提交 059c5342 编写于 作者: L Longfang Liu 提交者: Herbert Xu

crypto: hisilicon/sec - Fixes AES algorithm mode parameter problem

The input data of the ECB (AES) algorithm needs to be aligned
with 16 bytes, and the input data of the XTS (AES) algorithm is
at least 16 bytes. Otherwise the SEC hardware will go wrong.
Signed-off-by: NLongfang Liu <liulongfang@huawei.com>
Signed-off-by: NHerbert Xu <herbert@gondor.apana.org.au>
上级 0ae86992
...@@ -1397,6 +1397,36 @@ static int sec_aead_sha512_ctx_init(struct crypto_aead *tfm) ...@@ -1397,6 +1397,36 @@ static int sec_aead_sha512_ctx_init(struct crypto_aead *tfm)
return sec_aead_ctx_init(tfm, "sha512"); return sec_aead_ctx_init(tfm, "sha512");
} }
static int sec_skcipher_cryptlen_ckeck(struct sec_ctx *ctx,
struct sec_req *sreq)
{
u32 cryptlen = sreq->c_req.sk_req->cryptlen;
struct device *dev = ctx->dev;
u8 c_mode = ctx->c_ctx.c_mode;
int ret = 0;
switch (c_mode) {
case SEC_CMODE_XTS:
if (unlikely(cryptlen < AES_BLOCK_SIZE)) {
dev_err(dev, "skcipher XTS mode input length error!\n");
ret = -EINVAL;
}
break;
case SEC_CMODE_ECB:
case SEC_CMODE_CBC:
if (unlikely(cryptlen & (AES_BLOCK_SIZE - 1))) {
dev_err(dev, "skcipher AES input length error!\n");
ret = -EINVAL;
}
break;
default:
ret = -EINVAL;
}
return ret;
}
static int sec_skcipher_param_check(struct sec_ctx *ctx, struct sec_req *sreq) static int sec_skcipher_param_check(struct sec_ctx *ctx, struct sec_req *sreq)
{ {
struct skcipher_request *sk_req = sreq->c_req.sk_req; struct skcipher_request *sk_req = sreq->c_req.sk_req;
...@@ -1421,12 +1451,9 @@ static int sec_skcipher_param_check(struct sec_ctx *ctx, struct sec_req *sreq) ...@@ -1421,12 +1451,9 @@ static int sec_skcipher_param_check(struct sec_ctx *ctx, struct sec_req *sreq)
} }
return 0; return 0;
} else if (c_alg == SEC_CALG_AES || c_alg == SEC_CALG_SM4) { } else if (c_alg == SEC_CALG_AES || c_alg == SEC_CALG_SM4) {
if (unlikely(sk_req->cryptlen & (AES_BLOCK_SIZE - 1))) { return sec_skcipher_cryptlen_ckeck(ctx, sreq);
dev_err(dev, "skcipher aes input length error!\n");
return -EINVAL;
}
return 0;
} }
dev_err(dev, "skcipher algorithm error!\n"); dev_err(dev, "skcipher algorithm error!\n");
return -EINVAL; return -EINVAL;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册