1
0
mirror of https://git.FreeBSD.org/src.git synced 2025-01-21 15:45:02 +00:00
Mirror of the FreeBSD src repository https://git.FreeBSD.org/src.git .
Go to file
Pawel Jakub Dawidek 5ad4a7c74a Bring in geli suspend/resume functionality (finally).
Before this change if you wanted to suspend your laptop and be sure that your
encryption keys are safe, you had to stop all processes that use file system
stored on encrypted device, unmount the file system and detach geli provider.

This isn't very handy. If you are a lucky user of a laptop where suspend/resume
actually works with FreeBSD (I'm not!) you most likely want to suspend your
laptop, because you don't want to start everything over again when you turn
your laptop back on.

And this is where geli suspend/resume steps in. When you execute:

	# geli suspend -a

geli will wait for all in-flight I/O requests, suspend new I/O requests, remove
all geli sensitive data from the kernel memory (like encryption keys) and will
wait for either 'geli resume' or 'geli detach'.

Now with no keys in memory you can suspend your laptop without stopping any
processes or unmounting any file systems.

When you resume your laptop you have to resume geli devices using 'geli resume'
command. You need to provide your passphrase, etc. again so the keys can be
restored and suspended I/O requests released.

Of course you need to remember that 'geli suspend' won't clear file system
cache and other places where data from your geli-encrypted file system might be
present. But to get rid of those stopping processes and unmounting file system
won't help either - you have to turn your laptop off. Be warned.

Also note, that suspending geli device which contains file system with geli
utility (or anything used by 'geli resume') is not very good idea, as you won't
be able to resume it - when you execute geli(8), the kernel will try to read it
and this read I/O request will be suspended.
2010-10-20 20:50:55 +00:00
bin sh(1): Clarify subshells/processes for pipelines. 2010-10-16 14:37:56 +00:00
cddl Properly handle IO with B_FAILFAST 2010-09-27 09:42:31 +00:00
contrib mdoc: drop even more redundant .Pp calls 2010-10-19 12:35:40 +00:00
crypto Remove copyright strings printed at login time via login(1) or sshd(8). 2010-09-28 20:57:14 +00:00
etc No longer install /etc/manpath.config since the BSDL man utilities 2010-10-04 01:07:04 +00:00
games mdoc: drop redundant .Pp and .LP calls 2010-10-08 12:40:16 +00:00
gnu Add FreeBSD 8.2. 2010-10-14 14:48:11 +00:00
include Add pthread_rwlockattr_setkind_np and pthread_rwlockattr_getkind_np, the 2010-10-18 05:09:22 +00:00
kerberos5 Fix a typo. 2010-01-09 18:53:03 +00:00
lib Revert revision 214007, I realized that MySQL wants to resolve 2010-10-20 02:34:02 +00:00
libexec mdoc: drop even more redundant .Pp calls 2010-10-19 12:35:40 +00:00
release Replace an obsolete flag -L in an mkisofs(1) command line with 2010-10-03 13:13:10 +00:00
rescue MFtbemd: 2010-08-23 22:24:11 +00:00
sbin Bring in geli suspend/resume functionality (finally). 2010-10-20 20:50:55 +00:00
secure Revert changes of 'assure' to 'ensure' made in r211936. 2010-09-11 10:49:56 +00:00
share catch up manual pages with rename of vm_page_sleep_busy to vm_page_sleep_if_busy 2010-10-20 06:29:11 +00:00
sys Bring in geli suspend/resume functionality (finally). 2010-10-20 20:50:55 +00:00
tools sh: Allow running 'prove' from tools/regression/bin/sh again 2010-10-15 20:01:35 +00:00
usr.bin Get rid of hand-rolled closefrom(3). 2010-10-20 19:53:29 +00:00
usr.sbin Simplify and significantly speed up the timezone listing backend script. 2010-10-19 15:18:40 +00:00
COPYRIGHT
LOCKS
MAINTAINERS Add a comment to MAINTAINERS indicating that sbin/routed is in fact 2010-04-10 12:29:09 +00:00
Makefile Connect FDT infrastructure to the build system. 2010-06-13 13:02:43 +00:00
Makefile.inc1 Check TARGET_ARCH as well as TARGET to determine if we are doing a cross 2010-09-08 19:53:16 +00:00
Makefile.mips Guard against TARGET_ABI being undefined (TARGET_ABI will go away soon) 2010-08-26 14:54:12 +00:00
ObsoleteFiles.inc catch up manual pages with rename of vm_page_sleep_busy to vm_page_sleep_if_busy 2010-10-20 06:29:11 +00:00
README
UPDATING Add a note on the removal of copyright strings from login(1) and sshd(8). 2010-10-07 17:26:22 +00:00

This is the top level of the FreeBSD source directory.  This file
was last revised on:
$FreeBSD$

For copyright information, please see the file COPYRIGHT in this
directory (additional copyright information also exists for some
sources in this tree - please see the specific source directories for
more information).

The Makefile in this directory supports a number of targets for
building components (or all) of the FreeBSD source tree, the most
commonly used one being ``world'', which rebuilds and installs
everything in the FreeBSD system from the source tree except the
kernel, the kernel-modules and the contents of /etc.  The ``world''
target should only be used in cases where the source tree has not
changed from the currently running version.  See:
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html
for more information, including setting make(1) variables.

The ``buildkernel'' and ``installkernel'' targets build and install
the kernel and the modules (see below).  Please see the top of
the Makefile in this directory for more information on the
standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process, documentation
for which can be found at:
   http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html
And in the config(8) man page.
Note: If you want to build and install the kernel with the
``buildkernel'' and ``installkernel'' targets, you might need to build
world before.  More information is available in the handbook.

The sample kernel configuration files reside in the sys/<arch>/conf
sub-directory (assuming that you've installed the kernel sources), the
file named GENERIC being the one used to build your initial installation
kernel.  The file NOTES contains entries and documentation for all possible
devices, not just those commonly used.  It is the successor of the ancient
LINT file, but in contrast to LINT, it is not buildable as a kernel but a
pure reference and documentation file.


Source Roadmap:
---------------
bin		System/user commands.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

games		Amusements.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

sys		Kernel sources.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.


For information on synchronizing your source tree with one or more of
the FreeBSD Project's development branches, please see:

  http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/synching.html