]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
crypto: authenc - use memcpy_sglist() instead of null skcipher
authorEric Biggers <ebiggers@google.com>
Thu, 30 Apr 2026 06:27:27 +0000 (23:27 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 30 Apr 2026 09:19:11 +0000 (11:19 +0200)
commit dbc4b1458e931e47198c3165ff5853bc1ad6bd7a upstream.

For copying data between two scatterlists, just use memcpy_sglist()
instead of the so-called "null skcipher".  This is much simpler.

Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
crypto/Kconfig
crypto/authenc.c
crypto/authencesn.c

index 649619df922c91f867f6ba8a1b97648d7bca00de..2e2978e2939f11440e75c0e99294a70772cadf29 100644 (file)
@@ -216,7 +216,6 @@ config CRYPTO_AUTHENC
        select CRYPTO_SKCIPHER
        select CRYPTO_MANAGER
        select CRYPTO_HASH
-       select CRYPTO_NULL
        help
          Authenc: Combined mode wrapper for IPsec.
 
index 17f674a7cdff5434a213f66f66ca5c6976b565de..2b402e764529c3f5d6a628f321f21e6d2580599e 100644 (file)
@@ -9,7 +9,6 @@
 #include <crypto/internal/hash.h>
 #include <crypto/internal/skcipher.h>
 #include <crypto/authenc.h>
-#include <crypto/null.h>
 #include <crypto/scatterwalk.h>
 #include <linux/err.h>
 #include <linux/init.h>
@@ -28,7 +27,6 @@ struct authenc_instance_ctx {
 struct crypto_authenc_ctx {
        struct crypto_ahash *auth;
        struct crypto_skcipher *enc;
-       struct crypto_sync_skcipher *null;
 };
 
 struct authenc_request_ctx {
@@ -174,21 +172,6 @@ out:
        authenc_request_complete(areq, err);
 }
 
-static int crypto_authenc_copy_assoc(struct aead_request *req)
-{
-       struct crypto_aead *authenc = crypto_aead_reqtfm(req);
-       struct crypto_authenc_ctx *ctx = crypto_aead_ctx(authenc);
-       SYNC_SKCIPHER_REQUEST_ON_STACK(skreq, ctx->null);
-
-       skcipher_request_set_sync_tfm(skreq, ctx->null);
-       skcipher_request_set_callback(skreq, aead_request_flags(req),
-                                     NULL, NULL);
-       skcipher_request_set_crypt(skreq, req->src, req->dst, req->assoclen,
-                                  NULL);
-
-       return crypto_skcipher_encrypt(skreq);
-}
-
 static int crypto_authenc_encrypt(struct aead_request *req)
 {
        struct crypto_aead *authenc = crypto_aead_reqtfm(req);
@@ -207,10 +190,7 @@ static int crypto_authenc_encrypt(struct aead_request *req)
        dst = src;
 
        if (req->src != req->dst) {
-               err = crypto_authenc_copy_assoc(req);
-               if (err)
-                       return err;
-
+               memcpy_sglist(req->dst, req->src, req->assoclen);
                dst = scatterwalk_ffwd(areq_ctx->dst, req->dst, req->assoclen);
        }
 
@@ -311,7 +291,6 @@ static int crypto_authenc_init_tfm(struct crypto_aead *tfm)
        struct crypto_authenc_ctx *ctx = crypto_aead_ctx(tfm);
        struct crypto_ahash *auth;
        struct crypto_skcipher *enc;
-       struct crypto_sync_skcipher *null;
        int err;
 
        auth = crypto_spawn_ahash(&ictx->auth);
@@ -323,14 +302,8 @@ static int crypto_authenc_init_tfm(struct crypto_aead *tfm)
        if (IS_ERR(enc))
                goto err_free_ahash;
 
-       null = crypto_get_default_null_skcipher();
-       err = PTR_ERR(null);
-       if (IS_ERR(null))
-               goto err_free_skcipher;
-
        ctx->auth = auth;
        ctx->enc = enc;
-       ctx->null = null;
 
        crypto_aead_set_reqsize(
                tfm,
@@ -344,8 +317,6 @@ static int crypto_authenc_init_tfm(struct crypto_aead *tfm)
 
        return 0;
 
-err_free_skcipher:
-       crypto_free_skcipher(enc);
 err_free_ahash:
        crypto_free_ahash(auth);
        return err;
@@ -357,7 +328,6 @@ static void crypto_authenc_exit_tfm(struct crypto_aead *tfm)
 
        crypto_free_ahash(ctx->auth);
        crypto_free_skcipher(ctx->enc);
-       crypto_put_default_null_skcipher();
 }
 
 static void crypto_authenc_free(struct aead_instance *inst)
index 6487b35851d54a6d99b8d376151661f2655cecae..fceee6d67d34cf3de51a1932705a048614396ee1 100644 (file)
@@ -12,7 +12,6 @@
 #include <crypto/internal/hash.h>
 #include <crypto/internal/skcipher.h>
 #include <crypto/authenc.h>
-#include <crypto/null.h>
 #include <crypto/scatterwalk.h>
 #include <linux/err.h>
 #include <linux/init.h>
@@ -31,7 +30,6 @@ struct crypto_authenc_esn_ctx {
        unsigned int reqoff;
        struct crypto_ahash *auth;
        struct crypto_skcipher *enc;
-       struct crypto_sync_skcipher *null;
 };
 
 struct authenc_esn_request_ctx {
@@ -164,20 +162,6 @@ static void crypto_authenc_esn_encrypt_done(struct crypto_async_request *req,
        authenc_esn_request_complete(areq, err);
 }
 
-static int crypto_authenc_esn_copy(struct aead_request *req, unsigned int len)
-{
-       struct crypto_aead *authenc_esn = crypto_aead_reqtfm(req);
-       struct crypto_authenc_esn_ctx *ctx = crypto_aead_ctx(authenc_esn);
-       SYNC_SKCIPHER_REQUEST_ON_STACK(skreq, ctx->null);
-
-       skcipher_request_set_sync_tfm(skreq, ctx->null);
-       skcipher_request_set_callback(skreq, aead_request_flags(req),
-                                     NULL, NULL);
-       skcipher_request_set_crypt(skreq, req->src, req->dst, len, NULL);
-
-       return crypto_skcipher_encrypt(skreq);
-}
-
 static int crypto_authenc_esn_encrypt(struct aead_request *req)
 {
        struct crypto_aead *authenc_esn = crypto_aead_reqtfm(req);
@@ -199,10 +183,7 @@ static int crypto_authenc_esn_encrypt(struct aead_request *req)
        dst = src;
 
        if (req->src != req->dst) {
-               err = crypto_authenc_esn_copy(req, assoclen);
-               if (err)
-                       return err;
-
+               memcpy_sglist(req->dst, req->src, assoclen);
                sg_init_table(areq_ctx->dst, 2);
                dst = scatterwalk_ffwd(areq_ctx->dst, req->dst, assoclen);
        }
@@ -292,11 +273,8 @@ static int crypto_authenc_esn_decrypt(struct aead_request *req)
 
        cryptlen -= authsize;
 
-       if (req->src != dst) {
-               err = crypto_authenc_esn_copy(req, assoclen + cryptlen);
-               if (err)
-                       return err;
-       }
+       if (req->src != dst)
+               memcpy_sglist(dst, req->src, assoclen + cryptlen);
 
        scatterwalk_map_and_copy(ihash, req->src, assoclen + cryptlen,
                                 authsize, 0);
@@ -332,7 +310,6 @@ static int crypto_authenc_esn_init_tfm(struct crypto_aead *tfm)
        struct crypto_authenc_esn_ctx *ctx = crypto_aead_ctx(tfm);
        struct crypto_ahash *auth;
        struct crypto_skcipher *enc;
-       struct crypto_sync_skcipher *null;
        int err;
 
        auth = crypto_spawn_ahash(&ictx->auth);
@@ -344,14 +321,8 @@ static int crypto_authenc_esn_init_tfm(struct crypto_aead *tfm)
        if (IS_ERR(enc))
                goto err_free_ahash;
 
-       null = crypto_get_default_null_skcipher();
-       err = PTR_ERR(null);
-       if (IS_ERR(null))
-               goto err_free_skcipher;
-
        ctx->auth = auth;
        ctx->enc = enc;
-       ctx->null = null;
 
        ctx->reqoff = ALIGN(2 * crypto_ahash_digestsize(auth),
                            crypto_ahash_alignmask(auth) + 1);
@@ -368,8 +339,6 @@ static int crypto_authenc_esn_init_tfm(struct crypto_aead *tfm)
 
        return 0;
 
-err_free_skcipher:
-       crypto_free_skcipher(enc);
 err_free_ahash:
        crypto_free_ahash(auth);
        return err;
@@ -381,7 +350,6 @@ static void crypto_authenc_esn_exit_tfm(struct crypto_aead *tfm)
 
        crypto_free_ahash(ctx->auth);
        crypto_free_skcipher(ctx->enc);
-       crypto_put_default_null_skcipher();
 }
 
 static void crypto_authenc_esn_free(struct aead_instance *inst)