Skip to content

Add support for ZFS encryption [reworked] - #580

Open
oldium wants to merge 11 commits into
latchset:masterfrom
oldium:feature/zfs
Open

oldium wants to merge 11 commits into
latchset:masterfrom
oldium:feature/zfs

Conversation

@oldium

@oldium oldium commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This Pull Request based on work by Vince van Oosten and Joel Low implements ZFS encryption:

Status:

  • [✅ Done] Clevis bind, unbind and unlock support
  • [✅ Done] Multiple pins for the same dataset
  • [✅ Done] Systemd support
  • [✅ Done] Dracut support
  • [✅ Done] initramfs-tools support
  • [✅ Done] Manual pages
  • [✅ Done] Tests for ZFS functionality (no emulation, real ZFS needed)

Example usage:

  • Bind ZFS rpool dataset to tang pin:
    clevis zfs bind -d rpool tang '{"url": "http://192.168.1.2/"}'
    
  • Bind ZFS rpool dataset to TPM 2 pin:
    clevis zfs bind -d rpool tpm2 '{"pcr_ids":"0,4,7"}'
    
  • Unbind ZFS rpool dataset:
    clevis zfs unbind -d rpool
    

Tested:

  • Tested with initramfs-tools, both TPM 1.2 and TPM 2 pins
  • Tested with Dracut with SystemD, both TPM 1.2 and TPM 2 pins
  • Tested with Dracut without SystemD (module was disabled). Tested both TPM 1.2 and TPM 2 pins
  • Tested full Meson test suite on ZFS-capable VM

Notable ZFS-related upstream work:

Release and packages:

Fixes: #218
Supersedes: #373, #467

Comment thread src/initramfs-tools/scripts/clevis-functions.in Fixed
Comment thread src/initramfs-tools/scripts/clevis-functions.in Fixed
Comment thread src/initramfs-tools/scripts/clevis-functions.in Fixed
Comment thread src/zfs/clevis-zfs-list Fixed
@oldium oldium mentioned this pull request Sep 28, 2026
5 of 6 tasks
techhazard and others added 4 commits September 28, 2026 20:56
Bind ZFS native encryption roots by storing the clevis encrypt output in
user properties of the encryption root, split into chunks when it exceeds
the property value size limit, and unlock them with it.

Co-authored-by: Joel Low <joel@joelsplace.sg>
Co-authored-by: Oldřich Jedlička <oldium.pro@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Store each binding under its own label, "default" unless given, and keep
the list of labels in a well-known property, so that different policies
can unlock the same encryption root. The recovered key is verified before
it is loaded, and -y is passed on to the pin.

Co-authored-by: Joel Low <joel@joelsplace.sg>
Co-authored-by: Oldřich Jedlička <oldium.pro@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Unlock ZFS encryption roots bound by clevis zfs bind through the regular
password prompts of the OpenZFS initramfs integration and of the
zfs-mount-generator units, when the ZFS support is installed. Only
locked encryption roots with keylocation=prompt are answered.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Let other clevis unlockers reuse it.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
oldium and others added 7 commits September 28, 2026 23:45
With systemd, the clevis module's password agent answers the key prompt
of zfs-load-key.sh. The mount-zfs.sh has no agent protocol, so a mount
hook right before it replaces zfs by a wrapper hooking its zfs load-key,
which ends the matching plymouth prompt. With systemd, the wrapper leaves
the TCSD to tcsd.service. Tang bindings on ZFS enable networking. The
TCSD start is attempted once per boot for all unlockers, and it is
stopped at cleanup also without the LUKS unlocker.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Let other clevis unlockers reuse them.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Load the key through the initramfs-tools-load-key.d hook of OpenZFS 2.2,
its standard way for third-party tools, before the password prompt. The
pins come from the clevis hook, networking and TCSD from the shared
functions, which now run once per boot for all unlockers, under flock.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Document the ZFS commands and unlockers in man pages and in the README,
the same way as the LUKS ones.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Test the ZFS commands on an encryption root in a pool on a file. They
need root and the ZFS tools with the loaded module, and are skipped
otherwise.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
The init script sets BOOT from boot=, never boot, so the networking was
configured again on NFS boot.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Oldřich Jedlička <oldium.pro@gmail.com>
@oldium

oldium commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

Last change was to get in sync with the fix sent upstream: openzfs/zfs#19209

@sarroutbi

Copy link
Copy Markdown
Collaborator

/packit test

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Use clevis for ZFS native encryption passphrase

4 participants