Re: [PATCH 0/3] lib/crypto: Provide functions for zeroizing SHA2 hmac_sha* structures

From: Eric Biggers

Date: Wed Sep 30 2026 - 15:55:19 EST


On Mon, Sep 28, 2026 at 10:30:52AM +0200, Thomas Huth wrote:
> This patch series has been split of my earlier zeroization patch
> series since there were some troubles left with the purgatory patch:
>
> https://lore.kernel.org/all/20260924145806.GA1949494@ax162/
>
> As I've confirmed now, the fix for the problem is indeed to set
> -D__DISABLE_EXPORTS for the other files in the x86 purgatory, too,
> so the first patch here has now been changed accordingly.
>
> Thomas Huth (3):
> x86/purgatory: Compile purgatory with -D__NO_FORTIFY and
> -D__DISABLE_EXPORTS
> lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha*
> structures
> smb: client: Use hmac_sha256_zeroize_ctx function to clear
> hmac_sha256_ctx
>
> arch/x86/purgatory/Makefile | 3 +-
> fs/smb/client/smb2transport.c | 3 +-
> include/crypto/sha2.h | 73 +++++++++++++++++++++++++++++++++++
> 3 files changed, 75 insertions(+), 4 deletions(-)

Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-next

- Eric