1 /* libguestfs - the guestfsd daemon
2 * Copyright (C) 2010 Red Hat Inc.
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the Free Software
16 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
28 #include "optgroups.h"
31 optgroup_luks_available (void)
33 return prog_exists ("cryptsetup");
37 luks_open (const char *device, const char *key, const char *mapname,
40 /* Sanity check: /dev/mapper/mapname must not exist already. Note
41 * that the device-mapper control device (/dev/mapper/control) is
42 * always there, so you can't ever have mapname == "control".
44 size_t len = strlen (mapname);
45 char devmapper[len+32];
46 snprintf (devmapper, len+32, "/dev/mapper/%s", mapname);
47 if (access (devmapper, F_OK) == 0) {
48 reply_with_error ("%s: device already exists", devmapper);
52 char tempfile[] = "/tmp/luksXXXXXX";
53 int fd = mkstemp (tempfile);
55 reply_with_perror ("mkstemp");
60 if (xwrite (fd, key, len) == -1) {
61 reply_with_perror ("write");
67 if (close (fd) == -1) {
68 reply_with_perror ("close");
76 argv[i++] = "cryptsetup";
79 if (readonly) argv[i++] = "--readonly";
80 argv[i++] = "luksOpen";
86 int r = commandv (NULL, &err, (const char * const *) argv);
90 reply_with_error ("%s", err);
103 do_luks_open (const char *device, const char *key, const char *mapname)
105 return luks_open (device, key, mapname, 0);
109 do_luks_open_ro (const char *device, const char *key, const char *mapname)
111 return luks_open (device, key, mapname, 1);
115 do_luks_close (const char *device)
117 /* Must be /dev/mapper/... */
118 if (! STRPREFIX (device, "/dev/mapper/")) {
119 reply_with_error ("luks_close: you must call this on the /dev/mapper device created by luks_open");
123 const char *mapname = &device[12];
126 int r = command (NULL, &err, "cryptsetup", "luksClose", mapname, NULL);
128 reply_with_error ("%s", err);