Re: [PATCH] random: add and use memzero_explicit() for clearing data

From: Daniel Borkmann
Date: Mon Dec 01 2014 - 06:49:08 EST


On 12/01/2014 12:29 PM, Dan Carpenter wrote:
On Mon, Dec 01, 2014 at 12:04:57PM +0100, Daniel Borkmann wrote:
Well, BSD has helpers such as bzero_explicit() for such cases to work
around this, which memzero_explicit() similarly does; see also [1].

[1] https://gcc.gnu.org/ml/gcc-help/2014-10/msg00059.html

We should make memset() a define and call a custom function internally.

Otherwise there are thousands of calls to memset() which we would need
to audit. We could do some of this automatically but it's going to be a
mess.

Sort of, yeah; for now random driver and crypto subsystem, which I consider
the main candidates, have been converted and with Julia's latest patch set
from today (via coccinelle) also remaining arch-specific crypto drivers.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/