2 * Copyright (c) 2011 Alex Hornung <alex@alexhornung.com>.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in
13 * the documentation and/or other materials provided with the
16 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
17 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
18 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
19 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
20 * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
21 * INCIDENTAL, SPECIAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING,
22 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
23 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
24 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
25 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
26 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 #include <sys/types.h>
30 #include <sys/diskslice.h>
32 #include <sys/select.h>
44 read_to_safe_mem(const char *file, off_t offset, size_t *sz)
50 if ((fd = open(file, O_RDONLY)) < 0) {
51 tc_log(1, "Error opening file %s\n", file);
55 if ((mem = alloc_safe_mem(*sz)) == NULL) {
56 tc_log(1, "Error allocating memory\n");
60 if ((lseek(fd, offset, SEEK_SET) < 0)) {
61 tc_log(1, "Error seeking on file %s\n", file);
65 if ((r = read(fd, mem, *sz)) <= 0) {
66 tc_log(1, "Error reading from file %s\n", file);
83 get_random(unsigned char *buf, size_t len)
88 struct timespec ts = { .tv_sec = 0, .tv_nsec = 10000000 }; /* 10 ms */
91 if ((fd = open("/dev/random", O_RDONLY)) < 0) {
92 tc_log(1, "Error opening /dev/random\n");
97 if ((r = read(fd, buf+rd, len-rd)) < 0) {
98 tc_log(1, "Error reading from /dev/random\n");
103 nanosleep(&ts, NULL);
110 static size_t secure_erase_total_bytes = 0;
111 static size_t secure_erase_erased_bytes = 0;
115 secure_erase_summary(void)
119 pct_done = (1.0 * secure_erase_erased_bytes) /
120 (1.0 * secure_erase_total_bytes) * 100.0;
121 tc_log(0, "Securely erasing, %.0f%% done.\n", pct_done);
125 secure_erase(const char *dev, size_t bytes, size_t blksz)
129 char buf[ERASE_BUFFER_SIZE];
133 if (blksz > MAX_BLKSZ) {
134 tc_log(1, "blksz > MAX_BLKSZ\n");
138 if ((fd_rand = open("/dev/urandom", O_RDONLY)) < 0) {
139 tc_log(1, "Error opening /dev/urandom\n");
143 if ((fd = open(dev, O_WRONLY)) < 0) {
145 tc_log(1, "Error opening %s\n", dev);
149 summary_fn = secure_erase_summary;
150 secure_erase_total_bytes = bytes;
152 sz = ERASE_BUFFER_SIZE;
153 while (erased < bytes) {
154 secure_erase_erased_bytes = erased;
155 /* Switch to block size when not much is remaining */
156 if ((bytes - erased) <= ERASE_BUFFER_SIZE)
159 if ((r = read(fd_rand, buf, sz)) < 0) {
160 tc_log(1, "Error reading from /dev/urandom\n");
167 if (r < (ssize_t)blksz)
170 if ((w = write(fd, buf, r)) < 0) {
171 tc_log(1, "Error writing to %s\n", dev);
190 get_disk_info(const char *dev, size_t *blocks, size_t *bsize)
192 struct partinfo pinfo;
195 if ((fd = open(dev, O_RDONLY)) < 0) {
196 tc_log(1, "Error opening %s\n", dev);
200 memset(&pinfo, 0, sizeof(struct partinfo));
202 if (ioctl(fd, DIOCGPART, &pinfo) < 0) {
207 *blocks = pinfo.media_blocks;
208 *bsize = pinfo.media_blksize;
215 write_mem(const char *dev, off_t offset, size_t blksz __unused, void *mem,
221 if ((fd = open(dev, O_WRONLY)) < 0) {
222 tc_log(1, "Error opening device %s\n", dev);
226 if ((lseek(fd, offset, SEEK_SET) < 0)) {
227 tc_log(1, "Error seeking on device %s\n", dev);
232 if ((w = write(fd, mem, bytes)) <= 0) {
233 tc_log(1, "Error writing to device %s\n", dev);
243 read_passphrase(const char *prompt, char *pass, size_t passlen, time_t timeout)
245 struct termios termios_old, termios_new;
249 int fd, r = 0, cfd = 0, nready;
251 if ((fd = open("/dev/tty", O_RDONLY)) == -1) {
259 memset(pass, 0, passlen);
261 tcgetattr(fd, &termios_old);
262 memcpy(&termios_new, &termios_old, sizeof(termios_new));
263 termios_new.c_lflag &= ~ECHO;
264 tcsetattr(fd, TCSAFLUSH, &termios_new);
267 memset(&to, 0, sizeof(to));
272 nready = select(fd + 1, &fds, NULL, NULL, &to);
279 n = read(fd, pass, passlen-1);
281 pass[n-1] = '\0'; /* Strip trailing \n */
290 tcsetattr(fd, TCSAFLUSH, &termios_old);