[PATCH v4 00/13] libcrypto: Provide more __cleanup functions for zeroizing data

Thomas Huth posted 13 patches 1 week, 1 day ago
.../crypto/libcrypto-zeroization.rst          | 150 ++++++++++++++++++
Documentation/crypto/libcrypto.rst            |   1 +
arch/x86/purgatory/Makefile                   |   3 +-
fs/smb/client/smb2transport.c                 |   3 +-
include/crypto/aes-ccm.h                      |  22 ++-
include/crypto/aes-gcm.h                      |  22 ++-
include/crypto/aes-xts.h                      |  13 +-
include/crypto/aes.h                          |  18 +++
include/crypto/blake2b.h                      |   9 ++
include/crypto/blake2s.h                      |   9 ++
include/crypto/md5.h                          |  19 +++
include/crypto/sha1.h                         |  19 +++
include/crypto/sha2.h                         |  73 +++++++++
include/crypto/sm3.h                          |  10 ++
lib/crypto/aes.c                              |  28 ++--
lib/crypto/blake2b.c                          |   2 +-
lib/crypto/blake2s.c                          |   2 +-
lib/crypto/md5.c                              |   2 +-
lib/crypto/sha1.c                             |   2 +-
lib/crypto/sm3.c                              |   2 +-
security/keys/trusted-keys/trusted_tpm1.c     |   2 +-
21 files changed, 380 insertions(+), 31 deletions(-)
create mode 100644 Documentation/crypto/libcrypto-zeroization.rst
[PATCH v4 00/13] libcrypto: Provide more __cleanup functions for zeroizing data
Posted by Thomas Huth 1 week, 1 day ago
Code that uses crypto-related structures (containing keys or context data)
should zeroize their local structures on the stack after use to avoid
leaking this sensitive material via the stack when the function returns.
Using the __cleanup() marker is a very elegant way to assert that the
data is zeroized without having to painfully verify that each early return
in a function might miss it.

Thus this series introduces zeroization functions for many crypto-related
structures that can be used with __cleanup(). The series focuses on the
introduction of the functions - most call sights will be adjusted to use
these new functions in separate patch series later (since each subsystem
needs separate review from the corresponding maintainer).

Note there is one minor ugliness in the patch "Compile purgatory with
-D__NO_FORTIFY":  Since sha2.h is also used in the x86 purgatory code,
and that code ships with its own implementation of string functions, we
have to compile the x86 purgatory with -D__NO_FORTIFY now to be able
to include <linux/string.h> in sha2.h.

v4:
- Updated the documentation patch according to Eric's suggestions:
  https://lore.kernel.org/lkml/20260910150900.GC5719@quark/
- Compile the whole x86 purgatory with -D__NO_FORTIFY, see:
  https://lore.kernel.org/lkml/20260916022705.GKaqn-eQ9zuCk5tYgR@fat_crate.local/

v3:
- Don't put function names into ``quotes`` in the last patch, so the
  cross-references will be generated right now.
- Added a missing #include <linux/string.h> in the sm3 patch

v2:
- Dropped some patches that have been picked up elsewhere already
- Merged the patches that introduce the zeroization functions and
  that update the callsites in lib/crypto/ - I think reviewing is
  easier this way
- Add more patches to zeroize structs that weren't handled in v1 yet
- Keep the kerneldoc comments simple and add a final patch for the
  Documentation folder instead that describes the zeroization needs.

Thomas Huth (13):
  lib/crypto: aes: Provide functions for zeroizing aes_key and
    aes_enckey
  lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key
  lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm*
    structures
  lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm*
    structures
  lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures
  lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx
    structure
  lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx
    structures
  lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures
  security: keys: trusted: always clear the hmac_sha1_ctx before
    returning
  x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY
  lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha*
    structures
  smb: client: Use hmac_sha256_zeroize_ctx function to clear
    hmac_sha256_ctx
  lib/crypto: Add documentation about zeroization of key and context
    data

 .../crypto/libcrypto-zeroization.rst          | 150 ++++++++++++++++++
 Documentation/crypto/libcrypto.rst            |   1 +
 arch/x86/purgatory/Makefile                   |   3 +-
 fs/smb/client/smb2transport.c                 |   3 +-
 include/crypto/aes-ccm.h                      |  22 ++-
 include/crypto/aes-gcm.h                      |  22 ++-
 include/crypto/aes-xts.h                      |  13 +-
 include/crypto/aes.h                          |  18 +++
 include/crypto/blake2b.h                      |   9 ++
 include/crypto/blake2s.h                      |   9 ++
 include/crypto/md5.h                          |  19 +++
 include/crypto/sha1.h                         |  19 +++
 include/crypto/sha2.h                         |  73 +++++++++
 include/crypto/sm3.h                          |  10 ++
 lib/crypto/aes.c                              |  28 ++--
 lib/crypto/blake2b.c                          |   2 +-
 lib/crypto/blake2s.c                          |   2 +-
 lib/crypto/md5.c                              |   2 +-
 lib/crypto/sha1.c                             |   2 +-
 lib/crypto/sm3.c                              |   2 +-
 security/keys/trusted-keys/trusted_tpm1.c     |   2 +-
 21 files changed, 380 insertions(+), 31 deletions(-)
 create mode 100644 Documentation/crypto/libcrypto-zeroization.rst

-- 
2.55.0
Re: [PATCH v4 00/13] libcrypto: Provide more __cleanup functions for zeroizing data
Posted by Eric Biggers 2 days, 1 hour ago
On Wed, Sep 16, 2026 at 11:50:02AM +0200, Thomas Huth wrote:
> Code that uses crypto-related structures (containing keys or context data)
> should zeroize their local structures on the stack after use to avoid
> leaking this sensitive material via the stack when the function returns.
> Using the __cleanup() marker is a very elegant way to assert that the
> data is zeroized without having to painfully verify that each early return
> in a function might miss it.
> 
> Thus this series introduces zeroization functions for many crypto-related
> structures that can be used with __cleanup(). The series focuses on the
> introduction of the functions - most call sights will be adjusted to use
> these new functions in separate patch series later (since each subsystem
> needs separate review from the corresponding maintainer).
> 
> Note there is one minor ugliness in the patch "Compile purgatory with
> -D__NO_FORTIFY":  Since sha2.h is also used in the x86 purgatory code,
> and that code ships with its own implementation of string functions, we
> have to compile the x86 purgatory with -D__NO_FORTIFY now to be able
> to include <linux/string.h> in sha2.h.
> 

Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-next

- Eric