Skip to content

mount: add passcommand mount option, fixes #6804 - #10508

Open
ThomasWaldmann wants to merge 1 commit into
borgbackup:masterfrom
ThomasWaldmann:mount-passcommand
Open

ThomasWaldmann wants to merge 1 commit into
borgbackup:masterfrom
ThomasWaldmann:mount-passcommand

Conversation

@ThomasWaldmann

@ThomasWaldmann ThomasWaldmann commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Fixes #6804.

fstab and autofs entries (fuse.borgfs) can only give mount options, not environment variables. So an encrypted repository could only be mounted from there by setting BORG_PASSCOMMAND / BORG_PASSPHRASE for the whole automount daemon (or the systemd unit), i.e. the same passphrase source for all mounts.

-o passcommand=CMD works like BORG_PASSCOMMAND=CMD, e.g.:

/path/to/repo /mnt/point fuse.borgfs defaults,noauto,passcommand=/usr/local/sbin/borg-pass-backup1 0 0
  • The key (and thus the passphrase) is loaded by @with_repository before the other mount options are processed in parse_mount_options(), so do_mount() moves the option from args.options to BORG_PASSCOMMAND before the repository is opened. It is not passed on to libfuse. The command then runs exactly as BORG_PASSCOMMAND does (shlex-split, no shell), before daemonizing, so errors still reach mount(8) / autofs.
  • Like the passphrase environment variables, it is mutually exclusive with BORG_PASSPHRASE, BORG_PASSCOMMAND and BORG_PASSPHRASE_FD (error instead of guessing). An empty passcommand is an error, too.
  • As mount options are separated by commas, the command can not contain a comma; the docs recommend a script without arguments.
  • There is deliberately no mount option for the passphrase itself: mount options are visible to other users (world-readable /etc/fstab and autofs maps, the ps output of the borgfs daemon for the whole mount lifetime, systemd-fstab-generator units, autofs debug logs). A command is not a secret, its output is.

Docs: borg mount --help (fstab paragraph) and the BORG_PASSCOMMAND entry of borg help env.

Tests: unit tests for use_passcommand_mount_option() (moved + removed, not given, empty, exclusive with each env var) and a FUSE test mounting with -o passcommand=... and BORG_PASSPHRASE unset (runs in Linux CI; local FUSE tests do not work on macOS 27). Locally checked that borg mount and borgfs with a wrong passcommand fail with "Passphrase ... is incorrect" before mounting, and with BORG_PASSPHRASE also set fail with the mutual exclusion error.

Independent of #10505 (other mount options); both touch mount_cmds.py, but different hunks.

🤖 Generated with Claude Code

fstab and autofs entries can only give mount options, not environment
variables, so an encrypted repository could not be mounted from there
without setting BORG_PASSCOMMAND for the whole automount daemon.

-o passcommand=CMD works like BORG_PASSCOMMAND=CMD. It is applied before
the repository is opened (the key is loaded before the other mount
options are processed) and is not passed on to libfuse. Like the
passphrase environment variables, it is mutually exclusive with them.

There is deliberately no mount option for the passphrase itself: mount
options are visible to other users (/etc/fstab, ps output, systemd
mount units, autofs logs).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ThomasWaldmann ThomasWaldmann changed the title mount: add passcommand mount option mount: add passcommand mount option, fixes #6804 Oct 7, 2026
@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.12%. Comparing base (7e3d305) to head (9c08f32).
⚠️ Report is 7 commits behind head on master.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #10508      +/-   ##
==========================================
- Coverage   89.12%   89.12%   -0.01%     
==========================================
  Files         103      103              
  Lines       19783    19799      +16     
  Branches     3099     3103       +4     
==========================================
+ Hits        17631    17645      +14     
- Misses       1490     1492       +2     
  Partials      662      662              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

borgfs mount via /etc/fstab - how to give the passphrase?

1 participant