From: Eric Biggers <ebiggers@kernel.org>
To: linux-xfs@vger.kernel.org
Cc: fstests@vger.kernel.org, linux-fscrypt@vger.kernel.org
Subject: [PATCH v3 8/9] xfs_io/encrypt: add 'rm_enckey' command
Date: Fri, 27 Sep 2019 17:02:42 -0700 [thread overview]
Message-ID: <20190928000243.77634-9-ebiggers@kernel.org> (raw)
In-Reply-To: <20190928000243.77634-1-ebiggers@kernel.org>
From: Eric Biggers <ebiggers@google.com>
Add a 'rm_enckey' command to xfs_io, to provide a command-line interface
to the FS_IOC_REMOVE_ENCRYPTION_KEY and
FS_IOC_REMOVE_ENCRYPTION_KEY_ALL_USERS ioctls.
Signed-off-by: Eric Biggers <ebiggers@google.com>
---
io/encrypt.c | 75 +++++++++++++++++++++++++++++++++++++++++++++++
man/man8/xfs_io.8 | 15 ++++++++++
2 files changed, 90 insertions(+)
diff --git a/io/encrypt.c b/io/encrypt.c
index 056f15bc..e87ac393 100644
--- a/io/encrypt.c
+++ b/io/encrypt.c
@@ -150,6 +150,7 @@ static const struct {
static cmdinfo_t get_encpolicy_cmd;
static cmdinfo_t set_encpolicy_cmd;
static cmdinfo_t add_enckey_cmd;
+static cmdinfo_t rm_enckey_cmd;
static void
get_encpolicy_help(void)
@@ -220,6 +221,21 @@ add_enckey_help(void)
"\n"));
}
+static void
+rm_enckey_help(void)
+{
+ printf(_(
+"\n"
+" remove an encryption key from the filesystem\n"
+"\n"
+" Examples:\n"
+" 'rm_enckey 0000111122223333' - remove key for v1 policies w/ given descriptor\n"
+" 'rm_enckey 00001111222233334444555566667777' - remove key for v2 policies w/ given identifier\n"
+"\n"
+" -a -- remove key for all users who have added it (privileged operation)\n"
+"\n"));
+}
+
static bool
parse_byte_value(const char *arg, __u8 *value_ret)
{
@@ -705,6 +721,54 @@ out:
return 0;
}
+static int
+rm_enckey_f(int argc, char **argv)
+{
+ int c;
+ struct fscrypt_remove_key_arg arg;
+ int ioc = FS_IOC_REMOVE_ENCRYPTION_KEY;
+
+ memset(&arg, 0, sizeof(arg));
+
+ while ((c = getopt(argc, argv, "a")) != EOF) {
+ switch (c) {
+ case 'a':
+ ioc = FS_IOC_REMOVE_ENCRYPTION_KEY_ALL_USERS;
+ break;
+ default:
+ return command_usage(&rm_enckey_cmd);
+ }
+ }
+ argc -= optind;
+ argv += optind;
+
+ if (argc != 1)
+ return command_usage(&rm_enckey_cmd);
+
+ if (str2keyspec(argv[0], -1, &arg.key_spec) < 0)
+ return 0;
+
+ if (ioctl(file->fd, ioc, &arg) != 0) {
+ fprintf(stderr, _("Error removing encryption key: %s\n"),
+ strerror(errno));
+ exitcode = 1;
+ return 0;
+ }
+ if (arg.removal_status_flags &
+ FSCRYPT_KEY_REMOVAL_STATUS_FLAG_OTHER_USERS) {
+ printf(_("Removed user's claim to encryption key with %s %s\n"),
+ keyspectype(&arg.key_spec), keyspec2str(&arg.key_spec));
+ } else if (arg.removal_status_flags &
+ FSCRYPT_KEY_REMOVAL_STATUS_FLAG_FILES_BUSY) {
+ printf(_("Removed encryption key with %s %s, but files still busy\n"),
+ keyspectype(&arg.key_spec), keyspec2str(&arg.key_spec));
+ } else {
+ printf(_("Removed encryption key with %s %s\n"),
+ keyspectype(&arg.key_spec), keyspec2str(&arg.key_spec));
+ }
+ return 0;
+}
+
void
encrypt_init(void)
{
@@ -738,7 +802,18 @@ encrypt_init(void)
add_enckey_cmd.oneline = _("add an encryption key to the filesystem");
add_enckey_cmd.help = add_enckey_help;
+ rm_enckey_cmd.name = "rm_enckey";
+ rm_enckey_cmd.cfunc = rm_enckey_f;
+ rm_enckey_cmd.args = _("[-a] keyspec");
+ rm_enckey_cmd.argmin = 0;
+ rm_enckey_cmd.argmax = -1;
+ rm_enckey_cmd.flags = CMD_NOMAP_OK | CMD_FOREIGN_OK;
+ rm_enckey_cmd.oneline =
+ _("remove an encryption key from the filesystem");
+ rm_enckey_cmd.help = rm_enckey_help;
+
add_command(&get_encpolicy_cmd);
add_command(&set_encpolicy_cmd);
add_command(&add_enckey_cmd);
+ add_command(&rm_enckey_cmd);
}
diff --git a/man/man8/xfs_io.8 b/man/man8/xfs_io.8
index 7d6a23fe..be90905a 100644
--- a/man/man8/xfs_io.8
+++ b/man/man8/xfs_io.8
@@ -764,6 +764,21 @@ Otherwise, the key is added as a v2 policy key, and on success the resulting
.RE
.PD
.TP
+.BI "rm_enckey [ -a ] " keyspec
+On filesystems that support encryption, remove an encryption key from the
+filesystem containing the currently open file.
+.I keyspec
+is a hex string specifying the key to remove, as a 16-character "key descriptor"
+or a 32-character "key identifier".
+.RS 1.0i
+.PD 0
+.TP 0.4i
+.BI \-a
+Remove the key for all users who have added it, not just the current user. This
+is a privileged operation.
+.RE
+.PD
+.TP
.BR lsattr " [ " \-R " | " \-D " | " \-a " | " \-v " ]"
List extended inode flags on the currently open file. If the
.B \-R
--
2.23.0.444.g18eeb5a265-goog
next prev parent reply other threads:[~2019-09-28 0:03 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-09-28 0:02 [PATCH v3 0/9] xfsprogs: support fscrypt API additions in xfs_io Eric Biggers
2019-09-28 0:02 ` [PATCH v3 1/9] xfs_io/encrypt: remove unimplemented encryption modes Eric Biggers
2019-09-28 0:02 ` [PATCH v3 2/9] xfs_io/encrypt: update to UAPI definitions from Linux v5.4 Eric Biggers
2019-09-28 0:02 ` [PATCH v3 3/9] xfs_io/encrypt: generate encryption modes for 'help set_encpolicy' Eric Biggers
2019-09-28 0:02 ` [PATCH v3 4/9] xfs_io/encrypt: add new encryption modes Eric Biggers
2019-09-28 0:02 ` [PATCH v3 5/9] xfs_io/encrypt: extend 'get_encpolicy' to support v2 policies Eric Biggers
2019-09-28 0:02 ` [PATCH v3 6/9] xfs_io/encrypt: extend 'set_encpolicy' " Eric Biggers
2019-09-28 0:02 ` [PATCH v3 7/9] xfs_io/encrypt: add 'add_enckey' command Eric Biggers
2019-09-28 0:02 ` Eric Biggers [this message]
2019-09-28 0:02 ` [PATCH v3 9/9] xfs_io/encrypt: add 'enckey_status' command Eric Biggers
2019-09-30 19:29 ` [PATCH v3 0/9] xfsprogs: support fscrypt API additions in xfs_io Eric Sandeen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190928000243.77634-9-ebiggers@kernel.org \
--to=ebiggers@kernel.org \
--cc=fstests@vger.kernel.org \
--cc=linux-fscrypt@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).