mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-10-05 16:46:35 -05:00
Handle protection failures before outer-password retries, retain cached and explicit outer credentials without adding default keyfiles, and focus the hidden-protection controls. Initialize hidden PIM and KDF independently, and retain an accepted backup header during protection recovery. Retry embedded backup headers after repeated hidden-protection failures without advancing the outer-password retry count. Restore the accepted primary-header selection if backup authentication fails, and report automatic backup use only when the selected header remains a backup. Keep primary-header recovery available after an automatic backup attempt fails with EIO, while reporting the error. Preserve cancellation and other error handling. Pass known protection failures from favorite mounts directly into GUI recovery, including keyfile-only credentials with a null password. Skip redundant authentication attempts and preserve the text interface's existing retry path. Initialize the backup-header checkbox with the other validated controls, so an initial backup-header request survives the first password prompt. Conceal the accepted outer password and PIM before disabling their controls during protection recovery.