Repository navigation
mount: add passcommand mount option, fixes #6804 - #10508
Open
ThomasWaldmann wants to merge 1 commit into
Open
ThomasWaldmann wants to merge 1 commit into
ThomasWaldmann wants to merge 1 commit into
Conversation
fstab and autofs entries can only give mount options, not environment variables, so an encrypted repository could not be mounted from there without setting BORG_PASSCOMMAND for the whole automount daemon. -o passcommand=CMD works like BORG_PASSCOMMAND=CMD. It is applied before the repository is opened (the key is loaded before the other mount options are processed) and is not passed on to libfuse. Like the passphrase environment variables, it is mutually exclusive with them. There is deliberately no mount option for the passphrase itself: mount options are visible to other users (/etc/fstab, ps output, systemd mount units, autofs logs). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThomasWaldmann
force-pushed
the
mount-passcommand
branch
from
October 7, 2026 10:01
45a4504 to
9c08f32
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #10508 +/- ##
==========================================
- Coverage 89.12% 89.12% -0.01%
==========================================
Files 103 103
Lines 19783 19799 +16
Branches 3099 3103 +4
==========================================
+ Hits 17631 17645 +14
- Misses 1490 1492 +2
Partials 662 662 ☔ View full report in Codecov by Harness. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #6804.
fstab and autofs entries (
fuse.borgfs) can only give mount options, not environment variables. So an encrypted repository could only be mounted from there by settingBORG_PASSCOMMAND/BORG_PASSPHRASEfor the whole automount daemon (or the systemd unit), i.e. the same passphrase source for all mounts.-o passcommand=CMDworks likeBORG_PASSCOMMAND=CMD, e.g.:@with_repositorybefore the other mount options are processed inparse_mount_options(), sodo_mount()moves the option fromargs.optionstoBORG_PASSCOMMANDbefore the repository is opened. It is not passed on to libfuse. The command then runs exactly asBORG_PASSCOMMANDdoes (shlex-split, no shell), before daemonizing, so errors still reach mount(8) / autofs.BORG_PASSPHRASE,BORG_PASSCOMMANDandBORG_PASSPHRASE_FD(error instead of guessing). An emptypasscommandis an error, too.psoutput of the borgfs daemon for the whole mount lifetime, systemd-fstab-generator units, autofs debug logs). A command is not a secret, its output is.Docs:
borg mount --help(fstab paragraph) and theBORG_PASSCOMMANDentry ofborg help env.Tests: unit tests for
use_passcommand_mount_option()(moved + removed, not given, empty, exclusive with each env var) and a FUSE test mounting with-o passcommand=...andBORG_PASSPHRASEunset (runs in Linux CI; local FUSE tests do not work on macOS 27). Locally checked thatborg mountandborgfswith a wrong passcommand fail with "Passphrase ... is incorrect" before mounting, and withBORG_PASSPHRASEalso set fail with the mutual exclusion error.Independent of #10505 (other mount options); both touch
mount_cmds.py, but different hunks.🤖 Generated with Claude Code