A tfm's context holds the expanded key schedule, which a crash dump
would capture.

Allocate tfms from the secret pool, so that their backing pages are
marked by crash_memaction for the kdump kernel to wipe.
The context is a flexible array at the end of struct crypto_tfm and the
frontend's private data sits in front of the struct, so the whole
allocation moves into the pool.

Allocation cost increases by a bucket lookup in crash_memaction. Freeing
is unchanged.

Signed-off-by: Jan Sebastian Götte <[email protected]>
Assisted-by: Claude Opus 5 <[email protected]>
---
 crypto/api.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/crypto/api.c b/crypto/api.c
index 24227582cfcf..eba310f128dc 100644
--- a/crypto/api.c
+++ b/crypto/api.c
@@ -18,6 +18,7 @@
 #include <linux/module.h>
 #include <linux/param.h>
 #include <linux/sched/signal.h>
+#include <linux/secret_pool.h>
 #include <linux/slab.h>
 #include <linux/string.h>
 #include <linux/completion.h>
@@ -413,7 +414,7 @@ struct crypto_tfm *__crypto_alloc_tfm(struct crypto_alg 
*alg, u32 type,
        int err = -ENOMEM;
 
        tfm_size = sizeof(*tfm) + crypto_ctxsize(alg, type, mask);
-       tfm = kzalloc(tfm_size, GFP_KERNEL);
+       tfm = secret_pool_zalloc(tfm_size, GFP_KERNEL);
        if (tfm == NULL)
                goto out_err;
 
@@ -428,7 +429,7 @@ struct crypto_tfm *__crypto_alloc_tfm(struct crypto_alg 
*alg, u32 type,
        crypto_exit_ops(tfm);
        if (err == -EAGAIN)
                crypto_shoot_alg(alg);
-       kfree(tfm);
+       kfree_sensitive(tfm);
 out_err:
        tfm = ERR_PTR(err);
 out:
@@ -502,7 +503,7 @@ void *crypto_create_tfm_node(struct crypto_alg *alg,
        int err;
 
        size = frontend->tfmsize + sizeof(*tfm) + frontend->extsize(alg);
-       mem = kzalloc_node(size, GFP_KERNEL, node);
+       mem = secret_pool_zalloc_node(size, GFP_KERNEL, node);
        if (!mem)
                return ERR_PTR(-ENOMEM);
 
@@ -525,7 +526,7 @@ void *crypto_create_tfm_node(struct crypto_alg *alg,
 out_free_tfm:
        if (err == -EAGAIN)
                crypto_shoot_alg(alg);
-       kfree(mem);
+       kfree_sensitive(mem);
        mem = ERR_PTR(err);
 out:
        return mem;

-- 
2.55.0


Reply via email to