Re: [PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN

From: Lukas Wunner

Date: Tue Jul 28 2026 - 02:21:35 EST


[cc += Martin Kepplinger-NovakoviÄ?]

On Tue, Jul 28, 2026 at 08:43:00AM +1000, Changwei Zou wrote:
> out_buf is used as a DMA buffer for the RSA verification operation.
> If out_buf is not aligned to ARCH_DMA_MINALIGN, cacheline sharing
> problems (data corruption) would occur on CPUs with DMA-incoherent caches,
> leading to -EKEYREJECTED.
>
> Fix by aligning out_buf to ARCH_DMA_MINALIGN using PTR_ALIGN(), and
> allocating ARCH_DMA_MINALIGN extra bytes in the child_req allocation
> to accommodate the alignment padding.
>
> The intermittent error 'Key was rejected by service' on i.MX8 with CAAM
> can be triggered when loading signed kernel modules.
>
> for i in $(seq 1 100); do
> sudo modprobe xfs 2>&1 && echo "SUCCESS on attempt $i" \
> && sudo rmmod xfs || echo "FAILED on attempt $i"
> done
>
> Fixes: 8552cb04e083 ("crypto: rsassa-pkcs1 - Copy source data for SG list")
> Signed-off-by: Changwei Zou <changwei.zou@xxxxxxxxxxxxx>

@Martin Kepplinger-NovakoviÄ?: Could you test whether this fixes
the issue you reported in February?

If it does:

Reported-by: Martin Kepplinger-NovakoviÄ? <Martin.Kepplinger-Novakovic@xxxxxxxxxxxxx>
Closes: https://lore.kernel.org/r/6029acc0f0ddfe25e2537c2866d54fd7f54bc182.camel@xxxxxxxxxxxxx


@Changwei Zou: Just to double-check, I assume this supersedes the
following patch, right?

https://lore.kernel.org/r/20260723150107.33546-1-changwei.zou@xxxxxxxxxxxxx


> +++ b/crypto/rsassa-pkcs1.c
> @@ -237,12 +239,13 @@ static int rsassa_pkcs1_verify(struct crypto_sig *tfm,
> return -EINVAL;
>
> /* RFC 8017 sec 8.2.2 step 2 - RSA verification */
> - child_req = kmalloc(sizeof(*child_req) + child_reqsize + ctx->key_size,
> - GFP_KERNEL);
> + child_req = kmalloc(sizeof(*child_req) + child_reqsize +
> + ctx->key_size + ARCH_DMA_MINALIGN, GFP_KERNEL);
> if (!child_req)
> return -ENOMEM;
>
> - out_buf = (u8 *)(child_req + 1) + child_reqsize;
> + out_buf = PTR_ALIGN((u8 *)(child_req + 1) + child_reqsize,
> + ARCH_DMA_MINALIGN);
> memcpy(out_buf, src, slen);

We've got CRYPTO_DMA_ALIGN, CRYPTO_MINALIGN, CRYPTO_DMA_PADDING macros,
I think those would be more appropriate.

A few nits:
There's a duplicate blank in the "out_buf =" assignment and
the line-wrapped function arguments aren't aligned to the opening brace.

> @@ -7,6 +7,8 @@
> * Copyright (c) 2015 - 2024 Intel Corporation
> */
>
> +#include <linux/align.h>
> +#include <linux/cache.h>
> #include <linux/module.h>
> #include <linux/scatterlist.h>
> #include <crypto/akcipher.h>

I think you won't be needing those #includes if you use the CRYPTO_*
alignment macros.

Thanks,

Lukas