From: Thomas Huth <thuth@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>,
"Jason A. Donenfeld" <Jason@zx2c4.com>,
Ard Biesheuvel <ardb@kernel.org>
Cc: x86@kernel.org, Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH 00/11] libcrypto: Provide more __cleanup functions for zeroizing data
Date: Thu, 13 Aug 2026 15:49:38 +0200 [thread overview]
Message-ID: <20260813134953.979481-1-thuth@redhat.com> (raw)
Code that uses crypto-related structures (containing keys or context data)
should zeroize their local structures on the stack after use to avoid
leaking this sensitive material via the stack when the function returns.
Using the __cleanup() marker is a very elegant way to assert that the
data is zeroized without having to painfully verify that each early return
in a function might miss it.
Thus this series introduces zeroization functions for many crypto-related
structures that can be used with __cleanup(). The series focuses on the
introduction of the functions - most call sights will be adjusted to use
these new functions in separate patch series later (since each subsystem
needs separate review from the corresponding maintainer). However, I
already included the two "safexcel" patches, since they already got ack'ed
by the maintainer Antoine, so I think they should be fine to go via the
libcrypto tree.
Note there is one minor ugliness in patch 10: Since sha2.h is also used
in the x86 purgatory code, and that code ships with its own implementation
of string functions, we have to compile the purgatory.c file with
-D__NO_FORTIFY now to be able to include <linux/string.h> in sha2.h.
I hope that solution is OK (especially since the sha256.c file in the
same folder gets that treatment already, too), if not - I'm certainly
open for other suggestions here!
Thomas Huth (11):
lib/crypto: aes: Provide a wrapper function for zeroizing
crypto_aes_ctx
crypto: safexcel - Simplify the check for a valid AES key
crypto: safexcel - zeroize crypto_aes_ctx with
__cleanup(aes_zeroize_ctx)
lib/crypto: aes: Provide functions for zeroizing aes_key and
aes_enckey
lib/crypto: aes: Use aes_zeroize_*key() instead of memzero_explicit()
lib/crypto: md5: Provide a function for zeroizing hmac_md5_ctx
structures
lib/crypto: md5: Use hmac_md5_zeroize_ctx() instead of
memzero_explicit()
lib/crypto: sha1: Provide a wrapper for zeroizing hmac_sha1_ctx
lib/crypto: sha1: Use hmac_sha1_zeroize_ctx() instead of
memzero_explicit()
x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY
lib/crypto: sha2: Provide wrappers for zeroizing SHA2 hmac_sha*_ctx
structures
arch/x86/purgatory/Makefile | 1 +
.../crypto/inside-secure/safexcel_cipher.c | 16 ++----
drivers/crypto/inside-secure/safexcel_hash.c | 3 +-
include/crypto/aes.h | 40 +++++++++++++
include/crypto/md5.h | 15 +++++
include/crypto/sha1.h | 17 ++++++
include/crypto/sha2.h | 57 +++++++++++++++++++
lib/crypto/aes.c | 10 ++--
lib/crypto/md5.c | 2 +-
lib/crypto/sha1.c | 2 +-
10 files changed, 143 insertions(+), 20 deletions(-)
--
2.55.0
next reply other threads:[~2026-08-13 13:50 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 13:49 Thomas Huth [this message]
2026-08-13 13:49 ` [PATCH 01/11] lib/crypto: aes: Provide a wrapper function for zeroizing crypto_aes_ctx Thomas Huth
2026-08-13 13:49 ` [PATCH 02/11] crypto: safexcel - Simplify the check for a valid AES key Thomas Huth
2026-08-13 13:49 ` [PATCH 03/11] crypto: safexcel - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Thomas Huth
2026-08-13 13:49 ` [PATCH 04/11] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Thomas Huth
2026-08-13 13:49 ` [PATCH 05/11] lib/crypto: aes: Use aes_zeroize_*key() instead of memzero_explicit() Thomas Huth
2026-08-13 13:49 ` [PATCH 06/11] lib/crypto: md5: Provide a function for zeroizing hmac_md5_ctx structures Thomas Huth
2026-08-13 13:49 ` [PATCH 07/11] lib/crypto: md5: Use hmac_md5_zeroize_ctx() instead of memzero_explicit() Thomas Huth
2026-08-13 13:49 ` [PATCH 08/11] lib/crypto: sha1: Provide a wrapper for zeroizing hmac_sha1_ctx Thomas Huth
2026-08-13 13:49 ` [PATCH 09/11] lib/crypto: sha1: Use hmac_sha1_zeroize_ctx() instead of memzero_explicit() Thomas Huth
2026-08-13 13:49 ` [PATCH 10/11] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Thomas Huth
2026-08-13 13:49 ` [PATCH 11/11] lib/crypto: sha2: Provide wrappers for zeroizing SHA2 hmac_sha*_ctx structures Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260813134953.979481-1-thuth@redhat.com \
--to=thuth@redhat.com \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox