utils_dm.h 5.58 KB
Newer Older
Milan Broz's avatar
Milan Broz committed
1 2 3
/*
 * libdevmapper - device-mapper backend for cryptsetup
 *
Milan Broz's avatar
Milan Broz committed
4
 * Copyright (C) 2004, Jana Saout <jana@saout.de>
Milan Broz's avatar
Milan Broz committed
5
 * Copyright (C) 2004-2007, Clemens Fruhwirth <clemens@endorphin.org>
Milan Broz's avatar
Milan Broz committed
6 7
 * Copyright (C) 2009-2018, Red Hat, Inc. All rights reserved.
 * Copyright (C) 2009-2018, Milan Broz
Milan Broz's avatar
Milan Broz committed
8 9 10
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License
11 12
 * as published by the Free Software Foundation; either version 2
 * of the License, or (at your option) any later version.
Milan Broz's avatar
Milan Broz committed
13 14 15 16 17 18 19 20 21 22 23
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */

24 25 26 27
#ifndef _UTILS_DM_H
#define _UTILS_DM_H

/* device-mapper library helpers */
28 29 30
#include <inttypes.h>

struct crypt_device;
31
struct volume_key;
32
struct crypt_params_verity;
Milan Broz's avatar
Milan Broz committed
33
struct device;
34 35 36 37 38 39

/* Device mapper backend - kernel support flags */
#define DM_KEY_WIPE_SUPPORTED (1 << 0)	/* key wipe message */
#define DM_LMK_SUPPORTED      (1 << 1)	/* lmk mode */
#define DM_SECURE_SUPPORTED   (1 << 2)	/* wipe (secure) buffer flag */
#define DM_PLAIN64_SUPPORTED  (1 << 3)	/* plain64 IV */
40
#define DM_DISCARDS_SUPPORTED (1 << 4)	/* discards/TRIM option is supported */
Milan Broz's avatar
Milan Broz committed
41
#define DM_VERITY_SUPPORTED   (1 << 5)	/* dm-verity target supported */
42
#define DM_TCW_SUPPORTED      (1 << 6)	/* tcw (TCRYPT CBC with whitening) */
43 44
#define DM_SAME_CPU_CRYPT_SUPPORTED (1 << 7) /* same_cpu_crypt */
#define DM_SUBMIT_FROM_CRYPT_CPUS_SUPPORTED (1 << 8) /* submit_from_crypt_cpus */
45
#define DM_VERITY_ON_CORRUPTION_SUPPORTED (1 << 9) /* ignore/restart_on_corruption, ignore_zero_block */
46
#define DM_VERITY_FEC_SUPPORTED (1 << 10) /* Forward Error Correction (FEC) */
47
#define DM_KERNEL_KEYRING_SUPPORTED (1 << 11) /* dm-crypt allows loading kernel keyring keys */
48
#define DM_INTEGRITY_SUPPORTED (1 << 12) /* dm-integrity target supported */
49 50
#define DM_SECTOR_SIZE_SUPPORTED (1 << 13) /* support for sector size setting in dm-crypt/dm-integrity */
#define DM_CAPI_STRING_SUPPORTED (1 << 14) /* support for cryptoapi format cipher definition */
51
#define DM_DEFERRED_SUPPORTED (1 << 15) /* deferred removal of device */
52

53 54 55
typedef enum { DM_CRYPT = 0, DM_VERITY, DM_INTEGRITY, DM_UNKNOWN } dm_target_type;

int dm_flags(dm_target_type target, uint32_t *flags);
56

57
#define DM_ACTIVE_DEVICE	(1 << 0)
58
#define DM_ACTIVE_UUID		(1 << 1)
59
#define DM_ACTIVE_HOLDERS	(1 << 2)
60

61 62 63 64 65 66 67
#define DM_ACTIVE_CRYPT_CIPHER	(1 << 3)
#define DM_ACTIVE_CRYPT_KEYSIZE	(1 << 4)
#define DM_ACTIVE_CRYPT_KEY	(1 << 5)

#define DM_ACTIVE_VERITY_ROOT_HASH	(1 << 6)
#define DM_ACTIVE_VERITY_HASH_DEVICE	(1 << 7)
#define DM_ACTIVE_VERITY_PARAMS		(1 << 8)
68

69
#define DM_ACTIVE_INTEGRITY_PARAMS	(1 << 9)
70 71

struct crypt_dm_active_device {
72
	dm_target_type target;
73 74
	uint64_t size;		/* active device size */
	uint32_t flags;		/* activation flags */
75
	const char *uuid;
Milan Broz's avatar
Milan Broz committed
76
	struct device *data_device;
77
	unsigned holders:1;
78 79 80
	union {
	struct {
		const char *cipher;
81
		const char *integrity;
82
		char *key_description;
83

84 85
		/* Active key for device */
		struct volume_key *vk;
86

87 88
		/* struct crypt_active_device */
		uint64_t offset;	/* offset in sectors */
Andrea Gelmini's avatar
Andrea Gelmini committed
89
		uint64_t iv_offset;	/* IV initialisation sector */
90 91
		uint32_t tag_size;	/* additional on-disk tag size */
		uint32_t sector_size;	/* encryption sector size */
92 93
	} crypt;
	struct {
Milan Broz's avatar
Milan Broz committed
94
		struct device *hash_device;
95
		struct device *fec_device;
96 97

		const char *root_hash;
98
		uint32_t root_hash_size;
99

100
		uint64_t hash_offset;	/* hash offset in blocks (not header) */
101
		uint64_t hash_blocks;	/* size of hash device (in hash blocks) */
102
		uint64_t fec_offset;	/* FEC offset in blocks (not header) */
103
		uint64_t fec_blocks;	/* size of FEC device (in hash blocks) */
104
		struct crypt_params_verity *vp;
105
	} verity;
106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125
	struct {
		uint64_t journal_size;
		uint32_t journal_watermark;
		uint32_t journal_commit_time;
		uint32_t interleave_sectors;
		uint32_t tag_size;
		uint64_t offset;	/* offset in sectors */
		uint32_t sector_size;	/* integrity sector size */
		uint32_t buffer_sectors;

		const char *integrity;
		/* Active key for device */
		struct volume_key *vk;

		const char *journal_integrity;
		struct volume_key *journal_integrity_key;

		const char *journal_crypt;
		struct volume_key *journal_crypt_key;
	} integrity;
126
	} u;
127 128
};

129 130
void dm_backend_init(void);
void dm_backend_exit(void);
Milan Broz's avatar
Milan Broz committed
131

132
int dm_remove_device(struct crypt_device *cd, const char *name, uint32_t flags);
Milan Broz's avatar
Milan Broz committed
133 134 135 136 137 138 139 140 141 142
int dm_status_device(struct crypt_device *cd, const char *name);
int dm_status_suspended(struct crypt_device *cd, const char *name);
int dm_status_verity_ok(struct crypt_device *cd, const char *name);
int dm_query_device(struct crypt_device *cd, const char *name,
		    uint32_t get_flags, struct crypt_dm_active_device *dmd);
int dm_create_device(struct crypt_device *cd, const char *name,
		     const char *type, struct crypt_dm_active_device *dmd,
		     int reload);
int dm_suspend_and_wipe_key(struct crypt_device *cd, const char *name);
int dm_resume_and_reinstate_key(struct crypt_device *cd, const char *name,
143
				const struct volume_key *vk);
Milan Broz's avatar
Milan Broz committed
144 145

const char *dm_get_dir(void);
146

147 148
int lookup_dm_dev_by_uuid(const char *uuid, const char *type);

149 150 151 152 153
/* These are DM helpers used only by utils_devpath file */
int dm_is_dm_device(int major, int minor);
int dm_is_dm_kernel_name(const char *name);
char *dm_device_path(const char *prefix, int major, int minor);

154
#endif /* _UTILS_DM_H */