docs(cryptpilot-fde): explain dm-verity/dm-crypt layering order rationale - #135
Merged
Merged
Conversation
|
@imlk0 ,您好,您的请求已接收,请耐心等待结果。 |
|
@imlk0 ,您好,未检测到有镜像需要构建,如需重新检测请评论 /start 。 |
…nale Add a design note to the boot architecture docs explaining why CryptPilot layers dm-crypt below dm-verity (decrypt-then-verify, with the hash tree built over plaintext). The choice is driven by two practical considerations: key rotation does not require rebuilding the hash tree, and a single reference value can attest instances encrypted with different keys. Also document the alternative Encrypt-then-MAC order (verity over ciphertext) and its trade-offs for completeness.
imlk0
force-pushed
the
doc-layering-rationale
branch
from
September 14, 2026 03:11
edd4af9 to
95a603b
Compare
|
@imlk0 ,您好,您的请求已接收,请耐心等待结果。 |
|
@imlk0 ,您好,未检测到有镜像需要构建,如需重新检测请评论 /start 。 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a design note to the boot architecture docs (
cryptpilot-fde/docs/boot.mdandboot_zh.md) explaining the layering order of dm-verity and dm-crypt when rootfs encryption is enabled.Context
When rootfs encryption is enabled, CryptPilot layers dm-crypt below dm-verity (decrypt-then-verify): dm-crypt sits close to the disk (decryption) and dm-verity sits close to the filesystem (verifying plaintext), with the Merkle hash tree built over plaintext.
This order was chosen over the alternative (verity-over-ciphertext, i.e. Encrypt-then-MAC) for two practical reasons:
The note also documents the alternative Encrypt-then-MAC order and its trade-offs (stricter authenticate-before-decrypt composition, but key rotation forces a full hash-tree rebuild and the root_hash becomes key-dependent) for completeness.
Files changed
cryptpilot-fde/docs/boot.md— English notecryptpilot-fde/docs/boot_zh.md— Chinese noteDocs-only change; no code or behavior impact.