aboutsummaryrefslogtreecommitdiff
path: root/gnu/packages/cryptsetup.scm
blob: 2a824d416e9c15313e24f95c563f3feb70061457 (about) (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2013 Andreas Enge <andreas@enge.fr>
;;; Copyright © 2016 Ludovic Courtès <ludo@gnu.org>
;;; Copyright © 2019 Tobias Geerinckx-Rice <me@tobias.gr>
;;;
;;; This file is part of GNU Guix.
;;;
;;; GNU Guix is free software; you can redistribute it and/or modify it
;;; under the terms of the GNU General Public License as published by
;;; the Free Software Foundation; either version 3 of the License, or (at
;;; your option) any later version.
;;;
;;; GNU Guix is distributed in the hope that it will be useful, but
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
;;; GNU General Public License for more details.
;;;
;;; You should have received a copy of the GNU General Public License
;;; along with GNU Guix.  If not, see <http://www.gnu.org/licenses/>.

(define-module (gnu packages cryptsetup)
  #:use-module ((guix licenses) #:prefix license:)
  #:use-module (guix packages)
  #:use-module (guix download)
  #:use-module (guix build-system gnu)
  #:use-module (guix utils)
  #:use-module (gnu packages)
  #:use-module (gnu packages gnupg)
  #:use-module (gnu packages password-utils)
  #:use-module (gnu packages pkg-config)
  #:use-module (gnu packages popt)
  #:use-module (gnu packages linux)
  #:use-module (gnu packages web))

(define-public cryptsetup
  (package
   (name "cryptsetup")
   (version "2.2.2")
   (source (origin
            (method url-fetch)
            (uri (string-append "mirror://kernel.org/linux/utils/cryptsetup/v"
                                (version-major+minor version)
                                "/cryptsetup-" version ".tar.xz"))
            (sha256
             (base32
              "0ija889kfhg4n2fshpq9yh2b1jl2ipvd7sfafh08g75ba6ayrw1a"))))
   (build-system gnu-build-system)
   (arguments
    `(#:configure-flags
      (list
       ;; Argon2 is always enabled, this just selects the (faster) full version.
       "--enable-libargon2"
       ;; The default is OpenSSL which provides better PBKDF performance.
       "--with-crypto_backend=gcrypt"
       ;; GRUB as of 2.04 still can't read LUKS2 containers.
       "--with-default-luks-format=LUKS1")))
   (native-inputs
    `(("pkg-config" ,pkg-config)))
   (inputs
    `(("argon2" ,argon2)
      ("json-c" ,json-c)
      ("libgcrypt" ,libgcrypt)
      ("lvm2" ,lvm2)                    ; device-mapper
      ("popt" ,popt)
      ("util-linux" ,util-linux)))      ; libuuid
   (synopsis "Hard disk encryption tool")
   (description
    "LUKS (Linux Unified Key Setup)/Cryptsetup provides a standard on-disk
encryption format, which does not only facilitate compatibility among
distributions, but which also provides secure management of multiple user
passwords.  In contrast to existing solutions, LUKS stores all setup necessary
setup information in the partition header, enabling the users to transport
or migrate their data seamlessly.")
   (license license:gpl2)
   (home-page "https://gitlab.com/cryptsetup/cryptsetup")))

(define (static-library library)
  "Return a variant of package LIBRARY that provides static libraries ('.a'
files).  This assumes LIBRARY uses Libtool."
  (package
    (inherit library)
    (name (string-append (package-name library) "-static"))
    (arguments
     (substitute-keyword-arguments (package-arguments library)
       ((#:configure-flags flags ''())
        `(append '("--disable-shared" "--enable-static")
                 ,flags))))))

(define-public cryptsetup-static
  ;; Stripped-down statically-linked 'cryptsetup' command for use in initrds.
  (package
    (inherit cryptsetup)
    (name "cryptsetup-static")
    (arguments
     '(#:configure-flags '("--disable-shared"
                           "--enable-static-cryptsetup"

                           "--disable-veritysetup"
                           "--disable-cryptsetup-reencrypt"
                           "--disable-integritysetup"

                           ;; The default is OpenSSL which provides better PBKDF performance.
                           "--with-crypto_backend=gcrypt"

                           "--disable-blkid"
                           ;; 'libdevmapper.a' pulls in libpthread, libudev and libm.
                           "LIBS=-ludev -pthread -lm")

       #:allowed-references ()                  ;this should be self-contained

       #:modules ((ice-9 ftw)
                  (ice-9 match)
                  (guix build utils)
                  (guix build gnu-build-system))

       #:phases (modify-phases %standard-phases
                  (add-after 'install 'remove-cruft
                    (lambda* (#:key outputs #:allow-other-keys)
                      ;; Remove everything except the 'cryptsetup' command.
                      (let ((out (assoc-ref outputs "out")))
                        (with-directory-excursion out
                          (let ((dirs (scandir "."
                                               (match-lambda
                                                 ((or "." "..") #f)
                                                 (_ #t)))))
                            (for-each delete-file-recursively
                                      (delete "sbin" dirs))
                            (for-each (lambda (file)
                                        (rename-file (string-append file
                                                                    ".static")
                                                     file)
                                        (remove-store-references file))
                                      '("sbin/cryptsetup"))
                            #t))))))))
    (inputs
     (let ((libgcrypt-static
            (package
              (inherit (static-library libgcrypt))
              (propagated-inputs
               `(("libgpg-error-host" ,(static-library libgpg-error)))))))
       `(("json-c" ,json-c)
         ("libgcrypt" ,libgcrypt-static)
         ("lvm2" ,lvm2-static)
         ("util-linux" ,util-linux "static")
         ("util-linux" ,util-linux)
         ("popt" ,popt))))
    (synopsis "Hard disk encryption tool (statically linked)")))
>gnu: QEMU: Install the manual pages....* gnu/packages/virtualization.scm (qemu)[arguments]: Add '--enable-docs' to #:configure-flags. [native-inputs]: Add python-sphinx. (qemu-minimal-2.10)[native-inputs]: Remove python-sphinx. Leo Famulari 2020-01-24gnu: QEMU: Fix CVE-2020-{7039,7211}....* gnu/packages/patches/qemu-CVE-2020-7039.patch, gnu/packages/patches/qemu-CVE-2020-7211.patch: New files. * gnu/local.mk (dist_patch_DATA): Add them. * gnu/packages/virtualization.scm (qemu)[source]: Use them. Leo Famulari 2020-01-23gnu: bochs: Update to 2.6.11....* gnu/packages/virtualization.scm (bochs): Update to 2.6.11. Tobias Geerinckx-Rice 2020-01-02gnu: libosinfo: Update to 1.7.1....* gnu/packages/virtualization.scm (libosinfo): Update to 1.7.1. [source]: Switch the release tarball to xz compression. [build-system]: Switch to the meson build system. [arguments]: Switch the configure flags style to work with Meson. Christopher Baines 2019-12-24gnu: bochs: Update to 2.6.10....* gnu/packages/virtualization.scm (bochs): Update to 2.6.10. Tobias Geerinckx-Rice 2019-12-23gnu: umoci: Update to 0.4.5....* gnu/packages/virtualization.scm (umoci): Update to 0.4.5. Tobias Geerinckx-Rice 2019-12-15gnu: criu: Update to 3.13....* gnu/packages/virtualization.scm (criu): Update to 3.13. Signed-off-by: Ludovic Courtès <ludo@gnu.org> nixo 2019-12-11gnu: qemu: Build with vde2 support....* gnu/packages/virtualization.scm (qemu)[inputs]: Add vde2. * gnu/packages/virtualization.scm (qemu-minimal)[inputs]: Remove vde2 from inherited inputs. Signed-off-by: Ludovic Courtès <ludo@gnu.org> Diego Nicola Barbato 2019-11-28Merge branch 'master' into stagingMarius Bakke 2019-11-28gnu: bubblewrap: Update to 0.4.0....* gnu/packages/virtualization.scm (bubblewrap): Update to 0.4.0. Marius Bakke 2019-11-28gnu: bubblewrap: Update home page....* gnu/packages/virtualization.scm (bubblewrap)[source, home-page]: Follow redirect to. Marius Bakke 2019-11-21Merge branch 'master' into stagingMarius Bakke 2019-11-21gnu: lxc: Adjust for GCC 7....* gnu/packages/virtualization.scm (lxc)[arguments]: Add #:make-flags. Marius Bakke 2019-11-21gnu: qemu: Update to 4.1.1....* gnu/packages/virtualization.scm (qemu): Update to 4.1.1. [source](patches): Remove. Marius Bakke 2019-11-21gnu: libseccomp: Update to 2.4.2....* gnu/packages/linux.scm (libseccomp): Update to 2.4.2. * gnu/packages/virtualization.scm (qemu-minimal-2.10)[inputs]: Remove "libseccomp". Marius Bakke 2019-11-15Merge branch 'master' into stagingMarius Bakke 2019-11-13gnu: qmpbackup: Don't use unstable tarball....* gnu/packages/virtualization.scm (qmpbackup)[source]: Download using git-fetch. Efraim Flashner 2019-11-10gnu: qemu: Add upstream patch for failing test....Fixes <https://bugs.gnu.org/37860>. Reported by Danny Milosavljevic <dannym@scratchpost.org>. * gnu/packages/virtualization.scm (qemu)[patches]: Add upstream patch to fix tests on linux-libre >= 5.3. Signed-off-by: Marius Bakke <mbakke@fastmail.com> Miguel Ángel Arruga Vivas 2019-11-05gnu: virt-manager: Update to 2.2.1....* gnu/packages/virtualization.scm (virt-manager): Update to version 2.2.1. Point to the correct file in fix-setup and fix-default-uri phases. Add fix-qemu-img-reference phase. Add gtksourceview as an input. Signed-off-by: Ludovic Courtès <ludo@gnu.org> Miguel Ángel Arruga Vivas 2019-11-05gnu: python-libvirt: Update to 5.8.0....* gnu/packages/virtualization.scm (python-libvirt): Update version to 5.8.0, update hash and remove obsolete comment. Signed-off-by: Ludovic Courtès <ludo@gnu.org> Miguel Ángel Arruga Vivas 2019-11-05gnu: libvirt: Update to 5.8.0....* gnu/local.mk (dist_patch_DATA): Add new patch file. * gnu/packages/patches/libvirt-create-machine-cgroup.patch: New patch, submitted to upstream for upstream bug 1760233. * gnu/packages/virtualization.scm (libvirt): Update version to 5.8.0. Include patch. Avoid execution of failing tests qemuxml2argvtest and qemuhotplugtest. Replace python by python-wrapper to avoid warnings on patch-shebangs phase. Signed-off-by: Ludovic Courtès <ludo@gnu.org> Miguel Ángel Arruga Vivas 2019-11-01gnu: skopeo: Update to 0.1.40....* gnu/packages/virtualization.scm (skopeo): Update to 0.1.40. Tobias Geerinckx-Rice 2019-10-18gnu: looking-glass-client: Adjust for Mesa 19.2....* gnu/packages/virtualization.scm (looking-glass-client)[arguments]: Add phase 'add-missing-include'. Marius Bakke 2019-10-18gnu: looking-glass-client: Disable CPU-specific optimizations....* gnu/packages/virtualization.scm (looking-glass-client)[source](modules, snippet): New fields. Marius Bakke 2019-10-01Merge branch 'master' into core-updatesLudovic Courtès 2019-09-30gnu: bubblewrap: Update to 0.3.3....* gnu/packages/virtualization.scm (bubblewrap): Update to 0.3.3. [arguments]: Adjust test substitutions. Marius Bakke 2019-09-27Merge branch 'master' into core-updatesMarius Bakke 2019-09-26gnu: skopeo: Update to 0.1.39....* gnu/packages/virtualization.scm (skopeo): Update to 0.1.39. Tobias Geerinckx-Rice