Skip to content

Commit 404baa1

Browse files
jyn514ebiggers
authored andcommitted
Don't retry passwords if fscrypt unlock doesn't have a tty
Fixes #429
1 parent 440b932 commit 404baa1

3 files changed

Lines changed: 37 additions & 5 deletions

File tree

‎cli-tests/t_unlock.out‎

Lines changed: 28 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,30 @@ Protected with 1 protector:
6262
PROTECTOR LINKED DESCRIPTION
6363
desc2 No custom protector "prot"
6464

65+
# Try to unlock with no stdin
66+
[ERROR] fscrypt unlock: incorrect key provided
67+
"MNT/dir" is encrypted with fscrypt.
68+
69+
Policy: desc1
70+
Options: padding:32 contents:AES_256_XTS filenames:AES_256_CTS policy_version:2
71+
Unlocked: No
72+
73+
Protected with 1 protector:
74+
PROTECTOR LINKED DESCRIPTION
75+
desc2 No custom protector "prot"
76+
77+
# Try to unlock with only a newline
78+
[ERROR] fscrypt unlock: incorrect key provided
79+
"MNT/dir" is encrypted with fscrypt.
80+
81+
Policy: desc1
82+
Options: padding:32 contents:AES_256_XTS filenames:AES_256_CTS policy_version:2
83+
Unlocked: No
84+
85+
Protected with 1 protector:
86+
PROTECTOR LINKED DESCRIPTION
87+
desc2 No custom protector "prot"
88+
6589
# Unlock directory
6690
Enter custom passphrase for protector "prot": "MNT/dir" is now unlocked and ready for use.
6791

@@ -90,7 +114,7 @@ desc1 Yes desc2
90114
the policy metadata for "MNT/dir".
91115
This directory has either been encrypted with another
92116
tool (such as e4crypt), or the file
93-
"MNT/.fscrypt/policies/desc20"
117+
"MNT/.fscrypt/policies/desc24"
94118
has been deleted.
95119

96120
# Try to unlock with missing protector metadata
@@ -103,14 +127,14 @@ information.
103127
[ERROR] fscrypt unlock: inconsistent metadata between encrypted directory
104128
"MNT/dir1" and its corresponding
105129
metadata file
106-
"MNT/.fscrypt/policies/desc21".
130+
"MNT/.fscrypt/policies/desc25".
107131

108132
Directory has
109-
descriptor:desc21 padding:32
133+
descriptor:desc25 padding:32
110134
contents:AES_256_XTS filenames:AES_256_CTS
111135
policy_version:2
112136

113137
Metadata file has
114-
descriptor:desc23 padding:32
138+
descriptor:desc27 padding:32
115139
contents:AES_256_XTS filenames:AES_256_CTS
116140
policy_version:2

‎cli-tests/t_unlock.sh‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,14 @@ _print_header "Try to unlock with wrong passphrase"
3838
_expect_failure "echo bad | fscrypt unlock --quiet '$dir'"
3939
fscrypt status "$dir"
4040

41+
_print_header "Try to unlock with no stdin"
42+
_expect_failure "fscrypt unlock --quiet '$dir' </dev/null"
43+
fscrypt status "$dir"
44+
45+
_print_header "Try to unlock with only a newline"
46+
_expect_failure "echo | fscrypt unlock --quiet '$dir'"
47+
fscrypt status "$dir"
48+
4149
_print_header "Unlock directory"
4250
echo hunter2 | fscrypt unlock "$dir"
4351
_print_header "=> Check dir status"

‎cmd/fscrypt/keys.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,7 @@ func makeKeyFunc(supportRetry, shouldConfirm bool, prefix string) actions.KeyFun
145145
panic("this KeyFunc does not support retrying")
146146
}
147147
// Don't retry for non-interactive sessions
148-
if quietFlag.Value {
148+
if quietFlag.Value || !term.IsTerminal(stdinFd) {
149149
return nil, ErrWrongKey
150150
}
151151
fmt.Println("Incorrect Passphrase")

0 commit comments

Comments
 (0)