Commit 458c0480 authored by Arvind Sankar's avatar Arvind Sankar Committed by Herbert Xu
Browse files

crypto: hash - Use memzero_explicit() for clearing state



Without the barrier_data() inside memzero_explicit(), the compiler may
optimize away the state-clearing if it can tell that the state is not
used afterwards.

Signed-off-by: default avatarArvind Sankar <nivedita@alum.mit.edu>
Acked-by: default avatarArd Biesheuvel <ardb@kernel.org>
Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
parent 1762818f
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -168,7 +168,7 @@ static int ghash_final(struct shash_desc *desc, u8 *dst)
	put_unaligned_be64(ctx->digest[1], dst);
	put_unaligned_be64(ctx->digest[0], dst + 8);

	*ctx = (struct ghash_desc_ctx){};
	memzero_explicit(ctx, sizeof(*ctx));
	return 0;
}

+1 −1
Original line number Diff line number Diff line
@@ -177,7 +177,7 @@ void poly1305_final_arch(struct poly1305_desc_ctx *dctx, u8 *dst)
	}

	poly1305_emit(&dctx->h, dst, dctx->s);
	*dctx = (struct poly1305_desc_ctx){};
	memzero_explicit(dctx, sizeof(*dctx));
}
EXPORT_SYMBOL(poly1305_final_arch);

+1 −1
Original line number Diff line number Diff line
@@ -94,7 +94,7 @@ static int sha3_final(struct shash_desc *desc, u8 *out)
	if (digest_size & 4)
		put_unaligned_le32(sctx->st[i], (__le32 *)digest);

	*sctx = (struct sha3_state){};
	memzero_explicit(sctx, sizeof(*sctx));
	return 0;
}

+1 −1
Original line number Diff line number Diff line
@@ -209,7 +209,7 @@ void poly1305_final_arch(struct poly1305_desc_ctx *dctx, u8 *dst)
	}

	poly1305_simd_emit(&dctx->h, dst, dctx->s);
	*dctx = (struct poly1305_desc_ctx){};
	memzero_explicit(dctx, sizeof(*dctx));
}
EXPORT_SYMBOL(poly1305_final_arch);

+2 −1
Original line number Diff line number Diff line
@@ -12,6 +12,7 @@
#include <crypto/sha.h>
#include <linux/crypto.h>
#include <linux/module.h>
#include <linux/string.h>

#include <asm/unaligned.h>

@@ -101,7 +102,7 @@ static inline int sha1_base_finish(struct shash_desc *desc, u8 *out)
	for (i = 0; i < SHA1_DIGEST_SIZE / sizeof(__be32); i++)
		put_unaligned_be32(sctx->state[i], digest++);

	*sctx = (struct sha1_state){};
	memzero_explicit(sctx, sizeof(*sctx));
	return 0;
}

Loading