On Wed, Aug 12, 2026 at 12:08:39PM +0200, Jan Sebastian Götte wrote:
> I can imagine one alternative way to approach this, tell me what you think:
> Instead of registering wipe handlers that memzero places on panic, I could
> put an optional registry of (addr, len) descriptors into crashkernel memory
> that the original kernel populates with the PAs of buffers to clear ahead of
> time. Then the kdump kernel could do the actual memzero. This would remove
> all code from the actual kdump path here. The registry could be made
> per-core to avoid locks.

Or create a dedicated mempool from which all sensitive data is allocated,
then call mempool_free_bulk() on kexec to poison everything in that pool?

Thanks,

Lukas

Reply via email to