summaryrefslogtreecommitdiff
path: root/crypto
diff options
context:
space:
mode:
authorRichard Weinberger <richard@nod.at>2026-07-26 21:27:16 +0200
committerHerbert Xu <herbert@gondor.apana.org.au>2026-07-30 17:44:21 +1000
commit285d8204638cf8be0dc304dc40f0290ada701340 (patch)
treea8b03b16cf06a033118b57485f74984d958b044f /crypto
parent6b36f13891ab4709b7d60023005176cdd5c368cf (diff)
downloadlinux-285d8204638cf8be0dc304dc40f0290ada701340.tar.gz
linux-285d8204638cf8be0dc304dc40f0290ada701340.zip
crypto: af_alg - Allow cbc(paes)
Commit 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") breaks a special use case. The cbc-paes-caam driver implements the algorithm cbc(paes), it offers a way to use AES in CBC mode with key material unknown to userspace. Instead of an AES key a CAAM BLOB is passed to the kernel. So, this crypto operation cannot be implemented in a userspace library and needs always help from the kernel. Explicitly allow this use case. Cc: Demi Marie Obenour <demiobenour@gmail.com> Suggested-by: Eric Biggers <ebiggers@kernel.org> Fixes: 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") Signed-off-by: Richard Weinberger <richard@nod.at> Reviewed-by: Eric Biggers <ebiggers@kernel.org> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Diffstat (limited to 'crypto')
-rw-r--r--crypto/algif_skcipher.c8
1 files changed, 7 insertions, 1 deletions
diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index df20bdfe1f1f..035fed7db81f 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -32,6 +32,7 @@
#include <linux/mm.h>
#include <linux/module.h>
#include <linux/net.h>
+#include <linux/string.h>
#include <net/sock.h>
static int skcipher_sendmsg(struct socket *sock, struct msghdr *msg,
@@ -309,7 +310,12 @@ static struct proto_ops algif_skcipher_ops_nokey = {
static void *skcipher_bind(const char *name)
{
- return crypto_alloc_skcipher(name, 0, AF_ALG_CRYPTOAPI_MASK);
+ u32 mask = AF_ALG_CRYPTOAPI_MASK;
+
+ if (strcmp(name, "cbc(paes)") == 0)
+ mask = 0;
+
+ return crypto_alloc_skcipher(name, 0, mask);
}
static void skcipher_release(void *private)