Linux: rewrite mount.veracrypt in POSIX sh (#1895)

Use POSIX sh and collect VeraCrypt arguments as quoted positional
parameters. Preserve whitespace in option values and keep wildcard
characters literal.

Handle calls without an option list and skip flags supplied between
the mountpoint and -o.

Collect system, nokernelcrypto, headerbak, and timestamp into one
--mount-options argument. Previously, only system had a mapping to
that argument; the remaining options went to the filesystem options.

Reject the obsolete truecrypt option before invoking VeraCrypt.

Validation: 32 cases passed under both Bash and dash using a stub
executable, with comparisons against the original helper.

Signed-off-by: Ville Takio <ville+git@takio.fi>
This commit is contained in:
Ville Takio authored and GitHub committed 2026-09-30 15:06:28 +09:00
1 parent 41bc8e5f6a
commit 81cd94f18f
1 file changed
+37 -18
+37 -18
View File
@@ -1,23 +1,42 @@
#!/bin/bash
DEV="$1"
MNTPT="$2"
VCOPTIONS=""
OPTIONS=""
#!/bin/sh
# mount.veracrypt <device> <mountpoint> [flags] [-o comma-options]
DEV=$1
MNTPT=$2
MOUNTOPTS=
OPTIONS=
shift 3
IFS=','
for arg in $*; do
case "$arg" in
truecrypt) VCOPTIONS=(${VCOPTIONS[*]} --truecrypt);;
system) VCOPTIONS=(${VCOPTIONS[*]} --mount-options=system);;
fs=*) VCOPTIONS=(${VCOPTIONS[*]} --filesystem=${arg#*=});;
keyfiles=*) VCOPTIONS=(${VCOPTIONS[*]} --keyfiles=${arg#*=});;
password=*) VCOPTIONS=(${VCOPTIONS[*]} --password=${arg#*=});;
pim=*) VCOPTIONS=(${VCOPTIONS[*]} --pim=${arg#*=});;
protect-hidden=*) VCOPTIONS=(${VCOPTIONS[*]} --protect-hidden=${arg#*=});;
slot=*) VCOPTIONS=(${VCOPTIONS[*]} --slot=${arg#*=});;
shift 2
while [ "$#" -gt 0 ] && [ "$1" != "-o" ]; do shift; done
[ "$#" -gt 0 ] && shift
OLDIFS=$IFS
IFS=,
set -f
OPTSTR="$*"
# Collect veracrypt arguments as positional parameters so values with spaces
# (e.g. keyfile paths) stay single arguments.
set --
for arg in $OPTSTR; do
case $arg in
system|nokernelcrypto|headerbak|timestamp)
MOUNTOPTS="${MOUNTOPTS:+$MOUNTOPTS,}$arg" ;;
truecrypt)
echo "mount.veracrypt: TrueCrypt mode is no longer supported" >&2
exit 1 ;;
fs=*) set -- "$@" "--filesystem=${arg#*=}" ;;
keyfiles=*) set -- "$@" "--keyfiles=${arg#*=}" ;;
password=*) set -- "$@" "--password=${arg#*=}" ;;
pim=*) set -- "$@" "--pim=${arg#*=}" ;;
protect-hidden=*) set -- "$@" "--protect-hidden=${arg#*=}" ;;
slot=*) set -- "$@" "--slot=${arg#*=}" ;;
*) OPTIONS="${OPTIONS}${arg}," ;;
esac
done
IFS=$OLDIFS
set +f
/usr/bin/veracrypt --text --non-interactive ${VCOPTIONS[*]} --fs-options="${OPTIONS%,*}" ${DEV} ${MNTPT}
# veracrypt reads a single --mount-options value, so pass one comma list.
[ -n "$MOUNTOPTS" ] && set -- "$@" "--mount-options=$MOUNTOPTS"
exec /usr/bin/veracrypt --text --non-interactive "$@" \
--fs-options="${OPTIONS%,}" "$DEV" "$MNTPT"