From: Ahsan Atta <ahsan.atta@intel.com>
To: herbert@gondor.apana.org.au
Cc: linux-crypto@vger.kernel.org, qat-linux@intel.com,
Ahsan Atta <ahsan.atta@intel.com>,
Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Subject: [PATCH 1/2] crypto: qat - hold cfg->lock when accessing config sections
Date: Fri, 18 Sep 2026 13:41:11 +0100 [thread overview]
Message-ID: <20260918124112.537571-2-ahsan.atta@intel.com> (raw)
In-Reply-To: <20260918124112.537571-1-ahsan.atta@intel.com>
adf_cfg_sec_find() walks the per-device section list without holding
cfg->lock, and the returned section pointer is used later under the
lock. A concurrent section deletion under cfg->lock
(adf_cfg_del_all_except() on device down, or adf_cfg_dev_remove() on
removal) can free the section first, leading to a use-after-free.
The debugfs dev_cfg reader has the same problem: qat_dev_cfg_show()
walks both the section list and each section's param_head under the
global qat_cfg_read_lock mutex, not the per-device cfg->lock used by the
add and delete paths, so the two do not serialise. Updating an existing
key frees the old key_val under cfg->lock, so even a config write
concurrent with an open dev_cfg read can free an entry mid-walk, a wider
window than section deletion alone.
Take cfg->lock around the section lookup in adf_cfg_add_key_value_param()
and around the lookup and insert in adf_cfg_section_add(), and use
down_read()/up_read(&cfg->lock) in the debugfs start/stop callbacks.
Remove the now-unused qat_cfg_read_lock.
While here, return -ENOENT rather than -EFAULT when the section is not
found; EFAULT (bad userspace address) is not meaningful for this case.
Fixes: d8cba25d2c68 ("crypto: qat - Intel(R) QAT driver framework")
Signed-off-by: Ahsan Atta <ahsan.atta@intel.com>
Reviewed-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
---
drivers/crypto/intel/qat/qat_common/adf_cfg.c | 49 +++++++++++--------
1 file changed, 29 insertions(+), 20 deletions(-)
diff --git a/drivers/crypto/intel/qat/qat_common/adf_cfg.c b/drivers/crypto/intel/qat/qat_common/adf_cfg.c
index b88febf53a19..e13db9ede0fa 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_cfg.c
+++ b/drivers/crypto/intel/qat/qat_common/adf_cfg.c
@@ -1,6 +1,5 @@
// SPDX-License-Identifier: (BSD-3-Clause OR GPL-2.0-only)
/* Copyright(c) 2014 - 2020 Intel Corporation */
-#include <linux/mutex.h>
#include <linux/slab.h>
#include <linux/string.h>
#include <linux/list.h>
@@ -9,13 +8,11 @@
#include "adf_cfg.h"
#include "adf_common_drv.h"
-static DEFINE_MUTEX(qat_cfg_read_lock);
-
static void *qat_dev_cfg_start(struct seq_file *sfile, loff_t *pos)
{
struct adf_cfg_device_data *dev_cfg = sfile->private;
- mutex_lock(&qat_cfg_read_lock);
+ down_read(&dev_cfg->lock);
return seq_list_start(&dev_cfg->sec_list, *pos);
}
@@ -43,7 +40,9 @@ static void *qat_dev_cfg_next(struct seq_file *sfile, void *v, loff_t *pos)
static void qat_dev_cfg_stop(struct seq_file *sfile, void *v)
{
- mutex_unlock(&qat_cfg_read_lock);
+ struct adf_cfg_device_data *dev_cfg = sfile->private;
+
+ up_read(&dev_cfg->lock);
}
static const struct seq_operations qat_dev_cfg_sops = {
@@ -272,13 +271,10 @@ int adf_cfg_add_key_value_param(struct adf_accel_dev *accel_dev,
enum adf_cfg_val_type type)
{
struct adf_cfg_device_data *cfg = accel_dev->cfg;
+ struct adf_cfg_section *section;
struct adf_cfg_key_val *key_val;
- struct adf_cfg_section *section = adf_cfg_sec_find(accel_dev,
- section_name);
char temp_val[ADF_CFG_MAX_VAL_LEN_IN_BYTES];
-
- if (!section)
- return -EFAULT;
+ int ret = 0;
key_val = kzalloc_obj(*key_val);
if (!key_val)
@@ -308,20 +304,28 @@ int adf_cfg_add_key_value_param(struct adf_accel_dev *accel_dev,
* anything (the newly created key_val is freed).
*/
down_write(&cfg->lock);
+
+ section = adf_cfg_sec_find(accel_dev, section_name);
+ if (!section) {
+ kfree(key_val);
+ ret = -ENOENT;
+ goto unlock;
+ }
+
if (!adf_cfg_key_val_get(accel_dev, section_name, key, temp_val)) {
if (strncmp(temp_val, key_val->val, sizeof(temp_val))) {
adf_cfg_keyval_remove(key, section);
} else {
kfree(key_val);
- goto out;
+ goto unlock;
}
}
adf_cfg_keyval_add(key_val, section);
-out:
+unlock:
up_write(&cfg->lock);
- return 0;
+ return ret;
}
EXPORT_SYMBOL_GPL(adf_cfg_add_key_value_param);
@@ -339,21 +343,26 @@ EXPORT_SYMBOL_GPL(adf_cfg_add_key_value_param);
int adf_cfg_section_add(struct adf_accel_dev *accel_dev, const char *name)
{
struct adf_cfg_device_data *cfg = accel_dev->cfg;
- struct adf_cfg_section *sec = adf_cfg_sec_find(accel_dev, name);
+ struct adf_cfg_section *sec;
+ int ret = 0;
- if (sec)
- return 0;
+ down_write(&cfg->lock);
+
+ if (adf_cfg_sec_find(accel_dev, name))
+ goto unlock;
sec = kzalloc_obj(*sec);
- if (!sec)
- return -ENOMEM;
+ if (!sec) {
+ ret = -ENOMEM;
+ goto unlock;
+ }
strscpy(sec->name, name);
INIT_LIST_HEAD(&sec->param_head);
- down_write(&cfg->lock);
list_add_tail(&sec->list, &cfg->sec_list);
+unlock:
up_write(&cfg->lock);
- return 0;
+ return ret;
}
EXPORT_SYMBOL_GPL(adf_cfg_section_add);
--
2.50.1
next prev parent reply other threads:[~2026-09-18 12:40 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 12:41 [PATCH 0/2] crypto: qat - fix config table locking Ahsan Atta
2026-09-18 12:41 ` Ahsan Atta [this message]
2026-09-18 12:41 ` [PATCH 2/2] crypto: qat - avoid redundant config list walks when adding a key Ahsan Atta
2026-09-23 8:51 ` [PATCH 0/2] crypto: qat - fix config table locking Herbert Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918124112.537571-2-ahsan.atta@intel.com \
--to=ahsan.atta@intel.com \
--cc=giovanni.cabiddu@intel.com \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=qat-linux@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox