From: Harald Freudenberger <freude@linux.ibm.com>
To: dengler@linux.ibm.com, fcallies@linux.ibm.com
Cc: freude@linux.ibm.com, linux-s390@vger.kernel.org,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Alexander Gordeev <agordeev@linux.ibm.com>
Subject: [PATCH v3 1/2] s390/zcrypt: Guard domain index uses against speculative bypass
Date: Tue, 6 Oct 2026 17:46:02 +0200 [thread overview]
Message-ID: <20261006154603.9699-2-freude@linux.ibm.com> (raw)
In-Reply-To: <20261006154603.9699-1-freude@linux.ibm.com>
The previous array_index_nospec() placement only covered the admin
permission check, leaving ap_test_config_usage_domain() and
ap_test_config_ctrl_domain() in the CCA path exposed to speculative
execution.
Move the sanitization to before all permission and config checks in
both the CCA and EP11 paths. Hold the sanitized domain value in
another variable so that the later use can choose to use either the
original value (subject to speculative execution) or the sanitized
value (which may in case of AUTOSEL_DOM reflect the wrong
value). Before that, check the domain value to be either AUTOSEL_DOM
or in range 0...AP_DOMAIN-1 and return with -EINVAL in case this check
does not pass.
Fixes: e935cd525af4 ("s390/zcrypt: Close speculative mem read possibility")
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Cc: stable@vger.kernel.org
---
drivers/s390/crypto/zcrypt_api.c | 35 +++++++++++++++++++++++---------
1 file changed, 25 insertions(+), 10 deletions(-)
diff --git a/drivers/s390/crypto/zcrypt_api.c b/drivers/s390/crypto/zcrypt_api.c
index ec6a4c2f9f04..625578b3fabe 100644
--- a/drivers/s390/crypto/zcrypt_api.c
+++ b/drivers/s390/crypto/zcrypt_api.c
@@ -854,7 +854,7 @@ static long _zcrypt_send_cprb(u32 xflags, struct ap_perms *perms,
struct ica_xcRB *xcrb)
{
bool userspace = xflags & ZCRYPT_XFLAG_USERSPACE;
- unsigned int card, domain, func_code = 0;
+ unsigned int card, domain, _dom, func_code = 0;
unsigned int wgt = 0, pref_wgt = 0;
struct zcrypt_queue *zq, *pref_zq;
struct zcrypt_card *zc, *pref_zc;
@@ -877,10 +877,17 @@ static long _zcrypt_send_cprb(u32 xflags, struct ap_perms *perms,
print_hex_dump_debug("ccareq: ", DUMP_PREFIX_ADDRESS, 16, 1,
ap_msg.msg, ap_msg.len, false);
+ /* Check domain for either AUTOSEL_DOM or in range 0...AP_DOMAIN-1 */
+ if (domain != AUTOSEL_DOM && domain >= AP_DOMAINS) {
+ rc = -EINVAL;
+ goto out;
+ }
+ /* Spectre-v1: sanitize domain unconditionally for later use */
+ _dom = array_index_nospec(domain, AP_DOMAINS);
+
if (perms != &ap_perms && domain < AP_DOMAINS) {
if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
- domain = array_index_nospec(domain, AP_DOMAINS);
- if (!test_bit_inv(domain, perms->adm)) {
+ if (!test_bit_inv(_dom, perms->adm)) {
rc = -ENODEV;
goto out;
}
@@ -893,10 +900,11 @@ static long _zcrypt_send_cprb(u32 xflags, struct ap_perms *perms,
* If a valid target domain is set and this domain is NOT a usage
* domain but a control only domain, autoselect target domain.
*/
- if (domain < AP_DOMAINS &&
- !ap_test_config_usage_domain(domain) &&
- ap_test_config_ctrl_domain(domain))
- domain = AUTOSEL_DOM;
+ if (domain < AP_DOMAINS) {
+ if (!ap_test_config_usage_domain(_dom) &&
+ ap_test_config_ctrl_domain(_dom))
+ domain = AUTOSEL_DOM;
+ }
pref_zc = NULL;
pref_zq = NULL;
@@ -1041,7 +1049,7 @@ static long _zcrypt_send_ep11_cprb(u32 xflags, struct ap_perms *perms,
struct ep11_target_dev *targets = NULL;
unsigned short target_num;
unsigned int wgt = 0, pref_wgt = 0;
- unsigned int func_code = 0, domain;
+ unsigned int func_code = 0, domain, _dom;
struct ap_message ap_msg;
int cpen, qpen, qid = 0, rc;
struct module *mod;
@@ -1078,10 +1086,17 @@ static long _zcrypt_send_ep11_cprb(u32 xflags, struct ap_perms *perms,
print_hex_dump_debug("ep11req: ", DUMP_PREFIX_ADDRESS, 16, 1,
ap_msg.msg, ap_msg.len, false);
+ /* Check domain for either AUTOSEL_DOM or in range 0...AP_DOMAIN-1 */
+ if (domain != AUTOSEL_DOM && domain >= AP_DOMAINS) {
+ rc = -EINVAL;
+ goto out;
+ }
+ /* Spectre-v1: sanitize domain unconditionally for later use */
+ _dom = array_index_nospec(domain, AP_DOMAINS);
+
if (perms != &ap_perms && domain < AP_DOMAINS) {
if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
- domain = array_index_nospec(domain, AP_DOMAINS);
- if (!test_bit_inv(domain, perms->adm)) {
+ if (!test_bit_inv(_dom, perms->adm)) {
rc = -ENODEV;
goto out;
}
--
2.43.0
next prev parent reply other threads:[~2026-10-06 15:46 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 15:46 [PATCH v3 0/2] Fix minor LLM findings in zcrypt dd Harald Freudenberger
2026-10-06 15:46 ` Harald Freudenberger [this message]
2026-10-06 15:55 ` [PATCH v3 1/2] s390/zcrypt: Guard domain index uses against speculative bypass sashiko-bot
2026-10-08 14:08 ` Holger Dengler
2026-10-06 15:46 ` [PATCH v3 2/2] s390/zcrypt: Fix out-of-bounds ptr advance in cca_query_crypto_facility() Harald Freudenberger
2026-10-06 15:54 ` sashiko-bot
2026-10-08 14:48 ` Holger Dengler
2026-10-08 18:02 ` [PATCH v3 0/2] Fix minor LLM findings in zcrypt dd Heiko Carstens
2026-10-08 18:05 ` Heiko Carstens
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006154603.9699-2-freude@linux.ibm.com \
--to=freude@linux.ibm.com \
--cc=agordeev@linux.ibm.com \
--cc=dengler@linux.ibm.com \
--cc=fcallies@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox