crypto: ccree - dec auth tag size from cryptlen map
authorGilad Ben-Yossef <gilad@benyossef.com>
Sun, 2 Feb 2020 16:19:14 +0000 (18:19 +0200)
committerHerbert Xu <herbert@gondor.apana.org.au>
Thu, 13 Feb 2020 09:05:25 +0000 (17:05 +0800)
Remove the auth tag size from cryptlen before mapping the destination
in out-of-place AEAD decryption thus resolving a crash with
extended testmgr tests.

Signed-off-by: Gilad Ben-Yossef <gilad@benyossef.com>
Reported-by: Geert Uytterhoeven <geert+renesas@glider.be>
Cc: stable@vger.kernel.org # v4.19+
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
drivers/crypto/ccree/cc_buffer_mgr.c

index 885347b..954f14b 100644 (file)
@@ -894,8 +894,12 @@ static int cc_aead_chain_data(struct cc_drvdata *drvdata,
 
        if (req->src != req->dst) {
                size_for_map = areq_ctx->assoclen + req->cryptlen;
-               size_for_map += (direct == DRV_CRYPTO_DIRECTION_ENCRYPT) ?
-                               authsize : 0;
+
+               if (direct == DRV_CRYPTO_DIRECTION_ENCRYPT)
+                       size_for_map += authsize;
+               else
+                       size_for_map -= authsize;
+
                if (is_gcm4543)
                        size_for_map += crypto_aead_ivsize(tfm);