From: Lukas Wunner <lukas@wunner.de>
To: Changwei Zou <changwei.zou@canonical.com>,
Martin Kepplinger-Novakovic
<Martin.Kepplinger-Novakovic@ginzinger.com>,
Martin Kepplinger-Novakovic <martink@posteo.de>
Cc: herbert@gondor.apana.org.au, ignat@linux.win,
davem@davemloft.net, linux-crypto@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN
Date: Tue, 28 Jul 2026 08:16:58 +0200 [thread overview]
Message-ID: <amhJWs2AdPgFzw8t@wunner.de> (raw)
In-Reply-To: <20260727224300.150132-1-changwei.zou@canonical.com>
[cc += Martin Kepplinger-NovakoviÄ]
On Tue, Jul 28, 2026 at 08:43:00AM +1000, Changwei Zou wrote:
> out_buf is used as a DMA buffer for the RSA verification operation.
> If out_buf is not aligned to ARCH_DMA_MINALIGN, cacheline sharing
> problems (data corruption) would occur on CPUs with DMA-incoherent caches,
> leading to -EKEYREJECTED.
>
> Fix by aligning out_buf to ARCH_DMA_MINALIGN using PTR_ALIGN(), and
> allocating ARCH_DMA_MINALIGN extra bytes in the child_req allocation
> to accommodate the alignment padding.
>
> The intermittent error 'Key was rejected by service' on i.MX8 with CAAM
> can be triggered when loading signed kernel modules.
>
> for i in $(seq 1 100); do
> sudo modprobe xfs 2>&1 && echo "SUCCESS on attempt $i" \
> && sudo rmmod xfs || echo "FAILED on attempt $i"
> done
>
> Fixes: 8552cb04e083 ("crypto: rsassa-pkcs1 - Copy source data for SG list")
> Signed-off-by: Changwei Zou <changwei.zou@canonical.com>
@Martin Kepplinger-NovakoviÄ: Could you test whether this fixes
the issue you reported in February?
If it does:
Reported-by: Martin Kepplinger-NovakoviÄ <Martin.Kepplinger-Novakovic@ginzinger.com>
Closes: https://lore.kernel.org/r/6029acc0f0ddfe25e2537c2866d54fd7f54bc182.camel@ginzinger.com
@Changwei Zou: Just to double-check, I assume this supersedes the
following patch, right?
https://lore.kernel.org/r/20260723150107.33546-1-changwei.zou@canonical.com
> +++ b/crypto/rsassa-pkcs1.c
> @@ -237,12 +239,13 @@ static int rsassa_pkcs1_verify(struct crypto_sig *tfm,
> return -EINVAL;
>
> /* RFC 8017 sec 8.2.2 step 2 - RSA verification */
> - child_req = kmalloc(sizeof(*child_req) + child_reqsize + ctx->key_size,
> - GFP_KERNEL);
> + child_req = kmalloc(sizeof(*child_req) + child_reqsize +
> + ctx->key_size + ARCH_DMA_MINALIGN, GFP_KERNEL);
> if (!child_req)
> return -ENOMEM;
>
> - out_buf = (u8 *)(child_req + 1) + child_reqsize;
> + out_buf = PTR_ALIGN((u8 *)(child_req + 1) + child_reqsize,
> + ARCH_DMA_MINALIGN);
> memcpy(out_buf, src, slen);
We've got CRYPTO_DMA_ALIGN, CRYPTO_MINALIGN, CRYPTO_DMA_PADDING macros,
I think those would be more appropriate.
A few nits:
There's a duplicate blank in the "out_buf =" assignment and
the line-wrapped function arguments aren't aligned to the opening brace.
> @@ -7,6 +7,8 @@
> * Copyright (c) 2015 - 2024 Intel Corporation
> */
>
> +#include <linux/align.h>
> +#include <linux/cache.h>
> #include <linux/module.h>
> #include <linux/scatterlist.h>
> #include <crypto/akcipher.h>
I think you won't be needing those #includes if you use the CRYPTO_*
alignment macros.
Thanks,
Lukas
next prev parent reply other threads:[~2026-07-28 6:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 22:43 [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN Changwei Zou
2026-07-28 6:16 ` Lukas Wunner [this message]
2026-07-28 6:23 ` Lukas Wunner
2026-07-28 9:19 ` Changwei Zou
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amhJWs2AdPgFzw8t@wunner.de \
--to=lukas@wunner.de \
--cc=Martin.Kepplinger-Novakovic@ginzinger.com \
--cc=changwei.zou@canonical.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=ignat@linux.win \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=martink@posteo.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox