Re: [PATCH] crypto: atmel: handle authenc requests without plaintext

From: Herbert Xu

Date: Fri Oct 02 2026 - 04:28:45 EST


On Tue, Sep 22, 2026 at 07:17:04AM +0200, Karl Mehltretter wrote:
> Authenc permits a nonempty associated-data string with no plaintext. The
> Atmel driver accepts such a request, has SHA process the associated data,
> and then unconditionally asks AES DMA to transfer zero bytes. The Atmel
> DMA engines reject the zero-length descriptor, so the valid request fails,
> normally with -ENOMEM.
>
> Skip the AES transfer when textlen is zero and proceed directly to SHA
> finalization.
>
> Once an HMAC transform has cached its inner and outer states, SHA can
> complete this path synchronously. The forced ahash completion callback
> then invokes the AES finalizer through a void function and discards its
> return value. This loses -EBADMSG for a mismatched tag and reports
> successful decryption.
>
> For synchronous SHA completion, release the SHA device without invoking
> the ahash callback and call the AES finalizer directly. Its result then
> propagates through the synchronous call chain. Keep the existing callback
> path for asynchronous completion.
>
> On a SAM9X75, the unpatched driver failed valid AAD-only requests and
> returned success for a bad tag after the transform had been used once. With
> this change, bad tags return -EBADMSG for both fresh and reused transforms.
>
> Fixes: 89a82ef87e01 ("crypto: atmel-authenc - add support to authenc(hmac(shaX), Y(aes)) modes")
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
> ---
> drivers/crypto/atmel-aes.c | 2 ++
> drivers/crypto/atmel-sha.c | 14 ++++++++++++++
> 2 files changed, 16 insertions(+)

Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt