Releases: vgough/encfs
Releases · vgough/encfs
Release list
2.0 beta 1 - Rust rewrite
Complete rewrite in Rust.
- Supports reading/writing existing encfs folders.
- New encfs volumes use a new signed config format
- New defaults: encryption mode, key derivation function
v2.0.0-beta.1 / 2026-06-14
* Implement `encfsr` for a virtual encrypted read-only filesystem (reverse mode)
* Complete migration away from OpenSSL to pure RustCrypto implementations
* Process-level memory protections and security hardening (prevent tracing/dumps)
* Force configuration files to be safely synced to disk using fsync
* Support disabling path IV chaining on creation
* Correct file holes and truncation handling
* Verify current password when changing passwords
* Add fuzz testing and switch integration tests to nextest
v2.0.0-alpha.3 / 2026-02-21
* New config format added which is tamper resistant
* Add new block encryption mode, aes-gcm-siv
* Add new key derivation mode: Argon2id
v2.0.0-alpha.1 / 2025-12-13
* "encfs" main program ported to Rust
* Old C++ implementation and support moved to `legacy` directory
v1.9.5
- Correct a int/off_t buffer overflow in getSize() (#468)
- Correct a possible write crash (#494)
- Correct
encfsctl catand addencfsctl --reverse cat(#483) - Add
-c&-ucmdline options (#474) - Add
--noattrcache&--nodatacachecmdline options (#500) - Ignore .encfs6.xml file in reverse mode (#478)
- Do not count usage on root path (to avoid resetting the
--idleoption) (#471) - Use stderr instead of stdout for error messages (#491)
- Add the ability to disable data encryption (absolutely discouraged) (#487)
- Add Cygwin support (#499)
v1.9.4
v1.9.3
NOTE: The v1.9.3 release incorrectly reports version 1.9.2 when compiled.
- Fix compilation with "-std=c++11"
- Fix a gid permission issue with allow_other
- Fix operations on symlinks
- Fix a race in idle unmount
- Add
--reversewritecli option - Add PID to syslog logging
- Deep code sanity check
- Modernize coding style
- Make codebase warnings & clang-tidy clean
- Bump FUSE_USE_VERSION to 29
- Ensure compatibility with LibreSSL
- Switch to vendored lib tinyxml2 & easylogging
- Reorganize man page and add missing options
- Add gtest and micro benchmarks
v1.9.2
- fix a use-after-free bug that was introduced in v1.9-rc1 (#214)
- cast booleans to int before writing the XML config (#343)
- support reading the config file from pipes (#253)
- add "-t" option to set syslog tag
- allow read/write in standard reverse mode (#301)
- reject empty passwords
- support building with openssl 1.1
v1.9.1
v1.9
Build system
- switch to CMake
- OSX build improvements, RPATH setup
Dependencies
- Drop Boost dependency. Uses tinyxml2 to read existing XML config archives.
- Drop librlog dependency. Uses easylogging++ for logging.
FUSE and FreeBSD updates
- add encfs_create operation
- replace getdir with readdir
Misc
- cleanup includes and reformat code
- allow writes in reverse mode when no header is used
- make use of C++11 (eg std unordered_map in place of GNU internal hashmap)
v1.9-rc3
Fixed in rc3:
- install gettext translation files
- do not install internal libraries (libtinyxml2)
- do not install static library by default (libencfs.a)
Previous changes since last 1.8 release:
Dependencies
- Drop Boost dependency. Use tinyxml2 to read existing XML config archives.
- Drop librlog dependency. Use easylogging++ for logging.
C++11
- use std unordered_map in place of GNU internal hashmap
Build system
- switch to CMake
- OSX build improvements, RPATH setup
Fuse
- add encfs_create operation
- replace getdir with readdir
Misc
- cleanup includes and reformat code
- allow writes in reverse mode when no header is used
v1.9-rc2
Dependencies
- Drop Boost dependency. Use tinyxml2 to read existing XML config archives.
- Drop librlog dependency. Use easylogging++ for logging.
C++11
- use std unordered_map in place of GNU internal hashmap
Build system
- switch to CMake
- OSX build improvements, RPATH setup
Fuse
- add encfs_create operation
- replace getdir with readdir
Misc
- cleanup includes and reformat code
- allow writes in reverse mode when no header is used
v1.8.1
- add
configurescript to release tarball - reverse: re-enable kernel cache (bug #60)
- reverse mode: disable unique IV by default (was enabled in 1.8)
- add
make benchmark-reverse - remove
-o default_permissionsunless needed to improve performance - add option
--require-macs(bug #14) - add po files to git (bug #63)