Re: [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump

"David Hildenbrand (Arm)" <[email protected]>
Newsgroups org.kernel.vger.linux-integrity,org.infradead.lists.kexec,org.kernel.vger.keyrings,org.kernel.vger.linux-devicetree,org.kernel.vger.linux-kernel,org.kernel.vger.linux-security-module,org.kvack.linux-mm
Message-ID <[email protected]>
On 7/31/26 18:27, Jan Sebastian Götte wrote:
> Register a CRASH_ZEROIZE notifier that wipes secretmem folios. As a
> result, when CONFIG_CRASH_ZEROIZE is set, secretmem areas will be
> cleared before the kdump kernel is kexec'ed.
> 
> Zeroization runs after the other CPUs have been stopped, so the page
> cache cannot be mutated concurrently and the xarray may be walked
> without taking the i_pages lock. This is a best effort, defense in depth
> measure. s_inode_list_lock is taken with trylock only. If a CPU was
> stopped mid-modification the list may be inconsistent, and this late
> into the panic path, there's nothing we can do about it.
> 
> Signed-off-by: Jan Sebastian Götte <[email protected]>

Are you actually using secretmem in your use case? I heard some rumors that
secretmem isn't used all that much in practice :)

-- 
Cheers,

David
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.