X-Git-Url: http://git.grml.org/?a=blobdiff_plain;f=grml-crypt;h=73f206ca6e43f5cd97c5dbd383b520b0dfa180b3;hb=5347d32127aa14496b919346e8b61f0b2e4ffc02;hp=b9f0f266af5bd69269f2bcdf8fb4eb2a1d61f669;hpb=c1103c317b0436c41cc07c92587907771e825d9c;p=grml-crypt.git diff --git a/grml-crypt b/grml-crypt index b9f0f26..73f206c 100755 --- a/grml-crypt +++ b/grml-crypt @@ -4,7 +4,6 @@ # Authors: Michael Gebetsroither # Bug-Reports: see http://grml.org/bugs/ # License: This file is licensed under the GPL v2. -# Latest change: Don Jul 26 19:57:28 CEST 2007 [mika] ################################################################################ @@ -36,6 +35,7 @@ ACTION_="" DM_PREFIX_="grml-crypt_" FORCE_='false' FSCK_='false' +FSCK_EXTRA_OPTS_="" ENTROPY_SOURCE_='/dev/urandom' OPTIMIZED_MODE_SET_='false' OPTIMIZING_LEVEL_=0 @@ -67,7 +67,10 @@ OPTIONS: -o optimised initialisation mode (should be as secure as the default but faster) -y verifies the passphrase by asking for it twice -f force file overwriting in format mode and/or disable confirmation dialog - -F only for action start: run fsck before mounting the filesystem. Use fsck's -f option if given twice. + -F only for action start: run fsck before mounting the filesystem. + Use fsck's -f option if given twice. + -X Read next argument as a list of options to pass to fsck: + 'grml-crypt -FF -X "-y -T" start /dev/ice' will run fsck with options -y and -T. -m additional arguments to mount -v verbose (show what is going on, v++) -h this help text @@ -75,16 +78,16 @@ OPTIONS: CRYPTSETUP FORMAT OPTIONS: -S cipher size, could be 128, 192 or 256 (default=$CIPHER_SIZE_) -C cipher, should be aes-plain for pre-2.6.10 (default=$CIPHER_) - -I iteration time spend with PBKDF2 password processing in seconds (default=$ITERATION_TIME_) - -A additional arguments for cryptsetup (only supportet by format) + -I iteration time spent with PBKDF2 password processing in seconds (default=$ITERATION_TIME_) + -A additional arguments for cryptsetup (only supported by format) ACTIONS: format [mountpoint] Format a device or a file (is created with the given size if it does not exist) with the given filesystem and mount it, if a mountpoint was given. - start - Mount the device/file in the mountpoint. + start [mountpoint] + Mount the device/file in the mountpoint or to a default mountpoint. stop Umount the given mountpoint (umount, luksClose, losetup -d) @@ -156,7 +159,7 @@ function formatDevice warn "could not create filesystem on $DM_PATH_" 1 return 1 else - echo "Successully created $FSTYPE_ on encrypted $TARGET_" + echo "Successfully created $FSTYPE_ on encrypted $TARGET_" return 0 fi } @@ -166,13 +169,13 @@ function actionStart { ret_=0 - # no mountpoint, by-by if [[ "$MOUNT_POINT_" == "" ]]; then - printUsage - die 'no mountpoint given' - fi - if [ ! -d "$MOUNT_POINT_" ]; then - die "mountpoint $MOUNT_POINT_ does not exist" + MOUNT_POINT_="/media/$DM_NAME_" + else + # error out if mountpoint was given but doesn't exist + if [ ! -d "$MOUNT_POINT_" ]; then + die "mountpoint $MOUNT_POINT_ does not exist" + fi fi # removed due to unionfs problem isLuks does not work with filesystem images # without losetup @@ -192,12 +195,17 @@ function actionStart execute "$CRYPTSETUP_ $cargs_ luksOpen $TARGET_ $DM_NAME_" warn || execute "losetup -d $TARGET_" || \ die "could not luksOpen $TARGET_" if [[ "$FSCK_" == "true" ]] ; then - execute "fsck -C $DM_PATH_" || die "fsck failed on $DM_PATH_" + execute "fsck $FSCK_EXTRA_OPTS_ -C $DM_PATH_" || die "fsck failed on $DM_PATH_" elif [[ "$FSCK_" == "trueforce" ]] ; then - execute "fsck -f -C $DM_PATH_" || die "fsck failed on $DM_PATH_" + execute "fsck -f $FSCK_EXTRA_OPTS_ -C $DM_PATH_" || die "fsck failed on $DM_PATH_" fi margs_="" $READONLY_SET_ && margs_='-r' + # mountpoint was not given so we use the default one which we need to create first + if [ ! -d "$MOUNT_POINT_" ]; then + execute "mkdir -p '$MOUNT_POINT_'" || die "failed to create mountpoint $MOUNT_POINT_" + fi + udevadm settle execute "mount $margs_ $ADDITIONAL_MOUNT_ARGS_ $DM_PATH_ $MOUNT_POINT_" die } @@ -240,12 +248,15 @@ function actionStop dprint "device_=\"$device_\"" execute "umount $dm_path_" die "could not unmount $device_" + if [[ "$MOUNT_POINT_" == "/media/$dm_name_" ]]; then + rmdir "$MOUNT_POINT_" + fi execute "$CRYPTSETUP_ luksClose $dm_name_" die "could not close $dm_path_" echo "$device_" |grep loop &>/dev/null && execute "losetup -d $device_" \ die "could not delete loop device $device_" || \ execute "losetup -d $device_ &>/dev/null" eprint "could not delete loop device $device_, \ this device possibly is not a loop device => maybe bogus error" - notice "$mp_ successfully unmountet/closed/deleted" + notice "$mp_ successfully unmounted/closed/deleted" } function yesDialog @@ -291,7 +302,7 @@ function actionFormat die "could not initialise $TARGET_ with /dev/zero" else if [[ $ENTROPY_SOURCE_ == '/dev/zero' ]]; then - echo "INSERCURE mode" + echo "INSECURE mode" else echo "SECURE mode (taking /dev/urandom as source, this could take some time)" fi @@ -311,7 +322,7 @@ function actionFormat formatDevice "$init_" ret_=$? else - $FORCE_ || (yesDialog "Are you shure you want to overwrite $TARGET_ ?" || die 'You are not sure') + $FORCE_ || (yesDialog "Are you sure you want to overwrite ${TARGET_}?" || die 'You are not sure') notice 'Operating on a device' echo -n 'Initialising device with ' if [[ $OPTIMIZED_MODE_SET_ == 'true' ]]; then @@ -349,7 +360,7 @@ function actionFormat execute "mount $margs_ $ADDITIONAL_MOUNT_ARGS_ $DM_PATH_ $MOUNT_POINT_" die else if [[ $MOUNT_POINT_ != "" ]]; then - $mount_point_exists_ || warn "mountpoint $MOUNT_POINT_ does not exist, not mounting. please use \"grml-crypt start $ORIG_TARGET_ \" to start the device" + $mount_point_exists_ || warn "mountpoint $MOUNT_POINT_ does not exist, not mounting. Please use \"grml-crypt start $ORIG_TARGET_ \" to start the device" fi execute "$CRYPTSETUP_ luksClose $DM_NAME_" warn $IS_IMAGE_ && execute "losetup -d $TARGET_" warn @@ -366,7 +377,7 @@ function actionFormat ### __MAIN ### -while getopts "s:t:rzoyfFm:hvS:C:I:A:" opt; do +while getopts "s:t:rzoyfFm:hvS:C:I:A:X:" opt; do case "$opt" in s) SIZE_="$OPTARG"; SIZE_SET_='true' ;; t) FSTYPE_="$OPTARG" ;; @@ -384,6 +395,7 @@ while getopts "s:t:rzoyfFm:hvS:C:I:A:" opt; do FSCK_='true' fi ;; + X) FSCK_EXTRA_OPTS_="$OPTARG" ;; m) ADDITIONAL_MOUNT_ARGS_="$OPTARG" ;; h) printUsage; exit ;; v) let verbose_=$verbose_+1 ;; @@ -410,12 +422,12 @@ if (( $# < 2 )); then fi if (( $OPTIMIZING_LEVEL_ > 1 )); then printUsage - die "please choose ONE initialisation methode" + die "please choose ONE initialisation method" fi TARGET_="$2" -MKFS_="/sbin/mkfs.$FSTYPE_" -if [ ! -x "$MKFS_" ]; then +MKFS_="`which mkfs.$FSTYPE_`" +if [ $? != "0" ]; then die "invalid filesystem type \"$FSTYPE_\"" 1 fi