* [PATCH 0/2] ext4: refuse encryption when block size > page size
@ 2026-09-25 14:19 Alberto Garcia
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
` (2 more replies)
0 siblings, 3 replies; 8+ messages in thread
From: Alberto Garcia @ 2026-09-25 14:19 UTC (permalink / raw)
To: Theodore Ts'o
Cc: Alberto Garcia, Andreas Dilger, Baokun Li, Jan Kara,
Ojaswin Mujoo, Ritesh Harjani, Zhang Yi, Eric Biggers,
linux-fscrypt, linux-ext4
Hi,
encryption is not supported when a filesystem's block size is larger
than the page size. Although the kernel refuses to mount such a
filesystem if the "encrypt" feature is already set, it is possible to
enable it on a mounted filesystem with e.g. tune2fs.
# mkfs.ext4 -b 16384 /dev/vdb
# mount /dev/vdb /mnt/
# tune2fs -O encrypt /dev/vdb
# mkdir /mnt/foo
# fscrypt setup /mnt
# fscrypt encrypt /mnt/foo/
# head -c 20M /dev/urandom > /mnt/foo/data
# sync
[ 116.014221] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 130040)
[ 116.014235] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
[ 116.014241] Buffer I/O error on device vdb, logical block 130040
[...]
[ 116.014264] Buffer I/O error on device vdb, logical block 130049
[ 116.015505] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 66552)
[ 116.015520] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
[ 116.016451] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 65784)
[ 116.016459] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
This affects all kernels starting from v6.19 up to v7.3-rc4.
Note that this still allows encrypted inodes even when the 'encrypt'
feature is missing as long as block size <= page size. With v1
encryption policies they can be used normally.
There's an additional bug that only affects kernels between v6.19 and
v7.2 (but not v7.3), which will be dealt with separately.
Regards,
Berto
Alberto Garcia (2):
ext4: refuse encryption when block size > page size
ext4: reject encrypted inodes when block size > page size
fs/ext4/crypto.c | 9 +++++++++
fs/ext4/inode.c | 6 ++++++
2 files changed, 15 insertions(+)
--
2.47.3
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 1/2] ext4: refuse encryption when block size > page size
2026-09-25 14:19 [PATCH 0/2] ext4: refuse encryption when block size > page size Alberto Garcia
@ 2026-09-25 14:19 ` Alberto Garcia
2026-09-25 14:27 ` sashiko-bot
2026-10-03 15:17 ` Baokun Li
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
2026-09-25 19:59 ` [PATCH 0/2] ext4: refuse encryption " Eric Biggers
2 siblings, 2 replies; 8+ messages in thread
From: Alberto Garcia @ 2026-09-25 14:19 UTC (permalink / raw)
To: Theodore Ts'o
Cc: Alberto Garcia, Andreas Dilger, Baokun Li, Jan Kara,
Ojaswin Mujoo, Ritesh Harjani, Zhang Yi, Eric Biggers,
linux-fscrypt, linux-ext4, stable
Encryption is not supported when a filesystem's block size is larger
than the page size, and commit 709f0f1f1bf5 ("ext4: add checks for
large folio incompatibilities when BS > PS") added a check to refuse
mounting such a filesystem.
However, it is also possible to enable the "encrypt" feature on a
filesystem that is already mounted (with tune2fs -O encrypt). Once
that happens it won't be possible to mount the filesystem again in
the future, but there is nothing preventing the user from setting an
encryption policy while the filesystem is still mounted.
Fix this by refusing to set an fscrypt context in ext4_set_context()
when the block size is larger than the page size.
Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
Cc: stable@vger.kernel.org # v6.19+
Signed-off-by: Alberto Garcia <berto@igalia.com>
---
fs/ext4/crypto.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/fs/ext4/crypto.c b/fs/ext4/crypto.c
index 1a0fccb084ef..318b2eaea741 100644
--- a/fs/ext4/crypto.c
+++ b/fs/ext4/crypto.c
@@ -156,6 +156,15 @@ static int ext4_set_context(struct inode *inode, const void *ctx, size_t len,
if (ext4_test_inode_flag(inode, EXT4_INODE_DAX))
return -EOPNOTSUPP;
+ /*
+ * Encryption is not supported when the block size is larger
+ * than the page size. This is rejected at mount time by
+ * ext4_check_large_folio(), and this check here is for the case
+ * when the 'encrypt' feature is enabled on a mounted filesystem.
+ */
+ if (inode->i_sb->s_blocksize > PAGE_SIZE)
+ return -EOPNOTSUPP;
+
res = ext4_convert_inline_data(inode);
if (res)
return res;
--
2.47.3
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 2/2] ext4: reject encrypted inodes when block size > page size
2026-09-25 14:19 [PATCH 0/2] ext4: refuse encryption when block size > page size Alberto Garcia
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
@ 2026-09-25 14:19 ` Alberto Garcia
2026-09-25 14:26 ` sashiko-bot
2026-10-03 15:28 ` Baokun Li
2026-09-25 19:59 ` [PATCH 0/2] ext4: refuse encryption " Eric Biggers
2 siblings, 2 replies; 8+ messages in thread
From: Alberto Garcia @ 2026-09-25 14:19 UTC (permalink / raw)
To: Theodore Ts'o
Cc: Alberto Garcia, Andreas Dilger, Baokun Li, Jan Kara,
Ojaswin Mujoo, Ritesh Harjani, Zhang Yi, Eric Biggers,
linux-fscrypt, linux-ext4, stable
Encryption is not supported when a filesystem's block size is larger
than the page size. ext4_check_large_folio() refuses to mount a
filesystem like that if the "encrypt" feature is already enabled, and
ext4_set_context() refuses to create encrypted inodes if the feature
is enabled after mounting.
However, a corrupted or hand-crafted filesystem can still have
encrypted inodes even if the "encrypt" feature is not set, and those
inodes can be unlocked if they're using v1 policies.
Check this in __ext4_iget() and reject them as corrupted.
Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
Suggested-by: Eric Biggers <ebiggers@kernel.org>
Cc: stable@vger.kernel.org # v6.19+
Signed-off-by: Alberto Garcia <berto@igalia.com>
---
fs/ext4/inode.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index 26f0f9714f03..31248fef8bce 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -5671,6 +5671,12 @@ struct inode *__ext4_iget(struct super_block *sb, unsigned long ino,
ret = -EFSCORRUPTED;
goto bad_inode;
}
+ if (IS_ENCRYPTED(inode) && sb->s_blocksize > PAGE_SIZE) {
+ ext4_error_inode(inode, function, line, 0,
+ "encrypted inode with block size larger than page size");
+ ret = -EFSCORRUPTED;
+ goto bad_inode;
+ }
ext4_set_inode_mapping_order(inode);
--
2.47.3
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH 2/2] ext4: reject encrypted inodes when block size > page size
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
@ 2026-09-25 14:26 ` sashiko-bot
2026-10-03 15:28 ` Baokun Li
1 sibling, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-09-25 14:26 UTC (permalink / raw)
To: Alberto Garcia; +Cc: linux-ext4, tytso
> Encryption is not supported when a filesystem's block size is larger
> than the page size. ext4_check_large_folio() refuses to mount a
> filesystem like that if the "encrypt" feature is already enabled, and
> ext4_set_context() refuses to create encrypted inodes if the feature
> is enabled after mounting.
>
> However, a corrupted or hand-crafted filesystem can still have
> encrypted inodes even if the "encrypt" feature is not set, and those
> inodes can be unlocked if they're using v1 policies.
>
> Check this in __ext4_iget() and reject them as corrupted.
>
> Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
> Suggested-by: Eric Biggers <ebiggers@kernel.org>
> Cc: stable@vger.kernel.org # v6.19+
> Signed-off-by: Alberto Garcia <berto@igalia.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790343958.git.berto@igalia.com?part=2
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/2] ext4: refuse encryption when block size > page size
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
@ 2026-09-25 14:27 ` sashiko-bot
2026-10-03 15:17 ` Baokun Li
1 sibling, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-09-25 14:27 UTC (permalink / raw)
To: Alberto Garcia; +Cc: linux-ext4, tytso
> Encryption is not supported when a filesystem's block size is larger
> than the page size, and commit 709f0f1f1bf5 ("ext4: add checks for
> large folio incompatibilities when BS > PS") added a check to refuse
> mounting such a filesystem.
>
> However, it is also possible to enable the "encrypt" feature on a
> filesystem that is already mounted (with tune2fs -O encrypt). Once
> that happens it won't be possible to mount the filesystem again in
> the future, but there is nothing preventing the user from setting an
> encryption policy while the filesystem is still mounted.
>
> Fix this by refusing to set an fscrypt context in ext4_set_context()
> when the block size is larger than the page size.
>
> Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
> Cc: stable@vger.kernel.org # v6.19+
> Signed-off-by: Alberto Garcia <berto@igalia.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790343958.git.berto@igalia.com?part=1
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 0/2] ext4: refuse encryption when block size > page size
2026-09-25 14:19 [PATCH 0/2] ext4: refuse encryption when block size > page size Alberto Garcia
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
@ 2026-09-25 19:59 ` Eric Biggers
2 siblings, 0 replies; 8+ messages in thread
From: Eric Biggers @ 2026-09-25 19:59 UTC (permalink / raw)
To: Alberto Garcia
Cc: Theodore Ts'o, Andreas Dilger, Baokun Li, Jan Kara,
Ojaswin Mujoo, Ritesh Harjani, Zhang Yi, linux-fscrypt,
linux-ext4
On Fri, Sep 25, 2026 at 04:19:17PM +0200, Alberto Garcia wrote:
> Hi,
>
> encryption is not supported when a filesystem's block size is larger
> than the page size. Although the kernel refuses to mount such a
> filesystem if the "encrypt" feature is already set, it is possible to
> enable it on a mounted filesystem with e.g. tune2fs.
>
> # mkfs.ext4 -b 16384 /dev/vdb
> # mount /dev/vdb /mnt/
> # tune2fs -O encrypt /dev/vdb
> # mkdir /mnt/foo
> # fscrypt setup /mnt
> # fscrypt encrypt /mnt/foo/
> # head -c 20M /dev/urandom > /mnt/foo/data
> # sync
> [ 116.014221] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 130040)
> [ 116.014235] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
> [ 116.014241] Buffer I/O error on device vdb, logical block 130040
> [...]
> [ 116.014264] Buffer I/O error on device vdb, logical block 130049
> [ 116.015505] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 66552)
> [ 116.015520] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
> [ 116.016451] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 65784)
> [ 116.016459] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss! (inode 19, error -5)
>
> This affects all kernels starting from v6.19 up to v7.3-rc4.
>
> Note that this still allows encrypted inodes even when the 'encrypt'
> feature is missing as long as block size <= page size. With v1
> encryption policies they can be used normally.
>
> There's an additional bug that only affects kernels between v6.19 and
> v7.2 (but not v7.3), which will be dealt with separately.
>
> Regards,
>
> Berto
>
> Alberto Garcia (2):
> ext4: refuse encryption when block size > page size
> ext4: reject encrypted inodes when block size > page size
>
> fs/ext4/crypto.c | 9 +++++++++
> fs/ext4/inode.c | 6 ++++++
> 2 files changed, 15 insertions(+)
Reviewed-by: Eric Biggers <ebiggers@kernel.org>
- Eric
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/2] ext4: refuse encryption when block size > page size
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
2026-09-25 14:27 ` sashiko-bot
@ 2026-10-03 15:17 ` Baokun Li
1 sibling, 0 replies; 8+ messages in thread
From: Baokun Li @ 2026-10-03 15:17 UTC (permalink / raw)
To: Alberto Garcia
Cc: Theodore Ts'o, Andreas Dilger, Jan Kara, Ojaswin Mujoo,
Ritesh Harjani, Zhang Yi, Eric Biggers, linux-fscrypt, linux-ext4,
stable
On 2026/9/25 22:19, Alberto Garcia wrote:
> Encryption is not supported when a filesystem's block size is larger
> than the page size, and commit 709f0f1f1bf5 ("ext4: add checks for
> large folio incompatibilities when BS > PS") added a check to refuse
> mounting such a filesystem.
>
> However, it is also possible to enable the "encrypt" feature on a
> filesystem that is already mounted (with tune2fs -O encrypt). Once
> that happens it won't be possible to mount the filesystem again in
> the future, but there is nothing preventing the user from setting an
> encryption policy while the filesystem is still mounted.
>
> Fix this by refusing to set an fscrypt context in ext4_set_context()
> when the block size is larger than the page size.
>
> Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
> Cc: stable@vger.kernel.org # v6.19+
> Signed-off-by: Alberto Garcia <berto@igalia.com>
Thanks for the patch, feel free to add:
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
> ---
> fs/ext4/crypto.c | 9 +++++++++
> 1 file changed, 9 insertions(+)
>
> diff --git a/fs/ext4/crypto.c b/fs/ext4/crypto.c
> index 1a0fccb084ef..318b2eaea741 100644
> --- a/fs/ext4/crypto.c
> +++ b/fs/ext4/crypto.c
> @@ -156,6 +156,15 @@ static int ext4_set_context(struct inode *inode, const void *ctx, size_t len,
> if (ext4_test_inode_flag(inode, EXT4_INODE_DAX))
> return -EOPNOTSUPP;
>
> + /*
> + * Encryption is not supported when the block size is larger
> + * than the page size. This is rejected at mount time by
> + * ext4_check_large_folio(), and this check here is for the case
> + * when the 'encrypt' feature is enabled on a mounted filesystem.
> + */
> + if (inode->i_sb->s_blocksize > PAGE_SIZE)
> + return -EOPNOTSUPP;
> +
> res = ext4_convert_inline_data(inode);
> if (res)
> return res;
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 2/2] ext4: reject encrypted inodes when block size > page size
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
2026-09-25 14:26 ` sashiko-bot
@ 2026-10-03 15:28 ` Baokun Li
1 sibling, 0 replies; 8+ messages in thread
From: Baokun Li @ 2026-10-03 15:28 UTC (permalink / raw)
To: Alberto Garcia
Cc: Theodore Ts'o, Andreas Dilger, Jan Kara, Ojaswin Mujoo,
Ritesh Harjani, Zhang Yi, Eric Biggers, linux-fscrypt, linux-ext4,
stable
On 2026/9/25 22:19, Alberto Garcia wrote:
> Encryption is not supported when a filesystem's block size is larger
> than the page size. ext4_check_large_folio() refuses to mount a
> filesystem like that if the "encrypt" feature is already enabled, and
> ext4_set_context() refuses to create encrypted inodes if the feature
> is enabled after mounting.
>
> However, a corrupted or hand-crafted filesystem can still have
> encrypted inodes even if the "encrypt" feature is not set, and those
> inodes can be unlocked if they're using v1 policies.
>
> Check this in __ext4_iget() and reject them as corrupted.
>
> Fixes: 709f0f1f1bf5 ("ext4: add checks for large folio incompatibilities when BS > PS")
> Suggested-by: Eric Biggers <ebiggers@kernel.org>
> Cc: stable@vger.kernel.org # v6.19+
> Signed-off-by: Alberto Garcia <berto@igalia.com>
Looks good, feel free to add:
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
> ---
> fs/ext4/inode.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
> index 26f0f9714f03..31248fef8bce 100644
> --- a/fs/ext4/inode.c
> +++ b/fs/ext4/inode.c
> @@ -5671,6 +5671,12 @@ struct inode *__ext4_iget(struct super_block *sb, unsigned long ino,
> ret = -EFSCORRUPTED;
> goto bad_inode;
> }
> + if (IS_ENCRYPTED(inode) && sb->s_blocksize > PAGE_SIZE) {
> + ext4_error_inode(inode, function, line, 0,
> + "encrypted inode with block size larger than page size");
> + ret = -EFSCORRUPTED;
> + goto bad_inode;
> + }
>
> ext4_set_inode_mapping_order(inode);
>
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-10-03 15:29 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 14:19 [PATCH 0/2] ext4: refuse encryption when block size > page size Alberto Garcia
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
2026-09-25 14:27 ` sashiko-bot
2026-10-03 15:17 ` Baokun Li
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
2026-09-25 14:26 ` sashiko-bot
2026-10-03 15:28 ` Baokun Li
2026-09-25 19:59 ` [PATCH 0/2] ext4: refuse encryption " Eric Biggers
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox