From: Ahsan Atta <ahsan.atta@intel.com>
To: herbert@gondor.apana.org.au
Cc: linux-crypto@vger.kernel.org, qat-linux@intel.com,
Ahsan Atta <ahsan.atta@intel.com>,
Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Subject: [PATCH v2] crypto: qat - fix active_devs leak on crypto alg registration failure
Date: Tue, 8 Sep 2026 13:10:13 +0100 [thread overview]
Message-ID: <20260908121013.697443-1-ahsan.atta@intel.com> (raw)
adf_dev_start() registered both alg sets in a single condition.
If qat_algs_register() succeeds but qat_asym_algs_register() fails,
ADF_STATUS_CRYPTO_ALGS_REGISTERED is left clear, so adf_dev_stop() skips
qat_algs_unregister(): the skciphers and aeads stay registered with
active_devs stuck at 1, pinning the module.
Both helpers leak active_devs internally as well - they increment it and
return without decrementing when a crypto_register_*() call fails, and
the asym path also leaves the already-registered akcipher behind.
Split the registration in adf_dev_start() so that an asym failure
unregisters qat_algs, and unwind active_devs (and the akcipher) on the
error paths of both register helpers. While at it, propagate the error
code returned by the register helpers instead of a blanket -EFAULT.
Fixes: 9b2f33a1bfcd ("crypto: qat - fix unregistration of crypto algorithms")
Signed-off-by: Ahsan Atta <ahsan.atta@intel.com>
Reviewed-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
---
Changes in v2:
- adf_dev_start(): propagate the error code returned by qat_algs_register()
and qat_asym_algs_register() instead of returning a blanket -EFAULT.
.../crypto/intel/qat/qat_common/adf_init.c | 24 ++++++++++++-----
.../crypto/intel/qat/qat_common/qat_algs.c | 15 ++++++-----
.../intel/qat/qat_common/qat_asym_algs.c | 26 ++++++++++++++-----
3 files changed, 45 insertions(+), 20 deletions(-)
diff --git a/drivers/crypto/intel/qat/qat_common/adf_init.c b/drivers/crypto/intel/qat/qat_common/adf_init.c
index 3e39c53814de..81cb5e6c9f4a 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_init.c
+++ b/drivers/crypto/intel/qat/qat_common/adf_init.c
@@ -260,13 +260,23 @@ static int adf_dev_start(struct adf_accel_dev *accel_dev)
clear_bit(ADF_STATUS_STARTING, &accel_dev->status);
set_bit(ADF_STATUS_STARTED, &accel_dev->status);
- if (!list_empty(&accel_dev->crypto_list) &&
- (qat_algs_register() || qat_asym_algs_register())) {
- dev_err(&GET_DEV(accel_dev),
- "Failed to register crypto algs\n");
- set_bit(ADF_STATUS_STARTING, &accel_dev->status);
- clear_bit(ADF_STATUS_STARTED, &accel_dev->status);
- return -EFAULT;
+ if (!list_empty(&accel_dev->crypto_list)) {
+ ret = qat_algs_register();
+ if (ret) {
+ dev_err(&GET_DEV(accel_dev), "Failed to register crypto algs\n");
+ set_bit(ADF_STATUS_STARTING, &accel_dev->status);
+ clear_bit(ADF_STATUS_STARTED, &accel_dev->status);
+ return ret;
+ }
+
+ ret = qat_asym_algs_register();
+ if (ret) {
+ dev_err(&GET_DEV(accel_dev), "Failed to register crypto asym algs\n");
+ qat_algs_unregister();
+ set_bit(ADF_STATUS_STARTING, &accel_dev->status);
+ clear_bit(ADF_STATUS_STARTED, &accel_dev->status);
+ return ret;
+ }
}
set_bit(ADF_STATUS_CRYPTO_ALGS_REGISTERED, &accel_dev->status);
diff --git a/drivers/crypto/intel/qat/qat_common/qat_algs.c b/drivers/crypto/intel/qat/qat_common/qat_algs.c
index 91663805d9e6..f954e7c0e4d0 100644
--- a/drivers/crypto/intel/qat/qat_common/qat_algs.c
+++ b/drivers/crypto/intel/qat/qat_common/qat_algs.c
@@ -1320,19 +1320,22 @@ int qat_algs_register(void)
ret = crypto_register_skciphers(qat_skciphers,
ARRAY_SIZE(qat_skciphers));
if (ret)
- goto unlock;
+ goto err_dec;
ret = crypto_register_aeads(qat_aeads, ARRAY_SIZE(qat_aeads));
if (ret)
- goto unreg_algs;
+ goto err_unreg_skciphers;
-unlock:
mutex_unlock(&algs_lock);
- return ret;
+ return 0;
-unreg_algs:
+err_unreg_skciphers:
crypto_unregister_skciphers(qat_skciphers, ARRAY_SIZE(qat_skciphers));
- goto unlock;
+err_dec:
+ active_devs--;
+unlock:
+ mutex_unlock(&algs_lock);
+ return ret;
}
void qat_algs_unregister(void)
diff --git a/drivers/crypto/intel/qat/qat_common/qat_asym_algs.c b/drivers/crypto/intel/qat/qat_common/qat_asym_algs.c
index 1049c583f84f..77d59e977472 100644
--- a/drivers/crypto/intel/qat/qat_common/qat_asym_algs.c
+++ b/drivers/crypto/intel/qat/qat_common/qat_asym_algs.c
@@ -1340,13 +1340,25 @@ int qat_asym_algs_register(void)
int ret = 0;
mutex_lock(&algs_lock);
- if (++active_devs == 1) {
- rsa.base.cra_flags = 0;
- ret = crypto_register_akcipher(&rsa);
- if (ret)
- goto unlock;
- ret = crypto_register_kpp(&dh);
- }
+ if (++active_devs != 1)
+ goto unlock;
+
+ rsa.base.cra_flags = 0;
+ ret = crypto_register_akcipher(&rsa);
+ if (ret)
+ goto err_dec;
+
+ ret = crypto_register_kpp(&dh);
+ if (ret)
+ goto err_unreg_akcipher;
+
+ mutex_unlock(&algs_lock);
+ return 0;
+
+err_unreg_akcipher:
+ crypto_unregister_akcipher(&rsa);
+err_dec:
+ active_devs--;
unlock:
mutex_unlock(&algs_lock);
return ret;
--
2.50.1
next reply other threads:[~2026-09-08 12:09 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 12:10 Ahsan Atta [this message]
2026-09-08 16:09 ` [PATCH v2] crypto: qat - fix active_devs leak on crypto alg registration failure Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908121013.697443-1-ahsan.atta@intel.com \
--to=ahsan.atta@intel.com \
--cc=giovanni.cabiddu@intel.com \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=qat-linux@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.