8 # generate primary header with luks2 keyslot kdf object
9 # having left over params.
11 # secondary header is corrupted on purpose as well
15 # $2 full source luks2 image
20 test -d $TMPDIR || mkdir $TMPDIR
21 read_luks2_json0 $TGT_IMG $TMPDIR/json0
22 read_luks2_bin_hdr0 $TGT_IMG $TMPDIR/hdr0
23 read_luks2_bin_hdr1 $TGT_IMG $TMPDIR/hdr1
28 # add keyslot 1 to second digest
29 obj_len=$(jq -c -M '.keyslots."2".kdf | length' $TMPDIR/json0)
30 json_str=$(jq -r -c -M '.keyslots."2".kdf.type = "argon2id" | .keyslots."2".kdf.iterations = 1001 | .keyslots."2".kdf.hash = "sha256"' $TMPDIR/json0)
31 test ${#json_str} -lt $((LUKS2_JSON_SIZE*512)) || exit 2
33 write_luks2_json "$json_str" $TMPDIR/json0
35 merge_bin_hdr_with_json $TMPDIR/hdr0 $TMPDIR/json0 $TMPDIR/area0
36 erase_checksum $TMPDIR/area0
37 chks0=$(calc_sha256_checksum_file $TMPDIR/area0)
38 write_checksum $chks0 $TMPDIR/area0
39 write_luks2_hdr0 $TMPDIR/area0 $TGT_IMG
40 kill_bin_hdr $TMPDIR/hdr1
41 write_luks2_hdr1 $TMPDIR/hdr1 $TGT_IMG
46 read_luks2_bin_hdr1 $TGT_IMG $TMPDIR/hdr_res1
47 local str_res1=$(head -c 6 $TMPDIR/hdr_res1)
48 test "$str_res1" = "VACUUM" || exit 2
50 read_luks2_json0 $TGT_IMG $TMPDIR/json_res0
51 chks_res0=$(read_sha256_checksum $TGT_IMG)
52 test "$chks0" = "$chks_res0" || exit 2
53 new_obj_len=$(jq -c -M '.keyslots."2".kdf | length' $TMPDIR/json_res0)
54 test $((obj_len+2)) -eq $new_obj_len || exit 2
63 test $# -eq 2 || exit 1
65 TGT_IMG=$1/$(test_img_name $0)