Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp3508154ybi; Tue, 2 Jul 2019 08:55:01 -0700 (PDT) X-Google-Smtp-Source: APXvYqzLkChV0YMhtFffMT2Kd/jHUTBLlR8eOpPKNRySI3tWM0acG3RQjCv+HsWVHCEgomGNbzem X-Received: by 2002:a17:902:e287:: with SMTP id cf7mr35653447plb.32.1562082901719; Tue, 02 Jul 2019 08:55:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1562082901; cv=none; d=google.com; s=arc-20160816; b=TKurepZbuy4f80PHSKFw/JmX98na83Cv3WmXpdHscFxUfKJYzCNZ6Nzjm+re8cbBlf 7E2JJMiwuSJ7SgpJGXHgjuvsCt0nJ+a6lt1fIf94tpDF7aB7d7NaZifJO8vwBAOHaciM zBAm6ExcyE6X2hQHBgIz+LJvOeN1TcoCiwBmIXiLsfbz8dOnYCgcW1QsI5etcpmEuoJf 1kB6h3fQZU0chq4IRI+DDBXRyXDuzPjfi9yqZ6eXyWNHjCc4/2g64bsK+tmG5dn8irCX Iw/gOhOKolgyuYkMZ/tpS63rHCiUWXrP+JBrcJVQxRIB15mh1R+79unQDhhknPgydb8Z Wfmw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=PR1qo53XP9jAFJ0H3oFjFoo6ycsv/pZI1HwVoOhNLG0=; b=Inyjcaq4xAYOXutH5ynmrpWv+IPnoVor8pYmFEw7qnJWl7z9h39sMCdE27GMx3+apr gb2VgpCYXuXHEUeQGAAp5h45ZaJbcjKLtGRG7do3jGTuz1pBziX4etvWanpzLCB3bd8/ kZaEIg2DoN0j5k7NojLuNZuZDXcsK9zEJMv4oEn9BoR70Fk3XRp6VxYgr/8yFU+3/fns ErUSLhiJrs5IaSmrQmhFLQGWzQaRaR3niMVEsJ88bSAy8i75Gqo4SG/eWxrkEu7PvMkA kNCpV/dlI79HIjLws7R4q15ZvTpX+prTCCUItq0PuZcqhwtEqx8Q4VLIOE0XqfGSS2Gh 5mZA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=GQyZzmZt; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g145si13589507pfb.173.2019.07.02.08.54.47; Tue, 02 Jul 2019 08:55:01 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=GQyZzmZt; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727234AbfGBPxo (ORCPT + 99 others); Tue, 2 Jul 2019 11:53:44 -0400 Received: from mail.kernel.org ([198.145.29.99]:43304 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726308AbfGBPxk (ORCPT ); Tue, 2 Jul 2019 11:53:40 -0400 Received: from sol.localdomain (c-24-5-143-220.hsd1.ca.comcast.net [24.5.143.220]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 4C1E42082F; Tue, 2 Jul 2019 15:53:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1562082819; bh=H9aGzcRIAF8z4znsY082TkkEBo8mLXRjkdpeEtNj/VE=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=GQyZzmZt+hAFbRuIk9/PKT9lT2fPlVjgT/gP4qos5EpIEGEgKjNF1290flNniLpBB jUYizh3qkyO9Ksv+gk14yXnADZBxYDO2dnGlDns6fDwXFH6WWK+/laPgUv0xrCGcjn 66Torw3LgSM0m78lPcZdICvQm4e4NiR+B8veDoUw= Date: Tue, 2 Jul 2019 08:53:37 -0700 From: Eric Biggers To: Gary R Hook Cc: Cfir Cohen , "Lendacky, Thomas" , "Hook, Gary" , Herbert Xu , David Rientjes , "linux-kernel@vger.kernel.org" , "linux-crypto@vger.kernel.org" Subject: Re: [PATCH] crypto: ccp/gcm - use const time tag comparison. Message-ID: <20190702155337.GA895@sol.localdomain> References: <20190702000132.88836-1-cfir@google.com> <20190702002522.GA693@sol.localdomain> <1eea04e4-ac19-241d-695b-61be43640509@amd.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1eea04e4-ac19-241d-695b-61be43640509@amd.com> User-Agent: Mutt/1.12.1 (2019-06-15) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Jul 02, 2019 at 03:41:23PM +0000, Gary R Hook wrote: > On 7/1/19 7:25 PM, Eric Biggers wrote: > > On Mon, Jul 01, 2019 at 05:01:32PM -0700, Cfir Cohen wrote: > >> Avoid leaking GCM tag through timing side channel. > >> > >> Signed-off-by: Cfir Cohen > >> --- > >> drivers/crypto/ccp/ccp-ops.c | 3 ++- > >> 1 file changed, 2 insertions(+), 1 deletion(-) > >> > >> diff --git a/drivers/crypto/ccp/ccp-ops.c b/drivers/crypto/ccp/ccp-ops.c > >> index db8de89d990f..633670220f6c 100644 > >> --- a/drivers/crypto/ccp/ccp-ops.c > >> +++ b/drivers/crypto/ccp/ccp-ops.c > >> @@ -840,7 +840,8 @@ static int ccp_run_aes_gcm_cmd(struct ccp_cmd_queue *cmd_q, > >> if (ret) > >> goto e_tag; > >> > >> - ret = memcmp(tag.address, final_wa.address, AES_BLOCK_SIZE); > >> + ret = crypto_memneq(tag.address, final_wa.address, > >> + AES_BLOCK_SIZE) ? -EBADMSG : 0; > >> ccp_dm_free(&tag); > >> } > >> > >> -- > >> 2.22.0.410.gd8fdbe21b5-goog > >> > > > > Looks like this needs: > > > > Fixes: 36cf515b9bbe ("crypto: ccp - Enable support for AES GCM on v5 CCPs") > > Cc: # v4.12+ > > > Yes, it does. For clarity, does that mean you've taken care of this? > Herbert is the person who will apply this, so he'd need to do it. But it might be better just to resend. - Eric