The branch main has been updated by jhb:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=6e17a2e00d62fd3041e0bb511fe925079ad1c0d7

commit 6e17a2e00d62fd3041e0bb511fe925079ad1c0d7
Author:     John Baldwin <[email protected]>
AuthorDate: 2021-12-09 19:52:41 +0000
Commit:     John Baldwin <[email protected]>
CommitDate: 2021-12-09 19:52:41 +0000

    crypto: Validate AES-GCM IV length in check_csp().
    
    This centralizes the check for valid nonce lengths for AES-GCM.
    
    While here, remove some duplicate checks for valid AES-GCM tag lengths
    from ccp(4) and ccr(4).
    
    Reviewed by:    markj
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D33194
---
 sys/crypto/aesni/aesni.c         | 3 +--
 sys/crypto/armv8/armv8_crypto.c  | 2 --
 sys/crypto/ccp/ccp.c             | 5 -----
 sys/dev/cxgbe/crypto/t4_crypto.c | 6 ------
 sys/dev/qat/qat.c                | 2 --
 sys/dev/safexcel/safexcel.c      | 3 ---
 sys/opencrypto/crypto.c          | 5 ++++-
 sys/opencrypto/cryptosoft.c      | 3 ---
 8 files changed, 5 insertions(+), 24 deletions(-)

diff --git a/sys/crypto/aesni/aesni.c b/sys/crypto/aesni/aesni.c
index cd31287b08f0..a69488971cac 100644
--- a/sys/crypto/aesni/aesni.c
+++ b/sys/crypto/aesni/aesni.c
@@ -305,8 +305,7 @@ aesni_probesession(device_t dev, const struct 
crypto_session_params *csp)
                        if (csp->csp_auth_mlen != 0 &&
                            csp->csp_auth_mlen != GMAC_DIGEST_LEN)
                                return (EINVAL);
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN ||
-                           !sc->has_aes)
+                       if (!sc->has_aes)
                                return (EINVAL);
                        break;
                case CRYPTO_AES_CCM_16:
diff --git a/sys/crypto/armv8/armv8_crypto.c b/sys/crypto/armv8/armv8_crypto.c
index 95bb96124323..0811a1c03390 100644
--- a/sys/crypto/armv8/armv8_crypto.c
+++ b/sys/crypto/armv8/armv8_crypto.c
@@ -217,8 +217,6 @@ armv8_crypto_probesession(device_t dev,
                case CRYPTO_AES_NIST_GCM_16:
                        if (!sc->has_pmul)
                                return (EINVAL);
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-                               return (EINVAL);
                        if (csp->csp_auth_mlen != 0 &&
                            csp->csp_auth_mlen != GMAC_DIGEST_LEN)
                                return (EINVAL);
diff --git a/sys/crypto/ccp/ccp.c b/sys/crypto/ccp/ccp.c
index 51679942c386..4ceb028b593e 100644
--- a/sys/crypto/ccp/ccp.c
+++ b/sys/crypto/ccp/ccp.c
@@ -378,11 +378,6 @@ ccp_probesession(device_t dev, const struct 
crypto_session_params *csp)
        case CSP_MODE_AEAD:
                switch (csp->csp_cipher_alg) {
                case CRYPTO_AES_NIST_GCM_16:
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-                               return (EINVAL);
-                       if (csp->csp_auth_mlen < 0 ||
-                           csp->csp_auth_mlen > AES_GMAC_HASH_LEN)
-                               return (EINVAL);
                        if ((sc->hw_features & VERSION_CAP_AES) == 0)
                                return (EINVAL);
                        break;
diff --git a/sys/dev/cxgbe/crypto/t4_crypto.c b/sys/dev/cxgbe/crypto/t4_crypto.c
index fae77423aaa5..5ad239d56dfc 100644
--- a/sys/dev/cxgbe/crypto/t4_crypto.c
+++ b/sys/dev/cxgbe/crypto/t4_crypto.c
@@ -2540,12 +2540,6 @@ ccr_probesession(device_t dev, const struct 
crypto_session_params *csp)
        case CSP_MODE_AEAD:
                switch (csp->csp_cipher_alg) {
                case CRYPTO_AES_NIST_GCM_16:
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-                               return (EINVAL);
-                       if (csp->csp_auth_mlen < 0 ||
-                           csp->csp_auth_mlen > AES_GMAC_HASH_LEN)
-                               return (EINVAL);
-                       break;
                case CRYPTO_AES_CCM_16:
                        break;
                default:
diff --git a/sys/dev/qat/qat.c b/sys/dev/qat/qat.c
index 49cb408fd702..68a3d2053f54 100644
--- a/sys/dev/qat/qat.c
+++ b/sys/dev/qat/qat.c
@@ -1911,8 +1911,6 @@ qat_probesession(device_t dev, const struct 
crypto_session_params *csp)
        case CSP_MODE_AEAD:
                switch (csp->csp_cipher_alg) {
                case CRYPTO_AES_NIST_GCM_16:
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-                               return EINVAL;
                        break;
                default:
                        return EINVAL;
diff --git a/sys/dev/safexcel/safexcel.c b/sys/dev/safexcel/safexcel.c
index dc43b7dfc026..5a0ddc804da0 100644
--- a/sys/dev/safexcel/safexcel.c
+++ b/sys/dev/safexcel/safexcel.c
@@ -2304,9 +2304,6 @@ safexcel_probesession(device_t dev, const struct 
crypto_session_params *csp)
        case CSP_MODE_AEAD:
                switch (csp->csp_cipher_alg) {
                case CRYPTO_AES_NIST_GCM_16:
-                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-                               return (EINVAL);
-                       break;
                case CRYPTO_AES_CCM_16:
                        break;
                default:
diff --git a/sys/opencrypto/crypto.c b/sys/opencrypto/crypto.c
index cc0e5860c882..1fe8a1377157 100644
--- a/sys/opencrypto/crypto.c
+++ b/sys/opencrypto/crypto.c
@@ -851,7 +851,10 @@ check_csp(const struct crypto_session_params *csp)
                                return (false);
                        break;
                case CRYPTO_AES_NIST_GCM_16:
-                       if (csp->csp_auth_mlen > 16)
+                       if (csp->csp_auth_mlen > AES_GMAC_HASH_LEN)
+                               return (false);
+
+                       if (csp->csp_ivlen != AES_GCM_IV_LEN)
                                return (false);
                        break;
                case CRYPTO_CHACHA20_POLY1305:
diff --git a/sys/opencrypto/cryptosoft.c b/sys/opencrypto/cryptosoft.c
index f8dfef5323d5..5013cf145288 100644
--- a/sys/opencrypto/cryptosoft.c
+++ b/sys/opencrypto/cryptosoft.c
@@ -1308,9 +1308,6 @@ swcr_setup_gcm(struct swcr_session *ses,
        struct swcr_auth *swa;
        const struct auth_hash *axf;
 
-       if (csp->csp_ivlen != AES_GCM_IV_LEN)
-               return (EINVAL);
-
        /* First, setup the auth side. */
        swa = &ses->swcr_auth;
        switch (csp->csp_cipher_klen * 8) {

Reply via email to