On 14 October 2016 at 09:55, Johannes Berg <johannes@xxxxxxxxxxxxxxxx> wrote: > On Fri, 2016-10-14 at 09:47 +0100, Ard Biesheuvel wrote: >> >> Do you have a reference for the sg_set_buf() call on odata? >> crypto/ccm.c does not seem to have it (afaict), > > It's indirect - crypto_ccm_encrypt() calls crypto_ccm_init_crypt() > which does it. > Indeed. And the decrypt path does the same for auth_tag[]. But that still means there are two separate problems here, one which affects the WPA code, and one that only affects the generic CCM chaining mode (but not the accelerated arm64 implementation) Unsurprisingly, I would strongly prefer those to be fixed properly rather than backing out my patch, but I'm happy to help out whichever solution we reach consensus on. >> and the same problem >> does not exist in the accelerated arm64 implementation. In the mean >> time, I will try and see if we can move aad[] off the stack in the >> WPA code. > > I had that with per-CPU buffers, just sent the patch upthread. > I will check whether this removes the issue when not using crypto/ccm.ko