Re: [PATCH v3 00/10] crypto: Provide a function for zeroizing crypto_aes_ctx

Eric Biggers <[email protected]> Wed, 5 Aug 2026 13:22:06 -0700
Newsgroups org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel
Message-ID <20260805202206.GE3438@quark>
On Wed, Aug 05, 2026 at 01:57:38PM +0200, Thomas Huth wrote:
> Several crypto drivers need to zeroize their local crypto_aes_ctx
> structures after use to avoid leaking key material on the stack.
> Currently some call sites do this with their own memzero_explicit()
> call, which is error-prone since it is easy to miss a return path
> (what already happened in a driver). Some other call sites miss
> to clear crypto_aes_ctx completely.
> 
> To improve this situation, the first patch introduces an aes_zeroize_ctx()
> helper that can be used with __cleanup() to automatically zeroize the
> context when it goes out of scope. The following 6 patches add this
> __cleanup() to spots in the code where this has been forgotten so far.
> The final patches change some files to do the zeroization with
> the new __cleanup() way instead of calling memzero_explicit() manually.
> 
> v3:
> - Renamed aes_clear_ctx() to aes_zeroize_ctx()
> - Split up the safeexcel patch to rework safexcel_aead_setkey in a
>   separate patch
> - Removed goto in the padlock patch
> 
> v2:
> - Rebased onto cryptodev master branch, updated the "qat" patch accordingly

I'll assume that Herbert will take this series via cryptodev/master,
since it mostly deals with drivers/crypto/.  And the new library APIs
don't use 'struct crypto_aes_ctx'.  It's just going to stay around for a
while to serve drivers that call aes_expandkey().

I'll take the AES-CMAC one.

- Eric