[PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)

David Hildenbrand (Arm) david at kernel.org
Mon Sep 28 18:58:22 UTC 2026


On 9/28/26 19:49, Lorenzo Stoakes (ARM) wrote:
> On Mon, Sep 28, 2026 at 07:17:48PM +0200, Jan Sebastian Götte wrote:
>> I'm using linux on an embedded target in a Hardware Security Module-like
>> application. One requirement is that I want the system to be able to
>> quickly erase its memory when it detects physical tampering. I'm
>> approaching that by using kdump to load into a small payload that
>> instead of dumping RAM, erases RAM frmo start to end. However, writing
>> all of RAM, especially on an embedded target, is rather slow. For this
>> reason, I propose a new crash_memaction mechanism that lets the old
>> kernel indicate marked memory areas to the kdump kernel at page
>> granularity.
> 
> Sorry this all seems really invasive for what seems to be a very specific
> use case.
> 
> In general, with big changes like this, you should send the series as an
> RFC.
> 
> Please send any future revisions of this as an RFC.
> 
> The bar for a new VMA flag, a new madvise() flag, 

It's actually three new madvise modes. Way to invasive indeed. This won't fly.

-- 
Cheers,

David



More information about the Linux-security-module-archive mailing list