Repository navigation
Conversation
5 of 6 tasks
Bind ZFS native encryption roots by storing the clevis encrypt output in user properties of the encryption root, split into chunks when it exceeds the property value size limit, and unlock them with it. Co-authored-by: Joel Low <joel@joelsplace.sg> Co-authored-by: Oldřich Jedlička <oldium.pro@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Store each binding under its own label, "default" unless given, and keep the list of labels in a well-known property, so that different policies can unlock the same encryption root. The recovered key is verified before it is loaded, and -y is passed on to the pin. Co-authored-by: Joel Low <joel@joelsplace.sg> Co-authored-by: Oldřich Jedlička <oldium.pro@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Unlock ZFS encryption roots bound by clevis zfs bind through the regular password prompts of the OpenZFS initramfs integration and of the zfs-mount-generator units, when the ZFS support is installed. Only locked encryption roots with keylocation=prompt are answered. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Let other clevis unlockers reuse it. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
4 of 14 tasks
With systemd, the clevis module's password agent answers the key prompt of zfs-load-key.sh. The mount-zfs.sh has no agent protocol, so a mount hook right before it replaces zfs by a wrapper hooking its zfs load-key, which ends the matching plymouth prompt. With systemd, the wrapper leaves the TCSD to tcsd.service. Tang bindings on ZFS enable networking. The TCSD start is attempted once per boot for all unlockers, and it is stopped at cleanup also without the LUKS unlocker. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Let other clevis unlockers reuse them. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Load the key through the initramfs-tools-load-key.d hook of OpenZFS 2.2, its standard way for third-party tools, before the password prompt. The pins come from the clevis hook, networking and TCSD from the shared functions, which now run once per boot for all unlockers, under flock. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Document the ZFS commands and unlockers in man pages and in the README, the same way as the LUKS ones. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Test the ZFS commands on an encryption root in a pool on a file. They need root and the ZFS tools with the loaded module, and are skipped otherwise. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
The init script sets BOOT from boot=, never boot, so the networking was configured again on NFS boot. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Contributor
Author
|
Last change was to get in sync with the fix sent upstream: openzfs/zfs#19209 |
Collaborator
|
/packit test |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This Pull Request based on work by Vince van Oosten and Joel Low implements ZFS encryption:
Status:
Example usage:
rpooldataset to tang pin:rpooldataset to TPM 2 pin:rpooldataset:Tested:
Notable ZFS-related upstream work:
Release and packages:
Fixes: #218
Supersedes: #373, #467