diff options
| author | root <root@alpha.trunkmasters.com> | 2026-06-13 22:21:26 -0500 |
|---|---|---|
| committer | root <root@alpha.trunkmasters.com> | 2026-06-13 22:21:26 -0500 |
| commit | f997c3ee588099e4f43e9ec845935868e3e60b8e (patch) | |
| tree | 07f0967cda575ee2edf2d62ed8c0f67855ae6bd3 /sys-fs/cryptsetup | |
| parent | b589bc93e15b300c3e5318fe97241d57e464bea1 (diff) | |
| download | baldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.tar.gz baldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.tar.xz baldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.zip | |
Adding metadata
Diffstat (limited to 'sys-fs/cryptsetup')
| -rw-r--r-- | sys-fs/cryptsetup/Manifest | 4 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild | 106 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild | 177 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild (renamed from sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild) | 108 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd (renamed from sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd) | 9 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc (renamed from sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc) | 73 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch | 45 | ||||
| -rw-r--r-- | sys-fs/cryptsetup/metadata.xml | 14 |
8 files changed, 111 insertions, 425 deletions
diff --git a/sys-fs/cryptsetup/Manifest b/sys-fs/cryptsetup/Manifest index 53811dd4ffe4..429c718f3550 100644 --- a/sys-fs/cryptsetup/Manifest +++ b/sys-fs/cryptsetup/Manifest @@ -1,6 +1,2 @@ -DIST cryptsetup-2.8.3.tar.sign 833 BLAKE2B f03bb85dfdcc3b22ab7141478fb289fb6ff8bc2000da62a952266e47e894b611439f32456db7fb0340f124af33e05932f4ebeae1b4f985e8cb42ed58302d5f67 SHA512 893215ec657b73608ff7d97313b4f0b56126ee20a9f7cd2d5c69b844dac06a3ac5cdac470b358d3920c51afd72047012948b71200b8b2d4f437856657f82d37a -DIST cryptsetup-2.8.3.tar.xz 11863620 BLAKE2B 9559fb8cd0d916903c0e491c14f8d30a156672313065f4d58ca02a67293288831e6b5d12e843ae607c604d6a08bed46da887308a9ff87413e413b1cf7756810d SHA512 6aaf5a7e6d716e581b50fce417dad079022ff15d54e8a93697888b030b8defa03a39fd94725c3a8692cd07147573bd7f1c3c41571c488aabd44e4f9def9673e2 -DIST cryptsetup-2.8.4.tar.sign 833 BLAKE2B 22264d6a314cb14cabf1614225cc339261ec7dc44c280547a00ee552f6723243591260e0aa793330f4a2a8460840e687847d08923ab3abfea2e11d81a8e3e805 SHA512 b568ea6272960f186c83247c95c666355c44deb9be7508202ec56d0bca8dcfe660ef175f0f0792ebf9c1219f15cd3f24536dffff5e131142c1ead408a5350274 DIST cryptsetup-2.8.4.tar.xz 11880632 BLAKE2B 135721fe1daca13bf5c1116dfe9888d50e617d06f8c2c3cff60bb76ab9d2ef4f91524d8c4185c5f673290b5a7f9dcd83b9ab9c25112500fea9100e30d8a8caf0 SHA512 cf9923552f93d3ca047fa17e2d73923b782e0f5146d9721fb8e1196374185524c2642c1243ea72107aef03a0b0b9d967576a58b1a680dd9b6a17dbf4a4430489 -DIST cryptsetup-2.8.6.tar.sign 833 BLAKE2B 399d3ec4b5bce2abd4d4a3f81f4ca79867ecd12e5e1b3128cb610629ed716877cf23b42bc7c9579f977187aa62541c13df7fa371f89a962e453e3f087e1b5239 SHA512 5299d18b55c119bc80654be8868b9d111aedbe33654ccc64cb0e627d39c5265e960b406884347d4ed4129c39cc3fcd990c1861a80d7958059a17e945df769548 DIST cryptsetup-2.8.6.tar.xz 11887880 BLAKE2B 1d5ac80bbd2349f727fbb4ff1c7b85e48dbf7bc5a2cb985f23f3c4a482d44043900c0ab4b5190c2cd2d8e6037346d8ed9e1eabb19123c627498fb723776cb677 SHA512 b580e0b384a590447cf21a9d50142e7f799c3dae0fc13999886db45716f95523fa47c795335a27a7282ff1ee67eedd69989c56e6a429016aa957171fe2646d5e diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild index 688b1d8096df..db638b18b21f 100644 --- a/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild +++ b/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild @@ -1,42 +1,29 @@ -# Copyright 1999-2026 Gentoo Authors +# Copyright 2021-2026 Liguros Authors # Distributed under the terms of the GNU General Public License v2 - EAPI=8 -# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492) -VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc -inherit linux-info tmpfiles verify-sig +inherit linux-info tmpfiles DESCRIPTION="Tool to setup encrypted devices with dm-crypt" -HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup" -SRC_URI=" - https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz - verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign ) -" -S="${WORKDIR}"/${P/_/-} +HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup/blob/master/README.md" +SRC_URI="https://www.kernel.org/pub/linux/utils/cryptsetup/v$(ver_cut 1-2)/${P/_/-}.tar.xz" LICENSE="GPL-2+" SLOT="0/12" # libcryptsetup.so version -if [[ ${PV} != *_rc* ]] ; then - KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86" -fi - +[[ ${PV} != *_rc* ]] && \ +KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~loong ~mips ppc ppc64 ~riscv ~s390 sparc x86" CRYPTO_BACKENDS="gcrypt kernel nettle +openssl" # we don't support nss since it doesn't allow cryptsetup to be built statically # and it's missing ripemd160 support so it can't provide full backward compatibility -IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom" +IUSE="${CRYPTO_BACKENDS} +argon2 nls pwquality reencrypt ssh static static-libs test +udev urandom" RESTRICT="!test? ( test )" -# bug #496612, bug #832711, bug #843863 -REQUIRED_USE=" - ?? ( pwquality passwdqc ) - ^^ ( ${CRYPTO_BACKENDS//+/} ) - static? ( !ssh !udev !fips ) - static-libs? ( !passwdqc ) - fips? ( !kernel !nettle ) -" +REQUIRED_USE="^^ ( ${CRYPTO_BACKENDS//+/} ) + ? ( openssl ) + static? ( !gcrypt !ssh !udev )" LIB_DEPEND=" dev-libs/json-c:=[static-libs(+)] + dev-libs/libgpg-error[static-libs(+)] dev-libs/popt[static-libs(+)] >=sys-apps/util-linux-2.31-r1[static-libs(+)] argon2? ( app-crypt/argon2:=[static-libs(+)] ) @@ -45,31 +32,31 @@ LIB_DEPEND=" dev-libs/libgpg-error[static-libs(+)] ) nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] ) - openssl? ( dev-libs/openssl:0=[static-libs(+)] ) + openssl? ( + dev-libs/openssl:0=[static-libs(+)] + + ) pwquality? ( dev-libs/libpwquality[static-libs(+)] ) - passwdqc? ( sys-auth/passwdqc ) - ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] ) - sys-fs/lvm2[static-libs(+)] -" + ssh? ( net-libs/libssh[static-libs(+)] ) + sys-fs/lvm2[static-libs(+)]" # We have to always depend on ${LIB_DEPEND} rather than put behind # !static? () because we provide a shared library which links against -# these other packages. bug #414665 -RDEPEND=" - static-libs? ( ${LIB_DEPEND} ) +# these other packages. #414665 +RDEPEND="static-libs? ( ${LIB_DEPEND} ) ${LIB_DEPEND//\[static-libs\([+-]\)\]} - udev? ( virtual/libudev:= ) -" -DEPEND=" - ${RDEPEND} + udev? ( virtual/libudev:= )" +# vim-core needed for xxd in tests +DEPEND="${RDEPEND} static? ( ${LIB_DEPEND} ) + test? ( app-editors/vim-core ) + dev-ruby/asciidoctor " -# vim-core needed for xxd in tests BDEPEND=" virtual/pkgconfig - test? ( app-editors/vim-core ) - verify-sig? ( sec-keys/openpgp-keys-milanbroz ) " +S="${WORKDIR}/${P/_/-}" + pkg_setup() { local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256" local WARNING_DM_CRYPT="CONFIG_DM_CRYPT:\tis not set (required for cryptsetup)\n" @@ -79,25 +66,20 @@ pkg_setup() { check_extra_config } -src_unpack() { - if use verify-sig; then - verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \ - "${DISTDIR}"/${P/_/-}.tar.sign - else - default - fi -} - src_prepare() { - default - sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die + default } src_configure() { + if use kernel ; then + ewarn "Note that kernel backend is very slow for this type of operation" + ewarn "and is provided mainly for embedded systems wanting to avoid" + ewarn "userspace crypto libraries." + fi + local myeconfargs=( --disable-internal-argon2 - --disable-asciidoc --enable-shared --sbindir="${EPREFIX}"/sbin # for later use @@ -107,17 +89,16 @@ src_configure() { $(use_enable argon2 libargon2) $(use_enable nls) $(use_enable pwquality) - $(use_enable passwdqc) + $(use_enable reencrypt luks2-reencryption) $(use_enable !static external-tokens) $(use_enable static static-cryptsetup) $(use_enable static-libs static) $(use_enable udev) $(use_enable !urandom dev-random) $(use_enable ssh ssh-token) - $(usev !argon2 '--with-luks2-pbkdf=pbkdf2') - $(use_enable fips) + $(usex argon2 '' '--with-luks2-pbkdf=pbkdf2') + $(use_enable ! fips) ) - econf "${myeconfargs[@]}" } @@ -142,26 +123,21 @@ src_install() { mv "${ED}"/sbin/cryptsetup{.static,} || die mv "${ED}"/sbin/veritysetup{.static,} || die mv "${ED}"/sbin/integritysetup{.static,} || die - if use ssh ; then mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die fi + if use reencrypt ; then + mv "${ED}"/sbin/cryptsetup-reencrypt{.static,} || die + fi fi - find "${ED}" -type f -name "*.la" -delete || die dodoc docs/v*ReleaseNotes - newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt - newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt + newconfd "${FILESDIR}"/1.6.7-dmcrypt.confd dmcrypt + newinitd "${FILESDIR}"/1.6.7-dmcrypt.rc dmcrypt } pkg_postinst() { tmpfiles_process cryptsetup.conf - - if use kernel ; then - ewarn "Note that kernel backend is very slow for this type of operation" - ewarn "and is provided mainly for embedded systems wanting to avoid" - ewarn "userspace crypto libraries." - fi } diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild deleted file mode 100644 index 2fb701e205ec..000000000000 --- a/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild +++ /dev/null @@ -1,177 +0,0 @@ -# Copyright 1999-2026 Gentoo Authors -# Distributed under the terms of the GNU General Public License v2 - -EAPI=8 - -# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492) -VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc -inherit linux-info tmpfiles verify-sig - -DESCRIPTION="Tool to setup encrypted devices with dm-crypt" -HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup" -SRC_URI=" - https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz - verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign ) -" -S="${WORKDIR}"/${P/_/-} - -LICENSE="GPL-2+" -SLOT="0/12" # libcryptsetup.so version -if [[ ${PV} != *_rc* ]] ; then - KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86" -fi - -CRYPTO_BACKENDS="gcrypt kernel nettle +openssl" -# we don't support nss since it doesn't allow cryptsetup to be built statically -# and it's missing ripemd160 support so it can't provide full backward compatibility -IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom" -RESTRICT="!test? ( test )" -# bug #496612, bug #832711, bug #843863 -REQUIRED_USE=" - ?? ( pwquality passwdqc ) - ^^ ( ${CRYPTO_BACKENDS//+/} ) - static? ( !ssh !udev !fips ) - static-libs? ( !passwdqc ) - fips? ( !kernel !nettle ) -" - -LIB_DEPEND=" - dev-libs/json-c:=[static-libs(+)] - dev-libs/popt[static-libs(+)] - >=sys-apps/util-linux-2.31-r1[static-libs(+)] - argon2? ( app-crypt/argon2:=[static-libs(+)] ) - gcrypt? ( - dev-libs/libgcrypt:0=[static-libs(+)] - dev-libs/libgpg-error[static-libs(+)] - ) - nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] ) - openssl? ( dev-libs/openssl:0=[static-libs(+)] ) - pwquality? ( dev-libs/libpwquality[static-libs(+)] ) - passwdqc? ( sys-auth/passwdqc ) - ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] ) - sys-fs/lvm2[static-libs(+)] -" -# We have to always depend on ${LIB_DEPEND} rather than put behind -# !static? () because we provide a shared library which links against -# these other packages. bug #414665 -RDEPEND=" - static-libs? ( ${LIB_DEPEND} ) - ${LIB_DEPEND//\[static-libs\([+-]\)\]} - udev? ( virtual/libudev:= ) -" -DEPEND=" - ${RDEPEND} - static? ( ${LIB_DEPEND} ) -" -# vim-core needed for xxd in tests -BDEPEND=" - virtual/pkgconfig - test? ( app-editors/vim-core ) - verify-sig? ( sec-keys/openpgp-keys-milanbroz ) -" - -pkg_setup() { - local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256" - local WARNING_DM_CRYPT="CONFIG_DM_CRYPT:\tis not set (required for cryptsetup)\n" - local WARNING_CRYPTO_SHA256="CONFIG_CRYPTO_SHA256:\tis not set (required for cryptsetup)\n" - local WARNING_CRYPTO_CBC="CONFIG_CRYPTO_CBC:\tis not set (required for kernel 2.6.19)\n" - local WARNING_CRYPTO="CONFIG_CRYPTO:\tis not set (required for cryptsetup)\n" - - # The kernel crypto backend talks to the in-kernel crypto API via AF_ALG - if use kernel ; then - CONFIG_CHECK+=" ~CRYPTO_USER_API ~CRYPTO_USER_API_HASH ~CRYPTO_USER_API_SKCIPHER" - local WARNING_CRYPTO_USER_API="CONFIG_CRYPTO_USER_API:\tis not set (required for the kernel crypto backend)\n" - local WARNING_CRYPTO_USER_API_HASH="CONFIG_CRYPTO_USER_API_HASH:\tis not set (required for the kernel crypto backend)\n" - local WARNING_CRYPTO_USER_API_SKCIPHER="CONFIG_CRYPTO_USER_API_SKCIPHER:\tis not set (required for the kernel crypto backend)\n" - fi - check_extra_config -} - -src_unpack() { - if use verify-sig; then - verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \ - "${DISTDIR}"/${P/_/-}.tar.sign - else - default - fi -} - -src_prepare() { - default - - sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die -} - -src_configure() { - # configure may search for libselinux but it seems to only be for - # statically linking lvm2 - local myeconfargs=( - --disable-internal-argon2 - --disable-asciidoc - --enable-shared - --sbindir="${EPREFIX}"/sbin - # for later use - --with-default-luks-format=LUKS2 - --with-tmpfilesdir="${EPREFIX}/usr/lib/tmpfiles.d" - --with-crypto_backend=$(for x in ${CRYPTO_BACKENDS//+/} ; do usev ${x} ; done) - $(use_enable argon2 libargon2) - $(use_enable nls) - $(use_enable pwquality) - $(use_enable passwdqc) - $(use_enable !static external-tokens) - $(use_enable static static-cryptsetup) - $(use_enable static-libs static) - $(use_enable udev) - $(use_enable !urandom dev-random) - $(use_enable ssh ssh-token) - $(usev !argon2 '--with-luks2-pbkdf=pbkdf2') - $(use_enable fips) - ) - - econf "${myeconfargs[@]}" -} - -src_test() { - if [[ ! -e /dev/mapper/control ]] ; then - ewarn "No /dev/mapper/control found -- skipping tests" - return 0 - fi - - local p - for p in /dev/mapper /dev/loop* ; do - addwrite ${p} - done - - default -} - -src_install() { - default - - if use static ; then - mv "${ED}"/sbin/cryptsetup{.static,} || die - mv "${ED}"/sbin/veritysetup{.static,} || die - mv "${ED}"/sbin/integritysetup{.static,} || die - - if use ssh ; then - mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die - fi - fi - - find "${ED}" -type f -name "*.la" -delete || die - - dodoc docs/v*ReleaseNotes - - newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt - newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt -} - -pkg_postinst() { - tmpfiles_process cryptsetup.conf - - if use kernel ; then - ewarn "Note that kernel backend is very slow for this type of operation" - ewarn "and is provided mainly for embedded systems wanting to avoid" - ewarn "userspace crypto libraries." - fi -} diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild index 0c0908160273..db638b18b21f 100644 --- a/sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild +++ b/sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild @@ -1,42 +1,29 @@ -# Copyright 1999-2026 Gentoo Authors +# Copyright 2021-2026 Liguros Authors # Distributed under the terms of the GNU General Public License v2 - EAPI=8 -# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492) -VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc -inherit linux-info tmpfiles verify-sig +inherit linux-info tmpfiles DESCRIPTION="Tool to setup encrypted devices with dm-crypt" -HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup" -SRC_URI=" - https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz - verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign ) -" -S="${WORKDIR}"/${P/_/-} +HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup/blob/master/README.md" +SRC_URI="https://www.kernel.org/pub/linux/utils/cryptsetup/v$(ver_cut 1-2)/${P/_/-}.tar.xz" LICENSE="GPL-2+" SLOT="0/12" # libcryptsetup.so version -if [[ ${PV} != *_rc* ]] ; then - KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86" -fi - +[[ ${PV} != *_rc* ]] && \ +KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~loong ~mips ppc ppc64 ~riscv ~s390 sparc x86" CRYPTO_BACKENDS="gcrypt kernel nettle +openssl" # we don't support nss since it doesn't allow cryptsetup to be built statically # and it's missing ripemd160 support so it can't provide full backward compatibility -IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom" +IUSE="${CRYPTO_BACKENDS} +argon2 nls pwquality reencrypt ssh static static-libs test +udev urandom" RESTRICT="!test? ( test )" -# bug #496612, bug #832711, bug #843863 -REQUIRED_USE=" - ?? ( pwquality passwdqc ) - ^^ ( ${CRYPTO_BACKENDS//+/} ) - static? ( !ssh !udev !fips ) - static-libs? ( !passwdqc ) - fips? ( !kernel !nettle ) -" +REQUIRED_USE="^^ ( ${CRYPTO_BACKENDS//+/} ) + ? ( openssl ) + static? ( !gcrypt !ssh !udev )" LIB_DEPEND=" dev-libs/json-c:=[static-libs(+)] + dev-libs/libgpg-error[static-libs(+)] dev-libs/popt[static-libs(+)] >=sys-apps/util-linux-2.31-r1[static-libs(+)] argon2? ( app-crypt/argon2:=[static-libs(+)] ) @@ -45,34 +32,30 @@ LIB_DEPEND=" dev-libs/libgpg-error[static-libs(+)] ) nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] ) - openssl? ( dev-libs/openssl:0=[static-libs(+)] ) + openssl? ( + dev-libs/openssl:0=[static-libs(+)] + + ) pwquality? ( dev-libs/libpwquality[static-libs(+)] ) - passwdqc? ( sys-auth/passwdqc ) - ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] ) - sys-fs/lvm2[static-libs(+)] -" + ssh? ( net-libs/libssh[static-libs(+)] ) + sys-fs/lvm2[static-libs(+)]" # We have to always depend on ${LIB_DEPEND} rather than put behind # !static? () because we provide a shared library which links against -# these other packages. bug #414665 -RDEPEND=" - static-libs? ( ${LIB_DEPEND} ) +# these other packages. #414665 +RDEPEND="static-libs? ( ${LIB_DEPEND} ) ${LIB_DEPEND//\[static-libs\([+-]\)\]} - udev? ( virtual/libudev:= ) -" -DEPEND=" - ${RDEPEND} + udev? ( virtual/libudev:= )" +# vim-core needed for xxd in tests +DEPEND="${RDEPEND} static? ( ${LIB_DEPEND} ) + test? ( app-editors/vim-core ) + dev-ruby/asciidoctor " -# vim-core needed for xxd in tests BDEPEND=" virtual/pkgconfig - test? ( app-editors/vim-core ) - verify-sig? ( sec-keys/openpgp-keys-milanbroz ) " -PATCHES=( - "${FILESDIR}/cryptsetup-2.8.3-bitlocker.patch" -) +S="${WORKDIR}/${P/_/-}" pkg_setup() { local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256" @@ -83,25 +66,20 @@ pkg_setup() { check_extra_config } -src_unpack() { - if use verify-sig; then - verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \ - "${DISTDIR}"/${P/_/-}.tar.sign - else - default - fi -} - src_prepare() { - default - sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die + default } src_configure() { + if use kernel ; then + ewarn "Note that kernel backend is very slow for this type of operation" + ewarn "and is provided mainly for embedded systems wanting to avoid" + ewarn "userspace crypto libraries." + fi + local myeconfargs=( --disable-internal-argon2 - --disable-asciidoc --enable-shared --sbindir="${EPREFIX}"/sbin # for later use @@ -111,17 +89,16 @@ src_configure() { $(use_enable argon2 libargon2) $(use_enable nls) $(use_enable pwquality) - $(use_enable passwdqc) + $(use_enable reencrypt luks2-reencryption) $(use_enable !static external-tokens) $(use_enable static static-cryptsetup) $(use_enable static-libs static) $(use_enable udev) $(use_enable !urandom dev-random) $(use_enable ssh ssh-token) - $(usev !argon2 '--with-luks2-pbkdf=pbkdf2') - $(use_enable fips) + $(usex argon2 '' '--with-luks2-pbkdf=pbkdf2') + $(use_enable ! fips) ) - econf "${myeconfargs[@]}" } @@ -146,26 +123,21 @@ src_install() { mv "${ED}"/sbin/cryptsetup{.static,} || die mv "${ED}"/sbin/veritysetup{.static,} || die mv "${ED}"/sbin/integritysetup{.static,} || die - if use ssh ; then mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die fi + if use reencrypt ; then + mv "${ED}"/sbin/cryptsetup-reencrypt{.static,} || die + fi fi - find "${ED}" -type f -name "*.la" -delete || die dodoc docs/v*ReleaseNotes - newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt - newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt + newconfd "${FILESDIR}"/1.6.7-dmcrypt.confd dmcrypt + newinitd "${FILESDIR}"/1.6.7-dmcrypt.rc dmcrypt } pkg_postinst() { tmpfiles_process cryptsetup.conf - - if use kernel ; then - ewarn "Note that kernel backend is very slow for this type of operation" - ewarn "and is provided mainly for embedded systems wanting to avoid" - ewarn "userspace crypto libraries." - fi } diff --git a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd index 8250e8268ac9..642ff087078b 100644 --- a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd +++ b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd @@ -44,7 +44,6 @@ dmcrypt_retries=5 # for blkid (see -t option). This is safer than using # the full path to the device. # key='</path/to/keyfile>[:<mode>]' == Fullpath from / or from inside removable media. -# header='</path/to/header>' == Full path to detached LUKS header file. # remdev='<dev>' == Device that will be assigned to removable media. # gpg_options='<opts>' == Default are --quiet --decrypt # options='<opts>' == cryptsetup, for LUKS you can only use --readonly @@ -53,8 +52,6 @@ dmcrypt_retries=5 # be looked up automatically. # pre_mount='cmds' == commands to execute before mounting partition. # post_mount='cmds' == commands to execute after mounting partition. -# wait=5 == wait given amount of seconds for source or -# detached header file appear. #----------- # Supported Modes # gpg == decrypt and pipe key into cryptsetup. @@ -82,12 +79,6 @@ dmcrypt_retries=5 #source='/dev/hda5' #key='/full/path/to/homekey' -## /home with regular keyfile and detached header -#target=crypt-home -#source='/dev/hda5' -#key='/full/path/to/homekey' -#header='/full/path/to/header/file' - ## /home with gpg protected key #target=crypt-home #source='/dev/hda5' diff --git a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc index ea9a5ca4807b..d4fe6030355f 100644 --- a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc +++ b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc @@ -3,9 +3,7 @@ # Distributed under the terms of the GNU General Public License v2 depend() { - use modules before checkfs fsck - after dev-settle if grep -qs ^swap= "${conf_file}" ; then before swap @@ -23,7 +21,7 @@ fi # Setup mappings for an individual target/swap # Note: This relies on variables localized in the main body below. dm_crypt_execute() { - local dev ret mode foo source_dev + local dev ret mode foo if [ -z "${target}" -a -z "${swap}" ] ; then return @@ -33,7 +31,6 @@ dm_crypt_execute() { : ${dmcrypt_key_timeout:=1} : ${dmcrypt_max_timeout:=300} : ${dmcrypt_retries:=5} - : ${wait:=5} # Handle automatic look up of the source path. if [ -z "${source}" -a -n "${loop_file}" ] ; then @@ -41,16 +38,7 @@ dm_crypt_execute() { fi case ${source} in *=*) - i=0 - while [ ${i} -lt ${wait} ]; do - if source_dev="$(blkid -l -t "${source}" -o device)"; then - source="${source_dev}" - break - fi - : $((i += 1)) - einfo "waiting for source \"${source}\" for ${target}..." - sleep 1 - done + source=$(blkid -l -t "${source}" -o device) ;; esac if [ -z "${source}" ] || [ ! -e "${source}" ] ; then @@ -58,28 +46,11 @@ dm_crypt_execute() { return fi - if [ -n "${header}" ] ; then - header_opt="--header=${header}" - - i=0 - while [ ! -e "${header}" ] && [ ${i} -lt ${wait} ] ; do - : $((i += 1)) - einfo "Waiting for header ${header} to appear for ${target} ${i}/${dmcrypt_max_timeout} ..." - sleep 1 - done - if [ ${i} -gt ${wait} ] || [ ${i} -eq ${wait} ] ; then - ewarn "Waited ${i} times for header file ${header}. Aborting ${target}." - return - fi - else - header_opt="" - fi - if [ -n "${target}" ] ; then # let user set options, otherwise leave empty : ${options:=' '} elif [ -n "${swap}" ] ; then - if cryptsetup ${header_opt} isLuks ${source} 2>/dev/null ; then + if cryptsetup isLuks ${source} 2>/dev/null ; then ewarn "The swap you have defined is a LUKS partition. Aborting crypt-swap setup." return fi @@ -100,7 +71,7 @@ dm_crypt_execute() { # open <device> <name> # <device> is $source # create <name> <device> # <name> is $target local arg1="create" arg2="${target}" arg3="${source}" - if cryptsetup ${header_opt} isLuks ${source} 2>/dev/null ; then + if cryptsetup isLuks ${source} 2>/dev/null ; then arg1="open" arg2="${source}" arg3="${target}" @@ -110,7 +81,7 @@ dm_crypt_execute() { # ${target} is active: # Newer versions report: # ${target} is active[ and is in use.] - if cryptsetup ${header_opt} status ${target} | grep -E -q ' is active' ; then + if cryptsetup status ${target} | grep -E -q ' is active' ; then einfo "dm-crypt mapping ${target} is already configured" return fi @@ -200,7 +171,7 @@ dm_crypt_execute() { else mode=none fi - ebegin " ${target} using: ${header_opt} ${options} ${arg1} ${arg2} ${arg3}" + ebegin " ${target} using: ${options} ${arg1} ${arg2} ${arg3}" if [ "${mode}" = "gpg" ] ; then : ${gpg_options:='-q -d'} # gpg available ? @@ -210,7 +181,7 @@ dm_crypt_execute() { # paranoid, don't store key in a variable, pipe it so it stays very little in ram unprotected. # save stdin stdout stderr "values" timeout ${dmcrypt_max_timeout} gpg ${gpg_options} ${key} 2>/dev/null | \ - cryptsetup ${header_opt} --key-file - ${options} ${arg1} ${arg2} ${arg3} + cryptsetup --key-file - ${options} ${arg1} ${arg2} ${arg3} ret=$? # The timeout command exits 124 when it times out. [ ${ret} -eq 0 -o ${ret} -eq 124 ] && break @@ -225,11 +196,11 @@ dm_crypt_execute() { fi else if [ "${mode}" = "reg" ] ; then - cryptsetup ${header_opt} ${options} -d ${key} ${arg1} ${arg2} ${arg3} + cryptsetup ${options} -d ${key} ${arg1} ${arg2} ${arg3} ret=$? eend ${ret} "failure running cryptsetup" else - cryptsetup ${header_opt} ${options} ${arg1} ${arg2} ${arg3} + cryptsetup ${options} ${arg1} ${arg2} ${arg3} ret=$? eend ${ret} "failure running cryptsetup" fi @@ -265,7 +236,7 @@ get_bootparam_val() { } start() { - local print_header=true cryptfs_status=0 + local header=true cryptfs_status=0 local gpg_options key loop_file target targetline options pre_mount post_mount source swap remdev local x @@ -285,8 +256,8 @@ start() { rc_*) continue ;; esac - ${print_header} && ebegin "Setting up dm-crypt mappings" - print_header=false + ${header} && ebegin "Setting up dm-crypt mappings" + header=false # check for the start of a new target/swap case ${targetline} in @@ -295,10 +266,10 @@ start() { dm_crypt_execute # Prepare for the next target/swap by resetting variables - unset gpg_options key loop_file target options pre_mount post_mount source swap remdev wait header header_opt + unset gpg_options key loop_file target options pre_mount post_mount source swap remdev ;; - gpg_options=*|remdev=*|key=*|loop_file=*|options=*|pre_mount=*|post_mount=*|wait=*|source=*|header=*) + gpg_options=*|remdev=*|key=*|loop_file=*|options=*|pre_mount=*|post_mount=*|source=*) if [ -z "${target}${swap}" ] ; then ewarn "Ignoring setting outside target/swap section: ${targetline}" continue @@ -326,14 +297,14 @@ start() { } stop() { - local line print_header + local line header # Break down all mappings - print_header=true + header=true grep -E "^(target|swap)=" ${conf_file} | \ while read line ; do - ${print_header} && einfo "Removing dm-crypt mappings" - print_header=false + ${header} && einfo "Removing dm-crypt mappings" + header=false target= swap= eval ${line} @@ -345,16 +316,16 @@ stop() { fi ebegin " ${target}" - cryptsetup ${header_opt} remove ${target} + cryptsetup remove ${target} eend $? done # Break down loop devices - print_header=true + header=true grep '^source=./dev/loop' ${conf_file} | \ while read line ; do - ${print_header} && einfo "Detaching dm-crypt loop devices" - print_header=false + ${header} && einfo "Detaching dm-crypt loop devices" + header=false source= eval ${line} diff --git a/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch b/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch deleted file mode 100644 index a6ca2652cd82..000000000000 --- a/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch +++ /dev/null @@ -1,45 +0,0 @@ -https://bugs.gentoo.org/969153 -https://gitlab.com/cryptsetup/cryptsetup/-/issues/973 -https://gitlab.com/cryptsetup/cryptsetup/-/merge_requests/883 - -From 4eb729da3f46642d6fe1fabbbedb127078eccb95 Mon Sep 17 00:00:00 2001 -From: Vojtech Trefny <vtrefny@redhat.com> -Date: Sun, 11 Jan 2026 14:31:29 +0100 -Subject: [PATCH] bitlk: Do not try to use empty password for password keyslots - -Passing empty password means we want to try to open the device -using the clear key so we can skip all other keyslots in this case. - -This also fixes unlocking a BitLocker device where recovery -passphrase is in the first keyslot where we try to use the empty -passhrase first, hoping for a clear key, and never actually prompt -user for an actual (recovery) passphrase after. - -Fixes: #973 ---- - lib/bitlk/bitlk.c | 11 +++++++++++ - tests/bitlk-images.tar.xz | Bin 355720 -> 376840 bytes - 2 files changed, 11 insertions(+) - -diff --git a/lib/bitlk/bitlk.c b/lib/bitlk/bitlk.c -index 3b7b093d..0e8f9d1d 100644 ---- a/lib/bitlk/bitlk.c -+++ b/lib/bitlk/bitlk.c -@@ -1300,6 +1300,17 @@ int BITLK_get_volume_key(struct crypt_device *cd, - next_vmk = params->vmks; - while (next_vmk) { - bool is_decrypted = false; -+ -+ if (password == NULL && next_vmk->protection != BITLK_PROTECTION_CLEAR_KEY) { -+ /* -+ * Clearkey is the only slot that doesn't require password so no password -+ * means we are trying to use clearkey and we can skip all other key slots. -+ */ -+ r = -EPERM; -+ next_vmk = next_vmk->next; -+ continue; -+ } -+ - if (next_vmk->protection == BITLK_PROTECTION_PASSPHRASE) { - r = bitlk_kdf(password, passwordLen, false, next_vmk->salt, &vmk_dec_key); - if (r) { diff --git a/sys-fs/cryptsetup/metadata.xml b/sys-fs/cryptsetup/metadata.xml index 66fef2269d6f..252353aa5edd 100644 --- a/sys-fs/cryptsetup/metadata.xml +++ b/sys-fs/cryptsetup/metadata.xml @@ -2,24 +2,26 @@ <!DOCTYPE pkgmetadata SYSTEM "https://docs.baldeagleos.com/dtd/metadata.dtd"> <pkgmetadata> <maintainer type="project"> + <email>dev@liguros.net</email> + <name>Development</name> + </maintainer> + <maintainer type="project"> <email>base-system@gentoo.org</email> <name>Gentoo Base System</name> </maintainer> + <upstream> + <remote-id type="cpe">cpe:/a:cryptsetup_project:cryptsetup</remote-id> + </upstream> <use> <flag name="argon2">Enable password hashing algorithm from <pkg>app-crypt/argon2</pkg> </flag> - <flag name="fips">Enable FIPS mode restrictions</flag> <flag name="gcrypt">Use <pkg>dev-libs/libgcrypt</pkg> crypto backend</flag> <flag name="kernel">Use kernel crypto backend (mainly for embedded systems)</flag> <flag name="nettle">Use <pkg>dev-libs/nettle</pkg> crypto backend</flag> <flag name="openssl">Use <pkg>dev-libs/openssl</pkg> crypto backend</flag> <flag name="pwquality">Use <pkg>dev-libs/libpwquality</pkg> for password quality checking</flag> - <flag name="passwdqc">Use <pkg>sys-auth/passwdqc</pkg> for password quality checking</flag> - <flag name="ssh">Build cryptsetup-ssh for experimental support of token via SSH-server</flag> <flag name="urandom">Use /dev/urandom instead of /dev/random</flag> + <flag name="reencrypt">Build cryptsetup-reencrypt</flag> </use> - <upstream> - <remote-id type="cpe">cpe:/a:cryptsetup_project:cryptsetup</remote-id> - </upstream> <origin>baldeagleos-repo</origin> </pkgmetadata> |
