Re: [PATCH crypto 2/2] crypto: safexcel - Map AEAD buffers with accurate DMA directions

From: Herbert Xu

Date: Mon Sep 28 2026 - 01:13:17 EST


On Wed, Sep 23, 2026 at 11:13:17AM +0200, Ralf Lici wrote:
>
> There is no caller to identify for that particular single-entry layout,
> it was only a hypothetical example in response to your question. Even
> for out-of-place AEAD, the destination starts with space reserved for
> the associated data (as documented in the comment at the top of
> include/crypto/aead.h). A single linear destination entry can therefore
> contain both that reserved prefix, which the device does not write, and
> the ciphertext and tag, which it does write. Because the DMA direction
> applies to the whole entry, such a mixed entry is mapped
> DMA_BIDIRECTIONAL.

So why is it a problem if the dst SG list entries aren't pointing
to memory that's also occupied by the SG list entries?

Even if the hardware doesn't write to the data, it should be OK to
map them.

The only issue that I can see is if the same memory is present in
both the src SG list and the dst SG list, but that is expressly
forbidden for out-of-place operations, and indeed would be a grave
security issue.

Thanks,
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt