Skip to content

Latest commit

 

History

History
112 lines (81 loc) · 3.48 KB

File metadata and controls

112 lines (81 loc) · 3.48 KB

Linux testing guide (DeviceCryptor)

Linux is the first supported test platform. Windows EFI/driver paths remain scaffolded.

Build

cargo build -p dc-cli
# binary: target/debug/dc

One-shot harness

./scripts/linux-test.sh

Covers: create FAT32, keyfiles, mount/write/dismount persistence, wrong password, header backup/chpasswd/restore, hidden volumes, unit tests.

Create sizes

--size and --hidden-size accept bytes or binary units: 16M, 1G, 512K.

Password change & header backup

./target/debug/dc header backup ./vol.dc ./vol.hdrbak
./target/debug/dc chpasswd ./vol.dc --password old --new-password new
./target/debug/dc header restore ./vol.dc ./vol.hdrbak   # optional rollback

chpasswd re-seals the DC01 header with a new salt/password while keeping the master key (data area is not rewritten). Backup files are mode 0600 and contain only header slots (first 128 KiB of the container layout), not file contents.

Manual smoke

./target/debug/dc create ./vol.dc --size 16M --password 'secret' --fs fat32
mkdir mnt
# Mount needs password (+ optional keyfile). Dismount does not.
./target/debug/dc mount ./vol.dc ./mnt --password 'secret' --id t1
echo hi > ./mnt/hi.txt
./target/debug/dc dismount --id t1

mkdir mnt2
./target/debug/dc mount ./vol.dc ./mnt2 --password 'secret' --id t2
cat ./mnt2/hi.txt
./target/debug/dc dismount --id t2

Mount / dismount workflow

Action Credentials
Mount Password required; keyfile(s) optional (--keyfile)
Dismount Mount id only (dc dismount / dc dismount --id …) — no password

On mount, DeviceCryptor caches the unlocked master key in a user-private session file (~/.local/state/devicecryptor/<id>.session, mode 0600) so checkin can sync without re-prompting. The session file is wiped on dismount.

Mount backends

FS Backend Privileges
fat32 (default) checkout/checkin — extracts FAT tree to a directory; dismount writes it back none
ext4 decrypt to raw + losetup + mount root

Checkout mounts are not live kernel mounts: edit files in the mountpoint directory, then dismount to sync into the encrypted container.

Hidden volumes

./target/debug/dc create ./h.dc --size 33554432 --password outer --hidden-size 8388608 \
  --hidden-password hidden --fs fat32
./target/debug/dc mount ./h.dc ./outer --password outer --id o
# … write decoy files …
./target/debug/dc dismount --id o
./target/debug/dc mount ./h.dc ./hid --password hidden --id h
# … write secret files …
./target/debug/dc dismount --id h

Use --protect-hidden + --hidden-password when mounting the outer volume to refuse writes that would overwrite the hidden region.

Keyfiles

./target/debug/dc create ./k.dc --password p --keyfile ./kf.bin --fs fat32
./target/debug/dc mount ./k.dc ./mnt --password p --keyfile ./kf.bin --id k
./target/debug/dc dismount --id k

Traveler / portable

Copy target/release/dc next to your containers — no installer required for checkout mounts.

Initramfs (system encryption — later)

See boot/linux-initramfs/. Header unlock is wired; full dm/ublk attach is next.

Ext4 (root)

sudo ./target/debug/dc create ./e.dc --size 67108864 --password p --fs ext4
sudo mkdir /mnt/dc
sudo ./target/debug/dc mount ./e.dc /mnt/dc --password p --fs ext4 --id e
# use /mnt/dc as a normal filesystem
sudo ./target/debug/dc dismount --id e