crypto: chacha20 - Fix unaligned access when loading constants
authorEric Biggers <ebiggers@google.com>
Wed, 22 Nov 2017 19:51:35 +0000 (11:51 -0800)
committerHerbert Xu <herbert@gondor.apana.org.au>
Wed, 29 Nov 2017 06:33:31 +0000 (17:33 +1100)
The four 32-bit constants for the initial state of ChaCha20 were loaded
from a char array which is not guaranteed to have the needed alignment.

Fix it by just assigning the constants directly instead.

Signed-off-by: Eric Biggers <ebiggers@google.com>
Acked-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
crypto/chacha20_generic.c

index 4a45fa4..ec84e78 100644 (file)
@@ -41,12 +41,10 @@ static void chacha20_docrypt(u32 *state, u8 *dst, const u8 *src,
 
 void crypto_chacha20_init(u32 *state, struct chacha20_ctx *ctx, u8 *iv)
 {
-       static const char constant[16] = "expand 32-byte k";
-
-       state[0]  = le32_to_cpuvp(constant +  0);
-       state[1]  = le32_to_cpuvp(constant +  4);
-       state[2]  = le32_to_cpuvp(constant +  8);
-       state[3]  = le32_to_cpuvp(constant + 12);
+       state[0]  = 0x61707865; /* "expa" */
+       state[1]  = 0x3320646e; /* "nd 3" */
+       state[2]  = 0x79622d32; /* "2-by" */
+       state[3]  = 0x6b206574; /* "te k" */
        state[4]  = ctx->key[0];
        state[5]  = ctx->key[1];
        state[6]  = ctx->key[2];