[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[RFC PATCH 17/19] tools/vhost-user-rpmb: add key persistence
From: |
Alex Bennée |
Subject: |
[RFC PATCH 17/19] tools/vhost-user-rpmb: add key persistence |
Date: |
Fri, 25 Sep 2020 13:51:45 +0100 |
Add support for persisting the key in --key-path. By default it will
accept the program-key command and store the key in the key file. If
you pass --key-set then the key is deemed to be programmed and can't
be re-programmed. Obviously you will need some other mechanism to let
the guest know what the key is so it can do other operations.
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
---
tools/vhost-user-rpmb/main.c | 37 ++++++++++++++++++++++++++++++++++++
1 file changed, 37 insertions(+)
diff --git a/tools/vhost-user-rpmb/main.c b/tools/vhost-user-rpmb/main.c
index 49d4e00b24a9..34607ad19429 100644
--- a/tools/vhost-user-rpmb/main.c
+++ b/tools/vhost-user-rpmb/main.c
@@ -38,15 +38,19 @@
static gchar *socket_path;
static char *flash_path;
+static char *key_path;
static gint socket_fd = -1;
static gboolean print_cap;
static gboolean verbose;
static gboolean debug;
+static gboolean key_set;
static GOptionEntry options[] =
{
{ "socket-path", 0, 0, G_OPTION_ARG_FILENAME, &socket_path, "Location of
vhost-user Unix domain socket, incompatible with --fd", "PATH" },
{ "flash-path", 0, 0, G_OPTION_ARG_FILENAME, &flash_path, "Location of raw
flash image file", "PATH" },
+ { "key-path", 0, 0, G_OPTION_ARG_FILENAME, &key_path, "Location of
persistent keyfile", "KEY"},
+ { "key-set", 0, 0, G_OPTION_ARG_NONE, &key_set, "Is the key already
programmed", NULL},
{ "fd", 0, 0, G_OPTION_ARG_INT, &socket_fd, "Specify the file-descriptor
of the backend, incompatible with --socket-path", "FD" },
{ "print-capabilities", 0, 0, G_OPTION_ARG_NONE, &print_cap, "Output to
stdout the backend capabilities in JSON format and exit", NULL},
{ "verbose", 'v', 0, G_OPTION_ARG_NONE, &verbose, "Be more verbose in
output", NULL},
@@ -296,8 +300,18 @@ static void vrpmb_handle_program_key(VuDev *dev, struct
virtio_rpmb_frame *frame
} else {
r->key = g_memdup(&frame->key_mac[0], RPMB_KEY_MAC_SIZE);
r->last_result = VIRTIO_RPMB_RES_OK;
+ if (key_path) {
+ GError *err = NULL;
+ if (!g_file_set_contents(key_path, (char *) r->key,
+ RPMB_KEY_MAC_SIZE, &err)) {
+ g_warning("%s: unable to persist key data to %s: %s",
+ __func__, key_path, err->message);
+ g_error_free(err);
+ }
+ }
}
+
g_info("%s: req_resp = %x, result = %x", __func__,
r->last_reqresp, r->last_result);
return;
@@ -709,6 +723,25 @@ static bool vrpmb_load_flash_image(VuRpmb *r, char
*img_path)
return true;
}
+static void vrpmb_set_key(VuRpmb *r, char *key_path)
+{
+ GError *err = NULL;
+ gsize length;
+
+ if (!g_file_get_contents(key_path, (char **) &r->key, &length, &err)) {
+ g_print("Unable to read %s: %s", key_path, err->message);
+ exit(1);
+ }
+ if (length < RPMB_KEY_MAC_SIZE) {
+ g_print("key file to small %ld < %d", length, RPMB_KEY_MAC_SIZE);
+ exit(1);
+ } else if (length > RPMB_KEY_MAC_SIZE) {
+ /* being too big isn't fatal, we just ignore the excess */
+ g_warning("%ld bytes of %s ignore (file too big)",
+ length - RPMB_KEY_MAC_SIZE, key_path);
+ }
+}
+
static void vrpmb_destroy(VuRpmb *r)
{
vug_deinit(&r->dev);
@@ -760,6 +793,10 @@ int main(int argc, char *argv[])
vrpmb_load_flash_image(&rpmb, flash_path);
}
+ if (key_path && key_set) {
+ vrpmb_set_key(&rpmb, key_path);
+ }
+
if (!socket_path && socket_fd < 0) {
g_printerr("Please specify either --fd or --socket-path\n");
exit(EXIT_FAILURE);
--
2.20.1
- [RFC PATCH 05/19] virtio-pci: add notification trace points, (continued)
- [RFC PATCH 05/19] virtio-pci: add notification trace points, Alex Bennée, 2020/09/25
- [RFC PATCH 03/19] hw/virtio: move virtio-pci.h into shared include space, Alex Bennée, 2020/09/25
- [RFC PATCH 06/19] tools/vhost-user-rpmb: add boilerplate and initial main, Alex Bennée, 2020/09/25
- [RFC PATCH 07/19] tools/vhost-user-rpmb: implement --print-capabilities, Alex Bennée, 2020/09/25
- [RFC PATCH 08/19] tools/vhost-user-rpmb: connect to fd and instantiate basic run loop, Alex Bennée, 2020/09/25
- [RFC PATCH 09/19] tools/vhost-user-rpmb: add a --verbose/debug flags for logging, Alex Bennée, 2020/09/25
- [RFC PATCH 11/19] tools/vhost-user-rpmb: add --flash-path for backing store, Alex Bennée, 2020/09/25
- [RFC PATCH 12/19] tools/vhost-user-rpmb: import hmac_sha256 functions, Alex Bennée, 2020/09/25
- [RFC PATCH 10/19] tools/vhost-user-rpmb: handle shutdown and SIGINT/SIGHUP cleanly, Alex Bennée, 2020/09/25
- [RFC PATCH 17/19] tools/vhost-user-rpmb: add key persistence,
Alex Bennée <=
- [RFC PATCH 15/19] tools/vhost-user-rpmb: implement VIRTIO_RPMB_REQ_DATA_WRITE, Alex Bennée, 2020/09/25
- [RFC PATCH 16/19] tools/vhost-user-rpmb: implement VIRTIO_RPMB_REQ_DATA_READ, Alex Bennée, 2020/09/25
- [RFC PATCH 18/19] tools/vhost-user-rpmb: allow setting of the write_count, Alex Bennée, 2020/09/25
- [RFC PATCH 13/19] tools/vhost-user-rpmb: implement the PROGRAM_KEY handshake, Alex Bennée, 2020/09/25
- [RFC PATCH 19/19] docs: add a man page for vhost-user-rpmb, Alex Bennée, 2020/09/25
- [RFC PATCH 14/19] tools/vhost-user-rpmb: implement VIRTIO_RPMB_REQ_GET_WRITE_COUNTER, Alex Bennée, 2020/09/25
- Re: [RFC PATCH 00/19] vhost-user-rpmb (Replay Protected Memory Block), no-reply, 2020/09/25