1#!/bin/sh 2# 3# Copyright (c) 2005 Pawel Jakub Dawidek <pjd@FreeBSD.org> 4# All rights reserved. 5# 6# Redistribution and use in source and binary forms, with or without 7# modification, are permitted provided that the following conditions 8# are met: 9# 1. Redistributions of source code must retain the above copyright 10# notice, this list of conditions and the following disclaimer. 11# 2. Redistributions in binary form must reproduce the above copyright 12# notice, this list of conditions and the following disclaimer in the 13# documentation and/or other materials provided with the distribution. 14# 15# THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND 16# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 17# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 18# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE 19# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 20# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 21# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 22# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 23# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 24# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 25# SUCH DAMAGE. 26# 27# 28 29# PROVIDE: disks 30# KEYWORD: nojail 31 32. /etc/rc.subr 33 34name="geli" 35desc="GELI disk encryption" 36start_precmd='[ -n "$(geli_make_list)" -o -n "${geli_groups}" ]' 37start_cmd="geli_start" 38stop_cmd="geli_stop" 39required_modules="geom_eli:g_eli" 40 41geli_start() 42{ 43 devices=`geli_make_list` 44 45 if [ -z "${geli_tries}" ]; then 46 if [ -n "${geli_attach_attempts}" ]; then 47 # Compatibility with rc.d/gbde. 48 geli_tries=${geli_attach_attempts} 49 else 50 geli_tries=`${SYSCTL_N} kern.geom.eli.tries` 51 fi 52 fi 53 54 for provider in ${devices}; do 55 provider_=`ltr ${provider} '/-' '_'` 56 57 eval "flags=\${geli_${provider_}_flags}" 58 if [ -z "${flags}" ]; then 59 flags=${geli_default_flags} 60 fi 61 if [ -e "/dev/${provider}" -a ! -e "/dev/${provider}.eli" ]; then 62 echo "Configuring Disk Encryption for ${provider}." 63 count=1 64 while [ ${count} -le ${geli_tries} ]; do 65 geli attach ${flags} ${provider} 66 if [ -e "/dev/${provider}.eli" ]; then 67 break 68 fi 69 echo "Attach failed; attempt ${count} of ${geli_tries}." 70 count=$((count+1)) 71 done 72 fi 73 done 74 75 for group in ${geli_groups}; do 76 group_=`ltr ${group} '/-' '_'` 77 78 eval "flags=\${geli_${group_}_flags}" 79 if [ -z "${flags}" ]; then 80 flags=${geli_default_flags} 81 fi 82 83 eval "providers=\${geli_${group_}_devices}" 84 if [ -z "${providers}" ]; then 85 echo "No devices listed in geli group ${group}." 86 continue 87 fi 88 89 if [ -e "/dev/${providers%% *}" -a ! -e "/dev/${providers%% *}.eli" ]; then 90 echo "Configuring Disk Encryption for geli group ${group}, containing ${providers}." 91 count=1 92 while [ ${count} -le ${geli_tries} ]; do 93 geli attach ${flags} ${providers} 94 if [ -e "/dev/${providers%% *}.eli" ]; then 95 break 96 fi 97 echo "Attach failed; attempt ${count} of ${geli_tries}." 98 count=$((count+1)) 99 done 100 fi 101 done 102} 103 104geli_stop() 105{ 106 devices=`geli_make_list` 107 108 for group in ${geli_groups}; do 109 group_=`ltr ${group} '/-' '_'` 110 111 eval "providers=\${geli_${group_}_devices}" 112 113 devices="${devices} ${providers}" 114 done 115 116 for provider in ${devices}; do 117 if [ -e "/dev/${provider}.eli" ]; then 118 umount "/dev/${provider}.eli" 2>/dev/null 119 geli detach "${provider}" 120 fi 121 done 122} 123 124load_rc_config $name 125run_rc_command "$1" 126