@@ -91,6 +91,17 @@ its keyid should be passed in via sysfs.
The command format for doing a secure erase is:
erase <old keyid>
+9. Overwrite
+------------
+The command format for doing an overwrite is:
+overwrite <old keyid>
+
+Overwrite can be done without a key if security is not enabled. A key serial
+of 0 can be passed in to indicate no key.
+
+The sysfs attribute "security" can be polled to wait on overwrite completion.
+Overwrite can last tens of minutes or more depending on nvdimm size.
+
An "old" key with the passphrase payload that is tied to the nvdimm should be
injected with a key description that does not have the "nvdimm:" prefix and
its keyid should be passed in via sysfs.
Add overwrite command usages to security documentation. Signed-off-by: Dave Jiang <dave.jiang@intel.com> --- Documentation/nvdimm/security.txt | 11 +++++++++++ 1 file changed, 11 insertions(+)