> "You can trust any disk whose blocks you can decrypt with key X, to have been only written to by someone with key X."
No you can not. That is your sentence not from Secure Boot People.
Also I assume that APFS will support encrypted and unencrypted logical FS in the same space sharing FS instance. So the separate OS partition is just a logical FS which is unencrypted. - Which I meant in my original post.
GELI and the AES-GCM are authenticated. Not sure if GCM has equivalent properties to the GELI HMAC feature but probably good enough.
No you can not. That is your sentence not from Secure Boot People.
Also I assume that APFS will support encrypted and unencrypted logical FS in the same space sharing FS instance. So the separate OS partition is just a logical FS which is unencrypted. - Which I meant in my original post.
GELI and the AES-GCM are authenticated. Not sure if GCM has equivalent properties to the GELI HMAC feature but probably good enough.
https://en.wikipedia.org/wiki/Galois/Counter_Mode