From: T Pratham <t-pratham@ti.com>
To: T Pratham <t-pratham@ti.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>
Cc: Sebin Francis <sebin.francis@ti.com>,
Manorit Chawdhry <m-chawdhry@ti.com>,
Vishal Mahaveer <vishalm@ti.com>,
Praneeth Bajjuri <praneeth@ti.com>,
<linux-crypto@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Subject: [PATCH v5 13/15] crypto: ti - Correct AEAD tag operations against dma cache invalidation
Date: Fri, 18 Sep 2026 15:52:43 +0530 [thread overview]
Message-ID: <20260918102245.2784000-14-t-pratham@ti.com> (raw)
In-Reply-To: <20260918102245.2784000-1-t-pratham@ti.com>
There are two issues wrt tag operations (tag read/write in AEAD
algorithms) pointed out by Sashiko:
1. dma_sync_sg_for_cpu() before tag operations always uses rx_dev. But
dst is mapped with tx_dev in case of inline operations. This is
"technically" a no-issue right now as both devices use different
channels from the same dma device. But it is nice to be correct.
2. dma_unmap_sg() is being called after tag operations. But between
them, there is no synchronisation step. So tag operations writing TAG
into the dst scatterlist could in theory be lost in the cache
invalidation done as part of unmapping scatterlists.
Now, in the current code, we can correct both of these with some
conditional logic and repeating the sync (this time with
sync_for_device). However, it felt more elegant to move the TAG
operations to occur after all the scatterlists are unmapped. This
ensures all buffers are properly synced as well as avoids unnecessary
repeated syncing of caches.
Fixes: 37b902c603042 ("crypto: ti - Add support for AES-GCM in DTHEv2 driver")
Signed-off-by: T Pratham <t-pratham@ti.com>
---
drivers/crypto/ti/dthev2-aes.c | 25 ++++++++++++++++---------
1 file changed, 16 insertions(+), 9 deletions(-)
diff --git a/drivers/crypto/ti/dthev2-aes.c b/drivers/crypto/ti/dthev2-aes.c
index 150ce65f613fa..150ba73776aa9 100644
--- a/drivers/crypto/ti/dthev2-aes.c
+++ b/drivers/crypto/ti/dthev2-aes.c
@@ -913,6 +913,7 @@ static int dthe_aead_run(struct crypto_engine *engine, void *areq)
struct device *tx_dev, *rx_dev;
struct dma_async_tx_descriptor *desc_in, *desc_out, *desc_aad_out;
bool cleanup_tx_chan = false;
+ bool do_tag_ops = false;
int ret;
int err;
@@ -1136,15 +1137,11 @@ static int dthe_aead_run(struct crypto_engine *engine, void *areq)
ret = 0;
}
- if (cryptlen != 0)
- dma_sync_sg_for_cpu(rx_dev, dst, dst_nents, dst_dir);
-
- if (rctx->enc)
- err = dthe_aead_enc_get_tag(req);
- else
- err = dthe_aead_dec_verify_tag(req);
-
- ret = (ret) ? ret : err;
+ /*
+ * Need to read TAG registers if data is submitted, even in case
+ * of DMA timeout, to clear the hardware states
+ */
+ do_tag_ops = true;
aead_dma_prep_dst_err:
if (diff_dst && cryptlen != 0)
@@ -1160,6 +1157,16 @@ static int dthe_aead_run(struct crypto_engine *engine, void *areq)
if (assoclen != 0)
dma_unmap_sg(tx_dev, aad_sg, aad_nents, aad_dir);
+ /* Do tag ops after scatterlist unmapping syncs caches */
+ if (do_tag_ops) {
+ if (rctx->enc)
+ err = dthe_aead_enc_get_tag(req);
+ else
+ err = dthe_aead_dec_verify_tag(req);
+
+ ret = (ret) ? ret : err;
+ }
+
aead_dma_map_aad_err:
if (diff_dst && cryptlen != 0)
kfree(dst);
--
2.34.1
next prev parent reply other threads:[~2026-09-18 10:24 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 10:22 [PATCH v5 00/15] Fix several issues in DTHEv2 driver T Pratham
2026-09-18 10:22 ` [PATCH v5 01/15] crypto: ti - Use list_first_entry_or_null() in dthe_get_dev() T Pratham
2026-09-18 10:22 ` [PATCH v5 02/15] crypto: ti - Fix spinlock inconsistency in DTHEv2 T Pratham
2026-09-18 10:22 ` [PATCH v5 03/15] crypto: ti - Fix potential memory corruption on highmem pages T Pratham
2026-09-18 10:22 ` [PATCH v5 04/15] crypto: ti - Fix use-after-free of dev_data on DTHEv2 driver removal T Pratham
2026-09-23 5:51 ` Herbert Xu
2026-09-24 15:39 ` T Pratham
2026-09-28 5:20 ` Herbert Xu
2026-09-18 10:22 ` [PATCH v5 05/15] crypto: ti - Trim scatterlists to correct length in AES T Pratham
2026-09-18 10:22 ` [PATCH v5 06/15] crypto: ti - Align buffers to cacheline for DMA T Pratham
2026-09-18 10:22 ` [PATCH v5 07/15] crypto: ti - Separate padding buffer for src and dst T Pratham
2026-09-18 10:22 ` [PATCH v5 08/15] crypto: ti - Validate sg_nents_for_len() return value in DTHEv2 AES T Pratham
2026-09-18 10:22 ` [PATCH v5 09/15] crypto: ti - Validate sg_nents_for_len() return value in DTHEv2 AEAD T Pratham
2026-09-18 10:22 ` [PATCH v5 10/15] crypto: ti - Terminate DMA on all error paths in AES to clear descriptors T Pratham
2026-09-18 10:22 ` [PATCH v5 11/15] crypto: ti - Terminate DMA on all error paths in AEAD " T Pratham
2026-09-18 10:22 ` [PATCH v5 12/15] crypto: ti - Do AEAD software fallback on only ENOMEM T Pratham
2026-09-18 10:22 ` T Pratham [this message]
2026-09-18 10:22 ` [PATCH v5 14/15] crypto: ti - Change lengths in AES to u64 to avoid potential overflows T Pratham
2026-09-18 10:22 ` [PATCH v5 15/15] crypto: ti - Change lengths in AEAD " T Pratham
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918102245.2784000-14-t-pratham@ti.com \
--to=t-pratham@ti.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=m-chawdhry@ti.com \
--cc=praneeth@ti.com \
--cc=sebin.francis@ti.com \
--cc=vishalm@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox