From: Richard Weinberger Date: Sun, 26 Jul 2026 19:27:16 +0000 (+0200) Subject: crypto: af_alg - Allow cbc(paes) X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=285d8204638cf8be0dc304dc40f0290ada701340;p=thirdparty%2Fkernel%2Flinux.git crypto: af_alg - Allow cbc(paes) Commit 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") breaks a special use case. The cbc-paes-caam driver implements the algorithm cbc(paes), it offers a way to use AES in CBC mode with key material unknown to userspace. Instead of an AES key a CAAM BLOB is passed to the kernel. So, this crypto operation cannot be implemented in a userspace library and needs always help from the kernel. Explicitly allow this use case. Cc: Demi Marie Obenour Suggested-by: Eric Biggers Fixes: 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") Signed-off-by: Richard Weinberger Reviewed-by: Eric Biggers Signed-off-by: Herbert Xu --- diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c index df20bdfe1f1f..035fed7db81f 100644 --- a/crypto/algif_skcipher.c +++ b/crypto/algif_skcipher.c @@ -32,6 +32,7 @@ #include #include #include +#include #include static int skcipher_sendmsg(struct socket *sock, struct msghdr *msg, @@ -309,7 +310,12 @@ static struct proto_ops algif_skcipher_ops_nokey = { static void *skcipher_bind(const char *name) { - return crypto_alloc_skcipher(name, 0, AF_ALG_CRYPTOAPI_MASK); + u32 mask = AF_ALG_CRYPTOAPI_MASK; + + if (strcmp(name, "cbc(paes)") == 0) + mask = 0; + + return crypto_alloc_skcipher(name, 0, mask); } static void skcipher_release(void *private)