[ANNOUNCE] cryptsetup 2.2.2

Milan Broz <[email protected]>
Newsgroups gmane.linux.kernel.device-mapper.dm-crypt
Message-ID <[email protected]>
The cryptsetup 2.2.2 release is available at

    https://gitlab.com/cryptsetup/cryptsetup

Please note that release packages are located on kernel.org

    https://www.kernel.org/pub/linux/utils/cryptsetup/v2.2/

Feedback and bug reports are welcomed.

Cryptsetup 2.2.2 Release Notes
==============================
Stable bug-fix release.

All users of cryptsetup 2.1 and 2.2 should upgrade to this version.

Changes since version 2.2.1
~~~~~~~~~~~~~~~~~~~~~~~~~~~

* Print error message if a keyslot open failed for a different reason
  than wrong passwords (for example there is not enough memory).
  Only an exit code was present in this case.

* The progress function switches unit sizes (B/s to GiB/s) according
  to the actual speed. Also, it properly calculates speed in the case
  of a resumed reencryption operation.

* The --version now supports short -V short option and better handles
  common option priorities.

* If cryptsetup wipes signatures during format actions through blkid,
  it also prints signature device offsets.

* Compilation now properly uses LTLIBINTL gettext setting in Makefiles.

* Device-mapper backend now supports new DM_GET_TARGET_VERSION ioctl
  (available since Linux kernel 5.4).
  This should help to detect some kernel/userspace incompatibilities
  earlier later after a failed device activation.

* Fixes LUKS2 reencryption on systems without kernel keyring.

* Fixes unlocking prompt for partitions mapped through loop devices
  (to properly show the backing device).

* For LUKS2 decryption, a device is now marked for deferred removal
  to be automatically deactivated.

* Reencryption now limits hotzone size to be maximal 1 GiB or 1/4
  system memory (if lower).

* Reencryption now retains activation flags during online reencryption.

* Reencryption now allows LUKS2 device to activate device right after
  LUKS2 encryption is initialized through optional active device name
  for cryptsetup reencrypt --encrypt command.
  This could help with automated encryption during boot.

  NOTE: It means that part of the device is still not encrypted during
  activation. Use with care!

* Fixes failure in resize and plain format activation if activated device
  size was not aligned to underlying logical device size.

* Fixes conversion to LUKS2 format with detached header if a detached
  header size was smaller than the expected aligned LUKS1 header size.

_______________________________________________
dm-crypt mailing list
[email protected]
https://www.saout.de/mailman/listinfo/dm-crypt
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKikYJD/eRmSNBob52bBXe9k+mPwFAl27+RUACgkQ2bBXe9k+
mPyoHQ//XhlSL2LRkp9PYFtv4ozCdo8LQCMXJjIuvWWEHbYJDITspU6N3Jy/qr9M
b6Z+sepnc8LvgrVXsW/LU/YGLkMDUS4TfRpcZ/S6SoT7pao56ffa3rN85HCBApzc
c+RDePXRdGY6k6CVALX/5wAIQR9lZ5CMpetKJLOYMA+H6sZ/XN2rmJaZcXTkxlLz
5WUdIDRSIoIOV/KPrXE38d2jR0aiwhIXgCjU0phwdIFjnc6/nBclnRZtatPpkRh/
jGDv76RwzblsBCnC4p4UGndRk9/IQU15hab/4/0n7Yu1FLvmq3ArVCpfM6zVirQO
oFTg7yGmJGs+KJwVCeL8LQb/TjRU9OJTnkI/ayo8cbNB3++75RdM2sSnV7sskQDs
7uUSseFDi+CsFtK2R0BBZ14tJrO2Hc2HfLDXU7+FlxNgv4C0K6Io74SSiN4+hxc7
lpAIAMrX/1ZaNOS+3UjKrbHx5cjMktCZhUZoho95TWCI+6ix7LrfJwtXcUvSbVuM
7KefhEYENRCvfNaIQmgefkwsD+ZGZKzReay2BBR/AD3sk7j4Q+rhESzuMWF5JGon
NaPRsgj7syHyRySpTv0zMWRgbvgPDyP221xDvIN7HtU2JM6PIevw26Xp88Vy2byQ
uWFa5NDjkyiRf0tPwB23HrVlGWzPtv9uxzd8cKQBDyX9v8G5+wQ=
=0en1
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.