Linux EXT4 FS development
 help / color / mirror / Atom feed
* [PATCH 0/2] ext4: refuse encryption when block size > page size
@ 2026-09-25 14:19 Alberto Garcia
  2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Alberto Garcia @ 2026-09-25 14:19 UTC (permalink / raw)
  To: Theodore Ts'o
  Cc: Alberto Garcia, Andreas Dilger, Baokun Li, Jan Kara,
	Ojaswin Mujoo, Ritesh Harjani, Zhang Yi, Eric Biggers,
	linux-fscrypt, linux-ext4

Hi,

encryption is not supported when a filesystem's block size is larger
than the page size. Although the kernel refuses to mount such a
filesystem if the "encrypt" feature is already set, it is possible to
enable it on a mounted filesystem with e.g. tune2fs.

# mkfs.ext4 -b 16384 /dev/vdb
# mount /dev/vdb /mnt/
# tune2fs -O encrypt /dev/vdb
# mkdir /mnt/foo
# fscrypt setup /mnt
# fscrypt encrypt /mnt/foo/
# head -c 20M /dev/urandom > /mnt/foo/data
# sync
[  116.014221] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 130040)
[  116.014235] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss!  (inode 19, error -5)
[  116.014241] Buffer I/O error on device vdb, logical block 130040
[...]
[  116.014264] Buffer I/O error on device vdb, logical block 130049
[  116.015505] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 66552)
[  116.015520] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss!  (inode 19, error -5)
[  116.016451] EXT4-fs warning (device vdb): ext4_end_bio:360: I/O error 19 writing to inode 19 starting block 65784)
[  116.016459] EXT4-fs (vdb): failed to convert unwritten extents to written extents -- potential data loss!  (inode 19, error -5)

This affects all kernels starting from v6.19 up to v7.3-rc4.

Note that this still allows encrypted inodes even when the 'encrypt'
feature is missing as long as block size <= page size. With v1
encryption policies they can be used normally.

There's an additional bug that only affects kernels between v6.19 and
v7.2 (but not v7.3), which will be dealt with separately.

Regards,

Berto

Alberto Garcia (2):
  ext4: refuse encryption when block size > page size
  ext4: reject encrypted inodes when block size > page size

 fs/ext4/crypto.c | 9 +++++++++
 fs/ext4/inode.c  | 6 ++++++
 2 files changed, 15 insertions(+)

-- 
2.47.3


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-10-03 15:29 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 14:19 [PATCH 0/2] ext4: refuse encryption when block size > page size Alberto Garcia
2026-09-25 14:19 ` [PATCH 1/2] " Alberto Garcia
2026-09-25 14:27   ` sashiko-bot
2026-10-03 15:17   ` Baokun Li
2026-09-25 14:19 ` [PATCH 2/2] ext4: reject encrypted inodes " Alberto Garcia
2026-09-25 14:26   ` sashiko-bot
2026-10-03 15:28   ` Baokun Li
2026-09-25 19:59 ` [PATCH 0/2] ext4: refuse encryption " Eric Biggers

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox