Thread (13 messages) 13 messages, 5 authors, 2014-08-05

Re: [PATCH 0/5] ext4: RFC: Encryption

From: Michael Halcrow <hidden>
Date: 2014-07-23 22:39:20
Also in: linux-fsdevel

On Wed, Jul 23, 2014 at 3:34 PM, Pavel Machek [off-list ref] wrote:
On Thu 2014-07-24 00:25:06, Pavel Machek wrote:
quoted
Hi!
quoted
This patchset proposes a method for encrypting in EXT4 data read and
write paths. It's a proof-of-concept/prototype only right
now. Outstanding issues:

 * While it seems to work well with complex tasks like a parallel
   kernel build, fsx is pretty good at reliably breaking it in its
   current form. I think it's trying to decrypt a page of all zeros
   when doing a mmap'd write after an falloc. I want to get feedback
   on the overall approach before I spend too much time bug-hunting.
quoted
Can I keep just a subtree (/home/pavel/.ssh) encrypted?
Ok, as far as I can tell no, this is whole filesystem encryption for
now. I guess encrypting based on some attribute is planned...?
Correct; that's TBD as part of the LSS discussion next month. You can see
it wouldn't be that far-fetched to add an xattr to the parent directory that
specifies the key sig to use. It's just that unexpected things can happen
with hard links.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help