From: Thomas Huth <thuth@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Jason A. Donenfeld" <Jason@zx2c4.com>,
Ard Biesheuvel <ardb@kernel.org>
Cc: linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>
Subject: [PATCH v2 06/13] lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx structure
Date: Wed, 9 Sep 2026 13:54:42 +0200 [thread overview]
Message-ID: <20260909115455.157093-7-thuth@redhat.com> (raw)
In-Reply-To: <20260909115455.157093-1-thuth@redhat.com>
In certain cases crypto code functions need to zeroize their local
sm3_ctx structure after use to avoid leaking sensitive material. Provide
a sm3_zeroize_ctx() helper function that e.g. can be used with __cleanup()
to automatically zeroize the structure when it goes out of scope.
While we're at it, replace the related memzero_explicit() call in
lib/crypto/sm3.c with a call to the new helper function.
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
include/crypto/sm3.h | 9 +++++++++
lib/crypto/sm3.c | 2 +-
2 files changed, 10 insertions(+), 1 deletion(-)
diff --git a/include/crypto/sm3.h b/include/crypto/sm3.h
index 371e8a6617054..1b41356ed0864 100644
--- a/include/crypto/sm3.h
+++ b/include/crypto/sm3.h
@@ -41,6 +41,15 @@ struct sm3_ctx {
u8 buf[SM3_BLOCK_SIZE] __aligned(__alignof__(__be64));
};
+/**
+ * sm3_zeroize_ctx() - Zeroize an sm3_ctx structure
+ * @ctx: The sm3_ctx to zeroize
+ */
+static inline void sm3_zeroize_ctx(struct sm3_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* sm3_init() - Initialize an SM3 context for a new message
* @ctx: the context to initialize
diff --git a/lib/crypto/sm3.c b/lib/crypto/sm3.c
index b02b8a247adf2..23059347b4493 100644
--- a/lib/crypto/sm3.c
+++ b/lib/crypto/sm3.c
@@ -258,7 +258,7 @@ static void __sm3_final(struct sm3_ctx *ctx, u8 out[SM3_DIGEST_SIZE])
void sm3_final(struct sm3_ctx *ctx, u8 out[SM3_DIGEST_SIZE])
{
__sm3_final(ctx, out);
- memzero_explicit(ctx, sizeof(*ctx));
+ sm3_zeroize_ctx(ctx);
}
EXPORT_SYMBOL_GPL(sm3_final);
--
2.55.0
next prev parent reply other threads:[~2026-09-09 11:55 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 11:54 [PATCH v2 00/13] libcrypto: Provide more __cleanup functions for zeroizing data Thomas Huth
2026-09-09 11:54 ` [PATCH v2 01/13] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Thomas Huth
2026-09-09 11:54 ` [PATCH v2 02/13] lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key Thomas Huth
2026-09-09 11:54 ` [PATCH v2 03/13] lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 04/13] lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 05/13] lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures Thomas Huth
2026-09-09 11:54 ` Thomas Huth [this message]
2026-09-09 11:54 ` [PATCH v2 07/13] lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 08/13] lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning Thomas Huth
2026-09-09 11:54 ` [PATCH v2 10/13] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Thomas Huth
2026-09-09 11:54 ` [PATCH v2 11/13] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 12/13] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2026-09-09 11:54 ` [PATCH v2 13/13] lib/crypto: Add documentation about zeroization of key and context data Thomas Huth
2026-09-09 13:22 ` Jonathan Corbet
2026-09-10 9:09 ` Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909115455.157093-7-thuth@redhat.com \
--to=thuth@redhat.com \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.