ການເຂົ້າລະຫັດລະບົບໄຟລ໌ສຳລັບ Ubuntu Touch 24.04

ການເຂົ້າລະຫັດລະບົບໄຟລ໌ໃນເອກະສານນີ້ ໝາຍເຖິງການເຂົ້າລະຫັດແບບແຍກແຕ່ລະໄຟລ໌ (File Based Encryption), ເມື່ອທຽບກັບການເຂົ້າລະຫັດດິດທັງໝົດ (Full Disk Encryption).

ການເຂົ້າລະຫັດໃນ Ubuntu Touch 24.04 ແມ່ນໃຊ້ fscrypt.

ລາຍລະອຽດທາງເຕັກນິກ

ແທນທີ່ຈະເຂົ້າລະຫັດດິດທັງໝົດແບບ LUKS, fscrypt ຈະເປີດໃຊ້ການເຂົ້າລະຫັດທີ່ຝັງຢູ່ໃນລະບົບໄຟລ໌ ext4 ແລະ f2fs ສຳລັບແຕ່ລະໄດເຣັກທໍຣີ. ວິທີນີ້ຊ່ວຍໃຫ້ລະບົບບູດຈາກ root filesystem ທີ່ບໍ່ໄດ້ເຂົ້າລະຫັດໄດ້ ໃນຂະນະທີ່ເລື່ອນການປ້ອນ PIN ໄປຈົນກວ່າຈະຮອດຈຸດທີ່ຈຳເປັນ. ນີ້ແມ່ນສິ່ງສຳຄັນຫຼາຍສຳລັບຮູບແບບການແບ່ງພາທິຊັນ (partitioning) ຂອງ Ubuntu Touch.

ສິ່ງນີ້ເຮັດໄດ້ໂດຍການໂຫຼດຄີ (key) ຂອງຜູ້ໃຊ້ລົງໃນ user's keyring (ນະໂຍບາຍ v1) ຫຼື filesystem keyring (ນະໂຍບາຍ v2). ການໂຫຼດຄີລົງໃນ user's keyring ຈະເຮັດໃຫ້ຜູ້ໃຊ້ອື່ນ (ລວມທັງ root) ບໍ່ສາມາດຖອດລະຫັດໄຟລ໌ໄດ້. ຫາກໃຊ້ filesystem keyring ສິ່ງຕ່າງໆ ເຊັ່ນ Docker ທີ່ຕ້ອງເຂົ້າເຖິງ home directory ຈະເຮັດວຽກໄດ້ຢ່າງຖືກຕ້ອງ.

ທຸກໄດເຣັກທໍຣີທີ່ຜູ້ໃຊ້ຕັ້ງຄ່າໂດຍໃຊ້ຕົວປ້ອງກັນການເຂົ້າລະບົບ (PIN ຫຼື ລະຫັດຜ່ານ) ຈະຖືກປົດລັອກເມື່ອຜູ້ໃຊ້ປົດລັອກອຸປະກອນຕອນບູດເຄື່ອງ. ໝາຍຄວາມວ່າຜູ້ໃຊ້ອາດຈະເພີ່ມຫຼາຍໄດເຣັກທໍຣີເພື່ອເຂົ້າລະຫັດໄດ້.

ການສ້າງໄຟລ໌ fscrypt.conf

ການພອດອຸປະກອນໃໝ່ຕ້ອງມີໄຟລ໌ທີ່ກຳນົດຄ່າໄວ້ກ່ອນໃນ /etc/fscrypt.conf. ນີ້ແມ່ນສິ່ງຈຳເປັນທີ່ຕ້ອງເຮັດ overlay ເພື່ອຮອງຮັບການເຂົ້າລະຫັດໃນອຸປະກອນ.

ຣັນຄຳສັ່ງ sudo fscrypt setup ເພື່ອສ້າງໄຟລ໌ໃໝ່.

The resulting configuration file might look like:

{
    "source": "custom_passphrase",
    "hash_costs": {
        "time": "12",
        "memory": "131072",
        "parallelism": "8"
    },
    "options": {
        "padding": "32",
        "contents": "AES_256_XTS",
        "filenames": "AES_256_CTS",
        "policy_version": "1"
    },
    "use_fs_keyring_for_v1_policies": false,
    "allow_cross_user_metadata": false
}

ຕົວເລືອກການຕັ້ງຄ່າ use_fs_keyring_for_v1_policies

ອຸປະກອນທີ່ໃຊ້ນະໂຍບາຍເວີຊັນ "2" ແຕ່ຕ້ອງການຮອງຮັບບ່ອນເກັບຂໍ້ມູນທີ່ເຂົ້າລະຫັດດ້ວຍເວີຊັນ "1" ມາກ່ອນ ຈະຕ້ອງຕັ້ງຄ່ານີ້ເປັນ true ເພື່ອໃຫ້ການເຂົ້າລະບົບສາມາດປົດລັອກ home directory ແລະ ເກັບຄີໄວ້ໃນ filesystem keyring ໄດ້.

ອຸປະກອນທີ່ໃຊ້ເຄີເນີນໃໝ່ (5.4 ຂຶ້ນໄປ) ບໍ່ຈຳເປັນຕ້ອງປ່ຽນແປງຄ່ານີ້ ແລະ ສາມາດໃຊ້ນະໂຍບາຍການເຂົ້າລະຫັດເວີຊັນ 2 ໄດ້ເລີຍ.

ການຕັ້ງຄ່າຂໍ້ມູນອຸປະກອນ (Device info)

ເພື່ອຢືນຢັນວ່າການຕັ້ງຄ່າສຳເລັດແລ້ວ ແລະ ເພື່ອເປີດໃຊ້ UI ການເຂົ້າລະຫັດໃນ lomiri-system-settings, ຕ້ອງຕັ້ງຄ່າ FilesystemEncryption ໃນ DeviceInfo ໃຫ້ເປັນ true.

Example:

sargo:
  Vendor: Google
  PrettyName: Pixel 3a
  DeviceType: phone
  GridUnit: 25
  SupportedOrientations:
    - Portrait
    - Landscape
    - InvertedLandscape
  FilesystemEncryption: true

ຫຼັງຈາກເຮັດຂັ້ນຕອນນີ້ແລ້ວ ທ່ານຈຶ່ງຈະສາມາດຕັ້ງຄ່າການເຂົ້າລະຫັດໃນອຸປະກອນຂອງທ່ານໄດ້.

ການ Backport ເຄີເນີນ

If your device uses kernel version 4.14 or 4.19, then you can backport policy version 2 support from the Android Common Kernel repository. To fetch sources from there, add the remote to your Git tree:

git remote add google https://android.googlesource.com/kernel/common

ວິທີງ່າຍໆໃນການນຳການຮອງຮັບນະໂຍບາຍ v2 ມາໃຊ້ ແມ່ນການຊອກຫາ Common Kernel ເວີຊັນທີ່ໃກ້ຄຽງທີ່ສຸດທີ່ມີການຮອງຮັບ v2 ເຊິ່ງກົງກັບເວີຊັນເຄີເນີນຂອງທ່ານ, ແລ້ວທຳການ checkout ໄຟລ໌ຕ່າງໆທີ່ກ່ຽວກັບ fscrypt ແລະ ລະບົບໄຟລ໌ທີ່ຮອງຮັບລົງໃນ kernel tree ຂອງທ່ານ. ເລີ່ມຈາກການຊອກຫາ commit ທີ່ທຳການ merge commit "fscrypt: v2 encryption policy support" ແລະ commit ທີ່ກ່ຽວຂ້ອງເຂົ້າໃນ Common Kernel.

For example, if the device kernel is using 4.19.81, according to the Common Kernel's Git history an appropriate source base would be commit c2ad33f0296a2528fd0bf4e96af0802dad0b1b27, which is based on version 4.19.78 and a close match to the rest of the source tree. Fetch those sources using:

git fetch google c2ad33f0296a2528fd0bf4e96af0802dad0b1b27

After determining the right commit, check out fs/crypto and encryption-supporting filesystems at that commit (replace the commit hash in the example with your determined match):

git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/crypto/
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/f2fs/
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/ext4
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/ubifs
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/f2fs_fs.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/fs.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/fscrypt.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/uapi/linux/fs.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/uapi/linux/fscrypt.h

Should the compilation of your kernel fail at first with missing identifier errors, undefined references or missing files, compare with the Common Kernel and check out missing changes and dependencies individually:

git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/verity
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/unicode
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/direct-io.c
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- fs/inode.c
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- mm/mmap.c
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- block/blk-merge.c
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/mm.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/dcache.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/linux/fsverity.h
git checkout c2ad33f0296a2528fd0bf4e96af0802dad0b1b27 -- include/uapi/linux/fsverity.h

ຫາກເຄີເນີນອຸປະກອນມີການເພິ່ງພາອາໄສກັນ (inter-dependencies) ລະຫວ່າງໂຄ້ດ crypto, ໂຄ້ດລະບົບໄຟລ໌ ແລະ ໄດຣເວີອື່ນໆ, ທ່ານຈະຕ້ອງແກ້ໄຂໂຄ້ດດ້ວຍຕົນເອງເພື່ອໃຫ້ຮອງຮັບ fscrypt ໃໝ່. ຕົວຢ່າງ: ໃນອຸປະກອນ Qualcomm ໄດຣເວີ "qseecom" ອາດຈະຮຽກໃຊ້ຟັງຊັນທີ່ຖືກຂຽນທັບໄປ, ທ່ານຈຶ່ງຕ້ອງເພີ່ມຟັງຊັນທີ່ຂາດໄປນັ້ນຄືນ. ເຄີເນີນທີ່ເປີດໃຊ້ "sdcardfs" ຈະຕ້ອງມີການປັບແຕ່ງໄດຣເວີ sdcardfs ໃຫ້ເຮັດວຽກກັບ fscrypt ໃໝ່ໄດ້ ໂດຍການ forward-port ຟັງຊັນທີ່ຂາດໄປ ຫຼື ລຶບພວກມັນອອກ.