Re: [PATCH 10/16] fs/buffer: Remove fs-layer decryption code
Jan Kara <[email protected]> Wed, 24 Jun 2026 13:40:56 +0200
| Newsgroups | org.kernel.vger.linux-fscrypt,net.sourceforge.lists.linux-f2fs-devel,org.kernel.vger.linux-block,org.kernel.vger.linux-ext4,org.kernel.vger.linux-fsdevel |
|---|---|
| Message-ID | <hu7h6ga2ndrsedjvjbemdevjzrhvtz7jx2hbc2rtmkskufckmi@yf3a6t4hhike> |
On Tue 23-06-26 22:03:28, Eric Biggers wrote: > Now that fscrypt's file contents en/decryption is always implemented > using blk-crypto when the filesystem is block-based, the fs-layer > decryption code in fs/buffer.c is unused code. Remove it. > > Signed-off-by: Eric Biggers <[email protected]> Fine by me. Feel free to add: Reviewed-by: Jan Kara <[email protected]> Honza > --- > fs/buffer.c | 45 ++++++++------------------------------------- > 1 file changed, 8 insertions(+), 37 deletions(-) > > diff --git a/fs/buffer.c b/fs/buffer.c > index 9af5f061a1f8..21dd9596a941 100644 > --- a/fs/buffer.c > +++ b/fs/buffer.c > @@ -334,82 +334,53 @@ static void end_buffer_async_read(struct buffer_head *bh, int uptodate) > > still_busy: > spin_unlock_irqrestore(&first->b_uptodate_lock, flags); > } > > -struct postprocess_bh_ctx { > +struct verify_bh_ctx { > struct work_struct work; > struct buffer_head *bh; > struct fsverity_info *vi; > }; > > static void verify_bh(struct work_struct *work) > { > - struct postprocess_bh_ctx *ctx = > - container_of(work, struct postprocess_bh_ctx, work); > + struct verify_bh_ctx *ctx = > + container_of(work, struct verify_bh_ctx, work); > struct buffer_head *bh = ctx->bh; > bool valid; > > valid = fsverity_verify_blocks(ctx->vi, bh->b_folio, bh->b_size, > bh_offset(bh)); > end_buffer_async_read(bh, valid); > kfree(ctx); > } > > -static void decrypt_bh(struct work_struct *work) > -{ > - struct postprocess_bh_ctx *ctx = > - container_of(work, struct postprocess_bh_ctx, work); > - struct buffer_head *bh = ctx->bh; > - int err; > - > - err = fscrypt_decrypt_pagecache_blocks(bh->b_folio, bh->b_size, > - bh_offset(bh)); > - if (err == 0 && ctx->vi) { > - /* > - * We use different work queues for decryption and for verity > - * because verity may require reading metadata pages that need > - * decryption, and we shouldn't recurse to the same workqueue. > - */ > - INIT_WORK(&ctx->work, verify_bh); > - fsverity_enqueue_verify_work(&ctx->work); > - return; > - } > - end_buffer_async_read(bh, err == 0); > - kfree(ctx); > -} > - > /* > * I/O completion handler for block_read_full_folio() - folios > * which come unlocked at the end of I/O. > */ > static void bh_end_async_read(struct bio *bio) > { > struct buffer_head *bh; > bool uptodate = bio_endio_bh(bio, &bh); > struct inode *inode = bh->b_folio->mapping->host; > - bool decrypt = fscrypt_inode_uses_fs_layer_crypto(inode); > struct fsverity_info *vi = NULL; > > /* needed by ext4 */ > if (bh->b_folio->index < DIV_ROUND_UP(inode->i_size, PAGE_SIZE)) > vi = fsverity_get_info(inode); > > - /* Decrypt (with fscrypt) and/or verify (with fsverity) if needed. */ > - if (uptodate && (decrypt || vi)) { > - struct postprocess_bh_ctx *ctx = kmalloc_obj(*ctx, GFP_ATOMIC); > + /* Verify (with fsverity) if needed. */ > + if (vi && uptodate) { > + struct verify_bh_ctx *ctx = kmalloc_obj(*ctx, GFP_ATOMIC); > > if (ctx) { > ctx->bh = bh; > ctx->vi = vi; > - if (decrypt) { > - INIT_WORK(&ctx->work, decrypt_bh); > - fscrypt_enqueue_decrypt_work(&ctx->work); > - } else { > - INIT_WORK(&ctx->work, verify_bh); > - fsverity_enqueue_verify_work(&ctx->work); > - } > + INIT_WORK(&ctx->work, verify_bh); > + fsverity_enqueue_verify_work(&ctx->work); > return; > } > uptodate = false; > } > end_buffer_async_read(bh, uptodate); > -- > 2.54.0 > -- Jan Kara <[email protected]> SUSE Labs, CR