From unknown Tue Jun 17 20:19:47 2025 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.509 (Entity 5.509) Content-Type: text/plain; charset=utf-8 From: bug#77499 <77499@debbugs.gnu.org> To: bug#77499 <77499@debbugs.gnu.org> Subject: Status: [PATCH] mapped-devices/luks: Support extra options. Reply-To: bug#77499 <77499@debbugs.gnu.org> Date: Wed, 18 Jun 2025 03:19:47 +0000 retitle 77499 [PATCH] mapped-devices/luks: Support extra options. reassign 77499 guix-patches submitter 77499 45mg <45mg.writes@gmail.com> severity 77499 normal tag 77499 patch thanks From debbugs-submit-bounces@debbugs.gnu.org Thu Apr 03 13:47:52 2025 Received: (at submit) by debbugs.gnu.org; 3 Apr 2025 17:47:52 +0000 Received: from localhost ([127.0.0.1]:35539 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1u0OfP-0000qI-TU for submit@debbugs.gnu.org; Thu, 03 Apr 2025 13:47:52 -0400 Received: from lists.gnu.org ([2001:470:142::17]:37402) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <45mg.writes@gmail.com>) id 1u0OfM-0000q0-OX for submit@debbugs.gnu.org; Thu, 03 Apr 2025 13:47:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <45mg.writes@gmail.com>) id 1u0OfC-0000fD-KU for guix-patches@gnu.org; Thu, 03 Apr 2025 13:47:38 -0400 Received: from mail-pg1-x544.google.com ([2607:f8b0:4864:20::544]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from <45mg.writes@gmail.com>) id 1u0OfA-00034o-0d; Thu, 03 Apr 2025 13:47:38 -0400 Received: by mail-pg1-x544.google.com with SMTP id 41be03b00d2f7-7fd35b301bdso1277951a12.2; Thu, 03 Apr 2025 10:47:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1743702453; x=1744307253; darn=gnu.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=PRpUokgVxkc9dlmOdTPhQ/4BB8312sSYvCSVMmhcUbs=; b=RhDfT0HuwlIarg3uNtKLLSvvTXcG7Qn9PHpNoshfSWUHadbgvLeZ/K60jTwhfIsGAb Ewosze9nXB64sS3jiM/SSpxFTIkUipOkjM98T1CBvFL9aMtXk4mFZcUvo7VS+AXVV3BV ShpEm/TSVs6qgMuwkRsMtUMgcmn4xoK7KhGRcg6iiyQUHKNiykTcnYl6XOl/Jfa7bOx5 SR28QbaJsgY0ktfsxaMf01cUmQ36lhqEiZA55TE53tSJ4kIXFoAR0qkYbvtzR5kf8Rew vrSP2AZVYd5j63RvySNqo7ZZd2Qs1OlohHY/+XjvHOIkW+LsS3/AKuDL5sJ5S9+l7uUk jKOA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1743702453; x=1744307253; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=PRpUokgVxkc9dlmOdTPhQ/4BB8312sSYvCSVMmhcUbs=; b=o29zVQF7mRaxfrMT5jQ/2P086k2/3aTBlSedIqX9n3v4/EThS+Olj93TEebWjivG6w pazHBXv53c8TzJruCQdaIu1cQvLwo5/paKA6zw0Al2OOdUBQwi6Uv+P/MsSUvCFd3KWt qrXAFngCfz//XFyHzcPICjmmJLjVimVGVtDSRr7Gizzm18Ig9dtRUQCJWX35Ijk/PMpt Ai1oJIkjM08QcMbmsnuMUBNO4C4JaCf7qp9YNpv7DOoHSX99VSc4v06Wz0+3BFPvX7NX OW4Fz2WkzhG8lA2b43iqpq+NX4Nlf32+t4TYz9Sz3VtCCAOEjbrTDJm4Iqj3I66XUrEE 8JEw== X-Forwarded-Encrypted: i=1; AJvYcCXOaI7TwCg5u6wQhrxnUf6YyLDpfoj+02cwVaA4e9DDJGddebATfpA/C6oS5UIZOX5PP1FP@gnu.org X-Gm-Message-State: AOJu0Yyb6hoJO0YLP4yEDAsyG6G9+/Kew0HiLQJlITq0+tkW9PTOI1zQ fFLAtuk/RPQBvsF0+eNrXRSmvBZkt7JGDsbKQueuUxBVnASQf8n+geJkOB3p X-Gm-Gg: ASbGncs0TwNlLCCd140csz8Dwfesksg4s6VyXek7m44+MahLGWn1pbhr34KXslAW48Q ddkSPnHzX0IDgfMJJoo64Tb+jRAEsdVyV0/kx8kkKihfF4cFEelqFV8oKAt3hIXN5/Ji5MyeJ6I v2cfYMOl8i7L7if15ADOQDKLTIDeK7xaxtplrmV+DDuiurST88tSJU7D02xK39x33lgRRzNlX8L mqA4hILlZVoo2/mhcNYnozXo61N5LKezMKqu20XyYaJUOyxxKEnPPGBrvxi9kxcYYL0locZ7nMM YGfKba2Hdl/AE0KzvrmBBOGb6bANhbGLi9Edx+iVEtYVRd1SSvPpd8UYvDBav4uMcvM= X-Google-Smtp-Source: AGHT+IFXa0PBVpu+aWKmk2941UdLZFO6JPKwg8F/N+4XAwZXvmn1v7Q5IjWWBdMffYdW5L40bwtcug== X-Received: by 2002:a17:90a:d007:b0:2ff:6608:78cd with SMTP id 98e67ed59e1d1-306a47e0781mr790135a91.9.1743702452817; Thu, 03 Apr 2025 10:47:32 -0700 (PDT) Received: from localhost.localdomain (utm3.nitt.edu. [14.139.162.2]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-305827d71a4sm1820007a91.1.2025.04.03.10.47.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Apr 2025 10:47:32 -0700 (PDT) From: 45mg <45mg.writes@gmail.com> To: guix-patches@gnu.org Subject: [PATCH] mapped-devices/luks: Support extra options. Date: Thu, 3 Apr 2025 23:13:57 +0530 Message-ID: X-Mailer: git-send-email 2.49.0 MIME-Version: 1.0 X-Debbugs-Cc: Ludovic Courtès , Maxim Cournoyer Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=2607:f8b0:4864:20::544; envelope-from=45mg.writes@gmail.com; helo=mail-pg1-x544.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 1.0 (+) X-Debbugs-Envelope-To: submit Cc: Maxim Cournoyer , soeren@soeren-tempel.net, Sisiutl , =?UTF-8?q?Ludovic=20Court=C3=A8s?= , 45mg <45mg.writes@gmail.com>, Hilton Chain , Tomas Volf <~@wolfsden.cz> X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.0 (/) Allow passing extra options to the 'cryptsetup open' command. * gnu/system/mapped-devices.scm (luks-device-mapping-with-options): [#:extra-options]: New argument. (open-luks-device): Use it. * doc/guix.texi (Mapped Devices): Document it. * gnu/tests/install.scm (%test-encrypted-root-extra-options-os): New test for it, as well as the previously untested #:allow-discards? option. (%encrypted-root-extra-options-os): New os declaration for the test. Change-Id: Ia9fd129d1c66cbf27abdd3064d59188083465247 --- CCing everyone who worked on the allow-discards option - this change is very similar. %encrypted-root-extra-options-os is copied from %encrypted-root-os; only the mapped-devices field is changed. I wish I could avoid this code duplication by having `(inherit %encrypted-root-os)` in the os definition, but when I do that, the test fails with this error in the build log: /mnt/etc/config.scm:1:100: error: %encrypted-root-os: unbound variable Any chance you Guile wizards know how to make this work? doc/guix.texi | 20 ++++++++++- gnu/system/mapped-devices.scm | 25 ++++++++----- gnu/tests/install.scm | 68 +++++++++++++++++++++++++++++++++++ 3 files changed, 104 insertions(+), 9 deletions(-) diff --git a/doc/guix.texi b/doc/guix.texi index bcb1f9d9cf..9cd1304522 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -18461,7 +18461,7 @@ Mapped Devices @code{dm-crypt} Linux kernel module. @end defvar -@deffn {Procedure} luks-device-mapping-with-options [#:key-file #:allow-discards?] +@deffn {Procedure} luks-device-mapping-with-options [#:key-file #:allow-discards? #:extra-options] Return a @code{luks-device-mapping} object, which defines LUKS block device encryption using the @command{cryptsetup} command from the package with the same name. It relies on the @code{dm-crypt} Linux @@ -18492,6 +18492,24 @@ Mapped Devices information, refer to the description of the @code{--allow-discards} option in the @code{cryptsetup-open(8)} man page. +@code{extra-options} may be used to specify a list of additional +command-line options for the @code{cryptsetup open} command. See the +@code{cryptsetup-open(8)} man page for a list of supported options. + +For example, here is how you could specify the +@code{--perf-no_read_workqueue} and @code{--perf-no_write_workqueue} +options, along with @code{--allow-discards}: + +@lisp +(mapped-device + (source "/dev/sdb1) + (target "data) + (type (luks-device-mapping-with-options + #:allow-discards? #t + #:extra-options '("--perf-no_read_workqueue" + "--perf-no_write_workqueue")))) +@end lisp + @end deffn @defvar raid-device-mapping diff --git a/gnu/system/mapped-devices.scm b/gnu/system/mapped-devices.scm index 667a495570..520ade9ef8 100644 --- a/gnu/system/mapped-devices.scm +++ b/gnu/system/mapped-devices.scm @@ -194,10 +194,12 @@ (define (check-device-initrd-modules device linux-modules location) ;;; Common device mappings. ;;; -(define* (open-luks-device source targets #:key key-file allow-discards?) +(define* (open-luks-device source targets + #:key key-file allow-discards? extra-options) "Return a gexp that maps SOURCE to TARGET as a LUKS device, using 'cryptsetup'. When ALLOW-DISCARDS? is true, the use of discard (TRIM) -requests is allowed for the underlying device." +requests is allowed for the underlying device. EXTRA-OPTIONS is a list of +additional options to be passed to the 'cryptsetup open' command." (with-imported-modules (source-module-closure '((gnu build file-systems) (guix build utils))) ;; For mkdir-p @@ -238,10 +240,15 @@ (define* (open-luks-device source targets #:key key-file allow-discards?) (let ((cryptsetup #$(file-append cryptsetup-static "/sbin/cryptsetup")) (cryptsetup-flags (cons* - "open" "--type" "luks" partition #$target - (if #$allow-discards? - '("--allow-discards") - '())))) + "open" "--type" "luks" + (append + (if #$allow-discards? + '("--allow-discards") + '()) + (if (pair? '#$extra-options) + '#$extra-options + '()) + (list partition #$target))))) ;; We want to fallback to the password unlock if the keyfile ;; fails. (or (and keyfile @@ -290,7 +297,8 @@ (define luks-device-mapping ((gnu build file-systems) #:select (find-partition-by-luks-uuid system*/tty)))))) -(define* (luks-device-mapping-with-options #:key key-file allow-discards?) +(define* (luks-device-mapping-with-options + #:key key-file allow-discards? extra-options) "Return a luks-device-mapping object with open modified to pass the arguments into the open-luks-device procedure." (mapped-device-kind @@ -298,7 +306,8 @@ (define* (luks-device-mapping-with-options #:key key-file allow-discards?) (open (λ (source targets) (open-luks-device source targets #:key-file key-file - #:allow-discards? allow-discards?))))) + #:allow-discards? allow-discards? + #:extra-options extra-options))))) (define (open-raid-device sources targets) "Return a gexp that assembles SOURCES (a list of devices) to the RAID device diff --git a/gnu/tests/install.scm b/gnu/tests/install.scm index a837637b18..fd9f17eb4d 100644 --- a/gnu/tests/install.scm +++ b/gnu/tests/install.scm @@ -68,6 +68,7 @@ (define-module (gnu tests install) %test-separate-home-os %test-raid-root-os %test-encrypted-root-os + %test-encrypted-root-extra-options-os %test-encrypted-home-os %test-encrypted-home-os-key-file %test-encrypted-root-not-boot-os @@ -843,6 +844,73 @@ (define %test-encrypted-root-os (run-basic-test %encrypted-root-os command "encrypted-root-os" #:initialization enter-luks-passphrase))))) + +;;; +;;; LUKS-encrypted root with extra options: --allow-discards, +;;; --perf-no_read_workqueue and --perf-no_write_workqueue +;;; + +;; Except for the 'mapped-devices' field, this is exactly the same as +;; %encrypted-root-os. +(define-os-with-source (%encrypted-root-extra-options-os + %encrypted-root-extra-options-os-source) + ;; The OS we want to install. + (use-modules (gnu) (gnu tests) (srfi srfi-1)) + + (operating-system + (host-name "liberigilo") + (timezone "Europe/Paris") + (locale "en_US.UTF-8") + + (bootloader (bootloader-configuration + (bootloader grub-bootloader) + (targets '("/dev/vdb")))) + + ;; Note: Do not pass "console=ttyS0" so we can use our passphrase prompt + ;; detection logic in 'enter-luks-passphrase'. + + (mapped-devices (list (mapped-device + (source (uuid "12345678-1234-1234-1234-123456789abc")) + (target "the-root-device") + (type (luks-device-mapping-with-options + #:allow-discards? #t + #:extra-options + '("--perf-no_read_workqueue" + "--perf-no_write_workqueue")))))) + (file-systems (cons (file-system + (device "/dev/mapper/the-root-device") + (mount-point "/") + (type "ext4")) + %base-file-systems)) + (users (cons (user-account + (name "charlie") + (group "users") + (supplementary-groups '("wheel" "audio" "video"))) + %base-user-accounts)) + (services (cons (service marionette-service-type + (marionette-configuration + (imported-modules '((gnu services herd) + (guix combinators))))) + %base-services)))) + +(define %test-encrypted-root-extra-options-os + (system-test + (name "encrypted-root-extra-options-os") + (description + "Test basic functionality of an OS installed like one would do by hand, +with an LUKS-encrypted root partition opened with extra options +(--allow-discards, --perf-no_read_workqueue and --perf-no_write_workqueue). +This test is expensive in terms of CPU and storage usage since we need to +build (current-guix) and then store a couple of full system images.") + (value + (mlet* %store-monad ((images (run-install %encrypted-root-extra-options-os + %encrypted-root-extra-options-os-source + #:script + %encrypted-root-installation-script)) + (command (qemu-command* images))) + (run-basic-test %encrypted-root-os command "encrypted-root-extra-options-os" + #:initialization enter-luks-passphrase))))) + ;;; ;;; Separate /home on LVM base-commit: 4ea012fc6ddcb32574fbd4a854b11808c34fbca8 -- 2.49.0 From debbugs-submit-bounces@debbugs.gnu.org Sat Apr 26 09:16:57 2025 Received: (at 77499) by debbugs.gnu.org; 26 Apr 2025 13:16:57 +0000 Received: from localhost ([127.0.0.1]:59415 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1u8fOq-0008Si-Ic for submit@debbugs.gnu.org; Sat, 26 Apr 2025 09:16:57 -0400 Received: from mail-pj1-x1030.google.com ([2607:f8b0:4864:20::1030]:49324) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1u8fOn-0008SN-RU for 77499@debbugs.gnu.org; Sat, 26 Apr 2025 09:16:54 -0400 Received: by mail-pj1-x1030.google.com with SMTP id 98e67ed59e1d1-30332dfc820so3898323a91.2 for <77499@debbugs.gnu.org>; Sat, 26 Apr 2025 06:16:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1745673407; x=1746278207; darn=debbugs.gnu.org; h=content-transfer-encoding:mime-version:user-agent:message-id:date :references:in-reply-to:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=4vn9cPhcnEAsrfl9RVj2i4KiYPQcuvHcFjmlk8aeL1g=; b=HZ47yFCQxk/PdcAOBFGxmmP0MoYAHG1MxcXneQu8bxs+qi7SQn0FEmt9eqTndJPRoZ 8lwCUifesTs2gfa0j/SUyWFDkTnjQ+Te3s775KKRG/VCvE4YKWuTxLP/vv0faJQnSBHD g4BVDfmyYQx2BqLjdYClWd5Y8JJdDKASb6amZnCswJ9NE8xTafHu4O46b30PoKPmsHs6 SmCSj07q/qXpVMBhAnFszm1MSVloFMDCrGays9NYJmsRzB7uJfnosQuYivZdHGG95Qm8 SmTBsHH7DCoI+YgWk2IZ95molb42Hb3C68iOBw1drMHzR+KlYBb8koIv/ADiXj2ma1zo tB5w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1745673407; x=1746278207; h=content-transfer-encoding:mime-version:user-agent:message-id:date :references:in-reply-to:subject:cc:to:from:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=4vn9cPhcnEAsrfl9RVj2i4KiYPQcuvHcFjmlk8aeL1g=; b=CZBfKOswRlclwbUPSNHsQIx8E9GxJil+oEtG2kgWbfTBhIvlkmA+jYLai3fMolKDEF Sei3qYyZkBy69CbNy7EoOHmyVlWzXr2mmOs3+xTd+XTkT1gZTwGqzlIqakDQEl4TDCHH xMWz/Teu1WrPOzi569kfvfVfyk5UWkJm7ZhxO9u0n/+/tQng40+QmdaYW6uQ/DpAVO/H kpRJSgiRFB50xsuWXHsPAthfketuZ5pp/217VXk5ULJemxFEUgQghAyHkcDKfAwSW4gv qm1L3QeW74G0pdfpKvAvuqr1uFYhnngJH99Nwu77Uog/vynJEAceIBdh/cwoheWFewQT bHig== X-Gm-Message-State: AOJu0YxKoLmA0u5oC8ponF+T6e084dP2rp2Gc1WW7jWzxZPthaeFs9U+ b/slBaDkvOeRgWCfkJkpqsbFN0AXPj5400NtIRQcsnLnS8Mt8T8h X-Gm-Gg: ASbGncu4bwxtr9zILxeS1fUjHvIVUpcY89PrfNDOxMfnYgZ97fvMgHBFms4QnXd3+0i 4IMi1n0G+zun2ICpIfD5GOIfzXFpPXzY9MB4ByxKW7Wc9Ykf/gHwZUI0jKiG9hg1NA/t2F3xDqa ujTI3bRqJBa5efKduot6TwK+pSy8M9QHVyAM4iHzU6R9RymcCY5n+BOvy+xlN+MitWCIF5o20OW peiKyopHYUgYSiNoMK9Xf5SjNpte/Qpp5Qfjy2IR58boUw8wPi+8EMYXljFkda+EyIHg7Nu2aM/ aIeR1hqbBUpUOoErgGYW0ncZhqoNxPVdS/I873I= X-Google-Smtp-Source: AGHT+IETPkiD7bw1zqssrR+Y3ab/0LZ1hxlB+j7er1gmysnJ5E0wwH/YNSQoEPopCVExTypTk9TORA== X-Received: by 2002:a17:90b:1f89:b0:2fe:b174:31fe with SMTP id 98e67ed59e1d1-309f7da6db1mr9455172a91.2.1745673407372; Sat, 26 Apr 2025 06:16:47 -0700 (PDT) Received: from terra ([2405:6586:be0:0:83c8:d31d:2cec:f542]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-309f7754d52sm3904539a91.19.2025.04.26.06.16.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 26 Apr 2025 06:16:46 -0700 (PDT) From: Maxim Cournoyer To: 45mg <45mg.writes@gmail.com> Subject: Re: [bug#77499] [PATCH] mapped-devices/luks: Support extra options. In-Reply-To: (45mg.writes@gmail.com's message of "Thu, 3 Apr 2025 23:13:57 +0530") References: Date: Sat, 26 Apr 2025 22:16:43 +0900 Message-ID: <87selvcbb8.fsf@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 77499 Cc: soeren@soeren-tempel.net, Sisiutl , Ludovic =?utf-8?Q?Court=C3=A8s?= , 77499@debbugs.gnu.org, Hilton Chain , Tomas Volf <~@wolfsden.cz> X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) Hi, 45mg <45mg.writes@gmail.com> writes: > Allow passing extra options to the 'cryptsetup open' command. > > * gnu/system/mapped-devices.scm (luks-device-mapping-with-options): > [#:extra-options]: New argument. > (open-luks-device): Use it. > * doc/guix.texi (Mapped Devices): Document it. > * gnu/tests/install.scm (%test-encrypted-root-extra-options-os): New > test for it, as well as the previously untested #:allow-discards? > option. > (%encrypted-root-extra-options-os): New os declaration for the test. Sounds good. > Change-Id: Ia9fd129d1c66cbf27abdd3064d59188083465247 > --- > CCing everyone who worked on the allow-discards option - this change is v= ery > similar. > > %encrypted-root-extra-options-os is copied from %encrypted-root-os; only > the mapped-devices field is changed. I wish I could avoid this code > duplication by having `(inherit %encrypted-root-os)` in the os > definition, but when I do that, the test fails with this error in the > build log: > > /mnt/etc/config.scm:1:100: error: %encrypted-root-os: unbound variable > > Any chance you Guile wizards know how to make this work? I think I've probably banged my head on this at some point but don't have an immediate idea. > > doc/guix.texi | 20 ++++++++++- > gnu/system/mapped-devices.scm | 25 ++++++++----- > gnu/tests/install.scm | 68 +++++++++++++++++++++++++++++++++++ > 3 files changed, 104 insertions(+), 9 deletions(-) > > diff --git a/doc/guix.texi b/doc/guix.texi > index bcb1f9d9cf..9cd1304522 100644 > --- a/doc/guix.texi > +++ b/doc/guix.texi > @@ -18461,7 +18461,7 @@ Mapped Devices > @code{dm-crypt} Linux kernel module. > @end defvar >=20=20 > -@deffn {Procedure} luks-device-mapping-with-options [#:key-file #:allow-= discards?] > +@deffn {Procedure} luks-device-mapping-with-options [#:key-file #:allow-= discards? #:extra-options] Was there a way to break a line in Texinfo? > Return a @code{luks-device-mapping} object, which defines LUKS block > device encryption using the @command{cryptsetup} command from the > package with the same name. It relies on the @code{dm-crypt} Linux > @@ -18492,6 +18492,24 @@ Mapped Devices > information, refer to the description of the @code{--allow-discards} > option in the @code{cryptsetup-open(8)} man page. >=20=20 > +@code{extra-options} may be used to specify a list of additional > +command-line options for the @code{cryptsetup open} command. See the > +@code{cryptsetup-open(8)} man page for a list of supported options. > + > +For example, here is how you could specify the > +@code{--perf-no_read_workqueue} and @code{--perf-no_write_workqueue} > +options, along with @code{--allow-discards}: For the command-line options, you can use @option{...} (see: (info "(texinfo) @option")). > + > +@lisp > +(mapped-device > + (source "/dev/sdb1) > + (target "data) Your strings are double quoted only on the left side. > + (type (luks-device-mapping-with-options > + #:allow-discards? #t > + #:extra-options '("--perf-no_read_workqueue" > + "--perf-no_write_workqueue")))) > +@end lisp > + > @end deffn >=20=20 > @defvar raid-device-mapping > diff --git a/gnu/system/mapped-devices.scm b/gnu/system/mapped-devices.scm > index 667a495570..520ade9ef8 100644 > --- a/gnu/system/mapped-devices.scm > +++ b/gnu/system/mapped-devices.scm > @@ -194,10 +194,12 @@ (define (check-device-initrd-modules device linux-m= odules location) > ;;; Common device mappings. > ;;; >=20=20 > -(define* (open-luks-device source targets #:key key-file allow-discards?) > +(define* (open-luks-device source targets > + #:key key-file allow-discards? extra-options) > "Return a gexp that maps SOURCE to TARGET as a LUKS device, using > 'cryptsetup'. When ALLOW-DISCARDS? is true, the use of discard (TRIM) > -requests is allowed for the underlying device." > +requests is allowed for the underlying device. EXTRA-OPTIONS is a list = of > +additional options to be passed to the 'cryptsetup open' command." > (with-imported-modules (source-module-closure > '((gnu build file-systems) > (guix build utils))) ;; For mkdir-p > @@ -238,10 +240,15 @@ (define* (open-luks-device source targets #:key key= -file allow-discards?) > (let ((cryptsetup #$(file-append cryptsetup-static > "/sbin/cryptsetup")) > (cryptsetup-flags (cons* > - "open" "--type" "luks" partition #= $target > - (if #$allow-discards? > - '("--allow-discards") > - '())))) > + "open" "--type" "luks" > + (append > + (if #$allow-discards? > + '("--allow-discards") > + '()) > + (if (pair? '#$extra-options) > + '#$extra-options > + '()) > + (list partition #$target))))) > ;; We want to fallback to the password unlock if the keyf= ile > ;; fails. > (or (and keyfile > @@ -290,7 +297,8 @@ (define luks-device-mapping > ((gnu build file-systems) > #:select (find-partition-by-luks-uuid system*/tty)))))) >=20=20 > -(define* (luks-device-mapping-with-options #:key key-file allow-discards= ?) > +(define* (luks-device-mapping-with-options > + #:key key-file allow-discards? extra-options) > "Return a luks-device-mapping object with open modified to pass the ar= guments > into the open-luks-device procedure." > (mapped-device-kind > @@ -298,7 +306,8 @@ (define* (luks-device-mapping-with-options #:key key-= file allow-discards?) > (open (=CE=BB (source targets) > (open-luks-device source targets > #:key-file key-file > - #:allow-discards? allow-discards?))))) > + #:allow-discards? allow-discards? > + #:extra-options extra-options))))) >=20=20 > (define (open-raid-device sources targets) > "Return a gexp that assembles SOURCES (a list of devices) to the RAID = device > diff --git a/gnu/tests/install.scm b/gnu/tests/install.scm > index a837637b18..fd9f17eb4d 100644 > --- a/gnu/tests/install.scm > +++ b/gnu/tests/install.scm > @@ -68,6 +68,7 @@ (define-module (gnu tests install) > %test-separate-home-os > %test-raid-root-os > %test-encrypted-root-os > + %test-encrypted-root-extra-options-os > %test-encrypted-home-os > %test-encrypted-home-os-key-file > %test-encrypted-root-not-boot-os > @@ -843,6 +844,73 @@ (define %test-encrypted-root-os > (run-basic-test %encrypted-root-os command "encrypted-root-os" > #:initialization enter-luks-passphrase))))) >=20=20 > + > +;;; > +;;; LUKS-encrypted root with extra options: --allow-discards, > +;;; --perf-no_read_workqueue and --perf-no_write_workqueue > +;;; > + > +;; Except for the 'mapped-devices' field, this is exactly the same as > +;; %encrypted-root-os. > +(define-os-with-source (%encrypted-root-extra-options-os > + %encrypted-root-extra-options-os-source) > + ;; The OS we want to install. > + (use-modules (gnu) (gnu tests) (srfi srfi-1)) > + > + (operating-system > + (host-name "liberigilo") > + (timezone "Europe/Paris") > + (locale "en_US.UTF-8") > + > + (bootloader (bootloader-configuration > + (bootloader grub-bootloader) > + (targets '("/dev/vdb")))) > + > + ;; Note: Do not pass "console=3DttyS0" so we can use our passphrase = prompt > + ;; detection logic in 'enter-luks-passphrase'. > + > + (mapped-devices (list (mapped-device > + (source (uuid "12345678-1234-1234-1234-123456= 789abc")) > + (target "the-root-device") > + (type (luks-device-mapping-with-options > + #:allow-discards? #t > + #:extra-options > + '("--perf-no_read_workqueue" > + "--perf-no_write_workqueue")))))) > + (file-systems (cons (file-system > + (device "/dev/mapper/the-root-device") > + (mount-point "/") > + (type "ext4")) > + %base-file-systems)) > + (users (cons (user-account > + (name "charlie") > + (group "users") > + (supplementary-groups '("wheel" "audio" "video"))) > + %base-user-accounts)) > + (services (cons (service marionette-service-type > + (marionette-configuration > + (imported-modules '((gnu services herd) > + (guix combinators))))) > + %base-services)))) > + > +(define %test-encrypted-root-extra-options-os > + (system-test > + (name "encrypted-root-extra-options-os") > + (description > + "Test basic functionality of an OS installed like one would do by ha= nd, > +with an LUKS-encrypted root partition opened with extra options > +(--allow-discards, --perf-no_read_workqueue and --perf-no_write_workqueu= e). > +This test is expensive in terms of CPU and storage usage since we need to > +build (current-guix) and then store a couple of full system images.") > + (value > + (mlet* %store-monad ((images (run-install %encrypted-root-extra-opti= ons-os > + %encrypted-root-extra-opti= ons-os-source > + #:script > + %encrypted-root-installati= on-script)) > + (command (qemu-command* images))) > + (run-basic-test %encrypted-root-os command "encrypted-root-extra-o= ptions-os" > + #:initialization enter-luks-passphrase))))) Looks good to me. I haven't tried running it yet; if you send a v2 with the small problem I've seen above I'll happily try it and if it passes merge it. --=20 Thanks, Maxim