* [PATCH] nvmet-auth: always free derived key data
@ 2025-04-25 9:34 Hannes Reinecke
2025-04-25 21:45 ` Sagi Grimberg
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Hannes Reinecke @ 2025-04-25 9:34 UTC (permalink / raw)
To: Christoph Hellwig
Cc: Keith Busch, Sagi Grimberg, linux-nvme, Hannes Reinecke, Yi Zhang,
Maurizio Lombardi
After calling nvme_auth_derive_tls_psk() we need to free the resulting
psk data, as either TLS is disable (and we don't need the data anyway)
or the psk data is copied into the resulting key (and can be free, too).
Fixes: fa2e0f8bbc68 ("nvmet-tcp: support secure channel concatenation")
Reported-by: Yi Zhang <yi.zhang@redhat.com>
Suggested-by: Maurizio Lombardi <mlombard@bsdbackstore.eu>
Signed-off-by: Hannes Reinecke <hare@kernel.org>
---
drivers/nvme/target/auth.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/nvme/target/auth.c b/drivers/nvme/target/auth.c
index 3f9fad732350..8f67fc21149c 100644
--- a/drivers/nvme/target/auth.c
+++ b/drivers/nvme/target/auth.c
@@ -656,13 +656,12 @@ void nvmet_auth_insert_psk(struct nvmet_sq *sq)
pr_warn("%s: ctrl %d qid %d failed to refresh key, error %ld\n",
__func__, sq->ctrl->cntlid, sq->qid, PTR_ERR(tls_key));
tls_key = NULL;
- kfree_sensitive(tls_psk);
}
if (sq->ctrl->tls_key)
key_put(sq->ctrl->tls_key);
sq->ctrl->tls_key = tls_key;
#endif
-
+ kfree_sensitive(tls_psk);
out_free_digest:
kfree_sensitive(digest);
out_free_psk:
--
2.35.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] nvmet-auth: always free derived key data
2025-04-25 9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
@ 2025-04-25 21:45 ` Sagi Grimberg
2025-04-27 5:31 ` Yi Zhang
2025-04-29 13:10 ` Christoph Hellwig
2 siblings, 0 replies; 4+ messages in thread
From: Sagi Grimberg @ 2025-04-25 21:45 UTC (permalink / raw)
To: Hannes Reinecke, Christoph Hellwig
Cc: Keith Busch, linux-nvme, Yi Zhang, Maurizio Lombardi
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] nvmet-auth: always free derived key data
2025-04-25 9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
2025-04-25 21:45 ` Sagi Grimberg
@ 2025-04-27 5:31 ` Yi Zhang
2025-04-29 13:10 ` Christoph Hellwig
2 siblings, 0 replies; 4+ messages in thread
From: Yi Zhang @ 2025-04-27 5:31 UTC (permalink / raw)
To: Hannes Reinecke
Cc: Christoph Hellwig, Keith Busch, Sagi Grimberg, linux-nvme,
Maurizio Lombardi
On Fri, Apr 25, 2025 at 5:40 PM Hannes Reinecke <hare@kernel.org> wrote:
>
> After calling nvme_auth_derive_tls_psk() we need to free the resulting
> psk data, as either TLS is disable (and we don't need the data anyway)
> or the psk data is copied into the resulting key (and can be free, too).
>
> Fixes: fa2e0f8bbc68 ("nvmet-tcp: support secure channel concatenation")
> Reported-by: Yi Zhang <yi.zhang@redhat.com>
> Suggested-by: Maurizio Lombardi <mlombard@bsdbackstore.eu>
> Signed-off-by: Hannes Reinecke <hare@kernel.org>
Thanks for the fix:
Tested-by: Yi Zhang <yi.zhang@redhat.com>
> ---
> drivers/nvme/target/auth.c | 3 +--
> 1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/drivers/nvme/target/auth.c b/drivers/nvme/target/auth.c
> index 3f9fad732350..8f67fc21149c 100644
> --- a/drivers/nvme/target/auth.c
> +++ b/drivers/nvme/target/auth.c
> @@ -656,13 +656,12 @@ void nvmet_auth_insert_psk(struct nvmet_sq *sq)
> pr_warn("%s: ctrl %d qid %d failed to refresh key, error %ld\n",
> __func__, sq->ctrl->cntlid, sq->qid, PTR_ERR(tls_key));
> tls_key = NULL;
> - kfree_sensitive(tls_psk);
> }
> if (sq->ctrl->tls_key)
> key_put(sq->ctrl->tls_key);
> sq->ctrl->tls_key = tls_key;
> #endif
> -
> + kfree_sensitive(tls_psk);
> out_free_digest:
> kfree_sensitive(digest);
> out_free_psk:
> --
> 2.35.3
>
--
Best Regards,
Yi Zhang
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] nvmet-auth: always free derived key data
2025-04-25 9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
2025-04-25 21:45 ` Sagi Grimberg
2025-04-27 5:31 ` Yi Zhang
@ 2025-04-29 13:10 ` Christoph Hellwig
2 siblings, 0 replies; 4+ messages in thread
From: Christoph Hellwig @ 2025-04-29 13:10 UTC (permalink / raw)
To: Hannes Reinecke
Cc: Christoph Hellwig, Keith Busch, Sagi Grimberg, linux-nvme,
Yi Zhang, Maurizio Lombardi
Thanks,
added to nvme-6.15.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2025-04-29 15:16 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-04-25 9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
2025-04-25 21:45 ` Sagi Grimberg
2025-04-27 5:31 ` Yi Zhang
2025-04-29 13:10 ` Christoph Hellwig
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox