Re: [PATCH] mm/swap: reject swapon() on filesystem-level encrypted files
Andrew Morton <[email protected]> Thu, 30 Jul 2026 12:53:27 -0700
| Newsgroups | org.kernel.vger.linux-fscrypt,net.sourceforge.lists.linux-f2fs-devel,org.kernel.vger.linux-ext4,org.kernel.vger.linux-kernel,org.kernel.vger.stable,org.kvack.linux-mm |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 30 Jul 2026 11:48:53 -0700 Eric Biggers <[email protected]> wrote: > ext4 and f2fs don't prevent filesystem-level encrypted files from being > set up directly as swap files. In this case, encryption is bypassed. > > No one should be doing this, vs. the methods of encrypted swap that > actually do work (such as swapping to a dm-crypt device, or swapping to > a loopback device on top of a filesystem-level encrypted file). > > Nevertheless, to prevent user error, make swapon() explicitly reject > this case. Document this behavior in fscrypt.rst as well. > > Fixes: 9bd8212f981e ("ext4 crypto: add encryption policy and password salt support") > Fixes: f424f664f0e8 ("f2fs crypto: add encryption policy and password salt support") Ouch. We are going to break ten year old setups? I don't think we can do this! I think the best we can do is to emit loud warnings which point the operator to some Documentation/ which tells operator that this deprecated configuration will be disallowed in, umm, 2029. > + Alternatively, encrypted swap can use a dm-crypt device instead. That's tautological. s/ intead// ;)