github PentHertz/LUKSbox v0.4.0-rc.3

latest releases: v0.6.0-rc.1, v0.5.2, v0.5.2-rc.1...
pre-release3 months ago

Verify your download

Cryptographic provenance (GitHub / Sigstore attestation)

Every artifact below is signed via GitHub Artifact
Attestations
,
which uses Sigstore under the hood. The signature proves
the artifact was produced by this exact workflow run on
this exact commit SHA, no human had a chance to swap it
after the fact.

Verify with the GitHub CLI (one-liner):

# Install gh once if you don't have it:
#   sudo apt install gh   |   sudo dnf install gh   |   brew install gh
gh attestation verify <downloaded-file> --owner penthertz
# Prints "Loaded digest ..." then "PASS" with the
# workflow run + commit SHA the artifact came from.

Offline check (no gh needed)

Every artifact also has a SHA-256 in SHA256SUMS.txt
(attached to this release):

# Linux / macOS:
sha256sum -c SHA256SUMS.txt   # Linux
shasum -a 256 -c SHA256SUMS.txt   # macOS
# Windows (PowerShell):
Get-FileHash luksbox-*.msi -Algorithm SHA256
# then compare to the `*.msi` row in SHA256SUMS.txt

Trust chain summary

Artifacts on this release page are uploaded only by the
GitHub Actions release workflow that ran on this tagged
commit (.github/workflows/release.yml in the repo).
The commit itself is GPG-signed by the maintainer, the
upload uses GitHub's OIDC release token, and the
Sigstore attestation above pins the signature to that
workflow run. GPG-signed release tarballs
(SHA256SUMS.txt.asc) and full SLSA L3 provenance are
on the roadmap.

For at-a-glance SHA-256 checking against the published
values:

File SHA-256
luksbox-0.4.0-rc.3-1.aarch64.rpm cea483565f68ff760c7e8139c2ca35b31f167c18796c7f6edbc039f70a30ce58
luksbox-0.4.0-rc.3-1.x86_64.rpm 5f9165b24916f370371f76eeddd4e1a704024b0b5dea3312929b37a1be6fcc5b
luksbox-v0.4.0-rc.3-aarch64-linux-jammy.tar.gz c320ad5b78032116fe87d324b2b1652110c29ec520a59c7d0b03ae8845ebffea
luksbox-v0.4.0-rc.3-aarch64-linux-noble.tar.gz 81fa38e60dd7e61e3ab3fa2992b3e099d6236202ebc00748fe9ae454ca957226
luksbox-v0.4.0-rc.3-aarch64-linux-resolute.tar.gz 45008812c52c3c25afac51ca6d02a24680455f14cf9e09ce5f8b1bb326f4a7b1
luksbox-v0.4.0-rc.3-aarch64-linux-trixie.tar.gz 7508b1a3e83e58bdbc59b3175e7fd75bcc06e37c622484c01c3995e381d6f436
luksbox-v0.4.0-rc.3-aarch64-macos-fuset-portable.tar.gz bb765993d7874bf3611985940b30d1207099490b351c821d87cb7b15f3312c72
luksbox-v0.4.0-rc.3-aarch64-macos-fuset.dmg 5fa7db62c7c84bc2e7a4931a9906ea7eb6c4673872ab18422373308fbc02c68f
luksbox-v0.4.0-rc.3-aarch64-macos-macfuse-portable.tar.gz a2acade7985b2736a3a1539ea60f6ac8086a6864bcfa3640b8bb5586d3561fbd
luksbox-v0.4.0-rc.3-aarch64-macos-macfuse.dmg 7e0e0b5ae3e6dac7eed7a1fd8478a899bd1c79ae29d839f6a71a64f82e15fa34
luksbox-v0.4.0-rc.3-x86_64-linux-jammy.tar.gz 9c0e033f5c085d348e5f09391a21c1fe13a803d2a7daa232f33e4d9b9dbfe4b5
luksbox-v0.4.0-rc.3-x86_64-linux-noble.tar.gz 5ea0e2d62ffa6da305222893f029f7efa0d13a0e924096f119aa261b601cefe5
luksbox-v0.4.0-rc.3-x86_64-linux-resolute.tar.gz 2236bc5d3bd26b72847813ab7acfc023c1718ec9430d95fc7319feee91684264
luksbox-v0.4.0-rc.3-x86_64-linux-trixie.tar.gz 9cf48967a760bd4bcc19bdb72fc5d6153a916caa7406df9657b9cabdfcf52495
luksbox-v0.4.0-rc.3-x86_64-windows-setup.exe b74b56c7e9e8a5080067fc0bf973759b6b87d0d124c21695a3d53d01094767ba
luksbox-v0.4.0-rc.3-x86_64-windows.msi 846fd421c614a5a3ccc5e2046925f4de48e87204113dd49236bff890a1fc8556
luksbox-v0.4.0-rc.3-x86_64-windows.zip 5eb21ab9cf9feba1e0a35139a8a7cd03c23bd745a8386eacfe01acbf70afbfca
luksbox_0.4.0~rc.3-1_jammy_amd64.deb fae684e09b78ad37349a980b1199989a27ae6a550ded3e4a15ae84d0e8c0f50d
luksbox_0.4.0~rc.3-1_jammy_arm64.deb a6ff7dd4500ec23df4f882cb96d7f48e20178624bfe4ef214d5eade0afce0b18
luksbox_0.4.0~rc.3-1_noble_amd64.deb 929cdee9c3baa5ba529917386ada3b2095e73cbbe65cbda38d55871ad1a7f63c
luksbox_0.4.0~rc.3-1_noble_arm64.deb d9daf5b6604288783004c0ced337d6916975236ae16e20124fddc076ab02d720
luksbox_0.4.0~rc.3-1_resolute_amd64.deb 5319400d584b8af1324ab7699b233d3918f98d6cd942dc9f541a589254689a41
luksbox_0.4.0~rc.3-1_resolute_arm64.deb dd877b5c12a96fbcbe211d4bd2fe5b12d4872ff7f1ec59563f85dcb5ac2cd9ce
luksbox_0.4.0~rc.3-1_trixie_amd64.deb 7906e5ec8b29e34d3189773345eae618d0cad9edf4189d790d611d0a18631056
luksbox_0.4.0~rc.3-1_trixie_arm64.deb 16babd88440f29cbf9f182221719f66c0e22929c2edc3b90aa7953db5dafd291

Install

Linux (Ubuntu 22.04, Debian 11/12, Mint 21.x, .deb):
download luksbox_*_jammy_amd64.deb (or _arm64) and
install with sudo apt install ./luksbox_*_jammy_amd64.deb.
Pulls in libfido2-1, libfuse3-3, and libtss2-*
automatically. Registers a luksbox-gui desktop
launcher and a MIME type for .lbx files.

Linux (Ubuntu 24.04 noble, .deb):
download luksbox_*_noble_amd64.deb (or _arm64) and
install with sudo apt install ./luksbox_*_noble_amd64.deb.
Same package layout as the jammy build, but with
t64-transitioned dependency names (libssl3t64,
libfido2-1t64, libtss2-mu-4.0.1-0t64, etc.). The
jammy and noble .deb files cannot be installed
interchangeably, the dependency names differ.

Linux (Debian 13 trixie / Ubuntu 26.04 resolute, .deb):
these distros bump shared-library sonames again past
noble, so they get their own builds. Download
luksbox_*_trixie_amd64.deb on Debian 13 or
luksbox_*_resolute_amd64.deb on Ubuntu 26.04 (or the
matching _arm64) and install with sudo apt install ./<file>. Each .deb's dependency names are resolved
against its own distro, so install the one matching your
release rather than the noble build.

Linux (Fedora / RHEL / Rocky / Alma, .rpm): download
luksbox-*.x86_64.rpm (or aarch64.rpm) and install
with sudo dnf install ./luksbox-*.x86_64.rpm (or
sudo rpm -i). One .rpm covers every rpm-based
distro, RPM uses SONAMEs for shared-library
dependencies which are stable across releases.
Pulls in libfido2 and fuse3-libs automatically.

Linux (x86_64, generic tarball): tar xzf luksbox-v0.4.0-rc.3-x86_64-linux-jammy.tar.gz && cd luksbox-v0.4.0-rc.3-x86_64-linux-jammy && ./install.sh
For Arch / NixOS / Alpine / any non-deb non-rpm distro.
The jammy variant has the broadest glibc compatibility;
if you are on a very recent distro and prefer the noble
build, swap -jammy for -noble in the filename.
Installs to ~/.local/bin and registers a desktop launcher.
Use ./install.sh --system for system-wide install, or
./install.sh --uninstall to remove. Requires
libfido2-1 (and libfuse3-3 for mount):
sudo apt install libfido2-1 libfuse3-3 (Debian/Ubuntu)
or sudo dnf install libfido2 fuse3-libs (Fedora/RHEL).

Linux (aarch64): tar xzf luksbox-v0.4.0-rc.3-aarch64-linux-jammy.tar.gz && cd luksbox-v0.4.0-rc.3-aarch64-linux-jammy && ./install.sh
Same runtime deps and installer as x86_64. Built natively
on a GitHub ARM64 runner, no QEMU emulation. Same
jammy/noble distinction applies as for the .deb above.

macOS (Apple Silicon): two .dmg variants, one per
FUSE backend. Pick one based on which FUSE provider you
want to install. Both .dmgs are otherwise identical
(same crypto, same on-disk format, same UI); the
difference is what luksbox mount calls under the hood
and whether you need a kernel extension.

FUSE-T variant (recommended for personal laptops):

  download: luksbox-v0.4.0-rc.3-aarch64-macos-fuset.dmg
  install FUSE-T first:
      brew tap macos-fuse-t/homebrew-cask
      brew install --cask fuse-t
  then drag LUKSbox.app onto Applications.

No kernel extension, no Privacy & Security prompt, no
Apple-Silicon Reduced-Security dance. The .app launches
cleanly even if FUSE-T isn't installed yet (you just
can't use mount until you install it). Uses an NFS-
over-loopback transport with NO authentication on the
loopback port
- on a multi-user Mac, any other local
process can connect to the mount via NFSv4 and bypass
LUKSbox's permission model. Documented in
docs/MACOS_FUSE_T.md.
Fine for the common single-user-laptop case.

macFUSE variant (recommended for shared machines or
audit-required deployments):

  download: luksbox-v0.4.0-rc.3-aarch64-macos-macfuse.dmg
  install macFUSE FIRST (REQUIRED, see warning below):
      brew install --cask macfuse
      # then approve the kext under System Settings
      # -> Privacy & Security and reboot. On Apple
      # Silicon also: Recovery Mode -> Startup Security
      # Utility -> Reduced Security.
  then drag LUKSbox.app onto Applications.

IMPORTANT: this variant transitively links macFUSE's
MFMount.framework. If macFUSE is NOT installed when you
try to launch LUKSbox.app, macOS kills the process
before it can show any UI
(dyld: Library not loaded
error). Install macFUSE first, then the LUKSbox.app.
Uses macFUSE's /dev/macfuse* device-node permissions
for the kernel<->FS channel, which restricts access to
the mounting UID - the better local-attacker model.

Verify which backend a given .app uses:

  /Applications/LUKSbox.app/Contents/MacOS/luksbox --version
  # luksbox X.Y.Z
  # FUSE backend: fuse-t (...)   <- FUSE-T variant
  # FUSE backend: macfuse (...)  <- macFUSE variant

macOS (Apple Silicon), portable .tar.gz: also two
variants, -fuset-portable.tar.gz and -macfuse-portable.tar.gz,
same backend split as the .dmgs. Ships the bare CLI +
GUI binaries (bin/luksbox, bin/luksbox-gui) with
their dylib closure under Frameworks/. Run in place:
./bin/luksbox --help or ./bin/luksbox-gui &. No
.app, no Gatekeeper warning, no quarantine xattr to
clear (when extracted via Terminal). See
README-MACOS.txt inside for the full layout + caveats.

First launch: the .dmg is codesigned with the
Penthertz Apple Developer ID Application certificate
(team 456J2U7HQL) and Apple-notarised
, with the
notarisation ticket stapled to the bundle. macOS shows
the standard "downloaded from internet, are you sure?"
prompt that every Mac shows for any downloaded app -
click Open and you're set. Subsequent launches are
silent. No Gatekeeper override and no
xattr -dr com.apple.quarantine workaround needed.

Verify the signature and notarisation locally:

# Signature: identity + chain trust
codesign --verify --deep --strict --verbose=2 \
    /Applications/LUKSbox.app

# Notarisation: ticket present + valid
spctl --assess --type execute --verbose \
    /Applications/LUKSbox.app
# expects: "accepted, source=Notarized Developer ID"

You can additionally verify the .dmg SHA-256 against
the table at the top of these release notes for an
independent integrity check that doesn't depend on
Apple's PKI.

macOS (Intel): not shipped, build from source with
cargo build --profile release-hardened on an Intel Mac
with brew install libfido2 (the release-hardened
profile matches the hardening flags used for the shipped
Apple-Silicon binary). The CI matrix entry for
x86_64-apple-darwin is commented out in
.github/workflows/release.yml, GitHub's macos-13
runner has been intermittently blocking releases.

Windows (x86_64), recommended: download
luksbox-v0.4.0-rc.3-x86_64-windows-setup.exe,
double-click. The bootstrapper installs WinFsp 2.0.23075
(if not already present) AND LUKSbox in one wizard.
Unattended deploy: LUKSboxSetup.exe /quiet. To skip
WinFsp (e.g., you manage it via Group Policy):
LUKSboxSetup.exe InstallWinFsp=0. WinFsp is bundled
under its non-GPL-app linking exception; full license
ships as LICENSE-WINFSP.txt in the install dir.

Windows (x86_64), IT-admin / bare MSI: download
luksbox-v0.4.0-rc.3-x86_64-windows.msi. This
MSI does not include WinFsp; install WinFsp 2.x
separately from https://winfsp.dev/rel/ first
(LUKSbox statically links winfsp-x64.dll and the MSI
refuses to install without it). For unattended deploy
behind Group Policy / SCCM / Intune where WinFsp is
managed as a separate dependency, this is the right
artifact. Otherwise the -setup.exe above is easier.

Windows (x86_64), portable: unzip
luksbox-v0.4.0-rc.3-x86_64-windows.zip
and run the .exe in place. No installation, no Start
menu entry, no PATH change. Same binaries as the MSI.
Because nothing was added to PATH, you must either
(a) run from a shell where <WinFspInstall>\bin is on
PATH, or (b) drop a copy of winfsp-x64.dll next to
luksbox.exe in the unzipped folder.

libfido2 is statically linked into the .exe; no runtime
install needed for FIDO2.

See the Verify your download section at the top for
checksum verification commands.

Full Changelog: v0.4.0-rc.2...v0.4.0-rc.3

Don't miss a new LUKSbox release

NewReleases is sending notifications on new releases.