Comment 29 for bug 1305335

Revision history for this message
Rocko (rockorequin) wrote :

> I don't like the idea of eCryptfs supporting the clone ioctl by default.
> It would allow an attacker to discover that the files (the original and
> the clone) are the same.

I agree with that reasoning.

In any case, I think that the btrfs clone operation should be disallowed in ecryptfs as a matter of urgency (upstream as well), since it can result in data loss, which is far worse than the (presumably small in practice) disk space savings available though using the clone.