Skip to content

Add: Qualcomm User Data Encryption test script & Document - #141

Merged
Srikanth Muppandam (smuppand) merged 1 commit into
qualcomm-linux:mainfrom
xbharani:main
Jan 20, 2026
Merged

Add: Qualcomm User Data Encryption test script & Document#141
Srikanth Muppandam (smuppand) merged 1 commit into
qualcomm-linux:mainfrom
xbharani:main

Conversation

@xbharani

Copy link
Copy Markdown
Contributor
  • Checks for fscryptctl binary presence
  • Creates a random sw encryption key
  • Applies and verifies encryption policy
  • Confirms functionality with a test file

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
@github-actions

Copy link
Copy Markdown

This pull request has been marked as stale due to 30 days of inactivity. To prevent automatic closure in 7 days, remove the stale label or add a comment. You can reopen a closed pull request at any time.

@github-actions github-actions Bot added the Stale label Sep 12, 2025
@smuppand

Copy link
Copy Markdown
Contributor

xbharani Any update on the requested changes?

@github-actions github-actions Bot removed the Stale label Sep 13, 2025
@github-actions

Copy link
Copy Markdown

This pull request has been marked as stale due to 30 days of inactivity. To prevent automatic closure in 7 days, remove the stale label or add a comment. You can reopen a closed pull request at any time.

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
@xbharani
xbharani force-pushed the main branch 2 times, most recently from bd6eccf to 56d715d Compare November 20, 2025 09:52
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
@xbharani
xbharani force-pushed the main branch 2 times, most recently from 686cf9f to 8f29437 Compare December 8, 2025 05:26
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the script is close, but a few things will bite in CI / reliability, plus a couple of correctness/safety issues.

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few additional minor changes are required. Other than that, everything appears to be fine.

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/README_UserDataEncryption.md Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/README_UserDataEncryption.md Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Few nice to have changes

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still few must fix items.

log_info "Created unique mount directory: $MOUNT_DIR"


FS_PATH=$(df --output=target "$MOUNT_DIR" | tail -n 1)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if there's any chance of a busybox/ non-GNU environment, just be aware --output=target may not exist. Given the meta-qcom target, it's probably fine. If we want to be ultra-portable in future, this part might be abstracted into hlper, but for now it's acceptable.

Still it is not addressed. This is ok most of the time. But it can include leading spaces depending on the df output formatting.

safer
FS_PATH="$(df --output=target "$MOUNT_DIR" 2>/dev/null | awk 'NR==2{print $1}')"

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor NIT changes.

Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/README_UserDataEncryption.md Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/README_UserDataEncryption.md Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/README_UserDataEncryption.md Outdated
Comment thread Runner/suites/Kernel/Baseport/UserDataEncryption/run.sh
@smuppand

Copy link
Copy Markdown
Contributor

xbharani please respond to the comments where you have addressed. Otherwise it is hard to find what has been addressed.

- Checks for fscryptctl binary presence
- Creates a random sw encryption key
- Applies and verifies encryption policy
- Confirms functionality with a test file
- Added yaml config

Signed-off-by: Bharani Bhuvanagiri <bbharani@qti.qualcomm.com>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@smuppand
Srikanth Muppandam (smuppand) merged commit 9ce0a72 into qualcomm-linux:main Jan 20, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants