Skip to content

veracrypt: add version 1.26.29 - #30597

Open
flatstik wants to merge 1 commit into
openwrt:masterfrom
flatstik:veracrypt-add
Open

flatstik wants to merge 1 commit into
openwrt:masterfrom
flatstik:veracrypt-add

Conversation

@flatstik

@flatstik flatstik commented Sep 25, 2026 •

Copy link
Copy Markdown

📦 Package Details

Maintainer: @flatstik

Description:
Add a console-only VeraCrypt package for OpenWrt.

Upstream: https://github.com/veracrypt/VeraCrypt/releases/tag/VeraCrypt_1.26.29

This replaces closed PR #30508 with a clean single-commit history (no GitHub merge commits).


🧪 Run Testing Details

Run-tested on the device above with the 25.12.5 SDK build: --test self-tests, --create --filesystem=ext4 (formatted through FUSE, no dmsetup), mount/write/read/unmount, auto-hash mount, mount.veracrypt; about 11 MB/s encrypt+write, ~57 s per unlock (SHA-512 PBKDF2) on MT7621.

Build-tested with the current snapshot SDK on all ten CI architectures (aarch64_generic, arm_cortex-a15_neon-vfpv4, arm_cortex-a9_vfpv3-d16, i386_pentium-mmx, mips_24kc, mipsel_24kc, powerpc_464fp, powerpc_8548, riscv64_generic, x86_64); the x86_64 build passes the generic runtime checks plus test.sh and test-version.sh.


✅ Formalities

  • I have reviewed the CONTRIBUTING.md file for detailed contributing guidelines.

If your PR contains a patch:

  • It can be applied using git am
  • It has been refreshed to avoid offsets, fuzzes, etc., using
    make package/<your-package>/refresh V=s
  • It is structured in a way that it is potentially upstreamable
    (e.g., subject line, commit description, etc.)
    We must try to upstream patches to reduce maintenance burden.

@openwrt openwrt Bot added the Add package label Sep 25, 2026
flatstik added a commit to flatstik/luci that referenced this pull request Sep 25, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 25, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 25, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
Comment thread utils/veracrypt/files/mount.veracrypt Outdated
Comment thread utils/veracrypt/test.sh Outdated
flatstik added a commit to flatstik/luci that referenced this pull request Sep 26, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 26, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 26, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
Comment thread utils/veracrypt/Makefile Outdated
@flatstik
flatstik requested a review from openwrt-ai September 27, 2026 16:30
@flatstik
flatstik force-pushed the veracrypt-add branch 2 times, most recently from 5f8a33b to 19d0a0a Compare September 27, 2026 18:36
flatstik added a commit to flatstik/luci that referenced this pull request Sep 27, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 27, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 27, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Commit checks

  • de9cc1a "veracrypt: add version 1.26.29" — the Signed-off-by: Ville Takio trailer appears twice; keep one.

Generated by Claude Code

Comment thread utils/veracrypt/Makefile Outdated
Comment thread utils/veracrypt/test.sh Outdated
flatstik added a commit to flatstik/luci that referenced this pull request Sep 27, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. New password, hidden
volume password and token PIN are fed on stdin, not via
--new-password, --protection-password or --token-pin.

CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Sep 30, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. tests/run.sh exercises the rpcd
backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik

Copy link
Copy Markdown
Author

Run-tested on an ASUS RT-AX53U (ramips/mt7621, OpenWrt 25.12.5, no lvm2), which turned up one more issue: --create --filesystem=ext4 wrote the container but then failed with "dmsetup not found", because formatting maps the new volume through dmsetup unless nokernelcrypto is given. New patch 040 makes VeraCrypt fall back to FUSE when dmsetup is not installed (submitted as veracrypt/VeraCrypt#1898); with it, create/format, mount, write/read, unmount and mount.veracrypt all pass on the device. The package description is adjusted accordingly.

@flatstik

Copy link
Copy Markdown
Author

The previous CI run failed on mips_24kc in the runtime test: veracrypt --text --test (added to test.sh in the review round) reported TestFailed at VeraCrypt::TestCipher:222. It is the only big-endian target CI runs, and the failure is real: VeraCrypt's portable C code assumes a little-endian host, so on big-endian CPUs Twofish, Camellia and Kuznyechik produced wrong ciphertext, and SHA-256/512, BLAKE2s, Streebog and the PBKDF2 block counter were wrong as well. Volumes created on such a router would not open anywhere else, and vice versa.

New patch 050 fixes all of them (submitted as veracrypt/VeraCrypt#1899). On little-endian CPUs the generated code does not change. Verified with the OpenWrt toolchains: Self-tests of all algorithms passed on mips_24kc under qemu-mips (previously failing), and still on mipsel_24kc (qemu) and x86_64.

flatstik added a commit to flatstik/luci that referenced this pull request Sep 30, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. tests/run.sh exercises the rpcd
backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik
flatstik force-pushed the veracrypt-add branch 2 times, most recently from bb508a0 to c41f1dc Compare October 1, 2026 08:07
flatstik added a commit to flatstik/luci that referenced this pull request Oct 1, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt
output are always shown as text, never parsed as HTML. tests/run.sh
exercises the rpcd backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik

flatstik commented Oct 1, 2026

Copy link
Copy Markdown
Author

Updated after another review pass:

  • PKG_LICENSE_FILES used $(WX_VERSION) before it was defined and expanded to src/wxWidgets-/docs/licence.txt; the wx variables now come first.
  • Patch 050 (big-endian fix, Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899) revised: the code for little-endian CPUs is now exactly unchanged — the objects of all seven touched files are byte-identical with and without the patch on x86_64, aarch64 and mipsel — and big-endian uses inline byte swaps. Self-tests pass on mips_24kc (qemu) and x86_64.
  • 040/050 carry their upstream commit ids; the commit message no longer says direct veracrypt use needs nokernelcrypto.
  • 900 stays on purpose: with lvm2 installed but without the XTS/AES crypto modules, kernel crypto would fail without falling back, so mount.veracrypt keeps FUSE as the predictable default; veracrypt itself still uses dm-crypt when it is available.

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; no new issues found.


Generated by Claude Code

@flatstik

flatstik commented Oct 1, 2026

Copy link
Copy Markdown
Author

They are the runtime tests the feeds CI runs in the target container:

  • test.sh checks that veracrypt and mount.veracrypt are installed and runs veracrypt --text --test, VeraCrypt's own algorithm self-tests. Upstream runs these right after linking, which a cross build cannot do (NOTEST=1); here they caught the big-endian crypto bug on mips_24kc (patch 050).
  • test-version.sh replaces the generic version check: veracrypt prints its version only with --text --version, and mount.veracrypt would treat the test's arguments as a device and mount point. Same approach as e.g. admin/sudo or admin/nload.

@flatstik
flatstik requested a review from karlp October 1, 2026 10:02
flatstik added a commit to flatstik/luci that referenced this pull request Oct 1, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt
output are always shown as text, never parsed as HTML. tests/run.sh
exercises the rpcd backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik

flatstik commented Oct 1, 2026

Copy link
Copy Markdown
Author

Pushed 4353a16:

  • Dropped PKG_BUILD_FLAGS:=no-mips16 as @karlp suggested.
  • Moved the WX_* variables above PKG_LICENSE_FILES, so the wxWidgets licence path expands correctly.
  • Patch 050 is regenerated from the revised Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899. Patches 051 (unaligned 64-bit accesses, SIGBUS on mips64) and 052 (more self-test vectors) are new, from the same PR. All patches are quilt-refreshed.

I built and tested it with the 25.12 SDKs on mips64, mips_24kc, powerpc_464fp, powerpc_8548 (big-endian), and aarch64_generic, arm_cortex-a9, arm_cortex-a15, i386_pentium-mmx, mipsel_24kc, riscv64_generic, x86_64 (little-endian), under qemu-user. On every target veracrypt --text --test passes and all five official Tests/*.hc volumes open and accept a password change. Big-endian CI for the upstream PR: https://github.com/flatstik/VeraCrypt/actions/runs/36880422979

flatstik added a commit to flatstik/luci that referenced this pull request Oct 1, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt
output are always shown as text, never parsed as HTML. tests/run.sh
exercises the rpcd backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik

flatstik commented Oct 1, 2026

Copy link
Copy Markdown
Author

Pushed b65eb1c: the patches still pending upstream are renumbered 100-103 (0xx backports, 1xx pending upstream, 9xx OpenWrt-specific). Quilt refresh leaves all patches unchanged. Run-tested again on an RT-AX53U (mipsel_24kc, 25.12.5): the self-tests pass, and create, mount (FUSE), unmount and mount.veracrypt all work.

@flatstik

flatstik commented Oct 2, 2026

Copy link
Copy Markdown
Author

Pushed cf39772: patches 101-103 regenerated from the hardened veracrypt/VeraCrypt#1899. Big-endian loads and stores are now byte-wise (safe on misaligned buffers), and the BLAKE2s parameter block is built from its fields. Quilt refresh is clean. On all 11 test targets (4 big-endian) the self-tests pass, all official volumes open, and the known-answer output matches.

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; no new issues found.


Generated by Claude Code

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add the missing FUSE3 build dependency and the runtime dependency providing mkfs.ext4.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds VeraCrypt 1.26.29 as a console-only OpenWrt package using FUSE3, loop devices, and cross-platform fixes.

Changes:

  • Adds build metadata, configuration, licensing, dependencies, and tests.
  • Adds mount-helper, FUSE fallback, portability, alignment, and crypto patches.
  • Adds version and runtime self-test scripts.
File Description
utils/​veracrypt/​test.sh Runtime self-test
utils/​veracrypt/​test-version.sh Version validation
utils/​veracrypt/​patches/​900-mount.veracrypt-default-nokernelcrypto.patch OpenWrt FUSE default
utils/​veracrypt/​patches/​103-volume-test-multi-block-pbkdf2-and-streebog-carry.patch Expanded crypto tests
utils/​veracrypt/​patches/​102-volume-avoid-unaligned-64-bit-accesses.patch Alignment fix
utils/​veracrypt/​patches/​101-crypto-fix-portable-c-code-on-big-endian-cpus.patch Big-endian crypto fixes
utils/​veracrypt/​patches/​100-linux-fall-back-to-fuse-without-dmsetup.patch FUSE fallback
utils/​veracrypt/​patches/​030-crypto-fix-noasm-link-failures-on-x86.patch x86 NOASM fix
utils/​veracrypt/​patches/​020-mount.veracrypt-posix-sh.patch POSIX mount helper
utils/​veracrypt/​patches/​010-cpu-vc-inline.patch ARM link fix
utils/​veracrypt/​Makefile Package build and installation definition
utils/​veracrypt/​files/​veracrypt.config Default UCI configuration

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread utils/veracrypt/Makefile
PKG_CPE_ID:=cpe:/a:idrix:veracrypt

PKG_BUILD_PARALLEL:=1
PKG_BUILD_DEPENDS:=pcsc-lite

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not needed: in OpenWrt a runtime DEPENDS:=+libfuse3 already makes the package build depend on the source package that provides libfuse3 (fuse3). scripts/package-metadata.pl (gen_package_mk) turns package dependencies into build-order dependencies, so fuse3's headers and fuse3.pc are staged before veracrypt is built. Clean SDK builds and the CI test builds succeed this way. pcsc-lite is in PKG_BUILD_DEPENDS only because it's a header-only build dependency with no runtime package dependency.

Add a console-only VeraCrypt package using FUSE3 and statically
linked wxBase. x86 builds without assembler (NOASM); other targets
use VeraCrypt's C/intrinsics code, including ARMv8 hardware AES.
Runtime depends on libstdcpp, libatomic, libfuse3, fuse3-utils,
losetup and kmod-loop (volumes are mounted through a loop device).

Patches 010-030 are backports from upstream. Without dmsetup (lvm2)
VeraCrypt mounts and formats volumes through FUSE3 (patch 100), and
mount.veracrypt always passes nokernelcrypto (patch 900).
Patches 101-103 fix the portable crypto code on big-endian targets
(mips, powerpc), avoid unaligned 64-bit accesses (mips64) and extend
the self-tests. Patch 901 lets the OpenWrt jobserver control the
wxWidgets build. test.sh checks the version and runs the algorithm
self-tests.

Upstream: https://github.com/veracrypt/VeraCrypt/releases/tag/VeraCrypt_1.26.29
Run-tested on ramips/mt7621 (ASUS RT-AX53U, mipsel_24kc) with OpenWrt
25.12.5: self-tests, create, FUSE mount, unmount and mount.veracrypt.

Signed-off-by: Ville Takio <ville+git@takio.fi>
flatstik added a commit to flatstik/luci that referenced this pull request Oct 2, 2026
Web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

Not bundled into veracrypt; apk add luci-app-veracrypt depends on
+veracrypt. Calls veracrypt --text only. The current password is
passed on stdin (--stdin), never --password. Other secrets (new
password, hidden volume password, token PIN) are answered to
veracrypt's prompts one at a time through a private FIFO; values with
line breaks are refused, and secrets are kept out of the environment.

All paths are confined to /mnt/<name>/... (or a whole disk device)
and used in resolved form. Each job has its own random id and state
directory under /var/run, and package installation needs the separate
luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt
output are always shown as text, never parsed as HTML. tests/run.sh
exercises the rpcd backend in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik

flatstik commented Oct 2, 2026

Copy link
Copy Markdown
Author

Pushed d061c88:

  • Patches 101-103 (Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899):
    • The big-endian Kuznyechik path no longer forms misaligned uint64* pointers.
    • The byte-wise helpers are inline functions, so each argument is evaluated once.
    • The XTS stack arrays are declared 8-byte aligned.
    • Little-endian object code is unchanged.
  • New 901: the wxWidgets sub-build follows the OpenWrt jobserver instead of -j 4.
  • test.sh: also checks the version.
  • Commit message: states what was run-tested.

Verification:

  • Quilt refresh leaves all 9 patches unchanged.
  • An 11-target rebuild (4 big-endian) passes the self-tests, opens all official test volumes, and matches the known-answer output.
  • The RT-AX53U (mipsel_24kc, 25.12.5) run passes 42/42.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants