All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN
@ 2026-07-27 22:43 Changwei Zou
  2026-07-28  6:16 ` Lukas Wunner
  0 siblings, 1 reply; 4+ messages in thread
From: Changwei Zou @ 2026-07-27 22:43 UTC (permalink / raw)
  To: herbert, lukas, ignat; +Cc: changwei.zou, davem, linux-crypto, linux-kernel

out_buf is used as a DMA buffer for the RSA verification operation.
If out_buf is not aligned to ARCH_DMA_MINALIGN, cacheline sharing
problems (data corruption) would occur on CPUs with DMA-incoherent caches,
leading to -EKEYREJECTED.

Fix by aligning out_buf to ARCH_DMA_MINALIGN using PTR_ALIGN(), and
allocating ARCH_DMA_MINALIGN extra bytes in the child_req allocation
to accommodate the alignment padding.

The intermittent error 'Key was rejected by service' on i.MX8 with CAAM
can be triggered when loading signed kernel modules.

    for i in $(seq 1 100); do
        sudo modprobe xfs 2>&1 && echo "SUCCESS on attempt $i" \
        && sudo rmmod xfs || echo "FAILED on attempt $i"
    done

Fixes: 8552cb04e083 ("crypto: rsassa-pkcs1 - Copy source data for SG list")
Signed-off-by: Changwei Zou <changwei.zou@canonical.com>
---
 crypto/rsassa-pkcs1.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/crypto/rsassa-pkcs1.c b/crypto/rsassa-pkcs1.c
index 94fa5e9600e7..a8d90959c871 100644
--- a/crypto/rsassa-pkcs1.c
+++ b/crypto/rsassa-pkcs1.c
@@ -7,6 +7,8 @@
  * Copyright (c) 2015 - 2024 Intel Corporation
  */
 
+#include <linux/align.h>
+#include <linux/cache.h>
 #include <linux/module.h>
 #include <linux/scatterlist.h>
 #include <crypto/akcipher.h>
@@ -237,12 +239,13 @@ static int rsassa_pkcs1_verify(struct crypto_sig *tfm,
 		return -EINVAL;
 
 	/* RFC 8017 sec 8.2.2 step 2 - RSA verification */
-	child_req = kmalloc(sizeof(*child_req) + child_reqsize + ctx->key_size,
-			    GFP_KERNEL);
+	child_req = kmalloc(sizeof(*child_req) + child_reqsize +
+				    ctx->key_size + ARCH_DMA_MINALIGN, GFP_KERNEL);
 	if (!child_req)
 		return -ENOMEM;
 
-	out_buf = (u8 *)(child_req + 1) + child_reqsize;
+	out_buf  = PTR_ALIGN((u8 *)(child_req + 1) + child_reqsize,
+				    ARCH_DMA_MINALIGN);
 	memcpy(out_buf, src, slen);
 
 	crypto_init_wait(&cwait);
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-28  9:19 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 22:43 [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN Changwei Zou
2026-07-28  6:16 ` Lukas Wunner
2026-07-28  6:23   ` Lukas Wunner
2026-07-28  9:19   ` Changwei Zou

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.