tree 798347e10dba644f861fd9dbf55fe59cef9fb82f
parent 6767e052c761f2b19a4966f707c65d8bc08c3c3c
author Mateusz Zalega <mateusz@monogon.tech> 1627052282 +0200
committer Mateusz Zalega <mateusz@monogon.tech> 1628606354 +0000

m/n/b/mkverity: implement a dm-verity hash image generator

Background: https://github.com/monogon-dev/monogon/issues/57

The piece of code included implements a subset of veritysetup
functionality (see: dm-verity). It was written in an attempt to
minimize projected higher maintenance cost of packaging cryptsetup
for metropolis in the long term.

The implementation was verified with the original veritysetup tool:
>$ ./go-veritysetup format file1 file2
>33359c1f1bdd25e7afc2e98cd27c440e7af9ef2fb55462ce562a1b8254bf02e4
>$ veritysetup --debug --verbose verify file1 file2 33359c1f1bdd25e7afc2e98cd27c440e7af9ef2fb55462ce562a1b8254bf02e4

Ktest-based tests and buildsystem integration are still pending.

Compatibility with the original cryptsetup tool might be dropped
eventually, if it's found beneficial to do so.

Change-Id: I5a6e1b18b692b1701e405013f132f6f2711b2c96
Reviewed-on: https://review.monogon.dev/c/monogon/+/250
Reviewed-by: Sergiusz Bazanski <serge@monogon.tech>
