aboutsummaryrefslogtreecommitdiff
path: root/Documentation
diff options
context:
space:
mode:
authormaximilize2026-06-26 00:23:30 +0200
committerrfjakob2026-07-12 20:39:59 +0200
commit3ac282047ff36affb86f260b54ff50653007fdee (patch)
tree31ccb22fa8ef3875876c24db753f55d1c2d7b899 /Documentation
parent1a03e993cf898bd66125d88dcd682dc056a398d6 (diff)
reverse: hide custom -config file located inside CIPHERDIR
In reverse mode, a custom config file passed via -config that lives inside CIPHERDIR was presented as an ordinary encrypted file in the encrypted view, which is useless and confusing. By default the config is mapped to a virtual gocryptfs.conf, but ConfigCustom skips that mapping, so an in-CIPHERDIR custom config was neither mapped nor hidden. Plumb the config path into the reverse RootNode and treat a custom config file located inside CIPHERDIR as excluded in isExcludedPlain, hiding it from both readdir and lookup. Also document the -config reverse-mode behaviour in MANPAGE.md and add a regression test. Fixes #1009
Diffstat (limited to 'Documentation')
-rw-r--r--Documentation/MANPAGE.md8
1 files changed, 8 insertions, 0 deletions
diff --git a/Documentation/MANPAGE.md b/Documentation/MANPAGE.md
index 64bbaa8..3ef6500 100644
--- a/Documentation/MANPAGE.md
+++ b/Documentation/MANPAGE.md
@@ -457,6 +457,14 @@ Use specified config file instead of `CIPHERDIR/gocryptfs.conf`.
Applies to: all actions that use a config file: mount, `-fsck`, `-passwd`, `-info`, `-init`.
+In `-reverse` mode, this also changes what the encrypted view contains: by
+default the config is exposed there as a virtual `gocryptfs.conf` (so a backup
+of the encrypted view is self-contained), but with `-config` no `gocryptfs.conf`
+is presented. Make sure to back up the config file (or the master key) from its
+custom location separately, otherwise the encrypted data cannot be decrypted.
+If the custom config file is located inside `CIPHERDIR`, it is hidden from the
+encrypted view rather than exposed in encrypted form.
+
#### -cpuprofile string
Write cpu profile to specified file.