Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp2709299ybi; Mon, 1 Jul 2019 17:25:50 -0700 (PDT) X-Google-Smtp-Source: APXvYqx2mHc0UDpe36x8l3ZCSp8lzfr7JeaQppIJht46ieXbG78yyu76rTxM1zQWrW3BaEKFYHNO X-Received: by 2002:a17:90a:fa12:: with SMTP id cm18mr2193574pjb.137.1562027150464; Mon, 01 Jul 2019 17:25:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1562027150; cv=none; d=google.com; s=arc-20160816; b=GkO9r7+YE7i4B+Gigu3kbPgb5HE1DzV6XwtHxkGP3fb73Nq6s7ILOBS6qgI0D8bxKl zv+RhW1xIpyT4eGrcSzgimleeji27XGEbBZyUXj7xaCnISByFy2F2e/jT6tGwqgnJFyo vpKbWspCBdHDcta8dw620Hqm5RNq+zjjVMADmZWJzUFUTvjW7WS4nAsDlOrMoiLYxnwy yqUv9FnNZR8SxbY+zqclHwHsW84b8yyCuP1VaEbHG0Qk0gMtGjXiokkWwVqDlMbMHCf7 qKBfoCMMEfGF6bo/rFSGwJB+CJUPFbV2zFIy1gbFjAGidVA0re5KYsLlac47ikVBdr55 l2hg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=6VApHB1v6HB7+qCOqnKx3fVXJ6vs5CZq9EmtfUZTcrw=; b=azNjI0v9nT5pvROWygAMtNKWzIkm2eM+uoI5nR/JgOKzfUWh5qKaJAvM6hZ0ATkqvM kX+4kM+4GYdkUUwaJpdQVw+QjsrxohHNbVCPhTmbKiBCQMJ/rL2A6wGAk3Hl/dZUuhny MMSw68pYLATQUeiuxtTlEpt6qcm/pQSWkhAoHCcx8g06dLDoTZTzkLzL9xamFU6qqh3j KRp1bDd5ARdQGYnvVeMO8AszqYNeK1Q31duKrIJhHlbMtziXCvCkI9oaH+gohEZ2pOq9 TZFevlMTMUFODBRrL0aarEB76zMaKLvaI9zZZhcLPNzSWKTxTnVuNpLMjgnBgRjTmErU 7TsA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=K17hf1xl; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id y16si12205179pfe.129.2019.07.01.17.25.28; Mon, 01 Jul 2019 17:25:50 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=K17hf1xl; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727035AbfGBAZZ (ORCPT + 99 others); Mon, 1 Jul 2019 20:25:25 -0400 Received: from mail.kernel.org ([198.145.29.99]:40162 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727023AbfGBAZY (ORCPT ); Mon, 1 Jul 2019 20:25:24 -0400 Received: from sol.localdomain (c-24-5-143-220.hsd1.ca.comcast.net [24.5.143.220]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 9319C21721; Tue, 2 Jul 2019 00:25:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1562027123; bh=MPIDSjZSqrqTeWvWT//E/0wZy5fEnuIgGI95YyoSxss=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=K17hf1xlfaVcjMn/oGAGN5LYYVhtG4iXNAAmaxiEg6SyeDPInPxpVPw9wjAXFJ5Yg T+yiH8itPf3deW5gsoP+7cb8s7Psg8LUbHUvGwIGZ6WFZTbzcNOAvJrUISTps6zu/7 S2f7kL+yDqHTPQbr/5Lua9vshmIaF/SqxhPY5dYg= Date: Mon, 1 Jul 2019 17:25:22 -0700 From: Eric Biggers To: Cfir Cohen Cc: Tom Lendacky , Gary Hook , Herbert Xu , David Rientjes , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org Subject: Re: [PATCH] crypto: ccp/gcm - use const time tag comparison. Message-ID: <20190702002522.GA693@sol.localdomain> References: <20190702000132.88836-1-cfir@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20190702000132.88836-1-cfir@google.com> User-Agent: Mutt/1.12.1 (2019-06-15) Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org On Mon, Jul 01, 2019 at 05:01:32PM -0700, Cfir Cohen wrote: > Avoid leaking GCM tag through timing side channel. > > Signed-off-by: Cfir Cohen > --- > drivers/crypto/ccp/ccp-ops.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/drivers/crypto/ccp/ccp-ops.c b/drivers/crypto/ccp/ccp-ops.c > index db8de89d990f..633670220f6c 100644 > --- a/drivers/crypto/ccp/ccp-ops.c > +++ b/drivers/crypto/ccp/ccp-ops.c > @@ -840,7 +840,8 @@ static int ccp_run_aes_gcm_cmd(struct ccp_cmd_queue *cmd_q, > if (ret) > goto e_tag; > > - ret = memcmp(tag.address, final_wa.address, AES_BLOCK_SIZE); > + ret = crypto_memneq(tag.address, final_wa.address, > + AES_BLOCK_SIZE) ? -EBADMSG : 0; > ccp_dm_free(&tag); > } > > -- > 2.22.0.410.gd8fdbe21b5-goog > Looks like this needs: Fixes: 36cf515b9bbe ("crypto: ccp - Enable support for AES GCM on v5 CCPs") Cc: # v4.12+ - Eric