- ppc/xive: Fix ESB length overflow on 32-bit hosts - target/hppa: Fix PSW V-bit packaging in cpu_hppa_get for hppa64 - target/ppc: Fix migration of CPUs with TLB_EMB TLB type - target/arm: Clear high SVE elements in handle_vec_simd_wshli - module: Prevent crash by resetting local_err in module_load_qom_all() - tests/docker: update debian i686 and mipsel images to bookworm - target/arm: Fix SVE SDOT/UDOT/USDOT (4-way, indexed) - docs/sphinx/depfile.py: Handle env.doc2path() returning a Path not a str - block/blkio: use FUA flag on write zeroes only if supported - virtio-pci: Fix the use of an uninitialized irqfd - hw/cxl: Ensure there is enough data to read the input header in cmd_get_physical_port_state() - intel_iommu: Send IQE event when setting reserved bit in IQT_TAIL - virtio-net: Avoid indirection_table_mask overflow - Fix calculation of minimum in colo_compare_tcp - target/riscv/csr.c: Fix an access to VXSAT - linux-user: Clean up unused header - raw-format: Fix error message for invalid offset/size - hw/loongarch/virt: Remove unnecessary 'cpu.h' inclusion - tests: Wait for migration completion on destination QEMU to avoid failures - acpi: ged: Add macro for acpi sleep control register - hw/intc/openpic: Improve errors for out of bounds property values - hw/pci-bridge: Add a Kconfig switch for the normal PCI bridge - docs/tools/qemu-img.rst: fix typo (sumarizes) - audio/pw: Report more accurate error when connecting to PipeWire fails - audio/pw: Report more accurate error when connecting to PipeWire fails - dma: Fix function names in documentation Ensure the function names match. - edu: fix DMA range upper bound check - platform-bus: fix refcount leak - hw/net/can/sja1000: fix bug for single acceptance filter and standard frame - tests/avocado: fix typo in replay_linux - util/userfaultfd: Remove unused uffd_poll_events - Consider discard option when writing zeros - crypto: factor out conversion of QAPI to gcrypt constants - crypto: drop gnutls debug logging support - crypto: use consistent error reporting pattern for unsupported cipher modes - hw/gpio/aspeed_gpio: Avoid shift into sign bit Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com> (cherry picked from commit b6e04df301d30895427ab41a1edff0f40149bdd9)
79 lines
2.9 KiB
Diff
79 lines
2.9 KiB
Diff
From 7bd04536327357a97206d8048f5d9341780bbe5a Mon Sep 17 00:00:00 2001
|
|
From: dinglimin <dinglimin@cmss.chinamobile.com>
|
|
Date: Sat, 12 Oct 2024 11:26:16 +0800
|
|
Subject: [PATCH] crypto: use consistent error reporting pattern for
|
|
unsupported cipher modes MIME-Version: 1.0 Content-Type: text/plain;
|
|
charset=UTF-8 Content-Transfer-Encoding: 8bit
|
|
MIME-Version: 1.0
|
|
Content-Type: text/plain; charset=UTF-8
|
|
Content-Transfer-Encoding: 8bit
|
|
|
|
Not all paths in qcrypto_cipher_ctx_new() were correctly distinguishing
|
|
between valid user input for cipher mode (which should report a user
|
|
facing error), vs program logic errors (which should assert).
|
|
|
|
Reported-by: Peter Maydell <peter.maydell@linaro.org>
|
|
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
|
|
Signed-off-by: dinglimin <dinglimin@cmss.chinamobile.com>
|
|
---
|
|
crypto/cipher-nettle.c.inc | 18 ++++++++++++++----
|
|
1 file changed, 14 insertions(+), 4 deletions(-)
|
|
|
|
diff --git a/crypto/cipher-nettle.c.inc b/crypto/cipher-nettle.c.inc
|
|
index 766de036ba..2654b439c1 100644
|
|
--- a/crypto/cipher-nettle.c.inc
|
|
+++ b/crypto/cipher-nettle.c.inc
|
|
@@ -525,8 +525,10 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgorithm alg,
|
|
case QCRYPTO_CIPHER_MODE_CTR:
|
|
drv = &qcrypto_nettle_des_driver_ctr;
|
|
break;
|
|
- default:
|
|
+ case QCRYPTO_CIPHER_MODE_XTS:
|
|
goto bad_cipher_mode;
|
|
+ default:
|
|
+ g_assert_not_reached();
|
|
}
|
|
|
|
ctx = g_new0(QCryptoNettleDES, 1);
|
|
@@ -551,8 +553,10 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgorithm alg,
|
|
case QCRYPTO_CIPHER_MODE_CTR:
|
|
drv = &qcrypto_nettle_des3_driver_ctr;
|
|
break;
|
|
- default:
|
|
+ case QCRYPTO_CIPHER_MODE_XTS:
|
|
goto bad_cipher_mode;
|
|
+ default:
|
|
+ g_assert_not_reached();
|
|
}
|
|
|
|
ctx = g_new0(QCryptoNettleDES3, 1);
|
|
@@ -663,8 +667,10 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgorithm alg,
|
|
case QCRYPTO_CIPHER_MODE_CTR:
|
|
drv = &qcrypto_nettle_cast128_driver_ctr;
|
|
break;
|
|
- default:
|
|
+ case QCRYPTO_CIPHER_MODE_XTS:
|
|
goto bad_cipher_mode;
|
|
+ default:
|
|
+ g_assert_not_reached();
|
|
}
|
|
|
|
ctx = g_new0(QCryptoNettleCAST128, 1);
|
|
@@ -741,8 +747,12 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgorithm alg,
|
|
case QCRYPTO_CIPHER_MODE_ECB:
|
|
drv = &qcrypto_nettle_sm4_driver_ecb;
|
|
break;
|
|
- default:
|
|
+ case QCRYPTO_CIPHER_MODE_CBC:
|
|
+ case QCRYPTO_CIPHER_MODE_CTR:
|
|
+ case QCRYPTO_CIPHER_MODE_XTS:
|
|
goto bad_cipher_mode;
|
|
+ default:
|
|
+ g_assert_not_reached();
|
|
}
|
|
|
|
ctx = g_new0(QCryptoNettleSm4, 1);
|
|
--
|
|
2.41.0.windows.1
|
|
|