Page MenuHomeFreeBSD

cryptodev: Permit explicit IV/nonce and MAC/tag lengths.
ClosedPublic

Authored by jhb on Sep 24 2021, 6:04 PM.
Tags
None
Referenced Files
F174710673: D32107.id95641.diff
Mon, Oct 5, 9:45 AM
F174706289: D32107.id.diff
Mon, Oct 5, 9:02 AM
F174694210: D32107.id96376.diff
Mon, Oct 5, 6:37 AM
Unknown Object (File)
Sun, Oct 4, 3:57 PM
Unknown Object (File)
Fri, Oct 2, 9:23 PM
Unknown Object (File)
Fri, Oct 2, 5:14 PM
Unknown Object (File)
Wed, Sep 30, 6:53 PM
Unknown Object (File)
Sun, Sep 20, 5:33 AM
Subscribers

Details

Summary

Add 'ivlen' and 'maclen' fields to the structure used for CIOGSESSION2
to specify the explicit IV/nonce and MAC/tag lengths for crypto
sessions. If these fields are zero, the default lengths are used.

This permits selecting an alternate nonce length for AEAD ciphers such
as AES-CCM which support multiple nonce leengths. It also supports
truncated MACs as input to AEAD or ETA requests.

Sponsored by: The FreeBSD Foundation

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
No Lint Coverage
Unit
No Test Coverage
Build Status
Buildable 41905
Build 38793: arc lint + arc unit

Event Timeline

sys/opencrypto/cryptodev.c
598

Why is this assignment needed? It is done again below.

jhb marked an inline comment as done.Oct 1 2021, 8:59 PM
jhb added inline comments.
sys/opencrypto/cryptodev.c
598

Oops, an earlier leftover from my first cut at doing this.

jhb marked an inline comment as done.
  • Drop an unnecessary line.
This revision is now accepted and ready to land.Oct 1 2021, 9:42 PM