From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 08C67A034F for ; Wed, 10 Nov 2021 07:34:31 +0100 (CET) Received: from [217.70.189.124] (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id F08614068B; Wed, 10 Nov 2021 07:34:30 +0100 (CET) Received: from NAM12-MW2-obe.outbound.protection.outlook.com (mail-mw2nam12on2059.outbound.protection.outlook.com [40.107.244.59]) by mails.dpdk.org (Postfix) with ESMTP id EB8FF40142 for ; Wed, 10 Nov 2021 07:34:28 +0100 (CET) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kYlJdJvoo4MEUuwK5DbVUZmAQ5wb7Z63VgP36daPP8Bww1JqfR3vJi2dV31VxIxotuNEmn3W/sM0JMe3FeIOCpJ6YFm5+TUy4SoFuak54cfekKTpjwKlBrsedAC+LlQT/w2BmA3h4WOFhYYYEkKJlyRujIPv+Q1ITiGznsQ+5pG3Pv5B/MEQ+OqOPsLPKuxK+caWEoXmimsS2TYt5MvwbtVbbTXMqmAn/Y+2JrieiCbvxwBhkniqhCm6q5lohz6UltTJuGxPN6g5wbqPCVMywhleYja5GQrzSPfwFCK+OY040P95MetzBLlq8SYynOxVsX1loCok431/I6vKTrolKg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vuHLTLRZgSr7iz3C/wWvNw6r2q2CjPp+RRRCZUYislw=; b=SD1FfnFNEy3uINYXtaclD7WhiNnkbCNHGazuaYiQftRvlOc8PvItgMOLaVLrVKPtnNtzChqyCya7rMzIUOLcgSP4/jVkRoZ9e7UTbRu6/SrpNfXgH7jNNv1w54o4bW3yYEBcMT+hFkrlfpC1O+KQ65dWY61XBrtdBTomFgnRO56nir4f3Dkxwg6PbZAOl+QZyshf7NHHTVC1PpVgGUntxShgAXU2GUtEhKhDgvSwnboYHo+Lf4eIVpVN59OsHa2p7yJVkrBmgzr15tMnnNAhunSpUwXBzVFr1U8CsUQ9n/oK3JQEi/zNRrAWm+WOxtmEMjFKoawGiP7+RXTl/HcZiA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.112.34) smtp.rcpttodomain=intel.com smtp.mailfrom=nvidia.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vuHLTLRZgSr7iz3C/wWvNw6r2q2CjPp+RRRCZUYislw=; b=VUM5aPoPkgRJVZpwoDscNLGLVjwZR1x5R4zdlVQI76/Q2V3/hYnaDzp2JkfmpBKNIIcqKfczh4f2HwHLjjfQpHzSdY/vs1dQOxqqxl3b1kckYfo3NWDvrmAeaRimH2Q1FdB97ZhHRP2/+7x/i023ERyZzovgB64YMWWyw3aH0XsrXwycSgy1chunCxU4J1h1RChmX99/OPdRGHoiOPM5MEzAiwJuKQ6EG7C1FQzYWa4PjuUnQS8e8jzHOwKNNr5LP5PTP6Nam9kRKZ+b0mpwXkAb8KG9T99Vyrnctc1RY/K+Ko3SvPgCZOc11395tX5D5e2oeKrffO5qDGXbpP9WEA== Received: from DM6PR02CA0164.namprd02.prod.outlook.com (2603:10b6:5:332::31) by BYAPR12MB4693.namprd12.prod.outlook.com (2603:10b6:a03:98::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4669.13; Wed, 10 Nov 2021 06:34:24 +0000 Received: from DM6NAM11FT022.eop-nam11.prod.protection.outlook.com (2603:10b6:5:332:cafe::be) by DM6PR02CA0164.outlook.office365.com (2603:10b6:5:332::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4669.11 via Frontend Transport; Wed, 10 Nov 2021 06:34:24 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.112.34) smtp.mailfrom=nvidia.com; intel.com; dkim=none (message not signed) header.d=none;intel.com; dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.112.34 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.112.34; helo=mail.nvidia.com; Received: from mail.nvidia.com (216.228.112.34) by DM6NAM11FT022.mail.protection.outlook.com (10.13.172.210) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.4690.15 via Frontend Transport; Wed, 10 Nov 2021 06:34:24 +0000 Received: from nvidia.com (172.20.187.6) by HQMAIL107.nvidia.com (172.20.187.13) with Microsoft SMTP Server (TLS) id 15.0.1497.18; Wed, 10 Nov 2021 06:34:20 +0000 From: Xueming Li To: Ciara Power CC: Luca Boccassi , Fan Zhang , dpdk stable Date: Wed, 10 Nov 2021 14:28:22 +0800 Message-ID: <20211110063216.2744012-19-xuemingl@nvidia.com> X-Mailer: git-send-email 2.33.0 In-Reply-To: <20211110063216.2744012-1-xuemingl@nvidia.com> References: <20211110063216.2744012-1-xuemingl@nvidia.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-Originating-IP: [172.20.187.6] X-ClientProxiedBy: HQMAIL101.nvidia.com (172.20.187.10) To HQMAIL107.nvidia.com (172.20.187.13) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 1eb9ddd8-6af9-4980-fb8a-08d9a41422ea X-MS-TrafficTypeDiagnostic: BYAPR12MB4693: X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:9508; X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: 60VU58xCPV7Dqx1coF+0SNmLIYg6k2VxipuDbdxlKwjLr61e/jjEmHoBjZuqF+KgHWEaKdAcQ5c64SLDLFeBq5wOiWl1vF5NINM68H4Ss0WG7nbOGFZ4U4FN0Z0+xaSWnd8Zud5VoPV53m7yiwWeX7+o4c+v/oYRCuwF3foBlmkQkQqN7tw6DYh4+Q0GIFAXLZqEhYDaVmX+8S4wgHirwpi9i2qgnd6QhmS3H6JzaTosZQbzvaM2x8rBzCvveZXO3X1Hzt8ZYCy61UiWvrr/YlGXuZQ1owCdRNh0cb2+DmCD0kak1VBt+VmeZw55PrgfpdLLRlm8lQBtDz3nsMI0oycZxOb6HbSGkRN9/SobvMsrpA7yooy8sWMIAdc6BaMfJrA+TMIoyNk46QN6nsA5d8SUB7oVa20RM7UjvM1dchYAFs+6RYFjT2S/iVbYKgd8sxnLTkMN7OcMZo4NquT6HoL3+/ut6/DUJF3otqXbchpQtwIx+oN/2Zb5Q5mHJ0fR1LRIpIxpoj8HTzp1/n5njaE1z9F8cBOUy7GCE6qcyGuB07IJLsbnnuKYwMBb21TLRwiptljuCRq+wrWfXyvM/lwW5bQSIvXi+8zmAovUR7sFwGW/0Q2iwN5gSgX7PbJq34MP42EY33eX/jIiSL+RhFOE1flNZHCoyxuStgW5hjCTCUG44CWc6fS9L2D1hRHoyYUooO/0oijhe/SLIYZYXW2pX7EPVR0JBbkVc35k5c4Ckyx3n+vQIMyn6rha7vYSf1iDKWpF9UPwcOcPsPMOQ43giIuVRccTnncPwzXDNN9DXqZawff8Yw8hg5SVj09nVRrh+OEnQxIwLwIV/m5pQQ== X-Forefront-Antispam-Report: CIP:216.228.112.34; CTRY:US; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:mail.nvidia.com; PTR:schybrid03.nvidia.com; CAT:NONE; SFS:(4636009)(46966006)(36840700001)(16526019)(26005)(8936002)(36860700001)(6286002)(36906005)(54906003)(47076005)(83380400001)(356005)(7636003)(55016002)(8676002)(186003)(6916009)(5660300002)(36756003)(316002)(4326008)(426003)(508600001)(86362001)(4001150100001)(2616005)(53546011)(70586007)(966005)(7696005)(82310400003)(2906002)(336012)(70206006)(1076003); DIR:OUT; SFP:1101; X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Nov 2021 06:34:24.0542 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 1eb9ddd8-6af9-4980-fb8a-08d9a41422ea X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a; Ip=[216.228.112.34]; Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: DM6NAM11FT022.eop-nam11.prod.protection.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR12MB4693 Subject: [dpdk-stable] patch 'crypto/openssl: fix CCM processing 0 length source' has been queued to stable release 20.11.4 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Sender: "stable" Hi, FYI, your patch has been queued to stable release 20.11.4 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 11/12/21. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/steevenlee/dpdk This queued commit can be viewed at: https://github.com/steevenlee/dpdk/commit/52ed92cfb6b9933746264d9bb696bfdbf4dc230c Thanks. Xueming Li --- >From 52ed92cfb6b9933746264d9bb696bfdbf4dc230c Mon Sep 17 00:00:00 2001 From: Ciara Power Date: Mon, 23 Aug 2021 12:47:14 +0000 Subject: [PATCH] crypto/openssl: fix CCM processing 0 length source Cc: Xueming Li [ upstream commit 589f5e033d0d8489e0d4bf2f54332febf483f764 ] When given a source length 0 for CCM, the encryption and decryption functions did not call the EVP_ENCRYPTUPDATE/EVP_DECRYPTUPDATE functions with a src and dst, causing some FIPS validation failures for testcases with PLen=0: process_openssl_auth_encryption_ccm() line 1131: Process openssl auth encryption ccm failed Fixes: 1a4998dc4d94 ("crypto/openssl: support AES-CCM") Signed-off-by: Ciara Power Acked-by: Fan Zhang --- drivers/crypto/openssl/rte_openssl_pmd.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/crypto/openssl/rte_openssl_pmd.c b/drivers/crypto/openssl/rte_openssl_pmd.c index 7d3959f550..ca4265d2be 100644 --- a/drivers/crypto/openssl/rte_openssl_pmd.c +++ b/drivers/crypto/openssl/rte_openssl_pmd.c @@ -1114,7 +1114,7 @@ process_openssl_auth_encryption_ccm(struct rte_mbuf *mbuf_src, int offset, if (EVP_EncryptUpdate(ctx, NULL, &len, aad + 18, aadlen) <= 0) goto process_auth_encryption_ccm_err; - if (srclen > 0) + if (srclen >= 0) if (process_openssl_encryption_update(mbuf_src, offset, &dst, srclen, ctx, 0)) goto process_auth_encryption_ccm_err; @@ -1197,7 +1197,7 @@ process_openssl_auth_decryption_ccm(struct rte_mbuf *mbuf_src, int offset, if (EVP_DecryptUpdate(ctx, NULL, &len, aad + 18, aadlen) <= 0) goto process_auth_decryption_ccm_err; - if (srclen > 0) + if (srclen >= 0) if (process_openssl_decryption_update(mbuf_src, offset, &dst, srclen, ctx, 0)) return -EFAULT; -- 2.33.0 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2021-11-10 14:17:02.928050624 +0800 +++ 0018-crypto-openssl-fix-CCM-processing-0-length-source.patch 2021-11-10 14:17:01.754080379 +0800 @@ -1 +1 @@ -From 589f5e033d0d8489e0d4bf2f54332febf483f764 Mon Sep 17 00:00:00 2001 +From 52ed92cfb6b9933746264d9bb696bfdbf4dc230c Mon Sep 17 00:00:00 2001 @@ -4,0 +5,3 @@ +Cc: Xueming Li + +[ upstream commit 589f5e033d0d8489e0d4bf2f54332febf483f764 ] @@ -15 +17,0 @@ -Cc: stable@dpdk.org @@ -24 +26 @@ -index 47004337d5..37b969b916 100644 +index 7d3959f550..ca4265d2be 100644