RE: [PATCH v6 07/12] x86/cpu/keylocker: Load an internal wrapping key at boot-time

From: Elliott, Robert (Servers)
Date: Mon May 08 2023 - 15:19:55 EST



> diff --git a/arch/x86/kernel/keylocker.c b/arch/x86/kernel/keylocker.c
...
> +void __init destroy_keylocker_data(void)
> +{
> + memset(&kl_setup.key, KEY_DESTROY, sizeof(kl_setup.key));
> +}

That's a special value for garbage collected keyring keys assigned
a keytype of ".dead". memzero() or memzero_explicit() might be better
for this use case.