Veracrypt error opening encrypted file - run0-sudo

I’m on a fresh Tumbleweed install (20260616 snapshot) but Veracrypt doesn’t open any encrypted file.

This error dialog appears after inserting the administrator password after the file password. Both are correct but still get this error.

Failed to obtain administrator privileges: run0-sudo: opção inválida -- "S"
run0-sudo: opção inválida -- "p"
run0-sudo - execute a command as another user via run0

usage: run0-sudo -h | -K | -k | -V
usage: run0-sudo -v [-g group] [-u user]
usage: run0-sudo [-EHkNnP] [-D directory] [-g group]
            [-u user] [VAR=value] [-i | -s] [command [arg ...]]

Options:
  -D, --chdir=<directory>   Change the working directory
  -E, --preserve-env        Preserve user environment
      --preserve-env=<list> Preserve specific environment variables
  -g, --group=<group>       Run command as specified group or GID
  -H, --set-home            Set HOME variable, default with run0
  -h, --help                Display help text and exit
  -i, --login               Run login shell as the target user
  -K, --remove-timestamp    Invalidate polkit keep
  -k, --reset-timestamp     Invalidate polkit keep
  -s, --shell               Run the specified shell
  -u, --user=user           Run command as specified user or UID
  -V, --version             Display version and exit
  -v, --validate            Update timestamp without running a command

Is there a bug in the package?

I’m using Veracrypt on that snapshot without any issues. I’m using it for a fully-encrypted device (3 actually), but without seeing the command you’re using, it’s difficult to diagnose.

So perhaps show the command you’re running so we can see what’s happening better. :slight_smile:

1 Like

The command is “veracrypt” or “/usr/bin/veracrypt %f” (xfce whisker menu icon) to open the gui. This is all in the gui.
Then select file → mount → enter file password → enter admin password → error

Sorry if I misunderstand.

The packages run0-wrappers and run0-policy-wheel-auth-self enables users in the wheel group to authenticate as root with their own password.

If you want the old behaviour (sudo with admin password), uninstall these two packages. Restart your box.

1 Like

No, I wasn’t asking how to use veracrypt (I use it and it works fine). I was specifically asking you to tell us what command you entered to get the output you got.

When posting command output, it’s best practice to include the command line you entered so we can see what you did to get the output:

$ veracrypt --help
Usage: veracrypt [--auto-mount <str>] [--backup-headers] [--background-task] [-C] [-c] [--create-keyfile] [--delete-token-keyfiles] [-d] [-u] [--emergency-unmount] [--display-password] [--encryption <str>] [--explore] [--export-token-keyfile] [--filesystem <str>] [-f] [--fs-options <str>] [--hash <str>] [-h] [--import-token-keyfiles] [-k <str>] [-l] [--list-token-keyfiles] [--list-securitytoken-keyfiles] [--list-emvtoken-keyfiles] [--load-preferences] [--mount] [-m <str>] [--new-hash <str>] [--new-keyfiles <str>] [--new-password <str>] [--new-pim <str>] [--non-interactive] [--stdin] [-p <str>] [--pim <str>] [--protect-hidden <str>] [--protection-hash <str>] [--protection-keyfiles <str>] [--protection-password <str>] [--protection-pim <str>] [--random-source <str>] [--restore-headers] [--save-preferences] [--quick] [--size <str>] [--slot <str>] [--test] [-t] [--token-lib <str>] [--token-pin <str>] [-v] [--version] [--volume-properties] [--volume-type <str>] [--no-size-check] [--legacy-password-maxlength] [--use-dummy-sudo-password] [--allow-insecure-mount] [Volume path] [Mount point]
  --auto-mount=<str>           	Auto mount device-hosted/favorite volumes
  --backup-headers             	Backup volume headers
  --background-task            	Start Background Task
  -C, --change                 	Change password or keyfiles
  -c, --create                 	Create new volume
  --create-keyfile             	Create new keyfile
  --delete-token-keyfiles      	Delete security token keyfiles
  -d, --dismount               	Unmount volume (deprecated: use 'unmount')
  -u, --unmount                	Unmount volume
  --emergency-unmount          	Attempt emergency cleanup if normal Linux unmount fails
  --display-password           	Display password while typing
  --encryption=<str>           	Encryption algorithm
  --explore                    	Open explorer window for mounted volume
  --export-token-keyfile       	Export keyfile from token
  --filesystem=<str>           	Filesystem type
  -f, --force                  	Force mount/unmount/overwrite
  --fs-options=<str>           	Filesystem mount options
  --hash=<str>                 	Header key derivation algorithm
  -h, --help                   	Display detailed command line help
  --import-token-keyfiles      	Import keyfiles to security token
  -k, --keyfiles=<str>         	Keyfiles
  -l, --list                   	List mounted volumes
  --list-token-keyfiles        	List token keyfiles
  --list-securitytoken-keyfiles	List security token keyfiles
  --list-emvtoken-keyfiles     	List EMV token keyfiles
  --load-preferences           	Load user preferences
  --mount                      	Mount volume interactively
  -m, --mount-options=<str>    	VeraCrypt volume mount options
  --new-hash=<str>             	New header key derivation algorithm
  --new-keyfiles=<str>         	New keyfiles
  --new-password=<str>         	New password
  --new-pim=<str>              	New PIM
  --non-interactive            	Do not interact with user
  --stdin                      	Read password from standard input
  -p, --password=<str>         	Password
  --pim=<str>                  	PIM
  --protect-hidden=<str>       	Protect hidden volume
  --protection-hash=<str>      	Header key derivation algorithm for protected hidden volume
  --protection-keyfiles=<str>  	Keyfiles for protected hidden volume
  --protection-password=<str>  	Password for protected hidden volume
  --protection-pim=<str>       	PIM for protected hidden volume
  --random-source=<str>        	Use file as source of random data
  --restore-headers            	Restore volume headers
  --save-preferences           	Save user preferences
  --quick                      	Enable quick format
  --size=<str>                 	Size in bytes
  --slot=<str>                 	Volume slot number
  --test                       	Test internal algorithms
  -t, --text                   	Use text user interface
  --token-lib=<str>            	Security token library
  --token-pin=<str>            	Security token PIN
  -v, --verbose                	Enable verbose output
  --version                    	Display version information
  --volume-properties          	Display volume properties
  --volume-type=<str>          	Volume type
  --no-size-check              	Disable check of container size against disk free space.
  --legacy-password-maxlength  	Use legacy maximum password length (64 UTF-8 bytes)
  --use-dummy-sudo-password    	Use dummy password in sudo to detect if it is already authenticated
  --allow-insecure-mount       	Allow mounting volumes on mount points that are in the user's PATH

For example. You’ll notice that I included my prompt and the command:

$ veracrypt --help

And then immediately afterwards the output.

That way there’s no need to guess what was typed to produce the output presented. With so many command-line options, it’s impossible to know what they are unless you tell us what you typed. :slight_smile:

I hope that provides clarity about what I was asking for.

@hendersj

I don’t want a less secure behaviour which I assume is the old way.

Besides when removing those packages it also removes packages that the system is relying on like the xfce4-power-manager.

I’ve added my user to the wheel group, restarted and still same error.

@hui

the command veracrypt --mount goes directly to what I’m trying to do and gets the error in the end.

The output of this error is a window dialog, not command line per se:

I didn’t have this problem in my previous Tumbleweed install (which ran for some years).

Again, you haven’t said what command you’re actually running to get that output. We can’t help you without knowing that.

What veracrypt version do you run, where is it coming from?

@tende - apologies, I misread what you said when you responded to the question of what command you were running - I see that you did answer that question, and I failed to recognize that. My mistake. :slight_smile:

I would apply the change that hui suggested as a test. Depending on what you’re ultimately trying to mount, you may not need root privileges to mount the device or file.

I’m using this repo: https://download.opensuse.org/repositories/security/openSUSE_Tumbleweed

Is that it?

Info on the package:

user@localhost:~> zypper info veracrypt
A obter dados do repositório...
A ler pacotes instalados...


Informação para pacote veracrypt:
---------------------------------
Repositório       : openSUSE_Tumbleweed for security
Nome              : veracrypt
Versão            : 1.26.29-6.1
Arch              : x86_64
Vendedor          : obs://build.opensuse.org/security
Tamanho Instalado : 6,0 MiB
Instalado         : Sim
Estado            : Actualizado
Pacotes fonte     : veracrypt-1.26.29-6.1.src
URL ascendente    : https://www.veracrypt.fr
Resumo            : Free disk encryption software based on TrueCrypt
Descrição         : 
    VeraCrypt is software for establishing and maintaining an
    on-the-fly-encrypted volume (data storage device).
    On-the-fly encryption means that data is automatically encrypted
    right before it is saved and decrypted right after it is loaded,
    without any user intervention. No data stored on an encrypted
    volume can be read (decrypted) without using the correct
    password/keyfile(s) or correct encryption keys. Entire file system
    is encrypted (e.g., file names, folder names, contents of every
    file, free space, meta data, etc).
    It is based on original TrueCrypt 7.1a with security enhancements
    and modifications.

That’s the one I’m using. I don’t have the run0 packages installed, and would suggest removing them since they’re creating an issue for you.

1 Like

I took the bullet and unninstalled the run0 packages.

For anyone doing that: you need to install sudo after unninstalling run0 (use su for that)

Then installed the packages that were unnistalled with run0-wrappers (xfce-power-manager, catfish, patterns-xfce-xfce, etc…) and it seems it’s all good.
System is up and running and Veracrypt works now.

Thanks everyone for the help.

1 Like

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.