From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0002e601.pphosted.com (mx0b-0002e601.pphosted.com [148.163.154.28]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B079D4AB3C0; Wed, 30 Sep 2026 13:00:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=148.163.154.28 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790773236; cv=fail; b=Ki+B3cGmD8UKmVhoQ9IMf3aAqVZD/A3NcM0jUPluozzyJfF3/CSifWEqEqt7saGpzGHgsTOttCd04qb9E6UIIWn4Q4or1Y//Xbb3P03qT7n25YB03oLUZ28UYfcd9Z0YXn3vIBvgro1Bot6azRLeCyWzIE6+Ewg0LWFLbDOIyB4= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790773236; c=relaxed/simple; bh=ETiH608gFqP/LN8YspmBFExIQvlTXGQFejk32JmBw+k=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Y5qS+2cbODF3TopgZuvOc2ZWp/ejDnnDJyB87a1xYqNbFDtykDqaYiR/EMXJaTWveSmYTgrv7LxUcLfiCJx0C251MSXuKIJoKJt8I4rPFKMKKZ0k2cAO1b+XGlR4OwsdB1kr0rRTKjdPCt9F3RZ0O7MrGwWZtZbK6ndt65DvSFg= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=ti.com; spf=pass smtp.mailfrom=ti.com; dkim=pass (2048-bit key) header.d=ti.com header.i=@ti.com header.b=DNHTfMZ5; dkim=pass (1024-bit key) header.d=ticloud.onmicrosoft.com header.i=@ticloud.onmicrosoft.com header.b=nd05J9nl; arc=fail smtp.client-ip=148.163.154.28 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=ti.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ti.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ti.com header.i=@ti.com header.b="DNHTfMZ5"; dkim=pass (1024-bit key) header.d=ticloud.onmicrosoft.com header.i=@ticloud.onmicrosoft.com header.b="nd05J9nl" Received: from pps.filterd (m0374955.ppops.net [127.0.0.1]) by mx0b-0002e601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68UB61oR3214079; Wed, 30 Sep 2026 08:00:18 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ti.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s= proofpoint-05-2026; bh=yN+cbQdydLHEXPtxBhfRIW3PMlfOPTP7xmQJQTrPc z0=; b=DNHTfMZ5lH3FP2IIA3NnZwLOR5VO8QSu7R95iOAHVuQrfbiNKpprJ4c3b 1mH90W6uVOHauZAYM4m8fLSxrrysEbUkcKIrprhI80hIYL2f1kg425xg+T+oUoKZ iRANiPOvim9Le0BX1q0xfQ+EFwUzRlcl0v5DHmb7f5i7oDiBHpRcM8Sxq63Ze3Ua m9tlVNgjSGjZv2qN3/gYd6i//+NvbqJMfBUqFqrqvOmlkDxjwR7gx9Buvm1I2XGt 6CHLou4tlk6IhrVralNgj7hRHadtANhZo79T70RRnNh06R9BeklPdpTD/Ni2BtNy YBxmqzDNS1JSKS3CzHKHVZJApOL2A== Received: from co1pr03cu002.outbound.protection.outlook.com (mail-westus2azon11010068.outbound.protection.outlook.com [52.101.46.68]) by mx0b-0002e601.pphosted.com (PPS) with ESMTPS id 4h0ydv95v6-1 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Wed, 30 Sep 2026 08:00:17 -0500 (CDT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MQqiZWyIO8Ont/nXDt3QV2Uy44NAODwYd0bS+EAnLCF8R4EEze7XqeX6lcztUdEII5FC7W0CrNm/oLOLG1WPPPwmqikHwoE3lNudhm7F4WCBmYB/2WqojqPw9rv7fS0SLQOgApXzBbEBbNf48K03yWz9vb71c+4OugXXXP8REA3tiAMkGZiDp2+hHsJi12d2uTFjI7pBZPqoNym1Sx17WoIldg6vqkZYL2ZnrDT5EPNinpnC1a/u8/081h1bWer5qP1UDnAw6B0Sos2c1sA6jhuZYLohhwNECPo9J8N4giKwH67Bs0Ctkk9BhuBCwBqBk1vJcw4PQBj0J0JJzDOOYg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=yN+cbQdydLHEXPtxBhfRIW3PMlfOPTP7xmQJQTrPcz0=; b=AcfKJWZP23XtLXoze5SFlGMuPCC7mRFypp4tQsfq9z32GpTHdRyT8ACMysFdAnRSHPkT11YmLgknQzVBzooqwpdASymdosaypunw13cAopgNsAP7cJ6S5xeEsZt1uwuhiKMRh8NoZvEs/hXRynDHP9ilTSoK81qcQaTiGCBQnG26RFTeWMNE4/7pIoL7yHaIQHY12Tqf3OoW2VFCavNpNDGeAImva91v2anFo7lCVDdmNbrwSDSgtXUtPHT5S/ugeNPBms/7YWIQCooALyU2Dr/gP5y8yqmn0lfsM/qzptfXtD4rsI71jfLvwFVdpGTIeFOo0EsC4odL6Fe0wjvKPQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 198.47.21.195) smtp.rcpttodomain=gondor.apana.org.au smtp.mailfrom=ti.com; dmarc=pass (p=quarantine sp=none pct=100) action=none header.from=ti.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ticloud.onmicrosoft.com; s=selector1-ticloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yN+cbQdydLHEXPtxBhfRIW3PMlfOPTP7xmQJQTrPcz0=; b=nd05J9nl00svV6BuIUfz5pwusOxvH/5ucLi5K8lZsZsqHOKK78YQTz/wLwKYaaQjaFq7y/9kvRFqi579vvQPLFyp4tYUvQhWuEc7HPUKvF2RtIUITEZFyVL4eneNsqu74Ex/jqS5+quLb2tAm5acHV6nAAX4lNwvHjUNzB8vKEs= Received: from BL1PR13CA0304.namprd13.prod.outlook.com (2603:10b6:208:2c1::9) by MN0PR10MB5911.namprd10.prod.outlook.com (2603:10b6:208:3cd::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.472.7; Wed, 30 Sep 2026 13:00:06 +0000 Received: from BN3PEPF0000B071.namprd04.prod.outlook.com (2603:10b6:208:2c1:cafe::a7) by BL1PR13CA0304.outlook.office365.com (2603:10b6:208:2c1::9) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.382.7 via Frontend Transport; Wed, 30 Sep 2026 13:00:06 +0000 X-MS-Exchange-Authentication-Results: mx.microsoft.com 1; spf=pass (sender IP is 198.47.21.195) smtp.mailfrom=ti.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=ti.com; Received-SPF: Pass (protection.outlook.com: domain of ti.com designates 198.47.21.195 as permitted sender) receiver=protection.outlook.com; client-ip=198.47.21.195; helo=flwvzet201.ext.ti.com; pr=C Received: from flwvzet201.ext.ti.com (198.47.21.195) by BN3PEPF0000B071.mail.protection.outlook.com (10.167.243.116) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.472.14 via Frontend Transport; Wed, 30 Sep 2026 13:00:04 +0000 Received: from DFLE213.ent.ti.com (10.64.6.71) by flwvzet201.ext.ti.com (10.248.192.32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 30 Sep 2026 07:59:18 -0500 Received: from DFLE210.ent.ti.com (10.64.6.68) by DFLE213.ent.ti.com (10.64.6.71) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 30 Sep 2026 07:59:18 -0500 Received: from lelvem-mr06.itg.ti.com (10.180.75.8) by DFLE210.ent.ti.com (10.64.6.68) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45 via Frontend Transport; Wed, 30 Sep 2026 07:59:18 -0500 Received: from pratham-Workstation-PC (pratham-workstation-pc.dhcp.ti.com [10.24.53.205]) by lelvem-mr06.itg.ti.com (8.18.1/8.18.1) with ESMTP id 68UCxGCM3153798; Wed, 30 Sep 2026 07:59:17 -0500 From: T Pratham To: T Pratham , Herbert Xu , "David S. Miller" CC: Sebin Francis , Manorit Chawdhry , Praneeth Bajjuri , Vishal Mahaveer , , Subject: [PATCH v7 04/15] crypto: ti - Fix use-after-free of dev_data on DTHEv2 driver removal Date: Wed, 30 Sep 2026 18:28:48 +0530 Message-ID: <20260930125859.1749849-5-t-pratham@ti.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260930125859.1749849-1-t-pratham@ti.com> References: <20260930125859.1749849-1-t-pratham@ti.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B071:EE_|MN0PR10MB5911:EE_ X-MS-Office365-Filtering-Correlation-Id: b32a1b50-2e56-4f44-2b62-08df1ef2bf58 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|36860700016|82310400026|376014|1800799024|56012099006|22082099003|18002099003|10067099003; X-Microsoft-Antispam-Message-Info: R85koE7pO+1bAoqEsetfWD6XfCy7hBDLVw1GYfzNc/TOHeCer18a7Nn8TkqF8sFTW57XvBuc1cs6nWI1hLfplGxYukALcSW5Wn5r8PPsCKQ2zhzy+zjjicV3Dv3WzyVh8nJBdCHwULwLVWDS0s00zecLSDHAtA3sAAbL9fk0goKoSFKqoLqFQTfql1An/O7Lv6m401CnnC7tNsxXsbpz4zkrcF7kiDQk2Cl/vKyWlUFX8cugUREAUypVDpRpvhjbS8s9QwyzySs88WbK2k+dsGlKiIpmrNvDWpys61PSh0OTZF24LuQNN5Q4IZ2YHr3KsJ3A1iATlpLPuFnYGNjfdRjzhSdJmjenStMFddX0/8EaXBjzIogENLAFJE/PkcpoJ923wHeCmWrDmRDV8UddSupLyF9GFqg3wMRi79d4K/U1//Avd8uI/j4MnFb3crLud/Lcb4d7dh1YgvUyCLSJ5eDnWQXQzSVv6W5A+KDovke0RewGMhm5ZJHU3oG4lSldWfDv968fyzLUx4aaoQO0JPL/eYTlGNSfHNoKd8SvEK6164HCTthTgP6WHcQYy2BiuKN9SF4xKlEZz9kzS0zCdHZDjl5nHtVjFYJTFgwpR67LLfwWK8jLwqU34BiRECcWi9y8HetCoxst8eXaUfaDG1RtzyP+0C8YFuk8kRMHqlj/AOoQ/0BTBbIXVS64Qmq0Lq/cRod9H68Cf7bpkhG05A== X-Forefront-Antispam-Report: CIP:198.47.21.195;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:flwvzet201.ext.ti.com;PTR:ErrorRetry;CAT:NONE;SFS:(13230040)(23010399003)(36860700016)(82310400026)(376014)(1800799024)(56012099006)(22082099003)(18002099003)(10067099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: KkC3fBO52c561WuDPoTCsYeflV7l8G4wClxQQfg3v+6cS3cQ8VBVrG2rCMfH7mPeoKzLMC6segiEICiRiDnnQk8pihkJCGKuObXRZwu5LfyknOMNMHbb6gRQdr9ToSXMMllzlqm/Y+vFVPxBWRYSPv3b9tOpvi5AjTXwoZA5lxIjy6uJa7NVkxI9PRxLoiJzWtSXLuhA3QgX6HGmpxln1OxY7olsCARbWFasdMoFLE7i3eBVx1l1om9WrnCXPD7ooT2U7s48KraN5Kv3ZbRJ6KFn1WN/O4ylcyJmAw7hggxOOcRE9dcSg4vARh7mEFrAkVGqe7eaP2lTUy99sGraMiABb72rF3ne+3lK4lLcT9jyohGyHGMjiJ5TdVMeSqFviydbrpEaveSffWui4475iJ70UnpkKL4gC9B8WgbdVENt5leWmDXHxljalNwSNemt X-Exchange-RoutingPolicyChecked: q6JZprOTGQLaKoVndLZ8KhRIQu9lDe+3sUkwIv7uGHojFnZRm6q5D8mVE/P3GgpElkTQNXtduP+U2UcWu6vMaip4VY/Dw10IL2fAC0N/mA2wvQsq/AFLNJz307WspxqVd1Fuio0Uk3SfRNzoykVUJ5PeWsg/EHhlQRQs+5EQ454gtJeZTy9AiotthwECLeO57sFe7yOBjP3NLwTAsLP9KawMFg4Lp68lW58IUHA1RYE33qLGY5UtVfDudJgpMzfF21TkMT1neleoI6BTKqjRcuDtWYeuJqjHBPys9r9YgCvwFxx3vcbElgE1O9PS1xW5M9C82brf5IvDwCMJOIF5nQ== X-OriginatorOrg: ti.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Sep 2026 13:00:04.9820 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: b32a1b50-2e56-4f44-2b62-08df1ef2bf58 X-MS-Exchange-CrossTenant-Id: e5b49634-450b-4709-8abb-1e2b19b982b7 X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=e5b49634-450b-4709-8abb-1e2b19b982b7;Ip=[198.47.21.195];Helo=[flwvzet201.ext.ti.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B071.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN0PR10MB5911 X-Proofpoint-Spam-Info: AW1haW4tMjYwOTMwMDA1MSBTYWx0ZWRfX8mYDIitG8xEg ybr8es6xEQZ29nKdrS5nUeBgJwFOkDGy9uToxNaMwAIxutErO4zSThgkRwFJpERv2dyeiyuvyie UjSUE+Io/3FdYPQ4noi7EjdGE+jXmgY= X-Proofpoint-GUID: S156AafdhSUnTyrbyzIynD70kQThOq0P X-Authority-Analysis: v=2.4 cv=TegDJhQh c=1 sm=1 tr=0 ts=6abd07e1 cx=c_pps a=bquUzJqYOqw1EpBvECFzMQ==:117 a=tJyPKKxUohctrY4NYmUjkA==:17 a=6eWqkTHjU83fiwn7nKZWdM+Sl24=:19 a=VdqzKS8jKosA:10 a=AlMIdn_sM9wA:10 a=VkNPw1HP01LnGYTKEx00:22 a=Z8NIEmU8O1QQgoT56wFK:22 a=fPAWb5peG099m5CrUpKH:22 a=sozttTNsAAAA:8 a=wGUsS79KCXjsn4X1cW0A:9 X-Proofpoint-ORIG-GUID: S156AafdhSUnTyrbyzIynD70kQThOq0P X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTMwMDA1MSBTYWx0ZWRfX5R5PgLxJOTTF tpj9rEgKIXth1mERTfz/26d/p/6XZn1R8/hDlfpqjHkVlrJO8F8HG9ZW14awcbDbm6Tci+IC+WP S9SWUcynogbgBwWqyTuComDbpU/QvLRxeI+5v3JwGrwDjeqJZRVWeN6IC9S0W6P9h1KftpVn7zg NAAPp9LnwkHM/1QSxSsLld0dIUKVGsZfw5rPncHj4ic3sGCXVmq6Q9N4JyinP9BU6NJMNFMxV4f pje3h8tLgSr5ipyHYm9cEOaTgD26vX8ZZbsuSFRXsPLEXYINo6bgDa8GsxA8HX4d1devjsaHNDZ lckuDsq6tsa1IFIjLcBiAZA3zCOnji7S2YBSA1mRDMZyospHrQdi8RxfTtG599xGJrOBhSVxpRY 9Dy8ma/KgaBlsxQJ3wS2QTEI9zaiQKI2n0BtqPJqkAPBfoWR+5aHtl52SCievY8Jb5N8WlpsaGv TMvlP8qMZbKzKkZgXDg== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-30_02,2026-09-21_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 lowpriorityscore=0 malwarescore=0 phishscore=0 bulkscore=0 clxscore=1015 priorityscore=1501 adultscore=0 suspectscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609300051 Each *_init_tfm() caches a pointer to the per-instance struct dthe_data in its transform context (ctx->dev_data), but never takes a reference on it. If there are tfms in progress when dthe_remove() is called, the devm allocated dev_data gets freed. Then ctx->dev_data will point to a memory that has been freed. Move dthe_data to req_ctx structs of algorithms, and store the device pointer in tfm_ctx. Add a refcnt to struct dthe_data, which atomically counts the number of requests enqueued in the crypto engine queue which reference the dthe_data object. A waitqueue waits on this atomic counter to get back to zero in dthe_remove() before doing the driver teardown. Fixes: 52f641bc63a46 ("crypto: ti - Add driver for DTHE V2 AES Engine (ECB, CBC)") Signed-off-by: T Pratham --- drivers/crypto/ti/dthev2-aes.c | 74 +++++++++++++++++++++---------- drivers/crypto/ti/dthev2-common.c | 43 +++++++++++++++--- drivers/crypto/ti/dthev2-common.h | 53 ++++++++++++++++++++-- 3 files changed, 138 insertions(+), 32 deletions(-) diff --git a/drivers/crypto/ti/dthev2-aes.c b/drivers/crypto/ti/dthev2-aes.c index 4fdd24ee91637..6a8fbe67ef6cd 100644 --- a/drivers/crypto/ti/dthev2-aes.c +++ b/drivers/crypto/ti/dthev2-aes.c @@ -110,12 +110,11 @@ enum aes_ctrl_mode_masks { static int dthe_cipher_init_tfm(struct crypto_skcipher *tfm) { struct dthe_tfm_ctx *ctx = crypto_skcipher_ctx(tfm); - struct dthe_data *dev_data = dthe_get_dev(ctx); - if (!dev_data) + ctx->dev = dthe_get_dev(); + if (!dev) return -ENODEV; - ctx->dev_data = dev_data; ctx->keylen = 0; return 0; @@ -124,20 +123,19 @@ static int dthe_cipher_init_tfm(struct crypto_skcipher *tfm) static int dthe_cipher_init_tfm_fallback(struct crypto_skcipher *tfm) { struct dthe_tfm_ctx *ctx = crypto_skcipher_ctx(tfm); - struct dthe_data *dev_data = dthe_get_dev(ctx); const char *alg_name = crypto_tfm_alg_name(crypto_skcipher_tfm(tfm)); - if (!dev_data) + ctx->dev = dthe_get_dev(); + if (!ctx->dev) return -ENODEV; - ctx->dev_data = dev_data; ctx->keylen = 0; - ctx->skcipher_fb = crypto_alloc_sync_skcipher(alg_name, 0, CRYPTO_ALG_NEED_FALLBACK); if (IS_ERR(ctx->skcipher_fb)) { - dev_err(dev_data->dev, "fallback driver %s couldn't be loaded\n", + dev_err(ctx->dev, "fallback driver %s couldn't be loaded\n", alg_name); + dthe_put_dev(ctx->dev); return PTR_ERR(ctx->skcipher_fb); } @@ -149,6 +147,7 @@ static void dthe_cipher_exit_tfm(struct crypto_skcipher *tfm) struct dthe_tfm_ctx *ctx = crypto_skcipher_ctx(tfm); crypto_free_sync_skcipher(ctx->skcipher_fb); + dthe_put_dev(ctx->dev); } static int dthe_aes_setkey(struct crypto_skcipher *tfm, const u8 *key, unsigned int keylen) @@ -225,7 +224,7 @@ static void dthe_aes_set_ctrl_key(struct dthe_tfm_ctx *ctx, struct dthe_aes_req_ctx *rctx, u32 *iv_in) { - struct dthe_data *dev_data = dthe_get_dev(ctx); + struct dthe_data *dev_data = rctx->dev_data; void __iomem *aes_base_reg = dev_data->regs + DTHE_P_AES_BASE; u32 ctrl_val = 0; @@ -337,8 +336,8 @@ static int dthe_aes_run(struct crypto_engine *engine, void *areq) { struct skcipher_request *req = container_of(areq, struct skcipher_request, base); struct dthe_tfm_ctx *ctx = crypto_skcipher_ctx(crypto_skcipher_reqtfm(req)); - struct dthe_data *dev_data = dthe_get_dev(ctx); struct dthe_aes_req_ctx *rctx = skcipher_request_ctx(req); + struct dthe_data *dev_data = rctx->dev_data; unsigned int len = req->cryptlen; struct scatterlist *src = req->src; @@ -520,14 +519,17 @@ static int dthe_aes_run(struct crypto_engine *engine, void *areq) local_bh_disable(); crypto_finalize_skcipher_request(dev_data->engine, req, ret); local_bh_enable(); + dthe_put_drvdata(dev_data); return 0; } static int dthe_aes_crypt(struct skcipher_request *req) { struct dthe_tfm_ctx *ctx = crypto_skcipher_ctx(crypto_skcipher_reqtfm(req)); - struct dthe_data *dev_data = dthe_get_dev(ctx); + struct dthe_aes_req_ctx *rctx = skcipher_request_ctx(req); + struct dthe_data *dev_data; struct crypto_engine *engine; + int ret; /* * If data is not a multiple of AES_BLOCK_SIZE: @@ -553,8 +555,18 @@ static int dthe_aes_crypt(struct skcipher_request *req) return 0; } + dev_data = dthe_get_drvdata(ctx->dev); + if (!dev_data) + return -ENODEV; + + rctx->dev_data = dev_data; + engine = dev_data->engine; - return crypto_transfer_skcipher_request_to_engine(engine, req); + ret = crypto_transfer_skcipher_request_to_engine(engine, req); + if (ret != -EINPROGRESS && ret != -EBUSY) + dthe_put_drvdata(dev_data); + + return ret; } static int dthe_aes_encrypt(struct skcipher_request *req) @@ -576,19 +588,18 @@ static int dthe_aes_decrypt(struct skcipher_request *req) static int dthe_aead_init_tfm(struct crypto_aead *tfm) { struct dthe_tfm_ctx *ctx = crypto_aead_ctx(tfm); - struct dthe_data *dev_data = dthe_get_dev(ctx); const char *alg_name = crypto_tfm_alg_name(crypto_aead_tfm(tfm)); - if (!dev_data) + ctx->dev = dthe_get_dev(); + if (!ctx->dev) return -ENODEV; - ctx->dev_data = dev_data; - ctx->aead_fb = crypto_alloc_sync_aead(alg_name, 0, CRYPTO_ALG_NEED_FALLBACK); if (IS_ERR(ctx->aead_fb)) { - dev_err(dev_data->dev, "fallback driver %s couldn't be loaded\n", + dev_err(ctx->dev, "fallback driver %s couldn't be loaded\n", alg_name); + dthe_put_dev(ctx->dev); return PTR_ERR(ctx->aead_fb); } @@ -600,6 +611,7 @@ static void dthe_aead_exit_tfm(struct crypto_aead *tfm) struct dthe_tfm_ctx *ctx = crypto_aead_ctx(tfm); crypto_free_sync_aead(ctx->aead_fb); + dthe_put_dev(ctx->dev); } /** @@ -711,9 +723,9 @@ static struct scatterlist *dthe_aead_prep_crypt(struct scatterlist *sg, return crypt_sg; } -static int dthe_aead_read_tag(struct dthe_tfm_ctx *ctx, u32 *tag) +static int dthe_aead_read_tag(struct dthe_aes_req_ctx *rctx, u32 *tag) { - struct dthe_data *dev_data = dthe_get_dev(ctx); + struct dthe_data *dev_data = rctx->dev_data; void __iomem *aes_base_reg = dev_data->regs + DTHE_P_AES_BASE; u32 val; int ret; @@ -734,11 +746,12 @@ static int dthe_aead_read_tag(struct dthe_tfm_ctx *ctx, u32 *tag) static int dthe_aead_enc_get_tag(struct aead_request *req) { struct dthe_tfm_ctx *ctx = crypto_aead_ctx(crypto_aead_reqtfm(req)); + struct dthe_aes_req_ctx *rctx = aead_request_ctx(req); u32 tag[AES_BLOCK_WORDS]; int nents; int ret; - ret = dthe_aead_read_tag(ctx, tag); + ret = dthe_aead_read_tag(rctx, tag); if (ret) return ret; @@ -753,12 +766,13 @@ static int dthe_aead_enc_get_tag(struct aead_request *req) static int dthe_aead_dec_verify_tag(struct aead_request *req) { struct dthe_tfm_ctx *ctx = crypto_aead_ctx(crypto_aead_reqtfm(req)); + struct dthe_aes_req_ctx *rctx = aead_request_ctx(req); u32 tag_out[AES_BLOCK_WORDS]; u32 tag_in[AES_BLOCK_WORDS]; int nents; int ret; - ret = dthe_aead_read_tag(ctx, tag_out); + ret = dthe_aead_read_tag(rctx, tag_out); if (ret) return ret; @@ -859,7 +873,7 @@ static int dthe_aead_run(struct crypto_engine *engine, void *areq) struct aead_request *req = container_of(areq, struct aead_request, base); struct dthe_tfm_ctx *ctx = crypto_aead_ctx(crypto_aead_reqtfm(req)); struct dthe_aes_req_ctx *rctx = aead_request_ctx(req); - struct dthe_data *dev_data = dthe_get_dev(ctx); + struct dthe_data *dev_data = rctx->dev_data; unsigned int cryptlen = req->cryptlen; unsigned int assoclen = req->assoclen; @@ -1130,6 +1144,7 @@ static int dthe_aead_run(struct crypto_engine *engine, void *areq) local_bh_disable(); crypto_finalize_aead_request(engine, req, ret); local_bh_enable(); + dthe_put_drvdata(dev_data); return 0; } @@ -1137,10 +1152,11 @@ static int dthe_aead_crypt(struct aead_request *req) { struct dthe_tfm_ctx *ctx = crypto_aead_ctx(crypto_aead_reqtfm(req)); struct dthe_aes_req_ctx *rctx = aead_request_ctx(req); - struct dthe_data *dev_data = dthe_get_dev(ctx); + struct dthe_data *dev_data; struct crypto_engine *engine; unsigned int cryptlen = req->cryptlen; bool is_zero_ctr = true; + int ret; /* In decryption, last authsize bytes are the TAG */ if (!rctx->enc) @@ -1191,8 +1207,18 @@ static int dthe_aead_crypt(struct aead_request *req) (ctx->aes_mode == DTHE_AES_CCM && !is_zero_ctr)) return dthe_aead_do_fallback(req); + dev_data = dthe_get_drvdata(ctx->dev); + if (!dev_data) + return -ENODEV; + + rctx->dev_data = dev_data; + engine = dev_data->engine; - return crypto_transfer_aead_request_to_engine(engine, req); + ret = crypto_transfer_aead_request_to_engine(engine, req); + if (ret != -EINPROGRESS && ret != -EBUSY) + dthe_put_drvdata(dev_data); + + return ret; } static int dthe_aead_encrypt(struct aead_request *req) diff --git a/drivers/crypto/ti/dthev2-common.c b/drivers/crypto/ti/dthev2-common.c index b8b02b82317b8..12ecdc5362756 100644 --- a/drivers/crypto/ti/dthev2-common.c +++ b/drivers/crypto/ti/dthev2-common.c @@ -31,22 +31,48 @@ static struct dthe_list dthe_dev_list = { .lock = __SPIN_LOCK_UNLOCKED(dthe_dev_list.lock), }; -struct dthe_data *dthe_get_dev(struct dthe_tfm_ctx *ctx) +struct device *dthe_get_dev(void) { struct dthe_data *dev_data; - - if (ctx->dev_data) - return ctx->dev_data; + struct device *dev = NULL; spin_lock_bh(&dthe_dev_list.lock); dev_data = list_first_entry_or_null(&dthe_dev_list.dev_list, struct dthe_data, list); - if (dev_data) + if (dev_data) { list_move_tail(&dev_data->list, &dthe_dev_list.dev_list); + dev = get_device(dev_data->dev); + } + spin_unlock_bh(&dthe_dev_list.lock); + + return dev; +} + +void dthe_put_dev(struct device *dev) +{ + put_device(dev); +} + +struct dthe_data *dthe_get_drvdata(struct device *dev) +{ + struct dthe_data *dev_data; + + spin_lock_bh(&dthe_dev_list.lock); + dev_data = dev_get_drvdata(dev); + if (dev_data && !atomic_fetch_inc(&dev_data->req_refcnt)) + reinit_completion(&dev_data->drain_compl); spin_unlock_bh(&dthe_dev_list.lock); return dev_data; } +void dthe_put_drvdata(struct dthe_data *dev_data) +{ + spin_lock_bh(&dthe_dev_list.lock); + if (atomic_dec_and_test(&dev_data->req_refcnt)) + complete(&dev_data->drain_compl); + spin_unlock_bh(&dthe_dev_list.lock); +} + struct scatterlist *dthe_copy_sg(struct scatterlist *dst, struct scatterlist *src, unsigned int buflen) @@ -152,6 +178,10 @@ static int dthe_probe(struct platform_device *pdev) if (IS_ERR(dev_data->regs)) return PTR_ERR(dev_data->regs); + atomic_set(&dev_data->req_refcnt, 0); + init_completion(&dev_data->drain_compl); + complete(&dev_data->drain_compl); + platform_set_drvdata(pdev, dev_data); spin_lock_bh(&dthe_dev_list.lock); @@ -202,10 +232,13 @@ static void dthe_remove(struct platform_device *pdev) spin_lock_bh(&dthe_dev_list.lock); list_del(&dev_data->list); + platform_set_drvdata(pdev, NULL); spin_unlock_bh(&dthe_dev_list.lock); dthe_unregister_algs(); + wait_for_completion(&dev_data->drain_compl); + crypto_engine_exit(dev_data->engine); dma_release_channel(dev_data->dma_aes_rx); diff --git a/drivers/crypto/ti/dthev2-common.h b/drivers/crypto/ti/dthev2-common.h index 75d9a097650da..0e2f5bc07afe1 100644 --- a/drivers/crypto/ti/dthev2-common.h +++ b/drivers/crypto/ti/dthev2-common.h @@ -18,6 +18,8 @@ #include #include +#include +#include #include #include #include @@ -53,6 +55,9 @@ enum dthe_aes_mode { * @dma_aes_rx: AES Rx DMA Channel * @dma_aes_tx: AES Tx DMA Channel * @dma_sha_tx: SHA Tx DMA Channel + * @req_refcnt: Count of requests currently using this instance. + * @drain_compl: Completed whenever @req_refcnt drops to zero; waited on by + * dthe_remove(). */ struct dthe_data { struct device *dev; @@ -64,6 +69,9 @@ struct dthe_data { struct dma_chan *dma_aes_tx; struct dma_chan *dma_sha_tx; + + atomic_t req_refcnt; + struct completion drain_compl; }; /** @@ -78,7 +86,7 @@ struct dthe_list { /** * struct dthe_tfm_ctx - Transform ctx struct containing ctx for all sub-components of DTHE V2 - * @dev_data: Device data struct pointer + * @dev: Device this transform is bound to. * @keylen: AES key length * @authsize: Authentication size for modes with authentication * @key: AES key @@ -87,7 +95,7 @@ struct dthe_list { * @skcipher_fb: Fallback crypto skcipher handle for AES-XTS mode */ struct dthe_tfm_ctx { - struct dthe_data *dev_data; + struct device *dev; unsigned int keylen; unsigned int authsize; u32 key[DTHE_MAX_KEYSIZE / sizeof(u32)]; @@ -103,16 +111,55 @@ struct dthe_tfm_ctx { * @enc: flag indicating encryption or decryption operation * @padding: padding buffer for handling unaligned data * @aes_compl: Completion variable for use in manual completion in case of DMA callback failure + * @dev_data: Device data struct pointer */ struct dthe_aes_req_ctx { int enc; u8 padding[2 * AES_BLOCK_SIZE]; struct completion aes_compl; + struct dthe_data *dev_data; }; /* Struct definitions end */ -struct dthe_data *dthe_get_dev(struct dthe_tfm_ctx *ctx); +/** + * dthe_get_dev - Get the device pointer after increasing its reference count + * + * Description: + * Picks a device instance and gets the associated device pointer through get_device() + * to maintain its reference count by the kernel itself. Callers must ensure to call + * dthe_put_dev() at exit to decrease the refcnt. + */ +struct device *dthe_get_dev(void); + +/** + * dthe_put_dev - Decrease the reference count of the device + * @dev: Device pointer to be released + * + * Description: + * Decreases the reference count of the device pointer obtained through dthe_get_dev() + * by calling put_device(). + */ +void dthe_put_dev(struct device *dev); + +/** + * dthe_get_drvdata - Get a reference counted device driver data pointer + * @dev: Device pointer + * + * Description: + * Returns the instance's driver data if it is still bound, with @req_refcnt + * incremented, or NULL if it has been removed. Every req accepted for + * processing must call this and balance it with exactly one + * dthe_put_drvdata() when done. + */ +struct dthe_data *dthe_get_drvdata(struct device *dev); + +/** + * dthe_put_drvdata - Decrease the refcnt of the device driver data acquired through + * dthe_get_drvdata() + * @dev_data: Driver data previously returned by dthe_get_drvdata() + */ +void dthe_put_drvdata(struct dthe_data *dev_data); /** * dthe_copy_sg - Copy sg entries from src to dst -- 2.34.1