| From 4587d4a56aa45ca3095671db55bfa1db0ed857da Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 18 May 2022 08:32:18 +0200 |
| Subject: net: af_key: check encryption module availability consistency |
| |
| From: Thomas Bartschies <thomas.bartschies@cvk.de> |
| |
| [ Upstream commit 015c44d7bff3f44d569716117becd570c179ca32 ] |
| |
| Since the recent introduction supporting the SM3 and SM4 hash algos for IPsec, the kernel |
| produces invalid pfkey acquire messages, when these encryption modules are disabled. This |
| happens because the availability of the algos wasn't checked in all necessary functions. |
| This patch adds these checks. |
| |
| Signed-off-by: Thomas Bartschies <thomas.bartschies@cvk.de> |
| Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/key/af_key.c | 6 +++--- |
| 1 file changed, 3 insertions(+), 3 deletions(-) |
| |
| diff --git a/net/key/af_key.c b/net/key/af_key.c |
| index 776f94ecbfe6..d5dc614af2f9 100644 |
| --- a/net/key/af_key.c |
| +++ b/net/key/af_key.c |
| @@ -2935,7 +2935,7 @@ static int count_ah_combs(const struct xfrm_tmpl *t) |
| break; |
| if (!aalg->pfkey_supported) |
| continue; |
| - if (aalg_tmpl_set(t, aalg)) |
| + if (aalg_tmpl_set(t, aalg) && aalg->available) |
| sz += sizeof(struct sadb_comb); |
| } |
| return sz + sizeof(struct sadb_prop); |
| @@ -2953,7 +2953,7 @@ static int count_esp_combs(const struct xfrm_tmpl *t) |
| if (!ealg->pfkey_supported) |
| continue; |
| |
| - if (!(ealg_tmpl_set(t, ealg))) |
| + if (!(ealg_tmpl_set(t, ealg) && ealg->available)) |
| continue; |
| |
| for (k = 1; ; k++) { |
| @@ -2964,7 +2964,7 @@ static int count_esp_combs(const struct xfrm_tmpl *t) |
| if (!aalg->pfkey_supported) |
| continue; |
| |
| - if (aalg_tmpl_set(t, aalg)) |
| + if (aalg_tmpl_set(t, aalg) && aalg->available) |
| sz += sizeof(struct sadb_comb); |
| } |
| } |
| -- |
| 2.35.1 |
| |