], [
|
AC_DEFUN([CONFIGURE_KERNEL], [
|
||||||
AC_CHECK_HEADERS(linux/if_alg.h,,
|
AC_CHECK_HEADERS(linux/if_alg.h,,
|
||||||
[AC_MSG_ERROR('You need Linux kernel with userspace crypto interface.')])
|
[AC_MSG_ERROR([You need Linux kernel headers with userspace crypto interface.])])
|
||||||
# AC_CHECK_DECLS([AF_ALG],,
|
# AC_CHECK_DECLS([AF_ALG],,
|
||||||
# [AC_MSG_ERROR('You need Linux kernel with userspace crypto interface.')],
|
# [AC_MSG_ERROR([You need Linux kernel with userspace crypto interface.])],
|
||||||
# [#include <sys/socket.h>])
|
# [#include <sys/socket.h>])
|
||||||
|
use_internal_pbkdf2=1
|
||||||
|
NO_FIPS([])
|
||||||
])
|
])
|
||||||
|
|
||||||
AC_DEFUN([CONFIGURE_NETTLE], [
|
AC_DEFUN([CONFIGURE_NETTLE], [
|
||||||
AC_CHECK_HEADERS(nettle/sha.h,,
|
AC_CHECK_HEADERS(nettle/sha.h,,
|
||||||
[AC_MSG_ERROR('You need Nettle cryptographic library.')])
|
[AC_MSG_ERROR([You need Nettle cryptographic library.])])
|
||||||
|
|
||||||
saved_LIBS=$LIBS
|
saved_LIBS=$LIBS
|
||||||
AC_CHECK_LIB(nettle, nettle_ripemd160_init,,
|
AC_CHECK_LIB(nettle, nettle_pbkdf2_hmac_sha256,,
|
||||||
[AC_MSG_ERROR('You need Nettle library version 2.4 or more recent.')])
|
[AC_MSG_ERROR([You need Nettle library version 2.6 or more recent.])])
|
||||||
CRYPTO_LIBS=$LIBS
|
CRYPTO_LIBS=$LIBS
|
||||||
LIBS=$saved_LIBS
|
LIBS=$saved_LIBS
|
||||||
|
|
||||||
CRYPTO_STATIC_LIBS=$CRYPTO_LIBS
|
CRYPTO_STATIC_LIBS=$CRYPTO_LIBS
|
||||||
|
use_internal_pbkdf2=0
|
||||||
|
NO_FIPS([])
|
||||||
])
|
])
|
||||||
|
|
||||||
dnl ==========================================================================
|
dnl ==========================================================================
|
||||||
@@ -144,7 +256,17 @@ if test x$enable_static_cryptsetup = xyes; then
|
|||||||
enable_static=yes
|
enable_static=yes
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
AM_CONDITIONAL(STATIC_CRYPTSETUP, test x$enable_static_cryptsetup = xyes)
|
AM_CONDITIONAL(STATIC_TOOLS, test x$enable_static_cryptsetup = xyes)
|
||||||
|
|
||||||
|
AC_ARG_ENABLE(veritysetup,
|
||||||
|
AS_HELP_STRING([--disable-veritysetup],
|
||||||
|
[disable veritysetup support]),[], [enable_veritysetup=yes])
|
||||||
|
AM_CONDITIONAL(VERITYSETUP, test x$enable_veritysetup = xyes)
|
||||||
|
|
||||||
|
AC_ARG_ENABLE([cryptsetup-reencrypt],
|
||||||
|
AS_HELP_STRING([--enable-cryptsetup-reencrypt],
|
||||||
|
[enable cryptsetup-reencrypt tool]))
|
||||||
|
AM_CONDITIONAL(REENCRYPT, test x$enable_cryptsetup_reencrypt = xyes)
|
||||||
|
|
||||||
AC_ARG_ENABLE(selinux,
|
AC_ARG_ENABLE(selinux,
|
||||||
AS_HELP_STRING([--disable-selinux],
|
AS_HELP_STRING([--disable-selinux],
|
||||||
@@ -166,6 +288,7 @@ LIBS=$saved_LIBS
|
|||||||
|
|
||||||
LIBS="$LIBS $DEVMAPPER_LIBS"
|
LIBS="$LIBS $DEVMAPPER_LIBS"
|
||||||
AC_CHECK_DECLS([dm_task_secure_data], [], [], [#include <libdevmapper.h>])
|
AC_CHECK_DECLS([dm_task_secure_data], [], [], [#include <libdevmapper.h>])
|
||||||
|
AC_CHECK_DECLS([dm_task_retry_remove], [], [], [#include <libdevmapper.h>])
|
||||||
AC_CHECK_DECLS([DM_UDEV_DISABLE_DISK_RULES_FLAG], [have_cookie=yes], [have_cookie=no], [#include <libdevmapper.h>])
|
AC_CHECK_DECLS([DM_UDEV_DISABLE_DISK_RULES_FLAG], [have_cookie=yes], [have_cookie=no], [#include <libdevmapper.h>])
|
||||||
if test "x$enable_udev" = xyes; then
|
if test "x$enable_udev" = xyes; then
|
||||||
if test "x$have_cookie" = xno; then
|
if test "x$have_cookie" = xno; then
|
||||||
@@ -181,6 +304,19 @@ AC_ARG_WITH([crypto_backend],
|
|||||||
AS_HELP_STRING([--with-crypto_backend=BACKEND], [crypto backend (gcrypt/openssl/nss/kernel/nettle) [gcrypt]]),
|
AS_HELP_STRING([--with-crypto_backend=BACKEND], [crypto backend (gcrypt/openssl/nss/kernel/nettle) [gcrypt]]),
|
||||||
[], with_crypto_backend=gcrypt
|
[], with_crypto_backend=gcrypt
|
||||||
)
|
)
|
||||||
|
|
||||||
|
dnl Kernel crypto API backend needed for benchmark and tcrypt
|
||||||
|
AC_ARG_ENABLE([kernel_crypto], AS_HELP_STRING([--disable-kernel_crypto],
|
||||||
|
[disable kernel userspace crypto (no benchmark and tcrypt)]),
|
||||||
|
[with_kernel_crypto=$enableval],
|
||||||
|
[with_kernel_crypto=yes])
|
||||||
|
|
||||||
|
if test "x$with_kernel_crypto" = "xyes"; then
|
||||||
|
AC_CHECK_HEADERS(linux/if_alg.h,,
|
||||||
|
[AC_MSG_ERROR([You need Linux kernel headers with userspace crypto interface. (Or use --disable-kernel_crypto.)])])
|
||||||
|
AC_DEFINE(ENABLE_AF_ALG, 1, [Enable using of kernel userspace crypto])
|
||||||
|
fi
|
||||||
|
|
||||||
case $with_crypto_backend in
|
case $with_crypto_backend in
|
||||||
gcrypt) CONFIGURE_GCRYPT([]) ;;
|
gcrypt) CONFIGURE_GCRYPT([]) ;;
|
||||||
openssl) CONFIGURE_OPENSSL([]) ;;
|
openssl) CONFIGURE_OPENSSL([]) ;;
|
||||||
@@ -195,6 +331,9 @@ AM_CONDITIONAL(CRYPTO_BACKEND_NSS, test $with_crypto_backend = nss)
|
|||||||
AM_CONDITIONAL(CRYPTO_BACKEND_KERNEL, test $with_crypto_backend = kernel)
|
AM_CONDITIONAL(CRYPTO_BACKEND_KERNEL, test $with_crypto_backend = kernel)
|
||||||
AM_CONDITIONAL(CRYPTO_BACKEND_NETTLE, test $with_crypto_backend = nettle)
|
AM_CONDITIONAL(CRYPTO_BACKEND_NETTLE, test $with_crypto_backend = nettle)
|
||||||
|
|
||||||
|
AM_CONDITIONAL(CRYPTO_INTERNAL_PBKDF2, test $use_internal_pbkdf2 = 1)
|
||||||
|
AC_DEFINE_UNQUOTED(USE_INTERNAL_PBKDF2, [$use_internal_pbkdf2], [Use internal PBKDF2])
|
||||||
|
|
||||||
dnl Magic for cryptsetup.static build.
|
dnl Magic for cryptsetup.static build.
|
||||||
if test x$enable_static_cryptsetup = xyes; then
|
if test x$enable_static_cryptsetup = xyes; then
|
||||||
saved_PKG_CONFIG=$PKG_CONFIG
|
saved_PKG_CONFIG=$PKG_CONFIG
|
||||||
@@ -230,6 +369,11 @@ fi
|
|||||||
AC_SUBST([DEVMAPPER_LIBS])
|
AC_SUBST([DEVMAPPER_LIBS])
|
||||||
AC_SUBST([DEVMAPPER_STATIC_LIBS])
|
AC_SUBST([DEVMAPPER_STATIC_LIBS])
|
||||||
|
|
||||||
|
AC_SUBST([PWQUALITY_LIBS])
|
||||||
|
AC_SUBST([PWQUALITY_STATIC_LIBS])
|
||||||
|
|
||||||
|
AC_SUBST([PASSWDQC_LIBS])
|
||||||
|
|
||||||
AC_SUBST([CRYPTO_CFLAGS])
|
AC_SUBST([CRYPTO_CFLAGS])
|
||||||
AC_SUBST([CRYPTO_LIBS])
|
AC_SUBST([CRYPTO_LIBS])
|
||||||
AC_SUBST([CRYPTO_STATIC_LIBS])
|
AC_SUBST([CRYPTO_STATIC_LIBS])
|
||||||
@@ -260,21 +404,53 @@ AC_DEFUN([CS_NUM_WITH], [AC_ARG_WITH([$1],
|
|||||||
[CS_DEFINE([$1], [$3], [$2])]
|
[CS_DEFINE([$1], [$3], [$2])]
|
||||||
)])
|
)])
|
||||||
|
|
||||||
|
dnl ==========================================================================
|
||||||
|
dnl Python bindings
|
||||||
|
AC_ARG_ENABLE([python], AS_HELP_STRING([--enable-python],[enable Python bindings]),
|
||||||
|
[with_python=$enableval],
|
||||||
|
[with_python=no])
|
||||||
|
|
||||||
|
AC_ARG_WITH([python_version],
|
||||||
|
AS_HELP_STRING([--with-python_version=VERSION], [required Python version [2.6]]),
|
||||||
|
[PYTHON_VERSION=$withval], [PYTHON_VERSION=2.6])
|
||||||
|
|
||||||
|
if test "x$with_python" = "xyes"; then
|
||||||
|
AM_PATH_PYTHON([$PYTHON_VERSION])
|
||||||
|
|
||||||
|
if ! test -x "$PYTHON-config" ; then
|
||||||
|
AC_MSG_ERROR([Cannot find python development packages to build bindings])
|
||||||
|
fi
|
||||||
|
|
||||||
|
PYTHON_INCLUDES=$($PYTHON-config --includes)
|
||||||
|
AC_SUBST(PYTHON_INCLUDES)
|
||||||
|
|
||||||
|
PYTHON_LIBS=$($PYTHON-config --libs)
|
||||||
|
AC_SUBST(PYTHON_LIBS)
|
||||||
|
fi
|
||||||
|
AM_CONDITIONAL([PYTHON_CRYPTSETUP], [test "x$with_python" = "xyes"])
|
||||||
|
|
||||||
|
dnl ==========================================================================
|
||||||
CS_STR_WITH([plain-hash], [password hashing function for plain mode], [ripemd160])
|
CS_STR_WITH([plain-hash], [password hashing function for plain mode], [ripemd160])
|
||||||
CS_STR_WITH([plain-cipher], [cipher for plain mode], [aes])
|
CS_STR_WITH([plain-cipher], [cipher for plain mode], [aes])
|
||||||
CS_STR_WITH([plain-mode], [cipher mode for plain mode], [cbc-essiv:sha256])
|
CS_STR_WITH([plain-mode], [cipher mode for plain mode], [cbc-essiv:sha256])
|
||||||
CS_NUM_WITH([plain-keybits],[key length in bits for plain mode], [256])
|
CS_NUM_WITH([plain-keybits],[key length in bits for plain mode], [256])
|
||||||
|
|
||||||
CS_STR_WITH([luks1-hash], [hash function for LUKS1 header], [sha1])
|
CS_STR_WITH([luks1-hash], [hash function for LUKS1 header], [sha256])
|
||||||
CS_STR_WITH([luks1-cipher], [cipher for LUKS1], [aes])
|
CS_STR_WITH([luks1-cipher], [cipher for LUKS1], [aes])
|
||||||
CS_STR_WITH([luks1-mode], [cipher mode for LUKS1], [cbc-essiv:sha256])
|
CS_STR_WITH([luks1-mode], [cipher mode for LUKS1], [xts-plain64])
|
||||||
CS_NUM_WITH([luks1-keybits],[key length in bits for LUKS1], [256])
|
CS_NUM_WITH([luks1-keybits],[key length in bits for LUKS1], [256])
|
||||||
|
CS_NUM_WITH([luks1-iter-time],[PBKDF2 iteration time for LUKS1 (in ms)], [2000])
|
||||||
|
|
||||||
CS_STR_WITH([loopaes-cipher], [cipher for loop-AES mode], [aes])
|
CS_STR_WITH([loopaes-cipher], [cipher for loop-AES mode], [aes])
|
||||||
CS_NUM_WITH([loopaes-keybits],[key length in bits for loop-AES mode], [256])
|
CS_NUM_WITH([loopaes-keybits],[key length in bits for loop-AES mode], [256])
|
||||||
|
|
||||||
CS_NUM_WITH([keyfile-size-maxkb],[maximum keyfile size (in kilobytes)], [8192])
|
CS_NUM_WITH([keyfile-size-maxkb],[maximum keyfile size (in KiB)], [8192])
|
||||||
CS_NUM_WITH([passphrase-size-max],[maximum keyfile size (in kilobytes)], [512])
|
CS_NUM_WITH([passphrase-size-max],[maximum keyfile size (in characters)], [512])
|
||||||
|
|
||||||
|
CS_STR_WITH([verity-hash], [hash function for verity mode], [sha256])
|
||||||
|
CS_NUM_WITH([verity-data-block], [data block size for verity mode], [4096])
|
||||||
|
CS_NUM_WITH([verity-hash-block], [hash block size for verity mode], [4096])
|
||||||
|
CS_NUM_WITH([verity-salt-size], [salt size for verity mode], [32])
|
||||||
|
|
||||||
dnl ==========================================================================
|
dnl ==========================================================================
|
||||||
|
|
||||||
@@ -284,9 +460,12 @@ lib/libcryptsetup.pc
|
|||||||
lib/crypto_backend/Makefile
|
lib/crypto_backend/Makefile
|
||||||
lib/luks1/Makefile
|
lib/luks1/Makefile
|
||||||
lib/loopaes/Makefile
|
lib/loopaes/Makefile
|
||||||
|
lib/verity/Makefile
|
||||||
|
lib/tcrypt/Makefile
|
||||||
src/Makefile
|
src/Makefile
|
||||||
po/Makefile.in
|
po/Makefile.in
|
||||||
man/Makefile
|
man/Makefile
|
||||||
tests/Makefile
|
tests/Makefile
|
||||||
|
python/Makefile
|
||||||
])
|
])
|
||||||
AC_OUTPUT
|
AC_OUTPUT
|
||||||
887
docs/ChangeLog.old
Normal file
887
docs/ChangeLog.old
Normal file
@@ -0,0 +1,887 @@
|
|||||||
|
2012-12-21 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Since version 1.6 This file is no longer maintained.
|
||||||
|
* See version control log http://code.google.com/p/cryptsetup/source/list
|
||||||
|
|
||||||
|
2012-10-11 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Added keyslot checker (by Arno Wagner).
|
||||||
|
* Version 1.5.1.
|
||||||
|
|
||||||
|
2012-09-11 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Add crypt_keyslot_area() API call.
|
||||||
|
|
||||||
|
2012-08-27 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Optimize seek to keyfile-offset (Issue #135, thx to dreisner).
|
||||||
|
* Fix luksHeaderBackup for very old v1.0 unaligned LUKS headers.
|
||||||
|
|
||||||
|
2012-08-12 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Allocate loop device late (only when real block device needed).
|
||||||
|
* Rework underlying device/file access functions.
|
||||||
|
* Create hash image if doesn't exist in veritysetup format.
|
||||||
|
* Provide better error message if running as non-root user (device-mapper, loop).
|
||||||
|
|
||||||
|
2012-07-10 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Version 1.5.0.
|
||||||
|
|
||||||
|
2012-06-25 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Add --device-size option for reencryption tool.
|
||||||
|
* Switch to use unit suffix for --reduce-device-size option.
|
||||||
|
* Remove open device debugging feature (no longer needed).
|
||||||
|
* Fix library name for FIPS check.
|
||||||
|
|
||||||
|
2012-06-20 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Version 1.5.0-rc2.
|
||||||
|
|
||||||
|
2012-06-18 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Introduce cryptsetup-reencrypt - experimental offline LUKS reencryption tool.
|
||||||
|
* Fix luks-header-from-active script (do not use LUKS header on-disk, add UUID).
|
||||||
|
* Add --test-passphrase option for luksOpen (check passphrase only).
|
||||||
|
|
||||||
|
2012-06-11 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Introduce veritysetup for dm-verity target management.
|
||||||
|
* Version 1.5.0-rc1.
|
||||||
|
|
||||||
|
2012-06-10 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Both data and header device can now be a file.
|
||||||
|
* Loop is automatically allocated in crypt_set_data_device().
|
||||||
|
* Require only up to last keyslot area for header device (ignore data offset).
|
||||||
|
* Fix header backup and restore to work on files with large data offset.
|
||||||
|
|
||||||
|
2012-05-27 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Fix readonly activation if underlying device is readonly (1.4.0).
|
||||||
|
* Include stddef.h in libdevmapper.h (size_t definition).
|
||||||
|
* Version 1.4.3.
|
||||||
|
|
||||||
|
2012-05-21 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Add --enable-fips for linking with fipscheck library.
|
||||||
|
* Initialize binary and library selfcheck if running in FIPS mode.
|
||||||
|
* Use FIPS RNG in FIPS mode for KEY and SALT (only gcrypt backend supported).
|
||||||
|
|
||||||
|
2012-05-09 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Fix keyslot removal (wipe keyslot) for device with 4k hw block (1.4.0).
|
||||||
|
* Allow empty cipher (cipher_null) for testing.
|
||||||
|
|
||||||
|
2012-05-02 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Fix loop mapping on readonly file.
|
||||||
|
* Relax --shared test, allow mapping even for overlapping segments.
|
||||||
|
* Support shared flag for LUKS devices (dangerous).
|
||||||
|
* Switch on retry on device remove for libdevmapper.
|
||||||
|
* Allow "private" activation (skip some udev global rules) flag.
|
||||||
|
|
||||||
|
2012-04-09 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Fix header check to support old (cryptsetup 1.0.0) header alignment. (1.4.0)
|
||||||
|
* Version 1.4.2.
|
||||||
|
|
||||||
|
2012-03-16 Milan Broz <gmazyland@gmail.com>
|
||||||
|
* Add --keyfile-offset and --new-keyfile-offset parameters to API and CLI.
|
||||||
|
* Add repair command and crypt_repair() for known LUKS metadata problems repair.
|
||||||
|
* Allow to specify --align-payload only for luksFormat.
|
||||||
|
|
||||||
|
2012-03-16 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Unify password verification option.
|
||||||
|
* Support password verification with quiet flag if possible. (1.2.0)
|
||||||
|
* Fix retry if entered passphrases (with verify option) do not match.
|
||||||
|
* Support UUID=<LUKS_UUID> format for device specification.
|
||||||
|
|
||||||
|
2012-02-11 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add --master-key-file option to luksOpen (open using volume key).
|
||||||
|
|
||||||
|
2012-01-12 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix use of empty keyfile.
|
||||||
|
|
||||||
|
2011-11-13 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix error message for luksClose and detached LUKS header.
|
||||||
|
* Allow --header for status command to get full info with detached header.
|
||||||
|
|
||||||
|
2011-11-09 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.4.1.
|
||||||
|
|
||||||
|
2011-11-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Merge pycryptsetup (Python libcryptsetup bindings).
|
||||||
|
* Fix stupid typo in set_iteration_time API call.
|
||||||
|
* Fix cryptsetup status output if parameter is device path.
|
||||||
|
|
||||||
|
2011-10-27 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix crypt_get_volume_key_size() for plain device.
|
||||||
|
* Fix FSF address in license text.
|
||||||
|
|
||||||
|
2011-10-25 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Print informative message in isLuks only in verbose mode.
|
||||||
|
* Version 1.4.0.
|
||||||
|
|
||||||
|
2011-10-10 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.4.0-rc1.
|
||||||
|
|
||||||
|
2011-10-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Support Nettle 2.4 crypto backend (for ripemd160).
|
||||||
|
* If device is not rotational, do not use Gutmann wipe method.
|
||||||
|
* Add crypt_last_error() API call.
|
||||||
|
* Fix luksKillSLot exit code if slot is inactive or invalid.
|
||||||
|
* Fix exit code if passphrases do not match in luksAddKey.
|
||||||
|
* Add LUKS on-disk format description into package.
|
||||||
|
|
||||||
|
2011-09-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Support key-slot option for luksOpen (use only explicit keyslot).
|
||||||
|
|
||||||
|
2011-08-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add more paranoid checks for LUKS header and keyslot attributes.
|
||||||
|
* Fix crypt_load to properly check device size.
|
||||||
|
* Use new /dev/loop-control (kernel 3.1) if possible.
|
||||||
|
* Enhance check of device size before writing LUKS header.
|
||||||
|
* Do not allow context format of already formatted device.
|
||||||
|
|
||||||
|
2011-07-25 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Remove hash/hmac restart from crypto backend and make it part of hash/hmac final.
|
||||||
|
* Improve check for invalid offset and size values.
|
||||||
|
|
||||||
|
2011-07-19 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Revert default initialisation of volume key in crypt_init_by_name().
|
||||||
|
* Do not allow key retrieval while suspended (key could be wiped).
|
||||||
|
* Do not allow suspend for non-LUKS devices.
|
||||||
|
* Support retries and timeout parameters for luksSuspend.
|
||||||
|
* Add --header option for detached metadata (on-disk LUKS header) device.
|
||||||
|
* Add crypt_init_by_name_and_header() and crypt_set_data_device() to API.
|
||||||
|
* Allow different data offset setting for detached header.
|
||||||
|
|
||||||
|
2011-07-07 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Remove old API functions (all functions using crypt_options).
|
||||||
|
* Add --enable-discards option to allow discards/TRIM requests.
|
||||||
|
* Add crypt_get_iv_offset() function to API.
|
||||||
|
|
||||||
|
2011-07-01 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add --shared option for creating non-overlapping crypt segments.
|
||||||
|
* Add shared flag to libcryptsetup api.
|
||||||
|
* Fix plain crypt format parameters to include size option (API change).
|
||||||
|
|
||||||
|
2011-06-08 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix return code for status command when device doesn't exists.
|
||||||
|
|
||||||
|
2011-05-24 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.3.1.
|
||||||
|
|
||||||
|
2011-05-17 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix keyfile=- processing in create command (1.3.0).
|
||||||
|
* Simplify device path status check.
|
||||||
|
|
||||||
|
2011-05-03 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Do not ignore size argument for create command (1.2.0).
|
||||||
|
|
||||||
|
2011-04-18 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix error paths in blockwise code and lseek_write call.
|
||||||
|
* Add Nettle crypto backend support.
|
||||||
|
|
||||||
|
2011-04-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.3.0.
|
||||||
|
|
||||||
|
2011-03-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Also support --skip and --hash option for loopaesOpen.
|
||||||
|
* Fix return code when passphrase is read from pipe.
|
||||||
|
* Document cryptsetup exit codes.
|
||||||
|
|
||||||
|
2011-03-18 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Respect maximum keyfile size paramater.
|
||||||
|
* Introduce maximum default keyfile size, add configure option.
|
||||||
|
* Require the whole key read from keyfile in create command (broken in 1.2.0).
|
||||||
|
* Fix offset option for loopaesOpen.
|
||||||
|
* Lock memory also in luksDump command.
|
||||||
|
* Version 1.3.0-rc2.
|
||||||
|
|
||||||
|
2011-03-14 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.3.0-rc1.
|
||||||
|
|
||||||
|
2011-03-11 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add loop manipulation code and support mapping of images in file.
|
||||||
|
* Add backing device loop info into status message.
|
||||||
|
* Add luksChangeKey command.
|
||||||
|
|
||||||
|
2011-03-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add exception to COPYING for binary distribution linked with OpenSSL library.
|
||||||
|
* Set secure data flag (wipe all ioclt buffers) if devmapper library supports it.
|
||||||
|
|
||||||
|
2011-01-29 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix mapping removal if device disappeared but node still exists.
|
||||||
|
* Fix luksAddKey return code if master key is used.
|
||||||
|
|
||||||
|
2011-01-25 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add loop-AES handling (loopaesOpen and loopaesClose commands).
|
||||||
|
(requires kernel 2.6.38 and above)
|
||||||
|
|
||||||
|
2011-01-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix static build (--disable-static-cryptsetup now works properly).
|
||||||
|
|
||||||
|
2010-12-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add compile time crypto backends implementation
|
||||||
|
(gcrypt, OpenSSL, NSS and userspace Linux kernel crypto api).
|
||||||
|
* Currently NSS is lacking ripemd160, cannot provide full plain compatibility.
|
||||||
|
* Use --with-crypto_backend=[gcrypt|openssl|nss|kernel] to configure.
|
||||||
|
|
||||||
|
2010-12-20 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.2.0.
|
||||||
|
|
||||||
|
2010-11-25 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix crypt_activate_by_keyfile() to work with PLAIN devices.
|
||||||
|
* Fix create command to properly handle keyfile size.
|
||||||
|
|
||||||
|
2010-11-16 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.2.0-rc1.
|
||||||
|
|
||||||
|
2010-11-13 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix password callback call.
|
||||||
|
* Fix default plain password entry from terminal in activate_by_passphrase.
|
||||||
|
* Add --dump-master-key option for luksDump to allow volume key dump.
|
||||||
|
* Allow to activate by internally cached volume key
|
||||||
|
(format/activate without keyslots active - used for temporary devices).
|
||||||
|
* Initialize volume key from active device in crypt_init_by_name()
|
||||||
|
* Fix cryptsetup binary exitcodes.
|
||||||
|
* Increase library version (still binary compatible with 1.1.x release).
|
||||||
|
|
||||||
|
2010-11-01 Milan Broz <mbroz@redhat.com>
|
||||||
|
* No longer support luksDelKey, reload and --non-exclusive.
|
||||||
|
* Remove some obsolete info from man page.
|
||||||
|
* Add crypt_get_type(), crypt_resize(), crypt_keyslot_max()
|
||||||
|
and crypt_get_active_device() to API.
|
||||||
|
* Rewrite all implementations in cryptsetup to new API.
|
||||||
|
* Fix luksRemoveKey to behave as documented (do not ask
|
||||||
|
for remaining keyslot passphrase).
|
||||||
|
* Add more regression tests for commands.
|
||||||
|
* Disallow mapping of device which is already in use (mapped or mounted).
|
||||||
|
* Disallow luksFormat on device in use.
|
||||||
|
|
||||||
|
2010-10-27 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Rewrite cryptsetup luksFormat, luksOpen, luksAddKey to use new API
|
||||||
|
to allow adding new features.
|
||||||
|
* Implement --use-random and --use-urandom for luksFormat to allow
|
||||||
|
setting of RNG for volume key generator.
|
||||||
|
* Add crypt_set_rng_type() and crypt_get_rng_type() to API.
|
||||||
|
* Add crypt_set_uuid() to API.
|
||||||
|
* Allow UUID setting in luksFormat and luksUUID (--uuid parameter).
|
||||||
|
* Add --keyfile-size and --new-keyfile-size (in bytes) size and disallow overloading
|
||||||
|
of --key-size for limiting keyfile reads.
|
||||||
|
* Fix luksFormat to properly use key file with --master-key-file switch.
|
||||||
|
* Fix possible double free when handling master key file.
|
||||||
|
|
||||||
|
2010-10-17 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add crypt_get_device_name() to API (get underlying device name).
|
||||||
|
* Change detection for static libraries.
|
||||||
|
* Fix pkg-config use in automake scripts.
|
||||||
|
* Remove --disable-shared-library switch and handle static library build
|
||||||
|
by common libtool logic (using --enable-static).
|
||||||
|
* Add --enable-static-cryptsetup option to build cryptsetup.static binary
|
||||||
|
together with shared build.
|
||||||
|
|
||||||
|
2010-08-05 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Wipe iteration and salt after KillSlot in LUKS header.
|
||||||
|
* Rewrite file differ test to C (and fix it to really work).
|
||||||
|
* Switch to 1MiB default alignment of data.
|
||||||
|
For more info see https://bugzilla.redhat.com/show_bug.cgi?id=621684
|
||||||
|
* Do not query non-existent device twice (cryptsetup status /dev/nonexistent).
|
||||||
|
* Check if requested hash is supported before writing LUKS header.
|
||||||
|
|
||||||
|
2010-07-28 Arno Wagner <arno@wagner.name>
|
||||||
|
* Add FAQ (Frequently Asked Questions) file to distribution.
|
||||||
|
|
||||||
|
2010-07-03 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix udev support for old libdevmapper with not compatible definition.
|
||||||
|
* Version 1.1.3.
|
||||||
|
|
||||||
|
2010-06-01 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix device alignment ioctl calls parameters.
|
||||||
|
* Fix activate_by_* API calls to handle NULL device name as documented.
|
||||||
|
|
||||||
|
2010-05-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Version 1.1.2.
|
||||||
|
|
||||||
|
2010-05-27 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix luksFormat/luksOpen reading passphrase from stdin and "-" keyfile.
|
||||||
|
* Support --key-file/-d option for luksFormat.
|
||||||
|
* Fix description of --key-file and add --verbose and --debug options to man page.
|
||||||
|
* Add verbose log level and move unlocking message there.
|
||||||
|
* Remove device even if underlying device disappeared.
|
||||||
|
* Fix (deprecated) reload device command to accept new device argument.
|
||||||
|
|
||||||
|
2010-05-23 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix luksClose operation for stacked DM devices.
|
||||||
|
* Version 1.1.1.
|
||||||
|
|
||||||
|
2010-05-03 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix automatic dm-crypt module loading.
|
||||||
|
* Escape hyphens in man page.
|
||||||
|
* Version 1.1.1-rc2.
|
||||||
|
|
||||||
|
2010-04-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Try to use pkgconfig for device mapper library.
|
||||||
|
* Detect old dm-crypt module and disable LUKS suspend/resume.
|
||||||
|
* Fix apitest to work on older systems.
|
||||||
|
* Allow no hash specification in plain device constructor.
|
||||||
|
* Fix luksOpen reading of passphrase on stdin (if "-" keyfile specified).
|
||||||
|
* Fix isLuks to initialise crypto backend (blkid instead is suggested anyway).
|
||||||
|
* Version 1.1.1-rc1.
|
||||||
|
|
||||||
|
2010-04-12 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix package config to use proper package version.
|
||||||
|
* Avoid class C++ keyword in library header.
|
||||||
|
* Detect and use devmapper udev support if available (disable by --disable-udev).
|
||||||
|
|
||||||
|
2010-04-06 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Prefer some device paths in status display.
|
||||||
|
* Support device topology detectionfor data alignment.
|
||||||
|
|
||||||
|
2010-02-25 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Do not verify unlocking passphrase in luksAddKey command.
|
||||||
|
* Properly initialise crypto backend in header backup/restore commands.
|
||||||
|
|
||||||
|
2010-01-17 Milan Broz <mbroz@redhat.com>
|
||||||
|
* If gcrypt compiled with capabilities, document workaround for cryptsetup (see lib/gcrypt.c).
|
||||||
|
* Version 1.1.0.
|
||||||
|
|
||||||
|
2010-01-10 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix initialisation of gcrypt duting luksFormat.
|
||||||
|
* Convert hash name to lower case in header (fix sha1 backward comatible header)
|
||||||
|
* Check for minimum required gcrypt version.
|
||||||
|
|
||||||
|
2009-12-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix key slot iteration count calculation (small -i value was the same as default).
|
||||||
|
* The slot and key digest iteration minimun is now 1000.
|
||||||
|
* The key digest iteration # is calculated from iteration time (approx 1/8 of that).
|
||||||
|
* Version 1.1.0-rc4.
|
||||||
|
|
||||||
|
2009-12-11 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix error handling during reading passhrase.
|
||||||
|
|
||||||
|
2009-12-01 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Allow changes of default compiled-in cipher parameters through configure.
|
||||||
|
* Switch default key size for LUKS to 256bits.
|
||||||
|
* Switch default plain mode to aes-cbc-essiv:sha256 (default is backward incompatible!).
|
||||||
|
|
||||||
|
2009-11-14 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add CRYPT_ prefix to enum defined in libcryptsetup.h.
|
||||||
|
* Fix status call to fail when running as non-root user.
|
||||||
|
* Check in configure if selinux libraries are required in static version.
|
||||||
|
* Add temporary debug code to find processes locking internal device.
|
||||||
|
* Simplify build system, use autopoint and clean gettext processing.
|
||||||
|
* Use proper NLS macros and detection (so the message translation works again).
|
||||||
|
* Version 1.1.0-rc3.
|
||||||
|
|
||||||
|
2009-09-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix exported symbols and versions in libcryptsetup.
|
||||||
|
* Do not use internal lib functions in cryptsetup.
|
||||||
|
* Add crypt_log to library.
|
||||||
|
* Fix crypt_remove_device (remove, luksClose) implementation.
|
||||||
|
* Move dm backend initialisation to library calls.
|
||||||
|
* Move duplicate Command failed message to verbose level (error is printed always).
|
||||||
|
* Add some password and used algorithms notes to man page.
|
||||||
|
* Version 1.1.0-rc2.
|
||||||
|
|
||||||
|
2009-09-28 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add luksHeaderBackup and luksHeaderRestore commands.
|
||||||
|
* Fail passphrase read if piped input no longer exists.
|
||||||
|
* Version 1.1.0-rc1.
|
||||||
|
|
||||||
|
2009-09-15 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Initialize crypto library before LUKS header load.
|
||||||
|
* Fix manpage to not require --size which expands to device size by default.
|
||||||
|
|
||||||
|
2009-09-10 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Clean up Makefiles and configure script.
|
||||||
|
* Version 1.1.0-test0.
|
||||||
|
|
||||||
|
2009-09-08 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Use dm-uuid for all crypt devices, contains device type and name now.
|
||||||
|
* Try to read first sector from device to properly check that device is ready.
|
||||||
|
|
||||||
|
2009-09-02 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Add luksSuspend (freeze device and wipe key) and luksResume (with provided passphrase).
|
||||||
|
|
||||||
|
2009-08-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Require device device-mapper to build and do not use backend wrapper for dm calls.
|
||||||
|
* Move memory locking and dm initialization to command layer.
|
||||||
|
* Increase priority of process if memory is locked.
|
||||||
|
* Add log macros and make logging modre consitent.
|
||||||
|
* Move command successful messages to verbose level.
|
||||||
|
* Introduce --debug parameter.
|
||||||
|
* Move device utils code and provide context parameter (for log).
|
||||||
|
* Keyfile now must be provided by path, only stdin file descriptor is used (api only).
|
||||||
|
* Do not call isatty() on closed keyfile descriptor.
|
||||||
|
* Run performance check for PBKDF2 from LUKS code, do not mix hash algoritms results.
|
||||||
|
* Add ability to provide pre-generated master key and UUID in LUKS header format.
|
||||||
|
* Add LUKS function to verify master key digest.
|
||||||
|
* Move key slot manuipulation function into LUKS specific code.
|
||||||
|
* Replace global options struct with separate parameters in helper functions.
|
||||||
|
* Add new libcryptsetup API (documented in libcryptsetup.h).
|
||||||
|
* Implement old API calls using new functions.
|
||||||
|
* Remove old API code helper functions.
|
||||||
|
* Add --master-key-file option for luksFormat and luksAddKey.
|
||||||
|
|
||||||
|
2009-08-17 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix PBKDF2 speed calculation for large passhrases.
|
||||||
|
* Allow using passphrase provided in options struct for LuksOpen.
|
||||||
|
* Allow restrict keys size in LuksOpen.
|
||||||
|
|
||||||
|
2009-07-30 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix errors when compiled with LUKS_DEBUG.
|
||||||
|
* Print error when getline fails.
|
||||||
|
* Remove po/cryptsetup-luks.pot, it's autogenerated.
|
||||||
|
* Return ENOENT for empty keyslots, EINVAL will be used later for other type of error.
|
||||||
|
* Switch PBKDF2 from internal SHA1 to libgcrypt, make hash algorithm not hardcoded to SHA1 here.
|
||||||
|
* Add required parameters for changing hash used in LUKS key setup scheme.
|
||||||
|
* Do not export simple XOR helper now used only inside AF functions.
|
||||||
|
* Completely remove internal SHA1 implementanion code, not needed anymore.
|
||||||
|
* Enable hash algorithm selection for LUKS through -h luksFormat option.
|
||||||
|
|
||||||
|
2009-07-28 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Pad luks header to 512 sector size.
|
||||||
|
* Rework read/write blockwise to not split operation to many pieces.
|
||||||
|
* Use posix_memalign if available.
|
||||||
|
|
||||||
|
2009-07-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Fix segfault if provided slot in luksKillslot is invalid.
|
||||||
|
* Remove unneeded timeout when remove of temporary device succeeded.
|
||||||
|
|
||||||
|
2009-07-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
* version 1.0.7
|
||||||
|
|
||||||
|
2009-07-16 Milan Broz <mbroz@redhat.com>
|
||||||
|
* Allow removal of last slot in luksRemoveKey and luksKillSlot.
|
||||||
|
|
||||||
|
2009-07-11 Milan Broz <mbroz@redhat.com>
|
||||||
|
|
||||||
|
* Add --disable-selinux option and fix static build if selinux is required.
|
||||||
|
* Reject unsupported --offset and --skip options for luksFormat and update man page.
|
||||||
|
|
||||||
|
2009-06-22 Milan Broz <mbroz@redhat.com>
|
||||||
|
|
||||||
|
* Summary of changes in subversion for 1.0.7-rc1:
|
||||||
|
* Various man page fixes.
|
||||||
|
* Set UUID in device-mapper for LUKS devices.
|
||||||
|
* Retain readahead of underlying device.
|
||||||
|
* Display device name when asking for password.
|
||||||
|
* Check device size when loading LUKS header. Remove misleading error message later.
|
||||||
|
* Add error hint if dm-crypt mapping failed.
|
||||||
|
* Use better error messages if device doesn't exist or is already used by other mapping.
|
||||||
|
* Fix make distcheck.
|
||||||
|
* Check if all slots are full during luksAddKey.
|
||||||
|
* Fix segfault in set_error.
|
||||||
|
* Code cleanups, remove precompiled pot files, remove unnecessary files from po directory
|
||||||
|
* Fix uninitialized return value variable in setup.c.
|
||||||
|
* Code cleanups. (thanks to Ivan Stankovic)
|
||||||
|
* Fix wrong output for remaining key at key deletion.
|
||||||
|
* Allow deletion of key slot while other keys have the same key information.
|
||||||
|
* Add missing AM_PROG_CC_C_O to configure.in
|
||||||
|
* Remove duplicate sentence in man page.
|
||||||
|
* Wipe start of device (possible fs signature) before LUKS-formatting.
|
||||||
|
* Do not process configure.in in hidden directories.
|
||||||
|
* Return more descriptive error in case of IO or header format error.
|
||||||
|
* Use remapping to error target instead of calling udevsettle for temporary crypt device.
|
||||||
|
* Check device mapper communication and warn user if device-mapper support missing in kernel.
|
||||||
|
* Fix signal handler to properly close device.
|
||||||
|
* write_lseek_blockwise: declare innerCount outside the if block.
|
||||||
|
* add -Wall to the default CFLAGS. fix some signedness issues.
|
||||||
|
* Error handling improvement.
|
||||||
|
* Add non-exclusive override to interface definition.
|
||||||
|
* Refactor key slot selection into keyslot_from_option.
|
||||||
|
|
||||||
|
2007-05-01 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/backends.c, man/cryptsetup.8: Apply patch from Ludwig Nussel
|
||||||
|
<ludwig.nussel@suse.de>, for old SuSE compat hashing.
|
||||||
|
|
||||||
|
2007-04-16 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Summary of changes in subversion:
|
||||||
|
Fix segfault for key size > 32 bytes.
|
||||||
|
Kick ancient header version conversion.
|
||||||
|
Fix http://bugs.debian.org/403075
|
||||||
|
No passwort retrying for I/O errors.
|
||||||
|
Fix hang on "-i 0".
|
||||||
|
Fix parenthesization error that prevented --tries from working
|
||||||
|
correctly.
|
||||||
|
|
||||||
|
2006-11-28 gettextize <bug-gnu-gettext@gnu.org>
|
||||||
|
|
||||||
|
* m4/gettext.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/glibc2.m4: New file, from gettext-0.15.
|
||||||
|
* m4/intmax.m4: New file, from gettext-0.15.
|
||||||
|
* m4/inttypes-h.m4: New file, from gettext-0.15.
|
||||||
|
* m4/inttypes-pri.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/lib-link.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/lib-prefix.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/lock.m4: New file, from gettext-0.15.
|
||||||
|
* m4/longdouble.m4: New file, from gettext-0.15.
|
||||||
|
* m4/longlong.m4: New file, from gettext-0.15.
|
||||||
|
* m4/nls.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/po.m4: Upgrade to gettext-0.15.
|
||||||
|
* m4/printf-posix.m4: New file, from gettext-0.15.
|
||||||
|
* m4/signed.m4: New file, from gettext-0.15.
|
||||||
|
* m4/size_max.m4: New file, from gettext-0.15.
|
||||||
|
* m4/visibility.m4: New file, from gettext-0.15.
|
||||||
|
* m4/wchar_t.m4: New file, from gettext-0.15.
|
||||||
|
* m4/wint_t.m4: New file, from gettext-0.15.
|
||||||
|
* m4/xsize.m4: New file, from gettext-0.15.
|
||||||
|
* m4/Makefile.am: New file.
|
||||||
|
* configure.in (AC_OUTPUT): Add m4/Makefile.
|
||||||
|
(AM_GNU_GETTEXT_VERSION): Bump to 0.15.
|
||||||
|
|
||||||
|
2006-10-22 David Härdeman <david@hardeman.nu>
|
||||||
|
|
||||||
|
* Allow hashing of keys passed through stdin.
|
||||||
|
|
||||||
|
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: 1.0.4 release
|
||||||
|
|
||||||
|
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* man/cryptsetup.8: Document --tries switch; patch by Jonas
|
||||||
|
Meurer.
|
||||||
|
|
||||||
|
2006-10-13 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c: Added terminal timeout rewrite as forwarded by
|
||||||
|
Jonas Meurer
|
||||||
|
|
||||||
|
2006-10-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Merged patch from Marc Merlin <marc@merlins.org> to allow user
|
||||||
|
selection of key slot.
|
||||||
|
|
||||||
|
2006-09-26 gettextize <bug-gnu-gettext@gnu.org>
|
||||||
|
|
||||||
|
* m4/codeset.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/gettext.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/glibc2.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/glibc21.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/iconv.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/intdiv0.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/intmax.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/inttypes.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/inttypes_h.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/inttypes-pri.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/isc-posix.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/lcmessage.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/lib-ld.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/lib-link.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/lib-prefix.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/longdouble.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/longlong.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/nls.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/po.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/printf-posix.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/progtest.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/signed.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/size_max.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/stdint_h.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/uintmax_t.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/ulonglong.m4: Upgrade to gettext-0.14.4.
|
||||||
|
* m4/wchar_t.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/wint_t.m4: New file, from gettext-0.14.4.
|
||||||
|
* m4/xsize.m4: New file, from gettext-0.14.4.
|
||||||
|
* Makefile.am (ACLOCAL_AMFLAGS): New variable.
|
||||||
|
* configure.in (AM_GNU_GETTEXT_VERSION): Bump to 0.14.4.
|
||||||
|
|
||||||
|
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: 1.0.4-rc2
|
||||||
|
|
||||||
|
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/Makefile.am: Add a few regression tests
|
||||||
|
|
||||||
|
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (get_key): Applied patch from David Härdeman
|
||||||
|
<david@2gen.com> for reading binary keys from stdin using
|
||||||
|
the "-" as key file.
|
||||||
|
|
||||||
|
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (__crypt_luks_add_key): For checking options struct
|
||||||
|
(optionsCheck) filter out CRYPT_FLAG_VERIFY and
|
||||||
|
CRYPT_FLAG_VERIFY_IF_POSSIBLE, so that in no case password verification is done
|
||||||
|
for password retrieval.
|
||||||
|
|
||||||
|
2006-08-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: Merge Patch from http://bugs.gentoo.org/show_bug.cgi?id=132126 for sepol
|
||||||
|
|
||||||
|
2006-07-23 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Applied patches from David Härdeman <david@2gen.com> to fix 64
|
||||||
|
bit compiler warning issues.
|
||||||
|
|
||||||
|
2006-05-19 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Applied patches from Jonas Meurer
|
||||||
|
- fix terminal status after timeout
|
||||||
|
- add remark for --tries to manpage
|
||||||
|
- allow more than 32 chars from standard input.
|
||||||
|
- exit status fix for cryptsetup status.
|
||||||
|
|
||||||
|
2006-05-06 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c (yesDialog): Fix getline problem for 64-bit archs.
|
||||||
|
|
||||||
|
2006-04-05 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: Release 1.0.3.
|
||||||
|
|
||||||
|
* Applied patch by Johannes Weißl for more meaningful exit codes
|
||||||
|
and password retries
|
||||||
|
|
||||||
|
2006-03-30 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (__crypt_create_device): (char *) -> (const char *)
|
||||||
|
|
||||||
|
2006-03-30 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Apply alignPayload patch from Peter Palfrader <weasel@debian.org>
|
||||||
|
|
||||||
|
2006-03-15 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: 1.0.3-rc3. Most unplease release ever.
|
||||||
|
* lib/setup.c (__crypt_create_device): More verbose error message.
|
||||||
|
|
||||||
|
2006-02-26 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c: Revert to 1.0.1 key reading.
|
||||||
|
|
||||||
|
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* man/cryptsetup.8: merge patch from Jonas Meurer
|
||||||
|
|
||||||
|
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: 1.0.3-rc2
|
||||||
|
|
||||||
|
2006-02-25 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/libdevmapper.c (dm_create_device): Remove dup check here.
|
||||||
|
* lib/setup.c (__crypt_luks_open): Adopt same dup check as regular
|
||||||
|
create command.
|
||||||
|
|
||||||
|
2006-02-22 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: Spin 1.0.3-rc1
|
||||||
|
|
||||||
|
2006-02-22 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c (action_create): Change defaulting.
|
||||||
|
(action_luksFormat): Change defaulting.
|
||||||
|
|
||||||
|
* lib/setup.c (parse_into_name_and_mode): Revert that default
|
||||||
|
change. This is FORBIDDEN here, as it will change cryptsetup
|
||||||
|
entire default. This is BAD in a non-LUKS world.
|
||||||
|
|
||||||
|
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/keyencryption.c (setup_mapping): Add proper size restriction to mapping.
|
||||||
|
(LUKS_endec_template): Add more verbose error message.
|
||||||
|
|
||||||
|
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/libdevmapper.c (dm_query_device): Incorporate patch from
|
||||||
|
Bastian Blank
|
||||||
|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344313
|
||||||
|
|
||||||
|
2006-02-21 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c: Rename show_error -> show_status.
|
||||||
|
|
||||||
|
2006-02-20 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/libdevmapper.c (dm_create_device): Prevent existing mapping
|
||||||
|
from being removed when a mapping with the same name is added
|
||||||
|
|
||||||
|
* Add timeout patch from Jonas Meurer
|
||||||
|
|
||||||
|
* src/cryptsetup.c: Remove conditional error printing to enable
|
||||||
|
printing the no-error msg (Command successful). Verify passphrase
|
||||||
|
for LUKS volumes.
|
||||||
|
(main): Add no-verify-passphrase
|
||||||
|
|
||||||
|
* lib/setup.c (parse_into_name_and_mode): Change default mode complition to essiv:sha256.
|
||||||
|
|
||||||
|
2006-01-04 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c (help): Merge patch from Gentoo: change gettext(..) to _(..).
|
||||||
|
|
||||||
|
2005-12-06 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* man/cryptsetup.8: Correct "seconds" to "microseconds" in the explaination for -i.
|
||||||
|
|
||||||
|
2005-11-09 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c (main): Add version string.
|
||||||
|
|
||||||
|
2005-11-08 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/backends.c: compile fix.
|
||||||
|
|
||||||
|
2005-09-11 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (get_key): Fixed another incompatibility from my
|
||||||
|
get_key rewrite with original cryptsetup.
|
||||||
|
|
||||||
|
2005-09-11 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Merged changes from Florian Knauf's fk02 branch.
|
||||||
|
|
||||||
|
2005-09-08 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (get_key): Fixed another incompatiblity with
|
||||||
|
original cryptsetup.
|
||||||
|
|
||||||
|
2005-08-20 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* Checked in a patch from Michael Gebetsroither <gebi@sbox.tugraz.at>
|
||||||
|
to silent all confirmation dialogs.
|
||||||
|
|
||||||
|
2005-06-23 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c (help): print PACKAGE_STRING
|
||||||
|
|
||||||
|
2005-06-20 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/keymanage.c (LUKS_set_key): Security check against header manipulation
|
||||||
|
|
||||||
|
* src/cryptsetup.c (action_luksDelKey): Safety check in luksDelKey
|
||||||
|
|
||||||
|
* luks/keymanage.c: Changed disk layout generation to align key material to 4k boundaries.
|
||||||
|
(LUKS_is_last_keyslot): Added LUKS_is_last_keyslot function.
|
||||||
|
|
||||||
|
* Applied patch from Bill Nottingham fixing a lot of prototypes.
|
||||||
|
|
||||||
|
* src/cryptsetup.c (action_luksOpen): Add support for -r flag.
|
||||||
|
|
||||||
|
* configure.in: Version bump 1.0.1
|
||||||
|
|
||||||
|
2005-06-16 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (__crypt_luks_open): Remove mem leaking of dmCipherSpec.
|
||||||
|
(get_key): Fix missing zero termination for read string.
|
||||||
|
|
||||||
|
2005-06-12 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/keyencryption.c (setup_mapping): Added CRYPT_FLAG_READONLY in case of O_RDONLY mode
|
||||||
|
|
||||||
|
2005-06-11 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: Version bump 1.0.1-pre
|
||||||
|
|
||||||
|
2005-06-09 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/utils.c: Added write_llseek_blocksize method to support sector wiping on sector_size != 512
|
||||||
|
media
|
||||||
|
|
||||||
|
2005-05-23 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/setup.c (crypt_luksDelKey): Added missing return statement
|
||||||
|
(setup_leave): Added missing return statement
|
||||||
|
|
||||||
|
* luks/keyencryption.c (clear_mapping): Added missing return statement
|
||||||
|
|
||||||
|
2005-05-19 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* lib/utils.c (write_blockwise, read_blockwise): Changed to soft bsize instead of SECTOR_SIZE
|
||||||
|
|
||||||
|
* luks/keymanage.c (wipe): Changed open mode to O_DIRECT | O_SYNC, and changed write
|
||||||
|
to use the blockwise write helper
|
||||||
|
|
||||||
|
2005-04-21 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* man/cryptsetup.8: Corrected an error, thanks to Dick Middleton.
|
||||||
|
|
||||||
|
2005-04-09 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/sha/hmac.c: Add 64 bit bug fix courtesy to
|
||||||
|
Oliver Paukstadt <pstadt@sourcentral.org>.
|
||||||
|
|
||||||
|
* luks/pbkdf.c, luks/keyencryption.c, luks/keymanage.c, luks/af.c: Added a license
|
||||||
|
disclaimer and remove option for "any future GPL versions".
|
||||||
|
|
||||||
|
2005-03-25 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* configure.in: man page Makefile. Version bump 1.0.
|
||||||
|
|
||||||
|
* man/cryptsetup.8: finalize man page and move to section 8.
|
||||||
|
|
||||||
|
* src/cryptsetup.c (action_luksFormat): Add "are you sure" for interactive sessions.
|
||||||
|
|
||||||
|
* lib/setup.c (crypt_luksDump), src/cryptsetup.c: add LUKS dump command
|
||||||
|
|
||||||
|
2005-03-24 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* src/cryptsetup.c, luks/Makefile.am (test), lib/setup.c (setup_enter):
|
||||||
|
rename luksInit to luksFormat
|
||||||
|
|
||||||
|
2005-03-12 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* man/cryptsetup.1: Add man page.
|
||||||
|
|
||||||
|
* lib/setup.c: Remove unneccessary LUKS_write_phdr call, so the
|
||||||
|
phdr is written after passphrase reading, so the user can change
|
||||||
|
his mind, and not have a partial written LUKS header on it's disk.
|
||||||
|
|
||||||
|
2005-02-09 Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
|
||||||
|
* luks/keymanage.c (LUKS_write_phdr): converted argument phdr to
|
||||||
|
pointer, and make a copy of phdr for conversion
|
||||||
|
|
||||||
|
* configure.in: Version dump.
|
||||||
|
|
||||||
|
* luks/keyencryption.c: Convert to read|write_blockwise.
|
||||||
|
|
||||||
|
* luks/keymanage.c: Convert to read|write_blockwise.
|
||||||
|
|
||||||
|
* lib/utils.c: Add read|write_blockwise functions, to use in
|
||||||
|
O_DIRECT file accesses.
|
||||||
|
|
||||||
|
2004-03-11 Thursday 15:52 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* lib/blockdev.h: BLKGETSIZE64 really uses size_t as third
|
||||||
|
argument, the rest is wrong.
|
||||||
|
|
||||||
|
2004-03-10 Wednesday 17:50 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* lib/: libcryptsetup.h, libdevmapper.c: Small fixes.
|
||||||
|
|
||||||
|
2004-03-09 Tuesday 21:41 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* lib/internal.h, lib/libcryptsetup.h, lib/libdevmapper.c,
|
||||||
|
lib/setup.c, po/de.po, src/cryptsetup.c: Added internal flags to
|
||||||
|
keep track of malloc'ed return values in struct crypt_options and
|
||||||
|
add a function to free the memory. Also add a readonly flag to
|
||||||
|
libcryptsetup.
|
||||||
|
|
||||||
|
2004-03-09 Tuesday 16:03 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* ChangeLog, configure.in, setup-gettext, lib/Makefile.am,
|
||||||
|
lib/backends.c, lib/blockdev.h, lib/gcrypt.c, lib/internal.h,
|
||||||
|
lib/libcryptsetup.h, lib/libdevmapper.c, lib/setup.c,
|
||||||
|
lib/utils.c, po/de.po, src/Makefile.am, src/cryptsetup.c: More
|
||||||
|
reorganization work.
|
||||||
|
|
||||||
|
2004-03-08 Monday 01:38 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* ChangeLog, Makefile.am, acinclude.m4, configure.in,
|
||||||
|
lib/Makefile.am, lib/backends.c, lib/blockdev.h, lib/gcrypt.c,
|
||||||
|
lib/libdevmapper.c, lib/setup.c, lib/utils.c, po/de.po,
|
||||||
|
src/Makefile.am: BLKGETSIZE64 fixes and started modularity
|
||||||
|
enhancements
|
||||||
|
|
||||||
|
2004-03-04 Thursday 21:06 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* Makefile.am, po/de.po, src/cryptsetup.c, src/cryptsetup.h: First
|
||||||
|
backward compatible working version.
|
||||||
|
|
||||||
|
2004-03-04 Thursday 00:42 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* NEWS, AUTHORS, ChangeLog, Makefile.am, README, autogen.sh,
|
||||||
|
configure.in, setup-gettext, po/ChangeLog, po/LINGUAS,
|
||||||
|
po/POTFILES.in, po/de.po, src/cryptsetup.c, src/cryptsetup.h,
|
||||||
|
src/Makefile.am (utags: initial): Initial checkin.
|
||||||
|
|
||||||
|
2004-03-04 Thursday 00:42 Jana Saout <jana@saout.de>
|
||||||
|
|
||||||
|
* NEWS, AUTHORS, ChangeLog, Makefile.am, README, autogen.sh,
|
||||||
|
configure.in, setup-gettext, po/ChangeLog, po/LINGUAS,
|
||||||
|
po/POTFILES.in, po/de.po, src/cryptsetup.c, src/cryptsetup.h,
|
||||||
|
src/Makefile.am: Initial revision
|
||||||
@@ -3,6 +3,8 @@
|
|||||||
*
|
*
|
||||||
* The documentation covers public parts of cryptsetup API. In the following sections you'll find
|
* The documentation covers public parts of cryptsetup API. In the following sections you'll find
|
||||||
* the examples that describe some features of cryptsetup API.
|
* the examples that describe some features of cryptsetup API.
|
||||||
|
* For more info about libcryptsetup API versions see
|
||||||
|
* <a href="http://upstream-tracker.org/versions/libcryptsetup.html">Upstream Tracker</a>.
|
||||||
*
|
*
|
||||||
* <OL type="A">
|
* <OL type="A">
|
||||||
* <LI>@ref cexamples "Cryptsetup API examples"</LI>
|
* <LI>@ref cexamples "Cryptsetup API examples"</LI>
|
||||||
@@ -54,7 +56,7 @@
|
|||||||
* in a persistent way on the device. Keyslot area is an array beyond LUKS header, where
|
* in a persistent way on the device. Keyslot area is an array beyond LUKS header, where
|
||||||
* volume key is stored in the encrypted form using user input passphrase. For more info about
|
* volume key is stored in the encrypted form using user input passphrase. For more info about
|
||||||
* LUKS keyslots and how it's actually protected, please look at
|
* LUKS keyslots and how it's actually protected, please look at
|
||||||
* <A HREF="http://code.google.com/p/cryptsetup/wiki/Specification">LUKS specification</A>.
|
* <A HREF="https://gitlab.com/cryptsetup/cryptsetup/wikis/Specification">LUKS specification</A>.
|
||||||
* There are two basic methods to create a new keyslot:
|
* There are two basic methods to create a new keyslot:
|
||||||
*
|
*
|
||||||
* @subsection ckeyslot_vol crypt_keyslot_add_by_volume_key()
|
* @subsection ckeyslot_vol crypt_keyslot_add_by_volume_key()
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU Lesser General Public
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* License along with this file; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU Lesser General Public
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* License along with this file; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|||||||
Binary file not shown.
@@ -62,14 +62,14 @@ WARNING: This release removes old deprecated API from libcryptsetup
|
|||||||
cannot properly work (there is filesystem allocation layer between
|
cannot properly work (there is filesystem allocation layer between
|
||||||
header and disk).
|
header and disk).
|
||||||
|
|
||||||
* Support --enable-discards option to allow discards/TRIM requests.
|
* Support --allow-discards option to allow discards/TRIM requests.
|
||||||
|
|
||||||
Since kernel 3.1, dm-crypt devices optionally (not by default) support
|
Since kernel 3.1, dm-crypt devices optionally (not by default) support
|
||||||
block discards (TRIM) comands.
|
block discards (TRIM) commands.
|
||||||
If you want to enable this operation, you have to enable it manually
|
If you want to enable this operation, you have to enable it manually
|
||||||
on every activation using --enable-discards
|
on every activation using --allow-discards
|
||||||
|
|
||||||
cryptsetup luksOpen --enable-discards /dev/sdb test_disk
|
cryptsetup luksOpen --allow-discards /dev/sdb test_disk
|
||||||
|
|
||||||
WARNING: There are several security consequences, please read at least
|
WARNING: There are several security consequences, please read at least
|
||||||
http://asalor.blogspot.com/2011/08/trim-dm-crypt-problems.html
|
http://asalor.blogspot.com/2011/08/trim-dm-crypt-problems.html
|
||||||
|
|||||||
25
docs/v1.4.1-ReleaseNotes
Normal file
25
docs/v1.4.1-ReleaseNotes
Normal file
@@ -0,0 +1,25 @@
|
|||||||
|
Cryptsetup 1.4.1 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.4.0
|
||||||
|
|
||||||
|
* Merge experimental Python cryptsetup (pycryptsetup) binding.
|
||||||
|
|
||||||
|
This option is disabled by default, you can enable build of Python binding
|
||||||
|
with --enable--python configure switch.
|
||||||
|
|
||||||
|
Note that binding currently covers only partial libcryptsetup functions,
|
||||||
|
mainly LUKS device handling needed for Anaconda installer.
|
||||||
|
Until now provided separately as python-cryptsetup.
|
||||||
|
Thanks to Martin Sivak for the code.
|
||||||
|
|
||||||
|
See python subdirectory for more info.
|
||||||
|
|
||||||
|
Python binding code is experimental for now, no stable API guarantee.
|
||||||
|
|
||||||
|
* Fix crypt_get_volume_key_size() for plain device.
|
||||||
|
(cryptsetup status reported zero key size for plain crypt devices).
|
||||||
|
|
||||||
|
* Fix typo in set_iteration_time API call (old name remains for compatibility reasons).
|
||||||
|
|
||||||
|
* Fix FSF address in license and add LGPL license text.
|
||||||
44
docs/v1.4.2-ReleaseNotes
Normal file
44
docs/v1.4.2-ReleaseNotes
Normal file
@@ -0,0 +1,44 @@
|
|||||||
|
Cryptsetup 1.4.2 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.4.1
|
||||||
|
|
||||||
|
* Add --keyfile-offset and --new-keyfile-offset parameters to API and CLI.
|
||||||
|
These options can be used to skip start of keyfile or device used as keyfile.
|
||||||
|
|
||||||
|
* Add repair command and crypt_repair() for known LUKS metadata problems repair.
|
||||||
|
|
||||||
|
Some well-known LUKS metadata corruptions are easy to repair, this
|
||||||
|
command should provide a way to fix these problems.
|
||||||
|
|
||||||
|
Always create binary backup of header device before running repair,
|
||||||
|
(only 4kB - visible header) for example by using dd:
|
||||||
|
dd if=/dev/<LUKS header device> of=repair_bck.img bs=1k count=4
|
||||||
|
|
||||||
|
Then you can try to run repair:
|
||||||
|
cryptsetup repair <device>
|
||||||
|
|
||||||
|
Note, not all problems are possible to repair and if keyslot or some header
|
||||||
|
parameters are overwritten, device is lost permanently.
|
||||||
|
|
||||||
|
* Fix header check to support old (cryptsetup 1.0.0) header alignment.
|
||||||
|
(Regression in 1.4.0)
|
||||||
|
|
||||||
|
* Allow to specify --align-payload only for luksFormat.
|
||||||
|
|
||||||
|
* Add --master-key-file option to luksOpen (open using volume key).
|
||||||
|
|
||||||
|
* Support UUID=<LUKS_UUID> format for device specification.
|
||||||
|
You can open device by UUID (only shortcut to /dev/disk/by-uuid/ symlinks).
|
||||||
|
|
||||||
|
* Support password verification with quiet flag if possible. (1.2.0)
|
||||||
|
Password verification can be still possible if input is terminal.
|
||||||
|
|
||||||
|
* Fix retry if entered passphrases (with verify option) do not match.
|
||||||
|
(It should retry if requested, not fail.)
|
||||||
|
|
||||||
|
* Fix use of empty keyfile.
|
||||||
|
|
||||||
|
* Fix error message for luksClose and detached LUKS header.
|
||||||
|
|
||||||
|
* Allow --header for status command to get full info with detached header.
|
||||||
62
docs/v1.4.3-ReleaseNotes
Normal file
62
docs/v1.4.3-ReleaseNotes
Normal file
@@ -0,0 +1,62 @@
|
|||||||
|
Cryptsetup 1.4.3 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.4.2
|
||||||
|
|
||||||
|
* Fix readonly activation if underlying device is readonly (1.4.0).
|
||||||
|
|
||||||
|
* Fix loop mapping on readonly file.
|
||||||
|
|
||||||
|
* Include stddef.h in libdevmapper.h (size_t definition).
|
||||||
|
|
||||||
|
* Fix keyslot removal for device with 4k hw block (1.4.0).
|
||||||
|
(Wipe keyslot failed in this case.)
|
||||||
|
|
||||||
|
* Relax --shared flag to allow mapping even for overlapping segments.
|
||||||
|
|
||||||
|
The --shared flag (and API CRYPT_ACTIVATE_SHARED flag) is now able
|
||||||
|
to map arbitrary overlapping area. From API it is even usable
|
||||||
|
for LUKS devices.
|
||||||
|
It is user responsibility to not cause data corruption though.
|
||||||
|
|
||||||
|
This allows e.g. scubed to work again and also allows some
|
||||||
|
tricky extensions later.
|
||||||
|
|
||||||
|
* Allow empty cipher (cipher_null) for testing.
|
||||||
|
|
||||||
|
You can now use "null" (or directly cipher_null-ecb) in cryptsetup.
|
||||||
|
This means no encryption, useful for performance tests
|
||||||
|
(measure dm-crypt layer overhead).
|
||||||
|
|
||||||
|
* Switch on retry on device remove for libdevmapper.
|
||||||
|
Device-mapper now retry removal if device is busy.
|
||||||
|
|
||||||
|
* Allow "private" activation (skip some udev global rules) flag.
|
||||||
|
Cryptsetup library API now allows to specify CRYPT_ACTIVATE_PRIVATE,
|
||||||
|
which means that some udev rules are not processed.
|
||||||
|
(Used for temporary devices, like internal keyslot mappings where
|
||||||
|
it is not desirable to run any device scans.)
|
||||||
|
|
||||||
|
* This release also includes some Red Hat/Fedora specific extensions
|
||||||
|
related to FIPS140-2 compliance.
|
||||||
|
|
||||||
|
In fact, all these patches are more formal changes and are just subset
|
||||||
|
of building blocks for FIPS certification. See FAQ for more details
|
||||||
|
about FIPS.
|
||||||
|
|
||||||
|
FIPS extensions are enabled by using --enable-fips configure switch.
|
||||||
|
|
||||||
|
In FIPS mode (kernel booted with fips=1 and gcrypt in FIPS mode)
|
||||||
|
|
||||||
|
- it provides library and binary integrity verification using
|
||||||
|
libfipscheck (requires pre-generated checksums)
|
||||||
|
|
||||||
|
- it uses FIPS approved RNG for encryption key and salt generation
|
||||||
|
(note that using /dev/random is not formally FIPS compliant RNG).
|
||||||
|
|
||||||
|
- only gcrypt crypto backend is currently supported in FIPS mode.
|
||||||
|
|
||||||
|
The FIPS RNG requirement for salt comes from NIST SP 800-132 recommendation.
|
||||||
|
(Recommendation for Password-Based Key Derivation. Part 1: Storage Applications.
|
||||||
|
http://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf)
|
||||||
|
LUKS should be aligned to this recommendation otherwise.
|
||||||
241
docs/v1.5.0-ReleaseNotes
Normal file
241
docs/v1.5.0-ReleaseNotes
Normal file
@@ -0,0 +1,241 @@
|
|||||||
|
Cryptsetup 1.5.0 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
This release covers mainly inclusion of:
|
||||||
|
|
||||||
|
* Veritysetup tool (and related libcryptsetup extensions for dm-verity).
|
||||||
|
|
||||||
|
* Experimental cryptsetup-reencrypt tool (LUKS offline reencryption).
|
||||||
|
|
||||||
|
Changes since version 1.5.0-rc2
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
* Add --device-size option for reencryption tool.
|
||||||
|
|
||||||
|
* Switch to use unit suffix for --reduce-device-size option.
|
||||||
|
|
||||||
|
* Remove open device debugging feature (no longer needed).
|
||||||
|
|
||||||
|
* Fix library name for FIPS check.
|
||||||
|
|
||||||
|
* Add example of using reencryption inside dracut (see misc/dracut).
|
||||||
|
|
||||||
|
Changes since version 1.5.0-rc1
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
Introduce cryptsetup-reencrypt - experimental offline LUKS reencryption tool.
|
||||||
|
|
||||||
|
! cryptsetup-reencrypt tool is EXPERIMENTAL
|
||||||
|
! ALWAYS BE SURE YOU HAVE RELIABLE BACKUP BEFORE USING THIS TOOL
|
||||||
|
|
||||||
|
This tool tries to simplify situation when you need to re-encrypt the whole
|
||||||
|
LUKS device in situ (without need to move data elsewhere).
|
||||||
|
|
||||||
|
This can happen for example when you want to change volume (master) key,
|
||||||
|
encryption algorithm, or other encryption parameter.
|
||||||
|
|
||||||
|
Cryptsetup-reencrypt can even optionally shift data on device
|
||||||
|
(reducing data device size - you need some free space at the end of device).
|
||||||
|
|
||||||
|
In general, cryptsetup-reencrypt can be used to
|
||||||
|
|
||||||
|
- re-generate volume key
|
||||||
|
- change arbitrary encryption parameters
|
||||||
|
- add encryption to not yet encrypted drive
|
||||||
|
|
||||||
|
Side effect of reencryption is that final device will contain
|
||||||
|
only ciphertext (for all sectors) so even if device was not properly
|
||||||
|
wiped by random data, after reencryption you cannot distinguish
|
||||||
|
which sectors are used.
|
||||||
|
(Reecryption is done always for the whole device.)
|
||||||
|
|
||||||
|
There are for sure bugs, please TEST IT IN TEST ENVIRONMENT before
|
||||||
|
use for your data.
|
||||||
|
|
||||||
|
This tool is not resistant to HW and kernel failures - hw crash
|
||||||
|
will cause serious data corruption.
|
||||||
|
|
||||||
|
You can enable compilation of this tool with --enable-cryptsetup-reencrypt
|
||||||
|
configure option (it is switched off by default).
|
||||||
|
(Tool requires libcryptsetup 1.4.3 and later.)
|
||||||
|
|
||||||
|
You have to provide all keyslot passphrases or use --keyslot-option
|
||||||
|
(then all other keyslots will be disabled).
|
||||||
|
|
||||||
|
EXAMPLES (from man page)
|
||||||
|
|
||||||
|
Reencrypt /dev/sdb1 (change volume key)
|
||||||
|
# cryptsetup-reencrypt /dev/sdb1
|
||||||
|
|
||||||
|
Reencrypt and also change cipher and cipher mode
|
||||||
|
# cryptsetup-reencrypt /dev/sdb1 -c aes-xts-plain64
|
||||||
|
|
||||||
|
Note: if you are changing key size, there must be enough space
|
||||||
|
for keyslots in header or you have to use --reduce-device size and
|
||||||
|
reduce fs in advance.
|
||||||
|
|
||||||
|
Add LUKS encryption to not yet encrypted device
|
||||||
|
First, be sure you have space added to disk.
|
||||||
|
Or, alternatively, shrink filesystem in advance.
|
||||||
|
|
||||||
|
Here we need 4096 512-bytes sectors (enough for 2x128 bit key).
|
||||||
|
|
||||||
|
# fdisk -u /dev/sdb # move sdb1 partition end + 4096 sectors
|
||||||
|
|
||||||
|
# cryptsetup-reencrypt /dev/sdb1 --new --reduce-device-size 4096
|
||||||
|
|
||||||
|
There are some options which can improve performance (depends on system),
|
||||||
|
namely --use-directio (use direct IO for all operations) can be faster
|
||||||
|
on some systems. See man page.
|
||||||
|
|
||||||
|
Progress and estimated time is printed during reencryption.
|
||||||
|
|
||||||
|
You can suspend reencryption (using ctrl+c or term signal).
|
||||||
|
To continue reencryption you have to provide only
|
||||||
|
the device parameter (offset is stored in temporary log file).
|
||||||
|
|
||||||
|
Please note LUKS device is marked invalid during reencryption and
|
||||||
|
you have to retain tool temporary files until reencryption finishes.
|
||||||
|
|
||||||
|
Temporary files are LUKS-<uuid>.[log|org|new]
|
||||||
|
|
||||||
|
Other changes
|
||||||
|
~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
* Fix luks-header-from-active script (do not use LUKS header on-disk, add UUID).
|
||||||
|
|
||||||
|
* Add --test-passphrase option for luksOpen (check passphrase only).
|
||||||
|
|
||||||
|
* Fix parsing of hexadecimal string (salt or root hash) in veritysetup.
|
||||||
|
|
||||||
|
Changes since version 1.4.3
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
Introduce veritysetup tool for dm-verity target management.
|
||||||
|
|
||||||
|
The dm-verity device-mapper target was added to Linux kernel 3.4 and
|
||||||
|
provides transparent integrity checking of block devices using a cryptographic
|
||||||
|
digest provided by the kernel crypto API. This target is read-only.
|
||||||
|
|
||||||
|
It is meant to be setup as part of a verified boot path (it was originally
|
||||||
|
developed by Chrome OS authors as part of verified boot infrastructure).
|
||||||
|
|
||||||
|
For deeper description please see http://code.google.com/p/cryptsetup/wiki/DMVerity
|
||||||
|
and kernel dm-verity documentation.
|
||||||
|
|
||||||
|
The libcryptsetup library was extended to support manipulation
|
||||||
|
with dm-verity kernel module and new veritysetup CLI tool is added.
|
||||||
|
|
||||||
|
There are no additional library requirements (it uses the same crypto
|
||||||
|
backend as cryptsetup).
|
||||||
|
|
||||||
|
If you want compile cryptsetup without veritysetup tool,
|
||||||
|
use --disable-veritysetup configure option.
|
||||||
|
For other configuration option see configure --help and veritysetup --help
|
||||||
|
(e.g. default parameters).
|
||||||
|
|
||||||
|
Supported libcryptsetup functions new CRYPT_VERITY type:
|
||||||
|
crypt_init
|
||||||
|
crypt_init_by_name
|
||||||
|
crypt_set_data device
|
||||||
|
crypt_get_type
|
||||||
|
crypt_format
|
||||||
|
crypt_load
|
||||||
|
crypt_get_active_device
|
||||||
|
crypt_activate_by_volume_key (volume key == root hash here)
|
||||||
|
crypt_dump
|
||||||
|
and new introduced function
|
||||||
|
crypt_get_verity_info
|
||||||
|
|
||||||
|
Please see comments in libcryptsetup.h and veritysetup.c as an code example
|
||||||
|
how to use CRYPT_VERITY API.
|
||||||
|
|
||||||
|
The veritysetup tool supports these operations:
|
||||||
|
|
||||||
|
veritysetup format <data_device> <hash_device>
|
||||||
|
Formats <hash_device> (calculates all hash areas according to <data_device>).
|
||||||
|
This is initial command to prepare device <hash_device> for later verification.
|
||||||
|
|
||||||
|
veritysetup create <name> <data_device> <hash_device> <root_hash>
|
||||||
|
Creates (activates) a dm-verity mapping with <name> backed by device <data_device>
|
||||||
|
and using <hash_device> for in-kernel verification.
|
||||||
|
|
||||||
|
veritysetup verify <data_device> <hash_device> <root_hash>
|
||||||
|
Verifies data in userspace (no kernel device is activated).
|
||||||
|
|
||||||
|
veritysetup remove <name>
|
||||||
|
Removes activated device from kernel (similar to dmsetup remove).
|
||||||
|
|
||||||
|
veritysetup status <name>
|
||||||
|
Reports status for the active kernel dm-verity device.
|
||||||
|
|
||||||
|
veritysetup dump <hash_device>
|
||||||
|
Reports parameters of verity device from on-disk stored superblock.
|
||||||
|
|
||||||
|
For more info see veritysetup --help and veritysetup man page.
|
||||||
|
|
||||||
|
Other changes
|
||||||
|
~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
* Both data and header device can now be a file and
|
||||||
|
loop device is automatically allocated.
|
||||||
|
|
||||||
|
* Require only up to last keyslot area for header device, previously
|
||||||
|
backup (and activation) required device/file of size up to data start
|
||||||
|
offset (data payload).
|
||||||
|
|
||||||
|
* Fix header backup and restore to work on files with large data offset.
|
||||||
|
Backup and restore now works even if backup file is smaller than data offset.
|
||||||
|
|
||||||
|
Appendix: Examples of veritysetup use
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
Format device using default parameters, info and final root hash is printed:
|
||||||
|
# veritysetup format /dev/sdb /dev/sdc
|
||||||
|
VERITY header information for /dev/sdc
|
||||||
|
UUID: fad30431-0c59-4fa6-9b57-732a90501f75
|
||||||
|
Hash type: 1
|
||||||
|
Data blocks: 52224
|
||||||
|
Data block size: 4096
|
||||||
|
Hash block size: 4096
|
||||||
|
Hash algorithm: sha256
|
||||||
|
Salt: 5cc52759af76a092e0c21829cd0ef6938f69831bf86926525106f92a7e9e3aa9
|
||||||
|
Root hash: 7aefa4506f7af497ac491a27f862cf8005ea782a5d97f6426945a6896ab557a1
|
||||||
|
|
||||||
|
Activation of device in-kernel:
|
||||||
|
# veritysetup create vr /dev/sdb /dev/sdc 7aefa4506f7af497ac491a27f862cf8005ea782a5d97f6426945a6896ab557a1
|
||||||
|
Note - if device is corrupted, kernel mapping is created but will report failure:
|
||||||
|
Verity device detected corruption after activation.
|
||||||
|
|
||||||
|
Userspace verification:
|
||||||
|
# veritysetup verify /dev/sdb /dev/sdc 7aefa4506f7af497ac491a27f862cf8005ea782a5d97f6426945a6896ab557a1
|
||||||
|
Verification failed at position 8192.
|
||||||
|
Verification of data area failed.
|
||||||
|
|
||||||
|
Active device status report:
|
||||||
|
# veritysetup status vr
|
||||||
|
/dev/mapper/vr is active.
|
||||||
|
type: VERITY
|
||||||
|
status: verified
|
||||||
|
hash type: 1
|
||||||
|
data block: 4096
|
||||||
|
hash block: 4096
|
||||||
|
hash name: sha256
|
||||||
|
salt: 5cc52759af76a092e0c21829cd0ef6938f69831bf86926525106f92a7e9e3aa9
|
||||||
|
data device: /dev/sdb
|
||||||
|
size: 417792 sectors
|
||||||
|
mode: readonly
|
||||||
|
hash device: /dev/sdc
|
||||||
|
hash offset: 8 sectors
|
||||||
|
|
||||||
|
Dump of on-disk superblock information:
|
||||||
|
# veritysetup dump /dev/sdc
|
||||||
|
VERITY header information for /dev/sdc
|
||||||
|
UUID: fad30431-0c59-4fa6-9b57-732a90501f75
|
||||||
|
Hash type: 1
|
||||||
|
Data blocks: 52224
|
||||||
|
Data block size: 4096
|
||||||
|
Hash block size: 4096
|
||||||
|
Hash algorithm: sha256
|
||||||
|
Salt: 5cc52759af76a092e0c21829cd0ef6938f69831bf86926525106f92a7e9e3aa9
|
||||||
|
|
||||||
|
Remove mapping:
|
||||||
|
# veritysetup remove vr
|
||||||
32
docs/v1.5.1-ReleaseNotes
Normal file
32
docs/v1.5.1-ReleaseNotes
Normal file
@@ -0,0 +1,32 @@
|
|||||||
|
Cryptsetup 1.5.1 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.5.0
|
||||||
|
|
||||||
|
* The libcryptsetup library now tries to initialize device-mapper backend and
|
||||||
|
loop devices only if they are really needed (lazy initializations).
|
||||||
|
This allows some operations to be run by a non-root user.
|
||||||
|
|
||||||
|
(Unfortunately LUKS header keyslot operations still require temporary dm-crypt
|
||||||
|
device and device-mapper subsystem is available only to superuser.)
|
||||||
|
|
||||||
|
Also clear error messages are provided if running as non-root user and
|
||||||
|
operation requires privileged user.
|
||||||
|
|
||||||
|
* Veritysetup can be now used by a normal user for creating hash image to file
|
||||||
|
and also it can create hash image if doesn't exist.
|
||||||
|
(Previously it required pre-allocated space.)
|
||||||
|
|
||||||
|
* Added crypt_keyslot_area() API call which allows external tools
|
||||||
|
to get exact keyslot offsets and analyse content.
|
||||||
|
|
||||||
|
An example of a tool that searches the keyslot area of a LUKS container
|
||||||
|
for positions where entropy is low and hence there is a high probability
|
||||||
|
of damage is in misc/kesylot_checker.
|
||||||
|
(Thanks to Arno Wagner for the code.)
|
||||||
|
|
||||||
|
* Optimized seek to keyfile-offset if key offset is large.
|
||||||
|
|
||||||
|
* Fixed luksHeaderBackup for very old v1.0 unaligned LUKS headers.
|
||||||
|
|
||||||
|
* Various fixes for problems found by a several static analysis tools.
|
||||||
261
docs/v1.6.0-ReleaseNotes
Normal file
261
docs/v1.6.0-ReleaseNotes
Normal file
@@ -0,0 +1,261 @@
|
|||||||
|
Cryptsetup 1.6.0 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.0-rc1
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
* Change LUKS default cipher to to use XTS encryption mode,
|
||||||
|
aes-xts-plain64 (i.e. using AES128-XTS).
|
||||||
|
|
||||||
|
XTS mode becomes standard in hard disk encryption.
|
||||||
|
|
||||||
|
You can still use any old mode:
|
||||||
|
- compile cryptsetup with old default:
|
||||||
|
configure --with-luks1-cipher=aes --with-luks1-mode=cbc-essiv:sha256 --with-luks1-keybits=256
|
||||||
|
- format LUKS device with old default:
|
||||||
|
cryptsetup luksFormat -c aes-cbc-essiv:sha256 -s 256 <device>
|
||||||
|
|
||||||
|
|
||||||
|
* Skip tests and fix error messages if running on old systems (or with old kernel).
|
||||||
|
|
||||||
|
* Rename configure.in to configure.ac and fix issues with new automake and pkgconfig
|
||||||
|
and --disable-kernel_crypto option to allow compilation with old kernel headers.
|
||||||
|
|
||||||
|
* Allow repair of 512 bits key header.
|
||||||
|
|
||||||
|
* Fix status of device if path argument is used and fix double path prefix
|
||||||
|
for non-existent device path.
|
||||||
|
|
||||||
|
|
||||||
|
Changes since version 1.5.1
|
||||||
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
Important changes
|
||||||
|
~~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
* Cryptsetup and libcryptsetup is now released under GPLv2+
|
||||||
|
(GPL version 2 or any later).
|
||||||
|
Some internal code handling files (loopaes, verity, tcrypt
|
||||||
|
and crypto backend wrapper) are LGPLv2+.
|
||||||
|
|
||||||
|
Previously code was GPL version 2 only.
|
||||||
|
|
||||||
|
|
||||||
|
* Introducing new unified command open and close.
|
||||||
|
|
||||||
|
Example:
|
||||||
|
cryptsetup open --type plain|luks|loopaes|tcrypt <device> <name>
|
||||||
|
(type defaults to luks)
|
||||||
|
|
||||||
|
with backward-compatible aliases plainOpen, luksOpen, loopaesOpen,
|
||||||
|
tcryptOpen. Basically "open --type xyz" has alias "xyzOpen".
|
||||||
|
|
||||||
|
The "create" command (plain device create) is DEPRECATED but will
|
||||||
|
be still supported.
|
||||||
|
(This command is confusing because of switched arguments order.)
|
||||||
|
|
||||||
|
The close command is generic command to remove mapping and have
|
||||||
|
backward compatible aliases (remove, luksClose, ...) which behaves
|
||||||
|
exactly the same.
|
||||||
|
|
||||||
|
While all old syntax is still supported, I strongly suggest to use
|
||||||
|
new command syntax which is common for all device types (and possible
|
||||||
|
new formats added in future).
|
||||||
|
|
||||||
|
|
||||||
|
* cryptsetup now support directly TCRYPT (TrueCrypt and compatible tc-play)
|
||||||
|
on-disk format
|
||||||
|
(Code is independent implementation not related to original project).
|
||||||
|
|
||||||
|
Only dump (tcryptDump command) and activation (open --type tcrypt or tcryptOpen)
|
||||||
|
of TCRYPT device are supported. No header changes are supported.
|
||||||
|
|
||||||
|
It is intended to easily access containers shared with other operating systems
|
||||||
|
without need to install 3rd party software. For native Linux installations LUKS
|
||||||
|
is the preferred format.
|
||||||
|
|
||||||
|
WARNING: TCRYPT extension requires kernel userspace crypto API to be
|
||||||
|
available (introduced in Linux kernel 2.6.38).
|
||||||
|
If you are configuring kernel yourself, enable "User-space interface
|
||||||
|
for symmetric key cipher algorithms" in "Cryptographic API" section
|
||||||
|
(CRYPTO_USER_API_SKCIPHER .config option).
|
||||||
|
|
||||||
|
Because TCRYPT header is encrypted, you have to always provide valid
|
||||||
|
passphrase and keyfiles. Keyfiles are handled exactly the same as in original
|
||||||
|
format (basically, first 1MB of every keyfile is mixed using CRC32 into pool).
|
||||||
|
|
||||||
|
Cryptsetup should recognize all TCRYPT header variants ever released, except
|
||||||
|
legacy cipher chains using LRW encryption mode with 64 bits encryption block
|
||||||
|
(namely Blowfish in LRW mode is not recognized, this is limitation of kernel
|
||||||
|
crypto API).
|
||||||
|
|
||||||
|
Device activation is supported only for LRW/XTS modes (again, limitation
|
||||||
|
of kernel dmcrypt which do not implements TCRYPT extensions to CBC mode).
|
||||||
|
(So old containers cannot be activated, but you can use libcryptsetup
|
||||||
|
for lost password search, example of such code is included in misc directory.)
|
||||||
|
|
||||||
|
Hidden header are supported using --tcrypt-hidden option, system encryption
|
||||||
|
using --tcrypt-system option.
|
||||||
|
|
||||||
|
For detailed description see man page.
|
||||||
|
|
||||||
|
EXAMPLE:
|
||||||
|
* Dump device parameters of container in file:
|
||||||
|
|
||||||
|
# cryptsetup tcryptDump tst
|
||||||
|
Enter passphrase:
|
||||||
|
|
||||||
|
TCRYPT header information for tst
|
||||||
|
Version: 5
|
||||||
|
Driver req.: 7
|
||||||
|
Sector size: 512
|
||||||
|
MK offset: 131072
|
||||||
|
PBKDF2 hash: sha512
|
||||||
|
Cipher chain: serpent-twofish-aes
|
||||||
|
Cipher mode: xts-plain64
|
||||||
|
MK bits: 1536
|
||||||
|
|
||||||
|
You can also dump master key using --dump-master-key.
|
||||||
|
Dump does not require superuser privilege.
|
||||||
|
|
||||||
|
* Activation of this container
|
||||||
|
|
||||||
|
# cryptsetup tcryptOpen tst tcrypt_dev
|
||||||
|
Enter passphrase:
|
||||||
|
(Chain of dmcrypt devices is activated as /dev/mapper/tcrypt_dev.)
|
||||||
|
|
||||||
|
* See status of active TCRYPT device
|
||||||
|
|
||||||
|
# cryptsetup status tcrypt_dev
|
||||||
|
|
||||||
|
/dev/mapper/tcrypt_dev is active.
|
||||||
|
type: TCRYPT
|
||||||
|
cipher: serpent-twofish-aes-xts-plain64
|
||||||
|
keysize: 1536 bits
|
||||||
|
device: /dev/loop0
|
||||||
|
loop: /tmp/tst
|
||||||
|
offset: 256 sectors
|
||||||
|
size: 65024 sectors
|
||||||
|
skipped: 256 sectors
|
||||||
|
mode: read/write
|
||||||
|
|
||||||
|
* And plaintext filesystem now ready to mount
|
||||||
|
|
||||||
|
# blkid /dev/mapper/tcrypt_dev
|
||||||
|
/dev/mapper/tcrypt_dev: SEC_TYPE="msdos" UUID="9F33-2954" TYPE="vfat"
|
||||||
|
|
||||||
|
|
||||||
|
* Add (optional) support for lipwquality for new LUKS passwords.
|
||||||
|
|
||||||
|
If password is entered through terminal (no keyfile specified)
|
||||||
|
and cryptsetup is compiled with --enable-pwquality, default
|
||||||
|
system pwquality settings are used to check password quality.
|
||||||
|
|
||||||
|
You can always override this check by using new --force-password option.
|
||||||
|
|
||||||
|
For more info about pwquality project see http://libpwquality.fedorahosted.org/
|
||||||
|
|
||||||
|
|
||||||
|
* Proper handle interrupt signals (ctrl+c and TERM signal) in tools
|
||||||
|
|
||||||
|
Code should now handle interrupt properly, release and explicitly wipe
|
||||||
|
in-memory key materials on interrupt.
|
||||||
|
(Direct users of libcryptsetup should always call crypt_free() when
|
||||||
|
code is interrupted to wipe all resources. There is no signal handling
|
||||||
|
in library, it is up to the tool using it.)
|
||||||
|
|
||||||
|
|
||||||
|
* Add new benchmark command
|
||||||
|
|
||||||
|
The "benchmark" command now tries to benchmark PBKDF2 and some block
|
||||||
|
cipher variants. You can specify you own parameters (--cipher/--key-size
|
||||||
|
for block ciphers, --hash for PBKDF2).
|
||||||
|
|
||||||
|
See man page for detailed description.
|
||||||
|
|
||||||
|
WARNING: benchmark command requires kernel userspace crypto API to be
|
||||||
|
available (introduced in Linux kernel 2.6.38).
|
||||||
|
If you are configuring kernel yourself, enable "User-space interface
|
||||||
|
for symmetric key cipher algorithms" in "Cryptographic API" section
|
||||||
|
(CRYPTO_USER_API_SKCIPHER .config option).
|
||||||
|
|
||||||
|
EXAMPLE:
|
||||||
|
# cryptsetup benchmark
|
||||||
|
# Tests are approximate using memory only (no storage IO).
|
||||||
|
PBKDF2-sha1 111077 iterations per second
|
||||||
|
PBKDF2-sha256 53718 iterations per second
|
||||||
|
PBKDF2-sha512 18832 iterations per second
|
||||||
|
PBKDF2-ripemd160 89775 iterations per second
|
||||||
|
PBKDF2-whirlpool 23918 iterations per second
|
||||||
|
# Algorithm | Key | Encryption | Decryption
|
||||||
|
aes-cbc 128b 212.0 MiB/s 428.0 MiB/s
|
||||||
|
serpent-cbc 128b 23.1 MiB/s 66.0 MiB/s
|
||||||
|
twofish-cbc 128b 46.1 MiB/s 50.5 MiB/s
|
||||||
|
aes-cbc 256b 163.0 MiB/s 350.0 MiB/s
|
||||||
|
serpent-cbc 256b 23.1 MiB/s 66.0 MiB/s
|
||||||
|
twofish-cbc 256b 47.0 MiB/s 50.0 MiB/s
|
||||||
|
aes-xts 256b 190.0 MiB/s 190.0 MiB/s
|
||||||
|
serpent-xts 256b 58.4 MiB/s 58.0 MiB/s
|
||||||
|
twofish-xts 256b 49.0 MiB/s 49.5 MiB/s
|
||||||
|
aes-xts 512b 175.0 MiB/s 175.0 MiB/s
|
||||||
|
serpent-xts 512b 59.0 MiB/s 58.0 MiB/s
|
||||||
|
twofish-xts 512b 48.5 MiB/s 49.5 MiB/s
|
||||||
|
|
||||||
|
Or you can specify cipher yourself:
|
||||||
|
# cryptsetup benchmark --cipher cast5-cbc-essiv:sha256 -s 128
|
||||||
|
# Tests are approximate using memory only (no storage IO).
|
||||||
|
# Algorithm | Key | Encryption | Decryption
|
||||||
|
cast5-cbc 128b 32.4 MiB/s 35.0 MiB/s
|
||||||
|
|
||||||
|
WARNING: these tests do not use dmcrypt, only crypto API.
|
||||||
|
You have to benchmark the whole device stack and you can get completely
|
||||||
|
different results. But is is usable for basic comparison.
|
||||||
|
(Note for example AES-NI decryption optimization effect in example above.)
|
||||||
|
|
||||||
|
Features
|
||||||
|
~~~~~~~~
|
||||||
|
|
||||||
|
* Do not maintain ChangeLog file anymore, see git log for detailed changes,
|
||||||
|
e.g. here http://code.google.com/p/cryptsetup/source/list
|
||||||
|
|
||||||
|
* Move change key into library, add crypt_keyslot_change_by_passphrase().
|
||||||
|
This change is useful mainly in FIPS mode, where we cannot
|
||||||
|
extract volume key directly from libcryptsetup.
|
||||||
|
|
||||||
|
* Add verbose messages during reencryption.
|
||||||
|
|
||||||
|
* Default LUKS PBKDF2 iteration time is now configurable.
|
||||||
|
|
||||||
|
* Add simple cipher benchmarking API.
|
||||||
|
|
||||||
|
* Add kernel skcipher backend.
|
||||||
|
|
||||||
|
* Add CRC32 implementation (for TCRYPT).
|
||||||
|
|
||||||
|
* Move PBKDF2 into crypto backend wrapper.
|
||||||
|
This allows use it in other formats, use library implementations and
|
||||||
|
also possible use of different KDF function in future.
|
||||||
|
|
||||||
|
* New PBKDF2 benchmark using getrusage().
|
||||||
|
|
||||||
|
Fixes
|
||||||
|
~~~~~
|
||||||
|
|
||||||
|
* Avoid O_DIRECT open if underlying storage doesn't support it.
|
||||||
|
|
||||||
|
* Fix some non-translated messages.
|
||||||
|
|
||||||
|
* Fix regression in header backup (1.5.1) with container in file.
|
||||||
|
|
||||||
|
* Fix blockwise read/write for end writes near end of device.
|
||||||
|
(was not used in previous versions)
|
||||||
|
|
||||||
|
* Ignore setpriority failure.
|
||||||
|
|
||||||
|
* Code changes to fix/ignore problems found by Coverity static analysis, including
|
||||||
|
- Get page size should never fail.
|
||||||
|
- Fix time of check/use (TOCTOU test) in tools
|
||||||
|
- Fix time of check/use in loop/wipe utils.
|
||||||
|
- Fix time of check/use in device utils.
|
||||||
|
|
||||||
|
* Disallow header restore if context is non-LUKS device.
|
||||||
32
docs/v1.6.1-ReleaseNotes
Normal file
32
docs/v1.6.1-ReleaseNotes
Normal file
@@ -0,0 +1,32 @@
|
|||||||
|
Cryptsetup 1.6.1 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.0
|
||||||
|
|
||||||
|
* Fix loop-AES keyfile parsing.
|
||||||
|
Loop-AES keyfile should be text keyfile, reject keyfiles which
|
||||||
|
are not properly terminated.
|
||||||
|
|
||||||
|
* Fix passphrase pool overflow for too long TCRYPT passphrase.
|
||||||
|
(Maximal TCRYPT passphrase length is 64 characters.)
|
||||||
|
|
||||||
|
* Return EPERM (translated to exit code 2) for too long TCRYPT passphrase.
|
||||||
|
|
||||||
|
* Fix deactivation of device when failed underlying node disappeared.
|
||||||
|
|
||||||
|
* Fix API deactivate call for TCRYPT format and NULL context parameter.
|
||||||
|
|
||||||
|
* Improve keyslot checker example documentation.
|
||||||
|
|
||||||
|
* Report error message if deactivation fails and device is still busy.
|
||||||
|
|
||||||
|
* Make passphrase prompts more consistent (and remove "LUKS" form prompt).
|
||||||
|
|
||||||
|
* Fix some missing headers (compilation failed with alternative libc).
|
||||||
|
|
||||||
|
* Remove not functional API UUID support for plain & loopaes devices.
|
||||||
|
(not persistent activation UUID).
|
||||||
|
|
||||||
|
* Properly cleanup devices on interrupt in api-test.
|
||||||
|
|
||||||
|
* Support all tests run if kernel is in FIPS mode.
|
||||||
25
docs/v1.6.2-ReleaseNotes
Normal file
25
docs/v1.6.2-ReleaseNotes
Normal file
@@ -0,0 +1,25 @@
|
|||||||
|
Cryptsetup 1.6.2 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.1
|
||||||
|
|
||||||
|
* Print error and fail if more device arguments are present for isLuks command.
|
||||||
|
|
||||||
|
* Fix cipher specification string parsing (found by gcc -fsanitize=address option).
|
||||||
|
|
||||||
|
* Try to map TCRYPT system encryption through partition
|
||||||
|
(allows to activate mapping when other partition on the same device is mounted).
|
||||||
|
|
||||||
|
* Print a warning if system encryption is used and device is a partition.
|
||||||
|
(TCRYPT system encryption uses whole device argument.)
|
||||||
|
|
||||||
|
* Disallow explicit small payload offset for LUKS detached header.
|
||||||
|
LUKS detached header only allows data payload 0 (whole data device is used)
|
||||||
|
or explicit offset larger than header + keyslots size.
|
||||||
|
|
||||||
|
* Fix boundary condition for verity device that caused failure for certain device sizes.
|
||||||
|
|
||||||
|
* Various fixes to documentation, including update FAQ, default modes
|
||||||
|
and TCRYPT description.
|
||||||
|
|
||||||
|
* Workaround for some recent changes in automake (serial-tests).
|
||||||
50
docs/v1.6.3-ReleaseNotes
Normal file
50
docs/v1.6.3-ReleaseNotes
Normal file
@@ -0,0 +1,50 @@
|
|||||||
|
Cryptsetup 1.6.3 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.2
|
||||||
|
|
||||||
|
* Fix cryptsetup reencryption tool to work properly
|
||||||
|
with devices using 4kB sectors.
|
||||||
|
|
||||||
|
* Always use page size if running through loop device,
|
||||||
|
this fixes failures for external LUKS header and
|
||||||
|
filesystem requiring 4kB block size.
|
||||||
|
|
||||||
|
* Fix TCRYPT system encryption mapping for multiple partitions.
|
||||||
|
Since this commit, one can use partition directly as device parameter.
|
||||||
|
If you need to activate such partition from image in file,
|
||||||
|
please first use map partitioned loop device (losetup -P)
|
||||||
|
on image.
|
||||||
|
(Cryptsetup require partition offsets visible in kernel sysfs
|
||||||
|
in this mode.)
|
||||||
|
|
||||||
|
* Support activation of old TrueCrypt containers using CBC mode
|
||||||
|
and whitening (created in TrueCrypt version < 4.1).
|
||||||
|
This requires Linux kernel 3.13 or later.
|
||||||
|
(Containers with cascade CBC ciphers are not supported.)
|
||||||
|
|
||||||
|
* Properly display keys in dump --dump-master-key command
|
||||||
|
for TrueCrypt CBC containers.
|
||||||
|
|
||||||
|
* Rewrite cipher benchmark loop which was unreliable
|
||||||
|
on very fast machines.
|
||||||
|
|
||||||
|
* Add warning if LUKS device was activated using non-cryptsetup
|
||||||
|
library which did not set UUID properly (e.g. cryptmount).
|
||||||
|
(Some commands, like luksSuspend, are not available then.)
|
||||||
|
|
||||||
|
* Support length limitation also for plain (no hash) length.
|
||||||
|
This can be used for mapping problematic cryptosystems which
|
||||||
|
wipes some key (losetup sometimes set last 32 byte to zero,
|
||||||
|
which can be now configured as --hash plain:31 parameter).
|
||||||
|
|
||||||
|
* Fix hash limit if parameter is not a number.
|
||||||
|
(The whole key was set to zero instead of command failure.)
|
||||||
|
|
||||||
|
* Unify --key-slot behavior in cryptsetup_reencrypt tool.
|
||||||
|
|
||||||
|
* Update dracut example scripts for system reencryption on first boot.
|
||||||
|
|
||||||
|
* Add command line option --tcrypt-backup to access TCRYPT backup header.
|
||||||
|
|
||||||
|
* Fix static compilation with OpenSSL.
|
||||||
57
docs/v1.6.4-ReleaseNotes
Normal file
57
docs/v1.6.4-ReleaseNotes
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
Cryptsetup 1.6.4 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.3
|
||||||
|
|
||||||
|
* Implement new erase (with alias luksErase) command.
|
||||||
|
|
||||||
|
The erase cryptsetup command can be used to permanently erase
|
||||||
|
all keyslots and make the LUKS container inaccessible.
|
||||||
|
(The only way to unlock such device is to use LUKS header backup
|
||||||
|
created before erase command was used.)
|
||||||
|
|
||||||
|
You do not need to provide any password for this operation.
|
||||||
|
|
||||||
|
This operation is irreversible.
|
||||||
|
|
||||||
|
* Add internal "whirlpool_gcryptbug hash" for accessing flawed
|
||||||
|
Whirlpool hash in gcrypt (requires gcrypt 1.6.1 or above).
|
||||||
|
|
||||||
|
The gcrypt version of Whirlpool hash algorithm was flawed in some
|
||||||
|
situations.
|
||||||
|
|
||||||
|
This means that if you used Whirlpool in LUKS header and upgraded
|
||||||
|
to new gcrypt library your LUKS container become inaccessible.
|
||||||
|
|
||||||
|
Please refer to cryptsetup FAQ for detail how to fix this situation.
|
||||||
|
|
||||||
|
* Allow to use --disable-gcrypt-pbkdf2 during configuration
|
||||||
|
to force use internal PBKDF2 code.
|
||||||
|
|
||||||
|
* Require gcrypt 1.6.1 for imported implementation of PBKDF2
|
||||||
|
(PBKDF2 in gcrypt 1.6.0 is too slow).
|
||||||
|
|
||||||
|
* Add --keep-key to cryptsetup-reencrypt.
|
||||||
|
|
||||||
|
This allows change of LUKS header hash (and iteration count) without
|
||||||
|
the need to reencrypt the whole data area.
|
||||||
|
(Reencryption of LUKS header only without master key change.)
|
||||||
|
|
||||||
|
* By default verify new passphrase in luksChangeKey and luksAddKey
|
||||||
|
commands (if input is from terminal).
|
||||||
|
|
||||||
|
* Fix memory leak in Nettle crypto backend.
|
||||||
|
|
||||||
|
* Support --tries option even for TCRYPT devices in cryptsetup.
|
||||||
|
|
||||||
|
* Support --allow-discards option even for TCRYPT devices.
|
||||||
|
(Note that this could destroy hidden volume and it is not suggested
|
||||||
|
by original TrueCrypt security model.)
|
||||||
|
|
||||||
|
* Link against -lrt for clock_gettime to fix undefined reference
|
||||||
|
to clock_gettime error (introduced in 1.6.2).
|
||||||
|
|
||||||
|
* Fix misleading error message when some algorithms are not available.
|
||||||
|
|
||||||
|
* Count system time in PBKDF2 benchmark if kernel returns no self usage info.
|
||||||
|
(Workaround to broken getrusage() syscall with some hypervisors.)
|
||||||
54
docs/v1.6.5-ReleaseNotes
Normal file
54
docs/v1.6.5-ReleaseNotes
Normal file
@@ -0,0 +1,54 @@
|
|||||||
|
Cryptsetup 1.6.5 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.4
|
||||||
|
|
||||||
|
* Allow LUKS header operation handling without requiring root privilege.
|
||||||
|
It means that you can manipulate with keyslots as a regular user, only
|
||||||
|
write access to device (or image) is required.
|
||||||
|
|
||||||
|
This requires kernel crypto wrapper (similar to TrueCrypt device handling)
|
||||||
|
to be available (CRYPTO_USER_API_SKCIPHER kernel option).
|
||||||
|
If this kernel interface is not available, code fallbacks to old temporary
|
||||||
|
keyslot device creation (where root privilege is required).
|
||||||
|
|
||||||
|
Note that activation, deactivation, resize and suspend operations still
|
||||||
|
need root privilege (limitation of kernel device-mapper backend).
|
||||||
|
|
||||||
|
* Fix internal PBKDF2 key derivation function implementation for alternative
|
||||||
|
crypto backends (kernel, NSS) which do not support PBKDF2 directly and have
|
||||||
|
issues with longer HMAC keys.
|
||||||
|
|
||||||
|
This fixes the problem for long keyfiles where either calculation is too slow
|
||||||
|
(because of internal rehashing in every iteration) or there is a limit
|
||||||
|
(kernel backend seems to not support HMAC key longer than 20480 bytes).
|
||||||
|
|
||||||
|
(Note that for recent version of gcrypt, nettle or openssl the internal
|
||||||
|
PBKDF2 code is not compiled in and crypto library internal functions are
|
||||||
|
used instead.)
|
||||||
|
|
||||||
|
* Support for Python3 for simple Python binding.
|
||||||
|
Python >= 2.6 is now required. You can set Python compiled version by setting
|
||||||
|
--with-python_version configure option (together with --enable-python).
|
||||||
|
|
||||||
|
* Use internal PBKDF2 in Nettle library for Nettle crypto backend.
|
||||||
|
Cryptsetup compilation requires Nettle >= 2.6 (if using Nettle crypto backend).
|
||||||
|
|
||||||
|
* Allow simple status of crypt device without providing metadata header.
|
||||||
|
The command "cryptsetup status" will print basic info, even if you
|
||||||
|
do not provide detached header argument.
|
||||||
|
|
||||||
|
* Allow to specify ECB mode in cryptsetup benchmark.
|
||||||
|
|
||||||
|
* Add some LUKS images for regression testing.
|
||||||
|
Note that if image with Whirlpool fails, the most probable cause is that
|
||||||
|
you have old gcrypt library with flawed whirlpool hash.
|
||||||
|
Read FAQ section 8.3 for more info.
|
||||||
|
|
||||||
|
Cryptsetup API NOTE:
|
||||||
|
The direct terminal handling for passphrase entry will be removed from
|
||||||
|
libcryptsetup in next major version (application should handle it itself).
|
||||||
|
|
||||||
|
It means that you have to always either provide password in buffer or set
|
||||||
|
your own password callback function trhough crypt_set_password_callback().
|
||||||
|
See API documentation (or libcryptsetup.h) for more info.
|
||||||
29
docs/v1.6.6-ReleaseNotes
Normal file
29
docs/v1.6.6-ReleaseNotes
Normal file
@@ -0,0 +1,29 @@
|
|||||||
|
Cryptsetup 1.6.6 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.5
|
||||||
|
|
||||||
|
* LUKS: Fix keyslot device access for devices which
|
||||||
|
do not support direct IO operations. (Regression in 1.6.5.)
|
||||||
|
|
||||||
|
* LUKS: Fallback to old temporary keyslot device mapping method
|
||||||
|
if hash (for ESSIV) is not supported by userspace crypto
|
||||||
|
library. (Regression in 1.6.5.)
|
||||||
|
|
||||||
|
* Properly activate device with discard (TRIM for SSDs)
|
||||||
|
if requested even if dm_crypt module is not yet loaded.
|
||||||
|
Only if discard is not supported by the old kernel then
|
||||||
|
the discard option is ignored.
|
||||||
|
|
||||||
|
* Fix some static analysis build warnings (scan-build).
|
||||||
|
|
||||||
|
* Report crypto lib version only once (and always add kernel
|
||||||
|
version) in debug output.
|
||||||
|
|
||||||
|
Cryptsetup API NOTE:
|
||||||
|
The direct terminal handling for passphrase entry will be removed from
|
||||||
|
libcryptsetup in next major version (application should handle it itself).
|
||||||
|
|
||||||
|
It means that you have to always either provide password in buffer or set
|
||||||
|
your own password callback function through crypt_set_password_callback().
|
||||||
|
See API documentation (or libcryptsetup.h) for more info.
|
||||||
84
docs/v1.6.7-ReleaseNotes
Normal file
84
docs/v1.6.7-ReleaseNotes
Normal file
@@ -0,0 +1,84 @@
|
|||||||
|
Cryptsetup 1.6.7 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.6
|
||||||
|
|
||||||
|
* Cryptsetup git and wiki are now hosted on GitLab.
|
||||||
|
https://gitlab.com/cryptsetup/cryptsetup
|
||||||
|
|
||||||
|
Repository of stable releases remains on kernel.org site
|
||||||
|
https://www.kernel.org/pub/linux/utils/cryptsetup/
|
||||||
|
|
||||||
|
For more info please see README file.
|
||||||
|
|
||||||
|
* Cryptsetup TCRYPT mode now supports VeraCrypt devices (TrueCrypt extension).
|
||||||
|
|
||||||
|
The VeraCrypt extension only increases iteration count for the key
|
||||||
|
derivation function (on-disk format is the same as TrueCrypt format).
|
||||||
|
|
||||||
|
Note that unlocking of a VeraCrypt device can take very long time if used
|
||||||
|
on slow machines.
|
||||||
|
|
||||||
|
To use this extension, add --veracrypt option, for example
|
||||||
|
cryptsetup open --type tcrypt --veracrypt <container> <name>
|
||||||
|
|
||||||
|
For use through libcryptsetup, just add CRYPT_TCRYPT_VERA_MODES flag.
|
||||||
|
|
||||||
|
* Support keyfile-offset and keyfile-size options even for plain volumes.
|
||||||
|
|
||||||
|
* Support keyfile option for luksAddKey if the master key is specified.
|
||||||
|
|
||||||
|
* For historic reasons, hashing in the plain mode is not used
|
||||||
|
if keyfile is specified (with exception of --key-file=-).
|
||||||
|
Print a warning if these parameters are ignored.
|
||||||
|
|
||||||
|
* Support permanent device decryption for cryptsetup-reencrypt.
|
||||||
|
To remove LUKS encryption from a device, you can now use --decrypt option.
|
||||||
|
|
||||||
|
* Allow to use --header option in all LUKS commands.
|
||||||
|
The --header always takes precedence over positional device argument.
|
||||||
|
|
||||||
|
* Allow luksSuspend without need to specify a detached header.
|
||||||
|
|
||||||
|
* Detect if O_DIRECT is usable on a device allocation.
|
||||||
|
There are some strange storage stack configurations which wrongly allows
|
||||||
|
to open devices with direct-io but fails on all IO operations later.
|
||||||
|
|
||||||
|
Cryptsetup now tries to read the device first sector to ensure it can use
|
||||||
|
direct-io.
|
||||||
|
|
||||||
|
* Add low-level performance options tuning for dmcrypt (for Linux 4.0 and later).
|
||||||
|
|
||||||
|
Linux kernel 4.0 contains rewritten dmcrypt code which tries to better utilize
|
||||||
|
encryption on parallel CPU cores.
|
||||||
|
|
||||||
|
While tests show that this change increases performance on most configurations,
|
||||||
|
dmcrypt now provides some switches to change its new behavior.
|
||||||
|
|
||||||
|
You can use them (per-device) with these cryptsetup switches:
|
||||||
|
--perf-same_cpu_crypt
|
||||||
|
--perf-submit_from_crypt_cpus
|
||||||
|
|
||||||
|
Please use these only in the case of serious performance problems.
|
||||||
|
Refer to the cryptsetup man page and dm-crypt documentation
|
||||||
|
(for same_cpu_crypt and submit_from_crypt_cpus options).
|
||||||
|
https://gitlab.com/cryptsetup/cryptsetup/wikis/DMCrypt
|
||||||
|
|
||||||
|
* Get rid of libfipscheck library.
|
||||||
|
(Note that this option was used only for Red Hat and derived distributions.)
|
||||||
|
With recent FIPS changes we do not need to link to this FIPS monster anymore.
|
||||||
|
Also drop some no longer needed FIPS mode checks.
|
||||||
|
|
||||||
|
* Many fixes and clarifications to man pages.
|
||||||
|
|
||||||
|
* Prevent compiler to optimize-out zeroing of buffers for on-stack variables.
|
||||||
|
|
||||||
|
* Fix a crash if non-GNU strerror_r is used.
|
||||||
|
|
||||||
|
Cryptsetup API NOTE:
|
||||||
|
The direct terminal handling for passphrase entry will be removed from
|
||||||
|
libcryptsetup in next major version (application should handle it itself).
|
||||||
|
|
||||||
|
It means that you have to always either provide password in buffer or set
|
||||||
|
your own password callback function through crypt_set_password_callback().
|
||||||
|
See API documentation (or libcryptsetup.h) for more info.
|
||||||
47
docs/v1.6.8-ReleaseNotes
Normal file
47
docs/v1.6.8-ReleaseNotes
Normal file
@@ -0,0 +1,47 @@
|
|||||||
|
Cryptsetup 1.6.8 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.6.7
|
||||||
|
|
||||||
|
* If the null cipher (no encryption) is used, allow only empty password for LUKS.
|
||||||
|
(Previously cryptsetup accepted any password in this case.)
|
||||||
|
|
||||||
|
The null cipher can be used only for testing and it is used temporarily during
|
||||||
|
offline encrypting not yet encrypted device (cryptsetup-reencrypt tool).
|
||||||
|
|
||||||
|
Accepting only empty password prevents situation when someone adds another
|
||||||
|
LUKS device using the same UUID (UUID of existing LUKS device) with faked
|
||||||
|
header containing null cipher.
|
||||||
|
This could force user to use different LUKS device (with no encryption)
|
||||||
|
without noticing.
|
||||||
|
(IOW it prevents situation when attacker intentionally forces
|
||||||
|
user to boot into different system just by LUKS header manipulation.)
|
||||||
|
|
||||||
|
Properly configured systems should have an additional integrity protection
|
||||||
|
in place here (LUKS here provides only confidentiality) but it is better
|
||||||
|
to not allow this situation in the first place.
|
||||||
|
|
||||||
|
(For more info see QubesOS Security Bulletin QSB-019-2015.)
|
||||||
|
|
||||||
|
* Properly support stdin "-" handling for luksAddKey for both new and old
|
||||||
|
keyfile parameters.
|
||||||
|
|
||||||
|
* If encrypted device is file-backed (it uses underlying loop device),
|
||||||
|
cryptsetup resize will try to resize underlying loop device as well.
|
||||||
|
(It can be used to grow up file-backed device in one step.)
|
||||||
|
|
||||||
|
* Cryptsetup now allows to use empty password through stdin pipe.
|
||||||
|
(Intended only for testing in scripts.)
|
||||||
|
|
||||||
|
Cryptsetup API NOTE:
|
||||||
|
|
||||||
|
Direct terminal handling and password calling callback for passphrase
|
||||||
|
entry will be removed from libcryptsetup in next major (2.x) version
|
||||||
|
(application should handle it itself).
|
||||||
|
It means that application have to always provide password in API calls.
|
||||||
|
|
||||||
|
Functions returning last error will be removed in next major version (2.x).
|
||||||
|
These functions did not work properly for early initialization errors
|
||||||
|
and application can implement better function easily using own error callback.
|
||||||
|
|
||||||
|
See comments in libcryptsetup.h for more info about deprecated functions.
|
||||||
81
docs/v1.7.0-ReleaseNotes
Normal file
81
docs/v1.7.0-ReleaseNotes
Normal file
@@ -0,0 +1,81 @@
|
|||||||
|
Cryptsetup 1.7.0 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
The cryptsetup 1.7 release changes defaults for LUKS,
|
||||||
|
there are no API changes.
|
||||||
|
|
||||||
|
Changes since version 1.6.8
|
||||||
|
|
||||||
|
* Default hash function is now SHA256 (used in key derivation function
|
||||||
|
and anti-forensic splitter).
|
||||||
|
|
||||||
|
Note that replacing SHA1 with SHA256 is not for security reasons.
|
||||||
|
(LUKS does not have problems even if collisions are found for SHA1,
|
||||||
|
for details see FAQ item 5.20).
|
||||||
|
|
||||||
|
Using SHA256 as default is mainly to prevent compatibility problems
|
||||||
|
on hardened systems where SHA1 is already be phased out.
|
||||||
|
|
||||||
|
Note that all checks (kernel crypto API availability check) now uses
|
||||||
|
SHA256 as well.
|
||||||
|
|
||||||
|
* Default iteration time for PBKDF2 is now 2 seconds.
|
||||||
|
|
||||||
|
Increasing iteration time is in combination with PBKDF2 benchmark
|
||||||
|
fixes a try to keep PBKDF2 iteration count still high enough and
|
||||||
|
also still acceptable for users.
|
||||||
|
|
||||||
|
N.B. Long term is to replace PBKDF2 algorithm with Password Hashing
|
||||||
|
Competition winner - Argon2.
|
||||||
|
|
||||||
|
Distributions can still change these defaults in compilation time.
|
||||||
|
|
||||||
|
You can change iteration time and used hash function in existing LUKS
|
||||||
|
header with cryptsetup-reencrypt utility even without full reencryption
|
||||||
|
of device (see --keep-key option).
|
||||||
|
|
||||||
|
* Fix PBKDF2 iteration benchmark for longer key sizes.
|
||||||
|
|
||||||
|
The previous PBKDF2 benchmark code did not take into account
|
||||||
|
output key length properly.
|
||||||
|
|
||||||
|
For SHA1 (with 160-bits output) and 256-bit keys (and longer)
|
||||||
|
it means that the final iteration value was higher than it should be.
|
||||||
|
|
||||||
|
For other hash algorithms (like SHA256 or SHA512) it caused
|
||||||
|
that iteration count was lower (in comparison to SHA1) than
|
||||||
|
expected for the requested time period.
|
||||||
|
|
||||||
|
The PBKDF2 benchmark code is now fixed to use the key size for
|
||||||
|
the formatted device (or default LUKS key size if running in informational
|
||||||
|
benchmark mode).
|
||||||
|
|
||||||
|
Thanks to A.Visconti, S.Bossi, A.Calo and H.Ragab
|
||||||
|
(http://www.club.di.unimi.it/) for point this out.
|
||||||
|
(Based on "What users should know about Full Disk Encryption
|
||||||
|
based on LUKS" paper to be presented on CANS2015).
|
||||||
|
|
||||||
|
* Remove experimental warning for reencrypt tool.
|
||||||
|
The strong request for full backup before using reencryption utility
|
||||||
|
still applies :)
|
||||||
|
|
||||||
|
* Add optional libpasswdqc support for new LUKS passwords.
|
||||||
|
|
||||||
|
If password is entered through terminal (no keyfile specified) and
|
||||||
|
cryptsetup is compiled with --enable-passwdqc[=/etc/passwdqc.conf],
|
||||||
|
configured system passwdqc settings are used to check password quality.
|
||||||
|
|
||||||
|
* Update FAQ document.
|
||||||
|
|
||||||
|
Cryptsetup API NOTE:
|
||||||
|
|
||||||
|
Direct terminal handling and password calling callback for passphrase
|
||||||
|
entry will be removed from libcryptsetup in next major (2.x) version
|
||||||
|
(application should handle it itself).
|
||||||
|
It means that application have to always provide password in API calls.
|
||||||
|
|
||||||
|
Functions returning last error will be removed in next major version (2.x).
|
||||||
|
These functions did not work properly for early initialization errors
|
||||||
|
and application can implement better function easily using own error callback.
|
||||||
|
|
||||||
|
See comments in libcryptsetup.h for more info about deprecated functions.
|
||||||
36
docs/v1.7.1-ReleaseNotes
Normal file
36
docs/v1.7.1-ReleaseNotes
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
Cryptsetup 1.7.1 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.7.0
|
||||||
|
|
||||||
|
* Code now uses kernel crypto API backend according to new
|
||||||
|
changes introduced in mainline kernel
|
||||||
|
|
||||||
|
While mainline kernel should contain backward compatible
|
||||||
|
changes, some stable series kernels do not contain fully
|
||||||
|
backported compatibility patches.
|
||||||
|
Without these patches most of cryptsetup operations
|
||||||
|
(like unlocking device) fail.
|
||||||
|
|
||||||
|
This change in cryptsetup ensures that all operations using
|
||||||
|
kernel crypto API works even on these kernels.
|
||||||
|
|
||||||
|
* The cryptsetup-reencrypt utility now properly detects removal
|
||||||
|
of underlying link to block device and does not remove
|
||||||
|
ongoing re-encryption log.
|
||||||
|
This allows proper recovery (resume) of reencrypt operation later.
|
||||||
|
|
||||||
|
NOTE: Never use /dev/disk/by-uuid/ path for reencryption utility,
|
||||||
|
this link disappears once the device metadata is temporarily
|
||||||
|
removed from device.
|
||||||
|
|
||||||
|
* Cryptsetup now allows special "-" (standard input) keyfile handling
|
||||||
|
even for TCRYPT (TrueCrypt and VeraCrypt compatible) devices.
|
||||||
|
|
||||||
|
* Cryptsetup now fails if there are more keyfiles specified
|
||||||
|
for non-TCRYPT device.
|
||||||
|
|
||||||
|
* The luksKillSlot command now does not suppress provided password
|
||||||
|
in batch mode (if password is wrong slot is not destroyed).
|
||||||
|
Note that not providing password in batch mode means that keyslot
|
||||||
|
is destroyed unconditionally.
|
||||||
37
docs/v1.7.2-ReleaseNotes
Normal file
37
docs/v1.7.2-ReleaseNotes
Normal file
@@ -0,0 +1,37 @@
|
|||||||
|
Cryptsetup 1.7.2 Release Notes
|
||||||
|
==============================
|
||||||
|
|
||||||
|
Changes since version 1.7.1
|
||||||
|
|
||||||
|
* Update LUKS documentation format.
|
||||||
|
Clarify fixed sector size and keyslots alignment.
|
||||||
|
|
||||||
|
* Support activation options for error handling modes in Linux kernel
|
||||||
|
dm-verity module:
|
||||||
|
|
||||||
|
--ignore-corruption - dm-verity just logs detected corruption
|
||||||
|
|
||||||
|
--restart-on-corruption - dm-verity restarts the kernel if corruption is detected
|
||||||
|
|
||||||
|
If the options above are not specified, default behavior for dm-verity remains.
|
||||||
|
Default is that I/O operation fails with I/O error if corrupted block is detected.
|
||||||
|
|
||||||
|
--ignore-zero-blocks - Instructs dm-verity to not verify blocks that are expected
|
||||||
|
to contain zeroes and always return zeroes directly instead.
|
||||||
|
|
||||||
|
NOTE that these options could have security or functional impacts,
|
||||||
|
do not use them without assessing the risks!
|
||||||
|
|
||||||
|
* Fix help text for cipher benchmark specification (mention --cipher option).
|
||||||
|
|
||||||
|
* Fix off-by-one error in maximum keyfile size.
|
||||||
|
Allow keyfiles up to compiled-in default and not that value minus one.
|
||||||
|
|
||||||
|
* Support resume of interrupted decryption in cryptsetup-reencrypt utility.
|
||||||
|
To resume decryption, LUKS device UUID (--uuid option) option must be used.
|
||||||
|
|
||||||
|
* Do not use direct-io for LUKS header with unaligned keyslots.
|
||||||
|
Such headers were used only by the first cryptsetup-luks-1.0.0 release (2005).
|
||||||
|
|
||||||
|
* Fix device block size detection to properly work on particular file-based
|
||||||
|
containers over underlying devices with 4k sectors.
|
||||||
@@ -1,38 +1,39 @@
|
|||||||
SUBDIRS = crypto_backend luks1 loopaes
|
SUBDIRS = crypto_backend luks1 loopaes verity tcrypt
|
||||||
|
|
||||||
moduledir = $(libdir)/cryptsetup
|
moduledir = $(libdir)/cryptsetup
|
||||||
|
|
||||||
pkgconfigdir = $(libdir)/pkgconfig
|
pkgconfigdir = $(libdir)/pkgconfig
|
||||||
pkgconfig_DATA = libcryptsetup.pc
|
pkgconfig_DATA = libcryptsetup.pc
|
||||||
|
|
||||||
INCLUDES = \
|
AM_CPPFLAGS = -include config.h \
|
||||||
-I$(top_srcdir) \
|
-I$(top_srcdir) \
|
||||||
-I$(top_srcdir)/lib/crypto_backend \
|
-I$(top_srcdir)/lib/crypto_backend \
|
||||||
-I$(top_srcdir)/lib/luks1 \
|
-I$(top_srcdir)/lib/luks1 \
|
||||||
-I$(top_srcdir)/lib/loopaes \
|
-I$(top_srcdir)/lib/loopaes \
|
||||||
|
-I$(top_srcdir)/lib/verity \
|
||||||
|
-I$(top_srcdir)/lib/tcrypt \
|
||||||
-DDATADIR=\""$(datadir)"\" \
|
-DDATADIR=\""$(datadir)"\" \
|
||||||
-DLIBDIR=\""$(libdir)"\" \
|
-DLIBDIR=\""$(libdir)"\" \
|
||||||
-DPREFIX=\""$(prefix)"\" \
|
-DPREFIX=\""$(prefix)"\" \
|
||||||
-DSYSCONFDIR=\""$(sysconfdir)"\" \
|
-DSYSCONFDIR=\""$(sysconfdir)"\" \
|
||||||
-DVERSION=\""$(VERSION)"\" \
|
-DVERSION=\""$(VERSION)"\"
|
||||||
-D_GNU_SOURCE \
|
|
||||||
-D_LARGEFILE64_SOURCE \
|
|
||||||
-D_FILE_OFFSET_BITS=64
|
|
||||||
|
|
||||||
lib_LTLIBRARIES = libcryptsetup.la
|
lib_LTLIBRARIES = libcryptsetup.la
|
||||||
|
|
||||||
common_ldadd = \
|
common_ldadd = \
|
||||||
crypto_backend/libcrypto_backend.la \
|
crypto_backend/libcrypto_backend.la \
|
||||||
luks1/libluks1.la \
|
luks1/libluks1.la \
|
||||||
loopaes/libloopaes.la
|
loopaes/libloopaes.la \
|
||||||
|
verity/libverity.la \
|
||||||
|
tcrypt/libtcrypt.la
|
||||||
|
|
||||||
libcryptsetup_la_DEPENDENCIES = $(common_ldadd) libcryptsetup.sym
|
libcryptsetup_la_DEPENDENCIES = $(common_ldadd) libcryptsetup.sym
|
||||||
|
|
||||||
libcryptsetup_la_LDFLAGS = \
|
libcryptsetup_la_LDFLAGS = $(AM_LDFLAGS) -no-undefined \
|
||||||
-Wl,--version-script=$(top_srcdir)/lib/libcryptsetup.sym \
|
-Wl,--version-script=$(top_srcdir)/lib/libcryptsetup.sym \
|
||||||
-version-info @LIBCRYPTSETUP_VERSION_INFO@
|
-version-info @LIBCRYPTSETUP_VERSION_INFO@
|
||||||
|
|
||||||
libcryptsetup_la_CFLAGS = -Wall @CRYPTO_CFLAGS@
|
libcryptsetup_la_CFLAGS = -Wall $(AM_CFLAGS) @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
libcryptsetup_la_LIBADD = \
|
libcryptsetup_la_LIBADD = \
|
||||||
@UUID_LIBS@ \
|
@UUID_LIBS@ \
|
||||||
@@ -44,16 +45,20 @@ libcryptsetup_la_LIBADD = \
|
|||||||
libcryptsetup_la_SOURCES = \
|
libcryptsetup_la_SOURCES = \
|
||||||
setup.c \
|
setup.c \
|
||||||
internal.h \
|
internal.h \
|
||||||
|
bitops.h \
|
||||||
nls.h \
|
nls.h \
|
||||||
libcryptsetup.h \
|
libcryptsetup.h \
|
||||||
utils.c \
|
utils.c \
|
||||||
|
utils_benchmark.c \
|
||||||
utils_crypt.c \
|
utils_crypt.c \
|
||||||
utils_crypt.h \
|
utils_crypt.h \
|
||||||
utils_debug.c \
|
|
||||||
utils_loop.c \
|
utils_loop.c \
|
||||||
utils_loop.h \
|
utils_loop.h \
|
||||||
utils_devpath.c \
|
utils_devpath.c \
|
||||||
utils_wipe.c \
|
utils_wipe.c \
|
||||||
|
utils_fips.c \
|
||||||
|
utils_fips.h \
|
||||||
|
utils_device.c \
|
||||||
libdevmapper.c \
|
libdevmapper.c \
|
||||||
utils_dm.h \
|
utils_dm.h \
|
||||||
volumekey.c \
|
volumekey.c \
|
||||||
|
|||||||
123
lib/bitops.h
Normal file
123
lib/bitops.h
Normal file
@@ -0,0 +1,123 @@
|
|||||||
|
/*
|
||||||
|
* No copyright is claimed. This code is in the public domain; do with
|
||||||
|
* it what you wish.
|
||||||
|
*
|
||||||
|
* Written by Karel Zak <kzak@redhat.com>
|
||||||
|
*/
|
||||||
|
#ifndef BITOPS_H
|
||||||
|
#define BITOPS_H
|
||||||
|
|
||||||
|
#include <stdint.h>
|
||||||
|
#include <sys/param.h>
|
||||||
|
|
||||||
|
#if defined(HAVE_BYTESWAP_H)
|
||||||
|
# include <byteswap.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#if defined(HAVE_ENDIAN_H)
|
||||||
|
# include <endian.h>
|
||||||
|
#elif defined(HAVE_SYS_ENDIAN_H) /* BSDs have them here */
|
||||||
|
# include <sys/endian.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#if defined(__OpenBSD__)
|
||||||
|
# include <sys/types.h>
|
||||||
|
# define be16toh(x) betoh16(x)
|
||||||
|
# define be32toh(x) betoh32(x)
|
||||||
|
# define be64toh(x) betoh64(x)
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Fallbacks
|
||||||
|
*/
|
||||||
|
#ifndef bswap_16
|
||||||
|
# define bswap_16(x) ((((x) & 0x00FF) << 8) | \
|
||||||
|
(((x) & 0xFF00) >> 8))
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#ifndef bswap_32
|
||||||
|
# define bswap_32(x) ((((x) & 0x000000FF) << 24) | \
|
||||||
|
(((x) & 0x0000FF00) << 8) | \
|
||||||
|
(((x) & 0x00FF0000) >> 8) | \
|
||||||
|
(((x) & 0xFF000000) >> 24))
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#ifndef bswap_64
|
||||||
|
# define bswap_64(x) ((((x) & 0x00000000000000FFULL) << 56) | \
|
||||||
|
(((x) & 0x000000000000FF00ULL) << 40) | \
|
||||||
|
(((x) & 0x0000000000FF0000ULL) << 24) | \
|
||||||
|
(((x) & 0x00000000FF000000ULL) << 8) | \
|
||||||
|
(((x) & 0x000000FF00000000ULL) >> 8) | \
|
||||||
|
(((x) & 0x0000FF0000000000ULL) >> 24) | \
|
||||||
|
(((x) & 0x00FF000000000000ULL) >> 40) | \
|
||||||
|
(((x) & 0xFF00000000000000ULL) >> 56))
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#ifndef htobe16
|
||||||
|
# if !defined(WORDS_BIGENDIAN)
|
||||||
|
# define htobe16(x) bswap_16 (x)
|
||||||
|
# define htole16(x) (x)
|
||||||
|
# define be16toh(x) bswap_16 (x)
|
||||||
|
# define le16toh(x) (x)
|
||||||
|
# define htobe32(x) bswap_32 (x)
|
||||||
|
# define htole32(x) (x)
|
||||||
|
# define be32toh(x) bswap_32 (x)
|
||||||
|
# define le32toh(x) (x)
|
||||||
|
# define htobe64(x) bswap_64 (x)
|
||||||
|
# define htole64(x) (x)
|
||||||
|
# define be64toh(x) bswap_64 (x)
|
||||||
|
# define le64toh(x) (x)
|
||||||
|
# else
|
||||||
|
# define htobe16(x) (x)
|
||||||
|
# define htole16(x) bswap_16 (x)
|
||||||
|
# define be16toh(x) (x)
|
||||||
|
# define le16toh(x) bswap_16 (x)
|
||||||
|
# define htobe32(x) (x)
|
||||||
|
# define htole32(x) bswap_32 (x)
|
||||||
|
# define be32toh(x) (x)
|
||||||
|
# define le32toh(x) bswap_32 (x)
|
||||||
|
# define htobe64(x) (x)
|
||||||
|
# define htole64(x) bswap_64 (x)
|
||||||
|
# define be64toh(x) (x)
|
||||||
|
# define le64toh(x) bswap_64 (x)
|
||||||
|
# endif
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Byte swab macros (based on linux/byteorder/swab.h)
|
||||||
|
*/
|
||||||
|
#define swab16(x) bswap_16(x)
|
||||||
|
#define swab32(x) bswap_32(x)
|
||||||
|
#define swab64(x) bswap_64(x)
|
||||||
|
|
||||||
|
#define cpu_to_le16(x) ((uint16_t) htole16(x))
|
||||||
|
#define cpu_to_le32(x) ((uint32_t) htole32(x))
|
||||||
|
#define cpu_to_le64(x) ((uint64_t) htole64(x))
|
||||||
|
|
||||||
|
#define cpu_to_be16(x) ((uint16_t) htobe16(x))
|
||||||
|
#define cpu_to_be32(x) ((uint32_t) htobe32(x))
|
||||||
|
#define cpu_to_be64(x) ((uint64_t) htobe64(x))
|
||||||
|
|
||||||
|
#define le16_to_cpu(x) ((uint16_t) le16toh(x))
|
||||||
|
#define le32_to_cpu(x) ((uint32_t) le32toh(x))
|
||||||
|
#define le64_to_cpu(x) ((uint64_t) le64toh(x))
|
||||||
|
|
||||||
|
#define be16_to_cpu(x) ((uint16_t) be16toh(x))
|
||||||
|
#define be32_to_cpu(x) ((uint32_t) be32toh(x))
|
||||||
|
#define be64_to_cpu(x) ((uint64_t) be64toh(x))
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Bit map related macros. Usually provided by libc.
|
||||||
|
*/
|
||||||
|
#ifndef NBBY
|
||||||
|
# define NBBY CHAR_BIT
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#ifndef setbit
|
||||||
|
# define setbit(a,i) ((a)[(i)/NBBY] |= 1<<((i)%NBBY))
|
||||||
|
# define clrbit(a,i) ((a)[(i)/NBBY] &= ~(1<<((i)%NBBY)))
|
||||||
|
# define isset(a,i) ((a)[(i)/NBBY] & (1<<((i)%NBBY)))
|
||||||
|
# define isclr(a,i) (((a)[(i)/NBBY] & (1<<((i)%NBBY))) == 0)
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#endif /* BITOPS_H */
|
||||||
@@ -1,12 +1,14 @@
|
|||||||
/*
|
/*
|
||||||
* cryptsetup plain device helper functions
|
* cryptsetup plain device helper functions
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004, Christophe Saout <christophe@saout.de>
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
* Copyright (C) 2010-2011 Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012 Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2012, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -15,15 +17,15 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <stdlib.h>
|
#include <stdio.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
|
|
||||||
|
#include "libcryptsetup.h"
|
||||||
#include "internal.h"
|
#include "internal.h"
|
||||||
#include "crypto_backend.h"
|
|
||||||
|
|
||||||
static int hash(const char *hash_name, size_t key_size, char *key,
|
static int hash(const char *hash_name, size_t key_size, char *key,
|
||||||
size_t passphrase_size, const char *passphrase)
|
size_t passphrase_size, const char *passphrase)
|
||||||
@@ -81,7 +83,11 @@ int crypt_plain_hash(struct crypt_device *ctx __attribute__((unused)),
|
|||||||
/* hash[:hash_length] */
|
/* hash[:hash_length] */
|
||||||
if ((s = strchr(hash_name_buf, ':'))) {
|
if ((s = strchr(hash_name_buf, ':'))) {
|
||||||
*s = '\0';
|
*s = '\0';
|
||||||
hash_size = atoi(++s);
|
s++;
|
||||||
|
if (!*s || sscanf(s, "%zd", &hash_size) != 1) {
|
||||||
|
log_dbg("Hash length is not a number");
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
if (hash_size > key_size) {
|
if (hash_size > key_size) {
|
||||||
log_dbg("Hash length %zd > key length %zd",
|
log_dbg("Hash length %zd > key length %zd",
|
||||||
hash_size, key_size);
|
hash_size, key_size);
|
||||||
@@ -93,7 +99,16 @@ int crypt_plain_hash(struct crypt_device *ctx __attribute__((unused)),
|
|||||||
pad_size = 0;
|
pad_size = 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
r = hash(hash_name_buf, hash_size, key, passphrase_size, passphrase);
|
/* No hash, copy passphrase directly */
|
||||||
|
if (!strcmp(hash_name_buf, "plain")) {
|
||||||
|
if (passphrase_size < hash_size) {
|
||||||
|
log_dbg("Too short plain passphrase.");
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
memcpy(key, passphrase, hash_size);
|
||||||
|
r = 0;
|
||||||
|
} else
|
||||||
|
r = hash(hash_name_buf, hash_size, key, passphrase_size, passphrase);
|
||||||
|
|
||||||
if (r == 0 && pad_size)
|
if (r == 0 && pad_size)
|
||||||
memset(key + hash_size, 0, pad_size);
|
memset(key + hash_size, 0, pad_size);
|
||||||
|
|||||||
@@ -2,9 +2,10 @@ moduledir = $(libdir)/cryptsetup
|
|||||||
|
|
||||||
noinst_LTLIBRARIES = libcrypto_backend.la
|
noinst_LTLIBRARIES = libcrypto_backend.la
|
||||||
|
|
||||||
libcrypto_backend_la_CFLAGS = -Wall @CRYPTO_CFLAGS@
|
libcrypto_backend_la_CFLAGS = $(AM_CFLAGS) -Wall @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
libcrypto_backend_la_SOURCES = crypto_backend.h
|
libcrypto_backend_la_SOURCES = crypto_backend.h \
|
||||||
|
crypto_cipher_kernel.c crypto_storage.c pbkdf_check.c crc32.c
|
||||||
|
|
||||||
if CRYPTO_BACKEND_GCRYPT
|
if CRYPTO_BACKEND_GCRYPT
|
||||||
libcrypto_backend_la_SOURCES += crypto_gcrypt.c
|
libcrypto_backend_la_SOURCES += crypto_gcrypt.c
|
||||||
@@ -22,4 +23,8 @@ if CRYPTO_BACKEND_NETTLE
|
|||||||
libcrypto_backend_la_SOURCES += crypto_nettle.c
|
libcrypto_backend_la_SOURCES += crypto_nettle.c
|
||||||
endif
|
endif
|
||||||
|
|
||||||
INCLUDES = -D_GNU_SOURCE -I$(top_srcdir)/lib
|
if CRYPTO_INTERNAL_PBKDF2
|
||||||
|
libcrypto_backend_la_SOURCES += pbkdf2_generic.c
|
||||||
|
endif
|
||||||
|
|
||||||
|
AM_CPPFLAGS = -include config.h -I$(top_srcdir)/lib
|
||||||
|
|||||||
116
lib/crypto_backend/crc32.c
Normal file
116
lib/crypto_backend/crc32.c
Normal file
@@ -0,0 +1,116 @@
|
|||||||
|
/*
|
||||||
|
* COPYRIGHT (C) 1986 Gary S. Brown. You may use this program, or
|
||||||
|
* code or tables extracted from it, as desired without restriction.
|
||||||
|
*
|
||||||
|
* First, the polynomial itself and its table of feedback terms. The
|
||||||
|
* polynomial is
|
||||||
|
* X^32+X^26+X^23+X^22+X^16+X^12+X^11+X^10+X^8+X^7+X^5+X^4+X^2+X^1+X^0
|
||||||
|
*
|
||||||
|
* Note that we take it "backwards" and put the highest-order term in
|
||||||
|
* the lowest-order bit. The X^32 term is "implied"; the LSB is the
|
||||||
|
* X^31 term, etc. The X^0 term (usually shown as "+1") results in
|
||||||
|
* the MSB being 1.
|
||||||
|
*
|
||||||
|
* Note that the usual hardware shift register implementation, which
|
||||||
|
* is what we're using (we're merely optimizing it by doing eight-bit
|
||||||
|
* chunks at a time) shifts bits into the lowest-order term. In our
|
||||||
|
* implementation, that means shifting towards the right. Why do we
|
||||||
|
* do it this way? Because the calculated CRC must be transmitted in
|
||||||
|
* order from highest-order term to lowest-order term. UARTs transmit
|
||||||
|
* characters in order from LSB to MSB. By storing the CRC this way,
|
||||||
|
* we hand it to the UART in the order low-byte to high-byte; the UART
|
||||||
|
* sends each low-bit to hight-bit; and the result is transmission bit
|
||||||
|
* by bit from highest- to lowest-order term without requiring any bit
|
||||||
|
* shuffling on our part. Reception works similarly.
|
||||||
|
*
|
||||||
|
* The feedback terms table consists of 256, 32-bit entries. Notes
|
||||||
|
*
|
||||||
|
* The table can be generated at runtime if desired; code to do so
|
||||||
|
* is shown later. It might not be obvious, but the feedback
|
||||||
|
* terms simply represent the results of eight shift/xor opera-
|
||||||
|
* tions for all combinations of data and CRC register values.
|
||||||
|
*
|
||||||
|
* The values must be right-shifted by eight bits by the "updcrc"
|
||||||
|
* logic; the shift must be unsigned (bring in zeroes). On some
|
||||||
|
* hardware you could probably optimize the shift in assembler by
|
||||||
|
* using byte-swap instructions.
|
||||||
|
* polynomial $edb88320
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <stdio.h>
|
||||||
|
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
|
||||||
|
static const uint32_t crc32_tab[] = {
|
||||||
|
0x00000000L, 0x77073096L, 0xee0e612cL, 0x990951baL, 0x076dc419L,
|
||||||
|
0x706af48fL, 0xe963a535L, 0x9e6495a3L, 0x0edb8832L, 0x79dcb8a4L,
|
||||||
|
0xe0d5e91eL, 0x97d2d988L, 0x09b64c2bL, 0x7eb17cbdL, 0xe7b82d07L,
|
||||||
|
0x90bf1d91L, 0x1db71064L, 0x6ab020f2L, 0xf3b97148L, 0x84be41deL,
|
||||||
|
0x1adad47dL, 0x6ddde4ebL, 0xf4d4b551L, 0x83d385c7L, 0x136c9856L,
|
||||||
|
0x646ba8c0L, 0xfd62f97aL, 0x8a65c9ecL, 0x14015c4fL, 0x63066cd9L,
|
||||||
|
0xfa0f3d63L, 0x8d080df5L, 0x3b6e20c8L, 0x4c69105eL, 0xd56041e4L,
|
||||||
|
0xa2677172L, 0x3c03e4d1L, 0x4b04d447L, 0xd20d85fdL, 0xa50ab56bL,
|
||||||
|
0x35b5a8faL, 0x42b2986cL, 0xdbbbc9d6L, 0xacbcf940L, 0x32d86ce3L,
|
||||||
|
0x45df5c75L, 0xdcd60dcfL, 0xabd13d59L, 0x26d930acL, 0x51de003aL,
|
||||||
|
0xc8d75180L, 0xbfd06116L, 0x21b4f4b5L, 0x56b3c423L, 0xcfba9599L,
|
||||||
|
0xb8bda50fL, 0x2802b89eL, 0x5f058808L, 0xc60cd9b2L, 0xb10be924L,
|
||||||
|
0x2f6f7c87L, 0x58684c11L, 0xc1611dabL, 0xb6662d3dL, 0x76dc4190L,
|
||||||
|
0x01db7106L, 0x98d220bcL, 0xefd5102aL, 0x71b18589L, 0x06b6b51fL,
|
||||||
|
0x9fbfe4a5L, 0xe8b8d433L, 0x7807c9a2L, 0x0f00f934L, 0x9609a88eL,
|
||||||
|
0xe10e9818L, 0x7f6a0dbbL, 0x086d3d2dL, 0x91646c97L, 0xe6635c01L,
|
||||||
|
0x6b6b51f4L, 0x1c6c6162L, 0x856530d8L, 0xf262004eL, 0x6c0695edL,
|
||||||
|
0x1b01a57bL, 0x8208f4c1L, 0xf50fc457L, 0x65b0d9c6L, 0x12b7e950L,
|
||||||
|
0x8bbeb8eaL, 0xfcb9887cL, 0x62dd1ddfL, 0x15da2d49L, 0x8cd37cf3L,
|
||||||
|
0xfbd44c65L, 0x4db26158L, 0x3ab551ceL, 0xa3bc0074L, 0xd4bb30e2L,
|
||||||
|
0x4adfa541L, 0x3dd895d7L, 0xa4d1c46dL, 0xd3d6f4fbL, 0x4369e96aL,
|
||||||
|
0x346ed9fcL, 0xad678846L, 0xda60b8d0L, 0x44042d73L, 0x33031de5L,
|
||||||
|
0xaa0a4c5fL, 0xdd0d7cc9L, 0x5005713cL, 0x270241aaL, 0xbe0b1010L,
|
||||||
|
0xc90c2086L, 0x5768b525L, 0x206f85b3L, 0xb966d409L, 0xce61e49fL,
|
||||||
|
0x5edef90eL, 0x29d9c998L, 0xb0d09822L, 0xc7d7a8b4L, 0x59b33d17L,
|
||||||
|
0x2eb40d81L, 0xb7bd5c3bL, 0xc0ba6cadL, 0xedb88320L, 0x9abfb3b6L,
|
||||||
|
0x03b6e20cL, 0x74b1d29aL, 0xead54739L, 0x9dd277afL, 0x04db2615L,
|
||||||
|
0x73dc1683L, 0xe3630b12L, 0x94643b84L, 0x0d6d6a3eL, 0x7a6a5aa8L,
|
||||||
|
0xe40ecf0bL, 0x9309ff9dL, 0x0a00ae27L, 0x7d079eb1L, 0xf00f9344L,
|
||||||
|
0x8708a3d2L, 0x1e01f268L, 0x6906c2feL, 0xf762575dL, 0x806567cbL,
|
||||||
|
0x196c3671L, 0x6e6b06e7L, 0xfed41b76L, 0x89d32be0L, 0x10da7a5aL,
|
||||||
|
0x67dd4accL, 0xf9b9df6fL, 0x8ebeeff9L, 0x17b7be43L, 0x60b08ed5L,
|
||||||
|
0xd6d6a3e8L, 0xa1d1937eL, 0x38d8c2c4L, 0x4fdff252L, 0xd1bb67f1L,
|
||||||
|
0xa6bc5767L, 0x3fb506ddL, 0x48b2364bL, 0xd80d2bdaL, 0xaf0a1b4cL,
|
||||||
|
0x36034af6L, 0x41047a60L, 0xdf60efc3L, 0xa867df55L, 0x316e8eefL,
|
||||||
|
0x4669be79L, 0xcb61b38cL, 0xbc66831aL, 0x256fd2a0L, 0x5268e236L,
|
||||||
|
0xcc0c7795L, 0xbb0b4703L, 0x220216b9L, 0x5505262fL, 0xc5ba3bbeL,
|
||||||
|
0xb2bd0b28L, 0x2bb45a92L, 0x5cb36a04L, 0xc2d7ffa7L, 0xb5d0cf31L,
|
||||||
|
0x2cd99e8bL, 0x5bdeae1dL, 0x9b64c2b0L, 0xec63f226L, 0x756aa39cL,
|
||||||
|
0x026d930aL, 0x9c0906a9L, 0xeb0e363fL, 0x72076785L, 0x05005713L,
|
||||||
|
0x95bf4a82L, 0xe2b87a14L, 0x7bb12baeL, 0x0cb61b38L, 0x92d28e9bL,
|
||||||
|
0xe5d5be0dL, 0x7cdcefb7L, 0x0bdbdf21L, 0x86d3d2d4L, 0xf1d4e242L,
|
||||||
|
0x68ddb3f8L, 0x1fda836eL, 0x81be16cdL, 0xf6b9265bL, 0x6fb077e1L,
|
||||||
|
0x18b74777L, 0x88085ae6L, 0xff0f6a70L, 0x66063bcaL, 0x11010b5cL,
|
||||||
|
0x8f659effL, 0xf862ae69L, 0x616bffd3L, 0x166ccf45L, 0xa00ae278L,
|
||||||
|
0xd70dd2eeL, 0x4e048354L, 0x3903b3c2L, 0xa7672661L, 0xd06016f7L,
|
||||||
|
0x4969474dL, 0x3e6e77dbL, 0xaed16a4aL, 0xd9d65adcL, 0x40df0b66L,
|
||||||
|
0x37d83bf0L, 0xa9bcae53L, 0xdebb9ec5L, 0x47b2cf7fL, 0x30b5ffe9L,
|
||||||
|
0xbdbdf21cL, 0xcabac28aL, 0x53b39330L, 0x24b4a3a6L, 0xbad03605L,
|
||||||
|
0xcdd70693L, 0x54de5729L, 0x23d967bfL, 0xb3667a2eL, 0xc4614ab8L,
|
||||||
|
0x5d681b02L, 0x2a6f2b94L, 0xb40bbe37L, 0xc30c8ea1L, 0x5a05df1bL,
|
||||||
|
0x2d02ef8dL
|
||||||
|
};
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This a generic crc32() function, it takes seed as an argument,
|
||||||
|
* and does __not__ xor at the end. Then individual users can do
|
||||||
|
* whatever they need.
|
||||||
|
*/
|
||||||
|
uint32_t crypt_crc32(uint32_t seed, const unsigned char *buf, size_t len)
|
||||||
|
{
|
||||||
|
uint32_t crc = seed;
|
||||||
|
const unsigned char *p = buf;
|
||||||
|
|
||||||
|
while(len-- > 0)
|
||||||
|
crc = crc32_tab[(crc ^ *p++) & 0xff] ^ (crc >> 8);
|
||||||
|
|
||||||
|
return crc;
|
||||||
|
}
|
||||||
|
|
||||||
@@ -1,17 +1,41 @@
|
|||||||
|
/*
|
||||||
|
* crypto backend implementation
|
||||||
|
*
|
||||||
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2014, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
#ifndef _CRYPTO_BACKEND_H
|
#ifndef _CRYPTO_BACKEND_H
|
||||||
#define _CRYPTO_BACKEND_H
|
#define _CRYPTO_BACKEND_H
|
||||||
|
|
||||||
#include "libcryptsetup.h"
|
#include <stdint.h>
|
||||||
#include "internal.h"
|
#include <string.h>
|
||||||
|
|
||||||
|
struct crypt_device;
|
||||||
struct crypt_hash;
|
struct crypt_hash;
|
||||||
struct crypt_hmac;
|
struct crypt_hmac;
|
||||||
|
struct crypt_cipher;
|
||||||
|
struct crypt_storage;
|
||||||
|
|
||||||
int crypt_backend_init(struct crypt_device *ctx);
|
int crypt_backend_init(struct crypt_device *ctx);
|
||||||
|
|
||||||
#define CRYPT_BACKEND_KERNEL (1 << 0) /* Crypto uses kernel part, for benchmark */
|
#define CRYPT_BACKEND_KERNEL (1 << 0) /* Crypto uses kernel part, for benchmark */
|
||||||
|
|
||||||
uint32_t crypt_backend_flags(void);
|
uint32_t crypt_backend_flags(void);
|
||||||
|
const char *crypt_backend_version(void);
|
||||||
|
|
||||||
/* HASH */
|
/* HASH */
|
||||||
int crypt_hash_size(const char *name);
|
int crypt_hash_size(const char *name);
|
||||||
@@ -28,4 +52,61 @@ int crypt_hmac_write(struct crypt_hmac *ctx, const char *buffer, size_t length);
|
|||||||
int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length);
|
int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length);
|
||||||
int crypt_hmac_destroy(struct crypt_hmac *ctx);
|
int crypt_hmac_destroy(struct crypt_hmac *ctx);
|
||||||
|
|
||||||
|
/* RNG (if fips paramater set, must provide FIPS compliance) */
|
||||||
|
enum { CRYPT_RND_NORMAL = 0, CRYPT_RND_KEY = 1, CRYPT_RND_SALT = 2 };
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips);
|
||||||
|
|
||||||
|
/* PBKDF*/
|
||||||
|
int crypt_pbkdf_check(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
size_t key_length, uint64_t *iter_secs);
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations);
|
||||||
|
|
||||||
|
#if USE_INTERNAL_PBKDF2
|
||||||
|
/* internal PBKDF2 implementation */
|
||||||
|
int pkcs5_pbkdf2(const char *hash,
|
||||||
|
const char *P, size_t Plen,
|
||||||
|
const char *S, size_t Slen,
|
||||||
|
unsigned int c,
|
||||||
|
unsigned int dkLen, char *DK,
|
||||||
|
unsigned int hash_block_size);
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/* CRC32 */
|
||||||
|
uint32_t crypt_crc32(uint32_t seed, const unsigned char *buf, size_t len);
|
||||||
|
|
||||||
|
/* ciphers */
|
||||||
|
int crypt_cipher_blocksize(const char *name);
|
||||||
|
int crypt_cipher_init(struct crypt_cipher **ctx, const char *name,
|
||||||
|
const char *mode, const void *buffer, size_t length);
|
||||||
|
int crypt_cipher_destroy(struct crypt_cipher *ctx);
|
||||||
|
int crypt_cipher_encrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length);
|
||||||
|
int crypt_cipher_decrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length);
|
||||||
|
|
||||||
|
/* storage encryption wrappers */
|
||||||
|
int crypt_storage_init(struct crypt_storage **ctx, uint64_t sector_start,
|
||||||
|
const char *cipher, const char *cipher_mode,
|
||||||
|
char *key, size_t key_length);
|
||||||
|
int crypt_storage_destroy(struct crypt_storage *ctx);
|
||||||
|
int crypt_storage_decrypt(struct crypt_storage *ctx, uint64_t sector,
|
||||||
|
size_t count, char *buffer);
|
||||||
|
int crypt_storage_encrypt(struct crypt_storage *ctx, uint64_t sector,
|
||||||
|
size_t count, char *buffer);
|
||||||
|
|
||||||
|
/* Memzero helper (memset on stack can be optimized out) */
|
||||||
|
static inline void crypt_backend_memzero(void *s, size_t n)
|
||||||
|
{
|
||||||
|
volatile uint8_t *p = (volatile uint8_t *)s;
|
||||||
|
while(n--) *p++ = 0;
|
||||||
|
}
|
||||||
|
|
||||||
#endif /* _CRYPTO_BACKEND_H */
|
#endif /* _CRYPTO_BACKEND_H */
|
||||||
|
|||||||
269
lib/crypto_backend/crypto_cipher_kernel.c
Normal file
269
lib/crypto_backend/crypto_cipher_kernel.c
Normal file
@@ -0,0 +1,269 @@
|
|||||||
|
/*
|
||||||
|
* Linux kernel userspace API crypto backend implementation (skcipher)
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2016, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
#include <sys/socket.h>
|
||||||
|
#include <sys/stat.h>
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
#ifdef ENABLE_AF_ALG
|
||||||
|
|
||||||
|
#include <linux/if_alg.h>
|
||||||
|
|
||||||
|
#ifndef AF_ALG
|
||||||
|
#define AF_ALG 38
|
||||||
|
#endif
|
||||||
|
#ifndef SOL_ALG
|
||||||
|
#define SOL_ALG 279
|
||||||
|
#endif
|
||||||
|
|
||||||
|
struct crypt_cipher {
|
||||||
|
int tfmfd;
|
||||||
|
int opfd;
|
||||||
|
};
|
||||||
|
|
||||||
|
struct cipher_alg {
|
||||||
|
const char *name;
|
||||||
|
int blocksize;
|
||||||
|
};
|
||||||
|
|
||||||
|
/* FIXME: Getting block size should be dynamic from cipher backend. */
|
||||||
|
static struct cipher_alg cipher_algs[] = {
|
||||||
|
{ "cipher_null", 16 },
|
||||||
|
{ "aes", 16 },
|
||||||
|
{ "serpent", 16 },
|
||||||
|
{ "twofish", 16 },
|
||||||
|
{ "anubis", 16 },
|
||||||
|
{ "blowfish", 8 },
|
||||||
|
{ "camellia", 16 },
|
||||||
|
{ "cast5", 8 },
|
||||||
|
{ "cast6", 16 },
|
||||||
|
{ "des", 8 },
|
||||||
|
{ "des3_ede", 8 },
|
||||||
|
{ "khazad", 8 },
|
||||||
|
{ "seed", 16 },
|
||||||
|
{ "tea", 8 },
|
||||||
|
{ "xtea", 8 },
|
||||||
|
{ NULL, 0 }
|
||||||
|
};
|
||||||
|
|
||||||
|
static struct cipher_alg *_get_alg(const char *name)
|
||||||
|
{
|
||||||
|
int i = 0;
|
||||||
|
|
||||||
|
while (name && cipher_algs[i].name) {
|
||||||
|
if (!strcasecmp(name, cipher_algs[i].name))
|
||||||
|
return &cipher_algs[i];
|
||||||
|
i++;
|
||||||
|
}
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_blocksize(const char *name)
|
||||||
|
{
|
||||||
|
struct cipher_alg *ca = _get_alg(name);
|
||||||
|
|
||||||
|
return ca ? ca->blocksize : -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* ciphers
|
||||||
|
*
|
||||||
|
* ENOENT - algorithm not available
|
||||||
|
* ENOTSUP - AF_ALG family not available
|
||||||
|
* (but cannot check specificaly for skcipher API)
|
||||||
|
*/
|
||||||
|
int crypt_cipher_init(struct crypt_cipher **ctx, const char *name,
|
||||||
|
const char *mode, const void *buffer, size_t length)
|
||||||
|
{
|
||||||
|
struct crypt_cipher *h;
|
||||||
|
struct sockaddr_alg sa = {
|
||||||
|
.salg_family = AF_ALG,
|
||||||
|
.salg_type = "skcipher",
|
||||||
|
};
|
||||||
|
|
||||||
|
h = malloc(sizeof(*h));
|
||||||
|
if (!h)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
snprintf((char *)sa.salg_name, sizeof(sa.salg_name),
|
||||||
|
"%s(%s)", mode, name);
|
||||||
|
|
||||||
|
h->opfd = -1;
|
||||||
|
h->tfmfd = socket(AF_ALG, SOCK_SEQPACKET, 0);
|
||||||
|
if (h->tfmfd < 0) {
|
||||||
|
crypt_cipher_destroy(h);
|
||||||
|
return -ENOTSUP;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (bind(h->tfmfd, (struct sockaddr *)&sa, sizeof(sa)) < 0) {
|
||||||
|
crypt_cipher_destroy(h);
|
||||||
|
return -ENOENT;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!strcmp(name, "cipher_null"))
|
||||||
|
length = 0;
|
||||||
|
|
||||||
|
if (setsockopt(h->tfmfd, SOL_ALG, ALG_SET_KEY, buffer, length) < 0) {
|
||||||
|
crypt_cipher_destroy(h);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
h->opfd = accept(h->tfmfd, NULL, 0);
|
||||||
|
if (h->opfd < 0) {
|
||||||
|
crypt_cipher_destroy(h);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
*ctx = h;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* The in/out should be aligned to page boundary */
|
||||||
|
static int crypt_cipher_crypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length,
|
||||||
|
uint32_t direction)
|
||||||
|
{
|
||||||
|
int r = 0;
|
||||||
|
ssize_t len;
|
||||||
|
struct af_alg_iv *alg_iv;
|
||||||
|
struct cmsghdr *header;
|
||||||
|
uint32_t *type;
|
||||||
|
struct iovec iov = {
|
||||||
|
.iov_base = (void*)(uintptr_t)in,
|
||||||
|
.iov_len = length,
|
||||||
|
};
|
||||||
|
int iv_msg_size = iv ? CMSG_SPACE(sizeof(*alg_iv) + iv_length) : 0;
|
||||||
|
char buffer[CMSG_SPACE(sizeof(*type)) + iv_msg_size];
|
||||||
|
struct msghdr msg = {
|
||||||
|
.msg_control = buffer,
|
||||||
|
.msg_controllen = sizeof(buffer),
|
||||||
|
.msg_iov = &iov,
|
||||||
|
.msg_iovlen = 1,
|
||||||
|
};
|
||||||
|
|
||||||
|
if (!in || !out || !length)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if ((!iv && iv_length) || (iv && !iv_length))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
memset(buffer, 0, sizeof(buffer));
|
||||||
|
|
||||||
|
/* Set encrypt/decrypt operation */
|
||||||
|
header = CMSG_FIRSTHDR(&msg);
|
||||||
|
if (!header)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
header->cmsg_level = SOL_ALG;
|
||||||
|
header->cmsg_type = ALG_SET_OP;
|
||||||
|
header->cmsg_len = CMSG_LEN(sizeof(*type));
|
||||||
|
type = (void*)CMSG_DATA(header);
|
||||||
|
*type = direction;
|
||||||
|
|
||||||
|
/* Set IV */
|
||||||
|
if (iv) {
|
||||||
|
header = CMSG_NXTHDR(&msg, header);
|
||||||
|
header->cmsg_level = SOL_ALG;
|
||||||
|
header->cmsg_type = ALG_SET_IV;
|
||||||
|
header->cmsg_len = iv_msg_size;
|
||||||
|
alg_iv = (void*)CMSG_DATA(header);
|
||||||
|
alg_iv->ivlen = iv_length;
|
||||||
|
memcpy(alg_iv->iv, iv, iv_length);
|
||||||
|
}
|
||||||
|
|
||||||
|
len = sendmsg(ctx->opfd, &msg, 0);
|
||||||
|
if (len != (ssize_t)length) {
|
||||||
|
r = -EIO;
|
||||||
|
goto bad;
|
||||||
|
}
|
||||||
|
|
||||||
|
len = read(ctx->opfd, out, length);
|
||||||
|
if (len != (ssize_t)length)
|
||||||
|
r = -EIO;
|
||||||
|
bad:
|
||||||
|
crypt_backend_memzero(buffer, sizeof(buffer));
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_encrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length)
|
||||||
|
{
|
||||||
|
return crypt_cipher_crypt(ctx, in, out, length,
|
||||||
|
iv, iv_length, ALG_OP_ENCRYPT);
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_decrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length)
|
||||||
|
{
|
||||||
|
return crypt_cipher_crypt(ctx, in, out, length,
|
||||||
|
iv, iv_length, ALG_OP_DECRYPT);
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_destroy(struct crypt_cipher *ctx)
|
||||||
|
{
|
||||||
|
if (ctx->tfmfd >= 0)
|
||||||
|
close(ctx->tfmfd);
|
||||||
|
if (ctx->opfd >= 0)
|
||||||
|
close(ctx->opfd);
|
||||||
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
|
free(ctx);
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
#else /* ENABLE_AF_ALG */
|
||||||
|
|
||||||
|
int crypt_cipher_blocksize(const char *name)
|
||||||
|
{
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_init(struct crypt_cipher **ctx, const char *name,
|
||||||
|
const char *mode, const void *buffer, size_t length)
|
||||||
|
{
|
||||||
|
return -ENOTSUP;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_destroy(struct crypt_cipher *ctx)
|
||||||
|
{
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_cipher_encrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length)
|
||||||
|
{
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
int crypt_cipher_decrypt(struct crypt_cipher *ctx,
|
||||||
|
const char *in, char *out, size_t length,
|
||||||
|
const char *iv, size_t iv_length)
|
||||||
|
{
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
#endif
|
||||||
@@ -1,31 +1,35 @@
|
|||||||
/*
|
/*
|
||||||
* GCRYPT crypto backend implementation
|
* GCRYPT crypto backend implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2014, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
#include <stdio.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <assert.h>
|
#include <assert.h>
|
||||||
#include <gcrypt.h>
|
#include <gcrypt.h>
|
||||||
#include "crypto_backend.h"
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
#define GCRYPT_REQ_VERSION "1.1.42"
|
|
||||||
|
|
||||||
static int crypto_backend_initialised = 0;
|
static int crypto_backend_initialised = 0;
|
||||||
|
static int crypto_backend_secmem = 1;
|
||||||
|
static int crypto_backend_whirlpool_bug = -1;
|
||||||
|
static char version[64];
|
||||||
|
|
||||||
struct crypt_hash {
|
struct crypt_hash {
|
||||||
gcry_md_hd_t hd;
|
gcry_md_hd_t hd;
|
||||||
@@ -39,12 +43,49 @@ struct crypt_hmac {
|
|||||||
int hash_len;
|
int hash_len;
|
||||||
};
|
};
|
||||||
|
|
||||||
int crypt_backend_init(struct crypt_device *ctx __attribute__((unused)))
|
/*
|
||||||
|
* Test for wrong Whirlpool variant,
|
||||||
|
* Ref: http://lists.gnupg.org/pipermail/gcrypt-devel/2014-January/002889.html
|
||||||
|
*/
|
||||||
|
static void crypt_hash_test_whirlpool_bug(void)
|
||||||
|
{
|
||||||
|
struct crypt_hash *h;
|
||||||
|
char buf[2] = "\0\0", hash_out1[64], hash_out2[64];
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (crypto_backend_whirlpool_bug >= 0)
|
||||||
|
return;
|
||||||
|
|
||||||
|
crypto_backend_whirlpool_bug = 0;
|
||||||
|
if (crypt_hash_init(&h, "whirlpool"))
|
||||||
|
return;
|
||||||
|
|
||||||
|
/* One shot */
|
||||||
|
if ((r = crypt_hash_write(h, &buf[0], 2)) ||
|
||||||
|
(r = crypt_hash_final(h, hash_out1, 64))) {
|
||||||
|
crypt_hash_destroy(h);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Split buf (crypt_hash_final resets hash state) */
|
||||||
|
if ((r = crypt_hash_write(h, &buf[0], 1)) ||
|
||||||
|
(r = crypt_hash_write(h, &buf[1], 1)) ||
|
||||||
|
(r = crypt_hash_final(h, hash_out2, 64))) {
|
||||||
|
crypt_hash_destroy(h);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
crypt_hash_destroy(h);
|
||||||
|
|
||||||
|
if (memcmp(hash_out1, hash_out2, 64))
|
||||||
|
crypto_backend_whirlpool_bug = 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_backend_init(struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
if (crypto_backend_initialised)
|
if (crypto_backend_initialised)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
log_dbg("Initialising gcrypt crypto backend.");
|
|
||||||
if (!gcry_control (GCRYCTL_INITIALIZATION_FINISHED_P)) {
|
if (!gcry_control (GCRYCTL_INITIALIZATION_FINISHED_P)) {
|
||||||
if (!gcry_check_version (GCRYPT_REQ_VERSION)) {
|
if (!gcry_check_version (GCRYPT_REQ_VERSION)) {
|
||||||
return -ENOSYS;
|
return -ENOSYS;
|
||||||
@@ -57,8 +98,8 @@ int crypt_backend_init(struct crypt_device *ctx __attribute__((unused)))
|
|||||||
* and it locks its memory space anyway.
|
* and it locks its memory space anyway.
|
||||||
*/
|
*/
|
||||||
#if 0
|
#if 0
|
||||||
log_dbg("Initializing crypto backend (secure memory disabled).");
|
|
||||||
gcry_control (GCRYCTL_DISABLE_SECMEM);
|
gcry_control (GCRYCTL_DISABLE_SECMEM);
|
||||||
|
crypto_backend_secmem = 0;
|
||||||
#else
|
#else
|
||||||
|
|
||||||
gcry_control (GCRYCTL_SUSPEND_SECMEM_WARN);
|
gcry_control (GCRYCTL_SUSPEND_SECMEM_WARN);
|
||||||
@@ -69,14 +110,44 @@ int crypt_backend_init(struct crypt_device *ctx __attribute__((unused)))
|
|||||||
}
|
}
|
||||||
|
|
||||||
crypto_backend_initialised = 1;
|
crypto_backend_initialised = 1;
|
||||||
|
crypt_hash_test_whirlpool_bug();
|
||||||
|
|
||||||
|
snprintf(version, 64, "gcrypt %s%s%s",
|
||||||
|
gcry_check_version(NULL),
|
||||||
|
crypto_backend_secmem ? "" : ", secmem disabled",
|
||||||
|
crypto_backend_whirlpool_bug > 0 ? ", flawed whirlpool" : ""
|
||||||
|
);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *crypt_backend_version(void)
|
||||||
|
{
|
||||||
|
return crypto_backend_initialised ? version : "";
|
||||||
|
}
|
||||||
|
|
||||||
uint32_t crypt_backend_flags(void)
|
uint32_t crypt_backend_flags(void)
|
||||||
{
|
{
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static const char *crypt_hash_compat_name(const char *name, unsigned int *flags)
|
||||||
|
{
|
||||||
|
const char *hash_name = name;
|
||||||
|
|
||||||
|
/* "whirlpool_gcryptbug" is out shortcut to flawed whirlpool
|
||||||
|
* in libgcrypt < 1.6.0 */
|
||||||
|
if (name && !strcasecmp(name, "whirlpool_gcryptbug")) {
|
||||||
|
#if GCRYPT_VERSION_NUMBER >= 0x010601
|
||||||
|
if (flags)
|
||||||
|
*flags |= GCRY_MD_FLAG_BUGEMU1;
|
||||||
|
#endif
|
||||||
|
hash_name = "whirlpool";
|
||||||
|
}
|
||||||
|
|
||||||
|
return hash_name;
|
||||||
|
}
|
||||||
|
|
||||||
/* HASH */
|
/* HASH */
|
||||||
int crypt_hash_size(const char *name)
|
int crypt_hash_size(const char *name)
|
||||||
{
|
{
|
||||||
@@ -84,7 +155,7 @@ int crypt_hash_size(const char *name)
|
|||||||
|
|
||||||
assert(crypto_backend_initialised);
|
assert(crypto_backend_initialised);
|
||||||
|
|
||||||
hash_id = gcry_md_map_name(name);
|
hash_id = gcry_md_map_name(crypt_hash_compat_name(name, NULL));
|
||||||
if (!hash_id)
|
if (!hash_id)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
@@ -94,6 +165,7 @@ int crypt_hash_size(const char *name)
|
|||||||
int crypt_hash_init(struct crypt_hash **ctx, const char *name)
|
int crypt_hash_init(struct crypt_hash **ctx, const char *name)
|
||||||
{
|
{
|
||||||
struct crypt_hash *h;
|
struct crypt_hash *h;
|
||||||
|
unsigned int flags = 0;
|
||||||
|
|
||||||
assert(crypto_backend_initialised);
|
assert(crypto_backend_initialised);
|
||||||
|
|
||||||
@@ -101,13 +173,13 @@ int crypt_hash_init(struct crypt_hash **ctx, const char *name)
|
|||||||
if (!h)
|
if (!h)
|
||||||
return -ENOMEM;
|
return -ENOMEM;
|
||||||
|
|
||||||
h->hash_id = gcry_md_map_name(name);
|
h->hash_id = gcry_md_map_name(crypt_hash_compat_name(name, &flags));
|
||||||
if (!h->hash_id) {
|
if (!h->hash_id) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (gcry_md_open(&h->hd, h->hash_id, 0)) {
|
if (gcry_md_open(&h->hd, h->hash_id, flags)) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
@@ -163,6 +235,7 @@ int crypt_hmac_init(struct crypt_hmac **ctx, const char *name,
|
|||||||
const void *buffer, size_t length)
|
const void *buffer, size_t length)
|
||||||
{
|
{
|
||||||
struct crypt_hmac *h;
|
struct crypt_hmac *h;
|
||||||
|
unsigned int flags = GCRY_MD_FLAG_HMAC;
|
||||||
|
|
||||||
assert(crypto_backend_initialised);
|
assert(crypto_backend_initialised);
|
||||||
|
|
||||||
@@ -170,13 +243,13 @@ int crypt_hmac_init(struct crypt_hmac **ctx, const char *name,
|
|||||||
if (!h)
|
if (!h)
|
||||||
return -ENOMEM;
|
return -ENOMEM;
|
||||||
|
|
||||||
h->hash_id = gcry_md_map_name(name);
|
h->hash_id = gcry_md_map_name(crypt_hash_compat_name(name, &flags));
|
||||||
if (!h->hash_id) {
|
if (!h->hash_id) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (gcry_md_open(&h->hd, h->hash_id, GCRY_MD_FLAG_HMAC)) {
|
if (gcry_md_open(&h->hd, h->hash_id, flags)) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
@@ -227,3 +300,55 @@ int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
|||||||
free(ctx);
|
free(ctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* RNG */
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips)
|
||||||
|
{
|
||||||
|
switch(quality) {
|
||||||
|
case CRYPT_RND_NORMAL:
|
||||||
|
gcry_randomize(buffer, length, GCRY_STRONG_RANDOM);
|
||||||
|
break;
|
||||||
|
case CRYPT_RND_SALT:
|
||||||
|
case CRYPT_RND_KEY:
|
||||||
|
default:
|
||||||
|
gcry_randomize(buffer, length, GCRY_VERY_STRONG_RANDOM);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* PBKDF */
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations)
|
||||||
|
{
|
||||||
|
const char *hash_name = crypt_hash_compat_name(hash, NULL);
|
||||||
|
|
||||||
|
#if USE_INTERNAL_PBKDF2
|
||||||
|
if (!kdf || strncmp(kdf, "pbkdf2", 6))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return pkcs5_pbkdf2(hash_name, password, password_length, salt, salt_length,
|
||||||
|
iterations, key_length, key, 0);
|
||||||
|
|
||||||
|
#else /* USE_INTERNAL_PBKDF2 */
|
||||||
|
int hash_id = gcry_md_map_name(hash_name);
|
||||||
|
int kdf_id;
|
||||||
|
|
||||||
|
if (!hash_id)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (kdf && !strncmp(kdf, "pbkdf2", 6))
|
||||||
|
kdf_id = GCRY_KDF_PBKDF2;
|
||||||
|
else
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (gcry_kdf_derive(password, password_length, kdf_id, hash_id,
|
||||||
|
salt, salt_length, iterations, key_length, key))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
#endif /* USE_INTERNAL_PBKDF2 */
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,20 +1,22 @@
|
|||||||
/*
|
/*
|
||||||
* Linux kernel userspace API crypto backend implementation
|
* Linux kernel userspace API crypto backend implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2016, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
@@ -36,20 +38,22 @@
|
|||||||
#endif
|
#endif
|
||||||
|
|
||||||
static int crypto_backend_initialised = 0;
|
static int crypto_backend_initialised = 0;
|
||||||
|
static char version[64];
|
||||||
|
|
||||||
struct hash_alg {
|
struct hash_alg {
|
||||||
const char *name;
|
const char *name;
|
||||||
const char *kernel_name;
|
const char *kernel_name;
|
||||||
int length;
|
int length;
|
||||||
|
unsigned int block_length;
|
||||||
};
|
};
|
||||||
|
|
||||||
static struct hash_alg hash_algs[] = {
|
static struct hash_alg hash_algs[] = {
|
||||||
{ "sha1", "sha1", 20 },
|
{ "sha1", "sha1", 20, 64 },
|
||||||
{ "sha256", "sha256", 32 },
|
{ "sha256", "sha256", 32, 64 },
|
||||||
{ "sha512", "sha512", 64 },
|
{ "sha512", "sha512", 64, 128 },
|
||||||
{ "ripemd160", "rmd160", 20 },
|
{ "ripemd160", "rmd160", 20, 64 },
|
||||||
{ "whirlpool", "wp512", 64 },
|
{ "whirlpool", "wp512", 64, 64 },
|
||||||
{ NULL, 0 }
|
{ NULL, NULL, 0, 0 }
|
||||||
};
|
};
|
||||||
|
|
||||||
struct crypt_hash {
|
struct crypt_hash {
|
||||||
@@ -64,58 +68,60 @@ struct crypt_hmac {
|
|||||||
int hash_len;
|
int hash_len;
|
||||||
};
|
};
|
||||||
|
|
||||||
static int _socket_init(struct sockaddr_alg *sa, int *tfmfd, int *opfd)
|
static int crypt_kernel_socket_init(struct sockaddr_alg *sa, int *tfmfd, int *opfd,
|
||||||
|
const void *key, size_t key_length)
|
||||||
{
|
{
|
||||||
*tfmfd = socket(AF_ALG, SOCK_SEQPACKET, 0);
|
*tfmfd = socket(AF_ALG, SOCK_SEQPACKET, 0);
|
||||||
if (*tfmfd == -1)
|
if (*tfmfd < 0)
|
||||||
goto bad;
|
return -ENOTSUP;
|
||||||
|
|
||||||
if (bind(*tfmfd, (struct sockaddr *)sa, sizeof(*sa)) == -1)
|
if (bind(*tfmfd, (struct sockaddr *)sa, sizeof(*sa)) < 0) {
|
||||||
goto bad;
|
|
||||||
|
|
||||||
*opfd = accept(*tfmfd, NULL, 0);
|
|
||||||
if (*opfd == -1)
|
|
||||||
goto bad;
|
|
||||||
|
|
||||||
return 0;
|
|
||||||
bad:
|
|
||||||
if (*tfmfd != -1) {
|
|
||||||
close(*tfmfd);
|
close(*tfmfd);
|
||||||
*tfmfd = -1;
|
*tfmfd = -1;
|
||||||
|
return -ENOENT;
|
||||||
}
|
}
|
||||||
if (*opfd != -1) {
|
|
||||||
close(*opfd);
|
if (key && setsockopt(*tfmfd, SOL_ALG, ALG_SET_KEY, key, key_length) < 0) {
|
||||||
*opfd = -1;
|
close(*tfmfd);
|
||||||
|
*tfmfd = -1;
|
||||||
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
return -EINVAL;
|
|
||||||
|
*opfd = accept(*tfmfd, NULL, 0);
|
||||||
|
if (*opfd < 0) {
|
||||||
|
close(*tfmfd);
|
||||||
|
*tfmfd = -1;
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
int crypt_backend_init(struct crypt_device *ctx)
|
int crypt_backend_init(struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
struct utsname uts;
|
struct utsname uts;
|
||||||
|
|
||||||
struct sockaddr_alg sa = {
|
struct sockaddr_alg sa = {
|
||||||
.salg_family = AF_ALG,
|
.salg_family = AF_ALG,
|
||||||
.salg_type = "hash",
|
.salg_type = "hash",
|
||||||
.salg_name = "sha1",
|
.salg_name = "sha256",
|
||||||
};
|
};
|
||||||
int tfmfd = -1, opfd = -1;
|
int tfmfd = -1, opfd = -1;
|
||||||
|
|
||||||
if (crypto_backend_initialised)
|
if (crypto_backend_initialised)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
log_dbg("Initialising kernel crypto API backend.");
|
|
||||||
|
|
||||||
if (uname(&uts) == -1 || strcmp(uts.sysname, "Linux"))
|
if (uname(&uts) == -1 || strcmp(uts.sysname, "Linux"))
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
log_dbg("Kernel version %s %s.", uts.sysname, uts.release);
|
|
||||||
|
|
||||||
if (_socket_init(&sa, &tfmfd, &opfd) < 0)
|
if (crypt_kernel_socket_init(&sa, &tfmfd, &opfd, NULL, 0) < 0)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
close(tfmfd);
|
close(tfmfd);
|
||||||
close(opfd);
|
close(opfd);
|
||||||
|
|
||||||
|
snprintf(version, sizeof(version), "%s %s kernel cryptoAPI",
|
||||||
|
uts.sysname, uts.release);
|
||||||
|
|
||||||
crypto_backend_initialised = 1;
|
crypto_backend_initialised = 1;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -125,6 +131,11 @@ uint32_t crypt_backend_flags(void)
|
|||||||
return CRYPT_BACKEND_KERNEL;
|
return CRYPT_BACKEND_KERNEL;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *crypt_backend_version(void)
|
||||||
|
{
|
||||||
|
return crypto_backend_initialised ? version : "";
|
||||||
|
}
|
||||||
|
|
||||||
static struct hash_alg *_get_alg(const char *name)
|
static struct hash_alg *_get_alg(const char *name)
|
||||||
{
|
{
|
||||||
int i = 0;
|
int i = 0;
|
||||||
@@ -167,7 +178,7 @@ int crypt_hash_init(struct crypt_hash **ctx, const char *name)
|
|||||||
|
|
||||||
strncpy((char *)sa.salg_name, ha->kernel_name, sizeof(sa.salg_name));
|
strncpy((char *)sa.salg_name, ha->kernel_name, sizeof(sa.salg_name));
|
||||||
|
|
||||||
if (_socket_init(&sa, &h->tfmfd, &h->opfd) < 0) {
|
if (crypt_kernel_socket_init(&sa, &h->tfmfd, &h->opfd, NULL, 0) < 0) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
@@ -203,9 +214,9 @@ int crypt_hash_final(struct crypt_hash *ctx, char *buffer, size_t length)
|
|||||||
|
|
||||||
int crypt_hash_destroy(struct crypt_hash *ctx)
|
int crypt_hash_destroy(struct crypt_hash *ctx)
|
||||||
{
|
{
|
||||||
if (ctx->tfmfd != -1)
|
if (ctx->tfmfd >= 0)
|
||||||
close(ctx->tfmfd);
|
close(ctx->tfmfd);
|
||||||
if (ctx->opfd != -1)
|
if (ctx->opfd >= 0)
|
||||||
close(ctx->opfd);
|
close(ctx->opfd);
|
||||||
memset(ctx, 0, sizeof(*ctx));
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
free(ctx);
|
free(ctx);
|
||||||
@@ -242,16 +253,11 @@ int crypt_hmac_init(struct crypt_hmac **ctx, const char *name,
|
|||||||
snprintf((char *)sa.salg_name, sizeof(sa.salg_name),
|
snprintf((char *)sa.salg_name, sizeof(sa.salg_name),
|
||||||
"hmac(%s)", ha->kernel_name);
|
"hmac(%s)", ha->kernel_name);
|
||||||
|
|
||||||
if (_socket_init(&sa, &h->tfmfd, &h->opfd) < 0) {
|
if (crypt_kernel_socket_init(&sa, &h->tfmfd, &h->opfd, buffer, length) < 0) {
|
||||||
free(h);
|
free(h);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (setsockopt(h->tfmfd, SOL_ALG, ALG_SET_KEY, buffer, length) == -1) {
|
|
||||||
crypt_hmac_destroy(h);
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
*ctx = h;
|
*ctx = h;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -283,11 +289,33 @@ int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length)
|
|||||||
|
|
||||||
int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
||||||
{
|
{
|
||||||
if (ctx->tfmfd != -1)
|
if (ctx->tfmfd >= 0)
|
||||||
close(ctx->tfmfd);
|
close(ctx->tfmfd);
|
||||||
if (ctx->opfd != -1)
|
if (ctx->opfd >= 0)
|
||||||
close(ctx->opfd);
|
close(ctx->opfd);
|
||||||
memset(ctx, 0, sizeof(*ctx));
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
free(ctx);
|
free(ctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* RNG - N/A */
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips)
|
||||||
|
{
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* PBKDF */
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations)
|
||||||
|
{
|
||||||
|
struct hash_alg *ha = _get_alg(hash);
|
||||||
|
|
||||||
|
if (!ha || !kdf || strncmp(kdf, "pbkdf2", 6))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return pkcs5_pbkdf2(hash, password, password_length, salt, salt_length,
|
||||||
|
iterations, key_length, key, ha->block_length);
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,20 +1,22 @@
|
|||||||
/*
|
/*
|
||||||
* Nettle crypto backend implementation
|
* Nettle crypto backend implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2011 Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2011-2012 Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2011-2014, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -22,8 +24,11 @@
|
|||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <nettle/sha.h>
|
#include <nettle/sha.h>
|
||||||
#include <nettle/hmac.h>
|
#include <nettle/hmac.h>
|
||||||
|
#include <nettle/pbkdf2.h>
|
||||||
#include "crypto_backend.h"
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
static char *version = "Nettle";
|
||||||
|
|
||||||
typedef void (*init_func) (void *);
|
typedef void (*init_func) (void *);
|
||||||
typedef void (*update_func) (void *, unsigned, const uint8_t *);
|
typedef void (*update_func) (void *, unsigned, const uint8_t *);
|
||||||
typedef void (*digest_func) (void *, unsigned, uint8_t *);
|
typedef void (*digest_func) (void *, unsigned, uint8_t *);
|
||||||
@@ -135,10 +140,14 @@ static struct hash_alg *_get_alg(const char *name)
|
|||||||
|
|
||||||
int crypt_backend_init(struct crypt_device *ctx)
|
int crypt_backend_init(struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
log_dbg("Initialising Nettle crypto backend.");
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *crypt_backend_version(void)
|
||||||
|
{
|
||||||
|
return version;
|
||||||
|
}
|
||||||
|
|
||||||
/* HASH */
|
/* HASH */
|
||||||
int crypt_hash_size(const char *name)
|
int crypt_hash_size(const char *name)
|
||||||
{
|
{
|
||||||
@@ -257,8 +266,40 @@ int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length)
|
|||||||
int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
||||||
{
|
{
|
||||||
memset(ctx->key, 0, ctx->key_length);
|
memset(ctx->key, 0, ctx->key_length);
|
||||||
memset(ctx, 0, sizeof(*ctx));
|
|
||||||
free(ctx->key);
|
free(ctx->key);
|
||||||
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
free(ctx);
|
free(ctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* RNG - N/A */
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips)
|
||||||
|
{
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* PBKDF */
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations)
|
||||||
|
{
|
||||||
|
struct crypt_hmac *h;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (!kdf || strncmp(kdf, "pbkdf2", 6))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = crypt_hmac_init(&h, hash, password, password_length);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
nettle_pbkdf2(&h->nettle_ctx, h->hash->nettle_hmac_update,
|
||||||
|
h->hash->nettle_hmac_digest, h->hash->length, iterations,
|
||||||
|
salt_length, (const uint8_t *)salt, key_length,
|
||||||
|
(uint8_t *)key);
|
||||||
|
crypt_hmac_destroy(h);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,20 +1,22 @@
|
|||||||
/*
|
/*
|
||||||
* NSS crypto backend implementation
|
* NSS crypto backend implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2014, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
@@ -23,21 +25,25 @@
|
|||||||
#include <pk11pub.h>
|
#include <pk11pub.h>
|
||||||
#include "crypto_backend.h"
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
#define CONST_CAST(x) (x)(uintptr_t)
|
||||||
|
|
||||||
static int crypto_backend_initialised = 0;
|
static int crypto_backend_initialised = 0;
|
||||||
|
static char version[64];
|
||||||
|
|
||||||
struct hash_alg {
|
struct hash_alg {
|
||||||
const char *name;
|
const char *name;
|
||||||
SECOidTag oid;
|
SECOidTag oid;
|
||||||
CK_MECHANISM_TYPE ck_type;
|
CK_MECHANISM_TYPE ck_type;
|
||||||
int length;
|
int length;
|
||||||
|
unsigned int block_length;
|
||||||
};
|
};
|
||||||
|
|
||||||
static struct hash_alg hash_algs[] = {
|
static struct hash_alg hash_algs[] = {
|
||||||
{ "sha1", SEC_OID_SHA1, CKM_SHA_1_HMAC, 20 },
|
{ "sha1", SEC_OID_SHA1, CKM_SHA_1_HMAC, 20, 64 },
|
||||||
{ "sha256", SEC_OID_SHA256, CKM_SHA256_HMAC, 32 },
|
{ "sha256", SEC_OID_SHA256, CKM_SHA256_HMAC, 32, 64 },
|
||||||
{ "sha384", SEC_OID_SHA384, CKM_SHA384_HMAC, 48 },
|
{ "sha384", SEC_OID_SHA384, CKM_SHA384_HMAC, 48, 128 },
|
||||||
{ "sha512", SEC_OID_SHA512, CKM_SHA512_HMAC, 64 },
|
{ "sha512", SEC_OID_SHA512, CKM_SHA512_HMAC, 64, 128 },
|
||||||
// { "ripemd160", SEC_OID_RIPEMD160, CKM_RIPEMD160_HMAC, 20 },
|
// { "ripemd160", SEC_OID_RIPEMD160, CKM_RIPEMD160_HMAC, 20, 64 },
|
||||||
{ NULL, 0, 0, 0 }
|
{ NULL, 0, 0, 0 }
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -70,10 +76,14 @@ int crypt_backend_init(struct crypt_device *ctx)
|
|||||||
if (crypto_backend_initialised)
|
if (crypto_backend_initialised)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
log_dbg("Initialising NSS crypto backend.");
|
|
||||||
if (NSS_NoDB_Init(".") != SECSuccess)
|
if (NSS_NoDB_Init(".") != SECSuccess)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
|
#if HAVE_DECL_NSS_GETVERSION
|
||||||
|
snprintf(version, 64, "NSS %s", NSS_GetVersion());
|
||||||
|
#else
|
||||||
|
snprintf(version, 64, "NSS");
|
||||||
|
#endif
|
||||||
crypto_backend_initialised = 1;
|
crypto_backend_initialised = 1;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -83,6 +93,11 @@ uint32_t crypt_backend_flags(void)
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *crypt_backend_version(void)
|
||||||
|
{
|
||||||
|
return crypto_backend_initialised ? version : "";
|
||||||
|
}
|
||||||
|
|
||||||
/* HASH */
|
/* HASH */
|
||||||
int crypt_hash_size(const char *name)
|
int crypt_hash_size(const char *name)
|
||||||
{
|
{
|
||||||
@@ -149,7 +164,7 @@ int crypt_hash_final(struct crypt_hash *ctx, char *buffer, size_t length)
|
|||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
memcpy(buffer, tmp, length);
|
memcpy(buffer, tmp, length);
|
||||||
memset(tmp, 0, sizeof(tmp));
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
|
||||||
if (tmp_len < length)
|
if (tmp_len < length)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
@@ -251,7 +266,7 @@ int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length)
|
|||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
memcpy(buffer, tmp, length);
|
memcpy(buffer, tmp, length);
|
||||||
memset(tmp, 0, sizeof(tmp));
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
|
||||||
if (tmp_len < length)
|
if (tmp_len < length)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
@@ -274,3 +289,31 @@ int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
|||||||
free(ctx);
|
free(ctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* RNG */
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips)
|
||||||
|
{
|
||||||
|
if (fips)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (PK11_GenerateRandom((unsigned char *)buffer, length) != SECSuccess)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* PBKDF */
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations)
|
||||||
|
{
|
||||||
|
struct hash_alg *ha = _get_alg(hash);
|
||||||
|
|
||||||
|
if (!ha || !kdf || strncmp(kdf, "pbkdf2", 6))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return pkcs5_pbkdf2(hash, password, password_length, salt, salt_length,
|
||||||
|
iterations, key_length, key, ha->block_length);
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,20 +1,22 @@
|
|||||||
/*
|
/*
|
||||||
* OPENSSL crypto backend implementation
|
* OPENSSL crypto backend implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2010-2014, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*
|
*
|
||||||
* In addition, as a special exception, the copyright holders give
|
* In addition, as a special exception, the copyright holders give
|
||||||
* permission to link the code of portions of this program with the
|
* permission to link the code of portions of this program with the
|
||||||
@@ -22,7 +24,7 @@
|
|||||||
* individual source file, and distribute linked combinations
|
* individual source file, and distribute linked combinations
|
||||||
* including the two.
|
* including the two.
|
||||||
*
|
*
|
||||||
* You must obey the GNU General Public License in all respects
|
* You must obey the GNU Lesser General Public License in all respects
|
||||||
* for all of the code used other than OpenSSL.
|
* for all of the code used other than OpenSSL.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@@ -30,6 +32,7 @@
|
|||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <openssl/hmac.h>
|
#include <openssl/hmac.h>
|
||||||
|
#include <openssl/rand.h>
|
||||||
#include "crypto_backend.h"
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
static int crypto_backend_initialised = 0;
|
static int crypto_backend_initialised = 0;
|
||||||
@@ -51,8 +54,7 @@ int crypt_backend_init(struct crypt_device *ctx)
|
|||||||
if (crypto_backend_initialised)
|
if (crypto_backend_initialised)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
OpenSSL_add_all_digests();
|
OpenSSL_add_all_algorithms();
|
||||||
log_dbg("OpenSSL crypto backend initialized.");
|
|
||||||
|
|
||||||
crypto_backend_initialised = 1;
|
crypto_backend_initialised = 1;
|
||||||
return 0;
|
return 0;
|
||||||
@@ -63,6 +65,11 @@ uint32_t crypt_backend_flags(void)
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *crypt_backend_version(void)
|
||||||
|
{
|
||||||
|
return SSLeay_version(SSLEAY_VERSION);
|
||||||
|
}
|
||||||
|
|
||||||
/* HASH */
|
/* HASH */
|
||||||
int crypt_hash_size(const char *name)
|
int crypt_hash_size(const char *name)
|
||||||
{
|
{
|
||||||
@@ -126,7 +133,7 @@ int crypt_hash_final(struct crypt_hash *ctx, char *buffer, size_t length)
|
|||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
memcpy(buffer, tmp, length);
|
memcpy(buffer, tmp, length);
|
||||||
memset(tmp, 0, sizeof(tmp));
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
|
||||||
if (tmp_len < length)
|
if (tmp_len < length)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
@@ -196,7 +203,7 @@ int crypt_hmac_final(struct crypt_hmac *ctx, char *buffer, size_t length)
|
|||||||
HMAC_Final(&ctx->md, tmp, &tmp_len);
|
HMAC_Final(&ctx->md, tmp, &tmp_len);
|
||||||
|
|
||||||
memcpy(buffer, tmp, length);
|
memcpy(buffer, tmp, length);
|
||||||
memset(tmp, 0, sizeof(tmp));
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
|
||||||
if (tmp_len < length)
|
if (tmp_len < length)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
@@ -213,3 +220,39 @@ int crypt_hmac_destroy(struct crypt_hmac *ctx)
|
|||||||
free(ctx);
|
free(ctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* RNG */
|
||||||
|
int crypt_backend_rng(char *buffer, size_t length, int quality, int fips)
|
||||||
|
{
|
||||||
|
if (fips)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (RAND_bytes((unsigned char *)buffer, length) != 1)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* PBKDF */
|
||||||
|
int crypt_pbkdf(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
char *key, size_t key_length,
|
||||||
|
unsigned int iterations)
|
||||||
|
{
|
||||||
|
const EVP_MD *hash_id;
|
||||||
|
|
||||||
|
if (!kdf || strncmp(kdf, "pbkdf2", 6))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
hash_id = EVP_get_digestbyname(hash);
|
||||||
|
if (!hash_id)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (!PKCS5_PBKDF2_HMAC(password, (int)password_length,
|
||||||
|
(unsigned char *)salt, (int)salt_length,
|
||||||
|
(int)iterations, hash_id, (int)key_length, (unsigned char *)key))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|||||||
293
lib/crypto_backend/crypto_storage.c
Normal file
293
lib/crypto_backend/crypto_storage.c
Normal file
@@ -0,0 +1,293 @@
|
|||||||
|
/*
|
||||||
|
* Generic wrapper for storage encryption modes and Initial Vectors
|
||||||
|
* (reimplementation of some functions from Linux dm-crypt kernel)
|
||||||
|
*
|
||||||
|
* Copyright (C) 2014, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include "bitops.h"
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
#define SECTOR_SHIFT 9
|
||||||
|
#define SECTOR_SIZE (1 << SECTOR_SHIFT)
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Internal IV helper
|
||||||
|
* IV documentation: https://gitlab.com/cryptsetup/cryptsetup/wikis/DMCrypt
|
||||||
|
*/
|
||||||
|
struct crypt_sector_iv {
|
||||||
|
enum { IV_NONE, IV_NULL, IV_PLAIN, IV_PLAIN64, IV_ESSIV, IV_BENBI } type;
|
||||||
|
int iv_size;
|
||||||
|
char *iv;
|
||||||
|
struct crypt_cipher *essiv_cipher;
|
||||||
|
int benbi_shift;
|
||||||
|
};
|
||||||
|
|
||||||
|
/* Block encryption storage context */
|
||||||
|
struct crypt_storage {
|
||||||
|
uint64_t sector_start;
|
||||||
|
struct crypt_cipher *cipher;
|
||||||
|
struct crypt_sector_iv cipher_iv;
|
||||||
|
};
|
||||||
|
|
||||||
|
static int int_log2(unsigned int x)
|
||||||
|
{
|
||||||
|
int r = 0;
|
||||||
|
for (x >>= 1; x > 0; x >>= 1)
|
||||||
|
r++;
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int crypt_sector_iv_init(struct crypt_sector_iv *ctx,
|
||||||
|
const char *cipher_name, const char *mode_name,
|
||||||
|
const char *iv_name, char *key, size_t key_length)
|
||||||
|
{
|
||||||
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
|
|
||||||
|
ctx->iv_size = crypt_cipher_blocksize(cipher_name);
|
||||||
|
if (ctx->iv_size < 0)
|
||||||
|
return -ENOENT;
|
||||||
|
|
||||||
|
if (!iv_name ||
|
||||||
|
!strcmp(cipher_name, "cipher_null") ||
|
||||||
|
!strcmp(mode_name, "ecb")) {
|
||||||
|
ctx->type = IV_NONE;
|
||||||
|
ctx->iv_size = 0;
|
||||||
|
return 0;
|
||||||
|
} else if (!strcasecmp(iv_name, "null")) {
|
||||||
|
ctx->type = IV_NULL;
|
||||||
|
} else if (!strcasecmp(iv_name, "plain64")) {
|
||||||
|
ctx->type = IV_PLAIN64;
|
||||||
|
} else if (!strcasecmp(iv_name, "plain")) {
|
||||||
|
ctx->type = IV_PLAIN;
|
||||||
|
} else if (!strncasecmp(iv_name, "essiv:", 6)) {
|
||||||
|
struct crypt_hash *h = NULL;
|
||||||
|
char *hash_name = strchr(iv_name, ':');
|
||||||
|
int hash_size;
|
||||||
|
char tmp[256];
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (!hash_name)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
hash_size = crypt_hash_size(++hash_name);
|
||||||
|
if (hash_size < 0)
|
||||||
|
return -ENOENT;
|
||||||
|
|
||||||
|
if ((unsigned)hash_size > sizeof(tmp))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (crypt_hash_init(&h, hash_name))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = crypt_hash_write(h, key, key_length);
|
||||||
|
if (r) {
|
||||||
|
crypt_hash_destroy(h);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = crypt_hash_final(h, tmp, hash_size);
|
||||||
|
crypt_hash_destroy(h);
|
||||||
|
if (r) {
|
||||||
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = crypt_cipher_init(&ctx->essiv_cipher, cipher_name, "ecb",
|
||||||
|
tmp, hash_size);
|
||||||
|
crypt_backend_memzero(tmp, sizeof(tmp));
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
ctx->type = IV_ESSIV;
|
||||||
|
} else if (!strncasecmp(iv_name, "benbi", 5)) {
|
||||||
|
int log = int_log2(ctx->iv_size);
|
||||||
|
if (log > SECTOR_SHIFT)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
ctx->type = IV_BENBI;
|
||||||
|
ctx->benbi_shift = SECTOR_SHIFT - log;
|
||||||
|
} else
|
||||||
|
return -ENOENT;
|
||||||
|
|
||||||
|
ctx->iv = malloc(ctx->iv_size);
|
||||||
|
if (!ctx->iv)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int crypt_sector_iv_generate(struct crypt_sector_iv *ctx, uint64_t sector)
|
||||||
|
{
|
||||||
|
uint64_t val;
|
||||||
|
|
||||||
|
switch (ctx->type) {
|
||||||
|
case IV_NONE:
|
||||||
|
break;
|
||||||
|
case IV_NULL:
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
break;
|
||||||
|
case IV_PLAIN:
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
*(uint32_t *)ctx->iv = cpu_to_le32(sector & 0xffffffff);
|
||||||
|
break;
|
||||||
|
case IV_PLAIN64:
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
*(uint64_t *)ctx->iv = cpu_to_le64(sector);
|
||||||
|
break;
|
||||||
|
case IV_ESSIV:
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
*(uint64_t *)ctx->iv = cpu_to_le64(sector);
|
||||||
|
return crypt_cipher_encrypt(ctx->essiv_cipher,
|
||||||
|
ctx->iv, ctx->iv, ctx->iv_size, NULL, 0);
|
||||||
|
break;
|
||||||
|
case IV_BENBI:
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
val = cpu_to_be64((sector << ctx->benbi_shift) + 1);
|
||||||
|
memcpy(ctx->iv + ctx->iv_size - sizeof(val), &val, sizeof(val));
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int crypt_sector_iv_destroy(struct crypt_sector_iv *ctx)
|
||||||
|
{
|
||||||
|
if (ctx->type == IV_ESSIV)
|
||||||
|
crypt_cipher_destroy(ctx->essiv_cipher);
|
||||||
|
|
||||||
|
if (ctx->iv) {
|
||||||
|
memset(ctx->iv, 0, ctx->iv_size);
|
||||||
|
free(ctx->iv);
|
||||||
|
}
|
||||||
|
|
||||||
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Block encryption storage wrappers */
|
||||||
|
|
||||||
|
int crypt_storage_init(struct crypt_storage **ctx,
|
||||||
|
uint64_t sector_start,
|
||||||
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
|
char *key, size_t key_length)
|
||||||
|
{
|
||||||
|
struct crypt_storage *s;
|
||||||
|
char mode_name[64];
|
||||||
|
char *cipher_iv = NULL;
|
||||||
|
int r = -EIO;
|
||||||
|
|
||||||
|
s = malloc(sizeof(*s));
|
||||||
|
if (!s)
|
||||||
|
return -ENOMEM;
|
||||||
|
memset(s, 0, sizeof(*s));
|
||||||
|
|
||||||
|
/* Remove IV if present */
|
||||||
|
strncpy(mode_name, cipher_mode, sizeof(mode_name));
|
||||||
|
mode_name[sizeof(mode_name) - 1] = 0;
|
||||||
|
cipher_iv = strchr(mode_name, '-');
|
||||||
|
if (cipher_iv) {
|
||||||
|
*cipher_iv = '\0';
|
||||||
|
cipher_iv++;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = crypt_cipher_init(&s->cipher, cipher, mode_name, key, key_length);
|
||||||
|
if (r) {
|
||||||
|
crypt_storage_destroy(s);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = crypt_sector_iv_init(&s->cipher_iv, cipher, mode_name, cipher_iv, key, key_length);
|
||||||
|
if (r) {
|
||||||
|
crypt_storage_destroy(s);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
s->sector_start = sector_start;
|
||||||
|
|
||||||
|
*ctx = s;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_storage_decrypt(struct crypt_storage *ctx,
|
||||||
|
uint64_t sector, size_t count,
|
||||||
|
char *buffer)
|
||||||
|
{
|
||||||
|
unsigned int i;
|
||||||
|
int r = 0;
|
||||||
|
|
||||||
|
for (i = 0; i < count; i++) {
|
||||||
|
r = crypt_sector_iv_generate(&ctx->cipher_iv, sector + i);
|
||||||
|
if (r)
|
||||||
|
break;
|
||||||
|
r = crypt_cipher_decrypt(ctx->cipher,
|
||||||
|
&buffer[i * SECTOR_SIZE],
|
||||||
|
&buffer[i * SECTOR_SIZE],
|
||||||
|
SECTOR_SIZE,
|
||||||
|
ctx->cipher_iv.iv,
|
||||||
|
ctx->cipher_iv.iv_size);
|
||||||
|
if (r)
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_storage_encrypt(struct crypt_storage *ctx,
|
||||||
|
uint64_t sector, size_t count,
|
||||||
|
char *buffer)
|
||||||
|
{
|
||||||
|
unsigned int i;
|
||||||
|
int r = 0;
|
||||||
|
|
||||||
|
for (i = 0; i < count; i++) {
|
||||||
|
r = crypt_sector_iv_generate(&ctx->cipher_iv, sector + i);
|
||||||
|
if (r)
|
||||||
|
break;
|
||||||
|
r = crypt_cipher_encrypt(ctx->cipher,
|
||||||
|
&buffer[i * SECTOR_SIZE],
|
||||||
|
&buffer[i * SECTOR_SIZE],
|
||||||
|
SECTOR_SIZE,
|
||||||
|
ctx->cipher_iv.iv,
|
||||||
|
ctx->cipher_iv.iv_size);
|
||||||
|
if (r)
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_storage_destroy(struct crypt_storage *ctx)
|
||||||
|
{
|
||||||
|
if (!ctx)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
crypt_sector_iv_destroy(&ctx->cipher_iv);
|
||||||
|
|
||||||
|
if (ctx->cipher)
|
||||||
|
crypt_cipher_destroy(ctx->cipher);
|
||||||
|
|
||||||
|
memset(ctx, 0, sizeof(*ctx));
|
||||||
|
free(ctx);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
426
lib/crypto_backend/pbkdf2_generic.c
Normal file
426
lib/crypto_backend/pbkdf2_generic.c
Normal file
@@ -0,0 +1,426 @@
|
|||||||
|
/*
|
||||||
|
* Implementation of Password-Based Cryptography as per PKCS#5
|
||||||
|
* Copyright (C) 2002,2003 Simon Josefsson
|
||||||
|
* Copyright (C) 2004 Free Software Foundation
|
||||||
|
*
|
||||||
|
* cryptsetup related changes
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2014, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <errno.h>
|
||||||
|
#include <alloca.h>
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
static int hash_buf(const char *src, size_t src_len,
|
||||||
|
char *dst, size_t dst_len,
|
||||||
|
const char *hash_name)
|
||||||
|
{
|
||||||
|
struct crypt_hash *hd = NULL;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (crypt_hash_init(&hd, hash_name))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = crypt_hash_write(hd, src, src_len);
|
||||||
|
|
||||||
|
if (!r)
|
||||||
|
r = crypt_hash_final(hd, dst, dst_len);
|
||||||
|
|
||||||
|
crypt_hash_destroy(hd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* 5.2 PBKDF2
|
||||||
|
*
|
||||||
|
* PBKDF2 applies a pseudorandom function (see Appendix B.1 for an
|
||||||
|
* example) to derive keys. The length of the derived key is essentially
|
||||||
|
* unbounded. (However, the maximum effective search space for the
|
||||||
|
* derived key may be limited by the structure of the underlying
|
||||||
|
* pseudorandom function. See Appendix B.1 for further discussion.)
|
||||||
|
* PBKDF2 is recommended for new applications.
|
||||||
|
*
|
||||||
|
* PBKDF2 (P, S, c, dkLen)
|
||||||
|
*
|
||||||
|
* Options: PRF underlying pseudorandom function (hLen
|
||||||
|
* denotes the length in octets of the
|
||||||
|
* pseudorandom function output)
|
||||||
|
*
|
||||||
|
* Input: P password, an octet string (ASCII or UTF-8)
|
||||||
|
* S salt, an octet string
|
||||||
|
* c iteration count, a positive integer
|
||||||
|
* dkLen intended length in octets of the derived
|
||||||
|
* key, a positive integer, at most
|
||||||
|
* (2^32 - 1) * hLen
|
||||||
|
*
|
||||||
|
* Output: DK derived key, a dkLen-octet string
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* if hash_block_size is not zero, the HMAC key is pre-hashed
|
||||||
|
* inside this function.
|
||||||
|
* This prevents situation when crypto backend doesn't support
|
||||||
|
* long HMAC keys or it tries hash long key in every iteration
|
||||||
|
* (because of crypt_final() cannot do simple key reset.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#define MAX_PRF_BLOCK_LEN 80
|
||||||
|
|
||||||
|
int pkcs5_pbkdf2(const char *hash,
|
||||||
|
const char *P, size_t Plen,
|
||||||
|
const char *S, size_t Slen,
|
||||||
|
unsigned int c, unsigned int dkLen,
|
||||||
|
char *DK, unsigned int hash_block_size)
|
||||||
|
{
|
||||||
|
struct crypt_hmac *hmac;
|
||||||
|
char U[MAX_PRF_BLOCK_LEN];
|
||||||
|
char T[MAX_PRF_BLOCK_LEN];
|
||||||
|
char P_hash[MAX_PRF_BLOCK_LEN];
|
||||||
|
int i, k, rc = -EINVAL;
|
||||||
|
unsigned int u, hLen, l, r;
|
||||||
|
size_t tmplen = Slen + 4;
|
||||||
|
char *tmp;
|
||||||
|
|
||||||
|
tmp = alloca(tmplen);
|
||||||
|
if (tmp == NULL)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
hLen = crypt_hmac_size(hash);
|
||||||
|
if (hLen == 0 || hLen > MAX_PRF_BLOCK_LEN)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (c == 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (dkLen == 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
/*
|
||||||
|
*
|
||||||
|
* Steps:
|
||||||
|
*
|
||||||
|
* 1. If dkLen > (2^32 - 1) * hLen, output "derived key too long" and
|
||||||
|
* stop.
|
||||||
|
*/
|
||||||
|
|
||||||
|
if (dkLen > 4294967295U)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* 2. Let l be the number of hLen-octet blocks in the derived key,
|
||||||
|
* rounding up, and let r be the number of octets in the last
|
||||||
|
* block:
|
||||||
|
*
|
||||||
|
* l = CEIL (dkLen / hLen) ,
|
||||||
|
* r = dkLen - (l - 1) * hLen .
|
||||||
|
*
|
||||||
|
* Here, CEIL (x) is the "ceiling" function, i.e. the smallest
|
||||||
|
* integer greater than, or equal to, x.
|
||||||
|
*/
|
||||||
|
|
||||||
|
l = dkLen / hLen;
|
||||||
|
if (dkLen % hLen)
|
||||||
|
l++;
|
||||||
|
r = dkLen - (l - 1) * hLen;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* 3. For each block of the derived key apply the function F defined
|
||||||
|
* below to the password P, the salt S, the iteration count c, and
|
||||||
|
* the block index to compute the block:
|
||||||
|
*
|
||||||
|
* T_1 = F (P, S, c, 1) ,
|
||||||
|
* T_2 = F (P, S, c, 2) ,
|
||||||
|
* ...
|
||||||
|
* T_l = F (P, S, c, l) ,
|
||||||
|
*
|
||||||
|
* where the function F is defined as the exclusive-or sum of the
|
||||||
|
* first c iterates of the underlying pseudorandom function PRF
|
||||||
|
* applied to the password P and the concatenation of the salt S
|
||||||
|
* and the block index i:
|
||||||
|
*
|
||||||
|
* F (P, S, c, i) = U_1 \xor U_2 \xor ... \xor U_c
|
||||||
|
*
|
||||||
|
* where
|
||||||
|
*
|
||||||
|
* U_1 = PRF (P, S || INT (i)) ,
|
||||||
|
* U_2 = PRF (P, U_1) ,
|
||||||
|
* ...
|
||||||
|
* U_c = PRF (P, U_{c-1}) .
|
||||||
|
*
|
||||||
|
* Here, INT (i) is a four-octet encoding of the integer i, most
|
||||||
|
* significant octet first.
|
||||||
|
*
|
||||||
|
* 4. Concatenate the blocks and extract the first dkLen octets to
|
||||||
|
* produce a derived key DK:
|
||||||
|
*
|
||||||
|
* DK = T_1 || T_2 || ... || T_l<0..r-1>
|
||||||
|
*
|
||||||
|
* 5. Output the derived key DK.
|
||||||
|
*
|
||||||
|
* Note. The construction of the function F follows a "belt-and-
|
||||||
|
* suspenders" approach. The iterates U_i are computed recursively to
|
||||||
|
* remove a degree of parallelism from an opponent; they are exclusive-
|
||||||
|
* ored together to reduce concerns about the recursion degenerating
|
||||||
|
* into a small set of values.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
|
||||||
|
/* If hash_block_size is provided, hash password in advance. */
|
||||||
|
if (hash_block_size > 0 && Plen > hash_block_size) {
|
||||||
|
if (hash_buf(P, Plen, P_hash, hLen, hash))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (crypt_hmac_init(&hmac, hash, P_hash, hLen))
|
||||||
|
return -EINVAL;
|
||||||
|
crypt_backend_memzero(P_hash, sizeof(P_hash));
|
||||||
|
} else {
|
||||||
|
if (crypt_hmac_init(&hmac, hash, P, Plen))
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (i = 1; (unsigned int) i <= l; i++) {
|
||||||
|
memset(T, 0, hLen);
|
||||||
|
|
||||||
|
for (u = 1; u <= c ; u++) {
|
||||||
|
if (u == 1) {
|
||||||
|
memcpy(tmp, S, Slen);
|
||||||
|
tmp[Slen + 0] = (i & 0xff000000) >> 24;
|
||||||
|
tmp[Slen + 1] = (i & 0x00ff0000) >> 16;
|
||||||
|
tmp[Slen + 2] = (i & 0x0000ff00) >> 8;
|
||||||
|
tmp[Slen + 3] = (i & 0x000000ff) >> 0;
|
||||||
|
|
||||||
|
if (crypt_hmac_write(hmac, tmp, tmplen))
|
||||||
|
goto out;
|
||||||
|
} else {
|
||||||
|
if (crypt_hmac_write(hmac, U, hLen))
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (crypt_hmac_final(hmac, U, hLen))
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
for (k = 0; (unsigned int) k < hLen; k++)
|
||||||
|
T[k] ^= U[k];
|
||||||
|
}
|
||||||
|
|
||||||
|
memcpy(DK + (i - 1) * hLen, T, (unsigned int) i == l ? r : hLen);
|
||||||
|
}
|
||||||
|
rc = 0;
|
||||||
|
out:
|
||||||
|
crypt_hmac_destroy(hmac);
|
||||||
|
crypt_backend_memzero(U, sizeof(U));
|
||||||
|
crypt_backend_memzero(T, sizeof(T));
|
||||||
|
crypt_backend_memzero(tmp, tmplen);
|
||||||
|
|
||||||
|
return rc;
|
||||||
|
}
|
||||||
|
|
||||||
|
#if 0
|
||||||
|
#include <stdio.h>
|
||||||
|
|
||||||
|
struct test_vector {
|
||||||
|
const char *hash;
|
||||||
|
unsigned int hash_block_length;
|
||||||
|
unsigned int iterations;
|
||||||
|
const char *password;
|
||||||
|
unsigned int password_length;
|
||||||
|
const char *salt;
|
||||||
|
unsigned int salt_length;
|
||||||
|
const char *output;
|
||||||
|
unsigned int output_length;
|
||||||
|
};
|
||||||
|
|
||||||
|
struct test_vector test_vectors[] = {
|
||||||
|
/* RFC 3962 */
|
||||||
|
{
|
||||||
|
"sha1", 64, 1,
|
||||||
|
"password", 8,
|
||||||
|
"ATHENA.MIT.EDUraeburn", 21,
|
||||||
|
"\xcd\xed\xb5\x28\x1b\xb2\xf8\x01"
|
||||||
|
"\x56\x5a\x11\x22\xb2\x56\x35\x15"
|
||||||
|
"\x0a\xd1\xf7\xa0\x4b\xb9\xf3\xa3"
|
||||||
|
"\x33\xec\xc0\xe2\xe1\xf7\x08\x37", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 2,
|
||||||
|
"password", 8,
|
||||||
|
"ATHENA.MIT.EDUraeburn", 21,
|
||||||
|
"\x01\xdb\xee\x7f\x4a\x9e\x24\x3e"
|
||||||
|
"\x98\x8b\x62\xc7\x3c\xda\x93\x5d"
|
||||||
|
"\xa0\x53\x78\xb9\x32\x44\xec\x8f"
|
||||||
|
"\x48\xa9\x9e\x61\xad\x79\x9d\x86", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 1200,
|
||||||
|
"password", 8,
|
||||||
|
"ATHENA.MIT.EDUraeburn", 21,
|
||||||
|
"\x5c\x08\xeb\x61\xfd\xf7\x1e\x4e"
|
||||||
|
"\x4e\xc3\xcf\x6b\xa1\xf5\x51\x2b"
|
||||||
|
"\xa7\xe5\x2d\xdb\xc5\xe5\x14\x2f"
|
||||||
|
"\x70\x8a\x31\xe2\xe6\x2b\x1e\x13", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 5,
|
||||||
|
"password", 8,
|
||||||
|
"\0224VxxV4\022", 8, // "\x1234567878563412
|
||||||
|
"\xd1\xda\xa7\x86\x15\xf2\x87\xe6"
|
||||||
|
"\xa1\xc8\xb1\x20\xd7\x06\x2a\x49"
|
||||||
|
"\x3f\x98\xd2\x03\xe6\xbe\x49\xa6"
|
||||||
|
"\xad\xf4\xfa\x57\x4b\x6e\x64\xee", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 1200,
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", 64,
|
||||||
|
"pass phrase equals block size", 29,
|
||||||
|
"\x13\x9c\x30\xc0\x96\x6b\xc3\x2b"
|
||||||
|
"\xa5\x5f\xdb\xf2\x12\x53\x0a\xc9"
|
||||||
|
"\xc5\xec\x59\xf1\xa4\x52\xf5\xcc"
|
||||||
|
"\x9a\xd9\x40\xfe\xa0\x59\x8e\xd1", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 1200,
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", 65,
|
||||||
|
"pass phrase exceeds block size", 30,
|
||||||
|
"\x9c\xca\xd6\xd4\x68\x77\x0c\xd5"
|
||||||
|
"\x1b\x10\xe6\xa6\x87\x21\xbe\x61"
|
||||||
|
"\x1a\x8b\x4d\x28\x26\x01\xdb\x3b"
|
||||||
|
"\x36\xbe\x92\x46\x91\x5e\xc8\x2a", 32
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 50,
|
||||||
|
"\360\235\204\236", 4, // g-clef ("\xf09d849e)
|
||||||
|
"EXAMPLE.COMpianist", 18,
|
||||||
|
"\x6b\x9c\xf2\x6d\x45\x45\x5a\x43"
|
||||||
|
"\xa5\xb8\xbb\x27\x6a\x40\x3b\x39"
|
||||||
|
"\xe7\xfe\x37\xa0\xc4\x1e\x02\xc2"
|
||||||
|
"\x81\xff\x30\x69\xe1\xe9\x4f\x52", 32
|
||||||
|
}, {
|
||||||
|
/* RFC-6070 */
|
||||||
|
"sha1", 64, 1,
|
||||||
|
"password", 8,
|
||||||
|
"salt", 4,
|
||||||
|
"\x0c\x60\xc8\x0f\x96\x1f\x0e\x71\xf3\xa9"
|
||||||
|
"\xb5\x24\xaf\x60\x12\x06\x2f\xe0\x37\xa6", 20
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 2,
|
||||||
|
"password", 8,
|
||||||
|
"salt", 4,
|
||||||
|
"\xea\x6c\x01\x4d\xc7\x2d\x6f\x8c\xcd\x1e"
|
||||||
|
"\xd9\x2a\xce\x1d\x41\xf0\xd8\xde\x89\x57", 20
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 4096,
|
||||||
|
"password", 8,
|
||||||
|
"salt", 4,
|
||||||
|
"\x4b\x00\x79\x01\xb7\x65\x48\x9a\xbe\xad"
|
||||||
|
"\x49\xd9\x26\xf7\x21\xd0\x65\xa4\x29\xc1", 20
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 16777216,
|
||||||
|
"password", 8,
|
||||||
|
"salt", 4,
|
||||||
|
"\xee\xfe\x3d\x61\xcd\x4d\xa4\xe4\xe9\x94"
|
||||||
|
"\x5b\x3d\x6b\xa2\x15\x8c\x26\x34\xe9\x84", 20
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 4096,
|
||||||
|
"passwordPASSWORDpassword", 24,
|
||||||
|
"saltSALTsaltSALTsaltSALTsaltSALTsalt", 36,
|
||||||
|
"\x3d\x2e\xec\x4f\xe4\x1c\x84\x9b\x80\xc8"
|
||||||
|
"\xd8\x36\x62\xc0\xe4\x4a\x8b\x29\x1a\x96"
|
||||||
|
"\x4c\xf2\xf0\x70\x38", 25
|
||||||
|
}, {
|
||||||
|
"sha1", 64, 4096,
|
||||||
|
"pass\0word", 9,
|
||||||
|
"sa\0lt", 5,
|
||||||
|
"\x56\xfa\x6a\xa7\x55\x48\x09\x9d\xcc\x37"
|
||||||
|
"\xd7\xf0\x34\x25\xe0\xc3", 16
|
||||||
|
}, {
|
||||||
|
/* empty password test */
|
||||||
|
"sha1", 64, 2,
|
||||||
|
"", 0,
|
||||||
|
"salt", 4,
|
||||||
|
"\x13\x3a\x4c\xe8\x37\xb4\xd2\x52\x1e\xe2"
|
||||||
|
"\xbf\x03\xe1\x1c\x71\xca\x79\x4e\x07\x97", 20
|
||||||
|
}, {
|
||||||
|
/* Password exceeds block size test */
|
||||||
|
"sha256", 64, 1200,
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", 65,
|
||||||
|
"pass phrase exceeds block size", 30,
|
||||||
|
"\x22\x34\x4b\xc4\xb6\xe3\x26\x75"
|
||||||
|
"\xa8\x09\x0f\x3e\xa8\x0b\xe0\x1d"
|
||||||
|
"\x5f\x95\x12\x6a\x2c\xdd\xc3\xfa"
|
||||||
|
"\xcc\x4a\x5e\x6d\xca\x04\xec\x58", 32
|
||||||
|
}, {
|
||||||
|
"sha512", 128, 1200,
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", 129,
|
||||||
|
"pass phrase exceeds block size", 30,
|
||||||
|
"\x0f\xb2\xed\x2c\x0e\x6e\xfb\x7d"
|
||||||
|
"\x7d\x8e\xdd\x58\x01\xb4\x59\x72"
|
||||||
|
"\x99\x92\x16\x30\x5e\xa4\x36\x8d"
|
||||||
|
"\x76\x14\x80\xf3\xe3\x7a\x22\xb9", 32
|
||||||
|
}, {
|
||||||
|
"whirlpool", 64, 1200,
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
|
||||||
|
"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", 65,
|
||||||
|
"pass phrase exceeds block size", 30,
|
||||||
|
"\x9c\x1c\x74\xf5\x88\x26\xe7\x6a"
|
||||||
|
"\x53\x58\xf4\x0c\x39\xe7\x80\x89"
|
||||||
|
"\x07\xc0\x31\x19\x9a\x50\xa2\x48"
|
||||||
|
"\xf1\xd9\xfe\x78\x64\xe5\x84\x50", 32
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
static void printhex(const char *s, const char *buf, size_t len)
|
||||||
|
{
|
||||||
|
size_t i;
|
||||||
|
|
||||||
|
printf("%s: ", s);
|
||||||
|
for (i = 0; i < len; i++)
|
||||||
|
printf("\\x%02x", (unsigned char)buf[i]);
|
||||||
|
printf("\n");
|
||||||
|
fflush(stdout);
|
||||||
|
}
|
||||||
|
|
||||||
|
static int pkcs5_pbkdf2_test_vectors(void)
|
||||||
|
{
|
||||||
|
char result[64];
|
||||||
|
unsigned int i, j;
|
||||||
|
struct test_vector *vec;
|
||||||
|
|
||||||
|
for (i = 0; i < (sizeof(test_vectors) / sizeof(*test_vectors)); i++) {
|
||||||
|
vec = &test_vectors[i];
|
||||||
|
for (j = 1; j <= vec->output_length; j++) {
|
||||||
|
if (pkcs5_pbkdf2(vec->hash,
|
||||||
|
vec->password, vec->password_length,
|
||||||
|
vec->salt, vec->salt_length,
|
||||||
|
vec->iterations,
|
||||||
|
j, result, vec->hash_block_length)) {
|
||||||
|
printf("pbkdf2 failed, vector %d\n", i);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
if (memcmp(result, vec->output, j) != 0) {
|
||||||
|
printf("vector %u\n", i);
|
||||||
|
printhex(" got", result, j);
|
||||||
|
printhex("want", vec->output, j);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
memset(result, 0, sizeof(result));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
#endif
|
||||||
117
lib/crypto_backend/pbkdf_check.c
Normal file
117
lib/crypto_backend/pbkdf_check.c
Normal file
@@ -0,0 +1,117 @@
|
|||||||
|
/*
|
||||||
|
* PBKDF performance check
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2014, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include <sys/time.h>
|
||||||
|
#include <sys/resource.h>
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
static long time_ms(struct rusage *start, struct rusage *end)
|
||||||
|
{
|
||||||
|
int count_kernel_time = 0;
|
||||||
|
long ms;
|
||||||
|
|
||||||
|
if (crypt_backend_flags() & CRYPT_BACKEND_KERNEL)
|
||||||
|
count_kernel_time = 1;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* FIXME: if there is no self usage info, count system time.
|
||||||
|
* This seem like getrusage() bug in some hypervisors...
|
||||||
|
*/
|
||||||
|
if (!end->ru_utime.tv_sec && !start->ru_utime.tv_sec &&
|
||||||
|
!end->ru_utime.tv_usec && !start->ru_utime.tv_usec)
|
||||||
|
count_kernel_time = 1;
|
||||||
|
|
||||||
|
ms = (end->ru_utime.tv_sec - start->ru_utime.tv_sec) * 1000;
|
||||||
|
ms += (end->ru_utime.tv_usec - start->ru_utime.tv_usec) / 1000;
|
||||||
|
|
||||||
|
if (count_kernel_time) {
|
||||||
|
ms += (end->ru_stime.tv_sec - start->ru_stime.tv_sec) * 1000;
|
||||||
|
ms += (end->ru_stime.tv_usec - start->ru_stime.tv_usec) / 1000;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ms;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* This code benchmarks PBKDF and returns iterations/second using specified hash */
|
||||||
|
int crypt_pbkdf_check(const char *kdf, const char *hash,
|
||||||
|
const char *password, size_t password_length,
|
||||||
|
const char *salt, size_t salt_length,
|
||||||
|
size_t key_length, uint64_t *iter_secs)
|
||||||
|
{
|
||||||
|
struct rusage rstart, rend;
|
||||||
|
int r = 0, step = 0;
|
||||||
|
long ms = 0;
|
||||||
|
char *key = NULL;
|
||||||
|
unsigned int iterations;
|
||||||
|
|
||||||
|
if (!kdf || !hash || key_length <= 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
key = malloc(key_length);
|
||||||
|
if (!key)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
iterations = 1 << 15;
|
||||||
|
while (ms < 500) {
|
||||||
|
if (getrusage(RUSAGE_SELF, &rstart) < 0) {
|
||||||
|
r = -EINVAL;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = crypt_pbkdf(kdf, hash, password, password_length, salt,
|
||||||
|
salt_length, key, key_length, iterations);
|
||||||
|
if (r < 0)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if (getrusage(RUSAGE_SELF, &rend) < 0) {
|
||||||
|
r = -EINVAL;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
ms = time_ms(&rstart, &rend);
|
||||||
|
if (ms > 500)
|
||||||
|
break;
|
||||||
|
|
||||||
|
if (ms <= 62)
|
||||||
|
iterations <<= 4;
|
||||||
|
else if (ms <= 125)
|
||||||
|
iterations <<= 3;
|
||||||
|
else if (ms <= 250)
|
||||||
|
iterations <<= 2;
|
||||||
|
else
|
||||||
|
iterations <<= 1;
|
||||||
|
|
||||||
|
if (++step > 10 || !iterations) {
|
||||||
|
r = -EINVAL;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (iter_secs)
|
||||||
|
*iter_secs = (iterations * 1000) / ms;
|
||||||
|
out:
|
||||||
|
if (key) {
|
||||||
|
crypt_backend_memzero(key, key_length);
|
||||||
|
free(key);
|
||||||
|
}
|
||||||
|
return r;
|
||||||
|
}
|
||||||
@@ -1,19 +1,43 @@
|
|||||||
|
/*
|
||||||
|
* libcryptsetup - cryptsetup library internal
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2012, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef INTERNAL_H
|
#ifndef INTERNAL_H
|
||||||
#define INTERNAL_H
|
#define INTERNAL_H
|
||||||
|
|
||||||
#ifdef HAVE_CONFIG_H
|
|
||||||
# include "config.h"
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
#include <stdarg.h>
|
#include <stdarg.h>
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
|
|
||||||
#include "nls.h"
|
#include "nls.h"
|
||||||
|
#include "bitops.h"
|
||||||
#include "utils_crypt.h"
|
#include "utils_crypt.h"
|
||||||
#include "utils_loop.h"
|
#include "utils_loop.h"
|
||||||
#include "utils_dm.h"
|
#include "utils_dm.h"
|
||||||
|
#include "utils_fips.h"
|
||||||
|
#include "crypto_backend.h"
|
||||||
|
|
||||||
|
#include "libcryptsetup.h"
|
||||||
|
|
||||||
/* to silent gcc -Wcast-qual for const cast */
|
/* to silent gcc -Wcast-qual for const cast */
|
||||||
#define CONST_CAST(x) (x)(uintptr_t)
|
#define CONST_CAST(x) (x)(uintptr_t)
|
||||||
@@ -37,46 +61,63 @@ struct volume_key *crypt_alloc_volume_key(unsigned keylength, const char *key);
|
|||||||
struct volume_key *crypt_generate_volume_key(struct crypt_device *cd, unsigned keylength);
|
struct volume_key *crypt_generate_volume_key(struct crypt_device *cd, unsigned keylength);
|
||||||
void crypt_free_volume_key(struct volume_key *vk);
|
void crypt_free_volume_key(struct volume_key *vk);
|
||||||
|
|
||||||
|
/* Device backend */
|
||||||
|
struct device;
|
||||||
|
int device_alloc(struct device **device, const char *path);
|
||||||
|
void device_free(struct device *device);
|
||||||
|
const char *device_path(const struct device *device);
|
||||||
|
const char *device_block_path(const struct device *device);
|
||||||
|
void device_topology_alignment(struct device *device,
|
||||||
|
unsigned long *required_alignment, /* bytes */
|
||||||
|
unsigned long *alignment_offset, /* bytes */
|
||||||
|
unsigned long default_alignment);
|
||||||
|
int device_block_size(struct device *device);
|
||||||
|
int device_read_ahead(struct device *device, uint32_t *read_ahead);
|
||||||
|
int device_size(struct device *device, uint64_t *size);
|
||||||
|
int device_open(struct device *device, int flags);
|
||||||
|
void device_disable_direct_io(struct device *device);
|
||||||
|
|
||||||
|
|
||||||
|
enum devcheck { DEV_OK = 0, DEV_EXCL = 1, DEV_SHARED = 2 };
|
||||||
|
int device_block_adjust(struct crypt_device *cd,
|
||||||
|
struct device *device,
|
||||||
|
enum devcheck device_check,
|
||||||
|
uint64_t device_offset,
|
||||||
|
uint64_t *size,
|
||||||
|
uint32_t *flags);
|
||||||
|
size_t size_round_up(size_t size, unsigned int block);
|
||||||
|
|
||||||
|
/* Receive backend devices from context helpers */
|
||||||
|
struct device *crypt_metadata_device(struct crypt_device *cd);
|
||||||
|
struct device *crypt_data_device(struct crypt_device *cd);
|
||||||
|
|
||||||
int crypt_confirm(struct crypt_device *cd, const char *msg);
|
int crypt_confirm(struct crypt_device *cd, const char *msg);
|
||||||
|
|
||||||
char *crypt_lookup_dev(const char *dev_id);
|
char *crypt_lookup_dev(const char *dev_id);
|
||||||
int crypt_sysfs_check_crypt_segment(const char *device, uint64_t offset, uint64_t size);
|
int crypt_dev_is_rotational(int major, int minor);
|
||||||
int crypt_sysfs_get_rotational(int major, int minor, int *rotational);
|
int crypt_dev_is_partition(const char *dev_path);
|
||||||
|
char *crypt_get_partition_device(const char *dev_path, uint64_t offset, uint64_t size);
|
||||||
|
char *crypt_get_base_device(const char *dev_path);
|
||||||
|
uint64_t crypt_dev_partition_offset(const char *dev_path);
|
||||||
|
|
||||||
int sector_size_for_device(const char *device);
|
ssize_t write_blockwise(int fd, int bsize, void *buf, size_t count);
|
||||||
int device_read_ahead(const char *dev, uint32_t *read_ahead);
|
ssize_t read_blockwise(int fd, int bsize, void *_buf, size_t count);
|
||||||
ssize_t write_blockwise(int fd, void *buf, size_t count);
|
ssize_t write_lseek_blockwise(int fd, int bsize, char *buf, size_t count, off_t offset);
|
||||||
ssize_t read_blockwise(int fd, void *_buf, size_t count);
|
|
||||||
ssize_t write_lseek_blockwise(int fd, char *buf, size_t count, off_t offset);
|
|
||||||
int device_ready(struct crypt_device *cd, const char *device, int mode);
|
|
||||||
int device_size(const char *device, uint64_t *size);
|
|
||||||
|
|
||||||
enum devcheck { DEV_OK = 0, DEV_EXCL = 1, DEV_SHARED = 2 };
|
unsigned crypt_getpagesize(void);
|
||||||
int device_check_and_adjust(struct crypt_device *cd,
|
int init_crypto(struct crypt_device *ctx);
|
||||||
const char *device,
|
|
||||||
enum devcheck device_check,
|
|
||||||
uint64_t *size,
|
|
||||||
uint64_t *offset,
|
|
||||||
uint32_t *flags);
|
|
||||||
|
|
||||||
void logger(struct crypt_device *cd, int class, const char *file, int line, const char *format, ...);
|
void logger(struct crypt_device *cd, int class, const char *file, int line, const char *format, ...) __attribute__ ((format (printf, 5, 6)));
|
||||||
#define log_dbg(x...) logger(NULL, CRYPT_LOG_DEBUG, __FILE__, __LINE__, x)
|
#define log_dbg(x...) logger(NULL, CRYPT_LOG_DEBUG, __FILE__, __LINE__, x)
|
||||||
#define log_std(c, x...) logger(c, CRYPT_LOG_NORMAL, __FILE__, __LINE__, x)
|
#define log_std(c, x...) logger(c, CRYPT_LOG_NORMAL, __FILE__, __LINE__, x)
|
||||||
#define log_verbose(c, x...) logger(c, CRYPT_LOG_VERBOSE, __FILE__, __LINE__, x)
|
#define log_verbose(c, x...) logger(c, CRYPT_LOG_VERBOSE, __FILE__, __LINE__, x)
|
||||||
#define log_err(c, x...) logger(c, CRYPT_LOG_ERROR, __FILE__, __LINE__, x)
|
#define log_err(c, x...) logger(c, CRYPT_LOG_ERROR, __FILE__, __LINE__, x)
|
||||||
|
|
||||||
int crypt_get_debug_level(void);
|
int crypt_get_debug_level(void);
|
||||||
void debug_processes_using_device(const char *name);
|
|
||||||
|
|
||||||
int crypt_memlock_inc(struct crypt_device *ctx);
|
int crypt_memlock_inc(struct crypt_device *ctx);
|
||||||
int crypt_memlock_dec(struct crypt_device *ctx);
|
int crypt_memlock_dec(struct crypt_device *ctx);
|
||||||
|
|
||||||
void get_topology_alignment(const char *device,
|
|
||||||
unsigned long *required_alignment, /* bytes */
|
|
||||||
unsigned long *alignment_offset, /* bytes */
|
|
||||||
unsigned long default_alignment);
|
|
||||||
|
|
||||||
enum { CRYPT_RND_NORMAL = 0, CRYPT_RND_KEY = 1 };
|
|
||||||
int crypt_random_init(struct crypt_device *ctx);
|
int crypt_random_init(struct crypt_device *ctx);
|
||||||
int crypt_random_get(struct crypt_device *ctx, char *buf, size_t len, int quality);
|
int crypt_random_get(struct crypt_device *ctx, char *buf, size_t len, int quality);
|
||||||
void crypt_random_exit(void);
|
void crypt_random_exit(void);
|
||||||
@@ -105,7 +146,7 @@ typedef enum {
|
|||||||
* random algorithm */
|
* random algorithm */
|
||||||
} crypt_wipe_type;
|
} crypt_wipe_type;
|
||||||
|
|
||||||
int crypt_wipe(const char *device,
|
int crypt_wipe(struct device *device,
|
||||||
uint64_t offset,
|
uint64_t offset,
|
||||||
uint64_t sectors,
|
uint64_t sectors,
|
||||||
crypt_wipe_type type,
|
crypt_wipe_type type,
|
||||||
|
|||||||
@@ -1,3 +1,26 @@
|
|||||||
|
/*
|
||||||
|
* libcryptsetup - cryptsetup library
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2016, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2016, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @file libcryptsetup.h
|
* @file libcryptsetup.h
|
||||||
* @brief Public cryptsetup API
|
* @brief Public cryptsetup API
|
||||||
@@ -12,6 +35,7 @@
|
|||||||
extern "C" {
|
extern "C" {
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#include <stddef.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
struct crypt_device; /* crypt device handle */
|
struct crypt_device; /* crypt device handle */
|
||||||
@@ -65,7 +89,7 @@ int crypt_init_by_name_and_header(struct crypt_device **cd,
|
|||||||
int crypt_init_by_name(struct crypt_device **cd, const char *name);
|
int crypt_init_by_name(struct crypt_device **cd, const char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup loglevel "Cryptsetup logging"
|
* @defgroup loglevel Cryptsetup logging
|
||||||
*
|
*
|
||||||
* Set of functions and defines used in cryptsetup for
|
* Set of functions and defines used in cryptsetup for
|
||||||
* logging purposes
|
* logging purposes
|
||||||
@@ -112,7 +136,7 @@ void crypt_log(struct crypt_device *cd, int level, const char *msg);
|
|||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set confirmation callback (yes/no)
|
* Set confirmation callback (yes/no).
|
||||||
*
|
*
|
||||||
* If code need confirmation (like resetting uuid or restoring LUKS header from file)
|
* If code need confirmation (like resetting uuid or restoring LUKS header from file)
|
||||||
* this function is called. If not defined, everything is confirmed.
|
* this function is called. If not defined, everything is confirmed.
|
||||||
@@ -132,7 +156,7 @@ void crypt_set_confirm_callback(struct crypt_device *cd,
|
|||||||
void *usrptr);
|
void *usrptr);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set password query callback.
|
* Set password query callback. DEPRECATED
|
||||||
*
|
*
|
||||||
* If code need @e _interactive_ query for password, this callback is called.
|
* If code need @e _interactive_ query for password, this callback is called.
|
||||||
* If not defined, compiled-in default is called (uses terminal input).
|
* If not defined, compiled-in default is called (uses terminal input).
|
||||||
@@ -152,6 +176,7 @@ void crypt_set_confirm_callback(struct crypt_device *cd,
|
|||||||
* @note Only zero terminated passwords can be entered this way, for complex
|
* @note Only zero terminated passwords can be entered this way, for complex
|
||||||
* use API functions directly.
|
* use API functions directly.
|
||||||
* @note Maximal length of password is limited to @e length @e - @e 1 (minimal 511 chars)
|
* @note Maximal length of password is limited to @e length @e - @e 1 (minimal 511 chars)
|
||||||
|
* @note This function is DEPRECATED and will be removed in future versions.
|
||||||
*
|
*
|
||||||
* @see Callback function is used in these call provided, that certain conditions are met:
|
* @see Callback function is used in these call provided, that certain conditions are met:
|
||||||
* @li crypt_keyslot_add_by_passphrase
|
* @li crypt_keyslot_add_by_passphrase
|
||||||
@@ -168,7 +193,7 @@ void crypt_set_password_callback(struct crypt_device *cd,
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Set timeout for interactive password entry using default
|
* Set timeout for interactive password entry using default
|
||||||
* password callback
|
* password callback. DEPRECATED
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param timeout_sec timeout in seconds
|
* @param timeout_sec timeout in seconds
|
||||||
@@ -176,45 +201,50 @@ void crypt_set_password_callback(struct crypt_device *cd,
|
|||||||
void crypt_set_timeout(struct crypt_device *cd, uint64_t timeout_sec);
|
void crypt_set_timeout(struct crypt_device *cd, uint64_t timeout_sec);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set number of retries in case password input has been incorrect
|
* Set number of retries in case password input has been incorrect. DEPRECATED.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param tries the number
|
* @param tries the number
|
||||||
|
*
|
||||||
|
* @note This function is DEPRECATED and will be removed in future versions.
|
||||||
*/
|
*/
|
||||||
void crypt_set_password_retry(struct crypt_device *cd, int tries);
|
void crypt_set_password_retry(struct crypt_device *cd, int tries);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set how long should cryptsetup iterate in PBKDF2 function.
|
* Set how long should cryptsetup iterate in PBKDF2 function.
|
||||||
* Default value heads towards the iterations which takes around 1 second
|
* Default value heads towards the iterations which takes around 1 second.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param iteration_time_ms the time in ms
|
* @param iteration_time_ms the time in ms
|
||||||
*/
|
*/
|
||||||
|
void crypt_set_iteration_time(struct crypt_device *cd, uint64_t iteration_time_ms);
|
||||||
|
/* Don't ask :-) */
|
||||||
void crypt_set_iterarion_time(struct crypt_device *cd, uint64_t iteration_time_ms);
|
void crypt_set_iterarion_time(struct crypt_device *cd, uint64_t iteration_time_ms);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set whether passphrase will be verified on input
|
* Set whether passphrase will be verified on input
|
||||||
* (user has to input same passphrase twice)
|
* (user has to input same passphrase twice). DEPRECATED
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param password_verify @e 0 = false, @e !0 true
|
* @param password_verify @e 0 = false, @e !0 true
|
||||||
|
*
|
||||||
|
* @note This function is DEPRECATED and will be removed in future versions.
|
||||||
*/
|
*/
|
||||||
void crypt_set_password_verify(struct crypt_device *cd, int password_verify);
|
void crypt_set_password_verify(struct crypt_device *cd, int password_verify);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set data device (encrypted payload area device) if LUKS header is separated
|
* Set data device
|
||||||
|
* For LUKS it is encrypted data device when LUKS header is separated.
|
||||||
|
* For VERITY it is data device when hash device is separated.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param device path to device
|
* @param device path to device
|
||||||
*
|
*
|
||||||
* @pre context is of LUKS type
|
|
||||||
* @pre unlike @ref crypt_init, in this function param @e device
|
|
||||||
* has to be block device (at least 512B large)
|
|
||||||
*/
|
*/
|
||||||
int crypt_set_data_device(struct crypt_device *cd, const char *device);
|
int crypt_set_data_device(struct crypt_device *cd, const char *device);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup rng "Cryptsetup RNG"
|
* @defgroup rng Cryptsetup RNG
|
||||||
*
|
*
|
||||||
* @addtogroup rng
|
* @addtogroup rng
|
||||||
* @{
|
* @{
|
||||||
@@ -236,7 +266,7 @@ int crypt_set_data_device(struct crypt_device *cd, const char *device);
|
|||||||
void crypt_set_rng_type(struct crypt_device *cd, int rng_type);
|
void crypt_set_rng_type(struct crypt_device *cd, int rng_type);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get which RNG (random number generator) is used for generating long term key
|
* Get which RNG (random number generator) is used for generating long term key.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @return RNG type on success or negative errno value otherwise.
|
* @return RNG type on success or negative errno value otherwise.
|
||||||
@@ -247,7 +277,7 @@ int crypt_get_rng_type(struct crypt_device *cd);
|
|||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Helper to lock/unlock memory to avoid swap sensitive data to disk
|
* Helper to lock/unlock memory to avoid swap sensitive data to disk.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle, can be @e NULL
|
* @param cd crypt device handle, can be @e NULL
|
||||||
* @param lock 0 to unlock otherwise lock memory
|
* @param lock 0 to unlock otherwise lock memory
|
||||||
@@ -260,7 +290,7 @@ int crypt_get_rng_type(struct crypt_device *cd);
|
|||||||
int crypt_memory_lock(struct crypt_device *cd, int lock);
|
int crypt_memory_lock(struct crypt_device *cd, int lock);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup crypt_type "Cryptsetup on-disk format types"
|
* @defgroup crypt_type Cryptsetup on-disk format types
|
||||||
*
|
*
|
||||||
* Set of functions, \#defines and structs related
|
* Set of functions, \#defines and structs related
|
||||||
* to on-disk format types
|
* to on-disk format types
|
||||||
@@ -271,12 +301,16 @@ int crypt_memory_lock(struct crypt_device *cd, int lock);
|
|||||||
* @{
|
* @{
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/** regular crypt device, no on-disk header */
|
/** plain crypt device, no on-disk header */
|
||||||
#define CRYPT_PLAIN "PLAIN"
|
#define CRYPT_PLAIN "PLAIN"
|
||||||
/** LUKS version 1 header on-disk */
|
/** LUKS version 1 header on-disk */
|
||||||
#define CRYPT_LUKS1 "LUKS1"
|
#define CRYPT_LUKS1 "LUKS1"
|
||||||
/** loop-AES compatibility mode */
|
/** loop-AES compatibility mode */
|
||||||
#define CRYPT_LOOPAES "LOOPAES"
|
#define CRYPT_LOOPAES "LOOPAES"
|
||||||
|
/** dm-verity mode */
|
||||||
|
#define CRYPT_VERITY "VERITY"
|
||||||
|
/** TCRYPT (TrueCrypt-compatible and VeraCrypt-compatible) mode */
|
||||||
|
#define CRYPT_TCRYPT "TCRYPT"
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get device type
|
* Get device type
|
||||||
@@ -288,7 +322,7 @@ const char *crypt_get_type(struct crypt_device *cd);
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
*
|
*
|
||||||
* Structure used as parameter for PLAIN device type
|
* Structure used as parameter for PLAIN device type.
|
||||||
*
|
*
|
||||||
* @see crypt_format
|
* @see crypt_format
|
||||||
*/
|
*/
|
||||||
@@ -300,7 +334,7 @@ struct crypt_params_plain {
|
|||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Structure used as parameter for LUKS device type
|
* Structure used as parameter for LUKS device type.
|
||||||
*
|
*
|
||||||
* @see crypt_format, crypt_load
|
* @see crypt_format, crypt_load
|
||||||
*
|
*
|
||||||
@@ -316,7 +350,7 @@ struct crypt_params_luks1 {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
*
|
*
|
||||||
* Structure used as parameter for loop-AES device type
|
* Structure used as parameter for loop-AES device type.
|
||||||
*
|
*
|
||||||
* @see crypt_format
|
* @see crypt_format
|
||||||
*
|
*
|
||||||
@@ -327,10 +361,71 @@ struct crypt_params_loopaes {
|
|||||||
uint64_t skip; /**< IV offset / initialization sector */
|
uint64_t skip; /**< IV offset / initialization sector */
|
||||||
};
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
*
|
||||||
|
* Structure used as parameter for dm-verity device type.
|
||||||
|
*
|
||||||
|
* @see crypt_format, crypt_load
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
struct crypt_params_verity {
|
||||||
|
const char *hash_name; /**< hash function */
|
||||||
|
const char *data_device; /**< data_device (CRYPT_VERITY_CREATE_HASH) */
|
||||||
|
const char *hash_device; /**< hash_device (output only) */
|
||||||
|
const char *salt; /**< salt */
|
||||||
|
uint32_t salt_size; /**< salt size (in bytes) */
|
||||||
|
uint32_t hash_type; /**< in-kernel hashing type */
|
||||||
|
uint32_t data_block_size; /**< data block size (in bytes) */
|
||||||
|
uint32_t hash_block_size; /**< hash block size (in bytes) */
|
||||||
|
uint64_t data_size; /**< data area size (in data blocks) */
|
||||||
|
uint64_t hash_area_offset; /**< hash/header offset (in bytes) */
|
||||||
|
uint32_t flags; /**< CRYPT_VERITY* flags */
|
||||||
|
};
|
||||||
|
|
||||||
|
/** No on-disk header (only hashes) */
|
||||||
|
#define CRYPT_VERITY_NO_HEADER (1 << 0)
|
||||||
|
/** Verity hash in userspace before activation */
|
||||||
|
#define CRYPT_VERITY_CHECK_HASH (1 << 1)
|
||||||
|
/** Create hash - format hash device */
|
||||||
|
#define CRYPT_VERITY_CREATE_HASH (1 << 2)
|
||||||
|
|
||||||
|
/**
|
||||||
|
*
|
||||||
|
* Structure used as parameter for TCRYPT device type.
|
||||||
|
*
|
||||||
|
* @see crypt_load
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
struct crypt_params_tcrypt {
|
||||||
|
const char *passphrase; /**< passphrase to unlock header (input only) */
|
||||||
|
size_t passphrase_size; /**< passphrase size (input only, max length is 64) */
|
||||||
|
const char **keyfiles; /**< keyfile paths to unlock header (input only) */
|
||||||
|
unsigned int keyfiles_count;/**< keyfiles count (input only) */
|
||||||
|
const char *hash_name; /**< hash function for PBKDF */
|
||||||
|
const char *cipher; /**< cipher chain c1[-c2[-c3]] */
|
||||||
|
const char *mode; /**< cipher block mode */
|
||||||
|
size_t key_size; /**< key size in bytes (the whole chain) */
|
||||||
|
uint32_t flags; /**< CRYPT_TCRYPT* flags */
|
||||||
|
};
|
||||||
|
|
||||||
|
/** Include legacy modes when scanning for header */
|
||||||
|
#define CRYPT_TCRYPT_LEGACY_MODES (1 << 0)
|
||||||
|
/** Try to load hidden header (describing hidden device) */
|
||||||
|
#define CRYPT_TCRYPT_HIDDEN_HEADER (1 << 1)
|
||||||
|
/** Try to load backup header */
|
||||||
|
#define CRYPT_TCRYPT_BACKUP_HEADER (1 << 2)
|
||||||
|
/** Device contains encrypted system (with boot loader) */
|
||||||
|
#define CRYPT_TCRYPT_SYSTEM_HEADER (1 << 3)
|
||||||
|
/** Include VeraCrypt modes when scanning for header,
|
||||||
|
* all other TCRYPT flags applies as well.
|
||||||
|
* VeraCrypt device is reported as TCRYPT type.
|
||||||
|
*/
|
||||||
|
#define CRYPT_TCRYPT_VERA_MODES (1 << 4)
|
||||||
|
|
||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create (format) new crypt device (and possible header on-disk) but not activates it.
|
* Create (format) new crypt device (and possible header on-disk) but do not activate it.
|
||||||
*
|
*
|
||||||
* @pre @e cd contains initialized and not formatted device context (device type must @b not be set)
|
* @pre @e cd contains initialized and not formatted device context (device type must @b not be set)
|
||||||
*
|
*
|
||||||
@@ -345,8 +440,10 @@ struct crypt_params_loopaes {
|
|||||||
*
|
*
|
||||||
* @returns @e 0 on success or negative errno value otherwise.
|
* @returns @e 0 on success or negative errno value otherwise.
|
||||||
*
|
*
|
||||||
* @note Note that crypt_format does not enable any keyslot (in case of work with LUKS device), but it stores volume key internally
|
* @note Note that crypt_format does not enable any keyslot (in case of work with LUKS device),
|
||||||
* and subsequent crypt_keyslot_add_* calls can be used.
|
* but it stores volume key internally and subsequent crypt_keyslot_add_* calls can be used.
|
||||||
|
* @note For VERITY @link crypt_type @endlink, only uuid parameter is used, others paramaters
|
||||||
|
* are ignored and verity specific attributes are set through mandatory params option.
|
||||||
*/
|
*/
|
||||||
int crypt_format(struct crypt_device *cd,
|
int crypt_format(struct crypt_device *cd,
|
||||||
const char *type,
|
const char *type,
|
||||||
@@ -358,7 +455,7 @@ int crypt_format(struct crypt_device *cd,
|
|||||||
void *params);
|
void *params);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Set new UUID for already existing device
|
* Set new UUID for already existing device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param uuid requested UUID or @e NULL if it should be generated
|
* @param uuid requested UUID or @e NULL if it should be generated
|
||||||
@@ -371,10 +468,10 @@ int crypt_set_uuid(struct crypt_device *cd,
|
|||||||
const char *uuid);
|
const char *uuid);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Load crypt device parameters from on-disk header
|
* Load crypt device parameters from on-disk header.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param requested_type - use @e NULL for all known
|
* @param requested_type @link crypt_type @endlink or @e NULL for all known
|
||||||
* @param params crypt type specific parameters (see @link crypt_type @endlink)
|
* @param params crypt type specific parameters (see @link crypt_type @endlink)
|
||||||
*
|
*
|
||||||
* @returns 0 on success or negative errno value otherwise.
|
* @returns 0 on success or negative errno value otherwise.
|
||||||
@@ -382,7 +479,7 @@ int crypt_set_uuid(struct crypt_device *cd,
|
|||||||
* @post In case LUKS header is read successfully but payload device is too small
|
* @post In case LUKS header is read successfully but payload device is too small
|
||||||
* error is returned and device type in context is set to @e NULL
|
* error is returned and device type in context is set to @e NULL
|
||||||
*
|
*
|
||||||
* @note Note that in current version load works only for LUKS device type
|
* @note Note that in current version load works only for LUKS and VERITY device type.
|
||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
int crypt_load(struct crypt_device *cd,
|
int crypt_load(struct crypt_device *cd,
|
||||||
@@ -390,7 +487,21 @@ int crypt_load(struct crypt_device *cd,
|
|||||||
void *params);
|
void *params);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resize crypt device
|
* Try to repair crypt device on-disk header if invalid.
|
||||||
|
*
|
||||||
|
* @param cd crypt device handle
|
||||||
|
* @param requested_type @link crypt_type @endlink or @e NULL for all known
|
||||||
|
* @param params crypt type specific parameters (see @link crypt_type @endlink)
|
||||||
|
*
|
||||||
|
* @returns 0 on success or negative errno value otherwise.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
int crypt_repair(struct crypt_device *cd,
|
||||||
|
const char *requested_type,
|
||||||
|
void *params);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resize crypt device.
|
||||||
*
|
*
|
||||||
* @param cd - crypt device handle
|
* @param cd - crypt device handle
|
||||||
* @param name - name of device to resize
|
* @param name - name of device to resize
|
||||||
@@ -403,7 +514,7 @@ int crypt_resize(struct crypt_device *cd,
|
|||||||
uint64_t new_size);
|
uint64_t new_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Suspends crypt device.
|
* Suspend crypt device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle, can be @e NULL
|
* @param cd crypt device handle, can be @e NULL
|
||||||
* @param name name of device to suspend
|
* @param name name of device to suspend
|
||||||
@@ -417,7 +528,7 @@ int crypt_suspend(struct crypt_device *cd,
|
|||||||
const char *name);
|
const char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resumes crypt device using passphrase.
|
* Resume crypt device using passphrase.
|
||||||
*
|
*
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
@@ -429,39 +540,54 @@ int crypt_suspend(struct crypt_device *cd,
|
|||||||
* @return unlocked key slot number or negative errno otherwise.
|
* @return unlocked key slot number or negative errno otherwise.
|
||||||
*
|
*
|
||||||
* @note Only LUKS device type is supported
|
* @note Only LUKS device type is supported
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
*/
|
*/
|
||||||
int crypt_resume_by_passphrase(struct crypt_device *cd,
|
int crypt_resume_by_passphrase(struct crypt_device *cd,
|
||||||
const char *name,
|
const char *name,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
const char *passphrase,
|
const char *passphrase,
|
||||||
size_t passphrase_size);
|
size_t passphrase_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resumes crypt device using key file.
|
* Resume crypt device using key file.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param name name of device to resume
|
* @param name name of device to resume
|
||||||
* @param keyslot requested keyslot or CRYPT_ANY_SLOT
|
* @param keyslot requested keyslot or CRYPT_ANY_SLOT
|
||||||
* @param keyfile key file used to unlock volume key, @e NULL for passphrase query
|
* @param keyfile key file used to unlock volume key, @e NULL for passphrase query
|
||||||
* @param keyfile_size number of bytes to read from keyfile, 0 is unlimited
|
* @param keyfile_size number of bytes to read from keyfile, 0 is unlimited
|
||||||
|
* @param keyfile_offset number of bytes to skip at start of keyfile
|
||||||
*
|
*
|
||||||
* @return unlocked key slot number or negative errno otherwise.
|
* @return unlocked key slot number or negative errno otherwise.
|
||||||
|
*
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
|
*/
|
||||||
|
int crypt_resume_by_keyfile_offset(struct crypt_device *cd,
|
||||||
|
const char *name,
|
||||||
|
int keyslot,
|
||||||
|
const char *keyfile,
|
||||||
|
size_t keyfile_size,
|
||||||
|
size_t keyfile_offset);
|
||||||
|
/**
|
||||||
|
* Backward compatible crypt_resume_by_keyfile_offset() (without offset).
|
||||||
*/
|
*/
|
||||||
int crypt_resume_by_keyfile(struct crypt_device *cd,
|
int crypt_resume_by_keyfile(struct crypt_device *cd,
|
||||||
const char *name,
|
const char *name,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
const char *keyfile,
|
const char *keyfile,
|
||||||
size_t keyfile_size);
|
size_t keyfile_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Releases crypt device context and used memory.
|
* Release crypt device context and used memory.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*/
|
*/
|
||||||
void crypt_free(struct crypt_device *cd);
|
void crypt_free(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup keyslot "Cryptsetup LUKS keyslots"
|
* @defgroup keyslot Cryptsetup LUKS keyslots
|
||||||
* @addtogroup keyslot
|
* @addtogroup keyslot
|
||||||
* @{
|
* @{
|
||||||
*
|
*
|
||||||
@@ -471,7 +597,7 @@ void crypt_free(struct crypt_device *cd);
|
|||||||
#define CRYPT_ANY_SLOT -1
|
#define CRYPT_ANY_SLOT -1
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Add key slot using provided passphrase
|
* Add key slot using provided passphrase.
|
||||||
*
|
*
|
||||||
* @pre @e cd contains initialized and formatted LUKS device context
|
* @pre @e cd contains initialized and formatted LUKS device context
|
||||||
*
|
*
|
||||||
@@ -483,6 +609,9 @@ void crypt_free(struct crypt_device *cd);
|
|||||||
* @param new_passphrase_size size of @e new_passphrase (binary data)
|
* @param new_passphrase_size size of @e new_passphrase (binary data)
|
||||||
*
|
*
|
||||||
* @return allocated key slot number or negative errno otherwise.
|
* @return allocated key slot number or negative errno otherwise.
|
||||||
|
*
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
*/
|
*/
|
||||||
int crypt_keyslot_add_by_passphrase(struct crypt_device *cd,
|
int crypt_keyslot_add_by_passphrase(struct crypt_device *cd,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
@@ -492,17 +621,37 @@ int crypt_keyslot_add_by_passphrase(struct crypt_device *cd,
|
|||||||
size_t new_passphrase_size);
|
size_t new_passphrase_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get number of keyslots supported for device type.
|
* Change defined key slot using provided passphrase.
|
||||||
*
|
*
|
||||||
* @param type crypt device type
|
* @pre @e cd contains initialized and formatted LUKS device context
|
||||||
*
|
*
|
||||||
* @return slot count or negative errno otherwise if device
|
* @param cd crypt device handle
|
||||||
* doesn't not support keyslots.
|
* @param keyslot_old old keyslot or @e CRYPT_ANY_SLOT
|
||||||
|
* @param keyslot_new new keyslot (can be the same as old)
|
||||||
|
* @param passphrase passphrase used to unlock volume key, @e NULL for query
|
||||||
|
* @param passphrase_size size of passphrase (binary data)
|
||||||
|
* @param new_passphrase passphrase for new keyslot, @e NULL for query
|
||||||
|
* @param new_passphrase_size size of @e new_passphrase (binary data)
|
||||||
|
*
|
||||||
|
* @return allocated key slot number or negative errno otherwise.
|
||||||
|
*
|
||||||
|
* @note This function is just internal implementation of luksChange
|
||||||
|
* command to avoid reading of volume key outside libcryptsetup boundary
|
||||||
|
* in FIPS mode.
|
||||||
|
*
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
*/
|
*/
|
||||||
int crypt_keyslot_max(const char *type);
|
int crypt_keyslot_change_by_passphrase(struct crypt_device *cd,
|
||||||
|
int keyslot_old,
|
||||||
|
int keyslot_new,
|
||||||
|
const char *passphrase,
|
||||||
|
size_t passphrase_size,
|
||||||
|
const char *new_passphrase,
|
||||||
|
size_t new_passphrase_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Add key slot using provided key file path
|
* Add key slot using provided key file path.
|
||||||
*
|
*
|
||||||
* @pre @e cd contains initialized and formatted LUKS device context
|
* @pre @e cd contains initialized and formatted LUKS device context
|
||||||
*
|
*
|
||||||
@@ -510,13 +659,26 @@ int crypt_keyslot_max(const char *type);
|
|||||||
* @param keyslot requested keyslot or @e CRYPT_ANY_SLOT
|
* @param keyslot requested keyslot or @e CRYPT_ANY_SLOT
|
||||||
* @param keyfile key file used to unlock volume key, @e NULL for passphrase query
|
* @param keyfile key file used to unlock volume key, @e NULL for passphrase query
|
||||||
* @param keyfile_size number of bytes to read from keyfile, @e 0 is unlimited
|
* @param keyfile_size number of bytes to read from keyfile, @e 0 is unlimited
|
||||||
|
* @param keyfile_offset number of bytes to skip at start of keyfile
|
||||||
* @param new_keyfile keyfile for new keyslot, @e NULL for passphrase query
|
* @param new_keyfile keyfile for new keyslot, @e NULL for passphrase query
|
||||||
* @param new_keyfile_size number of bytes to read from @e new_keyfile, @e 0 is unlimited
|
* @param new_keyfile_size number of bytes to read from @e new_keyfile, @e 0 is unlimited
|
||||||
|
* @param new_keyfile_offset number of bytes to skip at start of new_keyfile
|
||||||
*
|
*
|
||||||
* @return allocated key slot number or negative errno otherwise.
|
* @return allocated key slot number or negative errno otherwise.
|
||||||
*
|
*
|
||||||
* @note Note that @e keyfile can be "-" for STDIN
|
* @note Note that @e keyfile can be "-" for STDIN. This special handling is DEPRECATED
|
||||||
*
|
* and will be removed in next version.
|
||||||
|
*/
|
||||||
|
int crypt_keyslot_add_by_keyfile_offset(struct crypt_device *cd,
|
||||||
|
int keyslot,
|
||||||
|
const char *keyfile,
|
||||||
|
size_t keyfile_size,
|
||||||
|
size_t keyfile_offset,
|
||||||
|
const char *new_keyfile,
|
||||||
|
size_t new_keyfile_size,
|
||||||
|
size_t new_keyfile_offset);
|
||||||
|
/**
|
||||||
|
* Backward compatible crypt_keyslot_add_by_keyfile_offset() (without offset).
|
||||||
*/
|
*/
|
||||||
int crypt_keyslot_add_by_keyfile(struct crypt_device *cd,
|
int crypt_keyslot_add_by_keyfile(struct crypt_device *cd,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
@@ -526,7 +688,7 @@ int crypt_keyslot_add_by_keyfile(struct crypt_device *cd,
|
|||||||
size_t new_keyfile_size);
|
size_t new_keyfile_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Add key slot using provided volume key
|
* Add key slot using provided volume key.
|
||||||
*
|
*
|
||||||
* @pre @e cd contains initialized and formatted LUKS device context
|
* @pre @e cd contains initialized and formatted LUKS device context
|
||||||
*
|
*
|
||||||
@@ -539,6 +701,8 @@ int crypt_keyslot_add_by_keyfile(struct crypt_device *cd,
|
|||||||
*
|
*
|
||||||
* @return allocated key slot number or negative errno otherwise.
|
* @return allocated key slot number or negative errno otherwise.
|
||||||
*
|
*
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
*/
|
*/
|
||||||
int crypt_keyslot_add_by_volume_key(struct crypt_device *cd,
|
int crypt_keyslot_add_by_volume_key(struct crypt_device *cd,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
@@ -548,7 +712,7 @@ int crypt_keyslot_add_by_volume_key(struct crypt_device *cd,
|
|||||||
size_t passphrase_size);
|
size_t passphrase_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Destroy (and disable) key slot
|
* Destroy (and disable) key slot.
|
||||||
*
|
*
|
||||||
* @pre @e cd contains initialized and formatted LUKS device context
|
* @pre @e cd contains initialized and formatted LUKS device context
|
||||||
*
|
*
|
||||||
@@ -564,7 +728,7 @@ int crypt_keyslot_destroy(struct crypt_device *cd, int keyslot);
|
|||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup aflags "Device runtime attributes"
|
* @defgroup aflags Device runtime attributes
|
||||||
*
|
*
|
||||||
* Activation flags
|
* Activation flags
|
||||||
*
|
*
|
||||||
@@ -576,10 +740,25 @@ int crypt_keyslot_destroy(struct crypt_device *cd, int keyslot);
|
|||||||
#define CRYPT_ACTIVATE_READONLY (1 << 0)
|
#define CRYPT_ACTIVATE_READONLY (1 << 0)
|
||||||
/** only reported for device without uuid */
|
/** only reported for device without uuid */
|
||||||
#define CRYPT_ACTIVATE_NO_UUID (1 << 1)
|
#define CRYPT_ACTIVATE_NO_UUID (1 << 1)
|
||||||
/** activate more non-overlapping mapping to the same device */
|
/** activate even if cannot grant exclusive access (DANGEROUS) */
|
||||||
#define CRYPT_ACTIVATE_SHARED (1 << 2)
|
#define CRYPT_ACTIVATE_SHARED (1 << 2)
|
||||||
/** enable discards aka TRIM */
|
/** enable discards aka TRIM */
|
||||||
#define CRYPT_ACTIVATE_ALLOW_DISCARDS (1 << 3)
|
#define CRYPT_ACTIVATE_ALLOW_DISCARDS (1 << 3)
|
||||||
|
/** skip global udev rules in activation ("private device"), input only */
|
||||||
|
#define CRYPT_ACTIVATE_PRIVATE (1 << 4)
|
||||||
|
/** corruption detected (verity), output only */
|
||||||
|
#define CRYPT_ACTIVATE_CORRUPTED (1 << 5)
|
||||||
|
/** use same_cpu_crypt option for dm-crypt */
|
||||||
|
#define CRYPT_ACTIVATE_SAME_CPU_CRYPT (1 << 6)
|
||||||
|
/** use submit_from_crypt_cpus for dm-crypt */
|
||||||
|
#define CRYPT_ACTIVATE_SUBMIT_FROM_CRYPT_CPUS (1 << 7)
|
||||||
|
/** dm-verity: ignore_corruption flag - ignore corruption, log it only */
|
||||||
|
#define CRYPT_ACTIVATE_IGNORE_CORRUPTION (1 << 8)
|
||||||
|
/** dm-verity: restart_on_corruption flag - restart kernel on corruption */
|
||||||
|
#define CRYPT_ACTIVATE_RESTART_ON_CORRUPTION (1 << 9)
|
||||||
|
/** dm-verity: ignore_zero_blocks - do not verify zero blocks */
|
||||||
|
#define CRYPT_ACTIVATE_IGNORE_ZERO_BLOCKS (1 << 10)
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Active device runtime attributes
|
* Active device runtime attributes
|
||||||
@@ -592,7 +771,7 @@ struct crypt_active_device {
|
|||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Receives runtime attributes of active crypt device
|
* Receive runtime attributes of active crypt device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle (can be @e NULL)
|
* @param cd crypt device handle (can be @e NULL)
|
||||||
* @param name name of active device
|
* @param name name of active device
|
||||||
@@ -608,7 +787,7 @@ int crypt_get_active_device(struct crypt_device *cd,
|
|||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Activate device or check passphrase
|
* Activate device or check passphrase.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param name name of device to create, if @e NULL only check passphrase
|
* @param name name of device to create, if @e NULL only check passphrase
|
||||||
@@ -618,6 +797,9 @@ int crypt_get_active_device(struct crypt_device *cd,
|
|||||||
* @param flags activation flags
|
* @param flags activation flags
|
||||||
*
|
*
|
||||||
* @return unlocked key slot number or negative errno otherwise.
|
* @return unlocked key slot number or negative errno otherwise.
|
||||||
|
*
|
||||||
|
* @note If passphrase is @e NULL always use crypt_set_password_callback.
|
||||||
|
* Internal terminal password query is DEPRECATED and will be removed in next version.
|
||||||
*/
|
*/
|
||||||
int crypt_activate_by_passphrase(struct crypt_device *cd,
|
int crypt_activate_by_passphrase(struct crypt_device *cd,
|
||||||
const char *name,
|
const char *name,
|
||||||
@@ -627,17 +809,28 @@ int crypt_activate_by_passphrase(struct crypt_device *cd,
|
|||||||
uint32_t flags);
|
uint32_t flags);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Activate device or check using key file
|
* Activate device or check using key file.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param name name of device to create, if @e NULL only check keyfile
|
* @param name name of device to create, if @e NULL only check keyfile
|
||||||
* @param keyslot requested keyslot to check or CRYPT_ANY_SLOT
|
* @param keyslot requested keyslot to check or CRYPT_ANY_SLOT
|
||||||
* @param keyfile key file used to unlock volume key
|
* @param keyfile key file used to unlock volume key
|
||||||
* @param keyfile_size number of bytes to read from keyfile, 0 is unlimited
|
* @param keyfile_size number of bytes to read from keyfile, 0 is unlimited
|
||||||
|
* @param keyfile_offset number of bytes to skip at start of keyfile
|
||||||
* @param flags activation flags
|
* @param flags activation flags
|
||||||
*
|
*
|
||||||
* @return unlocked key slot number or negative errno otherwise.
|
* @return unlocked key slot number or negative errno otherwise.
|
||||||
*/
|
*/
|
||||||
|
int crypt_activate_by_keyfile_offset(struct crypt_device *cd,
|
||||||
|
const char *name,
|
||||||
|
int keyslot,
|
||||||
|
const char *keyfile,
|
||||||
|
size_t keyfile_size,
|
||||||
|
size_t keyfile_offset,
|
||||||
|
uint32_t flags);
|
||||||
|
/**
|
||||||
|
* Backward compatible crypt_activate_by_keyfile_offset() (without offset).
|
||||||
|
*/
|
||||||
int crypt_activate_by_keyfile(struct crypt_device *cd,
|
int crypt_activate_by_keyfile(struct crypt_device *cd,
|
||||||
const char *name,
|
const char *name,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
@@ -646,7 +839,7 @@ int crypt_activate_by_keyfile(struct crypt_device *cd,
|
|||||||
uint32_t flags);
|
uint32_t flags);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Activate device using provided volume key
|
* Activate device using provided volume key.
|
||||||
*
|
*
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
@@ -660,6 +853,11 @@ int crypt_activate_by_keyfile(struct crypt_device *cd,
|
|||||||
* @note If @e NULL is used for volume_key, device has to be initialized
|
* @note If @e NULL is used for volume_key, device has to be initialized
|
||||||
* by previous operation (like @ref crypt_format
|
* by previous operation (like @ref crypt_format
|
||||||
* or @ref crypt_init_by_name)
|
* or @ref crypt_init_by_name)
|
||||||
|
* @note For VERITY the volume key means root hash required for activation.
|
||||||
|
* Because kernel dm-verity is always read only, you have to provide
|
||||||
|
* CRYPT_ACTIVATE_READONLY flag always.
|
||||||
|
* @note For TCRYPT the volume key should be always NULL and because master
|
||||||
|
* key from decrypted header is used instead.
|
||||||
*/
|
*/
|
||||||
int crypt_activate_by_volume_key(struct crypt_device *cd,
|
int crypt_activate_by_volume_key(struct crypt_device *cd,
|
||||||
const char *name,
|
const char *name,
|
||||||
@@ -681,7 +879,7 @@ int crypt_activate_by_volume_key(struct crypt_device *cd,
|
|||||||
int crypt_deactivate(struct crypt_device *cd, const char *name);
|
int crypt_deactivate(struct crypt_device *cd, const char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get volume key from of crypt device
|
* Get volume key from crypt device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param keyslot use this keyslot or @e CRYPT_ANY_SLOT
|
* @param keyslot use this keyslot or @e CRYPT_ANY_SLOT
|
||||||
@@ -692,6 +890,9 @@ int crypt_deactivate(struct crypt_device *cd, const char *name);
|
|||||||
* @param passphrase_size size of @e passphrase
|
* @param passphrase_size size of @e passphrase
|
||||||
*
|
*
|
||||||
* @return unlocked key slot number or negative errno otherwise.
|
* @return unlocked key slot number or negative errno otherwise.
|
||||||
|
*
|
||||||
|
* @note For TCRYPT cipher chain is the volume key concatenated
|
||||||
|
* for all ciphers in chain.
|
||||||
*/
|
*/
|
||||||
int crypt_volume_key_get(struct crypt_device *cd,
|
int crypt_volume_key_get(struct crypt_device *cd,
|
||||||
int keyslot,
|
int keyslot,
|
||||||
@@ -701,7 +902,7 @@ int crypt_volume_key_get(struct crypt_device *cd,
|
|||||||
size_t passphrase_size);
|
size_t passphrase_size);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Verify that provided volume key is valid for crypt device
|
* Verify that provided volume key is valid for crypt device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param volume_key provided volume key
|
* @param volume_key provided volume key
|
||||||
@@ -713,9 +914,8 @@ int crypt_volume_key_verify(struct crypt_device *cd,
|
|||||||
const char *volume_key,
|
const char *volume_key,
|
||||||
size_t volume_key_size);
|
size_t volume_key_size);
|
||||||
|
|
||||||
|
/**
|
||||||
/*
|
* @defgroup devstat Crypt and Verity device status
|
||||||
* @defgroup devstat "dmcrypt device status"
|
|
||||||
* @addtogroup devstat
|
* @addtogroup devstat
|
||||||
* @{
|
* @{
|
||||||
*/
|
*/
|
||||||
@@ -731,7 +931,7 @@ typedef enum {
|
|||||||
} crypt_status_info;
|
} crypt_status_info;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get status info about device name
|
* Get status info about device name.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle, can be @e NULL
|
* @param cd crypt device handle, can be @e NULL
|
||||||
* @param name crypt device name
|
* @param name crypt device name
|
||||||
@@ -742,7 +942,7 @@ typedef enum {
|
|||||||
crypt_status_info crypt_status(struct crypt_device *cd, const char *name);
|
crypt_status_info crypt_status(struct crypt_device *cd, const char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Dump text-formatted information about crypt device to log output
|
* Dump text-formatted information about crypt or verity device to log output.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -751,7 +951,7 @@ crypt_status_info crypt_status(struct crypt_device *cd, const char *name);
|
|||||||
int crypt_dump(struct crypt_device *cd);
|
int crypt_dump(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get cipher used in device
|
* Get cipher used in device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -761,7 +961,7 @@ int crypt_dump(struct crypt_device *cd);
|
|||||||
const char *crypt_get_cipher(struct crypt_device *cd);
|
const char *crypt_get_cipher(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get cipher mode used in device
|
* Get cipher mode used in device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -771,7 +971,7 @@ const char *crypt_get_cipher(struct crypt_device *cd);
|
|||||||
const char *crypt_get_cipher_mode(struct crypt_device *cd);
|
const char *crypt_get_cipher_mode(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get device UUID
|
* Get device UUID.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -781,7 +981,7 @@ const char *crypt_get_cipher_mode(struct crypt_device *cd);
|
|||||||
const char *crypt_get_uuid(struct crypt_device *cd);
|
const char *crypt_get_uuid(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get path to underlaying device
|
* Get path to underlaying device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -791,7 +991,7 @@ const char *crypt_get_uuid(struct crypt_device *cd);
|
|||||||
const char *crypt_get_device_name(struct crypt_device *cd);
|
const char *crypt_get_device_name(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get device offset in sectors where real data starts on underlying device)
|
* Get device offset in sectors where real data starts (on underlying device).
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -801,7 +1001,7 @@ const char *crypt_get_device_name(struct crypt_device *cd);
|
|||||||
uint64_t crypt_get_data_offset(struct crypt_device *cd);
|
uint64_t crypt_get_data_offset(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get IV offset in sectors (skip)
|
* Get IV offset in sectors (skip).
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -811,7 +1011,7 @@ uint64_t crypt_get_data_offset(struct crypt_device *cd);
|
|||||||
uint64_t crypt_get_iv_offset(struct crypt_device *cd);
|
uint64_t crypt_get_iv_offset(struct crypt_device *cd);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get size (in bytes) of volume key for crypt device
|
* Get size (in bytes) of volume key for crypt device.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
*
|
*
|
||||||
@@ -820,6 +1020,79 @@ uint64_t crypt_get_iv_offset(struct crypt_device *cd);
|
|||||||
*/
|
*/
|
||||||
int crypt_get_volume_key_size(struct crypt_device *cd);
|
int crypt_get_volume_key_size(struct crypt_device *cd);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get device parameters for VERITY device.
|
||||||
|
*
|
||||||
|
* @param cd crypt device handle
|
||||||
|
* @param vp verity device info
|
||||||
|
*
|
||||||
|
* @e 0 on success or negative errno value otherwise.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
int crypt_get_verity_info(struct crypt_device *cd,
|
||||||
|
struct crypt_params_verity *vp);
|
||||||
|
/** @} */
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @defgroup benchmark Benchmarking
|
||||||
|
*
|
||||||
|
* Benchmarking of algorithms
|
||||||
|
*
|
||||||
|
* @addtogroup benchmark
|
||||||
|
* @{
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Informational benchmark for ciphers.
|
||||||
|
*
|
||||||
|
* @param cd crypt device handle
|
||||||
|
* @param cipher (e.g. "aes")
|
||||||
|
* @param cipher_mode (e.g. "xts"), IV generator is ignored
|
||||||
|
* @param volume_key_size size of volume key in bytes
|
||||||
|
* @param iv_size size of IV in bytes
|
||||||
|
* @param buffer_size size of encryption buffer in bytes used in test
|
||||||
|
* @param encryption_mbs measured encryption speed in MiB/s
|
||||||
|
* @param decryption_mbs measured decryption speed in MiB/s
|
||||||
|
*
|
||||||
|
* @return @e 0 on success or negative errno value otherwise.
|
||||||
|
*
|
||||||
|
* @note If encryption_buffer_size is too small and encryption time
|
||||||
|
* cannot be properly measured, -ERANGE is returned.
|
||||||
|
*/
|
||||||
|
int crypt_benchmark(struct crypt_device *cd,
|
||||||
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
|
size_t volume_key_size,
|
||||||
|
size_t iv_size,
|
||||||
|
size_t buffer_size,
|
||||||
|
double *encryption_mbs,
|
||||||
|
double *decryption_mbs);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Informational benchmark for KDF.
|
||||||
|
*
|
||||||
|
* @param cd crypt device handle
|
||||||
|
* @param kdf Key derivation function (e.g. "pbkdf2")
|
||||||
|
* @param hash Hash algorithm used in KDF (e.g. "sha256")
|
||||||
|
* @param password password for benchmark
|
||||||
|
* @param password_size size of password
|
||||||
|
* @param salt salt for benchmark
|
||||||
|
* @param salt_size size of salt
|
||||||
|
* @param iterations_sec returns measured KDF iterations per second
|
||||||
|
*
|
||||||
|
* @return @e 0 on success or negative errno value otherwise.
|
||||||
|
*/
|
||||||
|
int crypt_benchmark_kdf(struct crypt_device *cd,
|
||||||
|
const char *kdf,
|
||||||
|
const char *hash,
|
||||||
|
const char *password,
|
||||||
|
size_t password_size,
|
||||||
|
const char *salt,
|
||||||
|
size_t salt_size,
|
||||||
|
uint64_t *iterations_sec);
|
||||||
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @addtogroup keyslot
|
* @addtogroup keyslot
|
||||||
* @{
|
* @{
|
||||||
@@ -838,7 +1111,7 @@ typedef enum {
|
|||||||
} crypt_keyslot_info;
|
} crypt_keyslot_info;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get information about particular key slot
|
* Get information about particular key slot.
|
||||||
*
|
*
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
@@ -851,10 +1124,36 @@ crypt_keyslot_info crypt_keyslot_status(struct crypt_device *cd, int keyslot);
|
|||||||
/** @} */
|
/** @} */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Backup header and keyslots to file
|
* Get number of keyslots supported for device type.
|
||||||
|
*
|
||||||
|
* @param type crypt device type
|
||||||
|
*
|
||||||
|
* @return slot count or negative errno otherwise if device
|
||||||
|
* doesn't not support keyslots.
|
||||||
|
*/
|
||||||
|
int crypt_keyslot_max(const char *type);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get keyslot area pointers (relative to metadata device).
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param requested_type type of header to backup
|
* @param keyslot keyslot number
|
||||||
|
* @param offset offset on metadata device (in bytes)
|
||||||
|
* @param length length of keyslot area (in bytes)
|
||||||
|
*
|
||||||
|
* @return @e 0 on success or negative errno value otherwise.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
int crypt_keyslot_area(struct crypt_device *cd,
|
||||||
|
int keyslot,
|
||||||
|
uint64_t *offset,
|
||||||
|
uint64_t *length);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Backup header and keyslots to file.
|
||||||
|
*
|
||||||
|
* @param cd crypt device handle
|
||||||
|
* @param requested_type @link crypt_type @endlink or @e NULL for all known
|
||||||
* @param backup_file file to backup header to
|
* @param backup_file file to backup header to
|
||||||
*
|
*
|
||||||
* @return @e 0 on success or negative errno value otherwise.
|
* @return @e 0 on success or negative errno value otherwise.
|
||||||
@@ -865,11 +1164,11 @@ int crypt_header_backup(struct crypt_device *cd,
|
|||||||
const char *backup_file);
|
const char *backup_file);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Restore header and keyslots from backup file
|
* Restore header and keyslots from backup file.
|
||||||
*
|
*
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param requested_type type of header to restore
|
* @param requested_type @link crypt_type @endlink or @e NULL for all known
|
||||||
* @param backup_file file to restore header from
|
* @param backup_file file to restore header from
|
||||||
*
|
*
|
||||||
* @return @e 0 on success or negative errno value otherwise.
|
* @return @e 0 on success or negative errno value otherwise.
|
||||||
@@ -880,14 +1179,14 @@ int crypt_header_restore(struct crypt_device *cd,
|
|||||||
const char *backup_file);
|
const char *backup_file);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Receives last reported error
|
* Receive last reported error, DEPRECATED.
|
||||||
*
|
*
|
||||||
* @param cd crypt device handle
|
* @param cd crypt device handle
|
||||||
* @param buf buffef for message
|
* @param buf buffef for message
|
||||||
* @param size size of buffer
|
* @param size size of buffer
|
||||||
*
|
*
|
||||||
* @note Note that this is old API function using global context.
|
* @note This function is DEPRECATED and will be removed in future versions.
|
||||||
* All error messages are reported also through log callback.
|
* @note All error messages are reported also through log callback.
|
||||||
*/
|
*/
|
||||||
void crypt_last_error(struct crypt_device *cd, char *buf, size_t size);
|
void crypt_last_error(struct crypt_device *cd, char *buf, size_t size);
|
||||||
|
|
||||||
@@ -897,8 +1196,7 @@ void crypt_last_error(struct crypt_device *cd, char *buf, size_t size);
|
|||||||
* @param buf buffef for message
|
* @param buf buffef for message
|
||||||
* @param size size of buffer
|
* @param size size of buffer
|
||||||
*
|
*
|
||||||
* @note Note that this is old API function using global context.
|
* @note This function is DEPRECATED and will be removed in future versions.
|
||||||
* All error messages are reported also through log callback.
|
|
||||||
*/
|
*/
|
||||||
void crypt_get_error(char *buf, size_t size);
|
void crypt_get_error(char *buf, size_t size);
|
||||||
|
|
||||||
@@ -910,7 +1208,7 @@ void crypt_get_error(char *buf, size_t size);
|
|||||||
const char *crypt_get_dir(void);
|
const char *crypt_get_dir(void);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @defgroup dbg "Library debug level"
|
* @defgroup dbg Library debug level
|
||||||
*
|
*
|
||||||
* Set library debug level
|
* Set library debug level
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ CRYPTSETUP_1.0 {
|
|||||||
crypt_set_timeout;
|
crypt_set_timeout;
|
||||||
crypt_set_password_retry;
|
crypt_set_password_retry;
|
||||||
crypt_set_iterarion_time;
|
crypt_set_iterarion_time;
|
||||||
|
crypt_set_iteration_time;
|
||||||
crypt_set_password_verify;
|
crypt_set_password_verify;
|
||||||
crypt_set_uuid;
|
crypt_set_uuid;
|
||||||
crypt_set_data_device;
|
crypt_set_data_device;
|
||||||
@@ -16,24 +17,31 @@ CRYPTSETUP_1.0 {
|
|||||||
crypt_memory_lock;
|
crypt_memory_lock;
|
||||||
crypt_format;
|
crypt_format;
|
||||||
crypt_load;
|
crypt_load;
|
||||||
|
crypt_repair;
|
||||||
crypt_resize;
|
crypt_resize;
|
||||||
crypt_suspend;
|
crypt_suspend;
|
||||||
crypt_resume_by_passphrase;
|
crypt_resume_by_passphrase;
|
||||||
crypt_resume_by_keyfile;
|
crypt_resume_by_keyfile;
|
||||||
|
crypt_resume_by_keyfile_offset;
|
||||||
crypt_free;
|
crypt_free;
|
||||||
|
|
||||||
crypt_keyslot_add_by_passphrase;
|
crypt_keyslot_add_by_passphrase;
|
||||||
|
crypt_keyslot_change_by_passphrase;
|
||||||
crypt_keyslot_add_by_keyfile;
|
crypt_keyslot_add_by_keyfile;
|
||||||
|
crypt_keyslot_add_by_keyfile_offset;
|
||||||
crypt_keyslot_add_by_volume_key;
|
crypt_keyslot_add_by_volume_key;
|
||||||
crypt_keyslot_destroy;
|
crypt_keyslot_destroy;
|
||||||
crypt_activate_by_passphrase;
|
crypt_activate_by_passphrase;
|
||||||
crypt_activate_by_keyfile;
|
crypt_activate_by_keyfile;
|
||||||
|
crypt_activate_by_keyfile_offset;
|
||||||
crypt_activate_by_volume_key;
|
crypt_activate_by_volume_key;
|
||||||
crypt_deactivate;
|
crypt_deactivate;
|
||||||
crypt_volume_key_get;
|
crypt_volume_key_get;
|
||||||
crypt_volume_key_verify;
|
crypt_volume_key_verify;
|
||||||
crypt_status;
|
crypt_status;
|
||||||
crypt_dump;
|
crypt_dump;
|
||||||
|
crypt_benchmark;
|
||||||
|
crypt_benchmark_kdf;
|
||||||
crypt_get_cipher;
|
crypt_get_cipher;
|
||||||
crypt_get_cipher_mode;
|
crypt_get_cipher_mode;
|
||||||
crypt_get_uuid;
|
crypt_get_uuid;
|
||||||
@@ -41,6 +49,7 @@ CRYPTSETUP_1.0 {
|
|||||||
crypt_get_iv_offset;
|
crypt_get_iv_offset;
|
||||||
crypt_get_volume_key_size;
|
crypt_get_volume_key_size;
|
||||||
crypt_get_device_name;
|
crypt_get_device_name;
|
||||||
|
crypt_get_verity_info;
|
||||||
|
|
||||||
crypt_get_type;
|
crypt_get_type;
|
||||||
crypt_get_active_device;
|
crypt_get_active_device;
|
||||||
@@ -49,6 +58,7 @@ CRYPTSETUP_1.0 {
|
|||||||
crypt_get_rng_type;
|
crypt_get_rng_type;
|
||||||
|
|
||||||
crypt_keyslot_max;
|
crypt_keyslot_max;
|
||||||
|
crypt_keyslot_area;
|
||||||
crypt_keyslot_status;
|
crypt_keyslot_status;
|
||||||
crypt_last_error;
|
crypt_last_error;
|
||||||
crypt_get_error;
|
crypt_get_error;
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -2,15 +2,13 @@ moduledir = $(libdir)/cryptsetup
|
|||||||
|
|
||||||
noinst_LTLIBRARIES = libloopaes.la
|
noinst_LTLIBRARIES = libloopaes.la
|
||||||
|
|
||||||
libloopaes_la_CFLAGS = -Wall @CRYPTO_CFLAGS@
|
libloopaes_la_CFLAGS = -Wall $(AM_CFLAGS) @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
libloopaes_la_SOURCES = \
|
libloopaes_la_SOURCES = \
|
||||||
loopaes.c \
|
loopaes.c \
|
||||||
loopaes.h
|
loopaes.h
|
||||||
|
|
||||||
INCLUDES = -D_GNU_SOURCE \
|
AM_CPPFLAGS = -include config.h \
|
||||||
-D_LARGEFILE64_SOURCE \
|
|
||||||
-D_FILE_OFFSET_BITS=64 \
|
|
||||||
-I$(top_srcdir)/lib \
|
-I$(top_srcdir)/lib \
|
||||||
-I$(top_srcdir)/lib/crypto_backend
|
-I$(top_srcdir)/lib/crypto_backend
|
||||||
|
|
||||||
|
|||||||
@@ -1,20 +1,22 @@
|
|||||||
/*
|
/*
|
||||||
* loop-AES compatible volume handling
|
* loop-AES compatible volume handling
|
||||||
*
|
*
|
||||||
* Copyright (C) 2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2011-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2011-2013, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This file is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
* version 2 as published by the Free Software Foundation.
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This file is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
* GNU General Public License for more details.
|
* Lesser General Public License for more details.
|
||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
* along with this program; if not, write to the Free Software
|
* License along with this file; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
@@ -22,8 +24,9 @@
|
|||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
#include "crypto_backend.h"
|
#include "libcryptsetup.h"
|
||||||
#include "loopaes.h"
|
#include "loopaes.h"
|
||||||
|
#include "internal.h"
|
||||||
|
|
||||||
static const char *get_hash(unsigned int key_size)
|
static const char *get_hash(unsigned int key_size)
|
||||||
{
|
{
|
||||||
@@ -72,16 +75,16 @@ static int hash_keys(struct crypt_device *cd,
|
|||||||
const char *hash_override,
|
const char *hash_override,
|
||||||
const char **input_keys,
|
const char **input_keys,
|
||||||
unsigned int keys_count,
|
unsigned int keys_count,
|
||||||
unsigned int key_len_output)
|
unsigned int key_len_output,
|
||||||
|
unsigned int key_len_input)
|
||||||
{
|
{
|
||||||
const char *hash_name;
|
const char *hash_name;
|
||||||
char tweak, *key_ptr;
|
char tweak, *key_ptr;
|
||||||
unsigned i, key_len_input;
|
unsigned int i;
|
||||||
int r;
|
int r;
|
||||||
|
|
||||||
hash_name = hash_override ?: get_hash(key_len_output);
|
hash_name = hash_override ?: get_hash(key_len_output);
|
||||||
tweak = get_tweak(keys_count);
|
tweak = get_tweak(keys_count);
|
||||||
key_len_input = strlen(input_keys[0]);
|
|
||||||
|
|
||||||
if (!keys_count || !key_len_output || !hash_name || !key_len_input) {
|
if (!keys_count || !key_len_output || !hash_name || !key_len_input) {
|
||||||
log_err(cd, _("Key processing error (using hash %s).\n"),
|
log_err(cd, _("Key processing error (using hash %s).\n"),
|
||||||
@@ -131,9 +134,10 @@ int LOOPAES_parse_keyfile(struct crypt_device *cd,
|
|||||||
size_t buffer_len)
|
size_t buffer_len)
|
||||||
{
|
{
|
||||||
const char *keys[LOOPAES_KEYS_MAX];
|
const char *keys[LOOPAES_KEYS_MAX];
|
||||||
unsigned i, key_index, key_len, offset;
|
unsigned int key_lengths[LOOPAES_KEYS_MAX];
|
||||||
|
unsigned int i, key_index, key_len, offset;
|
||||||
|
|
||||||
log_dbg("Parsing loop-AES keyfile of size %d.", buffer_len);
|
log_dbg("Parsing loop-AES keyfile of size %zu.", buffer_len);
|
||||||
|
|
||||||
if (!buffer_len)
|
if (!buffer_len)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
@@ -151,33 +155,45 @@ int LOOPAES_parse_keyfile(struct crypt_device *cd,
|
|||||||
|
|
||||||
offset = 0;
|
offset = 0;
|
||||||
key_index = 0;
|
key_index = 0;
|
||||||
|
key_lengths[0] = 0;
|
||||||
while (offset < buffer_len && key_index < LOOPAES_KEYS_MAX) {
|
while (offset < buffer_len && key_index < LOOPAES_KEYS_MAX) {
|
||||||
keys[key_index++] = &buffer[offset];
|
keys[key_index] = &buffer[offset];
|
||||||
while (offset < buffer_len && buffer[offset])
|
key_lengths[key_index] = 0;;
|
||||||
|
while (offset < buffer_len && buffer[offset]) {
|
||||||
offset++;
|
offset++;
|
||||||
|
key_lengths[key_index]++;
|
||||||
|
}
|
||||||
|
if (offset == buffer_len) {
|
||||||
|
log_dbg("Unterminated key #%d in keyfile.", key_index);
|
||||||
|
log_err(cd, _("Incompatible loop-AES keyfile detected.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
while (offset < buffer_len && !buffer[offset])
|
while (offset < buffer_len && !buffer[offset])
|
||||||
offset++;
|
offset++;
|
||||||
|
key_index++;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* All keys must be the same length */
|
/* All keys must be the same length */
|
||||||
key_len = key_index ? strlen(keys[0]) : 0;
|
key_len = key_lengths[0];
|
||||||
for (i = 0; i < key_index; i++)
|
for (i = 0; i < key_index; i++)
|
||||||
if (key_len != strlen(keys[i])) {
|
if (!key_lengths[i] || (key_lengths[i] != key_len)) {
|
||||||
log_dbg("Unexpected length %d of key #%d (should be %d).",
|
log_dbg("Unexpected length %d of key #%d (should be %d).",
|
||||||
strlen(keys[i]), i, key_len);
|
key_lengths[i], i, key_len);
|
||||||
key_len = 0;
|
key_len = 0;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
log_dbg("Keyfile: %d keys of length %d.", key_index, key_len);
|
|
||||||
if (offset != buffer_len || key_len == 0 ||
|
if (offset != buffer_len || key_len == 0 ||
|
||||||
(key_index != 1 && key_index !=64 && key_index != 65)) {
|
(key_index != 1 && key_index !=64 && key_index != 65)) {
|
||||||
log_err(cd, _("Incompatible loop-AES keyfile detected.\n"));
|
log_err(cd, _("Incompatible loop-AES keyfile detected.\n"));
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
log_dbg("Keyfile: %d keys of length %d.", key_index, key_len);
|
||||||
|
|
||||||
*keys_count = key_index;
|
*keys_count = key_index;
|
||||||
return hash_keys(cd, vk, hash, keys, key_index, crypt_get_volume_key_size(cd));
|
return hash_keys(cd, vk, hash, keys, key_index,
|
||||||
|
crypt_get_volume_key_size(cd), key_len);
|
||||||
}
|
}
|
||||||
|
|
||||||
int LOOPAES_activate(struct crypt_device *cd,
|
int LOOPAES_activate(struct crypt_device *cd,
|
||||||
@@ -191,18 +207,20 @@ int LOOPAES_activate(struct crypt_device *cd,
|
|||||||
uint32_t req_flags;
|
uint32_t req_flags;
|
||||||
int r;
|
int r;
|
||||||
struct crypt_dm_active_device dmd = {
|
struct crypt_dm_active_device dmd = {
|
||||||
.device = crypt_get_device_name(cd),
|
.target = DM_CRYPT,
|
||||||
.cipher = NULL,
|
|
||||||
.uuid = crypt_get_uuid(cd),
|
|
||||||
.vk = vk,
|
|
||||||
.offset = crypt_get_data_offset(cd),
|
|
||||||
.iv_offset = crypt_get_iv_offset(cd),
|
|
||||||
.size = 0,
|
.size = 0,
|
||||||
.flags = flags
|
.flags = flags,
|
||||||
|
.data_device = crypt_data_device(cd),
|
||||||
|
.u.crypt = {
|
||||||
|
.cipher = NULL,
|
||||||
|
.vk = vk,
|
||||||
|
.offset = crypt_get_data_offset(cd),
|
||||||
|
.iv_offset = crypt_get_iv_offset(cd),
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
r = device_block_adjust(cd, dmd.data_device, DEV_EXCL,
|
||||||
r = device_check_and_adjust(cd, dmd.device, DEV_EXCL, &dmd.size, &dmd.offset, &flags);
|
dmd.u.crypt.offset, &dmd.size, &dmd.flags);
|
||||||
if (r)
|
if (r)
|
||||||
return r;
|
return r;
|
||||||
|
|
||||||
@@ -216,12 +234,13 @@ int LOOPAES_activate(struct crypt_device *cd,
|
|||||||
if (r < 0)
|
if (r < 0)
|
||||||
return -ENOMEM;
|
return -ENOMEM;
|
||||||
|
|
||||||
dmd.cipher = cipher;
|
dmd.u.crypt.cipher = cipher;
|
||||||
log_dbg("Trying to activate loop-AES device %s using cipher %s.", name, dmd.cipher);
|
log_dbg("Trying to activate loop-AES device %s using cipher %s.",
|
||||||
|
name, dmd.u.crypt.cipher);
|
||||||
|
|
||||||
r = dm_create_device(name, CRYPT_LOOPAES, &dmd, 0);
|
r = dm_create_device(cd, name, CRYPT_LOOPAES, &dmd, 0);
|
||||||
|
|
||||||
if (!r && !(dm_flags() & req_flags)) {
|
if (r < 0 && !(dm_flags() & req_flags)) {
|
||||||
log_err(cd, _("Kernel doesn't support loop-AES compatible mapping.\n"));
|
log_err(cd, _("Kernel doesn't support loop-AES compatible mapping.\n"));
|
||||||
r = -ENOTSUP;
|
r = -ENOTSUP;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,8 +1,28 @@
|
|||||||
|
/*
|
||||||
|
* loop-AES compatible volume handling
|
||||||
|
*
|
||||||
|
* Copyright (C) 2011-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2011-2013, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef _LOOPAES_H
|
#ifndef _LOOPAES_H
|
||||||
#define _LOOPAES_H
|
#define _LOOPAES_H
|
||||||
|
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
#include "config.h"
|
|
||||||
|
|
||||||
struct crypt_device;
|
struct crypt_device;
|
||||||
struct volume_key;
|
struct volume_key;
|
||||||
|
|||||||
@@ -2,20 +2,16 @@ moduledir = $(libdir)/cryptsetup
|
|||||||
|
|
||||||
noinst_LTLIBRARIES = libluks1.la
|
noinst_LTLIBRARIES = libluks1.la
|
||||||
|
|
||||||
libluks1_la_CFLAGS = -Wall @CRYPTO_CFLAGS@
|
libluks1_la_CFLAGS = -Wall $(AM_CFLAGS) @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
libluks1_la_SOURCES = \
|
libluks1_la_SOURCES = \
|
||||||
af.c \
|
af.c \
|
||||||
pbkdf.c \
|
|
||||||
keymanage.c \
|
keymanage.c \
|
||||||
keyencryption.c \
|
keyencryption.c \
|
||||||
pbkdf.h \
|
|
||||||
af.h \
|
af.h \
|
||||||
luks.h
|
luks.h
|
||||||
|
|
||||||
INCLUDES = -D_GNU_SOURCE \
|
AM_CPPFLAGS = -include config.h \
|
||||||
-D_LARGEFILE64_SOURCE \
|
|
||||||
-D_FILE_OFFSET_BITS=64 \
|
|
||||||
-I$(top_srcdir)/lib \
|
-I$(top_srcdir)/lib \
|
||||||
-I$(top_srcdir)/lib/crypto_backend
|
-I$(top_srcdir)/lib/crypto_backend
|
||||||
|
|
||||||
|
|||||||
@@ -2,14 +2,15 @@
|
|||||||
* AFsplitter - Anti forensic information splitter
|
* AFsplitter - Anti forensic information splitter
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
*
|
*
|
||||||
* AFsplitter diffuses information over a large stripe of data,
|
* AFsplitter diffuses information over a large stripe of data,
|
||||||
* therefor supporting secure data destruction.
|
* therefor supporting secure data destruction.
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -18,7 +19,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stddef.h>
|
#include <stddef.h>
|
||||||
@@ -26,7 +27,6 @@
|
|||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <netinet/in.h>
|
#include <netinet/in.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include "crypto_backend.h"
|
|
||||||
#include "internal.h"
|
#include "internal.h"
|
||||||
#include "af.h"
|
#include "af.h"
|
||||||
|
|
||||||
@@ -67,9 +67,14 @@ out:
|
|||||||
|
|
||||||
static int diffuse(char *src, char *dst, size_t size, const char *hash_name)
|
static int diffuse(char *src, char *dst, size_t size, const char *hash_name)
|
||||||
{
|
{
|
||||||
unsigned int digest_size = crypt_hash_size(hash_name);
|
int hash_size = crypt_hash_size(hash_name);
|
||||||
|
unsigned int digest_size;
|
||||||
unsigned int i, blocks, padding;
|
unsigned int i, blocks, padding;
|
||||||
|
|
||||||
|
if (hash_size <= 0)
|
||||||
|
return 1;
|
||||||
|
digest_size = hash_size;
|
||||||
|
|
||||||
blocks = size / digest_size;
|
blocks = size / digest_size;
|
||||||
padding = size % digest_size;
|
padding = size % digest_size;
|
||||||
|
|
||||||
@@ -142,3 +147,17 @@ out:
|
|||||||
free(bufblock);
|
free(bufblock);
|
||||||
return r;
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Size of final split data including sector alignment */
|
||||||
|
size_t AF_split_sectors(size_t blocksize, unsigned int blocknumbers)
|
||||||
|
{
|
||||||
|
size_t af_size;
|
||||||
|
|
||||||
|
/* data material * stripes */
|
||||||
|
af_size = blocksize * blocknumbers;
|
||||||
|
|
||||||
|
/* round up to sector */
|
||||||
|
af_size = (af_size + (SECTOR_SIZE - 1)) / SECTOR_SIZE;
|
||||||
|
|
||||||
|
return af_size;
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,10 +1,28 @@
|
|||||||
#ifndef INCLUDED_CRYPTSETUP_LUKS_AF_H
|
|
||||||
#define INCLUDED_CRYPTSETUP_LUKS_AF_H
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* AFsplitter - Anti forensic information splitter
|
* AFsplitter - Anti forensic information splitter
|
||||||
* Copyright 2004, Clemens Fruhwirth <clemens@endorphin.org>
|
*
|
||||||
|
* Copyright (C) 2004, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* AFsplitter diffuses information over a large stripe of data,
|
||||||
|
* therefor supporting secure data destruction.
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU Library General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
#ifndef INCLUDED_CRYPTSETUP_LUKS_AF_H
|
||||||
|
#define INCLUDED_CRYPTSETUP_LUKS_AF_H
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* AF_split operates on src and produces information split data in
|
* AF_split operates on src and produces information split data in
|
||||||
@@ -21,5 +39,6 @@
|
|||||||
|
|
||||||
int AF_split(char *src, char *dst, size_t blocksize, unsigned int blocknumbers, const char *hash);
|
int AF_split(char *src, char *dst, size_t blocksize, unsigned int blocknumbers, const char *hash);
|
||||||
int AF_merge(char *src, char *dst, size_t blocksize, unsigned int blocknumbers, const char *hash);
|
int AF_merge(char *src, char *dst, size_t blocksize, unsigned int blocknumbers, const char *hash);
|
||||||
|
size_t AF_split_sectors(size_t blocksize, unsigned int blocknumbers);
|
||||||
|
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -2,10 +2,13 @@
|
|||||||
* LUKS - Linux Unified Key Setup
|
* LUKS - Linux Unified Key Setup
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004-2006, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2006, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2014, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -14,186 +17,244 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <stdlib.h>
|
|
||||||
#include <ctype.h>
|
|
||||||
#include <inttypes.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <sys/stat.h>
|
|
||||||
#include <sys/ioctl.h>
|
|
||||||
#include <sys/mman.h>
|
|
||||||
#include <sys/utsname.h>
|
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
#include <unistd.h>
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <signal.h>
|
|
||||||
|
|
||||||
#include "luks.h"
|
#include "luks.h"
|
||||||
#include "internal.h"
|
#include "internal.h"
|
||||||
|
|
||||||
#define div_round_up(a,b) ({ \
|
static void _error_hint(struct crypt_device *ctx, const char *device,
|
||||||
typeof(a) __a = (a); \
|
const char *cipher, const char *mode, size_t keyLength)
|
||||||
typeof(b) __b = (b); \
|
|
||||||
(__a - 1) / __b + 1; \
|
|
||||||
})
|
|
||||||
|
|
||||||
static inline int round_up_modulo(int x, int m) {
|
|
||||||
return div_round_up(x, m) * m;
|
|
||||||
}
|
|
||||||
|
|
||||||
static const char *cleaner_name=NULL;
|
|
||||||
static uint64_t cleaner_size = 0;
|
|
||||||
static int devfd=-1;
|
|
||||||
|
|
||||||
static int setup_mapping(const char *cipher, const char *name,
|
|
||||||
const char *device,
|
|
||||||
struct volume_key *vk,
|
|
||||||
unsigned int sector, size_t srcLength,
|
|
||||||
int mode, struct crypt_device *ctx)
|
|
||||||
{
|
{
|
||||||
int device_sector_size = sector_size_for_device(device);
|
char cipher_spec[MAX_CIPHER_LEN * 3];
|
||||||
struct crypt_dm_active_device dmd = {
|
|
||||||
.device = device,
|
|
||||||
.cipher = cipher,
|
|
||||||
.uuid = NULL,
|
|
||||||
.vk = vk,
|
|
||||||
.offset = sector,
|
|
||||||
.iv_offset = 0,
|
|
||||||
.size = 0,
|
|
||||||
.flags = (mode == O_RDONLY) ? CRYPT_ACTIVATE_READONLY : 0
|
|
||||||
};
|
|
||||||
|
|
||||||
/*
|
if (snprintf(cipher_spec, sizeof(cipher_spec), "%s-%s", cipher, mode) < 0)
|
||||||
* we need to round this to nearest multiple of the underlying
|
return;
|
||||||
* device's sector size, otherwise the mapping will be refused.
|
|
||||||
*/
|
|
||||||
if(device_sector_size < 0) {
|
|
||||||
log_err(ctx, _("Unable to obtain sector size for %s"), device);
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
dmd.size = round_up_modulo(srcLength,device_sector_size)/SECTOR_SIZE;
|
log_err(ctx, _("Failed to setup dm-crypt key mapping for device %s.\n"
|
||||||
cleaner_size = dmd.size;
|
"Check that kernel supports %s cipher (check syslog for more info).\n"),
|
||||||
|
device, cipher_spec);
|
||||||
|
|
||||||
return dm_create_device(name, "TEMP", &dmd, 0);
|
if (!strncmp(mode, "xts", 3) && (keyLength != 256 && keyLength != 512))
|
||||||
|
log_err(ctx, _("Key size in XTS mode must be 256 or 512 bits.\n"));
|
||||||
}
|
}
|
||||||
|
|
||||||
static void sigint_handler(int sig __attribute__((unused)))
|
|
||||||
{
|
|
||||||
if(devfd >= 0)
|
|
||||||
close(devfd);
|
|
||||||
devfd = -1;
|
|
||||||
if(cleaner_name)
|
|
||||||
dm_remove_device(cleaner_name, 1, cleaner_size);
|
|
||||||
|
|
||||||
signal(SIGINT, SIG_DFL);
|
|
||||||
kill(getpid(), SIGINT);
|
|
||||||
}
|
|
||||||
|
|
||||||
static const char *_error_hint(char *cipherMode, size_t keyLength)
|
|
||||||
{
|
|
||||||
const char *hint= "";
|
|
||||||
|
|
||||||
if (!strncmp(cipherMode, "xts", 3) && (keyLength != 256 && keyLength != 512))
|
|
||||||
hint = _("Key size in XTS mode must be 256 or 512 bits.\n");
|
|
||||||
|
|
||||||
return hint;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* This function is not reentrant safe, as it installs a signal
|
|
||||||
handler and global vars for cleaning */
|
|
||||||
static int LUKS_endec_template(char *src, size_t srcLength,
|
static int LUKS_endec_template(char *src, size_t srcLength,
|
||||||
struct luks_phdr *hdr,
|
const char *cipher, const char *cipher_mode,
|
||||||
struct volume_key *vk,
|
struct volume_key *vk,
|
||||||
const char *device,
|
|
||||||
unsigned int sector,
|
unsigned int sector,
|
||||||
ssize_t (*func)(int, void *, size_t),
|
ssize_t (*func)(int, int, void *, size_t),
|
||||||
int mode,
|
int mode,
|
||||||
struct crypt_device *ctx)
|
struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
char *name = NULL;
|
char name[PATH_MAX], path[PATH_MAX];
|
||||||
char *fullpath = NULL;
|
char cipher_spec[MAX_CIPHER_LEN * 3];
|
||||||
char *dmCipherSpec = NULL;
|
struct crypt_dm_active_device dmd = {
|
||||||
const char *dmDir = dm_get_dir();
|
.target = DM_CRYPT,
|
||||||
int r = -1;
|
.uuid = NULL,
|
||||||
|
.flags = CRYPT_ACTIVATE_PRIVATE,
|
||||||
|
.data_device = crypt_metadata_device(ctx),
|
||||||
|
.u.crypt = {
|
||||||
|
.cipher = cipher_spec,
|
||||||
|
.vk = vk,
|
||||||
|
.offset = sector,
|
||||||
|
.iv_offset = 0,
|
||||||
|
}
|
||||||
|
};
|
||||||
|
int r, bsize, devfd = -1;
|
||||||
|
|
||||||
if(dmDir == NULL) {
|
log_dbg("Using dmcrypt to access keyslot area.");
|
||||||
log_err(ctx, _("Failed to obtain device mapper directory."));
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
if(asprintf(&name,"temporary-cryptsetup-%d",getpid()) == -1 ||
|
|
||||||
asprintf(&fullpath,"%s/%s",dmDir,name) == -1 ||
|
|
||||||
asprintf(&dmCipherSpec,"%s-%s",hdr->cipherName, hdr->cipherMode) == -1) {
|
|
||||||
r = -ENOMEM;
|
|
||||||
goto out1;
|
|
||||||
}
|
|
||||||
|
|
||||||
signal(SIGINT, sigint_handler);
|
bsize = device_block_size(dmd.data_device);
|
||||||
cleaner_name = name;
|
if (bsize <= 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
r = setup_mapping(dmCipherSpec, name, device,
|
dmd.size = size_round_up(srcLength, bsize) / SECTOR_SIZE;
|
||||||
vk, sector, srcLength, mode, ctx);
|
|
||||||
if(r < 0) {
|
if (mode == O_RDONLY)
|
||||||
log_err(ctx, _("Failed to setup dm-crypt key mapping for device %s.\n"
|
dmd.flags |= CRYPT_ACTIVATE_READONLY;
|
||||||
"Check that kernel supports %s cipher (check syslog for more info).\n%s"),
|
|
||||||
device, dmCipherSpec,
|
if (snprintf(name, sizeof(name), "temporary-cryptsetup-%d", getpid()) < 0)
|
||||||
_error_hint(hdr->cipherMode, vk->keylength * 8));
|
return -ENOMEM;
|
||||||
r = -EIO;
|
if (snprintf(path, sizeof(path), "%s/%s", dm_get_dir(), name) < 0)
|
||||||
goto out1;
|
return -ENOMEM;
|
||||||
|
if (snprintf(cipher_spec, sizeof(cipher_spec), "%s-%s", cipher, cipher_mode) < 0)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
r = device_block_adjust(ctx, dmd.data_device, DEV_OK,
|
||||||
|
dmd.u.crypt.offset, &dmd.size, &dmd.flags);
|
||||||
|
if (r < 0) {
|
||||||
|
log_err(ctx, _("Device %s doesn't exist or access denied.\n"),
|
||||||
|
device_path(dmd.data_device));
|
||||||
|
return -EIO;
|
||||||
}
|
}
|
||||||
|
|
||||||
devfd = open(fullpath, mode | O_DIRECT | O_SYNC); /* devfd is a global var */
|
if (mode != O_RDONLY && dmd.flags & CRYPT_ACTIVATE_READONLY) {
|
||||||
if(devfd == -1) {
|
log_err(ctx, _("Cannot write to device %s, permission denied.\n"),
|
||||||
|
device_path(dmd.data_device));
|
||||||
|
return -EACCES;
|
||||||
|
}
|
||||||
|
|
||||||
|
r = dm_create_device(ctx, name, "TEMP", &dmd, 0);
|
||||||
|
if (r < 0) {
|
||||||
|
if (r != -EACCES && r != -ENOTSUP)
|
||||||
|
_error_hint(ctx, device_path(dmd.data_device),
|
||||||
|
cipher, cipher_mode, vk->keylength * 8);
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
|
||||||
|
devfd = open(path, mode | O_DIRECT | O_SYNC);
|
||||||
|
if (devfd == -1) {
|
||||||
log_err(ctx, _("Failed to open temporary keystore device.\n"));
|
log_err(ctx, _("Failed to open temporary keystore device.\n"));
|
||||||
r = -EIO;
|
r = -EIO;
|
||||||
goto out2;
|
goto out;
|
||||||
}
|
}
|
||||||
|
|
||||||
r = func(devfd,src,srcLength);
|
r = func(devfd, bsize, src, srcLength);
|
||||||
if(r < 0) {
|
if (r < 0) {
|
||||||
log_err(ctx, _("Failed to access temporary keystore device.\n"));
|
log_err(ctx, _("Failed to access temporary keystore device.\n"));
|
||||||
r = -EIO;
|
r = -EIO;
|
||||||
goto out3;
|
} else
|
||||||
}
|
r = 0;
|
||||||
|
out:
|
||||||
r = 0;
|
if(devfd != -1)
|
||||||
out3:
|
close(devfd);
|
||||||
close(devfd);
|
dm_remove_device(ctx, name, 1, dmd.size);
|
||||||
devfd = -1;
|
|
||||||
out2:
|
|
||||||
dm_remove_device(cleaner_name, 1, cleaner_size);
|
|
||||||
out1:
|
|
||||||
signal(SIGINT, SIG_DFL);
|
|
||||||
cleaner_name = NULL;
|
|
||||||
cleaner_size = 0;
|
|
||||||
free(dmCipherSpec);
|
|
||||||
free(fullpath);
|
|
||||||
free(name);
|
|
||||||
return r;
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
int LUKS_encrypt_to_storage(char *src, size_t srcLength,
|
int LUKS_encrypt_to_storage(char *src, size_t srcLength,
|
||||||
struct luks_phdr *hdr,
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
struct volume_key *vk,
|
struct volume_key *vk,
|
||||||
const char *device,
|
|
||||||
unsigned int sector,
|
unsigned int sector,
|
||||||
struct crypt_device *ctx)
|
struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
return LUKS_endec_template(src,srcLength,hdr,vk, device,
|
|
||||||
sector, write_blockwise, O_RDWR, ctx);
|
struct device *device = crypt_metadata_device(ctx);
|
||||||
|
struct crypt_storage *s;
|
||||||
|
int devfd = -1, bsize, r = 0;
|
||||||
|
|
||||||
|
/* Only whole sector writes supported */
|
||||||
|
if (srcLength % SECTOR_SIZE)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
/* Encrypt buffer */
|
||||||
|
r = crypt_storage_init(&s, 0, cipher, cipher_mode, vk->key, vk->keylength);
|
||||||
|
|
||||||
|
if (r)
|
||||||
|
log_dbg("Userspace crypto wrapper cannot use %s-%s (%d).",
|
||||||
|
cipher, cipher_mode, r);
|
||||||
|
|
||||||
|
/* Fallback to old temporary dmcrypt device */
|
||||||
|
if (r == -ENOTSUP || r == -ENOENT)
|
||||||
|
return LUKS_endec_template(src, srcLength, cipher, cipher_mode,
|
||||||
|
vk, sector, write_blockwise, O_RDWR, ctx);
|
||||||
|
|
||||||
|
if (r) {
|
||||||
|
_error_hint(ctx, device_path(device), cipher, cipher_mode,
|
||||||
|
vk->keylength * 8);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
log_dbg("Using userspace crypto wrapper to access keyslot area.");
|
||||||
|
|
||||||
|
r = crypt_storage_encrypt(s, 0, srcLength / SECTOR_SIZE, src);
|
||||||
|
crypt_storage_destroy(s);
|
||||||
|
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = -EIO;
|
||||||
|
|
||||||
|
/* Write buffer to device */
|
||||||
|
bsize = device_block_size(device);
|
||||||
|
if (bsize <= 0)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
devfd = device_open(device, O_RDWR);
|
||||||
|
if (devfd == -1)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if (lseek(devfd, sector * SECTOR_SIZE, SEEK_SET) == -1 ||
|
||||||
|
write_blockwise(devfd, bsize, src, srcLength) == -1)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
r = 0;
|
||||||
|
out:
|
||||||
|
if(devfd != -1)
|
||||||
|
close(devfd);
|
||||||
|
if (r)
|
||||||
|
log_err(ctx, _("IO error while encrypting keyslot.\n"));
|
||||||
|
|
||||||
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
int LUKS_decrypt_from_storage(char *dst, size_t dstLength,
|
int LUKS_decrypt_from_storage(char *dst, size_t dstLength,
|
||||||
struct luks_phdr *hdr,
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
struct volume_key *vk,
|
struct volume_key *vk,
|
||||||
const char *device,
|
|
||||||
unsigned int sector,
|
unsigned int sector,
|
||||||
struct crypt_device *ctx)
|
struct crypt_device *ctx)
|
||||||
{
|
{
|
||||||
return LUKS_endec_template(dst,dstLength,hdr,vk, device,
|
struct device *device = crypt_metadata_device(ctx);
|
||||||
sector, read_blockwise, O_RDONLY, ctx);
|
struct crypt_storage *s;
|
||||||
|
int devfd = -1, bsize, r = 0;
|
||||||
|
|
||||||
|
/* Only whole sector reads supported */
|
||||||
|
if (dstLength % SECTOR_SIZE)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = crypt_storage_init(&s, 0, cipher, cipher_mode, vk->key, vk->keylength);
|
||||||
|
|
||||||
|
if (r)
|
||||||
|
log_dbg("Userspace crypto wrapper cannot use %s-%s (%d).",
|
||||||
|
cipher, cipher_mode, r);
|
||||||
|
|
||||||
|
/* Fallback to old temporary dmcrypt device */
|
||||||
|
if (r == -ENOTSUP || r == -ENOENT)
|
||||||
|
return LUKS_endec_template(dst, dstLength, cipher, cipher_mode,
|
||||||
|
vk, sector, read_blockwise, O_RDONLY, ctx);
|
||||||
|
|
||||||
|
if (r) {
|
||||||
|
_error_hint(ctx, device_path(device), cipher, cipher_mode,
|
||||||
|
vk->keylength * 8);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
log_dbg("Using userspace crypto wrapper to access keyslot area.");
|
||||||
|
|
||||||
|
r = -EIO;
|
||||||
|
|
||||||
|
/* Read buffer from device */
|
||||||
|
bsize = device_block_size(device);
|
||||||
|
if (bsize <= 0)
|
||||||
|
goto bad;
|
||||||
|
|
||||||
|
devfd = device_open(device, O_RDONLY);
|
||||||
|
if (devfd == -1)
|
||||||
|
goto bad;
|
||||||
|
|
||||||
|
if (lseek(devfd, sector * SECTOR_SIZE, SEEK_SET) == -1 ||
|
||||||
|
read_blockwise(devfd, bsize, dst, dstLength) == -1)
|
||||||
|
goto bad;
|
||||||
|
|
||||||
|
close(devfd);
|
||||||
|
|
||||||
|
/* Decrypt buffer */
|
||||||
|
r = crypt_storage_decrypt(s, 0, dstLength / SECTOR_SIZE, dst);
|
||||||
|
crypt_storage_destroy(s);
|
||||||
|
|
||||||
|
return r;
|
||||||
|
bad:
|
||||||
|
if(devfd != -1)
|
||||||
|
close(devfd);
|
||||||
|
|
||||||
|
log_err(ctx, _("IO error while decrypting keyslot.\n"));
|
||||||
|
crypt_storage_destroy(s);
|
||||||
|
|
||||||
|
return r;
|
||||||
}
|
}
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -1,3 +1,24 @@
|
|||||||
|
/*
|
||||||
|
* LUKS - Linux Unified Key Setup
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004-2006, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef INCLUDED_CRYPTSETUP_LUKS_LUKS_H
|
#ifndef INCLUDED_CRYPTSETUP_LUKS_LUKS_H
|
||||||
#define INCLUDED_CRYPTSETUP_LUKS_LUKS_H
|
#define INCLUDED_CRYPTSETUP_LUKS_LUKS_H
|
||||||
|
|
||||||
@@ -31,8 +52,6 @@
|
|||||||
#define LUKS_MAGIC {'L','U','K','S', 0xba, 0xbe};
|
#define LUKS_MAGIC {'L','U','K','S', 0xba, 0xbe};
|
||||||
#define LUKS_MAGIC_L 6
|
#define LUKS_MAGIC_L 6
|
||||||
|
|
||||||
#define LUKS_PHDR_SIZE (sizeof(struct luks_phdr)/SECTOR_SIZE+1)
|
|
||||||
|
|
||||||
/* Actually we need only 37, but we don't want struct autoaligning to kick in */
|
/* Actually we need only 37, but we don't want struct autoaligning to kick in */
|
||||||
#define UUID_STRING_L 40
|
#define UUID_STRING_L 40
|
||||||
|
|
||||||
@@ -43,6 +62,7 @@
|
|||||||
converted */
|
converted */
|
||||||
|
|
||||||
struct volume_key;
|
struct volume_key;
|
||||||
|
struct device_backend;
|
||||||
|
|
||||||
struct luks_phdr {
|
struct luks_phdr {
|
||||||
char magic[LUKS_MAGIC_L];
|
char magic[LUKS_MAGIC_L];
|
||||||
@@ -88,47 +108,40 @@ int LUKS_generate_phdr(
|
|||||||
unsigned int alignOffset,
|
unsigned int alignOffset,
|
||||||
uint32_t iteration_time_ms,
|
uint32_t iteration_time_ms,
|
||||||
uint64_t *PBKDF2_per_sec,
|
uint64_t *PBKDF2_per_sec,
|
||||||
const char *metadata_device,
|
int detached_metadata_device,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_read_phdr(
|
int LUKS_read_phdr(
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
int require_luks_device,
|
int require_luks_device,
|
||||||
|
int repair,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_read_phdr_backup(
|
int LUKS_read_phdr_backup(
|
||||||
const char *backup_file,
|
const char *backup_file,
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
int require_luks_device,
|
int require_luks_device,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_hdr_uuid_set(
|
int LUKS_hdr_uuid_set(
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
const char *uuid,
|
const char *uuid,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_hdr_backup(
|
int LUKS_hdr_backup(
|
||||||
const char *backup_file,
|
const char *backup_file,
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_hdr_restore(
|
int LUKS_hdr_restore(
|
||||||
const char *backup_file,
|
const char *backup_file,
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_write_phdr(
|
int LUKS_write_phdr(
|
||||||
const char *device,
|
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_set_key(
|
int LUKS_set_key(
|
||||||
const char *device,
|
|
||||||
unsigned int keyIndex,
|
unsigned int keyIndex,
|
||||||
const char *password,
|
const char *password,
|
||||||
size_t passwordLen,
|
size_t passwordLen,
|
||||||
@@ -139,7 +152,6 @@ int LUKS_set_key(
|
|||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_open_key_with_hdr(
|
int LUKS_open_key_with_hdr(
|
||||||
const char *device,
|
|
||||||
int keyIndex,
|
int keyIndex,
|
||||||
const char *password,
|
const char *password,
|
||||||
size_t passwordLen,
|
size_t passwordLen,
|
||||||
@@ -148,7 +160,6 @@ int LUKS_open_key_with_hdr(
|
|||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_del_key(
|
int LUKS_del_key(
|
||||||
const char *device,
|
|
||||||
unsigned int keyIndex,
|
unsigned int keyIndex,
|
||||||
struct luks_phdr *hdr,
|
struct luks_phdr *hdr,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
@@ -157,20 +168,24 @@ crypt_keyslot_info LUKS_keyslot_info(struct luks_phdr *hdr, int keyslot);
|
|||||||
int LUKS_keyslot_find_empty(struct luks_phdr *hdr);
|
int LUKS_keyslot_find_empty(struct luks_phdr *hdr);
|
||||||
int LUKS_keyslot_active_count(struct luks_phdr *hdr);
|
int LUKS_keyslot_active_count(struct luks_phdr *hdr);
|
||||||
int LUKS_keyslot_set(struct luks_phdr *hdr, int keyslot, int enable);
|
int LUKS_keyslot_set(struct luks_phdr *hdr, int keyslot, int enable);
|
||||||
|
int LUKS_keyslot_area(struct luks_phdr *hdr,
|
||||||
|
int keyslot,
|
||||||
|
uint64_t *offset,
|
||||||
|
uint64_t *length);
|
||||||
|
|
||||||
int LUKS_encrypt_to_storage(
|
int LUKS_encrypt_to_storage(
|
||||||
char *src, size_t srcLength,
|
char *src, size_t srcLength,
|
||||||
struct luks_phdr *hdr,
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
struct volume_key *vk,
|
struct volume_key *vk,
|
||||||
const char *device,
|
|
||||||
unsigned int sector,
|
unsigned int sector,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
int LUKS_decrypt_from_storage(
|
int LUKS_decrypt_from_storage(
|
||||||
char *dst, size_t dstLength,
|
char *dst, size_t dstLength,
|
||||||
struct luks_phdr *hdr,
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
struct volume_key *vk,
|
struct volume_key *vk,
|
||||||
const char *device,
|
|
||||||
unsigned int sector,
|
unsigned int sector,
|
||||||
struct crypt_device *ctx);
|
struct crypt_device *ctx);
|
||||||
|
|
||||||
|
|||||||
@@ -1,266 +0,0 @@
|
|||||||
/* Implementation of Password-Based Cryptography as per PKCS#5
|
|
||||||
* Copyright (C) 2002,2003 Simon Josefsson
|
|
||||||
* Copyright (C) 2004 Free Software Foundation
|
|
||||||
*
|
|
||||||
* LUKS code
|
|
||||||
* Copyright (C) 2004, Clemens Fruhwirth <clemens@endorphin.org>
|
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
|
||||||
*
|
|
||||||
* This file is free software; you can redistribute it and/or
|
|
||||||
* modify it under the terms of the GNU Lesser General Public
|
|
||||||
* License as published by the Free Software Foundation; either
|
|
||||||
* version 2.1 of the License, or (at your option) any later version.
|
|
||||||
*
|
|
||||||
* This file is distributed in the hope that it will be useful,
|
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
||||||
* Lesser General Public License for more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU Lesser General Public
|
|
||||||
* License along with this file; if not, write to the Free Software
|
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <netinet/in.h>
|
|
||||||
#include <errno.h>
|
|
||||||
#include <signal.h>
|
|
||||||
#include <alloca.h>
|
|
||||||
#include <string.h>
|
|
||||||
#include <sys/time.h>
|
|
||||||
#include "crypto_backend.h"
|
|
||||||
#include "pbkdf.h"
|
|
||||||
|
|
||||||
static volatile uint64_t __PBKDF2_global_j = 0;
|
|
||||||
static volatile uint64_t __PBKDF2_performance = 0;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* 5.2 PBKDF2
|
|
||||||
*
|
|
||||||
* PBKDF2 applies a pseudorandom function (see Appendix B.1 for an
|
|
||||||
* example) to derive keys. The length of the derived key is essentially
|
|
||||||
* unbounded. (However, the maximum effective search space for the
|
|
||||||
* derived key may be limited by the structure of the underlying
|
|
||||||
* pseudorandom function. See Appendix B.1 for further discussion.)
|
|
||||||
* PBKDF2 is recommended for new applications.
|
|
||||||
*
|
|
||||||
* PBKDF2 (P, S, c, dkLen)
|
|
||||||
*
|
|
||||||
* Options: PRF underlying pseudorandom function (hLen
|
|
||||||
* denotes the length in octets of the
|
|
||||||
* pseudorandom function output)
|
|
||||||
*
|
|
||||||
* Input: P password, an octet string (ASCII or UTF-8)
|
|
||||||
* S salt, an octet string
|
|
||||||
* c iteration count, a positive integer
|
|
||||||
* dkLen intended length in octets of the derived
|
|
||||||
* key, a positive integer, at most
|
|
||||||
* (2^32 - 1) * hLen
|
|
||||||
*
|
|
||||||
* Output: DK derived key, a dkLen-octet string
|
|
||||||
*/
|
|
||||||
|
|
||||||
#define MAX_PRF_BLOCK_LEN 80
|
|
||||||
|
|
||||||
static int pkcs5_pbkdf2(const char *hash,
|
|
||||||
const char *P, size_t Plen,
|
|
||||||
const char *S, size_t Slen,
|
|
||||||
unsigned int c, unsigned int dkLen,
|
|
||||||
char *DK, int perfcheck)
|
|
||||||
{
|
|
||||||
struct crypt_hmac *hmac;
|
|
||||||
char U[MAX_PRF_BLOCK_LEN];
|
|
||||||
char T[MAX_PRF_BLOCK_LEN];
|
|
||||||
int i, k, rc = -EINVAL;
|
|
||||||
unsigned int u, hLen, l, r;
|
|
||||||
size_t tmplen = Slen + 4;
|
|
||||||
char *tmp;
|
|
||||||
|
|
||||||
tmp = alloca(tmplen);
|
|
||||||
if (tmp == NULL)
|
|
||||||
return -ENOMEM;
|
|
||||||
|
|
||||||
hLen = crypt_hmac_size(hash);
|
|
||||||
if (hLen == 0 || hLen > MAX_PRF_BLOCK_LEN)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
if (c == 0)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
if (dkLen == 0)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
/*
|
|
||||||
*
|
|
||||||
* Steps:
|
|
||||||
*
|
|
||||||
* 1. If dkLen > (2^32 - 1) * hLen, output "derived key too long" and
|
|
||||||
* stop.
|
|
||||||
*/
|
|
||||||
|
|
||||||
if (dkLen > 4294967295U)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* 2. Let l be the number of hLen-octet blocks in the derived key,
|
|
||||||
* rounding up, and let r be the number of octets in the last
|
|
||||||
* block:
|
|
||||||
*
|
|
||||||
* l = CEIL (dkLen / hLen) ,
|
|
||||||
* r = dkLen - (l - 1) * hLen .
|
|
||||||
*
|
|
||||||
* Here, CEIL (x) is the "ceiling" function, i.e. the smallest
|
|
||||||
* integer greater than, or equal to, x.
|
|
||||||
*/
|
|
||||||
|
|
||||||
l = dkLen / hLen;
|
|
||||||
if (dkLen % hLen)
|
|
||||||
l++;
|
|
||||||
r = dkLen - (l - 1) * hLen;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* 3. For each block of the derived key apply the function F defined
|
|
||||||
* below to the password P, the salt S, the iteration count c, and
|
|
||||||
* the block index to compute the block:
|
|
||||||
*
|
|
||||||
* T_1 = F (P, S, c, 1) ,
|
|
||||||
* T_2 = F (P, S, c, 2) ,
|
|
||||||
* ...
|
|
||||||
* T_l = F (P, S, c, l) ,
|
|
||||||
*
|
|
||||||
* where the function F is defined as the exclusive-or sum of the
|
|
||||||
* first c iterates of the underlying pseudorandom function PRF
|
|
||||||
* applied to the password P and the concatenation of the salt S
|
|
||||||
* and the block index i:
|
|
||||||
*
|
|
||||||
* F (P, S, c, i) = U_1 \xor U_2 \xor ... \xor U_c
|
|
||||||
*
|
|
||||||
* where
|
|
||||||
*
|
|
||||||
* U_1 = PRF (P, S || INT (i)) ,
|
|
||||||
* U_2 = PRF (P, U_1) ,
|
|
||||||
* ...
|
|
||||||
* U_c = PRF (P, U_{c-1}) .
|
|
||||||
*
|
|
||||||
* Here, INT (i) is a four-octet encoding of the integer i, most
|
|
||||||
* significant octet first.
|
|
||||||
*
|
|
||||||
* 4. Concatenate the blocks and extract the first dkLen octets to
|
|
||||||
* produce a derived key DK:
|
|
||||||
*
|
|
||||||
* DK = T_1 || T_2 || ... || T_l<0..r-1>
|
|
||||||
*
|
|
||||||
* 5. Output the derived key DK.
|
|
||||||
*
|
|
||||||
* Note. The construction of the function F follows a "belt-and-
|
|
||||||
* suspenders" approach. The iterates U_i are computed recursively to
|
|
||||||
* remove a degree of parallelism from an opponent; they are exclusive-
|
|
||||||
* ored together to reduce concerns about the recursion degenerating
|
|
||||||
* into a small set of values.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
if (crypt_hmac_init(&hmac, hash, P, Plen))
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
for (i = 1; (uint) i <= l; i++) {
|
|
||||||
memset(T, 0, hLen);
|
|
||||||
|
|
||||||
for (u = 1; u <= c ; u++) {
|
|
||||||
if (u == 1) {
|
|
||||||
memcpy(tmp, S, Slen);
|
|
||||||
tmp[Slen + 0] = (i & 0xff000000) >> 24;
|
|
||||||
tmp[Slen + 1] = (i & 0x00ff0000) >> 16;
|
|
||||||
tmp[Slen + 2] = (i & 0x0000ff00) >> 8;
|
|
||||||
tmp[Slen + 3] = (i & 0x000000ff) >> 0;
|
|
||||||
|
|
||||||
if (crypt_hmac_write(hmac, tmp, tmplen))
|
|
||||||
goto out;
|
|
||||||
} else {
|
|
||||||
if (crypt_hmac_write(hmac, U, hLen))
|
|
||||||
goto out;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (crypt_hmac_final(hmac, U, hLen))
|
|
||||||
goto out;
|
|
||||||
|
|
||||||
for (k = 0; (uint) k < hLen; k++)
|
|
||||||
T[k] ^= U[k];
|
|
||||||
|
|
||||||
if (perfcheck && __PBKDF2_performance) {
|
|
||||||
rc = 0;
|
|
||||||
goto out;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (perfcheck)
|
|
||||||
__PBKDF2_global_j++;
|
|
||||||
}
|
|
||||||
|
|
||||||
memcpy(DK + (i - 1) * hLen, T, (uint) i == l ? r : hLen);
|
|
||||||
}
|
|
||||||
rc = 0;
|
|
||||||
out:
|
|
||||||
crypt_hmac_destroy(hmac);
|
|
||||||
return rc;
|
|
||||||
}
|
|
||||||
|
|
||||||
int PBKDF2_HMAC(const char *hash,
|
|
||||||
const char *password, size_t passwordLen,
|
|
||||||
const char *salt, size_t saltLen, unsigned int iterations,
|
|
||||||
char *dKey, size_t dKeyLen)
|
|
||||||
{
|
|
||||||
return pkcs5_pbkdf2(hash, password, passwordLen, salt, saltLen,
|
|
||||||
iterations, (unsigned int)dKeyLen, dKey, 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
int PBKDF2_HMAC_ready(const char *hash)
|
|
||||||
{
|
|
||||||
if (crypt_hmac_size(hash) < 20)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
return 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
static void sigvtalarm(int foo __attribute__((unused)))
|
|
||||||
{
|
|
||||||
__PBKDF2_performance = __PBKDF2_global_j;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* This code benchmarks PBKDF2 and returns iterations/second using wth specified hash */
|
|
||||||
int PBKDF2_performance_check(const char *hash, uint64_t *iter)
|
|
||||||
{
|
|
||||||
int timer_type, r;
|
|
||||||
char buf;
|
|
||||||
struct itimerval it;
|
|
||||||
|
|
||||||
if (__PBKDF2_global_j)
|
|
||||||
return -EBUSY;
|
|
||||||
|
|
||||||
if (PBKDF2_HMAC_ready(hash) < 0)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
/* If crypto backend is not implemented in userspace,
|
|
||||||
* but uses some kernel part, we must measure also time
|
|
||||||
* spent in kernel. */
|
|
||||||
if (crypt_backend_flags() & CRYPT_BACKEND_KERNEL) {
|
|
||||||
timer_type = ITIMER_PROF;
|
|
||||||
signal(SIGPROF,sigvtalarm);
|
|
||||||
} else {
|
|
||||||
timer_type = ITIMER_VIRTUAL;
|
|
||||||
signal(SIGVTALRM,sigvtalarm);
|
|
||||||
}
|
|
||||||
|
|
||||||
it.it_interval.tv_usec = 0;
|
|
||||||
it.it_interval.tv_sec = 0;
|
|
||||||
it.it_value.tv_usec = 0;
|
|
||||||
it.it_value.tv_sec = 1;
|
|
||||||
if (setitimer(timer_type, &it, NULL) < 0)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
r = pkcs5_pbkdf2(hash, "foo", 3, "bar", 3, ~(0U), 1, &buf, 1);
|
|
||||||
|
|
||||||
*iter = __PBKDF2_performance;
|
|
||||||
__PBKDF2_global_j = 0;
|
|
||||||
__PBKDF2_performance = 0;
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
#ifndef INCLUDED_CRYPTSETUP_LUKS_PBKDF_H
|
|
||||||
#define INCLUDED_CRYPTSETUP_LUKS_PBKDF_H
|
|
||||||
|
|
||||||
#include <stddef.h>
|
|
||||||
|
|
||||||
int PBKDF2_HMAC(const char *hash,
|
|
||||||
const char *password, size_t passwordLen,
|
|
||||||
const char *salt, size_t saltLen, unsigned int iterations,
|
|
||||||
char *dKey, size_t dKeyLen);
|
|
||||||
|
|
||||||
|
|
||||||
int PBKDF2_performance_check(const char *hash, uint64_t *iter);
|
|
||||||
int PBKDF2_HMAC_ready(const char *hash);
|
|
||||||
|
|
||||||
#endif
|
|
||||||
@@ -31,4 +31,4 @@
|
|||||||
( (Count) == 1 ? (Singular) : (Plural) )
|
( (Count) == 1 ? (Singular) : (Plural) )
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#endif /* CRYPTSETUP_H */
|
#endif /* CRYPTSETUP_NLS_H */
|
||||||
|
|||||||
23
lib/random.c
23
lib/random.c
@@ -1,11 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* cryptsetup kernel RNG access functions
|
* cryptsetup kernel RNG access functions
|
||||||
*
|
*
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -14,7 +15,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -22,6 +23,7 @@
|
|||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <assert.h>
|
#include <assert.h>
|
||||||
|
#include <sys/select.h>
|
||||||
|
|
||||||
#include "libcryptsetup.h"
|
#include "libcryptsetup.h"
|
||||||
#include "internal.h"
|
#include "internal.h"
|
||||||
@@ -160,6 +162,9 @@ int crypt_random_init(struct crypt_device *ctx)
|
|||||||
if(random_fd == -1)
|
if(random_fd == -1)
|
||||||
goto fail;
|
goto fail;
|
||||||
|
|
||||||
|
if (crypt_fips_mode())
|
||||||
|
log_verbose(ctx, _("Running in FIPS mode.\n"));
|
||||||
|
|
||||||
random_initialised = 1;
|
random_initialised = 1;
|
||||||
return 0;
|
return 0;
|
||||||
fail:
|
fail:
|
||||||
@@ -176,7 +181,17 @@ int crypt_random_get(struct crypt_device *ctx, char *buf, size_t len, int qualit
|
|||||||
case CRYPT_RND_NORMAL:
|
case CRYPT_RND_NORMAL:
|
||||||
status = _get_urandom(ctx, buf, len);
|
status = _get_urandom(ctx, buf, len);
|
||||||
break;
|
break;
|
||||||
|
case CRYPT_RND_SALT:
|
||||||
|
if (crypt_fips_mode())
|
||||||
|
status = crypt_backend_rng(buf, len, quality, 1);
|
||||||
|
else
|
||||||
|
status = _get_urandom(ctx, buf, len);
|
||||||
|
break;
|
||||||
case CRYPT_RND_KEY:
|
case CRYPT_RND_KEY:
|
||||||
|
if (crypt_fips_mode()) {
|
||||||
|
status = crypt_backend_rng(buf, len, quality, 1);
|
||||||
|
break;
|
||||||
|
}
|
||||||
rng_type = ctx ? crypt_get_rng_type(ctx) :
|
rng_type = ctx ? crypt_get_rng_type(ctx) :
|
||||||
crypt_random_default_key_rng();
|
crypt_random_default_key_rng();
|
||||||
switch (rng_type) {
|
switch (rng_type) {
|
||||||
@@ -219,9 +234,11 @@ void crypt_random_exit(void)
|
|||||||
|
|
||||||
int crypt_random_default_key_rng(void)
|
int crypt_random_default_key_rng(void)
|
||||||
{
|
{
|
||||||
|
/* coverity[pointless_string_compare] */
|
||||||
if (!strcmp(DEFAULT_RNG, RANDOM_DEVICE))
|
if (!strcmp(DEFAULT_RNG, RANDOM_DEVICE))
|
||||||
return CRYPT_RNG_RANDOM;
|
return CRYPT_RNG_RANDOM;
|
||||||
|
|
||||||
|
/* coverity[pointless_string_compare] */
|
||||||
if (!strcmp(DEFAULT_RNG, URANDOM_DEVICE))
|
if (!strcmp(DEFAULT_RNG, URANDOM_DEVICE))
|
||||||
return CRYPT_RNG_URANDOM;
|
return CRYPT_RNG_URANDOM;
|
||||||
|
|
||||||
|
|||||||
1615
lib/setup.c
1615
lib/setup.c
File diff suppressed because it is too large
Load Diff
14
lib/tcrypt/Makefile.am
Normal file
14
lib/tcrypt/Makefile.am
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
moduledir = $(libdir)/cryptsetup
|
||||||
|
|
||||||
|
noinst_LTLIBRARIES = libtcrypt.la
|
||||||
|
|
||||||
|
libtcrypt_la_CFLAGS = -Wall $(AM_CFLAGS) @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
|
libtcrypt_la_SOURCES = \
|
||||||
|
tcrypt.c \
|
||||||
|
tcrypt.h
|
||||||
|
|
||||||
|
AM_CPPFLAGS = -include config.h \
|
||||||
|
-I$(top_srcdir)/lib \
|
||||||
|
-I$(top_srcdir)/lib/crypto_backend
|
||||||
|
|
||||||
1071
lib/tcrypt/tcrypt.c
Normal file
1071
lib/tcrypt/tcrypt.c
Normal file
File diff suppressed because it is too large
Load Diff
115
lib/tcrypt/tcrypt.h
Normal file
115
lib/tcrypt/tcrypt.h
Normal file
@@ -0,0 +1,115 @@
|
|||||||
|
/*
|
||||||
|
* TCRYPT (TrueCrypt-compatible) header defitinion
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2014, Milan Broz
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include "libcryptsetup.h"
|
||||||
|
|
||||||
|
#ifndef _CRYPTSETUP_TCRYPT_H
|
||||||
|
#define _CRYPTSETUP_TCRYPT_H
|
||||||
|
|
||||||
|
#define TCRYPT_HDR_SALT_LEN 64
|
||||||
|
#define TCRYPT_HDR_IV_LEN 16
|
||||||
|
#define TCRYPT_HDR_LEN 448
|
||||||
|
#define TCRYPT_HDR_KEY_LEN 192
|
||||||
|
#define TCRYPT_HDR_MAGIC "TRUE"
|
||||||
|
#define VCRYPT_HDR_MAGIC "VERA"
|
||||||
|
#define TCRYPT_HDR_MAGIC_LEN 4
|
||||||
|
|
||||||
|
#define TCRYPT_HDR_HIDDEN_OFFSET_OLD -1536
|
||||||
|
#define TCRYPT_HDR_HIDDEN_OFFSET 65536
|
||||||
|
|
||||||
|
#define TCRYPT_HDR_HIDDEN_OFFSET_BCK -65536
|
||||||
|
#define TCRYPT_HDR_OFFSET_BCK -131072
|
||||||
|
|
||||||
|
#define TCRYPT_HDR_SYSTEM_OFFSET 31744
|
||||||
|
|
||||||
|
#define TCRYPT_LRW_IKEY_LEN 16
|
||||||
|
#define TCRYPT_KEY_POOL_LEN 64
|
||||||
|
#define TCRYPT_KEYFILE_LEN 1048576
|
||||||
|
|
||||||
|
#define TCRYPT_HDR_FLAG_SYSTEM (1 << 0)
|
||||||
|
#define TCRYPT_HDR_FLAG_NONSYSTEM (1 << 1)
|
||||||
|
|
||||||
|
struct tcrypt_phdr {
|
||||||
|
char salt[TCRYPT_HDR_SALT_LEN];
|
||||||
|
|
||||||
|
/* encrypted part, TCRYPT_HDR_LEN bytes */
|
||||||
|
union {
|
||||||
|
struct __attribute__((__packed__)) {
|
||||||
|
char magic[TCRYPT_HDR_MAGIC_LEN];
|
||||||
|
uint16_t version;
|
||||||
|
uint16_t version_tc;
|
||||||
|
uint32_t keys_crc32;
|
||||||
|
uint64_t _reserved1[2]; /* data/header ctime */
|
||||||
|
uint64_t hidden_volume_size;
|
||||||
|
uint64_t volume_size;
|
||||||
|
uint64_t mk_offset;
|
||||||
|
uint64_t mk_size;
|
||||||
|
uint32_t flags;
|
||||||
|
uint32_t sector_size;
|
||||||
|
uint8_t _reserved2[120];
|
||||||
|
uint32_t header_crc32;
|
||||||
|
char keys[256];
|
||||||
|
} d;
|
||||||
|
char e[TCRYPT_HDR_LEN];
|
||||||
|
};
|
||||||
|
} __attribute__((__packed__));
|
||||||
|
|
||||||
|
struct crypt_dm_active_device;
|
||||||
|
struct volume_key;
|
||||||
|
struct device;
|
||||||
|
|
||||||
|
int TCRYPT_read_phdr(struct crypt_device *cd,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params);
|
||||||
|
|
||||||
|
int TCRYPT_init_by_name(struct crypt_device *cd, const char *name,
|
||||||
|
const struct crypt_dm_active_device *dmd,
|
||||||
|
struct device **device,
|
||||||
|
struct crypt_params_tcrypt *tcrypt_params,
|
||||||
|
struct tcrypt_phdr *tcrypt_hdr);
|
||||||
|
|
||||||
|
int TCRYPT_activate(struct crypt_device *cd,
|
||||||
|
const char *name,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params,
|
||||||
|
uint32_t flags);
|
||||||
|
|
||||||
|
int TCRYPT_deactivate(struct crypt_device *cd,
|
||||||
|
const char *name);
|
||||||
|
|
||||||
|
uint64_t TCRYPT_get_data_offset(struct crypt_device *cd,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params);
|
||||||
|
|
||||||
|
uint64_t TCRYPT_get_iv_offset(struct crypt_device *cd,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params);
|
||||||
|
|
||||||
|
int TCRYPT_get_volume_key(struct crypt_device *cd,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params,
|
||||||
|
struct volume_key **vk);
|
||||||
|
|
||||||
|
int TCRYPT_dump(struct crypt_device *cd,
|
||||||
|
struct tcrypt_phdr *hdr,
|
||||||
|
struct crypt_params_tcrypt *params);
|
||||||
|
|
||||||
|
#endif
|
||||||
337
lib/utils.c
337
lib/utils.c
@@ -1,13 +1,15 @@
|
|||||||
/*
|
/*
|
||||||
* utils - miscellaneous device utilities for cryptsetup
|
* utils - miscellaneous device utilities for cryptsetup
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004, Christophe Saout <christophe@saout.de>
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2012, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -16,28 +18,24 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <stddef.h>
|
|
||||||
#include <stdarg.h>
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <linux/fs.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <unistd.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <sys/stat.h>
|
|
||||||
#include <sys/ioctl.h>
|
|
||||||
#include <fcntl.h>
|
|
||||||
#include <sys/mman.h>
|
#include <sys/mman.h>
|
||||||
#include <sys/resource.h>
|
#include <sys/resource.h>
|
||||||
|
|
||||||
#include "libcryptsetup.h"
|
|
||||||
#include "internal.h"
|
#include "internal.h"
|
||||||
|
|
||||||
|
unsigned crypt_getpagesize(void)
|
||||||
|
{
|
||||||
|
long r = sysconf(_SC_PAGESIZE);
|
||||||
|
return r < 0 ? DEFAULT_MEM_ALIGNMENT : r;
|
||||||
|
}
|
||||||
|
|
||||||
static int get_alignment(int fd)
|
static int get_alignment(int fd)
|
||||||
{
|
{
|
||||||
int alignment = DEFAULT_MEM_ALIGNMENT;
|
int alignment = DEFAULT_MEM_ALIGNMENT;
|
||||||
@@ -69,52 +67,15 @@ static void *aligned_malloc(void **base, int size, int alignment)
|
|||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
int device_read_ahead(const char *dev, uint32_t *read_ahead)
|
ssize_t write_blockwise(int fd, int bsize, void *orig_buf, size_t count)
|
||||||
{
|
|
||||||
int fd, r = 0;
|
|
||||||
long read_ahead_long;
|
|
||||||
|
|
||||||
if ((fd = open(dev, O_RDONLY)) < 0)
|
|
||||||
return 0;
|
|
||||||
|
|
||||||
r = ioctl(fd, BLKRAGET, &read_ahead_long) ? 0 : 1;
|
|
||||||
close(fd);
|
|
||||||
|
|
||||||
if (r)
|
|
||||||
*read_ahead = (uint32_t) read_ahead_long;
|
|
||||||
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
static int sector_size(int fd)
|
|
||||||
{
|
|
||||||
int bsize;
|
|
||||||
if (ioctl(fd,BLKSSZGET, &bsize) < 0)
|
|
||||||
return -EINVAL;
|
|
||||||
else
|
|
||||||
return bsize;
|
|
||||||
}
|
|
||||||
|
|
||||||
int sector_size_for_device(const char *device)
|
|
||||||
{
|
|
||||||
int fd = open(device, O_RDONLY);
|
|
||||||
int r;
|
|
||||||
if(fd < 0)
|
|
||||||
return -EINVAL;
|
|
||||||
r = sector_size(fd);
|
|
||||||
close(fd);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
ssize_t write_blockwise(int fd, void *orig_buf, size_t count)
|
|
||||||
{
|
{
|
||||||
void *hangover_buf, *hangover_buf_base = NULL;
|
void *hangover_buf, *hangover_buf_base = NULL;
|
||||||
void *buf, *buf_base = NULL;
|
void *buf, *buf_base = NULL;
|
||||||
int r, hangover, solid, bsize, alignment;
|
int r, hangover, solid, alignment;
|
||||||
ssize_t ret = -1;
|
ssize_t ret = -1;
|
||||||
|
|
||||||
if ((bsize = sector_size(fd)) < 0)
|
if (fd == -1 || !orig_buf || bsize <= 0)
|
||||||
return bsize;
|
return -1;
|
||||||
|
|
||||||
hangover = count % bsize;
|
hangover = count % bsize;
|
||||||
solid = count - hangover;
|
solid = count - hangover;
|
||||||
@@ -138,16 +99,19 @@ ssize_t write_blockwise(int fd, void *orig_buf, size_t count)
|
|||||||
goto out;
|
goto out;
|
||||||
|
|
||||||
r = read(fd, hangover_buf, bsize);
|
r = read(fd, hangover_buf, bsize);
|
||||||
if (r < 0 || r != bsize)
|
if (r < 0 || r < hangover)
|
||||||
goto out;
|
goto out;
|
||||||
|
|
||||||
|
if (r < bsize)
|
||||||
|
bsize = r;
|
||||||
|
|
||||||
r = lseek(fd, -bsize, SEEK_CUR);
|
r = lseek(fd, -bsize, SEEK_CUR);
|
||||||
if (r < 0)
|
if (r < 0)
|
||||||
goto out;
|
goto out;
|
||||||
memcpy(hangover_buf, (char*)buf + solid, hangover);
|
memcpy(hangover_buf, (char*)buf + solid, hangover);
|
||||||
|
|
||||||
r = write(fd, hangover_buf, bsize);
|
r = write(fd, hangover_buf, bsize);
|
||||||
if (r < 0 || r != bsize)
|
if (r < 0 || r < hangover)
|
||||||
goto out;
|
goto out;
|
||||||
}
|
}
|
||||||
ret = count;
|
ret = count;
|
||||||
@@ -158,14 +122,14 @@ out:
|
|||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
ssize_t read_blockwise(int fd, void *orig_buf, size_t count) {
|
ssize_t read_blockwise(int fd, int bsize, void *orig_buf, size_t count) {
|
||||||
void *hangover_buf, *hangover_buf_base = NULL;
|
void *hangover_buf, *hangover_buf_base = NULL;
|
||||||
void *buf, *buf_base = NULL;
|
void *buf, *buf_base = NULL;
|
||||||
int r, hangover, solid, bsize, alignment;
|
int r, hangover, solid, alignment;
|
||||||
ssize_t ret = -1;
|
ssize_t ret = -1;
|
||||||
|
|
||||||
if ((bsize = sector_size(fd)) < 0)
|
if (fd == -1 || !orig_buf || bsize <= 0)
|
||||||
return bsize;
|
return -1;
|
||||||
|
|
||||||
hangover = count % bsize;
|
hangover = count % bsize;
|
||||||
solid = count - hangover;
|
solid = count - hangover;
|
||||||
@@ -187,7 +151,7 @@ ssize_t read_blockwise(int fd, void *orig_buf, size_t count) {
|
|||||||
if (!hangover_buf)
|
if (!hangover_buf)
|
||||||
goto out;
|
goto out;
|
||||||
r = read(fd, hangover_buf, bsize);
|
r = read(fd, hangover_buf, bsize);
|
||||||
if (r < 0 || r != bsize)
|
if (r < 0 || r < hangover)
|
||||||
goto out;
|
goto out;
|
||||||
|
|
||||||
memcpy((char *)buf + solid, hangover_buf, hangover);
|
memcpy((char *)buf + solid, hangover_buf, hangover);
|
||||||
@@ -208,15 +172,15 @@ out:
|
|||||||
* is implicitly included in the read/write offset, which can not be set to non-aligned
|
* is implicitly included in the read/write offset, which can not be set to non-aligned
|
||||||
* boundaries. Hence, we combine llseek with write.
|
* boundaries. Hence, we combine llseek with write.
|
||||||
*/
|
*/
|
||||||
ssize_t write_lseek_blockwise(int fd, char *buf, size_t count, off_t offset) {
|
ssize_t write_lseek_blockwise(int fd, int bsize, char *buf, size_t count, off_t offset) {
|
||||||
char *frontPadBuf;
|
char *frontPadBuf;
|
||||||
void *frontPadBuf_base = NULL;
|
void *frontPadBuf_base = NULL;
|
||||||
int r, bsize, frontHang;
|
int r, frontHang;
|
||||||
size_t innerCount = 0;
|
size_t innerCount = 0;
|
||||||
ssize_t ret = -1;
|
ssize_t ret = -1;
|
||||||
|
|
||||||
if ((bsize = sector_size(fd)) < 0)
|
if (fd == -1 || !buf || bsize <= 0)
|
||||||
return bsize;
|
return -1;
|
||||||
|
|
||||||
frontHang = offset % bsize;
|
frontHang = offset % bsize;
|
||||||
|
|
||||||
@@ -250,7 +214,7 @@ ssize_t write_lseek_blockwise(int fd, char *buf, size_t count, off_t offset) {
|
|||||||
count -= innerCount;
|
count -= innerCount;
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = count ? write_blockwise(fd, buf, count) : 0;
|
ret = count ? write_blockwise(fd, bsize, buf, count) : 0;
|
||||||
if (ret >= 0)
|
if (ret >= 0)
|
||||||
ret += innerCount;
|
ret += innerCount;
|
||||||
out:
|
out:
|
||||||
@@ -259,182 +223,6 @@ out:
|
|||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
int device_ready(struct crypt_device *cd, const char *device, int mode)
|
|
||||||
{
|
|
||||||
int devfd, r = 0;
|
|
||||||
ssize_t s;
|
|
||||||
struct stat st;
|
|
||||||
char buf[512];
|
|
||||||
|
|
||||||
if(stat(device, &st) < 0) {
|
|
||||||
log_err(cd, _("Device %s doesn't exist or access denied.\n"), device);
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!S_ISBLK(st.st_mode))
|
|
||||||
return -ENOTBLK;
|
|
||||||
|
|
||||||
log_dbg("Trying to open and read device %s.", device);
|
|
||||||
devfd = open(device, mode | O_DIRECT | O_SYNC);
|
|
||||||
if(devfd < 0) {
|
|
||||||
log_err(cd, _("Cannot open device %s for %s%s access.\n"), device,
|
|
||||||
(mode & O_EXCL) ? _("exclusive ") : "",
|
|
||||||
(mode & O_RDWR) ? _("writable") : _("read-only"));
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Try to read first sector */
|
|
||||||
s = read_blockwise(devfd, buf, sizeof(buf));
|
|
||||||
if (s < 0 || s != sizeof(buf)) {
|
|
||||||
log_verbose(cd, _("Cannot read device %s.\n"), device);
|
|
||||||
r = -EIO;
|
|
||||||
}
|
|
||||||
|
|
||||||
memset(buf, 0, sizeof(buf));
|
|
||||||
close(devfd);
|
|
||||||
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
int device_size(const char *device, uint64_t *size)
|
|
||||||
{
|
|
||||||
int devfd, r = 0;
|
|
||||||
|
|
||||||
devfd = open(device, O_RDONLY);
|
|
||||||
if(devfd == -1)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
if (ioctl(devfd, BLKGETSIZE64, size) < 0)
|
|
||||||
r = -EINVAL;
|
|
||||||
|
|
||||||
close(devfd);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
static int get_device_infos(const char *device, enum devcheck device_check,
|
|
||||||
int *readonly, uint64_t *size)
|
|
||||||
{
|
|
||||||
struct stat st;
|
|
||||||
unsigned long size_small;
|
|
||||||
int fd, r = -1;
|
|
||||||
int flags = 0;
|
|
||||||
|
|
||||||
*readonly = 0;
|
|
||||||
*size = 0;
|
|
||||||
|
|
||||||
if (stat(device, &st) < 0)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
/* never wipe header on mounted device */
|
|
||||||
if (device_check == DEV_EXCL && S_ISBLK(st.st_mode))
|
|
||||||
flags |= O_EXCL;
|
|
||||||
|
|
||||||
/* Try to open read-write to check whether it is a read-only device */
|
|
||||||
fd = open(device, O_RDWR | flags);
|
|
||||||
if (fd == -1 && errno == EROFS) {
|
|
||||||
*readonly = 1;
|
|
||||||
fd = open(device, O_RDONLY | flags);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (fd == -1 && device_check == DEV_EXCL && errno == EBUSY)
|
|
||||||
return -EBUSY;
|
|
||||||
|
|
||||||
if (fd == -1)
|
|
||||||
return -EINVAL;
|
|
||||||
|
|
||||||
/* If the device can be opened read-write, i.e. readonly is still 0, then
|
|
||||||
* check whether BKROGET says that it is read-only. E.g. read-only loop
|
|
||||||
* devices may be openend read-write but are read-only according to BLKROGET
|
|
||||||
*/
|
|
||||||
if (*readonly == 0 && (r = ioctl(fd, BLKROGET, readonly)) < 0)
|
|
||||||
goto out;
|
|
||||||
|
|
||||||
if (ioctl(fd, BLKGETSIZE64, size) >= 0) {
|
|
||||||
*size >>= SECTOR_SHIFT;
|
|
||||||
r = 0;
|
|
||||||
goto out;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (ioctl(fd, BLKGETSIZE, &size_small) >= 0) {
|
|
||||||
*size = (uint64_t)size_small;
|
|
||||||
r = 0;
|
|
||||||
goto out;
|
|
||||||
}
|
|
||||||
|
|
||||||
r = -EINVAL;
|
|
||||||
out:
|
|
||||||
close(fd);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
int device_check_and_adjust(struct crypt_device *cd,
|
|
||||||
const char *device,
|
|
||||||
enum devcheck device_check,
|
|
||||||
uint64_t *size,
|
|
||||||
uint64_t *offset,
|
|
||||||
uint32_t *flags)
|
|
||||||
{
|
|
||||||
int r, real_readonly;
|
|
||||||
uint64_t real_size;
|
|
||||||
|
|
||||||
if (!device)
|
|
||||||
return -ENOTBLK;
|
|
||||||
|
|
||||||
r = get_device_infos(device, device_check, &real_readonly, &real_size);
|
|
||||||
if (r < 0) {
|
|
||||||
if (r == -EBUSY)
|
|
||||||
log_err(cd, _("Cannot use device %s which is in use "
|
|
||||||
"(already mapped or mounted).\n"),
|
|
||||||
device);
|
|
||||||
else
|
|
||||||
log_err(cd, _("Cannot get info about device %s.\n"),
|
|
||||||
device);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (*offset >= real_size) {
|
|
||||||
log_err(cd, _("Requested offset is beyond real size of device %s.\n"),
|
|
||||||
device);
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!*size) {
|
|
||||||
*size = real_size;
|
|
||||||
if (!*size) {
|
|
||||||
log_err(cd, _("Device %s has zero size.\n"), device);
|
|
||||||
return -ENOTBLK;
|
|
||||||
}
|
|
||||||
*size -= *offset;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* in case of size is set by parameter */
|
|
||||||
if ((real_size - *offset) < *size) {
|
|
||||||
log_dbg("Device %s: offset = %" PRIu64 " requested size = %" PRIu64
|
|
||||||
", backing device size = %" PRIu64,
|
|
||||||
device, *offset, *size, real_size);
|
|
||||||
log_err(cd, _("Device %s is too small.\n"), device);
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (device_check == DEV_SHARED) {
|
|
||||||
log_dbg("Checking crypt segments for device %s.", device);
|
|
||||||
r = crypt_sysfs_check_crypt_segment(device, *offset, *size);
|
|
||||||
if (r < 0) {
|
|
||||||
log_err(cd, _("Cannot use device %s (crypt segments "
|
|
||||||
"overlaps or in use by another device).\n"),
|
|
||||||
device);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (real_readonly)
|
|
||||||
*flags |= CRYPT_ACTIVATE_READONLY;
|
|
||||||
|
|
||||||
log_dbg("Calculated device size is %" PRIu64 " sectors (%s), offset %" PRIu64 ".",
|
|
||||||
*size, real_readonly ? "RO" : "RW", *offset);
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* MEMLOCK */
|
/* MEMLOCK */
|
||||||
#define DEFAULT_PROCESS_PRIORITY -18
|
#define DEFAULT_PROCESS_PRIORITY -18
|
||||||
|
|
||||||
@@ -447,7 +235,7 @@ int crypt_memlock_inc(struct crypt_device *ctx)
|
|||||||
if (!_memlock_count++) {
|
if (!_memlock_count++) {
|
||||||
log_dbg("Locking memory.");
|
log_dbg("Locking memory.");
|
||||||
if (mlockall(MCL_CURRENT | MCL_FUTURE) == -1) {
|
if (mlockall(MCL_CURRENT | MCL_FUTURE) == -1) {
|
||||||
log_err(ctx, _("WARNING!!! Possibly insecure memory. Are you root?\n"));
|
log_dbg("Cannot lock memory with mlockall.");
|
||||||
_memlock_count--;
|
_memlock_count--;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -456,7 +244,7 @@ int crypt_memlock_inc(struct crypt_device *ctx)
|
|||||||
log_err(ctx, _("Cannot get process priority.\n"));
|
log_err(ctx, _("Cannot get process priority.\n"));
|
||||||
else
|
else
|
||||||
if (setpriority(PRIO_PROCESS, 0, DEFAULT_PROCESS_PRIORITY))
|
if (setpriority(PRIO_PROCESS, 0, DEFAULT_PROCESS_PRIORITY))
|
||||||
log_err(ctx, _("setpriority %d failed: %s\n"),
|
log_dbg("setpriority %d failed: %s",
|
||||||
DEFAULT_PROCESS_PRIORITY, strerror(errno));
|
DEFAULT_PROCESS_PRIORITY, strerror(errno));
|
||||||
}
|
}
|
||||||
return _memlock_count ? 1 : 0;
|
return _memlock_count ? 1 : 0;
|
||||||
@@ -469,64 +257,7 @@ int crypt_memlock_dec(struct crypt_device *ctx)
|
|||||||
if (munlockall() == -1)
|
if (munlockall() == -1)
|
||||||
log_err(ctx, _("Cannot unlock memory.\n"));
|
log_err(ctx, _("Cannot unlock memory.\n"));
|
||||||
if (setpriority(PRIO_PROCESS, 0, _priority))
|
if (setpriority(PRIO_PROCESS, 0, _priority))
|
||||||
log_err(ctx, _("setpriority %d failed: %s\n"), _priority, strerror(errno));
|
log_dbg("setpriority %d failed: %s", _priority, strerror(errno));
|
||||||
}
|
}
|
||||||
return _memlock_count ? 1 : 0;
|
return _memlock_count ? 1 : 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* DEVICE TOPOLOGY */
|
|
||||||
|
|
||||||
/* block device topology ioctls, introduced in 2.6.32 */
|
|
||||||
#ifndef BLKIOMIN
|
|
||||||
#define BLKIOMIN _IO(0x12,120)
|
|
||||||
#define BLKIOOPT _IO(0x12,121)
|
|
||||||
#define BLKALIGNOFF _IO(0x12,122)
|
|
||||||
#endif
|
|
||||||
|
|
||||||
void get_topology_alignment(const char *device,
|
|
||||||
unsigned long *required_alignment, /* bytes */
|
|
||||||
unsigned long *alignment_offset, /* bytes */
|
|
||||||
unsigned long default_alignment)
|
|
||||||
{
|
|
||||||
int dev_alignment_offset = 0;
|
|
||||||
unsigned int min_io_size = 0, opt_io_size = 0;
|
|
||||||
unsigned long temp_alignment = 0;
|
|
||||||
int fd;
|
|
||||||
|
|
||||||
*required_alignment = default_alignment;
|
|
||||||
*alignment_offset = 0;
|
|
||||||
|
|
||||||
fd = open(device, O_RDONLY);
|
|
||||||
if (fd == -1)
|
|
||||||
return;
|
|
||||||
|
|
||||||
/* minimum io size */
|
|
||||||
if (ioctl(fd, BLKIOMIN, &min_io_size) == -1) {
|
|
||||||
log_dbg("Topology info for %s not supported, using default offset %lu bytes.",
|
|
||||||
device, default_alignment);
|
|
||||||
goto out;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* optimal io size */
|
|
||||||
if (ioctl(fd, BLKIOOPT, &opt_io_size) == -1)
|
|
||||||
opt_io_size = min_io_size;
|
|
||||||
|
|
||||||
/* alignment offset, bogus -1 means misaligned/unknown */
|
|
||||||
if (ioctl(fd, BLKALIGNOFF, &dev_alignment_offset) == -1 || dev_alignment_offset < 0)
|
|
||||||
dev_alignment_offset = 0;
|
|
||||||
*alignment_offset = (unsigned long)dev_alignment_offset;
|
|
||||||
|
|
||||||
temp_alignment = (unsigned long)min_io_size;
|
|
||||||
|
|
||||||
if (temp_alignment < (unsigned long)opt_io_size)
|
|
||||||
temp_alignment = (unsigned long)opt_io_size;
|
|
||||||
|
|
||||||
/* If calculated alignment is multiple of default, keep default */
|
|
||||||
if (temp_alignment && (default_alignment % temp_alignment))
|
|
||||||
*required_alignment = temp_alignment;
|
|
||||||
|
|
||||||
log_dbg("Topology: IO (%u/%u), offset = %lu; Required alignment is %lu bytes.",
|
|
||||||
min_io_size, opt_io_size, *alignment_offset, *required_alignment);
|
|
||||||
out:
|
|
||||||
(void)close(fd);
|
|
||||||
}
|
|
||||||
|
|||||||
269
lib/utils_benchmark.c
Normal file
269
lib/utils_benchmark.c
Normal file
@@ -0,0 +1,269 @@
|
|||||||
|
/*
|
||||||
|
* libcryptsetup - cryptsetup library, cipher bechmark
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2012-2013, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include <time.h>
|
||||||
|
|
||||||
|
#include "internal.h"
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This is not simulating storage, so using disk block causes extreme overhead.
|
||||||
|
* Let's use some fixed block size where results are more reliable...
|
||||||
|
*/
|
||||||
|
#define CIPHER_BLOCK_BYTES 65536
|
||||||
|
|
||||||
|
/*
|
||||||
|
* If the measured value is lower, encrypted buffer is probably too small
|
||||||
|
* and calculated values are not reliable.
|
||||||
|
*/
|
||||||
|
#define CIPHER_TIME_MIN_MS 0.001
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The whole test depends on Linux kernel usermode crypto API for now.
|
||||||
|
* (The same implementations are used in dm-crypt though.)
|
||||||
|
*/
|
||||||
|
|
||||||
|
struct cipher_perf {
|
||||||
|
char name[32];
|
||||||
|
char mode[32];
|
||||||
|
char *key;
|
||||||
|
size_t key_length;
|
||||||
|
char *iv;
|
||||||
|
size_t iv_length;
|
||||||
|
size_t buffer_size;
|
||||||
|
};
|
||||||
|
|
||||||
|
static int time_ms(struct timespec *start, struct timespec *end, double *ms)
|
||||||
|
{
|
||||||
|
double start_ms, end_ms;
|
||||||
|
|
||||||
|
start_ms = start->tv_sec * 1000.0 + start->tv_nsec / (1000.0 * 1000);
|
||||||
|
end_ms = end->tv_sec * 1000.0 + end->tv_nsec / (1000.0 * 1000);
|
||||||
|
|
||||||
|
*ms = end_ms - start_ms;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int cipher_perf_one(struct cipher_perf *cp, char *buf,
|
||||||
|
size_t buf_size, int enc)
|
||||||
|
{
|
||||||
|
struct crypt_cipher *cipher = NULL;
|
||||||
|
size_t done = 0, block = CIPHER_BLOCK_BYTES;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (buf_size < block)
|
||||||
|
block = buf_size;
|
||||||
|
|
||||||
|
r = crypt_cipher_init(&cipher, cp->name, cp->mode, cp->key, cp->key_length);
|
||||||
|
if (r < 0) {
|
||||||
|
log_dbg("Cannot initialise cipher %s, mode %s.", cp->name, cp->mode);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
while (done < buf_size) {
|
||||||
|
if ((done + block) > buf_size)
|
||||||
|
block = buf_size - done;
|
||||||
|
|
||||||
|
if (enc)
|
||||||
|
r = crypt_cipher_encrypt(cipher, &buf[done], &buf[done],
|
||||||
|
block, cp->iv, cp->iv_length);
|
||||||
|
else
|
||||||
|
r = crypt_cipher_decrypt(cipher, &buf[done], &buf[done],
|
||||||
|
block, cp->iv, cp->iv_length);
|
||||||
|
if (r < 0)
|
||||||
|
break;
|
||||||
|
|
||||||
|
done += block;
|
||||||
|
}
|
||||||
|
|
||||||
|
crypt_cipher_destroy(cipher);
|
||||||
|
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
static int cipher_measure(struct cipher_perf *cp, char *buf,
|
||||||
|
size_t buf_size, int encrypt, double *ms)
|
||||||
|
{
|
||||||
|
struct timespec start, end;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Using getrusage would be better here but the precision
|
||||||
|
* is not adequate, so better stick with CLOCK_MONOTONIC
|
||||||
|
*/
|
||||||
|
if (clock_gettime(CLOCK_MONOTONIC, &start) < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = cipher_perf_one(cp, buf, buf_size, encrypt);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
if (clock_gettime(CLOCK_MONOTONIC, &end) < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = time_ms(&start, &end, ms);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
if (*ms < CIPHER_TIME_MIN_MS) {
|
||||||
|
log_dbg("Measured cipher runtime (%1.6f) is too low.", *ms);
|
||||||
|
return -ERANGE;
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static double speed_mbs(unsigned long bytes, double ms)
|
||||||
|
{
|
||||||
|
double speed = bytes, s = ms / 1000.;
|
||||||
|
|
||||||
|
return speed / (1024 * 1024) / s;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int cipher_perf(struct cipher_perf *cp,
|
||||||
|
double *encryption_mbs, double *decryption_mbs)
|
||||||
|
{
|
||||||
|
double ms_enc, ms_dec, ms;
|
||||||
|
int r, repeat_enc, repeat_dec;
|
||||||
|
void *buf = NULL;
|
||||||
|
|
||||||
|
if (posix_memalign(&buf, crypt_getpagesize(), cp->buffer_size))
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
ms_enc = 0.0;
|
||||||
|
repeat_enc = 1;
|
||||||
|
while (ms_enc < 1000.0) {
|
||||||
|
r = cipher_measure(cp, buf, cp->buffer_size, 1, &ms);
|
||||||
|
if (r < 0) {
|
||||||
|
free(buf);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
ms_enc += ms;
|
||||||
|
repeat_enc++;
|
||||||
|
}
|
||||||
|
|
||||||
|
ms_dec = 0.0;
|
||||||
|
repeat_dec = 1;
|
||||||
|
while (ms_dec < 1000.0) {
|
||||||
|
r = cipher_measure(cp, buf, cp->buffer_size, 0, &ms);
|
||||||
|
if (r < 0) {
|
||||||
|
free(buf);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
ms_dec += ms;
|
||||||
|
repeat_dec++;
|
||||||
|
}
|
||||||
|
|
||||||
|
free(buf);
|
||||||
|
|
||||||
|
*encryption_mbs = speed_mbs(cp->buffer_size * repeat_enc, ms_enc);
|
||||||
|
*decryption_mbs = speed_mbs(cp->buffer_size * repeat_dec, ms_dec);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_benchmark(struct crypt_device *cd,
|
||||||
|
const char *cipher,
|
||||||
|
const char *cipher_mode,
|
||||||
|
size_t volume_key_size,
|
||||||
|
size_t iv_size,
|
||||||
|
size_t buffer_size,
|
||||||
|
double *encryption_mbs,
|
||||||
|
double *decryption_mbs)
|
||||||
|
{
|
||||||
|
struct cipher_perf cp = {
|
||||||
|
.key_length = volume_key_size,
|
||||||
|
.iv_length = iv_size,
|
||||||
|
.buffer_size = buffer_size,
|
||||||
|
};
|
||||||
|
char *c;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (!cipher || !cipher_mode || !volume_key_size)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = init_crypto(cd);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = -ENOMEM;
|
||||||
|
if (iv_size) {
|
||||||
|
cp.iv = malloc(iv_size);
|
||||||
|
if (!cp.iv)
|
||||||
|
goto out;
|
||||||
|
crypt_random_get(cd, cp.iv, iv_size, CRYPT_RND_NORMAL);
|
||||||
|
}
|
||||||
|
|
||||||
|
cp.key = malloc(volume_key_size);
|
||||||
|
if (!cp.key)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
crypt_random_get(cd, cp.key, volume_key_size, CRYPT_RND_NORMAL);
|
||||||
|
strncpy(cp.name, cipher, sizeof(cp.name)-1);
|
||||||
|
strncpy(cp.mode, cipher_mode, sizeof(cp.mode)-1);
|
||||||
|
|
||||||
|
/* Ignore IV generator */
|
||||||
|
if ((c = strchr(cp.mode, '-')))
|
||||||
|
*c = '\0';
|
||||||
|
|
||||||
|
r = cipher_perf(&cp, encryption_mbs, decryption_mbs);
|
||||||
|
out:
|
||||||
|
free(cp.key);
|
||||||
|
free(cp.iv);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_benchmark_kdf(struct crypt_device *cd,
|
||||||
|
const char *kdf,
|
||||||
|
const char *hash,
|
||||||
|
const char *password,
|
||||||
|
size_t password_size,
|
||||||
|
const char *salt,
|
||||||
|
size_t salt_size,
|
||||||
|
uint64_t *iterations_sec)
|
||||||
|
{
|
||||||
|
int r, key_length = 0;
|
||||||
|
|
||||||
|
if (!iterations_sec)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = init_crypto(cd);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
// FIXME: this should be in KDF check API parameters later
|
||||||
|
if (cd)
|
||||||
|
key_length = crypt_get_volume_key_size(cd);
|
||||||
|
|
||||||
|
if (key_length == 0)
|
||||||
|
key_length = DEFAULT_LUKS1_KEYBITS / 8;
|
||||||
|
|
||||||
|
if (!strncmp(kdf, "pbkdf2", 6))
|
||||||
|
r = crypt_pbkdf_check(kdf, hash, password, password_size,
|
||||||
|
salt, salt_size, key_length, iterations_sec);
|
||||||
|
else
|
||||||
|
r = -EINVAL;
|
||||||
|
|
||||||
|
if (!r)
|
||||||
|
log_dbg("KDF %s, hash %s: %" PRIu64 " iterations per second (%d-bits key).",
|
||||||
|
kdf, hash, *iterations_sec, key_length * 8);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
@@ -1,12 +1,14 @@
|
|||||||
/*
|
/*
|
||||||
* util_crypt - cipher utilities for cryptsetup
|
* utils_crypt - cipher utilities for cryptsetup
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2012, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -15,7 +17,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -23,6 +25,8 @@
|
|||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
|
#include <ctype.h>
|
||||||
|
#include <limits.h>
|
||||||
#include <sys/types.h>
|
#include <sys/types.h>
|
||||||
#include <sys/stat.h>
|
#include <sys/stat.h>
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
@@ -58,6 +62,15 @@ int crypt_parse_name_and_mode(const char *s, char *cipher, int *key_nums,
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Short version for "empty" cipher */
|
||||||
|
if (!strcmp(s, "null")) {
|
||||||
|
strncpy(cipher, "cipher_null", MAX_CIPHER_LEN);
|
||||||
|
strncpy(cipher_mode, "ecb", 9);
|
||||||
|
if (key_nums)
|
||||||
|
*key_nums = 0;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
if (sscanf(s, "%" MAX_CIPHER_LEN_STR "[^-]", cipher) == 1) {
|
if (sscanf(s, "%" MAX_CIPHER_LEN_STR "[^-]", cipher) == 1) {
|
||||||
strncpy(cipher_mode, "cbc-plain", 10);
|
strncpy(cipher_mode, "cbc-plain", 10);
|
||||||
if (key_nums)
|
if (key_nums)
|
||||||
@@ -68,6 +81,18 @@ int crypt_parse_name_and_mode(const char *s, char *cipher, int *key_nums,
|
|||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Replacement for memset(s, 0, n) on stack that can be optimized out
|
||||||
|
* Also used in safe allocations for explicit memory wipe.
|
||||||
|
*/
|
||||||
|
void crypt_memzero(void *s, size_t n)
|
||||||
|
{
|
||||||
|
volatile uint8_t *p = (volatile uint8_t *)s;
|
||||||
|
|
||||||
|
while(n--)
|
||||||
|
*p++ = 0;
|
||||||
|
}
|
||||||
|
|
||||||
/* safe allocations */
|
/* safe allocations */
|
||||||
void *crypt_safe_alloc(size_t size)
|
void *crypt_safe_alloc(size_t size)
|
||||||
{
|
{
|
||||||
@@ -81,7 +106,9 @@ void *crypt_safe_alloc(size_t size)
|
|||||||
return NULL;
|
return NULL;
|
||||||
|
|
||||||
alloc->size = size;
|
alloc->size = size;
|
||||||
|
crypt_memzero(&alloc->data, size);
|
||||||
|
|
||||||
|
/* coverity[leaked_storage] */
|
||||||
return &alloc->data;
|
return &alloc->data;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -95,7 +122,7 @@ void crypt_safe_free(void *data)
|
|||||||
alloc = (struct safe_allocation *)
|
alloc = (struct safe_allocation *)
|
||||||
((char *)data - offsetof(struct safe_allocation, data));
|
((char *)data - offsetof(struct safe_allocation, data));
|
||||||
|
|
||||||
memset(data, 0, alloc->size);
|
crypt_memzero(data, alloc->size);
|
||||||
|
|
||||||
alloc->size = 0x55aa55aa;
|
alloc->size = 0x55aa55aa;
|
||||||
free(alloc);
|
free(alloc);
|
||||||
@@ -142,7 +169,7 @@ static int untimed_read(int fd, char *pass, size_t maxlen)
|
|||||||
static int timed_read(int fd, char *pass, size_t maxlen, long timeout)
|
static int timed_read(int fd, char *pass, size_t maxlen, long timeout)
|
||||||
{
|
{
|
||||||
struct timeval t;
|
struct timeval t;
|
||||||
fd_set fds;
|
fd_set fds = {}; /* Just to avoid scan-build false report for FD_SET */
|
||||||
int failed = -1;
|
int failed = -1;
|
||||||
|
|
||||||
FD_ZERO(&fds);
|
FD_ZERO(&fds);
|
||||||
@@ -161,16 +188,18 @@ static int interactive_pass(const char *prompt, char *pass, size_t maxlen,
|
|||||||
{
|
{
|
||||||
struct termios orig, tmp;
|
struct termios orig, tmp;
|
||||||
int failed = -1;
|
int failed = -1;
|
||||||
int infd = STDIN_FILENO, outfd;
|
int infd, outfd;
|
||||||
|
|
||||||
if (maxlen < 1)
|
if (maxlen < 1)
|
||||||
goto out_err;
|
return failed;
|
||||||
|
|
||||||
/* Read and write to /dev/tty if available */
|
/* Read and write to /dev/tty if available */
|
||||||
if ((infd = outfd = open("/dev/tty", O_RDWR)) == -1) {
|
infd = open("/dev/tty", O_RDWR);
|
||||||
|
if (infd == -1) {
|
||||||
infd = STDIN_FILENO;
|
infd = STDIN_FILENO;
|
||||||
outfd = STDERR_FILENO;
|
outfd = STDERR_FILENO;
|
||||||
}
|
} else
|
||||||
|
outfd = infd;
|
||||||
|
|
||||||
if (tcgetattr(infd, &orig))
|
if (tcgetattr(infd, &orig))
|
||||||
goto out_err;
|
goto out_err;
|
||||||
@@ -250,6 +279,49 @@ out_err:
|
|||||||
return r;
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* A simple call to lseek(3) might not be possible for some inputs (e.g.
|
||||||
|
* reading from a pipe), so this function instead reads of up to BUFSIZ bytes
|
||||||
|
* at a time until the specified number of bytes. It returns -1 on read error
|
||||||
|
* or when it reaches EOF before the requested number of bytes have been
|
||||||
|
* discarded.
|
||||||
|
*/
|
||||||
|
static int keyfile_seek(int fd, size_t bytes)
|
||||||
|
{
|
||||||
|
char tmp[BUFSIZ];
|
||||||
|
size_t next_read;
|
||||||
|
ssize_t bytes_r;
|
||||||
|
off_t r;
|
||||||
|
|
||||||
|
r = lseek(fd, bytes, SEEK_CUR);
|
||||||
|
if (r > 0)
|
||||||
|
return 0;
|
||||||
|
if (r < 0 && errno != ESPIPE)
|
||||||
|
return -1;
|
||||||
|
|
||||||
|
while (bytes > 0) {
|
||||||
|
/* figure out how much to read */
|
||||||
|
next_read = bytes > sizeof(tmp) ? sizeof(tmp) : bytes;
|
||||||
|
|
||||||
|
bytes_r = read(fd, tmp, next_read);
|
||||||
|
if (bytes_r < 0) {
|
||||||
|
if (errno == EINTR)
|
||||||
|
continue;
|
||||||
|
|
||||||
|
/* read error */
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (bytes_r == 0)
|
||||||
|
/* EOF */
|
||||||
|
break;
|
||||||
|
|
||||||
|
bytes -= bytes_r;
|
||||||
|
}
|
||||||
|
|
||||||
|
return bytes == 0 ? 0 : -1;
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Note: --key-file=- is interpreted as a read from a binary file (stdin)
|
* Note: --key-file=- is interpreted as a read from a binary file (stdin)
|
||||||
* key_size_max == 0 means detect maximum according to input type (tty/file)
|
* key_size_max == 0 means detect maximum according to input type (tty/file)
|
||||||
@@ -257,14 +329,14 @@ out_err:
|
|||||||
*/
|
*/
|
||||||
int crypt_get_key(const char *prompt,
|
int crypt_get_key(const char *prompt,
|
||||||
char **key, size_t *key_size,
|
char **key, size_t *key_size,
|
||||||
size_t keyfile_size_max, const char *key_file,
|
size_t keyfile_offset, size_t keyfile_size_max,
|
||||||
int timeout, int verify,
|
const char *key_file, int timeout, int verify,
|
||||||
struct crypt_device *cd)
|
struct crypt_device *cd)
|
||||||
{
|
{
|
||||||
int fd, regular_file, read_stdin, char_read, unlimited_read = 0;
|
int fd, regular_file, read_stdin, char_read, unlimited_read = 0;
|
||||||
int r = -EINVAL;
|
int r = -EINVAL, newline;
|
||||||
char *pass = NULL;
|
char *pass = NULL;
|
||||||
size_t buflen, i;
|
size_t buflen, i, file_read_size;
|
||||||
struct stat st;
|
struct stat st;
|
||||||
|
|
||||||
*key = NULL;
|
*key = NULL;
|
||||||
@@ -273,8 +345,13 @@ int crypt_get_key(const char *prompt,
|
|||||||
/* Passphrase read from stdin? */
|
/* Passphrase read from stdin? */
|
||||||
read_stdin = (!key_file || !strcmp(key_file, "-")) ? 1 : 0;
|
read_stdin = (!key_file || !strcmp(key_file, "-")) ? 1 : 0;
|
||||||
|
|
||||||
if(read_stdin && isatty(STDIN_FILENO))
|
if (read_stdin && isatty(STDIN_FILENO)) {
|
||||||
|
if (keyfile_offset) {
|
||||||
|
log_err(cd, _("Cannot use offset with terminal input.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
return crypt_get_key_tty(prompt, key, key_size, timeout, verify, cd);
|
return crypt_get_key_tty(prompt, key, key_size, timeout, verify, cd);
|
||||||
|
}
|
||||||
|
|
||||||
if (read_stdin)
|
if (read_stdin)
|
||||||
log_dbg("STDIN descriptor passphrase entry requested.");
|
log_dbg("STDIN descriptor passphrase entry requested.");
|
||||||
@@ -283,7 +360,7 @@ int crypt_get_key(const char *prompt,
|
|||||||
|
|
||||||
/* If not requsted otherwise, we limit input to prevent memory exhaustion */
|
/* If not requsted otherwise, we limit input to prevent memory exhaustion */
|
||||||
if (keyfile_size_max == 0) {
|
if (keyfile_size_max == 0) {
|
||||||
keyfile_size_max = DEFAULT_KEYFILE_SIZE_MAXKB * 1024;
|
keyfile_size_max = DEFAULT_KEYFILE_SIZE_MAXKB * 1024 + 1;
|
||||||
unlimited_read = 1;
|
unlimited_read = 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -303,11 +380,19 @@ int crypt_get_key(const char *prompt,
|
|||||||
}
|
}
|
||||||
if(S_ISREG(st.st_mode)) {
|
if(S_ISREG(st.st_mode)) {
|
||||||
regular_file = 1;
|
regular_file = 1;
|
||||||
|
file_read_size = (size_t)st.st_size;
|
||||||
|
|
||||||
|
if (keyfile_offset > file_read_size) {
|
||||||
|
log_err(cd, _("Cannot seek to requested keyfile offset.\n"));
|
||||||
|
goto out_err;
|
||||||
|
}
|
||||||
|
file_read_size -= keyfile_offset;
|
||||||
|
|
||||||
/* known keyfile size, alloc it in one step */
|
/* known keyfile size, alloc it in one step */
|
||||||
if ((size_t)st.st_size >= keyfile_size_max)
|
if (file_read_size >= keyfile_size_max)
|
||||||
buflen = keyfile_size_max;
|
buflen = keyfile_size_max;
|
||||||
else
|
else if (file_read_size)
|
||||||
buflen = st.st_size;
|
buflen = file_read_size;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -317,7 +402,13 @@ int crypt_get_key(const char *prompt,
|
|||||||
goto out_err;
|
goto out_err;
|
||||||
}
|
}
|
||||||
|
|
||||||
for(i = 0; i < keyfile_size_max; i++) {
|
/* Discard keyfile_offset bytes on input */
|
||||||
|
if (keyfile_offset && keyfile_seek(fd, keyfile_offset) < 0) {
|
||||||
|
log_err(cd, _("Cannot seek to requested keyfile offset.\n"));
|
||||||
|
goto out_err;
|
||||||
|
}
|
||||||
|
|
||||||
|
for(i = 0, newline = 0; i < keyfile_size_max; i++) {
|
||||||
if(i == buflen) {
|
if(i == buflen) {
|
||||||
buflen += 4096;
|
buflen += 4096;
|
||||||
pass = crypt_safe_realloc(pass, buflen);
|
pass = crypt_safe_realloc(pass, buflen);
|
||||||
@@ -335,12 +426,17 @@ int crypt_get_key(const char *prompt,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* Stop on newline only if not requested read from keyfile */
|
/* Stop on newline only if not requested read from keyfile */
|
||||||
if(char_read == 0 || (!key_file && pass[i] == '\n'))
|
if (char_read == 0)
|
||||||
break;
|
break;
|
||||||
|
if (!key_file && pass[i] == '\n') {
|
||||||
|
newline = 1;
|
||||||
|
pass[i] = '\0';
|
||||||
|
break;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Fail if piped input dies reading nothing */
|
/* Fail if piped input dies reading nothing */
|
||||||
if(!i && !regular_file) {
|
if(!i && !regular_file && !newline) {
|
||||||
log_dbg("Nothing read on input.");
|
log_dbg("Nothing read on input.");
|
||||||
r = -EPIPE;
|
r = -EPIPE;
|
||||||
goto out_err;
|
goto out_err;
|
||||||
@@ -348,7 +444,7 @@ int crypt_get_key(const char *prompt,
|
|||||||
|
|
||||||
/* Fail if we exceeded internal default (no specified size) */
|
/* Fail if we exceeded internal default (no specified size) */
|
||||||
if (unlimited_read && i == keyfile_size_max) {
|
if (unlimited_read && i == keyfile_size_max) {
|
||||||
log_err(cd, _("Maximum keyfile size exceeeded.\n"));
|
log_err(cd, _("Maximum keyfile size exceeded.\n"));
|
||||||
goto out_err;
|
goto out_err;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -357,12 +453,6 @@ int crypt_get_key(const char *prompt,
|
|||||||
goto out_err;
|
goto out_err;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Well, for historical reasons reading empty keyfile is not fail. */
|
|
||||||
if(!i) {
|
|
||||||
crypt_safe_free(pass);
|
|
||||||
pass = NULL;
|
|
||||||
}
|
|
||||||
|
|
||||||
*key = pass;
|
*key = pass;
|
||||||
*key_size = i;
|
*key_size = i;
|
||||||
r = 0;
|
r = 0;
|
||||||
@@ -374,3 +464,29 @@ out_err:
|
|||||||
crypt_safe_free(pass);
|
crypt_safe_free(pass);
|
||||||
return r;
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
ssize_t crypt_hex_to_bytes(const char *hex, char **result, int safe_alloc)
|
||||||
|
{
|
||||||
|
char buf[3] = "xx\0", *endp, *bytes;
|
||||||
|
size_t i, len;
|
||||||
|
|
||||||
|
len = strlen(hex);
|
||||||
|
if (len % 2)
|
||||||
|
return -EINVAL;
|
||||||
|
len /= 2;
|
||||||
|
|
||||||
|
bytes = safe_alloc ? crypt_safe_alloc(len) : malloc(len);
|
||||||
|
if (!bytes)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
for (i = 0; i < len; i++) {
|
||||||
|
memcpy(buf, &hex[i * 2], 2);
|
||||||
|
bytes[i] = strtoul(buf, &endp, 16);
|
||||||
|
if (endp != &buf[2]) {
|
||||||
|
safe_alloc ? crypt_safe_free(bytes) : free(bytes);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
*result = bytes;
|
||||||
|
return i;
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,11 +1,33 @@
|
|||||||
|
/*
|
||||||
|
* utils_crypt - cipher utilities for cryptsetup
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2012, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef _UTILS_CRYPT_H
|
#ifndef _UTILS_CRYPT_H
|
||||||
#define _UTILS_CRYPT_H
|
#define _UTILS_CRYPT_H
|
||||||
|
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
#include "config.h"
|
|
||||||
|
|
||||||
#define MAX_CIPHER_LEN 32
|
#define MAX_CIPHER_LEN 32
|
||||||
#define MAX_CIPHER_LEN_STR "32"
|
#define MAX_CIPHER_LEN_STR "31"
|
||||||
|
#define MAX_KEYFILES 32
|
||||||
|
|
||||||
struct crypt_device;
|
struct crypt_device;
|
||||||
|
|
||||||
@@ -14,7 +36,7 @@ int crypt_parse_name_and_mode(const char *s, char *cipher,
|
|||||||
|
|
||||||
int crypt_get_key(const char *prompt,
|
int crypt_get_key(const char *prompt,
|
||||||
char **key, size_t *key_size,
|
char **key, size_t *key_size,
|
||||||
size_t keyfile_size_max,
|
size_t keyfile_offset, size_t keyfile_size_max,
|
||||||
const char *key_file,
|
const char *key_file,
|
||||||
int timeout, int verify,
|
int timeout, int verify,
|
||||||
struct crypt_device *cd);
|
struct crypt_device *cd);
|
||||||
@@ -23,4 +45,8 @@ void *crypt_safe_alloc(size_t size);
|
|||||||
void crypt_safe_free(void *data);
|
void crypt_safe_free(void *data);
|
||||||
void *crypt_safe_realloc(void *data, size_t size);
|
void *crypt_safe_realloc(void *data, size_t size);
|
||||||
|
|
||||||
|
void crypt_memzero(void *s, size_t n);
|
||||||
|
|
||||||
|
ssize_t crypt_hex_to_bytes(const char *hex, char **result, int safe_alloc);
|
||||||
|
|
||||||
#endif /* _UTILS_CRYPT_H */
|
#endif /* _UTILS_CRYPT_H */
|
||||||
|
|||||||
@@ -1,146 +0,0 @@
|
|||||||
/*
|
|
||||||
* Temporary debug code to find processes locking internal cryptsetup devices.
|
|
||||||
* This code is intended to run only in debug mode.
|
|
||||||
*
|
|
||||||
* inspired by psmisc/fuser proc scanning code
|
|
||||||
*
|
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
|
||||||
*
|
|
||||||
* This program is free software; you can redistribute it and/or
|
|
||||||
* modify it under the terms of the GNU General Public License
|
|
||||||
* version 2 as published by the Free Software Foundation.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful,
|
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
* GNU General Public License for more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License
|
|
||||||
* along with this program; if not, write to the Free Software
|
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <stdint.h>
|
|
||||||
#include <stdio.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
#include <errno.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <sys/stat.h>
|
|
||||||
#include <dirent.h>
|
|
||||||
#include <fcntl.h>
|
|
||||||
#include <unistd.h>
|
|
||||||
#include <string.h>
|
|
||||||
#include "libcryptsetup.h"
|
|
||||||
#include "internal.h"
|
|
||||||
|
|
||||||
#define MAX_PATHNAME 1024
|
|
||||||
#define MAX_SHORTNAME 64
|
|
||||||
|
|
||||||
static int numeric_name(const char *name)
|
|
||||||
{
|
|
||||||
return (name[0] < '0' || name[0] > '9') ? 0 : 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
static int check_pid(const pid_t pid, const char *dev_name, const char *short_dev_name)
|
|
||||||
{
|
|
||||||
char dirpath[MAX_SHORTNAME], fdpath[MAX_SHORTNAME], linkpath[MAX_PATHNAME];
|
|
||||||
DIR *dirp;
|
|
||||||
struct dirent *direntry;
|
|
||||||
ssize_t len;
|
|
||||||
int r = 0;
|
|
||||||
|
|
||||||
snprintf(dirpath, sizeof(dirpath), "/proc/%d/fd", pid);
|
|
||||||
|
|
||||||
if (!(dirp = opendir(dirpath)))
|
|
||||||
return r;
|
|
||||||
|
|
||||||
while ((direntry = readdir(dirp))) {
|
|
||||||
if (!numeric_name(direntry->d_name))
|
|
||||||
continue;
|
|
||||||
|
|
||||||
snprintf(fdpath, sizeof(fdpath), "/proc/%d/fd/%s", pid, direntry->d_name);
|
|
||||||
|
|
||||||
if ((len = readlink(fdpath, linkpath, MAX_PATHNAME-1)) < 0)
|
|
||||||
break;
|
|
||||||
linkpath[len] = '\0';
|
|
||||||
|
|
||||||
if (!strcmp(dev_name, linkpath)) {
|
|
||||||
r = 1;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!strcmp(short_dev_name, linkpath)) {
|
|
||||||
r = 2;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
closedir(dirp);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
static int read_proc_info(const pid_t pid, pid_t *ppid, char *name, int max_size)
|
|
||||||
{
|
|
||||||
char path[MAX_SHORTNAME], info[max_size], c;
|
|
||||||
int fd, xpid, r = 0;
|
|
||||||
|
|
||||||
snprintf(path, sizeof(path), "/proc/%u/stat", pid);
|
|
||||||
if ((fd = open(path, O_RDONLY)) < 0)
|
|
||||||
return 0;
|
|
||||||
|
|
||||||
if (read(fd, info, max_size) > 0 &&
|
|
||||||
sscanf(info, "%d %s %c %d", &xpid, name, &c, ppid) == 4)
|
|
||||||
r = 1;
|
|
||||||
|
|
||||||
if (!r) {
|
|
||||||
*ppid = 0;
|
|
||||||
name[0] = '\0';
|
|
||||||
}
|
|
||||||
close(fd);
|
|
||||||
return r;
|
|
||||||
}
|
|
||||||
|
|
||||||
static void report_proc(const pid_t pid, const char *dev_name)
|
|
||||||
{
|
|
||||||
char name[MAX_PATHNAME], name2[MAX_PATHNAME];
|
|
||||||
pid_t ppid, ppid2;
|
|
||||||
|
|
||||||
if (read_proc_info(pid, &ppid, name, MAX_PATHNAME) &&
|
|
||||||
read_proc_info(ppid, &ppid2, name2, MAX_PATHNAME))
|
|
||||||
log_dbg("WARNING: Process PID %u %s [PPID %u %s] spying on internal device %s.",
|
|
||||||
pid, name, ppid, name2, dev_name);
|
|
||||||
}
|
|
||||||
|
|
||||||
void debug_processes_using_device(const char *dm_name)
|
|
||||||
{
|
|
||||||
char short_dev_name[MAX_SHORTNAME], dev_name[MAX_PATHNAME];
|
|
||||||
DIR *proc_dir;
|
|
||||||
struct dirent *proc_dentry;
|
|
||||||
struct stat st;
|
|
||||||
pid_t pid;
|
|
||||||
|
|
||||||
if (crypt_get_debug_level() != CRYPT_LOG_DEBUG)
|
|
||||||
return;
|
|
||||||
|
|
||||||
snprintf(dev_name, sizeof(dev_name), "/dev/mapper/%s", dm_name);
|
|
||||||
if (stat(dev_name, &st) || !S_ISBLK(st.st_mode))
|
|
||||||
return;
|
|
||||||
snprintf(short_dev_name, sizeof(short_dev_name), "/dev/dm-%u", minor(st.st_rdev));
|
|
||||||
|
|
||||||
if (!(proc_dir = opendir("/proc")))
|
|
||||||
return;
|
|
||||||
|
|
||||||
while ((proc_dentry = readdir(proc_dir))) {
|
|
||||||
if (!numeric_name(proc_dentry->d_name))
|
|
||||||
continue;
|
|
||||||
|
|
||||||
pid = atoi(proc_dentry->d_name);
|
|
||||||
switch(check_pid(pid, dev_name, short_dev_name)) {
|
|
||||||
case 1: report_proc(pid, dev_name);
|
|
||||||
break;
|
|
||||||
case 2: report_proc(pid, short_dev_name);
|
|
||||||
default:
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
closedir(proc_dir);
|
|
||||||
}
|
|
||||||
537
lib/utils_device.c
Normal file
537
lib/utils_device.c
Normal file
@@ -0,0 +1,537 @@
|
|||||||
|
/*
|
||||||
|
* device backend utilities
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2015, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2015, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <fcntl.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include <sys/types.h>
|
||||||
|
#include <sys/stat.h>
|
||||||
|
#include <sys/ioctl.h>
|
||||||
|
#include <linux/fs.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
#include "internal.h"
|
||||||
|
|
||||||
|
struct device {
|
||||||
|
char *path;
|
||||||
|
|
||||||
|
char *file_path;
|
||||||
|
int loop_fd;
|
||||||
|
|
||||||
|
int o_direct:1;
|
||||||
|
int init_done:1;
|
||||||
|
};
|
||||||
|
|
||||||
|
static int device_block_size_fd(int fd, size_t *min_size)
|
||||||
|
{
|
||||||
|
struct stat st;
|
||||||
|
int bsize = 0, r = -EINVAL;
|
||||||
|
|
||||||
|
if (fstat(fd, &st) < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (S_ISREG(st.st_mode)) {
|
||||||
|
r = (int)crypt_getpagesize();
|
||||||
|
bsize = r;
|
||||||
|
}
|
||||||
|
else if (ioctl(fd, BLKSSZGET, &bsize) >= 0)
|
||||||
|
r = bsize;
|
||||||
|
else
|
||||||
|
r = -EINVAL;
|
||||||
|
|
||||||
|
if (r < 0 || !min_size)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
if (S_ISREG(st.st_mode)) {
|
||||||
|
/* file can be empty as well */
|
||||||
|
if (st.st_size > bsize)
|
||||||
|
*min_size = bsize;
|
||||||
|
else
|
||||||
|
*min_size = st.st_size;
|
||||||
|
} else {
|
||||||
|
/* block device must have at least one block */
|
||||||
|
*min_size = bsize;
|
||||||
|
}
|
||||||
|
|
||||||
|
return bsize;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int device_read_test(int devfd)
|
||||||
|
{
|
||||||
|
char buffer[512];
|
||||||
|
int blocksize, r = -EIO;
|
||||||
|
size_t minsize = 0;
|
||||||
|
|
||||||
|
blocksize = device_block_size_fd(devfd, &minsize);
|
||||||
|
|
||||||
|
if (blocksize < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (minsize == 0)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
if (minsize > sizeof(buffer))
|
||||||
|
minsize = sizeof(buffer);
|
||||||
|
|
||||||
|
if (read_blockwise(devfd, blocksize, buffer, minsize) == (ssize_t)minsize)
|
||||||
|
r = 0;
|
||||||
|
|
||||||
|
crypt_memzero(buffer, sizeof(buffer));
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The direct-io is always preferred. The header is usually mapped to the same
|
||||||
|
* device and can be accessed when the rest of device is mapped to data device.
|
||||||
|
* Using dirct-io encsures that we do not mess with data in cache.
|
||||||
|
* (But proper alignment should prevent this in the first place.)
|
||||||
|
* The read test is needed to detect broken configurations (seen with remote
|
||||||
|
* block devices) that allow open with direct-io but then fails on read.
|
||||||
|
*/
|
||||||
|
static int device_ready(struct device *device, int check_directio)
|
||||||
|
{
|
||||||
|
int devfd = -1, r = 0;
|
||||||
|
struct stat st;
|
||||||
|
|
||||||
|
device->o_direct = 0;
|
||||||
|
if (check_directio) {
|
||||||
|
log_dbg("Trying to open and read device %s with direct-io.",
|
||||||
|
device_path(device));
|
||||||
|
devfd = open(device_path(device), O_RDONLY | O_DIRECT);
|
||||||
|
if (devfd >= 0) {
|
||||||
|
if (device_read_test(devfd) == 0) {
|
||||||
|
device->o_direct = 1;
|
||||||
|
} else {
|
||||||
|
close(devfd);
|
||||||
|
devfd = -1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (devfd < 0) {
|
||||||
|
log_dbg("Trying to open device %s without direct-io.",
|
||||||
|
device_path(device));
|
||||||
|
devfd = open(device_path(device), O_RDONLY);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (devfd < 0) {
|
||||||
|
log_err(NULL, _("Device %s doesn't exist or access denied.\n"),
|
||||||
|
device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (fstat(devfd, &st) < 0)
|
||||||
|
r = -EINVAL;
|
||||||
|
else if (!S_ISBLK(st.st_mode))
|
||||||
|
r = S_ISREG(st.st_mode) ? -ENOTBLK : -EINVAL;
|
||||||
|
|
||||||
|
close(devfd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int device_open(struct device *device, int flags)
|
||||||
|
{
|
||||||
|
int devfd;
|
||||||
|
|
||||||
|
flags |= O_SYNC;
|
||||||
|
if (device->o_direct)
|
||||||
|
flags |= O_DIRECT;
|
||||||
|
|
||||||
|
devfd = open(device_path(device), flags);
|
||||||
|
|
||||||
|
if (devfd < 0)
|
||||||
|
log_dbg("Cannot open device %s.", device_path(device));
|
||||||
|
|
||||||
|
return devfd;
|
||||||
|
}
|
||||||
|
|
||||||
|
int device_alloc(struct device **device, const char *path)
|
||||||
|
{
|
||||||
|
struct device *dev;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (!path) {
|
||||||
|
*device = NULL;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
dev = malloc(sizeof(struct device));
|
||||||
|
if (!dev)
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
memset(dev, 0, sizeof(struct device));
|
||||||
|
dev->path = strdup(path);
|
||||||
|
if (!dev->path) {
|
||||||
|
free(dev);
|
||||||
|
return -ENOMEM;
|
||||||
|
}
|
||||||
|
dev->loop_fd = -1;
|
||||||
|
|
||||||
|
r = device_ready(dev, 1);
|
||||||
|
if (!r) {
|
||||||
|
dev->init_done = 1;
|
||||||
|
} else if (r == -ENOTBLK) {
|
||||||
|
/* alloc loop later */
|
||||||
|
} else if (r < 0) {
|
||||||
|
free(dev->path);
|
||||||
|
free(dev);
|
||||||
|
return -ENOTBLK;
|
||||||
|
}
|
||||||
|
|
||||||
|
*device = dev;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
void device_free(struct device *device)
|
||||||
|
{
|
||||||
|
if (!device)
|
||||||
|
return;
|
||||||
|
|
||||||
|
if (device->loop_fd != -1) {
|
||||||
|
log_dbg("Closed loop %s (%s).", device->path, device->file_path);
|
||||||
|
close(device->loop_fd);
|
||||||
|
}
|
||||||
|
|
||||||
|
free(device->file_path);
|
||||||
|
free(device->path);
|
||||||
|
free(device);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Get block device path */
|
||||||
|
const char *device_block_path(const struct device *device)
|
||||||
|
{
|
||||||
|
if (!device || !device->init_done)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
return device->path;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Get path to device / file */
|
||||||
|
const char *device_path(const struct device *device)
|
||||||
|
{
|
||||||
|
if (!device)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
if (device->file_path)
|
||||||
|
return device->file_path;
|
||||||
|
|
||||||
|
return device->path;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* block device topology ioctls, introduced in 2.6.32 */
|
||||||
|
#ifndef BLKIOMIN
|
||||||
|
#define BLKIOMIN _IO(0x12,120)
|
||||||
|
#define BLKIOOPT _IO(0x12,121)
|
||||||
|
#define BLKALIGNOFF _IO(0x12,122)
|
||||||
|
#endif
|
||||||
|
|
||||||
|
void device_topology_alignment(struct device *device,
|
||||||
|
unsigned long *required_alignment, /* bytes */
|
||||||
|
unsigned long *alignment_offset, /* bytes */
|
||||||
|
unsigned long default_alignment)
|
||||||
|
{
|
||||||
|
int dev_alignment_offset = 0;
|
||||||
|
unsigned int min_io_size = 0, opt_io_size = 0;
|
||||||
|
unsigned long temp_alignment = 0;
|
||||||
|
int fd;
|
||||||
|
|
||||||
|
*required_alignment = default_alignment;
|
||||||
|
*alignment_offset = 0;
|
||||||
|
|
||||||
|
if (!device || !device->path) //FIXME
|
||||||
|
return;
|
||||||
|
|
||||||
|
fd = open(device->path, O_RDONLY);
|
||||||
|
if (fd == -1)
|
||||||
|
return;
|
||||||
|
|
||||||
|
/* minimum io size */
|
||||||
|
if (ioctl(fd, BLKIOMIN, &min_io_size) == -1) {
|
||||||
|
log_dbg("Topology info for %s not supported, using default offset %lu bytes.",
|
||||||
|
device->path, default_alignment);
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* optimal io size */
|
||||||
|
if (ioctl(fd, BLKIOOPT, &opt_io_size) == -1)
|
||||||
|
opt_io_size = min_io_size;
|
||||||
|
|
||||||
|
/* alignment offset, bogus -1 means misaligned/unknown */
|
||||||
|
if (ioctl(fd, BLKALIGNOFF, &dev_alignment_offset) == -1 || dev_alignment_offset < 0)
|
||||||
|
dev_alignment_offset = 0;
|
||||||
|
*alignment_offset = (unsigned long)dev_alignment_offset;
|
||||||
|
|
||||||
|
temp_alignment = (unsigned long)min_io_size;
|
||||||
|
|
||||||
|
if (temp_alignment < (unsigned long)opt_io_size)
|
||||||
|
temp_alignment = (unsigned long)opt_io_size;
|
||||||
|
|
||||||
|
/* If calculated alignment is multiple of default, keep default */
|
||||||
|
if (temp_alignment && (default_alignment % temp_alignment))
|
||||||
|
*required_alignment = temp_alignment;
|
||||||
|
|
||||||
|
log_dbg("Topology: IO (%u/%u), offset = %lu; Required alignment is %lu bytes.",
|
||||||
|
min_io_size, opt_io_size, *alignment_offset, *required_alignment);
|
||||||
|
out:
|
||||||
|
(void)close(fd);
|
||||||
|
}
|
||||||
|
|
||||||
|
int device_block_size(struct device *device)
|
||||||
|
{
|
||||||
|
int fd, r = -EINVAL;
|
||||||
|
|
||||||
|
if (!device)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
if (device->file_path)
|
||||||
|
return (int)crypt_getpagesize();
|
||||||
|
|
||||||
|
fd = open(device->path, O_RDONLY);
|
||||||
|
if(fd < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
r = device_block_size_fd(fd, NULL);
|
||||||
|
|
||||||
|
if (r <= 0)
|
||||||
|
log_dbg("Cannot get block size for device %s.", device_path(device));
|
||||||
|
|
||||||
|
close(fd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
int device_read_ahead(struct device *device, uint32_t *read_ahead)
|
||||||
|
{
|
||||||
|
int fd, r = 0;
|
||||||
|
long read_ahead_long;
|
||||||
|
|
||||||
|
if (!device)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
if ((fd = open(device->path, O_RDONLY)) < 0)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
r = ioctl(fd, BLKRAGET, &read_ahead_long) ? 0 : 1;
|
||||||
|
close(fd);
|
||||||
|
|
||||||
|
if (r)
|
||||||
|
*read_ahead = (uint32_t) read_ahead_long;
|
||||||
|
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Get data size in bytes */
|
||||||
|
int device_size(struct device *device, uint64_t *size)
|
||||||
|
{
|
||||||
|
struct stat st;
|
||||||
|
int devfd, r = -EINVAL;
|
||||||
|
|
||||||
|
devfd = open(device->path, O_RDONLY);
|
||||||
|
if(devfd == -1)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (fstat(devfd, &st) < 0)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if (S_ISREG(st.st_mode)) {
|
||||||
|
*size = (uint64_t)st.st_size;
|
||||||
|
r = 0;
|
||||||
|
} else if (ioctl(devfd, BLKGETSIZE64, size) >= 0)
|
||||||
|
r = 0;
|
||||||
|
out:
|
||||||
|
close(devfd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int device_info(struct device *device,
|
||||||
|
enum devcheck device_check,
|
||||||
|
int *readonly, uint64_t *size)
|
||||||
|
{
|
||||||
|
struct stat st;
|
||||||
|
int fd, r = -EINVAL, flags = 0;
|
||||||
|
|
||||||
|
*readonly = 0;
|
||||||
|
*size = 0;
|
||||||
|
|
||||||
|
if (stat(device->path, &st) < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
/* never wipe header on mounted device */
|
||||||
|
if (device_check == DEV_EXCL && S_ISBLK(st.st_mode))
|
||||||
|
flags |= O_EXCL;
|
||||||
|
|
||||||
|
/* Try to open read-write to check whether it is a read-only device */
|
||||||
|
/* coverity[toctou] */
|
||||||
|
fd = open(device->path, O_RDWR | flags);
|
||||||
|
if (fd == -1 && errno == EROFS) {
|
||||||
|
*readonly = 1;
|
||||||
|
fd = open(device->path, O_RDONLY | flags);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (fd == -1 && device_check == DEV_EXCL && errno == EBUSY)
|
||||||
|
return -EBUSY;
|
||||||
|
|
||||||
|
if (fd == -1)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (S_ISREG(st.st_mode)) {
|
||||||
|
//FIXME: add readonly check
|
||||||
|
*size = (uint64_t)st.st_size;
|
||||||
|
*size >>= SECTOR_SHIFT;
|
||||||
|
} else {
|
||||||
|
/* If the device can be opened read-write, i.e. readonly is still 0, then
|
||||||
|
* check whether BKROGET says that it is read-only. E.g. read-only loop
|
||||||
|
* devices may be openend read-write but are read-only according to BLKROGET
|
||||||
|
*/
|
||||||
|
if (*readonly == 0 && (r = ioctl(fd, BLKROGET, readonly)) < 0)
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if (ioctl(fd, BLKGETSIZE64, size) >= 0) {
|
||||||
|
*size >>= SECTOR_SHIFT;
|
||||||
|
r = 0;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
r = -EINVAL;
|
||||||
|
out:
|
||||||
|
close(fd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int device_internal_prepare(struct crypt_device *cd, struct device *device)
|
||||||
|
{
|
||||||
|
char *loop_device, *file_path = NULL;
|
||||||
|
int r, loop_fd, readonly = 0;
|
||||||
|
|
||||||
|
if (device->init_done)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
log_dbg("Allocating a free loop device.");
|
||||||
|
loop_device = crypt_loop_get_device();
|
||||||
|
if (!loop_device) {
|
||||||
|
if (getuid() || geteuid())
|
||||||
|
log_err(cd, _("Cannot use a loopback device, "
|
||||||
|
"running as non-root user.\n"));
|
||||||
|
else
|
||||||
|
log_err(cd, _("Cannot find a free loopback device.\n"));
|
||||||
|
return -ENOTSUP;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Keep the loop open, dettached on last close. */
|
||||||
|
loop_fd = crypt_loop_attach(loop_device, device->path, 0, 1, &readonly);
|
||||||
|
if (loop_fd == -1) {
|
||||||
|
log_err(cd, _("Attaching loopback device failed "
|
||||||
|
"(loop device with autoclear flag is required).\n"));
|
||||||
|
free(loop_device);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
file_path = device->path;
|
||||||
|
device->path = loop_device;
|
||||||
|
|
||||||
|
r = device_ready(device, device->o_direct);
|
||||||
|
if (r < 0) {
|
||||||
|
device->path = file_path;
|
||||||
|
crypt_loop_detach(loop_device);
|
||||||
|
free(loop_device);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
device->loop_fd = loop_fd;
|
||||||
|
device->file_path = file_path;
|
||||||
|
device->init_done = 1;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int device_block_adjust(struct crypt_device *cd,
|
||||||
|
struct device *device,
|
||||||
|
enum devcheck device_check,
|
||||||
|
uint64_t device_offset,
|
||||||
|
uint64_t *size,
|
||||||
|
uint32_t *flags)
|
||||||
|
{
|
||||||
|
int r, real_readonly;
|
||||||
|
uint64_t real_size;
|
||||||
|
|
||||||
|
if (!device)
|
||||||
|
return -ENOTBLK;
|
||||||
|
|
||||||
|
r = device_internal_prepare(cd, device);
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = device_info(device, device_check, &real_readonly, &real_size);
|
||||||
|
if (r < 0) {
|
||||||
|
if (r == -EBUSY)
|
||||||
|
log_err(cd, _("Cannot use device %s which is in use "
|
||||||
|
"(already mapped or mounted).\n"),
|
||||||
|
device->path);
|
||||||
|
else
|
||||||
|
log_err(cd, _("Cannot get info about device %s.\n"),
|
||||||
|
device->path);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (device_offset >= real_size) {
|
||||||
|
log_err(cd, _("Requested offset is beyond real size of device %s.\n"),
|
||||||
|
device->path);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (size && !*size) {
|
||||||
|
*size = real_size;
|
||||||
|
if (!*size) {
|
||||||
|
log_err(cd, _("Device %s has zero size.\n"), device->path);
|
||||||
|
return -ENOTBLK;
|
||||||
|
}
|
||||||
|
*size -= device_offset;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* in case of size is set by parameter */
|
||||||
|
if (size && ((real_size - device_offset) < *size)) {
|
||||||
|
log_dbg("Device %s: offset = %" PRIu64 " requested size = %" PRIu64
|
||||||
|
", backing device size = %" PRIu64,
|
||||||
|
device->path, device_offset, *size, real_size);
|
||||||
|
log_err(cd, _("Device %s is too small.\n"), device->path);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (flags && real_readonly)
|
||||||
|
*flags |= CRYPT_ACTIVATE_READONLY;
|
||||||
|
|
||||||
|
if (size)
|
||||||
|
log_dbg("Calculated device size is %" PRIu64" sectors (%s), offset %" PRIu64 ".",
|
||||||
|
*size, real_readonly ? "RO" : "RW", device_offset);
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
size_t size_round_up(size_t size, unsigned int block)
|
||||||
|
{
|
||||||
|
size_t s = (size + (block - 1)) / block;
|
||||||
|
return s * block;
|
||||||
|
}
|
||||||
|
|
||||||
|
void device_disable_direct_io(struct device *device)
|
||||||
|
{
|
||||||
|
device->o_direct = 0;
|
||||||
|
}
|
||||||
@@ -1,13 +1,15 @@
|
|||||||
/*
|
/*
|
||||||
* devname - search for device name
|
* devname - search for device name
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004, Christophe Saout <christophe@saout.de>
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2009-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2009-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2013, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -16,7 +18,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
@@ -26,13 +28,13 @@
|
|||||||
#include <dirent.h>
|
#include <dirent.h>
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
|
#include <limits.h>
|
||||||
#include <sys/stat.h>
|
#include <sys/stat.h>
|
||||||
#include <sys/types.h>
|
#include <sys/types.h>
|
||||||
#include "utils_dm.h"
|
#ifdef HAVE_SYS_SYSMACROS_H
|
||||||
|
# include <sys/sysmacros.h> /* for major, minor */
|
||||||
char *crypt_lookup_dev(const char *dev_id);
|
#endif
|
||||||
int crypt_sysfs_check_crypt_segment(const char *device, uint64_t offset, uint64_t size);
|
#include "internal.h"
|
||||||
int crypt_sysfs_get_rotational(int major, int minor, int *rotational);
|
|
||||||
|
|
||||||
static char *__lookup_dev(char *path, dev_t dev, int dir_level, const int max_level)
|
static char *__lookup_dev(char *path, dev_t dev, int dir_level, const int max_level)
|
||||||
{
|
{
|
||||||
@@ -135,7 +137,7 @@ char *crypt_lookup_dev(const char *dev_id)
|
|||||||
if (snprintf(path, sizeof(path), "/sys/dev/block/%s", dev_id) < 0)
|
if (snprintf(path, sizeof(path), "/sys/dev/block/%s", dev_id) < 0)
|
||||||
return NULL;
|
return NULL;
|
||||||
|
|
||||||
len = readlink(path, link, sizeof(link));
|
len = readlink(path, link, sizeof(link) - 1);
|
||||||
if (len < 0) {
|
if (len < 0) {
|
||||||
/* Without /sys use old scan */
|
/* Without /sys use old scan */
|
||||||
if (stat("/sys/dev/block", &st) < 0)
|
if (stat("/sys/dev/block", &st) < 0)
|
||||||
@@ -168,15 +170,12 @@ char *crypt_lookup_dev(const char *dev_id)
|
|||||||
return devpath;
|
return devpath;
|
||||||
}
|
}
|
||||||
|
|
||||||
static int crypt_sysfs_get_major_minor(const char *kname, int *major, int *minor)
|
static int _read_uint64(const char *sysfs_path, uint64_t *value)
|
||||||
{
|
{
|
||||||
char path[PATH_MAX], tmp[64] = {0};
|
char tmp[64] = {0};
|
||||||
int fd, r = 0;
|
int fd, r;
|
||||||
|
|
||||||
if (snprintf(path, sizeof(path), "/sys/block/%s/dev", kname) < 0)
|
if ((fd = open(sysfs_path, O_RDONLY)) < 0)
|
||||||
return 0;
|
|
||||||
|
|
||||||
if ((fd = open(path, O_RDONLY)) < 0)
|
|
||||||
return 0;
|
return 0;
|
||||||
r = read(fd, tmp, sizeof(tmp));
|
r = read(fd, tmp, sizeof(tmp));
|
||||||
close(fd);
|
close(fd);
|
||||||
@@ -184,85 +183,191 @@ static int crypt_sysfs_get_major_minor(const char *kname, int *major, int *minor
|
|||||||
if (r <= 0)
|
if (r <= 0)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
tmp[63] = '\0';
|
if (sscanf(tmp, "%" PRIu64, value) != 1)
|
||||||
if (sscanf(tmp, "%d:%d", major, minor) != 2)
|
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
return 1;
|
return 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
static int crypt_sysfs_get_holders_dir(const char *device, char *path, int size)
|
static int _sysfs_get_uint64(int major, int minor, uint64_t *value, const char *attr)
|
||||||
{
|
{
|
||||||
|
char path[PATH_MAX];
|
||||||
|
|
||||||
|
if (snprintf(path, sizeof(path), "/sys/dev/block/%d:%d/%s",
|
||||||
|
major, minor, attr) < 0)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
return _read_uint64(path, value);
|
||||||
|
}
|
||||||
|
|
||||||
|
static int _path_get_uint64(const char *sysfs_path, uint64_t *value, const char *attr)
|
||||||
|
{
|
||||||
|
char path[PATH_MAX];
|
||||||
|
|
||||||
|
if (snprintf(path, sizeof(path), "%s/%s",
|
||||||
|
sysfs_path, attr) < 0)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
return _read_uint64(path, value);
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_dev_is_rotational(int major, int minor)
|
||||||
|
{
|
||||||
|
uint64_t val;
|
||||||
|
|
||||||
|
if (!_sysfs_get_uint64(major, minor, &val, "queue/rotational"))
|
||||||
|
return 1; /* if failed, expect rotational disk */
|
||||||
|
|
||||||
|
return val ? 1 : 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_dev_is_partition(const char *dev_path)
|
||||||
|
{
|
||||||
|
uint64_t val;
|
||||||
struct stat st;
|
struct stat st;
|
||||||
|
|
||||||
if (stat(device, &st) < 0 || !S_ISBLK(st.st_mode))
|
if (stat(dev_path, &st) < 0)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
if (snprintf(path, size, "/sys/dev/block/%d:%d/holders",
|
if (!S_ISBLK(st.st_mode))
|
||||||
major(st.st_rdev), minor(st.st_rdev)) < 0)
|
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
return 1;
|
if (!_sysfs_get_uint64(major(st.st_rdev), minor(st.st_rdev),
|
||||||
|
&val, "partition"))
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
return val ? 1 : 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
int crypt_sysfs_check_crypt_segment(const char *device, uint64_t offset, uint64_t size)
|
uint64_t crypt_dev_partition_offset(const char *dev_path)
|
||||||
{
|
{
|
||||||
|
uint64_t val;
|
||||||
|
struct stat st;
|
||||||
|
|
||||||
|
if (!crypt_dev_is_partition(dev_path))
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
if (stat(dev_path, &st) < 0)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
if (!_sysfs_get_uint64(major(st.st_rdev), minor(st.st_rdev),
|
||||||
|
&val, "start"))
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
return val;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Try to find partition which match offset and size on top level device */
|
||||||
|
char *crypt_get_partition_device(const char *dev_path, uint64_t offset, uint64_t size)
|
||||||
|
{
|
||||||
|
char link[PATH_MAX], path[PATH_MAX], part_path[PATH_MAX], *devname;
|
||||||
|
char *result = NULL;
|
||||||
|
struct stat st;
|
||||||
|
size_t devname_len;
|
||||||
|
ssize_t len;
|
||||||
|
struct dirent *entry;
|
||||||
DIR *dir;
|
DIR *dir;
|
||||||
struct dirent *d;
|
uint64_t part_offset, part_size;
|
||||||
char path[PATH_MAX], *dmname;
|
|
||||||
int major, minor, r = 0;
|
|
||||||
|
|
||||||
if (!crypt_sysfs_get_holders_dir(device, path, sizeof(path)))
|
if (stat(dev_path, &st) < 0)
|
||||||
return -EINVAL;
|
return NULL;
|
||||||
|
|
||||||
if (!(dir = opendir(path)))
|
if (!S_ISBLK(st.st_mode))
|
||||||
return -EINVAL;
|
return NULL;
|
||||||
|
|
||||||
while (!r && (d = readdir(dir))) {
|
if (snprintf(path, sizeof(path), "/sys/dev/block/%d:%d",
|
||||||
if (!strcmp(d->d_name, ".") || !strcmp(d->d_name, ".."))
|
major(st.st_rdev), minor(st.st_rdev)) < 0)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
dir = opendir(path);
|
||||||
|
if (!dir)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
len = readlink(path, link, sizeof(link) - 1);
|
||||||
|
if (len < 0) {
|
||||||
|
closedir(dir);
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Get top level disk name for sysfs search */
|
||||||
|
link[len] = '\0';
|
||||||
|
devname = strrchr(link, '/');
|
||||||
|
if (!devname) {
|
||||||
|
closedir(dir);
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
devname++;
|
||||||
|
|
||||||
|
/* DM devices do not use kernel partitions. */
|
||||||
|
if (dm_is_dm_kernel_name(devname)) {
|
||||||
|
closedir(dir);
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
devname_len = strlen(devname);
|
||||||
|
while((entry = readdir(dir))) {
|
||||||
|
if (strncmp(entry->d_name, devname, devname_len))
|
||||||
continue;
|
continue;
|
||||||
|
|
||||||
if (!dm_is_dm_kernel_name(d->d_name)) {
|
if (snprintf(part_path, sizeof(part_path), "%s/%s",
|
||||||
r = -EBUSY;
|
path, entry->d_name) < 0)
|
||||||
break;
|
continue;
|
||||||
}
|
|
||||||
|
|
||||||
if (!crypt_sysfs_get_major_minor(d->d_name, &major, &minor)) {
|
if (stat(part_path, &st) < 0)
|
||||||
r = -EINVAL;
|
continue;
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!(dmname = dm_device_path(NULL, major, minor))) {
|
if (S_ISDIR(st.st_mode)) {
|
||||||
r = -EINVAL;
|
if (!_path_get_uint64(part_path, &part_offset, "start") ||
|
||||||
break;
|
!_path_get_uint64(part_path, &part_size, "size"))
|
||||||
|
continue;
|
||||||
|
if (part_offset == offset && part_size == size &&
|
||||||
|
snprintf(part_path, sizeof(part_path), "/dev/%s",
|
||||||
|
entry->d_name) > 0) {
|
||||||
|
result = strdup(part_path);
|
||||||
|
break;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
r = dm_check_segment(dmname, offset, size);
|
|
||||||
free(dmname);
|
|
||||||
}
|
}
|
||||||
closedir(dir);
|
closedir(dir);
|
||||||
|
|
||||||
return r;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
int crypt_sysfs_get_rotational(int major, int minor, int *rotational)
|
/* Try to find base device from partition */
|
||||||
|
char *crypt_get_base_device(const char *dev_path)
|
||||||
{
|
{
|
||||||
char path[PATH_MAX], tmp[64] = {0};
|
char link[PATH_MAX], path[PATH_MAX], part_path[PATH_MAX], *devname;
|
||||||
int fd, r;
|
struct stat st;
|
||||||
|
ssize_t len;
|
||||||
|
|
||||||
if (snprintf(path, sizeof(path), "/sys/dev/block/%d:%d/queue/rotational",
|
if (!crypt_dev_is_partition(dev_path))
|
||||||
major, minor) < 0)
|
return NULL;
|
||||||
return 0;
|
|
||||||
|
|
||||||
if ((fd = open(path, O_RDONLY)) < 0)
|
if (stat(dev_path, &st) < 0)
|
||||||
return 0;
|
return NULL;
|
||||||
r = read(fd, tmp, sizeof(tmp));
|
|
||||||
close(fd);
|
|
||||||
|
|
||||||
if (r <= 0)
|
if (snprintf(path, sizeof(path), "/sys/dev/block/%d:%d",
|
||||||
return 0;
|
major(st.st_rdev), minor(st.st_rdev)) < 0)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
if (sscanf(tmp, "%d", rotational) != 1)
|
len = readlink(path, link, sizeof(link) - 1);
|
||||||
return 0;
|
if (len < 0)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
return 1;
|
/* Get top level disk name for sysfs search */
|
||||||
|
link[len] = '\0';
|
||||||
|
devname = strrchr(link, '/');
|
||||||
|
if (!devname)
|
||||||
|
return NULL;
|
||||||
|
*devname = '\0';
|
||||||
|
devname = strrchr(link, '/');
|
||||||
|
if (!devname)
|
||||||
|
return NULL;
|
||||||
|
devname++;
|
||||||
|
|
||||||
|
if (dm_is_dm_kernel_name(devname))
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
snprintf(part_path, sizeof(part_path), "/dev/%s", devname);
|
||||||
|
return strdup(part_path);
|
||||||
}
|
}
|
||||||
|
|||||||
115
lib/utils_dm.h
115
lib/utils_dm.h
@@ -1,3 +1,26 @@
|
|||||||
|
/*
|
||||||
|
* libdevmapper - device-mapper backend for cryptsetup
|
||||||
|
*
|
||||||
|
* Copyright (C) 2004, Jana Saout <jana@saout.de>
|
||||||
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
|
* Copyright (C) 2009-2016, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2016, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef _UTILS_DM_H
|
#ifndef _UTILS_DM_H
|
||||||
#define _UTILS_DM_H
|
#define _UTILS_DM_H
|
||||||
|
|
||||||
@@ -6,6 +29,8 @@
|
|||||||
|
|
||||||
struct crypt_device;
|
struct crypt_device;
|
||||||
struct volume_key;
|
struct volume_key;
|
||||||
|
struct crypt_params_verity;
|
||||||
|
struct device;
|
||||||
|
|
||||||
/* Device mapper backend - kernel support flags */
|
/* Device mapper backend - kernel support flags */
|
||||||
#define DM_KEY_WIPE_SUPPORTED (1 << 0) /* key wipe message */
|
#define DM_KEY_WIPE_SUPPORTED (1 << 0) /* key wipe message */
|
||||||
@@ -13,48 +38,76 @@ struct volume_key;
|
|||||||
#define DM_SECURE_SUPPORTED (1 << 2) /* wipe (secure) buffer flag */
|
#define DM_SECURE_SUPPORTED (1 << 2) /* wipe (secure) buffer flag */
|
||||||
#define DM_PLAIN64_SUPPORTED (1 << 3) /* plain64 IV */
|
#define DM_PLAIN64_SUPPORTED (1 << 3) /* plain64 IV */
|
||||||
#define DM_DISCARDS_SUPPORTED (1 << 4) /* discards/TRIM option is supported */
|
#define DM_DISCARDS_SUPPORTED (1 << 4) /* discards/TRIM option is supported */
|
||||||
|
#define DM_VERITY_SUPPORTED (1 << 5) /* dm-verity target supported */
|
||||||
|
#define DM_TCW_SUPPORTED (1 << 6) /* tcw (TCRYPT CBC with whitening) */
|
||||||
|
#define DM_SAME_CPU_CRYPT_SUPPORTED (1 << 7) /* same_cpu_crypt */
|
||||||
|
#define DM_SUBMIT_FROM_CRYPT_CPUS_SUPPORTED (1 << 8) /* submit_from_crypt_cpus */
|
||||||
|
#define DM_VERITY_ON_CORRUPTION_SUPPORTED (1 << 9) /* ignore/restart_on_corruption, ignore_zero_block */
|
||||||
|
|
||||||
uint32_t dm_flags(void);
|
uint32_t dm_flags(void);
|
||||||
|
|
||||||
#define DM_ACTIVE_DEVICE (1 << 0)
|
#define DM_ACTIVE_DEVICE (1 << 0)
|
||||||
#define DM_ACTIVE_CIPHER (1 << 1)
|
#define DM_ACTIVE_UUID (1 << 1)
|
||||||
#define DM_ACTIVE_UUID (1 << 2)
|
|
||||||
#define DM_ACTIVE_KEYSIZE (1 << 3)
|
#define DM_ACTIVE_CRYPT_CIPHER (1 << 2)
|
||||||
#define DM_ACTIVE_KEY (1 << 4)
|
#define DM_ACTIVE_CRYPT_KEYSIZE (1 << 3)
|
||||||
|
#define DM_ACTIVE_CRYPT_KEY (1 << 4)
|
||||||
|
|
||||||
|
#define DM_ACTIVE_VERITY_ROOT_HASH (1 << 5)
|
||||||
|
#define DM_ACTIVE_VERITY_HASH_DEVICE (1 << 6)
|
||||||
|
#define DM_ACTIVE_VERITY_PARAMS (1 << 7)
|
||||||
|
|
||||||
struct crypt_dm_active_device {
|
struct crypt_dm_active_device {
|
||||||
const char *device;
|
enum { DM_CRYPT = 0, DM_VERITY } target;
|
||||||
const char *cipher;
|
|
||||||
const char *uuid;
|
|
||||||
|
|
||||||
/* Active key for device */
|
|
||||||
struct volume_key *vk;
|
|
||||||
|
|
||||||
/* struct crypt_active_device */
|
|
||||||
uint64_t offset; /* offset in sectors */
|
|
||||||
uint64_t iv_offset; /* IV initilisation sector */
|
|
||||||
uint64_t size; /* active device size */
|
uint64_t size; /* active device size */
|
||||||
uint32_t flags; /* activation flags */
|
uint32_t flags; /* activation flags */
|
||||||
|
const char *uuid;
|
||||||
|
struct device *data_device;
|
||||||
|
union {
|
||||||
|
struct {
|
||||||
|
const char *cipher;
|
||||||
|
|
||||||
|
/* Active key for device */
|
||||||
|
struct volume_key *vk;
|
||||||
|
|
||||||
|
/* struct crypt_active_device */
|
||||||
|
uint64_t offset; /* offset in sectors */
|
||||||
|
uint64_t iv_offset; /* IV initilisation sector */
|
||||||
|
} crypt;
|
||||||
|
struct {
|
||||||
|
struct device *hash_device;
|
||||||
|
|
||||||
|
const char *root_hash;
|
||||||
|
uint32_t root_hash_size;
|
||||||
|
|
||||||
|
uint64_t hash_offset; /* hash offset in blocks (not header) */
|
||||||
|
struct crypt_params_verity *vp;
|
||||||
|
} verity;
|
||||||
|
} u;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
void dm_backend_init(void);
|
||||||
|
void dm_backend_exit(void);
|
||||||
|
|
||||||
|
int dm_remove_device(struct crypt_device *cd, const char *name,
|
||||||
|
int force, uint64_t size);
|
||||||
|
int dm_status_device(struct crypt_device *cd, const char *name);
|
||||||
|
int dm_status_suspended(struct crypt_device *cd, const char *name);
|
||||||
|
int dm_status_verity_ok(struct crypt_device *cd, const char *name);
|
||||||
|
int dm_query_device(struct crypt_device *cd, const char *name,
|
||||||
|
uint32_t get_flags, struct crypt_dm_active_device *dmd);
|
||||||
|
int dm_create_device(struct crypt_device *cd, const char *name,
|
||||||
|
const char *type, struct crypt_dm_active_device *dmd,
|
||||||
|
int reload);
|
||||||
|
int dm_suspend_and_wipe_key(struct crypt_device *cd, const char *name);
|
||||||
|
int dm_resume_and_reinstate_key(struct crypt_device *cd, const char *name,
|
||||||
|
size_t key_size, const char *key);
|
||||||
|
|
||||||
const char *dm_get_dir(void);
|
const char *dm_get_dir(void);
|
||||||
int dm_init(struct crypt_device *context, int check_kernel);
|
|
||||||
void dm_exit(void);
|
/* These are DM helpers used only by utils_devpath file */
|
||||||
int dm_remove_device(const char *name, int force, uint64_t size);
|
|
||||||
int dm_status_device(const char *name);
|
|
||||||
int dm_status_suspended(const char *name);
|
|
||||||
int dm_query_device(const char *name, uint32_t get_flags,
|
|
||||||
struct crypt_dm_active_device *dmd);
|
|
||||||
int dm_create_device(const char *name,
|
|
||||||
const char *type,
|
|
||||||
struct crypt_dm_active_device *dmd,
|
|
||||||
int reload);
|
|
||||||
int dm_suspend_and_wipe_key(const char *name);
|
|
||||||
int dm_resume_and_reinstate_key(const char *name,
|
|
||||||
size_t key_size,
|
|
||||||
const char *key);
|
|
||||||
char *dm_device_path(const char *prefix, int major, int minor);
|
|
||||||
int dm_is_dm_device(int major, int minor);
|
int dm_is_dm_device(int major, int minor);
|
||||||
int dm_is_dm_kernel_name(const char *name);
|
int dm_is_dm_kernel_name(const char *name);
|
||||||
int dm_check_segment(const char *name, uint64_t offset, uint64_t size);
|
char *dm_device_path(const char *prefix, int major, int minor);
|
||||||
|
|
||||||
#endif /* _UTILS_DM_H */
|
#endif /* _UTILS_DM_H */
|
||||||
|
|||||||
46
lib/utils_fips.c
Normal file
46
lib/utils_fips.c
Normal file
@@ -0,0 +1,46 @@
|
|||||||
|
/*
|
||||||
|
* FIPS mode utilities
|
||||||
|
*
|
||||||
|
* Copyright (C) 2011-2015, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <unistd.h>
|
||||||
|
#include <fcntl.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include "utils_fips.h"
|
||||||
|
|
||||||
|
#if !ENABLE_FIPS
|
||||||
|
int crypt_fips_mode(void) { return 0; }
|
||||||
|
#else
|
||||||
|
static int kernel_fips_mode(void)
|
||||||
|
{
|
||||||
|
int fd;
|
||||||
|
char buf[1] = "";
|
||||||
|
|
||||||
|
if ((fd = open("/proc/sys/crypto/fips_enabled", O_RDONLY)) >= 0) {
|
||||||
|
while (read(fd, buf, sizeof(buf)) < 0 && errno == EINTR);
|
||||||
|
close(fd);
|
||||||
|
}
|
||||||
|
|
||||||
|
return (buf[0] == '1') ? 1 : 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int crypt_fips_mode(void)
|
||||||
|
{
|
||||||
|
return kernel_fips_mode() && !access("/etc/system-fips", F_OK);
|
||||||
|
}
|
||||||
|
#endif /* ENABLE_FIPS */
|
||||||
26
lib/utils_fips.h
Normal file
26
lib/utils_fips.h
Normal file
@@ -0,0 +1,26 @@
|
|||||||
|
/*
|
||||||
|
* FIPS mode utilities
|
||||||
|
*
|
||||||
|
* Copyright (C) 2011-2015, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef _UTILS_FIPS_H
|
||||||
|
#define _UTILS_FIPS_H
|
||||||
|
|
||||||
|
int crypt_fips_mode(void);
|
||||||
|
|
||||||
|
#endif /* _UTILS_FIPS_H */
|
||||||
@@ -1,11 +1,13 @@
|
|||||||
/*
|
/*
|
||||||
* loopback block device utilities
|
* loopback block device utilities
|
||||||
*
|
*
|
||||||
* Copyright (C) 2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2011-2015, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2015, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -14,7 +16,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
@@ -25,6 +27,10 @@
|
|||||||
#include <limits.h>
|
#include <limits.h>
|
||||||
#include <sys/ioctl.h>
|
#include <sys/ioctl.h>
|
||||||
#include <sys/stat.h>
|
#include <sys/stat.h>
|
||||||
|
#include <sys/types.h>
|
||||||
|
#ifdef HAVE_SYS_SYSMACROS_H
|
||||||
|
# include <sys/sysmacros.h> /* for major, minor */
|
||||||
|
#endif
|
||||||
#include <linux/loop.h>
|
#include <linux/loop.h>
|
||||||
|
|
||||||
#include "utils_loop.h"
|
#include "utils_loop.h"
|
||||||
@@ -39,17 +45,18 @@
|
|||||||
#define LOOP_CTL_GET_FREE 0x4C82
|
#define LOOP_CTL_GET_FREE 0x4C82
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#ifndef LOOP_SET_CAPACITY
|
||||||
|
#define LOOP_SET_CAPACITY 0x4C07
|
||||||
|
#endif
|
||||||
|
|
||||||
static char *crypt_loop_get_device_old(void)
|
static char *crypt_loop_get_device_old(void)
|
||||||
{
|
{
|
||||||
char dev[20];
|
char dev[20];
|
||||||
int i, loop_fd;
|
int i, loop_fd;
|
||||||
struct stat st;
|
|
||||||
struct loop_info64 lo64 = {0};
|
struct loop_info64 lo64 = {0};
|
||||||
|
|
||||||
for (i = 0; i < 256; i++) {
|
for (i = 0; i < 256; i++) {
|
||||||
sprintf(dev, "/dev/loop%d", i);
|
sprintf(dev, "/dev/loop%d", i);
|
||||||
if (stat(dev, &st) || !S_ISBLK(st.st_mode))
|
|
||||||
return NULL;
|
|
||||||
|
|
||||||
loop_fd = open(dev, O_RDONLY);
|
loop_fd = open(dev, O_RDONLY);
|
||||||
if (loop_fd < 0)
|
if (loop_fd < 0)
|
||||||
@@ -96,10 +103,11 @@ int crypt_loop_attach(const char *loop, const char *file, int offset,
|
|||||||
int autoclear, int *readonly)
|
int autoclear, int *readonly)
|
||||||
{
|
{
|
||||||
struct loop_info64 lo64 = {0};
|
struct loop_info64 lo64 = {0};
|
||||||
|
char *lo_file_name;
|
||||||
int loop_fd = -1, file_fd = -1, r = 1;
|
int loop_fd = -1, file_fd = -1, r = 1;
|
||||||
|
|
||||||
file_fd = open(file, (*readonly ? O_RDONLY : O_RDWR) | O_EXCL);
|
file_fd = open(file, (*readonly ? O_RDONLY : O_RDWR) | O_EXCL);
|
||||||
if (file_fd < 0 && errno == EROFS && !*readonly) {
|
if (file_fd < 0 && (errno == EROFS || errno == EACCES) && !*readonly) {
|
||||||
*readonly = 1;
|
*readonly = 1;
|
||||||
file_fd = open(file, O_RDONLY | O_EXCL);
|
file_fd = open(file, O_RDONLY | O_EXCL);
|
||||||
}
|
}
|
||||||
@@ -110,7 +118,9 @@ int crypt_loop_attach(const char *loop, const char *file, int offset,
|
|||||||
if (loop_fd < 0)
|
if (loop_fd < 0)
|
||||||
goto out;
|
goto out;
|
||||||
|
|
||||||
strncpy((char*)lo64.lo_file_name, file, LO_NAME_SIZE);
|
lo_file_name = (char*)lo64.lo_file_name;
|
||||||
|
lo_file_name[LO_NAME_SIZE-1] = '\0';
|
||||||
|
strncpy(lo_file_name, file, LO_NAME_SIZE-1);
|
||||||
lo64.lo_offset = offset;
|
lo64.lo_offset = offset;
|
||||||
if (autoclear)
|
if (autoclear)
|
||||||
lo64.lo_flags |= LO_FLAGS_AUTOCLEAR;
|
lo64.lo_flags |= LO_FLAGS_AUTOCLEAR;
|
||||||
@@ -157,6 +167,21 @@ int crypt_loop_detach(const char *loop)
|
|||||||
return r;
|
return r;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
int crypt_loop_resize(const char *loop)
|
||||||
|
{
|
||||||
|
int loop_fd = -1, r = 1;
|
||||||
|
|
||||||
|
loop_fd = open(loop, O_RDONLY);
|
||||||
|
if (loop_fd < 0)
|
||||||
|
return 1;
|
||||||
|
|
||||||
|
if (!ioctl(loop_fd, LOOP_SET_CAPACITY, 0))
|
||||||
|
r = 0;
|
||||||
|
|
||||||
|
close(loop_fd);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
static char *_ioctl_backing_file(const char *loop)
|
static char *_ioctl_backing_file(const char *loop)
|
||||||
{
|
{
|
||||||
struct loop_info64 lo64 = {0};
|
struct loop_info64 lo64 = {0};
|
||||||
|
|||||||
@@ -1,3 +1,24 @@
|
|||||||
|
/*
|
||||||
|
* loopback block device utilities
|
||||||
|
*
|
||||||
|
* Copyright (C) 2011-2015, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2015, Milan Broz
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
#ifndef _UTILS_LOOP_H
|
#ifndef _UTILS_LOOP_H
|
||||||
#define _UTILS_LOOP_H
|
#define _UTILS_LOOP_H
|
||||||
|
|
||||||
@@ -9,5 +30,6 @@ int crypt_loop_device(const char *loop);
|
|||||||
int crypt_loop_attach(const char *loop, const char *file, int offset,
|
int crypt_loop_attach(const char *loop, const char *file, int offset,
|
||||||
int autoclear, int *readonly);
|
int autoclear, int *readonly);
|
||||||
int crypt_loop_detach(const char *loop);
|
int crypt_loop_detach(const char *loop);
|
||||||
|
int crypt_loop_resize(const char *loop);
|
||||||
|
|
||||||
#endif /* _UTILS_LOOP_H */
|
#endif /* _UTILS_LOOP_H */
|
||||||
|
|||||||
106
lib/utils_wipe.c
106
lib/utils_wipe.c
@@ -2,11 +2,13 @@
|
|||||||
* utils_wipe - wipe a device
|
* utils_wipe - wipe a device
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2011-2012, Red Hat, Inc. All rights reserved.
|
||||||
|
* Copyright (C) 2009-2012, Milan Broz
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -15,7 +17,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
@@ -27,6 +29,9 @@
|
|||||||
#include <sys/types.h>
|
#include <sys/types.h>
|
||||||
#include <sys/stat.h>
|
#include <sys/stat.h>
|
||||||
#include <sys/ioctl.h>
|
#include <sys/ioctl.h>
|
||||||
|
#ifdef HAVE_SYS_SYSMACROS_H
|
||||||
|
# include <sys/sysmacros.h> /* for major, minor */
|
||||||
|
#endif
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
|
|
||||||
#include "libcryptsetup.h"
|
#include "libcryptsetup.h"
|
||||||
@@ -34,10 +39,20 @@
|
|||||||
|
|
||||||
#define MAXIMUM_WIPE_BYTES 1024 * 1024 * 32 /* 32 MiB */
|
#define MAXIMUM_WIPE_BYTES 1024 * 1024 * 32 /* 32 MiB */
|
||||||
|
|
||||||
static ssize_t _crypt_wipe_zero(int fd, char *buffer, uint64_t offset, uint64_t size)
|
static ssize_t _crypt_wipe_zero(int fd, int bsize, char *buffer,
|
||||||
|
uint64_t offset, uint64_t size)
|
||||||
{
|
{
|
||||||
memset(buffer, 0, size);
|
memset(buffer, 0, size);
|
||||||
return write_lseek_blockwise(fd, buffer, size, offset);
|
return write_lseek_blockwise(fd, bsize, buffer, size, offset);
|
||||||
|
}
|
||||||
|
|
||||||
|
static ssize_t _crypt_wipe_random(int fd, int bsize, char *buffer,
|
||||||
|
uint64_t offset, uint64_t size)
|
||||||
|
{
|
||||||
|
if (crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL) < 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
return write_lseek_blockwise(fd, bsize, buffer, size, offset);
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -66,38 +81,45 @@ static void wipeSpecial(char *buffer, size_t buffer_size, unsigned int turn)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static ssize_t _crypt_wipe_disk(int fd, char *buffer, uint64_t offset, uint64_t size)
|
static ssize_t _crypt_wipe_disk(int fd, int bsize, char *buffer,
|
||||||
|
uint64_t offset, uint64_t size)
|
||||||
{
|
{
|
||||||
|
int r;
|
||||||
unsigned int i;
|
unsigned int i;
|
||||||
ssize_t written;
|
ssize_t written;
|
||||||
|
|
||||||
for(i = 0; i < 39; ++i) {
|
for(i = 0; i < 39; ++i) {
|
||||||
if (i < 5) crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL);
|
if (i < 5) {
|
||||||
else if(i >= 5 && i < 32) wipeSpecial(buffer, size, i - 5);
|
r = crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL);
|
||||||
else if(i >= 32 && i < 38) crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL);
|
} else if(i >= 5 && i < 32) {
|
||||||
else if(i >= 38 && i < 39) memset(buffer, 0xFF, size);
|
wipeSpecial(buffer, size, i - 5);
|
||||||
|
r = 0;
|
||||||
|
} else if(i >= 32 && i < 38) {
|
||||||
|
r = crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL);
|
||||||
|
} else if(i >= 38 && i < 39) {
|
||||||
|
memset(buffer, 0xFF, size);
|
||||||
|
r = 0;
|
||||||
|
}
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
written = write_lseek_blockwise(fd, buffer, size, offset);
|
written = write_lseek_blockwise(fd, bsize, buffer, size, offset);
|
||||||
if (written < 0 || written != (ssize_t)size)
|
if (written < 0 || written != (ssize_t)size)
|
||||||
return written;
|
return written;
|
||||||
}
|
}
|
||||||
|
|
||||||
return written;
|
/* Rewrite it finally with random */
|
||||||
|
return _crypt_wipe_random(fd, bsize, buffer, offset, size);
|
||||||
}
|
}
|
||||||
|
|
||||||
static ssize_t _crypt_wipe_random(int fd, char *buffer, uint64_t offset, uint64_t size)
|
static ssize_t _crypt_wipe_ssd(int fd, int bsize, char *buffer,
|
||||||
{
|
uint64_t offset, uint64_t size)
|
||||||
crypt_random_get(NULL, buffer, size, CRYPT_RND_NORMAL);
|
|
||||||
return write_lseek_blockwise(fd, buffer, size, offset);
|
|
||||||
}
|
|
||||||
|
|
||||||
static ssize_t _crypt_wipe_ssd(int fd, char *buffer, uint64_t offset, uint64_t size)
|
|
||||||
{
|
{
|
||||||
// FIXME: for now just rewrite it by random
|
// FIXME: for now just rewrite it by random
|
||||||
return _crypt_wipe_random(fd, buffer, offset, size);
|
return _crypt_wipe_random(fd, bsize, buffer, offset, size);
|
||||||
}
|
}
|
||||||
|
|
||||||
int crypt_wipe(const char *device,
|
int crypt_wipe(struct device *device,
|
||||||
uint64_t offset,
|
uint64_t offset,
|
||||||
uint64_t size,
|
uint64_t size,
|
||||||
crypt_wipe_type type,
|
crypt_wipe_type type,
|
||||||
@@ -105,58 +127,64 @@ int crypt_wipe(const char *device,
|
|||||||
{
|
{
|
||||||
struct stat st;
|
struct stat st;
|
||||||
char *buffer;
|
char *buffer;
|
||||||
int devfd, flags, rotational;
|
int devfd, flags, bsize;
|
||||||
ssize_t written;
|
ssize_t written;
|
||||||
|
|
||||||
if (!size || size % SECTOR_SIZE || (size > MAXIMUM_WIPE_BYTES)) {
|
if (!size || size % SECTOR_SIZE || (size > MAXIMUM_WIPE_BYTES)) {
|
||||||
log_dbg("Unsuported wipe size for device %s: %ld.",
|
log_dbg("Unsuported wipe size for device %s: %ld.",
|
||||||
device, (unsigned long)size);
|
device_path(device), (unsigned long)size);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (stat(device, &st) < 0) {
|
if (stat(device_path(device), &st) < 0) {
|
||||||
log_dbg("Device %s not found.", device);
|
log_dbg("Device %s not found.", device_path(device));
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (type == CRYPT_WIPE_DISK) {
|
if (type == CRYPT_WIPE_DISK && S_ISBLK(st.st_mode)) {
|
||||||
if (!crypt_sysfs_get_rotational(major(st.st_rdev),
|
if (!crypt_dev_is_rotational(major(st.st_rdev),
|
||||||
minor(st.st_rdev),
|
minor(st.st_rdev))) {
|
||||||
&rotational))
|
|
||||||
rotational = 1;
|
|
||||||
log_dbg("Rotational flag is %d.", rotational);
|
|
||||||
if (!rotational)
|
|
||||||
type = CRYPT_WIPE_SSD;
|
type = CRYPT_WIPE_SSD;
|
||||||
|
log_dbg("Non-rotational device, using SSD wipe mode.");
|
||||||
|
} else
|
||||||
|
log_dbg("Rotational device, using normal wipe mode.");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
bsize = device_block_size(device);
|
||||||
|
if (bsize <= 0)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
buffer = malloc(size);
|
buffer = malloc(size);
|
||||||
if (!buffer)
|
if (!buffer)
|
||||||
return -ENOMEM;
|
return -ENOMEM;
|
||||||
|
|
||||||
flags = O_WRONLY | O_DIRECT | O_SYNC;
|
flags = O_RDWR;
|
||||||
|
|
||||||
/* use O_EXCL only for block devices */
|
/* use O_EXCL only for block devices */
|
||||||
if (exclusive && S_ISBLK(st.st_mode))
|
if (exclusive && S_ISBLK(st.st_mode))
|
||||||
flags |= O_EXCL;
|
flags |= O_EXCL;
|
||||||
|
|
||||||
devfd = open(device, flags);
|
/* coverity[toctou] */
|
||||||
|
devfd = device_open(device, flags);
|
||||||
if (devfd == -1) {
|
if (devfd == -1) {
|
||||||
free(buffer);
|
free(buffer);
|
||||||
return errno == EBUSY ? -EBUSY : -EINVAL;
|
return errno ? -errno : -EINVAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
// FIXME: use fixed block size and loop here
|
// FIXME: use fixed block size and loop here
|
||||||
switch (type) {
|
switch (type) {
|
||||||
case CRYPT_WIPE_ZERO:
|
case CRYPT_WIPE_ZERO:
|
||||||
written = _crypt_wipe_zero(devfd, buffer, offset, size);
|
written = _crypt_wipe_zero(devfd, bsize, buffer, offset, size);
|
||||||
break;
|
break;
|
||||||
case CRYPT_WIPE_DISK:
|
case CRYPT_WIPE_DISK:
|
||||||
written = _crypt_wipe_disk(devfd, buffer, offset, size);
|
written = _crypt_wipe_disk(devfd, bsize, buffer, offset, size);
|
||||||
|
break;
|
||||||
case CRYPT_WIPE_SSD:
|
case CRYPT_WIPE_SSD:
|
||||||
written = _crypt_wipe_ssd(devfd, buffer, offset, size);
|
written = _crypt_wipe_ssd(devfd, bsize, buffer, offset, size);
|
||||||
break;
|
break;
|
||||||
case CRYPT_WIPE_RANDOM:
|
case CRYPT_WIPE_RANDOM:
|
||||||
written = _crypt_wipe_random(devfd, buffer, offset, size);
|
written = _crypt_wipe_random(devfd, bsize, buffer, offset, size);
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
log_dbg("Unsuported wipe type requested: (%d)", type);
|
log_dbg("Unsuported wipe type requested: (%d)", type);
|
||||||
written = -1;
|
written = -1;
|
||||||
|
|||||||
14
lib/verity/Makefile.am
Normal file
14
lib/verity/Makefile.am
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
moduledir = $(libdir)/cryptsetup
|
||||||
|
|
||||||
|
noinst_LTLIBRARIES = libverity.la
|
||||||
|
|
||||||
|
libverity_la_CFLAGS = -Wall $(AM_CFLAGS) @CRYPTO_CFLAGS@
|
||||||
|
|
||||||
|
libverity_la_SOURCES = \
|
||||||
|
verity_hash.c \
|
||||||
|
verity.c \
|
||||||
|
verity.h
|
||||||
|
|
||||||
|
AM_CPPFLAGS = -include config.h \
|
||||||
|
-I$(top_srcdir)/lib \
|
||||||
|
-I$(top_srcdir)/lib/crypto_backend
|
||||||
292
lib/verity/verity.c
Normal file
292
lib/verity/verity.c
Normal file
@@ -0,0 +1,292 @@
|
|||||||
|
/*
|
||||||
|
* dm-verity volume handling
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <errno.h>
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdint.h>
|
||||||
|
#include <sys/types.h>
|
||||||
|
#include <sys/stat.h>
|
||||||
|
#include <fcntl.h>
|
||||||
|
#include <netinet/in.h>
|
||||||
|
#include <uuid/uuid.h>
|
||||||
|
|
||||||
|
#include "libcryptsetup.h"
|
||||||
|
#include "verity.h"
|
||||||
|
#include "internal.h"
|
||||||
|
|
||||||
|
#define VERITY_SIGNATURE "verity\0\0"
|
||||||
|
|
||||||
|
/* https://gitlab.com/cryptsetup/cryptsetup/wikis/DMVerity#verity-superblock-format */
|
||||||
|
struct verity_sb {
|
||||||
|
uint8_t signature[8]; /* "verity\0\0" */
|
||||||
|
uint32_t version; /* superblock version */
|
||||||
|
uint32_t hash_type; /* 0 - Chrome OS, 1 - normal */
|
||||||
|
uint8_t uuid[16]; /* UUID of hash device */
|
||||||
|
uint8_t algorithm[32];/* hash algorithm name */
|
||||||
|
uint32_t data_block_size; /* data block in bytes */
|
||||||
|
uint32_t hash_block_size; /* hash block in bytes */
|
||||||
|
uint64_t data_blocks; /* number of data blocks */
|
||||||
|
uint16_t salt_size; /* salt size */
|
||||||
|
uint8_t _pad1[6];
|
||||||
|
uint8_t salt[256]; /* salt */
|
||||||
|
uint8_t _pad2[168];
|
||||||
|
} __attribute__((packed));
|
||||||
|
|
||||||
|
/* Read verity superblock from disk */
|
||||||
|
int VERITY_read_sb(struct crypt_device *cd,
|
||||||
|
uint64_t sb_offset,
|
||||||
|
char **uuid_string,
|
||||||
|
struct crypt_params_verity *params)
|
||||||
|
{
|
||||||
|
struct device *device = crypt_metadata_device(cd);
|
||||||
|
int bsize = device_block_size(device);
|
||||||
|
struct verity_sb sb = {};
|
||||||
|
ssize_t hdr_size = sizeof(struct verity_sb);
|
||||||
|
int devfd = 0, sb_version;
|
||||||
|
|
||||||
|
log_dbg("Reading VERITY header of size %zu on device %s, offset %" PRIu64 ".",
|
||||||
|
sizeof(struct verity_sb), device_path(device), sb_offset);
|
||||||
|
|
||||||
|
if (params->flags & CRYPT_VERITY_NO_HEADER) {
|
||||||
|
log_err(cd, _("Verity device %s doesn't use on-disk header.\n"),
|
||||||
|
device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (sb_offset % 512) {
|
||||||
|
log_err(cd, _("Unsupported VERITY hash offset.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
devfd = device_open(device, O_RDONLY);
|
||||||
|
if(devfd == -1) {
|
||||||
|
log_err(cd, _("Cannot open device %s.\n"), device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if(lseek(devfd, sb_offset, SEEK_SET) < 0 ||
|
||||||
|
read_blockwise(devfd, bsize, &sb, hdr_size) < hdr_size) {
|
||||||
|
close(devfd);
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
close(devfd);
|
||||||
|
|
||||||
|
if (memcmp(sb.signature, VERITY_SIGNATURE, sizeof(sb.signature))) {
|
||||||
|
log_err(cd, _("Device %s is not a valid VERITY device.\n"),
|
||||||
|
device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
sb_version = le32_to_cpu(sb.version);
|
||||||
|
if (sb_version != 1) {
|
||||||
|
log_err(cd, _("Unsupported VERITY version %d.\n"), sb_version);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
params->hash_type = le32_to_cpu(sb.hash_type);
|
||||||
|
if (params->hash_type > VERITY_MAX_HASH_TYPE) {
|
||||||
|
log_err(cd, _("Unsupported VERITY hash type %d.\n"), params->hash_type);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
params->data_block_size = le32_to_cpu(sb.data_block_size);
|
||||||
|
params->hash_block_size = le32_to_cpu(sb.hash_block_size);
|
||||||
|
if (VERITY_BLOCK_SIZE_OK(params->data_block_size) ||
|
||||||
|
VERITY_BLOCK_SIZE_OK(params->hash_block_size)) {
|
||||||
|
log_err(cd, _("Unsupported VERITY block size.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
params->data_size = le64_to_cpu(sb.data_blocks);
|
||||||
|
|
||||||
|
params->hash_name = strndup((const char*)sb.algorithm, sizeof(sb.algorithm));
|
||||||
|
if (!params->hash_name)
|
||||||
|
return -ENOMEM;
|
||||||
|
if (crypt_hash_size(params->hash_name) <= 0) {
|
||||||
|
log_err(cd, _("Hash algorithm %s not supported.\n"),
|
||||||
|
params->hash_name);
|
||||||
|
free(CONST_CAST(char*)params->hash_name);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
params->salt_size = le16_to_cpu(sb.salt_size);
|
||||||
|
if (params->salt_size > sizeof(sb.salt)) {
|
||||||
|
log_err(cd, _("VERITY header corrupted.\n"));
|
||||||
|
free(CONST_CAST(char*)params->hash_name);
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
params->salt = malloc(params->salt_size);
|
||||||
|
if (!params->salt) {
|
||||||
|
free(CONST_CAST(char*)params->hash_name);
|
||||||
|
return -ENOMEM;
|
||||||
|
}
|
||||||
|
memcpy(CONST_CAST(char*)params->salt, sb.salt, params->salt_size);
|
||||||
|
|
||||||
|
if ((*uuid_string = malloc(40)))
|
||||||
|
uuid_unparse(sb.uuid, *uuid_string);
|
||||||
|
|
||||||
|
params->hash_area_offset = sb_offset;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Write verity superblock to disk */
|
||||||
|
int VERITY_write_sb(struct crypt_device *cd,
|
||||||
|
uint64_t sb_offset,
|
||||||
|
const char *uuid_string,
|
||||||
|
struct crypt_params_verity *params)
|
||||||
|
{
|
||||||
|
struct device *device = crypt_metadata_device(cd);
|
||||||
|
int bsize = device_block_size(device);
|
||||||
|
struct verity_sb sb = {};
|
||||||
|
ssize_t hdr_size = sizeof(struct verity_sb);
|
||||||
|
char *algorithm;
|
||||||
|
uuid_t uuid;
|
||||||
|
int r, devfd = 0;
|
||||||
|
|
||||||
|
log_dbg("Updating VERITY header of size %zu on device %s, offset %" PRIu64 ".",
|
||||||
|
sizeof(struct verity_sb), device_path(device), sb_offset);
|
||||||
|
|
||||||
|
if (!uuid_string || uuid_parse(uuid_string, uuid) == -1) {
|
||||||
|
log_err(cd, _("Wrong VERITY UUID format provided on device %s.\n"),
|
||||||
|
device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (params->flags & CRYPT_VERITY_NO_HEADER) {
|
||||||
|
log_err(cd, _("Verity device %s doesn't use on-disk header.\n"),
|
||||||
|
device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
devfd = device_open(device, O_RDWR);
|
||||||
|
if(devfd == -1) {
|
||||||
|
log_err(cd, _("Cannot open device %s.\n"), device_path(device));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
memcpy(&sb.signature, VERITY_SIGNATURE, sizeof(sb.signature));
|
||||||
|
sb.version = cpu_to_le32(1);
|
||||||
|
sb.hash_type = cpu_to_le32(params->hash_type);
|
||||||
|
sb.data_block_size = cpu_to_le32(params->data_block_size);
|
||||||
|
sb.hash_block_size = cpu_to_le32(params->hash_block_size);
|
||||||
|
sb.salt_size = cpu_to_le16(params->salt_size);
|
||||||
|
sb.data_blocks = cpu_to_le64(params->data_size);
|
||||||
|
algorithm = (char *)sb.algorithm;
|
||||||
|
algorithm[sizeof(sb.algorithm)-1] = '\0';
|
||||||
|
strncpy(algorithm, params->hash_name, sizeof(sb.algorithm)-1);
|
||||||
|
memcpy(sb.salt, params->salt, params->salt_size);
|
||||||
|
memcpy(sb.uuid, uuid, sizeof(sb.uuid));
|
||||||
|
|
||||||
|
r = write_lseek_blockwise(devfd, bsize, (char*)&sb, hdr_size, sb_offset) < hdr_size ? -EIO : 0;
|
||||||
|
if (r)
|
||||||
|
log_err(cd, _("Error during update of verity header on device %s.\n"),
|
||||||
|
device_path(device));
|
||||||
|
close(devfd);
|
||||||
|
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Calculate hash offset in hash blocks */
|
||||||
|
uint64_t VERITY_hash_offset_block(struct crypt_params_verity *params)
|
||||||
|
{
|
||||||
|
uint64_t hash_offset = params->hash_area_offset;
|
||||||
|
|
||||||
|
if (params->flags & CRYPT_VERITY_NO_HEADER)
|
||||||
|
return hash_offset / params->hash_block_size;
|
||||||
|
|
||||||
|
hash_offset += sizeof(struct verity_sb);
|
||||||
|
hash_offset += params->hash_block_size - 1;
|
||||||
|
|
||||||
|
return hash_offset / params->hash_block_size;
|
||||||
|
}
|
||||||
|
|
||||||
|
int VERITY_UUID_generate(struct crypt_device *cd, char **uuid_string)
|
||||||
|
{
|
||||||
|
uuid_t uuid;
|
||||||
|
|
||||||
|
if (!(*uuid_string = malloc(40)))
|
||||||
|
return -ENOMEM;
|
||||||
|
uuid_generate(uuid);
|
||||||
|
uuid_unparse(uuid, *uuid_string);
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Activate verity device in kernel device-mapper */
|
||||||
|
int VERITY_activate(struct crypt_device *cd,
|
||||||
|
const char *name,
|
||||||
|
const char *root_hash,
|
||||||
|
size_t root_hash_size,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
uint32_t activation_flags)
|
||||||
|
{
|
||||||
|
struct crypt_dm_active_device dmd;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
log_dbg("Trying to activate VERITY device %s using hash %s.",
|
||||||
|
name ?: "[none]", verity_hdr->hash_name);
|
||||||
|
|
||||||
|
if (verity_hdr->flags & CRYPT_VERITY_CHECK_HASH) {
|
||||||
|
log_dbg("Verification of data in userspace required.");
|
||||||
|
r = VERITY_verify(cd, verity_hdr,
|
||||||
|
root_hash, root_hash_size);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!name)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
dmd.target = DM_VERITY;
|
||||||
|
dmd.data_device = crypt_data_device(cd);
|
||||||
|
dmd.u.verity.hash_device = crypt_metadata_device(cd);
|
||||||
|
dmd.u.verity.root_hash = root_hash;
|
||||||
|
dmd.u.verity.root_hash_size = root_hash_size;
|
||||||
|
dmd.u.verity.hash_offset = VERITY_hash_offset_block(verity_hdr),
|
||||||
|
dmd.flags = activation_flags;
|
||||||
|
dmd.size = verity_hdr->data_size * verity_hdr->data_block_size / 512;
|
||||||
|
dmd.uuid = crypt_get_uuid(cd);
|
||||||
|
dmd.u.verity.vp = verity_hdr;
|
||||||
|
|
||||||
|
r = device_block_adjust(cd, dmd.u.verity.hash_device, DEV_OK,
|
||||||
|
0, NULL, NULL);
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = device_block_adjust(cd, dmd.data_device, DEV_EXCL,
|
||||||
|
0, &dmd.size, &dmd.flags);
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = dm_create_device(cd, name, CRYPT_VERITY, &dmd, 0);
|
||||||
|
if (r < 0 && !(dm_flags() & DM_VERITY_SUPPORTED)) {
|
||||||
|
log_err(cd, _("Kernel doesn't support dm-verity mapping.\n"));
|
||||||
|
return -ENOTSUP;
|
||||||
|
}
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
r = dm_status_verity_ok(cd, name);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
if (!r)
|
||||||
|
log_err(cd, _("Verity device detected corruption after activation.\n"));
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
64
lib/verity/verity.h
Normal file
64
lib/verity/verity.h
Normal file
@@ -0,0 +1,64 @@
|
|||||||
|
/*
|
||||||
|
* dm-verity volume handling
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef _VERITY_H
|
||||||
|
#define _VERITY_H
|
||||||
|
|
||||||
|
#include <unistd.h>
|
||||||
|
|
||||||
|
#define VERITY_MAX_HASH_TYPE 1
|
||||||
|
#define VERITY_BLOCK_SIZE_OK(x) ((x) % 512 || (x) < 512 || \
|
||||||
|
(x) > (512 * 1024) || (x) & ((x)-1))
|
||||||
|
|
||||||
|
struct crypt_device;
|
||||||
|
struct crypt_params_verity;
|
||||||
|
|
||||||
|
int VERITY_read_sb(struct crypt_device *cd,
|
||||||
|
uint64_t sb_offset,
|
||||||
|
char **uuid,
|
||||||
|
struct crypt_params_verity *params);
|
||||||
|
|
||||||
|
int VERITY_write_sb(struct crypt_device *cd,
|
||||||
|
uint64_t sb_offset,
|
||||||
|
const char *uuid_string,
|
||||||
|
struct crypt_params_verity *params);
|
||||||
|
|
||||||
|
int VERITY_activate(struct crypt_device *cd,
|
||||||
|
const char *name,
|
||||||
|
const char *root_hash,
|
||||||
|
size_t root_hash_size,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
uint32_t activation_flags);
|
||||||
|
|
||||||
|
int VERITY_verify(struct crypt_device *cd,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
const char *root_hash,
|
||||||
|
size_t root_hash_size);
|
||||||
|
|
||||||
|
int VERITY_create(struct crypt_device *cd,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
char *root_hash,
|
||||||
|
size_t root_hash_size);
|
||||||
|
|
||||||
|
uint64_t VERITY_hash_offset_block(struct crypt_params_verity *params);
|
||||||
|
|
||||||
|
int VERITY_UUID_generate(struct crypt_device *cd, char **uuid_string);
|
||||||
|
|
||||||
|
#endif
|
||||||
430
lib/verity/verity_hash.c
Normal file
430
lib/verity/verity_hash.c
Normal file
@@ -0,0 +1,430 @@
|
|||||||
|
/*
|
||||||
|
* dm-verity volume handling
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012, Red Hat, Inc. All rights reserved.
|
||||||
|
*
|
||||||
|
* This file is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU Lesser General Public
|
||||||
|
* License as published by the Free Software Foundation; either
|
||||||
|
* version 2.1 of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This file is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
* Lesser General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU Lesser General Public
|
||||||
|
* License along with this file; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <errno.h>
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
|
#include "verity.h"
|
||||||
|
#include "internal.h"
|
||||||
|
|
||||||
|
#define VERITY_MAX_LEVELS 63
|
||||||
|
|
||||||
|
static unsigned get_bits_up(size_t u)
|
||||||
|
{
|
||||||
|
unsigned i = 0;
|
||||||
|
while ((1U << i) < u)
|
||||||
|
i++;
|
||||||
|
return i;
|
||||||
|
}
|
||||||
|
|
||||||
|
static unsigned get_bits_down(size_t u)
|
||||||
|
{
|
||||||
|
unsigned i = 0;
|
||||||
|
while ((u >> i) > 1U)
|
||||||
|
i++;
|
||||||
|
return i;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int verify_zero(struct crypt_device *cd, FILE *wr, size_t bytes)
|
||||||
|
{
|
||||||
|
char block[bytes];
|
||||||
|
size_t i;
|
||||||
|
|
||||||
|
if (fread(block, bytes, 1, wr) != 1) {
|
||||||
|
log_dbg("EIO while reading spare area.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
for (i = 0; i < bytes; i++)
|
||||||
|
if (block[i]) {
|
||||||
|
log_err(cd, _("Spare area is not zeroed at position %" PRIu64 ".\n"),
|
||||||
|
ftello(wr) - bytes);
|
||||||
|
return -EPERM;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int verify_hash_block(const char *hash_name, int version,
|
||||||
|
char *hash, size_t hash_size,
|
||||||
|
const char *data, size_t data_size,
|
||||||
|
const char *salt, size_t salt_size)
|
||||||
|
{
|
||||||
|
struct crypt_hash *ctx = NULL;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (crypt_hash_init(&ctx, hash_name))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (version == 1 && (r = crypt_hash_write(ctx, salt, salt_size)))
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if ((r = crypt_hash_write(ctx, data, data_size)))
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
if (version == 0 && (r = crypt_hash_write(ctx, salt, salt_size)))
|
||||||
|
goto out;
|
||||||
|
|
||||||
|
r = crypt_hash_final(ctx, hash, hash_size);
|
||||||
|
out:
|
||||||
|
crypt_hash_destroy(ctx);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int mult_overflow(off_t *u, off_t b, size_t size)
|
||||||
|
{
|
||||||
|
*u = (uint64_t)b * size;
|
||||||
|
if ((off_t)(*u / size) != b || (off_t)*u < 0)
|
||||||
|
return 1;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int create_or_verify(struct crypt_device *cd, FILE *rd, FILE *wr,
|
||||||
|
off_t data_block, size_t data_block_size,
|
||||||
|
off_t hash_block, size_t hash_block_size,
|
||||||
|
off_t blocks, int version,
|
||||||
|
const char *hash_name, int verify,
|
||||||
|
char *calculated_digest, size_t digest_size,
|
||||||
|
const char *salt, size_t salt_size)
|
||||||
|
{
|
||||||
|
char left_block[hash_block_size];
|
||||||
|
char data_buffer[data_block_size];
|
||||||
|
char read_digest[digest_size];
|
||||||
|
size_t hash_per_block = 1 << get_bits_down(hash_block_size / digest_size);
|
||||||
|
size_t digest_size_full = 1 << get_bits_up(digest_size);
|
||||||
|
off_t blocks_to_write = (blocks + hash_per_block - 1) / hash_per_block;
|
||||||
|
off_t seek_rd, seek_wr;
|
||||||
|
size_t left_bytes;
|
||||||
|
unsigned i;
|
||||||
|
int r;
|
||||||
|
|
||||||
|
if (mult_overflow(&seek_rd, data_block, data_block_size) ||
|
||||||
|
mult_overflow(&seek_wr, hash_block, hash_block_size)) {
|
||||||
|
log_err(cd, _("Device offset overflow.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (fseeko(rd, seek_rd, SEEK_SET)) {
|
||||||
|
log_dbg("Cannot seek to requested position in data device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (wr && fseeko(wr, seek_wr, SEEK_SET)) {
|
||||||
|
log_dbg("Cannot seek to requested position in hash device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
|
||||||
|
memset(left_block, 0, hash_block_size);
|
||||||
|
while (blocks_to_write--) {
|
||||||
|
left_bytes = hash_block_size;
|
||||||
|
for (i = 0; i < hash_per_block; i++) {
|
||||||
|
if (!blocks)
|
||||||
|
break;
|
||||||
|
blocks--;
|
||||||
|
if (fread(data_buffer, data_block_size, 1, rd) != 1) {
|
||||||
|
log_dbg("Cannot read data device block.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (verify_hash_block(hash_name, version,
|
||||||
|
calculated_digest, digest_size,
|
||||||
|
data_buffer, data_block_size,
|
||||||
|
salt, salt_size))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (!wr)
|
||||||
|
break;
|
||||||
|
if (verify) {
|
||||||
|
if (fread(read_digest, digest_size, 1, wr) != 1) {
|
||||||
|
log_dbg("Cannot read digest form hash device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
if (memcmp(read_digest, calculated_digest, digest_size)) {
|
||||||
|
log_err(cd, _("Verification failed at position %" PRIu64 ".\n"),
|
||||||
|
ftello(rd) - data_block_size);
|
||||||
|
return -EPERM;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
if (fwrite(calculated_digest, digest_size, 1, wr) != 1) {
|
||||||
|
log_dbg("Cannot write digest to hash device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (version == 0) {
|
||||||
|
left_bytes -= digest_size;
|
||||||
|
} else {
|
||||||
|
if (digest_size_full - digest_size) {
|
||||||
|
if (verify) {
|
||||||
|
r = verify_zero(cd, wr, digest_size_full - digest_size);
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
} else if (fwrite(left_block, digest_size_full - digest_size, 1, wr) != 1) {
|
||||||
|
log_dbg("Cannot write spare area to hash device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
left_bytes -= digest_size_full;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (wr && left_bytes) {
|
||||||
|
if (verify) {
|
||||||
|
r = verify_zero(cd , wr, left_bytes);
|
||||||
|
if (r)
|
||||||
|
return r;
|
||||||
|
} else if (fwrite(left_block, left_bytes, 1, wr) != 1) {
|
||||||
|
log_dbg("Cannot write remaining spare area to hash device.");
|
||||||
|
return -EIO;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
static int VERITY_create_or_verify_hash(struct crypt_device *cd,
|
||||||
|
int verify,
|
||||||
|
int version,
|
||||||
|
const char *hash_name,
|
||||||
|
struct device *hash_device,
|
||||||
|
struct device *data_device,
|
||||||
|
size_t hash_block_size,
|
||||||
|
size_t data_block_size,
|
||||||
|
off_t data_blocks,
|
||||||
|
off_t hash_position,
|
||||||
|
char *root_hash,
|
||||||
|
size_t digest_size,
|
||||||
|
const char *salt,
|
||||||
|
size_t salt_size)
|
||||||
|
{
|
||||||
|
char calculated_digest[digest_size];
|
||||||
|
FILE *data_file = NULL;
|
||||||
|
FILE *hash_file = NULL, *hash_file_2;
|
||||||
|
off_t hash_level_block[VERITY_MAX_LEVELS];
|
||||||
|
off_t hash_level_size[VERITY_MAX_LEVELS];
|
||||||
|
off_t data_file_blocks, s;
|
||||||
|
size_t hash_per_block_bits;
|
||||||
|
off_t data_device_size = 0, hash_device_size = 0;
|
||||||
|
uint64_t dev_size;
|
||||||
|
int levels, i, r;
|
||||||
|
|
||||||
|
log_dbg("Hash %s %s, data device %s, data blocks %" PRIu64
|
||||||
|
", hash_device %s, offset %" PRIu64 ".",
|
||||||
|
verify ? "verification" : "creation", hash_name,
|
||||||
|
device_path(data_device), data_blocks,
|
||||||
|
device_path(hash_device), hash_position);
|
||||||
|
|
||||||
|
if (data_blocks < 0 || hash_position < 0) {
|
||||||
|
log_err(cd, _("Invalid size parameters for verity device.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!data_blocks) {
|
||||||
|
r = device_size(data_device, &dev_size);
|
||||||
|
if (r < 0)
|
||||||
|
return r;
|
||||||
|
|
||||||
|
data_file_blocks = dev_size / data_block_size;
|
||||||
|
} else
|
||||||
|
data_file_blocks = data_blocks;
|
||||||
|
|
||||||
|
if (mult_overflow(&data_device_size, data_blocks, data_block_size)) {
|
||||||
|
log_err(cd, _("Device offset overflow.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
hash_per_block_bits = get_bits_down(hash_block_size / digest_size);
|
||||||
|
if (!hash_per_block_bits)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
levels = 0;
|
||||||
|
if (data_file_blocks) {
|
||||||
|
while (hash_per_block_bits * levels < 64 &&
|
||||||
|
(data_file_blocks - 1) >> (hash_per_block_bits * levels))
|
||||||
|
levels++;
|
||||||
|
}
|
||||||
|
log_dbg("Using %d hash levels.", levels);
|
||||||
|
|
||||||
|
if (levels > VERITY_MAX_LEVELS) {
|
||||||
|
log_err(cd, _("Too many tree levels for verity volume.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (i = levels - 1; i >= 0; i--) {
|
||||||
|
hash_level_block[i] = hash_position;
|
||||||
|
// verity position of block data_file_blocks at level i
|
||||||
|
s = (data_file_blocks + ((off_t)1 << ((i + 1) * hash_per_block_bits)) - 1) >> ((i + 1) * hash_per_block_bits);
|
||||||
|
hash_level_size[i] = s;
|
||||||
|
if ((hash_position + s) < hash_position ||
|
||||||
|
(hash_position + s) < 0) {
|
||||||
|
log_err(cd, _("Device offset overflow.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
hash_position += s;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (mult_overflow(&hash_device_size, hash_position, hash_block_size)) {
|
||||||
|
log_err(cd, _("Device offset overflow.\n"));
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
|
log_dbg("Data device size required: %" PRIu64 " bytes.",
|
||||||
|
data_device_size);
|
||||||
|
data_file = fopen(device_path(data_device), "r");
|
||||||
|
if (!data_file) {
|
||||||
|
log_err(cd, _("Cannot open device %s.\n"),
|
||||||
|
device_path(data_device)
|
||||||
|
);
|
||||||
|
r = -EIO;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
log_dbg("Hash device size required: %" PRIu64 " bytes.",
|
||||||
|
hash_device_size);
|
||||||
|
hash_file = fopen(device_path(hash_device), verify ? "r" : "r+");
|
||||||
|
if (!hash_file) {
|
||||||
|
log_err(cd, _("Cannot open device %s.\n"),
|
||||||
|
device_path(hash_device));
|
||||||
|
r = -EIO;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
|
||||||
|
memset(calculated_digest, 0, digest_size);
|
||||||
|
|
||||||
|
for (i = 0; i < levels; i++) {
|
||||||
|
if (!i) {
|
||||||
|
r = create_or_verify(cd, data_file, hash_file,
|
||||||
|
0, data_block_size,
|
||||||
|
hash_level_block[i], hash_block_size,
|
||||||
|
data_file_blocks, version, hash_name, verify,
|
||||||
|
calculated_digest, digest_size, salt, salt_size);
|
||||||
|
if (r)
|
||||||
|
goto out;
|
||||||
|
} else {
|
||||||
|
hash_file_2 = fopen(device_path(hash_device), "r");
|
||||||
|
if (!hash_file_2) {
|
||||||
|
log_err(cd, _("Cannot open device %s.\n"),
|
||||||
|
device_path(hash_device));
|
||||||
|
r = -EIO;
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
r = create_or_verify(cd, hash_file_2, hash_file,
|
||||||
|
hash_level_block[i - 1], hash_block_size,
|
||||||
|
hash_level_block[i], hash_block_size,
|
||||||
|
hash_level_size[i - 1], version, hash_name, verify,
|
||||||
|
calculated_digest, digest_size, salt, salt_size);
|
||||||
|
fclose(hash_file_2);
|
||||||
|
if (r)
|
||||||
|
goto out;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (levels)
|
||||||
|
r = create_or_verify(cd, hash_file, NULL,
|
||||||
|
hash_level_block[levels - 1], hash_block_size,
|
||||||
|
0, hash_block_size,
|
||||||
|
1, version, hash_name, verify,
|
||||||
|
calculated_digest, digest_size, salt, salt_size);
|
||||||
|
else
|
||||||
|
r = create_or_verify(cd, data_file, NULL,
|
||||||
|
0, data_block_size,
|
||||||
|
0, hash_block_size,
|
||||||
|
data_file_blocks, version, hash_name, verify,
|
||||||
|
calculated_digest, digest_size, salt, salt_size);
|
||||||
|
out:
|
||||||
|
if (verify) {
|
||||||
|
if (r)
|
||||||
|
log_err(cd, _("Verification of data area failed.\n"));
|
||||||
|
else {
|
||||||
|
log_dbg("Verification of data area succeeded.");
|
||||||
|
r = memcmp(root_hash, calculated_digest, digest_size) ? -EPERM : 0;
|
||||||
|
if (r)
|
||||||
|
log_err(cd, _("Verification of root hash failed.\n"));
|
||||||
|
else
|
||||||
|
log_dbg("Verification of root hash succeeded.");
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
if (r == -EIO)
|
||||||
|
log_err(cd, _("Input/output error while creating hash area.\n"));
|
||||||
|
else if (r)
|
||||||
|
log_err(cd, _("Creation of hash area failed.\n"));
|
||||||
|
else {
|
||||||
|
fsync(fileno(hash_file));
|
||||||
|
memcpy(root_hash, calculated_digest, digest_size);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (data_file)
|
||||||
|
fclose(data_file);
|
||||||
|
if (hash_file)
|
||||||
|
fclose(hash_file);
|
||||||
|
return r;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Verify verity device using userspace crypto backend */
|
||||||
|
int VERITY_verify(struct crypt_device *cd,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
const char *root_hash,
|
||||||
|
size_t root_hash_size)
|
||||||
|
{
|
||||||
|
return VERITY_create_or_verify_hash(cd, 1,
|
||||||
|
verity_hdr->hash_type,
|
||||||
|
verity_hdr->hash_name,
|
||||||
|
crypt_metadata_device(cd),
|
||||||
|
crypt_data_device(cd),
|
||||||
|
verity_hdr->hash_block_size,
|
||||||
|
verity_hdr->data_block_size,
|
||||||
|
verity_hdr->data_size,
|
||||||
|
VERITY_hash_offset_block(verity_hdr),
|
||||||
|
CONST_CAST(char*)root_hash,
|
||||||
|
root_hash_size,
|
||||||
|
verity_hdr->salt,
|
||||||
|
verity_hdr->salt_size);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Create verity hash */
|
||||||
|
int VERITY_create(struct crypt_device *cd,
|
||||||
|
struct crypt_params_verity *verity_hdr,
|
||||||
|
char *root_hash,
|
||||||
|
size_t root_hash_size)
|
||||||
|
{
|
||||||
|
unsigned pgsize = crypt_getpagesize();
|
||||||
|
|
||||||
|
if (verity_hdr->salt_size > 256)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
if (verity_hdr->data_block_size > pgsize)
|
||||||
|
log_err(cd, _("WARNING: Kernel cannot activate device if data "
|
||||||
|
"block size exceeds page size (%u).\n"), pgsize);
|
||||||
|
|
||||||
|
return VERITY_create_or_verify_hash(cd, 0,
|
||||||
|
verity_hdr->hash_type,
|
||||||
|
verity_hdr->hash_name,
|
||||||
|
crypt_metadata_device(cd),
|
||||||
|
crypt_data_device(cd),
|
||||||
|
verity_hdr->hash_block_size,
|
||||||
|
verity_hdr->data_block_size,
|
||||||
|
verity_hdr->data_size,
|
||||||
|
VERITY_hash_offset_block(verity_hdr),
|
||||||
|
root_hash,
|
||||||
|
root_hash_size,
|
||||||
|
verity_hdr->salt,
|
||||||
|
verity_hdr->salt_size);
|
||||||
|
}
|
||||||
@@ -2,11 +2,12 @@
|
|||||||
* cryptsetup volume key implementation
|
* cryptsetup volume key implementation
|
||||||
*
|
*
|
||||||
* Copyright (C) 2004-2006, Clemens Fruhwirth <clemens@endorphin.org>
|
* Copyright (C) 2004-2006, Clemens Fruhwirth <clemens@endorphin.org>
|
||||||
* Copyright (C) 2010-2011, Red Hat, Inc. All rights reserved.
|
* Copyright (C) 2010-2012, Red Hat, Inc. All rights reserved.
|
||||||
*
|
*
|
||||||
* This program is free software; you can redistribute it and/or
|
* This program is free software; you can redistribute it and/or
|
||||||
* modify it under the terms of the GNU General Public License
|
* modify it under the terms of the GNU General Public License
|
||||||
* version 2 as published by the Free Software Foundation.
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
*
|
*
|
||||||
* This program is distributed in the hope that it will be useful,
|
* This program is distributed in the hope that it will be useful,
|
||||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -15,7 +16,7 @@
|
|||||||
*
|
*
|
||||||
* You should have received a copy of the GNU General Public License
|
* You should have received a copy of the GNU General Public License
|
||||||
* along with this program; if not, write to the Free Software
|
* along with this program; if not, write to the Free Software
|
||||||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
@@ -34,7 +35,7 @@ struct volume_key *crypt_alloc_volume_key(unsigned keylength, const char *key)
|
|||||||
if (key)
|
if (key)
|
||||||
memcpy(&vk->key, key, keylength);
|
memcpy(&vk->key, key, keylength);
|
||||||
else
|
else
|
||||||
memset(&vk->key, 0, keylength);
|
crypt_memzero(&vk->key, keylength);
|
||||||
|
|
||||||
return vk;
|
return vk;
|
||||||
}
|
}
|
||||||
@@ -42,7 +43,7 @@ struct volume_key *crypt_alloc_volume_key(unsigned keylength, const char *key)
|
|||||||
void crypt_free_volume_key(struct volume_key *vk)
|
void crypt_free_volume_key(struct volume_key *vk)
|
||||||
{
|
{
|
||||||
if (vk) {
|
if (vk) {
|
||||||
memset(vk->key, 0, vk->keylength);
|
crypt_memzero(vk->key, vk->keylength);
|
||||||
vk->keylength = 0;
|
vk->keylength = 0;
|
||||||
free(vk);
|
free(vk);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,3 +1,11 @@
|
|||||||
man8_MANS = cryptsetup.8
|
man8_MANS = cryptsetup.8
|
||||||
|
|
||||||
EXTRA_DIST = cryptsetup.8
|
if VERITYSETUP
|
||||||
|
man8_MANS += veritysetup.8
|
||||||
|
endif
|
||||||
|
|
||||||
|
if REENCRYPT
|
||||||
|
man8_MANS += cryptsetup-reencrypt.8
|
||||||
|
endif
|
||||||
|
|
||||||
|
EXTRA_DIST = cryptsetup.8 veritysetup.8 cryptsetup-reencrypt.8
|
||||||
|
|||||||
241
man/cryptsetup-reencrypt.8
Normal file
241
man/cryptsetup-reencrypt.8
Normal file
@@ -0,0 +1,241 @@
|
|||||||
|
.TH CRYPTSETUP-REENCRYPT "8" "January 2015" "cryptsetup-reencrypt" "Maintenance Commands"
|
||||||
|
.SH NAME
|
||||||
|
cryptsetup-reencrypt - tool for offline LUKS device re-encryption
|
||||||
|
.SH SYNOPSIS
|
||||||
|
.B cryptsetup-reencrypt <options> <device>
|
||||||
|
.SH DESCRIPTION
|
||||||
|
.PP
|
||||||
|
Cryptsetup-reencrypt can be used to change reencryption parameters
|
||||||
|
which otherwise require full on-disk data change (re-encryption).
|
||||||
|
|
||||||
|
You can regenerate \fBvolume key\fR (the real key used in on-disk encryption
|
||||||
|
unclocked by passphrase), \fBcipher\fR, \fBcipher mode\fR.
|
||||||
|
|
||||||
|
Cryptsetup-reencrypt reencrypts data on LUKS device in-place. During
|
||||||
|
reencryption process the LUKS device is marked unavailable.
|
||||||
|
|
||||||
|
\fIWARNING\fR: The cryptsetup-reencrypt program is not resistant to hardware
|
||||||
|
or kernel failures during reencryption (you can lose you data in this case).
|
||||||
|
|
||||||
|
\fIALWAYS BE SURE YOU HAVE RELIABLE BACKUP BEFORE USING THIS TOOL.\fR
|
||||||
|
.br
|
||||||
|
The reencryption can be temporarily suspended (by TERM signal or by
|
||||||
|
using ctrl+c) but you need to retain temporary files named LUKS-<uuid>.[log|org|new].
|
||||||
|
LUKS device is unavailable until reencryption is finished though.
|
||||||
|
|
||||||
|
Current working directory must by writable and temporary
|
||||||
|
files created during reencryption must be present.
|
||||||
|
|
||||||
|
For more info about LUKS see cryptsetup(8).
|
||||||
|
.PP
|
||||||
|
.SH OPTIONS
|
||||||
|
.TP
|
||||||
|
To start (or continue) re-encryption for <device> use:
|
||||||
|
.PP
|
||||||
|
\fIcryptsetup-reencrypt\fR <device>
|
||||||
|
|
||||||
|
\fB<options>\fR can be [\-\-batch-mode, \-\-block-size, \-\-cipher, \-\-debug,
|
||||||
|
\-\-device-size, \-\-hash, \-\-iter-time, \-\-use-random | \-\-use-urandom,
|
||||||
|
\-\-keep-key, \-\-key-size, \-\-key-file, \-\-key-slot, \-\-keyfile-offset,
|
||||||
|
\-\-keyfile-size, \-\-tries, \-\-use-directio, \-\-use-fsync, \-\-verbose, \-\-write-log,
|
||||||
|
\-\-uuid]
|
||||||
|
|
||||||
|
To encrypt data on (not yet encrypted) device, use \fI\-\-new\fR with combination
|
||||||
|
with \fI\-\-reduce-device-size\fR.
|
||||||
|
|
||||||
|
To remove encryption from device, use \fI\-\-decrypt\fR.
|
||||||
|
|
||||||
|
For detailed description of encryption and key file options see \fIcryptsetup(8)\fR
|
||||||
|
man page.
|
||||||
|
.TP
|
||||||
|
.B "\-\-verbose, \-v"
|
||||||
|
Print more information on command execution.
|
||||||
|
.TP
|
||||||
|
.B "\-\-debug"
|
||||||
|
Run in debug mode with full diagnostic logs. Debug output
|
||||||
|
lines are always prefixed by '#'.
|
||||||
|
.TP
|
||||||
|
.B "\-\-cipher, \-c" \fI<cipher-spec>\fR
|
||||||
|
Set the cipher specification string.
|
||||||
|
.TP
|
||||||
|
.B "\-\-key-size, \-s \fI<bits>\fR"
|
||||||
|
Set key size in bits. The argument has to be a multiple of 8.
|
||||||
|
|
||||||
|
The possible key-sizes are limited by the cipher and mode used.
|
||||||
|
|
||||||
|
If you are increasing key size, there must be enough space in the LUKS header
|
||||||
|
for enlarged keyslots (data offset must be large enough) or reencryption
|
||||||
|
cannot be performed.
|
||||||
|
|
||||||
|
If there is not enough space for keyslots with new key size,
|
||||||
|
you can destructively shrink device with \-\-reduce-device-size option.
|
||||||
|
.TP
|
||||||
|
.B "\-\-hash, \-h \fI<hash-spec>\fR"
|
||||||
|
Specifies the hash used in the LUKS key setup scheme and volume key digest.
|
||||||
|
|
||||||
|
\fBNOTE:\fR if this parameter is not specified, default hash algorithm is always used
|
||||||
|
for new device header.
|
||||||
|
.TP
|
||||||
|
.B "\-\-iter-time, \-i \fI<milliseconds>\fR"
|
||||||
|
The number of milliseconds to spend with PBKDF2 passphrase processing for the
|
||||||
|
new LUKS header.
|
||||||
|
.TP
|
||||||
|
.B "\-\-use-random"
|
||||||
|
.TP
|
||||||
|
.B "\-\-use-urandom"
|
||||||
|
Define which kernel random number generator will be used to create the volume key.
|
||||||
|
.TP
|
||||||
|
.B "\-\-key-file, \-d \fIname\fR"
|
||||||
|
Read the passphrase from file.
|
||||||
|
|
||||||
|
\fBWARNING:\fR \-\-key-file option can be used only if there only one active keyslot,
|
||||||
|
or alternatively, also if \-\-key-slot option is specified (then all other keyslots
|
||||||
|
will be disabled in new LUKS device).
|
||||||
|
|
||||||
|
If this option is not used, cryptsetup-reencrypt will ask for all active keyslot
|
||||||
|
passphrases.
|
||||||
|
.TP
|
||||||
|
.B "\-\-key-slot, \-S <0-7>"
|
||||||
|
Specify which key slot is used.
|
||||||
|
|
||||||
|
\fBWARNING:\fR All other keyslots will be disabled if this option is used.
|
||||||
|
.TP
|
||||||
|
.B "\-\-keyfile-offset \fIvalue\fR"
|
||||||
|
Skip \fIvalue\fR bytes at the beginning of the key file.
|
||||||
|
.TP
|
||||||
|
.B "\-\-keyfile-size, \-l"
|
||||||
|
Read a maximum of \fIvalue\fR bytes from the key file.
|
||||||
|
Default is to read the whole file up to the compiled-in
|
||||||
|
maximum.
|
||||||
|
.TP
|
||||||
|
.B "\-\-keep-key"
|
||||||
|
Do not change encryption key, just reencrypt the LUKS header and keyslots.
|
||||||
|
|
||||||
|
This option can be combined only with \fI\-\-hash\fR or \fI\-\-iter-time\fR
|
||||||
|
options.
|
||||||
|
.TP
|
||||||
|
.B "\-\-tries, \-T"
|
||||||
|
Number of retries for invalid passphrase entry.
|
||||||
|
.TP
|
||||||
|
.B "\-\-block-size, \-B \fIvalue\fR"
|
||||||
|
Use re-encryption block size of <value> in MiB.
|
||||||
|
|
||||||
|
Values can be between 1 and 64 MiB.
|
||||||
|
.TP
|
||||||
|
.B "\-\-device-size \fIsize[units]\fR"
|
||||||
|
Instead of real device size, use specified value.
|
||||||
|
|
||||||
|
It means that only specified area (from the start of the device
|
||||||
|
to the specified size) will be reencrypted.
|
||||||
|
|
||||||
|
\fBWARNING:\fR This is destructive operation.
|
||||||
|
|
||||||
|
If no unit suffix is specified, the size is in bytes.
|
||||||
|
|
||||||
|
Unit suffix can be S for 512 byte sectors, K/M/G/T (or KiB,MiB,GiB,TiB)
|
||||||
|
for units with 1024 base or KB/MB/GB/TB for 1000 base (SI scale).
|
||||||
|
|
||||||
|
\fBWARNING:\fR This is destructive operation.
|
||||||
|
.TP
|
||||||
|
.B "\-\-reduce-device-size \fIsize[units]\fR"
|
||||||
|
Enlarge data offset to specified value by shrinking device size.
|
||||||
|
|
||||||
|
This means that last sectors on the original device will be lost,
|
||||||
|
ciphertext data will be effectively shifted by specified
|
||||||
|
number of sectors.
|
||||||
|
|
||||||
|
It can be useful if you e.g. added some space to underlying
|
||||||
|
partition (so last sectors contains no data).
|
||||||
|
|
||||||
|
For units suffix see \-\-device-size parameter description.
|
||||||
|
|
||||||
|
\fBWARNING:\fR This is destructive operation and cannot be reverted.
|
||||||
|
Use with extreme care - shrinked filesystems are usually unrecoverable.
|
||||||
|
|
||||||
|
You cannot shrink device more than by 64 MiB (131072 sectors).
|
||||||
|
.TP
|
||||||
|
.B "\-\-new, \-N"
|
||||||
|
Create new header (encrypt not yet encrypted device).
|
||||||
|
|
||||||
|
This option must be used together with \-\-reduce-device-size.
|
||||||
|
|
||||||
|
\fBWARNING:\fR This is destructive operation and cannot be reverted.
|
||||||
|
.TP
|
||||||
|
.B "\-\-decrypt"
|
||||||
|
Remove encryption (decrypt already encrypted device and remove LUKS header).
|
||||||
|
|
||||||
|
\fBWARNING:\fR This is destructive operation and cannot be reverted.
|
||||||
|
.TP
|
||||||
|
.B "\-\-use-directio"
|
||||||
|
Use direct-io (O_DIRECT) for all read/write data operations related
|
||||||
|
to block device undergoing reencryption.
|
||||||
|
|
||||||
|
Useful if direct-io operations perform better than normal buffered
|
||||||
|
operations (e.g. in virtual environments).
|
||||||
|
.TP
|
||||||
|
.B "\-\-use-fsync"
|
||||||
|
Use fsync call after every written block. This applies for reencryption
|
||||||
|
log files as well.
|
||||||
|
.TP
|
||||||
|
.B "\-\-write-log"
|
||||||
|
Update log file after every block write. This can slow down reencryption
|
||||||
|
but will minimize data loss in the case of system crash.
|
||||||
|
.TP
|
||||||
|
.B "\-\-uuid" \fI<uuid>\fR
|
||||||
|
Use only while resuming an interrupted decryption process (see \-\-decrypt).
|
||||||
|
To find out what \fI<uuid>\fR to pass look for temporary files LUKS-<uuid>.[|log|org|new] of the
|
||||||
|
interrupted decryption process.
|
||||||
|
.TP
|
||||||
|
.B "\-\-batch-mode, \-q"
|
||||||
|
Suppresses all warnings and reencryption progress output.
|
||||||
|
.TP
|
||||||
|
.B "\-\-version"
|
||||||
|
Show the program version.
|
||||||
|
.SH RETURN CODES
|
||||||
|
Cryptsetup-reencrypt returns 0 on success and a non-zero value on error.
|
||||||
|
|
||||||
|
Error codes are: 1 wrong parameters, 2 no permission,
|
||||||
|
3 out of memory, 4 wrong device specified, 5 device already exists
|
||||||
|
or device is busy.
|
||||||
|
.SH EXAMPLES
|
||||||
|
.TP
|
||||||
|
Reencrypt /dev/sdb1 (change volume key)
|
||||||
|
cryptsetup-reencrypt /dev/sdb1
|
||||||
|
.TP
|
||||||
|
Reencrypt and also change cipher and cipher mode
|
||||||
|
cryptsetup-reencrypt /dev/sdb1 \-c aes-xts-plain64
|
||||||
|
.TP
|
||||||
|
Add LUKS encryption to not yet encrypted device
|
||||||
|
|
||||||
|
First, be sure you have space added to disk.
|
||||||
|
|
||||||
|
Or alternatively shrink filesystem in advance.
|
||||||
|
.br
|
||||||
|
Here we need 4096 512-bytes sectors (enough for 2x128 bit key).
|
||||||
|
|
||||||
|
fdisk \-u /dev/sdb # move sdb1 partition end + 4096 sectors
|
||||||
|
(or use resize2fs or tool for your filesystem and shrink it)
|
||||||
|
|
||||||
|
cryptsetup-reencrypt /dev/sdb1 \-\-new \-\-reduce-device-size 4096S
|
||||||
|
.TP
|
||||||
|
Remove LUKS encryption completely
|
||||||
|
|
||||||
|
cryptsetup-reencrypt /dev/sdb1 \-\-decrypt
|
||||||
|
|
||||||
|
.SH REPORTING BUGS
|
||||||
|
Report bugs, including ones in the documentation, on
|
||||||
|
the cryptsetup mailing list at <dm-crypt@saout.de>
|
||||||
|
or in the 'Issues' section on LUKS website.
|
||||||
|
Please attach the output of the failed command with the
|
||||||
|
\-\-debug option added.
|
||||||
|
.SH AUTHORS
|
||||||
|
Cryptsetup-reencrypt was written by Milan Broz <gmazyland@gmail.com>.
|
||||||
|
.SH COPYRIGHT
|
||||||
|
Copyright \(co 2012-2015 Milan Broz
|
||||||
|
.br
|
||||||
|
Copyright \(co 2012-2013 Red Hat, Inc.
|
||||||
|
|
||||||
|
This is free software; see the source for copying conditions. There is NO
|
||||||
|
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
|
||||||
|
.SH SEE ALSO
|
||||||
|
The project website at \fBhttps://gitlab.com/cryptsetup/cryptsetup\fR
|
||||||
1237
man/cryptsetup.8
1237
man/cryptsetup.8
File diff suppressed because it is too large
Load Diff
162
man/veritysetup.8
Normal file
162
man/veritysetup.8
Normal file
@@ -0,0 +1,162 @@
|
|||||||
|
.TH VERITYSETUP "8" "December 2013" "veritysetup" "Maintenance Commands"
|
||||||
|
.SH NAME
|
||||||
|
veritysetup - manage dm-verity (block level verification) volumes
|
||||||
|
.SH SYNOPSIS
|
||||||
|
.B veritysetup <options> <action> <action args>
|
||||||
|
.SH DESCRIPTION
|
||||||
|
.PP
|
||||||
|
Veritysetup is used to configure dm-verity managed device-mapper mappings.
|
||||||
|
|
||||||
|
Device-mapper verity target provides read-only transparent integrity
|
||||||
|
checking of block devices using kernel crypto API.
|
||||||
|
|
||||||
|
The dm-verity devices are always read-only.
|
||||||
|
|
||||||
|
Veritysetup supports these operations:
|
||||||
|
.PP
|
||||||
|
\fIformat\fR <data_device> <hash_device>
|
||||||
|
.IP
|
||||||
|
Calculates and permanently stores hash verification data for data_device.
|
||||||
|
Hash area can be located on the same device after data if specified
|
||||||
|
by \-\-hash\-offset option.
|
||||||
|
|
||||||
|
Note you need to provide root hash string for device verification
|
||||||
|
or activation. Root hash must be trusted.
|
||||||
|
|
||||||
|
The data or hash device argument can be block device or file image.
|
||||||
|
If hash device path doesn't exist, it will be created as file.
|
||||||
|
|
||||||
|
\fB<options>\fR can be [\-\-hash, \-\-no-superblock, \-\-format,
|
||||||
|
\-\-data-block-size, \-\-hash-block-size, \-\-data-blocks, \-\-hash-offset,
|
||||||
|
\-\-salt, \-\-uuid]
|
||||||
|
.PP
|
||||||
|
\fIcreate\fR <name> <data_device> <hash_device> <root_hash>
|
||||||
|
.IP
|
||||||
|
Creates a mapping with <name> backed by device <data_device> and using
|
||||||
|
<hash_device> for in-kernel verification.
|
||||||
|
|
||||||
|
The <root_hash> is a hexadecimal string.
|
||||||
|
|
||||||
|
\fB<options>\fR can be [\-\-hash-offset, \-\-no-superblock,
|
||||||
|
\-\-ignore-corruption or \-\-restart-on-corruption, \-\-ignore-zero-blocks]
|
||||||
|
|
||||||
|
If option \-\-no-superblock is used, you have to use as the same options
|
||||||
|
as in initial format operation.
|
||||||
|
.PP
|
||||||
|
\fIverify\fR <data_device> <hash_device> <root_hash>
|
||||||
|
.IP
|
||||||
|
Verifies data on data_device with use of hash blocks stored on hash_device.
|
||||||
|
|
||||||
|
This command performs userspace verification, no kernel device is created.
|
||||||
|
|
||||||
|
The <root_hash> is a hexadecimal string.
|
||||||
|
|
||||||
|
\fB<options>\fR can be [\-\-hash-offset, \-\-no-superblock]
|
||||||
|
|
||||||
|
If option \-\-no-superblock is used, you have to use as the same options
|
||||||
|
as in initial format operation.
|
||||||
|
.PP
|
||||||
|
\fIremove\fR <name>
|
||||||
|
.IP
|
||||||
|
Removes existing mapping <name>.
|
||||||
|
.PP
|
||||||
|
\fIstatus\fR <name>
|
||||||
|
.IP
|
||||||
|
Reports status for the active verity mapping <name>.
|
||||||
|
.PP
|
||||||
|
\fIdump\fR <hash_device>
|
||||||
|
.IP
|
||||||
|
Reports parameters of verity device from on-disk stored superblock.
|
||||||
|
|
||||||
|
\fB<options>\fR can be [\-\-no-superblock]
|
||||||
|
.SH OPTIONS
|
||||||
|
.TP
|
||||||
|
.B "\-\-verbose, \-v"
|
||||||
|
Print more information on command execution.
|
||||||
|
.TP
|
||||||
|
.B "\-\-debug"
|
||||||
|
Run in debug mode with full diagnostic logs. Debug output
|
||||||
|
lines are always prefixed by '#'.
|
||||||
|
.TP
|
||||||
|
.B "\-\-no-superblock"
|
||||||
|
Create or use dm-verity without permanent on-disk superblock.
|
||||||
|
.TP
|
||||||
|
.B "\-\-format=number"
|
||||||
|
Specifies the hash version type.
|
||||||
|
Format type 0 is original Chrome OS verion. Format type 1 is current version.
|
||||||
|
.TP
|
||||||
|
.B "\-\-data-block-size=bytes"
|
||||||
|
Used block size for the data device.
|
||||||
|
(Note kernel supports only page-size as maximum here.)
|
||||||
|
.TP
|
||||||
|
.B "\-\-hash-block-size=bytes"
|
||||||
|
Used block size for the hash device.
|
||||||
|
(Note kernel supports only page-size as maximum here.)
|
||||||
|
.TP
|
||||||
|
.B "\-\-data-blocks=blocks"
|
||||||
|
Size of data device used in verification.
|
||||||
|
If not specified, the whole device is used.
|
||||||
|
.TP
|
||||||
|
.B "\-\-hash-offset=bytes"
|
||||||
|
Offset of hash area/superblock on hash_device.
|
||||||
|
Value must be aligned to disk sector offset.
|
||||||
|
.TP
|
||||||
|
.B "\-\-salt=hex string"
|
||||||
|
Salt used for format or verification.
|
||||||
|
Format is a hexadecimal string.
|
||||||
|
.TP
|
||||||
|
.B "\-\-uuid=UUID"
|
||||||
|
Use the provided UUID for format command instead of generating new one.
|
||||||
|
|
||||||
|
The UUID must be provided in standard UUID format,
|
||||||
|
e.g. 12345678-1234-1234-1234-123456789abc.
|
||||||
|
.TP
|
||||||
|
.B "\-\-ignore-corruption", "\-\-restart-on-corruption"
|
||||||
|
Defines what to do if data integrity problem is detected (data corruption).
|
||||||
|
|
||||||
|
Without these options kernel fails the IO operation with I/O error.
|
||||||
|
With \-\-ignore-corruption option the corruption is only logged.
|
||||||
|
With \-\-restart-on-corruption the kernel is restarted immediatelly.
|
||||||
|
(You have to provide way how to avoid restart loops.)
|
||||||
|
|
||||||
|
\fBWARNING:\fR Use these options only for very specific cases.
|
||||||
|
These options are available since Linux kernel version 4.1.
|
||||||
|
.TP
|
||||||
|
.B "\-\-ignore-zero-blocks"
|
||||||
|
Instruct kernel to not verify blocks that are expected to contain zeroes
|
||||||
|
and always directly return zeroes instead.
|
||||||
|
|
||||||
|
\fBWARNING:\fR Use this option only in very specific cases.
|
||||||
|
This option is available since Linux kernel version 4.5.
|
||||||
|
.TP
|
||||||
|
.B "\-\-version"
|
||||||
|
Show the program version.
|
||||||
|
.SH RETURN CODES
|
||||||
|
Veritysetup returns 0 on success and a non-zero value on error.
|
||||||
|
|
||||||
|
Error codes are: 1 wrong parameters, 2 no permission,
|
||||||
|
3 out of memory, 4 wrong device specified, 5 device already exists
|
||||||
|
or device is busy.
|
||||||
|
.SH REPORTING BUGS
|
||||||
|
Report bugs, including ones in the documentation, on
|
||||||
|
the cryptsetup mailing list at <dm-crypt@saout.de>
|
||||||
|
or in the 'Issues' section on LUKS website.
|
||||||
|
Please attach the output of the failed command with the
|
||||||
|
\-\-debug option added.
|
||||||
|
.SH AUTHORS
|
||||||
|
The first implementation of veritysetup was written by Chrome OS authors.
|
||||||
|
|
||||||
|
This version is based on verification code written by Mikulas Patocka <mpatocka@redhat.com>
|
||||||
|
and rewritten for libcryptsetup by Milan Broz <gmazyland@gmail.com>.
|
||||||
|
.SH COPYRIGHT
|
||||||
|
Copyright \(co 2012-2016 Red Hat, Inc.
|
||||||
|
.br
|
||||||
|
Copyright \(co 2012-2016 Milan Broz
|
||||||
|
|
||||||
|
This is free software; see the source for copying conditions. There is NO
|
||||||
|
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
|
||||||
|
.SH SEE ALSO
|
||||||
|
The project website at \fBhttps://gitlab.com/cryptsetup/cryptsetup\fR
|
||||||
|
|
||||||
|
The verity on-disk format specification available at
|
||||||
|
\fBhttps://gitlab.com/cryptsetup/cryptsetup/wikis/DMVerity\fR
|
||||||
17
misc/11-dm-crypt.rules
Normal file
17
misc/11-dm-crypt.rules
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
# Old udev rules historically used in device-mapper.
|
||||||
|
# No need to install these until you have some weird configuration.
|
||||||
|
# (Code internally set the same flags.)
|
||||||
|
|
||||||
|
ACTION!="add|change", GOTO="crypt_end"
|
||||||
|
ENV{DM_UDEV_RULES_VSN}!="?*", GOTO="crypt_end"
|
||||||
|
|
||||||
|
ENV{DM_UUID}=="CRYPT-TEMP-?*", GOTO="crypt_disable"
|
||||||
|
ENV{DM_UUID}!="?*", ENV{DM_NAME}=="temporary-cryptsetup-?*", GOTO="crypt_disable"
|
||||||
|
GOTO="crypt_end"
|
||||||
|
|
||||||
|
LABEL="crypt_disable"
|
||||||
|
ENV{DM_UDEV_DISABLE_SUBSYSTEM_RULES_FLAG}="1"
|
||||||
|
ENV{DM_UDEV_DISABLE_DISK_RULES_FLAG}="1"
|
||||||
|
ENV{DM_UDEV_DISABLE_OTHER_RULES_FLAG}="1"
|
||||||
|
|
||||||
|
LABEL="crypt_end"
|
||||||
17
misc/dict_search/Makefile
Normal file
17
misc/dict_search/Makefile
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
TARGET=crypt_dict
|
||||||
|
CFLAGS=-O2 -g -Wall -D_GNU_SOURCE
|
||||||
|
LDLIBS=-lcryptsetup
|
||||||
|
CC=gcc
|
||||||
|
|
||||||
|
SOURCES=$(wildcard *.c)
|
||||||
|
OBJECTS=$(SOURCES:.c=.o)
|
||||||
|
|
||||||
|
all: $(TARGET)
|
||||||
|
|
||||||
|
$(TARGET): $(OBJECTS)
|
||||||
|
$(CC) -o $@ $^ $(LDLIBS)
|
||||||
|
|
||||||
|
clean:
|
||||||
|
rm -f *.o *~ core $(TARGET)
|
||||||
|
|
||||||
|
.PHONY: clean
|
||||||
22
misc/dict_search/README
Normal file
22
misc/dict_search/README
Normal file
@@ -0,0 +1,22 @@
|
|||||||
|
Simple example how to use libcryptsetup
|
||||||
|
for password search.
|
||||||
|
|
||||||
|
Run: crypt_dict luks|tcrypt <device|image> <dictionary> [cpus]
|
||||||
|
|
||||||
|
luks|tcrypt specified device type (LUKS or TrueCrypt)
|
||||||
|
|
||||||
|
<device|image> is LUKS or TrueCrypt device or image
|
||||||
|
|
||||||
|
<dictionary> is list of passphrases to try
|
||||||
|
(note trailing EOL is stripped)
|
||||||
|
|
||||||
|
cpus - number of processes to start in parallel
|
||||||
|
|
||||||
|
Format of dictionary file is simple one password per line,
|
||||||
|
if first char on line s # it is skiped as comment.
|
||||||
|
|
||||||
|
For LUKS, you have it run as root (device-mapper cannot
|
||||||
|
create dmcrypt devices as nrmal user. Code need
|
||||||
|
to map keyslots as temporary dmcrypt device.)
|
||||||
|
|
||||||
|
For TrueCrypt devices root privilege is not required.
|
||||||
158
misc/dict_search/crypt_dict.c
Normal file
158
misc/dict_search/crypt_dict.c
Normal file
@@ -0,0 +1,158 @@
|
|||||||
|
/*
|
||||||
|
* Example of LUKS/TrueCrypt password dictionary search
|
||||||
|
*
|
||||||
|
* Copyright (C) 2012 Milan Broz <gmazyland@gmail.com>
|
||||||
|
*
|
||||||
|
* Run this (for LUKS as root),
|
||||||
|
* e.g. ./crypt_dict test.img /usr/share/john/password.lst 4
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of the GNU General Public License
|
||||||
|
* as published by the Free Software Foundation; either version 2
|
||||||
|
* of the License, or (at your option) any later version.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful,
|
||||||
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
* GNU General Public License for more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program; if not, write to the Free Software
|
||||||
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <string.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
#include <sys/types.h>
|
||||||
|
#include <sys/wait.h>
|
||||||
|
#include <sys/prctl.h>
|
||||||
|
#include <sys/time.h>
|
||||||
|
#include <sys/resource.h>
|
||||||
|
#include <libcryptsetup.h>
|
||||||
|
|
||||||
|
#define MAX_LEN 512
|
||||||
|
|
||||||
|
static enum { LUKS, TCRYPT } device_type;
|
||||||
|
|
||||||
|
static void check(struct crypt_device *cd, const char *pwd_file, unsigned my_id, unsigned max_id)
|
||||||
|
{
|
||||||
|
FILE *f;
|
||||||
|
int len, r = -1;
|
||||||
|
unsigned long line = 0;
|
||||||
|
char pwd[MAX_LEN];
|
||||||
|
|
||||||
|
if (fork())
|
||||||
|
return;
|
||||||
|
|
||||||
|
/* open password file, now in separate process */
|
||||||
|
f = fopen(pwd_file, "r");
|
||||||
|
if (!f) {
|
||||||
|
printf("Cannot open %s.\n", pwd_file);
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
while (fgets(pwd, MAX_LEN, f)) {
|
||||||
|
|
||||||
|
/* every process tries N-th line, skip others */
|
||||||
|
if (line++ % max_id != my_id)
|
||||||
|
continue;
|
||||||
|
|
||||||
|
len = strlen(pwd);
|
||||||
|
|
||||||
|
/* strip EOL - this is like a input from tty */
|
||||||
|
if (len && pwd[len - 1] == '\n') {
|
||||||
|
pwd[len - 1] = '\0';
|
||||||
|
len--;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* lines starting "#!comment" are comments */
|
||||||
|
if (len >= 9 && !strncmp(pwd, "#!comment", 9)) {
|
||||||
|
/* printf("skipping %s\n", pwd); */
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* printf("%d: checking %s\n", my_id, pwd); */
|
||||||
|
if (device_type == LUKS)
|
||||||
|
r = crypt_activate_by_passphrase(cd, NULL, CRYPT_ANY_SLOT, pwd, len, 0);
|
||||||
|
else if (device_type == TCRYPT) {
|
||||||
|
struct crypt_params_tcrypt params = {
|
||||||
|
.flags = CRYPT_TCRYPT_LEGACY_MODES,
|
||||||
|
.passphrase = pwd,
|
||||||
|
.passphrase_size = len,
|
||||||
|
};
|
||||||
|
r = crypt_load(cd, CRYPT_TCRYPT, ¶ms);
|
||||||
|
}
|
||||||
|
if (r >= 0) {
|
||||||
|
printf("Found passphrase for slot %d: \"%s\"\n", r, pwd);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fclose(f);
|
||||||
|
crypt_free(cd);
|
||||||
|
exit(r >= 0 ? 2 : EXIT_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
|
int main(int argc, char *argv[])
|
||||||
|
{
|
||||||
|
int i, status, procs = 4;
|
||||||
|
struct crypt_device *cd;
|
||||||
|
|
||||||
|
if (argc < 4 || argc > 5) {
|
||||||
|
printf("Use: %s luks|tcrypt <device|file> <password file> [#processes] %d\n", argv[0], argc);
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (argc == 5 && (sscanf(argv[4], "%i", &procs) != 1 || procs < 1)) {
|
||||||
|
printf("Wrong number of processes.\n");
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!strcmp(argv[1], "luks"))
|
||||||
|
device_type = LUKS;
|
||||||
|
else if (!strcmp(argv[1], "tcrypt"))
|
||||||
|
device_type = TCRYPT;
|
||||||
|
else {
|
||||||
|
printf("Wrong device type %s.\n", argv[1]);
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* crypt_set_debug_level(CRYPT_DEBUG_ALL); */
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Need to create temporary keyslot device-mapper devices and allocate loop if needed,
|
||||||
|
* so root is requried here.
|
||||||
|
*/
|
||||||
|
if (getuid() != 0) {
|
||||||
|
printf("You must be root to run this program.\n");
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* signal all children if anything happens */
|
||||||
|
prctl(PR_SET_PDEATHSIG, SIGHUP);
|
||||||
|
setpriority(PRIO_PROCESS, 0, -5);
|
||||||
|
|
||||||
|
/* we are not going to modify anything, so common init is ok */
|
||||||
|
if (crypt_init(&cd, argv[2]) ||
|
||||||
|
(device_type == LUKS && crypt_load(cd, CRYPT_LUKS1, NULL))) {
|
||||||
|
printf("Cannot open %s.\n", argv[2]);
|
||||||
|
exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* run scan in separate processes, it is up to scheduler to assign CPUs inteligently */
|
||||||
|
for (i = 0; i < procs; i++)
|
||||||
|
check(cd, argv[3], i, procs);
|
||||||
|
|
||||||
|
/* wait until at least one finishes with error or status 2 (key found) */
|
||||||
|
while (wait(&status) != -1 && WIFEXITED(status)) {
|
||||||
|
if (WEXITSTATUS(status) == EXIT_SUCCESS)
|
||||||
|
continue;
|
||||||
|
/* kill rest of processes */
|
||||||
|
kill(0, SIGHUP);
|
||||||
|
/* not reached */
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
exit(0);
|
||||||
|
}
|
||||||
40
misc/dracut_90reencrypt/README
Normal file
40
misc/dracut_90reencrypt/README
Normal file
@@ -0,0 +1,40 @@
|
|||||||
|
Example of simple dracut module for reencryption of system
|
||||||
|
LUKS drive on-the-fly.
|
||||||
|
|
||||||
|
Install in /usr/[share|lib]/dracut/modules.d/90reencrypt, then
|
||||||
|
build special intramfs "with dracut -a reencrypt -o crypt".
|
||||||
|
Reencrypt module doesn't work (has a conflict) with crypt module as
|
||||||
|
of now. After successfull reencryption reboot using original initramfs.
|
||||||
|
|
||||||
|
Dracut then recognize argument rd.luks.reencrypt=name:size,
|
||||||
|
e.g. rd.luks.reencrypt=sda2:52G means only 52G of device
|
||||||
|
will be reencrypted (default is whole device).
|
||||||
|
(Name is kernel name of device.)
|
||||||
|
|
||||||
|
If there's more than single active keyslot in the target luks device
|
||||||
|
you're required to select one keyslot explicitly for reencryption via
|
||||||
|
rd.luks.reencrypt_keyslot=<keyslot_number> option. Bear in mind that
|
||||||
|
if you use this option, all other keyslots will get deactivated in the
|
||||||
|
process.
|
||||||
|
|
||||||
|
Another argument, rd.luks.reencrypt_key=/dev/sda:/path/to/keyfile
|
||||||
|
can be used to read password for specific keyslot from device containing
|
||||||
|
filesystem with a keyfile (file with a password). If you omit reencrypt_key
|
||||||
|
argument, reencryption would work only in case a LUKS container has
|
||||||
|
exactly one keyslot activated.
|
||||||
|
|
||||||
|
Arguments rd.luks.reencrypt_keyslot and rd.luks.reencrypt_key are not
|
||||||
|
mandatory.
|
||||||
|
|
||||||
|
Note that reencryption context is stored in ramdisk, any
|
||||||
|
fail can mean complete lost of data!
|
||||||
|
|
||||||
|
Copyright (C) 2012 Milan Broz <gmazyland@gmail.com>
|
||||||
|
|
||||||
|
This copyrighted material is made available to anyone wishing to use,
|
||||||
|
modify, copy, or redistribute it subject to the terms and conditions
|
||||||
|
of the GNU General Public License v.2.
|
||||||
|
|
||||||
|
You should have received a copy of the GNU General Public License
|
||||||
|
along with this program; if not, write to the Free Software Foundation,
|
||||||
|
Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
5
misc/dracut_90reencrypt/check.old
Executable file
5
misc/dracut_90reencrypt/check.old
Executable file
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
which cryptsetup-reencrypt >/dev/null 2>&1 || exit 1
|
||||||
|
|
||||||
|
exit 0
|
||||||
6
misc/dracut_90reencrypt/install.old
Executable file
6
misc/dracut_90reencrypt/install.old
Executable file
@@ -0,0 +1,6 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
inst cryptsetup-reencrypt
|
||||||
|
|
||||||
|
inst_hook cmdline 30 "$moddir/parse-reencrypt.sh"
|
||||||
|
inst "$moddir"/reencrypt.sh /sbin/reencrypt
|
||||||
31
misc/dracut_90reencrypt/module-setup.sh
Executable file
31
misc/dracut_90reencrypt/module-setup.sh
Executable file
@@ -0,0 +1,31 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
check() {
|
||||||
|
[ -x /sbin/cryptsetup-reencrypt ] || return 1
|
||||||
|
return 255
|
||||||
|
}
|
||||||
|
|
||||||
|
depends() {
|
||||||
|
echo dm rootfs-block
|
||||||
|
}
|
||||||
|
|
||||||
|
installkernel() {
|
||||||
|
# requires hostonly='' override so that loop module is pulled in initramfs
|
||||||
|
# even if not loaded in actual kernel. dracut bug?
|
||||||
|
hostonly='' instmods dm_crypt =crypto loop
|
||||||
|
}
|
||||||
|
|
||||||
|
install() {
|
||||||
|
if dracut_module_included crypt; then
|
||||||
|
derror "'reencrypt' can't be installed together with 'crypt'."
|
||||||
|
derror "Add '-o crypt' option to install reencrypt module."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
dracut_install cryptsetup-reencrypt
|
||||||
|
|
||||||
|
# moddir variable is assigned in dracut general shell lib
|
||||||
|
# shellcheck disable=SC2154
|
||||||
|
inst_hook cmdline 30 "$moddir/parse-reencrypt.sh"
|
||||||
|
inst_simple "$moddir"/reencrypt.sh /sbin/reencrypt
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user