From: "Jan Sebastian Götte" <linux@jaseg.de>
To: "Jan Sebastian Götte" <linux@jaseg.de>
Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org,
kexec@lists.infradead.org, keyrings@vger.kernel.org,
linux-mm@kvack.org, linux-security-module@vger.kernel.org,
linux-integrity@vger.kernel.org
Subject: [PATCH 4/4] security/keys: zeroize key payloads before kdump
Date: Fri, 31 Jul 2026 18:27:39 +0200 [thread overview]
Message-ID: <20260731162739.158320-5-linux@jaseg.de> (raw)
In-Reply-To: <20260731162739.158320-1-linux@jaseg.de>
When CONFIG_CRASH_ZEROIZE is set, try to erase key payloads on panic
before jumping to the kdump kernel.
CRASH_ZEROIZE notifiers run during panic() with other CPUs stopped and
preemption disabled. In this state, we can't rely on free()'ing being
safe, so we define a new zeroize key op.
Implement the zeroize op for the user/logon, encrypted, trusted, and
big_key types.
Signed-off-by: Jan Sebastian Götte <linux@jaseg.de>
---
include/linux/key-type.h | 9 +++++
security/keys/big_key.c | 15 ++++++++
security/keys/encrypted-keys/encrypted.c | 12 +++++++
security/keys/key.c | 44 +++++++++++++++++++++++
security/keys/trusted-keys/trusted_core.c | 14 ++++++++
security/keys/user_defined.c | 11 ++++++
6 files changed, 105 insertions(+)
diff --git a/include/linux/key-type.h b/include/linux/key-type.h
index bb97bd3e5af4..ff0944ce368f 100644
--- a/include/linux/key-type.h
+++ b/include/linux/key-type.h
@@ -122,6 +122,15 @@ struct key_type {
/* clear the data from a key (optional) */
void (*destroy)(struct key *key);
+ /* scrub the key material without free'ing (optional)
+ * - used from CONFIG_CRASH_ZEROIZE during panic to keep keys out of
+ * crash dumps
+ * - called from the panic path with other CPUs stopped and preemption
+ * disabled
+ * - must not sleep, allocate, free or take locks
+ */
+ void (*zeroize)(struct key *key);
+
/* describe a key */
void (*describe)(const struct key *key, struct seq_file *p);
diff --git a/security/keys/big_key.c b/security/keys/big_key.c
index 268f702df380..ad8537dda70f 100644
--- a/security/keys/big_key.c
+++ b/security/keys/big_key.c
@@ -35,6 +35,8 @@ struct big_key_payload {
*/
#define BIG_KEY_FILE_THRESHOLD (sizeof(struct inode) + sizeof(struct dentry))
+static void big_key_zeroize(struct key *key);
+
/*
* big_key defined keys take an arbitrary string as the description and an
* arbitrary blob of data as the payload
@@ -46,6 +48,7 @@ struct key_type key_type_big_key = {
.instantiate = generic_key_instantiate,
.revoke = big_key_revoke,
.destroy = big_key_destroy,
+ .zeroize = big_key_zeroize,
.describe = big_key_describe,
.read = big_key_read,
.update = big_key_update,
@@ -279,6 +282,18 @@ long big_key_read(const struct key *key, char *buffer, size_t buflen)
return ret;
}
+static void big_key_zeroize(struct key *key)
+{
+ struct big_key_payload *payload = to_big_key_payload(key->payload);
+
+ if (payload->data) {
+ if (payload->length > BIG_KEY_FILE_THRESHOLD)
+ memzero_explicit(payload->data, CHACHA20POLY1305_KEY_SIZE);
+ else
+ memzero_explicit(payload->data, payload->length);
+ }
+}
+
/*
* Register key type
*/
diff --git a/security/keys/encrypted-keys/encrypted.c b/security/keys/encrypted-keys/encrypted.c
index 59cb77b237b3..9f56fa9b4aaf 100644
--- a/security/keys/encrypted-keys/encrypted.c
+++ b/security/keys/encrypted-keys/encrypted.c
@@ -970,11 +970,23 @@ static void encrypted_destroy(struct key *key)
kfree_sensitive(key->payload.data[0]);
}
+static void encrypted_zeroize(struct key *key)
+{
+ struct encrypted_key_payload *epayload = key->payload.data[0];
+
+ if (!epayload)
+ return;
+
+ memzero_explicit(epayload->payload_data,
+ epayload->payload_datalen + epayload->datablob_len);
+}
+
struct key_type key_type_encrypted = {
.name = "encrypted",
.instantiate = encrypted_instantiate,
.update = encrypted_update,
.destroy = encrypted_destroy,
+ .zeroize = encrypted_zeroize,
.describe = user_describe,
.read = encrypted_read,
};
diff --git a/security/keys/key.c b/security/keys/key.c
index b34a64d81d47..5673dcc8c5d2 100644
--- a/security/keys/key.c
+++ b/security/keys/key.c
@@ -12,6 +12,7 @@
#include <linux/slab.h>
#include <linux/security.h>
#include <linux/workqueue.h>
+#include <linux/crash_core.h>
#include <linux/random.h>
#include <linux/err.h>
#include "internal.h"
@@ -1268,6 +1269,44 @@ void unregister_key_type(struct key_type *ktype)
}
EXPORT_SYMBOL(unregister_key_type);
+#ifdef CONFIG_CRASH_ZEROIZE
+/* Called far into vpanic from crash_core.c with other CPUs stopped and
+ * preemption disabled
+ */
+static int key_crash_zeroize(struct notifier_block *nb, unsigned long action,
+ void *data)
+{
+ struct rb_node *node;
+
+ /* If we can't acquire the lock, the rbtree might be in an inconsistent
+ * state. That's all we can do then, as there's no point to waiting
+ * at this stage.
+ */
+ if (!spin_trylock(&key_serial_lock)) {
+ pr_crit("crash_zeroize: can't acquire key_serial_lock. skipping keyrings.\n");
+ return NOTIFY_DONE;
+ }
+
+ for (node = rb_first(&key_serial_tree); node; node = rb_next(node)) {
+ struct key *key = rb_entry(node, struct key, serial_node);
+
+ if (key->type == &key_type_keyring ||
+ key->state == KEY_IS_UNINSTANTIATED)
+ continue;
+
+ /* custom zeroize since free'ing isn't safe at this point */
+ if (key->type->zeroize)
+ key->type->zeroize(key);
+ }
+ /* off to kexec()! */
+ return NOTIFY_DONE;
+}
+
+static struct notifier_block key_crash_zeroize_nb = {
+ .notifier_call = key_crash_zeroize
+};
+#endif /* CONFIG_CRASH_ZEROIZE */
+
/*
* Initialise the key management state.
*/
@@ -1290,4 +1329,9 @@ void __init key_init(void)
rb_insert_color(&root_key_user.node,
&key_user_tree);
+
+#ifdef CONFIG_CRASH_ZEROIZE
+ atomic_notifier_chain_register(&crash_zeroize_notifier_list,
+ &key_crash_zeroize_nb);
+#endif
}
diff --git a/security/keys/trusted-keys/trusted_core.c b/security/keys/trusted-keys/trusted_core.c
index 0509d9955f2a..f159faeafe23 100644
--- a/security/keys/trusted-keys/trusted_core.c
+++ b/security/keys/trusted-keys/trusted_core.c
@@ -325,11 +325,25 @@ static void trusted_destroy(struct key *key)
kfree_sensitive(key->payload.data[0]);
}
+static void trusted_zeroize(struct key *key)
+{
+ struct trusted_key_payload *p = key->payload.data[0];
+
+ if (!p)
+ return;
+
+ memzero_explicit(p->key, sizeof(p->key));
+ memzero_explicit(p->blob, sizeof(p->blob));
+ p->key_len = 0;
+ p->blob_len = 0;
+}
+
struct key_type key_type_trusted = {
.name = "trusted",
.instantiate = trusted_instantiate,
.update = trusted_update,
.destroy = trusted_destroy,
+ .zeroize = trusted_zeroize,
.describe = user_describe,
.read = trusted_read,
};
diff --git a/security/keys/user_defined.c b/security/keys/user_defined.c
index 6f88b507f927..ade95dc2481d 100644
--- a/security/keys/user_defined.c
+++ b/security/keys/user_defined.c
@@ -15,6 +15,7 @@
#include "internal.h"
static int logon_vet_description(const char *desc);
+static void user_zeroize(struct key *key);
/*
* user defined keys take an arbitrary string as the description and an
@@ -28,6 +29,7 @@ struct key_type key_type_user = {
.update = user_update,
.revoke = user_revoke,
.destroy = user_destroy,
+ .zeroize = user_zeroize,
.describe = user_describe,
.read = user_read,
};
@@ -48,6 +50,7 @@ struct key_type key_type_logon = {
.update = user_update,
.revoke = user_revoke,
.destroy = user_destroy,
+ .zeroize = user_zeroize,
.describe = user_describe,
.vet_description = logon_vet_description,
};
@@ -152,6 +155,14 @@ void user_destroy(struct key *key)
EXPORT_SYMBOL_GPL(user_destroy);
+static void user_zeroize(struct key *key)
+{
+ struct user_key_payload *upayload = key->payload.data[0];
+
+ if (upayload)
+ memzero_explicit(upayload->data, upayload->datalen);
+}
+
/*
* describe the user key
*/
--
2.53.0
prev parent reply other threads:[~2026-07-31 16:27 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 16:27 [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump Jan Sebastian Götte
2026-07-31 16:27 ` [PATCH 1/4] of/kexec: fix typo in comment (usable-memory-range) Jan Sebastian Götte
2026-07-31 16:27 ` [PATCH 2/4] kexec: add CRASH_ZEROIZE to wipe secrets before kdump Jan Sebastian Götte
2026-07-31 16:27 ` [PATCH 3/4] mm/secretmem: zeroize secret pages " Jan Sebastian Götte
2026-07-31 16:27 ` Jan Sebastian Götte [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731162739.158320-5-linux@jaseg.de \
--to=linux@jaseg.de \
--cc=devicetree@vger.kernel.org \
--cc=kexec@lists.infradead.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-security-module@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox