Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package disk-encryption-tool for
openSUSE:Factory checked in at 2026-09-29 17:47:35
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/disk-encryption-tool (Old)
and /work/SRC/openSUSE:Factory/.disk-encryption-tool.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "disk-encryption-tool"
Tue Sep 29 17:47:35 2026 rev:23 rq:1381187 version:1+git20260928.f64eda7
Changes:
--------
---
/work/SRC/openSUSE:Factory/disk-encryption-tool/disk-encryption-tool.changes
2026-08-28 19:47:12.490611201 +0200
+++
/work/SRC/openSUSE:Factory/.disk-encryption-tool.new.383539/disk-encryption-tool.changes
2026-09-29 17:48:28.518948715 +0200
@@ -1,0 +2,6 @@
+Mon Sep 28 14:03:52 UTC 2026 - Alberto Planas Dominguez <[email protected]>
+
+- Update to version 1+git20260928.f64eda7:
+ * Name encrypted devices following the DPS document
+
+-------------------------------------------------------------------
Old:
----
disk-encryption-tool-1+git20260827.0550628.obscpio
New:
----
disk-encryption-tool-1+git20260928.f64eda7.obscpio
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ disk-encryption-tool.spec ++++++
--- /var/tmp/diff_new_pack.5zCwYQ/_old 2026-09-29 17:48:29.711998625 +0200
+++ /var/tmp/diff_new_pack.5zCwYQ/_new 2026-09-29 17:48:29.713998709 +0200
@@ -18,7 +18,7 @@
Name: disk-encryption-tool
-Version: 1+git20260827.0550628
+Version: 1+git20260928.f64eda7
Release: 0
Summary: Tool to reencrypt kiwi raw images
License: MIT
++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.5zCwYQ/_old 2026-09-29 17:48:29.753000341 +0200
+++ /var/tmp/diff_new_pack.5zCwYQ/_new 2026-09-29 17:48:29.756000466 +0200
@@ -1,6 +1,6 @@
<servicedata>
<service name="tar_scm">
<param
name="url">https://github.com/openSUSE/disk-encryption-tool.git</param>
- <param
name="changesrevision">055062883d5c0071cb507970728949a816618501</param></service></servicedata>
+ <param
name="changesrevision">f64eda71e45706d62ae099f91e0759d4fe87e47a</param></service></servicedata>
(No newline at EOF)
++++++ disk-encryption-tool-1+git20260827.0550628.obscpio ->
disk-encryption-tool-1+git20260928.f64eda7.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/disk-encryption-tool-1+git20260827.0550628/disk-encryption-tool
new/disk-encryption-tool-1+git20260928.f64eda7/disk-encryption-tool
--- old/disk-encryption-tool-1+git20260827.0550628/disk-encryption-tool
2026-08-27 13:57:27.000000000 +0200
+++ new/disk-encryption-tool-1+git20260928.f64eda7/disk-encryption-tool
2026-09-28 15:45:39.000000000 +0200
@@ -17,8 +17,8 @@
is_generated=1
is_rootfs=1
switched_rw=
-cr_name=
-cr_dev=
+volume_name=
+volume_dev=
blkdev=
blkpart=
mp=
@@ -42,8 +42,8 @@
while read -r line; do
eval "$line"
mapfile -td, options < <(echo -n "$OPTIONS")
- if [ -n "$cr_dev" ] && [ "$SOURCE" = "$blkpart"
]; then
- SOURCE="$cr_dev"
+ if [ -n "$volume_dev" ] && [ "$SOURCE" =
"$blkpart" ]; then
+ SOURCE="$volume_dev"
fi
mount "$SOURCE" "$TARGET" -t "$FSTYPE" -o
"$OPTIONS"
done < "$tmpdir/mounts"
@@ -59,7 +59,7 @@
Usage: $0 [OPTIONS] [MOUNTPOINT|BLOCKDEV] [VOLUME_NAME]
Encrypt MOUNTPOINT or BLOCKDEV. If not specified, uses /sysroot
- Default VOLUME_NAME is cr_root
+ Default VOLUME_NAME is root
OPTIONS:
--verbose verbose
@@ -132,12 +132,12 @@
log_info "encrypt with options ${encrypt_options[*]}"
if [ -n "$password" ]; then
# XXX: hopefully we can use the kernel keyring in the future
here
- cryptsetup reencrypt --force-password --verbose --encrypt
"${encrypt_options[@]}" "$@" "${blkpart}" "$cr_name" <<<"$password"
+ cryptsetup reencrypt --force-password --verbose --encrypt
"${encrypt_options[@]}" "$@" "${blkpart}" "$volume_name" <<<"$password"
[ -z "$is_generated" ] || echo
'{"type":"enrollment-key","keyslots":["0"]}' | cryptsetup token import
"${blkpart}"
else
- cryptsetup reencrypt --batch-mode --verify-passphrase
--force-password --verbose --encrypt "${encrypt_options[@]}" "$@" "${blkpart}"
"$cr_name"
+ cryptsetup reencrypt --batch-mode --verify-passphrase
--force-password --verbose --encrypt "${encrypt_options[@]}" "$@" "${blkpart}"
"$volume_name"
fi
- cr_dev="/dev/mapper/$cr_name"
+ volume_dev="/dev/mapper/$volume_name"
}
make_rw()
@@ -178,12 +178,12 @@
esac
done
-[ -z "$1" ] && [ -e /etc/initrd-release ] && set -- /sysroot cr_root
+[ -z "$1" ] && [ -e /etc/initrd-release ] && set -- /sysroot root
{ [ -n "$1" ] && [ -n "$2" ]; } || helpandquit
-cr_name="$2"
-[ -e "/dev/mapper/$cr_name" ] && err "$cr_name exists. Exit."
+volume_name="$2"
+[ -e "/dev/mapper/$volume_name" ] && err "$volume_name exists. Exit."
if [ -d "$1" ] || [ -b "$1" ]; then
if [ -b "$1" ]; then
@@ -300,13 +300,13 @@
# Seems to be the only way to tell the kernel about a
# specific partition change
partx -u --nr "$partno" "$blkdev" || :
- cryptsetup resize "$cr_name" <<<"$password"
+ cryptsetup resize "$volume_name" <<<"$password"
fi
fi
if [ -n "$is_btrfs" ]; then
if [ -z "$mounted" ]; then
- mount -o rw "$cr_dev" "$tmpdir/mnt"
+ mount -o rw "$volume_dev" "$tmpdir/mnt"
mp="$tmpdir/mnt"
else
read -r line < "$tmpdir/mounts"
@@ -314,8 +314,8 @@
mapfile -td, options < <(echo -n "$OPTIONS")
for ((i=0;i<${#options};++i)); do [ "${options[i]}" = ro ] &&
options[i]=rw; done
OPTIONS="$(IFS=, eval echo '"${options[*]}"')"
- [ "$SOURCE" = "$blkpart" ] && SOURCE="$cr_dev"
- mount "$cr_dev" "$TARGET" -t "$FSTYPE" -o "$OPTIONS"
+ [ "$SOURCE" = "$blkpart" ] && SOURCE="$volume_dev"
+ mount "$volume_dev" "$TARGET" -t "$FSTYPE" -o "$OPTIONS"
mp="$TARGET"
fi
@@ -327,12 +327,12 @@
make_rw "$root_mp"
elif [ -n "$is_swap" ]; then
declare loop_UUID
- eval "$(blkid -c /dev/null -o export "$cr_dev"|sed 's/^/loop_/')"
+ eval "$(blkid -c /dev/null -o export "$volume_dev"|sed 's/^/loop_/')"
if [ -n "$loop_UUID" ]; then
- mkswap --uuid "$loop_UUID" "$cr_dev"
+ mkswap --uuid "$loop_UUID" "$volume_dev"
else
warn "Can't determine device UUID. Can't recreate swap with
same UUID"
- mkswap "$cr_dev"
+ mkswap "$volume_dev"
fi
fi
@@ -341,21 +341,24 @@
if [ -n "$loop_UUID" ]; then
opts=
if [ -z "$crypttab_options" ] || [ "$crypttab_options" = "auto" ]; then
- # cr_root and cr_etc are mounted early, in the
- # initrd. In openSUSE cr_var too because of the
- # SELinux re-labeling. Technically we do not need
- # x-initrd.attach here, as dracut is now able to
- # recognize this.
+ # root and etc are mounted early, in the initrd. In
+ # openSUSE var too because of the SELinux re-labeling.
+ # Technically we do not need x-initrd.attach here, as
+ # dracut is now able to recognize this.
+ #
+ # "root" is the name that the Discoverable Partitions
+ # Specification sets, and "cr_root" the one used
+ # before.
#
# https://systemd.io/MOUNT_REQUIREMENTS/
- if [ "$cr_name" = "cr_root" ]; then
+ if [ "$volume_name" = "root" ] || [ "$volume_name" = "cr_root"
]; then
opts="x-initrd.attach"
fi
elif [ "$crypttab_options" != "none" ]; then
opts="$crypttab_options"
fi
- [ -n "$opts" ] && echo "$cr_name UUID=$loop_UUID none $opts" >>
"$root_mp"/etc/crypttab
- [ -z "$opts" ] && echo "$cr_name UUID=$loop_UUID none" >>
"$root_mp"/etc/crypttab
+ [ -n "$opts" ] && echo "$volume_name UUID=$loop_UUID none $opts" >>
"$root_mp"/etc/crypttab
+ [ -z "$opts" ] && echo "$volume_name UUID=$loop_UUID none" >>
"$root_mp"/etc/crypttab
else
warn "Can't determine device UUID. Can't generate crypttab"
fi
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/disk-encryption-tool-1+git20260827.0550628/disk-encryption-tool-dracut
new/disk-encryption-tool-1+git20260928.f64eda7/disk-encryption-tool-dracut
--- old/disk-encryption-tool-1+git20260827.0550628/disk-encryption-tool-dracut
2026-08-27 13:57:27.000000000 +0200
+++ new/disk-encryption-tool-1+git20260928.f64eda7/disk-encryption-tool-dracut
2026-09-28 15:45:39.000000000 +0200
@@ -70,20 +70,20 @@
fi
if [ "$inhibitor" != $'\e' ]; then
root_device="$(findmnt -nvo SOURCE /sysroot)"
- root_cr_name="cr_root"
+ root_volume_name="root"
root_options="auto"
if get_credentials partitions disk-encryption-tool-dracut.partitions;
then
for line in "${partitions[@]}"; do
- read -r cr_name device options <<<"$line"
- [ "$device" = "$root_device" ] &&
root_cr_name="$cr_name" && root_options="$options" && continue
+ read -r volume_name device options <<<"$line"
+ [ "$device" = "$root_device" ] &&
root_volume_name="$volume_name" && root_options="$options" && continue
echo "Encrypt $device"
- /usr/bin/disk-encryption-tool --keyring cryptenroll
--options "${options:-auto}" --root /sysroot "$device" "$cr_name" || die
"Encryption failed"
+ /usr/bin/disk-encryption-tool --keyring cryptenroll
--options "${options:-auto}" --root /sysroot "$device" "$volume_name" || die
"Encryption failed"
clean_growpart_flag "$device"
done
fi
if [ "$root_options" != "skip" ]; then
echo "Encrypt /sysroot"
- /usr/bin/disk-encryption-tool --keyring cryptenroll --options
"${root_options:-auto}" "/sysroot" "$root_cr_name" || die "Encryption failed"
+ /usr/bin/disk-encryption-tool --keyring cryptenroll --options
"${root_options:-auto}" "/sysroot" "$root_volume_name" || die "Encryption
failed"
clean_growpart_flag "$root_device"
fi
fi
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/disk-encryption-tool-1+git20260827.0550628/test/testscript
new/disk-encryption-tool-1+git20260928.f64eda7/test/testscript
--- old/disk-encryption-tool-1+git20260827.0550628/test/testscript
2026-08-27 13:57:27.000000000 +0200
+++ new/disk-encryption-tool-1+git20260928.f64eda7/test/testscript
2026-09-28 15:45:39.000000000 +0200
@@ -68,15 +68,15 @@
trap '[ $? -eq 0 ] || poweroff -f' EXIT
findmnt
lsblk
-if [ "$(findmnt -nrvo SOURCE /)" != "/dev/mapper/cr_root" ]; then
+if [ "$(findmnt -nrvo SOURCE /)" != "/dev/mapper/root" ]; then
echo "Not encrypted?"
exit 1
fi
-# The root filesystem is on /dev/mapper/cr_root whether the enrollment
+# The root filesystem is on /dev/mapper/root whether the enrollment
# ran or not, opened by the key that disk-encryption-tool generated, so
# the check above says nothing about it. The credential asked for
# "linux" as an extra password, and only the device can confirm it
-backing="$(cryptsetup status cr_root | sed -n 's,^ *device: *,,p')"
+backing="$(cryptsetup status root | sed -n 's,^ *device: *,,p')"
systemd-cryptenroll "$backing"
if ! printf 'linux' | cryptsetup luksOpen --test-passphrase "$backing"; then
echo "The password credential was not enrolled"
++++++ disk-encryption-tool.obsinfo ++++++
--- /var/tmp/diff_new_pack.5zCwYQ/_old 2026-09-29 17:48:29.898006407 +0200
+++ /var/tmp/diff_new_pack.5zCwYQ/_new 2026-09-29 17:48:29.904006658 +0200
@@ -1,5 +1,5 @@
name: disk-encryption-tool
-version: 1+git20260827.0550628
-mtime: 1787831847
-commit: 055062883d5c0071cb507970728949a816618501
+version: 1+git20260928.f64eda7
+mtime: 1790603139
+commit: f64eda71e45706d62ae099f91e0759d4fe87e47a