Conversation
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
0d4699c to
5d2e55b
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
5d2e55b to
82411df
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
84b7180 to
19d0a0a
Compare
19d0a0a to
82b98b5
Compare
5f8a33b to
19d0a0a
Compare
19d0a0a to
9b0133f
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
9b0133f to
b4ccd75
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
b4ccd75 to
de9cc1a
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
openwrt-ai
left a comment
There was a problem hiding this comment.
Commit checks
- de9cc1a "veracrypt: add version 1.26.29" — the
Signed-off-by: Ville Takiotrailer appears twice; keep one.
Generated by Claude Code
de9cc1a to
8ece9cb
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. New password, hidden volume password and token PIN are fed on stdin, not via --new-password, --protection-password or --token-pin. CLI reference: https://www.veracrypt.fr/en/Command%20Line%20Usage.html Signed-off-by: Ville Takio <ville+git@takio.fi>
b305d42 to
ce1f47d
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
|
Run-tested on an ASUS RT-AX53U (ramips/mt7621, OpenWrt 25.12.5, no lvm2), which turned up one more issue: |
ce1f47d to
2ed5a0e
Compare
|
The previous CI run failed on New patch |
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
bb508a0 to
c41f1dc
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt output are always shown as text, never parsed as HTML. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
|
Updated after another review pass:
|
c41f1dc to
e81bd0a
Compare
|
They are the runtime tests the feeds CI runs in the target container:
|
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt output are always shown as text, never parsed as HTML. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
e81bd0a to
4353a16
Compare
|
Pushed 4353a16:
I built and tested it with the 25.12 SDKs on mips64, mips_24kc, powerpc_464fp, powerpc_8548 (big-endian), and aarch64_generic, arm_cortex-a9, arm_cortex-a15, i386_pentium-mmx, mipsel_24kc, riscv64_generic, x86_64 (little-endian), under qemu-user. On every target |
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt output are always shown as text, never parsed as HTML. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
4353a16 to
b65eb1c
Compare
|
Pushed b65eb1c: the patches still pending upstream are renumbered 100-103 (0xx backports, 1xx pending upstream, 9xx OpenWrt-specific). Quilt refresh leaves all patches unchanged. Run-tested again on an RT-AX53U (mipsel_24kc, 25.12.5): the self-tests pass, and create, mount (FUSE), unmount and mount.veracrypt all work. |
b65eb1c to
cf39772
Compare
|
Pushed cf39772: patches 101-103 regenerated from the hardened veracrypt/VeraCrypt#1899. Big-endian loads and stores are now byte-wise (safe on misaligned buffers), and the BLAKE2s parameter block is built from its fields. Quilt refresh is clean. On all 11 test targets (4 big-endian) the self-tests pass, all official volumes open, and the known-answer output matches. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Add the missing FUSE3 build dependency and the runtime dependency providing mkfs.ext4.
Review effort: Lite
Findings: 1
What changed in this PR
Adds VeraCrypt 1.26.29 as a console-only OpenWrt package using FUSE3, loop devices, and cross-platform fixes.
Changes:
- Adds build metadata, configuration, licensing, dependencies, and tests.
- Adds mount-helper, FUSE fallback, portability, alignment, and crypto patches.
- Adds version and runtime self-test scripts.
| File | Description |
|---|---|
utils/veracrypt/test.sh |
Runtime self-test |
utils/veracrypt/test-version.sh |
Version validation |
utils/veracrypt/patches/900-mount.veracrypt-default-nokernelcrypto.patch |
OpenWrt FUSE default |
utils/veracrypt/patches/103-volume-test-multi-block-pbkdf2-and-streebog-carry.patch |
Expanded crypto tests |
utils/veracrypt/patches/102-volume-avoid-unaligned-64-bit-accesses.patch |
Alignment fix |
utils/veracrypt/patches/101-crypto-fix-portable-c-code-on-big-endian-cpus.patch |
Big-endian crypto fixes |
utils/veracrypt/patches/100-linux-fall-back-to-fuse-without-dmsetup.patch |
FUSE fallback |
utils/veracrypt/patches/030-crypto-fix-noasm-link-failures-on-x86.patch |
x86 NOASM fix |
utils/veracrypt/patches/020-mount.veracrypt-posix-sh.patch |
POSIX mount helper |
utils/veracrypt/patches/010-cpu-vc-inline.patch |
ARM link fix |
utils/veracrypt/Makefile |
Package build and installation definition |
utils/veracrypt/files/veracrypt.config |
Default UCI configuration |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| PKG_CPE_ID:=cpe:/a:idrix:veracrypt | ||
|
|
||
| PKG_BUILD_PARALLEL:=1 | ||
| PKG_BUILD_DEPENDS:=pcsc-lite |
There was a problem hiding this comment.
Not needed: in OpenWrt a runtime DEPENDS:=+libfuse3 already makes the package build depend on the source package that provides libfuse3 (fuse3). scripts/package-metadata.pl (gen_package_mk) turns package dependencies into build-order dependencies, so fuse3's headers and fuse3.pc are staged before veracrypt is built. Clean SDK builds and the CI test builds succeed this way. pcsc-lite is in PKG_BUILD_DEPENDS only because it's a header-only build dependency with no runtime package dependency.
Add a console-only VeraCrypt package using FUSE3 and statically linked wxBase. x86 builds without assembler (NOASM); other targets use VeraCrypt's C/intrinsics code, including ARMv8 hardware AES. Runtime depends on libstdcpp, libatomic, libfuse3, fuse3-utils, losetup and kmod-loop (volumes are mounted through a loop device). Patches 010-030 are backports from upstream. Without dmsetup (lvm2) VeraCrypt mounts and formats volumes through FUSE3 (patch 100), and mount.veracrypt always passes nokernelcrypto (patch 900). Patches 101-103 fix the portable crypto code on big-endian targets (mips, powerpc), avoid unaligned 64-bit accesses (mips64) and extend the self-tests. Patch 901 lets the OpenWrt jobserver control the wxWidgets build. test.sh checks the version and runs the algorithm self-tests. Upstream: https://github.com/veracrypt/VeraCrypt/releases/tag/VeraCrypt_1.26.29 Run-tested on ramips/mt7621 (ASUS RT-AX53U, mipsel_24kc) with OpenWrt 25.12.5: self-tests, create, FUSE mount, unmount and mount.veracrypt. Signed-off-by: Ville Takio <ville+git@takio.fi>
cf39772 to
d061c88
Compare
Web UI for the console veracrypt package (packages feed): openwrt/packages#30597 Not bundled into veracrypt; apk add luci-app-veracrypt depends on +veracrypt. Calls veracrypt --text only. The current password is passed on stdin (--stdin), never --password. Other secrets (new password, hidden volume password, token PIN) are answered to veracrypt's prompts one at a time through a private FIFO; values with line breaks are refused, and secrets are kept out of the environment. All paths are confined to /mnt/<name>/... (or a whole disk device) and used in resolved form. Each job has its own random id and state directory under /var/run, and package installation needs the separate luci-app-veracrypt-pkg ACL grant. File names, paths and veracrypt output are always shown as text, never parsed as HTML. tests/run.sh exercises the rpcd backend in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
|
Pushed d061c88:
Verification:
|

📦 Package Details
Maintainer: @flatstik
Description:
Add a console-only VeraCrypt package for OpenWrt.
NOASM), other targets use VeraCrypt's normal C/intrinsics code (ARMv8 hardware AES included)VeraCrypt_1.26.29_Source.tar.bz2;License.txtis installed to/usr/share/doc/veracrypt/as the TrueCrypt License 3.0 requires/sbin/mount.veracryptis upstream's helper; it always passes--mount-options=nokernelcrypto, so volumes mount through FUSE3 and dmsetup/lvm2 is not a dependency (pass it yourself when callingveracryptdirectly)/etc/config/veracrypt(conffile) with global settings and commented example volumes; luci-app-veracrypt edits it010: ARMCPU_Query*link fix (VC_INLINE), backport of merged Crypto: use VC_INLINE for the ARM CPU_Query helpers veracrypt/VeraCrypt#1886 (veracrypt/VeraCrypt@5c7f60d)020: POSIX shmount.veracrypt, backport of merged Linux: make mount.veracrypt POSIX sh veracrypt/VeraCrypt#1895 (veracrypt/VeraCrypt@81cd94f)030: x86NOASMlink fix, backport of merged Crypto: fix NOASM link failures on x86 veracrypt/VeraCrypt#1896 (veracrypt/VeraCrypt@a15c996)100: fall back to FUSE when dmsetup is not installed (so--createwith ext4 and plain mounts work without lvm2), Linux: fall back to FUSE when dmsetup is not installed veracrypt/VeraCrypt#1898101: fix the portable C code of Twofish, Camellia, Kuznyechik, SHA-2, BLAKE2s, Streebog and PBKDF2 on big-endian CPUs (mips_24kc, powerpc), Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899102: avoid unaligned 64-bit header and test vector accesses (SIGBUS on mips64), Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899103: self-test multi-block PBKDF2 output and the Streebog carry case, Crypto: fix portable C code on big-endian CPUs veracrypt/VeraCrypt#1899900: defaultnokernelcryptoinmount.veracrypt(OpenWrt-specific)901: let the OpenWrt jobserver control the wxWidgets build instead of a fixed-j 4(OpenWrt-specific)Upstream: https://github.com/veracrypt/VeraCrypt/releases/tag/VeraCrypt_1.26.29
This replaces closed PR #30508 with a clean single-commit history (no GitHub merge commits).
🧪 Run Testing Details
Run-tested on the device above with the 25.12.5 SDK build:
--testself-tests,--create --filesystem=ext4(formatted through FUSE, no dmsetup), mount/write/read/unmount, auto-hash mount,mount.veracrypt; about 11 MB/s encrypt+write, ~57 s per unlock (SHA-512 PBKDF2) on MT7621.Build-tested with the current snapshot SDK on all ten CI architectures (aarch64_generic, arm_cortex-a15_neon-vfpv4, arm_cortex-a9_vfpv3-d16, i386_pentium-mmx, mips_24kc, mipsel_24kc, powerpc_464fp, powerpc_8548, riscv64_generic, x86_64); the x86_64 build passes the generic runtime checks plus
test.shandtest-version.sh.✅ Formalities
If your PR contains a patch:
git am(e.g., subject line, commit description, etc.)
We must try to upstream patches to reduce maintenance burden.