On Wed, Aug 12, 2026 at 12:08:39PM +0200, Jan Sebastian Götte wrote: > I can imagine one alternative way to approach this, tell me what you think: > Instead of registering wipe handlers that memzero places on panic, I could > put an optional registry of (addr, len) descriptors into crashkernel memory > that the original kernel populates with the PAs of buffers to clear ahead of > time. Then the kdump kernel could do the actual memzero. This would remove > all code from the actual kdump path here. The registry could be made > per-core to avoid locks.
Or create a dedicated mempool from which all sensitive data is allocated, then call mempool_free_bulk() on kexec to poison everything in that pool? Thanks, Lukas

