Re: [PATCH net-next v11 12/15] quic: add crypto packet encryption and decryption
Xin Long <[email protected]> Thu, 26 Mar 2026 11:10:25 -0400
| Newsgroups | dev.linux.lists.quic,dev.linux.lists.kernel-tls-handshake,org.kernel.vger.linux-cifs,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CADvbK_d+oVgMNWQ3fT_Rz9WGkU6i6m+Z=3J34_-QiCjEABoCpg@mail.gmail.com> |
On Tue, Mar 24, 2026 at 11:49=E2=80=AFPM Xin Long <[email protected]> wr= ote: > > This patch adds core support for packet-level encryption and decryption > using AEAD, including both payload protection and QUIC header protection. > It introduces helpers to encrypt packets before transmission and to > remove header protection and decrypt payloads upon reception, in line > with QUIC's cryptographic requirements. > > - quic_crypto_encrypt(): Perform header protection and payload > encryption (TX). > > - quic_crypto_decrypt(): Perform header protection removal and > payload decryption (RX). > > The patch also includes support for Retry token handling. It provides > helpers to compute the Retry integrity tag, generate tokens for address > validation, and verify tokens received from clients during the > handshake phase. > > - quic_crypto_get_retry_tag(): Compute tag for Retry packets. > > - quic_crypto_generate_token(): Generate retry token. > > - quic_crypto_verify_token(): Verify retry token. > > These additions establish the cryptographic primitives necessary for > secure QUIC packet exchange and address validation. > > Signed-off-by: Xin Long <[email protected]> > --- > v3: > - quic_crypto_decrypt(): return -EKEYREVOKED to defer key updates to > the workqueue when the packet is not marked backlog, since > quic_crypto_key_update()/crypto_aead_setkey() must run in process > context. > - Only perform header decryption if !cb->number_len to avoid double > decryption when a key-update packet (with flipped key_phase) > re-enters quic_crypto_decrypt() from the workqueue. > v4: > - skb_dst_force() is already called in in quic_udp_rcv() on recv path, > so remove its call from quic_crypto_payload_decrypt(), which may be > called without RCU protection. > - Remove the incorrect (void *) cast to quic_crypto_done. > v5: > - Use skb_cb->crypto_ctx for async crypto context freeing, which is > safer than using skb_shinfo(skb)->destructor_arg. > - skb_cb->number_max is removed and number is reused as the largest > previously seen and update quic_crypto_get_header() accordingly. > - Change timestamp variables from u32 to u64 and use quic_ktime_get_us(= ) > for current timestamps, as jiffies_to_usecs() is not accurate enough. > v6: > - Rename quic_crypto_get_header() to quic_crypto_get_number(), move > key_phase parsing out of it, check cb->length when parsing packet > number, and update all callers. > - Use hdr->pnl + 1 instead of (*p & QUIC_PN_LEN_BITS_MASK) + 1 to get > packet number length, and remove the unnecessary the len variable > and QUIC_PN_LEN_BITS_MASK macro from quic_crypto_header_decrypt(). > v8: > - Move skb_cow_data() from quic_crypto_payload_decrypt() to > quic_crypto_header_decrypt(), as header decryption also writes to > the skb and is invoked earlier than payload decryption on RX path. > v10: > - Fix double period at end of the comment for quic_crypto_encrypt(). > v11: > - Note for AI review: call quic_crypto_aead_mem_alloc() after > skb_cow_data() as it uses the return value for nsg. If the allocation > fails, skb is dropped, so no rollback of prior skb modifications is > needed. The AI report on https://netdev-ai.bots.linux.dev/ai-review.html?id=3D1624d906-c0b6-4e12-a= 63f-5cbfc51b660e#patch-11 is already explained by this "Note for AI review", not an issue.