Commit 87e02063 authored by Nikita Zhandarovich's avatar Nikita Zhandarovich Committed by Herbert Xu

crypto: safexcel - Add error handling for dma_map_sg() calls

Macro dma_map_sg() may return 0 on error. This patch enables
checks in case of the macro failure and ensures unmapping of
previously mapped buffers with dma_unmap_sg().

Found by Linux Verification Center (linuxtesting.org) with static
analysis tool SVACE.

Fixes: 49186a7d ("crypto: inside_secure - Avoid dma map if size is zero")
Signed-off-by: default avatarNikita Zhandarovich <n.zhandarovich@fintech.ru>
Reviewed-by: default avatarAntoine Tenart <atenart@kernel.org>
Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
parent 429fec81
...@@ -742,9 +742,9 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring, ...@@ -742,9 +742,9 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring,
max(totlen_src, totlen_dst)); max(totlen_src, totlen_dst));
return -EINVAL; return -EINVAL;
} }
if (sreq->nr_src > 0) if (sreq->nr_src > 0 &&
dma_map_sg(priv->dev, src, sreq->nr_src, !dma_map_sg(priv->dev, src, sreq->nr_src, DMA_BIDIRECTIONAL))
DMA_BIDIRECTIONAL); return -EIO;
} else { } else {
if (unlikely(totlen_src && (sreq->nr_src <= 0))) { if (unlikely(totlen_src && (sreq->nr_src <= 0))) {
dev_err(priv->dev, "Source buffer not large enough (need %d bytes)!", dev_err(priv->dev, "Source buffer not large enough (need %d bytes)!",
...@@ -752,8 +752,9 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring, ...@@ -752,8 +752,9 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring,
return -EINVAL; return -EINVAL;
} }
if (sreq->nr_src > 0) if (sreq->nr_src > 0 &&
dma_map_sg(priv->dev, src, sreq->nr_src, DMA_TO_DEVICE); !dma_map_sg(priv->dev, src, sreq->nr_src, DMA_TO_DEVICE))
return -EIO;
if (unlikely(totlen_dst && (sreq->nr_dst <= 0))) { if (unlikely(totlen_dst && (sreq->nr_dst <= 0))) {
dev_err(priv->dev, "Dest buffer not large enough (need %d bytes)!", dev_err(priv->dev, "Dest buffer not large enough (need %d bytes)!",
...@@ -762,9 +763,11 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring, ...@@ -762,9 +763,11 @@ static int safexcel_send_req(struct crypto_async_request *base, int ring,
goto unmap; goto unmap;
} }
if (sreq->nr_dst > 0) if (sreq->nr_dst > 0 &&
dma_map_sg(priv->dev, dst, sreq->nr_dst, !dma_map_sg(priv->dev, dst, sreq->nr_dst, DMA_FROM_DEVICE)) {
DMA_FROM_DEVICE); ret = -EIO;
goto unmap;
}
} }
memcpy(ctx->base.ctxr->data, ctx->key, ctx->key_len); memcpy(ctx->base.ctxr->data, ctx->key, ctx->key_len);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment