Re: [PATCH v2 1/9] crypto: Provide a wrapper for zeroizing crypto_aes_ctx

From: Simon Richter

Date: Mon Aug 03 2026 - 22:22:33 EST


Hi,

On 8/4/26 4:05 AM, Eric Biggers wrote:

I guess we should start using __cleanup with type-specific zeroization
functions like this more often.
Frame challenge: should key material be copied that often that we need a mechanism to keep track of it?

My feeling is that this wasn't a conscious decision, but is the result of two other decisions (that individually make sense): contexts need to be self-contained (so need to include key material), and context creation should be cheap (so stack contexts are allowed).

So I can see two other approaches:

1. add a parameter to library functions that instructs them to clear the key material from the context. Most callers with the context on the stack could probably use that mechanism, and SIMD based implementations might even be able to do this rather early.

2. allow contexts to refer to key material stored elsewhere to avoid the copy. That opens the lifetime tracking can of worms, but the on-stack crypto context is rather short-lived.

Simon