From: T Pratham <t-pratham@ti.com>
To: Manorit Chawdhry <m-chawdhry@ti.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
Keerthy <j-keerthy@ti.com>,
Colin Ian King <colin.i.king@gmail.com>
Cc: Andrew Davis <afd@ti.com>, Kamlesh Gurudasani <kamlesh@ti.com>,
Udit Kumar <u-kumar1@ti.com>, <linux-crypto@vger.kernel.org>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads
Date: Thu, 17 Sep 2026 15:43:45 +0530 [thread overview]
Message-ID: <dfddf92e-1547-4cad-94c4-b5fbba098134@ti.com> (raw)
In-Reply-To: <20260915-b4-upstream-sa2ul-cleanup-v1-23-57ab34e97162@ti.com>
On 9/15/26 15:25, Manorit Chawdhry wrote:
[...]
>
> -static int sa_export_shash(void *state, struct shash_desc *hash,
> - int digest_size, __be32 *out)
> +static int sa_export_shash(struct shash_desc *hash, int digest_size,
> + __be32 *out)
> {
> - struct sha1_state *sha1;
> - struct sha256_state *sha256;
> u32 *result;
> int ret = 0;
> + int state_size;
> + u8 *sha;
> +
> + state_size = crypto_shash_statesize(hash->tfm);
> + if (state_size <= 0) {
> + dev_err(sa_k3_dev, "%s: invalid state_size=%d\n", __func__,
> + state_size);
> + return -EINVAL;
> + }
> +
> + sha = kmalloc(state_size, GFP_KERNEL);
> + if (!sha)
> + return -ENOMEM;
>
> /* Export the intermediate digest to program into SA2UL */
> - ret = crypto_shash_export(hash, state);
> + ret = crypto_shash_export(hash, sha);
> if (ret) {
> dev_err(sa_k3_dev, "%s: crypto_shash_export failed\n",
> __func__);
> + kfree_sensitive(sha);
> return ret;
> }
>
> switch (digest_size) {
> case SHA1_DIGEST_SIZE:
> - sha1 = state;
> - result = sha1->state;
> + result = (u32 *)sha;
> break;
> case SHA256_DIGEST_SIZE:
> - sha256 = state;
> - result = sha256->state;
> + result = (u32 *)sha;
> break;
> default:
> dev_err(sa_k3_dev, "%s: bad digest_size=%d\n", __func__,
> digest_size);
> + kfree_sensitive(sha);
> return -EINVAL;
> }
>
All the arms in this switch-case are now doing the exact same thing. If
digest_size is guaranteed to be supplied correct in this function, this
can be removed.
--
Regards
T Pratham <t-pratham@ti.com>
next prev parent reply other threads:[~2026-09-17 10:14 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 9:55 [PATCH 00/30] Clean and improve SA2UL driver Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 01/30] crypto: sa2ul - remove dead code Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 02/30] crypto: sa2ul - remove totally unused structure fields Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 03/30] crypto: sa2ul - remove unused algorithm ID fields Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 04/30] crypto: sa2ul - remove unused fields from sa_cmdl_cfg Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 05/30] crypto: sa2ul - remove unused fields from sa_tfm_ctx Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 06/30] crypto: sa2ul - remove unused macro definitions Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 07/30] crypto: sa2ul - consolidate encryption offset definitions Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 08/30] crypto: sa2ul - remove unused SC ID range tracking Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 09/30] crypto: sa2ul - remove unused base register pointer Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 10/30] crypto: sa2ul - remove unused includes and defines Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 11/30] crypto: sa2ul - remove unused line Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 12/30] crypto: sa2ul - remove redundant sa_sha_digest() wrapper Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 13/30] crypto: sa2ul - fix struct documentation for match_data Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 14/30] crypto: sa2ul - zero out security context on free Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 15/30] crypto: sa2ul - fix context release on errors Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 16/30] crypto: sa2ul - fix resource leak of sha in init_alg() error path Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 17/30] crypto: sa2ul - fix resource leak of AEAD " Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 18/30] crypto: sa2ul - fix DMA mapping leak in sa_run() error paths Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 19/30] crypto: sa2ul - generate dynamic metadata length Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 20/30] crypto: sa2ul - fix command label stack corruption Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 21/30] crypto: sa2ul - fix error handling in sa_prepare_iopad Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 22/30] crypto: sa2ul - move export to appropriate location Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 23/30] crypto: sa2ul - fix stack overflow in sa_prepare_iopads Manorit Chawdhry
2026-09-17 10:13 ` T Pratham [this message]
2026-09-15 9:55 ` [PATCH 24/30] crypto: sa2ul - add more checks before processing ipad/opad Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 25/30] crypto: sa2ul - fix data corruption by skipping device sync on unmap Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 26/30] crypto: sa2ul - use correct DMA direction in sa_sync_from_device Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 27/30] crypto: sa2ul - change dma_alloc_pool to mempool Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 28/30] crypto: sa2ul - route requests through crypto_engine Manorit Chawdhry
2026-09-17 10:05 ` T Pratham
2026-09-15 9:55 ` [PATCH 29/30] crypto: sa2ul - report SA engine hardware revision Manorit Chawdhry
2026-09-15 9:55 ` [PATCH 30/30] crypto: sa2ul - add AES-CM (SA3UL_CM) TRNG priming support Manorit Chawdhry
2026-09-23 5:16 ` [PATCH 00/30] Clean and improve SA2UL driver Herbert Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dfddf92e-1547-4cad-94c4-b5fbba098134@ti.com \
--to=t-pratham@ti.com \
--cc=afd@ti.com \
--cc=colin.i.king@gmail.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=j-keerthy@ti.com \
--cc=kamlesh@ti.com \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=m-chawdhry@ti.com \
--cc=u-kumar1@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox