git: 17126d54c40a - main - cxgbe: Various assertions for lengths in KTLS work requests

From: John Baldwin <jhb_at_FreeBSD.org>
Date: Wed, 30 Sep 2026 19:25:08 UTC
The branch main has been updated by jhb:

URL: https://cgit.FreeBSD.org/src/commit/?id=17126d54c40a2e3f3e2a81e31a07c299416ddf4a

commit 17126d54c40a2e3f3e2a81e31a07c299416ddf4a
Author:     John Baldwin <jhb@FreeBSD.org>
AuthorDate: 2026-09-30 19:19:11 +0000
Commit:     John Baldwin <jhb@FreeBSD.org>
CommitDate: 2026-09-30 19:19:11 +0000

    cxgbe: Various assertions for lengths in KTLS work requests
    
    The construction of KTLS work requests is quite fragile, and these
    assertions ensure that the constructed work requests match the length
    fields encoded in some of the WR structures.
    
    Sponsored by:   Chelsio Communications
---
 sys/dev/cxgbe/crypto/t7_kern_tls.c | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)

diff --git a/sys/dev/cxgbe/crypto/t7_kern_tls.c b/sys/dev/cxgbe/crypto/t7_kern_tls.c
index a9f5a042b895..a539a6793f16 100644
--- a/sys/dev/cxgbe/crypto/t7_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t7_kern_tls.c
@@ -1930,6 +1930,8 @@ ktls_write_tls_wr(struct tlspcb *tlsp, struct sge_txq *txq,
 		panic("%s: failed to append sglist", __func__);
 #endif
 	}
+	KASSERT(txq->gl->sg_nseg == nsegs, ("%s: sg_nseg %u != nsegs %u",
+	    __func__, txq->gl->sg_nseg, nsegs));
 	if (last_ghash_frag) {
 		if (sglist_append_phys(txq->gl, zero_buffer_pa,
 		    AES_GMAC_HASH_LEN) != 0) {
@@ -1940,6 +1942,10 @@ ktls_write_tls_wr(struct tlspcb *tlsp, struct sge_txq *txq,
 	}
 	out = write_gl_to_buf(txq->gl, out);
 
+	KASSERT((char *)out - (char *)(wr + 1) == roundup2(txpkt_lens[0], 16),
+	    ("%s: txpkts_len[0] mismatch: %td vs %u", __func__,
+	    (char *)out - (char *)(wr + 1), roundup2(txpkt_lens[0], 16)));
+
 	if (request_ghash) {
 		/* ULP_TXPKT */
 		txpkt = (void *)out;
@@ -1988,8 +1994,18 @@ ktls_write_tls_wr(struct tlspcb *tlsp, struct sge_txq *txq,
 		m_snd_tag_ref(&tlsp->com);
 
 		txq->kern_tls_ghash_requested++;
+
+		KASSERT((char *)out - (char *)txpkt ==
+		    roundup2(txpkt_lens[1], 16),
+		    ("%s: txpkts_len[1] mismatch: %td vs %u", __func__,
+		    (char *)out - (char *)txpkt, roundup2(txpkt_lens[1], 16)));
+
 	}
 
+	KASSERT((char *)out - (char *)wr == roundup2(wr_len, 16),
+	    ("%s: wr_len mismatch: %td vs %u", __func__,
+	    (char *)out - (char *)wr, roundup2(wr_len, 16)));
+
 	if (using_scratch) {
 		out = dst;
 		copy_to_txd(eq, txq->ss, &out, wr_len);