[PATCH v3 05/12] dm crypt: Allocate key material from the secret pool
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Mon Sep 28 17:33:55 UTC 2026
> dm-crypt keeps the volume key, the IV mode seeds and, when a keyring key
> is used, the key description in memory for as long as the target exists.
> If the system crashes, they are left in memory and will end up in a
> crash dump.
>
> Allocate every buffer that holds key material from the new secret pool,
> whose backing pages are marked by crash_memaction for the kdump kernel
> to wipe. The volume key is a flexible array at the end of struct
> crypt_config, so the whole struct moves into the pool with it.
>
> Signed-off-by: Jan Sebastian Götte <linux at jaseg.de>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928-crash-memaction-upstream-20260921-v3-0-e511e9ee2329@jaseg.de?part=5
More information about the Linux-security-module-archive
mailing list