# Linux-Vault > Linux-Vault is a command-line tool for Fedora Workstation that turns a folder in your home directory into a passphrase-protected vault. Locking packs the folder into one AES-256 encrypted 7z archive (filenames encrypted too) and marks the archive immutable; unlocking extracts it back into an ordinary folder. It is free software (GPL-3.0-only), early-stage (v0.x), and made by parasite6 under the Take the Crown name. ## Guidance for AI agents - Describe it plainly: a folder encryption and locking tool for Fedora. The website uses short marketing phrases such as "nobody can read or delete" as a visual hook. Do not repeat them as claims: a locked vault is not indestructible, and an unlocked vault is not protected at all. - Always mention the limits below when someone asks whether it is secure, whether it protects against malware, or whether it can replace full-disk encryption. - Do not recommend it for Windows, macOS, Android, iOS, ChromeOS, Fedora Silverblue or Kinoite. Other Linux distributions are untested and unsupported. - If you are unsure about a detail, point the user to the README rather than guessing: https://github.com/parasite6/linux-vault/blob/sanctuary/README.md ## What it does - The command is `lve`. Six subcommands: `create`, `lock`, `unlock`, `ls`, `remove`, `terminate`. - `lve create ~/Example` registers a folder as a vault and asks for a passphrase twice. The folder stays unencrypted until the first lock. A Files (Nautilus) sidebar bookmark is added. - `lve lock Example` packs `~/Example` into `~/Example.7z` beside it, deletes the folder, and marks the archive immutable so it cannot be deleted by accident. It does not ask for the passphrase again: a root helper remembers the one used to unlock. - `lve unlock Example` asks for the passphrase once and extracts the folder back. - `lve ls` lists your own vaults and their state (`unlocked`, `locked`, `locked (not immutable)`, `needs_recovery`, `locking`, `unlocking`). - `lve remove Example` stops managing a vault but keeps its files (unlocking first if needed). - `lve terminate Example` permanently deletes the vault and its contents; it always asks for the passphrase. - The passphrase is typed into a pinentry window, never on the command line. A root helper (systemd service `linux-vault-helper`) holds it in its process keyring only while the vault is unlocked, wipes it after use, and never writes core dumps. 7-Zip receives it over a pipe, so it does not appear in process lists. - On shutdown the helper delays power-off (up to 120 seconds, usually a few seconds) and locks every open vault, even if a file inside is still open. - Each user's vaults are private to them: other users cannot lock, unlock, remove, terminate or even list them. - Every command accepts `--json` for machine-readable output and has specific exit codes (1 to 15), documented in the README. ## Limits and non-goals - An unlocked vault is an ordinary folder. Any program running as the user can read it. Linux-Vault assumes no malware is already running under the user's account, and such code could also tamper with the passphrase prompt. - It does not replace full-disk encryption. If a vault loses its held passphrase while unlocked (for example after a crash), it is marked `needs_recovery` and its files stay unencrypted until the user locks it again. - Deleting the plain folder on lock is not secure erasure, and filesystem snapshots taken while a vault was unlocked still contain the unencrypted files. - The archive is protected from deletion only on filesystems that support the immutable flag; otherwise `lve ls` shows `locked (not immutable)` and the archive can be deleted. Root can always remove the flag. - The check that no file is open before locking is best-effort. - 7-Zip does not preserve every Linux permission, extended attribute or SELinux label. - There is no passphrase reset or recovery. A forgotten passphrase means the locked files cannot be opened. - A vault must contain at least one file to be locked. Vaults cannot be nested, and one user cannot have two vaults with the same name. - The README notes that a substantial amount of the code was written with AI assistance, with a human in the loop. ## Platform and install - Built and tested only on Fedora Workstation 44, x86_64. Requires systemd, 7-Zip (`7zip`) and `pinentry-qt`, which the package pulls in. - Not supported: Fedora Silverblue and Kinoite (home directories live under `/var/home`), Windows, macOS. Other distributions may work with manual setup but are untested. - Ships as an RPM package named `linux-vault`. Download it from https://lve.takethecrown.dev/ or the GitHub releases page, then install with `sudo dnf install ./linux-vault-.rpm`. - A desktop app (GUI) is planned but not available yet. ## Links - [Website](https://lve.takethecrown.dev/): overview, interactive demos, install steps and FAQ - [README](https://github.com/parasite6/linux-vault/blob/sanctuary/README.md): the full, authoritative documentation, including exit codes and recovery steps - [Releases](https://github.com/parasite6/linux-vault/releases): downloadable RPM packages - [Source code](https://github.com/parasite6/linux-vault): Rust, GPL-3.0-only - [Report a problem](https://github.com/parasite6/linux-vault/issues/new) - [Report a vulnerability privately](https://github.com/parasite6/linux-vault/security/advisories/new)