From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 93894470E5 for ; Thu, 25 Dec 2025 10:20:14 +0100 (CET) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 7C0F2402C8; Thu, 25 Dec 2025 10:20:14 +0100 (CET) Received: from BN1PR04CU002.outbound.protection.outlook.com (mail-eastus2azon11010024.outbound.protection.outlook.com [52.101.56.24]) by mails.dpdk.org (Postfix) with ESMTP id 11FF34025E for ; Thu, 25 Dec 2025 10:20:12 +0100 (CET) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=RoObi8hbZcRW9DD1gb9t2S2P6druaYGyOJC7/GivttdYSCJGwngKWAOtAlZX18J2ddNHewF2cGEDlFYPcii+OWeJZzD5Ei0bitus2P6+Kry/yirirb+vhq38tLtMKEDH65K0hi/ubWtC8aUWd5JACU0uMUq7vdLyr0FHziPyRiLkNUI7U5zd52qnUYUmMwqNLSvQ7dLXyQy55xpmzTXSd2D+IbchUm242NmDTcUef9w9g+jC7uJm+VphLqQs/jXTuMtPFS7+tK+6EOnNOWbZU4FgMgTv5DLPU3B+OcxOiflVVHoNAjvUbtZ6zl1HdnIPAVbhOoWf/+FN24Brf1wlDg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=htAlIabRAGieTx7GKkotG7lCMgKDm6nEkIAXN1KHgO4=; b=HGW8Gqj/Hohci9axOuFhvyTNMa/HQ6RGkzUcL/Wu4o7EKZpsntL+qMbuM+tDURrVm8GeYHwkqIhxCx4HOZ4uqWpokIhIgoLBn4vZvpBIpjyM2708epujbASx5/qjodCfzNUVPhn7lQqlKuv7OmY6vqCILZHuiRGFiBHGv+WweFBO1O/bOeFwHO7VUnphplRyVCtnPVarpZNI7s0yT3ZGJqyIuBdyHXN9kTkUWoCadpjgaX/a2gaVF3TDGwtBmbnvcC3ODrEP7vFoPp0k34X0HuRjKcBRsrnL+ToacEfeg97wsZ0ESHnVDXm4Wjx5jIiqyZQ9h0X1aOpNSuMyASjt1g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.161) smtp.rcpttodomain=marvell.com smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=htAlIabRAGieTx7GKkotG7lCMgKDm6nEkIAXN1KHgO4=; b=r6OkliEaP/9b7NaoOE/4qKOW0DJQvtmLBbZdP1w8MZjUmRfGC4Ei4zgsg8OaXW1M5WB57Fk74knlgFzi3yNmaVAtN3PJNJkAwo3QYtXDAMO7ud09XArtV5NSzb38Y0D4laG4w5VWtnzl4EsWd7tST7vZCVfi9fFnYDUFKlvhpKdp0j6XaJqD8xSfRqtlfhEXi1eH0Zyj7yAa7pVBq9/EPYPnsISZYANoa8PagB2QJrtiWGkDwBwdLX3/OI+dw6RPjNVgVa9XTGYDNhGwayT0zANTiV1YSQHC5/vZ3b+AjXY+OyIqoj2nVBUC61FbX2tDCu2NTHvhgG4gd9LzrAprYQ== Received: from SJ2PR07CA0011.namprd07.prod.outlook.com (2603:10b6:a03:505::20) by DS4PR12MB9705.namprd12.prod.outlook.com (2603:10b6:8:277::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9434.11; Thu, 25 Dec 2025 09:20:08 +0000 Received: from MWH0EPF000989EC.namprd02.prod.outlook.com (2603:10b6:a03:505:cafe::74) by SJ2PR07CA0011.outlook.office365.com (2603:10b6:a03:505::20) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.9456.12 via Frontend Transport; Thu, 25 Dec 2025 09:20:05 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.161) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.161 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.161; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.161) by MWH0EPF000989EC.mail.protection.outlook.com (10.167.241.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9456.9 via Frontend Transport; Thu, 25 Dec 2025 09:20:07 +0000 Received: from rnnvmail202.nvidia.com (10.129.68.7) by mail.nvidia.com (10.129.200.67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Thu, 25 Dec 2025 01:19:54 -0800 Received: from rnnvmail201.nvidia.com (10.129.68.8) by rnnvmail202.nvidia.com (10.129.68.7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Thu, 25 Dec 2025 01:19:53 -0800 Received: from nvidia.com (10.127.8.12) by mail.nvidia.com (10.129.68.8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20 via Frontend Transport; Thu, 25 Dec 2025 01:19:52 -0800 From: Shani Peretz To: Sucharitha Sarananaga CC: dpdk stable Subject: patch 'crypto/cnxk: refactor RSA verification' has been queued to stable release 23.11.6 Date: Thu, 25 Dec 2025 11:17:25 +0200 Message-ID: <20251225091938.345892-4-shperetz@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20251225091938.345892-1-shperetz@nvidia.com> References: <20251221145746.763179-93-shperetz@nvidia.com> <20251225091938.345892-1-shperetz@nvidia.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MWH0EPF000989EC:EE_|DS4PR12MB9705:EE_ X-MS-Office365-Filtering-Correlation-Id: e043c9e1-7be3-453d-150f-08de4396cbd3 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|36860700013|376014|1800799024|82310400026|13003099007|7053199007; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?10N+5kd3uwoKoivLHktXGH+Qn7ahkS19+uS6KUCw/VrYvkGFy6wbttVXOa5i?= =?us-ascii?Q?6OCO88dEGCyyzBqnJu5xhMxYl5cvlvOuFh3shr33U024zWAqO+2VAdJZrSa/?= =?us-ascii?Q?lBCkF7GS6nRJR6+tEEgV3Kis83L88qLX+ISH5Z2Ye1wYEZpWPl/jPk43VvXq?= =?us-ascii?Q?QHjebihW+0/h28i6anMGKqucp9AjcAIsmUs5iYCDBN1uEW5nFSrwwIi5pOTh?= =?us-ascii?Q?Wwu7YdfheX7kqEkVlvhzi/rStFnZCsYuaTUlih4EuhfU6ai7Y7H6fEW2H4rO?= =?us-ascii?Q?F9TFYbvrnTJNE7x6YirTq/9+VYyDedkUAci3fLHqQoyBcyDW3u5UjQmoXjHb?= =?us-ascii?Q?WXjL1Ake6tyOSunXN5kwHY0C4VDAWYTfgk6pfMJnSojZ0AJcl4ZW2wT/0qko?= =?us-ascii?Q?wuMLx7+bcvuN9dyxupCB+KEdUFov/8hYBsqDDgnEjUopZzgXnrZxByZwYrAJ?= =?us-ascii?Q?tOi40Oz3DETxFUn2JFDq1gIZzkt4H8zTsOVAjlkq78qeEhbZ+BM6dvkQjwc+?= =?us-ascii?Q?P9XAZdADQjcZcC8MIq+HCsBw1dBvI8MtNEsRvDqvwfaQdSWAPmn5YKyj78l6?= =?us-ascii?Q?xWbx8xy7l8IPqmS3uUrWChbPyPFCmFyzmKhZaU8u7c1NyKQL+CKLYlKqM8Q8?= =?us-ascii?Q?DOOLDcEZh76cH2XwCWWCdP2nkRUR7EY7gjEn8OGGUa2V2Z/R+jp2fgTa5Wr0?= =?us-ascii?Q?D6lJxHD7Zc4gzuLxAA5IEXGskWiMyMfFM782VP6G0UlYph4kVziqNS1ylikS?= =?us-ascii?Q?UZ+8EKfUmxd8Cm/hhx941B6846HckMMGUHYiHJ90ismI3iKI7O20RqZqSs0w?= =?us-ascii?Q?qil8oaKhH9HdIQF78uKxCqrjLD62hPykjB1i1hPPCjFa5UChrRtonkX9wZbi?= =?us-ascii?Q?sBZCqCE8AMhsnNRMhK/vxj788cHrQXSoEstEDM3bkKp9bC/KYX1ijHfotZY0?= =?us-ascii?Q?L8Ob1zgEm7zMDCX46tk690uywZsK5zKX5YeXzEa0hoyjVZl3ZdcvlvPGGj93?= =?us-ascii?Q?iTqa8Lz3gDZPRX7q1Cp9K5iz8ynGITViV9RsHiLlpiWqwcK4Ba+qqh7Mv0s7?= =?us-ascii?Q?cOrpUUoDyw5lIX28rPl/jUsIxyiGQB+HGzCVi0ypt0oN/8IL/PgMclpchcIp?= =?us-ascii?Q?cntIYvDJ/EhnstmWFmCwk7QweWOHlppwMghMwvXMQhVY6+u+tnKM2E73rJ24?= =?us-ascii?Q?C4E+SRQZpQbdKu0mTjYIg6KTnmJovRnD/Duzyzq3ZwZL3b5DOI2XhvOy+7mY?= =?us-ascii?Q?qVOMo9A1vtB1WX+/3uFFmerljHKbW/O9FdteOE/yHVyq2eooJ2VKawc7/iHL?= =?us-ascii?Q?rJaGoXUm9U1DbJ62UZaXKcZDGehkCkCZUb/5R/TeLTdMZr/bt9VTDG79HqJH?= =?us-ascii?Q?pB7gE+M/AN1NGHvGoIy9c5rXPJ8feVKmGrawmvFfhV21rg3v4Us7PVmJRb+Y?= =?us-ascii?Q?liAPOkXoCD+LhcqAmvdUeFAh4qF5X1FJginS8B3/1IIIC11buCAjDrp3BCf6?= =?us-ascii?Q?0eKu67LansDsTOsRG4MFEdRh9hakVbMbTiNTn9zlK4oYXtTbaBJIkUnh5CAk?= =?us-ascii?Q?SOHPJOCegLk77u2Od+57HInd6lQ8XGyvagE6A86x?= X-Forefront-Antispam-Report: CIP:216.228.117.161; CTRY:US; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:mail.nvidia.com; PTR:dc6edge2.nvidia.com; CAT:NONE; SFS:(13230040)(36860700013)(376014)(1800799024)(82310400026)(13003099007)(7053199007); DIR:OUT; SFP:1101; X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Dec 2025 09:20:07.5915 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: e043c9e1-7be3-453d-150f-08de4396cbd3 X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a; Ip=[216.228.117.161]; Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: MWH0EPF000989EC.namprd02.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS4PR12MB9705 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Hi, FYI, your patch has been queued to stable release 23.11.6 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 12/30/25. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/shanipr/dpdk-stable This queued commit can be viewed at: https://github.com/shanipr/dpdk-stable/commit/09f4829c2fa9f6cb3a30ce52184da89894e0fd2d Thanks. Shani --- >From 09f4829c2fa9f6cb3a30ce52184da89894e0fd2d Mon Sep 17 00:00:00 2001 From: Sucharitha Sarananaga Date: Mon, 29 Sep 2025 15:13:49 +0530 Subject: [PATCH] crypto/cnxk: refactor RSA verification [ upstream commit dfd038b97ec3d173ded0f985df39301b7c7662f2 ] This patch avoid copying the decrypted message into the signature buffer, which is actually an input to the verify operation. This prevents overwriting the input buffer unnecessarily. Fixes: 6661bedf1605 ("crypto/cnxk: add asymmetric datapath") Signed-off-by: Sucharitha Sarananaga --- drivers/crypto/cnxk/cnxk_ae.h | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/drivers/crypto/cnxk/cnxk_ae.h b/drivers/crypto/cnxk/cnxk_ae.h index ef9cb5eb91..527b5b9730 100644 --- a/drivers/crypto/cnxk/cnxk_ae.h +++ b/drivers/crypto/cnxk/cnxk_ae.h @@ -1173,20 +1173,17 @@ cnxk_ae_dequeue_rsa_op(struct rte_crypto_op *cop, uint8_t *rptr, case RTE_CRYPTO_ASYM_OP_VERIFY: if (rsa->padding.type == RTE_CRYPTO_RSA_PADDING_NONE) { rsa->sign.length = rsa_ctx->n.length; - memcpy(rsa->sign.data, rptr, rsa->sign.length); + if (memcmp(rptr, rsa->message.data, rsa->message.length)) + cop->status = RTE_CRYPTO_OP_STATUS_ERROR; } else { /* Get length of signed output */ - rsa->sign.length = - rte_cpu_to_be_16(*((uint16_t *)rptr)); + rsa->sign.length = rte_cpu_to_be_16(*((uint16_t *)rptr)); /* * Offset output data pointer by length field - * (2 bytes) and copy signed data. + * (2 bytes) and compare signed data. */ - memcpy(rsa->sign.data, rptr + 2, rsa->sign.length); - } - if (memcmp(rsa->sign.data, rsa->message.data, - rsa->message.length)) { - cop->status = RTE_CRYPTO_OP_STATUS_ERROR; + if (memcmp(rptr + 2, rsa->message.data, rsa->message.length)) + cop->status = RTE_CRYPTO_OP_STATUS_ERROR; } break; default: -- 2.43.0 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2025-12-25 11:16:36.581826409 +0200 +++ 0004-crypto-cnxk-refactor-RSA-verification.patch 2025-12-25 11:16:35.267823000 +0200 @@ -1 +1 @@ -From dfd038b97ec3d173ded0f985df39301b7c7662f2 Mon Sep 17 00:00:00 2001 +From 09f4829c2fa9f6cb3a30ce52184da89894e0fd2d Mon Sep 17 00:00:00 2001 @@ -5,0 +6,2 @@ +[ upstream commit dfd038b97ec3d173ded0f985df39301b7c7662f2 ] + @@ -12 +13,0 @@ -Cc: stable@dpdk.org @@ -20 +21 @@ -index 8508ab8736..912a2a9496 100644 +index ef9cb5eb91..527b5b9730 100644 @@ -23 +24 @@ -@@ -1592,20 +1592,17 @@ cnxk_ae_dequeue_rsa_op(struct rte_crypto_op *cop, uint8_t *rptr, +@@ -1173,20 +1173,17 @@ cnxk_ae_dequeue_rsa_op(struct rte_crypto_op *cop, uint8_t *rptr, @@ -25 +26 @@ - if (rsa_ctx->padding.type == RTE_CRYPTO_RSA_PADDING_NONE) { + if (rsa->padding.type == RTE_CRYPTO_RSA_PADDING_NONE) {