From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A36047ACC1 for ; Thu, 13 Aug 2026 13:50:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629013; cv=none; b=VXRIV8f5jZfo8pH94c6XKLtyO0YSEn+Pm/GbbrfRpqgEP3PQwGm+m6ahy9Riuq7/HHq+OlNAJMKAus+uj1rT6wmF/fmi2lQb8aH0MwIGhaoI01VEXSkTdmfqDktEO+ZcNmsE9Wd19okBTi9/yrbddZb0D6iAfCACnQl2OX0aghU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629013; c=relaxed/simple; bh=3xW7xdIM2wNppA0nF0o+0eYHDMxOofqYYPTNEqPAzYk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Qc4cOsK02JG0w59o9tRhdAK2HtGF+UqrnJZ0YoChPoZfuOvWyZRoOCB7LdcSdgRNsymPm4cUTv8I3NNUiWW00biNO4HGbCj3OFjQY4mOb+3kbtfr4B9HQ1S7bYgB4HytfsedwcJ4gI6+3IbItgEMhWAn0x3wItp+F2K+47DBXW4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=U+qunspb; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="U+qunspb" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629011; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=k4VB0ko4NuEn9j2j4MfCIFBIKAPYilKmfffKRX5qXbE=; b=U+qunspbzWbvyxF2UdOw0sUfNKM+e6yybXTeMYSC5SSDkW6pOnfeGNWQMKmQgP2rrQ2p63 GH8vtxZuOIZ8fma44mdVR4VcDh85QUSg+Jsy4gQXHKmdt9yLdFr0rVZe1bFLM8wHwta0EC AjcMgf/zjt2Sj3vN7MxpmD9U4BUB2y8= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-375-kcStfmB0NMqXaSKxFnD80A-1; Thu, 13 Aug 2026 09:50:08 -0400 X-MC-Unique: kcStfmB0NMqXaSKxFnD80A-1 X-Mimecast-MFC-AGG-ID: kcStfmB0NMqXaSKxFnD80A_1786629002 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 62A5C1955E70; Thu, 13 Aug 2026 13:50:02 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 36D921800577; Thu, 13 Aug 2026 13:49:59 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 01/11] lib/crypto: aes: Provide a wrapper function for zeroizing crypto_aes_ctx Date: Thu, 13 Aug 2026 15:49:39 +0200 Message-ID: <20260813134953.979481-2-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Several crypto drivers need to zeroize their local crypto_aes_ctx structures after use to avoid leaking key material on the stack. Currently some call sites do this with their own memzero_explicit() call, which is error-prone since it is easy to miss a return path (what already happened in some drivers). Some other call sites miss to clear crypto_aes_ctx completely. Provide an aes_zeroize_ctx() helper that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Signed-off-by: Thomas Huth --- include/crypto/aes.h | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/include/crypto/aes.h b/include/crypto/aes.h index 16fbfd93e2bd0..faf1d1b75a15f 100644 --- a/include/crypto/aes.h +++ b/include/crypto/aes.h @@ -8,6 +8,7 @@ =20 #include #include +#include =20 #define AES_MIN_KEY_SIZE 16 #define AES_MAX_KEY_SIZE 32 @@ -125,6 +126,19 @@ struct crypto_aes_ctx { u32 key_length; }; =20 +/** + * aes_zeroize_ctx - Clear a crypto_aes_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the crypto_aes_ctx with zeroes. For + * example, use it with __cleanup() for local crypto_aes_ctx structures on + * the stack to avoid that their content is leaked when the context is lef= t. + */ +static inline void aes_zeroize_ctx(struct crypto_aes_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /* * validate key length for AES algorithms */ --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CB4D948096D for ; Thu, 13 Aug 2026 13:50:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629016; cv=none; b=JVkcxDp1VwwD9dpWMSWCjz6kgRgTLpJh5N2ibXyg/VyRFtzi6XBvABlsLNl7WRK60xD0yg9NeCcBro2vAbcNMXS1oGMoYpZtbckojJpA9B1/1TY4hw+XNcQSlZoqwnXoAxVmG6oFTJq5lijjecXcdh2f0w384ilvJo7VXpoBBtM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629016; c=relaxed/simple; bh=bX6HRBwdnB6ZIpN9/d4z0qHvQIXwP/ROMZqxiYBFN58=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=stjWhQfINlqRV68wz8xTOHrNnhgRneU4CVMZ2Ld+YqmPzt2QPm+irH/dRJyvuj9LxIZ65mN/UylhgPboBvPr6epUKzzo8ZpHrYUpMDpZP5aF5eyfxwOxlXekR/sIISCMcn2SeMYvig7iGO9aFL3qDuO0L5APapAt4pykOMc/KR0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=jO+UFGJr; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="jO+UFGJr" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629013; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/ewMKbBScmXwQYp7ywq0PQOjQEbufTUVDV5iJ2npxWc=; b=jO+UFGJr/4xdOoOT/NXpK2w446dEUo714QToJYZYI2kHeACUYvIWUiNtKnCA2vCnJa356J 3nLiSHUoIquDbmS60WfU8lH5fna/HQC+W2/Cor46MaBHTHqeK1NTsHQiCptm7OcHWwQntb IVBsVnxuW2p8n52sAQ558gFt+5dGtrI= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-210-CrbOrvhXMBe16k_ysetcMA-1; Thu, 13 Aug 2026 09:50:09 -0400 X-MC-Unique: CrbOrvhXMBe16k_ysetcMA-1 X-Mimecast-MFC-AGG-ID: CrbOrvhXMBe16k_ysetcMA_1786629007 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8BBBD195608A; Thu, 13 Aug 2026 13:50:06 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1D6CA180049F; Thu, 13 Aug 2026 13:50:02 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Antoine Tenart , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 02/11] crypto: safexcel - Simplify the check for a valid AES key Date: Thu, 13 Aug 2026 15:49:40 +0200 Message-ID: <20260813134953.979481-3-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth safexcel_aead_setkey() currently uses aes_expandkey() to check for a valid AES key, but then does not use the crypto_aes_ctx afterwards anymore, i.e. this is just a wasteful way of checking the key length, and thus aes_check_keylen() should be used instead. This also fixes a potential leak of sensitive data via the stack, since this function forgot to zeroize crypto_aes_ctx before returning to the caller. Suggested-by: Antoine Tenart Acked-by: Antoine Tenart Signed-off-by: Thomas Huth --- drivers/crypto/inside-secure/safexcel_cipher.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index a8349b684693e..f07d043c67d45 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -407,7 +407,6 @@ static int safexcel_aead_setkey(struct crypto_aead *ctf= m, const u8 *key, struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; int err =3D -EINVAL, i; const char *alg; =20 @@ -438,7 +437,7 @@ static int safexcel_aead_setkey(struct crypto_aead *ctf= m, const u8 *key, goto badkey; break; case SAFEXCEL_AES: - err =3D aes_expandkey(&aes, keys.enckey, keys.enckeylen); + err =3D aes_check_keylen(keys.enckeylen); if (unlikely(err)) goto badkey; break; --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2089847FB19 for ; Thu, 13 Aug 2026 13:50:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629018; cv=none; b=F+hJL5hNnUoYpwGpA6TvyN6Q5Z7hdilSM4L9p0ENQVvThn7Eo9gcpngeA77Hw/wrqBhueYCXt+FwwkyAzM5XZio0H3lp8nR+OkI/JkNw9XCqiFP6/BvMLpRDsDWWZPO2Ai5/nejBjVvI1T7GMNs/p4ZyWA0fcuUfIIB20WpyuAk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629018; c=relaxed/simple; bh=mRIq6aOo8Xre5dmapUQRuqQO2Rgcce3ztC5/CcVoVP8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oecAfqOelcZJv0BQDwQ11UQHTk9MJQEzho9g5ck720pz1BgtcgTmzSuHv//QVpcjIbd3hQOElEQRGFwM6QytNnzdaQiSCk7yVw3b8v7HIAWb59Eurp1qpYC89SxuaW/evfwlexQIwIVeX9+d/gPGX6UViEYogO2Up/DvKIr4phk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=OV/TGq1n; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="OV/TGq1n" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629016; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=hCtTLF0JiWbnDet+pboh6iIiYU7Zl/uxYrEoLKTK9go=; b=OV/TGq1nPGzXezgIXBo9X64qGnqRI6PoNyIwhln/553yAIFSCCjvYBtHc7UhdeH26wvTqE emEfJNSU6LIzmmrSt7jmybp1LEeEfzDn6GlRssNRIS2i5jiaJxmuJdYNI8FB7fD1PPrZJY FSxy5WU4Ko2o2vWGMyWxrV8u9zJ9Tws= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-224-eRoiWHoIOMSkmxy9-v_Hyw-1; Thu, 13 Aug 2026 09:50:12 -0400 X-MC-Unique: eRoiWHoIOMSkmxy9-v_Hyw-1 X-Mimecast-MFC-AGG-ID: eRoiWHoIOMSkmxy9-v_Hyw_1786629011 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8A8021800742; Thu, 13 Aug 2026 13:50:10 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 799F2180049F; Thu, 13 Aug 2026 13:50:07 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Antoine Tenart , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 03/11] crypto: safexcel - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Date: Thu, 13 Aug 2026 15:49:41 +0200 Message-ID: <20260813134953.979481-4-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The code clears the crypto_aes_ctx in most cases already with memzero_explicit(), but safexcel_skcipher_aesxts_setkey() runs aes_expandkey() twice, and in case the second call fails, the context from the first call is leaked. To fix this issue and to avoid future similar problems, let's use the new __cleanup(aes_zeroize_ctx) mechanism to make sure that we always clear the crypto_aes_ctx in all cases. Acked-by: Antoine Tenart Signed-off-by: Thomas Huth --- drivers/crypto/inside-secure/safexcel_cipher.c | 13 ++++--------- drivers/crypto/inside-secure/safexcel_hash.c | 3 +-- 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index f07d043c67d45..b031cb9652ec3 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -375,7 +375,7 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -396,7 +396,6 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, =20 ctx->key_len =3D len; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -1361,7 +1360,7 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -1387,7 +1386,6 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2541,7 +2539,7 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -2589,7 +2587,6 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen << 1; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2755,12 +2752,11 @@ static int safexcel_aead_ccm_setkey(struct crypto_a= ead *ctfm, const u8 *key, struct crypto_tfm *tfm =3D crypto_aead_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); if (ret) { - memzero_explicit(&aes, sizeof(aes)); return ret; } =20 @@ -2789,7 +2785,6 @@ static int safexcel_aead_ccm_setkey(struct crypto_aea= d *ctfm, const u8 *key, else ctx->hash_alg =3D CONTEXT_CONTROL_CRYPTO_ALG_XCBC128; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 diff --git a/drivers/crypto/inside-secure/safexcel_hash.c b/drivers/crypto/= inside-secure/safexcel_hash.c index 3402e570d045c..20c17eb09495e 100644 --- a/drivers/crypto/inside-secure/safexcel_hash.c +++ b/drivers/crypto/inside-secure/safexcel_hash.c @@ -1905,7 +1905,7 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, unsigned int len) { struct safexcel_ahash_ctx *ctx =3D crypto_tfm_ctx(crypto_ahash_tfm(tfm)); - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -1928,7 +1928,6 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, } ctx->cbcmac =3D true; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 46B8D481250 for ; Thu, 13 Aug 2026 13:50:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629022; cv=none; b=f8a0to+hWlJVomW7OKJ/6/Ln25FA6g4AjQhD/1Ntj2ASEPbYKQbg5+mzWtXRzfYsJQFdr0J8jYZiHEXm5ZvpqmhUpHoyAi9JttjhnfZUl432SU9U0pvUmjteNCyMuAtVkcWHNd5EioVyDVuMCZEf0tIlvPbOcKyv3nNpBdoVDbo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629022; c=relaxed/simple; bh=uUa5plyw0TfZtImmIp9ZSco5a2LUcuWZ490iootreRw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MGzHOieD7yYNMakk8ZziL1nq2Lc5KPNk3lEms2RtvZe/CPdPkWsZhw+H0f00El+LhzRfSATxW10zlKlDIBoO1LTyv015SS/wbmA3Tc1ePGqRxrlVBxl2UQDTTCSv14AAuEj/Tz+RGtLecZMaGyNKNrTs0eHOs1aXrmf8daghrQE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=aVvhblnn; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="aVvhblnn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629020; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=sddW5u89pPuUGP366qWgtzb2asLGLVmYCNoyTSeV2rs=; b=aVvhblnnXQv1ZvVlVJFFYFdq+93gnDkUao4/y1bsrXKH/Vh01GaRAkBAYMgvdlqLOjE48y H6njwk/KqAozJIRNKCjUqRADcLVa5NnNp9Qe3+Sal03ocyaZDarpOd0B/5g4XeCxHvpZRK D6O77rCqAVJ1W/6y78p+xigKmc3er4A= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-150-nsNrpX_9PsqVVQdzjt1OWw-1; Thu, 13 Aug 2026 09:50:15 -0400 X-MC-Unique: nsNrpX_9PsqVVQdzjt1OWw-1 X-Mimecast-MFC-AGG-ID: nsNrpX_9PsqVVQdzjt1OWw_1786629014 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D3A451954B09; Thu, 13 Aug 2026 13:50:13 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5C2421800348; Thu, 13 Aug 2026 13:50:11 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 04/11] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Date: Thu, 13 Aug 2026 15:49:42 +0200 Message-ID: <20260813134953.979481-5-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Some crypto functions need to zeroize their local aes_key or aes_enckey structures after use to avoid leaking sensitive material on the stack. Provide aes_zeroize_key() and aes_zeroize_enckey() helper functions that can be used with __cleanup() to automatically zeroize the structs when they go out of scope. Signed-off-by: Thomas Huth --- include/crypto/aes.h | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/include/crypto/aes.h b/include/crypto/aes.h index faf1d1b75a15f..d00d88b71690b 100644 --- a/include/crypto/aes.h +++ b/include/crypto/aes.h @@ -102,6 +102,19 @@ struct aes_enckey { union aes_enckey_arch k; }; =20 +/** + * aes_zeroize_enckey() - Zeroize an aes_enckey structure + * @key: The location of the key structure that should be zeroized + * + * Explicitly fills the aes_enckey with zeroes. For example, use it with + * __cleanup() for local aes_enckey structures on the stack, so that their + * content is not leaked when the context is left. + */ +static inline void aes_zeroize_enckey(struct aes_enckey *key) +{ + memzero_explicit(key, sizeof(*key)); +} + /** * struct aes_key - An AES key prepared for encryption and decryption * @aes_enckey: Common fields and the key prepared for encryption @@ -116,6 +129,19 @@ struct aes_key { union aes_invkey_arch inv_k; }; =20 +/** + * aes_zeroize_key() - Zeroize an aes_key structure + * @key: The location of the key structure that should be zeroized + * + * Explicitly fills the aes_key with zeroes. For example, use it with + * __cleanup() for local aes_key structures on the stack, so that their + * content is not leaked when the context is left. + */ +static inline void aes_zeroize_key(struct aes_key *key) +{ + memzero_explicit(key, sizeof(*key)); +} + /* * Please ensure that the first two fields are 16-byte aligned * relative to the start of the structure, i.e., don't move them! --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6650B48167B for ; Thu, 13 Aug 2026 13:50:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629024; cv=none; b=frXF/zUlkqBvd4S1fpkc/PYFFfUjtlnQeP2+8oNi59495ruwT10h7H46OO5gEJDYfu0QgYQYmAYMr8F2Hgz1E73SiI34+n9YJDllYuTH7q+iPm1/jtlHVLv1Mny/9xCn6dbeAhkY8H0LogpZSE+SUfQ7hPEgtiukZW1UvRFgA2A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629024; c=relaxed/simple; bh=VnTATtlriT9hJ+g1OI5ge5YmyAW+/25F62oqLI5lA8w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PXekVHUXYpx/EAVfPOlgW7aAf1NAgdHY+MVnBnb2Dcvp8lrOmHWYJnpQobBQgkCRoXQ8JYWhcK7jTODlXXNMBvNt1dROFfGrqgKf/CIL01sy6NeRUrIL/VYEmjGhkXBtqMegXAppOcvhDPKmRAdc1H8TdzTuK8aW2Lvr4N/Aqc0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=GB/jYcd1; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="GB/jYcd1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629022; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/IFcVC78qv0vNde4zIlgnYNgCLsv1G2LAGNIFkaroL4=; b=GB/jYcd1igap9HUuKhytQxJ53QEMTB1Jjs9Iov9piz0mZfQM6THXM8dPCSc4IHWXuJLWOV 2dULUC6F0Lu00b0RCwfNbfEqcU5PSXt+gYVXMqmyG3up8l7rSnN77YuQA4prKVDYHy59sq R+2RRii0rHtAP7FxD1bjWQW42WSoaNo= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-634-ciUfV5ZyPg2tBbJuNUBH9g-1; Thu, 13 Aug 2026 09:50:19 -0400 X-MC-Unique: ciUfV5ZyPg2tBbJuNUBH9g-1 X-Mimecast-MFC-AGG-ID: ciUfV5ZyPg2tBbJuNUBH9g_1786629017 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7C02E19560AD; Thu, 13 Aug 2026 13:50:17 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id ABFFC1800577; Thu, 13 Aug 2026 13:50:14 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: x86@kernel.org, Herbert Xu , "David S. Miller" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 05/11] lib/crypto: aes: Use aes_zeroize_*key() instead of memzero_explicit() Date: Thu, 13 Aug 2026 15:49:43 +0200 Message-ID: <20260813134953.979481-6-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth It's only cosmetics here, but since we have the new aes_zeroize_key() and aes_zeroize_enckey() functions anyway, we can also use them here. Signed-off-by: Thomas Huth --- lib/crypto/aes.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/lib/crypto/aes.c b/lib/crypto/aes.c index f1549839b3de0..07c1d912ac365 100644 --- a/lib/crypto/aes.c +++ b/lib/crypto/aes.c @@ -539,7 +539,7 @@ static void __init aes_fips_test(void) if (memcmp(fips_test_data, data, sizeof(data)) !=3D 0) panic("aes: FIPS self-test failed (wrong plaintext)\n"); =20 - memzero_explicit(&key, sizeof(key)); + aes_zeroize_key(&key); } =20 #if IS_ENABLED(CONFIG_CRYPTO_LIB_AES_CBC_MACS) @@ -827,7 +827,7 @@ static void __init aes_ecb_fips_test(void) if (memcmp(fips_test_data, data, sizeof(data)) !=3D 0) panic("aes: ECB FIPS self-test failed (wrong plaintext)\n"); =20 - memzero_explicit(&key, sizeof(key)); + aes_zeroize_key(&key); } #else /* CONFIG_CRYPTO_LIB_AES_ECB */ static inline void aes_ecb_fips_test(void) @@ -1040,7 +1040,7 @@ static void __init aes_cbc_fips_test(void) if (memcmp(fips_test_data, data, sizeof(data)) !=3D 0) panic("aes: CBC FIPS self-test failed (wrong plaintext)\n"); =20 - memzero_explicit(&key, sizeof(key)); + aes_zeroize_key(&key); } =20 /* FIPS cryptographic algorithm self-test for AES-CBC-CTS */ @@ -1069,7 +1069,7 @@ static void __init aes_cbc_cts_fips_test(void) if (memcmp(ptext, data, data_len) !=3D 0) panic("aes: CBC-CTS FIPS self-test failed (wrong plaintext)\n"); =20 - memzero_explicit(&key, sizeof(key)); + aes_zeroize_key(&key); } #else /* CONFIG_CRYPTO_LIB_AES_CBC */ static inline void aes_cbc_fips_test(void) @@ -1194,7 +1194,7 @@ static void __init aes_ctr_fips_test(void) if (memcmp(fips_test_data, data, sizeof(data)) !=3D 0) panic("aes: CTR FIPS self-test failed (wrong plaintext)\n"); =20 - memzero_explicit(&key, sizeof(key)); + aes_zeroize_enckey(&key); } #else /* CONFIG_CRYPTO_LIB_AES_CTR */ static inline void aes_ctr_fips_test(void) --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6BE70483815 for ; Thu, 13 Aug 2026 13:50:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629027; cv=none; b=ZqPJjrb5u4FC0gFyT1M8VhEPermlWd70tUClBYIWutE61mycFd02mkHigIaPBX4xRgbsv9ptwtrMQ73MvQEoM3E87mBlsuiKXr4253eJJ5KsErfFdTrE2xIIQfqoic1+Po1ax9Ch63VRb0/L3oDYqV3i9BjD5YOjFJNC3jj39yQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629027; c=relaxed/simple; bh=zTVu/A2ms08L5lU1yEoQM73ayTlZ9/oZk9DjvB1306I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kHHWmBvFmnK1HFfbaLqAoamYURuWqXMFDS4aRxZ/JRWRVho6asy2V3CDeyVVELpmS9kVG43pcH4DsPpXHGd4KXLxq/uBHXzArMpfJ3SPCXGA8v+m7WoNV6f6gsF/yczrJBDne92n++yBpbAPj+xdAE/5jLZbLrLlWtyUXr+Xnb4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=KfR3WL7G; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="KfR3WL7G" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629025; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fjC6RQ33hHDSrNn6DlYe2EQPZM5s0/22UcKy9xjB7gs=; b=KfR3WL7G51m+5q0SnNxLSh3bqPP4gzBcM6Emo2kQHwpA4XUxJ21RpAhAvxTYq7nPXfWsks uYRQZ8hTcumlwNDA0Qi+mEEIVWDXgkx76SAEt7pRTExPCPjBzpyv+Fmfs64OW/PVtT/xIy 6XRxlSK/IJM9hhZe0tXYH5BO9wgz9KA= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-213-q7eoBlF5N9ai4fDiJ00OMg-1; Thu, 13 Aug 2026 09:50:23 -0400 X-MC-Unique: q7eoBlF5N9ai4fDiJ00OMg-1 X-Mimecast-MFC-AGG-ID: q7eoBlF5N9ai4fDiJ00OMg_1786629020 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B8BFD19560AE; Thu, 13 Aug 2026 13:50:20 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 45F981800348; Thu, 13 Aug 2026 13:50:18 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 06/11] lib/crypto: md5: Provide a function for zeroizing hmac_md5_ctx structures Date: Thu, 13 Aug 2026 15:49:44 +0200 Message-ID: <20260813134953.979481-7-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Some crypto code functions need to zeroize their local hmac_md5_ctx structures after use to avoid leaking sensitive material on the stack. Provide a hmac_md5_zeroize_ctx() helper function that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Signed-off-by: Thomas Huth --- include/crypto/md5.h | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/include/crypto/md5.h b/include/crypto/md5.h index c47aedfe67ecd..8cf26fd965323 100644 --- a/include/crypto/md5.h +++ b/include/crypto/md5.h @@ -4,6 +4,7 @@ =20 #include #include +#include =20 #define MD5_DIGEST_SIZE 16 #define MD5_HMAC_BLOCK_SIZE 64 @@ -108,6 +109,20 @@ struct hmac_md5_ctx { struct md5_block_state ostate; }; =20 +/** + * hmac_md5_zeroize_ctx() - Zeroize an hmac_md5_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_md5_ctx with zeroes. For + * example, use it with __cleanup() for local hmac_md5_ctx structures + * on the stack, so that their content is not leaked when the context is + * left. Note: This is only required when not using hmac_md5_final(). + */ +static inline void hmac_md5_zeroize_ctx(struct hmac_md5_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_md5_preparekey() - Prepare a key for HMAC-MD5 * @key: (output) the key structure to initialize --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB8C2480959 for ; Thu, 13 Aug 2026 13:50:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629036; cv=none; b=mm4yjY2WDql9BeU3NgZqyx4QX2gLaYRjAhxlX3kT0oKIVkRe6PFSh8D7htpdmdTzOopZOl/M4dfLP/tNTcwjlv+9dr2GSkzm8iq1AJ1DQiFFiDaSwY9JA3y/YjcvSK7aTn8TeRsBK39ukjSk+7YCPFg9FmQDI4iTlOeZeZX0/BY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629036; c=relaxed/simple; bh=UFJphz2HCaus0zGusjKTqSYg8G+KwkOhX1aebVlqLgM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PhiDSio2D3uj0H/wxKx8OaQWw1MZfJl100312y7qPeTeuALbYmEEhxMqHm/fvGm2knQSisOkzH5IDPyObeoy+MSUsOtb+zBaHJLLtaenc/VytSfFPcetT+o2wHIgtgxY7CyOvMSpuOBmbexWdvuLCIAOhwq9ddM0Dsz+77ASqKs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=YHtxeh79; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="YHtxeh79" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629034; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OIj4h+dI3DPEf3hvqsFZKfrcm+ChB0/2xtHLuuFb0+A=; b=YHtxeh79yBUPOC6kNxRR5vH2YTAaZIAMuBYTz5o95VcKeoclbDSxIXbSKqs57GfVLU113A XlcwKbfCTe9XH3JQuU0qAd5wZ+61i2bPrKn001xcczrJcKk+YTHm9g2faq5Mo1geez93De usAHp4zPfAzpJfdfo5Zj9Rb6aGaFzwA= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-116-tAT7j24OMFiwWZVvRHw8lg-1; Thu, 13 Aug 2026 09:50:25 -0400 X-MC-Unique: tAT7j24OMFiwWZVvRHw8lg-1 X-Mimecast-MFC-AGG-ID: tAT7j24OMFiwWZVvRHw8lg_1786629024 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 344F91800655; Thu, 13 Aug 2026 13:50:24 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 7585C1800348; Thu, 13 Aug 2026 13:50:21 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: x86@kernel.org, Herbert Xu , "David S. Miller" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 07/11] lib/crypto: md5: Use hmac_md5_zeroize_ctx() instead of memzero_explicit() Date: Thu, 13 Aug 2026 15:49:45 +0200 Message-ID: <20260813134953.979481-8-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth It's only cosmetics, but since we have the new hmac_md5_zeroize_ctx() function anyway, we can also use it here. Signed-off-by: Thomas Huth --- lib/crypto/md5.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/crypto/md5.c b/lib/crypto/md5.c index 3d2b017a0525a..a8ee57600012d 100644 --- a/lib/crypto/md5.c +++ b/lib/crypto/md5.c @@ -271,7 +271,7 @@ void hmac_md5_final(struct hmac_md5_ctx *ctx, u8 out[MD= 5_DIGEST_SIZE]) cpu_to_le32_array(ctx->ostate.h, ARRAY_SIZE(ctx->ostate.h)); memcpy(out, ctx->ostate.h, MD5_DIGEST_SIZE); =20 - memzero_explicit(ctx, sizeof(*ctx)); + hmac_md5_zeroize_ctx(ctx); } EXPORT_SYMBOL_GPL(hmac_md5_final); =20 --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8408448033F for ; Thu, 13 Aug 2026 13:50:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629036; cv=none; b=X7LiD8y2Qwb2W1SgSbKk+wamai3faffDfu515sQv3HuPszDcu6L2X1dM7DKp9okLQjRhGOo1z1X+z/C7szIFvY7H7db59dg/6bfhtmrIc6jIuTk2Lzzbu6i2EdxjUagjL0BUMySI4My9k+L3lS3L4PX2inzd8W7lBJAJZjEB1d4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629036; c=relaxed/simple; bh=d+L8foNQBrjJ8WnaiI4PwJAfjUHuu28jNyMGmN6okvc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=t/ML6UU5OWlWTe7hJMg0rz2W7OMC4JKQrXkFeFVNM0rMbCZ1ds7uAaH31rJBkIeQ+9nrTRuvx/ZtTeqgIl5f2/pwCp+MYIFHCmAK7loW6ssQw3XtEl443W4TeS68mOTOgkjvK42Y7yBd+od9RyunZwgWgsdkT15UbkIhmyh+cT4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=GMMNBsbL; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="GMMNBsbL" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629033; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DXpHjZdJlgTVAOWLqnDb9i2gpqAP30mT9+QLCS2hQXo=; b=GMMNBsbLN+Ve3gbQM8lZLEMjFNVimEvD799DGOqxRARDCYlIDNvu590SEK3L1AEKsLioeU tQIPLUfeJnuMOmvxbJgAfEt8M8YxTvVKVTVOZqTGuk+aQVUrLVZaZsFj7sxsVkdi3SvBF5 2g4cJMFnJ63OSFTNFgzXzyLIIku6gOI= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-332-DeiIw1h5OGGKb5C1Bl5FUA-1; Thu, 13 Aug 2026 09:50:29 -0400 X-MC-Unique: DeiIw1h5OGGKb5C1Bl5FUA-1 X-Mimecast-MFC-AGG-ID: DeiIw1h5OGGKb5C1Bl5FUA_1786629027 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 97537195608E; Thu, 13 Aug 2026 13:50:27 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DD5C61800348; Thu, 13 Aug 2026 13:50:24 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 08/11] lib/crypto: sha1: Provide a wrapper for zeroizing hmac_sha1_ctx Date: Thu, 13 Aug 2026 15:49:46 +0200 Message-ID: <20260813134953.979481-9-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Some kernel code needs to zeroize their local hmac_sha1_ctx structures after use to avoid leaking sensitive material on the stack. Provide an hmac_sha1_zeroize_ctx() helper that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Signed-off-by: Thomas Huth --- include/crypto/sha1.h | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/include/crypto/sha1.h b/include/crypto/sha1.h index 4d973e016cd69..888dfc62e1c65 100644 --- a/include/crypto/sha1.h +++ b/include/crypto/sha1.h @@ -7,6 +7,7 @@ #define _CRYPTO_SHA1_H =20 #include +#include =20 #define SHA1_DIGEST_SIZE 20 #define SHA1_BLOCK_SIZE 64 @@ -106,6 +107,22 @@ struct hmac_sha1_ctx { struct sha1_block_state ostate; }; =20 +/** + * hmac_sha1_zeroize_ctx() - Zeroize an hmac_sha1_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha1_ctx with zeroes. For + * example, it can be used with __cleanup() for local hmac_sha1_ctx + * structures on the stack, so that their content is not leaked via the + * stack when the context is left. Note: This is only required when not + * using hmac_sha1_final() that already zeroizes the structure at the + * end. + */ +static inline void hmac_sha1_zeroize_ctx(struct hmac_sha1_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha1_preparekey() - Prepare a key for HMAC-SHA1 * @key: (output) the key structure to initialize --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B834D480968 for ; Thu, 13 Aug 2026 13:50:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629039; cv=none; b=dyGLJM6h7DH/MGN4XI7DuvNgZilIkvktyC6n7k7yK+5dleeVrWYwY7WDZybroUyqVSIv3vtrZ2Dg68acPLtaJa1sVjHhbdWgFLjbP7EryQvW0bmgeTS6UBvsE0PYyKO84Km2Lmv/IrL1D89gZ8xIAOKBfJArNZA3mDBfX5SX+a0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629039; c=relaxed/simple; bh=+2zRxSvjAmqwYOE+tKwr1WSnbMWmNOH7W2evqTcz3wE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aGXLn+0Y3a6yT8z2mG8hGGdlGe+V8yWh/uVJgps8TSQ5CMB2wWi6BZGGipu5wr5lO+DFigcwG84PjHjTU8S00Mj0MG9oTVlRigVtiELIBclI34bgp72RcvncthQK68BqIdJTMmTJ1h45yd6ftuexSWaarwPtLc5alHQyFx9Ogog= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=BmJQCi4u; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="BmJQCi4u" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629037; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JpTxCCo1JlTQTpMq2MklUewzzbiQjhVKEixoMx1SLYE=; b=BmJQCi4ufR+Od4n43zEQcKleZ5kI3DUIuxyNF0rzJZg2AAp5QVnvIPgzZE9ESfZMOARvwC iubvFve29GnCyyt2BaUs514mPZxUEpTN2czmsuV86dygdpKQx/n6J64yxNjszGFkvFe8CF BwELGU6vDzIBnfbFTZM7oldh2LMXCPo= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-474-ok_ga5V1OjWuAl6pclbzXw-1; Thu, 13 Aug 2026 09:50:32 -0400 X-MC-Unique: ok_ga5V1OjWuAl6pclbzXw-1 X-Mimecast-MFC-AGG-ID: ok_ga5V1OjWuAl6pclbzXw_1786629030 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B6E1B1800846; Thu, 13 Aug 2026 13:50:30 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4D1851800348; Thu, 13 Aug 2026 13:50:28 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: x86@kernel.org, Herbert Xu , "David S. Miller" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 09/11] lib/crypto: sha1: Use hmac_sha1_zeroize_ctx() instead of memzero_explicit() Date: Thu, 13 Aug 2026 15:49:47 +0200 Message-ID: <20260813134953.979481-10-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth It's only cosmetics, but since we have the new hmac_sha1_zeroize_ctx() function anyway, we can also use it here. Signed-off-by: Thomas Huth --- lib/crypto/sha1.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/crypto/sha1.c b/lib/crypto/sha1.c index b687b89d97cb4..c4361ef77166e 100644 --- a/lib/crypto/sha1.c +++ b/lib/crypto/sha1.c @@ -275,7 +275,7 @@ void hmac_sha1_final(struct hmac_sha1_ctx *ctx, u8 out[= SHA1_DIGEST_SIZE]) for (size_t i =3D 0; i < SHA1_DIGEST_SIZE; i +=3D 4) put_unaligned_be32(ctx->ostate.h[i / 4], out + i); =20 - memzero_explicit(ctx, sizeof(*ctx)); + hmac_sha1_zeroize_ctx(ctx); } EXPORT_SYMBOL_GPL(hmac_sha1_final); =20 --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 83B5C480968 for ; Thu, 13 Aug 2026 13:50:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629044; cv=none; b=UHDVgAqVYj25ZhDaK3zU/kJyuvnREkpLvJ+MlIuyjUE4AgIQlcdhSwTyO3viZUUb8f3GhirrwWf0d+CnduGJAKrH6mWAFhllSYptfYoXiI75FyRPQOyDHWH9F6McIp3YBemOUkxKLuaws06CwboGsUsBQeOFMQ1xDy9yJg8NU4w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629044; c=relaxed/simple; bh=XgaO4VcBnXqnegcdzvYcbT+W/5cM5fHNPQJkvkvWHoc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IVm37HS8DgdO7alWwBKIVEY7gGIMRk2TuGJwUj1KDZMhuzrmRDPx0MlNJ77PCKFy3WBlCyzElofsNiy8CVJJq+LQCVIaCmO/BRn4UOpMFvag6a0pjnYbVGDdsD5huUK6mjYNYO5zaLtf4GS0W1BiXfuV8VswzLXNZOcsDlGYmBw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=iCMuGZCS; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="iCMuGZCS" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629042; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xJFxwPC/lONIUC+gsyoHfrFegnGesCm7Wa4rIv9vDZA=; b=iCMuGZCS6z4Xm7Ybi63rckDZYnAN7YaLpZNZJsHmaTOGe/EnjaYgTnmDkbdJnnnkEoj8sX CRLYcYsB4ZwEjYYdp/LznlbjrDzLZJLfHkuVOXTgGcf2BDE+FLy655yhiKzLh7V7stThsw 5MSBkw5AmlEGVuawQvF4imnucxeSkkE= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-225-LrEbr0AyOE60wx5p1htHSQ-1; Thu, 13 Aug 2026 09:50:39 -0400 X-MC-Unique: LrEbr0AyOE60wx5p1htHSQ-1 X-Mimecast-MFC-AGG-ID: LrEbr0AyOE60wx5p1htHSQ_1786629037 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8873818002F8; Thu, 13 Aug 2026 13:50:36 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6F8691800348; Thu, 13 Aug 2026 13:50:31 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org Cc: Herbert Xu , "David S. Miller" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, "H. Peter Anvin" Subject: [PATCH 10/11] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Date: Thu, 13 Aug 2026 15:49:48 +0200 Message-ID: <20260813134953.979481-11-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth purgatory.c includes both, the header and the arch/x86/boot/string.h header. The latter provides its own prototypes for a lot of string functions which clash with the fortified macros from . The next patch will add #include to sha2.h to be able to use memzero_explicit() there, so we have to compile the code in purgatory.c with -D__NO_FORTIFY to avoid compilation problems in this file. Signed-off-by: Thomas Huth --- arch/x86/purgatory/Makefile | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/purgatory/Makefile b/arch/x86/purgatory/Makefile index 5ce1d42630000..9191e3cffc30b 100644 --- a/arch/x86/purgatory/Makefile +++ b/arch/x86/purgatory/Makefile @@ -12,6 +12,7 @@ $(obj)/sha256.o: $(srctree)/lib/crypto/sha256.c FORCE $(call if_changed_rule,cc_o_c) =20 CFLAGS_sha256.o :=3D -D__DISABLE_EXPORTS -D__NO_FORTIFY +CFLAGS_purgatory.o +=3D -D__NO_FORTIFY =20 # When profile-guided optimization is enabled, llvm emits two different # overlapping text sections, which is not supported by kexec. Remove profi= le --=20 2.55.0 From nobody Tue Sep 29 02:33:19 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AE0CC481FC5 for ; Thu, 13 Aug 2026 13:50:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629047; cv=none; b=jdXLn8dv6WSBsqaABSS/3ApIekQe9J9Wqr1CbDoSNOzkPmxInt8CmSLJqa1z8sPSA8+Fcge9gg9bQAuFeAjxjUoInz4PWhaH2I6XcUH4bJAWKmCOClvPYvscQtWmOL1ECf5sE/3OsNCNpPOXQkO63gmRpScPhMZ33LaZBY7zQiQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786629047; c=relaxed/simple; bh=LBJGRPEX+c7ESpwmdOsrAF1eS6K7PlwVdVAherwht48=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iuYEEnMZGqg+GQXyvfL1F4Mp7AEJWBAlQ6Z3pSLgd+BLBFBUz8BzWb43pH2ufU4qUH06Jqh+6dbJGyIgtq72prKcq87gIvw6ILZ8LP4QHndm8ATGbbOgy7JPwf5/BiF0anFrfJ0V2ZC3qiFjLdsfiRGaHiqhvbXCuGig4q1K7bk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FLoNdA+T; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FLoNdA+T" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786629044; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qrmNWOfIIVDyeK/HAUK9wucBz8cLmmeO96RwNn6+/qo=; b=FLoNdA+Tb2+B2t2aceUVw5dz+fRabX1u00F7ZBfdqqGZJA21BKQFDSKVLFoiBD3GaBOr/A +zLSp/e8AOim8c7TXu/6pJlcs6uHss++3WqFy+ergqC8RG4qBPvLeD5DHojk+jI8DpgAV4 hJH7EYFy8I0wLvqg7OWk7C64BtArDgk= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-423-E9bXOoQfOG-mrSnz4Qjkww-1; Thu, 13 Aug 2026 09:50:41 -0400 X-MC-Unique: E9bXOoQfOG-mrSnz4Qjkww-1 X-Mimecast-MFC-AGG-ID: E9bXOoQfOG-mrSnz4Qjkww_1786629040 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E98DD180075E; Thu, 13 Aug 2026 13:50:39 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 785791800348; Thu, 13 Aug 2026 13:50:37 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel , Herbert Xu , "David S. Miller" Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 11/11] lib/crypto: sha2: Provide wrappers for zeroizing SHA2 hmac_sha*_ctx structures Date: Thu, 13 Aug 2026 15:49:49 +0200 Message-ID: <20260813134953.979481-12-thuth@redhat.com> In-Reply-To: <20260813134953.979481-1-thuth@redhat.com> References: <20260813134953.979481-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Some crypto code functions need to zeroize their local SHA2 hmac_sha*_ctx structures after use to avoid leaking sensitive material on the stack. Provide hmac_sha*_zeroize_ctx() helper functions that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Signed-off-by: Thomas Huth --- Note: These will be useful in some spots in the fs/smb/ code later. include/crypto/sha2.h | 57 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 57 insertions(+) diff --git a/include/crypto/sha2.h b/include/crypto/sha2.h index 7bb8fe169daf2..2b2b06ebff993 100644 --- a/include/crypto/sha2.h +++ b/include/crypto/sha2.h @@ -7,6 +7,7 @@ #define _CRYPTO_SHA2_H =20 #include +#include =20 #define SHA224_DIGEST_SIZE 28 #define SHA224_BLOCK_SIZE 64 @@ -218,6 +219,20 @@ struct hmac_sha224_ctx { struct __hmac_sha256_ctx ctx; }; =20 +/** + * hmac_sha224_zeroize_ctx() - Zeroize an hmac_sha224_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha224_ctx with zeroes. For + * example, use it with __cleanup() for local hmac_sha224_ctx structures + * on the stack, so that their content is not leaked when the context is + * left. Note: This is only required when not using hmac_sha224_final(). + */ +static inline void hmac_sha224_zeroize_ctx(struct hmac_sha224_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha224_preparekey() - Prepare a key for HMAC-SHA224 * @key: (output) the key structure to initialize @@ -422,6 +437,20 @@ struct hmac_sha256_ctx { struct __hmac_sha256_ctx ctx; }; =20 +/** + * hmac_sha256_zeroize_ctx() - Zeroize an hmac_sha256_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha256_ctx with zeroes. For + * example, use it with __cleanup() for local hmac_sha256_ctx structures + * on the stack, so that their content is not leaked when the context is + * left. Note: This is only required when not using hmac_sha256_final(). + */ +static inline void hmac_sha256_zeroize_ctx(struct hmac_sha256_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha256_preparekey() - Prepare a key for HMAC-SHA256 * @key: (output) the key structure to initialize @@ -631,6 +660,20 @@ struct hmac_sha384_ctx { struct __hmac_sha512_ctx ctx; }; =20 +/** + * hmac_sha384_zeroize_ctx() - Zeroize an hmac_sha384_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha384_ctx with zeroes. For + * example, use it with __cleanup() for local hmac_sha384_ctx structures + * on the stack, so that their content is not leaked when the context is + * left. Note: This is only required when not using hmac_sha384_final(). + */ +static inline void hmac_sha384_zeroize_ctx(struct hmac_sha384_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha384_preparekey() - Prepare a key for HMAC-SHA384 * @key: (output) the key structure to initialize @@ -806,6 +849,20 @@ struct hmac_sha512_ctx { struct __hmac_sha512_ctx ctx; }; =20 +/** + * hmac_sha512_zeroize_ctx() - Zeroize an hmac_sha512_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha512_ctx with zeroes. For + * example, use it with __cleanup() for local hmac_sha512_ctx structures + * on the stack, so that their content is not leaked when the context is + * left. Note: This is only required when not using hmac_sha512_final(). + */ +static inline void hmac_sha512_zeroize_ctx(struct hmac_sha512_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha512_preparekey() - Prepare a key for HMAC-SHA512 * @key: (output) the key structure to initialize --=20 2.55.0