From patchwork Tue Dec 16 14:19:28 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Taras Kondratiuk X-Patchwork-Id: 42334 Return-Path: X-Original-To: linaro@patches.linaro.org Delivered-To: linaro@patches.linaro.org Received: from mail-wi0-f198.google.com (mail-wi0-f198.google.com [209.85.212.198]) by ip-10-151-82-157.ec2.internal (Postfix) with ESMTPS id 0C7F126C54 for ; Tue, 16 Dec 2014 14:20:05 +0000 (UTC) Received: by mail-wi0-f198.google.com with SMTP id r20sf5016776wiv.1 for ; Tue, 16 Dec 2014 06:20:04 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:delivered-to:from:to:date:message-id:in-reply-to :references:subject:precedence:list-id:list-unsubscribe:list-archive :list-post:list-help:list-subscribe:mime-version:content-type :content-transfer-encoding:errors-to:sender:x-original-sender :x-original-authentication-results:mailing-list; bh=MEnd40pJiNpLEGDmvdDgY0hWILXhpkI8uSMNfIQCFHs=; b=mxUtvvHTuuWDzJeG0CsJkaTXNSmpFAYhk/z7nUKPO88vU/g97+9qdG6GHcmyOLNA1v lx7BwWhv91BKZZoIwNxAQwLpEWLOrS0SCGHoZDzI/LM2pWmoU5bHBrjhNk72GJYmQAbY ei9QmTjS8OIsWgRm95Hu+UjI/1cxUr+Loks0WTyVm55UeibgfdzSmi7m72wX5tyemXWf 0TdVYegwW34NSZ/lXIT3FaZoVIMJ4VKQPYMH3G2wBX9NhxDVizcHQHcIA6WgUEpggR7J LPV+o+2sgC90fIW867oxhM1mGOXjYVzG+AlYvBYJlZ9iW3f2Z9oog96xuo1XxIC7is7u e1gA== X-Gm-Message-State: ALoCoQlkjpqCDuVayVvNXdhy5PEg5sImgo5ga2t8C1YyZUAASlvrQApppFfCs0NMjwxpcarXxpIT X-Received: by 10.112.154.232 with SMTP id vr8mr397984lbb.10.1418739604301; Tue, 16 Dec 2014 06:20:04 -0800 (PST) X-BeenThere: patchwork-forward@linaro.org Received: by 10.152.5.166 with SMTP id t6ls996478lat.20.gmail; Tue, 16 Dec 2014 06:20:04 -0800 (PST) X-Received: by 10.152.28.71 with SMTP id z7mr36096361lag.60.1418739604161; Tue, 16 Dec 2014 06:20:04 -0800 (PST) Received: from mail-la0-f48.google.com (mail-la0-f48.google.com. [209.85.215.48]) by mx.google.com with ESMTPS id o4si920583lah.75.2014.12.16.06.20.04 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 16 Dec 2014 06:20:04 -0800 (PST) Received-SPF: pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.215.48 as permitted sender) client-ip=209.85.215.48; Received: by mail-la0-f48.google.com with SMTP id gf13so11080002lab.7 for ; Tue, 16 Dec 2014 06:20:04 -0800 (PST) X-Received: by 10.152.234.35 with SMTP id ub3mr36228650lac.70.1418739604057; Tue, 16 Dec 2014 06:20:04 -0800 (PST) X-Forwarded-To: patchwork-forward@linaro.org X-Forwarded-For: patch@linaro.org patchwork-forward@linaro.org Delivered-To: patch@linaro.org Received: by 10.112.142.69 with SMTP id ru5csp1051159lbb; Tue, 16 Dec 2014 06:20:03 -0800 (PST) X-Received: by 10.224.135.193 with SMTP id o1mr41969514qat.97.1418739602129; Tue, 16 Dec 2014 06:20:02 -0800 (PST) Received: from ip-10-35-177-41.ec2.internal (lists.linaro.org. [54.225.227.206]) by mx.google.com with ESMTPS id c9si994241qci.18.2014.12.16.06.20.01 (version=TLSv1 cipher=RC4-SHA bits=128/128); Tue, 16 Dec 2014 06:20:02 -0800 (PST) Received-SPF: none (google.com: lng-odp-bounces@lists.linaro.org does not designate permitted sender hosts) client-ip=54.225.227.206; Received: from localhost ([127.0.0.1] helo=ip-10-35-177-41.ec2.internal) by ip-10-35-177-41.ec2.internal with esmtp (Exim 4.76) (envelope-from ) id 1Y0syi-0001fk-6y; Tue, 16 Dec 2014 14:19:56 +0000 Received: from mail-lb0-f170.google.com ([209.85.217.170]) by ip-10-35-177-41.ec2.internal with esmtp (Exim 4.76) (envelope-from ) id 1Y0syW-0001eB-5j for lng-odp@lists.linaro.org; Tue, 16 Dec 2014 14:19:44 +0000 Received: by mail-lb0-f170.google.com with SMTP id 10so11066548lbg.29 for ; Tue, 16 Dec 2014 06:19:38 -0800 (PST) X-Received: by 10.152.204.9 with SMTP id ku9mr35991429lac.55.1418739578590; Tue, 16 Dec 2014 06:19:38 -0800 (PST) Received: from uglx0153363.synapse.com ([195.238.92.128]) by mx.google.com with ESMTPSA id l9sm240769lae.0.2014.12.16.06.19.37 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Tue, 16 Dec 2014 06:19:38 -0800 (PST) From: Taras Kondratiuk To: lng-odp@lists.linaro.org, robking@cisco.com Date: Tue, 16 Dec 2014 16:19:28 +0200 Message-Id: <1418739571-656-2-git-send-email-taras.kondratiuk@linaro.org> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1418739571-656-1-git-send-email-taras.kondratiuk@linaro.org> References: <1418739571-656-1-git-send-email-taras.kondratiuk@linaro.org> X-Topics: crypto patch Subject: [lng-odp] [PATCHv2 1/4] linux-generic: crypto: always make a copy of IV X-BeenThere: lng-odp@lists.linaro.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: , List-Help: , List-Subscribe: , MIME-Version: 1.0 Errors-To: lng-odp-bounces@lists.linaro.org Sender: lng-odp-bounces@lists.linaro.org X-Removed-Original-Auth: Dkim didn't pass. X-Original-Sender: taras.kondratiuk@linaro.org X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.215.48 as permitted sender) smtp.mail=patch+caf_=patchwork-forward=linaro.org@linaro.org Mailing-list: list patchwork-forward@linaro.org; contact patchwork-forward+owners@linaro.org X-Google-Group-Id: 836684582541 DES library modifies IV buffer in-place. Current code handles this correctly only in case of encryption operation with session IV. To prevent user buffer modifications always make a copy of a provided IV. Signed-off-by: Taras Kondratiuk --- platform/linux-generic/odp_crypto.c | 50 +++++++++++++++++++++---------------- 1 file changed, 28 insertions(+), 22 deletions(-) diff --git a/platform/linux-generic/odp_crypto.c b/platform/linux-generic/odp_crypto.c index d3cdec7..a2d4ab8 100644 --- a/platform/linux-generic/odp_crypto.c +++ b/platform/linux-generic/odp_crypto.c @@ -147,30 +147,25 @@ enum crypto_alg_err des_encrypt(odp_crypto_op_params_t *params, { uint8_t *data = odp_packet_addr(params->out_pkt); uint32_t len = params->cipher_range.length; - DES_cblock *iv = NULL; - DES_cblock iv_temp; + DES_cblock iv; + void *iv_ptr; + + if (params->override_iv_ptr) + iv_ptr = params->override_iv_ptr; + else if (session->cipher.iv.data) + iv_ptr = session->cipher.iv.data; + else + return ODP_CRYPTO_SES_CREATE_ERR_INV_CIPHER; /* * Create a copy of the IV. The DES library modifies IV * and if we are processing packets on parallel threads * we could get corruption. */ - if (session->cipher.iv.data) { - memcpy(iv_temp, session->cipher.iv.data, sizeof(iv_temp)); - iv = &iv_temp; - } + memcpy(iv, iv_ptr, sizeof(iv)); /* Adjust pointer for beginning of area to cipher */ data += params->cipher_range.offset; - - /* Override IV if requested */ - if (params->override_iv_ptr) - iv = (DES_cblock *)params->override_iv_ptr; - - /* No session or operation IV */ - if (!iv) - return ODP_CRYPTO_SES_CREATE_ERR_INV_CIPHER; - /* Encrypt it */ DES_ede3_cbc_encrypt(data, data, @@ -178,7 +173,7 @@ enum crypto_alg_err des_encrypt(odp_crypto_op_params_t *params, &session->cipher.data.des.ks1, &session->cipher.data.des.ks2, &session->cipher.data.des.ks3, - iv, + &iv, 1); return ODP_CRYPTO_ALG_ERR_NONE; @@ -190,15 +185,26 @@ enum crypto_alg_err des_decrypt(odp_crypto_op_params_t *params, { uint8_t *data = odp_packet_addr(params->out_pkt); uint32_t len = params->cipher_range.length; - DES_cblock *iv = (DES_cblock *)session->cipher.iv.data; + DES_cblock iv; + void *iv_ptr; + + if (params->override_iv_ptr) + iv_ptr = params->override_iv_ptr; + else if (session->cipher.iv.data) + iv_ptr = session->cipher.iv.data; + else + return ODP_CRYPTO_SES_CREATE_ERR_INV_CIPHER; + + /* + * Create a copy of the IV. The DES library modifies IV + * and if we are processing packets on parallel threads + * we could get corruption. + */ + memcpy(iv, iv_ptr, sizeof(iv)); /* Adjust pointer for beginning of area to cipher */ data += params->cipher_range.offset; - /* Override IV if requested */ - if (params->override_iv_ptr) - iv = (DES_cblock *)params->override_iv_ptr; - /* Decrypt it */ DES_ede3_cbc_encrypt(data, data, @@ -206,7 +212,7 @@ enum crypto_alg_err des_decrypt(odp_crypto_op_params_t *params, &session->cipher.data.des.ks1, &session->cipher.data.des.ks2, &session->cipher.data.des.ks3, - iv, + &iv, 0); return ODP_CRYPTO_ALG_ERR_NONE;