Key payloads sit in memory in plain text for as long as the key exists, and a kdump crash dump captures them along with everything else.
Allocate the payloads of the user-defined, trusted and encrypted key types from the new secret pool, so that their backing pages are marked by crash_memaction for the kdump kernel to wipe. This commit covers the key types used by dm-crypt/cryptsetup. Additional key types can be added if needed in future commits. Signed-off-by: Jan Sebastian Götte <[email protected]> Assisted-by: Claude Opus 5 <[email protected]> --- security/keys/encrypted-keys/encrypted.c | 5 +++-- security/keys/trusted-keys/trusted_core.c | 3 ++- security/keys/user_defined.c | 3 ++- 3 files changed, 7 insertions(+), 4 deletions(-) diff --git a/security/keys/encrypted-keys/encrypted.c b/security/keys/encrypted-keys/encrypted.c index e07092ea301a..633f31131867 100644 --- a/security/keys/encrypted-keys/encrypted.c +++ b/security/keys/encrypted-keys/encrypted.c @@ -27,6 +27,7 @@ #include <linux/random.h> #include <linux/rcupdate.h> #include <linux/scatterlist.h> +#include <linux/secret_pool.h> #include <linux/ctype.h> #include <crypto/aes.h> #include <crypto/sha2.h> @@ -648,8 +649,8 @@ static struct encrypted_key_payload *encrypted_key_alloc(struct key *key, if (ret < 0) return ERR_PTR(ret); - epayload = kzalloc_flex(*epayload, payload_data, payload_totallen, - GFP_KERNEL); + epayload = secret_pool_zalloc_flex(*epayload, payload_data, + payload_totallen, GFP_KERNEL); if (!epayload) return ERR_PTR(-ENOMEM); diff --git a/security/keys/trusted-keys/trusted_core.c b/security/keys/trusted-keys/trusted_core.c index 0509d9955f2a..5f209c5f3f14 100644 --- a/security/keys/trusted-keys/trusted_core.c +++ b/security/keys/trusted-keys/trusted_core.c @@ -22,6 +22,7 @@ #include <linux/parser.h> #include <linux/random.h> #include <linux/rcupdate.h> +#include <linux/secret_pool.h> #include <linux/slab.h> #include <linux/static_call.h> #include <linux/string.h> @@ -140,7 +141,7 @@ static struct trusted_key_payload *trusted_payload_alloc(struct key *key) ret = key_payload_reserve(key, sizeof(*p)); if (ret < 0) goto err; - p = kzalloc_obj(*p); + p = secret_pool_zalloc_obj(*p); if (!p) goto err; diff --git a/security/keys/user_defined.c b/security/keys/user_defined.c index 6f88b507f927..dce2508587df 100644 --- a/security/keys/user_defined.c +++ b/security/keys/user_defined.c @@ -7,6 +7,7 @@ #include <linux/export.h> #include <linux/init.h> +#include <linux/secret_pool.h> #include <linux/slab.h> #include <linux/seq_file.h> #include <linux/err.h> @@ -64,7 +65,7 @@ int user_preparse(struct key_preparsed_payload *prep) if (datalen == 0 || datalen > 32767 || !prep->data) return -EINVAL; - upayload = kmalloc_flex(*upayload, data, datalen); + upayload = secret_pool_alloc_flex(*upayload, data, datalen); if (!upayload) return -ENOMEM; -- 2.55.0

