* [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups
@ 2026-09-18 12:27 Weili Qian
2026-09-18 12:27 ` [PATCH 1/7] crypto: hisilicon/hpre - fix pointer dereference before length check Weili Qian
` (7 more replies)
0 siblings, 8 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
Patches 1-5 fix bugs (OOB read, dead code, wrong errno, DMA mapping
and GFP flags) in the ECDH/RSA/DH paths; patches 6-7 are cleanups.
Weili Qian (7):
crypto: hisilicon/hpre - fix pointer dereference before length check
crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in
ECDH
crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output
buffer
crypto: hisilicon/hpre - fix ECDH destination DMA mapping
crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent
crypto: hisilicon/hpre - extract clusters num into inline function
crypto: hisilicon/hpre - remove unused macros and struct fields
drivers/crypto/hisilicon/hpre/hpre.h | 1 -
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 28 ++++++++---------
drivers/crypto/hisilicon/hpre/hpre_main.c | 47 +++++++++--------------------
3 files changed, 28 insertions(+), 48 deletions(-)
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 1/7] crypto: hisilicon/hpre - fix pointer dereference before length check
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 2/7] crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in ECDH Weili Qian
` (6 subsequent siblings)
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
In hpre_rsa_drop_leading_zeros(), the loop condition dereferences *ptr
before checking *len, causing an out-of-bounds read when *len is zero.
Swap to while (*len && !**ptr) to test length first.
Fixes: c8b4b477079d ("crypto: hisilicon - add HiSilicon HPRE accelerator")
Cc: stable@vger.kernel.org
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index 09077abbf6ad..7894211b9972 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -720,7 +720,7 @@ static void hpre_dh_exit_tfm(struct crypto_kpp *tfm)
static void hpre_rsa_drop_leading_zeros(const char **ptr, size_t *len)
{
- while (!**ptr && *len) {
+ while (*len && !**ptr) {
(*ptr)++;
(*len)--;
}
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 2/7] crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in ECDH
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
2026-09-18 12:27 ` [PATCH 1/7] crypto: hisilicon/hpre - fix pointer dereference before length check Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 3/7] crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output buffer Weili Qian
` (5 subsequent siblings)
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
In hpre_ecdh_hw_data_clr_all(), req->dst is always NULL because
hpre_ecdh_dst_data_init() sets hpre_req->dst = NULL before mapping
the user buffer with dma_map_single(). The dma_free_coherent() call
on req->dst is therefore dead code. Remove it.
Fixes: 05e7b906aa7c ("crypto: hisilicon/hpre - add 'ECDH' algorithm")
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index 7894211b9972..8551d6ccb78d 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -1407,8 +1407,6 @@ static void hpre_ecdh_hw_data_clr_all(struct hpre_ctx *ctx,
if (unlikely(dma_mapping_error(dev, dma)))
return;
- if (req->dst)
- dma_free_coherent(dev, ctx->key_sz << 1, req->dst, dma);
if (dst)
dma_unmap_single(dev, dma, ctx->key_sz << 1, DMA_FROM_DEVICE);
}
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 3/7] crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output buffer
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
2026-09-18 12:27 ` [PATCH 1/7] crypto: hisilicon/hpre - fix pointer dereference before length check Weili Qian
2026-09-18 12:27 ` [PATCH 2/7] crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in ECDH Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 4/7] crypto: hisilicon/hpre - fix ECDH destination DMA mapping Weili Qian
` (4 subsequent siblings)
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
hpre_ecdh_msg_request_set() returns -EINVAL when the output buffer
is too small, after setting req->dst_len to the required size.
-EINVAL is misleading because the caller can retry with a larger
buffer. Return -EOVERFLOW as other kpp implementations do.
Fixes: 05e7b906aa7c ("crypto: hisilicon/hpre - add 'ECDH' algorithm")
Cc: stable@vger.kernel.org
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index 8551d6ccb78d..6dea9ce5bae2 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -1450,7 +1450,7 @@ static int hpre_ecdh_msg_request_set(struct hpre_ctx *ctx,
if (req->dst_len < ctx->key_sz << 1) {
req->dst_len = ctx->key_sz << 1;
- return -EINVAL;
+ return -EOVERFLOW;
}
tmp = kpp_request_ctx(req);
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 4/7] crypto: hisilicon/hpre - fix ECDH destination DMA mapping
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
` (2 preceding siblings ...)
2026-09-18 12:27 ` [PATCH 3/7] crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output buffer Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 5/7] crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent Weili Qian
` (3 subsequent siblings)
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
hpre_ecdh_dst_data_init() rejects valid requests whose output length
does not equal ctx->key_sz << 1, and maps the user buffer using the
user-provided len instead of the hardware transfer size. Drop the
redundant length check and use ctx->key_sz << 1 for dma_map_single()
so the whole hardware output is mapped.
Fixes: 05e7b906aa7c ("crypto: hisilicon/hpre - add 'ECDH' algorithm")
Cc: stable@vger.kernel.org
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index 6dea9ce5bae2..f77c318caa35 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -1510,13 +1510,13 @@ static int hpre_ecdh_dst_data_init(struct hpre_asym_request *hpre_req,
struct device *dev = ctx->dev;
dma_addr_t dma;
- if (unlikely(!data || !sg_is_last(data) || len != ctx->key_sz << 1)) {
- dev_err(dev, "data or data length is illegal!\n");
+ if (unlikely(!data || !sg_is_last(data))) {
+ dev_err(dev, "data is illegal!\n");
return -EINVAL;
}
hpre_req->dst = NULL;
- dma = dma_map_single(dev, sg_virt(data), len, DMA_FROM_DEVICE);
+ dma = dma_map_single(dev, sg_virt(data), ctx->key_sz << 1, DMA_FROM_DEVICE);
if (unlikely(dma_mapping_error(dev, dma))) {
dev_err(dev, "dma map data err!\n");
return -ENOMEM;
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 5/7] crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
` (3 preceding siblings ...)
2026-09-18 12:27 ` [PATCH 4/7] crypto: hisilicon/hpre - fix ECDH destination DMA mapping Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 6/7] crypto: hisilicon/hpre - extract clusters num into inline function Weili Qian
` (2 subsequent siblings)
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
The HPRE driver hard-codes GFP_ATOMIC for RSA/DH and GFP_KERNEL for
ECDH. This may cause "scheduling while atomic" in atomic context or
unnecessary allocation failures under memory pressure.
Select GFP flags dynamically based on CRYPTO_TFM_REQ_MAY_SLEEP and
store them in hpre_asym_request::flags. The areq field is a union of
rsa/dh/ecdh request pointers; reading base.flags through any union
member other than the one that was written would be type-punning, so
a dedicated flags field avoids that.
Fixes: 98dfa9343f37 ("crypto: hisilicon/hpre - don't use GFP_KERNEL to alloc mem during softirq")
Cc: stable@vger.kernel.org
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index f77c318caa35..6ca34f3bf9ff 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -138,6 +138,7 @@ struct hpre_asym_request {
int err;
hpre_cb cb;
struct timespec64 req_time;
+ u32 flags;
};
static inline unsigned int hpre_align_sz(void)
@@ -186,6 +187,7 @@ static int hpre_prepare_dma_buf(struct hpre_asym_request *hpre_req,
struct scatterlist *data, unsigned int len,
int is_src, dma_addr_t *tmp)
{
+ gfp_t gfp = hpre_req->flags & CRYPTO_TFM_REQ_MAY_SLEEP ? GFP_KERNEL : GFP_ATOMIC;
struct hpre_ctx *ctx = hpre_req->ctx;
struct device *dev = ctx->dev;
void *ptr;
@@ -195,7 +197,7 @@ static int hpre_prepare_dma_buf(struct hpre_asym_request *hpre_req,
if (unlikely(shift < 0))
return -EINVAL;
- ptr = dma_alloc_coherent(dev, ctx->key_sz, tmp, GFP_ATOMIC);
+ ptr = dma_alloc_coherent(dev, ctx->key_sz, tmp, gfp);
if (unlikely(!ptr))
return -ENOMEM;
@@ -419,6 +421,7 @@ static int hpre_msg_request_set(struct hpre_ctx *ctx, void *req, bool is_rsa)
h_req = PTR_ALIGN(tmp, hpre_align_sz());
h_req->cb = hpre_rsa_cb;
h_req->areq.rsa = akreq;
+ h_req->flags = akreq->base.flags;
msg = &h_req->req;
memset(msg, 0, sizeof(*msg));
} else {
@@ -433,6 +436,7 @@ static int hpre_msg_request_set(struct hpre_ctx *ctx, void *req, bool is_rsa)
h_req = PTR_ALIGN(tmp, hpre_align_sz());
h_req->cb = hpre_dh_cb;
h_req->areq.dh = kreq;
+ h_req->flags = kreq->base.flags;
msg = &h_req->req;
memset(msg, 0, sizeof(*msg));
msg->key = cpu_to_le64(ctx->dh.dma_xa_p);
@@ -1457,6 +1461,7 @@ static int hpre_ecdh_msg_request_set(struct hpre_ctx *ctx,
h_req = PTR_ALIGN(tmp, hpre_align_sz());
h_req->cb = hpre_ecdh_cb;
h_req->areq.ecdh = req;
+ h_req->flags = req->base.flags;
msg = &h_req->req;
memset(msg, 0, sizeof(*msg));
msg->in = cpu_to_le64(DMA_MAPPING_ERROR);
@@ -1475,6 +1480,7 @@ static int hpre_ecdh_msg_request_set(struct hpre_ctx *ctx,
static int hpre_ecdh_src_data_init(struct hpre_asym_request *hpre_req,
struct scatterlist *data, unsigned int len)
{
+ gfp_t gfp = hpre_req->flags & CRYPTO_TFM_REQ_MAY_SLEEP ? GFP_KERNEL : GFP_ATOMIC;
struct hpre_sqe *msg = &hpre_req->req;
struct hpre_ctx *ctx = hpre_req->ctx;
struct device *dev = ctx->dev;
@@ -1488,7 +1494,7 @@ static int hpre_ecdh_src_data_init(struct hpre_asym_request *hpre_req,
if (unlikely(shift < 0))
return -EINVAL;
- ptr = dma_alloc_coherent(dev, ctx->key_sz << 2, &dma, GFP_KERNEL);
+ ptr = dma_alloc_coherent(dev, ctx->key_sz << 2, &dma, gfp);
if (unlikely(!ptr))
return -ENOMEM;
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 6/7] crypto: hisilicon/hpre - extract clusters num into inline function
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
` (4 preceding siblings ...)
2026-09-18 12:27 ` [PATCH 5/7] crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-18 12:27 ` [PATCH 7/7] crypto: hisilicon/hpre - remove unused macros and struct fields Weili Qian
2026-09-23 8:51 ` [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Herbert Xu
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
Seven functions in hpre_main.c open-code the same cluster number
extraction from HPRE_CORE_INFO. Extract into hpre_get_clusters_num().
hpre_pre_store_cap_reg() uses a local hpre_cap[] array rather than
qm->cap_tables.dev_cap_table[] and is therefore not converted.
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre_main.c | 43 ++++++++---------------
1 file changed, 15 insertions(+), 28 deletions(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre_main.c b/drivers/crypto/hisilicon/hpre/hpre_main.c
index b6903fce6071..e1a567383de5 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_main.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_main.c
@@ -381,6 +381,14 @@ static const char *hpre_channel_name[HPRE_MAX_CHANNEL_NUM] = {
static const struct hisi_qm_err_ini hpre_err_ini;
+static inline u8 hpre_get_clusters_num(struct hisi_qm *qm)
+{
+ u32 cap = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
+
+ return (cap >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
+ hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+}
+
bool hpre_check_alg_support(struct hisi_qm *qm, u32 alg)
{
u32 cap_val;
@@ -557,15 +565,12 @@ static int hpre_set_cluster(struct hisi_qm *qm)
struct device *dev = &qm->pdev->dev;
u32 cluster_core_mask;
unsigned long offset;
- u32 hpre_core_info;
u8 clusters_num;
u32 val = 0;
int ret, i;
cluster_core_mask = qm->cap_tables.dev_cap_table[HPRE_CORE_EN].cap_val;
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
offset = i * HPRE_CLSTR_ADDR_INTRVL;
@@ -659,7 +664,6 @@ static void hpre_enable_clock_gate(struct hisi_qm *qm)
{
unsigned long offset;
u8 clusters_num, i;
- u32 hpre_core_info;
u32 val;
if (qm->ver < QM_HW_V3)
@@ -673,9 +677,7 @@ static void hpre_enable_clock_gate(struct hisi_qm *qm)
val |= HPRE_PEH_CFG_AUTO_GATE_EN;
writel(val, qm->io_base + HPRE_PEH_CFG_AUTO_GATE);
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
offset = (unsigned long)i * HPRE_CLSTR_ADDR_INTRVL;
val = readl(qm->io_base + offset + HPRE_CLUSTER_DYN_CTL);
@@ -692,7 +694,6 @@ static void hpre_disable_clock_gate(struct hisi_qm *qm)
{
unsigned long offset;
u8 clusters_num, i;
- u32 hpre_core_info;
u32 val;
if (qm->ver < QM_HW_V3)
@@ -706,9 +707,7 @@ static void hpre_disable_clock_gate(struct hisi_qm *qm)
val &= ~HPRE_PEH_CFG_AUTO_GATE_EN;
writel(val, qm->io_base + HPRE_PEH_CFG_AUTO_GATE);
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
offset = (unsigned long)i * HPRE_CLSTR_ADDR_INTRVL;
val = readl(qm->io_base + offset + HPRE_CLUSTER_DYN_CTL);
@@ -782,14 +781,11 @@ static int hpre_set_user_domain_and_cache(struct hisi_qm *qm)
static void hpre_cnt_regs_clear(struct hisi_qm *qm)
{
unsigned long offset;
- u32 hpre_core_info;
u8 clusters_num;
int i;
/* clear clusterX/cluster_ctrl */
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
offset = HPRE_CLSTR_BASE + i * HPRE_CLSTR_ADDR_INTRVL;
writel(0x0, qm->io_base + offset + HPRE_CLUSTER_INQURY);
@@ -1072,13 +1068,10 @@ static int hpre_cluster_debugfs_init(struct hisi_qm *qm)
char buf[HPRE_DBGFS_VAL_MAX_LEN];
struct debugfs_regset32 *regset;
struct dentry *tmp_d;
- u32 hpre_core_info;
u8 clusters_num;
int i, ret;
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
ret = snprintf(buf, HPRE_DBGFS_VAL_MAX_LEN, "cluster%d", i);
if (ret >= HPRE_DBGFS_VAL_MAX_LEN)
@@ -1308,13 +1301,10 @@ static int hpre_show_last_regs_init(struct hisi_qm *qm)
int com_dfx_regs_num = ARRAY_SIZE(hpre_com_dfx_regs);
struct qm_debug *debug = &qm->debug;
void __iomem *io_base;
- u32 hpre_core_info;
u8 clusters_num;
int i, j, idx;
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
debug->last_words = kcalloc(cluster_dfx_regs_num * clusters_num +
com_dfx_regs_num, sizeof(unsigned int), GFP_KERNEL);
if (!debug->last_words)
@@ -1354,7 +1344,6 @@ static void hpre_show_last_dfx_regs(struct hisi_qm *qm)
struct qm_debug *debug = &qm->debug;
struct pci_dev *pdev = qm->pdev;
void __iomem *io_base;
- u32 hpre_core_info;
u8 clusters_num;
int i, j, idx;
u32 val;
@@ -1370,9 +1359,7 @@ static void hpre_show_last_dfx_regs(struct hisi_qm *qm)
hpre_com_dfx_regs[i].name, debug->last_words[i], val);
}
- hpre_core_info = qm->cap_tables.dev_cap_table[HPRE_CORE_INFO].cap_val;
- clusters_num = (hpre_core_info >> hpre_basic_info[HPRE_CLUSTER_NUM_CAP].shift) &
- hpre_basic_info[HPRE_CLUSTER_NUM_CAP].mask;
+ clusters_num = hpre_get_clusters_num(qm);
for (i = 0; i < clusters_num; i++) {
io_base = qm->io_base + hpre_cluster_offsets[i];
for (j = 0; j < cluster_dfx_regs_num; j++) {
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 7/7] crypto: hisilicon/hpre - remove unused macros and struct fields
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
` (5 preceding siblings ...)
2026-09-18 12:27 ` [PATCH 6/7] crypto: hisilicon/hpre - extract clusters num into inline function Weili Qian
@ 2026-09-18 12:27 ` Weili Qian
2026-09-23 8:51 ` [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Herbert Xu
7 siblings, 0 replies; 9+ messages in thread
From: Weili Qian @ 2026-09-18 12:27 UTC (permalink / raw)
To: herbert; +Cc: linux-kernel, linux-crypto, liulongfang
Several macros, the hpre_asym_request::err field and the hpre::status
field are defined but never referenced. Remove them.
Signed-off-by: Weili Qian <qianweili@huawei.com>
---
drivers/crypto/hisilicon/hpre/hpre.h | 1 -
drivers/crypto/hisilicon/hpre/hpre_crypto.c | 6 ------
drivers/crypto/hisilicon/hpre/hpre_main.c | 4 ----
3 files changed, 11 deletions(-)
diff --git a/drivers/crypto/hisilicon/hpre/hpre.h b/drivers/crypto/hisilicon/hpre/hpre.h
index 021dbd9a1d48..f73d01f6da87 100644
--- a/drivers/crypto/hisilicon/hpre/hpre.h
+++ b/drivers/crypto/hisilicon/hpre/hpre.h
@@ -70,7 +70,6 @@ struct hpre_debug {
struct hpre {
struct hisi_qm qm;
struct hpre_debug debug;
- unsigned long status;
};
enum hpre_alg_type {
diff --git a/drivers/crypto/hisilicon/hpre/hpre_crypto.c b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
index 6ca34f3bf9ff..66a276786a7d 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_crypto.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_crypto.c
@@ -21,19 +21,15 @@ struct hpre_ctx;
#define HPRE_CRYPTO_ALG_PRI 1000
#define HPRE_ALIGN_SZ 64
#define HPRE_BITS_2_BYTES_SHIFT 3
-#define HPRE_RSA_512BITS_KSZ 64
-#define HPRE_RSA_1536BITS_KSZ 192
#define HPRE_CRT_PRMS 5
#define HPRE_CRT_Q 2
#define HPRE_CRT_P 3
#define HPRE_CRT_INV 4
#define HPRE_DH_G_FLAG 0x02
#define HPRE_TRY_SEND_TIMES 100
-#define HPRE_INVLD_REQ_ID (-1)
#define HPRE_SQE_ALG_BITS 5
#define HPRE_SQE_DONE_SHIFT 30
-#define HPRE_DH_MAX_P_SZ 512
#define HPRE_DFX_SEC_TO_US 1000000
#define HPRE_DFX_US_TO_NS 1000
@@ -56,7 +52,6 @@ struct hpre_ctx;
#define HPRE_DRV_RSA_MASK_CAP BIT(0)
#define HPRE_DRV_DH_MASK_CAP BIT(1)
#define HPRE_DRV_ECDH_MASK_CAP BIT(2)
-#define HPRE_DRV_X25519_MASK_CAP BIT(5)
static DEFINE_MUTEX(hpre_algs_lock);
static unsigned int hpre_available_devs;
@@ -135,7 +130,6 @@ struct hpre_asym_request {
struct kpp_request *dh;
struct kpp_request *ecdh;
} areq;
- int err;
hpre_cb cb;
struct timespec64 req_time;
u32 flags;
diff --git a/drivers/crypto/hisilicon/hpre/hpre_main.c b/drivers/crypto/hisilicon/hpre/hpre_main.c
index e1a567383de5..03aa11a7a3b4 100644
--- a/drivers/crypto/hisilicon/hpre/hpre_main.c
+++ b/drivers/crypto/hisilicon/hpre/hpre_main.c
@@ -16,7 +16,6 @@
#define CAP_FILE_PERMISSION 0444
#define HPRE_CTRL_CNT_CLR_CE_BIT BIT(0)
#define HPRE_CTRL_CNT_CLR_CE 0x301000
-#define HPRE_FSM_MAX_CNT 0x301008
#define HPRE_VFG_AXQOS 0x30100c
#define HPRE_VFG_AXCACHE 0x301010
#define HPRE_RDCHN_INI_CFG 0x301014
@@ -41,7 +40,6 @@
#define HPRE_HAC_INT_SET 0x301500
#define HPRE_AXI_ERROR_MASK GENMASK(21, 10)
#define HPRE_RNG_TIMEOUT_NUM 0x301A34
-#define HPRE_CORE_INT_ENABLE 0
#define HPRE_RDCHN_INI_ST 0x301a00
#define HPRE_CLSTR_BASE 0x302000
#define HPRE_CORE_EN_OFFSET 0x04
@@ -61,8 +59,6 @@
#define HPRE_CORE_ENB (HPRE_CLSTR_BASE + HPRE_CORE_EN_OFFSET)
#define HPRE_CORE_INI_CFG (HPRE_CLSTR_BASE + HPRE_CORE_INI_CFG_OFFSET)
#define HPRE_CORE_INI_STATUS (HPRE_CLSTR_BASE + HPRE_CORE_INI_STATUS_OFFSET)
-#define HPRE_HAC_ECC1_CNT 0x301a04
-#define HPRE_HAC_ECC2_CNT 0x301a08
#define HPRE_HAC_SOURCE_INT 0x301600
#define HPRE_CLSTR_ADDR_INTRVL 0x1000
#define HPRE_CLUSTER_INQURY 0x100
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
` (6 preceding siblings ...)
2026-09-18 12:27 ` [PATCH 7/7] crypto: hisilicon/hpre - remove unused macros and struct fields Weili Qian
@ 2026-09-23 8:51 ` Herbert Xu
7 siblings, 0 replies; 9+ messages in thread
From: Herbert Xu @ 2026-09-23 8:51 UTC (permalink / raw)
To: Weili Qian; +Cc: linux-kernel, linux-crypto, liulongfang
On Fri, Sep 18, 2026 at 08:27:19PM +0800, Weili Qian wrote:
> Patches 1-5 fix bugs (OOB read, dead code, wrong errno, DMA mapping
> and GFP flags) in the ECDH/RSA/DH paths; patches 6-7 are cleanups.
>
> Weili Qian (7):
> crypto: hisilicon/hpre - fix pointer dereference before length check
> crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in
> ECDH
> crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output
> buffer
> crypto: hisilicon/hpre - fix ECDH destination DMA mapping
> crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent
> crypto: hisilicon/hpre - extract clusters num into inline function
> crypto: hisilicon/hpre - remove unused macros and struct fields
>
> drivers/crypto/hisilicon/hpre/hpre.h | 1 -
> drivers/crypto/hisilicon/hpre/hpre_crypto.c | 28 ++++++++---------
> drivers/crypto/hisilicon/hpre/hpre_main.c | 47 +++++++++--------------------
> 3 files changed, 28 insertions(+), 48 deletions(-)
>
> --
> 2.43.0
All applied. Thanks.
--
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-09-23 8:51 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-18 12:27 [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Weili Qian
2026-09-18 12:27 ` [PATCH 1/7] crypto: hisilicon/hpre - fix pointer dereference before length check Weili Qian
2026-09-18 12:27 ` [PATCH 2/7] crypto: hisilicon/hpre - remove dma_free_coherent on NULL req->dst in ECDH Weili Qian
2026-09-18 12:27 ` [PATCH 3/7] crypto: hisilicon/hpre - return -EOVERFLOW for small ECDH output buffer Weili Qian
2026-09-18 12:27 ` [PATCH 4/7] crypto: hisilicon/hpre - fix ECDH destination DMA mapping Weili Qian
2026-09-18 12:27 ` [PATCH 5/7] crypto: hisilicon/hpre - fix GFP flags for dma_alloc_coherent Weili Qian
2026-09-18 12:27 ` [PATCH 6/7] crypto: hisilicon/hpre - extract clusters num into inline function Weili Qian
2026-09-18 12:27 ` [PATCH 7/7] crypto: hisilicon/hpre - remove unused macros and struct fields Weili Qian
2026-09-23 8:51 ` [PATCH 0/7] crypto: hisilicon/hpre - misc fixes and cleanups Herbert Xu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®