From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1kUeKc-0000We-RP for mharc-grub-devel@gnu.org; Mon, 19 Oct 2020 19:12:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:40668) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kUeKX-0000VO-Ar for grub-devel@gnu.org; Mon, 19 Oct 2020 19:12:42 -0400 Received: from mail-ot1-x341.google.com ([2607:f8b0:4864:20::341]:42991) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kUeKR-0007UP-9c for grub-devel@gnu.org; Mon, 19 Oct 2020 19:12:40 -0400 Received: by mail-ot1-x341.google.com with SMTP id h62so1472635oth.9 for ; Mon, 19 Oct 2020 16:12:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=efficientek-com.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=5MjB4ZkNZsJYOTlxt3Tv8gOfcWaNR7q3TCFB3w1G2Ak=; b=s8ZKgpDRz1/AWVxK1KK5Zj8xPdiD2WhV8VUBmfV4NneKms0i6rJKnRLfTZbN1e5ACK c2imw1KZG1zts4Ro1sJVMce0CH4w27chJjIkld0mV+7F9qgAj/2S+kTjagTuS758UHga c5J3F9OjP4FWlSEz/KqD4SNa9ltP6Y8zEJc8vmgHzbk5CPuVZu0ANJ6sgRxDFQiGxKEN jzd5TC/sRSuPLJuaqSjXgpbV+lTYPPI8uz7wRE/fxFw2lyTZyTN00bmUzUOkXI6y3Z54 7pr+JJhtIu3daoWBwGvEiV0lIr6vCda4lEpsB6UwARJTXD/dNoOZNS5jsegASb8DCZoG 3zWg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=5MjB4ZkNZsJYOTlxt3Tv8gOfcWaNR7q3TCFB3w1G2Ak=; b=XpQiZCSHOjVKLMCquf7YgNAgBN0JsmHxOTNk1qT96O0y08X7tPEH/tX/u0BH/GgfJC ICsxFR1S1S242YtgWLH+52PTyRHuzpeBwVXYl1qGN7QVadBQ9gkxaF3qsxdfrjG2QPbJ a1/2VplwXCqS9OcBRf879y/qFGZrM+1IgboC6vYRDYdU7GA+W82maegrpMTGpvLHrMlv Hl9Vr8DJ/GY9Kr5e5wve1WuDZeMwr+Q2T51NYyE1+SQQL+CfGch/UKyl1YvSv3LT2TTt l10qAON+56u41VFWO0RuoxHvUfbTz2D2/7bkZl3thjZeFek9l9i/o0UvMn8SxIT8f5jE 54yA== X-Gm-Message-State: AOAM5303IGcwqOQvHWcDODJdqyk6wOq/e1fRHQYC/kayQgOxwyq2RVS2 3TJQtTOEBeObiyuSrCN6Lly6vct+w9Itxw== X-Google-Smtp-Source: ABdhPJyfWYUhuYJ6CicLCHbOCPPWrpgDOtnk1rjkYZQqnnjNI8YfOF8As3ZI91tCdKRNnQkmwIkbYQ== X-Received: by 2002:a9d:4711:: with SMTP id a17mr1579871otf.264.1603149153586; Mon, 19 Oct 2020 16:12:33 -0700 (PDT) Received: from localhost.localdomain (47-218-232-180.bcstcmtk03.res.dyn.suddenlink.net. [47.218.232.180]) by smtp.gmail.com with ESMTPSA id d27sm310848otc.6.2020.10.19.16.12.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 19 Oct 2020 16:12:32 -0700 (PDT) From: Glenn Washburn To: grub-devel@gnu.org Cc: Patrick Steinhardt , Daniel Kiper , Glenn Washburn Subject: [PATCH v3 03/10] luks2: Use more intuitive keyslot key instead of index when naming keyslot. Date: Mon, 19 Oct 2020 18:09:51 -0500 Message-Id: <1f65a04e05b52b01d8816efbcdc84a3b9b2f5a2d.1603148099.git.development@efficientek.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: References: <20201009100122.GH2088@tanuki> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=2607:f8b0:4864:20::341; envelope-from=development@efficientek.com; helo=mail-ot1-x341.google.com X-detected-operating-system: by eggs.gnu.org: No matching host in p0f cache. That's all we know. X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Oct 2020 23:12:43 -0000 Use the keyslot key value in the keyslot json array rather than the index of the keyslot in the json array. This is less confusing for the end user. For example, say you have a LUKS2 device with a key in slot 1 and slot 4. When using the password for slot 4 to unlock the device, the messages using the index of the keyslot will mention keyslot 1 (its a zero-based index). Furthermore,with this change the keyslot number will align with the number used to reference the keyslot when using the --key-slot argument to cryptsetup. Signed-off-by: Glenn Washburn --- grub-core/disk/luks2.c | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/grub-core/disk/luks2.c b/grub-core/disk/luks2.c index c3cd63606..4e1e47161 100644 --- a/grub-core/disk/luks2.c +++ b/grub-core/disk/luks2.c @@ -65,6 +65,7 @@ typedef struct grub_luks2_header grub_luks2_header_t; struct grub_luks2_keyslot { + grub_uint64_t slot_key; grub_int64_t key_size; grub_int64_t priority; struct @@ -259,12 +260,12 @@ luks2_get_keyslot (grub_luks2_keyslot_t *k, grub_luks2_digest_t *d, grub_luks2_s { grub_json_t keyslots, keyslot, digests, digest, segments, segment; grub_size_t i, size; - grub_uint64_t keyslot_key, digest_key, segment_key; + grub_uint64_t digest_key, segment_key; /* Get nth keyslot */ if (grub_json_getvalue (&keyslots, root, "keyslots") || grub_json_getchild (&keyslot, &keyslots, keyslot_idx) || - grub_json_getuint64 (&keyslot_key, &keyslot, NULL) || + grub_json_getuint64 (&k->slot_key, &keyslot, NULL) || grub_json_getchild (&keyslot, &keyslot, 0) || luks2_parse_keyslot (k, &keyslot)) return grub_error (GRUB_ERR_BAD_ARGUMENT, "Could not parse keyslot index %"PRIuGRUB_SIZE, keyslot_idx); @@ -281,11 +282,11 @@ luks2_get_keyslot (grub_luks2_keyslot_t *k, grub_luks2_digest_t *d, grub_luks2_s luks2_parse_digest (d, &digest)) return grub_error (GRUB_ERR_BAD_ARGUMENT, "Could not parse digest index %"PRIuGRUB_SIZE, i); - if ((d->keyslots & (1 << keyslot_key))) + if ((d->keyslots & (1 << k->slot_key))) break; } if (i == size) - return grub_error (GRUB_ERR_FILE_NOT_FOUND, "No digest for keyslot \"%"PRIuGRUB_UINT64_T"\"", keyslot_key); + return grub_error (GRUB_ERR_FILE_NOT_FOUND, "No digest for keyslot \"%"PRIuGRUB_UINT64_T"\"", k->slot_key); /* Get segment that matches the digest. */ if (grub_json_getvalue (&segments, root, "segments") || @@ -599,11 +600,11 @@ luks2_recover_key (grub_disk_t disk, if (keyslot.priority == 0) { - grub_dprintf ("luks2", "Ignoring keyslot %"PRIuGRUB_SIZE" due to priority\n", i); + grub_dprintf ("luks2", "Ignoring keyslot %"PRIuGRUB_UINT64_T" due to priority\n", keyslot.slot_key); continue; } - grub_dprintf ("luks2", "Trying keyslot %"PRIuGRUB_SIZE"\n", i); + grub_dprintf ("luks2", "Trying keyslot %"PRIuGRUB_UINT64_T"\n", keyslot.slot_key); /* Set up disk according to keyslot's segment. */ crypt->offset = grub_divmod64 (segment.offset, segment.sector_size, NULL); @@ -618,16 +619,16 @@ luks2_recover_key (grub_disk_t disk, (const grub_uint8_t *) passphrase, grub_strlen (passphrase)); if (ret) { - grub_dprintf ("luks2", "Decryption with keyslot %"PRIuGRUB_SIZE" failed: %s\n", - i, grub_errmsg); + grub_dprintf ("luks2", "Decryption with keyslot %"PRIuGRUB_UINT64_T" failed: %s\n", + keyslot.slot_key, grub_errmsg); continue; } ret = luks2_verify_key (&digest, candidate_key, keyslot.key_size); if (ret) { - grub_dprintf ("luks2", "Could not open keyslot %"PRIuGRUB_SIZE": %s\n", - i, grub_errmsg); + grub_dprintf ("luks2", "Could not open keyslot %"PRIuGRUB_UINT64_T": %s\n", + keyslot.slot_key, grub_errmsg); continue; } @@ -635,7 +636,7 @@ luks2_recover_key (grub_disk_t disk, * TRANSLATORS: It's a cryptographic key slot: one element of an array * where each element is either empty or holds a key. */ - grub_printf_ (N_("Slot %"PRIuGRUB_SIZE" opened\n"), i); + grub_printf_ (N_("Slot %"PRIuGRUB_UINT64_T" opened\n"), keyslot.slot_key); candidate_key_len = keyslot.key_size; break; -- 2.27.0