From patchwork Wed Sep 4 17:56:32 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 172960 Delivered-To: patch@linaro.org Received: by 2002:ac9:5c4b:0:0:0:0:0 with SMTP id r11csp1068330ocp; Wed, 4 Sep 2019 11:32:02 -0700 (PDT) X-Google-Smtp-Source: APXvYqyW2X3KkmXOK+mtpJ5fMQ1j8pSYOHVKLK7CTlFLW1wSY0qItemdbtX8k5jETrivuy/VW4Tj X-Received: by 2002:a63:505a:: with SMTP id q26mr35295889pgl.18.1567621922477; Wed, 04 Sep 2019 11:32:02 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1567621922; cv=none; d=google.com; s=arc-20160816; b=IF6wHvMqyIIzrccmNVW6Rid8UFw7rVdGSudcf3AETGhooWPFJdVLSb8kr4BVuM12MZ Ap7uVjiMsMkWAS4aI5CAYX0XBg5BsagV/+oXEShEioQZA2neVblGXxnACj1rPvhiqoLc h03kz4LFMjk9o5tLlAVSHn1pCB8B/VoamGD3bP7+6DYLz2usQQCikbh/6rrFy0tHQlRH PaSgMDn0GKGggJAggM3B1gs+nCPNsdszuQWgEHpPazVBCSvb8Xc4Laj9gB8UtOMsYyEs xtynVH8jsCaJn4dGk0FYwVQO8xhdCA31Noj341TuVc49dH+X1q7dD5xWg+5gZ/5Nwerq EeyQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:date:subject:cc:to:from :dkim-signature; bh=kzUvJ4x+cBUYsW/Z5UZs0WRC1GlvmsgHO4UKe0rgIe8=; b=rDgqKR2ZOjgZmDm9BFjblsyA/7NhabFH0kU+dsuNEJJjwCYjx4beqi3uDKQ9kDVwus Mam+8ptgXOW4HMom7l+QXZM7jts6fhMShVi1QFxIjF8On7EME0WQS1tluRyWvXMO/poo 7P5uqMPkIQ5DiGVNxDyiiiqvO1YTyPNybM0EZtPbT/sCleu3DHyvLNaN66zZlCSHnz4k ddoUfw4dvqp+nLgAe207vvblq4+6Dv0LhMTzGshyFYC+pnrb4qkyOOFNSCojjEO8+GhL Q5L7cqXGcytBM1FhVPfSf5XkMhmlBObD5VWlSuXcEijexGA2ZbMKILP7CVLFbbC4V3JO kmtA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=JAH4mrnP; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id i6si2874654pjs.13.2019.09.04.11.32.01; Wed, 04 Sep 2019 11:32:02 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=JAH4mrnP; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732142AbfIDS1L (ORCPT + 3 others); Wed, 4 Sep 2019 14:27:11 -0400 Received: from mail-pf1-f196.google.com ([209.85.210.196]:32830 "EHLO mail-pf1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2387670AbfIDR4m (ORCPT ); Wed, 4 Sep 2019 13:56:42 -0400 Received: by mail-pf1-f196.google.com with SMTP id q10so8662119pfl.0 for ; Wed, 04 Sep 2019 10:56:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id; bh=kzUvJ4x+cBUYsW/Z5UZs0WRC1GlvmsgHO4UKe0rgIe8=; b=JAH4mrnPzvo2U8nPir/dh5Olg3utEpstjsa8f+a0TUCRfTkHD3xPywAlnd//2vRuYR tW1EuQCIGcYRPlUIlCUGe6t9OocMN675aBPUKMZ91OPf/BtfHBPYGvr3mNiMK6DuWNto XXL3WNNmOI4zQ0H2ka2bZHWxT2wViIZGru12TzzG9XdflUUjO2bPurEM7zmoUT/IeBgK 0IPQnDBA7oikZvoBtGlssugHo//G09BJmCwQdIx74IHFLJ+Dlf09FKvy5iC3cOCz1Dff azUEyO83h5BEavDxR/RGbzey0Q731Zmnrudxz9+c5lIPQEX+UoWzZX5yzV8ao2w/7VXw sf/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=kzUvJ4x+cBUYsW/Z5UZs0WRC1GlvmsgHO4UKe0rgIe8=; b=Ra+oolCXvGbSDKkI5ee6vgFIsauOOU9iEYnB2WRrgawvCR59yoCU/OEMazayeQvJY4 /EO0wrBUjqYoibTQ4mu+eWGhoEPmB2fNUQXKhtYMhb9ZZeoi7Sx/EEtmEue41toRCmh8 oSze1aqGaIr1UiA7G2QJHGNtm2N0RvFCPfwTi3Bo9YJVT2y2GPV8WFzFY2ck0hg71ULm tXQ42VTKZznbZwTg3pGbJIx+j803I8A1nxpDht+aGqGOpAdNCKxm+9S4ytR3sglIIE5x 6oVSGrDiLecQmHM73h8+ZX7QUi345god/QiKYPzrFJkjrkAa4oHChXACX7dX5ghndtbP AHxQ== X-Gm-Message-State: APjAAAVFgDjsgyIjDOUMc1OwbniiZLZG/WfAFiS27eUJsDCxGHRXr3OP A3aIIG9J83wSpD7CqPIOWuom3LH36s9XiPSk X-Received: by 2002:a17:90a:ba96:: with SMTP id t22mr6411962pjr.104.1567619801071; Wed, 04 Sep 2019 10:56:41 -0700 (PDT) Received: from e111045-lin.nice.arm.com ([104.133.8.102]) by smtp.gmail.com with ESMTPSA id ce7sm2924900pjb.16.2019.09.04.10.56.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 04 Sep 2019 10:56:40 -0700 (PDT) From: Ard Biesheuvel To: linux-crypto@vger.kernel.org Cc: herbert@gondor.apana.org.au, Ard Biesheuvel Subject: [PATCH] crypto: x86/aes-ni - use AES library instead of single-use AES cipher Date: Wed, 4 Sep 2019 10:56:32 -0700 Message-Id: <20190904175632.5546-1-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 2.17.1 Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org The RFC4106 key derivation code instantiates an AES cipher transform to encrypt only a single block before it is freed again. Switch to the new AES library which is more suitable for such use cases. Signed-off-by: Ard Biesheuvel --- arch/x86/crypto/aesni-intel_glue.c | 17 ++++++----------- 1 file changed, 6 insertions(+), 11 deletions(-) -- 2.17.1 diff --git a/arch/x86/crypto/aesni-intel_glue.c b/arch/x86/crypto/aesni-intel_glue.c index bf12bb71cecc..3e707e81afdb 100644 --- a/arch/x86/crypto/aesni-intel_glue.c +++ b/arch/x86/crypto/aesni-intel_glue.c @@ -628,26 +628,21 @@ static int xts_decrypt(struct skcipher_request *req) static int rfc4106_set_hash_subkey(u8 *hash_subkey, const u8 *key, unsigned int key_len) { - struct crypto_cipher *tfm; + struct crypto_aes_ctx ctx; int ret; - tfm = crypto_alloc_cipher("aes", 0, 0); - if (IS_ERR(tfm)) - return PTR_ERR(tfm); - - ret = crypto_cipher_setkey(tfm, key, key_len); + ret = aes_expandkey(&ctx, key, key_len); if (ret) - goto out_free_cipher; + return ret; /* Clear the data in the hash sub key container to zero.*/ /* We want to cipher all zeros to create the hash sub key. */ memset(hash_subkey, 0, RFC4106_HASH_SUBKEY_SIZE); - crypto_cipher_encrypt_one(tfm, hash_subkey, hash_subkey); + aes_encrypt(&ctx, hash_subkey, hash_subkey); -out_free_cipher: - crypto_free_cipher(tfm); - return ret; + memzero_explicit(&ctx, sizeof(ctx)); + return 0; } static int common_rfc4106_set_key(struct crypto_aead *aead, const u8 *key,