From nobody Fri Oct 2 12:24:38 2026 Received: from fhigh-b3-smtp.messagingengine.com (fhigh-b3-smtp.messagingengine.com [202.12.124.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D866E469829; Fri, 31 Jul 2026 16:27:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.12.124.154 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515274; cv=none; b=MsjVKLp8k1VjPyOa+R6hZB7qfKzUjDwBcNxAfGrn7Hu7fOFW3ZWKAYsjQCjF/9yJYe/bLXu+RlS6N0SNIl+2qIoLqYElPzGEcBYR6tQqLrYrLtBglaZlfds6qMGfzKJu+rLCtJTpXfEmCDjAUU61YwMNvuKarz0K4UZKbYpK08A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515274; c=relaxed/simple; bh=oQakT4tZTZ26yYuWUyxmknYxLRV5Ax8XxkRik07misk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=aU7ogxYRAQZfibPOwBwQw69+5zz4TaEGJIXhIsVF6WWCPg8LHCaXBBRW+PvT18CMTHivhlBFr8c2z0VQPiNupm12EfsrGptrz/4VdwfRTbFqHJzU2zmUHpGi98ZBok6TX4yjhVNJ6P8pAScUyeSK0E8D5H8ApnPXdPYAGxGXHtI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de; spf=pass smtp.mailfrom=jaseg.de; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b=b5nCQHhm; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=aQa0aJKS; arc=none smtp.client-ip=202.12.124.154 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=jaseg.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b="b5nCQHhm"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="aQa0aJKS" Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfhigh.stl.internal (Postfix) with ESMTP id 4D71A7A00C2; Fri, 31 Jul 2026 12:27:49 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Fri, 31 Jul 2026 12:27:49 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jaseg.de; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1785515269; x=1785601669; bh=J5nIrNoSMiFUIl5DH8xWdANuglVgj8cbxwTsb9rwYoA=; b= b5nCQHhm0J+Bh4qWMlYQ+VsiYMqE3pkfp60xUmMoRloMX0iNUYrevWKmbbyiOWGv C8A4jONRfkjwdqa4UDoPf2/VFB+0CJDYxlfdIuwSFIxZ1y5yisj6t0jPZSM4VxsH pqOYwrh8rjbx+0D9GGSdTnnVK18qbw6BQAVphQpwLDfz4mV8GxmENU1812Qmh5Mh Ai8uEnYo6JS6yVNNqsya7j+iQ9tZbapAF0QAWYlNV4Tj9LskF3Mp8dVvKMe/e6jt bPcW0IZ8vzdsMlpLkaVB7E1912BAhzHsum9haIOY48eNaYCmPLEPkjirpl8oGvVO BCNwOK0df5Nv7Fh7gsl1uQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1785515269; x= 1785601669; bh=J5nIrNoSMiFUIl5DH8xWdANuglVgj8cbxwTsb9rwYoA=; b=a Qa0aJKSLM9u3cdJFxgBm0tbxdbLzGB4URrat1wcWTbAgoDVihHaOx1FvOk5GIiQR /9p0LgUh2oyils3n7tYpJKvL79ebLZhQB0aghE1ZC1j4GhFSfbj859ouesVQHpTR 21iCK7tU/bndrfcMO96y43oh9nCedWbYQwwgEDW3Ng2xKkth4bK/CclGpjKqfrNr 6g3aqGKku+hEg9VOusp0tbXKRRX9+w2lHNgEwF9ea2ZOoWk1yP9DpQEtpDwF+IsT OVW5dLG/FN5Eg5QFY7GFd4Cg0P0hlhUvEJGbgcnZD7AL/LonmXWVSSdE+vPlk7K8 GD2+mOHKnOpxl9PcfPyJA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTGGTelZmm0/EhQAYArVTdDhZzjnmAPb6bZI2uOfRhcPRz2TI2oV8V45PSh9LdLr+9 dOlgXoBfEoyyFAhrcqXPD5Q9hVEjtJXoIhF2MoKd1yKDTw2ea5Nuq/+/AmFYSUo339o9zZ H/at4LG3KrzxwoyaKUbXnTAmsLw8u8bstL0n0Hm+zeS6dtuk4WBOYvxR1KeM91qs9pbTHn V5Yj6ph4RyA95kbMawVJDFVjaiGwugJQQV6H1QnRSnyH1rCnmQnAGiB4dMHKZak/Asn8tO F/0oy0n4YeNO9MT0ImsCVvnJvFB1zR3ciQwN/2JEWm+YOztTqwzq31OHYrU6wne+Cpi3K5 TTD8qnOBAfOaIb/KCcnmwKr8TGm24y8rMJ8KNnshmEvBNvcrVA3lZ/fsqnabQ+bcEZvCxK jVF6kNhPnROpmUpXsT9cQQ9WQAmvp3ChKXD/51Kcb96H3pMPJzDNcq1KfaKpkTZ8t4KfO5 AZsrHKXNbdf8Go9a0FfJSzKbdlEWCCQe6tUIEj8/1faJjDnVbgdenfwqKItxhfUu5xB2KJ wGozjEql6w4pzgqozJiilyeInEsR6qujBgBrWFTgx+kdN6tGchhD24yAmJ/Q5c67/RvrEs wT/Jm4IWcIvL3Yzv1SN3Sy2S1UiUxCs+GGRjhmkWjnngDVFojYXuBC16Bqmg X-ME-Proxy: Feedback-ID: i60a14417:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 31 Jul 2026 12:27:47 -0400 (EDT) From: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= To: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, kexec@lists.infradead.org, keyrings@vger.kernel.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org Subject: [PATCH 1/4] of/kexec: fix typo in comment (usable-memory-range) Date: Fri, 31 Jul 2026 18:27:36 +0200 Message-ID: <20260731162739.158320-2-linux@jaseg.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731162739.158320-1-linux@jaseg.de> References: <20260731162739.158320-1-linux@jaseg.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Signed-off-by: Jan Sebastian G=C3=B6tte --- drivers/of/kexec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/of/kexec.c b/drivers/of/kexec.c index 029903b986cb..36635f6cb900 100644 --- a/drivers/of/kexec.c +++ b/drivers/of/kexec.c @@ -24,7 +24,7 @@ =20 /* * Additional space needed for the FDT buffer so that we can add initrd, - * bootargs, kaslr-seed, rng-seed, useable-memory-range and elfcorehdr. + * bootargs, kaslr-seed, rng-seed, usable-memory-range and elfcorehdr. */ #define FDT_EXTRA_SPACE 0x1000 =20 --=20 2.53.0 From nobody Fri Oct 2 12:24:38 2026 Received: from fout-b1-smtp.messagingengine.com (fout-b1-smtp.messagingengine.com [202.12.124.144]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 155A93672AA; Fri, 31 Jul 2026 16:27:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.12.124.144 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515277; cv=none; b=JkRhHxxbLJt7fsKuWcpy0x7MlaOJPZaZFJdDGqrAeEa7/IMv1YqKbDCVTtRIyfx41FZo6HhocVdSw7VABYni2GxkE6Zg0J/8XvanY9c+GVRh+7BxHhK4Ev3xfThy/FgZOl7iSUFlpH/U+cOA+f4PJgXnhAzdFLVMBfHLZiPkFYQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515277; c=relaxed/simple; bh=I2k9tNY8KM9fClDrZSMYISjwoUpnSWKEICUB8QwP4cM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=SQGGF5+rGfw8V3UdfDrj8dmSCcIbP78vZQKuYKKKd+2S9T84EeVY9Mtv0Kay9FQ2GH7FGqYTh2G6chi3j5AvehgkA5RiRy6DI8k8EexSv72dLKcfH1zE2UOE6vSlGnJo9SSsqfn/xqu651xeH6a4gO9sBEn/HeOD4FflKljhwGg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de; spf=pass smtp.mailfrom=jaseg.de; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b=Hclb6FV2; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=Wv7tZH1Q; arc=none smtp.client-ip=202.12.124.144 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=jaseg.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b="Hclb6FV2"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="Wv7tZH1Q" Received: from phl-compute-01.internal (phl-compute-01.internal [10.202.2.41]) by mailfout.stl.internal (Postfix) with ESMTP id 41BD21D000DD; Fri, 31 Jul 2026 12:27:51 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-01.internal (MEProxy); Fri, 31 Jul 2026 12:27:51 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jaseg.de; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1785515271; x=1785601671; bh=WDJuTD8Vcay2+Rdlju8jd0+4JfwRzRzUz3/gOwvyzEk=; b= Hclb6FV2E4h7miUmIFatF7vgILbkq5iEkCMeqX58TuS1emswDoozRst6lCLKrT1r IwITO94liQrRfXoq/UR1Cp45KPNsviPwwaTbL5dl1J8NxCPQ13RczR1dczbxjxZP 9yc1a8zrGTfnHzhDuEwa7y5ErpPHcdhwPrDPhXLxII/PT8FJzNMWEp4NwHhtdTXf h4j/3BmUkYfS/ar6hgh3ffuMnR6LX31WkKnzR/LgTwG20Zs/bgUe0u2jMR8u2zXW 9R/T76b5+qNd+cj2Mbi7EhQyyRkH8+/nDEC5w5Lp3crhvIugjKbgkLBw0MzF4u84 yWx3dHwY61PVrsiE8Ham3A== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1785515271; x= 1785601671; bh=WDJuTD8Vcay2+Rdlju8jd0+4JfwRzRzUz3/gOwvyzEk=; b=W v7tZH1Q/YHqS3HUVGTuTIPse3MKFqCZelV6q9mYHY4epWM2zC+aAKpHYzUeAySVC rDOKrgHWMN+O21uy3IjLf3ebGB2cUpbFc3LQ7G6aurdaEeA5N6MEJv2wJ/zSiWbP AzPKJ8WKMUGeylC2516STchvP0vG+fB7DTU5uv3wEV052H0Mrkg6lwAozynmpeTi YNJKnLkhgerLAIWp2Np26HbQP2WFTZGHiQTXKltDpnYyfV5XOCXl40+zj4O6UJTE TXsFg/Igq8SRvisRCMykDMbxchMDiktjSKPctY0bjnbFHdBJG4S74Lyu6QKijenN vK/oIJEMFzMqNN3Xz1HSw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTELfHAaFlN+kIG6IssmIq8q0/JRtHYiEDamnKwtHAGTm/rIkphiM7dmck7n/tEVID Jll9XZRXegS5DA66U1m8pj9kUlkWW6jbmxkpZ2Vy+f9sbLWY4LPn/k9o06nVK28CzSnHlD lWYRxoJf+HWhSZ1zy9/rODG5OphaTJnkZfxiinHtBeukYGRaEV6rsOpAthbf9Rnwd5neaW b5ga7UTCgjqgAq9wYXuIHu4RL0lK64k1SgzKLwhWoz9uN8eIJVTlSs/QiafsKJeCqGBPP+ mXVeoA/rZsAKFBE67k4yvTZ9NpiBwhCbzC9zQWp6wR2HnNM114K5oGLjvHnZO8zy7kGoVA hWs1HmKnirvo6badLfxFLC1ngv0vJGoRz2yU1pHhumbJcOkKOI1TtNPdhNaBkQabzrHwSs Y+7ylrnEBz1FMgf9G6IsR8hTGiv7XS1m50dEM7iVhvYlPUG0379fhge2f9V/z3oUvLoxr9 ROaKaguFReJhiqZNhkD2XnlISmZ06TLF+XHEmpScoNRo1mg4BzI04MU+Oxq/K72xAlD1/c lRg7SLxd+kAXPrpQII8V7zbztgUBuWpkzKb8l+6UjlDsNcWEj2Tr5qCKIMZOXP0v6qIQIy +V+eXG639NjJ3RxuUWndaCx4R8t6V8NOngjS48abG8QAD/cuG5n/twKPLx9w X-ME-Proxy: Feedback-ID: i60a14417:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 31 Jul 2026 12:27:49 -0400 (EDT) From: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= To: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, kexec@lists.infradead.org, keyrings@vger.kernel.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org Subject: [PATCH 2/4] kexec: add CRASH_ZEROIZE to wipe secrets before kdump Date: Fri, 31 Jul 2026 18:27:37 +0200 Message-ID: <20260731162739.158320-3-linux@jaseg.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731162739.158320-1-linux@jaseg.de> References: <20260731162739.158320-1-linux@jaseg.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When kdump is used to capture system memory after a panic(), any secret keys currently in RAM end up in the dump. Add an opt-in atomic notifier chain, crash_zeroize_notifier_list, invoked late into __crash_kexec(). Subsystems holding secrets can register a callback to scrub them. Callbacks are run after machine_crash_shutdown() has already stopped the other CPUs and disabled preemption. Callbacks must not wait on locks, which will never be released. This is a best-effort, defence-in-depth measure, not a guarantee. Secrets in flight on the stack, in registers, in DMA buffers, or in other places in memory are out of scope. Signed-off-by: Jan Sebastian G=C3=B6tte --- include/linux/crash_core.h | 5 +++++ kernel/Kconfig.kexec | 8 ++++++++ kernel/crash_core.c | 18 ++++++++++++++++++ 3 files changed, 31 insertions(+) diff --git a/include/linux/crash_core.h b/include/linux/crash_core.h index bc087124cd78..5c7207c0bba1 100644 --- a/include/linux/crash_core.h +++ b/include/linux/crash_core.h @@ -5,6 +5,7 @@ #include #include #include +#include =20 struct kimage; =20 @@ -34,6 +35,10 @@ static inline void arch_kexec_protect_crashkres(void) { } static inline void arch_kexec_unprotect_crashkres(void) { } #endif =20 +#ifdef CONFIG_CRASH_ZEROIZE +extern struct atomic_notifier_head crash_zeroize_notifier_list; +#endif + #ifndef arch_crash_handle_hotplug_event static inline void arch_crash_handle_hotplug_event(struct kimage *image, v= oid *arg) { } #endif diff --git a/kernel/Kconfig.kexec b/kernel/Kconfig.kexec index 15632358bcf7..92ab0a69c8ec 100644 --- a/kernel/Kconfig.kexec +++ b/kernel/Kconfig.kexec @@ -179,4 +179,12 @@ config CRASH_MAX_MEMORY_RANGES the computation behind the value provided through the /sys/kernel/crash_elfcorehdr_size attribute. =20 +config CRASH_ZEROIZE + bool "Zeroize secrets on panic" + depends on CRASH_DUMP + help + Wipe secrets (e.g. kernel keyring and memfd_secret pages) on crash or p= anic. + + If unsure, say N. + endmenu diff --git a/kernel/crash_core.c b/kernel/crash_core.c index 2b36aa9fade0..d3a7763e2759 100644 --- a/kernel/crash_core.c +++ b/kernel/crash_core.c @@ -23,6 +23,7 @@ #include #include #include +#include =20 #include #include @@ -33,6 +34,22 @@ /* Per cpu memory for storing cpu states in case of system crash. */ note_buf_t __percpu *crash_notes; =20 +#ifdef CONFIG_CRASH_ZEROIZE +ATOMIC_NOTIFIER_HEAD(crash_zeroize_notifier_list); +EXPORT_SYMBOL_GPL(crash_zeroize_notifier_list); + +static void crash_zeroize(void) +{ + ktime_t zeroize_start =3D ktime_get(); + + pr_info("Wiping sensitive secrets...\n"); + atomic_notifier_call_chain(&crash_zeroize_notifier_list, 0, NULL); + pr_info("Done in %lld us\n", ktime_us_delta(ktime_get(), zeroize_start)); +} +#else +static inline void crash_zeroize(void) { } +#endif /* CONFIG_CRASH_ZEROIZE */ + /* time to wait for possible DMA to finish before starting the kdump kernel * when a CMA reservation is used */ @@ -142,6 +159,7 @@ void __noclone __crash_kexec(struct pt_regs *regs) crash_save_vmcoreinfo(); machine_crash_shutdown(&fixed_regs); crash_cma_clear_pending_dma(); + crash_zeroize(); machine_kexec(kexec_crash_image); } kexec_unlock(); --=20 2.53.0 From nobody Fri Oct 2 12:24:38 2026 Received: from fhigh-b3-smtp.messagingengine.com (fhigh-b3-smtp.messagingengine.com [202.12.124.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 760AD46985D; Fri, 31 Jul 2026 16:27:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.12.124.154 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515282; cv=none; b=fWnCYJ422EQqrk/z/1aGhReSZ6+6xIjeB7GH96eTXIzexunxQtrs3b3o49L563bQQz87KnBmNWW9bR6HY107OPswPgmrLJ5ze7KdcVfJyD1fdGESrhKNlwOkOF/wQ/LYesor7XE8vK//he9bA9cZ+lHkbHWw6D8AsOJxLE8+iRM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515282; c=relaxed/simple; bh=vS5BfHBU3Cnn2TXuBo2HKYKqPnGyz48W7eVptxeLUZ4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=MbhovJDsY1Q7Kp6n2NVrZjNOZ94+oO5bedy5iFa7ct5Lq+IQgz9mhxSasiplXPK2HGJbd9Jwbtuh4VvQIJ7Xv03rdIPXg7gZD9ic4BXvO6ertqkywR2K2+DggJLRRBHSiBWzwLXh7uGMPRijSktfvo5FZkSWqJhIXJ1jCEZ9vJ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de; spf=pass smtp.mailfrom=jaseg.de; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b=k0Fn2v0h; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=dsZHhPgu; arc=none smtp.client-ip=202.12.124.154 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=jaseg.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b="k0Fn2v0h"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="dsZHhPgu" Received: from phl-compute-07.internal (phl-compute-07.internal [10.202.2.47]) by mailfhigh.stl.internal (Postfix) with ESMTP id 3A9757A011A; Fri, 31 Jul 2026 12:27:53 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-07.internal (MEProxy); Fri, 31 Jul 2026 12:27:53 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jaseg.de; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1785515273; x=1785601673; bh=vuhD3aoT0AyBzEwnNlnOqTcbkLD3kV+I1Y8Pd5N2o2I=; b= k0Fn2v0hBAvs16EZ/yLw7TLmuFAcOyD/YVjC8Ouq96comN5aDewzZCfL0asIk2DM c7VaqQfnLFOz3ABgiGWXaGftTmHIkQV30TQUqsMkko6p8fVn/eX1C7HZKlwCwSZ/ 2q5TdpN7JGDxH/IaZPK8mBG2PdPABArXvqZxVV0f1jdA44KVF1NtJaTuAFfaSGbL 1WbTOlIVJrCpI1KDUJ3L5Cp6TI8dLucgg5JT/pkj3NQxdJHUdAdjESSRuZ6G6LkT 7zRhJxK8optUcn1MCi5sFsYsVZA/q/8vf9K0Fr4Yg6lynEgKjmq4NGh58slVn9tg v5mBwTY08HlUzvXNCUe6rQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1785515273; x= 1785601673; bh=vuhD3aoT0AyBzEwnNlnOqTcbkLD3kV+I1Y8Pd5N2o2I=; b=d sZHhPgulOxyRAtF1Xbe6k93rj3Mywvhma1m4kxcnHqoNqiBzekcoalPjzyO1gyy+ Y4jC5rQKNvHv9ZYWpvZ+aDztsnCABebXs2Izww02hHxEj5V1Rp4vh6Xd7wyVDujc 8xB5SdcKqwRsoFyI2w/FVwJBzuiln+aLCY4ODovodqBgvz+bou6uK56JmAAQfn4T wVX7XWb7r/BoMEjViUVmIqxm2mE1gRlklds09mmeDQMN78mjMinH0wJjCMz+ih4M 06Aeu0npEkJowZhGqcRJLLl2c+ATj2EFJClO+H2uctY06MJF15RsbvGuFqtoRkDR VCNNIPnCa5cPuhlsXu4XA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTELfHAaFlN+kIG6IssmIq8q0/JRtHYiEDamnKwtHAGTm/rIkphiM7dmck7n/tEVID Jll9XZRXegS5DA66U1m8pj9kUlkWW6jbmxkpZ2Vy+f9sbLWY4LPn/k9o06nVK28CzSnHlD lWYRxoJf+HWhSZ1zy9/rODG5OphaTJnkZfxiinHtBeukYGRaEV6rsOpAthbf9Rnwd5neaW b5ga7UTCgjqgAq9wYXuIHu4RL0lK64k1SgzKLwhWoz9uN8eIJVTlSs/QiafsKJeCqGBPP+ mXVeoA/rZsAKFBE67k4yvTZ9NpiBwhCbzC9zQWp6wR2HnNM114K5oGLjvHnZO8zy7kGoM+ 43ztEq9yvmk5FIo339uS7eTYuFuzoPGBEBAV56zSFneeUyT1x+W8YuJDcNHflL5vlg94Nc tRE/z0/TBF6FknKyzSzFwXEGXce61rnIpBKiwhKAJPH1q9EgnFkJH/sYGfFrxEcKBzyjWF wJSyyb0894hIenNcHuohbTXDuBYnFqA9f9SKfwB/j1Fia7HM5hm118pFRPbsHhewSXfAqg 1BMqPWBdv1JpB+6v6hYDG3BaNrKft+MpEMXFdE7J5adB6kIQFZDjk4ycPJK4tw3VG5E28x OVWMXqMrDck/XjQJJw4OWKtP4nkq1iPW22fpkHdEnpj5tXx568GTn10k6v1Q X-ME-Proxy: Feedback-ID: i60a14417:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 31 Jul 2026 12:27:51 -0400 (EDT) From: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= To: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, kexec@lists.infradead.org, keyrings@vger.kernel.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org Subject: [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump Date: Fri, 31 Jul 2026 18:27:38 +0200 Message-ID: <20260731162739.158320-4-linux@jaseg.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731162739.158320-1-linux@jaseg.de> References: <20260731162739.158320-1-linux@jaseg.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Register a CRASH_ZEROIZE notifier that wipes secretmem folios. As a result, when CONFIG_CRASH_ZEROIZE is set, secretmem areas will be cleared before the kdump kernel is kexec'ed. Zeroization runs after the other CPUs have been stopped, so the page cache cannot be mutated concurrently and the xarray may be walked without taking the i_pages lock. This is a best effort, defense in depth measure. s_inode_list_lock is taken with trylock only. If a CPU was stopped mid-modification the list may be inconsistent, and this late into the panic path, there's nothing we can do about it. Signed-off-by: Jan Sebastian G=C3=B6tte --- mm/secretmem.c | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) diff --git a/mm/secretmem.c b/mm/secretmem.c index d29865075b6e..53f629d6633c 100644 --- a/mm/secretmem.c +++ b/mm/secretmem.c @@ -13,9 +13,11 @@ #include #include #include +#include #include #include #include +#include #include #include =20 @@ -187,6 +189,50 @@ static const struct inode_operations secretmem_iops = =3D { =20 static struct vfsmount *secretmem_mnt; =20 +#ifdef CONFIG_CRASH_ZEROIZE +/* Called far into vpanic from crash_core.c with other CPUs stopped and + * preemption disabled + */ +static int secretmem_crash_zeroize(struct notifier_block *nb, unsigned long + action, void *data) +{ + struct super_block *sb; + struct inode *inode; + + if (!secretmem_mnt) + return NOTIFY_DONE; + sb =3D secretmem_mnt->mnt_sb; + + /* If the list was modified in the exact moment we panic'ed, it might be + * in an inconsistent state that would be unsafe to iterate. If we can't + * get the lock, too bad, that's all we can do here. + */ + if (!spin_trylock(&sb->s_inode_list_lock)) { + pr_crit("crash_zeroize: can't acquire secretmem superblock lock.\n" + "crash_zeroize: skipping zeroizing secretmem.\n"); + return NOTIFY_DONE; + } + + list_for_each_entry(inode, &sb->s_inodes, i_sb_list) { + XA_STATE(xas, &inode->i_mapping->i_pages, 0); + struct folio *folio; + + /* no need for locks if we're burning down the house :) */ + xas_for_each(&xas, folio, ULONG_MAX) { + if (xas_retry(&xas, folio) || xa_is_value(folio)) + continue; + inode->i_mapping->a_ops->free_folio(folio); + } + } + /* off to kexec()! */ + return NOTIFY_DONE; +} + +static struct notifier_block secretmem_zeroize_nb =3D { + .notifier_call =3D secretmem_crash_zeroize +}; +#endif /* CONFIG_CRASH_ZEROIZE */ + static struct file *secretmem_file_create(unsigned long flags) { struct file *file; @@ -263,6 +309,10 @@ static int __init secretmem_init(void) if (IS_ERR(secretmem_mnt)) return PTR_ERR(secretmem_mnt); =20 +#ifdef CONFIG_CRASH_ZEROIZE + atomic_notifier_chain_register(&crash_zeroize_notifier_list, &secretmem_z= eroize_nb); +#endif + return 0; } fs_initcall(secretmem_init); --=20 2.53.0 From nobody Fri Oct 2 12:24:38 2026 Received: from fhigh-b3-smtp.messagingengine.com (fhigh-b3-smtp.messagingengine.com [202.12.124.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0B1EF4508EB; Fri, 31 Jul 2026 16:27:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.12.124.154 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515282; cv=none; b=LO4qwcugr+M12JzFyBEtfEeeKbHybjQ83hIk1tuqtSILsUUm4LpgRMJE38dw7VWkxoaapUyAUm04iduGCOUYBiXqBSxiLTyYx9NxAJ6f2Zska8pb0A3yV+2uWbTBOL066YtIG9JSN2IbBcMYk8pidAFVXzANZb3l2R2NLR7zFVg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515282; c=relaxed/simple; bh=79WnKnmlwUieqZ8sU7dL38///FPa2eNTv6xm5BkH4gc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=blEBQzTE7HBDJsrICeAzrBVtV3eNV461lF42TgdOrAguWuH4A384iIQNPehqM64cyGfZDVABAflHjLgNPXShgSYoGdT56z5Qt6DqqtuDzb13jW0JnSXJ4F+cvgaly5amQGIKl5A3OSMGzy2Vowop29a/bipVltTMMY3E4QXSbsA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de; spf=pass smtp.mailfrom=jaseg.de; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b=YUz5MR51; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=cE7SOqoa; arc=none smtp.client-ip=202.12.124.154 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=jaseg.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=jaseg.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=jaseg.de header.i=@jaseg.de header.b="YUz5MR51"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="cE7SOqoa" Received: from phl-compute-01.internal (phl-compute-01.internal [10.202.2.41]) by mailfhigh.stl.internal (Postfix) with ESMTP id 230AA7A0112; Fri, 31 Jul 2026 12:27:55 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-01.internal (MEProxy); Fri, 31 Jul 2026 12:27:55 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jaseg.de; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1785515274; x=1785601674; bh=6RJPYbBdKyVevokLLvrFaLY6IOxzeT8FvabNtZpBPjM=; b= YUz5MR510i+WmXGI7a4kC5uqawHagcWlThX/znOeuRjkIJrcn2zxv0EsYGbM20lb i5yjscraNBNQfufT3LtYFRxnI0PCj5X76beHrvcmSIEU1d2fHZrUWO6XIAi7OWDU rpE2w0joPx55gGeemOiiqSM0bOSu6EgZj9K2NvJ0uJI8fg0aS8KZhGS1sXhk9EeU Xn3a0nNO7LYe5vFb9ipY8TccSzGCc1jNGae7Ncb+VoA+eEMurDBLCM1RyDXi/jwi Bl1clFSRw9/MyZyGuTc3fleqXsSSmVHhcMZQUkkwkNP7Myvg7pMS4n7PX8M9XHTS KeJ2d49aUOJSd3kt7vIPeg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1785515274; x= 1785601674; bh=6RJPYbBdKyVevokLLvrFaLY6IOxzeT8FvabNtZpBPjM=; b=c E7SOqoa3Otd7WsGDI1EXvQLZ5uj79zcwLoXFNNZ3ZhmOiWo8vcAxHQw5MA8dqUYd 7DQvxudJBbVDkploQoBg1qu3X/W/4umdXLFrwfFlzY9Gf//CeCIvl0yiml7ROhqK Qb2QCGMeNGxi351dOwLvEtDB3+vChBbKO2cVaF4xTLljSb95UrLr61C3cvwvbfaq yV2E5czozC/kxvDeddrTSmn9PJhduC5uBwqKjjcfB0L8sEZ5+HD/gFVbI7SZmjQd HKX+jX74c1FBv7HDt74zfE5RrnOw/PFTwFKQ6yAlkc64gKUEGtkzrLebYsnfwT0l HKxWtXy94CSDS2JuLZp7A== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFK/nfZ71g8ktujuuoyrF9Ty3Awc1kurrPu2o1v6nhgMM6NL3zj5ESd/fiJ+lq6Fq Z3OuJgsO9Fs2GPtTwEyFZyDKihsNiiEsnOWMvsOfBTFOP9roQM0mTP8MtpTOtxDCDWThhp R6cquw+SMl49Oku+QQXCkKW+TrFunMbAzDZTMwRiMkrGaoNe0GLi6W90Q6fubhxR5onr5q JMP4yfob1UtqZ4XCQdoJfvSelSRy/3zTBtxj7H4AUAz0Xtt/lL1/4chym5iL4gRXLFaWSQ TqzwgVHkZuxaKP3mHZdHzlPw99hzi3gU4xKCX1rRjxCDxKjnlHRIs9asJOBHpx9Xtx82Wu KfYE0fXzVTV12FAmSzQyjawktIBVNf4pTw9FSHRBmhVSjR/DfddoxPl4utqYB4lxLjouzt oXC5NAFahcYIV6iVTmqO7YcRb0qN1Q5SAf4H5gLw4tfLgIBe6suNECZv0viYMaX8RmL/Z0 mWD0jSZEDPOu6r2LNzYFAaUhaglPqA+u4ArkGHwvjPud20jbUikr0ul60+KyV5NudeSHon KHKewFBLzNSRafof6rP0ltLpAIe7339yDePtxqrF1sw2mIchka9xTpJ9ZDEige5ZTrIo+b 18pexHS4+MVejnDnuk3GvyPN1lshEFrhRooCzfsWwDeVqxpuffogHi3ECxTA X-ME-Proxy: Feedback-ID: i60a14417:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 31 Jul 2026 12:27:53 -0400 (EDT) From: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= To: =?UTF-8?q?Jan=20Sebastian=20G=C3=B6tte?= Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, kexec@lists.infradead.org, keyrings@vger.kernel.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org Subject: [PATCH 4/4] security/keys: zeroize key payloads before kdump Date: Fri, 31 Jul 2026 18:27:39 +0200 Message-ID: <20260731162739.158320-5-linux@jaseg.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731162739.158320-1-linux@jaseg.de> References: <20260731162739.158320-1-linux@jaseg.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When CONFIG_CRASH_ZEROIZE is set, try to erase key payloads on panic before jumping to the kdump kernel. CRASH_ZEROIZE notifiers run during panic() with other CPUs stopped and preemption disabled. In this state, we can't rely on free()'ing being safe, so we define a new zeroize key op. Implement the zeroize op for the user/logon, encrypted, trusted, and big_key types. Signed-off-by: Jan Sebastian G=C3=B6tte --- include/linux/key-type.h | 9 +++++ security/keys/big_key.c | 15 ++++++++ security/keys/encrypted-keys/encrypted.c | 12 +++++++ security/keys/key.c | 44 +++++++++++++++++++++++ security/keys/trusted-keys/trusted_core.c | 14 ++++++++ security/keys/user_defined.c | 11 ++++++ 6 files changed, 105 insertions(+) diff --git a/include/linux/key-type.h b/include/linux/key-type.h index bb97bd3e5af4..ff0944ce368f 100644 --- a/include/linux/key-type.h +++ b/include/linux/key-type.h @@ -122,6 +122,15 @@ struct key_type { /* clear the data from a key (optional) */ void (*destroy)(struct key *key); =20 + /* scrub the key material without free'ing (optional) + * - used from CONFIG_CRASH_ZEROIZE during panic to keep keys out of + * crash dumps + * - called from the panic path with other CPUs stopped and preemption + * disabled + * - must not sleep, allocate, free or take locks + */ + void (*zeroize)(struct key *key); + /* describe a key */ void (*describe)(const struct key *key, struct seq_file *p); =20 diff --git a/security/keys/big_key.c b/security/keys/big_key.c index 268f702df380..ad8537dda70f 100644 --- a/security/keys/big_key.c +++ b/security/keys/big_key.c @@ -35,6 +35,8 @@ struct big_key_payload { */ #define BIG_KEY_FILE_THRESHOLD (sizeof(struct inode) + sizeof(struct dentr= y)) =20 +static void big_key_zeroize(struct key *key); + /* * big_key defined keys take an arbitrary string as the description and an * arbitrary blob of data as the payload @@ -46,6 +48,7 @@ struct key_type key_type_big_key =3D { .instantiate =3D generic_key_instantiate, .revoke =3D big_key_revoke, .destroy =3D big_key_destroy, + .zeroize =3D big_key_zeroize, .describe =3D big_key_describe, .read =3D big_key_read, .update =3D big_key_update, @@ -279,6 +282,18 @@ long big_key_read(const struct key *key, char *buffer,= size_t buflen) return ret; } =20 +static void big_key_zeroize(struct key *key) +{ + struct big_key_payload *payload =3D to_big_key_payload(key->payload); + + if (payload->data) { + if (payload->length > BIG_KEY_FILE_THRESHOLD) + memzero_explicit(payload->data, CHACHA20POLY1305_KEY_SIZE); + else + memzero_explicit(payload->data, payload->length); + } +} + /* * Register key type */ diff --git a/security/keys/encrypted-keys/encrypted.c b/security/keys/encry= pted-keys/encrypted.c index 59cb77b237b3..9f56fa9b4aaf 100644 --- a/security/keys/encrypted-keys/encrypted.c +++ b/security/keys/encrypted-keys/encrypted.c @@ -970,11 +970,23 @@ static void encrypted_destroy(struct key *key) kfree_sensitive(key->payload.data[0]); } =20 +static void encrypted_zeroize(struct key *key) +{ + struct encrypted_key_payload *epayload =3D key->payload.data[0]; + + if (!epayload) + return; + + memzero_explicit(epayload->payload_data, + epayload->payload_datalen + epayload->datablob_len); +} + struct key_type key_type_encrypted =3D { .name =3D "encrypted", .instantiate =3D encrypted_instantiate, .update =3D encrypted_update, .destroy =3D encrypted_destroy, + .zeroize =3D encrypted_zeroize, .describe =3D user_describe, .read =3D encrypted_read, }; diff --git a/security/keys/key.c b/security/keys/key.c index b34a64d81d47..5673dcc8c5d2 100644 --- a/security/keys/key.c +++ b/security/keys/key.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include #include "internal.h" @@ -1268,6 +1269,44 @@ void unregister_key_type(struct key_type *ktype) } EXPORT_SYMBOL(unregister_key_type); =20 +#ifdef CONFIG_CRASH_ZEROIZE +/* Called far into vpanic from crash_core.c with other CPUs stopped and + * preemption disabled + */ +static int key_crash_zeroize(struct notifier_block *nb, unsigned long acti= on, + void *data) +{ + struct rb_node *node; + + /* If we can't acquire the lock, the rbtree might be in an inconsistent + * state. That's all we can do then, as there's no point to waiting + * at this stage. + */ + if (!spin_trylock(&key_serial_lock)) { + pr_crit("crash_zeroize: can't acquire key_serial_lock. skipping keyrings= .\n"); + return NOTIFY_DONE; + } + + for (node =3D rb_first(&key_serial_tree); node; node =3D rb_next(node)) { + struct key *key =3D rb_entry(node, struct key, serial_node); + + if (key->type =3D=3D &key_type_keyring || + key->state =3D=3D KEY_IS_UNINSTANTIATED) + continue; + + /* custom zeroize since free'ing isn't safe at this point */ + if (key->type->zeroize) + key->type->zeroize(key); + } + /* off to kexec()! */ + return NOTIFY_DONE; +} + +static struct notifier_block key_crash_zeroize_nb =3D { + .notifier_call =3D key_crash_zeroize +}; +#endif /* CONFIG_CRASH_ZEROIZE */ + /* * Initialise the key management state. */ @@ -1290,4 +1329,9 @@ void __init key_init(void) =20 rb_insert_color(&root_key_user.node, &key_user_tree); + +#ifdef CONFIG_CRASH_ZEROIZE + atomic_notifier_chain_register(&crash_zeroize_notifier_list, + &key_crash_zeroize_nb); +#endif } diff --git a/security/keys/trusted-keys/trusted_core.c b/security/keys/trus= ted-keys/trusted_core.c index 0509d9955f2a..f159faeafe23 100644 --- a/security/keys/trusted-keys/trusted_core.c +++ b/security/keys/trusted-keys/trusted_core.c @@ -325,11 +325,25 @@ static void trusted_destroy(struct key *key) kfree_sensitive(key->payload.data[0]); } =20 +static void trusted_zeroize(struct key *key) +{ + struct trusted_key_payload *p =3D key->payload.data[0]; + + if (!p) + return; + + memzero_explicit(p->key, sizeof(p->key)); + memzero_explicit(p->blob, sizeof(p->blob)); + p->key_len =3D 0; + p->blob_len =3D 0; +} + struct key_type key_type_trusted =3D { .name =3D "trusted", .instantiate =3D trusted_instantiate, .update =3D trusted_update, .destroy =3D trusted_destroy, + .zeroize =3D trusted_zeroize, .describe =3D user_describe, .read =3D trusted_read, }; diff --git a/security/keys/user_defined.c b/security/keys/user_defined.c index 6f88b507f927..ade95dc2481d 100644 --- a/security/keys/user_defined.c +++ b/security/keys/user_defined.c @@ -15,6 +15,7 @@ #include "internal.h" =20 static int logon_vet_description(const char *desc); +static void user_zeroize(struct key *key); =20 /* * user defined keys take an arbitrary string as the description and an @@ -28,6 +29,7 @@ struct key_type key_type_user =3D { .update =3D user_update, .revoke =3D user_revoke, .destroy =3D user_destroy, + .zeroize =3D user_zeroize, .describe =3D user_describe, .read =3D user_read, }; @@ -48,6 +50,7 @@ struct key_type key_type_logon =3D { .update =3D user_update, .revoke =3D user_revoke, .destroy =3D user_destroy, + .zeroize =3D user_zeroize, .describe =3D user_describe, .vet_description =3D logon_vet_description, }; @@ -152,6 +155,14 @@ void user_destroy(struct key *key) =20 EXPORT_SYMBOL_GPL(user_destroy); =20 +static void user_zeroize(struct key *key) +{ + struct user_key_payload *upayload =3D key->payload.data[0]; + + if (upayload) + memzero_explicit(upayload->data, upayload->datalen); +} + /* * describe the user key */ --=20 2.53.0