# Copyright 1999-2026 Gentoo Authors # Distributed under the terms of the GNU General Public License v2 EAPI=8 WX_GTK_VER="3.2-gtk3" inherit desktop eapi9-ver linux-info pax-utils toolchain-funcs wxwidgets xdg DESCRIPTION="Disk encryption with strong security based on TrueCrypt" HOMEPAGE="https://veracrypt.io/en/Home.html" SRC_URI="https://github.com/${PN}/VeraCrypt/archive/VeraCrypt_${PV}.tar.gz -> ${P}.tar.gz" S="${WORKDIR}/VeraCrypt-VeraCrypt_${PV}/src" # The modules not linked against in Linux include (but not limited to): # libzip, chacha-xmm, chacha256, chachaRng, rdrand, t1ha2 # Tested by actually removing the source files and performing a build # For this reason, we don't have to worry about their licenses LICENSE="Apache-2.0 BSD RSA truecrypt-3.0" SLOT="0" KEYWORDS="~amd64" IUSE="+asm cpu_flags_x86_aes cpu_flags_x86_sse2 doc gui" REQUIRED_USE="cpu_flags_x86_sse2? ( asm )" RESTRICT="bindist mirror" RDEPEND=" app-admin/sudo sys-apps/pcsc-lite sys-fs/fuse:3= sys-fs/lvm2 x11-libs/wxGTK:${WX_GTK_VER}= gui? ( x11-libs/wxGTK:${WX_GTK_VER}=[X] ) " DEPEND="${RDEPEND}" BDEPEND=" asm? ( dev-lang/yasm ) virtual/pkgconfig " CONFIG_CHECK="~BLK_DEV_DM ~CRYPTO ~CRYPTO_XTS ~DM_CRYPT ~FUSE_FS" PATCHES=( "${FILESDIR}"/${P}-fix-release-date.patch "${FILESDIR}"/${PN}-1.26.29-argon2-avx2-avx512f.patch "${FILESDIR}"/${PN}-1.26.29-fix-nosse2.patch ) src_prepare() { default # Respect *FLAGS sed -i -e 's/^.* += $(REPRODUCIBLE_/#&/' Makefile || die } src_configure() { setup-wxwidgets myemakeargs=( NOSTRIP=1 NOTEST=1 VERBOSE=1 WITHFUSE3=1 AR="$(tc-getAR)" CC="$(tc-getCC)" CXX="$(tc-getCXX)" RANLIB="$(tc-getRANLIB)" TC_EXTRA_CFLAGS="${CFLAGS}" TC_EXTRA_CXXFLAGS="${CXXFLAGS}" TC_EXTRA_LFLAGS="${LDFLAGS}" WX_CONFIG="${WX_CONFIG}" $(usex gui "" "NOGUI=1") ) # x86-specific options causing build failures on other arches if use x86 || use amd64; then myemakeargs+=( $(usev !asm "NOASM=1") $(usev !cpu_flags_x86_aes "NOAESNI=1") $(usev !cpu_flags_x86_sse2 "NOSSE2=1") ) fi } src_compile() { emake "${myemakeargs[@]}" } src_test() { ./Main/veracrypt --text --test || die "tests failed" } src_install() { local DOCS=( Readme.txt ) # TODO: install translations myemakeargs+=( INSTALL_UNINSTALLER=0 INSTALL_LICENSE=0 INSTALL_DOCS=0 INSTALL_LANGUAGES=0 INSTALL_APPIMAGE_FILES=0 ) if use gui; then myemakeargs+=( INSTALL_DESKTOP=1 INSTALL_MIME=1 INSTALL_ICONS=1 ) else myemakeargs+=( INSTALL_DESKTOP=0 INSTALL_MIME=0 INSTALL_ICONS=0 ) fi emake DESTDIR="${D}" "${myemakeargs[@]}" install if use doc; then DOCS+=( "${S}"/../doc/EFI-DCS ) docompress -x /usr/share/doc/${PF}/EFI-DCS HTML_DOCS=( "${S}"/../doc/html/. ) fi einstalldocs newinitd "${FILESDIR}"/veracrypt.init veracrypt pax-mark -m "${ED}"/usr/bin/veracrypt } pkg_postinst() { use gui && xdg_pkg_postinst ewarn "VeraCrypt has a very restrictive license. Please be explicitly aware" ewarn "of the limitations on redistribution of binaries or modified source." # Remove this when we remove veracrypt-1.25.9.ebuild from the tree. if ver_replacing -lt "1.26.7"; then ewarn "Starting with 1.26.7, TrueCrypt volumes are no longer supported." ewarn "Please explore alternatives such as dm-crypt to mount truecrypt volumes." ewarn "Moreover, support for RIPEMD160 and GOST89 is dropped." ewarn "Volumes using these algoritms will no longer mount." fi } pkg_postrm() { use gui && xdg_pkg_postrm }