From: Harald Freudenberger <freude@linux.ibm.com>
To: Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Alexander Gordeev <agordeev@linux.ibm.com>,
herbert@gondor.apana.org.au
Cc: freude@linux.ibm.com, linux-s390@vger.kernel.org,
linux-crypto@vger.kernel.org
Subject: [PATCH v7 3/9] s390/crypto: Fix use of mutex in atomic context in PAES
Date: Mon, 31 Aug 2026 10:38:32 +0200 [thread overview]
Message-ID: <20260831083838.3703-4-freude@linux.ibm.com> (raw)
In-Reply-To: <20260831083838.3703-1-freude@linux.ibm.com>
The PAES CTR implementation used a mutex to lock one page of exclusive
memory for fast CTR processing. Unfortunately a mutex is not save to
use in atomic or interrupt context. So use a binary semaphore instead
which is save to use in such environments.
Furthermore rework the code to get rid of conditional locking. So
restructure the PAES CRT code by extracting the main loop into a
separate function and just give in information about the (locked) page
can be used or not (is not locked).
Fixes: 6cd87cb5ef6c ("s390/crypto: Rework protected key AES for true asynch support")
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Reviewed-by: Holger Dengler <dengler@linux.ibm.com>
Cc: stable@vger.kernel.org # 6.16+
---
arch/s390/crypto/paes_s390.c | 107 +++++++++++++++++++----------------
1 file changed, 57 insertions(+), 50 deletions(-)
diff --git a/arch/s390/crypto/paes_s390.c b/arch/s390/crypto/paes_s390.c
index d075b0241f1f..10d1c56a049d 100644
--- a/arch/s390/crypto/paes_s390.c
+++ b/arch/s390/crypto/paes_s390.c
@@ -19,7 +19,7 @@
#include <linux/init.h>
#include <linux/miscdevice.h>
#include <linux/module.h>
-#include <linux/mutex.h>
+#include <linux/semaphore.h>
#include <linux/spinlock.h>
#include <crypto/aes.h>
#include <crypto/algapi.h>
@@ -45,7 +45,7 @@ module_param_named(clrkey, pkey_clrkey_allowed, bool, 0444);
MODULE_PARM_DESC(clrkey, "Allow clear key material (default N)");
static u8 *ctrblk;
-static DEFINE_MUTEX(ctrblk_lock);
+static DEFINE_SEMAPHORE(ctrblk_sem, 1);
static cpacf_mask_t km_functions, kmc_functions, kmctr_functions;
@@ -937,41 +937,14 @@ static inline unsigned int __ctrblk_init(u8 *ctrptr, u8 *iv, unsigned int nbytes
return n;
}
-static int ctr_paes_do_crypt(struct s390_paes_ctx *ctx,
- struct s390_pctr_req_ctx *req_ctx,
- bool tested, bool maysleep)
+static int __ctr_paes_do_crypt(struct s390_paes_ctx *ctx,
+ struct ctr_param *param,
+ struct skcipher_walk *walk,
+ bool tested, bool maysleep, bool locked)
{
- struct ctr_param *param = &req_ctx->param;
- struct skcipher_walk *walk = &req_ctx->walk;
- u8 buf[AES_BLOCK_SIZE], *ctrptr;
unsigned int nbytes, n, k;
- int pk_state, locked, rc = 0;
-
- if (!req_ctx->param_init_done) {
- /* fetch and check protected key state */
- spin_lock_bh(&ctx->pk_lock);
- pk_state = ctx->pk_state;
- switch (pk_state) {
- case PK_STATE_NO_KEY:
- rc = -ENOKEY;
- break;
- case PK_STATE_CONVERT_IN_PROGRESS:
- rc = -EKEYEXPIRED;
- break;
- case PK_STATE_VALID:
- memcpy(param->key, ctx->pk.protkey, sizeof(param->key));
- req_ctx->param_init_done = true;
- break;
- default:
- rc = pk_state < 0 ? pk_state : -EIO;
- break;
- }
- spin_unlock_bh(&ctx->pk_lock);
- }
- if (rc)
- goto out;
-
- locked = mutex_trylock(&ctrblk_lock);
+ u8 *ctrptr;
+ int rc = 0;
/*
* Note that in case of partial processing or failure the walk
@@ -991,37 +964,71 @@ static int ctr_paes_do_crypt(struct s390_paes_ctx *ctx,
AES_BLOCK_SIZE);
crypto_inc(walk->iv, AES_BLOCK_SIZE);
rc = skcipher_walk_done(walk, nbytes - k);
- if (rc) {
- if (locked)
- mutex_unlock(&ctrblk_lock);
+ if (rc)
goto out;
- }
}
if (k < n) {
if (!maysleep) {
- if (locked)
- mutex_unlock(&ctrblk_lock);
rc = -EKEYEXPIRED;
goto out;
}
rc = paes_convert_key(ctx, tested);
- if (rc) {
- if (locked)
- mutex_unlock(&ctrblk_lock);
+ if (rc)
goto out;
- }
spin_lock_bh(&ctx->pk_lock);
memcpy(param->key, ctx->pk.protkey, sizeof(param->key));
spin_unlock_bh(&ctx->pk_lock);
}
}
- if (locked)
- mutex_unlock(&ctrblk_lock);
+
+out:
+ return rc;
+}
+
+static int ctr_paes_do_crypt(struct s390_paes_ctx *ctx,
+ struct s390_pctr_req_ctx *req_ctx,
+ bool tested, bool maysleep)
+{
+ struct ctr_param *param = &req_ctx->param;
+ struct skcipher_walk *walk = &req_ctx->walk;
+ u8 buf[AES_BLOCK_SIZE];
+ int pk_state, rc = 0;
+
+ if (!req_ctx->param_init_done) {
+ /* fetch and check protected key state */
+ spin_lock_bh(&ctx->pk_lock);
+ pk_state = ctx->pk_state;
+ switch (pk_state) {
+ case PK_STATE_NO_KEY:
+ rc = -ENOKEY;
+ break;
+ case PK_STATE_CONVERT_IN_PROGRESS:
+ rc = -EKEYEXPIRED;
+ break;
+ case PK_STATE_VALID:
+ memcpy(param->key, ctx->pk.protkey, sizeof(param->key));
+ req_ctx->param_init_done = true;
+ break;
+ default:
+ rc = pk_state < 0 ? pk_state : -EIO;
+ break;
+ }
+ spin_unlock_bh(&ctx->pk_lock);
+ }
+ if (rc)
+ goto out;
+
+ if (down_trylock(&ctrblk_sem) == 0) {
+ rc = __ctr_paes_do_crypt(ctx, param, walk, tested, maysleep, true);
+ up(&ctrblk_sem);
+ } else {
+ rc = __ctr_paes_do_crypt(ctx, param, walk, tested, maysleep, false);
+ }
/* final block may be < AES_BLOCK_SIZE, copy only nbytes */
- if (nbytes) {
+ if (!rc && walk->nbytes > 0) {
memset(buf, 0, AES_BLOCK_SIZE);
- memcpy(buf, walk->src.virt.addr, nbytes);
+ memcpy(buf, walk->src.virt.addr, walk->nbytes);
while (1) {
if (cpacf_kmctr(ctx->fc, param, buf,
buf, AES_BLOCK_SIZE,
@@ -1038,7 +1045,7 @@ static int ctr_paes_do_crypt(struct s390_paes_ctx *ctx,
memcpy(param->key, ctx->pk.protkey, sizeof(param->key));
spin_unlock_bh(&ctx->pk_lock);
}
- memcpy(walk->dst.virt.addr, buf, nbytes);
+ memcpy(walk->dst.virt.addr, buf, walk->nbytes);
crypto_inc(walk->iv, AES_BLOCK_SIZE);
rc = skcipher_walk_done(walk, 0);
}
--
2.43.0
next prev parent reply other threads:[~2026-08-31 8:38 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 8:38 [PATCH v7 0/9] Fixes and rework for paes_s390 and phmac_s390 Harald Freudenberger
2026-08-31 8:38 ` [PATCH v7 1/9] s390/crypto: Fix return code handling at skcipher_walk_done in PAES algorithms Harald Freudenberger
2026-08-31 8:55 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 2/9] s390/crypto: Fix missing scrub of temp buffers with PAES algorithm Harald Freudenberger
2026-08-31 9:10 ` sashiko-bot
2026-08-31 8:38 ` Harald Freudenberger [this message]
2026-08-31 9:19 ` [PATCH v7 3/9] s390/crypto: Fix use of mutex in atomic context in PAES sashiko-bot
2026-08-31 8:38 ` [PATCH v7 4/9] s390/crypto: Fix missing cra_flags in paes_s390 Harald Freudenberger
2026-08-31 9:32 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 5/9] s390/crypto: Fix handling of EBUSY in PAES when req is pushed to crypto engine Harald Freudenberger
2026-08-31 9:45 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 6/9] s390/crypto: Fix handling of EBUSY in PHMAC " Harald Freudenberger
2026-08-31 9:58 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 7/9] s390/crypto: Fix wrong return code to engine in asynch callbacks Harald Freudenberger
2026-08-31 10:04 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 8/9] s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly Harald Freudenberger
2026-08-31 10:10 ` sashiko-bot
2026-08-31 8:38 ` [PATCH v7 9/9] s390/crypto: Enable CONTEXT_ANALYSIS Harald Freudenberger
2026-08-31 10:11 ` sashiko-bot
2026-09-03 19:36 ` [PATCH v7 0/9] Fixes and rework for paes_s390 and phmac_s390 Heiko Carstens
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831083838.3703-4-freude@linux.ibm.com \
--to=freude@linux.ibm.com \
--cc=agordeev@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.