Key payloads sit in memory in plain text for as long as the key exists,
and a kdump crash dump captures them along with everything else.

Allocate the payloads of the user-defined, trusted and encrypted key
types from the new secret pool, so that their backing pages are marked
by crash_memaction for the kdump kernel to wipe.

This commit covers the key types used by dm-crypt/cryptsetup. Additional
key types can be added if needed in future commits.

Signed-off-by: Jan Sebastian Götte <[email protected]>
Assisted-by: Claude Opus 5 <[email protected]>
---
 security/keys/encrypted-keys/encrypted.c  | 5 +++--
 security/keys/trusted-keys/trusted_core.c | 3 ++-
 security/keys/user_defined.c              | 3 ++-
 3 files changed, 7 insertions(+), 4 deletions(-)

diff --git a/security/keys/encrypted-keys/encrypted.c 
b/security/keys/encrypted-keys/encrypted.c
index e07092ea301a..633f31131867 100644
--- a/security/keys/encrypted-keys/encrypted.c
+++ b/security/keys/encrypted-keys/encrypted.c
@@ -27,6 +27,7 @@
 #include <linux/random.h>
 #include <linux/rcupdate.h>
 #include <linux/scatterlist.h>
+#include <linux/secret_pool.h>
 #include <linux/ctype.h>
 #include <crypto/aes.h>
 #include <crypto/sha2.h>
@@ -648,8 +649,8 @@ static struct encrypted_key_payload 
*encrypted_key_alloc(struct key *key,
        if (ret < 0)
                return ERR_PTR(ret);
 
-       epayload = kzalloc_flex(*epayload, payload_data, payload_totallen,
-                               GFP_KERNEL);
+       epayload = secret_pool_zalloc_flex(*epayload, payload_data,
+                                          payload_totallen, GFP_KERNEL);
        if (!epayload)
                return ERR_PTR(-ENOMEM);
 
diff --git a/security/keys/trusted-keys/trusted_core.c 
b/security/keys/trusted-keys/trusted_core.c
index 0509d9955f2a..5f209c5f3f14 100644
--- a/security/keys/trusted-keys/trusted_core.c
+++ b/security/keys/trusted-keys/trusted_core.c
@@ -22,6 +22,7 @@
 #include <linux/parser.h>
 #include <linux/random.h>
 #include <linux/rcupdate.h>
+#include <linux/secret_pool.h>
 #include <linux/slab.h>
 #include <linux/static_call.h>
 #include <linux/string.h>
@@ -140,7 +141,7 @@ static struct trusted_key_payload 
*trusted_payload_alloc(struct key *key)
        ret = key_payload_reserve(key, sizeof(*p));
        if (ret < 0)
                goto err;
-       p = kzalloc_obj(*p);
+       p = secret_pool_zalloc_obj(*p);
        if (!p)
                goto err;
 
diff --git a/security/keys/user_defined.c b/security/keys/user_defined.c
index 6f88b507f927..dce2508587df 100644
--- a/security/keys/user_defined.c
+++ b/security/keys/user_defined.c
@@ -7,6 +7,7 @@
 
 #include <linux/export.h>
 #include <linux/init.h>
+#include <linux/secret_pool.h>
 #include <linux/slab.h>
 #include <linux/seq_file.h>
 #include <linux/err.h>
@@ -64,7 +65,7 @@ int user_preparse(struct key_preparsed_payload *prep)
        if (datalen == 0 || datalen > 32767 || !prep->data)
                return -EINVAL;
 
-       upayload = kmalloc_flex(*upayload, data, datalen);
+       upayload = secret_pool_alloc_flex(*upayload, data, datalen);
        if (!upayload)
                return -ENOMEM;
 

-- 
2.55.0


Reply via email to