Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1628447
| From | Eric Biggers <ebiggers3@gmail.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 3/5] KEYS: encrypted: sanitize all key material |
| Date | 2017-04-21 20:30 +0200 |
| Message-ID | <tyLtG-Ix-67@gated-at.bofh.it> (permalink) |
| References | <tyCgF-3B2-7@gated-at.bofh.it> <tyCgF-3B2-9@gated-at.bofh.it> <tyHT3-6W1-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, Apr 21, 2017 at 03:31:08PM +0100, David Howells wrote: > Eric Biggers <ebiggers3@gmail.com> wrote: > > > - memzero_explicit(epayload->decrypted_data, epayload->decrypted_datalen); > > - kfree(key->payload.data[0]); > > + kzfree(key->payload.data[0]); > > Should kzfree() be using memzero_explicit() rather than memset()? > > David It's not actually needed because it's impossible for the compiler to optimize away the memset(). memzero_explicit() is only needed on stack data. The reason I still used memzero_explicit() for heap data in a couple of my patches, even though it's unnecessary, is just that it makes it clearer that it's being done for sanitization purposes, as opposed to some random memset. That's not as much of an issue for kzfree(), since it's explicitly for sanitization purposes already. As a separate note, something that might make sense at some point would be to skip the memset in kzfree() if slab poisoning is enabled. Eric
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3/5] KEYS: encrypted: sanitize all key material Eric Biggers <ebiggers3@gmail.com> - 2017-04-21 10:40 +0200
Re: [PATCH 3/5] KEYS: encrypted: sanitize all key material David Howells <dhowells@redhat.com> - 2017-04-21 16:40 +0200
Re: [PATCH 3/5] KEYS: encrypted: sanitize all key material Eric Biggers <ebiggers3@gmail.com> - 2017-04-21 20:30 +0200
Re: [PATCH 3/5] KEYS: encrypted: sanitize all key material David Howells <dhowells@redhat.com> - 2017-04-24 16:20 +0200
csiph-web