devfs: rewrite cryptio()
adjust to new aes_xts routines. allow optional offset in the 4th argument where the encrypted sectors start instead of hardcoding the 64K header area for cryptsetup. avoid allocating temporary buffer for cryptio() reads, we can just decrypt in place there. use sdmalloc() to allocate the temporary buffer for cryptio() writes so that devsd wont need to allocate and copy in case it didnt like our alignment. do not duplicate the error reporting code, just use io() that is what it is for. allow 2*256 bit keys in addition to 2*128 bit keys.
This commit is contained in:
parent
c021390e21
commit
93117262c2
2 changed files with 60 additions and 62 deletions
|
@ -21,10 +21,9 @@
|
||||||
#include "io.h"
|
#include "io.h"
|
||||||
#include "ureg.h"
|
#include "ureg.h"
|
||||||
#include "../port/error.h"
|
#include "../port/error.h"
|
||||||
|
#include "../port/sd.h"
|
||||||
#include <libsec.h>
|
#include <libsec.h>
|
||||||
|
|
||||||
int dec16(uchar *out, int lim, char *in, int n);
|
|
||||||
|
|
||||||
enum
|
enum
|
||||||
{
|
{
|
||||||
Fnone,
|
Fnone,
|
||||||
|
@ -39,6 +38,7 @@ enum
|
||||||
|
|
||||||
Sectorsz = 1,
|
Sectorsz = 1,
|
||||||
Blksize = 8*1024, /* for Finter only */
|
Blksize = 8*1024, /* for Finter only */
|
||||||
|
Cryptsectsz = 512, /* for Fcrypt only */
|
||||||
|
|
||||||
Incr = 5, /* Increments for the dev array */
|
Incr = 5, /* Increments for the dev array */
|
||||||
|
|
||||||
|
@ -447,11 +447,9 @@ setdsize(Fsdev* mp, vlong *ilen)
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case Fcrypt:
|
case Fcrypt:
|
||||||
if(inlen > (64*1024)) {
|
if(mp->start > inlen)
|
||||||
mp->size = inlen - (64 * 1024);
|
error("crypt starts after device end");
|
||||||
} else {
|
mp->size = (inlen - mp->start) & ~((vlong)Cryptsectsz-1);
|
||||||
mp->size = 0;
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -552,7 +550,8 @@ mconfig(char* a, long n)
|
||||||
vlong size, start;
|
vlong size, start;
|
||||||
vlong *ilen;
|
vlong *ilen;
|
||||||
char *tname, *dname, *fakef[4];
|
char *tname, *dname, *fakef[4];
|
||||||
uchar key[32];
|
uchar key[2*256/8];
|
||||||
|
int keylen;
|
||||||
Chan **idev;
|
Chan **idev;
|
||||||
Cmdbuf *cb;
|
Cmdbuf *cb;
|
||||||
Cmdtab *ct;
|
Cmdtab *ct;
|
||||||
|
@ -571,6 +570,7 @@ mconfig(char* a, long n)
|
||||||
cb = nil;
|
cb = nil;
|
||||||
idev = nil;
|
idev = nil;
|
||||||
ilen = nil;
|
ilen = nil;
|
||||||
|
keylen = 0;
|
||||||
|
|
||||||
if(waserror()){
|
if(waserror()){
|
||||||
free(cb);
|
free(cb);
|
||||||
|
@ -600,8 +600,19 @@ mconfig(char* a, long n)
|
||||||
mdelctl("*", "*"); /* del everything */
|
mdelctl("*", "*"); /* del everything */
|
||||||
return;
|
return;
|
||||||
case Fcrypt:
|
case Fcrypt:
|
||||||
if(dec16(key, 32, cb->f[2], strlen(cb->f[2])) != 32)
|
if(cb->nf >= 4) {
|
||||||
|
start = strtoul(cb->f[3], 0, 0);
|
||||||
|
cb->nf = 3;
|
||||||
|
} else
|
||||||
|
start = 64*1024; /* cryptsetup header */
|
||||||
|
keylen = dec16(key, sizeof(key), cb->f[2], strlen(cb->f[2]));
|
||||||
|
switch(keylen){
|
||||||
|
default:
|
||||||
error("bad hexkey");
|
error("bad hexkey");
|
||||||
|
case 2*128/8:
|
||||||
|
case 2*256/8:
|
||||||
|
break;
|
||||||
|
}
|
||||||
cb->nf -= 1;
|
cb->nf -= 1;
|
||||||
break;
|
break;
|
||||||
case Fpart:
|
case Fpart:
|
||||||
|
@ -694,10 +705,11 @@ Fail:
|
||||||
}
|
}
|
||||||
if(mp->type == Fcrypt) {
|
if(mp->type == Fcrypt) {
|
||||||
Key *k = secalloc(sizeof(Key));
|
Key *k = secalloc(sizeof(Key));
|
||||||
setupAESstate(&k->tweak, &key[0], 16, nil);
|
setupAESstate(&k->tweak, &key[0], keylen/2, nil);
|
||||||
setupAESstate(&k->ecb, &key[16], 16, nil);
|
setupAESstate(&k->ecb, &key[keylen/2], keylen/2, nil);
|
||||||
memset(key, 0, 32);
|
memset(key, 0, sizeof(key));
|
||||||
mp->key = k;
|
mp->key = k;
|
||||||
|
mp->start = start;
|
||||||
}
|
}
|
||||||
for(i = 1; i < cb->nf; i++){
|
for(i = 1; i < cb->nf; i++){
|
||||||
inprv = mp->inner[i-1] = mallocz(sizeof(Inner), 1);
|
inprv = mp->inner[i-1] = mallocz(sizeof(Inner), 1);
|
||||||
|
@ -1014,62 +1026,47 @@ io(Fsdev *mp, Inner *in, int isread, void *a, long l, vlong off)
|
||||||
}
|
}
|
||||||
|
|
||||||
static long
|
static long
|
||||||
cryptio(Fsdev *mp, int isread, uchar *a, long l, vlong off)
|
cryptio(Fsdev *mp, int isread, uchar *a, long n, vlong off)
|
||||||
{
|
{
|
||||||
long wl, ws, wo, wb;
|
long l, m, o, nb;
|
||||||
uchar *buf;
|
uchar *b;
|
||||||
Chan *mc;
|
|
||||||
Inner *in;
|
|
||||||
Key *k;
|
|
||||||
enum {
|
|
||||||
Sectsz = 512,
|
|
||||||
Maxbuf = 32*Sectsz,
|
|
||||||
};
|
|
||||||
|
|
||||||
if(off < 0 || l <= 0 || ((off|l) & (Sectsz-1)))
|
if((((ulong)off|n) & (Cryptsectsz-1)))
|
||||||
error(Ebadarg);
|
error(Ebadarg);
|
||||||
|
if(isread){
|
||||||
k = mp->key;
|
l = io(mp, mp->inner[0], Isread, a, n, off);
|
||||||
in = mp->inner[0];
|
if(l > 0){
|
||||||
mc = in->idev;
|
l &= ~(Cryptsectsz-1);
|
||||||
if(mc == nil)
|
for(o=0; o<l; o+=Cryptsectsz)
|
||||||
error(Egone);
|
aes_xts_decrypt(&mp->key->tweak, &mp->key->ecb,
|
||||||
off += 64*1024; // Header
|
off+o, a+o, a+o, Cryptsectsz);
|
||||||
wb = l;
|
}
|
||||||
if(wb > Maxbuf)
|
return l;
|
||||||
wb = Maxbuf;
|
}
|
||||||
buf = smalloc(wb);
|
nb = n < SDmaxio ? n : SDmaxio;
|
||||||
|
while((b = sdmalloc(nb)) == nil){
|
||||||
|
if(!waserror()){
|
||||||
|
resrcwait("no memory for cryptio");
|
||||||
|
poperror();
|
||||||
|
}
|
||||||
|
}
|
||||||
if(waserror()) {
|
if(waserror()) {
|
||||||
free(buf);
|
sdfree(b);
|
||||||
print("#k: %s: byte %,lld count %ld (of #k/%s): %s error: %s\n",
|
|
||||||
in->iname, off, l, mp->name, (isread? "read": "write"),
|
|
||||||
(up && up->errstr? up->errstr: ""));
|
|
||||||
nexterror();
|
nexterror();
|
||||||
}
|
}
|
||||||
for(ws = 0; ws < l; ws += wo){
|
for(l = 0; (m = n - l) > 0; l += m){
|
||||||
wo = l - ws;
|
if(m > nb) m = nb;
|
||||||
if(wo > wb)
|
for(o=0; o<m; o+=Cryptsectsz)
|
||||||
wo = wb;
|
aes_xts_encrypt(&mp->key->tweak, &mp->key->ecb,
|
||||||
if (isread) {
|
off+o, a+o, b+o, Cryptsectsz);
|
||||||
wo = devtab[mc->type]->read(mc, buf, wo, off);
|
if(io(mp, mp->inner[0], Iswrite, b, m, off) != m)
|
||||||
if(wo < Sectsz)
|
error(Eio);
|
||||||
break;
|
off += m;
|
||||||
wo &= ~(Sectsz-1);
|
a += m;
|
||||||
for(wl=0; wl<wo; wl+=Sectsz)
|
|
||||||
aes_xts_decrypt(k->tweak.ekey, k->ecb.dkey, off+wl, buf+wl, a+wl, Sectsz);
|
|
||||||
} else {
|
|
||||||
for(wl=0; wl<wo; wl+=Sectsz)
|
|
||||||
aes_xts_encrypt(k->tweak.ekey, k->ecb.ekey, off+wl, a+wl, buf+wl, Sectsz);
|
|
||||||
if(devtab[mc->type]->write(mc, buf, wo, off) != wo)
|
|
||||||
error(Eio);
|
|
||||||
}
|
|
||||||
off += wo;
|
|
||||||
a += wo;
|
|
||||||
}
|
}
|
||||||
|
sdfree(b);
|
||||||
poperror();
|
poperror();
|
||||||
free(buf);
|
return l;
|
||||||
|
|
||||||
return ws;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/* NB: a transfer could span multiple inner devices */
|
/* NB: a transfer could span multiple inner devices */
|
||||||
|
@ -1243,7 +1240,7 @@ mread(Chan *c, void *a, long n, vlong off)
|
||||||
(up && up->errstr? up->errstr: ""));
|
(up && up->errstr? up->errstr: ""));
|
||||||
break;
|
break;
|
||||||
case Fcrypt:
|
case Fcrypt:
|
||||||
res = cryptio(mp, Isread, a, n, off);
|
res = cryptio(mp, Isread, a, n, mp->start + off);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
Done:
|
Done:
|
||||||
|
@ -1341,7 +1338,7 @@ mwrite(Chan *c, void *a, long n, vlong off)
|
||||||
|
|
||||||
break;
|
break;
|
||||||
case Fcrypt:
|
case Fcrypt:
|
||||||
res = cryptio(mp, Iswrite, a, n, off);
|
res = cryptio(mp, Iswrite, a, n, mp->start + off);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
Done:
|
Done:
|
||||||
|
|
|
@ -155,6 +155,7 @@ extern char end[];
|
||||||
extern int getfields(char*, char**, int, int, char*);
|
extern int getfields(char*, char**, int, int, char*);
|
||||||
extern int tokenize(char*, char**, int);
|
extern int tokenize(char*, char**, int);
|
||||||
extern int dec64(uchar*, int, char*, int);
|
extern int dec64(uchar*, int, char*, int);
|
||||||
|
extern int dec16(uchar*, int, char*, int);
|
||||||
extern int encodefmt(Fmt*);
|
extern int encodefmt(Fmt*);
|
||||||
extern void qsort(void*, long, long, int (*)(void*, void*));
|
extern void qsort(void*, long, long, int (*)(void*, void*));
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue