* [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures
@ 2026-09-28 8:30 Thomas Huth
2026-09-28 8:30 ` [PATCH 1/3] x86/purgatory: Compile purgatory with -D__NO_FORTIFY and -D__DISABLE_EXPORTS Thomas Huth
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Thomas Huth @ 2026-09-28 8:30 UTC (permalink / raw)
To: Eric Biggers, Herbert Xu, Thomas Gleixner, Ingo Molnar,
Borislav Petkov, Dave Hansen
Cc: David S. Miller, linux-kernel, linux-cifs, linux-crypto, x86,
H. Peter Anvin, Paulo Alcantara, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM
This patch series has been split of my earlier zeroization patch
series since there were some troubles left with the purgatory patch:
https://lore.kernel.org/all/20260924145806.GA1949494@ax162/
As I've confirmed now, the fix for the problem is indeed to set
-D__DISABLE_EXPORTS for the other files in the x86 purgatory, too,
so the first patch here has now been changed accordingly.
Thomas Huth (3):
x86/purgatory: Compile purgatory with -D__NO_FORTIFY and
-D__DISABLE_EXPORTS
lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha*
structures
smb: client: Use hmac_sha256_zeroize_ctx function to clear
hmac_sha256_ctx
arch/x86/purgatory/Makefile | 3 +-
fs/smb/client/smb2transport.c | 3 +-
include/crypto/sha2.h | 73 +++++++++++++++++++++++++++++++++++
3 files changed, 75 insertions(+), 4 deletions(-)
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 1/3] x86/purgatory: Compile purgatory with -D__NO_FORTIFY and -D__DISABLE_EXPORTS
2026-09-28 8:30 [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
@ 2026-09-28 8:30 ` Thomas Huth
2026-09-28 8:30 ` [PATCH 2/3] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-28 8:30 ` [PATCH 3/3] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2 siblings, 0 replies; 4+ messages in thread
From: Thomas Huth @ 2026-09-28 8:30 UTC (permalink / raw)
To: Eric Biggers, Herbert Xu, Thomas Gleixner, Ingo Molnar,
Borislav Petkov, Dave Hansen
Cc: David S. Miller, linux-kernel, linux-cifs, linux-crypto, x86,
H. Peter Anvin, Paulo Alcantara, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM
A subsequent patch will add #include <linux/string.h> to <crypto/sha2.h>
to use memzero_explicit() there. This will introduce a conflict with the
purgatory code: purgatory.c includes both, the <crypto/sha2.h> header and
the arch/x86/boot/string.h header. The latter provides its own prototypes
for a lot of string functions which clash with the fortified macros
from <linux/string.h>, causing the compiler to emit errors like this:
In file included from .../linux/include/linux/string.h:383,
from .../linux/include/crypto/sha2.h:10,
from .../linux/arch/x86/purgatory/purgatory.c:14:
.../linux/include/linux/fortify-string.h:576:63: error: expected identifier or ‘(’ before ‘{’ token
576 | p_size_field, q_size_field, op) ({ \
| ^
.../linux/include/linux/fortify-string.h:644:27: note: in expansion of macro ‘__fortify_memcpy_chk’
644 | #define memmove(p, q, s) __fortify_memcpy_chk(p, q, s, \
| ^~~~~~~~~~~~~~~~~~~~
.../linux/arch/x86/purgatory/../boot/string.h:11:7: note: in expansion of macro ‘memmove’
11 | void *memmove(void *dst, const void *src, size_t len);
| ^~~~~~~
.../linux/include/linux/fortify-string.h:208:9: error: expected identifier or ‘(’ before ‘__builtin_choose_expr’
208 | __builtin_choose_expr(__is_constexpr(__builtin_strlen(p)), \
| ^~~~~~~~~~~~~~~~~~~~~
./linux/arch/x86/purgatory/../boot/string.h:23:15: note: in expansion of macro ‘strlen’
23 | extern size_t strlen(const char *s);
| ^~~~~~
To avoid the problem, let's compile the whole code in the purgatory with
-D__NO_FORTIFY, so <linux/string.h> can properly be included from headers
like <crypto/sha2.h> in the purgatory, too.
When compiling/linking with the LLVM tools, and CONFIG_CFI=y, there is
an additional problem during linking:
ld.lld: error: undefined symbol: __memset
>>> referenced by string.c
>>> arch/x86/purgatory/purgatory.ro:(__UNIQUE_ID_addressable___memset_5)
ld.lld: error: undefined symbol: __memmove
>>> referenced by string.c
>>> arch/x86/purgatory/purgatory.ro:(__UNIQUE_ID_addressable___memmove_6)
This can be fixed by moving the -D__DISABLE_EXPORTS to the general CFLAGS
of the purgatory, too.
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
arch/x86/purgatory/Makefile | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/arch/x86/purgatory/Makefile b/arch/x86/purgatory/Makefile
index 5ce1d42630000..fad91ea28fe71 100644
--- a/arch/x86/purgatory/Makefile
+++ b/arch/x86/purgatory/Makefile
@@ -11,8 +11,6 @@ $(obj)/string.o: $(srctree)/arch/x86/boot/compressed/string.c FORCE
$(obj)/sha256.o: $(srctree)/lib/crypto/sha256.c FORCE
$(call if_changed_rule,cc_o_c)
-CFLAGS_sha256.o := -D__DISABLE_EXPORTS -D__NO_FORTIFY
-
# When profile-guided optimization is enabled, llvm emits two different
# overlapping text sections, which is not supported by kexec. Remove profile
# optimization flags.
@@ -37,6 +35,7 @@ PURGATORY_CFLAGS := -mcmodel=small -ffreestanding -fno-zero-initialized-in-bss -
PURGATORY_CFLAGS += -fpic -fvisibility=hidden
PURGATORY_CFLAGS += $(DISABLE_KSTACK_ERASE) -DDISABLE_BRANCH_PROFILING
PURGATORY_CFLAGS += -fno-stack-protector
+PURGATORY_CFLAGS += -D__DISABLE_EXPORTS -D__NO_FORTIFY
# Default KBUILD_CFLAGS can have -pg option set when FTRACE is enabled. That
# in turn leaves some undefined symbols like __fentry__ in purgatory and not
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 2/3] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures
2026-09-28 8:30 [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-28 8:30 ` [PATCH 1/3] x86/purgatory: Compile purgatory with -D__NO_FORTIFY and -D__DISABLE_EXPORTS Thomas Huth
@ 2026-09-28 8:30 ` Thomas Huth
2026-09-28 8:30 ` [PATCH 3/3] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2 siblings, 0 replies; 4+ messages in thread
From: Thomas Huth @ 2026-09-28 8:30 UTC (permalink / raw)
To: Eric Biggers, Herbert Xu, Thomas Gleixner, Ingo Molnar,
Borislav Petkov, Dave Hansen
Cc: David S. Miller, linux-kernel, linux-cifs, linux-crypto, x86,
H. Peter Anvin, Paulo Alcantara, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM
In certain cases crypto code functions need to zeroize their local SHA2
hmac_sha*_key or hmac_sha*_ctx structures after use to avoid leaking
sensitive material on the stack.
Provide hmac_sha*_zeroize_key() and hmac_sha*_zeroize_ctx() helper
functions that can be used with __cleanup() to automatically zeroize
the structure when it goes out of scope.
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
include/crypto/sha2.h | 73 +++++++++++++++++++++++++++++++++++++++++++
1 file changed, 73 insertions(+)
diff --git a/include/crypto/sha2.h b/include/crypto/sha2.h
index 7bb8fe169daf2..22fbc37ae8407 100644
--- a/include/crypto/sha2.h
+++ b/include/crypto/sha2.h
@@ -7,6 +7,7 @@
#define _CRYPTO_SHA2_H
#include <linux/types.h>
+#include <linux/string.h>
#define SHA224_DIGEST_SIZE 28
#define SHA224_BLOCK_SIZE 64
@@ -210,6 +211,15 @@ struct hmac_sha224_key {
struct __hmac_sha256_key key;
};
+/**
+ * hmac_sha224_zeroize_key() - Zeroize an hmac_sha224_key structure
+ * @key: The hmac_sha224_key to zeroize
+ */
+static inline void hmac_sha224_zeroize_key(struct hmac_sha224_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* struct hmac_sha224_ctx - Context for computing HMAC-SHA224 of a message
* @ctx: private
@@ -218,6 +228,15 @@ struct hmac_sha224_ctx {
struct __hmac_sha256_ctx ctx;
};
+/**
+ * hmac_sha224_zeroize_ctx() - Zeroize an hmac_sha224_ctx structure
+ * @ctx: The hmac_sha224_ctx context to zeroize
+ */
+static inline void hmac_sha224_zeroize_ctx(struct hmac_sha224_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* hmac_sha224_preparekey() - Prepare a key for HMAC-SHA224
* @key: (output) the key structure to initialize
@@ -414,6 +433,15 @@ struct hmac_sha256_key {
struct __hmac_sha256_key key;
};
+/**
+ * hmac_sha256_zeroize_key() - Zeroize an hmac_sha256_key structure
+ * @key: The hmac_sha256_key to zeroize
+ */
+static inline void hmac_sha256_zeroize_key(struct hmac_sha256_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* struct hmac_sha256_ctx - Context for computing HMAC-SHA256 of a message
* @ctx: private
@@ -422,6 +450,15 @@ struct hmac_sha256_ctx {
struct __hmac_sha256_ctx ctx;
};
+/**
+ * hmac_sha256_zeroize_ctx() - Zeroize an hmac_sha256_ctx structure
+ * @ctx: The hmac_sha256_ctx context to zeroize
+ */
+static inline void hmac_sha256_zeroize_ctx(struct hmac_sha256_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* hmac_sha256_preparekey() - Prepare a key for HMAC-SHA256
* @key: (output) the key structure to initialize
@@ -623,6 +660,15 @@ struct hmac_sha384_key {
struct __hmac_sha512_key key;
};
+/**
+ * hmac_sha384_zeroize_key() - Zeroize an hmac_sha384_key structure
+ * @key: The hmac_sha384_key to zeroize
+ */
+static inline void hmac_sha384_zeroize_key(struct hmac_sha384_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* struct hmac_sha384_ctx - Context for computing HMAC-SHA384 of a message
* @ctx: private
@@ -631,6 +677,15 @@ struct hmac_sha384_ctx {
struct __hmac_sha512_ctx ctx;
};
+/**
+ * hmac_sha384_zeroize_ctx() - Zeroize an hmac_sha384_ctx structure
+ * @ctx: The hmac_sha384_ctx context to zeroize
+ */
+static inline void hmac_sha384_zeroize_ctx(struct hmac_sha384_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* hmac_sha384_preparekey() - Prepare a key for HMAC-SHA384
* @key: (output) the key structure to initialize
@@ -798,6 +853,15 @@ struct hmac_sha512_key {
struct __hmac_sha512_key key;
};
+/**
+ * hmac_sha512_zeroize_key() - Zeroize an hmac_sha512_key structure
+ * @key: The hmac_sha512_key to zeroize
+ */
+static inline void hmac_sha512_zeroize_key(struct hmac_sha512_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* struct hmac_sha512_ctx - Context for computing HMAC-SHA512 of a message
* @ctx: private
@@ -806,6 +870,15 @@ struct hmac_sha512_ctx {
struct __hmac_sha512_ctx ctx;
};
+/**
+ * hmac_sha512_zeroize_ctx() - Zeroize an hmac_sha512_ctx structure
+ * @ctx: The hmac_sha512_ctx context to zeroize
+ */
+static inline void hmac_sha512_zeroize_ctx(struct hmac_sha512_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* hmac_sha512_preparekey() - Prepare a key for HMAC-SHA512
* @key: (output) the key structure to initialize
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 3/3] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx
2026-09-28 8:30 [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-28 8:30 ` [PATCH 1/3] x86/purgatory: Compile purgatory with -D__NO_FORTIFY and -D__DISABLE_EXPORTS Thomas Huth
2026-09-28 8:30 ` [PATCH 2/3] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
@ 2026-09-28 8:30 ` Thomas Huth
2 siblings, 0 replies; 4+ messages in thread
From: Thomas Huth @ 2026-09-28 8:30 UTC (permalink / raw)
To: Eric Biggers, Herbert Xu, Thomas Gleixner, Ingo Molnar,
Borislav Petkov, Dave Hansen
Cc: David S. Miller, linux-kernel, linux-cifs, linux-crypto, x86,
H. Peter Anvin, Paulo Alcantara, Namjae Jeon, Ronnie Sahlberg,
Shyam Prasad N, Tom Talpey, Bharath SM
It's just cosmetics, but now that we have a helper function for clearing
hmac_sha256_ctx with a __cleanup() statement, we can also use it in the smb
client code for good measure.
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
fs/smb/client/smb2transport.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/fs/smb/client/smb2transport.c b/fs/smb/client/smb2transport.c
index c407f30e00401..080864b24a0c5 100644
--- a/fs/smb/client/smb2transport.c
+++ b/fs/smb/client/smb2transport.c
@@ -212,7 +212,7 @@ smb2_calc_signature(struct smb_rqst *rqst, struct TCP_Server_Info *server)
unsigned char smb2_signature[SMB2_HMACSHA256_SIZE];
struct kvec *iov = rqst->rq_iov;
struct smb2_hdr *shdr = (struct smb2_hdr *)iov[0].iov_base;
- struct hmac_sha256_ctx hmac_ctx;
+ struct hmac_sha256_ctx hmac_ctx __cleanup(hmac_sha256_zeroize_ctx);
struct smb_rqst drqst;
__u64 sid = le64_to_cpu(shdr->SessionId);
u8 key[SMB2_NTLMV2_SESSKEY_SIZE];
@@ -250,7 +250,6 @@ smb2_calc_signature(struct smb_rqst *rqst, struct TCP_Server_Info *server)
memcpy(shdr->Signature, smb2_signature, SMB2_SIGNATURE_SIZE);
memzero_explicit(key, sizeof(key));
- memzero_explicit(&hmac_ctx, sizeof(hmac_ctx));
return rc;
}
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-28 8:31 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 8:30 [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-28 8:30 ` [PATCH 1/3] x86/purgatory: Compile purgatory with -D__NO_FORTIFY and -D__DISABLE_EXPORTS Thomas Huth
2026-09-28 8:30 ` [PATCH 2/3] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-28 8:30 ` [PATCH 3/3] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®