On Wed, 19 Aug 2026 at 17:59, Eric Biggers <[email protected]> wrote:
> On Wed, Aug 19, 2026 at 04:22:23PM +0200, Daniel Vacek wrote:
> > > > +     /* We can't wipe the master key secret until the last activeref is
> > > > +      * dropped on the master key with per-extent encryption since the 
> > > > key
> > > > +      * derivation continues to happen as long as there are active 
> > > > refs.
> > > > +      * Wipe it here now that we're done using it.
> > > > +      */
> > > > +     if (sb->s_cop->has_per_extent_encryption)
> > > > +             wipe_master_key_secret(&mk->mk_secret);
> > >
> > > wipe_master_key_secret() is idempotent, so we might as well just do it
> > > unconditionally here.
> >
> > While this is true, it also (kind of) documents that the secret should
> > already be wiped out by now in case of !extent encryption.
> >
> > But I can wipe the secret unconditionally here if you insist.
>
> So leave a comment that mentions that it's not always needed.  Just like
> how fscrypt_free_master_key() does kfree_sensitive(), because why not.

Right. Thanks.

--nX

> - Eric

Reply via email to