> dm-crypt keeps the volume key, the IV mode seeds and, when a keyring key > is used, the key description in memory for as long as the target exists. > If the system crashes, they are left in memory and will end up in a > crash dump. > > Allocate every buffer that holds key material from the new secret pool, > whose backing pages are marked by crash_memaction for the kdump kernel > to wipe. The volume key is a flexible array at the end of struct > crypt_config, so the whole struct moves into the pool with it. > > Signed-off-by: Jan Sebastian Götte <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20260928-crash-memaction-upstream-20260921-v3-0-e511e9ee2...@jaseg.de?part=5

