Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
103 changes: 103 additions & 0 deletions utils/veracrypt/Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,103 @@
include $(TOPDIR)/rules.mk

PKG_NAME:=veracrypt
PKG_VERSION:=1.26.29
PKG_RELEASE:=1

PKG_SOURCE:=VeraCrypt_$(PKG_VERSION)_Source.tar.bz2
PKG_SOURCE_URL:=https://github.com/veracrypt/VeraCrypt/releases/download/VeraCrypt_$(PKG_VERSION)
PKG_HASH:=60826731e2982b4bd231e3930e85a44391169638671a1b200c518f8c8b46cb2a

PKG_MAINTAINER:=Ville Takio <ville+git@takio.fi>
PKG_LICENSE:=Apache-2.0 AND LicenseRef-TrueCrypt-3.0 AND LicenseRef-wxWindows-3.1 AND GPL-2.0-only
PKG_LICENSE_FILES:=src/License.txt License.txt
PKG_CPE_ID:=cpe:/a:idrix:veracrypt

PKG_BUILD_PARALLEL:=1
PKG_BUILD_FLAGS:=no-mips16
# Headers only (libpcsclite is dlopened at runtime for token keyfiles).
# PKG_BUILD_DEPENDS uses source-directory names (utils/fuse3, utils/pcsc-lite).
# OpenWrt installs pcsclite.h under usr/include/PCSC.
PKG_BUILD_DEPENDS:=fuse3 pcsc-lite

WX_VERSION:=3.2.10
WX_FILE:=wxWidgets-$(WX_VERSION).tar.bz2
WX_HASH:=d66e929569947a4a5920699539089a9bda83a93e5f4917fb313a61f0c344b896

include $(INCLUDE_DIR)/package.mk

define Package/veracrypt
SECTION:=utils
CATEGORY:=Utilities
SUBMENU:=Encryption
TITLE:=VeraCrypt disk encryption (console)
URL:=https://www.veracrypt.fr/
DEPENDS:=+libstdcpp +libatomic +fuse3-utils +losetup
endef

define Package/veracrypt/description
Console-only VeraCrypt. Mounts encrypted volumes via FUSE3.
Uses statically linked wxBase (no GUI). Crypto is portable C
(no x86 assembler).
endef

define Download/wxwidgets
URL:=https://github.com/wxWidgets/wxWidgets/releases/download/v$(WX_VERSION)
FILE:=$(WX_FILE)
HASH:=$(WX_HASH)
endef
$(eval $(call Download,wxwidgets))

# Official source tarball has no top-level directory.
PKG_UNPACK:=$(HOST_TAR) -C $(PKG_BUILD_DIR) -xjf $(DL_DIR)/$(PKG_SOURCE)

define Build/Prepare
$(call Build/Prepare/Default)
$(HOST_TAR) -C $(PKG_BUILD_DIR) -xjf $(DL_DIR)/$(WX_FILE)
endef
Comment thread
flatstik marked this conversation as resolved.

# x86_64/i386: NOASM skips aes_hw_cpu.o but Cipher.cpp still calls AES-NI/SHA-NI;
# CRYPTOPP_DISABLE_* keeps those on portable C.
# aarch64: DetectArmFeatures needs C99 static inline; see
# patches/010-cpu-static-inline.patch.
VC_MAKE_FLAGS = \
AR="$(TARGET_AR)" \
CC="$(TARGET_CC)" \
CXX="$(TARGET_CXX)" \
AS="$(TARGET_CC)" \
RANLIB="$(TARGET_RANLIB)" \
PKG_CONFIG="$(PKG_CONFIG)" \
PKG_CONFIG_PATH="$(STAGING_DIR)/usr/lib/pkgconfig:$(STAGING_DIR)/usr/share/pkgconfig" \
PKG_CONFIG_LIBDIR="$(STAGING_DIR)/usr/lib/pkgconfig:$(STAGING_DIR)/usr/share/pkgconfig" \
WX_ROOT="$(PKG_BUILD_DIR)/wxWidgets-$(WX_VERSION)" \
WX_BUILD_DIR="$(PKG_BUILD_DIR)/wxBuildConsole" \
WX_CONFIGURE_EXTRA_FLAGS="--target=$(GNU_TARGET_NAME) --host=$(GNU_TARGET_NAME) --build=$(GNU_HOST_NAME) --prefix=/usr --exec-prefix=/usr --disable-rpath --with-libiconv=no --disable-gui --disable-shared" \
TC_EXTRA_CFLAGS="$(TARGET_CFLAGS) $(TARGET_CPPFLAGS) -I$(STAGING_DIR)/usr/include/PCSC -DCRYPTOPP_DISABLE_ASM -DCRYPTOPP_DISABLE_AESNI -DCRYPTOPP_DISABLE_SHANI -DCRYPTOPP_DISABLE_X86ASM" \
TC_EXTRA_CXXFLAGS="$(TARGET_CXXFLAGS) $(TARGET_CPPFLAGS) -I$(STAGING_DIR)/usr/include/PCSC -DCRYPTOPP_DISABLE_ASM -DCRYPTOPP_DISABLE_AESNI -DCRYPTOPP_DISABLE_SHANI -DCRYPTOPP_DISABLE_X86ASM" \
TC_EXTRA_LFLAGS="$(TARGET_LDFLAGS) -latomic" \
CPU_ARCH=unknown \
NOASM=1 \
NOAESNI=1 \
NOGUI=1 \
WITHFUSE3=1 \
WXSTATIC=1 \
NOTEST=1 \
NOSTRIP=1 \
GCC_GTEQ_430=0 \
GCC_GTEQ_440=0 \
GCC_GTEQ_470=0 \
GCC_GTEQ_500=0 \
SIMD_SUPPORTED=0

define Build/Compile
+$(MAKE) -C $(PKG_BUILD_DIR)/src $(VC_MAKE_FLAGS) wxbuild
+$(MAKE) -C $(PKG_BUILD_DIR)/src $(PKG_JOBS) $(VC_MAKE_FLAGS)
endef

define Package/veracrypt/install
$(INSTALL_DIR) $(1)/usr/bin $(1)/sbin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/src/Main/veracrypt $(1)/usr/bin/veracrypt
$(INSTALL_BIN) ./files/mount.veracrypt $(1)/sbin/mount.veracrypt
Comment thread
flatstik marked this conversation as resolved.
endef

$(eval $(call BuildPackage,veracrypt))
59 changes: 59 additions & 0 deletions utils/veracrypt/files/mount.veracrypt
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
#!/bin/sh
# SPDX-License-Identifier: GPL-2.0-only
# mount.veracrypt <device> <mountpoint> [flags] [-o comma-opts]
DEV=$1
MNTPT=$2
VCOPTIONS=
OPTIONS=
PASS=
PASSFILE=

shift 2
while [ "$#" -gt 0 ] && [ "$1" != "-o" ]; do shift; done
[ "$#" -gt 0 ] && shift

OLDIFS=$IFS
IFS=,
set -f
for arg in $*; do
case $arg in
truecrypt) VCOPTIONS="$VCOPTIONS --truecrypt" ;;
system) VCOPTIONS="$VCOPTIONS --mount-options=system" ;;
fs=*) VCOPTIONS="$VCOPTIONS --filesystem=${arg#*=}" ;;
keyfiles=*) VCOPTIONS="$VCOPTIONS --keyfiles=${arg#*=}" ;;
password-file=*) PASSFILE=${arg#*=} ;;
password=*) PASS=${arg#*=} ;;
Comment thread
flatstik marked this conversation as resolved.
pim=*) VCOPTIONS="$VCOPTIONS --pim=${arg#*=}" ;;
protect-hidden=*) VCOPTIONS="$VCOPTIONS --protect-hidden=${arg#*=}" ;;
slot=*) VCOPTIONS="$VCOPTIONS --slot=${arg#*=}" ;;
*) OPTIONS="${OPTIONS}${arg}," ;;
esac
done
IFS=$OLDIFS
set +f

if [ -n "$PASSFILE" ]; then
case $PASSFILE in
/*) ;;
*) echo "mount.veracrypt: password-file must be an absolute path" >&2; exit 1 ;;
esac
if [ ! -r "$PASSFILE" ]; then
echo "mount.veracrypt: cannot read $PASSFILE" >&2
exit 1
fi
IFS= read -r PASS < "$PASSFILE" || true
Comment thread
flatstik marked this conversation as resolved.
if [ -z "$PASS" ]; then
echo "mount.veracrypt: $PASSFILE is empty" >&2
exit 1
fi
fi

if [ -n "$PASS" ]; then
# ash printf is a builtin, so the passphrase is not in veracrypt's argv.
# Prefer password-file= over password= so the secret is not in this helper's argv.
printf '%s\n' "$PASS" | /usr/bin/veracrypt --text --non-interactive --stdin \
$VCOPTIONS --fs-options="${OPTIONS%,}" "$DEV" "$MNTPT"
exit $?
fi
exec /usr/bin/veracrypt --text --non-interactive \
$VCOPTIONS --fs-options="${OPTIONS%,}" "$DEV" "$MNTPT"
36 changes: 36 additions & 0 deletions utils/veracrypt/patches/010-cpu-static-inline.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Ville Takio <ville+git@takio.fi>
Date: Mon, 21 Sep 2026 20:50:00 +0000
Subject: [PATCH] Crypto: make ARM CPU_Query helpers static inline

C99 inline without static does not emit a function body, so aarch64
builds fail to link DetectArmFeatures (undefined reference to
CPU_QueryAES / CPU_QuerySHA2).

Upstream-Status: Submitted [https://github.com/veracrypt/VeraCrypt/pull/1886]

Signed-off-by: Ville Takio <ville+git@takio.fi>
---
src/Crypto/cpu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)

--- a/src/Crypto/cpu.c
+++ b/src/Crypto/cpu.c
@@ -489,7 +489,7 @@ void DisableCPUExtendedFeatures ()
volatile int g_hasAESARM = 0;
volatile int g_hasSHA256ARM = 0;

-inline int CPU_QueryAES()
+static inline int CPU_QueryAES()
{
#if defined(CRYPTOPP_ARM_AES_AVAILABLE)
#if defined(__linux__) && defined(__aarch64__)
@@ -513,7 +513,7 @@ inline int CPU_QueryAES()
#endif
}

-inline int CPU_QuerySHA2()
+static inline int CPU_QuerySHA2()
{
#if defined(CRYPTOPP_ARM_SHA2_AVAILABLE)
#if defined(__linux__) && defined(__aarch64__)
14 changes: 14 additions & 0 deletions utils/veracrypt/test-version.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
#!/bin/sh
# SPDX-License-Identifier: GPL-2.0-only
# shellcheck shell=busybox
# Skip generic --version probing of mount.veracrypt (it is a mount helper).

case "$PKG_NAME" in
veracrypt)
veracrypt --text --version 2>&1 | grep -F "$PKG_VERSION"
;;
*)
echo "Untested package: $PKG_NAME" >&2
exit 1
;;
esac
3 changes: 3 additions & 0 deletions utils/veracrypt/test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
#!/bin/sh
# SPDX-License-Identifier: GPL-2.0-only
veracrypt --text --version 2>&1 | grep -F "$PKG_VERSION"