On Thu, 30 Jul 2026 11:48:53 -0700 Eric Biggers <[email protected]> wrote:

> ext4 and f2fs don't prevent filesystem-level encrypted files from being
> set up directly as swap files.  In this case, encryption is bypassed.
> 
> No one should be doing this, vs. the methods of encrypted swap that
> actually do work (such as swapping to a dm-crypt device, or swapping to
> a loopback device on top of a filesystem-level encrypted file).
> 
> Nevertheless, to prevent user error, make swapon() explicitly reject
> this case.  Document this behavior in fscrypt.rst as well.
> 
> Fixes: 9bd8212f981e ("ext4 crypto: add encryption policy and password salt 
> support")
> Fixes: f424f664f0e8 ("f2fs crypto: add encryption policy and password salt 
> support")

Ouch.  We are going to break ten year old setups?  I don't think we can
do this!

I think the best we can do is to emit loud warnings which point the
operator to some Documentation/ which tells operator that this
deprecated configuration will be disallowed in, umm, 2029.

> +  Alternatively, encrypted swap can use a dm-crypt device instead.

That's tautological.  s/ intead// ;)

Reply via email to