Commit e5a7f7e0 authored by Harald Freudenberger's avatar Harald Freudenberger Committed by Heiko Carstens
Browse files

s390/pkey: Provide and pass xflags within pkey and zcrypt layers



Provide and pass the xflag parameter from pkey ioctls through
the pkey handler and further down to the implementations
(CCA, EP11, PCKMO and UV). So all the code is now prepared
and ready to support xflags ("execution flag").

The pkey layer supports the xflag PKEY_XFLAG_NOMEMALLOC: If this
flag is given in the xflags parameter, the pkey implementation is
not allowed to allocate memory but instead should fall back to use
preallocated memory or simple fail with -ENOMEM. This flag is for
protected key derive within a cipher or similar which must not
allocate memory which would cause io operations - see also the
CRYPTO_ALG_ALLOCATES_MEMORY flag in crypto.h.

Within the pkey handlers this flag is then to be translated to
appropriate zcrypt xflags before any zcrypt related functions
are called. So the PKEY_XFLAG_NOMEMALLOC translates to
ZCRYPT_XFLAG_NOMEMALLOC - If this flag is set, no memory
allocations which may trigger any IO operations are done.

The pkey in-kernel pkey API still does not provide this xflag
param. That's intended to come with a separate patch which
enables this functionality.

Signed-off-by: default avatarHarald Freudenberger <freude@linux.ibm.com>
Reviewed-by: default avatarHolger Dengler <dengler@linux.ibm.com>
Link: https://lore.kernel.org/r/20250424133619.16495-25-freude@linux.ibm.com


Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
parent a42831f0
Loading
Loading
Loading
Loading
+10 −0
Original line number Diff line number Diff line
@@ -25,4 +25,14 @@
int pkey_key2protkey(const u8 *key, u32 keylen,
		     u8 *protkey, u32 *protkeylen, u32 *protkeytype);

/*
 * If this flag is given in the xflags parameter, the pkey implementation
 * is not allowed to allocate memory but instead should fall back to use
 * preallocated memory or simple fail with -ENOMEM.
 * This flag is for protected key derive within a cipher or similar
 * which must not allocate memory which would cause io operations - see
 * also the CRYPTO_ALG_ALLOCATES_MEMORY flag in crypto.h.
 */
#define PKEY_XFLAG_NOMEMALLOC 0x0001

#endif /* _KAPI_PKEY_H */
+26 −23
Original line number Diff line number Diff line
@@ -24,7 +24,8 @@
 */
static int key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
		       const u8 *key, size_t keylen,
		       u8 *protkey, u32 *protkeylen, u32 *protkeytype)
		       u8 *protkey, u32 *protkeylen, u32 *protkeytype,
		       u32 xflags)
{
	int rc;

@@ -32,14 +33,14 @@ static int key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
	rc = pkey_handler_key_to_protkey(apqns, nr_apqns,
					 key, keylen,
					 protkey, protkeylen,
					 protkeytype);
					 protkeytype, xflags);

	/* if this did not work, try the slowpath way */
	if (rc == -ENODEV) {
		rc = pkey_handler_slowpath_key_to_protkey(apqns, nr_apqns,
							  key, keylen,
							  protkey, protkeylen,
							  protkeytype);
							  protkeytype, xflags);
		if (rc)
			rc = -ENODEV;
	}
@@ -55,13 +56,14 @@ int pkey_key2protkey(const u8 *key, u32 keylen,
		     u8 *protkey, u32 *protkeylen, u32 *protkeytype)
{
	int rc;
	const u32 xflags = 0;

	rc = key2protkey(NULL, 0, key, keylen,
			 protkey, protkeylen, protkeytype);
			 protkey, protkeylen, protkeytype, xflags);
	if (rc == -ENODEV) {
		pkey_handler_request_modules();
		rc = key2protkey(NULL, 0, key, keylen,
				 protkey, protkeylen, protkeytype);
				 protkey, protkeylen, protkeytype, xflags);
	}

	return rc;
@@ -103,7 +105,7 @@ static int pkey_ioctl_genseck(struct pkey_genseck __user *ugs)
	keybuflen = sizeof(kgs.seckey.seckey);
	rc = pkey_handler_gen_key(&apqn, 1,
				  kgs.keytype, PKEY_TYPE_CCA_DATA, 0, 0,
				  kgs.seckey.seckey, &keybuflen, NULL);
				  kgs.seckey.seckey, &keybuflen, NULL, 0);
	pr_debug("gen_key()=%d\n", rc);
	if (!rc && copy_to_user(ugs, &kgs, sizeof(kgs)))
		rc = -EFAULT;
@@ -129,7 +131,7 @@ static int pkey_ioctl_clr2seck(struct pkey_clr2seck __user *ucs)
				     kcs.keytype, PKEY_TYPE_CCA_DATA, 0, 0,
				     kcs.clrkey.clrkey,
				     pkey_keytype_aes_to_size(kcs.keytype),
				     kcs.seckey.seckey, &keybuflen, NULL);
				     kcs.seckey.seckey, &keybuflen, NULL, 0);
	pr_debug("clr_to_key()=%d\n", rc);
	if (!rc && copy_to_user(ucs, &kcs, sizeof(kcs)))
		rc = -EFAULT;
@@ -154,7 +156,8 @@ static int pkey_ioctl_sec2protk(struct pkey_sec2protk __user *usp)
					 ksp.seckey.seckey,
					 sizeof(ksp.seckey.seckey),
					 ksp.protkey.protkey,
					 &ksp.protkey.len, &ksp.protkey.type);
					 &ksp.protkey.len, &ksp.protkey.type,
					 0);
	pr_debug("key_to_protkey()=%d\n", rc);
	if (!rc && copy_to_user(usp, &ksp, sizeof(ksp)))
		rc = -EFAULT;
@@ -198,7 +201,7 @@ static int pkey_ioctl_clr2protk(struct pkey_clr2protk __user *ucp)
	rc = key2protkey(NULL, 0,
			 tmpbuf, sizeof(*t) + keylen,
			 kcp.protkey.protkey,
			 &kcp.protkey.len, &kcp.protkey.type);
			 &kcp.protkey.len, &kcp.protkey.type, 0);
	pr_debug("key2protkey()=%d\n", rc);

	kfree_sensitive(tmpbuf);
@@ -228,12 +231,12 @@ static int pkey_ioctl_findcard(struct pkey_findcard __user *ufc)
	rc = pkey_handler_apqns_for_key(kfc.seckey.seckey,
					sizeof(kfc.seckey.seckey),
					PKEY_FLAGS_MATCH_CUR_MKVP,
					apqns, &nr_apqns);
					apqns, &nr_apqns, 0);
	if (rc == -ENODEV)
		rc = pkey_handler_apqns_for_key(kfc.seckey.seckey,
						sizeof(kfc.seckey.seckey),
						PKEY_FLAGS_MATCH_ALT_MKVP,
						apqns, &nr_apqns);
						apqns, &nr_apqns, 0);
	pr_debug("apqns_for_key()=%d\n", rc);
	if (rc) {
		kfree(apqns);
@@ -262,7 +265,7 @@ static int pkey_ioctl_skey2pkey(struct pkey_skey2pkey __user *usp)
					 sizeof(ksp.seckey.seckey),
					 ksp.protkey.protkey,
					 &ksp.protkey.len,
					 &ksp.protkey.type);
					 &ksp.protkey.type, 0);
	pr_debug("key_to_protkey()=%d\n", rc);
	if (!rc && copy_to_user(usp, &ksp, sizeof(ksp)))
		rc = -EFAULT;
@@ -285,7 +288,7 @@ static int pkey_ioctl_verifykey(struct pkey_verifykey __user *uvk)
	rc = pkey_handler_verify_key(kvk.seckey.seckey,
				     sizeof(kvk.seckey.seckey),
				     &kvk.cardnr, &kvk.domain,
				     &keytype, &keybitsize, &flags);
				     &keytype, &keybitsize, &flags, 0);
	pr_debug("verify_key()=%d\n", rc);
	if (!rc && keytype != PKEY_TYPE_CCA_DATA)
		rc = -EINVAL;
@@ -312,7 +315,7 @@ static int pkey_ioctl_genprotk(struct pkey_genprotk __user *ugp)
	rc = pkey_handler_gen_key(NULL, 0, kgp.keytype,
				  PKEY_TYPE_PROTKEY, 0, 0,
				  kgp.protkey.protkey, &kgp.protkey.len,
				  &kgp.protkey.type);
				  &kgp.protkey.type, 0);
	pr_debug("gen_key()=%d\n", rc);
	if (!rc && copy_to_user(ugp, &kgp, sizeof(kgp)))
		rc = -EFAULT;
@@ -354,7 +357,7 @@ static int pkey_ioctl_verifyprotk(struct pkey_verifyprotk __user *uvp)
	memcpy(t->protkey, kvp.protkey.protkey, kvp.protkey.len);

	rc = pkey_handler_verify_key(tmpbuf, sizeof(*t),
				     NULL, NULL, NULL, NULL, NULL);
				     NULL, NULL, NULL, NULL, NULL, 0);
	pr_debug("verify_key()=%d\n", rc);

	kfree_sensitive(tmpbuf);
@@ -377,7 +380,7 @@ static int pkey_ioctl_kblob2protk(struct pkey_kblob2pkey __user *utp)
	ktp.protkey.len = sizeof(ktp.protkey.protkey);
	rc = key2protkey(NULL, 0, kkey, ktp.keylen,
			 ktp.protkey.protkey, &ktp.protkey.len,
			 &ktp.protkey.type);
			 &ktp.protkey.type, 0);
	pr_debug("key2protkey()=%d\n", rc);
	kfree_sensitive(kkey);
	if (!rc && copy_to_user(utp, &ktp, sizeof(ktp)))
@@ -414,7 +417,7 @@ static int pkey_ioctl_genseck2(struct pkey_genseck2 __user *ugs)
	}
	rc = pkey_handler_gen_key(apqns, kgs.apqn_entries,
				  u, kgs.type, kgs.size, kgs.keygenflags,
				  kkey, &klen, NULL);
				  kkey, &klen, NULL, 0);
	pr_debug("gen_key()=%d\n", rc);
	kfree(apqns);
	if (rc) {
@@ -471,7 +474,7 @@ static int pkey_ioctl_clr2seck2(struct pkey_clr2seck2 __user *ucs)
	rc = pkey_handler_clr_to_key(apqns, kcs.apqn_entries,
				     u, kcs.type, kcs.size, kcs.keygenflags,
				     kcs.clrkey.clrkey, kcs.size / 8,
				     kkey, &klen, NULL);
				     kkey, &klen, NULL, 0);
	pr_debug("clr_to_key()=%d\n", rc);
	kfree(apqns);
	if (rc) {
@@ -514,7 +517,7 @@ static int pkey_ioctl_verifykey2(struct pkey_verifykey2 __user *uvk)

	rc = pkey_handler_verify_key(kkey, kvk.keylen,
				     &kvk.cardnr, &kvk.domain,
				     &kvk.type, &kvk.size, &kvk.flags);
				     &kvk.type, &kvk.size, &kvk.flags, 0);
	pr_debug("verify_key()=%d\n", rc);

	kfree_sensitive(kkey);
@@ -544,7 +547,7 @@ static int pkey_ioctl_kblob2protk2(struct pkey_kblob2pkey2 __user *utp)
	ktp.protkey.len = sizeof(ktp.protkey.protkey);
	rc = key2protkey(apqns, ktp.apqn_entries, kkey, ktp.keylen,
			 ktp.protkey.protkey, &ktp.protkey.len,
			 &ktp.protkey.type);
			 &ktp.protkey.type, 0);
	pr_debug("key2protkey()=%d\n", rc);
	kfree(apqns);
	kfree_sensitive(kkey);
@@ -579,7 +582,7 @@ static int pkey_ioctl_apqns4k(struct pkey_apqns4key __user *uak)
		return PTR_ERR(kkey);
	}
	rc = pkey_handler_apqns_for_key(kkey, kak.keylen, kak.flags,
					apqns, &nr_apqns);
					apqns, &nr_apqns, 0);
	pr_debug("apqns_for_key()=%d\n", rc);
	kfree_sensitive(kkey);
	if (rc && rc != -ENOSPC) {
@@ -626,7 +629,7 @@ static int pkey_ioctl_apqns4kt(struct pkey_apqns4keytype __user *uat)
	}
	rc = pkey_handler_apqns_for_keytype(kat.type,
					    kat.cur_mkvp, kat.alt_mkvp,
					    kat.flags, apqns, &nr_apqns);
					    kat.flags, apqns, &nr_apqns, 0);
	pr_debug("apqns_for_keytype()=%d\n", rc);
	if (rc && rc != -ENOSPC) {
		kfree(apqns);
@@ -678,7 +681,7 @@ static int pkey_ioctl_kblob2protk3(struct pkey_kblob2pkey3 __user *utp)
		return -ENOMEM;
	}
	rc = key2protkey(apqns, ktp.apqn_entries, kkey, ktp.keylen,
			 protkey, &protkeylen, &ktp.pkeytype);
			 protkey, &protkeylen, &ktp.pkeytype, 0);
	pr_debug("key2protkey()=%d\n", rc);
	kfree(apqns);
	kfree_sensitive(kkey);
+20 −14
Original line number Diff line number Diff line
@@ -150,7 +150,8 @@ EXPORT_SYMBOL(pkey_handler_put);

int pkey_handler_key_to_protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
				const u8 *key, u32 keylen,
				u8 *protkey, u32 *protkeylen, u32 *protkeytype)
				u8 *protkey, u32 *protkeylen, u32 *protkeytype,
				u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;
@@ -159,7 +160,7 @@ int pkey_handler_key_to_protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (h && h->key_to_protkey) {
		rc = h->key_to_protkey(apqns, nr_apqns, key, keylen,
				       protkey, protkeylen,
				       protkeytype);
				       protkeytype, xflags);
	}
	pkey_handler_put(h);

@@ -177,7 +178,7 @@ int pkey_handler_slowpath_key_to_protkey(const struct pkey_apqn *apqns,
					 size_t nr_apqns,
					 const u8 *key, u32 keylen,
					 u8 *protkey, u32 *protkeylen,
					 u32 *protkeytype)
					 u32 *protkeytype, u32 xflags)
{
	const struct pkey_handler *h, *htmp[10];
	int i, n = 0, rc = -ENODEV;
@@ -199,7 +200,7 @@ int pkey_handler_slowpath_key_to_protkey(const struct pkey_apqn *apqns,
			rc = h->slowpath_key_to_protkey(apqns, nr_apqns,
							key, keylen,
							protkey, protkeylen,
							protkeytype);
							protkeytype, xflags);
		module_put(h->module);
	}

@@ -210,7 +211,7 @@ EXPORT_SYMBOL(pkey_handler_slowpath_key_to_protkey);
int pkey_handler_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
			 u32 keytype, u32 keysubtype,
			 u32 keybitsize, u32 flags,
			 u8 *keybuf, u32 *keybuflen, u32 *keyinfo)
			 u8 *keybuf, u32 *keybuflen, u32 *keyinfo, u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;
@@ -219,7 +220,7 @@ int pkey_handler_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (h && h->gen_key) {
		rc = h->gen_key(apqns, nr_apqns, keytype, keysubtype,
				keybitsize, flags,
				keybuf, keybuflen, keyinfo);
				keybuf, keybuflen, keyinfo, xflags);
	}
	pkey_handler_put(h);

@@ -231,7 +232,8 @@ int pkey_handler_clr_to_key(const struct pkey_apqn *apqns, size_t nr_apqns,
			    u32 keytype, u32 keysubtype,
			    u32 keybitsize, u32 flags,
			    const u8 *clrkey, u32 clrkeylen,
			    u8 *keybuf, u32 *keybuflen, u32 *keyinfo)
			    u8 *keybuf, u32 *keybuflen, u32 *keyinfo,
			    u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;
@@ -240,7 +242,7 @@ int pkey_handler_clr_to_key(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (h && h->clr_to_key) {
		rc = h->clr_to_key(apqns, nr_apqns, keytype, keysubtype,
				   keybitsize, flags, clrkey, clrkeylen,
				   keybuf, keybuflen, keyinfo);
				   keybuf, keybuflen, keyinfo, xflags);
	}
	pkey_handler_put(h);

@@ -250,7 +252,8 @@ EXPORT_SYMBOL(pkey_handler_clr_to_key);

int pkey_handler_verify_key(const u8 *key, u32 keylen,
			    u16 *card, u16 *dom,
			    u32 *keytype, u32 *keybitsize, u32 *flags)
			    u32 *keytype, u32 *keybitsize, u32 *flags,
			    u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;
@@ -258,7 +261,7 @@ int pkey_handler_verify_key(const u8 *key, u32 keylen,
	h = pkey_handler_get_keybased(key, keylen);
	if (h && h->verify_key) {
		rc = h->verify_key(key, keylen, card, dom,
				   keytype, keybitsize, flags);
				   keytype, keybitsize, flags, xflags);
	}
	pkey_handler_put(h);

@@ -267,14 +270,16 @@ int pkey_handler_verify_key(const u8 *key, u32 keylen,
EXPORT_SYMBOL(pkey_handler_verify_key);

int pkey_handler_apqns_for_key(const u8 *key, u32 keylen, u32 flags,
			       struct pkey_apqn *apqns, size_t *nr_apqns)
			       struct pkey_apqn *apqns, size_t *nr_apqns,
			       u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;

	h = pkey_handler_get_keybased(key, keylen);
	if (h && h->apqns_for_key)
		rc = h->apqns_for_key(key, keylen, flags, apqns, nr_apqns);
		rc = h->apqns_for_key(key, keylen, flags, apqns, nr_apqns,
				      xflags);
	pkey_handler_put(h);

	return rc;
@@ -283,7 +288,8 @@ EXPORT_SYMBOL(pkey_handler_apqns_for_key);

int pkey_handler_apqns_for_keytype(enum pkey_key_type keysubtype,
				   u8 cur_mkvp[32], u8 alt_mkvp[32], u32 flags,
				   struct pkey_apqn *apqns, size_t *nr_apqns)
				   struct pkey_apqn *apqns, size_t *nr_apqns,
				   u32 xflags)
{
	const struct pkey_handler *h;
	int rc = -ENODEV;
@@ -292,7 +298,7 @@ int pkey_handler_apqns_for_keytype(enum pkey_key_type keysubtype,
	if (h && h->apqns_for_keytype) {
		rc = h->apqns_for_keytype(keysubtype,
					  cur_mkvp, alt_mkvp, flags,
					  apqns, nr_apqns);
					  apqns, nr_apqns, xflags);
	}
	pkey_handler_put(h);

+23 −14
Original line number Diff line number Diff line
@@ -159,29 +159,33 @@ struct pkey_handler {
	bool (*is_supported_keytype)(enum pkey_key_type);
	int (*key_to_protkey)(const struct pkey_apqn *apqns, size_t nr_apqns,
			      const u8 *key, u32 keylen,
			      u8 *protkey, u32 *protkeylen, u32 *protkeytype);
			      u8 *protkey, u32 *protkeylen, u32 *protkeytype,
			      u32 xflags);
	int (*slowpath_key_to_protkey)(const struct pkey_apqn *apqns,
				       size_t nr_apqns,
				       const u8 *key, u32 keylen,
				       u8 *protkey, u32 *protkeylen,
				       u32 *protkeytype);
				       u32 *protkeytype, u32 xflags);
	int (*gen_key)(const struct pkey_apqn *apqns, size_t nr_apqns,
		       u32 keytype, u32 keysubtype,
		       u32 keybitsize, u32 flags,
		       u8 *keybuf, u32 *keybuflen, u32 *keyinfo);
		       u8 *keybuf, u32 *keybuflen, u32 *keyinfo, u32 xflags);
	int (*clr_to_key)(const struct pkey_apqn *apqns, size_t nr_apqns,
			  u32 keytype, u32 keysubtype,
			  u32 keybitsize, u32 flags,
			  const u8 *clrkey, u32 clrkeylen,
			  u8 *keybuf, u32 *keybuflen, u32 *keyinfo);
			  u8 *keybuf, u32 *keybuflen, u32 *keyinfo, u32 xflags);
	int (*verify_key)(const u8 *key, u32 keylen,
			  u16 *card, u16 *dom,
			  u32 *keytype, u32 *keybitsize, u32 *flags);
			  u32 *keytype, u32 *keybitsize, u32 *flags,
			  u32 xflags);
	int (*apqns_for_key)(const u8 *key, u32 keylen, u32 flags,
			     struct pkey_apqn *apqns, size_t *nr_apqns);
			     struct pkey_apqn *apqns, size_t *nr_apqns,
			     u32 xflags);
	int (*apqns_for_keytype)(enum pkey_key_type ktype,
				 u8 cur_mkvp[32], u8 alt_mkvp[32], u32 flags,
				 struct pkey_apqn *apqns, size_t *nr_apqns);
				 struct pkey_apqn *apqns, size_t *nr_apqns,
				 u32 xflags);
	/* used internal by pkey base */
	struct list_head list;
};
@@ -199,29 +203,34 @@ void pkey_handler_put(const struct pkey_handler *handler);

int pkey_handler_key_to_protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
				const u8 *key, u32 keylen,
				u8 *protkey, u32 *protkeylen, u32 *protkeytype);
				u8 *protkey, u32 *protkeylen, u32 *protkeytype,
				u32 xflags);
int pkey_handler_slowpath_key_to_protkey(const struct pkey_apqn *apqns,
					 size_t nr_apqns,
					 const u8 *key, u32 keylen,
					 u8 *protkey, u32 *protkeylen,
					 u32 *protkeytype);
					 u32 *protkeytype, u32 xflags);
int pkey_handler_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
			 u32 keytype, u32 keysubtype,
			 u32 keybitsize, u32 flags,
			 u8 *keybuf, u32 *keybuflen, u32 *keyinfo);
			 u8 *keybuf, u32 *keybuflen, u32 *keyinfo, u32 xflags);
int pkey_handler_clr_to_key(const struct pkey_apqn *apqns, size_t nr_apqns,
			    u32 keytype, u32 keysubtype,
			    u32 keybitsize, u32 flags,
			    const u8 *clrkey, u32 clrkeylen,
			    u8 *keybuf, u32 *keybuflen, u32 *keyinfo);
			    u8 *keybuf, u32 *keybuflen, u32 *keyinfo,
			    u32 xflags);
int pkey_handler_verify_key(const u8 *key, u32 keylen,
			    u16 *card, u16 *dom,
			    u32 *keytype, u32 *keybitsize, u32 *flags);
			    u32 *keytype, u32 *keybitsize, u32 *flags,
			    u32 xflags);
int pkey_handler_apqns_for_key(const u8 *key, u32 keylen, u32 flags,
			       struct pkey_apqn *apqns, size_t *nr_apqns);
			       struct pkey_apqn *apqns, size_t *nr_apqns,
			       u32 xflags);
int pkey_handler_apqns_for_keytype(enum pkey_key_type ktype,
				   u8 cur_mkvp[32], u8 alt_mkvp[32], u32 flags,
				   struct pkey_apqn *apqns, size_t *nr_apqns);
				   struct pkey_apqn *apqns, size_t *nr_apqns,
				   u32 xflags);

/*
 * Unconditional try to load all handler modules
+49 −27
Original line number Diff line number Diff line
@@ -70,12 +70,15 @@ static bool is_cca_keytype(enum pkey_key_type key_type)
}

static int cca_apqns4key(const u8 *key, u32 keylen, u32 flags,
			 struct pkey_apqn *apqns, size_t *nr_apqns)
			 struct pkey_apqn *apqns, size_t *nr_apqns, u32 pflags)
{
	struct keytoken_header *hdr = (struct keytoken_header *)key;
	u32 _apqns[MAXAPQNSINLIST], _nr_apqns = ARRAY_SIZE(_apqns);
	u32 xflags;
	int rc;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	if (!flags)
		flags = PKEY_FLAGS_MATCH_CUR_MKVP | PKEY_FLAGS_MATCH_ALT_MKVP;

@@ -109,7 +112,7 @@ static int cca_apqns4key(const u8 *key, u32 keylen, u32 flags,
		}
		rc = cca_findcard2(_apqns, &_nr_apqns, 0xFFFF, 0xFFFF,
				   minhwtype, AES_MK_SET,
				   cur_mkvp, old_mkvp);
				   cur_mkvp, old_mkvp, xflags);
		if (rc)
			goto out;

@@ -128,7 +131,7 @@ static int cca_apqns4key(const u8 *key, u32 keylen, u32 flags,
		}
		rc = cca_findcard2(_apqns, &_nr_apqns, 0xFFFF, 0xFFFF,
				   ZCRYPT_CEX7, APKA_MK_SET,
				   cur_mkvp, old_mkvp);
				   cur_mkvp, old_mkvp, xflags);
		if (rc)
			goto out;

@@ -153,11 +156,15 @@ static int cca_apqns4key(const u8 *key, u32 keylen, u32 flags,

static int cca_apqns4type(enum pkey_key_type ktype,
			  u8 cur_mkvp[32], u8 alt_mkvp[32], u32 flags,
			  struct pkey_apqn *apqns, size_t *nr_apqns)
			  struct pkey_apqn *apqns, size_t *nr_apqns,
			  u32 pflags)
{
	u32 _apqns[MAXAPQNSINLIST], _nr_apqns = ARRAY_SIZE(_apqns);
	u32 xflags;
	int rc;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	zcrypt_wait_api_operational();

	if (ktype == PKEY_TYPE_CCA_DATA || ktype == PKEY_TYPE_CCA_CIPHER) {
@@ -172,7 +179,7 @@ static int cca_apqns4type(enum pkey_key_type ktype,
			minhwtype = ZCRYPT_CEX6;
		rc = cca_findcard2(_apqns, &_nr_apqns, 0xFFFF, 0xFFFF,
				   minhwtype, AES_MK_SET,
				   cur_mkvp, old_mkvp);
				   cur_mkvp, old_mkvp, xflags);
		if (rc)
			goto out;

@@ -185,7 +192,7 @@ static int cca_apqns4type(enum pkey_key_type ktype,
			old_mkvp = *((u64 *)alt_mkvp);
		rc = cca_findcard2(_apqns, &_nr_apqns, 0xFFFF, 0xFFFF,
				   ZCRYPT_CEX7, APKA_MK_SET,
				   cur_mkvp, old_mkvp);
				   cur_mkvp, old_mkvp, xflags);
		if (rc)
			goto out;

@@ -210,12 +217,16 @@ static int cca_apqns4type(enum pkey_key_type ktype,

static int cca_key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
			   const u8 *key, u32 keylen,
			   u8 *protkey, u32 *protkeylen, u32 *protkeytype)
			   u8 *protkey, u32 *protkeylen, u32 *protkeytype,
			   u32 pflags)
{
	struct keytoken_header *hdr = (struct keytoken_header *)key;
	struct pkey_apqn _apqns[MAXAPQNSINLIST];
	u32 xflags;
	int i, rc;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	if (keylen < sizeof(*hdr))
		return -EINVAL;

@@ -251,7 +262,7 @@ static int cca_key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (!apqns || (nr_apqns == 1 &&
		       apqns[0].card == 0xFFFF && apqns[0].domain == 0xFFFF)) {
		nr_apqns = MAXAPQNSINLIST;
		rc = cca_apqns4key(key, keylen, 0, _apqns, &nr_apqns);
		rc = cca_apqns4key(key, keylen, 0, _apqns, &nr_apqns, pflags);
		if (rc)
			goto out;
		apqns = _apqns;
@@ -262,16 +273,16 @@ static int cca_key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
		    hdr->version == TOKVER_CCA_AES) {
			rc = cca_sec2protkey(apqns[i].card, apqns[i].domain,
					     key, protkey,
					     protkeylen, protkeytype);
					     protkeylen, protkeytype, xflags);
		} else if (hdr->type == TOKTYPE_CCA_INTERNAL &&
			   hdr->version == TOKVER_CCA_VLSC) {
			rc = cca_cipher2protkey(apqns[i].card, apqns[i].domain,
						key, protkey,
						protkeylen, protkeytype);
						protkeylen, protkeytype, xflags);
		} else if (hdr->type == TOKTYPE_CCA_INTERNAL_PKA) {
			rc = cca_ecc2protkey(apqns[i].card, apqns[i].domain,
					     key, protkey,
					     protkeylen, protkeytype);
					     protkeylen, protkeytype, xflags);
		} else {
			rc = -EINVAL;
			break;
@@ -295,10 +306,13 @@ static int cca_key2protkey(const struct pkey_apqn *apqns, size_t nr_apqns,
static int cca_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
		       u32 keytype, u32 subtype,
		       u32 keybitsize, u32 flags,
		       u8 *keybuf, u32 *keybuflen, u32 *_keyinfo)
		       u8 *keybuf, u32 *keybuflen, u32 *_keyinfo, u32 pflags)
{
	struct pkey_apqn _apqns[MAXAPQNSINLIST];
	int i, len, rc;
	u32 xflags;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	/* check keytype, subtype, keybitsize */
	switch (keytype) {
@@ -333,7 +347,8 @@ static int cca_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (!apqns || (nr_apqns == 1 &&
		       apqns[0].card == 0xFFFF && apqns[0].domain == 0xFFFF)) {
		nr_apqns = MAXAPQNSINLIST;
		rc = cca_apqns4type(subtype, NULL, NULL, 0, _apqns, &nr_apqns);
		rc = cca_apqns4type(subtype, NULL, NULL, 0,
				    _apqns, &nr_apqns, pflags);
		if (rc)
			goto out;
		apqns = _apqns;
@@ -343,11 +358,11 @@ static int cca_gen_key(const struct pkey_apqn *apqns, size_t nr_apqns,
		if (subtype == PKEY_TYPE_CCA_CIPHER) {
			rc = cca_gencipherkey(apqns[i].card, apqns[i].domain,
					      keybitsize, flags,
					      keybuf, keybuflen);
					      keybuf, keybuflen, xflags);
		} else {
			/* PKEY_TYPE_CCA_DATA */
			rc = cca_genseckey(apqns[i].card, apqns[i].domain,
					   keybitsize, keybuf);
					   keybitsize, keybuf, xflags);
			*keybuflen = (rc ? 0 : SECKEYBLOBSIZE);
		}
	}
@@ -370,10 +385,13 @@ static int cca_clr2key(const struct pkey_apqn *apqns, size_t nr_apqns,
		       u32 keytype, u32 subtype,
		       u32 keybitsize, u32 flags,
		       const u8 *clrkey, u32 clrkeylen,
		       u8 *keybuf, u32 *keybuflen, u32 *_keyinfo)
		       u8 *keybuf, u32 *keybuflen, u32 *_keyinfo, u32 pflags)
{
	struct pkey_apqn _apqns[MAXAPQNSINLIST];
	int i, len, rc;
	u32 xflags;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	/* check keytype, subtype, clrkeylen, keybitsize */
	switch (keytype) {
@@ -413,7 +431,8 @@ static int cca_clr2key(const struct pkey_apqn *apqns, size_t nr_apqns,
	if (!apqns || (nr_apqns == 1 &&
		       apqns[0].card == 0xFFFF && apqns[0].domain == 0xFFFF)) {
		nr_apqns = MAXAPQNSINLIST;
		rc = cca_apqns4type(subtype, NULL, NULL, 0, _apqns, &nr_apqns);
		rc = cca_apqns4type(subtype, NULL, NULL, 0,
				    _apqns, &nr_apqns, pflags);
		if (rc)
			goto out;
		apqns = _apqns;
@@ -423,11 +442,11 @@ static int cca_clr2key(const struct pkey_apqn *apqns, size_t nr_apqns,
		if (subtype == PKEY_TYPE_CCA_CIPHER) {
			rc = cca_clr2cipherkey(apqns[i].card, apqns[i].domain,
					       keybitsize, flags, clrkey,
					       keybuf, keybuflen);
					       keybuf, keybuflen, xflags);
		} else {
			/* PKEY_TYPE_CCA_DATA */
			rc = cca_clr2seckey(apqns[i].card, apqns[i].domain,
					    keybitsize, clrkey, keybuf);
					    keybitsize, clrkey, keybuf, xflags);
			*keybuflen = (rc ? 0 : SECKEYBLOBSIZE);
		}
	}
@@ -439,12 +458,15 @@ static int cca_clr2key(const struct pkey_apqn *apqns, size_t nr_apqns,

static int cca_verifykey(const u8 *key, u32 keylen,
			 u16 *card, u16 *dom,
			 u32 *keytype, u32 *keybitsize, u32 *flags)
			 u32 *keytype, u32 *keybitsize, u32 *flags, u32 pflags)
{
	struct keytoken_header *hdr = (struct keytoken_header *)key;
	u32 apqns[MAXAPQNSINLIST], nr_apqns = ARRAY_SIZE(apqns);
	u32 xflags;
	int rc;

	xflags = pflags & PKEY_XFLAG_NOMEMALLOC ? ZCRYPT_XFLAG_NOMEMALLOC : 0;

	if (keylen < sizeof(*hdr))
		return -EINVAL;

@@ -461,14 +483,14 @@ static int cca_verifykey(const u8 *key, u32 keylen,
		*keybitsize = t->bitsize;
		rc = cca_findcard2(apqns, &nr_apqns, *card, *dom,
				   ZCRYPT_CEX3C, AES_MK_SET,
				   t->mkvp, 0);
				   t->mkvp, 0, xflags);
		if (!rc)
			*flags = PKEY_FLAGS_MATCH_CUR_MKVP;
		if (rc == -ENODEV) {
			nr_apqns = ARRAY_SIZE(apqns);
			rc = cca_findcard2(apqns, &nr_apqns, *card, *dom,
					   ZCRYPT_CEX3C, AES_MK_SET,
					   0, t->mkvp);
					   0, t->mkvp, xflags);
			if (!rc)
				*flags = PKEY_FLAGS_MATCH_ALT_MKVP;
		}
@@ -495,14 +517,14 @@ static int cca_verifykey(const u8 *key, u32 keylen,
			*keybitsize = PKEY_SIZE_AES_256;
		rc = cca_findcard2(apqns, &nr_apqns, *card, *dom,
				   ZCRYPT_CEX6, AES_MK_SET,
				   t->mkvp0, 0);
				   t->mkvp0, 0, xflags);
		if (!rc)
			*flags = PKEY_FLAGS_MATCH_CUR_MKVP;
		if (rc == -ENODEV) {
			nr_apqns = ARRAY_SIZE(apqns);
			rc = cca_findcard2(apqns, &nr_apqns, *card, *dom,
					   ZCRYPT_CEX6, AES_MK_SET,
					   0, t->mkvp0);
					   0, t->mkvp0, xflags);
			if (!rc)
				*flags = PKEY_FLAGS_MATCH_ALT_MKVP;
		}
@@ -533,7 +555,7 @@ static int cca_slowpath_key2protkey(const struct pkey_apqn *apqns,
				    size_t nr_apqns,
				    const u8 *key, u32 keylen,
				    u8 *protkey, u32 *protkeylen,
				    u32 *protkeytype)
				    u32 *protkeytype, u32 pflags)
{
	const struct keytoken_header *hdr = (const struct keytoken_header *)key;
	const struct clearkeytoken *t = (const struct clearkeytoken *)key;
@@ -555,12 +577,12 @@ static int cca_slowpath_key2protkey(const struct pkey_apqn *apqns,
		tmplen = SECKEYBLOBSIZE;
		rc = cca_clr2key(NULL, 0, t->keytype, PKEY_TYPE_CCA_DATA,
				 8 * keysize, 0, t->clearkey, t->len,
				 tmpbuf, &tmplen, NULL);
				 tmpbuf, &tmplen, NULL, pflags);
		pr_debug("cca_clr2key()=%d\n", rc);
		if (rc)
			continue;
		rc = cca_key2protkey(NULL, 0, tmpbuf, tmplen,
				     protkey, protkeylen, protkeytype);
				     protkey, protkeylen, protkeytype, pflags);
		pr_debug("cca_key2protkey()=%d\n", rc);
	}

Loading