Skip to content

luci-app-veracrypt-lite: add new package - #9119

Open
flatstik wants to merge 1 commit into
openwrt:masterfrom
flatstik:luci-app-veracrypt-lite
Open

flatstik wants to merge 1 commit into
openwrt:masterfrom
flatstik:luci-app-veracrypt-lite

Conversation

@flatstik

@flatstik flatstik commented Oct 8, 2026

Copy link
Copy Markdown

Pull request details

Description

A small web UI for the console veracrypt package (openwrt/packages#30597), as an alternative to luci-app-veracrypt (#9069). Both PRs are independent: either or both can be merged, and the two apps can be installed side by side (they share the favorites in /etc/config/veracrypt, which the veracrypt package ships).

Background: in #9069 the backend was found too complex for review (#9069 (review)). This package is the reduced design: the full feature set stays in luci-app-veracrypt, and this one covers the common cases with a much smaller implementation.

  • Features: status of mounted volumes, mount, unmount, create (container file under /mnt or a whole free disk), create keyfile, favorites (shared UCI volume sections), job progress with abort
  • Not included (use luci-app-veracrypt or veracrypt --text): change password, header backup/restore, hidden volumes, security tokens, fsck/repair, package installation, file management
  • Backend: a ucode rpcd plugin (luci.veracrypt-lite, ~430 lines). Mount and create take minutes on a router (key derivation), longer than an rpc call may take, so they run in the background through a ~70-line helper that starts veracrypt --text --non-interactive --stdin with the password on stdin, never in argv, environment or logs; one job at a time (flock)
  • Paths: volumes, keyfiles and mount directories must be under /mnt on a mounted disk, also after resolving symlinks; new files are refused in directories writable by other users; devices that are mounted, used as swap, held, eMMC, or on a disk with a mounted partition are not offered
  • ACL: ubus methods split into read/write, file list on /mnt only (for the file chooser); no file write or exec
  • tests/run.sh <openwrt-rootfs.tar.gz> runs the plugin and helper against a fake veracrypt inside an OpenWrt rootfs (unprivileged namespace chroot): 196 checks

Maintainer (preferred)

@flatstik


Tested on

OpenWrt version: OpenWrt 25.12.5 (r33051-f5dae5ece4), ASUS RT-AX53U, ramips/mt7621
LuCI version: LuCI openwrt-25.12 branch
Web browser(s): Firefox

Installed together with luci-app-veracrypt from #9069 on the device above (the veracrypt run-test passes with both installed); the plugin was also run under a real rpcd/ubusd in the OpenWrt 25.12 x86_64 rootfs.


Checklist

@openwrt openwrt Bot added the add package Introduces a new package Makefile build script label Oct 8, 2026
Comment thread applications/luci-app-veracrypt-lite/tests/run.sh Outdated
A small web UI for the console veracrypt package (packages feed):
openwrt/packages#30597

It is an alternative to luci-app-veracrypt
(openwrt#9069): mount, unmount and create
volumes (container files or whole free disks), create keyfiles, and
favorites in /etc/config/veracrypt, which both apps share. Change
password, header backup/restore, hidden volumes, security tokens,
fsck and package installation are only in luci-app-veracrypt. The two
can be installed side by side.

The backend is a ucode rpcd plugin. Mount and create take minutes on
a router, so they run in the background through a small helper that
starts veracrypt --text --non-interactive --stdin with the password on
stdin, never in argv or logs; one job at a time. Volumes, keyfiles and
mount directories must lie under /mnt on a mounted disk, also after
resolving symlinks. tests/run.sh exercises the plugin and the helper
in an OpenWrt rootfs.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@flatstik
flatstik force-pushed the luci-app-veracrypt-lite branch from 06942fc to 7417973 Compare October 9, 2026 07:19

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; no new issues found.


Generated by Claude Code

@BKPepe BKPepe left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is the wrong direction. My concern was that the original implementation had become unnecessarily complex, not that we needed a second, reduced version of the same application.

Having both luci-app-veracrypt and luci-app-veracrypt-lite means maintaining two separate implementations, UIs, ACLs and test suites for the same purpose. Sharing the UCI configuration does not solve that problem; it can actually make the behavior less consistent.

I would much rather see the original PR simplified along these lines, with a clearly defined and maintainable scope, than introduce a second package that duplicates much of the same functionality.

Could we keep this as a single luci-app-veracrypt package and use the simpler implementation as the replacement for the current backend, instead of maintaining two alternatives?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

add package Introduces a new package Makefile build script

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants