2 -- Copyright (c) 2015 Pedro Souza <pedrosouza@freebsd.org>
3 -- Copyright (C) 2018 Kyle Evans <kevans@FreeBSD.org>
4 -- All rights reserved.
6 -- Redistribution and use in source and binary forms, with or without
7 -- modification, are permitted provided that the following conditions
9 -- 1. Redistributions of source code must retain the above copyright
10 -- notice, this list of conditions and the following disclaimer.
11 -- 2. Redistributions in binary form must reproduce the above copyright
12 -- notice, this list of conditions and the following disclaimer in the
13 -- documentation and/or other materials provided with the distribution.
15 -- THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16 -- ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17 -- IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18 -- ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19 -- FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20 -- DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21 -- OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22 -- HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23 -- LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24 -- OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
30 local core = require("core")
31 local screen = require("screen")
36 function password.read()
42 if ch == core.KEY_ENTER then
45 -- XXX TODO: Evaluate if we really want this or not, as a
46 -- security consideration of sorts
47 if ch == core.KEY_BACKSPACE or ch == core.KEY_DELETE then
50 -- loader.printc("\008 \008")
55 str = str .. string.char(ch)
62 function password.check()
65 -- pwd is optionally supplied if we want to check it
66 local function do_prompt(prompt, pwd)
69 local read_pwd = password.read()
70 if pwd == nil or pwd == read_pwd then
71 -- Throw an extra newline after password prompt
75 print("\n\nloader: incorrect password!\n")
76 loader.delay(3*1000*1000)
79 local function compare(prompt, pwd)
83 do_prompt(prompt, pwd)
86 local boot_pwd = loader.getenv("bootlock_password")
87 compare("Boot password: ", boot_pwd)
89 local geli_prompt = loader.getenv("geom_eli_passphrase_prompt")
90 if geli_prompt ~= nil and geli_prompt:lower() == "yes" then
91 local passphrase = do_prompt("GELI Passphrase: ")
92 loader.setenv("kern.geom.eli.passphrase", passphrase)
95 local pwd = loader.getenv("password")
99 compare("Password: ", pwd)