summaryrefslogtreecommitdiff
path: root/sys-fs/cryptsetup
diff options
context:
space:
mode:
authorroot <root@alpha.trunkmasters.com>2026-06-13 22:21:26 -0500
committerroot <root@alpha.trunkmasters.com>2026-06-13 22:21:26 -0500
commitf997c3ee588099e4f43e9ec845935868e3e60b8e (patch)
tree07f0967cda575ee2edf2d62ed8c0f67855ae6bd3 /sys-fs/cryptsetup
parentb589bc93e15b300c3e5318fe97241d57e464bea1 (diff)
downloadbaldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.tar.gz
baldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.tar.xz
baldeagleos-repo-f997c3ee588099e4f43e9ec845935868e3e60b8e.zip
Adding metadata
Diffstat (limited to 'sys-fs/cryptsetup')
-rw-r--r--sys-fs/cryptsetup/Manifest4
-rw-r--r--sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild106
-rw-r--r--sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild177
-rw-r--r--sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild (renamed from sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild)108
-rw-r--r--sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd (renamed from sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd)9
-rw-r--r--sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc (renamed from sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc)73
-rw-r--r--sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch45
-rw-r--r--sys-fs/cryptsetup/metadata.xml14
8 files changed, 111 insertions, 425 deletions
diff --git a/sys-fs/cryptsetup/Manifest b/sys-fs/cryptsetup/Manifest
index 53811dd4ffe4..429c718f3550 100644
--- a/sys-fs/cryptsetup/Manifest
+++ b/sys-fs/cryptsetup/Manifest
@@ -1,6 +1,2 @@
-DIST cryptsetup-2.8.3.tar.sign 833 BLAKE2B f03bb85dfdcc3b22ab7141478fb289fb6ff8bc2000da62a952266e47e894b611439f32456db7fb0340f124af33e05932f4ebeae1b4f985e8cb42ed58302d5f67 SHA512 893215ec657b73608ff7d97313b4f0b56126ee20a9f7cd2d5c69b844dac06a3ac5cdac470b358d3920c51afd72047012948b71200b8b2d4f437856657f82d37a
-DIST cryptsetup-2.8.3.tar.xz 11863620 BLAKE2B 9559fb8cd0d916903c0e491c14f8d30a156672313065f4d58ca02a67293288831e6b5d12e843ae607c604d6a08bed46da887308a9ff87413e413b1cf7756810d SHA512 6aaf5a7e6d716e581b50fce417dad079022ff15d54e8a93697888b030b8defa03a39fd94725c3a8692cd07147573bd7f1c3c41571c488aabd44e4f9def9673e2
-DIST cryptsetup-2.8.4.tar.sign 833 BLAKE2B 22264d6a314cb14cabf1614225cc339261ec7dc44c280547a00ee552f6723243591260e0aa793330f4a2a8460840e687847d08923ab3abfea2e11d81a8e3e805 SHA512 b568ea6272960f186c83247c95c666355c44deb9be7508202ec56d0bca8dcfe660ef175f0f0792ebf9c1219f15cd3f24536dffff5e131142c1ead408a5350274
DIST cryptsetup-2.8.4.tar.xz 11880632 BLAKE2B 135721fe1daca13bf5c1116dfe9888d50e617d06f8c2c3cff60bb76ab9d2ef4f91524d8c4185c5f673290b5a7f9dcd83b9ab9c25112500fea9100e30d8a8caf0 SHA512 cf9923552f93d3ca047fa17e2d73923b782e0f5146d9721fb8e1196374185524c2642c1243ea72107aef03a0b0b9d967576a58b1a680dd9b6a17dbf4a4430489
-DIST cryptsetup-2.8.6.tar.sign 833 BLAKE2B 399d3ec4b5bce2abd4d4a3f81f4ca79867ecd12e5e1b3128cb610629ed716877cf23b42bc7c9579f977187aa62541c13df7fa371f89a962e453e3f087e1b5239 SHA512 5299d18b55c119bc80654be8868b9d111aedbe33654ccc64cb0e627d39c5265e960b406884347d4ed4129c39cc3fcd990c1861a80d7958059a17e945df769548
DIST cryptsetup-2.8.6.tar.xz 11887880 BLAKE2B 1d5ac80bbd2349f727fbb4ff1c7b85e48dbf7bc5a2cb985f23f3c4a482d44043900c0ab4b5190c2cd2d8e6037346d8ed9e1eabb19123c627498fb723776cb677 SHA512 b580e0b384a590447cf21a9d50142e7f799c3dae0fc13999886db45716f95523fa47c795335a27a7282ff1ee67eedd69989c56e6a429016aa957171fe2646d5e
diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild
index 688b1d8096df..db638b18b21f 100644
--- a/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild
+++ b/sys-fs/cryptsetup/cryptsetup-2.8.4.ebuild
@@ -1,42 +1,29 @@
-# Copyright 1999-2026 Gentoo Authors
+# Copyright 2021-2026 Liguros Authors
# Distributed under the terms of the GNU General Public License v2
-
EAPI=8
-# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492)
-VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc
-inherit linux-info tmpfiles verify-sig
+inherit linux-info tmpfiles
DESCRIPTION="Tool to setup encrypted devices with dm-crypt"
-HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup"
-SRC_URI="
- https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz
- verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign )
-"
-S="${WORKDIR}"/${P/_/-}
+HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup/blob/master/README.md"
+SRC_URI="https://www.kernel.org/pub/linux/utils/cryptsetup/v$(ver_cut 1-2)/${P/_/-}.tar.xz"
LICENSE="GPL-2+"
SLOT="0/12" # libcryptsetup.so version
-if [[ ${PV} != *_rc* ]] ; then
- KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86"
-fi
-
+[[ ${PV} != *_rc* ]] && \
+KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~loong ~mips ppc ppc64 ~riscv ~s390 sparc x86"
CRYPTO_BACKENDS="gcrypt kernel nettle +openssl"
# we don't support nss since it doesn't allow cryptsetup to be built statically
# and it's missing ripemd160 support so it can't provide full backward compatibility
-IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom"
+IUSE="${CRYPTO_BACKENDS} +argon2 nls pwquality reencrypt ssh static static-libs test +udev urandom"
RESTRICT="!test? ( test )"
-# bug #496612, bug #832711, bug #843863
-REQUIRED_USE="
- ?? ( pwquality passwdqc )
- ^^ ( ${CRYPTO_BACKENDS//+/} )
- static? ( !ssh !udev !fips )
- static-libs? ( !passwdqc )
- fips? ( !kernel !nettle )
-"
+REQUIRED_USE="^^ ( ${CRYPTO_BACKENDS//+/} )
+ ? ( openssl )
+ static? ( !gcrypt !ssh !udev )"
LIB_DEPEND="
dev-libs/json-c:=[static-libs(+)]
+ dev-libs/libgpg-error[static-libs(+)]
dev-libs/popt[static-libs(+)]
>=sys-apps/util-linux-2.31-r1[static-libs(+)]
argon2? ( app-crypt/argon2:=[static-libs(+)] )
@@ -45,31 +32,31 @@ LIB_DEPEND="
dev-libs/libgpg-error[static-libs(+)]
)
nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] )
- openssl? ( dev-libs/openssl:0=[static-libs(+)] )
+ openssl? (
+ dev-libs/openssl:0=[static-libs(+)]
+
+ )
pwquality? ( dev-libs/libpwquality[static-libs(+)] )
- passwdqc? ( sys-auth/passwdqc )
- ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] )
- sys-fs/lvm2[static-libs(+)]
-"
+ ssh? ( net-libs/libssh[static-libs(+)] )
+ sys-fs/lvm2[static-libs(+)]"
# We have to always depend on ${LIB_DEPEND} rather than put behind
# !static? () because we provide a shared library which links against
-# these other packages. bug #414665
-RDEPEND="
- static-libs? ( ${LIB_DEPEND} )
+# these other packages. #414665
+RDEPEND="static-libs? ( ${LIB_DEPEND} )
${LIB_DEPEND//\[static-libs\([+-]\)\]}
- udev? ( virtual/libudev:= )
-"
-DEPEND="
- ${RDEPEND}
+ udev? ( virtual/libudev:= )"
+# vim-core needed for xxd in tests
+DEPEND="${RDEPEND}
static? ( ${LIB_DEPEND} )
+ test? ( app-editors/vim-core )
+ dev-ruby/asciidoctor
"
-# vim-core needed for xxd in tests
BDEPEND="
virtual/pkgconfig
- test? ( app-editors/vim-core )
- verify-sig? ( sec-keys/openpgp-keys-milanbroz )
"
+S="${WORKDIR}/${P/_/-}"
+
pkg_setup() {
local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256"
local WARNING_DM_CRYPT="CONFIG_DM_CRYPT:\tis not set (required for cryptsetup)\n"
@@ -79,25 +66,20 @@ pkg_setup() {
check_extra_config
}
-src_unpack() {
- if use verify-sig; then
- verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \
- "${DISTDIR}"/${P/_/-}.tar.sign
- else
- default
- fi
-}
-
src_prepare() {
- default
-
sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die
+ default
}
src_configure() {
+ if use kernel ; then
+ ewarn "Note that kernel backend is very slow for this type of operation"
+ ewarn "and is provided mainly for embedded systems wanting to avoid"
+ ewarn "userspace crypto libraries."
+ fi
+
local myeconfargs=(
--disable-internal-argon2
- --disable-asciidoc
--enable-shared
--sbindir="${EPREFIX}"/sbin
# for later use
@@ -107,17 +89,16 @@ src_configure() {
$(use_enable argon2 libargon2)
$(use_enable nls)
$(use_enable pwquality)
- $(use_enable passwdqc)
+ $(use_enable reencrypt luks2-reencryption)
$(use_enable !static external-tokens)
$(use_enable static static-cryptsetup)
$(use_enable static-libs static)
$(use_enable udev)
$(use_enable !urandom dev-random)
$(use_enable ssh ssh-token)
- $(usev !argon2 '--with-luks2-pbkdf=pbkdf2')
- $(use_enable fips)
+ $(usex argon2 '' '--with-luks2-pbkdf=pbkdf2')
+ $(use_enable ! fips)
)
-
econf "${myeconfargs[@]}"
}
@@ -142,26 +123,21 @@ src_install() {
mv "${ED}"/sbin/cryptsetup{.static,} || die
mv "${ED}"/sbin/veritysetup{.static,} || die
mv "${ED}"/sbin/integritysetup{.static,} || die
-
if use ssh ; then
mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die
fi
+ if use reencrypt ; then
+ mv "${ED}"/sbin/cryptsetup-reencrypt{.static,} || die
+ fi
fi
-
find "${ED}" -type f -name "*.la" -delete || die
dodoc docs/v*ReleaseNotes
- newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt
- newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt
+ newconfd "${FILESDIR}"/1.6.7-dmcrypt.confd dmcrypt
+ newinitd "${FILESDIR}"/1.6.7-dmcrypt.rc dmcrypt
}
pkg_postinst() {
tmpfiles_process cryptsetup.conf
-
- if use kernel ; then
- ewarn "Note that kernel backend is very slow for this type of operation"
- ewarn "and is provided mainly for embedded systems wanting to avoid"
- ewarn "userspace crypto libraries."
- fi
}
diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild
deleted file mode 100644
index 2fb701e205ec..000000000000
--- a/sys-fs/cryptsetup/cryptsetup-2.8.6-r1.ebuild
+++ /dev/null
@@ -1,177 +0,0 @@
-# Copyright 1999-2026 Gentoo Authors
-# Distributed under the terms of the GNU General Public License v2
-
-EAPI=8
-
-# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492)
-VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc
-inherit linux-info tmpfiles verify-sig
-
-DESCRIPTION="Tool to setup encrypted devices with dm-crypt"
-HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup"
-SRC_URI="
- https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz
- verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign )
-"
-S="${WORKDIR}"/${P/_/-}
-
-LICENSE="GPL-2+"
-SLOT="0/12" # libcryptsetup.so version
-if [[ ${PV} != *_rc* ]] ; then
- KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86"
-fi
-
-CRYPTO_BACKENDS="gcrypt kernel nettle +openssl"
-# we don't support nss since it doesn't allow cryptsetup to be built statically
-# and it's missing ripemd160 support so it can't provide full backward compatibility
-IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom"
-RESTRICT="!test? ( test )"
-# bug #496612, bug #832711, bug #843863
-REQUIRED_USE="
- ?? ( pwquality passwdqc )
- ^^ ( ${CRYPTO_BACKENDS//+/} )
- static? ( !ssh !udev !fips )
- static-libs? ( !passwdqc )
- fips? ( !kernel !nettle )
-"
-
-LIB_DEPEND="
- dev-libs/json-c:=[static-libs(+)]
- dev-libs/popt[static-libs(+)]
- >=sys-apps/util-linux-2.31-r1[static-libs(+)]
- argon2? ( app-crypt/argon2:=[static-libs(+)] )
- gcrypt? (
- dev-libs/libgcrypt:0=[static-libs(+)]
- dev-libs/libgpg-error[static-libs(+)]
- )
- nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] )
- openssl? ( dev-libs/openssl:0=[static-libs(+)] )
- pwquality? ( dev-libs/libpwquality[static-libs(+)] )
- passwdqc? ( sys-auth/passwdqc )
- ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] )
- sys-fs/lvm2[static-libs(+)]
-"
-# We have to always depend on ${LIB_DEPEND} rather than put behind
-# !static? () because we provide a shared library which links against
-# these other packages. bug #414665
-RDEPEND="
- static-libs? ( ${LIB_DEPEND} )
- ${LIB_DEPEND//\[static-libs\([+-]\)\]}
- udev? ( virtual/libudev:= )
-"
-DEPEND="
- ${RDEPEND}
- static? ( ${LIB_DEPEND} )
-"
-# vim-core needed for xxd in tests
-BDEPEND="
- virtual/pkgconfig
- test? ( app-editors/vim-core )
- verify-sig? ( sec-keys/openpgp-keys-milanbroz )
-"
-
-pkg_setup() {
- local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256"
- local WARNING_DM_CRYPT="CONFIG_DM_CRYPT:\tis not set (required for cryptsetup)\n"
- local WARNING_CRYPTO_SHA256="CONFIG_CRYPTO_SHA256:\tis not set (required for cryptsetup)\n"
- local WARNING_CRYPTO_CBC="CONFIG_CRYPTO_CBC:\tis not set (required for kernel 2.6.19)\n"
- local WARNING_CRYPTO="CONFIG_CRYPTO:\tis not set (required for cryptsetup)\n"
-
- # The kernel crypto backend talks to the in-kernel crypto API via AF_ALG
- if use kernel ; then
- CONFIG_CHECK+=" ~CRYPTO_USER_API ~CRYPTO_USER_API_HASH ~CRYPTO_USER_API_SKCIPHER"
- local WARNING_CRYPTO_USER_API="CONFIG_CRYPTO_USER_API:\tis not set (required for the kernel crypto backend)\n"
- local WARNING_CRYPTO_USER_API_HASH="CONFIG_CRYPTO_USER_API_HASH:\tis not set (required for the kernel crypto backend)\n"
- local WARNING_CRYPTO_USER_API_SKCIPHER="CONFIG_CRYPTO_USER_API_SKCIPHER:\tis not set (required for the kernel crypto backend)\n"
- fi
- check_extra_config
-}
-
-src_unpack() {
- if use verify-sig; then
- verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \
- "${DISTDIR}"/${P/_/-}.tar.sign
- else
- default
- fi
-}
-
-src_prepare() {
- default
-
- sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die
-}
-
-src_configure() {
- # configure may search for libselinux but it seems to only be for
- # statically linking lvm2
- local myeconfargs=(
- --disable-internal-argon2
- --disable-asciidoc
- --enable-shared
- --sbindir="${EPREFIX}"/sbin
- # for later use
- --with-default-luks-format=LUKS2
- --with-tmpfilesdir="${EPREFIX}/usr/lib/tmpfiles.d"
- --with-crypto_backend=$(for x in ${CRYPTO_BACKENDS//+/} ; do usev ${x} ; done)
- $(use_enable argon2 libargon2)
- $(use_enable nls)
- $(use_enable pwquality)
- $(use_enable passwdqc)
- $(use_enable !static external-tokens)
- $(use_enable static static-cryptsetup)
- $(use_enable static-libs static)
- $(use_enable udev)
- $(use_enable !urandom dev-random)
- $(use_enable ssh ssh-token)
- $(usev !argon2 '--with-luks2-pbkdf=pbkdf2')
- $(use_enable fips)
- )
-
- econf "${myeconfargs[@]}"
-}
-
-src_test() {
- if [[ ! -e /dev/mapper/control ]] ; then
- ewarn "No /dev/mapper/control found -- skipping tests"
- return 0
- fi
-
- local p
- for p in /dev/mapper /dev/loop* ; do
- addwrite ${p}
- done
-
- default
-}
-
-src_install() {
- default
-
- if use static ; then
- mv "${ED}"/sbin/cryptsetup{.static,} || die
- mv "${ED}"/sbin/veritysetup{.static,} || die
- mv "${ED}"/sbin/integritysetup{.static,} || die
-
- if use ssh ; then
- mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die
- fi
- fi
-
- find "${ED}" -type f -name "*.la" -delete || die
-
- dodoc docs/v*ReleaseNotes
-
- newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt
- newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt
-}
-
-pkg_postinst() {
- tmpfiles_process cryptsetup.conf
-
- if use kernel ; then
- ewarn "Note that kernel backend is very slow for this type of operation"
- ewarn "and is provided mainly for embedded systems wanting to avoid"
- ewarn "userspace crypto libraries."
- fi
-}
diff --git a/sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild b/sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild
index 0c0908160273..db638b18b21f 100644
--- a/sys-fs/cryptsetup/cryptsetup-2.8.3-r1.ebuild
+++ b/sys-fs/cryptsetup/cryptsetup-2.8.6.ebuild
@@ -1,42 +1,29 @@
-# Copyright 1999-2026 Gentoo Authors
+# Copyright 2021-2026 Liguros Authors
# Distributed under the terms of the GNU General Public License v2
-
EAPI=8
-# TODO: meson (not just yet as of 2.8.0, see https://gitlab.com/cryptsetup/cryptsetup/-/issues/949#note_2585304492)
-VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/milanbroz.asc
-inherit linux-info tmpfiles verify-sig
+inherit linux-info tmpfiles
DESCRIPTION="Tool to setup encrypted devices with dm-crypt"
-HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup"
-SRC_URI="
- https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.xz
- verify-sig? ( https://www.kernel.org/pub/linux/utils/${PN}/v$(ver_cut 1-2)/${P/_/-}.tar.sign )
-"
-S="${WORKDIR}"/${P/_/-}
+HOMEPAGE="https://gitlab.com/cryptsetup/cryptsetup/blob/master/README.md"
+SRC_URI="https://www.kernel.org/pub/linux/utils/cryptsetup/v$(ver_cut 1-2)/${P/_/-}.tar.xz"
LICENSE="GPL-2+"
SLOT="0/12" # libcryptsetup.so version
-if [[ ${PV} != *_rc* ]] ; then
- KEYWORDS="~alpha amd64 arm arm64 ~hppa ~loong ~mips ppc ppc64 ~riscv ~s390 ~sparc x86"
-fi
-
+[[ ${PV} != *_rc* ]] && \
+KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~loong ~mips ppc ppc64 ~riscv ~s390 sparc x86"
CRYPTO_BACKENDS="gcrypt kernel nettle +openssl"
# we don't support nss since it doesn't allow cryptsetup to be built statically
# and it's missing ripemd160 support so it can't provide full backward compatibility
-IUSE="${CRYPTO_BACKENDS} +argon2 fips nls pwquality passwdqc ssh static static-libs test +udev urandom"
+IUSE="${CRYPTO_BACKENDS} +argon2 nls pwquality reencrypt ssh static static-libs test +udev urandom"
RESTRICT="!test? ( test )"
-# bug #496612, bug #832711, bug #843863
-REQUIRED_USE="
- ?? ( pwquality passwdqc )
- ^^ ( ${CRYPTO_BACKENDS//+/} )
- static? ( !ssh !udev !fips )
- static-libs? ( !passwdqc )
- fips? ( !kernel !nettle )
-"
+REQUIRED_USE="^^ ( ${CRYPTO_BACKENDS//+/} )
+ ? ( openssl )
+ static? ( !gcrypt !ssh !udev )"
LIB_DEPEND="
dev-libs/json-c:=[static-libs(+)]
+ dev-libs/libgpg-error[static-libs(+)]
dev-libs/popt[static-libs(+)]
>=sys-apps/util-linux-2.31-r1[static-libs(+)]
argon2? ( app-crypt/argon2:=[static-libs(+)] )
@@ -45,34 +32,30 @@ LIB_DEPEND="
dev-libs/libgpg-error[static-libs(+)]
)
nettle? ( >=dev-libs/nettle-2.4[static-libs(+)] )
- openssl? ( dev-libs/openssl:0=[static-libs(+)] )
+ openssl? (
+ dev-libs/openssl:0=[static-libs(+)]
+
+ )
pwquality? ( dev-libs/libpwquality[static-libs(+)] )
- passwdqc? ( sys-auth/passwdqc )
- ssh? ( net-libs/libssh[static-libs(+)] net-libs/libssh[sftp(+)] )
- sys-fs/lvm2[static-libs(+)]
-"
+ ssh? ( net-libs/libssh[static-libs(+)] )
+ sys-fs/lvm2[static-libs(+)]"
# We have to always depend on ${LIB_DEPEND} rather than put behind
# !static? () because we provide a shared library which links against
-# these other packages. bug #414665
-RDEPEND="
- static-libs? ( ${LIB_DEPEND} )
+# these other packages. #414665
+RDEPEND="static-libs? ( ${LIB_DEPEND} )
${LIB_DEPEND//\[static-libs\([+-]\)\]}
- udev? ( virtual/libudev:= )
-"
-DEPEND="
- ${RDEPEND}
+ udev? ( virtual/libudev:= )"
+# vim-core needed for xxd in tests
+DEPEND="${RDEPEND}
static? ( ${LIB_DEPEND} )
+ test? ( app-editors/vim-core )
+ dev-ruby/asciidoctor
"
-# vim-core needed for xxd in tests
BDEPEND="
virtual/pkgconfig
- test? ( app-editors/vim-core )
- verify-sig? ( sec-keys/openpgp-keys-milanbroz )
"
-PATCHES=(
- "${FILESDIR}/cryptsetup-2.8.3-bitlocker.patch"
-)
+S="${WORKDIR}/${P/_/-}"
pkg_setup() {
local CONFIG_CHECK="~DM_CRYPT ~CRYPTO ~CRYPTO_CBC ~CRYPTO_SHA256"
@@ -83,25 +66,20 @@ pkg_setup() {
check_extra_config
}
-src_unpack() {
- if use verify-sig; then
- verify-sig_uncompress_verify_unpack "${DISTDIR}"/${P/_/-}.tar.xz \
- "${DISTDIR}"/${P/_/-}.tar.sign
- else
- default
- fi
-}
-
src_prepare() {
- default
-
sed -i '/^LOOPDEV=/s:$: || exit 0:' tests/{compat,mode}-test || die
+ default
}
src_configure() {
+ if use kernel ; then
+ ewarn "Note that kernel backend is very slow for this type of operation"
+ ewarn "and is provided mainly for embedded systems wanting to avoid"
+ ewarn "userspace crypto libraries."
+ fi
+
local myeconfargs=(
--disable-internal-argon2
- --disable-asciidoc
--enable-shared
--sbindir="${EPREFIX}"/sbin
# for later use
@@ -111,17 +89,16 @@ src_configure() {
$(use_enable argon2 libargon2)
$(use_enable nls)
$(use_enable pwquality)
- $(use_enable passwdqc)
+ $(use_enable reencrypt luks2-reencryption)
$(use_enable !static external-tokens)
$(use_enable static static-cryptsetup)
$(use_enable static-libs static)
$(use_enable udev)
$(use_enable !urandom dev-random)
$(use_enable ssh ssh-token)
- $(usev !argon2 '--with-luks2-pbkdf=pbkdf2')
- $(use_enable fips)
+ $(usex argon2 '' '--with-luks2-pbkdf=pbkdf2')
+ $(use_enable ! fips)
)
-
econf "${myeconfargs[@]}"
}
@@ -146,26 +123,21 @@ src_install() {
mv "${ED}"/sbin/cryptsetup{.static,} || die
mv "${ED}"/sbin/veritysetup{.static,} || die
mv "${ED}"/sbin/integritysetup{.static,} || die
-
if use ssh ; then
mv "${ED}"/sbin/cryptsetup-ssh{.static,} || die
fi
+ if use reencrypt ; then
+ mv "${ED}"/sbin/cryptsetup-reencrypt{.static,} || die
+ fi
fi
-
find "${ED}" -type f -name "*.la" -delete || die
dodoc docs/v*ReleaseNotes
- newconfd "${FILESDIR}"/2.4.3-dmcrypt.confd dmcrypt
- newinitd "${FILESDIR}"/2.4.3-dmcrypt.rc dmcrypt
+ newconfd "${FILESDIR}"/1.6.7-dmcrypt.confd dmcrypt
+ newinitd "${FILESDIR}"/1.6.7-dmcrypt.rc dmcrypt
}
pkg_postinst() {
tmpfiles_process cryptsetup.conf
-
- if use kernel ; then
- ewarn "Note that kernel backend is very slow for this type of operation"
- ewarn "and is provided mainly for embedded systems wanting to avoid"
- ewarn "userspace crypto libraries."
- fi
}
diff --git a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd
index 8250e8268ac9..642ff087078b 100644
--- a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.confd
+++ b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.confd
@@ -44,7 +44,6 @@ dmcrypt_retries=5
# for blkid (see -t option). This is safer than using
# the full path to the device.
# key='</path/to/keyfile>[:<mode>]' == Fullpath from / or from inside removable media.
-# header='</path/to/header>' == Full path to detached LUKS header file.
# remdev='<dev>' == Device that will be assigned to removable media.
# gpg_options='<opts>' == Default are --quiet --decrypt
# options='<opts>' == cryptsetup, for LUKS you can only use --readonly
@@ -53,8 +52,6 @@ dmcrypt_retries=5
# be looked up automatically.
# pre_mount='cmds' == commands to execute before mounting partition.
# post_mount='cmds' == commands to execute after mounting partition.
-# wait=5 == wait given amount of seconds for source or
-# detached header file appear.
#-----------
# Supported Modes
# gpg == decrypt and pipe key into cryptsetup.
@@ -82,12 +79,6 @@ dmcrypt_retries=5
#source='/dev/hda5'
#key='/full/path/to/homekey'
-## /home with regular keyfile and detached header
-#target=crypt-home
-#source='/dev/hda5'
-#key='/full/path/to/homekey'
-#header='/full/path/to/header/file'
-
## /home with gpg protected key
#target=crypt-home
#source='/dev/hda5'
diff --git a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc
index ea9a5ca4807b..d4fe6030355f 100644
--- a/sys-fs/cryptsetup/files/2.4.3-dmcrypt.rc
+++ b/sys-fs/cryptsetup/files/1.6.7-dmcrypt.rc
@@ -3,9 +3,7 @@
# Distributed under the terms of the GNU General Public License v2
depend() {
- use modules
before checkfs fsck
- after dev-settle
if grep -qs ^swap= "${conf_file}" ; then
before swap
@@ -23,7 +21,7 @@ fi
# Setup mappings for an individual target/swap
# Note: This relies on variables localized in the main body below.
dm_crypt_execute() {
- local dev ret mode foo source_dev
+ local dev ret mode foo
if [ -z "${target}" -a -z "${swap}" ] ; then
return
@@ -33,7 +31,6 @@ dm_crypt_execute() {
: ${dmcrypt_key_timeout:=1}
: ${dmcrypt_max_timeout:=300}
: ${dmcrypt_retries:=5}
- : ${wait:=5}
# Handle automatic look up of the source path.
if [ -z "${source}" -a -n "${loop_file}" ] ; then
@@ -41,16 +38,7 @@ dm_crypt_execute() {
fi
case ${source} in
*=*)
- i=0
- while [ ${i} -lt ${wait} ]; do
- if source_dev="$(blkid -l -t "${source}" -o device)"; then
- source="${source_dev}"
- break
- fi
- : $((i += 1))
- einfo "waiting for source \"${source}\" for ${target}..."
- sleep 1
- done
+ source=$(blkid -l -t "${source}" -o device)
;;
esac
if [ -z "${source}" ] || [ ! -e "${source}" ] ; then
@@ -58,28 +46,11 @@ dm_crypt_execute() {
return
fi
- if [ -n "${header}" ] ; then
- header_opt="--header=${header}"
-
- i=0
- while [ ! -e "${header}" ] && [ ${i} -lt ${wait} ] ; do
- : $((i += 1))
- einfo "Waiting for header ${header} to appear for ${target} ${i}/${dmcrypt_max_timeout} ..."
- sleep 1
- done
- if [ ${i} -gt ${wait} ] || [ ${i} -eq ${wait} ] ; then
- ewarn "Waited ${i} times for header file ${header}. Aborting ${target}."
- return
- fi
- else
- header_opt=""
- fi
-
if [ -n "${target}" ] ; then
# let user set options, otherwise leave empty
: ${options:=' '}
elif [ -n "${swap}" ] ; then
- if cryptsetup ${header_opt} isLuks ${source} 2>/dev/null ; then
+ if cryptsetup isLuks ${source} 2>/dev/null ; then
ewarn "The swap you have defined is a LUKS partition. Aborting crypt-swap setup."
return
fi
@@ -100,7 +71,7 @@ dm_crypt_execute() {
# open <device> <name> # <device> is $source
# create <name> <device> # <name> is $target
local arg1="create" arg2="${target}" arg3="${source}"
- if cryptsetup ${header_opt} isLuks ${source} 2>/dev/null ; then
+ if cryptsetup isLuks ${source} 2>/dev/null ; then
arg1="open"
arg2="${source}"
arg3="${target}"
@@ -110,7 +81,7 @@ dm_crypt_execute() {
# ${target} is active:
# Newer versions report:
# ${target} is active[ and is in use.]
- if cryptsetup ${header_opt} status ${target} | grep -E -q ' is active' ; then
+ if cryptsetup status ${target} | grep -E -q ' is active' ; then
einfo "dm-crypt mapping ${target} is already configured"
return
fi
@@ -200,7 +171,7 @@ dm_crypt_execute() {
else
mode=none
fi
- ebegin " ${target} using: ${header_opt} ${options} ${arg1} ${arg2} ${arg3}"
+ ebegin " ${target} using: ${options} ${arg1} ${arg2} ${arg3}"
if [ "${mode}" = "gpg" ] ; then
: ${gpg_options:='-q -d'}
# gpg available ?
@@ -210,7 +181,7 @@ dm_crypt_execute() {
# paranoid, don't store key in a variable, pipe it so it stays very little in ram unprotected.
# save stdin stdout stderr "values"
timeout ${dmcrypt_max_timeout} gpg ${gpg_options} ${key} 2>/dev/null | \
- cryptsetup ${header_opt} --key-file - ${options} ${arg1} ${arg2} ${arg3}
+ cryptsetup --key-file - ${options} ${arg1} ${arg2} ${arg3}
ret=$?
# The timeout command exits 124 when it times out.
[ ${ret} -eq 0 -o ${ret} -eq 124 ] && break
@@ -225,11 +196,11 @@ dm_crypt_execute() {
fi
else
if [ "${mode}" = "reg" ] ; then
- cryptsetup ${header_opt} ${options} -d ${key} ${arg1} ${arg2} ${arg3}
+ cryptsetup ${options} -d ${key} ${arg1} ${arg2} ${arg3}
ret=$?
eend ${ret} "failure running cryptsetup"
else
- cryptsetup ${header_opt} ${options} ${arg1} ${arg2} ${arg3}
+ cryptsetup ${options} ${arg1} ${arg2} ${arg3}
ret=$?
eend ${ret} "failure running cryptsetup"
fi
@@ -265,7 +236,7 @@ get_bootparam_val() {
}
start() {
- local print_header=true cryptfs_status=0
+ local header=true cryptfs_status=0
local gpg_options key loop_file target targetline options pre_mount post_mount source swap remdev
local x
@@ -285,8 +256,8 @@ start() {
rc_*) continue ;;
esac
- ${print_header} && ebegin "Setting up dm-crypt mappings"
- print_header=false
+ ${header} && ebegin "Setting up dm-crypt mappings"
+ header=false
# check for the start of a new target/swap
case ${targetline} in
@@ -295,10 +266,10 @@ start() {
dm_crypt_execute
# Prepare for the next target/swap by resetting variables
- unset gpg_options key loop_file target options pre_mount post_mount source swap remdev wait header header_opt
+ unset gpg_options key loop_file target options pre_mount post_mount source swap remdev
;;
- gpg_options=*|remdev=*|key=*|loop_file=*|options=*|pre_mount=*|post_mount=*|wait=*|source=*|header=*)
+ gpg_options=*|remdev=*|key=*|loop_file=*|options=*|pre_mount=*|post_mount=*|source=*)
if [ -z "${target}${swap}" ] ; then
ewarn "Ignoring setting outside target/swap section: ${targetline}"
continue
@@ -326,14 +297,14 @@ start() {
}
stop() {
- local line print_header
+ local line header
# Break down all mappings
- print_header=true
+ header=true
grep -E "^(target|swap)=" ${conf_file} | \
while read line ; do
- ${print_header} && einfo "Removing dm-crypt mappings"
- print_header=false
+ ${header} && einfo "Removing dm-crypt mappings"
+ header=false
target= swap=
eval ${line}
@@ -345,16 +316,16 @@ stop() {
fi
ebegin " ${target}"
- cryptsetup ${header_opt} remove ${target}
+ cryptsetup remove ${target}
eend $?
done
# Break down loop devices
- print_header=true
+ header=true
grep '^source=./dev/loop' ${conf_file} | \
while read line ; do
- ${print_header} && einfo "Detaching dm-crypt loop devices"
- print_header=false
+ ${header} && einfo "Detaching dm-crypt loop devices"
+ header=false
source=
eval ${line}
diff --git a/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch b/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch
deleted file mode 100644
index a6ca2652cd82..000000000000
--- a/sys-fs/cryptsetup/files/cryptsetup-2.8.3-bitlocker.patch
+++ /dev/null
@@ -1,45 +0,0 @@
-https://bugs.gentoo.org/969153
-https://gitlab.com/cryptsetup/cryptsetup/-/issues/973
-https://gitlab.com/cryptsetup/cryptsetup/-/merge_requests/883
-
-From 4eb729da3f46642d6fe1fabbbedb127078eccb95 Mon Sep 17 00:00:00 2001
-From: Vojtech Trefny <vtrefny@redhat.com>
-Date: Sun, 11 Jan 2026 14:31:29 +0100
-Subject: [PATCH] bitlk: Do not try to use empty password for password keyslots
-
-Passing empty password means we want to try to open the device
-using the clear key so we can skip all other keyslots in this case.
-
-This also fixes unlocking a BitLocker device where recovery
-passphrase is in the first keyslot where we try to use the empty
-passhrase first, hoping for a clear key, and never actually prompt
-user for an actual (recovery) passphrase after.
-
-Fixes: #973
----
- lib/bitlk/bitlk.c | 11 +++++++++++
- tests/bitlk-images.tar.xz | Bin 355720 -> 376840 bytes
- 2 files changed, 11 insertions(+)
-
-diff --git a/lib/bitlk/bitlk.c b/lib/bitlk/bitlk.c
-index 3b7b093d..0e8f9d1d 100644
---- a/lib/bitlk/bitlk.c
-+++ b/lib/bitlk/bitlk.c
-@@ -1300,6 +1300,17 @@ int BITLK_get_volume_key(struct crypt_device *cd,
- next_vmk = params->vmks;
- while (next_vmk) {
- bool is_decrypted = false;
-+
-+ if (password == NULL && next_vmk->protection != BITLK_PROTECTION_CLEAR_KEY) {
-+ /*
-+ * Clearkey is the only slot that doesn't require password so no password
-+ * means we are trying to use clearkey and we can skip all other key slots.
-+ */
-+ r = -EPERM;
-+ next_vmk = next_vmk->next;
-+ continue;
-+ }
-+
- if (next_vmk->protection == BITLK_PROTECTION_PASSPHRASE) {
- r = bitlk_kdf(password, passwordLen, false, next_vmk->salt, &vmk_dec_key);
- if (r) {
diff --git a/sys-fs/cryptsetup/metadata.xml b/sys-fs/cryptsetup/metadata.xml
index 66fef2269d6f..252353aa5edd 100644
--- a/sys-fs/cryptsetup/metadata.xml
+++ b/sys-fs/cryptsetup/metadata.xml
@@ -2,24 +2,26 @@
<!DOCTYPE pkgmetadata SYSTEM "https://docs.baldeagleos.com/dtd/metadata.dtd">
<pkgmetadata>
<maintainer type="project">
+ <email>dev@liguros.net</email>
+ <name>Development</name>
+ </maintainer>
+ <maintainer type="project">
<email>base-system@gentoo.org</email>
<name>Gentoo Base System</name>
</maintainer>
+ <upstream>
+ <remote-id type="cpe">cpe:/a:cryptsetup_project:cryptsetup</remote-id>
+ </upstream>
<use>
<flag name="argon2">Enable password hashing algorithm from <pkg>app-crypt/argon2</pkg>
</flag>
- <flag name="fips">Enable FIPS mode restrictions</flag>
<flag name="gcrypt">Use <pkg>dev-libs/libgcrypt</pkg> crypto backend</flag>
<flag name="kernel">Use kernel crypto backend (mainly for embedded systems)</flag>
<flag name="nettle">Use <pkg>dev-libs/nettle</pkg> crypto backend</flag>
<flag name="openssl">Use <pkg>dev-libs/openssl</pkg> crypto backend</flag>
<flag name="pwquality">Use <pkg>dev-libs/libpwquality</pkg> for password quality checking</flag>
- <flag name="passwdqc">Use <pkg>sys-auth/passwdqc</pkg> for password quality checking</flag>
- <flag name="ssh">Build cryptsetup-ssh for experimental support of token via SSH-server</flag>
<flag name="urandom">Use /dev/urandom instead of /dev/random</flag>
+ <flag name="reencrypt">Build cryptsetup-reencrypt</flag>
</use>
- <upstream>
- <remote-id type="cpe">cpe:/a:cryptsetup_project:cryptsetup</remote-id>
- </upstream>
<origin>baldeagleos-repo</origin>
</pkgmetadata>