| From: |
| Andrey Albershteyn <aalbersh-AT-kernel.org> |
| To: |
| linux-xfs-AT-vger.kernel.org, fsverity-AT-lists.linux.dev, linux-fsdevel-AT-vger.kernel.org, ebiggers-AT-kernel.org |
| Subject: |
| [PATCH v3 00/35] fs-verity support for XFS with post EOF merkle tree |
| Date: |
| Wed, 18 Feb 2026 00:19:00 +0100 |
| Message-ID: |
| <20260217231937.1183679-1-aalbersh@kernel.org> |
| Cc: |
| Andrey Albershteyn <aalbersh-AT-kernel.org>, hch-AT-lst.de, djwong-AT-kernel.org |
| Archive-link: |
| Article |
Hi all,
This patch series adds fs-verity support for XFS. This version stores
merkle tree beyond end of the file, the same way as ext4 does it. The
verity descriptor is stored at the tail of the merkle tree.
The patchset starts with a few fs-verity preparation patches. Then, a few
patches to allow iomap to work in post EOF region. The XFS fs-verity
implementation follows.
Preallocations. The preallocations are disabled for fs-verity files. If
inode is fs-verity one the allocation size is set to zero. This is fine
as the only writing happening is merkle tree data and descriptor.
The tree is read by iomap into page cache at offset of next largest
folio past end of file. This offset is different from one stored
on-disk, file offset is 1ULL << 53. This is far enough to handle any
supported file size.
This patchsets also synthesizes merkle tree block full of hashes of
zeroed data blocks. This merkle blocks are not stored on disk, they are
holes in the tree.
Testing. The -g verity is passing for 1k, 8k and 4k with/without quota,
the tests include different merkle tree block size.
From time to time I see a generic/579 (stress test enable/read) failing
on xfs_8k. Somehow, merkle block is zeroed page. I haven't found the
reason why yet.
Feedback is welcomed :)
This series based on latest fsverity branch with patchset fs generated
integrity information [1] and the one preceding it [2] and traces
patchset [3].
xfsprogs:
https://github.com/alberand/xfsprogs/tree/b4/fsverity
xfstests:
https://github.com/alberand/xfstests/tree/b4/fsverity
Cc: fsverity@lists.linux.dev
Cc: linux-fsdevel@vger.kernel.org
Cc: linux-xfs@vger.kernel.org
Cc: djwong@kernel.org
Cc: ebiggers@kernel.org
Cc: hch@lst.de
[1]: https://lore.kernel.org/linux-xfs/20260128161517.666412-1...
[2]: https://lore.kernel.org/linux-xfs/aXnb17nHHog9z6tC@nidhog...
[3]: https://lore.kernel.org/fsverity/20260203-wasser-universa...
---
Changes in v3:
- Different on-disk and pagecache offset
- Use read path ioends
- Switch to hashtable fsverity info
- Synthesize merkle tree blocks full of zeroes
- Other minor refactors
- Link to v2: https://lore.kernel.org/fsverity/20260114164210.GO15583@f...
Changes in v2:
- Move to VFS interface for merkle tree block reading
- Drop patchset for per filesystem workqueues
- Change how offsets of the descriptor and tree metadata is calculated
- Store fs-verity descriptor in data fork side by side with merkle tree
- Simplify iomap changes, remove interface for post eof read/write
- Get rid of extended attribute implementation
- Link to v1: https://lore.kernel.org/r/20250728-fsverity-v1-0-9e5443af...
Andrey Albershteyn (31):
fsverity: expose ensure_fsverity_info()
fsverity: add consolidated pagecache offset for metadata
fsverity: generate and store zero-block hash
fsverity: introduce fsverity_folio_zero_hash()
fsverity: pass digest size and hash of the empty block to ->write
iomap: introduce IOMAP_F_FSVERITY
iomap: don't limit fsverity metadata by EOF in writeback
iomap: obtain fsverity info for read path
iomap: issue readahead for fsverity merkle tree
iomap: allow filesystem to read fsverity metadata beyound EOF
iomap: let fsverity verify holes
xfs: use folio host instead of file struct
xfs: add fs-verity ro-compat flag
xfs: add inode on-disk VERITY flag
xfs: initialize fs-verity on file open
xfs: don't allow to enable DAX on fs-verity sealed inode
xfs: disable direct read path for fs-verity files
xfs: introduce XFS_FSVERITY_CONSTRUCTION inode flag
xfs: introduce XFS_FSVERITY_REGION_START constant
xfs: disable preallocations for fsverity Merkle tree writes
xfs: add iomap write/writeback and reading of Merkle tree pages
xfs: add helper to check that inode data need fsverity verification
xfs: use read ioend for fsverity data verification
xfs: add helpers to convert between pagecache and on-disk offset
xfs: add a helper to decide if bmbt record needs offset conversion
xfs: use different on-disk and pagecache offset for fsverity
xfs: add fs-verity support
xfs: add fs-verity ioctls
xfs: introduce health state for corrupted fsverity metadata
xfs: add fsverity traces
xfs: enable ro-compat fs-verity flag
Darrick J. Wong (4):
fsverity: report validation errors back to the filesystem
xfs: advertise fs-verity being available on filesystem
xfs: check and repair the verity inode flag state
xfs: report verity failures through the health system
fs/btrfs/verity.c | 6 +-
fs/ext4/verity.c | 4 +-
fs/f2fs/verity.c | 4 +-
fs/iomap/buffered-io.c | 64 +++-
fs/iomap/trace.h | 3 +-
fs/verity/enable.c | 4 +-
fs/verity/fsverity_private.h | 3 +
fs/verity/open.c | 8 +-
fs/verity/pagecache.c | 28 ++
fs/verity/verify.c | 4 +
fs/xfs/Makefile | 1 +
fs/xfs/libxfs/xfs_bmap.c | 13 +-
fs/xfs/libxfs/xfs_format.h | 13 +-
fs/xfs/libxfs/xfs_fs.h | 27 ++
fs/xfs/libxfs/xfs_health.h | 6 +-
fs/xfs/libxfs/xfs_inode_buf.c | 8 +
fs/xfs/libxfs/xfs_inode_util.c | 2 +
fs/xfs/libxfs/xfs_sb.c | 4 +
fs/xfs/scrub/attr.c | 7 +
fs/xfs/scrub/common.c | 53 ++++
fs/xfs/scrub/common.h | 2 +
fs/xfs/scrub/inode.c | 7 +
fs/xfs/scrub/inode_repair.c | 36 +++
fs/xfs/xfs_aops.c | 55 +++-
fs/xfs/xfs_bmap_util.c | 8 +
fs/xfs/xfs_file.c | 19 +-
fs/xfs/xfs_fsverity.c | 511 ++++++++++++++++++++++++++++++++
fs/xfs/xfs_fsverity.h | 46 +++
fs/xfs/xfs_health.c | 2 +
fs/xfs/xfs_inode.h | 6 +
fs/xfs/xfs_ioctl.c | 16 +
fs/xfs/xfs_iomap.c | 45 ++-
fs/xfs/xfs_iops.c | 4 +
fs/xfs/xfs_message.c | 4 +
fs/xfs/xfs_message.h | 1 +
fs/xfs/xfs_mount.h | 4 +
fs/xfs/xfs_super.c | 7 +
fs/xfs/xfs_trace.h | 46 +++
include/linux/fsverity.h | 43 ++-
include/linux/iomap.h | 7 +
include/trace/events/fsverity.h | 19 ++
41 files changed, 1109 insertions(+), 41 deletions(-)
create mode 100644 fs/xfs/xfs_fsverity.c
create mode 100644 fs/xfs/xfs_fsverity.h
--
2.51.2