Linux cryptographic layer development
 help / color / mirror / Atom feed
* [PATCH 00/30] Clean and improve SA2UL driver
@ 2026-09-15  9:55 Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 01/30] crypto: sa2ul - remove dead code Manorit Chawdhry
                   ` (30 more replies)
  0 siblings, 31 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The following series focuses on some cleanups to the sa2ul driver, it
starts with very trivial cleanups then goes to fix some bigger cleanups
and migration to crypto_engine which help fix the broader race condition
problems with the driver, thereafter it adds the support for AES CM as
per SAxUL 3.1 IP. KASAN is also run alongside to fix the issues caught
by them.

Self test results across K3 family: 
https://gist.github.com/manorit2001/544587ec3535125663e3ca9dbc186e96

Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
Manorit Chawdhry (30):
      crypto: sa2ul - remove dead code
      crypto: sa2ul - remove totally unused structure fields
      crypto: sa2ul - remove unused algorithm ID fields
      crypto: sa2ul - remove unused fields from sa_cmdl_cfg
      crypto: sa2ul - remove unused fields from sa_tfm_ctx
      crypto: sa2ul - remove unused macro definitions
      crypto: sa2ul - consolidate encryption offset definitions
      crypto: sa2ul - remove unused SC ID range tracking
      crypto: sa2ul - remove unused base register pointer
      crypto: sa2ul - remove unused includes and defines
      crypto: sa2ul - remove unused line
      crypto: sa2ul - remove redundant sa_sha_digest() wrapper
      crypto: sa2ul - fix struct documentation for match_data
      crypto: sa2ul - zero out security context on free
      crypto: sa2ul - fix context release on errors
      crypto: sa2ul - fix resource leak of sha in init_alg() error path
      crypto: sa2ul - fix resource leak of AEAD in init_alg() error path
      crypto: sa2ul - fix DMA mapping leak in sa_run() error paths
      crypto: sa2ul - generate dynamic metadata length
      crypto: sa2ul - fix command label stack corruption
      crypto: sa2ul - fix error handling in sa_prepare_iopad
      crypto: sa2ul - move export to appropriate location.
      crypto: sa2ul - fix stack overflow in sa_prepare_iopads
      crypto: sa2ul - add more checks before processing ipad/opad
      crypto: sa2ul - fix data corruption by skipping device sync on unmap
      crypto: sa2ul - use correct DMA direction in sa_sync_from_device
      crypto: sa2ul - change dma_alloc_pool to mempool
      crypto: sa2ul - route requests through crypto_engine
      crypto: sa2ul - report SA engine hardware revision
      crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support

 drivers/crypto/Kconfig |    1 +
 drivers/crypto/sa2ul.c | 1042 +++++++++++++++++++++++++++++-------------------
 drivers/crypto/sa2ul.h |  162 ++------
 3 files changed, 661 insertions(+), 544 deletions(-)
---
base-commit: a9d7ced84989ec05be09b4b8428759ef60450a0f
change-id: 20251106-b4-upstream-sa2ul-cleanup-ce85d40c7eb8

Best regards,
--  
Manorit Chawdhry <m-chawdhry@ti.com>


^ permalink raw reply	[flat|nested] 34+ messages in thread

* [PATCH 01/30] crypto: sa2ul - remove dead code
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 02/30] crypto: sa2ul - remove totally unused structure fields Manorit Chawdhry
                   ` (29 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The following codepath is not used at all as SA_CMDL_UPD_AUTH_IV and
SA_CMDL_UPD_AUX_KEY are never set. Remove it.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 24 ------------------------
 1 file changed, 24 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 0dce2b98886a..f7e4f58c02c2 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -41,8 +41,6 @@
 #define SA_CMDL_UPD_ENC         0x0001
 #define SA_CMDL_UPD_AUTH        0x0002
 #define SA_CMDL_UPD_ENC_IV      0x0004
-#define SA_CMDL_UPD_AUTH_IV     0x0008
-#define SA_CMDL_UPD_AUX_KEY     0x0010
 
 #define SA_AUTH_SUBKEY_LEN	16
 #define SA_CMDL_PAYLOAD_LENGTH_MASK	0xFFFF
@@ -551,17 +549,6 @@ static void sa_set_sc_auth(struct algo_data *ad, const u8 *key, u16 key_sz,
 	}
 }
 
-static inline void sa_copy_iv(__be32 *out, const u8 *iv, bool size16)
-{
-	int j;
-
-	for (j = 0; j < ((size16) ? 4 : 2); j++) {
-		*out = cpu_to_be32(*((u32 *)iv));
-		iv += 4;
-		out++;
-	}
-}
-
 /* Format general command label */
 static int sa_format_cmdl_gen(struct sa_cmdl_cfg *cfg, u8 *cmdl,
 			      struct sa_cmdl_upd_info *upd_info)
@@ -670,17 +657,6 @@ static inline void sa_update_cmdl(struct sa_req *req, u32 *cmdl,
 		cmdl[upd_info->auth_offset.index] |=
 			FIELD_PREP(SA_CMDL_SOP_BYPASS_LEN_MASK,
 				   req->auth_offset);
-		if (upd_info->flags & SA_CMDL_UPD_AUTH_IV) {
-			sa_copy_iv((void *)&cmdl[upd_info->auth_iv.index],
-				   req->auth_iv,
-				   (upd_info->auth_iv.size > 8));
-		}
-		if (upd_info->flags & SA_CMDL_UPD_AUX_KEY) {
-			int offset = (req->auth_size & 0xF) ? 4 : 0;
-
-			memcpy(&cmdl[upd_info->aux_key_info.index],
-			       &upd_info->aux_key[offset], 16);
-		}
 	}
 }
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 02/30] crypto: sa2ul - remove totally unused structure fields
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 01/30] crypto: sa2ul - remove dead code Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 03/30] crypto: sa2ul - remove unused algorithm ID fields Manorit Chawdhry
                   ` (28 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The following have never been used in code. Remove them.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.h | 44 --------------------------------------------
 1 file changed, 44 deletions(-)

diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 12c17a68d350..847d6586c036 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -230,35 +230,19 @@ struct sa_cmdl_param_info {
  * @flags: flags in command label
  * @submode: Encryption submodes
  * @enc_size: Size of first pass encryption size
- * @enc_size2: Size of second pass encryption size
  * @enc_offset: Encryption payload offset in the packet
  * @enc_iv: Encryption initialization vector for pass2
- * @enc_iv2: Encryption initialization vector for pass2
- * @aad: Associated data
- * @payload: Payload info
  * @auth_size: Authentication size for pass 1
- * @auth_size2: Authentication size for pass 2
  * @auth_offset: Authentication payload offset
- * @auth_iv: Authentication initialization vector
- * @aux_key_info: Authentication aux key information
- * @aux_key: Aux key for authentication
  */
 struct sa_cmdl_upd_info {
 	u16	flags;
 	u16	submode;
 	struct sa_cmdl_param_info	enc_size;
-	struct sa_cmdl_param_info	enc_size2;
 	struct sa_cmdl_param_info	enc_offset;
 	struct sa_cmdl_param_info	enc_iv;
-	struct sa_cmdl_param_info	enc_iv2;
-	struct sa_cmdl_param_info	aad;
-	struct sa_cmdl_param_info	payload;
 	struct sa_cmdl_param_info	auth_size;
-	struct sa_cmdl_param_info	auth_size2;
 	struct sa_cmdl_param_info	auth_offset;
-	struct sa_cmdl_param_info	auth_iv;
-	struct sa_cmdl_param_info	aux_key_info;
-	u32				aux_key[SA_MAX_AUX_DATA_WORDS];
 };
 
 /*
@@ -307,7 +291,6 @@ struct sa_tfm_ctx {
 	struct sa_crypto_data *dev_data;
 	struct sa_ctx_info enc;
 	struct sa_ctx_info dec;
-	struct sa_ctx_info auth;
 	int keylen;
 	int iv_idx;
 	u32 key[AES_KEYSIZE_256 / sizeof(u32)];
@@ -333,13 +316,6 @@ struct sa_sha_req_ctx {
 	struct ahash_request	fallback_req;
 };
 
-enum sa_submode {
-	SA_MODE_GEN = 0,
-	SA_MODE_CCM,
-	SA_MODE_GCM,
-	SA_MODE_GMAC
-};
-
 /* Encryption algorithms */
 enum sa_ealg_id {
 	SA_EALG_ID_NONE = 0,        /* No encryption */
@@ -374,26 +350,6 @@ enum sa_aalg_id {
 	SA_AALG_ID_AES_XCBC       /* AES Extended Cipher Block Chaining */
 };
 
-/*
- * Mode control engine algorithms used to index the
- * mode control instruction tables
- */
-enum sa_eng_algo_id {
-	SA_ENG_ALGO_ECB = 0,
-	SA_ENG_ALGO_CBC,
-	SA_ENG_ALGO_CFB,
-	SA_ENG_ALGO_OFB,
-	SA_ENG_ALGO_CTR,
-	SA_ENG_ALGO_F8,
-	SA_ENG_ALGO_F8F9,
-	SA_ENG_ALGO_GCM,
-	SA_ENG_ALGO_GMAC,
-	SA_ENG_ALGO_CCM,
-	SA_ENG_ALGO_CMAC,
-	SA_ENG_ALGO_CBCMAC,
-	SA_NUM_ENG_ALGOS
-};
-
 /**
  * struct sa_eng_info: Security accelerator engine info
  * @eng_id: Engine ID

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 03/30] crypto: sa2ul - remove unused algorithm ID fields
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 01/30] crypto: sa2ul - remove dead code Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 02/30] crypto: sa2ul - remove totally unused structure fields Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 04/30] crypto: sa2ul - remove unused fields from sa_cmdl_cfg Manorit Chawdhry
                   ` (27 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

These algorithm ID fields were never referenced. Remove them.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 19 -------------------
 drivers/crypto/sa2ul.h | 34 ----------------------------------
 2 files changed, 53 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index f7e4f58c02c2..3297a25d9d9d 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -92,7 +92,6 @@ static struct device *sa_k3_dev;
 
 /**
  * struct sa_cmdl_cfg - Command label configuration descriptor
- * @aalg: authentication algorithm ID
  * @enc_eng_id: Encryption Engine ID supported by the SA hardware
  * @auth_eng_id: Authentication Engine ID
  * @iv_size: Initialization Vector size
@@ -101,7 +100,6 @@ static struct device *sa_k3_dev;
  * @enc: True, if this is an encode request
  */
 struct sa_cmdl_cfg {
-	int aalg;
 	u8 enc_eng_id;
 	u8 auth_eng_id;
 	u8 iv_size;
@@ -118,8 +116,6 @@ struct sa_cmdl_cfg {
  * @hash_size: Size of digest
  * @iv_idx: iv index in psdata
  * @iv_out_size: iv out size
- * @ealg_id: Encryption Algorithm ID
- * @aalg_id: Authentication algorithm ID
  * @mci_enc: Mode Control Instruction for Encryption algorithm
  * @mci_dec: Mode Control Instruction for Decryption
  * @inv_key: Whether the encryption algorithm demands key inversion
@@ -134,8 +130,6 @@ struct algo_data {
 	u8 hash_size;
 	u8 iv_idx;
 	u8 iv_out_size;
-	u8 ealg_id;
-	u8 aalg_id;
 	u8 *mci_enc;
 	u8 *mci_dec;
 	bool inv_key;
@@ -934,7 +928,6 @@ static int sa_aes_cbc_setkey(struct crypto_skcipher *tfm, const u8 *key,
 	ad.mci_enc = mci_cbc_enc_array[key_idx];
 	ad.mci_dec = mci_cbc_dec_array[key_idx];
 	ad.inv_key = true;
-	ad.ealg_id = SA_EALG_ID_AES_CBC;
 	ad.iv_idx = 4;
 	ad.iv_out_size = 16;
 
@@ -954,7 +947,6 @@ static int sa_aes_ecb_setkey(struct crypto_skcipher *tfm, const u8 *key,
 	ad.mci_enc = mci_ecb_enc_array[key_idx];
 	ad.mci_dec = mci_ecb_dec_array[key_idx];
 	ad.inv_key = true;
-	ad.ealg_id = SA_EALG_ID_AES_ECB;
 
 	return sa_cipher_setkey(tfm, key, keylen, &ad);
 }
@@ -966,7 +958,6 @@ static int sa_3des_cbc_setkey(struct crypto_skcipher *tfm, const u8 *key,
 
 	ad.mci_enc = mci_cbc_3des_enc_array;
 	ad.mci_dec = mci_cbc_3des_dec_array;
-	ad.ealg_id = SA_EALG_ID_3DES_CBC;
 	ad.iv_idx = 6;
 	ad.iv_out_size = 8;
 
@@ -1429,7 +1420,6 @@ static int sa_sha_setup(struct sa_tfm_ctx *ctx, struct  algo_data *ad)
 
 	memset(ctx->authkey, 0, bs);
 	memset(&cfg, 0, sizeof(cfg));
-	cfg.aalg = ad->aalg_id;
 	cfg.enc_eng_id = ad->enc_eng.eng_id;
 	cfg.auth_eng_id = ad->auth_eng.eng_id;
 	cfg.iv_size = 0;
@@ -1577,7 +1567,6 @@ static int sa_sha1_cra_init(struct crypto_tfm *tfm)
 
 	sa_sha_cra_init_alg(tfm, "sha1");
 
-	ad.aalg_id = SA_AALG_ID_SHA1;
 	ad.hash_size = SHA1_DIGEST_SIZE;
 	ad.auth_ctrl = SA_AUTH_SW_CTRL_SHA1;
 
@@ -1593,7 +1582,6 @@ static int sa_sha256_cra_init(struct crypto_tfm *tfm)
 
 	sa_sha_cra_init_alg(tfm, "sha256");
 
-	ad.aalg_id = SA_AALG_ID_SHA2_256;
 	ad.hash_size = SHA256_DIGEST_SIZE;
 	ad.auth_ctrl = SA_AUTH_SW_CTRL_SHA256;
 
@@ -1609,7 +1597,6 @@ static int sa_sha512_cra_init(struct crypto_tfm *tfm)
 
 	sa_sha_cra_init_alg(tfm, "sha512");
 
-	ad.aalg_id = SA_AALG_ID_SHA2_512;
 	ad.hash_size = SHA512_DIGEST_SIZE;
 	ad.auth_ctrl = SA_AUTH_SW_CTRL_SHA512;
 
@@ -1770,12 +1757,10 @@ static int sa_aead_setkey(struct crypto_aead *authenc,
 	ad->mci_dec = mci_cbc_dec_no_iv_array[key_idx];
 	ad->inv_key = true;
 	ad->keyed_mac = true;
-	ad->ealg_id = SA_EALG_ID_AES_CBC;
 	ad->prep_iopad = sa_prepare_iopads;
 
 	memset(&cfg, 0, sizeof(cfg));
 	cfg.enc = true;
-	cfg.aalg = ad->aalg_id;
 	cfg.enc_eng_id = ad->enc_eng.eng_id;
 	cfg.auth_eng_id = ad->auth_eng.eng_id;
 	cfg.iv_size = crypto_aead_ivsize(authenc);
@@ -1831,8 +1816,6 @@ static int sa_aead_cbc_sha1_setkey(struct crypto_aead *authenc,
 {
 	struct algo_data ad = { 0 };
 
-	ad.ealg_id = SA_EALG_ID_AES_CBC;
-	ad.aalg_id = SA_AALG_ID_HMAC_SHA1;
 	ad.hash_size = SHA1_DIGEST_SIZE;
 	ad.auth_ctrl = SA_AUTH_SW_CTRL_SHA1;
 
@@ -1844,8 +1827,6 @@ static int sa_aead_cbc_sha256_setkey(struct crypto_aead *authenc,
 {
 	struct algo_data ad = { 0 };
 
-	ad.ealg_id = SA_EALG_ID_AES_CBC;
-	ad.aalg_id = SA_AALG_ID_HMAC_SHA2_256;
 	ad.hash_size = SHA256_DIGEST_SIZE;
 	ad.auth_ctrl = SA_AUTH_SW_CTRL_SHA256;
 
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 847d6586c036..097a496067e1 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -316,40 +316,6 @@ struct sa_sha_req_ctx {
 	struct ahash_request	fallback_req;
 };
 
-/* Encryption algorithms */
-enum sa_ealg_id {
-	SA_EALG_ID_NONE = 0,        /* No encryption */
-	SA_EALG_ID_NULL,            /* NULL encryption */
-	SA_EALG_ID_AES_CTR,         /* AES Counter mode */
-	SA_EALG_ID_AES_F8,          /* AES F8 mode */
-	SA_EALG_ID_AES_CBC,         /* AES CBC mode */
-	SA_EALG_ID_DES_CBC,         /* DES CBC mode */
-	SA_EALG_ID_3DES_CBC,        /* 3DES CBC mode */
-	SA_EALG_ID_CCM,             /* Counter with CBC-MAC mode */
-	SA_EALG_ID_GCM,             /* Galois Counter mode */
-	SA_EALG_ID_AES_ECB,
-	SA_EALG_ID_LAST
-};
-
-/* Authentication algorithms */
-enum sa_aalg_id {
-	SA_AALG_ID_NONE = 0,      /* No Authentication  */
-	SA_AALG_ID_NULL = SA_EALG_ID_LAST, /* NULL Authentication  */
-	SA_AALG_ID_MD5,           /* MD5 mode */
-	SA_AALG_ID_SHA1,          /* SHA1 mode */
-	SA_AALG_ID_SHA2_224,      /* 224-bit SHA2 mode */
-	SA_AALG_ID_SHA2_256,      /* 256-bit SHA2 mode */
-	SA_AALG_ID_SHA2_512,      /* 512-bit SHA2 mode */
-	SA_AALG_ID_HMAC_MD5,      /* HMAC with MD5 mode */
-	SA_AALG_ID_HMAC_SHA1,     /* HMAC with SHA1 mode */
-	SA_AALG_ID_HMAC_SHA2_224, /* HMAC with 224-bit SHA2 mode */
-	SA_AALG_ID_HMAC_SHA2_256, /* HMAC with 256-bit SHA2 mode */
-	SA_AALG_ID_GMAC,          /* Galois Message Auth. Code mode */
-	SA_AALG_ID_CMAC,          /* Cipher-based Mes. Auth. Code mode */
-	SA_AALG_ID_CBC_MAC,       /* Cipher Block Chaining */
-	SA_AALG_ID_AES_XCBC       /* AES Extended Cipher Block Chaining */
-};
-
 /**
  * struct sa_eng_info: Security accelerator engine info
  * @eng_id: Engine ID

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 04/30] crypto: sa2ul - remove unused fields from sa_cmdl_cfg
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (2 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 03/30] crypto: sa2ul - remove unused algorithm ID fields Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 05/30] crypto: sa2ul - remove unused fields from sa_tfm_ctx Manorit Chawdhry
                   ` (26 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

These are assigned but never used. Remove them.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 8 --------
 1 file changed, 8 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 3297a25d9d9d..e49cb741074f 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -95,16 +95,12 @@ static struct device *sa_k3_dev;
  * @enc_eng_id: Encryption Engine ID supported by the SA hardware
  * @auth_eng_id: Authentication Engine ID
  * @iv_size: Initialization Vector size
- * @akey: Authentication key
- * @akey_len: Authentication key length
  * @enc: True, if this is an encode request
  */
 struct sa_cmdl_cfg {
 	u8 enc_eng_id;
 	u8 auth_eng_id;
 	u8 iv_size;
-	const u8 *akey;
-	u16 akey_len;
 	bool enc;
 };
 
@@ -1423,8 +1419,6 @@ static int sa_sha_setup(struct sa_tfm_ctx *ctx, struct  algo_data *ad)
 	cfg.enc_eng_id = ad->enc_eng.eng_id;
 	cfg.auth_eng_id = ad->auth_eng.eng_id;
 	cfg.iv_size = 0;
-	cfg.akey = NULL;
-	cfg.akey_len = 0;
 
 	ctx->dev_data = dev_get_drvdata(sa_k3_dev);
 	/* Setup Encryption Security Context & Command label template */
@@ -1764,8 +1758,6 @@ static int sa_aead_setkey(struct crypto_aead *authenc,
 	cfg.enc_eng_id = ad->enc_eng.eng_id;
 	cfg.auth_eng_id = ad->auth_eng.eng_id;
 	cfg.iv_size = crypto_aead_ivsize(authenc);
-	cfg.akey = keys.authkey;
-	cfg.akey_len = keys.authkeylen;
 
 	/* Setup Encryption Security Context & Command label template */
 	if (sa_init_sc(&ctx->enc, ctx->dev_data->match_data, keys.enckey,

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 05/30] crypto: sa2ul - remove unused fields from sa_tfm_ctx
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (3 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 04/30] crypto: sa2ul - remove unused fields from sa_cmdl_cfg Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 06/30] crypto: sa2ul - remove unused macro definitions Manorit Chawdhry
                   ` (25 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Dead assignment. Remove it.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 2 --
 drivers/crypto/sa2ul.h | 2 --
 2 files changed, 4 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index e49cb741074f..b36437d76891 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1406,7 +1406,6 @@ static int sa_sha_run(struct ahash_request *req)
 
 static int sa_sha_setup(struct sa_tfm_ctx *ctx, struct  algo_data *ad)
 {
-	int bs = crypto_shash_blocksize(ctx->shash);
 	int cmdl_len;
 	struct sa_cmdl_cfg cfg;
 
@@ -1414,7 +1413,6 @@ static int sa_sha_setup(struct sa_tfm_ctx *ctx, struct  algo_data *ad)
 	ad->auth_eng.eng_id = SA_ENG_ID_AM1;
 	ad->auth_eng.sc_size = SA_CTX_AUTH_TYPE2_SZ;
 
-	memset(ctx->authkey, 0, bs);
 	memset(&cfg, 0, sizeof(cfg));
 	cfg.enc_eng_id = ad->enc_eng.eng_id;
 	cfg.auth_eng_id = ad->auth_eng.eng_id;
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 097a496067e1..f29e0b9ac82f 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -293,8 +293,6 @@ struct sa_tfm_ctx {
 	struct sa_ctx_info dec;
 	int keylen;
 	int iv_idx;
-	u32 key[AES_KEYSIZE_256 / sizeof(u32)];
-	u8 authkey[SHA512_BLOCK_SIZE];
 	struct crypto_shash	*shash;
 	/* for fallback */
 	union {

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 06/30] crypto: sa2ul - remove unused macro definitions
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (4 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 05/30] crypto: sa2ul - remove unused fields from sa_tfm_ctx Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 07/30] crypto: sa2ul - consolidate encryption offset definitions Manorit Chawdhry
                   ` (24 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove unused macro definitions for auth functions (SA_MK_U32_AUTH,
SA_AUTHSW_VALID, SA_AUTHSW_*, SA_AUTH_OP_*) and related constants.
These macros were defined but never used.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 -
 drivers/crypto/sa2ul.h | 1 -
 2 files changed, 2 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index b36437d76891..09cefd766c95 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -42,7 +42,6 @@
 #define SA_CMDL_UPD_AUTH        0x0002
 #define SA_CMDL_UPD_ENC_IV      0x0004
 
-#define SA_AUTH_SUBKEY_LEN	16
 #define SA_CMDL_PAYLOAD_LENGTH_MASK	0xFFFF
 #define SA_CMDL_SOP_BYPASS_LEN_MASK	0xFF000000
 
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index f29e0b9ac82f..0aa6a36c0f20 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -46,7 +46,6 @@ struct sa_tfm_ctx;
 
 /* Number of 32 bit words in PS data  */
 #define SA_DMA_NUM_PS_WORDS     16
-#define NKEY_SZ			3
 #define MCI_SZ			27
 
 /*

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 07/30] crypto: sa2ul - consolidate encryption offset definitions
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (5 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 06/30] crypto: sa2ul - remove unused macro definitions Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 08/30] crypto: sa2ul - remove unused SC ID range tracking Manorit Chawdhry
                   ` (23 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Move all SA2UL encryption offset macro definitions to a single
location for better maintainability. No functional change.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 44 ++++++++++++++++++++++++++++----------------
 drivers/crypto/sa2ul.h | 13 -------------
 2 files changed, 28 insertions(+), 29 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 09cefd766c95..cde08686f27a 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -33,10 +33,23 @@
 
 #include "sa2ul.h"
 
-/* Byte offset for key in encryption security context */
-#define SC_ENC_KEY_OFFSET (1 + 27 + 4)
-/* Byte offset for Aux-1 in encryption security context */
-#define SC_ENC_AUX1_OFFSET (1 + 27 + 4 + 32)
+#define SC_ENC_MODESEL_OFFSET (0)
+#define SC_ENC_MODESEL_SIZE (1)
+
+#define SC_ENC_MCI_OFFSET (SC_ENC_MODESEL_SIZE)
+#define SC_ENC_MCI_SIZE (27)
+
+#define SC_ENC_KEY_OFFSET (SC_ENC_MCI_OFFSET + SC_ENC_MCI_SIZE + 4)
+#define SC_ENC_KEY_SIZE 32
+
+#define SC_ENC_AUX1_OFFSET (SC_ENC_KEY_OFFSET + SC_ENC_KEY_SIZE)
+#define SC_ENC_AUX1_SIZE 32
+
+#define SC_ENC_AUX2_OFFSET (SC_ENC_AUX1_OFFSET + SC_ENC_AUX1_SIZE)
+#define SC_ENC_AUX2_SIZE 16
+
+#define SC_ENC_AUX3_OFFSET (SC_ENC_AUX2_OFFSET + SC_ENC_AUX2_SIZE)
+#define SC_ENC_AUX3_SIZE 16
 
 #define SA_CMDL_UPD_ENC         0x0001
 #define SA_CMDL_UPD_AUTH        0x0002
@@ -45,7 +58,6 @@
 #define SA_CMDL_PAYLOAD_LENGTH_MASK	0xFFFF
 #define SA_CMDL_SOP_BYPASS_LEN_MASK	0xFF000000
 
-#define MODE_CONTROL_BYTES	27
 #define SA_HASH_PROCESSING	0
 #define SA_CRYPTO_PROCESSING	0
 #define SA_UPLOAD_HASH_TO_TLR	BIT(6)
@@ -229,7 +241,7 @@ struct sa_req {
  * Mode Control Instructions for various Key lengths 128, 192, 256
  * For CBC (Cipher Block Chaining) mode for encryption
  */
-static u8 mci_cbc_enc_array[3][MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_enc_array[3][SC_ENC_MCI_SIZE] = {
 	{	0x61, 0x00, 0x00, 0x18, 0x88, 0x0a, 0xaa, 0x4b, 0x7e, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00	},
@@ -245,7 +257,7 @@ static u8 mci_cbc_enc_array[3][MODE_CONTROL_BYTES] = {
  * Mode Control Instructions for various Key lengths 128, 192, 256
  * For CBC (Cipher Block Chaining) mode for decryption
  */
-static u8 mci_cbc_dec_array[3][MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_dec_array[3][SC_ENC_MCI_SIZE] = {
 	{	0x71, 0x00, 0x00, 0x80, 0x8a, 0xca, 0x98, 0xf4, 0x40, 0xc0,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00	},
@@ -261,7 +273,7 @@ static u8 mci_cbc_dec_array[3][MODE_CONTROL_BYTES] = {
  * Mode Control Instructions for various Key lengths 128, 192, 256
  * For CBC (Cipher Block Chaining) mode for encryption
  */
-static u8 mci_cbc_enc_no_iv_array[3][MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_enc_no_iv_array[3][SC_ENC_MCI_SIZE] = {
 	{	0x21, 0x00, 0x00, 0x18, 0x88, 0x0a, 0xaa, 0x4b, 0x7e, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00	},
@@ -277,7 +289,7 @@ static u8 mci_cbc_enc_no_iv_array[3][MODE_CONTROL_BYTES] = {
  * Mode Control Instructions for various Key lengths 128, 192, 256
  * For CBC (Cipher Block Chaining) mode for decryption
  */
-static u8 mci_cbc_dec_no_iv_array[3][MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_dec_no_iv_array[3][SC_ENC_MCI_SIZE] = {
 	{	0x31, 0x00, 0x00, 0x80, 0x8a, 0xca, 0x98, 0xf4, 0x40, 0xc0,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00	},
@@ -326,25 +338,25 @@ static u8 mci_ecb_dec_array[3][27] = {
  * For CBC (Cipher Block Chaining) mode and ECB mode
  * encryption and for decryption respectively
  */
-static u8 mci_cbc_3des_enc_array[MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_3des_enc_array[SC_ENC_MCI_SIZE] = {
 	0x60, 0x00, 0x00, 0x18, 0x88, 0x52, 0xaa, 0x4b, 0x7e, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00,
 };
 
-static u8 mci_cbc_3des_dec_array[MODE_CONTROL_BYTES] = {
+static u8 mci_cbc_3des_dec_array[SC_ENC_MCI_SIZE] = {
 	0x70, 0x00, 0x00, 0x85, 0x0a, 0xca, 0x98, 0xf4, 0x40, 0xc0, 0x00, 0x00,
 	0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00,
 };
 
-static u8 mci_ecb_3des_enc_array[MODE_CONTROL_BYTES] = {
+static u8 mci_ecb_3des_enc_array[SC_ENC_MCI_SIZE] = {
 	0x20, 0x00, 0x00, 0x85, 0x0a, 0x04, 0xb7, 0x90, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00,
 };
 
-static u8 mci_ecb_3des_dec_array[MODE_CONTROL_BYTES] = {
+static u8 mci_ecb_3des_dec_array[SC_ENC_MCI_SIZE] = {
 	0x30, 0x00, 0x00, 0x85, 0x0a, 0x04, 0xb7, 0x90, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
 	0x00, 0x00, 0x00,
@@ -494,7 +506,7 @@ static int sa_set_sc_enc(struct algo_data *ad, const u8 *key, u16 key_sz,
 	const u8 *mci = NULL;
 
 	/* Set Encryption mode selector to crypto processing */
-	sc_buf[0] = SA_CRYPTO_PROCESSING;
+	sc_buf[SC_ENC_MODESEL_OFFSET] = SA_CRYPTO_PROCESSING;
 
 	if (enc)
 		mci = ad->mci_enc;
@@ -502,7 +514,7 @@ static int sa_set_sc_enc(struct algo_data *ad, const u8 *key, u16 key_sz,
 		mci = ad->mci_dec;
 	/* Set the mode control instructions in security context */
 	if (mci)
-		memcpy(&sc_buf[1], mci, MODE_CONTROL_BYTES);
+		memcpy(&sc_buf[SC_ENC_MCI_OFFSET], mci, SC_ENC_MCI_SIZE);
 
 	/* For AES-CBC decryption get the inverse key */
 	if (ad->inv_key && !enc) {
@@ -585,7 +597,7 @@ static int sa_format_cmdl_gen(struct sa_cmdl_cfg *cfg, u8 *cmdl,
 				SA_CMDL_HEADER_SIZE_BYTES + cfg->iv_size;
 
 			cmdl[enc_offset + SA_CMDL_OFFSET_OPTION_CTRL1] =
-				(SA_CTX_ENC_AUX2_OFFSET | (cfg->iv_size >> 3));
+				(SC_ENC_AUX2_OFFSET | (cfg->iv_size >> 3));
 			total += SA_CMDL_HEADER_SIZE_BYTES + cfg->iv_size;
 		} else {
 			cmdl[enc_offset + SA_CMDL_OFFSET_LABEL_LEN] =
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 0aa6a36c0f20..94101300736c 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -46,7 +46,6 @@ struct sa_tfm_ctx;
 
 /* Number of 32 bit words in PS data  */
 #define SA_DMA_NUM_PS_WORDS     16
-#define MCI_SZ			27
 
 /*
  * Maximum number of simultaeneous security contexts
@@ -60,12 +59,6 @@ struct sa_tfm_ctx;
 #define SA_CTX_SIZE_TO_DMA_SIZE(ctx_sz) \
 		((ctx_sz) ? ((ctx_sz) / 32 - 1) : 0)
 
-#define SA_CTX_ENC_KEY_OFFSET   32
-#define SA_CTX_ENC_AUX1_OFFSET  64
-#define SA_CTX_ENC_AUX2_OFFSET  96
-#define SA_CTX_ENC_AUX3_OFFSET  112
-#define SA_CTX_ENC_AUX4_OFFSET  128
-
 /* Next Engine Select code in CP_ACE */
 #define SA_ENG_ID_EM1   2       /* Enc/Dec engine with AES/DEC core */
 #define SA_ENG_ID_EM2   3       /* Encryption/Decryption enginefor pass 2 */
@@ -142,12 +135,6 @@ struct sa_tfm_ctx;
  */
 #define SA_CTX_SCCTL_OWNER_OFFSET 0
 
-#define SA_CTX_ENC_KEY_OFFSET   32
-#define SA_CTX_ENC_AUX1_OFFSET  64
-#define SA_CTX_ENC_AUX2_OFFSET  96
-#define SA_CTX_ENC_AUX3_OFFSET  112
-#define SA_CTX_ENC_AUX4_OFFSET  128
-
 #define SA_SCCTL_FE_AUTH_ENC	0x65
 #define SA_SCCTL_FE_ENC		0x8D
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 08/30] crypto: sa2ul - remove unused SC ID range tracking
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (6 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 07/30] crypto: sa2ul - consolidate encryption offset definitions Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 09/30] crypto: sa2ul - remove unused base register pointer Manorit Chawdhry
                   ` (22 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove unused sc_id_start and sc_id_end fields from sa_dev_data.
These were intended for security context ID management but were
never used in the driver.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 4 ++--
 drivers/crypto/sa2ul.h | 4 ----
 2 files changed, 2 insertions(+), 6 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index cde08686f27a..72be29820859 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -764,7 +764,7 @@ static void sa_free_ctx_info(struct sa_ctx_info *ctx,
 {
 	unsigned long bn;
 
-	bn = ctx->sc_id - data->sc_id_start;
+	bn = ctx->sc_id;
 	spin_lock(&data->scid_lock);
 	__clear_bit(bn, data->ctx_bm);
 	data->sc_id--;
@@ -788,7 +788,7 @@ static int sa_init_ctx_info(struct sa_ctx_info *ctx,
 	data->sc_id++;
 	spin_unlock(&data->scid_lock);
 
-	ctx->sc_id = (u16)(data->sc_id_start + bn);
+	ctx->sc_id = (u16)bn;
 
 	ctx->sc = dma_pool_alloc(data->sc_pool, GFP_KERNEL, &ctx->sc_phys);
 	if (!ctx->sc) {
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 94101300736c..c41c688687f5 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -168,8 +168,6 @@ struct sa_match_data;
  * @sc_pool: security context pool
  * @dev: Device pointer
  * @scid_lock: secure context ID lock
- * @sc_id_start: starting index for SC ID
- * @sc_id_end: Ending index for SC ID
  * @sc_id: Security Context ID
  * @ctx_bm: Bitmap to keep track of Security context ID's
  * @ctx: SA tfm context pointer
@@ -185,8 +183,6 @@ struct sa_crypto_data {
 	struct device *dev;
 	spinlock_t	scid_lock; /* lock for SC-ID allocation */
 	/* Security context data */
-	u16		sc_id_start;
-	u16		sc_id_end;
 	u16		sc_id;
 	unsigned long	ctx_bm[DIV_ROUND_UP(SA_MAX_NUM_CTX,
 				BITS_PER_LONG)];

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 09/30] crypto: sa2ul - remove unused base register pointer
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (7 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 08/30] crypto: sa2ul - remove unused SC ID range tracking Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 10/30] crypto: sa2ul - remove unused includes and defines Manorit Chawdhry
                   ` (21 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove unused base register pointer from sa_dev_data structure.
The driver uses the psilss_base pointer instead for all register
accesses.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 -
 drivers/crypto/sa2ul.h | 2 --
 2 files changed, 3 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 72be29820859..13e941f58c4b 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -2342,7 +2342,6 @@ static int sa_ul_probe(struct platform_device *pdev)
 	sa_k3_dev = dev;
 	dev_data->dev = dev;
 	dev_data->pdev = pdev;
-	dev_data->base = saul_base;
 	platform_set_drvdata(pdev, dev_data);
 	dev_set_drvdata(sa_k3_dev, dev_data);
 
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index c41c688687f5..48ed1933ecae 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -162,7 +162,6 @@ struct sa_match_data;
 
 /**
  * struct sa_crypto_data - Crypto driver instance data
- * @base: Base address of the register space
  * @soc_data: Pointer to SoC specific data
  * @pdev: Platform device pointer
  * @sc_pool: security context pool
@@ -176,7 +175,6 @@ struct sa_match_data;
  * @dma_tx: Pointer to DMA TX channel
  */
 struct sa_crypto_data {
-	void __iomem *base;
 	const struct sa_match_data *match_data;
 	struct platform_device	*pdev;
 	struct dma_pool		*sc_pool;

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 10/30] crypto: sa2ul - remove unused includes and defines
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (8 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 09/30] crypto: sa2ul - remove unused base register pointer Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 11/30] crypto: sa2ul - remove unused line Manorit Chawdhry
                   ` (20 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove unused includes and define statements that are not
referenced anywhere in the driver.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 13 -------------
 drivers/crypto/sa2ul.h | 12 ------------
 2 files changed, 25 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 13e941f58c4b..f98d199729d0 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -9,7 +9,6 @@
  *		Tero Kristo
  */
 #include <linux/bitfield.h>
-#include <linux/clk.h>
 #include <linux/dma-mapping.h>
 #include <linux/dmaengine.h>
 #include <linux/dmapool.h>
@@ -70,14 +69,6 @@
 #define SA_SW2_EGRESS_LENGTH		0xFF000000
 #define SA_BASIC_HASH		0x10
 
-#define SHA256_DIGEST_WORDS    8
-/* Make 32-bit word from 4 bytes */
-#define SA_MK_U32(b0, b1, b2, b3) (((b0) << 24) | ((b1) << 16) | \
-				   ((b2) << 8) | (b3))
-
-/* size of SCCTL structure in bytes */
-#define SA_SCCTL_SZ 16
-
 /* Max Authentication tag size */
 #define SA_MAX_AUTH_TAG_SZ 64
 
@@ -199,14 +190,12 @@ struct sa_rx_data {
 
 /**
  * struct sa_req: SA request definition
- * @dev: device for the request
  * @size: total data to the xmitted via DMA
  * @enc_offset: offset of cipher data
  * @enc_size: data to be passed to cipher engine
  * @enc_iv: cipher IV
  * @auth_offset: offset of the authentication data
  * @auth_size: size of the authentication data
- * @auth_iv: authentication IV
  * @type: algorithm type for the request
  * @cmdl: command label pointer
  * @base: pointer to the base request
@@ -218,14 +207,12 @@ struct sa_rx_data {
  * @mdata_size: metadata size passed to DMA
  */
 struct sa_req {
-	struct device *dev;
 	u16 size;
 	u8 enc_offset;
 	u16 enc_size;
 	u8 *enc_iv;
 	u8 auth_offset;
 	u16 auth_size;
-	u8 *auth_iv;
 	u32 type;
 	u32 *cmdl;
 	struct crypto_async_request *base;
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 48ed1933ecae..7c0ca2ca966e 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -169,7 +169,6 @@ struct sa_match_data;
  * @scid_lock: secure context ID lock
  * @sc_id: Security Context ID
  * @ctx_bm: Bitmap to keep track of Security context ID's
- * @ctx: SA tfm context pointer
  * @dma_rx1: Pointer to DMA rx channel for sizes < 256 Bytes
  * @dma_rx2: Pointer to DMA rx channel for sizes > 256 Bytes
  * @dma_tx: Pointer to DMA TX channel
@@ -184,7 +183,6 @@ struct sa_crypto_data {
 	u16		sc_id;
 	unsigned long	ctx_bm[DIV_ROUND_UP(SA_MAX_NUM_CTX,
 				BITS_PER_LONG)];
-	struct sa_tfm_ctx	*ctx;
 	struct dma_chan		*dma_rx1;
 	struct dma_chan		*dma_rx2;
 	struct dma_chan		*dma_tx;
@@ -193,12 +191,10 @@ struct sa_crypto_data {
 /**
  * struct sa_cmdl_param_info: Command label parameters info
  * @index: Index of the parameter in the command label format
- * @offset: the offset of the parameter
  * @size: Size of the parameter
  */
 struct sa_cmdl_param_info {
 	u16	index;
-	u16	offset;
 	u16	size;
 };
 
@@ -208,7 +204,6 @@ struct sa_cmdl_param_info {
 /**
  * struct sa_cmdl_upd_info: Command label updation info
  * @flags: flags in command label
- * @submode: Encryption submodes
  * @enc_size: Size of first pass encryption size
  * @enc_offset: Encryption payload offset in the packet
  * @enc_iv: Encryption initialization vector for pass2
@@ -217,7 +212,6 @@ struct sa_cmdl_param_info {
  */
 struct sa_cmdl_upd_info {
 	u16	flags;
-	u16	submode;
 	struct sa_cmdl_param_info	enc_size;
 	struct sa_cmdl_param_info	enc_offset;
 	struct sa_cmdl_param_info	enc_iv;
@@ -262,7 +256,6 @@ struct sa_ctx_info {
  * @dev_data: struct sa_crypto_data pointer
  * @enc: struct sa_ctx_info for encryption
  * @dec: struct sa_ctx_info for decryption
- * @keylen: encrption/decryption keylength
  * @iv_idx: Initialization vector index
  * @key: encryption key
  * @fallback: SW fallback algorithm
@@ -271,7 +264,6 @@ struct sa_tfm_ctx {
 	struct sa_crypto_data *dev_data;
 	struct sa_ctx_info enc;
 	struct sa_ctx_info dec;
-	int keylen;
 	int iv_idx;
 	struct crypto_shash	*shash;
 	/* for fallback */
@@ -284,13 +276,9 @@ struct sa_tfm_ctx {
 
 /**
  * struct sa_sha_req_ctx: Structure used for sha request
- * @dev_data: struct sa_crypto_data pointer
- * @cmdl: Complete command label with psdata and epib included
  * @fallback_req: SW fallback request container
  */
 struct sa_sha_req_ctx {
-	struct sa_crypto_data	*dev_data;
-	u32			cmdl[SA_MAX_CMDL_WORDS + SA_PSDATA_CTX_WORDS];
 	struct ahash_request	fallback_req;
 };
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 11/30] crypto: sa2ul - remove unused line
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (9 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 10/30] crypto: sa2ul - remove unused includes and defines Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 12/30] crypto: sa2ul - remove redundant sa_sha_digest() wrapper Manorit Chawdhry
                   ` (19 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove an unused line from the driver.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index f98d199729d0..c774447e7a5a 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1239,7 +1239,6 @@ static int sa_run(struct sa_req *req)
 				   sizeof(u32))), cmdl, sizeof(sa_ctx->epib),
 			   sa_ctx->epib);
 
-	ml = sa_ctx->cmdl_size + (SA_PSDATA_CTX_WORDS * sizeof(u32));
 	dmaengine_desc_set_metadata_len(tx_out, req->mdata_size);
 
 	dmaengine_submit(tx_out);

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 12/30] crypto: sa2ul - remove redundant sa_sha_digest() wrapper
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (10 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 11/30] crypto: sa2ul - remove unused line Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 13/30] crypto: sa2ul - fix struct documentation for match_data Manorit Chawdhry
                   ` (18 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Remove the sa_sha_digest() function which was a simple wrapper
that only called crypto_shash_digest(). Replace all calls with
direct crypto_shash_digest() calls.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 11 +++--------
 1 file changed, 3 insertions(+), 8 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index c774447e7a5a..673cd1458948 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1476,11 +1476,6 @@ static int sa_sha_cra_init_alg(struct crypto_tfm *tfm, const char *alg_base)
 	return 0;
 }
 
-static int sa_sha_digest(struct ahash_request *req)
-{
-	return sa_sha_run(req);
-}
-
 static int sa_sha_init(struct ahash_request *req)
 {
 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
@@ -1997,7 +1992,7 @@ static struct sa_alg_tmpl sa_algs[] = {
 			.update			= sa_sha_update,
 			.final			= sa_sha_final,
 			.finup			= sa_sha_finup,
-			.digest			= sa_sha_digest,
+			.digest			= sa_sha_run,
 			.export			= sa_sha_export,
 			.import			= sa_sha_import,
 		},
@@ -2026,7 +2021,7 @@ static struct sa_alg_tmpl sa_algs[] = {
 			.update			= sa_sha_update,
 			.final			= sa_sha_final,
 			.finup			= sa_sha_finup,
-			.digest			= sa_sha_digest,
+			.digest			= sa_sha_run,
 			.export			= sa_sha_export,
 			.import			= sa_sha_import,
 		},
@@ -2055,7 +2050,7 @@ static struct sa_alg_tmpl sa_algs[] = {
 			.update			= sa_sha_update,
 			.final			= sa_sha_final,
 			.finup			= sa_sha_finup,
-			.digest			= sa_sha_digest,
+			.digest			= sa_sha_run,
 			.export			= sa_sha_export,
 			.import			= sa_sha_import,
 		},

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 13/30] crypto: sa2ul - fix struct documentation for match_data
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (11 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 12/30] crypto: sa2ul - remove redundant sa_sha_digest() wrapper Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 14/30] crypto: sa2ul - zero out security context on free Manorit Chawdhry
                   ` (17 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Update structure name in documentation comment from sa_of_data
to sa_match_data to match the actual structure definition.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 7c0ca2ca966e..04669bf7fcb5 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -162,7 +162,7 @@ struct sa_match_data;
 
 /**
  * struct sa_crypto_data - Crypto driver instance data
- * @soc_data: Pointer to SoC specific data
+ * @match_data: Pointer to match data
  * @pdev: Platform device pointer
  * @sc_pool: security context pool
  * @dev: Device pointer

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 14/30] crypto: sa2ul - zero out security context on free
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (12 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 13/30] crypto: sa2ul - fix struct documentation for match_data Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 15/30] crypto: sa2ul - fix context release on errors Manorit Chawdhry
                   ` (16 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Zero out the security context memory before freeing to prevent
potential information leakage of cryptographic keys and state.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 673cd1458948..7ec048136114 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -758,6 +758,7 @@ static void sa_free_ctx_info(struct sa_ctx_info *ctx,
 	spin_unlock(&data->scid_lock);
 
 	if (ctx->sc) {
+		memzero_explicit(ctx->sc, SA_CTX_MAX_SZ);
 		dma_pool_free(data->sc_pool, ctx->sc, ctx->sc_phys);
 		ctx->sc = NULL;
 	}

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 15/30] crypto: sa2ul - fix context release on errors
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (13 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 14/30] crypto: sa2ul - zero out security context on free Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 16/30] crypto: sa2ul - fix resource leak of sha in init_alg() error path Manorit Chawdhry
                   ` (15 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Fix security context cleanup in error paths to prevent memory
leaks when crypto operations fail.

Fixes: 7694b6ca649f ("crypto: sa2ul - Add crypto driver")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 15 +++++++++------
 1 file changed, 9 insertions(+), 6 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 7ec048136114..cd80a2dabc99 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -826,16 +826,14 @@ static int sa_cipher_cra_init(struct crypto_skcipher *tfm)
 	if (ret)
 		return ret;
 	ret = sa_init_ctx_info(&ctx->dec, data);
-	if (ret) {
-		sa_free_ctx_info(&ctx->enc, data);
-		return ret;
-	}
+	if (ret)
+		goto ctx_dec_err;
 
 	child = crypto_alloc_skcipher(name, 0, CRYPTO_ALG_NEED_FALLBACK);
-
 	if (IS_ERR(child)) {
 		dev_err(sa_k3_dev, "Error allocating fallback algo %s\n", name);
-		return PTR_ERR(child);
+		ret = PTR_ERR(child);
+		goto alloc_err;
 	}
 
 	ctx->fallback.skcipher = child;
@@ -846,6 +844,11 @@ static int sa_cipher_cra_init(struct crypto_skcipher *tfm)
 		__func__, tfm, ctx->enc.sc_id, &ctx->enc.sc_phys,
 		ctx->dec.sc_id, &ctx->dec.sc_phys);
 	return 0;
+alloc_err:
+	sa_free_ctx_info(&ctx->dec, data);
+ctx_dec_err:
+	sa_free_ctx_info(&ctx->enc, data);
+	return ret;
 }
 
 static int sa_cipher_setkey(struct crypto_skcipher *tfm, const u8 *key,

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 16/30] crypto: sa2ul - fix resource leak of sha in init_alg() error path
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (14 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 15/30] crypto: sa2ul - fix context release on errors Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 17/30] crypto: sa2ul - fix resource leak of AEAD " Manorit Chawdhry
                   ` (14 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Add crypto_free_shash() call before returning the error to properly
clean up the resource allocated in the previous call.

Fixes: 2dc53d004745 ("crypto: sa2ul - add sha1/sha256/sha512 support")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index cd80a2dabc99..9379d1271698 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1465,6 +1465,7 @@ static int sa_sha_cra_init_alg(struct crypto_tfm *tfm, const char *alg_base)
 		if (IS_ERR(ctx->fallback.ahash)) {
 			dev_err(ctx->dev_data->dev,
 				"Could not load fallback driver\n");
+			crypto_free_shash(ctx->shash);
 			return PTR_ERR(ctx->fallback.ahash);
 		}
 	}

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 17/30] crypto: sa2ul - fix resource leak of AEAD in init_alg() error path
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (15 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 16/30] crypto: sa2ul - fix resource leak of sha in init_alg() error path Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 18/30] crypto: sa2ul - fix DMA mapping leak in sa_run() error paths Manorit Chawdhry
                   ` (13 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Add crypto_free_shash() call before returning the error to properly
clean up the resource allocated in the previous call.

Fixes: d2c8ac187fc9 ("crypto: sa2ul - Add AEAD algorithm support")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 9379d1271698..dcddb81dc842 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1671,6 +1671,7 @@ static int sa_cra_init_aead(struct crypto_aead *tfm, const char *hash,
 	if (IS_ERR(ctx->fallback.aead)) {
 		dev_err(sa_k3_dev, "fallback driver %s couldn't be loaded\n",
 			fallback);
+		crypto_free_shash(ctx->shash);
 		return PTR_ERR(ctx->fallback.aead);
 	}
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 18/30] crypto: sa2ul - fix DMA mapping leak in sa_run() error paths
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (16 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 17/30] crypto: sa2ul - fix resource leak of AEAD " Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 19/30] crypto: sa2ul - generate dynamic metadata length Manorit Chawdhry
                   ` (12 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

In sa_run(), when dma_map_sgtable() fails, the code was using kfree(rxd)
directly instead of sa_free_sa_rx_data(rxd). This is problematic because
if an earlier DMA mapping succeeded, it won't be unmapped, leading to a
DMA resource leak.

The sa_free_sa_rx_data() function properly checks the mapped flag and
unmaps any successfully mapped buffers before freeing the rxd structure.

Replace kfree(rxd) with sa_free_sa_rx_data(rxd) in both early error
paths
to ensure proper cleanup of any partial DMA mappings.

Fixes: 854b77371998 ("crypto: sa2ul - Fix memory leak of rxd")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index dcddb81dc842..cc9f2881efda 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1131,7 +1131,7 @@ static int sa_run(struct sa_req *req)
 		mapped_sg->sgt.orig_nents = src_nents;
 		ret = dma_map_sgtable(ddev, &mapped_sg->sgt, dir_src, 0);
 		if (ret) {
-			kfree(rxd);
+			sa_free_sa_rx_data(rxd);
 			return ret;
 		}
 
@@ -1142,7 +1142,7 @@ static int sa_run(struct sa_req *req)
 		mapped_sg->sgt.orig_nents = sg_nents;
 		ret = dma_map_sgtable(ddev, &mapped_sg->sgt, dir_src, 0);
 		if (ret) {
-			kfree(rxd);
+			sa_free_sa_rx_data(rxd);
 			return ret;
 		}
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 19/30] crypto: sa2ul - generate dynamic metadata length
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (17 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 18/30] crypto: sa2ul - fix DMA mapping leak in sa_run() error paths Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 20/30] crypto: sa2ul - fix command label stack corruption Manorit Chawdhry
                   ` (11 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Calculate metadata length dynamically based on actual algorithm
requirements instead of using a fixed value and remove the code that is
not in the spec and not required to be passed to sa2ul.

Aligns the index as well after the removal of those extra bytes.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 25 +++++++------------------
 drivers/crypto/sa2ul.h | 23 +----------------------
 2 files changed, 8 insertions(+), 40 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index cc9f2881efda..a60b968c21f3 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -956,7 +956,7 @@ static int sa_3des_cbc_setkey(struct crypto_skcipher *tfm, const u8 *key,
 
 	ad.mci_enc = mci_cbc_3des_enc_array;
 	ad.mci_dec = mci_cbc_3des_dec_array;
-	ad.iv_idx = 6;
+	ad.iv_idx = 4;
 	ad.iv_out_size = 8;
 
 	return sa_cipher_setkey(tfm, key, keylen, &ad);
@@ -1028,7 +1028,7 @@ static void sa_aes_dma_in_callback(void *data)
 	skcipher_request_complete(req, 0);
 }
 
-static void
+static int
 sa_prepare_tx_desc(u32 *mdptr, u32 pslen, u32 *psdata, u32 epiblen, u32 *epib)
 {
 	u32 *out, *in;
@@ -1041,6 +1041,8 @@ sa_prepare_tx_desc(u32 *mdptr, u32 pslen, u32 *psdata, u32 epiblen, u32 *epib)
 	for (out = &mdptr[5], in = psdata, i = 0;
 	     i < pslen / sizeof(u32); i++)
 		*out++ = *in++;
+
+	return epiblen + sizeof(u32) + pslen;
 }
 
 static int sa_run(struct sa_req *req)
@@ -1097,16 +1099,6 @@ static int sa_run(struct sa_req *req)
 
 	sa_update_cmdl(req, cmdl, &sa_ctx->cmdl_upd_info);
 
-	if (req->type != CRYPTO_ALG_TYPE_AHASH) {
-		if (req->enc)
-			req->type |=
-				(SA_REQ_SUBTYPE_ENC << SA_REQ_SUBTYPE_SHIFT);
-		else
-			req->type |=
-				(SA_REQ_SUBTYPE_DEC << SA_REQ_SUBTYPE_SHIFT);
-	}
-
-	cmdl[sa_ctx->cmdl_size / sizeof(u32)] = req->type;
 
 	/*
 	 * Map the packets, first we check if the data fits into a single
@@ -1239,9 +1231,9 @@ static int sa_run(struct sa_req *req)
 	 */
 	mdptr = (u32 *)dmaengine_desc_get_metadata_ptr(tx_out, &pl, &ml);
 
-	sa_prepare_tx_desc(mdptr, (sa_ctx->cmdl_size + (SA_PSDATA_CTX_WORDS *
-				   sizeof(u32))), cmdl, sizeof(sa_ctx->epib),
-			   sa_ctx->epib);
+	req->mdata_size = sa_prepare_tx_desc(mdptr, sa_ctx->cmdl_size,
+					     cmdl, sizeof(sa_ctx->epib),
+					     sa_ctx->epib);
 
 	dmaengine_desc_set_metadata_len(tx_out, req->mdata_size);
 
@@ -1298,7 +1290,6 @@ static int sa_cipher_run(struct skcipher_request *req, u8 *iv, int enc)
 	sa_req.type = CRYPTO_ALG_TYPE_SKCIPHER;
 	sa_req.enc = enc;
 	sa_req.callback = sa_aes_dma_in_callback;
-	sa_req.mdata_size = 44;
 	sa_req.base = &req->base;
 	sa_req.ctx = ctx;
 
@@ -1398,7 +1389,6 @@ static int sa_sha_run(struct ahash_request *req)
 	sa_req.enc = true;
 	sa_req.type = CRYPTO_ALG_TYPE_AHASH;
 	sa_req.callback = sa_sha_dma_in_callback;
-	sa_req.mdata_size = 28;
 	sa_req.ctx = ctx;
 	sa_req.base = &req->base;
 
@@ -1862,7 +1852,6 @@ static int sa_aead_run(struct aead_request *req, u8 *iv, int enc)
 	sa_req.type = CRYPTO_ALG_TYPE_AEAD;
 	sa_req.enc = enc;
 	sa_req.callback = sa_aead_dma_in_callback;
-	sa_req.mdata_size = 52;
 	sa_req.base = &req->base;
 	sa_req.ctx = ctx;
 	sa_req.src = req->src;
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 04669bf7fcb5..fbea98981f10 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -31,22 +31,9 @@ struct sa_tfm_ctx;
 #define SA_EEC_CPPI_PORT_IN_EN		0x00000200
 #define SA_EEC_CPPI_PORT_OUT_EN		0x00000800
 
-/*
- * Encoding used to identify the typo of crypto operation
- * performed on the packet when the packet is returned
- * by SA
- */
-#define SA_REQ_SUBTYPE_ENC	0x0001
-#define SA_REQ_SUBTYPE_DEC	0x0002
-#define SA_REQ_SUBTYPE_SHIFT	16
-#define SA_REQ_SUBTYPE_MASK	0xffff
-
 /* Number of 32 bit words in EPIB  */
 #define SA_DMA_NUM_EPIB_WORDS   4
 
-/* Number of 32 bit words in PS data  */
-#define SA_DMA_NUM_PS_WORDS     16
-
 /*
  * Maximum number of simultaeneous security contexts
  * supported by the driver
@@ -219,16 +206,8 @@ struct sa_cmdl_upd_info {
 	struct sa_cmdl_param_info	auth_offset;
 };
 
-/*
- * Number of 32bit words appended after the command label
- * in PSDATA to identify the crypto request context.
- * word-0: Request type
- * word-1: pointer to request
- */
-#define SA_PSDATA_CTX_WORDS 4
-
 /* Maximum size of Command label in 32 words */
-#define SA_MAX_CMDL_WORDS (SA_DMA_NUM_PS_WORDS - SA_PSDATA_CTX_WORDS)
+#define SA_MAX_CMDL_WORDS 24
 
 /**
  * struct sa_ctx_info: SA context information

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 20/30] crypto: sa2ul - fix command label stack corruption
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (18 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 19/30] crypto: sa2ul - generate dynamic metadata length Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 21/30] crypto: sa2ul - fix error handling in sa_prepare_iopad Manorit Chawdhry
                   ` (10 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Fix a race between sa_run() reading sa_ctx->cmdl_size and
sa_ctx->cmdl_upd_info and a concurrent setkey() call reallocating or
replacing sa_ctx. sa_run() already copies the command label template
into a per-request stack buffer, but it read the shared context's
size and update-info fields directly while building that copy, so a
concurrent setkey() replacing sa_ctx underneath an in-flight request
could corrupt the per-request command label.

Snapshot sa_ctx->cmdl_size and sa_ctx->cmdl_upd_info into local
variables before using them, isolating the in-flight request from a
concurrent setkey().

Fixes: 7694b6ca649f ("crypto: sa2ul - Add crypto driver")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index a60b968c21f3..9e86b9531366 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1050,6 +1050,8 @@ static int sa_run(struct sa_req *req)
 	struct sa_rx_data *rxd;
 	gfp_t gfp_flags;
 	u32 cmdl[SA_MAX_CMDL_WORDS];
+	u16 cmdl_size;
+	struct sa_cmdl_upd_info cmdl_upd_info;
 	struct sa_crypto_data *pdata = dev_get_drvdata(sa_k3_dev);
 	struct device *ddev;
 	struct dma_chan *dma_rx;
@@ -1095,9 +1097,12 @@ static int sa_run(struct sa_req *req)
 	ddev = dmaengine_get_dma_device(pdata->dma_tx);
 	rxd->ddev = ddev;
 
-	memcpy(cmdl, sa_ctx->cmdl, sa_ctx->cmdl_size);
+	/* Snapshot TFM context to local copies for isolation from setkey() */
+	cmdl_size = sa_ctx->cmdl_size;
+	cmdl_upd_info = sa_ctx->cmdl_upd_info;
+	memcpy(cmdl, sa_ctx->cmdl, cmdl_size);
 
-	sa_update_cmdl(req, cmdl, &sa_ctx->cmdl_upd_info);
+	sa_update_cmdl(req, cmdl, &cmdl_upd_info);
 
 
 	/*
@@ -1211,7 +1216,7 @@ static int sa_run(struct sa_req *req)
 	rxd->req = (void *)req->base;
 	rxd->enc = req->enc;
 	rxd->iv_idx = req->ctx->iv_idx;
-	rxd->enc_iv_size = sa_ctx->cmdl_upd_info.enc_iv.size;
+	rxd->enc_iv_size = cmdl_upd_info.enc_iv.size;
 	rxd->tx_in->callback = req->callback;
 	rxd->tx_in->callback_param = rxd;
 
@@ -1231,7 +1236,7 @@ static int sa_run(struct sa_req *req)
 	 */
 	mdptr = (u32 *)dmaengine_desc_get_metadata_ptr(tx_out, &pl, &ml);
 
-	req->mdata_size = sa_prepare_tx_desc(mdptr, sa_ctx->cmdl_size,
+	req->mdata_size = sa_prepare_tx_desc(mdptr, cmdl_size,
 					     cmdl, sizeof(sa_ctx->epib),
 					     sa_ctx->epib);
 

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 21/30] crypto: sa2ul - fix error handling in sa_prepare_iopad
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (19 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 20/30] crypto: sa2ul - fix command label stack corruption Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 22/30] crypto: sa2ul - move export to appropriate location Manorit Chawdhry
                   ` (9 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Fixes the call stack for sa_prepare_iopad to start returning errors
incase of failures. Also fix sa_export_hash to propagate the errors as
well as it comes in the same call chain.

Fixes: d2c8ac187fc9 ("crypto: sa2ul - Add AEAD algorithm support")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 101 ++++++++++++++++++++++++++++++++++++++-----------
 1 file changed, 79 insertions(+), 22 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 9e86b9531366..f89e84c5529b 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -133,8 +133,8 @@ struct algo_data {
 	bool inv_key;
 	struct sa_tfm_ctx *ctx;
 	bool keyed_mac;
-	void (*prep_iopad)(struct algo_data *algo, const u8 *key,
-			   u16 key_sz, __be32 *ipad, __be32 *opad);
+	int (*prep_iopad)(struct algo_data *algo, const u8 *key,
+			  u16 key_sz, __be32 *ipad, __be32 *opad);
 };
 
 /**
@@ -392,12 +392,13 @@ static void prepare_kopad(u8 *k_opad, const u8 *key, u16 key_sz)
 		k_opad[i] = 0x5c;
 }
 
-static void sa_export_shash(void *state, struct shash_desc *hash,
-			    int digest_size, __be32 *out)
+static int sa_export_shash(void *state, struct shash_desc *hash,
+			   int digest_size, __be32 *out)
 {
 	struct sha1_state *sha1;
 	struct sha256_state *sha256;
 	u32 *result;
+	int ret = 0;
 
 	switch (digest_size) {
 	case SHA1_DIGEST_SIZE:
@@ -411,20 +412,29 @@ static void sa_export_shash(void *state, struct shash_desc *hash,
 	default:
 		dev_err(sa_k3_dev, "%s: bad digest_size=%d\n", __func__,
 			digest_size);
-		return;
+		return -EINVAL;
 	}
 
-	crypto_shash_export(hash, state);
+	ret = crypto_shash_export(hash, state);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
+			__func__);
+		return ret;
+	}
 
 	cpu_to_be32_array(out, result, digest_size / 4);
+
+	return ret;
 }
 
-static void sa_prepare_iopads(struct algo_data *data, const u8 *key,
-			      u16 key_sz, __be32 *ipad, __be32 *opad)
+static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
+			     u16 key_sz, __be32 *ipad, __be32 *opad)
 {
 	SHASH_DESC_ON_STACK(shash, data->ctx->shash);
 	int block_size = crypto_shash_blocksize(data->ctx->shash);
 	int digest_size = crypto_shash_digestsize(data->ctx->shash);
+	int ret = 0;
+
 	union {
 		struct sha1_state sha1;
 		struct sha256_state sha256;
@@ -435,18 +445,49 @@ static void sa_prepare_iopads(struct algo_data *data, const u8 *key,
 
 	prepare_kipad(sha.k_pad, key, key_sz);
 
-	crypto_shash_init(shash);
-	crypto_shash_update(shash, sha.k_pad, block_size);
-	sa_export_shash(&sha, shash, digest_size, ipad);
+	ret = crypto_shash_init(shash);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: crypto_shash_init for ipad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
+	ret = crypto_shash_update(shash, sha.k_pad, block_size);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for ipad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
+	ret = sa_export_shash(&sha, shash, digest_size, ipad);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: sa_export_shash for ipad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
 
 	prepare_kopad(sha.k_pad, key, key_sz);
 
-	crypto_shash_init(shash);
-	crypto_shash_update(shash, sha.k_pad, block_size);
-
-	sa_export_shash(&sha, shash, digest_size, opad);
+	ret = crypto_shash_init(shash);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: crypto_shash_init for opad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
+	ret = crypto_shash_update(shash, sha.k_pad, block_size);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for opad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
+	ret = sa_export_shash(&sha, shash, digest_size, opad);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: %d: sa_export_shash for opad failed, ret=%d\n",
+			__func__, __LINE__, ret);
+		return ret;
+	}
 
 	memzero_explicit(&sha, sizeof(sha));
+
+	return ret;
 }
 
 /* Derive the inverse key used in AES-CBC decryption operation */
@@ -516,11 +557,12 @@ static int sa_set_sc_enc(struct algo_data *ad, const u8 *key, u16 key_sz,
 }
 
 /* Set Security context for the authentication engine */
-static void sa_set_sc_auth(struct algo_data *ad, const u8 *key, u16 key_sz,
-			   u8 *sc_buf)
+static int sa_set_sc_auth(struct algo_data *ad, const u8 *key, u16 key_sz,
+			  u8 *sc_buf)
 {
 	__be32 *ipad = (void *)(sc_buf + 32);
 	__be32 *opad = (void *)(sc_buf + 64);
+	int ret = 0;
 
 	/* Set Authentication mode selector to hash processing */
 	sc_buf[0] = SA_HASH_PROCESSING;
@@ -529,12 +571,20 @@ static void sa_set_sc_auth(struct algo_data *ad, const u8 *key, u16 key_sz,
 	sc_buf[1] |= ad->auth_ctrl;
 
 	/* Copy the keys or ipad/opad */
-	if (ad->keyed_mac)
-		ad->prep_iopad(ad, key, key_sz, ipad, opad);
+	if (ad->keyed_mac) {
+		ret = ad->prep_iopad(ad, key, key_sz, ipad, opad);
+		if (ret) {
+			dev_err(sa_k3_dev, "%s: %d: sa_prepare_iopads failed, ret=%d\n",
+				__func__, __LINE__, ret);
+			return ret;
+		}
+	}
 	else {
 		/* basic hash */
 		sc_buf[1] |= SA_BASIC_HASH;
 	}
+
+	return 0;
 }
 
 /* Format general command label */
@@ -688,6 +738,7 @@ int sa_init_sc(struct sa_ctx_info *ctx, const struct sa_match_data *match_data,
 	u8 *sc_buf = ctx->sc;
 	u16 sc_id = ctx->sc_id;
 	u8 first_engine = 0;
+	int ret = 0;
 
 	memzero_explicit(sc_buf, SA_CTX_MAX_SZ);
 
@@ -727,9 +778,15 @@ int sa_init_sc(struct sa_ctx_info *ctx, const struct sa_match_data *match_data,
 	}
 
 	/* Prepare context for authentication engine */
-	if (ad->auth_eng.sc_size)
-		sa_set_sc_auth(ad, auth_key, auth_key_sz,
-			       &sc_buf[auth_sc_offset]);
+	if (ad->auth_eng.sc_size) {
+		ret = sa_set_sc_auth(ad, auth_key, auth_key_sz,
+				     &sc_buf[auth_sc_offset]);
+		if (ret) {
+			dev_err(sa_k3_dev, "%s: Error in setting authentication context\n",
+				__func__);
+			return ret;
+		}
+	}
 
 	/* Set the ownership of context to CP_ACE */
 	sc_buf[SA_CTX_SCCTL_OWNER_OFFSET] = 0x80;

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 22/30] crypto: sa2ul - move export to appropriate location.
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (20 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 21/30] crypto: sa2ul - fix error handling in sa_prepare_iopad Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads Manorit Chawdhry
                   ` (8 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The current code just writes ipad/opad into the sa2ul context but SA2UL
requires the intermediate digest to be programmed into it.

Export the intermediate hash state before big endian processing to
program the correct state in SA2UL.

Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index f89e84c5529b..36c8403b5713 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -400,6 +400,14 @@ static int sa_export_shash(void *state, struct shash_desc *hash,
 	u32 *result;
 	int ret = 0;
 
+	/* Export the intermediate digest to program into SA2UL */
+	ret = crypto_shash_export(hash, state);
+	if (ret) {
+		dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
+			__func__);
+		return ret;
+	}
+
 	switch (digest_size) {
 	case SHA1_DIGEST_SIZE:
 		sha1 = state;
@@ -415,13 +423,6 @@ static int sa_export_shash(void *state, struct shash_desc *hash,
 		return -EINVAL;
 	}
 
-	ret = crypto_shash_export(hash, state);
-	if (ret) {
-		dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
-			__func__);
-		return ret;
-	}
-
 	cpu_to_be32_array(out, result, digest_size / 4);
 
 	return ret;

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (21 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 22/30] crypto: sa2ul - move export to appropriate location Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-17 10:13   ` T Pratham
  2026-09-15  9:55 ` [PATCH 24/30] crypto: sa2ul - add more checks before processing ipad/opad Manorit Chawdhry
                   ` (7 subsequent siblings)
  30 siblings, 1 reply; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The sa_export_shash() function uses a fixed-size stack union to hold
the hash state during export. This union was sized at 104 bytes,
covering sha1_state and sha256_state but no longer including
sha512_state as it did when the AEAD support was first added, leaving
zero margin once crypto_shash_export() needs to write more than 104
bytes:

  BUG: KASAN: stack-out-of-bounds in __crypto_sha256_export.isra.0+0xf4/0x138
  Write of size 1 at addr ffff800084c46d78 by task cryptomgr_test/219
  Hardware name: Texas Instruments J721S2 EVM (DT)
  Call trace:
   show_stack+0x18/0x24 (C)
   dump_stack_lvl+0x68/0x94
   print_report+0x118/0x200
   kasan_report+0xa8/0xe4
   __asan_store1
   __crypto_sha256_export.isra.0
   crypto_sha256_export
   __crypto_shash_export
   crypto_shash_export
   sa_export_shash+0xa4/0x198
   sa_prepare_iopads+0x234/0x460
   sa_init_sc+0x268/0x730
   sa_aead_setkey+0x20c/0x390
   sa_aead_cbc_sha256_setkey+0xa4/0xe4
   crypto_aead_setkey
   test_aead_vec_cfg
   test_aead_vec
   alg_test_aead
  The buggy address belongs to stack of task cryptomgr_test/219,
  offset 152 in frame: sa_export_shash+0x0/0x198
  This frame has 1 object: [48, 152) 'sha'

This reproduced on every board tested (311 occurrences on a single
J721S2 EVM boot log alone), always via the authenc(hmac(sha256),
cbc(aes))-sa2ul AEAD self-test. It surfaced after upstream sha256
changes (e.g. commit 3bf533787910 ("crypto: sha256 - Use the partial
block API")) altered which sha256 shash implementation gets selected
for hmac(sha256), but the underlying union has been undersized ever
since it was shrunk to drop sha512_state.

Fix this by replacing the fixed-size stack union with a dynamically
allocated buffer sized via crypto_shash_statesize(). This ensures the
buffer is always large enough for the current hash algorithm's state,
regardless of future changes to the state structures. The buffer is
allocated with kmalloc(GFP_KERNEL) and freed with kfree_sensitive() on
all exit paths to prevent information leakage.

Fixes: ad0bb4e4d226 ("crypto: sa2ul - Reduce stack usage")
Assisted-by: Sisyphus:claude-sonnet-5
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 52 +++++++++++++++++++++++++++++---------------------
 1 file changed, 30 insertions(+), 22 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 36c8403b5713..265d1afaad81 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -18,6 +18,7 @@
 #include <linux/of_platform.h>
 #include <linux/platform_device.h>
 #include <linux/pm_runtime.h>
+#include <linux/slab.h>
 
 #include <crypto/aes.h>
 #include <crypto/authenc.h>
@@ -392,39 +393,51 @@ static void prepare_kopad(u8 *k_opad, const u8 *key, u16 key_sz)
 		k_opad[i] = 0x5c;
 }
 
-static int sa_export_shash(void *state, struct shash_desc *hash,
-			   int digest_size, __be32 *out)
+static int sa_export_shash(struct shash_desc *hash, int digest_size,
+			   __be32 *out)
 {
-	struct sha1_state *sha1;
-	struct sha256_state *sha256;
 	u32 *result;
 	int ret = 0;
+	int state_size;
+	u8 *sha;
+
+	state_size = crypto_shash_statesize(hash->tfm);
+	if (state_size <= 0) {
+		dev_err(sa_k3_dev, "%s: invalid state_size=%d\n", __func__,
+			state_size);
+		return -EINVAL;
+	}
+
+	sha = kmalloc(state_size, GFP_KERNEL);
+	if (!sha)
+		return -ENOMEM;
 
 	/* Export the intermediate digest to program into SA2UL */
-	ret = crypto_shash_export(hash, state);
+	ret = crypto_shash_export(hash, sha);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
 			__func__);
+		kfree_sensitive(sha);
 		return ret;
 	}
 
 	switch (digest_size) {
 	case SHA1_DIGEST_SIZE:
-		sha1 = state;
-		result = sha1->state;
+		result = (u32 *)sha;
 		break;
 	case SHA256_DIGEST_SIZE:
-		sha256 = state;
-		result = sha256->state;
+		result = (u32 *)sha;
 		break;
 	default:
 		dev_err(sa_k3_dev, "%s: bad digest_size=%d\n", __func__,
 			digest_size);
+		kfree_sensitive(sha);
 		return -EINVAL;
 	}
 
 	cpu_to_be32_array(out, result, digest_size / 4);
 
+	kfree_sensitive(sha);
 	return ret;
 }
 
@@ -435,16 +448,11 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 	int block_size = crypto_shash_blocksize(data->ctx->shash);
 	int digest_size = crypto_shash_digestsize(data->ctx->shash);
 	int ret = 0;
-
-	union {
-		struct sha1_state sha1;
-		struct sha256_state sha256;
-		u8 k_pad[SHA1_BLOCK_SIZE];
-	} sha;
+	u8 k_pad[SHA1_BLOCK_SIZE];
 
 	shash->tfm = data->ctx->shash;
 
-	prepare_kipad(sha.k_pad, key, key_sz);
+	prepare_kipad(k_pad, key, key_sz);
 
 	ret = crypto_shash_init(shash);
 	if (ret) {
@@ -452,20 +460,20 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = crypto_shash_update(shash, sha.k_pad, block_size);
+	ret = crypto_shash_update(shash, k_pad, block_size);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for ipad failed, ret=%d\n",
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = sa_export_shash(&sha, shash, digest_size, ipad);
+	ret = sa_export_shash(shash, digest_size, ipad);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: sa_export_shash for ipad failed, ret=%d\n",
 			__func__, __LINE__, ret);
 		return ret;
 	}
 
-	prepare_kopad(sha.k_pad, key, key_sz);
+	prepare_kopad(k_pad, key, key_sz);
 
 	ret = crypto_shash_init(shash);
 	if (ret) {
@@ -473,20 +481,20 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = crypto_shash_update(shash, sha.k_pad, block_size);
+	ret = crypto_shash_update(shash, k_pad, block_size);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for opad failed, ret=%d\n",
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = sa_export_shash(&sha, shash, digest_size, opad);
+	ret = sa_export_shash(shash, digest_size, opad);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: sa_export_shash for opad failed, ret=%d\n",
 			__func__, __LINE__, ret);
 		return ret;
 	}
 
-	memzero_explicit(&sha, sizeof(sha));
+	memzero_explicit(k_pad, SHA1_BLOCK_SIZE);
 
 	return ret;
 }

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 24/30] crypto: sa2ul - add more checks before processing ipad/opad
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (22 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 25/30] crypto: sa2ul - fix data corruption by skipping device sync on unmap Manorit Chawdhry
                   ` (6 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

When the key_sz is greater than the block_size then we need to hash it
with the transform to process it further. To avoid repeated hashing for
the key for individual ipad/opad, merge the prepare_kipad and
prepare_kopad in sa_prepare_iopad itself.

Also as per fips standard, there is a minimum key size requirement so
check that based on fips enablement to return the appropriate error
code.

Since the framework doesn't provide the intermediate hash, replicate the
checks of the framework and make sa2ul code similar to that.

Fixes: d2c8ac187fc9 ("crypto: sa2ul - Add AEAD algorithm support")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 63 +++++++++++++++++++++++++-------------------------
 1 file changed, 31 insertions(+), 32 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 265d1afaad81..cd5cd9182bdb 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -12,6 +12,7 @@
 #include <linux/dma-mapping.h>
 #include <linux/dmaengine.h>
 #include <linux/dmapool.h>
+#include <linux/fips.h>
 #include <linux/kernel.h>
 #include <linux/module.h>
 #include <linux/of.h>
@@ -24,6 +25,7 @@
 #include <crypto/authenc.h>
 #include <crypto/utils.h>
 #include <crypto/des.h>
+#include <crypto/hmac.h>
 #include <crypto/internal/aead.h>
 #include <crypto/internal/hash.h>
 #include <crypto/internal/skcipher.h>
@@ -368,31 +370,6 @@ static void sa_swiz_128(u8 *in, u16 len)
 	}
 }
 
-/* Prepare the ipad and opad from key as per SHA algorithm step 1*/
-static void prepare_kipad(u8 *k_ipad, const u8 *key, u16 key_sz)
-{
-	int i;
-
-	for (i = 0; i < key_sz; i++)
-		k_ipad[i] = key[i] ^ 0x36;
-
-	/* Instead of XOR with 0 */
-	for (; i < SHA1_BLOCK_SIZE; i++)
-		k_ipad[i] = 0x36;
-}
-
-static void prepare_kopad(u8 *k_opad, const u8 *key, u16 key_sz)
-{
-	int i;
-
-	for (i = 0; i < key_sz; i++)
-		k_opad[i] = key[i] ^ 0x5c;
-
-	/* Instead of XOR with 0 */
-	for (; i < SHA1_BLOCK_SIZE; i++)
-		k_opad[i] = 0x5c;
-}
-
 static int sa_export_shash(struct shash_desc *hash, int digest_size,
 			   __be32 *out)
 {
@@ -448,11 +425,34 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 	int block_size = crypto_shash_blocksize(data->ctx->shash);
 	int digest_size = crypto_shash_digestsize(data->ctx->shash);
 	int ret = 0;
-	u8 k_pad[SHA1_BLOCK_SIZE];
+	int i = 0;
+	u8 k_ipad[SHA1_BLOCK_SIZE];
+	u8 k_opad[SHA1_BLOCK_SIZE];
+
+	if (fips_enabled && (key_sz < 112 / 8))
+		return -EINVAL;
 
 	shash->tfm = data->ctx->shash;
 
-	prepare_kipad(k_pad, key, key_sz);
+	if (key_sz > block_size) {
+		int err;
+
+		err = crypto_shash_digest(shash, key, key_sz, k_ipad);
+		if (err)
+			return err;
+
+		key_sz = digest_size;
+	} else {
+		memcpy(k_ipad, key, key_sz);
+	}
+
+	memset(k_ipad + key_sz, 0, block_size - key_sz);
+	memcpy(k_opad, k_ipad, block_size);
+
+	for (i = 0; i < block_size; i++) {
+		k_ipad[i] ^= HMAC_IPAD_VALUE;
+		k_opad[i] ^= HMAC_OPAD_VALUE;
+	}
 
 	ret = crypto_shash_init(shash);
 	if (ret) {
@@ -460,7 +460,7 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = crypto_shash_update(shash, k_pad, block_size);
+	ret = crypto_shash_update(shash, k_ipad, block_size);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for ipad failed, ret=%d\n",
 			__func__, __LINE__, ret);
@@ -473,15 +473,13 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 		return ret;
 	}
 
-	prepare_kopad(k_pad, key, key_sz);
-
 	ret = crypto_shash_init(shash);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: crypto_shash_init for opad failed, ret=%d\n",
 			__func__, __LINE__, ret);
 		return ret;
 	}
-	ret = crypto_shash_update(shash, k_pad, block_size);
+	ret = crypto_shash_update(shash, k_opad, block_size);
 	if (ret) {
 		dev_err(sa_k3_dev, "%s: %d: crypto_shash_update for opad failed, ret=%d\n",
 			__func__, __LINE__, ret);
@@ -494,7 +492,8 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 		return ret;
 	}
 
-	memzero_explicit(k_pad, SHA1_BLOCK_SIZE);
+	memzero_explicit(k_ipad, SHA1_BLOCK_SIZE);
+	memzero_explicit(k_opad, SHA1_BLOCK_SIZE);
 
 	return ret;
 }

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 25/30] crypto: sa2ul - fix data corruption by skipping device sync on unmap
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (23 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 24/30] crypto: sa2ul - add more checks before processing ipad/opad Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 26/30] crypto: sa2ul - use correct DMA direction in sa_sync_from_device Manorit Chawdhry
                   ` (5 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The sa_free_sa_rx_data() function is called after explicitly syncing
DMA buffers to CPU via sa_sync_from_device(). Between the sync and
unmap, the DMA completion callbacks read and modify the buffer contents
to extract results.

Without DMA_ATTR_SKIP_CPU_SYNC, dma_unmap_sgtable() performs a
device-to-CPU cache sync, which invalidates the CPU cache and
overwrites the CPU's modifications with stale device data. This
causes data corruption where processed results are lost.

Add DMA_ATTR_SKIP_CPU_SYNC to keep the buffer in CPU domain after
the explicit sync, preventing the unmap operation from corrupting
the modified data.

Fixes: 00c9211f60db ("crypto: sa2ul - Fix DMA mapping API usage")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index cd5cd9182bdb..5e0ef12eb02b 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1059,7 +1059,7 @@ static void sa_free_sa_rx_data(struct sa_rx_data *rxd)
 
 		if (mapped_sg->mapped) {
 			dma_unmap_sgtable(rxd->ddev, &mapped_sg->sgt,
-					  mapped_sg->dir, 0);
+					  mapped_sg->dir, DMA_ATTR_SKIP_CPU_SYNC);
 			kfree(mapped_sg->split_sg);
 		}
 	}

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 26/30] crypto: sa2ul - use correct DMA direction in sa_sync_from_device
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (24 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 25/30] crypto: sa2ul - fix data corruption by skipping device sync on unmap Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 27/30] crypto: sa2ul - change dma_alloc_pool to mempool Manorit Chawdhry
                   ` (4 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

Use correct DMA direction during sa_sync_from_device for proper
cache coherency handling.

Fixes: 00c9211f60db ("crypto: sa2ul - Fix DMA mapping API usage")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 5e0ef12eb02b..df905b391339 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -1041,13 +1041,17 @@ static int sa_3des_ecb_setkey(struct crypto_skcipher *tfm, const u8 *key,
 static void sa_sync_from_device(struct sa_rx_data *rxd)
 {
 	struct sg_table *sgt;
+	u32 dir;
 
-	if (rxd->mapped_sg[0].dir == DMA_BIDIRECTIONAL)
+	if (rxd->mapped_sg[0].dir == DMA_BIDIRECTIONAL) {
 		sgt = &rxd->mapped_sg[0].sgt;
-	else
+		dir = rxd->mapped_sg[0].dir;
+	} else {
 		sgt = &rxd->mapped_sg[1].sgt;
+		dir = rxd->mapped_sg[1].dir;
+	}
 
-	dma_sync_sgtable_for_cpu(rxd->ddev, sgt, DMA_FROM_DEVICE);
+	dma_sync_sgtable_for_cpu(rxd->ddev, sgt, dir);
 }
 
 static void sa_free_sa_rx_data(struct sa_rx_data *rxd)

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 27/30] crypto: sa2ul - change dma_alloc_pool to mempool
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (25 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 26/30] crypto: sa2ul - use correct DMA direction in sa_sync_from_device Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine Manorit Chawdhry
                   ` (3 subsequent siblings)
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The SA2UL engine is a DMA master, so any memory it accesses must either
be allocated coherent or be explicitly synced with the CPU cache around
each access.

The security context buffer is currently allocated from a DMA pool via
dma_pool_alloc(), which assumes a coherent memory which is untrue at a
bus level for many of our SoCs. This causes any fetch issues from SA2UL
to end up getting some stale or unsynced data causing failures for any
crypto operations.

To remove this, allocate the security context from a kmalloc-backed
mempool instead. Since this memory is now ordinary cacheable kernel
memory, explicitly call dma_map_single()/dma_unmap_single() for DMA
related operations.

Fixes: 7694b6ca649f ("crypto: sa2ul - Add crypto driver")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 23 +++++++++++++++++------
 drivers/crypto/sa2ul.h |  2 +-
 2 files changed, 18 insertions(+), 7 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index df905b391339..cadc8db14bbb 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -14,6 +14,7 @@
 #include <linux/dmapool.h>
 #include <linux/fips.h>
 #include <linux/kernel.h>
+#include <linux/mempool.h>
 #include <linux/module.h>
 #include <linux/of.h>
 #include <linux/of_platform.h>
@@ -741,6 +742,9 @@ int sa_init_sc(struct sa_ctx_info *ctx, const struct sa_match_data *match_data,
 	       const u8 *auth_key, u16 auth_key_sz,
 	       struct algo_data *ad, u8 enc, u32 *swinfo)
 {
+	struct sa_crypto_data *data = dev_get_drvdata(sa_k3_dev);
+	struct device *dev = &data->pdev->dev;
+
 	int enc_sc_offset = 0;
 	int auth_sc_offset = 0;
 	u8 *sc_buf = ctx->sc;
@@ -802,6 +806,12 @@ int sa_init_sc(struct sa_ctx_info *ctx, const struct sa_match_data *match_data,
 	/* swizzle the security context */
 	sa_swiz_128(sc_buf, SA_CTX_MAX_SZ);
 
+	ctx->sc_phys = dma_map_single(dev, ctx->sc, SA_CTX_MAX_SZ, DMA_BIDIRECTIONAL);
+	if (dma_mapping_error(dev, ctx->sc_phys)) {
+		mempool_free(ctx->sc, data->sc_pool);
+		return -ENOMEM;
+	}
+
 	sa_set_swinfo(first_engine, ctx->sc_id, ctx->sc_phys, 1, 0,
 		      SA_SW_INFO_FLAG_EVICT, ad->hash_size, swinfo);
 
@@ -814,6 +824,7 @@ int sa_init_sc(struct sa_ctx_info *ctx, const struct sa_match_data *match_data,
 static void sa_free_ctx_info(struct sa_ctx_info *ctx,
 			     struct sa_crypto_data *data)
 {
+	struct device *dev = &data->pdev->dev;
 	unsigned long bn;
 
 	bn = ctx->sc_id;
@@ -824,7 +835,8 @@ static void sa_free_ctx_info(struct sa_ctx_info *ctx,
 
 	if (ctx->sc) {
 		memzero_explicit(ctx->sc, SA_CTX_MAX_SZ);
-		dma_pool_free(data->sc_pool, ctx->sc, ctx->sc_phys);
+		dma_unmap_single(dev, ctx->sc_phys, SA_CTX_MAX_SZ, DMA_BIDIRECTIONAL);
+		mempool_free(ctx->sc, data->sc_pool);
 		ctx->sc = NULL;
 	}
 }
@@ -843,7 +855,7 @@ static int sa_init_ctx_info(struct sa_ctx_info *ctx,
 
 	ctx->sc_id = (u16)bn;
 
-	ctx->sc = dma_pool_alloc(data->sc_pool, GFP_KERNEL, &ctx->sc_phys);
+	ctx->sc = mempool_alloc(data->sc_pool, GFP_KERNEL);
 	if (!ctx->sc) {
 		dev_err(&data->pdev->dev, "Failed to allocate SC memory\n");
 		err = -ENOMEM;
@@ -2244,8 +2256,7 @@ static int sa_init_mem(struct sa_crypto_data *dev_data)
 {
 	struct device *dev = &dev_data->pdev->dev;
 	/* Setup dma pool for security context buffers */
-	dev_data->sc_pool = dma_pool_create("keystone-sc", dev,
-					    SA_CTX_MAX_SZ, 64, 0);
+	dev_data->sc_pool = mempool_create_kmalloc_pool(64, SA_CTX_MAX_SZ);
 	if (!dev_data->sc_pool) {
 		dev_err(dev, "Failed to create dma pool");
 		return -ENOMEM;
@@ -2439,7 +2450,7 @@ static int sa_ul_probe(struct platform_device *pdev)
 	dma_release_channel(dev_data->dma_tx);
 
 destroy_dma_pool:
-	dma_pool_destroy(dev_data->sc_pool);
+	mempool_destroy(dev_data->sc_pool);
 
 disable_pm:
 	pm_runtime_put_sync(dev);
@@ -2460,7 +2471,7 @@ static void sa_ul_remove(struct platform_device *pdev)
 	dma_release_channel(dev_data->dma_rx1);
 	dma_release_channel(dev_data->dma_tx);
 
-	dma_pool_destroy(dev_data->sc_pool);
+	mempool_destroy(dev_data->sc_pool);
 
 	platform_set_drvdata(pdev, NULL);
 
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index fbea98981f10..7ca385e908cc 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -163,7 +163,7 @@ struct sa_match_data;
 struct sa_crypto_data {
 	const struct sa_match_data *match_data;
 	struct platform_device	*pdev;
-	struct dma_pool		*sc_pool;
+	mempool_t		*sc_pool;
 	struct device *dev;
 	spinlock_t	scid_lock; /* lock for SC-ID allocation */
 	/* Security context data */

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (26 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 27/30] crypto: sa2ul - change dma_alloc_pool to mempool Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-17 10:05   ` T Pratham
  2026-09-15  9:55 ` [PATCH 29/30] crypto: sa2ul - report SA engine hardware revision Manorit Chawdhry
                   ` (2 subsequent siblings)
  30 siblings, 1 reply; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

SA2UL previously submitted skcipher, ahash, and aead requests directly
from crypto_alg callbacks. This mixes sleepable and atomic request
contexts on the same hardware queue and gives concurrent callers no
serialization against the single security accelerator.

Register a struct crypto_engine per SA2UL instance and convert each
skcipher/ahash/aead algorithm to submit through
crypto_transfer_{skcipher,hash,aead}_request_to_engine() with a
matching do_one_request() callback. The engine now serializes all HW
submissions to SA2UL, so requests from different contexts no longer
race on the same crypto accelerator queue.

Select CRYPTO_ENGINE in Kconfig and add engine allocation/start in
probe and engine_exit in the remove/error paths.

Fixes: 7694b6ca649f ("crypto: sa2ul - Add crypto driver")
Assisted-by: Sisyphus:claude-sonnet-4-6
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/Kconfig |   1 +
 drivers/crypto/sa2ul.c | 536 +++++++++++++++++++++++++++++--------------------
 drivers/crypto/sa2ul.h |  22 ++
 3 files changed, 339 insertions(+), 220 deletions(-)

diff --git a/drivers/crypto/Kconfig b/drivers/crypto/Kconfig
index 0189dfdcbbe1..c9596f0c9087 100644
--- a/drivers/crypto/Kconfig
+++ b/drivers/crypto/Kconfig
@@ -816,6 +816,7 @@ config CRYPTO_DEV_SA2UL
 	select CRYPTO_ALGAPI
 	select CRYPTO_AUTHENC
 	select CRYPTO_DES
+	select CRYPTO_ENGINE
 	select CRYPTO_SHA1
 	select CRYPTO_SHA256
 	select CRYPTO_SHA512
diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index cadc8db14bbb..d92ba1f581c0 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -33,6 +33,7 @@
 #include <crypto/scatterwalk.h>
 #include <crypto/sha1.h>
 #include <crypto/sha2.h>
+#include <crypto/engine.h>
 
 #include "sa2ul.h"
 
@@ -150,9 +151,9 @@ struct algo_data {
 struct sa_alg_tmpl {
 	u32 type;		/* CRYPTO_ALG_TYPE from <linux/crypto.h> */
 	union {
-		struct skcipher_alg skcipher;
-		struct ahash_alg ahash;
-		struct aead_alg aead;
+		struct skcipher_engine_alg skcipher;
+		struct ahash_engine_alg ahash;
+		struct aead_engine_alg aead;
 	} alg;
 	bool registered;
 };
@@ -914,8 +915,8 @@ static int sa_cipher_cra_init(struct crypto_skcipher *tfm)
 	}
 
 	ctx->fallback.skcipher = child;
-	crypto_skcipher_set_reqsize(tfm, crypto_skcipher_reqsize(child) +
-					 sizeof(struct skcipher_request));
+	crypto_skcipher_set_reqsize(tfm, sizeof(struct sa_cipher_req_ctx) +
+					 crypto_skcipher_reqsize(child));
 
 	dev_dbg(sa_k3_dev, "%s(0x%p) sc-ids(0x%x(0x%pad), 0x%x(0x%pad))\n",
 		__func__, tfm, ctx->enc.sc_id, &ctx->enc.sc_phys,
@@ -1086,6 +1087,7 @@ static void sa_free_sa_rx_data(struct sa_rx_data *rxd)
 static void sa_aes_dma_in_callback(void *data)
 {
 	struct sa_rx_data *rxd = data;
+	struct sa_crypto_data *pdata = dev_get_drvdata(sa_k3_dev);
 	struct skcipher_request *req;
 	u32 *result;
 	__be32 *mdptr;
@@ -1106,7 +1108,7 @@ static void sa_aes_dma_in_callback(void *data)
 
 	sa_free_sa_rx_data(rxd);
 
-	skcipher_request_complete(req, 0);
+	crypto_finalize_skcipher_request(pdata->engine, req, 0);
 }
 
 static int
@@ -1337,12 +1339,19 @@ static int sa_run(struct sa_req *req)
 	return ret;
 }
 
-static int sa_cipher_run(struct skcipher_request *req, u8 *iv, int enc)
+static int sa_run_one(struct sa_req *req)
+{
+	int ret = sa_run(req);
+
+	return ret == -EINPROGRESS ? 0 : ret;
+}
+
+static int sa_cipher_run(struct skcipher_request *req, int enc)
 {
 	struct sa_tfm_ctx *ctx =
 	    crypto_skcipher_ctx(crypto_skcipher_reqtfm(req));
 	struct crypto_alg *alg = req->base.tfm->__crt_alg;
-	struct sa_req sa_req = { 0 };
+	struct sa_cipher_req_ctx *rctx = skcipher_request_ctx(req);
 
 	if (!req->cryptlen)
 		return 0;
@@ -1354,7 +1363,7 @@ static int sa_cipher_run(struct skcipher_request *req, u8 *iv, int enc)
 	if (req->cryptlen > SA_MAX_DATA_SZ ||
 	    (req->cryptlen >= SA_UNSAFE_DATA_SZ_MIN &&
 	     req->cryptlen <= SA_UNSAFE_DATA_SZ_MAX)) {
-		struct skcipher_request *subreq = skcipher_request_ctx(req);
+		struct skcipher_request *subreq = &rctx->fallback_req;
 
 		skcipher_request_set_tfm(subreq, ctx->fallback.skcipher);
 		skcipher_request_set_callback(subreq, req->base.flags,
@@ -1368,33 +1377,46 @@ static int sa_cipher_run(struct skcipher_request *req, u8 *iv, int enc)
 			return crypto_skcipher_decrypt(subreq);
 	}
 
+	rctx->enc = enc;
+
+	return crypto_transfer_skcipher_request_to_engine(ctx->dev_data->engine, req);
+}
+
+static int sa_cipher_do_one_req(struct crypto_engine *engine, void *areq)
+{
+	struct skcipher_request *req = container_of(areq, struct skcipher_request, base);
+	struct sa_tfm_ctx *ctx = crypto_skcipher_ctx(crypto_skcipher_reqtfm(req));
+	struct sa_cipher_req_ctx *rctx = skcipher_request_ctx(req);
+	struct sa_req sa_req = { 0 };
+
 	sa_req.size = req->cryptlen;
 	sa_req.enc_size = req->cryptlen;
 	sa_req.src = req->src;
 	sa_req.dst = req->dst;
-	sa_req.enc_iv = iv;
+	sa_req.enc_iv = req->iv;
 	sa_req.type = CRYPTO_ALG_TYPE_SKCIPHER;
-	sa_req.enc = enc;
+	sa_req.enc = rctx->enc;
 	sa_req.callback = sa_aes_dma_in_callback;
 	sa_req.base = &req->base;
 	sa_req.ctx = ctx;
 
-	return sa_run(&sa_req);
+	return sa_run_one(&sa_req);
 }
 
 static int sa_encrypt(struct skcipher_request *req)
 {
-	return sa_cipher_run(req, req->iv, 1);
+	return sa_cipher_run(req, 1);
 }
 
 static int sa_decrypt(struct skcipher_request *req)
 {
-	return sa_cipher_run(req, req->iv, 0);
+	return sa_cipher_run(req, 0);
 }
 
 static void sa_sha_dma_in_callback(void *data)
 {
 	struct sa_rx_data *rxd = data;
+	struct sa_crypto_data *pdata = dev_get_drvdata(sa_k3_dev);
 	struct ahash_request *req;
 	struct crypto_ahash *tfm;
 	unsigned int authsize;
@@ -1416,7 +1438,7 @@ static void sa_sha_dma_in_callback(void *data)
 
 	sa_free_sa_rx_data(rxd);
 
-	ahash_request_complete(req, 0);
+	crypto_finalize_hash_request(pdata->engine, req, 0);
 }
 
 static int zero_message_process(struct ahash_request *req)
@@ -1445,7 +1467,6 @@ static int sa_sha_run(struct ahash_request *req)
 {
 	struct sa_tfm_ctx *ctx = crypto_ahash_ctx(crypto_ahash_reqtfm(req));
 	struct sa_sha_req_ctx *rctx = ahash_request_ctx(req);
-	struct sa_req sa_req = { 0 };
 	size_t auth_len;
 
 	auth_len = req->nbytes;
@@ -1468,8 +1489,17 @@ static int sa_sha_run(struct ahash_request *req)
 		return ret;
 	}
 
-	sa_req.size = auth_len;
-	sa_req.auth_size = auth_len;
+	return crypto_transfer_hash_request_to_engine(ctx->dev_data->engine, req);
+}
+
+static int sa_sha_do_one_req(struct crypto_engine *engine, void *areq)
+{
+	struct ahash_request *req = container_of(areq, struct ahash_request, base);
+	struct sa_tfm_ctx *ctx = crypto_ahash_ctx(crypto_ahash_reqtfm(req));
+	struct sa_req sa_req = { 0 };
+
+	sa_req.size = req->nbytes;
+	sa_req.auth_size = req->nbytes;
 	sa_req.src = req->src;
 	sa_req.dst = req->src;
 	sa_req.enc = true;
@@ -1478,7 +1508,7 @@ static int sa_sha_run(struct ahash_request *req)
 	sa_req.ctx = ctx;
 	sa_req.base = &req->base;
 
-	return sa_run(&sa_req);
+	return sa_run_one(&sa_req);
 }
 
 static int sa_sha_setup(struct sa_tfm_ctx *ctx, struct  algo_data *ad)
@@ -1689,6 +1719,7 @@ static void sa_sha_cra_exit(struct crypto_tfm *tfm)
 static void sa_aead_dma_in_callback(void *data)
 {
 	struct sa_rx_data *rxd = data;
+	struct sa_crypto_data *pdata = dev_get_drvdata(sa_k3_dev);
 	struct aead_request *req;
 	struct crypto_aead *tfm;
 	unsigned int start;
@@ -1722,7 +1753,7 @@ static void sa_aead_dma_in_callback(void *data)
 
 	sa_free_sa_rx_data(rxd);
 
-	aead_request_complete(req, err);
+	crypto_finalize_aead_request(pdata->engine, req, err);
 }
 
 static int sa_cra_init_aead(struct crypto_aead *tfm, const char *hash,
@@ -1751,7 +1782,7 @@ static int sa_cra_init_aead(struct crypto_aead *tfm, const char *hash,
 		return PTR_ERR(ctx->fallback.aead);
 	}
 
-	crypto_aead_set_reqsize(tfm, sizeof(struct aead_request) +
+	crypto_aead_set_reqsize(tfm, sizeof(struct sa_aead_req_ctx) +
 				crypto_aead_reqsize(ctx->fallback.aead));
 
 	ret = sa_init_ctx_info(&ctx->enc, data);
@@ -1897,11 +1928,11 @@ static int sa_aead_cbc_sha256_setkey(struct crypto_aead *authenc,
 	return sa_aead_setkey(authenc, key, keylen, &ad);
 }
 
-static int sa_aead_run(struct aead_request *req, u8 *iv, int enc)
+static int sa_aead_run(struct aead_request *req, int enc)
 {
 	struct crypto_aead *tfm = crypto_aead_reqtfm(req);
 	struct sa_tfm_ctx *ctx = crypto_aead_ctx(tfm);
-	struct sa_req sa_req = { 0 };
+	struct sa_aead_req_ctx *rctx = aead_request_ctx(req);
 	size_t auth_size, enc_size;
 
 	enc_size = req->cryptlen;
@@ -1915,7 +1946,7 @@ static int sa_aead_run(struct aead_request *req, u8 *iv, int enc)
 	if (auth_size > SA_MAX_DATA_SZ ||
 	    (auth_size >= SA_UNSAFE_DATA_SZ_MIN &&
 	     auth_size <= SA_UNSAFE_DATA_SZ_MAX)) {
-		struct aead_request *subreq = aead_request_ctx(req);
+		struct aead_request *subreq = &rctx->fallback_req;
 		int ret;
 
 		aead_request_set_tfm(subreq, ctx->fallback.aead);
@@ -1930,265 +1961,314 @@ static int sa_aead_run(struct aead_request *req, u8 *iv, int enc)
 		return ret;
 	}
 
+	rctx->enc = enc;
+
+	return crypto_transfer_aead_request_to_engine(ctx->dev_data->engine, req);
+}
+
+static int sa_aead_do_one_req(struct crypto_engine *engine, void *areq)
+{
+	struct aead_request *req = container_of(areq, struct aead_request, base);
+	struct crypto_aead *tfm = crypto_aead_reqtfm(req);
+	struct sa_tfm_ctx *ctx = crypto_aead_ctx(tfm);
+	struct sa_aead_req_ctx *rctx = aead_request_ctx(req);
+	struct sa_req sa_req = { 0 };
+	size_t auth_size, enc_size;
+
+	enc_size = req->cryptlen;
+	auth_size = req->assoclen + req->cryptlen;
+
+	if (!rctx->enc) {
+		enc_size -= crypto_aead_authsize(tfm);
+		auth_size -= crypto_aead_authsize(tfm);
+	}
+
 	sa_req.enc_offset = req->assoclen;
 	sa_req.enc_size = enc_size;
 	sa_req.auth_size = auth_size;
 	sa_req.size = auth_size;
-	sa_req.enc_iv = iv;
+	sa_req.enc_iv = req->iv;
 	sa_req.type = CRYPTO_ALG_TYPE_AEAD;
-	sa_req.enc = enc;
+	sa_req.enc = rctx->enc;
 	sa_req.callback = sa_aead_dma_in_callback;
 	sa_req.base = &req->base;
 	sa_req.ctx = ctx;
 	sa_req.src = req->src;
 	sa_req.dst = req->dst;
 
-	return sa_run(&sa_req);
+	return sa_run_one(&sa_req);
 }
 
 /* AEAD algorithm encrypt interface function */
 static int sa_aead_encrypt(struct aead_request *req)
 {
-	return sa_aead_run(req, req->iv, 1);
+	return sa_aead_run(req, 1);
 }
 
 /* AEAD algorithm decrypt interface function */
 static int sa_aead_decrypt(struct aead_request *req)
 {
-	return sa_aead_run(req, req->iv, 0);
+	return sa_aead_run(req, 0);
 }
 
 static struct sa_alg_tmpl sa_algs[] = {
 	[SA_ALG_CBC_AES] = {
 		.type = CRYPTO_ALG_TYPE_SKCIPHER,
 		.alg.skcipher = {
-			.base.cra_name		= "cbc(aes)",
-			.base.cra_driver_name	= "cbc-aes-sa2ul",
-			.base.cra_priority	= 30000,
-			.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_NEED_FALLBACK,
-			.base.cra_blocksize	= AES_BLOCK_SIZE,
-			.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-			.base.cra_module	= THIS_MODULE,
-			.init			= sa_cipher_cra_init,
-			.exit			= sa_cipher_cra_exit,
-			.min_keysize		= AES_MIN_KEY_SIZE,
-			.max_keysize		= AES_MAX_KEY_SIZE,
-			.ivsize			= AES_BLOCK_SIZE,
-			.setkey			= sa_aes_cbc_setkey,
-			.encrypt		= sa_encrypt,
-			.decrypt		= sa_decrypt,
+			.base = {
+				.base.cra_name		= "cbc(aes)",
+				.base.cra_driver_name	= "cbc-aes-sa2ul",
+				.base.cra_priority	= 30000,
+				.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_NEED_FALLBACK,
+				.base.cra_blocksize	= AES_BLOCK_SIZE,
+				.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+				.base.cra_module	= THIS_MODULE,
+				.init			= sa_cipher_cra_init,
+				.exit			= sa_cipher_cra_exit,
+				.min_keysize		= AES_MIN_KEY_SIZE,
+				.max_keysize		= AES_MAX_KEY_SIZE,
+				.ivsize			= AES_BLOCK_SIZE,
+				.setkey			= sa_aes_cbc_setkey,
+				.encrypt		= sa_encrypt,
+				.decrypt		= sa_decrypt,
+			},
+			.op.do_one_request = sa_cipher_do_one_req,
 		}
 	},
 	[SA_ALG_EBC_AES] = {
 		.type = CRYPTO_ALG_TYPE_SKCIPHER,
 		.alg.skcipher = {
-			.base.cra_name		= "ecb(aes)",
-			.base.cra_driver_name	= "ecb-aes-sa2ul",
-			.base.cra_priority	= 30000,
-			.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_NEED_FALLBACK,
-			.base.cra_blocksize	= AES_BLOCK_SIZE,
-			.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-			.base.cra_module	= THIS_MODULE,
-			.init			= sa_cipher_cra_init,
-			.exit			= sa_cipher_cra_exit,
-			.min_keysize		= AES_MIN_KEY_SIZE,
-			.max_keysize		= AES_MAX_KEY_SIZE,
-			.setkey			= sa_aes_ecb_setkey,
-			.encrypt		= sa_encrypt,
-			.decrypt		= sa_decrypt,
+			.base = {
+				.base.cra_name		= "ecb(aes)",
+				.base.cra_driver_name	= "ecb-aes-sa2ul",
+				.base.cra_priority	= 30000,
+				.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_NEED_FALLBACK,
+				.base.cra_blocksize	= AES_BLOCK_SIZE,
+				.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+				.base.cra_module	= THIS_MODULE,
+				.init			= sa_cipher_cra_init,
+				.exit			= sa_cipher_cra_exit,
+				.min_keysize		= AES_MIN_KEY_SIZE,
+				.max_keysize		= AES_MAX_KEY_SIZE,
+				.setkey			= sa_aes_ecb_setkey,
+				.encrypt		= sa_encrypt,
+				.decrypt		= sa_decrypt,
+			},
+			.op.do_one_request = sa_cipher_do_one_req,
 		}
 	},
 	[SA_ALG_CBC_DES3] = {
 		.type = CRYPTO_ALG_TYPE_SKCIPHER,
 		.alg.skcipher = {
-			.base.cra_name		= "cbc(des3_ede)",
-			.base.cra_driver_name	= "cbc-des3-sa2ul",
-			.base.cra_priority	= 30000,
-			.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_NEED_FALLBACK,
-			.base.cra_blocksize	= DES_BLOCK_SIZE,
-			.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-			.base.cra_module	= THIS_MODULE,
-			.init			= sa_cipher_cra_init,
-			.exit			= sa_cipher_cra_exit,
-			.min_keysize		= 3 * DES_KEY_SIZE,
-			.max_keysize		= 3 * DES_KEY_SIZE,
-			.ivsize			= DES_BLOCK_SIZE,
-			.setkey			= sa_3des_cbc_setkey,
-			.encrypt		= sa_encrypt,
-			.decrypt		= sa_decrypt,
+			.base = {
+				.base.cra_name		= "cbc(des3_ede)",
+				.base.cra_driver_name	= "cbc-des3-sa2ul",
+				.base.cra_priority	= 30000,
+				.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_NEED_FALLBACK,
+				.base.cra_blocksize	= DES_BLOCK_SIZE,
+				.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+				.base.cra_module	= THIS_MODULE,
+				.init			= sa_cipher_cra_init,
+				.exit			= sa_cipher_cra_exit,
+				.min_keysize		= 3 * DES_KEY_SIZE,
+				.max_keysize		= 3 * DES_KEY_SIZE,
+				.ivsize			= DES_BLOCK_SIZE,
+				.setkey			= sa_3des_cbc_setkey,
+				.encrypt		= sa_encrypt,
+				.decrypt		= sa_decrypt,
+			},
+			.op.do_one_request = sa_cipher_do_one_req,
 		}
 	},
 	[SA_ALG_ECB_DES3] = {
 		.type = CRYPTO_ALG_TYPE_SKCIPHER,
 		.alg.skcipher = {
-			.base.cra_name		= "ecb(des3_ede)",
-			.base.cra_driver_name	= "ecb-des3-sa2ul",
-			.base.cra_priority	= 30000,
-			.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_NEED_FALLBACK,
-			.base.cra_blocksize	= DES_BLOCK_SIZE,
-			.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-			.base.cra_module	= THIS_MODULE,
-			.init			= sa_cipher_cra_init,
-			.exit			= sa_cipher_cra_exit,
-			.min_keysize		= 3 * DES_KEY_SIZE,
-			.max_keysize		= 3 * DES_KEY_SIZE,
-			.setkey			= sa_3des_ecb_setkey,
-			.encrypt		= sa_encrypt,
-			.decrypt		= sa_decrypt,
+			.base = {
+				.base.cra_name		= "ecb(des3_ede)",
+				.base.cra_driver_name	= "ecb-des3-sa2ul",
+				.base.cra_priority	= 30000,
+				.base.cra_flags		= CRYPTO_ALG_TYPE_SKCIPHER |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_NEED_FALLBACK,
+				.base.cra_blocksize	= DES_BLOCK_SIZE,
+				.base.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+				.base.cra_module	= THIS_MODULE,
+				.init			= sa_cipher_cra_init,
+				.exit			= sa_cipher_cra_exit,
+				.min_keysize		= 3 * DES_KEY_SIZE,
+				.max_keysize		= 3 * DES_KEY_SIZE,
+				.setkey			= sa_3des_ecb_setkey,
+				.encrypt		= sa_encrypt,
+				.decrypt		= sa_decrypt,
+			},
+			.op.do_one_request = sa_cipher_do_one_req,
 		}
 	},
 	[SA_ALG_SHA1] = {
 		.type = CRYPTO_ALG_TYPE_AHASH,
 		.alg.ahash = {
-			.halg.base = {
-				.cra_name	= "sha1",
-				.cra_driver_name	= "sha1-sa2ul",
-				.cra_priority	= 400,
-				.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_NEED_FALLBACK,
-				.cra_blocksize	= SHA1_BLOCK_SIZE,
-				.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-				.cra_module	= THIS_MODULE,
-				.cra_init	= sa_sha1_cra_init,
-				.cra_exit	= sa_sha_cra_exit,
+			.base = {
+				.halg.base = {
+					.cra_name	= "sha1",
+					.cra_driver_name	= "sha1-sa2ul",
+					.cra_priority	= 400,
+					.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_NEED_FALLBACK,
+					.cra_blocksize	= SHA1_BLOCK_SIZE,
+					.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+					.cra_module	= THIS_MODULE,
+					.cra_init	= sa_sha1_cra_init,
+					.cra_exit	= sa_sha_cra_exit,
+				},
+				.halg.digestsize	= SHA1_DIGEST_SIZE,
+				.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
+							  sizeof(struct sha1_state),
+				.init			= sa_sha_init,
+				.update			= sa_sha_update,
+				.final			= sa_sha_final,
+				.finup			= sa_sha_finup,
+				.digest			= sa_sha_run,
+				.export			= sa_sha_export,
+				.import			= sa_sha_import,
 			},
-			.halg.digestsize	= SHA1_DIGEST_SIZE,
-			.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
-						  sizeof(struct sha1_state),
-			.init			= sa_sha_init,
-			.update			= sa_sha_update,
-			.final			= sa_sha_final,
-			.finup			= sa_sha_finup,
-			.digest			= sa_sha_run,
-			.export			= sa_sha_export,
-			.import			= sa_sha_import,
+			.op.do_one_request = sa_sha_do_one_req,
 		},
 	},
 	[SA_ALG_SHA256] = {
 		.type = CRYPTO_ALG_TYPE_AHASH,
 		.alg.ahash = {
-			.halg.base = {
-				.cra_name	= "sha256",
-				.cra_driver_name	= "sha256-sa2ul",
-				.cra_priority	= 400,
-				.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_NEED_FALLBACK,
-				.cra_blocksize	= SHA256_BLOCK_SIZE,
-				.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-				.cra_module	= THIS_MODULE,
-				.cra_init	= sa_sha256_cra_init,
-				.cra_exit	= sa_sha_cra_exit,
+			.base = {
+				.halg.base = {
+					.cra_name	= "sha256",
+					.cra_driver_name	= "sha256-sa2ul",
+					.cra_priority	= 400,
+					.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_NEED_FALLBACK,
+					.cra_blocksize	= SHA256_BLOCK_SIZE,
+					.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+					.cra_module	= THIS_MODULE,
+					.cra_init	= sa_sha256_cra_init,
+					.cra_exit	= sa_sha_cra_exit,
+				},
+				.halg.digestsize	= SHA256_DIGEST_SIZE,
+				.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
+							  sizeof(struct sha256_state),
+				.init			= sa_sha_init,
+				.update			= sa_sha_update,
+				.final			= sa_sha_final,
+				.finup			= sa_sha_finup,
+				.digest			= sa_sha_run,
+				.export			= sa_sha_export,
+				.import			= sa_sha_import,
 			},
-			.halg.digestsize	= SHA256_DIGEST_SIZE,
-			.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
-						  sizeof(struct sha256_state),
-			.init			= sa_sha_init,
-			.update			= sa_sha_update,
-			.final			= sa_sha_final,
-			.finup			= sa_sha_finup,
-			.digest			= sa_sha_run,
-			.export			= sa_sha_export,
-			.import			= sa_sha_import,
+			.op.do_one_request = sa_sha_do_one_req,
 		},
 	},
 	[SA_ALG_SHA512] = {
 		.type = CRYPTO_ALG_TYPE_AHASH,
 		.alg.ahash = {
-			.halg.base = {
-				.cra_name	= "sha512",
-				.cra_driver_name	= "sha512-sa2ul",
-				.cra_priority	= 400,
-				.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
-						  CRYPTO_ALG_ASYNC |
-						  CRYPTO_ALG_KERN_DRIVER_ONLY |
-						  CRYPTO_ALG_NEED_FALLBACK,
-				.cra_blocksize	= SHA512_BLOCK_SIZE,
-				.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
-				.cra_module	= THIS_MODULE,
-				.cra_init	= sa_sha512_cra_init,
-				.cra_exit	= sa_sha_cra_exit,
+			.base = {
+				.halg.base = {
+					.cra_name	= "sha512",
+					.cra_driver_name	= "sha512-sa2ul",
+					.cra_priority	= 400,
+					.cra_flags	= CRYPTO_ALG_TYPE_AHASH |
+							  CRYPTO_ALG_ASYNC |
+							  CRYPTO_ALG_KERN_DRIVER_ONLY |
+							  CRYPTO_ALG_NEED_FALLBACK,
+					.cra_blocksize	= SHA512_BLOCK_SIZE,
+					.cra_ctxsize	= sizeof(struct sa_tfm_ctx),
+					.cra_module	= THIS_MODULE,
+					.cra_init	= sa_sha512_cra_init,
+					.cra_exit	= sa_sha_cra_exit,
+				},
+				.halg.digestsize	= SHA512_DIGEST_SIZE,
+				.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
+							  sizeof(struct sha512_state),
+				.init			= sa_sha_init,
+				.update			= sa_sha_update,
+				.final			= sa_sha_final,
+				.finup			= sa_sha_finup,
+				.digest			= sa_sha_run,
+				.export			= sa_sha_export,
+				.import			= sa_sha_import,
 			},
-			.halg.digestsize	= SHA512_DIGEST_SIZE,
-			.halg.statesize		= sizeof(struct sa_sha_req_ctx) +
-						  sizeof(struct sha512_state),
-			.init			= sa_sha_init,
-			.update			= sa_sha_update,
-			.final			= sa_sha_final,
-			.finup			= sa_sha_finup,
-			.digest			= sa_sha_run,
-			.export			= sa_sha_export,
-			.import			= sa_sha_import,
+			.op.do_one_request = sa_sha_do_one_req,
 		},
 	},
 	[SA_ALG_AUTHENC_SHA1_AES] = {
 		.type	= CRYPTO_ALG_TYPE_AEAD,
 		.alg.aead = {
 			.base = {
-				.cra_name = "authenc(hmac(sha1),cbc(aes))",
-				.cra_driver_name =
-					"authenc(hmac(sha1),cbc(aes))-sa2ul",
-				.cra_blocksize = AES_BLOCK_SIZE,
-				.cra_flags = CRYPTO_ALG_TYPE_AEAD |
-					CRYPTO_ALG_KERN_DRIVER_ONLY |
-					CRYPTO_ALG_ASYNC |
-					CRYPTO_ALG_NEED_FALLBACK,
-				.cra_ctxsize = sizeof(struct sa_tfm_ctx),
-				.cra_module = THIS_MODULE,
-				.cra_priority = 3000,
+				.base = {
+					.cra_name = "authenc(hmac(sha1),cbc(aes))",
+					.cra_driver_name =
+						"authenc(hmac(sha1),cbc(aes))-sa2ul",
+					.cra_blocksize = AES_BLOCK_SIZE,
+					.cra_flags = CRYPTO_ALG_TYPE_AEAD |
+						CRYPTO_ALG_KERN_DRIVER_ONLY |
+						CRYPTO_ALG_ASYNC |
+						CRYPTO_ALG_NEED_FALLBACK,
+					.cra_ctxsize = sizeof(struct sa_tfm_ctx),
+					.cra_module = THIS_MODULE,
+					.cra_priority = 3000,
+				},
+				.ivsize = AES_BLOCK_SIZE,
+				.maxauthsize = SHA1_DIGEST_SIZE,
+
+				.init = sa_cra_init_aead_sha1,
+				.exit = sa_exit_tfm_aead,
+				.setkey = sa_aead_cbc_sha1_setkey,
+				.setauthsize = sa_aead_setauthsize,
+				.encrypt = sa_aead_encrypt,
+				.decrypt = sa_aead_decrypt,
 			},
-			.ivsize = AES_BLOCK_SIZE,
-			.maxauthsize = SHA1_DIGEST_SIZE,
-
-			.init = sa_cra_init_aead_sha1,
-			.exit = sa_exit_tfm_aead,
-			.setkey = sa_aead_cbc_sha1_setkey,
-			.setauthsize = sa_aead_setauthsize,
-			.encrypt = sa_aead_encrypt,
-			.decrypt = sa_aead_decrypt,
+			.op.do_one_request = sa_aead_do_one_req,
 		},
 	},
 	[SA_ALG_AUTHENC_SHA256_AES] = {
 		.type	= CRYPTO_ALG_TYPE_AEAD,
 		.alg.aead = {
 			.base = {
-				.cra_name = "authenc(hmac(sha256),cbc(aes))",
-				.cra_driver_name =
-					"authenc(hmac(sha256),cbc(aes))-sa2ul",
-				.cra_blocksize = AES_BLOCK_SIZE,
-				.cra_flags = CRYPTO_ALG_TYPE_AEAD |
-					CRYPTO_ALG_KERN_DRIVER_ONLY |
-					CRYPTO_ALG_ASYNC |
-					CRYPTO_ALG_NEED_FALLBACK,
-				.cra_ctxsize = sizeof(struct sa_tfm_ctx),
-				.cra_module = THIS_MODULE,
-				.cra_alignmask = 0,
-				.cra_priority = 3000,
+				.base = {
+					.cra_name = "authenc(hmac(sha256),cbc(aes))",
+					.cra_driver_name =
+						"authenc(hmac(sha256),cbc(aes))-sa2ul",
+					.cra_blocksize = AES_BLOCK_SIZE,
+					.cra_flags = CRYPTO_ALG_TYPE_AEAD |
+						CRYPTO_ALG_KERN_DRIVER_ONLY |
+						CRYPTO_ALG_ASYNC |
+						CRYPTO_ALG_NEED_FALLBACK,
+					.cra_ctxsize = sizeof(struct sa_tfm_ctx),
+					.cra_module = THIS_MODULE,
+					.cra_alignmask = 0,
+					.cra_priority = 3000,
+				},
+				.ivsize = AES_BLOCK_SIZE,
+				.maxauthsize = SHA256_DIGEST_SIZE,
+
+				.init = sa_cra_init_aead_sha256,
+				.exit = sa_exit_tfm_aead,
+				.setkey = sa_aead_cbc_sha256_setkey,
+				.setauthsize = sa_aead_setauthsize,
+				.encrypt = sa_aead_encrypt,
+				.decrypt = sa_aead_decrypt,
 			},
-			.ivsize = AES_BLOCK_SIZE,
-			.maxauthsize = SHA256_DIGEST_SIZE,
-
-			.init = sa_cra_init_aead_sha256,
-			.exit = sa_exit_tfm_aead,
-			.setkey = sa_aead_cbc_sha256_setkey,
-			.setauthsize = sa_aead_setauthsize,
-			.encrypt = sa_aead_encrypt,
-			.decrypt = sa_aead_decrypt,
+			.op.do_one_request = sa_aead_do_one_req,
 		},
 	},
 };
@@ -2209,14 +2289,14 @@ static void sa_register_algos(struct sa_crypto_data *dev_data)
 
 		type = sa_algs[i].type;
 		if (type == CRYPTO_ALG_TYPE_SKCIPHER) {
-			alg_name = sa_algs[i].alg.skcipher.base.cra_name;
-			err = crypto_register_skcipher(&sa_algs[i].alg.skcipher);
+			alg_name = sa_algs[i].alg.skcipher.base.base.cra_name;
+			err = crypto_engine_register_skcipher(&sa_algs[i].alg.skcipher);
 		} else if (type == CRYPTO_ALG_TYPE_AHASH) {
-			alg_name = sa_algs[i].alg.ahash.halg.base.cra_name;
-			err = crypto_register_ahash(&sa_algs[i].alg.ahash);
+			alg_name = sa_algs[i].alg.ahash.base.halg.base.cra_name;
+			err = crypto_engine_register_ahash(&sa_algs[i].alg.ahash);
 		} else if (type == CRYPTO_ALG_TYPE_AEAD) {
-			alg_name = sa_algs[i].alg.aead.base.cra_name;
-			err = crypto_register_aead(&sa_algs[i].alg.aead);
+			alg_name = sa_algs[i].alg.aead.base.base.cra_name;
+			err = crypto_engine_register_aead(&sa_algs[i].alg.aead);
 		} else {
 			dev_err(dev,
 				"un-supported crypto algorithm (%d)",
@@ -2242,11 +2322,11 @@ static void sa_unregister_algos(const struct device *dev)
 		if (!sa_algs[i].registered)
 			continue;
 		if (type == CRYPTO_ALG_TYPE_SKCIPHER)
-			crypto_unregister_skcipher(&sa_algs[i].alg.skcipher);
+			crypto_engine_unregister_skcipher(&sa_algs[i].alg.skcipher);
 		else if (type == CRYPTO_ALG_TYPE_AHASH)
-			crypto_unregister_ahash(&sa_algs[i].alg.ahash);
+			crypto_engine_unregister_ahash(&sa_algs[i].alg.ahash);
 		else if (type == CRYPTO_ALG_TYPE_AEAD)
-			crypto_unregister_aead(&sa_algs[i].alg.aead);
+			crypto_engine_unregister_aead(&sa_algs[i].alg.aead);
 
 		sa_algs[i].registered = false;
 	}
@@ -2422,6 +2502,16 @@ static int sa_ul_probe(struct platform_device *pdev)
 	if (ret)
 		goto destroy_dma_pool;
 
+	dev_data->engine = crypto_engine_alloc_init(dev, 0);
+	if (!dev_data->engine) {
+		ret = -ENOMEM;
+		goto release_dma;
+	}
+
+	ret = crypto_engine_start(dev_data->engine);
+	if (ret)
+		goto free_engine;
+
 	spin_lock_init(&dev_data->scid_lock);
 
 	val = SA_EEC_ENCSS_EN | SA_EEC_AUTHSS_EN | SA_EEC_CTXCACH_EN |
@@ -2436,15 +2526,19 @@ static int sa_ul_probe(struct platform_device *pdev)
 
 	ret = of_platform_populate(node, NULL, NULL, dev);
 	if (ret)
-		goto release_dma;
+		goto unregister_algos;
 
 	device_for_each_child(dev, dev, sa_link_child);
 
 	return 0;
 
-release_dma:
+unregister_algos:
 	sa_unregister_algos(dev);
 
+free_engine:
+	crypto_engine_exit(dev_data->engine);
+
+release_dma:
 	dma_release_channel(dev_data->dma_rx2);
 	dma_release_channel(dev_data->dma_rx1);
 	dma_release_channel(dev_data->dma_tx);
@@ -2467,6 +2561,8 @@ static void sa_ul_remove(struct platform_device *pdev)
 
 	sa_unregister_algos(&pdev->dev);
 
+	crypto_engine_exit(dev_data->engine);
+
 	dma_release_channel(dev_data->dma_rx2);
 	dma_release_channel(dev_data->dma_rx1);
 	dma_release_channel(dev_data->dma_tx);
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 7ca385e908cc..53d2bfd895cf 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -159,6 +159,7 @@ struct sa_match_data;
  * @dma_rx1: Pointer to DMA rx channel for sizes < 256 Bytes
  * @dma_rx2: Pointer to DMA rx channel for sizes > 256 Bytes
  * @dma_tx: Pointer to DMA TX channel
+ * @engine: crypto_engine instance for this device
  */
 struct sa_crypto_data {
 	const struct sa_match_data *match_data;
@@ -173,6 +174,7 @@ struct sa_crypto_data {
 	struct dma_chan		*dma_rx1;
 	struct dma_chan		*dma_rx2;
 	struct dma_chan		*dma_tx;
+	struct crypto_engine	*engine;
 };
 
 /**
@@ -261,6 +263,26 @@ struct sa_sha_req_ctx {
 	struct ahash_request	fallback_req;
 };
 
+/**
+ * struct sa_cipher_req_ctx: Structure used for skcipher request
+ * @enc: True if this request is an encrypt operation
+ * @fallback_req: SW fallback request container
+ */
+struct sa_cipher_req_ctx {
+	bool enc;
+	struct skcipher_request fallback_req;
+};
+
+/**
+ * struct sa_aead_req_ctx: Structure used for aead request
+ * @enc: True if this request is an encrypt operation
+ * @fallback_req: SW fallback request container
+ */
+struct sa_aead_req_ctx {
+	bool enc;
+	struct aead_request fallback_req;
+};
+
 /**
  * struct sa_eng_info: Security accelerator engine info
  * @eng_id: Engine ID

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 29/30] crypto: sa2ul - report SA engine hardware revision
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (27 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-15  9:55 ` [PATCH 30/30] crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support Manorit Chawdhry
  2026-09-23  5:16 ` [PATCH 00/30] Clean and improve SA2UL driver Herbert Xu
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The SA2UL/SA3UL crypto engine exposes a REVISION register at offset
0x0 that encodes the major/minor hardware version (major == 2 for
SA2_UL, major == 3 minor == 0 for SA3_UL, major == 3 minor == 1 for
SA3_UL_CM). This version information is needed to detect the AES-CM
(SA3UL_CM) variant so the driver can enable the extra TRNG-priming
and AES key-expansion workarounds it requires.

Add the SA_REVISION register offset and its major/minor field masks,
read the register during probe, and log the decoded version via
dev_info() for diagnostics.

Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
Assisted-by: Sisyphus:claude-sonnet-5
---
 drivers/crypto/sa2ul.c | 8 +++++++-
 drivers/crypto/sa2ul.h | 9 +++++++++
 2 files changed, 16 insertions(+), 1 deletion(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index d92ba1f581c0..9c4748110eef 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -2465,7 +2465,8 @@ static int sa_ul_probe(struct platform_device *pdev)
 	struct device_node *node = dev->of_node;
 	static void __iomem *saul_base;
 	struct sa_crypto_data *dev_data;
-	u32 status, val;
+	u32 status, val, rev;
+	unsigned int major, minor;
 	int ret;
 
 	dev_data = devm_kzalloc(dev, sizeof(*dev_data), GFP_KERNEL);
@@ -2494,6 +2495,11 @@ static int sa_ul_probe(struct platform_device *pdev)
 		return ret;
 	}
 
+	rev = readl_relaxed(saul_base + SA_REVISION);
+	major = FIELD_GET(SA_REVISION_MAJOR_MASK, rev);
+	minor = FIELD_GET(SA_REVISION_MINOR_MASK, rev);
+	dev_info(dev, "SAxUL_VERSION: %u.%u\n", major, minor);
+
 	ret = sa_init_mem(dev_data);
 	if (ret)
 		goto disable_pm;
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index 53d2bfd895cf..c5e73ed14f44 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -16,9 +16,18 @@
 #include <crypto/sha1.h>
 #include <crypto/sha2.h>
 
+#define SA_REVISION			0x0000
 #define SA_ENGINE_STATUS		0x0008
 #define SA_ENGINE_ENABLE_CONTROL	0x1000
 
+/*
+ * SA_REVISION register fields (see REVISION Register, offset 0x0)
+ * major == 2: SA2_UL, major == 3: SA3_UL (minor 0 == SA3_UL, minor 1 ==
+ * SA3_UL_CM aka SA3_UL v3.1)
+ */
+#define SA_REVISION_MAJOR_MASK		GENMASK(10, 8)
+#define SA_REVISION_MINOR_MASK		GENMASK(5, 0)
+
 struct sa_tfm_ctx;
 /*
  * SA_ENGINE_ENABLE_CONTROL register bits

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* [PATCH 30/30] crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (28 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 29/30] crypto: sa2ul - report SA engine hardware revision Manorit Chawdhry
@ 2026-09-15  9:55 ` Manorit Chawdhry
  2026-09-23  5:16 ` [PATCH 00/30] Clean and improve SA2UL driver Herbert Xu
  30 siblings, 0 replies; 34+ messages in thread
From: Manorit Chawdhry @ 2026-09-15  9:55 UTC (permalink / raw)
  To: Herbert Xu, David S. Miller, Keerthy, Colin Ian King
  Cc: Andrew Davis, Pratham T, Kamlesh Gurudasani, Udit Kumar,
	linux-crypto, linux-kernel, Manorit Chawdhry

The SA3UL_CM hardware variant (rev 3.1) requires an extra AES key
schedule round (round 15) for AES-256 decryption, and needs a
one-time TRNG-seeded AES-ECB priming operation after every power-up
before its side-channel countermeasures are considered active.

Add aes_cm detection in sa_ul_probe() based on the SA revision
register, compute the extra round-15 key material into a local
array (crypto_aes_ctx.key_enc[] only holds 60 words for rounds 0-14,
so round 15 cannot be written into it directly), and add
sa_aes_cm_trng_prime() which runs a throwaway ecb(aes) encrypt with a
random key and random plaintext through the driver's own registered
transform to satisfy the priming requirement.

Assisted-by: Sisyphus:claude-sonnet-5
Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/crypto/sa2ul.c | 100 ++++++++++++++++++++++++++++++++++++++++++++++++-
 drivers/crypto/sa2ul.h |   2 +
 2 files changed, 100 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 9c4748110eef..ccc402bade2d 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -21,6 +21,7 @@
 #include <linux/platform_device.h>
 #include <linux/pm_runtime.h>
 #include <linux/slab.h>
+#include <linux/random.h>
 
 #include <crypto/aes.h>
 #include <crypto/authenc.h>
@@ -500,11 +501,22 @@ static int sa_prepare_iopads(struct algo_data *data, const u8 *key,
 	return ret;
 }
 
+/* SubWord using kernel AES S-box */
+static inline u32 sa_aes_subword(u32 w)
+{
+	return (u32)crypto_aes_sbox[w & 0xff] |
+	       ((u32)crypto_aes_sbox[(w >> 8) & 0xff] << 8) |
+	       ((u32)crypto_aes_sbox[(w >> 16) & 0xff] << 16) |
+	       ((u32)crypto_aes_sbox[(w >> 24) & 0xff] << 24);
+}
+
 /* Derive the inverse key used in AES-CBC decryption operation */
-static inline int sa_aes_inv_key(u8 *inv_key, const u8 *key, u16 key_sz)
+static inline int sa_aes_inv_key(u8 *inv_key, const u8 *key, u16 key_sz,
+				 bool aes_cm)
 {
 	struct crypto_aes_ctx ctx __cleanup(aes_zeroize_ctx);
 	int key_pos;
+	u32 round15[4];
 
 	if (aes_expandkey(&ctx, key, key_sz)) {
 		dev_err(sa_k3_dev, "%s: bad key len(%d)\n", __func__, key_sz);
@@ -517,6 +529,23 @@ static inline int sa_aes_inv_key(u8 *inv_key, const u8 *key, u16 key_sz)
 		ctx.key_enc[53] = ctx.key_enc[52] ^ ctx.key_enc[47];
 	}
 
+	/*
+	 * SA3UL CM hardware variant needs an extra round 15 for AES-256.
+	 * ctx.key_enc[] only holds 60 words (rounds 0-14), so round 15 is
+	 * computed into a local array instead of writing past its end.
+	 */
+	if (key_sz == AES_KEYSIZE_256 && aes_cm) {
+		round15[0] = sa_aes_subword(ctx.key_enc[59]) ^ ctx.key_enc[52];
+		round15[1] = round15[0] ^ ctx.key_enc[53];
+		round15[2] = round15[1] ^ ctx.key_enc[54];
+		round15[3] = round15[2] ^ ctx.key_enc[55];
+
+		/* Decrypt key = round14 || round15 */
+		memcpy(inv_key, &ctx.key_enc[56], 16);
+		memcpy(inv_key + 16, round15, 16);
+		return 0;
+	}
+
 	/* Based crypto_aes_expand_key logic */
 	switch (key_sz) {
 	case AES_KEYSIZE_128:
@@ -556,7 +585,10 @@ static int sa_set_sc_enc(struct algo_data *ad, const u8 *key, u16 key_sz,
 
 	/* For AES-CBC decryption get the inverse key */
 	if (ad->inv_key && !enc) {
-		if (sa_aes_inv_key(&sc_buf[SC_ENC_KEY_OFFSET], key, key_sz))
+		struct sa_crypto_data *dev_data = dev_get_drvdata(sa_k3_dev);
+		bool aes_cm = dev_data ? dev_data->aes_cm : false;
+
+		if (sa_aes_inv_key(&sc_buf[SC_ENC_KEY_OFFSET], key, key_sz, aes_cm))
 			return -EINVAL;
 	/* For all other cases: key is used */
 	} else {
@@ -2459,6 +2491,63 @@ static const struct of_device_id of_match[] = {
 };
 MODULE_DEVICE_TABLE(of, of_match);
 
+/*
+ * SA3UL_CM (aes_cm) requires a one-time TRNG-seeded AES-ECB priming
+ * operation after every power-up/reset before its side-channel
+ * countermeasures are considered active. This reuses the driver's own
+ * registered ecb(aes) transform with a throwaway random key/plaintext.
+ */
+static int sa_aes_cm_trng_prime(struct sa_crypto_data *dev_data)
+{
+	struct crypto_skcipher *tfm;
+	struct skcipher_request *req;
+	struct crypto_wait wait;
+	u8 key[AES_KEYSIZE_128];
+	u8 *pt;
+	struct scatterlist sg;
+	int ret;
+
+	pt = kmalloc(AES_BLOCK_SIZE, GFP_KERNEL);
+	if (!pt)
+		return -ENOMEM;
+
+	get_random_bytes(key, sizeof(key));
+	get_random_bytes(pt, AES_BLOCK_SIZE);
+
+	tfm = crypto_alloc_skcipher("ecb-aes-sa2ul", 0, 0);
+	if (IS_ERR(tfm)) {
+		ret = PTR_ERR(tfm);
+		goto out_zero;
+	}
+
+	req = skcipher_request_alloc(tfm, GFP_KERNEL);
+	if (!req) {
+		ret = -ENOMEM;
+		goto free_tfm;
+	}
+
+	ret = crypto_skcipher_setkey(tfm, key, sizeof(key));
+	if (ret)
+		goto free_req;
+
+	sg_init_one(&sg, pt, AES_BLOCK_SIZE);
+	crypto_init_wait(&wait);
+	skcipher_request_set_callback(req, CRYPTO_TFM_REQ_MAY_SLEEP,
+				      crypto_req_done, &wait);
+	skcipher_request_set_crypt(req, &sg, &sg, AES_BLOCK_SIZE, NULL);
+
+	ret = crypto_wait_req(crypto_skcipher_encrypt(req), &wait);
+
+free_req:
+	skcipher_request_free(req);
+free_tfm:
+	crypto_free_skcipher(tfm);
+out_zero:
+	memzero_explicit(key, sizeof(key));
+	kfree(pt);
+	return ret;
+}
+
 static int sa_ul_probe(struct platform_device *pdev)
 {
 	struct device *dev = &pdev->dev;
@@ -2499,6 +2588,7 @@ static int sa_ul_probe(struct platform_device *pdev)
 	major = FIELD_GET(SA_REVISION_MAJOR_MASK, rev);
 	minor = FIELD_GET(SA_REVISION_MINOR_MASK, rev);
 	dev_info(dev, "SAxUL_VERSION: %u.%u\n", major, minor);
+	dev_data->aes_cm = (major == 3 && minor == 1);
 
 	ret = sa_init_mem(dev_data);
 	if (ret)
@@ -2530,6 +2620,12 @@ static int sa_ul_probe(struct platform_device *pdev)
 
 	sa_register_algos(dev_data);
 
+	if (dev_data->aes_cm) {
+		ret = sa_aes_cm_trng_prime(dev_data);
+		if (ret)
+			dev_warn(dev, "aes_cm TRNG priming failed: %d\n", ret);
+	}
+
 	ret = of_platform_populate(node, NULL, NULL, dev);
 	if (ret)
 		goto unregister_algos;
diff --git a/drivers/crypto/sa2ul.h b/drivers/crypto/sa2ul.h
index c5e73ed14f44..045fedda90c9 100644
--- a/drivers/crypto/sa2ul.h
+++ b/drivers/crypto/sa2ul.h
@@ -184,6 +184,8 @@ struct sa_crypto_data {
 	struct dma_chan		*dma_rx2;
 	struct dma_chan		*dma_tx;
 	struct crypto_engine	*engine;
+	/* true if HW is SA3UL_CM (SA_REVISION major=3 minor=1) */
+	bool aes_cm;
 };
 
 /**

-- 
2.43.0


^ permalink raw reply related	[flat|nested] 34+ messages in thread

* Re: [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine
  2026-09-15  9:55 ` [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine Manorit Chawdhry
@ 2026-09-17 10:05   ` T Pratham
  0 siblings, 0 replies; 34+ messages in thread
From: T Pratham @ 2026-09-17 10:05 UTC (permalink / raw)
  To: Manorit Chawdhry, Herbert Xu, David S. Miller, Keerthy,
	Colin Ian King
  Cc: Andrew Davis, Kamlesh Gurudasani, Udit Kumar, linux-crypto,
	linux-kernel

On 9/15/26 15:25, Manorit Chawdhry wrote:
[...]
> @@ -914,8 +915,8 @@ static int sa_cipher_cra_init(struct crypto_skcipher *tfm)
>  	}
>  
>  	ctx->fallback.skcipher = child;
> -	crypto_skcipher_set_reqsize(tfm, crypto_skcipher_reqsize(child) +
> -					 sizeof(struct skcipher_request));
> +	crypto_skcipher_set_reqsize(tfm, sizeof(struct sa_cipher_req_ctx) +
> +					 crypto_skcipher_reqsize(child));
>  
Last I remember, crypto_*_set_reqsize() type dynamic reqsize setting was
being deprecated in lieu of cra_reqsize field in the algorithm
registration struct. Should change this to that.

While we are here, also rename the cra_init/cra_exit functions to
init_tfm/exit_tfm as these are no longer associated inside cra.

-- 
Regards
T Pratham <t-pratham@ti.com>

^ permalink raw reply	[flat|nested] 34+ messages in thread

* Re: [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads
  2026-09-15  9:55 ` [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads Manorit Chawdhry
@ 2026-09-17 10:13   ` T Pratham
  0 siblings, 0 replies; 34+ messages in thread
From: T Pratham @ 2026-09-17 10:13 UTC (permalink / raw)
  To: Manorit Chawdhry, Herbert Xu, David S. Miller, Keerthy,
	Colin Ian King
  Cc: Andrew Davis, Kamlesh Gurudasani, Udit Kumar, linux-crypto,
	linux-kernel

On 9/15/26 15:25, Manorit Chawdhry wrote:
[...]
>  
> -static int sa_export_shash(void *state, struct shash_desc *hash,
> -			   int digest_size, __be32 *out)
> +static int sa_export_shash(struct shash_desc *hash, int digest_size,
> +			   __be32 *out)
>  {
> -	struct sha1_state *sha1;
> -	struct sha256_state *sha256;
>  	u32 *result;
>  	int ret = 0;
> +	int state_size;
> +	u8 *sha;
> +
> +	state_size = crypto_shash_statesize(hash->tfm);
> +	if (state_size <= 0) {
> +		dev_err(sa_k3_dev, "%s: invalid state_size=%d\n", __func__,
> +			state_size);
> +		return -EINVAL;
> +	}
> +
> +	sha = kmalloc(state_size, GFP_KERNEL);
> +	if (!sha)
> +		return -ENOMEM;
>  
>  	/* Export the intermediate digest to program into SA2UL */
> -	ret = crypto_shash_export(hash, state);
> +	ret = crypto_shash_export(hash, sha);
>  	if (ret) {
>  		dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
>  			__func__);
> +		kfree_sensitive(sha);
>  		return ret;
>  	}
>  
>  	switch (digest_size) {
>  	case SHA1_DIGEST_SIZE:
> -		sha1 = state;
> -		result = sha1->state;
> +		result = (u32 *)sha;
>  		break;
>  	case SHA256_DIGEST_SIZE:
> -		sha256 = state;
> -		result = sha256->state;
> +		result = (u32 *)sha;
>  		break;
>  	default:
>  		dev_err(sa_k3_dev, "%s: bad digest_size=%d\n", __func__,
>  			digest_size);
> +		kfree_sensitive(sha);
>  		return -EINVAL;
>  	}
>  
All the arms in this switch-case are now doing the exact same thing. If
digest_size is guaranteed to be supplied correct in this function, this
can be removed.

-- 
Regards
T Pratham <t-pratham@ti.com>

^ permalink raw reply	[flat|nested] 34+ messages in thread

* Re: [PATCH 00/30] Clean and improve SA2UL driver
  2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
                   ` (29 preceding siblings ...)
  2026-09-15  9:55 ` [PATCH 30/30] crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support Manorit Chawdhry
@ 2026-09-23  5:16 ` Herbert Xu
  30 siblings, 0 replies; 34+ messages in thread
From: Herbert Xu @ 2026-09-23  5:16 UTC (permalink / raw)
  To: Manorit Chawdhry
  Cc: David S. Miller, Keerthy, Colin Ian King, Andrew Davis, Pratham T,
	Kamlesh Gurudasani, Udit Kumar, linux-crypto, linux-kernel

On Tue, Sep 15, 2026 at 03:25:06PM +0530, Manorit Chawdhry wrote:
> The following series focuses on some cleanups to the sa2ul driver, it
> starts with very trivial cleanups then goes to fix some bigger cleanups
> and migration to crypto_engine which help fix the broader race condition
> problems with the driver, thereafter it adds the support for AES CM as
> per SAxUL 3.1 IP. KASAN is also run alongside to fix the issues caught
> by them.
> 
> Self test results across K3 family: 
> https://gist.github.com/manorit2001/544587ec3535125663e3ca9dbc186e96
> 
> Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
> ---
> Manorit Chawdhry (30):
>       crypto: sa2ul - remove dead code
>       crypto: sa2ul - remove totally unused structure fields
>       crypto: sa2ul - remove unused algorithm ID fields
>       crypto: sa2ul - remove unused fields from sa_cmdl_cfg
>       crypto: sa2ul - remove unused fields from sa_tfm_ctx
>       crypto: sa2ul - remove unused macro definitions
>       crypto: sa2ul - consolidate encryption offset definitions
>       crypto: sa2ul - remove unused SC ID range tracking
>       crypto: sa2ul - remove unused base register pointer
>       crypto: sa2ul - remove unused includes and defines
>       crypto: sa2ul - remove unused line
>       crypto: sa2ul - remove redundant sa_sha_digest() wrapper
>       crypto: sa2ul - fix struct documentation for match_data
>       crypto: sa2ul - zero out security context on free
>       crypto: sa2ul - fix context release on errors
>       crypto: sa2ul - fix resource leak of sha in init_alg() error path
>       crypto: sa2ul - fix resource leak of AEAD in init_alg() error path
>       crypto: sa2ul - fix DMA mapping leak in sa_run() error paths
>       crypto: sa2ul - generate dynamic metadata length
>       crypto: sa2ul - fix command label stack corruption
>       crypto: sa2ul - fix error handling in sa_prepare_iopad
>       crypto: sa2ul - move export to appropriate location.
>       crypto: sa2ul - fix stack overflow in sa_prepare_iopads
>       crypto: sa2ul - add more checks before processing ipad/opad
>       crypto: sa2ul - fix data corruption by skipping device sync on unmap
>       crypto: sa2ul - use correct DMA direction in sa_sync_from_device
>       crypto: sa2ul - change dma_alloc_pool to mempool
>       crypto: sa2ul - route requests through crypto_engine
>       crypto: sa2ul - report SA engine hardware revision
>       crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support
> 
>  drivers/crypto/Kconfig |    1 +
>  drivers/crypto/sa2ul.c | 1042 +++++++++++++++++++++++++++++-------------------
>  drivers/crypto/sa2ul.h |  162 ++------
>  3 files changed, 661 insertions(+), 544 deletions(-)
> ---
> base-commit: a9d7ced84989ec05be09b4b8428759ef60450a0f
> change-id: 20251106-b4-upstream-sa2ul-cleanup-ce85d40c7eb8
> 
> Best regards,
> --  
> Manorit Chawdhry <m-chawdhry@ti.com>

Please check the Sashiko comments:

https://sashiko.dev/#/patchset/20260915-b4-upstream-sa2ul-cleanup-v1-0-57ab34e97162%40ti.com

Thanks,
-- 
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

^ permalink raw reply	[flat|nested] 34+ messages in thread

end of thread, other threads:[~2026-09-23  5:16 UTC | newest]

Thread overview: 34+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15  9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 01/30] crypto: sa2ul - remove dead code Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 02/30] crypto: sa2ul - remove totally unused structure fields Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 03/30] crypto: sa2ul - remove unused algorithm ID fields Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 04/30] crypto: sa2ul - remove unused fields from sa_cmdl_cfg Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 05/30] crypto: sa2ul - remove unused fields from sa_tfm_ctx Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 06/30] crypto: sa2ul - remove unused macro definitions Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 07/30] crypto: sa2ul - consolidate encryption offset definitions Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 08/30] crypto: sa2ul - remove unused SC ID range tracking Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 09/30] crypto: sa2ul - remove unused base register pointer Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 10/30] crypto: sa2ul - remove unused includes and defines Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 11/30] crypto: sa2ul - remove unused line Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 12/30] crypto: sa2ul - remove redundant sa_sha_digest() wrapper Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 13/30] crypto: sa2ul - fix struct documentation for match_data Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 14/30] crypto: sa2ul - zero out security context on free Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 15/30] crypto: sa2ul - fix context release on errors Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 16/30] crypto: sa2ul - fix resource leak of sha in init_alg() error path Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 17/30] crypto: sa2ul - fix resource leak of AEAD " Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 18/30] crypto: sa2ul - fix DMA mapping leak in sa_run() error paths Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 19/30] crypto: sa2ul - generate dynamic metadata length Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 20/30] crypto: sa2ul - fix command label stack corruption Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 21/30] crypto: sa2ul - fix error handling in sa_prepare_iopad Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 22/30] crypto: sa2ul - move export to appropriate location Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads Manorit Chawdhry
2026-09-17 10:13   ` T Pratham
2026-09-15  9:55 ` [PATCH 24/30] crypto: sa2ul - add more checks before processing ipad/opad Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 25/30] crypto: sa2ul - fix data corruption by skipping device sync on unmap Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 26/30] crypto: sa2ul - use correct DMA direction in sa_sync_from_device Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 27/30] crypto: sa2ul - change dma_alloc_pool to mempool Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine Manorit Chawdhry
2026-09-17 10:05   ` T Pratham
2026-09-15  9:55 ` [PATCH 29/30] crypto: sa2ul - report SA engine hardware revision Manorit Chawdhry
2026-09-15  9:55 ` [PATCH 30/30] crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support Manorit Chawdhry
2026-09-23  5:16 ` [PATCH 00/30] Clean and improve SA2UL driver Herbert Xu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox