Cybersecurity
04 Oct 2026
6 min read
fs-verity Verifies Read-Only Files as They Are Read
fs-verity Verifies Read-Only Files as They Are Read A conventional file hash is often checked before a file is trusted. Linux fs-verity moves part of that integrity work into the filesystem. Once verity is enabled for a regular file on a supporting filesystem, the file becomes read-only and its data is checked against a persisted Merkle tree as data is read. The mechanism has a deliberately narrow boundary. fs-verity can detect data that no longer matches the digest enforced for a verity file. Authenticating that digest against a trusted identity or release policy is a separate decision. The distinction prevents an integrity primitive from being mistaken for a complete software-trust policy.