Changing persistent-encryption to accept a list TYPE... instead.
[live-boot-grml.git] / scripts / live-helpers
1 # live-boot helper functions, used by live-boot on boot and by live-snapshot
2
3 if [ ! -x "/bin/fstype" ]
4 then
5         # klibc not in path -> not in initramfs
6         export PATH="${PATH}:/usr/lib/klibc/bin"
7 fi
8
9 # handle upgrade path from old udev (using udevinfo) to
10 # recent versions of udev (using udevadm info)
11 if [ -x /sbin/udevadm ]
12 then
13         udevinfo='/sbin/udevadm info'
14 else
15         udevinfo='udevinfo'
16 fi
17
18 sys2dev ()
19 {
20         sysdev=${1#/sys}
21         echo "/dev/$($udevinfo -q name -p ${sysdev} 2>/dev/null|| echo ${sysdev##*/})"
22 }
23
24 subdevices ()
25 {
26         sysblock=${1}
27         r=""
28
29         for dev in "${sysblock}"/* "${sysblock}"
30         do
31                 if [ -e "${dev}/dev" ]
32                 then
33                         r="${r} ${dev}"
34                 fi
35         done
36
37         echo ${r}
38 }
39
40 storage_devices()
41 {
42         black_listed_devices="${1}"
43         white_listed_devices="${2}"
44
45         for sysblock in $(echo /sys/block/* | tr ' ' '\n' | grep -vE "loop|ram|fd")
46         do
47                 fulldevname=$(sys2dev "${sysblock}")
48
49                 if echo "${black_listed_devices}" | grep -qw "${fulldevname}" || \
50                         [ -n "${white_listed_devices}" ] && \
51                         echo "${white_listed_devices}" | grep -vqw "${fulldevname}"
52                 then
53                         # skip this device entirely
54                         continue
55                 fi
56
57                 for dev in $(subdevices "${sysblock}")
58                 do
59                         devname=$(sys2dev "${dev}")
60
61                         if echo "${black_listed_devices}" | grep -qw "${devname}"
62                         then
63                                 # skip this subdevice
64                                 continue
65                         else
66                                 echo "${devname}"
67                         fi
68                 done
69         done
70 }
71
72 is_supported_fs ()
73 {
74         fstype="${1}"
75
76         # Validate input first
77         if [ -z "${fstype}" ]
78         then
79                 return 1
80         fi
81
82         # Try to look if it is already supported by the kernel
83         if grep -q ${fstype} /proc/filesystems
84         then
85                 return 0
86         else
87                 # Then try to add support for it the gentle way using the initramfs capabilities
88                 modprobe ${fstype}
89                 if grep -q ${fstype} /proc/filesystems
90                 then
91                         return 0
92                 # Then try the hard way if /root is already reachable
93                 else
94                         kmodule="/root/lib/modules/`uname -r`/${fstype}/${fstype}.ko"
95                         if [ -e "${kmodule}" ]
96                         then
97                                 insmod "${kmodule}"
98                                 if grep -q ${fstype} /proc/filesystems
99                                 then
100                                         return 0
101                                 fi
102                         fi
103                 fi
104         fi
105
106         return 1
107 }
108
109 get_fstype ()
110 {
111         /sbin/blkid -s TYPE -o value $1 2>/dev/null
112 }
113
114 where_is_mounted ()
115 {
116         device=${1}
117
118         if grep -q "^${device} " /proc/mounts
119         then
120                 # return the first found
121                 grep -m1 "^${device} " /proc/mounts | cut -f2 -d ' '
122         fi
123 }
124
125 lastline ()
126 {
127         while read lines
128         do
129                 line=${lines}
130         done
131
132         echo "${line}"
133 }
134
135 base_path ()
136 {
137         testpath="${1}"
138         mounts="$(awk '{print $2}' /proc/mounts)"
139         testpath="$(busybox realpath ${testpath})"
140
141         while true
142         do
143                 if echo "${mounts}" | grep -qs "^${testpath}"
144                 then
145                         set -- $(echo "${mounts}" | grep "^${testpath}" | lastline)
146                         echo ${1}
147                         break
148                 else
149                         testpath=$(dirname $testpath)
150                 fi
151         done
152 }
153
154 fs_size ()
155 {
156         # Returns used/free fs kbytes + 5% more
157         # You could pass a block device as ${1} or the mount point as ${2}
158
159         dev="${1}"
160         mountp="${2}"
161         used="${3}"
162
163         if [ -z "${mountp}" ]
164         then
165                 mountp="$(where_is_mounted ${dev})"
166
167                 if [ -z "${mountp}" ]
168                 then
169                         mountp="/mnt/tmp_fs_size"
170
171                         mkdir -p "${mountp}"
172                         mount -t $(get_fstype "${dev}") -o ro "${dev}" "${mountp}" || log_warning_msg "cannot mount -t $(get_fstype ${dev}) -o ro ${dev} ${mountp}"
173
174                         doumount=1
175                 fi
176         fi
177
178         if [ "${used}" = "used" ]
179         then
180                 size=$(du -ks ${mountp} | cut -f1)
181                 size=$(expr ${size} + ${size} / 20 ) # FIXME: 5% more to be sure
182         else
183                 # free space
184                 size="$(df -k | grep -s ${mountp} | awk '{print $4}')"
185         fi
186
187         if [ -n "${doumount}" ]
188         then
189                 umount "${mountp}" || log_warning_msg "cannot umount ${mountp}"
190                 rmdir "${mountp}"
191         fi
192
193         echo "${size}"
194 }
195
196 load_keymap ()
197 {
198         # Load custom keymap
199         if [ -x /bin/loadkeys -a -r /etc/boottime.kmap.gz ]
200         then
201                 loadkeys /etc/boottime.kmap.gz
202         fi
203 }
204
205 setup_loop ()
206 {
207         local fspath=${1}
208         local module=${2}
209         local pattern=${3}
210         local offset=${4}
211         local encryption=${5}
212         local readonly=${6}
213
214         # the output of setup_loop is evaluated in other functions,
215         # modprobe leaks kernel options like "libata.dma=0"
216         # as "options libata dma=0" on stdout, causing serious
217         # problems therefor, so instead always avoid output to stdout
218         modprobe -q -b "${module}" 1>/dev/null
219
220         udevadm settle
221
222         for loopdev in ${pattern}
223         do
224                 if [ "$(cat ${loopdev}/size)" -eq 0 ]
225                 then
226                         dev=$(sys2dev "${loopdev}")
227                         options=''
228
229                         if [ -n "${readonly}" ]
230                         then
231                                 if losetup --help 2>&1 | grep -q -- "-r\b"
232                                 then
233                                         options="${options} -r"
234                                 fi
235                         fi
236
237                         if [ -n "${offset}" ] && [ 0 -lt "${offset}" ]
238                         then
239                                 options="${options} -o ${offset}"
240                         fi
241
242                         if [ -z "${encryption}" ]
243                         then
244                                 losetup ${options} "${dev}" "${fspath}"
245                         else
246                                 # Loop AES encryption
247                                 while true
248                                 do
249                                         load_keymap
250
251                                         echo -n "Enter passphrase for root filesystem: " >&6
252                                         read -s passphrase
253                                         echo "${passphrase}" > /tmp/passphrase
254                                         unset passphrase
255                                         exec 9</tmp/passphrase
256                                         /sbin/losetup ${options} -e "${encryption}" -p 9 "${dev}" "${fspath}"
257                                         error=${?}
258                                         exec 9<&-
259                                         rm -f /tmp/passphrase
260
261                                         if [ 0 -eq ${error} ]
262                                         then
263                                                 unset error
264                                                 break
265                                         fi
266
267                                         echo
268                                         echo -n "There was an error decrypting the root filesystem ... Retry? [Y/n] " >&6
269                                         read answer
270
271                                         if [ "$(echo "${answer}" | cut -b1 | tr A-Z a-z)" = "n" ]
272                                         then
273                                                 unset answer
274                                                 break
275                                         fi
276                                 done
277                         fi
278
279                         echo "${dev}"
280                         return 0
281                 fi
282         done
283
284         panic "No loop devices available"
285 }
286
287 try_mount ()
288 {
289         dev="${1}"
290         mountp="${2}"
291         opts="${3}"
292         fstype="${4}"
293
294         old_mountp="$(where_is_mounted ${dev})"
295
296         if [ -n "${old_mountp}" ]
297         then
298                 if [ "${opts}" != "ro" ]
299                 then
300                         mount -o remount,"${opts}" "${dev}" "${old_mountp}" || panic "Remounting ${dev} ${opts} on ${old_mountp} failed"
301                 fi
302
303                 mount -o bind "${old_mountp}" "${mountp}" || panic "Cannot bind-mount ${old_mountp} on ${mountp}"
304         else
305                 if [ -z "${fstype}" ]
306                 then
307                         fstype=$(get_fstype "${dev}")
308                 fi
309                 mount -t "${fstype}" -o "${opts}" "${dev}" "${mountp}" || \
310                 ( echo "SKIPPING: Cannot mount ${dev} on ${mountp}, fstype=${fstype}, options=${opts}" > live-boot.log && return 0 )
311         fi
312 }
313
314 open_luks_device ()
315 {
316         dev="${1}"
317         name="$(basename ${dev})"
318         opts="--key-file=-"
319
320         load_keymap
321
322         while true
323         do
324                 /lib/cryptsetup/askpass "Enter passphrase for ${dev}: " | \
325                         /sbin/cryptsetup -T 1 luksOpen ${dev} ${name} ${opts}
326
327                 if [ 0 -eq ${?} ]
328                 then
329                         luks_device="/dev/mapper/${name}"
330                         echo ${luks_device}
331                         return 0
332                 fi
333
334                 echo >&6
335                 echo -n "There was an error decrypting ${dev} ... Retry? [Y/n] " >&6
336                 read answer
337
338                 if [ "$(echo "${answer}" | cut -b1 | tr A-Z a-z)" = "n" ]
339                 then
340                         return 2
341                 fi
342         done
343 }
344
345 find_persistent_media ()
346 {
347         # Scans devices for overlays and snapshots, and returns a whitespace
348         # separated list of how to use them. Only overlays with a partition
349         # label or file name in ${overlays} are returned, and ditto for
350         # snapshots with labels in ${snapshots}.
351         #
352         # When scanning a LUKS device, the user will be asked to enter the
353         # passphrase; on failure to enter it, or if no persistent partitions
354         # or files were found, the LUKS device is closed.
355         #
356         # For a snapshot file the return value is ${label}=${snapdata}", where
357         # ${snapdata} is the parameter used for try_snap().
358         #
359         # For all other cases (overlay/snapshot partition and overlay file) the
360         # return value is "${label}=${device}", where ${device} a device that
361         # can mount the content. In the case of an overlay file, the device
362         # containing the file will remain mounted as a side-effect.
363         #
364         # No devices in ${black_listed_devices} will be scanned, and if
365         # ${white_list_devices} is non-empty, only devices in it will be
366         # scanned.
367
368         overlays="${1}"
369         snapshots="${2}"
370         black_listed_devices="${3}"
371         white_listed_devices="${4}"
372
373         for dev in $(storage_devices "${black_listed_devices}" "${white_listed_devices}")
374         do
375                 luks_device=""
376
377                 # Checking for a luks device
378                 if echo ${PERSISTENT_ENCRYPTION} | grep -qw luks && \
379                    /sbin/cryptsetup isLuks ${dev}
380                 then
381                         if luks_device=$(open_luks_device "${dev}")
382                         then
383                                 dev="${luks_device}"
384                         else
385                                 # skip $dev since we failed/chose not to open it
386                                 continue
387                         fi
388                 elif echo ${PERSISTENT_ENCRYPTION} | grep -qwv none
389                 then
390                         # skip $dev since we don't allow unencrypted storage
391                         continue
392                 fi
393
394                 if echo ${PERSISTENT_STORAGE} | grep -qw filesystem
395                 then
396                         for label in ${overlays} ${snapshots}
397                         do
398                                 if [ "$(/sbin/blkid -s LABEL -o value $dev 2>/dev/null)" = "${label}" ]
399                                 then
400                                         overlays=$(echo ${overlays} | sed -e "s|\<${label}\>||")
401                                         snapshots=$(echo ${snapshots} | sed -e "s|\<${label}\>||")
402                                         echo "${label}=${dev}"
403                                         # skip to the next device
404                                         continue 2
405                                 fi
406                         done
407                 fi
408
409                 if echo ${PERSISTENT_STORAGE} | grep -qw file
410                 then
411                         devfstype="$(get_fstype ${dev})"
412                         overlay_on_dev=""
413                         snapshot_on_dev=""
414                         backing="/$(basename ${dev})-backing"
415                         mkdir -p "${backing}"
416                         if is_supported_fs ${devfstype} && try_mount "${dev}" "${backing}" "rw" "${devfstype}"
417                         then
418                                 for label in ${overlays}
419                                 do
420                                         path=${backing}/${PERSISTENT_PATH}${label}
421                                         if [ -f "${path}" ]
422                                         then
423                                                 overlays=$(echo ${overlays} | sed -e "s|\<${label}\>||")
424                                                 overlay_on_dev="yes"
425                                                 echo "${label}=$(setup_loop "${path}" "loop" "/sys/block/loop*")"
426                                         fi
427                                 done
428
429                                 for label in ${snapshots}
430                                 do
431                                         for ext in squashfs cpio.gz ext2 ext3 ext4 jffs2
432                                         do
433                                                 path="${PERSISTENT_PATH}${label}.${ext}"
434                                                 if [ -f "${backing}/${path}" ]
435                                                 then
436                                                         snapshots=$(echo ${snapshots} | sed -e "s|\<${label}\>||")
437                                                         snapshot_on_dev="yes"
438                                                         echo "${label}=${dev}:${backing}:${path}"
439                                                 fi
440                                         done
441                                 done
442                         fi
443                         if [ -z "${overlay_on_dev}" ]
444                         then
445                                 umount ${backing} > /dev/null 2>&1 || true
446                                 if [ -z "${snapshot_on_dev}" ] && [ -n "${luks_device}" ] && /sbin/cryptsetup status "${luks_device}" 1> /dev/null
447                                 then
448                                         /sbin/cryptsetup luksClose "${luks_device}"
449                                 fi
450                         fi
451                 fi
452         done
453 }
454
455 get_mac ()
456 {
457         mac=""
458
459         for adaptor in /sys/class/net/*
460         do
461                 status="$(cat ${adaptor}/iflink)"
462
463                 if [ "${status}" -eq 2 ]
464                 then
465                         mac="$(cat ${adaptor}/address)"
466                         mac="$(echo ${mac} | sed 's/:/-/g' | tr '[a-z]' '[A-Z]')"
467                 fi
468         done
469
470         echo ${mac}
471 }
472
473 is_luks()
474 {
475     devname="${1}"
476     if [ -x /sbin/cryptsetup ]
477     then
478         /sbin/cryptsetup isLuks "${devname}" 2>/dev/null || ret=${?}
479         return ${ret}
480     else
481         return 1
482     fi
483
484 }
485
486 removable_dev ()
487 {
488         output_format="${1}"
489         want_usb="${2}"
490         ret=
491
492         for sysblock in $(echo /sys/block/* | tr ' ' '\n' | grep -vE "/(loop|ram|dm-|fd)")
493         do
494                 dev_ok=
495                 if [ "$(cat ${sysblock}/removable)" = "1" ]
496                 then
497                         if [ -z "${want_usb}" ]
498                         then
499                                 dev_ok="yes"
500                         else
501                                 if readlink ${sysblock} | grep -q usb
502                                 then
503                                         dev_ok="yes"
504                                 fi
505                         fi
506                 fi
507
508                 if [ "${dev_ok}" = "yes" ]
509                 then
510                         case "${output_format}" in
511                                 sys)
512                                         ret="${ret} ${sysblock}"
513                                         ;;
514                                 *)
515                                         devname=$(sys2dev "${sysblock}")
516                                         ret="${ret} ${devname}"
517                                         ;;
518                         esac
519                 fi
520         done
521
522         echo "${ret}"
523 }
524
525 removable_usb_dev ()
526 {
527         output_format="${1}"
528
529         removable_dev "${output_format}" "want_usb"
530 }
531
532 non_removable_dev ()
533 {
534         output_format="${1}"
535         ret=
536
537         for sysblock in $(echo /sys/block/* | tr ' ' '\n' | grep -vE "/(loop|ram|dm-|fd)")
538         do
539                 if [ "$(cat ${sysblock}/removable)" = "0" ]
540                 then
541                         case "${output_format}" in
542                                 sys)
543                                         ret="${ret} ${sysblock}"
544                                         ;;
545                                 *)
546                                         devname=$(sys2dev "${sysblock}")
547                                         ret="${ret} ${devname}"
548                                         ;;
549                         esac
550                 fi
551         done
552
553         echo "${ret}"
554 }