Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

fscrypt-0.3.7-1.1 RPM for x86_64

From OpenSuSE Tumbleweed for x86_64

Name: fscrypt Distribution: openSUSE Tumbleweed
Version: 0.3.7 Vendor: openSUSE
Release: 1.1 Build date: Sat Aug 22 21:53:30 2026
Group: System/Base Build host: reproducible
Size: 7883752 Source RPM: fscrypt-0.3.7-1.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://github.com/google/fscrypt
Summary: Go tool for managing Linux filesystem encryption
fscrypt is a high-level tool for the management of Linux filesystem encryption.
This tool manages metadata, key generation, key wrapping, PAM integration, and
provides a uniform interface for creating and modifying encrypted directories.

Provides

Requires

License

Apache-2.0

Changelog

* Sat Aug 22 2026 Marcus Rueckert <mrueckert@suse.de>
  - update to 0.3.7:
    - Upgraded various dependencies, including golang.org/x/crypto to
      resolve the usual CVEs in it (but as usual, not actually
      affecting fscrypt's use of it).
    - When selecting password hashing parameters, fscrypt now takes
      cgroup limitations into consideration.
    - fscrypt encrypt no longer follows trailing symlinks when
      writing the recovery instructions.
    - fscrypt unlock no longer enters an infinite loop when an
      incorrect key file is specified using --key=FILE, --quiet isn't
      specified, and standard input is a terminal.
    - fscrypt unlock no longer enters an infinite loop when an
      incorrect password is specified, --quiet isn't specified, and
      standard input isn't a terminal.
    - The error message when multiple protectors are available now
      mentions --unlock-with in addition to --protector.
    - Documented the udev dependency for /dev/disk/by-uuid/ links.
* Thu Nov 06 2025 Marcus Rueckert <mrueckert@suse.de>
  - update to 0.3.6:
    - Document stdin behaviour for getting raw key
    - Compare mount by value instead of reference
    - update dependencies
* Thu May 09 2024 Dirk Müller <dmueller@suse.com>
  - update to 0.3.5:
    * Upgraded various dependencies, resolving two security alerts
      from GitHub.
    * `fscrypt` now requires Go 1.18 or later to build.
    * `fscrypt` now provides a better error message when it's asked
      to operate on a locked regular file.
    * Made some improvements to the documentation.
* Wed Mar 08 2023 Dirk Müller <dmueller@suse.com>
  - move to pam_vendordir
  - add baselibs
* Wed Feb 15 2023 Dirk Müller <dmueller@suse.com>
  - add fscrypt pam configuration
  - drop pam-specs from main package
* Tue Jan 31 2023 Marcus Rueckert <mrueckert@suse.de>
  - update to 0.3.4:
    - fscrypt now requires Go 1.16 or later to build.
    - pam_fscrypt now supports the option unlock_only to disable
      locking of directories on logout.
    - Fixed a bug where the number of CPUs used in the passphrase
      hash would be calculated incorrectly on systems with more than
      255 CPUs.
    - Added support for AES-256-HCTR2 filenames encryption.
    - Directories are now synced immediately after an encryption
      policy is applied, reducing the chance of an inconsistency
      after a sudden crash.
    - Added Lustre to the list of allowed filesystems.
    - Added a NEWS.md file that contains the release notes, and
      backfilled it from the GitHub release notes.
* Tue Mar 08 2022 Dirk Müller <dmueller@suse.com>
  - use pam_moduledir
* Thu Feb 24 2022 Dirk Müller <dmueller@suse.com>
  - update to 0.3.3:
    * Correctly handle malicious mountpoint paths in the fscrypt bash completion
      script (CVE-2022-25328, command injection).
    * Validate the size, type, and owner (for login protectors) of policy and
      protector files (CVE-2022-25327, denial of service).
    * Make the fscrypt metadata directories non-world-writable by default
      (CVE-2022-25326, denial of service).
    * When running as a non-root user, ignore policy and protector files that
      aren't owned by the user or by root.
    * Also require that the metadata directories themselves and the mountpoint
      root directory be owned by the user or by root.
    * Make policy and protector files mode 0600 rather than 0644.
    * Make all relevant files owned by the user when root encrypts a directory
      with a user's login protector, not just the the login protector itself.
    * Make pam_fscrypt ignore system users completely.
  - drop 346.patch: upstream
* Wed Feb 23 2022 Dirk Müller <dmueller@suse.com>
  - refresh 346.patch with final merged state
* Tue Feb 22 2022 Dirk Müller <dmueller@suse.com>
  - add 346.patch (bsc#1195623)

Files

/usr/bin/fscrypt
/usr/share/bash-completion/completions/fscrypt
/usr/share/doc/packages/fscrypt
/usr/share/doc/packages/fscrypt/README.md
/usr/share/licenses/fscrypt
/usr/share/licenses/fscrypt/LICENSE


Generated by rpm2html 1.8.1

Fabrice Bellet, Fri Aug 28 00:06:58 2026