Received: by 2002:a25:868d:0:0:0:0:0 with SMTP id z13csp3647911ybk; Tue, 19 May 2020 09:35:21 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwgylRMkmI7mmLYclgVrK9m6Op+c8qR+rg8UnCeaWh4zHejI09q+oKzOSWWPS179iVOF4SA X-Received: by 2002:a50:f40e:: with SMTP id r14mr17696685edm.241.1589906121375; Tue, 19 May 2020 09:35:21 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1589906121; cv=none; d=google.com; s=arc-20160816; b=SM6AMW8HItRyAkQgoX2qpY7HLIejXOHXOt7hjLljUxqIeJfNMwMSApSZD2M9lAGnBs /q8Y5hUF0lJ1Knt+iCuK8B2ak5/SdeP4Gu5te30pwXRWX9D2TjS240xvCrg6g2H6s3F3 chYZP2gCJMamTArZVpEO3iLO/ZGvgaMRxvpWEp3k8Ztxw2FBw6N8Zz6TIM5sKFcyX2da 1H3w+9yiF5JMqDiyLZAz7Bd/tWYoNJEDy+P9YbtRJoV5SpKqYu/+UTyzkvnnPkYO2ZKY Gd4MQ5dk+ECNccjM9b398t6GkbuShNcLB3i00YhQH8TMkIPQeRHl0me0h7xscMSGlBYC JabQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=2FsHvUk8dZh0ajzB3TiumDfxSGd35hr/R1OCXsEMaZA=; b=ce1YA0k6ltneAh0lXfvREjC16Q8s3jWnAZgV9gBERLRt1tKgqveVK+E6jq9zGdyH6p +yP+7ihrKdh4b2c4/muGSx1HSO7EPRmFT62AaB+ssThkJSVOTEUXPQMu5ihCnpGnfr7R /c0NpWTJOSI1SLXFzjBVwLSmc3b22pSwP9RQjegGGovQ1KD+oCUo2gzCEcu5wx5FH+Ex 1rXyLyKY1Omv25eMqS50DpOAI6lhT5Bb8/nOxzSZlL9a+pA2yJPZHbQkHyUBpyCdGXx/ y9MvOTKOnQ/7aEOUbaGtEJnflsjt+BGW4ApuriC3bm0w3nshPRJOiyFuCt6vnE+5/M3U p0FA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=OuDq+uZ2; spf=pass (google.com: domain of linux-ext4-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-ext4-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id m27si187202ejd.630.2020.05.19.09.34.50; Tue, 19 May 2020 09:35:21 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-ext4-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=OuDq+uZ2; spf=pass (google.com: domain of linux-ext4-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-ext4-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729438AbgESQdn (ORCPT + 99 others); Tue, 19 May 2020 12:33:43 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47822 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729435AbgESQdY (ORCPT ); Tue, 19 May 2020 12:33:24 -0400 Received: from mail-lj1-x241.google.com (mail-lj1-x241.google.com [IPv6:2a00:1450:4864:20::241]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 796B5C08C5C1 for ; Tue, 19 May 2020 09:33:24 -0700 (PDT) Received: by mail-lj1-x241.google.com with SMTP id k5so371842lji.11 for ; Tue, 19 May 2020 09:33:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=2FsHvUk8dZh0ajzB3TiumDfxSGd35hr/R1OCXsEMaZA=; b=OuDq+uZ2QpYJRvb/GeO+A1uwQ5ZGVdYpPQNakARsRaC0tVz+Y2WhHx7QO92kh4zmEo hat1wqnZozmWrQqBpNGDXrYSjHetfvdRerSP00yzpoJpdWsHDdybi1TPyV469jMT2/Bw w//6XEQgmwhX2rpK8Bf14xhWiiSsMzArs41dJIB6inPZ7k1okxBmAkm0cZzYn+8s0AtU ISUd/6VByWUaIMiDlQ9ds+3/hneGNiP/6Ef4pq7a7WYas/7HaOxqm7ITPmJ30VyOO4SE 4cgiZVpPS9Y9QZcQhRloXVF0GMXP0p/5dX55Zve9rXXG/f4/yxiZvpTshzXuKEgWJSTA +jNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=2FsHvUk8dZh0ajzB3TiumDfxSGd35hr/R1OCXsEMaZA=; b=qnuKI1SNzDJfJveY1NkVjmhD7aKBwuTjiQPM1hnEKGJ5hrzI/Sixja5hBl+gCY01pS jGwmfVf8EmLpjh7L++p97P+gFN4P28qo+KWk989bd9njC2a6id7434Gfk2NH8SaRe7qo AFokSbMmAGDkz3leUBOH3a+8N7iKVVpHpXd+L1sOiO5x6Dfw8eYgf5pDiqJsT+5vSpYp Chh8OZhyA2bowl9oX8ebO7m7xOQcAw6r5+wUNDCgTuwPuXdQoFlHaWp5isaKM9kZybhh w2++CJgayLfCyYcMOOrFEA0Z1qf3j3wjcmYhSF+zrgkfJBTR2RcK8/lNWEXs38lqYUZi zsNQ== X-Gm-Message-State: AOAM53299amRvldT9sj5EoIS1mKaWWwkYJb0TwSsmpw6zfaI/cEs7ABV P8LP+EkJiaYE68hD7j3OlCvi3572NZHa7ZldrYx9Rg== X-Received: by 2002:a05:651c:3c6:: with SMTP id f6mr179097ljp.138.1589906002547; Tue, 19 May 2020 09:33:22 -0700 (PDT) MIME-Version: 1.0 References: <20200515204141.251098-1-ebiggers@kernel.org> In-Reply-To: <20200515204141.251098-1-ebiggers@kernel.org> From: Paul Crowley Date: Tue, 19 May 2020 09:33:11 -0700 Message-ID: Subject: Re: [PATCH] fscrypt: add support for IV_INO_LBLK_32 policies To: Eric Biggers Cc: linux-fscrypt@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-ext4@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-crypto@vger.kernel.org, linux-mmc@vger.kernel.org, "Theodore Y . Ts'o" , Satya Tangirala , Jaegeuk Kim Content-Type: text/plain; charset="UTF-8" Sender: linux-ext4-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-ext4@vger.kernel.org On Fri, 15 May 2020 at 13:50, Eric Biggers wrote: > > From: Eric Biggers > > The eMMC inline crypto standard will only specify 32 DUN bits (a.k.a. IV > bits), unlike UFS's 64. IV_INO_LBLK_64 is therefore not applicable, but > an encryption format which uses one key per policy and permits the > moving of encrypted file contents (as f2fs's garbage collector requires) > is still desirable. > > To support such hardware, add a new encryption format IV_INO_LBLK_32 > that makes the best use of the 32 bits: the IV is set to > 'SipHash-2-4(inode_number) + file_logical_block_number mod 2^32', where > the SipHash key is derived from the fscrypt master key. We hash only > the inode number and not also the block number, because we need to > maintain contiguity of DUNs to merge bios. Reviewed-by: Paul Crowley This is the best that can be done cryptographically on such hardware.