From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 667943D411B; Mon, 31 Aug 2026 08:37:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788165470; cv=none; b=mSALRx2m43Ork+lBj/CLH3rFs0xDgX4/aGXk5UuHeUrfVMZT/5bIo8SC7RTCF0yJdIGpUmPWClDk0xhlL1ir9+gRtUT1mKbKRsnWmOWoHADpsgiGgqZoNdQVEoftqJVdyQJd8TlqoOBiRVd/9EWlECeI/nW5zN2TYkW/2R55Obk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788165470; c=relaxed/simple; bh=uy+irBUijc345MtcL1xRWHmTcNGZNqrA0mki6miEpO0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=i2qdU6hhHG5fGPdWGZGPJyRkdqTkZWKJVqUxOJ/ZVz+ImGp9nv4SfeFhxjuOGfxdduSrg0nRC5bUoNOsnqYD1CZ6ebxT/mTwHvb/Kk4Axe6F3V6xWjVdUuDfVOqXK5f5ZpQuhVjPc6pWncB1nHkG8kpbaqWfalBfiiiew9v9P1A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=B4SXj5rg; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="B4SXj5rg" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67V822FB1639055; Mon, 31 Aug 2026 08:37:41 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=yxcatIt9SQ2dGGZwj cBd9vGqxAVhxzBClvvFiSa6bJs=; b=B4SXj5rgX1bSILLocbPo45hOikSrG7q8J 673nbjvXRV7mBduCr1zmv7C++Ow0RhOnYjN2tebwRDsQlcHZgEFOpBKQowHwDq6T 3BKcRTwkac2LUVfgzxaCSGJJ6zFgvjIQ0n0654ff8wk+bueqNM3KOZ1W3R+Yh5Dx xqUYg3yCoYRmZShC350x9rGuLzc/TrWp4OqcmzM3R9gTkUkOb/o2C4Lsq8mrMT+n cj/fgdXdNtgDKUv5uGE3OIWC2xTRBxyE0mCDFaROZHgMHs5bDrq+ZXDLo71PlBOT 2kyF7r7JwT0Plik9C3ckgn1QYWGsyzkxCUqQcESHT/3AU3YULJHKA== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4gbq54g3ks-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 31 Aug 2026 08:37:41 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67V8QOof024643; Mon, 31 Aug 2026 08:37:40 GMT Received: from smtprelay02.fra02v.mail.ibm.com ([9.218.2.226]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4gca4vvxx8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 31 Aug 2026 08:37:40 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (smtpav03.fra02v.mail.ibm.com [10.20.54.102]) by smtprelay02.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67V8baog46596554 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 31 Aug 2026 08:37:36 GMT Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 389662004F; Mon, 31 Aug 2026 08:37:36 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1539A2004E; Mon, 31 Aug 2026 08:37:36 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.165.38]) by smtpav03.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 31 Aug 2026 08:37:36 +0000 (GMT) From: Harald Freudenberger To: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , herbert@gondor.apana.org.au Cc: freude@linux.ibm.com, linux-s390@vger.kernel.org, linux-crypto@vger.kernel.org Subject: [PATCH v5 3/3] s390/crypto: Fix use of mutex in atomic context Date: Mon, 31 Aug 2026 10:37:35 +0200 Message-ID: <20260831083735.3625-5-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260831083735.3625-1-freude@linux.ibm.com> References: <20260831083735.3625-1-freude@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-s390@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODMxMDA3MiBTYWx0ZWRfX7v0DJCo+zf68 PlCLHbjx1lAwRtJz5zjQYl72ceAo9IeJvVZ223AoAY3XF9l5tX84+HK5VkgYRWkADrSL5VPcQy8 r7lBl8rWdR0pv6DYwkt0W6AEALIHvQiD/PGvhCNZbEYYAeF+uVrdreQZjnhsbpHqLm0SAjHXe5H TAHpGQ88lu1xHUod33t1AxP9yUXH2tvUVlM7WX9j66WkAXdu67DeUdRs+glF8BakSArAvGeqe8i lFrnQ7SuFJg71ugO/17CsMS4e2hFiKKuYKQTKL3qFwvanFS+KkzCAZgGC0no9YXrwcTYPculELz D9TYFqpvrkLLlEcEeOMG5dkV7eHY+WjuVaY0+ISv0W/cAEKxG2LhvTTqp8PYx8bMbl5tPf82tqT 1jCXNLgNmh9JaPg5LacrSNemxSWM7MSceoZSlHFBmRYgC9lrcDX1He4mt4KjlpDiWwGg9CFE497 wTTmJfC9m8cpVWGnCWQ== X-Proofpoint-ORIG-GUID: hpSVCYcGU7xdwCpi60Tf0pQhdVklHvWF X-Authority-Analysis: v=2.4 cv=CNgamxrD c=1 sm=1 tr=0 ts=6a953d55 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=VwQbUJbxAAAA:8 a=rMnTsvF-YiblEJPg39wA:9 X-Proofpoint-GUID: hpSVCYcGU7xdwCpi60Tf0pQhdVklHvWF X-Proofpoint-Spam-Info: AW1haW4tMjYwODMxMDA3MiBTYWx0ZWRfX7BdKRLTCPyhU U25PzEeWvOfe/M5rMUMUMBjuebxPAo84/Fp2eed+q3OockM+pxar37uH69kDG/HnesrqPdyD7Wh up3e2MSkkoJIfLA1duH6BdJC0+qRWyI= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-31_03,2026-08-27_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 suspectscore=0 phishscore=0 lowpriorityscore=0 priorityscore=1501 clxscore=1015 impostorscore=0 adultscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608310072 The AES CTR implementation used a mutex to lock one page of exclusive memory for fast CTR processing. Unfortunately a mutex is not save to use in atomic or interrupt context. So use a binary semaphore instead which is save to use in such environments. Furthermore rework the code to get rid of conditional locking. So restructure the AES CRT code by extracting the main loop into a separate function and just give in information about the (locked) page can be used or not (is not locked). Fixes: 7988fb2c03c8 ("crypto: s390/aes - convert to skcipher API") Suggested-by: Heiko Carstens Signed-off-by: Harald Freudenberger Reviewed-by: Holger Dengler Cc: stable@vger.kernel.org # 5.5+ --- arch/s390/crypto/aes_s390.c | 63 +++++++++++++++++++++++-------------- 1 file changed, 39 insertions(+), 24 deletions(-) diff --git a/arch/s390/crypto/aes_s390.c b/arch/s390/crypto/aes_s390.c index 10561aa687c7..0be6fa779d2c 100644 --- a/arch/s390/crypto/aes_s390.c +++ b/arch/s390/crypto/aes_s390.c @@ -26,14 +26,14 @@ #include #include #include -#include #include +#include #include #include #include static u8 *ctrblk; -static DEFINE_MUTEX(ctrblk_lock); +static DEFINE_SEMAPHORE(ctrblk_sem, 1); static cpacf_mask_t km_functions, kmc_functions, kmctr_functions, kma_functions; @@ -562,46 +562,61 @@ static unsigned int __ctrblk_init(u8 *ctrptr, u8 *iv, unsigned int nbytes) return n; } +static int __ctr_aes_crypt(struct s390_aes_ctx *sctx, + struct skcipher_walk *walk, bool locked) +{ + unsigned int n, nbytes; + int ret = 0; + u8 *ctrptr; + + while (!ret && ((nbytes = walk->nbytes) >= AES_BLOCK_SIZE)) { + n = AES_BLOCK_SIZE; + if (nbytes >= 2 * AES_BLOCK_SIZE && locked) + n = __ctrblk_init(ctrblk, walk->iv, nbytes); + ctrptr = (n > AES_BLOCK_SIZE) ? ctrblk : walk->iv; + cpacf_kmctr(sctx->fc, sctx->key, walk->dst.virt.addr, + walk->src.virt.addr, n, ctrptr); + if (ctrptr == ctrblk) + memcpy(walk->iv, ctrptr + n - AES_BLOCK_SIZE, + AES_BLOCK_SIZE); + crypto_inc(walk->iv, AES_BLOCK_SIZE); + ret = skcipher_walk_done(walk, nbytes - n); + } + + return ret; +} + static int ctr_aes_crypt(struct skcipher_request *req) { struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); struct s390_aes_ctx *sctx = crypto_skcipher_ctx(tfm); - u8 buf[AES_BLOCK_SIZE], *ctrptr; struct skcipher_walk walk; - unsigned int n, nbytes; - int ret, locked; + u8 buf[AES_BLOCK_SIZE]; + int ret; if (unlikely(!sctx->fc)) return fallback_skcipher_crypt(sctx, req, 0); - locked = mutex_trylock(&ctrblk_lock); - ret = skcipher_walk_virt(&walk, req, false); - while (!ret && ((nbytes = walk.nbytes) >= AES_BLOCK_SIZE)) { - n = AES_BLOCK_SIZE; + if (ret) + return ret; - if (nbytes >= 2*AES_BLOCK_SIZE && locked) - n = __ctrblk_init(ctrblk, walk.iv, nbytes); - ctrptr = (n > AES_BLOCK_SIZE) ? ctrblk : walk.iv; - cpacf_kmctr(sctx->fc, sctx->key, walk.dst.virt.addr, - walk.src.virt.addr, n, ctrptr); - if (ctrptr == ctrblk) - memcpy(walk.iv, ctrptr + n - AES_BLOCK_SIZE, - AES_BLOCK_SIZE); - crypto_inc(walk.iv, AES_BLOCK_SIZE); - ret = skcipher_walk_done(&walk, nbytes - n); + if (down_trylock(&ctrblk_sem) == 0) { + ret = __ctr_aes_crypt(sctx, &walk, true); + up(&ctrblk_sem); + } else { + ret = __ctr_aes_crypt(sctx, &walk, false); } - if (locked) - mutex_unlock(&ctrblk_lock); + /* * final block may be < AES_BLOCK_SIZE, copy only nbytes */ - if (!ret && nbytes) { + if (!ret && walk.nbytes > 0) { memset(buf, 0, AES_BLOCK_SIZE); - memcpy(buf, walk.src.virt.addr, nbytes); + memcpy(buf, walk.src.virt.addr, walk.nbytes); cpacf_kmctr(sctx->fc, sctx->key, buf, buf, AES_BLOCK_SIZE, walk.iv); - memcpy(walk.dst.virt.addr, buf, nbytes); + memcpy(walk.dst.virt.addr, buf, walk.nbytes); crypto_inc(walk.iv, AES_BLOCK_SIZE); ret = skcipher_walk_done(&walk, 0); memzero_explicit(buf, sizeof(buf)); -- 2.43.0