commit | 2e207237ed731b20c6088fcf976a275d26a68754 | [log] [tgz] |
---|---|---|
author | Jakub Kicinski <[email protected]> | Tue Feb 06 17:18:21 2024 -0800 |
committer | COS Cherry Picker <[email protected]> | Mon Mar 25 10:39:31 2024 -0700 |
tree | fe3c6a08ec7e60eb9704a3acf61124a9d5c85986 | |
parent | 3f210da309023fecbb54e0b87a193714c72b8077 [diff] |
net: tls: handle backlogging of crypto requests [ Upstream commit 8590541473188741055d27b955db0777569438e3 ] Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case, the async callback will also be called twice: first with err == -EINPROGRESS, which it seems we can just ignore, then with err == 0. Compared to Sabrina's original patch this version uses the new tls_*crypt_async_wait() helpers and converts the EBUSY to EINPROGRESS to avoid having to modify all the error handling paths. The handling is identical. BUG=b/326485556 TEST=presubmit RELEASE_NOTE=Fixed CVE-2024-26584 in the Linux kernel. cos-patch: security-high Fixes: a54667f6728c ("tls: Add support for encryption using async offload accelerator") Fixes: 94524d8fc965 ("net/tls: Add support for async decryption of tls records") Co-developed-by: Sabrina Dubroca <[email protected]> Signed-off-by: Sabrina Dubroca <[email protected]> Link: https://lore.kernel.org/netdev/9681d1febfec295449a62300938ed2ae66983f28.1694018970.git.sd@queasysnail.net/ Signed-off-by: Jakub Kicinski <[email protected]> Reviewed-by: Simon Horman <[email protected]> Signed-off-by: David S. Miller <[email protected]> Signed-off-by: Sasha Levin <[email protected]> (cherry picked from commit 13eca403876bbea3716e82cdfe6f1e6febb38754) Signed-off-by: Robert Kolchmeyer <[email protected]> Change-Id: Icc1d39df83e746a7e6cd4aec4bd02854612355dc Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/67110 Reviewed-by: Oleksandr Tymoshenko <[email protected]> Main-Branch-Verified: Cusky Presubmit Bot <[email protected]> Tested-by: Cusky Presubmit Bot <[email protected]>