mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 0/2] lib/crypto: arm64: Fix Poly1305 NEON resume carry loss
@ 2026-10-08 20:19 Jérémy Jean
  2026-10-08 20:19 ` [PATCH v2 1/2] lib/crypto: arm64: Fix lost Poly1305 carry when resuming NEON state Jérémy Jean
  2026-10-08 20:19 ` [PATCH v2 2/2] lib/crypto: tests: Add Poly1305 split-update carry regression test Jérémy Jean
  0 siblings, 2 replies; 6+ messages in thread
From: Jérémy Jean @ 2026-10-08 20:19 UTC (permalink / raw)
  To: Eric Biggers, Jason A. Donenfeld, Ard Biesheuvel
  Cc: linux-crypto, linux-kernel, Jérémy Jean

When poly1305_blocks_neon() resumes from a base 2^26 accumulator with an
odd number of blocks, its base conversion can lose a carry into the top
limb and emit a wrong tag.

Patch 1 fixes the lost carry. Patch 2 adds a KUnit regression for the
split-update witness that triggers it.

Changes in v2:
 - detail the computations reaching the bug and improve commit message, 
 - add a KUnit regression test.

Jérémy Jean (2):
  lib/crypto: arm64: Fix lost Poly1305 carry when resuming NEON state
  lib/crypto: tests: Add Poly1305 split-update carry regression test

 lib/crypto/arm64/poly1305-armv8.pl |  2 +-
 lib/crypto/tests/poly1305_kunit.c  | 31 ++++++++++++++++++++++++++++++
 2 files changed, 32 insertions(+), 1 deletion(-)

-- 
2.47.3

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-09 14:27 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 20:19 [PATCH v2 0/2] lib/crypto: arm64: Fix Poly1305 NEON resume carry loss Jérémy Jean
2026-10-08 20:19 ` [PATCH v2 1/2] lib/crypto: arm64: Fix lost Poly1305 carry when resuming NEON state Jérémy Jean
2026-10-09 13:03   ` Eric Biggers
2026-10-09 13:26     ` Jérémy Jean
2026-10-09 14:27       ` Eric Biggers
2026-10-08 20:19 ` [PATCH v2 2/2] lib/crypto: tests: Add Poly1305 split-update carry regression test Jérémy Jean

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®