From: Thomas Huth <thuth@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Jason A. Donenfeld" <Jason@zx2c4.com>,
Ard Biesheuvel <ardb@kernel.org>
Cc: linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>
Subject: [PATCH v2 08/13] lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures
Date: Wed, 9 Sep 2026 13:54:44 +0200 [thread overview]
Message-ID: <20260909115455.157093-9-thuth@redhat.com> (raw)
In-Reply-To: <20260909115455.157093-1-thuth@redhat.com>
In certain cases crypto code needs to zeroize their local hmac_sha1_key
or hmac_sha1_ctx structures after use to avoid leaking sensitive material.
Provide hmac_sha1_zeroize_key() and hmac_sha1_zeroize_ctx() helper
functions that e.g. can be used with __cleanup() to automatically zeroize
the structures when they go out of scope.
While we're at it, replace the related memzero_explicit() call in
lib/crypto/sha1.c with a call to the new helper function.
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
include/crypto/sha1.h | 19 +++++++++++++++++++
lib/crypto/sha1.c | 2 +-
2 files changed, 20 insertions(+), 1 deletion(-)
diff --git a/include/crypto/sha1.h b/include/crypto/sha1.h
index 4d973e016cd69..bc0046bffeaee 100644
--- a/include/crypto/sha1.h
+++ b/include/crypto/sha1.h
@@ -7,6 +7,7 @@
#define _CRYPTO_SHA1_H
#include <linux/types.h>
+#include <linux/string.h>
#define SHA1_DIGEST_SIZE 20
#define SHA1_BLOCK_SIZE 64
@@ -96,6 +97,15 @@ struct hmac_sha1_key {
struct sha1_block_state ostate;
};
+/**
+ * hmac_sha1_zeroize_key() - Zeroize an hmac_sha1_key structure
+ * @key: The hmac_sha1_key to zeroize
+ */
+static inline void hmac_sha1_zeroize_key(struct hmac_sha1_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* struct hmac_sha1_ctx - Context for computing HMAC-SHA1 of a message
* @sha_ctx: private
@@ -106,6 +116,15 @@ struct hmac_sha1_ctx {
struct sha1_block_state ostate;
};
+/**
+ * hmac_sha1_zeroize_ctx() - Zeroize an hmac_sha1_ctx structure
+ * @ctx: The hmac_sha1_ctx context to zeroize
+ */
+static inline void hmac_sha1_zeroize_ctx(struct hmac_sha1_ctx *ctx)
+{
+ memzero_explicit(ctx, sizeof(*ctx));
+}
+
/**
* hmac_sha1_preparekey() - Prepare a key for HMAC-SHA1
* @key: (output) the key structure to initialize
diff --git a/lib/crypto/sha1.c b/lib/crypto/sha1.c
index b687b89d97cb4..c4361ef77166e 100644
--- a/lib/crypto/sha1.c
+++ b/lib/crypto/sha1.c
@@ -275,7 +275,7 @@ void hmac_sha1_final(struct hmac_sha1_ctx *ctx, u8 out[SHA1_DIGEST_SIZE])
for (size_t i = 0; i < SHA1_DIGEST_SIZE; i += 4)
put_unaligned_be32(ctx->ostate.h[i / 4], out + i);
- memzero_explicit(ctx, sizeof(*ctx));
+ hmac_sha1_zeroize_ctx(ctx);
}
EXPORT_SYMBOL_GPL(hmac_sha1_final);
--
2.55.0
next prev parent reply other threads:[~2026-09-09 11:55 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 11:54 [PATCH v2 00/13] libcrypto: Provide more __cleanup functions for zeroizing data Thomas Huth
2026-09-09 11:54 ` [PATCH v2 01/13] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Thomas Huth
2026-09-09 11:54 ` [PATCH v2 02/13] lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key Thomas Huth
2026-09-09 11:54 ` [PATCH v2 03/13] lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 04/13] lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 05/13] lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 06/13] lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx structure Thomas Huth
2026-09-09 11:54 ` [PATCH v2 07/13] lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx structures Thomas Huth
2026-09-09 11:54 ` Thomas Huth [this message]
2026-09-09 11:54 ` [PATCH v2 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning Thomas Huth
2026-09-09 11:54 ` [PATCH v2 10/13] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Thomas Huth
2026-09-09 11:54 ` [PATCH v2 11/13] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 12/13] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2026-09-09 11:54 ` [PATCH v2 13/13] lib/crypto: Add documentation about zeroization of key and context data Thomas Huth
2026-09-09 13:22 ` Jonathan Corbet
2026-09-10 9:09 ` Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909115455.157093-9-thuth@redhat.com \
--to=thuth@redhat.com \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.