fscrypt Policies Bind Directory Trees to Filesystem Encryption Keys
A directory can remain fully visible in a mounted Linux filesystem while its regular-file contents and filenames are unusable without a particular key. With fscrypt, that boundary is attached to filesystem objects rather than created by mounting a second encrypted filesystem. An encryption policy assigned to an empty directory is inherited by regular files, directories, and symbolic links created beneath it. The property is narrower than full filesystem secrecy. fscrypt encrypts file contents and filenames, but most filesystem metadata remains visible, and ordinary permission checks continue to define who may access objects once the relevant key is present. Encryption policy and access control are therefore separate boundaries.