[$] Per-extent encrypted keys for fscrypt

Post Syndicated from original https://lwn.net/Articles/918893/

The kernel’s fscrypt
subsystem
enables filesystems to store files and
directories in encrypted form, protecting them against offline attacks. A
few filesystems support encryption with fscrypt currently, but Btrfs is an
exception, despite a number of attempts to add this feature. The problem
is that, as so often seems to be the case, Btrfs works differently and does
not fit well with one of the key assumptions in the design of fscrypt. With this
patch series
, Sweet Tea Dorminy is working to enhance fscrypt to be a
better fit for filesystems like Btrfs.