From: Thomas Huth <thuth@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Jason A. Donenfeld" <Jason@zx2c4.com>,
Ard Biesheuvel <ardb@kernel.org>
Cc: linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>
Subject: [PATCH v3 00/13] libcrypto: Provide more __cleanup functions for zeroizing data
Date: Thu, 10 Sep 2026 14:41:19 +0200 [thread overview]
Message-ID: <20260910124138.417439-1-thuth@redhat.com> (raw)
Code that uses crypto-related structures (containing keys or context data)
should zeroize their local structures on the stack after use to avoid
leaking this sensitive material via the stack when the function returns.
Using the __cleanup() marker is a very elegant way to assert that the
data is zeroized without having to painfully verify that each early return
in a function might miss it.
Thus this series introduces zeroization functions for many crypto-related
structures that can be used with __cleanup(). The series focuses on the
introduction of the functions - most call sights will be adjusted to use
these new functions in separate patch series later (since each subsystem
needs separate review from the corresponding maintainer).
Note there is one minor ugliness in the patch "Compile purgatory.c with
-D__NO_FORTIFY": Since sha2.h is also used in the x86 purgatory code,
and that code ships with its own implementation of string functions, we
have to compile the purgatory.c file with -D__NO_FORTIFY now to be able
to include <linux/string.h> in sha2.h. I hope that solution is OK
(especially since the sha256.c file in the same folder gets that treatment
already, too), if not - I'm certainly open for other suggestions here!
v3:
- Don't put function names into ``quotes`` in the last patch, so the
cross-references will be generated right now.
- Added a missing #include <linux/string.h> in the sm3 patch
v2:
- Dropped some patches that have been picked up elsewhere already
- Merged the patches that introduce the zeroization functions and
that update the callsites in lib/crypto/ - I think reviewing is
easier this way
- Add more patches to zeroize structs that weren't handled in v1 yet
- Keep the kerneldoc comments simple and add a final patch for the
Documentation folder instead that describes the zeroization needs.
Thomas Huth (13):
lib/crypto: aes: Provide functions for zeroizing aes_key and
aes_enckey
lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key
lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm*
structures
lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm*
structures
lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures
lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx
structure
lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx
structures
lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures
security: keys: trusted: always clear the hmac_sha1_ctx before
returning
x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY
lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha*
structures
smb: client: Use hmac_sha256_zeroize_ctx function to clear
hmac_sha256_ctx
lib/crypto: Add documentation about zeroization of key and context
data
.../crypto/libcrypto-zeroization.rst | 129 ++++++++++++++++++
Documentation/crypto/libcrypto.rst | 1 +
arch/x86/purgatory/Makefile | 1 +
fs/smb/client/smb2transport.c | 3 +-
include/crypto/aes-ccm.h | 22 ++-
include/crypto/aes-gcm.h | 22 ++-
include/crypto/aes-xts.h | 13 +-
include/crypto/aes.h | 18 +++
include/crypto/blake2b.h | 9 ++
include/crypto/blake2s.h | 9 ++
include/crypto/md5.h | 19 +++
include/crypto/sha1.h | 19 +++
include/crypto/sha2.h | 73 ++++++++++
include/crypto/sm3.h | 10 ++
lib/crypto/aes.c | 28 ++--
lib/crypto/blake2b.c | 2 +-
lib/crypto/blake2s.c | 2 +-
lib/crypto/md5.c | 2 +-
lib/crypto/sha1.c | 2 +-
lib/crypto/sm3.c | 2 +-
security/keys/trusted-keys/trusted_tpm1.c | 2 +-
21 files changed, 358 insertions(+), 30 deletions(-)
create mode 100644 Documentation/crypto/libcrypto-zeroization.rst
--
2.55.0
next reply other threads:[~2026-09-10 12:41 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 12:41 Thomas Huth [this message]
2026-09-10 12:41 ` [PATCH v3 01/13] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Thomas Huth
2026-09-10 12:41 ` [PATCH v3 02/13] lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key Thomas Huth
2026-09-10 12:41 ` [PATCH v3 03/13] lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm* structures Thomas Huth
2026-09-10 12:41 ` [PATCH v3 04/13] lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm* structures Thomas Huth
2026-09-10 12:41 ` [PATCH v3 05/13] lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures Thomas Huth
2026-09-10 12:41 ` [PATCH v3 06/13] lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx structure Thomas Huth
2026-09-10 12:41 ` [PATCH v3 07/13] lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx structures Thomas Huth
2026-09-10 12:41 ` [PATCH v3 08/13] lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures Thomas Huth
2026-09-10 12:41 ` [PATCH v3 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning Thomas Huth
2026-09-10 12:41 ` [PATCH v3 10/13] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Thomas Huth
2026-09-10 12:41 ` [PATCH v3 11/13] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-11 1:15 ` Namjae Jeon
2026-09-10 12:41 ` [PATCH v3 12/13] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2026-09-10 12:41 ` [PATCH v3 13/13] lib/crypto: Add documentation about zeroization of key and context data Thomas Huth
2026-09-10 15:09 ` Eric Biggers
2026-09-10 15:40 ` [PATCH v3 00/13] libcrypto: Provide more __cleanup functions for zeroizing data Borislav Petkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910124138.417439-1-thuth@redhat.com \
--to=thuth@redhat.com \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®