1 /* mount.c - Mount a crypto container
2 * Copyright (C) 2009 Free Software Foundation, Inc.
4 * This file is part of GnuPG.
6 * GnuPG is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
11 * GnuPG is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, see <https://www.gnu.org/licenses/>.
36 #include "mountinfo.h"
39 #include "server.h" /*(g13_keyblob_decrypt)*/
40 #include "../common/sysutils.h"
41 #include "call-syshelp.h"
44 /* Mount the container with name FILENAME at MOUNTPOINT. */
46 g13_mount_container (ctrl_t ctrl, const char *filename, const char *mountpoint)
50 int needs_syshelp = 0;
51 void *enckeyblob = NULL;
55 tupledesc_t tuples = NULL;
57 const unsigned char *value;
60 char *mountpoint_buffer = NULL;
61 char *blockdev_buffer = NULL;
63 /* Decide whether we need to use the g13-syshelp. */
64 err = call_syshelp_find_device (ctrl, filename, &blockdev_buffer);
68 filename = blockdev_buffer;
70 else if (gpg_err_code (err) != GPG_ERR_NOT_FOUND)
72 log_error ("error finding device '%s': %s <%s>\n",
73 filename, gpg_strerror (err), gpg_strsource (err));
78 /* A quick check to see whether we can the container exists. */
79 if (access (filename, R_OK))
80 return gpg_error_from_syserror ();
85 mountpoint_buffer = xtrystrdup ("/tmp/g13-XXXXXX");
86 if (!mountpoint_buffer)
87 return gpg_error_from_syserror ();
88 if (!gnupg_mkdtemp (mountpoint_buffer))
90 err = gpg_error_from_syserror ();
91 log_error (_("can't create directory '%s': %s\n"),
92 "/tmp/g13-XXXXXX", gpg_strerror (err));
93 xfree (mountpoint_buffer);
96 mountpoint = mountpoint_buffer;
104 /* Try to take a lock. */
105 lock = dotlock_create (filename, 0);
108 xfree (mountpoint_buffer);
109 return gpg_error_from_syserror ();
112 if (dotlock_take (lock, 0))
114 err = gpg_error_from_syserror ();
119 /* Check again that the file exists. */
124 if (stat (filename, &sb))
126 err = gpg_error_from_syserror ();
131 /* Read the encrypted keyblob. */
134 err = call_syshelp_set_device (ctrl, filename);
137 err = call_syshelp_get_keyblob (ctrl, &enckeyblob, &enckeybloblen);
140 err = g13_keyblob_read (filename, &enckeyblob, &enckeybloblen);
144 /* Decrypt that keyblob and store it in a tuple descriptor. */
145 err = g13_keyblob_decrypt (ctrl, enckeyblob, enckeybloblen,
146 &keyblob, &keybloblen);
152 err = create_tupledesc (&tuples, keyblob, keybloblen);
157 if (gpg_err_code (err) == GPG_ERR_NOT_SUPPORTED)
158 log_error ("unknown keyblob version\n");
162 dump_tupledesc (tuples);
164 value = find_tuple (tuples, KEYBLOB_TAG_CONTTYPE, &n);
165 if (!value || n != 2)
168 conttype = (value[0] << 8 | value[1]);
169 if (!be_is_supported_conttype (conttype))
171 log_error ("content type %d is not supported\n", conttype);
172 err = gpg_error (GPG_ERR_NOT_SUPPORTED);
175 err = be_mount_container (ctrl, conttype, filename, mountpoint, tuples, &rid);
178 else if (conttype == CONTTYPE_DM_CRYPT)
179 g13_request_shutdown ();
182 /* Unless this is a DM-CRYPT mount we put it into our mounttable
183 so that we can manage the mounts ourselves. For dm-crypt we
184 do not keep a process to monitor he mounts (for now). */
185 err = mountinfo_add_mount (filename, mountpoint, conttype, rid,
186 !!mountpoint_buffer);
187 /* Fixme: What shall we do if this fails? Add a provisional
188 mountinfo entry first and remove it on error? */
191 char *tmp = percent_plus_escape (mountpoint);
193 err = gpg_error_from_syserror ();
196 g13_status (ctrl, STATUS_MOUNTPOINT, tmp, NULL);
203 destroy_tupledesc (tuples);
206 dotlock_destroy (lock);
207 xfree (mountpoint_buffer);
208 xfree (blockdev_buffer);
213 /* Unmount the container with name FILENAME or the one mounted at
214 MOUNTPOINT. If both are given the FILENAME takes precedence. */
216 g13_umount_container (ctrl_t ctrl, const char *filename, const char *mountpoint)
221 if (!filename && !mountpoint)
222 return gpg_error (GPG_ERR_ENOENT);
224 /* Decide whether we need to use the g13-syshelp. */
225 err = call_syshelp_find_device (ctrl, filename, &blockdev);
228 /* Need to employ the syshelper to umount the file system. */
229 /* FIXME: We should get the CONTTYPE from the blockdev. */
230 err = be_umount_container (ctrl, CONTTYPE_DM_CRYPT, blockdev);
233 /* if (conttype == CONTTYPE_DM_CRYPT) */
234 g13_request_shutdown ();
237 else if (gpg_err_code (err) != GPG_ERR_NOT_FOUND)
239 log_error ("error finding device '%s': %s <%s>\n",
240 filename, gpg_strerror (err), gpg_strsource (err));
244 /* Not in g13tab - kill the runner process for this mount. */
248 err = mountinfo_find_mount (filename, mountpoint, &rid);
252 runner = runner_find_by_rid (rid);
255 log_error ("runner %u not found\n", rid);
256 return gpg_error (GPG_ERR_NOT_FOUND);
259 runner_cancel (runner);
260 runner_release (runner);