Repository navigation
Conversation
A small web UI for the console veracrypt package (packages feed): openwrt/packages#30597 It is an alternative to luci-app-veracrypt (openwrt#9069): mount, unmount and create volumes (container files or whole free disks), create keyfiles, and favorites in /etc/config/veracrypt, which both apps share. Change password, header backup/restore, hidden volumes, security tokens, fsck and package installation are only in luci-app-veracrypt. The two can be installed side by side. The backend is a ucode rpcd plugin. Mount and create take minutes on a router, so they run in the background through a small helper that starts veracrypt --text --non-interactive --stdin with the password on stdin, never in argv or logs; one job at a time. Volumes, keyfiles and mount directories must lie under /mnt on a mounted disk, also after resolving symlinks. tests/run.sh exercises the plugin and the helper in an OpenWrt rootfs. Signed-off-by: Ville Takio <ville+git@takio.fi>
06942fc to
7417973
Compare
BKPepe
left a comment
There was a problem hiding this comment.
I think this is the wrong direction. My concern was that the original implementation had become unnecessarily complex, not that we needed a second, reduced version of the same application.
Having both luci-app-veracrypt and luci-app-veracrypt-lite means maintaining two separate implementations, UIs, ACLs and test suites for the same purpose. Sharing the UCI configuration does not solve that problem; it can actually make the behavior less consistent.
I would much rather see the original PR simplified along these lines, with a clearly defined and maintainable scope, than introduce a second package that duplicates much of the same functionality.
Could we keep this as a single luci-app-veracrypt package and use the simpler implementation as the replacement for the current backend, instead of maintaining two alternatives?
Pull request details
Description
A small web UI for the console
veracryptpackage (openwrt/packages#30597), as an alternative to luci-app-veracrypt (#9069). Both PRs are independent: either or both can be merged, and the two apps can be installed side by side (they share the favorites in/etc/config/veracrypt, which theveracryptpackage ships).Background: in #9069 the backend was found too complex for review (#9069 (review)). This package is the reduced design: the full feature set stays in luci-app-veracrypt, and this one covers the common cases with a much smaller implementation.
/mntor a whole free disk), create keyfile, favorites (shared UCIvolumesections), job progress with abortveracrypt --text): change password, header backup/restore, hidden volumes, security tokens, fsck/repair, package installation, file managementluci.veracrypt-lite, ~430 lines). Mount and create take minutes on a router (key derivation), longer than an rpc call may take, so they run in the background through a ~70-line helper that startsveracrypt --text --non-interactive --stdinwith the password on stdin, never in argv, environment or logs; one job at a time (flock)/mnton a mounted disk, also after resolving symlinks; new files are refused in directories writable by other users; devices that are mounted, used as swap, held, eMMC, or on a disk with a mounted partition are not offeredliston/mntonly (for the file chooser); no file write or exectests/run.sh <openwrt-rootfs.tar.gz>runs the plugin and helper against a fakeveracryptinside an OpenWrt rootfs (unprivileged namespace chroot): 196 checksMaintainer (preferred)
@flatstik
Tested on
OpenWrt version: OpenWrt 25.12.5 (r33051-f5dae5ece4), ASUS RT-AX53U, ramips/mt7621
LuCI version: LuCI openwrt-25.12 branch
Web browser(s): Firefox
Installed together with luci-app-veracrypt from #9069 on the device above (the veracrypt run-test passes with both installed); the plugin was also run under a real rpcd/ubusd in the OpenWrt 25.12 x86_64 rootfs.
Checklist