From nobody Fri Oct 2 10:07:26 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8561232B136; Sun, 2 Aug 2026 23:02:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711724; cv=none; b=PLnrNSnrE0Z6AV9CCazMj4s4z1yU4D9+r1K8P/joMsTcutNoWhsKvGYTvFjYiKGXDg7QhkEFAuck9FYThWpwEEJMoU7tj/R78GoFmU20jXtXQeqeNm487EpYrpHUtqgvdxkDHfM1BIo3a6eAFgUS77A6Aon0SziNUupRg2g2lVU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711724; c=relaxed/simple; bh=yQmL8K4SKHc9RAQBEBdy9LfMi8IUQFrhNvJZCbsKJD4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=i2gOK2fHeu+q99/oWNHS2PMe2Kf8qNAuX2pDWld+qtrWBMNju1HJxoqccCNVs286e9IpOUPJSnhts+PbB+2eNZv+id87SdFrN+25wUk4bH/tOh8VRKenV5DhyuTl/d1EhKnWhK0bKLKV7KXYQjJg3J23Qs3e2c7BScyxSf+5Ud8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=juklaJQ4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="juklaJQ4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2978F1F00A3D; Sun, 2 Aug 2026 23:02:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785711723; bh=xsDoFBNG0XcHBCgcqwyp020b85v8chptiEHsK1IxUg0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=juklaJQ4JCsu0JdL16RBrcv0zQ14urPgOn8wEix/3SE+LKV8XF//xaqOmt6D2JKFM wElTRuuCOAWXJwgr/dMPz+N+8qijbkFD1rj1B1hzfSuBGlXsMcnu2HmKrBWz0R9dSF 27gB5CtWf9XabVR14JKDNgRD8fUje9deJWrg3EkvspMOFOZZ4LHEblFirz/TAFpftL GDiEqIhY8mhZY2TRjm4nEY558CO0/dmAXh/oXbNM6CLe/iRqBezwyaYLF+SGzXZMUD J1sPAzkbF2C95jesqeyqSKrMpk9Q5gTDlKO1Tsqy3kJLAtc8go99O82qTF6bBfuY5s Dcn2W6e7XII7A== From: Eric Biggers To: linux-crypto@vger.kernel.org, Herbert Xu Cc: Richard Weinberger , linux-kernel@vger.kernel.org, Eric Biggers Subject: [PATCH 1/3] crypto: af_alg - Make cbc(paes) privileged-only Date: Sun, 2 Aug 2026 16:00:53 -0700 Message-ID: <20260802230055.100746-2-ebiggers@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802230055.100746-1-ebiggers@kernel.org> References: <20260802230055.100746-1-ebiggers@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" So far the only reported use cases for cbc(paes) have involved processes running as root. Therefore, make af_alg_restrict=3D1 allow only privileged use of this algorithm for now. Fixes: 947d62c09436 ("Merge git://git.kernel.org/pub/scm/linux/kernel/git/h= erbert/crypto-2.6") Signed-off-by: Eric Biggers Reviewed-by: Richard Weinberger --- crypto/algif_skcipher.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c index 4c86b1993bde..68b48d805e92 100644 --- a/crypto/algif_skcipher.c +++ b/crypto/algif_skcipher.c @@ -41,7 +41,7 @@ static const struct af_alg_allowlist_entry skcipher_allow= list[] =3D { { "cbc(aes)", true }, /* iwd */ { "cbc(des)", true }, /* iwd */ { "cbc(des3_ede)", true }, /* iwd */ - { "cbc(paes)", false }, /* caam and others */ + { "cbc(paes)", true }, /* caam and others */ { "ctr(aes)", true }, /* iwd */ { "ecb(aes)", true }, /* iwd, bluez */ { "ecb(des)", true }, /* iwd */ --=20 2.55.0 From nobody Fri Oct 2 10:07:26 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AD63F33B6D6; Sun, 2 Aug 2026 23:02:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711724; cv=none; b=C3fMzWzPISyv3e5x/Ob2o4aQ8Xl+vF0sbkLOB/ngyWjDqyqf4mTBiLqR9p9BLoDG5BQSgEbKbCUyYSF1afBU+ILLgF/8OPfZo8a/N3UvIkVu9lRobDxwWxPbceJ4MYEsp8tS8i6pOsLCecjB/2A5/JF2LdLBy/nG4LWLdS/ory8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711724; c=relaxed/simple; bh=HpmGyOC5i+V9OsGBPyzzkUSXu/sFkWbNfcFFPKqkzAQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=droOQSrWQ90G87P+NIfc8CietrnltNJroGBL+rca0o3+TkH2C/HnFYywV91Kt4qpDFZuYV0Lq/H0jwYqgMbLh3e2PLngFyzrSgCLvgo2AE/mxFX/W0wIZBn7c2o95jJkbfb/z1Vn5ENkOyc0jvyKdk+jCblqAfOcKLOG5RsrXpE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=n5UX3XSU; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="n5UX3XSU" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6EAE71F00A3F; Sun, 2 Aug 2026 23:02:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785711723; bh=KaAPm6xsRE/SAQjze+2Z5h80E28qgp02afNZXVMba84=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=n5UX3XSUbyNqQpZZsoLg+Z+Z/MK5FKmBjsU8kQxQVrrUWDiROpnjcZIVhg1O7Z27d lJxhu7v5rb6clL9oCtr9yNB+LMkvyTgqCLYavj0giQyHLM1+JrQsv9cbaLKazsdSw8 R22NPPnVGYLQBHB+hrXnVFYN+fAfKHDIMkXSbdIsIRoTCjHqgsfxUTE5LEvqrIcADM BeeDhB8zGEpRupt4hahfO4zAe77qZlT5GLvLBfb+5sPwXosTpZRjbRkC4dIUwNGQ5+ rJSPCK+cbGx2B6J4e6OvrgO4kLW1kU8KCZbgH8S7mQ+2Xkvn4uZn9gFAc9Qt1U32ib ASpu437XWF3KQ== From: Eric Biggers To: linux-crypto@vger.kernel.org, Herbert Xu Cc: Richard Weinberger , linux-kernel@vger.kernel.org, Eric Biggers Subject: [PATCH 2/3] crypto: af_alg - Replace 'bool privileged' with flags Date: Sun, 2 Aug 2026 16:00:54 -0700 Message-ID: <20260802230055.100746-3-ebiggers@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802230055.100746-1-ebiggers@kernel.org> References: <20260802230055.100746-1-ebiggers@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" It isn't obvious what false/true mean at the definition sites, so let's replace it with flags instead. Also flip the polarity to make the default zero-initialized value be the secure (privileged-only) value. Signed-off-by: Eric Biggers --- crypto/af_alg.c | 3 ++- crypto/algif_aead.c | 2 +- crypto/algif_hash.c | 28 ++++++++++++++-------------- crypto/algif_skcipher.c | 28 ++++++++++++++-------------- include/crypto/if_alg.h | 6 +++++- 5 files changed, 36 insertions(+), 31 deletions(-) diff --git a/crypto/af_alg.c b/crypto/af_alg.c index 34b801568fba..1e5da61b315c 100644 --- a/crypto/af_alg.c +++ b/crypto/af_alg.c @@ -146,7 +146,8 @@ int af_alg_check_restriction(const char *name, for (const struct af_alg_allowlist_entry *ent =3D allowlist; ent->name; ent++) { if (strcmp(name, ent->name) =3D=3D 0 && - (!ent->privileged || af_alg_capable())) + ((ent->flags & AF_ALG_UNPRIVILEGED) || + af_alg_capable())) return 0; } } diff --git a/crypto/algif_aead.c b/crypto/algif_aead.c index b9217f9086aa..5574e2d70539 100644 --- a/crypto/algif_aead.c +++ b/crypto/algif_aead.c @@ -35,7 +35,7 @@ #include =20 static const struct af_alg_allowlist_entry aead_allowlist[] =3D { - { "ccm(aes)", true }, /* bluez */ + { "ccm(aes)" }, /* bluez */ {}, }; =20 diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c index a8d958d51ece..6e8b5fb82a7f 100644 --- a/crypto/algif_hash.c +++ b/crypto/algif_hash.c @@ -17,20 +17,20 @@ #include =20 static const struct af_alg_allowlist_entry hash_allowlist[] =3D { - { "cmac(aes)", true }, /* iwd, bluez */ - { "hmac(md5)", true }, /* iwd */ - { "hmac(sha1)", true }, /* iwd */ - { "hmac(sha224)", true }, /* iwd */ - { "hmac(sha256)", true }, /* iwd */ - { "hmac(sha384)", true }, /* iwd */ - { "hmac(sha512)", true }, /* iwd, sha512hmac */ - { "md4", true }, /* iwd */ - { "md5", true }, /* iwd */ - { "sha1", false }, /* iwd, iproute2 < 7.0 */ - { "sha224", true }, /* iwd */ - { "sha256", true }, /* iwd */ - { "sha384", true }, /* iwd */ - { "sha512", true }, /* iwd */ + { "cmac(aes)" }, /* iwd, bluez */ + { "hmac(md5)" }, /* iwd */ + { "hmac(sha1)" }, /* iwd */ + { "hmac(sha224)" }, /* iwd */ + { "hmac(sha256)" }, /* iwd */ + { "hmac(sha384)" }, /* iwd */ + { "hmac(sha512)" }, /* iwd, sha512hmac */ + { "md4" }, /* iwd */ + { "md5" }, /* iwd */ + { "sha1", AF_ALG_UNPRIVILEGED }, /* iwd, iproute2 < 7.0 */ + { "sha224" }, /* iwd */ + { "sha256" }, /* iwd */ + { "sha384" }, /* iwd */ + { "sha512" }, /* iwd */ {}, }; =20 diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c index 68b48d805e92..1e61fe6e24b9 100644 --- a/crypto/algif_skcipher.c +++ b/crypto/algif_skcipher.c @@ -36,20 +36,20 @@ #include =20 static const struct af_alg_allowlist_entry skcipher_allowlist[] =3D { - { "adiantum(xchacha12,aes)", false }, /* cryptsetup */ - { "adiantum(xchacha20,aes)", false }, /* cryptsetup */ - { "cbc(aes)", true }, /* iwd */ - { "cbc(des)", true }, /* iwd */ - { "cbc(des3_ede)", true }, /* iwd */ - { "cbc(paes)", true }, /* caam and others */ - { "ctr(aes)", true }, /* iwd */ - { "ecb(aes)", true }, /* iwd, bluez */ - { "ecb(des)", true }, /* iwd */ - { "hctr2(aes)", false }, /* cryptsetup */ - { "xts(aes)", false }, /* cryptsetup benchmark */ - { "xts(camellia)", false }, /* cryptsetup */ - { "xts(serpent)", false }, /* cryptsetup */ - { "xts(twofish)", false }, /* cryptsetup */ + { "adiantum(xchacha12,aes)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ + { "adiantum(xchacha20,aes)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ + { "cbc(aes)" }, /* iwd */ + { "cbc(des)" }, /* iwd */ + { "cbc(des3_ede)" }, /* iwd */ + { "cbc(paes)" }, /* caam and others */ + { "ctr(aes)" }, /* iwd */ + { "ecb(aes)" }, /* iwd, bluez */ + { "ecb(des)" }, /* iwd */ + { "hctr2(aes)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ + { "xts(aes)", AF_ALG_UNPRIVILEGED }, /* cryptsetup benchmark */ + { "xts(camellia)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ + { "xts(serpent)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ + { "xts(twofish)", AF_ALG_UNPRIVILEGED }, /* cryptsetup */ {}, }; =20 diff --git a/include/crypto/if_alg.h b/include/crypto/if_alg.h index dbf6a97c72a2..0d51428c1da4 100644 --- a/include/crypto/if_alg.h +++ b/include/crypto/if_alg.h @@ -8,6 +8,7 @@ #ifndef _CRYPTO_IF_ALG_H #define _CRYPTO_IF_ALG_H =20 +#include #include #include #include @@ -161,9 +162,12 @@ struct af_alg_ctx { unsigned int inflight; }; =20 +/* Flags for af_alg_allowlist_entry::flags: */ +#define AF_ALG_UNPRIVILEGED BIT(0) /* Unprivileged use is allowed */ + struct af_alg_allowlist_entry { const char *name; - bool privileged; + u32 flags; }; =20 int af_alg_register_type(const struct af_alg_type *type); --=20 2.55.0 From nobody Fri Oct 2 10:07:26 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A153D34041C; Sun, 2 Aug 2026 23:02:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711725; cv=none; b=NMtF42lkoBtyyBYL9a+fHL2eXpmPsPfw5f+KS9eB1Wn5zj5aBpNdw12hTfW4FOv2GckL1qUnGMB7wtRPQJ0Tg+uzFkZtbmXfG6Sko1xR3AzBtKZvUv1HoXMLnVDQe0cTgeZ50y/yvGR+Z/nE08a7wKitJWoLNrZre8YB2CrQgN4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785711725; c=relaxed/simple; bh=lLal+leuJtehj+DFCsY8ciP1Hzfu6ttl8xq811k6TLI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=k1UT5NHKE8F/TQ0rVxThL3ukZ+oUyiNzYorcnPpg/xOy9edp8Myan2LIXoF1SAtVGpEhcI51ZOGEYRcecCxWcW6CFf3EuakKmA9XR84gd8LkQeZvWE6xc1sFG7sAm2AhssQX8xfV+qP7oLsc1J0GxSVR5zNdZQDH04I0OHYV9v0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=KYek+Zlr; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="KYek+Zlr" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B6D7C1F00AC4; Sun, 2 Aug 2026 23:02:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785711723; bh=kIzg9GOQSA3QUe+ILmEeajJXxnc5iqX0Du1fki1bNxs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KYek+ZlrywcFl67vo/OkdLnmgJGLFCEuQ8oAi2ahI+CPsyqSd1zLhlYRU6+R5sqo2 JE9U3pABIFGOta6HSl2OFPkBb7/teb+bouDOGOROrKEtAp9FM9/Y4nXjxe4OPyJi7Z zkrrvLFIT+k8LdnCokUmjguN+f6Rq7PgRsRIAKm7LQM2Vb5qi8DxHsuK9CSj/yy+r1 U8tNsKxt49K5tF5FOmVTinNrGNxIQReTbzVRTm9Kk65FLudPmF240smg1zYbLItVJO oHddGxNPw8K70wX+H7oeW7D4GTI5LJCNsTlW/rBkX8ScYbvuq3Dr4AC0Nvv467dUtA TkNdCTWoiM8Gg== From: Eric Biggers To: linux-crypto@vger.kernel.org, Herbert Xu Cc: Richard Weinberger , linux-kernel@vger.kernel.org, Eric Biggers Subject: [PATCH 3/3] crypto: af_alg - Stop after finding name in allowlist Date: Sun, 2 Aug 2026 16:00:55 -0700 Message-ID: <20260802230055.100746-4-ebiggers@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802230055.100746-1-ebiggers@kernel.org> References: <20260802230055.100746-1-ebiggers@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" If the algorithm name is found in the allowlist and the privilege check doesn't pass, there's no need to consider remaining entries since the list contains (and is intended to contain) at most one entry per name. Signed-off-by: Eric Biggers --- crypto/af_alg.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/crypto/af_alg.c b/crypto/af_alg.c index 1e5da61b315c..ab84c4488a15 100644 --- a/crypto/af_alg.c +++ b/crypto/af_alg.c @@ -145,10 +145,13 @@ int af_alg_check_restriction(const char *name, if (level =3D=3D 1) { for (const struct af_alg_allowlist_entry *ent =3D allowlist; ent->name; ent++) { - if (strcmp(name, ent->name) =3D=3D 0 && - ((ent->flags & AF_ALG_UNPRIVILEGED) || - af_alg_capable())) - return 0; + if (strcmp(name, ent->name) =3D=3D 0) { + if ((ent->flags & AF_ALG_UNPRIVILEGED) || + af_alg_capable()) + return 0; + /* List contains at most one entry per name. */ + break; + } } } /* --=20 2.55.0