commit | 96c2b8f3d7e33875c0d0b3a01f65fafdbacffa8a | [log] [tgz] |
---|---|---|
author | Jakub Kicinski <[email protected]> | Tue Feb 06 17:18:21 2024 -0800 |
committer | Robert Kolchmeyer <[email protected]> | Sun Jun 16 17:30:09 2024 +0000 |
tree | ec28db97b0393003b31aa82da6f50305b6f60eff | |
parent | 117793401924075ff762ae88f1c78ebf69734c04 [diff] |
net: tls: handle backlogging of crypto requests commit 8590541473188741055d27b955db0777569438e3 upstream. Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case, the async callback will also be called twice: first with err == -EINPROGRESS, which it seems we can just ignore, then with err == 0. Compared to Sabrina's original patch this version uses the new tls_*crypt_async_wait() helpers and converts the EBUSY to EINPROGRESS to avoid having to modify all the error handling paths. The handling is identical. BUG=b/338196126 TEST=presubmit RELEASE_NOTE=Fixed CVE-2024-26584 in the Linux kernel. cos-patch: security-high Fixes: a54667f6728c ("tls: Add support for encryption using async offload accelerator") Fixes: 94524d8fc965 ("net/tls: Add support for async decryption of tls records") Co-developed-by: Sabrina Dubroca <[email protected]> Signed-off-by: Sabrina Dubroca <[email protected]> Link: https://lore.kernel.org/netdev/9681d1febfec295449a62300938ed2ae66983f28.1694018970.git.sd@queasysnail.net/ Signed-off-by: Jakub Kicinski <[email protected]> Reviewed-by: Simon Horman <[email protected]> Signed-off-by: David S. Miller <[email protected]> [v5.15: fixed contextual merge-conflicts in tls_decrypt_done and tls_encrypt_done] Cc: <[email protected]> # 5.15 Signed-off-by: Shaoying Xu <[email protected]> Signed-off-by: Greg Kroah-Hartman <[email protected]> (cherry picked from commit 3ade391adc584f17b5570fd205de3ad029090368) Signed-off-by: Robert Kolchmeyer <[email protected]> Change-Id: I44faca450c7d722bd06ddf17b00406dd7b37033b Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/74297 Tested-by: Cusky Presubmit Bot <[email protected]> Reviewed-by: Oleksandr Tymoshenko <[email protected]>