1 Commits
1.2-1 ... 0.9-2

Author SHA1 Message Date
Julien Coloos
3449995d4a Use SHA256 checksums instead of MD5
v0.9-2
2021-11-12 19:25:06 +01:00
6 changed files with 231 additions and 559 deletions

View File

@@ -1,115 +1,75 @@
2026-07-12 Julien Coloos <julien.coloos [at] gmail [dot] com> 2021-11-12 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v1.2-1 * v0.10-1
New option to log some messages to kmsg too. Option to use login shell instead of cryptsetup script
Re-enable Wake-on-LAN on network device
Change network speed to 10M during boot, to reduce consumption upon WoL.
2025-11-15 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v1.1-2
Removed 11-dm-initramfs.rules, which was added to 10-dm.rules.
See: https://gitlab.archlinux.org/archlinux/mkinitcpio/mkinitcpio/-/commit/589e0397ea55e61a08fdbcab52ad4639d382f08e
Use full version (pkgver and pkgrel) for source archive name.
Sometimes we need to change the sources, but only for minor external
dependencies diff (e.g. adding/removing upstream source), in which
case we wish to only bump pkgrel.
2022-03-24 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v1.1-1
Refactored install script to more easily spot code coming from other
nominal hooks.
Updated install script message with latest available options.
Removed dependency to '/lib/libnss_files.so', as it does not exist and
should not be needed anymore.
Prevents unwanted warning when building initcpio
==> ERROR: file not found: `/lib/libnss_files.so'
See: https://bugs.archlinux.org/task/73702
2021-11-13 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v1.0-1
Option to use login shell instead of cryptsetup unlocking script.
Option to re-enable Wake-on-LAN on network device.
2021-11-12 Julien Coloos <julien.coloos [at] gmail [dot] com> 2021-11-12 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.9-2 * v0.9-2
Use SHA256 checksums instead of MD5. Use SHA256 checksums instead of MD5
2021-10-24 Julien Coloos <julien.coloos [at] gmail [dot] com> 2021-10-24 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.9-1 * v0.9-1
Try to print network devices information when interface setup fails. Try to print network devices information when interface setup fails
2021-08-15 Julien Coloos <julien.coloos [at] gmail [dot] com> 2021-08-15 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.8-1 * v0.8-1
Include 'libgcc_s.so.1' which is necessary for (at least) proper LUKS Include 'libgcc_s.so.1' which is necessary for (at least) proper LUKS v2 handling
v2 handling.
2020-07-14 Julien Coloos <julien.coloos [at] gmail [dot] com> 2020-07-14 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.7-1 * v0.7-1
Dropped 'dsa' private key support; added 'ed25519' private key support. Dropped 'dsa' private key support; added 'ed25519' private key support
2018-03-13 Julien Coloos <julien.coloos [at] gmail [dot] com> 2018-03-13 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.6-1 * v0.6-1
Dropped '-m' option when calling dropbear (latest ArchLinux version Dropped '-m' option when calling dropbear (latest ArchLinux version does not handle it)
does not handle it).
2017-06-25 Julien Coloos <julien.coloos [at] gmail [dot] com> 2017-06-25 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.5-1 * v0.5-1
Fixed cryptsetup additional arguments handling: were not properly Fixed cryptsetup additional arguments handling: were not properly passed
passed.
2017-06-25 Julien Coloos <julien.coloos [at] gmail [dot] com> 2017-06-25 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.4-1 * v0.4-1
Fixed TRIM option handling in /etc/crypttab: 'discard' Fixed TRIM option handling in /etc/crypttab: 'discard' ('allow-discards' being the switch name to use in cryptsetup)
('allow-discards' being the switch name to use in cryptsetup).
2015-11-22 Julien Coloos <julien.coloos [at] gmail [dot] com> 2015-11-22 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.3-1 * v0.3-1
Added configurable timeout for ipconfig. Added configurable timeout for ipconfig
Moved configuration file from /etc/dropbear/initrd.env to Moved configuration file from /etc/dropbear/initrd.env to /etc/initcpio/sshcs_env
/etc/initcpio/sshcs_env.
2014-05-20 Julien Coloos <julien.coloos [at] gmail [dot] com> 2014-05-20 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.2-1 * v0.2-1
Removed unnecessary dependency: psmisc. Removed unnecessary dependency: psmisc
Added configurable timeout to unlock devices before automatic poweroff. Added configurable timeout to unlock devices before automatic poweroff
2014-05-19 Julien Coloos <julien.coloos [at] gmail [dot] com> 2014-05-19 Julien Coloos <julien.coloos [at] gmail [dot] com>
* v0.1-1 * v0.1-1
Code adapted from dropbear_initrd_encrypt. * Code adapted from dropbear_initrd_encrypt (https://aur.archlinux.org/packages/dropbear_initrd_encrypt/)
See: https://aur.archlinux.org/packages/dropbear_initrd_encrypt/ Reworked code
Dropped non-LUKS support
Rely on /etc/crypttab
Handle multiple devices to unlock
Merged dropbear and encryptssh hooks
Better resources cleanup
Reworked code.
Dropped non-LUKS support.
Rely on /etc/crypttab.
Handle multiple devices to unlock.
Merged dropbear and encryptssh hooks.
Better resources cleanup.

View File

@@ -1,21 +1,20 @@
# Maintainer: Julien Coloos <julien.coloos [at] gmail [dot] com> # Maintainer: Julien Coloos <julien.coloos [at] gmail [dot] com>
pkgname=initrd-ssh-cryptsetup pkgname=initrd-ssh-cryptsetup
pkgver=1.2 pkgver=0.10
pkgrel=1 pkgrel=1
pkgdesc="Allows to remotely unlock LUKS-encrypted devices over SSH" pkgdesc="Allows for LUKS-encrypted devices to be unlocked remotely over SSH"
arch=('any') arch=('any')
url="https://github.com/suiryc/archlinux-$pkgname" url="https://github.com/suiryc/archlinux-$pkgname"
license=('GPL3') license=('GPL3')
depends=('dropbear' 'cryptsetup' 'mkinitcpio-nfs-utils' 'iproute2' 'ethtool') depends=('dropbear' 'cryptsetup' 'mkinitcpio-nfs-utils' 'iproute2' 'ethtool')
install=$pkgname.install install=$pkgname.install
changelog='ChangeLog' changelog='ChangeLog'
source=("http://julien.coloos.free.fr/archlinux/$pkgname-$pkgver-$pkgrel.tar.xz" "$pkgname.install") source=("http://julien.coloos.free.fr/archlinux/$pkgname-$pkgver.tar.xz" "$pkgname.install")
sha256sums=('94156250bfc04490801d8575192a787363cf4637ade2473147d3f63924c5f814' sha256sums=('c3fa91fc8ba2228b3492d3709231918c8015cc3da49f516c3eacea5c0217536c'
'b84978b3c2ef32208c2b104ee2d3ce8aaec26da0bd4e9e1c83942f373bbf6285') 'b84978b3c2ef32208c2b104ee2d3ce8aaec26da0bd4e9e1c83942f373bbf6285')
package() { package() {
install -Dm644 "$srcdir/src/install/ssh-cryptsetup" "$pkgdir/usr/lib/initcpio/install/ssh-cryptsetup" install -Dm644 "$srcdir/src/install/ssh-cryptsetup" "$pkgdir/usr/lib/initcpio/install/ssh-cryptsetup"
install -Dm644 "$srcdir/src/hooks/ssh-cryptsetup" "$pkgdir/usr/lib/initcpio/hooks/ssh-cryptsetup" install -Dm644 "$srcdir/src/hooks/ssh-cryptsetup" "$pkgdir/usr/lib/initcpio/hooks/ssh-cryptsetup"
install -Dm644 "$srcdir/src/hooks/ssh-cryptsetup-tools" "$pkgdir/usr/lib/initcpio/hooks/ssh-cryptsetup-tools"
} }

View File

@@ -1,31 +1,29 @@
Personal ArchLinux package combining dropbear and cryptsetup in initramfs for unlocking LUKS-encrypted devices either locally (boot console) or remotely over SSH. Personal ArchLinux package combining dropbear and cryptsetup in initrd for unlocking LUKS-encrypted devices either locally (boot console) or remotely over SSH.
The code was reworked from legacy dropbear_initrd_encrypt AUR package. The code was reworked from legacy dropbear_initrd_encrypt AUR package.
## Installation ## Installation
After cloning the repo, installation is done as for an AUR package, e.g.: After cloning the repo, installation is done as for an AUR package, e.g.:
```bash
makepkg -sri makepkg -sri
```
## Dropbear ## Dropbear
SSH server key need to be generated for `dropbear`. SSH server key need to be generated for `dropbear`.
Either a new key can be generated with `dropbearkey`, e.g.: Either a new key can be generated with `dropbearkey`, e.g.:
```bash
dropbearkey -t ecdsa -f /etc/dropbear/dropbear_ecdsa_host_key dropbearkey -t ecdsa -f /etc/dropbear/dropbear_ecdsa_host_key
```
Or an existing OpenSSH key can be converted with `dropbearconvert` (useful so that the server fingerprint is the same with both), e.g.: Or an existing OpenSSH key can be converted with `dropbearconvert` (useful so that the server fingerprint is the same with both), e.g.:
```bash
dropbearconvert openssh dropbear /etc/ssh/ssh_host_ecdsa_key /etc/dropbear/dropbear_ecdsa_host_key dropbearconvert openssh dropbear /etc/ssh/ssh_host_ecdsa_key /etc/dropbear/dropbear_ecdsa_host_key
```
Notes: Notes:
* `rsa` and `ed25519` types are also handled * `rsa` and `ed25519` types are also handled
* OpenSSH keys must be in `PEM` format for `dropbearconvert` to properly work * OpenSSH keys must be in `PEM` format for `dropbearconvert` to properly work
If necessary an existing key file can be converted to `PEM` format using `ssh-keygen`: If necessary an existing key file can be converted to `PEM` format using `ssh-keygen`:
```bash
ssh-keygen -A -p -m PEM -f /etc/ssh/ssh_host_ecdsa_key ssh-keygen -A -p -m PEM -f /etc/ssh/ssh_host_ecdsa_key
```
## Configuration ## Configuration
As explained upon installation, the following things need to be done: As explained upon installation, the following things need to be done:
@@ -39,54 +37,33 @@ As explained upon installation, the following things need to be done:
The LUKS-encrypted devices to unlock are derived from `/etc/crypttab`. The LUKS-encrypted devices to unlock are derived from `/etc/crypttab`.
Some options can be set in `/etc/initcpio/sshcs_env` (file is sourced in initramfs shell): Some options can be set in `/etc/initcpio/sshcs_env` (file is sourced in initrd shell):
* `sshcs_opt_log_kmsg`: whether to log (debug, info, error) messages to kmsg too
- default: `1`
- many messages are only printed on console and are not concerned
- by default (debug disabled), only useful messages are concerned
- set `0` to disable
* `sshcs_opt_debug`: whether to be more verbose about ongoing actions * `sshcs_opt_debug`: whether to be more verbose about ongoing actions
- default: `0` - default: 0
- any non-zero value to enable - any non-zero value to enable
* `sshcs_opt_net_wol`: Wake-on-LAN option to set on network device
- default: `g` (MagicPacket™)
- usually WoL is disabled once in initramfs shell
- set empty to not change network device WoL setting
* `sshcs_opt_net_speed`: speed to set on network device
- default: `10`
- full duplex is enabled, and auto-negociation disabled
- latest Arch/kernel tend to keep the speed at 1000M even during WoL
- this only applies to boot phase and persists for WoL: when unlocking devices, the network is reconfigured before the OS is fully ready
- set `0` to not change network device speed
* `sshcs_opt_timeout_ipconfig`: time (in seconds) to configure IP * `sshcs_opt_timeout_ipconfig`: time (in seconds) to configure IP
- default: `10` - default: 10 seconds
* `sshcs_opt_listen`: SSH listening port * `sshcs_opt_listen`: SSH listening port
- default: `22` - default: 22
* `sshcs_opt_timeout_poweroff`: time (in seconds) to unlock devices before automatic powering off * `sshcs_opt_timeout_poweroff`: time (in seconds) to unlock devices before automatic powering off
- default (and minimum value): `120` (2 minutes) - default (and minimum value): 2 minutes
- negative value to deactivate - negative value to deactivate
* `sshcs_opt_use_shell`: whether to start a full `ash` shell
- default: `0`
- `1` to enable
- when disabled (the default), a script to unlock devices is executed instead
For example: For example:
```bash
sshcs_opt_timeout_ipconfig=30 sshcs_opt_timeout_ipconfig=30
sshcs_opt_listen=2222 sshcs_opt_listen=2222
sshcs_opt_timeout_poweroff=-1 sshcs_opt_timeout_poweroff=-1
sshcs_opt_use_shell=1
```
## Building notes ## Building notes
1. Modify the sources (features in `src`, and/or package building files) 1. Modify the sources (features in `src`, and/or package building files)
2. If `src` was modified 2. If `src` was modified
* bump `pkgver`, or `pkgrel`, in `PKGBUILD` * archive the `src` folder in `$pkgname-$pkgver.tar.xz` file; e.g.: `tar -cJf initrd-ssh-cryptsetup-0.9.tar.xz src`
* archive the `src` folder in `$pkgname-$pkgver-$pkgrel.tar.xz` file; e.g.: `tar -cJf initrd-ssh-cryptsetup-$(grep "^pkgver=" PKGBUILD | cut -d'=' -f2)-$(grep "^pkgrel=" PKGBUILD | cut -d'=' -f2).tar.xz src`
* upload the archive on the online repository (pointed by `PKGBUILD`) * upload the archive on the online repository (pointed by `PKGBUILD`)
3. Update ChangeLog 3. Update ChangeLog
4. Update `PKGBUILD` 4. Update `PKGBUILD`
* bump `pkgrel` if only building files were modified * bump `pkgver` if `src` was modified, or `pkgrel` if building files were modified
* refresh `sha256sums` with `updpkgsums` if necessary * refresh `sha256sums` with `updpkgsums` if necessary
- or manually, based on `sha256sum initrd-ssh-cryptsetup-*.tar.xz initrd-ssh-cryptsetup.install` output - or manually, based on `sha256sum initrd-ssh-cryptsetup-*.tar.xz initrd-ssh-cryptsetup.install` output
5. Delete generated archive file if any 5. Delete generated archive file if any

View File

@@ -1,30 +1,38 @@
#!/usr/bin/ash #!/usr/bin/ash
. "/usr/local/bin/ssh-cryptsetup-tools" dbg () {
[ ${sshcs_opt_debug} != 0 ] && echo "$@"
}
sshcs_env_load() {
local debug_default=0
local timeout_ipconfig_default=10
local timeout_poweroff_min=120
local use_shell_default=0
[ -e "${sshcs_env}" ] && . "${sshcs_env}"
[ -z "${sshcs_opt_debug}" ] && sshcs_opt_debug=${debug_default}
[ -z "${sshcs_opt_timeout_ipconfig}" ] && sshcs_opt_timeout_ipconfig=${timeout_ipconfig_default}
[ -n "${sshcs_opt_listen}" ] && sshcs_opt_listen="-p ${sshcs_opt_listen}"
[ -z "${sshcs_opt_timeout_poweroff}" ] && sshcs_opt_timeout_poweroff=${timeout_poweroff_min}
[ -z "${sshcs_opt_use_shell}" ] && sshcs_opt_use_shell=${use_shell_default}
[ ${sshcs_opt_timeout_poweroff} -ge 0 ] && [ ${sshcs_opt_timeout_poweroff} -lt ${timeout_poweroff_min} ] && sshcs_opt_timeout_poweroff=${timeout_poweroff_min}
}
sshcs_net_start() { sshcs_net_start() {
local iparg net_address ipconfig_out net_netmask net_gateway net_dns0 net_dns1
# we must have an 'ip' setting, and a device in it # we must have an 'ip' setting, and a device in it
[ -z "${ip}" ] && [ -n "${nfsaddrs}" ] && ip="${nfsaddrs}" [ -z "${ip}" ] && [ -n "${nfsaddrs}" ] && ip="${nfsaddrs}"
[ -z "${ip}" ] && { [ -z "${ip}" ] && {
log_dbg "No ip setting to setup network" dbg "No ip setting to setup network"
return 1 return 1
} }
net_device=$(echo ${ip} | cut -d: -f6) net_device=$(echo ${ip} | cut -d: -f6)
[ -z "${net_device}" ] && { [ -z "${net_device}" ] && {
log_dbg "No network device to setup" dbg "No network device to setup"
return 1 return 1
} }
# Note: ethtool can access WoL settings right now, but not other settings
# until the network is setup.
if [ "${sshcs_opt_net_wol:-d}" != "d" ]; then
log_dbg "Setting network device=${net_device} wol=${sshcs_opt_net_wol}"
ethtool -s "${net_device}" wol "${sshcs_opt_net_wol}"
fi
# Setup network and save some values # Setup network and save some values
# Note: some useful redirection means ('< <(...)' and '<<< "$(...)"') are # Note: some useful redirection means ('< <(...)' and '<<< "$(...)"') are
# not supported in the available shell. So we have to write code in a # not supported in the available shell. So we have to write code in a
@@ -37,7 +45,7 @@ sshcs_net_start() {
# ipconfig manual: https://git.kernel.org/pub/scm/libs/klibc/klibc.git/tree/usr/kinit/ipconfig/README.ipconfig # ipconfig manual: https://git.kernel.org/pub/scm/libs/klibc/klibc.git/tree/usr/kinit/ipconfig/README.ipconfig
ipconfig_out=$(ipconfig -t "${sshcs_opt_timeout_ipconfig}" "ip=${ip}") ipconfig_out=$(ipconfig -t "${sshcs_opt_timeout_ipconfig}" "ip=${ip}")
if [ $? -ne 0 ]; then if [ $? -ne 0 ]; then
log_err "IP configuration timeout!" err "IP configuration timeout!"
echo "Devices probing:" echo "Devices probing:"
ipconfig -n -t 5 -c none all ipconfig -n -t 5 -c none all
return 1 return 1
@@ -60,31 +68,22 @@ sshcs_net_start() {
. "${net_env}" . "${net_env}"
rm -f "${net_env}" rm -f "${net_env}"
log_msg "IP-Config: device=${net_device} ip=${net_address}/${net_netmask} gw=${net_gateway} dns0=${net_dns0} dns1=${net_dns1}" echo "IP-Config: device=${net_device} ip=${net_address}/${net_netmask} gw=${net_gateway} dns0=${net_dns0} dns1=${net_dns1}"
# Ensure we have an address [ -n "${net_address}" ]
[ -n "${net_address}" ] || return 1
# Note: We cannot change the device settings, other than WoL, before the
# network is setup.
if [ ${sshcs_opt_net_speed} != 0 ]; then
log_dbg "Setting network device=${net_device} speed=${sshcs_opt_net_speed}"
ethtool -s "${net_device}" speed "${sshcs_opt_net_speed}" duplex full autoneg off
fi
} }
sshcs_net_done() { sshcs_net_done() {
# we are done with the network # we are done with the network
if [ -n "${net_device}" ]; then if [ -n "${net_device}" ]; then
log_dbg "Setting network device=${net_device} down" dbg "Setting network device=${net_device} down"
ip addr flush dev "${net_device}" ip addr flush dev "${net_device}"
ip link set dev "${net_device}" down ip link set dev "${net_device}" down
fi fi
} }
sshcs_trapped_timeout() { sshcs_trapped_timeout() {
log_err "Timeout reached! Powering off." err "Timeout reached! Powering off."
sleep 2
poweroff -f poweroff -f
exit exit
} }
@@ -96,13 +95,12 @@ sshcs_trap_timeout() {
echo "" echo ""
echo "WARNING! Automatic poweroff will be triggered in ${sshcs_opt_timeout_poweroff}s" echo "WARNING! Automatic poweroff will be triggered in ${sshcs_opt_timeout_poweroff}s"
echo "To deactivate, please unlock devices" echo "To deactivate, please unlock devices"
echo ""
trap sshcs_trapped_timeout SIGALRM trap sshcs_trapped_timeout SIGALRM
( (
# Wait for timeout
sleep ${sshcs_opt_timeout_poweroff} sleep ${sshcs_opt_timeout_poweroff}
# Signal process (triggers poweroff)
kill -SIGALRM ${pid_init} kill -SIGALRM ${pid_init}
# Note: signal is not processed if cryptsetup is waiting for the password # Signal is not processed if cryptsetup is waiting for the password
killall cryptsetup > /dev/null 2>&1 killall cryptsetup > /dev/null 2>&1
) & ) &
pid_timeout=$! pid_timeout=$!
@@ -110,33 +108,23 @@ sshcs_trap_timeout() {
} }
sshcs_untrap_timeout() { sshcs_untrap_timeout() {
[ -z "${pid_timeout:-}" ] && return 0 [ -z "${pid_timeout}" ] && return 0
# Notes: kill ${pid_timeout}
# If there was a running SSH shell, it may also try to kill it.
# This only kills the spawned subshell, leaving the 'sleep' command still
# running until done (which is not an issue).
proc_parse_stat ${pid_timeout} && kill ${pid_timeout}
pid_timeout=
trap - SIGALRM trap - SIGALRM
log_dbg "Timeout cleared." msg "Timeout cleared."
} }
sshcs_shell_run() { sshcs_unlock() {
sshcs_trap_timeout sshcs_trap_timeout
# actual script (shared with SSH login) with which we can unlock devices # actual script (shared with SSH login) unlocking encrypted devices
sshcs_unlocked_test=0 . "${sshcs_cryptsetup_script}"
log_dbg "Running ${sshcs_shell_script}"
# Belt and suspenders: if the script does not exist, trying to source it sshcs_untrap_timeout
# actually triggers a kernel panic.
if [ ! -e "${sshcs_shell_script}" ]; then
log_err "No script to run! ${sshcs_shell_script} does not exist!"
return
fi
. "${sshcs_shell_script}"
} }
sshcs_dropbear_run() { sshcs_dropbear_unlock() {
local pid_timeout=
local dev_pts_mounted=0 local dev_pts_mounted=0
local listen= local listen=
@@ -148,22 +136,63 @@ sshcs_dropbear_run() {
fi fi
# /etc/passwd file for the root user # /etc/passwd file for the root user
echo "root:x:0:0:root:/root:${sshcs_shell_script}" > "/etc/passwd" if [ ${sshcs_opt_use_shell} -eq 0 ]; then
echo "${sshcs_shell_script}" > "/etc/shells" echo "root:x:0:0:root:/root:${dropbear_cryptsetup_shell}" > "/etc/passwd"
echo "${dropbear_cryptsetup_shell}" > "/etc/shells"
else
echo "root:x:0:0:root:/root:/usr/bin/ash" > "/etc/passwd"
fi
# root login script
cat <<EOF > "${dropbear_cryptsetup_shell}"
#!/usr/bin/ash
. "/init_functions"
if [ ! -f "${sshcs_cryptsetup_script}" ]; then
err "No cryptsetup script present! Please retry."
exit 0
fi
if [ -c "/dev/mapper/control" ]; then
CSQUIET=
. "${sshcs_cryptsetup_script}"
echo ""
echo "cryptsetup succeeded! Boot sequence should go on."
echo "Please wait and retry for standard SSH service."
else
err "Device resources missing! Please retry."
fi
echo ""
EOF
chmod a+x "${dropbear_cryptsetup_shell}"
[ ! -d "/var/log" ] && mkdir -p "/var/log" [ ! -d "/var/log" ] && mkdir -p "/var/log"
touch "/var/log/lastlog" touch "/var/log/lastlog"
log_dbg "Starting dropbear ..." msg "Starting dropbear ..."
dropbear -Esgjk -P "${path_dropbear_pid}" ${sshcs_opt_listen} dropbear -Esgjk -P "${path_dropbear_pid}" ${sshcs_opt_listen}
# Actual unlocking shell # Actual unlocking
sshcs_shell_run sshcs_unlock
# cleanup dropbear
if [ -f "${path_dropbear_pid}" ]; then
msg "Stopping dropbear ..."
kill $(cat "${path_dropbear_pid}")
rm -f "${path_dropbear_pid}"
fi
rm -f "${sshcs_cryptsetup_script}" "${dropbear_cryptsetup_shell}" "/etc/passwd" "/etc/shells" "/var/log/lastlog"
# cleanup /dev/pts if necessary
if [ ${dev_pts_mounted} -ne 0 ]; then
umount "/dev/pts"
rm -R "/dev/pts"
fi
} }
sshcs_cryptpart_process() { sshcs_cryptpart_process() {
local cryptdev_orig cryptopt cryptargs
# ensure there is a device (handle 'UUID=' format) # ensure there is a device (handle 'UUID=' format)
[ -z "${cryptdev}" ] && return 0 [ -z "${cryptdev}" ] && return 0
[ "${cryptdev#UUID=}" != "${cryptdev}" ] && cryptdev="/dev/disk/by-uuid/${cryptdev#UUID=}" [ "${cryptdev#UUID=}" != "${cryptdev}" ] && cryptdev="/dev/disk/by-uuid/${cryptdev#UUID=}"
@@ -189,61 +218,70 @@ sshcs_cryptpart_process() {
cryptdev_orig=${cryptdev} cryptdev_orig=${cryptdev}
if cryptdev=$(resolve_device "${cryptdev_orig}" ${rootdelay}); then if cryptdev=$(resolve_device "${cryptdev_orig}" ${rootdelay}); then
if cryptsetup isLuks "${cryptdev}" >/dev/null 2>&1; then if cryptsetup isLuks "${cryptdev}" >/dev/null 2>&1; then
log_dbg "Adding crypt device=${cryptdev} type=${crypttype} name=${cryptname} args=<${cryptargs}> in setup script" dbg "Adding crypt device=${cryptdev} type=${crypttype} name=${cryptname} args=<${cryptargs}> in setup script"
# update script used to unlock device either in console or SSH # update script used to unlock device either in console or SSH
[ -s "${sshcs_cryptsetup_script}" ] || cat <<'EOF' > "${sshcs_cryptsetup_script}" [ -s "${sshcs_cryptsetup_script}" ] || cat <<EOF > "${sshcs_cryptsetup_script}"
#!/usr/bin/ash
. "/usr/local/bin/ssh-cryptsetup-tools"
cycle_or_retry() { cycle_or_retry() {
local res local res
read -n 1 -s -t 5 -p "Within 5s press 'P' to poweroff, 'R' to reboot or any other key to retry. " res read -n 1 -s -t 5 -p "Whithin 5s press 'P' to poweroff, 'R' to reboot or any other key to retry. " res
echo "" echo ""
[ "${res}" == "P" ] && poweroff -f if [ "\${res}" = "P" ]; then
[ "${res}" == "R" ] && reboot -f poweroff -f
elif [ "\${res}" = "R" ]; then
reboot -f
fi
} }
try_unlock() {
EOF EOF
cat <<EOF >> "${sshcs_cryptsetup_script}" cat <<EOF >> "${sshcs_cryptsetup_script}"
# loop until device is available # loop until device is available
while [ ! -e "/dev/mapper/${cryptname}" ]; do while [ ! -e "/dev/mapper/${cryptname}" ]; do
if [ \${sshcs_unlocked_test:-0} -eq 1 ]; then if cryptsetup open --type "${crypttype}" "${cryptdev}" "${cryptname}" ${cryptargs} "\${CSQUIET}"; then
sshcs_unlocked=0 if poll_device "/dev/mapper/${cryptname}" ${rootdelay}; then
return killall cryptsetup > /dev/null 2>&1
fi
if cryptsetup open --type "${crypttype}" "${cryptdev}" "${cryptname}" ${cryptargs} "\${CSQUIET}"; then
if poll_device "/dev/mapper/${cryptname}" ${rootdelay}; then
killall cryptsetup > /dev/null 2>&1
break
fi
log_err "Device still not mapped! Please wait or retry."
elif [ ! -e "/dev/mapper/${cryptname}" ]; then
log_err "cryptsetup failed! Please retry."
else
break break
fi fi
err "Device still not mapped! Please wait or retry."
elif [ ! -e "/dev/mapper/${cryptname}" ]; then
err "cryptsetup failed! Please retry."
else
break
fi
cycle_or_retry cycle_or_retry
done done
EOF EOF
else else
log_err "Failed to manage encrypted device ${cryptdev_orig}: not a LUKS volume." err "Failed to manage encrypted device ${cryptdev_orig}: not a LUKS volume."
fi fi
fi fi
} }
sshcs_cryptpart_setup() { run_hook() {
local cryptdev crypttype cryptname cryptpass cryptoptions local etc_crypttab="/etc/crypttab"
local sshcs_env="/etc/initcpio/sshcs_env"
local path_dropbear_pid="/.dropbear.pid"
local dropbear_cryptsetup_shell="/.cryptsetup_shell.sh"
local sshcs_cryptsetup_script="/.cryptsetup_script.sh"
local net_env="/.net_env.sh"
local line iparg net_address net_device ipconfig_out net_netmask net_gateway net_dns0 net_dns1
local cryptdev cryptdev_orig crypttype cryptname cryptpass cryptoptions cryptopt cryptargs CSQUIET
# Notes: # Load our options
# The script is built piece by piece to unlock each target device. sshcs_env_load
# If there is no device to unlock, there is no script, and boot should simply
# go on as usual. # sanity check: crypttab should be present
[ ! -e "${etc_crypttab}" ] && {
dbg "No crypttab configuration to process"
return 0
}
modprobe -a -q dm-crypt >/dev/null 2>&1
[ "${quiet}" = "y" ] && CSQUIET=">/dev/null"
umask 0022
# check encrypted devices to handle # check encrypted devices to handle
cryptdev= cryptdev=
@@ -257,96 +295,24 @@ sshcs_cryptpart_setup() {
sshcs_cryptpart_process sshcs_cryptpart_process
done < "${etc_crypttab}" done < "${etc_crypttab}"
# Nothing else to do if there is no device we can unlock
[ -s "${sshcs_cryptsetup_script}" ] || return 0
# There were deviced to unlock.
# We can now finish the script.
cat <<'EOF' >> "${sshcs_cryptsetup_script}"
# No other device to unlock
}
if [ -c "/dev/mapper/control" ]; then
CSQUIET=
try_unlock
[ ${sshcs_unlocked_test:-0} -eq 1 ] && return
sshcs_check_done 0
else
if [ \${sshcs_unlocked_test:-0} -eq 1 ]; then
sshcs_unlocked=0
return
fi
echo ""
log_err "Device resources missing! Please retry."
fi
EOF
chmod a+x "${sshcs_cryptsetup_script}"
if [ ${sshcs_opt_use_shell} -eq 0 ]; then
# The script we built *is* the shell to run.
sshcs_shell_script=${sshcs_cryptsetup_script}
else
# User will have a full shell, and can call the script if needed.
cat <<EOF > "${sshcs_shell_script}"
#!/usr/bin/ash
. "/usr/local/bin/ssh-cryptsetup-tools"
echo ""
echo "Call ${sshcs_cryptsetup_script} to try unlocking device(s)"
# Now give the user its shell
/usr/bin/ash
# Check whether we are fully done
sshcs_check_done 1
EOF
chmod a+x "${sshcs_shell_script}"
fi
}
run_hook() {
local etc_crypttab="/etc/crypttab"
local path_dropbear_pid="/.dropbear.pid"
local sshcs_shell_script="/.sshcs_shell.sh"
local net_env="/.sshcs_net_env.sh"
local line net_device
local CSQUIET
# Note: options were loaded already
# sanity check: crypttab should be present
[ ! -e "${etc_crypttab}" ] && {
log_dbg "No crypttab configuration to process"
return 0
}
# Initialize random generator ASAP.
# May delay first SSH login by a few seconds otherwise.
(dd if=/dev/urandom of=/dev/null bs=4 count=1 status=none > /dev/null 2>&1) &
(dd if=/dev/random of=/dev/null bs=4 count=1 status=none > /dev/null 2>&1) &
modprobe -a -q dm-crypt >/dev/null 2>&1
[ "${quiet}" = "y" ] && CSQUIET=">/dev/null"
umask 0022
# Setup script used to unlock device either in console or SSH
sshcs_cryptpart_setup
if [ ! -e "${sshcs_cryptsetup_script}" ]; then if [ ! -e "${sshcs_cryptsetup_script}" ]; then
log_err "No encrypted device found! Skipping crypt remote unlocking." err "No encrypted device found! Skipping crypt remote unlocking."
return 0 return 0
fi fi
# start and check network # start and check network
if ! sshcs_net_start; then if ! sshcs_net_start; then
log_err "Net interface not available! Skipping crypt remote unlocking." err "Net interface not available! Skipping crypt remote unlocking."
# We still allow to unlock locally with timeout # We still allow to unlock locally with timeout
sshcs_shell_run sshcs_unlock
# stop the network if possible
sshcs_net_done
return 0 return 0
fi fi
# time to unlock (through console or dropbear) # time to unlock (through console or dropbear)
sshcs_dropbear_run sshcs_dropbear_unlock
# stop the network before going on in boot sequence
sshcs_net_done
} }

View File

@@ -1,221 +0,0 @@
#!/usr/bin/ash
. "/init_functions"
# Log debug message, if debug enabled.
# Also log as kmsg if enabled.
log_dbg() {
[ ${sshcs_opt_debug} -eq 0 ] && return 0
echo "$@"
[ ${sshcs_opt_log_kmsg} -eq 0 ] && return 0
echo "<31>sshcs: $@" > /dev/kmsg
}
# Log information message, even if quiet.
# Also log as kmsg if enabled.
log_msg() {
echo "$@"
[ ${sshcs_opt_log_kmsg} -eq 0 ] && return 0
echo "<30>sshcs: $@" > /dev/kmsg
}
# Log error message (prefixed with "ERROR: " in console).
# Also log as kmsg if enabled.
log_err() {
err "$@"
[ ${sshcs_opt_log_kmsg} -eq 0 ] && return 0
echo "<27>sshcs: $@" > /dev/kmsg
}
sshcs_env_load() {
local sshcs_env="/etc/initcpio/sshcs_env"
local log_kmsg_default=1
local debug_default=0
local net_wol_default=g
local net_speed_default=10
local timeout_ipconfig_default=10
local timeout_poweroff_min=120
local use_shell_default=0
[ ${sshcs_env_loaded:-0} -eq 1 ] && return
[ -e "${sshcs_env}" ] && . "${sshcs_env}"
sshcs_env_loaded=1
[ -z "${sshcs_opt_log_kmsg}" ] && sshcs_opt_log_kmsg=${log_kmsg_default}
[ -z "${sshcs_opt_debug}" ] && sshcs_opt_debug=${debug_default}
[ -z "${sshcs_opt_net_wol}" ] && sshcs_opt_net_wol=${net_wol_default}
[ -z "${sshcs_opt_net_speed}" ] && sshcs_opt_net_speed=${net_speed_default}
[ -z "${sshcs_opt_timeout_ipconfig}" ] && sshcs_opt_timeout_ipconfig=${timeout_ipconfig_default}
[ -n "${sshcs_opt_listen}" ] && sshcs_opt_listen="-p ${sshcs_opt_listen}"
[ -z "${sshcs_opt_timeout_poweroff}" ] && sshcs_opt_timeout_poweroff=${timeout_poweroff_min}
[ -z "${sshcs_opt_use_shell}" ] && sshcs_opt_use_shell=${use_shell_default}
[ ${sshcs_opt_timeout_poweroff} -ge 0 ] && [ ${sshcs_opt_timeout_poweroff} -lt ${timeout_poweroff_min} ] && sshcs_opt_timeout_poweroff=${timeout_poweroff_min}
sshcs_cryptsetup_script="/.sshcs_cryptsetup_script.sh"
}
proc_parse_stat() {
local unused
pid=$1
cmd=
ppid=
[ ! -e /proc/${pid}/stat ] && return 1
read unused cmd unused ppid unused < /proc/${pid}/stat
}
proc_find_parent_cmd() {
pid=$1
proc_parse_stat ${pid} || return 1
while [ ${ppid} -gt 1 ]
do
proc_parse_stat ${ppid} || return 1
if [ "${cmd}" == "($2)" ]; then
ppid=${pid}
pid=$1
return 0
fi
pid=${ppid}
done
return 1
}
proc_is_console() {
if [ -z "${is_console:-}" ]; then
# We are in console if we were not forked from dropbear.
is_console=1
proc_find_parent_cmd $$ "dropbear" && is_console=0
fi
[ "${is_console}" -eq 1 ]
}
sshcs_cleanup() {
local pgrep_output
# Reminders:
# We are called when devices have been unlocked.
#
# We are only called as part of the main shell (whether on console - the init
# script - or through SSH - as the user login shell), and once we return our
# parent shell will end.
#
# The unlocking script does 'killall cryptsetup' after each successful unlock,
# which is used to wakeup any other running unlocking script.
# Thus as long as all devices have been unlocked, we don't expect any script
# to be stuck on 'cryptsetup' calls.
# If we did change the network speed, time to reset it.
if [ -n "${net_device}" ] && [ ${sshcs_opt_net_speed} != 0 ]; then
log_dbg "Restoring network device=${net_device} speed"
ethtool -s "${net_device}" autoneg on
fi
if proc_is_console; then
# We are in the console.
# It is time to properly end the processes we started and files we created.
# When using a shell - instead of directly calling the unlocking script -
# we also need to signal any SSH shell so that it is properly cleaned too.
# cleanup dropbear
if [ -f "${path_dropbear_pid}" ]; then
log_dbg "Stopping dropbear ..."
kill $(cat "${path_dropbear_pid}")
rm -f "${path_dropbear_pid}"
fi
if [ ${sshcs_opt_use_shell} -eq 1 ]; then
# Find and kill all shells spawned by SSH.
# This is necessary to properly terminate both these shells and the spawned
# SSH processes.
# Reminder: "... | ..." does fork a subshell
log_dbg "Searching SSH shells ..."
pgrep_output=$(pgrep /usr/bin/ash)
pgrep_output=$(echo "${pgrep_output}" | grep -E -v "^(|1|$$)$")
echo "${pgrep_output}" | while read pid; do
proc_parse_stat ${pid} || continue
proc_find_parent_cmd ${pid} "dropbear" || continue
log_dbg "Killing SSH shell pid=${pid}"
kill -SIGHUP ${pid}
done
fi
# cleanup /dev/pts if necessary
if [ ${dev_pts_mounted:-0} -ne 0 ]; then
umount "/dev/pts"
rm -R "/dev/pts"
fi
# stop the network before going on in boot sequence
sshcs_net_done
rm -f "${sshcs_cryptsetup_script}" "${sshcs_shell_script}" "/etc/passwd" "/etc/shells" "/var/log/lastlog"
elif [ ${sshcs_opt_use_shell} -eq 1 ]; then
# We are in a SSH shell session.
# Find and kill console shell.
# This is necessary so that our script launched from the init process can
# finally check that devices have been properly unlocked, properly end and
# let the init process end booting.
# Note: as a side effect, this will also kill the shell that was forked to
# trigger a timeout, which is fine (we want to kill it, either from here or
# from the init shell).
log_dbg "Searching console shells ..."
pgrep_output=$(pgrep /usr/bin/ash)
pgrep_output=$(echo "${pgrep_output}" | grep -E -v "^(|1|$$)$")
echo "${pgrep_output}" | while read pid; do
proc_find_parent_cmd ${pid} "dropbear" && continue
log_dbg "Killing console shell pid=${pid}"
kill -SIGHUP ${pid}
done
fi
# else: when in SSH shell script, we have nothing else to do other than exit.
log_dbg "All done"
}
sshcs_check_done() {
# Whether we are called from the main script: that is whether the shell will
# end when we return.
local finalize=$1
# This is always the main script when not using shell
[ ${sshcs_opt_use_shell} -eq 0 ] && finalize=1
# Reset timeout when applicable: only possible from init script.
proc_is_console && type sshcs_untrap_timeout > /dev/null 2>&1 && sshcs_untrap_timeout
# Check devices are unlocked.
sshcs_unlocked_test=1
sshcs_unlocked=1
. "${sshcs_cryptsetup_script}"
if [ ${sshcs_unlocked} -ne 1 ]; then
echo ""
# When finalizing in console, power off
if [ ${finalize} -eq 1 ] && proc_is_console; then
log_err "Devices are still locked! Powering off."
poweroff -f
fi
# When in shell or SSH, let user try again
log_err "Devices are still locked! Please retry."
return
fi
if [ ${finalize} -eq 0 ]; then
# Kill our parent (the interactive shell); the script that launched it will
# do finalization.
proc_parse_stat $$
kill -SIGHUP ${ppid}
exit 0
fi
echo ""
log_msg "cryptsetup succeeded! Boot sequence should go on."
proc_is_console || echo "Please wait and reconnect to nominal SSH service."
sshcs_cleanup
}
sshcs_env_load

View File

@@ -52,70 +52,53 @@ build() {
sshcs_check_keys sshcs_check_keys
# Note: parts of this script (modules/binaries/files added) are the same than add_checked_modules "/drivers/net/"
# other install scripts (/usr/lib/initcpio/install/): # Note: parts of this script (modules/binaries added) are the same than the
# - 'encrypt': nominal support of encrypted volumes at boot time # 'encrypt' install script (/usr/lib/initcpio/install/encrypt) which is the
# - 'net': network tools # nominal one to deal with encrypted volumes at boot time.
add_module dm-crypt
## Modules # Note: crypto modules are necessary
# (from 'encrypt') if [ -n "${CRYPTO_MODULES}" ]; then
add_module 'dm-crypt'
add_module 'dm-integrity'
if [[ $CRYPTO_MODULES ]]; then
local mod local mod
for mod in $CRYPTO_MODULES; do for mod in ${CRYPTO_MODULES}; do
add_module "$mod" add_module "${mod}"
done done
else else
add_all_modules '/crypto/' add_all_modules "/crypto/"
fi fi
# (from 'net')
add_checked_modules '/drivers/net/'
## Binaries
# (from 'encrypt')
add_binary 'cryptsetup'
# cryptsetup calls pthread_create(), which dlopen()s libgcc_s.so.1
# Note: at least necessary for LUKS v2 volumes.
# Also see similar/related bug reports (e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=950254).
add_binary '/usr/lib/libgcc_s.so.1'
# (from 'net')
add_binary '/usr/lib/initcpio/ipconfig' '/bin/ipconfig'
# (ours)
# Note: dmsetup is necessary for device mapper features # Note: dmsetup is necessary for device mapper features
add_binary 'dmsetup' add_binary "cryptsetup"
add_binary 'dropbear' add_binary "dmsetup"
add_binary 'ip' add_binary "dropbear"
add_binary 'ethtool' add_binary "ip"
add_binary "/usr/lib/initcpio/ipconfig" "/bin/ipconfig"
add_binary "ethtool"
# Our hook files
## Other files
# (from 'encrypt')
# cryptsetup-related files
map add_udev_rule \
'10-dm.rules' \
'13-dm-disk.rules' \
'95-dm-notify.rules'
# (ours)
# Our script and options
[ -e "${sshcs_env}" ] && add_file "${sshcs_env}" [ -e "${sshcs_env}" ] && add_file "${sshcs_env}"
# Note: use /usr/local/bin, even though everything actually points to /usr/bin
# in initramfs. # auth-related files
add_file '/usr/lib/initcpio/hooks/ssh-cryptsetup-tools' '/usr/local/bin/ssh-cryptsetup-tools' add_file "/lib/libnss_files.so"
# SSH-related files # SSH-related files
add_file "${dropbear_authorized_keys}" '/root/.ssh/authorized_keys' add_file "${dropbear_authorized_keys}" "/root/.ssh/authorized_keys"
for keytype in "${dropbear_key_types[@]}"; do for keytype in "${dropbear_key_types[@]}"; do
add_file "${dropbear_keyfile_prefix}${keytype}${dropbear_keyfile_suffix}" add_file "${dropbear_keyfile_prefix}${keytype}${dropbear_keyfile_suffix}"
done done
# crypt partitions # cryptsetup-related files
add_file "${etc_crypttab}" add_file "${etc_crypttab}"
add_file "/usr/lib/udev/rules.d/10-dm.rules"
add_file "/usr/lib/udev/rules.d/13-dm-disk.rules"
add_file "/usr/lib/udev/rules.d/95-dm-notify.rules"
add_file "/usr/lib/initcpio/udev/11-dm-initramfs.rules" "/usr/lib/udev/rules.d/11-dm-initramfs.rules"
# At least with LUKS v2 volumes, cryptsetup calls pthread_cancel(), which
# dlopen()s libgcc_s.so.1.
# See the nominal 'encrypt' module, and similar/related bug reports (e.g.
# https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=950254).
add_binary "/usr/lib/libgcc_s.so.1"
add_runscript add_runscript
} }
@@ -129,8 +112,15 @@ Network is configured with 'ip=' kernel parameter (see 'mkinitcpio-nfs-utils').
Authorized SSH key(s) must be present in '/etc/dropbear/initrd.authorized_keys'. Authorized SSH key(s) must be present in '/etc/dropbear/initrd.authorized_keys'.
LUKS encrypted devices to unlock are derived from '/etc/crypttab', which must LUKS encrypted devices to unlock are derived from '/etc/crypttab', which must
be present. be present.
Some options can be set in '/etc/initcpio/sshcs_env'. Some options can be set in '/etc/initcpio/sshcs_env' (file is sourced in
See the README for more details. initrd shell):
* 'sshcs_opt_timeout_ipconfig': time (s) to configure IP
- default: 10 seconds
* 'sshcs_opt_listen': listening port (22 by default)
* 'sshcs_opt_timeout_poweroff': time (s) to unlock devices before automatic
powering off
- default (and minimum value): 2 minutes
- negative value to deactivate
Each SSH server key ('dropbear_rsa_host_key', 'dropbear_ecdsa_host_key' and Each SSH server key ('dropbear_rsa_host_key', 'dropbear_ecdsa_host_key' and
'dropbear_ed25519_host_key' in '/etc/dropbear' folder) is imported from OpenSSH 'dropbear_ed25519_host_key' in '/etc/dropbear' folder) is imported from OpenSSH
@@ -138,3 +128,4 @@ if present or generated if missing. Fingerprints are displayed upon building
the initramfs image. the initramfs image.
EOF EOF
} }