From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1kbG8q-0000N1-8I for mharc-grub-devel@gnu.org; Fri, 06 Nov 2020 23:47:56 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:45444) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kbG8o-0000J0-KB for grub-devel@gnu.org; Fri, 06 Nov 2020 23:47:54 -0500 Received: from mail-ot1-x344.google.com ([2607:f8b0:4864:20::344]:34926) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kbG8l-0002tr-BE for grub-devel@gnu.org; Fri, 06 Nov 2020 23:47:54 -0500 Received: by mail-ot1-x344.google.com with SMTP id n11so3342677ota.2 for ; Fri, 06 Nov 2020 20:47:50 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=efficientek-com.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=dZkpYHh7/6OP04g3VyGBc5ZafGVaEnkV+4bEyHJRFsY=; b=o+bWejvYsWAsrvNuI0hsQ0n/2qFk6kdwkHZYaWYgmHE/JyMeDaX4jFMc/Iyw8TtSdH Jg5l50biW/JTukCsjT3p0otu2DLfqpBdAnIBaX56HSCjisGzQK2UHeN649hKoujUnfrW IAL57174hSQzjwD0xDvJl9gbRvcD5Pm6QNlsFDsEQ7hqScagPHA7s3o7p+XNUR+OmJx7 tVAJDgajEApInN02JywkiUWvj9l7otnmd4pyusMzPf5V/X1SnUjDcHDfqwHejO4hkWvT YlARNve0x9epsqm1WxfDTX5RvtEQgwd41okJMGEcBGivndF1RR/aN7qpzVB4CnjgoGsN WjJw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=dZkpYHh7/6OP04g3VyGBc5ZafGVaEnkV+4bEyHJRFsY=; b=VmQ2ZOe09au8zRz5tmGRsrTx/K8qqyzKzOjnKQ+ikUPS15y+vpoLZznPD8a9s+iacm cjGlyxJilBeMcbTDqBaPl9B4rc0gAzRdKKz16AvZ0z2C7w7GSgi7rf4ISN7rP0BU6u6W Wx/4M4iyqJ8fedRkPSQJyVOLgZJIx3il4zyhNF9e/9EbVVzGwVLwVValWUS/6SdcGMv5 b1AajyZJO21L4vT7ZU7EyZ6sq+cLgD5jsXb571lEmMkT/mEdVFgjLS+lXlGS9NjkLUVt eUspCu2TIV6RVboAL6QdT7ze+3YPRw9ZEyDA7ahMFa/AzNxVY1wauu76RmDGpnYu+rvl SZ5g== X-Gm-Message-State: AOAM531psphCJxlQYBkTS/MTEWcROUSvGOxCfJyhMLXYjYoqubYw13n8 e2+tEB3hyMS1JHNf5bfYMjHSCUNJ2GmCneiU X-Google-Smtp-Source: ABdhPJxoA7mOlAQIc2PHMRXmSfjdY+epjExugVyvKlHWJkgBi3O9jg1RWQe9gLbJ7yF+YXmr/8KIuw== X-Received: by 2002:a9d:dc8:: with SMTP id 66mr3327201ots.302.1604724470133; Fri, 06 Nov 2020 20:47:50 -0800 (PST) Received: from localhost.localdomain ([136.49.44.103]) by smtp.gmail.com with ESMTPSA id x25sm836888oie.17.2020.11.06.20.47.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 06 Nov 2020 20:47:49 -0800 (PST) From: Glenn Washburn To: grub-devel@gnu.org Cc: Patrick Steinhardt , Daniel Kiper , Glenn Washburn Subject: [PATCH v4 10/15] luks2: Use more intuitive keyslot key instead of index when naming keyslot. Date: Fri, 6 Nov 2020 22:44:30 -0600 Message-Id: <31b9f0b832994d1128fffc4614d332fc34c44d8a.1604723348.git.development@efficientek.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=2607:f8b0:4864:20::344; envelope-from=development@efficientek.com; helo=mail-ot1-x344.google.com X-detected-operating-system: by eggs.gnu.org: No matching host in p0f cache. That's all we know. X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 07 Nov 2020 04:47:54 -0000 Use the keyslot key value in the keyslot json array rather than the index of the keyslot in the json array. This is less confusing for the end user. For example, say you have a LUKS2 device with a key in slot 1 and slot 4. When using the password for slot 4 to unlock the device, the messages using the index of the keyslot will mention keyslot 1 (its a zero-based index). Furthermore, with this change the keyslot number will align with the number used to reference the keyslot when using the --key-slot argument to cryptsetup. Signed-off-by: Glenn Washburn --- grub-core/disk/luks2.c | 27 ++++++++++++++++----------- 1 file changed, 16 insertions(+), 11 deletions(-) diff --git a/grub-core/disk/luks2.c b/grub-core/disk/luks2.c index 9b171bf9d..ca830d73b 100644 --- a/grub-core/disk/luks2.c +++ b/grub-core/disk/luks2.c @@ -65,6 +65,7 @@ typedef struct grub_luks2_header grub_luks2_header_t; struct grub_luks2_keyslot { + grub_uint64_t slot_key; grub_int64_t key_size; grub_int64_t priority; struct @@ -103,6 +104,7 @@ typedef struct grub_luks2_keyslot grub_luks2_keyslot_t; struct grub_luks2_segment { + grub_uint64_t slot_key; grub_uint64_t offset; const char *size; const char *encryption; @@ -112,6 +114,7 @@ typedef struct grub_luks2_segment grub_luks2_segment_t; struct grub_luks2_digest { + grub_uint64_t slot_key; /* Both keyslots and segments are interpreted as bitfields here */ grub_uint64_t keyslots; grub_uint64_t segments; @@ -259,12 +262,12 @@ luks2_get_keyslot (grub_luks2_keyslot_t *k, grub_luks2_digest_t *d, grub_luks2_s { grub_json_t keyslots, keyslot, digests, digest, segments, segment; grub_size_t i, size; - grub_uint64_t keyslot_key, digest_key, segment_key; + grub_uint64_t digest_key, segment_key; /* Get nth keyslot */ if (grub_json_getvalue (&keyslots, root, "keyslots") || grub_json_getchild (&keyslot, &keyslots, keyslot_idx) || - grub_json_getuint64 (&keyslot_key, &keyslot, NULL) || + grub_json_getuint64 (&k->slot_key, &keyslot, NULL) || grub_json_getchild (&keyslot, &keyslot, 0) || luks2_parse_keyslot (k, &keyslot)) return grub_error (GRUB_ERR_BAD_ARGUMENT, "Could not parse keyslot index %"PRIuGRUB_SIZE, keyslot_idx); @@ -281,11 +284,12 @@ luks2_get_keyslot (grub_luks2_keyslot_t *k, grub_luks2_digest_t *d, grub_luks2_s luks2_parse_digest (d, &digest)) return grub_error (GRUB_ERR_BAD_ARGUMENT, "Could not parse digest index %"PRIuGRUB_SIZE, i); - if ((d->keyslots & (1 << keyslot_key))) + d->slot_key = digest_key; + if ((d->keyslots & (1 << k->slot_key))) break; } if (i == size) - return grub_error (GRUB_ERR_FILE_NOT_FOUND, "No digest for keyslot \"%"PRIuGRUB_UINT64_T"\"", keyslot_key); + return grub_error (GRUB_ERR_FILE_NOT_FOUND, "No digest for keyslot \"%"PRIuGRUB_UINT64_T"\"", k->slot_key); /* Get segment that matches the digest. */ if (grub_json_getvalue (&segments, root, "segments") || @@ -299,6 +303,7 @@ luks2_get_keyslot (grub_luks2_keyslot_t *k, grub_luks2_digest_t *d, grub_luks2_s luks2_parse_segment (s, &segment)) return grub_error (GRUB_ERR_BAD_ARGUMENT, "Could not parse segment index %"PRIuGRUB_SIZE, i); + s->slot_key = segment_key; if ((d->segments & (1 << segment_key))) break; } @@ -599,11 +604,11 @@ luks2_recover_key (grub_disk_t source, if (keyslot.priority == 0) { - grub_dprintf ("luks2", "Ignoring keyslot %"PRIuGRUB_SIZE" due to priority\n", i); + grub_dprintf ("luks2", "Ignoring keyslot %"PRIuGRUB_UINT64_T" due to priority\n", keyslot.slot_key); continue; } - grub_dprintf ("luks2", "Trying keyslot %"PRIuGRUB_SIZE"\n", i); + grub_dprintf ("luks2", "Trying keyslot %"PRIuGRUB_UINT64_T"\n", keyslot.slot_key); /* Set up disk according to keyslot's segment. */ crypt->offset_sectors = grub_divmod64 (segment.offset, segment.sector_size, NULL); @@ -618,16 +623,16 @@ luks2_recover_key (grub_disk_t source, (const grub_uint8_t *) passphrase, grub_strlen (passphrase)); if (ret) { - grub_dprintf ("luks2", "Decryption with keyslot %"PRIuGRUB_SIZE" failed: %s\n", - i, grub_errmsg); + grub_dprintf ("luks2", "Decryption with keyslot %"PRIuGRUB_UINT64_T" failed: %s\n", + keyslot.slot_key, grub_errmsg); continue; } ret = luks2_verify_key (&digest, candidate_key, keyslot.key_size); if (ret) { - grub_dprintf ("luks2", "Could not open keyslot %"PRIuGRUB_SIZE": %s\n", - i, grub_errmsg); + grub_dprintf ("luks2", "Could not open keyslot %"PRIuGRUB_UINT64_T": %s\n", + keyslot.slot_key, grub_errmsg); continue; } @@ -635,7 +640,7 @@ luks2_recover_key (grub_disk_t source, * TRANSLATORS: It's a cryptographic key slot: one element of an array * where each element is either empty or holds a key. */ - grub_printf_ (N_("Slot %"PRIuGRUB_SIZE" opened\n"), i); + grub_printf_ (N_("Slot %"PRIuGRUB_UINT64_T" opened\n"), keyslot.slot_key); candidate_key_len = keyslot.key_size; break; -- 2.27.0