[PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)
David Hildenbrand (Arm)
david at kernel.org
Mon Sep 28 18:58:22 UTC 2026
On 9/28/26 19:49, Lorenzo Stoakes (ARM) wrote:
> On Mon, Sep 28, 2026 at 07:17:48PM +0200, Jan Sebastian Götte wrote:
>> I'm using linux on an embedded target in a Hardware Security Module-like
>> application. One requirement is that I want the system to be able to
>> quickly erase its memory when it detects physical tampering. I'm
>> approaching that by using kdump to load into a small payload that
>> instead of dumping RAM, erases RAM frmo start to end. However, writing
>> all of RAM, especially on an embedded target, is rather slow. For this
>> reason, I propose a new crash_memaction mechanism that lets the old
>> kernel indicate marked memory areas to the kdump kernel at page
>> granularity.
>
> Sorry this all seems really invasive for what seems to be a very specific
> use case.
>
> In general, with big changes like this, you should send the series as an
> RFC.
>
> Please send any future revisions of this as an RFC.
>
> The bar for a new VMA flag, a new madvise() flag,
It's actually three new madvise modes. Way to invasive indeed. This won't fly.
--
Cheers,
David
More information about the Linux-security-module-archive
mailing list