Linux-NVME Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] nvmet-auth: always free derived key data
@ 2025-04-25  9:34 Hannes Reinecke
  2025-04-25 21:45 ` Sagi Grimberg
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Hannes Reinecke @ 2025-04-25  9:34 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Keith Busch, Sagi Grimberg, linux-nvme, Hannes Reinecke, Yi Zhang,
	Maurizio Lombardi

After calling nvme_auth_derive_tls_psk() we need to free the resulting
psk data, as either TLS is disable (and we don't need the data anyway)
or the psk data is copied into the resulting key (and can be free, too).

Fixes: fa2e0f8bbc68 ("nvmet-tcp: support secure channel concatenation")
Reported-by: Yi Zhang <yi.zhang@redhat.com>
Suggested-by: Maurizio Lombardi <mlombard@bsdbackstore.eu>
Signed-off-by: Hannes Reinecke <hare@kernel.org>
---
 drivers/nvme/target/auth.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/nvme/target/auth.c b/drivers/nvme/target/auth.c
index 3f9fad732350..8f67fc21149c 100644
--- a/drivers/nvme/target/auth.c
+++ b/drivers/nvme/target/auth.c
@@ -656,13 +656,12 @@ void nvmet_auth_insert_psk(struct nvmet_sq *sq)
 		pr_warn("%s: ctrl %d qid %d failed to refresh key, error %ld\n",
 			__func__, sq->ctrl->cntlid, sq->qid, PTR_ERR(tls_key));
 		tls_key = NULL;
-		kfree_sensitive(tls_psk);
 	}
 	if (sq->ctrl->tls_key)
 		key_put(sq->ctrl->tls_key);
 	sq->ctrl->tls_key = tls_key;
 #endif
-
+	kfree_sensitive(tls_psk);
 out_free_digest:
 	kfree_sensitive(digest);
 out_free_psk:
-- 
2.35.3



^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] nvmet-auth: always free derived key data
  2025-04-25  9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
@ 2025-04-25 21:45 ` Sagi Grimberg
  2025-04-27  5:31 ` Yi Zhang
  2025-04-29 13:10 ` Christoph Hellwig
  2 siblings, 0 replies; 4+ messages in thread
From: Sagi Grimberg @ 2025-04-25 21:45 UTC (permalink / raw)
  To: Hannes Reinecke, Christoph Hellwig
  Cc: Keith Busch, linux-nvme, Yi Zhang, Maurizio Lombardi

Reviewed-by: Sagi Grimberg <sagi@grimberg.me>


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] nvmet-auth: always free derived key data
  2025-04-25  9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
  2025-04-25 21:45 ` Sagi Grimberg
@ 2025-04-27  5:31 ` Yi Zhang
  2025-04-29 13:10 ` Christoph Hellwig
  2 siblings, 0 replies; 4+ messages in thread
From: Yi Zhang @ 2025-04-27  5:31 UTC (permalink / raw)
  To: Hannes Reinecke
  Cc: Christoph Hellwig, Keith Busch, Sagi Grimberg, linux-nvme,
	Maurizio Lombardi

On Fri, Apr 25, 2025 at 5:40 PM Hannes Reinecke <hare@kernel.org> wrote:
>
> After calling nvme_auth_derive_tls_psk() we need to free the resulting
> psk data, as either TLS is disable (and we don't need the data anyway)
> or the psk data is copied into the resulting key (and can be free, too).
>
> Fixes: fa2e0f8bbc68 ("nvmet-tcp: support secure channel concatenation")
> Reported-by: Yi Zhang <yi.zhang@redhat.com>
> Suggested-by: Maurizio Lombardi <mlombard@bsdbackstore.eu>
> Signed-off-by: Hannes Reinecke <hare@kernel.org>

Thanks for the fix:

Tested-by: Yi Zhang <yi.zhang@redhat.com>

> ---
>  drivers/nvme/target/auth.c | 3 +--
>  1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/drivers/nvme/target/auth.c b/drivers/nvme/target/auth.c
> index 3f9fad732350..8f67fc21149c 100644
> --- a/drivers/nvme/target/auth.c
> +++ b/drivers/nvme/target/auth.c
> @@ -656,13 +656,12 @@ void nvmet_auth_insert_psk(struct nvmet_sq *sq)
>                 pr_warn("%s: ctrl %d qid %d failed to refresh key, error %ld\n",
>                         __func__, sq->ctrl->cntlid, sq->qid, PTR_ERR(tls_key));
>                 tls_key = NULL;
> -               kfree_sensitive(tls_psk);
>         }
>         if (sq->ctrl->tls_key)
>                 key_put(sq->ctrl->tls_key);
>         sq->ctrl->tls_key = tls_key;
>  #endif
> -
> +       kfree_sensitive(tls_psk);
>  out_free_digest:
>         kfree_sensitive(digest);
>  out_free_psk:
> --
> 2.35.3
>


-- 
Best Regards,
  Yi Zhang



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] nvmet-auth: always free derived key data
  2025-04-25  9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
  2025-04-25 21:45 ` Sagi Grimberg
  2025-04-27  5:31 ` Yi Zhang
@ 2025-04-29 13:10 ` Christoph Hellwig
  2 siblings, 0 replies; 4+ messages in thread
From: Christoph Hellwig @ 2025-04-29 13:10 UTC (permalink / raw)
  To: Hannes Reinecke
  Cc: Christoph Hellwig, Keith Busch, Sagi Grimberg, linux-nvme,
	Yi Zhang, Maurizio Lombardi

Thanks,

added to nvme-6.15.



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-04-29 15:16 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-04-25  9:34 [PATCH] nvmet-auth: always free derived key data Hannes Reinecke
2025-04-25 21:45 ` Sagi Grimberg
2025-04-27  5:31 ` Yi Zhang
2025-04-29 13:10 ` Christoph Hellwig

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox