Skip to content

Archive

Fs-Verity

1 articles
Cybersecurity 04 Oct 2026 6 min read

fs-verity Verifies Read-Only Files as They Are Read

fs-verity Verifies Read-Only Files as They Are Read A conventional file hash is often checked before a file is trusted. Linux fs-verity moves part of that integrity work into the filesystem. Once verity is enabled for a regular file on a supporting filesystem, the file becomes read-only and its data is checked against a persisted Merkle tree as data is read. The mechanism has a deliberately narrow boundary. fs-verity can detect data that no longer matches the digest enforced for a verity file. Authenticating that digest against a trusted identity or release policy is a separate decision. The distinction prevents an integrity primitive from being mistaken for a complete software-trust policy.