1 /* libguestfs - the guestfsd daemon
2 * Copyright (C) 2010 Red Hat Inc.
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
27 #include "optgroups.h"
32 optgroup_luks_available (void)
34 return prog_exists ("cryptsetup");
37 /* Callers must also call remove_temp (tempfile). */
39 write_key_to_temp (const char *key)
41 char *tempfile = strdup ("/tmp/luksXXXXXX");
43 reply_with_perror ("strdup");
47 int fd = mkstemp (tempfile);
49 reply_with_perror ("mkstemp");
53 size_t len = strlen (key);
54 if (xwrite (fd, key, len) == -1) {
55 reply_with_perror ("write");
60 if (close (fd) == -1) {
61 reply_with_perror ("close");
74 remove_temp (char *tempfile)
81 luks_open (const char *device, const char *key, const char *mapname,
84 /* Sanity check: /dev/mapper/mapname must not exist already. Note
85 * that the device-mapper control device (/dev/mapper/control) is
86 * always there, so you can't ever have mapname == "control".
88 size_t len = strlen (mapname);
89 char devmapper[len+32];
90 snprintf (devmapper, len+32, "/dev/mapper/%s", mapname);
91 if (access (devmapper, F_OK) == 0) {
92 reply_with_error ("%s: device already exists", devmapper);
96 char *tempfile = write_key_to_temp (key);
100 const char *argv[MAX_ARGS];
103 ADD_ARG (argv, i, "cryptsetup");
104 ADD_ARG (argv, i, "-d");
105 ADD_ARG (argv, i, tempfile);
106 if (readonly) ADD_ARG (argv, i, "--readonly");
107 ADD_ARG (argv, i, "luksOpen");
108 ADD_ARG (argv, i, device);
109 ADD_ARG (argv, i, mapname);
110 ADD_ARG (argv, i, NULL);
113 int r = commandv (NULL, &err, (const char * const *) argv);
114 remove_temp (tempfile);
117 reply_with_error ("%s", err);
130 do_luks_open (const char *device, const char *key, const char *mapname)
132 return luks_open (device, key, mapname, 0);
136 do_luks_open_ro (const char *device, const char *key, const char *mapname)
138 return luks_open (device, key, mapname, 1);
142 do_luks_close (const char *device)
144 /* Must be /dev/mapper/... */
145 if (! STRPREFIX (device, "/dev/mapper/")) {
146 reply_with_error ("luks_close: you must call this on the /dev/mapper device created by luks_open");
150 const char *mapname = &device[12];
153 int r = command (NULL, &err, "cryptsetup", "luksClose", mapname, NULL);
155 reply_with_error ("%s", err);
168 luks_format (const char *device, const char *key, int keyslot,
171 char *tempfile = write_key_to_temp (key);
175 const char *argv[MAX_ARGS];
179 ADD_ARG (argv, i, "cryptsetup");
180 ADD_ARG (argv, i, "-q");
182 ADD_ARG (argv, i, "--cipher");
183 ADD_ARG (argv, i, cipher);
185 ADD_ARG (argv, i, "--key-slot");
186 snprintf (keyslot_s, sizeof keyslot_s, "%d", keyslot);
187 ADD_ARG (argv, i, keyslot_s);
188 ADD_ARG (argv, i, "luksFormat");
189 ADD_ARG (argv, i, device);
190 ADD_ARG (argv, i, tempfile);
191 ADD_ARG (argv, i, NULL);
194 int r = commandv (NULL, &err, (const char * const *) argv);
195 remove_temp (tempfile);
198 reply_with_error ("%s", err);
211 do_luks_format (const char *device, const char *key, int keyslot)
213 return luks_format (device, key, keyslot, NULL);
217 do_luks_format_cipher (const char *device, const char *key, int keyslot,
220 return luks_format (device, key, keyslot, cipher);
224 do_luks_add_key (const char *device, const char *key, const char *newkey,
227 char *keyfile = write_key_to_temp (key);
231 char *newkeyfile = write_key_to_temp (newkey);
233 remove_temp (keyfile);
237 const char *argv[MAX_ARGS];
241 ADD_ARG (argv, i, "cryptsetup");
242 ADD_ARG (argv, i, "-q");
243 ADD_ARG (argv, i, "-d");
244 ADD_ARG (argv, i, keyfile);
245 ADD_ARG (argv, i, "--key-slot");
246 snprintf (keyslot_s, sizeof keyslot_s, "%d", keyslot);
247 ADD_ARG (argv, i, keyslot_s);
248 ADD_ARG (argv, i, "luksAddKey");
249 ADD_ARG (argv, i, device);
250 ADD_ARG (argv, i, newkeyfile);
251 ADD_ARG (argv, i, NULL);
254 int r = commandv (NULL, &err, (const char * const *) argv);
255 remove_temp (keyfile);
256 remove_temp (newkeyfile);
259 reply_with_error ("%s", err);
270 do_luks_kill_slot (const char *device, const char *key, int keyslot)
272 char *tempfile = write_key_to_temp (key);
276 const char *argv[MAX_ARGS];
280 ADD_ARG (argv, i, "cryptsetup");
281 ADD_ARG (argv, i, "-q");
282 ADD_ARG (argv, i, "-d");
283 ADD_ARG (argv, i, tempfile);
284 ADD_ARG (argv, i, "luksKillSlot");
285 ADD_ARG (argv, i, device);
286 snprintf (keyslot_s, sizeof keyslot_s, "%d", keyslot);
287 ADD_ARG (argv, i, keyslot_s);
288 ADD_ARG (argv, i, NULL);
291 int r = commandv (NULL, &err, (const char * const *) argv);
292 remove_temp (tempfile);
295 reply_with_error ("%s", err);