|
|
Log in / Subscribe / Register

fs-verity support for XFS with post EOF merkle tree

From:  Andrey Albershteyn <aalbersh-AT-kernel.org>
To:  linux-xfs-AT-vger.kernel.org, fsverity-AT-lists.linux.dev, linux-fsdevel-AT-vger.kernel.org, ebiggers-AT-kernel.org
Subject:  [PATCH v3 00/35] fs-verity support for XFS with post EOF merkle tree
Date:  Wed, 18 Feb 2026 00:19:00 +0100
Message-ID:  <20260217231937.1183679-1-aalbersh@kernel.org>
Cc:  Andrey Albershteyn <aalbersh-AT-kernel.org>, hch-AT-lst.de, djwong-AT-kernel.org
Archive-link:  Article

Hi all,

This patch series adds fs-verity support for XFS. This version stores
merkle tree beyond end of the file, the same way as ext4 does it. The
verity descriptor is stored at the tail of the merkle tree.

The patchset starts with a few fs-verity preparation patches. Then, a few
patches to allow iomap to work in post EOF region. The XFS fs-verity
implementation follows.

Preallocations. The preallocations are disabled for fs-verity files. If
inode is fs-verity one the allocation size is set to zero. This is fine
as the only writing happening is merkle tree data and descriptor.

The tree is read by iomap into page cache at offset of next largest
folio past end of file. This offset is different from one stored
on-disk, file offset is 1ULL << 53. This is far enough to handle any
supported file size.

This patchsets also synthesizes merkle tree block full of hashes of
zeroed data blocks. This merkle blocks are not stored on disk, they are
holes in the tree.

Testing. The -g verity is passing for 1k, 8k and 4k with/without quota,
the tests include different merkle tree block size.

From time to time I see a generic/579 (stress test enable/read) failing
on xfs_8k. Somehow, merkle block is zeroed page. I haven't found the
reason why yet.

Feedback is welcomed :)

This series based on latest fsverity branch with patchset fs generated
integrity information [1] and the one preceding it [2] and traces
patchset [3].

xfsprogs:
https://github.com/alberand/xfsprogs/tree/b4/fsverity

xfstests:
https://github.com/alberand/xfstests/tree/b4/fsverity

Cc: fsverity@lists.linux.dev
Cc: linux-fsdevel@vger.kernel.org
Cc: linux-xfs@vger.kernel.org

Cc: djwong@kernel.org
Cc: ebiggers@kernel.org
Cc: hch@lst.de

[1]: https://lore.kernel.org/linux-xfs/20260128161517.666412-1...
[2]: https://lore.kernel.org/linux-xfs/aXnb17nHHog9z6tC@nidhog...
[3]: https://lore.kernel.org/fsverity/20260203-wasser-universa...

---
Changes in v3:
- Different on-disk and pagecache offset
- Use read path ioends
- Switch to hashtable fsverity info
- Synthesize merkle tree blocks full of zeroes
- Other minor refactors
- Link to v2: https://lore.kernel.org/fsverity/20260114164210.GO15583@f...
Changes in v2:
- Move to VFS interface for merkle tree block reading
- Drop patchset for per filesystem workqueues
- Change how offsets of the descriptor and tree metadata is calculated
- Store fs-verity descriptor in data fork side by side with merkle tree
- Simplify iomap changes, remove interface for post eof read/write
- Get rid of extended attribute implementation
- Link to v1: https://lore.kernel.org/r/20250728-fsverity-v1-0-9e5443af...

Andrey Albershteyn (31):
  fsverity: expose ensure_fsverity_info()
  fsverity: add consolidated pagecache offset for metadata
  fsverity: generate and store zero-block hash
  fsverity: introduce fsverity_folio_zero_hash()
  fsverity: pass digest size and hash of the empty block to ->write
  iomap: introduce IOMAP_F_FSVERITY
  iomap: don't limit fsverity metadata by EOF in writeback
  iomap: obtain fsverity info for read path
  iomap: issue readahead for fsverity merkle tree
  iomap: allow filesystem to read fsverity metadata beyound EOF
  iomap: let fsverity verify holes
  xfs: use folio host instead of file struct
  xfs: add fs-verity ro-compat flag
  xfs: add inode on-disk VERITY flag
  xfs: initialize fs-verity on file open
  xfs: don't allow to enable DAX on fs-verity sealed inode
  xfs: disable direct read path for fs-verity files
  xfs: introduce XFS_FSVERITY_CONSTRUCTION inode flag
  xfs: introduce XFS_FSVERITY_REGION_START constant
  xfs: disable preallocations for fsverity Merkle tree writes
  xfs: add iomap write/writeback and reading of Merkle tree pages
  xfs: add helper to check that inode data need fsverity verification
  xfs: use read ioend for fsverity data verification
  xfs: add helpers to convert between pagecache and on-disk offset
  xfs: add a helper to decide if bmbt record needs offset conversion
  xfs: use different on-disk and pagecache offset for fsverity
  xfs: add fs-verity support
  xfs: add fs-verity ioctls
  xfs: introduce health state for corrupted fsverity metadata
  xfs: add fsverity traces
  xfs: enable ro-compat fs-verity flag

Darrick J. Wong (4):
  fsverity: report validation errors back to the filesystem
  xfs: advertise fs-verity being available on filesystem
  xfs: check and repair the verity inode flag state
  xfs: report verity failures through the health system

 fs/btrfs/verity.c               |   6 +-
 fs/ext4/verity.c                |   4 +-
 fs/f2fs/verity.c                |   4 +-
 fs/iomap/buffered-io.c          |  64 +++-
 fs/iomap/trace.h                |   3 +-
 fs/verity/enable.c              |   4 +-
 fs/verity/fsverity_private.h    |   3 +
 fs/verity/open.c                |   8 +-
 fs/verity/pagecache.c           |  28 ++
 fs/verity/verify.c              |   4 +
 fs/xfs/Makefile                 |   1 +
 fs/xfs/libxfs/xfs_bmap.c        |  13 +-
 fs/xfs/libxfs/xfs_format.h      |  13 +-
 fs/xfs/libxfs/xfs_fs.h          |  27 ++
 fs/xfs/libxfs/xfs_health.h      |   6 +-
 fs/xfs/libxfs/xfs_inode_buf.c   |   8 +
 fs/xfs/libxfs/xfs_inode_util.c  |   2 +
 fs/xfs/libxfs/xfs_sb.c          |   4 +
 fs/xfs/scrub/attr.c             |   7 +
 fs/xfs/scrub/common.c           |  53 ++++
 fs/xfs/scrub/common.h           |   2 +
 fs/xfs/scrub/inode.c            |   7 +
 fs/xfs/scrub/inode_repair.c     |  36 +++
 fs/xfs/xfs_aops.c               |  55 +++-
 fs/xfs/xfs_bmap_util.c          |   8 +
 fs/xfs/xfs_file.c               |  19 +-
 fs/xfs/xfs_fsverity.c           | 511 ++++++++++++++++++++++++++++++++
 fs/xfs/xfs_fsverity.h           |  46 +++
 fs/xfs/xfs_health.c             |   2 +
 fs/xfs/xfs_inode.h              |   6 +
 fs/xfs/xfs_ioctl.c              |  16 +
 fs/xfs/xfs_iomap.c              |  45 ++-
 fs/xfs/xfs_iops.c               |   4 +
 fs/xfs/xfs_message.c            |   4 +
 fs/xfs/xfs_message.h            |   1 +
 fs/xfs/xfs_mount.h              |   4 +
 fs/xfs/xfs_super.c              |   7 +
 fs/xfs/xfs_trace.h              |  46 +++
 include/linux/fsverity.h        |  43 ++-
 include/linux/iomap.h           |   7 +
 include/trace/events/fsverity.h |  19 ++
 41 files changed, 1109 insertions(+), 41 deletions(-)
 create mode 100644 fs/xfs/xfs_fsverity.c
 create mode 100644 fs/xfs/xfs_fsverity.h

-- 
2.51.2




Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds