git: ed5fc8066f98 - main - cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 16 Sep 2026 19:56:40 UTC
The branch main has been updated by jhb:
URL: https://cgit.FreeBSD.org/src/commit/?id=ed5fc8066f98e639f624de9997b33727ed883c32
commit ed5fc8066f98e639f624de9997b33727ed883c32
Author: John Baldwin <jhb@FreeBSD.org>
AuthorDate: 2026-09-16 19:56:20 +0000
Commit: John Baldwin <jhb@FreeBSD.org>
CommitDate: 2026-09-16 19:56:20 +0000
cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record
If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.
Note that this does not effect correctness, just efficiency.
Reviewed by: np
Fixes: 9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D59711
---
sys/dev/cxgbe/crypto/t7_kern_tls.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sys/dev/cxgbe/crypto/t7_kern_tls.c b/sys/dev/cxgbe/crypto/t7_kern_tls.c
index f23e9de61c0e..d3a4f6d3ab6f 100644
--- a/sys/dev/cxgbe/crypto/t7_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t7_kern_tls.c
@@ -1975,7 +1975,7 @@ ktls_write_tls_wr(struct tlspcb *tlsp, struct sge_txq *txq,
tlsp->ghash_pending = true;
tlsp->ghash_valid = false;
tlsp->ghash_lcb = ghash_lcb;
- if (last_ghash_frag)
+ if (ghash_lcb)
tlsp->ghash_offset = offset + plen;
else
tlsp->ghash_offset = rounddown2(offset + plen,