Re: [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN

Lukas Wunner <[email protected]> Tue, 28 Jul 2026 08:16:58 +0200
Newsgroups org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
[cc += Martin Kepplinger-Novaković]

On Tue, Jul 28, 2026 at 08:43:00AM +1000, Changwei Zou wrote:
> out_buf is used as a DMA buffer for the RSA verification operation.
> If out_buf is not aligned to ARCH_DMA_MINALIGN, cacheline sharing
> problems (data corruption) would occur on CPUs with DMA-incoherent caches,
> leading to -EKEYREJECTED.
> 
> Fix by aligning out_buf to ARCH_DMA_MINALIGN using PTR_ALIGN(), and
> allocating ARCH_DMA_MINALIGN extra bytes in the child_req allocation
> to accommodate the alignment padding.
> 
> The intermittent error 'Key was rejected by service' on i.MX8 with CAAM
> can be triggered when loading signed kernel modules.
> 
>     for i in $(seq 1 100); do
>         sudo modprobe xfs 2>&1 && echo "SUCCESS on attempt $i" \
>         && sudo rmmod xfs || echo "FAILED on attempt $i"
>     done
> 
> Fixes: 8552cb04e083 ("crypto: rsassa-pkcs1 - Copy source data for SG list")
> Signed-off-by: Changwei Zou <[email protected]>

@Martin Kepplinger-Novaković:  Could you test whether this fixes
the issue you reported in February?

If it does:

Reported-by: Martin Kepplinger-Novaković <[email protected]>
Closes: https://lore.kernel.org/r/[email protected]


@Changwei Zou:  Just to double-check, I assume this supersedes the
following patch, right?

https://lore.kernel.org/r/[email protected]


> +++ b/crypto/rsassa-pkcs1.c
> @@ -237,12 +239,13 @@ static int rsassa_pkcs1_verify(struct crypto_sig *tfm,
>  		return -EINVAL;
>  
>  	/* RFC 8017 sec 8.2.2 step 2 - RSA verification */
> -	child_req = kmalloc(sizeof(*child_req) + child_reqsize + ctx->key_size,
> -			    GFP_KERNEL);
> +	child_req = kmalloc(sizeof(*child_req) + child_reqsize +
> +				    ctx->key_size + ARCH_DMA_MINALIGN, GFP_KERNEL);
>  	if (!child_req)
>  		return -ENOMEM;
>  
> -	out_buf = (u8 *)(child_req + 1) + child_reqsize;
> +	out_buf  = PTR_ALIGN((u8 *)(child_req + 1) + child_reqsize,
> +				    ARCH_DMA_MINALIGN);
>  	memcpy(out_buf, src, slen);

We've got CRYPTO_DMA_ALIGN, CRYPTO_MINALIGN, CRYPTO_DMA_PADDING macros,
I think those would be more appropriate.

A few nits:
There's a duplicate blank in the "out_buf  =" assignment and
the line-wrapped function arguments aren't aligned to the opening brace.

> @@ -7,6 +7,8 @@
>   * Copyright (c) 2015 - 2024 Intel Corporation
>   */
>  
> +#include <linux/align.h>
> +#include <linux/cache.h>
>  #include <linux/module.h>
>  #include <linux/scatterlist.h>
>  #include <crypto/akcipher.h>

I think you won't be needing those #includes if you use the CRYPTO_*
alignment macros.

Thanks,

Lukas