Re: [PATCH v3 00/10] crypto: Provide a function for zeroizing crypto_aes_ctx

Eric Biggers <[email protected]>
Newsgroups gmane.linux.kernel.cryptoapi,gmane.linux.kernel
Message-ID <20260805202206.GE3438@quark>
On Wed, Aug 05, 2026 at 01:57:38PM +0200, Thomas Huth wrote:
> Several crypto drivers need to zeroize their local crypto_aes_ctx
> structures after use to avoid leaking key material on the stack.
> Currently some call sites do this with their own memzero_explicit()
> call, which is error-prone since it is easy to miss a return path
> (what already happened in a driver). Some other call sites miss
> to clear crypto_aes_ctx completely.
> 
> To improve this situation, the first patch introduces an aes_zeroize_ctx()
> helper that can be used with __cleanup() to automatically zeroize the
> context when it goes out of scope. The following 6 patches add this
> __cleanup() to spots in the code where this has been forgotten so far.
> The final patches change some files to do the zeroization with
> the new __cleanup() way instead of calling memzero_explicit() manually.
> 
> v3:
> - Renamed aes_clear_ctx() to aes_zeroize_ctx()
> - Split up the safeexcel patch to rework safexcel_aead_setkey in a
>   separate patch
> - Removed goto in the padlock patch
> 
> v2:
> - Rebased onto cryptodev master branch, updated the "qat" patch accordingly

I'll assume that Herbert will take this series via cryptodev/master,
since it mostly deals with drivers/crypto/.  And the new library APIs
don't use 'struct crypto_aes_ctx'.  It's just going to stay around for a
while to serve drivers that call aes_expandkey().

I'll take the AES-CMAC one.

- Eric
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.