From 81cd94f18f183eb2276a10b9e1afa0a1ea9f9f60 Mon Sep 17 00:00:00 2001 From: Ville Takio <93599126+flatstik@users.noreply.github.com> Date: Wed, 30 Sep 2026 06:06:28 +0000 Subject: [PATCH] Linux: rewrite mount.veracrypt in POSIX sh (#1895) Use POSIX sh and collect VeraCrypt arguments as quoted positional parameters. Preserve whitespace in option values and keep wildcard characters literal. Handle calls without an option list and skip flags supplied between the mountpoint and -o. Collect system, nokernelcrypto, headerbak, and timestamp into one --mount-options argument. Previously, only system had a mapping to that argument; the remaining options went to the filesystem options. Reject the obsolete truecrypt option before invoking VeraCrypt. Validation: 32 cases passed under both Bash and dash using a stub executable, with comparisons against the original helper. Signed-off-by: Ville Takio --- src/Setup/Linux/mount.veracrypt | 59 ++++++++++++++++++++++----------- 1 file changed, 39 insertions(+), 20 deletions(-) diff --git a/src/Setup/Linux/mount.veracrypt b/src/Setup/Linux/mount.veracrypt index a891c253..fdcebfef 100755 --- a/src/Setup/Linux/mount.veracrypt +++ b/src/Setup/Linux/mount.veracrypt @@ -1,23 +1,42 @@ -#!/bin/bash -DEV="$1" -MNTPT="$2" -VCOPTIONS="" -OPTIONS="" +#!/bin/sh +# mount.veracrypt [flags] [-o comma-options] +DEV=$1 +MNTPT=$2 +MOUNTOPTS= +OPTIONS= -shift 3 -IFS=',' -for arg in $*; do - case "$arg" in - truecrypt) VCOPTIONS=(${VCOPTIONS[*]} --truecrypt);; - system) VCOPTIONS=(${VCOPTIONS[*]} --mount-options=system);; - fs=*) VCOPTIONS=(${VCOPTIONS[*]} --filesystem=${arg#*=});; - keyfiles=*) VCOPTIONS=(${VCOPTIONS[*]} --keyfiles=${arg#*=});; - password=*) VCOPTIONS=(${VCOPTIONS[*]} --password=${arg#*=});; - pim=*) VCOPTIONS=(${VCOPTIONS[*]} --pim=${arg#*=});; - protect-hidden=*) VCOPTIONS=(${VCOPTIONS[*]} --protect-hidden=${arg#*=});; - slot=*) VCOPTIONS=(${VCOPTIONS[*]} --slot=${arg#*=});; - *) OPTIONS="${OPTIONS}${arg},";; - esac +shift 2 +while [ "$#" -gt 0 ] && [ "$1" != "-o" ]; do shift; done +[ "$#" -gt 0 ] && shift + +OLDIFS=$IFS +IFS=, +set -f +OPTSTR="$*" +# Collect veracrypt arguments as positional parameters so values with spaces +# (e.g. keyfile paths) stay single arguments. +set -- +for arg in $OPTSTR; do + case $arg in + system|nokernelcrypto|headerbak|timestamp) + MOUNTOPTS="${MOUNTOPTS:+$MOUNTOPTS,}$arg" ;; + truecrypt) + echo "mount.veracrypt: TrueCrypt mode is no longer supported" >&2 + exit 1 ;; + fs=*) set -- "$@" "--filesystem=${arg#*=}" ;; + keyfiles=*) set -- "$@" "--keyfiles=${arg#*=}" ;; + password=*) set -- "$@" "--password=${arg#*=}" ;; + pim=*) set -- "$@" "--pim=${arg#*=}" ;; + protect-hidden=*) set -- "$@" "--protect-hidden=${arg#*=}" ;; + slot=*) set -- "$@" "--slot=${arg#*=}" ;; + *) OPTIONS="${OPTIONS}${arg}," ;; + esac done +IFS=$OLDIFS +set +f -/usr/bin/veracrypt --text --non-interactive ${VCOPTIONS[*]} --fs-options="${OPTIONS%,*}" ${DEV} ${MNTPT} +# veracrypt reads a single --mount-options value, so pass one comma list. +[ -n "$MOUNTOPTS" ] && set -- "$@" "--mount-options=$MOUNTOPTS" + +exec /usr/bin/veracrypt --text --non-interactive "$@" \ + --fs-options="${OPTIONS%,}" "$DEV" "$MNTPT"