From patchwork Thu Sep 12 22:30:19 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Maxim Levitsky X-Patchwork-Id: 11143853 Return-Path: Received: from mail.kernel.org (pdx-korg-mail-1.web.codeaurora.org [172.30.200.123]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 13B091599 for ; Thu, 12 Sep 2019 22:38:38 +0000 (UTC) Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id C562920830 for ; Thu, 12 Sep 2019 22:38:37 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org C562920830 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=redhat.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=qemu-devel-bounces+patchwork-qemu-devel=patchwork.kernel.org@nongnu.org Received: from localhost ([::1]:39278 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1i8XjY-00082j-4h for patchwork-qemu-devel@patchwork.kernel.org; Thu, 12 Sep 2019 18:38:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:41831) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1i8XcE-0007of-9X for qemu-devel@nongnu.org; Thu, 12 Sep 2019 18:31:06 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1i8XcA-0005mK-5l for qemu-devel@nongnu.org; Thu, 12 Sep 2019 18:31:02 -0400 Received: from mx1.redhat.com ([209.132.183.28]:60360) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1i8Xc1-0005fW-PR; Thu, 12 Sep 2019 18:30:50 -0400 Received: from smtp.corp.redhat.com (int-mx06.intmail.prod.int.phx2.redhat.com [10.5.11.16]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 1F48086668; Thu, 12 Sep 2019 22:30:49 +0000 (UTC) Received: from maximlenovopc.usersys.redhat.com (unknown [10.35.206.59]) by smtp.corp.redhat.com (Postfix) with ESMTP id D9B4F5C22F; Thu, 12 Sep 2019 22:30:44 +0000 (UTC) From: Maxim Levitsky To: qemu-devel@nongnu.org Date: Fri, 13 Sep 2019 01:30:19 +0300 Message-Id: <20190912223028.18496-3-mlevitsk@redhat.com> In-Reply-To: <20190912223028.18496-1-mlevitsk@redhat.com> References: <20190912223028.18496-1-mlevitsk@redhat.com> X-Scanned-By: MIMEDefang 2.79 on 10.5.11.16 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Thu, 12 Sep 2019 22:30:49 +0000 (UTC) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.132.183.28 Subject: [Qemu-devel] [PATCH v2 02/11] qcrypto-luks: extend the create options for upcoming encryption key management X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Kevin Wolf , =?utf-8?q?Daniel_P=2E_Berrang=C3=A9?= , qemu-block@nongnu.org, Markus Armbruster , Max Reitz , Maxim Levitsky , John Snow Errors-To: qemu-devel-bounces+patchwork-qemu-devel=patchwork.kernel.org@nongnu.org Sender: "Qemu-devel" Now you can specify which slot to put the encryption key to Plus add 'active' option which will let user erase the key secret instead of adding it. Check that active=true it when creating. Signed-off-by: Maxim Levitsky --- block/crypto.c | 2 ++ block/crypto.h | 16 +++++++++++ block/qcow2.c | 2 ++ crypto/block-luks.c | 26 +++++++++++++++--- qapi/crypto.json | 19 ++++++++++++++ tests/qemu-iotests/082.out | 54 ++++++++++++++++++++++++++++++++++++++ 6 files changed, 115 insertions(+), 4 deletions(-) diff --git a/block/crypto.c b/block/crypto.c index 6e822c6e50..a6a3e1f1d8 100644 --- a/block/crypto.c +++ b/block/crypto.c @@ -144,6 +144,8 @@ static QemuOptsList block_crypto_create_opts_luks = { BLOCK_CRYPTO_OPT_DEF_LUKS_IVGEN_HASH_ALG(""), BLOCK_CRYPTO_OPT_DEF_LUKS_HASH_ALG(""), BLOCK_CRYPTO_OPT_DEF_LUKS_ITER_TIME(""), + BLOCK_CRYPTO_OPT_DEF_LUKS_SLOT(""), + BLOCK_CRYPTO_OPT_DEF_LUKS_ACTIVE(""), { /* end of list */ } }, }; diff --git a/block/crypto.h b/block/crypto.h index b935695e79..05cc43d9bc 100644 --- a/block/crypto.h +++ b/block/crypto.h @@ -35,12 +35,14 @@ "ID of the secret that provides the AES encryption key") #define BLOCK_CRYPTO_OPT_LUKS_KEY_SECRET "key-secret" +#define BLOCK_CRYPTO_OPT_LUKS_SLOT "slot" #define BLOCK_CRYPTO_OPT_LUKS_CIPHER_ALG "cipher-alg" #define BLOCK_CRYPTO_OPT_LUKS_CIPHER_MODE "cipher-mode" #define BLOCK_CRYPTO_OPT_LUKS_IVGEN_ALG "ivgen-alg" #define BLOCK_CRYPTO_OPT_LUKS_IVGEN_HASH_ALG "ivgen-hash-alg" #define BLOCK_CRYPTO_OPT_LUKS_HASH_ALG "hash-alg" #define BLOCK_CRYPTO_OPT_LUKS_ITER_TIME "iter-time" +#define BLOCK_CRYPTO_OPT_LUKS_ACTIVE "active" #define BLOCK_CRYPTO_OPT_DEF_LUKS_KEY_SECRET(prefix) \ BLOCK_CRYPTO_OPT_DEF_KEY_SECRET(prefix, \ @@ -88,6 +90,20 @@ .help = "Time to spend in PBKDF in milliseconds", \ } +#define BLOCK_CRYPTO_OPT_DEF_LUKS_SLOT(prefix) \ + { \ + .name = prefix BLOCK_CRYPTO_OPT_LUKS_SLOT, \ + .type = QEMU_OPT_NUMBER, \ + .help = "Controls the slot where the secret is added/erased", \ + } + +#define BLOCK_CRYPTO_OPT_DEF_LUKS_ACTIVE(prefix) \ + { \ + .name = prefix BLOCK_CRYPTO_OPT_LUKS_ACTIVE, \ + .type = QEMU_OPT_BOOL, \ + .help = "Controls if the added secret is added or erased", \ + } + QCryptoBlockCreateOptions * block_crypto_create_opts_init(QDict *opts, Error **errp); diff --git a/block/qcow2.c b/block/qcow2.c index 0882ff6e92..5bdb8b18f4 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -5166,6 +5166,8 @@ static QemuOptsList qcow2_create_opts = { BLOCK_CRYPTO_OPT_DEF_LUKS_IVGEN_HASH_ALG("encrypt."), BLOCK_CRYPTO_OPT_DEF_LUKS_HASH_ALG("encrypt."), BLOCK_CRYPTO_OPT_DEF_LUKS_ITER_TIME("encrypt."), + BLOCK_CRYPTO_OPT_DEF_LUKS_SLOT("encrypt."), + BLOCK_CRYPTO_OPT_DEF_LUKS_ACTIVE("encrypt."), { .name = BLOCK_OPT_CLUSTER_SIZE, .type = QEMU_OPT_SIZE, diff --git a/crypto/block-luks.c b/crypto/block-luks.c index 6c53bdc428..fed80e6646 100644 --- a/crypto/block-luks.c +++ b/crypto/block-luks.c @@ -1211,6 +1211,7 @@ qcrypto_block_luks_create(QCryptoBlock *block, const char *hash_alg; g_autofree char *cipher_mode_spec = NULL; uint64_t iters; + unsigned int slot_idx = 0; memcpy(&luks_opts, &options->u.luks, sizeof(luks_opts)); if (!luks_opts.has_iter_time) { @@ -1244,12 +1245,30 @@ qcrypto_block_luks_create(QCryptoBlock *block, luks->ivgen_hash_alg = luks_opts.ivgen_hash_alg; luks->hash_alg = luks_opts.hash_alg; + if (luks_opts.has_active && !luks_opts.active) { + error_setg(errp, + "For image creation, the added secret must be active!"); + goto error; + + } + + if (luks_opts.has_slot) { + if (luks_opts.slot >= QCRYPTO_BLOCK_LUKS_NUM_KEY_SLOTS || + luks_opts.slot < 0) { + error_setg(errp, + "Invalid slot %" PRId64 " is specified", + luks_opts.slot); + goto error; + } + slot_idx = (unsigned int)luks_opts.slot; + } + /* Note we're allowing ivgen_hash_alg to be set even for * non-essiv iv generators that don't need a hash. It will * be silently ignored, for compatibility with dm-crypt */ - if (!options->u.luks.key_secret) { + if (!luks_opts.has_key_secret) { error_setg(errp, "Parameter '%skey-secret' is required for cipher", optprefix ? optprefix : ""); goto error; @@ -1455,11 +1474,10 @@ qcrypto_block_luks_create(QCryptoBlock *block, goto error; } - - /* populate the slot 0 with the password encrypted master key*/ + /* populate one of the slots with the password encrypted master key*/ /* This will also store the header */ if (qcrypto_block_luks_store_key(block, - 0, + slot_idx, password, masterkey, luks_opts.iter_time, diff --git a/qapi/crypto.json b/qapi/crypto.json index b2a4cff683..9b83a70634 100644 --- a/qapi/crypto.json +++ b/qapi/crypto.json @@ -190,6 +190,20 @@ # Currently defaults to 'sha256' # @hash-alg: the master key hash algorithm # Currently defaults to 'sha256' +# +# @active: Should the new secret be added (true) or erased (false) +# (amend only, since 4.2) +# +# @slot: The slot in which to put/erase the secret +# if not given, will select first free slot for secret addtion +# and erase all matching keyslots for erase. except last one +# (optional, since 4.2) +# +# @unlock-secret: The secret to use to unlock the image +# If not given, will use the secret that was used +# when opening the image. +# (optional, for amend only, since 4.2) +# # @iter-time: number of milliseconds to spend in # PBKDF passphrase processing. Currently defaults # to 2000. (since 2.8) @@ -201,7 +215,12 @@ '*cipher-mode': 'QCryptoCipherMode', '*ivgen-alg': 'QCryptoIVGenAlgorithm', '*ivgen-hash-alg': 'QCryptoHashAlgorithm', + '*hash-alg': 'QCryptoHashAlgorithm', + '*active' : 'bool', + '*slot': 'int', + '*unlock-secret': 'str', + '*iter-time': 'int'}} diff --git a/tests/qemu-iotests/082.out b/tests/qemu-iotests/082.out index 9d4ed4dc9d..5651a0b953 100644 --- a/tests/qemu-iotests/082.out +++ b/tests/qemu-iotests/082.out @@ -50,6 +50,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -58,6 +59,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -73,6 +75,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -81,6 +84,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -96,6 +100,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -104,6 +109,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -119,6 +125,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -127,6 +134,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -142,6 +150,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -150,6 +159,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -165,6 +175,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -173,6 +184,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -188,6 +200,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -196,6 +209,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -211,6 +225,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -219,6 +234,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -249,6 +265,7 @@ Supported qcow2 options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -257,6 +274,7 @@ Supported qcow2 options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -330,6 +348,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -338,6 +357,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -353,6 +373,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -361,6 +382,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -376,6 +398,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -384,6 +407,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -399,6 +423,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -407,6 +432,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -422,6 +448,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -430,6 +457,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -445,6 +473,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -453,6 +482,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -468,6 +498,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -476,6 +507,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -491,6 +523,7 @@ Supported options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -499,6 +532,7 @@ Supported options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates nocow= - Turn off copy-on-write (valid only on btrfs) @@ -529,6 +563,7 @@ Supported qcow2 options: compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -537,6 +572,7 @@ Supported qcow2 options: encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -621,6 +657,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -629,6 +666,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -645,6 +683,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -653,6 +692,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -669,6 +709,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -677,6 +718,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -693,6 +735,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -701,6 +744,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -717,6 +761,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -725,6 +770,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -741,6 +787,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -749,6 +796,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -765,6 +813,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -773,6 +822,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -789,6 +839,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -797,6 +848,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full) @@ -830,6 +882,7 @@ Creation options for 'qcow2': compat= - Compatibility level (v2 [0.10] or v3 [1.1]) data_file= - File name of an external data file data_file_raw= - The external data file must stay valid as a raw image + encrypt.active= - Controls if the added secret is added or erased encrypt.cipher-alg= - Name of encryption cipher algorithm encrypt.cipher-mode= - Name of encryption cipher mode encrypt.format= - Encrypt the image, format choices: 'aes', 'luks' @@ -838,6 +891,7 @@ Creation options for 'qcow2': encrypt.ivgen-alg= - Name of IV generator algorithm encrypt.ivgen-hash-alg= - Name of IV generator hash algorithm encrypt.key-secret= - ID of secret providing qcow AES key or LUKS passphrase + encrypt.slot= - Controls the slot where the secret is added/erased encryption= - Encrypt the image with format 'aes'. (Deprecated in favor of encrypt.format=aes) lazy_refcounts= - Postpone refcount updates preallocation= - Preallocation mode (allowed values: off, metadata, falloc, full)