Linux is the first supported test platform. Windows EFI/driver paths remain scaffolded.
cargo build -p dc-cli
# binary: target/debug/dc./scripts/linux-test.shCovers: create FAT32, keyfiles, mount/write/dismount persistence, wrong password, header backup/chpasswd/restore, hidden volumes, unit tests.
--size and --hidden-size accept bytes or binary units: 16M, 1G, 512K.
./target/debug/dc header backup ./vol.dc ./vol.hdrbak
./target/debug/dc chpasswd ./vol.dc --password old --new-password new
./target/debug/dc header restore ./vol.dc ./vol.hdrbak # optional rollbackchpasswd re-seals the DC01 header with a new salt/password while keeping the master key
(data area is not rewritten). Backup files are mode 0600 and contain only header slots
(first 128 KiB of the container layout), not file contents.
./target/debug/dc create ./vol.dc --size 16M --password 'secret' --fs fat32
mkdir mnt
# Mount needs password (+ optional keyfile). Dismount does not.
./target/debug/dc mount ./vol.dc ./mnt --password 'secret' --id t1
echo hi > ./mnt/hi.txt
./target/debug/dc dismount --id t1
mkdir mnt2
./target/debug/dc mount ./vol.dc ./mnt2 --password 'secret' --id t2
cat ./mnt2/hi.txt
./target/debug/dc dismount --id t2| Action | Credentials |
|---|---|
| Mount | Password required; keyfile(s) optional (--keyfile) |
| Dismount | Mount id only (dc dismount / dc dismount --id …) — no password |
On mount, DeviceCryptor caches the unlocked master key in a user-private session file
(~/.local/state/devicecryptor/<id>.session, mode 0600) so checkin can sync without
re-prompting. The session file is wiped on dismount.
| FS | Backend | Privileges |
|---|---|---|
fat32 (default) |
checkout/checkin — extracts FAT tree to a directory; dismount writes it back |
none |
ext4 |
decrypt to raw + losetup + mount |
root |
Checkout mounts are not live kernel mounts: edit files in the mountpoint directory, then dismount to sync into the encrypted container.
Hidden volumes
./target/debug/dc create ./h.dc --size 33554432 --password outer --hidden-size 8388608 \
--hidden-password hidden --fs fat32
./target/debug/dc mount ./h.dc ./outer --password outer --id o
# … write decoy files …
./target/debug/dc dismount --id o
./target/debug/dc mount ./h.dc ./hid --password hidden --id h
# … write secret files …
./target/debug/dc dismount --id hUse --protect-hidden + --hidden-password when mounting the outer volume to refuse writes that would overwrite the hidden region.
./target/debug/dc create ./k.dc --password p --keyfile ./kf.bin --fs fat32
./target/debug/dc mount ./k.dc ./mnt --password p --keyfile ./kf.bin --id k
./target/debug/dc dismount --id kCopy target/release/dc next to your containers — no installer required for checkout mounts.
See boot/linux-initramfs/. Header unlock is wired; full dm/ublk attach is next.
sudo ./target/debug/dc create ./e.dc --size 67108864 --password p --fs ext4
sudo mkdir /mnt/dc
sudo ./target/debug/dc mount ./e.dc /mnt/dc --password p --fs ext4 --id e
# use /mnt/dc as a normal filesystem
sudo ./target/debug/dc dismount --id e