github PentHertz/LUKSbox v0.6.0-rc.1

pre-release2 hours ago

Verify your download

Cryptographic provenance (GitHub / Sigstore attestation)

Every artifact below is signed via GitHub Artifact
Attestations
,
which uses Sigstore under the hood. The signature proves
the artifact was produced by this exact workflow run on
this exact commit SHA, no human had a chance to swap it
after the fact.

Verify with the GitHub CLI (one-liner):

# Install gh once if you don't have it:
#   sudo apt install gh   |   sudo dnf install gh   |   brew install gh
gh attestation verify <downloaded-file> --owner penthertz
# Prints "Loaded digest ..." then "PASS" with the
# workflow run + commit SHA the artifact came from.

Offline check (no gh needed)

Every artifact also has a SHA-256 in SHA256SUMS.txt
(attached to this release):

# Linux / macOS:
sha256sum -c SHA256SUMS.txt   # Linux
shasum -a 256 -c SHA256SUMS.txt   # macOS
# Windows (PowerShell):
Get-FileHash luksbox-*.msi -Algorithm SHA256
# then compare to the `*.msi` row in SHA256SUMS.txt

Trust chain summary

Artifacts on this release page are uploaded only by the
GitHub Actions release workflow that ran on this tagged
commit (.github/workflows/release.yml in the repo).
The commit itself is GPG-signed by the maintainer, the
upload uses GitHub's OIDC release token, and the
Sigstore attestation above pins the signature to that
workflow run. GPG-signed release tarballs
(SHA256SUMS.txt.asc) and full SLSA L3 provenance are
on the roadmap.

For at-a-glance SHA-256 checking against the published
values:

File SHA-256
LUKSbox-aarch64.AppImage 257a17f7009f13fa258e4ec13cbeb2c72444e42683101e6f43ea94e195d71894
LUKSbox-x86_64.AppImage c3556b7c87175c746c2b4740e2ed1efe8c4e0537b5221722c4909d5faf1480c9
luksbox-0.6.0-rc.1-1.aarch64.rpm fa9e6cef4a69034943c654fbeb7341f5419d046ffffcb70b43e6c2abb296b0ee
luksbox-0.6.0-rc.1-1.x86_64.rpm 81ebbd1081cd3c68f11b2e5587907e2cbc7b607a94057a8d1eda45475315870e
luksbox-aarch64-unknown-linux-musl.tar.gz 4897e67fe53561893c317d3ec1c0dfad8449011190a6dd969aa7bd37637a72de
luksbox-v0.6.0-rc.1-aarch64-linux-jammy.tar.gz e0f7cf28eaa9b0481f9c7aba6aae9c5e46e51fe290b3989ee4e207386ebb4b73
luksbox-v0.6.0-rc.1-aarch64-linux-musl-static.tar.gz 4897e67fe53561893c317d3ec1c0dfad8449011190a6dd969aa7bd37637a72de
luksbox-v0.6.0-rc.1-aarch64-linux-noble.tar.gz 032ea80135ef670806fcfe02e1bd0e023360b31016a43b3093059d96fc12aec4
luksbox-v0.6.0-rc.1-aarch64-linux-resolute.tar.gz 82370f7ab132e3dd7bad5e5af507c742a6ba217cc7e051830b0f63e64e5229c6
luksbox-v0.6.0-rc.1-aarch64-linux-trixie.tar.gz 620408c2477c29b2ad3048f2cbb0360b75330b6857313e655dc9254db0b0449e
luksbox-v0.6.0-rc.1-aarch64-macos-fuset-portable.tar.gz c245f10eda37c5db91036149ba365013f8e2df4f1e56e434bc4f783d211992c5
luksbox-v0.6.0-rc.1-aarch64-macos-fuset.dmg 84c4fbd176a02e7555c9b7e192ad15b7764dbed75d566fc944d9ce1a8241f24d
luksbox-v0.6.0-rc.1-aarch64-macos-macfuse-portable.tar.gz 1b8681d199147f0258f2aaf4916c2988931235e277162205953d506e85546736
luksbox-v0.6.0-rc.1-aarch64-macos-macfuse.dmg 4fadcd06441b769f3368c9da2a76d7a20908641183967481683299b09ba5fb42
luksbox-v0.6.0-rc.1-aarch64.AppImage 257a17f7009f13fa258e4ec13cbeb2c72444e42683101e6f43ea94e195d71894
luksbox-v0.6.0-rc.1-x86_64-linux-jammy.tar.gz 5a7157763d5a2c6efd2b6552a46d34edf55121c05bfe8f5c7ad7389fc4361a99
luksbox-v0.6.0-rc.1-x86_64-linux-musl-static.tar.gz cc921688aaee6933f24f99a0f5d589ca901a827f0e59482cc66cc1ca3d5da5e0
luksbox-v0.6.0-rc.1-x86_64-linux-noble.tar.gz 6299d6ac354d10323a66c437cd6afb058c99f3207690769ec825cf769a3aaf58
luksbox-v0.6.0-rc.1-x86_64-linux-resolute.tar.gz 619337ecbf2d9915a9e9e8d41d599371034bec49acc5d0647f4a895a0dc3575b
luksbox-v0.6.0-rc.1-x86_64-linux-trixie.tar.gz ed6eb8fa9a70dd41fa36f88b9ebcde05267a98bb194b02426a935d962fcb8723
luksbox-v0.6.0-rc.1-x86_64-windows-setup.exe d6a0f15e8d12cbdfbaed51f8b88d4da367531f02745767490214aa4e54a4981b
luksbox-v0.6.0-rc.1-x86_64-windows.msi 1f48c6e8eccc12b2b848db1a88587eef780f8b9ee462968317c2c5795227a120
luksbox-v0.6.0-rc.1-x86_64-windows.zip 3cc5232ff03ca40ab83a6dea7c74006d48485fa0387ed7dc866b10ed96bdfc2d
luksbox-v0.6.0-rc.1-x86_64.AppImage c3556b7c87175c746c2b4740e2ed1efe8c4e0537b5221722c4909d5faf1480c9
luksbox-x86_64-unknown-linux-musl.tar.gz cc921688aaee6933f24f99a0f5d589ca901a827f0e59482cc66cc1ca3d5da5e0
luksbox_0.6.0~rc.1-1_jammy_amd64.deb a62cd469dad6ea820b803e1d2a0a87498fc310d56a0febba945febbe67523e58
luksbox_0.6.0~rc.1-1_jammy_arm64.deb 8cada111d0ee7db2dcc8d918dfd83859d33293de901023cf97c4f6c33ae47d82
luksbox_0.6.0~rc.1-1_noble_amd64.deb 23700d06b828a6dc4851360f25e10597e58f9ded8a46412c8efd26b0c946f26a
luksbox_0.6.0~rc.1-1_noble_arm64.deb c0367cf03254ee2762429746d55f83802e3d3b662312ee2085b42e7ccfb21514
luksbox_0.6.0~rc.1-1_resolute_amd64.deb e8b6239766b97ff1721e1856db6460c5d1f569427d264c4963315e02ab1bec45
luksbox_0.6.0~rc.1-1_resolute_arm64.deb 513bd0553743c047871553e3f9454b9c802087d2f8e9f92975b1bee00c142a27
luksbox_0.6.0~rc.1-1_trixie_amd64.deb ae733b74c9b24c0e201c34d95dd9c3bc8e550c5583ed527731021d5d1d86e892
luksbox_0.6.0~rc.1-1_trixie_arm64.deb 4c5b7e0069087577b745482c387251cb752997d90dfce62e609f26afa54da77b

Install

Linux (Ubuntu 22.04, Debian 11/12, Mint 21.x, .deb):
download luksbox_*_jammy_amd64.deb (or _arm64) and
install with sudo apt install ./luksbox_*_jammy_amd64.deb.
Pulls in libfido2-1, libfuse3-3, and libtss2-*
automatically. Registers a luksbox-gui desktop
launcher and a MIME type for .lbx files.

Linux (Ubuntu 24.04 noble, .deb):
download luksbox_*_noble_amd64.deb (or _arm64) and
install with sudo apt install ./luksbox_*_noble_amd64.deb.
Same package layout as the jammy build, but with
t64-transitioned dependency names (libssl3t64,
libfido2-1t64, libtss2-mu-4.0.1-0t64, etc.). The
jammy and noble .deb files cannot be installed
interchangeably, the dependency names differ.

Linux (Debian 13 trixie / Ubuntu 26.04 resolute, .deb):
these distros bump shared-library sonames again past
noble, so they get their own builds. Download
luksbox_*_trixie_amd64.deb on Debian 13 or
luksbox_*_resolute_amd64.deb on Ubuntu 26.04 (or the
matching _arm64) and install with sudo apt install ./<file>. Each .deb's dependency names are resolved
against its own distro, so install the one matching your
release rather than the noble build.

Linux (Fedora / RHEL / Rocky / Alma, .rpm): download
luksbox-*.x86_64.rpm (or aarch64.rpm) and install
with sudo dnf install ./luksbox-*.x86_64.rpm (or
sudo rpm -i). One .rpm covers every rpm-based
distro, RPM uses SONAMEs for shared-library
dependencies which are stable across releases.
Pulls in libfido2 and fuse3-libs automatically.

Linux (x86_64, generic tarball): tar xzf luksbox-v0.6.0-rc.1-x86_64-linux-jammy.tar.gz && cd luksbox-v0.6.0-rc.1-x86_64-linux-jammy && ./install.sh
For Arch / NixOS / Alpine / any non-deb non-rpm distro.
The jammy variant has the broadest glibc compatibility;
if you are on a very recent distro and prefer the noble
build, swap -jammy for -noble in the filename.
Installs to ~/.local/bin and registers a desktop launcher.
Use ./install.sh --system for system-wide install, or
./install.sh --uninstall to remove. Requires
libfido2-1 (and libfuse3-3 for mount):
sudo apt install libfido2-1 libfuse3-3 (Debian/Ubuntu)
or sudo dnf install libfido2 fuse3-libs (Fedora/RHEL).

Linux (aarch64): tar xzf luksbox-v0.6.0-rc.1-aarch64-linux-jammy.tar.gz && cd luksbox-v0.6.0-rc.1-aarch64-linux-jammy && ./install.sh
Same runtime deps and installer as x86_64. Built natively
on a GitHub ARM64 runner, no QEMU emulation. Same
jammy/noble distinction applies as for the .deb above.

Linux (any distro, GUI, AppImage): download
luksbox-v0.6.0-rc.1-x86_64.AppImage (or
-aarch64.AppImage), chmod +x it and run it. Nothing to
install; libfido2 / libcbor / libcrypto are bundled, glibc
2.35+ (Ubuntu 22.04, Debian 12, Fedora 36 or newer) and
the desktop's graphics stack come from the host. mount
needs fusermount3 (package fuse3). The same files are
also published as LUKSbox-x86_64.AppImage /
LUKSbox-aarch64.AppImage for stable download links.

Linux (any distro, CLI only, static): tar xzf luksbox-v0.6.0-rc.1-x86_64-linux-musl-static.tar.gz
(or aarch64) and copy the single luksbox binary onto
your PATH. Fully static (musl), no shared-library
dependency at all; includes the TUI wizard and mount
(needs fusermount3), but not FIDO2 or TPM 2.0 keyslots.
Also published as luksbox-x86_64-unknown-linux-musl.tar.gz
/ luksbox-aarch64-unknown-linux-musl.tar.gz.

macOS (Apple Silicon): two .dmg variants, one per
FUSE backend. Pick one based on which FUSE provider you
want to install. Both .dmgs are otherwise identical
(same crypto, same on-disk format, same UI); the
difference is what luksbox mount calls under the hood
and whether you need a kernel extension.

FUSE-T variant (recommended for personal laptops):

  download: luksbox-v0.6.0-rc.1-aarch64-macos-fuset.dmg
  install FUSE-T first:
      brew tap macos-fuse-t/homebrew-cask
      brew install --cask fuse-t
  then drag LUKSbox.app onto Applications.

No kernel extension, no Privacy & Security prompt, no
Apple-Silicon Reduced-Security dance. The .app launches
cleanly even if FUSE-T isn't installed yet (you just
can't use mount until you install it). Uses an NFS-
over-loopback transport with NO authentication on the
loopback port
- on a multi-user Mac, any other local
process can connect to the mount via NFSv4 and bypass
LUKSbox's permission model. Documented in
docs/MACOS_FUSE_T.md.
Fine for the common single-user-laptop case.

macFUSE variant (recommended for shared machines or
audit-required deployments):

  download: luksbox-v0.6.0-rc.1-aarch64-macos-macfuse.dmg
  install macFUSE FIRST (REQUIRED, see warning below):
      brew install --cask macfuse
      # then approve the kext under System Settings
      # -> Privacy & Security and reboot. On Apple
      # Silicon also: Recovery Mode -> Startup Security
      # Utility -> Reduced Security.
  then drag LUKSbox.app onto Applications.

IMPORTANT: this variant transitively links macFUSE's
MFMount.framework. If macFUSE is NOT installed when you
try to launch LUKSbox.app, macOS kills the process
before it can show any UI
(dyld: Library not loaded
error). Install macFUSE first, then the LUKSbox.app.
Uses macFUSE's /dev/macfuse* device-node permissions
for the kernel<->FS channel, which restricts access to
the mounting UID - the better local-attacker model.

Verify which backend a given .app uses:

  /Applications/LUKSbox.app/Contents/MacOS/luksbox --version
  # luksbox X.Y.Z
  # FUSE backend: fuse-t (...)   <- FUSE-T variant
  # FUSE backend: macfuse (...)  <- macFUSE variant

macOS (Apple Silicon), portable .tar.gz: also two
variants, -fuset-portable.tar.gz and -macfuse-portable.tar.gz,
same backend split as the .dmgs. Ships the bare CLI +
GUI binaries (bin/luksbox, bin/luksbox-gui) with
their dylib closure under Frameworks/. Run in place:
./bin/luksbox --help or ./bin/luksbox-gui &. No
.app, no Gatekeeper warning, no quarantine xattr to
clear (when extracted via Terminal). See
README-MACOS.txt inside for the full layout + caveats.

First launch: the .dmg is codesigned with the
Penthertz Apple Developer ID Application certificate
(team 456J2U7HQL) and Apple-notarised
, with the
notarisation ticket stapled to the bundle. macOS shows
the standard "downloaded from internet, are you sure?"
prompt that every Mac shows for any downloaded app -
click Open and you're set. Subsequent launches are
silent. No Gatekeeper override and no
xattr -dr com.apple.quarantine workaround needed.

Verify the signature and notarisation locally:

# Signature: identity + chain trust
codesign --verify --deep --strict --verbose=2 \
    /Applications/LUKSbox.app

# Notarisation: ticket present + valid
spctl --assess --type execute --verbose \
    /Applications/LUKSbox.app
# expects: "accepted, source=Notarized Developer ID"

You can additionally verify the .dmg SHA-256 against
the table at the top of these release notes for an
independent integrity check that doesn't depend on
Apple's PKI.

macOS (Intel): not shipped, build from source with
cargo build --profile release-hardened on an Intel Mac
with brew install libfido2 (the release-hardened
profile matches the hardening flags used for the shipped
Apple-Silicon binary). The CI matrix entry for
x86_64-apple-darwin is commented out in
.github/workflows/release.yml, GitHub's macos-13
runner has been intermittently blocking releases.

Windows (x86_64), recommended: download
luksbox-v0.6.0-rc.1-x86_64-windows-setup.exe,
double-click. The bootstrapper installs WinFsp 2.0.23075
(if not already present) AND LUKSbox in one wizard.
Unattended deploy: LUKSboxSetup.exe /quiet. To skip
WinFsp (e.g., you manage it via Group Policy):
LUKSboxSetup.exe InstallWinFsp=0. WinFsp is bundled
under its non-GPL-app linking exception; full license
ships as LICENSE-WINFSP.txt in the install dir.

Windows (x86_64), IT-admin / bare MSI: download
luksbox-v0.6.0-rc.1-x86_64-windows.msi. This
MSI does not include WinFsp; install WinFsp 2.x
separately from https://winfsp.dev/rel/ first
(LUKSbox statically links winfsp-x64.dll and the MSI
refuses to install without it). For unattended deploy
behind Group Policy / SCCM / Intune where WinFsp is
managed as a separate dependency, this is the right
artifact. Otherwise the -setup.exe above is easier.

Windows (x86_64), portable: unzip
luksbox-v0.6.0-rc.1-x86_64-windows.zip
and run the .exe in place. No installation, no Start
menu entry, no PATH change. Same binaries as the MSI.
Because nothing was added to PATH, you must either
(a) run from a shell where <WinFspInstall>\bin is on
PATH, or (b) drop a copy of winfsp-x64.dll next to
luksbox.exe in the unzipped folder.

libfido2 is statically linked into the .exe; no runtime
install needed for FIDO2.

See the Verify your download section at the top for
checksum verification commands.

Full Changelog: v0.5.2...v0.6.0-rc.1

Don't miss a new LUKSbox release

NewReleases is sending notifications on new releases.