|
 |
33f49e |
From d0169a303de017ff0c847a5f752a2449a76fdd17 Mon Sep 17 00:00:00 2001
|
|
 |
33f49e |
From: Ondrej Kozina <okozina@redhat.com>
|
|
 |
33f49e |
Date: Thu, 6 Jan 2022 14:47:44 +0100
|
|
 |
33f49e |
Subject: [PATCH 17/28] Split requirements validation from config section
|
|
 |
33f49e |
validation.
|
|
 |
33f49e |
|
|
 |
33f49e |
---
|
|
 |
33f49e |
lib/luks2/luks2_json_metadata.c | 17 ++++++++++++++++-
|
|
 |
33f49e |
1 file changed, 16 insertions(+), 1 deletion(-)
|
|
 |
33f49e |
|
|
 |
33f49e |
diff --git a/lib/luks2/luks2_json_metadata.c b/lib/luks2/luks2_json_metadata.c
|
|
 |
33f49e |
index e45a9739..9109b07a 100644
|
|
 |
33f49e |
--- a/lib/luks2/luks2_json_metadata.c
|
|
 |
33f49e |
+++ b/lib/luks2/luks2_json_metadata.c
|
|
 |
33f49e |
@@ -855,9 +855,10 @@ static int hdr_validate_digests(struct crypt_device *cd, json_object *hdr_jobj)
|
|
 |
33f49e |
return 0;
|
|
 |
33f49e |
}
|
|
 |
33f49e |
|
|
 |
33f49e |
+/* requirements being validated in stand-alone routine */
|
|
 |
33f49e |
static int hdr_validate_config(struct crypt_device *cd, json_object *hdr_jobj)
|
|
 |
33f49e |
{
|
|
 |
33f49e |
- json_object *jobj_config, *jobj, *jobj1;
|
|
 |
33f49e |
+ json_object *jobj_config, *jobj;
|
|
 |
33f49e |
int i;
|
|
 |
33f49e |
uint64_t keyslots_size, metadata_size, segment_offset;
|
|
 |
33f49e |
|
|
 |
33f49e |
@@ -912,6 +913,19 @@ static int hdr_validate_config(struct crypt_device *cd, json_object *hdr_jobj)
|
|
 |
33f49e |
return 1;
|
|
 |
33f49e |
}
|
|
 |
33f49e |
|
|
 |
33f49e |
+ return 0;
|
|
 |
33f49e |
+}
|
|
 |
33f49e |
+
|
|
 |
33f49e |
+static int hdr_validate_requirements(struct crypt_device *cd, json_object *hdr_jobj)
|
|
 |
33f49e |
+{
|
|
 |
33f49e |
+ int i;
|
|
 |
33f49e |
+ json_object *jobj_config, *jobj, *jobj1;
|
|
 |
33f49e |
+
|
|
 |
33f49e |
+ if (!json_object_object_get_ex(hdr_jobj, "config", &jobj_config)) {
|
|
 |
33f49e |
+ log_dbg(cd, "Missing config section.");
|
|
 |
33f49e |
+ return 1;
|
|
 |
33f49e |
+ }
|
|
 |
33f49e |
+
|
|
 |
33f49e |
/* Requirements object is optional */
|
|
 |
33f49e |
if (json_object_object_get_ex(jobj_config, "requirements", &jobj)) {
|
|
 |
33f49e |
if (!json_contains(cd, jobj_config, "section", "Config", "requirements", json_type_object))
|
|
 |
33f49e |
@@ -937,6 +951,7 @@ int LUKS2_hdr_validate(struct crypt_device *cd, json_object *hdr_jobj, uint64_t
|
|
 |
33f49e |
struct {
|
|
 |
33f49e |
int (*validate)(struct crypt_device *, json_object *);
|
|
 |
33f49e |
} checks[] = {
|
|
 |
33f49e |
+ { hdr_validate_requirements },
|
|
 |
33f49e |
{ hdr_validate_tokens },
|
|
 |
33f49e |
{ hdr_validate_digests },
|
|
 |
33f49e |
{ hdr_validate_segments },
|
|
 |
33f49e |
--
|
|
 |
33f49e |
2.27.0
|
|
 |
33f49e |
|