a45f795c65
Starting with 4.9, kernel stacks may be vmalloced and therefore not guaranteed to be physically contiguous; the new CONFIG_VMAP_STACK option is enabled by default on x86. This makes it invalid to use on-stack buffers with the crypto scatterlist API, as sg_set_buf() expects a logical address and won't work with vmalloced addresses. There isn't a different (e.g. kvec-based) crypto API we could switch net/ceph/crypto.c to and the current scatterlist.h API isn't getting updated to accommodate this use case. Allocating a new header and padding for each operation is a non-starter, so do the en/decryption in-place on a single pre-assembled (header + data + padding) heap buffer. This is explicitly supported by the crypto API: "... the caller may provide the same scatter/gather list for the plaintext and cipher text. After the completion of the cipher operation, the plaintext data is replaced with the ciphertext data in case of an encryption and vice versa for a decryption." Signed-off-by: Ilya Dryomov <idryomov@gmail.com> Reviewed-by: Sage Weil <sage@redhat.com>
56 lines
1.6 KiB
C
56 lines
1.6 KiB
C
#ifndef _FS_CEPH_CRYPTO_H
|
|
#define _FS_CEPH_CRYPTO_H
|
|
|
|
#include <linux/ceph/types.h>
|
|
#include <linux/ceph/buffer.h>
|
|
|
|
/*
|
|
* cryptographic secret
|
|
*/
|
|
struct ceph_crypto_key {
|
|
int type;
|
|
struct ceph_timespec created;
|
|
int len;
|
|
void *key;
|
|
};
|
|
|
|
static inline void ceph_crypto_key_destroy(struct ceph_crypto_key *key)
|
|
{
|
|
if (key) {
|
|
kfree(key->key);
|
|
key->key = NULL;
|
|
}
|
|
}
|
|
|
|
int ceph_crypto_key_clone(struct ceph_crypto_key *dst,
|
|
const struct ceph_crypto_key *src);
|
|
int ceph_crypto_key_encode(struct ceph_crypto_key *key, void **p, void *end);
|
|
int ceph_crypto_key_decode(struct ceph_crypto_key *key, void **p, void *end);
|
|
int ceph_crypto_key_unarmor(struct ceph_crypto_key *key, const char *in);
|
|
|
|
/* crypto.c */
|
|
int ceph_decrypt(struct ceph_crypto_key *secret,
|
|
void *dst, size_t *dst_len,
|
|
const void *src, size_t src_len);
|
|
int ceph_encrypt(struct ceph_crypto_key *secret,
|
|
void *dst, size_t *dst_len,
|
|
const void *src, size_t src_len);
|
|
int ceph_decrypt2(struct ceph_crypto_key *secret,
|
|
void *dst1, size_t *dst1_len,
|
|
void *dst2, size_t *dst2_len,
|
|
const void *src, size_t src_len);
|
|
int ceph_encrypt2(struct ceph_crypto_key *secret,
|
|
void *dst, size_t *dst_len,
|
|
const void *src1, size_t src1_len,
|
|
const void *src2, size_t src2_len);
|
|
int ceph_crypt(const struct ceph_crypto_key *key, bool encrypt,
|
|
void *buf, int buf_len, int in_len, int *pout_len);
|
|
int ceph_crypto_init(void);
|
|
void ceph_crypto_shutdown(void);
|
|
|
|
/* armor.c */
|
|
int ceph_armor(char *dst, const char *src, const char *end);
|
|
int ceph_unarmor(char *dst, const char *src, const char *end);
|
|
|
|
#endif
|