Re: [PATCH v11 4/5] s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
Holger Dengler <[email protected]> Mon, 3 Aug 2026 17:03:47 +0200
| Newsgroups | org.kernel.vger.linux-s390 |
|---|---|
| Message-ID | <[email protected]> |
On 8/3/26 10:33, Harald Freudenberger wrote:
> The zcrypt_msgtype6_send_ep11_cprb() function uses fragile struct
> overlays to access and modify the domain field in the EP11 CPRB
> payload, creating maintainability and security concerns:
> 1. Struct overlay approach (pld_hdr) assumes fixed payload structure
> and doesn't validate the actual ASN.1 encoding.
> 2. Complex length format detection logic is error-prone and doesn't
> properly validate bounds at each parsing step.
> 3. Direct struct member access bypasses proper ASN.1 validation.
>
> Fix by replacing struct overlays with explicit ASN.1 parsing that
> validates each field (payload tag/length, function tag/length/value,
> optional domain tag/length/value) with proper bounds checking at every
> step. Add asn1_int_encode() helper function to safely write integer
> values with correct endianness conversion. This makes the code
> consistent with the validation pattern introduced with the rework of
> the xcrb_msg_to_type6_ep11cprb_msgx() function.
>
> Fixes: e2c6d91eb8b1 ("s390/zcrypt: Rework domain processing within zcrypt device driver")
> Signed-off-by: Harald Freudenberger <[email protected]>
> Cc: [email protected] # 7.1+
Reviewed-by: Holger Dengler <[email protected]>
--
Mit freundlichen Grüßen / Kind regards
Holger Dengler